Terminal equipment scanning method and system, electronic equipment and storage medium
By deploying proxy devices in the target network segment and employing UDP multicast scanning and encryption technology, the problems of limited scanning range and insufficient compatibility of terminal devices are solved, enabling efficient and secure management of terminal devices across network segments.
Patent Information
- Application Number
- CN202511136650.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-11-14
AI Technical Summary
In existing technologies, the scanning range of terminal devices is limited to the Layer 2 broadcast domain, making it difficult to cross VLANs and Layer 3 routers, and there are problems of insufficient compatibility and broadcast storms.
By deploying proxy devices in each target network segment, generating scan command packets using the TCP protocol, and performing UDP multicast scans, combined with HMAC-SHA256 and AES-256-CBC encryption, cross-network segment terminal device discovery and management can be achieved.
It significantly expands the scanning range, improves compatibility and stability, reduces network bandwidth usage and proxy device resource consumption, ensures data transmission security and integrity, and improves operation and maintenance efficiency.
Smart Images

Figure CN120956477A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) communication technology, and in particular to a terminal device scanning method, a terminal device scanning system, an electronic device, and a computer storage medium. Background Technology
[0002] With the continuous development of enterprise networks and Internet of Things (IoT) technologies, the number of connected terminal devices in networks is gradually increasing, such as personal computers (PCs), printers, smart devices, cameras, sensors, and so on within enterprises. In enterprise office scenarios, industrial automation systems, smart buildings, or security systems, maintenance personnel typically need to manage all terminal devices in the network in a unified manner, and monitor the type, status, access location, and changes of the devices to ensure network security, improve resource utilization, and achieve automated asset management.
[0003] In existing technologies, broadcast probing is typically performed using Layer 2 network protocols to automate the scanning and identification of terminal devices on the network, thereby managing all devices across the network. For example, a host broadcasts Address Resolution Protocol (ARP) requests or Network Basic Input / Output System (NetBIOS) requests within its local area network (LAN). If a terminal device is found at a given Internet Protocol (IP) address, it will return the corresponding response information (such as a Media Access Control (MAC) address) to the host, completing the terminal device scan. Based on this, the host collects the response information and constructs a device list for the corresponding network segment, thus enabling the management of the terminal devices.
[0004] In computer networks, Layer 2 network devices (such as Layer 2 switches) primarily forward data frames based on MAC addresses. For example, a broadcast data packet (such as an ARP request frame) with a destination MAC address of FF:FF:FF:FF:FF:FF indicates that the frame should be forwarded to all hosts within the same broadcast domain. However, Layer 3 network devices (such as Layer 3 switches and routers) make forwarding decisions based on the IP protocol and routing table rules at the network layer. This means that when a Layer 3 device receives a Layer 2 broadcast frame, it will not forward it to other broadcast domains but will discard the frame directly, thus limiting the broadcast to a single Layer 2 network. Therefore, existing Layer 2 broadcast requests (such as ARP and NetBIOS) cannot cross Layer 3 devices in the network topology, resulting in a limited scanning range and making them unsuitable for the Virtual Local Area Network (VLAN) segmentation and Layer 3 routing architecture widely used in modern enterprises.
[0005] Meanwhile, large-scale broadcast requests may cause ARP frames to flood the network, consuming link bandwidth resources and even triggering broadcast storms, affecting normal business traffic and network stability. In addition, these methods rely on the device's response to specific protocols. Some IoT terminal devices may have ARP responses disabled by default or not support NetBIOS, resulting in incomplete identification results and insufficient compatibility.
[0006] Therefore, existing technologies suffer from problems such as a small scanning range and insufficient compatibility. Summary of the Invention
[0007] Therefore, the purpose of this invention is to provide a terminal device scanning method.
[0008] A terminal device scanning method includes the following steps:
[0009] S1: Based on the TCP scan request packet and the registration information of the proxy device, generate a device scan instruction packet and send it to the proxy device;
[0010] The TCP scan request packet represents a request initiated by the user terminal and sent to the server via the TCP protocol, and includes one or more specified target network segments; the device scan instruction packet includes a globally unique task identifier, timeout, dynamic key, and filter code.
