Terminal identification method, apparatus and system
Through the clustering method of the terminal's open port information and MAC/IP address, the problem of low terminal recognition rate in the existing technology is solved, and efficient recognition is achieved in various terminal environments.
Patent Information
- Application Number
- PCT/CN2025/080156
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-28
- Filing Date
- 2025-03-03
- Publication Date
- 2025-09-25
AI Technical Summary
Existing terminal recognition methods cannot effectively identify various terminals with blurred boundaries, resulting in a low recognition rate.
By obtaining the open port information of the terminal for clustering, the similarity of the open port information of the terminal is used for clustering, and the terminal type is identified by combining the MAC address and IP address.
It improves the accuracy and efficiency of terminal recognition and can ensure the recognition rate in scenarios where various types of terminals emerge in an endless stream.
Smart Images

Figure CN2025080156_25092025_PF_FP_ABST
Abstract
Description
Terminal identification method, device and system
[0001] This application claims priority to Chinese patent application number 202410332525.9, filed with the Patent Office of China on March 21, 2024, entitled “A Terminal Identification Method and Device,” the entire contents of which are incorporated herein by reference.
[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on March 28, 2024, with application number 202410374530.6 and invention name “A terminal identification method, device and system”, the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of terminal technology, and in particular to a method, device, and system for identifying a terminal. Background Art
[0004] With the development of technologies such as automation, intelligence, and the Internet of Things, a wide variety of terminals have emerged to provide users with relevant services. For example, in government affairs, the emergence of terminals such as government kiosks, queue checkers, evaluators, and information screens facilitates users in handling government affairs. Similarly, in education, the emergence of terminals such as electronic class signs, multimedia teaching devices, and facial recognition devices facilitates work in the education sector.
[0005] In networks, it's often necessary to identify terminals accessing the network to facilitate functions such as asset management, secure access, and network optimization. Terminal identification methods include: Method 1, which identifies the terminal based on a match between its fingerprint and fingerprint information in a fingerprint database; and Method 2, which identifies the terminal based on its traffic characteristics. However, as the boundaries between terminals become increasingly blurred, current terminal identification methods are unable to effectively identify the ever-increasing variety of terminals, resulting in low terminal recognition rates. Summary of the Invention
[0006] Based on this, the present application provides a terminal identification method, device and system, which can ensure effective identification of terminals even when facing terminals with blurred boundaries in the network and a variety of terminals in the network, and can improve the recognition rate of terminals to a certain extent.
[0007] In a first aspect, the present application provides a terminal identification method, wherein an identification device obtains open port information of multiple terminals and clusters the multiple terminals based on the open port information of each terminal, thereby identifying at least one cluster to which the multiple terminals belong based on the clustering results. The open port information of each terminal indicates at least one open port of each terminal, and the terminals included in each of the at least one cluster are of the same type. Thus, considering that terminals generally require specific ports to be opened to connect to the server corresponding to the terminal, and different types of terminals require different specific ports to be opened, the method clusters the terminals to be identified based on the open port information of the terminals to be identified. In the clustering results, the open port information of the terminals belonging to the same cluster is similar, and the terminals belonging to the same cluster are likely to be of the same type, thereby achieving effective and accurate identification of the terminals. In scenarios where various types of terminals emerge in an endless stream, the terminal identification rate can be guaranteed, overcoming the problem that current terminal identification methods require the accumulation of terminal fingerprint information or the service traffic (or service messages) after the terminal joins the network, which cannot guarantee the terminal identification rate.
[0008] In some possible implementations, if there is at least one cluster of a known type in the network, then the "multiple terminals" in the method may refer to terminals that are newly connected to the network during the time interval from the last identification of the terminals in the network to the current execution of the method. The identification device clusters the multiple terminals based on the open port information of the multiple terminals, which may include: the identification device determines the cluster of the known type to which each terminal in the multiple terminals belongs based on the similarity between the open port information of the multiple terminals and the open port information of each cluster of the known type. In this way, by comparing the similarity between the open port information of the terminal to be identified and the open port information of the cluster of the known type, the terminal to be identified is classified into a reasonable cluster of the known type, thereby determining the type of the terminal to be identified belonging to the cluster of the known type through the type of the cluster of the known type, thereby completing the clustering and identification of the terminal to be identified.
[0009] In some possible implementations, if no clusters of known types exist in the network, for example, if this method is being executed for the first time to identify terminals in the network, then the identification device clustering the multiple terminals based on their open port information may include: the identification device clustering the multiple terminals based on the similarity of their open port information. Thus, by comparing the similarity of the open port information between the terminals to be identified, the terminals with similar open port information are clustered into a single cluster. The type of each cluster is then used to determine the type of the terminals to be identified belonging to that cluster, thereby completing the clustering and identification of the terminals to be identified.
[0010] In some possible implementations, to further improve the reliability of terminal identification, the terminal type may be identified based on the terminal's open port information in combination with other terminal information. Taking into account the characteristics of how the network assigns addresses to terminals and how users assign addresses to their own terminals, other terminal information may include, but is not limited to, the terminal's Media Access Control (MAC) address and / or the terminal's Internet Protocol (IP) address.
[0011] As an example, the identification device can identify the types of multiple terminals based on the MAC addresses of the multiple terminals and the open port information of the multiple terminals. In this example, the method may also include: the identification device obtains the MAC address of each terminal in the multiple terminals, then the identification device clustering the multiple terminals may include: the identification device clustering the multiple terminals based on the open port information of each terminal and the MAC address of each terminal. In specific implementation, the identification device can first determine the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the MAC address between each terminal; then, the identification device clusters the multiple terminals based on the comprehensive similarity between the terminals. In this way, based on the MAC address of the terminal and the open port information of the terminal, the type of the terminal can be accurately identified through clustering.
[0012] As another example, the identification device can identify the types of multiple terminals based on the IP addresses of the multiple terminals and the open port information of the multiple terminals. In this example, the method can also include: the identification device obtains the IP address of each of the multiple terminals. Then, the identification device clustering the multiple terminals can include: the identification device clustering the multiple terminals based on the open port information of each terminal and the IP address of each terminal. In specific implementation, the identification device can first determine the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the IP addresses between each terminal; then, the identification device clusters the multiple terminals based on the comprehensive similarity between the terminals. In this way, based on the IP address and the open port information of the terminal, the terminal type can be accurately identified through clustering.
[0013] As another example, the identification device can identify the types of multiple terminals based on the MAC addresses of multiple terminals, the IP addresses of multiple terminals, and the open port information of multiple terminals. In this example, the method can also include: the identification device obtains the MAC address and IP address of each terminal in the multiple terminals. Then, the identification device clustering the multiple terminals can include: the identification device clustering the multiple terminals based on the open port information of each terminal, the MAC address of each terminal, and the IP address of each terminal. In specific implementation, the identification device can first determine the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal, the similarity of the MAC addresses between each terminal, and the similarity of the IP addresses between each terminal; then, the identification device clusters the multiple terminals based on the comprehensive similarity between the terminals. In this way, based on the MAC address of the terminal, the IP address of the terminal, and the open port information of the terminal, the type of the terminal can be accurately identified through clustering.
[0014] In some possible implementations, if the identification device and the port scanning device belong to different devices, then the identification device obtaining the open port information of multiple terminals may include: the identification device receiving the open port information of the multiple terminals sent by the port scanning device. In a specific implementation, the port scanning device performs port scanning on the multiple terminals, obtains the open port information of the multiple terminals, and then the device where the port scanning device resides sends the open port information of the multiple terminals to the device where the identification device resides, providing a data foundation for the identification device to implement the method provided in this application to achieve identification of the multiple terminals.
[0015] In other possible implementations, if the identification device and the port scanning device belong to the same device, then the identification device obtains the open port information of multiple terminals, which may include: the device where the identification device is located performs port scanning on each of the multiple terminals to obtain the open port information of each of the multiple terminals. In specific implementation, inside the device where the identification device and the port scanning device are located, the port scanning device first performs port scanning on the multiple terminals to obtain the open port information of the multiple terminals, and then the port scanning device synchronizes the obtained open port information of the multiple terminals to the identification device, providing a data basis for the identification device to implement the method provided in this application to realize the identification of multiple terminals.
[0016] The open port information of each terminal among the multiple terminals may refer to the open port information obtained by a port scanning device through a port scanning of all or some of the designated ports of the terminal. The designated ports may be commonly used ports to be detected (e.g., the top 100 most commonly used ports in a commonly used port list), or may be special ports to be detected (e.g., ports with designated port numbers based on actual application scenario requirements). Therefore, when the port scanning device performs a port scan on the terminal, the port scanning device needs to send port detection messages corresponding to each designated port to the terminal, and the number of port detection messages sent is the same as the number of designated ports of the terminal.
[0017] Wherein, the multiple terminals may be all terminals in the network, and the identification device obtaining the open port information of all terminals in the network may include: the identification device performing a port scan on all terminals in the network to obtain the open port information of the multiple terminals. Alternatively, the multiple terminals may be terminals in a target network segment in the network, and the identification device obtaining the open port information of all terminals in the target network segment in the network may include: the identification device performing a port scan on terminals in the target network segment to obtain the open port information of the multiple terminals. Alternatively, the terminals may be terminals in a target virtual local area network (VLAN) in the network, and the identification device obtaining the open port information of all terminals in the target VLAN in the network may include: the identification device performing a port scan on terminals in the target VLAN to obtain the open port information of the multiple terminals. Alternatively, the multiple terminals may be terminals in a target broadcast domain (Bridge Domain, BD) in the network, and the identification device obtaining the open port information of all terminals in the target BD in the network may include: the identification device performing a port scan on terminals in the target BD to obtain the open port information of the multiple terminals. It can be seen that the range of terminals to be identified in this application can be flexibly designed based on actual needs.
[0018] In some possible implementations, the identification device identifies at least one cluster to which multiple terminals belong based on the clustering results, which may include: the identification device determines the type of each cluster in the at least one cluster, and the type of each cluster is the type of the terminal belonging to the cluster. Therefore, determining the type of each cluster is equivalent to determining the types of multiple terminals, thereby realizing effective identification of the terminals.
[0019] As an example, the identification device determines the type of each cluster in at least one cluster, which may include: automatically identifying the types of some clusters, and displaying the type of one or more clusters whose specific types cannot be identified as unknown types; and manually marking the specific types of the one or more clusters. In this way, through the method of automatic identification + manual marking, the type of each cluster can be determined to ensure the recognition rate of the terminal. Among them, the identification device's marking of the specific type of the unknown type cluster may, for example, include: for any first cluster in the unknown type cluster, identifying the type of one or more terminals in the first cluster, and marking the type as the type of the first cluster. In this way, after automatic identification, the type of the cluster is marked by the identification results of a small number of terminal types in each cluster of the unknown type, thereby achieving efficient marking of the cluster and achieving efficient terminal identification.
[0020] As another example, the identification device determining the type of each cluster in at least one cluster may include automatically identifying the types of all clusters. For example, for any second cluster in at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes a first target port, the identification device determines that the type of the second cluster is the first type corresponding to the first target port. For another example, for any second cluster in at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, the identification device determines that the type of the second cluster is the first type. In this way, for each cluster in the at least one determined cluster, the identification device can automatically identify the type of the cluster, thereby realizing intelligent identification of the terminals.
[0021] As another example, in the step of determining the type of each cluster in at least one cluster, the recognition device may, after automatically identifying the type of the cluster, identify the type of the cluster as a candidate type, prompt and wait for the user to confirm or edit the candidate type to finally determine the type of the cluster. This example can be considered an automatic recognition + manual confirmation method. In this example, the recognition device determining the type of each cluster in at least one cluster may include: for any second cluster in the at least one cluster, determining the type of the second cluster as a first type based on automatic recognition; then, in response to an edit operation or a confirmation operation on the first type of the second cluster, determining the type of the second cluster as a second type. If the user confirms the first type of the second cluster, the second type is the same as the first type. If the user finds that the automatic recognition result (i.e., the first type) is inaccurate, the user may identify the type of the second cluster using any other method, determine the second cluster as the second type, and then perform an edit operation on the first type of the second cluster to change the type of the second cluster from the first type to the second type. In this case, the second type is different from the first type. In this way, the automatic recognition + manual confirmation method can improve the accuracy of terminal recognition while ensuring recognition efficiency.
[0022] In some possible implementations, to further improve the accuracy of terminal identification results, the method may further include: the identification device correcting the clustering results. As an example, when the terminal type is inconsistent with the type of the cluster to which the terminal belongs, the identification device changes the cluster to which the terminal belongs based on the terminal type. In this way, by correcting the clustering results, higher-precision terminal identification can be achieved.
[0023] In some possible implementations, the method may further include: the identification device performing network admission control on the terminal based on the type of the terminal. Alternatively, the method may further include: the identification device sending configuration information to the terminal of that type based on the type of the terminal.
[0024] In some possible implementations, the method may be applied to a network controller, and the identification device may be a functional module of the network controller that is used to implement the method provided in this application. For example, the network controller may be a Network Admission Controller (NAC), and the identification device may be a functional module of the NAC that is used to implement the method provided in this application.
[0025] In a second aspect, the present application also provides a terminal identification method, which is applied to a terminal to be identified. The method may, for example, include: the terminal to be identified receiving a port detection message for a target port of the terminal to be identified; if the target port is open, the terminal to be identified sending a response message to the port detection message for the target port, the response message being used to guide the identification of the type of the terminal to be identified. Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes the target port, and the open port information is used to identify the type of the terminal to be identified. Thus, considering that a terminal generally requires opening a specific port to connect to a server corresponding to the terminal, and different types of terminals require different specific ports to be opened, the method performs a port scan on the terminal to be identified to obtain the open port information of the terminal to be identified, thereby using this information as a basis for identifying the type of the terminal to be identified. In scenarios where various types of terminals emerge in an endless stream, the terminal identification rate can be guaranteed, overcoming the problem that current terminal identification methods require the accumulation of terminal fingerprint information or the service traffic (or service messages) after the terminal joins the network, which cannot guarantee the terminal identification rate.
[0026] It should be noted that for the relevant description of the method of the second aspect, please refer to the corresponding description of the first aspect.
[0027] In a third aspect, the present application also provides a terminal identification device, which can be used in an identification device. The device may include: an acquisition unit and a processing unit. The acquisition unit is configured to acquire open port information for multiple terminals, where the open port information for each terminal indicates at least one open port of each terminal; the processing unit is configured to cluster the multiple terminals based on the open port information for each terminal; and the processing unit is further configured to identify, based on the clustering results, at least one cluster to which the multiple terminals belong, where the terminals included in each cluster are of the same type.
[0028] In some possible implementations, the acquisition unit of the device is further configured to acquire the MAC address of each terminal; and the processing unit is specifically configured to cluster the multiple terminals according to the open port information of each terminal and the MAC address of each terminal.
[0029] In some possible implementations, the acquisition unit of the device is further configured to acquire the IP address of each terminal; and the processing unit is specifically configured to cluster the multiple terminals according to the open port information of each terminal and the IP address of each terminal.
[0030] In some possible implementations, the acquiring unit is specifically configured to receive open port information of multiple terminals sent by a port scanning device.
[0031] In some possible implementations, the acquiring unit is specifically configured to acquire open port information of multiple terminals by performing port scanning on all ports or some designated ports of each terminal.
[0032] In some possible implementations, the acquiring unit specifically performs any one of the following steps:
[0033] Scan ports of all terminals in the network to obtain information about open ports of multiple terminals.
[0034] Alternatively, by performing port scanning on terminals in the target network segment, information on open ports of multiple terminals can be obtained;
[0035] Alternatively, the open port information of multiple terminals can be obtained by performing port scanning on the terminals in the target VLAN;
[0036] Alternatively, the open port information of multiple terminals is obtained by performing port scanning on the terminals in the target BD.
[0037] In some possible implementations, the processing unit is specifically configured to: cluster the multiple terminals according to similarities in the open port information of the multiple terminals.
[0038] In some possible implementations, the processing unit is specifically configured to determine the cluster of the known type to which each of the multiple terminals belongs based on similarities between the open port information of the multiple terminals and the open port information of each cluster of the known type.
[0039] In some possible implementations, the processing unit is specifically configured to: determine a type of each cluster in the at least one cluster.
[0040] As an example, the processing unit is specifically configured to: for one or more clusters whose specific types cannot be identified, display the type of one or more clusters as unknown; and manually mark the specific type of one or more clusters. The processing unit is also configured to mark the specific type of clusters of unknown types. The processing unit is specifically configured to: for any first cluster of the unknown type clusters, identify the type of one or more terminals in the first cluster and mark the type as the type of the first cluster.
[0041] As another example, the processing unit is specifically configured to: for any second cluster in the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes the first target port, determine the type of the second cluster to be the first type corresponding to the first target port.
[0042] As another example, the processing unit is specifically configured to: for any second cluster in the at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, determine that the type of the second cluster is the first type.
[0043] For the second cluster, the processing unit is further configured to, in response to an edit operation or a confirmation operation of the first type on the second cluster, determine that the type of the second cluster is a second type, which is the same as or different from the first type.
[0044] In some possible implementations, the processing unit of the device is further configured to correct the clustering result.
[0045] As an example, the processing unit is specifically configured to: when the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, change the cluster to which the terminal belongs according to the type of the terminal.
[0046] In some possible implementations, the processing unit of the device is further configured to perform network admission control on the terminal based on the type of the terminal.
[0047] In some possible implementations, the processing unit of the device is further configured to send configuration information to a terminal of the type based on the type of the terminal.
[0048] In some possible implementations, the device is applied to a network controller, that is, the device may be the network controller itself, or may be a functional module belonging to the network controller for implementing the method provided in this application. The network controller may be, for example, a NAC.
[0049] It should be noted that for the relevant description of the device of the third aspect, please refer to the corresponding description of the first aspect.
[0050] In a fourth aspect, the present application also provides a terminal identification device, which is applied to a terminal to be identified. The device may include: a receiving unit and a sending unit. The receiving unit is configured to receive a port detection message for a target port of the terminal to be identified; and the sending unit is configured to send a response message to the port detection message for the target port if the target port is open, wherein the response message is used to guide the identification of the type of the terminal to be identified. Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes the target port, and the open port information is used to identify the type of the terminal to be identified.
[0051] It should be noted that for the relevant description of the device of the fourth aspect, please refer to the corresponding description of the second aspect.
[0052] In a fifth aspect, the present application provides a communication device, the communication device comprising a communication interface and a processor;
[0053] A communication interface for executing the method provided by the first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect;
[0054] A processor is used to execute the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0055] In a sixth aspect, the present application further provides a communication device, the communication device comprising a memory and a processor;
[0056] a memory for storing instructions;
[0057] A processor is used to execute the instructions in the memory and execute the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0058] In a seventh aspect, the present application further provides a communication system, the communication system comprising a terminal identification device and a terminal to be identified;
[0059] A terminal identification device, configured to execute the first aspect or any possible implementation of the first aspect to identify the terminal to be identified;
[0060] The terminal to be identified is used to execute the method provided by the aforementioned second aspect or any possible implementation of the second aspect.
[0061] In the eighth aspect, the present application also provides a storage medium, which includes instructions. When the instructions are run on a processor, the processor executes the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0062] In the ninth aspect, the present application also provides a program product, which includes a program. When the program runs on a processor, it executes the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0063] In the tenth aspect, the present application provides a chip comprising a memory and a processor, the memory being used to store instructions, and the processor being used to call and execute the instructions from the memory to implement the method provided by the aforementioned first aspect, any possible implementation of the first aspect, the second aspect, and any possible implementation of the second aspect.
