Information transmission methods, devices, equipment and storage media

By introducing a management system and a communication system, dynamically generating identity authentication and data communication keys, and monitoring channel usage in real time, the resource waste and security risks of P2P negotiation servers in scenarios with massive IoT devices are resolved, thereby improving system performance and security.

CN119094590BActive Publication Date: 2025-10-31CHINA MOBILE M2M +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411175636.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-23
Publication Date
2025-10-31
Estimated Expiration
2044-08-23

AI Technical Summary

Technical Problem

In existing technologies, P2P negotiation servers maintain useless connections in scenarios with a large number of IoT devices, resulting in serious resource waste and affecting system performance. Furthermore, they do not consider the dynamic updating of the authentication keys of accessing clients, which poses a risk of communication data leakage and unauthorized access by counterfeit devices.

Method used

By introducing a management and communication system and abandoning the P2P negotiation server, a connection is established with the access client through the management channel. The system dynamically generates identity authentication keys and data communication keys, monitors channel usage in real time, and proactively disconnects connections that have not been used for a long time, thus ensuring the rational use of ports and communication resources.

Benefits of technology

It effectively solved the problem of resource waste, improved system performance, reduced the data security risks caused by static key leakage, and ensured the stable operation and security of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094590B_ABST
    Figure CN119094590B_ABST
Patent Text Reader

Abstract

This application discloses an information transmission method, apparatus, device, and storage medium, belonging to the field of communication technology. The method includes introducing a management system and a communication system. After a second client is started, a management channel is established between the management system and the second client. Upon receiving a remote access request from a first client and confirming a connection between the information transmission system and the second client, a first forwarding channel is established in the information transmission system, and a second forwarding channel is established on the second client. A remote access channel is established between the first client, the second client, the management system, and the communication system through the first and second forwarding channels. Since the first and second forwarding channels are disconnectable, the aforementioned forwarding channels can be actively disconnected according to the actual communication situation. This ensures information communication between the first and second clients while guaranteeing the rational utilization of ports and communication resources, thereby improving the performance of the transmission system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communication technology, specifically relating to an information transmission method, apparatus, device, and storage medium. Background Technology

[0002] A Virtual Private Network (VPN) can utilize the Internet or public Internet infrastructure to provide the same functionality and security as a private network, i.e., to conduct encrypted VPN communications over a public network.

[0003] In related technologies, a peer-to-peer (P2P) negotiation server can receive access requests from requesting clients to establish communication relationships with them, and establish communication relationships between the requesting and accessing clients based on the access requests, so that the two clients can each launch their respective VPN programs to exchange data. However, if a massive number of IoT devices are used as accessing clients, and there is no data communication for a long time after the connection channel is established between the requesting client and the massive number of accessing clients, it will cause a large waste of public network port resources of the P2P negotiation server, affecting the system performance of the P2P negotiation server. Summary of the Invention

[0004] The purpose of this application is to provide an information transmission method, apparatus, device, storage medium, and computer program product to solve the problem of serious resource waste in maintaining useless connections and reduced system performance of P2P negotiation servers in the prior art.

[0005] In a first aspect, embodiments of this application provide an information transmission method applied to an information transmission system, the information transmission system including a management system and a communication system, comprising:

[0006] Receive a first remote access request sent by a first client, the first remote access request being used to request access to a remote service in a second client;

[0007] When the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client, a first forwarding channel is established between the first session port and the bridging port based on the first remote access request. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the port for communication between the communication system and the management system in the information transmission system.

[0008] A first instruction is sent to the second client through the first session port. The first instruction carries the channel information of the first forwarding channel. The first instruction is used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system in the second client and the second client. The first forwarding channel and the second forwarding channel are disconnectable channels.

[0009] Upon receiving the response information corresponding to the remote service from the second client via the first session port, a remote connection command is sent to the first client. The response information is obtained by the second client through the second forwarding channel. The remote connection command carries information related to the response information and is used to instruct the first client to display the information related to the response information.

[0010] Secondly, embodiments of this application provide an information transmission method applied to an information transmission system, the information transmission system including a management system and a communication system, comprising:

[0011] The receiving module is used to receive a first remote access request sent by a first client, the first remote access request being used to request access to a remote service in a second client;

[0012] A module is established to establish a first forwarding channel between a first session port and a bridging port based on a first remote access request, when the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the communication port between the communication system and the management system in the information transmission system.

[0013] The transceiver module is used to send a first instruction to the second client through the first session port. The first instruction carries the channel information of the first forwarding channel. The first instruction is used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system in the second client and the second client. The first forwarding channel and the second forwarding channel are disconnectable channels.

[0014] The transceiver module is also used to send a remote connection command to the first client when it receives a response message corresponding to the remote service from the second client through the first session port. The response message is obtained by the second client through the second forwarding channel. The remote connection command carries information related to the response message and is used to instruct the first client to display information related to the response message.

[0015] Thirdly, embodiments of this application provide an electronic device, which includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the steps of the information transmission method as described in the first aspect.

[0016] Fourthly, embodiments of this application provide a readable storage medium on which a program or instructions are stored, and when the program or instructions are executed by a processor, the steps of the information transmission method as described in the first aspect are implemented.

[0017] Fifthly, embodiments of this application provide a chip, which includes a processor and a display interface, the display interface and the processor being coupled together, the processor being used to run programs or instructions to implement the steps of the information transmission method as described in the first aspect.

[0018] In a sixth aspect, embodiments of this application provide a computer program product stored in a storage medium, which is executed by at least one processor to implement the steps of the information transmission method as described in the first aspect.

