Operations and maintenance action control method, electronic device, storage medium, and program product

WO2026179412A1PCT designated stage Publication Date: 2026-09-03ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/070331
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-28
Filing Date
2026-01-05
Publication Date
2026-09-03

Smart Images

  • Figure CN2026070331_03092026_PF_FP_ABST
    Figure CN2026070331_03092026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of security operations and maintenance, and discloses an operations and maintenance action control method, an electronic device, a storage medium, and a program product. The method comprises: acquiring a command execution request, the command execution request comprising execution command information, an operations and maintenance action command, and network element identifier information; intercepting sending of the operations and maintenance action command to a target network element device, and determining, on the basis of echo information fed back by the target network element device with respect to the execution command information, a target execution command; and in response to determining, on the basis of the target execution command and interception configuration information of the target network element device, that execution of the target execution command is allowed, sending the operations and maintenance action command to the target network element device.
Need to check novelty before this filing date? Find Prior Art

Description

Operation and maintenance control methods, electronic equipment, storage media and software products

[0001] Cross-referencing

[0002] This application claims priority to Chinese Patent Application No. 202510235092.X, filed on February 28, 2025, entitled "Operation and Maintenance Control Method, Electronic Device, Storage Medium and Program Product", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of security operation and maintenance technology, and in particular to an operation and maintenance control method, electronic device, storage medium and program product. Background Technology

[0004] During equipment operation and maintenance, maintenance personnel typically input different commands to manage the equipment. In order to reduce the risks caused by unauthorized execution of high-risk commands during operation and maintenance, it is necessary to effectively control the execution of commands.

[0005] In related technologies, 4A gateways can be used to intercept high-risk commands. Specifically, when maintenance personnel execute commands, the 4A gateway determines whether execution is allowed based on the risk level of the user-input command itself. If the 4A gateway allows execution, the operation command on the device will execute normally; if the 4A gateway does not allow execution, it will indicate that the operation command execution failed. However, because the interaction method between the 4A gateway and the network management system is different, it cannot be directly integrated with the network management system, making it inconvenient to manage and deploy it. Furthermore, the high-risk command management list of the 4A gateway lacks device and scenario segmentation, making targeted and refined command control impossible, thus limiting the command interception scenarios. Summary of the Invention

[0006] This application provides an operation and maintenance control method, an electronic device, a storage medium, and a program product.

[0007] In a first aspect, embodiments of this application provide an operation and maintenance control method, comprising: acquiring a command execution request, wherein the command execution request includes execution command information, an operation and maintenance command, and network element identification information, wherein the operation and maintenance command is used to instruct a target network element device corresponding to the network element identification information to execute the target execution command indicated by the execution command information; intercepting the transmission of the operation and maintenance command to the target network element device, and determining the target execution command based on the feedback information returned by the target network element device in response to the execution command information; and in response to determining that the execution of the target execution command is permitted based on the target execution command and the interception configuration information of the target network element device, sending the operation and maintenance command to the target network element device.

[0008] In a second aspect, embodiments of this application provide an electronic device, which includes a processor and a memory. The memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, they implement the steps of the method described in the first aspect above.

[0009] Thirdly, embodiments of this application provide a computer-readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect above.

[0010] Fourthly, embodiments of this application provide a computer program product, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions, which, when executed by a computer, cause the computer to perform the steps of the method described in the first aspect above.

[0011] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0012] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0013] Figure 1 illustrates a schematic diagram of an application scenario for the operation and maintenance control method provided in an embodiment of this application.

[0014] Figure 2 shows a flowchart of the operation and maintenance control method provided in the embodiment of this application;

[0015] Figure 3 shows a flowchart of the command extraction method provided in an embodiment of this application;

[0016] Figure 4 shows an example diagram of the time-sharing management strategy configuration page provided in an embodiment of this application;

[0017] Figure 5 shows a flowchart of the command execution method provided in an embodiment of this application;

[0018] Figure 6 shows an interface display diagram of the authorization prompt information provided in an embodiment of this application;

[0019] Figure 7 illustrates a schematic diagram of the authorization execution process provided in an embodiment of this application;

[0020] Figure 8 shows a schematic diagram of the operation and maintenance control system provided in an embodiment of this application;

[0021] Figure 9 shows a schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application. Detailed Implementation

[0022] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0023] To mitigate the risks associated with unauthorized execution of high-risk commands during operation and maintenance, relevant technologies propose a solution using a 4A gateway for high-risk command interception. This solution involves the device automatically sending the command to the 4A gateway for authorization verification. If the 4A gateway allows execution, the command will execute normally on the device; otherwise, it will display a command execution failure message.

