Communication method, device and equipment
By setting up gateways among participants in cross-network interactions and using internal and external service ports to communicate, the security risks caused by port randomness in cross-network interactions are solved, and communication security is improved.
Patent Information
- Application Number
- CN202510239738.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-27
AI Technical Summary
In cross-network interaction, since most of the process ports are random and random, entry restrictions cannot be made through the firewall in time, which poses security risks.
By setting up gateways between source participants and target participants, using internal service ports to obtain routing information, and connecting to the other party's gateway through external service ports, establishing a target connection, so that the source client and the target client communicate through the target connection.
By setting up gateways in participants, communication security between clients in different network segments can be improved, external service ports can be fixed, firewall entry and exit rules management capabilities can be enhanced, and security risks can be reduced.
Smart Images

Figure CN120050321A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication security technology, and particularly to a communication method, apparatus and device. Background Art
[0002] Currently, both parties in cross-network segment interaction communicate through a direct connection method. At this time, the corresponding gateway ports need to be opened by the processes of both parties for communication. Since the number of ports opened by one party is uncertain, the process ports are mostly random ports, and it is impossible to make ingress and egress restrictions through the firewall in a timely manner, resulting in security risks. Summary of the Invention
[0003] The present invention provides a communication method, apparatus and device to improve the communication security between cross-network segment clients.
[0004] According to one aspect of the present invention, a communication method is provided, which is applied to the source gateway of the source participant. The method includes:
[0005] Obtaining source routing information sent by the source client of the source participant through the source internal service port; the source routing information includes the source client identifier of the source client, the target participant identifier of the target participant, and the target client identifier of the target client;
[0006] Connecting to the target gateway of the target participant according to the source routing information through the source external service port, establishing a target connection between the source gateway and the target gateway, so that the source client and the target client communicate through the target connection.
[0007] According to another aspect of the present invention, a communication method is provided, which is applied to the target gateway of the target participant. The method includes:
[0008] Obtaining target routing information sent by the target client of the target participant through the target internal service port; the target routing information includes the target client identifier of the target client, the source participant identifier of the source participant, and the source client identifier of the source client;
[0009] Connecting to the source gateway of the source participant according to the target routing information through the target external service port, establishing a target connection between the target gateway and the source gateway, so that the target client and the source client communicate through the target connection.
[0010] According to another aspect of the present invention, a communication apparatus is provided, which is configured in the source gateway of the source participant. The apparatus includes:
[0011] A source route information acquisition module, configured to acquire source route information sent by a source client of a source participant through a source internal service port; the source route information includes a source client identifier of the source client, a target participant identifier of a target participant, and a target client identifier of a target client.
[0012] An external communication module, configured to connect to a target gateway of the target participant through a source external service port according to the source route information, and establish a target connection between the source gateway and the target gateway, so that the source client and the target client communicate through the target connection.
[0013] According to another aspect of the present invention, there is provided a communication device, configured in a target gateway of a target participant, the device includes:
[0014] A target route information acquisition module, configured to acquire target route information sent by a target client of a target participant through a target internal service port; the target route information includes a target client identifier of the target client, a source participant identifier of a source participant, and a source client identifier of a source client.
[0015] An external communication module, configured to connect to a source gateway of the source participant through a target external service port according to the target route information, and establish a target connection between the target gateway and the source gateway, so that the target client and the source client communicate through the target connection.
[0016] According to another aspect of the present invention, there is provided an electronic device, the electronic device includes:
[0017] At least one processor; and
[0018] A memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the communication method according to any embodiment of the present invention.
[0020] According to another aspect of the present invention, there is provided a computer-readable storage medium, the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the communication method according to any embodiment of the present invention when executed by a processor.
[0021] According to another aspect of the present invention, there is provided a computer program product, the computer program product includes a computer program, and the computer program implements the communication method according to any embodiment of the present invention when executed by a processor.
[0022] In the technical solution of the embodiment of the present invention, source routing information sent by a source client of a source participant is obtained through an internal service port of the source; the source routing information includes a source client identifier of the source client, a target participant identifier of a target participant, and a target client identifier of a target client. Then, through an external service port of the source, a connection is established with a target gateway of the target participant according to the source routing information, and a target connection is established between the source gateway and the target gateway, so that the source client and the target client can communicate through the target connection. In the above technical solution, by setting gateways in the participants, that is, through communication connections via the internal service port and the external service port, the communication security between clients in different network segments can be improved.
