Stadium communication method and system based on multi-TCP connection and storage medium
By establishing a main TCP connection between the edge gateway and the cloud server and establishing different sub TCP connections according to the sub-connection creation instructions, the real-time data transmission problem caused by the concentration of communication tasks on a single link is solved, and flexible data transmission and real-time improvements are achieved.
Patent Information
- Application Number
- CN202510548154.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-04-28
AI Technical Summary
In the prior art, communication tasks between edge gateways and cloud servers are concentrated on a single link, resulting in real-time impact on data transmission.
Establish a main TCP connection between the edge gateway and the cloud server, and establish different sub TCP connections based on the sub-connection creation instructions, which are used to transmit control instructions and HTTP requests, and perform different communication tasks through different TCP connections respectively.
It effectively avoids the real-time data transmission problem caused by the concentration of communication tasks on a single link, improves the flexibility and real-time data transmission, and adapts to complex communication scenarios and business needs.
Smart Images

Figure CN120281804A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a communication method, system and storage medium for stadiums based on multiple TCP connections. Background Art
[0002] In the intelligent management scenario of stadiums, the edge gateway, as the host computer, docks with the terminal hardware in the stadium through the serial port protocol, or communicates with other services in the local area network through the RJ-45 network port. At the same time, it needs to establish a stable TCP connection with the cloud server to transparently transmit control instructions in real time and proxy and forward HTTP requests to communicate with other services in the local area network. Traditional edge gateways usually use a single TCP connection to connect to the server, and all communication tasks are concentrated on a single link, which is prone to link congestion and affects the real-time performance of data transmission.
[0003] Therefore, there are deficiencies in the prior art and it needs to be improved and developed. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a communication method, device, terminal and storage medium for stadiums based on multiple TCP connections in view of the above-mentioned deficiencies of the prior art, aiming to solve the problem of affecting the real-time performance of data transmission caused by the concentration of communication tasks between the edge gateway and the cloud server on a single link.
[0005] The technical solution adopted by the present invention to solve the technical problem is as follows:
[0006] In the first aspect, an embodiment of the present invention provides a communication method for stadiums based on multiple TCP connections, and the method includes:
[0007] Establish a main TCP connection between the edge gateway and the cloud server;
[0008] If the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, establish a sub-TCP connection with the cloud server according to the sub-connection creation instruction;
[0009] Use the edge gateway to receive the control instructions sent by the cloud server through the sub-TCP connection, and transparently transmit the control instructions to the target terminal hardware in the stadium;
[0010] Use the edge gateway to receive the HTTP requests sent by the cloud server through the sub-TCP connection, and forward the HTTP requests to the target web service in the local area network where the edge gateway is located.
[0011] In an implementation manner, establishing a main TCP connection between the edge gateway and the cloud server includes:
[0012] Use the edge gateway to obtain and parse preset connection data, and obtain the username and password of the edge gateway, the IP address and port of the cloud server, and a first connection identifier. The first connection identifier contains a preset role number, the physical MAC fingerprint of the edge gateway, and a connection sequence number;
[0013] Use the edge gateway to initiate a TCP three-way handshake to the target address composed of the IP address and port of the cloud server;
[0014] If the TCP three-way handshake is successful, generate a first identity authentication request based on the username, password, and local IP address of the edge gateway, and the first connection identifier, and send it to the cloud server;
[0015] If the verification result of the first identity authentication request is passed, perform secondary authentication with the cloud server;
[0016] If the secondary authentication is passed, complete the establishment of the main TCP connection.
[0017] In one implementation, performing secondary authentication with the cloud server includes:
[0018] Use the edge gateway to receive the encrypted message generated by the cloud server, and decrypt the encrypted message to obtain the original data message;
[0019] Use the edge gateway to modify a preset field in the original data message, and encrypt based on the modified data to obtain a second encrypted message;
[0020] Use the edge gateway to send the second encrypted message to the cloud server.