[0019] In this embodiment, a first remote access request sent by a first client can be received. The first remote access request is used to request access to a remote service in a second client. If the connection between the information transmission system and the second client is determined through a management channel between the management system and the second client, a first forwarding channel is established between a first session port and a bridging port based on the first remote access request. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the communication port between the communication system and the management system in the information transmission system. Then, a first instruction is sent to the second client through the first session port. The first instruction carries channel information of the first forwarding channel and is used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system and the second client. If a response information corresponding to the remote service is received from the second client through the first session port, a remote connection instruction is sent to the first client. The response information is obtained by the second client through the second forwarding channel. The remote connection instruction carries information related to the response information and is used to instruct the first client to display information related to the response information. By introducing a management system and a communication system, and eliminating the P2P negotiation server in the existing solution, a management channel can be established between the management system and the second client after the second client starts. Upon receiving the first remote access request from the first client and confirming the connection between the information transmission system and the second client, a first forwarding channel is established in the information transmission system, and a second forwarding channel is established in the second client. Then, a remote access channel is established between the first client, the second client, the management system, and the communication system through the first and second forwarding channels. Since the first and second forwarding channels are disconnectable, the two clients can actively disconnect these two forwarding channels based on their actual communication situation. This ensures information communication between the first and second clients while guaranteeing the rational utilization of ports and communication resources, improving the performance of the transmission system, and ultimately ensuring the stable operation of the information transmission system. Attached Figure Description

[0020] Figure 1 This is a schematic diagram of the structure of an information transmission system provided in an embodiment of this application;

[0021] Figure 2 A flowchart illustrating an information transmission method provided in an embodiment of this application;

[0022] Figure 3 A flowchart illustrating the establishment of a management channel in an information transmission method provided in this application embodiment;

[0023] Figure 4A flowchart illustrating the establishment of a forwarding channel in an information transmission method provided in this application embodiment;

[0024] Figure 5 This is one of the flowcharts for forwarding channel reclamation in an information transmission method provided in this application embodiment;

[0025] Figure 6 This is the second flowchart of a forwarding channel recovery process in an information transmission method provided in this application embodiment;

[0026] Figure 7 This is a schematic diagram of the structure of an information transmission device provided in an embodiment of this application;

[0027] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;

[0028] Figure 9 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0029] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0030] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0031] The acquisition, storage, use, and processing of data (including but not limited to features and information mentioned in the text) in this application all comply with relevant national laws and regulations. To address the aforementioned technical problems, embodiments of this application provide an information transmission method, apparatus, computer equipment, and storage medium.

[0032] In related technologies, requesting clients and accessing clients can communicate via P2P intranet traversal VPN. The requesting client sends an access request to the P2P negotiation server to establish a communication relationship with the accessing client. The access request includes the requesting client's identification data, which is the unique identifier of the client. The P2P negotiation server negotiates and establishes a communication relationship between the requesting client and the accessing client based on the identification data of the requesting client and the accessing client, and generates the corresponding Internet Protocol (IP) port combination and sends it back to the requesting client and the accessing client. The requesting client and the accessing client each start their respective VPN programs based on their received IP port combinations to establish a communication channel for data exchange, thereby controlling the restriction that at least one party must have a public IP address when the two locations are connected to the network through VPN technology.

[0033] The above methods do not address scenarios involving a massive number of accessing clients. If a large number of IoT devices are used as accessing clients, and no channel usage is monitored after a connection is established between the requesting client and the accessing client, prolonged periods without data communication between clients will result in a significant waste of public network port resources on the negotiation server and the maintenance of numerous useless connections, impacting the system performance of the P2P negotiation server. Furthermore, the aforementioned methods do not consider a dynamic update mechanism for the accessing client's authentication key when establishing a remote access channel. In an IoT scenario, if the device authentication key, serving as the accessing client, is hijacked or cracked by attackers, it can easily lead to unauthorized impersonation devices accessing the communication system, as well as the leakage and unauthorized tampering of communication data.

[0034] To address the problems in related technologies, this application provides an information transmission method, apparatus, device, storage medium, and computer program product. It introduces a management system and a communication system, eliminating the negotiation server in the original solution. Thus, after the client device starts up, it first connects to the management system to establish a management channel. When the client requests remote access to local services through the management system, the management system sends remote access connection information, dynamic keys, and other parameters to the device through the management channel. A secure remote access channel is then established between the device, the communication system, and the management system. After the channel is established, the management system actively monitors the usage of the remote access channel. If the channel remains unused for an extended period, it actively disconnects, ensuring the rational use of ports and communication resources and guaranteeing stable system operation. This solves the performance issues related to communication resource utilization and reduces the data security risks associated with static key leakage.

[0035] Based on this, the following is in conjunction with the appendix Figures 1 to 6 The information transmission method provided in this application will be described in detail through specific embodiments and application scenarios.

[0036] First, combined Figure 1 This application provides a detailed description of an information transmission system according to an embodiment.

[0037] Figure 1 This is a schematic diagram of the structure of an information transmission system provided in an embodiment of this application.

[0038] like Figure 1 As shown, the information transmission system provided in this application embodiment may include a communication system and a management system. Based on this, the information transmission system in this application embodiment will be described in detail below in conjunction with the aforementioned two systems, the first client (which can be understood as a requesting client) and the second client (which can be understood as an accessing client).

[0039] The information transmission system, the first client, and the second client in this application embodiment may include the following information.

[0040] 1) IP address of the communication system: IP_tra

[0041] 2) The session port of the communication system, i.e., the first session port: Port_tra_tun

[0042] 3) Through the system's bridging port: Port_tra_bri_0

[0043] 4) The IP address of the second client device: IP_dev

[0044] 5) The session port of the second client device, i.e., the second session port: Port_dev_tun_0

[0045] 6) The port of the remote service A of the second client is the service port: Port_dev_srv_A

[0046] Based on this, the information transmission system and the first and second clients can perform the following process, as detailed below.

