Remote temporary connection building method, system, device and equipment and storage medium

By verifying terminal configuration information in the relay server and sending path mapping information, the direct connection between the terminal and the intranet server is realized, which solves the problem of high cost of remote connection operation and maintenance and construction, and improves the security and efficiency of the connection.

CN120200871AActive Publication Date: 2025-06-24HANGZHOU VISION TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510347674.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-24
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

The operation, maintenance and construction of remote connections require high costs, mainly because of the need to build a large number of relay servers to process and forward information.

Method used

By pre-storing the intranet configuration information in the relay server, verifying the configuration information sent by the terminal, and directly sending the path mapping information of the target intranet server to the terminal after verification, so that the terminal and the intranet server are directly connected to avoid information processing and forwarding of the relay server.

Benefits of technology

Reduces the operation and maintenance and construction costs of remote connections, improves the security and efficiency of connections, and reduces network latency and overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200871A_ABST
    Figure CN120200871A_ABST
Patent Text Reader

Abstract

The invention discloses a remote temporary connection building method, system, device and equipment and a storage medium, and relates to the technical field of digital information transmission, the remote temporary connection building method comprises the following steps: when terminal configuration information sent by a terminal is received, verifying the terminal configuration information based on internal network configuration information pre-stored locally, and sending the terminal configuration information to the terminal; and if the verification is passed, path mapping information corresponding to the target intranet server pre-stored locally is sent to the terminal, and the intranet configuration information is sent to the local by the intranet server, so that the relay server can verify the terminal configuration information based on the intranet configuration information. The corresponding path mapping information is sent to the terminal, so that the terminal and the intranet server carry out information interaction based on the path mapping information, the relay server only carries out verification and does not need to process and forward information, and therefore, the application can reduce the cost required by operation and maintenance and establishment of remote connection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of digital information transmission technology, and particularly to a method, system, device, equipment, and storage medium for establishing a remote temporary connection. Background Art

[0002] When performing remote data access, in order to ensure the integrity of data during transmission, a VPN is usually used to communicate between different networks. Before the VPN tunnel is established, the internal network server to be accessed remotely needs to expose its public IP on the public network for the terminal device accessing remotely to find the server. However, due to the need for network security protection and usage fees for the use of public IP, the usage conditions are harsh and the usage cost is high.

[0003] Currently, a relay server with a public IP is usually used for relaying. The terminal device directly accesses the relay server, and the relay server matches based on the authentication information of the terminal device and the server to be accessed remotely to establish two-way VPN communication. However, the current method requires the construction of a large number of relay servers to process and forward information through the relay server, resulting in relatively high costs for the operation and maintenance and construction of remote connections. Summary of the Invention

[0004] The main purpose of this application is to provide a method, system, device, equipment, and storage medium for establishing a remote temporary connection, aiming to solve the technical problem of relatively high costs for the operation and maintenance and construction of remote connections.

[0005] To achieve the above object, this application proposes a method for establishing a remote temporary connection, which is applied to a relay server. The method includes:

[0006] When receiving the terminal configuration information sent by the terminal, verify the terminal configuration information based on the internal network configuration information pre-stored locally, where the internal network configuration information is sent to the local by the internal network server, and the internal network configuration information includes internal network user information and internal network device information, and the terminal configuration information includes terminal user information and target device information of the target internal network server;

[0007] If the verification is passed, send the path mapping information corresponding to the target internal network server pre-stored locally to the terminal for the terminal to directly connect to the target internal network server, and based on the path mapping information, perform information interaction with the target internal network server without the need for local message processing and forwarding.

[0008] In one embodiment, the intranet configuration information further includes the association information of the intranet user information and the intranet device information. The step of verifying the terminal configuration information based on the intranet configuration information pre-stored locally when receiving the terminal configuration information sent by the terminal includes:

[0009] Based on the intranet user information of each intranet server pre-stored locally, determine whether there is target intranet user information that matches the terminal user information;

[0010] If there is, then based on the association information of each intranet server pre-stored locally, determine whether the target intranet server is associated with the target intranet user information;

[0011] If it is associated, the verification passes.

[0012] To achieve the above object, the present application also proposes a method for establishing a remote temporary connection, which is applied to a terminal. The method includes:

[0013] In response to a user's remote connection operation, obtain terminal configuration information, where the terminal configuration information includes terminal user information and target device information of a target intranet server;

[0014] Send the terminal configuration information to a relay server, so that after the relay server successfully verifies the terminal configuration information, based on the terminal configuration information, feedback the path mapping information corresponding to the target intranet server, where the relay server pre-stores the path mapping information corresponding to each intranet server;

[0015] After receiving the path mapping information, establish a connection with the target intranet server based on the path mapping information, so as to perform information interaction with the target intranet server based on the path mapping information without the need for the relay server to process and forward information.

