WO2023184264A1 - Traffic proxy methods and apparatuses, electronic device and storage medium - Google Patents

Traffic proxy methods and apparatuses, electronic device and storage medium Download PDF

Info

Publication number
WO2023184264A1
WO2023184264A1 PCT/CN2022/084176 CN2022084176W WO2023184264A1 WO 2023184264 A1 WO2023184264 A1 WO 2023184264A1 CN 2022084176 W CN2022084176 W CN 2022084176W WO 2023184264 A1 WO2023184264 A1 WO 2023184264A1
Authority
WO
WIPO (PCT)
Prior art keywords
data frame
terminal device
transmission channel
cloud server
local transmission
Prior art date
Application number
PCT/CN2022/084176
Other languages
French (fr)
Chinese (zh)
Inventor
李书珍
Original Assignee
北京小米移动软件有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 北京小米移动软件有限公司 filed Critical 北京小米移动软件有限公司
Priority to PCT/CN2022/084176 priority Critical patent/WO2023184264A1/en
Priority to CN202280000789.3A priority patent/CN114902635A/en
Publication of WO2023184264A1 publication Critical patent/WO2023184264A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/16Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]
    • H04L69/163In-band adaptation of TCP data exchange; In-band control procedures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/16Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]
    • H04L69/164Adaptation or special uses of UDP protocol

Abstract

The present disclosure relates to traffic proxy methods and apparatuses, an electronic device and a storage medium, belonging to the technical field of Internet of Things. A method comprises: establishing a transmission control protocol (TCP) connection channel with a cloud server; establishing a user datagram protocol (UDP) local transmission channel with one or more terminal devices in the Internet of Things; and by means of the TCP connection channel and the UDP local transmission channel, transmitting data frames required during communication of the terminal device(s) with the cloud server. Therefore, by means of the TCP connection channel and the UDP local transmission channel, the data frames required during communication of the terminal device(s) with the cloud server can be transmitted, thereby achieving proxy for traffics of the terminal device(s), reducing the pressure of TCP connection performed between the terminal device(s) and the cloud server, and improving the network service quality.