[0047] The first client can send a request to the management system to remotely access the remote service A of the second client.

[0048] The management system randomly generates a first session identifier (ID), a first session authentication key Ka, and a session encryption communication key Ke for this remote access session connection.

[0049] The management system sends the session ID and session authentication key Ka to the communication system through the HTTPS interface of the communication system.

[0050] The management system sends a command to the second client device to establish a remote access connection through the Message Queuing Telemetry Transport (MQTTS) management channel. The command carries information such as the first session ID, the first session authentication key Ka, the session encryption communication key Ke, the communication system session port address IP_tra:Port_tra_tun, and the service port Port_dev_srv_A.

[0051] After receiving the instruction, the second client device generates a random string P and calculates its hash value H. It then encrypts the random string with the session authentication key Ka to obtain its ciphertext C.

[0052] The second client initiates a second session connection request to the communication system session port address IP_tra:Port_tra_tun through the second session port address IP_dev:Port_dev_tun_0. The second session connection request carries the second session connection information, which includes the second session ID, the second hash value H of the second random string, and the ciphertext C of the random string.

[0053] When the communication system receives a second session connection request from a device, it extracts the second session ID and finds the associated session authentication key Ka locally. It decrypts the random string ciphertext C to obtain the plaintext P' and calculates its hash value H'. It verifies whether the hash value H' is equal to the received random string hash value H to verify the legitimacy of the device initiating the session. If it is not legitimate, it disconnects directly.

[0054] After the legitimacy verification is successful, the communication system internally maps the device-side session port address IP_dev:Port_dev_tun_0 to a bridging port Port_tra_bri_0 of the communication system, establishes the first forwarding channel of the communication system, and returns a connection success response and the bridging port Port_tra_bri_0 to the second client device.

[0055] After receiving the connection success message, the second client device maps the service port Port_dev_srv_A to the device-side second session port Port_dev_tun_0, establishes a device forwarding channel, and then returns the bridging port Port_tra_bri_0 to the management system through the MQTTS management channel.

[0056] After receiving the bridging port Port_tra_bri_0 returned by the second client device, the management system sends a request to the bridging port address IP_tra:Port_tra_bri_0 of the communication system to access the remote local service A of the second client device and encrypts the request data using the session encryption communication key Ke.

[0057] After receiving the request data from the management system, the communication system forwards the data to the device-side session port address IP_dev:Port_dev_tun_0 according to the port mapping relationship.

[0058] After receiving the request data forwarded from the communication system, the device decrypts the request data using the session encryption communication key Ke, and forwards the data to the port Port_dev_srv_A of local service A according to the port mapping relationship.

[0059] The device uses the session encryption communication key Ke to encrypt and return response data from local service A to the communication system.

[0060] After receiving the response data, the communication system forwards it to the management system.

[0061] After receiving the response data, the management system uses the session encryption communication key Ke to decrypt the response data and returns it to the first session port for display.

[0062] This completes the establishment of the device's local second forwarding channel and the entire process of a data request / response.

[0063] Therefore, in the communication process provided by this application embodiment, the device, communication system, and management system all hold the dynamically generated identity authentication key Ka bound to the connection channel of this remote access session. The device and management system also hold the dynamically generated data communication encryption and decryption key Ke, which can ensure the legitimacy of the identity of the device and local service participating in this remote access session, while ensuring communication security, preventing man-in-the-middle eavesdropping or tampering with the communication data content, and reducing the risk of key theft from the time dimension.

[0064] Furthermore, after the device's local second forwarding channel connection is established, the management system monitors the data packet transmission and reception volume in the remote access session connection channel in real time, identifies abnormal data packet volume, and comprehensively analyzes and judges the resource utilization and robustness of the session connection channel. If the channel is not used for a long time, or the frequency of abnormal data packets is high, the management system will send a command to terminate communication and enter the device's local second forwarding channel recycling process. In addition, by embedding a unified secure communication agent program, the differences between different types and models of devices are masked. After the agent program completes device adaptation, it can use the same set of processes to communicate with different adapted devices.

[0065] It should be noted that the information transmission method provided in this application embodiment can be applied to situations where a management system controls a device to establish a remote access channel by connecting to a communication system, enabling remote access to local device services. This can be extended to application scenarios such as accessing files within the device, modifying configurations, and transferring connections to external systems. Furthermore, this application embodiment can leverage the platform's on-demand device connection and secure communication methods to manage various types of devices in a one-stop manner, providing data acquisition and remote access to local services, effectively overcoming differences in device type and platform, and fully supporting all device functions. Secondly, combined with... Figure 2 This application provides a detailed description of an information transmission method based on an embodiment.

[0066] Figure 2 This is a flowchart of an information transmission method provided in an embodiment of this application.

[0067] like Figure 2 As shown, the information transmission method provided in this application embodiment can be applied to, for example... Figure 1 The information transmission system shown may include a management system and a communication system. Based on this, the information transmission method may include the following steps:

[0068] Step 210: Receive a first remote access request sent by the first client. The first remote access request is used to request access to a remote service in the second client. Step 220: If the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client, establish a first forwarding channel between a first session port and a bridging port based on the first remote access request. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the communication port between the communication system and the management system in the information transmission system. Step 230: Send a first instruction to the second client through the first session port. The first instruction carries channel information of the first forwarding channel and instructs the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system and the second client in the second client. The first and second forwarding channels are disconnectable channels. Step 240: If a response information corresponding to the remote service is received from the second client through the first session port, send a remote connection instruction to the first client. The response information is obtained by the second client through the second forwarding channel. The remote connection instruction carries information related to the response information and instructs the first client to display information related to the response information.

