Method and device for managing local area network equipment, storage medium and electronic device

By selecting proxy devices in the local area network and establishing remote management relationships, the problem of high public network address consumption when controlling network devices in the local area network is solved, and efficient and stable management of multiple network devices is achieved.

CN122120243APending Publication Date: 2026-05-29SUNWAVE COMM

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUNWAVE COMM
Filing Date
2026-02-26
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

When controlling network devices in a local area network, the existing technology consumes a large number of public network addresses, which leads to an increase in the complexity of operator NAT devices and a rise in management complexity.

Method used

By obtaining reference device information from multiple network devices in a local area network (LAN), proxy devices are selected, and a remote management relationship with the control devices is established. Only one public network address needs to be assigned to each network device in the LAN to achieve centralized control of multiple network devices.

Benefits of technology

It reduces the consumption of public network addresses, improves the efficiency and stability of remote management, and reduces the waste of public network resources and management complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120243A_ABST
    Figure CN122120243A_ABST
Patent Text Reader

Abstract

The application discloses a kind of management method and device of local area network equipment, storage medium and electronic device, it is applied to the target network equipment in multiple network equipment deployed in local area network, method includes: obtaining reference device information of reference network equipment;According to reference device information, proxy device is screened out in multiple network equipment;In the case where target network equipment is proxy device, target network equipment constructs remote management relationship with control device, wherein, control device is used to initiate the running control operation of multiple network equipment by remote management relationship between target network equipment, using the above technical solution, the technical problem that control device is larger in related art when controlling network equipment in local area network to public network address consumption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more specifically, to a method and apparatus for managing local area network (LAN) devices, a storage medium, and an electronic device. Background Technology

[0002] Currently, with the rapid popularization of 5G private networks, NB-IoT, and home cellular coverage, a large number of micro base stations (such as 4G / 5G GFemtocells and Small Cells) and IoT gateways are being deployed in home broadband networks, SME office networks, or industrial edge nodes. These devices generally access the Internet through residential optical modems, enterprise firewalls, or carrier-grade CGNAT (Carrier-Grade NAT), and are behind at least one or even multiple layers of NAT (Network Address Translation), meaning their local private IP (Internet Protocol) addresses cannot be directly accessed by the public network. To achieve remote operation and maintenance, including parameter configuration, log capture, fault diagnosis, security policy updates, and firmware upgrades, the industry widely adopts TR-069 (CPE WAN Management Protocol) as the standard management framework, and relies on its supplementary standard TR-111 to achieve reverse connection capabilities: network devices obtain public network mapping addresses through the STUN (Session Traversal Utilities for NAT) protocol and report them to the cloud ACS (Auto Configuration Server); when the ACS needs to issue instructions, it sends a plaintext UDP (User Datagram Protocol) trigger packet to this address, inducing the network device to actively initiate an HTTPS connection back. This mechanism can achieve basic remote management in an ideal network environment. However, with the increasing demand for network device deployment, dozens or even hundreds of network devices need to be deployed in a local area network in scenarios such as enterprise parks and smart factories. If each network device in the local area network is controlled in the above way, it will inevitably consume a large number of public network addresses, increase the complexity of the operator's NAT equipment, and exponentially increase the operational complexity.

[0003] There is still no effective solution to the problem of high public network address consumption when controlling network devices in a local area network in related technologies. Summary of the Invention

[0004] This application provides a method and apparatus for managing local area network (LAN) devices, a storage medium, and an electronic device, to at least solve the problem in related technologies that the control of network devices in a LAN consumes a large number of public network addresses.

[0005] According to one embodiment of this application, a method for managing local area network (LAN) devices is provided. The method is applied to a target network device among multiple network devices deployed in a LAN. The method includes:

[0006] Obtain reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time.

[0007] Based on the reference device information, a proxy device is selected from the plurality of network devices. The proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network. The control device is used to manage the operating status of the plurality of network devices.

[0008] When the target network device is determined to be the proxy device, the target network device establishes a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the plurality of network devices through the remote management relationship with the target network device.

[0009] Optionally, the step of selecting a proxy device from the plurality of network devices based on the reference device information includes: selecting a first device from the reference network devices based on the reference device information to proxy communication between the plurality of network devices and the control device during the reference time period; if the first device exists in the reference network devices, determining the first device as the proxy device; if the first device does not exist in the reference network devices, determining the target network device as the proxy device.

[0010] Optionally, the step of selecting a proxy device from the plurality of network devices based on the reference device information includes: predicting a first service load of the reference network device within a target time period after the current time based on the reference service load of the reference network device, and predicting a second service load of the target network device within the target time period based on the target service load of the target network device, wherein the reference device information includes the reference service load, which is used to indicate the service carrying capacity of the reference network device within the reference time period, and the target service load is used to indicate the service carrying capacity of the target network device within the reference time period; selecting a second device from the plurality of network devices whose service load is less than a preset load within the target time period based on the first service load and the second service load; and determining the second device as the proxy device.

[0011] Optionally, predicting the first service load of the reference network device within the target time period based on the reference service load of the reference network device includes: constructing a first load change curve of the reference network device using the reference service load, wherein the first load change curve records the change relationship of the service load of the reference network device over time; predicting the first service load of the reference network device within the target time period according to the change relationship of the service load over time recorded in the first load change curve; predicting the second service load of the target network device within the target time period based on the target service load of the target network device includes: constructing a second load change curve of the target network device using the target service load, wherein the second load change curve records the change relationship of the service load of the target network device over time; predicting the second service load of the target network device within the target time period according to the change relationship of the service load over time recorded in the second load change curve.

[0012] Optionally, the establishment of a remote management relationship between the target network device and the control device includes: obtaining the candidate lifetimes of multiple candidate public network mapping addresses allocated by the STUN server to devices within the local area network before the current time, wherein the candidate public network mapping addresses are used to indicate that devices within the local area network were allocated public network addresses in the public network before the current time, and the candidate lifetimes are used to indicate the storage duration of the corresponding candidate public network mapping addresses in the STUN server; predicting the remaining lifetime of the target public network mapping address allocated to the target network device during a target time period before the current time based on the candidate lifetimes; and sending the target public network mapping address and the remaining lifetimes to the control device, wherein the control device is used to call the target public network mapping address to send operation control commands to the target network device for devices within the local area network within the time window indicated by the remaining lifetimes.

[0013] Optionally, predicting the remaining lifespan of the target public network mapping address allocated to the target network device in the target time period based on the candidate lifespans includes: obtaining the target network address translation type of the target network device; filtering out a first lifespan corresponding to the target network address translation type from the candidate lifespans; predicting a second lifespan of the target public network mapping address based on the first lifespan; calculating the difference between the second lifespan and the third lifespan of the target public network mapping address to obtain the remaining lifespan, wherein the third lifespan is used to indicate the duration for which the target public network mapping address has been stored in the STUN server.

[0014] Optionally, after predicting the remaining lifespan of the target public network mapping address allocated to the target network device in the target time period based on the candidate lifespan, the method further includes: accessing the reference public network mapping address of the target network device stored in the STUN server according to the target access cycle; and if the reference public network mapping address and the target public network mapping address match, sending a target adjustment instruction to the control device, wherein the target adjustment instruction is used to instruct the control device to increase the remaining lifespan of the target public network mapping address by a target duration.

