Communication method and device, power distribution network, storage medium and program product
By using the communication method between the control equipment and the network equipment in the distribution network, and using the instructions information to ensure access to the legal equipment, the problem of low network security in the distribution network is solved and network security is improved.
Patent Information
- Application Number
- CN202311649188.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-01
- Publication Date
- 2025-06-03
AI Technical Summary
There is a problem of low network security in the distribution network, especially in unguarded places, which may lead to illegal equipment being vertically directed to the main site, illegal access to the main site data or attacking the main site network.
By implementing a communication method between the control device and the network device, using the first indication information and the second indication information, it is ensured that only a legitimate network device can access the control device, thereby improving network security.
This method effectively avoids the equipment poses safety hazards to the distribution network through other ports before the network equipment is determined to be legal, and improves the network security of the distribution network.
Smart Images

Figure CN120091042A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to communication technologies, and in particular, to a communication method, apparatus, distribution network, storage medium, and program product. Background Art
[0002] The distribution network may refer to a network formed by communication devices arranged in each power distribution site (such as multiple sites including a main power service station, a substation, a switching station, a ring main unit, a community power distribution room, etc.) in a power distribution architecture. This distribution network can carry information and data related to power distribution.
[0003] Currently, the current operation and maintenance of the distribution network mainly rely on manual operation and maintenance, and there is no network management software to manage the network security of the distribution network. Moreover, places such as the above-mentioned ring main units and community power distribution rooms are usually unattended, and there is a possibility that communication devices such as switches in the places are illegally connected or replaced, which may lead to illegal devices directly accessing the main station vertically, illegally accessing the main station data, or attacking the main station network. Therefore, the distribution network has the problem of low network security. Summary of the Invention
[0004] The present application provides a communication method, apparatus, distribution network, storage medium, and program product to improve the network security of the distribution network.
[0005] In a first aspect, the present application provides a communication method applied to a control device. The method includes:
[0006] Sending a first indication message to a first control starting point device, where the first indication message is used to instruct the first control starting point device to use a target port as a device interconnection control port;
[0007] Receiving a request message sent by the first control starting point device; the request message includes: an identifier of a network device to be connected to the control device received by the first control starting point device through the device interconnection control port;
[0008] When determining that the network device is legal according to the identifier, sending a second indication message to the first control starting point device, where the second indication message is used to indicate that the network device is legal.
[0009] In a possible implementation, when determining that the network device is legal according to the identifier, the method further includes:
[0010] Regarding the network device as a second control starting point device.
[0011] In a possible implementation, the first indication information is further used to indicate that the device interconnection control port allows the traffic required for receiving the identifier to pass through; the second indication information is used to indicate lifting the restriction on the device interconnection control port, so that the first control starting device responds to the second indication information and communicates with the network device to be connected to the control device.
[0012] In a second aspect, the present application provides a communication method applied to a first control starting device. The method includes:
[0013] Receiving first indication information sent by a control device and using a target port as a device interconnection control port; the first indication information is used to indicate that the first control starting device uses the target port as the device interconnection control port;
[0014] Receiving, through the device interconnection control port, an identifier of a network device to be connected to the control device, and sending a request message including the identifier to the control device;
[0015] In a case of receiving second indication information fed back by the control device according to the request message, communicating with the network device, where the second indication information is used to indicate that the network device is legal.
[0016] In a possible implementation, the first indication information is further used to indicate that the device interconnection control port allows the traffic required for receiving the identifier to pass through; the second indication information is used to indicate lifting the restriction on the device interconnection control port.
[0017] In a third aspect, the present application provides a communication device applied to a control device. The device includes:
[0018] A first sending module, configured to send first indication information to a first control starting device, where the first indication information is used to indicate that the first control starting device uses a target port as a device interconnection control port;
[0019] A receiving module, configured to receive a request message sent by the first control starting device; the request message includes: an identifier of a network device to be connected to the control device received by the first control starting device through the device interconnection control port;
[0020] A second sending module, configured to send second indication information to the first control starting device when determining that the network device is legal according to the identifier, where the second indication information is used to indicate that the first control starting device communicates with the network device.
