Private network connection method, apparatus, device, medium and program product
Patent Information
- Application Number
- CN202610645023.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-11
- Publication Date
- 2026-08-28
AI Technical Summary
[0004]然而,在上述方法中,由于所有流量必须经过第三方服务器中转,所以流量的传输速度会受限于家庭宽带的较低上行带宽(通常为4-50Mbps)和所租用服务器的带宽配额,即会形成双重瓶颈
[0020] In a sixth aspect, embodiments of this application provide a chip including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect.
Smart Images

Figure CN122661237A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a private network connection method, apparatus, device, medium, and program product. Background Technology
[0002] With the emergence of new smart home hardware, private networks are being further applied and promoted in home scenarios. More and more mobile users need the network capability of "one network at home and outside", such as communicating with devices in the home network via mobile terminals such as mobile phones.
[0003] Typically, to access a home private network via a mobile device, a "mobile device → public network relay server → home private network device" architecture can be adopted. This involves deploying client software on the home private network and simultaneously setting up a cloud server with a fixed Internet Protocol (IP) connection on the public network as a relay hub. The mobile device can then connect to this public network server from the external network, and the server will forward the request to the target device on the home private network, thus enabling remote access.
[0004] However, in the above method, since all traffic must be relayed through a third-party server, the transmission speed is limited by the low upload bandwidth of the home broadband (typically 4-50Mbps) and the bandwidth quota of the rented server, creating a double bottleneck. Simultaneously, data routing also significantly increases network latency. Thus, the process of private network connections is both speed-limited and has high latency. Summary of the Invention
[0005] This application provides a private network connection method, apparatus, device, medium, and program product to improve the efficiency of private network connection and the data transmission efficiency after private network connection.
[0006] In a first aspect, embodiments of this application provide a private network connection method applied to a private network server. The method includes: receiving a private network connection request from a target mobile terminal, the private network connection request being used to request connection to a target private network device, the private network connection request including dedicated domain name information allocated to the target private network device under a corresponding private network service; resolving the dedicated domain name information to obtain address information of the target private network device; and sending the address information of the target private network device to the target mobile terminal, the address information of the target private network device being used by the target mobile terminal to establish a connection with the target private network device.
[0007] The technical solution provided in this application offers at least the following advantages: The private network server can resolve the domain name information of the target private network device contained in the received private network connection request from the target mobile terminal to obtain the address information of the target private network device to be connected. Then, the private network server can send this address information to the target mobile terminal, enabling the target mobile terminal to directly connect to the target private network device based on this address information, thereby achieving direct access to home private network resources. This avoids the speed limits and high latency issues caused by connecting to the private network through an intermediate internet server, thus improving the efficiency of private network connections and the efficiency of data transmission after a private network connection.
[0008] In one possible implementation, the above-mentioned private network connection method may further include: obtaining the address information and private network service information of the target mobile terminal, wherein the private network service information includes: the contact information of the subscribed user, the subscribed broadband account, and the subscribed user's private network domain name; the private network domain name is used to indicate the address information of at least one private network device, wherein the at least one private network device includes the target private network device; generating a firewall whitelist based on the address information of the target mobile terminal and the address information of at least one private network device, and synchronizing the firewall whitelist to the home smart gateway; one private network device corresponds to one address information; wherein the firewall whitelist is used by the home smart gateway to verify whether to allow the target mobile terminal to establish a connection with the target private network device.
[0009] Another possible implementation, the above private network connection method may further include: when at least one of the address information of the target mobile terminal and the address information of at least one private network device changes, dynamically updating the firewall whitelist based on the changed address information of the target mobile terminal and the address information of at least one private network device.
[0010] Another possible implementation method for the above-mentioned private network connection method may include: determining the address information of at least one private network device based on the private network domain name of the contracted user through dynamic domain name service.
[0011] Another possible implementation is that receiving the private network connection request from the target mobile terminal includes: receiving the private network connection request from the target mobile terminal forwarded by the public server.
[0012] Secondly, embodiments of this application provide a private network connection device, comprising: a receiving module, a parsing module, and a sending module; the receiving module is configured to receive a private network connection request from a target mobile terminal, the private network connection request being used to request connection to a target private network device, the private network connection request including dedicated domain name information allocated to the target private network device under a corresponding private network service; the parsing module is configured to parse the dedicated domain name information received by the receiving module to obtain the address information of the target private network device; the sending module is configured to send the address information of the target private network device obtained by the parsing module to the target mobile terminal, the address information of the target private network device being used by the target mobile terminal to establish a connection with the target private network device.
[0013] In one possible implementation, the aforementioned private network connection device further includes: an acquisition module and a generation module; the acquisition module is used to acquire the address information and private network service information of the target mobile terminal, the private network service information including: the contact information of the subscribed user, the subscribed broadband account, and the subscribed user's private network domain name; the subscribed user's private network domain name is used to indicate the address information of at least one private network device, the at least one private network device including the target private network device; the generation module is used to generate a firewall whitelist based on the address information of the target mobile terminal and the address information of at least one private network device acquired by the acquisition module, and synchronize the firewall whitelist to the home smart gateway; one private network device corresponds to one address information; wherein, the firewall whitelist is used by the home smart gateway to verify whether to allow the target mobile terminal to establish a connection with the target private network device.
[0014] In another possible implementation, the aforementioned private network connection device further includes an update module; the update module is used to dynamically update the firewall whitelist based on the changed address information of the target mobile terminal and the address information of at least one private network device when at least one of the address information of the target mobile terminal and the address information of at least one private network device is detected to have changed.