[0015] According to another embodiment of this application, a management device for local area network (LAN) devices is also provided. The device is applied to a target network device among multiple network devices deployed in a LAN. The device includes: an acquisition module, configured to acquire reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the multiple network devices, and the reference device information is used to indicate the operating status of the reference network device during a reference time period prior to the current time; a filtering module, configured to filter out proxy devices among the multiple network devices based on the reference device information, wherein the proxy device is used to proxy the multiple network devices to communicate with a control device deployed on a public network, and the control device is used to manage the operating status of the multiple network devices; and a construction module, configured to, when the target network device is determined to be the proxy device, establish a remote management relationship between the target network device and the control device, wherein the control device is used to initiate operation control operations on the multiple network devices through the remote management relationship with the target network device.

[0016] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, wherein a computer program is stored in the computer program, and the computer program is configured to execute the above-described management method for local area network devices when it is run.

[0017] According to another aspect of the embodiments of this application, an electronic device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the management method of the local area network device through the computer program.

[0018] In this embodiment, for multiple network devices deployed in a local area network (LAN), when communication with a control device deployed in a public network environment is required, reference device information of reference network devices (excluding the target network device) is obtained from the multiple network devices. This allows for the selection of a proxy device to act as an intermediary for communication between the multiple network devices and the control device based on the operating status of the multiple network devices within a reference time period. When the target network device is the proxy device, the target network device establishes a remote management relationship with the control device. This enables the control device to initiate operational control of all network devices deployed in the LAN through the target network device acting as the proxy device. In this process, only one public network address needs to be allocated to each network device in the LAN, solving the technical problem of high public network address consumption when the control device controls network devices in the LAN in related technologies. This achieves the technical effect of reducing the public network address consumption when the control device controls network devices in the LAN. Attached Figure Description

[0019] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0020] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a schematic diagram of the hardware environment for a local area network device management method according to an embodiment of this application;

[0022] Figure 2 This is a flowchart of a local area network (LAN) device management method according to an embodiment of this application;

[0023] Figure 3 This is a schematic diagram of a local area network device penetration-type remote control process according to an embodiment of this application;

[0024] Figure 4 This is a structural block diagram of a local area network (LAN) device management apparatus according to an embodiment of this application. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] The methods and embodiments provided in this application can be executed on a computer terminal, device terminal, or similar computing device. Taking running on a computer terminal as an example, Figure 1 This is a schematic diagram of the hardware environment for a local area network (LAN) device management method according to an embodiment of this application. Figure 1 As shown, a computer terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. In one exemplary embodiment, the computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, the computer terminal may also include components that are more complex than those described above. Figure 1 The more or fewer components shown, or having the same Figure 1 Equivalent functions or ratios shown Figure 1 The functions shown have more different configurations.

[0028] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the message push sending method in this embodiment of the invention. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0029] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the computer terminal. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0030] This embodiment provides a method for managing local area network (LAN) devices, applied to the aforementioned computer terminal. Figure 2 This is a flowchart of a local area network (LAN) device management method according to an embodiment of this application. The method is applied to a target network device among multiple network devices deployed in a LAN, and the process includes the following steps:

[0031] Step S202: Obtain reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time.

[0032] Step S204: Select a proxy device from the plurality of network devices according to the reference device information, wherein the proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network, and the control device is used to manage the operating status of the plurality of network devices;

[0033] Step S206: If the target network device is determined to be the proxy device, the target network device establishes a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the multiple network devices through the remote management relationship with the target network device.

[0034] Through the above steps, when multiple network devices deployed in a local area network (LAN) need to communicate with a control device deployed in a public network environment, reference device information of reference network devices (excluding the target network device) is obtained from the multiple network devices. This allows for the selection of a proxy device to facilitate communication between the multiple network devices and the control device based on their operating status within a reference time period. When the target network device acts as the proxy device, it establishes a remote management relationship with the control device. This enables the control device to initiate operational control of all network devices deployed in the LAN through the target network device acting as the proxy. This process only requires allocating one public network address to each network device in the LAN, solving the technical problem of high public network address consumption when the control device controls network devices in a LAN. This effectively reduces the public network address consumption of the control device when controlling network devices in a LAN.

[0035] This application's embodiments can be applied, but are not limited to, scenarios where a control device deployed on a public network performs reverse control over a network device deployed on a local area network (LAN). It primarily addresses the issue of network devices behind NAT / firewalls being actively accessed by controllers on the external network (public network).

[0036] In the technical solution provided in step S202 above, the multiple network devices are network devices deployed in a local area network environment, and the multiple network devices can communicate with each other through the local area network, but not limited to the local area network.

[0037] Optionally, in this embodiment, the reference device information is used to reflect how the reference network device performs its network connection, communication behavior, or resource usage during the reference time period. Its purpose is to provide a basis for selecting the network device that acts as a proxy for communication between the network device and the control device in the local area network from among multiple network devices.

[0038] In the technical solution provided in step S204 above, the purpose of filtering multiple network devices based on reference device information is to identify one or more suitable devices as communication intermediaries from a set of devices with communication capabilities. These devices must be able to establish connections between other network devices and control devices in the public network. The selected proxy device is not arbitrary; rather, it is a node determined to have proxy functionality based on specific attributes or conditions defined by the reference device information. Its function is to centrally handle the interaction between multiple network devices and the control device. The filtering principle for selecting proxy devices from multiple network devices can be a performance-first principle, i.e., based on the reference performance information of the reference network device and the target performance information of the target network device. The reference performance information indicates the service response capability of the reference network device for the handled services within a reference time period, and the target performance information indicates the service response capability of the target network device for the pending services within the reference time period. The reference device information includes the reference performance information. Then, based on the reference performance information and the target performance information, network devices with service response capabilities greater than or equal to the target threshold are selected from multiple network devices deployed in the local area network as proxy devices.

[0039] Optionally, in this embodiment, once the proxy device is selected, it assumes the role of a relay for forwarding control commands from the control device to other network devices besides itself. This allows these network devices to receive commands and report status through the proxy device without communicating directly with the control device on the public network. The control device only needs to maintain a communication link with the proxy device to achieve unified management of the operating status of multiple network devices without establishing separate independent connections. Thus, centralized control and status monitoring of multiple devices can be achieved without changing the original architecture of the control device.

[0040] In the technical solution provided in step S206 above, when the target network device is identified as a proxy device, it establishes a management channel that can be invoked by the control device by constructing a remote management relationship with the control device. This remote management relationship uses the proxy device as an intermediary node, enabling the control device to initiate operation control operations to multiple network devices based on this relationship, without having to establish an independent connection with each controlled device directly. The proxy device, as the endpoint of the management relationship, carries the logical bridge function of centralized scheduling and instruction transmission of the control device to multiple network devices, thereby realizing a collaborative mechanism in which a single control device implements operation control of multiple network devices through a unified management relationship.

