Remote temporary connection building method, system, device and equipment and storage medium
By storing intranet configuration information and verifying terminal configuration information in the relay server, and directly sending path mapping information, the terminal and the intranet server can interact, solving the problem of high cost of remote connection operation and maintenance and setting up, and realizing a secure, convenient and low-cost connection.
Patent Information
- Application Number
- CN202510347674.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-03-24
AI Technical Summary
The maintenance and setup of remote connections are costly, mainly due to the large number of relay servers and the high demand for information processing.
By storing intranet configuration information in the relay server, verifying terminal configuration information, and directly sending path mapping information after successful verification, the terminal and the intranet server can interact with each other, avoiding information processing and forwarding by the relay server.
It reduces the operation and maintenance costs of remote connections, improves connection security and convenience, and reduces network latency and overhead.
Smart Images

Figure CN120200871B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of digital information transmission, and particularly relates to a remote temporary connection building method, system, device and storage medium. BACKGROUND
[0002] When remote data access is performed, in order to ensure the integrity of data in the transmission process, a vpn is usually used to communicate between different networks. Before the vpn tunnel is established, the intranet server accessed remotely needs to expose its public network ip to the public network for the terminal device accessed remotely to find the server. However, due to the network security protection and use cost of the public network ip, the use condition is harsh and the use cost is high.
[0003] Currently, a relay server with a public network ip is usually used for transfer. The terminal device directly accesses the relay server. The relay server matches based on the verification information of the terminal device and the server accessed remotely to establish bidirectional vpn communication. However, the current method needs to build a large number of relay servers to process and forward information through the relay servers, which results in high cost of remote connection operation and building. SUMMARY
[0004] The main purpose of the present application is to provide a remote temporary connection building method, system, device and storage medium, which aims to solve the technical problem of high cost of remote connection operation and building.
[0005] To achieve the above purpose, the present application provides a remote temporary connection building method applied to a relay server, which comprises the following steps:
[0006] When receiving the terminal configuration information sent by the terminal, the terminal configuration information is verified based on the intranet configuration information stored in the local in advance, wherein the intranet configuration information is sent to the local by the intranet server, the intranet configuration information comprises intranet user information and intranet device information, and the terminal configuration information comprises terminal user information and target device information of the target intranet server;
[0007] If the verification is passed, the path mapping information corresponding to the target intranet server stored in the local in advance is sent to the terminal, so that the terminal and the target intranet server are directly connected. Without the need for local message processing and forwarding, the target intranet server is interacted based on the path mapping information.
[0008] In an embodiment, the intranet configuration information further comprises association information of the intranet user information and the intranet device information, and when the terminal configuration information sent by the terminal is received, the step of verifying the terminal configuration information based on the intranet configuration information stored locally in advance comprises:
[0009] judging whether there is target intranet user information matching the terminal user information based on the intranet user information of each intranet server stored locally in advance;
[0010] if there is, judging whether the target intranet server is associated with the target intranet user information based on the association information of each intranet server stored locally in advance;
[0011] if associated, the verification is passed.
[0012] To achieve the above-mentioned purpose, the application further provides a remote temporary connection building method applied to a terminal, which comprises:
[0013] obtaining terminal configuration information in response to a remote connection operation of a user, wherein the terminal configuration information comprises terminal user information and target device information of a target intranet server;
[0014] sending the terminal configuration information to a relay server, so that the relay server feeds back path mapping information corresponding to the target intranet server based on the terminal configuration information after successfully verifying the terminal configuration information, wherein the relay server has stored path mapping information corresponding to each intranet server in advance;
[0015] after receiving the path mapping information, establishing a connection with the target intranet server based on the path mapping information, so as to interact with the target intranet server based on the path mapping information without information processing and forwarding of the relay server.
[0016] In an embodiment, the step of obtaining terminal configuration information in response to a remote connection operation of a user further comprises:
[0017] obtaining user information input by a user when logging in as terminal user information in response to a login operation of the user;
[0018] sending the terminal user information to a relay server, so that the relay server sends associated intranet device information corresponding to the terminal user information to the local terminal after successfully verifying the terminal user information, wherein the associated intranet device information is device information of one or more intranet servers associated with the terminal user information, and the associated intranet device information is sent to the relay server by an intranet server;
[0019] After receiving the associated intranet device information, the associated intranet device information is stored locally to determine the connectable intranet server when remotely accessed.
[0020] To achieve the above object, the application further provides a remote temporary connection building method applied to an intranet server, which comprises:
[0021] In response to a user's configuration completion confirmation operation, corresponding intranet information is acquired, wherein the intranet information comprises intranet user information and intranet device information, the intranet user information is user information input by the user during configuration, and the intranet device information is device number information pre-stored in the local;
[0022] In response to a user's connection operation, a connection is established with a relay server, and path mapping information corresponding to the local is acquired;
[0023] The intranet information and the path mapping information are sent to the relay server, so that the relay server stores the intranet information and the path mapping information, and sends the path mapping information to the terminal when the terminal is connected to the local.
