Network device remote access method, system, device, medium and program product
By configuring reverse and forward proxies, the problem of complex remote access processes for network devices is solved, enabling secure and portable access to network devices, simplifying terminal configuration, and ensuring access security and control.
Patent Information
- Application Number
- CN202511554681.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-28
- Publication Date
- 2026-01-16
AI Technical Summary
In existing technologies, the remote access process for network devices is complex, requiring the additional deployment of virtual private network servers and the installation of remote access software, resulting in issues such as high security, poor availability, and insufficient control.
By configuring reverse and forward proxies between the terminal and the server, access paths for network devices can be established without deploying a virtual private network server or installing remote access software. Dynamic session keys and fine-grained access control ensure security and portability.
It simplifies the remote access process for network devices, improves portability and security, avoids the risks of direct access to network devices, and enables fine-grained access control and authentication.
Smart Images

Figure CN121357232A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a network device remote access method, system, device, medium and program product. BACKGROUND
[0002] At present, a user terminal can remotely access a network device in other network through a virtual private network. However, this remote access mode needs to additionally deploy a server of the virtual private network and install corresponding remote access software on the user terminal, resulting in a complex remote access process of the network device. SUMMARY
[0003] The present application provides a network device remote access method, system, device, medium and program product to solve the problem of complex remote access process of the network device.
[0004] In a first aspect, the present application provides a network device remote access method suitable for a first service, comprising: receiving a first access request of a first terminal for a first network device in a first network; wherein the first terminal does not belong to the first network; configuring reverse proxy information for the first network device based on the first access request, wherein the reverse proxy information is used to create a first reverse proxy for the first network device; configuring a first forward proxy for associating the first terminal with the first reverse proxy after the first reverse proxy is created; providing an access path for the first network device to the first terminal through the first forward proxy and the first reverse proxy.
[0005] In a second aspect, the present application provides a network device remote access device suitable for a first service, comprising: a first receiving module configured to receive a first access request of a first terminal for a first network device in a first network; wherein the first terminal does not belong to the first network; a first configuration module configured to configure reverse proxy information for the first network device based on the first access request, wherein the reverse proxy information is used to create a first reverse proxy for the first network device; a second configuration module configured to configure a first forward proxy for associating the first terminal with the first reverse proxy after the first reverse proxy is created; an access control module configured to provide an access path for the first network device to the first terminal through the first forward proxy and the first reverse proxy.
[0006] In a third aspect, the present application provides an electronic device, comprising a memory and a processor, which are communicatively connected with each other, and the memory stores computer instructions, and the processor executes the network device remote access method of the first aspect or any of the corresponding embodiments thereof by executing the computer instructions.
[0007] In a fourth aspect, the present application provides a computer readable storage medium, which stores computer instructions, and the computer instructions are used to make a computer execute the network device remote access method of the first aspect or any of the corresponding embodiments thereof.
[0008] In a fifth aspect, the present application provides a computer program product, which comprises computer instructions, and the computer instructions are used to make a computer execute the network device remote access method of the first aspect or any of the corresponding embodiments thereof.
[0009] The network device remote access method provided by the embodiments of the present application, in the case that the first terminal does not belong to the first network, if the first terminal needs to access the first network device in the first network, a first access request for the first network device can be sent to the first service. Further, the first service configures reverse proxy information for the first network device based on the first access request, to create a first reverse proxy for the first network device, and after the first reverse proxy is created, a first forward proxy for associating the first terminal with the first reverse proxy is configured, so that the first terminal is provided with an access path for the first network device through the first forward proxy and the first reverse proxy. In this process, there is no need to separately deploy a virtual private network server for the first terminal, nor is there a requirement for the first terminal to install remote access software corresponding to the virtual private network, thus the network device remote access process can be simplified, and the portability of the first network device remote access can be improved. Moreover, the first terminal can be prevented from directly accessing the first network device, and the security of the first network device remote access can be ensured.
[0010] The beneficial effects of the network device remote access apparatus, the electronic device, the storage medium and the program product correspond to those of the network device remote access method, which will not be described herein again. BRIEF DESCRIPTION OF DRAWINGS
[0011] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the description of the embodiments or the prior art. Obviously, the drawings described below are some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor.
[0012] Figure 1is a schematic diagram of an application scenario according to an embodiment of the present application; Figure 2 is a first flowchart of a network device remote access method according to an embodiment of the present application; Figure 3 is an interaction diagram of a network device remote access method according to an embodiment of the present application; Figure 4 is a second flowchart of a network device remote access method according to an embodiment of the present application; Figure 5 is a structural block diagram of a network device remote access apparatus according to an embodiment of the present application; Figure 6 is a hardware structure schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0013] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0014] It can be understood that, before using the technical solutions disclosed in the embodiments of the present application, the type, use range, use scenario and the like of the personal information involved in the present application should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0015] For example, in response to receiving the active request of the user, prompt information is sent to the user to explicitly prompt the user that the operation requested to be executed will need to obtain and use the personal information of the user. Thus, the user can voluntarily choose whether to provide the personal information to the electronic device, application program, server or storage medium and the like software or hardware that execute the operation of the technical solutions of the present application according to the prompt information.
[0016] As an optional but not limited implementation manner, in response to receiving the active request of the user, the manner of sending the prompt information to the user may, for example, be a pop-up window manner, and the prompt information may, for example, be presented in the form of text in the pop-up window. In addition, the pop-up window may, for example, also carry a selection control for the user to select "agree" or "disagree" to provide the personal information to the electronic device.