[0015] In another possible implementation, the aforementioned private network connection device further includes: a determination module; the determination module is used to determine the address information of at least one private network device based on the private network domain name of the subscribed user through a dynamic domain name service.
[0016] Another possible implementation is that the aforementioned receiving module is specifically used to receive private network connection requests from the target mobile terminal forwarded by the public server.
[0017] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory stores a program or instructions executable on the processor, wherein the program or instructions, when executed by the processor, implement the method of the first aspect described above.
[0018] Fourthly, this application provides a readable storage medium on which a program or instructions are stored, which, when executed by a computer, implement the method of the first aspect described above.
[0019] Fifthly, this application provides a computer program product stored in a storage medium, which, when executed by a computer, implements the method described in the first aspect.
[0020] In a sixth aspect, embodiments of this application provide a chip including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect.
[0021] The beneficial effects of the second to sixth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description
[0022] Figure 1 A schematic diagram of the network architecture for a private network connection method provided in this application embodiment;
[0023] Figure 2 A flowchart illustrating a private network connection method provided in an embodiment of this application;
[0024] Figure 3 A flowchart illustrating another private network connection method provided in an embodiment of this application;
[0025] Figure 4 A flowchart illustrating yet another private network connection method provided in an embodiment of this application;
[0026] Figure 5 A flowchart illustrating yet another private network connection method provided in an embodiment of this application;
[0027] Figure 6 A flowchart illustrating yet another private network connection method provided in an embodiment of this application;
[0028] Figure 7 A schematic diagram of a network architecture for a private network connection service provided in an embodiment of this application;
[0029] Figure 8 This is a schematic diagram of the structure of a private network connection device provided in an embodiment of this application;
[0030] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0031] The following is a detailed description of the private network connection method, apparatus, equipment, medium, and program products provided in this application, with reference to the accompanying drawings.
[0032] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0033] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0034] The terms "at least one," "at least one of," etc., used in the specification and claims of this application refer to any one, any two, or a combination of two or more of the included items. For example, at least one of a, b, and c can mean: "a," "b," "c," "a and b," "a and c," "b and c," and "a, b, and c," where a, b, and c can be single or multiple. Similarly, "at least two" refers to two or more items, and its meaning is similar to that of "at least one."
[0035] In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0036] The embodiments of this application provide a private network connection method, apparatus, device, medium, and program product that can be applied to scenarios where a mobile terminal remotely accesses devices in a home network.
[0037] IPv6, short for "Internet Protocol Version 6," is the next-generation IP protocol designed by the Internet Engineering Task Force (IETF) to replace IPv4. It is said to have enough addresses to assign an address to every grain of sand in the world.
[0038] The Domain Name System (DNS) is a fundamental service of the Internet used to map domain names to IP addresses and provides distributed directory services with various record types, including A / AAAA, Mail Exchange Record (MX), Name Server Record (NS), Service Record (SRV), and Pointer Record (PTR).
[0039] Dynamic Domain Name Server (DDNS) maps a user's dynamic IP address to a fixed domain name resolution service. Every time a user connects to the network, the client program transmits the host's dynamic IP address to the server program located on the service provider's host via information transmission. The server program is responsible for providing DNS services and implementing dynamic domain name resolution.
[0040] User Plane Function (UPF) is an important component of the 3GPP 5G core network system architecture, primarily responsible for routing and forwarding user plane data packets in the 5G core network.
[0041] AAA, which stands for Authentication, Authorization, and Accounting, is a network security management mechanism.
[0042] Network Address Translation (NAT) devices are network devices with network address translation capabilities, enabling them to translate IP addresses between different networks and achieve communication between private and public networks.
[0043] Network Attached Storage (NAS) is a dedicated file storage device that allows employees continuous access to data for effective collaboration over a network. All computer networks have interconnected server machines and client machines that send requests to the servers. NAS devices are dedicated servers designed to handle data storage and file sharing requests. These devices provide fast, secure, and reliable storage services for private networks.
[0044] The control plane is a collection of logical or physical components in a network, communication, or system architecture that are responsible for managing and controlling core functions such as data transmission paths, resource allocation, and policy execution.
[0045] SRv6 L3VPN is a Layer 3 Virtual Private Network (L3VPN) solution based on SRv6 (Segment Routing over IPv6) technology. It combines the flexibility of SRv6 with the layered isolation capabilities of L3VPN, providing operators and enterprises with an efficient and scalable way to interconnect networks.
[0046] With the emergence of new smart home devices, private networks are being further applied and promoted in home scenarios. More and more mobile users need the network capability of "one network at home and outside," such as remote access between mobile terminals like smartphones and devices in the home network. However, private networks and mobile networks use different protocol sets, and their control planes cannot communicate with each other. Therefore, in related technologies, remote access can be achieved through public network relay.
[0047] In related technologies, there are generally two solutions for accessing home private network resources via mobile terminals:
[0048] Option 1: Internet Server Relay Solution
[0049] The typical architecture is "mobile device → public network relay server → home private network device". Its core is deploying client software (such as an FRP client, DDNS tool, or virtual networking node) on the home private network, while simultaneously using a cloud server with a fixed IP address on the public network as a relay hub, establishing an encrypted tunnel between the two. Thus, the mobile terminal can first connect to this public network server from the external network, and then the server forwards the request to the target device on the home private network, thereby enabling remote access.
[0050] However, the above method has the following unresolved issues:
[0051] 1. Performance and Cost Bottlenecks. Since all traffic must be relayed through a third-party server, transmission speed is limited by the low uplink bandwidth of home broadband (typically 4-50Mbps) and the bandwidth quota of the rented server, creating a double bottleneck. Simultaneously, data routing significantly increases network latency, typically by 50-300 milliseconds compared to direct connections. For applications requiring high-definition video streaming or real-time interaction, the experience is often poor. Furthermore, high-performance, high-bandwidth cloud servers incur ongoing rental costs.
