Intranet device accesses extranet method, device, equipment, medium and program product
By replacing the access link with an internal network server and using a secure channel to obtain external network data, the problem of internal network devices being unable to access the external network is solved, achieving secure and compatible external network data acquisition.
Patent Information
- Application Number
- CN202411964039.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2044-12-30
AI Technical Summary
In existing technologies, intranet devices cannot obtain external network data while ensuring network security. Firewalls filter out requests to access the external network, and intranet servers also do not have permission to access external network data.
After receiving an access request from an internal network device, the internal network server determines whether it contains an external network access identifier, replaces the internal network access link with an external network access link, and sends the request to the external network server through a secure communication channel. After obtaining the external network data, it sends it back to the internal network device.
This allows internal network devices to obtain external network data while ensuring network security, without requiring modifications to the internal network devices, thus improving compatibility.
Smart Images

Figure CN119892431B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and in particular to a method and device for accessing an external network by an internal network device, a medium, and a program product. BACKGROUND
[0002] In order to ensure data security and network security, a network is usually divided into an internal network and an external network, and an internal network device can only obtain internal network data.
[0003] In the prior art, after an internal network device sends an access request, a firewall checks the access request and filters out a request for accessing an external network, and only allows a request for accessing an internal network to pass. After an internal network server receives the access request, the internal network server sends corresponding internal network data to the internal network device. Moreover, the internal network server has no access right to the external network and cannot obtain external network data.
[0004] Therefore, there is an urgent need for a method for accessing an external network by an internal network device, which can enable an internal network device to obtain external network data while ensuring network security. SUMMARY
[0005] Embodiments of the present application provide a method and device for accessing an external network by an internal network device, a medium, and a program product, which can enable an internal network device to obtain external network data while ensuring network security.
[0006] In a first aspect, a method for accessing an external network by an internal network device is provided, and the method is applied to an internal network server and includes the following steps.
[0007] Receiving an internal network access request sent by an internal network device, wherein the internal network access request includes a first internal network access link, and the first internal network access link includes an address of the internal network server.
[0008] If an external network access identifier is included in the first internal network access link, replacing the first internal network access link with a first external network access link according to a stored link replacement table to obtain an external network access request.
[0009] Sending the external network access request to an external network server.
[0010] Receiving external network data sent by the external network server.
[0011] Sending the external network data to the internal network device.
[0012] In a possible implementation, before the step of sending the external network data to the internal network device, the method further includes the following steps.
[0013] determining a second intranet access link corresponding to each second extranet access link in the extranet data, each of the second intranet access links comprising the extranet access identifier;
[0014] for each second extranet access link in the extranet data, replacing the second extranet access link with the second intranet access link corresponding to the second extranet access link to obtain updated extranet data;
[0015] the sending of the extranet data to the intranet device comprises:
[0016] the sending of the updated extranet data to the intranet device.
[0017] In a possible implementation, the determining of the second intranet access link corresponding to each second extranet access link in the extranet data comprises:
[0018] for each second extranet access link, replacing an extranet address in the second extranet access link with an address of the intranet server and adding the extranet access identifier to obtain a first link corresponding to the second extranet access link;
[0019] for each first link corresponding to each second extranet access link, the following processing is performed in sequence:
[0020] judging whether the first link exists in the link replacement table;
[0021] if the first link does not exist in the link replacement table, taking the first link as the second intranet access link corresponding to the second extranet access link, and storing the second extranet access link and the first link in the link replacement table;
[0022] if the first link exists in the link replacement table, performing character adding processing on the first link to obtain a second link that does not exist in the link replacement table, taking the second link as the second intranet access link corresponding to the second extranet access link, and storing the second extranet access link and the second link in the link replacement table.
[0023] In a possible implementation, the sending of the extranet access request to an extranet server comprises:
[0024] sending the extranet access request to an extranet server through a preset secure communication channel;
[0025] the receiving of the extranet data sent by the extranet server comprises:
[0026] receiving the extranet data sent by the extranet server through the preset secure communication channel.
[0027] In a possible implementation, the preset secure communication channel includes any one of a secure sockets layer (SSL) channel, a transport layer security (TLS) channel, a virtual private network (VPN) channel, and an encrypted tunnel.
[0028] In a possible implementation, the method further includes:
[0029] If the external network access identifier is not included in the first internal network access link, obtaining internal network data according to the first internal network access link;
[0030] sending the internal network data to the internal network device.