[0017] It can be understood that the above notification and user authorization process is only illustrative, and does not limit the implementation manner of the present application, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present application.
[0018] It can be understood that the data involved in the technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws and regulations and relevant provisions.
[0019] The terms "first", "second" are only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, the meaning of "multiple" is two or more, unless otherwise specifically limited.
[0020] With the deepening of the digital transformation of enterprises, more and more network devices are deployed in private network environments. These network devices usually have web control interfaces, such as firewall control interfaces, switch control interfaces, etc., and users need to access and operate these network devices remotely through a virtual private network (VPN). However, although VPN can achieve remote access to network devices, it has the following problems: 1. Security problem. VPN gives users too much access to private networks, even the entire private network, with high security risks.
[0021] 2. Availability problem. VPN configuration is complex and requires professional network knowledge for network configuration and maintenance. The terminal needs to install a special VPN server and client software.
[0022] 3. Control problem. VPN is difficult to achieve fine-grained access control and authentication.
[0023] In some other related technologies, there are also some network address translation (NAT) port mapping schemes for remote access of network devices. However, the remote access of NAT port mapping has the following problems: 1. Complex port management, prone to conflicts.
[0024] 2. Lack of unified access entry and identity authentication.
[0025] 3. Difficult to achieve dynamic port allocation and session control.
[0026] 4. Security depends on a single authentication mechanism.
[0027] There are also some related technologies that provide remote access based on a Hypertext Transfer Protocol (HTTP) / Protocol for sessions traversal across firewall securely (SOCKS) proxy, but such remote access has the following problems: 1. The terminal needs to be configured with an HTTP / SOCKS proxy.
[0028] 2. Limited support for protocols such as HTTPS and Web SOCKS.
[0029] 3. It is difficult to implement domain-based remote access of multiple network devices.
[0030] Therefore, with the deepening of the digital transformation of enterprises, there is an urgent need for a secure and portable remote access solution for network devices in a private network.
[0031] As an optional application scenario of the embodiments of the present application, as shown in Figure 1 The first terminal 110 is installed with a browser 110, and the user 120 can interact with the browser 110 through the first terminal 110 and / or the access device of the first terminal 110.
[0032] In the application scenario shown in Figure 1 If the browser 110 is in an active state, the first terminal 110 can present an interface 112 of the browser 110. The interface 112 can include various pages that the browser 110 can provide for network devices in the first network, such as access pages, setting pages, query pages, and the like.
[0033] In some embodiments, the first terminal 110 is communicatively connected with the server 120, and a client 141 corresponding to the server 120 is deployed in the first network, and the server 120 cooperates with the client 141 to provide an access service for the first terminal 110 to the network device 142 in the first network. The first terminal 110 can be a mobile terminal, a fixed terminal, or a portable terminal, and the like, including but not limited to a mobile phone, a desktop computer, a notebook computer, a multimedia tablet, an electronic book device, a game device, or any combination of the above, including accessories and peripherals of the devices or any combination thereof. In some embodiments, the first terminal 110 can also support any type of interface, and the server 120 can be various types of computing systems, servers, capable of providing computing capabilities, including but not limited to mainframes, edge computing nodes, computing devices in cloud environments, and the like. The server 120 is configured with a first service 131 and a second service 132, the second service 132 is pre-registered with the network device 142 in the first network that needs to be accessed, and controls the access permission of the network device 142. The second service 132 serves as a unified portal of the server 120, and is used to receive an access request issued by a browser of the first terminal 110, and generate authentication information for the access request according to the access permission of the network device 142, to provide authentication capability of the first terminal 110 accessing the network device 142. The first service 131 generates reverse proxy information for the network device 142 when the first terminal 110 has access permission of the network device 142, to configure a reverse proxy for the network device 142, and configure a forward proxy for the first terminal 110, so as to provide an access path for the network device 142 by using the forward proxy and the reverse proxy. The first service 131 serves as a unified portal of the network device 142 proxy, and is used to receive an access request for the network device 142, and authenticate all accesses to the network device 142, to ensure the security of the network device 142 access.
[0034] It should be noted that, Figure 1 This is only an example of an application scenario, and does not limit the protection scope of the present application.
[0035] According to the embodiments of the present application, a network device remote access method embodiment is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown herein.
[0036] In the present embodiment, a network device remote access method is provided, which can be used in the above-mentioned server 120, such as a computing device in a cloud environment. The network device remote access method of the present embodiment is particularly applicable to the first service deployed in the server 120. Figure 2is a flowchart of a network device remote access method according to an embodiment of the present application, as shown in the figure, the flow includes the following steps: Figure 2 Step S201, receiving a first access request of a first terminal for a first network device in a first network; wherein the first terminal does not belong to the first network.
[0037] Wherein, the first network can be an enterprise intranet or other private network, and the first network device is the network device to be accessed by the first terminal in the first network.
[0038] In actual application, the first terminal displays an access page, and the access page displays device information of the network device in the first network. The user can select the first network device to be accessed on the first terminal according to the device information displayed in the access page. The first terminal sends a first access request for the first network device to the first service in response to the selection operation of the first network device.
[0039] Step S202, configuring reverse proxy information for the first network device based on the first access request, and the reverse proxy information is used to create a first reverse proxy for the first network device.