[0024] The solution of using a 4A gateway to intercept high-risk commands has at least the following problems:

[0025] 1) This solution requires the additional deployment of a dedicated 4A gateway for command interception. Due to the different interaction methods between the 4A gateway and the network management system, the 4A gateway cannot directly link with the network management system.

[0026] 2) The 4A gateway cannot implement time-sharing management and control functions.

[0027] 3) Configuring high-risk interception templates on the 4A gateway is complex and not easy to deploy and implement.

[0028] 4) Both the 4A gateway and the device need to support the high-risk command interception function.

[0029] 5) The high-risk command management list in the 4A gateway does not support different devices or scenarios, and the command interception scenario is limited.

[0030] To address the aforementioned problems in the secure operation and maintenance of equipment, this application provides an operation and maintenance control method, as shown in Figure 1. This method can be applied to a server 110, which can be a network management server. When a user needs to execute an operation and maintenance command, the server 110 sends the command to the network element device 120. If the server 110 detects that the sent command does not meet the requirements, it will intercept the command and send a prompt message to the client. This client can be either a first client 131 used by the operator or a second client 132 used by the administrator. This method eliminates the need for additional configuration of a 4A gateway for command interception. The server 110 can flexibly configure the interception configuration information of the network element device 120 according to actual needs, thus adapting to command interception scenarios for various types of network element devices.

[0031] Please refer to Figure 2, which shows a flowchart of the operation and maintenance control method provided in this embodiment. The execution subject of this method can be a server 110. As shown in the figure, the operation and maintenance control method 200 may include the following steps:

[0032] Step 201: Obtain a command execution request. The command execution request includes execution command information, operation and maintenance command, and network element identification information. The operation and maintenance command is used to instruct the target network element device corresponding to the network element identification information to execute the target execution command indicated by the execution command information.

[0033] In one exemplary embodiment, a user performs maintenance operations on a target network element device through client 130. The user enters the execution command "reboot" (indicating restarting the target network element device) and maintenance operation commands in the command line of client 130. These maintenance operation commands instruct the target network element device corresponding to the network element identification information to execute the target execution command indicated by the execution command information entered in the command line. In specific applications, the maintenance operation command can be the Enter key or other pre-set keys, such as the "F1" key, "Ctrl+Enter" key, etc. These keys are used to trigger the target network element device to execute the target execution command indicated by the execution command information entered in the command line.

[0034] Step 202: Intercept the operation and maintenance command sent to the target network element device, and determine the target execution command based on the feedback information of the target network element device in response to the execution command information.

[0035] In one exemplary embodiment, server 110 intercepts operation commands sent to the target network element device to ensure that the target execution command indicated by the execution command information is not directly executed on the target network element device. However, since the execution command information entered by the user in the command line of client 130 can be the arrow keys, Tab key, or other special commands, if server 110 intercepts commands based on the command information entered by the user in the command line, the target execution command indicated by the execution command information may not be effectively intercepted. For example, when the user enters "↑" in the command line, the target execution command executed by the target network element device is not "↑" itself, but the previous command indicated by "↑". Therefore, in this embodiment, the target execution command is determined based on the feedback information from the target network element device regarding the execution command information to improve the reliability of command interception.

[0036] Step 203: In response to determining that the execution of the target execution command is permitted based on the target execution command and the interception configuration information of the target network element device, the operation and maintenance command is sent to the target network element device.

[0037] The server 110 can determine whether to allow the execution of the target execution command based on the pre-configured interception configuration information of the target network element device. If it is determined that the execution of the target execution command is allowed, it sends an operation and maintenance command to the target network element device so that the target network element device executes the target execution command indicated by the execution command information.