[0021] In one implementation, after establishing the main TCP connection between the edge gateway and the cloud server, it further includes:
[0022] Start a heartbeat mechanism to keep the main TCP connection alive.
[0023] In one implementation, establishing a sub-TCP connection with the cloud server according to the sub-connection creation instruction includes:
[0024] Parse the sub-connection creation instruction to obtain the role type of the sub-connection;
[0025] Establish a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type. In one implementation, establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type includes:
[0026] If the role type is a work connection, a second connection identifier is formed by combining the role number corresponding to the work connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway;
[0027] Use the edge gateway to initiate a TCP three-way handshake to a target address composed of the IP address and port of the cloud server;
[0028] If the TCP three-way handshake is successful, generate a second identity authentication request based on the username, password, and local IP address of the edge gateway, and the second connection identifier, and send it to the cloud server;
[0029] If the verification result of the second identity authentication request is passed, perform secondary authentication with the cloud server;
[0030] If the secondary authentication is passed, bind the protocol type corresponding to the role type to complete the establishment of the work TCP connection, and the work TCP connection is used to transmit the control instructions issued by the cloud server.
[0031] In one implementation, before establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type, it further includes:
[0032] If the role type is an agent connection, a third connection identifier is formed by combining the second role number corresponding to the agent connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway;
[0033] Use the edge gateway to initiate a TCP three-way handshake to a target address composed of the IP address and port of the cloud server;
[0034] If the TCP three-way handshake is successful, generate a third identity authentication request based on the username, password, and local IP address of the edge gateway, and the third connection identifier, and send it to the cloud server;
[0035] If the verification result of the third identity authentication request is passed, perform secondary authentication with the cloud server;
[0036] If the secondary authentication is passed, bind the protocol type corresponding to the role type to complete the establishment of the agent TCP connection, and the agent TCP connection is used to transmit the HTTP requests issued by the cloud server.
[0037] In one implementation, before establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type, it further includes:
[0038] Obtain the MAC address of the physical network card of the edge gateway;
[0039] Perform hash cloud processing on the MAC address to obtain the physical MAC fingerprint.
[0040] In a second aspect, an embodiment of the present invention further provides a stadium communication system based on multiple TCP connections, and the system includes:
[0041] A main TCP connection establishment module, configured to establish a main TCP connection between an edge gateway and a cloud server;
[0042] A dynamic TCP connection establishment module, configured to, if the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, establish a sub-TCP connection with the cloud server according to the sub-connection creation instruction;
[0043] An instruction transparent transmission module, configured to use the edge gateway to receive a control instruction sent by the cloud server through the sub-TCP connection and transparently transmit the control instruction to a target terminal hardware in the stadium;
[0044] An instruction forwarding module, configured to use the edge gateway to receive an HTTP request sent by the cloud server through the sub-TCP connection and forward the HTTP request to a target web service in the local area network where the edge gateway is located.
[0045] In a third aspect, an embodiment of the present invention further provides a computer-readable storage medium, and the computer-readable storage medium stores a stadium communication program based on multiple TCP connections. The stadium communication program based on multiple TCP connections can be executed to implement the steps of the stadium communication method based on multiple TCP connections as described above.
[0046] Advantages of the present invention: The present invention establishes a main TCP connection between an edge gateway and a cloud server; if the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, a sub-TCP connection with the cloud server is established according to the sub-connection creation instruction; the edge gateway is used to receive a control instruction sent by the cloud server through the sub-TCP connection and transparently transmit the control instruction to a target terminal hardware in the stadium; the edge gateway is used to receive an HTTP request sent by the cloud server through the sub-TCP connection and forward the HTTP request to a target web service in the local area network where the edge gateway is located. By creating different TCP connections to execute different communication tasks, the present invention can effectively avoid the problem of affecting data transmission real-time performance caused by communication tasks being concentrated on a single link. Description of the Drawings
[0047] Figure 1 is a flowchart of a preferred embodiment of the stadium communication method based on multiple TCP connections in the present invention.
[0048] Figure 2 is a flowchart of the establishment of the main TCP connection in the present invention.