[0011] S2: Perform a UDP multicast scan on the local terminal devices according to the device scanning instruction packet to obtain information on all local terminal devices; wherein, the UDP multicast scan is performed by the proxy device;
[0012] S3: Classify and encrypt all local terminal device information, generate encrypted device data packets, and send them to the server;
[0013] S4: Decrypt and integrate the encrypted device data packets according to the dynamic key to form a device information list, and send it to the user terminal.
[0014] The terminal device scanning method described in this invention, compared with the prior art, deploys proxy devices in each target network segment and has the server uniformly schedule and execute the scanning tasks. This enables the scanning command to perform UDP multicast scanning locally through the proxy devices, thereby breaking through the Layer 2 broadcast domain restriction and realizing the discovery of VLANs and terminal devices across Layer 3 routers, effectively expanding the scanning coverage.
[0015] Meanwhile, the globally unique task identifier, dynamic key, and filter code included in the device scanning instruction package enable the scanning task to have higher controllability and security, prevent replay attacks, and adapt to the identification needs of multiple types of terminal devices, thereby significantly improving the compatibility and stability of the scanning process.
[0016] Furthermore, by encrypting and transmitting the scan results back and decrypting and integrating them on the server side, the security of information transmission and data integrity of terminal devices across network segments can be ensured, enabling centralized management and rapid identification of multiple network segments and types of terminal devices.
[0017] Furthermore, step S2 includes the following sub-steps:
[0018] When the agent device receives the device scan instruction packet, it parses it to obtain the task parameter information;
[0019] The task parameter information includes a task identifier, timeout, dynamic key, and filter code.
[0020] The task parameter information is uniformly encapsulated according to the UDP protocol to generate broadcast data packets;
[0021] The broadcast data packet is sent to the local area network where the current agent device is located, and waits for the local terminal devices to respond until all local terminal device information is obtained; wherein, the duration of waiting for the local terminal devices to respond is the timeout time in the task parameter information by default;
[0022] Step S3 further includes the following sub-steps:
[0023] Once all local terminal device information is obtained, it is categorized according to the task identifier in the task parameter information to form integrated terminal device information.
[0024] Based on the dynamic key carried in the task parameter information, the HMAC-SHA256 algorithm is used to calculate the hash digest of the integrated terminal device information to generate an HMAC check value.
[0025] Using AES-256-CBC mode, the HMAC checksum and the integrated terminal device information are encrypted based on the dynamic key in the task parameter information, and then uniformly encapsulated through the TCP protocol to generate encrypted device data packets, which are then sent to the server.
[0026] Accordingly, this invention achieves high efficiency and controllability in discovering terminal devices across network segments by parsing task parameter information and performing controlled UDP broadcast scanning at the proxy device end. This effectively breaks through the technical bottleneck of traditional Layer 2 broadcast being limited by the broadcast domain and significantly reduces the impact of broadcast on network bandwidth. At the same time, the proxy device only needs to send a broadcast data packet and collect response data once during the scanning task, without continuously monitoring network traffic or performing full packet capture. Therefore, its CPU and memory usage can be maintained below 5% for a long time. Compared with traditional proxy solutions based on network sniffing, which require continuous packet capture and have resource usage exceeding 30%, this invention significantly reduces the consumption of the proxy device's own performance and extends its stable operating time.
[0027] Furthermore, by generating an HMAC-SHA256 checksum before encryption and using AES-256-CBC mode for encryption, the confidentiality and integrity of the data transmitted back to the server are ensured during transmission, effectively preventing data from being tampered with or forged in a wide area network (WAN) environment, thereby significantly improving the overall system security and reliability.
[0028] Furthermore, when the agent device starts up for the first time, the agent device initiates a TCP connection request to the server;
[0029] After the server establishes a connection based on the TCP connection request, the proxy device sends a registration message to the server; wherein, the registration message contains information about the proxy device, including the unique identifier of the proxy device and the network segment to which it belongs;
[0030] The server parses the registration message and writes the parsing result into the agent device registry, saving it as the agent device's registration information.