[0038] Through the above steps, a command execution request is obtained, which includes execution command information, operation and maintenance commands, and network element identification information. The operation and maintenance commands sent to the target network element are intercepted, and the target execution command is determined based on the feedback information from the target network element regarding the execution command information. In response, based on the target execution command and the target network element's interception configuration information, it is determined whether the execution of the target execution command is permitted, and the operation and maintenance command is sent to the target network element. This avoids users circumventing command interception using arrow keys, Tab keys, or other special commands, improving the reliability of command interception. Furthermore, no additional configuration of a 4A gateway for command interception is required, and the interception configuration information of the target network element can be flexibly configured according to actual needs, thus adapting to command interception scenarios for various types of network element devices.

[0039] In some implementations, step 202 above, determining the target execution command based on the echo information returned by the target network element device in response to the execution command information, includes:

[0040] Obtain the feedback information from the target network element device in response to the execution command information; compare whether the feedback command carried in the feedback information is consistent with the target execution command indicated by the execution command information; in response to the consistency between the feedback command and the target execution command indicated by the execution command information, extract the feedback command from the feedback information, and determine the target execution command based on the feedback command.

[0041] In practice, the user enters execution command information on the command line of client 130. The target network element device responds with echo information based on this execution command information. For example, if the user enters the command "reboot" on the command line, the target network element device will echo this command; as another example, if the user enters "↑" on the command line, the target network element device will echo the command indicated by "↑". The echo command carried in the echo information is compared character by character to see if it matches the target execution command indicated by the execution command information. When the echo command matches the target execution command indicated by the execution command information, the echo command is extracted from the echo information, and the target execution command is determined based on the echo command.

[0042] In other embodiments, after comparing whether the echo command carried in the echo information is consistent with the target execution command indicated by the execution command information, the method further includes: in response to the inconsistency between the echo command and the target execution command indicated by the execution command information, continuing to acquire the next echo information fed back by the target network element device until the received echo information satisfies a first condition; wherein the first condition includes at least one of the following: no next echo information fed back by the target network element device is received within a preset time period after the echo information is received; the echo command carried in the first echo information is consistent with the target execution command indicated by the execution command information; extracting the echo command from the echo information that satisfies the first condition, and determining the target execution command based on the echo command.

[0043] The aforementioned preset time period can be set based on information such as device display rate, display time, display content, and historical behavior.

[0044] In specific implementation, when the echo command is inconsistent with the target execution command indicated by the execution command information, the system continues to acquire the next echo information fed back by the target network element until the received echo information meets any of the following conditions:

[0045] 1) If no further echo information is received from the target network element within a preset time period after receiving the echo information, that is, if it is determined that the target network element has finished echoing, then the echo information is obtained; if it is determined that the target network element has not finished echoing, then the system waits for the target network element to continue echoing until the echoing ends. This preset time period can be set according to information such as the device's echo rate, echo time, echo content, and historical behavior.

[0046] 2) The echo command carried in the received echo information is consistent with the target execution command indicated by the execution command information.

[0047] Obtain the echo information that meets the above conditions, extract the echo command from the echo information, and determine the target execution command of the target network element device based on the echo command.

[0048] The aforementioned echo command can be obtained by segmenting the echo information according to a preset operation prompt; the preset operation prompt is obtained from the target echo information, which is the echo information fed back by the target network element device when a communication connection is successfully established with the target network element device.

[0049] The operation prompts can be " / ", "<", ">", etc., used to distinguish different parts of the command.

[0050] In an exemplary embodiment, as shown in FIG3, the command extraction method described above includes the following steps:

[0051] Step 301: A communication connection was successfully established with the target network element device, and the server 110 successfully connected to and logged into the device.

[0052] Step 302: Extract the hostname and operation prompt from the target echo information returned by the target network element device when the login is successful.

[0053] Step 303: Obtain the execution command information input by the user.

[0054] Step 304: Obtain the operation and maintenance command input by the user. The operation and maintenance command can be Enter or Submit.

[0055] Step 305: Intercept the operation command, that is, intercept the user's input of Enter or Submit command.

[0056] Step 306: Compare the echo command carried in the echo information with the target execution command indicated by the execution command information entered by the user.

[0057] Step 307: Determine whether the echoed command is consistent with the target execution command indicated by the execution command information; if the echoed command is inconsistent with the target execution command indicated by the execution command information, proceed to step 308; if the echoed command is consistent with the target execution command indicated by the execution command information, proceed to step 311.

[0058] Step 308: Detect information such as the device's response rate, response time, response content, and historical behavior.

