Session channel establishment method and device, terminal equipment and storage medium
By dynamically selecting supernodes to establish encrypted session channels with terminal devices, the problems of server operating pressure and data leakage are solved, hardware and maintenance costs are reduced, and data transmission security and efficiency are improved.
Patent Information
- Application Number
- CN202511881959.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-02-13
AI Technical Summary
When the number of terminal devices becomes too large, the server is under tremendous operational pressure, hardware and maintenance costs rise sharply, and the gateway is at risk of data leakage.
The server scheduler dynamically selects super nodes, the terminal device establishes a lease with the super node, and establishes an encrypted session channel with the server through a transparent path composed of the target node and the gateway. The multiplexed stream identifier is used to ensure the direction of data transmission, and the target node and the gateway perform transparent transmission to avoid decryption operations.
This reduces the number of long-lived connection sessions between terminal devices and servers, reduces server-side hardware and maintenance costs, and improves the security and efficiency of data transmission.
Smart Images

Figure CN121531019A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and in particular relates to a method, apparatus, terminal equipment and storage medium for establishing a session channel. Background Technology
[0002] In related technologies, multiple terminal devices establish session channels with the server through gateways, message forwarding nodes, etc. When the number of terminal devices becomes too large, the server will be under enormous pressure on file descriptors, memory, and threads, leading to a sharp increase in hardware and maintenance costs and making it difficult to achieve cost-effective horizontal scaling. In addition, business data streams usually need to be terminated, decrypted, or parsed at the gateway to achieve routing and load balancing, making the gateway a point of visibility for plaintext business data, posing a risk of data leakage. Summary of the Invention
[0003] This application provides a method, apparatus, terminal device, and storage medium for establishing a session channel, in order to solve the technical problem in the related art that when the scale of terminal devices is too large, the server will bear huge operating pressure and the gateway will have the risk of data leakage.
[0004] In a first aspect, embodiments of this application provide a method for establishing a session channel, wherein a server establishes at least one session with multiple terminal devices through a gateway; the method for establishing the session channel is applied to a first terminal device among the multiple terminal devices; when the first terminal device is not a super node, the method for establishing the session channel includes: The node candidate set sent by the scheduler of the receiving server is selected as the target node from the node candidate set according to the preset selection rules. The node candidate set includes at least one super node selected from multiple terminal devices. Establish a lease with the target node; A session binding request is sent to the target node so that the target node generates a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, and registers the first multiplexed stream identifier with the gateway. An encrypted session channel carrying the first multiplexed stream identifier is established with the server through the transparent transmission path formed by the target node and the gateway.
[0005] In some embodiments, before receiving the node candidate set sent by the server's scheduler, the process includes: Send communication link observation reports to the scheduler via the gateway; The receiver scheduler generates a set of candidate nodes adapted to the terminal device based on the communication link observation report. The set of candidate nodes includes the node identifier of the super node and the scheduling policy information corresponding to the node identifier. Receive the node candidate set sent by the scheduler, and determine a super node as the target node from the node candidate set according to preset selection rules, including: Receive the node candidate set sent by the scheduler; Based on the round-trip latency with each supernode, network topology affinity, network address translation affinity, and scheduling policy information, a supernode is selected as the target node from the candidate node set.
[0006] In some embodiments, establishing a lease with the target node includes: Send a lease request to the target node; Upon receiving lease confirmation information from the target node in response to the lease request, a lease is established with the target node based on the lease confirmation information. Upon receiving a lease rejection message from the target node in response to the lease request, update the target node to another super node in the node candidate set, and execute: send a lease request to the target node until a lease is established with the target node.
[0007] In some embodiments, a session binding request is sent to the target node, and an encrypted session channel carrying a first multiplexed stream identifier is established with the server via a transparent path consisting of the target node and the gateway, including: Establish or resume an inner session with the server; Based on the first session identifier of the inner session and the first service identifier of the service instance corresponding to the inner session, a session binding request is sent to the target node so that the target node allocates the first multiplexed flow identifier corresponding to the first session identifier according to the session binding request, updates the preset routing mapping table, and registers the first multiplexed flow identifier with the gateway. The preset routing mapping table includes the mapping relationship between the device identifier of the first terminal device, the first service identifier, and the first multiplexed flow identifier. The system receives the first multiplexed stream identifier sent by the target node, and establishes an encrypted session channel with the server carrying the first multiplexed stream identifier via the transparent path formed by the target node and the gateway.
[0008] In some embodiments, after sending a session binding request to the target node, establishing an encrypted session channel carrying a first multiplexed stream identifier with the server via a transparent path formed by the target node and the gateway, the process includes: Obtain link parameter information between the target node; If the link parameter information meets the preset congestion rules, another super node is determined as the replacement node from the node candidate set according to the preset selection rules; A lease restoration request is sent to the replacement node so that the replacement node can establish a lease with the first terminal device according to the lease restoration request, update the preset routing mapping table, register the first multiplexed flow identifier with the gateway, and establish an encrypted session channel carrying the first multiplexed flow identifier with the server through the transparent path formed by the replacement node and the gateway.
[0009] In some embodiments, when the first terminal device is a supernode, the method for establishing a session channel further includes: Receive lease requests from a second terminal device based on a node candidate set sent by the scheduler, wherein the multiple terminal devices include the second terminal device and the node candidate set includes at least the first terminal device; Establish a lease agreement with the second terminal device based on the lease request; The system receives a session binding request from the second terminal device, generates a second multiplexed stream identifier based on the session binding request, and registers the second multiplexed stream identifier with the gateway, so that the second terminal device can establish an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent transmission path formed by the first terminal device and the gateway.
[0010] In some embodiments, receiving a session binding request sent by a second terminal device, generating a second multiplexed stream identifier based on the session binding request, and registering a first multiplexed stream identifier with the gateway, so that the second terminal device establishes an encrypted session channel carrying the second multiplexed stream identifier with the server via a transparent path formed by the first terminal device and the gateway, including: Receive a session binding request sent by the second terminal device. The session binding request includes the second session identifier of the inner session between the second terminal device and the server, and the second service identifier of the service instance corresponding to the inner session. According to the session binding request, the second multiplexed flow identifier corresponding to the second session identifier is assigned to the second terminal device, and the preset route mapping table is updated and the second multiplexed flow identifier is registered with the gateway. The preset route mapping table includes the mapping relationship between the device identifier of the second terminal device, the second service identifier and the second multiplexed flow identifier. A mapping registration request is generated based on the preset routing mapping table, and a mapping registration request is sent to the gateway to register the second multiplexed flow identifier with the gateway. A transparent transmission path is constructed through the first terminal device and the gateway, and an encrypted session channel carrying the second multiplexed flow identifier is established with the server.