[0021] In a fourth aspect, the present application provides a communication device applied to a first control starting device. The device includes:
[0022] A receiving module, configured to receive first indication information sent by a control device, use a target port as a device interconnection management port; receive an identifier of a network device to be connected to the control device through the device interconnection management port; the first indication information is used to instruct the first management starting device to use the target port as the device interconnection management port.
[0023] A sending module, configured to send a request message including the identifier to the control device.
[0024] A communication module, configured to communicate with the network device when receiving second indication information fed back by the control device according to the request message, where the second indication information is used to indicate that the network device is legal.
[0025] In a fifth aspect, the present application provides a distribution network, where the distribution network includes a control device and network devices in at least one power distribution site; the control device is configured to execute the method according to any one of the first aspect; the first management starting device is one of the network devices, and the first management starting device is configured to execute the method according to any one of the second aspect.
[0026] In a sixth aspect, the present application provides a computer-readable storage medium, on which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, the method according to any one of the first aspect and / or the second aspect is implemented.
[0027] In a seventh aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method according to any one of the first aspect and / or the second aspect is implemented.
[0028] The communication method, device, distribution network, storage medium and program product provided by this application enable the first control starting device to receive the identifier of the network device to be connected to the control device through the target port according to the instruction of the control device, avoiding potential security risks to the distribution network caused by the network device to be connected to the control device through other ports before determining the legality of the network device to be connected to the control device, and improving the network security of the distribution network. The first control starting device can send the identifier of the network device to be connected to the control device to the control device, so that the control device can verify the legality of the network device to be connected to the control device. When the network device to be connected to the control device is legal, the first control starting device communicates with the network device to be connected to the control device to connect the network device to be connected to the control device to the control device. Through the above method, while ensuring that the network device to be connected to the control device can be connected to the control device, it also ensures that the network device connected to the control device is a legal device, improving the security of the connected devices in the control device and further enhancing the network security of the network where the control device is located. Description of the Drawings
[0029] To more clearly illustrate the technical solutions of this application, the following will briefly introduce the drawings required for the description of the application embodiments. Obviously, the drawings below are some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0030] Figure 1 It is a schematic diagram of a power distribution architecture;
[0031] Figure 2 It is a schematic diagram of a scenario for accessing a distribution network provided by this application;
[0032] Figure 3 It is a schematic flowchart of a communication method provided by this application;
[0033] Figure 4 It is a schematic flowchart of another communication method provided by this application;
[0034] Figure 5 It is a schematic structural diagram of a communication device provided by this application;
[0035] Figure 6 It is a schematic structural diagram of another communication device provided by this application;
[0036] Figure 7 It is a schematic structural diagram of an electronic device provided by this application.
[0037] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and will be described in more detail hereinafter. These drawings and the textual description are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by reference to specific embodiments. Detailed Description of Specific Embodiments
[0038] To make the objectives, technical solutions, and advantages of the present application clearer, the technical solutions in the present application will be clearly and completely described below with reference to the accompanying drawings in the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without making creative efforts shall fall within the scope of protection of the present application.
[0039] First, some noun concepts related to the present application will be explained below:
[0040] Power distribution architecture: Figure 1 It is a schematic diagram of a power distribution architecture. As Figure 1 shown, the power distribution architecture may include multiple locations such as a power business master station, a substation, a switching station, a ring main unit, and a community power distribution room. Among them, the power business master station is the control center for various services such as power distribution services, dispatching services, and comprehensive services. The substation, such as a 110-kilovolt (kV) substation, is used for high / low voltage conversion (transforming electricity) of the transmission network and is also an execution node for power dispatching. The switching station, such as a 10-kV switching station, is usually the next-level node for power distribution from the substation downward. It is an independent outdoor room (usually ranging from a few square meters to dozens of square meters). There are power distribution switches, wireless terminal devices (Data Transfer unit, DTU), etc. in the switching station. The ring main unit, such as a 10-kV ring main unit, is a passing (relay) node for power distribution (outdoor metal cabinet). Generally, a line is led from a neighboring ring main unit to the community power distribution room, and multiple ring main units may be passed through during power distribution. The community power distribution room is the end node of power distribution (converted into residential electricity) and is generally inside the community.
