Message transmission method and device, electronic equipment and computer storage medium

By introducing the MDP transmission interface into SSDP and selecting appropriate transmission protocols and encryption mechanisms, the unreliable and insecure UDP transmission issues are resolved, and efficient, secure, and flexible group management of device discovery and service management is achieved.

CN120583065BActive Publication Date: 2025-10-17INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511066801.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-17
Estimated Expiration
2045-07-31

AI Technical Summary

Technical Problem

In large-scale intelligent campuses, UDP-based SSDP message transmission has unreliability and security issues, making it difficult to meet the reliability, security, and group management requirements in device discovery and service discovery scenarios.

Method used

The Managed Discovery Protocol (MDP) is used to encapsulate the transmission interface. By selecting transmission protocols with different security levels (such as TCP and UDP) for message transmission and encrypting the message information, flexible application of device group management and grouping strategies can be achieved.

Benefits of technology

It improves the security, reliability and flexibility of device discovery and service management, and meets the device discovery and service management needs in the complex network environment of large-scale intelligent campuses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120583065B_ABST
    Figure CN120583065B_ABST
Patent Text Reader

Abstract

The application provides a message transmission method and device, electronic equipment and computer storage medium, which can be applied to the technical fields of computers, data transmission and information security. The message transmission method comprises the following steps: in response to receiving a first message from a first device, determining message information matched with the first message, wherein the message information comprises receiving device information and a message type, and the message type comprises a type for managing a device group composed of multiple devices; calling a transmission interface, determining a transmission mode for transmitting the message information according to the message type, and transmitting the message information to a receiving device matched with the receiving device information through the transmission mode; wherein the transmission mode comprises a first transmission mode using different transmission protocols and a second transmission mode, the security level of the transmission protocol used by the first transmission mode is higher than that of the transmission protocol used by the second transmission mode; and the transmission interface is further used for encrypting the message information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical fields of computer, data transmission and information security, and particularly relates to a message transmission method and device, electronic equipment and computer storage medium. BACKGROUND

[0002] With the continuous development of computer technology, automatic discovery and communication between multiple devices in a local area network or a server cluster are very important. Simple Service Discovery Protocol (SSDP) is an application layer protocol used for discovering and publishing devices and services in a local area network or a server cluster.

[0003] However, the current SSDP transmits messages based on a simple User Datagram Protocol (UDP) to realize device discovery and communication. However, in actual application processes, such as large intelligent parks, the message transmission based on UDP is difficult to meet the security, reliability and isolation of message transmission between multiple devices. SUMMARY

[0004] In view of the above problems, the present application provides a message transmission method and device, electronic equipment and computer storage medium.

[0005] According to a first aspect of the present application, a message transmission method is provided, comprising: in response to receiving a first message from a first device, determining message information matched with the first message, wherein the message information comprises receiving device information and a message type, and the message type comprises a type for managing a device group composed of multiple devices; calling a transmission interface, determining a transmission mode for transmitting the message information according to the message type, and transmitting the message information to a receiving device matched with the receiving device information through the transmission mode; wherein the transmission mode comprises a first transmission mode using different transmission protocols and a second transmission mode, the security level of the transmission protocol used by the first transmission mode is higher than that of the transmission protocol used by the second transmission mode; and the transmission interface is further used for encrypting the message information.

[0006] The second aspect of the present application provides a message transmission device, comprising: a determination module configured to determine message information matched with a first message in response to receiving the first message from a first device, wherein the message information comprises receiving device information and a message type, and the message type comprises a type for managing a device group composed of a plurality of devices; a calling module configured to call a transmission interface, determine a transmission manner for transmitting the message information according to the message type, and transmit the message information to a receiving device matched with the receiving device information through the transmission manner; wherein the transmission manner comprises a first transmission manner and a second transmission manner using different transmission protocols, and the security level of the transmission protocol used by the first transmission manner is higher than that of the transmission protocol used by the second transmission manner; and the transmission interface is further configured to encrypt the message information.

[0007] The third aspect of the present application provides an electronic device, comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method.

[0008] The fourth aspect of the present application further provides a computer-readable storage medium having a computer program or instructions stored thereon, wherein the computer program or instructions are executed by a processor to implement the steps of the method.

[0009] The fifth aspect of the present application further provides a computer program product comprising a computer program or instructions, wherein the computer program or instructions are executed by a processor to implement the steps of the method. BRIEF DESCRIPTION OF DRAWINGS

[0010] The above and other objects, features and advantages of the present application will become more apparent from the following description of embodiments of the present application, taken in conjunction with the accompanying drawings.

[0011] Figure 1 An application scenario diagram of the message transmission method, device, equipment, medium and program product according to the embodiments of the present application is shown.

[0012] Figure 2 A schematic diagram of a protocol architecture according to the embodiments of the present application is shown.

[0013] Figure 3 A flowchart of the message transmission method according to the embodiments of the present application is shown.

[0014] Figure 4 A scenario diagram of digital certificate verification based on MDP according to the embodiments of the present application is shown.

[0015] Figure 5 A scenario diagram of device group creation and device group joining based on MDP according to the embodiments of the present application is shown.

[0016] Figure 6 A scenario diagram of device registration based on MDP is shown according to an embodiment of the present application.

[0017] Figure 7 A scenario diagram of service request based on MDP is shown according to an embodiment of the present application.

[0018] Figure 8 A scenario diagram of extended message transmission based on MDP for custom message type and service information is shown according to an embodiment of the present application.

[0019] Figure 9 A scenario diagram of encryption and decryption using symmetric encryption algorithm and asymmetric encryption algorithm is shown according to an embodiment of the present application.

[0020] Figure 10 A scenario diagram of retransmission based on MDP for TCP transmission is shown according to an embodiment of the present application.

[0021] Figure 11 A scenario diagram of MDP based on UDP transmission is shown according to an embodiment of the present application.

[0022] Figure 12 A structure block diagram of a message transmission apparatus is shown according to an embodiment of the present application.

[0023] Figure 13 A block diagram of an electronic device suitable for implementing the message transmission method is shown according to an embodiment of the present application. DETAILED DESCRIPTION

[0024] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. It should be understood, however, that the description which follows is merely illustrative and is not intended to limit the scope of the present application. In the following detailed description of embodiments of the present application, numerous specific details are set forth in order to provide a thorough understanding of the present application. However, it will be apparent to one skilled in the art that one or more embodiments of the present application can be practiced without these specific details. In other instances, well-known structures and functions have not been described in detail in order to avoid obscuring aspects of the present application.

[0025] The terms used herein are merely used to describe specific embodiments and are not intended to limit the present application. The terms "include" and "have" and the like used herein indicate the presence of the described features, steps, operations, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, or components.

[0026] All terms used herein, including technical and scientific terms, have the meanings commonly understood by one of ordinary skill in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted as having a meaning that is consistent with the context of the specification, and should not be interpreted in an idealized or overly formal way.

[0027] In the technical solutions of the present application, the user information (including but not limited to user personal information, user image information, user equipment information such as location information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of related data comply with relevant laws, regulations and standards, necessary security measures are taken, do not violate public order and good customs, and appropriate operation portals are provided for users to choose authorization or refusal.

[0028] For service discovery and device discovery scenarios, the SSDP underlying layer transmits messages through UDP. In the device discovery phase, devices periodically send notification messages (NOTIFY) containing their own device information and service descriptions to a specific multicast address. The message format complies with the HyperText Transfer Protocol (HTTP) implemented based on UDP, i.e., the HTTPU protocol format, which carries device name, type, service address, and other key information in text form. Receiving devices capture notification messages through the multicast address, thereby discovering new devices in the network. For example, in a home network, a smart TV will automatically send a NOTIFY message to the multicast address after first accessing the network, and other SSDP-enabled devices in the home (such as smart speakers and smart routers) can receive this message and learn about the existence of the smart TV.

[0029] When a device needs to find a specific service, it sends a search request message (M-SEARCH), which contains the type of the target service or other filtering conditions. Upon receiving the M-SEARCH message, devices in the network that provide matching services will reply with a response message (HTTP 200 OK) carrying detailed descriptions of the devices and services. In the SSDP scenario, devices describe their device information and service details by providing standardized text files, such as Extensible Markup Language (XML) files. For example, in an office network, a computer needs to find a network printing service. It sends an M-SEARCH message, and printers in the office area that support printing services will send response messages to the computer. Based on the information in the response message, the computer can connect to the printer to perform printing tasks.

[0030] However, the UDP protocol used by SSDP is inherently connectionless, eliminating the need for a handshake between the sending and receiving devices before message transmission, and eliminating the need to establish a dedicated logical connection channel. Consequently, message transmission is prone to packet loss, out-of-order messaging, or duplication, leading to unreliable message transmission. Furthermore, the lack of a security verification mechanism makes it difficult to verify the identity of the device sending SSDP messages, making them vulnerable to interception and devices unable to handle SSDP amplification attacks, limiting the security of message transmission. This problem becomes increasingly prominent in large-scale network environments.

[0031] For example, large intelligent campuses with numerous network devices typically utilize large-scale network environments. For the simple unicast and multicast methods described above, when devices perform periodic service notifications, reliable message transmission cannot be guaranteed. This can result in notification messages sent by some devices not being fully received by other devices, or being duplicated or out of order during transmission. This can lead to incomplete device discovery or delayed service status updates, impacting the normal use and collaborative operation of devices and services within the network. Furthermore, in complex network environments, the packet loss rate for UDP-based messages can reach 10%-20%, severely hindering efficient network operation. For SSDP amplification attacks, attackers can fabricate source Internet Protocol (IP) addresses to send SSDP query requests to a large number of reflectors, causing these reflectors to flood the campus with search request messages, resulting in network congestion and even denial of service for devices within the campus.

[0032] Furthermore, in real-world applications, large-scale intelligent campuses with numerous network devices often require group management. This allows for differentiated management by differentiating devices, and also for security reasons, allows for device and service isolation. However, current SSDP messaging makes it difficult to implement flexible device grouping, as well as differentiated access control, service control, and bandwidth allocation within these groups.

[0033] To this end, the present application proposes a message transmission method, comprising: in response to receiving a first message from a first device, determining message information matched with the first message, wherein the message information comprises receiving device information and a message type, and the message type comprises a type for managing a device group composed of multiple devices; calling a transmission interface, determining a transmission manner for transmitting the message information according to the message type, and transmitting the message information to a receiving device matched with the receiving device information through the transmission manner; wherein the transmission manner comprises a first transmission manner and a second transmission manner using different transmission protocols, and the security level of the transmission protocol used by the first transmission manner is higher than that of the transmission protocol used by the second transmission manner; the transmission interface is further used for encrypting the message information. By encapsulating a new Managed Discovery Protocol (MDP) into the transmission interface, after receiving the first message of the first device and determining the message information matched with the first device, the transmission interface can be called to automatically select the transmission manner of the message information to be transmitted according to the message type in the message information, and to perform encrypted transmission, so as to make up for the shortcomings of SSDP, and to meet the security and reliability of message transmission between multiple devices in the device discovery and service discovery scenarios; for the message type for managing a device group composed of multiple devices, the transmission interface based on MDP can provide corresponding group management functions, so as to improve the security, reliability and group management flexibility of device discovery and service management in the network.

[0034] Figure 1 An application scenario diagram of the message transmission method, apparatus, device, medium and program product according to an embodiment of the present application is shown.

[0035] As shown in Figure 1 The application scenario according to this embodiment can include multiple first terminal devices 101, second terminal devices 102 and third terminal devices 103. The network 104 is a medium for providing communication links between the first terminal devices 101, the second terminal devices 102 and the third terminal devices 103. The network 104 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc. The first terminal devices 101, the second terminal devices 102 and the third terminal devices 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers and desktop computers, etc. They can also be network devices such as gateways, routers and servers.

[0036] It should be noted that the first terminal device 101, the second terminal device 102, and the third terminal device 103 can all serve as a sending device or a receiving device to realize message transmission between devices. Thus, the message transmission method provided in the embodiments of the present application can be executed by the first terminal device 101, the second terminal device 102, and the third terminal device 103. Correspondingly, the message transmission apparatus provided in the embodiments of the present application can be arranged in the first terminal device 101, the second terminal device 102, and the third terminal device 103. It should be understood that Figure 1 The number of terminal devices and networks in FIG. 1 is merely illustrative. According to the implementation needs, there can be any number of terminal devices and networks.

[0037] Figure 2 A schematic diagram of a protocol architecture according to an embodiment of the present application is shown.

[0038] In the embodiments of the present application, the MDP integrated with the transmission interface adopts a layered architecture, which includes, from top to bottom, an application layer, a transmission layer, a network layer, a data link layer, and a physical layer, as shown in FIG. 2. Figure 2 As shown in FIG. 2, two adjacent layers can communicate with each other.

[0039] Application layer: responsible for processing device and service discovery, registration, deregistration, group management, and other application logic. The application layer can interact with application software, generate corresponding application layer messages, and package and send the application layer messages to the transmission layer. The application layer can also parse and process the messages of the application software, invoke corresponding function modules according to the business requirements, and process them. For example, a user sends a device query request through a network management platform, the application layer receives the request, constructs an MDP query message according to the query conditions, and sends it.

[0040] Transmission layer: used to realize hybrid transmission, which can transmit messages through the first transmission mode and the second transmission mode. For example, the transmission protocol used by the first transmission mode can be the Transmission Control Protocol (TCP), and the transmission protocol used by the second transmission mode can be UDP. The first transmission mode and the second transmission mode are referred to as TCP and UDP, respectively. The transmission layer is responsible for message packaging, unpackaging, and conversion and forwarding between different transmission protocols, selects a suitable transmission protocol according to different message types and priorities, and realizes efficient and reliable message transmission. For example, the transmission layer can utilize the reliability of TCP to ensure the accurate transmission of critical messages (such as registration, deregistration, group management, and other messages of devices), and ensure the stability of network connection; at the same time, UDP is reserved for the fast sending of device discovery messages to improve the discovery efficiency.