[0011] In some embodiments, the method for establishing a session channel further includes: Receive keep-alive signals sent by a third terminal device at preset keep-alive intervals. The third terminal device is the terminal device that has established a lease with the first terminal device among multiple terminal devices. At least every two preset keep-alive cycles, a heartbeat aggregation packet is generated based on the keep-alive signals sent by multiple third-party terminal devices within at least two preset keep-alive cycles, and the heartbeat aggregation packet is sent to the gateway. The receiving gateway sends network adjustment instructions to the third terminal device based on the network adjustment instructions fed back by the heartbeat aggregation packets sent by multiple super nodes, and coordinates with the third terminal device according to the network adjustment instructions.
[0012] Secondly, embodiments of this application provide a terminal device connection apparatus, wherein a server establishes at least one session with multiple terminal devices through a gateway; the terminal device connection apparatus includes: The determination module is used to receive a set of candidate nodes sent by the scheduler of the server when the first terminal device is not a super node, and determine a super node as the target node from the set of candidate nodes according to a preset selection rule. The set of candidate nodes includes at least one super node selected from multiple terminal devices. The lease establishment module is used to establish leases with the target node; The session channel establishment module is used to send a session binding request to the target node, so that the target node generates a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, registers the first multiplexed stream identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent transmission path formed by the target node and the gateway.
[0013] Thirdly, embodiments of this application provide a terminal device, which includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, it implements the session channel establishment method described above.
[0014] Fourthly, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the session channel establishment method described above.
[0015] The session channel establishment method, apparatus, terminal device, and storage medium provided in this application embodiment receive a node candidate set sent by the server's scheduler, and determine a super node as the target node from the node candidate set according to a preset selection rule, thereby dynamically selecting the required super node as the target node; establish a lease with the target node, and send a session binding request to the target node, so that the target node can generate a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, and register the first multiplexed stream identifier with the gateway, thereby establishing an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent path formed by the target node and the gateway. The first multiplexed stream identifier ensures the direction of data transmission, and the transparent path formed by the target node and the gateway improves the security of data transmission; multiple terminal devices can establish leases with the same super node, thereby reducing the number of long connection sessions established between the terminal devices and the server, and reducing the hardware cost and operation and maintenance cost of the server. Attached Figure Description
[0016] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating a method for establishing a session channel according to an embodiment of this application; Figure 2 This is a schematic diagram of the data transmission structure of a session channel establishment method provided in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of a terminal device connection device provided in an embodiment of this application; Figure 4 This is a schematic diagram of the hardware structure of a terminal device provided in an embodiment of this application. Detailed Implementation
[0018] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples of this application.
[0019] It should be noted that, in this document, relational terms such as "second" and "third" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0020] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The embodiments will now be described in detail with reference to the accompanying drawings.
[0021] In related technologies, multiple terminal devices establish session channels with the server through gateways, message forwarding nodes, etc. When the number of terminal devices becomes too large, the server will be under enormous pressure on file descriptors, memory, and threads, leading to a sharp increase in hardware and maintenance costs and making it difficult to achieve cost-effective horizontal scaling. In addition, business data streams usually need to be terminated, decrypted, or parsed at the gateway to achieve routing and load balancing, making the gateway a point of visibility for plaintext business data, posing a risk of data leakage.
[0022] For example, when multiple terminal devices establish a session channel with a server through a message forwarding node (Broker), the heartbeat data sent by the terminal devices is directly sent to the server. The number of server connections and the amount of heartbeat data received are linearly related to the number of terminal devices, and the message forwarding node does not have the ability to pass through or converge data.
[0023] For example, when multiple terminal devices establish a session channel with a server through a gateway, the gateway is a fixed device and cannot be dynamically adjusted according to the number of terminal devices accessing the server. The number of terminal devices accessing the server is limited by the gateway's capacity and quantity. The gateway also lacks pass-through and data convergence capabilities.
[0024] To address the problems of the prior art, embodiments of this application provide a method, apparatus, terminal device, and storage medium for establishing a session channel. The method for establishing a session channel provided in this application embodiment will be described first below.
[0025] Figure 1 This illustration shows a flowchart of a method for establishing a session channel according to an embodiment of this application. The server establishes at least one session with multiple terminal devices through a gateway; the session channel establishment method is applied to a first terminal device among the multiple terminal devices; when the first terminal device is not a super node, the session channel establishment method includes: S110, Receive the node candidate set sent by the scheduler of the server, and determine a super node as the target node from the node candidate set according to the preset selection rules. The node candidate set includes at least one super node selected from multiple terminal devices. S120, establish a lease with the target node; S130, a session binding request is sent to the target node so that the target node generates a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, and registers the first multiplexed stream identifier with the gateway. Through the transparent transmission path formed by the target node and the gateway, an encrypted session channel carrying the first multiplexed stream identifier is established with the server.
[0026] The session channel establishment method provided in this application can be applied to a first terminal device. The first terminal device, at least one second terminal device, and other terminal devices (leaf nodes) all establish a long-lived connection session with the server through a gateway (GW), which can be an application server.
[0027] In this embodiment, a massive number of terminal devices are distributed in a complex network environment. The server's scheduler (SCH) dynamically selects super nodes (SN) as relays based on performance indicators. The super nodes establish a few long connections with the gateway, and the gateway is responsible for mapping the multiplexed data streams to the server, thereby achieving convergence of the number of connections between the massive number of terminal devices and the server, as well as end-to-end secure and efficient transmission.
[0028] The first terminal device can act as a regular node in the system, i.e., a non-super node. This first terminal device establishes an encrypted session channel with the server through the super node and gateway. The first terminal device can also act as a super node in the system, and other terminal devices, such as the second terminal device, establish encrypted session channels with the server through the first terminal device and gateway.
[0029] The gateway can be a cloud gateway. The cloud gateway, scheduler, and business server can be deployed together in the same geographical location, while the terminal devices can be distributed across multiple regions. In this embodiment, the server establishes at least one session with multiple terminal devices through the gateway. This at least one session can be a long-lived connection session based on QUIC (QUIC transport protocol) or HTTP3 (Hypertext Transfer Protocol 3), carrying independent data streams. The terminal devices also establish an encrypted session channel with the server through a transparent path formed by the supernode and the gateway. This encrypted session channel can be based on Transport Layer Security (TLS) or application layer session frames. The supernode performs ciphertext transparent forwarding, and the supernode is unaware of the plaintext business data. Optionally, multiple supernodes map the inner sessions of the connected terminal devices into QUIC data streams and send them to the gateway.
