Network device management method, system, computer device and readable storage medium

CN119835058BActive Publication Date: 2025-09-23PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411997280.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-09-23
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

然而,这种调整方式可能产生一些问题

Benefits of technology

[0060]In an embodiment of the present application, a communication gateway obtains a login authentication message transmitted by a first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports communication connections between any network device and a corresponding domain control server; the communication gateway performs key parsing on the login authentication message to obtain a key to be verified for the first network device; the communication gateway determines a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and reads a control authentication key of the first domain control server; wherein the preset domain relationship mapping table contains a mapping relationship between the management authority of each domain control server for different network devices, and the management authority of each domain control server for the corresponding network device is determined and granted by the central control server based on the registration configuration information of the corresponding network device; when the communication gateway compares the key to be verified with the control authentication key and finds that it is consistent, the communication gateway merges the first network device into the target domain network controlled by the first domain control server. In this way, all network devices managed by the domain control server can connect to the central control server and the communication gateway via the open virtual private network protocol. When the network topology changes, only the configuration needs to be updated on the central control server and the communication gateway, without the need to set up a controller in each branch and perform separate maintenance and changes on the controller, thereby reducing system complexity and management costs and improving management efficiency. On the other hand, as an independent open virtual private network protocol solution, the OpenVPN protocol can establish a communication connection between network devices and communication gateways through corresponding tunnels. It can run on a variety of hardware platforms, does not require specific protocol-compatible hardware, and does not have specific requirements for hardware and platforms, greatly increasing the scalability of the network. In summary, this application can reduce the complexity of system management while increasing the scalability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835058B_ABST
    Figure CN119835058B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a network device management method, system, computer device and readable storage medium. The method includes: the communication gateway obtains a login authentication message transmitted by the first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol; the communication gateway performs key parsing on the login authentication message to obtain a key to be verified for the first network device; the communication gateway determines the first domain control server for managing and controlling the first network device based on a preset domain relationship mapping table, and reads the corresponding control authentication key; wherein the preset domain relationship mapping table contains a mapping relationship of management permissions of each domain control server to different network devices; when the communication gateway compares the key to be verified and the control authentication key and finds consistency, the communication gateway incorporates the first network device into the target domain network controlled by the first domain control server. In this way, the scalability of the network can be increased while reducing the complexity of system management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a network device management method, system, computer device, and readable storage medium. Background Art

[0002] In recent years, Internet technology and network services have developed rapidly. Scalable, efficient, and intelligent network control and management have become a key development direction for the mobile Internet. Mobile devices, as the primary communication entities in the mobile Internet, retain vast amounts of data and information, which can be used to analyze network performance and provide various services. As application scenarios and the number of mobile devices increase, the demand for inter-device communication and the complexity of unified management of all devices are also increasing. Effective management of massive mobile devices has become a critical issue that needs to be addressed in the mobile Internet era.

[0003] In the related art, most multi-domain network systems provide interfaces for Software-Defined Networking (SDN) based on the OpenFlow protocol to facilitate the control and management of the data plane. However, when the network topology changes and traffic routing needs to be adjusted, the controller will generate corresponding OpenFlow rules based on the current workload of each server and send them to the switch so that the switch can forward incoming data packets to the most appropriate destination server based on these rules. However, this adjustment method may cause some problems. On the one hand, the forwarding action depends entirely on the implementation of the OpenFlow interface of the switch. Each forwarding decision needs to be defined through an OpenFlow table entry, which means that any change in network topology or policy requires updating the corresponding table entry. As the network scale expands, the difficulty of managing and maintaining these tables increases exponentially, thereby increasing the complexity of the system. On the other hand, the OpenFlow protocol has undergone multiple versions, and there are functional differences and syntax changes between different versions, which affect the scalability of the network. Summary of the Invention

[0004] The main purpose of the embodiments of the present application is to provide a network device management method, system, computer device and readable storage medium, which can reduce the complexity of system management while increasing the scalability of the network.

[0005] To achieve the above objectives, a first aspect of an embodiment of the present application provides a network device management method, which is applied to a network device management system, wherein the network device management system includes a central control server, multiple domain control servers, and a communication gateway. The method includes:

[0006] The communication gateway obtains a login authentication message transmitted by the first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports a communication connection between any network device and a corresponding domain control server;

[0007] The communication gateway performs key parsing on the login authentication message to obtain a key to be verified of the first network device;

[0008] The communication gateway determines, based on a preset domain relationship mapping table, a first domain control server for controlling the first network device, and reads a control authentication key generated by the first domain control server for the first network device;

[0009] The preset domain relationship mapping table includes a mapping relationship between the management authority of each domain control server and different network devices, and the management authority of each domain control server for the corresponding network device is determined and granted by the central control server based on the registration configuration information of the corresponding network device;

[0010] When the communication gateway compares the key to be verified with the management and control authentication key and finds that the key is consistent with the management and control authentication key, the communication gateway incorporates the first network device into the target domain network controlled by the first domain management and control server.

[0011] In some implementations, before the communication gateway obtains the login authentication message transmitted by the first network device via the data transmission tunnel, the method further includes:

[0012] The central control server obtains registration configuration information corresponding to the first network device and saves the registration configuration information; wherein the first network device is a communication device to be incorporated into the domain network;

[0013] The central control server determines, based on the registration configuration information, a first domain control server having a management authority mapping relationship with the first network device;

[0014] Encapsulating the registration configuration information and the management authority mapping relationship into a first message, and transmitting the first message to the first domain management and control server and the communication gateway respectively;

[0015] The first domain management and control server extracts the device identification information of the first network device from the first message and saves the device identification information;

[0016] The communication gateway extracts the management authority mapping relationship from the first message and stores the management authority mapping relationship in a domain relationship mapping table.

[0017] In some implementations, after the communication gateway extracts the management authority mapping relationship from the first message and stores the management authority mapping relationship in a domain relationship mapping table, the method further includes:

[0018] The communication gateway obtains first network device information managed by the first domain management and control server;

[0019] When the first network device information indicates that the first network device is the first network device managed by the first domain management server, the communication gateway adds a network address translation route for the first network device.

[0020] In some implementations, before the communication gateway obtains the login authentication message transmitted by the first network device via the data transmission tunnel, the method further includes:

[0021] The communication gateway configures communication data of the data transmission tunnel through a pre-configured open virtual private network server, wherein the communication data includes at least a port address for receiving data packets, a tunnel transmission protocol, a tunnel mode, a target certificate storage path, a certificate verification algorithm path, and a target network segment allowed to be accessed by the first network device;

[0022] After the open virtual private network client pre-installed on the first network device and the open virtual private network server are both turned on, a data transmission tunnel is formed between the communication gateway and the first network device, wherein the open virtual private network client is configured with at least the Internet Protocol address and the port address of the open virtual private network server.

[0023] In some implementations, the network device management method further includes:

[0024] The communication gateway receives a network exit request message sent by the second network device via the corresponding data transmission tunnel;

[0025] The communication gateway verifies the network withdrawal request message according to the field structure of the network withdrawal request message to obtain a first verification result;

[0026] When the first verification result indicates that the network withdrawal request message passes verification, the communication gateway transmits the network withdrawal request message to the second domain management and control server corresponding to the second network device;

[0027] The second domain management and control server deletes the data resources corresponding to the second network device according to the network exit request message;

[0028] The second domain control server sends a data refresh request to the central control server, so that the central control server refreshes data on the network device management system after receiving the data refresh request;

[0029] The communication gateway deletes the management authority mapping relationship corresponding to the second network device in the domain relationship mapping table.

[0030] In some implementations, the communication gateway verifies the detach request message according to the field structure of the detach request message to obtain a first verification result, including:

[0031] The communication gateway obtains a verification hash table;

[0032] The communication gateway extracts fields from the network exit request message according to the field structure to obtain a plurality of fields to be checked;

[0033] The communication gateway performs regularization verification on the corresponding multiple fields to be verified based on the regularization rule corresponding to each field to be verified in the verification hash table to obtain a first verification result.

[0034] In some implementations, after the communication gateway deletes the management authority mapping relationship corresponding to the second network device in the domain relationship mapping table, the further step includes:

[0035] The communication gateway obtains the second network device information managed by the second domain management and control server;

[0036] When the second network device information indicates that the second network device is the last network device managed by the second domain management and control server, the communication gateway deletes the network address translation route corresponding to the second network device.