[0052] 2. Concentrated security risks. The public network relay server becomes a single point of failure and a core target for attacks. Once this server is compromised, all data transmitted through it may be at risk of being leaked, and the entire remote access system will be paralyzed. If users build their own services, they also need to bear the responsibility for server security maintenance (such as patching system vulnerabilities and configuring firewalls), which poses a high barrier to entry for ordinary users.
[0053] 3. Connection reliability issues. Network fluctuations or service restarts on either the home network or the public network server can cause remote connection interruptions. Furthermore, in complex carrier NAT environments (especially symmetric NAT), tunnel establishment may fail or stability may degrade. Users therefore require additional reconnection mechanisms and monitoring measures.
[0054] 4. Complex configuration and maintenance. Users need to purchase, configure, and maintain public network servers long-term, including handling a series of technical operations such as IP changes, domain name resolution, certificate updates, and software upgrades. This poses a high barrier to entry and a significant technical burden for non-professional users.
[0055] 5. Limited scalability and functionality. This architecture typically struggles to support basic broadcast, multicast, or convenient automatic service discovery (such as printer and smart device discovery) within a home LAN. Access is mostly point-to-point, failing to accurately reproduce the complete local network experience.
[0056] In summary, while public network server relay solutions are a common method for achieving remote access, they have inherent shortcomings in terms of performance, security, reliability, and ease of use.
[0057] Option 2: Direct Access Based on IPv6
[0058] The core of the solution for mobile terminals to directly access home private network resources via IPv6 lies in leveraging the "direct access via public IP address" feature of IPv6. When both the home broadband and mobile network are assigned global IPv6 addresses, the mobile terminal can directly access the network through the IPv6 address of the device to be connected, and the data does not need to be relayed through a third-party server. This bypasses the bandwidth, latency, and single point of failure issues associated with the relay solution mentioned above, enabling efficient, low-latency end-to-end direct connection.
[0059] However, the following problems still remain unresolved using the methods described above:
[0060] 1. Because the IPv6 addresses of home broadband resources are constantly changing and the IPv6 address format is complex and difficult to remember, they cannot be accessed directly using the address. The connection process must rely on the domain name.
[0061] 2. When using domain names, users must possess a valid DNS domain name and use DDNS technology to dynamically bind the IPv6 address of their home broadband resource. However, for most customers of telecom operators, this presents a high technical barrier and adds extra costs associated with domain name usage.
[0062] 3. Home broadband private network resources are directly exposed to the Internet, especially after being bound to a domain name, which will greatly increase the risk of attacks on private network resources and privacy leaks.
[0063] To address the aforementioned technical problems, embodiments of this application provide a private network connection method, apparatus, device, medium, and program product. The private network server can resolve the domain name information of the target private network device contained in the received private network connection request from the target mobile terminal to obtain the address information of the target private network device to be connected. Then, the private network server can send this address information to the target mobile terminal, enabling the target mobile terminal to directly connect to the target private network device based on this address information, thereby achieving direct access to home private network resources. This avoids the speed limits and high latency problems caused by private network connections through intermediate internet servers, thus improving the efficiency of private network connections and the data transmission efficiency after a private network connection.
[0064] The following description, in conjunction with the accompanying drawings, details the private network connection method, apparatus, device, medium, and program products provided in the embodiments of this application.
[0065] Figure 1 This illustration shows a network architecture for a private network connection method provided in an embodiment of this application. For example... Figure 1 As shown, the network architecture includes a private network server 101 and a terminal device 102. The private network server 101 and the terminal device 102 are interconnected.
[0066] In some embodiments, the private network server 101 may be a server, a computer, or a processor or processing unit within a server or computer. The server may be a single server or a server cluster consisting of multiple servers. It should be noted that this application embodiment does not limit the specific device form of the private network connection device 101. Figure 1 The example shown is a private network server 101, which is a single server.
[0067] In some embodiments, the terminal device may be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, personal computer (PC), ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., and the embodiments of this application do not specifically limit it. Figure 1 The example shown is a mobile phone, with terminal device 102 as an example.
[0068] In some embodiments, when terminal device 102 needs to connect to a private network device (such as a target private network device) within a home private network, terminal device 102 can send a private network connection request to private network server 101. This private network connection request can be used to request a connection to the target private network device, and it may include the dedicated domain name information allocated to the target private network device under the corresponding private network service. Private network server 101 can then resolve the domain name information of the target private network device to obtain its address information. Private network server 101 can then send the address information of the target private network device to mobile terminal 102, allowing mobile terminal 102 to establish a connection with the target private network device based on its address information.
[0069] It should be noted that the network architecture described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As network architectures evolve, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0070] See Figure 2 This is a flowchart illustrating a private network connection method provided in an embodiment of this application. Figure 2 As shown, the private network connection method provided in this application embodiment can be implemented through the aforementioned private network server, specifically including the following steps 201 to 203.
[0071] Step 201: The private network server receives a private network connection request from the target mobile terminal.
[0072] In some embodiments, the aforementioned private network server can be a platform corresponding to a private network service. For example, a mobile private network service platform.
[0073] In some embodiments, the aforementioned private network service platform may correspond to a proprietary DNS server, such as the accompanying private network service DNS server.
[0074] In some embodiments, the above-described private network connection request can be used to request a connection to a target private network device.
[0075] In some embodiments, the target private network device may be any one of at least one preset private network device.
