Communication method, apparatus, and system, storage medium, and program product

WO2026199960A1PCT designated stage Publication Date: 2026-10-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/134988
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-26
Filing Date
2025-11-14
Publication Date
2026-10-01

Smart Images

  • Figure CN2025134988_01102026_PF_FP_ABST
    Figure CN2025134988_01102026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a communication method, apparatus, and system, a storage medium, and a program product. The method in the embodiments of the present application comprises: receiving first information from an NAC, the first information being used for indicating that a VLAN is to be switched; sending second information, the second information being used for detecting whether the VLAN has been switched; and receiving third information, the third information being used for indicating an IP address corresponding to the switched VLAN. In this way, when an NAC needs to adjust a VLAN to which a terminal device belongs, the NAC sends, to the terminal device, first information indicating that the VLAN is to be switched, so that the terminal device can promptly learn that the VLAN needs to be switched, thereby enabling quick detection of whether the VLAN has been switched. When the VLAN has been switched, the terminal device can promptly acquire an IP address corresponding to the switched VLAN, thereby promptly updating the IP address of the terminal device, and avoiding impacting communication of the terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method, apparatus, system, storage medium, and program product

[0001] This application claims priority to Chinese Patent Application No. 202510374410.0, filed on March 26, 2025, entitled "A Communication Method, Apparatus, System, Storage Medium and Program Product", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, specifically to a communication method, apparatus, system, storage medium, and program product. Background Technology

[0003] Currently, after the network access controller (NAC) adjusts the virtual local area network (VLAN) to which a terminal device belongs, the user needs to manually perform corresponding operations on the terminal device to trigger a request for a new Internet Protocol (IP) address in order to update the terminal device's IP address. As a result, the terminal device's IP address cannot be updated in a timely manner, which will affect the terminal device's communication. Summary of the Invention

[0004] This application provides a communication method, apparatus, system, storage medium, and program product that promptly updates the IP address of the terminal device after a VLAN switch, thereby avoiding any impact on the terminal device's communication.

[0005] In view of the above, firstly, embodiments of this application provide a communication method that can be executed by a terminal device. Unless otherwise specified, the term "terminal device" in embodiments of this application can refer to the terminal device itself, a component within the terminal device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the terminal device's functions. The method includes: the terminal device receiving first information from a NAC, the first information indicating a VLAN switchover; the terminal device sending second information to detect whether a VLAN switchover has occurred; and the terminal device receiving third information indicating the IP address corresponding to the switched VLAN.

[0006] In the method provided in this application, when the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC will send first information indicating that the VLAN has been switched to the terminal device. In this way, the terminal device can know in time that the VLAN is about to be switched and actively send second information to detect whether the VLAN has been switched. If the VLAN has been switched, the terminal device can receive third information and obtain the IP address corresponding to the switched VLAN from the third information. This allows the terminal device to update its IP address in a timely manner, reduce the offline latency of the terminal device caused by the VLAN switch, avoid affecting the communication of the terminal device, and improve the user experience.

[0007] In conjunction with the first aspect, in one possible implementation of the first aspect, the method further includes: in the event of a VLAN switch, the terminal device sends fourth information, which is used to request an IP address. Thus, in the event of a VLAN switch, the terminal device can promptly request a new IP address, thereby updating the terminal device's IP address in a timely manner and avoiding any impact on the terminal device's communication.

[0008] In conjunction with the first aspect, in one possible implementation of the first aspect, sending the fourth information includes: the terminal device sending a first Dynamic Host Configuration Protocol Discover (DHCP DISCOVER) message, which carries the fourth information. In this way, the terminal device can request a new IP address using existing DHCP DISCOVER messages without designing new messages, thus improving the feasibility of the solution.

[0009] In conjunction with the first aspect, in one possible implementation of the first aspect, the method further includes: when a VLAN switch occurs, the terminal device executes a first instruction, which triggers a request for an IP address. Thus, when a VLAN switch occurs, the terminal device can promptly trigger a request for a new IP address, thereby obtaining the IP address corresponding to the switched VLAN in a timely manner, updating the terminal device's IP address promptly, and avoiding any impact on the terminal device's communication.

[0010] In conjunction with the first aspect, in one possible implementation of the first aspect, the method further includes: if the number of times the second information is sent exceeds a first threshold and no response information corresponding to the second information is received, the terminal device determines that a VLAN switch has occurred; or, if the second information is sent multiple times within a first time period and no response information corresponding to the second information is received within the first time period, the terminal device determines that a VLAN switch has occurred; or, if the number of times the second information is sent within a second time period exceeds a second threshold and no response information corresponding to the second information is received, the terminal device determines that a VLAN switch has occurred. By setting a first threshold, or a first time period, or a second time period and a second threshold, jitter can be eliminated, and the determination of whether a VLAN switch has occurred can be made timely and accurately. This allows for timely updates of the terminal device's IP address in the event of a VLAN switch, avoiding disruption to the terminal device's communication.

[0011] In conjunction with the first aspect, in one possible implementation of the first aspect, receiving third information includes: the terminal device receiving a Dynamic Host Configuration Protocol (DHCP) Offer message, which carries third information. In this way, the terminal device can carry a new IP address using existing DHCP Offer messages without designing new messages, thus improving the feasibility of the solution.

[0012] In conjunction with the first aspect, in one possible implementation of the first aspect, sending the second information includes: the terminal device sending a second DHCP DISCOVER message carrying the second information; or, the terminal device sending a Dynamic Host Configuration Protocol Request (DHCP REQUEST) message carrying the second information. In this way, the terminal device can detect whether its VLAN has switched using existing DHCP DISCOVER or DHCP REQUEST messages without designing new messages, thus improving the feasibility of the solution. Furthermore, multiple messages can be used to detect whether the VLAN to which the terminal device belongs has switched, allowing the appropriate message to be selected based on the actual situation, facilitating the implementation of the solution.

[0013] In conjunction with the first aspect, in one possible implementation of the first aspect, sending the second information includes: the terminal device sending an Address Resolution Protocol (ARP) message carrying the second information; or sending an Internet Control Message Protocol (ICMP) message carrying the second information; or sending a Bidirectional Forwarding Detection (BFD) message carrying the second information. In this way, the terminal device can detect whether its VLAN has switched using existing ARP, ICMP, or BFD messages without designing new messages, thus improving the feasibility of the solution. Furthermore, multiple messages can be used to detect whether the VLAN to which the terminal device belongs has switched, allowing the appropriate message to be selected based on the actual situation, facilitating the implementation of the solution.

[0014] In conjunction with the first aspect, in one possible implementation of the first aspect, receiving the first information from the NAC includes: receiving a Hypertext Transfer Protocol (HTTP) message from the NAC, the HTTP message carrying the first information; or, receiving a Hypertext Transfer Protocol Secure (HTTPS) message from the NAC, the HTTPS message carrying the first information. In this way, the terminal device can indicate a VLAN switchover using existing HTTP or HTTPS messages without designing new messages, thus improving the feasibility of the solution.

[0015] Secondly, this application provides a communication method that can be executed by a Network Access Control (NAC). Unless otherwise specified, "NAC" in this application can refer to the NAC itself, a component within the NAC (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing all or part of the NAC's functions. The method includes: the NAC sending first information to a terminal device, the first information indicating a VLAN switchover to trigger the terminal device to detect whether a VLAN switchover has occurred; and the NAC sending fifth information to a network access device, the fifth information indicating a VLAN switchover.

[0016] In the method provided in this application, when the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC will send first information indicating that the VLAN has been switched to the terminal device, triggering the terminal device to detect whether the VLAN has been switched, and sending fifth information to the network access device to indicate the VLAN switch. In this way, the terminal device can know in time that the VLAN is about to be switched and actively detect whether the VLAN has been switched. Thus, when the VLAN is switched, the terminal device's IP address can be updated in time, reducing the offline latency of the terminal device caused by the VLAN switch, avoiding the impact on the terminal device's communication, and improving the user experience.

[0017] In conjunction with the second aspect, in one possible implementation of the second aspect, sending the fifth information to the network access device includes: the NAC sending a Representational State Transfer Configuration (RESTCONF) message to the network access device, the RESTCONF message carrying the fifth information; or, the NAC sending a Network Configuration Protocol (NETCONF) message to the network access device, the NETCONF message carrying the fifth information. In this way, the terminal device can indicate VLAN switching using existing RESTCONF or NETCONF messages, without needing to design new messages, thus improving the feasibility of the solution. Furthermore, multiple messages can be used to indicate VLAN switching, allowing the appropriate message to be selected based on actual conditions, facilitating the implementation of the solution.