[0024] In an embodiment, after the step of sending the intranet information and the path mapping information to the relay server, the method further comprises:
[0025] When a preset time period elapses, the path mapping information corresponding to the local is re-acquired;
[0026] If the intranet information and the path mapping information are changed, the changed intranet information and the path mapping information are sent to the relay server.
[0027] In addition, to achieve the above object, the application further provides a remote temporary connection building system, which comprises a relay server, a terminal and an intranet server, wherein the relay server is connected to the terminal and the intranet server;
[0028] The relay server is configured to, when receiving terminal configuration information sent by the terminal, verify the terminal configuration information based on pre-stored intranet configuration information, wherein the intranet configuration information comprises intranet user information and intranet device information, the terminal configuration information comprises terminal user information and target device information of a target intranet server, and the relay server is further configured to, if the verification is passed, send path mapping information corresponding to the target intranet server pre-stored in the local to the terminal;
[0029] The terminal is configured to, in response to a remote connection operation of a user, acquire terminal configuration information, and send the terminal configuration information to a relay server. The terminal is further configured to, after receiving path mapping information, establish a connection with the target intranet server based on the path mapping information, so as to interact with the target intranet server based on the path mapping information without the need for the relay server to process and forward information.
[0030] The intranet server is configured to, in response to a configuration completion confirmation operation of a user locally, acquire corresponding intranet information, wherein the intranet device information is device number information pre-stored locally. The intranet server is further configured to, in response to a connection operation of a user, connect with a relay server, acquire path mapping information corresponding to the local, and send the intranet information and the path mapping information to the relay server.
[0031] In addition, to achieve the above-mentioned purpose, the application further provides a remote temporary connection building device, which comprises:
[0032] The information verification module is configured to, when receiving the terminal configuration information sent by the terminal, verify the terminal configuration information based on the intranet configuration information pre-stored locally, wherein the intranet configuration information is sent to the local by the intranet server, and the intranet configuration information comprises intranet user information and intranet device information, and the terminal configuration information comprises terminal user information and target device information of the target intranet server.
[0033] The path sending module is configured to, if the verification is passed, send the path mapping information corresponding to the target intranet server pre-stored locally to the terminal, so that the terminal and the target intranet server are directly connected, and interact with the target intranet server based on the path mapping information without the need for the local to process and forward messages.
[0034] In addition, to achieve the above-mentioned purpose, the application further provides a remote temporary connection building device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is configured to implement the steps of the remote temporary connection building method as described above.
[0035] In addition, to achieve the above-mentioned purpose, the application further provides a storage medium, which is a computer readable storage medium, and the storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the remote temporary connection building method as described above.
[0036] The one or more technical solutions provided by the application have at least the following technical effects:
[0037] When the terminal configuration information sent by the terminal is received, the terminal configuration information is verified based on the intranet configuration information pre-stored locally, and if the verification is passed, the path mapping information corresponding to the target intranet server pre-stored locally is sent to the terminal.
[0038] The intranet configuration information is sent to the local by the intranet server, therefore, the relay server has the intranet configuration information including intranet user information and intranet device information, so as to verify the terminal configuration information including terminal user information and target device information. After the verification is passed, the corresponding path mapping information is sent to the terminal, so that the terminal and the intranet server are directly connected and information interaction is carried out based on the path mapping information. The relay server only performs verification and does not need to process and forward information, therefore, the application can reduce the cost required for operation and maintenance and building of remote connection. BRIEF DESCRIPTION OF DRAWINGS
[0039] The accompanying drawings, which are incorporated herein and constitute part of the specification, illustrate embodiments consistent with the application and, together with the description, serve to explain the principles of the application.
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, those skilled in the art can obtain other drawings from these drawings without creative labor.
[0041] Figure 1 The flowchart provided for the first embodiment of the remote temporary connection building method of the application;
[0042] Figure 2 The scene diagram provided for the first embodiment of the remote temporary connection building method of the application;
[0043] Figure 3 The flowchart provided for the second embodiment of the remote temporary connection building method of the application;
[0044] Figure 4 The flowchart provided for the third embodiment of the remote temporary connection building method of the application;
[0045] Figure 5 The module structure diagram of the remote temporary connection building device of the embodiment of the application;
[0046] Figure 6 The device structure diagram of the hardware running environment involved in the remote temporary connection building method in the embodiment of the application.
[0047] The object, functional characteristics and advantages of the present application will be further explained in conjunction with the embodiments, with reference to the accompanying drawings. DETAILED DESCRIPTION
[0048] It should be understood that the specific embodiments described herein are merely intended to explain the technical solutions of the present application, and are not intended to limit the present application.
[0049] In order to better understand the technical solutions of the present application, the following will be described in detail in conjunction with the drawings and specific embodiments.
