Remote configuration operation and maintenance method for embedded system, electronic equipment and storage medium
By establishing an encrypted connection between the system gateway and the configuration operation and maintenance server and the tunnel server, and establishing a subtunit for transmission of operation and maintenance information, the configuration operation and maintenance problems caused by different protocols of embedded terminal devices are solved, and the unified operation and maintenance configuration of multi-platform equipment is realized, which improves operation and maintenance efficiency and security.
Patent Information
- Application Number
- CN202510054585.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, embedded terminal equipment cannot work under the same configuration operation and maintenance system due to the docking of different protocols, which increases the development workload and cost, and has poor security.
By establishing a configuration encrypted connection between the system gateway and the configuration operation and maintenance server, and establishing a secure network tunnel encrypted connection with the tunnel server, a subtunit is established for transmitting operation and maintenance information, so that the target terminal equipment can work under the same operation and maintenance configuration system without the need to connect to the platform protocol.
It realizes that the same operation and maintenance configuration system is used for embedded terminal equipment of multiple platforms or manufacturers, which reduces the cost and labor demand of remote configuration operation and maintenance, and improves the efficiency and security of remote operation and maintenance.
Smart Images

Figure CN119945760A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of electronic technology, and in particular to a method, electronic device and storage medium for remote configuration and operation of an embedded system. Background Art
[0002] Embedded terminal devices refer to computer systems designed for specific functions or applications. They are usually embedded in other devices and cannot run independently. Compared with general-purpose computers, embedded terminal devices have lower power consumption, smaller size and higher stability. They are widely used in a range of industries and applications, such as smart homes, automotive electronic equipment, industrial control systems, and IoT devices. With the rapid development of IoT technology, more and more embedded terminal devices are being put into use in production and life. As a result, the configuration and operation and maintenance of embedded terminal devices have become a challenge.
[0003] The inventors have found that there are at least the following problems in the related art: if an embedded terminal device needs to be remotely configured and maintained, the IoT platform and the embedded terminal device need to be connected through a platform protocol. If there are multiple embedded terminal devices that have been connected to different protocols, these embedded terminal devices that have been connected to different protocols do not work under the same configuration and maintenance system, which increases the workload of development, thereby increasing the manpower, time and cost required for remote configuration and maintenance development work, and has poor security. Summary of the invention
[0004] The purpose of the embodiments of the present invention is to provide a method, electronic device and storage medium for remote configuration and operation of an embedded system, so that multiple embedded terminal devices can work under the same configuration and operation system and the embedded terminal devices can achieve remote configuration and operation without connecting to any platform protocol, thereby improving the convenience of remote access and reducing the cost of remote configuration and operation.
[0005] To solve the above technical problems, an embodiment of the present invention provides a method for remote configuration and operation of an embedded system, which is applied to a system gateway, and includes: establishing a configuration encryption connection with a configuration and operation server, and after successfully establishing the configuration encryption connection, obtaining the connection sub-tunnel configuration information issued by the configuration and operation server; establishing a secure network tunnel encryption connection with a tunnel server, and after successfully establishing the secure network tunnel encryption connection, establishing a sub-tunnel with the tunnel server according to the connection sub-tunnel configuration information, and the sub-tunnel is used to transmit operation and maintenance information of a target terminal device; receiving the operation and maintenance information through the sub-tunnel, and performing local service access to the target terminal device according to the operation and maintenance information.
[0006] An embodiment of the present invention also provides a method for remote configuration and operation of an embedded system, which is applied to a system platform, wherein the system platform includes a configuration and operation server and a tunnel server; the method includes: the configuration and operation server establishes a configuration encryption connection with a system gateway, and after successfully establishing the configuration encryption connection, sends the sub-tunnel configuration information to the system gateway; the tunnel server establishes a secure network tunnel encryption connection with the system gateway, and after successfully establishing the secure network tunnel encryption connection, establishes a sub-tunnel with the system gateway, and the sub-tunnel is used to transmit operation and maintenance information of a target terminal device; the tunnel server sends the operation and maintenance information to the system gateway through the sub-tunnel.
[0007] An embodiment of the present invention also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned method of remote configuration and operation of an embedded system.
[0008] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the above-mentioned method for remote configuration and operation of an embedded system.
[0009] In an embodiment of the present invention, a secure network tunnel encryption connection is established between the system gateway and the tunnel server, and operation and maintenance information of the target terminal device is transmitted through a sub-tunnel. Local service access is performed on the target terminal device based on the operation and maintenance information, so that the operation and maintenance information can be issued through the secure network tunnel, so that embedded terminal devices of multiple platforms or manufacturers can all use the same set of operation and maintenance configuration system, and the target terminal device or system gateway can achieve remote operation and maintenance without going through the docking platform protocol. The local configuration operation and maintenance service of the embedded terminal device is mapped to the remote operation and maintenance platform through the secure network tunnel technology, which reduces the manpower demand for secondary development, saves human resources and improves the efficiency of remote operation and maintenance. In addition, due to the addition of a secure network tunnel for encrypted connection communication, remote access and operation and maintenance information transmission are safer and more convenient.
