Terminal cooperation method and device of bastion host, electronic equipment and storage medium
By generating a shared link in the fortress machine, the problem of terminal nodes only supporting a single user in the prior art is solved, real-time sharing and collaboration between multiple users is realized, and collaboration efficiency is improved.
Patent Information
- Application Number
- CN202411966026.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-16
AI Technical Summary
Each end node of an existing bastion machine is only targeted at a single user and cannot support multi-user collaboration, resulting in the inability to realize real-time shared collaboration between different users.
Shared links are generated through the service node network of the bastion machine, allowing different users to cooperate terminally through shared links, real-time sharing and collaboration between multiple users.
Through shared links, users from different users can collaborate on a shared link to solve problems, improving the efficiency and real-time nature of multi-user collaboration.
Smart Images

Figure CN120017306A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication network technology, and in particular to a terminal collaboration method, device, electronic device and storage medium of a bastion host. Background Art
[0002] A bastion host is a device that uses various technical means to collect and monitor the system status, security events, and network activities of each component in a specific network environment in real time in order to protect the network and data from intrusion and damage from external and internal users, so as to centrally generate alarms, timely process, and audit and determine responsibility.
[0003] However, each terminal node in the existing bastion host is only for a single user and does not support multi-user collaboration, which makes it impossible to achieve real-time sharing and collaboration between different users. Summary of the invention
[0004] The embodiments of the present application provide a terminal collaboration method, device, electronic device and storage medium of a bastion host to achieve real-time sharing and collaboration between different users.
[0005] In a first aspect, an embodiment of the present application provides a terminal cooperation method of a bastion host, the method comprising:
[0006] In response to a terminal collaboration request of a first terminal node on the bastion host, a shared link of the first terminal node is generated through a service node corresponding to the first terminal node in a service node network of the bastion host; wherein the first terminal node corresponds to a first user, and the shared link is used to display the terminal nodes that have joined the shared link;
[0007] Link joining requests for the shared link are received from multiple second users respectively, so that the first user and the multiple second users can perform terminal collaboration through the shared link.
[0008] In an optional embodiment, before responding to the terminal cooperation request of the first terminal node on the bastion host, the method further includes:
[0009] Based on the user identifier of the first user, determine a first terminal node associated with the user identifier from multiple terminal nodes of the bastion host;
[0010] A terminal cooperation request sent by a first user through a first terminal node is received.
[0011] In an optional embodiment, generating a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host includes:
[0012] Determining communication distances between a plurality of service nodes included in the service node network and the first terminal node respectively;
[0013] Based on the obtained multiple communication distances, a target service node with the shortest communication distance is screened out from the multiple service nodes, and a shared link of the first terminal node is generated through the target service node.
[0014] In an optional embodiment, the service node network is constructed in the following manner:
[0015] Calculate the node communication delay between any two service nodes among the multiple service nodes corresponding to the bastion host;
[0016] Determine node connection relationships corresponding to the plurality of service nodes based on the plurality of node communication delays corresponding to the plurality of service nodes; wherein each node connection relationship is used to indicate at least two service nodes having the smallest node communication delay with the corresponding service node;
[0017] A service node network is constructed based on multiple service nodes and their corresponding node connection relationships.
[0018] In an optional embodiment, after constructing a service node network based on a plurality of service nodes and their corresponding node connection relationships, the method further includes:
[0019] In response to a communication request between a first service node and a second service node, a node communication path that meets a set communication delay requirement is screened out from a service node network; wherein the first service node and the second service node are any two service nodes from a plurality of service nodes;
[0020] The node communication path is used as a communication path between the first service node and the second service node.
[0021] In an optional embodiment, the method further includes:
[0022] If there is an abnormal service node in the node communication path, the node communication path that meets the set communication delay requirement is screened out from the service node network after the abnormal node is removed.
[0023] In an optional embodiment, the method further includes:
[0024] Receiving an operation permission request from a third user for the first terminal node;
[0025] When it is determined that the third user meets the operation permission opening condition set for the first terminal node, the operation permission of the first terminal node is opened to the third user.
[0026] In a second aspect, an embodiment of the present application further provides a terminal cooperation device of a bastion host, the device comprising:
[0027] A generation module, configured to respond to a terminal collaboration request of a first terminal node on a bastion host, and generate a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host; wherein the first terminal node corresponds to a first user, and the shared link is used to display the terminal nodes that have joined the shared link;
[0028] The collaboration module is used to receive link joining requests from multiple second users for the shared link, so that the first user and the multiple second users can perform terminal collaboration through the shared link.