[0031] Meanwhile, the server sends TCP heartbeat packets to the proxy devices in the proxy device registry at a preset time interval. If any proxy device does not respond for multiple consecutive heartbeat cycles, it is considered that the proxy device has gone offline, and its status is updated or its information is removed from the proxy device registry.
[0032] Accordingly, the present invention automatically initiates a Transmission Control Protocol (TCP) connection request to the server when the proxy device is first started, and actively reports the unique identifier and network segment information after the connection is established, so that the server can immediately include the proxy device in the proxy device registry and continuously send TCP heartbeat packets for online status monitoring according to a preset time interval.
[0033] Compared to the method that requires maintenance personnel to manually configure the network parameters of proxy devices and enter their network segment and IP address information, this invention can automatically complete the registration and status maintenance of proxy devices when the network structure changes dynamically (such as the addition or removal of subnets, replacement or migration of proxy devices). This effectively ensures the real-time and accuracy of the proxy device list, significantly improves the response speed and scheduling efficiency of cross-network segment terminal device scanning tasks, and reduces the management burden and configuration error risk caused by manual intervention.
[0034] Furthermore, step S4 includes the following sub-steps:
[0035] Upon receiving the encrypted device data packet, the encrypted device data packet is decrypted using the dynamic key to obtain the original terminal device information and the corresponding HMAC checksum.
[0036] Based on the dynamic key, the original terminal device information is hashed using the HMAC-SHA256 algorithm, and the hash result is matched with the corresponding HMAC checksum. If they do not match, the original terminal device information is considered to have been tampered with, and the data packet is recorded as an anomaly and discarded. If they match, the original terminal device information has not been tampered with.
[0037] Based on the task identifier, all verified original terminal device information is deduplicated and categorized, and integrated into a structured device information list.
[0038] The structured list of equipment information is visualized, and the visualized content is pushed to the user terminal via the TCP protocol.
[0039] Accordingly, this invention, by performing integrity verification on the received encrypted terminal device information, can effectively detect and eliminate data packets that have been tampered with or forged during transmission, ensuring the authenticity and reliability of the data results. Simultaneously, by using globally unique task identifiers to deduplicate and categorize data, duplicate records or interference from old data are avoided, ensuring that the final generated structured device information list can completely and accurately reflect the current network status.
[0040] A terminal device scanning system includes a scanning instruction generation unit, a local terminal device scanning unit, a classification and encryption unit, and a data integration unit.
[0041] The scan instruction generation unit is deployed on the server and is used to generate a device scan instruction packet based on the TCP scan request packet and the registration information of the proxy device, and send it to the proxy device.
[0042] The TCP scan request packet represents a request initiated by the user terminal and sent to the server via the TCP protocol, and includes one or more specified target network segments; the device scan instruction packet includes a globally unique task identifier, timeout, dynamic key, and filter code.
[0043] The local terminal device scanning unit is deployed on the proxy device and is used to perform UDP multicast scanning on local terminal devices according to the device scanning instruction packet to obtain information on all local terminal devices.
[0044] The classification and encryption unit is deployed on the agent device and is used to classify and encrypt all local terminal device information, generate encrypted device data packets, and send them to the server.
[0045] The data integration unit is deployed on the server and is used to decrypt and integrate encrypted device data packets according to the dynamic key to form a device information list, which is then sent to the user terminal.
[0046] To better understand and implement this invention, the following detailed description is provided in conjunction with the accompanying drawings. Attached Figure Description
[0047] Figure 1 This is a simplified architectural diagram of the terminal device scanning system described in this invention;
[0048] Figure 2 This is a simplified structural diagram of the terminal device scanning system described in this invention;
[0049] Figure 3 This is a simplified flowchart illustrating the terminal device scanning method described in this invention. Detailed Implementation
[0050] To address the limitations of existing technologies, such as limited scanning range and insufficient compatibility, this invention generates a device scanning instruction packet for a proxy device based on a TCP scan request packet sent from a user terminal to the server and the registration information of the proxy device on the server. The proxy device then performs a UDP multicast scan on its local terminal devices according to the device scanning instruction packet, obtaining information on all local devices. This information is then categorized and encrypted to generate encrypted device data packets, which are sent to the server. Finally, the server decrypts and integrates the encrypted device data packets using a dynamic key to form information on all devices, which is then sent to the user terminal.