[0041] Network layer: responsible for routing and addressing in the network, that is, routing MDP messages, determining the forwarding path of MDP messages, and ensuring that messages can be accurately delivered to the target service in the receiving device or receiving device. The network layer can select the optimal transmission path for the message in combination with network topology information and routing strategy, support device discovery and service interaction in a multi-network environment, and realize device and service communication across subnets.

[0042] Data link layer: used for media access control (Media Access Control, MAC) processing, such as MAC address resolution, frame construction and disassembly, etc., to ensure correct transmission of data on physical media. The data link layer can also perform error detection and correction on received data to ensure data transmission accuracy, and access control to the transmission medium to avoid data conflicts.

[0043] Physical layer: the lowest layer of physical media transmission, used for physical media interaction for message transmission.

[0044] The first message, message information, etc. involved in the message transmission method provided in the application are MDP messages, and the transmission mode can be TCP or UDP. The format of the MDP message can include a message header and a message body. The message header includes message type and receiving device information, and the message body includes specific content and fields corresponding to the message type. In addition, the encryption and decryption of the message information refer to the encryption and decryption of the information in the message body.

[0045] For example, the message header can include the following contents.

[0046] Protocol version information, which can be a version number (Version), has a length of 4 bits, and is used to ensure that the sending device and the receiving device use compatible protocol versions for communication.

[0047] Message type (Type): 8 bits, defines the type of the message, such as device discovery type (DiscoverRequest), device discovery response type (DiscoverResponse), device registration type (Register), device deregistration type (Unregister), device group creation type (CreateGroup), device group joining type (JoinGroup), device group exit type (LeaveGroup), etc. The receiving device can select the corresponding processing logic according to the message type.

[0048] Message ID (Message ID): 32 bits, used to uniquely identify an MDP message, facilitating message confirmation, retransmission, and matching operations. In the same interaction process, the sent and received messages have the same Message ID.

[0049] Source IP: 32 bits or 128 bits, following Internet Protocol version (IPv) such as IPv4 or IPv6, used to identify the IP address of the device sending the message, for the routing and backhaul of the message.

[0050] Destination IP: 32 bits or 128 bits, used to identify the IP address of the message receiving device, for broadcast or multicast messages of UDP, it can be a broadcast address or a multicast address.

[0051] Source Port: 16 bits, used to identify the application port number of the message sending device, for distinguishing different MDP application instances and services.

[0052] Destination Port: 16 bits, used to identify the application port number of the message receiving device, to ensure that the message is correctly delivered to the target application.

[0053] Length: 16 bits, indicating the total length of the entire MDP message (including the message header and the message body) in bytes, for message parsing and integrity checking.

[0054] Checksum: 16 bits, used to detect whether the message has errors during transmission, the receiving device calculates the checksum of the received message and compares it with the checksum in the message header, if they are inconsistent, the message is discarded and retransmission can be requested. For example, the checksum can be a hash value or message digest calculated by a hash algorithm.

[0055] The following will be based on Figure 1 the scenario described, through Figures 3-11 a detailed description of the message transmission method of the embodiments of the present application.

[0056] Figure 3 A flowchart of a message transmission method according to an embodiment of the present application is shown. As Figure 3 shown, the embodiment 300 includes operation S310~operation S320.

[0057] In operation S310, in response to receiving a first message from a first device, message information matching the first message is determined, wherein the message information includes receiving device information and message type.

[0058] In the message transmission scenario, a certain device can act as a receiving device of a message and also as a sending device of another message. For example, a first device sending a first message is a sending device of the first message, and a current device receiving the first message is a receiving device. For message information to be sent, the current device can also act as a sending device of the message information.

[0059] The first message has a specific function, such as notification, service request, device discovery, device registration, etc. The message information matched with the first message refers to message information sent to the receiving device after processing the first message. For example, for a first message having multiple functions, the current device, in response to receiving the first message, invokes a service of the current device according to the first message, obtains a service result, and generates message information according to the service result.

[0060] The receiving device information represents attribute information of the receiving device of the message information, for example, the attribute information can include at least one of the following: device name, device type, IP address, MAC address, port address, device description, etc. For the receiving device, the IP address in the attribute information can be used as a target IP address in the message header, and other information can be set in the message body to facilitate transmission of the receiving device message.

[0061] The message type defines the type of the message, indicating the function of the message information. For example, the function indicated by the message type can be the same as or different from the first message. For example, the message type can be a type indicating functions such as notification, service request, device discovery, device registration, etc.

[0062] The message type can include a type for managing a device group composed of multiple devices to implement device group management in the device and service discovery scenario. The message type can include types such as device group creation type, device group joining type, device group exit type, etc. Multiple devices in a large intelligent park can form multiple device groups. For example, 5 devices can form a device group, and another 3 devices can form another device group, or 3 devices of the 5 devices and another 3 devices form a new device group. Multiple device groups usually have multiple permissions and multiple management strategies.

[0063] For example, in an embodiment, the first message is used to request a service in the current device. The current device, in response to receiving the first message, processes information in the first message according to the service indicated by the first message, and obtains a corresponding service result. At this time, the receiving device is the first device, the message information can include the service result, the message type can be a feedback of the service request, and the receiving device information can be the IP address of the first device, etc.

[0064] The transmission interface is invoked in operation S320, a transmission manner for transmitting the message information is determined according to the message type, and the message information is transmitted to the receiving device matched with the receiving device information through the transmission manner.

[0065] According to the embodiments of the present application, the transmission interface is packaged with a new MDP, and multiple functions corresponding to the MDP can be realized by invoking the transmission interface. The embodiments of the present application can realize autonomous selection of a transmission manner according to a message type in the message information in the SSDP scenario by invoking the transmission interface, instead of relying on only one transmission manner. For example, by invoking the transmission interface, a transmission manner matched with the message type can be determined according to a mapping relationship between the message type and the transmission manner in the MDP, and the message information is transmitted to the receiving device through the transmission manner.

[0066] The MDP supports message transmission through a first transmission manner and a second transmission manner using different transmission protocols, that is, the message information can be transmitted to the receiving device through the first transmission manner or the second transmission manner. It can be understood that for message information of multiple message types, the first transmission manner can be determined to be used for transmission according to part of the message types, and the second transmission manner can be determined to be used for transmission according to another part of the message types.

[0067] The security level of the transmission protocol used by the first transmission manner is higher than the security level of the transmission protocol used by the second transmission manner, and the security level of the transmission protocol is determined according to the characteristics of the transmission protocol. For example, if a transmission protocol adopts more device verification operations or handshake operations, the security level of the transmission protocol is higher. For example, the transmission protocol used by the first transmission manner can be TCP, and the transmission protocol used by the second transmission manner can be UDP.

[0068] The transmission interface is also used for encrypting the message information, that is, the MDP also supports encrypting the message information, which solves the problem that the SSDP does not support encryption, and further improves the security of message transmission.

[0069] In one embodiment, the transmission interface can determine whether to encrypt the message information according to the transmission manner; and at least one encryption algorithm can be used to encrypt the message information.

[0070] It should be noted that the first device can also invoke the transmission interface to determine a transmission manner of the first message, such as TCP or UDP, according to a message type contained in the first message, as the sending device of the first message.

[0071] In the embodiments of the present application, the current device can automatically select the transmission mode of the message information to be transmitted according to the message type in the message information by calling the transmission interface encapsulating the new MDP after receiving the first message of the first device and determining the message information matched with the first device, and perform encrypted transmission, so as to meet the security and reliability of message transmission between multiple devices in the SSDP scenario. For the message type including the message type used for managing the device group composed of multiple devices, the MDP-based transmission interface can also provide corresponding group management function to improve the security, reliability and group management flexibility of device discovery and service management in the network.

[0072] It is considered that the SSDP only supports sending notification messages to a specific multicast address through multicast, which can be accessed by all devices to synchronize messages. However, in a large intelligent park, the devices / services between different buildings may not need to be synchronized, and the management strategies of the devices / services in different buildings are different. Therefore, the SSDP has weak group management capability for devices and services, and cannot meet the requirements of flexible device group division and differentiated strategy deployment in a complex network, and the group management efficiency is low.

[0073] In the embodiments of the present application, the current device can receive the first message of the first device for managing the device group, and determine the message information matched with the first message, and then send the message information for managing the device group to the receiving device by calling the transmission interface, so that the device group management function is applicable between the first device, the current device and the receiving device.

[0074] In one specific embodiment, the first message includes a device group creation message, and in response to receiving the first message from the first device, the message information matched with the first message is determined, including: in response to receiving the device group creation message from the first device, parsing the device group creation message to obtain the group information of the first device group to be created, wherein the group information includes at least one of the following: identification information, description information, device range, access authority, group management strategy; generating a group record of the first device group according to the group information of the first device group; determining that the message type matched with the device group creation information is a new group broadcast type; determining at least one device in a second device group to which the current device belongs except the current device; wherein the message information includes: the group record, the new group broadcast message, and the receiving device information indicating that the at least one device is the receiving device.

[0075] For example, the identification information includes a Universally Unique Identifier (UUID) and a name of the group. The device scope can be a condition of a device allowed to join the device group, or a service configuration supported by a device in the device group, etc. The service configuration can be a type of service allowed to be published and discovered in the group, a service priority, etc. The description information is used to represent service functions, management functions, etc. of the device group. The access right can be which role or which device attribute supported by a device in the device group is allowed to access. The group management policy can include an access control policy for adjusting the access right, a service discovery policy for adjusting the device scope, and other management policies, such as a data transmission policy, a bandwidth limitation policy, etc. The group information is used to create a device group with specific attributes and rules in the MDP, and to realize organization and management of devices and services. For a CreateGroup message, the message body contains the group information.

[0076] Each device group can have one or more group management policies. For example, for an enterprise network of a certain floor, all the research and development devices of a “research and development group” as a device group can be set with a higher network bandwidth priority and specific service access rights, and the research and development devices are limited to access only internal research and development servers and related test tools. All the market devices of a “market group” as a device group are allocated different network resources and access rights. When a device joins a corresponding device group, the group management policy of the device group can be automatically applied, fine network management and resource allocation based on the device group are realized, and the security and management efficiency of the network are improved.

[0077] In one embodiment, the first device can be provided with a network management platform, and a user can interact with the network management platform of the first device to specify group information of a first device group to be created. The first device encapsulates the group information of the first device group into a device group creation message according to the interaction operation, and at this time, the message type is a device group creation type. The first device determines a transmission mode matched with the device group creation type by calling a transmission interface, and transmits the device group creation message to the current device through the transmission mode. The current device parses the device group creation message in response to receiving the device group creation message of the first device, and obtains the group information of the first device group.

[0078] For example, a user can specify that identification information of a created device group is A, description information is a power supply device group of all devices of a current floor, a device scope is all power supply devices of the current floor, an access right is a power supply service personnel, and a group management policy can be a lower network bandwidth priority.

[0079] The current device can be a group management server, after receiving the group information of the first device group, the group record in a predetermined form can be generated according to the group information in the first device group, and the group record of the first device group can be created in the corresponding group management database. For example, the form of the group record can match the group management database. In addition, the group management database can also store the related configuration information and member list of the device group, and provide data support for subsequent group management operations.

[0080] In the case of the first message being a device group creation message, in order to ensure that the device group can be created in sequence and allow multiple devices to automatically join the device group, the group information of the first device group needs to be broadcast to multiple devices, so the message type in the message information can be directly determined as a new group broadcast type.

[0081] Since the current device is a group management server, and the group management server can belong to at least one second device group at the same time, in order to realize the management function of multiple devices in the at least one second device group, in order to ensure that the devices allowed to join the first device group can find and join the newly created first device group, at least one device in the at least one second device group except the current device can be determined as a receiving device according to the member list of the at least one second device group. It can be understood that the information of the at least one device can be pre-stored in the group management server, and when the at least one device is determined, the information of the at least one device can be directly obtained, that is, the receiving device information.

[0082] Therefore, the message information matched with the device group creation message includes: a group record, a new group broadcast type, and receiving device information indicating that the at least one device is a receiving device, so as to broadcast to the at least one device that the first device group has been created, and each device can determine whether to join the first device group according to its own attribute information. For example, each device can determine whether to join the first device group according to the device type, the department to which it belongs, the geographical location, etc., and the device range in the group record, and if it needs to join the first device group, it can actively send a device group join message to the group management server.

[0083] In the embodiments of the present application, by receiving the device group creation message and determining the at least one device to be notified by means of the at least one second device group to which the group management server belongs, the situation that the device cannot join the first device group due to not receiving the message that the first device group has been created is avoided, thereby realizing the device group creation function in the group management scenario.

[0084] In another specific embodiment, multiple group management servers can exist in the large intelligent park at the same time, and each group management server is used for managing one or more device groups. The device range can also include a designated group management server, so that the first device can send a device group creation message to the designated group management server, and broadcast that the first device group has been created in at least one second device group to which the designated group management server belongs, without broadcasting to all devices, which not only avoids the situation that the first device group cannot be joined due to not receiving the message that the first device group has been created, but also realizes notification at the granularity of multiple device groups.

[0085] In another specific embodiment, the first message includes at least one of the following: a device group join message and a device group exit message; determining the message information matched with the first message in response to receiving the first message from the first device includes: in response to receiving the first message from the first device, parsing the first message to obtain digital certificate information of the first device and a third device group; for the device group join message, verifying the digital certificate information of the first device and the device join condition of the third device group respectively to obtain group change information for the third device group; for the device group exit message, verifying the digital certificate information of the first device to obtain the group change information for the third device group; determining that the message type matched with the first message is a device group change type; wherein the message information includes: the group change information, the device group change type, and the receiving device information indicating that at least one device in the third device group is a receiving device.

[0086] For a certain created third device group, the first device can actively apply to join or exit the third device group, for example, in the case that the first device needs to be offline for maintenance, the first device can actively apply to exit the third device group; in the case that the first device is online, the first device can actively apply to join the third device group. For the entire large intelligent park, because the online and offline situations of multiple first devices are different, the joining and exiting of multiple first devices to the entire third device group is dynamically changed, and the devices contained in the third device group are also changed.

[0087] For the first device with device group join or device group exit demand, the first device can call the transmission interface, determine the transmission mode according to the device group join type or the device group exit type, and based on the transmission mode, encapsulate the message information including the digital certificate information of the first device, the third device group and the message type into the device group join message or the device group exit message and send it to the current device. In addition, if the device group has a role corresponding to the permission, the device group join message can also include the role requested when joining the device group.