[0031] In a second aspect, an embodiment of the present application provides an internal network device accessing an external network apparatus, including:
[0032] a receiving module configured to receive an internal network access request sent by an internal network device, the internal network access request including a first internal network access link, and the first internal network access link including an address of an internal network server;
[0033] a processing module configured to, if an external network access identifier is included in the first internal network access link, replace the first internal network access link with a first external network access link according to a stored link replacement table, to obtain an external network access request;
[0034] a sending module configured to send the external network access request to an external network server;
[0035] the receiving module is further configured to receive external network data sent by the external network server;
[0036] the sending module is further configured to send the external network data to the internal network device.
[0037] In a third aspect, an embodiment of the present application provides a server, including:
[0038] a processor, a memory, and a communication interface;
[0039] the memory is configured to store executable instructions of the processor;
[0040] The processor is configured to execute the internal network device accessing an external network method according to any one of the first aspect via executing the executable instructions.
[0041] In a fourth aspect, an embodiment of the present application provides a readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the internal network device accessing an external network method according to any one of the first aspect.
[0042] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, which, when executed by a processor, is used to implement the method for accessing an external network by an internal network device according to any one of the first aspect.
[0043] The method, device, equipment, medium and program product for accessing an external network by an internal network device provided by the embodiments of the present application can replace the first internal network access link with the first external network access link if the first internal network access link includes the external network access identifier, so as to obtain an external network access request. Then, the external network access request is sent to an external network server, and after receiving the external network data sent by the external network server, the external network data is sent to the internal network device. The present application can not only enable the internal network device to obtain the external network data, but also ensure network security. BRIEF DESCRIPTION OF DRAWINGS
[0044] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0045] Figure 1 An application scenario diagram of the method for accessing an external network by an internal network device provided by the present application is shown in the following figure.
[0046] Figure 2 A flowchart of the first embodiment of the method for accessing an external network by an internal network device provided by the present application is shown in the following figure.
[0047] Figure 3 A flowchart of the second embodiment of the method for accessing an external network by an internal network device provided by the present application is shown in the following figure.
[0048] Figure 4 A structure diagram of the device for accessing an external network by an internal network device provided by the present application is shown in the following figure.
[0049] Figure 5 A structure diagram of a server provided by the present application is shown in the following figure.
[0050] The above figures have shown the specific embodiments of the present application, which will be described in more detail in the following. These figures and the written description are not intended to limit the scope of the present application concept in any way, but to illustrate the present application concept to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0051] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals represent like elements, unless the context dictates otherwise. The following description of exemplary embodiments is not representative of all embodiments consistent with the present application. Instead, they are merely examples of apparatus and methods consistent with some aspects of the present application as detailed in the appended claims.
[0052] The terms "first", "second", "third", "fourth" and the like, if any, used in the description and in the claims of the present application as well as above-mentioned drawings (if any) are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of the terms so construed herein is merely for convenience and illustrative purposes and that the application can be implemented in other sequences, except for the steps disclosed in the claims. Further, the terms "comprise", "include", "comprising", "including" and the like, as used with respect to the components of the processes, methods and devices of the application, are intended to mean "consist at least in part of", "include at least in part of", "comprise at least in part of", "include at least in part of", "comprising at least in part of", "including at least in part of", and the like, such that when the phrase is used in this manner, the process, method or device includes the stated feature, but is not limited to those features.
[0053] In order to improve data security and network security, an internal network, referred to as an intranet, is usually set up, and intranet devices in the intranet can only obtain intranet data.
[0054] In the prior art, after an intranet device sends an access request, a firewall checks the access request and filters out requests for accessing the extranet and only allows requests for accessing the intranet. That is, the firewall determines whether the access link in the access request includes the address of an intranet server, and if the access link includes the address of the intranet server, it is determined that the access request is a request for accessing the intranet, and the access request is allowed.
[0055] After receiving the access request, the intranet server sends corresponding intranet data to the intranet device. Moreover, the intranet server has no access right to the extranet and cannot obtain extranet data.
[0056] Therefore, there is an urgent need for a method for an intranet device to access the extranet, which can enable the intranet device to obtain extranet data while ensuring network security.