[0041] Optionally, in this embodiment, by obtaining the operating status information of other network devices in the local area network besides the target network device within a reference time period, a proxy device with stable communication capabilities is intelligently selected based on this information. The proxy device then establishes a unified remote management relationship with the control device in the public network, thereby converging the independent communication channels originally scattered across multiple network devices into a single, centralized management path. This mechanism effectively alleviates the problem of limited public network resources under NAT, avoids bandwidth waste and increased management complexity caused by multiple devices establishing connections separately, and enables the control device to efficiently initiate unified operation control operations on all network devices through a single proxy node. This significantly improves remote management efficiency and device collaboration capabilities, ultimately achieving stable, centralized, and low-resource-consumption intelligent operation and maintenance of multiple devices in a restricted network environment.

[0042] Optionally, in this embodiment, to ensure the relay quality of control commands issued to the control device, the proxy device can dynamically switch between multiple network devices during the execution of relay services. In this embodiment, the dynamic switching of the proxy device can be initiated by a non-proxy device among the multiple network devices. Therefore, the control method for the local area network device further includes: when a third device in the reference network device is determined to be a proxy device, in a target time period after the current time period, the target network device obtains the first service information of the third device, wherein the first service information is used to indicate the third device's ability to handle the services undertaken in the target time period; when the first service information indicates that the third device's service handling ability in the target time period is lower than a target threshold, and the second service information of the target network device indicates that the target network device's service handling ability in the target time period is greater than or equal to the target threshold, the target network device sends a switching request to the reference network device, wherein the switching request is used to indicate that the target network device is configured as the proxy device, and then the target network device establishes a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the multiple network devices through the remote management relationship with the target network device.

[0043] Optionally, in this embodiment, to ensure the relay quality of control commands issued to the control device, the proxy device can dynamically switch between multiple network devices during the relay service. In this embodiment, the dynamic switching of the proxy device can be initiated by the proxy device itself. Therefore, after the target network device establishes a remote management relationship with the control device, the method further includes: obtaining third service information of the target network device within a target time period, and fourth service information of the reference network device within the target time period. The third service information is used to indicate the service processing capability of the target network device for the accepted services within the target time period, and the fourth service information is used to indicate the service processing capability of the reference network device within the target time period. The service processing capability of the target network device for the accepted services within a time period; when the third service information indicates that the service processing capability of the target network device is lower than the target threshold within the target time period, a fourth device is selected from the reference network devices whose service processing capability is greater than or equal to the target threshold according to the fourth service information; the target network device sends a switching instruction to the fourth device, wherein the switching instruction is used to instruct the fourth device to be configured as the proxy device, and the fourth device is used to respond to the switching instruction to establish a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the multiple network devices through the remote management relationship with the fourth device.

[0044] Optionally, in this embodiment, after the target network device establishes a remote management relationship with the control device, the method further includes: receiving a control instruction sent by the control device, wherein the control instruction is used to instruct the control device to request control of a candidate network device among the plurality of network devices to perform a target service operation; if the candidate network device is determined to be the target network device, responding to the control instruction to perform the target service operation; if the candidate network device is not the target network device, forwarding the control instruction to the candidate network device, wherein the candidate network device, after receiving the control instruction, responds to the control instruction to perform the target service operation.

[0045] As an optional embodiment, the step of filtering out the proxy device from the plurality of network devices based on the reference device information includes:

[0046] Based on the reference device information, a first device is selected from the reference network devices to act as an intermediary for communication between the plurality of network devices and the control device during the reference time period;

[0047] If the first device is present in the reference network device, the first device is identified as the proxy device;

[0048] If the first device is not present in the reference network devices, the target network device is identified as the proxy device.

[0049] Optionally, in this embodiment, the target network device obtains the operating status information of other network devices within the reference time period, identifies the first device that previously assumed the proxy communication responsibility, and prioritizes it as the current proxy device. This achieves stable inheritance of historical proxy roles and avoids management interruptions or communication oscillations caused by switching without a basis. When no device in the reference network has historical proxy behavior, the target network device is forced to assume the proxy responsibility itself. This ensures that the proxy role can still be reliably established even without historical reference, thereby ensuring that the remote management channel between all network devices and the public network control device can always be established and maintained. This effectively solves the problems of poor stability, high response latency, and management failure caused by uncertain proxy selection in multi-device collaborative management under NAT environment. It realizes intelligent reuse and fallback allocation of proxy roles and improves the overall reliability and efficiency of remote management of devices within the local area network.

[0050] As an optional embodiment, the step of filtering out the proxy device from the plurality of network devices based on the reference device information includes:

[0051] The reference network device is used to predict a first service load of the reference network device in a target time period after the current time based on the reference service load of the reference network device, and a second service load of the target network device in the target time period is predicted based on the target service load of the target network device, wherein the reference device information includes the reference service load, which is used to indicate the service carrying status of the reference network device in the reference time period, and the target service load is used to indicate the service carrying status of the target network device in the reference time period;

[0052] Based on the first service load and the second service load, a second device with a service load less than a preset load during the target time period is selected from the plurality of network devices;

[0053] The second device is identified as the agent device.

[0054] Optionally, in this embodiment, the method of predicting the first service load of the reference network device in a target time period after the current time based on the reference service load of the reference network device may include, but is not limited to: determining the third service load of the reference network device at multiple reference times included in the reference time period, wherein the reference service load includes the third service load; assigning a first weight parameter to each third service load according to the temporal change relationship between the third service loads at multiple reference times, wherein the first weight parameter is used to indicate the degree of influence of the third service load at the corresponding reference time on the service load of the reference network device at the target time; and using the first weight parameter to perform a weighted summation of the third service loads to obtain the first service load. Similarly, the method of predicting the second service load of the target network device within the target time period based on the target service load of the target network device includes: determining the fourth service load of the target network device at multiple reference times included in the reference time period, wherein the target service load includes the fourth service load; assigning a second weight parameter to each fourth service load according to the temporal change relationship between the fourth service loads at multiple reference times, wherein the second weight parameter is used to indicate the degree of influence of the fourth service load at the corresponding reference time on the service load of the target network device at the target time; and using the second weight parameter to perform a weighted summation of the fourth service loads to obtain the second service load.

[0055] Optionally, in this embodiment, the target network device obtains the reference service load of other network devices in the historical reference time period and its own target service load in the same time period, respectively predicts its first service load and second service load in the subsequent target time period, and comprehensively evaluates the resource carrying pressure of each device in the future time period based on the prediction results of the two, thereby selecting the second device with a service load lower than a preset threshold as the proxy device, ensuring that the selected proxy device has sufficient processing capacity and network bandwidth during critical communication periods, avoiding management command delays, communication interruptions or resource exhaustion caused by selecting a device that will soon be under high load to assume proxy responsibilities, significantly improving the stability and response efficiency of remote management in a multi-device collaborative environment, realizing the intelligent upgrade of the proxy mechanism from static historical judgment to dynamic load prediction under the condition of limited public network resources in the NAT environment, effectively ensuring the reliable remote control and status management of all devices in the local area network by the control device.