[0040] Optionally, the reverse proxy information includes at least one of a session key, a certificate corresponding to the session key, first port information of a first reverse proxy port of the first service, and second port information of a second reverse proxy port of a client on the first network. Wherein, the session key can be a key pair of Secure Shell (SSH), and the certificate can be a Secure Shell certificate, which can be adjusted according to actual conditions, and is not limited here.
[0041] Specifically, the above step S202 includes: the first service generates a session creation request based on the reverse proxy information, and sends the session creation request to the second service. The second service forwards the session creation request to the client. The client configures a reverse proxy with the first service using the reverse proxy information carried in the session creation request, and configures a target proxy associated with the reverse proxy and the first network device to form a first reverse proxy for the first network device. Wherein, the target proxy is a local proxy (Socat) of the client for the first network device.
[0042] Step S203, after the first reverse proxy is created, configuring a first forward proxy for associating the first terminal with the first reverse proxy.
[0043] Specifically, the first service can determine the creation of the first reverse proxy by detecting the connectivity between the first reverse proxy port and the second reverse proxy port. If the first reverse proxy port and the second reverse proxy port are connected, the first reverse proxy is created. If the first reverse proxy port and the second reverse proxy port are not connected, the first reverse proxy is not created.
[0044] In step S204, the first terminal is provided with an access path to the first network device through the first forward proxy and the first reverse proxy.
[0045] It can be understood that the first forward proxy is used to forward the information (such as the first access request) sent by the first terminal to the first reverse proxy, so as to send the information sent by the first terminal to the first network device through the first reverse proxy. Conversely, the information sent by the first network device can also be sent to the first forward proxy through the first reverse proxy, and then the first forward proxy forwards the information sent by the first network device to the first terminal, thereby realizing the access path to the first network device.
[0046] The network device remote access method provided by the embodiment can be used in the case that the first terminal does not belong to the first network. If the first terminal needs to access the first network device in the first network, the first terminal can send a first access request for the first network device to the first service. Then, the first service configures reverse proxy information for the first network device based on the first access request, creates a first reverse proxy for the first network device, and configures a first forward proxy for associating the first terminal with the first reverse proxy after the first reverse proxy is created. Thus, the first terminal is provided with an access path to the first network device through the first forward proxy and the first reverse proxy. In this process, a virtual private network server does not need to be deployed for the first terminal, and the first terminal does not need to install remote access software corresponding to the virtual private network or configure a network address of the network device. Therefore, the network device remote access process can be simplified, and the portability of the first network device remote access is improved. Moreover, the first terminal can be prevented from directly accessing the first network device, and the security of the first network device remote access is ensured.
[0047] In some optional embodiments, the first access request carries first authentication information; the first authentication information is generated by the second service based on the access permission of the first network device and is fed back to the first terminal.
[0048] Specifically, the second service receives a second access request for a first network device in a first network from a first terminal, generates first authentication information corresponding to the second access request based on the access permission of the network device in the first network, and feeds back the first authentication information to the first terminal.
[0049] The second service is pre-registered with the network device in the first network that needs to be accessed and is configured with the access permission of the network device. The second service serves as a unified portal of the server. A user can access the second service through the first terminal, select a network device (for example, the first network device) in the first network that needs to be accessed, and access the second service through a browser deployed in the first terminal. The device information of the network device in the first network is displayed on the browser. The user can select the first network device to be accessed according to actual needs. The browser generates a second access request according to the selected first network device, and the first terminal sends the second access request to the second service. Then, the second service receives the second access request, generates first authentication information corresponding to the second access request according to the access permission of the network device in the first network, and feeds back the first authentication information to the first terminal.
[0050] Optionally, the first authentication information is an authentication token.
[0051] Further, the network device remote access method of the present application further comprises: Step a1, sending the first authentication information to the second service for authentication.
[0052] Specifically, the first service receives the first access request of the first terminal for the first network device, and sends the first authentication information carried in the first access request to the second service.
[0053] That is, the first service verifies the access permission of the first terminal for the first network device by using the second service through the first authentication information carried in the first access request.
[0054] Step a2, receiving the authentication result fed back by the second service; Specifically, the second service stores the correspondence relationship among the first terminal, the first network device, and the first authentication information when generating the first authentication information. The first service sends the first authentication information carried in the first access request to the second service. The second service performs authentication according to the first authentication information sent by the first service and the correspondence relationship stored in advance, and obtains the authentication result. The second service feeds back the authentication result to the first service.
[0055] Step a3, if the authentication result indicates that the authentication is passed, configuring the reverse proxy information for the first network device.
[0056] It is worth noting that if the authentication result indicates that the authentication is not passed, it means that the first terminal does not have the access permission for the first network device. In this case, the first terminal is not allowed to access the first network device, thereby ensuring the security of the network device remote access.
[0057] The network device remote access method provided in the embodiment configures the access permission of the network device in the first network in the second service. When the second service receives the second access request of the first terminal for the first network device in the first network, the corresponding first authentication information can be generated by using the configured access permission, so that it is ensured that the first terminal can only access the network device with the corresponding permission. Then, the first terminal sends the first access request for the first network device to the first service according to the first authentication information fed back by the second service. The first service authenticates in the second service according to the first authentication information carried in the first access request, and only when the authentication is passed, the first service provides the access path for the first terminal to the first network device, so that the first terminal can effectively avoid accessing the network device without permission, and the security of the network device in the first network is ensured.