[0030] The scheduler dynamically selects one or more super nodes adapted to the first terminal device based on performance indicators, and these one or more super nodes constitute a node candidate set. The first terminal device dynamically selects a super node from the node candidate set as the target node based on its own communication indicators, and then establishes a lease with the target node. The lease limits the data transmission quota, keep-alive period, lease duration, data transmission priority, etc. between the first terminal device and the target node.
[0031] After successfully establishing a lease with the target node, a session binding request is sent to the target node. This causes the target node to generate a first multiplexed stream identifier corresponding to the first terminal device based on the session binding request, and register the first multiplexed stream identifier with the gateway. This first multiplexed stream identifier allows identification of data sent by different terminal devices, as well as data sent by the same terminal device based on different service instances. When the first terminal device sends encrypted data carrying the first multiplexed stream identifier to the target node, the target node can determine the gateway to which the encrypted data should be transmitted based on the first multiplexed stream identifier, and the gateway can determine the server to which the encrypted data should be transmitted based on the first multiplexed stream identifier. The target node and the gateway only transmit the encrypted data transparently; neither the target node nor the gateway decrypts the encrypted data, nor are they aware of its content.
[0032] In the session channel establishment method provided in this application, a super node is selected as the target node from the node candidate set sent by the scheduler of the receiving server according to a preset selection rule. This allows for dynamic selection of the required super node as the target node. A lease is established with the target node, and a session binding request is sent to the target node. The target node generates a first multiplexed stream identifier corresponding to the first terminal device based on the session binding request and registers the first multiplexed stream identifier with the gateway. Thus, an encrypted session channel carrying the first multiplexed stream identifier is established with the server via the transparent path formed by the target node and the gateway. The first multiplexed stream identifier ensures the direction of data transmission, and the transparent path formed by the target node and the gateway improves the security of data transmission. Multiple terminal devices can establish leases with the same super node, thereby reducing the number of long-connection sessions established between the terminal devices and the server, and reducing the hardware and maintenance costs on the server side.
[0033] In some embodiments, prior to S110, the following is included: S210 sends a communication link observation report to the scheduler through the gateway; S220, Receive the node candidate set adapted to the terminal device generated by the scheduler based on the communication link observation report. The node candidate set includes the node identifier of the super node and the scheduling policy information corresponding to the node identifier. S120 includes: S230, Receive the node candidate set sent by the scheduler; S240, based on the round-trip delay with each super node, network topology region affinity, network address translation affinity, and scheduling policy information, determine a super node as the target node from the node candidate set.
[0034] The first terminal device can send a communication link observation report to the scheduler when it comes online, switches networks, or reaches a preset discovery period (Δt_discover). The communication link observation report includes, but is not limited to: the device identifier (node_id) of the first terminal device, the network topology region (region / as) of the first terminal device, the Network Address Translation (NAT) type (nat_type), the round-trip time quantile (rtt_p50 / p95), the packet loss rate (loss), the network latency fluctuation level (jitter), the uplink and downlink bandwidth (bw_up / down), the uptime (uptime), the temperature (temp / power), the protocol support capabilities (proto_caps), the supported TLS suite versions (sec_caps), the timestamp of sending the communication link observation report (ts_ms), and the anti-duplicate random number (nonce).
[0035] The scheduler can perform deduplication, normalization, and outlier processing on multiple received communication link observation reports based on the receiving device identifier and timestamp. Then, it uses the communication link observation reports received within a preset event window as observation samples, performs a comprehensive score on the observation samples, and selects one or more super nodes from multiple terminal devices based on the comprehensive score, network topology region, and capacity constraints, generating a node candidate set Ck that includes one or more super nodes.
[0036] Optionally, the preset event window is 5-15 minutes. Optionally, the comprehensive score can be calculated using exponential smoothing and confidence interval limiting. The higher the comprehensive score, the better the performance of the terminal device as a super node. Optionally, the scheduler generates different node candidate sets Ck for different network topology regions, and the scheduler sends the same node candidate set Ck to terminal devices that are not super nodes in the same network topology region.
[0037] In some embodiments, the scheduler sets a terminal device that has not reported a communication link observation report for several consecutive preset discovery periods as a non-super node. In some embodiments, upon receiving a regional jitter alarm or capacity alarm for a first network topology region, the scheduler regenerates a node candidate set Ck corresponding to that first network topology region. In some embodiments, if the number of observed samples is lower than a preset number of samples, the node candidate set Ck corresponding to the previous preset event window is retained as the node candidate set Ck corresponding to the current preset event window.
[0038] The scheduler sends a node candidate set Ck to the first terminal device. The node candidate set Ck includes, but is not limited to, the supernode's node identifier (sn_id), overall score (score), service coverage area (cover_radius), and lease capacity limit (lease_quota). Scheduling policy information includes, but is not limited to, policy version (policy_version), candidate set validity period (validity), suggested jitter hint (jitter_hint), and anti-duplicate random number (nonce). The first terminal device receives and updates its stored node candidate set Ck. In some embodiments, the node candidate set Ck is empty; the first terminal device switches to a session mode that establishes a session with the server through a gateway and requests scheduling additions from the scheduler.
[0039] After receiving a non-empty set of candidate nodes, the first terminal device determines a target supernode from the candidate node set within a preset selection time based on round-trip time with each supernode, network topology affinity, network address translation affinity, and a comprehensive score. Optionally, the round-trip time, network topology affinity, and network address translation affinity of the supernode have different priorities, from highest to lowest: network topology affinity, network address translation affinity, round-trip time, and comprehensive score. Preferably, the preset selection time is 2-5 seconds. Preferably, the round-trip time is the median of 3-5 samples.
[0040] In this embodiment, a super node is selected as the target node from the node candidate set based on the round-trip latency with each super node, network topology region affinity, network address translation affinity, and scheduling policy information, thereby achieving dynamic selection of a suitable target node and improving the performance of the super node that establishes a connection with the first terminal device.