Description

一种流量代理方法、装置、电子设备及存储介质A traffic proxy method, device, electronic device and storage medium 技术领域Technical field
本公开涉及物联网技术领域,尤其涉及一种流量代理方法、装置、电子设备及存储介质。The present disclosure relates to the technical field of the Internet of Things, and in particular, to a traffic proxy method, device, electronic device and storage medium.
背景技术Background technique
目前,随着物联网技术的蓬勃发展,在普通家庭宽带下连网的终端设备的数量也越来越多。At present, with the vigorous development of Internet of Things technology, the number of terminal devices connected to the Internet under ordinary home broadband is also increasing.
随着终端设备的数量的增多,相应地终端设备与云服务器之间进行TCP(Transmission Control Protocol,传输控制协议)长连接的网络压力会增大,往往会降低网络服务质量。As the number of terminal devices increases, the network pressure on long TCP (Transmission Control Protocol) connections between terminal devices and cloud servers will increase, which often reduces network service quality.
发明内容Contents of the invention
本公开提供一种流量代理方法、装置、电子设备及存储介质,以至少解决相关技术中随着终端设备的数量的增多,终端设备和云服务器之间进行TCP连接的压力增大,降低网络服务质量的问题。The present disclosure provides a traffic proxy method, device, electronic device and storage medium to at least solve the problem in related technologies that as the number of terminal devices increases, the pressure on TCP connections between terminal devices and cloud servers increases and network services are reduced. Quality issues.
本公开的技术方案如下:The technical solutions of the present disclosure are as follows:
根据本公开实施例的第一方面,提供一种流量代理方法,适用于代理设备,包括:与云服务器建立传输控制协议TCP连接通道;与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道;通过所述TCP连接通道和所述UDP本地传输通道,传输所述终端设备与所述云服务器通信时所需数据帧。According to the first aspect of the embodiment of the present disclosure, a traffic proxy method is provided, which is suitable for proxy devices, including: establishing a transmission control protocol TCP connection channel with a cloud server; establishing a user connection with one or more terminal devices in the same Internet of Things Datagram protocol UDP local transmission channel; through the TCP connection channel and the UDP local transmission channel, the data frames required when the terminal device communicates with the cloud server are transmitted.
根据本公开实施例的第二方面,提供一种流量代理方法,适用于终端设备,包括:响应于与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道;通过所述UDP本地传输通道传输与所述云服务器通信所需的数据帧。According to a second aspect of the embodiment of the present disclosure, a traffic proxy method is provided, which is suitable for terminal devices, including: in response to establishing a User Datagram Protocol UDP local transmission channel with a proxy device in the Internet of Things, disconnecting from the cloud server The first TCP connection channel; transmits data frames required for communication with the cloud server through the UDP local transmission channel.
根据本公开实施例的第三方面,提供一种流量代理装置,适用于代理设备,包括:连接模块,被配置为执行与云服务器建立传输控制协议TCP连接通道;第一传输模块,被配置为执行与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道;第二传输模块,被配置为执行通过所述TCP连接通道和所述UDP本地传输通道,传输所述终端设备与所述云服务器通信时所需数据帧。According to a third aspect of the embodiment of the present disclosure, a traffic proxy device is provided, suitable for proxy equipment, including: a connection module configured to establish a transmission control protocol TCP connection channel with a cloud server; a first transmission module configured to Execute the establishment of a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things; the second transmission module is configured to execute the transmission of the User Datagram Protocol UDP local transmission channel through the TCP connection channel and the UDP local transmission channel. Data frames required when the terminal device communicates with the cloud server.
根据本公开实施例的第四方面,提供一种流量代理装置,适用于终端设备,包括:连接模块,被配置为执行响应于与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道;传输模块,被配置为执行通过所述UDP本地传输通道传输与所述云服务器通信所需的数据帧。According to a fourth aspect of the embodiment of the present disclosure, a traffic proxy device is provided, which is suitable for a terminal device and includes: a connection module configured to execute a response to establishing a User Datagram Protocol UDP local transmission channel with a proxy device in the Internet of Things , disconnect the first TCP connection channel with the cloud server; the transmission module is configured to perform transmission of data frames required for communication with the cloud server through the UDP local transmission channel.
根据本公开实施例的第五方面,提供一种电子设备,包括:处理器;用于存储所述处理器的可执行指令的存储器;其中,所述处理器被配置为执行所述指令,以实现如本公开实施例第一方面或者本公开实施例第二方面所述的流量代理方法。According to a fifth aspect of an embodiment of the present disclosure, an electronic device is provided, including: a processor; a memory for storing executable instructions of the processor; wherein the processor is configured to execute the instructions to Implement the traffic proxy method described in the first aspect of this disclosure embodiment or the second aspect of this disclosure embodiment.
根据本公开实施例的第六方面,提供一种计算机可读存储介质,当所述计算机可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行如本公开实施例第一方面或者本公开实施例第二方面所述的流量代理方法。According to a sixth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, which when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to execute the steps of the first embodiment of the present disclosure. The traffic proxy method described in one aspect or the second aspect of this disclosure embodiment.
本公开的实施例提供的技术方案至少带来以下有益效果:可通过TCP连接通道和UDP本地传输通 道对终端设备与云服务器通信时所需数据帧进行传输,实现了对终端设备流量的代理,减少了终端设备和云端服务器之间进行TCP连接的压力,提高了网络服务质量。The technical solution provided by the embodiments of the present disclosure at least brings the following beneficial effects: the data frames required when the terminal device communicates with the cloud server can be transmitted through the TCP connection channel and the UDP local transmission channel, realizing the proxy for the terminal device traffic, It reduces the pressure on TCP connections between terminal devices and cloud servers and improves network service quality.
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本公开。It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and do not limit the present disclosure.
附图说明Description of drawings
为了更清楚地说明本公开实施例或背景技术中的技术方案,下面将对本公开实施例或背景技术中所需要使用的附图进行说明。In order to more clearly illustrate the technical solutions in the embodiments of the disclosure or the background technology, the drawings required to be used in the embodiments or the background technology of the disclosure will be described below.
图1是根据一示例性实施例示出的一种流量代理方法的流程图。Figure 1 is a flow chart of a traffic proxy method according to an exemplary embodiment.
图2是根据一示例性实施例示出的流量代理的示意图。Figure 2 is a schematic diagram of a traffic proxy according to an exemplary embodiment.
图3是根据一示例性实施例示出的另一种流量代理方法的流程图。Figure 3 is a flow chart of another traffic proxy method according to an exemplary embodiment.
图4是根据一示例性实施例示出的建立UDP本地传输通道的交互示意图。Figure 4 is an interactive diagram illustrating the establishment of a UDP local transmission channel according to an exemplary embodiment.
图5是根据一示例性实施例示出的另一种流量代理方法的流程图。Figure 5 is a flow chart of another traffic proxy method according to an exemplary embodiment.
图6是根据一示例性实施例示出的另一种流量代理方法的流程图。Figure 6 is a flow chart of another traffic proxy method according to an exemplary embodiment.
图7是根据一示例性实施例示出的关闭UDP本地传输通道的交互示意图。Figure 7 is an interactive diagram illustrating closing a UDP local transmission channel according to an exemplary embodiment.
图8是根据一示例性实施例示出的另一种流量代理方法的流程图。Figure 8 is a flow chart of another traffic proxy method according to an exemplary embodiment.
图9是根据一示例性实施例示出的一种流量代理方法的流程图。Figure 9 is a flow chart of a traffic proxy method according to an exemplary embodiment.
图10是根据一示例性实施例示出的一种流量代理装置的框图。Figure 10 is a block diagram of a traffic proxy device according to an exemplary embodiment.
图11是根据一示例性实施例示出的另一种流量代理装置的框图。Figure 11 is a block diagram of another traffic proxy device according to an exemplary embodiment.
图12是根据一示例性实施例示出的一种电子设备的框图。FIG. 12 is a block diagram of an electronic device according to an exemplary embodiment.
具体实施方式Detailed ways
为了使本领域普通人员更好地理解本公开的技术方案,下面将结合附图,对本公开实施例中的技术方案进行清楚、完整地描述。In order to allow ordinary people in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings.
需要说明的是,本公开的说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便这里描述的本公开的实施例能够以除了在这里图示或描述的那些以外的顺序实施。以下示例性实施例中所描述的实施方式并不代表与本公开相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本公开的一些方面相一致的装置和方法的例子。It should be noted that the terms "first", "second", etc. in the description and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It is to be understood that the data so used are interchangeable under appropriate circumstances so that the embodiments of the disclosure described herein can be practiced in sequences other than those illustrated or described herein. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present disclosure. Rather, they are merely examples of apparatus and methods consistent with aspects of the disclosure as detailed in the appended claims.
图1是根据一示例性实施例示出的一种流量代理方法的流程图,适用于代理设备,如图1所示,本公开实施例的流量代理方法由代理设备执行,该方法可以包括以下步骤:Figure 1 is a flow chart of a traffic proxy method according to an exemplary embodiment, which is applicable to a proxy device. As shown in Figure 1, the traffic proxy method according to the embodiment of the present disclosure is executed by the proxy device. The method may include the following steps :
S101,与云服务器建立传输控制协议TCP连接通道。S101: Establish a transmission control protocol TCP connection channel with the cloud server.
需要说明的是,本公开实施例的流量代理方法的执行主体为代理设备,其中,代理设备包括但不限于手机、平板电脑、笔记本、台式电脑、车载终端、智能家电等。本公开实施例的流量代理方法可以由本公开实施例的流量代理装置执行,本公开实施例的流量代理装置可以配置在任意代理设备中,以执行本公开实施例的流量代理方法。It should be noted that the execution subject of the traffic proxy method in the embodiment of the present disclosure is a proxy device, where the proxy device includes but is not limited to mobile phones, tablet computers, notebooks, desktop computers, vehicle-mounted terminals, smart home appliances, etc. The traffic proxy method of the embodiment of the present disclosure can be executed by the traffic proxy device of the embodiment of the present disclosure. The traffic proxy device of the embodiment of the present disclosure can be configured in any proxy device to execute the traffic proxy method of the embodiment of the present disclosure.
本领域可以理解的是,光猫或光纤入户路由器需要为所有接入路由器的终端设备对应的TCP连接通道进行NAT(Network Address Translation,网络地址转换)转换,而运营商的设备硬件资源有限,智能家居场景下用户连网的终端设备越多,光猫或入户路由器的NAT转换压力就越大,从而降低了网络质量,影响用户的上网体验。It can be understood in this field that optical modems or fiber-to-the-home routers need to perform NAT (Network Address Translation) conversion for the TCP connection channels corresponding to all terminal devices connected to the router, and the operator's equipment hardware resources are limited. In smart home scenarios, the more terminal devices users connect to the Internet, the greater the NAT conversion pressure on optical modems or home routers, thereby reducing network quality and affecting users' Internet experience.
基于此,本公开实施例提出了一种流量代理方法,通过TCP连接通道和UDP(User Datagram Protocol,用户数据报协议)本地传输通道对终端设备与云服务器通信时所需数据帧进行传输,能够使流量被代理的终端设备不再单独创建TCP连接通道,从而消除运营商设备的NAT转换压力,突破终端设备连网数量限制,提高网络服务质量。Based on this, the embodiment of the present disclosure proposes a traffic proxy method that transmits the data frames required when the terminal device communicates with the cloud server through the TCP connection channel and UDP (User Datagram Protocol, User Datagram Protocol) local transmission channel, which can The terminal device whose traffic is proxied no longer creates a separate TCP connection channel, thereby eliminating the NAT conversion pressure on the operator's equipment, breaking through the limit on the number of terminal devices connected to the network, and improving the quality of network service.
本公开的实施例中,代理设备即对处于物联网中的终端设备进行流量代理的中枢设备,云服务器即对连接的设备提供基础服务和配置的云端主机,代理设备与云服务器可建立传输控制协议TCP连接通道,以进行后续通信消息的处理和转发,如图2所示。In the embodiment of the present disclosure, the proxy device is a central device that performs traffic proxy for terminal devices in the Internet of Things, and the cloud server is a cloud host that provides basic services and configurations for connected devices. The proxy device and the cloud server can establish transmission control. Protocol TCP connection channel for processing and forwarding of subsequent communication messages, as shown in Figure 2.
S102,与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道。S102. Establish a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things.
本公开的实施例中,终端设备即物联网中的设备,代理设备与处于同一物联网中的终端设备之间建立用户数据报协议UDP本地传输通道,以进行后续信息接收和转发。其中,终端设备的数量可以为一个或者多个。需要说明的是,代理设备的初始状态与云服务器连接,终端设备在与代理设备建立UDP本地传输通道后,会断开与云服务器的连接,之后通过UDP本地传输通道进行信息交互。In the embodiment of the present disclosure, the terminal device is a device in the Internet of Things, and a User Datagram Protocol UDP local transmission channel is established between the proxy device and the terminal device in the same Internet of Things for subsequent information reception and forwarding. The number of terminal devices may be one or more. It should be noted that the initial state of the proxy device is connected to the cloud server. After the terminal device establishes a UDP local transmission channel with the proxy device, it will disconnect from the cloud server, and then exchange information through the UDP local transmission channel.
还需要说明的是,本公开实施例中,对终端设备的具体类别不做过多限定,可根据实际情况进行设置,例如,终端设备具体可包括但不限于空气净化器、窗帘控制器、智能门锁等。It should also be noted that in the embodiments of the present disclosure, the specific categories of terminal devices are not too limited and can be set according to the actual situation. For example, the terminal devices may include but are not limited to air purifiers, curtain controllers, smart phones, etc. Door locks etc.
例如,继续如上图2所示,终端设备为物联网WiFi设备,具体可包括但不限于空气净化器、智能摄像机、窗帘电机等,在传输层上,每个终端设备与代理设备之间各自建立用户数据报协议UDP本地传输通道,则终端设备不再与云服务器直接建立TCP连接通道,所有终端设备与云服务器交互的流量由代理设备进行代理转发,在应用层上,代理设备与被代理流量的终端设备之间交换信息使用UDP报文。For example, as shown in Figure 2 above, the terminal device is an Internet of Things WiFi device, which may include but is not limited to air purifiers, smart cameras, curtain motors, etc. On the transmission layer, each terminal device and the agent device establish separate User Datagram Protocol UDP local transmission channel, the terminal device no longer directly establishes a TCP connection channel with the cloud server. All traffic between the terminal device and the cloud server is forwarded by the proxy device. On the application layer, the proxy device and the proxy traffic UDP packets are used to exchange information between terminal devices.
S103,通过TCP连接通道和UDP本地传输通道,传输终端设备与云服务器通信时所需数据帧。S103: Transmit the data frames required when the terminal device communicates with the cloud server through the TCP connection channel and the UDP local transmission channel.
本公开的实施例中,代理设备通过步骤S101建立的TCP连接通道和步骤S102建立的UDP本地传输通道对终端设备和云服务器之间通信时所需的消数据帧进行代理。其中,数据帧为终端设备与云服务器通信数据的数据单元。In the embodiment of the present disclosure, the proxy device proxies the data frames required for communication between the terminal device and the cloud server through the TCP connection channel established in step S101 and the UDP local transmission channel established in step S102. Among them, the data frame is the data unit of communication data between the terminal device and the cloud server.
作为一种可能的实现方式,终端设备通过UDP本地传输通道发送通信时所需数据帧至代理设备,代理设备接收到终端设备发送的数据帧后,通过与云服务器之间建立的TCP连接通道将该数据帧发送至云服务器,云服务器接受到代理设备发送的数据帧后返回相应的数据帧至代理设备,代理设备在接收到该云服务器返回的数据帧后将其发送至终端设备,从而实现对终端设备和云服务器之间通信时所需数据帧的传输。As a possible implementation method, the terminal device sends the data frames required for communication to the proxy device through the UDP local transmission channel. After the proxy device receives the data frames sent by the terminal device, it sends the data frames through the TCP connection channel established with the cloud server. The data frame is sent to the cloud server. The cloud server receives the data frame sent by the proxy device and returns the corresponding data frame to the proxy device. After receiving the data frame returned by the cloud server, the proxy device sends it to the terminal device, thereby realizing Transmission of data frames required for communication between terminal devices and cloud servers.
本公开的实施例提供的流量代理方法,代理设备与云服务器建立传输控制协议TCP连接通道,与处于物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道,通过TCP连接通道和UDP本地传输通道,传输终端设备与云服务器通信时所需数据帧。由此,可通过TCP连接通道和UDP 本地传输通道对终端设备与云服务器通信时所需数据帧进行传输,实现了对终端设备流量的代理,减少了终端设备和云端服务器之间进行TCP连接的压力,提高了网络服务质量。In the traffic proxy method provided by the embodiments of the present disclosure, the proxy device establishes a Transmission Control Protocol TCP connection channel with the cloud server, and establishes a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the Internet of Things, through the TCP connection channel and UDP local transmission channel to transmit the data frames required when the terminal device communicates with the cloud server. As a result, the data frames required for communication between the terminal device and the cloud server can be transmitted through the TCP connection channel and the UDP local transmission channel, realizing the proxy for the terminal device traffic and reducing the TCP connection between the terminal device and the cloud server. pressure, improving network service quality.
作为一种可能的实现方式,代理设备与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道,UDP本地传输通道的需要在已知设备双方的地址信息的基础上进行建立。本公开中,代理设备可以获取自身的第一地址信息,并且可以还需要获取到终端设备的第二地址信息,在已知设备双方的地址信息的基础上,可以执行UDP建链流程,以与终端设备之间建立UDP本地传输通道。需要说明的是,本公开的地址信息可选地为IP地址信息。As a possible implementation method, the proxy device establishes a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things. The UDP local transmission channel needs to be based on the address information of both devices. to create. In this disclosure, the proxy device can obtain its own first address information, and may also need to obtain the second address information of the terminal device. Based on the known address information of both devices, the UDP link establishment process can be executed to communicate with the terminal device. Establish a UDP local transmission channel between terminal devices. It should be noted that the address information of the present disclosure is optionally IP address information.