[0051] Accordingly, this invention achieves automated discovery of terminal devices across network segments by deploying independent proxy devices in each target network segment, effectively breaking through the technical bottleneck of traditional Layer 2 broadcast being limited by the broadcast domain and significantly expanding the scanning range; at the same time, by adopting controlled single UDP multicast instead of continuous packet capture mode, the occupation of network bandwidth and proxy device resources is reduced, effectively improving the stability and compatibility of system operation.
[0052] Ultimately, by centrally integrating information from multiple types of terminal devices across network segments via servers, operations and maintenance personnel can easily manage, identify, and locate the entire network, thereby improving operational efficiency and asset management accuracy.
[0053] Based on the above design, this invention proposes a terminal device scanning method and a terminal device scanning system based on the method.
[0054] Please also refer to Figure 1 , Figure 2 and Figure 3 , Figure 1 This is a simplified architectural diagram of the terminal device scanning system described in this invention. Figure 2 This is a simplified structural diagram of the terminal device scanning system described in this invention. Figure 3 This is a simplified flowchart illustrating the terminal device scanning method described in this invention.
[0055] The terminal device scanning system of the present invention includes a scanning instruction generation unit 1, a local terminal device scanning unit 2, a classification and encryption unit 3, and a data integration unit 4.
[0056] The scan instruction generation unit 1 is deployed on the server and is used to perform step S1: generate a device scan instruction packet based on the TCP scan request packet and the registration information of the proxy device, and send it to the proxy device.
[0057] Specifically, the target network segment in the scan request packet is used as an index to find the registration information of the corresponding proxy device, and the information of the proxy device is uniformly encapsulated to generate a structured device scan instruction packet.
[0058] The TCP (Transmission Control Protocol) scan request packet represents a request initiated by the user terminal and sent to the server via the TCP protocol. It includes one or more specified target network segments, such as subnets:["192.168.1.0 / 24", "10.10.2.0 / 24"];
[0059] The registration information of the proxy devices is the identification information of each proxy device stored in the proxy device registry maintained on the server. By default, it includes the unique identifier of the proxy device, the device type, and the network segment information to which it belongs. It is stored through the following steps:
[0060] When the agent device starts up for the first time, it initiates a TCP connection request to the server.
[0061] After the server establishes a connection based on the TCP connection request, the proxy device sends a registration message to the server. The registration message contains information about the proxy device, specifically including the unique identifier of the proxy device and the network segment it belongs to, for example: "{"proxyID":"10001","type":"gateway","subnet":"192.168.1.0 / 24"}.
[0062] The unique identifier of the proxy device is a combination of IP address and MAC address by default.
[0063] Finally, the server parses the registration message and writes the parsing result into the agent device's registry, saving it as the agent device's registration information.
[0064] Furthermore, in order to maintain the validity of the online status of the proxy devices, the server sends TCP heartbeat packets to the proxy devices in the proxy device registry at a preset time interval. If a proxy device does not respond for several consecutive heartbeat cycles, it is considered that the proxy device has gone offline, and its status is updated or its information is removed from the proxy device registry to ensure the validity of the online status of the proxy devices.
[0065] It should be noted that the fields in the agent device registry can be flexibly expanded according to the actual deployment environment, and the present invention does not impose specific limitations on this; at the same time, the generated device scanning instruction package may include a timeout period, a dynamic key, and a filter code when uniformly packaged; the timeout period is used to preset the maximum time for waiting for a scan response; the dynamic key is used to encrypt communication; the filter code is used to control the scanning range according to the target network segment or the type of device terminal.
