Method and device for accessing an agent gateway on a cloud phone by an agent client
Patent Information
- Application Number
- CN202610773602.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-29
- Publication Date
- 2026-09-11
AI Technical Summary
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description.
Smart Images

Figure CN122741584A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to the fields of artificial intelligence such as deep learning, large models, intelligent agents, and cloud platforms. Specifically, it relates to a method and apparatus for an intelligent agent client to access an intelligent agent gateway on a cloud mobile phone. Background Technology
[0002] Cloud phones are a new type of mobile terminal service based on cloud computing and virtualization technologies. Their core is running a complete mobile operating system on a server in a data center, creating a remotely accessible and independently operating virtual mobile device instance. Users can control cloud phones in real time from any terminal via the network without relying on a local physical device. Because cloud phone resources are centrally deployed in the cloud, they offer advantages such as high availability, strong isolation, and elastic scalability, and have been widely used in scenarios such as mobile office and smart device hosting. Summary of the Invention
[0003] This application provides a method and apparatus for a smart agent client to access a smart agent gateway on a cloud phone. The specific solution is as follows:
[0004] According to one aspect of this application, a method is provided for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: Receive a credential verification request sent by the access gateway; wherein, the credential verification request is used to request the legality verification of the target user's access credentials to the target cloud phone in the first connection request sent by the smart agent client; Verify the validity of access credentials; In response to the access credentials being verified as valid, the network address of the smart agent gateway in the target cloud phone is obtained and sent to the access gateway. Receive a second connection request sent by the access gateway; wherein the second connection request is generated by the access gateway based on the network address; Based on the second connection request, a communication connection is established with the agent gateway; wherein, the communication connection is used to control the gateway to transmit messages between the agent client and the agent gateway.
[0005] According to another aspect of this application, a method is provided for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: Receive a first connection request sent by the intelligent agent client; wherein the first connection request includes the target user's access credentials to the target cloud phone; Send a credential verification request to the control gateway; the credential verification request is used to request the validity of the access credentials. In response to obtaining the network address of the smart agent gateway in the target cloud phone sent by the control gateway, a second connection request is generated based on the network address; wherein, the network address is obtained by the control gateway after the access credentials have been verified as valid; The second connection request is sent to the control gateway, which then establishes a communication connection with the agent gateway. This communication connection is used by the control gateway to transmit messages between the agent client and the agent gateway.
[0006] According to another aspect of this application, an apparatus is provided for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: The receiving module is used to receive the credential verification request sent by the access gateway; wherein, the credential verification request is used to request the legality verification of the target user's access credentials to the target cloud phone in the first connection request sent by the smart agent client; The verification module is used to verify the legitimacy of access credentials; The sending module is used to obtain the network address of the smart agent gateway in the target cloud phone in response to the access credential passing the validity verification, and send the network address to the access gateway; The receiving module is also used to receive a second connection request sent by the access gateway; wherein the second connection request is generated by the access gateway based on the network address; The module establishes a communication connection with the agent gateway based on the second connection request; wherein the communication connection is used to control the gateway to transmit messages between the agent client and the agent gateway.
[0007] According to another aspect of this application, an apparatus is provided for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: The receiving module is used to receive a first connection request sent by the intelligent agent client; wherein the first connection request includes the target user's access credentials to the target cloud phone; The sending module is used to send a credential verification request to the control gateway; the credential verification request is used to request the validity of the access credentials. The generation module is used to generate a second connection request in response to obtaining the network address of the smart agent gateway in the target cloud phone sent by the control gateway; wherein, the network address is obtained by the control gateway after the access credentials have been verified as valid; The sending module is also used to send the second connection request to the control gateway, so that the control gateway can establish a communication connection with the intelligent agent gateway in the target cloud phone; wherein, the communication connection is used by the control gateway to transmit messages between the intelligent agent client and the intelligent agent gateway.
[0008] According to another aspect of this application, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the method described in the above embodiments.
[0009] According to another aspect of this application, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to perform the method described in the above embodiments.
[0010] According to another aspect of this application, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the method described in the above embodiments.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description
[0012] The accompanying drawings are provided for a better understanding of this solution and do not constitute a limitation of this application. Wherein: Figure 1 A flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, as provided in an embodiment of this application; Figure 2 A flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, provided in another embodiment of this application; Figure 3 A flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, provided in another embodiment of this application; Figure 4 A flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, provided in another embodiment of this application; Figure 5 A schematic diagram illustrating the architecture of an intelligent agent client accessing an intelligent agent gateway on a cloud phone, provided in an embodiment of this application; Figure 6 This application provides a schematic diagram illustrating the process by which an intelligent agent client accesses an intelligent agent gateway on a cloud phone. Figure 7 A schematic diagram of a device for an intelligent agent client to access an intelligent agent gateway on a cloud phone, provided in an embodiment of this application; Figure 8A schematic diagram of a device for connecting an intelligent agent client to an intelligent agent gateway on a cloud phone, provided in another embodiment of this application. Figure 9 This is a block diagram of an electronic device used to implement the method of intelligent agent client accessing intelligent agent gateway on cloud phone according to the embodiments of this application. Detailed Implementation
[0013] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0014] It should be noted that the acquisition, storage, use, and processing of data in this application comply with the relevant provisions of national laws and regulations and do not violate public order and good morals.
[0015] The following description, with reference to the accompanying drawings, describes a method, apparatus, electronic device, and storage medium for a smart agent client to access a smart agent gateway on a cloud phone, according to embodiments of this application.
[0016] Figure 1 This is a flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, as provided in an embodiment of this application.
[0017] The method for a smart agent client to access a smart agent gateway on a cloud phone according to embodiments of this application can be executed by a device for accessing a smart agent client to a smart agent gateway on a cloud phone according to embodiments of this application. This device can be configured in an electronic device. The electronic device can be any device with computing capabilities.
[0018] In some embodiments, the method by which the intelligent agent client accesses the intelligent agent gateway on the cloud phone can be executed by the control gateway. For example, the control gateway can be deployed on a server based on an x86 architecture.
[0019] In one application scenario, the cloud phone can run on the ARM intranet in the data center without exposing its ports to the outside world. The smart agent client needs to access the smart agent gateway on the cloud phone through the public network to realize full-scale interaction such as remote device control, chat dialogue, and smart agent scheduling.
[0020] The method for accessing the intelligent agent gateway using the embodiments of this application enables intelligent agent clients (i.e., public network users) on the public network side to securely access the intelligent agent gateway within the cloud phone without exposing the cloud phone's ports to the outside world. It can achieve transparent proxying of the intelligent agent gateway protocol while ensuring the security of the public network.
[0021] The intelligent agent gateway protocol here can refer to the application layer protocol defined by the intelligent agent gateway, which is a business layer protocol built on top of the communication protocol.
[0022] like Figure 1 As shown, the method for the intelligent agent client to access the intelligent agent gateway on the cloud phone may include: Step 101: Receive the credential verification request sent by the access gateway.
[0023] In this application, the control gateway can receive credential verification requests sent by the access gateway. Exemplarily, the access gateway can be deployed within a buffer zone established between the internal network and the external network (or public network). Exemplarily, the access gateway can be implemented based on Nginx or other reverse proxy platforms that support script extensions.
[0024] For example, a credential verification request can be used to request the control gateway to verify the legitimacy of the target user's access credentials to the target cloud phone in the first connection request sent by the smart agent client.
[0025] For example, the control gateway integrates a credential verification service. After receiving the first connection request sent by the smart agent client, the access gateway can send a credential verification request to the control gateway to call the credential verification service and verify the legitimacy of the access credential (Ticket).
[0026] For example, the first connection request may be a connection request initiated by the agent client to the agent gateway. The agent gateway can be understood as a network service entity running on a cloud phone, capable of providing agent services. These agent services may refer to the remote interaction capabilities provided by the agent gateway. The agent gateway is not only responsible for receiving and processing instructions from external agent clients (such as remote control commands, natural language dialogue requests, task scheduling signals, etc.), but also for undertaking deep interactions with internal system services of the cloud phone, the agent runtime environment, etc.
[0027] For example, the access credential can be a one-time, time-limited access credential, which can be generated by an access credential issuing service. For example, the credential issuing service can be a centralized service, so that different intelligent agent clients can apply to the credential issuing service for the issuance of access credentials.
[0028] For example, the target cloud phone can be a cloud phone with an agent runtime deployed. When the target user uses the agent client, the agent client needs to communicate with the agent gateway in the target cloud phone in order to reply to the target user in the agent client.
[0029] For example, the credential verification request may include access credentials, and may also include the device identifier of the target cloud phone, etc.
[0030] Step 102: Verify the validity of the access credentials.
[0031] In some embodiments, legitimacy verification may include, but is not limited to, timeliness verification and verification of binding relationships related to access credentials.
[0032] For example, since access credentials have an expiration date, expiration verification can be used to verify whether the access credentials are within their validity period.