[0023] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention, and for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0025] Figure 1 is an interaction diagram of two existing communication parties provided according to an embodiment of the present invention;
[0026] Figure 2 is a flowchart of a communication method provided according to an embodiment of the present invention;
[0027] Figure 3 is a flowchart of a communication method provided according to an embodiment of the present invention;
[0028] Figure 4 is an interaction diagram of a communication method provided according to an embodiment of the present invention;
[0029] Figure 5 is a schematic structural diagram of a communication device provided according to an embodiment of the present invention;
[0030] Figure 6 is a schematic structural diagram of a communication device provided according to an embodiment of the present invention;
[0031] Figure 7 is a schematic structural diagram of an electronic device for implementing the communication method of the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] To enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0033] It should be noted that in the description and claims of the present invention and the above-mentioned accompanying drawings, the terms "first", "second", "target", "source", etc. are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0034] In addition, it should also be noted that in the technical solution of the present invention, the collection, storage, use, processing, transmission, provision, and disclosure of relevant data such as routing data and communication data comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0035] Currently, when the two parties (i.e., the client of the source participating party and the client of the target participating party) in the security request interaction communicate, they all communicate through a direct connection method. At this time, the corresponding gateway ports of both parties' processes need to be opened for communication. Since the number of ports opened by one party is uncertain, the process ports are mostly random ports, and it is impossible to make ingress and egress restrictions through the firewall in a timely manner. The interaction diagram between the request parties is as Figure 1 shown:
[0036] Among them, the interaction logic is as follows: Party-B (denoted as Party B) acts as the host and starts service B-host-1 on port 50001 (this port is a random port). Party-A (denoted as Party A) acts as the guest and connects to B-host-1 through the address of the service transmitted by the upper layer. A and B perform a security request interaction. Since Party B can start many hosts at the same time, the ports are mostly random ports, making it impossible to set ingress and egress rules for the firewall. Moreover, once the service is started, it is also impossible to authenticate the connected guest party.
[0037] Figure 2It is a flowchart of a communication method provided according to an embodiment of the present invention. This embodiment is applicable to the situation of secure communication between cross-segment clients. This method can be executed by a communication device, which can be implemented in the form of hardware and / or software, and can be configured in an electronic device carrying communication functions, such as the source gateway of the source participant; optionally, the source gateway includes two services, an internal source service and an external source service. In this embodiment, communication between the source participant and the target participant is carried out through the gateway. As Figure 2 shown, the method includes:
[0038] S110. Obtain the source routing information sent by the source client of the source participant through the internal source service port.
[0039] Among them, the internal source service port refers to the port provided for the clients inside the source participant for the clients inside the source participant to connect. The source participant may include at least one source client.
[0040] The so-called source routing information refers to the routing information of the source client; optionally, the source routing information includes the source client identifier of the source client, the target participant identifier of the target participant, and the target client identifier of the target client. Among them, the source client identifier is used to uniquely identify the source client and is represented in the form of a string; the target participant identifier is used to uniquely identify the target participant and is represented in the form of a string; the target client identifier is used to uniquely identify the target client and is represented in the form of a string.
[0041] Specifically, the source client of the source participant connects to the source gateway, and after the connection, sends the source routing information to the source gateway; correspondingly, the source gateway of the source participant obtains the source routing information sent by the source client through the internal source service port.
[0042] S120. Connect to the target gateway of the target participant according to the source routing information through the external source service port, establish a target connection between the source gateway and the target gateway, so that the source client and the target client can communicate through the target connection.
[0043] Among them, the external source service port refers to the port provided by the source participant to the outside for other external participants to connect; it should be noted that the external source service port can be set through the firewall, that is to say, it can be set through the firewall which ports in the source gateway are available for external connection access; in this way, compared with the existing two-party interaction where multiple clients of the target participant can be started simultaneously, the corresponding ports are random ports and the access rules for entry and exit cannot be set through the firewall, and once the service is started, the source clients connected cannot be authenticated. By setting up a gateway in the participant and then configuring the external service interface through the firewall, the external service port can be fixed to improve security.
[0044] The so-called target connection refers to the only connection established for this interaction between the source participant and the target participant.
[0045] An optional method is to find the target external service port of the target gateway from the routing table according to the target participant identifier of the target participant in the source routing information; establish a target connection between the source gateway and the target gateway by connecting through the source external service port and the target external service port; obtain the communication data sent by the source client, and send the communication data to the target client through the target connection, so that communication can be carried out between the source client and the target client.