[0037] In some implementations, the network device management method further includes:

[0038] The central control server transmits a first device transfer request message to the communication gateway, wherein the first device transfer request message includes registration configuration information of the third network device to be transferred, and server information of the third domain control server to which the third network device needs to be transferred;

[0039] The communication gateway verifies the first device transfer request message according to the field structure of the received first device transfer request message to obtain a second verification result;

[0040] When the second verification result indicates that the first device transfer request message has passed verification, the communication gateway transfers the target data message subsequently transmitted by the third network device to the target queue for temporary storage;

[0041] The communication gateway parses the first device transfer request message to determine the third domain control server to which the third network device is transferred;

[0042] The communication gateway extracts the server information of the destination domain control server from the first device transfer request message, and modifies the management authority mapping relationship between the third network device and the historically associated domain control server in the domain relationship mapping table based on the server information, so as to establish an updated management authority mapping relationship between the third network device and the third domain control server;

[0043] The historically associated domain control server deletes the device identification information corresponding to the third network device;

[0044] The third domain control server stores the device identification information corresponding to the third network device, and transfers the target data message temporarily stored in the target queue to the third domain control server.

[0045] In some implementations, the network device management method further includes:

[0046] When the third network device to be transferred is a single network device, the communication gateway adds a network address translation route for the third network device according to the Internet Protocol address of the third network device;

[0047] When the number of the plurality of third network devices to be transferred exceeds a preset threshold, the communication gateway adds a network address translation route for the plurality of third network devices according to a network segment address corresponding to any third network device.

[0048] In some implementations, the network device management method further includes:

[0049] When a domain control server fails, the central control server determines a fourth network device that has a management authority mapping relationship with the failed domain control server;

[0050] Obtaining, through the central control server, available loads corresponding to a plurality of normally operating domain control servers, and determining at least one fourth domain control server from the plurality of domain control servers based on the available loads;

[0051] The central control server transmits a second device transfer request message to the communication gateway; wherein, the second device transfer request message includes the registration configuration information of the fourth network device to be transferred, and the server information of the fourth domain control server to which the fourth network device needs to be transferred.

[0052] Accordingly, a second aspect of an embodiment of the present application proposes a network device management system, including a central control server, multiple domain control servers, and a communication gateway, including:

[0053] The central control server is used to determine the management authority granted to each domain control server for the corresponding network device based on the registration configuration information of the corresponding network device;

[0054] The domain control server is used to manage corresponding network devices;

[0055] The communication gateway is configured to obtain a login authentication message transmitted by the first network device via a data transmission tunnel, perform key parsing on the login authentication message, and obtain a key to be verified of the first network device, wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports a communication connection between any network device and a corresponding domain control server;

[0056] The communication gateway is further configured to determine a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and read a control authentication key generated by the first domain control server for the first network device, wherein the preset domain relationship mapping table includes a mapping relationship between management permissions of each domain control server for different network devices;

[0057] The communication gateway is further configured to, when the key to be verified is consistent with the management and control authentication key, merge the first network device into the target domain network controlled by the first domain management and control server.

[0058] Correspondingly, the third aspect of the embodiments of the present application proposes a computer device, which includes a memory and a processor, the memory stores a computer program, and the processor implements the network device management method described in any one of the embodiments of the first aspect of the present application when executing the computer program.

[0059] Correspondingly, the fourth aspect of the embodiments of the present application proposes a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the network device management method described in any one of the embodiments of the first aspect of the present application.

[0060] In an embodiment of the present application, a communication gateway obtains a login authentication message transmitted by a first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports communication connections between any network device and a corresponding domain control server; the communication gateway performs key parsing on the login authentication message to obtain a key to be verified for the first network device; the communication gateway determines a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and reads a control authentication key of the first domain control server; wherein the preset domain relationship mapping table contains a mapping relationship between the management authority of each domain control server for different network devices, and the management authority of each domain control server for the corresponding network device is determined and granted by the central control server based on the registration configuration information of the corresponding network device; when the communication gateway compares the key to be verified with the control authentication key and finds that it is consistent, the communication gateway merges the first network device into the target domain network controlled by the first domain control server. In this way, all network devices managed by the domain control server can connect to the central control server and the communication gateway via the open virtual private network protocol. When the network topology changes, only the configuration needs to be updated on the central control server and the communication gateway, without the need to set up a controller in each branch and perform separate maintenance and changes on the controller, thereby reducing system complexity and management costs and improving management efficiency. On the other hand, as an independent open virtual private network protocol solution, the OpenVPN protocol can establish a communication connection between network devices and communication gateways through corresponding tunnels. It can run on a variety of hardware platforms, does not require specific protocol-compatible hardware, and does not have specific requirements for hardware and platforms, greatly increasing the scalability of the network. In summary, this application can reduce the complexity of system management while increasing the scalability of the network. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 This is a schematic diagram of the architecture of the network device management system provided in an embodiment of the present application;

[0062] Figure 2 This is a functional module diagram of the device management system provided by the embodiment of the present application

[0063] Figure 3 This is a flow chart of a network device management method provided by an embodiment of the present application;

[0064] Figure 4 This is a flowchart of the network access of a network device provided in an embodiment of the present application;

[0065] Figure 5 This is a flowchart of the network device disconnection provided by an embodiment of the present application;

[0066] Figure 6 This is a flow chart of inter-domain transfer of network devices provided in an embodiment of the present application;

[0067] Figure 7 This is a schematic diagram of the hardware structure of the computer device provided in the embodiment of the present application. DETAILED DESCRIPTION

[0068] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0069] It should be noted that although the system diagrams illustrate functional module divisions and the flowcharts illustrate logical sequences, in certain circumstances, the steps shown or described may be performed in a sequence that differs from the module divisions in the system or the sequence in the flowcharts. The terms "first," "second," and so on, in the specification, claims, and drawings, are used to distinguish similar items and are not necessarily used to describe a specific sequence or precedence.

[0070] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0071] In recent years, Internet technology and network services have developed rapidly. Scalable, efficient, and intelligent network control and management have become a key development direction for the mobile Internet. Mobile devices, as the primary communication entities in the mobile Internet, retain vast amounts of data and information, which can be used to analyze network performance and provide various services. As application scenarios and the number of mobile devices increase, the demand for inter-device communication and the complexity of unified management of all devices are also increasing. Effective management of massive mobile devices has become a critical issue that needs to be addressed in the mobile Internet era.

[0072] In the related art, most multi-domain network systems provide interfaces for Software-Defined Networking (SDN) based on the OpenFlow protocol to facilitate the control and management of the data plane. However, when the network topology changes and traffic routing needs to be adjusted, the controller will generate corresponding OpenFlow rules based on the current workload of each server and send them to the switch so that the switch can forward incoming data packets to the most appropriate destination server based on these rules. However, this adjustment method may cause some problems. On the one hand, the forwarding action depends entirely on the implementation of the OpenFlow interface of the switch. Each forwarding decision needs to be defined through an OpenFlow table entry, which means that any change in network topology or policy requires updating the corresponding table entry. As the network scale expands, the difficulty of managing and maintaining these tables increases exponentially, thereby increasing the complexity of the system. On the other hand, the OpenFlow protocol has undergone multiple versions, and there are functional differences and syntax changes between different versions, which affect the scalability of the network.

[0073] Based on this, the embodiments of the present application provide a network device management method, system, computer device and readable storage medium, which can reduce the complexity of system management while increasing the scalability of the network.

[0074] The network device management method, system, computer device and readable storage medium provided in the embodiments of the present application are specifically illustrated through the following embodiments. First, the network device management system in the embodiments of the present application is described.

[0075] Please refer to Figure 1 In some implementations, an embodiment of the present application provides a device management system, including a central management server, multiple domain management servers, and a communication gateway.

[0076] In some embodiments, a central management center (CMC) is configured to determine, based on registration configuration information of the corresponding network device, the management authority granted to each domain management server for the corresponding network device;

[0077] Area Controller (AR), used to manage corresponding network devices;

[0078] a communication gateway (Gateway Router, GR), configured to obtain a login authentication message transmitted by the first network device via a data transmission tunnel, perform key parsing on the login authentication message, and obtain a key to be verified of the first network device, wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports a communication connection between any network device and a corresponding domain control server;

[0079] The communication gateway is further configured to determine a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and read a control authentication key generated by the first domain control server for the first network device, wherein the preset domain relationship mapping table includes a mapping relationship between management permissions of each domain control server for different network devices;

[0080] The communication gateway is further configured to merge the first network device (Mobile Router, MR) into the target domain network controlled by the first domain control server when the key to be verified is consistent with the control authentication key.

[0081] The specific implementation of the network device management system is basically the same as the specific embodiment of the network device management method, which will be further introduced below and will not be repeated here.