[0076] For example, the aforementioned at least one private network device can be a device in a home network.
[0077] In some embodiments, when a user needs to connect to a target private network device through a target mobile terminal, the user can initiate a private network connection request by entering the domain name of the target private network device in the address bar of an application (APP), mini-program, or browser through the target mobile terminal.
[0078] In some embodiments, the private network connection request may include the private domain name information allocated to the target private network device under the corresponding private network service.
[0079] It should be noted that for the description of the above-mentioned private network services and dedicated domain names, please refer to the description of steps 301 and 302 and their related steps below, which will not be repeated here in the embodiments of this application.
[0080] In some embodiments, combined with Figure 2 ,like Figure 3 As shown, step 201 above can be implemented through step 201a below.
[0081] Step 201a: The private network server receives the private network connection request from the target mobile terminal forwarded by the public server.
[0082] In some embodiments, the aforementioned public server may be a public DNS server.
[0083] Understandably, the target mobile terminal can first send a private network connection request to the public DNS server, and then the public DNS server can forward the private network connection request to the accompanying private network DNS server to entrust the domain name of the private network business to the accompanying private network DNS server for domain name resolution.
[0084] In this way, the public server only forwards private network connection requests without performing any other operations. This avoids the speed limiting and high latency problems caused by using an internet intermediary server (such as a public server) for private network connections, thereby improving the efficiency of private network connections and the efficiency of data transmission after the private network connection is established.
[0085] Step 202: The private network server resolves the dedicated domain name information to obtain the address information of the target private network device.
[0086] In some embodiments, the address information described above may be an IPv6 address.
[0087] In some embodiments, the private network server can resolve the aforementioned private domain name information through the accompanying private network service DNS server to obtain the address information of the target private network device.
[0088] For example, when the target private network device is a NAS, the accompanying private network service DNS server can resolve the NAS's private domain name information (such as nas.123.wo.cn) to the IPv6 address corresponding to the NAS at the current moment, such as 2408::C::1. Alternatively, when the target private network device is a camera, the accompanying private network service DNS server can resolve the camera's private domain name information (such as camea.123.wo.cn) to the IPv6 address corresponding to the camera at the current moment, such as 2408::C::2.
[0089] Step 203: The private network server sends the address information of the target private network device to the target mobile terminal.
[0090] In some embodiments, the address information of the target private network device can be used by the target mobile terminal to establish a connection with the target private network device.
[0091] In some embodiments, after the target mobile terminal receives the address information of the target private network device, the target mobile terminal can use the address information of the target private network device as the destination address to initiate a network connection.
[0092] It should be noted that since the information involved in the above network connections are all public IPv6 addresses, no NAT device is needed for address translation during the network connection process, thus enabling direct access without NAT.
[0093] In the private network connection method provided in this application, the private network server can resolve the domain name information of the target private network device contained in the received private network connection request from the target mobile terminal to obtain the address information of the target private network device to be connected. Then, the private network server can send this address information to the target mobile terminal, enabling the target mobile terminal to directly connect to the target private network device based on this address information, thereby achieving direct access to home private network resources. This avoids the speed limiting and high latency problems caused by private network connections through intermediate internet servers, thus improving the efficiency of private network connections and the data transmission efficiency after the private network connection is established.
[0094] In some embodiments, combined with Figure 2 ,like Figure 4 As shown, prior to step 201 above, the private network connection method provided in this application embodiment may further include steps 301 and 302 below.
[0095] Step 301: The private network server obtains the address information and private network service information of the target mobile terminal.
[0096] In some embodiments, since the mobile network-side UPF can monitor the IPv6 address allocation of the subscriber's mobile terminal (i.e., the target mobile terminal), the mobile network-side UPF can announce the IPv6 address of the target mobile terminal to the accompanying private network service platform in real time, so that the accompanying private network service platform can set up a firewall whitelist based on the IPv6 address of the target mobile terminal.
[0097] In some embodiments, users can apply for private network services (such as mobile private network services) on the business operation support platform. The business operation support platform can then create a record containing a family group ID, contracted contact information (such as the contracted mobile phone number), and contracted broadband account, and synchronize the corresponding information of the family group ID, contracted mobile phone number, and broadband account to the fixed-line AAA system and the core network unified data management (UDM) network element.
[0098] It should be noted that, under the above-mentioned mobile private network service agreement, fixed-line and mobile users can go online and start the fixed-mobile converged mobile private network service. At this time, the connection and authentication processes for fixed-line and mobile users can remain unchanged.
[0099] In some embodiments, the aforementioned private network service information may include, but is not limited to, at least one of the following: the contact information of the contracted user, the contracted broadband account, and the contracted user's private network domain name.
[0100] In some embodiments, the aforementioned private domain name of the contracted user can be used to indicate the address information of at least one private network device.
[0101] In some embodiments, the aforementioned at least one private network device may include a target private network device.
[0102] In some embodiments, the private network server can obtain the user's mobile phone number and UE IP association information from the private network UPF (User Plane Function), and obtain the user's mobile phone number, broadband account, and the contracted user's accompanying private network domain name from the business operation support platform.
[0103] In some embodiments, the business operation support platform can register a dedicated domain name (such as wo.cn) for the Suixing Private Network business and delegate the resolution of this domain name to the Suixing Private Network business's own DNS server.
[0104] In some embodiments, when a user signs up for the aforementioned private network service, the business operation support platform can enter the user's IPv6 private network service subdomains, a list of bound mobile phone numbers, etc.
[0105] For example, the subdomain of a user's IPv6 mobile private network service can be a subdomain set by the user using characters such as numbers and letters. For example, the subdomain can be 123.wo.cn, or abc.wo.cn, or 1231234 1234.wo.cn, where 123 1234 1234 is used to represent the user's mobile phone number.