[0010] In addition, establishing a configuration encryption connection with the configuration operation and maintenance server includes: performing authentication verification with the configuration operation and maintenance server through a TLS encryption certificate, and establishing the configuration encryption connection after successful verification; wherein, the authentication verification through the TLS encryption certificate includes a legality verification of the TLS certificate and a revocation detection of the TLS certificate; when the verification result of the TLS certificate is legal and the TLS certificate has not been revoked, the authentication verification result of the TLS certificate is passed.
[0011] In addition, establishing a secure network tunnel encrypted connection with the tunnel server includes: after receiving the tunnel request sent by the configuration and operation server, generating a local tunnel connection configuration, using the local tunnel connection configuration to connect to the tunnel server, and reporting the service operation code to the tunnel server.
[0012] In addition, the method also includes: receiving an IP address query instruction for the target terminal device issued by the configuration and operation and maintenance server, and maintaining a monitoring task for the MAC address of the target terminal device; when the device address status of the target terminal device changes, notifying the configuration and operation and maintenance server of the status of the target terminal device in the form of an event.
[0013] In addition, after the tunnel server sends the operation and maintenance information to the system gateway through the sub-tunnel, the method also includes: after the configuration operation and maintenance server receives a reply message to the operation and maintenance information, the configuration operation and maintenance server creates a new target mapping device for the target terminal device; the configuration operation and maintenance server creates a new target mapping service under the target mapping device according to the reply message.
[0014] In addition, the method further includes: the configuration and operation server issues an IP address query instruction for the target terminal device; when the device address status of the target terminal device changes, receiving an event notification about the status of the target terminal device sent by the system gateway.
[0015] In addition, the method also includes: if the operation and maintenance service of the target terminal device is a web operation and maintenance service, after the tunnel server and the system gateway establish a sub-tunnel, the configuration operation and maintenance server adds the remote domain name of the web operation and maintenance service to the sub-tunnel configuration information. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.
[0017] Figure 1 It is a network topology diagram of the operation and maintenance system provided in an embodiment of the present application;
[0018] Figure 2 It is a timing flow chart of establishing a configuration encryption connection between the system gateway of the present application and the configuration operation and maintenance server;
[0019] Figure 3 It is a timing flow chart of the system gateway of the present application and the tunnel server establishing a secure network tunnel encryption connection;
[0020] Figure 4 It is a timing flow chart of the operation and maintenance message transmission process of this application;
[0021] Figure 5 It is a timing flow chart of the operation and maintenance system of this application when performing platform protocol docking;
[0022] Figure 6 It is a corresponding schematic diagram of the equipment operation and maintenance code and the system gateway identification code provided in an embodiment of the present application;
[0023] Figure 7 This is a basic execution flow chart of HTTP request operation and maintenance service provided by an embodiment of the present application;
[0024] Figure 8 This is a flowchart of scheduled task operation and maintenance execution provided by an embodiment of the present application;
[0025] Fig. 9 This is a logic trigger task operation and maintenance execution flow chart provided by an embodiment of the present application;
[0026] Fig.10 This is a flow chart of equipment linkage task operation and maintenance execution provided by an embodiment of the present application;
[0027] Fig.11 It is a schematic diagram of the internal structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0028] Since embedded terminal devices connected to different protocols do not work under the same configuration and operation system, the development workload is increased, which increases the manpower, time and cost required for remote configuration and operation development, and the security is poor. Therefore, a method, electronic device and storage medium for remote configuration and operation of embedded systems are needed to solve the above technical problems.
[0029] To make the purpose, technical scheme and advantages of the embodiments of the present invention clearer, the embodiments of the present invention will be described in detail below in conjunction with the accompanying drawings. However, it will be appreciated by those skilled in the art that in the embodiments of the present invention, many technical details are proposed in order to enable the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical scheme claimed in the present application can be implemented. The division of the following embodiments is for the convenience of description, and should not constitute any limitation on the specific implementation of the present invention. The various embodiments can be combined and referenced with each other without contradiction.
[0030] An embodiment of the present invention relates to a method for remote configuration and operation of an embedded system, which can be applied to a system gateway connected to an embedded terminal device. The method for remote configuration and operation of an embedded system of a system gateway includes: establishing a configuration encryption connection with a configuration and operation server, and after successfully establishing the configuration encryption connection, obtaining the connection sub-tunnel configuration information issued by the configuration and operation server; establishing a secure network tunnel encryption connection with a tunnel server, and after successfully establishing the secure network tunnel encryption connection, establishing a sub-tunnel with the tunnel server according to the connection sub-tunnel configuration information, and the sub-tunnel is used to transmit the operation and maintenance information of the target terminal device; receiving the operation and maintenance information through the sub-tunnel, and performing local service access to the target terminal device according to the operation and maintenance information.
[0031] Another embodiment of the present invention relates to a method for remote configuration and operation of an embedded system, which is applied to a system platform, wherein the system platform includes a configuration and operation server and a tunnel server; the method for remote configuration and operation of an embedded system of the system platform includes: the configuration and operation server establishes a configuration encryption connection with a system gateway, and after successfully establishing the configuration encryption connection, sends sub-tunnel configuration information to the system gateway; the tunnel server establishes a secure network tunnel encryption connection with the system gateway, and after successfully establishing the secure network tunnel encryption connection, establishes a sub-tunnel with the system gateway, and the sub-tunnel is used to transmit operation and maintenance information of a target terminal device; the tunnel server sends the operation and maintenance information to the system gateway through the sub-tunnel.
