Gateway access method, gateway access system and electronic device

By determining characteristic data between private cloud servers and public cloud servers, the gateway can achieve batch network access registration and authentication, which solves the problem of low gateway network access efficiency in the existing technology and improves network access efficiency and accuracy.

CN120811795BActive Publication Date: 2025-11-21GUANGDONG WODAWELL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511310284.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2025-11-21
Estimated Expiration
2045-09-15

AI Technical Summary

Technical Problem

In private cloud platforms, gateway network access efficiency is low, especially in multi-user, multi-device scenarios. Manual configuration is time-consuming and error-prone, while templates or configuration tools have compatibility issues, leading to network access failures.

Method used

After receiving the activation authentication request on the private cloud server, the system determines the characteristic data and sends it to the application. The application then determines the target gateway from the public cloud server based on the characteristic data and sends a network access activation request, thereby enabling the gateway to register, authenticate, and verify in batches.

Benefits of technology

It improves the efficiency and accuracy of gateway network access, ensuring that gateways can quickly and securely access the network in batches, reducing the time and error rate of manual configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811795B_ABST
    Figure CN120811795B_ABST
Patent Text Reader

Abstract

The application is suitable for the field of cloud computing technology, and provides a gateway network access method, a gateway network access system and an electronic device. The method comprises the following steps: after a private cloud server receives a start authentication request sent by an application end, the private cloud server determines characteristic data of the private cloud server and sends the characteristic data to the application end, so that the application end determines a target gateway from a public cloud server associated with the private cloud server according to the characteristic data; then, in the case that an activation request sent by the target gateway (i.e. a gateway with the same characteristic data) is received, the private cloud server sends a first activation result to the target gateway according to the activation request, so that the target gateway performs network access registration authentication with the public cloud server and the application end through the first activation result; finally, according to a network access registration authentication result fed back by the application end, the target gateway and the application end perform network access verification. The application can realize batch network access of gateways and improve the network access efficiency of the gateways.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of cloud computing technology, and in particular relates to a gateway access method, gateway access system and electronic device. Background Technology

[0002] In cloud computing, public cloud is a shared cloud computing platform built on the Internet, which is uniformly managed and operated by cloud service providers. Users can obtain elastic and scalable cloud service resources by registering an account or paying on demand. Private cloud is a dedicated cloud platform deployed in an exclusive environment within an organization. Its infrastructure can be located in the enterprise's local data center or third-party hosting facilities. Through strict access control mechanisms, it serves the organization and its branches exclusively, ensuring resource exclusivity and data privacy.

[0003] Currently, users can deploy different devices in a private cloud platform according to their needs (for example, users can deploy multiple gateways according to their project requirements, and each gateway can connect to multiple devices). In order for the gateway and its connected devices to access both the private and public cloud platforms, the gateway needs to be activated for network access. However, due to the large number of gateways and connected devices in a private cloud platform, the efficiency of gateway network access is relatively low. Summary of the Invention

[0004] This application provides a gateway network access method, a gateway network access system, and an electronic device, which can enable gateways to access the network in batches and improve gateway network access efficiency.

[0005] In a first aspect, embodiments of this application provide a gateway access method, applied to a private cloud server, including:

[0006] Upon receiving a startup authentication request from the application, characteristic data is determined and sent to the application, so that the application can determine the target gateway from the public cloud servers associated with the private cloud server based on the characteristic data; the characteristic data is data reflecting the unique network source of the private cloud server, and the target gateway is the gateway with the same characteristic data among the gateways associated with the public cloud server.

[0007] Upon receiving a network access activation request from the target gateway, a first activation result is sent to the target gateway according to the network access activation request, so that the target gateway can perform network access registration and authentication through the first activation result, the public cloud server, and the application terminal.

[0008] The system receives the network access registration and authentication result fed back by the application based on the first activation result, and performs network access verification based on the network access registration and authentication result, the target gateway, and the application.

[0009] Secondly, embodiments of this application provide a gateway access method, applied to a public cloud server, including:

[0010] Upon receiving a second query request from the application, a list of target gateways is sent to the application based on the second query request. The second query request includes feature data determined by the application from the private cloud server associated with the public cloud server. The feature data is data reflecting the unique network source of the private cloud server, and the target gateways in the list of target gateways are gateways with the same feature data.

[0011] Receive the network access registration request fed back by the application terminal based on the target gateway list, and send an activation command to the target gateway in the target gateway list;

[0012] Receive the second activation result fed back by the target gateway based on the activation command;

[0013] The network registration result is sent to the application based on the second activation result, so that the application performs network registration authentication based on the network registration result and the public cloud server to obtain the network registration authentication result, and performs network verification based on the network registration authentication result, the target gateway, and the private cloud server.

[0014] Thirdly, embodiments of this application provide a gateway network access system, including: a public cloud server, at least one private cloud server communicatively connected to the public cloud server, at least one gateway communicatively connected to the private cloud server, and an application terminal communicatively connected to both the public cloud server and the private cloud server, wherein gateways communicatively connected to the same private cloud server have the same characteristic data, and the characteristic data is data reflecting the unique network source of the private cloud server.

[0015] Fourthly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the gateway access method described in the first and second aspects above.

[0016] Fifthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the gateway access method described in the first and second aspects above.

[0017] Sixthly, embodiments of this application provide a computer program product that, when run on an electronic device, causes the electronic device to execute the gateway access method described in either the first or second aspect above.