[0088] The current device may be a group management server. In response to receiving a device group join message or a device group exit message, the current device may parse the device group join message or the device group exit message to obtain the digital certificate information of the first device and the third device group. It should be noted that the device group join message or the device group exit message may refer to the third device group using identification information.

[0089] Regarding the device group join message, since the third device group has a corresponding group management policy, if the first device's identity and device group joining conditions are not verified, the first device's risk could expose all devices in the third device group to risk. Therefore, the current device not only verifies the digital certificate information but also locally obtains the device joining conditions for the third device group and verifies whether the first device meets these conditions.

[0090] For example, digital certificate information includes the device's identity, validity period, and digital signature. Furthermore, when using an asymmetric encryption algorithm to encrypt messages, the digital certificate also includes the device's public key. Before connecting to the network, each MDP device must apply for and install a digital certificate from a Certificate Authority (CA).

[0091] The method for verifying digital certificate information includes: obtaining a verification public key that matches the identity information; comparing the public key in the digital certificate information with the verification public key to determine whether they are consistent, thereby obtaining a first verification result; verifying the issuing authority of the digital signature based on the digital signature to obtain a second verification result; and verifying the validity of the digital certificate information based on the validity period to obtain a third verification result. If the first, second, and third verification results all pass, the verification result of the digital certificate information is determined to be passed; otherwise, if any verification result fails, the verification result of the digital certificate information is determined to be failed. For example, if the public key and the verification public key are consistent, the first verification result is determined to be passed; otherwise, it is failed. By verifying the compliance of the issuing authority of the digital signature, if the verification passes, the second verification result is determined to be passed; otherwise, it is failed. If the validity of the digital certificate information passes, the third verification result is determined to be passed. In this embodiment, through a two-way authentication mechanism based on digital certificate information, identity authentication is not only performed on the first device, but also further authentication is performed when joining a third device group, thereby avoiding security risks caused by device identity fraud.

[0092] Figure 4 FIG1 shows a scenario diagram of digital certificate verification based on MDP according to an embodiment of the present application. Figure 4As shown, taking the first device as device A and the current device as device B as an example. When device A accesses the network, device A applies for digital certificate information to the CA, and after the application is successful, device A installs the digital certificate information locally. Device A sends a message carrying digital certificate information, and device B receives the message carrying digital certificate information. The message carrying digital certificate information can be of multiple message types. Device B verifies the digital certificate information, including verifying the digital signature, the validity period, and the public key respectively, and determines whether all three verifications pass. If all three verifications pass, the identity authentication passes, a trusted connection is established, and the corresponding operation of the message is performed; if any verification fails, the connection is rejected, and a log is recorded.

[0093] The device joining condition can be determined according to the group information provided when the device group is created. For example, the device joining condition can be that the first device meets the device range of the third device group.

[0094] In this embodiment, in the case where the verification results of the digital certificate information of the first device and the device joining condition of the third device group are both passed, the first device is allowed to join the third device group, the first device can be added to the member list of the third device group, and group change information indicating that the third device group has changed is generated, such as the group change information being “the third device group adds the first device”.

[0095] For the device group exit message, the digital certificate information of the first device is verified to obtain the group change information of the third device group. The verification of the digital certificate information is as described above. In the case where the verification result of the digital certificate information is passed, the first device is allowed to exit the third device group, the first device can be deleted from the member list of the third device group, and group change information indicating that the third device group has changed is generated, such as the group change information being “the third device group exits the first device”.

[0096] For the device group joining message and the device group exit message, not only the first device and the group management service need to change the group information of the device group, but also the other devices in the third device group need to update the member list to ensure that the information of the multiple devices in the third device group is consistent. Therefore, the message information includes: group change information, device group change type, and receiving device information indicating that at least one device in the third device group is a receiving device. The group management server can broadcast the message information to at least one device in the third device group to dynamically update the member list of the device.

[0097] In the embodiments of the present application, the group management server (current device) can ensure that the first device does not appear identity impersonation and meets the joining conditions of the third device group by receiving the device group joining message and verifying the digital certificate information of the first device and the device joining information of the third device group, through a double guarantee mechanism, while dynamically managing the device group and ensuring the security of the device group. The group management server can ensure that the first device does not appear identity impersonation by receiving the device group exit message and verifying the digital certificate information of the first device, while dynamically managing the device group and ensuring the security of the device group. In addition, by taking at least one device in the third device group as a receiving device, the data consistency of at least one device in the third and device group can be further ensured.

[0098] Figure 5 A scenario diagram for creating a device group and joining a device group based on MDP according to an embodiment of the present application is shown.

[0099] As shown in Figure 5 , an administrator creates a device group 1 through a network management platform and specifies detailed group information, a server of the network management platform constructs a device group creation message (CreateGroup) message, transmits the CreateGroup message to the group management server through TCP, the group management server creates a group record locally, and broadcasts a new group broadcast type message to a plurality of devices in a device group 2 to which the group management server belongs, such as sending a group creation notification message (GroupNotification) to device A, device B, device C…, to notify the creation of a new device group 1, and device A, device B, device C can decide whether to apply to join the device group 1 according to their own situation.

[0100] When device C needs to join an existing device group 1, a device group joining (JoinGroup) message is constructed and sent to the group management server through TCP. The group management server parses the JoinGroup message and verifies the digital certificate information and the device joining conditions of the device group 1 respectively. If the verification is passed, device C is added to the member list, and other devices in the device group 1 are notified, and the joining is completed. For example, a joining device group change type message such as a success response message (JoinResponse) is sent to device C, and at the same time, the joining of other devices in the device group 1 is notified through TCP, the member list in the group is updated, and the joining is completed. If the verification fails, the group management server sends a joining failure response message to device C through TCP, and returns the failure reason.

[0101] Similarly, when device C needs to leave device group 1, a device group leave (LeaveGroup) message is sent to the group management server through TCP, the group management server removes device C from the group member list of device group 1, and notifies other devices in the group to update the member list through TCP, and the group leave process is completed.

[0102] In still another embodiment, the first message comprises a registration message; determining the message information matched with the first message comprises: in response to receiving the registration message from the first device, parsing the registration message; in a case where the parsed registration message comprises registration information of the first device, group information of a fourth device group and digital certificate information of the first device, verifying the digital certificate information of the first device and a device joining condition of the fourth device group respectively to obtain a registration result of the first device, wherein the fourth device group is a device group that the first device requests to join when registering; determining that the message type matched with the registration message is a registration result notification type; generating the message information according to the registration result, wherein the message information comprises the registration result, the registration result notification type, and receiving device information indicating that at least one device in the fourth device group and the first device are receiving devices.

[0103] In a case where the first device is a new device, the new device needs to complete initialization when accessing the network. The initialization process comprises: when the device starts, first load local information, including attribute information of the device, key files, etc., then start the MDP protocol stack, initialize each protocol layer module, establish a connection with the network layer and the transport layer, and prepare to start the reception and processing of MDP messages. After initialization, in order to be able to provide services or participate in group management in the network, the first device will actively perform device registration.

[0104] The fourth device group refers to a device group that the device needs to join by default when registering.

[0105] For example, the first device generates a registration (Register) message, and the Register message usually comprises detailed registration information, such as attribute information of the device, a list of services provided, a security level, extensible service attributes, etc. In addition, for the first device that has completed initialization, the Register message further comprises digital certificate information issued by the CA; for the first device that needs to join a certain device group by default, the group information of the device group that needs to be joined is further included in the Register message. The above-mentioned digital certificate information, group information and registration information can all be located in the message body of the registration message.

[0106] For the first device, the transmission mode corresponding to the Register message can be determined by calling the transmission interface, and the Register message is sent to the current device through the transmission mode.

[0107] The current device can be a group management server, which parses the received Register message after receiving the Register message. In the case that the Register message includes the registration information of the first device, the digital certificate information and the group information of the fourth device group, the group management device not only needs to authenticate the first device, but also needs to verify whether the first device can join the fourth device group. The verification method of the digital certificate information and the device joining condition is as described above, and will not be repeated here.

[0108] In the case that the verification results of the digital certificate information and the device joining condition of the fourth device group are both passed, it is determined that the registration result is passed, and the registration information of the first device is stored locally in the group management server, and the first device is added to the fourth device group; otherwise, in the case that any verification result is not passed, it is determined that the registration result is not passed. Whether the registration result is passed or not, the devices in the fourth device group and the first device need to be notified, that is, the message type matched with the registration message is the registration result notification type.

[0109] For example, in the case that the registration result is passed, the message information such as a registration success response (RegisterResponse) indicating that the registration is passed is broadcasted to the devices in the fourth device group and the first device, to notify at least one device in the fourth device group to update the member list, and to notify the first device that the registration is successful and update the member list of the first device. In the case that the registration result is not passed, the message information (registration failure response Registerfault indicating failure) can also include the failure reason, such as authentication failure, digital certificate invalidation, network policy restriction, etc.

[0110] It can be understood that in the case that the Register message does not include the group information of the fourth device group, only the digital certificate information of the first device can be verified, and the registration result is determined to be passed if the verification is passed, and the registration information of the first device is stored locally in the group management server; otherwise, the registration result is determined to be not passed.

[0111] In the embodiments of the present application, the group management server receives the registration message, and in the case that the registration message includes the group information of the fourth device group, the digital certificate information of the first device and the device joining information of the fourth device group are verified synchronously, the verification of device group joining is completed synchronously when the device is registered, which not only realizes the dynamic joining of the device group at the time of registration, but also ensures that the first device will not appear identity impersonation and guarantees the security of the device group.

[0112] It should be noted that the above-mentioned first device group, second device group, third device group, fourth device group are only used as a substitute for describing the first message with multiple functions, and in essence, the above-mentioned four device groups can be the same or different, which is determined according to the actual situation.

[0113] Figure 6 A scenario diagram of device registration based on MDP is shown according to an embodiment of the present application. As shown, a device P can construct and send a registration message by calling a transmission interface, wherein the device P sends the registration message to a group management server through TCP. If the registration message includes group information, the group management server verifies the digital certificate information and device joining conditions; if the verification is passed, the group management server stores the registration information locally and updates the member list, and then returns a registration success response to the device P; otherwise, the group management server directly returns a failure reason. Figure 6

[0114] According to an embodiment of the present application, the transmission manner for transmitting the message information is determined according to the message type, including: determining the first transmission manner as the transmission manner for transmitting the message information in a case where the message type is determined as the first type; and determining the second transmission manner as the transmission manner for transmitting the message information in a case where the message type is determined as the second type.

[0115] The security level of the first type is higher than that of the second type. For example, the first type can be a type with a higher security level, and thus the first transmission manner with a higher security level, such as TCP, can be used for transmission to ensure the security of the message transmission process; the second type can be a type with a lower security level, and the second transmission manner with a lower security level, such as UDP, can be used for transmission to ensure the quickness of the message transmission.

[0116] In the embodiment of the present application, the corresponding transmission manner is selected according to the message type by calling the transmission interface, which can autonomously determine the security level of the message information according to the message type of the message to be transmitted, so as to determine the transmission manner adapted to the security level, and meet the security transmission requirement or quickness transmission requirement of the message information. For the current device, since the current device can send various message information to multiple devices, the corresponding transmission manner is determined for each message information by calling the transmission interface, which can balance the security and quickness of the overall message transmission of the current device.

[0117] According to an embodiment of the present application, the first type includes at least one of the following: a device registration type, a registration result notification type, a device deregistration type, a deregistration result notification type, a data transmission type, a backup data recovery type, a network exception handling type, a fault handling type, and a type for managing a device group composed of multiple devices. The type for managing a device group composed of multiple devices includes one of the following: a device group creation type, a new group broadcast type, a device group change type, a device group joining type, and a device group exiting type. The second type includes at least one of the following: a device discovery type, a device survival type, a backup notification type, a backup verification type, a network state type, and a fault alarm type.​

[0118] In the embodiments of the present application, the function of managing the device group is added in the service discovery and device discovery scenarios through the transmission interface. The management function of the device group is to improve the security and isolation of the interaction between the device and the service. Therefore, in order to avoid the leakage or loss of the message related to the management of the device group, for the types used for managing the device group and the registration and deregistration related types that may involve the change of the device group, the first transmission mode with higher security level can be used for transmission. In the case of implementing the fine management of the device group function, the security of the information transmission is further improved. For the types related to the fault and abnormal scenarios, the first transmission mode is used for transmission, which can ensure the security of the fault and abnormal analysis and processing. For the device discovery, service discovery or alarm notification related types, the second transmission mode is used for transmission to improve the speed of notification.

[0119] In one embodiment, the transmission mode of the first message and the message information is the same, and both can use the first transmission mode.

[0120] Taking the device group creation message, the device group joining message, the device group exit message and the registration message (including the group information of the fourth device group) included in the first message as an example, in the case that the first message is the registration message, the device group joining message, the device group exit message and the device group creation message respectively, the message type of the first message is the device registration type, the device group joining type, the device group exit type and the device group creation type respectively. The first device can transmit the first message through the first transmission mode. After the current device determines the message information corresponding to the above first message respectively, according to the new group broadcast type, the device group change type and the registration result notification type in the message information, it is determined that the first transmission mode is used to transmit the above message information.

[0121] In addition, the deregistration type and the deregistration result notification type are similar to the registration type and the registration result notification type respectively. For example, in the case that the first message includes the deregistration message, the group management server receives the deregistration message from the first device and parses the deregistration message. The parsed deregistration message includes the group information of the fifth device group to which the first device belongs and the digital certificate information of the first device. In the case that the verification result of the digital certificate information of the first device is passed, it is determined that the deregistration result is passed, and the registration information of the first device is deleted in the group management server. It is determined that the message type is the deregistration result notification type, and the message information includes the deregistration result, the deregistration result notification type, and the receiving device information indicating that at least one device in the fifth device group and the first device are receiving devices.

[0122] In one embodiment, the first message and the message information can also use the second transmission mode. For example, for the first message and the message information of the device discovery type and the device survival type, the second transmission mode is used.

