Intranet service management system and method

By designing an intranet service management system, using the combination of intranet penetration server, client and proxy, the port restriction problem of existing intranet penetration tools when managing a large number of intranet devices is solved, and flexible management and expansion of intranet device services are realized.

CN119484471BActive Publication Date: 2025-05-09BEIJING TINGYU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510045404.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-09
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

When existing intranet penetration tools manage service calls to a large number of intranet devices, they cannot effectively distinguish new devices and services, resulting in a limited number of available ports on public network IP, making it difficult to achieve flexible management of intranet devices.

Method used

Design an intranet service management system, including an intranet penetration server deployed on public network IP, an intranet penetration client deployed on intranet devices, and a proxy. The user's intranet service access request is obtained through the proxy, and send it to the intranet penetration server through the proxy protocol. The latter parses the request and establishes a communication connection with the intranet nodes to realize unified management of intranet device services.

Benefits of technology

This system can quickly map services of a large number of intranet devices to the public network, realize horizontal expansion of intranet nodes and increase convenient services to nodes, avoiding management difficulties caused by port restrictions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484471B_ABST
    Figure CN119484471B_ABST
Patent Text Reader

Abstract

The present invention provides an intranet service management system and method, wherein the system includes: an intranet penetration service end deployed on a public network IP, an intranet penetration client end deployed on an intranet device, and an agent end; the agent end is connected to a user client end for communication, and is used to obtain an intranet service access request from the user client end, and sends the intranet service access request to the intranet penetration service end in the form of a proxy protocol; the intranet penetration service end is used to obtain a proxy protocol from the agent end, and parse the proxy protocol, determine the intranet node and node service to be accessed, and establish a communication connection with the intranet node through the intranet penetration client end; the intranet penetration client end is used to provide the user client end with the node service corresponding to the intranet node. Through the present invention, it is possible to quickly map the node services of a large number of intranet devices to the public network for unified management, and to achieve convenient services for intranet nodes when horizontally expanding and adding nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet communication technology, and in particular to an intranet service management system and method. Background Art

[0002] Since intranet devices do not have public network addresses, services deployed in the intranet need to be mapped to the public Internet through a third-party intranet penetration tool. Intranet penetration is also called NAT penetration, which is the connection communication required when the external network connects to the computer node of the intranet when the computer to be accessed is a local area network. The mapping mechanism of the existing mainstream intranet penetration tools is: open a port on the public network IP, each port corresponds to a service of an intranet machine. When multiple services are opened on the same intranet machine or multiple intranet machines need to provide services, multiple ports need to be opened on the public network IP. If the same port is used, it will be impossible to distinguish the nodes and services to be accessed. In other words, when adding new services or adding new intranet devices, you will face the following problems:

[0003] 1) Access to new services requires mapping new ports on the intranet penetration tool;

[0004] 2) Intranet penetration tools cannot distinguish new intranet devices from other devices.

[0005] In simple usage scenarios, this method can easily meet the needs. However, if there are more than 10,000 intranet devices to be managed and multiple services need to be mapped externally, the number of available ports on the public IP is fixed, and this method is somewhat insufficient. Summary of the invention

[0006] To this end, the present invention provides an intranet service management system and method, aiming to solve the technical problem that the prior art cannot manage the service calls of a large number of intranet devices.

[0007] To achieve the above objectives, the present invention adopts the following technical solutions:

[0008] According to a first aspect of the present invention, the present invention provides an intranet service management system, the system comprising: an intranet penetration server deployed on a public network IP, an intranet penetration client and an agent deployed on an intranet device;

[0009] The proxy terminal is connected to the user client for communication, and is used to obtain an intranet service access request from the user client, and send the intranet service access request to the intranet penetration server terminal in the form of a proxy protocol;

[0010] The intranet penetration server is used to obtain the proxy protocol from the proxy, parse the proxy protocol, determine the intranet node and node service that need to be accessed, and establish a communication connection with the intranet node through the intranet penetration client;

[0011] The intranet penetration client is used to provide the user client with the node service corresponding to the intranet node.

[0012] Optionally, the proxy terminal adopts a proxy server based on the sock5 protocol.

[0013] Optionally, the intranet penetration server is provided with an external unified service port, and is connected to the proxy terminal through the unified service port;

[0014] The proxy end is also used to obtain an intranet service access request carrying the intranet node and node service that need to be accessed, and send the intranet node and the node service to the intranet penetration server end through a proxy of the sock5 protocol.

[0015] Optionally, the intranet penetration server is also used to parse the username field in the sock5 protocol to obtain the intranet node and node service that need to be accessed.