[0057] To address the problems existing in the prior art, the inventors, during their research on methods for intranet devices to access the external network, discovered that since firewalls only allow requests to access the intranet, requests to access the external network can be modified to resemble intranet access requests, including an external network access identifier. When this access request reaches the intranet server, the intranet server can determine that the request is for accessing the external network based on the external network access identifier. Therefore, to solve the problem of the intranet server lacking permission to access the external network, the intranet server modifies the access request back into an external network access request and sends it to the external network server. The external network server then retrieves the external network data and sends it back to the intranet server, which in turn sends the external network data to the intranet device. Based on the above inventive concept, the intranet device access to the external network scheme of this application was designed.
[0058] For example, Figure 1 This is a schematic diagram illustrating an application scenario for the method of accessing the external network by an intranet device provided in this application, such as... Figure 1 As shown, this application scenario may include: intranet device 11, intranet device 12, firewall 13, intranet server 14, and extranet server 15.
[0059] exist Figure 1 In the application scenario shown, the intranet device 12 sends an external network access request. The external network access request does not include the address of the intranet server 14, so the firewall 13 blocks the external network access request.
[0060] Internal network device 11 sends an internal network access request. The internal network access request includes a first internal network access link, which includes the address of internal network server 14. Therefore, firewall 13 allows the internal network access request, and internal network server 14 can receive the internal network access request.
[0061] Then, the intranet server 14 determines that the first intranet access link includes an external access identifier, indicating that the intranet device 12 wants to obtain external data. The intranet server 14 replaces the first intranet access link with the first external access link according to the stored link replacement table, obtains the external access request, and then sends the external access request to the external server 15.
[0062] After obtaining external network data based on the external network access request, the external network server 15 sends the external network data to the internal network server 14.
[0063] The intranet server 14 then transmits the external network data to the intranet device 12, which can then obtain the external network data.
[0064] It should be noted that, Figure 1 This is merely a schematic diagram illustrating one application scenario provided by an embodiment of this application. This embodiment does not necessarily represent... Figure 1 The document does not limit the actual form of the various devices included, nor does it specify the form of the devices.Figure 1 The manner of interaction between the internal network device and the external network device is limited, and in a specific application of the scheme, the actual needs can be set.
[0065] The technical scheme of the present application will be described in detail below through specific embodiments. It should be noted that the following specific embodiments can be combined with each other, and the same or similar concepts or processes can not be described again in some embodiments.
[0066] Figure 2 The flowchart of the internal network device accessing the external network method provided in the present application is shown in the embodiment of the present application, which describes the case where the internal network server replaces the first internal network access link in the internal network access request with the first external network access link, and then sends the external network data obtained in combination with the external network server to the internal network device. The method in the present embodiment can be realized by software, hardware or a combination of software and hardware. As shown in the figure, the internal network device accessing the external network method specifically includes the following steps: Figure 2
[0067] S201: receiving an internal network access request sent by an internal network device.
[0068] When the internal network device needs to obtain external network data, an internal network access request also needs to be sent to ensure data security and network security. The internal network access request includes a first internal network access link, and the first internal network access link includes the address of the internal network server. Since the internal network access request includes the address of the internal network server, the internal network access request will be sent to the internal network server through the firewall.
[0069] In this step, the internal network server can receive the internal network access request after the internal network device sends the internal network access request.
[0070] It should be noted that the internal network access request can be input by a user, or can be obtained by modifying an actual external network access request by the internal network device, or can be obtained by modifying an actual external network access request by the internal network service, and then sent to the internal network device.
[0071] S202: If the first internal network access link includes an external network access identifier, replace the first internal network access link with a first external network access link according to the stored link replacement table to obtain an external network access request.
[0072] In this step, in order to determine whether the internal network access request is a real request to access the internal network or a modified request to access the external network, the internal network server needs to judge whether the first internal network access link in the internal network access request includes an external network access identifier after receiving the internal network access request.
[0073] If the intranet server determines that the first intranet access link includes the extranet access identifier, it indicates that the intranet access request is a modified actual access extranet request. In order to obtain extranet data, the first intranet access link is replaced by the first extranet access link according to the stored link replacement table, and the extranet access request is obtained.