[0033] Step 103: In response to the access credentials passing the validity verification, obtain the network address of the smart agent gateway in the target cloud phone and send the network address to the access gateway.
[0034] In this application, if the access credentials are verified to be valid, the control gateway can obtain the network address of the smart agent gateway through the cloud phone platform.
[0035] For example, the network address of the intelligent agent gateway may include the IP address and service port of the target cloud phone. For example, the service port may be the service port of the intelligent agent gateway. For example, the intelligent agent gateway uses different service ports for different communication protocols; for example, the service port corresponding to the HTTP protocol is different from the service port corresponding to the WebSocket protocol.
[0036] For example, the network address of an agent gateway can also be called the upstream address.
[0037] For example, the network address of the agent gateway is used by the control gateway to establish a communication connection with the agent gateway.
[0038] Step 104: Receive the second connection request sent by the access gateway.
[0039] In this application, the second connection request may be generated by the access gateway based on the network address of the agent gateway. For example, the second connection request may be used to request the establishment of a communication connection with the agent gateway.
[0040] For example, the second connection request could be a protocol upgrade request, used to switch the current communication protocol to another. For instance, the second connection request could be an HTTP request that upgrades from the current HTTP protocol to the WebSocket protocol.
[0041] For example, the second connection request can also be a regular connection request, without the need for protocol upgrades.
[0042] Step 105: Based on the second connection request, establish a communication connection with the agent gateway.
[0043] In this application, the control gateway can send a second connection request to the agent gateway to request the agent client to establish a communication connection with the agent gateway. This communication connection can be used by the control gateway to transparently transmit messages between the agent client and the agent gateway; that is, the control gateway can transparently transmit messages between the agent client and the agent gateway based on this communication connection.
[0044] In some embodiments, the control gateway may directly establish a communication connection with the agent gateway based on a second connection request.
[0045] For example, if a response message indicating a successful connection is received from the agent gateway, it can be determined that a communication connection has been established between the control gateway and the agent gateway, and thus a communication connection has also been established between the agent client and the agent gateway.
[0046] For example, the communication connection established between the control gateway and the intelligent agent gateway based on the second connection request can be a connection based on any communication protocol, such as an HTTP connection or a WebSocket connection, without limitation.
[0047] In this embodiment, after receiving the first connection request forwarded by the access gateway, the access credentials of the target user to the target cloud phone carried in the request are validated for legitimacy. When the access credentials pass the validation, the network address of the intelligent agent gateway in the target cloud phone is obtained and returned to the access gateway, thereby avoiding direct exposure of the internal network address. Then, the second connection request generated based on the network address sent by the access gateway is received, and the control gateway establishes a communication connection with the intelligent agent gateway accordingly. Thus, the access to the intelligent agent gateway is improved through the security policy of validating the access credentials, which enhances the security of the intelligent agent client's access to the intelligent agent gateway. This enables public network users to securely access the intelligent agent gateway on the cloud phone, which not only ensures the access security of cloud phone resources, but also isolates the direct interaction between the client and internal network services through the transparent transmission mechanism of the control gateway, further strengthening the internal network boundary protection and providing solid support for secure and reliable communication of intelligent agents in multi-tenant, high-concurrency scenarios.
[0048] Figure 2 This is a flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, as provided in another embodiment of this application.
[0049] like Figure 2 As shown, the method for the intelligent agent client to access the intelligent agent gateway on the cloud phone may include: Step 201: Receive the credential verification request sent by the access gateway.
[0050] In this application, step 201 can be implemented in any of the embodiments of this application, so it will not be described in detail here.
[0051] Step 202: Verify the validity of the access credentials.
[0052] In this application, the access credentials have a certain validity period, which can be used to verify whether the access credentials are within the validity period. If the access credentials are within the validity period, it can be determined that the access credentials have passed the validity period verification; if the access credentials are not within the validity period, it means that the access credentials have expired or have become invalid, the intelligent agent client does not have permission to access the intelligent agent gateway, and the control gateway can send a message indicating that the access credentials have expired to the access gateway.
[0053] Step 203: In response to the access credentials passing the timeliness verification, verify the binding relationship between the access credentials and the device identifier.
[0054] In this application, the credential verification request may also include the device identifier of the target cloud phone. If the access credential passes the timeliness verification, the binding relationship between the access credential and the device identifier of the target cloud phone can be further verified to verify whether there is a binding relationship between the access credential and the target cloud phone.
[0055] For example, this binding relationship verification can be used to confirm whether the access credentials are authorized for accessing the target cloud phone, in order to prevent the access credentials from being stolen.
[0056] Step 204: In response to the verification of the binding relationship between the access credentials and the device identifier, obtain the network address of the smart agent gateway in the target cloud phone, and send the network address to the access gateway.
[0057] In this application, if the access credentials and the device identifier are verified through a binding relationship, it means that the target user or the smart agent client has the permission to access the target cloud phone. Then, the network address corresponding to the device identifier can be obtained by querying the cloud phone platform based on the device identifier.
[0058] For example, the cloud phone platform stores the device identifier, IP address, data center number of the data center where the cloud phone is located, and usage identifier assigned to the user during the use of the cloud phone. The IP address here can be the address of the cloud phone on the intranet.
[0059] For example, the control gateway can send a query request to the cloud phone platform. The query request includes the device identifier of the target cloud phone. Based on the device identifier, the cloud phone platform can determine the IP address of the target cloud phone corresponding to the device identifier by querying the mapping relationship between the device identifier and the IP address. Based on the IP address and the communication protocol port, the network address of the intelligent agent gateway can be determined and returned to the control gateway.
[0060] Therefore, when the access credentials and device identifier are verified through a binding relationship, the accuracy of the network address obtained by querying the cloud phone platform based on the target cloud phone's device identifier can be improved, which in turn can improve the accuracy of the subsequent access gateway.
[0061] Step 205: Receive the second connection request sent by the access gateway.
[0062] Step 206: Based on the second connection request, establish a communication connection with the agent gateway.
[0063] In this application, steps 204-206 can be implemented in any of the embodiments of this application, so they will not be described in detail here.
[0064] In this embodiment, by verifying the validity of access credentials, the validity of the access credentials can be guaranteed. On this basis, when the access credentials are valid, a binding relationship verification is further performed to verify whether the access credentials are authorized to access the specified cloud phone. This not only prevents the abuse of access credentials, but also effectively blocks the risk of using legitimate access credentials across devices. Even if a valid credential is obtained, if it is not bound to the target device identifier, access cannot be completed. This achieves fine-grained and highly reliable dual authentication of identity and device, which can effectively improve the accuracy of access credential validity verification, thereby enhancing the security of the smart agent client accessing the smart agent gateway.
[0065] Figure 3 This is a flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, as provided in another embodiment of this application.
[0066] like Figure 3 As shown, the method for the intelligent agent client to access the intelligent agent gateway on the cloud phone may include: Step 301: Receive the credential verification request sent by the access gateway.
[0067] Step 302: Verify the validity of the access credentials.
[0068] Step 303: In response to the access credentials passing the validity verification, obtain the network address of the smart agent gateway in the target cloud phone and send the network address to the access gateway.
[0069] Step 304: Receive the second connection request sent by the access gateway.
[0070] In this application, steps 303-304 can be implemented in any of the embodiments of this application, so they will not be described in detail here.
[0071] In some embodiments, the second connection request may include an access authorization token.
[0072] For example, the access authorization token can be a token that authorizes the agent client used by the target user to access the agent gateway.
[0073] For example, the access authorization token may be issued by the billing gateway.
[0074] For example, the second connection request may also include the target user's user identifier, the target cloud phone's device identifier, the session identifier, the network address of the smart agent gateway, and the data center code of the data center where the target cloud phone is located. Among them, the session identifier can be used for connection auditing and tracing.
[0075] For example, the access authorization token, the user identifier of the target user, the device identifier of the target cloud phone, the session identifier, the network address of the smart agent gateway, and the data center code of the data center where the target cloud phone is located can be information injected by the access gateway into the control gateway in the second connection request.
[0076] Step 305: Authenticate the access authorization token.
[0077] In this application, in order to further improve the security of intelligent agent client accessing intelligent agent gateway, access authorization tokens can be authenticated.
[0078] In some embodiments, authentication of the access authorization token may include, but is not limited to, verification of the legality of the access authorization token, verification of the binding relationship between the user identifier of the target user and the device identifier of the target cloud phone, and verification of the proxy access permission of the access authorization token.
[0079] For example, this binding relationship verification is used to confirm whether the target user has permission to access the cloud phone.
[0080] For example, the proxy access permission verification of the access authorization token can be used to confirm whether the access authorization token has been granted proxy access permission, that is, to verify whether the target user and its smart agent client corresponding to the access authorization token have been granted permission to connect to the smart agent gateway on the target cloud phone through a proxy.