[0049] Figure 3 is the flowchart of role verification in the present invention.
[0050] Figure 4 is the schematic diagram of establishing different TCP connections according to different instructions in the present invention.
[0051] Figure 5 is the schematic structural diagram of a preferred embodiment of the stadium communication system based on multiple TCP connections in the present invention. Detailed implementation manners
[0052] To make the objectives, technical solutions and advantages of the present invention clearer and more definite, the present invention will be further described in detail below with reference to the accompanying drawings and by way of examples. It should be understood that the specific examples described herein are only used to explain the present invention and are not used to limit the present invention.
[0053] In the intelligent management scenario of a stadium, as a host computer, the edge gateway docks with the terminal hardware in the stadium through a serial port protocol, or communicates with other services in the local area network through an RJ-45 network port. At the same time, it is necessary to establish a stable TCP connection with the cloud server to transparently transmit control instructions in real time and proxy and forward HTTP requests to communicate with other services in the local area network. The traditional edge gateway usually uses a single TCP connection to connect to the server, and all communication tasks are concentrated on a single link, which is likely to cause link congestion and affect the real-time performance of data transmission.
[0054] In view of the above defects of the prior art, the present invention provides a stadium communication method, system and storage medium based on multiple TCP connections. The method includes: establishing a main TCP connection between the edge gateway and the cloud server; if the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, establishing a sub-TCP connection with the cloud server according to the sub-connection creation instruction; using the edge gateway to receive the control instructions sent by the cloud server through the sub-TCP connection and transparently transmit the control instructions to the target terminal hardware in the stadium; using the edge gateway to receive the HTTP requests sent by the cloud server through the sub-TCP connection and forward the HTTP requests to the target web service in the local area network where the edge gateway is located. By creating different TCP connections to execute different communication tasks, the present invention can effectively avoid the problem of affecting the real-time performance of data transmission caused by the concentration of communication tasks on a single link.
[0055] Please refer to Figure 1 , the stadium communication method based on multiple TCP connections according to the embodiment of the present invention includes the following steps:
[0056] Step S100, establish a main TCP connection between the edge gateway and the cloud server.
[0057] Specifically, as the basic control channel of the communication system, the main TCP connection needs to be established and maintained in a long - connection state preferentially. Instructions for creating all subsequent sub - TCP connections need to be sent through this main TCP connection.
[0058] In one implementation, establishing a main TCP connection between the edge gateway and the cloud server includes:
[0059] Using the edge gateway to obtain and parse preset connection data to obtain the username and password of the edge gateway, the IP address and port of the cloud server, and a first connection identifier. The first connection identifier contains a preset role number, the physical MAC fingerprint of the edge gateway, and a connection sequence number;
[0060] Using the edge gateway to initiate a TCP three - way handshake to the target address composed of the IP address and port of the cloud server;
[0061] If the TCP three - way handshake is successful, generate a first identity authentication request based on the username, password, and local IP address of the edge gateway, and the first connection identifier, and send it to the cloud server;
[0062] If the verification result of the first identity authentication request is passed, perform secondary authentication with the cloud server;
[0063] If the secondary authentication is passed, complete the establishment of the main TCP connection.
[0064] Specifically, the connection data is pre - placed in the edge gateway configuration file in the form of a standardized string. The format is username:password@tcp(IP:Port) / WorkerID. Here, username is the username of the edge gateway, password is the password of the edge gateway, IP is the IP address of the server, Port is the port of the server, and WorkerID is the connection identifier. The format of the connection identifier is: device physical MAC fingerprint_role number_connection sequence number. For example, the first connection identifier can be A1B2C3D4E5F6_00_0001. A1B2C3D4E5F6 is the physical MAC fingerprint of the edge gateway, 00 is the role number, used to indicate the role of the connection. 0001 is the connection sequence number, that is, the sequence number of the current TCP connection of the edge gateway. A counter is set in the edge gateway. Whenever a new TCP connection is created, the counter increments by 1 to update the connection sequence number. In the present invention, the role types involved include three categories: main connection, working connection, and proxy connection. The role number corresponding to the main connection is 00, the role number corresponding to the working connection is 01, and the role number corresponding to the proxy connection is 02. Different connection roles limit different TCP link functions. For example, in the present invention, the main connection can only be used to transmit sub - connection creation instructions. The working connection is only used to transmit control instructions for the terminal hardware in the stadium, and the proxy connection is only used to transmit HTTP requests.