[0082] Please refer to Figure 2 In some implementations, the functional modules of the device management system include a communication interaction module, a domain management module, a security protection module, and a data storage module, and each module can communicate and interact.

[0083] For example, a communication interaction module is provided in each of the central control server, domain control server, communication gateway, and network device. The communication interaction module can standardize the data message format and interaction process transmitted in the network. For example, the communication interaction module can maintain the forwarding of communication messages between the network device and the domain control server, as well as the mapping relationship between the two, update system routing information, and parse messages in the communication gateway.

[0084] Furthermore, a domain management module can be set up in the communication gateway and central control server. This module can use tunneling technology and routing strategies to adjust the domain network structure, divide different network domains, and maintain the domain relationship of network devices. Specifically, this includes information mapping and updating between network devices and domain networks, as well as updating domain network information.

[0085] Furthermore, a security protection module can be set up in the communication gateway to verify the format of the data packets flowing through it, preventing illegal or invalid data packets from attacking the internal network. The security protection module can be used for key consistency checks and message security checks in network device management systems, etc.

[0086] Furthermore, a data storage module can be set up in the communication gateway, domain control server and central control server. The data storage module can perform distributed storage of information transmitted from remote devices, including the design of a preset domain relationship mapping table, etc. The data storage module can include the storage and update of information of network devices connected to the network, the storage and update of domain network information and mapping information between network devices and domain control servers, the storage of key information and routing information, etc.

[0087] In some implementations, on the premise of meeting the requirements of the embodiments of the present application, the network device management system may further be provided with other functional modules to implement the network device management method in the embodiments of the present application.

[0088] The network device management method in the embodiments of the present application can be illustrated by the following embodiments.

[0089] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to user identity or characteristics such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiment of the present application needs to obtain the user's sensitive personal information, the user's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or consent, the necessary user-related data for the normal operation of the embodiment of the present application will be obtained.

[0090] In the embodiment of the present application, the network device management system will be described from the perspective of the network device management system, which may include a central management server, multiple domain management servers, and a communication gateway. The network device management system may be integrated into a computer device. Figure 3 and Figure 4 , Figure 3 and Figure 4 This is a flowchart of the steps of the network device management method provided in an embodiment of the present application. In this embodiment of the present application, the network device management system is specifically integrated into a terminal or server as an example. When the processor on the terminal or server executes the program instructions corresponding to the network device management method, the specific process is as follows:

[0091] In step 101, the communication gateway obtains a login authentication message transmitted by the first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports a communication connection between any network device and a corresponding domain control server.

[0092] In some embodiments, in order to ensure the security of the internal network, when a network device needs to access the network, the login authentication message of the corresponding first network device can be obtained through the data transmission tunnel, so that the first network device can be authenticated through the login authentication message to improve the efficiency and security of network management.

[0093] Among them, the communication gateway can be a unified entry point for data transmission between network devices and multiple internal domain networks. In addition, the communication gateway also undertakes tasks such as security checking, key resolution and network address translation routing.

[0094] The first network device may be a new network device to be incorporated into the corresponding domain network, and may be any type of network terminal or router.

[0095] The data transmission tunnel may be a secure transmission channel created based on an Open Virtual Private Network (OpenVPN) protocol, and is used to transmit data packets between two network entities.

[0096] The login authentication message can be a verification packet sent to the communication gateway through a data transmission tunnel when a new network device attempts to join the corresponding domain network for the first time. The login authentication message contains the identity information of the first network device and the key material required for authentication, which is used to prove the legal identity of the first network device and request access permission.

[0097] The OpenVPN protocol is an open-source virtual private network protocol used to create a secure encrypted tunnel over a public network (such as the Internet). The OpenVPN protocol allows users to securely access remote networks or services over a public network (such as the Internet), is adaptable to different network environments and network device types, and is not dependent on specific hardware.

[0098] The domain control server can be used to manage and maintain the status information and configuration parameters of all network devices in the domain network.

[0099] Exemplarily, the login authentication message may include the device identification of the first network device, the Media Access Control (MAC) address or serial number, the user name or user password, the digital certificate, the device status information, etc. The login authentication messages corresponding to different network devices may be different, and the specific details shall be determined based on the actual situation.

[0100] Specifically, a data transmission tunnel created based on an open virtual private network protocol can be used to transmit login authentication messages, so that after passing the authentication, the first network device can be added to the corresponding domain network without making large-scale adjustments to the entire infrastructure, and a secure and reliable communication path is provided for the first network device.

[0101] By using a communication gateway as a unified entry point for data transmission between network devices and multiple internal domain networks, the system not only achieves centralized management and efficient data routing, but also ensures key tasks such as security checks, key resolution, and network address translation routing for all incoming and outgoing data. For new network devices to be incorporated into the domain network (such as the first network device), regardless of their type of terminal or router, they can send login authentication messages through a secure transmission tunnel created based on the open virtual private network protocol to conduct identity verification and access requests. This allows the new device to quickly and securely join the corresponding domain network and enjoy a stable and reliable encrypted communication path in subsequent operations.

[0102] In some embodiments, to ensure that all first network devices attempting to access the network undergo a formal registration process so that they can be effectively managed and monitored, the central control server can select the most appropriate domain control server for the first target device based on its specific circumstances (e.g., regional location, functional requirements, etc.), and transmit the information to the domain control server and the communication gateway to ensure that it can be quickly and accurately integrated into the existing management system, thereby optimizing resource utilization and simplifying the network architecture. For example, before step 101, the following may also be included:

[0103] (A.1) The central control server obtains registration configuration information corresponding to a first network device and saves the registration configuration information; wherein the first network device is a communication device to be incorporated into the domain network;

[0104] (A.2) The central control server determines, based on the registration configuration information, a first domain control server that has a management authority mapping relationship with the first network device;

[0105] (A.3) Encapsulating the registration configuration information and the management authority mapping relationship into a first message, and transmitting the first message to the first domain management and control server and the communication gateway respectively;

[0106] (A.4) The first domain management and control server extracts the device identification information of the first network device from the first message and saves the device identification information;

[0107] (A.5) The communication gateway extracts the management authority mapping relationship from the first message and stores the management authority mapping relationship in the domain relationship mapping table.

[0108] Among them, the central control server can be one of the core components of the network equipment management system, responsible for performing cross-domain equipment management tasks, such as network equipment access, network exit and inter-domain transfer in the entire network, and working with communication gateways, domain control servers and network equipment to achieve efficient domain management of large-scale network equipment.

[0109] The registration configuration information may refer to the basic information submitted by a first network device when applying to join a domain network. The registration configuration information includes, but is not limited to, the device name, Internet Protocol address, geographic location, domain network, and intended use. This information is used to assist the central control server in evaluating and determining the target domain network to be assigned to the first network device.

[0110] The first domain control server may be a domain control server selected by the central control server for managing network devices. Each domain network has its own dedicated domain control server to handle all related matters within the domain network.

[0111] The first message may be an information packet including registration configuration information of the first network device and a management authority mapping relationship between the first network device and the corresponding first domain control server.

[0112] The device identification information may be a basic information set used to uniquely identify and configure the first network device, such as the device name and Internet Protocol address of the first network device.

[0113] The management authority mapping relationship may describe the scope of control authority that the first domain control server has over the first network device, that is, which specific domain control server can manage and configure the first network device. The management authority mapping relationship is determined by the central control server based on the registration configuration information of the first network device.

[0114] The domain relationship mapping table may be a database table stored inside the communication gateway, which records the corresponding relationship between each domain management and control server and its associated network devices.

[0115] For example, assume that a new first network device (e.g., router Device_X) needs to be added to a LAN in the internal network. The following are the detailed steps in the specific implementation process:

[0116] First, the network administrator registers the registration configuration information of the first network device on the central management and control platform, such as the device name (Device_X), the province (Province A), the IP address (100.600.1.100) and the first domain management and control server (AR_A).

[0117] Furthermore, after receiving the registration configuration information, the central management server can verify and save it. Subsequently, the central management server can encapsulate the registration configuration information and the management authority mapping relationship into a first message named "First_Report." The first message can be transmitted to the first domain management server (AR_A) and the communication gateway via the communication interaction module.

[0118] Furthermore, after receiving the "First_Report" message, the first domain management server (AR_A) extracts the device identification information (such as device name, Internet Protocol address, etc.) of Device_X and saves the device identification information in its local database for subsequent management and use.