[0059] Step 309: Determine whether the execution command information entered by the user has been echoed on the target network element device; if the execution command information has not been echoed on the target network element device, proceed to step 310; if the execution command information has been echoed on the target network element device, proceed to step 311.

[0060] Specifically, the system can continue to acquire the next feedback information from the target network element device until no further feedback information is received from the target network element device within a preset time period after acquiring the feedback information. In this case, it is determined that the execution command information has ended being displayed on the target network element device. The preset time period can be set based on the information acquired in step 310 above. Alternatively, the system can determine that the execution command information has ended being displayed on the target network element device when it is determined that the feedback command carried in the feedback information is consistent with the target execution command indicated by the execution command information.

[0061] Step 310: Wait for the device to continue displaying the message, then return to step 308.

[0062] Step 311: Extract the echo command from the echo information.

[0063] Step 312: Complete command extraction and end the process.

[0064] The aforementioned determination of the target execution command based on the echo command includes: adjusting the format of the echo command to obtain the target execution command.

[0065] In one exemplary embodiment, since the extracted echo commands may contain newlines, indentation, or non-echo characters, the format of the extracted echo commands can be adjusted to obtain the target execution command. The format adjustment includes, but is not limited to, removing newlines, removing prompts and non-echo characters, and removing redundant spaces and indentation. This can improve the accuracy of the target execution command.

[0066] In some implementations, step 202 above, after the interceptor sends the operation and maintenance command to the target network element device, further includes: obtaining the interception configuration information of the target network element device, and determining the request time point corresponding to the target execution command based on the command execution request. The interception configuration information includes an interception time period and matching information. The matching information includes one of the following: information corresponding to commands that are allowed to be executed; information corresponding to commands that are prohibited from being executed; in response to the request time point being within the interception time period, determining whether to allow the execution of the target execution command based on the matching result of the target execution command in the matching information.

[0067] In an exemplary embodiment, the interception time period of the target network element device can be configured on the preset time-sharing control policy configuration page, as shown in Figure 4. First, the target network element device to be controlled is selected from multiple network element devices, and then the interception time period is configured for the selected target network element device. The interception time period can be a certain month, a certain week, or a certain day. For example, the interception time period is a week from Sunday to Saturday, or it can be a specific time period within a certain day. For example, the interception time period is 06:00-18:00 on Sunday.

[0068] Additionally, matching information can be configured for target network elements that require management. This configuration information includes information corresponding to allowed commands (i.e., a whitelist) or prohibited commands (i.e., a blacklist). For example, the matching information may include a scenario name, a blacklist, and a whitelist. Both the blacklist and whitelist can contain multiple sets of high-risk commands, each set including commands that need to be blocked or allowed, represented using regular expressions.

[0069] The target network element device can be identified by its model or series. Different network element devices can be blocked using different lists. For example, when a network element device is under strict control and allows fewer commands to be executed, a whitelist can be configured for that network element device. When a network element device allows more commands to be executed, a blacklist can be configured for that network element device.

[0070] In some implementations, after determining whether to allow the execution of the target execution command based on the matching result in the matching information, the method further includes: in response to determining that the execution of the target execution command is prohibited based on the matching result in the matching information, sending authorization prompt information to the operation and maintenance client, the authorization prompt information being used to instruct the operation and maintenance client to input the authorization code of the target execution command; obtaining the authorization code returned by the operation and maintenance client based on the authorization prompt information, and performing authorization authentication on the authorization code; in response to the authorization authentication result indicating that the authorization code is valid, determining that the execution of the target execution command is allowed.

[0071] In other embodiments, after determining whether to allow the execution of the target execution command based on the matching result in the matching information, the method further includes: in response to the request time point being outside the interception time period, determining that the execution of the target execution command is allowed.

[0072] In specific implementation, the interception configuration information of the pre-configured target network element device is obtained, and the request time point corresponding to the target execution command is determined according to the command execution request. When the request time point is outside the interception period, that is, the target execution command is not within the control period of the target network element device, it is determined that the execution of the target execution command is allowed. When the request time point is within the interception period, it is determined whether the execution of the target execution command is allowed according to the matching result of the target execution command and the matching information. Specifically, when the target execution command matches the information corresponding to the allowed command, or when the target execution command does not match the information corresponding to the prohibited command, it is determined that the execution of the target execution command is allowed.