[0081] For example, the access authorization token can be authenticated in the following ways: The access authorization token can be validated for legitimacy. If the access authorization token passes the legitimacy validation, the binding relationship between the target user's user identifier and the target cloud phone's device identifier can be verified to confirm whether the target user has permission to use the smart agent in the cloud phone. If the binding relationship between the user identifier and the device identifier passes the verification, the proxy access permission of the access authorization token can be verified to confirm whether the access authorization token has been granted proxy access permission. If all three verifications pass, the access authorization token can be considered to have passed authentication.
[0082] For example, validating the access authorization token may include one or more of the following: verifying the existence of the access authorization token, verifying the validity of the access authorization token, verifying the timeliness of the access authorization token, etc.
[0083] For example, the access authorization token can be sequentially verified for existence, validity, and timeliness.
[0084] As an example, the existence of an access authorization token can be verified by checking if the string of the access authorization token is not empty. If the string of the access authorization token is not empty, the access authorization token is considered to exist, and the existence verification can be confirmed. If the string of the access authorization token is empty, it means that the access authorization token does not exist, and the existence verification can be confirmed. A message indicating that the access authorization token is missing can be returned.
[0085] As an example, the validity of an access authorization token can be verified by checking if a metadata record for the token exists in the metadata database. If the metadata record exists, the access authorization token is valid, and the validity verification has passed. If the metadata record does not exist, the access authorization token is invalid, and the validity verification has failed. An invalid access authorization token message can be returned.
[0086] As an example, the validity of an access authorization token can be verified by checking if its expiration time is later than the current time. If the expiration time is later than the current time, the access authorization token has not expired, and the validity verification can be confirmed. If the expiration time is earlier than or equal to the current time, the access authorization token has expired, and the validity verification can be confirmed. A message indicating that the access authorization token has expired can be returned.
[0087] It should be noted that authentication of access authorization tokens can be performed using one or more of the following three methods: verifying the legitimacy of the access authorization token, verifying the binding relationship between the target user's user identifier and the target cloud phone's device identifier, and verifying the proxy access permissions of the access authorization token. There are no restrictions on which method is used.
[0088] In this embodiment, the access authorization token's reliability is ensured by verifying its legitimacy. Furthermore, the binding relationship between the user identifier associated with the access authorization token and the device identifier of the cloud phone is verified to prevent the legitimate token from being abused across devices, ensuring that the correct user accesses the correct device. After verifying the binding relationship between the user identifier and the device identifier, the access authorization token is further verified to determine if it has proxy access permissions, confirming whether the target user is authorized to connect to the smart agent gateway on the target cloud phone via a proxy. Thus, through a multi-level, progressive verification mechanism, the access authorization token is authenticated, effectively blocking security risks such as forged access authorization tokens, stolen access authorization tokens, and unauthorized access. It also achieves fine-grained access control, providing solid technical support for the secure and reliable access of smart agent clients to intranet cloud phone resources while ensuring high availability.
[0089] Step 306: In response to the access authorization token being authenticated, a third connection request is sent to the smart agent gateway.
[0090] In this application, if the access authorization token is authenticated, the control gateway can send a third connection request to the intelligent agent gateway based on the network address of the intelligent agent gateway.
[0091] For example, a third connection request can be a protocol upgrade request, requesting a switch from the current communication protocol to another. For instance, a third connection request could be an HTTP request that upgrades from the current HTTP protocol to the WebSocket protocol.
[0092] For example, a third connection request can also be a regular connection request that does not require protocol upgrades.
[0093] Step 307: In response to receiving a connection success message from the agent gateway, determine that a communication connection has been established between the control gateway and the agent gateway.
[0094] In this application, the connection success message is used to indicate that the control gateway and the agent gateway have successfully established a communication connection. Based on the connection success message, the control gateway can determine that a communication connection has been established with the agent gateway.
[0095] As an example, if the first, second, and third connection requests are all protocol upgrade requests, requesting an upgrade from the current HTTP protocol to the WebSocket protocol, and if the control gateway sends the third connection request to the agent gateway based on the agent gateway's network address and then receives a connection success message from the agent gateway, such as a protocol upgrade success message, it indicates that a WebSocket connection has been established between the control gateway and the agent gateway.
[0096] For example, if the communication connection between the control gateway and the agent gateway fails to be established, the agent gateway can send a connection failure message to the control gateway.
[0097] In some embodiments, after the control gateway and the agent gateway establish a communication connection, the agent client and the agent gateway can perform an agent gateway protocol handshake based on this communication connection. This protocol handshake is an end-to-end protocol-level authentication between the agent client and the agent gateway. During this protocol handshake process, the control gateway is completely unaware of the frame content of this process and only transmits it transparently.
[0098] For example, the handshake process between the agent client and the agent gateway can be as follows: The agent gateway can send a connection control message to the control gateway. The control gateway can then forward this connection control message to the agent client. After receiving the connection control message, the agent client generates an authentication request based on the connection control message and sends it to the control gateway. The control gateway then forwards this authentication request to the agent gateway. After successfully authenticating the agent client based on the authentication request, the agent gateway can send an authentication success response message to the control gateway. The control gateway then forwards this response message to the agent client. Thus, the handshake between the agent gateway and the agent client is successful.
[0099] For example, a connection control message can be viewed as a connection challenge invitation sent by the agent gateway to the agent client. The connection control message may carry a random number, the current timestamp of the agent gateway, the version identifier of the agent gateway, etc.
[0100] For example, an authentication request can be used to request whether the agent client has permission to establish a trusted business session with the agent gateway.
[0101] For example, the agent client generates an authentication request in the following way: The agent client can generate an identity credential based on the random number and timestamp in the connection control message, and then generate an authentication request based on the identity credential. This identity credential can be used by the agent gateway to verify whether the agent client has the authority to establish a trusted business session with the agent gateway.
[0102] For example, the intelligent agent client can generate identity credentials using random numbers and timestamps according to agreed rules.
[0103] For example, after receiving an authentication request, the intelligent agent gateway can parse the identity credential to obtain a random number and a timestamp. If the parsed random number is consistent with the one sent to the intelligent agent client, and the parsed timestamp is consistent with the one sent to the intelligent agent client, it can be determined that the intelligent agent client has passed the authentication and has the authority to establish a trusted business session with the intelligent agent gateway.
[0104] Therefore, the agent client generates an identity credential based on the random number and timestamp in the connection control message, and generates an identity authentication request based on the identity credential. This makes it easier for the agent gateway to use the identity credential to authenticate the agent client and improve the reliability of communication.
[0105] Optionally, in addition to identity credentials, the authentication request may also include the agent client's identification information (such as client version number, client name, etc.), the operating system type of the device on which the agent client is located, the capability description of the agent client, and the requested protocol version number. The protocol version number refers to the version number of the agent protocol.
[0106] For example, the agent client can use this capability description to tell the agent gateway which functions it supports.
[0107] For example, the authentication success response message is a confirmation message of a successful handshake. The authentication success response message can be used to indicate to the agent client that authentication has been successful, the connection has been established, and it can communicate with the agent gateway.
[0108] For example, the successful authentication response message may include, but is not limited to, the protocol version negotiated between the agent client and the agent gateway, the list of functions supported by the agent gateway, a snapshot of the current target cloud phone's status (such as screen resolution, system version, etc.), and the target cloud phone's identity information.
[0109] Taking the communication connection between the agent client and the agent gateway as a WebSocket connection as an example, if the agent client receives an authentication success response message, it can be determined that the agent client and the agent gateway can communicate through a WebSocket connection.
[0110] For example, an agent client can send WebSocket frames to the control gateway, which then forwards the WebSocket frames to the agent gateway. Similarly, the agent gateway can send WebSocket frames to the control gateway, which then forwards them to the agent client. Thus, the control gateway performs zero-parse, zero-serialization byte-level forwarding of all WebSocket frames, achieving transparent, byte-level protocol proxying without the client's awareness.
[0111] In this embodiment, the control gateway (such as the proxy layer) does not process the content of the data fields in the WebSocket frame during the data transmission phase. Therefore, regardless of the protocol used for the data carried by the WebSocket frame, the behavior of the proxy layer remains completely consistent, consisting of byte-level copying. This means that changes in the protocol's encoding format do not affect the proxy layer, nor do changes in the protocol's method set.
[0112] In this embodiment, the control gateway forwards the connection control message issued by the agent gateway to the agent client, triggering the agent client to generate an authentication request. The control gateway then forwards the entire request back to the agent gateway for authentication and finally returns the authentication result to the agent client. By implementing a bidirectional forwarding mechanism between the agent client and the agent gateway in the control gateway, a secure and decoupled authentication channel is constructed. This ensures that the decision-making power for authentication is completely retained by the agent gateway on the target cloud phone side, guaranteeing the contextual accuracy and security of permission judgment. At the same time, it avoids the control gateway from parsing or caching sensitive authentication data, reducing the security risks of intermediate nodes.
[0113] Furthermore, the pass-through mechanism enhances the system's flexibility and compatibility, supporting future expansion of authentication protocols without modifying the control gateway logic. This ensures secure end-to-end communication while improving the maintainability and reliability of the overall architecture.