[0065] The flowchart for establishing the main TCP connection is as Figure 2 shown. After the first identity authentication request is sent to the cloud server, the cloud server verifies the username, password, local IP address of the edge gateway, and the first connection identifier in the first identity authentication request. Specifically, the cloud server stores the username, password, and local IP address of each edge gateway and compares them step by step. When all the above comparisons pass, role verification is also carried out. Specifically, the MAC fingerprint in the first connection identifier is verified. If the verification passes, the role number is further verified; if the verification passes, it is further verified whether the connection sequence numbers are consecutive. If any verification fails during the above process, the underlying transmission channel generated by the TCP three - way handshake is disconnected and an alarm message is generated. After passing all the verifications, it is determined that the verification result of the first identity authentication request is passed, and a secondary authentication is initiated. This process can be as Figure 3 shown.
[0066] In one implementation, if the TCP three - way handshake fails, the establishment of the main TCP connection ends and an error log is recorded.
[0067] In one implementation, if the verification result of the first identity authentication request is failed, the establishment of the main TCP connection ends and an error log is recorded.
[0068] In one implementation, if the secondary authentication fails, the establishment of the main TCP connection is terminated and an error log is recorded.
[0069] In one implementation, performing secondary authentication with the cloud server includes:
[0070] Using the edge gateway to receive the encrypted message generated by the cloud server and decrypt the encrypted message to obtain the original data message;
[0071] Using the edge gateway to modify a preset field in the original data message and encrypt the modified data to obtain a second encrypted message;
[0072] Using the edge gateway to send the second encrypted message to the cloud server.
[0073] Specifically, after the first identity authentication request passes the verification, the cloud server generates an original data message composed of a random number and a timestamp, encrypts the original data message using an encryption algorithm, generates an encrypted message and sends it to the edge gateway. After decrypting, the edge gateway obtains the original data message. After modifying the random number, the edge gateway encrypts the modified original data message using the same encryption algorithm to obtain a second encrypted message. The way to modify the random number can be to perform a fixed-value operation on the random number. After the edge gateway sends the second encrypted message to the cloud server, the cloud server decrypts the second encrypted message and verifies the validity of the timestamp to prevent replay attacks. In addition, it also verifies that the modified random number is obtained by performing a fixed-value operation on the random number. If both of these verifications are successful, the secondary authentication is successful. By setting up secondary authentication, the present invention can effectively improve the security of the TCP connection and avoid the illegal occupation or attack of server resources.
[0074] In one implementation, after establishing the main TCP connection between the edge gateway and the cloud server, it further includes:
[0075] Starting a heartbeat mechanism to keep the main TCP connection alive.
[0076] Specifically, since the main TCP connection is a basic TCP connection and needs to be kept alive. Therefore, it is set to send a heartbeat every 5 seconds to keep it alive. When there is instruction transmission in the main TCP connection, the heartbeat sending is stopped.
[0077] Please refer to Figure 1 , the method for stadium communication based on multiple TCP connections described in the embodiments of the present invention further includes the following steps:
[0078] Step S200, if the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, establish a sub-TCP connection with the cloud server according to the sub-connection creation instruction.
[0079] Specifically, after the main TCP connection is established, if a sub-connection creation instruction is received, different sub-TCP connections are established according to the sub-connection creation instruction. Subsequently, control instructions for terminal hardware in the stadium or HTTP requests can be transmitted based on the sub-TCP connections. By creating different TCP connections to execute different communication tasks, the present invention can effectively avoid the problem of affecting data transmission real-time performance caused by communication tasks concentrating on a single link. In addition, through this method, complex communication scenarios can be dealt with, and new sub-TCP connections can be flexibly created to meet different service requirements.