[0064] In an eleventh aspect, the present application provides a terminal identification method, which can be applied to a communication system, wherein the communication system may include a first communication entity, a second communication entity, and a third communication entity. The method may, for example, include: the first communication entity in the communication system provides a web page to the terminal; the second communication entity in the communication system calls the terminal's browser interface through the web page to obtain the terminal's capability information; and the third communication entity in the communication system identifies the terminal's type based on the terminal's capability information. In this way, in the communication system, the terminal's browser interface can be called through the web page provided by the web server to obtain the terminal's capability information, and the specific type of the terminal can be accurately identified based on the terminal's capability information. This overcomes the problem in current terminal identification methods that cannot accurately identify the terminal's type based on the terminal's fingerprint information (such as the Hypertext Transfer Protocol User Agent (HTTP UA)). In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0065] As an example, if the communication system is a Web server, that is, the method is applied to the Web server, then the first communication entity, the second communication entity and the third communication entity can be understood as group modules, components or chips within the Web server, the first communication entity and the second communication entity can be understood as components that implement the functions of the Web server, and the third communication entity can be understood as a component that implements the functions of the terminal identification device.
[0066] As another example, if the communication system includes three independent devices: a Web server, a communication device where the terminal identification device is located, and a terminal, then the first communication entity can be understood as implementing the Web server, the second communication entity can be understood as the terminal, and the third communication entity can be understood as the communication device where the terminal identification device is located.
[0067] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or Universal Serial Bus (USB) capability.
[0068] In one possible implementation, a web page may include a script whose content may at least include: calling a browser interface to obtain terminal capability information. In this way, the terminal can obtain the terminal capability information by executing the web page script, providing a basis for accurate terminal identification.
[0069] In one possible implementation, the script included in the web page may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. In this way, the terminal can proactively transmit the terminal's capability information to the terminal identification device by executing the script on the web page. This allows the terminal identification device to obtain the terminal's capability information, which serves as the basis for accurate terminal identification, enabling the terminal identification device to accurately identify the terminal.
[0070] As an example, the terminal identification device may be deployed in a Web server, and the above-mentioned network interface may be a network interface opened by the Web server to the terminal.
[0071] As another example, the terminal identification device may not be deployed in the Web server. In this case, the network interface may be a network interface opened to the terminal by the communication device where the terminal identification device is located.
[0072] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the third communication entity in the communication system identifies the type of the terminal based on the capability information of the terminal, which may include: the third communication entity in the communication system identifies the type of the terminal based on the capability information of the terminal and the fingerprint information of the terminal. The fingerprint information of the terminal includes at least one of the following: a Medium Access Control Organizationally Unique Identifier (MAC OUI), a Dynamic Host Configuration Protocol Option (DHCP Option), an HTTP UA, a Multicast Domain Name Service (mDNS), a Link Layer Discovery Protocol (LLDP), a MAC address, or an Internet Protocol (IP) address. In this way, the specific type of the terminal can be more accurately identified through the capability information of the terminal and the fingerprint information of the terminal, and even if the boundary of the terminal is relatively vague, refined identification of the terminal can be achieved.
[0073] In a twelfth aspect, the present application also provides a terminal identification method, which is applied to a terminal. For example, the method may include: the terminal receiving a web page sent by a web server; the terminal executing a script on the web page, the content of which may at least include: calling a browser interface to obtain terminal capability information; and the terminal sending the terminal capability information to a terminal identification device. In this way, the terminal obtains the terminal capability information based on the script added to the web page downloaded from the web server and provides the terminal capability information to the terminal identification device, making it possible for the terminal identification device to accurately identify the specific type of the terminal based on the terminal capability information. This overcomes the problem in current terminal identification methods that the terminal fingerprint information cannot accurately identify the terminal type. In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0074] In one possible implementation, the content of the script may further include: calling a network interface to send the terminal capability information to the terminal identification device; then, the terminal sending the terminal capability information to the terminal identification device may include: the terminal sending the terminal capability information to the terminal identification device through the network interface.
[0075] As an example, the terminal identification device may be deployed in a Web server, and the above-mentioned network interface may be a network interface opened by the Web server to the terminal.
[0076] As another example, the terminal identification device may not be deployed in the Web server. In this case, the network interface may be a network interface opened to the terminal by the communication device where the terminal identification device is located.
[0077] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0078] In one possible implementation, to further improve the reliability and accuracy of terminal identification, the terminal may also obtain and transmit its fingerprint information to the terminal identification device. This fingerprint information may include at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address. This allows for more accurate identification of the terminal's specific type, even when the terminal's boundaries are vague, by combining the terminal's capability information and fingerprint information.
[0079] Thirteenthly, the present application also provides a terminal identification method, which is applied to a terminal identification device. For example, the method may include: the terminal identification device receiving capability information of the terminal, and identifying the terminal type based on the capability information. In this way, the terminal identification device can obtain the capability information of the terminal and accurately identify the specific terminal type based on the capability information. This overcomes the inability of current terminal identification methods to accurately identify the terminal type based on the terminal's fingerprint information. This method can improve the accuracy of terminal identification in scenarios where various types of terminals are constantly emerging and the boundaries between terminals are relatively vague.
[0080] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The script in the web page may include invoking a browser interface of the terminal to obtain the terminal's capability information. Optionally, the script in the web page may also include invoking a network interface to transmit the terminal's capability information to a terminal identification device. In this way, the terminal obtains the terminal's capability information based on the script added to the web page downloaded from the web server and provides the terminal identification device with the capability information. The terminal identification device can then accurately identify the terminal's specific type based on the capability information, thereby improving the accuracy of terminal identification.
[0081] As an example, the terminal identification device may be deployed in a Web server, and the above-mentioned network interface may be a network interface opened by the Web server to the terminal.
[0082] As another example, the terminal identification device may not be deployed in the Web server. In this case, the network interface may be a network interface opened to the terminal by the communication device where the terminal identification device is located.
[0083] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0084] In one possible implementation, to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the terminal type based on the terminal's capability information. This may include: the terminal identification device identifies the terminal type based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address. In this way, the terminal identification device can more accurately identify the specific terminal type based on the terminal's capability information and fingerprint information, enabling refined terminal identification even when the terminal's boundaries are relatively vague.
[0085] In a fourteenth aspect, the present application further provides a communication system comprising a first communication entity, a second communication entity, and a third communication entity. The first communication entity is configured to provide a web page to a terminal; the second communication entity is configured to invoke a browser interface of the terminal via the web page to obtain capability information of the terminal; and the third communication entity is configured to identify the type of the terminal based on the capability information of the terminal.
[0086] As an example, the communication system is a Web server, and the first communication entity, the second communication entity, and the third communication entity are components in the Web server.
[0087] As another example, the first communication entity is a Web server, the second communication entity is a terminal, and the third communication entity is a terminal identification device.
[0088] In a possible implementation, the web page includes a script, and the content of the script may include: calling a browser interface to obtain capability information of the terminal.
[0089] As an example, the script may also include invoking a network interface to transmit the terminal's capability information to a third communication entity. In one scenario, the third communication entity may be deployed in a web server, in which case the network interface may be a network interface exposed by the web server to the terminal. In another scenario, the third communication entity may not be deployed in a web server, in which case the network interface may be a network interface exposed by the communication device housing the third communication entity to the terminal.
[0090] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0091] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the third communication entity is specifically used to: identify the type of the terminal based on the terminal capability information and the terminal fingerprint information, where the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0092] It should be noted that for the relevant description of the communication system in the fourteenth aspect, please refer to the corresponding description in the eleventh aspect.
[0093] In a fifteenth aspect, the present application provides a communication device, which is applied to a terminal. The communication device may include a receiving unit, a processing unit, and a sending unit. The receiving unit is configured to receive a web page sent by a web server; the processing unit is configured to execute a script in the web page, wherein the script may include: calling a browser interface to obtain terminal capability information; and the sending unit is configured to send the terminal capability information to a terminal identification device.
[0094] In one possible implementation, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. The transmitting unit may then be configured to transmit the terminal's capability information to the terminal identification device via the network interface. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in a web server. In this case, the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0095] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0096] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the communication device may further include an acquisition unit, the acquisition unit being used to obtain fingerprint information of the terminal; and a sending unit being further used to send the fingerprint information of the terminal to the terminal identification device, where the fingerprint information of the terminal includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0097] It should be noted that for the relevant description of the communication device in the fifteenth aspect, please refer to the corresponding description in the twelfth aspect.
[0098] In a sixteenth aspect, the present application further provides a communication device, which is applied to a terminal identification device. The communication device may include, for example, a receiving unit and a processing unit. The receiving unit is configured to receive capability information of a terminal; and the processing unit is configured to identify the type of the terminal based on the capability information of the terminal.
[0099] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The content of the web page script includes: calling the terminal's browser interface to obtain the terminal's capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in the web server. In this case, the network interface may be a network interface exposed to the terminal by the communication device where the terminal identification device resides.
[0100] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0101] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the processing unit is specifically used to: identify the type of the terminal based on the terminal capability information and the terminal fingerprint information, where the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0102] It should be noted that for the relevant description of the communication device in the sixteenth aspect, please refer to the corresponding description in the thirteenth aspect.
[0103] In a seventeenth aspect, the present application further provides a computer storage medium, the computer storage medium including instructions, which, when executed on a processor, implement the following method:
[0104] Provide web pages to terminals;
[0105] Use the web page to call the terminal's browser interface to obtain the terminal's capability information.
[0106] In one possible implementation, when the instructions of the computer storage medium are executed on a processor, the following method is also implemented:
[0107] Identify the terminal type based on the terminal's capability information.
[0108] In a possible implementation, the web page includes a script, and the content of the script may include: calling a browser interface to obtain capability information of the terminal.
[0109] As an example, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. In one scenario, the terminal identification device may be deployed in a web server, in which case the network interface may be a network interface exposed by the web server to the terminal. In another scenario, the terminal identification device may not be deployed in a web server, in which case the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0110] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0111] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0112] It should be noted that for the relevant description of the computer storage medium in the seventeenth aspect, please refer to the corresponding description in the eleventh aspect or the fourteenth aspect.
[0113] In an eighteenth aspect, the present application further provides a computer storage medium, the computer storage medium including instructions, which, when executed on a processor, implement the following method:
[0114] Receive web pages sent by the web server;
[0115] Execute the script on the web page. The script includes: calling the browser interface to obtain the terminal's capability information; and
[0116] The terminal capability information is sent to the terminal identification device.
[0117] In one possible implementation, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. When the instructions of the computer storage medium are executed on the processor, the following method is specifically implemented: transmitting the terminal's capability information to the terminal identification device via the network interface. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in a web server. In this case, the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0118] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0119] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0120] It should be noted that for the relevant description of the computer storage medium in the eighteenth aspect, please refer to the corresponding description in the twelfth aspect or the fifteenth aspect.
[0121] In a nineteenth aspect, the present application further provides a computer storage medium, the computer storage medium including instructions, which, when executed on a processor, implement the following method:
[0122] receiving terminal capability information;
[0123] Identify the type of terminal based on the terminal's capability information.
[0124] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The content of the web page script includes: calling the terminal's browser interface to obtain the terminal's capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in the web server. In this case, the network interface may be a network interface exposed to the terminal by the communication device where the terminal identification device resides.
[0125] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0126] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, when the instructions of the computer storage medium are executed on the processor, the following method is specifically implemented: based on the terminal capability information and the terminal fingerprint information, the terminal type is identified, and the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0127] It should be noted that for the relevant description of the computer storage medium in the nineteenth aspect, please refer to the corresponding description in the thirteenth aspect or the sixteenth aspect.
[0128] In a twentieth aspect, the present application further provides a computer program product, comprising a computer program; when the computer program is run on a processor, the following method is implemented:
[0129] Provide web pages to terminals;
[0130] Use the web page to call the terminal's browser interface to obtain the terminal's capability information.
[0131] In a possible implementation manner, when the computer program of the computer program product runs on a processor, the following method is further implemented:
[0132] Identify the terminal type based on the terminal's capability information.
[0133] In a possible implementation, the web page includes a script, and the content of the script may include: calling a browser interface to obtain capability information of the terminal.
[0134] As an example, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. In one scenario, the terminal identification device may be deployed in a web server, in which case the network interface may be a network interface exposed by the web server to the terminal. In another scenario, the terminal identification device may not be deployed in a web server, in which case the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0135] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0136] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0137] It should be noted that for the relevant description of the computer program product in the twentieth aspect, please refer to the corresponding description in the eleventh aspect, the fourteenth aspect or the seventeenth aspect.
[0138] In a twenty-first aspect, the present application further provides a computer program product, comprising a computer program; when the computer program is run on a processor, the following method is implemented:
[0139] Receive web pages sent by the web server;
[0140] Execute the script on the web page. The script includes: calling the browser interface to obtain the terminal's capability information; and
[0141] The terminal capability information is sent to the terminal identification device.
[0142] In one possible implementation, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. When the computer program of the computer program product runs on a processor, the following method is specifically implemented: transmitting the terminal's capability information to the terminal identification device via the network interface. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in a web server. In this case, the network interface may be a network interface exposed to the terminal by a communication device containing the terminal identification device.
[0143] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0144] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0145] It should be noted that for the relevant description of the computer program product in the twenty-first aspect, please refer to the corresponding description in the twelfth aspect, the fifteenth aspect or the eighteenth aspect.
[0146] In a twenty-second aspect, the present application further provides a computer program product, comprising a computer program; when the computer program is run on a processor, the following method is implemented:
[0147] receiving terminal capability information;
[0148] Identify the type of terminal based on the terminal's capability information.
[0149] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The content of the web page script includes: calling the terminal's browser interface to obtain the terminal's capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in the web server. In this case, the network interface may be a network interface exposed to the terminal by the communication device where the terminal identification device resides.
[0150] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0151] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, when the computer program of the computer program product runs on a processor, the following method is specifically implemented: based on the terminal capability information and the terminal fingerprint information, the terminal type is identified, and the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0152] It should be noted that for the relevant description of the computer program product in the twenty-second aspect, please refer to the corresponding description in the thirteenth aspect, the sixteenth aspect or the nineteenth aspect.
[0153] In the twenty-third aspect, the present application provides a communication entity, which includes a processor and a memory; the processor is used to execute instructions stored in the memory so that the communication device implements the method corresponding to the eleventh aspect, the twelfth aspect or the thirteenth aspect and its possible implementation methods.
[0154] In the twenty-fourth aspect, the present application provides a communication entity, which includes a communication interface and a processor; the communication interface is used to perform the sending and receiving operations in the methods corresponding to the aforementioned eleventh aspect, twelfth aspect or thirteenth aspect and their possible implementations; the processor is used to perform the processing operations in the methods corresponding to the aforementioned eleventh aspect, twelfth aspect or thirteenth aspect and their possible implementations.
[0155] In a twenty-fifth aspect, the present application provides a chip system comprising a memory and a processor, wherein the memory is configured to store instructions, and the processor is configured to call and execute the instructions from the memory to implement the methods corresponding to the aforementioned eleventh aspect, twelfth aspect, or thirteenth aspect and their possible implementations. The chip system may include one or more chips, and the communication system in the embodiments of the present application may be, for example, such a chip system. BRIEF DESCRIPTION OF THE DRAWINGS
[0156] FIG1 is a schematic diagram of a network architecture applicable to an embodiment of the present application;
[0157] FIG2 is a schematic diagram of a flow chart of a terminal identification method 100 provided in an embodiment of the present application;
[0158] FIG3 is a schematic diagram of a network framework applicable to an embodiment of the present application;
[0159] FIG4 is a flow chart of the method 200 corresponding to FIG3 in an embodiment of the present application;
[0160] FIG5 is a schematic diagram of another applicable network framework in an embodiment of the present application;
[0161] FIG6 is a flow chart of method 300 corresponding to FIG5 in an embodiment of the present application;
[0162] FIG7 is a flow chart of a terminal identification method 400 according to an embodiment of the present application;
[0163] FIG8 is a schematic structural diagram of a communication device 800 according to an embodiment of the present application;
[0164] FIG9 is a schematic structural diagram of a communication device 900 according to an embodiment of the present application;
[0165] FIG10 is a schematic structural diagram of a communication device 1000 according to an embodiment of the present application;
[0166] FIG11 is a schematic structural diagram of a communication system 1100 according to an embodiment of the present application;
[0167] FIG12 is a schematic diagram of a network architecture applicable to an embodiment of the present application;
[0168] FIG13 is a schematic diagram of another applicable network architecture in an embodiment of the present application;
[0169] FIG14 is a schematic diagram of another applicable network architecture in an embodiment of the present application;
[0170] FIG15 is a flow chart of a terminal identification method 500 provided in an embodiment of the present application;
[0171] FIG16 is a flow chart of a terminal identification method 600 provided in an embodiment of the present application;
[0172] FIG17 is a flow chart of a terminal identification method 700 provided in an embodiment of the present application;
[0173] FIG18 is a flow chart of a terminal identification method 800 provided in an embodiment of the present application;
[0174] FIG19 is a schematic structural diagram of a communication device 1900 according to an embodiment of the present application;
[0175] FIG20 is a schematic structural diagram of a communication device 2000 according to an embodiment of the present application;
[0176] FIG21 is a schematic structural diagram of a communication device 2100 according to an embodiment of the present application;
[0177] FIG22 is a schematic structural diagram of a communication device 2200 according to an embodiment of the present application;
[0178] FIG23 is a schematic structural diagram of a communication system 2300 in an embodiment of the present application. DETAILED DESCRIPTION
[0179] With the development of the Internet of Things (IoT), a wide variety of terminals have emerged to meet the increasingly complex functional requirements of various industries in their respective scenarios. Different types of terminals are used to implement different functions. In different business scenarios, users can select and deploy corresponding terminal types based on their needs. It is often necessary to identify the type of terminal accessing the network. This identification is used to perform asset management, security access, and network optimization based on the identified terminal type. Therefore, accurate identification of terminals in the network is a crucial and necessary step in the network operation.
[0180] The following is an introduction to the currently used terminal identification methods.
[0181] In one method, the identification device can identify the terminal based on the fingerprint information of the terminal. This method can be divided into active terminal identification and passive terminal identification according to the method of obtaining the fingerprint information of the terminal. Among them, active terminal identification can refer to the identification device scanning the terminal through a possible scanning method, obtaining the fingerprint information of the terminal from the response information of the terminal to the scan, and determining the type of the terminal by matching the obtained fingerprint information with the fingerprint information in the fingerprint library. The scanning method that the identification device may use to scan the terminal includes but is not limited to any one of the following methods: Simple Network Management Protocol (SNMP) query scanning method, Network Mapper (NMAP) operating system (OS) scanning method or other dynamically extensible detection script scanning method. Passive terminal identification can refer to the identification device collecting the fingerprint information of the terminal and determining the type of the terminal by matching the collected fingerprint information with the fingerprint information in the fingerprint library.
[0182] Among them, the fingerprint information may refer to information in the relevant information of the terminal that can be used to identify the terminal, and the fingerprint information may include but is not limited to at least one of the following information: Medium Access Control (MAC) Organizationally Unique Identifier (OUI), Dynamic Host Configuration Protocol Option (DHCP Option), Hypertext Transfer Protocol (Hypertext Transfer Protocol) User Agent (UA), Multicast Domain Name Service (mDNS) or Link Layer Discovery Protocol (LLDP).
[0183] A fingerprint library may refer to a database that stores fingerprint information for terminals of known types. The fingerprint library may store multiple sets of correspondences between fingerprint information and corresponding terminal types. Therefore, in the above-mentioned terminal identification method, the identification device matches the fingerprint information of the terminal to be identified with the fingerprint information in the fingerprint library to determine the terminal type. Specifically, the identification device searches for fingerprint information that matches the fingerprint information of the terminal to be identified from the multiple sets of fingerprint information in the fingerprint library, and determines the terminal type in the correspondence relationship where the matching fingerprint information exists as the type of the terminal to be identified.