[0119] Furthermore, the communication gateway can extract the mapping relationship between Device_X and AR_A from the first message named "First_Report" and store it in its own domain relationship mapping table. This allows centralized management and unified configuration to ensure that all relevant information about the new first network device is stored accordingly, reducing the possibility of human error, ensuring data consistency, and improving data maintainability.

[0120] Through the above methods, centralized management and unified configuration of cross-domain devices can be achieved through the central control server, ensuring the accurate storage of new device information and efficient operation of the network, and improving the efficiency and flexibility of large-scale network device management.

[0121] In some implementations, to ensure that a newly added first network device can communicate with the corresponding first domain control server or external network through the communication gateway, when the first network device information indicates that the first network device is the first network device managed by the first domain control server, the communication gateway may add a network address translation route for the first network device to enable smooth data transmission. For example, after (A.5), the following may also be included:

[0122] (B.1) The communication gateway obtains information of a first network device managed by the first domain management and control server;

[0123] (B.2) When the first network device information indicates that the first network device is the first network device managed by the first domain management and control server, the communication gateway adds a network address translation route for the first network device.

[0124] The first network device information may be information about multiple network devices managed by the first domain management and control server, including but not limited to the number of the multiple network devices managed.

[0125] Among them, the network address translation route can be a Network Address Translation (NAT) route, which can be a rule or path set by the communication gateway for the first network device, so that the first network device can smoothly access the Internet or other external networks, while protecting the first network device's real internal Internet Protocol address from being directly identified by the outside world.

[0126] In some embodiments, when the first network device joins a domain network managed by a domain control server, since the domain network previously had no task network devices accessing external networks or communicating with other internal networks via public Internet Protocol (IP) addresses, it is necessary to add a network address translation route for the first network device to ensure that the first network device can correctly communicate between the internal and external networks. For subsequent network devices joining the same domain network, the existing address translation rules can be reused, eliminating the need to configure new network address translation routes for each network device. This conserves public IP address resources and simplifies network configuration.

[0127] For example, after the communication gateway obtains the information of the first network device managed by the first domain control server (AR_A), it learns that the first network device (MR_X) is the first device managed by the first domain control server. Therefore, the communication gateway can add a network address translation route for MR_X, mapping MR_X's private IP address (192.168.1.2) to the public IP address (203.0.113.1) of the communication gateway, so that MR_X can access the Internet.

[0128] Through this approach, the communication gateway can intelligently determine when and how to configure network address translation routes, ensuring that every network device can communicate securely and efficiently while also optimizing network resource utilization and management processes. This mechanism provides greater flexibility and reliability, especially for large-scale, dynamically changing enterprise network environments.

[0129] In some implementations, to ensure that the first network device can be incorporated into the corresponding target domain network in the most secure manner while maintaining good communication performance and service quality, a data transmission tunnel can be configured between the first network device and the communication gateway to ensure data transmission security and enhance the scalability and flexibility of the network architecture. For example, before step 101, the following steps may also be included:

[0130] (C.1) The communication gateway configures communication data of the data transmission tunnel through a pre-configured open virtual private network server, wherein the communication data includes at least a port address for receiving data packets, a tunnel transmission protocol, a tunnel mode, a target certificate storage path, a certificate verification algorithm path, and a target network segment that the first network device is allowed to access;

[0131] (C.2) After the open virtual private network client pre-installed on the first network device and the open virtual private network server are both turned on, a data transmission tunnel is formed between the communication gateway and the first network device, wherein the open virtual private network client is configured with at least the Internet Protocol address and port address of the open virtual private network server.

[0132] Among them, the open virtual private network server can be a software component based on the OpenVPN protocol, which can run on the communication gateway. By establishing an encrypted connection between the open virtual private network server and the open virtual private network client, it can ensure that data exchange between the internal network and the external network is both safe and reliable.

[0133] The communication data may be a set of parameters and information required to configure when setting up a data transmission tunnel. The communication data is used to define the relevant data for building, maintaining, and terminating a secure communication channel.

[0134] The tunnel transmission protocol may be a transport layer protocol used by the data transmission tunnel, and the tunnel transmission protocol may be a User Datagram Protocol (UDP) or a Transmission Control Protocol (TCP).

[0135] The tunnel mode may be a virtual network interface type used by a data transmission tunnel to create a secure data transmission channel. The tunnel mode may be a network tunnel (TUN) or a point-to-point tunnel (TAP).

[0136] The target certificate storage path may be a file path of a digital certificate (eg, a root certificate), which is used to sign the digital certificates (eg, root certificates) of the open VPN server and the open VPN client to ensure the authenticity of the identities of both parties.

[0137] The certificate verification algorithm path may be a specified Diffie-Hellman parameter file path, which is used to securely negotiate a shared key between the open virtual private network client and the open virtual private network server.

[0138] The target network segment may be an intranet segment that is accessible to an open virtual private network client, so that the open virtual private network client can access corresponding resources through a data transmission tunnel.

[0139] The open VPN client may be an application installed on the first network device, responsible for initiating and maintaining a secure connection with the open VPN server. The open VPN client may locate the corresponding open VPN server based on preset configuration items (such as the server's Internet Protocol address and port address).

[0140] In some embodiments, the establishment of a data transmission tunnel relies on close collaboration between a pre-configured Open Virtual Private Network (OpenVPN) server and client. Specifically, the communication gateway, as a core node, can define the communication rules of the secure channel by setting a series of key parameters (such as port address, transmission protocol, tunnel mode, certificate storage path, verification algorithm path and target network segment) in the Open Virtual Private Network server. When the OpenVPN client is installed and configured on the first network device and successfully connected to the OpenVPN server on the communication gateway, an encrypted data transmission tunnel is formed between the two. The data transmission tunnel not only ensures the security and privacy of all transmitted data, but also allows remote network devices to securely access the internal network through the public Internet, while achieving effective management and monitoring of these network devices.

[0141] For example, if you need to securely add the first network device MR1 to the internal network of Enterprise A, first install and configure the OpenVPN Server program (also known as the Open Virtual Private Network server) on the communication gateway, set the port address to 1194, use the UDP transport protocol, and specify the routing tunnel mode as tun. Next, configure security parameters such as the Certificate Authority (CA) certificate, the location of the server's public and private keys, and the certificate verification algorithm path, and set the target network segment that MR1 is allowed to access.

[0142] Furthermore, an OpenVPN client (also known as an open virtual private network client) can be installed on MR1, and the necessary information can be configured, including the Internet Protocol address and port address of the communication gateway (i.e., the remote address remote), the CA certificate (ca.crt) and key (cl ient.key) required for authentication. A tunnel route is added on MR1, and the sent data packets are transferred to the tun interface on MR1 to ensure that they are transmitted through the data transmission tunnel. Finally, after starting the OpenVPN service on both sides, a data transmission tunnel can be established between MR1 and the communication gateway. At this time, the communication gateway will detect the data packets on port 1194 and forward the data from MR1 to the corresponding domain control server according to the preset routing rules, thereby achieving the management of MR1 and the secure transmission of data. In addition, the communication gateway turns on the IP forwarding function to ensure that the data packets can accurately reach the domain control server. In this way, the data transmission tunnel between the new network device MR1 and the communication gateway is established. In some embodiments, the data transmission tunnel between any network device and the communication gateway can be established with reference to the above steps, and this application will not go into details here.

[0143] By building a data transmission tunnel between the first network device and the communication gateway, the first network device can be securely added to the internal network, ensuring that it can access necessary internal resources while maintaining the security and reliability of data transmission, providing a solid foundation for the domain management of large-scale network devices.

[0144] In step 102, the communication gateway performs key analysis on the login authentication message to obtain the key to be verified of the first network device.

[0145] In some implementations, in order to prevent unauthorized network devices from accessing and ensure the security and stability of the network environment, the communication gateway may parse and authenticate the login authentication message sent by the first network device to ensure that only authorized devices can successfully join the network.

[0146] Among them, the key to be verified can be encrypted information extracted from the login authentication message and used to verify the identity of the first network device. The key to be verified can be generated by the first network device and encapsulated into a login authentication message and sent to the communication gateway when the first network device attempts to access the network.

[0147] For example, if the first network device Device_X needs to be securely incorporated into the domain network of enterprise A, after establishing a data transmission tunnel between Device_X and the communication gateway, Device_X will send a login authentication message containing authentication information to the communication gateway through the data transmission tunnel. After receiving the login authentication message sent by Device_X, the communication gateway will first perform a preliminary analysis on it and extract key fields in the login authentication message, including but not limited to device identification information (such as MAC address or serial number), user name / password, digital certificate, etc. Furthermore, the communication gateway can extract the pre-shared key or other form of key material used for encrypted transmission from the login authentication message. If the key material is encrypted, the pre-configured server private key is used to decrypt this part of the data to restore the original key to be verified. For example, if the key secret-key-123456 is extracted, then secret-key-123456 is the key to be verified.