[0056] As an optional embodiment, predicting the first service load of the reference network device within the target time period based on the reference service load of the reference network device includes: constructing a first load change curve of the reference network device using the reference service load, wherein the first load change curve records the relationship between the service load of the reference network device and time; and predicting the first service load of the reference network device within the target time period according to the relationship between the service load and time recorded in the first load change curve.

[0057] The step of predicting the second service load of the target network device within the target time period based on the target service load of the target network device includes: constructing a second load change curve of the target network device using the target service load, wherein the second load change curve records the change relationship of the service load of the target network device over time; and predicting the second service load of the target network device within the target time period according to the change relationship of the service load over time recorded in the second load change curve.

[0058] Optionally, in this embodiment, a first load change curve is constructed using the reference service load of a reference network device within a reference time period to accurately depict the trend characteristics of its service load evolution over time. Based on the dynamic change pattern of this curve, its first service load within a target time period is predicted. Simultaneously, a second load change curve is constructed using the target service load of the target network device to analyze its own load temporal fluctuation pattern and predict its second service load within the same target time period. This upgrades the selection criteria for proxy devices from a single instantaneous load value to a load trend prediction based on the time dimension. This allows the selection process to comprehensively evaluate the future load carrying capacity of each device, effectively avoiding the problem of mistakenly selecting high-load devices due to instantaneous load fluctuations. This significantly improves the stability and foresight of proxy device selection, ensuring that in multi-device collaborative management under NAT, the device with the lightest and most stable load always assumes the proxy responsibility, and ensuring that the remote management operations of the control device on all network devices are continuously executed efficiently and reliably.

[0059] As an optional embodiment, the target network device establishes a remote management relationship with the control device, including:

[0060] Obtain the candidate lifetimes of multiple candidate public network mapping addresses allocated by the STUN server to devices within the local area network before the current time. The candidate public network mapping addresses are used to indicate that devices within the local area network were allocated public network addresses in the public network before the current time, and the candidate lifetimes are used to indicate the storage duration of the corresponding candidate public network mapping addresses in the STUN server.

[0061] Based on the candidate lifetime, predict the remaining lifetime of the target public network mapping address allocated to the target network device during the target time period before the current time.

[0062] The target public network mapping address and the remaining service life are sent to the control device, wherein the control device is used to call the target public network mapping address to send operation control instructions for the devices in the local area network to the target network device within the time window indicated by the remaining service life.

[0063] Optionally, in this embodiment, the method of predicting the remaining lifespan of the target public network mapping address allocated to the target network device in the target time period before the current time based on the candidate lifespan may include: calculating the average of the candidate lifespans and determining the calculated average lifespan as the remaining lifespan of the target public network mapping table address.

[0064] In this embodiment, the target network device obtains the candidate public network mapping addresses and their corresponding candidate lifespans allocated by the STUN server to multiple devices in the local area network before the current time. It analyzes the storage duration patterns of these addresses in the STUN server and predicts the remaining lifespan of the target public network mapping address allocated to it within the target time period. The device then actively sends the address and its remaining lifespan to the control device. Based on this timeliness information, the control device can accurately invoke the target public network mapping address to initiate remote management commands within the predicted effective time window. This avoids communication failures and resource waste caused by blindly sending commands after the mapping has expired. It optimizes the timing and improves the success rate of remote management operations for multiple devices, significantly enhancing the collaborative efficiency and management reliability between the proxy device and the control device in a NAT environment.

[0065] As an optional embodiment, predicting the remaining lifespan of the target public network mapping address allocated to the target network device during the target time period based on the candidate lifespan includes:

[0066] Obtain the target network address translation type of the target network device;

[0067] Select a first lifetime corresponding to the target network address translation type from the candidate lifetimes;

[0068] The second lifespan of the target public network mapping address is predicted based on the first lifespan.

[0069] The difference between the second lifetime and the third lifetime of the target public network mapping address is calculated to obtain the remaining lifetime, wherein the third lifetime is used to indicate the length of time the target public network mapping address has been stored in the STUN server.

[0070] Optionally, in this embodiment, the network address translation type may include, but is not limited to: full cone NAT, i.e., one-to-one NAT; restricted cone NAT; port restricted cone NAT; and symmetric NAT.

[0071] Optionally, in this embodiment, the method for predicting the second lifespan of the target public network mapping address based on the first lifespan can be as follows: averaging the first lifespan to obtain a third lifespan; calculating the product between the third lifespan and a target weight parameter to obtain a fourth lifespan, wherein the target weight parameter is used to indicate the influence of the candidate lifespan of the candidate public network mapping address on the lifespan of the target public network mapping address; if the fourth lifespan is less than a preset lifespan threshold, setting the lifespan value of the second lifespan to be equal to the fourth lifespan; if the fourth lifespan is greater than or equal to the preset lifespan threshold, setting the lifespan value of the second lifespan to be equal to the preset lifespan threshold.

[0072] In this embodiment, the target network device obtains its own target network address translation type and accurately selects the first lifespan that matches the type from the candidate lifespans of multiple candidate public network mapping addresses in the STUN server's historical records. Then, based on the type-specific historical lifespan data, it predicts the second lifespan of the target public network mapping address within the target time period. Combining this with the third lifespan that the mapping address has actually been saved in the STUN server, the remaining lifespan is dynamically obtained by calculating the difference between the two, thereby achieving type-adaptive prediction of the NAT mapping lifespan. This process fully considers the differentiated impact of different NAT types (such as full cone, restricted cone, port restricted cone, or symmetric) on the stability and renewal period of public network address mapping, avoiding the prediction deviation caused by the traditional unified estimation method ignoring type characteristics. It ensures that the control device triggers remote commands only within the real and effective management window period, significantly improving the accuracy and timeliness of remote management triggering, effectively preventing command mis-sending or omission, and ultimately ensuring the reliability and stability of remote collaborative management in a multi-device NAT environment.

[0073] As an optional embodiment, after predicting the remaining lifespan of the target public network mapping address allocated to the target network device during the target time period based on the candidate lifespan, the method further includes:

[0074] Access the reference public network mapping address of the target network device stored in the STUN server according to the target access cycle;

[0075] If the reference public network mapping address and the target public network mapping address match, a target adjustment command is sent to the control device, wherein the target adjustment command is used to instruct the control device to increase the remaining service life of the target public network mapping address by a target duration.

[0076] In this embodiment, after establishing a remote management relationship with the control device, the target network device, acting as a proxy device, periodically accesses its own reference public network mapping address stored in the STUN server. It actively compares whether the currently allocated target public network mapping address is consistent. When the two match, it indicates that its public network mapping is still in a stable and valid state. At this time, it actively sends a target adjustment command to the control device to request an extension of the remaining lifespan of the public network mapping address. Thus, without waiting for the device to actively report Inform messages, the control device can dynamically maintain a controllable time window for multiple devices in the local area network. This effectively avoids management interruptions and reconnection delays caused by the near expiration of the mapping lifespan, improves the continuity and response efficiency of remote command issuance, and ultimately achieves stability and real-time optimization of collaborative management of multiple devices in deployment scenarios with limited public network resources and complex NAT environments.