[0080] In one implementation, establishing a sub-TCP connection with a cloud server according to the sub-connection creation instruction includes:
[0081] Parsing the sub-connection creation instruction to obtain the role type of the sub-connection;
[0082] Establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type.
[0083] Specifically, the sub-connection creation instruction contains the role type. Different role types have different ways of establishing sub-TCP connections.
[0084] In one implementation, establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type includes:
[0085] If the role type is a working connection, the role number corresponding to the working connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection serial number of the edge gateway are combined to form a second connection identifier;
[0086] Using the edge gateway to initiate a TCP three-way handshake to a target address composed of the IP address and port of the cloud server;
[0087] If the TCP three-way handshake is successful, a second identity authentication request is generated based on the username, password, and local IP address of the edge gateway, and the second connection identifier, and sent to the cloud server;
[0088] If the verification result of the second identity authentication request is passed, a secondary authentication is performed with the cloud server;
[0089] If the secondary authentication is passed, the protocol type corresponding to the role type is bound to complete the establishment of the working TCP connection, and the working TCP connection is used to transmit control instructions sent by the cloud server and receive response data returned by the target terminal hardware.
[0090] Specifically, when the role type is a work connection, it means that the to-be-established sub-TCP connection is used to transmit the control instructions sent by the cloud server for the terminal hardware in the stadium. When establishing a work TCP connection, the three-way handshake, identity authentication, and secondary authentication are also performed. The process here is the same as that of the main TCP connection, only the connection identifier is different, which will not be elaborated here. The protocol types corresponding to the work connection include the Modbus protocol and the level signal protocol. The Modbus protocol can be used for the lamp control module in the stadium, and the level signal protocol can be used for the turnstile relay, water control switch, etc. in the stadium.
[0091] In one implementation, establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type further includes:
[0092] If the role type is a proxy connection, then the second role number corresponding to the proxy connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway are combined to form a third connection identifier;
[0093] Use the edge gateway to initiate a TCP three-way handshake to the target address composed of the IP address and port of the cloud server;
[0094] If the TCP three-way handshake is successful, then generate a third identity authentication request based on the username, password, and local IP address of the edge gateway, and the third connection identifier, and send it to the cloud server;
[0095] If the verification result of the third identity authentication request is passed, then perform secondary authentication with the cloud server;
[0096] If the secondary authentication is passed, then bind the protocol type corresponding to the role type to complete the establishment of the proxy TCP connection, and the proxy TCP connection is used to transmit the HTTP requests sent by the cloud server and receive the response data returned by the target web service.
[0097] Specifically, when the role type is a proxy connection, it means that the to-be-established sub-TCP connection is used to transmit the HTTP requests sent by the cloud server. When establishing a proxy TCP connection, the three-way handshake, identity authentication, and secondary authentication are also performed. The process here is the same as that of the main TCP connection, only the connection identifier is different, which will not be elaborated here. The protocol type corresponding to the proxy connection is the HTTP protocol.
[0098] Please refer to Figure 1 , the method for communicating in a stadium based on multiple TCP connections according to the embodiments of the present invention further includes the following steps:
[0099] Step S300: Use the edge gateway to receive the control instructions sent by the cloud server through the sub-TCP connection, and transparently transmit the control instructions to the target terminal hardware in the stadium.
[0100] Specifically, the control instructions contain the IP address of the target terminal hardware. The edge gateway can transparently transmit the control instructions to the target terminal hardware in the stadium.
[0101] Please refer to Figure 1 , the communication method for stadiums based on multiple TCP connections according to the embodiments of the present invention further includes the following steps:
[0102] Step S400: Use the edge gateway to receive the HTTP requests sent by the cloud server through the sub-TCP connection, and forward the HTTP requests to the target web service in the local area network where the edge gateway is located.