[0016] In one embodiment, the steps before the step of obtaining terminal configuration information in response to a user's remote connection operation further include:

[0017] In response to a user's login operation, obtain the user information entered by the user during login as the terminal user information;

[0018] Send the terminal user information to a relay server, so that after the relay server successfully verifies the terminal user information, send the associated intranet device information corresponding to the terminal user information to the local, where the associated intranet device information is the device information of one or more intranet servers associated with the terminal user information, and the associated intranet device information is sent by the intranet server to the relay server;

[0019] After receiving the associated intranet device information, store the associated intranet device information locally to determine the intranet servers that can be connected during remote access.

[0020] To achieve the above object, the present application also proposes a method for building a remote temporary connection, which is applied to an intranet server. The method includes:

[0021] In response to the user's confirmation operation for local configuration completion, obtain the corresponding intranet information. Among them, the intranet information includes intranet user information and intranet device information. The intranet user information is the user information input by the user during configuration, and the intranet device information is the device number information pre-stored locally;

[0022] In response to the user's connection operation, connect to the relay server and obtain the path mapping information corresponding to the local;

[0023] Send the intranet information and the path mapping information to the relay server for the relay server to store the intranet information and the path mapping information, so that when the terminal connects to the local, the path mapping information is sent to the terminal.

[0024] In an embodiment, after the step of sending the intranet information and the path mapping information to the relay server, the method further includes:

[0025] When a preset time period has passed, re-obtain the path mapping information corresponding to the local;

[0026] If the intranet information and the path mapping information are changed, send the changed intranet information and the path mapping information to the relay server.

[0027] In addition, to achieve the above object, the present application also proposes a remote temporary connection building system. The remote temporary connection building system includes: a relay server, a terminal, and an intranet server. The relay server is connected to the terminal and the intranet server;

[0028] The relay server is configured to, when receiving the terminal configuration information sent by the terminal, verify the terminal configuration information based on the intranet configuration information pre-stored locally. Among them, the intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server. The relay server is further configured to, if the verification is passed, send the path mapping information corresponding to the target intranet server pre-stored locally to the terminal;

[0029] A terminal, which is used to obtain terminal configuration information in response to a user's remote connection operation, send the terminal configuration information to a relay server, and the terminal is also used to establish a connection with the target intranet server based on the path mapping information after receiving the path mapping information, so as to perform information interaction with the target intranet server based on the path mapping information without the need for the relay server to process and forward information;

[0030] An intranet server, which is used to obtain corresponding intranet information in response to a user's confirmation operation of local configuration completion. The intranet device information is device number information pre-stored locally. The intranet server is also used to establish a connection with the relay server in response to a user's connection operation, obtain path mapping information corresponding to the local, and send the intranet information and the path mapping information to the relay server.

[0031] In addition, to achieve the above object, the present application also proposes a remote temporary connection building device, and the remote temporary connection building device includes:

[0032] An information verification module, which is used to verify the terminal configuration information based on the intranet configuration information pre-stored locally when receiving the terminal configuration information sent by the terminal. The intranet configuration information is sent to the local by the intranet server, and the intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server;

[0033] A path sending module, which is used to, if the verification is passed, send the path mapping information corresponding to the target intranet server pre-stored locally to the terminal for the terminal and the target intranet server to directly connect and perform information interaction based on the path mapping information without the need for local message processing and forwarding.

[0034] In addition, to achieve the above object, the present application also proposes a remote temporary connection building device, and the device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the remote temporary connection building method as described above.

[0035] In addition, to achieve the above object, the present application also proposes a storage medium, the storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the remote temporary connection building method as described above are implemented.

[0036] One or more technical solutions proposed by the present application have at least the following technical effects:

[0037] When this application receives the terminal configuration information sent by the terminal, it verifies the terminal configuration information based on the intranet configuration information pre-stored locally. If the verification passes, it sends the path mapping information corresponding to the target intranet server pre-stored locally to the terminal.

[0038] The intranet configuration information is sent to the local by the intranet server. Therefore, the relay server has the intranet configuration information including the intranet user information and the intranet device information, so that it can verify the terminal configuration information including the terminal user information and the target device information. After the verification passes, the corresponding path mapping information is sent to the terminal, enabling the terminal and the intranet server to directly connect and perform information interaction based on the path mapping information. The relay server only performs verification and does not need to process and forward information. Therefore, this application can reduce the costs required for the operation and maintenance and setup of remote connections. Description of the Drawings

[0039] The drawings here are incorporated into the specification and form a part of this specification, showing the embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0040] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0041] Figure 1 It is a schematic flowchart provided for Embodiment 1 of the method for establishing a remote temporary connection in this application;

[0042] Figure 2 It is a schematic scenario diagram provided for Embodiment 1 of the method for establishing a remote temporary connection in this application;

[0043] Figure 3 It is a schematic flowchart provided for Embodiment 2 of the method for establishing a remote temporary connection in this application;

[0044] Figure 4 It is a schematic flowchart provided for Embodiment 3 of the method for establishing a remote temporary connection in this application;

[0045] Figure 5 It is a schematic module structure diagram of the device for establishing a remote temporary connection in the embodiment of this application;

[0046] Figure 6 It is a schematic device structure diagram of the hardware operating environment involved in the method for establishing a remote temporary connection in the embodiment of this application.