[0074] It should be noted that the way of determining whether the first intranet access link includes the extranet access identifier can be: determining whether the specified position in the first intranet access link is the extranet access identifier. The specified position can be the first position, the last position, the n-th position, the first position to the n-th position, the n-th position to the m-th position, the m-th position to the last position; the extranet access identifier can be / maps, outernet, 1, etc.; n and m can be 2, 5, 7, 9, etc. The application embodiments do not limit the specified position, the extranet access identifier, n and m, which can be determined according to actual conditions.
[0075] For example, Table 1 is a link replacement table provided by the application.
[0076] Table 1
[0077] Intranet access link Extranet access link http: / / ABCdef / maps http: / / 12345def http: / / ABCJKIF / maps http: / / 79364JKIF http: / / ABCHUF / maps http: / / 45801HUF
[0078] As shown in Table 1, ABC in the intranet access link is the address of the intranet server, and / maps is the extranet access identifier. The first intranet access link is http: / / ABCdef / maps, and the corresponding first extranet access link is found through the link replacement table http: / / 12345def.
[0079] It should be noted that Table 1 is only an example of a link replacement table, and the application embodiments do not limit the link replacement table, which can be determined according to actual conditions.
[0080] It should be noted that if the intranet server determines that the first intranet access link does not include the extranet access identifier, it indicates that the intranet access request is a real access intranet request, and then the intranet data is obtained according to the first intranet access link, and then the intranet data is sent to the intranet device.
[0081] S203: Send the extranet access request to the extranet server.
[0082] In this step, after the intranet server obtains the extranet access request, since the intranet server has no access to the extranet, the extranet access request is sent to the extranet server.
[0083] After the extranet server receives the extranet access request, the extranet data is obtained according to the extranet access request, and then the extranet data is sent to the intranet server.
[0084] It should be noted that, in order to ensure the security of the external network access request and the external network data, the internal network server sends the external network access request to the external network server through a preset secure communication channel; the external network server sends the external network data to the internal network server through a preset secure communication channel.
[0085] The preset secure communication channel includes any one of a Secure Sockets Layer (SSL) channel, a Transport Layer Security (TLS) channel, a Virtual Private Network (VPN) channel, and an encrypted tunnel, and the embodiments of the present application do not limit the preset secure communication channel, which can be determined according to actual conditions.
[0086] S204: After receiving the external network data sent by the external network server, the external network data is sent to the internal network device.
[0087] In this step, after the external network server sends the external network data to the internal network server, the internal network server can receive the external network data, and then send the external network data to the internal network device, so that the internal network device can obtain the external network data.
[0088] It should be noted that, in order to ensure the security of the external network data, the external network server sends the external network data to the internal network server through a preset secure communication channel, that is, the internal network server receives the external network data sent by the external network server through a preset secure communication channel.
[0089] The internal network device access external network method provided by the embodiment, after the internal network server receives the internal network access request sent by the internal network device, if it is determined that the first internal network access link in the internal network access request includes the external network access identifier, the first internal network access link is replaced with the first external network access link to obtain the external network access request. Further, the external network access request is sent to the external network server, and after receiving the external network data sent by the external network server, the external network data is sent to the internal network device. The present application replaces the first internal network access link with the first external network access link, and uses the external network server to obtain the external network data, so that the internal network device and the internal network server are not exposed to the external network, which not only enables the internal network device to obtain the external network data, but also ensures network security. Moreover, no changes need to be made to the internal network device, improving compatibility.
[0090] Figure 3 The flowchart of the internal network device access external network method provided by the second embodiment of the present application is based on the above-mentioned embodiments, and the present embodiment explains the case where the second external network access link in the external network data is replaced before the internal network server sends the external network data to the internal network device. As shown in FIG. 6, the internal network server receives the internal network access request sent by the internal network device, and determines whether the first internal network access link in the internal network access request includes the external network access identifier. If the first internal network access link includes the external network access identifier, the first internal network access link is replaced with the first external network access link to obtain the external network access request. Further, the external network access request is sent to the external network server, and after receiving the external network data sent by the external network server, the external network data is sent to the internal network device. Figure 3As shown, the method for the intranet device to access the extranet specifically includes the following steps:
[0091] S301: Determine the second intranet access link corresponding to each second extranet access link in the extranet data.
[0092] In this step, after the intranet server receives the extranet data sent by the extranet server, since there may be extranet access links in the extranet data, if they are not processed, subsequent users will not be able to obtain the corresponding extranet data when clicking the extranet access link in the intranet device, so the extranet data needs to be processed.