[0018] Thirdly, embodiments of this application provide a communication system, which includes: a terminal device, an NAC, and a network access device;

[0019] NAC is used to send first information, which indicates that a VLAN switch has occurred.

[0020] Terminal equipment, used to receive the first information;

[0021] NAC is also used to send a fifth message, which indicates a VLAN switch.

[0022] Network access devices used for switching VLANs based on fifth information;

[0023] The terminal device is also used to send a second message, which is used to detect whether a VLAN switch has occurred;

[0024] The terminal device is also used to receive third information, which indicates the IP address corresponding to the switched VLAN.

[0025] It should be noted that, unless otherwise specified, the term "terminal device" in the embodiments of this application can refer to the terminal device itself, a component within the terminal device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terminal device; the term "NAC" in the embodiments of this application can refer to the NAC itself, a component within the NAC (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the NAC; the term "network access device" in the embodiments of this application can refer to the network access device itself, a component within the network access device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the network access device.

[0026] In the system provided by this application, when the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC sends first information indicating that the VLAN has been switched to the terminal device, triggering the terminal device to detect whether the VLAN has been switched, and sends fifth information to the network access device to indicate the VLAN switch. In this way, the terminal device can know in time that the VLAN is about to be switched and actively detect whether the VLAN has been switched. In the case of VLAN switching, the terminal device can receive third information and obtain the IP address corresponding to the switched VLAN from the third information, thereby updating the IP address of the terminal device in time, reducing the offline latency of the terminal device caused by VLAN switching, avoiding the impact on the communication of the terminal device, and improving the user experience.

[0027] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is further configured to send a fourth message in the event of a VLAN switch, the fourth message being used to request an IP address.

[0028] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is further configured to send a first DHCP DISCOVER message carrying fourth information.

[0029] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is further configured to execute a first instruction in the event of a VLAN switch, the first instruction being used to trigger a request for an IP address.

[0030] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is further configured to determine that a VLAN switch has occurred if the number of times the second information is sent exceeds a first threshold and no response information corresponding to the second information is received; or, if the second information is sent multiple times within a first time period and no response information corresponding to the second information is received within the first time period, the terminal device is configured to determine that a VLAN switch has occurred; or, if the number of times the second information is sent within a second time period exceeds a second threshold and no response information corresponding to the second information is received, the terminal device is configured to determine that a VLAN switch has occurred.

[0031] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is specifically configured to receive a DHCP OFFER message carrying third information.

[0032] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is specifically configured to send a second DHCP DISCOVER message carrying second information; or, send a DHCP REQUEST message carrying second information.

[0033] In conjunction with the third aspect, in one possible implementation of the third aspect, the terminal device is specifically configured to send an ARP message carrying second information; or, send an ICMP message carrying second information; or, send a BFD message carrying second information.

[0034] In conjunction with the third aspect, in one possible implementation of the third aspect, the NAC is specifically used to send an HTTP message carrying first information; or, to send an HTTPS message carrying first information.

[0035] In conjunction with the third aspect, in one possible implementation of the third aspect, the NAC is specifically used to send a RESTCONF message to the network access device, the RESTCONF message carrying the fifth information; or, to send a NETCONF message to the network access device, the NETCONF message carrying the fifth information.

[0036] Fourthly, embodiments of this application provide a communication device, which includes a module for executing the communication method in the first aspect or any optional embodiment of the first aspect, or a module for executing the communication method in the second aspect or any optional embodiment of the second aspect.

[0037] Fifthly, embodiments of this application provide a communication device, the device comprising:

[0038] The transceiver unit is used to receive first information from the NAC, which indicates that a VLAN switch has occurred.

[0039] The transceiver unit is also used to send second information, which is used to detect whether a VLAN switch has occurred;

[0040] The transceiver unit is also used to receive third information, which indicates the IP address corresponding to the switched VLAN.

[0041] Sixthly, embodiments of this application provide a communication device, the device comprising:

[0042] The transceiver unit is used to send first information to the terminal device, which indicates that a VLAN switch has occurred, so as to trigger the terminal device to detect whether a VLAN switch has occurred.

[0043] The transceiver unit is used to send fifth information to the network access device, which is used to indicate VLAN switching.

[0044] In a seventh aspect, embodiments of this application provide a communication device that can be applied to a terminal device or circuits, chips, chip systems, etc. within a terminal device, or to a NAC or circuits, chips, chip systems, etc. within a NAC. The device may include at least one processor, which is configured to call computer instructions in memory to cause the communication device to execute the communication method in the first aspect or any optional embodiment of the first aspect, or to execute the communication method in the second aspect or any optional embodiment of the second aspect.

[0045] In conjunction with the seventh aspect, in one possible implementation of the seventh aspect, the communication device may further include a memory.

[0046] Eighthly, embodiments of this application provide a computer-readable storage medium that may include instructions that, when executed on a computer, cause the computer to perform the communication method in the first aspect or any optional embodiment of the first aspect, or to perform the communication method in the second aspect or any optional embodiment of the second aspect.

[0047] Ninthly, this application provides a computer program product containing instructions, which may include instructions that, when executed on a computer, cause the computer to perform the communication method in the first aspect or any optional embodiment of the first aspect, or to perform the communication method in the second aspect or any optional embodiment of the second aspect.

[0048] In a tenth aspect, embodiments of this application provide a chip system including a processor for supporting a device in implementing the functions involved in the foregoing aspects, such as transmitting or processing data and / or information involved in the foregoing methods. In one possible design, the chip system further includes a memory for storing program instructions and data necessary for the device. This chip system may be composed of chips or may include chips and other discrete devices.

[0049] Eleventhly, embodiments of this application provide a chip including one or more interface circuits and one or more processors; the interface circuits are used to receive signals from the memory of an electronic device and send signals to the processors, the signals including computer instructions stored in the memory; when the processor executes the computer instructions, it causes the electronic device to perform the communication method in the first aspect or any optional embodiment of the first aspect, or to perform the communication method in the second aspect or any optional embodiment of the second aspect. Attached Figure Description

[0050] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this application;

[0051] Figure 2 is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;

[0052] Figure 3 is a flowchart illustrating a communication method provided in an embodiment of this application;

[0053] Figure 4 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0054] Figure 5 is a schematic diagram of an HTTPS message provided in an embodiment of this application;

[0055] Figure 6 is a schematic diagram of a NETCONF message header provided in an embodiment of this application;

[0056] Figure 7 is a schematic diagram of a DHCP DISCOVER message provided in an embodiment of this application;

[0057] Figure 8 is a schematic diagram of an ARP message provided in an embodiment of this application;

[0058] Figure 9 is a schematic diagram of an ICMP message provided in an embodiment of this application;

[0059] Figure 10 is a schematic diagram of a BFD message provided in an embodiment of this application;

[0060] Figure 11 is a flowchart illustrating a method for detecting a network environment according to an embodiment of this application;

[0061] Figure 12 is a flowchart illustrating another communication method provided in an embodiment of this application;

[0062] Figure 13 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0063] Figure 14 is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation

[0064] The embodiments of this application will now be described with reference to the accompanying drawings. Those skilled in the art will recognize that, with technological advancements and the emergence of new scenarios, the technical solutions provided in the embodiments of this application are equally applicable to similar technical problems.

[0065] The terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. The term "at least one" should be understood as one or more, and "at least one" should be understood as one or more. It should be understood that such terms can be used interchangeably where appropriate; this is merely a way of distinguishing objects with the same attributes in the description of embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of units is not necessarily limited to those units, but may include other units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0066] This application applies to communication systems, which can be second-generation (2G) communication systems, third-generation (3G) communication systems, long-term evolution (LTE) systems, fifth-generation (5G) communication systems, hybrid LTE / 5G architectures, 5G New Radio (5G NR) systems, and other new communication systems emerging in future communication development. Within these systems, a first entity sends configuration information to a second entity and sends or receives data from the second entity; and a second entity receives configuration information and, based on the configuration information, sends or receives data from the first entity.

[0067] A communication system may include a first device, a second device, and a third device. The first device may be used to perform security control on access users, isolate illegal or insecure terminal devices, or only allow terminal devices to access limited resources; in some cases, it is also called a network access controller, NAC, or NAC controller. The second device may be a hardware device that connects terminal devices to the network, enabling the terminal devices to access various network resources such as the Internet and local area networks. It is the enforcement point of the network security policy, responsible for implementing corresponding access control according to the established security policy, such as allowing, denying, isolating, or restricting access; in some cases, it is also called a network access device. The third device may be a device that accesses the network, typically a terminal. An example of a communication system is shown in Figure 1, which includes a network access controller 1, a network access device 2, and a terminal 3.