[0184] It can be seen that in this method, whether the terminal to be identified can be identified depends on whether the fingerprint database has accumulated a corresponding relationship including the fingerprint information of the terminal to be identified. If so, the terminal to be identified can be identified; if not, the terminal to be identified cannot be identified. Therefore, this method of identifying terminals based on their fingerprint information is difficult to guarantee recognition rate for the diverse types of terminals currently used in various industries. If the fingerprint information of a certain type of terminal is not accumulated in the fingerprint database, then this method cannot identify that type of terminal.
[0185] In another approach, the identification device can identify terminals through clustering based on the characteristics of the service traffic or service messages generated by the terminals after they join the network. For example, the identification device clusters multiple terminals to be identified based on the waveform similarity of the service traffic generated by the multiple terminals after they join the network, and manually labels the type corresponding to each cluster to determine that the terminal type is the type of the class to which the terminal belongs. For another example, the identification device clusters multiple terminals to be identified based on the content similarity of the service messages generated by the multiple terminals after they join the network, and manually labels the type corresponding to each cluster to determine that the terminal type is the type of the class to which the terminal belongs. Optionally, this approach can also be used as a method for accumulating a fingerprint library, accumulating identification results into the fingerprint library to improve the recognition rate of terminal identification based on terminal fingerprint information. However, this approach requires that the terminals to be identified must have generated service traffic or service messages after joining the network. Terminals that have connected to the network but have not yet generated service traffic or service messages cannot be identified using this approach. Moreover, the recognition accuracy of this method also depends on the amount of business traffic or business messages generated. Therefore, for terminals that access the network and generate a small amount of business traffic or business messages, the accuracy of the recognition results obtained by this method is difficult to guarantee.
[0186] Therefore, the terminal identification methods currently used are unable to effectively identify the ever-increasing variety of terminals, making it difficult to guarantee the terminal identification rate.
[0187] For example, in scenarios such as automatic admission, since the terminal has no business traffic (or business messages) before joining the network, it is impossible to identify the terminal by clustering the characteristics of business traffic (or business messages). Among them, terminal admission can be understood as when a terminal accesses the network but does not operate normally, the network admission controller (also called the network access controller) in the network determines whether the terminal can be admitted to the network based on the terminal type. The admitted terminal can operate normally in the network and provide the corresponding functions or services of the terminal.
[0188] For another example, for dumb terminals, the terminal identification method based on fingerprint information is not able to obtain the fingerprint information of various dumb terminals based on the current method of obtaining the fingerprint information of the terminal, that is, it is difficult to obtain the fingerprint information of the dumb terminal, resulting in the problem of poor recognition effect of the dumb terminal based on fingerprint information. Among them, dumb terminals can be a type of terminal that is divided according to whether it has a processing function. This type of terminal has no processing function and usually does not have a microprocessor. For example, printers, cameras, etc. are all dumb terminals. According to whether it has a processing function, in addition to dumb terminals, terminals can also include smart terminals (also called smart terminals). Smart terminals can refer to terminals with certain processing functions. This type of terminal has its own microprocessor and control circuit. For example, smart phones, laptops, etc. are all smart terminals. At present, some terminals with single functions and simple systems (such as smart screens) are usually classified as dumb terminals. For example, a dumb terminal's MAC OUI typically uses the first six characters of its MAC address to indicate its manufacturer. This manufacturer is only a reference and is not accurate. It also does not indicate other information, such as the type of dumb terminal. For another example, because dumb terminals cannot open web pages to introduce themselves, their HTTP UA (a common terminal fingerprint) cannot be obtained. Furthermore, except for printers and projection devices, mDNS (a common terminal fingerprint) cannot be obtained from other dumb terminals. Furthermore, LLDP can only be obtained by IP phones, and dumb terminals cannot obtain LLDP (a common terminal fingerprint). Therefore, obtaining the fingerprint information of dumb terminals is quite difficult.
[0189] Based on this, an embodiment of the present application provides a terminal identification method, which achieves effective and accurate identification of the terminal to be identified based on clustering of the open ports of the terminal to be identified. Even if the terminals in the network are diverse, this method can improve the terminal identification rate to a certain extent. In specific implementation, the method may include, for example: first, the identification device obtains the open port information of multiple terminals, and the open port information of each terminal indicates at least one port of each terminal that is in an open state; then, the identification device can cluster the multiple terminals based on the open port information of each terminal, and identify at least one cluster to which the multiple terminals belong based on the clustering results, where the terminals included in each cluster are of the same type. In this way, considering that the terminal usually needs to open a specific port to connect to the server corresponding to the terminal, different types of terminals need to open different specific ports. Therefore, in this method, the open port information of the terminal to be identified is used as the basis for clustering the terminals to be identified. Then, in the clustering results, the open port information of the terminals belonging to the same cluster is similar, and the terminals belonging to the same cluster are likely to be of the same type, thereby achieving effective and accurate identification of the terminals, overcoming the problem that the current terminal identification method needs to accumulate the fingerprint information of the terminal or requires business traffic (or business messages) after the terminal enters the network, and cannot guarantee the recognition rate of the terminal. In the scenario where various types of terminals emerge in an endless stream, the recognition rate of the terminal can be guaranteed.
[0190] The method provided in the embodiment of the present application can be adapted to various scenarios with terminal identification requirements, such as automatic admission of dumb terminals. The method provided in the embodiment of the present application can effectively identify the type of terminal and ensure the recognition rate of the terminal.
[0191] For example, the network architecture adapted by the embodiments of the present application can be seen in Figure 1. As shown in Figure 1, the network architecture may include at least: an identification device 10, and terminals 21, 22, ..., and 2N to be identified, where N is an integer greater than or equal to 1. The identification device 10 is used to implement the methods provided in the embodiments of the present application (such as the following method 100) to identify terminals 21, 22, ..., and 2N. As an example, the identification device 10 can obtain the open port information 1 of terminal 21, the open port information 2 of terminal 22, ... the open port information N of terminal 2N, and thus cluster the terminals 21 to 2N according to the open port information 1 to the open port information N to obtain the clustering results. The clustering results may include cluster 1, cluster 2, ... cluster M, where M is a positive integer less than N, each cluster includes at least one terminal, and the types of terminals in each cluster are the same. For example, cluster 1 includes terminal 21 and terminal 2N, and terminal 21 and terminal 2N are both printers. For another example, cluster 2 includes terminal 22, terminal 23 and terminal 24, and terminal 22, terminal 23 and terminal 24 are all electronic class signs. For another example, cluster 3 includes terminal 25 and terminal 26, and terminal 25 and terminal 26 are both information screens.
[0192] The open port information is used to indicate the ports in the open state on the corresponding terminal. The identification device 20 can determine the port numbers and the number of ports in the open state on the corresponding terminal based on the open port information. For example, open port information 1 is used to indicate that the ports in the open state on terminal 21 are Transmission Control Protocol (TCP) 80 and TCP 81. Based on open port information 1, the number of ports in the open state on terminal 21 is determined to be 2, and the specific port numbers in the open state are TCP 80 and TCP 81. Then, the identification device 20 clusters terminals 21 to 2N based on open port information 1 to open port information N. For example, the identification device 20 can determine the number and / or port numbers of ports in the open state on terminals 21 to 2N based on open port information 1 to open port information N, and group terminals with the same or similar number of open ports and / or a high degree of similarity in open port numbers (e.g., meeting a preset similarity threshold) into the same cluster. Among them, the similarity of the port numbers in the open state can be related to the number of port numbers in the same open state. For example, two port numbers are the same between the port numbers in the open state of terminal 21 and the port numbers in the open state of terminal 22, and four port numbers are the same between the port numbers in the open state of terminal 21 and the port numbers in the open state of terminal 2N. Then, it can be considered that the similarity of the port numbers in the open state of terminal 21 and terminal 2N is higher than the similarity of the port numbers in the open state of terminal 21 and terminal 22.
[0193] In the embodiments of the present application, the identification device can be any communication device in the network that has the ability to implement the methods provided in the embodiments of the present application. The communication device can be a network device such as a switch or router. Alternatively, the identification device can be a functional module, component, or chip in any communication device in the network that has the ability to implement the methods provided in the embodiments of the present application, such as a single board or line card on the network device. The embodiments of the present application do not specifically limit the form and type of the identification device.
[0194] In the embodiments of the present application, a terminal may refer to any terminal that can be deployed in a network, and may be a smart terminal or a dumb terminal. The embodiments of the present application do not specifically limit the form and type of the terminal.
[0195] In order to introduce the embodiment of the present application more clearly, the method provided in the embodiment of the present application is described below with reference to FIG2 .
[0196] Figure 2 is a flow chart illustrating a terminal identification method 100 provided in an embodiment of the present application. In this method 100, the present embodiment is described using an identification device as the execution entity. This identification device may be, for example, identification device 10 in Figure 1 , or may correspond to the network controller 30 of the network framework shown in Figure 3 , the network controller 30 of the network framework shown in Figure 5 , or communication device 800 . In scenarios where the terminal identification result is used by the NAC to automatically determine terminal admission, the identification device executing this method 100 may be the NAC itself or a corresponding functional module within the NAC.
[0197] As shown in FIG2 , the method 100 may include, for example, the following steps S101 to S103 :
[0198] S101: Acquire open port information of a plurality of terminals, where the open port information of each terminal indicates at least one open port of each terminal.
[0199] The "terminal" in the method 100 can be understood as a terminal to be identified, for example, it can include one or more of the terminal 21, terminal 22, ..., terminal 2N in Figure 1. As an example, the terminal to be identified can be all terminals in the network, then S101 can include: the identification device obtains the open port information of all terminals in the network. As another example, the terminal to be identified can be a terminal belonging to a target network segment in the network, then S101 can include: the identification device obtains the open port information of all terminals belonging to the target network segment in the network. As yet another example, the terminal to be identified can be a terminal belonging to a target VLAN in the network, then S101 can include: the identification device obtains the open port information of all terminals belonging to the target VLAN in the network. As another example, the terminal to be identified can be a terminal belonging to a target BD in the network, then S101 can include: the identification device obtains the open port information of all terminals belonging to the target BD in the network.
[0200] Typically, a terminal has multiple ports, each of which can be in an open state or a closed state. The terminal can interact with other communication devices through the open ports. For example, the terminal can open a specific port so that the specific port is in an open state, thereby connecting to the server corresponding to the terminal based on the open port. Thus, through the interaction between the terminal and the server, the terminal provides corresponding services to the user. Taking a common terminal such as a printer as an example, the printer can open port 631, and other devices can connect to the printer based on the Internet Printing Protocol (IPP), enabling other devices to manage the printer and use the printer's printing services.
[0201] The open port information of a terminal may refer to any information that can indicate at least one port of the terminal that is in an open state. The specific embodiment of the open port information is not limited in the embodiments of the present application. As an example, the open port information may be an open port set. For example, the ports in the open state of terminal 21 include TCP port 80 and TCP port 81. Then, the open port information 1 of terminal 21 may be represented as an open port set such as {TCP 80, TCP 81}. As another example, the open port information may include the number of ports in the open state and the port number in the open state. Still taking the example that the ports in the open state of terminal 21 include TCP port 80 and TCP port 81, the open port information 1 of terminal 21 may also be represented as {number of ports in the open state: 2; port numbers in the open state: {TCP 80, TCP 81}}.
[0202] The terminal's open port information can be obtained by a port scanning device performing a port scan on each of a plurality of terminals. The process of the port scanning device performing a port scan on a terminal can, for example, include: the port scanning device generating a port probe message corresponding to each port to be detected on the terminal, and sending the generated port probe message to the terminal; if the port to be detected by the port probe message received by the terminal is in an open state, the terminal sends a response message corresponding to the port probe message to the port scanning device; if the port to be detected by the port probe message received by the terminal is not in an open state, the terminal does not generate a response message corresponding to the port probe message; in this way, the port scanning device can determine at least one open port on the terminal based on the received response message to the port probe message, and obtain the terminal's open port information based on the at least one open port determined on the terminal. The number of response messages corresponding to the port probe messages received by the port scanning device is equal to the number of open ports in the detected ports of the terminal.
[0203] For example, the terminal 21 includes 6 ports: TCP port 78, TCP port 79, TCP port 80, TCP port 81, TCP port 82 and TCP port 83. Assume that the ports in the open state among the 6 ports include: TCP port 80, TCP port 81 and TCP port 83, and the ports to be detected among the 6 ports on the terminal 21 include: TCP port 78, TCP port 79, TCP port 80 and TCP port 81. Then, the process of the port scanning device performing a port scan on the terminal 21 may include: the port scanning device generates 4 port detection messages: port detection message 1 to port detection message 4, wherein the port detection message 1 to port detection message 4 are used to detect TCP port 78, TCP port 79, TCP port 80 and TCP port 81 respectively; since the TCP ports 78 and TCP 81 of the terminal 21 are Port 79 is not in an open state, so terminal 21 does not generate a response message for port detection message 1 and port detection message 2. Since TCP port 80 and TCP port 81 of terminal 21 are in an open state, terminal 21 generates response message 3 for port detection message 3 and response message 4 for port detection message 4; terminal 21 sends response message 3 and response message 4 to the port scanning device; the port scanning device determines that TCP port 80 is in an open state according to response message 3, and determines that TCP port 81 is in an open state according to response message 4. Therefore, the port identification device can determine the open port information of the terminal 21, and the open port information is used to indicate that the ports in the terminal 21 that are in an open state include TCP port 80 and TCP port 81.
[0204] The type of port to be detected is different, and the type of port detection message constructed is also different. For example, if the port to be detected is a TCP type port, then the port detection message can be a TCP message; for another example, if the port to be detected is a User Datagram Protocol (UDP) type port, then the port detection message can be a UDP message. The port detection message can include indication information indicating the port to be detected. The indication information can be the port number of the port to be detected, and the indication information can be carried in the destination port (Destination Port, Dst Port) field of the port detection message. For example, if the port to be detected is TCP port 80 of the terminal, then the port detection message can be a TCP message. In the message header of the port detection message, the protocol field = TCP and the Dst Port field = 80.
[0205] The ports to be detected can be flexibly determined according to actual needs. In one case, the ports to be detected can be all the ports of the terminal. Then, during the process of the port scanning device performing port scanning on the terminal, the port scanning device needs to send port detection messages corresponding to each port to the terminal, and the number of port detection messages sent is the same as the number of ports included in the terminal. For another example, the ports to be detected can be a specified portion of the ports of the terminal (which can also be understood as a portion of the specified ports among all the ports of the terminal). The specified portion of ports can be commonly used ports that need to be detected (such as the top 100 most commonly used ports (i.e., Top 100) in a commonly used port list), or can also be designated ports that need to be detected (such as ports with designated port numbers according to actual application scenario requirements). Then, during the process of the port scanning device performing port scanning on the terminal, the port scanning device needs to send port detection messages corresponding to each designated port to the terminal, and the number of port detection messages sent is the same as the number of designated ports of the terminal.
[0206] Regarding the timing of the port scanning device executing the port scanning of the terminal, as an example, upon the start of method 100, the port scanning device is triggered to execute the port scanning process of the terminal to obtain the terminal's open port information. As another example, the port scanning device may pre-execute the port scanning process of the terminal and save the open port information of multiple terminals. When the method 100 is started, the identification device reads the pre-saved open port information of the multiple terminals from the port scanning device.
[0207] If the port scanning device and the identification device belong to the same network device, then the port scanning device obtaining the open port information of the terminal is equivalent to the identification device obtaining the open port information of the terminal. In this case, S101 can be understood as: the network device including the port scanning device and the identification device obtains the open port information of multiple terminals by performing port scanning on the port to be detected of each terminal. Specifically, it can include: the network device sends port detection messages to the multiple terminals and obtains the open port information of the multiple terminals based on the received response messages. Taking the "multiple terminals" in S101 as all terminals in the network as an example, S101 can include: the network device including the port scanning device and the identification device performs port scanning on all terminals in the network to obtain the open port information of the multiple terminals (i.e., all terminals in the network). Taking the "multiple terminals" in S101 as all terminals in the target network segment as an example, S101 can include: the network device including the port scanning device and the identification device performs port scanning on all terminals in the target network segment to obtain the open port information of the multiple terminals (i.e., all terminals in the target network segment). Taking the "multiple terminals" in S101 as all terminals in the target VLAN in the network as an example, S101 may include, for example: the network device including a port scanning device and an identification device performs a port scan on all terminals in the network to obtain open port information of the multiple terminals (i.e., all terminals in the target VLAN in the network). Taking the "multiple terminals" in S101 as all terminals in the target BD in the network as an example, S101 may include, for example: the network device including a port scanning device and an identification device performs a port scan on all terminals in the network to obtain open port information of the multiple terminals (i.e., all terminals in the target BD in the network).
[0208] If the port scanning device and the identification device belong to two network devices, then after the port scanning device obtains the open port information of the terminal, it can send the obtained open port information of the terminal to the identification device. In this case, S101 can be understood as: the network device where the identification device is located receives the open port information of multiple terminals sent by the network device where the port scanning device is located.
[0209] It can be seen that obtaining the open port information of multiple terminals through S101 provides a reliable basis for subsequent terminal identification based on the open port information of the terminals, making it possible to achieve terminal identification with a high recognition rate.
[0210] S102: Cluster the multiple terminals according to the open port information of each terminal.
[0211] In a first possible implementation manner, the identification device may identify the type of the terminal only based on the open port information of the terminal.
[0212] As a first example, if the execution of method 100 is the first identification of terminals in the network and there is no cluster of known type in the network, or if the terminals in the network are re-identified and the known type of cluster is no longer valid, then S102 may include: the identification device clusters the multiple terminals according to the similarity of the open port information of the multiple terminals.
[0213] The similarity between the open port information of the terminals can be determined based on the number and port numbers of the ports in the open state of the terminals, and the calculation strategy for determining the similarity can be designed according to actual needs.
[0214] For example, the similarity between the open port information of the terminals = the number of ports with the same open number * the weight corresponding to the port number - the difference in the number of ports in the open state * the weight corresponding to the number of ports, the weight corresponding to the port number is 20%, the weight corresponding to the port number is 80%, the open port information 1 of terminal 1 indicates that the port numbers of terminal 1 in the open state are: TCP 79, TCP 80 and TCP 81, the open port information 2 of terminal 2 indicates that the port numbers of terminal 2 in the open state are: TCP 80 and TCP 81, the open port information 3 of terminal 3 indicates that the port numbers of terminal 3 in the open state are: TCP 78, TCP 80 and TCP 81, and the open port information 4 of terminal 4 indicates that the port numbers of terminal 4 in the open state are: TCP 78, TCP 80, TCP 82 and TCP 83, then, the similarity between the open port information 1 of terminal 1 and the open port information 2 of terminal 2 = 2*80% - 1*20% = 1.4, the similarity between the open port information 1 of terminal 1 and the open port information 3 of terminal 3 = 2*80% - 0*20% = 1.6, and the similarity between the open port information 1 of terminal 1 and the open port information 4 of terminal 4 = 1*80% - 1*20% = 0.6.
[0215] For another example, the similarity between the open port information of the terminals = the number of the same port numbers in the open state + (1-the difference in the number of ports in the open state). It is still assumed that the open port information 1 of terminal 1 indicates that the port numbers of terminal 1 in the open state are: TCP 79, TCP 80 and TCP 81, the open port information 2 of terminal 2 indicates that the port numbers of terminal 2 in the open state are: TCP 80 and TCP 81, the open port information 3 of terminal 3 indicates that the port numbers of terminal 3 in the open state are: TCP 78, TCP 80 and TCP 81, and the open port information 4 of terminal 4 indicates that the port numbers of terminal 4 in the open state are: TCP 78, TCP 80 and TCP 82. Then, the similarity between the open port information 1 of terminal 1 and the open port information 2 of terminal 2 = 2+(1-1)=2, the similarity between the open port information 1 of terminal 1 and the open port information 3 of terminal 3 = 2+(1-0)=3, and the similarity between the open port information 1 of terminal 1 and the open port information 4 of terminal 4 = 1+(1-0)=2.