为了保证数据传输的安全性,可选地代理设备与终端设备需要在具有相同的用户标识或者绑定账号的基础上,建立UDP本地传输通道。本公开中,代理设备还可以获取终端设备所绑定的第二用户标识,以及自身所绑定的第一用户标识,在两个用户标识一致的情况下,建立与终端设备之间的UDP本地传输通道。可选地,终端设备可以获取到代理设备的第一用户标识,终端设备确定出自身的第二用户标识和第一用户标识一致时,向代理设备发送第二地址信息和第二用户标识。In order to ensure the security of data transmission, optionally the proxy device and the terminal device need to establish a UDP local transmission channel based on having the same user ID or bound account. In the present disclosure, the proxy device can also obtain the second user identification bound to the terminal device and the first user identification bound to itself. When the two user identifications are consistent, establish a UDP local connection with the terminal device. transmission channel. Optionally, the terminal device may obtain the first user identification of the proxy device. When the terminal device determines that its second user identification is consistent with the first user identification, it sends the second address information and the second user identification to the proxy device.
本公开中,为了保证代理设备与终端设备之间的数据传输是安全的,代理设备还需要获取到第二用户标识对应的密钥,以便于能够实现与终端设备之间进行安全传输,即在UDP本地传输通道上传输的数据是基于第二用户标识对应的密钥加密后的数据。In this disclosure, in order to ensure that the data transmission between the proxy device and the terminal device is secure, the proxy device also needs to obtain the key corresponding to the second user identification so that secure transmission with the terminal device can be achieved, that is, in The data transmitted on the UDP local transmission channel is encrypted data based on the key corresponding to the second user ID.
图3是根据一示例性实施例示出的另一种流量代理方法的流程图,如图3所示,本公开实施例的流量代理方法由代理设备执行,该方法可以包括以下步骤:Figure 3 is a flow chart of another traffic proxy method according to an exemplary embodiment. As shown in Figure 3, the traffic proxy method according to the embodiment of the present disclosure is executed by a proxy device. The method may include the following steps:
S301,与云服务器建立传输控制协议TCP连接通道。S301: Establish a transmission control protocol TCP connection channel with the cloud server.
本实施例中的步骤S301的介绍可参见上述实施例中相关内容的记载,此处不再赘述。For an introduction to step S301 in this embodiment, please refer to the relevant content recorded in the above embodiment, and will not be described again here.
S302,周期性广播探测请求帧,其中,探测请求帧中包括代理设备对应的第一用户标识和第一地址信息。S302. Periodically broadcast a detection request frame, where the detection request frame includes the first user identification and first address information corresponding to the proxy device.
本公开的实施例中,代理设备周期性广播探测请求帧至终端设备,其中,探测请求帧用于代理设备发现局域网内同一用户名下的终端设备,为建立UDP本地传输通道做好准备,第一用户标识为代理设备所属的用户账号的UID(User Identity,用户识别码),第一地址信息为代理设备发送的探测请求帧的源IP(Internet Protocol,IP地址)信息。可选地,探测请求帧的UID的字节长度为8。In the embodiment of the present disclosure, the proxy device periodically broadcasts the detection request frame to the terminal device, where the detection request frame is used by the proxy device to discover the terminal device under the same user name in the local area network and prepare for the establishment of the UDP local transmission channel. A user identification is the UID (User Identity, User Identification Code) of the user account to which the proxy device belongs, and the first address information is the source IP (Internet Protocol, IP address) information of the detection request frame sent by the proxy device. Optionally, the UID of the probe request frame has a byte length of 8.
需要说明的是,广播指一对多的信息交换,对应的,一对一的信息交换即为单播,本公开对代理设备周期性广播的具体形式不做过多限定,可根据实际情况进行设置。例如,代理设备可以将1分钟或5秒钟作为一个周期,到达设定周期后就向终端设备发送一次探测请求帧,以实现定时广播的需求。It should be noted that broadcast refers to one-to-many information exchange. Correspondingly, one-to-one information exchange is unicast. This disclosure does not place too many restrictions on the specific form of periodic broadcast by the agent device, and it can be carried out according to the actual situation. set up. For example, the proxy device can set 1 minute or 5 seconds as a cycle, and send a detection request frame to the terminal device once the set cycle is reached to meet the requirement of scheduled broadcast.
例如,图4为流量代理模式下终端设备和代理设备的交互示意图,如图4所示,探测请求帧为probe_request,探测响应帧为probe_response,代理设备和终端设备分别在初始化、连接云服务器即和服务器建立TCP连接通道后,代理设备向终端设备以广播的形式发送探测请求帧probe_request。其中,初始化即初始化设备的参数,恢复设备默认状态。For example, Figure 4 is a schematic diagram of the interaction between the terminal device and the proxy device in the traffic proxy mode. As shown in Figure 4, the probe request frame is probe_request, and the probe response frame is probe_response. The proxy device and the terminal device are initializing, connecting to the cloud server, and After the server establishes the TCP connection channel, the proxy device sends the probe request frame probe_request to the terminal device in the form of a broadcast. Among them, initialization means initializing the parameters of the device and restoring the default state of the device.
进一步地,终端设备在接收到代理设备的探测请求帧后,对探测请求帧中的UID字段进行解析,如果代理设备的UID与终端设备自身的UID相同即两者同属一个用户账户,则终端设备记录收到的探测请求帧的UDP报文的源IP信息,并返回探测响应帧至代理设备。Further, after receiving the detection request frame from the proxy device, the terminal device parses the UID field in the detection request frame. If the UID of the proxy device is the same as the UID of the terminal device itself, that is, both belong to the same user account, then the terminal device Record the source IP information of the UDP message of the received detection request frame, and return the detection response frame to the proxy device.
S303,接收终端设备返回的探测响应帧,其中,探测响应帧包括终端设备对应的第二用户标识和第二地址信息。S303. Receive a detection response frame returned by the terminal device, where the detection response frame includes the second user identification and second address information corresponding to the terminal device.
其中,探测响应帧由终端设备确定出第一用户标识和第二用户标识相同。In the detection response frame, the terminal device determines that the first user identity and the second user identity are the same.
本公开的实施例中,第二用户标识为终端设备所属的用户账户的UID,第二地址信息为终端设备发来的探测响应帧的源IP信息,当步骤S302的探测请求帧的第一用户标识和本步骤的探测响应帧的第二用户标识相同时即代理设备和终端设备处于同一用户账户下时,终端设备确定返回探测响应帧,代理设备对终端设备返回的探测响应帧进行接收,如图4所示,终端设备在接收到代理设备以广播的形式发送的探测请求帧probe_request后,以单播的形式向代理设备返回探测响应帧probe_response。In the embodiment of the present disclosure, the second user identification is the UID of the user account to which the terminal device belongs, and the second address information is the source IP information of the detection response frame sent by the terminal device. When the first user of the detection request frame in step S302 When the identification is the same as the second user identification of the detection response frame in this step, that is, when the proxy device and the terminal device are under the same user account, the terminal device determines to return the detection response frame, and the proxy device receives the detection response frame returned by the terminal device, such as As shown in Figure 4, after receiving the probe request frame probe_request sent by the proxy device in the form of broadcast, the terminal device returns the probe response frame probe_response to the proxy device in the form of unicast.
需要说明的是,代理设备在接收到终端设备返回的探测响应帧后,对终端设备返回的探测响应帧中的UID字段进行解析,当确认代理设备的UID与终端设备自身的UID相同之后,代理设备记录接收到的探测响应帧的UDP报文的源IP和终端设备的唯一的DID(Device Identity,设备识别码)。可选地,探测请求帧的DID可为全0xFF,DID的字节长度为8。It should be noted that after receiving the detection response frame returned by the terminal device, the proxy device parses the UID field in the detection response frame returned by the terminal device. After confirming that the UID of the proxy device is the same as the UID of the terminal device itself, the proxy device The device records the source IP of the UDP message of the received detection response frame and the unique DID (Device Identity, device identification code) of the terminal device. Optionally, the DID of the probe request frame can be all 0xFF, and the byte length of the DID is 8.
需要说明的是,代理设备可对终端设备返回的数据帧或探测响应帧的有效性进行判断和相应的处理。It should be noted that the proxy device can determine the validity of the data frame or detection response frame returned by the terminal device and process it accordingly.
在一些实施方式中,代理设备响应于接收到数据帧或探测响应帧,从数据帧或探测响应帧中提取时间戳,并基于时间戳和当前时间,获取时间差,响应于时间差小于或者等于窗口时间,确定数据帧或探测响应帧为有效帧,对有效帧进行处理或传输;响应于时间差大于窗口时间,确定数据帧或探测响应帧为无效帧,对无效帧进行丢弃。不难看出,只有当时间差小于或者等于窗口时间时,代理设备收到的终端设备发送的数据帧或探测响应帧才是有效的。In some embodiments, the proxy device responds to receiving the data frame or the probe response frame, extracts a timestamp from the data frame or the probe response frame, and obtains a time difference based on the timestamp and the current time, in response to the time difference being less than or equal to the window time. , determine the data frame or detection response frame as a valid frame, process or transmit the valid frame; in response to the time difference being greater than the window time, determine the data frame or detection response frame as an invalid frame, and discard the invalid frame. It is not difficult to see that only when the time difference is less than or equal to the window time, the data frame or detection response frame sent by the terminal device received by the proxy device is valid.
本领域人员可以理解的是,时间戳用于进行消息去重及防重放攻击。可选地,时间戳(timestamp,简称ts)可为国际标准UNIX时间戳,该时间戳的字节长度为4。Those in the art can understand that timestamps are used to deduplicate messages and prevent replay attacks. Optionally, the timestamp (timestamp, ts for short) can be an international standard UNIX timestamp, and the byte length of the timestamp is 4.
S304,基于第一地址信息和第二地址信息与终端设备进行UDP建链流程,以建立UDP本地传输通道。S304: Perform a UDP link establishment process with the terminal device based on the first address information and the second address information to establish a UDP local transmission channel.
本公开的实施例中,代理设备可基于步骤S302的第一地址信息和步骤S303的第二地址信息,与终端设备进行建链流程,从而建立UDP本地传输通道。In the embodiment of the present disclosure, the proxy device can perform a link establishment process with the terminal device based on the first address information in step S302 and the second address information in step S303, thereby establishing a UDP local transmission channel.
需要说明的是,经过一轮探测请求帧和探测响应帧的信息交换,代理设备和终端设备均获得了对方的地址信息即源IP信息,基于代理设备和终端设备的地址信息,在代理设备和终端设备之间建立UDP本地传输通道。It should be noted that after a round of information exchange between the detection request frame and the detection response frame, the proxy device and the terminal device have obtained each other's address information, that is, the source IP information. Based on the address information of the proxy device and the terminal device, between the proxy device and the terminal device, Establish a UDP local transmission channel between terminal devices.
例如,对本地传输通道的建立过程进行描述,继续如上图4所示,代理设备在成功从云服务器获取终端设备的密钥后,以单播的形式进一步向终端设备发送连接请求帧link_request以请求建立本地传输通道,终端设备在接收到代理设备发送的link_request后,同样以单播的形式向代理设备返回连接响应帧link_response表示同意建立本地传输通道,以实现本地传输通道的建立。For example, to describe the establishment process of the local transmission channel, continue as shown in Figure 4 above. After the proxy device successfully obtains the key of the terminal device from the cloud server, it further sends a connection request frame link_request to the terminal device in the form of unicast to request Establish a local transmission channel. After receiving the link_request sent by the proxy device, the terminal device also returns the connection response frame link_response to the proxy device in the form of unicast to express its agreement to establish the local transmission channel to achieve the establishment of the local transmission channel.
图5是根据一示例性实施例示出的另一种流量代理方法的流程图,如图5所示,本公开实施例的流量代理方法由代理设备执行,该方法可以包括以下步骤:Figure 5 is a flow chart of another traffic proxy method according to an exemplary embodiment. As shown in Figure 5, the traffic proxy method according to the embodiment of the present disclosure is executed by a proxy device. The method may include the following steps:
S501,与云服务器建立传输控制协议TCP连接通道。S501: Establish a transmission control protocol TCP connection channel with the cloud server.
S502,周期性广播探测请求帧,其中,探测请求帧中包括代理设备对应的第一用户标识和第一地 址信息。S502. Periodically broadcast a detection request frame, where the detection request frame includes the first user identification and first address information corresponding to the proxy device.
本实施例中的步骤S501~步骤502的介绍,可参见上述实施例中相关内容的记载,此处不再赘述。For the introduction of steps S501 to 502 in this embodiment, please refer to the relevant content records in the above embodiments, and will not be described again here.
S503,接收终端设备返回的探测响应帧,其中,探测响应帧包括终端设备对应的第二用户标识和第二地址信息。S503. Receive a detection response frame returned by the terminal device, where the detection response frame includes the second user identification and second address information corresponding to the terminal device.
其中,探测响应帧由终端设备确定出第一用户标识和第二用户标识相同。In the detection response frame, the terminal device determines that the first user identity and the second user identity are the same.
本实施例中的步骤S501~步骤503的介绍,可参见上述实施例中相关内容的记载,此处不再赘述。For the introduction of steps S501 to 503 in this embodiment, please refer to the relevant content records in the above embodiments, and will not be described again here.
S504,基于设备标识和第二用户标识向云服务器发送密钥获取请求。S504: Send a key acquisition request to the cloud server based on the device identification and the second user identification.
本公开的实施例中,探测响应帧还包括终端设备的第一设备标识,设备标识为终端设备唯一的DID(Device Identity,设备识别码),密钥为终端设备绑定用户账户时由云服务器生成并下发到终端设备的Token(令牌),代理设备基于设备标识和第二用户标识可向云服务器发送密钥获取请求,以获取用户账户下的终端设备对应的密钥。需要说明的是,一个终端设备有且只有一个对应的密钥,不同用户账户和/或不同终端设备均有着不同的密钥。In the embodiment of the present disclosure, the detection response frame also includes the first device identification of the terminal device. The device identification is the unique DID (Device Identity, device identification code) of the terminal device. The key is provided by the cloud server when the terminal device binds a user account. To generate and deliver a Token to the terminal device, the proxy device can send a key acquisition request to the cloud server based on the device identification and the second user identification to obtain the key corresponding to the terminal device under the user account. It should be noted that one terminal device has and has only one corresponding key, and different user accounts and/or different terminal devices have different keys.
需要说明的是,代理设备仅能从云服务器获取和终端设备相同用户账号名下的终端设备的密钥。It should be noted that the proxy device can only obtain the key of the terminal device under the same user account name as the terminal device from the cloud server.
S505,响应于接收到云服务器返回的第二用户标识对应的密钥,以单播方式向终端设备发送通道建立请求,其中,通道建立请求用于请求与终端设备建立UDP本地传输通道。S505. In response to receiving the key corresponding to the second user ID returned by the cloud server, send a channel establishment request to the terminal device in a unicast manner, where the channel establishment request is used to request the establishment of a UDP local transmission channel with the terminal device.
本公开的实施例中,代理设备在接收到云服务器返回的第二用户标识对应的密钥后,以单播方式向终端设备发送用于请求与终端设备建立UDP本地传输通道的通道建立请求。In the embodiment of the present disclosure, after receiving the key corresponding to the second user ID returned by the cloud server, the proxy device sends a channel establishment request to the terminal device in a unicast manner for requesting to establish a UDP local transmission channel with the terminal device.
如果代理设备未能从云服务器成功获取第二用户标识对应的终端设备的密钥,例如,发生代理设备未连接到云服务器、云服务器故障等情况,代理设备则不会发送通道建立请求(link_request)至终端设备,这样也就无法建立UDP本地传输通道,那么终端设备则按照正常启动流程连接云服务器,保持原有连接逻辑不变。If the proxy device fails to successfully obtain the key of the terminal device corresponding to the second user ID from the cloud server, for example, the proxy device is not connected to the cloud server, the cloud server fails, etc., the proxy device will not send a channel establishment request (link_request ) to the terminal device, so that the UDP local transmission channel cannot be established. Then the terminal device will connect to the cloud server according to the normal startup process, keeping the original connection logic unchanged.
S506,基于第一地址信息和第二地址信息与终端设备进行UDP建链流程,以建立UDP本地传输通道。S506: Perform a UDP link establishment process with the terminal device based on the first address information and the second address information to establish a UDP local transmission channel.
本实施例中的步骤S501~步骤506的介绍,可参见上述实施例中相关内容的记载,此处不再赘述。For an introduction to steps S501 to 506 in this embodiment, please refer to the relevant records in the above embodiments and will not be described again here.
在建立UDP本地传输通道之后,若代理设备和终端设备中的一个IP地址信息发生更新,而两者之间的UDP本地传输通道未进行同步更新,则代理设备与终端设备之间的本地通信无法进行,往往会导致数据丢失。After the UDP local transmission channel is established, if one of the IP address information in the proxy device and the terminal device is updated, but the UDP local transmission channel between the two is not updated synchronously, the local communication between the proxy device and the terminal device cannot Doing so often results in data loss.
本公开实施例中,代理设备需要对第一地址信息和第二地址信息进行更新监控,以及时发现是否发生地址信息更新,尽快进行UDP本地通信道路的重建,能够使得数据的传输更加安全。响应于监测到第一地址和/或第二地址信息更新,则基于更新后地址信息对UDP本地传输通道进行重新建立,也就是重新执行UDP本地传输通道的建链流程。In this disclosed embodiment, the proxy device needs to update and monitor the first address information and the second address information, promptly discover whether the address information has been updated, and reconstruct the UDP local communication path as soon as possible, which can make data transmission more secure. In response to monitoring the update of the first address and/or the second address information, the UDP local transmission channel is re-established based on the updated address information, that is, the link establishment process of the UDP local transmission channel is re-executed.
作为一种可能的实现方式,在建立UDP本地传输通道之后,代理设备定期与终端设备进行探测请求帧和探测响应帧的交互,可选地,提取代理设备探测请求帧中的地址信息,将提取到的代理设备的地址信息与第一地址信息对比,若两者对比未一致确定代理设备发生地址更新。代理设备提取探测响应帧中的地址信息与第二地信息对比,若两者对比未一致确定终端设备发生地址更新。也就是说,当第一地 址信息对比未一致和/或第二地址信息比对未一致,可以确定出第一地址和/或第二地址信息发生更新。As a possible implementation method, after establishing a UDP local transmission channel, the proxy device regularly interacts with the terminal device with detection request frames and detection response frames. Optionally, the address information in the proxy device detection request frame is extracted. The obtained address information of the proxy device is compared with the first address information. If the two comparisons are not consistent, it is determined that an address update has occurred on the proxy device. The proxy device extracts the address information in the detection response frame and compares it with the second location information. If the two comparisons are not consistent, it is determined that the address update of the terminal device has occurred. That is to say, when the comparison of the first address information is not consistent and/or the comparison of the second address information is not consistent, it can be determined that the first address and/or the second address information are updated.