[0123] For example, in an active discovery scenario, when a first device needs to discover other devices in the network or services within the device, a first message of the device discovery type, such as a DiscoverRequest message, is constructed, parameters such as a discovery range, attribute information of a requested device, and the like are set. The discovery range, attribute information of the requested device, and the like can all be used as a message body of the DiscoverRequest message. By calling a transmission interface, transmission to the current device (including a group management server and other devices) is selected through UDP. After the other devices in the network receive the DiscoverRequest message, whether the discovery condition is met is determined according to the attribute and the current authorization state of the device itself. If the discovery condition is met, a message information of the device discovery type, such as a DiscoverResponse message, is generated. The DiscoverResponse message includes attribute information of the current device, service information, a message type indicating the device discovery type, and a receiving device message (usually the first device sending the DiscoverRequest), and the message information is returned to the first device through UDP. After the first device collects multiple DiscoverResponse messages, the attribute information and the service information of the device are sorted and analyzed, the local device list and the service list are updated, and the device discovery process is completed.

[0124] In a passive discovery scenario: the first device can periodically send a first message of the device alive type, such as a device alive notification message (AliveNotification), through a UDP groupcast mode to inform other devices of the alive state, device information, and service information of the first device. After the current device receives the AliveNotification message, the corresponding information in the local device list and the service list is updated, and a message information of the device alive type is generated. The message information can include an update result of the device list and the service list, and receiving device information indicating that the first device is a receiving device. The current device can also return the message information to the first device through UDP. Through the passive discovery mechanism, the timeliness and accuracy of the update of the device list and the service list are ensured.

[0125] In another embodiment, the first message and the message information are transmitted through different transmission modes. For example, the first message uses a first transmission mode, and the message information uses a second transmission mode; or the first message uses the second transmission mode, and the message information uses the first transmission mode.

[0126] In actual application, for a message transmission process supporting a single transmission mode, such as an existing SSDP, only the quickness of message transmission can be met, but the security cannot be met, and the security and the quickness cannot be considered.

[0127] In the embodiments of the present application, the devices that transmit messages based on MDP all support the first transmission mode and the second transmission mode, such as UDP and TCP, so that the sending and receiving of messages do not need to follow a single transmission mode, but can select a transmission mode different from the first message to transmit the message information according to the message type in the message information, so as to simultaneously meet the security and speed of a message transmission process.

[0128] According to the embodiments of the present application, the devices in a large intelligent park can all be servers and are configured in a master-backup architecture, such as a one master and three backup mode. When registering devices or registering services to the master server of the group management server, other devices can synchronize the registration information to multiple backup servers, improve the reliable storage of the registration information, and avoid the loss of device information or the unavailability of services due to single point failure. When the master server fails, the backup server can quickly take over and continue to provide group management services and device discovery functions, ensuring the continuous and stable operation of the network.

[0129] According to the embodiments of the present application, the first device includes a data production device, and the first message includes a backup notification message transmitted through the second transmission mode; in response to receiving the first message from the first device, determining the message information matched with the first message includes: in response to receiving the backup notification message from the data production device, parsing the backup notification message to obtain the data volume of the data to be backed up and the estimated transmission time length; determining that the message type matched with the backup notification message is a data transmission type; determining the data transmission time information according to the data volume, the estimated transmission time length and the running state of the current device; wherein the message information includes the data transmission time information, the data transmission type and the receiving device information indicating that the data production device is a receiving device, the message information is transmitted through the first transmission mode, and the first transmission mode is determined according to the data transmission type.

[0130] For example, in the data backup scenario, the first device can be a data production device, such as a master server of a group management server, which can generate a variety of data, and the current device can be a backup device of the data production device, such as a backup server.

[0131] For the data production device, when the key business data is generated, such as financial transaction records, medical image data, etc., this part of data can be regarded as data to be backed up, and a backup notification message is quickly sent to the current device through UDP. The backup notification message can include brief information such as the unique identifier of the data to be backed up, the data volume and the estimated transmission time length, and the unique identifier can be a timestamp, a business serial number, etc.

[0132] The current device receives and parses the backup notification message to obtain the data volume and the estimated transmission duration. The running state of the current device includes a load state. If the current device is in a high load state, the data volume is higher than a first threshold value in the high load state and / or the estimated transmission duration is higher than a second threshold value in the high load state, it is determined that the data transmission time information is to delay a first predetermined duration for transmission of the data to be backed up. Otherwise, it is determined that the data transmission time information is to delay a second predetermined duration for transmission of the data to be backed up. The first predetermined duration is greater than the second predetermined duration. If the current device is in a low load state, the data volume is higher than a third threshold value in the low load state and / or the estimated transmission duration is higher than a fourth threshold value in the low load state, it is determined that the data transmission time information is to delay a third predetermined duration for transmission of the data to be backed up. Otherwise, the data transmission time information is determined according to the current time and the estimated transmission duration, that is, the current time can be used for transmission of the data to be backed up. Thus, the current device determines to use TCP according to the data transmission type, and returns the data transmission time information to the data production device, so that the data production device transmits the data to be backed up at the time indicated by the data transmission time information. For example, the data production device can encapsulate the data to be backed up as a first message of the data transmission type, and transmit it to the current device through TCP.

[0133] In the embodiments of the present application, since the data generated by the data production device is service-related data with a high security level, the safety and reliability of the data cannot be guaranteed through UDP. However, the backup notification message for the data does not include the data itself, but only includes brief information of the data for negotiating the backup time. Thus, the embodiments of the present application transmit the backup notification message through UDP, and the current device determines the data transmission time information according to the backup notification message and transmits it through TCP, which not only improves the safety of the data transmission time information, but also improves the efficiency of negotiating the transmission time. In addition, since the attacker cannot determine the specific transmission time of the backup data, the safety of transmitting the data to be backed up is further improved.

[0134] According to the embodiments of the present application, the first device includes a backup device, and the first message includes a backup data recovery message transmitted through a first transmission mode. In response to receiving the first message from the first device, message information matched with the first message is determined, including: in response to receiving the backup data recovery message from the backup device, the backup data is parsed from the backup data recovery message; the message type matched with the backup data recovery message is determined as a backup verification type; a first hash value of the backup data is determined by using a hash algorithm; wherein the message information includes the first hash value, the backup verification type, and receiving device information indicating that the backup device is a receiving device, and the message information is transmitted through a second transmission mode, so that the backup device determines the integrity of the backup data according to the first hash value and a second hash value, and the second transmission mode is determined according to the backup verification type.

[0135] For example, in a backup recovery scenario, the first device can be a backup device, such as a backup server of a group management server, and the current device can be a data production device, such as a master server of the group management server.

[0136] When it is necessary to recover the backup data from the backup device, the first device encapsulates the backup data into a data transmission type backup data recovery message, and transmits the backup data recovery message through TCP. In the recovery process, the current device receives and parses the backup data recovery message to obtain the backup data. To ensure the integrity of the backup data, the current device also calculates a first hash value of the backup data in real time by using a hash algorithm. After the backup data recovery is completed, the current device sends a backup verification type message information (such as a recovery data verification request) to the first device through UDP. The first device calculates a second hash value of the locally stored backup data by using the hash algorithm and stores the second hash value in the first device. After receiving the first hash value transmitted by the current device, the first device determines whether the backup data is complete by comparing the first hash value and the second hash value. If the backup data is complete, the first device can feed back that the backup data is complete through UDP. Otherwise, the first device can determine the missing backup data according to the first hash value and the second hash value, and retransmit the missing backup data through TCP.

[0137] In the embodiments of the present application, the backup data is transmitted through TCP for security, and the first hash value based on the backup data is transmitted through UDP for rapidity, so as to balance the security and rapidity of the backup data in the data recovery scenario.

[0138] According to the embodiments of the present application, the first message includes a network state message transmitted through the second transmission mode; in response to receiving the first message from the first device, determining the message information matched with the first message includes: in response to receiving the network state message from the first device, parsing the network state message to obtain network state information, wherein the network state information includes at least one of the following: processor usage, memory occupation state, network interface traffic, network delay duration, packet loss rate of the first device in a target period, bandwidth fluctuation amplitude; detecting the network state information to obtain a detection result; in a case where it is determined that the detection result is abnormal, determining that the message type matched with the network state message is a network exception handling type; generating first request information for obtaining running information of the first device; wherein the message information includes the first request information, the network exception handling type, and receiving device information indicating that the first device is a receiving device; the message information is transmitted through the first transmission mode, and the first transmission mode is determined according to the network exception handling type.

[0139] For example, in the fault and abnormal scenario, the first device can be a router, a switch, a terminal device, etc., and the current device can be a group management server, which is used to obtain the network state information of each first device in the device group. The target period in the network state information can be a period with a fixed time interval from the current time, such as the packet loss rate in the target period can be the packet loss rate 5s before the current time.

[0140] The first device can periodically generate network state messages of the network state type, and transmit the network state messages to the current device through UDP, such as generating and transmitting every 5s. The group management server receives and parses the network state messages to obtain the network state information, and detects the network state information to obtain a detection result. If the detection result is normal, no message can be fed back; if the detection result is abnormal, the running information of the first device can be obtained by means of the management and analysis capability of the current device, and abnormal analysis and abnormal processing can be performed. After the current device determines that the message type matched by the network state message is the network abnormal processing type, a transmission interface can be called, the message information can be transmitted to the first device by TCP according to the network abnormal processing type, so that the first device feeds back the running information according to the first request information in the message information, for example, the first request information can be a storage address of the running information of the first device, and the running information can include a load state, a network connection list, a process running condition, etc. Similarly, the first device can transmit the running information of the first device to the current device through TCP, so that the current device analyzes the reason for the network abnormality according to the running information and processes it.

[0141] In the embodiments of the present application, since the network state information of the first device in the device group may be abnormal due to the fact that an attacker constructs a large number of requests, at this time, the first device may have a security risk, therefore, the embodiments of the present application use the group management server to quickly obtain the network state information from the first device through UDP, and transmit the running information through TCP when detecting the abnormality, so as to realize the rapid detection and safe analysis of the network abnormality, and further realize the safe running and rapid recovery of the first device in the device group. In addition, since the running information of the first device usually includes relatively detailed information, once it is leaked, the first device will be completely exposed in a non-safe environment, and the risk of being attacked will increase dramatically, therefore, transmitting the running information through TCP can further ensure the security of the first device.

[0142] According to the embodiments of the present application, the network state information is detected to obtain a detection result, including at least one of the following: comparing the network state information with at least one network state threshold to obtain the detection result, wherein the network state threshold includes: a processor usage rate threshold, a memory occupation state threshold, a network interface traffic threshold, a network delay duration threshold, a packet loss rate threshold of the first device in a target period, a bandwidth fluctuation threshold, and a comprehensive weighted threshold; inputting the network state information into a prediction model to output a prediction result; and determining the detection result according to the prediction result.

[0143] For example, the manner of determining that the detection result is abnormal can include at least one of the following: if the processor usage rate is higher than the processor usage rate threshold, the memory occupation state is higher than the memory occupation state threshold, the network interface traffic is higher than the network interface traffic threshold, the network delay duration is higher than the network delay duration threshold, the packet loss rate of the first device in the target period is higher than the packet loss rate threshold, and the bandwidth fluctuation amplitude is higher than the bandwidth fluctuation threshold. Conversely, the detection result is normal.

[0144] Alternatively, at least two of the selected processor usage rate, memory occupation state, network interface traffic, network delay duration, packet loss rate of the first device in the target period, and bandwidth fluctuation amplitude can be weighted and summed according to the respective thresholds to obtain a comprehensive result; in the case where the comprehensive result is higher than the comprehensive weighted threshold, the detection result is abnormal; otherwise, the detection result is normal. For example, the comprehensive result can be a transmission quality index (TQI), which can be determined according to three dimensions of network delay duration (RTT), packet loss rate, and bandwidth fluctuation amplitude, such as TQI = (delay weight × RTT) + (packet loss rate weight × packet loss rate) + (bandwidth fluctuation weight × fluctuation amplitude). When TQI > the comprehensive weighted threshold, such as 80 points, it is determined that the network state is poor, and the detection result is abnormal; otherwise, the detection result is normal.

[0145] Alternatively, the prediction model can be a machine learning model, such as a long short-term memory network (LSTM) to predict the network state trend in the next 10 seconds to obtain a corresponding prediction result. If the network state trend indicates that the network state is poor, the detection result is not passed; otherwise, the detection result is normal. The machine learning model can be trained based on historical network state information, such as using historical information to calculate TQI.

[0146] In the embodiments of the present application, by using multiple detection methods to detect the network state information, multiple data and multiple dimensions can be used for network state detection to improve the accuracy of network state detection by the group management server.

[0147] According to the embodiment of the present application, the first message comprises a fault alarm message transmitted by the second transmission mode, in response to receiving the first message from the first device, determining the message information matched with the first message, comprising: in response to receiving the fault alarm message from the first device, parsing the fault alarm message to obtain the fault type and at least one second device associated with the first device; determining that the message type matched with the fault alarm message is the fault processing type; generating the second request information for obtaining the running information matched with the fault type; wherein the message information comprises the second request information, the fault processing type, the receiving device information indicating that the at least one second device and the first device are receiving devices; the message information is transmitted by the first transmission mode, and the first transmission mode is determined according to the fault processing type.

[0148] For example, in the fault and abnormal scenario, the first device can be a router, a switch, a terminal device, etc., and the current device can be a group management server.

[0149] In the daily operation process of the first device, the network link or other communication of the first device with other devices can be suddenly interrupted, whereby, when detecting the network link or communication interruption, the first device sends a fault alarm message by UDP, the message type of the fault alarm message is the fault alarm type, and the fault alarm message can include at least one second device associated with the first device, the fault type, the fault occurrence time, the affected service, etc. At least one second device associated with the first device, that is, the device that will be affected when the first device fails. The current device receives and parses the fault alarm message to obtain the fault type and the second device, and generates the second request information for obtaining the log file of a specific range or time period through rule matching. Then, the message information is transmitted to the first device by TCP, so that the first device returns the log file of a specific range or time period by TCP, so as to utilize the above log file for fault analysis and fault processing.