[0047] The realization of the purpose, functional features and advantages of this application will be further described in conjunction with embodiments with reference to the accompanying drawings. Specific embodiments

[0048] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0049] To better understand the technical solutions of this application, the following will be described in detail in conjunction with the accompanying drawings of the specification and specific embodiments.

[0050] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device, a remote temporary connection building device, etc. that can implement the above functions. The following takes the remote temporary connection building device as an example to illustrate this embodiment and the following embodiments.

[0051] When performing remote data access, in order to ensure the integrity of data during the transmission process, VPN is usually used to communicate between different networks. Before the establishment of the VPN tunnel, the internal network server to be accessed remotely needs to expose its public network IP on the public network for the terminal device accessing remotely to find the server. However, due to the need for network security protection and usage fees for the use of public network IP, the usage conditions are harsh and the usage cost is high.

[0052] Currently, a relay server with a public network IP is usually used for relaying. The terminal device directly accesses the relay server, and the relay server matches based on the authentication information of the terminal device and the server to be accessed remotely to establish a two-way VPN communication. However, the current method requires the construction of a large number of relay servers to process and forward information through the relay server, resulting in relatively high costs for the operation and maintenance and construction of remote connections.

[0053] Based on this, the embodiment of this application provides a method for building a remote temporary connection, referring to Figure 1 , Figure 1 is a schematic flowchart of the first embodiment of the method for building a remote temporary connection of this application.

[0054] In this embodiment, the remote temporary building method is applied to a terminal, and the method includes steps S10 to S20:

[0055] Step S10: When receiving the terminal configuration information sent by the terminal, verify the terminal configuration information based on the intranet configuration information pre-stored locally, where the intranet configuration information is sent to the local by the intranet server, and the intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server.

[0056] It should be noted that the intranet user information is the user account password information corresponding to the intranet server, and the intranet configuration information is the device code and parameter configuration information of the intranet server. The terminal user information is the user account password information corresponding to the terminal, and the target intranet server is the intranet server selected by the user to connect through the terminal.

[0057] It can be understood that after the remote connection is established, data transmission usually occurs. If the connection is made directly without verification, it may be accessed by illegal devices, resulting in security problems such as data leakage and network attacks. Therefore, in this application, the terminal configuration information is verified based on the intranet configuration information pre-stored locally.

[0058] By verifying the terminal configuration information, only accounts with access permissions can perform remote connections, thus ensuring the security of the remote connection. Moreover, through the verification of the terminal configuration information, connection errors existing during the connection can be discovered and corrected.

[0059] In a feasible implementation manner, the intranet configuration information further includes the association information between the intranet user information and the intranet device information. The specific implementation manner of verifying the terminal configuration information based on the intranet configuration information pre-stored locally when receiving the terminal configuration information sent by the terminal can also be:

[0060] Based on the intranet user information of each intranet server pre-stored locally, determine whether there is target intranet user information that matches the terminal user information. If so, based on the association information of each intranet server pre-stored locally, determine whether the target intranet server is associated with the target intranet user information. If it is associated, the verification passes.

[0061] It should be noted that the target intranet user information is the intranet user information that is the same as the terminal user information among the intranet user information stored in the relay server.

[0062] It can be understood that the relay server pre-stores the intranet user information that can access the intranet sent by each intranet server. In this embodiment, only accounts with access rights can connect remotely, and accounts with access rights have been pre-stored in the relay server. Therefore, this embodiment verifies whether the terminal user information has matching target intranet user information to ensure the security of the remote connection.

[0063] Furthermore, since one account can have multiple intranet server devices associated with it, there may be a situation where an intranet user has access rights but does not have corresponding intranet server connection rights. Therefore, after verifying the intranet user information, this embodiment also confirms whether the target intranet server is associated with the target intranet user information based on the association information pre-stored in the relay server, thereby preventing the user from remotely accessing the intranet server through an unassociated intranet server.

[0064] In the process of transmitting data such as intranet configuration information and terminal configuration information, multiple data transmissions will increase network delay and increase overhead. Therefore, this embodiment reduces network communication overhead and delay by packaging data and sending it at one time, and performing unpacking verification in the relay server.

[0065] Step S20, if the verification is successful, the path mapping information corresponding to the target intranet server pre-stored locally is sent to the terminal so that the terminal and the target intranet server can be directly connected, and information interaction is performed with the target intranet server based on the path mapping information without the need for local message processing and forwarding.

[0066] It should be noted that the path mapping information includes the NAT device IP and port mapping information, and the port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the intranet server.