[0018] The beneficial effects of the embodiments in this application compared with the prior art are:

[0019] In this embodiment, when the private cloud server receives a startup authentication request from the application, the private cloud server determines its own characteristic data and sends it to the application. The application then determines the target gateway (i.e., a gateway with the same characteristic data) based on this characteristic data. Upon receiving an activation request from the target gateway, the private cloud server sends a first activation result to the target gateway. This allows the target gateway to perform network registration authentication with the public cloud server and the application through the first activation result. Finally, based on the network registration authentication result returned by the application, the application performs network verification with the target gateway and the application. Since the aforementioned characteristic data reflects the unique network source of the private cloud server, it means that for all gateways with the same characteristic data—that is, any target gateway associated with a private cloud server—network registration authentication and verification can be performed with the public cloud server and the application based on their characteristic data. This enables batch network access for gateways and improves gateway network access efficiency. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a schematic flowchart of a gateway network access method for a private cloud server provided in an embodiment of this application;

[0022] Figure 2 This is a schematic flowchart of a gateway network access method for a public cloud server provided in an embodiment of this application;

[0023] Figure 3 This is an interaction diagram of a private cloud server and a public cloud server accessing the network through a gateway, provided in one embodiment of this application.

[0024] Figure 4 This is a schematic diagram of the gateway network access system provided in the embodiments of this application;

[0025] Figure 5 This is a schematic diagram illustrating the deployment scenarios of private cloud servers and public cloud servers provided in the embodiments of this application;

[0026] Figure 6 This is a schematic diagram of the gateway network access device provided in the embodiments of this application;

[0027] Figure 7 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0028] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0029] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0030] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0031] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0032] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0033] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0034] In a cloud computing environment, gateways, private clouds, and public clouds together constitute a complete end-to-end data communication system. Each plays a different role and achieves data exchange, storage, and computation through network connections. The public and private clouds are two independent and complete cloud environments, while the gateway acts as a bridge connecting devices to the cloud environment, primarily responsible for data acquisition, protocol conversion, and edge computing. For example, data with high sensitivity and requiring low-latency processing (such as environmental data collected by sensors connected to the gateway) can be uploaded to the private cloud environment for processing. Data requiring elastic scaling and intelligent analysis (such as data collected by smart devices connected to the gateway for AI analysis) can be uploaded to the public cloud environment for processing and analysis. Furthermore, data in the public and private cloud environments can be backed up to each other, enabling timely synchronization of cloud environments and operational analysis.

[0035] To achieve network communication, data exchange, and resource management between gateways, private clouds, and public clouds in the aforementioned data communication system, gateways need to be registered with the network. Currently, gateway registration is mainly achieved through the following methods: 1. Configuring individual gateways one by one, for example, manually configuring the parameters of each gateway; 2. Batch configuring network parameters for multiple gateways using templates or other configuration tools.

[0036] However, the above methods have the following problems in gateway network access: 1. Manual configuration has low accuracy and efficiency, and cannot be applied to gateway network access scenarios with multiple users and multiple devices. For example, when operators deploy thousands of 5G base station gateways, manual configuration will consume a lot of time and is prone to errors; 2. When using templates or other configuration tools for batch gateway network access, due to differences in gateway sources, device information, deployment environment, etc., templates or other configuration tools may have compatibility or incompatibility issues, leading to gateway network access failure and affecting the efficiency of gateway network access.

[0037] Therefore, the above method has the problem of low efficiency in gateway network access.

[0038] To improve the efficiency of gateway network access, this application provides a gateway network access method. In this method, after receiving a startup authentication request sent by an application, the private cloud server determines its own characteristic data and sends it to the application. This allows the application to determine the target gateway from the public cloud server associated with the private cloud server based on the characteristic data. Then, upon receiving an activation request from the target gateway (i.e., a gateway with the same characteristic data), the application sends a first activation result to the target gateway based on the activation request. This enables the target gateway to perform network access registration and authentication with the public cloud server and the application through the first activation result. Finally, based on the network access registration and authentication result returned by the application, the application performs network access verification with the target gateway and the application.

[0039] Figure 1 The diagram illustrates a flowchart of a gateway network access method provided in an embodiment of this application. The method is applied to a private cloud server and is described in detail below:

[0040] S11. Upon receiving an authentication request from the application, determine the feature data and send it to the application, so that the application can determine the target gateway from the public cloud server associated with the private cloud server based on the feature data; the feature data is data reflecting the unique network source of the private cloud server, and the target gateway is a gateway with the same feature data among the gateways associated with the public cloud server.

[0041] It should be understood that the aforementioned application can be a business system, client, or microservice that relies on the gateway for services. For example, the aforementioned application can be a client application installed on terminal devices (such as mobile phones, computers, tablets, etc.). The aforementioned application can be used to remotely control network communication between the gateway and private cloud servers and public cloud servers, manage data exchange between the gateway and private cloud servers and public cloud servers, and maintain business services between the gateway and private cloud servers and public cloud servers. The aforementioned private cloud server is a server deployed in the user's local environment that provides private cloud services. The aforementioned public cloud server is a server deployed in a third-party environment that provides public cloud services. Based on the characteristics of the cloud, the aforementioned public cloud server can communicate and connect with one or more private cloud servers to provide cloud services. Furthermore, the aforementioned private cloud server can connect to one or more gateways, and each gateway can connect to one or more terminal devices. The terminal devices connected to the aforementioned gateways include, but are not limited to, sensing devices, smart devices, and other IoT devices.

[0042] It should also be understood that the aforementioned characteristic data can be data reflecting the network connection status of the private cloud server, including network connection address, network connection identifier, network connection sequence code, etc. For example, the aforementioned characteristic data can be the IP address (e.g., IPv4, IPv6, etc.) of the external network interface to which the private cloud server is connected. Of course, to improve the security of the characteristic data transmission process, the aforementioned characteristic data can also be data processed using hash algorithms or encryption algorithms. For example, the aforementioned characteristic data can be a sequence code generated after processing the external network address (such as IPv4) using the MD5 hash algorithm.