[0150] In the embodiment of the present application, the group management server is used to quickly obtain the fault alarm message from the first device by UDP, so as to realize the rapid detection of the fault, and the second request information for obtaining the running information matched with the fault type is transmitted by TCP when detecting the fault, so as to avoid the security problem of fault analysis caused by the leakage of the second request information, not only the rapid detection of the fault can be realized, but also the security analysis of the fault can be realized. In addition, since the running information of the first device usually includes detailed information, once leaked, the first device will be completely exposed in a non-secure environment, and the risk of attack will increase dramatically, therefore, transmitting the running information matched with the fault type by TCP can further ensure the security of the first device.

[0151] Thus, in one embodiment, the transmission manner for transmitting the message information is determined according to the message type, including: in the case that the message type is a service request, determining the target service requested from the message information; and determining the transmission manner for transmitting the message information according to the security level of the target service, wherein the target service with a higher security level corresponds to a first transmission manner, and the target service with a lower security level corresponds to a second transmission manner.

[0152] For some messages, the corresponding transmission manner can be directly determined according to the message type in the message information, however, for some message types related to the requested service, the requirement of the message transmission on security and speed is related to the specific service requested. For example, the higher the security level of the target service requested is, the higher security level TCP can be used to return the message information; otherwise, the lower security level UDP can be used to return the message information.

[0153] For example, the security level of the service related to the permission modification is higher, the security level of the service related to the query is lower, and the security level of the service related to the device group is higher.

[0154] Figure 7 A scenario diagram of service request based on MDP according to the embodiment of the present application is shown. Taking a first device as the device interacting with the user, the current device as device A, and the receiving device as device B as an example, the user can interact with the first device to specify the target service requested, the first device encapsulates the specified target service as a first message of service request type, and transmits the first message to device A through TCP or UDP according to the target service. In the case that the target service is provided by device B, device A determines that the target service is provided by device B according to the target service in the first message and the pre-stored service information of each device (pre-acquired from the device discovery process or acquired through the group management server), thus, the determined message information includes the target service requested, the service type, the operation parameter, the device information of device A, the digital security information, the message type indicating the service request, etc. At this time, the message information is also called the message information of service request (ServiceRequest), which is abbreviated as service request message (ServiceRequest).

[0155] As Figure 7As shown, device A calls the transmission interface to determine to send the service request message through TCP or UDP according to the security level of the target service. After receiving the service request message, device B parses and verifies the service request message, including verifying the digital certificate information and the requested operation parameters (such as whether to be in the same device group). If the verification is passed, device B calls the corresponding service processing program to perform the service operation, encapsulates the service result in a service response message (ServiceResponse), and returns the service response message through the corresponding TCP or UDP. After receiving the service response message, device A processes and uses the received service result, and completes the service interaction process.

[0156] In addition, in the above service request process, the current device can also be device B, the first device and the receiving device can be device A, the ServiceRequest sent by device A can be the first message, and the message information returned by device B can be the message information of ServiceResponse. In addition, if device A and device B do not belong to the same device group, the verification of ServiceRequest fails, the target service cannot be requested, and a service request failure is returned through TCP.

[0157] In the embodiments of the present application, the selection of the transmission mode according to the security level of the target service through the MDP can ensure the confidentiality, integrity, authenticity and speed of the service request and response messages. The service request based on the device group management can further improve the security and isolation of the service interaction at the device group granularity.

[0158] According to the embodiments of the present application, the transmission mode for transmitting the message information is determined according to the message type, including: determining the protocol version information from the message information in the case of determining that the message type is a custom type; and determining the transmission mode for transmitting the message information according to the protocol version information and the custom type.

[0159] With the expansion of the network size and the increase of the device types, the existing SSDP architecture is difficult to adapt to large-scale network environment, cannot be flexibly expanded to support more devices and service types, and is difficult to integrate and expand new functions, which limits the further development and evolution of the network.

[0160] In the embodiments of the present application, the MDP integrated with the transmission interface not only defines the basic message format, field and message type, but also supports customization of message type and service information to meet special needs in different application scenarios. For example, special service information and message type are defined for specific industry devices to realize customized extension of the protocol and adapt to diversified development needs. For example, the medical device can add a "sensor data format" field, and the industrial device can extend a "control instruction protocol" field, so that the protocol can quickly adapt to emerging scenarios such as smart grids and Internet of Vehicles.

[0161] Since the message type corresponds to the transmission mode of TCP or UDP, in order to ensure that the corresponding transmission mode can be supported for the customized type, the message information can also include protocol version information, such as a protocol version number in the form of a field. The latest version of the MDP protocol is determined according to the protocol version information, and the transmission mode corresponding to the customized type is determined based on the latest version of the MDP protocol. Similarly, for the receiving device, the receiving device can select the corresponding analysis and processing mode according to the protocol version information, to ensure the interaction of the customized message type. Similarly, if the message information includes customized service information, the customized service information is determined according to the protocol version information and the corresponding operation is performed.

[0162] In the embodiments of the present application, through the protocol version information indicated in the message information, the current device and the receiving device can realize the transmission mode selection and transmission of the customized type, support the transmission mode selection in multiple scenarios, and improve the scenario applicability.

[0163] Figure 8 An extension message transmission scenario diagram for customizing message type and service information based on MDP according to the embodiments of the present application is shown. As shown in Figure 8 According to user needs, the message type and service information can be customized by upgrading the protocol version to realize the extension of the message format. Then, the devices carrying the upgraded protocol version can construct the corresponding message information according to the protocol version information. For example, the device E generates an extension message with an extended message format, the device E sends the extension message carrying the protocol version information, the device F receives the extension message carrying the upgraded protocol version, the device F processes the extension message according to the protocol version information, and realizes the operation of the customized service information and message type.

[0164] According to the embodiments of the present application, the version update of the MDP protocol can be compatible with the information of the previous version. For example, the MDP protocol of the subsequent version is extended and optimized on the basis of preserving compatibility with the previous version. Thus, when the MDP is upgraded, multiple devices based on different versions of MDP can also coexist and communicate in the network, realizing smooth evolution and upgrade of the MDP protocol.

[0165] In addition to determining the transmission mode according to the message type, the transmission interface can also perform encryption and transmission through the message.

[0166] According to an embodiment of the present application, transmitting the message information to the receiving device matched with the receiving device information through the transmission mode includes: in the case that the transmission mode is the first transmission mode, encrypting the message information by using at least one encryption algorithm to obtain an encrypted message; transmitting the encrypted message to the receiving device matched with the receiving device information through the first transmission mode; and in the case that the transmission mode is the second transmission mode, transmitting the message information to the receiving device matched with the receiving device information through the second transmission mode.

[0167] For example, the encryption algorithm used for encrypting the message information can include at least one of the following: Advanced Encryption Standard (AES), Rivest-Shamir-Adleman (RSA), and State Machine (SM). The specific algorithms used by AES, RSA, and SM can be various, such as SM4.

[0168] In an embodiment of the present application, the security of the message transmission using the first transmission mode is further improved by further encrypting the message information and transmitting the encrypted message through the first transmission mode with a higher security level. If the second transmission mode is used, the message information does not need to be encrypted and can be directly transmitted to ensure the quickness of the message transmission.

[0169] In one embodiment, the message information is encrypted by using at least one encryption algorithm to obtain an encrypted message, including: performing a hash calculation on the message information to obtain a first message digest; and encrypting the message information by using a symmetric key of a symmetric encryption algorithm; wherein the encrypted message includes the encrypted message information and the first message digest, so that the receiving device decrypts the encrypted message information by using the symmetric key, the symmetric key is encrypted by using a public key of the receiving device and then transmitted to the receiving device, the length of the symmetric key is determined according to the security level of the current device, and the length of the public key is determined according to the security level of the receiving device.

[0170] For example, the encryption can be performed in a combination of AES and RSA. In the device discovery process, the RSA public keys of the receiving device and the current device can be exchanged, and then the AES encryption key generated by the current device is encrypted by using the RSA public key of the receiving device and then transmitted to the receiving device, the receiving device decrypts the AES encryption key by using its own RSA private key to obtain the AES encryption key, so that the receiving device can decrypt by using the AES encryption key in the message transmission stage.

[0171] During the message transmission phase, the current device encrypts the message using the AES encryption key to improve encryption efficiency. Furthermore, because the AES encryption key is encrypted using RSA before transmission, this phase ensures secure message transmission. The current device also hashes the message to generate a message digest, such as using a 256-bit Secure Hash Algorithm (SHA-256), to produce a first message digest. Since the first message digest is sent to the receiving device during message transmission, the receiving device can re-hash the message to produce a second message digest. If the first and second message digests match, the message has not been tampered with during transmission, ensuring message integrity. Otherwise, the message has been tampered with, and appropriate security measures can be taken.

[0172] According to an embodiment of the present application, when using RSA and AES in combination for encryption, due to the different security levels of different devices, their security requirements for message transmission are different. Therefore, for multiple devices, keys of different lengths can also be used for encryption. For example, according to the security level from high to low, the devices can include three security levels: core devices, ordinary devices, and temporary devices. For devices with different security levels, the length of the AES encryption key (128 bits / 256 bits) and the length of the RSA key (2048 bits / 4096 bits) are dynamically adjusted. It can be understood that since RSA uses a key pair consisting of a public key and a private key, the length of the public key and the private key are determined according to the security level of the device.

[0173] For example, the core equipment for industrial control uses 256-bit AES+4096-bit RSA, and the guest equipment (temporary equipment) uses 128-bit AES+2048-bit RSA to balance security and encryption resource consumption.

[0174] In an embodiment of the present application, encryption is performed by combining AES and RSA, and the length of the key is determined according to the security level of the device, so as to realize message transmission based on the security level and the composite encryption algorithm. On the basis of transmitting message information based on TCP, the security of message transmission is further improved.

[0175] Figure 9 The following diagram shows a scenario of encryption and decryption using a symmetric encryption algorithm and an asymmetric encryption algorithm according to an embodiment of the present application. Figure 9As shown, for the message transmitted using TCP, including the first message and the message information corresponding to the message type, device A and device B are respectively taken as the sending device and the receiving device. Device A can generate an encryption key using a symmetric encryption algorithm, and encrypt the encryption key using an asymmetric encryption algorithm, and transmit the encrypted encryption key to device B in advance before message transmission. Device B decrypts the encryption key of the symmetric encryption algorithm using the private key of the asymmetric encryption algorithm. In the message transmission stage, device A encrypts the message information using the encryption key of the symmetric encryption algorithm to obtain encrypted message information, and processes the message information using a hash algorithm to generate a first message digest, and transmits the encrypted message information and the first message digest through TCP. Device B decrypts the encrypted message information using the encryption key to obtain decrypted message information, and generates second digest information using a hash algorithm. In addition, the message information transmitted by TCP includes digital certificate information, and the verification method is as above, if the verification is passed, the processing can be continued, if the verification is not passed, the message information of this message is discarded.

[0176] According to an embodiment of the present application, the message transmission method further comprises: in the case that the symmetric key satisfies the invalidation condition, generating a new symmetric key of a predetermined length according to the security level of the current device; wherein the invalidation condition comprises at least one of the following: the number of times of use of the symmetric key reaches a number threshold, the valid time length of the symmetric key reaches a time threshold; encrypting the new symmetric key using the public key of the receiving device, and transmitting the encrypted new symmetric key to the receiving device through the first transmission mode, wherein the public key of the receiving device is updated at a fixed time.

[0177] For example, the AES symmetric key of each device is automatically invalidated every 1000 encrypted messages or more than 24 hours of survival time. For the current device, a new symmetric key can be generated, and the predetermined length of the new symmetric key is determined by the security level of the current device, such as the predetermined length can be 128 bits or 256 bits. After generating the new encryption key, the new encryption key is re-negotiated through RSA, such as the new encryption key is encrypted using the RSA public key of the receiving device and then transmitted to the receiving device through TCP, and the receiving device decrypts the new encryption key using its own RSA private key. The update of the RSA public key is controlled by the CA, and is forced to update every 6 months, such as the receiving device or the current device automatically synchronizes the new RSA public key of each other when requesting a new certificate from the CA through TCP.

[0178] In the embodiments of the present application, the dynamic update of the AES symmetric key is realized by judging whether the symmetric key meets the invalidation condition, the dynamic update of the key of the asymmetric encryption algorithm is realized by regularly updating the RSA public key, the security hidden danger of the traditional AES / RSA "one key to the end" is solved, the security risk caused by long-term use of the same key is avoided, and the security of the TCP message transmission is improved.

[0179] According to the embodiments of the present application, the method further comprises: in response to detecting that the current device has a key abnormality, generating first message information according to the identification information of the abnormal key, the message type indicating the key abnormality, and the receiving device information indicating that at least one device in the second device group to which the current device belongs is a receiving device; transmitting the first message information to the at least one device through a second transmission mode; generating second message information according to the identification information, the message type indicating the key negotiation, and the receiving device information indicating that the target management device is a receiving device; encrypting the second message information by using the backup public key stored in the hardware security device to obtain third message information; and transmitting the third message information to the target management device through the first transmission mode, so that the target management device generates a key for replacing the abnormal key.

[0180] For example, the current device can receive a message transmitted by another device, and if the number of times of decryption failure using the AES symmetric key exceeds a threshold, the number of times of decryption failure using the RSA private key exceeds a threshold, the number of times of verification failure of the public key of the current device in the digital certificate information transmitted by another device exceeds a threshold, such as 3 times, or the message tampering is detected by comparing the message digests, it can be determined that the current device has a key abnormality.

[0181] When the current device has a key abnormality, the current device transmits first message information to all devices in the second device group to which the current device belongs through UDP, broadcasts the abnormal key and the message type of the key abnormality to all devices in the second device group to which the current device belongs, so that these devices mark the abnormal key and the message type of the key abnormality, and set the information carried in the message as untrusted information when receiving the message type of the message, so as to be processed subsequently (such as re-negotiating the key and requiring to resend such messages). Meanwhile, in order to be able to negotiate with the target management device, such as a group management server or a CA, to generate a new key to replace the above abnormal key, after the current device generates the second message information of the key negotiation type, not only the second message information is encrypted by using the more secure backup public key to obtain third message information, but also the third message information is transmitted to the target management device by using the more secure TCP, so that the target management device re-generates the key for replacing the abnormal key; similarly, the target management device returns the re-generated key to the current device through TCP.