[0067] It is understandable that if the verification is successful, it means that the terminal user has access rights to the corresponding target intranet server. Since the intranet server usually hides its real IP address and usually uses dynamic port allocation, the external terminal cannot directly know the private IP and port number of the intranet server, that is, the terminal device cannot access the exact location of the intranet server. The NAT device can allow multiple devices to share a public IP address, converting the request of the intranet server into an externally visible public IP address. Through the public IP of the NAT device and the corresponding port mapping information, data packets can be forwarded, thereby realizing information interaction between the intranet server and the terminal. The verification and interaction process of this embodiment can refer to Figure 2 .

[0068] When the verification is passed, the relay server sends the path mapping information corresponding to the target intranet server to the terminal. The terminal and the intranet server can directly establish a connection, and forward the information to the correct IP and port through the corresponding NAT device IP and port mapping information to achieve information interaction. During the above connection establishment and information interaction process, the relay server only needs to verify both the terminal and the intranet server, and does not need to process and forward the information. Therefore, a large number of relay servers are not required for information interaction between the terminal and the intranet server, reducing the costs required for the operation and maintenance and construction of remote connections.

[0069] In summary, when receiving the terminal configuration information sent by the terminal, in this embodiment, based on the intranet configuration information pre-stored locally, the terminal configuration information is verified. If the verification is passed, the path mapping information corresponding to the target intranet server pre-stored locally is sent to the terminal.

[0070] The intranet configuration information is sent to the local by the intranet server. Therefore, the relay server has the intranet configuration information including intranet user information and intranet device information, so that the terminal configuration information including terminal user information and target device information can be verified. After the verification is passed, the corresponding path mapping information is sent to the terminal, enabling the terminal and the intranet server to directly establish a connection and perform information interaction based on the path mapping information. The relay server only performs verification and does not need to process and forward information. Therefore, this application can reduce the costs required for the operation and maintenance and construction of remote connections.

[0071] The embodiment of the present application also provides a method for building a remote temporary connection. Refer to Figure 3 , Figure 3 which is a schematic flowchart of the second embodiment of the method for building a remote temporary connection in the present application.

[0072] In this embodiment, the method for building a remote temporary connection is applied to an intranet server, and the method includes steps A10 to A30:

[0073] Step A10, in response to a user's remote connection operation, obtain terminal configuration information, where the terminal configuration information includes terminal user information and target device information of a target intranet server;

[0074] It should be noted that the user's remote connection operation is an operation for the user to connect to the intranet server through the terminal, and the terminal user information is account password information stored in the terminal.

[0075] It can be understood that, when the user conducts remote access in this embodiment, obtaining the terminal user information first is to enable the system to confirm the identity of the user and verify whether they have the permission to connect, thereby improving the security of remote access. And when conducting remote access through the intranet server, different users may have different requirements. For example, some users may only need a small amount of traffic for access, and some users may require higher security when conducting remote access. Therefore, in this embodiment, the terminal user information is obtained first when the user conducts remote access, so that different configuration services can be provided according to different user requirements, and the scalability of remote access can be further improved while ensuring the security of remote access.

[0076] For the same user, there may be multiple different intranet server devices under the terminal user account, and the user selects which intranet server device to connect through according to specific needs. Therefore, in this embodiment, in addition to obtaining the terminal user information, it is also necessary to obtain the target intranet server that the user wants to connect to, so as to ensure the accuracy of establishing the remote connection. And by obtaining the target intranet server, the network resources can be accurately managed and subsequent optimization can be provided for the user.

[0077] Step A20: Send the terminal configuration information to the relay server, so that after the relay server successfully verifies the terminal configuration information, based on the terminal configuration information, feedback the path mapping information corresponding to the target intranet server, where the relay server pre-stores the path mapping information corresponding to each intranet server;

[0078] It should be noted that the path mapping information in this embodiment includes the NAT device IP and port mapping information.

[0079] It can be understood that the terminal device cannot access the exact location of the intranet server and cannot directly interact with the intranet server through the IP and port corresponding to the intranet server. Therefore, it is necessary to forward the data packet through the public IP of the NAT device and the corresponding port mapping information, so as to realize the information interaction between the intranet server and the terminal.

[0080] Each terminal user account may be associated with multiple intranet servers, and the port mapping information of different intranet servers is also different. In order to interact with the correct intranet server, it is necessary to first send the terminal user information and the target device information to the relay server, and then obtain the NAT device IP and port mapping information corresponding to the target intranet server based on the relay server, so as to ensure the accuracy of information interaction after the remote connection is established.

[0081] Step A30: After receiving the path mapping information, establish a connection with the target intranet server based on the path mapping information, so as to perform information interaction with the target intranet server based on the path mapping information without the need for the relay server to process and forward information. It can be understood that when the NAT device IP and the port mapping information are received, it means that the end user can have the permission for remote connection, and the corresponding intranet server is associated with the end user, and information interaction can be performed between the terminal and the intranet server through the NAT device.