[0058] In some optional embodiments, the second service is configured with a valid time length of the first authentication information; and the second service is configured to perform invalidation processing on the first authentication information when the use time length of the first authentication information exceeds the valid time length.
[0059] It can be understood that the second service also configures a valid time length of the first authentication information when generating the first authentication information. The valid time length of the first authentication information is 30s, and in addition, it can also be 25s, 35s, etc., which can be configured according to actual conditions.
[0060] It should be noted that the first authentication information is invalid not only when the use time length of the first authentication information exceeds the corresponding valid time length, but also when the first authentication is completed for the first time.
[0061] The network device remote access method provided in the embodiment, the second service configures the valid time length of the first authentication information, so that the security risk of the first network device can be avoided due to the long time in the valid state of the first authentication information. At the same time, the additional data resource occupation can also be reduced.
[0062] In some optional embodiments, the second service is further configured to feed back the proxy address of the first service to the first terminal when it is determined that the first terminal has the access permission for the first network device, and the first terminal is configured to send the first access request to the first service by using the proxy address and the first authentication information.
[0063] It can be understood that the second service generates the proxy address of the first service at the same time of generating the first authentication information based on the access permission. The second service feeds back the first authentication information and the proxy address to the first terminal. The browser deployed in the first terminal automatically opens the proxy address in a new window, and accesses the first service by carrying the first authentication information in the cache (Cookie) of the browser to generate the first access request.
[0064] The network device remote access method provided in the embodiment can feed back the proxy address of the first service to the first terminal only when the first terminal has access permission for the first network device, thereby avoiding the first terminal from accessing the first service without having access permission for the first network device, avoiding the first service from providing an access path for the first network device to the first terminal due to a misjudgment that the first terminal has access permission for the first network device, and further ensuring the security of the first network device access.
[0065] In some optional embodiments, the configuration of the reverse proxy information for the first network device in step a3 comprises: In step a31, first optional port information of the first service and second optional port information of the client on the first network are obtained.
[0066] The first optional port information comprises information of an optional port of the first service, such as a port address and a port identifier of the optional port of the first service. The second optional port information comprises information of an optional port of the client, such as a port address and a port identifier of the optional port of the client.
[0067] Optionally, the first service is deployed with an SSH server, and the client is an SSH client.
[0068] In step a32, first port information of a first reverse proxy port of the first service and second port information of a second reverse proxy port of the client are determined from the first optional port information and the second optional port information.
[0069] Specifically, the first service dynamically determines the first port information of the first reverse proxy port of the first service and the second port information of the second reverse proxy port of the client from the first optional port information and the second optional port information. For example, the first reverse proxy port of the first service and the second reverse proxy port of the client are randomly allocated by a random algorithm to obtain the first port information and the second port information. Further, the first reverse proxy port and the second reverse proxy port can be configured in combination with a history of attacks on each port to obtain the first port information and the second port information.
[0070] It should be noted that when the first reverse proxy port and the second reverse proxy port are dynamically determined, it is necessary to avoid a conflict of the reverse proxy ports. In the determination of the first reverse proxy port and the second reverse proxy port, a multi-port cooperative mapping mechanism can be combined to realize end-to-end connection control. When the first reverse proxy fails or the first reverse proxy is not successfully created, the port resources are automatically recycled to realize reuse of the port. Thus, the session control mechanism between the first service and the client can be combined to realize optimized use of the port resources in a high-concurrency scenario.
[0071] Optionally, the first port information includes a port address, a port identifier, or the like of the first reverse proxy port.
[0072] Optionally, the second port information includes a port address, a port identifier, or the like of the second reverse proxy port.
[0073] In step a33, the first port information and the second port information are sent to the client as the reverse proxy information, and the client creates the first reverse proxy according to the reverse proxy information sent by the first service.
[0074] The network device remote access method provided by the embodiment dynamically generates a reverse proxy port of the first service and the client by the first service, and thus the security of the first reverse proxy can be ensured by dynamically configuring the reverse proxy port.
[0075] In some optional embodiments, the network device remote access method further includes: In step b1, a session key is created, and a valid time length of the session key is configured, and the session key is used by the client to establish an encrypted session with the first service in the process of creating the first reverse proxy.
[0076] It can be understood that the first service dynamically generates an independent session key for a session or a reverse proxy between different terminals and the network device, so as to be used by the client to connect to the first service.
[0077] Optionally, the session key is an RSA key pair, and other forms of session keys can also be selected, which are not limited herein.
[0078] It is worth noting that the session service (such as an SSH service) provided by the first service is exposed to the public network, and there is a certain security risk. Therefore, when the session key is created, the valid time length of the session key is configured to perform certain access control on the session service provided by the first service.
[0079] Optionally, the valid time length of the session key is 30s, and the valid time length can also be dynamically adjusted to 25s, 35s, or the like, which can be selected according to actual conditions.
[0080] It can be understood that if the valid time length of the session key is 30s, the session key is invalid after 30s, and each session key is used only once.
[0081] In step b2, the session key and the reverse proxy information are sent to the client.
[0082] That is, the first service sends the first port information, the second port information, and the session key to the client, so that the client creates the first reverse proxy according to the first port information, the second port information, and the session key.