[0093] First, the second intranet access link corresponding to each second extranet access link in the extranet data is determined, and each second intranet access link includes an extranet access identifier. The link that does not include the intranet server address is the second extranet access link.
[0094] Specifically, for each second extranet access link, the extranet address in the second extranet access link is replaced with the address of the intranet server, and an extranet access identifier is added to obtain the first link corresponding to the second extranet access link.
[0095] It should be noted that the position of adding the extranet access identifier can be before the first position, after the last position, between the first position and the second position, or between the Kth position and the K+1th position in the second extranet access link after replacing the extranet address. K can be 2, 4, 7, etc. The application embodiments do not limit the position of adding the extranet access identifier and K, which can be determined according to actual conditions.
[0096] For example, the second extranet access link is http: / / 07943lmn, where 07943 is the extranet address, the address of the intranet server is ABC, and the extranet access identifier is / maps, so the first link is http: / / ABClmn / maps.
[0097] After obtaining the first link corresponding to each second extranet access link, in order to prevent the subsequent replacement from being unable to be replaced back due to repeated links, the first link needs to be processed again.
[0098] In turn, for each first link corresponding to the second extranet access link, the following processing is performed:
[0099] Determine whether the first link exists in the link replacement table.
[0100] If the first link does not exist in the link replacement table, it means that there is no repeated link in the link replacement table, so the first link is taken as the second intranet access link corresponding to the second extranet access link, and the second extranet access link and the first link are stored in the link replacement table.
[0101] If the first link exists in the link replacement table, it indicates that the link replacement table has a repeated link with the first link. The first link is processed by adding characters to obtain a second link that does not exist in the link replacement table. The second link is taken as a second internal network access link corresponding to a second external network access link, and the second external network access link and the second link are stored in the link replacement table.
[0102] It should be noted that after adding characters to the first link, if the first link after adding characters still exists in the link replacement table, characters need to be continuously added until the first link after adding characters does not exist in the link replacement table, and the second link is obtained.
[0103] It should be noted that when adding characters, no identifier can be added in the external network access identifier to avoid subsequent inability to identify the link after adding characters as a link that needs to access the external network. Also, no identifier can be added in the internal network server address to avoid the internal network server being unable to receive the link after adding characters. In addition, the external network access identifier after adding characters needs to be ensured to be in the specified position to avoid subsequent inability to identify the link after adding characters as a link that needs to access the external network.
[0104] For example, the first link is http: / / ABCl / maps, exists in the link replacement table, the address of the internal network server is ABC, the external network access identifier is / maps, and the specified position is the fifth last to the last. Therefore, m can be added after l to obtain http: / / ABClm / maps, which also exists in the link replacement table. Therefore, characters need to be continuously added, and g is added after m to obtain http: / / ABClmg / maps, which does not exist in the link replacement table. Therefore, the second link is http: / / ABClmg / maps.
[0105] It should be noted that the external network data can include data of multiple data types, such as link type, text type, code type, video type, and picture type. The data of the link type, the text type, and the code type can include the second external network access link.
[0106] S302: For each second external network access link in the external network data, the second external network access link is replaced with the second internal network access link corresponding to the second external network access link to obtain updated external network data.
[0107] In this step, after the internal network server determines the second internal network access link corresponding to each second external network access link, for each second external network access link in the external network data, the second external network access link is replaced with the second internal network access link corresponding to the second external network access link to obtain updated external network data.
[0108] S303: Send the updated external network data to the internal network device.
[0109] In this step, after the computer obtains the updated external network data, the updated external network data is sent to the internal network device, so that the internal network device outputs related content according to the external network data.
[0110] The internal network device accesses the external network method provided in this embodiment replaces the second external network access link with the second internal network access link, so that the subsequent internal network device can obtain the external network data corresponding to the second external network access link through the second internal network access link.
[0111] The following is a device embodiment of the present application, which can be used to execute the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.
[0112] Figure 4 The structure diagram of the internal network device accessing the external network device embodiment provided in the present application is shown. The device can be integrated in the internal network server in the above-mentioned method embodiments, or can be realized through the internal network server in the above-mentioned method embodiments. As shown in the figure, the internal network device accessing the external network device 40 includes: Figure 4
[0113] The receiving module 41 is configured to receive the internal network access request sent by the internal network device, wherein the internal network access request includes the first internal network access link, and the first internal network access link includes the address of the internal network server.