[0216] It should be noted that, generally, the larger the similarity value, the more similar the open ports between the terminals are, and the more likely the terminals are to belong to the same type. Conversely, the smaller the similarity value, the less similar the open ports between the terminals are, and the more likely the terminals are to belong to different types.
[0217] For the identification device in S102 to cluster multiple terminals based on the similarity of the open port information of multiple terminals, it can be implemented by any clustering strategy, clustering algorithm or clustering model, and the embodiments of the present application are not specifically limited. For example, the clustering in S102 can be implemented by a preconfigured clustering strategy, and the clustering strategy can be, for example: preconfigure a similarity range, and divide two terminals whose similarities fall within the similarity range into one cluster, and each terminal can only belong to one cluster. For another example, the clustering in S102 can be implemented by a clustering algorithm, and the clustering algorithm can be, for example, a density-based spatial clustering of applications with noise (Density-Based Spatial Clustering of Applications with Noise, DBSCAN) algorithm or a k-means clustering algorithm (k-means clustering algorithm, K-means).
[0218] In this example, the clustering results obtained in S102 include at least one cluster, each of which includes at least one terminal of the same type. For example, the multiple terminals in S101 include terminals 1 to 10. After clustering in S102, three clusters are obtained: clusters 1 to 3. Cluster 1 includes terminals 1, 3, and 5; cluster 2 includes terminals 2, 4, and 8; and cluster 3 includes terminals 6, 7, 9, and 10.
[0219] As a second example, if, prior to the current execution of method 100, terminals in the network have been identified at least once, and at least one cluster of a known type exists in the network, then the "multiple terminals" in method 100 may refer to terminals newly connected to the network during the time interval between the last identification of the terminals in the network and the execution of method 100. S102 may include: the identification device determining, based on similarity between the open port information of the multiple terminals and the open port information of each cluster of the known type, the cluster of the known type to which each of the multiple terminals belongs, thereby completing clustering of the multiple terminals.
[0220] Among them, the similarity between the open port information of the terminal and the open port information of each cluster of known types can be determined based on the number and port number of the terminals in the open state, and the number and port number of the terminals in the open state at the cluster center of each cluster of known types. The similarity calculation strategy can be designed according to actual needs. For example, the clusters of known types include cluster 1 and cluster 2. The terminal at the cluster center of cluster 1 is terminal 1, and the terminal at the cluster center of cluster 2 is terminal 8. The multiple terminals to be identified include terminal 31, terminal 32, and terminal 33. Then, the identification device needs to calculate the similarity between the open port information of terminal 31, terminal 32, and terminal 33 and the open port information of terminal 1, and calculate the similarity between the open port information of terminal 31, terminal 32, and terminal 33 and the open port information of terminal 8. By comparing the calculated similarities, it is determined whether terminals 31, terminal 32, and terminal 33 should be classified into cluster 1 or cluster 2.
[0221] It should be noted that the calculation method of the similarity between the open port information of the terminals can refer to the relevant description above.
[0222] In S102, the identification device clusters the multiple terminals based on the similarity between the open port information of the multiple terminals and the open port information of each cluster of known types. This may be: for each terminal in the "multiple terminals", the terminal is assigned to the cluster with the greatest similarity to the open port information of the terminal. For example, if the similarity between the open port information of terminal 31 and the open port information of terminal 1 is greater than the similarity between the open port information of terminal 31 and the open port information of terminal 8, then terminal 31 is assigned to cluster 1 where terminal 1 is located. Similarly, if the similarity between the open port information of terminal 32 and the open port information of terminal 1 is less than the similarity between the open port information of terminal 32 and the open port information of terminal 8, then terminal 31 is assigned to cluster 2 where terminal 8 is located.
[0223] It should be noted that the clustering results in this example may include not only clusters of known types after executing S102, but also newly clustered clusters. For the clustering method of the newly clustered clusters, please refer to the relevant instructions of the first example above. For subsequent processing, please refer to the instructions related to the first example below.
[0224] In this example, the clustering results obtained in S102 may include clusters of known types, each of which includes at least one terminal of the same type. For example, the multiple terminals in S101 include terminals 31 to 35, and the clusters of known types include clusters 1 to 3. After clustering in S102, terminals 31 and 33 are added to cluster 1, terminals 32, 34, and 35 are added to cluster 2, and no new terminals are added to cluster 3.
[0225] In a second possible implementation, to further improve the reliability of terminal identification, the terminal type can be identified based on the terminal's open port information combined with other terminal information. Taking into account the characteristics of how the network assigns addresses to terminals and how users assign addresses to their own terminals, the other terminal information may include, but is not limited to, the terminal's Media Access Control (MAC) address and / or the terminal's IP address.
[0226] As an example, before S102, the method may further include: the identification device obtains the MAC address of each terminal from the plurality of terminals. Then, S102 may include: the identification device clustering the plurality of terminals based on the open port information of each terminal and the MAC address of each terminal. The manner in which the identification device obtains the MAC address of each terminal from the plurality of terminals can refer to the manner in which the identification device obtains the open port information of each terminal from the plurality of terminals. For example, the identification device may obtain the open port information of the terminal and the MAC address of the terminal by performing a port scan on all or a specified portion of the ports of the terminal. For another example, the identification device may receive the MAC address of the terminal from a port scanning device that receives the open port information of the terminal.
[0227] In specific implementation, S102 may include: the identification device determines the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the MAC address between each terminal; thereby, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals.
[0228] The calculation method of the similarity of the open port information between the terminals can refer to the description above.
[0229] Among them, the similarity of MAC addresses between terminals is calculated based on the prefix similarity of the MAC addresses in one case, that is, starting from the highest bit of the MAC address, the similarity of the two MAC addresses is determined based on the number of consecutive identical bits. The more consecutive identical bits there are, the higher the similarity of the MAC addresses of the two terminals is considered to be; the fewer consecutive identical bits there are, the lower the similarity of the MAC addresses of the two terminals is considered to be. For example, the MAC address of terminal 1 is 000BD4041508, the MAC address of terminal 2 is 000BD4042608, and the MAC address of terminal 3 is 000BD4160508. Since the consecutive identical bits from the highest bit in the MAC addresses of terminal 1 and terminal 2 are 000BD404, and the consecutive identical bits from the highest bit in the MAC addresses of terminal 1 and terminal 3 are 000BD4, the similarity of the MAC addresses of terminal 1 and terminal 2 is higher than the similarity of the MAC addresses of terminal 1 and terminal 3. In this way, if the user assigns MAC addresses to his many terminals based on the prefix of the applied MAC address, the prefix of the MAC address of all terminals is the same as the prefix of the applied MAC address. The prefix of the MAC address is then assigned a specific MAC address to each terminal according to the type of terminal. For example, the prefix of the MAC address applied for by user A is 000BD4. User A assigns 000BD404 to printer terminal 1 and printer terminal 2, and the MAC addresses are: 000BD4041508 and 000BD4042608 respectively. User A assigns 000BD416 to smart screen terminal 3 and smart screen terminal 4, and the MAC addresses are: 000BD4160508 and 000BD4160609 respectively.
[0230] In another case, the MAC address can be considered as a string, and the similarity of the MAC addresses between terminals is calculated based on the similarity of the strings. That is, the number of characters with the same values at corresponding positions in the MAC addresses of the two terminals is checked. The similarity of the two MAC addresses is determined based on the number of characters with the same values. The more characters with the same values, the higher the similarity of the MAC addresses of the two terminals; the fewer characters with the same values, the lower the similarity of the MAC addresses of the two terminals. For example, the MAC address of terminal 1 is 000BD4041508, the MAC address of terminal 2 is 000BD4042608, and the MAC address of terminal 3 is 000BD4160508. Since the MAC addresses of terminal 1 and terminal 2 have the same values for a total of 10 characters, 000BD404 and 08, and the MAC addresses of terminal 1 and terminal 3 have the same values for 9 consecutive characters starting from the highest bit, 000BD4 and 508, the similarity of the MAC addresses of terminal 1 and terminal 2 is higher than that of the MAC addresses of terminal 1 and terminal 3. In this way, it is possible to provide a certain reference for whether two terminals are of the same type based on the character similarity of the MAC addresses.
[0231] The comprehensive similarity between terminals can refer to an indicator that can reflect the similarity between the two factors of open port information and MAC address between the terminals. The comprehensive similarity between terminals can be, for example, the sum of the similarity of open port information between terminals and the similarity of MAC addresses between terminals, or it can be the average or weighted average of the similarity of open port information between terminals and the similarity of MAC addresses between terminals. The weight can be flexibly set according to actual needs.
[0232] As another example, before S102, the method may further include: the identification device obtains the IP address of each terminal from the plurality of terminals. Then, S102 may include: the identification device clustering the plurality of terminals based on the open port information of each terminal and the IP address of each terminal. The manner in which the identification device obtains the IP address of each terminal from the plurality of terminals can refer to the manner in which the identification device obtains the open port information of each terminal from the plurality of terminals. For example, the identification device may perform a port scan on all or a specified portion of the ports of the terminal to obtain the open port information of the terminal and the IP address of the terminal. For another example, the identification device may receive the IP address of the terminal from a port scanning device that receives the open port information of the terminal.
[0233] In specific implementation, S102 may include: the identification device determines the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal and the similarity of the IP addresses between each terminal; thereby, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals.
[0234] The calculation method of the similarity of the open port information between terminals can refer to the description of the method of calculating the similarity of the open port information between terminals above. The calculation method of the similarity of the IP addresses between terminals can refer to the calculation method of calculating the similarity of the IP addresses between terminals above.
[0235] The comprehensive similarity between terminals can refer to an indicator that can reflect the similarity between the two factors of open port information and IP addresses between the terminals. The comprehensive similarity between terminals can be, for example, the sum of the similarity of open port information between terminals and the similarity of IP addresses between terminals, or it can be the average or weighted average of the similarity of open port information between terminals and the similarity of IP addresses between terminals. The weight can be flexibly set according to actual needs.
[0236] As another example, before S102, the method may further include: the identification device obtains the MAC address and IP address of each terminal in the plurality of terminals. Then, S102 may include: the identification device clusters the plurality of terminals based on the open port information of each terminal and the MAC address and IP address of each terminal. The manner in which the identification device obtains the MAC address and IP address of each terminal in the plurality of terminals can refer to the manner in which the identification device obtains the open port information of each terminal in the plurality of terminals. For example, the identification device may obtain the open port information of the terminal by performing a port scan on all or a specified portion of the ports of the terminal to obtain the MAC address and IP address of the terminal. For another example, the identification device may receive the MAC address and IP address of the terminal from a port scanning device that receives the open port information of the terminal.
[0237] In specific implementation, S102 may include: the identification device determines the comprehensive similarity between the terminals based on the similarity of the open port information between each terminal, the similarity of the MAC addresses between each terminal, and the similarity of the IP addresses between each terminal; thereby, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals.
[0238] For the method for calculating the similarity of open port information between terminals, please refer to the description above regarding the method for calculating the similarity of open port information between terminals. For the method for calculating the similarity of IP addresses between terminals, please refer to the description above regarding the method for calculating the similarity of IP addresses between terminals. For the method for calculating the similarity of MAC addresses between terminals, please refer to the description above regarding the method for calculating the similarity of MAC addresses between terminals.
[0239] The comprehensive similarity between terminals can refer to an indicator that can reflect the similarity of the three factors of open port information, MAC address and IP address between the terminals. The comprehensive similarity between terminals can be, for example, the sum of the similarity of open port information between terminals, the similarity of MAC addresses between terminals and the similarity of IP addresses between terminals, or it can be the average value or weighted average value of the similarity of open port information between terminals, the similarity of MAC addresses between terminals and the similarity of IP addresses between terminals. The weights can be flexibly set according to actual needs.
[0240] It should be noted that in the above three examples, the identification device clusters multiple terminals based on the comprehensive similarity between the terminals. Please refer to the implementation method of the above identification device clustering multiple terminals based on the similarity of open port information between the terminals.
[0241] In this second implementation method, the scenario corresponding to the first example in the above-mentioned first implementation method is described. The scenario corresponding to the second example in the above-mentioned first implementation method is similar to the implementation method in the second example of the first implementation method. Please refer to the relevant description in the second example of the first implementation method.
[0242] S103 : Identify, based on the clustering result, at least one cluster to which the multiple terminals belong, wherein the terminals included in each cluster belong to the same type.
[0243] A cluster is a collection of terminals belonging to a single type in the clustering results. If multiple terminals to be identified belong to the same type, a single cluster corresponding to that type is identified based on the clustering results. If multiple terminals to be identified belong to multiple types, multiple clusters are identified based on the clustering results, with the number of clusters being the same as the number of types the terminals belong to.
[0244] In a specific implementation, S103 may include, for example, determining, based on the clustering results, the type of each cluster in at least one cluster to which the multiple terminals belong. The type of a cluster is the type of all terminals belonging to that cluster. Therefore, determining the type of each cluster is equivalent to identifying the types of the terminals in each cluster, thereby achieving terminal identification. Determining the type of each cluster in S103 may be performed automatically, through a combination of automatic identification and manual confirmation, through manual labeling, or through a combination of automatic identification and manual labeling.
[0245] As an example, for each cluster in the at least one determined cluster, the type of the cluster may be automatically identified based on an automatic matching strategy, a local identification strategy, a machine learning model, or the like.
[0246] Taking the automatic matching strategy as an example, in one case, S103 may include: for any second cluster in the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes the first target port, determining that the type of the second cluster is the first type corresponding to the first target port. Specifically, the identification device may pre-configure certain correspondences between terminal types and ports as a basis for matching. Then, for each of the at least one determined clusters, the identification device checks whether the open ports indicated by the open port information of each terminal in the cluster match any of the correspondences. If so, the type of the cluster is determined to be the type of the terminal included in the matched correspondence. For example, if the identification device pre-configured correspondences include correspondence 1 between a printer and port 631, and the identification device finds that the open ports indicated by the open port information of each terminal in cluster 1 among the three determined clusters all include port 631, cluster 1 may be considered to match correspondence 1, and the type of cluster 1 is determined to be the terminal type of printer in correspondence 1.
[0247] Taking the local identification strategy as an example, in another case, S103 may include: for any second cluster in at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, determining that the type of the second cluster is the first type. Specifically, the identification device may select at least one terminal in each of the at least one determined clusters, identify the type of the selected terminal based on any possible method, and use the type as the type of the cluster. The method for identifying the type of the selected terminal may, for example, adopt fingerprint recognition, business traffic (or business message) clustering, etc. For example, the identification device selects terminal 1 in cluster 1 of the three determined clusters, and determines that terminal 1 is a smart screen based on fingerprint recognition. Then, the identification device may determine that the type of cluster 1 is a smart screen, and the type of all terminals in cluster 1 (including terminal 1) is a smart screen. It should be noted that in this implementation, the fewer terminal types selected, the faster the cluster type is identified and the higher the recognition efficiency; the more terminal types selected, the more accurate and reliable the cluster type is identified, but the recognition efficiency and recognition rate will be affected to a certain extent.
[0248] Thus, the identification result of the terminal may include: the type corresponding to the cluster of the specific type, and further, the number of terminals included in the cluster of the specific type. In order to facilitate users to view, check and manage their own assets, after S103, the method 100 may further include: a page displaying the identification result of the terminal, which may include, for example, a display item corresponding to each cluster in at least one cluster, and the display content of each display item may include, but is not limited to: the type of the corresponding cluster, the number of terminals included in the cluster, and an operation control, which provides the user with several operable operation items, and the operability may include, but is not limited to: viewing operation, editing operation, confirmation operation, etc. The user can view the terminals included in the cluster by clicking the viewing operation; the user can modify the type of the cluster and the type of one or several terminals included in the cluster by clicking the editing operation; the user can confirm the automatically identified type of the cluster by clicking the confirmation operation.
[0249] As another example, for each of the at least one determined clusters, after automatically identifying the type of the cluster, the cluster type can be identified as a candidate type, prompting and waiting for the user to confirm or edit the candidate type to finally determine the type of the cluster. This example can be considered an automatic identification + manual confirmation method. In this example, S103 may include: for any second cluster in the at least one cluster, the identification device determines the type of the second cluster as the first type based on automatic identification; then, in response to an edit operation or confirmation operation on the first type of the second cluster, determining the type of the second cluster as the second type. If the user confirms the first type of the second cluster, the second type is the same as the first type. If the user finds that the automatic identification result (i.e., the first type) is inaccurate, the user can identify the type of the second cluster based on any other method, determine the second cluster as the second type, and then perform an edit operation on the first type of the second cluster to change the type of the second cluster from the first type to the second type. In this case, the second type is different from the first type. In this way, the automatic identification + manual confirmation method can improve the accuracy of terminal recognition while ensuring recognition efficiency.
[0250] As another example, for at least one determined cluster, after automatically identifying the specific types of some clusters, the clusters whose specific types are not identified can be displayed as unknown types, prompting and waiting for the user to manually mark the unknown types, so as to determine the types of all clusters. This example can be regarded as an automatic identification + manual marking method. In this example, S103 may include: for one or more clusters whose specific types cannot be identified, displaying the types of one or more clusters as unknown types; manually marking the specific types of one or more clusters. Among them, the marking method for clusters of unknown types can be, for example: for any first cluster in the cluster of unknown type, identifying the type of one or more terminals in the first cluster, and marking the type as the type of the first cluster. In this way, through the method of automatic identification + manual marking, the type of each cluster can be determined, and the recognition rate of the terminal can be guaranteed.
[0251] It should be noted that in order to further improve the accuracy of the terminal recognition results, the method 100 may also include: a process in which the recognition device corrects the clustering results. As an example, the recognition device correcting the clustering results may include: when the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, changing the cluster to which the terminal belongs according to the type of the terminal. Specifically, on the page displaying the terminal recognition results, the user can view the terminals belonging to a certain display entry through a viewing operation. If it is found that a terminal does not belong to the same type as other terminals under the entry, the user can migrate the terminal from the entry to another display entry. The type of the cluster corresponding to the migrated entry is the same as the type of the terminal. For example, when the user views the terminals included in cluster 1 corresponding to the printer, it is found that the type of terminal 1 in cluster 1 is a smart screen. Therefore, in response to the user performing a correction operation on the type of terminal 1 (such as after the user clicks the correction operation item corresponding to terminal 1, enters "smart screen" in the pop-up input box and confirms it), the recognition device migrates terminal 1 to cluster 2 corresponding to the smart screen. After the migration, cluster 1 no longer includes terminal 1, and cluster 2 includes terminal 1.
[0252] In some possible implementations, after obtaining identification results for multiple terminals, the identification results can be used in any scenario.
[0253] For example, the recognition results can be integrated into the user's digital map, displaying the user's network topology. When the user selects a point on the digital map, the map will also display the terminals deployed at that point. The displayed terminals are displayed based on the recognition results, and other terminal details can also be displayed. In this way, by integrating terminal recognition results into the digital map, the information provided to the user is enriched, making it easier for users to deploy, manage, and control their network.
[0254] For another example, network access control can be performed on terminals based on their type. For example, terminals 1 and 2, which are electronic signboards, are automatically allowed access and assigned to VLAN 100. Terminals 3, 4, and 5, which are smart screens, are automatically allowed access and assigned to VLAN 200. Terminals 6 to 10, which are smartphones, are automatically blocked and prohibited from accessing the network. In this way, by applying terminal identification results to automatic terminal access control scenarios, rapid and effective terminal management is achieved.