[0083] The network device remote access method provided by the embodiment dynamically configures a session key for the client to connect to the first service by the first service. Therefore, the security of the first reverse proxy can be ensured by dynamically configuring the session key.
[0084] In some optional embodiments, the network device remote access method further includes: sending a first instruction to the network isolation device corresponding to the first network, the first instruction carrying first port information and second port information, and the first instruction being used to instruct the network isolation device to open a data path between the first reverse proxy port and the second reverse proxy port.
[0085] Optionally, the network isolation device includes a firewall or other network device used to isolate the first network from an external network, where the external network is a network other than the first network, such as a network where the first terminal or the first service is located.
[0086] It can be understood that, since the network isolation device of the first network isolates the access of the external network to the network device in the first network. Therefore, before the first reverse proxy is configured, the second reverse proxy port needs to be opened in the network isolation device to open the data path between the first reverse proxy port and the second reverse proxy port, so as to ensure the successful configuration of the first reverse proxy.
[0087] The network device remote access method provided by the embodiment controls the network isolation device to open the data path between the first reverse proxy port and the second reverse proxy port before the first reverse proxy is configured, and therefore, the configuration failure of the first reverse proxy caused by network isolation can be avoided.
[0088] In some optional embodiments, the network device remote access method further includes: if the opening duration of the data path reaches a preset duration and the first reverse proxy is not created, sending a second instruction to the network isolation device, the second instruction being used to instruct the network isolation device to close the data path.
[0089] The preset duration can be consistent with the valid duration of the session key, or can be inconsistent with the valid duration of the session key.
[0090] Optionally, the preset duration is 30s, which can be dynamically adjusted to 25s, 35s, etc. according to actual conditions, and is not limited herein.
[0091] For example, if the preset duration is 30s, after the first service sends a session creation request to the client through the reverse proxy information and the second service, the network isolation device will open the data path for 30s, and then close the data path.
[0092] The network device remote access method provided by the embodiment can close the data channel if the opening duration of the data channel reaches the preset duration and the first reverse proxy is not created, thereby avoiding the security risks of the network device in the first network caused by long-time opening of the data channel.
[0093] In some optional embodiments, the second service is configured with the access domain name of the network device in the first network.
[0094] Specifically, the second service is pre-registered with the network device in the first network, and the second service is assigned with a device identifier for each network device, and each device identifier corresponds to an access domain name (Domain).
[0095] Optionally, the device identifier is a Universally Unique Identifier (UUID).
[0096] The configuration of the first forward proxy for associating the first terminal with the first reverse proxy in the step S203 includes: obtaining the first access domain name corresponding to the network device in the first network from the second service, and configuring the first forward proxy based on the first access domain name.
[0097] It can be understood that, when configuring the first forward proxy, the first service points the first access domain name to a local reverse proxy (i.e., the first reverse proxy), thereby building an access channel between the first terminal and the network device in the first network by using the first forward proxy and the first reverse proxy.
[0098] It should be noted that, in the first service, each reverse proxy corresponds to a network device.
[0099] In some optional embodiments, the network device remote access method further includes: If the first access request is received for the first time, the second authentication information corresponding to the access channel is generated.
[0100] Optionally, the second authentication information is a HyperText Transfer Protocol Token (HTTP Token).
[0101] Specifically, the first service generates the second authentication information, and configures the effective duration of the second authentication information.
[0102] Optionally, the effective duration of the second authentication information can be 2h, which can be dynamically adjusted according to actual conditions.
[0103] For example, if the effective duration of the second authentication information is 2h, the first service can use the second authentication information to use the access channel within 2h, and the second authentication information is invalid after 2h. At the same time, the second authentication information can also be actively deleted on the first service.
[0104] Step c2, the second authentication information is fed back to the first terminal, and the first terminal is configured to access the first network device through the second authentication information and the access channel.
[0105] It can be understood that in the subsequent process of the first terminal accessing the first network device, the first terminal sends an access request for the first network device to the first service using the second authentication information, and the first service verifies the access permission of the first terminal to the first network device according to the second authentication information.
[0106] The network device remote access method provided by the embodiment can generate the second authentication information corresponding to the access channel when the first access request is first received, and feed back the second authentication information to the first terminal. Therefore, the access of the first terminal can be authenticated repeatedly using the second service and the first authentication information in the subsequent access process, the authentication efficiency is improved, and the access delay for the first network device is reduced.
[0107] In some optional embodiments, when the first access request is first received, the network device remote access method of the application further includes: forwarding the first access request to the first network device through the first forward proxy and the first reverse proxy, and receiving response information of the first network device to the first access request, and feeding back the response information to the first terminal.
[0108] It should be noted that after the access channel is created, if the access channel is not invalid, the first service forwards the first access request of the first terminal to the first network device for the first time to the first network device.
[0109] The network device remote access method provided by the embodiment can generate the second authentication information corresponding to the access channel when the first access request is first received, and feed back the second authentication information to the first terminal. Therefore, the access of the first terminal can be authenticated repeatedly using the second service and the first authentication information in the subsequent access process, the authentication efficiency is improved, and the access delay for the first network device is reduced.
[0110] In some optional embodiments, the network device remote access method of the application further includes: recording the access information of the first terminal to the first network device through the first forward proxy.
[0111] It should be noted that which network devices in the first network can be accessed by the first terminal is controlled by the first service. For example, tenant A can access network devices 1-3, and role B can access network device 1. All access traffic of the first terminal to the first network device will be forwarded through the first forward proxy. Therefore, the access information of the first terminal to the first network device can be recorded by using the first forward proxy.