[0114] In this embodiment, the access credentials are validated based on a credential verification request. Once the access credentials pass validation, the network address of the smart agent gateway in the target cloud phone is obtained and returned to the access gateway. Then, a second connection request generated based on the network address is received from the access gateway, and the access authorization token in the second connection request is authenticated. If authentication is successful, a third connection request is sent to the smart agent gateway. If a connection success message is received, it is determined that a communication connection has been established between the control gateway and the smart agent client. Therefore, through security strategies such as access credential validation and access authorization token authentication, unauthorized or illegal client access attempts can be effectively blocked, further improving the security of smart agent client access to the smart agent gateway.
[0115] In some embodiments of this application, in order to improve the reliability of communication during the communication process between the intelligent agent client and the intelligent agent gateway, a three-layer heartbeat keep-alive mechanism can be adopted, namely client liveness detection, protocol-level keep-alive detection, and intelligent agent gateway liveness detection, to detect network connectivity, application layer liveness, etc.
[0116] In some embodiments, the following method can be used to detect client liveness: the control gateway sends a first liveness probe message to the agent client every first preset time interval to detect the liveness of the agent client. If the control gateway receives a first liveness response message from the agent client within a second preset time interval, it can be determined that the agent client is alive. If the control gateway does not receive a first liveness response message from the agent client within a second preset time interval, it can be determined that the agent client is not alive.
[0117] For example, the first liveness detection message can be a Ping message, and the first liveness response message can be a Pong message.
[0118] For example, if the agent client and the agent gateway communicate via a WebSocket connection, the first liveness detection message and the first liveness response message are sent based on the WebSocket connection. For instance, the control gateway sends a Ping message by sending a WebSocket Ping frame to the agent client; if the agent client is alive, it can send a Pong message by sending a WebSocket Pong frame to the control gateway.
[0119] For example, the second preset duration can be greater than or equal to the first preset duration. For instance, the control gateway sends a first liveness detection message to the agent client every 15 seconds. If the control gateway does not receive a first liveness response message from the agent client within 30 seconds, it can determine that the agent client is not alive.
[0120] Optionally, if it is determined that the agent client is not alive, a fault recovery strategy associated with the agent client's failure to live can be executed.
[0121] For example, the fault recovery strategy may include, but is not limited to, closing the communication connection and clearing the connection metadata.
[0122] For example, the connection metadata may refer to the metadata of the communication connection, the active connection list of the target cloud phone, etc. For example, the metadata of the communication connection may include, but is not limited to, the IP address, port, protocol, timestamp, etc. of the target cloud phone, and the active connection list of the target cloud phone includes the communication connections existing on the target cloud phone.
[0123] As an example, if the agent client is not alive, delete the metadata of the corresponding communication connection and remove the communication connection from the active connection list of the target cloud phone.
[0124] In this embodiment, the control gateway periodically sends liveness detection messages to the agent client and combines them with timeout judgment logic to perform liveness detection on the agent client. This liveness detection mechanism based on heartbeat detection realizes proactive, real-time and reliable monitoring of the client connection status. It can not only effectively avoid the long-term occupation of system resources by "zombie connections" caused by network interruptions, abnormal client crashes or silent disconnections, but also significantly improve the robustness, resource utilization efficiency and fault self-healing ability of the system.
[0125] In some embodiments, protocol-level keep-alive detection can be implemented in the following way: the agent gateway can send a heartbeat detection message to the control gateway every third preset time interval, and the control gateway will pass the heartbeat detection message to the agent client. That is, the control gateway will pass the heartbeat detection message sent by the agent gateway every third preset time interval to the agent client.
[0126] For example, the heartbeat detection message can be used to detect whether the agent gateway is abnormal. If the agent client receives the heartbeat detection message within a fourth preset time period, it is determined that the agent gateway is normal. If it does not receive the heartbeat detection message within the fourth preset time period, it is determined that the agent gateway is abnormal.
[0127] For example, the fourth preset duration can be greater than or equal to the third preset duration. For instance, if the agent gateway sends a heartbeat detection message every 30 seconds, and the agent client does not receive a heartbeat detection message within 90 seconds, it can be determined that the agent gateway is malfunctioning.
[0128] Optionally, if the agent gateway is determined to be abnormal, a fault recovery strategy associated with the agent gateway abnormality can be adopted.
[0129] For example, fault recovery strategies associated with intelligent agent gateway anomalies may include, but are not limited to, sending alarms (e.g., the target cloud phone may crash, the intelligent agent process may crash, etc.), triggering device health checks, sending connection closure information to the client with the reason, closing the communication connection, and clearing connection metadata. The connection metadata here is similar to the connection metadata mentioned above, so it will not be described again here.
[0130] For example, a device health check can refer to a health check for a target cloud phone.
[0131] In this embodiment, the agent gateway periodically sends heartbeat detection messages, which are then transmitted to the agent client via the control gateway. The agent client dynamically determines the availability of the agent gateway based on whether it receives the heartbeat detection message within a fourth preset time period. If it receives the message on time, it confirms that the gateway service is normal; if it does not receive the message within the time limit, it determines that the agent gateway is abnormal. This protocol-level keep-alive detection, which is actively triggered by the server (i.e., the agent gateway) and passively verified by the client, can avoid communication failures caused by the crash of the agent gateway process. Thus, without increasing the complexity of the protocol, it significantly improves the accuracy of connection status perception and the timeliness of fault detection, thereby improving communication reliability.
[0132] In some embodiments, the agent gateway liveness detection can be performed in the following manner: the control gateway sends a second liveness detection message to the agent gateway every fifth preset time interval to detect the liveness of the agent gateway; if a second liveness response message sent by the agent gateway is received within a sixth preset time interval, it is determined that the agent gateway is alive; if a second liveness response message sent by the agent gateway is not received within a sixth preset time interval, it is determined that the agent gateway is not alive.
[0133] For example, the second liveness detection message can be a Ping message, and the second liveness response message can be a Pong message.
[0134] For example, if the agent client and the agent gateway communicate via a WebSocket connection, the second liveness detection message and the second liveness response message are sent based on the WebSocket connection. For instance, the control gateway sends a Ping message by sending a WebSocket Ping frame to the agent gateway, and if the agent gateway is alive, it can send a Pong message by sending a WebSocket Pong frame to the control gateway.
[0135] For example, the sixth preset duration can be greater than or equal to the fifth preset duration. For instance, the control gateway sends a second liveness detection message to the agent gateway every 15 seconds. If the control gateway does not receive a second liveness response message from the agent gateway within 30 seconds, it can determine that the agent gateway is not alive.
[0136] Optionally, if the agent gateway is not alive, a fault recovery strategy associated with the agent gateway not being alive can be executed.
[0137] For example, fault recovery strategies associated with the agent gateway failing to live may include controlling the gateway to close its communication connection with the agent gateway, controlling the gateway to close its communication connection with the agent client, and clearing connection metadata. The connection metadata here is similar to the connection metadata described above, and therefore will not be repeated here.
[0138] Therefore, by periodically sending liveness detection messages to the agent gateway through the control gateway, if the agent gateway receives a liveness response (i.e., the aforementioned liveness response message) within the set response window, it is confirmed that the agent gateway is normal and the communication link is normal. If no response is received within the timeout period, the agent gateway is determined to be abnormal, and the corresponding fault recovery strategy is triggered. This agent gateway liveness detection mechanism, led by the control gateway, judges whether the agent gateway is abnormal based on the response timeout, realizing proactive, real-time, and reliable heartbeat monitoring of the backend agent gateway service. It can effectively avoid problems such as resource deadlock and request backlog caused by agent gateway abnormality. It can not only improve the ability to perceive the health status of backend services, but also enhance the fault tolerance, resource reclamation efficiency, and high availability guarantee level of the overall architecture.
[0139] In this embodiment, client liveness detection is used to detect the network link (belonging to the public network segment) from the client to the control gateway (including the proxy layer), agent gateway liveness detection is used to detect the connectivity of the communication link (such as the WebSocket link) from the proxy layer to the agent gateway (belonging to the internal network segment), and protocol-level keep-alive detection is used to independently detect the application layer liveness of the agent gateway process.
[0140] Understandably, the key difference between protocol-level keep-alive detection and agent gateway liveness detection is that agent gateway liveness detection detects transport layer connectivity through liveness probe messages and liveness response messages, while agent processes may stop sending heartbeat detection messages (such as tick events) due to deadlock, event loop blocking, or other reasons.
[0141] In this embodiment, protocol-level keep-alive detection is monitored through an independent heartbeat detection message channel. The timer can be reset only when a heartbeat detection message is received. Response messages from ordinary RPCs (Remote Procedure Calls) do not affect the protocol-level keep-alive detection timer. The identification of heartbeat detection messages can use lightweight byte prefix matching (e.g., checking whether the first 64 bytes of the frame contain "method":"tick"), which does not involve complete JSON parsing and does not violate the zero-parse semantics of transparent proxies.