[0066] Furthermore, to prevent abnormal statistics caused by duplicate response data or replay attacks by attackers forging old data, a globally unique task identifier is generated and embedded in the device scan instruction package before uniform encapsulation and generation of structured device scan instruction packages, to ensure that the device scan instruction package is unique throughout the scanning system.
[0067] The local terminal device scanning unit 2 is deployed on the proxy device and is used to perform step S2: perform UDP multicast scanning on the local terminal devices according to the device scanning instruction packet to obtain information on all local terminal devices.
[0068] In general, traditional technologies require the host to send Layer 2 broadcast requests such as ARP or NetBIOS directly to discover terminal devices in the network. However, such broadcasts are limited by the boundaries of the broadcast domain and cannot cross VLANs or Layer 3 routers, resulting in a limited scanning range. Furthermore, such broadcast behavior is difficult to control precisely and can easily trigger broadcast storms, causing network congestion.
[0069] To this end, the present invention deploys proxy devices in each target network segment as local execution nodes for scanning tasks, and performs controlled broadcast scanning, i.e., UDP multicast scanning, through the proxy devices to improve the ability to discover terminal devices across network segments. Specifically, this includes the following steps:
[0070] When the agent device receives the device scan instruction packet, it parses it to obtain the task parameter information.
[0071] The task parameter information includes a task identifier, timeout, dynamic key, and filter code, which are matched one-to-one with the information carried in the device scanning instruction packet.
[0072] Next, the task parameter information is uniformly encapsulated according to the UDP (User Datagram Protocol) protocol, a broadcast data packet is generated, and the broadcast data packet is sent to the local area network where the current agent device is located (such as the preset port 5000), and waits for the local terminal device to respond until all local terminal device information is obtained;
[0073] When the local terminal device receives the broadcast data packet, if the filtering conditions are met, it returns its own terminal device information to the proxy device via the UDP protocol.
[0074] The broadcast data packet by default includes a task identifier and a filter code, which are used to guide the terminal device to identify the scanning task and return the necessary information. The terminal device information by default includes the terminal device's own IP address, MAC address and other related information. The time limit for waiting for the local terminal device to respond is the timeout time in the task parameter information by default.
[0075] Since the proxy device is deployed within the target network segment, this invention effectively overcomes the structural limitation that traditional broadcasting cannot cross network segments; at the same time, the filter code, timeout and other fields configured in the task parameters can precisely control the scope and target of broadcasting behavior, greatly improving the controllability and efficiency of scanning, and significantly reducing interference with normal network traffic.
[0076] The classification and encryption unit 3 is deployed on the agent device and is used to perform step S3: classify and encrypt all local terminal device information, generate encrypted device data packets, and send them to the server.
[0077] Specifically, after obtaining all local terminal device information, the information is categorized according to the task identifier in the task parameter information to form integrated terminal device information.
[0078] Next, using AES-256-CBC mode (Advanced Encryption Standard 256-bit Cipher Block Chaining), the integrated terminal device information is encrypted according to the dynamic key in the task parameter information, and then uniformly encapsulated through the TCP protocol to generate encrypted device data packets, which are then sent to the server.
[0079] Accordingly, this invention achieves effective data integration through classification and encryption, while ensuring the security and uniqueness of data transmission, and preventing man-in-the-middle attacks and duplicate data interference.
[0080] Furthermore, to prevent device information from being tampered with or forged during transmission, before encrypting the integrated terminal device information, the HMAC-SHA256 algorithm (Hash-based Message Authentication Code - Secure Hash Algorithm 256) is used to calculate the hash digest of the integrated terminal device information based on the dynamic key carried in the task parameter information, generating an HMAC checksum. This checksum is then encrypted and uniformly encapsulated together with the integrated terminal device information, thereby ensuring the security and reliability of the data during transmission.
[0081] It should be noted that, in terms of data security design, this invention distinguishes the security risks between the communication environment between the agent device and the terminal device within a local area network (LAN) and the public network or cross-network segment communication environment where the agent device transmits data back to the server. Specifically, since UDP broadcasts and responses occur within physically or logically isolated LANs and propagate only within the same subnet, the risk of data tampering or eavesdropping is low. Therefore, no additional encryption is needed at this stage to avoid increasing network load.