[0069] By introducing a management system and a communication system, and eliminating the P2P negotiation server in the existing solution, a management channel can be established between the management system and the second client after the second client starts. When the first remote access request sent by the first client is received and the connection between the information transmission system and the second client is confirmed, a first forwarding channel is established in the information transmission system and a second forwarding channel is established in the second client. Then, a remote access channel is established between the first client, the second client, the management system, and the communication system through the first and second forwarding channels. Since the first and second forwarding channels are disconnectable, the two clients can actively disconnect the aforementioned two forwarding channels according to the actual communication situation. While ensuring information communication between the first client and the second client, the rational use of ports and communication resources is guaranteed, the performance of the transmission system is improved, and thus the stable operation of the information transmission system is ensured.

[0070] In this embodiment, a client agent program can be used to securely communicate with the first client device, the second client device, and the management system and communication system. A software and hardware compatible agent program version is adapted for different IoT devices and installed into the device. This aims to solve the problem of resource waste in the communication process and reduce the risks of counterfeit devices accessing the communication system, communication data leakage, and illegal tampering.

[0071] Based on this, the embodiments of this application include three steps: establishing a device management channel, establishing a device remote access channel, and reclaiming a device remote access channel, as detailed below.

[0072] The steps described above are explained in detail below.

[0073] First, regarding step 220, in some embodiments of this application, before establishing a first forwarding channel between a first session port and a bridge port based on a first remote access request, a process of establishing a management channel may also be included. Based on this, before step 220, the information transmission method provided in the embodiments of this application may also include steps 2501 to 2503.

[0074] Step 2501: Generate the first service access device authentication information based on the first identity information of the registered client.

[0075] Step 2502: Upon receiving a connection request sent by the second client, in which the connection request carries the authentication information of the second service access device, the authentication information of the second service access device is verified based on the authentication information of the first service access device to obtain the information verification result. The authentication information of the second service access device is determined by the second identity information of the second client.

[0076] Step 2503: If the information verification result indicates that the authentication information of the second service access device has been verified, establish a management channel between the management system and the second client.

[0077] For example, such as Figure 3 As shown, after the second client device powers on, it starts the agent program. The program automatically connects to the management system using the MQTTS protocol, establishing a management channel between the device and the management system. The specific implementation process for establishing the management channel is as follows: The device ID (MAC address) is registered in the management system. MQTTS service access device authentication information is generated using a specific encryption algorithm and submitted to the MQTTS service within the management system. The device starts the agent program, generates the MQTTS service access device authentication information using the same method, and initiates an authentication and connection request to the MQTTS service. The MQTTS service compares the device ID with the MQTTS service access device authentication information. If the authentication information is inconsistent, it returns relevant error information and refuses the connection. Otherwise, the MQTTS service accepts the device connection and establishes the management channel, while simultaneously pushing a device online message to the device management service within the management system. At this point, the device management channel is established, and the management command issuance and response channel between the device and the management system is opened.

[0078] Therefore, the MQTTS-based device connection protocol is simple, easy to implement, and provides a more stable connection, allowing for real-time monitoring of the device's connection status.

[0079] In some embodiments of this application, the connection between the information transmission system and the second client can be determined by the following steps. Based on this, before step 120, the information transmission method provided in the application embodiment may also include steps 2601 to 2604.

[0080] Step 2601: Based on the first remote access request, generate first session connection information, which includes a first session identifier and a first session authentication key.

[0081] Step 2602: Send an authentication command to the second client through the management channel. The authentication command carries the first session connection information and the first port information of the first session port. The authentication command is used to instruct the second client to generate second session connection information based on the first session connection information and the first port information.

[0082] Step 2603: Upon receiving the second session connection information sent by the first client based on the first port information through the first session port, authenticate the second client based on the second session connection information and generate an authentication result.

[0083] Step 2604: If the authentication result indicates that the second client's authentication is successful, determine that the information transmission system is connected to the second client.

[0084] Specifically, the second session connection information in this application embodiment includes a second session identifier, a first hash value, and a random string ciphertext. The first hash value is the hash value corresponding to the first random string generated by the second client based on the remote access connection instruction. The random string ciphertext is obtained by encrypting the first random string with the first session authentication key. Based on this, the above step 2603 may specifically include steps 26031 to 26034.

[0085] Step 26031: Based on the second session identifier, obtain the second session identity authentication key corresponding to the second session identifier.

[0086] Step 26032: Decrypt the random string ciphertext using the second session authentication key to obtain the second random string.

[0087] Step 26033: Calculate the second hash value corresponding to the second random string based on the second random string.

[0088] Step 26034: Generate an authentication result based on the matching result of the first hash value and the second hash value.

[0089] Furthermore, the authentication result in this embodiment includes a first authentication result or a second authentication result. The first authentication result indicates that the second client has passed authentication, and the second authentication result indicates that the second client has failed authentication. Based on this, step 26034 may specifically include:

[0090] If the first hash value and the second hash value match, a first authentication result is generated.

[0091] For example, such as Figure 4 As shown, if the first authentication result is obtained, the step of determining the connection between the information transmission system and the second client can be executed.

[0092] If the first hash value and the second hash value do not match, a second authentication result is generated.

[0093] For example, such as Figure 5 As shown, after generating the second authentication result, a failure reason, i.e. authentication failure, can be sent to the device of the first client to prompt the user to request again.

[0094] Based on this, step 220 may specifically include steps 2201 and 2202.

[0095] Step 2201: Based on the first remote access request, obtain the third port information of the second session port corresponding to the first session port in the second client.

[0096] Step 2202: Map the third port information to the bridge port and establish the first forwarding channel.

[0097] Therefore, device connections are built on demand, and the communication and management systems are equipped with channel monitoring and analysis programs. If the device is not used for a long time, the system will issue a disconnect command to the device to disconnect the relevant connections and reclaim resources in a timely manner, thereby improving the effective utilization rate of system resources.