[0142] Figure 4 This is a flowchart illustrating a method for a smart agent client to access a smart agent gateway on a cloud phone, according to another embodiment of this application. This method can be executed by the access gateway.
[0143] like Figure 4 As shown, the method for the intelligent agent client to access the intelligent agent gateway on the cloud phone may include: Step 401: Receive the first connection request sent by the intelligent agent client.
[0144] In this application, the intelligent agent client initiates a first connection request to the intelligent agent gateway to request the intelligent agent gateway in the target cloud phone, and the access gateway receives the first connection request sent by the intelligent agent client.
[0145] For example, the first connection request may be a WSS (WebSocket Secure) connection request, which may use the encrypted WebSocket protocol or the unencrypted WebSocket protocol, without limitation.
[0146] For example, the first connection request may include the target user's access credentials to the target cloud phone. The explanation of the access credentials can be found in the above embodiments, and therefore will not be repeated here.
[0147] For example, the first connection request may also include the target cloud phone's device identifier, the target user's user identifier, the session identifier, and the data center code of the data center where the target cloud phone is located. Among them, the session identifier can be used for connection auditing and tracing.
[0148] It should be noted that the above WSS connection request is only an example of the first connection request. The first connection request can also use other communication protocols, such as the HTTP protocol, and this application does not limit it.
[0149] Step 402: Send a credential verification request to the control gateway.
[0150] In this application, the access gateway can generate a credential verification request based on the access credentials in the first connection request, and send the credential verification request to the control gateway, which will then verify the legitimacy of the access credentials.
[0151] Understandably, a credential verification request is used to request the control gateway to verify the legitimacy of access credentials.
[0152] For example, the credential verification request may include access credentials, the device identifier of the target cloud phone, etc.
[0153] For example, the control gateway integrates a credential verification service. The access gateway can verify the legitimacy of the access credentials by calling this credential verification service based on the access credentials, the device identifier of the target cloud phone, etc.
[0154] In some embodiments, a security policy may be executed on the first connection request before sending the credential verification request to the control gateway, and the credential verification request may be sent to the control gateway after the security policy processing is completed.
[0155] For example, a security policy may include at least one of the following: TLS (Transport Layer Security Termination), WAF (Web Application Firewall) inspection, and IP-based rate limiting.
[0156] TLS is a security protocol used to encrypt network communications. TLS termination refers to the access gateway decrypting encrypted traffic (such as HTTPS or WSS) from the client, converting it to plaintext (HTTP or WS), and then forwarding it to the backend service. This allows for centralized management of certificates and keys, reduces the encryption / decryption burden on backend services, and facilitates security checks (such as WAF checks), logging, and routing at the proxy layer.
[0157] WAF inspection can be used to detect and block web layer attacks by detecting malicious content (such as SQL injection, command injection, etc.) in the first connection request to block attack traffic.
[0158] IP-based rate limiting can restrict the frequency of requests from the same IP address, preventing abuse or DDoS (Distributed Denial of Service) attacks.
[0159] As an example, an access gateway can rate-limit the first connection request from a smart agent client based on the source IP, preventing a single user or attacker from exhausting backend resources and preventing excessive requests from a single IP.
[0160] Therefore, by executing the security policy on the first connection request and then sending the credential verification request to the control gateway, the encryption and decryption burden of the backend service can be reduced, web layer attacks can be intercepted, and resource utilization can be improved.
[0161] Step 403: In response to obtaining the network address of the smart agent gateway in the target cloud phone sent by the control gateway, a second connection request is generated based on the network address.
[0162] In this application, the control gateway verifies the validity of the access credentials. After the access credentials pass the validity verification, it obtains the network address of the intelligent agent gateway in the target cloud phone and sends it to the access gateway. If the access gateway obtains the network address of the intelligent agent gateway sent by the control gateway, it can generate a second connection request based on the network address.
[0163] For example, the second connection request may include the network address of the agent gateway so that the control gateway can establish a communication connection with the agent gateway.
[0164] In some embodiments, an access authorization token and the device identifier of the target cloud phone can be obtained from the first connection request, and a second connection request can be generated based on the network address, access authorization token, and device identifier. Thus, the second connection request can carry the network address, access authorization token, device identifier, etc., of the smart agent gateway.
[0165] The explanation of the access authorization token can be found in the above embodiments, so it will not be repeated here.
[0166] Therefore, the second connection request not only carries the network address of the intelligent agent gateway, but also information such as the access authorization token and the device identifier of the target cloud phone, so that the control gateway can perform security policies such as authentication of the access authorization token, which can improve the security of accessing the intelligent agent gateway.
[0167] In some embodiments, the access gateway can generate a second connection request based on the gateway address and the access authorization token, user identifier of the target user, device identifier of the target cloud phone, session identifier, and data center code of the data center where the target cloud phone is located, carried in the first connection request. Thus, the access gateway can inject this information into the control gateway in the second connection request, facilitating the control gateway to authenticate access permissions based on this information and establish a communication connection after successful authentication.
[0168] Step 404: Send the second connection request to the control gateway, and the control gateway establishes a communication connection with the smart agent gateway in the target cloud phone.
[0169] In this application, the communication connection between the control gateway and the agent gateway is used by the control gateway to transparently transmit messages between the agent client and the agent gateway. That is, the control gateway can transparently transmit messages between the agent client and the agent gateway based on the communication connection.
[0170] In some embodiments, the access gateway may send a second connection request generated based on the network address of the agent gateway to the control gateway, and the control gateway may establish a communication connection with the agent gateway based on the network address of the agent gateway in the second connection request.
[0171] In this embodiment, after receiving the first connection request from the intelligent agent client carrying access credentials, the access credentials are submitted to the control gateway for validity verification. Only when the access credentials are successfully verified and the real network address of the intelligent agent gateway in the target cloud phone is obtained, a second connection request is generated, and the control gateway actively establishes a communication connection with the intelligent agent gateway. This channel is subsequently used for bidirectional transparent transmission of all messages between the client and the intelligent agent gateway, avoiding direct exposure of the cloud phone's internal service address and achieving separation of access authentication and data transmission. Therefore, accessing the intelligent agent gateway through a security policy that verifies the validity of access credentials improves the security of intelligent agent client access to the intelligent agent gateway. This not only ensures the security of cloud phone resource access but also isolates direct interaction between the client and internal network services through the control gateway's transparent transmission mechanism, further strengthening internal network boundary protection and providing solid support for secure and reliable communication of intelligent agents in multi-tenant, high-concurrency scenarios.
[0172] In one embodiment of this application, the access credential may be generated by the smart agent client by calling the credential issuance service.
[0173] In some embodiments, the intelligent agent client can obtain access credentials by calling the credential issuance service based on the API (Application Programming Interface) key and the authentication information of the target user.
[0174] For example, the credential issuance service may include: identifying whether the intelligent agent client is legitimate based on the API key; if the intelligent agent client is legitimate, verifying the target information in the authentication information; if the target information passes the verification, obtaining the gateway domain name associated with the target cloud phone by querying the cloud phone platform based on the usage identifier of the target cloud phone in the authentication information, generating an access credential based on a random number, and returning the access credential and the gateway domain name.
[0175] For example, the authentication information of the target user may include, but is not limited to, platform identifier, target user's user identifier, session identifier, access authorization token, and target user's usage identifier of the target cloud phone. The platform identifier may refer to the type of operating system of the terminal device where the intelligent agent client resides.
[0176] For example, the usage identifier can refer to the usage identifier assigned to a target user during the use of the bound target cloud phone. For the same cloud phone, different users may be assigned different usage identifiers during the use of the cloud phone.
[0177] For example, the target information in the authentication information may include the target user's user identifier, session identifier (such as that which can be used for audit trails), access authorization token, and the target user's usage identifier for the target cloud phone.
[0178] For example, access credentials generated based on random numbers can be structured identifiers generated from random numbers.
[0179] For example, after the target information passes verification, the data center code of the data center where the target cloud phone is located can be obtained by querying the cloud phone platform based on the target cloud phone's usage identifier. The gateway domain name associated with the target cloud phone can then be determined based on the data center code. In other words, the gateway domain name can be determined based on the data center code of the data center where the target cloud phone is located.
[0180] For example, the device identifier and IP address of the target cloud phone can be obtained from the cloud phone platform, and metadata of the access credential can be generated and stored locally based on the access credential, the user identifier of the target user, the session identifier, the access authorization token, the usage identifier of the target cloud phone, the device identifier of the target cloud phone, the IP address of the target cloud phone, the data center code, the issuance time of the access credential, the expiration time of the access credential, etc., for subsequent use.
[0181] For example, when there is network jitter, if the agent client repeatedly requests the issuance of access credentials, the credentials can be obtained by querying the local metadata and then returned to the agent client, without the need for re-verification and regeneration.