[0050] It should be noted that the execution subject of the present embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of realizing the above functions, a remote temporary connection building device, etc. The present embodiment and the following embodiments will be described below taking the remote temporary connection building device as an example.
[0051] When performing remote data access, in order to ensure the integrity of the data in the transmission process, vpn is usually used to communicate between different networks. Before the vpn tunnel is established, the intranet server accessed remotely needs to expose its public ip in the public network for the terminal device accessed remotely to find the server. However, due to the need for network security protection and use cost of public ip, the use conditions are harsh and the use cost is high.
[0052] Currently, a relay server with public ip is usually used for transfer. The terminal device directly accesses the relay server, and the relay server matches based on the authentication information of the terminal device and the server accessed remotely to establish bidirectional vpn communication. However, the current method needs to build a large number of relay servers to process and forward information through the relay servers, resulting in high cost of remote connection operation and building.
[0053] Based on this, the present embodiment provides a remote temporary connection building method, which will be described below with reference to Figure 1 , Figure 1 The flowchart of the first embodiment of the remote temporary connection building method of the present application.
[0054] In the present embodiment, the remote temporary building method is applied to a terminal, and the method comprises steps S10-S20:
[0055] Step S10: When receiving terminal configuration information sent by the terminal, the terminal configuration information is verified based on the intranet configuration information pre-stored locally. The intranet configuration information is sent to the local machine by the intranet server and includes intranet user information and intranet device information. The terminal configuration information includes terminal user information and target device information of the target intranet server.
[0056] It should be noted that the intranet user information refers to the user account and password information corresponding to the intranet server, and the intranet configuration information refers to the device code and parameter configuration information of the intranet server. The terminal user information refers to the user account and password information corresponding to the terminal, and the target intranet server is the intranet server that the user selects to connect to through the terminal.
[0057] It is understandable that after a remote connection is established, data is usually transmitted. If the connection is established without verification, it may be accessed by unauthorized devices, resulting in security issues such as data leakage and network attacks. Therefore, this application verifies the terminal configuration information based on the intranet configuration information pre-stored locally.
[0058] By verifying the terminal configuration information, only accounts with authorized access rights can make remote connections, thus ensuring the security of remote connections. Furthermore, by verifying the terminal configuration information, connection errors can be detected and corrected during the connection process.
[0059] In one feasible implementation, the intranet configuration information further includes association information between the intranet user information and the intranet device information. A further implementation of verifying the terminal configuration information based on pre-stored local intranet configuration information upon receiving terminal configuration information sent by the terminal can also be:
[0060] Based on the intranet user information pre-stored locally on each intranet server, it is determined whether there is target intranet user information that matches the terminal user information. If so, based on the association information pre-stored locally on each intranet server, it is determined whether the target intranet server is associated with the target intranet user information. If they are associated, the verification is successful.
[0061] It should be noted that the target intranet user information is the intranet user information stored in the relay server, and is consistent with the terminal user information.
[0062] It is understood that the relay server pre-stores intranet user information that can access the intranet sent by each intranet server. In this embodiment, only accounts with access permissions can make remote connections, and accounts with access permissions have been pre-stored in the relay server. Therefore, this embodiment verifies whether the terminal user information has matching target intranet user information to ensure the security of remote connections.
[0063] Furthermore, since an account can be associated with multiple intranet server devices, there may be situations where an intranet user has access permissions but lacks the corresponding intranet server connection permissions. Therefore, this embodiment, after verifying the intranet user information, also confirms whether the target intranet server is associated with the target intranet user information based on the association information pre-stored in the relay server, preventing users from remotely accessing the server through an unassociated intranet server.
[0064] During the transmission of intranet configuration information, terminal configuration information, and other data, multiple data transmissions can increase network latency and overhead. Therefore, this embodiment reduces network communication overhead and lowers latency by packaging and sending the data in a single package and then unpacking and verifying it on a relay server.
[0065] Step S20: If the verification is successful, the path mapping information corresponding to the target intranet server, which is pre-stored locally, is sent to the terminal so that the terminal and the target intranet server can directly connect and interact with the target intranet server based on the path mapping information without needing to perform message processing and forwarding locally.
[0066] It should be noted that the path mapping information includes NAT device IP and port mapping information, and the port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the internal network server.
[0067] Understandably, if the verification passes, it indicates that the end user has access to the corresponding target intranet server. Since intranet servers typically hide their real IP address and usually use dynamic port allocation, external terminals cannot directly know the private IP address and port number of the intranet server, meaning the terminal device cannot access the exact location of the intranet server. A NAT device, however, allows multiple devices to share a single public IP address, converting requests from the intranet server into externally visible public IP addresses. Through the public IP address and corresponding port mapping information of the NAT device, data packets can be forwarded, thereby enabling information exchange between the intranet server and the terminal. The verification and interaction process in this embodiment can be referred to... Figure 2 .