[0073] In an exemplary embodiment, as shown in FIG5, the command execution method described above may include the following steps:

[0074] Step 501: Obtain the extracted target execution command and the request time point corresponding to the target execution command.

[0075] Step 502: Determine whether the request time point corresponding to the target execution command is within the interception time period; if it is determined that the request time point is outside the interception time period, proceed to step 505; if the request time point is within the interception time period, proceed to step 503.

[0076] Step 503: Obtain the interception configuration information, which includes the interception time period and matching information. The matching information includes the device type, execution command scenario, blacklist, and whitelist. The whitelist contains information corresponding to commands that are allowed to be executed, and the blacklist contains information corresponding to commands that are prohibited from being executed.

[0077] Step 504: Determine whether to allow the execution of the target execution command based on the matching result in the matching information; in response to determining that the execution of the target execution command is allowed, proceed to step 505; in response to determining that the execution of the target execution command is prohibited, proceed to step 506.

[0078] Step 505: Send an operation and maintenance command to the target network element device so that the target network element device executes the target execution command.

[0079] Step 506: Proceed to the authorized execution process.

[0080] In another exemplary embodiment, when it is determined that the execution of the target execution command is prohibited based on the target execution command and the interception configuration information of the target network element device, an authorization prompt message is sent to the operation and maintenance client, as shown in Figure 6. This authorization prompt message includes the authorization method, the username of the authorized personnel, and the authorization code. The user enters the authorization code on the display interface of the authorization prompt message. The server 110 obtains the authorization code and performs authorization authentication. In response to the authorization authentication result indicating that the authorization code is valid, it determines that the execution of the target execution command is permitted.

[0081] In some implementations, after authorizing the authorization code, the method further includes: in response to the result of the authorization authentication indicating that the authorization code is invalid, determining that the execution of the target execution command is prohibited, and sending an authorization failure prompt message to the operation and maintenance client.

[0082] Continuing with the above embodiment, when the authorization authentication result indicates that the authorization code is invalid, it is determined that the execution of the target command is prohibited, and an authorization failure prompt message is sent to the operation and maintenance client to remind the user that the authorization failed and to re-enter the authorization code.

[0083] In some implementations, before sending the authorization prompt information to the operation and maintenance client, the method further includes: determining whether the execution time of the target execution command is within the authorization validity period of the target execution command; in response to the execution time being within the authorization validity period, determining that the execution of the target execution command is permitted; and in response to the execution time being outside the authorization validity period, performing the step of sending the authorization prompt information to the operation and maintenance client.

[0084] In an exemplary embodiment, as shown in FIG7, the above authorization process includes the following steps: Step 701: The operation and maintenance personnel apply for authorization from the second client 132 through the first client 131, send authorization information to the server 110, and apply for authorization from the second client 132 through the server 110; Step 702: The operation and maintenance personnel enter the authorization code on the interface; Step 703: The authorization code is sent to the server 110 for judgment. If the authorization fails, it returns to the first client 131 and prompts that the authorization failed; if the authorization is successful, the authorization information is recorded, the command is executed, and the execution result is returned to the first client 131; Step 704: No re-authorization is required during the period when the authorization has not expired. If the authorization expires and a high-risk command is executed again, re-authorization is required.

[0085] In some implementations, after sending the operation and maintenance command to the target network element device, the method further includes: obtaining the execution result of the operation and maintenance command fed back by the target network element device; and sending the execution result to the operation and maintenance client.

[0086] In practice, after sending the operation and maintenance command to the target network element device, the server 110 also obtains the execution result of the operation and maintenance command fed back by the target network element device and sends the execution result to the operation and maintenance client so that the user can know the execution status of the target network element device in a timely manner.