[0041] It should be understood that Figure 1 this is only an exemplary description of the power distribution architecture. In some embodiments, the first node downward from the substation may be, for example, a switching station, or a ring main unit, or a larger power distribution room, etc.
[0042] Distribution network: The distribution network may refer to the network formed by the communication devices arranged in each location (such as the multiple locations of the above-mentioned power business master station, substation, switching station, ring main unit, community power distribution room, etc.) in the power distribution architecture. The distribution network can usually be divided into a main network and an access network. As Figure 1As shown, the communication devices deployed in the power service master station can be the communication devices of the main network. The communication devices in substations, switchgear stations, ring main units, community distribution rooms, etc. can be the communication devices in the access network. That is to say, the network services of the distribution network can extend longitudinally from the power service master station to the end community distribution room, passing through multiple levels. This distribution network can carry information and data related to power distribution.
[0043] Currently, the operation and maintenance of the current distribution network are relatively primitive, mainly relying on manual operation and maintenance, and there is no network management software to manage the network security of the distribution network. And the above-mentioned ring main units, community distribution rooms, etc. are generally outdoors, and there are usually no personnel on guard in these places, and important industrial switches are deployed in these places. This leads to certain security risks in the distribution network. For example, after the outdoor ring main unit / distribution room is privately opened, it is illegally connected or replaced by illegal devices, and then the illegal devices may directly reach the master station longitudinally, illegally access the master station data or attack the master station network. Therefore, the distribution network has the problem of low network security.
[0044] Considering the above problems existing in the distribution network, this application proposes a method for verifying network devices accessing the distribution network to improve the security of the network devices accessing the distribution network and improve the network security of the distribution network.
[0045] The technical solutions provided by this application will be described in detail below in conjunction with specific embodiments. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0046] First, Figure 2 This is a schematic diagram of a scenario for accessing the distribution network provided by this application. As Figure 2 shown, the distribution network can include a control device, and network devices in at least one power distribution site. The above control device can verify the network device to be accessed to the distribution network through the first control starting point device (one of the network devices in the above at least one power distribution site).
[0047] Exemplarily, the above control device can be an electronic device with processing functions deployed in the aforementioned power service master station. The above first control starting point device can be, for example, a network device in a substation with strict security measures or manned, or a switchgear station with a security access control.
[0048] It should be understood that this application does not limit the type of the above network device. Exemplarily, the above network device can be an electronic device with network communication functions such as a switch.
[0049] It should be understood that the above is only an exemplary description of the communication method provided by this application, taking the network where the control device is located as the distribution network as an example. This application does not limit the network where the control device is located.
[0050] Figure 3 It is a schematic flow chart of a communication method provided by this application. As Figure 3 shown, the method may include the following steps:
[0051] S101. The control device sends first indication information to the first management starting device.
[0052] Among them, the above first indication information can be used to instruct the first management starting device to use the target port as the device interconnection management port. The first management starting device can be one of the network devices in the network.
[0053] It should be understood that the control device can, for example, respond to a command to send the above first indication information triggered by the user and send the first indication information to the first management starting device. Or, taking the distribution network as an example, the control device can also receive the identifier of the network device in the distribution network input by the user, and the identifier of the port of the network device, and use the network device as the first management starting device and the port with the identifier as the target port. Then, the control device can generate the above first indication information according to the identifier of the port.
[0054] S102. The first management starting device receives the first indication information sent by the control device and uses the target port as the device interconnection management port.