[0068] In the embodiments provided in this application, the terminal can take various forms, such as a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a vehicle-mounted terminal device, a wireless terminal in self-driving technology, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a wearable terminal device, etc. The terminal may also be referred to as a terminal device, user equipment (UE), access terminal device, vehicle-mounted terminal, industrial control terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal device, mobile device, UE terminal device, terminal device, wireless communication device, UE agent, or UE device, etc. The terminal can also be a fixed terminal or a mobile terminal.

[0069] To more clearly illustrate the technical solutions of the embodiments of this application, the relevant concepts involved in the embodiments of this application are explained below.

[0070] (1) NAC (Network Access Control) is mainly used to control terminal devices accessing the network. It controls terminal devices attempting to access the network through various methods, ensuring that only authenticated terminal devices can access the network, and isolating unauthenticated or unverified terminal devices, thereby improving the overall security protection capability of the network. Among them, NAC can receive threat event information in the network and adjudicate the occurrence of threat events, such as assigning the terminal device involved in the threat event to an isolation VLAN, notifying the network access device to change the VLAN, and notifying the corresponding software deployed on the terminal device that the terminal device is about to be isolated, etc.

[0071] In this application embodiment, the NAC can be a product or platform such as security information and event management (SIEM), security orchestration, automation, and response (SOAR), or security operations center (SOC). It can be deployed on the user's local area network or in the cloud to provide services to multiple tenants. It can receive threat events, analyze events, issue response actions, and control devices in the network to jointly handle threat events.

[0072] It should be noted that the NAC in this application embodiment can also be called a security control center, etc.

[0073] (2) Network access devices are products that support authentication and authorization of access devices. They are the implementation points of security policies in the network and are responsible for implementing corresponding access controls, such as allowing, denying, isolating, or restricting access, according to the security policies established by the network. Network access devices can achieve the goals of mandatory user access authentication, denying network access to unauthorized users, isolating unhealthy terminals, and providing network services to "legitimate users" and "healthy terminals." Specifically, network access devices can authenticate terminal devices attempting to access the network, and classify VLANs for access terminal devices based on the authentication and authorization results to achieve network access control. Network access devices accept NAC control and, based on the NAC's handling of threat events, classify VLANs for terminal devices involved in threat events to achieve isolation of compromised terminal devices.

[0074] The network access device in this application embodiment may be a switch, router, wireless access point, firewall, broadband access server (BAS) or other device with network device access authentication function or capable of accessing third-party authentication device to achieve access authentication function, etc.

[0075] (3) VLAN is a communication technology that logically divides a physical Local Area Network (LAN) into multiple broadcast domains. In this technology, packets in different VLANs are isolated from each other during transmission, meaning that users in one VLAN cannot communicate directly with users in other VLANs.

[0076] (4) Endpoint detection and response (EDR) is an advanced network security technology that aims to detect and respond to potential security threats in a timely manner by monitoring and analyzing the behavioral data of terminal devices in real time.

[0077] Endpoint detection and response agent (EDR Agent) is a security protection software that can be deployed on the operating system of terminal devices as a software agent. It is responsible for security detection and response of the deployed terminal devices, collecting data on the behavior, resources, and operating status of the terminal devices from multiple dimensions. When a threat event is detected, it will report the threat event to NAC and accept the control of NAC to implement handling actions on the terminal devices.

[0078] (5) Extended Detection and Response (XDR) is a more comprehensive security solution that expands the functionality of EDR by integrating data from multiple security layers, such as endpoints, networks, cloud, and email, to provide a wider range of threat detection and response capabilities.

[0079] (6) Dynamic Host Configuration Protocol (DHCP) is a network protocol used to automatically assign IP addresses and other network configuration parameters to devices in a network.

[0080] The DHCP DISCOVER message is used to find an available DHCP server on the network and request an IP address allocation. It is the first step in the DHCP protocol interaction process.

[0081] A DHCP OFFER message is a response message sent by a DHCP server after receiving a DHCP Discover message from a client. The DHCP OFFER message contains the IP address assigned by the server to the client and other network configuration information.

[0082] A DHCP server can be located on the north side of the network access device, and does not necessarily have to be directly connected to the network access device. It is used to provide IP addresses to terminal devices.

[0083] (7) HTTPS is a protocol for securely transmitting data over the Internet. It is an encrypted version of HTTP. By combining the Secure Sockets Layer / Transport Layer Security (SSL / TLS) protocol on top of HTTP, HTTPS provides encrypted protection for network communication and ensures the security of data during transmission between the client and the server.

[0084] RESTCONF is a network device configuration and management protocol based on the principle of representational state transfer (REST).

[0085] NETCONF is a network management protocol based on Extensible Markup Language (XML) used for configuring and managing network devices.

[0086] ARP is a network protocol used to resolve network layer IP addresses to link layer hardware addresses, such as media access control (MAC) addresses. ARP packets are the core data structure of ARP, used to dynamically resolve the mapping relationship between IP addresses and hardware addresses within a local area network.

[0087] ICMP is a network layer protocol used to send control messages and error reports in IP networks, helping network devices diagnose problems, report errors, and provide network status information.

[0088] BFD is a protocol for quickly detecting network link failures. It supports single-hop and multi-hop link detection and detects link status by periodically sending control messages. It can detect link failures in milliseconds, thereby accelerating network failure recovery.

[0089] (8) The northbound interface is an interface in a system or device that faces the upper-layer application or management system. It is mainly used to provide services and data to the upper layer, enabling the upper-layer system to manage, configure and monitor the system or device.

[0090] There are two main scenarios in NAC where the VLAN to which a terminal device belongs is adjusted. First, after a terminal device successfully authenticates while attempting to access the network, NAC authorizes the device, which may involve assigning the device to a specific VLAN. In this case, the VLAN to which the terminal device belongs changes before and after authentication. Second, in scenarios where NAC and EDR are integrated, when EDR generates a threat event, it will trigger NAC to adjust the authorization result for the terminal device, switching the VLAN to isolate the threatened terminal device and ensure network security.

[0091] However, after NAC adjusts the VLAN to which the terminal device belongs, the terminal device will not actively trigger a new IP address request. The user needs to manually perform the corresponding operation on the terminal device to trigger the request for a new IP address in order to update the terminal device's IP address. As a result, the terminal device's IP address cannot be updated in a timely manner, which will affect the terminal device's communication.

[0092] Currently, IP addresses can be automatically assigned via DHCP. Specifically, DHCP will attempt to renew the IP address lease when it has 1 / 2 and 7 / 8 remaining. If no response is received from the server, the current IP address will be discontinued, and the DHCP-based IP address acquisition process will restart. However, after adjusting the VLAN in NAC, DHCP cannot be automatically triggered; it must wait for the lease to expire. This waiting time is long. Even with a default lease period of 1 day for dynamic allocation, the IP address of the terminal device cannot be updated in a timely manner.

[0093] For dumb terminals that do not support user interface operations, such as printers, the flash authentication interface can be used to trigger the terminal device under the flash authentication interface to re-request an IP address. However, this method requires a specific flash authentication interface and has poor compatibility. Furthermore, it requires that there is only one terminal device under the flash authentication interface, or that the flash authentication interface is directly connected to the terminal device; otherwise, a flash interruption of the flash authentication interface will affect other terminal devices under the flash authentication interface. Therefore, wireless access users are not supported in triggering a re-request of an IP address via a flash interruption of the flash authentication interface, and the flash authentication interface must be a physical interface, not an Ethernet link aggregation (Eth-trunk) interface.

[0094] To address this, this application discloses a communication method, apparatus, system, storage medium, and program product. When the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC sends first information indicating a VLAN switch to the terminal device and fifth information indicating the VLAN switch to the network access device. This allows the terminal device to promptly detect a potential VLAN switch and quickly assess whether a switch has occurred. If a VLAN switch has occurred, the terminal device can promptly receive the third information and obtain the IP address corresponding to the new VLAN from it, thereby updating the terminal device's IP address in a timely manner. This reduces offline latency caused by VLAN switching, avoids impacting terminal device communication, and improves user experience. Furthermore, it achieves timely IP address updates without requiring a specific intermittent authentication interface, demonstrating strong compatibility.

[0095] Specifically, please refer to Figure 3, which is a flowchart illustrating a communication method provided in this application. This communication method can be implemented through a communication system as shown in Figure 2. The communication system may include NAC 1, network access device 2, terminal device 3, first server 4, and second server 5. Unless otherwise specified, in this application, "NAC" can refer to the NAC itself, a component within the NAC (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing all or part of the NAC's functions; in this application, "network access device" can refer to the network access device itself, a component within the network access device (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing all or part of the network access device's functions; "terminal device" can refer to the terminal device itself, a component within the terminal device (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing all or part of the terminal device's functions; in this application, "server" can refer to the server itself, a component within the server (e.g., a processor, chip, or chip system), or a logical module or software capable of implementing all or part of the server's functions. The communication method provided in this application embodiment may include:

[0096] S301.NAC sends the first information to the terminal device.