[0068] If verification is successful, the relay server sends the path mapping information corresponding to the target intranet server to the terminal. The terminal and the intranet server can then directly establish a connection, forwarding the information to the correct IP and port through the corresponding NAT device IP and port mapping information to achieve information exchange. During the connection establishment and information exchange process, the relay server only needs to verify both the terminal and the intranet server; it does not need to process or forward information. This reduces the need for a large number of relay servers for information exchange between the terminal and the intranet server, lowering the cost of maintaining and setting up remote connections.
[0069] In summary, when this embodiment receives terminal configuration information sent by the terminal, it verifies the terminal configuration information based on the intranet configuration information pre-stored locally. If the verification is successful, the path mapping information corresponding to the target intranet server pre-stored locally is sent to the terminal.
[0070] The intranet configuration information is sent to the local machine from the intranet server. Therefore, the relay server possesses intranet configuration information including intranet user information and intranet device information, enabling it to verify terminal configuration information, including terminal user information and target device information. Upon successful verification, the corresponding path mapping information is sent to the terminal, allowing the terminal and intranet server to connect directly and exchange information based on the path mapping information. The relay server only performs verification and does not need to process or forward information. Therefore, this application can reduce the cost of maintaining and setting up remote connections.
[0071] This application also provides a method for establishing a remote temporary connection, as described in the embodiments below. Figure 3 , Figure 3 This is a flowchart illustrating the second embodiment of the remote temporary connection setup method of this application.
[0072] In this embodiment, the remote temporary connection establishment method is applied to an intranet server, and the method includes steps A10 to A30:
[0073] Step A10: In response to the user's remote connection operation, obtain terminal configuration information, wherein the terminal configuration information includes terminal user information and target device information of the target intranet server;
[0074] It should be noted that the user's remote connection operation refers to the operation of the user connecting to the intranet server through the terminal, and the terminal user information is the account and password information stored on the terminal.
[0075] It is understandable that in this embodiment, obtaining end-user information before remote access is to enable the system to verify the user's identity and confirm their connection permissions, thereby improving the security of remote access. Furthermore, when accessing remotely through an intranet server, different users may have different needs. For example, some users may only require low bandwidth, while others may require higher security. Therefore, by obtaining end-user information before remote access, this embodiment can provide different configuration services for different user needs, further improving the scalability of remote access while ensuring its security.
[0076] For the same user, their end-user account may be linked to multiple different intranet server devices. The user chooses which intranet server device to connect to based on their specific needs. Therefore, in addition to obtaining end-user information, this embodiment also needs to obtain the target intranet server that the user wants to connect to, thereby ensuring the accuracy of establishing a remote connection. Furthermore, obtaining the target intranet server allows for accurate management of network resources, providing users with subsequent optimizations.
[0077] Step A20: Send the terminal configuration information to the relay server so that after the relay server successfully verifies the terminal configuration information, it can provide feedback on the path mapping information corresponding to the target intranet server based on the terminal configuration information. The relay server has pre-stored the path mapping information corresponding to each intranet server.
[0078] It should be noted that the path mapping information in this embodiment includes NAT device IP and port mapping information.
[0079] Understandably, terminal devices cannot access the exact location of the internal network server and cannot directly interact with it using its IP address and port. Therefore, it is necessary to use the public IP address and corresponding port mapping information of the NAT device to forward data packets, thereby enabling information exchange between the internal network server and the terminal.
[0080] Each end-user account may be associated with multiple intranet servers, and the port mapping information of different intranet servers is also different. In order to interact with the correct intranet server, the end-user information and the target device information need to be sent to the relay server first. Then, the NAT device IP and port mapping information corresponding to the target intranet server are obtained based on the relay server to ensure the accuracy of information interaction after the remote connection is established.
[0081] Step A30: After receiving the path mapping information, a connection is established with the target intranet server based on the path mapping information, so as to exchange information with the target intranet server based on the path mapping information without requiring the relay server to process and forward information. It can be understood that when the NAT device IP and the port mapping information are received, it indicates that the terminal user has remote connection permission, and the corresponding intranet server is associated with the terminal user. Information exchange between the terminal and the intranet server can be performed through the NAT device.
[0082] During information exchange, when a data packet is sent from the intranet server to the internet, the NAT device replaces the intranet server's IP address and port number with the NAT device's IP address and corresponding port number, and then forwards it to the terminal. When a data packet wants to be sent from the terminal to the intranet server, the terminal sends its information to the NAT device's IP address and corresponding port number. Based on the port mapping information, the NAT device then sends the information to the corresponding intranet server's IP address and port number. Therefore, this embodiment can achieve information exchange between the terminal and the intranet server without the need for a relay server to process and forward information, reducing the cost required for remote connection maintenance and setup.