[0182] In some embodiments, when the credential issuance service communicates with the cloud phone platform, it can use a hybrid encryption of RSA and AES to improve data security.
[0183] For example, the credential issuance service constructs a request header based on the encryption type identifier field and the response encryption instruction field. It then determines the RSA public key based on the cloud phone platform's environment, encrypts the generated AES key using the RSA public key, and obtains the encrypted AES key. The request parameters are then concatenated into a string according to their order. This string is further encrypted using the AES key and a secure random number. Finally, based on the request header, the encrypted AES key, the secure random number, and the encrypted string, a query request is generated and sent to the query cloud phone platform. The cloud phone platform decrypts the query request and uses the same encryption method to encrypt information such as the data center code, the target cloud phone's device identifier, and the target cloud phone's IP address before returning it to the credential issuance service.
[0184] For example, the encryption type identifier field can be used to declare the symmetric encryption algorithm used in the request body, and the response encryption indication field can be used to indicate whether the server performs encryption on the response body.
[0185] For example, the encrypted AES key can be included in the request header of the query request.
[0186] As an example, encrypting the string using an AES key and a secure random number can include: padding the string to a multiple of 16 bytes, dividing the padded string into at least one 16-byte plaintext block, assuming there are multiple plaintext blocks, for the first plaintext block, performing an XOR operation between the first plaintext block and the secure random number, encrypting the result using the AES key to obtain the first ciphertext block, performing an XOR operation between the second plaintext block and the first ciphertext block, encrypting the result using the AES key to obtain the second ciphertext block, performing the same operation sequentially, and then concatenating the ciphertext blocks in order to obtain the encrypted string.
[0187] For example, each query request generates an independent secure random number, ensuring that the same plaintext produces different ciphertexts, thereby improving the security of communication.
[0188] In this embodiment, the intelligent agent client obtains a temporary access credential by calling the credential issuance service based on the API key and the target user's authentication information. The credential issuance service verifies the legitimacy of the intelligent agent client based on the API key to prevent unauthorized applications from accessing the platform, and verifies the target user's authentication information to ensure that the requesting entity is qualified to operate the target cloud phone. After the verification is successful, the service queries the cloud phone platform to dynamically obtain the gateway domain name associated with the cloud phone and generates a one-time access credential based on a random number. This effectively resists replay and prediction attacks and can significantly improve the security of access credentials and the accuracy of access.
[0189] To facilitate understanding, the following will be combined with... Figure 5 and Figure 6 To explain, Figure 5 This is a schematic diagram illustrating the architecture of an intelligent agent client accessing an intelligent agent gateway on a cloud phone, as provided in an embodiment of this application. Figure 6 This is a schematic diagram illustrating the process of an intelligent agent client accessing an intelligent agent gateway on a cloud phone, as provided in an embodiment of this application.
[0190] The following example uses the intranet of an x86-based server and the intranet of an ARM-based cloud phone as examples, combined with... Figure 5 The architecture will be explained.
[0191] like Figure 5As shown, this architecture has four layers: the first layer is the public network, the second layer is the access gateway, the third layer is the x86 intranet, and the fourth layer is the ARM intranet. The x86 intranet includes credential issuance service, credential verification service, and security proxy service. The credential issuance service is a centralized service, while the credential verification service and security proxy service can be integrated into the control gateway. The security proxy service includes a token authentication middleware and a connection manager. The token authentication middleware is used to authenticate access authorization tokens, and the connection manager manages communication connections, such as heartbeat detection and management of communication connection metadata. Here, heartbeat detection can include liveness detection for intelligent agent clients and liveness detection for intelligent agent gateways.
[0192] The first-layer intelligent agent client can first obtain access credentials and the gateway domain name through the credential issuance service. Then, when the intelligent agent client connects to the intelligent agent gateway through the access gateway, the access gateway calls the credential verification service to verify the access credentials. If verification is successful, it returns the network address of the intelligent agent gateway to the access gateway. After obtaining the network address, the access gateway can send a connection request to the WebSocket transparent proxy port of the security proxy service in plaintext via HTTP or WebSocket, or send a connection request to the HTTP bridging proxy port in plaintext via HTTP or WebSocket. The Token authentication middleware in the security proxy service can authenticate the access authorization token in the connection request. After successful authentication, a communication connection is established with the port of the fourth-layer ARM intranet intelligent agent gateway using the same communication protocol.
[0193] For example, the security proxy service connects to the smart agent gateway through a WebSocket transparent proxy port, enabling byte-level pass-through of WebSocket data; the security proxy service also connects to the smart agent gateway through an HTTP bridging proxy port, enabling HTTP reverse proxying.
[0194] like Figure 6 As shown, the process of the intelligent agent client connecting to the intelligent agent gateway on the cloud phone includes: Phase 1: Access credential issuance. The specific process is as follows: The intelligent agent client sends a credential issuance request to the credential issuance service. The credential issuance service verifies the API key and the target information in the target user's authentication information. After successful verification, it queries the device information through the cloud phone platform, obtains the device identifier, data center identifier (i.e., the data center code mentioned above), device IP address, etc., returned by the cloud phone platform, generates access credentials and metadata of the access credentials, and stores the metadata of the access credentials. Then, it sends the access credentials, device identifier, gateway domain name, etc., to the intelligent agent client. The explanations of authentication information, target information, etc., can be found in the above embodiments, and will not be repeated here; the device IP address refers to the IP address of the target cloud phone.
[0195] Phase 2: Accessing the smart agent gateway via access credentials. The specific process is as follows: The agent client initiates a WSS connection request to the access gateway (such as an OpenResty gateway) using the gateway domain name. This request carries access credentials, device identifier, etc. Upon receiving the WSS connection request, the agent gateway performs security policies such as TLS termination, WFA check, and IP rate limiting. Then, it sends a credential verification request to the credential verification service, which carries access credentials, device identifier, etc. The credential verification service verifies the validity of the access credentials and the binding relationship (i.e., the binding relationship between the access credentials and the device identifier). After successful verification, it accesses the cloud phone platform to perform a mapping query from the device identifier to the device IP address. The cloud phone platform returns the network address of the agent gateway, and the credential verification service then returns the network address to the access gateway. The access gateway caches the network address and forwards a WebSocket upgrade request to the security proxy service, which carries the access authorization token, device identifier, etc.
[0196] Phase 3: The proxy layer authenticates the access authorization token and connects to the upstream. The specific process is as follows: The security proxy service verifies the access authorization token, checks the binding relationship between the user identifier and the device identifier, and checks the proxy access permissions of the access authorization token. After these verifications and checks are successful, the security proxy service sends a WebSocket upgrade request to the intelligent agent gateway based on the gateway's network address. The intelligent agent gateway returns a message indicating that the protocol upgrade was successful to the security proxy service, and the security proxy service establishes a WebSocket connection with the intelligent agent gateway. Consequently, a WebSocket connection is also established between the intelligent agent gateway and the intelligent agent client.
[0197] Phase 4: Agent Gateway Protocol Handshake. The specific process is as follows: The agent gateway sends a connection control message to the security proxy service. The security proxy service then forwards this connection control message to the agent client. The agent client sends an authentication request to the agent gateway. After receiving the authentication request, the security proxy service forwards it to the agent gateway. The agent gateway verifies the agent client's identity and sends an authentication success message. The security proxy service then forwards this authentication success message to the agent client. This indicates that the agent client and the agent gateway can communicate according to the agreed communication protocol.
[0198] Phase 5: Byte-level bidirectional pass-through. The specific process is as follows: WebSocket frames (such as JSON text frames) sent by the agent client are passed through to the agent gateway byte-by-byte by the security proxy service, and WebSocket frames sent by the agent gateway are also passed through to the agent client byte-by-byte by the security proxy service.
[0199] The method in this application embodiment, during the connection establishment phase, involves the proxy layer actively executing security policies such as access credential verification, access authorization token authentication, device routing, and permission verification. During the transmission phase of the connection lifecycle, the proxy layer degenerates into a pure byte forwarder, without semantic understanding of the frame content. Thus, by moving the authentication responsibility to the connection establishment phase and downgrading data transmission to byte-level transparent transmission, security and zero maintenance cost are achieved.
[0200] The method in this application addresses a core problem: how a public network client (i.e., a public network user) can securely access the smart agent gateway within a cloud phone without exposing its ports to the outside world. The method in this application, without exposing the internal network where the cloud phone resides, can establish an independent secure channel (such as a WebSocket secure channel) for each cloud phone.
[0201] To implement the above embodiments, this application also proposes a device for an intelligent agent client to access an intelligent agent gateway on a cloud phone. Figure 7 This is a schematic diagram of a device for an intelligent agent client to access an intelligent agent gateway on a cloud phone, according to an embodiment of this application. This device can be configured on a control gateway.