[0255] For another example, configuration information can be sent to various types of terminals based on their type, completing automatic network configuration for each type of terminal. This configuration information can be sent by an identification device or other network device with information configuration capabilities to the network device to which the terminal is connected for network configuration. In this way, by applying the terminal identification results to the terminal's automatic configuration scenario, rapid and efficient terminal configuration is achieved.
[0256] It can be seen that through this method 100, considering that the terminal usually needs to open a specific port to connect to the server corresponding to the terminal, different types of terminals need to open different specific ports. Therefore, the open port information of the terminal to be identified is used as the basis for clustering the terminals to be identified. Then, in the clustering results, the open port information of the terminals belonging to a cluster is similar, and the terminals belonging to a cluster are likely to belong to the same type, thereby achieving effective and accurate identification of the terminals, overcoming the problem that the current terminal identification method needs to accumulate the fingerprint information of the terminal or needs to have the business traffic (or business message) after the terminal enters the network, and cannot guarantee the recognition rate of the terminal. In the scenario where various types of terminals emerge in an endless stream, the recognition rate of the terminal can be guaranteed.
[0257] It should be noted that the embodiment of the present application is explained by taking the identification of the type of terminal as an example. The method provided in the embodiment of the present application can also use the open port information of the terminal, or combine the open port information of the terminal and other information of the terminal to realize the identification of other attribute information of the terminal through clustering. The other attribute information of the terminal may, for example, include but is not limited to at least one of the following information: the manufacturer to which the terminal belongs, the model of the terminal or the operating system used by the terminal. The specific implementation method is not limited in the embodiment of the present application.
[0258] In order to make the method provided in the embodiment of the present application easier to understand, the method provided in the embodiment of the present application is exemplarily described below with reference to two specific network frameworks.
[0259] As shown in Figure 3, the network framework may include: a network controller 30, a network 3, and a terminal 40. Network 3 may include: a core layer device 31, an aggregation layer device 32, an aggregation layer device 33, an access layer device 34, an access layer device 35, and an access layer device 36. The network controller 30 has at least the corresponding functions of the identification device and the port scanning device in the method provided in the embodiment of the present application. The network architecture shown in Figure 3 is suitable for smaller networks.
[0260] As an example, for the network framework shown in Figure 3, the terminal identification process can refer to the method 200 shown in Figure 4. As shown in Figure 4, the method 200 may include:
[0261] S201: The user connects the terminal 40 to the network 3 shown in FIG3.
[0262] The terminal 40 may be a wired terminal, and then the terminal 40 may be connected to the access layer device 35 via a network cable; the terminal 40 may also be a wireless terminal, and then the terminal 40 may be connected to the access layer device 35 via a service set identifier (SSID).
[0263] S202: The user enables the terminal identification function on the network controller 30 and pre-configures the configuration information and network admission control policy of certain types of terminals in the network.
[0264] S203 , the network controller 30 performs a port scan on the terminal 40 to obtain the MAC address and open port information of the terminal 40 .
[0265] As an example, the network controller 30 can send the port detection message to the terminal 40 through the core layer device 31, the aggregation layer device 32 and the access layer device 35 in sequence. If the detected port on the terminal 40 is in an open state, the response message corresponding to the port is fed back to the network controller 30, so that the network controller 30 can determine the MAC address and open port information of the terminal 40 based on the received response message.
[0266] The scope of the port scan can be: terminals belonging to the target network segment, target VLAN or target BD, or terminals in the entire network. If a port scan is performed on terminals in the entire network, the port scan can be triggered by the Address Resolution Protocol (ARP) when the terminal goes online.
[0267] S204: The network controller 30 performs clustering based on the similarity between the MAC addresses and the open port information of the terminals to be identified, and obtains a clustering result. The terminals to be identified include the terminal 40 in FIG. 3 .
[0268] S205: The user marks the type of each cluster in the clustering result to obtain an identification result of the terminal to be identified.
[0269] S206 , based on the identification result, the network controller 30 automatically sends pre-configured content to the access layer device to which the terminal is connected, thereby achieving automatic control of the terminal.
[0270] The pre-configured content sent may include the configuration information of the corresponding type of terminal in the network and the network access control policy. For example, the identification result determines that terminal 40 belongs to cluster 1, and the type of cluster 1 is a printer. Then, the configuration information 1 and network access control policy 1 of the printer in the network can be sent to the access layer device 35 connected to the terminal 40. The configuration information 1 may include parameters such as the bandwidth and priority of the printer in the network. The network access control policy 1 may include automatic admission of the printer and access to VLAN 20.
[0271] In this way, through the method 200 provided in the embodiment of the present application, accurate identification of the terminal can be achieved in a scenario where the functions of port scanning and terminal identification are integrated into a communication device, providing a reliable data basis for terminal pre-configuration.
[0272] As shown in Figure 5, the network framework may include: a network controller 30, a network 3, and a terminal 40. The network 3 may include: a core layer device 31, an aggregation layer device 32, an aggregation layer device 33, an access layer device 34, an access layer device 35, and an access layer device 36. Among them, the network controller 30 at least has the function corresponding to the identification device in the method provided in the embodiment of the present application, and any device in the network 3 has the function corresponding to the port scanning device in the method provided in the embodiment of the present application. The method 300 shown in Figure 6 is described as an example in which the access layer device 35 has the function corresponding to the port scanning device in the method provided in the embodiment of the present application. The network architecture shown in Figure 5 is suitable for large-scale networks. In large-scale networks, the link between the network controller 30 and the terminal 40 may be disconnected, or the network controller 30 may perform port scanning on a large number of terminals, which is costly. In this case, it is not reasonable to integrate the functions corresponding to the identification device and the port scanning device on the network controller 30.
[0273] As an example, for the network framework shown in Figure 5, the process of terminal identification can refer to the method 600 shown in Figure 6. As shown in Figure 6, the method 300 may include:
[0274] S301: The user connects the terminal 40 to the network 3 shown in FIG5.
[0275] The terminal 40 may be a wired terminal, and then the terminal 40 may be connected to the access layer device 35 via a network cable; the terminal 40 may also be a wireless terminal, and then the terminal 40 may be connected to the access layer device 35 via an SSID.
[0276] S302: The user enables the terminal identification function on the network controller 30 and pre-configures the configuration information and network admission control policy of certain types of terminals in the network.
[0277] S303 , the network controller 30 notifies the access layer device 35 to perform a port scan on the terminal 40 .
[0278] S304 , the access layer device 35 performs a port scan on the terminal 40 to obtain the MAC address and open port information of the terminal 40 .
[0279] As an example, the access layer device 35 can send a port detection message to the terminal 40. If the detected port on the terminal 40 is in an open state, a response message corresponding to the port is fed back to the access layer device 35. Thus, the access layer device 35 can determine the MAC address and open port information of the terminal 40 based on the received response message.
[0280] S305 , the access layer device 35 sends the MAC address and open port information of the terminal 40 to the network controller 30 .
[0281] S306: The network controller 30 performs clustering based on the similarity between the MAC addresses and the open port information of the terminals to be identified, and obtains a clustering result. The terminals to be identified include the terminal 40 in FIG5 .
[0282] S307: The user marks the type of each cluster in the clustering result to obtain the identification result of the terminal to be identified.
[0283] S308 , based on the identification result, the network controller 30 automatically sends pre-configured content to the access layer device to which the terminal is connected, thereby achieving automatic control of the terminal.
[0284] As an example, S308 may include: the network controller 30 automatically sends the pre-configured content corresponding to the terminal 40 to the access layer device 35 based on the identification result. The pre-configured content sent may include but is not limited to: configuration information 1 of the terminal 40 in the network and the network access control policy 1 of the terminal 40.
[0285] In this way, through the method 300 provided in the embodiment of the present application, in a scenario where the functions of port scanning and terminal identification are integrated into two communication devices, accurate identification of the terminal can be achieved, providing a reliable data basis for terminal pre-configuration.
[0286] FIG7 is a flow chart of a terminal identification method 400 provided in an embodiment of the present application. In this method 400, the present application embodiment is described with the terminal to be identified as the execution subject. The terminal to be identified can be, for example, any terminal in FIG1 , or terminal 40 corresponding to the network framework shown in FIG3 or FIG5 below, or communication device 900 described below.
[0287] As shown in FIG7 , the method 400 may include, for example, the following steps S401 to S402 :
[0288] S401: Receive a port detection message for the target port of the terminal to be identified.
[0289] S402: If the target port is in an open state, a response message to the port detection message of the target port is sent, where the response message is used to guide identification of the type of the terminal to be identified.
[0290] Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes a target port, and the open port information is used to identify the type of the terminal to be identified.
[0291] In this way, considering that the terminal usually needs to open a specific port to connect to the server corresponding to the terminal, different types of terminals need to open different specific ports. Therefore, in this method 400, a port scan is performed on the terminal to be identified to obtain the open port information of the terminal to be identified, and thus, the type of the terminal to be identified is identified based on this. In the scenario where various types of terminals emerge in an endless stream, the recognition rate of the terminal can be guaranteed, overcoming the problem that the current terminal identification method needs to accumulate the fingerprint information of the terminal or requires business traffic (or business messages) after the terminal enters the network, and cannot guarantee the recognition rate of the terminal.
[0292] It should be noted that for the relevant description of method 400, please refer to the corresponding description of method 100, method 200 or method 300.
[0293] Accordingly, the embodiment of the present application also provides a communication device 800 (also referred to as a terminal identification device 800), as shown in Figure 8. The communication device 800 may correspond to the identification device 10 in Figure 1; the communication device 800 may also correspond to the network controller 30 in Figure 3 or Figure 5, specifically corresponding to the identification device in the network controller 30 for implementing the terminal identification function provided in the embodiment of the present application. The communication device 800 may include: an acquisition unit 801 and a processing unit 802. The processing unit 802 is used to perform the processing operations in the above method 100, method 200 or method 300; the acquisition unit 801 is used to perform other operations in the above method 100, method 200 or method 300 except the processing operations.
[0294] As an example, the acquisition unit 801 is configured to acquire open port information of multiple terminals, where the open port information of each terminal indicates at least one open port of each terminal. The acquisition unit 801 may execute S101 shown in FIG2 .
[0295] The processing unit 802 is configured to cluster multiple terminals according to the open port information of each terminal. The processing unit 802 may execute S102 shown in FIG2 .
[0296] The processing unit 802 is further configured to identify, based on the clustering result, at least one cluster to which the multiple terminals belong, wherein the terminals included in each cluster of the at least one cluster are of the same type. The processing unit 802 may execute S103 shown in FIG2 .
[0297] In some possible implementations, the acquisition unit 801 of the apparatus 800 is further configured to acquire the MAC address of each terminal; and the processing unit 802 is specifically configured to cluster multiple terminals according to the open port information of each terminal and the MAC address of each terminal.
[0298] In some possible implementations, the acquisition unit 801 of the apparatus 800 is further configured to acquire the IP address of each terminal; and the processing unit 802 is specifically configured to cluster multiple terminals according to the open port information of each terminal and the IP address of each terminal.
[0299] In some possible implementations, the acquiring unit 801 is specifically configured to receive open port information of multiple terminals sent by a port scanning device.
[0300] In some possible implementations, the acquiring unit 801 is specifically configured to acquire open port information of multiple terminals by performing port scanning on all ports or some designated ports of each terminal.
[0301] In some possible implementations, the acquiring unit 801 specifically performs any one of the following steps:
[0302] Scan ports of all terminals in the network to obtain information about open ports of multiple terminals.
[0303] Alternatively, by performing port scanning on terminals in the target network segment, information on open ports of multiple terminals can be obtained;
[0304] Alternatively, the open port information of multiple terminals can be obtained by performing port scanning on the terminals in the target VLAN;
[0305] Alternatively, the open port information of multiple terminals is obtained by performing port scanning on the terminals in the target BD.
[0306] In some possible implementations, the processing unit 802 is specifically configured to cluster the multiple terminals according to similarities in the open port information of the multiple terminals.
[0307] In some possible implementations, the processing unit 802 is specifically configured to determine the cluster of the known type to which each of the multiple terminals belongs based on similarities between the open port information of the multiple terminals and the open port information of each cluster of the known type.
[0308] In some possible implementations, the processing unit 802 is specifically configured to determine a type of each cluster in the at least one cluster.
[0309] As an example, processing unit 802 is specifically configured to: display the type of one or more clusters whose specific types cannot be identified as unknown; and manually mark the specific types of one or more clusters. Processing unit 802 of apparatus 800 is further configured to mark the specific types of clusters of unknown types. Processing unit 802 is specifically configured to: for any first cluster of the unknown type clusters, identify the type of one or more terminals in the first cluster and mark the type as the type of the first cluster.
[0310] As another example, the processing unit 802 is specifically configured to: for any second cluster in the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes the first target port, determine that the type of the second cluster is the first type corresponding to the first target port.
[0311] As another example, the processing unit 802 is specifically configured to: for any second cluster in the at least one cluster, in response to determining that one or more terminals in the second cluster belong to the first type, determine that the type of the second cluster is the first type.
[0312] For the second cluster, the processing unit 802 is further configured to, in response to an edit operation or a confirmation operation of the first type on the second cluster, determine that the type of the second cluster is a second type, which is the same as or different from the first type.
[0313] In some possible implementations, the processing unit 802 of the apparatus 800 is further configured to correct the clustering result.
[0314] As an example, the processing unit 802 is specifically configured to: when the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, change the cluster to which the terminal belongs according to the type of the terminal.
[0315] In some possible implementations, the processing unit 802 of the apparatus 800 is further configured to perform network admission control on the terminal based on the type of the terminal.
[0316] In some possible implementations, the processing unit 802 of the apparatus 800 is further configured to send configuration information to a terminal of the type based on the type of the terminal.
[0317] In some possible implementations, the apparatus 800 may be a network controller itself, or may be a functional module belonging to the network controller and used to implement the method provided in this application. The network controller may be, for example, a NAC.
[0318] It should be noted that various specific implementation modes of the communication device 800 can refer to the relevant introduction of method 100, method 200 or method 300, which will not be repeated in this embodiment.
[0319] Accordingly, an embodiment of the present application further provides a communication device 900 (also referred to as a terminal identification device 900), as shown in FIG9 . The communication device 900 is applied to a terminal to be identified. The communication device 900 may correspond to any terminal in FIG1 ; the communication device 900 may also correspond to the terminal 40 in FIG3 or FIG5 . The communication device 900 may include: a receiving unit 901 and a sending unit 902. Among them:
[0320] The receiving unit 901 is configured to receive a port detection message for a target port of the terminal to be identified. The receiving unit 901 may execute S401 shown in FIG7 .
[0321] The sending unit 902 is configured to send a response message to the port probe message for the target port if the target port is in an open state. The response message is used to guide the identification of the type of the terminal to be identified. Specifically, the response message is used to indicate that the open port information of the terminal to be identified includes the target port, and the open port information is used to identify the type of the terminal to be identified. The sending unit 901 can execute S402 shown in Figure 7.
[0322] It should be noted that various specific implementation modes of the communication device 900 can be found in the relevant introduction of the method 400, and will not be described in detail in this embodiment.
[0323] Referring to Figure 10 , an embodiment of the present application provides a communication device 1000. The communication device 1000 can be the execution subject of any of the above embodiments, for example, it can correspond to the identification device 10 or any terminal in Figure 1 , for example, it can correspond to the network controller 30 or terminal 40 in Figure 3 , for example, it can correspond to the network controller 30 or terminal 40 in Figure 5 . The communication device 1000 can implement the functions of the corresponding execution subjects in the above embodiments. The communication device 1000 includes at least one processor 1001, a bus system 1002, a memory 1003, and at least one communication interface 1004.
[0324] The communication device 1000 is a hardware structure device that can be used to implement the functional modules in the communication device 800 shown in Figure 8. For example, those skilled in the art can imagine that the acquisition unit 801 and the processing unit 802 in the communication device 800 shown in Figure 8 are implemented by the at least one processor 1001 calling the code in the memory 1003.
[0325] The communication device 1000 is a hardware structure device that can be used to implement the functional modules in the communication device 900 shown in Figure 9. For example, those skilled in the art can imagine that the receiving unit 901 and the sending unit 902 in the communication device 900 shown in Figure 9 are implemented by the at least one processor 1001 calling the code in the memory 1003.
[0326] Optionally, the communication device 1000 may be a network device or a control entity implementing an embodiment of the present application.
[0327] Optionally, the processor 1001 may be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0328] The bus system 1002 may include a channel for transmitting information between the components.
[0329] The communication interface 1004 is used to communicate with other devices or communication networks.
[0330] The memory 1003 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may exist independently and be connected to the processor via a bus. The memory may also be integrated with the processor.
[0331] The memory 1003 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 1001. The processor 1001 is used to execute the application code stored in the memory 1003, thereby realizing the functions of the method of the present application.
[0332] In a specific implementation, as an embodiment, the processor 1001 may include one or more CPUs, such as CPU0 and CPU1 in FIG10 .
[0333] In a specific implementation, as an embodiment, the communication device 1000 may include multiple processors, such as the processor 1001 and the processor 1007 in FIG10 . Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0334] It should be understood that the communication devices in the various product forms mentioned above respectively have any functions implemented by the execution subject in the above method embodiments, which will not be described in detail here.
[0335] The embodiment of the present application also provides a chip, including a processor and an interface circuit, the interface circuit is used to receive instructions and transmit them to the processor; the processor, for example, can be a specific implementation form in the embodiment of the present application, and can be used to execute the above-mentioned method 100, method 200, method 300 or method 400. The processor is coupled to a memory, and the memory is used to store programs or instructions. When the program or instructions are executed by the processor, the chip system implements the method in any of the above-mentioned method embodiments. In a specific implementation, when the chip provided by the present application can be specifically used to implement the operations performed by the communication device 800 described above, the interface circuit can be used to implement the relevant operations performed by the acquisition unit 801 in the communication device 800, and the processor can be used to implement the relevant operations performed by the processing unit 802 in the communication device 800.
[0336] Optionally, there may be one or more processors in the chip system. The processor may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0337] Optionally, the memory in the chip system may be one or more memories. The memory may be integrated with the processor or may be provided separately from the processor, which is not limited in this application. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or provided on different chips. This application does not specifically limit the type of memory or the configuration of the memory and the processor.
[0338] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chips.
[0339] In addition, an embodiment of the present application also provides a device that communicates with a linear direct-drive optical module, the device includes a first equalizer, and the linear direct-drive optical module includes a second equalizer; the device is used to execute the above-mentioned method 100 or method 200 to tune the parameters of the first equalizer and the second equalizer.
[0340] In addition, the embodiment of the present application further provides a communication system 1100, as shown in FIG11. The communication system 1100 may include a terminal to be identified 1101 and an identification device 1102. In particular:
[0341] Identification device 1102, configured to execute method 100, method 200, or method 300 to identify multiple terminals, where the multiple terminals include terminal 1101 to be identified;
[0342] The terminal 1101 to be identified is used to execute the above method 400.
[0343] Among them, the identification device 1102 can correspond to the identification device 10 shown in Figure 1 above, then the terminal 1101 to be identified can correspond to any terminal in Figure 1 (such as terminal 21); or, the identification device 1102 can correspond to the network controller 30 shown in Figure 3 above, then the terminal 1101 to be identified can correspond to the terminal 40 in Figure 3; or, the identification device 1102 can correspond to the network controller 30 shown in Figure 5 above, then the terminal 1101 to be identified can correspond to the terminal 40 in Figure 5; or, the identification device 1102 can correspond to the communication device 800 shown in Figure 8 above, then the terminal 1101 to be identified can correspond to the communication device 900 in Figure 9.
[0344] In addition, an embodiment of the present application further provides a storage medium, in which program code or instructions are stored. When the storage medium is run on a processor, the processor executes a method in any one of the implementation modes of the above embodiments.