[0029] In an optional embodiment, before responding to the terminal cooperation request of the first terminal node on the bastion host, the device further includes a receiving module, and the receiving module is specifically used to:
[0030] Based on the user identifier of the first user, determine a first terminal node associated with the user identifier from multiple terminal nodes of the bastion host;
[0031] A terminal cooperation request sent by a first user through a first terminal node is received.
[0032] In an optional embodiment, when generating a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host, the generating module is specifically used to:
[0033] Determining communication distances between a plurality of service nodes included in the service node network and the first terminal node respectively;
[0034] Based on the obtained multiple communication distances, a target service node with the shortest communication distance is screened out from the multiple service nodes, and a shared link of the first terminal node is generated through the target service node.
[0035] In an optional embodiment, the service node network is constructed by the generation module in the following manner:
[0036] Calculate the node communication delay between any two service nodes among the multiple service nodes corresponding to the bastion host;
[0037] Determine node connection relationships corresponding to the plurality of service nodes based on the plurality of node communication delays corresponding to the plurality of service nodes; wherein each node connection relationship is used to indicate at least two service nodes having the smallest node communication delay with the corresponding service node;
[0038] A service node network is constructed based on multiple service nodes and their corresponding node connection relationships.
[0039] In an optional embodiment, after constructing a service node network based on a plurality of service nodes and their corresponding node connection relationships, the generating module is further used to:
[0040] In response to a communication request between a first service node and a second service node, a node communication path that meets a set communication delay requirement is screened out from a service node network; wherein the first service node and the second service node are any two service nodes from a plurality of service nodes;
[0041] The node communication path is used as a communication path between the first service node and the second service node.
[0042] In an optional embodiment, the generating module is further used for:
[0043] If there is an abnormal service node in the node communication path, the node communication path that meets the set communication delay requirement is screened out from the service node network after the abnormal node is removed.
[0044] In an optional embodiment, the receiving module is further used for:
[0045] Receiving an operation permission request from a third user for the first terminal node;
[0046] When it is determined that the third user meets the operation permission opening condition set for the first terminal node, the operation permission of the first terminal node is opened to the third user.
[0047] In a third aspect, an embodiment of the present application further provides an electronic device, including:
[0048] Processor; and
[0049] Memory for storing programs,
[0050] The program includes instructions, which, when executed by a processor, cause the processor to execute the terminal collaboration method of the bastion host as described in the first aspect.
[0051] In a fourth aspect, an embodiment of the present application further provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a computer to execute the terminal collaboration method of the bastion host as described in the first aspect.
[0052] In a fifth aspect, the present application provides a computer program product, which, when called by a computer, enables the computer to execute the steps of the terminal collaboration method of the bastion host as described in the first aspect.
[0053] The beneficial effects of this application are as follows:
[0054] In the terminal collaboration method of the bastion host provided in the embodiment of the present application, in response to the terminal collaboration request of the first terminal node on the bastion host, a shared link of the first terminal node is generated through the service node corresponding to the first terminal node in the service node network of the bastion host; wherein the first terminal node corresponds to the first user, and the shared link can be used to display the terminal nodes that have joined the shared link; and link joining requests from multiple second users for the shared link are received, so that the first user and the multiple second users can perform terminal collaboration through the shared link. In this way, different terminals of different users can be gathered together through the shared link, so that users in different locations can collaborate on problems on a shared link.
[0055] In addition, other features and advantages of the present application will be described in the subsequent description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described here are used to provide a further understanding of the present application, constitute a part of the present application, and do not constitute an improper limitation on the present application. In the drawings:
[0057] Figure 1 A schematic diagram of an application scenario of a bastion host applicable to an embodiment of the present application;
[0058] Figure 2 A logical diagram of access control based on a bastion host provided for an embodiment of the present application;
[0059] Figure 3 A schematic diagram of an implementation flow of a terminal collaboration method of a bastion host provided in an embodiment of the present application;
[0060] Figure 4 A schematic diagram of a terminal node and its corresponding user identifier in a bastion host provided in an embodiment of the present application;
[0061] Figure 5 A schematic diagram of an implementation flow of a method for building a service node network provided in an embodiment of the present application;
[0062] Figure 6 A schematic diagram of the composition structure of a service node network provided in an embodiment of the present application;
[0063] Figure 7 A method based on the embodiment of the present application is provided Figure 2 Schematic diagram of specific application scenarios;
[0064] Figure 8 A schematic diagram of the structure of a terminal cooperation device of a bastion host provided in an embodiment of the present application;
[0065] Fig. 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0066] The embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as being limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not intended to limit the scope of protection of the present application.
[0067] It should be understood that the various steps described in the method implementation of the present application can be performed in different orders and / or performed in parallel. In addition, the method implementation may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this respect.