[0106] It should be noted that the above method for setting up subdomains is only an example. The specific setting requirements can be determined according to actual needs, and this application embodiment does not limit them.
[0107] It is understandable that for all users who have signed up for the aforementioned private network service, different users can be associated with different subdomains. That is, the subdomain can be understood as being used to represent the user's identity.
[0108] In some embodiments, users specify the MAC address of the device joining the mobile private network service and its corresponding subdomain through channels such as a business portal or an app. The business operations support platform can then synchronize this information to the mobile private network service platform.
[0109] In some embodiments, users can specify devices to join the mobile private network service by scanning a QR code or manually adding (registering).
[0110] In some embodiments, the devices that join the mobile private network service may include, but are not limited to, the mobile phone of the designated user, smart home devices, etc.
[0111] In some embodiments, the smart home may include, but is not limited to, at least one of the following: NAS, camera, smart door lock, printer, refrigerator, air conditioner, and speaker.
[0112] For example, the subdomain set by the user for the NAS can be nas.123.wo.cn; the subdomain set by the user for the camera can be cama.123.wo.cn.
[0113] In this way, by having the operator build its own domain name server, users do not need to own a domain name or configure DDNS, thus avoiding the high technical threshold and high cost of using solutions that directly access home private networks via IPv6 addresses.
[0114] In some embodiments, combined with Figure 4 ,like Figure 5 As shown, after step 301 above, the private network connection method provided in this application embodiment may further include the following step 401.
[0115] Step 401: The private network server determines the address information of at least one private network device based on the private network domain name of the contracted user through dynamic domain name service.
[0116] Understandably, the accompanying private network business platform can use DDNS to update the DNS records of private network devices in its own DNS server and match their public IPv6 addresses with the subdomains specified in step 301 above.
[0117] For example, the private network service platform can match the public IPv6 address 2408::C::1 corresponding to the NAS with the specified subdomain nas.123.wo.cn; the private network service platform can match the public IPv6 address 2408::C::2 corresponding to the camera with the specified subdomain cama.123.wo.cn.
[0118] Since address information may change frequently due to network restarts, operator policy adjustments, etc., private network servers use DDNS service to automatically update IPv6 addresses, ensuring that domain names always point to the currently valid address, thereby improving the accuracy of subsequent private network connections.
[0119] Step 302: The private network server can generate a firewall whitelist based on the address information of the target mobile terminal and the address information of at least one private network device, and synchronize the firewall whitelist to the home smart gateway.
[0120] In some embodiments, one of the at least one private network devices described above may correspond to an address information.
[0121] In some embodiments, the private network server can configure the home smart gateway firewall through the home gateway management system plugin to establish an external access whitelist for the IPv6 address of the mobile terminal.
[0122] In some embodiments, the private network server can dynamically generate DDNS records for the IPv6 address and domain name of the fixed private network device, so as to generate or update the firewall whitelist record of the user's fixed home gateway according to the settings.
[0123] In some embodiments, the firewall whitelist described above can be used by a home smart gateway to verify whether a target mobile terminal is allowed to establish a connection with a target private network device.
[0124] In some embodiments, after the target mobile terminal receives the address information of the target private network device, it can use that address information as the destination address to initiate a network connection. The home smart gateway first receives the network connection request and checks the address information of the target private network device against a firewall whitelist. If the firewall whitelist contains a matching relationship between the address information of the target private network device and the target private network device's address information, the home smart gateway can allow the network connection request, i.e., forward the request to the target private network device, thus enabling the target mobile terminal to connect to the target private network device.
[0125] Alternatively, if the firewall whitelist does not contain a matching relationship between the address information of the target private network device and the address information of the target private network device, the home smart gateway can block the request corresponding to the network connection. That is, it will not forward the request corresponding to the network connection to the target private network device, so the target mobile terminal cannot connect to the target private network device.
[0126] Understandably, in actual private network connections, because the home smart gateway has a firewall whitelist, which is an access rule, access will only be allowed if the source address is the user's mobile terminal's current IPv6 address; otherwise, it will be blocked, thus ensuring the security of the user's fixed-line private network resources.
[0127] In this way, the private network server can obtain the address information of mobile devices and at least one private network device, and establish a firewall whitelist based on the address information. Then, during subsequent private network connections, the home smart gateway can allow the addresses of user mobile terminals within the firewall whitelist to access private network resources. This avoids the situation in related technologies where direct access via IPv6 addresses leads to the exposure of home private network resources to the Internet. In other words, it can improve the security of private network connections.
[0128] In some embodiments, combined with Figure 4 ,like Figure 6 As shown, after step 302 above, the private network connection method provided in this application embodiment may further include step 303 below.
[0129] Step 303: If at least one of the address information of the target mobile terminal and the address information of at least one private network device changes, the private network server dynamically updates the firewall whitelist based on the changed address information of the target mobile terminal and the address information of at least one private network device.
[0130] In some embodiments, the mobile network side needs UPF / AAA to notify the accompanying private network service platform of the mobile terminal's IPv6 address allocation.
[0131] Understandably, the accompanying private network business platform can obtain mobile terminal IPv6 address information in real time through the mobile network UPF platform.
[0132] In some embodiments, the private network server can obtain the IPv6 address information of at least one private network device through a home gateway management system plugin.
[0133] In some embodiments, the home smart gateway can obtain the MAC address information of the private network device set by the user in the Travel Private Network Service Platform through the home gateway management system plugin, so as to obtain the public IPv6 address information allocated to the MAC address in real time and synchronize it to the Travel Private Network Service Platform.