[0345] In addition, an embodiment of the present application also provides a program product, which, when executed on a processor, enables the processor to execute any one of the aforementioned methods 100, 200, 300, or 400.
[0346] Current terminal identification relies on the correspondence between the fingerprint information of the terminal to be identified and the fingerprint information of the terminal to be identified, which is accumulated in the fingerprint database. However, as the boundaries between terminals become blurred, many terminals cannot accurately distinguish their specific types based on fingerprint information, making subsequent control such as terminal security access based on terminal type more difficult.
[0347] In some scenarios, enterprises want to identify the type of terminals brought by employees and use the terminal type as one of the criteria for automatic terminal access control. For example, for some companies in the financial industry or manufacturing industry, considering that employees' laptops may contain pirated software or store sensitive files or information, the automatic access control policy may include: prohibiting laptop terminals from accessing the network, while allowing other types of terminals (such as mobile phones and tablets) to access the network. Taking the type identification of tablets and laptops as an example, the current method of identifying the terminal type as a laptop or tablet is based on the terminal's HTTP UA. However, in order to obtain personal computer (PC)-level page layout, some tablets will modify their HTTP UA (hereinafter referred to as UA) to the laptop UA, making it impossible to identify the terminal type as a laptop or tablet based on the UA.
[0348] Based on this, an embodiment of the present application provides a terminal identification method, in which a web page is provided to the terminal, and the terminal's browser interface is called through the web page to obtain the terminal's capability information, and the terminal is effectively and accurately identified based on the terminal's capability information. Even if the boundaries of terminals in the network are vague, the method can distinguish the specific type of the terminal based on the obtained terminal capability information, thereby improving the accuracy of terminal identification to a certain extent. Among them, the terminal identification device can be deployed in a World Wide Web (Web, also known as the World Wide Web) server, or in other devices other than the web server. Taking the terminal identification device deployed in the web server as an example, the method may include: first, the web server provides a web page to the terminal; then, the terminal calls the terminal's browser interface through the web page to obtain the terminal's capability information, so that the web server obtains the terminal's capability information obtained by the terminal from the terminal; then, the web server identifies the type of the terminal based on the terminal's capability information. In this way, the browser interface of the terminal can be called through the Web page provided by the Web server to obtain the terminal capability information, so that the Web server with terminal identification function can accurately identify the specific type of the terminal based on the terminal capability information, overcoming the problem that the current terminal identification method cannot accurately identify the terminal type based on the terminal fingerprint information (such as HTTP UA). In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0349] The method provided in the embodiments of the present application can be adapted to various scenarios requiring terminal identification, such as automatic terminal access. The method provided in the embodiments of the present application can effectively identify the terminal type and ensure the accuracy of terminal identification. Through configuration within the network, terminals connected to the network can automatically connect to a web server and download web pages from the web server. The network configuration may include, but is not limited to, forced redirection to a web page or performing portal authentication on the web page.
[0350] For example, the network architecture applicable to the embodiments of the present application can be seen in Figure 12 . As shown in Figure 12 , the network architecture may include at least: a terminal identification device 10, a terminal 20 to be identified, and a web server 30. The web server 30 may be, for example, a portal server 30, and the terminal identification device 10 may be a functional module within a network controller 1. The network architecture may also include a network 4, which may include core layer devices 41, convergence layer devices 42, convergence layer devices 43, access layer devices 44, access layer devices 45, and access layer devices 46, with the terminal 20 connected to the access layer devices 45. The portal server 30 and the network controller 1 may access the network 4 via the core layer device 41. As an example, the identification process for the terminal 20 may include the following: first, after the terminal 20 accesses the network 4, the request message from the terminal 20, under the effect of portal authentication, causes the request message received by the portal server 30 to carry the address of the web page. Next, based on the address of the web page in the request message, the portal server 30 obtains the web page indicated by the address and sends the web page to the terminal 20 via the network 4. Next, after receiving the web page, terminal 20 executes the script in the web page: it calls the browser interface to obtain terminal 20's capability information; it then calls the network interface of network controller 1 to send the capability information of terminal 20 to terminal identification device 10 within network controller 1 via network 4. Finally, terminal identification device 10 within network controller 1 determines the type of terminal 20 based on the capability information. Thus, through the web page provided to terminal 20 by web server 30, terminal 20 can obtain its capability information and send it to terminal identification device 10, enabling terminal identification device 10 to perform refined identification of terminal 20 based on the capability information.
[0351] The network architecture applicable to the embodiment of the present application can also be seen in Figure 13. As shown in Figure 13, compared with the network architecture shown in Figure 12, the network architecture no longer includes the terminal identification device 10 and the Web server 30. The capabilities of the two can be combined on the network controller 13 or the authentication server 13. The network controller 13 or the authentication server 13 can realize the functions of the terminal identification device 10 and the Web server 30 in Figure 12. The network controller 13 or the authentication server 13 can interact with the terminal 20 to be identified through the network 4. The network 4 may include a core layer device 41, an aggregation layer device 42, an aggregation layer device 43, an access layer device 44, an access layer device 45 and an access layer device 46, and the terminal 20 is connected to the access layer device 45.
[0352] For example, the network architecture applicable to the embodiments of the present application can also be seen in Figure 14. As shown in Figure 14, compared with the network architecture shown in Figure 12, this network architecture no longer includes the terminal identification device 10 and the web server 30. The capabilities of both can be combined on any network device 4N in the network 4. The network device 4N can implement the functions of the terminal identification device 10 and the web server 30 in Figure 12. The network 4 may include a core layer device 41, an aggregation layer device 42, an aggregation layer device 43, an access layer device 44, an access layer device 45, and an access layer device 46, and the terminal 20 is connected to the access layer device 45. In Figure 14, the network device 4N is used as the access layer device 45 as an example.
[0353] The above Figures 12, 13 and 14 are merely illustrative of the network architecture applicable to the embodiments of the present application and do not limit the implementation scenarios of the embodiments of the present application.
[0354] In the embodiments of the present application, the terminal identification device can be any communication device in the network that has the ability to finely identify the terminal type based on the terminal's capability information. The communication device can be a network device such as a switch or router. Alternatively, the terminal identification device can be a functional module, component, or chip in any communication device in the network that has the ability to finely identify the terminal type based on the terminal's capability information, such as a single board or line card on a network device. It should be noted that the terminal identification device can be deployed in a web server as a module, component, or chip within the web server. The embodiments of the present application do not specifically limit the form and type of the terminal identification device.
[0355] In the embodiments of the present application, a web server can be any communication device in a network that has the ability to provide a web page to a terminal so that the terminal can obtain the terminal's capability information and send the terminal's capability information to a terminal identification device. The communication device can be a network device such as a switch or router. Alternatively, the web server can be a functional module, component, or chip in any communication device in a network that has the ability to provide a web page to a terminal to be identified so that the terminal can obtain the terminal's capability information and send the terminal's capability information to a terminal identification device, such as a single board or line card on a network device. The embodiments of the present application do not specifically limit the form and type of the web server.
[0356] In the embodiment of the present application, the terminal may refer to any terminal that can be deployed in the network, and the embodiment of the present application does not specifically limit the form and type of the terminal. For example, the terminal in the embodiment of the present application may be a smart terminal or a dumb terminal. Terminals can be divided into dumb terminals and smart terminals (also called smart terminals) according to whether they have processing functions. Dumb terminals may refer to a type of terminal that has no processing function and usually does not have a microprocessor. For example, printers, cameras, etc. are all dumb terminals; smart terminals may refer to terminals with certain processing functions. Such terminals have their own microprocessors and control circuits. For example, smart phones, laptops, etc. are all smart terminals. At present, some terminals with single functions and simple systems (such as smart screens) are usually classified as dumb terminals.
[0357] In order to introduce the embodiments of the present application more clearly, the method provided in the embodiments of the present application is described below with reference to a flow chart.
[0358] FIG15 is a flow chart of a terminal identification method 500 provided in an embodiment of the present application. In the method 500, an embodiment of the present application is introduced in an interactive manner between a Web server, a terminal identification device and a terminal. The Web server can be, for example, the Web server 30 in the network architecture shown in Figure 12, or the network controller 13 or the authentication server 13 in the network architecture shown in Figure 13, or the access layer device 45 in the network architecture shown in Figure 14, or the communication device 1900 or the communication device 2200, or the Web server 2301 in the communication system 2300; the terminal identification device can be, for example, the terminal identification device 10 in the network architecture shown in Figure 12, or the network controller 13 or the authentication server 13 in the network architecture shown in Figure 13, or the access layer device 45 in the network architecture shown in Figure 14, or the communication device 2000 or the communication device 2200, or the terminal identification device 2302 in the communication system 2300; the terminal can be, for example, the terminal 20 in the network architecture shown in Figure 12, Figure 13 or Figure 14, or the communication device 2100 or the communication device 2200, or the terminal 2303 in the communication system 2300.
[0359] Figure 15 is used as an example to illustrate that the Web server and the terminal identification device belong to two different communication devices. For the case where the two are combined in the same communication device, the interaction subject is simply changed from the terminal interacting with the two communication devices separately to the terminal interacting with the combined communication device, which does not affect the implementation of the embodiment of the present application.
[0360] As shown in FIG15 , the method 500 may include, for example, the following steps S501 to S507 :
[0361] S501: A web server receives a request message from a terminal, where the request message carries the address of a web page.
[0362] It should be noted that, in order to make the method 500 easier to understand, S501 which may be executed before S502 in an example is shown, and S501 can be understood as an optional step in the method 500.
[0363] The web server can be, for example, any communication device or functional module on a communication device capable of providing web pages to a terminal. Prior to step S501, the method 500 may further include: after the terminal accesses the network, sending a request message 1 to the network; the network processing the request message 1 to obtain the "request message" in step S501; and the network sending the "request message" to the web server.
[0364] Among them, if the terminal is a wired terminal, then the terminal access network can refer to: the terminal can be connected to the access layer device of the network through a network cable; if it is known to be a wireless terminal, then the terminal access network can refer to: the terminal is connected to the access layer device of the network through a service set identifier (SSID).
[0365] A terminal sends a request message 1 to a network. For example, the terminal may send the request message 1 to an access layer device connected to the network. Request message 1 may be used to request the opening of web page 1, and the request message 1 may include the URL of web page 1. As an example, the network processes request message 1 to obtain the "request message" in S501. This may include: the access layer device connected to the network modifies the URL of web page 1 included in request message 1 to the URL of web page 2, thereby obtaining the "request message" in S501, and the access layer device sends the "request message" to the web server. As another example, the network processes request message 1 to obtain the "request message" in S501. This may include: the access layer device connected to the network informs the terminal that web page 2 is to be accessed and provides the terminal with the URL of web page 2. The terminal modifies the URL of web page 1 included in request message 1 to the URL of web page 2, thereby obtaining the "request message" in S501, and the terminal sends the "request message" to the web server via the connected network. In S501 , the “web page” may refer to the web page 2 in the above example, and the “address of the web page” may refer to the URL of the web page 2 in the above example.
[0366] As an example, if the terminal's authentication method is 1902.1x or Media Access Control (MAC), a forced redirection function can be configured on the access layer device to which the terminal is connected. Request message 1 can be, for example, a network access request message sent by the terminal to the access layer device for 1902.1x or MAC authentication. This network access request message can be forcibly redirected by the access layer device to the "web page" in S501. In this example, the web server can be a 1902.1x authentication server, a MAC authentication server, a network controller, or other communication device capable of implementing the corresponding functions in this example.
[0367] As another example, if the terminal authentication method is Portal authentication, then the request message 1 sent by the terminal to the network may be, for example, a request message sent by the terminal to an access layer device of the network for Portal authentication. The request message corresponding to Portal authentication instructs connecting to a web server to download the "web page" in S501. In this example, the web server may be a Portal authentication server, a network controller, or other communication device capable of implementing the corresponding functions in this example.
[0368] S502: The web server provides the web page to the terminal based on the address of the web page.
[0369] S503: The terminal receives a web page sent by the web server.
[0370] In response to the terminal's request message for downloading a web page, the web server searches for the web page indicated by the web page address included in the request message and sends the web page to the terminal. If the "request message" in S501 is a network access request message for 1902.1x authentication (or MAC authentication), then the web page includes at least the 1902.1x authentication page (or MAC authentication page); if the "request message" in S501 is a request message for Portal authentication, then the web page includes at least the Portal authentication page.
[0371] In an embodiment of the present application, in addition to being able to render and display a specific web page on a terminal, a web page may also include a script. The content of the script includes: calling a browser interface to obtain the terminal's capability information. Optionally, the content of the script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, first information and second information may be added to the web page, with the first information used to indicate the acquisition of the terminal's capability information, and the second information used to indicate the provision of the terminal's capability information to the terminal identification device. The first information and the second information may be carried in a script on the web page, that is, in addition to the program segment for rendering and displaying the web page, a new script is added to the web page. The new script includes a program segment corresponding to the first information and a program segment corresponding to the second information; or the first information and the second information may be carried in two scripts on the web page, that is, in addition to the program segment for rendering and displaying the web page, two new scripts are added to the web page, one of which includes a program segment corresponding to the first information, and the other includes a program segment corresponding to the second information. In this way, by carrying the first information and the second information in the web page, the terminal can obtain the terminal's capability information and send it to the terminal identification device, enabling the terminal identification device to perform refined identification of the terminal based on the terminal's capability information.
[0372] In this way, by providing a web page that can call the browser interface of the terminal to obtain the capability information of the terminal to the terminal, it becomes possible to subsequently provide refined identification of the terminal based on the embodiments of the present application.
[0373] S504: The terminal calls the terminal's browser interface through the Web page to obtain the terminal's capability information.
[0374] It should be noted that after S503, method 500 may further include: the terminal rendering the received web page and displaying the web page on the display component of the terminal. Since the step of displaying the web page does not involve the core contribution of the embodiment of the present application, the step of displaying the web page is not described in detail. The embodiment of the present application does not limit the execution order of the step of displaying the web page and S504. The step of displaying the web page may be executed first and then S504, or S504 may be executed first and then the step of displaying the web page, or the step of displaying the web page and S504 may be executed simultaneously.
[0375] Capability information is used to indicate whether the terminal supports the target capability, which may include but is not limited to at least one of the following: touchscreen capability, media device capability, storage capability, or USB capability. Target capabilities can be determined based on the characteristics corresponding to the terminal's identification requirements. For example, for refined identification of laptops and tablets, considering that tablets support touchscreens but laptops do not, the target capability may include the terminal's touchscreen capability. For another example, for two types of terminals with similar message characteristics, considering that the capabilities of their media devices, such as cameras and microphones, are different, the target capability may include the terminal's media device capabilities.
[0376] In some possible implementations, if the web page includes a script that calls a browser interface to obtain terminal capability information, then S504 may include the terminal executing the web page script that calls a browser interface to obtain terminal capability information. The terminal obtains the capability information by calling the browser interface, providing a data basis for fine-grained identification of the terminal type.
[0377] For example, if the capability information includes touch screen capabilities, the terminal can obtain the terminal's touch screen capabilities by calling navigator.maxTouchPoints; if the capability information includes media device capabilities, the terminal can obtain the terminal's media device capabilities by calling navigator.mediaDevices. In navigator.mediaDevices, mediaDevices can be understood as a read-only property. After calling navigator.mediaDevices, the interface can return a media device (MediaDevices) object, which provides access to the terminal's connected media input devices (such as a camera or microphone) and / or screen sharing.
[0378] It can be seen that acquiring the capability information of the terminal through S504 provides a rich basis for the terminal identification device to reliably and effectively identify the terminal, thereby ensuring a certain recognition rate of the terminal identification device to accurately identify the terminal.
[0379] To further improve the reliability of terminal identification, the terminal type can be identified based on its capability information combined with its fingerprint information. Fingerprint information can be understood as information that can identify a terminal. For example, fingerprint information can include at least one of the following: MAC OUI, DHCP Option, mDNS, LLDP, UA, MAC address, or IP address.
[0380] In some possible implementations, the terminal identification device can identify the type of the terminal based on the capability information and UA information of the terminal. Then, the method 500 may further include: the terminal obtaining the UA information.
[0381] UA information, usually a string, is used to help identify the terminal type. For the definition of UA information, please refer to the introduction to UA in "https: / / developer.mozilla.org / en-US / docs / Web / API / Navigator / userAgent". The format of UA information can be: browser type field + system information field + platform field + platform details field + extensions field. For example, the UA information is: Mozilla / 5.0 (Macintosh; Intel Mac OS X 10_15_0) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 75.0.3770.210 Safari / 537.36, where Mozilla / 5.0 is the value of the browser type field, Macintosh; Intel Mac OS X 10_15_0 is the value of the system information field, AppleWebKit / 537.36 is the value of the platform field, KHTML, like Gecko is the value of the platform details field, and Chrome / 75.0.3770.210 Safari / 537.36 is the value of the extension field.
[0382] As an example, the script in the Web page also includes: a browser interface of the terminal to obtain the UA information of the terminal. Then, the terminal executes the script in the Web page to call the browser interface of the terminal to obtain the UA information of the terminal.
[0383] As another example, the message introducing the terminal's own attributes generated when the terminal joins the network may also include the terminal's UA information. Then, the terminal can obtain the terminal's UA information from the message by parsing the message introducing the terminal's own attributes.
[0384] In this way, the terminal can obtain UA information and combine it with the terminal's capability information as the basis for the terminal identification device to finely identify the terminal type, so that the terminal type can be effectively identified, the terminal recognition rate is guaranteed, and the recognition result is more accurate.
[0385] It should be noted that the UA information obtained in the embodiment of the present application may refer to a character string that can reflect real, complete and relatively more information of the terminal, for example, it may include information such as the hardware model of the terminal.
[0386] Currently, UA information generally has two common formats. Format 1 includes more information, including the device's hardware model. Format 2 sets many fixed values and excludes some device information. This is because UA information contains too much and complex information, making it difficult to easily obtain specific information. Furthermore, passive monitoring could potentially leak user privacy. Consequently, many standards and proposals, such as RFC8942 (see https: / / datatracker.ietf.org / doc / html / rfc8942) and the Web Incubator Community Group User-Agent Client Hints (WICG UA-CH) (see https: / / github.com / WICG / ua-client-hints), define UA information in Format 2. An example of UA information in Format 1 is as follows: Mozilla / 5.0 (Linux; Android 10; xxx Build / yyyxxx) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 78.0.32004.108 Mobile Safari / 537.36, where "xxx" can indicate the terminal's hardware model. However, in format 2, based on the WICG UA-CH definition, an example of UA information is as follows: Mozilla / 5.0 (Linux; Android 10; K) AppleWebKit / 537.36 (KHTML, like Gecko) Version / 4.0 Chrome / 71.0.0.0 Mobile Safari / 537.36, where the terminal's hardware model is replaced by a fixed value K. That is, regardless of the hardware model, the terminal's UA information includes K.
[0387] As an example, if the terminal obtains the UA information using format one, the UA information in the embodiment of the present application is obtained based on the web page, or the UA information in the embodiment of the present application is obtained by parsing the message in which the terminal introduces its own attributes.
[0388] As another example, if the UA information obtained by the terminal adopts format 2, then the UA information in the embodiment of the present application can be obtained as follows: in the message sent by the web server to the terminal for carrying the web page, add indication information, which is used to indicate the specific content of the UA information to be obtained. Among them, the message used to carry the web page can be, for example, an HTTP message, then the indication information can be carried in the response header (Response Header) of the HTTP message, and the indication information can be carried, for example, through the Accept-CH field in the response header. The specific content indicated by the indication information may include but is not limited to: user agent platform (UA-Platform), user agent platform version (UA-Platform-Version), user agent full version (UA-Full-Version), user agent architecture (UA-Arch), user agent model (UA-Model), user agent bitness (UA-Bitness), etc.
