Centralized initialization method and system, electronic equipment, readable medium and program product
By deploying a high-density wireless access node array in the computer room and using device identification information for pre-authentication and automated configuration, the problems of low efficiency and safety hazards of equipment online are solved, and the rapid batch online of equipment and efficient and safe initialization process of equipment is realized.
Patent Information
- Application Number
- CN202510766228.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-08-26
AI Technical Summary
The existing equipment online method relies on physical connections and on-site operations, which are inefficient, cost-effective, error-prone, and have inconsistent configurations and safety risks.
By deploying a high-density wireless access node array in the computer room, pre-authentication and automated configuration issuance are achieved using device identification information, a secure communication tunnel is established, and concurrent initialization of multiple devices is performed.
It realizes rapid batch launch of equipment, reduces labor costs, improves efficiency, enhances system configuration consistency and security, and significantly reduces operation and maintenance complexity.
Smart Images

Figure CN120547601A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of communication networks and device management, and in particular to a device centralized initialization method, a device centralized initialization system, an electronic device, a computer-readable medium, and a computer program product. Background Art
[0002] With the continuous development of SD-WAN and IoT technologies, the number of devices that need to be brought online on the network is rapidly increasing. Efficiently bringing these devices online has become a key concern for operations and maintenance personnel. Common methods for bringing devices online include URL deployment and USB flash drive deployment. These methods have been widely used in practice and have significantly improved onboarding efficiency compared to traditional manual configuration methods. However, these methods still have significant limitations: they rely on individual physical connections or on-site technicians, resulting in low efficiency, high costs, and prone to errors. Summary of the Invention
[0003] Embodiments of the present disclosure provide a device centralized initialization method, a device centralized initialization system, an electronic device, a computer-readable medium, and a computer program product.
[0004] In a first aspect, an embodiment of the present disclosure provides a method for centralized device initialization, comprising: pre-storing identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices; receiving access requests from the multiple devices through a wireless access node array, and establishing secure communication tunnels with each device based on identity authentication; for each device, determining the initialization configuration file of the device according to its identification information, and sending the initialization configuration file to the device through the corresponding secure communication tunnel; and receiving initialization status information fed back by the multiple devices.
[0005] In some embodiments, identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices are pre-stored, including: for each device to be initialized: obtaining at least one of the media access control address (MAC address) and serial number of the device as identification information; associating the identification information with the initialization configuration file corresponding to the device; and storing the identification information and the corresponding initialization configuration file.
[0006] In some embodiments, identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices are pre-stored, including: for each device to be initialized: obtaining at least one of the media access control address and serial number of the device as identification information; generating a corresponding initialization configuration file based on the identification information and a preset initialization configuration template; and storing the identification information and the initialization configuration file.
[0007] In some embodiments, access requests from the multiple devices are received through a wireless access node array, and a secure communication tunnel is established with each device based on identity authentication, including: configuring a dedicated initialized access identifier; controlling a wireless access node array that supports a multi-device high-concurrency access protocol to broadcast the access identifier; responding to access requests initiated by the multiple devices based on the access identifier, performing two-way identity authentication based on their respective device-specific encryption certificates; and after the identity authentication is successful, establishing a secure communication tunnel with each device based on a temporary IP address obtained by each device.
[0008] In some embodiments, configuring a dedicated initialized access identifier and controlling the wireless access node array to broadcast the identifier includes: configuring a dedicated initialized service set identifier for the wireless access point array in the wireless access node array composed of a wireless access point array; and controlling the wireless access point array to broadcast the service set identifier.
[0009] In some embodiments, receiving the initialization status information fed back by the multiple devices includes: receiving at least one of initialization success information and initialization failure information fed back by each device, wherein the initialization success information includes a device-specific activation credential generated by the device.
[0010] In some embodiments, the method further includes: when receiving initialization failure information, classifying the initialization failure into transmission failure and non-transmission failure according to the cause of the initialization failure; for transmission failure, performing automatic retransmission or breakpoint resumption of the initialization configuration file; for non-transmission failure, generating a statistical list of devices that failed initialization and a manual intervention prompt.
[0011] In a second aspect, an embodiment of the present disclosure provides a centralized device initialization system, comprising: at least one wireless access node, configured to broadcast an access identifier dedicated to initialization and support concurrent access of multiple devices; multiple devices to be initialized, each device configured to access the wireless access node through the access identifier, establish a secure communication tunnel with a centralized management platform based on identity authentication, and receive an initialization configuration file matching its identification information through the tunnel; a centralized management platform, configured to store the identification information of multiple devices to be initialized and the initialization configuration files corresponding to each device; send the initialization configuration file corresponding to each device to the corresponding device through the secure communication tunnel; and receive initialization status information fed back by the device.
[0012] In some embodiments, the wireless access node is a wireless access point array supporting a multi-device high-concurrency access protocol, and the protocol includes IEEE 802.11ax.