[0182] The backup public key is stored offline in a hardware security device. The hardware security device can be a hardware security chip, and the security of the backup public key stored in the hardware security device is ensured by hardware-level protection, which is more secure than network negotiation keys. The hardware security device can be integrated into the current device, and when there is a key exception, the second message information can be transmitted to the hardware security device, and the hardware security device performs internal encryption of the second message information, and then transmits the third message information through the TCP connection between the current device and the target management device.

[0183] In the embodiments of the present application, in the case of key exception, the current device can quickly notify the devices in the second device group of the exception of the current device through UDP, to realize fast and safe alarm; at the same time, the current device uses a more secure backup public key to negotiate a new key with the target management device through a more secure TCP, to further ensure the security of the key.

[0184] According to the embodiments of the present application, the message transmission method comprises: in response to detecting that the network delay duration of the current device satisfies a delay condition, replacing a symmetric encryption algorithm with a predetermined encryption algorithm to encrypt the message information by using the predetermined encryption algorithm, wherein the resource consumption of the predetermined encryption algorithm is less than the resource consumption of the symmetric encryption algorithm; and in response to detecting that the current device is in a risk environment, determining a symmetric key with an increased length, and encrypting the message information by using the symmetric key with the increased length.

[0185] In addition to the above-mentioned encryption, decryption, key exception detection and other functions, the MDP packaged by the transmission interface also has an encryption algorithm priority queue built in, such as AES>RSA>SM4. For example, the delay condition can be that the network delay duration is greater than a predetermined delay duration. For example, when it is detected that the network delay duration exceeds 50 ms, SM4 can be used to replace AES, to realize automatic degradation of AES to a lightweight algorithm. In this embodiment, the predetermined encryption algorithm is SM4, and the resource consumption of SM4 in encryption is less than the resource consumption of AES.

[0186] In addition, the current device can be attacked, and at this time, the current device is in a risk environment. If the number of times of exception in decryption of the current device by using the AES symmetric key, the number of times of exception in decryption by using the RSA private key, and the number of times of exception in verification of the public key of the current device in the digital certificate information transmitted by other devices all exceed an environmental risk threshold value, such as 10 times, it is determined that the current device is in a risk environment, and the security level of the current device can not be reliable, that is, the security risk is increased, and then the AES symmetric key used by the current device can be automatically upgraded to an AES key with a longer length, and combined with other RSA and hash algorithms used to generate a message digest to form an algorithm combination with a higher security level, such as 256-bit AES+4096-bit RSA+512-bit SHA.

[0187] In the embodiments of this application, by detecting whether the current device is in a risky environment, the encryption algorithm can be automatically upgraded, further improving encryption security while ensuring secure message transmission via TCP. By detecting the network delay duration of the current device, the encryption algorithm can be downgraded, further improving encryption security and message transmission efficiency while ensuring secure message transmission via TCP.

[0188] In the above embodiment, the message information is encrypted before TCP transmission to transmit the encrypted message; after TCP transmission, it is also necessary to ensure that the receiving device receives and decrypts the encrypted message.

[0189] Therefore, according to an embodiment of the present application, the message transmission method also includes: in response to no response to the encrypted message being detected within a preset time length, when the number of transmissions of the encrypted message is less than the preset number of transmissions, the encrypted message is transmitted again to the receiving device that matches the receiving device information through the first transmission method, and the number of transmissions of the encrypted message is updated; when the number of transmissions of the encrypted message is greater than or equal to the preset number of transmissions, an error message is displayed to the user.

[0190] The preset duration can be, for example, a timer timeout duration, and the preset number of transmissions can be, for example, a maximum number of retransmissions.

[0191] Figure 10 FIG. 1 shows a retransmission scenario diagram of TCP transmission based on MDP according to an embodiment of the present application. Figure 10 As shown, as a sending device, the current device generates message information and determines the message type from the message information. Based on the message type, it is determined to use the first transmission method. After encrypting the message information, the encrypted message is sent via the first transmission method, and a retransmission timer is started. When no response (ACK) is received from the receiving device before the timer times out, it is determined whether the number of transmissions of the encrypted message is less than the preset number of transmissions. If the number of transmissions is less than the preset number of transmissions, the encrypted message is retransmitted, the retransmission timer is reset, and the number of transmissions of the encrypted message is increased until an ACK is received or the maximum number of retransmissions is reached. The ACK is fed back via TCP. If the number of transmissions is greater than or equal to the maximum number of retransmissions, the transmission is terminated and an error message is displayed to the user, such as "message transmission failed or verification failed."

[0192] The receiving device receives the encrypted message and verifies its integrity, for example, by determining whether the first message digest and the second message digest are identical. If they are, the device sends a reply to the sending device, confirming successful receipt and verification of the encrypted message. Otherwise, the message is discarded and no reply is returned.

[0193] In the embodiments of the present application, by timing the answer to the encrypted message and in combination with the maximum number of retransmissions, not only the security and reliability of the TCP transmission can be ensured, but also accidental transmission failures caused by network fluctuations or other factors can be avoided, ensuring the secure transmission of the message.

[0194] According to the embodiments of the present application, the message information is transmitted to the device matched with the receiving device information by the second transmission mode, including: determining the sliding window length for dividing the sequence number according to the network state information of the current device; determining the sequence number list of the message information according to the sliding window length; transmitting the message information and the sequence number list to the receiving device matched with the receiving device information by the second transmission mode, so that the receiving device matched with the receiving device information responds to the received message information and sequence number list, and determines the packet loss detection result for the message information according to the sequence number list.

[0195] For the message information transmitted by UDP, due to the influence of network fluctuations, bandwidth and other information, the message is easy to be lost, repeated or out of order, therefore, in addition to assigning corresponding sequence numbers to the message information transmitted by UDP according to the sliding window, the length of the sliding window is also dynamically updated according to the network state information of the current device. For specific information of the network state information, please refer to the above, which will not be repeated here.

[0196] For example, when the packet loss rate is less than 5%, the length of the sliding window is 10, and when the packet loss rate is 10%-20%, the length of the sliding window is reduced to 5. The current device can divide the message information into continuous sequence numbers according to the length of the sliding window to form a sequence number list. Thus, when transmitting the message information and the sequence number list by UDP, the receiving device determines whether there is packet loss in the UDP transmission by detecting the continuity of the sequence numbers in the sequence number list. For example, if the sequence number list is

[01235] , by detecting the continuity of the sequence numbers, it can be determined that the missing information is the information in the sliding window indicated by the 4th sequence number, and the receiving device can request the current device to retransmit the information in the sliding window indicated by the 4th sequence number through UDP. Alternatively, the receiving device does not immediately request retransmission when it determines that the stored information is missing, but waits for 1 complete window transmission period, such as 50ms, to aggregate all missing sequence numbers, and requests bulk retransmission (BRQ) through UDP, reducing the number of retransmission interactions. For example, in a large intelligent park, the UDP heartbeat message (device survival type message) of thousands of devices uses this mechanism, which can reduce the retransmission message flow by 30%.

[0197] In the embodiments of the present application, when transmitting the message information by UDP, the length of the sliding window is dynamically changed according to the network state, and the sequence number list is generated by using the sliding window with varying length, to ensure the reliability of the UDP transmission and facilitate the retransmission of the packet loss information.

[0198] Figure 11 FIG1 shows a scene diagram of UDP transmission based on MDP according to an embodiment of the present application. Figure 11 As shown, the current device generates message information, determines the message type, and when determining to transmit through the second transmission mode, that is, UDP, assigns a sequence number list to the message information, and sends the message information and the sequence number list through the second transmission mode. The receiving device receives the message information and the sequence number list, and determines whether the sequence number list is continuous. In the case that the sequence number list is continuous, the operation corresponding to the message information is performed; conversely, in the case that it is discontinuous, retransmission is requested according to the sequence number list through UDP. After the current device receives the message for retransmission, the current device retransmits the information with the missing sequence number in the sequence number list. The receiving device receives the retransmission information in the retransmitted message, and merges the retransmission information with the previous information.

[0199] According to an embodiment of the present application, to further optimize the transmission performance of MDP, regardless of whether TCP or UDP is selected for message transmission, message compression and fragmented transmission are also supported for larger MDP messages. For example, a registration message may contain a large amount of service information and device information. To reduce transmission bandwidth occupancy and improve transmission efficiency, a message compression algorithm is used to compress the message information before transmission. At the same time, for messages that exceed the maximum transmission unit (MTU) of the transport layer, fragmentation can also be performed, splitting the message information into multiple smaller fragments for transmission. The fragments are then reassembled and restored at the receiving device to ensure the integrity and correct transmission of the message. This is particularly suitable for large-scale network environments and scenarios with high bandwidth requirements.

[0200] According to embodiments of the present application, MDP-based information transmission also incorporates a caching mechanism. For example, after a successful device discovery or service query, a device caches the query results (including device attribute information, service information, etc.) locally, setting a reasonable cache validity period. Subsequent identical or similar query requests within a certain period of time can retrieve results directly from the local cache, reducing the number of discovery requests sent over the network, reducing network traffic and device resource consumption, and improving discovery efficiency. Furthermore, the device regularly receives AliveNotification messages from other devices or device group change messages from the group management server. Based on these messages, it updates outdated information in the local cache to ensure the accuracy and validity of the cached content.

[0201] According to the embodiments of the present application, the MDP-based information transmission also has multi-thread processing and asynchronous operation. The MDP protocol stack adopts a multi-thread processing mechanism on both the device side and the server side, and a special thread is used for message receiving, parsing, processing and sending. The threads communicate with each other through a thread-safe queue for message transmission and data sharing, so as to improve the concurrent capability and response speed of protocol processing. For time-consuming operations (such as device registration, database access and network communication involved in group management, etc.), an asynchronous operation mode is adopted, and the operation result is processed through a callback function or an event notification mode after the task is submitted, so as to avoid thread blocking and improve the overall performance and resource utilization of the system.

[0202] According to the embodiments of the present application, the MDP-based protocol as a whole adopts a modular plug-in design, and different functions are encapsulated into independent functional modules, such as security authentication, group management, device discovery and the like. The modules interact with each other through defined interfaces. Through the plug-in architecture, new functional modules can be conveniently extended or the existing functional modules can be upgraded, for example, a new security authentication algorithm plug-in is added, a new device type identification plug-in is integrated, and the like, without modifying the core architecture of the protocol, so as to realize flexible expansion and function enhancement of the protocol.

[0203] According to the embodiments of the present application, in the network based on MDP for message transmission, for the management devices such as the group management server, a multi-path transmission pool is established at the bottom, and the same message is transmitted through 2-3 physical links, such as the main link, the standby Wi-Fi and the 4G module. The receiving device layer adopts a first-come-first-processed principle, and the messages received repeatedly are removed through the sequence number. If a link in the multi-path transmission pool fails, it is automatically switched to other links, and a notification indicating the failure is sent through UDP, and the information involved in the transmission failure of the failed link and the supplementary link is closed.

[0204] In addition, in order to ensure the effectiveness and security of message transmission, the message type also includes multiple priorities, for example, P0-P4, P0 being the highest. The P0-level message is forced to use TCP multi-path transmission, and occupies the highest bandwidth. The P0-level message can be a message type used for primary / standby switching. The P1-P2-level message (such as the first type of message described above): by default, in addition to using TCP transmission, if the TCP connection queue is full and / or the waiting time is exceeded, the UDP+sequence number list retransmission mechanism is temporarily used as a backup for TCP. However, this part of the transmission needs to be confirmed by the administrator before it can be backed up. The P3-P4-level message (such as the second type of message described above): by default, UDP transmission, if the network delay is relatively long, it is automatically downgraded to a "delayed sending" mode, and the interval time of UDP transmission is prolonged.

[0205] Figure 12 A structural block diagram of a message transmission device according to an embodiment of the present application is shown. As shown inFigure 12 As shown, the message transmission apparatus 1200 comprises a determination module 1210 configured to determine message information matched with the first message in response to receiving the first message from the first device, wherein the message information comprises receiving device information and a message type, and the message type comprises a type for managing a device group composed of a plurality of devices; and a calling module 1220 configured to call a transmission interface, determine a transmission manner for transmitting the message information according to the message type, and transmit the message information to a receiving device matched with the receiving device information through the transmission manner; wherein the transmission manner comprises a first transmission manner and a second transmission manner using different transmission protocols, and a security level of the transmission protocol used by the first transmission manner is higher than a security level of the transmission protocol used by the second transmission manner; and the transmission interface is further configured to encrypt the message information.

[0206] According to an embodiment of the present application, the first message comprises a device group creation message, and the determination module 1210 comprises: a first parsing sub-module configured to parse the device group creation message to obtain group information of a first device group to be created in response to receiving the device group creation message from the first device, wherein the group information comprises at least one of the following: identification information, description information, a device range, an access right, and a group management policy; a first generation sub-module configured to generate a group record of the first device group according to the group information of the first device group; a first determination sub-module configured to determine that the message type matched with the device group creation information is a new group broadcast type; and a second determination sub-module configured to determine at least one device in a second device group to which a current device belongs except the current device; wherein the message information comprises the group record, a new group broadcast message, and receiving device information indicating that the at least one device is a receiving device.

[0207] According to an embodiment of the present application, the first message comprises at least one of the following: a device group joining message and a device group exiting message; and the determination module 1210 comprises: a second parsing sub-module configured to parse the first message to obtain digital certificate information of the first device and a third device group in response to receiving the first message from the first device; a first verification sub-module configured to verify the digital certificate information of the first device and a device joining condition of the third device group respectively for the device group joining message to obtain group change information for the third device group; a second verification sub-module configured to verify the digital certificate information of the first device for the device group exiting message to obtain the group change information for the third device group; and a third determination sub-module configured to determine that the message type matched with the first message is a device group change type; wherein the message information comprises the group change information, the device group change type, and receiving device information indicating that at least one device in the third device group is a receiving device.