[0097] The first piece of information is used to indicate that a VLAN switch has occurred.

[0098] In this embodiment of the application, after the NAC sends the first information to the terminal device, the terminal device can receive the first information accordingly and learn from the first information that the VLAN to which it belongs is about to be switched, so as to further verify whether the VLAN to which it belongs has been switched.

[0099] It should be noted that the VLAN to which the terminal device belongs refers to the VLAN to which the terminal device is connected.

[0100] S302.NAC sends the fifth message to the network access device.

[0101] The fifth piece of information is used to indicate the VLAN switching.

[0102] It should be noted that the execution order of S301 and S302 is not limited in the embodiments of this application. S301 can be executed first and then S302; S302 can be executed first and then S301; or S301 and S302 can be executed simultaneously.

[0103] In this embodiment of the application, after the NAC sends the fifth information to the network access device, the network access device can receive the fifth information and learn from the fifth information that it needs to switch VLANs. Then the network access device can switch VLANs.

[0104] S303. The terminal device sends the second information.

[0105] The second piece of information is used to detect whether a VLAN switch has occurred.

[0106] It should be noted that in this embodiment, the first server is the server in the original VLAN, and the second server is the server in the switched VLAN. The second information in this embodiment may be sent to the first server, or it may be sent to the second server, or neither the first nor the second server may receive the second information.

[0107] In this embodiment, after the terminal device sends the second information, if the network access device has not yet switched VLANs, the second information may be sent to the first server, and the terminal device will receive the response information corresponding to the second information from the first server. If the network access device has completed the VLAN switch and the second information has not been sent to the second server, the terminal device will not receive the response information corresponding to the second information. If the network access device has completed the VLAN switch and the second information has just been sent to the second server, the terminal device may receive the response information corresponding to the second information from the second server. Here, the response information from the second server may be the third information.

[0108] S304. The second server sends third information to the terminal device.

[0109] The third piece of information is used to indicate the IP address corresponding to the switched VLAN.

[0110] In this embodiment of the application, when a VLAN is switched, the second server will send third information to the terminal device. The terminal device can receive the third information and obtain the new IP address from the third information, that is, obtain the IP address corresponding to the switched VLAN.

[0111] As can be seen, in this embodiment, when the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC sends first information indicating a VLAN switch to the terminal device and fifth information indicating a VLAN switch to the network access device. This allows the terminal device to promptly detect a potential VLAN switch and quickly determine if a switch has occurred. If a VLAN switch has occurred, the terminal device can promptly receive the third information and obtain the IP address corresponding to the new VLAN from it, thus updating the terminal device's IP address in a timely manner. This reduces offline latency caused by VLAN switching, avoids impacting terminal device communication, and improves user experience. Furthermore, it achieves timely IP address updates without requiring a specific intermittent authentication interface, demonstrating strong compatibility.

[0112] Please refer to Figure 4, which is a flowchart illustrating another communication method provided in this application. Figure 4 provides a more detailed explanation of the communication method based on the method provided in Figure 3. The communication method in Figure 4 can also be executed by a communication system. The definitions of "NAC," "network access device," "terminal device," and "server" in the embodiment shown in Figure 4 are the same as those in the embodiment shown in Figure 3, and will not be repeated here. The communication method provided in this application embodiment may include:

[0113] S401.NAC sends a notification message to the terminal device.

[0114] It is understood that S401 is similar to S301 in the above embodiments, and the same parts will not be described again here.

[0115] The notification message carries first information, which indicates that a VLAN switch has occurred. The notification message may include HTTP messages, HTTPS messages, etc., and this embodiment does not impose any limitations on this.

[0116] In one possible implementation, S401 may include: the NAC sending an HTTP message to the terminal device, the HTTP message carrying first information; or, the NAC sending an HTTPS message to the terminal device, the HTTPS message carrying the first information. In this way, the terminal device can indicate a VLAN switchover using existing HTTP or HTTPS messages without designing new messages, thus improving the feasibility of the solution.

[0117] Please refer to Figure 5, which is a schematic diagram of an HTTPS message provided in an embodiment of this application. The "VLAN change message" in Figure 5 is the first information. In this embodiment of the application, the NAC can first complete an SSL / TLS handshake with the terminal device, and then carry the first information in the HTTP request body of the data transmission stage, that is, carry the VLAN change notification message in the HTTP request body of the data transmission stage, and send the HTTPS message to the terminal device.

[0118] It should be noted that due to changes in access authentication, security events, etc., the NAC needs to switch VLANs for specific terminal devices. Because after the VLAN switch, the terminal device and the detection and response software deployed on it will lose connection with the NAC, it is necessary to notify the terminal device in advance. Specifically, the detection and response software deployed on the terminal device can be notified in advance to initiate its response process for the event. The detection and response software in this embodiment can be an EDR Agent, XDR, etc., and this embodiment does not impose any limitations on this.

[0119] S402.NAC sends a handover message to the network access network.

[0120] It is understood that S402 is similar to S302 in the above embodiments, and the same parts will not be described again here.

[0121] The handover message carries a fifth piece of information, which indicates the VLAN switching. The handover message may include RESTCONF messages, NETCONF messages, etc., and this embodiment does not impose any limitations on this.

[0122] In one possible implementation, S402 may include: the NAC sending a RESTCONF message to the network access network, the RESTCONF message carrying fifth information; or, the NAC sending a NETCONF message to the network access network, the NETCONF message carrying fifth information. In this way, the terminal device can indicate VLAN switching using existing RESTCONF or NETCONF messages, without needing to design new messages, thus improving the feasibility of the solution. Furthermore, multiple messages can be used to indicate VLAN switching, allowing the appropriate message to be selected based on actual conditions, facilitating the implementation of the solution.

[0123] In this embodiment, the NAC can communicate with the network access device through the northbound interface of the network access device, carrying the fifth piece of information in a RESTCONF or NETCONF message, that is, carrying the VLAN change command in a RESTCONF or NETCONF message. The NETCONF message in this embodiment consists of a message header and a message body. The message header is mainly used to delimit the message, and the message body is XML data containing specific operation information. On a Transmission Control Protocol (TCP) connection, NETCONF messages typically use length prefixing or framing characters for delimitation.

[0124] Please refer to Figure 6, which is a schematic diagram of a NETCONF message header provided in an embodiment of this application. The message header uses a length prefix to delimit the message.

[0125] Taking the example that the VLAN ID of the terminal device before the handover was 100 and the VLAN ID of the terminal device after the handover is 119, an example of the NETCONF message in this application embodiment can be as follows:

[0126] In one possible implementation, the fifth piece of information could be the identifier of the switched VLAN, etc.

[0127] S403. Network access devices switch VLANs based on the fifth information.

[0128] In this embodiment, after the NAC sends the handover message, the network access device can receive the corresponding handover message and obtain the fifth information from it, thereby knowing how to perform the VLAN handover, such as switching the VLAN with VLAN ID 100 to the VLAN with VLAN ID 119, etc. It should be understood that the above is merely an illustrative description and should not be construed as a limitation on the embodiments of this application.

[0129] It should be noted that after the network access device completes the VLAN switch, the terminal device and the detection and response software deployed on the terminal device are connected to the new VLAN. At this time, because the IP address of the terminal device has not been updated, it cannot establish a connection with NAC in the new VLAN.

[0130] S404. The terminal device sends a probe message.

[0131] It is understood that S404 is similar to S303 in the above embodiments, and the same parts will not be described again here.

[0132] It should be noted that the first server and the second server in the embodiments of this application can be DHCP servers, that is, the first server can be described as the first DHCP server and the second server can be described as the second DHCP server.

[0133] The probe message carries second information, which is used to detect whether a VLAN switch has occurred. The probe message may include DHCP DISCOVER messages, DHCP REQUEST messages, ARP messages, ICMP messages, BFD messages, etc., and this application embodiment does not limit this.