[0043] Specifically, the application can send an authentication start request to one or more associated private cloud servers to initiate the authentication process. Upon receiving the authentication start request, each private cloud server can determine its own characteristic data and send it to the application to inform it that the authentication process has started. After obtaining the characteristic data of each private cloud server, the application can determine the target gateway from the gateways associated with the public cloud server based on the characteristic data, and then initiate the network registration process through the public cloud server to the target gateway. It should be noted that the authentication start request can be actively triggered by the application based on user actions, or it can be automatically triggered at a preset time; this is not limited here.

[0044] For example, suppose a user sends an authentication request to private cloud server A and private cloud server B through an application. After receiving the authentication request, private cloud server A sends its own characteristic data A (e.g., the external IPv4 address to which private cloud server A connects or a sequence code generated based on the external IPv4 address) to the application. Private cloud server B sends its own characteristic data B (e.g., the external IPv4 address to which private cloud server B connects or a sequence code generated based on the external IPv4 address) to the application. Then, the application determines the target gateway from the gateways associated with the public cloud server based on characteristic data A and characteristic data B. This includes determining the target gateways GW1(A)-GW2(A) corresponding to characteristic data A from the public cloud server, and determining the target gateways GW3(B)-GW5(B) corresponding to characteristic data B from the public cloud server. Then, the application can initiate the network registration process through the public cloud server to the determined target gateways (i.e., target gateways GW1(A)-GW2(A) and target gateways GW3(B)-GW5(B)).

[0045] In this embodiment of the application, the target gateways can be quickly identified in batches from the public cloud server using the aforementioned feature data, and the network access registration process can be initiated, thereby realizing the batch network access registration of gateways and improving the efficiency of gateway network access.

[0046] S12. Upon receiving the network access activation request sent by the target gateway, a first activation result is sent to the target gateway according to the network access activation request, so that the target gateway can perform network access registration and authentication through the first activation result, the public cloud server, and the application terminal.

[0047] It should be understood that the aforementioned first activation result reflects the activation status of the target gateway by the private cloud server based on the aforementioned activation request. For example, the aforementioned first activation result can reflect whether the target gateway is currently registering and authenticating. Of course, the aforementioned first activation result may also include information such as activation time and activation ID.

[0048] Specifically, after receiving the network registration process initiated by the public cloud server, the target gateway can send a network activation request to the corresponding private cloud server. The private cloud server activates and registers the target gateway according to the network activation request and sends back the first activation result to the target gateway. The target gateway can then inform the public cloud server and the application to register and authenticate the target gateway based on the first activation result, so that the target gateway can perform network registration and authentication with the public cloud server and the application through the first activation result.

[0049] The aforementioned network access registration authentication refers to authenticating the activation status of the target gateway. When the first activation result indicates that the target gateway is undergoing network access registration authentication, the target gateway can perform network access registration authentication with the public cloud server. After the network access registration authentication is passed on the public cloud server, the target gateway can then perform network access registration authentication with the application through the public cloud server.

[0050] It should be noted that when the first activation result reflects the failure of the target gateway's network registration and authentication, it indicates that the target gateway has failed to activate the private cloud server. In this case, in order to reduce the workload of the public cloud server, the target gateway may choose not to perform network registration and authentication with the public cloud server, or the target gateway may send activation failure information to the public cloud server so that operation and maintenance management can be carried out through the public cloud server.

[0051] For example, suppose private cloud server A corresponds to feature data A. After receiving the network access registration process initiated by private cloud server A, the target gateways GW1(A)-GW2(A) corresponding to feature data A send a network access activation request to private cloud server A. Private cloud server A activates and registers the target gateways GW1(A)-GW2(A) according to the network access activation request and feeds back the first activation result to the target gateways GW1(A)-GW2(A). When the first activation result reflects that the target gateways GW1(A)-GW2(A) are performing network access registration authentication, the target gateways GW1(A)-GW2(A) can perform network access registration authentication based on the above first activation result, public cloud server A, and application terminal.

[0052] In this embodiment, since the target gateways are gateways with the same characteristic data, it means that the private cloud server can receive the network access activation requests of the target gateways in batches and return the first activation result. This allows the target gateway to perform network access registration and authentication with the public cloud server and the application through the first activation result, thereby realizing the three-party registration and authentication of the target gateway by the private cloud server, the public cloud server, and the application, and improving the accuracy of the target gateway's network access activation.

[0053] S13. Receive the network access registration authentication result fed back by the application terminal based on the first activation result, and perform network access verification according to the network access registration authentication result, the target gateway, and the application terminal.

[0054] Specifically, when the private cloud server receives the network access registration authentication result from the application based on the first activation result, it can verify the network access registration authentication result. If the verification is successful, it can send a verification success result to the target gateway to complete the network access activation of the target gateway. Then, after receiving the confirmation result from the target gateway, it sends a verification completion result to the application to inform the application that the target gateway has been successfully activated. If the verification fails, it can send a verification failure result to the target gateway and stop the activation of the target gateway. At the same time, it sends a verification failure result to the application to inform the application that the target gateway activation has failed.

[0055] In this embodiment, the private cloud server performs network access verification based on the received network registration result, the target gateway, and the application terminal, which can further verify the network access of the target gateway and improve the accuracy of the target gateway's network access activation.

[0056] In this embodiment, when the private cloud server receives a startup authentication request from the application, the private cloud server determines its own characteristic data and sends it to the application. The application then determines the target gateway (i.e., a gateway with the same characteristic data) based on this characteristic data. Upon receiving an activation request from the target gateway, the private cloud server sends a first activation result to the target gateway. This allows the target gateway to perform network registration authentication with the public cloud server and the application through the first activation result. Finally, based on the network registration authentication result returned by the application, the application performs network verification with the target gateway and the application. Since the aforementioned characteristic data reflects the unique network source of the private cloud server, it means that for all gateways with the same characteristic data—that is, any target gateway associated with a private cloud server—network registration authentication and verification can be performed with the public cloud server and the application based on their characteristic data. This enables batch network access for gateways and improves gateway network access efficiency.