[0068] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments". Relevant definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc. mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0069] It should be noted that the modifications of "one" and "plurality" mentioned in the present application are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0070] The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0071] First, the design concept of the embodiment of the present application is briefly introduced below:
[0072] The current bastion host can centrally manage asset permissions, record operation data throughout the process, and restore operation and maintenance scenarios in real time, helping enterprise users build a unified, secure, and efficient operation and maintenance channel on the cloud; and ensure that cloud operation and maintenance work permissions can be controlled, operations can be audited, and compliance can be followed. That is, in a specific network environment, in order to protect the network and data from intrusion and damage from external and internal users, various technical means are used to collect and monitor the system status, security events, and network activities of each component in the network environment in real time, so as to centrally alarm, promptly handle, and audit and determine responsibilities.
[0073] However, each terminal node of the existing bastion host is only for a single user, that is, the terminal node does not support multi-user collaboration. In this way, if different users are in different locations, it will be difficult to achieve real-time collaborative processing between different users. Therefore, in order to achieve real-time shared collaboration between different users. The embodiment of the present application proposes a terminal collaboration method for a bastion host, which may specifically include: in response to a terminal collaboration request of a first terminal node on the bastion host, a shared link of the first terminal node is generated through a service node corresponding to the first terminal node in the service node network of the bastion host; wherein the first terminal node corresponds to the first user, and the shared link can be used to display the terminal nodes that have joined the shared link; receiving link joining requests from multiple second users for the shared link, respectively, so that the first user and multiple second users can perform terminal collaboration through the shared link. In this way, different terminals of different users can be brought together through a shared link, so that users in different locations can collaborate on a shared link to solve problems.
[0074] In particular, the preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application, and the embodiments of the present application and the features in the embodiments may be combined with each other if there is no conflict.
[0075] See also Figure 1 As shown, it is a schematic diagram of an application scenario of a bastion host provided by an embodiment of the present application. In this application scenario, the bastion host can intercept the operation and maintenance operation request of the operation and maintenance personnel (or operation and maintenance terminal), and analyze the operation content corresponding to the operation and maintenance operation request. Therefore, the bastion host is equivalent to a proxy server for the operation and maintenance personnel. During the operation, the operation and maintenance personnel first connect to the bastion host, and then submit the operation and maintenance operation request to the bastion host. After the operation and maintenance operation request passes the permission check of the bastion host, it will connect to the target device on behalf of the operation and maintenance personnel to complete the operation and maintenance operation request. Then, the target device returns the operation execution result to the bastion host, and finally the bastion host returns the operation execution result to the operation and maintenance personnel.
[0076] For example, see Figure 2As shown, the bastion host can logically isolate the operation and maintenance personnel from the target device, and establish a management mode of "operation and maintenance personnel => main account (bastion host) => authorization => slave account (target device account) => target device". The bastion host is the only entrance for the operation and maintenance personnel to operate the target device. The login process is that the operation and maintenance personnel log in to the bastion host with a unique user account, and then the bastion host will prompt the operation and maintenance personnel to select the target device that can be accessed according to the pre-configured access control rules. After the operation and maintenance personnel complete the selection, they will automatically log in to the target device. While solving the operation permission control and behavior audit, it also solves the problem that encryption protocols and graphic protocols cannot be audited through protocol restoration.
[0077] It should be noted that in the embodiments of the present application, there is no specific limitation on the specific types and quantities of operation and maintenance terminals, bastion hosts and target devices included in the above application scenarios.
[0078] In addition, in an optional implementation, the bastion host in the embodiment of the present application may include multiple terminal nodes and multiple service nodes. Each terminal node is used for a corresponding operation and maintenance personnel to log in to the bastion host, and each service node is used to execute the instruction operation of the corresponding operation and maintenance personnel on the corresponding terminal node.
[0079] The following describes the terminal collaboration method of the bastion host provided by the exemplary embodiment of the present application in combination with the above-mentioned application scenarios and with reference to the accompanying drawings. It should be noted that the above-mentioned application scenarios are only shown to facilitate understanding of the spirit and principles of the present application, and the implementation methods of the present application are not limited in this regard.
[0080] See also Figure 3 As shown, it is a schematic diagram of the implementation process of a terminal cooperation method of a bastion host provided in an embodiment of the present application. The execution subject takes the bastion host as an example. The specific implementation process of the method is as follows:
[0081] S301: In response to a terminal cooperation request of a first terminal node on a bastion host, generate a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host.
[0082] The first terminal node corresponds to the first user, that is, each terminal node is set for a specific user. Once a terminal node is used by a user, other users cannot directly use the terminal node.