[0032] The present application establishes a secure network tunnel encryption connection between the system gateway and the tunnel server, transmits the operation and maintenance information of the target terminal device through the sub-tunnel, and performs local service access to the target terminal device based on the operation and maintenance information, so that the operation and maintenance information can be issued through the secure network tunnel, so that embedded terminal devices of multiple platforms or manufacturers can use the same operation and maintenance configuration system, and the target terminal device or system gateway can achieve remote operation and maintenance without going through the docking platform protocol. The local configuration operation and maintenance service of the embedded terminal device is mapped to the remote operation and maintenance platform through the secure network tunnel technology, which reduces the manpower demand for secondary development, saves human resources and improves the efficiency of remote operation and maintenance. In addition, due to the addition of a secure network tunnel for encrypted connection communication, remote access and operation and maintenance information transmission are safer and more convenient.
[0033] The following is a detailed description of the implementation details of the method for remote configuration and operation of an embedded system according to an embodiment of the present invention. The following content is only provided for the convenience of understanding the implementation details and is not necessary for the implementation of this solution.
[0034] like Figure 1As shown, the operation and maintenance system includes a system platform, a system gateway, an embedded terminal device and an operation and maintenance client. Among them, the system platform includes a tunnel server and a configuration operation and maintenance server. Among them, the system gateway is a specific gateway connected to the embedded terminal device; the configuration operation and maintenance server receives the user's operation on the client and sends the operation and maintenance information according to the user's configuration requirements; the tunnel server is used to establish a secure network tunnel with the system gateway for the transmission of operation and maintenance information; the embedded terminal device is connected to the system gateway and connected to the subnet of the corresponding system gateway. Specifically, the working environment of the system platform is the Internet.
[0035] Specifically, the operation and maintenance system also includes a gateway router for connecting to the system gateway and a user-side router for connecting to the user access client. Both the gateway router and the user-side router are connected to the system platform through the routing network of the network operator ISP. The configuration operation and maintenance server and the tunnel server in the system platform realize data intercommunication with each other. Further, in order to ensure the communication security between the configuration operation and maintenance server and the tunnel server, the tunnel server and the configuration operation and maintenance server need to run on the same server or under the same firewall; the tunnel server and the system gateway can directly establish a secure network tunnel encryption connection for more secure encrypted communication; the configuration operation and maintenance server can directly realize protocol communication with the system gateway or embedded terminal device through the platform protocol; the system gateway and the embedded terminal device access local services through the subnet connection.
[0036] Under normal network environment conditions, the operation and maintenance client or system platform cannot directly access the operation and maintenance configuration services of the system gateway or embedded terminal devices; however, the operation and maintenance system in the embodiment of the present application can map the operation and maintenance configuration services of the embedded terminal devices to the system platform, and the user client can access the operation and maintenance configuration services of the embedded terminal devices through the Internet.
[0037] Specifically, when the system gateway establishes a configuration encrypted connection with the configuration operation and maintenance server, the timing diagram for establishing the encrypted connection is as follows: Figure 2 As shown, the details are as follows:
[0038] In S201, the system gateway performs TLS certificate authentication with the configuration and operation server.
[0039] In S202, the system gateway and the configuration and operation server are authenticated by certificates.
[0040] In S203, the system gateway establishes a TLS encrypted communication connection with the configuration and operation server.
[0041] In S204, a TLS encrypted communication connection is successfully established between the system gateway and the configuration operation and maintenance server.
[0042] In S205, the operation and maintenance server is configured to send the management command to the system gateway.
[0043] In S206, the system gateway responds to the management command.
[0044] In S207, the operation and maintenance server is configured to send the tunnel TOKEN to the system gateway.
[0045] In S208, the system gateway responds to the tunnel TOKEN sending instruction.
[0046] In S209, the configuration operation and maintenance server sends the tunnel connection SUB-DOMAINS to the system gateway.
[0047] In S210, the system gateway replies to the tunnel connection SUB-DOMAINS.
[0048] Specifically, the tunnel TOKEN is a token issued by the configuration operation and maintenance server, which can be a string of characters; the tunnel connection SUB-DOMAINS is the subdomain name of the tunnel connection. The connection sub-tunnel configuration information includes information such as the service domain name, service type, service address, and service port. The system gateway connects to the tunnel server according to the connection sub-tunnel configuration information. In some implementations, the operation and maintenance data is transmitted through VPN, but VPN cannot be refined to control specific addresses and ports, and there is a large system risk. Therefore, from the perspective of data security, the operation and maintenance data is transmitted through a secure network tunnel, which can transmit the operation and maintenance data based on specific addresses and ports, and improve the security of the operation and maintenance data transmission in the operation and maintenance system, effectively avoiding risks in the operation and maintenance system.