[0134] Thus, since address information may change frequently due to network restarts, operator policy adjustments, etc., the private network server can dynamically update the firewall whitelist when it detects changes in address information, thereby improving the accuracy of subsequent private network connections.
[0135] It should be noted that the execution order of steps 303 and steps 201 to 203 described above is not limited in this embodiment. For example, step 303 can be executed first, followed by steps 201 to 203; or, steps 201 to 203 can be executed first, followed by step 303; or, steps 303 and steps 201 to 203 can be executed simultaneously. Figure 6 This example illustrates the process of executing step 303 first, followed by steps 201 to 203.
[0136] In some embodiments, when an operator's mobile network UPF element receives a request from a user's mobile terminal to the user's home broadband private network segment address, SRv6 L3VPN technology can be used to dynamically establish a VPN tunnel with the operator's broadband access edge router or broadband access server (BRAS) device.
[0137] Thus, by using SRv6 L3VPN encapsulation, user traffic can be isolated and encapsulated when it is transmitted over the Internet, preventing user traffic from being transmitted directly over the Internet, thereby further improving the security and privacy of users' private network data access.
[0138] Understandably, after encapsulation, other devices can obtain the encapsulated L3VPN network information, but will not obtain the original network connection records.
[0139] The private network connection method of this application will be described below through specific embodiments.
[0140] like Figure 7 As shown, the implementation process of the private network connection method provided in this application embodiment includes the following S1 to S3:
[0141] S1, Control Plane Flow
[0142] Users can apply for a private network service package on the business operation support platform. As a result, the business operation support platform can generate a record of a family group ID, a contracted mobile phone number, and a contracted broadband account. The platform will then synchronize the corresponding information of the family group ID, mobile phone number, and broadband account to the fixed network AAA system and the core network UDM element.
[0143] After completing the subscription for the mobile private network service package, fixed-line and mobile users can go online to activate the fixed-mobile converged mobile private network service. It should be noted that the connection and authentication processes for fixed-line and mobile users remain unchanged.
[0144] The mobile private network service platform can obtain user mobile phone numbers and UE IP association information from the private network UPF, and user mobile phone numbers, broadband accounts, and contracted user mobile private network domain names from the business operation support platform. Therefore, the mobile private network service platform dynamically generates DDNS records for the IPv6 addresses and domain names of fixed-line private network devices, and updates the firewall whitelist records of the user's fixed-line home gateway according to the settings.
[0145] 1. Fixed-line control plane service solution:
[0146] (1) Register a dedicated domain name (such as wo.cn) for the IPv6 private network service and entrust the resolution of this domain name to the private network service's own DNS server.
[0147] (2) The user signs up for the private network service and enters the subdomains of the user's IPv6 private network service, the list of bound mobile phone numbers, etc.
[0148] (3) Users can specify the MAC address of the device joining the private network service and its corresponding subdomain through the business portal or APP, and synchronize it to the private network service platform. For example, the subdomain corresponding to the camera can be camera.123.wo.cn; the subdomain corresponding to the NAS can be nas.123.wo.cn.
[0149] (4) The home smart gateway can obtain the MAC address information of the private network device set by the user in the Suixing private network business platform through the home gateway management system plug-in, obtain the public IPv6 address information assigned to the MAC address in real time, and synchronize it to the Suixing private network business platform.
[0150] (5) The accompanying private network business platform can use DDNS to update the DNS records of private network devices in its own DNS server and match their public IPv6 addresses with the subdomains specified in step (3).
[0151] (6) The mobile private network service platform can obtain the IPv6 address information of the mobile terminal in real time through the mobile network UPF platform, and set up the home smart gateway firewall through the home gateway management system plugin to establish an external access whitelist for the IPv6 address of the mobile terminal.
[0152] 2. Mobile network side control plane service scheme:
[0153] (1) Configuring the mobile network side UPF can monitor the IPv6 address allocation of the mobile terminal of the subscriber.
[0154] (2) The mobile network side UPF can announce the terminal IPv6 address to the accompanying private network service platform in real time, so that the service platform can set up a whitelist.
[0155] S2, Forwarding Plane Process
[0156] Let's take a mobile phone as an example. When a user wants to access a specific device on their home private network (e.g., a camera) while using their phone, they can initiate a request for the fixed-mobile converged private network service by entering the target device's domain name (e.g., cama.123.wo.cn) in the address bar of an app, mini-program, or browser. The private network service platform can then resolve the domain name cama.123.wo.cn to the public IPv6 address used by the camera, such as 2408::C::2, and send this IPv6 address (2408::C::2) to the mobile phone.
[0157] The mobile phone can use the IPv6 address 2408::C::2 as the destination address to initiate a network connection. Since both parties in the network connection have public IPv6 addresses, such as the mobile phone's IPv6 address 2408::A::1 and the camera's IPv6 address 2408::C::2, direct access without NAT can be achieved.
[0158] Specifically, because the home smart gateway has firewall whitelist access rules, when the home smart gateway receives a network connection request from a mobile phone, it can check the IPv6 address of the mobile phone (2408::A::1) and the IPv6 address of the camera (2408::C::2) according to the firewall whitelist. Then, it matches the address information of the target private network device with the address information of the target private network device in the firewall whitelist. That is, if the firewall whitelist includes "2408::A::1→2408::C::2", the home smart gateway can allow the network connection request, that is, allow (ALLOW) the mobile phone to connect to the camera, and forward the network connection request to the camera, so that the mobile phone can connect to the camera.