[0148] Through the above method, the communication gateway can efficiently and accurately verify each first network device attempting to join the network, ensuring that only first network devices that meet the requirements can obtain access rights, thereby ensuring the security and stability of the entire network environment.

[0149] Step 103: The communication gateway determines a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and reads a control authentication key generated by the first domain control server for the first network device.

[0150] The preset domain relationship mapping table includes the mapping relationship between the management authority of each domain control server and different network devices. The management authority of each domain control server to the corresponding network device is determined and granted by the central control server based on the registration configuration information of the corresponding network device.

[0151] In some embodiments, in order to ensure that the first network device is assigned to the correct management domain, the identity authentication process of the first network device can be completed by searching and matching the correct management and control authentication key in the preset domain relationship mapping table, so that the first network device can be safely and reliably assigned to the appropriate domain network, while also ensuring the effective utilization of network resources and service quality, and achieving a more efficient and intelligent network management method.

[0152] The control authentication key may be encrypted information generated by the first domain control server for a specific first network device and fed back to the communication gateway for storage.

[0153] In some embodiments, a preset domain relationship mapping table includes a mapping relationship between the management permissions of each domain control server and corresponding network devices. Specifically, after a first network device successfully registers with a central control server, the central control server assigns a corresponding first domain control server to the first network device. The assigned first domain control server has management permissions for the first network device. The central control server then encapsulates the permissions mapping relationship into a message and sends it to the communication gateway. The communication gateway then stores the permissions mapping relationship using the preset domain relationship mapping table.

[0154] In some implementations, the management authentication key can also be a shared key that the domain management server uses to verify all network devices with management permissions. This key is used to verify login authentication requests from the device, ensuring that only devices with the correct key are authorized to join the corresponding domain network. The management authentication key is created during initial device registration and is uniquely associated with each device's identity to ensure secure and accurate authentication.

[0155] In some embodiments, after receiving a first message from a central control server and parsing the first message to determine that it corresponds to a first network device to be managed, the control authentication key can be generated for the first network device and sent to the communication gateway for storage. Alternatively, after receiving a login authentication message from the first network device, the communication gateway can generate a corresponding control authentication key for the first network device and send it to the communication gateway. For example, the control authentication key can be in the form of deviceX-key-12345, etc.

[0156] Through the above method, the security and accuracy of the identity authentication of the first network device are ensured, the domain management process of large-scale network devices is simplified, resource utilization and service response speed are improved, and it is conducive to the subsequent rapid comparison of the key to be verified and the management and control authentication key.

[0157] In step 104 , when the communication gateway compares the key to be verified with the control authentication key and finds that the key is consistent, the communication gateway incorporates the first network device into the target domain network controlled by the first domain control server.

[0158] In some embodiments, in order to ensure that the first network device can be smoothly integrated into the domain network corresponding to the domain control server, the verified first network device can be incorporated into the target domain network controlled by the first domain control server to optimize resource allocation and management efficiency and enhance system security.

[0159] The target domain network can be a specific network area or subnet that the first network device is officially admitted to and allowed to access after successfully passing identity authentication. Each target domain network can be managed by at least one domain management server and have independent security policies, access control lists, and service configurations. Joining the first network device to the target domain network means that it can communicate with other network devices in the same domain and enjoy corresponding network resources and services according to preset rules.

[0160] For example, the first network device is represented by Device_X. When the communication gateway determines that the key to be verified is deviceX-key-12345 by parsing the login authentication message of Device_X, the communication gateway can query the control authentication key deviceX-key-12345 generated by the first domain control server for Device_X in the domain relationship mapping table, and save it in the local database. At the same time, the key to be verified is compared with the control authentication key to find out that the key to be verified and the control authentication key are consistent. Therefore, the first network device can be incorporated into the target domain network controlled by the first domain control server.

[0161] In some embodiments, when the key to be verified and the control authentication key are consistent, indicating that the first network device has failed to access the network, the communication gateway can return a prompt of network access failure to the first network device. When the number of times the first network device fails to access the network exceeds a preset number, for example, more than 3 times, the communication gateway can refuse to receive the login authentication message from the first network device.

[0162] In an embodiment of the present application, a communication gateway obtains a login authentication message transmitted by a first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports communication connections between any network device and a corresponding domain control server; the communication gateway performs key parsing on the login authentication message to obtain a key to be verified for the first network device; the communication gateway determines a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and reads a control authentication key of the first domain control server; wherein the preset domain relationship mapping table contains a mapping relationship between the management authority of each domain control server for different network devices, and the management authority of each domain control server for the corresponding network device is determined and granted by the central control server based on the registration configuration information of the corresponding network device; when the communication gateway compares the key to be verified with the control authentication key and finds that it is consistent, the communication gateway merges the first network device into the target domain network controlled by the first domain control server. In this way, all network devices managed by the domain control server can connect to the central control server and the communication gateway via the open virtual private network protocol. When the network topology changes, only the configuration needs to be updated on the central control server and the communication gateway, without the need to set up a controller in each branch and perform separate maintenance and changes on the controller, thereby reducing system complexity and management costs and improving management efficiency. On the other hand, as an independent open virtual private network protocol solution, the OpenVPN protocol can establish a communication connection between network devices and communication gateways through corresponding tunnels. It can run on a variety of hardware platforms, does not require specific protocol-compatible hardware, and does not have specific requirements for hardware and platforms, greatly increasing the scalability of the network. In summary, this application can reduce the complexity of system management while increasing the scalability of the network.

[0163] Please refer to Figure 5 In some implementations, when a network device needs to exit a domain network, in order to ensure that the network device can be safely and orderly removed from the management domain to which it belongs, a security check can be performed on the exit request message to verify the accuracy and security of the exit request message, thereby maintaining the overall security of the network and effective management of resources. For example, the network device management method may also include:

[0164] (D.1) The communication gateway receives a network exit request message sent by the second network device via the corresponding data transmission tunnel;

[0165] (D.2) The communication gateway verifies the network withdrawal request message according to the field structure of the network withdrawal request message to obtain a first verification result;

[0166] (D.3) When the first verification result indicates that the network exit request message has passed verification, the communication gateway transmits the network exit request message to the second domain management and control server corresponding to the second network device;

[0167] (D.4) The second domain management and control server deletes the data resources corresponding to the second network device according to the network exit request message;

[0168] (D.5) The second domain control server sends a data refresh request to the central control server, so that the central control server refreshes the data in the network device management system after receiving the data refresh request;

[0169] (D.6) The communication gateway deletes the management authority mapping relationship corresponding to the second network device in the domain relationship mapping table.

[0170] The second network device can be any network device that has joined the target domain network and is currently initiating a withdrawal request with the intention of withdrawing from or being removed from the current target domain network. The second network device may issue a withdrawal request message due to the device no longer needing to use the network resources, device failure, location change, or other management requirements.

[0171] The network withdrawal request message can be an encrypted message generated by the second network device and sent to the communication gateway, formally requesting to leave the current target domain network. The network withdrawal request message contains necessary information fields, such as a device identifier and reason, to ensure the system can correctly handle the withdrawal process.

[0172] The first verification result may be a result of the communication gateway performing a series of verifications (such as format checking and signature verification) on the content of the network withdrawal request message after receiving the message. The first verification result is used to determine whether to continue processing the network withdrawal request of the second network device.

[0173] The second domain control server may be the domain control server currently managing the second network device. The second domain control server receives the network exit request message forwarded by the communication gateway and performs corresponding cleanup operations on data resources related to the second network device.

[0174] The data resources may include but are not limited to configuration files, log records, session status, and other related information stored in the second domain management and control server related to the second network device.

[0175] For example, if the second network device a is a mobile router of enterprise A and needs to be removed from the internal network (i.e., the target domain network), the second network device a can encapsulate a disconnection request message containing the MAC address 00:A0:C9:14:C8:29 of the second network device a and the target domain network information, and send it to the communication gateway through the data transmission tunnel.

[0176] Furthermore, upon receiving the detach request message, the communication gateway may use a preset regularization rule to verify the fields in the detach request message, obtaining a first verification result to confirm the legitimacy and integrity of the detach request message. In some implementations, verification rules for different fields may be configured based on actual circumstances, and this embodiment of the present application does not impose specific limitations on this.