[0087] In an exemplary embodiment, this application also provides an operation and maintenance control system, which includes a first client 131, a second client 132, a server 110, and a network element device 120. As shown in FIG8, the server 110 includes: a strategy module 111, an interception module 112, a command issuance module 113, a command extraction module 114, and an authorization module 115; the strategy module 111 is used to configure and store interception configuration information; the interception module 112 is used to obtain a command execution request, the command execution request including execution command information, operation and maintenance command, and network element identification information; intercept the sending of the operation and maintenance command to the network element device 120, and determine the target execution command based on the feedback information of the network element device 120 regarding the execution command information; and respond to the determination of the target execution command and the interception configuration information of the network element device 120. The system allows the execution of the target command and sends the operation and maintenance command to the network element device 120. The command issuing module 113 is used to issue the operation and maintenance command to the network element device 120. The command extraction module 114 is used to extract the target execution command indicated by the user-input execution command information from the echo information of the network element device 120. The authorization module 115 is used to obtain the authorization code input by the first client and check the validity of the authorization code. If the authorization code is valid, the authorized execution time point and operation and maintenance command are sent to the interception module 112. Otherwise, an authorization failure prompt message is sent to the first client 131 to prompt the user that the authorization failed.

[0088] The first client 131 includes a user operation module, which is used to obtain a command execution request in response to information input by the user; the second client 132 includes an authorization approval module, which is used to review the intercepted target execution command, and execute the command after the review is approved.

[0089] Figure 9 illustrates a hardware structure diagram of the electronic device provided in the embodiments of this application. Referring to the figure, at the hardware level, the electronic device 900 includes a processor 910, and optionally includes an internal bus 920, a network interface 930, and a memory 940. The memory 940 may include main memory 941, such as high-speed random-access memory (RAM), and may also include non-volatile memory 942, such as at least one disk storage device. Of course, the electronic device 900 may also include other hardware required for other services.

[0090] The processor 910, network interface 930, and memory can be interconnected via an internal bus 920. This internal bus 920 can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be categorized as an address bus, data bus, control bus, etc. For ease of illustration, only a single bidirectional arrow is used in this diagram, but this does not imply that there is only one bus or one type of bus.

[0091] Memory 940 stores programs. Specifically, the program may include program code, which includes computer operation instructions. Memory 940 may include main memory 941 and non-volatile memory 942, and provides instructions and data to processor 910.

[0092] The processor 910 reads the corresponding computer program from the non-volatile memory 942 into memory and then runs it, forming a device for locating the target user at the logical level. The processor 910 executes the program stored in the memory and specifically performs the method disclosed in the embodiments shown in Figures 2, 3, 5 or 7, and implements the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0093] The methods disclosed in the embodiments shown in Figures 2, 3, 5, or 7 of this application can be applied to or implemented by the processor 910. The processor 910 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above methods can be completed by integrated logic circuits in the hardware or by instructions in software form within the processor 910. The processor 910 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0094] The computer device can also execute the methods described in the preceding method embodiments and achieve the functions and beneficial effects of the methods described in the preceding method embodiments, which will not be repeated here.

[0095] Of course, in addition to software implementation, the electronic device 900 of this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. In other words, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0096] This application also proposes a computer-readable storage medium that stores one or more programs. When executed by an electronic device including multiple applications, the one or more programs cause the electronic device to perform the methods disclosed in the embodiments shown in FIG2, FIG3, FIG5 or FIG7 and achieve the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0097] The computer-readable storage medium includes read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, etc.

[0098] Furthermore, this application also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, which, when executed by a computer, implement the following process: the method disclosed in the embodiments shown in FIG2, FIG3, FIG5 or FIG7 and achieve the functions and beneficial effects of the methods described in the foregoing method embodiments, which will not be repeated here.

[0099] The embodiments of this application can be applied to various scenarios of electronic device collaboration or interconnection, including: collaboration and interconnection between mobile phones and laptops / tablets; collaboration and interconnection between mobile terminals and smart TVs / monitors; collaboration and interconnection between mobile phones or tablets and in-vehicle entertainment systems; collaboration and interconnection between mobile terminals and smart conferencing systems, etc. This satisfies users' diverse needs in smart home, smart office, and smart travel scenarios.

[0100] In summary, the above description is merely a preferred embodiment of this application and does not limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

[0101] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0102] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can store information accessible to a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0103] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0104] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

Claims

1. A method for operation and maintenance control, comprising: Obtain a command execution request, which includes execution command information, operation and maintenance command, and network element identification information. The operation and maintenance command is used to instruct the target network element device corresponding to the network element identification information to execute the target execution command indicated by the execution command information. The operation and maintenance command sent to the target network element device is intercepted, and the target execution command is determined based on the feedback information of the target network element device in response to the execution command information. In response to determining that the execution of the target execution command is permitted based on the target execution command and the interception configuration information of the target network element device, the operation and maintenance command is sent to the target network element device.