[0389] In other possible implementations, considering that there is a certain correlation between the terminal's MAC OUI, DHCP Option, mDNS, or LLDP fingerprint information and the terminal's type, the terminal identification device can identify the terminal's type based on the terminal's MAC OUI, DHCP Option, mDNS, or LLDP fingerprint information and the terminal's capability information. In this way, the terminal can more accurately identify the terminal's specific type based on the terminal's capability information and the terminal's MAC OUI, DHCP Option, mDNS, or LLDP fingerprint information, enabling refined terminal identification even when the terminal's boundaries are relatively vague.
[0390] In other possible implementations, given the characteristics of how the network assigns addresses to terminals and how users assign addresses to their own terminals, the terminal's fingerprint information may include the terminal's address information. The terminal identification device then determines the terminal's type based on the terminal's capability information and the terminal's address information. The address information may include at least one of the following: a MAC address or an IP address. This allows for more accurate identification of the terminal's specific type using the terminal's capability information and address information, enabling refined terminal identification even when the boundaries between terminals are vague.
[0391] S505: The terminal sends the terminal capability information to the terminal identification device.
[0392] S506: The terminal identification device receives the capability information of the terminal.
[0393] In some possible implementations, the content of the script in the web page may also include: calling a network interface to send the terminal capability information to the terminal identification device. Then, S505 may, for example, include: the terminal executes the script in the web page and sends the terminal capability information to the terminal identification device.
[0394] As an example, if the terminal identification device is deployed on a Web server, then the network interface can be a network interface opened by the Web server to the terminal, and S505 may include: the terminal sends the terminal's capability information to the network interface opened to the terminal by the Web server; S506 may include: the Web server receives the capability information sent by the terminal from the network interface opened to the terminal, so that the terminal identification device in the Web server obtains the capability information of the terminal.
[0395] As another example, if the terminal identification device is not deployed on the Web server, then the network interface may be a network interface opened to the terminal by the communication device where the terminal identification device is located, and S505 may include: the terminal sends the capability information of the terminal to the network interface opened to the terminal by the communication device where the terminal identification device is located; S506 may include: the communication device where the terminal identification device is located receives the capability information sent by the terminal from the network interface opened to the terminal, so that the terminal identification device of the communication device obtains the capability information of the terminal.
[0396] The terminal may carry its own capability information in any message interacting with the terminal identification device, and send the message to the terminal identification device, thereby achieving the purpose of sending its own capability information to the terminal identification device.
[0397] As an example, S505 may include: the terminal sending an HTTP message to the terminal identification device, the HTTP message carrying the terminal's capability information; then, S506 may include: the terminal identification device receiving the HTTP message from the terminal and obtaining the terminal's capability information by parsing the HTTP message. The HTTP message may carry the terminal's capability information via any extensible field; for example, the HTTP message may carry the terminal's capability information in a payload.
[0398] As another example, the terminal sends a Constrained Application Protocol (CoAP) message to the terminal identification device, where the CoAP message carries the terminal's capability information. Then, S506 may include: the terminal identification device receives the CoAP message from the terminal, and obtains the terminal's capability information by parsing the CoAP message. The CoAP message may carry the terminal's capability information through any extensible field. For example, the CoAP message may carry the terminal's capability information in a payload.
[0399] For S505 to S506, the communication device where the terminal identification device is located needs to open a network interface for the terminal to call the network interface and send its capability information to the communication device where the terminal identification device is located. The network interface can be, for example, the / detect / report interface of the communication device where the terminal identification device is located.
[0400] In this way, the terminal obtains the terminal capability information through the Web page and sends the terminal capability information to the terminal identification device, which prepares the terminal identification device for realizing effective and accurate identification of the terminal.
[0401] S507: The terminal identification device identifies the type of the terminal based on the capability information of the terminal.
[0402] In some possible implementations, S507 may include: the terminal identification device is capable of determining the type of the terminal based only on the capability information of the terminal.
[0403] In some other possible implementations, S507 may include: the terminal identification device is capable of determining the type of the terminal based on the capability information of the terminal and the fingerprint information of the terminal.
[0404] Taking the example of a terminal's fingerprint information including the terminal's UA information, and the terminal identification device determining the terminal's type based on the terminal's capability information and the terminal's UA information, for example, for terminal 1 and terminal 2, the terminal identification device obtains capability information 1 and UA information 1 for terminal 1, and obtains capability information 2 and UA information 2 for terminal 2. In one case, if the terminal identification device can determine that the types of terminal 1 and terminal 2 are laptop computers or tablet computers based on UA information 1 and UA information 2, but cannot further refine the identification to determine whether they are laptop computers or tablet computers, the terminal identification device can determine that terminal 1 supports touch screens based on capability information 1, and that terminal 2 does not support touch screens based on capability information 2. Thus, the terminal identification device can determine that terminal 1 is a tablet computer and terminal 2 is a laptop computer. In another case, if the terminal identification device can determine that the type of terminal 1 and terminal 2 is type 1 or type 2 based on UA information 1 and UA information 2, but cannot further refine the identification to determine whether it is type 1 or type 2, at this time, the terminal identification device can determine that the media capabilities of terminal 1 such as camera and microphone are media device capability 1 based on capability information 1, and determine that the media capabilities of terminal 2 such as camera and microphone are media device capability 2 based on capability information 2. Thus, the terminal identification device can determine that the type of terminal 1 is type 1 based on capability information 1, and determine that the type of terminal 2 is type 2 based on capability information 2.
[0405] In some possible implementations, after obtaining the identification result of the terminal (such as the type of the terminal), the identification result can be used in any scenario.
[0406] For example, the recognition results can be integrated into the user's digital map, displaying the user's network topology. When the user selects a point on the digital map, the map will also display the terminals deployed at that point. The displayed terminals are displayed based on the recognition results, and other terminal details can also be displayed. In this way, by integrating terminal recognition results into the digital map, the information provided to the user is enriched, making it easier for users to deploy, manage, and control their network.
[0407] For another example, network access control can be performed on terminals based on their type. For example, Terminal 1 (a mobile phone) and Terminal 2 (a tablet) are automatically allowed access and assigned to VLAN 210. Terminal 3 (a laptop) is automatically blocked and denied network access. By applying terminal identification results to automatic terminal access control scenarios, fast and efficient terminal management is achieved.
[0408] For another example, configuration information can be sent to various types of terminals based on their type, completing automatic network configuration for each type of terminal. This configuration information can be sent by a terminal identification device or other network device with information configuration capabilities to the network device to which the terminal is connected (such as the access layer device to which the terminal is connected) to configure the terminal. In this way, by applying the terminal identification results to the terminal's automatic configuration scenario, rapid and efficient terminal configuration is achieved.
[0409] It can be seen that through this method 500, in the web page provided by the web server to the terminal, the script of the web page includes content for obtaining the terminal's capability information and sending the terminal's capability information to the terminal identification device. After the terminal downloads the web page, it obtains and provides the terminal's capability information to the terminal identification device by executing the web page, so that the terminal identification device can accurately identify the specific type of the terminal based on the terminal's capability information. This overcomes the problem in the current terminal identification method that the terminal's fingerprint information (such as HTTP UA) cannot accurately identify the terminal type and cannot guarantee the terminal's recognition rate. In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0410] It should be noted that the embodiment of the present application is explained by taking the identification of the type of terminal as an example. The method provided in the embodiment of the present application can also use the terminal's capability information, or combine the terminal's capability information and the terminal's fingerprint information to realize the identification of other attribute information of the terminal. The other attribute information of the terminal may, for example, include but is not limited to at least one of the following information: the manufacturer to which the terminal belongs, the model of the terminal, or the operating system used by the terminal. The specific implementation method is not limited in the embodiment of the present application.
[0411] It should be noted that, in order to more clearly illustrate method 500, the embodiment of the present application is described in terms of the interaction between a web server, a terminal identification device, and a terminal. However, the operations performed by the web server, the terminal identification device, and the terminal in method 500 can each be implemented as a separate embodiment to achieve the technical effects of the method provided in the embodiment of the present application.
[0412] FIG16 is a flow chart of a terminal identification method 600 provided in an embodiment of the present application. In this method 600, the present application embodiment is described using a web server as the execution subject. The web server can be, for example, the web server 30 in the network architecture shown in FIG12 , the network controller 13 or authentication server 13 in the network architecture shown in FIG13 , the access layer device 45 in the network architecture shown in FIG14 , the communication device 1900 or the communication device 2200 , or the web server 2301 in the communication system 2300 .
[0413] As shown in FIG16 , the method 600 may include, for example, the following S601 to S602:
[0414] S601: The web server provides a web page to the terminal.
[0415] S602: The Web server calls the browser interface of the terminal through the Web page to obtain the capability information of the terminal.
[0416] It should be noted that, for the relevant description of S601, reference may be made to the corresponding description of S502 above; for the relevant description of S602, reference may be made to the corresponding description of S504 above.
[0417] Optionally, in the case where the terminal identification device is deployed on a Web server, after S602, the method 600 may further include: the Web server identifying the type of the terminal according to the capability information of the terminal. For a description of this step, please refer to the description corresponding to S507 above.
[0418] It can be seen that through method 600, the Web server adds a script to the Web page provided to the terminal, and the content of the script includes: calling the browser interface to obtain the terminal capability information and providing the terminal capability information to the terminal identification device. Therefore, after the terminal downloads the Web page, the terminal capability information is obtained and provided to the terminal identification device by executing the newly added script on the Web page, making it possible for the terminal identification device to accurately identify the specific type of the terminal based on the terminal capability information. This overcomes the problem in the current terminal identification method that the terminal type cannot be accurately identified based on the terminal fingerprint information. In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0419] FIG17 is a flow chart of a terminal identification method 700 provided in an embodiment of the present application. In this method 700, the present application embodiment is described with a terminal identification device as the execution subject. The terminal identification device can be, for example, the terminal identification device 10 in the network architecture shown in FIG12 , the network controller 13 or the authentication server 13 in the network architecture shown in FIG13 , the access layer device 45 in the network architecture shown in FIG14 , the communication device 2000 or the communication device 2200 , or the terminal identification device 2302 in the communication system 2300 .
[0420] As shown in FIG. 17 , the method 700 may include, for example, the following steps S701 to S702 :
[0421] S701: The terminal identification device receives capability information of the terminal.
[0422] The terminal capability information is obtained by executing a script in a web page. The content of the web page script includes: calling a browser interface of the terminal to obtain the terminal capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal capability information to the terminal identification device.
[0423] S702: The terminal identification device identifies the type of the terminal based on the capability information of the terminal.
[0424] It should be noted that, for the relevant description of S701 , reference may be made to the corresponding description of S506 ; for the relevant description of S702 , reference may be made to the corresponding description of S507 .
[0425] It can be seen that through this method 700, the terminal obtains the terminal capability information and provides the terminal capability information to the terminal identification device based on the script added to the web page downloaded from the web server. The terminal identification device can accurately identify the specific type of the terminal based on the terminal capability information, overcoming the problem that the current terminal identification method cannot accurately identify the terminal type based on the terminal fingerprint information. In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0426] Figure 18 is a flow chart of a terminal identification method 800 provided in an embodiment of the present application. In this method 800, the present application embodiment is described with a terminal as the execution subject. The terminal can be, for example, terminal 20 in the network architecture shown in Figures 12, 13, or 14, or communication device 2100 or communication device 2200, or terminal 2303 in communication system 2300.
[0427] As shown in FIG18 , the method 800 may include, for example, the following steps S801 to S803 :
[0428] S801: A terminal receives a web page sent by a web server.
[0429] S802: The terminal executes a script on the web page. The content of the script includes: calling a browser interface to obtain capability information of the terminal.
[0430] S803: The terminal sends the terminal capability information to the terminal identification device.
[0431] It should be noted that, for the relevant description of S801, reference may be made to the corresponding description of S503 above; for the relevant description of S802, reference may be made to the corresponding description of S504 above; and for the relevant description of S803, reference may be made to the corresponding description of S505 above.
[0432] As an example, the content of the script may further include: calling a network interface to send the terminal capability information to the terminal identification device; then, S803 may include: the terminal sending the terminal capability information to the terminal identification device through the network interface.
[0433] The terminal identification device may be deployed in the Web server, and the network interface may be a network interface opened by the Web server to the terminal. Alternatively, the terminal identification device may not be deployed in the Web server, and the network interface may be a network interface opened by the communication device where the terminal identification device is located to the terminal.
[0434] It can be seen that through this method 800, the terminal obtains the terminal capability information and provides the terminal capability information to the terminal identification device based on the script added to the web page downloaded from the web server, making it possible for the terminal identification device to accurately identify the specific type of the terminal based on the terminal capability information. This overcomes the problem that the current terminal identification method cannot accurately identify the type of the terminal based on the terminal fingerprint information. In scenarios where various types of terminals emerge in an endless stream and the boundaries between terminals are relatively vague, the accuracy of terminal identification can be improved.
[0435] Accordingly, an embodiment of the present application further provides a communication device 1900 (also referred to as a terminal identification device 1900), which is applied to a web server, as shown in FIG19 . The communication device 1900 may correspond to the operations performed by the web server and the terminal identification device in method 500, or to the operations performed by the web server in method 600. The communication device 1900 may correspond to the network controller 13 in FIG13 ; the communication device 1900 may also correspond to the access layer device 45 in FIG14 , or may correspond to the communication system 2300 described below. The communication device 1900 may include: a sending unit 1901, a receiving unit 1902, and a processing unit 1903.
[0436] The sending unit 1901 is configured to provide a Web page type to the terminal. The sending unit 1901 may execute S502 shown in FIG15 or S601 shown in FIG16 .
[0437] The receiving unit 1902 is configured to call the browser interface of the terminal through a web page to obtain the capability information of the terminal. The receiving unit 1902 may execute S506 shown in FIG15 or S602 shown in FIG16 .
[0438] The processing unit 1903 is configured to identify the type of the terminal according to the capability information of the terminal. The processing unit 1903 may execute S507 shown in FIG15 .
[0439] In a possible implementation, the web page includes a script, and the content of the script may include: calling a browser interface to obtain capability information of the terminal.
[0440] As an example, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. In one scenario, the terminal identification device may be deployed in a web server, in which case the network interface may be a network interface exposed by the web server to the terminal. In another scenario, the terminal identification device may not be deployed in a web server, in which case the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0441] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0442] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the processing unit 1903 is specifically used to: identify the type of the terminal based on the terminal capability information and the terminal fingerprint information, where the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0443] It should be noted that various specific implementation modes of the communication device 1900 can be found in the relevant introduction of method 500 or method 600, and will not be repeated in this embodiment.
[0444] Accordingly, an embodiment of the present application further provides a communication device 2000 (also referred to as a terminal identification device 2000), which is applied to a terminal identification device, as shown in FIG20 . The communication device 2000 may correspond to the operations performed by the terminal identification device in method 500 or method 700. The communication device 2000 may correspond to the terminal identification device 10 in FIG12 ; the communication device 2000 may also correspond to the network controller 13 in FIG13 ; the communication device 2000 may also correspond to the access layer device 45 in FIG14 , and may also correspond to the third communication entity in the communication system 2300 described below. The communication device 2000 may, for example, include a receiving unit 2001 and a processing unit 2002.
[0445] The receiving unit 2001 is configured to receive capability information of a terminal. The receiving unit 2001 may execute S506 shown in FIG15 or S701 shown in FIG17 .
[0446] The processing unit 2002 is configured to identify the type of the terminal based on the capability information of the terminal. The processing unit 2002 may execute S507 shown in FIG15 or S702 shown in FIG17 .
[0447] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The content of the web page script includes: calling the terminal's browser interface to obtain the terminal's capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in the web server. In this case, the network interface may be a network interface exposed to the terminal by the communication device where the terminal identification device resides.
[0448] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0449] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the processing unit 2002 is specifically used to: identify the type of the terminal based on the terminal capability information and the terminal fingerprint information, where the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0450] It should be noted that various specific implementation modes of the communication device 2000 can be found in the relevant introduction of method 500 or method 700, and will not be repeated in this embodiment.
[0451] Accordingly, an embodiment of the present application further provides a communication device 2100 (also referred to as a terminal identification device 2100), which is applied to a terminal, as shown in FIG21. The communication device 2100 may correspond to the operations performed by the terminal in method 500 or method 800. The communication device 2100 may correspond to the terminal 20 in FIG12, FIG13, or FIG14; it may also correspond to the second communication entity in the communication system 2300 described below. The communication device 2100 may, for example, include a receiving unit 2101, a processing unit 2102, and a sending unit 2103.
[0452] The receiving unit 2101 is configured to receive a web page sent by a web server. The receiving unit 2101 may execute S503 shown in FIG15 or S801 shown in FIG18 .
[0453] The processing unit 2102 is configured to execute the script of the web page. The content of the script may include: calling the browser interface to obtain the capability information of the terminal. The processing unit 2102 may execute S504 shown in FIG15 or S802 shown in FIG18.
[0454] The sending unit 2103 is configured to send the terminal capability information to the terminal identification apparatus. The sending unit 2103 may execute S505 shown in FIG15 or S803 shown in FIG18 .
[0455] In one possible implementation, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. Then, the sending unit 2103 is specifically configured to transmit the terminal's capability information to the terminal identification device via the network interface. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in a web server. In this case, the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0456] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0457] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the communication device 2100 may also include an acquisition unit, which is used to obtain fingerprint information of the terminal; a sending unit 2103 is also used to send the fingerprint information of the terminal to the terminal identification device, and the fingerprint information of the terminal includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0458] It should be noted that various specific implementation modes of the communication device 2100 can be found in the relevant introduction of method 500 or method 800, and will not be repeated in this embodiment.
[0459] Referring to Figure 22 , an embodiment of the present application provides a communication device 2200. The communication device 2200 can be an execution subject in any of the above-mentioned embodiments, and can correspond to, for example, the terminal identification device 10, web server 30, or terminal 20 in Figure 12 , the network controller 13 or terminal 20 in Figure 13 , the access layer device 45 or terminal 20 in Figure 14 , or the communication device 1900, communication device 2000, or communication device 2100 described above. The communication device 2200 can implement the functions of the corresponding execution subjects in the above-mentioned embodiments. The communication device 2200 includes at least one processor 2201, a bus system 2202, a memory 2203, and at least one communication interface 2204.
[0460] The communication device 2200 is a hardware device that can be used to implement the functional modules in the communication device 1900 shown in Figure 19. For example, those skilled in the art can imagine that the sending unit 1901, the receiving unit 1902, and the processing unit 1903 in the communication device 1900 shown in Figure 19 are implemented by the at least one processor 2201 calling the code in the memory 2203.
[0461] The communication device 2200 is a hardware device that can be used to implement the functional modules in the communication device 2000 shown in Figure 20. For example, those skilled in the art can imagine that the receiving unit 2001 and the processing unit 2002 in the communication device 2000 shown in Figure 20 are implemented by the at least one processor 2201 calling the code in the memory 2203.
[0462] The communication device 2200 is a hardware device that can be used to implement the functional modules in the communication device 2100 shown in Figure 21. For example, those skilled in the art can imagine that the receiving unit 2101, the processing unit 2102, and the sending unit 2103 in the communication device 2100 shown in Figure 21 are implemented by the at least one processor 2201 calling the code in the memory 2203.
[0463] Optionally, the communication device 2200 may be a network device or a control entity implementing an embodiment of the present application.
[0464] Optionally, the processor 2201 may be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0465] The bus system 2202 may include a channel for transmitting information between the components.
[0466] The communication interface 2204 is used to communicate with other devices or communication networks.
[0467] The memory 2203 may be a read-only memory (ROM) or other static storage device capable of storing static information and instructions, a random access memory (RAM) or other dynamic storage device capable of storing information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but not limited thereto. The memory may be independent and connected to the processor via a bus. The memory may also be integrated with the processor.