[0177] Furthermore, when the first verification result indicates that the network disconnect request message has passed verification, the communication gateway may forward the network disconnect request message to the second domain control server corresponding to the second network device a. Upon receiving the network disconnect request message, the second domain control server clears all configuration files, log records, and database entries related to the second network device a, and stops any associated tasks or services.

[0178] Furthermore, after the second domain control server has deleted all resource data related to the second network device a, it can send a data refresh request to the central control server through the communication interaction module, prompting the central control server to update the relevant information in its network device management system to ensure data consistency and accuracy.

[0179] Furthermore, when the central management and control server refreshes the data of the entire network, the communication gateway will also update the corresponding domain relationship mapping table and delete the management authority mapping relationship related to the second network device a.

[0180] Through the above method, the second network device can be successfully and safely removed from the target domain network, ensuring the security of the network environment and the effective management of resources. This not only maintains the stability and consistency of the system, but also improves the overall management and operation efficiency.

[0181] In some implementations, to achieve highly automated and refined verification of network disconnection request messages, regularization rules can be introduced to verify network disconnection request messages, thereby ensuring that each network disconnection request is accurately processed while enhancing the system's security protection capabilities. For example, (D.2) may include:

[0182] (D.2.1) The communication gateway obtains the verification hash table;

[0183] (D.2.2) The communication gateway extracts fields from the network exit request message according to the field structure to obtain multiple fields to be checked;

[0184] (D.2.3) The communication gateway performs regularization verification on the corresponding multiple fields to be verified based on the regularization rule corresponding to each field to be verified in the verification hash table to obtain a first verification result.

[0185] The validation hash table can be a data structure that stores field names and their corresponding regular expression rules, used to verify that each field in the logout request message conforms to the expected format and content requirements. Each entry in the validation hash table contains an identifier for the field to be verified and an associated regular expression or other form of validation rule. The validation hash table can be predefined by the system administrator based on security policies and service requirements, or automatically generated by the system using preset data, so that it can be loaded and used by the communication gateway when needed.

[0186] The field to be checked may be a specific information item or data element extracted from the network exit request message, and the field to be checked is a key component of the entire message.

[0187] The regular rule may be a text matching pattern, which is used to define the valid format of each field in the data message to ensure that the received data meets the expected standards.

[0188] Exemplarily, the fields to be checked may include a device identifier, timestamp, operation type, etc. When checking the network exit request message, the communication gateway will take out each field to be checked one by one and check it according to the preset regular rules. Each field to be checked has its own corresponding regular rule to ensure its legality and accuracy.

[0189] For example, when verifying a detach request message, a preset verification hash table can be loaded. The verification hash table contains each field to be verified and its corresponding regular expression. The communication gateway can then parse the detach request message, extract key fields (i.e., fields to be verified), such as mac_address, domain_name, and time_tmp. The corresponding regular expression is applied to each field. If all fields to be verified pass verification, the first verification result is considered passed.

[0190] Through the above method, the communication gateway can efficiently and accurately verify the legitimacy of the network exit request message, ensuring that only requests that meet the specifications can be further processed, thereby ensuring the security and reliability of the network.

[0191] In some implementations, to optimize network configuration and reduce unnecessary resource usage, when the second network device is the last network device managed by the second domain control server, the data transmission tunnel and network address translation route associated with the domain control server can be deleted via the communication gateway to optimize network configuration. For example, after (D.6), the following steps may also be included:

[0192] (E.1) The communication gateway obtains information about the second network device managed by the second domain management and control server;

[0193] (E.2) When the second network device information indicates that the second network device is the last network device managed by the second domain management and control server, the communication gateway deletes the network address translation route corresponding to the second network device.

[0194] The second network device information may be information on the number of network devices managed by the second domain management and control server.

[0195] For example, assume that the second network device a is the last network device managed by the second domain control server, its MAC address is 00:A0:C9:14:C8:29, its IP address is 192.168.1.100, it is connected to the communication gateway via a data transmission tunnel, and is assigned an internal IP address of 10.8.0.2. When the second network device a needs to be disconnected from the network, the communication gateway requests the second domain control server to obtain the list of devices currently under management, confirms that the second network device a is the last (i.e., the only one currently managed) device managed by the second domain control server, and then the communication gateway can delete the network address translation route corresponding to the second network device a, as well as the corresponding tunnel route, that is, delete the data transmission tunnel related to the network device managed by the second domain control server.

[0196] Through the above methods, the security of the network environment and the effective management of resources can be ensured, relevant resources can be released in time, and the accuracy of network configuration can be ensured.

[0197] Please refer to Figure 6 In some implementations, in order to provide a secure, orderly, and efficient method for handling cross-domain transfers of network devices, the communication gateway may be notified of the need for device transfer and provided with necessary configuration information to ensure that data loss does not occur during the device transfer process, enabling the device to quickly adapt to the new working environment and continue to provide stable services, thereby ensuring the accuracy and integrity of information transmission. For example, the network device management method may also include:

[0198] (F.1) The central control server transmits a first device transfer request message to the communication gateway, wherein the first device transfer request message includes registration configuration information of the third network device to be transferred and server information of the third domain control server to which the third network device needs to be transferred;

[0199] (F.2) The communication gateway verifies the first device transfer request message according to the field structure of the received first device transfer request message to obtain a second verification result;

[0200] (F.3) When the second verification result indicates that the transfer request message of the first device has passed verification, the communication gateway transfers the target data message subsequently transmitted by the third network device to the target queue for temporary storage;

[0201] (F.4) The communication gateway parses the first device transfer request message and determines the third domain control server to which the third network device is to be transferred;

[0202] (F.5) The communication gateway extracts the server information of the destination domain control server from the first device transfer request message, and modifies the management authority mapping relationship between the third network device and the historically associated domain control server in the domain relationship mapping table based on the server information, thereby establishing an updated management authority mapping relationship between the third network device and the third domain control server;

[0203] (F.6) The historically associated domain control server deletes the device identification information corresponding to the third network device;

[0204] (F.7) The third domain control server saves the device identification information corresponding to the third network device, and transfers the target data message temporarily stored in the target queue to the third domain control server.

[0205] The first device transfer request message may be a special message generated by the central control server and sent to the communication gateway, indicating the transfer of a specific network device (the third network device) from the current management domain to another designated management domain. The first device transfer request message includes the registration configuration information of the device to be transferred and relevant information about the new domain management server.

[0206] The third network device may be a specific network device that is planned to be transferred from one domain network to another domain network for management. The third network device may need to change its domain due to business needs, location change or other management reasons.

[0207] The third domain control server can be a new domain control server that will take over the third network device. The third domain control server is responsible for receiving and managing the devices transferred to the domain, ensuring that these network devices can smoothly integrate into the new network environment and providing necessary management and monitoring services.

[0208] The server information may include but is not limited to the IP address, port number, access rights and other detailed information of the third domain control server, which is used to clearly identify and connect to the domain control server.

[0209] Among them, the second verification result can be the verification result obtained by the communication gateway after receiving the first device transfer request message, by performing a series of verifications (such as format checking, signature verification, etc.) on the content of the first device transfer request message, to decide whether to continue processing this transfer request.

[0210] The target data packets can be data packets generated by the third-party network device during or after the migration process and need to be forwarded to the new third-domain management and control server. The target data packets can contain important information such as device status updates and log records, and must be properly processed to ensure the normal operation and service continuity of the third-party network device.

[0211] The target queue can be a buffer in the communication gateway for temporarily storing data packets to be processed. When the device is being transferred, all data packets from the third network device will be temporarily stored in this queue until the transfer is completed and then forwarded to the new third domain control server.

[0212] In some implementations, the central control server can globally evaluate and decide which devices need to be transferred between domains, and centrally manage all network devices to ensure that all operations are performed within a controlled range, ensuring data consistency and avoiding confusion that may be caused by decentralized decision-making.

[0213] For example, assume that there is a large-scale network, which includes multiple domain control servers, a central control server and a communication gateway. Now, it is necessary to transfer a third network device (represented by MR_Z) from the domain network control range of a second domain control server AR_C to the domain network control range of a third domain control server AR_D. First, the central control server can encapsulate a first device transfer request message, which contains the registration configuration information of MR_Z (such as device name, IP address, etc.) and the server information of the third domain control server AR_D (such as IP address, etc.). After the above information is encapsulated, the first device transfer request message can be obtained. The central control server can send the first device transfer request message to the communication gateway through the communication interaction module of the agent program. The communication gateway performs regular rule verification on multiple preset fields in the first device transfer request message based on the field structure of the received first device transfer request message to obtain a second verification result. If it is determined that the message format of the first device transfer request message is correct and the information is complete, a second verification result of passing the verification can be obtained.