[0083] The above-mentioned shared link can be used to display the terminal nodes that have been added to the shared link. Exemplarily, the above-mentioned shared link can be a hypertext markup language (HTML) 5.0 canvas, and of course other types of canvases are also possible. The added terminal nodes are displayed on the HTML 5.0 canvas.
[0084] Optionally, the embodiment of the present application does not specifically limit the size of the HTML5.0 canvas. For example, it can be an HTML5.0 canvas of a set size, that is, it can only display a certain number of terminal nodes. For another example, it can also be an infinitely large HTML5.0 canvas, that is, it can display all added terminal nodes.
[0085] It should also be noted that for different terminal nodes in the bastion host, different terminal nodes correspond to different shared links, that is, the shared links of different terminal nodes generated by the service nodes in the service node network of the bastion host are different.
[0086] In order to improve the terminal collaboration efficiency of the bastion host, before executing step S301, the bastion host can determine the first terminal node associated with the user identifier from the multiple terminal nodes of the bastion host based on the user identifier of the first user, so as to receive the terminal collaboration request sent by the first user through the first terminal node. In this way, the terminal node (i.e., the first terminal node) for which the first user has operation authority can be quickly determined based on the user identifier of the first user, so as to ensure that the first user can quickly send the terminal collaboration request through the first terminal node, thereby improving the terminal collaboration efficiency of the bastion host.
[0087] For example, see Figure 4 As shown, the bastion host can include 5 terminal nodes, namely: End.point1, End.point2, End.point3, End.point4 and End.point5, and the user identifiers corresponding to the 5 terminal nodes are: User_A, User_B, User_C, User_D and User_E. Then, assuming that the user identifier of the first user is User_C, the terminal device can quickly determine from the aforementioned 5 terminal nodes that the terminal node that the first user has the operation authority is End.point3. At this time, the bastion host can extract the relevant operation configuration for the terminal node End.point3. For example, the bastion host can improve the relevant configuration for receiving the terminal collaboration request sent by the first user through the terminal node End.point3.
[0088] It should be noted that the user identifier of the first user is a unique identifier of the first user, that is, the user identifier can uniquely identify the first user, and different users have different user identifiers.
[0089] In an optional implementation, when executing step S201, the bastion host can determine the communication distances between the multiple service nodes included in the service node network and the first terminal node, thereby selecting the target service node with the smallest communication distance from the multiple service nodes based on the obtained multiple communication distances, and generating a shared link of the first terminal node through the target service node. In this way, the service node closest to the first terminal node is used by default to build or generate a shared link of the first terminal node, thereby improving the speed of generating shared links to a certain extent.
[0090] Exemplarily, the communication distance may be the distance between the deployment location of the first terminal node and the deployment location of the corresponding service node. For example, the deployment location of the first terminal node is represented as (x1, y1, z1) and the deployment location of the service node A is represented as (x2, y2, z2). Then, the communication distance between the first terminal node and the service node A may be calculated using the following formula:
[0091]
[0092] Among them, D represents the communication distance between the first terminal node and the service node A; x1, y1 and z1 are respectively the horizontal coordinate, vertical coordinate and vertical coordinate of the first terminal node in the current coordinate system (such as the standard reference coordinate system); x2, y2 and z2 are respectively the horizontal coordinate, vertical coordinate and vertical coordinate of the service node A in the current coordinate system.
[0093] It should be noted that the bastion host may also use other distance calculation formulas to determine the communication distance between the first terminal node and the service node A. The embodiment of the present application does not specifically limit this.
[0094] Taking the five service nodes (e.g., Service.node1, Service.node2, Service.node3, Service.node4, and Service.node5) included in the service node network as an example, after determining that the communication distances between the five service nodes and the first terminal node are D1, D2, D3, D4, and D5, respectively, the five communication distances obtained can be sorted. For example, if the five communication distances are, from large to small, D3, D2, D5, D1, and D4, it can be determined that the communication distance between the service node Service.node4 and the first terminal node is the smallest, and therefore, the service node Service.node4 can be used as the service node for subsequently generating a shared link for the first terminal node.
[0095] To ensure that the service node network of the bastion host can provide high availability and low latency backend services, and provide real-time network services (or technical guarantees) for terminal sharing. In an optional implementation, refer to Figure 5 As shown in the figure, the service node network of the bastion host can be constructed in the following way:
[0096] S501: Calculate the node communication delay between any two service nodes among the multiple service nodes corresponding to the bastion host respectively.
[0097] Specifically, when executing step S501, for any one of the multiple service nodes, the node communication delay between the service node and all service nodes except the service node is calculated. For example, if the bastion host corresponds to 5 service nodes, then for any one of the 5 service nodes, the node communication delay between the service node and the other 4 service nodes is calculated.