[0098] Furthermore, regarding step 230, in some embodiments of this application, a second local forwarding channel is established on the device, i.e., the establishment of the second forwarding channel. After the first client device initiates a remote access request to the second client device through the management system, the management system sends a connection instruction and related parameters to the device through the management channel. After receiving the instruction, the second client device parses the instruction content and establishes a remote access connection channel with the corresponding communication system. After the connection is established, the communication system returns access information to the device, and the device reports the access information to the management system through the management channel. The management system opens a remote access link to indirectly access the device's local services through the communication system based on the access information, thereby enabling the user to remotely access the device's local services.

[0099] Then, regarding step 240, in some embodiments of this application, the channel information of the first forwarding channel includes the fourth port information of the bridging port; the first session connection information includes the session encryption communication key. Based on this, before step 240, the information transmission method may also include steps 2701 to 2704.

[0100] Step 2701: Receive feedback information from the second client corresponding to the first instruction via the management channel. The feedback information includes the fourth port information of the bridging port and is used to indicate that the second client has established a second forwarding channel.

[0101] Step 2702: Based on the feedback information, generate access request information for accessing remote services.

[0102] Step 2703: Encrypt the access request information using the session encryption communication key to obtain encrypted request information.

[0103] Step 2704: Based on the first forwarding channel, send a second remote access request to the second session interface of the second client. The second remote access request carries encrypted request information. The second remote access request is used to request the second client to obtain the original response information corresponding to the remote service from the service port based on the second forwarding channel, and to encrypt the original response information using the session encryption communication key to obtain the response information.

[0104] Therefore, the communication channel uses dynamic keys to achieve communication identity authentication and communication data encryption and decryption, reducing the security risks caused by key leakage.

[0105] Based on this, the information related to the response information includes the original response information, and step 240 may specifically include steps 2401 to 2403.

[0106] Step 2401: Upon receiving the response information corresponding to the remote service sent by the second client through the first session port, the response information is decrypted using the session encryption communication key to obtain the original response information.

[0107] Step 2402: Generate a remote connection command based on the original response information.

[0108] Step 2403: Send a remote connection command to the first client.

[0109] The local second forwarding channel of the recycling equipment is divided into two situations: user-controlled recycling and management system-controlled recycling. These will be explained separately below.

[0110] In some embodiments provided in this application, the information transmission method in this application may further include step 2801.

[0111] Step 2801: Disconnect the first forwarding channel and send a connection disconnect command to the second client through the management channel. The connection disconnect command is used to instruct the second client to disconnect the second forwarding channel.

[0112] For example, such as Figure 6 As shown, users can actively reclaim remote access connection channels. After completing device access, users can initiate the termination of the communication process and release the access connection channel and related resources through management system operations (disconnecting / closing the browser, etc.). The management system sends a command to the device to disconnect the local service remote access session connection channel via the management channel. The device executes the command to disconnect the session connection with the communication system, releases the mapping relationship between the session port and the local service, and the dynamic key bound to the session, and returns the command response result to the management system via the management channel. The management system then sends a command to the communication system to disconnect the device's local service remote access connection channel. The communication system executes the command, releases the internal port mapping relationship and the dynamic key bound to the connection channel, reclaims port resources, clears buffered data, and returns the command response result to the management system. After completing the above two processing results, the management system releases and maintains the related resources and dynamic key of the device's local service remote access connection channel.

[0113] In some other embodiments provided in this application, the information transmission method may further include steps 2802 and 2803 before step 2801.

[0114] Step 2802: Obtain the transmission data of the management channel between the management system and the second client. The transmission data includes at least one of the following: the connection duration of the management channel and the frequency of abnormal data packets.

[0115] Step 2803: If the transmitted data meets the preset conditions, disconnect the first forwarding channel and send a connection disconnection command to the second client through the management channel.

[0116] For example, such as Figure 6 As shown, the management system automatically reclaims remote access connection channels. When the management system analyzes and identifies that a remote access connection channel has not been used for a long time or has a high frequency of abnormal data packets, it proactively initiates a request to disconnect the remote access connection channel to the device and communication system. This process is consistent with the process of proactively ending the communication flow and releasing the access connection channel and related resources when the user proactively reclaims the remote access connection channel.

[0117] Therefore, the described device connection and secure access method, after device adaptation and system compatibility processing, can achieve unified connection and access for all connected devices, and has built-in device authentication and secure communication capabilities to ensure that device communication data is legal and valid.

[0118] Thus, this application embodiment provides a method for device communication and external access to local services, introducing the lightweight, easy-to-implement, and simple open MQTTS communication protocol for device connection, and providing a solution for on-demand use and timely resource reclamation, aiming to maximize the use of limited resources to provide high-quality services while ensuring communication security. A method for establishing a remote access connection for a terminal device's local services and secure communication: After receiving a remote access connection command for local services, the device establishes a secure connection with the corresponding communication system according to the command parameters. After successful connection, the acquired connection information is reported to the management system, which automatically opens the corresponding connection information to enable remote access to the device's local services. During communication, a dynamic key bound to the connection session is used for communication authentication and encryption / decryption of communication data; A low-power, high-stability device connection method: During idle periods of the device's local service, there is no need to establish a persistent long-term business connection with the access side; the lightweight MQTTS protocol is used to keep the device online and maintain the communication channel; A method for efficient use of IT resources through communication monitoring: The device's remote access channel is only established when the user needs to use it. After the connection is established, the communication system continuously listens and reports, and the management system continuously analyzes the communication status. Resources should be promptly reclaimed when a connection experiences prolonged periods without communication services or when the communication failure rate is too high.

[0119] It should be noted that the examples described in this application are only one application scenario in this application, and not all examples. All other examples obtained by those skilled in the art based on the examples in this application without creative effort are within the protection scope of this application.