[0057] In some embodiments, the determination of feature data and its transmission to the application includes:

[0058] Send the first query request to the public cloud server associated with the aforementioned private cloud server;

[0059] The system receives the feature data fed back by the public cloud server based on the first query request and sends the feature data to the application.

[0060] It should be understood that private cloud servers and their associated public cloud servers can synchronize data in real time or periodically to improve data security. For example, a private cloud server can synchronize its connection characteristics and associated gateway information to the public cloud server. The aforementioned first query request may include information such as private cloud server information (e.g., private cloud server address), query ID, and query time.

[0061] Specifically, when a private cloud server receives an authentication request, it can send a first query request to the associated public cloud server. The public cloud server parses the first query request and then returns the corresponding feature data of the private cloud server. After receiving its own feature data, the private cloud server sends the feature data to the application to inform the application that the authentication process has been started.

[0062] It should be noted that after obtaining feature data from the public cloud server, it can be compared with local feature data. If the comparison is consistent, the feature data is sent to the application. If the comparison is inconsistent, the network access authentication process is stopped.

[0063] In this embodiment of the application, the private cloud server queries its own feature data through the associated public cloud server, which can improve the security of feature data query.

[0064] In some embodiments, when the target gateway sends an activation request, the network access activation request includes gateway information and authentication information. The gateway information may include gateway ID, gateway name, etc., and the authentication information may be information obtained by the target gateway in advance through identity authentication with the public cloud server. The authentication information can be used to authenticate the target gateway.

[0065] The above-mentioned sending of the first activation result to the target gateway according to the above-mentioned network access activation request includes:

[0066] Based on the aforementioned gateway information and authentication information, the aforementioned target gateway is activated and verified. If the activation verification is successful, the aforementioned first activation result is sent to the aforementioned target gateway. The aforementioned first activation result is used to indicate that the aforementioned target gateway is performing network access registration authentication with the aforementioned private cloud server.

[0067] Specifically, after receiving the network access activation request sent by the target gateway, the private cloud server can verify the gateway information in the network access activation request based on its own associated gateway information, and verify the authentication information in the network access activation request based on the authentication information synchronized from the public cloud server. After all the above verifications are successful, the private cloud server sends a first activation result to the target gateway to indicate that the target gateway is performing network access registration authentication with the private cloud server, that is, to notify the target gateway that the private cloud server is performing network access registration authentication based on the activation request.

[0068] For example, the target gateway GW1(A)-GW2(A) can send an activation request carrying the gateway ID (i.e., gateway information) and key information (i.e., pre-authenticated authentication information) to the private cloud server A. After the private cloud server A verifies the gateway ID and key information, it sends the first activation result to the target gateway GW1(A)-GW2(A) to indicate that the target gateway GW1(A)-GW2(A) is registering for network access.

[0069] It should be noted that when the private cloud server fails to verify gateway information and / or authentication information, it can send a first activation result to the target gateway to indicate that the target gateway's network registration authentication has failed.

[0070] In this embodiment, the private cloud server verifies the network access activation request using the gateway information and authentication information, which can perform activation verification on different target gateways and improve the accuracy of target gateway network access activation.

[0071] In some embodiments, after receiving a first activation result from a private cloud server indicating that the target gateway is performing network registration authentication with the private cloud server, the target gateway can perform network registration authentication with the public cloud server. After the network registration authentication is successful on the public cloud server, the target gateway performs network registration authentication with the application through the public cloud server. After the network registration authentication is successful, the application sends the network registration authentication result back to the private cloud server. The network registration authentication result includes target gateway information and target authentication information. The target authentication information is the authentication information of the target gateway that has been authenticated by the application. The target gateway information is the gateway information of the target gateway that has been authenticated by the application.

[0072] The above-mentioned network access verification based on the above-mentioned network access registration and authentication results, the above-mentioned target gateway, and the above-mentioned application terminal includes:

[0073] Verify the network access information for the aforementioned target gateway and target authentication information;

[0074] If the network access verification is successful, the network access verification result is sent to the target gateway that has been authenticated by the aforementioned application.

[0075] Upon receiving the network access verification confirmation result from the target gateway that has passed the above-mentioned application authentication based on the above-mentioned network access verification pass result, the network access verification completion result is sent to the above-mentioned application.

[0076] Specifically, the private cloud server can perform network access verification based on the aforementioned target gateway information and target authentication information. When both the target gateway information and target authentication information are verified successfully, the server sends a network access verification success result to the target gateway. After receiving the network access verification success result, each target gateway completes network access activation and sends the network access verification confirmation result back to the private cloud server. Based on the network access verification confirmation result, the private cloud server sends the network access verification completion result to the aforementioned application client, thereby notifying the application client's target gateway to complete network access activation.

[0077] In this embodiment, after the private cloud server verifies the network access registration authentication result received above, it completes the network access activation of the target gateway and notifies the application terminal, which can improve the security of network access activation.

[0078] Figure 2 The diagram illustrates a flowchart of a gateway network access method provided in an embodiment of this application. The method is applied to a public cloud server and is described in detail below:

[0079] S21. Upon receiving a second query request from the application, a list of target gateways is sent to the application according to the second query request. The second query request includes feature data determined by the application from the private cloud server associated with the public cloud server. The feature data is data reflecting the unique network source of the private cloud server, and the target gateways in the target gateway list are gateways with the same feature data.