[0016] Optionally, the intranet penetration client is further used to generate a unique identifier required for access for each intranet node;

[0017] The intranet penetration server is also used to simultaneously establish communication connections with multiple intranet nodes through the intranet penetration client.

[0018] Optionally, the intranet penetration client is further used to map the node service corresponding to the intranet node to the intranet penetration server;

[0019] The intranet penetration server is used to provide the node service to the user client through the proxy.

[0020] According to a second aspect of the present invention, the present invention provides an intranet service management method, which is applied to an intranet penetration server deployed on a public network IP, an intranet penetration client deployed on an intranet device, and an agent; the agent adopts a proxy server based on the sock5 protocol, and is connected to the user server by communication; the intranet penetration server is provided with an external unified service port, and is connected to the agent by communication through the unified service port; the method comprises:

[0021] Obtaining an intranet service access request from a user client through the proxy terminal, and sending the intranet service access request to the intranet penetration server through a proxy protocol;

[0022] The proxy protocol from the proxy client is obtained through the intranet penetration server, and the proxy protocol is parsed to determine the intranet node and node service to be accessed, and a communication connection with the intranet node is established through the intranet penetration client;

[0023] Mapping the node service corresponding to the intranet node to the intranet penetration server by using the intranet penetration client;

[0024] The intranet penetration service end provides the node service to the user client through the proxy end.

[0025] Optionally, obtaining the intranet service access request from the user client through the proxy end, and sending the intranet service access request to the intranet penetration server through a proxy protocol includes:

[0026] The proxy terminal obtains an intranet service access request carrying the intranet node and node service that need to be accessed, and sends the intranet node and the node service to the intranet penetration server terminal through a proxy of the sock5 protocol.

[0027] Optionally, parsing the proxy protocol to determine the intranet nodes and node services that need to be accessed includes:

[0028] The intranet penetration server is used to parse the user name field in the sock5 protocol to obtain the intranet node and node service that need to be accessed.

[0029] Optionally, the method further comprises:

[0030] Using the intranet penetration client to generate a unique identifier required for access for each intranet node;

[0031] The intranet penetration server establishes communication connections with multiple intranet nodes simultaneously through the intranet penetration client.

[0032] The present invention adopts the above technical solution and has at least the following beneficial effects:

[0033] Through the scheme of the present invention, an intranet penetration server is deployed on the public network IP, an intranet penetration client is deployed on the intranet device, and a proxy terminal is established to communicate with the user client and the intranet penetration server respectively; the proxy terminal is used to obtain the intranet service access request from the user client, and send the intranet service access request to the intranet penetration server in the form of a proxy protocol; the intranet penetration server is used to obtain the proxy protocol from the proxy terminal, and parse the proxy protocol to determine the intranet node and node service that needs to be accessed, and establish a communication connection with the intranet node through the intranet penetration client; the intranet penetration client is used to provide the user client with the node service corresponding to the intranet node. In this way, a large number of intranet device services such as ssh, http, etc. can be quickly mapped to the public network for unified management. When adding a new intranet device, mapping the new intranet service only requires a simple update of the service configuration on the intranet device, thereby realizing a convenient service for horizontal expansion and adding nodes for intranet nodes.

[0034] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0036] Figure 1 A schematic diagram showing the structure of an intranet service management system provided by an embodiment of the present invention is shown;

[0037] Figure 2 A schematic diagram of the process of an intranet service management method provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0038] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0039] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "include..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0040] The embodiment of the present invention provides an intranet service management system, such as Figure 1 As shown, the system may include: an intranet penetration server 110 , an intranet penetration client 120 and a proxy 130 .

[0041] The intranet penetration server 110 is deployed on a public network IP, the intranet penetration client 120 is deployed on an intranet device, and the proxy 130 is respectively connected to the user client and the intranet penetration server 110 for communication.

[0042] The proxy terminal 130 is used to obtain the intranet service access request from the user client, and send the intranet service access request to the intranet penetration server 110 in the form of a proxy protocol; the intranet penetration server 110 is used to obtain the proxy protocol from the proxy terminal 130, and parse the proxy protocol to determine the intranet node and node service that needs to be accessed, and establish a communication connection with the intranet node through the intranet penetration client 120; the intranet penetration client 120 is used to provide the user client with the node service corresponding to the intranet node.

[0043] In the embodiment of the present invention, a proxy terminal 130 is set between the user client and the intranet penetration server 110. The user initiates an intranet service access request through the user client, and the proxy terminal 130, as an intermediate bridge, forwards the intranet service access request in the form of a proxy protocol. Optionally, the proxy terminal 130 can use a proxy server based on the sock5 protocol. Socks is an Internet protocol that exchanges network data between the user client and the intranet penetration server 110 through a proxy server.