[0055] Exemplarily, the above first indication information can include, for example, the identifier of the above target port. The first management starting device can, for example, obtain the identifier of the target port from the above first indication information, determine the target port according to the identifier of the target port, and use the target port as the device interconnection management port.
[0056] S103. The first management starting device receives the identifier of the network device to be connected to the control device through the device interconnection management port.
[0057] Exemplarily, the network device to be connected to the control device can be an electronic device with network communication functions such as a switch. The identifier of the network device to be connected to the control device can be, for example, the Media Access Control Address (MAC address) or the serial number (SN) and other unique identifiers of the network device.
[0058] Exemplarily, the first control starting device can receive the identifier of the network device through the above-mentioned device interconnection control port by using the Link Layer Discovery Protocol (LLDP).
[0059] It should be understood that the present application does not limit the connection manner between the first control starting device and the network device of the to-be-accessed control device. For example, the connection between the first control starting device and the network device of the to-be-accessed control device can be a wired connection or a wireless connection.
[0060] S104. The first control starting device sends a request message including the above identifier to the control device.
[0061] That is to say, the above request message can include: the identifier of the network device of the to-be-accessed control device received by the first control starting device through the device interconnection control port. Exemplarily, after receiving the identifier of the network device of the to-be-accessed control device, the first control starting device can send a request message including the above identifier to the control device through LLDP.
[0062] Correspondingly, the control device can receive the above request message from the first control starting device.
[0063] S105. The control device determines whether the network device of the to-be-accessed control device is legal according to the above identifier.
[0064] Exemplarily, the control device may pre-store identifiers of multiple legal network devices. After receiving the above request message, the control device can parse the request message to obtain the identifier of the network device of the to-be-accessed control device. Then, the control device can compare the identifier with the identifiers of multiple legal network devices pre-stored in the control device to determine whether the identifier is the identifier of a legal network device. If so, the control device can determine that the network device of the to-be-accessed control device is legal. If not, the control device can determine that the network device of the to-be-accessed control device is illegal.
[0065] S106. When the control device determines that the network device of the to-be-accessed control device is legal, it sends second indication information to the first control starting device.
[0066] In a possible implementation, the second indication information can be used to indicate that the network device of the to-be-accessed control device is legal. For example, the second indication information may include an identifier for characterizing that "the network device of the to-be-accessed control device is legal", so that the first control starting device can determine that the network device of the to-be-accessed control device is legal according to the identifier.
[0067] Accordingly, the first control starting device can receive the above second indication information.
[0068] S107. The first control starting device communicates with the network device of the to-be-connected control device.
[0069] It should be understood that this application does not limit the manner of communication and the communication content between the first control starting device and the network device of the to-be-connected control device, etc.
[0070] In this embodiment, the first control starting device can receive the identifier of the network device of the to-be-connected control device through the target port according to the indication of the control device, avoiding potential safety hazards to the distribution network caused by the network device of the to-be-connected control device through other ports before determining the legality of the network device of the to-be-connected control device, and improving the network security of the distribution network. The first control starting device can send the identifier of the network device of the to-be-connected control device to the control device so that the control device can verify the legality of the network device of the to-be-connected control device. When the network device of the to-be-connected control device is legal, the first control starting device communicates with the network device of the to-be-connected control device to realize connecting the network device of the to-be-connected control device to the control device. Through the above method, while ensuring that the network device of the to-be-connected control device can be connected to the control device, it is ensured that the network device connected to the control device is a legal device, improving the security of the access devices in the control device, and further improving the network security of the network where the control device is located.
[0071] In some embodiments, after the control device determines that the network device of the to-be-connected control device is legal according to the identifier of the network device of the to-be-connected control device, for example, it can also use the network device of the to-be-connected control device as the second control starting device, that is, the next-level control starting device.