[0013] In a third aspect, an embodiment of the present disclosure provides an electronic device, comprising: one or more processors; a memory on which one or more programs are stored, and when the one or more programs are executed by the one or more processors, the one or more processors implement the device centralized initialization method described in the first aspect of the embodiment of the present disclosure.
[0014] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processor, the device centralized initialization method described in the first aspect of the embodiment of the present disclosure is implemented.
[0015] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, including a computer program or instructions, which, when executed by a processor, implements the device centralized initialization method described in the first aspect of the embodiment of the present disclosure.
[0016] This disclosure provides a wireless network-based centralized device initialization method and system, enabling concurrent multi-device access, automatic configuration delivery, and initialization status feedback, effectively improving device deployment efficiency. By configuring a dedicated initialization network and secure communication tunnel, the security and configuration consistency of the data transmission process are guaranteed. A centralized management platform uniformly manages the configuration and authentication processes, significantly reducing manual intervention costs and operational complexity. Compared to traditional methods, this solution can improve the efficiency of large-scale device initialization by at least an order of magnitude. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is a flow chart of a method for centralized initialization of devices according to an embodiment of the present disclosure;
[0018] Figure 2This is a wireless local area network topology diagram of a device centralized initialization system according to an embodiment of the present disclosure;
[0019] Figure 3 is a timing diagram of the CPE device batch initialization process according to an embodiment of the present disclosure;
[0020] Figure 4 This is a flow chart of the centralized management platform of an embodiment of the present disclosure performing centralized management of initialization files;
[0021] Figure 5 is a schematic diagram of the composition of an electronic device according to an embodiment of the present disclosure;
[0022] Figure 6 The present invention is a block diagram of a device centralized initialization server according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0023] In order to enable those skilled in the art to better understand the technical solution of the present disclosure, the technical solution of the present disclosure is described in detail below with reference to the accompanying drawings.
[0024] Example embodiments will be described more fully hereinafter with reference to the accompanying drawings, but the example embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the scope of this disclosure to those skilled in the art.
[0025] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.
[0026] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0027] The terms used herein are used only to describe specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a," "an," and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise. It will also be understood that when the terms "comprising" and / or "made of" are used in this specification, the presence of the features, wholes, steps, operations, elements, and / or components is specified, but the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups thereof is not excluded.
[0028] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined as such herein.
[0029] In this disclosure, unless otherwise specified, the following technical terms should be understood as follows:
[0030] CPE (Customer Premises Equipment) refers to terminal network equipment deployed at the user side, usually provided by the service provider.
[0031] IPSec (Internet Protocol Security) is a secure communication protocol that runs at the network layer. It supports encryption and authentication of IP data packets and is used to build end-to-end or gateway-to-gateway secure tunnel connections.
[0032] A wireless local area network (WLAN) is a local wireless communication network based on the IEEE 802.11 series of standards, allowing devices to access the network within a limited range (usually <100m) via radio waves.
[0033] SSID (Service Set Identifier) is a unique string used to identify a specific WLAN network.
[0034] WPA3-Enterprise is the third-generation wireless security protocol enterprise version developed by the Wi-Fi Alliance, providing enterprise-level certification based on 192-bit encryption suite (Wi-Fi Alliance WPA3 TM Specification v1.0).
[0035] ECDSA (Elliptic Curve Digital Signature Algorithm) is a digital signature algorithm based on elliptic curve cryptography (NIST FIPS 186-5 standard).
[0036] TFTP (Trivial File Transfer Protocol) is a simplified file transfer protocol (RFC 1350) that uses UDP port 69 for small file transfers.
[0037] DHCP (Dynamic Host Configuration Protocol) is a network protocol used to dynamically allocate IP addresses, gateways, DNS, and other information in an IP network.
[0038] This paper proposes a new device online solution, which uses the WiFi network of the computer room to centrally initialize multiple network terminal devices, thereby achieving rapid batch online of devices, significantly improving efficiency, reducing costs and reducing human errors.
[0039] In the following description, CPE devices are used as a representative example of network terminal devices. It should be understood that network terminal devices may include, but are not limited to, CPE devices, SD-WAN gateway devices, edge computing nodes, industrial IoT terminals, and other network communication devices with wireless access and remote initialization capabilities. This disclosure is not limited to any specific device type.
[0040] Specifically, the CPE device initialization process mainly faces the following technical issues:
[0041] 1) Strong reliance on physical access: Existing solutions generally rely on connecting each CPE device to the configuration terminal one by one through wired connections for initialization, resulting in low deployment efficiency and cumbersome operations;
[0042] 2) Geographical limitations: CPE devices must be manually configured by technicians at the installation site, resulting in high labor and time costs, which is particularly significant in large-scale deployment scenarios.
[0043] 3) Version and configuration inconsistency risk: Traditional decentralized configuration methods may lead to software version differences and configuration inconsistencies between devices due to inconsistent operations or human oversight, affecting system stability and subsequent operation and maintenance management.