[0046] Specifically, the source gateway finds the target external service port of the target gateway from the routing table according to the target participant identifier of the target participant in the source routing information. The source gateway connects through the source external service port and the target external service port, and the source gateway and the target gateway perform a handshake to establish a target connection between the source gateway and the target website. After the connection is established, the source gateway notifies the source client that it can perform an interaction operation with the target client. The source client sends communication data to the source gateway. The source gateway obtains the communication data sent by the source client and sends the communication data to the target client through the target connection, that is, the source gateway and the target gateway act as data routers to enable communication between the source client and the target client.
[0047] The technical solution of the embodiment of the present invention obtains the source routing information sent by the source client of the source participant through the source internal service port; the source routing information includes the source client identifier of the source client, the target participant identifier of the target participant, and the target client identifier of the target client. Then, through the source external service port, a connection is made with the target gateway of the target participant according to the source routing information to establish a target connection between the source gateway and the target gateway, so that the source client and the target client can communicate through the target connection. The above technical solution can improve the communication security between clients in different network segments by setting gateways at the participants, that is, through communication connections via internal service ports and external service ports.
[0048] Figure 3 It is a flowchart of a communication method provided according to an embodiment of the present invention. This embodiment is applicable to the situation of how to securely communicate between cross-network segment clients. This method can be executed by a communication device, which can be implemented in the form of hardware and / or software, and the device can be configured in an electronic device carrying a communication function, such as the target gateway of the target participant; optionally, the target gateway includes two services, a target internal service and a target external service. In this embodiment, communication between the source participant and the target participant is carried out through the gateway. As Figure 3 shown, the method includes:
[0049] S210. Obtain the target routing information sent by the target client of the target participant through the target internal service port.
[0050] Among them, the target internal service port refers to the port provided by the target client within the target participant for the clients within the target participant to connect. The target participant may include at least one target client.
[0051] The so-called target routing information refers to the routing information of the target client; optionally, the target routing information includes the target client identifier of the target client, the source participant identifier of the source participant, and the source client identifier of the source client. Among them, the source client identifier is used to uniquely identify the source client and is represented in the form of a string; the source participant identifier is used to uniquely identify the source participant and is represented in the form of a string; the target client identifier is used to uniquely identify the target client and is represented in the form of a string.
[0052] Specifically, the target client of the target participant connects to the target gateway, and after the connection, sends the target routing information to the target gateway; correspondingly, the target gateway of the target participant obtains the target routing information sent by the target client of the target participant through the target internal service port.
[0053] S220. Connect to the source gateway of the source participant according to the target routing information through the target external service port, and establish a target connection between the target gateway and the source gateway, so that the target client and the source client can communicate through the target connection.
[0054] Among them, the target external service port refers to the port provided by the target participant to the outside for other external participants to connect; it should be noted that the target external service port can be set through the firewall, that is to say, it can be set through the firewall which ports in the target gateway are available for external connection access; in this way, compared with the existing two-party interaction, the target participant can start multiple clients at the same time, and their corresponding ports are random ports, and the access rules cannot be set through the firewall. Once the service is started, the target clients connected cannot be authenticated either. By setting up a gateway in the participant and then configuring the external service interface through the firewall, the external service port can be fixed to improve security.
[0055] The so-called target connection refers to the only connection established between the source participant and the target participant for this interaction.
[0056] An optional method is to find the source external service port of the source gateway from the routing table according to the source participant identifier in the target routing information; establish a target connection between the target gateway and the source gateway by connecting through the target external service port and the source external service port; obtain the communication data sent by the source gateway through the target connection, and send the communication data to the target client, so that the source client and the target client can communicate with each other.
[0057] Specifically, the target gateway looks up the source external service port of the source gateway in the routing table according to the source participant identifier of the source participant in the target routing information. The target gateway connects to the source external service port through the target external service port, and the target gateway and the source gateway perform a handshake to establish a target connection between the target gateway and the source website. After the connection is established, the target gateway notifies the target client that it can perform interaction operations with the source client. The target gateway obtains the communication data of the source client sent by the source gateway through the target connection, and sends the communication data to the target client. When the target client sends communication data to the target gateway, the target gateway obtains the communication data sent by the target client and sends the communication data to the target client. That is, the source gateway and the target gateway act as data routers to enable communication between the source client and the target client.