[0072] That is to say, after determining that the network device of the to-be-connected control device is legal, the network device can execute the method described in any of the foregoing embodiments executed by the first control starting device. When there is a new network device of the to-be-connected control device connected to the legal network device, the legal network device receives the identifier of the new network device of the to-be-connected control device through the target port indicated by the control device and executes the method described in the foregoing embodiments, which will not be elaborated here.
[0073] Through the above method, taking the distribution network as an example, it can make the legal network devices in the distribution network all serve as control starting devices, thereby improving the scalability of the distribution network and the efficiency of network devices accessing the distribution network.
[0074] In some embodiments, the first indication information can also be used to instruct the interconnection control port of the device to only allow traffic required for receiving the above-mentioned identifier. That is to say, before determining whether the network device to be connected to the distribution network is safe, the network device to be connected to the distribution network cannot send other information to the first control starting point device, and can only send the above-mentioned identifier, thereby ensuring the safety of the first control starting point device.
[0075] Exemplarily, the control device can, for example, use an access control list (ACL) to enable the device interconnection control port to only allow specific traffic required for network devices to complete security registration.
[0076] In some embodiments, the second indication information can be used to indicate the lifting of the restrictions on the interconnection control port of the device, so that the first control starting point device can respond to the second indication information to communicate with the network device of the control device to be connected. By lifting the restrictions, the network device of the control device to be connected can access the distribution network by communicating with the first control starting point device, laying the foundation for the network device of the control device to be connected to access the distribution network.
[0077] Take the above network device as a switch as an example. Figure 4 A flow chart of another communication method provided by this application. Figure 4 As shown, the master station may refer to the above-mentioned control device. A software defined network (SDN) controller may be deployed in the control device. The control device may implement secure network registration of the network device to be connected to the control device through the SDN controller.
[0078] like Figure 4 As shown, the first control starting point device can be switch 1 (SW1) in the substation. The device is "physically secure", for example, deployed in a substation with strict security measures or manned personnel, or in a switchgear with security access control. Switch 2 (SW2) in the outdoor ring network cabinet 1 can be a switch to be connected to the distribution network. Figure 4As shown in steps ① - ⑤, the SW1 device goes online and is managed by the SDN controller. Then, the SDN controller can designate SW1 as the first control starting device and specify port 1 of SW1 as the device interconnection control port. Then, SW2 is connected to the device interconnection control port of SW1, so that SW1 reports the information of SW2 to the SDN controller. Furthermore, when the SDN controller determines that SW2 is a legal device, the restriction on the device interconnection control port of SW1 is lifted. The device interconnection control port only allows the specific traffic required for the security registration of directly connected neighbor devices (such as SW2), and all other traffic is prohibited. The general LLDP protocol can be used to carry the characteristic information required for the registration of devices (such as SW2) (the MAC address or SN serial number can be taken). That is to say, after the first control starting device (such as SW1) receives the characteristic information of its neighbor (such as SW2), it reports it to the SDN controller for judging whether it is a legal device. If the neighbor (such as SW2) is a legal device, the SDN controller lifts the control of the "device interconnection control port".
[0079] When the next-level device is connected, it can also be processed by analogy according to the above logic, that is, starting from the "first control starting device", the device network access is completed step by step. As Figure 4 shown, after determining that SW2 is legal, the SW2 device goes online and is managed by the SDN controller. Then, the SDN controller can issue the device interconnection control port configuration to SW2, that is, SW2 becomes the control starting device at the next level of SW1, that is, the second control starting device. For the new switch 3 (SW3) to be connected to this distribution network, SW3 can be connected to the device interconnection control port of SW2. Then, SW2 can report the information of SW3 to the SDN controller so that the controller can lift the restriction on the device interconnection control port of SW2 when it determines that SW3 is a legal device.
[0080] In this embodiment, only pre-registered legal devices are allowed to access the network. Through this physical security access scheme, the security risks caused by privately connecting switches can be effectively reduced. In the distribution network, even in unattended ring main units or distribution rooms, etc., the possibility of the access switch being illegally replaced can be reduced, and the network security of the distribution network is improved.