[0114] The processing module 42 is configured to, if the first internal network access link includes the external network access identifier, replace the first internal network access link with the first external network access link according to the stored link replacement table to obtain the external network access request.
[0115] The sending module 43 is configured to send the external network access request to the external network server.
[0116] The receiving module 41 is further configured to receive the external network data sent by the external network server.
[0117] The sending module 43 is further configured to send the external network data to the internal network device.
[0118] Further, before the external network data is sent to the internal network device, the processing module 42 is further configured to:
[0119] Determine the second internal network access link corresponding to each second external network access link in the external network data, and each second internal network access link includes the external network access identifier.
[0120] For each second external network access link in the external network data, the second external network access link is replaced by a second internal network access link corresponding to the second external network access link, to obtain updated external network data;
[0121] The sending module 43 is specifically configured to send the updated external network data to the internal network device.
[0122] Further, the processing module 42 is specifically configured to:
[0123] For each second external network access link, the external network address in the second external network access link is replaced by the address of the internal network server, and the external network access identifier is added, to obtain a first link corresponding to the second external network access link;
[0124] For each first link corresponding to each second external network access link, the following processing is performed in sequence:
[0125] It is determined whether the first link exists in the link replacement table;
[0126] If the first link does not exist in the link replacement table, the first link is taken as a second internal network access link corresponding to the second external network access link, and the second external network access link and the first link are stored in the link replacement table;
[0127] If the first link exists in the link replacement table, the first link is subjected to character addition processing to obtain a second link that does not exist in the link replacement table, the second link is taken as a second internal network access link corresponding to the second external network access link, and the second external network access link and the second link are stored in the link replacement table.
[0128] Further, the sending module 43 is specifically configured to send the external network access request to an external network server through a preset secure communication channel;
[0129] The receiving module 41 is specifically configured to receive external network data sent by an external network server through the preset secure communication channel.
[0130] Further, the preset secure communication channel includes any one of an SSL channel, a TLS channel, a VPN channel, and an encrypted tunnel.
[0131] Further, the processing module 42 is further configured to, if the external network access identifier is not included in the first internal network access link, acquire internal network data according to the first internal network access link;
[0132] The sending module 43 is further configured to send the internal network data to the internal network device.
[0133] The internal network device provided by the embodiment accesses the external network device, and is used for implementing the technical solution of the internal network server in any one of the preceding method embodiments, and has similar implementation principles and technical effects, which will not be described herein.
[0134] Figure 5 A structural schematic diagram of a server is provided in the present application. As shown in the figure, the server 50 comprises: Figure 5
[0135] a processor 51, a memory 52, and a communication interface 53;
[0136] The memory 52 is configured to store executable instructions of the processor 51.
[0137] The processor 51 is configured to implement the technical solution of the internal network server in any one of the preceding method embodiments by executing the executable instructions.
[0138] Optionally, the memory 52 can be independent or integrated with the processor 51.
[0139] Optionally, when the memory 52 is independent of the processor 51, the server 50 can further comprise:
[0140] a bus 54, the memory 52 and the communication interface 53 are connected with the processor 51 through the bus 54 and complete communication with each other, and the communication interface 53 is configured to communicate with other devices.
[0141] Optionally, the communication interface 53 can be implemented by a transceiver. The communication interface is configured to implement communication between the database access device and other devices (for example, a client, a read-write library and a read-only library). The memory can include a random access memory (RAM) and can also include a non-volatile memory, for example, at least one disk memory.
[0142] The bus 54 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is shown in the figure, but it does not mean that there is only one bus or only one type of bus.
[0143] The processor described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
[0144] The server is configured to perform the technical solutions of the intranet server in any of the preceding method embodiments, and has similar implementation principles and technical effects, which will not be described here.
[0145] The embodiments of the present application also provide a readable storage medium having a computer program stored thereon, and the computer program is configured to implement the technical solutions provided by any of the preceding method embodiments when executed by a processor.
[0146] The embodiments of the present application also provide a computer program product, including a computer program, and the computer program is configured to implement the technical solutions provided by any of the preceding method embodiments when executed by a processor.
[0147] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by a program instruction related hardware. The foregoing program can be stored in a computer readable storage medium. The program is executed to perform the steps of the above-mentioned method embodiments; and the foregoing storage medium includes ROM, RAM, magnetic disk or optical disk and various media that can store program codes.