[0468] The memory 2203 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 2201. The processor 2201 is used to execute the application code stored in the memory 2203, thereby realizing the functions of the method of the present application.
[0469] In a specific implementation, as an embodiment, the processor 2201 may include one or more CPUs, such as CPU0 and CPU1 in Figure 22.
[0470] In a specific implementation, as an embodiment, the communication device 2200 may include multiple processors, such as the processor 2201 and the processor 2207 in FIG22 . Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0471] It should be understood that the communication devices in the various product forms mentioned above respectively have any functions implemented by the execution subject in the above method embodiments, which will not be described in detail here.
[0472] The embodiment of the present application further provides a chip system, including a processor and an interface circuit, the interface circuit being configured to receive instructions and transmit them to the processor; the processor, for example, may be a specific implementation form in the embodiment of the present application, and may be configured to execute the above-mentioned method 500, method 600, method 700, or method 800. The processor is coupled to a memory, and the memory is configured to store programs or instructions. When the programs or instructions are executed by the processor, the chip system implements the method in any of the above-mentioned method embodiments. The chip system may include one or more chips. The chip system may, for example, be the following communication system 2300.
[0473] In a specific implementation, when the chip system provided in this application can be specifically used to implement the operations performed by the communication device 1900 described above, the interface circuit can be used to implement the relevant operations performed by the sending unit 1901 and the receiving unit 1902 in the communication device 1900, and the processor can be used to implement the relevant operations performed by the processing unit 1903 in the communication device 1900.
[0474] In a specific implementation, when the chip system provided in this application can be specifically used to implement the operations performed by the communication device 2000 described above, the interface circuit can be used to implement the relevant operations performed by the receiving unit 2001 in the communication device 2000, and the processor can be used to implement the relevant operations performed by the processing unit 2002 in the communication device 2000.
[0475] In a specific implementation, when the chip system provided in this application can be specifically used to implement the operations performed by the communication device 2100 described above, the interface circuit can be used to implement the relevant operations performed by the sending unit 2103 and the receiving unit 2101 in the communication device 2100, and the processor can be used to implement the relevant operations performed by the processing unit 2102 in the communication device 2100.
[0476] Optionally, there may be one or more processors in the chip system. The processor may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0477] Optionally, the memory in the chip system may be one or more. The memory may be integrated with the processor or may be provided separately from the processor, which is not limited in this application. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or provided on different chips. This application does not specifically limit the type of memory or the configuration of the memory and the processor.
[0478] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chips.
[0479] In addition, the embodiment of the present application further provides a communication system 2300, as shown in Figure 23. The communication system 2300 may include a first communication entity 2301, a second communication entity 2302, and a third communication entity 2303.
[0480] The first communication entity 2301 is used to provide a web page to the terminal;
[0481] The second communication entity 2302 is configured to call the browser interface of the terminal through the Web page to obtain capability information of the terminal;
[0482] The third communication entity 2303 is configured to identify the type of the terminal according to the capability information of the terminal.
[0483] As an example, if communication system 2300 is a web server, then first communication entity 2301, second communication entity 2302, and third communication entity 2303 are components within the web server. In this case, communication system 2300 may correspond to network controller 13 in FIG. 13 or access layer device 45 in FIG. 14; first communication entity 2301 and second communication entity 2302 correspond to portions of network controller 13 or access layer device 45 that implement web server functionality, for which specific reference may be made to the operations performed by the web server in method 500, method 600, or communication device 1900; and third communication entity 2303 corresponds to portions of network controller 13 or access layer device 45 that implement terminal identification functionality, for which specific reference may be made to the operations performed by the terminal identification device in method 500, method 700, or communication device 2000.
[0484] As another example, the first communication entity 2301 is a web server, the second communication entity 2302 is a terminal, and the third communication entity 2303 is a terminal identification device. In this case, the communication system 2300 may correspond to the network architecture shown in FIG12 , wherein the first communication entity 2301 corresponds to the web server 30, for which specific reference may be made to the operations performed by the web server in the aforementioned method 500, or to the method 600, or to the aforementioned communication device 1900; the second communication entity 2302 corresponds to the terminal 20, for which specific reference may be made to the operations performed by the terminal in the aforementioned method 500, or to the method 800, or to the aforementioned communication device 2100; and the third communication entity 2303 corresponds to the terminal identification device 10, for which specific reference may be made to the operations performed by the terminal identification device in the aforementioned method 500, or to the method 700, or to the aforementioned communication device 2000.
[0485] As an embodiment, the Web page includes a script, and the content of the script may include: calling the browser interface to obtain the capability information of the terminal.
[0486] As an embodiment, the content of the script may further include: calling a network interface to send the capability information of the terminal to the third communication entity.
[0487] In addition, an embodiment of the present application further provides a computer storage medium, which includes instructions. When the instructions are executed on a processor, the following method is implemented:
[0488] Provide web pages to terminals;
[0489] Use the web page to call the terminal's browser interface to obtain the terminal's capability information.
[0490] In one possible implementation, when the instructions of the computer storage medium are executed on a processor, the following method is also implemented:
[0491] Identify the terminal type based on the terminal's capability information.
[0492] In a possible implementation, the web page includes a script, and the content of the script may include: calling a browser interface to obtain capability information of the terminal.
[0493] As an example, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. In one scenario, the terminal identification device may be deployed in a web server, in which case the network interface may be a network interface exposed by the web server to the terminal. In another scenario, the terminal identification device may not be deployed in a web server, in which case the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0494] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0495] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0496] It should be noted that for the relevant description of the computer storage medium, reference may be made to the corresponding description of method 500 or method 600 .
[0497] In addition, an embodiment of the present application further provides a computer storage medium, which includes instructions. When the instructions are executed on a processor, the following method is implemented:
[0498] Receive web pages sent by the web server;
[0499] Execute the script on the web page. The script includes: calling the browser interface to obtain the terminal's capability information; and
[0500] The terminal capability information is sent to the terminal identification device.
[0501] In one possible implementation, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. When the instructions of the computer storage medium are executed on the processor, the following method is specifically implemented: transmitting the terminal's capability information to the terminal identification device via the network interface. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in a web server. In this case, the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0502] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0503] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0504] It should be noted that for the relevant description of the computer storage medium, please refer to the corresponding description of method 500 or method 800.
[0505] In addition, an embodiment of the present application further provides a computer storage medium, which includes instructions. When the instructions are executed on a processor, the following method is implemented:
[0506] receiving terminal capability information;
[0507] Identify the type of terminal based on the terminal's capability information.
[0508] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The content of the web page script includes: calling the terminal's browser interface to obtain the terminal's capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in the web server. In this case, the network interface may be a network interface exposed to the terminal by the communication device where the terminal identification device resides.
[0509] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0510] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, when the instructions of the computer storage medium are executed on the processor, the following method is specifically implemented: based on the terminal capability information and the terminal fingerprint information, the terminal type is identified, and the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0511] It should be noted that for the relevant description of the computer storage medium, please refer to the corresponding description of method 500 or method 700.
[0512] In addition, an embodiment of the present application further provides a computer program product, which includes a computer program; when the computer program is run on a processor, the following method is implemented:
[0513] Provide web pages to terminals;
[0514] Use the web page to call the terminal's browser interface to obtain the terminal's capability information.
[0515] In a possible implementation manner, when the computer program of the computer program product runs on a processor, the following method is further implemented:
[0516] Identify the terminal type based on the terminal's capability information.
[0517] In a possible implementation, the web page includes a script, and the content of the script may include: calling a browser interface to obtain capability information of the terminal.
[0518] As an example, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. In one scenario, the terminal identification device may be deployed in a web server, in which case the network interface may be a network interface exposed by the web server to the terminal. In another scenario, the terminal identification device may not be deployed in a web server, in which case the network interface may be a network interface exposed by the communication device containing the terminal identification device to the terminal.
[0519] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0520] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0521] It should be noted that for the relevant description of the computer program product, please refer to the corresponding description of method 500 or method 600.
[0522] In addition, an embodiment of the present application further provides a computer program product, which includes a computer program; when the computer program is run on a processor, the following method is implemented:
[0523] Receive web pages sent by the web server;
[0524] Execute the script on the web page. The script includes: calling the browser interface to obtain the terminal's capability information; and
[0525] The terminal capability information is sent to the terminal identification device.
[0526] In one possible implementation, the script may also include invoking a network interface to transmit the terminal's capability information to the terminal identification device. When the computer program of the computer program product runs on a processor, the following method is specifically implemented: transmitting the terminal's capability information to the terminal identification device via the network interface. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in a web server. In this case, the network interface may be a network interface exposed to the terminal by a communication device containing the terminal identification device.
[0527] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0528] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, the terminal identification device identifies the type of the terminal based on the terminal's capability information and the terminal's fingerprint information, where the terminal's fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address, or IP address.
[0529] It should be noted that for the relevant description of the computer program product, please refer to the corresponding description of method 500 or method 800.
[0530] In addition, an embodiment of the present application further provides a computer program product, which includes a computer program; when the computer program is run on a processor, the following method is implemented:
[0531] receiving terminal capability information;
[0532] Identify the type of terminal based on the terminal's capability information.
[0533] In one possible implementation, the terminal's capability information is obtained by executing a script in a web page. The content of the web page script includes: calling the terminal's browser interface to obtain the terminal's capability information. Optionally, the content of the web page script may also include: calling a network interface to send the terminal's capability information to the terminal identification device. As an example, the terminal identification device may be deployed in a web server. In this case, the network interface may be a network interface exposed by the web server to the terminal. As another example, the terminal identification device may not be deployed in the web server. In this case, the network interface may be a network interface exposed to the terminal by the communication device where the terminal identification device resides.
[0534] In a possible implementation, the capability information of the terminal may include at least one of the following: touch screen capability, media device capability, storage capability, or USB capability.
[0535] In one possible implementation, in order to further improve the reliability and accuracy of terminal identification, when the computer program of the computer program product runs on a processor, the following method is specifically implemented: based on the terminal capability information and the terminal fingerprint information, the terminal type is identified, and the terminal fingerprint information includes at least one of the following: MAC OUI, DHCP Option, HTTP UA, mDNS, LLDP, MAC address or IP address.
[0536] It should be noted that for the relevant description of the computer program product, please refer to the corresponding description of method 500 or method 700.
[0537] It should be understood that "determining B based on A" mentioned in the embodiments of the present application does not mean determining B only based on A, but B can also be determined based on A and / or other information.
[0538] It should be understood that the network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0539] In this application, ordinal numbers such as "1", "2", "3", "first", "second" and "third" are used to distinguish multiple objects and are not used to limit the order of multiple objects.
[0540] “A and / or B” mentioned in this application should be understood to include the following situations: only A, only B, or both A and B.
[0541] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or certain parts of the embodiments of the present application.
[0542] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments and device embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The device and system embodiments described above are merely schematic. The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative effort.
[0543] The above description is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application. It should be noted that those skilled in the art may make several improvements and modifications without departing from the scope of protection of the present application, and such improvements and modifications should also be considered as within the scope of protection of the present application.
Claims
1. A terminal identification method, characterized in that: The method comprises: Acquire open port information of a plurality of terminals, where the open port information of each terminal indicates at least one port of each terminal that is in an open state; Clustering the multiple terminals according to the open port information of each terminal; According to the clustering result, at least one cluster to which the plurality of terminals belong is identified, and the terminals included in each of the at least one cluster belong to the same type.
2. The method according to claim 1, characterized in that The method further comprises: Obtaining a media access control MAC address of each terminal; The clustering of the plurality of terminals according to the open port information of each terminal includes: The multiple terminals are clustered according to the open port information of each terminal and the MAC address of each terminal.
3. The method according to claim 1 or 2, characterized in that The obtaining of the open port information of the plurality of terminals includes: Receive the open port information of the multiple terminals sent by the port scanning device.
4. The method according to any one of claims 1 to 3, characterized in that The obtaining of the open port information of the plurality of terminals includes: The open port information of the multiple terminals is obtained by performing port scanning on all ports or part of the designated ports of each terminal.
5. The method according to any one of claims 1 to 4, characterized in that The obtaining of the open port information of the plurality of terminals includes any one of the following: Performing port scanning on all terminals in the network to obtain open port information of the terminals; Alternatively, by performing port scanning on terminals in the target network segment, the open port information of the plurality of terminals is obtained; Alternatively, the open port information of the plurality of terminals is obtained by performing port scanning on the terminals in the target virtual local area network VLAN; Alternatively, the open port information of the multiple terminals is obtained by performing port scanning on the terminals in the target broadcast domain BD.
6. The method according to any one of claims 1 to 5, characterized in that The clustering of the multiple terminals according to the open port information of the multiple terminals includes: The multiple terminals are clustered according to similarities in the open port information of the multiple terminals.
7. The method according to any one of claims 1 to 5, characterized in that The clustering of the multiple terminals according to the open port information of the multiple terminals includes: The cluster of the known type to which each of the plurality of terminals belongs is determined based on similarities between the open port information of the plurality of terminals and the open port information of each cluster of the known type.
8. The method according to any one of claims 1 to 6, characterized in that The step of identifying at least one cluster to which the plurality of terminals belong based on the clustering result includes: A type of each cluster of the at least one cluster is determined.
9. The method according to claim 8, characterized in that The determining the type of each cluster in the at least one cluster includes: For one or more clusters whose specific types cannot be identified, the types of the one or more clusters are displayed as unknown types; and the specific types of the one or more clusters are manually marked.
10. The method according to claim 9, characterized in that The specific type of marking for the unknown type of cluster includes: For any first cluster of the clusters of unknown type, the type of one or more terminals in the first cluster is identified, and the type is marked as the type of the first cluster.
11. The method according to claim 8, characterized in that The determining the type of each cluster in the at least one cluster includes: For any second cluster of the at least one cluster, in response to determining that the open port information of each terminal in the second cluster includes a first target port, the type of the second cluster is determined to be a first type corresponding to the first target port.
12. The method according to claim 11, characterized in that The determining the type of each cluster in the at least one cluster further includes: In response to an edit operation or a confirmation operation of the first type on the second cluster, the type of the second cluster is determined to be a second type, which is the same as or different from the first type.
13. The method according to any one of claims 1 to 12, characterized in that The method further comprises: The clustering result is corrected.
14. The method according to claim 13, characterized in that The modifying of the clustering result includes: When the type of the terminal is inconsistent with the type of the cluster to which the terminal belongs, the cluster to which the terminal belongs is changed according to the type of the terminal.
15. The method according to any one of claims 1 to 14, characterized in that The method further comprises: Perform network access control on terminals based on their types; Alternatively, based on the type of the terminal, the configuration information is sent to the terminal of that type.
16. The method according to any one of claims 1 to 15, characterized in that The method is applied to a network controller.
17. A communication device, characterized in that: The communication device includes an acquisition unit and a processing unit; The processing unit is configured to perform the processing operation in the method according to any one of claims 1 to 16 above; The acquisition unit is used to perform other operations except the processing operation in the method according to any one of claims 1 to 6.
18. A storage medium, characterized in that The storage medium includes instructions, and when the instructions are executed on a processor, the processor is caused to execute the method according to any one of claims 1 to 16.
19. A program product, characterized in that The program product includes a program, and when the program is run on a processor, the method according to any one of claims 1 to 16 is executed.
20. A terminal identification method, characterized in that: The method comprises: Providing a web page to the terminal; Invoking the browser interface of the terminal through the Web page to obtain capability information of the terminal; The type of the terminal is identified according to the capability information of the terminal.
21. The method according to claim 20, characterized in that The capability information of the terminal includes at least one of the following: touch screen capability, media device capability, storage capability or universal serial bus (USB) capability.
22. The method according to claim 20 or 21, characterized in that The web page includes a script, and the content of the script includes: calling the browser interface to obtain the capability information of the terminal.
23. The method according to claim 22, characterized in that The content of the script also includes: calling a network interface to send the capability information of the terminal to a terminal identification device.
24. The method according to claim 23, wherein The network interface is a network interface opened by a Web server to the terminal, and the terminal identification device is deployed in the Web server.
25. The method according to any one of claims 20 to 24, characterized in that The identifying the type of the terminal according to the capability information of the terminal includes: Identify the type of the terminal based on the capability information of the terminal and the fingerprint information of the terminal, where the fingerprint information of the terminal includes at least one of the following: a media access control organization unique identifier (MACOUI), a dynamic host configuration protocol option (DHCPOption), a hypertext transfer protocol user agent (HTTPUserAgent), a multicast domain name resolution service (mDNS), a link layer discovery protocol (LLDP), a media access control (MAC) address, or an internet protocol (IP) address.
26. The method according to any one of claims 20 to 25, characterized in that The method is applied to a Web server.
27. A terminal identification method, characterized in that: The method comprises: Receive web pages sent by the web server; Executing a script on the web page, the script includes: calling a browser interface to obtain capability information of the terminal; and The capability information of the terminal is sent to the terminal identification device.
28. The method according to claim 27, characterized in that The content of the script further includes: calling a network interface to send the capability information of the terminal to the terminal identification device; sending the capability information of the terminal to the terminal identification device includes: The capability information of the terminal is sent to the terminal identification device through the network interface.
29. The method according to claim 28, characterized in that The network interface is a network interface opened by a Web server to the terminal, and the terminal identification device is deployed in the Web server.
30. A communication system, characterized in that: The communication system includes a first communication entity, a second communication entity and a third communication entity; The first communication entity is configured to provide a web page to the terminal; The second communication entity is configured to call a browser interface of the terminal through the web page to obtain capability information of the terminal; The third communication entity is configured to identify the type of the terminal according to the capability information of the terminal.
31. The communication system according to claim 30, wherein: The communication system is a Web server, and the first communication entity, the second communication entity, and the third communication entity are components within the Web server.
32. The communication system according to claim 30, wherein: The first communication entity is a Web server, the second communication entity is the terminal, and the third communication entity is a terminal identification device.
33. The communication system according to any one of claims 30 to 32, characterized in that: The web page includes a script, and the content of the script includes: calling the browser interface to obtain the capability information of the terminal.
34. The communication system according to claim 33, wherein: The content of the script also includes: calling a network interface to send the capability information of the terminal to the third communication entity.
35. A communication device, characterized in that: The communication device includes a receiving unit, a processing unit and a sending unit; The receiving unit is used to receive a web page sent by a web server; The processing unit is configured to execute a script on the web page, wherein the script includes: calling a browser interface to obtain capability information of the terminal; as well as The sending unit is configured to send the capability information of the terminal to the terminal identification device.
36. A computer storage medium, characterized in that The computer storage medium includes instructions that, when executed on a processor, implement the following method: Provide web pages to terminals; The capability information of the terminal is acquired by calling the browser interface of the terminal through the Web page.
37. A computer storage medium, characterized in that The computer storage medium includes instructions that, when executed on a processor, implement the following method: Receive web pages sent by the web server; Executing a script on the web page, the script includes: calling a browser interface to obtain capability information of the terminal; as well as The capability information of the terminal is sent to the terminal identification device.
38. A computer program product, characterized in that The computer program product comprises a computer program; When the computer program is run on a processor, the following method is implemented: Providing the web page to the terminal; The capability information of the terminal is acquired by calling the browser interface of the terminal through the Web page.
39. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed on a processor, implements the following method: Receive web pages sent by the web server; Executing a script on the web page, the script includes: calling a browser interface to obtain capability information of the terminal; and The capability information of the terminal is sent to the terminal identification device.
Citation Information
Patent Citations
Equipment classification method and device
CN110213212A
User domain dumb terminal management method, device and system and storage medium
CN114629725A
Active-passive network terminal discovery and identification method based on K-means clustering
CN115865387A
System and method for automatic on-boarding of printers in a printer management system
US20200034094A1
Apparatus and method for identifying terminal information
WO2016076574A1