[0208] According to an embodiment of the present application, the first message comprises a registration message; the determining module 1210 comprises: a third parsing submodule, configured to parse the registration message in response to receiving the registration message from the first device; a third verifying submodule, configured to verify the digital certificate information of the first device and the device joining condition of the fourth device group respectively in the case that the parsed registration message comprises the registration information of the first device, the group information of the fourth device group and the digital certificate information of the first device, wherein the fourth device group is a device group that the first device requests to join when registering; a fourth determining submodule, configured to determine that the message type matched with the registration message is a registration result notification type; and a second generating submodule, configured to generate message information according to the registration result, wherein the message information comprises the registration result, the registration result notification type, and receiving device information indicating that at least one device in the fourth device group and the first device are receiving devices.

[0209] According to an embodiment of the present application, the calling module 1220 comprises a mode determining submodule, configured to determine a transmission mode for transmitting the message information according to the message type. The mode determining submodule comprises: a first determining unit, configured to determine the first transmission mode as the transmission mode for transmitting the message information in the case that the message type is determined to be a first type; and a second determining unit, configured to determine the second transmission mode as the transmission mode for transmitting the message information in the case that the message type is determined to be a second type, wherein the security level of the first type is higher than that of the second type.

[0210] According to an embodiment of the present application, the first type comprises at least one of the following: a device registration type, a registration result notification type, a device revocation type, a revocation result notification type, a data transmission type, a backup data recovery type, a network exception handling type, a fault handling type, and a type for managing a device group composed of a plurality of devices; the type for managing a device group composed of a plurality of devices comprises one of the following: a device group creation type, a new group broadcast type, a device group change type, a device group joining type, and a device group exiting type; and the second type comprises at least one of the following: a device discovery type, a device survival type, a backup notification type, a backup verification type, a network state type, and a fault alarm type.

[0211] According to an embodiment of the present application, the first message and the message information are transmitted through different transmission modes.

[0212] According to an embodiment of the present application, the first device comprises a data production device, and the first message comprises a backup notification message transmitted through a second transmission mode; the determining module 1210 comprises: a fourth parsing submodule, configured to, in response to receiving the backup notification message from the data production device, parse the backup notification message to obtain a data volume of the data to be backed up and an estimated transmission duration; a fifth determining submodule, configured to determine that the message type matched with the backup notification message is a data transmission type; and a sixth determining submodule, configured to determine data transmission time information according to the data volume, the estimated transmission duration and a running state of the current device; wherein the message information comprises the data transmission time information, the data transmission type and receiving device information indicating that the data production device is a receiving device, the message information is transmitted through the first transmission mode, and the first transmission mode is determined according to the data transmission type.

[0213] According to an embodiment of the present application, the first device comprises a backup device, and the first message comprises a backup data recovery message transmitted through a first transmission mode; in response to receiving the first message from the first device, determining the message information matched with the first message comprises: a fifth parsing submodule, configured to, in response to receiving the backup data recovery message from the backup device, parse the backup data recovery message to obtain backup data; a seventh determining submodule, configured to determine that the message type matched with the backup data recovery message is a backup verification type; and an eighth determining submodule, configured to determine a first hash value of the backup data by using a hash algorithm; wherein the message information comprises the first hash value, the backup verification type and receiving device information indicating that the backup device is a receiving device, the message information is transmitted through a second transmission mode, so that the backup device determines the integrity of the backup data according to the first hash value and a second hash value, and the second transmission mode is determined according to the backup verification type.

[0214] According to an embodiment of the present application, the first message comprises a network status message transmitted through a second transmission mode; the determining module 1210 comprises: a sixth parsing submodule, configured to, in response to receiving the network status message from the first device, parse the network status message to obtain network status information, wherein the network status information comprises at least one of the following: a processor usage rate, a memory occupation state, a network interface traffic, a network delay duration, a packet loss rate of the first device in a target period, and a bandwidth fluctuation amplitude; a detecting submodule, configured to detect the network status information to obtain a detection result; a ninth determining submodule, configured to, in a case where it is determined that the detection result is abnormal, determine that the message type matched with the network status message is a network exception handling type; and a third generating submodule, configured to generate first request information for obtaining running information of the first device; wherein the message information comprises the first request information, the network exception handling type and receiving device information indicating that the first device is a receiving device; the message information is transmitted through a first transmission mode, and the first transmission mode is determined according to the network exception handling type.

[0215] According to an embodiment of the present application, the detection submodule includes at least one of: a first detection unit configured to compare the network status information with at least one network status threshold to obtain a detection result, wherein the network status threshold includes: a processor usage rate threshold, a memory occupancy status threshold, a network interface traffic threshold, a network delay duration threshold, a first device packet loss rate threshold in a target period, a bandwidth fluctuation threshold, and a comprehensive weighted threshold; and a second detection unit configured to input the network status information into a prediction model to output a prediction result, and determine the detection result according to the prediction result.

[0216] According to an embodiment of the present application, the first message includes a fault alarm message transmitted by the second transmission method, and the determination module 1210 includes: a seventh analysis submodule configured to, in response to receiving the fault alarm message from the first device, analyze the fault alarm message to obtain a fault type and at least one second device associated with the first device; a tenth determination submodule configured to determine that the message type matching the fault alarm message is a fault handling type; and a fourth generation submodule configured to generate second request information for obtaining operation information matching the fault type; wherein the message information includes the second request information, the fault handling type, and receiving device information indicating that the at least one second device and the first device are receiving devices; and the message information is transmitted by the first transmission method, which is determined according to the fault handling type.

[0217] According to an embodiment of the present application, the calling module 1220 includes a method determination submodule configured to determine a transmission method for transmitting the message information according to the message type. The method determination submodule includes: a third determination unit configured to, in the case where the message type is a service request, determine a target service requested from the message information; and a fourth determination unit configured to determine the transmission method for transmitting the message information according to a security level of the target service, wherein a target service with a higher security level corresponds to a first transmission method, and a target service with a lower security level corresponds to a second transmission method.

[0218] According to an embodiment of the present application, the method determination submodule includes: a fifth determination unit configured to, in the case where it is determined that the message type is a custom type, determine protocol version information from the message information; and a sixth determination unit configured to determine the transmission method for transmitting the message information according to the protocol version information and the custom type.

[0219] According to an embodiment of the present application, the calling module 1220 comprises a transmission sub-module, configured to transmit the message information to the receiving device matched with the receiving device information by the transmission mode. The transmission sub-module comprises: a first transmission unit, configured to, when the transmission mode is a first transmission mode, encrypt the message information by using at least one encryption algorithm to obtain an encrypted message; and transmit the encrypted message to the receiving device matched with the receiving device information by the first transmission mode; and a second transmission unit, configured to, when the transmission mode is a second transmission mode, transmit the message information to the receiving device matched with the receiving device information by the second transmission mode.

[0220] According to an embodiment of the present application, the first transmission unit comprises: a calculation sub-unit, configured to perform a hash calculation on the message information to obtain a first message digest; and an encryption sub-unit, configured to encrypt the message information by using a symmetric key of a symmetric encryption algorithm; wherein the encrypted message comprises the encrypted message information and the first message digest, so that the receiving device decrypts the encrypted message information by using the symmetric key, the symmetric key is transmitted to the receiving device after being encrypted by using a public key of the receiving device, the length of the symmetric key is determined according to the security level of the current device, and the length of the public key is determined according to the security level of the receiving device.

[0221] According to an embodiment of the present application, the calling module 1220 further comprises: a first updating sub-module, configured to, when the symmetric key satisfies an invalidation condition, generate a new symmetric key with a predetermined length according to the security level of the current device; wherein the invalidation condition comprises at least one of the following: the number of times of using the symmetric key reaches a number threshold, and the valid time length of the symmetric key reaches a time threshold; and a second updating sub-module, configured to encrypt the new symmetric key by using the public key of the receiving device, and transmit the encrypted new symmetric key to the receiving device by the first transmission mode, wherein the public key of the receiving device is updated at a time.

[0222] According to an embodiment of the present application, the calling module 1220 further comprises: a first exception handling submodule, configured to, in response to detecting that the current device has a key exception, generate first message information according to identification information of the exception key, a message type indicating a key exception, and receiving device information indicating that at least one device in a second device group to which the current device belongs is a receiving device; a second exception handling submodule, configured to transmit the first message information to the at least one device by using a second transmission mode; a third exception handling submodule, configured to generate second message information according to the identification information, a message type indicating a key negotiation, and receiving device information indicating that a target management device is a receiving device; a fourth exception handling submodule, configured to encrypt the second message information by using a backup public key stored in the hardware security device to obtain third message information; and a fifth exception handling submodule, configured to transmit the third message information to the target management device by using a first transmission mode, so that the target management device generates a key for replacing the exception key.

[0223] According to an embodiment of the present application, the calling module 1220 comprises: a sixth exception handling submodule, configured to, in response to detecting that a network delay duration of the current device satisfies a delay condition, replace a symmetric encryption algorithm with a predetermined encryption algorithm for encrypting message information by using the predetermined encryption algorithm, wherein a resource consumption amount of the predetermined encryption algorithm is less than a resource consumption amount of the symmetric encryption algorithm; and a seventh exception handling submodule, configured to, in response to detecting that the current device is in a risk environment, determine a symmetric key with an increased length, and encrypt the message information by using the symmetric key with the increased length.

[0224] According to an embodiment of the present application, the calling module 1220 further comprises: a first retransmission submodule, configured to, in response to detecting that no reply to an encrypted message is received within a preset time duration, retransmit the encrypted message to a receiving device matching receiving device information by using a first transmission mode in a case where a transmission number of the encrypted message is less than a preset transmission number, and update the transmission number of the encrypted message; and a second retransmission submodule, configured to, in a case where the transmission number of the encrypted message is greater than or equal to the preset transmission number, display error information to a user.

[0225] According to an embodiment of the present application, the second transmission unit comprises: a first determination submodule, configured to determine a sliding window length for dividing a sequence number according to network state information of the current device; a second determination submodule, configured to determine a sequence number list of the message information according to the sliding window length; and a transmission submodule, configured to transmit the message information and the sequence number list to a receiving device matching the receiving device information by using a second transmission mode, so that the receiving device matching the receiving device information responds to receiving the message information and the sequence number list, and determines a packet loss detection result for the message information according to the sequence number list.

[0226] According to an embodiment of the present application, any of the modules 1210 and 1220 can be combined in one module, or any of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of the modules can be combined with at least part of the functions of the other modules, and implemented in one module. According to an embodiment of the present application, at least one of the modules 1210 and 1220 can be implemented at least in part as a hardware circuit, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on board, a system on package, an application specific integrated circuit (ASIC), or any other reasonable manner of integrating or packaging a circuit, etc. in hardware or firmware, or in any one of the three implementation manners of software, hardware and firmware, or in a proper combination of any one or more of them. Alternatively, at least one of the modules 1210 and 1220 can be implemented at least in part as a computer program module that can perform the corresponding functions when the computer program module is run.

[0227] Figure 13 A block diagram of an electronic device suitable for implementing the message transmission method according to an embodiment of the present application is shown.

[0228] As shown in Figure 13 The electronic device 1300 according to an embodiment of the present application includes a processor 1301 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 1302 or loaded from a storage portion 1308 into a random access memory (RAM) 1303. The processor 1301 can include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor, and / or a related chipset, and / or a special-purpose microprocessor (e.g., an application specific integrated circuit (ASIC)), etc. The processor 1301 can also include an on-board memory for cache use. The processor 1301 can include a single processing unit or multiple processing units for executing different actions of the method processes according to embodiments of the present application.

[0229] In the RAM 1303, various programs and data required for the operation of the electronic device 1300 are stored. The processor 1301, the ROM 1302, and the RAM 1303 are connected to each other via a bus 1304. The processor 1301 performs various operations of the method processes according to embodiments of the present application by executing the programs in the ROM 1302 and / or the RAM 1303. It should be noted that the programs can also be stored in one or more memories other than the ROM 1302 and the RAM 1303. The processor 1301 can also perform various operations of the method processes according to embodiments of the present application by executing the programs stored in the one or more memories.

[0230] According to embodiments of the present application, the electronic device 1300 can further include an input / output (I / O) interface 1305 that is also connected to the bus 1304. The electronic device 1300 can further include one or more of the following components connected to the input / output (I / O) interface 1305: an input part 1306 including a keyboard, a mouse, etc.; an output part 1307 including a display such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage part 1308 including a hard disk, etc.; and a communication part 1309 including a network interface card such as a LAN card, a modem, etc. The communication part 1309 performs communication processing via a network such as the Internet. A drive 1310 is also connected to the input / output (I / O) interface 1305 as necessary. A removable medium 1311 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 1310 as necessary, so that a computer program read out therefrom is installed in the storage part 1308 as necessary.

[0231] The present application also provides a computer readable storage medium, which can be included in the device / apparatus / system described in the above embodiments, or exist separately without being assembled into the device / apparatus / system. The above computer readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present application.

[0232] According to embodiments of the present application, the computer readable storage medium can be a non-volatile computer readable storage medium, which can include, but is not limited to, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present application, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device. For example, according to embodiments of the present application, the computer readable storage medium can include one or more memories such as the ROM 1302 and / or the RAM 1303 and / or one or more memory components other than the ROM 1302 and the RAM 1303 described above.

[0233] Embodiments of the present application also include a computer program product, which includes a computer program containing program codes for executing the methods shown in the flowcharts. When the computer program product is run in a computer system, the program codes are used to make the computer system implement the methods provided by the embodiments of the present application.

[0234] The above-described functions of the system / device defined in the system / apparatus of the embodiments of the present application are performed when the computer program is executed by the processor 1301. According to the embodiments of the present application, the system, apparatus, module, unit, etc. described above can be implemented by the computer program modules.

[0235] In one embodiment, the computer program can be stored in a tangible storage device, such as an optical storage device, a magnetic storage device, etc. In another embodiment, the computer program can also be transferred from a network medium, and be downloaded and installed by the communication part 1309, and / or be installed from the removable medium 1311. The program code included in the computer program can be transmitted using any suitable network medium, including, but not limited to, wireless, wired, etc., or any suitable combination of the above.