[0041] In some embodiments, S130 includes: S310, send a lease request to the target node; S320: Upon receiving lease confirmation information from the target node in response to the lease request, establish a lease with the target node based on the lease confirmation information. S330: Upon receiving a lease rejection message from the target node in response to the lease request, update the target node to another super node in the node candidate set, and execute S310 until a lease is established with the target node.
[0042] The first terminal device initiates a lease request to the target node. The lease request includes, but is not limited to, the device identifier (leaf_id) of the first terminal device, the node identifier (sn_id) of the target node, the requested quota (quota_req), the suggested keep-alive period (hb_period_suggest), the suggested lease duration (ttl_suggest), the service instance identifier (svc_id), the service quality tag (qos_tag), the security parameters of the session with the server (sec_params), and the anti-duplicate random number (nonce). If no feedback information is received from the target node according to the lease request within the first preset duration, the first terminal device initiates another lease request to the target node, updates the historical request count, and increases the first preset duration. If no feedback information is received from the target node according to the lease request within the first preset duration, the first terminal device initiates another lease request to the target node, updates the historical request count, and increases the first preset duration, until the historical request count reaches the preset request count. The first terminal device then updates the target node to another super node in the node candidate set, initializes the historical request count and the first preset duration, and executes S310 until a lease is established with the target node. Optionally, the preset number of requests is 3 to 5. Optionally, the first preset duration is initialized to 2 seconds, and the first preset duration is increased by 200 to 800 ms each time.
[0043] After receiving a lease request from the first terminal device, the target node analyzes the request. If the lease request meets the preset invitation rules, it sends a lease confirmation message (Lease-Ack) to the first terminal device. The preset invitation rules include, but are not limited to: the first terminal device's device identifier is not in a preset blacklist, the target node has a quota compatible with the lease request, and the first terminal device is within the network topology area covered by the target node. The lease confirmation message includes, but is not limited to, lease identifier (lease_id), lease validity period (ttl), keep-alive period (hb_period), authorized quota (quota_grant), priority class (prio_class), and security context (sec_ctx). Upon receiving the lease confirmation message, the first terminal device starts a keep-alive timer, where the keep-alive timer equals the keep-alive period (hb_period) ± jitter, and the first terminal device switches to lease active state. If the lease confirmation message is less than the first terminal device's preset minimum service requirement, the first terminal device switches to a session mode that establishes a session with the server through the gateway and requests additional scheduling from the scheduler.
[0044] If the lease request does not meet the preset invitation rules, a lease rejection message is sent to the first terminal device. The first terminal device executes S230 and updates the target node to a super node in the node candidate set that has not received a lease rejection message. It then executes S310 to send a lease request to the new target node until a lease is established with the target node. If the first terminal device fails to establish a lease with any super node in the node candidate set, it switches to a session mode that establishes a session with the server through the gateway and requests scheduling supplementation from the scheduler.
[0045] In this embodiment, by establishing a lease with the target node, the operations of establishing a connection, authentication and authorization for each session are simplified, thereby improving data transmission efficiency.
[0046] In some embodiments, S130 includes: S410, establishes or resumes an inner session with the server; S420, based on the first session identifier of the inner session and the first service identifier of the service instance corresponding to the inner session, a session binding request is sent to the target node, so that the target node allocates the first multiplexed flow identifier corresponding to the first session identifier according to the session binding request, updates the preset routing mapping table, and registers the first multiplexed flow identifier with the gateway. The preset routing mapping table includes the mapping relationship between the device identifier of the first terminal device, the first service identifier, and the first multiplexed flow identifier. S430 receives the first multiplexed stream identifier sent by the target node, and establishes an encrypted session channel with the server carrying the first multiplexed stream identifier via the transparent path formed by the target node and the gateway.
[0047] In S410, the inner session with the server differs from the outer session established directly between the first terminal device and the server through the gateway. The inner session transmits data through an encrypted session channel. This in-memory session can be TLS or an application-layer session. Upon resuming the inner session, the existing security and sequence number context are used to continue the session.
[0048] The first terminal device submits a session binding request (Bind-Session) to the target node. The session binding request includes, but is not limited to, the first terminal device's device identifier (leaf_id), service instance identifier (svc_id), session identifier (sess_key_id), and service quality tag (qos_tag). The target node allocates a first multiplexed stream identifier (stream_id) to the first terminal device based on the session binding request and updates the preset routing table. The preset routing table contains the mapping relationship between the first multiplexed stream identifier (stream_id), device identifier (leaf_id), and service instance identifier (svc_id). For the same terminal device, the same service instance identifier, and the same session identifier, the target node allocates the same first multiplexed stream identifier. If, during the first terminal device's submission of the session binding request to the target node, the target node has already allocated a first multiplexed stream identifier for the same terminal identifier, service instance identifier, and session identifier, then it will not reassign the first multiplexed stream identifier for this received session binding request, but will reuse the already allocated first multiplexed stream identifier to ensure idempotency.
[0049] The target node not only assigns a first multiplexed flow identifier to the first terminal device, but also registers the route mapping from the first multiplexed flow identifier to the service instance with the gateway. This route mapping carries a mapping table version value (map_version), which monotonically increments to distinguish the preset route mapping tables that have undergone sequential update operations. After the gateway atomically updates, it enters the mapping table ready state. The gateway can report the mapping table ready state information to the server, but it does not report the mapping table update operation. Repeated registration by a supernode based on the same first multiplexed flow identifier will not change the valid mapping of that first multiplexed flow identifier in the preset route mapping table.
[0050] By sending a session binding request, the gateway assigns a first multiplexed flow identifier to the first terminal device based on the first session identifier of the inner session and the first service identifier of the service instance corresponding to the inner session. This allows the gateway to establish a mapping relationship between the inner session of the first terminal device and the server for transmission between the target node and the gateway based on the first multiplexed flow identifier. The target node updates the preset routing mapping table and registers the first multiplexed flow identifier with the gateway, enabling the gateway and the target node to synchronize the mapping relationship between the inner session of the first terminal device and the server for transmission between the target node and the gateway. Thus, when the first terminal device sends session information with the first multiplexed flow identifier, the session information is transmitted to the server via the transparent path formed by the target node and the gateway.
[0051] In some embodiments, after S130, the following is included: S510, obtain link parameter information between the target node; S520: If the link parameter information meets the preset congestion rules, another super node is determined as the replacement node from the node candidate set according to the preset selection rules. S530, a lease restoration request is sent to the replacement node so that the replacement node establishes a lease with the first terminal device according to the lease restoration request, updates the preset routing mapping table, registers the first multiplexed flow identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed flow identifier with the server through the transparent path formed by the replacement node and the gateway.