[0214] Furthermore, when the second verification result indicates that the first device transfer request message has passed verification, the communication gateway begins blocking newly generated target data messages from MR_Z and transfers the target data messages to a target queue for temporary storage to prevent the newly generated target data messages from being lost during the device transfer process. Furthermore, the target queue can be set in the communication gateway or in a storage module uniformly maintained by the system.

[0215] Furthermore, the communication gateway can parse the verified first device transfer request message, extract the server information of the third network device to be transferred, such as device identification information, device IP address, etc., and determine the third domain management server AR_D to which the third network device will be transferred.

[0216] Furthermore, since the domain relationship mapping table of the communication gateway stores the management authority mapping relationship between the third network device and the historically associated domain control server AR_C, and after the third network device MR_Z is transferred, AR_C will no longer have the authority to manage MR_Z, it is necessary to modify the management authority mapping relationship, that is, to modify the management authority mapping relationship between MR_Z and AR_C to the management authority mapping relationship between MR_Z and AR_D.

[0217] Furthermore, since AR_C, with which MR_Z was historically associated, no longer has management authority over MR_Z, the device identification information and corresponding data resources associated with MR_Z can be deleted from AR_C. When the third network device MR_Z is the last network device managed by AR_C, the communication gateway also needs to delete the network address translation route corresponding to AR_C. If MR_Z is not the last network device managed by AR_C, deletion is not required.

[0218] In some implementations, before deleting the device identification information and corresponding data resources related to MR_Z in AR_C, the data resources can be copied or transferred to the origin field of the database table for backup, so that the relevant historical information of MR_Z can be queried when needed, to facilitate recovery and backtracking of domain migration operations.

[0219] Furthermore, after receiving the verified first device transfer request message, the third domain control server AR_D can extract the device identification information (e.g., device identification information, etc.) of the third network device MR_Z from the first device transfer request message and save it. Furthermore, AR_D can save the target data message of MR_Z temporarily stored in the target queue.

[0220] Furthermore, after the third domain management and control server AR_D saves the device identification information and target data message of MR_Z, it can request the central management and control server to refresh the visualization status of the entire network through the communication interaction module to facilitate resource update.

[0221] Through centralized management and strict verification mechanisms, network devices can be safely and orderly migrated between different management domains, while maintaining the consistency and stability of the entire network. While improving management efficiency, it also enhances the security and reliability of the system.

[0222] In some embodiments, in order to achieve efficient resource utilization and simplified management, during the device transfer process, the communication gateway may add corresponding network address translation routes based on the number and specific circumstances of the devices to be transferred, so as to flexibly and efficiently adjust the configuration of the network address translation routes according to different circumstances. Exemplary network device management methods may also include:

[0223] (G.1) When the third network device to be transferred is a single network device, the communication gateway adds a network address translation route for the third network device based on the Internet Protocol address of the third network device;

[0224] (G.2) When the number of the plurality of third network devices to be transferred exceeds a preset threshold, the communication gateway adds a network address translation route for the plurality of third network devices according to the network segment address corresponding to any third network device.

[0225] A network segment address is a network identifier used to identify a range of IP addresses. A network segment address consists of a network portion and a subnet mask, defining a specific subnet or network segment. For example, in IPv4, "192.168.1.0 / 24" indicates that all IP addresses from "192.168.1.0" to "192.168.1.255" belong to the same network segment. Therefore, "192.168.1.0 / 24" belongs to the network segment from "192.168.1.0" to "192.168.1.255."

[0226] For example, when device migration in a test environment or device adjustment under specific business needs requires manual migration of a single third network device (such as mobile router MR_Z) to a new management domain, the communication gateway can add a separate network address translation route accurate to IP for MR_Z based on its IP address (Internet Protocol address) to ensure that other devices are not affected and the migration process is more controllable.

[0227] For example, when a domain-side router fails and triggers an emergency strategy involving the automatic migration of all network devices in the domain, considering that configuring the network address translation route for each network device one by one will be very time-consuming and inefficient, since network devices in the same domain network usually share the same network segment address, a network segment-level network address translation route is sufficient to ensure that all data packets of third network devices can be correctly forwarded to the new domain control server. Therefore, by adding a network address translation route covering the entire network segment, all related network devices can be processed at one time to improve configuration efficiency.

[0228] Furthermore, whether multiple network devices with the same network segment address need to be migrated simultaneously can be determined by determining whether the number of the multiple third network devices to be migrated exceeds a preset threshold. For example, the preset threshold can be set to 3, 5, 10, etc. This application does not limit the specific value.

[0229] In some embodiments, when the number of multiple third network devices to be transferred exceeds a preset threshold, whether it is necessary to add a corresponding network address translation route to each third network device one by one, or to uniformly add a network address translation route to the network segment addresses corresponding to multiple third network devices, can also be determined by the technicians themselves.

[0230] Through the above methods, the communication gateway can flexibly configure network address translation routes according to different migration scenarios, improving management and operation efficiency.

[0231] In some implementations, in order to quickly and safely transfer the affected network devices to other normally functioning domain control servers when a domain control server fails, the load of the normally functioning domain control servers may be used to select the server most suitable for taking over the fourth network device, thereby ensuring service continuity and network stability, and improving resource utilization and management efficiency. For example, the network device management method may further include:

[0232] (H.1) When a domain control server fails, the central control server determines a fourth network device that has a management authority mapping relationship with the failed domain control server;

[0233] (H.2) obtaining, through the central control server, available loads corresponding to multiple normally operating domain control servers, and determining at least one fourth domain control server from the multiple domain control servers based on the available loads;

[0234] (H.3) The central control server transmits a second device transfer request message to the communication gateway; wherein the second device transfer request message includes the registration configuration information of the fourth network device to be transferred, and the server information of the fourth domain control server to which the fourth network device needs to be transferred.

[0235] The fourth network device may be a network device originally managed by the failed domain control server. Due to the problem with its original domain control server, the fourth network device needs to be transferred to another normally functioning domain control server for management and monitoring to ensure that it can continue to operate normally and provide services.

[0236] The fourth domain control server can be one or more new domain control servers selected from multiple normally operating domain control servers to take over the fourth network device affected by the failure of the original management server. The fourth domain control server de1 is selected based on the available load to ensure that the new domain control server can effectively handle the additional management tasks without being overloaded.

[0237] The second device transfer request message may be a data message generated by the central control server and sent to the communication gateway, instructing the transfer of a specific fourth network device from the failed domain control server to a selected fourth domain control server. The second device transfer request message includes the registration configuration information of the device to be transferred and information about the new domain control server, ensuring that the transfer operation can be carried out smoothly.

[0238] For example, consider a large network divided into multiple domain networks, each with its own domain control server. If the second domain control server (AR_B) experiences a failure, affecting the fourth network devices MR_G, MR_W, and so on that it manages, the central control server will identify all fourth network devices that have a management permission mapping relationship with the failed domain control server AR_B.

[0239] Furthermore, the central control server can obtain the available load corresponding to multiple domain control servers in normal operation, and select the domain control server with the largest available load, such as AR_X, as the fourth domain control server to take over the fourth network devices such as MR_G and MR_W.

[0240] Furthermore, the central control server can generate a second device transfer request message based on the registration configuration information of MR_G, MR_W, etc., the server information of the fourth domain control server AR_X to which the fourth network device needs to be transferred, and the management authority mapping relationship between the fourth network device and AR_X, and send the second device transfer request message to the communication gateway through the communication interaction module.

[0241] In some embodiments, after the communication gateway receives the second device transfer request message, the communication gateway parses the second device transfer request message and determines the fourth domain control server to which the fourth network device is transferred. Thereafter, the communication gateway extracts the server information of the fourth domain control server from the second device transfer request message, and based on the server information, modifies the management authority mapping relationship between the fourth network device and the faulty domain control server in the domain relationship mapping table to establish an updated management authority mapping relationship between the fourth network device and the fourth domain control server. The faulty domain control server deletes the device identification information corresponding to the fourth network device, and the fourth domain control server saves the device identification information corresponding to the fourth network device, and transfers the target data message temporarily stored in the target queue to the fourth domain control server. The details of the specific network device transfer have been expanded above and will not be repeated here.

[0242] Through the above method, the affected network devices can be quickly transferred to the new domain control server when the domain control server fails, ensuring service continuity and network stability, while improving resource utilization and management efficiency.

[0243] The present application also provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the above-mentioned network device management method when executing the computer program. The computer device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.

[0244] See also Figure 7 , Figure 7 The hardware structure of a computer device according to another embodiment is shown. The computer device includes:

[0245] The processor 71 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.