[0120] The information transmission method provided in this application can be executed by an information transmission device. This application uses an information transmission device to perform information transmission as an example to illustrate the apparatus of the information transmission method provided in this application.

[0121] Based on the same inventive concept, this application also provides an information transmission device. (Specifically combined with...) Figure 7 Please provide a detailed explanation.

[0122] Figure 7 This is a schematic diagram of the structure of an information transmission device provided in an embodiment of this application.

[0123] like Figure 7 As shown, the information transmission device 70 can be applied to an information transmission system, which includes a management system and a communication system. Specifically, the information transmission device 70 may include:

[0124] The receiving module 701 is used to receive a first remote access request sent by the first client, the first remote access request being used to request access to a remote service in the second client;

[0125] Module 702 is used to establish a first forwarding channel between a first session port and a bridging port based on a first remote access request when the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the communication port between the communication system and the management system in the information transmission system.

[0126] The transceiver module 703 is used to send a first instruction to the second client through the first session port. The first instruction carries the channel information of the first forwarding channel. The first instruction is used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system in the second client and the second client. The first forwarding channel and the second forwarding channel are disconnectable channels.

[0127] The transceiver module 703 is also used to send a remote connection instruction to the first client when it receives a response information corresponding to the remote service sent by the second client through the first session port. The response information is obtained by the second client through the second forwarding channel. The remote connection instruction carries information related to the response information and is used to instruct the first client to display information related to the response information.

[0128] The information transmission device 70 in the embodiments of this application will be described in detail below.

[0129] In some embodiments of this application, the information transmission device 70 may further include a generation module and a verification module; wherein,

[0130] The generation module is used to generate the first service access device authentication information based on the first identity information of the registered client;

[0131] The verification module is used to verify the authentication information of the second service access device based on the first service access device authentication information when receiving a connection request sent by the second client, and the connection request carries the authentication information of the second service access device. The verification result is obtained by the second identity information of the second client.

[0132] The module 702 can also be used to establish a management channel between the management system and the second client when the information verification result indicates that the authentication information of the second service access device has been verified.

[0133] In some embodiments of this application, the information transmission device 70 may further include a generation module and a determination module; wherein,

[0134] The generation module is used to generate first session connection information based on the first remote access request. The first session connection information includes a first session identifier and a first session authentication key.

[0135] The transceiver module 703 can also be used to send an authentication command to the second client through the management channel. The authentication command carries the first session connection information and the first port information of the first session port. The authentication command is used to instruct the second client to generate second session connection information based on the first session connection information and the first port information.

[0136] The transceiver module 703 can also be used to authenticate the second client and generate an authentication result based on the second session connection information when it receives second session connection information sent by the first client based on the first port information through the first session port.

[0137] The determination module is used to determine the connection between the information transmission system and the second client if the authentication result indicates that the authentication of the second client is successful.

[0138] In some embodiments of this application, the information transmission device 70 may further include an acquisition module, a decryption module, a calculation module, and a generation module; wherein,

[0139] The acquisition module is used to obtain the second session authentication key corresponding to the second session identifier based on the second session identifier when the second session connection information includes the second session identifier, the first hash value and the random string ciphertext, the first hash value being the hash value corresponding to the first random string generated by the second client based on the remote access connection command, and the random string ciphertext being the first random string encrypted with the first session authentication key.

[0140] The decryption module is used to decrypt the ciphertext of the random string using the second session authentication key to obtain the second random string;

[0141] The calculation module is used to calculate the second hash value corresponding to the second random string.

[0142] The generation module is used to generate authentication results based on the matching results of the first hash value and the second hash value.

[0143] In some embodiments of this application, the generation module can be specifically used to generate a first authentication result if the first hash value and the second hash value match, and to generate a second authentication result if the authentication result includes a first authentication result or a second authentication result, wherein the first authentication result indicates that the second client has been authenticated and the second authentication result indicates that the second client has not been authenticated; and to generate a second authentication result if the first hash value and the second hash value do not match.

[0144] In some embodiments of this application, the information transmission device 70 may further include an acquisition module, which is used to acquire third port information of the second session port corresponding to the first session port in the second client based on the first remote access request;

[0145] The module 702 can also be used to map third port information to a bridge port and establish a first forwarding channel.

[0146] In some embodiments of this application, the information transmission device 70 may further include a generation module and an encryption module; wherein,

[0147] The receiving module 701 can also be used to receive feedback information corresponding to the first instruction sent by the second client through the management channel when the channel information of the first forwarding channel includes the fourth port information of the bridge port and the first session connection information includes the session encryption communication key. The feedback information includes the fourth port information of the bridge port and is used to indicate that the second client has established the second forwarding channel.

[0148] The generation module is used to generate access request information for remote services based on feedback information.

[0149] The encryption module is used to encrypt the access request information using the session encryption communication key to obtain the encrypted request information;

[0150] The transceiver module 703 can also be used to send a second remote access request to the second session interface of the second client according to the first forwarding channel. The second remote access request carries encrypted request information. The second remote access request is used to request the second client to obtain the original response information corresponding to the remote service from the service port based on the second forwarding channel, and to encrypt the original response information through the session encryption communication key to obtain the response information.

[0151] In some embodiments of this application, the information transmission device 70 may further include a decryption module and a generation module; wherein,

[0152] The decryption module is used to decrypt the response information using the session encryption communication key to obtain the original response information when the information related to the response information includes the original response information and the response information corresponding to the remote service sent by the second client is received through the first session port.

[0153] The generation module is used to generate remote connection instructions based on the original response information;

[0154] The transceiver module 703 can also be used to send remote connection commands to the first client.

[0155] In some embodiments of this application, the information transmission device 70 may further include a disconnection module for disconnecting the first forwarding channel and sending a connection disconnection command to the second client via a management channel. The connection disconnection command is used to instruct the second client to disconnect the second forwarding channel.