[0083] In one feasible implementation, the step prior to obtaining terminal configuration information in response to a user's remote connection operation further includes:
[0084] In response to a user's login operation, the system obtains the user information entered during login as terminal user information and sends the terminal user information to a relay server. After the relay server successfully verifies the terminal user information, it sends the associated intranet device information corresponding to the terminal user information to its local machine. The associated intranet device information is the device information of one or more intranet servers associated with the terminal user information. The associated intranet device information is sent from the intranet server to the relay server. After receiving the associated intranet device information, the system stores the associated intranet device information locally to determine the intranet server that can be connected during remote access.
[0085] It should be noted that in this embodiment, the user's input information operation refers to the input operation when the user makes a remote connection using a new account, or the input operation when the user deletes the terminal user information already recorded on the terminal and re-enters the terminal user information. The device information of one or more intranet servers corresponding to the terminal user information is stored in the relay server before the terminal performs the access operation.
[0086] It is understandable that when the terminal does not record relevant user information, the user needs to manually enter the terminal user information so that the terminal can save the user information and connect in the future using the saved terminal user information.
[0087] Before a user uses a new account for remote access, the terminal device lacks user information and associated intranet server device information, and therefore cannot display any connectable intranet server devices. Therefore, the user information needs to be sent separately to the relay server for verification. The relay server then sends the associated intranet server device information, which is stored locally. Afterward, during remote access, the user can directly select the intranet server device to connect to on the terminal, thus improving the convenience of remote access.
[0088] In summary, this embodiment responds to the user's remote connection operation by acquiring terminal configuration information and sending the terminal configuration information to the relay server. After the relay server successfully verifies the terminal configuration information, it provides feedback on the path mapping information corresponding to the target intranet server based on the terminal configuration information. Upon receiving the path mapping information, the relay server establishes a connection with the target intranet server based on the path mapping information, so as to perform information interaction with the target intranet server based on the path mapping information without requiring the relay server to perform information processing and forwarding.
[0089] This embodiment establishes a connection with the corresponding target intranet server based on the NAT device's IP and port mapping information. This eliminates the need for the intranet server to expose its IP address to the public network during connection establishment. After connection is established, the NAT device can forward information based on the NAT device's IP and port mapping information, enabling information exchange between the intranet server and the terminal. This eliminates the need for numerous relay servers for information processing and forwarding, thus reducing the cost of remote connection maintenance and setup. Furthermore, this example enhances the convenience of remote access by verifying new accounts and storing associated intranet server device information for direct connection in subsequent processes.
[0090] This application also provides a method for establishing a remote temporary connection, as described in the embodiments below. Figure 4 , Figure 4 This is a flowchart illustrating the third embodiment of the remote temporary connection setup method of this application.
[0091] In this embodiment, the remote temporary connection establishment method is applied to an intranet server, and the method includes steps H10 to H30:
[0092] Step H10: In response to the user's confirmation of local configuration completion, obtain the corresponding intranet information, wherein the intranet information includes intranet user information and intranet device information. The intranet user information is the user information entered by the user when performing configuration, and the intranet device information is the device number information pre-stored locally.
[0093] It should be noted that the user's configuration operation is performed on the intranet server before remote access. The configuration operation includes entering the account and password and setting intranet server parameters. The intranet server parameter settings can be connection-related settings such as transmission traffic settings, access time settings, and access IP settings. The device number information is pre-programmed into the hardware of the intranet server.
[0094] Understandably, to ensure the security of remote connections, it is necessary to authenticate users connecting remotely through the intranet server. Before authentication, it is necessary to determine which users can be authenticated. Therefore, in this embodiment, in response to the user's confirmation of local configuration completion, the user's entered account and password information is obtained as intranet user information. This intranet user information refers to the user information that can connect to the intranet server.
[0095] Furthermore, different users have different needs when making remote connections. Therefore, this embodiment also obtains the intranet server parameter information set by the user, thereby improving the flexibility and scalability of the remote connection while ensuring the security of the remote connection.
[0096] Step H20: In response to the user's connection operation, connect to the relay server to obtain the path mapping information corresponding to the local location;
[0097] Understandably, internal network servers typically hide their IP addresses and use dynamic ports, making it difficult for external devices to obtain their IP and port information, thus hindering remote connections. Therefore, this embodiment connects to a relay server to obtain path mapping information, including NAT device IP and port mappings. The relay server acts as a central node to manage and monitor all relevant NAT devices and their mapping relationships. Relay server management allows for rapid configuration adjustments and makes remote connections between different locations easier and more efficient.
[0098] Step H30: Send the intranet information and the path mapping information to the relay server so that the relay server can store the intranet information and the path mapping information and send the path mapping information to the terminal when the terminal connects to the local machine.
[0099] It should be noted that the intranet information and the path mapping information will be packaged into data packets by the local machine and sent to the relay server. The relay server will unpack the data packets and send a message indicating successful unpacking back to the local machine so that the local machine can confirm that the relay server has received the corresponding data.