[0058] The technical solution of the embodiment of the present invention obtains target routing information sent by the target client of the target participant through the target internal service port. The target routing information includes the target client identifier of the target client, the source participant identifier of the source participant, and the source client identifier of the source client. Then, through the target external service port, a connection is established with the source gateway of the source participant according to the target routing information to establish a target connection between the target gateway and the source gateway, so that the target client and the source client can communicate through the target connection. The above technical solution can improve the communication security between clients in different network segments by setting gateways for participants, that is, through communication connections using internal service ports and external service ports.
[0059] Figure 4 It is an interaction diagram of a communication method provided according to an embodiment of the present invention. The source participant Party-A and the target participant Party-B are respectively provided with gateways GateWay-A and GateWay-B. Among them, taking the source participant as an example, the routing table information of the source gateway for the outside is as follows:
[0060] Participant ID Address Party-A 192.169.1.111:10000 Party-B 192.169.1.112:10000
[0061] Among them, the main protocol items for the connection between the gateway and the other gateway are as follows:
[0062] Name Type Description party_id string Own Participant ID node_id string Own Node (Client) ID dest_party_id string Other Party ID dest_node_id string Other Node (Client) ID … … …
[0063] Among them, the main protocol items for the intersection client to connect to the gateway are as follows
[0064] Name Type Description node_id string Own Node (Client) ID dest_party_id string Other Party ID dest_node_id string Other Node (Client) ID … … …
[0065] Figure 5It is a schematic structural diagram of a communication device provided according to an embodiment of the present invention. This embodiment is applicable to the situation of secure communication between cross-network segment clients. The device can be implemented in the form of hardware and / or software, and can be configured in an electronic device carrying a communication function, such as the source gateway of the source participant. As Figure 5 shown, the device includes:
[0066] A source routing information acquisition module 310, configured to obtain source routing information sent by a source client of a source participant through a source internal service port; the source routing information includes a source client identifier of the source client, a target participant identifier of a target participant, and a target client identifier of a target client;
[0067] An external communication module 320, configured to connect to a target gateway of a target participant through a source external service port according to the source routing information, and establish a target connection between the source gateway and the target gateway, so that the source client and the target client communicate through the target connection.
[0068] The technical solution of the embodiment of the present invention obtains source routing information sent by a source client of a source participant through a source internal service port; the source routing information includes a source client identifier of the source client, a target participant identifier of a target participant, and a target client identifier of a target client. Then, through the source external service port, a connection is made with the target gateway of the target participant according to the source routing information, and a target connection between the source gateway and the target gateway is established, so that the source client and the target client communicate through the target connection. The above technical solution can improve the communication security between clients in different network segments by setting gateways at the participants, that is, by performing communication connections through the internal service port and the external service port.
[0069] Optionally, the external communication module 320 is specifically configured to:
[0070] Find the target external service port of the target gateway from the routing table according to the target participant identifier in the source routing information;
[0071] Establish a target connection between the source gateway and the target gateway by connecting the source external service port to the target external service port;
[0072] Obtain communication data sent by the source client, and send the communication data to the target client through the target connection, so that communication is carried out between the source client and the target client.
[0073] Optionally, the source external service port is set through a firewall.
[0074] The communication device provided by the embodiment of the present invention can execute the communication method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0075] Figure 6 It is a schematic structural diagram of a communication device provided according to an embodiment of the present invention. This embodiment is applicable to the situation of how secure communication is carried out between cross-segment clients. The device can be implemented in the form of hardware and / or software, and can be configured in an electronic device carrying a communication function, such as the target gateway of the target participant. As Figure 6 shown, the device includes:
[0076] A target routing information acquisition module 410, configured to acquire target routing information sent by a target client of a target participant through a target internal service port; the target routing information includes a target client identifier of the target client, a source participant identifier of the source participant, and a source client identifier of the source client;
[0077] An external communication module 420, configured to connect to the source gateway of the source participant through the target external service port according to the target routing information, establish a target connection between the target gateway and the source gateway, so that the target client and the source client communicate through the target connection.
[0078] The technical solution of the embodiment of the present invention acquires target routing information sent by a target client of a target participant through a target internal service port. The target routing information includes a target client identifier of the target client, a source participant identifier of the source participant, and a source client identifier of the source client. Then, through the target external service port, a connection is made to the source gateway of the source participant according to the target routing information, and a target connection between the target gateway and the source gateway is established, so that the target client and the source client communicate through the target connection. The above technical solution can improve the communication security between clients in different network segments by setting gateways at the participants, that is, by performing communication connections through internal service ports and external service ports.