[0082] When the proxy device sends the scan results back to the server via the TCP protocol, the communication path may pass through a Wide Area Network (WAN) or cross an untrusted Layer 3 network environment, which significantly reduces security. Therefore, before sending the results back, a hash-based message authentication code (HMAC) verification value must be generated based on the dynamic key. The HMAC verification value and the integrated terminal device information are then encrypted using Advanced Encryption Standard 256-bit key length cipher block linking mode (AES-256-CBC) to ensure both the confidentiality and integrity of the data during transmission and effectively prevent man-in-the-middle attacks, data tampering, and forgery.
[0083] The data integration unit 4 is deployed on the server and is used to perform step S4: decrypt and integrate the encrypted device data packets according to the dynamic key to form a device information list and send it to the user terminal.
[0084] Specifically, after receiving the encrypted device data packet, the encrypted device data packet is decrypted according to the dynamic key to obtain the original terminal device information and the corresponding HMAC checksum.
[0085] Next, based on the dynamic key, the HMAC-SHA256 algorithm is used to calculate the hash digest of the original terminal device information, and the calculation result is matched with the corresponding HMAC checksum. If they do not match, it is considered that the original terminal device information has been tampered with, and the data packet is recorded as an abnormal information and discarded. If they match, it means that the original terminal device information has not been tampered with.
[0086] Then, based on the task identifier, all verified original terminal device information is deduplicated and categorized, and integrated into a structured device information list. The device information list includes by default fields such as the terminal device's IP address, MAC address, type, and response timestamp.
[0087] The structured list of equipment information is visualized, and the visualized content is pushed to the user terminal via the TCP protocol, which makes it convenient for maintenance personnel to manage, identify and locate all terminal devices in the network in a unified manner.
[0088] Accordingly, by integrating data from the server, the integrity, security, and real-time nature of the discovery process for terminal devices across network segments are ensured, enabling centralized management of multiple network segments and types of terminal devices.
[0089] It should be noted that when integrating data, the server uses the globally unique task identifier and corresponding timestamp in the device scanning instruction packet to retain only the latest response data in each task, avoiding statistical bias or replay attacks caused by repeated data transmission. In addition, since each agent device is deployed in a physically or logically isolated subnet and only responds to terminal devices within its own registered network segment, the agents do not interfere with each other during task execution, enabling efficient collection of device information and accurate deduplication integration.
[0090] Compared to existing technologies, this invention deploys the proxy device within the target network segment, enabling direct UDP multicast scanning within that segment. This effectively overcomes the limitations of Layer 2 broadcasts being restricted by the broadcast domain, supports VLAN traversal and Layer 3 routing architectures, and significantly expands the scanning coverage.
[0091] Meanwhile, by using single-time controlled UDP multicast instead of the traditional continuous packet capture mode, the proxy device's CPU and memory usage during scanning is less than 5%, which is far lower than that of traditional sniffing proxy solutions. Furthermore, the broadcast behavior can be precisely controlled in terms of range, frequency, and target type according to task parameters, reducing the impact on network bandwidth and business traffic.
[0092] In addition, by enabling the proxy device to establish a TCP connection with the server and complete automatic registration upon first startup, this invention eliminates the tedious process of manually configuring and maintaining the proxy address, thereby allowing the proxy device to dynamically adapt to changes in network topology and subnet structure, and improving the system's flexibility and maintainability.
[0093] Accordingly, the present invention solves the problems of limited scanning range and insufficient compatibility in the prior art, and significantly improves network performance consumption, security and automated operation and maintenance capabilities.
[0094] Based on the same inventive concept, this application also provides an electronic device, which can be a server, desktop computing device, or mobile computing device (e.g., laptop computing device, handheld computing device, tablet computer, netbook, etc.) or other terminal device. The device includes one or more processors and a memory, wherein the processor is used to execute a program to implement the terminal device scanning method of the embodiments of the present invention; the memory is used to store computer programs executable by the processor.