[0049] Furthermore, the system gateway and the tunnel server use TLS certificates for two-way authentication to establish an encrypted communication connection, and then use the HMAC-SHA512 algorithm to authenticate the TOKEN. When the system gateway and the tunnel server establish a secure network tunnel encrypted connection, the timing diagram for establishing an encrypted connection is as follows: Figure 3 As shown, the details are as follows:
[0050] In S301, the system gateway initiates TLS certificate authentication with the tunnel server.
[0051] In S302, the system gateway and the tunnel server are authenticated by certificates.
[0052] In S303, the system gateway establishes a TLS encrypted communication connection with the tunnel server.
[0053] In S304, the TLS encrypted communication connection between the system gateway and the tunnel server is successfully established.
[0054] In S305 , the system gateway initiates TOKEN HMAC authentication with the tunnel server.
[0055] In S306, the user logs in to the operation and maintenance client, and the operation and maintenance client sends a login request to the configuration operation and maintenance server.
[0056] In S307, the system gateway and the tunnel server are authenticated through TOKEN HMAC.
[0057] In S308, the configuration operation and maintenance server replies to the operation and maintenance client with a login success message.
[0058] In S309, the system gateway sends the management command to the tunnel server.
[0059] In S310, the tunnel server replies the management command to the system gateway.
[0060] In S311, the user initiates an operation and maintenance request on the operation and maintenance client, and the operation and maintenance client sends the operation and maintenance request message to the configuration operation and maintenance server.
[0061] In S312, the configuration operation and maintenance server sends the tunnel transparent transmission data to the tunnel server according to the operation and maintenance request; the tunnel server forwards the tunnel transparent transmission data to the system gateway. The system gateway performs local service access to the target terminal device connected to the system gateway according to the tunnel transparent transmission data.
[0062] In S313, the system gateway transparently transmits the operation and maintenance data to the configuration operation and maintenance server through the tunnel server, and the operation and maintenance server makes an operation and maintenance reply to the operation and maintenance client.
[0063] This implementation method adds the use of secure network tunnels to transmit data in the operation and maintenance system, and maps the local configuration operation and maintenance services of embedded terminal devices to the system platform through secure network tunnel technology, so that embedded terminals with local configuration operation and maintenance services can be added to the operation and maintenance system without any modification. Furthermore, the tunnel server uses TLS certificates for two-way authentication and performs secondary authentication on TOKEN, adopting a dual authentication authentication mechanism. TLS certificate two-way authentication ensures the legitimacy of the system platform connected to the system gateway and the legitimacy of the gateway device accessed by the system platform, thereby enhancing the security of the entire system. At the same time, the revocation mechanism of TLS certificates can be used to revoke the certificates of risky gateways to enhance risk management. TLS encrypted communication ensures that the intranet traffic is encrypted and transmitted in the public network, and cannot be monitored, tampered with or stolen, thereby improving the security of data transmission. At the same time, the tunnel server uses TOKEN for authentication, and the use of TOKEN can manage the access duration and timing of the system gateway in a more detailed manner. TOKEN is managed by the system platform and issued through the system platform protocol. The tunnel server can only be accessed when TOKEN is legal. TOKEN authentication uses the HMAC-SHA512 authentication algorithm to protect the privacy of TOKEN and prevent TOKEN leakage.
[0064] Figure 4 It is a timing diagram of the operation and maintenance message transmission process. Specifically, in S401, the user logs in to the operation and maintenance client, and the operation and maintenance client sends a login request to the configuration operation and maintenance server.
[0065] In S402, the operation and maintenance server is configured to reply a login success message to the operation and maintenance client.
[0066] At the same time, in S403, the system gateway initiates a request message for establishing a tunnel to the tunnel server; in S404, the tunnel server sends a reply message to the system gateway indicating that the secure network tunnel is successfully established.
[0067] In S405, the user sends a message for configuring the terminal tunnel connection to the configuration operation and maintenance server on the operation and maintenance client.
[0068] In S406, the configuration server sends the connection sub-tunnel configuration information to the system gateway according to the message for configuring the terminal tunnel connection.
[0069] In S407, the system gateway replies to the connection sub-tunnel configuration information.
[0070] In S408, the configuration operation and maintenance server transparently transmits the reply message of the system gateway to the connection sub-tunnel configuration information to the operation and maintenance client.
[0071] In S409, the system gateway initiates a sub-tunnel establishment request with the tunnel server according to the connection sub-tunnel configuration information.
[0072] In S410, the tunnel server and the system gateway successfully establish a sub-tunnel.
[0073] When the operation and maintenance service of the target terminal device is a local operation and maintenance service, the operation and maintenance request is directly transparently processed as follows:
[0074] In S411, the operation and maintenance client initiates an operation and maintenance request to the configuration operation and maintenance server.
[0075] In S412, the operation and maintenance server is configured to transparently transmit the operation and maintenance request to the tunnel server.
[0076] In S413, the tunnel server transparently transmits the operation and maintenance request to the system gateway through the sub-tunnel.
[0077] In S414, the system gateway sends the transparent operation and maintenance request to the target terminal device.
[0078] In S415, the target terminal device performs local operation and maintenance service processing and sends an operation and maintenance reply message to the system gateway.