[0052] The first terminal device and the target node determine link parameter information based on rolling window statistics. Link parameter information includes, but is not limited to, queue delay (queue_delay), packet loss rate (loss), round-trip time (RTT), and device temperature. In some embodiments, when the queue delay is greater than a preset delay, or the packet loss rate is greater than a preset packet loss rate, or the round-trip time is greater than a preset delay, or the device temperature exceeds a preset temperature, the link parameter information is considered to meet a preset congestion rule, and a congestion alarm is triggered. The recovery threshold can use hysteresis (e.g., 0.8 × θ_q) to avoid oscillation. The preset packet loss rate is 2–5%. The preset delay is 50–100 ms. The preset delay is β_q * the baseline P95 value of the delay (baseline_p95), where β_q is a sensitivity coefficient, β_q ∈ [1.5, 2.0].
[0053] In some embodiments, the congestion alarm is canceled if the queuing delay is less than or equal to the recovery threshold. The recovery threshold is a * preset delay. a is a value less than 1 to avoid oscillations. Optionally, a is 0.8.
[0054] Without terminating the existing session, the first terminal device determines another super node as the replacement node from the node candidate set and sends a lease-resume request to the replacement node. The lease-resume request includes, but is not limited to, the lease identifier (lease_id), session identifier (sess_key_id), and processed data sequence identifier (last_seq) between the replacement node and the target node, so that after the replacement node establishes a lease with the first terminal device, the replacement node can replace the old target node as the new target node to continue the session information pass-through work.
[0055] In some embodiments, if a lease is not established with a replacement node within a preset time, S520 is executed to reselect a replacement node.
[0056] After the replacement node establishes a lease with the first terminal device, it still needs to perform an atomic switch of the first multiplexed flow identifier with the gateway. It can also perform dual-path forwarding within a time of no more than 200 ms to process the data in transit. It also registers the route mapping from the first multiplexed flow identifier to the service instance with the gateway. The updated route mapping carries the incrementally effective mapping table version value and does not report the mapping table update operation to the server. The server side is unaware of the relay change.
[0057] The old supernode enters the draining phase, completing the transmission of buffered data and closing the relevant streams within a preset duration (T_drain) of 500–1500 ms; low-priority fragments that have not been drained within the preset duration are discarded, and status information (DRAIN_RESULT) is generated, which is recorded by the gateway and scheduler.
[0058] After the first terminal device confirms that the target node has switched to the replacement node, it updates the current target node and the local timer, and reports the switch event information to the scheduler for statistics and subsequent scheduling optimization. The first terminal device then returns to the active state and continues its services.
[0059] By first establishing a lease with the replacement node and then replacing the target node with the replacement node, the first terminal device can achieve hot switching with the super node in the event of congestion, which helps to improve data transmission efficiency.
[0060] In some embodiments, when the first terminal device is a supernode, the method for establishing a session channel further includes: S610, Receive a lease request from a second terminal device based on a node candidate set sent by the scheduler, wherein the multiple terminal devices include the second terminal device and the node candidate set includes at least the first terminal device; S620, establishes a lease with the second terminal device according to the lease request; S630: Receive a session binding request sent by the second terminal device, generate a second multiplexed stream identifier according to the session binding request, and register the second multiplexed stream identifier with the gateway, so that the second terminal device can establish an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent transmission path formed by the first terminal device and the gateway.
[0061] The first terminal device can be a non-super node or selected as a super node. When the first terminal device is a super node, at least one non-super node establishes a session channel with the server through the first terminal device and the gateway. This at least one non-super node may include a second terminal device.
[0062] In the session channel establishment method provided in this application, a lease is established with the second terminal device by receiving a lease request sent by the second terminal device according to the node candidate set sent by the scheduler; a second multiplexed flow identifier is generated according to the session binding request sent by the second terminal device by receiving a session binding request and registering the second multiplexed flow identifier with the gateway, so that the second terminal device establishes an encrypted session channel carrying the first multiplexed flow identifier with the server through the transparent path formed by the first terminal device and the gateway. The first multiplexed flow identifier ensures the direction of data transmission, and the transparent path formed by the target node and the gateway improves the security of data transmission. Multiple terminal devices can establish leases with the first terminal device, thereby reducing the number of long connection sessions established between the terminal devices and the server, and reducing the hardware cost and operation and maintenance cost of the server.
[0063] In some embodiments, S630 includes: S710. Receive a session binding request sent by the second terminal device. The session binding request includes the second session identifier of the inner session between the second terminal device and the server, and the second service identifier of the service instance corresponding to the inner session. S720. Assign a second multiplexed flow identifier corresponding to the second session identifier to the second terminal device according to the session binding request, update the preset route mapping table, and register the second multiplexed flow identifier with the gateway. The preset route mapping table includes the mapping relationship between the device identifier of the second terminal device, the second service identifier, and the second multiplexed flow identifier. S730. Generate a mapping registration request according to the preset routing mapping table and send the mapping registration request to the gateway to register the second multiplexed flow identifier with the gateway, construct a transparent path formed by the second terminal device through the first terminal device and the gateway, and establish an encrypted session channel carrying the second multiplexed flow identifier with the server.
[0064] The second terminal device submits a session binding request (Bind-Session) to the first terminal device. The session binding request includes, but is not limited to, the second terminal device's device identifier (leaf_id), service instance identifier (svc_id), session identifier (sess_key_id), and service quality tag (qos_tag). The first terminal device allocates a second multiplexed stream identifier (stream_id) to the second terminal device based on the session binding request and updates the preset routing table. The preset routing table contains the mapping relationship between the second multiplexed stream identifier (stream_id), the first terminal device's device identifier (leaf_id), and the service instance identifier (svc_id). For the same terminal device, the same service instance identifier, and the same session identifier, the first terminal device allocates the same second multiplexed stream identifier. If, during the second terminal device's submission of a session binding request to the first terminal device, the first terminal device has already allocated a second multiplexed stream identifier for the same terminal identifier, service instance identifier, and session identifier, then it will not reassign a second multiplexed stream identifier for this received session binding request, but will reuse the already allocated second multiplexed stream identifier to ensure idempotency.