[0095] Based on the same inventive concept, this application also provides a computer-readable storage medium, corresponding to the aforementioned embodiment of a terminal device scanning method, wherein the computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps of the terminal device scanning method described in any of the above embodiments.
[0096] This application may take the form of a computer program product implemented on one or more storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing program code. Computer storage media include permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information may be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to: phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0097] The embodiments described above are merely examples of several implementations of the present invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and the present invention also intends to include these modifications and variations.
Claims
1. A terminal device scanning method, characterized in that, Includes the following steps: S1: Based on the TCP scan request packet and the registration information of the proxy device, generate a device scan instruction packet and send it to the proxy device; The TCP scan request packet represents a request initiated by the user terminal and sent to the server via the TCP protocol, and includes one or more specified target network segments; the device scan instruction packet includes a globally unique task identifier, timeout, dynamic key, and filter code. S2: Perform a UDP multicast scan on the local terminal devices according to the device scanning instruction packet to obtain information on all local terminal devices; wherein, the UDP multicast scan is performed by the proxy device; S3: Classify and encrypt all local terminal device information, generate encrypted device data packets, and send them to the server; S4: Decrypt and integrate the encrypted device data packets according to the dynamic key to form a device information list, and send it to the user terminal.
2. The terminal device scanning method according to claim 1, characterized in that, Step S2 further includes the following sub-steps: When the agent device receives the device scan instruction packet, it parses it to obtain the task parameter information; The task parameter information includes a task identifier, timeout, dynamic key, and filter code. The task parameter information is uniformly encapsulated according to the UDP protocol to generate broadcast data packets; The broadcast data packet is sent to the local area network where the current agent device is located, and waits for the local terminal devices to respond until all local terminal device information is obtained; wherein, the duration of waiting for the local terminal devices to respond is the timeout time in the task parameter information by default; Step S3 further includes the following sub-steps: Once all local terminal device information is obtained, it is categorized according to the task identifier in the task parameter information to form integrated terminal device information. Based on the dynamic key carried in the task parameter information, the HMAC-SHA256 algorithm is used to calculate the hash digest of the integrated terminal device information to generate an HMAC check value. Using AES-256-CBC mode, the HMAC checksum and the integrated terminal device information are encrypted based on the dynamic key in the task parameter information, and then uniformly encapsulated through the TCP protocol to generate encrypted device data packets, which are then sent to the server.
3. The terminal device scanning method according to claim 2, characterized in that, When the agent device starts up for the first time, the agent device initiates a TCP connection request to the server; After the server establishes a connection based on the TCP connection request, the proxy device sends a registration message to the server; wherein, the registration message contains information about the proxy device, including the unique identifier of the proxy device and the network segment to which it belongs; The server parses the registration message and writes the parsing result into the agent device registry, saving it as the agent device's registration information. Meanwhile, the server sends TCP heartbeat packets to the proxy devices in the proxy device registry at a preset time interval. If any proxy device does not respond for multiple consecutive heartbeat cycles, it is considered that the proxy device has gone offline, and its status is updated or its information is removed from the proxy device registry.
4. The terminal device scanning method according to claim 3, characterized in that, Step S4 further includes the following sub-steps: Upon receiving the encrypted device data packet, the encrypted device data packet is decrypted using the dynamic key to obtain the original terminal device information and the corresponding HMAC checksum. Based on the dynamic key, the original terminal device information is hashed using the HMAC-SHA256 algorithm, and the hash result is matched with the corresponding HMAC checksum. If they do not match, the original terminal device information is considered to have been tampered with, and the data packet is recorded as an anomaly and discarded. If they match, the original terminal device information has not been tampered with. Based on the task identifier, all verified original terminal device information is deduplicated and categorized, and integrated into a structured device information list. The structured list of equipment information is visualized, and the visualized content is pushed to the user terminal via the TCP protocol.