[0044] 4) Security risks: During on-site debugging and configuration, there is a risk of configuration data being leaked, especially when it comes to network access parameters or authentication information, where security issues are more prominent.
[0045] This paper proposes a centralized device initialization method based on a wireless local area network (WLAN), aiming to address technical issues such as high manual dependency, low configuration efficiency, poor security, and insufficient consistency in the online deployment of existing network terminal devices. By deploying a high-density wireless network access environment (such as WiFi) in the computer room, this method combines a device pre-authentication mechanism with an automated configuration distribution system to achieve automated, batch, and secure initialization of multiple WiFi-enabled network terminal devices, effectively reducing deployment labor costs, improving online deployment efficiency, and enhancing the consistency and controllability of system configuration.
[0046] The centralized initialization solution based on wireless local area network disclosed in the present invention mainly includes:
[0047] 1) Pre-configured wireless access node array: Configure a high-density wireless access point (AP) cluster supporting multiple SSIDs in the data center or at the deployment site;
[0048] 2) Automatic authentication module: implements pre-authentication mechanism based on the device’s serial number;
[0049] 3) Configuration distribution system: Build a configuration distribution engine that supports concurrent connection transmission.
[0050] Figure 1 This is a flowchart of a method for centralized initialization of devices according to an embodiment of the present disclosure.
[0051] First, refer to Figure 1 , an embodiment of the present disclosure provides a method for centralized device initialization, including:
[0052] S11, pre-storing identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices;
[0053] S12. Receive access requests from the multiple devices through a wireless access node array, and establish secure communication tunnels with each device based on identity authentication;
[0054] S13. For each device, determine an initialization configuration file of the device according to its identification information, and send the initialization configuration file to the device through the corresponding secure communication tunnel;
[0055] S14: Receive initialization status information fed back by the multiple devices.
[0056] In some embodiments, pre-storing identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices includes:
[0057] For each device to be initialized:
[0058] Obtaining at least one of a media access control address (MAC address) and a serial number of the device as identification information;
[0059] Associating the identification information with an initialization configuration file corresponding to the device;
[0060] The identification information and the corresponding initialization configuration file are stored.
[0061] In some embodiments, pre-storing identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices includes:
[0062] For each device to be initialized:
[0063] Obtaining at least one of a media access control address and a serial number of the device as identification information;
[0064] Generate a corresponding initialization configuration file according to the identification information and a preset initialization configuration template;
[0065] The identification information and the initialization configuration file are stored.
[0066] In the disclosed embodiment, the centralized management platform (such as a DC server) has the ability to centrally manage the device initialization configuration file. In order to realize the centralized initialization of devices based on the wireless access environment, first perform relevant configurations on the centralized management platform, including: pre-entering the identification information of the device to be initialized (such as MAC address, serial number, etc.) into the centralized management platform, which can support device identification based on a single or combined identification; pre-generate and store the corresponding initialization configuration file for each device to be initialized in the centralized management platform, and establish a binding relationship with the device's identification information for subsequent configuration distribution; the initialization configuration file refers to a standardized configuration file pre-created in the centralized management platform for the device online initialization process, which facilitates automated deployment and remote operation and maintenance. The configuration file can be generated through a configuration template, or it can be directly preset and stored in the configuration file library.
[0067] In the disclosed embodiments, the centralized management platform may not directly store one-to-one configuration files for all devices, but instead only stores initialization configuration templates preset based on parameters such as device type. After the device completes identity authentication and establishes a communication tunnel, the platform matches the corresponding initialization configuration template based on the device's identification information (such as type, model, MAC address, etc.), dynamically generates the device's initialization configuration file, and then transmits it to the target device via a secure communication tunnel.
[0068] In some embodiments, receiving access requests from the multiple devices through a wireless access node array and establishing secure communication tunnels with each device based on identity authentication includes:
[0069] Configure dedicated initialization access identifier;
[0070] Controlling a wireless access node array supporting a multi-device high-concurrency access protocol to broadcast the access identifier;
[0071] In response to access requests initiated by the multiple devices based on the access identifier, perform two-way identity authentication based on the respective device-specific encryption certificates;
[0072] After the identity authentication is successful, a secure communication tunnel is established with each device based on the temporary IP address obtained by each device.
[0073] In some embodiments, configuring a dedicated initialized access identifier and controlling the wireless access node array to broadcast the identifier includes:
[0074] Configuring a dedicated initialized service set identifier for the wireless access point array in the wireless access node array formed by the wireless access point array;
[0075] The wireless access point array is controlled to broadcast the service set identifier.
[0076] In the embodiments of the present disclosure, multi-device high-concurrency access protocols include but are not limited to: IEEE 802.11ax (Wi-Fi 6) and its evolved versions; and other wireless communication protocols that can achieve equivalent high-concurrency performance.