[0134] In one possible implementation, S404 may include: the terminal device sending a second DHCP DISCOVER message carrying second information; or, the terminal device sending a DHCP REQUEST message carrying second information; or, the terminal device sending an ARP message carrying second information; or, the terminal device sending an ICMP message carrying second information; or, the terminal device sending a BFD message carrying second information. The terminal device can initiate a DHCP probe; if the original DHCP server does not respond, it indicates a VLAN switch. The terminal device can also send ARP, ICMP, or BFD messages to probe the original gateway or DHCP server address; if there is no response, it indicates a VLAN switch. Thus, the terminal device can use existing DHCP DISCOVER, DHCP REQUEST, ARP, ICMP, or BFD messages to detect whether its VLAN has switched, without needing to design new messages, improving the feasibility of the solution. Furthermore, multiple message types can be used to detect whether the VLAN to which the terminal device belongs has changed. This allows for the selection of appropriate messages based on the actual situation, facilitating the implementation of the solution.

[0135] Please refer to Figure 7, which is a schematic diagram of a DHCP DISCOVER message provided in an embodiment of this application. In Figure 7, Op represents the opcode, occupying 1 byte. An Op value of 1 indicates a request message, and an Op value of 2 indicates a response message. In the DHCP DISCOVER message, the Op value is 1. In Figure 7, Htype represents the hardware address type, occupying 1 byte. A common value is 1, indicating Ethernet. In Figure 7, Hlen represents the hardware address length, occupying 1 byte. For Ethernet, this value is 6. In Figure 7, Hops represents the hop count, occupying 1 byte. It is set to 0 when sent by the terminal device and increments by 1 for each relay agent. In Figure 7, Xid represents the transaction ID, occupying 4 bytes. It is generated by the terminal device and used to match requests and responses. The Xid values ​​are the same for request and response messages in the same DHCP interaction process. In Figure 7, Secs represents the seconds, occupying 2 bytes. It represents the time elapsed since the terminal device began attempting to obtain an IP address, in seconds. In Figure 7, the Flags field represents the flag bits, occupying 2 bytes. The highest bit is the broadcast flag; if it's 1, it indicates the terminal device requests the DHCP server to send a response message via broadcast; if it's 0, it indicates the response message is sent via unicast. The remaining bits are reserved and are generally 0. The Ciaddr field in Figure 7 represents the terminal device's IP address, occupying 4 bytes. In a DHCP DISCOVER message, the terminal device has not yet obtained an IP address, and this field is usually 0.0.0.0. The Yiaddr field in Figure 7 represents the IP address assigned to the terminal device by the DHCP server, occupying 4 bytes. In a DHCP DISCOVER message, this field is 0.0.0.0. The Siaddr field in Figure 7 represents the server's IP address, occupying 4 bytes. In a DHCP DISCOVER message, the terminal device does not know the server address, and this field is 0.0.0.0. The Giaddr field in Figure 7 represents the gateway's IP address, occupying 4 bytes. If there is a relay agent, this field represents the relay agent's IP address; otherwise, it is 0.0.0.0. In Figure 7, `Chaddr` represents the terminal device's hardware address, occupying 16 bytes, and is typically the MAC address of the terminal device's network card. `Sname` represents the server name, occupying 64 bytes; this is an optional field, and the name of a DHCP server is generally an empty string. `File` represents the boot file name, occupying 128 bytes; this is an optional field used to specify the file to be loaded when the terminal device starts up, and is generally an empty string in DHCP Discover messages. `Options` represents the options, a variable-length field containing various parameters and information requested by the terminal device, as well as configuration information returned by the server. Each option consists of three parts: "code + length + value".

[0136] The corresponding server response message is a DHCP OFFER message, with a structure similar to the DHCP DISCOVER message described above, with an Op value of 2 and an Option value of 53. It's important to note that when a DHCP server receives a duplicate DHCP DISCOVER message, it will attempt to provide the previously assigned IP address to the terminal device to improve the stability and efficiency of the DHCP allocation process. If the responding IP address hasn't changed, the VLAN remains unchanged; if there's no response, or a new DHCP server responds, the VLAN update is considered complete. Specifically, assuming there's only one DHCP server in a VLAN, if there's no response, a new IP address needs to be obtained; if a new DHCP server responds, a new IP address doesn't need to be obtained.

[0137] It should be noted that the original DHCP server is the first server mentioned above, and the new DHCP server is the second server mentioned above.

[0138] It's important to note that terminal devices use DHCP REQUEST messages when their IP address leases are about to expire. Specifically, when a terminal device has used half of its IP address lease time, it sends a DHCPREQUEST message to the DHCP server that assigned it the IP address, requesting renewal of the currently used IP address. This point in time is called T1, and T1 is typically set to 50% of the lease period. If the DHCP server is functioning correctly and there are no conflicts such as other terminal devices requesting the IP address, the DHCP server will send a Dynamic Host Configuration Protocol Acknowledgment (DHCP ACK) message in response, agreeing to the terminal device's renewal request. The terminal device can then continue using the IP address, and the lease time is recalculated from the moment the response is received. If the client's renewal request sent at time T1 does not receive a response from the DHCP server, then when the lease time reaches 87.5% (T2), the client will send another DHCP REQUEST message to the DHCP server to request renewal. If the client's renewal request sent at time T2 still does not receive a response from the server, then when the lease expires, the terminal device must stop using the current IP address and resend a DHCP DISCOVER message to begin a new round of IP address acquisition, just as when the terminal device first connected to the network, obtaining a new IP address and network configuration information from the DHCP server. Therefore, a DHCP REQUEST message can be used to probe, and the response result can determine the VLAN switching status; no response indicates that a VLAN switching has occurred.

[0139] Please refer to Figure 8, which is a schematic diagram of an ARP message provided in an embodiment of this application. In this embodiment, the terminal device can use the ARP message to probe the address of the original gateway or DHCP server. If there is no response, it indicates that a VLAN switch has occurred. Assuming the address of the original gateway or DHCP server is 172.168.1.1, the ARP message can be as shown in Figure 8. In Figure 8, the destination Ethernet address (or destination MAC address) occupies 48 bits. When sending an ARP request, it is a broadcast MAC address, 0xFFFF-FFFF-FFFF. The sender Ethernet address (or source MAC address) occupies 48 bits. The frame type occupies 16 bits in Figure 8, indicating the type of data that follows. For ARP requests or responses, the value of this field is 0x0806. The hardware type occupies 16 bits in Figure 8, indicating the type of hardware address. For Ethernet, the value of this type is "1". The protocol type in Figure 8 occupies 16 bits, indicating the type of protocol address the sender wants to map. For IP addresses, this value is 0x0800. The hardware length in Figure 8 occupies 8 bits, indicating the length of the hardware address in bytes. For ARP requests or replies, this value is 6. The protocol length in Figure 8 occupies 8 bits, indicating the length of the protocol address in bytes. For ARP requests or replies, this value is 4. The operation (OP) in Figure 8 occupies 16 bits, indicating the operation type. 1 represents an ARP request, 2 represents an ARP reply, 3 represents a Reverse Address Resolution Protocol (RARP) request, and 4 represents a RARP reply. The sender's Ethernet address in Figure 8 is repeated in the ARP header. The sender's IP address in Figure 8 occupies 32 bits. In Figure 8, the destination Ethernet address, i.e., the receiver's Ethernet address, occupies 48 bits. When sending an ARP request, this address is filled with the value 0x00.00.00.00.00.00. The destination IP address, i.e., the receiver's IP address, occupies 32 bits.

[0140] It should be noted that the structure of response messages in ARP is similar to that of request messages, except that the opcode value is 2.

[0141] Please refer to Figure 9, which is a schematic diagram of an ICMP message provided in an embodiment of this application. In this embodiment, the terminal device can use the ICMP message to probe the original gateway or DHCP server address. If there is no response, it indicates that a VLAN switch has occurred. The type in Figure 9 occupies 1 byte and is the core identifier of the ICMP message, used to distinguish different types of ICMP messages. For example, a value of 8 represents an echo request, such as a ping command request; a value of 0 represents an echo response, corresponding to a ping request response; and a value of 3 indicates that the destination is unreachable. The code in Figure 9 also occupies 1 byte. This field is used to further subdivide the situation under a specific ICMP type. For example, when the type is 3, the code can indicate specific reasons such as network unreachable, host unreachable, or port unreachable. The checksum in Figure 9 occupies 2 bytes. Its function is to perform error detection on the entire ICMP message, including the header and data portion. The sender calculates the checksum based on the message content and fills it into this field. The receiver recalculates the checksum after receiving the message and compares them to determine whether an error occurred during message transmission. The identifier in Figure 9 is an optional field, occupying 2 bytes. In scenarios where multiple ICMP requests are sent simultaneously, it is used to match requests and responses. For example, in a multi-threaded environment, multiple ping requests can be initiated simultaneously, each request using a different identifier, so that the received response can accurately correspond to the corresponding request. The sequence number in Figure 9 is also an optional field, occupying 2 bytes, used to number ICMP messages. The sender can use the sequence number to track the sending order of messages, while the receiver can detect whether messages are lost or out of order. For example, when sending multiple ping requests consecutively, each request has an incrementing sequence number, facilitating statistics and analysis. The length of the optional data in Figure 9 is variable, and its content depends on the specific type and purpose of the ICMP message. In echo request and response messages, this part can contain user-defined data for testing network performance, transmitting additional information, etc. For example, the ping command can carry some custom data blocks to test the network's ability to process data packets of different sizes.