进一步地,响应于探测请求帧和/或探测响应帧各自携带的地址信息更新,则基于更新后地址信息对UDP本地传输通道进行重新建立。Further, in response to the update of the address information carried by the probe request frame and/or the probe response frame, the UDP local transmission channel is re-established based on the updated address information.
例如,如上图4所示,代理设备在流量代理模式下,始终定期以广播的形式发送探测请求帧probe_request,已与代理设备建立本地传输通道的终端设备在收到probe_request后也会以单播的形式返回探测响应帧probe_response,代理设备和终端设备通过probe_request和probe_response的交互来维护对方的IP地址,当其中一方IP地址改变时,另一方能够及时发现并重新建立本地传输通道。For example, as shown in Figure 4 above, the proxy device always sends the probe request frame probe_request regularly in the form of broadcast in the traffic proxy mode. The terminal device that has established a local transmission channel with the proxy device will also send the probe_request in the form of unicast after receiving the probe_request. The probe response frame probe_response is returned in the form. The proxy device and the terminal device maintain each other's IP address through the interaction of probe_request and probe_response. When the IP address of one party changes, the other party can discover and re-establish the local transmission channel in time.
图6是根据一示例性实施例示出的另一种流量代理方法的流程图,如图6所示,本公开实施例的流量代理方法由代理设备执行,该方法可以包括以下步骤:Figure 6 is a flow chart of another traffic proxy method according to an exemplary embodiment. As shown in Figure 6, the traffic proxy method according to the embodiment of the present disclosure is executed by a proxy device. The method may include the following steps:
S601,与云服务器建立传输控制协议TCP连接通道。S601: Establish a transmission control protocol TCP connection channel with the cloud server.
S602,与处于物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道。S602: Establish a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the Internet of Things.
本实施例中的步骤S601~步骤602的介绍,可参见上述实施例中相关内容的记载,此处不再赘述。For an introduction to steps S601 to 602 in this embodiment, please refer to the relevant records in the above embodiments and will not be described again here.
S603,响应于接收到终端设备通过UDP本地传输通道发送的上行数据帧,通过TCP连接通道,将上行数据帧发送给云服务器。S603: In response to receiving the uplink data frame sent by the terminal device through the UDP local transmission channel, send the uplink data frame to the cloud server through the TCP connection channel.
本公开的实施例中,代理设备接收到终端设备通过UDP本地传输通道发送的上行数据帧后,通过代理设备和云服务器的TCP连接通道,将上行数据帧发送给云服务器。其中,一般情况下,终端设备的自身状态的改变会通知控制中心(代理设备或者云服务器),这种设备通知上报给控制中心的消息称为上行消息,此处的上行消息为终端设备加密后的上行消息。需要说明的是,终端设备发送上行消息时,使用第二用户标识对应的密钥加密上行消息,在将上行消息打包后通过UDP本地传输通道发送给代理设备。还需要说明的是,代理设备与云服务器的应用层协议采用MQTT over TLS(传输层安全的消息队列遥测传输标准协议)方案,该方案中对上行数据帧的定义如下:device/${DID}/up/${method}:其中,method由云服务器与代理设备约定而成,当DID为代理设备时,该消息为代理设备自身的上行消息,当DID为终端设备时,该消息为代理设备代理终端设备的上行消息。In the embodiment of the present disclosure, after the proxy device receives the uplink data frame sent by the terminal device through the UDP local transmission channel, it sends the uplink data frame to the cloud server through the TCP connection channel between the proxy device and the cloud server. Among them, under normal circumstances, the change of the terminal device's own status will notify the control center (agent device or cloud server). The message reported to the control center by this device notification is called an uplink message. The uplink message here is encrypted by the terminal device. Upward news. It should be noted that when the terminal device sends an uplink message, it uses the key corresponding to the second user ID to encrypt the uplink message, and then packages the uplink message and sends it to the proxy device through the UDP local transmission channel. It should also be noted that the application layer protocol between the proxy device and the cloud server adopts the MQTT over TLS (Transport Layer Secure Message Queuing Telemetry Transmission Standard Protocol) scheme. The definition of the upstream data frame in this scheme is as follows: device/${DID} /up/${method}: Among them, the method is agreed between the cloud server and the agent device. When the DID is the agent device, the message is the uplink message of the agent device itself. When the DID is the terminal device, the message is the agent device. Agents for upstream messages from terminal devices.
需要说明的是,本公开对代理设备发送上行数据帧至云服务器的具体方式不做过多限定,可根据实际情况进行设置。It should be noted that this disclosure does not place too many restrictions on the specific way in which the proxy device sends the uplink data frame to the cloud server, and it can be set according to the actual situation.
在一些实施方式中,代理设备可基于第一设备标识确定从云服务器获取到的第二用户标识对应的密钥,并基于第二用户标识对应的密钥对加密上行数据帧进行解密,并基于代理设备自身的密钥对解密后的上行消息进行加密后发送给云服务器。其中,代理设备在接收到上行数据帧后,对上行数据帧中的DID字段进行解析,使用相应的终端设备的密钥即第二用户标识对应的密钥对上行数据帧进行解密。In some embodiments, the proxy device may determine the key corresponding to the second user identification obtained from the cloud server based on the first device identification, decrypt the encrypted uplink data frame based on the key corresponding to the second user identification, and decrypt the encrypted uplink data frame based on the key corresponding to the second user identification. The agent device's own key encrypts the decrypted uplink message and sends it to the cloud server. After receiving the uplink data frame, the proxy device parses the DID field in the uplink data frame, and uses the key of the corresponding terminal device, that is, the key corresponding to the second user identification, to decrypt the uplink data frame.
S604,响应于接收到云服务器通过TCP连接通道发送的下行数据帧,通过UDP本地传输通道,将下行数据帧发送给终端设备。S604: In response to receiving the downlink data frame sent by the cloud server through the TCP connection channel, send the downlink data frame to the terminal device through the UDP local transmission channel.
本公开的实施例中,代理设备接收到云服务器通过TCP连接通道发送的下行数据帧后,通过UDP本地传输通道,将下行数据帧发送给终端设备。其中,一般情况下,用户想要控制终端设备时,控制中心(代理设备或者云服务器)会给终端设备发送控制指令,这种包含控制指令的数据帧称为下行数据帧,此处的下行数据帧为云服务器加密后的下行数据帧。In the embodiment of the present disclosure, after the proxy device receives the downlink data frame sent by the cloud server through the TCP connection channel, it sends the downlink data frame to the terminal device through the UDP local transmission channel. Among them, under normal circumstances, when the user wants to control the terminal device, the control center (agent device or cloud server) will send control instructions to the terminal device. This data frame containing the control instructions is called a downlink data frame. The downlink data here The frame is the downlink data frame encrypted by the cloud server.
需要说明的是,MQTT over TLS方案中对下行数据帧的定义如下:device/${DID}/down/${method}:其中,method由云服务器与代理设备约定而成,当DID为代理设备时,该消息为云服务器发给代理设备的下行数据帧,当DID为终端设备时,该消息为代理设备需要代为处理或转发的其他终端设备的下行数据帧。It should be noted that the definition of downlink data frames in the MQTT over TLS solution is as follows: device/${DID}/down/${method}: where method is agreed between the cloud server and the proxy device. When DID is the proxy device When the DID is a terminal device, the message is a downlink data frame sent by the cloud server to the proxy device. When the DID is a terminal device, the message is a downlink data frame of other terminal devices that the proxy device needs to process or forward on its behalf.
需要说明的是,本公开对代理设备发送下行数据帧的方式不做过多限定,可根据实际情况进行设置。It should be noted that this disclosure does not place too many restrictions on the way in which the proxy device sends downlink data frames, and it can be set according to actual conditions.
在一些实施方式中,代理设备可基于代理设备自身的密钥对加密下行数据帧进行解密,基于第一设备标识确定从云服务器获取到的第二用户标识对应的密钥,并基于第二用户标识对应的密钥对解密后的下行数据帧进行加密,并通过UDP本地传输通道发送给终端设备。In some embodiments, the proxy device can decrypt the encrypted downlink data frame based on the proxy device's own key, determine the key corresponding to the second user ID obtained from the cloud server based on the first device ID, and determine the key corresponding to the second user ID obtained from the cloud server based on the second user ID. The key corresponding to the identifier encrypts the decrypted downlink data frame and sends it to the terminal device through the UDP local transmission channel.
本公开的实施例提供的流量代理方法,代理设备与云服务器建立传输控制协议TCP连接通道,与处于物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道,响应于接收到终端设备通过UDP本地传输通道发送的上行数据帧消息,通过TCP连接通道,将上行数据帧发送给云服务器,响应于接收到云服务器通过TCP连接通道发送的下行数据帧,通过UDP本地传输通道,将下行数据帧发送给终端设备。由此,可通过TCP连接通道和UDP本地传输通道对终端设备与云服务器通信时所需数据帧进行传输,可以减少云服务器的端口的使用数量,缓解了云端服务器的TCP连接压力,增强了本地自动化控制终端设备的能力。同时,通过密钥对数据帧进行加密和解密,提高了传输的安全性,消除了隐私泄露风险。In the traffic proxy method provided by embodiments of the present disclosure, the proxy device establishes a Transmission Control Protocol TCP connection channel with the cloud server, and establishes a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the Internet of Things. In response to receiving The terminal device sends the uplink data frame message through the UDP local transmission channel, and sends the uplink data frame to the cloud server through the TCP connection channel. In response to receiving the downlink data frame sent by the cloud server through the TCP connection channel, through the UDP local transmission channel, Send the downlink data frame to the terminal device. As a result, the data frames required when the terminal device communicates with the cloud server can be transmitted through the TCP connection channel and the UDP local transmission channel, which can reduce the number of ports used by the cloud server, relieve the TCP connection pressure of the cloud server, and enhance the local The ability to automatically control terminal equipment. At the same time, the data frame is encrypted and decrypted through the key, which improves the security of the transmission and eliminates the risk of privacy leakage.
进一步地,关闭UDP本地传输通道的方式可以有以下两种:Furthermore, there are two ways to close the UDP local transmission channel:
一、响应于第一预设时长内未收到终端设备返回的探测响应帧,则关闭UDP本地传输通道。例如,如图7所示,当代理设备超过一定时间未收到终端设备返回的探测响应帧probe_response,代理设备则认为终端设备已经丢失,从而对相应的UDP本地传输通道进行关闭。需要说明的是,第一预设时长为事先设置,本公开对此不做过多限定,可根据实际情况进行设置。例如,可以将第一预设时长设置为一小时,即当代理设备一小时内未收到终端设备返回的探测响应帧,则关闭UDP本地传输通道。1. In response to not receiving the detection response frame returned by the terminal device within the first preset time period, the UDP local transmission channel is closed. For example, as shown in Figure 7, when the proxy device does not receive the probe response frame probe_response returned by the terminal device for a certain period of time, the proxy device considers that the terminal device has been lost, and thus closes the corresponding UDP local transmission channel. It should be noted that the first preset duration is set in advance. This disclosure does not limit this too much and can be set according to actual conditions. For example, the first preset time period can be set to one hour, that is, when the proxy device does not receive a detection response frame returned by the terminal device within one hour, the UDP local transmission channel is closed.
二、响应于代理设备退出代理模式,广播通道断开指示,其中,通道断开指示用于告知终端设备关闭UDP本地传输通道。例如,如图7所示,UDP本地传输通道建立后,如果代理设备不希望再代理终端设备的数据帧即退出代理模式,比如,代理设备出现更换、重启或故障等情况时,代理设备会以广播的形式发送unlink_notify以告知终端设备关闭UDP本地传输通道,终端设备在接收到代理设备的unlink_notify后对其中的DID和UID字段进行解析,如果DID、UID与当前跟终端设备建立UDP本地传输通道的代理设备相匹配,终端设备则会关闭UDP本地传输通道,停止向该代理设备发送上行数据帧,同时,终端设备则退回刚启动时的初始状态,重新连接云服务器。2. In response to the proxy device exiting the proxy mode, broadcast a channel disconnection indication, where the channel disconnection indication is used to inform the terminal device to close the UDP local transmission channel. For example, as shown in Figure 7, after the UDP local transmission channel is established, if the proxy device no longer wants to proxy the data frames of the terminal device, it will exit the proxy mode. For example, when the proxy device is replaced, restarted, or malfunctions, the proxy device will Send unlink_notify in the form of broadcast to inform the terminal device to close the UDP local transmission channel. After receiving the unlink_notify from the proxy device, the terminal device parses the DID and UID fields in it. If the DID and UID are the same as the UDP local transmission channel currently established with the terminal device, If the proxy device matches, the terminal device will close the UDP local transmission channel and stop sending uplink data frames to the proxy device. At the same time, the terminal device will return to the initial state when it was just started and reconnect to the cloud server.
图8为本公开另一实施例提供的流量代理方法的流程示意图。本公开实施例的流量代理方法由终端设备执行,该方法可包括以下步骤:Figure 8 is a schematic flowchart of a traffic proxy method provided by another embodiment of the present disclosure. The traffic proxy method in the embodiment of the present disclosure is executed by the terminal device. The method may include the following steps:
S801,响应于与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道。S801: In response to establishing a User Datagram Protocol UDP local transmission channel with the proxy device in the Internet of Things, disconnect the first TCP connection channel with the cloud server.
具体的,关于步骤801的具体介绍,可参加上述实施例中相关内容的记载,此处不再赘述。Specifically, for a detailed introduction to step 801, please refer to the relevant content recorded in the above embodiments, and will not be described again here.
S802,通过UDP本地传输通道传输与云服务器通信所需的数据帧。S802, transmit the data frames required for communication with the cloud server through the UDP local transmission channel.
本公开实施例中,代理设备与云服务器之间存在TCP连接通道。In this disclosed embodiment, a TCP connection channel exists between the proxy device and the cloud server.
通过UDP本地传输通道传输与云服务器通信所需的上行数据帧,代理设备通过与云服务器之间的TCP连接通道,将数据帧发送给云服务器。The upstream data frames required for communication with the cloud server are transmitted through the UDP local transmission channel, and the proxy device sends the data frames to the cloud server through the TCP connection channel with the cloud server.
作为一种可能的实施方式,终端设备可以通过UDP本地传输通道传输和代理设备向云服务器传输上行数据帧,通过UDP本地传输通道接收代理设备传输的来自云服务器的下行数据帧。As a possible implementation, the terminal device can transmit the uplink data frame to the cloud server through the UDP local transmission channel and the proxy device, and receive the downlink data frame from the cloud server transmitted by the proxy device through the UDP local transmission channel.
本公开的实施例提供的流量代理方法,终端设备与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道,通过UDP本地传输通道传输与云服务器通信所需的数据帧。由此,可通过TCP连接通道和UDP本地传输通道对终端设备与云服务器通信时所需数据帧进行传输,可以减少云服务器的端口的使用数量,缓解了云端服务器的TCP连接压力,增强了本地自动化控制终端设备的能力。In the traffic proxy method provided by the embodiments of the present disclosure, the terminal device establishes a user datagram protocol UDP local transmission channel with the proxy device in the Internet of Things, disconnects the first TCP connection channel with the cloud server, and transmits the data with the cloud server through the UDP local transmission channel. Data frames required for cloud server communication. As a result, the data frames required when the terminal device communicates with the cloud server can be transmitted through the TCP connection channel and the UDP local transmission channel, which can reduce the number of ports used by the cloud server, relieve the TCP connection pressure of the cloud server, and enhance the local The ability to automatically control terminal equipment.
作为一种可能的实现方式,终端设备与处于同一物联网中的代理设备建立用户数据报协议UDP本地传输通道的过程:UDP本地传输通道的需要在已知设备双方的地址信息的基础上进行建立。本公开中,终端设备可以获取自身的第二地址信息,还需要获取到代理设备的第一地址信息,在已知设备双方的地址信息的基础上,可以执行UDP建链流程,以与代理设备之间建立UDP本地传输通道。As a possible implementation method, the process of establishing a User Datagram Protocol UDP local transmission channel between a terminal device and a proxy device in the same Internet of Things: The UDP local transmission channel needs to be established based on the address information of both devices. . In this disclosure, the terminal device can obtain its own second address information and also needs to obtain the first address information of the proxy device. Based on the known address information of both devices, the UDP link establishment process can be executed to communicate with the proxy device. Establish a UDP local transmission channel between them.
为了保证数据传输的安全性,可选地终端设备与代理设备需要在具有相同的用户标识或者绑定账号的基础上,建立UDP本地传输通道。本公开中,终端设备还可以获取自身所绑定的第二用户标识,以及代理设备所绑定的第一用户标识,在两个用户标识一致的情况下,建立与代理设备之间的UDP本地传输通道。可选地,终端设备可以获取到代理设备的第一用户标识,终端设备确定出自身的第二用户标识和第一用户标识一致时,向代理设备发送第二地址信息和第二用户标识。In order to ensure the security of data transmission, optionally the terminal device and the proxy device need to establish a UDP local transmission channel based on having the same user ID or bound account. In this disclosure, the terminal device can also obtain the second user ID bound to itself and the first user ID bound to the proxy device. When the two user IDs are consistent, establish a UDP local connection with the proxy device. transmission channel. Optionally, the terminal device may obtain the first user identification of the proxy device. When the terminal device determines that its second user identification is consistent with the first user identification, it sends the second address information and the second user identification to the proxy device.
本公开中,为了保证代理设备与终端设备之间的数据传输是安全的,代理设备还需要获取到第二用户标识对应的密钥,以便于能够实现与终端设备之间进行安全传输,即在UDP本地传输通道上传输的数据是基于第二用户标识对应的密钥加密后的数据。可选地,在UDP本地传输通道建立之前,终端设备可以基于与云服务器之间的第一TCP的长连接,将第二用户标识对应的密钥、第二用户标识和终端设备的第一设备标识同步发送给所述云服务器,以便于代理设备基于上述信息从云服务器获取到第二用户标识所绑定的密钥。In this disclosure, in order to ensure that the data transmission between the proxy device and the terminal device is secure, the proxy device also needs to obtain the key corresponding to the second user identification so that secure transmission with the terminal device can be achieved, that is, in The data transmitted on the UDP local transmission channel is encrypted data based on the key corresponding to the second user ID. Optionally, before the UDP local transmission channel is established, the terminal device can transfer the key corresponding to the second user ID, the second user ID and the first device of the terminal device based on the first TCP long connection with the cloud server. The identity is synchronously sent to the cloud server, so that the proxy device obtains the key bound to the second user identity from the cloud server based on the above information.