[0156] In some embodiments of this application, the information transmission device 70 may further include an acquisition module and a disconnection module; wherein,

[0157] The acquisition module is used to acquire the transmission data of the management channel between the management system and the second client. The transmission data includes at least one of the following: the connection duration of the management channel and the frequency of abnormal data packets.

[0158] The disconnect module is used to disconnect the first forwarding channel and send a connection disconnect command to the second client through the management channel when the transmitted data meets the preset conditions.

[0159] The information transmission device in this application embodiment can be an electronic device or a component within an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices besides a terminal. For example, the electronic device can be a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. It can also be a server, network attached storage (NAS), personal computer (PC), television set (TV), ATM, or self-service machine, etc. This application embodiment does not specifically limit the device.

[0160] The information transmission device in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit the specific operating system used.

[0161] The device coordination apparatus provided in this application embodiment can achieve... Figures 1 to 6 The various processes implemented in the information transmission method embodiments shown achieve the same technical effect, and will not be described again here to avoid repetition.

[0162] Based on this, the information transmission device provided in this application embodiment can be used to: receive a first remote access request sent by a first client, the first remote access request being used to request access to a remote service in a second client; when the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client, based on the first remote access request, establish a first forwarding channel between a first session port and a bridging port, the first session port being the session port between the communication system and the second client in the information transmission system, and the bridging port being the communication port between the communication system and the management system in the information transmission system; then, send a first instruction to the second client through the first session port, the first instruction carrying channel information of the first forwarding channel, the first instruction being used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information, the second session port being the session port between the communication system and the second client in the second client; when a response information corresponding to the remote service is received from the second client through the first session port, send a remote connection instruction to the first client, the response information being obtained by the second client through the second forwarding channel, the remote connection instruction carrying information related to the response information, the remote connection instruction being used to instruct the first client to display information related to the response information. By introducing a management system and a communication system, and eliminating the P2P negotiation server in the existing solution, a management channel can be established between the management system and the second client after the second client starts. When the first remote access request sent by the first client is received and the connection between the information transmission system and the second client is confirmed, a first forwarding channel is established in the information transmission system and a second forwarding channel is established in the second client. Then, a remote access channel is established between the first client, the second client, the management system, and the communication system through the first and second forwarding channels. Since the first and second forwarding channels are disconnectable, the two clients can actively disconnect the aforementioned two forwarding channels according to the actual communication situation. While ensuring information communication between the first client and the second client, the rational use of ports and communication resources is guaranteed, the performance of the transmission system is improved, and thus the stable operation of the information transmission system is ensured.

[0163] Optional, such as Figure 8 As shown, this application embodiment also provides an electronic device 80, including a processor 801 and a memory 802. The memory 802 stores a program or instructions that can run on the processor 801. When the program or instructions are executed by the processor 801, they implement the various steps of the above-described information transmission method embodiment and can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0164] It should be noted that the electronic devices in this application embodiment include the aforementioned mobile electronic devices and non-mobile electronic devices. Specifically, the electronic devices can be the rescuer's equipment, the victim's equipment, and the equipment housing the information transmission system.

[0165] Figure 9 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application.

[0166] The electronic device 900 includes, but is not limited to, components such as: radio frequency unit 901, network module 902, audio output unit 903, input unit 904, sensor 905, display unit 906, user input unit 907, interface unit 908, memory 909, and processor 910.

[0167] Those skilled in the art will understand that the electronic device 900 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 910 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 9 The electronic device structure shown does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0168] It should be understood that the input unit 904 may include a graphics processing unit (GPU) 9041 and a microphone 9042. The GPU 9041 processes image data of still images or videos acquired by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 906 may include a display panel, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 907 includes at least one of a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 may include two parts: a touch detection device and a touch display. Other input devices 9072 may include, but are not limited to, a physical keyboard, function keys (such as volume display buttons, power buttons, etc.), a trackball, a mouse, and a joystick, which will not be described in detail here.

[0169] The memory 909 can be used to store software programs and various data. The memory 909 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 909 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 909 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.

[0170] Processor 910 may include one or more processing units; optionally, processor 910 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless display signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 910.

[0171] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described information transmission method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.

[0172] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0173] In addition, this application embodiment provides another chip, which includes a processor and a display interface. The display interface and the processor are coupled. The processor is used to run programs or instructions to implement the various processes of the above-described information transmission method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0174] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0175] This application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the information transmission method embodiments described above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0176] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0177] Furthermore, it should be noted that the scope of the methods and apparatus in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. In addition, features described with reference to certain examples may be combined in other examples.

[0178] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a distressed device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0179] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. An information transmission method, characterized in that, Applied to an information transmission system, the information transmission system including a management system and a communication system, including: Receive a first remote access request sent by a first client, the first remote access request being used to request access to a remote service in a second client; When the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client, a first forwarding channel is established between a first session port and a bridging port based on the first remote access request. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the communication port between the communication system and the management system in the information transmission system. A first instruction is sent to the second client through the first session port. The first instruction carries the channel information of the first forwarding channel. The first instruction is used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system in the second client and the second client. The first forwarding channel and the second forwarding channel are disconnectable channels. Upon receiving response information corresponding to the remote service from the second client via the first session port, a remote connection instruction is sent to the first client. The response information is obtained by the second client through the second forwarding channel. The remote connection instruction carries information related to the response information and is used to instruct the first client to display information related to the response information.

2. The method according to claim 1, characterized in that, Before establishing the first forwarding channel between the first session port and the bridge port based on the first remote access request, the method further includes: Generate the first service access device authentication information based on the registered client's primary identity information; When receiving a connection request sent by the second client, in which the connection request carries the authentication information of the second service access device, the authentication information of the second service access device is verified according to the authentication information of the first service access device to obtain an information verification result. The authentication information of the second service access device is determined by the second identity information of the second client. If the information verification result indicates that the authentication information of the second service access device has been verified, a management channel is established between the management system and the second client.

