A method for managing device nodes

By configuring the management mode of the device node and detecting the management channel, it automatically switches to a connected management node, solving the problem that network security equipment cannot work normally in a complex network environment, and achieving stable management of device nodes and efficient data transmission under abnormal circumstances.

CN119583334BActive Publication Date: 2025-09-30WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411652191.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-09-30
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

In a complex network topology environment, network security equipment may be unable to enter normal working state or supervision may fail due to network anomalies or equipment failures, posing a hidden danger to the enterprise intranet network data.

Method used

Configure the management mode of the device node, including configuring only the primary management node or configuring both the primary and secondary management nodes. Through management channel detection and online switching services, automatically switch to the connected management node for data transmission, and realize management through the collaborative cooperation of the primary and secondary management nodes.

Benefits of technology

It enables device nodes to enter the working state normally under complex and abnormal network conditions, reduces the burden on management nodes, and improves the reliability and management efficiency of network security equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583334B_ABST
    Figure CN119583334B_ABST
Patent Text Reader

Abstract

The present invention provides a method for managing device nodes, belonging to the technical field of network security equipment, and comprising: configuring a management mode of the device node; one management mode being: the device node is configured with only a first-level management node and establishes a management channel with the first-level management node; another management mode being: the device node is configured with a first-level management node and a second-level management node; preferentially detecting the management channel between the device node and the second-level management node, and after detecting that the management channel is connected, performing data transmission between the device node and the second-level management node; and switching the device node to the first-level management node when detecting that the management channel is not connected. The present invention detects connectivity with the management node by detecting the management channel, automatically configures its own network parameters according to the detection result, switches its own working mode and management channel, and completes automatic switching under different management nodes, thereby enabling the device node to normally enter a working state in complex and abnormal network conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security, and in particular to a method for managing device nodes. Background Art

[0002] Network security devices are deployed between an enterprise's internal trusted network and the internet, acting at the network layer to provide network security protection. Due to the inherent sensitivity of network security devices, a management node is typically deployed to remotely monitor and manage their status to prevent information leakage within the enterprise intranet. This allows for immediate and effective action in the event of device anomalies, safeguarding the enterprise network. However, in the event of a network anomaly or failure, network security devices are unable to communicate with the management node for data exchange, leaving them in an unknown and uncontrollable state, potentially posing a threat to enterprise intranet data.

[0003] In addition, network security equipment is characterized by large deployment volume, complex network environment, and difficulty in equipment activation, which creates certain difficulties for the activation and management of network security equipment. Summary of the Invention

[0004] The present invention provides a method for managing device nodes, which is used to solve the problem in the prior art that network security devices cannot normally enter a working state or supervision fails due to network anomalies or device failures in a complex network topology environment.

[0005] The present invention provides a method for managing a device node, comprising:

[0006] Configure the management mode of the device node;

[0007] One management mode is: the device node is configured with only one primary management node and establishes a management channel with the primary management node for data transmission;

[0008] Another management mode is: the device node is configured with a first-level management node and a second-level management node; the management channel between the device node and the second-level management node is detected first, and after detecting that the management channel is connected, data is transmitted between the device node and the second-level management node. When it is detected that the management channel is not connected, the device node is switched to the first-level management node, and data transmission is performed after the management channel with the first-level management node is connected.

[0009] The device node management method provided by the present invention further includes: no matter which management mode the device node is in, establishing a management channel with the first-level management node after the device node is started.

[0010] The device node management method provided by the present invention also includes: after the device node enters the working state, by receiving the management node online switching service initiated by the first-level management node, the configuration information of the device node is replaced, so that the device node is switched to the corresponding management node for management; wherein, the configuration information includes the management node type, the management node address, the central node address and related network routing information.

[0011] The device node management method provided by the present invention also includes: when the device node is only configured with a first-level management node, the device node only establishes a management channel with the first-level management node; when the device node is configured with both a first-level management node and a second-level management node, the device node establishes a management channel with both the first-level management node and the second-level management node.

[0012] According to the device node management method provided by the present invention, after the device node is configured with only a first-level management node and enters a working state, the first-level management node initiates a management node online switching service to switch the management node, including: the first-level management node sends first-level management node information and second-level management node information to the device node; wherein the second-level management node information is arranged in front of the first-level management node information; after the device node receives valid data, it switches to the second-level management node for management.

[0013] The device node management method provided by the present invention also includes: when the device node is managed under a first-level management node, it can perform all online management services with the first-level management node, but cannot perform any online management services with the second-level management node; when the device node is managed under a second-level management node, it can perform all online management services with the second-level management node, but can only perform some emergency online services with the first-level management node; wherein, some emergency online services include management node online switching services.

[0014] The device node management method provided by the present invention further includes: when the device node is switched to a certain management node for management, regularly reporting device status and log information to the certain management node.