[0077] To systematically address the reliability, security, and resource efficiency issues of remote base station management in complex NAT environments, this application constructs a collaborative management architecture characterized by end-side autonomy, state-driven mechanisms, and multi-level redundancy. This architecture is organically composed of five layers: NAT behavior modeling serves as the perceptual basis for dynamically predicting reverse connection windows; based on this, session-level dynamic keys are derived to support a secure STUN trigger mechanism for strong authentication wake-up; in multi-device deployment scenarios, the exit point is aggregated through a master-slave collaborative address pool to reduce public network resource consumption; when the network environment deteriorates, an adaptive degradation mechanism automatically switches to polling or an emergency channel to ensure uninterrupted connectivity. These five layers are activated on demand, linked by state, and provide closed-loop feedback, collectively achieving highly reliable, highly secure, and low-overhead remote management capabilities without modifying the existing ACS platform. Figure 3 This is a schematic diagram of a local area network device penetration-type remote control process according to an embodiment of this application, such as... Figure 3 As shown, it should include at least the following:

[0078] (1) NAT behavior modeling and dynamic decreasing window reporting:

[0079] The base station (i.e., the multiple network devices deployed in the local area network mentioned above; this embodiment uses the network device as the base station for example) autonomously models NAT behavior based on local observation data, predicts the available time window of the current public network mapped address, and actively reports it to the TR-069 network management platform (ACS) (i.e., the control device mentioned above, which is used to remotely control the network devices in the local area network) in the form of "remaining seconds"), thereby achieving schedulable and predictable reverse connection capabilities. The process for implementing this step is as follows:

[0080] A. Initialize the behavior database: When the base station starts up, it loads historical NAT behavior records. Each record contains: timestamp (last binding completion time); nat_type (identified NAT type); mapped_addr (authorized address); port_stable (whether the port remains unchanged during multiple keep-alive events (boolean value)); actual_lifetime_sec (actual duration from binding to the first failure). If there is no historical data, it is initialized to empty and will be stored in subsequent records.

[0081] B. Detect and identify NAT types: Send a Binding Request to the pre-configured STUN server, parse the XOR-MAPPED-ADDRESS in the response, and record it as the current public network mapped address. Send multiple Binding Requests to different destination addresses / ports, and compare whether the returned XOR-MAPPED-ADDRESS are consistent. The type is determined as follows: Full Cone: IP:Port does not change with the target; Restricted Cone: IP:Port changes with the target IP, but not with the port; Port-Restricted Cone: IP:Port changes with the target IP + Port; Symmetric: Each request returns a different port. The identification results are used for subsequent lifetime prediction strategy selection.

[0082] C. Predict initial validity period T0: Query the average lifetime (avg_lifetime) of the same NAT type in historical records; Use a conservative weighting strategy: T0 = min(1.2 × avg_lifetime, 180), indicating that the predicted validity period is 1.2 times the historical baseline value, but cannot exceed 180 seconds. If there is no NAT type, use the default value; Calculate the remaining time: Tremaining = T0 - (current_time - binding_complete_time). If Tremaining ≤ 0, set it to 0, indicating that the window is closed; Report window: Report the available reverse connection time Device.STUN.ReverseConnectSec and Device.STUN.PublicAddress in the inform heartbeat. Based on this, an available time window can be established and a security trigger packet can be sent within the window; Active correction mechanism: The base station periodically (e.g., every 10 seconds) sends STUN Binding Request for keep-alive; If a change in the mapping address is detected and there is no response, an event-type Inform (Event Code: 6 CONNECTION) is immediately initiated. (REQUEST), report ReverseConnectWindowSec=0, and notify ACS window is invalid. Table 1 shows an example of the NAT behavior rule base.

[0083] Table 1

[0084]

[0085] Table 2 is an optional base station operation example table according to an embodiment of this application. The table records the base station operation status in chronological order, as shown in Table 2:

[0086] Table 2

[0087]

[0088]

[0089] (2) Dynamic key derivation mechanism:

[0090] For each STUN session, a unique, forward-secure, device-identified temporary session key K is generated, strongly correlated with the current NAT behavior characteristics. This ensures that security triggers verify not only "who you are" but also "what network environment you are in," thereby resisting advanced man-in-the-middle or NAT spoofing attacks. A dynamic key derivation mechanism is added, with detailed steps as follows:

[0091] A. After completing the first step of NAT modeling, determine the current NAT type and encode the type into a fixed-length byte string (UTF-8 encoded and padded to 32 bytes, with 0x00 added if necessary).

[0092] B. Initiate a STUN Binding Request, carrying the X.509 certificate SHA256 digest hash (Cert), a 128-bit random TXID, the X-NAT-TYPE attribute, and the NAT type.

[0093] C. Returns a Binding Success Response, which includes the NONCE value.

[0094] D. Both parties independently calculate the session key K, K=HMAC-SHA256(Hash(Cert)||TXID||NONCE||Encode(NAT_Type), PSK).

[0095] E. Key lifecycle monitoring: K is only valid within the current NAT mapping window. If the NAT type changes (e.g. due to firewall policy updates), even if the address remains the same, it is considered a new session and K is forcibly re-derived.

[0096] (3) Secure connection triggering mechanism:

[0097] In the traditional TR-111 mechanism, the ACS sends a plaintext HTTP GET request (e.g., GET / tr111?device=DeviceID) to the TR-111 server, triggering it to send an unauthenticated, unencrypted UDP wake-up packet to the base station's public IP address. Upon receiving the packet, the base station unconditionally initiates a TR-069 callback. This process lacks authentication and replay protection, making it vulnerable to forgery. To overcome these shortcomings, this stage's secure connection triggering mechanism completely replaces the TR-111 plaintext UDP triggering mechanism. It constructs a lightweight, standardized reverse connection command distribution channel with strong authentication, replay attack resistance, and strict binding to the NAT mapping window, ensuring that only legitimate network administrators can trigger the base station's proactive callback within the valid time window. The steps are as follows:

[0098] A. The network management system (ACS) constructs a security trigger packet:

[0099] Prerequisite verification: Confirm that the target base station is currently within a valid reverse connection window (i.e., ReverseConnectSec > 0); Obtain the session key K corresponding to the base station (locally cached after the last Inform report); Generate a replay protection challenge: Generate a 16-byte (128-bit) random number (example: 7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d); Obtain a high-precision timestamp, using a millisecond-level Unix timestamp (the number of milliseconds since 1970-01-01 UTC, example: 1768234567890, corresponding to 2026-01-13 20:16:07.890 UTC), for subsequent timeliness verification to prevent replay of old packets; Calculate the authentication token: Using the HMAC-SHA256 algorithm, with K as the key (a dynamic key within its validity period), calculate the token based on the challenge and timestamp. The concatenated value is signed as follows: Token = HMAC - SHA256(Challenge||Timestamp,K), and the output is a 32-byte fixed-length digest (example: a3f1e9c8...b2d7 (hexadecimal)); the STUN Indication message is encapsulated: the Method field is set to 0x0011 (Indication); the following fields are carried through custom attributes (compatible with RFC 5389 extension mechanism).