[0159] Conversely, if the firewall whitelist does not contain a matching relationship between the address information of the target private network device and the address information of the target private network device, the home smart gateway can block the request corresponding to the network connection, that is, it will default to deny the mobile phone from connecting to the camera, so the mobile phone cannot connect to the corresponding private network device.
[0160] S3, SRv6 L3VPN encapsulation
[0161] When a mobile network UPF element receives a request from a user's mobile terminal to the user's home broadband private network segment address, it can use SRv6 L3VPN technology to establish a VPN tunnel with the operator's broadband access edge router or BRAS device to ensure that the user's actual transmission traffic is transmitted in an encapsulated form on the Internet, thereby further improving the security and privacy of the user's access data.
[0162] In this way, the private network server can resolve the domain name information of the camera included in the received private network connection request from the mobile phone to obtain the address information of the camera to be connected. The private network server can then send this address information to the mobile phone, allowing the phone to directly connect to the camera and achieve direct access to home private network resources. This avoids the speed limits and high latency issues caused by connecting to the private network through an intermediate internet server, thus improving the efficiency of the private network connection and the data transmission efficiency after the private network connection is established.
[0163] Secondly, during the private network connection process, the whitelist mechanism of the home smart gateway firewall can be used to avoid situations where home private network resources are exposed to the Internet due to direct access via IPv6 addresses in related technologies. In other words, the security of the private network connection can be improved.
[0164] Furthermore, since the above solution allows operators to build their own domain name servers, users do not need to own domain names or configure DDNS, thus avoiding the high technical barriers and costs associated with solutions that directly access home private networks via IPv6 addresses.
[0165] Furthermore, SRv6 L3VPN encapsulation can isolate and encapsulate user traffic as it is transmitted over the Internet, preventing user traffic from being transmitted directly over the Internet and thus further improving the security and privacy of users' private network data access.
[0166] Understandably, the business operation support platform, i.e. the operator, can have real-time and detailed information on the IPv6 addresses of users' mobile terminals and home broadband resources. This allows them to leverage the advantages of dynamic configuration of home broadband smart gateways to provide or build more comprehensive solutions for the aforementioned private network business scenarios.
[0167] It should be noted that the descriptions of each step S1 to S3 in this embodiment can be found in the descriptions in the above embodiments, and will not be repeated here.
[0168] It should be noted that the above-described method embodiments, or the various possible implementations of the method embodiments, can be executed individually, or, provided there is no conflict, they can be combined with each other. The specific implementation can be determined according to actual usage requirements, and this application embodiment does not impose any restrictions on this.
[0169] As can be seen, the above mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the embodiments of this application provide corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0170] This application embodiment can divide the private network connection device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0171] In some embodiments, this application also provides a private network connection device. The private network connection device may include one or more functional modules for implementing the private network connection method of the above method embodiments.
[0172] For example, Figure 8 This is a schematic diagram of a private network connection device provided in an embodiment of this application. Figure 8 As shown, the private network connection device 900 includes: a receiving module 901, a parsing module 902, and a sending module 903;
[0173] The receiving module 901 is used to receive a private network connection request from the target mobile terminal. The private network connection request is used to request a connection to the target private network device. The private network connection request includes the private domain name information allocated to the target private network device under the corresponding private network service.
[0174] The aforementioned parsing module 902 is used to parse the private domain name information received by the receiving module 901 to obtain the address information of the target private network device;
[0175] The aforementioned sending module 903 is used to send the address information of the target private network device obtained by the parsing module 902 to the target mobile terminal. The address information of the target private network device is used by the target mobile terminal to establish a connection with the target private network device.
[0176] The private network connection device provided in this application can resolve the domain name information of the target private network device contained in the received private network connection request from the target mobile terminal to obtain the address information of the target private network device to be connected. Then, the private network connection device can send this address information to the target mobile terminal, enabling the target mobile terminal to directly connect to the target private network device based on this address information, thereby achieving direct access to home private network resources. This avoids the speed limiting and high latency problems caused by private network connections through internet intermediary servers, thus improving the efficiency of private network connections and the data transmission efficiency after the private network connection is established.
[0177] In some embodiments, the private network connection device 900 may further include: an acquisition module and a generation module; the acquisition module is used to acquire the address information and private network service information of the target mobile terminal, the private network service information including: the contact information of the subscribed user, the subscribed broadband account, and the subscribed user's private network domain name; the subscribed user's private network domain name is used to indicate the address information of at least one private network device, the at least one private network device including the target private network device; the generation module is used to generate a firewall whitelist based on the address information of the target mobile terminal and the address information of at least one private network device acquired by the acquisition module, and synchronize the firewall whitelist to the home smart gateway; one private network device corresponds to one address information; wherein, the firewall whitelist is used by the home smart gateway to verify whether to allow the target mobile terminal to establish a connection with the target private network device.
[0178] In other embodiments, the private network connection device 900 may further include an update module; the update module is used to dynamically update the firewall whitelist based on the changed address information of the target mobile terminal and the address information of at least one private network device when at least one of the address information of the target mobile terminal and the address information of at least one private network device is detected to have changed.
[0179] In some other embodiments, the private network connection device 900 may further include: a determination module; the determination module is used to determine the address information of at least one private network device based on the private network domain name of the subscribed user through a dynamic domain name service.
[0180] In some other embodiments, the receiving module 901 is specifically used to receive a private network connection request from a target mobile terminal forwarded by a public server.
[0181] It should be noted that the private network connection device can implement all the processes implemented in the above method embodiments and achieve the same beneficial effects. To avoid repetition, it will not be described again here.