[0015] The device node management method provided by the present invention also includes: when the device node is managed by the secondary management node, the device node periodically reports node status information and log information to the secondary management node, and the secondary management node periodically synchronizes the device node reporting information with the primary management node to realize indirect management of the device node by the primary management node.

[0016] The device node management method provided by the present invention also includes: when the device node switches the management node, the original configuration information is first invalidated, and then new configuration information is configured; wherein the configuration information includes the management node type, the management node address, the central node address and related network routing information.

[0017] The device node management method provided by the present invention has the following advantages compared to the prior art:

[0018] (1) The present invention detects connectivity with the management node by means of management channel detection, automatically configures its own network parameters according to the detection results, switches its own working mode and management channel, completes automatic switching under different management nodes, and enables the device node to enter the working state normally in complex and abnormal network conditions.

[0019] (2) The present invention uses the active switching of the first-level management node to perform management node switching processing on the device node according to the actual deployment network topology of the device node and the management needs of the device node;

[0020] (3) The present invention realizes direct and indirect management of device nodes by the first-level management node through the collaborative cooperation of the first-level management node and the second-level management node, which greatly reduces the burden on the first-level management node. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0022] Figure 1 It is the installation and deployment network topology diagram of the device nodes provided by the present invention;

[0023] Figure 2 This is a flow chart of the device node switching management node provided by the present invention. DETAILED DESCRIPTION

[0024] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0025] It should be noted that, in the description of the embodiments of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "including a..." do not exclude the presence of other identical elements in the process, method, article or device comprising the elements. The orientation or positional relationship indicated by the terms "upper", "lower", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present invention and simplifying the description, and does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation, and therefore cannot be understood as a limitation on the present invention.

[0026] The device node management method provided by the present invention includes the following contents:

[0027] (1) The device node can be configured into two management modes by importing network access information. One is to configure only one set of management node information, namely the first-level management node. At this time, the device only accepts management from this management node. The other is to configure two sets of management node information, namely the first-level management node and the second-level management node. At this time, the device node will be connected to the second-level management node first. If it is not connected to the second-level management node, it can be switched to the first-level management node in an emergency to receive management from the first-level management node. Regardless of the management mode configured for the device node, after the device node enters the working state, it can switch the management node from the first-level management node to the management node according to the actual network topology requirements, and accept management from different management nodes in a time-sharing manner.

[0028] Among them, management node information is a very important component of the network security device automatic switching management system, which includes various parameters and configuration information required for the device (device node) to communicate with the management node.

[0029] (2) Regardless of the mode in which the device node is configured, after the device is started, it always establishes a management channel with the first-level management node and responds to the management node online switching service initiated by the first-level management node.

[0030] (3) When a device node is activated, one or two sets of management node information are configured through the network access file. After the device node enters the working state, it receives the management node online switching service initiated by the management node to replace the device node configuration. The configuration information mainly includes the management node type, management node address, central node address and related network routing information, so that the device node is switched to the corresponding management node for management.

[0031] (4) When a device node is configured with one set of management node information, it can only be configured with the primary management node information, and cannot be configured with the secondary management node information. When a device node is configured with two sets of management node information, after the device node is powered on, it will prioritize connecting to the secondary management node and automatically detect connectivity with the secondary management node. If the line is disconnected, it will switch to the primary management node and connect to the primary management node.

[0032] (5) After the device node is configured with only one set of management node information and enters the working state, the first-level management node can initiate the management node online switching service and send two sets of management node information, the first-level management node and the second-level management node, to the device node, with the second-level management node information arranged in front and the first-level management node information arranged in the back. After receiving valid data, the device node can switch to the second-level management node for management.

[0033] (6) When the device node switches to the management node, it first invalidates the original network configuration information, including the central node address information, the management node address information and the routing information of the relevant network ports on the processor, and then configures the new network configuration information.

[0034] (7) When a device node switches to a new management node, it first invalidates the original management policy information and then configures the management policy information under the new management node.

[0035] (8) When a device node is configured with only the primary management node information, the device node only establishes a management channel with the primary management node. When a device node is configured with both primary and secondary management node information, the device establishes a management channel with both sets of management nodes.

[0036] (9) When a device node is managed by a primary management node, it can perform all online management services with the primary management node, but cannot perform any online management services with the secondary management node. When a device node is managed by a secondary management node, it can perform all online management services with the secondary management node, but can only perform some emergency online services with the primary management node.

[0037] Among them, some emergency online services include online switching services for management nodes.

[0038] (10) The management node online switching service can only be initiated by the first-level management node and cannot be initiated by the second-level management node.

[0039] (11) The device node will regularly report the device status and log information to the management node to which it is switched.

[0040] (12) The primary management node and the secondary management node exchange data through dedicated services. The primary management node obtains management information data of the device node from the secondary management node, including device status, device logs and other information, to achieve indirect management of the device node by the primary management node.