[0236] In such an embodiment, the computer program can be downloaded and installed from a network by the communication part 1309, and / or be installed from the removable medium 1311. When the computer program is executed by the processor 1301, the above-described functions of the system defined in the embodiments of the present application are performed. According to the embodiments of the present application, the system, apparatus, device, module, unit, etc. described above can be implemented by the computer program modules.

[0237] According to the embodiments of the present application, the program code for performing the computer program provided by the embodiments of the present application can be written in any combination of one or more programming languages, and specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming language, and / or assembly / machine language. The programming language includes, but is not limited to, such as Java, C++, python, "C" language or similar programming language. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case involving a remote computing device, the remote computing device can be connected to the user computing device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, connected to the Internet through an Internet service provider).

[0238] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of the boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0239] Those skilled in the art will appreciate that the features described in the various embodiments of this application may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in this application. In particular, the features described in the various embodiments of this application may be combined and / or coupled in various ways without departing from the spirit and teachings of this application. All such combinations and / or couplings fall within the scope of this application.

[0240] The embodiments of the present application have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present application. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present application, those skilled in the art may make various substitutions and modifications, and these substitutions and modifications should all fall within the scope of the present application.

Claims

1. A message transmission method, characterized in that: The message transmission method includes: In response to receiving a first message from a first device, determining message information matching the first message, wherein the message information includes receiving device information and a message type, and the message type includes a type for managing a device group consisting of multiple devices; Calling a transmission interface, determining a transmission method for transmitting the message information according to the message type, and transmitting the message information to a receiving device matching the receiving device information through the transmission method, wherein the interface is applied to device discovery and service discovery scenarios; The transmission mode includes a first transmission mode and a second transmission mode using different transmission protocols, the security level of the transmission protocol used by the first transmission mode is higher than the security level of the transmission protocol used by the second transmission mode; the transmission interface is further used to encrypt the message information; The method further includes: the first message and the message information are transmitted via different transmission modes; the first device includes a data production device, and the first message includes a backup notification message transmitted via the second transmission mode; and in response to receiving the first message from the first device, determining message information matching the first message includes: In response to receiving the backup notification message from the data production device, parsing the backup notification message to obtain the data volume and estimated transmission time of the data to be backed up; Determining that a message type matching the backup notification message is a data transmission type; Determining data transmission time information based on the data volume, the estimated transmission duration, and the current operating state of the device; Among them, the message information includes the data transmission time information, the data transmission type and the receiving device information indicating that the data production device is the receiving device. The message information is transmitted through the first transmission mode, and the first transmission mode is determined according to the data transmission type.

2. The message transmission method according to claim 1, wherein: The first message includes a device group creation message, and in response to receiving the first message from the first device, determining message information matching the first message includes: In response to receiving the device group creation message from the first device, parsing the device group creation message to obtain group information of the first device group to be created, wherein the group information includes at least one of the following: identification information, description information, device range, access rights, and group management policy; generating a group record of the first device group according to the group information of the first device group; Determining that a message type matching the device group creation message is a new group broadcast type; Determining, based on the second device group to which the current device belongs, at least one device in the second device group other than the current device; The message information includes: the group record, the new group broadcast type, and the receiving device information indicating that the at least one device is a receiving device.

3. The message transmission method according to claim 1, wherein: The first message includes at least one of the following: a device group join message and a device group exit message; In response to receiving a first message from a first device, determining message information matching the first message includes: In response to receiving a first message from the first device, parsing the first message to obtain digital certificate information of the first device and a third device group; Verifying the digital certificate information of the first device and the device joining condition of the third device group respectively for the device group joining message to obtain group change information for the third device group; Verify the digital certificate information of the first device in response to the device group exit message to obtain group change information for the third device group; Determining that a message type matching the first message is a device group change type; The message information includes: the group change information, the device group change type, and receiving device information indicating that at least one device in the third device group is a receiving device.

4. The message transmission method according to claim 1, wherein: The first message includes a registration message; and in response to receiving the first message from the first device, determining message information matching the first message includes: In response to receiving a registration message from the first device, parsing the registration message; If the parsed registration message includes the registration information of the first device, the group information of the fourth device group, and the digital certificate information of the first device, verifying the digital certificate information of the first device and the device joining condition of the fourth device group, respectively, to obtain a registration result of the first device, wherein the fourth device group is the device group that the first device requested to join during registration; Determining that a message type matching the registration message is a registration result notification type; The message information is generated according to the registration result, wherein the message information includes the registration result, the registration result notification type, and receiving device information indicating that at least one device in the fourth device group and the first device are receiving devices.

5. The message transmission method according to any one of claims 1 to 4, characterized in that: The determining, according to the message type, a transmission mode for transmitting the message information includes: In a case where it is determined that the message type is the first type, determining the first transmission mode as the transmission mode for transmitting the message information; When it is determined that the message type is the second type, the second transmission mode is determined as the transmission mode for transmitting the message information, and the security level of the first type is higher than the security level of the second type.

6. The message transmission method according to claim 5, characterized in that: The first type includes at least one of the following: a device registration type, a registration result notification type, a device deregistration type, a deregistration result notification type, a data transmission type, a backup data recovery type, a network exception handling type, a fault handling type, and a type for managing a device group consisting of multiple devices; The type for managing a device group composed of multiple devices includes one of the following: a device group creation type, a new group broadcast type, a device group change type, a device group join type, and a device group exit type; The second type includes at least one of the following: a device discovery type, a device survival type, a backup notification type, a backup verification type, a network status type, and a fault alarm type.

7. The message transmission method according to claim 1, wherein: The first device includes a backup device, and the first message includes a backup data recovery message transmitted via the first transmission mode; The step of determining, in response to receiving a first message from a first device, message information matching the first message includes: In response to receiving the backup data restoration message from the backup device, parsing the backup data restoration message to obtain backup data; Determining that a message type matching the backup data restoration message is a backup verification type; Determine a first hash value of the backup data using a hash algorithm; In which, the message information includes the first hash value, the backup verification type and the receiving device information indicating that the backup device is the receiving device, and the message information is transmitted through the second transmission mode so that the backup device determines the integrity of the backup data based on the first hash value and the second hash value, and the second transmission mode is determined according to the backup verification type.

8. The message transmission method according to claim 1, wherein: The first message includes a network status message transmitted via a second transmission mode; The step of determining, in response to receiving a first message from a first device, message information matching the first message includes: In response to receiving the network status message from the first device, parsing the network status message to obtain network status information, wherein the network status information includes at least one of the following: processor usage, memory occupancy, network interface traffic, network delay duration, packet loss rate of the first device within a target time period, and bandwidth fluctuation range; Detecting the network status information to obtain a detection result; In the case where it is determined that the detection result is an abnormality, determining that the message type matching the network status message is a network abnormality processing type; generating first request information for obtaining operation information of the first device; Among them, the message information includes the first request information, the network exception processing type, and receiving device information indicating that the first device is the receiving device; the message information is transmitted through the first transmission method, and the first transmission method is determined according to the network exception processing type.

9. The message transmission method according to claim 8, characterized in that: The detecting of the network status information to obtain a detection result includes at least one of the following: Comparing the network status information with at least one network status threshold to obtain the detection result, wherein the network status threshold includes: a processor usage threshold, a memory occupancy threshold, a network interface traffic threshold, a network delay threshold, a packet loss rate threshold of the first device within a target time period, a bandwidth fluctuation threshold, and a comprehensive weighted threshold; The network status information is input into a prediction model, and a prediction result is output; and the detection result is determined based on the prediction result.

10. The message transmission method according to claim 1, wherein: The first message includes: a fault warning message transmitted through the second transmission mode, and the determining, in response to receiving the first message from the first device, message information matching the first message includes: In response to receiving the fault warning message from the first device, parsing the fault warning message to obtain a fault type and at least one second device associated with the first device; Determining that a message type matching the fault warning message is a fault handling type; generating second request information for obtaining operation information matching the fault type; Among them, the message information includes the second request information, the fault handling type, and receiving device information indicating that at least one of the second device and the first device is a receiving device; the message information is transmitted through the first transmission mode, and the first transmission mode is determined according to the fault handling type.

11. The message transmission method according to claim 1, wherein: The determining, according to the message type, a transmission mode for transmitting the message information includes: In the case where the message type is a service request, determining the requested target service from the message information; A transmission mode for transmitting the message information is determined according to the security level of the target service, wherein a target service with a higher security level corresponds to the first transmission mode, and a target service with a lower security level corresponds to the second transmission mode.

12. The message transmission method according to claim 1, wherein: The determining, according to the message type, a transmission mode for transmitting the message information includes: In a case where it is determined that the message type is a user-defined type, determining protocol version information from the message information; A transmission mode for transmitting the message information is determined according to the protocol version information and the custom type.

13. The message transmission method according to claim 1, wherein: The transmitting the message information to a receiving device matching the receiving device information by the transmission method includes: When the transmission mode is the first transmission mode, encrypting the message information using at least one encryption algorithm to obtain an encrypted message; transmitting the encrypted message to a receiving device that matches the receiving device information through the first transmission mode; In a case where the transmission mode is the second transmission mode, the message information is transmitted to a device matching the receiving device information via the second transmission mode.

14. The message transmission method according to claim 13, wherein: The step of encrypting the message information by using at least one encryption algorithm to obtain an encrypted message includes: Performing a hash calculation on the message information to obtain a first message digest; Encrypting the message information using a symmetric key of a symmetric encryption algorithm; The encrypted message includes the encrypted message information and the first message digest, so that the receiving device uses the symmetric key to decrypt the encrypted message information. The symmetric key is encrypted using the public key of the receiving device and then transmitted to the receiving device; the length of the symmetric key is determined according to the security level of the current device, and the length of the public key is determined according to the security level of the receiving device.

15. The message transmission method according to claim 14, characterized in that: The message transmission method further includes: If the symmetric key meets the expiration condition, a new symmetric key of a predetermined length is generated according to the security level of the current device; wherein the expiration condition includes at least one of the following: the number of times the symmetric key is used reaches a number threshold, and the validity period of the symmetric key reaches a duration threshold; The new symmetric key is encrypted using the public key of the receiving device, and the encrypted new symmetric key is transmitted to the receiving device through the first transmission mode, wherein the public key of the receiving device is updated regularly.

16. The message transmission method according to any one of claims 13 to 15, characterized in that: The message transmission method further includes: In response to detecting that a key anomaly exists in the current device, generating first message information according to identification information of the abnormal key, a message type indicating the key anomaly, and receiving device information indicating that at least one device in a second device group to which the current device belongs is a receiving device; transmitting the first message information to the at least one device through the second transmission mode; generating second message information according to the identification information, the message type indicating the key negotiation, and the receiving device information indicating that the target management device is the receiving device; encrypting the second message information using the backup public key stored in the hardware security device to obtain third message information; The third message information is transmitted to the target management device through the first transmission mode, so that the target management device generates a key for replacing the abnormal key.

17. The message transmission method according to claim 14, characterized in that: The message transmission method includes: In response to detecting that the network delay duration of the current device satisfies the delay condition, replacing the symmetric encryption algorithm with a predetermined encryption algorithm to encrypt the message information with the predetermined encryption algorithm, wherein resource consumption of the predetermined encryption algorithm is less than resource consumption of the symmetric encryption algorithm; In response to detecting that the current device is in a risky environment, a symmetric key with an increased length is determined, and the message information is encrypted using the symmetric key with the increased length.

18. The message transmission method according to claim 13, wherein: The message transmission method further includes: In response to not detecting a reply to the encrypted message within a preset time period, and if the number of transmissions of the encrypted message is less than a preset number of transmissions, retransmitting the encrypted message to a receiving device matching the receiving device information by using the first transmission mode, and updating the number of transmissions of the encrypted message; When the number of transmissions of the encrypted message is greater than or equal to the preset number of transmissions, an error message is displayed to the user.

19. The message transmission method according to claim 13, wherein: The transmitting the message information to a device matching the receiving device information by using the second transmission mode includes: Determine the length of the sliding window used to divide the sequence numbers based on the network status information of the current device; Determining a sequence number list of the message information according to the sliding window length; The message information and the sequence number list are transmitted to a receiving device that matches the receiving device information through the second transmission mode, so that the receiving device that matches the receiving device information responds to receiving the message information and the sequence number list, and determines the packet loss detection result for the message information based on the sequence number list.

20. A message transmission device, characterized in that: The message transmission device includes: a determining module configured to, in response to receiving a first message from a first device, determine message information matching the first message, wherein the message information includes receiving device information and a message type, and the message type includes a type for managing a device group consisting of multiple devices; a calling module, configured to call a transmission interface, determine a transmission mode for transmitting the message information according to the message type, and transmit the message information to a receiving device matching the receiving device information through the transmission mode, wherein the interface is applied to device discovery and service discovery scenarios; The transmission mode includes a first transmission mode and a second transmission mode using different transmission protocols, the security level of the transmission protocol used by the first transmission mode is higher than the security level of the transmission protocol used by the second transmission mode; the transmission interface is further used to encrypt the message information; The first message and the message information are transmitted via different transmission modes; the first device includes a data production device, and the first message includes a backup notification message transmitted via the second transmission mode; and the determining module is further configured to: In response to receiving the backup notification message from the data production device, parsing the backup notification message to obtain the data volume and estimated transmission time of the data to be backed up; Determining that a message type matching the backup notification message is a data transmission type; Determining data transmission time information based on the data volume, the estimated transmission duration, and the current operating state of the device; Among them, the message information includes the data transmission time information, the data transmission type and the receiving device information indicating that the data production device is the receiving device. The message information is transmitted through the first transmission mode, and the first transmission mode is determined according to the data transmission type.

21. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the message transmission method according to any one of claims 1 to 19.

22. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the message transmission method according to any one of claims 1 to 19 are implemented.

23. A computer program product comprising a computer program or instructions, characterized in that When the computer program or the instructions are executed by a processor, the steps of the message transmission method according to any one of claims 1 to 19 are implemented.

Citation Information

Patent Citations

  • Message transmission method and device and electronic equipment

    CN111756751A

  • A method for implementing equipment group and intercommunication between grouped equipments

    CN1691603A