可选地,终端设备存储有所绑定的第二用户标识对应的密钥,终端设备可以对上行数据帧进行加密,并通过UDP本地传输通道,将加密上行数据帧发送给代理设备。相应地,代理设备可以从云服务器获取到第二用户标识对应的密钥,进而可以根据第二用户标识对应的密钥对加密上行数据帧进行解密。进一步地,代理设备基于自身的密钥对解密后的上行数据帧进行加密后发送给云服务器。Optionally, the terminal device stores the key corresponding to the bound second user identity. The terminal device can encrypt the uplink data frame and send the encrypted uplink data frame to the proxy device through the UDP local transmission channel. Correspondingly, the proxy device can obtain the key corresponding to the second user identification from the cloud server, and then can decrypt the encrypted uplink data frame according to the key corresponding to the second user identification. Further, the proxy device encrypts the decrypted uplink data frame based on its own key and sends it to the cloud server.
可选地,云服务器可以通过与代理设备之间的TCP连接通道,将下行数据帧发送给终端设备,实现中,云服务器可以通过与代理设备之间的TCP连接通道,将下行数据帧发送给代理设备,代理设备通过UDP本地传输通道将下行数据帧发送给终端设备。Optionally, the cloud server can send the downlink data frame to the terminal device through the TCP connection channel with the proxy device. In implementation, the cloud server can send the downlink data frame to the terminal device through the TCP connection channel with the proxy device. The proxy device sends downlink data frames to the terminal device through the UDP local transmission channel.
可选地,为了保证通信安全,云服务器通过代理设备对应的密钥对下行数据帧进行加密,得到加密下行数据帧,并将加密下行数据帧发送给代理设备,代理设备基于自身的密钥进行解密,得到解密后下 行数据帧。进一步地,基于终端设备所绑定的第二用户标识对应的密钥对解密后下行数据帧进行加密,通过UDP本地传输通道发送至终端设备,相应地,终端设备通过UDP本地传输通道接收加密下行数据帧,并基于终端设备所绑定的第二用户标识对应的密钥对加密下行数据帧进行解密,得到下行数据帧。Optionally, in order to ensure communication security, the cloud server encrypts the downlink data frame through the key corresponding to the proxy device, obtains the encrypted downlink data frame, and sends the encrypted downlink data frame to the proxy device. The proxy device performs encryption based on its own key. Decrypt and obtain the decrypted downlink data frame. Further, the decrypted downlink data frame is encrypted based on the key corresponding to the second user identification bound to the terminal device, and is sent to the terminal device through the UDP local transmission channel. Correspondingly, the terminal device receives the encrypted downlink data through the UDP local transmission channel. data frame, and decrypts the encrypted downlink data frame based on the key corresponding to the second user identification bound to the terminal device to obtain the downlink data frame.
本公开的实施例中,终端设备、代理设备和云服务器基于第二用户标识对应的密钥和/或代理设备自身的密钥对数据帧进行相应的加密和/或解密处理,提高了传输的安全性,消除了隐私泄露的风险。此外,只有代理设备可以在云服务器获取到第二用户标识对应的密钥,增强了代理设备的控制能力,进一步提高了传输的安全性。In the embodiments of the present disclosure, the terminal device, the proxy device and the cloud server perform corresponding encryption and/or decryption processing on the data frame based on the key corresponding to the second user identification and/or the key of the proxy device itself, thereby improving the efficiency of transmission. Security, eliminating the risk of privacy leaks. In addition, only the proxy device can obtain the key corresponding to the second user ID from the cloud server, which enhances the control capability of the proxy device and further improves the security of transmission.
图9为本公开另一实施例提供的流量代理方法的流程示意图。如图9所示,本公开实施例的流量代理方法具体可包括以下步骤:Figure 9 is a schematic flowchart of a traffic proxy method provided by another embodiment of the present disclosure. As shown in Figure 9, the traffic proxy method according to the embodiment of the present disclosure may specifically include the following steps:
S901,获取代理设备周期性广播的探测请求帧。S901: Obtain the detection request frame periodically broadcast by the proxy device.
其中,探测请求帧中包括代理设备对应的第一用户标识和第一地址信息。The detection request frame includes the first user identification and first address information corresponding to the proxy device.
S902,确定第一用户标识和终端设备对应的第二用户标识一致时,向代理设备返回探测响应帧,其中,探测响应帧包括第二用户标识和终端设备的第二地址信息。S902: When it is determined that the first user identification and the second user identification corresponding to the terminal device are consistent, return a detection response frame to the proxy device, where the detection response frame includes the second user identification and the second address information of the terminal device.
S903,基于第一地址信息和第二地址信息,与代理设备进行UDP建链流程,以建立UDP本地传输通道。S903: Based on the first address information and the second address information, perform a UDP link establishment process with the proxy device to establish a UDP local transmission channel.
关于终端设备与代理设备建立UDP本地传输通道的具体过程,可参见上述实施例中相关内容的记载,此处不再赘述。Regarding the specific process of establishing a UDP local transmission channel between the terminal device and the proxy device, please refer to the relevant records in the above embodiments, and will not be described again here.
可选地,与处于同一物联网中代理设备建立UDP本地传输通道之前,终端设备基于第一TCP连接通道,将第二用户标识对应的密钥、第二用户标识和终端设备的第一设备标识同步发送给云服务器。Optionally, before establishing a UDP local transmission channel with the proxy device in the same Internet of Things, the terminal device uses the first TCP connection channel to transfer the key corresponding to the second user ID, the second user ID and the first device ID of the terminal device. Synchronously sent to the cloud server.
在建立UDP本地传输通道之后,若代理设备和终端设备中的一个地址信息发生更新,而两者之间的UDP本地传输通道未进行同步更新,则代理设备与终端设备之间的本地通信无法进行,往往会导致数据丢失。After the UDP local transmission channel is established, if one of the address information in the proxy device and the terminal device is updated, but the UDP local transmission channel between the two is not updated synchronously, the local communication between the proxy device and the terminal device cannot be carried out. , often leading to data loss.
本公开实施例中,终端设备需要对第一地址信息和第二地址信息进行更新监控,以及时发现是否发生地址信息更新,尽快进行UDP本地通信道路的重建,能够使得数据的传输更加安全。响应于监测到第一地址和/或第二地址信息更新,则基于更新后地址信息对UDP本地传输通道进行重新建立,也就是重新执行UDP本地传输通道的建链流程。In this disclosed embodiment, the terminal device needs to update and monitor the first address information and the second address information, promptly discover whether the address information has been updated, and reconstruct the UDP local communication path as soon as possible, which can make data transmission more secure. In response to monitoring the update of the first address and/or the second address information, the UDP local transmission channel is re-established based on the updated address information, that is, the link establishment process of the UDP local transmission channel is re-executed.
作为一种可能的实现方式,建立UDP本地传输通道之后,终端设备定期与代理设备进行探测请求帧和探测响应帧的交互,可选地,提取代理设备探测请求帧中的地址信息,将提取到的代理设备的地址信息与第一地址信息对比,若两者对比未一致确定代理设备发生地址更新。代理设备提取探测响应帧中的地址信息与第二地信息对比,若两者对比未一致确定终端设备发生地址更新。也就是说,当第一地址信息对比未一致和/或第二地址信息比对未一致,可以确定出第一地址和/或第二地址信息发生更新。As a possible implementation method, after establishing a UDP local transmission channel, the terminal device regularly interacts with the proxy device with detection request frames and detection response frames. Optionally, the address information in the proxy device detection request frame is extracted. The address information of the proxy device is compared with the first address information. If the two comparisons are not consistent, it is determined that the address update of the proxy device has occurred. The proxy device extracts the address information in the detection response frame and compares it with the second location information. If the two comparisons are not consistent, it is determined that the address update of the terminal device has occurred. That is to say, when the comparison of the first address information is not consistent and/or the comparison of the second address information is not consistent, it can be determined that the first address and/or the second address information are updated.
响应于探测请求帧和/或探测响应帧内携带的地址信息更新,则基于更新后地址信息对UDP本地传输通道进行重新建立。In response to the update of the address information carried in the probe request frame and/or the probe response frame, the UDP local transmission channel is re-established based on the updated address information.
可选地,响应于终端设备满足UDP本地传输通道的关闭条件,则关闭UDP本地传输通道,并重新 终端设备建立与云服务器之间的第一TCP连接通道。Optionally, in response to the terminal device meeting the closing condition of the UDP local transmission channel, the UDP local transmission channel is closed, and the first TCP connection channel between the terminal device and the cloud server is re-established.
可选地,UDP本地传输通道的关闭条件包括以下中的至少一项:预设时长内终端设备未收到代理设备广播的探测请求帧;接收代理设备广播的通道断开指示。Optionally, the closing condition of the UDP local transmission channel includes at least one of the following: the terminal device does not receive the detection request frame broadcast by the proxy device within a preset time period; the terminal device receives a channel disconnection indication broadcast by the proxy device.
可选地,通道断开指示包括第二设备标识和第三用户标识,其中,关闭UDP本地传输通道,包括:响应于第二设备标识为终端设备的第一设备标识,且第三用户标识为终端设备所绑定的第二用户标识,则关闭UDP本地传输通道。Optionally, the channel disconnection indication includes a second device identification and a third user identification, wherein closing the UDP local transmission channel includes: responding that the second device identification is the first device identification of the terminal device, and the third user identification is The second user ID bound to the terminal device closes the UDP local transmission channel.
此处需要说明的是,上述对流量代理方法实施例的解释说明,也适用于本公开实施例的流量代理方法,具体过程此处不再赘述。It should be noted here that the above explanation of the embodiments of the traffic proxy method also applies to the traffic proxy method of the embodiments of the present disclosure, and the specific process will not be described again here.
本公开的实施例中,终端设备响应于与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道,通过UDP本地传输通道传输与云服务器通信所需的数据帧。由此,通过UDP本地传输通道传输与云服务器通信所需的数据帧,可以减少云服务器的端口的使用数量,缓云服务器进行TCP连接的压力,提高了网络服务质量。In an embodiment of the present disclosure, the terminal device responds to establishing a User Datagram Protocol UDP local transmission channel with the proxy device in the Internet of Things, disconnects the first TCP connection channel with the cloud server, and transmits data to the cloud server through the UDP local transmission channel. Data frames required for communication. Therefore, transmitting the data frames required for communication with the cloud server through the UDP local transmission channel can reduce the number of ports used by the cloud server, relieve the pressure on the cloud server for TCP connections, and improve the quality of network service.
图10是根据一示例性实施例示出的一种流量代理装置的框图。如图10所示,本公开实施例的流量代理装置1000,包括连接模块1001、第一传输模块1002和第二传输模块1003。Figure 10 is a block diagram of a traffic proxy device according to an exemplary embodiment. As shown in Figure 10, the traffic proxy device 1000 according to the embodiment of the present disclosure includes a connection module 1001, a first transmission module 1002 and a second transmission module 1003.
连接模块1001,被配置为执行与云服务器建立传输控制协议TCP连接通道。The connection module 1001 is configured to establish a transmission control protocol TCP connection channel with the cloud server.
第一传输模块1002,被配置为执行与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道。The first transmission module 1002 is configured to establish a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things.
第二传输模块1003,被配置为执行通过TCP连接通道和UDP本地传输通道,传输终端设备与云服务器通信时所需数据帧。The second transmission module 1003 is configured to transmit the data frames required when the terminal device communicates with the cloud server through the TCP connection channel and the UDP local transmission channel.
在本公开的一个实施例中,第一传输模块1002,还被配置为执行:获取终端设备的第二地址信息,并基于代理设备自身的第一地址信息和第二地址信息,与终端设备进行UDP建链流程,以建立UDP本地传输通道。In one embodiment of the present disclosure, the first transmission module 1002 is further configured to: obtain the second address information of the terminal device, and communicate with the terminal device based on the first address information and the second address information of the proxy device itself. UDP link building process to establish UDP local transmission channel.
在本公开的一个实施例中,第一传输模块1002,还被配置为执行:在与终端设备建立UDP本地传输通道之前,获取所述终端设备的第一设备标识和所述终端设备绑定的第二用户标识,并基于第一设备标识和第二用户标识,从云服务器获取第二用户标识对应的密钥。In one embodiment of the present disclosure, the first transmission module 1002 is further configured to perform: before establishing a UDP local transmission channel with a terminal device, obtain the first device identification of the terminal device and the data bound to the terminal device. the second user identification, and based on the first device identification and the second user identification, obtain the key corresponding to the second user identification from the cloud server.
在本公开的一个实施例中,第一传输模块1002,还被配置为执行:周期性广播探测请求帧,其中,探测请求帧中包括代理设备对应的第一用户标识和第一地址信息;接收终端设备返回的探测响应帧,其中,探测响应帧包括终端设备对应的第二用户标识和第二地址信息;基于第一地址信息和第二地址信息与终端设备进行UDP建链流程,以建立UDP本地传输通道。In one embodiment of the present disclosure, the first transmission module 1002 is further configured to: periodically broadcast a detection request frame, where the detection request frame includes the first user identification and first address information corresponding to the proxy device; receive The detection response frame returned by the terminal device, where the detection response frame includes the second user identification and second address information corresponding to the terminal device; a UDP link establishment process is performed with the terminal device based on the first address information and the second address information to establish UDP local transmission channel.
在本公开的一个实施例中,探测响应帧还包括终端设备的第一设备标识,第一传输模块1002,还被配置为执行:基于第一设备标识和第二用户标识向云服务器发送密钥获取请求;响应于接收到云服务器返回的第二用户标识对应的密钥,以单播方式向终端设备发送通道建立请求,其中,通道建立请求用于请求与终端设备建立UDP本地传输通道。In one embodiment of the present disclosure, the detection response frame also includes the first device identification of the terminal device, and the first transmission module 1002 is also configured to perform: sending the key to the cloud server based on the first device identification and the second user identification. Obtain the request; in response to receiving the key corresponding to the second user ID returned by the cloud server, send a channel establishment request to the terminal device in a unicast manner, where the channel establishment request is used to request the establishment of a UDP local transmission channel with the terminal device.
在本公开的一个实施例中,第二传输模块1003,还被配置为执行:响应于接收到终端设备通过UDP 本地传输通道发送的上行数据帧,通过TCP连接通道,将上行数据帧发送给云服务器。In one embodiment of the present disclosure, the second transmission module 1003 is also configured to perform: in response to receiving the uplink data frame sent by the terminal device through the UDP local transmission channel, send the uplink data frame to the cloud through the TCP connection channel. server.
在本公开的一个实施例中,第二传输模块1003,还被配置为执行:响应于接收到云服务器通过TCP连接通道发送的下行数据帧;通过UDP本地传输通道,将下行数据帧发送给终端设备。In one embodiment of the present disclosure, the second transmission module 1003 is also configured to: respond to receiving the downlink data frame sent by the cloud server through the TCP connection channel; send the downlink data frame to the terminal through the UDP local transmission channel equipment.
在本公开的一个实施例中,上行数据帧为加密上行数据帧且包括终端设备的第一设备标识,其中,第二传输模块1003,还被配置为执行:基于第一设备标识确定从云服务器获取到的第二用户标识对应的密钥,并基于第二用户标识对应的密钥对加密上行数据帧进行解密;基于代理设备自身的密钥对解密后的上行数据帧进行加密后发送给云服务器。In one embodiment of the present disclosure, the uplink data frame is an encrypted uplink data frame and includes a first device identification of the terminal device, wherein the second transmission module 1003 is further configured to perform: determining from the cloud server based on the first device identification Obtain the key corresponding to the second user ID, and decrypt the encrypted uplink data frame based on the key corresponding to the second user ID; encrypt the decrypted uplink data frame based on the proxy device's own key and send it to the cloud. server.
在本公开的一个实施例中,下行数据帧为加密下行数据帧且包括终端设备的第一设备标识,其中,第二传输模块1003,还被配置为执行:基于代理设备自身的密钥对加密下行数据帧进行解密;基于第一设备标识确定从云服务器获取到的第二用户标识对应的密钥,并基于第二用户标识对应的密钥对解密后的下行数据帧进行加密,并通过UDP本地传输通道发送给终端设备。In one embodiment of the present disclosure, the downlink data frame is an encrypted downlink data frame and includes the first device identification of the terminal device, wherein the second transmission module 1003 is also configured to perform: encryption based on the key pair of the proxy device itself Decrypt the downlink data frame; determine the key corresponding to the second user identification obtained from the cloud server based on the first device identification, and encrypt the decrypted downlink data frame based on the key corresponding to the second user identification, and use UDP to The local transmission channel is sent to the terminal device.
在本公开的一个实施例中,该流量代理装置1000还包括:获取模块,被配置为执行响应于接收到数据帧或探测响应帧,从数据帧或探测响应帧中提取时间戳,并基于时间戳和当前时间,获取时间差;第一确定模块,被配置为执行响应于时间差小于或者等于窗口时间,确定数据帧或探测响应帧为有效帧,对有效帧进行处理或传输;第二确定模块,被配置为执行响应于时间差大于窗口时间,确定数据帧或探测响应帧为无效帧,对无效帧进行丢弃。In one embodiment of the present disclosure, the traffic proxy device 1000 further includes: an acquisition module configured to perform, in response to receiving a data frame or a probe response frame, extract a timestamp from the data frame or probe response frame, and extract a timestamp based on the time. stamp and the current time to obtain the time difference; the first determination module is configured to determine that the data frame or detection response frame is a valid frame in response to the time difference being less than or equal to the window time, and process or transmit the valid frame; the second determination module, It is configured to respond to a time difference greater than the window time, determine the data frame or detection response frame as an invalid frame, and discard the invalid frame.
在本公开的一个实施例中,第一传输模块1002,被配置为执行建立UDP本地传输通道之后,定期与终端设备进行探测请求帧和探测响应帧的交互;In one embodiment of the present disclosure, the first transmission module 1002 is configured to regularly interact with the terminal device with detection request frames and detection response frames after establishing the UDP local transmission channel;
更新模块,被配置为执行响应于探测请求帧和/或探测响应帧各自携带的地址信息更新,则基于更新后地址信息对UDP本地传输通道进行重新建立。The update module is configured to update the address information carried by the probe request frame and/or the probe response frame in response to each, and then re-establish the UDP local transmission channel based on the updated address information.
在本公开的一个实施例中,该流量代理装置1000还包括:关闭模块,被配置为执行响应于第一预设时长内未收到终端设备返回的探测响应帧,则关闭UDP本地传输通道。In one embodiment of the present disclosure, the traffic proxy device 1000 further includes: a closing module configured to close the UDP local transmission channel in response to not receiving a detection response frame returned by the terminal device within a first preset time period.