[0082] During the information interaction process, when a data packet is sent from the intranet server to the Internet, the NAT device will replace the IP address and port number of the intranet server with the NAT device's IP and the corresponding port number, and then forward it to the terminal. When a data packet wants to be sent from the terminal to the intranet server, the information of the terminal will be sent to the NAT device's IP and the corresponding port number, and the NAT device will send the information to the corresponding intranet server IP and port number based on the port mapping information. Therefore, in this embodiment, the relay server does not need to process and forward information, realizing information interaction between the terminal and the intranet server, and reducing the cost required for remote connection operation and maintenance and setup.

[0083] In a feasible implementation manner, the steps before obtaining the terminal configuration information in response to the user's remote connection operation further include:

[0084] In response to the user's login operation, obtain the user information entered by the user during login as the end user information, and send the end user information to the relay server. After the relay server successfully verifies the end user information, send the associated intranet device information corresponding to the end user information to the local side, where the associated intranet device information is the device information of one or more intranet servers associated with the end user information, and the associated intranet device information is sent from the intranet server to the relay server. After receiving the associated intranet device information, store the associated intranet device information locally to determine the connectable intranet server during remote access.

[0085] It should be noted that in this embodiment, the user's input information operation is the input operation when the user uses a new account for remote connection, or the input operation when the user deletes the end user information recorded by the terminal and re-enters the end user information. The device information of one or more intranet servers corresponding to the end user information is stored in the relay server before the terminal performs the access operation.

[0086] It can be understood that when the terminal does not record relevant user information, the user needs to manually input the terminal user information so that the terminal can save the user information for connection based on the saved terminal user information in subsequent connections.

[0087] Before the user uses a new account for remote access, there is no terminal user information and associated intranet server device information in the terminal device, and the connectable intranet server devices cannot be displayed. Therefore, it is necessary to first send the terminal user information to the relay server for verification to receive the associated intranet server device information sent by the relay server and store the received intranet server device information locally. When performing remote access later, the user can directly select the intranet server device to be connected in the terminal, thereby improving the convenience of remote access.

[0088] In summary, in this embodiment, in response to the user's remote connection operation, the terminal configuration information is obtained and sent to the relay server. After the relay server successfully verifies the terminal configuration information, based on the terminal configuration information, the path mapping information corresponding to the target intranet server is fed back. After receiving the path mapping information, a connection is established with the target intranet server based on the path mapping information to perform information interaction with the target intranet server based on the path mapping information without the need for the relay server to process and forward information.

[0089] This embodiment establishes a connection with the corresponding target intranet server based on the NAT device IP and port mapping information, so that the intranet server does not need to expose its own IP on the public network during the connection establishment process. After the connection is established, the NAT device can perform information forwarding for the corresponding IP and corresponding port based on the NAT device IP and the port mapping information to realize information interaction between the intranet server and the terminal, so that a large number of relay servers are not required to process and forward information. Therefore, this application can reduce the costs required for remote connection operation and maintenance and setup. And this example improves the convenience of remote access by verifying the new account and storing the device information of the associated intranet server for direct connection during subsequent connection processes.

[0090] The embodiment of the present application also provides a method for establishing a remote temporary connection. Refer to Figure 4 , Figure 4 which is a schematic flowchart of the third embodiment of the method for establishing a remote temporary connection of the present application.

[0091] In this embodiment, the method for establishing a remote temporary connection is applied to an intranet server, and the method includes steps H10 to H30:

[0092] Step H10: In response to the user's confirmation operation for local configuration completion, obtain the corresponding intranet information, where the intranet information includes intranet user information and intranet device information. The intranet user information is the user information input by the user during configuration, and the intranet device information is the device number information pre-stored locally.

[0093] It should be noted that the user's configuration operation is performed in the intranet server before remote access. The configuration operation includes inputting account passwords and setting intranet server parameters. The setting of intranet server parameters can be settings related to connection such as transmission traffic setting, accessible time setting, and accessible IP setting, etc. The device number information is pre-burned into the hardware of the intranet server.

[0094] It can be understood that in order to ensure the security of remote connections, it is necessary to verify users who remotely connect through the intranet server. And before verification, it is necessary to determine the users who can pass the verification. Therefore, in this embodiment, in response to the user's confirmation operation for local configuration completion, the input account password information of the user is obtained as the intranet user information, and this intranet user information is the user information that can connect through the intranet server.

[0095] Moreover, different users have different requirements when performing remote connection access. Therefore, this embodiment also obtains the intranet server parameter information set by the user, so as to improve the flexibility and scalability of remote connections while ensuring the security of remote connections.

[0096] Step H20: In response to the user's connection operation, connect to the relay server and obtain the path mapping information corresponding to the local area.