[0080] It should be understood that the application can send an authentication request to one or more associated private cloud servers to initiate the authentication process. Upon receiving the authentication request, each private cloud server sends its own characteristic data to the application. The application then sends a second query request to the public cloud server based on this characteristic data. This characteristic data can reflect the network connection status of the private cloud server, including network connection address, network connection identifier, and network connection sequence code. Optionally, this characteristic data can be the IP address (e.g., IPv4, IPv6) of the external network interface to which the private cloud server is connected. Of course, to improve the security of the characteristic data transmission process, the characteristic data can also be data processed using hash algorithms or encryption algorithms. For example, the characteristic data can be a sequence code generated by processing an external network address (such as IPv4) using the MD5 hash algorithm.

[0081] Specifically, when the public cloud server receives the second query request, it filters gateways carrying the same feature data based on the feature data in the second query request to obtain target gateways, and generates a corresponding target gateway list, which is then sent to the application. The application can initiate network registration for the target gateways included in the target gateway list. The target gateway list can include gateway information, authentication information, and feature data for each target gateway. The gateway information can include gateway ID, gateway name, etc., and the authentication information can be information obtained by the target gateway through prior identity authentication with the public cloud server.

[0082] It should be noted that the second query request mentioned above may include one or more feature data. When multiple feature data are included, the public cloud server can filter the corresponding target gateways based on the feature data. For example, assuming the second query request includes feature data A and feature data B, the target gateway list obtained by the public cloud server through filtering may include target gateways GW1(A)-GW2(A) (i.e., the target gateways corresponding to feature data A) and target gateways GW3(B)-GW5(B) (i.e., the target gateways corresponding to feature data B).

[0083] In this embodiment of the application, the target gateways that need to be activated for network access can be quickly screened using the above-mentioned feature data, thereby achieving batch screening of target gateways and improving the efficiency of gateway network access.

[0084] It should be understood that, in some optional embodiments, before sending the target gateway list to the application based on the second query request upon receiving the second query request from the application, the method further includes:

[0085] In response to the first query request sent by the aforementioned private cloud server, the feature data is sent to the aforementioned private cloud server.

[0086] Specifically, to improve the security of feature data query, when the private cloud server receives the start authentication request sent by the application, it can send a first query request to the associated public cloud server; the public cloud server can respond to the first query request, query the feature data of the private cloud server, and feed it back to the private cloud server.

[0087] For example, after receiving the first query request from private cloud server A, the public cloud server can query the corresponding feature data (such as the external IPv4 address of private cloud server A or the sequence code corresponding to the external IPv4 address) and send it to the private cloud server. Then, after the private cloud server verifies the feature data, it will send the feature data back to the application.

[0088] In this embodiment of the application, querying the feature data of the private cloud server through the public cloud server can improve the accuracy of feature data query and enhance the security of gateway access to the network.

[0089] It should also be understood that, in some alternative embodiments, before sending the feature data to the private cloud server in response to the first query request sent by the private cloud server, the method further includes:

[0090] Receive authentication requests sent by the gateway;

[0091] If the above authentication request is successful, the authentication result is sent to the above gateway; the authentication result includes at least the above feature data.

[0092] Among them, the aforementioned gateways can be gateways that have not been activated in the network. Before activation, each of the aforementioned gateways can send an identity authentication request to the public cloud server. When the public cloud server receives the identity authentication request sent by each gateway, it can perform identity authentication based on the gateway information and confirm the characteristic data corresponding to each gateway. After the identity authentication is completed, it generates the authentication information of each gateway and sends the aforementioned characteristic data and authentication information to the corresponding gateway.

[0093] It should be noted that the above authentication methods can be key-based authentication, certificate-based authentication, etc., and no specific method is limited here.

[0094] In this embodiment, by performing identity authentication and determining corresponding feature data for gateways that have not yet been activated in the network, each gateway can carry corresponding authentication information and feature data, thereby improving the efficiency of subsequent screening of target gateways through feature data and improving the accuracy of subsequent authentication of target gateways.

[0095] S22. Receive the network access registration request fed back by the application terminal based on the target gateway list, and send an activation command to the target gateway in the target gateway list.

[0096] Specifically, the application sends a network access registration request to the public cloud server based on the target gateway list to initiate the network access registration process. The network access registration request may include gateway information, authentication information, and private cloud server information of the target gateway that needs to be activated. The private cloud server information may be information used to identify the private cloud server, such as the private cloud server address and private cloud server ID. After receiving the network access registration request, the public cloud server can verify the gateway information and authentication information of the target gateway included in the request. After successful verification, the public cloud server sends an activation command to the target gateway in the target gateway list.

[0097] The activation instruction can be used to instruct the target gateway to perform network access activation. The activation instruction can include gateway information, authentication information, and private cloud server information of the target gateway that needs to be activated for network access.

[0098] It should be noted that the above-mentioned network access registration request may also include some target gateways in the target gateway list. That is, users can select some target gateways from the target gateway list through the application and send the network access registration request corresponding to these target gateways to the public cloud server. After the public cloud server verifies the target gateways, it sends activation instructions to these target gateways.

[0099] In this embodiment, the network registration request fed back by the application terminal can quickly send activation instructions to all or part of the target gateways in the target gateway list, thereby improving the efficiency of gateway network activation.

[0100] S23. Receive the second activation result fed back by the target gateway based on the activation instruction.

[0101] Specifically, after the target gateway sends a network access activation request to the private cloud server, it can send a second activation result to the public cloud server to notify the public cloud server that the target gateway is registering for network access. After receiving the second activation result, the public cloud server can perform corresponding activation verification on the target gateway.

[0102] S24. Send the network registration result to the application terminal according to the second activation result, so that the application terminal performs network registration authentication based on the network registration result and the public cloud server, obtains the network registration authentication result, and performs network verification based on the network registration authentication result, the target gateway and the private cloud server.