[0100] The entire message is sent via UDP to the public IP address:Port reported by the base station.

[0101] B. Base station side verification and response:

[0102] Listening and Receiving: The base station continuously listens on the UDP port during the NAT mapping window, receiving STUNIndication; Timeliness Verification: Extracts the Timestamp, calculates the absolute difference between it and the local current time. If |now-Timestamp| > 30,000ms (i.e., 30 seconds), it is discarded directly to prevent replay attacks; Identity and Legitimacy Verification: Using the locally cached session key K (from a valid dynamic key), the Token is recalculated in the same way. The calculated result is compared with the received Token byte by byte. If they do not match, it is silently discarded without returning any error (to avoid information leakage); Triggered Execution: If the verification passes, a standard TR-069 HTTPS Inform message is proactively initiated within 1 second. The Inform contains event code 6CONNECTIONREQUEST, indicating that this is a connection request triggered by ACS; Command Issuance: ACS embeds management commands in the Inform response (InformResponse), such as: Reboot, SetParameterValues(RadioEnable=false), GetParameterValues(Device.DeviceInfo). After the base station executes the procedure, it reports the result in the subsequent Inform. Based on the above information, it can be summarized that, to achieve the security requirements of identity authentication, the method adopted is that the token depends on K, and K is bound to the device certificate + NAT_Type, so only legitimate devices can generate a valid K value; when preventing duplication, the method adopted is to use Challenge random + Timestamp validity window (±30s), which expires 30 seconds after the packet is intercepted; when ensuring forward security, K is only valid in the current window and is destroyed when the window ends, so even if K is leaked, it will not affect historical / future sessions; when preventing forgery, attackers cannot reproduce the standard NAT environment and cannot generate the correct K, thus blocking cross-NAT type attacks; when standardizing, it is based on STUNIndication, requiring no new protocol and is compatible with existing network middleware (firewalls / NAT usually allow STUN).

[0103] Table 3 is an optional message structure table according to an embodiment of this application, as shown in Table 3:

[0104] Table 3

[0105]

[0106] (4) Multi-base station collaborative address pool mechanism:

[0107] In scenarios where multiple base stations (such as 5G Small Cells) are deployed in enterprise parks, factories, shopping malls, etc., the public network NAT mapping requirements of multiple devices are aggregated into a single exit point, significantly reducing the consumption of public network IPv4 port resources. Simultaneously, a unified and simplified logical view is presented to the network management system (ACS), improving manageability and resource efficiency. This unit designs a multi-base station collaborative address pool mechanism. By automatically selecting master and slave devices, the master device automatically registers for STUN service according to the first three stages and reports slave device information to the ACS. If the ACS wants to send commands to a slave base station, the master base station forwards them. The detailed steps are as follows:

[0108] A. Master-slave device negotiation:

[0109] When each device starts up, it first delays randomly by 0 to 2 seconds (staggering the power-on sequence); then it uses an ARP scan to detect whether there is already a master base station in the local area network; if not found, it waits another second for a second confirmation (to prevent another device from binding just now); if there is still no master station → it performs STUN binding on its own and becomes the master base station; if a master station already exists → it enters slave base station mode, does not initiate any external STUN requests, and does not listen to public network trigger ports.

[0110] B. Command delegation and confirmation:

[0111] When the ACS specifies a slave base station as the target through STUN Indication, the master base station forwards the instruction through the local UDP interface; a two-phase lightweight acknowledgment is adopted: ACK: the slave station returns immediately after receiving the instruction, indicating "enqueued"; DONE: the slave station returns after the operation is completed, including the execution result (success / failure); the master base station returns an InformResponse to the ACS based on the acknowledgment result: if DONE is received → report "operation successful"; if not received within the timeout → report "slave station unreachable" or "partial failure".

[0112] Results: Prevents false success reports, improves management reliability, and minimizes communication overhead.

[0113] C. Main station health monitoring (broadcast heartbeat):

[0114] The base station periodically checks the master station's liveness status using a dynamic frequency strategy: when the master station is running stably, the detection interval is 5 minutes, and the judgment is based on the default state; when the master station's response slows down, the detection interval is 30 seconds, and the judgment is based on a delay > 1 second; when the master station experiences consecutive timeouts, the detection interval is 5 seconds, and the judgment is based on two instances of no response.

[0115] Once the master station failure is confirmed, the slave base station immediately attempts to seize the master role and restore external management capabilities. Results: Low overhead during normal operation, rapid recovery during anomalies (as fast as 5 seconds), balancing efficiency and availability. Specific results are summarized below: For zero-configuration collaboration, the method used is: self-discovery + first-come, first-served; resource impact: no user intervention required. For dual-master protection, the method used is: random delay + secondary confirmation; resource impact: maximum startup time +3 seconds. For low-overhead monitoring, the method used is: broadcast heartbeat (5min → 5s); resource impact: memory ≈ 0. For reliable proxy, the method used is: ACK + DONE confirmation; resource impact: low consumption. For ACS transparency, the method used is: master station uniformly reports to all devices; resource impact: no ACS modification required.

[0116] (5) Adaptive degradation mechanism:

[0117] In complex and ever-changing home network environments (such as symmetric NAT, carrier CGNAT, multi-layer routers, firewall blocking, etc.), traditional STUN proactive triggering mechanisms often fail due to network limitations, resulting in devices becoming "unreachable and unmanageable." This mechanism, through a three-tiered elastic communication strategy and intelligent adaptive switching logic, ensures that devices maintain minimum remote management capabilities under any network conditions, achieving the high availability goals of "never losing connection, graceful degradation, and automatic recovery." It reduces the home device disconnection rate from the industry average of 5-10% to <1%; over 90% of problems can be resolved remotely, significantly reducing on-site maintenance costs; users require no configuration, and devices autonomously adapt to the network environment, providing a seamless user experience.

[0118] A. Using a three-level flexible working mechanism, Table 4 is an optional three-level flexible working mechanism table according to an embodiment of this application, as shown in Table 4:

[0119] Table 4

[0120]

[0121]

[0122] B. Three-level elastic mechanism switching logic. Table 5 is the switching logic table according to the embodiments of this application, as shown in Table 5:

[0123] Table 5

[0124]

[0125]

[0126] C. Unified architecture for multiple scenarios:

[0127] Single-device scenario (default): Independently executes all detection, decision-making, and communication, with no coordination overhead and minimal resource consumption. Multi-device scenario (enabled on demand): Only the master base station communicates externally, while slave stations remain silent; degradation logic is uniformly executed by the current master station (including polling reporting and resuming detection); after the master station fails, the slave station takes over the role and immediately activates its own degradation capabilities; strictly adheres to the "single exit" principle, ensuring a consistent ACS perspective at all times.

[0128] D. Management Closed Loop: Status Transparency and Intelligent Scheduling

[0129] The adaptive degradation mechanism not only ensures that devices "can maintain connectivity," but also enables the entire management system to "know how to efficiently utilize the current connection." To this end, devices proactively report their current communication status in each TR-069 Inform message, forming a closed-loop management system.