[0098] It should be noted that when calculating the node communication delay between any two service nodes, the same test data can be used for testing. Moreover, for each group of service nodes (i.e., two service nodes), the node communication delay can be determined by averaging multiple calculations to improve the calculation accuracy of the node communication delay.
[0099] In addition, in order to further improve the calculation accuracy of the node communication delay, when calculating the node communication delay for each group of service nodes, each service node in each group of service nodes needs to play the role of both a data receiver and a data sender. For example, take the group of service nodes including service node 1 and service node 2 as an example. When service node 1 acts as a data sender and service node 2 acts as a data receiver, the node communication delay is the time required for the test data to be sent from service node 1 to service node 2; when service node 1 acts as a data receiver and service node 2 acts as a data sender, the node communication delay is the time required for the test data to be sent from service node 2 to service node 1.
[0100] S502: Determine node connection relationships corresponding to the multiple service nodes based on multiple node communication delays corresponding to the multiple service nodes.
[0101] Each node connection relationship can be used to indicate at least two service nodes with the smallest node communication delay with the corresponding service node. In this way, since each service node can communicate with at least two service nodes, when one of the multiple service nodes fails or cannot provide service, it can still ensure that the service nodes connected to the service node can complete normal communication through other service nodes.
[0102] Under the premise of ensuring that the service node network constructed subsequently meets high availability and low latency, the complexity of the service node network is reduced, and each of the above node connection relationships can be used to indicate the two service nodes with the smallest node communication delay with the corresponding service node. Taking service nodes 1 to 5 as an example, if the two service nodes with the smallest node communication delay with service node 1 are service node 3 and service node 4, the node connection relationship corresponding to service node 1 can be expressed as: service node 1-service node 3 and service node 1-service node 4.
[0103] S503: Building a service node network based on multiple service nodes and their corresponding node connection relationships.
[0104] Exemplarily, when executing step S503, refer to Figure 6 As shown, the bastion host can build the following according to the 6 service nodes and their corresponding node connection relationships: Figure 6 The mesh network shown is the service node network.
[0105] Obviously, based on the construction method of the service node network recorded in the above steps S501 to S503, a distributed mesh network composed of multiple service nodes can be obtained. Since the service node network is interconnected by service nodes distributed in different locations, there is no central node. In addition, any service node in the service node network is connected to at least two service nodes. When any of the at least two communication links corresponding to the service node fails, it can be completed through other communication links, which has high reliability. At the same time, the distributed mesh network is also easy to expand.
[0106] Moreover, in the existing bastion hosts, the service nodes at the back end are usually allocated according to a certain round-robin algorithm by using load balancing and other methods when deploying the network in a unified manner according to the cluster; and the service nodes are usually composed of a master node and a backup node, and high availability is provided by switching between the master node and the backup node. The service node network constructed by the embodiment of the present application can form a mesh network of service nodes under multiple subnets, and any service node in the service node network is connected to at least two other nodes. In this way, when any service node fails or an abnormality occurs, services can be provided by other service nodes in the service node network, thereby achieving a high availability effect. Therefore, the service node network constructed by the embodiment of the present application reduces the complexity of the service node network while ensuring high availability.
[0107] Optionally, when a new service node wants to join the service node network, it may automatically connect to at least two service nodes in the service node network with which it has the shortest communication distance or the shortest node communication delay.
[0108] Furthermore, after the bastion host has constructed a service node network consisting of the above-mentioned multiple service nodes, it can realize network communication between any two service nodes (for example, the first service node and the second service node) in the aforementioned service node network. That is, the node communication path (or node communication link) of any two service nodes is selected in the service node network to realize network communication between any two service nodes.
[0109] In order to meet the shortest node communication delay requirement between service nodes, the bastion host can respond to the communication request between the above-mentioned first service node and the above-mentioned second service node, and screen out the node communication path that meets the set communication delay requirement (i.e., the shortest node communication delay) from the above-mentioned constructed service node network, thereby using the above-mentioned node communication path as the communication path between the above-mentioned first service node and the above-mentioned second service node.
[0110] Specifically, the node communication delay between any two connected service nodes in the service node network constitutes the path weight value between the two service nodes. Through the shortest path algorithm (such as Dijkstra algorithm or Floyd algorithm) between the source service node (such as the first service node) and the target service node (such as the second service node), the communication path with the shortest communication delay between the first service node and the second service node can be calculated. In this way, when the first service node and the second service node communicate, they can use the communication path with the shortest communication delay calculated by the aforementioned shortest path algorithm to communicate.