[0097] It can be understood that intranet servers usually hide their IPs and use dynamic ports, that is, it is difficult for external devices to obtain the IP and port information of the intranet server, and thus it is difficult to remotely connect to the intranet server. Therefore, in this embodiment, by connecting to the relay server, path mapping information including NAT device IP and port mapping information is obtained, and the relay server is used as a central node to manage and monitor all relevant NAT devices and their mapping relationships. Through the management of the relay server, the configuration can be adjusted quickly, and remote connections between different locations can be made easier and more efficient.

[0098] Step H30: Send the intranet information and the path mapping information to the relay server for the relay server to store the intranet information and the path mapping information, so that when the terminal connects to the local area, the path mapping information is sent to the terminal.

[0099] It should be noted that the intranet information and the path mapping information will be packaged into data packets locally and sent to the relay server. The relay server will unpack the data packets and send the successfully unpacked information to the local side, so that the local side can confirm that the relay server has received the corresponding data.

[0100] It can be understood that the relay server uniformly monitors and manages the NAT devices and their mapping relationships, and needs to determine the NAT device IPs, port mapping information, and intranet user information corresponding to different intranet servers. Therefore, in this embodiment, the intranet information including the intranet user information and the intranet device information, and the path mapping information including the NAT device IP and the port mapping information are sent to the relay server for binding and storage. Thus, when the terminal needs to make a connection, the corresponding path mapping information can be directly obtained, preventing remote connection errors caused by incorrect path mapping information and improving the efficiency and accuracy of remote connections.

[0101] In a feasible implementation manner, the specific implementation manner of sending the intranet information and the path mapping information to the relay server may also be:

[0102] When a preset time period has passed, re-obtain the path mapping information corresponding to the local side. If the intranet information and the path mapping information have changed, send the changed intranet information and the path mapping information to the relay server.

[0103] It should be noted that if the intranet user information, the NAT device IP, the port mapping information, and the intranet device information obtained locally this time are the same as the information obtained last time, there is no change. If one or more of the information is different from the information obtained last time, there is a change.

[0104] It can be understood that the NAT device IP and port mapping information originally obtained by the NAT device may change over time. If these information are not updated in time, it may cause external terminals to be unable to access the internal network server correctly. Therefore, in this embodiment, by setting a preset time period to regularly check and update the relevant information, it can be ensured that even when the network configuration changes, the system can maintain an effective connection state, avoiding remote connection failures caused by expired information and improving the stability of remote connections.

[0105] In summary, in this embodiment, in response to the user's confirmation operation on the local configuration, the corresponding intranet information is obtained. In response to the user's connection operation, a connection is made with the relay server, and the path mapping information corresponding to the local is obtained. The intranet information and the path mapping information are sent to the relay server for the relay server to store the intranet information and the path mapping information, so that when the terminal connects to the local, the path mapping information is sent to the terminal.

[0106] In this embodiment, by obtaining the intranet user information for subsequent user information verification, it is ensured that only authenticated users can perform remote access, improving the security of remote access. At the same time, by connecting to the relay server and obtaining the corresponding NAT device IP and port mapping information, the terminal can find the corresponding intranet server in the network without exposing the intranet server IP to the public network, thus eliminating the need for a public IP network security service and reducing the usage cost. This embodiment also continuously obtains the NAT device IP and port mapping information to maintain the connection in case of network configuration changes, thereby improving the stability of the remote connection.

[0107] It should be noted that the above examples are only for understanding the present application and do not constitute a limitation on the remote temporary connection establishment method of the present application. Based on this technical concept, more forms of simple transformations are within the protection scope of the present application.

[0108] The present application also provides a remote temporary connection establishment device. Please refer to Figure 5 , and the remote temporary connection establishment device includes:

[0109] An information verification module 10, configured to verify the terminal configuration information based on the intranet configuration information pre-stored locally when receiving the terminal configuration information sent by the terminal. The intranet configuration information is sent to the local by the intranet server, and the intranet configuration information includes intranet user information and intranet device information. The terminal configuration information includes terminal user information and target device information of the target intranet server;

[0110] A path sending module 20, configured to, if the verification is passed, send the path mapping information corresponding to the target intranet server pre-stored locally to the terminal for the terminal to directly connect to the target intranet server, and perform information interaction with the target intranet server based on the path mapping information without the need for local message processing and forwarding.

[0111] In one embodiment, the information verification module further includes:

[0112] A user verification sub-module, configured to determine whether there is target intranet user information that matches the terminal user information based on the intranet user information of each intranet server pre-stored locally;

[0113] A server verification sub-module, configured to, if it exists, determine whether the target intranet server is associated with the target intranet user information based on the association information of each intranet server pre-stored locally;

[0114] A verification confirmation sub-module, configured to, if it is associated, pass the verification.