[0079] In S416, the system gateway transparently transmits the operation and maintenance reply message to the tunnel server through the sub-tunnel.
[0080] In S417, the tunnel server transparently transmits the operation and maintenance reply to the configuration operation and maintenance server.
[0081] In S418, the operation and maintenance server is configured to provide an operation and maintenance reply to the operation and maintenance client.
[0082] When the system gateway successfully connects to the configuration operation and maintenance server and the tunnel server, the connection sub-tunnel configuration information can be configured on the configuration operation and maintenance server for the embedded terminal devices that need operation and maintenance management. After the sub-tunnel is successfully established, the local operation and maintenance services of the embedded terminal devices can be accessed on the configuration operation and maintenance server. It is worth noting that the sub-tunnel is a logical connection. After the configuration operation and maintenance server is configured, the connection sub-tunnel configuration information is generated, and then the connection sub-tunnel configuration information is sent to the system gateway. The system gateway and the tunnel server establish a sub-tunnel for the target terminal device to transmit data, so that when the system gateway is connected to multiple embedded terminal devices, the system gateway and the tunnel server establish a sub-tunnel through the connection sub-tunnel configuration information sent by the configuration operation and maintenance server. According to the connection sub-tunnel configuration information, only the local access services of some embedded terminal devices are mapped to the configuration operation and maintenance server. Users can configure the services that need to be opened for access according to actual needs, and map the operation and maintenance services on the system platform through the sub-tunnel as needed, thereby improving the configuration flexibility of the system platform and ensuring the security of the access services of embedded terminal devices. For example, when the embedded terminal devices connected to the system gateway are device A, device B, and device C, and when the user only needs to perform remote operation and maintenance access to device A and device C on the platform, device A and device C are the target terminal devices. By configuring the operation and maintenance server, the connection sub-tunnel configuration information about device A and device C is sent to the system gateway. The system gateway and the tunnel server establish a sub-tunnel related only to device A and device C to perform remote operation and maintenance data transmission of device A and device C.
[0083] When the operation and maintenance service of the target terminal device is a remote operation and maintenance request, the transmission of the operation and maintenance request and operation and maintenance reply messages is realized through the remote domain name. If the local operation and maintenance service of the target terminal device is HTTP(S), it can be directly accessed in a common WEB browser through the remote domain name in the connection sub-tunnel configuration. The details are as follows:
[0084] In S421, the operation and maintenance client directly initiates an operation and maintenance request to the tunnel server through the remote domain name.
[0085] In S422, the tunnel server transparently transmits the operation and maintenance request to the system gateway through the sub-tunnel.
[0086] In S423, the system gateway sends the transparent operation and maintenance request to the target terminal device.
[0087] In S424, the target terminal device performs local operation and maintenance service processing and sends an operation and maintenance reply message to the system gateway.
[0088] In S425, the system gateway transparently transmits the operation and maintenance reply message to the tunnel server through the sub-tunnel.
[0089] In S426, the tunnel server makes an operation and maintenance reply to the operation and maintenance client.
[0090] It is worth noting that, unlike protocol docking, in the embodiment of the present application, the operation and maintenance system uses the original operation and maintenance interface of the target terminal device in the system platform for secondary development, thereby forming a new operation and maintenance service in the system platform, and mapping the configuration operation and maintenance service of the target terminal device itself in the system platform. For some target terminal devices with operation and maintenance services, there is no need to develop services on the system platform, and the operation and maintenance services of the device itself can be used directly, saving resources for the development of operation and maintenance services. That is, the system platform in the present application supports mapping the original operation and maintenance services of embedded terminal devices, and can also perform secondary development of services on the system platform side. For embedded terminal devices that do not have local services, they can also be connected to the system platform through protocol docking to develop services. The system platform develops or provides operation and maintenance services in the above three ways, allowing developers to develop a highly customized and diversified device configuration operation and maintenance system based on existing embedded terminal devices.
[0091] When the configuration encryption connection or the secure network tunnel encryption connection fails to be established, a protocol communication line is established with the configuration operation and maintenance server through the platform protocol, the operation and maintenance information is received through the protocol communication line, and local service access is performed on the target terminal device based on the operation and maintenance information; the configuration operation and maintenance server establishes a protocol communication line with the system gateway or the target terminal device through the platform protocol, and sends the operation and maintenance information to the system gateway or the target terminal device through the protocol communication line. When the operation and maintenance system cannot transmit data through the secure network tunnel, or the encryption connection fails to be established, or the target terminal device does not have a local operation and maintenance service, the operation and maintenance system also supports the platform protocol to connect to the target terminal device to transmit operation and maintenance information, and when developing the operation and maintenance service, the platform protocol connection sequence diagram is shown as follows. Figure 5 As shown:
[0092] In S501, the operation and maintenance client initiates an operation and maintenance request to the configuration operation and maintenance server.
[0093] In S502, the operation and maintenance server is configured to perform platform protocol docking with the target terminal device, and a protocol operation and maintenance request is sent to the target terminal device.
[0094] In S503, after completing the operation and maintenance, the target terminal device performs a protocol operation and maintenance reply to the configuration operation and maintenance server.