[0130] Status transparent reporting: The device always carries the following standardized fields:

[0131] <communicationmode>: Current mode (ACTIVE / POLLING / EMERGENCY);

[0132] <degradationreason>Reasons for downgrading (e.g., SYMMETRIC_NAT, FIREWALL_BLOCK);

[0133] <currentpollinginterval>Current polling interval (seconds);

[0134] This information enables ACS to accurately identify the actual accessibility of a device, rather than relying solely on its "online / offline" status.

[0135] ACS Intelligent Scheduling:

[0136] Based on the reported status, ACS can dynamically optimize management strategies:

[0137] Polling mode devices: Non-urgent operations (such as log collection and configuration backup) are queued and "piggybacked" into the next Inform response to avoid command loss;

[0138] Emergency Alarm: Triggers manual maintenance process, initiating user outreach or on-site support;

[0139] High-frequency degradation areas: Aggregate data to generate network quality heatmaps, identify systemic problems caused by carrier CGNAT or home firewalls, and support network optimization decisions.

[0140] The adaptive degradation mechanism greatly improves continuity assurance, predictability assurance, and maintainability assurance.

[0141] As an optional implementation, a project deployed three 5G Small Cells (devices A, B, and C, i.e., multiple network devices deployed in the local area network), all connected to the Internet through the same enterprise-grade firewall. This firewall enabled Port-Restricted Cone NAT with a mapping timeout of 90 seconds.

[0142] Maintenance personnel urgently need to issue a "shut down radio frequency" command to device C. A sudden network fluctuation causes a brief loss of connection for the master station, triggering adaptive degradation and role switching. The entire process is completed on the existing TR-069 ACS platform without any modifications. A complete collaborative process example is shown in Table 6:

[0143]

[0144]

[0145]

[0146]

[0147] In summary, the five-layer mechanism proposed in this invention is not an isolated functional module, but a closed-loop management system characterized by end-side autonomy, cloud-side collaboration, and state-driven operation. The various mechanisms are deeply coupled in the following ways to jointly address the fundamental shortcomings of traditional TR-069 in NAT environments: NAT behavior modeling serves as the basis for perception; dynamic window prediction provides a time boundary for security triggering and simultaneously provides diagnostic criteria for adaptive degradation.

[0148] Using dynamic key derivation as a security anchor: the session key is strongly bound to the device identity and network environment, enabling the security trigger to have anti-forgery and forward security capabilities;

[0149] Using secure STUN triggering as the execution channel: completely replacing plaintext UDP, achieving highly reliable and secure reverse connections, and fully compatible with existing firewall / NAT policies;

[0150] Using multi-base station collaboration as a resource aggregator: In a cluster scenario, N management exits are converged into 1, significantly reducing public network port consumption, and all remote management logic is uniformly carried by the main station;

[0151] Adaptive degradation provides a safety net for resilience: When the network environment deteriorates, it automatically switches to polling or emergency channels to ensure that the device never leaves the management view and supports a smooth return after fault recovery.

[0152] Crucially, all of the aforementioned intelligence is implemented on the terminal side, requiring no protocol or architectural modifications to the existing TR-069 ACS platform. ACS only needs to parse extended parameters (such as ReverseConnectSec and CommunicationMode) in standard Inform messages to achieve optimized command scheduling and enhanced operational decision-making.

[0153] Through this five-layer collaborative architecture, the present invention systematically solves the reliability, security and scalability problems of remote management in NAT environment without changing the existing management ecosystem, and provides deterministic operation and maintenance guarantee capabilities for edge devices such as 5G home base stations and industrial IoT gateways.

[0154] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software and necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0155] Figure 4 This is a structural block diagram of a local area network (LAN) device management apparatus according to an embodiment of this application; the apparatus is applied to a target network device among multiple network devices deployed in a LAN, such as... Figure 4 As shown, it includes:

[0156] The acquisition module is used to acquire reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time.

[0157] A filtering module is used to filter out proxy devices from the plurality of network devices based on the reference device information, wherein the proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network, and the control device is used to manage the operating status of the plurality of network devices;

[0158] A construction module is configured to, when the target network device is determined to be the proxy device, establish a remote management relationship between the target network device and the control device, wherein the control device is configured to initiate operation control operations on the plurality of network devices through the remote management relationship with the target network device.

[0159] Through the above embodiments, when multiple network devices deployed in a local area network (LAN) need to communicate with a control device deployed in a public network environment, reference device information of reference network devices (excluding the target network device) is obtained from the multiple network devices. This allows for the selection of a proxy device to facilitate communication between the multiple network devices and the control device based on the operating status of the multiple network devices within a reference time period. When the target network device acts as the proxy device, it establishes a remote management relationship with the control device. This enables the control device to initiate operational control of all network devices deployed in the LAN through the target network device acting as the proxy. In this process, only one public network address needs to be allocated to each network device in the LAN, solving the technical problem of high public network address consumption when the control device controls network devices in the LAN. This achieves the technical effect of reducing the public network address consumption when the control device controls network devices in the LAN.

[0160] Optionally, the filtering module includes: a first filtering unit, configured to filter out a first device from the reference network devices that acts as a proxy for the communication between the plurality of network devices and the control device during the reference time period, based on the reference device information; a first determining unit, configured to determine the first device as the proxy device if the first device exists in the reference network devices; and a second determining unit, configured to determine the target network device as the proxy device if the first device does not exist in the reference network devices.

[0161] Optionally, the filtering module includes: a first prediction unit, configured to predict a first service load of the reference network device within a target time period after the current time based on the reference service load of the reference network device, and to predict a second service load of the target network device within the target time period based on the target service load of the target network device, wherein the reference device information includes the reference service load, the reference service load is used to indicate the service carrying capacity of the reference network device within the reference time period, and the target service load is used to indicate the service carrying capacity of the target network device within the reference time period; a second filtering unit, configured to filter out a second device from the plurality of network devices whose service load is less than a preset load within the target time period based on the first service load and the second service load; and a third determination unit, configured to determine the second device as the proxy device.

[0162] Optionally, the first prediction unit is configured to: construct a first load change curve for the reference network device using the reference service load, wherein the first load change curve records the relationship between the service load of the reference network device and time; predict the first service load of the reference network device within the target time period according to the relationship between the service load and time recorded in the first load change curve; the first prediction unit is configured to: construct a second load change curve for the target network device using the target service load, wherein the second load change curve records the relationship between the service load of the target network device and time; predict the second service load of the target network device within the target time period according to the relationship between the service load and time recorded in the second load change curve.

[0163] Optionally, the construction module includes: an acquisition unit, configured to acquire the candidate lifetimes of multiple candidate public network mapping addresses allocated by the STUN server to devices within the local area network before the current time, wherein the candidate public network mapping addresses are used to indicate that devices within the local area network were allocated public network addresses in the public network before the current time, and the candidate lifetimes are used to indicate the storage duration of the corresponding candidate public network mapping addresses in the STUN server; a second prediction unit, configured to predict the remaining lifetime of a target public network mapping address allocated to the target network device within a target time period before the current time based on the candidate lifetimes; and a sending unit, configured to send the target public network mapping address and the remaining lifetimes to the control device, wherein the control device is configured to call the target public network mapping address to send operation control instructions for devices within the local area network to the target network device within the time window indicated by the remaining lifetimes.