[0065] The first terminal device has not only assigned a second multiplexed flow identifier to the second terminal device, but also registered the route mapping from the second multiplexed flow identifier to the service instance with the gateway. This route mapping carries a mapping table version value (map_version), which monotonically increments to distinguish the preset route mapping table that has undergone successive update operations. After the gateway atomically updates, it enters the mapping table ready state. The gateway can report the mapping table ready state information to the server, but does not report the mapping table update operation. Repeated registration by the first terminal device based on the same second multiplexed flow identifier will not change the valid mapping of that second multiplexed flow identifier in the preset route mapping table.
[0066] By assigning a second multiplexed flow identifier to the second terminal device based on the first session identifier of the inner session and the first service identifier of the service instance corresponding to the inner session, a mapping relationship for the transmission of the inner session between the second terminal device and the server can be established based on the second multiplexed flow identifier. The first terminal device updates the preset routing mapping table and registers the second multiplexed flow identifier with the gateway, so that the gateway and the target node synchronize the mapping relationship for the transmission of the inner session between the second terminal device and the server between the first terminal device and the gateway. Thus, when the second terminal device sends session information with the first multiplexed flow identifier, the session information is transmitted to the server through the transparent path formed by the first terminal device and the gateway.
[0067] In some embodiments, the method for establishing a session channel further includes: S810, receives a keep-alive signal sent by a third terminal device at preset keep-alive intervals, wherein the third terminal device is a terminal device among multiple terminal devices that has established a lease with the first terminal device; S820 generates a heartbeat aggregation packet based on the keep-alive signals sent by multiple third-party terminal devices within at least two preset keep-alive cycles at intervals, and sends the heartbeat aggregation packet to the gateway. The S830 receives network adjustment instructions from the gateway based on the heartbeat aggregation packets sent by multiple super nodes, sends network adjustment instructions to the third terminal device, and coordinates with the third terminal device according to the network adjustment instructions.
[0068] Multiple third-party terminal devices establish leases with a first-party terminal device. While transmitting service frames, the third-party terminal devices send lightweight keep-alive signals to the first-party terminal device according to a preset keep-alive period (hb_period), while the first-party terminal device does not directly send the keep-alive signals to the gateway. The keep-alive signals include, but are not limited to, the device identifier (lease_id), the live bit (alive_bit), and the round-trip time delay sample (rtt_sample) of the third-party terminal device.
[0069] Every two preset keep-alive cycles (Δt_agg), the first terminal device aggregates the activity and lease changes of all subordinate third terminal devices to form a heartbeat aggregation packet. The heartbeat aggregation packet includes, but is not limited to, the first terminal device's node identifier (sn_id), aggregation protection cycle identifier (epoch), active bitmap, remaining lease duration (ttl_delta), queue length quantiles (qlen_p50 / p95), round-trip delay quantiles (rtt_p50 / p95), and packet loss rate. The active bitmap can be compressed using bitmap / Bloom and run-length or variable-length encoding, and the remaining lease duration can be displayed using variable-length encoding to reduce packet size. Optionally, the preset keep-alive cycle is (2~3) * hb_period.
[0070] The first terminal device multiplexes service frames and heartbeat aggregation packets onto a small number of outer-layer streams before sending them to the gateway, reducing the number of long connections and management overhead. The control plane takes precedence over the data plane, maintaining metrics such as inflight, round-trip time (RTT), packet loss rate, and retransmission count. It also incorporates token bucket technology to implement rate shaping and pre-congestion suppression. Optionally, independent control plane and data plane token buckets can be set up, with the control plane token generation rate ≥ 2 * data plane token rate. Tokens are retrieved from the corresponding bucket before packet transmission, thereby shaping bursty traffic into a stable flow and preventing instantaneous network overload.
[0071] The gateway reallocates resources and issues network adjustment commands based on heartbeat aggregation packets from multiple supernodes. These commands include, but are not limited to, lease renewal list updates (lease_renew), resource quota updates (quota_update), service priority updates (prio_update), and token bucket parameter updates (token_bucket). Optionally, for supernodes with queue backlogs exceeding a preset threshold or abnormal packet loss, the gateway can reduce the tokens in the data plane token bucket and increase the tokens in the control plane token bucket. It can also shorten the preset keep-alive period for subordinate devices of third-party devices connected to that supernode for encrypted observation.
[0072] The first terminal device sends the received network adjustment instructions to the third terminal device. The third terminal device, together with the first terminal device, adjusts the network operating parameters according to the network adjustment instructions. For example, the first terminal device sends the lease renewal list, resource quota updates, and service priority updates to the third terminal device. The first and third terminal devices prioritize unicast renewal of leases nearing the lease expiration time (TTL). For third terminal devices that have not responded for a long time or have abnormal packet loss, a warning status (LEASE_AT_RISK) is marked and reported to the gateway and scheduler. The first terminal device updates its local timer and quota and continues to operate.
[0073] Please see Figure 2 In this application, when the first terminal device is a non-super node, the leaf terminal of the first terminal device is responsible for session adaptation, local state sampling, and primary / backup switchover control. It encapsulates service data and samples its own communication link observation reports and link parameter information, and can proactively initiate pre-switching when queue or latency exceeds limits. When the first terminal device is a super node, it reuses the terminal sessions of multiple non-super nodes as data streams, compresses and reports the keep-alive signals of multiple terminals, and implements fine-grained queue management, rate shaping, and lease maintenance. It can also trigger local rate limiting and notify non-super nodes to switch when congestion is detected. The gateway and super node maintain a small number of multi-path QUIC connection pools, which are responsible for flow routing mapping and session migration, and issue backpressure and rate shaping instructions to the super node according to its real-time load to ensure control plane priority. The scheduler elects and publishes a set of node candidates for terminals based on communication link observation reports and manages the lifecycle of all leases. The server accesses the session without being aware of it through flow mapping, completely shielding the underlying complex network topology and switching logic.
[0074] Based on the session channel establishment method provided in the above embodiments, this application also provides specific implementation methods for the terminal device connection device. Please refer to the following embodiments.
[0075] See Figure 3This application provides a terminal device connection device 100, in which a server establishes at least one session with multiple terminal devices through a gateway; the terminal device connection device includes: The determining module 11 is used to receive a set of candidate nodes sent by the scheduler of the server when the first terminal device is not a super node, and determine a super node as the target node in the set of candidate nodes according to a preset selection rule. The set of candidate nodes includes at least one super node selected from multiple terminal devices. Lease establishment module 12 is used to establish a lease with the target node; The session channel establishment module 13 is used to send a session binding request to the target node, so that the target node generates a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, registers the first multiplexed stream identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent transmission path formed by the target node and the gateway.