[0081] In addition, it should be understood that the above communication method can not only be used in the distribution network to ensure the secure access of switching devices, but also be equally applicable in other scenarios where switches are illegally accessed to improve the network security.
[0082] Figure 5 It is a schematic structural diagram of a communication device provided by this application. The communication device 20 can be used for the control device described in any of the foregoing embodiments. As Figure 5As shown, the device 20 includes: a first sending module 21, a receiving module 22, and a second sending module 23.
[0083] The first sending module 21 is used to send first indication information to a first control starting point device, wherein the first indication information is used to instruct the first control starting point device to use the target port as a device interconnection control port, and the first control starting point device is one of the network devices.
[0084] The receiving module 22 is configured to receive a request message from the first control starting point device, wherein the request message includes: an identifier of a network device to be connected to the control device, received by the first control starting point device through the device interconnection control port.
[0085] The second sending module 23 is used to send second indication information to the first control starting point device when it is determined that the network device to be connected to the control device is legal based on the identification of the network device to be connected to the control device, so that the first control starting point device responds to the second indication information and communicates with the network device to be connected to the control device.
[0086] In a possible implementation, the communication device 20 may further include a determination module 24, which is used to use the network device to be connected to the control device as a second control starting point device when the network device is determined to be legitimate according to the identifier.
[0087] In a possible implementation, the first indication information is also used to instruct the device interconnection control port to open the traffic required for receiving the identification; the second indication information is used to instruct the lifting of the traffic release restriction on the device interconnection control port, so that the first control starting point device responds to the second indication information to communicate with the network device to be connected to the control device.
[0088] The communication device provided in the present application is used to execute the communication method embodiment executed by the aforementioned control device. Its implementation principle and technical effect are similar and will not be described in detail.
[0089] Figure 6 Schematic diagram of another communication device provided in this application. The communication device 30 can be used for the first control starting point device described in any of the above embodiments. Figure 6 As shown, the communication device 30 includes: a receiving module 31, a sending module 32, and a communication module 33. Among them,
[0090] A receiving module 31, configured to receive first indication information sent by a control device, use a target port as a device interconnection management port, and receive an identifier of a network device to be connected to the control device through the device interconnection management port. The first indication information is used to instruct the first management starting device to use the target port as the device interconnection management port.
[0091] A sending module 32, configured to send a request message including the identifier to the control device.
[0092] A communication module 33, configured to communicate with the network device when receiving second indication information fed back by the control device according to the request message. The second indication information is used to indicate that the network device is legal.
[0093] In a possible implementation, the first indication information is further used to indicate that the device interconnection management port allows traffic required for receiving the identifier to pass through; the second indication information is used to indicate lifting the traffic passing restriction on the device interconnection management port.
[0094] The communication device provided in this application is used to execute the communication method embodiments executed by the foregoing first management starting device, and its implementation principle and technical effects are similar, and will not be elaborated herein.
[0095] Figure 7 The figure is a schematic structural diagram of an electronic device provided in this application. Exemplarily, the electronic device may be the control device described in any of the foregoing embodiments, or the network device or the first management starting device described in any of the embodiments. As Figure 7 shown, the electronic device 500 may include at least one processor 501 and a memory 502.
[0096] The memory 502 is used to store a program. Specifically, the program may include program code, and the program code includes computer operation instructions.
[0097] The memory 502 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory.
[0098] The processor 501 is configured to execute the computer execution instructions stored in the memory 502 to implement the communication method described in the foregoing method embodiments. The processor 501 may be a central processing unit (CPU for short), or an application specific integrated circuit (ASIC for short), or one or more integrated circuits configured to implement the embodiments of this application.
[0099] In a possible implementation, the electronic device 500 may further include a communication interface 503. In a specific implementation, if the communication interface 503, the memory 502, and the processor 501 are implemented independently, the communication interface 503, the memory 502, and the processor 501 may be interconnected through a bus and communicate with each other. The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus may be divided into an address bus, a data bus, a control bus, etc., but it does not mean that there is only one bus or one type of bus.