[0112] Optionally, the access information comprises one or more of an access time, object information of an access object, Uniform Resource Locator (URL) information used by the first network device to access, and response information (such as a response status code) of the first network device.
[0113] The network device remote access method provided by the embodiment can record, by the first service, access information of the first terminal to the first network device, and thus can analyze complete access information of the first network device based on the access information recorded by the first service.
[0114] In some optional embodiments, the network device remote access method further comprises: in a case where the access of the first terminal to the first network device satisfies a preset session stop condition, the second service sends a session stop request to the client, and the client closes the first reverse proxy in response to the session stop request.
[0115] In some optional embodiments, the network device remote access method further comprises: in a case where an idle duration of the access channel reaches a preset maximum idle duration, the second service sends a session stop request to the client, and the client closes the first reverse proxy in response to the session stop request.
[0116] The second service closing the first reverse proxy comprises closing the reverse proxy and the target proxy of the first service.
[0117] As can be seen from the above, the network device remote access method comprises a multi-level security authentication system, and combines a fine-grained access control mechanism to achieve secure access under the principle of least privilege. Specifically, the network device remote access method has the following advantages: 1. a dual authentication mechanism of one-time first authentication information and a persistent session; 2. access isolation and permission control based on a network device; 3. dynamic session key configuration and time window access control; and 4. complete access information recording.
[0118] As a specific application embodiment of the network device remote access method, a system architecture using the network device remote access method is shown in FIG. 1. Figure 3 As shown in FIG. 1, the architecture comprises a first terminal, a server, and a first network. The first terminal is provided with a browser, a user can access the second service in the server through the browser, select a first network device to be accessed in the first network, and initiate a second access request to the first network device to the second service. The second service is a unified entrance of the server, receives the second access request, generates first authentication information and a proxy address according to a preset access permission of the network device in the first network, and feeds back the first authentication information and the proxy address to the first terminal. The first terminal accesses the first service through the proxy address.
[0119] The first service is deployed with a forward proxy and a remote login service. The remote login service is deployed with an SSH server. The first network is deployed with an SSH client. The first service serves as a unified portal of the network device proxy, receives a first access request initiated by a first terminal based on first authentication information to a first network device, generates reverse proxy information, and sends a session creation request to the second service based on the reverse proxy information, and the second service is responsible for session creation. Specifically, the second service forwards the session creation request to the SSH client, and the SSH client receives the session creation request, creates a reverse proxy to the first service, and creates a local proxy to the first network device to form a first reverse proxy to the first network device. The SSH connection state of the SSH server and the SSH client is controlled by the first service.
[0120] After the first reverse proxy is created, the first service obtains a first access domain name of the first network device from the second service, configures the forward proxy with the first access domain name of the first network device to obtain a first forward proxy, so as to realize data forwarding between the first terminal and the first reverse proxy. The first service provides an access path to the first network device by using the first forward proxy and the first reverse proxy. Further, the first terminal can access the first network device through a unified access domain name. The second service is responsible for session stop, that is, the closing of the access path.
[0121] It can be seen that the present application proposes a zero-configuration remote Graphical User Interface (GUI) access scheme for network devices in a private network (referring to the first network described above) based on a reverse SSH tunnel. The user does not need to install any software for remote access on the terminal, but can access the GUI interface of the network device in the private network through a browser only. The connection mechanism of the reverse proxy initiated by the client in the private network can break through the firewall (referring to the network isolation device described above) restriction. And through the intelligent routing of the access domain name, it supports the unified access portal of multiple network devices. Moreover, this remote access method supports transparent proxy of multiple protocols such as HTTP, HTTPS, Web Socket, specifically supports network device identification and routing algorithm based on domain name prefix, supports HTTP protocol header rewriting and protocol adaptation, and supports state maintenance and fault recovery of Web Socket long connection.
[0122] As another specific application embodiment of the present application, see Figure 4Taking a network isolation device as a firewall as an example, the remote access method for network devices in this application mainly includes the following process: The user selects the first network device to connect to in the first network through a browser on the first terminal. The browser sends a second access request for the first network device to a second service. The second service generates first authentication information and a proxy address for the first service. The browser enters the proxy address in the interface and sends the first access request to the forward proxy of the first service according to the first authentication information. The forward proxy sends the first access request to the first service. The first service sends the first authentication information carried in the second access information to the second service for authentication and obtains the authentication result returned by the second service. If the authentication result indicates successful authentication, the first service creates an SSH key pair and allocates a reverse proxy port between the first service and the client. The first service opens the allocated reverse proxy port in the firewall. The first service sends a session creation request to the second service according to the SSH key pair and the port information of the allocated reverse proxy port. The second service forwards the session creation request to the client in the first network. The client creates a reverse proxy according to the SSH key pair and port information in the session creation request and connects to the first service. Simultaneously, the client creates a local proxy for the first network device to form a first reverse proxy. The first service checks whether the first reverse proxy has been successfully created through the allocated reverse proxy port. If the first reverse proxy is successfully created, the first service configures a first forward proxy associated with the first terminal and the first reverse proxy. The first service forwards the first access request to the client through the first forward proxy and the client's reverse proxy with the first service. The client forwards the first access request to the first network device through the local proxy. The client receives the response information returned by the first network device for the first access request through the local proxy and returns the response information to the first forward proxy through the reverse proxy with the first service. The first service generates second authentication information through the first forward proxy and returns response information carrying the second authentication information to the browser, so that the browser can perform authentication in the first service through the second authentication information, and then access the first network device using the first forward proxy and the first reverse proxy.