[0100] Understandably, relay servers need to determine the NAT device IPs, port mapping information, and internal network user information corresponding to different internal network servers to uniformly monitor and manage NAT devices and their mapping relationships. Therefore, this embodiment sends the internal network information, including internal network user information and internal network device information, as well as the path mapping information, including the NAT device IPs and the port mapping information, to the relay server for binding and storage. This allows terminals to directly obtain the corresponding path mapping information when they need to connect, preventing remote connection errors due to incorrect path mapping information and improving the efficiency and accuracy of remote connections.
[0101] In one feasible implementation, the specific method for sending the intranet information and the path mapping information to the relay server may also be:
[0102] When a preset time period has elapsed, the corresponding path mapping information is retrieved again locally. If the intranet information and the path mapping information have changed, the changed intranet information and the path mapping information are sent to the relay server.
[0103] It should be noted that if the intranet user information, NAT device IP, port mapping information, and intranet device information obtained locally this time are the same as the information obtained last time, then no changes have occurred; if one or more of the information are different from the information obtained last time, then changes have occurred.
[0104] It is understandable that the NAT device's IP address and port mapping information may change over time. If this information is not updated in a timely manner, external terminals may be unable to access the internal network server correctly. Therefore, this embodiment sets a preset time period to periodically check and update the relevant information, thereby ensuring that the system can maintain a valid connection even if the network configuration changes, avoiding remote connection failures due to outdated information, and improving the stability of remote connections.
[0105] In summary, this embodiment responds to the user's confirmation of local configuration completion by obtaining the corresponding intranet information; responds to the user's connection operation by connecting to the relay server, obtaining the path mapping information corresponding to the local machine, and sending the intranet information and the path mapping information to the relay server so that the relay server can store the intranet information and the path mapping information and send the path mapping information to the terminal when the terminal connects to the local machine.
[0106] This embodiment obtains internal network user information for subsequent user verification, ensuring that only authenticated users can access remotely, thus improving remote access security. Simultaneously, by connecting to a relay server and obtaining the corresponding NAT device IP and port mapping information, the terminal can locate the corresponding internal network server on the network without exposing the internal server IP to the public internet, thereby eliminating the need for public IP network security services and reducing usage costs. This embodiment also continuously obtains NAT device IP and port mapping information to maintain the connection even when network configuration changes, thereby improving the stability of the remote connection.
[0107] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the remote temporary connection establishment method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0108] This application also provides a remote temporary connection setup device, please refer to... Figure 5 The remote temporary connection setup device includes:
[0109] The information verification module 10 is used to verify the terminal configuration information based on the intranet configuration information pre-stored locally when receiving terminal configuration information sent by the terminal. The intranet configuration information is sent to the local machine by the intranet server and includes intranet user information and intranet device information. The terminal configuration information includes terminal user information and target device information of the target intranet server.
[0110] The path sending module 20 is used to send the path mapping information corresponding to the target intranet server, which is pre-stored locally, to the terminal if the verification is successful, so that the terminal and the target intranet server can directly connect and interact with the target intranet server based on the path mapping information without needing to perform message processing and forwarding locally.
[0111] In one embodiment, the information verification module further includes:
[0112] The user verification submodule is used to determine whether there is target intranet user information that matches the terminal user information based on the intranet user information pre-stored on each intranet server.
[0113] The server verification submodule is used to determine, if present, whether the target intranet server is associated with the target intranet user information based on the association information of each intranet server pre-stored locally.
[0114] The verification and confirmation submodule is used to verify if the data is associated.
[0115] In one embodiment, the remote temporary connection establishment device further includes:
[0116] The configuration information acquisition module is used to acquire terminal configuration information in response to the user's remote connection operation, wherein the terminal configuration information includes terminal user information and target device information of the target intranet server;
[0117] The configuration information sending module is used to send the terminal configuration information to the relay server, so that after the relay server successfully verifies the terminal configuration information, it can feed back the path mapping information corresponding to the target intranet server based on the terminal configuration information. The relay server pre-stores the path mapping information corresponding to each intranet server.
[0118] The remote connection module is used to establish a connection with the target intranet server based on the path mapping information after receiving the path mapping information, so as to interact with the target intranet server based on the path mapping information without requiring the relay server to process and forward information.
[0119] In one embodiment, the remote connection module further includes:
[0120] The user information acquisition module is used to respond to the user's login operation and acquire the user information entered by the user during login as the terminal user information;
[0121] The information sending module is used to send the terminal user information to the relay server, so that after the relay server successfully verifies the terminal user information, it sends the associated intranet device information corresponding to the terminal user information to the local machine. The associated intranet device information is the device information of one or more intranet servers associated with the terminal user information, and the associated intranet device information is sent from the intranet server to the relay server.
[0122] The associated information storage module is used to store the associated intranet device information locally after receiving it, so as to determine the intranet server that can be connected during remote access.
[0123] In one embodiment, the remote temporary connection establishment device further includes:
[0124] The intranet information acquisition module is used to acquire corresponding intranet information in response to the user's confirmation operation of local configuration completion. The intranet information includes intranet user information and intranet device information. The intranet user information is the user information entered by the user when performing configuration, and the intranet device information is the device number information pre-stored locally.