[0182] In the case where the functions of the integrated modules described above are implemented in hardware, this application provides a possible structural schematic diagram of the electronic device involved in the above embodiments. For example... Figure 9 As shown, the electronic device 90 includes: a processor 92, a communication interface 93, and a bus 94. Optionally, the electronic device 90 may also include a memory 91.
[0183] Processor 92 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 92 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 92 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0184] Communication interface 93 is used to connect with other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.
[0185] The memory 91 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0186] As one possible implementation, the memory 91 can exist independently of the processor 92. The memory 91 can be connected to the processor 92 via a bus 94 and is used to store instructions or program code. When the processor 92 calls and executes the instructions or program code stored in the memory 91, it can implement the private network connection method provided in this application embodiment.
[0187] In another possible implementation, memory 91 can also be integrated with processor 92.
[0188] Bus 94 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 94 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 9 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0189] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.
[0190] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described private network connection method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0191] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0192] This application also provides a readable storage medium storing a program or instructions that, when executed by a computer, implement the private network connection method provided in the above embodiments. It is understood that all or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware; the readable storage medium can be any of the foregoing embodiments or memory; the readable storage medium can also be an external storage device of the service invocation device, such as a pluggable hard drive, Smart MediaCard (SMC), Secure Digital (SD) card, flash card, etc., equipped on the service invocation device. Further, the readable storage medium can include both internal storage units of the service invocation device and external storage devices. The readable storage medium is used to store the computer program and other programs and data required by the service invocation device. The readable storage medium can also be used to temporarily store data that has been output or will be output.
[0193] This application also provides a computer program product, which is stored in a storage medium and implements the private network connection method provided in the above embodiments when the computer program product is executed by a computer.
[0194] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0195] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0196] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A private network connection method, characterized in that, Applications to private network servers include: Receive a private network connection request from a target mobile terminal. The private network connection request is used to request a connection to a target private network device. The private network connection request includes the dedicated domain name information allocated to the target private network device under the corresponding private network service. The dedicated domain name information is parsed to obtain the address information of the target private network device; The address information of the target private network device is sent to the target mobile terminal, and the address information of the target private network device is used by the target mobile terminal to establish a connection with the target private network device.
2. The method according to claim 1, characterized in that, The method further includes: The address information and private network service information of the target mobile terminal are obtained. The private network service information includes: the contact information of the contracted user, the contracted broadband account, and the contracted user's private network domain name. The contracted user's private network domain name is used to indicate the address information of at least one private network device, and the at least one private network device includes the target private network device. Based on the address information of the target mobile terminal and the address information of at least one private network device, a firewall whitelist is generated and synchronized to the home smart gateway; one private network device corresponds to one address information. The firewall whitelist is used by the home smart gateway to verify whether the target mobile terminal is allowed to establish a connection with the target private network device.
3. The method according to claim 2, characterized in that, The method further includes: If at least one of the address information of the target mobile terminal and the address information of the at least one private network device changes, the firewall whitelist is dynamically updated based on the changed address information of the target mobile terminal and the address information of the at least one private network device.
4. The method according to claim 2 or 3, characterized in that, The method further includes: The address information of at least one private network device is determined based on the private network domain name of the contracted user through dynamic domain name service.
5. The method according to claim 1, characterized in that, Receiving a private network connection request from the target mobile terminal includes: Receive the private network connection request of the target mobile terminal forwarded by the public server.
6. A private network connection device, characterized in that, include: The module consists of a receiving module, a parsing module, and a sending module. The receiving module is used to receive a private network connection request from the target mobile terminal. The private network connection request is used to request a connection to the target private network device. The private network connection request includes the dedicated domain name information allocated to the target private network device under the corresponding private network service. The parsing module is used to parse the private domain name information received by the receiving module to obtain the address information of the target private network device; The sending module is used to send the address information of the target private network device obtained by the parsing module to the target mobile terminal. The address information of the target private network device is used by the target mobile terminal to establish a connection with the target private network device.
7. The apparatus according to claim 6, characterized in that, The device further includes: an acquisition module and a generation module; The acquisition module is used to acquire the address information and private network service information of the target mobile terminal. The private network service information includes: the contact information of the contracted user, the contracted broadband account, and the contracted user's private network domain name. The contracted user's private network domain name is used to indicate the address information of at least one private network device, and the at least one private network device includes the target private network device. The generation module is used to generate the firewall whitelist based on the address information of the target mobile terminal and the address information of the at least one private network device obtained by the acquisition module, and to synchronize the firewall whitelist to the home smart gateway; one private network device corresponds to one address information; The firewall whitelist is used by the home smart gateway to verify whether the target mobile terminal is allowed to establish a connection with the target private network device.
8. The apparatus according to claim 7, characterized in that, The device further includes: an update module; The update module is used to dynamically update the firewall whitelist based on the changed address information of the target mobile terminal and the address information of the at least one private network device when at least one of the address information of the target mobile terminal and the address information of the at least one private network device is detected to have changed.
9. The apparatus according to claim 7 or 8, characterized in that, The device further includes: a determining module; The determining module is used to determine the address information of at least one private network device based on the private network domain name of the contracted user through dynamic domain name service.
10. The apparatus according to claim 6, characterized in that, The receiving module is specifically used to receive the private network connection request of the target mobile terminal forwarded by the public server.
11. An electronic device, characterized in that, It includes a processor and a memory, the memory storing programs or instructions that can run on the processor, the programs or instructions being executed by the processor to implement the private network connection method as described in any one of claims 1-5.
12. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a computer, implement the private network connection method as described in any one of claims 1-5.
13. A computer program product, characterized in that, The computer program product is stored in a storage medium, and when executed by a computer, the computer program product implements the private network connection method as described in any one of claims 1-5.