[0123] As can be seen, in the network device remote access method of this application, all network devices in the first network can be accessed through the unified entry point provided by the second service and the first service. No software for remote access needs to be installed, nor is it necessary to record the access addresses of each network device; access can be achieved solely through a browser, thus realizing zero-configuration remote access on the terminal. Furthermore, it is compatible with multiple mainstream Web protocols such as HTTP, HTTPS, Web Socket, and Streaming SIMDExtensions (SSE).
[0124] Furthermore, the network device remote access method of this application grants access permissions only to specific ports of specific network devices to the first terminal, without opening the entire first network, thus adhering to the principle of least privilege. It employs a triple authentication mechanism—one-time first authentication information, persistent second authentication information, and session state—to strengthen the authentication of the first terminal accessing the first network device. Simultaneously, the first service uses an independent session key for each session, and the lifespan of the session key is controllable. Moreover, the allocated reverse proxy port has a valid duration and can be automatically reclaimed, thereby ensuring the security of access to network devices within the first network.
[0125] In addition, the network device remote access method of this application further records the complete access information of the first terminal to the first network device through the configured first forward proxy, which can effectively analyze and detect the access situation to the first network device.
[0126] This embodiment also provides a remote access device for network devices. This system is used to implement the above embodiments and preferred embodiments, and details already described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the system described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0127] This embodiment provides a remote access device for network devices, applicable to the first service, such as... Figure 5 As shown, it includes: The first receiving module 501 is used to receive a first access request from the first terminal for a first network device in the first network; wherein the first terminal does not belong to the first network.
[0128] The first configuration module 502 is used to configure reverse proxy information for the first network device based on the first access request. The reverse proxy information is used to create a first reverse proxy for the first network device.
[0129] The second configuration module 503 is used to configure the first forward proxy for associating the first terminal with the first reverse proxy after the first reverse proxy is created.
[0130] The access control module 504 is used to provide the first terminal with an access path for the first network device through the first forward proxy and the first reverse proxy.
[0131] In some optional implementations, the first access request carries first authentication information; the first authentication information is generated by the second service based on the access permissions of the first network device and fed back to the first terminal. The first configuration module 502 includes: The authentication unit is used to send the first authentication information to the second service for authentication.
[0132] The first receiving unit is used to receive the authentication result fed back by the second service.
[0133] The first configuration unit is used to configure reverse proxy information for the first network device if the authentication result indicates that the authentication is successful.
[0134] In some optional implementations, the second service is configured with a validity period for the first authentication information; the second service is used to invalidate the first authentication information if the usage period of the first authentication information exceeds the validity period.
[0135] In some optional implementations, the second service is further configured to, upon determining that the first terminal has access rights to the first network device, provide the first terminal with the proxy address of the first service, and the first terminal is configured to send a first access request to the first service via the proxy address and the first authentication information.
[0136] In some alternative implementations, the first configuration unit includes: The information acquisition subunit is used to acquire the first optional port information of the first service and the second optional port information of the client on the first network.
[0137] The port configuration subunit is used to determine, from the first optional port information and the second optional port information, the first port information of the first reverse proxy port of the first service and the second port information of the second reverse proxy port of the client, respectively.
[0138] The proxy information configuration subunit is used to use the first port information and the second port information as reverse proxy information. The client uses this information to create a first reverse proxy based on the reverse proxy information sent by the first service.
[0139] In some optional embodiments, the network device remote access device of this application further includes: The key creation module is used to create session keys and configure the validity period of the session keys. The session keys are used by the client to establish an encrypted session with the first service during the creation of the first reverse proxy.
[0140] The first sending module is used to send the session key and reverse proxy information to the client.
[0141] In some optional embodiments, the network device remote access device of this application further includes: The second sending module is used to send a first instruction to the network isolation device corresponding to the first network. The first instruction carries first port information and second port information. The first instruction is used to instruct the network isolation device to open the data path between the first reverse proxy port and the second reverse proxy port.
[0142] In some optional embodiments, the network device remote access device of this application further includes: The third sending module is used to send a second instruction to the network isolation device if the open duration of the data path reaches a preset duration and the first reverse proxy has not been created. The second instruction is used to instruct the network isolation device to close the data path.
[0143] In some alternative implementations, the second configuration module 503 includes: The forward proxy configuration unit is used to obtain the first access domain name corresponding to the first network device from the second service, and configure the first forward proxy based on the first access domain name.
[0144] In some optional embodiments, the network device remote access device of this application further includes: The third configuration module is used to generate second authentication information corresponding to the access path if the first access request is received for the first time.
[0145] The fourth sending module is used to send the second authentication information back to the first terminal, which is used to access the first network device through the second authentication information and the access path.
[0146] In some optional embodiments, the network device remote access device of this application further includes: The access logging module is used to record access information of the first terminal to the first network device through the first forward proxy.
[0147] The network device remote access apparatus provided in this application can execute the network device remote access method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects for executing the method. Further functional descriptions of the various modules and units described above are the same as those in the corresponding embodiments described above, and will not be repeated here.