在本公开的一个实施例中,该流量代理装置1000还包括:关闭模块,被配置为执行响应于代理设备退出代理模式,广播通道断开指示,其中,通道断开指示用于告知终端关闭UDP本地传输通道。In one embodiment of the present disclosure, the traffic proxy device 1000 further includes: a shutdown module configured to broadcast a channel disconnection indication in response to the proxy device exiting the proxy mode, wherein the channel disconnection indication is used to inform the terminal to close UDP local transmission channel.
关于上述实施例中的装置,其中各个模块执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。Regarding the devices in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be described in detail here.
本公开的实施例提供的流量代理装置,代理设备与云服务器建立传输控制协议TCP连接通道,与处于物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道,通过TCP连接通道和UDP本地传输通道,传输终端设备与云服务器通信时所需数据帧。由此,可通过TCP连接通道和UDP本地传输通道对终端设备与云服务器通信时所需数据帧进行传输,减少了终端设备和云端服务器之间进行TCP连接的压力,提高了网络服务质量。The traffic proxy device provided by the embodiment of the present disclosure establishes a transmission control protocol TCP connection channel between the proxy device and the cloud server, and establishes a user datagram protocol UDP local transmission channel with one or more terminal devices in the Internet of Things, through the TCP connection channel and UDP local transmission channel to transmit the data frames required when the terminal device communicates with the cloud server. As a result, the data frames required for communication between the terminal device and the cloud server can be transmitted through the TCP connection channel and the UDP local transmission channel, which reduces the pressure on the TCP connection between the terminal device and the cloud server and improves network service quality.
图11是根据一示例性实施例示出的一种流量代理装置的框图。如图11所示,本公开实施例的流量代理装置1100,包括连接模块1101和传输模块1102。Figure 11 is a block diagram of a traffic proxy device according to an exemplary embodiment. As shown in Figure 11, the traffic proxy device 1100 in the embodiment of the present disclosure includes a connection module 1101 and a transmission module 1102.
连接模块1101,被配置为执行响应于与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道。The connection module 1101 is configured to perform, in response to establishing a User Datagram Protocol UDP local transmission channel with the proxy device in the Internet of Things, disconnecting the first TCP connection channel with the cloud server.
传输模块1102,被配置为执行通过UDP本地传输通道传输与云服务器通信所需的数据帧。The transmission module 1102 is configured to transmit data frames required for communication with the cloud server through the UDP local transmission channel.
在本公开的一个实施例中,传输模块1102,还被配置为执行:通过UDP本地传输通道传输和代理设备向云服务器传输上行数据帧;通过UDP本地传输通道接收代理设备传输的来自云服务器的下行数据帧。In one embodiment of the present disclosure, the transmission module 1102 is also configured to perform: transmitting and transmitting uplink data frames from the proxy device to the cloud server through the UDP local transmission channel; receiving data from the cloud server transmitted by the proxy device through the UDP local transmission channel. Downstream data frame.
在本公开的一个实施例中,连接模块1101,还被配置为执行:获取代理设备对应的第一用户标识和第一地址信息,确定第一用户标识和终端设备对应的第二用户标识一致时,向代理设备发送第二用户标识和终端设备的第二地址信息;基于第一地址信息和第二地址信息,与代理设备进行UDP建链流程,以建立UDP本地传输通道。In one embodiment of the present disclosure, the connection module 1101 is further configured to: obtain the first user identification and first address information corresponding to the proxy device, and determine when the first user identification and the second user identification corresponding to the terminal device are consistent. , sending the second user identification and the second address information of the terminal device to the proxy device; based on the first address information and the second address information, performing a UDP link establishment process with the proxy device to establish a UDP local transmission channel.
在本公开的一个实施例中,连接模块1101,还被配置为执行:获取代理设备周期性广播的探测请求帧,其中,探测请求帧中包括代理设备对应的第一用户标识和第一地址信息;确定第一用户标识和终端设备对应的第二用户标识一致时,向代理设备返回探测响应帧,其中,探测响应帧包括第二用户标识和终端设备的第二地址信息;基于第一地址信息和第二地址信息,与代理设备进行UDP建链流程,以建立UDP本地传输通道。In one embodiment of the present disclosure, the connection module 1101 is further configured to: obtain a detection request frame periodically broadcast by the proxy device, where the detection request frame includes the first user identification and first address information corresponding to the proxy device. ; When it is determined that the first user identification and the second user identification corresponding to the terminal device are consistent, return a detection response frame to the proxy device, where the detection response frame includes the second user identification and the second address information of the terminal device; based on the first address information and second address information, and performs the UDP link establishment process with the proxy device to establish a UDP local transmission channel.
在本公开的一个实施例中,该流量代理装置1100,还包括:发送模块,被配置为执行与代理设备建立UDP本地传输通道之前,基于第一TCP连接通道,将第二用户标识对应的密钥、第二用户标识和终端设备的第一设备标识同步发送给云服务器。In one embodiment of the present disclosure, the traffic proxy device 1100 further includes: a sending module configured to send the password corresponding to the second user ID based on the first TCP connection channel before establishing a UDP local transmission channel with the proxy device. The key, the second user identification and the first device identification of the terminal device are synchronously sent to the cloud server.
在本公开的一个实施例中,传输模块1102,还被配置为执行:基于终端设备所绑定的第二用户标识对应的密钥,对上行数据帧进行加密;通过UDP本地传输通道,将加密上行数据帧发送给代理设备。In one embodiment of the present disclosure, the transmission module 1102 is also configured to: encrypt the uplink data frame based on the key corresponding to the second user identification bound to the terminal device; and encrypt the encrypted data frame through the UDP local transmission channel. Uplink data frames are sent to the proxy device.
在本公开的一个实施例中,下行数据帧为加密下行数据帧,其中,传输模块1102,还被配置为执行:通过UDP本地传输通道接收加密下行数据帧,并基于终端设备所绑定的第二用户标识对应的密钥对加密下行数据帧进行解密。In one embodiment of the present disclosure, the downlink data frame is an encrypted downlink data frame, wherein the transmission module 1102 is further configured to perform: receiving the encrypted downlink data frame through the UDP local transmission channel, and based on the third bound data frame of the terminal device. The key corresponding to the two user IDs decrypts the encrypted downlink data frame.
在本公开的一个实施例中,该流量代理装置1100,还包括:获取模块,被配置为执行每接收到数据帧或探测请求帧,从接收到的数据帧或探测请求帧中提取时间戳,并基于时间戳和当前时间,获取时间差;第一确定模块,被配置为执行响应于时间差小于或者等于窗口时间,确定该数据帧或探测请求帧为有效帧,对有效帧进行处理;第二确定模块,被配置为执行响应于时间差大于窗口时间,确定该数据帧或探测请求帧为无效帧,对无效帧进行丢弃。In one embodiment of the present disclosure, the traffic proxy device 1100 further includes: an acquisition module configured to extract a timestamp from the received data frame or probe request frame every time a data frame or probe request frame is received, And based on the timestamp and the current time, obtain the time difference; the first determination module is configured to execute in response to the time difference being less than or equal to the window time, determine that the data frame or the detection request frame is a valid frame, and process the valid frame; the second determination module The module is configured to determine that the data frame or the detection request frame is an invalid frame in response to the time difference being greater than the window time, and discard the invalid frame.
在本公开的一个实施例中,该流量代理装置1100,还包括:交互模块,被配置为执行建立UDP本地传输通道之后,定期与代理设备进行探测请求帧和探测响应帧的交互;更新模块,被配置为执行响应于探测请求帧和/或探测响应帧内携带的地址信息更新,则基于更新后地址信息对UDP本地传输通道进行重新建立。In one embodiment of the present disclosure, the traffic proxy device 1100 also includes: an interaction module configured to regularly interact with the proxy device with detection request frames and detection response frames after establishing a UDP local transmission channel; an update module, It is configured to update the address information carried in the probe request frame and/or the probe response frame in response to the update, and then re-establish the UDP local transmission channel based on the updated address information.
在本公开的一个实施例中,该流量代理装置1100,还包括:关闭模块,被配置为执行响应于终端设备满足UDP本地传输通道的关闭条件,则关闭UDP本地传输通道,并建立与云服务器之间的第二TCP连接通道。In one embodiment of the present disclosure, the traffic proxy device 1100 also includes: a shutdown module configured to close the UDP local transmission channel in response to the terminal device meeting the closing conditions of the UDP local transmission channel, and establish a connection with the cloud server. channel between the second TCP connection.
在本公开的一个实施例中,UDP本地传输通道的关闭条件包括以下中的至少一项:预设时长内终端设备未收到代理设备广播的探测请求帧;接收代理设备广播的通道断开指示。In one embodiment of the present disclosure, the closing condition of the UDP local transmission channel includes at least one of the following: the terminal device does not receive the detection request frame broadcast by the proxy device within a preset period of time; receives the channel disconnection indication broadcast by the proxy device .
在本公开的一个实施例中,通道断开指示包括第二设备标识和第三用户标识,其中,关闭模块,还被配置为执行:响应于第二设备标识为终端设备的第一设备标识,且第三用户标识为终端设备所绑定的第二用户标识,则关闭UDP本地传输通道。In one embodiment of the present disclosure, the channel disconnection indication includes a second device identification and a third user identification, wherein the shutdown module is further configured to perform: in response to the second device identification being the first device identification of the terminal device, If the third user ID is the second user ID bound to the terminal device, the UDP local transmission channel is closed.
关于上述实施例中的装置,其中各个模块执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。Regarding the devices in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be described in detail here.
本公开的实施例中,终端设备与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道,通过UDP本地传输通道传输与云服务器通信所需的数据帧。由此,通过UDP本地传输通道传输与云服务器通信所需数据帧,减少了终端设备和云端服务器之间进行TCP连接的压力,提高了网络服务质量。In the embodiment of the present disclosure, the terminal device establishes a user datagram protocol UDP local transmission channel with the proxy device in the Internet of Things, disconnects the first TCP connection channel with the cloud server, and transmits all communication data with the cloud server through the UDP local transmission channel. required data frame. As a result, the data frames required for communication with the cloud server are transmitted through the UDP local transmission channel, which reduces the pressure on the TCP connection between the terminal device and the cloud server and improves the quality of network service.
图12是根据一示例性实施例示出的一种电子设备1200的框图。FIG. 12 is a block diagram of an electronic device 1200 according to an exemplary embodiment.
如图12所示,上述电子设备1200包括:As shown in Figure 12, the above-mentioned electronic device 1200 includes:
存储器1201及处理器1202,连接不同组件(包括存储器1201和处理器1202)的总线1203,存储器1201存储有计算机程序,当处理器1202执行程序时实现本公开实施例上述的流量代理方法。The memory 1201 and the processor 1202 are connected to the bus 1203 of different components (including the memory 1201 and the processor 1202). The memory 1201 stores a computer program. When the processor 1202 executes the program, the traffic proxy method described above in the embodiment of the present disclosure is implemented.
总线1203表示几类总线结构中的一种或多种,包括存储器总线或者存储器控制器,外围总线,图形加速端口,处理器或者使用多种总线结构中的任意总线结构的局域总线。举例来说,这些体系结构包括但不限于工业标准体系结构(ISA)总线,微通道体系结构(MAC)总线,增强型ISA总线、视频电子标准协会(VESA)局域总线以及外围组件互连(PCI)总线。 Bus 1203 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics accelerated port, a processor, or a local bus using any of a variety of bus structures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect ( PCI) bus.
电子设备1200典型地包括多种电子设备可读介质。这些介质可以是任何能够被电子设备1200访问的可用介质,包括易失性和非易失性介质,可移动的和不可移动的介质。 Electronic device 1200 typically includes a variety of electronic device-readable media. These media can be any available media that can be accessed by electronic device 1200, including volatile and nonvolatile media, removable and non-removable media.
存储器1201还可以包括易失性存储器形式的计算机系统可读介质,例如随机存取存储器(RAM)1204和/或高速缓存存储器1205。电子设备1200可以进一步包括其它可移动/不可移动的、易失性/非易失性计算机系统存储介质。仅作为举例,存储系统1206可以用于读写不可移动的、非易失性磁介质(图12未显示,通常称为“硬盘驱动器”)。尽管图12中未示出,可以提供用于对可移动非易失性磁盘(例如“软盘”)读写的磁盘驱动器,以及对可移动非易失性光盘(例如CD-ROM,DVD-ROM或者其它光介质)读写的光盘驱动器。在这些情况下,每个驱动器可以通过一个或者多个数据介质接口与总线1203相连。存储器1201可以包括至少一个程序产品,该程序产品具有一组(例如至少一个)程序模块,这些程序模块被配置以执行本公开各实施例的功能。 Memory 1201 may also include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 1204 and/or cache memory 1205 . Electronic device 1200 may further include other removable/non-removable, volatile/non-volatile computer system storage media. By way of example only, storage system 1206 may be used to read and write to non-removable, non-volatile magnetic media (not shown in Figure 12, commonly referred to as a "hard drive"). Although not shown in FIG. 12, a disk drive for reading and writing removable non-volatile disks (e.g., "floppy disks"), and removable non-volatile optical disks (e.g., CD-ROM, DVD-ROM) may be provided. or other optical media) that can read and write optical disc drives. In these cases, each drive may be connected to bus 1203 through one or more data media interfaces. Memory 1201 may include at least one program product having a set of (eg, at least one) program modules configured to perform the functions of embodiments of the present disclosure.
具有一组(至少一个)程序模块1207的程序/实用工具1208,可以存储在例如存储器1201中,这样的程序模块1207包括——但不限于——操作系统、一个或者多个应用程序、其它程序模块以及程序数据,这些示例中的每一个或某种组合中可能包括网络环境的实现。程序模块1212通常执行本公开所描述的实施例中的功能和/或方法。A program/utility 1208 having a set of (at least one) program modules 1207, which may be stored, for example, in the memory 1201, such program modules 1207 including but not limited to an operating system, one or more applications, other programs Modules, as well as program data, each of these examples or some combination may include an implementation of a network environment. Program modules 1212 generally perform functions and/or methods in the embodiments described in this disclosure.
电子设备1200也可以与一个或多个外部设备1209(例如键盘、指向设备、显示器1210等)通信,还可与一个或者多个使得用户能与该电子设备1200交互的设备通信,和/或与使得该电子设备1200能与一个或多个其它计算设备进行通信的任何设备(例如网卡,调制解调器等等)通信。这种通信可以通 过输入/输出(I/O)接口1212进行。并且,电子设备1200还可以通过网络适配器1213与一个或者多个网络(例如局域网(LAN),广域网(WAN)和/或公共网络,例如因特网)通信。如图12所示,网络适配器1213通过总线1203与电子设备1200的其它模块通信。应当明白,尽管图中未示出,可以结合电子设备1200使用其它硬件和/或软件模块,包括但不限于:微代码、设备驱动器、冗余处理单元、外部磁盘驱动阵列、RAID系统、磁带驱动器以及数据备份存储系统等。 Electronic device 1200 may also communicate with one or more external devices 1209 (e.g., keyboard, pointing device, display 1210, etc.), may also communicate with one or more devices that enable a user to interact with electronic device 1200, and/or with Any device (eg, network card, modem, etc.) that enables the electronic device 1200 to communicate with one or more other computing devices. This communication may occur through an input/output (I/O) interface 1212. Furthermore, the electronic device 1200 may also communicate with one or more networks (eg, a local area network (LAN), a wide area network (WAN), and/or a public network, such as the Internet) through the network adapter 1213. As shown in Figure 12, network adapter 1213 communicates with other modules of electronic device 1200 through bus 1203. It should be understood that, although not shown in the figures, other hardware and/or software modules may be used in conjunction with electronic device 1200, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives And data backup storage system, etc.
处理器1202通过运行存储在存储器1201中的程序,从而执行各种功能应用以及数据处理。The processor 1202 executes various functional applications and data processing by running programs stored in the memory 1201 .
需要说明的是,本实施例的电子设备的实施过程和技术原理参见前述对本公开实施例的流量代理方法的解释说明,此处不再赘述。It should be noted that for the implementation process and technical principles of the electronic device in this embodiment, please refer to the aforementioned explanation of the traffic proxy method in the embodiment of the present disclosure, and will not be described again here.
本公开实施例提供的电子设备,可以执行如前所述的流量代理方法,与云服务器建立传输控制协议TCP连接通道,与处于物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道,通过TCP连接通道和UDP本地传输通道,传输终端设备与云服务器通信时所需数据帧。由此,可通过TCP连接通道和UDP本地传输通道对终端设备与云服务器通信时所需数据帧进行传输,减少了终端设备和云端服务器之间进行TCP连接的压力,提高了网络服务质量。The electronic device provided by the embodiment of the present disclosure can execute the traffic proxy method as described above, establish a transmission control protocol TCP connection channel with the cloud server, and establish a user datagram protocol UDP local with one or more terminal devices in the Internet of Things. Transmission channel, through TCP connection channel and UDP local transmission channel, transmits the data frames required when the terminal device communicates with the cloud server. As a result, the data frames required for communication between the terminal device and the cloud server can be transmitted through the TCP connection channel and the UDP local transmission channel, which reduces the pressure on the TCP connection between the terminal device and the cloud server and improves network service quality.
为了实现上述实施例,本公开还提出一种计算机可读存储介质。In order to implement the above embodiments, the present disclosure also proposes a computer-readable storage medium.
其中,该计算机可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行如前所述的流量代理方法。可选的,计算机可读存储介质可以是ROM、随机存取存储器(RAM)、CD-ROM、磁带、软盘和光数据存储设备等。Wherein, when the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device can perform the traffic proxy method as described above. Optionally, the computer-readable storage medium may be ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, optical data storage device, etc.
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本公开的其它实施方案。本公开旨在涵盖本公开的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本公开的一般性原理并包括本公开未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本公开的真正范围和精神由下面的权利要求指出。Other embodiments of the disclosure will be readily apparent to those skilled in the art from consideration of the specification and practice of the invention disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the disclosure that follow the general principles of the disclosure and include common common sense or customary technical means in the technical field that are not disclosed in the disclosure. . It is intended that the specification and examples be considered as exemplary only, with a true scope and spirit of the disclosure being indicated by the following claims.
应当理解的是,本公开并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本公开的范围仅由所附的权利要求来限制。It is to be understood that the present disclosure is not limited to the precise structures described above and illustrated in the accompanying drawings, and various modifications and changes may be made without departing from the scope thereof. The scope of the disclosure is limited only by the appended claims.