[0041] Figure 1 This is the installation and deployment network topology diagram of the device nodes provided by the present invention, such as Figure 1 As shown, the process of opening device node 1 and device node 2 and entering the working state depends on obtaining key management data from the primary management node or the secondary management node. Device node 1 and device node 2 can be connected to the primary management node by establishing management channel 1 with central node 1, and can also be connected to the secondary management node by establishing management channel 2 with central node 2 and the secondary management node.

[0042] Figure 2 This is a flow chart of the device node switching management node provided by the present invention. Figures 1 to 2 This method is further explained. The process is as follows:

[0043] (1) Import network access files

[0044] When the device is powered on, it first imports the network access file. This file is generated by the primary management node after comprehensively analyzing the device's network topology. The file primarily contains the device node address, central node address, primary management node address, port number, serial number, and type. The file may also contain secondary management node address, port number, serial number, and type.

[0045] (2) Network access file analysis

[0046] Based on the planned data format, the local device is configured by parsing the relevant data fields from the network access file. This includes basic local network configuration and management channel policy configuration. During basic local network configuration, the local device's address is compared with the central node address to determine whether it is a central node or a remote node. Management channel policy information consists of the device address, port, and protocol; the management node's address, port, and protocol; and some data fields for protection. This management channel policy information is configured into the kernel and, in conjunction with the kernel's network protocol stack, protects data exchanged with the management node.

[0047] (3) Establishment of management channels

[0048] After configuring a management policy, a device interacts and processes data with the central node based on the policy. Ultimately, the same protection factor is generated on both the device and central node. This protection factor protects the data exchanged between the device and the management node. If multiple management nodes are included in the network access file, the device node will establish multiple management policies.

[0049] (4) Device data configuration

[0050] After the management channel is established, the device node must obtain the necessary data from the management node before entering normal operation. The device node determines whether to initiate management channel detection based on the management channel establishment status. When the device is configured with only a primary management node, it directly connects to the management node and sends data. When the device is configured with both primary and secondary management nodes, it first detects the management channel with the secondary node. Once the management channel is connected, it connects to the secondary node and sends data. If it detects that the management channel is disconnected, the device switches to the primary management node and connects to the primary node and sends data.

[0051] (5)Node switching management

[0052] After the device enters the working state, it can be switched and managed according to the actual network topology and the needs of device management, switching back and forth between the primary management node and the secondary management node. Management system switching is performed on the primary management node management configuration web page interface. When switching a device node from a primary management node to a secondary management node, the device node is removed from the primary management node node management system on the primary management node management configuration web page and attached to the secondary management node node management system. At this time, the management node information to be sent to the device node contains both primary and secondary management node information. When switching a device from a secondary management node to a primary management node, the device node is removed from the secondary management node node management system on the primary management node management configuration web page and attached to the primary management node node management system. At this time, the management node information to be sent to the device node only contains primary management system node information.

[0053] (6) Synchronize node information between management nodes

[0054] After device node configuration is complete, node information synchronization is first completed between the primary and secondary management nodes. This process is accomplished through interaction using a specially designed, formatted data protocol. After node information synchronization is complete, when a device is configured under a primary management node, only the primary management node responds to active online services requested by the device node; the secondary node does not. When a device is configured under a secondary management node, the primary management node only responds to emergency online services requested by the device node and does not respond to general online services. The secondary management node responds to all online services requested by the device node.

[0055] (7) Switch the management node of the device node.

[0056] Initiate a node switch on the primary management node configuration webpage and send the management node information to the device node via the management channel. Upon receiving the management node data, the device node verifies the integrity of the data, parses the first set of management node information, and configures it locally. This management node is the active device interaction management node. The original management policy and protection factor are then deactivated. A new management policy is then reconfigured based on the management node information, a new protection factor is generated, and a new management channel is established to complete the management node switch.

[0057] (8) Regularly report device node status and log information.

[0058] Device nodes regularly report their status and log information to the currently configured management node. These reports are sent to the management node through the management channel. If the management node does not receive reports within the predetermined periodic interval, it can initiate an emergency response process.

[0059] (9) Synchronize device node reporting information between management nodes

[0060] When a device node is configured as a secondary management node, the device node periodically reports node status information and log information to the secondary management node. The secondary management node periodically synchronizes the device node reporting information with the primary node to implement indirect management of the device node by the primary node.

[0061] In summary, the device node management method provided by the present invention has the following advantages over the prior art:

[0062] (1) The present invention detects connectivity with the management node by means of management channel detection, automatically configures its own network parameters according to the detection results, switches its own working mode and management channel, completes automatic switching under different management nodes, and enables the device node to enter the working state normally in complex and abnormal network conditions.