[0095] In S504, the operation and maintenance server is configured to perform an operation and maintenance reply to the operation and maintenance client.
[0096] Specifically, when the configuration encryption connection or the secure network tunnel encryption connection fails to be established, the configuration operation and maintenance server establishes a protocol communication line with the system gateway or the target terminal device through the platform protocol, and sends the operation and maintenance information to the system gateway or the target terminal device through the protocol communication line. It is worth noting that when the configuration operation and maintenance server is connected to the system gateway through the platform protocol, the system gateway and the target terminal device in the subnet perform local service access. For terminals that do not have local configuration operation and maintenance services, the system platform also provides a platform protocol docking method to make the types of connected devices more diverse.
[0097] After the sequential interaction of the above operation and maintenance systems, the mapping of the embedded terminal device services under the system gateway on the configuration operation and maintenance server is realized, and users can use the services of the embedded terminal devices through the operation and maintenance client and the configuration operation and maintenance server.
[0098] Specifically, when mapping the embedded terminal device service on the configuration operation and maintenance server, first create a new target mapping device in the configuration operation and maintenance server. The information of the newly created target mapping device is determined according to the target terminal device information connected to the system gateway, as shown in the following table:
[0099]
[0100]
[0101] Further, after the target mapping device is created, a target mapping service is created under the target mapping device. The operation and maintenance server is configured to perform network mapping according to the service information of the embedded terminal device. The information of the newly created service is shown in the following table:
[0102]
[0103] It should be noted that under one system gateway, multiple embedded terminal devices may be connected; one embedded terminal device may have multiple services. Therefore, the service information of the target mapping device in the system platform is created by the customer in the configuration operation and maintenance server. The configuration operation and maintenance server stores the system gateway information, device information, and service information in the database of the configuration operation and maintenance server. The device is associated with the corresponding system gateway through the system gateway identifier, and the service is associated with the device through the device operation and maintenance code. The service operation and maintenance code is used to uniquely identify the operation and maintenance service, such as Figure 6 shown.
[0104] When the system gateway is connected to the operation and maintenance server, the operation and maintenance server sends a device IP address query command, and the corresponding system gateway replies with the device IP address being queried.
[0105] The request parameters are as follows:
[0106]
[0107] The reply payload parameters are as follows:
[0108]
[0109]
[0110] Among them, MAC corresponds to the MAC address of the device; IP corresponds to the IP address of the device. Configure the operation and maintenance server to update the address in the original database according to the device IP address replied by the system gateway to prevent the device from being found due to the change of the device IP address.
[0111] When a tunnel connection is created, a tunnel connection configuration and request is created in the configuration operation and maintenance server and stored in the database of the configuration operation and maintenance server. The fields in the database are shown in the following table:
[0112]
[0113] The configuration operation and maintenance server sends a tunnel configuration request to the tunnel server, and the tunnel server maps the corresponding network service to the MapPort port according to the service operation and maintenance code reported by the embedded terminal device. The parameters are as follows:
[0114]
[0115] Configure the operation and maintenance server to send tunnel requests to the system gateway. The parameters are as follows:
[0116]
[0117] After receiving the tunnel request from the configuration operation and maintenance server, the system gateway generates a local tunnel connection configuration and uses the configuration to connect to the tunnel server. The system gateway reports the service operation and maintenance code to the tunnel server. The tunnel server finds the target tunnel server mapping port through the service operation and maintenance code, and then maps the device service to the tunnel server mapping port, thereby realizing the mapping of the local operation and maintenance service of the embedded terminal device under the system gateway to the tunnel server. Since the tunnel server and the configuration operation and maintenance server realize data connection and intercommunication, the local operation and maintenance service of the embedded terminal device can be further accessed by accessing the configuration operation and maintenance server.
[0118] Each time the configuration operation and maintenance server sends a device IP address query, the system gateway will maintain a task. This task continuously monitors the sent MAC address. When the address status of the embedded terminal device changes, such as offline, online, address change, etc., the changed status will be notified to the configuration operation and maintenance server in the form of an event. The payload of the notification event is as follows:
[0119]
[0120] Among them, MAC is the MAC address of the device whose status has changed; IP is the IP address of the device whose status has changed; STATE is the status indication, such as indication update, offline, online, etc. The configuration operation and maintenance server will update the device information stored in the database according to the event, and re-send the tunnel connection configuration to the system gateway. The tunnel server does not need to update the event.
[0121] Specifically, if the target terminal device has rich operation and maintenance capabilities, after the target terminal device is connected to the system platform, the operation and maintenance interface of the target terminal device can be directly embedded in the system platform to improve the convenience and efficiency of operation and maintenance development.
[0122] Take the following 9 HTTP requests provided on the target terminal device for operation and maintenance services as an example:
[0123]
[0124] The basic execution process is as follows Figure 7 As shown; the configuration operation and maintenance server only needs to send the above HTTP request to the tunnel server to operate the target terminal device.
[0125] Furthermore, the system platform can also develop timed triggering, logic triggering, and equipment linkage operation tasks, and monitor and record the equipment online and offline.