2. The method according to claim 1, wherein, The step of determining the target execution command based on the feedback information from the target network element device in response to the execution command information includes: Obtain the feedback information from the target network element device in response to the executed command information; Compare whether the echo command carried in the echo information is consistent with the target execution command indicated by the execution command information; In response to the echo command being consistent with the target execution command indicated by the execution command information, the echo command is extracted from the echo information, and the target execution command is determined based on the echo command.

3. The method according to claim 2, wherein, After comparing whether the echo command carried in the echo information is consistent with the target execution command indicated by the execution command information, the method further includes: In response to the discrepancy between the echo command and the target execution command indicated by the execution command information, the system continues to acquire the next echo information fed back by the target network element until the received echo information meets a first condition; wherein the first condition includes at least one of the following: no next echo information fed back by the target network element is received within a preset time period after the echo information is received; the echo command carried in the echo information is consistent with the target execution command indicated by the execution command information; Extract the echo command from the echo information that satisfies the first condition, and determine the target execution command based on the echo command.

4. The method according to claim 2 or 3, wherein, The echo command is obtained by segmenting the echo information according to a preset operation prompt; the preset operation prompt is obtained from the target echo information, which is the echo information fed back by the target network element device when a communication connection is successfully established with the target network element device.

5. The method according to claim 2 or 3, wherein, Determining the target execution command based on the echo command includes: The format of the echo command is adjusted to obtain the target execution command.

6. The method according to claim 1, wherein, After the interception sends the operation and maintenance command to the target network element device, the method further includes: The interception configuration information of the target network element device is obtained, and the request time point corresponding to the target execution command is determined according to the command execution request. The interception configuration information includes an interception time period and matching information. The matching information includes one of the following: information corresponding to commands that are allowed to be executed; information corresponding to commands that are prohibited from being executed. In response to the request time point falling within the interception time period, the system determines whether to allow the execution of the target execution command based on the matching result of the target execution command in the matching information.

7. The method according to claim 6, wherein, After determining whether to allow the execution of the target execution command based on the matching result in the matching information according to the target execution command, the method further includes: In response to the matching result of the target execution command in the matching information, it is determined that the execution of the target execution command is prohibited, and an authorization prompt message is sent to the operation and maintenance client. The authorization prompt message is used to instruct the operation and maintenance client to enter the authorization code of the target execution command. Obtain the authorization code returned by the operation and maintenance client based on the authorization prompt information, and perform authorization authentication on the authorization code; In response to the authorization authentication result indicating that the authorization code is valid, it is determined that the execution of the target execution command is permitted.

8. The method according to claim 7, wherein, After authorizing and authenticating the authorization code, the process further includes: In response to the authorization authentication result indicating that the authorization code is invalid, the execution of the target execution command is prohibited, and an authorization failure message is sent to the operation and maintenance client.

9. The method according to claim 7, wherein, Before sending the authorization prompt message to the operation and maintenance client, the following is also included: Determine whether the execution time of the target execution command is within the authorization validity period of the target execution command; In response to the execution time point falling within the authorization validity period, it is determined that execution of the target execution command is permitted; In response to the execution time point being outside the authorization validity period, the step of sending the authorization prompt information to the operation and maintenance client is executed.

10. The method according to claim 6, wherein, After determining whether to allow the execution of the target execution command based on the matching result in the matching information according to the target execution command, the method further includes: In response to the fact that the requested time point is outside the interception time period, it is determined that the execution of the target command is permitted.

11. The method according to claim 1, wherein, After sending the operation and maintenance command to the target network element device, the method further includes: Obtain the execution result of the operation and maintenance command fed back by the target network element device; Send the execution result to the operation and maintenance client.

12. The method according to any one of claims 1 to 11, wherein, The method is applied to the network management server.

13. An electronic device comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as claimed in any one of claims 1 to 12.

14. A computer-readable storage medium on which a program or instructions are stored, wherein the program or instructions, when executed by a processor, implement the steps of the method as claimed in any one of claims 1 to 12.

15. A computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program including program instructions that, when executed by a computer, cause the computer to perform the steps of the method as described in any one of claims 1 to 12.