[0100] In a possible implementation, in a specific implementation, if the communication interface 503, the memory 502, and the processor 501 are integrated on a single chip, the communication interface 503, the memory 502, and the processor 501 may communicate through an internal interface.
[0101] This application also provides a computer-readable storage medium, which may include: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc. Specifically, the computer-readable storage medium stores program instructions for the method in the foregoing embodiments.
[0102] This application also provides a program product, which includes execution instructions stored in a readable storage medium. At least one processor of the electronic device may read the execution instructions from the readable storage medium, and the execution of the execution instructions by at least one processor causes the electronic device to implement the communication methods provided by the various implementation manners described above.
[0103] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A communication method, applied to a control device, characterized in that, the method includes: sending first indication information to a first control starting device, where the first indication information is used to instruct the first control starting device to use a target port as a device interconnection control port; receiving a request message sent by the first control starting device; the request message includes: an identifier of a network device to be connected to the control device received by the first control starting device through the device interconnection control port; when determining that the network device is legal according to the identifier, sending second indication information to the first control starting device, where the second indication information is used to indicate that the network device is legal.
2. The method according to claim 1, characterized in that, when determining that the network device is legal according to the identifier, the method further includes: using the network device as a second control starting device.
3. The method according to claim 1, characterized in that, the first indication information is further used to instruct the device interconnection control port to allow traffic required for receiving the identifier; the second indication information is used to instruct to lift the traffic allowance restriction on the device interconnection control port, so that the first control starting device responds to the second indication information and communicates with the network device to be connected to the control device.
4. A communication method, applied to a first control starting device, characterized in that, the method includes: receiving first indication information sent by a control device and using a target port as a device interconnection control port; the first indication information is used to instruct the first control starting device to use the target port as the device interconnection control port; receiving an identifier of a network device to be connected to the control device through the device interconnection control port and sending a request message including the identifier to the control device; when receiving second indication information fed back by the control device according to the request message, communicating with the network device, where the second indication information is used to indicate that the network device is legal.
5. The method according to claim 4, characterized in that, the first indication information is further used to instruct the device interconnection control port to allow traffic required for receiving the identifier; the second indication information is used to instruct to lift the traffic allowance restriction on the device interconnection control port.
6. A communication device, applied to a control device, characterized in that, the device includes: a first sending module, configured to send first indication information to a first control starting device, where the first indication information is used to instruct the first control starting device to use a target port as a device interconnection control port; a receiving module, configured to receive a request message sent by the first control starting device; the request message includes: an identifier of a network device to be connected to the control device received by the first control starting device through the device interconnection control port; a second sending module, configured to send second indication information to the first control starting device when determining that the network device is legal according to the identifier, where the second indication information is used to indicate that the network device is legal.
7. A communication device is applied to a first control starting point device. Characterized in that, The device includes: A receiving module, configured to receive first indication information sent by a control device, and use a target port as a device interconnection control port; receive an identifier of a network device to be connected to the control device through the device interconnection control port; the first indication information is used to instruct the first control starting point device to use the target port as the device interconnection control port; A sending module, configured to send a request message including the identifier to the control device; A communication module, configured to communicate with the network device when receiving second indication information fed back by the control device according to the request message, wherein the second indication information is used to indicate that the network device is legal.
8. A distribution network, Characterized in that, The distribution network includes a control device and network devices in at least one distribution site; the control device is configured to execute the method according to any one of claims 1-3; the first control starting point device is one of the network devices, and the first control starting point device is configured to execute the method according to any one of claims 4-5.
9. A computer-readable storage medium, Characterized in that, Computer-executable instructions are stored on the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, the method according to any one of claims 1-3 or 4-5 is implemented.
10. A computer program product, Characterized in that, It includes a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1-3 or 4-5 is implemented.