5. A terminal device scanning system, characterized in that, It includes a scan instruction generation unit, a local terminal device scanning unit, a classification and encryption unit, and a data integration unit; The scan instruction generation unit is deployed on the server and is used to generate a device scan instruction packet based on the TCP scan request packet and the registration information of the proxy device, and send it to the proxy device. The TCP scan request packet represents a request initiated by the user terminal and sent to the server via the TCP protocol, and includes one or more specified target network segments; the device scan instruction packet includes a globally unique task identifier, timeout, dynamic key, and filter code. The local terminal device scanning unit is deployed on the proxy device and is used to perform UDP multicast scanning on local terminal devices according to the device scanning instruction packet to obtain information on all local terminal devices. The classification and encryption unit is deployed on the agent device and is used to classify and encrypt all local terminal device information, generate encrypted device data packets, and send them to the server. The data integration unit is deployed on the server and is used to decrypt and integrate encrypted device data packets according to the dynamic key to form a device information list, which is then sent to the user terminal.
6. The terminal device scanning system according to claim 5, characterized in that, The local terminal device scanning unit further includes performing the following sub-steps: When the agent device receives the device scan instruction packet, it parses it to obtain the task parameter information; The task parameter information includes a task identifier, timeout, dynamic key, and filter code. The task parameter information is uniformly encapsulated according to the UDP protocol to generate broadcast data packets; The broadcast data packet is sent to the local area network where the current agent device is located, and waits for the local terminal devices to respond until all local terminal device information is obtained; wherein, the duration of waiting for the local terminal devices to respond is the timeout time in the task parameter information by default; The classification and encryption unit further includes performing the following sub-steps: Once all local terminal device information is obtained, it is categorized according to the task identifier in the task parameter information to form integrated terminal device information. Based on the dynamic key carried in the task parameter information, the HMAC-SHA256 algorithm is used to calculate the hash digest of the integrated terminal device information to generate an HMAC check value. Using AES-256-CBC mode, the HMAC checksum and the integrated terminal device information are encrypted based on the dynamic key in the task parameter information, and then uniformly encapsulated through the TCP protocol to generate an encrypted device data packet, which is then sent to the server.
7. The terminal device scanning system according to claim 6, characterized in that, When the agent device starts up for the first time, the agent device initiates a TCP connection request to the server; After the server establishes a connection based on the TCP connection request, the proxy device sends a registration message to the server; wherein, the registration message contains information about the proxy device, including the unique identifier of the proxy device and the network segment to which it belongs; The server parses the registration message and writes the parsing result into the agent device registry, saving it as the agent device's registration information. Meanwhile, the server sends TCP heartbeat packets to the proxy devices in the proxy device registry at a preset time interval. If any proxy device does not respond for multiple consecutive heartbeat cycles, it is considered that the proxy device has gone offline, and its status is updated or its information is removed from the proxy device registry.
8. The terminal device scanning system according to claim 7, characterized in that, The data integration unit further includes performing the following sub-steps: Upon receiving the encrypted device data packet, the encrypted device data packet is decrypted using the dynamic key to obtain the original terminal device information and the corresponding HMAC checksum. Based on the dynamic key, the original terminal device information is hashed using the HMAC-SHA256 algorithm, and the hash result is matched with the corresponding HMAC checksum. If they do not match, the original terminal device information is considered to have been tampered with, and the data packet is recorded as an anomaly and discarded. If they match, the original terminal device information has not been tampered with. Based on the task identifier, all verified original terminal device information is deduplicated and categorized, and integrated into a structured device information list. The structured list of equipment information is visualized, and the visualized content is pushed to the user terminal via the TCP protocol.
9. An electronic device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements a terminal device scanning method as described in any one of claims 1-4.
10. A computer-readable storage medium storing computer-executable instructions, characterized in that, When the computer-executable instructions are executed by the processor, they implement a terminal device scanning method as described in any one of claims 1-4.
Citation Information
Patent Citations
Method for scanning computer in Local Area Network (LAN) by cross-network segment
CN101888317A
Exposing network printers to wi-fi clients
CN104254844A
Network equipment scanning method and system and related devices
CN104796388A
Multi-device control device and system based on browser
CN106941500A
Flow proxy method and device, electronic equipment and storage medium
CN114902635A