[0125] The path information acquisition module is used to respond to the user's connection operation, connect to the relay server, and obtain the path mapping information corresponding to the local location;
[0126] An intranet server information sending module is used to send the intranet information and the path mapping information to the relay server, so that the relay server can store the intranet information and the path mapping information and send the path mapping information to the terminal when the terminal connects to the local machine.
[0127] In one embodiment, the remote temporary connection establishment device further includes:
[0128] The information re-acquisition module is used to re-acquire the corresponding path mapping information locally after a preset time period has elapsed;
[0129] The information retransmission module is used to send the modified intranet information and path mapping information to the relay server if the intranet information and path mapping information are changed.
[0130] The remote temporary connection setup device provided in this application, employing the remote temporary connection setup method in the above embodiments, can solve the technical problem that the operation and maintenance of remote connections require high costs. Compared with the prior art, the beneficial effects of the remote temporary connection setup device provided in this application are the same as those of the remote temporary connection setup method provided in the above embodiments, and other technical features in the remote temporary connection setup device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0131] This application provides a remote temporary connection establishment device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the remote temporary connection establishment method in the first embodiment described above.
[0132] The following is for reference. Figure 6 The diagram illustrates a structure suitable for implementing the remote temporary connection setup device in the embodiments of this application. The remote temporary connection setup device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, tablets, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The remote temporary connection setup device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0133] like Figure 6 As shown, the remote temporary connection setup device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the remote temporary connection setup device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the remote temporary connection setup device to communicate wirelessly or wiredly with other devices to exchange data. Although the figure shows remote temporary connection setup devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.
[0134] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0135] The remote temporary connection setup device provided in this application, employing the remote temporary connection setup method in the above embodiments, can solve the technical problem that the operation and maintenance of remote connections require high costs. Compared with the prior art, the beneficial effects of the remote temporary connection setup device provided in this application are the same as those of the remote temporary connection setup method provided in the above embodiments, and other technical features in this remote temporary connection setup device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0136] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0137] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0138] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the remote temporary connection establishment method in the above embodiments.
[0139] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0140] The aforementioned computer-readable storage medium may be included in the remote temporary connection setup device; or it may exist independently and not be assembled into the remote temporary connection setup device.
[0141] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the remote temporary connection setup device, cause the remote temporary connection setup device to perform the aforementioned remote temporary connection setup method.
[0142] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0143] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0144] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0145] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described remote temporary connection establishment method, which can solve the technical problem that the operation and maintenance and establishment of remote connections require high costs. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as the beneficial effects of the remote temporary connection establishment method provided in the above embodiments, and will not be repeated here.
[0146] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A method for establishing a remote temporary connection, characterized in that, Applied to relay servers, the method includes: When terminal configuration information is received from a terminal, the terminal configuration information is verified based on the intranet configuration information pre-stored locally. The intranet configuration information is sent to the local machine by an intranet server and includes intranet user information and intranet device information. The intranet user information is user information that can access the intranet sent by each intranet server. The terminal configuration information includes terminal user information and target device information of the target intranet server. If the verification is successful, the path mapping information corresponding to the target intranet server, which is pre-stored locally, is sent to the terminal. The path mapping information is sent locally by the intranet server to enable the terminal and the target intranet server to connect directly. Without needing to perform message processing and forwarding locally, the terminal interacts with the target intranet server based on the path mapping information. The path mapping information includes NAT device IP and port mapping information. The port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the intranet server. The intranet server hides the internal IP and uses dynamic ports.
2. The method as described in claim 1, characterized in that, The intranet configuration information also includes association information between the intranet user information and the intranet device information. The step of verifying the terminal configuration information based on pre-stored intranet configuration information when receiving terminal configuration information sent by the terminal includes: Based on the intranet user information pre-stored on each intranet server, determine whether there is target intranet user information that matches the terminal user information; If they exist, then based on the association information of each intranet server pre-stored locally, it is determined whether the target intranet server is associated with the target intranet user information; If they are related, the verification passes.
3. A method for establishing a remote temporary connection, characterized in that, Applied to a terminal, the method includes: In response to a user's remote connection operation, terminal configuration information is obtained, wherein the terminal configuration information includes terminal user information and target device information of the target intranet server; The terminal configuration information is sent to the relay server so that, after the relay server successfully verifies the terminal configuration information, it can provide feedback on the path mapping information corresponding to the target intranet server based on the terminal configuration information. The relay server pre-stores the path mapping information and intranet configuration information corresponding to each intranet server. The intranet configuration information includes intranet user information and intranet device information. The intranet user information is the user information that can access the intranet sent by each intranet server. The path mapping information includes NAT device IP and port mapping information. The port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the intranet server. The intranet server hides the internal IP and uses dynamic ports. After receiving the path mapping information, a direct connection is established with the target intranet server based on the path mapping information, so as to exchange information with the target intranet server based on the path mapping information without the need for the relay server to process and forward information.