[0103] Among them, the second activation result, the network access registration result, and the network access registration authentication result can all reflect the current network access registration status of the target gateway, including the gateway information, authentication information, and activation status of the current target gateway.

[0104] Specifically, the public cloud server can verify the target gateway based on the second activation result mentioned above. After successful verification, it sends a network access registration result indicating that the target gateway has been verified to the application. After receiving the verified network access registration result, the application can perform the corresponding registration authentication, obtain the network access registration authentication result, and send it back to the private cloud server. After the private cloud server verifies the network access registration authentication result, it can send a verification success result to the target gateway to complete the network access activation of the target gateway. Then, after receiving the confirmation result from the target gateway, it sends a verification completion result to the application to inform the application that the target gateway has been successfully activated.

[0105] It should be noted that the public cloud server verifies the target gateway based on the second activation result mentioned above. If the verification fails, it can send an access registration result indicating that the target gateway verification failed to the application, thereby informing the application that the target gateway authentication failed.

[0106] In this embodiment, the public cloud server determines a target gateway list based on the feature data in the second query request and sends it to the application. Then, it receives the network access registration request from the application based on the target gateway list, sends activation instructions to the target gateways in the list, and finally sends the network access registration result to the application based on the second activation result from the target gateway. This allows the application to perform network access registration authentication with the public cloud server based on the network access registration result. Since the aforementioned feature data reflects the unique network source of the private cloud server, it means that for all gateways with the same feature data—that is, target gateways associated with the public cloud server—network access registration authentication and verification can be performed based on the public cloud server, the private cloud server, and the application, thereby achieving batch network access for gateways and improving gateway network access efficiency.

[0107] In some embodiments, receiving the second activation result fed back by the target gateway based on the activation instruction includes:

[0108] The system receives the second activation result sent by the target gateway after obtaining the first activation result fed back from the private cloud server based on the activation instruction; the first activation result is used to indicate that after the private cloud server has verified the activation of the target gateway, the target gateway is performing network registration authentication with the private cloud server.

[0109] Specifically, after the public cloud server sends an activation command to the target gateway, the target gateway will send a network access activation request to the private cloud server based on the activation command. After receiving the network access activation request from the target gateway, the private cloud server can verify the gateway information and authentication information in the network access activation request. After successful verification, it sends a first activation result to the target gateway, indicating that the target gateway is performing network access registration and authentication with the aforementioned private cloud server. That is, it notifies the target gateway that the private cloud server is performing network access registration and authentication based on the activation request. Then, the target gateway will send the aforementioned second activation result back to the public cloud server.

[0110] In this embodiment, after receiving a first activation result indicating that the private cloud server has passed the activation verification of the target gateway, the target gateway sends a second activation result to the public cloud server, enabling the public cloud server to perform registration verification based on the received second activation result, thereby further improving the security of gateway registration verification.

[0111] To better illustrate how the gateway uses feature data to enable batch network access between private and public cloud servers, the following section will combine... Figure 3 Please refer to the explanation. Figure 3 The diagram shown illustrates the interaction between a private cloud server and a public cloud server when they connect to the network through a gateway.

[0112] The identity authentication phase involves the following steps:

[0113] A1: The gateway that has not been activated and is not connected to the network sends an authentication request to the public cloud server;

[0114] A2: The public cloud server completes identity authentication and returns authentication information and feature data. For example, the authentication information can be key information, certificate information, etc.; the feature data can be an external IP address (e.g., IPv4).

[0115] To initiate the authentication phase, follow these steps:

[0116] B1: The application sends a start authentication request to the private cloud server to initiate the authentication process. The start authentication request can be triggered by the user or automatically by the application. At the same time, the application can send start authentication requests to one or more private cloud servers.

[0117] B2: The private cloud server sends the first query request to the public cloud server to obtain its own characteristic data (such as IPv4);

[0118] B3: The public cloud server provides feedback on the characteristic data corresponding to the private cloud server;

[0119] B4: The private cloud server sends feature data to the application to inform it that the authentication process has been initiated.

[0120] During the registration phase, perform the following steps:

[0121] C1: The application sends a second query request to the public cloud server; the second query request may include feature data corresponding to one or more private cloud servers;

[0122] C2: The public cloud server filters target gateways based on feature data and sends the target gateway list to the application. The target gateway list may include gateway information (e.g., gateway ID), authentication information (e.g., authentication key), and feature data (e.g., IPv4).

[0123] C3: The application sends a network access registration request to the public cloud server based on the target gateway list to start the network access registration process. The network access registration request may include gateway information (such as gateway ID), authentication information (such as authentication key), and private cloud server information (such as private cloud server address addr) of the target gateway that needs to be activated for network access.

[0124] The following steps are performed during the network access registration and authentication phase:

[0125] D1: Send activation instructions to the target gateways in the target gateway list; the activation instructions may include gateway information (e.g., gateway ID), authentication information (e.g., authentication key), and private cloud server information (e.g., private cloud server address addr) of the target gateways that need to be activated for network access.

[0126] D2: The target gateway sends a network access activation request to the corresponding private cloud server based on the activation command to perform network access activation registration; the above network access activation request may include the target gateway's gateway information (such as gateway ID), authentication information (such as authentication information key), etc.

[0127] D3: After the private cloud server verifies the application, it sends back the first activation result. For example, the private cloud server activates and registers the target gateway according to the network access activation request and sends the first activation result to the target gateway, reflecting that the target gateway is conducting network access registration and authentication.

[0128] D4: The target gateway sends a second activation result to the public cloud server to inform the target gateway of its current registration status; for example, after receiving the first activation result indicating that the verification has passed, the target gateway can send a second activation result to the public cloud server indicating that the target gateway is undergoing network access registration and authentication.