[0111] Among them, the Dijkstra algorithm can start from the starting service node and gradually expand to other service nodes, each time selecting the unvisited node closest to the actual node and updating the distance to its adjacent nodes. Once the distance of a service node is determined, the service node will no longer be updated. The Floyd algorithm iteratively calculates the shortest path between all pairs of service nodes. Exemplarily, the Floyd algorithm can use a distance matrix, where the matrix diagonal is 0 initially, and the other elements are the weights of the edges, and iteratively updates the distance matrix until the shortest path between all service nodes is found.
[0112] It should be noted that the above Dijkstra algorithm is a greedy algorithm that cannot handle negative edge weights, while the above Floyd algorithm is a dynamic programming algorithm that can handle negative edge weights. Therefore, when assigning path weight values to service node components based on node communication delay, the edge weight processing characteristics of the shortest path algorithm can be combined for edge weight assignment.
[0113] In an optional implementation, if there are abnormal service nodes in the above-mentioned node communication paths, the bastion host can filter out node communication paths that meet the set communication delay requirements from the service node network after removing the abnormal nodes. In this way, it is possible to avoid the problem of abnormal service nodes existing on the filtered node communication paths, which in turn leads to the inability to achieve communication between the first service node and the second service node. In other words, the communication paths between service nodes can be adjusted in time according to the node status of the service nodes (i.e., normal status or abnormal status) to ensure normal communication between service nodes.
[0114] In the network topology of the service node network, each service node is connected to at least two service nodes, so each service node can also save the node status (i.e., node information) of at least two connected service nodes. In this way, when data is transmitted to the service node, a service node with a normal node status can be selected from the at least two connected service nodes according to the node status recorded by the service node as the service node in the subsequent node communication path.
[0115] It should be noted that the service node network may also be other types of network topologies, that is, any type of network topology that can achieve the same high availability and low latency effects as the distributed mesh network. For example, a point-to-point network architecture, a star network, etc. This application embodiment does not limit this.
[0116] S302: receiving link joining requests from multiple second users for the shared link respectively, so that the first user and the multiple second users perform terminal collaboration through the shared link.
[0117] Exemplarily, when executing step S302, after generating a shared link of the first terminal node, the first user can share the shared link with multiple second users. At this time, multiple second users can bring their respective terminal nodes to join the shared link, thereby realizing terminal collaboration between the first user and multiple second users.
[0118] See also Figure 7 As shown, taking the shared link as an infinite HTML5.0 canvas as an example, after sharing the HTML5.0 canvas, the terminal nodes corresponding to the multiple second users (for example, user 1, user 2 and user 3) that have joined can be displayed on the HTML5.0 canvas, which are: terminal 1, terminal 2 and terminal 3. In order to facilitate user operation, each user can add a new terminal node to the canvas, that is, each second user can add a new terminal node to the canvas. In addition, each terminal node has a corresponding cursor, and the terminal node and the cursor can be distinguished according to the (fill) color set for different users. In addition, by default, each second user only has the operation authority or control authority of the corresponding terminal node.
[0119] When a user needs to operate someone else's terminal node, he can request the operation permission of this terminal node. After obtaining the corresponding operation permission, he can operate the corresponding terminal node to achieve the purpose of collaborative sharing. Therefore, in an optional implementation method, the bastion host can also receive a request for operation permission from a third user for the first terminal node, so that when it is determined that the third user meets the operation permission opening conditions set for the first terminal node, the operation permission of the first terminal node is opened to the third user. Among them, the aforementioned operation permission opening conditions can be an operation whitelist for the first terminal node, that is, as long as the third user is in this operation whitelist, the operation permission of the first terminal node can be opened to the third user.
[0120] Optionally, the third user may also request the first user for operating authority, and the first user may open the operating authority of the first terminal node to the third user only after the first user determines that the operating authority of the first terminal node can be opened to the third user. Of course, there are other ways for the third user to obtain operating authority, which are not specifically limited in the embodiments of the present application. Therefore, if the third user initially has operating authority for the first terminal node, the third user can directly join the above-mentioned shared link.
[0121] Based on the above method, a low-latency distributed mesh network (i.e., service node network) is used to achieve real-time sharing of terminal nodes, and different terminals of different users are brought together through an infinite canvas (i.e., shared link), and then security is guaranteed through permission control, ultimately achieving the purpose of users in different locations collaborating on a single canvas to solve problems. That is, through a shared link, multiple users can operate multiple terminal nodes of a bastion machine on an infinite canvas, thereby achieving the effect of real-time sharing and collaboration, and facilitating users from different teams and locations to collaborate on the use of the bastion machine's terminal nodes.