Claims (36)

  1. 一种流量代理方法,其特征在于,适用于代理设备,所述方法包括:A traffic proxy method, characterized in that it is suitable for proxy equipment, and the method includes:
    与云服务器建立传输控制协议TCP连接通道;Establish a Transmission Control Protocol TCP connection channel with the cloud server;
    与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道;Establish a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things;
    通过所述TCP连接通道和所述UDP本地传输通道,传输所述终端设备与所述云服务器通信时所需数据帧。Through the TCP connection channel and the UDP local transmission channel, the data frames required when the terminal device communicates with the cloud server are transmitted.
  2. 根据权利要求1所述的方法,其特征在于,所述与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道,包括:The method according to claim 1, characterized in that establishing a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things includes:
    获取所述终端设备的第二地址信息;Obtain the second address information of the terminal device;
    基于所述代理设备自身的第一地址信息和所述第二地址信息,与所述终端设备进行UDP建链流程,以建立所述UDP本地传输通道。Based on the first address information and the second address information of the proxy device itself, a UDP link establishment process is performed with the terminal device to establish the UDP local transmission channel.
  3. 根据权利要求2所述的方法,其特征在于,所述基于所述第一地址信息和所述第二地址信息,与所述终端设备进行UDP建链流程,以建立所述UDP本地传输通道之前,还包括:The method according to claim 2, characterized in that, based on the first address information and the second address information, performing a UDP link establishment process with the terminal device before establishing the UDP local transmission channel ,Also includes:
    获取所述终端设备的第一设备标识和所述终端设备绑定的第二用户标识;Obtain the first device identification of the terminal device and the second user identification bound to the terminal device;
    基于所述第一设备标识和所述第二用户标识,从所述云服务器获取所述第二用户标识对应的密钥。Based on the first device identification and the second user identification, obtain a key corresponding to the second user identification from the cloud server.
  4. 根据权利要求1-3任一项所述的方法,其特征在于,所述通过所述TCP连接通道和所述UDP本地传输通道,传输所述终端设备与所述云服务器通信时所需数据帧,包括:The method according to any one of claims 1 to 3, characterized in that the data frames required when the terminal device communicates with the cloud server are transmitted through the TCP connection channel and the UDP local transmission channel. ,include:
    响应于接收到所述终端设备通过所述UDP本地传输通道发送的上行数据帧,通过所述TCP连接通道,将所述上行数据帧发送给所述云服务器。In response to receiving the uplink data frame sent by the terminal device through the UDP local transmission channel, the uplink data frame is sent to the cloud server through the TCP connection channel.
  5. 根据权利要求1-3任一项所述的方法,其特征在于,所述通过所述TCP连接通道和所述UDP本地传输通道,传输所述终端设备与所述云服务器通信时所需数据帧,包括:The method according to any one of claims 1 to 3, characterized in that the data frames required when the terminal device communicates with the cloud server are transmitted through the TCP connection channel and the UDP local transmission channel. ,include:
    响应于接收到所述云服务器通过所述TCP连接通道发送的下行数据帧,通过所述UDP本地传输通道,将所述下行数据帧发送给所述终端设备。In response to receiving the downlink data frame sent by the cloud server through the TCP connection channel, the downlink data frame is sent to the terminal device through the UDP local transmission channel.
  6. 根据权利要求4所述的方法,其特征在于,所述上行数据帧为加密上行数据帧且包括所述终端设备的第一设备标识,其中,所述通过所述TCP连接通道,将所述上行消息发送给所述云服务器,包括:The method according to claim 4, characterized in that the uplink data frame is an encrypted uplink data frame and includes a first device identification of the terminal device, wherein the uplink data frame is transmitted through the TCP connection channel. The message is sent to the cloud server, including:
    基于所述第一设备标识,确定从所述云服务器获取到的所述第二用户标识对应的密钥,并基于所述第二用户标识对应的密钥对所述加密上行数据帧进行解密;Based on the first device identification, determine the key corresponding to the second user identification obtained from the cloud server, and decrypt the encrypted uplink data frame based on the key corresponding to the second user identification;
    基于所述代理设备自身的密钥对解密后的上行消息进行加密后发送给所述云服务器。The decrypted uplink message is encrypted based on the proxy device's own key and then sent to the cloud server.
  7. 根据权利要求5所述的方法,其特征在于,所述下行数据帧为加密下行数据帧且包括所述终端设备的第一设备标识,其中,所述通过所述UDP本地传输通道,将所述下行消息发送给所述终端设备,包括:The method of claim 5, wherein the downlink data frame is an encrypted downlink data frame and includes a first device identification of the terminal device, wherein the UDP local transmission channel is used to transmit the Downlink messages are sent to the terminal device, including:
    基于所述代理设备自身的密钥对加密下行数据帧进行解密;Decrypt the encrypted downlink data frame based on the proxy device's own key;
    基于所述第一设备标识确定从所述云服务器获取到的所述第二用户标识对应的密钥,并基于所述第二用户标识对应的密钥对解密后的下行数据帧进行加密,并通过所述UDP本地传输通道发送给所述终端设备。Determine the key corresponding to the second user identification obtained from the cloud server based on the first device identification, and encrypt the decrypted downlink data frame based on the key corresponding to the second user identification, and Sent to the terminal device through the UDP local transmission channel.
  8. 根据权利要求1或2所述的方法,其特征在于,所述方法还包括:The method according to claim 1 or 2, characterized in that, the method further includes:
    响应于接收到所述数据帧,从所述数据帧中提取时间戳,并基于所述时间戳和当前时间,获取时间差;In response to receiving the data frame, extract a timestamp from the data frame and obtain a time difference based on the timestamp and the current time;
    响应于所述时间差小于或者等于窗口时间,确定所述数据帧为有效帧,对所述有效帧进行处理或传输;In response to the time difference being less than or equal to the window time, determining the data frame to be a valid frame, and processing or transmitting the valid frame;
    响应于所述时间差大于所述窗口时间,确定所述数据帧为无效帧,对所述无效帧进行丢弃。In response to the time difference being greater than the window time, it is determined that the data frame is an invalid frame, and the invalid frame is discarded.
  9. 根据权利要求1-3任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 1-3, characterized in that the method further includes:
    响应于所述代理设备退出代理模式,广播通道断开指示,其中,所述通道断开指示用于告知所述终端设备关闭所述UDP本地传输通道。In response to the proxy device exiting the proxy mode, a channel disconnection indication is broadcast, where the channel disconnection indication is used to inform the terminal device to close the UDP local transmission channel.
  10. 一种流量代理方法,其特征在于,适用于终端设备,所述方法包括:A traffic proxy method, characterized in that it is suitable for terminal equipment, and the method includes:
    响应于与处于物联网中的代理设备建立UDP本地传输通道,断开与云服务器的第一TCP连接通道;In response to establishing a UDP local transmission channel with the proxy device in the Internet of Things, disconnecting the first TCP connection channel with the cloud server;
    通过所述UDP本地传输通道传输与所述云服务器通信所需的数据帧。The data frames required for communication with the cloud server are transmitted through the UDP local transmission channel.
  11. 根据权利要求10所述的方法,其特征在于,所述通过所述UDP本地传输通道传输与所述云服务器通信所需的数据帧,包括:The method according to claim 10, characterized in that said transmitting the data frames required for communication with the cloud server through the UDP local transmission channel includes:
    通过所述UDP本地传输通道传输和所述代理设备向所述云服务器传输上行数据帧;Transmit the uplink data frame to the cloud server through the UDP local transmission channel and the proxy device;
    通过所述UDP本地传输通道接收所述代理设备传输的来自所述云服务器的下行数据帧。Receive the downlink data frame from the cloud server transmitted by the proxy device through the UDP local transmission channel.
  12. 根据权利要求10所述的方法,其特征在于,与所述代理设备建立UDP本地传输通道,包括:The method according to claim 10, characterized in that establishing a UDP local transmission channel with the proxy device includes:
    获取所述代理设备对应的第一用户标识和第一地址信息;Obtain the first user identification and first address information corresponding to the proxy device;
    确定所述第一用户标识和所述终端设备对应的第二用户标识一致时,向所述代理设备发送所述第二用户标识和所述终端设备的第二地址信息;When it is determined that the first user identification and the second user identification corresponding to the terminal device are consistent, send the second user identification and the second address information of the terminal device to the proxy device;
    基于所述第一地址信息和所述第二地址信息,与所述代理设备进行UDP建链流程,以建立所述UDP本地传输通道。Based on the first address information and the second address information, a UDP link establishment process is performed with the proxy device to establish the UDP local transmission channel.
  13. 根据权利要求12所述的方法,其特征在于,所述与所述代理设备建立UDP本地传输通道之前,还包括:The method according to claim 12, characterized in that before establishing a UDP local transmission channel with the proxy device, it further includes:
    基于所述第一TCP连接通道,将所述第二用户标识对应的密钥、所述第二用户标识和所述终端设备的第一设备标识同步发送给所述云服务器。Based on the first TCP connection channel, the key corresponding to the second user identification, the second user identification and the first device identification of the terminal device are synchronously sent to the cloud server.
  14. 根据权利要求10所述的方法,其特征在于,所述通过所述UDP本地传输通道传输与所述云服务器通信所需的数据帧,包括:The method according to claim 10, characterized in that said transmitting the data frames required for communication with the cloud server through the UDP local transmission channel includes:
    基于所述终端设备所绑定的第二用户标识对应的密钥,对所述上行数据帧进行加密;Encrypt the uplink data frame based on the key corresponding to the second user identification bound to the terminal device;
    通过所述UDP本地传输通道,将加密上行数据帧发送给所述代理设备。The encrypted uplink data frame is sent to the proxy device through the UDP local transmission channel.
  15. 根据权利要求11所述的方法,其特征在于,所述下行数据帧为加密下行数据帧,其中,所述通过所述UDP本地传输通道接收所述代理设备传输的来自所述云服务器的下行数据帧,包括:The method according to claim 11, wherein the downlink data frame is an encrypted downlink data frame, wherein the downlink data from the cloud server transmitted by the proxy device is received through the UDP local transmission channel. frames, including:
    通过所述UDP本地传输通道接收所述加密下行数据帧,并基于所述终端设备所绑定的第二用户标识对应的密钥对所述加密下行数据帧进行解密。The encrypted downlink data frame is received through the UDP local transmission channel, and the encrypted downlink data frame is decrypted based on the key corresponding to the second user identification bound to the terminal device.
  16. 根据权利要求13或14所述的方法,其特征在于,所述方法还包括:The method according to claim 13 or 14, characterized in that the method further includes:
    响应于接收到所述数据帧,从所述数据帧中提取时间戳,并基于所述时间戳和当前时间,获取时间差;In response to receiving the data frame, extract a timestamp from the data frame and obtain a time difference based on the timestamp and the current time;
    响应于所述时间差小于或者等于窗口时间,确定所述数据帧为有效帧,对所述有效帧进行处理;In response to the time difference being less than or equal to the window time, determining the data frame to be a valid frame, and processing the valid frame;
    响应于所述时间差大于所述窗口时间,确定所述数据帧为无效帧,对所述无效帧进行丢弃。In response to the time difference being greater than the window time, it is determined that the data frame is an invalid frame, and the invalid frame is discarded.
  17. 根据权利要求10所述的方法,其特征在于,所述方法还包括:The method of claim 10, further comprising:
    响应于所述终端设备满足所述UDP本地传输通道的关闭条件,则关闭所述UDP本地传输通道,并重新建立与所述云服务器之间的所述第一TCP连接通道。In response to the terminal device meeting the closing condition of the UDP local transmission channel, the UDP local transmission channel is closed and the first TCP connection channel with the cloud server is re-established.
  18. 一种流量代理装置,其特征在于,适用于代理设备,所述装置包括:A traffic proxy device, characterized in that it is suitable for proxy equipment, and the device includes:
    连接模块,被配置为执行与云服务器建立传输控制协议TCP连接通道;The connection module is configured to establish a transmission control protocol TCP connection channel with the cloud server;
    第一传输模块,被配置为执行与处于同一物联网中的一个或多个终端设备建立用户数据报协议UDP本地传输通道;The first transmission module is configured to establish a User Datagram Protocol UDP local transmission channel with one or more terminal devices in the same Internet of Things;
    第二传输模块,被配置为执行通过所述TCP连接通道和所述UDP本地传输通道,传输所述终端设备与所述云服务器通信时所需数据帧。The second transmission module is configured to transmit data frames required when the terminal device communicates with the cloud server through the TCP connection channel and the UDP local transmission channel.
  19. 根据权利要求18所述的装置,其特征在于,所述第一传输模块,还被配置为执行:The device according to claim 18, wherein the first transmission module is further configured to execute:
    获取所述终端设备的第二地址信息;Obtain the second address information of the terminal device;
    基于所述代理设备自身的第一地址信息和所述第二地址信息,与所述终端设备进行UDP建链流程,以建立所述UDP本地传输通道。Based on the first address information and the second address information of the proxy device itself, a UDP link establishment process is performed with the terminal device to establish the UDP local transmission channel.
  20. 根据权利要求19所述的装置,其特征在于,所述第一传输模块,还被配置为执行:The device according to claim 19, wherein the first transmission module is further configured to execute:
    获取所述终端设备的第一设备标识和所述终端设备绑定的第二用户标识;Obtain the first device identification of the terminal device and the second user identification bound to the terminal device;
    基于所述第一设备标识和所述第二用户标识,从所述云服务器处获取所述第二用户标识对应的密钥。Based on the first device identification and the second user identification, a key corresponding to the second user identification is obtained from the cloud server.
  21. 根据权利要求18-20任一项所述的装置,其特征在于,所述第二传输模块,还被配置为执行:The device according to any one of claims 18-20, characterized in that the second transmission module is further configured to execute:
    响应于接收到所述终端设备通过所述UDP本地传输通道发送的上行数据帧,通过所述TCP连接通道,将所述上行数据帧发送给所述云服务器。In response to receiving the uplink data frame sent by the terminal device through the UDP local transmission channel, the uplink data frame is sent to the cloud server through the TCP connection channel.
  22. 根据权利要求18-20任一项所述的装置,其特征在于,所述第二传输模块,还被配置为执行:The device according to any one of claims 18-20, characterized in that the second transmission module is further configured to execute:
    响应于接收到所述云服务器通过所述TCP连接通道发送的下行数据帧,通过所述UDP本地传输通道,将所述下行数据帧发送给所述终端设备。In response to receiving the downlink data frame sent by the cloud server through the TCP connection channel, the downlink data frame is sent to the terminal device through the UDP local transmission channel.
  23. 根据权利要求21所述的装置,其特征在于,所述上行数据帧为加密上行数据帧且包括所述终端设备的第一设备标识,其中,所述第二传输模块,还被配置为执行:The apparatus according to claim 21, wherein the uplink data frame is an encrypted uplink data frame and includes a first device identification of the terminal device, wherein the second transmission module is further configured to execute:
    基于所述第一设备标识确定从所述云服务器获取到的所述第二用户标识对应的密钥,并基于所述第二用户标识对应的密钥对所述加密上行数据帧进行解密;Determine the key corresponding to the second user identification obtained from the cloud server based on the first device identification, and decrypt the encrypted uplink data frame based on the key corresponding to the second user identification;
    基于所述代理设备自身的密钥对解密后的上行消息进行加密后发送给所述云服务器。The decrypted uplink message is encrypted based on the proxy device's own key and then sent to the cloud server.
  24. 根据权利要求22所述的装置,其特征在于,所述下行数据帧为加密下行数据帧且包括所述终端设备的第一设备标识,其中,所述第二传输模块,还被配置为执行:The apparatus according to claim 22, wherein the downlink data frame is an encrypted downlink data frame and includes the first device identification of the terminal device, wherein the second transmission module is further configured to execute:
    基于所述代理设备自身的密钥对加密下行数据帧进行解密;Decrypt the encrypted downlink data frame based on the proxy device's own key;
    基于所述第一设备标识确定从所述云服务器获取到的所述第二用户标识对应的密钥,并基于所述第二用户标识对应的密钥对解密后的下行数据帧进行加密,并通过所述UDP本地传输通道发送给所述终端设备。Determine the key corresponding to the second user identification obtained from the cloud server based on the first device identification, and encrypt the decrypted downlink data frame based on the key corresponding to the second user identification, and Sent to the terminal device through the UDP local transmission channel.
  25. 根据权利要求18或19所述的装置,其特征在于,所述装置还包括:The device according to claim 18 or 19, characterized in that the device further includes:
    获取模块,被配置为执行响应于接收到所述数据帧,从所述数据帧中提取时间戳,并基于所述时间戳和当前时间,获取时间差;An acquisition module configured to perform, in response to receiving the data frame, extract a timestamp from the data frame, and obtain a time difference based on the timestamp and the current time;
    第一确定模块,被配置为执行响应于所述时间差小于或者等于窗口时间,确定所述数据帧为有效帧,对所述有效帧进行处理或传输;A first determination module configured to determine that the data frame is a valid frame in response to the time difference being less than or equal to the window time, and process or transmit the valid frame;
    第二确定模块,被配置为执行响应于所述时间差大于所述窗口时间,确定所述数据帧或探测响应帧为无效帧,对所述无效帧进行丢弃。The second determination module is configured to determine that the data frame or the detection response frame is an invalid frame in response to the time difference being greater than the window time, and discard the invalid frame.
  26. 根据权利要求18或20所述的装置,其特征在于,所述装置还包括:The device according to claim 18 or 20, characterized in that the device further includes:
    关闭模块,被配置为执行响应于所述代理设备退出代理模式,广播通道断开指示,其中,所述通道断开指示用于告知所述终端关闭所述UDP本地传输通道。A closing module configured to broadcast a channel disconnection indication in response to the proxy device exiting the proxy mode, wherein the channel disconnection indication is used to inform the terminal to close the UDP local transmission channel.
  27. 一种流量代理装置,其特征在于,适用于终端设备,所述装置包括:A traffic proxy device, characterized in that it is suitable for terminal equipment, and the device includes:
    连接模块,被配置为执行响应于与处于物联网中的代理设备建立用户数据报协议UDP本地传输通道,断开与云服务器的第一TCP连接通道;The connection module is configured to perform, in response to establishing a User Datagram Protocol UDP local transmission channel with the proxy device in the Internet of Things, disconnecting the first TCP connection channel with the cloud server;
    传输模块,被配置为执行通过所述UDP本地传输通道传输与所述云服务器通信所需的数据帧。A transmission module configured to transmit data frames required for communication with the cloud server through the UDP local transmission channel.
  28. 根据权利要求27所述的装置,其特征在于,所述传输模块,还被配置为执行:The device according to claim 27, wherein the transmission module is further configured to execute:
    通过所述UDP本地传输通道传输和所述代理设备向所述云服务器传输上行数据帧;Transmit the uplink data frame to the cloud server through the UDP local transmission channel and the proxy device;
    通过所述UDP本地传输通道接收所述代理设备传输的来自所述云服务器的下行数据帧。Receive the downlink data frame from the cloud server transmitted by the proxy device through the UDP local transmission channel.
  29. 根据权利要求27所述的装置,其特征在于,所述连接模块,还被配置为执行:The device according to claim 27, wherein the connection module is further configured to perform:
    获取所述代理设备对应的第一用户标识和第一地址信息;Obtain the first user identification and first address information corresponding to the proxy device;
    确定所述第一用户标识和所述终端设备对应的第二用户标识一致时,向所述代理设备发送所述第二用户标识和所述终端设备的第二地址信息;When it is determined that the first user identification and the second user identification corresponding to the terminal device are consistent, send the second user identification and the second address information of the terminal device to the proxy device;
    基于所述第一地址信息和所述第二地址信息,与所述代理设备进行UDP建链流程,以建立所述UDP本地传输通道。Based on the first address information and the second address information, a UDP link establishment process is performed with the proxy device to establish the UDP local transmission channel.
  30. 根据权利要求29所述的装置,其特征在于,所述装置还包括:The device of claim 29, further comprising:
    发送模块,被配置为执行所述与所述代理设备建立UDP本地传输通道之前,基于所述第一TCP连接通道,将所述第二用户标识对应的密钥、所述第二用户标识和所述终端设备的第一设备标识同步发送给所述云服务器。The sending module is configured to, before establishing the UDP local transmission channel with the proxy device, based on the first TCP connection channel, send the key corresponding to the second user identification, the second user identification and the The first device identification of the terminal device is synchronously sent to the cloud server.
  31. 根据权利要求28所述的装置,其特征在于,所述传输模块,还被配置为执行:The device according to claim 28, wherein the transmission module is further configured to execute:
    基于所述终端设备所绑定的第二用户标识对应的密钥,对所述上行数据帧进行加密;Encrypt the uplink data frame based on the key corresponding to the second user identification bound to the terminal device;
    通过所述UDP本地传输通道,将加密上行数据帧发送给所述代理设备。The encrypted uplink data frame is sent to the proxy device through the UDP local transmission channel.
  32. 根据权利要求28所述的装置,其特征在于,所述下行数据帧为加密下行数据帧,其中,所述传输模块,还被配置为执行:The device according to claim 28, wherein the downlink data frame is an encrypted downlink data frame, and the transmission module is further configured to execute:
    通过所述UDP本地传输通道接收所述加密下行数据帧,并基于所述终端设备所绑定的第二用户标识对应的密钥对所述加密下行数据帧进行解密。The encrypted downlink data frame is received through the UDP local transmission channel, and the encrypted downlink data frame is decrypted based on the key corresponding to the second user identification bound to the terminal device.
  33. 根据权利要求27所述的装置,其特征在于,所述装置还包括:The device of claim 27, further comprising:
    获取模块,被配置为执行响应于接收到所述数据帧,从所述数据帧中提取时间戳,并基于所述时间戳和当前时间,获取时间差;An acquisition module configured to perform, in response to receiving the data frame, extract a timestamp from the data frame, and obtain a time difference based on the timestamp and the current time;
    第一确定模块,被配置为执行响应于所述时间差小于或者等于窗口时间,确定所述数据帧为有效帧,对所述有效帧进行处理;The first determination module is configured to determine that the data frame is a valid frame in response to the time difference being less than or equal to the window time, and process the valid frame;
    第二确定模块,被配置为执行响应于所述时间差大于所述窗口时间,确定所述数据帧为无效帧,对所述无效帧进行丢弃。The second determination module is configured to determine that the data frame is an invalid frame in response to the time difference being greater than the window time, and discard the invalid frame.
  34. 根据权利要求27所述的装置,其特征在于,所述装置,还包括:The device according to claim 27, characterized in that the device further includes:
    关闭模块,被配置为执行响应于所述终端设备满足所述UDP本地传输通道的关闭条件,则关闭所述UDP本地传输通道,并重新建立与所述云服务器之间的所述第一TCP连接通道。a shutdown module configured to close the UDP local transmission channel and re-establish the first TCP connection with the cloud server in response to the terminal device meeting the closing condition of the UDP local transmission channel. aisle.
  35. 一种电子设备,其特征在于,包括:An electronic device, characterized by including:
    处理器;processor;
    用于存储所述处理器的可执行指令的存储器;memory for storing executable instructions for the processor;
    其中,所述处理器被配置为执行所述指令,以实现如权利要求1-9中任一项所述的方法,或者如权利要求10-17中任一项所述的方法。Wherein, the processor is configured to execute the instructions to implement the method according to any one of claims 1-9, or the method according to any one of claims 10-17.
  36. 一种计算机可读存储介质,其特征在于,当所述计算机可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行如权利要求1-9中任一项所述的方法,或者如权利要求10-17中任一项所述的方法。A computer-readable storage medium, characterized in that, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is capable of executing the method described in any one of claims 1-9. Method, or the method according to any one of claims 10-17.
PCT/CN2022/084176 2022-03-30 2022-03-30 Traffic proxy methods and apparatuses, electronic device and storage medium WO2023184264A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2022/084176 WO2023184264A1 (en) 2022-03-30 2022-03-30 Traffic proxy methods and apparatuses, electronic device and storage medium
CN202280000789.3A CN114902635A (en) 2022-03-30 2022-03-30 Flow proxy method and device, electronic equipment and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2022/084176 WO2023184264A1 (en) 2022-03-30 2022-03-30 Traffic proxy methods and apparatuses, electronic device and storage medium