[0129] D5: The public cloud server sends the network registration result to the application based on the second activation result; for example, after the second activation result is verified, the public cloud server can send a network registration result to the public cloud server reflecting that the target gateway is conducting network registration authentication.

[0130] The following steps are performed during the network access verification phase:

[0131] E1: After the application verifies the network registration result, it sends the network registration authentication result to the private cloud server. The network registration authentication result may include target gateway information (e.g., the gateway ID of the target gateway that has been authenticated) and target authentication information (e.g., the authentication information key of the target gateway that has been authenticated).

[0132] E2: The private cloud server verifies the network access registration authentication result, and sends the network access verification result to the target gateway after the verification is successful.

[0133] E3: After receiving the network access verification result, the target gateway completes the network access activation and sends back the network access verification confirmation result;

[0134] E4: The private cloud server sends the network access verification completion result to the above application, thereby notifying the target gateway of the application to complete the network access activation.

[0135] In this embodiment, the public cloud server and the gateways that have not yet been activated for network access perform identity authentication and determine feature data in advance. Then, the application can use the feature data to determine the target gateways in batches from the public cloud server and send them to the public cloud server. The public cloud server can then issue activation commands to the target gateways in batches, thereby enabling gateways to join the network in batches and improving the efficiency of gateway network access. At the same time, when each target gateway performs network access authentication with the private cloud server and the public cloud service based on its own gateway information and authentication information, since the private cloud server and the public cloud server can synchronize data, it means that both the private cloud server and the public cloud server can verify based on the authentication information and gateway information, thereby improving the accuracy and security of gateway network access.

[0136] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0137] Corresponding to the gateway network access method described in the above embodiments, Figure 4 A schematic diagram of the gateway network access system provided in the embodiments of this application is shown. For ease of explanation, only the parts related to the embodiments of this application are shown.

[0138] Reference Figure 4 The system includes: a public cloud server 401, at least one private cloud server 402 connected to the public cloud server 401, at least one gateway 403 connected to the private cloud server 402, and an application terminal 404 connected to both the public cloud server 401 and the private cloud server 402. The gateways connected to the same private cloud server 402 have the same characteristic data, which is data reflecting the unique network source of the private cloud server 402.

[0139] The interactions and execution processes between the aforementioned private cloud server, public cloud server, gateway, and application are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0140] To better illustrate the aforementioned gateway network access system, the following will combine... Figure 5Describe the deployment of private cloud servers and public cloud servers, refer to... Figure 5 The diagram illustrates a scenario of deploying private and public cloud servers. During installation and deployment, multiple gateways are connected via a router, and a single uplink egress switch is configured. This allows the private cloud server to communicate with the public cloud server through a single uplink WAN port, ensuring the consistency of the characteristic data across the entire local area network. In other words, all gateways connected to the private cloud server have the same characteristic data, thereby enabling batch network access for gateways through the characteristic data.

[0141] Corresponding to the gateway network access method described in the above embodiments, Figure 6 A schematic diagram of the gateway network access device provided in the embodiments of this application is shown. For ease of explanation, only the parts related to the embodiments of this application are shown.

[0142] Reference Figure 6 The device may include a first gateway access device 61 and a second gateway access device 62. The first gateway access device 61 is applied to a private cloud server and may include a feature data determination module 611, a first activation authentication module 612, and a first access verification module 613. The second gateway access device 62 is applied to a public cloud server and may include a gateway determination module 621, an activation module 622, a second activation authentication module 623, and a second access verification module 624.

[0143] Reference Figure 6 The first gateway network access device 61 includes:

[0144] The feature data determination module 611 is used to determine feature data and send it to the application terminal when receiving a startup authentication request sent by the application terminal, so that the application terminal can determine the target gateway from the public cloud server associated with the private cloud server based on the feature data; the feature data is data reflecting the unique network source of the private cloud server, and the target gateway is the gateway with the same feature data among the gateways associated with the public cloud server.

[0145] The first activation authentication module 612 is used to send a first activation result to the target gateway according to the network access activation request when it receives the network access activation request sent by the target gateway, so that the target gateway can perform network access registration authentication with the public cloud server and the application terminal through the first activation result.

[0146] The first network access verification module 613 is used to receive the network access registration authentication result fed back by the application terminal based on the first activation result, and to perform network access verification according to the network access registration authentication result, the target gateway, and the application terminal.

[0147] The second gateway network access device 62 includes:

[0148] The gateway determination module 621 is used to send a target gateway list to the application terminal according to the second query request when receiving the second query request sent by the application terminal; the second query request includes feature data determined by the application terminal from the private cloud server associated with the public cloud server, the feature data is data reflecting the unique network source of the private cloud server, and the target gateways in the target gateway list are gateways with the same feature data.

[0149] Activation module 622 is used to receive the network access registration request fed back by the application terminal based on the target gateway list, and send activation instructions to the target gateways in the target gateway list;

[0150] The second activation authentication module 623 is used to receive the second activation result fed back by the target gateway based on the activation command;

[0151] The second network access verification module 624 is used to send the network access registration result to the application terminal according to the second activation result, so that the application terminal performs network access registration authentication based on the network access registration result and the public cloud server to obtain the network access registration authentication result, and performs network access verification based on the network access registration authentication result, the target gateway, and the private cloud server.

[0152] It should be noted that the information interaction and execution process between the devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, which will not be repeated here.

[0153] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 7 As shown, the electronic device 7 of this embodiment includes: at least one processor 70 ( Figure 7 Only one is shown in the diagram), memory 71, and computer program 72 stored in said memory 71 and executable on said at least one processor 70. When the processor 70 executes said computer program 72, it implements the steps in any of the various method embodiments.