[0164] Optionally, the second prediction unit is configured to: obtain the target network address translation type of the target network device; filter out a first lifespan corresponding to the target network address translation type from the candidate lifespans; predict a second lifespan of the target public network mapping address based on the first lifespan; calculate the difference between the second lifespan and the third lifespan of the target public network mapping address to obtain the remaining lifespan, wherein the third lifespan is used to indicate the duration for which the target public network mapping address has been stored in the STUN server.

[0165] Optionally, the apparatus further includes: an access module, configured to access the reference public network mapping address of the target network device stored in the STUN server according to a target access cycle after predicting the remaining lifespan of the target public network mapping address allocated to the target network device in the target time period based on the candidate lifespan; and a sending module, configured to send a target adjustment instruction to the control device when the reference public network mapping address and the target public network mapping address match, wherein the target adjustment instruction is used to instruct the control device to increase the remaining lifespan of the target public network mapping address by a target duration.

[0166] Embodiments of this application also provide a storage medium including a stored program, wherein the program executes any of the above-described local area network device management methods when it is run.

[0167] Optionally, in this embodiment, the storage medium may be configured to store program code for performing the following steps:

[0168] Obtain reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time.

[0169] Based on the reference device information, a proxy device is selected from the plurality of network devices. The proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network. The control device is used to manage the operating status of the plurality of network devices.

[0170] When the target network device is determined to be the proxy device, the target network device establishes a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the plurality of network devices through the remote management relationship with the target network device.

[0171] Embodiments of this application also provide an electronic device including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above embodiments of the management method for local area network devices.

[0172] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0173] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:

[0174] Obtain reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time.

[0175] Based on the reference device information, a proxy device is selected from the plurality of network devices. The proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network. The control device is used to manage the operating status of the plurality of network devices.

[0176] When the target network device is determined to be the proxy device, the target network device establishes a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the plurality of network devices through the remote management relationship with the target network device.

[0177] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0178] Optionally, specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated here.

[0179] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular combination of hardware and software.

[0180] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.< / currentpollinginterval> < / degradationreason> < / communicationmode>

Claims

1. A method for managing local area network (LAN) devices, characterized in that, The method is applied to a target network device among multiple network devices deployed in a local area network, and the method includes: Obtain reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time. Based on the reference device information, a proxy device is selected from the plurality of network devices. The proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network. The control device is used to manage the operating status of the plurality of network devices. When the target network device is determined to be the proxy device, the target network device establishes a remote management relationship with the control device, wherein the control device is used to initiate operation control operations on the plurality of network devices through the remote management relationship with the target network device.

2. The method according to claim 1, characterized in that, The step of filtering out proxy devices from the plurality of network devices based on the reference device information includes: Based on the reference device information, a first device is selected from the reference network devices to act as an intermediary for communication between the plurality of network devices and the control device during the reference time period; If the first device is present in the reference network device, the first device is identified as the proxy device; If the first device is not present in the reference network devices, the target network device is identified as the proxy device.

3. The method according to claim 1, characterized in that, The step of filtering out proxy devices from the plurality of network devices based on the reference device information includes: The reference network device is used to predict a first service load of the reference network device in a target time period after the current time based on the reference service load of the reference network device, and a second service load of the target network device in the target time period is predicted based on the target service load of the target network device, wherein the reference device information includes the reference service load, which is used to indicate the service carrying status of the reference network device in the reference time period, and the target service load is used to indicate the service carrying status of the target network device in the reference time period; Based on the first service load and the second service load, a second device with a service load less than a preset load during the target time period is selected from the plurality of network devices; The second device is identified as the agent device.

4. The method according to claim 3, characterized in that, The step of predicting the first service load of the reference network device within the target time period based on the reference service load of the reference network device includes: constructing a first load change curve of the reference network device using the reference service load, wherein the first load change curve records the relationship between the service load of the reference network device and time; and predicting the first service load of the reference network device within the target time period according to the relationship between the service load and time recorded in the first load change curve. The step of predicting the second service load of the target network device within the target time period based on the target service load of the target network device includes: constructing a second load change curve of the target network device using the target service load, wherein the second load change curve records the change relationship of the service load of the target network device over time; and predicting the second service load of the target network device within the target time period according to the change relationship of the service load over time recorded in the second load change curve.

5. The method according to claim 1, characterized in that, The establishment of a remote management relationship between the target network device and the control device includes: Obtain the candidate lifetimes of multiple candidate public network mapping addresses allocated by the STUN server to devices within the local area network before the current time. The candidate public network mapping addresses are used to indicate that devices within the local area network were allocated public network addresses in the public network before the current time, and the candidate lifetimes are used to indicate the storage duration of the corresponding candidate public network mapping addresses in the STUN server. Based on the candidate lifetime, predict the remaining lifetime of the target public network mapping address allocated to the target network device during the target time period before the current time. The target public network mapping address and the remaining service life are sent to the control device, wherein the control device is used to call the target public network mapping address to send operation control instructions for the devices in the local area network to the target network device within the time window indicated by the remaining service life.

6. The method according to claim 5, characterized in that, The step of predicting the remaining lifespan of the target public network mapping address allocated to the target network device in the target time period based on the candidate lifespan includes: Obtain the target network address translation type of the target network device; Select a first lifetime corresponding to the target network address translation type from the candidate lifetimes; The second lifespan of the target public network mapping address is predicted based on the first lifespan. The difference between the second lifetime and the third lifetime of the target public network mapping address is calculated to obtain the remaining lifetime, wherein the third lifetime is used to indicate the length of time the target public network mapping address has been stored in the STUN server.

7. The method according to claim 5, characterized in that, After predicting the remaining lifespan of the target public network mapping address allocated to the target network device during the target time period based on the candidate lifespan, the method further includes: Access the reference public network mapping address of the target network device stored in the STUN server according to the target access cycle; If the reference public network mapping address and the target public network mapping address match, a target adjustment command is sent to the control device, wherein the target adjustment command is used to instruct the control device to increase the remaining service life of the target public network mapping address by a target duration.

8. A management device for local area network (LAN) devices, characterized in that, The device is applied to a target network device among multiple network devices deployed in a local area network, and the device includes: The acquisition module is used to acquire reference device information of a reference network device, wherein the reference network device is a network device other than the target network device among the plurality of network devices, and the reference device information is used to indicate the operating status of the reference network device in a reference time period before the current time. A filtering module is used to filter out proxy devices from the plurality of network devices based on the reference device information, wherein the proxy device is used to communicate on behalf of the plurality of network devices with a control device deployed in the public network, and the control device is used to manage the operating status of the plurality of network devices; A construction module is configured to, when the target network device is determined to be the proxy device, establish a remote management relationship between the target network device and the control device, wherein the control device is configured to initiate operation control operations on the plurality of network devices through the remote management relationship with the target network device.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein the program, when executed, performs the method of any one of claims 1 to 7.

10. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to execute the method of any one of claims 1 to 7 through the computer program.