[0076] In some embodiments, the terminal device connection device 100 further includes: The sending module is used to send communication link observation reports to the scheduler via the gateway; The receiving module is used to receive a set of node candidates adapted to the terminal device generated by the scheduler based on the communication link observation report. The set of node candidates includes the node identifier of the super node and the scheduling policy information corresponding to the node identifier. The determination module 11 is also used to receive the node candidate set sent by the scheduler; Based on the round-trip latency with each supernode, network topology affinity, network address translation affinity, and scheduling policy information, a supernode is selected as the target node from the candidate node set.
[0077] In some embodiments, the lease establishment module 12 is further configured to: Send a lease request to the target node; Upon receiving lease confirmation information from the target node in response to the lease request, a lease is established with the target node based on the lease confirmation information. Upon receiving a lease rejection message from the target node in response to the lease request, update the target node to another super node in the node candidate set, and execute: send a lease request to the target node until a lease is established with the target node.
[0078] In some embodiments, the session channel establishment module 13 is further configured to: Establish or resume an inner session with the server; Based on the first session identifier of the inner session and the first service identifier of the service instance corresponding to the inner session, a session binding request is sent to the target node so that the target node allocates the first multiplexed flow identifier corresponding to the first session identifier according to the session binding request, updates the preset routing mapping table, and registers the first multiplexed flow identifier with the gateway. The preset routing mapping table includes the mapping relationship between the device identifier of the first terminal device, the first service identifier, and the first multiplexed flow identifier. The system receives the first multiplexed stream identifier sent by the target node, and establishes an encrypted session channel with the server carrying the first multiplexed stream identifier via the transparent path formed by the target node and the gateway.
[0079] In some embodiments, the terminal device connection device 100 further includes: The acquisition module is used to obtain link parameter information between the target node and the target node; The replacement module is used to determine another super node as the replacement node from the node candidate set according to the preset selection rules when the link parameter information meets the preset congestion rules. The session channel establishment module 13 is also used to send a lease restoration request to the replacement node, so that the replacement node establishes a lease with the first terminal device according to the lease restoration request, updates the preset routing mapping table, registers the first multiplexed flow identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed flow identifier with the server through the transparent path formed by the replacement node and the gateway.
[0080] In some embodiments, when the first terminal device is a super node, the receiving module is further configured to receive a lease request issued by the second terminal device based on a node candidate set sent by the scheduler, wherein the multiple terminal devices include the second terminal device and the node candidate set includes at least the first terminal device. The lease establishment module 12 is also used to establish a lease with the second terminal device according to the lease request; The session channel establishment module 13 is also used to receive a session binding request sent by the second terminal device, generate a second multiplexed stream identifier according to the session binding request, and register the second multiplexed stream identifier with the gateway, so that the second terminal device can establish an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent transmission path formed by the first terminal device and the gateway.
[0081] In some embodiments, the session channel establishment module 13 is further configured to: Receive a session binding request sent by the second terminal device. The session binding request includes the second session identifier of the inner session between the second terminal device and the server, and the second service identifier of the service instance corresponding to the inner session. According to the session binding request, the second multiplexed flow identifier corresponding to the second session identifier is assigned to the second terminal device, and the preset route mapping table is updated and the second multiplexed flow identifier is registered with the gateway. The preset route mapping table includes the mapping relationship between the device identifier of the second terminal device, the second service identifier and the second multiplexed flow identifier. A mapping registration request is generated based on the preset routing mapping table, and a mapping registration request is sent to the gateway to register the second multiplexed flow identifier with the gateway. A transparent transmission path is constructed through the first terminal device and the gateway, and an encrypted session channel carrying the second multiplexed flow identifier is established with the server.
[0082] In some embodiments, the receiving module is further configured to: Receive keep-alive signals sent by a third terminal device at preset keep-alive intervals. The third terminal device is the terminal device that has established a lease with the first terminal device among multiple terminal devices. The terminal device connection device 100 also includes: The heartbeat aggregation module is used to generate a heartbeat aggregation packet based on the keep-alive signals sent by multiple third-party terminal devices within at least two preset keep-alive cycles, and send the heartbeat aggregation packet to the gateway at least every two preset keep-alive cycles. The adjustment module is used to receive network adjustment instructions from the gateway based on the heartbeat aggregation packets sent by multiple super nodes, send network adjustment instructions to the third terminal device, and coordinate with the third terminal device according to the network adjustment instructions.
[0083] The terminal device connection device 100 provided in this embodiment of the invention can implement the various steps in the above method embodiments, and will not be described again here to avoid repetition.
[0084] Figure 4 A schematic diagram of the hardware structure of the terminal device provided in an embodiment of this application is shown.
[0085] The terminal device may include a processor 1001 and a memory 1002 storing computer program instructions.
[0086] Specifically, the processor 1001 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0087] Memory 1002 may include mass storage for data or instructions. For example, and not limitingly, memory 1002 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 1002 may include removable or non-removable (or fixed) media. Where appropriate, memory 1002 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 1002 is non-volatile solid-state memory.
[0088] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.
[0089] The processor 1001 reads and executes computer program instructions stored in the memory 1002 to implement any of the session channel establishment methods in the above embodiments.
[0090] In one example, the terminal device may also include a communication interface 1003 and a bus 1010. The processor 1001, memory 1002, and communication interface 1003 are connected via the bus 1010 and communicate with each other.
[0091] The communication interface 1003 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0092] Bus 1010 includes hardware, software, or both, that couples components of an end device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 1010 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.
[0093] The terminal device can implement the above-described session channel establishment method and apparatus based on the above embodiments.
[0094] Furthermore, in conjunction with the session channel establishment method in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the session channel establishment methods in the above embodiments and achieve the same technical effect. To avoid repetition, further details are omitted here. The aforementioned computer-readable storage medium may include non-transitory computer-readable storage media, such as read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, etc., and is not limited thereto.
[0095] In addition, this application also provides a computer program product, including computer program instructions, which, when executed by a processor, can implement the steps and corresponding content of the aforementioned method embodiments.
[0096] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0097] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0098] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0099] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0100] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A method for establishing a session channel, characterized in that, The server establishes at least one session with multiple terminal devices through a gateway; the method for establishing the session channel is applied to the first terminal device among the multiple terminal devices. When the first terminal device is not a super node, the method for establishing the session channel includes: The system receives a set of candidate nodes sent by the scheduler of the server, and determines a super node as the target node from the set of candidate nodes according to a preset selection rule. The set of candidate nodes includes at least one super node selected from the plurality of terminal devices. Establish a lease with the target node; A session binding request is sent to the target node, so that the target node generates a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, registers the first multiplexed stream identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent path formed by the target node and the gateway.