[0115] In one embodiment, the remote temporary connection establishment device further includes:

[0116] A configuration information acquisition module, configured to acquire terminal configuration information in response to a user's remote connection operation, where the terminal configuration information includes terminal user information and target device information of a target intranet server;

[0117] A configuration information sending module, configured to send the terminal configuration information to a relay server, so that after the relay server successfully verifies the terminal configuration information, based on the terminal configuration information, feedback path mapping information corresponding to the target intranet server, where the relay server pre-stores path mapping information corresponding to each intranet server;

[0118] A remote connection module, configured to, after receiving the path mapping information, establish a connection with the target intranet server based on the path mapping information, so as to perform information interaction with the target intranet server based on the path mapping information without the need for the relay server to perform information processing and forwarding.

[0119] In one embodiment, the remote connection module further includes:

[0120] A user information acquisition module, configured to acquire the user information input by the user during login as terminal user information in response to a user's login operation;

[0121] An information sending module for, configured to send the terminal user information to a relay server, so that after the relay server successfully verifies the terminal user information, send the associated intranet device information corresponding to the terminal user information to the local, where the associated intranet device information is device information of one or more intranet servers associated with the terminal user information, and the associated intranet device information is sent by the intranet server to the relay server;

[0122] An associated information storage module, configured to store the associated intranet device information locally after receiving the associated intranet device information, so as to determine an intranet server that can be connected during remote access.

[0123] In one embodiment, the remote temporary connection establishment device further includes:

[0124] An intranet information acquisition module, configured to acquire corresponding intranet information in response to a user's confirmation operation on local configuration, where the intranet information includes intranet user information and intranet device information, the intranet user information is user information input by the user during configuration, and the intranet device information is device number information pre-stored locally;

[0125] A path information acquisition module, configured to connect to a relay server in response to a user's connection operation, and acquire path mapping information corresponding to the local;

[0126] An intranet server information sending module, configured to send the intranet information and the path mapping information to the relay server, so that the relay server stores the intranet information and the path mapping information, and sends the path mapping information to the terminal when the terminal connects to the local.

[0127] In one embodiment, the remote temporary connection establishment device further includes:

[0128] An information re-acquisition module, configured to re-acquire path mapping information corresponding to the local when a preset time period elapses;

[0129] An information re-sending module, configured to send the changed intranet information and path mapping information to the relay server if the intranet information and the path mapping information are changed.

[0130] The remote temporary connection establishment device provided by the present application adopts the remote temporary connection establishment method in the above embodiment, and can solve the technical problem that the operation and maintenance and establishment of remote connections require high costs. Compared with the prior art, the beneficial effects of the remote temporary connection establishment device provided by the present application are the same as those of the remote temporary connection establishment method provided by the above embodiment, and other technical features in the remote temporary connection establishment device are the same as the features disclosed in the above embodiment method, and will not be elaborated here.

[0131] The present application provides a remote temporary connection establishment device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the remote temporary connection establishment method in the first embodiment above.

[0132] Refer to the following Figure 6 , which shows a schematic structural diagram of a remote temporary connection building device suitable for implementing the embodiments of the present application. The remote temporary connection building device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, tablet computers, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The remote temporary connection building device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0133] As Figure 6 shown, the remote temporary connection building device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the remote temporary connection building device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the remote temporary connection building device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a remote temporary connection building device having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be alternatively implemented or had.

[0134] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.

[0135] The remote temporary connection building device provided by the present application adopts the remote temporary connection building method in the above embodiments, and can solve the technical problem that the operation and maintenance and building of remote connections require relatively high costs. Compared with the prior art, the beneficial effects of the remote temporary connection building device provided by the present application are the same as those of the remote temporary connection building method provided by the above embodiments, and other technical features in the remote temporary connection building device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.

[0136] It should be understood that the various parts disclosed in the present application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0137] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0138] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the remote temporary connection building method in the above embodiments.

[0139] The computer-readable storage medium provided by the present application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0140] The above computer-readable storage medium can be included in the remotely temporarily connected construction device; it can also exist independently without being assembled into the remotely temporarily connected construction device.

[0141] The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the remotely temporarily connected construction device, the remotely temporarily connected construction device is caused to: execute the above remotely temporarily connected construction method.

[0142] Computer program code for performing the operations of the present application can be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages - such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0143] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0144] The modules described in the embodiments of the present application can be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the unit itself.

[0145] The readable storage medium provided by the present application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned remote temporary connection establishment method, which can solve the technical problem that the operation and maintenance and establishment of remote connections require relatively high costs. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as those of the remote temporary connection establishment method provided by the above embodiments, and will not be elaborated here.

[0146] The above are only some embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made by using the content of the specification and the accompanying drawings of the present application under the technical concept of the present application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.

Claims

1. A method for establishing a remote temporary connection, characterized in that: Applied to a relay server, the method includes: When receiving terminal configuration information sent by the terminal, verifying the terminal configuration information based on the intranet configuration information pre-stored locally, wherein the intranet configuration information is sent to the local by the intranet server, the intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server; If the verification is successful, the path mapping information corresponding to the target intranet server pre-stored locally will be sent to the terminal for direct connection between the terminal and the target intranet server, and information interaction will be performed with the target intranet server based on the path mapping information without the need for local message processing and forwarding.