[0077] In some embodiments, the wireless access node array is composed of a wireless access point array; the access identifier is an SSID of a Wi-Fi network, and the SSID is used for logical isolation of a device-initialized network.
[0078] In an embodiment of the present disclosure, in order to support the centralized initialization deployment of multiple devices, the system constructs a high-density wireless access environment in a computer room or on-site environment. The environment is preferably composed of an array of wireless access nodes based on WiFi technology, such as a wireless access point cluster (AP Array) that supports the IEEE 802.11ax (WiFi 6) protocol, to meet the needs of high-concurrency device access and stable configuration transmission. Depending on the specific deployment requirements, the access environment can also be expanded to support wireless access infrastructure composed of other wireless communication protocols to adapt to the access density, communication bandwidth and network control requirements in different scenarios.
[0079] To achieve logical isolation between the device initialization network and the service network, an access identifier dedicated to initialization is configured in the wireless access environment. In a WiFi scenario, this identifier is a Service Set Identifier (SSID), which the platform binds to a logically isolated Virtual Local Area Network (VLAN). In non-WiFi networks, the access identifier can be replaced with a network identification mechanism supported by the target protocol. The access identifier is used to guide the device to access the initialization network and establish a secure communication link with the centralized management platform to ensure data security and deployment consistency during the initialization phase.
[0080] After the device accesses the initialized network, it will perform two-way identity authentication based on digital certificates with the centralized management platform to establish a trusted communication relationship. The identity authentication preferably adopts the WPA3-Enterprise framework, combined with the EAP-TLS protocol to complete the two-way verification of the device-side certificate and the platform-side certificate, ensuring the authenticity of the identities of both parties and the confidentiality of the communication process. The centralized management platform pre-generates a device-specific encryption certificate for each device, preferably using ECDSA (elliptic curve digital signature algorithm) to generate a certificate bound to the device identification information (such as MAC address, serial number), and completes the binding of the certificate and device identification information during the initialization preparation stage. After completing the two-way identity authentication, a secure communication tunnel based on the IPSec protocol is established. TLS, SSL VPN or other secure communication protocols with authentication and encryption capabilities can also be used. The specific choice can be flexibly determined based on actual deployment and product support.
[0081] The platform can centrally configure and distribute a dedicated initialization SSID to the wireless access node array, enabling unified access management for initialized devices. The physical deployment of the relevant wireless access nodes can be completed by operations and maintenance personnel, while network parameters such as SSID configuration and broadcast control can be remotely and uniformly set by the platform. After a device accesses the network by scanning the initialization SSID and completes identity authentication, the platform retrieves the corresponding initialization configuration file from the configuration file library based on its identification information and distributes it to the target device via the established secure communication tunnel. This configuration file is standardized initialization configuration data preset by the platform and corresponds one-to-one with the device identification information, ensuring parameter consistency and deployment correctness.
[0082] Those skilled in the art should understand that the protocol standards, authentication methods, communication encryption mechanisms and network identification forms of the wireless access environment can be flexibly configured according to actual applications. Any wireless access node array that has identity authentication capabilities and supports the establishment of independent secure communication links can be adapted to the centralized initialization scheme disclosed herein.
[0083] In some embodiments, receiving the initialization status information fed back by the multiple devices includes:
[0084] Receive at least one of initialization success information and initialization failure information fed back by each device,
[0085] The initialization success information includes a device-specific activation certificate generated by the device.
[0086] In some embodiments, the method further comprises:
[0087] When receiving initialization failure information, the failure is classified into transmission failure and non-transmission failure according to the cause of the initialization failure;
[0088] For transmission failures, perform automatic retransmission or breakpoint resume of the initialization configuration file;
[0089] For non-transmission failures, a statistical list of devices that failed to initialize and a manual intervention prompt are generated.
[0090] In some embodiments, the transmission class failure includes an interruption or timeout in the transmission of the initialization configuration file.
[0091] In some embodiments, the method further comprises:
[0092] After all devices are initialized, an initialization result statistical report is generated, including a list of successfully initialized devices and a list of failed devices and their corresponding failure reasons.
[0093] In the disclosed embodiment, after a device accesses the initialization network through a wireless access node array and completes bidirectional identity authentication based on a dedicated encryption certificate, the centralized management platform sends the bound initialization configuration file to it through the established secure communication tunnel. After the device successfully receives and applies the configuration file, it generates a device-specific activation credential and reports it to the centralized management platform, indicating that the device has completed initialization and can be included in subsequent unified management, such as configuration changes. Throughout the initialization process, the centralized management platform tracks the initialization status of each device in real time and classifies and compiles statistics on the initialization results, including the following processing mechanisms:
[0094] 1. Failure classification and automatic processing:
[0095] If the device reports initialization failure, the platform will classify and handle it according to the failure type;
[0096] For transmission failures (such as unstable wireless channels, transmission interruptions, timeouts, etc.), the platform supports automatic retry and breakpoint resumption mechanisms;
[0097] For non-transmission failures (such as configuration import errors, format mismatches, authentication failures, etc.), the platform will list the device in the exception list and prompt manual intervention.