[0126] Take the timed trigger task as an example, such as restarting the target terminal device every 3 days. After the user creates a new timed task in the system platform and fills in the timed task name, timed task device, timed task device action, execution result processing action, timed period and other information, the configuration operation and maintenance server will create a unique timer task ID for the timed task and store the above configuration information in the database. The fields in the database are shown in the following table:
[0127]
[0128] The device association table information corresponding to the timer task is shown in the following table:
[0129]
[0130]
[0131] The scheduled task operation and maintenance execution process is as follows Figure 8 As shown: in step 11, wait for timing;
[0132] In step 12, it is determined whether the scheduled task has expired. If not, the process jumps back to step S11. If the scheduled task has expired, the process jumps back to step 13.
[0133] In step 13, perform HTTP login and follow the subsequent steps;
[0134] In step 14, the control performs a timing action;
[0135] In step 15, HTTP logout;
[0136] In step 16, control performs the result processing action and returns to step S11.
[0137] Take the logic trigger task as an example, when the device state 1 is the target state, the action 1 is triggered. After the user creates a new logic trigger task in the system platform and fills in the logic trigger task name, logic trigger task device, logic trigger task device action, execution result processing action, task description and other information, the configuration operation and maintenance server will create a unique trigger task ID for the logic trigger task and store the above configuration information in the database. The fields in the database are shown in the following table:
[0138] Parameter name Parameter Description Logical trigger task ID Unique identifier of the task. Logical trigger task name The name of the task. Logical trigger task description Description of the task. Result processing actions The result processing action of task execution can be analyzed, saved, and recorded.
[0139] The device association table information corresponding to the logic trigger task is shown in the following table:
[0140]
[0141]
[0142] The logical trigger task operation and maintenance execution process is as follows Fig. 9 As shown: In step 21, HTTP login is performed;
[0143] In step 22, poll or monitor the trigger information acquisition interface;
[0144] In step 23, determine whether the trigger condition is true, if not, jump to step 22, if yes, jump to step 24 and execute steps 24 to 25;
[0145] In step 24, the control performs a triggering action;
[0146] In step S25, control performs the result processing action and returns to step S23.
[0147] Taking the device linkage task as an example, when the state of the source device is the target state, the action of executing the target device is triggered. After the user creates a new device linkage task in the system platform and fills in the device linkage task name, source device, linkage condition, target device, target device action, execution result processing action, task description and other information, the configuration operation and maintenance server will create a unique device linkage task identifier for the device linkage task and store the above configuration information in the database. The fields in the database are shown in the following table:
[0148]
[0149] The source device association table information corresponding to the device linkage task is shown in the following table:
[0150]
[0151] The target device association table information corresponding to the device linkage task is shown in the following table:
[0152]
[0153] The equipment linkage task operation and maintenance execution process is as follows Fig.10 As shown: In step 31, it is determined whether the source device is traversed, if so, jump to step 321, if not, jump to step 331;
[0154] In step 321, HTTP logs into the target device and executes steps 322 to 325;
[0155] In step 322, control performs a triggering action;
[0156] In step 323, HTTP logs out of the target device;
[0157] In step 324, a structure processing action is performed;
[0158] In step 325, wait for the polling cycle and jump to step 31;
[0159] In step 331, switch the source device and execute steps 332 to 335;
[0160] In step 332, HTTP logs into the source device;
[0161] In step 333, poll or monitor the trigger information acquisition interface;
[0162] In step 334, HTTP logs out of the source device;
[0163] In step 335, determine whether the trigger condition is true, if so, execute step 341, if not, execute step 351;
[0164] In step 341, determine whether the trigger condition logic is "or", if so, execute step 321, if not, execute step 31;
[0165] In step 351, determine whether the trigger condition logic is "or", if so, execute step 31, if not, execute step 352;
[0166] In step 352, wait for the polling cycle and jump to step 31.
[0167] By developing timing triggers, logic triggers, device linkage and other operational tasks in the system platform and storing them in the database, and monitoring and recording the online and offline status of the devices through the system platform, the system platform is more convenient for developing embedded terminal devices.
[0168] In an embodiment of the present invention, a secure network tunnel encryption connection is established between the system gateway and the tunnel server, and operation and maintenance information of the target terminal device is transmitted through a sub-tunnel. Local service access is performed on the target terminal device based on the operation and maintenance information, so that the operation and maintenance information can be issued through the secure network tunnel, so that embedded terminal devices of multiple platforms or manufacturers can all use the same operation and maintenance configuration system. The target terminal device or system gateway can achieve remote operation and maintenance without going through the docking platform protocol. The local configuration operation and maintenance service of the embedded terminal device is mapped to the remote operation and maintenance platform through the secure network tunnel technology, which reduces the manpower demand for secondary development, saves human resources and improves the efficiency of remote operation and maintenance. In addition, due to the addition of a secure network tunnel for encrypted connection communication, remote access and operation and maintenance information transmission are safer and more convenient.
[0169] The steps of the above method are divided only for the purpose of clear description. When implemented, they can be combined into one step or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent; adding insignificant modifications to the algorithm or process or introducing insignificant designs without changing the core design of the algorithm and process are all within the scope of protection of this patent.