[0122] In summary, in the terminal collaboration method of the bastion host provided in the embodiment of the present application, in response to the terminal collaboration request of the first terminal node on the bastion host, a shared link of the first terminal node is generated through the service node corresponding to the first terminal node in the service node network of the bastion host; wherein the first terminal node corresponds to the first user, and the shared link can be used to display the terminal nodes that have joined the shared link; and link joining requests from multiple second users for the shared link are received, so that the first user and multiple second users can perform terminal collaboration through the shared link. In this way, different terminals of different users can be brought together through the shared link, so that users in different locations can collaborate on problems on a shared link.
[0123] Further, based on the same technical concept, the present application embodiment provides a terminal cooperation device of a bastion host, and the terminal cooperation device of the bastion host is used to implement the above method flow of the present application embodiment. Figure 8 As shown, the terminal cooperation device 800 of the bastion host includes: a generation module 801, a cooperation module 802 and a receiving module 803, wherein:
[0124] A generation module 801 is used to respond to a terminal collaboration request of a first terminal node on a bastion host, and generate a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host; wherein the first terminal node corresponds to a first user, and the shared link is used to display the terminal nodes that have joined the shared link;
[0125] The collaboration module 802 is configured to receive link joining requests from multiple second users for the shared link, so that the first user and the multiple second users can perform terminal collaboration via the shared link.
[0126] In an optional embodiment, before responding to the terminal cooperation request of the first terminal node on the bastion host, the receiving module 803 is specifically used to:
[0127] Based on the user identifier of the first user, determine a first terminal node associated with the user identifier from multiple terminal nodes of the bastion host;
[0128] A terminal cooperation request sent by a first user through a first terminal node is received.
[0129] In an optional embodiment, when generating a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host, the generating module 801 is specifically used to:
[0130] Determining communication distances between a plurality of service nodes included in the service node network and the first terminal node respectively;
[0131] Based on the obtained multiple communication distances, a target service node with the shortest communication distance is screened out from the multiple service nodes, and a shared link of the first terminal node is generated through the target service node.
[0132] In an optional embodiment, the service node network is constructed by the generation module 801 in the following manner:
[0133] Calculate the node communication delay between any two service nodes among the multiple service nodes corresponding to the bastion host;
[0134] Determine node connection relationships corresponding to the plurality of service nodes based on the plurality of node communication delays corresponding to the plurality of service nodes; wherein each node connection relationship is used to indicate at least two service nodes having the smallest node communication delay with the corresponding service node;
[0135] A service node network is constructed based on multiple service nodes and their corresponding node connection relationships.
[0136] In an optional embodiment, after constructing a service node network based on a plurality of service nodes and their corresponding node connection relationships, the generating module 801 is further used to:
[0137] In response to a communication request between a first service node and a second service node, a node communication path that meets a set communication delay requirement is screened out from a service node network; wherein the first service node and the second service node are any two service nodes from a plurality of service nodes;
[0138] The node communication path is used as a communication path between the first service node and the second service node.
[0139] In an optional embodiment, the generating module 801 is further used for:
[0140] If there is an abnormal service node in the node communication path, the node communication path that meets the set communication delay requirement is screened out from the service node network after the abnormal node is removed.
[0141] In an optional embodiment, the receiving module 803 is further configured to:
[0142] Receiving an operation permission request from a third user for the first terminal node;
[0143] When it is determined that the third user meets the operation permission opening condition set for the first terminal node, the operation permission of the first terminal node is opened to the third user.
[0144] Based on the description of the above method embodiment and device embodiment, the exemplary embodiment of the present invention further provides an electronic device, including: at least one processor; and a memory connected to the at least one processor in communication. The memory stores a computer program that can be executed by the at least one processor, and the computer program is used to enable the electronic device to perform the method according to the embodiment of the present invention when executed by the at least one processor.
[0145] An embodiment of the present application also provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to execute a method according to an embodiment of the present application.
[0146] An embodiment of the present application also provides a computer program product, including a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to execute a method according to an embodiment of the present application.
[0147] See also Fig. 9 As shown, the structured block diagram of the electronic device 900 that can be used as the server or client of the present application will now be described, which is an example of the hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent the computer device of various forms of digital electronics, such as, laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only used as examples, and are not intended to limit the implementation of the present application described herein and / or required.
[0148] like Fig. 9 As shown, the electronic device 900 includes a computing unit 901, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 902 or a computer program loaded from a storage unit 908 to a random access memory (RAM) 903. In the RAM 903, various programs and data required for the operation of the device 900 can also be stored. The computing unit 901, the ROM 902, and the RAM 903 are connected to each other via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.