3. The method according to claim 1 or 2, characterized in that, The method further includes: Based on the first remote access request, first session connection information is generated, which includes a first session identifier and a first session authentication key. Through the management channel, an authentication command is sent to the second client. The authentication command carries the first session connection information and the first port information of the first session port. The authentication command is used to instruct the second client to generate second session connection information based on the first session connection information and the first port information. Upon receiving second session connection information sent by the first client based on the first port information through the first session port, the second client is authenticated according to the second session connection information, and an authentication result is generated. If the authentication result indicates that the second client's authentication is successful, it is determined that the information transmission system is connected to the second client.

4. The method according to claim 3, characterized in that, The second session connection information includes a second session identifier, a first hash value, and a random string ciphertext. The first hash value is the hash value corresponding to the first random string generated by the second client based on the remote access connection instruction. The random string ciphertext is obtained by encrypting the first random string with the first session authentication key. The step of authenticating the second client based on the second session connection information and generating an authentication result includes: Based on the second session identifier, obtain the second session identity authentication key corresponding to the second session identifier; The second random string is obtained by decrypting the ciphertext of the random string using the second session authentication key. Based on the second random string, calculate the second hash value corresponding to the second random string; An authentication result is generated based on the matching result of the first hash value and the second hash value.

5. The method according to claim 4, characterized in that, The authentication result includes a first authentication result or a second authentication result, wherein the first authentication result indicates that the second client has been authenticated, and the second authentication result indicates that the second client has not been authenticated; The generation of authentication results based on the matching result of the first hash value and the second hash value includes: If the first hash value and the second hash value match, the first authentication result is obtained; If the first hash value and the second hash value do not match, the second authentication result is obtained.

6. The method according to claim 1, characterized in that, The step of establishing a first forwarding channel between a first session port and a bridge port based on the first remote access request includes: Based on the first remote access request, obtain the third port information of the second session port in the second client that corresponds to the first session port; The third port information is mapped to the bridge port to establish the first forwarding channel.

7. The method according to claim 3, characterized in that, The channel information of the first forwarding channel includes the fourth port information of the bridging port; the first session connection information includes the session encryption communication key; Before sending a remote connection command to the first client after receiving the response information corresponding to the remote service from the second client through the first session port, the method further includes: Through the management channel, feedback information corresponding to the first instruction sent by the second client is received. The feedback information includes the fourth port information of the bridging port. The feedback information is used to indicate that the second client has established the second forwarding channel. Based on the feedback information, an access request for accessing the remote service is generated; The access request information is encrypted using the session encryption communication key to obtain encrypted request information; According to the first forwarding channel, a second remote access request is sent to the second session interface of the second client. The second remote access request carries the encrypted request information. The second remote access request is used to request the second client to obtain the original response information corresponding to the remote service from the service port based on the second forwarding channel, and to encrypt the original response information using the session encryption communication key to obtain the response information.

8. The method according to claim 7, characterized in that, The information related to the response information includes the original response information; Upon receiving the response information corresponding to the remote service sent by the second client through the first session port, the step of sending a remote connection instruction to the first client includes: Upon receiving the response information corresponding to the remote service sent by the second client through the first session port, the response information is decrypted using the session encryption communication key to obtain the original response information; Based on the original response information, the remote connection command is generated; Send a remote connection command to the first client.

9. The method according to claim 1, characterized in that, The method further includes: The management channel disconnects the first forwarding channel and sends a connection disconnection command to the second client, the connection disconnection command being used to instruct the second client to disconnect the second forwarding channel.

10. The method according to claim 9, characterized in that, Before disconnecting the first forwarding channel and sending a connection disconnection command to the second client via the management channel, the method further includes: The system acquires the transmission data of the management channel between the management system and the second client, the transmission data including at least one of the following: the connection duration of the management channel and the frequency of abnormal data packets; If the transmitted data meets the preset conditions, the first forwarding channel is disconnected and a connection disconnection command is sent to the second client through the management channel.

11. An information transmission device, characterized in that, Applied to an information transmission system, the information transmission system including a management system and a communication system, including: The receiving module is used to receive a first remote access request sent by a first client, wherein the first remote access request is used to request access to a remote service in a second client; A module is established to establish a first forwarding channel between a first session port and a bridging port based on the first remote access request, when the connection between the information transmission system and the second client is determined through the management channel between the management system and the second client. The first session port is the session port between the communication system and the second client in the information transmission system, and the bridging port is the communication port between the communication system and the management system in the information transmission system. The transceiver module is used to send a first instruction to the second client through the first session port. The first instruction carries the channel information of the first forwarding channel. The first instruction is used to instruct the second client to establish a second forwarding channel between the second session port and the service port of the remote service based on the channel information. The second session port is the session port between the communication system in the second client and the second client. The first forwarding channel and the second forwarding channel are disconnectable channels. The transceiver module is further configured to, upon receiving response information corresponding to the remote service sent by the second client through the first session port, send a remote connection instruction to the first client, wherein the response information is obtained by the second client through the second forwarding channel, the remote connection instruction carries information related to the response information, and the remote connection instruction is used to instruct the first client to display information related to the response information.

12. A computer device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the information transmission method as described in any one of claims 1-10.

13. A computer program product, characterized in that, The program product is stored in a non-transient storage medium, and the program product is executed by at least one processor to implement the steps of the information transmission method as described in any one of claims 1-10.

Citation Information

Patent Citations

  • Device management client and server, and device management methods

    CN106411580A

  • method for realizing automatic access and roll-out of EOS node by accessing TCD cluster

    CN109600263A