[0103] Specifically, the HTTP requests contain the URL addresses. The corresponding target web services can be determined according to the URL addresses, and the HTTP requests are forwarded.
[0104] The schematic diagram of establishing different TCP connections according to different instructions in the present invention is as Figure 4 shown. By creating different TCP connections to execute different communication tasks, the problem of affecting the real-time data transmission caused by the concentration of communication tasks on a single link can be effectively avoided.
[0105] In summary, the present invention establishes a main TCP connection between the edge gateway and the cloud server; if the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, a sub-TCP connection with the cloud server is established according to the sub-connection creation instruction; the edge gateway is used to receive the control instructions sent by the cloud server through the sub-TCP connection and transparently transmit the control instructions to the target terminal hardware in the stadium; the edge gateway is used to receive the HTTP requests sent by the cloud server through the sub-TCP connection and forward the HTTP requests to the target web service in the local area network where the edge gateway is located. By creating different TCP connections to execute different communication tasks, the problem of affecting the real-time data transmission caused by the concentration of communication tasks on a single link can be effectively avoided.
[0106] In one embodiment, as Figure 5 shown, based on the above communication method for stadiums based on multiple TCP connections, the present invention also correspondingly provides a communication system for stadiums based on multiple TCP connections. The device includes:
[0107] A main TCP connection establishment module, configured to establish a main TCP connection between the edge gateway and the cloud server;
[0108] A dynamic TCP connection establishment module, which is used to establish a sub-TCP connection with the cloud server according to the sub-connection creation instruction if the edge gateway receives the sub-connection creation instruction sent by the cloud server through the main TCP connection;
[0109] An instruction pass-through module, which is used to receive the control instruction sent by the cloud server through the sub-TCP connection by using the edge gateway and pass the control instruction through to the target terminal hardware in the stadium;
[0110] An instruction forwarding module, which is used to receive the HTTP request sent by the cloud server through the sub-TCP connection by using the edge gateway and forward the HTTP request to the target web service in the local area network where the edge gateway is located.
[0111] In one embodiment, the main TCP connection establishment module includes:
[0112] A data parsing unit, which is used to obtain and parse the preset connection data by using the edge gateway to obtain the username and password of the edge gateway, the IP address and port of the cloud server, and a first connection identifier, where the first connection identifier includes a preset role number, the physical MAC fingerprint of the edge gateway, and a connection sequence number;
[0113] A main TCP three-way handshake unit, which is used to initiate a TCP three-way handshake to the target address composed of the IP address and port of the cloud server by using the edge gateway;
[0114] A main TCP identity authentication unit, which is used to generate a first identity authentication request based on the username, password and local IP address of the edge gateway, and the first connection identifier and send it to the cloud server if the TCP three-way handshake is successful;
[0115] A main TCP secondary authentication unit, which is used to perform secondary authentication with the cloud server if the verification result of the first identity authentication request is passed;
[0116] A main TCP establishment unit, which is used to complete the establishment of the main TCP connection if the secondary authentication is passed.
[0117] In one embodiment, the system further includes:
[0118] A decryption unit, which is used to receive the encrypted message generated by the cloud server by using the edge gateway and decrypt the encrypted message to obtain the original data message;
[0119] An encryption unit, which is used to modify the preset fields in the original data message by using the edge gateway and encrypt the data based on the modified data to obtain a second encrypted message;
[0120] A message sending unit, configured to use the edge gateway to send the second encrypted message to the cloud server.
[0121] In one embodiment, the system further includes:
[0122] A keep-alive unit, configured to start a heartbeat mechanism to perform keep-alive for the main TCP connection.
[0123] In one embodiment, the system further includes:
[0124] A parsing unit, configured to parse the sub-connection creation instruction to obtain the role type of the sub-connection;
[0125] A sub-connection establishing unit, configured to establish a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type.