[0149] A plurality of components in the electronic device 900 are connected to the I / O interface 905, including: an input unit 906, an output unit 907, a storage unit 908, and a communication unit 909. The input unit 906 may be any type of device capable of inputting information to the electronic device 900, and the input unit 906 may receive input digital or character information, and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 907 may be any type of device capable of presenting information, and may include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 908 may include but is not limited to a disk, an optical disk. The communication unit 909 allows the electronic device 900 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks, and may include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, a WiFi device, a worldwide interoperability for microwave access (WiMax) device, a cellular communication device, and / or the like.
[0150] The computing unit 901 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSP), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 901 performs the various methods and processes described above. For example, in some embodiments, the terminal cooperation method of the above-mentioned bastion host may be implemented as a computer software program, which is tangibly included in a machine-readable medium, such as a storage unit 908. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 900 via the ROM 902 and / or the communication unit 909. In some embodiments, the computing unit 901 may be configured to execute the terminal cooperation method of the above-mentioned bastion host in any other appropriate manner (e.g., by means of firmware).
[0151] The program code for implementing the method of the present application can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, implements the functions / operations specified in the flow chart and / or block diagram. The program code can be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0152] In the context of the present application, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a RAM, a ROM, an erasable programmable read-only memory (EPROM) or a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0153] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0154] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a cathode ray tub (CRT) or a liquid crystal display (LCD) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0155] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0156] A computer system may include clients and servers. Clients and servers are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship to each other.
[0157] Furthermore, it should be understood that what is disclosed above is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present invention. Therefore, equivalent changes made according to the claims of the present invention are still within the scope covered by the present application.
Claims
1. A terminal cooperation method of a bastion host, characterized in that: include: In response to a terminal collaboration request of a first terminal node on a bastion host, a shared link of the first terminal node is generated through a service node corresponding to the first terminal node in a service node network of the bastion host; wherein the first terminal node corresponds to a first user, and the shared link is used to display terminal nodes that have joined the shared link; Link joining requests for the shared link are received from multiple second users respectively, so that the first user and the multiple second users can perform terminal collaboration through the shared link.
2. The method according to claim 1, characterized in that Before responding to the terminal cooperation request of the first terminal node on the bastion host, the method further includes: Based on the user identifier of the first user, determining the first terminal node associated with the user identifier from the plurality of terminal nodes of the bastion server; The terminal cooperation request sent by the first user through the first terminal node is received.
3. The method according to claim 1, characterized in that The generating a shared link of the first terminal node through a service node corresponding to the first terminal node in the service node network of the bastion host includes: Determining communication distances between each of a plurality of service nodes included in the service node network and the first terminal node; Based on the obtained multiple communication distances, a target service node with the shortest communication distance is screened out from the multiple service nodes, and a shared link of the first terminal node is generated through the target service node.
4. The method according to any one of claims 1 to 3, characterized in that The service node network is constructed in the following manner: Calculate the node communication delay between any two service nodes among the multiple service nodes corresponding to the bastion host respectively; Determine the node connection relationships corresponding to the multiple service nodes based on the multiple node communication delays corresponding to the multiple service nodes; wherein each node connection relationship is used to indicate at least two service nodes with the smallest node communication delay with the corresponding service node; The service node network is constructed based on the multiple service nodes and their corresponding node connection relationships.
5. The method according to claim 4, characterized in that After the service node network is constructed based on the plurality of service nodes and their corresponding node connection relationships, the method further includes: In response to a communication request between a first service node and a second service node, a node communication path that meets a set communication delay requirement is screened out from the service node network; wherein the first service node and the second service node are any two service nodes among the multiple service nodes; The node communication path is used as a communication path between the first service node and the second service node.
6. The method according to claim 5, characterized in that The method further comprises: If there is an abnormal service node in the node communication path, a node communication path that meets the set communication delay requirement is screened out from the service node network after the abnormal node is removed.
7. The method according to any one of claims 1 to 3, characterized in that The method further comprises: receiving a request from a third user for operation permission for the first terminal node; When it is determined that the third user meets the operation permission opening condition set for the first terminal node, the operation permission of the first terminal node is opened to the third user.
8. A terminal cooperation device of a bastion host, characterized in that: include: A generation module, configured to respond to a terminal collaboration request of a first terminal node on a bastion host, and generate a shared link of the first terminal node through a service node corresponding to the first terminal node in a service node network of the bastion host; wherein the first terminal node corresponds to a first user, and the shared link is used to display terminal nodes that have joined the shared link; The collaboration module is used to receive link joining requests from multiple second users for the shared link respectively, so that the first user and the multiple second users can perform terminal collaboration through the shared link.
9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.