[0142] Please refer to Figure 10, which is a schematic diagram of a BFD message provided in an embodiment of this application. In this embodiment, the terminal device can use the BFD message to probe the original gateway or DHCP server address. If there is no response, it indicates that a VLAN switch has occurred. The version in Figure 10 occupies 4 bits. Currently, the commonly used version number for the BFD protocol is 1. This field is used to identify the protocol version followed by the BFD message, ensuring that both communicating parties use the same protocol rules for parsing and processing. The diagnostic in Figure 10 occupies 4 bits and is used to represent the diagnostic information of the BFD session. For example, a value of 0 indicates that the session is normal, and a non-zero value indicates that the session has encountered a certain fault condition. Different non-zero values ​​correspond to different fault types, such as link failure, peer device failure, etc. The state in Figure 10 occupies 2 bits and indicates the current state of the BFD session. Common states include 00 indicating Down state, i.e., the session has not been established or has been disconnected; 01 indicating Init state, i.e., the session is being initialized; and 11 indicating Up state, i.e., the session has been established and is running normally. In Figure 10, the `Poll` bit occupies 1 bit and indicates whether it is in polling mode. When this bit is 1, it indicates that BFD messages are sent in polling mode. This mode is usually used in some special scenarios, such as quickly detecting link status when network topology changes. A value of 0 indicates that normal timed sending mode is used. The `Final` bit in Figure 10 occupies 1 bit and is used in some cases to indicate whether this is the last BFD message. For example, during session closure, this bit can be set to 1 when sending the last BFD message to notify the other end that this is the last message of this session. The `control plane` bit in Figure 10 occupies 1 bit and is used to identify whether this BFD session is related to the control plane. If it is related to the control plane, it may be used to support control plane functions such as routing protocols, such as quickly detecting the connectivity of routing links to adjust the routing table in a timely manner. The `management plane` bit in Figure 10 occupies 1 bit and is used to identify whether this BFD session is related to the management plane. BFD sessions related to the management plane can be used for management-related detection functions, such as real-time monitoring of device link status by a device management system. In Figure 10, the reserved bits occupy 2 positions and are typically set to 0 for future expansion. As the BFD protocol evolves, these reserved bits may be used to add new functions or features. The detect multiplier in Figure 10 occupies 8 bits and specifies the time multiplier required to detect the peer as unreachable. This value is multiplied by the BFD message transmission interval to obtain the threshold of how many consecutively lost BFD messages are considered before considering the peer unreachable. The value typically ranges from 1 to 255, and users can adjust this value according to actual network conditions to balance the timeliness and accuracy of detection.In Figure 10, the 16-bit "length" field represents the total length of the BFD message, including the header and data. The receiver uses this field to accurately extract the complete BFD message from the network data. The 32-bit "My Discriminator" field is the local identifier, used to uniquely identify the local BFD session within a system. Each BFD session has a unique "My Discriminator" value, facilitating local device differentiation between different BFD sessions. The 32-bit "Your Discriminator" field is the peer identifier, used to identify the peer device's BFD session. The local device uses this field to identify the peer device, ensuring that the BFD message accurately matches the peer's session. The optional parameters in Figure 10 are of variable length and may include authentication information, extended functions, and other optional parameters. For example, in network environments requiring security authentication, the optional parameters may include authentication keys and other information. Additional parameters with extended functions can also be added based on specific application requirements.

[0143] Please refer to Figure 11, which is a flowchart illustrating a network environment detection process according to an embodiment of this application. In this embodiment, the detection and response software deployed on the terminal device initiates a network environment detection process upon receiving a notification message. Before the network access device switches VLANs, it can receive a response message from the first server in the original VLAN. If a response message from the first server in the original VLAN is received, the detection continues. After the network access device switches VLANs, it cannot receive a response from the first server. Multiple detection messages need to be sent to determine if the VLAN has switched. After determining that the VLAN has switched, the terminal device triggers a DHCP IP address request process, such as sending a DHCP DISCOVER message to a second server, which then responds with a DHCP OFFER message.

[0144] It should be noted that when a terminal device sends a probe packet to probe, the lack of response indicates that the VLAN may be switching. To confirm the VLAN switch, after the initial lack of response, it can be confirmed in certain ways, including but not limited to: a) no response after a specified number of probes, confirming the VLAN switch; b) no response after a specified time period, confirming the VLAN switch; c) no response after a specified number of probes within a specified time period, confirming the VLAN switch.

[0145] In one possible implementation, the communication method provided in this application further includes: determining that a VLAN switch has occurred when the number of times the second information is sent exceeds a first threshold and no response information corresponding to the second information is received; or, determining that a VLAN switch has occurred when the second information is sent multiple times within a first time period and no response information corresponding to the second information is received within the first time period; or, determining that a VLAN switch has occurred when the number of times the second information is sent within a second time period exceeds a second threshold and no response information corresponding to the second information is received. The first time period, first threshold, second time period, and second threshold can be set according to actual needs, and this application does not impose any restrictions on them. By setting the first threshold, or the first time period, or the second time period and the second threshold, jitter can be eliminated, and the timing and accuracy of determining whether a VLAN switch has occurred can be improved. This allows for timely updates of the terminal device's IP address when a VLAN switch occurs, avoiding any impact on the terminal device's communication.

[0146] S405. In the event of a VLAN switch, the terminal device sends a request message.

[0147] The request message carries fourth information, which is used to request an IP address. The request message may include DHCP DISCOVER messages, etc., and this embodiment does not limit this.

[0148] In one possible implementation, S405 may include sending a first DHCP DISCOVER message carrying fourth information. This allows the terminal device to request a new IP address using existing DHCP DISCOVER messages without needing to design new messages, thus improving the feasibility of the solution.

[0149] In one possible implementation, upon VLAN switching, the terminal device can execute a first instruction to trigger a request for an IP address. Correspondingly, upon VLAN switching, the terminal device can execute a first instruction to trigger the sending of a request packet. This first instruction can be to re-acquire network configuration information (ipconfig / renew), which can be executed by the detection and response software on the terminal device. ipconfig / renew is a command in the operating system used to update or re-acquire the DHCP configuration information of the network adapter, typically used to force the terminal device to re-request an IP address and other network configuration parameters from the DHCP server.

[0150] S406. The second server sends a response message to the terminal device.

[0151] In this embodiment of the application, after the terminal device sends a request message, the second server will receive the request message and send a response message to the terminal device.

[0152] The response message carries third information, which indicates the IP address corresponding to the switched VLAN. The response message may include DHCP OFFER messages, etc., and this embodiment does not limit this.

[0153] In one possible implementation, S406 may include: a second server sending a DHCP OFFER message carrying third information. This allows the terminal device to carry a new IP address using existing DHCP OFFER messages without needing to design new messages, thus improving the feasibility of the solution.

[0154] S407. The terminal device sends a connection message to the NAC.

[0155] In this embodiment, after the second server sends a response message, the terminal device receives the response message and obtains the third information from it. Based on the third information, it obtains the IP address corresponding to the switched VLAN. The terminal device can then send a connection message to the NAC to re-establish a connection. This process can use HTTPS or HTTP messages, similar to the process in S401, and will not be described further here.

[0156] The connection message carries a sixth piece of information, which is used to request a connection with NAC. The connection message may include HTTP messages, HTTPS messages, etc., and this embodiment does not impose any limitations on this.

[0157] As can be seen, in this embodiment, when the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC sends first information indicating a VLAN switch to the terminal device and fifth information indicating a VLAN switch to the network access device. This allows the terminal device to promptly detect a potential VLAN switch and quickly determine if a switch has occurred. If a VLAN switch occurs, the terminal device can promptly request a new IP address and obtain the IP address corresponding to the switched VLAN from the third information returned by the second server. This allows for timely updates to the terminal device's IP address, reducing offline latency caused by VLAN switching, avoiding impact on terminal device communication, and improving user experience. Furthermore, timely updates to the terminal device's IP address can be achieved without a specific intermittent authentication interface, demonstrating strong compatibility. In addition, in scenarios where permission adjustments are triggered by security events, the detection and response software can promptly reconnect to the NAC, reducing its offline time and enabling timely reporting of security events to the NAC for a response.