[0126] In one embodiment, the system further includes:
[0127] A second connection identifier generating unit, configured to, if the role type is a working connection, form a second connection identifier by combining the role number corresponding to the working connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway;
[0128] A working TCP three-way handshake unit, configured to use the edge gateway to initiate a TCP three-way handshake to a target address composed of the IP address and port of the cloud server;
[0129] A working TCP identity authentication unit, configured to, if the TCP three-way handshake is successful, generate a second identity authentication request based on the username, password, and local IP address of the edge gateway, and the second connection identifier, and send it to the cloud server;
[0130] A working TCP secondary authentication unit, configured to perform secondary authentication with the cloud server if the verification result of the second identity authentication request is passed;
[0131] A working TCP establishing unit, configured to, if the secondary authentication is passed, bind the protocol type corresponding to the role type to complete the establishment of the working TCP connection, where the working TCP connection is used to transmit control instructions issued by the cloud server.
[0132] In one embodiment, the system further includes:
[0133] A third connection identifier generating unit, if the role type is a proxy connection, form a third connection identifier by combining the second role number corresponding to the proxy connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway;
[0134] A proxy TCP three-way handshake unit for initiating a TCP three-way handshake with a target address composed of the IP address and port of a cloud server by using the edge gateway;
[0135] A proxy TCP authentication unit for, if the TCP three-way handshake is successful, generating a third authentication request based on the username, password, and local IP address of the edge gateway, and a third connection identifier, and sending the request to the cloud server;
[0136] A proxy TCP secondary authentication unit for, if the verification result of the third authentication request is passed, performing secondary authentication with the cloud server;
[0137] A proxy TCP establishment unit for, if the secondary authentication is passed, binding the protocol type corresponding to the role type to complete the establishment of the proxy TCP connection, where the proxy TCP connection is used to transmit HTTP requests sent by the cloud server and receive response data returned by the target web service.
[0138] An embodiment of the present invention further provides a computer-readable storage medium, on which a stadium communication program based on multiple TCP connections is stored. When the stadium communication program based on multiple TCP connections is executed by a processor, the steps of any one of the stadium communication methods based on multiple TCP connections provided by the embodiments of the present invention are implemented.
[0139] It should be understood that the sequence numbers of the steps in the above embodiments do not imply the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0140] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of mutual distinction and do not limit the protection scope of the present invention. The specific working process of the units and modules in the above device can refer to the corresponding process in the foregoing method embodiments and will not be elaborated herein.
[0141] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For parts not detailed or recorded in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0142] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0143] In the embodiments provided by the present invention, it should be understood that the disclosed device / terminal device and method can be implemented in other ways. For example, the device / terminal device embodiments described above are merely illustrative. For example, the above division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed.
[0144] The above-described embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not deviate from the spirit and scope of the technical solutions of the respective embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A communication method for stadiums based on multiple TCP connections, characterized in that, The method includes: Establish a main TCP connection between the edge gateway and the cloud server; If the edge gateway receives a sub-connection creation instruction sent by the cloud server through the main TCP connection, establish a sub-TCP connection with the cloud server according to the sub-connection creation instruction; Use the edge gateway to receive the control instruction sent by the cloud server through the sub-TCP connection and transparently transmit the control instruction to the target terminal hardware in the stadium; Use the edge gateway to receive the HTTP request sent by the cloud server through the sub-TCP connection and forward the HTTP request to the target web service in the local area network where the edge gateway is located.
2. The communication method for a stadium based on multiple TCP connections according to claim 1, wherein Establishing a main TCP connection between the edge gateway and the cloud server includes: Use the edge gateway to obtain and parse the preset connection data to obtain the username and password of the edge gateway, the IP address and port of the cloud server, and the first connection identifier, where the first connection identifier contains a preset role number, the physical MAC fingerprint of the edge gateway, and the connection sequence number; Use the edge gateway to initiate a TCP three-way handshake to the target address composed of the IP address and port of the cloud server; If the TCP three-way handshake is successful, generate a first identity authentication request based on the username, password, and local IP address of the edge gateway, and the first connection identifier, and send it to the cloud server; If the verification result of the first identity authentication request is passed, perform secondary authentication with the cloud server; If the secondary authentication is passed, the establishment of the main TCP connection is completed.