[0148] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0149] The following is a detailed reference. Figure 6This diagram illustrates a suitable structural schematic for implementing the electronic device described in the embodiments of this application. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from memory 608 into random access memory (RAM) 603. The RAM 603 also stores various programs and data required for the operation of the electronic device. The processor 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0150] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.
[0151] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 609, or installed from memory 608, or installed from ROM 602. When the computer program is executed by processor 601, it performs the functions defined in the network device remote access method of embodiments of this application.
[0152] Figure 6 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0153] This application also provides a computer-readable storage medium. The methods described in this application can be implemented in hardware or firmware, or implemented as recordable on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the remote access method for network devices shown in the above embodiments is implemented.
[0154] A portion of this application can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to this application through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0155] Although embodiments of this application have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of this application, and all such modifications and variations fall within the scope defined by the appended claims.
Claims
1. A network device remote access method, characterized by, The method is suitable for a first service, and comprises: receiving a first access request of a first terminal for a first network device in a first network, wherein the first terminal does not belong to the first network; configuring reverse proxy information for the first network device based on the first access request, wherein the reverse proxy information is used to create a first reverse proxy for the first network device; after the first reverse proxy is created, configuring a first forward proxy used to associate the first terminal with the first reverse proxy; providing an access path for the first terminal to the first network device through the first forward proxy and the first reverse proxy.
2. The method of claim 1, wherein the network device is a router. The first access request carries first authentication information, wherein the first authentication information is generated by a second service based on an access permission of the first network device and is fed back to the first terminal; The method further comprises: configuring the reverse proxy information for the first network device based on the first access request, comprising: sending the first authentication information to the second service for authentication; receiving an authentication result fed back by the second service; 3. The method of claim 2, wherein the network device is a router. if the authentication result indicates that the authentication is passed, configuring the reverse proxy information for the first network device. The method further comprises: obtaining first optional port information of the first service and second optional port information of a client on the first network; determining first port information of a first reverse proxy port of the first service and second port information of a second reverse proxy port of the client in the first optional port information and the second optional port information respectively; 4. The method of claim 3, wherein the network device is a router. sending the first port information and the second port information as the reverse proxy information, wherein the client is used to create the first reverse proxy according to the reverse proxy information sent by the first service. The method further comprises: creating a session key and configuring a valid time length of the session key, wherein the session key is used to establish an encrypted session between the client and the first service in the process of creating the first reverse proxy; 5. The method of claim 3, wherein the network device is a router. sending the session key and the reverse proxy information to the client. The method further comprises:
6. The method of claim 5, wherein the network device is remotely accessed by a user through a web browser. sending a first instruction to a network isolation device corresponding to the first network, wherein the first instruction carries the first port information and the second port information, and the first instruction is used to instruct the network isolation device to open a data path between the first reverse proxy port and the second reverse proxy port. The method further comprises:
7. The method of claim 1, wherein the network device is a router. if an open time length of the data path reaches a preset time length and the first reverse proxy is not created, sending a second instruction to the network isolation device, wherein the second instruction is used to instruct the network isolation device to close the data path. The method further comprises:
8. The method of claim 1, wherein the network device is remotely accessed by a user through a web browser. if the first access request is received for the first time, generating second authentication information corresponding to the access path. The method further comprises: if the first access request is received for the first time, generating second authentication information corresponding to the access path. The second authentication information is fed back to the first terminal, and the first terminal is configured to access the first network device through the second authentication information and the access path.
9. The method of claim 1, wherein the network device is a remote access server. Further comprising: The first terminal records access information of the first terminal to the first network device through the first forward proxy.
10. The method of claim 2, wherein the network device is remotely accessed by a user through a web browser. The second service is configured with a valid time length of the first authentication information, and the second service is configured to perform invalidation processing on the first authentication information when a use time length of the first authentication information exceeds the valid time length.
11. The method of claim 2, wherein the network device is remotely accessed by a user through a web browser. The second service is further configured to feed back a proxy address of the first service to the first terminal when it is determined that the first terminal has access authority to the first network device, and the first terminal is configured to send the first access request to the first service through the proxy address and the first authentication information.
12. A network device remote access apparatus, characterized by comprising: The first service comprises: A first receiving module configured to receive a first access request of a first terminal to a first network device in a first network; wherein the first terminal does not belong to the first network; A first configuration module configured to configure reverse proxy information for the first network device based on the first access request, the reverse proxy information being used to create a first reverse proxy for the first network device; A second configuration module configured to configure a first forward proxy for associating the first terminal with the first reverse proxy after the first reverse proxy is created; An access control module configured to provide an access path for the first terminal to the first network device through the first forward proxy and the first reverse proxy.
13. An electronic device, comprising: Further comprising: A memory and a processor, which are in communication connection with each other, and the memory stores computer instructions, and the processor executes the computer instructions to perform the network device remote access method in any one of claims 1 to 11.
14. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to make a computer execute the network device remote access method in any one of claims 1 to 11.
15. A computer program product, characterised in that, The computer instructions are used to make a computer execute the network device remote access method in any one of claims 1 to 11.
Citation Information
Patent Citations
Remote equipment control method and Internet of Things equipment management platform and system
CN114390095A
Intranet penetration method and device based on TLS
CN114629678A
Security service system, access control method and computer readable storage medium
CN114640512A
Remote management method and device for equipment WEB, server and storage medium
CN115883312A