[0158] Please refer to Figure 12, which is a flowchart illustrating another communication method provided in this application. Figure 12 provides a more detailed explanation of the communication method based on the communication method provided in Figure 2. The communication method in Figure 12 can also be executed by a communication system. The definitions of "NAC," "network access device," "terminal device," and "server" in the embodiment shown in Figure 12 are the same as those in the embodiment shown in Figure 2 above, and will not be repeated here. The communication method provided in this application embodiment may include:

[0159] S1201.NAC sends a notification message to the terminal device.

[0160] It is understood that S1201 is the same as S401 in the above embodiments, so it will not be described again.

[0161] S1202.NAC sends a handover message to the network access network.

[0162] It is understood that S1202 is the same as S402 in the above embodiments, so it will not be described again.

[0163] S1203. Network access devices switch VLANs based on the fifth information.

[0164] It is understood that S1203 is the same as S403 in the above embodiments, so it will not be described again.

[0165] S1204. The terminal device sends a second DHCP DISCOVER message.

[0166] It is understood that S1204 is similar to S404 in the above embodiments, and the same parts will not be described again here.

[0167] It should be noted that the probe message in this embodiment is a second DHCP DISCOVER message. The second DHCP DISCOVER message sent by the terminal device is received by the second server, and a new IP address can be obtained directly based on the DHCP OFFER message returned by the second server.

[0168] S1205. The second server sends a DHCP OFFER message to the terminal device.

[0169] It is understood that S1206 is similar to S406 in the above embodiments, and the same parts will not be described again here.

[0170] It should be noted that the response message in this embodiment is the response message corresponding to the second DHCP DISCOVER message. This response message is a DHCP OFFER message, from which the IP address corresponding to the switched VLAN can be obtained directly without sending a request message to request a new IP address.

[0171] S1206. The terminal device sends a connection message to the NAC.

[0172] It is understood that S1206 is the same as S407 in the above embodiments, so it will not be described again.

[0173] As can be seen, in this embodiment, when the NAC needs to adjust the VLAN to which the terminal device belongs, the NAC sends a first message indicating a VLAN switch to the terminal device and a fifth message indicating a VLAN switch to the network access device. This allows the terminal device to promptly detect a potential VLAN switch and quickly probe for a VLAN switch using a second DHCP DISCOVER message. If a VLAN switch occurs, the terminal device can directly obtain the IP address corresponding to the new VLAN from the DHCP OFFER message returned by the second server, thus updating its IP address promptly, reducing offline latency caused by VLAN switching, avoiding impact on terminal device communication, and improving user experience. Furthermore, it achieves timely IP address updates without requiring a specific intermittent authentication interface, demonstrating strong compatibility. In addition, in scenarios where permission adjustments are triggered by security events, the detection and response software can promptly reconnect to the NAC, reducing its offline time and enabling timely reporting and response to security events from the terminal device to the NAC.

[0174] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0175] To facilitate better implementation of the above-described solutions in the embodiments of this application, related systems and apparatuses for implementing the above-described solutions are also provided below.

[0176] This application provides a communication system, which includes: a terminal device, a network access device (NAC), and a network access device.

[0177] NAC is used to send first information, which indicates that a VLAN switch has occurred.

[0178] Terminal equipment, used to receive the first information;

[0179] NAC is also used to send a fifth message, which indicates a VLAN switch.

[0180] Network access devices used for switching VLANs based on fifth information;

[0181] The terminal device is also used to send a second message, which is used to detect whether a VLAN switch has occurred;

[0182] The terminal device is also used to receive third information, which indicates the IP address corresponding to the switched VLAN.

[0183] It should be noted that, unless otherwise specified, the term "terminal device" in the embodiments of this application can refer to the terminal device itself, a component within the terminal device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the terminal device; the term "NAC" in the embodiments of this application can refer to the NAC itself, a component within the NAC (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the NAC; the term "network access device" in the embodiments of this application can refer to the network access device itself, a component within the network access device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the network access device.

[0184] In one possible implementation, the terminal device in the communication system provided in this application embodiment is further configured to send a fourth message when a VLAN switch occurs, the fourth message being used to request an IP address.

[0185] In one possible implementation, the terminal device in the communication system provided in this application embodiment is further configured to send a first DHCP DISCOVER message, which carries fourth information.

[0186] In one possible implementation, the terminal device in the communication system provided in this application embodiment is further configured to execute a first instruction when a VLAN switch occurs, the first instruction being used to trigger a request for an IP address.

[0187] In one possible implementation, the terminal device in the communication system provided in this application embodiment is further configured to determine that a VLAN switch has occurred when the number of times the second information is sent exceeds a first threshold and no response information corresponding to the second information is received; or, determine that a VLAN switch has occurred when the second information is sent multiple times within a first time period and no response information corresponding to the second information is received within the first time period; or, determine that a VLAN switch has occurred when the number of times the second information is sent within a second time period exceeds a second threshold and no response information corresponding to the second information is received.

[0188] In one possible implementation, the terminal device in the communication system provided in this application embodiment is specifically used to receive a DHCP OFFER message, which carries third information.

[0189] In one possible implementation, the terminal device in the communication system provided in this application embodiment is specifically used to send a second DHCP DISCOVER message, which carries second information; or, to send a DHCP REQUEST message, which carries second information.

[0190] In one possible implementation, the terminal device in the communication system provided in this application embodiment is specifically used to send an ARP message carrying second information; or, send an ICMP message carrying second information; or, send a BFD message carrying second information.

[0191] In one possible implementation, the NAC in the communication system provided in this application embodiment is specifically used to send an HTTP message carrying first information; or to send an HTTPS message carrying first information.

[0192] In one possible implementation, the NAC in the communication system provided in this application embodiment is specifically used to send a RESTCONF message to the network access device, the RESTCONF message carrying fifth information; or, to send a NETCONF message to the network access device, the NETCONF message carrying fifth information.

[0193] Please refer to Figure 13, which is a schematic diagram of the structure of a communication device provided in an embodiment of this application. The communication device 1300 includes: a transceiver unit 1301 and a processing unit 1302.

[0194] The transceiver unit 1301 and the processing unit 1302 are used to enable the communication device 1300 to perform the functions of the terminal device in the above method embodiment, or to enable the communication device 1300 to perform the functions of NAC in the above method embodiment.

[0195] In some possible implementations, the communication device 1300 provided in the embodiments of this application further includes: a storage unit for storing any data, computer instructions and / or computer programs that may be involved in the embodiments of this application.

[0196] The communication device 1300 is installed on the terminal device, and the communication device 1300 will be described.

[0197] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is used to receive first information from NAC, which is used to indicate that a VLAN switch has occurred;

[0198] The transceiver unit 1301 is also used to send second information, which is used to detect whether a VLAN switch has occurred;

[0199] The transceiver unit 1301 is also used to receive third information, which is used to indicate the IP address corresponding to the switched VLAN.

[0200] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is used to send fourth information when a VLAN switch occurs, the fourth information being used to request an IP address.

[0201] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is specifically used to send a first DHCP DISCOVER message, which carries fourth information.

[0202] In some possible implementations, in the communication device 1300 provided in this application embodiment, the processing unit 1302 is used to execute a first instruction when a VLAN switch occurs, the first instruction being used to trigger a request for an IP address.

[0203] In some possible implementations, the processing unit 1302 in the communication device 1300 provided in this application embodiment is further configured to determine that a VLAN switch has occurred when the number of times the second information is sent exceeds a first threshold and no response information corresponding to the second information is received; or, determine that a VLAN switch has occurred when the second information is sent multiple times within a first time period and no response information corresponding to the second information is received within the first time period; or, determine that a VLAN switch has occurred when the number of times the second information is sent within a second time period exceeds a second threshold and no response information corresponding to the second information is received.

[0204] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is specifically used to receive DHCP OFFER messages, which carry third information.

[0205] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is specifically used to send a second DHCP DISCOVER message, which carries second information; or, to send a DHCP REQUEST message, which carries second information.

[0206] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is specifically used to send an ARP message carrying second information; or, send an ICMP message carrying second information; or, send a BFD message carrying second information.

[0207] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is specifically used to receive an HTTP message from NAC, the HTTP message carrying first information; or, to receive an HTTPS message from NAC, the HTTPS message carrying first information.

[0208] The communication device 1300 is installed on the NAC, and the communication device 1300 will be described.

[0209] In some possible implementations, in the communication device 1300 provided in this application embodiment, the transceiver unit 1301 is used to send first information to the terminal device, the first information being used to indicate that a VLAN switch has occurred, so as to trigger the terminal device to detect whether a VLAN switch has occurred.