[0246] The memory 72 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 72 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program codes are stored in the memory 72 and are called by the processor 71 to execute the network device management method of the embodiments of this application.

[0247] Input / output interface 73, used for information input and output;

[0248] Communication interface 74, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, Wi-Fi, Bluetooth, etc.);

[0249] bus 75 , which transmits information between the various components of the device (e.g., processor 71 , memory 72 , input / output interface 73 , and communication interface 74 );

[0250] The processor 71 , the memory 72 , the input / output interface 73 and the communication interface 74 are connected to each other in communication within the device via a bus 75 .

[0251] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned network device management method is implemented.

[0252] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0253] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0254] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0255] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0256] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0257] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0258] It should be understood that in this application, "at least one (item)" and "several" refer to one or more, and "plurality" refers to two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0259] In the several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the above units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0260] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0261] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0262] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store programs.

[0263] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.

Claims

1. A network device management method, characterized in that: Applied to a network device management system comprising a central control server, multiple domain control servers, and a communication gateway, the method comprises: The communication gateway obtains a login authentication message transmitted by the first network device via a data transmission tunnel; wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports a communication connection between any network device and a corresponding domain control server; The communication gateway performs key parsing on the login authentication message to obtain a key to be verified of the first network device; The communication gateway determines, based on a preset domain relationship mapping table, a first domain control server for controlling the first network device, and reads a control authentication key generated by the first domain control server for the first network device; The preset domain relationship mapping table includes a mapping relationship between the management authority of each domain control server and different network devices, and the management authority of each domain control server for the corresponding network device is determined and granted by the central control server based on the registration configuration information of the corresponding network device; When the communication gateway compares the key to be verified with the management and control authentication key and finds that the key is consistent with the management and control authentication key, the communication gateway incorporates the first network device into the target domain network controlled by the first domain management and control server.

2. The network device management method according to claim 1, wherein: Before the communication gateway obtains the login authentication message transmitted by the first network device via the data transmission tunnel, the method further includes: The central control server obtains registration configuration information corresponding to the first network device and saves the registration configuration information; wherein the first network device is a communication device to be incorporated into the domain network; The central control server determines, based on the registration configuration information, a first domain control server having a management authority mapping relationship with the first network device; Encapsulating the registration configuration information and the management authority mapping relationship into a first message, and transmitting the first message to the first domain management and control server and the communication gateway respectively; The first domain management and control server extracts the device identification information of the first network device from the first message and saves the device identification information; The communication gateway extracts the management authority mapping relationship from the first message and stores the management authority mapping relationship in a domain relationship mapping table.

3. The network device management method according to claim 2, wherein: After the communication gateway extracts the management authority mapping relationship from the first message and stores the management authority mapping relationship in the domain relationship mapping table, the method further includes: The communication gateway obtains first network device information managed by the first domain management and control server; When the first network device information indicates that the first network device is the first network device managed by the first domain management server, the communication gateway adds a network address translation route for the first network device.

4. The network device management method according to claim 1, wherein: Before the communication gateway obtains the login authentication message transmitted by the first network device via the data transmission tunnel, the method further includes: The communication gateway configures communication data of the data transmission tunnel through a pre-configured open virtual private network server, wherein the communication data includes at least a port address for receiving data packets, a tunnel transmission protocol, a tunnel mode, a target certificate storage path, a certificate verification algorithm path, and a target network segment allowed to be accessed by the first network device; After the open virtual private network client pre-installed on the first network device and the open virtual private network server are both turned on, a data transmission tunnel is formed between the communication gateway and the first network device, wherein the open virtual private network client is configured with at least the Internet Protocol address and the port address of the open virtual private network server.

5. The network device management method according to claim 1, wherein: The method further comprises: The communication gateway receives a network exit request message sent by the second network device via the corresponding data transmission tunnel; The communication gateway verifies the network withdrawal request message according to the field structure of the network withdrawal request message to obtain a first verification result; When the first verification result indicates that the network withdrawal request message passes verification, the communication gateway transmits the network withdrawal request message to the second domain management and control server corresponding to the second network device; The second domain management and control server deletes the data resources corresponding to the second network device according to the network exit request message; The second domain control server sends a data refresh request to the central control server, so that the central control server refreshes data on the network device management system after receiving the data refresh request; The communication gateway deletes the management authority mapping relationship corresponding to the second network device in the domain relationship mapping table.

6. The network device management method according to claim 5, characterized in that: The communication gateway verifies the network withdrawal request message according to the field structure of the network withdrawal request message to obtain a first verification result, including: The communication gateway obtains a verification hash table; The communication gateway extracts fields from the network exit request message according to the field structure to obtain a plurality of fields to be checked; The communication gateway performs regularization verification on the corresponding multiple fields to be verified based on the regularization rule corresponding to each field to be verified in the verification hash table to obtain a first verification result.

7. The network device management method according to claim 5, characterized in that: After the communication gateway deletes the management authority mapping relationship corresponding to the second network device in the domain relationship mapping table, the method further includes: The communication gateway obtains the second network device information managed by the second domain management and control server; When the second network device information indicates that the second network device is the last network device managed by the second domain management and control server, the communication gateway deletes the network address translation route corresponding to the second network device.

8. The network device management method according to claim 1, wherein: The method further comprises: The central control server transmits a first device transfer request message to the communication gateway, wherein the first device transfer request message includes registration configuration information of the third network device to be transferred, and server information of the third domain control server to which the third network device needs to be transferred; The communication gateway verifies the first device transfer request message according to the field structure of the received first device transfer request message to obtain a second verification result; When the second verification result indicates that the first device transfer request message has passed verification, the communication gateway transfers the target data message subsequently transmitted by the third network device to the target queue for temporary storage; The communication gateway parses the first device transfer request message to determine the third domain control server to which the third network device is transferred; The communication gateway extracts server information of the destination domain control server from the first device transfer request message, and modifies the management authority mapping relationship between the third network device and the historically associated domain control server in the domain relationship mapping table based on the server information, so as to establish an updated management authority mapping relationship between the third network device and the third domain control server; The historically associated domain control server deletes the device identification information corresponding to the third network device; The third domain control server stores the device identification information corresponding to the third network device, and transfers the target data message temporarily stored in the target queue to the third domain control server.

9. The network device management method according to claim 8, characterized in that: The method further comprises: When the third network device to be transferred is a single network device, the communication gateway adds a network address translation route for the third network device according to the Internet Protocol address of the third network device; When the number of the plurality of third network devices to be transferred exceeds a preset threshold, the communication gateway adds a network address translation route for the plurality of third network devices according to a network segment address corresponding to any third network device.

10. The network device management method according to claim 8, wherein: The method further comprises: When a domain control server fails, the central control server determines a fourth network device that has a management authority mapping relationship with the failed domain control server; Obtaining, through the central control server, available loads corresponding to a plurality of normally operating domain control servers, and determining at least one fourth domain control server from the plurality of domain control servers based on the available loads; The central control server transmits a second device transfer request message to the communication gateway; wherein, the second device transfer request message includes the registration configuration information of the fourth network device to be transferred, and the server information of the fourth domain control server to which the fourth network device needs to be transferred.

11. A network device management system, characterized in that: It includes a central control server, multiple domain control servers, and communication gateways, including: The central control server is used to determine the management authority granted to each domain control server for the corresponding network device based on the registration configuration information of the corresponding network device; The domain control server is used to manage corresponding network devices; The communication gateway is configured to obtain a login authentication message transmitted by the first network device via a data transmission tunnel, perform key parsing on the login authentication message, and obtain a key to be verified of the first network device, wherein the data transmission tunnel is generated based on an open virtual private network protocol, and the open virtual private network protocol supports a communication connection between any network device and a corresponding domain control server; The communication gateway is further configured to determine a first domain control server for controlling the first network device based on a preset domain relationship mapping table, and read a control authentication key generated by the first domain control server for the first network device, wherein the preset domain relationship mapping table includes a mapping relationship between management permissions of each domain control server for different network devices; The communication gateway is further configured to, when the key to be verified is consistent with the management and control authentication key, merge the first network device into the target domain network controlled by the first domain management and control server.

12. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the network device management method according to any one of claims 1 to 10 when executing the computer program.

13. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the network device management method according to any one of claims 1 to 10 is implemented.

Citation Information

Patent Citations

  • Method and device for controlling access of mobile terminal to enterprise intranet

    CN115277237A

  • Metropolitan Internet of Things system, security authentication method and device thereof, and storage medium

    CN116669032A