[0044] Furthermore, the intranet penetration server 110 is provided with an external unified service port, and is connected to the proxy 130 through the unified service port. It is understandable that the intranet service access request from the user client carries the intranet node and the corresponding node service (http / ssh). Therefore, after obtaining the intranet service access request carrying the intranet node and the node service, the proxy 130 can send the intranet node and the node service to the intranet penetration server 110 through the proxy of the sock5 protocol.

[0045] It should be noted that 1. the sock5 protocol carries a user name for identifying intranet nodes and node services. The intranet penetration server 110 in the embodiment of the present invention is also used to obtain the proxy protocol, and then parses the user name field in the sock5 protocol to obtain the intranet nodes and node services that need to be accessed. After determining the intranet node, the intranet penetration client 120 can establish a connection with the intranet node to call the corresponding node service.

[0046] It should be noted that in order to achieve unlimited expansion of intranet devices, the same intranet device can map multiple node services to the outside. The intranet penetration client 120 in the embodiment of the present invention is also used to generate a unique identifier (uuid) required for access for each intranet node. Based on this, the intranet penetration server 110 can also be used to simultaneously establish a communication connection with multiple intranet nodes (uuid1, uuid2, ...) through the intranet penetration client 120.

[0047] Furthermore, after the intranet penetration server 110 establishes a connection with the intranet node, the intranet penetration client 120 can also be used to map the node service corresponding to the intranet node to the intranet penetration server 110; the intranet penetration server 110 is used to provide the node service to the user client through the proxy 130. Thus, the user can obtain the node service required in the intranet service access request through the user client.

[0048] The embodiment of the present invention provides an intranet service management system, including an intranet penetration service end deployed on a public network IP, an intranet penetration client end deployed on an intranet device, and an agent end; the agent end is connected to a user client end for communication, and is used to obtain an intranet service access request from the user client end, and sends the intranet service access request to the intranet penetration service end in the form of a proxy protocol; the intranet penetration service end is used to obtain a proxy protocol from the agent end, and parse the proxy protocol, determine the intranet node and node service to be accessed, and establish a communication connection with the intranet node through the intranet penetration client end; the intranet penetration client end is used to provide the user client end with a node service corresponding to the intranet node. Through the present invention, the identity authentication process of the sock5 protocol and the intranet penetration tool are combined, and multiple services can be automatically expanded based on the existing sock5 agent tool to support batch intranet devices; the node services of a large number of intranet devices can be quickly mapped to the public network for unified management, and convenient services can be realized for intranet nodes when horizontal expansion and node addition occur.

[0049] Furthermore, the embodiment of the present invention also provides a method for applying Figure 1 The intranet service management method of the intranet service management system shown includes steps S201 to S204:

[0050] Step S201, obtaining an intranet service access request from a user client through a proxy terminal, and sending the intranet service access request to an intranet penetration server through a proxy protocol;

[0051] Step S202, obtaining the proxy protocol from the proxy end through the intranet penetration server, parsing the proxy protocol, determining the intranet node and node service to be accessed, and establishing a communication connection with the intranet node through the intranet penetration client;

[0052] Step S203, mapping the node service corresponding to the intranet node to the intranet penetration server by using the intranet penetration client;

[0053] Step S204: the intranet penetration server provides node services to the user client through the proxy.

[0054] Among them, the intranet penetration server is deployed on the public network IP, the intranet penetration client is deployed on the intranet device, and the proxy end uses a proxy server based on the sock5 protocol to communicate with the user server. The intranet penetration server has a unified service port for external communication, and communicates with the proxy end through the unified service port.

[0055] Furthermore, the intranet service access request from the user client is obtained through the proxy end, and the intranet service access request is sent to the intranet penetration server through the proxy protocol. Specifically, the intranet service access request carrying the intranet node and node service that needs to be accessed can be obtained through the proxy end, and the intranet node and node service are sent to the intranet penetration server through the proxy of the sock5 protocol.

[0056] Furthermore, the proxy protocol is parsed to determine the intranet nodes and node services that need to be accessed. Specifically, the intranet penetration server can be used to parse the username field in the sock5 protocol to obtain the intranet nodes and node services that need to be accessed.

[0057] Furthermore, the embodiment of the present invention can also utilize the intranet penetration client to generate a unique identifier required for access for each intranet node; the intranet penetration server simultaneously establishes communication connections with multiple intranet nodes through the intranet penetration client.