[0170] In addition, the examples mentioned in the above embodiments can be freely combined, and any combination can be understood as an embodiment. The "embodiment" or "example" appearing in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It can be understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0171] In summary, specific embodiments of the present application have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results.
[0172] Another embodiment of the present invention relates to an electronic device, such as Fig.11 As shown, it includes at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for remote configuration and operation of the embedded system as described above.
[0173] Among them, the memory and the processor are connected in a bus manner, and the bus may include any number of interconnected buses and bridges, and the bus connects various circuits of one or more processors and memories together. The bus can also connect various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be one element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. The data processed by the processor is transmitted on a wireless medium via an antenna, and further, the antenna also receives data and transmits the data to the processor.
[0174] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory can be used to store data used by the processor when performing operations.
[0175] Another embodiment of the present invention relates to a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-mentioned method embodiment for remote configuration and operation of an embedded system.
[0176] That is, those skilled in the art can understand that all or part of the steps in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a program, and the program is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0177] Those skilled in the art will appreciate that the above embodiments are specific embodiments for implementing the present invention, and that in actual applications, various changes may be made in form and detail without departing from the spirit and scope of the present invention.
Claims
1. A method for remote configuration and operation of an embedded system, applied to a system gateway, characterized in that: include: Establishing a configuration encryption connection with a configuration operation and maintenance server, and after successfully establishing the configuration encryption connection, obtaining the connection sub-tunnel configuration information issued by the configuration operation and maintenance server; Establishing a secure network tunnel encryption connection with a tunnel server. After successfully establishing the secure network tunnel encryption connection, establishing a sub-tunnel with the tunnel server according to the connection sub-tunnel configuration information, wherein the sub-tunnel is used to transmit operation and maintenance information of the target terminal device; The operation and maintenance information is received through the sub-tunnel, and local service access is performed on the target terminal device according to the operation and maintenance information.
2. The method for remote configuration and operation of an embedded system according to claim 1, characterized in that: The step of establishing a configuration encryption connection with the configuration operation and maintenance server includes: Perform authentication verification with the configuration operation and maintenance server through the TLS encryption certificate, and after successful verification, establish the configuration encryption connection; The authentication verification is performed through the TLS encryption certificate, including the legality verification of the TLS certificate and the revocation detection of the TLS certificate; When the verification result of the TLS certificate is legal and the TLS certificate has not been revoked, the authentication verification result of the TLS certificate is passed.
3. The method for remote configuration and operation of an embedded system according to claim 2, characterized in that: The step of establishing a secure network tunnel encryption connection with the tunnel server includes: After receiving the tunnel request sent by the configuration operation and maintenance server, a local tunnel connection configuration is generated, and the local tunnel connection configuration is used to connect to the tunnel server, and the service operation and maintenance code is reported to the tunnel server.
4. The method for remote configuration and operation of an embedded system according to claim 1, characterized in that: The method further comprises: Receiving an IP address query instruction for a target terminal device issued by the configuration operation and maintenance server, and maintaining a monitoring task for a MAC address of the target terminal device; When the device address status of the target terminal device changes, the status of the target terminal device is notified to the configuration operation and maintenance server in the form of an event.
5. A method for remote configuration and operation of an embedded system, applied to a system platform, characterized in that: The system platform includes a configuration operation and maintenance server and a tunnel server; The method comprises: The configuration operation and maintenance server establishes a configuration encryption connection with the system gateway, and after successfully establishing the configuration encryption connection, sends the sub-tunnel configuration information to the system gateway; The tunnel server establishes a secure network tunnel encryption connection with the system gateway, and after successfully establishing the secure network tunnel encryption connection, establishes a sub-tunnel with the system gateway, wherein the sub-tunnel is used to transmit operation and maintenance information of the target terminal device; The tunnel server sends the operation and maintenance information to the system gateway through the sub-tunnel.
6. The method for remote configuration and operation of an embedded system according to claim 5, characterized in that: After the tunnel server sends the operation and maintenance information to the system gateway through the sub-tunnel, the method further includes: After receiving the reply message to the operation and maintenance information, the configuration and operation and maintenance server creates a target mapping device for the target terminal device; The configuration operation and maintenance server creates a new target mapping service under the target mapping device according to the reply message.
7. The method for remote configuration and operation of an embedded system according to claim 5, characterized in that: The method further comprises: The configuration operation and maintenance server issues an IP address query instruction for the target terminal device; When the device address status of the target terminal device changes, an event notification about the status of the target terminal device sent by the system gateway is received.
8. The method for remote configuration and operation of an embedded system according to claim 5, characterized in that: The method also includes: if the operation and maintenance service of the target terminal device is a web operation and maintenance service, after the tunnel server and the system gateway establish a sub-tunnel, the configuration operation and maintenance server adds the remote domain name of the web operation and maintenance service to the sub-tunnel configuration information.
9. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for remote configuration and operation of an embedded system as described in any one of claims 1 to 4, or can execute the method for remote configuration and operation of an embedded system as described in any one of claims 5 to 8.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, it implements the method for remote configuration and operation of an embedded system as described in any one of claims 1 to 4, or can execute the method for remote configuration and operation of an embedded system as described in any one of claims 5 to 8.