[0148] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for an intranet device to access an external network, characterized in that, Applied to intranet servers, the method includes: Receive an intranet access request sent by an intranet device, wherein the intranet access request includes a first intranet access link, and the first intranet access link includes the address of the intranet server; If the first intranet access link includes an external network access identifier, then according to the stored link replacement table, the first intranet access link is replaced with the first external network access link to obtain an external network access request. Send the external network access request to the external network server; Receive external network data sent by the external network server; Determine the second internal network access link corresponding to each second external network access link in the external network data, wherein each second internal network access link includes the external network access identifier; For each second external network access link in the external network data, replace the second external network access link with the second internal network access link corresponding to the second external network access link to obtain the updated external network data; The updated external network data is sent to the internal network device; Determining the second internal network access link corresponding to each second external network access link in the external network data includes: For each second external network access link, replace the external network address in the second external network access link with the address of the internal network server, and add the external network access identifier to obtain the first link corresponding to the second external network access link; For each first link corresponding to the second external network access link, perform the following processing: Determine whether the first link exists in the link replacement table; If the first link does not exist in the link replacement table, the first link is used as the second internal network access link corresponding to the second external network access link, and the second external network access link and the first link are stored in the link replacement table. If the first link exists in the link replacement table, add characters to the first link to obtain a second link that does not exist in the link replacement table. Use the second link as the second internal network access link corresponding to the second external network access link, and store the second external network access link and the second link in the link replacement table.
2. The method according to claim 1, characterized in that, Sending the external network access request to the external network server includes: The external network access request is sent to the external network server through a preset secure communication channel; The receipt of external network data sent by the external network server includes: The system receives external network data sent by an external network server through the preset secure communication channel.
3. The method according to claim 2, characterized in that, The preset secure communication channel includes any one of the following: Secure Sockets Layer (SSL) channel, Transport Layer Security (TLS) channel, Virtual Private Network (VPN) channel, and encrypted tunnel.
4. The method according to claim 1, characterized in that, The method further includes: If the first intranet access link does not include the external network access identifier, then intranet data is obtained based on the first intranet access link; The intranet data is sent to the intranet device.
5. A device for accessing an external network from an intranet device, characterized in that, include: A receiving module is used to receive intranet access requests sent by intranet devices. The intranet access request includes a first intranet access link, and the first intranet access link includes the address of an intranet server. The processing module is used to replace the first intranet access link with the first external network access link according to the stored link replacement table if the first intranet access link includes an external network access identifier, thereby obtaining an external network access request. The sending module is used to send the external network access request to the external network server; The receiving module is also used to receive external network data sent by the external network server; The processing module is further configured to determine the second internal network access link corresponding to each second external network access link in the external network data, wherein each second internal network access link includes the external network access identifier; For each second external network access link in the external network data, replace the second external network access link with the second internal network access link corresponding to the second external network access link to obtain the updated external network data; The sending module is also used to send the updated external network data to the internal network device; The processing module, when determining the second internal network access link corresponding to each second external network access link in the external network data, is specifically used for: For each second external network access link, replace the external network address in the second external network access link with the address of the internal network server, and add the external network access identifier to obtain the first link corresponding to the second external network access link; For each first link corresponding to the second external network access link, perform the following processing: Determine whether the first link exists in the link replacement table; If the first link does not exist in the link replacement table, the first link is used as the second internal network access link corresponding to the second external network access link, and the second external network access link and the first link are stored in the link replacement table. If the first link exists in the link replacement table, add characters to the first link to obtain a second link that does not exist in the link replacement table. Use the second link as the second internal network access link corresponding to the second external network access link, and store the second external network access link and the second link in the link replacement table.
6. A server, characterized in that, include: Processor, memory, communication interface; The memory is used to store the executable instructions of the processor; The processor is configured to execute the method for an intranet device to access an external network as described in any one of claims 1 to 4 by executing the executable instructions.
7. A readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method for an intranet device to access an external network as described in any one of claims 1 to 4.
8. A computer program product, characterized in that, It includes a computer program, which, when executed by a processor, is used to implement the method for an intranet device to access an external network as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Mutual access method of intranet equipment and extranet equipment, routing equipment and server
CN116032879A
Method and system for controlling access authority of internal and external networks
CN118300831A