4. The method as described in claim 3, characterized in that, The steps prior to obtaining terminal configuration information in response to a user's remote connection operation further include: In response to a user's login action, the user information entered during login is obtained as the end-user information; The terminal user information is sent to the relay server, so that after the relay server successfully verifies the terminal user information, it sends the associated intranet device information corresponding to the terminal user information to the local machine. The associated intranet device information is the device information of one or more intranet servers associated with the terminal user information, and the associated intranet device information is sent to the relay server by the intranet server. After receiving the associated intranet device information, the associated intranet device information is stored locally to determine the intranet server that can be connected during remote access.
5. A method for establishing a remote temporary connection, characterized in that, The method, applied to intranet servers, includes: In response to the user's confirmation of local configuration completion, the corresponding intranet configuration information is obtained. The intranet configuration information includes intranet user information and intranet device information. The intranet user information is the user information entered by the user when configuring. The intranet device information is the device number information pre-stored locally. The intranet user information is the user information that can access the intranet. In response to a user's connection operation, a connection is established with the relay server to obtain path mapping information corresponding to the local network. The path mapping information includes NAT device IP and port mapping information. The port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the intranet server. The intranet server hides the internal IP and uses dynamic ports. The intranet configuration information and the path mapping information are sent to the relay server for storage. After successfully verifying the terminal configuration information, the relay server sends the path mapping information to the terminal. Upon receiving the path mapping information, the terminal establishes a direct connection with the target intranet server based on the path mapping information. This allows for information interaction with the target intranet server without requiring information processing and forwarding by the relay server. The relay server acts as a central node to manage and monitor all relevant NAT devices and their mapping relationships. The terminal configuration information includes terminal user information and target device information of the target intranet server.
6. The method as described in claim 5, characterized in that, After the step of sending the intranet configuration information and the path mapping information to the relay server, the method further includes: When the preset time period has elapsed, the corresponding local path mapping information will be retrieved again; If the intranet configuration information and the path mapping information are changed, the changed intranet configuration information and the path mapping information will be sent to the relay server.
7. A remote temporary connection establishment system, characterized in that, The system includes: a relay server, a terminal, and an intranet server, wherein the relay server is connected to the terminal and the intranet server; A relay server is used to verify terminal configuration information sent by a terminal based on pre-stored intranet configuration information when it receives such information. The intranet configuration information includes intranet user information and intranet device information. The intranet user information consists of user information accessible to the intranet sent by each intranet server. The terminal configuration information includes terminal user information and target device information of the target intranet server. If the verification passes, the relay server also sends pre-stored path mapping information corresponding to the target intranet server to the terminal. The intranet user information consists of user information accessible to the intranet sent by each intranet server. The path mapping information includes NAT device IP and port mapping information. The port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the intranet server. The intranet server hides the internal IP and uses dynamic ports, acting as a central node to manage and monitor all related NAT devices and their mapping relationships. The terminal is used to respond to the user's remote connection operation, obtain terminal configuration information, and send the terminal configuration information to the relay server. The terminal is also used to establish a direct connection with the target intranet server based on the path mapping information after receiving the path mapping information, so as to interact with the target intranet server based on the path mapping information without the need for the relay server to process and forward information. The intranet server is used to respond to the user's confirmation operation of local configuration completion, obtain the corresponding intranet configuration information, wherein the intranet device information is device number information pre-stored locally, and the intranet server is also used to respond to the user's connection operation, connect with the relay server, obtain the path mapping information corresponding to the local location, and send the intranet configuration information and the path mapping information to the relay server.
8. A relay server for establishing remote temporary connections, characterized in that, The relay server includes: The information verification module is used to verify the terminal configuration information sent by the terminal based on the intranet configuration information pre-stored locally when it receives the terminal configuration information sent by the terminal. The intranet configuration information is sent to the local machine by the intranet server, and the intranet user information is the user information that can access the intranet sent by each of the intranet servers. The intranet configuration information includes intranet user information and intranet device information, and the terminal configuration information includes terminal user information and target device information of the target intranet server. The path sending module is used to send the path mapping information corresponding to the target intranet server, which is pre-stored locally, to the terminal if the verification is successful. The path mapping information is sent locally by the intranet server so that the terminal and the target intranet server can directly connect and interact with the target intranet server based on the path mapping information without needing to perform message processing and forwarding locally. The path mapping information includes NAT device IP and port mapping information. The port mapping information is the mapping relationship between the public port of the NAT device and the internal IP and port of the intranet server. The intranet server hides the internal IP and uses dynamic ports.
9. A remote temporary connection setup device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the remote temporary connection establishment method as described in any one of claims 1 to 6.
10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the remote temporary connection establishment method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Communication method and system for cloud desktop
CN114915420A