[0098] 2. Statistical list and report generation:
[0099] The platform classifies all failed devices according to the reasons for failure and generates a statistical list of failed devices. After the initialization process of all devices is completed, the platform automatically generates an initialization status statistical report including a list of successful devices, a list of failed devices, and the corresponding failure type.
[0100] This mechanism achieves a shift from passive responsive configuration to active batch deployment through centralized and intelligent management of initialization configuration files and device status, significantly improving operation and maintenance efficiency and system deployment consistency. While ensuring security, it increases the initialization efficiency of large-scale device deployment by at least an order of magnitude.
[0101] Figure 2 This is a wireless local area network topology diagram of a device centralized initialization system according to an embodiment of the present disclosure.
[0102] Secondly, refer to Figure 2 , an embodiment of the present disclosure provides a centralized device initialization system, including:
[0103] at least one wireless access node configured to broadcast an initialization-specific access identifier and support concurrent access by multiple devices;
[0104] a plurality of devices to be initialized, each device being configured to access the wireless access node via the access identifier, establish a secure communication tunnel with the centralized management platform based on identity authentication, and receive an initialization configuration file matching its identification information via the tunnel;
[0105] The centralized management platform is configured to store identification information of multiple devices to be initialized and initialization configuration files corresponding to each device; send the initialization configuration file corresponding to each device to the corresponding device through the secure communication tunnel; and receive initialization status information fed back by the device.
[0106] In the embodiment of the present disclosure, Figure 2 As shown, this embodiment provides a centralized device initialization system based on a wireless local area network, whose topology includes:
[0107] The wireless access node array (wireless AP array) consists of multiple wireless APs supporting the IEEE 802.11ax protocol and is deployed in a dedicated initialization environment. It is configured with independent SSIDs to achieve logical isolation between the initialization network and the service network, providing high-density and high-concurrency wireless access capabilities.
[0108] The device to be initialized (CPE) includes multiple devices with WiFi access capabilities (such as CPE-1 to CPE-N). It accesses the network by scanning the initialization SSID and supports the following functions: automatic detection of local initialization status; bidirectional authentication based on the WPA3-Enterprise protocol; and establishment of IPSec secure tunnel communication.
[0109] The centralized management platform (DC server), deployed in the data center or on-site portable terminals, assumes core control responsibilities during the system initialization process. The DC server integrates the following functions: DHCP service, responsible for dynamically allocating temporary IP addresses to connected devices; Certificate Authority (CA), used to generate device-specific digital certificates for each device, implementing certificate-based two-way identity authentication; Configuration / Version Repository, used to store parameter configuration templates and operating system / firmware version files required for device initialization, supporting automatic matching and distribution by device type or serial number; Configuration Distribution Engine, responsible for distributing initialization configuration files to target devices, supporting breakpoint resuming and automatic retry of failed transfers.
[0110] A wireless communication link represents the wireless interaction path between a device and the platform. Devices connect to a wireless access node array via Wi-Fi, which then forwards data to the centralized management platform, enabling operations such as device access, identity authentication, configuration file distribution, and initialization completion status reporting.
[0111] Figure 3 This is a timing diagram of the CPE device batch initialization process in an embodiment of the present disclosure.
[0112] like Figure 3 As shown in the figure, the process involves the DC server, CPE device (CPE-n) and wireless access point (AP). The initialization process includes the following steps:
[0113] 1. Initialize wireless network identification and access
[0114] After being powered on, the DC server automatically scans the SSID of the target initialization network and completes its access to the initialization network.
[0115] After being powered on, the CPE device (such as CPE-n) automatically scans the initialization SSID and connects to the initialization network.
[0116] 2. Identity authentication and wireless networking
[0117] Use the WPA3-Enterprise authentication framework (or other digital certificate-based protocols) to complete two-way identity authentication between CPE, AP, and DC server to establish a trusted wireless network connection.
[0118] 3. Obtaining a temporary IP address
[0119] The CPE obtains a temporary IP address from the wireless AP through DHCP for subsequent communications.
[0120] 4. Establish a secure communication tunnel
[0121] The CPE establishes an encrypted tunnel with the DC server based on the temporary IP. Preferably, the tunnel is a secure communication channel established based on the IPSec protocol; other security protocols that support data encryption and identity authentication, such as TLS and SSL VPN, may also be used.
[0122] 5. Download and load configuration files
[0123] The CPE downloads an initialization configuration file from the DC server over a secure tunnel. This configuration file is generated by the centralized management platform based on device identification information (such as MAC address and serial number) and matched from a configuration template library. Once downloaded, the device automatically loads the configuration file and applies the initialization parameters.