[0202] like Figure 7 As shown, the device 700 includes: The receiving module 710 is used to receive a credential verification request sent by the access gateway; wherein, the credential verification request is used to request the legality verification of the target user's access credentials to the target cloud phone in the first connection request sent by the smart agent client. The verification module 720 is used to verify the legitimacy of access credentials; The sending module 730 is used to obtain the network address of the smart agent gateway in the target cloud phone in response to the access credential passing the validity verification, and send the network address to the access gateway; The receiving module 710 is also used to receive a second connection request sent by the access gateway; wherein the second connection request is generated by the access gateway based on the network address; Module 740 is used to establish a communication connection with the agent gateway based on the second connection request; wherein the communication connection is used to control the gateway to transmit messages between the agent client and the agent gateway.
[0203] Optionally, the verification module 720 is used for: Verify the validity of access credentials; In response to the access credentials passing the timeliness verification, the binding relationship between the access credentials and the device identifier is verified.
[0204] Optionally, the verification module 720 is used for: In response to the verification of the binding relationship between the access credentials and the device identifier, the network address corresponding to the device identifier is obtained by querying the cloud phone platform based on the device identifier.
[0205] Optionally, the second connection request also includes an access authorization token, established by module 740, for: Authenticate the access authorization token; In response to the access authorization token being authenticated, a third connection request is sent to the agent gateway. Upon receiving a connection success message from the agent gateway, it is determined that a communication connection has been established between the control gateway and the agent gateway.
[0206] Optionally, the second connection request may also include the user identifier of the target user and the device identifier of the target cloud phone. The connection establishment module 740 is used for: Verify the validity of the access authorization token; In response to the access authorization token passing the validity verification, the binding relationship between the user identifier and the device identifier is verified; In response to the verification of the binding relationship between the user identifier and the device identifier, the proxy access permission of the access authorization token is verified.
[0207] Optionally, the sending module 730 is also used to send a first liveness detection message to the intelligent agent client every first preset time interval to detect the liveness of the intelligent agent client; The device may further include a first determining module, configured to determine that the intelligent agent client is alive in response to receiving a first survival response message sent by the intelligent agent client within a second preset time period; and to determine that the intelligent agent client is not alive in response to not receiving a first survival response message sent by the intelligent agent client within the second preset time period, and to execute a fault recovery strategy associated with the intelligent agent client not being alive.
[0208] Optionally, the sending module 730 is further configured to transmit a heartbeat detection message sent by the agent gateway every third preset time interval to the agent client; wherein the heartbeat detection message is used to detect whether the agent gateway is abnormal, and the detection of whether the agent gateway is abnormal includes: If the agent client receives a heartbeat detection message within the fourth preset time period, it is determined that the agent gateway is normal. If no heartbeat detection message is received within the fourth preset time period, it is determined that the agent gateway is abnormal.
[0209] Optionally, the sending module 730 is also used to send a second liveness detection message to the intelligent agent gateway every fifth preset time interval to detect the liveness of the intelligent agent gateway; The device may further include a second determining module, configured to determine that the intelligent agent gateway is alive in response to receiving a second liveness response message sent by the intelligent agent gateway within a sixth preset time period; and to determine that the intelligent agent gateway is not alive in response to not receiving a second liveness response message sent by the intelligent agent gateway within the sixth preset time period, and to execute a fault recovery strategy associated with the intelligent agent gateway not being alive.
[0210] Optionally, the transmitting module 730 is also used for: Transmit the connection control message sent by the agent gateway to the agent client; The authentication request generated by the agent client based on the connection control message is forwarded to the agent gateway; the authentication request is used to authenticate whether the agent client has the authority to establish a trusted business session with the agent gateway. The successful authentication response message returned by the agent gateway is forwarded to the agent client.
[0211] Optionally, the authentication request is generated in the following manner: The agent client generates an identity credential based on the random number and timestamp in the connection control message; the identity credential is used by the agent gateway to verify whether the agent client has the authority to establish a trusted business session with the agent gateway. Generate an authentication request based on the identity credentials.
[0212] It should be noted that the explanation of the aforementioned method embodiment for the intelligent agent client to access the intelligent agent gateway on the cloud phone also applies to the device for the intelligent agent client to access the intelligent agent gateway on the cloud phone in this embodiment, so it will not be repeated here.
[0213] In this embodiment, after receiving the first connection request forwarded by the access gateway, the access credentials of the target user to the target cloud phone carried in the request are validated for legitimacy. Once the access credentials pass the validation, the network address of the intelligent agent gateway in the target cloud phone is obtained and returned to the access gateway, thereby avoiding direct exposure of the internal network address. Subsequently, the second connection request generated based on the network address sent by the access gateway is received, and the control gateway establishes a communication connection with the intelligent agent gateway accordingly. Thus, the access to the intelligent agent gateway is improved through the security policy of validating the access credentials, enhancing the security of the intelligent agent client's access to the intelligent agent gateway. This not only ensures the access security of cloud phone resources but also isolates the direct interaction between the client and internal network services through the transparent transmission mechanism of the control gateway, further strengthening the internal network boundary protection and providing solid support for secure and reliable communication of intelligent agents in multi-tenant, high-concurrency scenarios.
[0214] To implement the above embodiments, this application also proposes another device for intelligent agent clients to access intelligent agent gateways on cloud phones. Figure 8 This is a schematic diagram of a device for an intelligent agent client to access an intelligent agent gateway on a cloud phone, according to another embodiment of this application. This device can be configured to access the gateway.
[0215] like Figure 8 As shown, the device 800 includes: The receiving module 810 is used to receive a first connection request sent by the intelligent agent client; wherein the first connection request includes the target user's access credentials to the target cloud phone; The sending module 820 is used to send a credential verification request to the control gateway; wherein, the credential verification request is used to request the validity verification of the access credentials; The generation module 830 is used to generate a second connection request in response to obtaining the network address of the smart agent gateway in the target cloud phone sent by the control gateway; wherein, the network address is obtained by the control gateway after the access credentials have been verified as valid. The sending module 820 is also used to send the second connection request to the control gateway, so that the control gateway can establish a communication connection with the intelligent agent gateway in the target cloud phone; wherein, the communication connection is used by the control gateway to transmit messages between the intelligent agent client and the intelligent agent gateway.
[0216] Optionally, the generation module 830 is used for: Obtain the access authorization token and the device identifier of the target cloud phone from the first connection request; A second connection request is generated based on the network address, access authorization token, and device identifier.
[0217] Optionally, the transmitting module 820 is used for: A security policy is executed on the first connection request; wherein the security policy includes at least one of the following: Transport Layer Security (TLS) termination, Web Application Firewall (WAF) inspection, and IP-based rate limiting; After completing the security policy processing, a credential verification request is sent to the control gateway.
[0218] Optionally, access credentials are obtained in the following manner: The intelligent agent client obtains access credentials by calling the credential issuance service based on the application programming interface (API) key and the target user's authentication information; the credential issuance service includes: Based on the API key, determine whether the agent client is legitimate; In response to the legitimacy of the intelligent agent client, the target information in the authentication information is verified; In response to the target information passing verification, the gateway domain name associated with the target cloud phone is obtained by querying the cloud phone platform based on the target cloud phone's usage identifier in the authentication information. Access credentials are generated based on random numbers, and the access credentials and gateway domain name are returned.
[0219] It should be noted that the explanation of the aforementioned method embodiment for the intelligent agent client to access the intelligent agent gateway on the cloud phone also applies to the device for the intelligent agent client to access the intelligent agent gateway on the cloud phone in this embodiment, so it will not be repeated here.
[0220] In this embodiment, after receiving the first connection request from the intelligent agent client carrying access credentials, the access credentials are submitted to the control gateway for validity verification. Only when the access credentials are successfully verified and the real network address of the intelligent agent gateway in the target cloud phone is obtained, a second connection request is generated, and the control gateway actively establishes a communication connection with the intelligent agent gateway. This channel is subsequently used for bidirectional transparent transmission of all messages between the client and the intelligent agent gateway, avoiding direct exposure of the cloud phone's internal service address and achieving separation of access authentication and data transmission. Therefore, accessing the intelligent agent gateway through a security policy that verifies the validity of access credentials improves the security of intelligent agent client access to the intelligent agent gateway. This not only ensures the security of cloud phone resource access but also isolates direct interaction between the client and internal network services through the control gateway's transparent transmission mechanism, further strengthening internal network boundary protection and providing solid support for secure and reliable communication of intelligent agents in multi-tenant, high-concurrency scenarios.
[0221] According to embodiments of this application, this application also provides an electronic device, a readable storage medium, and a computer program product.
[0222] Figure 9 A schematic block diagram of an example electronic device 900 that can be used to implement embodiments of this application is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.
[0223] like Figure 9 As shown, device 900 includes a computing unit 901, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 902 or a computer program loaded from storage unit 908 into RAM (Random Access Memory) 903. RAM 903 can also store various programs and data required for the operation of device 900. The computing unit 901, ROM 902, and RAM 903 are interconnected via bus 904. I / O (Input / Output) interface 905 is also connected to bus 904.