2. The method for establishing a session channel according to claim 1, characterized in that, Before receiving the node candidate set sent by the scheduler of the server, the process includes: The gateway sends a communication link observation report to the scheduler. The system receives a set of candidate nodes adapted to the terminal device, generated by the scheduler based on the communication link observation report. The set of candidate nodes includes the node identifier of the super node and scheduling policy information corresponding to the node identifier. Receiving the node candidate set sent by the scheduler, and determining a super node as the target node from the node candidate set according to a preset selection rule, includes: Receive the node candidate set sent by the scheduler; Based on the round-trip latency with each of the supernodes, network topology region affinity, network address translation affinity, and the scheduling policy information, a supernode is determined from the node candidate set as the target node.
3. The method for establishing a session channel according to claim 1, characterized in that, The establishment of a lease with the target node includes: Send a lease request to the target node; Upon receiving lease confirmation information from the target node in accordance with the lease request, a lease is established with the target node based on the lease confirmation information; Upon receiving lease rejection information from the target node in response to the lease request, the target node is updated to another super node in the node candidate set, and the following steps are performed: send a lease request to the target node until a lease is established with the target node.
4. The method for establishing a session channel according to claim 1, characterized in that, The step of sending a session binding request to the target node, and establishing an encrypted session channel carrying the first multiplexed stream identifier with the server via a transparent path formed by the target node and the gateway, includes: Establish or resume an inner session with the server; Based on the first session identifier of the inner session and the first service identifier of the service instance corresponding to the inner session, a session binding request is sent to the target node, so that the target node allocates a first multiplexed flow identifier corresponding to the first session identifier according to the session binding request, updates the preset routing mapping table, and registers the first multiplexed flow identifier with the gateway. The preset routing mapping table includes the mapping relationship between the device identifier of the first terminal device, the first service identifier, and the first multiplexed flow identifier. The system receives the first multiplexed stream identifier sent by the target node and establishes an encrypted session channel carrying the first multiplexed stream identifier with the server via a transparent path formed by the target node and the gateway.
5. The method for establishing a session channel according to claim 4, characterized in that, After sending a session binding request to the target node, and establishing an encrypted session channel carrying the first multiplexed stream identifier with the server via the transparent path formed by the target node and the gateway, the process includes: Obtain the link parameter information between the target node and the target node; If the link parameter information meets the preset congestion rules, another super node is determined as a replacement node from the node candidate set according to the preset selection rules; A lease restoration request is sent to the replacement node, so that the replacement node establishes a lease with the first terminal device according to the lease restoration request, updates the preset routing mapping table, registers the first multiplexed flow identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed flow identifier with the server through the transparent path formed by the replacement node and the gateway.
6. The method for establishing a session channel according to claim 1, characterized in that, When the first terminal device is the super node, the method for establishing the session channel further includes: The system receives a lease request from a second terminal device based on a node candidate set sent by the scheduler, wherein the plurality of terminal devices includes the second terminal device and the node candidate set includes at least the first terminal device. Establish a lease with the second terminal device according to the lease request; The system receives a session binding request sent by the second terminal device, generates a second multiplexed stream identifier based on the session binding request, and registers the second multiplexed stream identifier with the gateway, so that the second terminal device can establish an encrypted session channel carrying the first multiplexed stream identifier with the server via the transparent path formed by the first terminal device and the gateway.
7. The method for establishing a session channel according to claim 6, characterized in that, The steps of receiving a session binding request sent by the second terminal device, generating a second multiplexed stream identifier based on the session binding request, and registering the first multiplexed stream identifier with the gateway, so that the second terminal device establishes an encrypted session channel carrying the second multiplexed stream identifier with the server via a transparent path formed by the first terminal device and the gateway, include: The system receives a session binding request sent by the second terminal device, wherein the session binding request includes a second session identifier of the inner session between the second terminal device and the server, and a second service identifier of the service instance corresponding to the inner session; According to the session binding request, a second multiplexed flow identifier corresponding to the second session identifier is allocated to the second terminal device, and the preset route mapping table is updated and the second multiplexed flow identifier is registered with the gateway. The preset route mapping table includes the mapping relationship between the device identifier of the second terminal device, the second service identifier and the second multiplexed flow identifier. A mapping registration request is generated according to the preset routing mapping table, and the mapping registration request is sent to the gateway to register the second multiplexed flow identifier with the gateway, construct a transparent path formed by the first terminal device and the gateway, and establish an encrypted session channel carrying the second multiplexed flow identifier with the server.
8. The method for establishing a session channel according to claim 6, characterized in that, The method for establishing the session channel also includes: The system receives keep-alive signals sent by a third terminal device at preset keep-alive intervals, wherein the third terminal device is a terminal device among the plurality of terminal devices that has established a lease with the first terminal device. Every two preset keep-alive cycles, a heartbeat aggregation packet is generated based on the keep-alive signals sent by the multiple third terminal devices within the at least two preset keep-alive cycles, and the heartbeat aggregation packet is sent to the gateway; The gateway receives network adjustment instructions fed back from the heartbeat aggregation packets sent by multiple super nodes, sends the network adjustment instructions to the third terminal device, and coordinates with the third terminal device according to the network adjustment instructions.
9. A terminal device connection device, characterized in that, The server has established at least one session with multiple terminal devices through the gateway; The terminal device connection device includes: The determination module is configured to receive a set of node candidates sent by the scheduler of the server when the first terminal device is not a super node, and determine a super node as the target node in the set of node candidates according to a preset selection rule. The set of node candidates includes at least one super node selected from the plurality of terminal devices. The lease establishment module is used to establish a lease with the target node; The session channel establishment module is used to send a session binding request to the target node, so that the target node generates a first multiplexed stream identifier corresponding to the first terminal device according to the session binding request, registers the first multiplexed stream identifier with the gateway, and establishes an encrypted session channel carrying the first multiplexed stream identifier with the server through the transparent path formed by the target node and the gateway.
10. A terminal device, characterized in that, The terminal device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the method for establishing a session channel as described in any one of claims 1-8.
11. A computer storage medium, characterized in that, The computer storage medium stores computer program instructions, which, when executed by a processor, implement the method for establishing a session channel as described in any one of claims 1-8.