[0124] 6. Activation certificate generation
[0125] The CPE generates a device-specific activation certificate, which serves as the basis for verifying the completion of initialization and subsequent management.
[0126] 7. Initialization completion report and confirmation
[0127] The CPE device sends an initialization completion notification to the DC server;
[0128] After receiving the notification, the platform records the initialization status and confirms that the device has completed the online process. The device can then enter the business network or perform further configuration.
[0129] Figure 4 This is a flow chart of the centralized management of initialization files by the centralized management platform (DC server) of an embodiment of the present disclosure.
[0130] like Figure 4 As shown in the figure, this process is the core step after the device accesses the platform through the wireless network, completes two-way identity authentication and establishes a secure communication channel. It mainly involves the search, transmission, loading and status feedback management of the initialization configuration file.
[0131] The following steps are involved:
[0132] 1. Initialization status detection and request initiation
[0133] The CPE device first locally checks its initialization status. If the status is determined to be "uninitialized," it initiates a request for an initialization configuration file from the DC server via a secure communication channel. The request message carries the device's unique identifier (such as its serial number), which the platform uses to identify the device and locate the corresponding initialization configuration file.
[0134] 2. Configuration file matching and preparation
[0135] After receiving the request, the DC server parses the device identification information (such as the serial number) in the message and matches the initialization configuration file bound to the identification in the pre-stored configuration file library. This configuration file is a standardized parameter template pre-stored by the platform during the initialization preparation phase.
[0136] 3. Configure file transfer
[0137] The DC server transmits the initialization configuration file to the target CPE device through the established secure communication tunnel. During the transmission process, the platform supports encrypted transmission and resumable download to ensure the integrity and reliability of file delivery.
[0138] 4. File reception and configuration loading
[0139] After receiving the initialization configuration file, the CPE device loads the file. After successfully loading the configuration, the device updates its local status to "Initialized" and generates a device-specific activation credential for subsequent platform management.
[0140] 5. Status reporting and recording
[0141] The CPE device reports the initialization completion status and the generated activation certificate to the DC server;
[0142] After receiving the device status feedback, the platform updates the device's initialization status record and archives it in the system initialization status database.
[0143] In the disclosed embodiment, the DC server serves as a centralized management platform and implements efficient device initialization management through the following mechanisms:
[0144] 1. Centralized configuration management
[0145] Maintain a unified configuration resource library; perform precise configuration matching and distribution based on the device's unique identifier (such as the serial number).
[0146] 2. Intelligent status monitoring
[0147] Real-time recording of initialization status (success / failure); automatic classification of failure causes (transmission interruption, configuration verification error, etc.); support for automatic retry and manual intervention dual modes.
[0148] 3. Automated operation and maintenance processing
[0149] Trigger corresponding processing for different failure types: if transmission fails, automatically resume the transmission; if there is a configuration error, generate an error report and alarm;
[0150] Output statistical reports (including success rate, failure classification, etc.).
[0151] Figure 5It is a schematic diagram of the composition of an electronic device according to an embodiment of the present disclosure.
[0152] Thirdly, refer to Figure 5 , an embodiment of the present disclosure provides an electronic device, comprising:
[0153] One or more processors 501;
[0154] A memory 502 storing one or more programs, which, when executed by one or more processors, enables the one or more processors to implement the device centralized initialization method according to the first aspect of the embodiments of the present disclosure;
[0155] One or more I / O interfaces 503 are connected between the processor and the memory and are configured to implement information exchange between the processor and the memory.
[0156] Among them, the processor 501 is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory 502 is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) 503 is connected between the processor 501 and the memory 502, and can realize information interaction between the processor 501 and the memory 502, including but not limited to a data bus (Bus), etc.
[0157] In some embodiments, the processor 501 , the memory 502 , and the I / O interface 503 are connected to each other via a bus 504 , and further connected to other components of the computing device.
[0158] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the device centralized initialization method described in the first aspect of the embodiment of the present disclosure.
[0159] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, including a computer program or instructions, which, when executed by a processor, implements the device centralized initialization method described in the first aspect of the embodiment of the present disclosure.
[0160] Figure 6 The present invention is a block diagram of a device centralized initialization server according to an embodiment of the present disclosure.
[0161] Sixth aspect, refer to Figure 6 , an embodiment of the present disclosure provides a device centralized initialization server, including:
[0162] A configuration and version repository 601 is configured to pre-store identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices;
[0163] The access management module 602 is configured to receive access requests from the plurality of devices through the wireless access node array and establish a secure communication tunnel with each device based on identity authentication;
[0164] The configuration sending module 603 is configured to determine, for each device, an initialization configuration file of the device according to its identification information, and send the initialization configuration file to the device through the corresponding secure communication tunnel;
[0165] The state management module 604 is configured to receive the initialization state information fed back by the multiple devices, and perform classification processing and statistical output.