[0210] The transceiver unit 1301 is used to send fifth information to the network access device, which is used to indicate VLAN switching.

[0211] In some possible implementations, the transceiver unit 1301 in the communication device 1300 provided in this application embodiment is specifically used to send a RESTCONF message to the network access device, the RESTCONF message carrying fifth information; or, to send a NETCONF message to the network access device, the NETCONF message carrying fifth information.

[0212] It should be noted that the information interaction and execution process between the various units of the above-mentioned device are based on the same concept as the method embodiment of this application, and the resulting technical effects are the same as those of the method embodiment of this application. For details, please refer to the description in the method embodiment shown above in this application, and it will not be repeated here.

[0213] Figure 14 illustrates another example of the composition of a communication device provided in an embodiment of this application. This communication device can be a third device, including but not limited to mobile phones, smart wearable devices (such as smartwatches), and other electronic devices. Taking a mobile phone as an example, the communication device may include a processor 310, an external memory interface 320, an internal memory 321, a display screen 330, a camera 340, an antenna 100, an antenna 200, a cellular communication module 350, and a short-range communication module 360, etc.

[0214] It is understood that the structure illustrated in this embodiment does not constitute a specific limitation on the communication device. In other embodiments, the communication device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0215] Processor 310 may include one or more processing units, such as: application processor (AP), modem processor, graphics processing unit (GPU), image signal processor (ISP), controller, video codec, digital signal processor (DSP), baseband processor, and / or neural network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.

[0216] It is understood that the interface connection relationships between the modules illustrated in this embodiment are merely illustrative and do not constitute a structural limitation on the communication device. In other embodiments of this application, the communication device may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.

[0217] The external storage interface 320 can be used to connect an external storage card, such as a Micro SD card, to expand the storage capacity of the communication device. The external storage card communicates with the processor 310 through the external storage interface 320 to perform data storage functions. For example, music, video, and other files can be saved on the external storage card.

[0218] Internal memory 321 can be used to store computer executable program code, which includes instructions. Processor 310 executes various functional applications and data processing of the communication device by running the instructions stored in internal memory 321, thereby implementing the communication method described in the above embodiments. Internal memory 321 may include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback, image playback, etc.), etc. The data storage area may store data created during the use of the communication device (such as audio data, phonebook, etc.). Furthermore, internal memory 321 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc. Processor 310 executes various functional applications and data processing of the communication device by running instructions stored in internal memory 321 and / or instructions stored in memory located within the processor.

[0219] The wireless communication function of the communication device can be realized through antenna 100, antenna 200, cellular communication module 350, short-range communication module 360, modem processor and baseband processor, etc.

[0220] Antennas 100 and 200 are used to transmit and receive electromagnetic wave signals. Each antenna in the communication device can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 100 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with a tuning switch.

[0221] The cellular communication module 350 can provide solutions for wireless communication applications including 2G / 3G / 4G / 5G in communication devices. The cellular communication module 350 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The cellular communication module 350 can receive electromagnetic waves through the antenna 100, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The cellular communication module 350 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation through the antenna 100. In some embodiments, at least some functional modules of the cellular communication module 350 may be housed in the processor 310. In some embodiments, at least some functional modules of the cellular communication module 350 and at least some modules of the processor 310 may be housed in the same device.

[0222] In some embodiments, the communication device initiates or receives call requests via cellular communication module 350 and antenna 100.

[0223] Furthermore, an operating system runs on the aforementioned components. Examples include iOS, Android, and Windows operating systems. Applications can be installed and run on this operating system. Those skilled in the art will understand that, for the sake of convenience and brevity, explanations and beneficial effects of the relevant content in any of the communication devices provided above can be found in the corresponding method embodiments provided above, and will not be repeated here.

[0224] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between devices or modules, and may be electrical, mechanical, or other forms.

[0225] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0226] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0227] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the essential contribution of the technical solution of this application, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the processes of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0228] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A communication method, characterized in that, The method includes: Receive first information from the network access controller, the first information being used to indicate that a virtual LAN switch has occurred; Send a second message, which is used to detect whether the virtual local area network has switched; Receive third information, which is used to indicate the Internet Protocol address corresponding to the switched virtual LAN.

2. The method according to claim 1, characterized in that, The method further includes: In the event of a switch in the virtual local area network, a fourth message is sent, which requests the Internet Protocol address.

3. The method according to claim 2, characterized in that, The sending of the fourth information includes: Send a first Dynamic Host Configuration Protocol (DHCP) discovery message, which carries the fourth information.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: In the event of a switch in the virtual local area network, a first instruction is executed, which triggers a request for the Internet Protocol address.

5. The method according to any one of claims 2 to 4, characterized in that, The method further includes: If the number of times the second information is sent exceeds the first threshold and no response information corresponding to the second information is received, it is determined that the virtual local area network has been switched. Alternatively, if the second information is sent multiple times within a first time period and no response information corresponding to the second information is received within the first time period, it is determined that the virtual local area network has been switched. Alternatively, if the number of times the second information is sent exceeds the second threshold within the second time period, and no response information corresponding to the second information is received, it is determined that the virtual local area network has been switched.

6. The method according to any one of claims 1 to 5, characterized in that, The receipt of the third information includes: Receive a Dynamic Host Configuration Protocol (DHCP) Provider Message, wherein the DHCP Provider Message carries the third information.

7. The method according to any one of claims 1 to 6, characterized in that, The sending of the second information includes: Send a second Dynamic Host Configuration Protocol (DHCP) discovery message, which carries the second information. Alternatively, a Dynamic Host Configuration Protocol (DHCP) request message may be sent, the DHCP request message carrying the second information.

8. The method according to any one of claims 1 to 6, characterized in that, The sending of the second information includes: Send an Address Resolution Protocol (ARP) message, the ARP message carrying the second information; Alternatively, send an Internet Control Message Protocol (ICP) message, the ICP message carrying the second information; Alternatively, a bidirectional forwarding detection message may be sent, the bidirectional forwarding detection message carrying the second information.

9. The method according to any one of claims 1 to 8, characterized in that, The receipt of the first information from the network access controller includes: Receive a Hypertext Transfer Protocol (HTTP) message from a network access controller, the HTTP message carrying the first information; Alternatively, receive a Hypertext Transfer Security Protocol (HTTP) message from a network access controller, the HTTP message carrying the first information.

10. A communication method, characterized in that, The method includes: Send first information to the terminal device, the first information being used to indicate that a virtual local area network (VLAN) switch has occurred, so as to trigger the terminal device to detect whether the VLAN switch has occurred; A fifth message is sent to the network access device, the fifth message being used to instruct the switching of the virtual local area network.

11. The method according to claim 10, characterized in that, The sending of the fifth piece of information to the network access device includes: Send a representational state transition configuration message to the network access device, the representational state transition configuration message carrying the fifth information; Alternatively, a network configuration protocol message may be sent to the network access device, the network configuration protocol message carrying the fifth information.

12. A communication system, characterized in that, The system includes: terminal equipment, network access controller, and network access equipment; The network access controller is used to send first information, which is used to indicate that a virtual local area network (VLAN) switch has occurred. The terminal device is used to receive the first information; The network access controller is also configured to send a fifth message, the fifth message being used to instruct the switching of the virtual local area network; The network access device is used to switch the virtual local area network based on the fifth information; The terminal device is also used to send second information, which is used to detect whether the virtual local area network has switched. The terminal device is also used to receive third information, which is used to indicate the Internet Protocol address corresponding to the switched virtual local area network.

13. A communication device, characterized in that, The apparatus includes a module for performing the communication method as described in any one of claims 1 to 9, or a module for performing the communication method as described in any one of claims 10 to 11.

14. A communication device comprising at least one processor, the processor being configured to invoke computer instructions in memory to cause the communication device to perform the communication method as claimed in any one of claims 1 to 9, or to perform the communication method as claimed in any one of claims 10 to 11.

15. A computer-readable storage medium, characterized in that, Includes instructions that, when executed on a computer, cause the computer to perform the communication method as described in any one of claims 1 to 9, or to perform the communication method as described in any one of claims 10 to 11.

16. A computer program product, characterized in that, Includes instructions that, when executed on a computer, cause the computer to perform the communication method as described in any one of claims 1 to 9, or to perform the communication method as described in any one of claims 10 to 11.

17. A chip, characterized in that, The device includes one or more interface circuits and one or more processors; the interface circuits are configured to receive signals from the memory of the electronic device and send the signals to the processors, the signals including computer instructions stored in the memory; when the processor executes the computer instructions, the electronic device performs the communication method as described in any one of claims 1 to 9, or performs the communication method as described in any one of claims 10 to 11.