3. The communication method for stadiums based on multiple TCP connections according to claim 2, characterized in that, Performing secondary authentication with the cloud server includes: Use the edge gateway to receive the encrypted message generated by the cloud server and decrypt the encrypted message to obtain the original data message; Use the edge gateway to modify the preset field in the original data message and encrypt it based on the modified data to obtain a second encrypted message; Use the edge gateway to send the second encrypted message to the cloud server.
4. The method for stadium communication based on multiple TCP connections according to claim 1, wherein After establishing the main TCP connection between the edge gateway and the cloud server, it further includes: Start a heartbeat mechanism to keep the main TCP connection alive.
5. The method for stadium communication based on multiple TCP connections according to claim 2, wherein Establishing a sub-TCP connection with the cloud server according to the sub-connection creation instruction includes: Parse the sub-connection creation instruction to obtain the role type of the sub-connection; Establish a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type.
6. The method for stadium communication based on multiple TCP connections according to claim 5, wherein Establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type includes: If the role type is a working connection, form a second connection identifier by combining the role number corresponding to the working connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway; Use the edge gateway to initiate a TCP three-way handshake to the target address composed of the IP address and port of the cloud server; If the TCP three-way handshake is successful, generate a second identity authentication request based on the username, password, and local IP address of the edge gateway, and the second connection identifier, and send it to the cloud server; If the verification result of the second identity authentication request is passed, perform secondary authentication with the cloud server; If the secondary authentication is passed, bind the protocol type corresponding to the role type to complete the establishment of the working TCP connection, which is used to transmit the control instructions sent by the cloud server.
7. The communication method for stadiums based on multiple TCP connections according to claim 5, characterized in that Establishing a corresponding sub-TCP connection between the edge gateway and the cloud server according to the role type further includes: If the role type is a proxy connection, compose a third connection identifier from the second role number corresponding to the proxy connection, the physical MAC fingerprint of the edge gateway, and the current TCP connection sequence number of the edge gateway; Initiate a TCP three-way handshake to the target address composed of the IP address and port of the cloud server using the edge gateway; If the TCP three-way handshake is successful, generate a third identity authentication request based on the username, password, and local IP address of the edge gateway, and the third connection identifier, and send it to the cloud server; If the verification result of the third identity authentication request is passed, perform secondary authentication with the cloud server; If the secondary authentication is passed, bind the protocol type corresponding to the role type to complete the establishment of the proxy TCP connection, which is used to transmit the HTTP requests sent by the cloud server.
8. The method for stadium communication based on multiple TCP connections according to claim 2, wherein , The physical MAC fingerprint is obtained by hashing the physical MAC address.
9. A stadium communication system based on multiple TCP connections, characterized in that, Includes: A main TCP connection establishment module, used to establish a main TCP connection between the edge gateway and the cloud server; A dynamic TCP connection establishment module, used to establish a sub-TCP connection with the cloud server according to the sub-connection creation instruction if the edge gateway receives the sub-connection creation instruction sent by the cloud server through the main TCP connection; An instruction pass-through module, used to receive the control instructions sent by the cloud server through the sub-TCP connection using the edge gateway, and pass through the control instructions to the target terminal hardware in the stadium; An instruction forwarding module, used to receive the HTTP requests sent by the cloud server through the sub-TCP connection using the edge gateway, and forward the HTTP requests to the target web service in the local area network where the edge gateway is located.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a stadium communication program based on multiple TCP connections. When the stadium communication program based on multiple TCP connections is executed by a processor, the steps of the stadium communication method based on multiple TCP connections according to any one of claims 1-8 are implemented.
Citation Information
Patent Citations
Data transmission method, device and system
CN110460641A
Acceleration method and device based on 5G network cloud service
CN115942433A
Agricultural image transmission system based on wireless communication and intelligent gateway
CN214256471U
Method and system for processing forged TCP packet
US20190020681A1