[0166] In some embodiments, the configuration and version repository 601 includes:
[0167] a first identification information acquisition submodule configured to acquire, for each device to be initialized, at least one of a media access control address and a serial number of the device as identification information;
[0168] A configuration association submodule configured to associate the identification information with an initialization configuration file corresponding to the device;
[0169] The first storage management submodule is configured to store the identification information and the corresponding initialization configuration file.
[0170] In some embodiments, the configuration and version repository 601 includes:
[0171] a second identification information acquisition submodule configured to acquire, for each device to be initialized, at least one of a media access control address and a serial number of the device as identification information;
[0172] A configuration file generating submodule is configured to generate a corresponding initialization configuration file according to the identification information and a preset initialization configuration template;
[0173] The second storage management submodule is configured to store the identification information and the initialization configuration file.
[0174] In some embodiments, the access management module 602 includes:
[0175] An identifier configuration submodule configured to configure a dedicated initialized access identifier;
[0176] a broadcast control submodule, configured to control the array of wireless access nodes supporting a multi-device high-concurrency access protocol to broadcast the access identifier;
[0177] an identity authentication submodule, configured to respond to access requests initiated by the multiple devices based on the access identifiers and perform two-way identity authentication based on the respective device-specific encryption certificates;
[0178] The tunnel establishment submodule is configured to establish a secure communication tunnel with each device based on the temporary IP address obtained by each device after the identity authentication is successful.
[0179] In some embodiments, the identifier configuration submodule further includes:
[0180] an SSID configuration unit configured to configure a dedicated initialized service set identifier (SSID) for the wireless access point array in the wireless access node array constituted by the wireless access point array;
[0181] The broadcast control submodule further includes:
[0182] The SSID broadcast control unit is configured to control the wireless access point array to broadcast the service set identifier.
[0183] In some embodiments, the state management module 604 includes:
[0184] a status information receiving submodule, configured to receive at least one of initialization success information and initialization failure information fed back by each device;
[0185] The initialization success information includes a device-specific activation certificate generated by the device.
[0186] In some embodiments, the device centralized initialization means further comprises:
[0187] A failure type classification module is configured to classify the initialization failure into a transmission failure or a non-transmission failure according to the cause of the initialization failure when receiving the initialization failure information;
[0188] A transmission failure processing module is configured to automatically retransmit or resume the initialization configuration file in response to a transmission failure;
[0189] The abnormal alarm module is configured to generate a statistical list of initialized failed devices and a manual intervention prompt for non-transmission failures.
[0190] In order to enable those skilled in the art to more clearly understand the technical solutions provided by the embodiments of the present disclosure, the device centralized initialization method provided by the embodiments of the present disclosure is described in detail below through specific examples:
[0191] Example 1
[0192] This embodiment is applied to batch initialization of SD-WAN edge devices (CPE) in an enterprise data center. The specific process is as follows:
[0193] Environmental preparation:
[0194] A wireless AP array supporting IEEE 802.11ax is deployed in the computer room, with a dedicated SSID configured and bound to an independent VLAN to isolate the initialization network from business traffic. The centralized management platform (DC server) is deployed in a portable server and integrates DHCP services, a certificate authority (CA), a configuration template library, and security protocol support.
[0195] Initialization process:
[0196] 1) Multiple SD-WAN CPE devices (supporting WiFi) automatically scan and initialize SSID after powering on and access the wireless network environment;
[0197] 2) The device completes two-way authentication with the management platform using the pre-configured certificate via the WPA3-Enterprise EAP-TLS protocol; a temporary IP address is assigned and a communication link is established;
[0198] 3) Each device establishes an encrypted tunnel with the DC server through the IPSec protocol. The platform matches the device serial number and issues a preset initialization configuration file;
[0199] 4) The device receives and loads the configuration, generates and reports a dedicated activation certificate after initialization is completed;
[0200] 5) The platform records the initialization completion status and incorporates the equipment into a unified operation and maintenance management platform.
[0201] Exception handling: Automatic retry (up to 3 times) when transmission fails; trigger an alarm when configuration verification fails and record it in the operation and maintenance work order system.
[0202] This disclosure aims to simplify the equipment management and online work of operation and maintenance personnel, and is particularly suitable for the automated deployment of large-scale CPE equipment. It involves the following technical features:
[0203] A device initialization method based on a wireless network includes: implementing concurrent authentication, configuration file distribution and deployment status verification of multiple CPE devices through a pre-established wireless network environment, thereby achieving an efficient, unified and automated device online process.
[0204] The key technical point of this disclosure is to provide a centralized initialization method for network terminal devices based on a wireless network. This method includes, through a pre-deployed array of wireless access nodes, enabling automatic access to multiple devices with wireless access capabilities, two-way authentication based on device identification, and the concurrent issuance and automatic application of initialization configuration files. After initialization is complete, the status results are fed back to a centralized management platform, thereby achieving zero-touch deployment and closed-loop status management of batch devices. Preferably, the authentication method is based on device certificates, and the configuration files are dynamically generated by the centralized management platform based on preset templates.