[0079] Optionally, the external communication module 420 is specifically configured to:
[0080] Find the source external service port of the source gateway from the routing table according to the source participant identifier in the target routing information;
[0081] Establish a target connection between the target gateway and the source gateway by connecting the target external service port to the source external service port;
[0082] Acquire communication data sent by the source gateway through the target connection, and send the communication data to the target client, so that communication is carried out between the source client and the target client.
[0083] Optionally, the target external service port is set through a firewall.
[0084] The communication device provided by an embodiment of the present invention can execute the communication method provided by any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution of the method.
[0085] According to an embodiment of the present invention, the present invention also provides an electronic device, a readable storage medium, and a computer program product.
[0086] Figure 7 It is a schematic structural diagram of an electronic device for implementing the communication method of the embodiment of the present invention. FIG. X shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0087] As Figure 7 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0088] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0089] The processor 11 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the communication method.
[0090] In some embodiments, the communication method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the communication method described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute the communication method by any other suitable means (e.g., by means of firmware).
[0091] The various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), systems-on-chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special or general-purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0092] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processors of general-purpose computers, special-purpose computers, or other programmable data processing devices, such that when the computer programs are executed by the processors, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0093] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0094] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).
[0095] The systems and techniques described herein can be implemented in a computing system that includes backend components (such as, for example, a data server), or a computing system that includes middleware components (such as, for example, an application server), or a computing system that includes frontend components (such as, for example, a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as, for example, a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0096] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0097] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0098] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A communication method, characterized in that: Applied to a source gateway of a source participant, the method comprises: Acquire source routing information sent by a source client of a source participant through a source internal service port; the source routing information includes a source client identifier of the source client, a target participant identifier of a target participant, and a target client identifier of a target client; Through the source external service port, a connection is made with the target gateway of the target participant according to the source routing information, and a target connection is established between the source gateway and the target gateway, so that the source client and the target client communicate through the target connection.
2. The method according to claim 1, characterized in that Connecting to the target gateway of the target participant through the source external service port according to the source routing information, and establishing a target connection between the source gateway and the target gateway, so that the source client and the target client communicate through the target connection, including: According to the target participant identifier of the target participant in the source routing information, searching the target external service port of the target gateway from the routing table; Connecting the source external service port to the target external service port to establish a target connection between the source gateway and the target gateway; The communication data sent by the source client is acquired, and the communication data is sent to the target client through the target connection, so that the source client and the target client communicate with each other.
3. The method according to claim 1 or 2, characterized in that: The source external service port is set through a firewall.
4. A communication method, characterized in that: Applied to a target gateway of a target participant, the method comprises: Acquire target routing information sent by a target client of a target participant through a target internal service port; the target routing information includes a target client identifier of the target client, a source participant identifier of a source participant, and a source client identifier of a source client; Through the target external service port, a connection is made with the source gateway of the source participant according to the target routing information, and a target connection is established between the target gateway and the source gateway, so that the target client and the source client communicate through the target connection.
5. The method according to claim 4, characterized in that Connecting to the source gateway of the source participant through the target external service port according to the target routing information, and establishing a target connection between the target gateway and the source gateway, so that the target client communicates with the source client through the target connection, including: According to the source participant identifier of the source participant in the target routing information, searching the source external service port of the source gateway from the routing table; Connecting the target external service port to the source external service port to establish a target connection between the target gateway and the source gateway; The communication data sent by the source gateway through the target connection is acquired, and the communication data is sent to the target client, so that the source client and the target client communicate with each other.
6. According to the method of claim 4 or 5, the target external service port is set through a firewall.
7. A communication device, characterized in that: A source gateway configured at a source participant, the device comprising: A source routing information acquisition module, used to acquire source routing information sent by a source client of a source participant through a source internal service port; the source routing information includes a source client identifier of the source client, a target participant identifier of a target participant, and a target client identifier of a target client; The external communication module is used to connect with the target gateway of the target participant through the source external service port according to the source routing information, and establish a target connection between the source gateway and the target gateway, so that the source client and the target client communicate through the target connection.
8. A communication device, characterized in that: A target gateway configured at a target participant, the device comprising: A target routing information acquisition module, used to acquire the target routing information sent by the target client of the target participant through the target internal service port; the target routing information includes the target client identifier of the target client, the source participant identifier of the source participant, and the source client identifier of the source client; The external communication module is used to connect to the source gateway of the source participant through the target external service port according to the target routing information, and establish a target connection between the target gateway and the source gateway, so that the target client and the source client can communicate through the target connection.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the communication method according to any one of claims 1 to 6.