[0154] The electronic device 7 can be a desktop computer, laptop, handheld computer, or cloud server, etc. The electronic device may include, but is not limited to, a processor 70 and a memory 71. Those skilled in the art will understand that... Figure 7This is merely an example of electronic device 7 and does not constitute a limitation on electronic device 7. It may include more or fewer components than shown, or combine certain components, or different components. For example, the electronic device may also include input transmitting devices, network access devices, buses, etc.

[0155] The processor 70 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0156] In some embodiments, the memory 71 may be an internal storage unit of the electronic device 7, such as a hard disk or memory of the electronic device 7. The memory 71 may also be an external storage device of the electronic device 7, such as a plug-in hard disk, smart media card (SMC), secure digital card (SD), flash card, etc., equipped on the electronic device 7. Furthermore, the memory 71 may include both internal and external storage units of the electronic device 7. The memory 71 is used to store the operating system, applications, bootloader, data, and other programs, such as the program code of the computer program. The memory 71 can also be used to temporarily store data that has been sent or will be sent.

[0157] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the division of the functional units and modules is only described as an example. In practical applications, the functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0158] This application also provides a network device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement the steps in any of the various method embodiments.

[0159] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments.

[0160] This application provides a computer program product that, when run on an electronic device, enables the electronic device to perform the steps described in the various method embodiments.

[0161] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the embodiments described in this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a photographic device / electronic device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.

[0162] In the embodiments described, each embodiment has its own emphasis. For parts not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0163] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0164] In the embodiments provided in this application, it should be understood that the disclosed apparatus / network devices and methods can be implemented in other ways. For example, the apparatus / network device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0165] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0166] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A gateway network access method, characterized in that, Applications to private cloud servers include: Upon receiving a startup authentication request from the application, characteristic data is determined and sent to the application, so that the application can determine the target gateway from the public cloud servers associated with the private cloud server based on the characteristic data; the characteristic data is data reflecting the unique network source of the private cloud server, and the target gateway is the gateway with the same characteristic data among the gateways associated with the public cloud server. Upon receiving a network access activation request from the target gateway, a first activation result is sent to the target gateway according to the network access activation request, so that the target gateway can perform network access registration and authentication through the first activation result, the public cloud server, and the application terminal. The system receives the network access registration and authentication result fed back by the application based on the first activation result, and performs network access verification based on the network access registration and authentication result, the target gateway, and the application.

2. The gateway access method as described in claim 1, characterized in that, The process of determining feature data and sending it to the application includes: Send a first query request to the public cloud server associated with the private cloud server; The system receives feature data from the public cloud server based on the first query request and sends the feature data to the application.

3. The gateway network access method as described in claim 2, characterized in that, The network access activation request includes gateway information and authentication information; Sending the first activation result to the target gateway according to the network access activation request includes: The target gateway is activated and verified based on the gateway information and the authentication information. If the activation verification is successful, the first activation result is sent to the target gateway. The first activation result is used to indicate that the target gateway is performing network registration authentication with the private cloud server.

4. The gateway access method as described in any one of claims 1-3, characterized in that, The network access registration and authentication result includes target gateway information and target authentication information. The target authentication information is the authentication information of the target gateway that the application has authenticated. The target gateway information is the gateway information of the target gateway that the application has authenticated. The network access verification based on the network access registration and authentication result, the target gateway, and the application includes: The target gateway information and the target authentication information are verified for network access. If the network access verification is successful, the network access verification result is sent to the target gateway that has been authenticated by the application. Upon receiving the network access verification confirmation result from the target gateway that has passed the network access verification based on the network access verification pass result, the application sends the network access verification completion result to the application.

5. A gateway network access method, characterized in that, Applied to public cloud servers, including: Upon receiving a second query request from the application, a list of target gateways is sent to the application based on the second query request. The second query request includes feature data determined by the application from the private cloud server associated with the public cloud server. The feature data is data reflecting the unique network source of the private cloud server, and the target gateways in the list of target gateways are gateways with the same feature data. Receive the network access registration request fed back by the application terminal based on the target gateway list, and send an activation command to the target gateway in the target gateway list; Receive the second activation result fed back by the target gateway based on the activation command; The network registration result is sent to the application based on the second activation result, so that the application performs network registration authentication based on the network registration result and the public cloud server to obtain the network registration authentication result, and performs network verification based on the network registration authentication result, the target gateway, and the private cloud server.

6. The gateway network access method as described in claim 5, characterized in that, The step of receiving the second activation result fed back by the target gateway based on the activation instruction includes: The system receives the second activation result sent by the target gateway after obtaining the first activation result fed back from the private cloud server based on the activation instruction; the first activation result is used to indicate that after the private cloud server has passed the activation verification of the target gateway, the target gateway is performing network registration authentication with the private cloud server.

7. The gateway network access method as described in claim 5 or 6, characterized in that, Before sending the target gateway list to the application based on the second query request upon receiving the second query request, the method further includes: In response to the first query request sent by the private cloud server, the feature data is sent to the private cloud server.

8. The gateway network access method as described in claim 7, characterized in that, Before sending the feature data to the private cloud server in response to the first query request sent by the private cloud server, the method further includes: Receive authentication requests sent by the gateway; If the identity authentication request is successful, an identity authentication result is sent to the gateway; the identity authentication result includes at least the feature data.

9. A gateway network access system, characterized in that, include: A public cloud server, at least one private cloud server connected to the public cloud server, at least one gateway connected to the private cloud server, and an application terminal connected to both the public cloud server and the private cloud server, wherein gateways connected to the same private cloud server have the same characteristic data, which is data reflecting the unique network source of the private cloud server.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 4, and the method as described in any one of claims 5 to 8.

Citation Information

Patent Citations

  • Sharing management method for user data and user data management system

    CN115495422A

  • Service providing method and apparatus and electronic device

    US20210029110A1