[0205] The device initialization method disclosed herein can bring the following beneficial effects:
[0206] 1) Significantly Improved Deployment Efficiency: This feature supports simultaneous initialization and configuration of over 200 CPE devices. Actual testing has shown that overall deployment efficiency is over five times higher than with traditional device-by-device configuration, significantly reducing operation and maintenance time.
[0207] 2) Enhanced system security: Adopting the principle of "Zero-Touch Provisioning" (ZTP) technology, the system eliminates manual intervention through automated processes, reduces the security risks of configuration leaks or errors caused by human operations, and improves the overall stability and security of the system.
[0208] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0209] Example embodiments have been disclosed herein, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.
Claims
1. A method for centralized device initialization, comprising: Pre-storing identification information of a plurality of devices to be initialized and initialization configuration files corresponding to each of the plurality of devices; Receive access requests from the multiple devices through a wireless access node array, and establish secure communication tunnels with each device based on identity authentication; For each device, determine the initialization configuration file of the device according to its identification information, and send the initialization configuration file to the device through the corresponding secure communication tunnel; Receive initialization status information fed back by the multiple devices.
2. The device centralized initialization method according to claim 1, wherein: Pre-storing identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices, including: For each device to be initialized: Obtaining at least one of a media access control address and a serial number of the device as identification information; Associating the identification information with an initialization configuration file corresponding to the device; The identification information and the corresponding initialization configuration file are stored.
3. The device centralized initialization method according to claim 1, wherein: Pre-storing identification information of multiple devices to be initialized and initialization configuration files corresponding to each of the multiple devices, including: For each device to be initialized: Obtaining at least one of a media access control address and a serial number of the device as identification information; Generate a corresponding initialization configuration file according to the identification information and a preset initialization configuration template; The identification information and the initialization configuration file are stored.
4. The device centralized initialization method according to claim 2 or 3, wherein: Receiving access requests from the multiple devices through a wireless access node array and establishing secure communication tunnels with each device based on identity authentication, including: Configure dedicated initialization access identifier; Controlling a wireless access node array supporting a multi-device high-concurrency access protocol to broadcast the access identifier; In response to access requests initiated by the multiple devices based on the access identifier, perform two-way identity authentication based on the respective device-specific encryption certificates; After the identity authentication is successful, a secure communication tunnel is established with each device based on the temporary IP address obtained by each device.
5. The device centralized initialization method according to claim 4, wherein: Configuring a dedicated initialized access identifier and controlling the wireless access node array to broadcast the identifier includes: Configuring a dedicated initialized service set identifier for the wireless access point array in the wireless access node array formed by the wireless access point array; The wireless access point array is controlled to broadcast the service set identifier.
6. The device centralized initialization method according to claim 5, wherein: Receiving initialization status information fed back by the multiple devices, including: Receive at least one of initialization success information and initialization failure information fed back by each device, The initialization success information includes a device-specific activation certificate generated by the device.
7. The device centralized initialization method according to claim 6, wherein: The method further comprises: When receiving initialization failure information, the failure is classified into transmission failure and non-transmission failure according to the cause of the initialization failure; For transmission failures, perform automatic retransmission or breakpoint resume of the initialization configuration file; For non-transmission failures, a statistical list of devices that failed to initialize and a manual intervention prompt are generated.
8. A centralized device initialization system, comprising: at least one wireless access node configured to broadcast an initialization-specific access identifier and support concurrent access by multiple devices; a plurality of devices to be initialized, each device being configured to access the wireless access node via the access identifier, establish a secure communication tunnel with the centralized management platform based on identity authentication, and receive an initialization configuration file matching its identification information via the tunnel; A centralized management platform configured to store identification information of multiple devices to be initialized and initialization configuration files corresponding to each device; Sending the initialization configuration file corresponding to each device to the corresponding device through the secure communication tunnel; and receiving initialization status information fed back by the device.
9. The centralized device initialization system according to claim 8, wherein: The wireless access node is a wireless access point array that supports a multi-device high-concurrency access protocol, and the protocol includes IEEE 802.11ax.
10. An electronic device comprising: one or more processors; A memory having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the device centralized initialization method according to any one of claims 1 to 7.
11. A computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method for centralized initialization of devices according to any one of claims 1 to 7 is implemented.
12. A computer program product, comprising a computer program or instructions, wherein when the computer program or instructions are executed by a processor, the method for centralized initialization of devices according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
A system and a method for realizing high-speed interconnection and intercommunication based on SDN and NFV technologies
CN109743244A
Network equipment, network management equipment and network equipment zero configuration opening system and method
CN112333026A
Equipment configuration method and device, equipment and storage medium
CN112491603A
Zero-touch-provisioning (ZTP) initialization method and device, computer equipment and storage medium
CN113472581A
Data transmission channel establishment method and device, computer equipment and storage medium
CN114039812A