[0063] (2) The present invention uses the active switching of the first-level management node to perform management node switching processing on the device node according to the actual deployment network topology of the device node and the management needs of the device node;

[0064] (3) The present invention realizes direct and indirect management of device nodes by the first-level management node through the collaborative cooperation of the first-level management node and the second-level management node, which greatly reduces the burden on the first-level management node.

[0065] On the other hand, the present invention further provides a computer program product, comprising a computer program stored on a non-transitory computer-readable storage medium, wherein the computer program comprises program instructions. When the program instructions are executed by a computer, the computer can perform the device node management method provided in each of the above embodiments, wherein the method comprises:

[0066] Configure the management mode of the device node;

[0067] One management mode is: the device node is configured with only one primary management node and establishes a management channel with the primary management node for data transmission;

[0068] Another management mode is: the device node is configured with a first-level management node and a second-level management node; the management channel between the device node and the second-level management node is detected first, and after detecting that the management channel is connected, data is transmitted between the device node and the second-level management node. When it is detected that the management channel is not connected, the device node is switched to the first-level management node, and data transmission is performed after the management channel with the first-level management node is connected.

[0069] In another aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for managing device nodes provided in the above embodiments is implemented, the method comprising:

[0070] Configure the management mode of the device node;

[0071] One management mode is: the device node is configured with only one primary management node and establishes a management channel with the primary management node for data transmission;

[0072] Another management mode is: the device node is configured with a first-level management node and a second-level management node; the management channel between the device node and the second-level management node is detected first, and after detecting that the management channel is connected, data is transmitted between the device node and the second-level management node. When it is detected that the management channel is not connected, the device node is switched to the first-level management node, and data transmission is performed after the management channel with the first-level management node is connected.

[0073] The above is only an exemplary embodiment of the present disclosure and cannot be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the specification and practicing the disclosure herein, those skilled in the art will easily think of the implementation scheme of the present disclosure. This application is intended to cover any variation, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the art that are not recorded in the present disclosure. The description and examples are to be regarded as exemplary only, and the scope and spirit of the present disclosure are defined by the claims.

[0074] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0075] It will be easily understood by those skilled in the art that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for managing a device node, characterized in that: include: Configure the management mode of the device node; One management mode is: the device node is configured with only one primary management node and establishes a management channel with the primary management node for data transmission; Another management mode is: the device node is configured with a primary management node and a secondary management node; Prioritize the detection of the management channel between the device node and the secondary management node. After detecting that the management channel is connected, data transmission is carried out between the device node and the secondary management node. If it is detected that the management channel is not connected, the device node is switched to the primary management node and data transmission is carried out after the management channel with the primary management node is connected. The method further includes: after the device node enters the working state, by receiving the management node online switching service initiated by the first-level management node, replacing the configuration information of the device node, so that the device node is switched to the corresponding management node for management.

2. The device node management method according to claim 1, characterized in that: Also includes: Regardless of the management mode the device node is in, a management channel is established with the primary management node after the device node is started.

3. The device node management method according to claim 1, characterized in that: in, The configuration information includes the management node type, management node address, central node address and related network routing information.

4. The method for managing device nodes according to claim 1, wherein: Also includes: When a device node is configured with only a primary management node, the device node only establishes a management channel with the primary management node. When a device node is configured with both a primary and a secondary management node, the device node establishes a management channel with both the primary and secondary management nodes.

5. The device node management method according to claim 1, characterized in that: After a device node is configured with only a primary management node and enters the working state, the primary management node initiates the management node online switching service to switch the management node, including: The primary management node sends primary management node information and secondary management node information to the device node; wherein the secondary management node information is arranged before the primary management node information; After the device node receives valid data, it switches to the secondary management node for management.

6. The method for managing device nodes according to claim 1, wherein: Also includes: When a device node is managed by a primary management node, it can perform all online management services with the primary management node, but cannot perform any online management services with the secondary management node. When a device node is managed by a secondary management node, it can perform all online management services with the secondary management node, but can only perform some emergency online services with the primary management node. Among them, some emergency online services include online switching services for management nodes.

7. The device node management method according to claim 1, characterized in that: Also includes: When a device node is switched to a certain management node for management, it regularly reports the device status and log information to the certain management node.

8. The method for managing device nodes according to claim 1, wherein: Also includes: When a device node is managed by a secondary management node, the device node periodically reports node status information and log information to the secondary management node. The secondary management node periodically synchronizes the device node reporting information with the primary management node to implement indirect management of the device node by the primary management node.

9. The device node management method according to claim 1, characterized in that: Also includes: When a device node switches to a management node, it first invalidates the original configuration information and then configures the new configuration information. The configuration information includes the management node type, management node address, central node address and related network routing information.

Citation Information

Patent Citations

  • Block structure of P2P network and its network set method

    CN101047550A

  • Server BMC dynamic network linkage management method and management system

    CN115134215A