[0058] It should be noted that the specific implementation of each step in the intranet service management method provided in the embodiment of the present invention can refer to Figure 1 The corresponding description of the functional modules in the shown system will not be repeated here.

[0059] Those skilled in the art can clearly understand that the specific working processes of the systems, devices, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and for the sake of brevity, they are not further described here.

[0060] In addition, the functional units in various embodiments of the present invention may be physically independent of each other, or two or more functional units may be integrated together, or all functional units may be integrated into one processing unit. The above integrated functional units may be implemented in the form of hardware, or in the form of software or firmware.

[0061] A person skilled in the art can understand that if the integrated functional unit is implemented in the form of software and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention can be essentially or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, which includes several instructions to enable a computing device (such as a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention when running the instructions. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program codes.

[0062] Alternatively, all or part of the steps of implementing the aforementioned method embodiments may be accomplished by hardware associated with program instructions (such as a computing device such as a personal computer, a server, or a network device), and the program instructions may be stored in a computer-readable storage medium. When the program instructions are executed by a processor of the computing device, the computing device executes all or part of the steps of the method described in the various embodiments of the present invention.

[0063] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that within the spirit and principles of the present invention, the technical solutions described in the aforementioned embodiments can still be modified, or some or all of the technical features therein can be replaced by equivalents. However, these modifications or replacements do not deviate from the protection scope of the present invention.

Claims

1. An intranet service management system, characterized in that: The system includes: an intranet penetration server deployed on a public network IP, an intranet penetration client and a proxy deployed on an intranet device; The proxy terminal is connected to the user client for communication, and is used to obtain an intranet service access request from the user client, and send the intranet service access request to the intranet penetration server terminal in the form of a proxy protocol; The intranet penetration server is used to obtain the proxy protocol from the proxy, parse the proxy protocol, determine the intranet node and node service that need to be accessed, and establish a communication connection with the intranet node through the intranet penetration client; The intranet penetration client is used to provide the user client with the node service corresponding to the intranet node; The proxy end adopts a proxy server based on the sock5 protocol; The intranet penetration server is provided with an external unified service port, and is connected to the proxy terminal through the unified service port; The proxy end is also used to obtain an intranet service access request carrying the intranet node and node service that need to be accessed, and send the intranet node and the node service to the intranet penetration server end through a proxy of the sock5 protocol.

2. The system according to claim 1, characterized in that The intranet penetration server is also used to parse the username field in the sock5 protocol to obtain the intranet node and node service that need to be accessed.

3. The system according to claim 1, characterized in that The intranet penetration client is also used to generate a unique identifier required for access for each intranet node; The intranet penetration server is also used to simultaneously establish communication connections with multiple intranet nodes through the intranet penetration client.

4. The system according to any one of claims 1 to 3, characterized in that: The intranet penetration client is also used to map the node service corresponding to the intranet node to the intranet penetration server; The intranet penetration server is used to provide the node service to the user client through the proxy.

5. An intranet service management method, characterized in that: The method is applied to an intranet penetration server deployed on a public network IP, an intranet penetration client and an agent deployed on an intranet device; the agent adopts a proxy server based on the sock5 protocol to communicate with the user server; the intranet penetration server is provided with an external unified service port, and is communicated with the agent through the unified service port; the method comprises: Obtaining an intranet service access request from a user client through the proxy terminal, and sending the intranet service access request to the intranet penetration server through a proxy protocol; The proxy protocol from the proxy client is obtained through the intranet penetration server, and the proxy protocol is parsed to determine the intranet node and node service to be accessed, and a communication connection with the intranet node is established through the intranet penetration client; Mapping the node service corresponding to the intranet node to the intranet penetration server by using the intranet penetration client; The intranet penetration server provides the node service to the user client through the proxy terminal; The step of obtaining an intranet service access request from a user client through the proxy end, and sending the intranet service access request to the intranet penetration server through a proxy protocol includes: The proxy terminal obtains an intranet service access request carrying the intranet node and node service that need to be accessed, and sends the intranet node and the node service to the intranet penetration server terminal through a proxy of the sock5 protocol.

6. The method according to claim 5, characterized in that The parsing of the proxy protocol to determine the intranet nodes and node services that need to be accessed includes: The intranet penetration server is used to parse the user name field in the sock5 protocol to obtain the intranet node and node service that need to be accessed.

7. The method according to any one of claims 5 to 6, characterized in that: The method further comprises: Using the intranet penetration client to generate a unique identifier required for access for each intranet node; The intranet penetration server establishes communication connections with multiple intranet nodes simultaneously through the intranet penetration client.

Citation Information

Patent Citations

  • Intranet penetration system

    CN116436891A