Publications (1)

Publication Number Publication Date
WO2023184264A1 true WO2023184264A1 (en) 2023-10-05

Family

ID=82729564

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/084176 WO2023184264A1 (en) 2022-03-30 2022-03-30 Traffic proxy methods and apparatuses, electronic device and storage medium

Country Status (2)

Country Link
CN (1) CN114902635A (en)
WO (1) WO2023184264A1 (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116962488B (en) * 2023-09-18 2023-12-19 腾讯科技(深圳)有限公司 Method, device, electronic equipment and readable medium for establishing cloud service connection

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060256771A1 (en) * 2005-05-12 2006-11-16 Yahoo! Inc. Proxy server for relaying VOIP messages
CN102088460A (en) * 2010-12-29 2011-06-08 北京新媒传信科技有限公司 Method, device and system for transmitting streaming media data in restricted networks
CN106357772A (en) * 2016-09-20 2017-01-25 深圳市赛格导航科技股份有限公司 Vehicle-mounted wireless communication system and method
CN113810349A (en) * 2020-06-17 2021-12-17 腾讯科技(深圳)有限公司 Data transmission method and device and computer equipment

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104566783A (en) * 2014-12-05 2015-04-29 广东志高空调有限公司 Air conditioner control method and air conditioner control system
US20180288179A1 (en) * 2017-04-03 2018-10-04 Randeep S. Bhatia Proxy for serving internet-of-things (iot) devices
CN110719248B (en) * 2018-07-12 2021-08-17 中移(杭州)信息技术有限公司 Method and device for forwarding user datagram protocol message
CN109495258B (en) * 2018-12-19 2022-05-13 天翼数字生活科技有限公司 Method and device for decrypting monitoring data, computer equipment and storage medium
CN112243002B (en) * 2020-10-10 2023-07-04 腾讯科技(深圳)有限公司 Data forwarding method, device, electronic equipment and computer readable medium
CN112637344A (en) * 2020-12-23 2021-04-09 苏州三六零智能安全科技有限公司 Monitoring method, equipment and device of Internet of things equipment and storage medium
CN114244886B (en) * 2021-11-22 2024-04-30 北京小米移动软件有限公司 Device control method, device control apparatus, and storage medium

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20060256771A1 (en) * 2005-05-12 2006-11-16 Yahoo! Inc. Proxy server for relaying VOIP messages
CN102088460A (en) * 2010-12-29 2011-06-08 北京新媒传信科技有限公司 Method, device and system for transmitting streaming media data in restricted networks
CN106357772A (en) * 2016-09-20 2017-01-25 深圳市赛格导航科技股份有限公司 Vehicle-mounted wireless communication system and method
CN113810349A (en) * 2020-06-17 2021-12-17 腾讯科技(深圳)有限公司 Data transmission method and device and computer equipment

Also Published As

Publication number Publication date
CN114902635A (en) 2022-08-12

Similar Documents

Publication Publication Date Title
US8452008B2 (en) Content distributing method, apparatus and system
US7376831B2 (en) Selectively encrypting different portions of data sent over a network
US8364772B1 (en) System, device and method for dynamically securing instant messages
WO2021104408A1 (en) Key agreement method and electronic device
WO2012100677A1 (en) Identity management method and device for mobile terminal
WO2023184262A1 (en) Secure transmission method and apparatus for data frames, electronic device and storage medium
CN111428225A (en) Data interaction method and device, computer equipment and storage medium
US10218681B2 (en) Home network controlling apparatus and method to obtain encrypted control information
WO2014135050A1 (en) Message processing method, device, gateway, set-top box and internet protocol television system
WO2020020007A1 (en) Network access method and device, terminal, base station, and readable storage medium
US11770709B2 (en) Network services in a mesh network
WO2020237880A1 (en) Data exchange method based on asymmetric encryption technology, sending terminal and computer readable storage medium
WO2023184264A1 (en) Traffic proxy methods and apparatuses, electronic device and storage medium
US20220294771A1 (en) Secure Virtual Personalized Network
CN112769868A (en) Communication method, communication device, electronic device and storage medium
WO2023184263A1 (en) Method and apparatus for establishing user datagram protocol (udp) transmission channel
WO2017067330A1 (en) An apparatus and method for configuration management of a wireless access point
WO2009132551A1 (en) Obtaining method of the meida stream key, session equipment and key management function entity
JP7366115B2 (en) Delivering notifications to mobile devices
US20220407689A1 (en) Key sharing for media frames using blockchain
CN112333088B (en) Compatible instant messaging transmission method
CN114928459A (en) Connection method and computer readable medium for private communication architecture
CN115622715B (en) Distributed storage system, gateway and method based on token
WO2005057845A1 (en) The safe verify method between the manager and the proxy in network transmission
CN116264525A (en) Remote access with man-in-the-middle attack prevention

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22934115

Country of ref document: EP

Kind code of ref document: A1