2. The method according to claim 1, characterized in that The intranet configuration information also includes association information between the intranet user information and the intranet device information. When receiving the terminal configuration information sent by the terminal, the step of verifying the terminal configuration information based on the intranet configuration information pre-stored locally includes: Based on the intranet user information pre-stored locally on each intranet server, determining whether there is target intranet user information matching the terminal user information; If so, judging whether the target intranet server is associated with the target intranet user information based on the association information of each intranet server pre-stored locally; If they are related, the verification is successful.

3. A remote temporary connection establishment method, characterized in that: Applied to a terminal, the method includes: In response to a remote connection operation by a user, terminal configuration information is acquired, wherein the terminal configuration information includes terminal user information and target device information of a target intranet server; Sending the terminal configuration information to the relay server, so that the relay server can feedback the path mapping information corresponding to the target intranet server based on the terminal configuration information after successfully verifying the terminal configuration information, wherein the relay server pre-stores the path mapping information corresponding to each intranet server; After receiving the path mapping information, a connection is established with the target intranet server based on the path mapping information, so as to exchange information with the target intranet server based on the path mapping information without requiring the relay server to process and forward information.

4. The method according to claim 3, characterized in that The step before obtaining the terminal configuration information in response to the user's remote connection operation also includes: In response to a login operation of the user, obtaining user information input by the user when logging in as terminal user information; Sending the terminal user information to the relay server, so that the relay server can send the associated intranet device information corresponding to the terminal user information to the local after successfully verifying the terminal user information, wherein the associated intranet device information is the device information of one or more intranet servers associated with the terminal user information, and the associated intranet device information is sent from the intranet server to the relay server; After receiving the associated intranet device information, the associated intranet device information is stored locally to determine an intranet server that can be connected during remote access.

5. A method for establishing a remote temporary connection, characterized in that: Applied to an intranet server, the method includes: In response to the user confirming the completion of the local configuration, the corresponding intranet information is obtained, wherein the intranet information includes intranet user information and intranet device information, the intranet user information is user information input by the user during configuration, and the intranet device information is device number information pre-stored locally; In response to the user's connection operation, connect to the relay server to obtain the path mapping information corresponding to the local; The intranet information and the path mapping information are sent to the relay server, so that the relay server stores the intranet information and the path mapping information, and sends the path mapping information to the terminal when the terminal is connected to the local.

6. The method according to claim 5, characterized in that After the step of sending the intranet information and the path mapping information to the relay server, the method further includes: When a preset time period has passed, the local corresponding path mapping information is re-acquired; If the intranet information and the path mapping information are changed, the changed intranet information and the path mapping information are sent to the relay server.

7. A remote temporary connection establishment system, characterized in that: The system comprises: a relay server, a terminal and an intranet server, wherein the relay server is connected to the terminal and the intranet server; The relay server is used to verify the terminal configuration information sent by the terminal based on the intranet configuration information pre-stored locally when receiving the terminal configuration information sent by the terminal, wherein the intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server. The relay server is also used to send the path mapping information corresponding to the target intranet server pre-stored locally to the terminal if the verification is passed; The terminal is used to obtain terminal configuration information in response to a remote connection operation of a user, and send the terminal configuration information to a relay server. The terminal is also used to establish a connection with the target intranet server based on the path mapping information after receiving the path mapping information, so as to exchange information with the target intranet server based on the path mapping information without requiring the relay server to process and forward the information; The intranet server is used to respond to the user's confirmation operation on the local configuration completion and obtain the corresponding intranet information, wherein the intranet device information is the device number information pre-stored locally. The intranet server is also used to respond to the user's connection operation, connect to the relay server, obtain the path mapping information corresponding to the local, and send the intranet information and the path mapping information to the relay server.

8. A remote temporary connection establishment device, characterized in that: The device comprises: An information verification module, configured to verify the terminal configuration information when receiving the terminal configuration information sent by the terminal, based on the intranet configuration information pre-stored locally, wherein the intranet configuration information is sent to the local by the intranet server, the intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server; The path sending module is used to send the path mapping information corresponding to the target intranet server pre-stored locally to the terminal if the verification is passed, so that the terminal and the target intranet server can be directly connected, and information interaction can be carried out with the target intranet server based on the path mapping information without the need for local message processing and forwarding.

9. A remote temporary connection establishment device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the remote temporary connection establishment method according to any one of claims 1 to 6.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the remote temporary connection establishment method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Method and device for establishing end-to-end network connection and network system

    CN110266828A

  • Communication method and system for cloud desktop

    CN114915420A

  • Data transmission link establishment method and device, equipment and medium

    CN117221269A

  • Camera module

    KR102618276B1