[0224] Multiple components in device 900 are connected to I / O interface 905, including: input unit 906, such as keyboard, mouse, etc.; output unit 907, such as various types of monitors, speakers, etc.; storage unit 908, such as disk, optical disk, etc.; and communication unit 909, such as network card, modem, wireless transceiver, etc. Communication unit 909 allows device 900 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0225] The computing unit 901 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 901 performs the various methods and processes described above, such as the method of an intelligent agent client accessing an intelligent agent gateway on a cloud phone. For example, in some embodiments, the method of an intelligent agent client accessing an intelligent agent gateway on a cloud phone can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 908. In some embodiments, part or all of the computer program can be loaded and / or installed on device 900 via ROM 902 and / or communication unit 909. When the computer program is loaded into RAM 903 and executed by computing unit 901, one or more steps of the method for an intelligent agent client to access an intelligent agent gateway on a cloud phone, as described above, can be performed. Alternatively, in other embodiments, computing unit 901 can be configured to perform the method for an intelligent agent client to access an intelligent agent gateway on a cloud phone by any other suitable means (e.g., by means of firmware).
[0226] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0227] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0228] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0229] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0230] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0231] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is established by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0232] According to an embodiment of this application, this application also provides a computer program product, which, when executed by an instruction processor, performs the method for a smart agent client to access a smart agent gateway on a cloud phone as proposed in the above embodiments of this application.
[0233] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this application can be achieved, and this is not limited herein.
[0234] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for a smart agent client to access a smart agent gateway on a cloud phone, comprising: Receive a credential verification request sent by the access gateway; wherein, the credential verification request is used to request the legality verification of the target user's access credentials to the target cloud phone in the first connection request sent by the smart agent client; The access credentials are validated for validity. In response to the access credentials being verified as valid, the network address of the smart agent gateway in the target cloud phone is obtained, and the network address is sent to the access gateway. Receive a second connection request sent by the access gateway; wherein the second connection request is generated by the access gateway based on the network address; Based on the second connection request, a communication connection is established with the agent gateway; wherein, the communication connection is used to control the gateway to transparently transmit messages between the agent client and the agent gateway.
2. The method as described in claim 1, wherein, The credential verification request also includes the device identifier of the target cloud phone, and verifies the legitimacy of the access credential, including: The validity period of the access credentials is verified. In response to the access credential passing the timeliness verification, the binding relationship between the access credential and the device identifier is verified.
3. The method as described in claim 2, wherein, The step of obtaining the network address of the smart agent gateway in the target cloud phone in response to the access credential passing legality verification includes: In response to the verification of the binding relationship between the access credential and the device identifier, the network address corresponding to the device identifier is obtained by querying the cloud mobile phone platform based on the device identifier.
4. The method as described in claim 1, wherein, The second connection request also includes an access authorization token. Establishing a communication connection with the agent client based on the second connection request includes: Authenticate the access authorization token; In response to the access authorization token being authenticated, a third connection request is sent to the smart agent gateway; Upon receiving a connection success message from the agent gateway, it is determined that a communication connection has been established between the control gateway and the agent gateway.
5. The method as described in claim 4, wherein, The second connection request also includes the user identifier of the target user and the device identifier of the target cloud phone. The authentication of the access authorization token includes: The validity of the access authorization token is verified; In response to the access authorization token passing the validity verification, the binding relationship between the user identifier and the device identifier is verified; In response to the verification of the binding relationship between the user identifier and the device identifier, the proxy access permission of the access authorization token is verified.
6. The method according to any one of claims 1-5, further comprising: Every first preset time interval, a first liveness detection message is sent to the intelligent agent client to detect the liveness of the intelligent agent client; Upon receiving a first survival response message from the agent client within a second preset time period, it is determined that the agent client is alive. If no first survival response message is received from the agent client within the second preset time period, it is determined that the agent client is not alive, and the fault recovery strategy associated with the agent client's failure to survive is executed.
7. The method according to any one of claims 1-5, further comprising: The heartbeat detection message sent by the intelligent agent gateway every third preset time interval is transparently transmitted to the intelligent agent client; wherein, the heartbeat detection message is used to detect whether the intelligent agent gateway is abnormal, and the detection of whether the intelligent agent gateway is abnormal includes: In response to the intelligent agent client receiving the heartbeat detection message within a fourth preset time period, it is determined that the intelligent agent gateway is normal; If the heartbeat detection message is not received within the fourth preset time period, it is determined that the intelligent agent gateway is abnormal.
8. The method according to any one of claims 1-5, further comprising: Every fifth preset time interval, a second liveness detection message is sent to the intelligent agent gateway to detect the liveness of the intelligent agent gateway; In response to receiving a second liveness response message sent by the agent gateway within a sixth preset time period, it is determined that the agent gateway is alive; If no second liveness response message is received from the agent gateway within the sixth preset time period, it is determined that the agent gateway is not alive, and the fault recovery strategy associated with the agent gateway not being alive is executed.
9. The method according to any one of claims 1-5, the method further comprising: The connection control message sent by the agent gateway is transparently transmitted to the agent client; The authentication request generated by the intelligent agent client based on the connection control message is transparently transmitted to the intelligent agent gateway; wherein, the authentication request is used to request authentication of whether the intelligent agent client has the authority to establish a trusted business session with the intelligent agent gateway; The successful authentication response message returned by the agent gateway is forwarded to the agent client.
10. The method of claim 9, wherein, The authentication request is generated in the following manner: The intelligent agent client generates an identity credential based on the random number and timestamp in the connection control message; wherein, the identity credential is used by the intelligent agent gateway to verify whether the intelligent agent client has the authority to establish a trusted business session with the intelligent agent gateway; The identity authentication request is generated based on the identity credentials.
11. A method for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: Receive a first connection request sent by the intelligent agent client; wherein the first connection request includes the target user's access credentials to the target cloud phone; Send a credential verification request to the control gateway; wherein the credential verification request is used to request the validity verification of the access credential; In response to obtaining the network address of the smart agent gateway in the target cloud phone sent by the control gateway, a second connection request is generated based on the network address; wherein, the network address is obtained by the control gateway after the access credentials pass the validity verification. The second connection request is sent to the control gateway, which then establishes a communication connection with the agent gateway; wherein the communication connection is used by the control gateway to transmit messages between the agent client and the agent gateway.
12. The method of claim 11, wherein, The step of generating a second connection request based on the network address includes: Obtain the access authorization token and the device identifier of the target cloud phone from the first connection request; The second connection request is generated based on the network address, the access authorization token, and the device identifier.
13. The method of claim 11, wherein, Sending the credential verification request to the control gateway includes: A security policy is executed on the first connection request; wherein the security policy includes at least one of the following: Transport Layer Security (TLS) termination, Web Application Firewall (WAF) inspection, and IP-based rate limiting; After completing the security policy processing, the credential verification request is sent to the control gateway.
14. The method according to any one of claims 11-13, wherein, The access credentials were obtained in the following manner: The intelligent agent client obtains the access credential by invoking a credential issuance service based on the application programming interface (API) key and the authentication information of the target user; wherein, the credential issuance service includes: Based on the API key, determine whether the agent client is legitimate; In response to the validity of the intelligent agent client, the target information in the authentication information is verified; In response to the target information passing verification, based on the usage identifier of the target cloud phone in the authentication information, the gateway domain name associated with the target cloud phone is obtained by querying the cloud phone platform; The access credential is generated based on a random number, and the access credential and gateway domain name are returned.
15. A device for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: The receiving module is used to receive a credential verification request sent by the access gateway; wherein the credential verification request is used to request the legality verification of the target user's access credentials to the target cloud phone in the first connection request sent by the smart agent client. The verification module is used to verify the legitimacy of the access credentials; The sending module is used to obtain the network address of the smart agent gateway in the target cloud phone in response to the access credential passing the legality verification, and send the network address to the access gateway; The receiving module is further configured to receive a second connection request sent by the access gateway; wherein the second connection request is generated by the access gateway based on the network address; A connection establishment module is configured to establish a communication connection with the agent gateway based on the second connection request; wherein the communication connection is used to control the gateway to transparently transmit messages between the agent client and the agent gateway.
16. A device for an intelligent agent client to access an intelligent agent gateway on a cloud phone, comprising: A receiving module is used to receive a first connection request sent by a smart agent client; wherein the first connection request includes the target user's access credentials to the target cloud phone; The sending module is used to send a credential verification request to the control gateway; wherein the credential verification request is used to request the validity verification of the access credential; A generation module is configured to, in response to obtaining the network address of the intelligent agent gateway in the target cloud phone sent by the control gateway, generate a second connection request based on the network address; wherein, the network address is obtained by the control gateway after the access credentials pass the validity verification; The sending module is further configured to send the second connection request to the control gateway, so that the control gateway can establish a communication connection with the agent gateway; wherein the communication connection is used by the control gateway to transmit messages between the agent client and the agent gateway.
17. An electronic device comprising: At least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-14.
18. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-14.
19. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1-14.