WO2023185823A1 - Remote communication methods for industrial device, apparatuses and devices - Google Patents

Remote communication methods for industrial device, apparatuses and devices Download PDF

Info

Publication number
WO2023185823A1
WO2023185823A1 PCT/CN2023/084356 CN2023084356W WO2023185823A1 WO 2023185823 A1 WO2023185823 A1 WO 2023185823A1 CN 2023084356 W CN2023084356 W CN 2023084356W WO 2023185823 A1 WO2023185823 A1 WO 2023185823A1
Authority
WO
WIPO (PCT)
Prior art keywords
data packet
address
local area
area network
edge device
Prior art date
Application number
PCT/CN2023/084356
Other languages
French (fr)
Chinese (zh)
Inventor
李林
Original Assignee
阿里巴巴(中国)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 阿里巴巴(中国)有限公司 filed Critical 阿里巴巴(中国)有限公司
Publication of WO2023185823A1 publication Critical patent/WO2023185823A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network
    • H04L67/1001Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
    • H04L67/1004Server selection for load balancing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02PCLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
    • Y02P90/00Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
    • Y02P90/02Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]

Definitions

  • the present application relates to the field of cloud computing technology, and in particular to a remote communication method, device and equipment for industrial equipment.
  • Embodiments of the present application provide a remote communication method, device and equipment for industrial equipment, in order to improve the security of remote communication of industrial equipment.
  • embodiments of the present application provide a remote communication method for industrial equipment, which is applied to an edge device.
  • the edge device implements a communication connection with at least one industrial device in a first local area network, including: through a virtual private network (Virtual Private Network) , VPN) channel, obtain the first data packet from the terminal device, the first data packet includes a destination address, and the destination address in the first data packet is the Internet Protocol (Internet Protocol) of the target industrial equipment in the first local area network. Protocol, IP) address, the target industrial device is one of the at least one industrial device; send the first data packet to the target industrial device.
  • VPN Virtual Private Network
  • IP Internet Protocol
  • embodiments of the present application provide a remote communication method for industrial equipment, applied to a VPN server, including: sending first configuration information to an edge device, the first configuration information carrying information about a network segment of a second local area network, the The network segment of the second LAN is the LAN used for communication through the VPN channel; the first data packet from the terminal device is forwarded to the edge device.
  • the first data packet includes a source address and a destination address.
  • the source address is the IP address of the terminal device in the second LAN
  • the destination address in the first data packet is the IP address of the target industrial equipment in the first LAN
  • the target industrial equipment is in the first LAN
  • embodiments of the present application provide a remote communication method for industrial equipment, applied to terminal equipment, including: Send a first data packet to the edge device through the VPN channel.
  • the first data packet includes a source address and a destination address.
  • the source address in the first data packet is the IP address of the terminal device in the second local area network.
  • the third data packet includes a source address and a destination address.
  • the destination address in a data packet is the IP address of a target industrial device in the first local area network, and the target industrial device is one of at least one industrial device that communicates with the edge device in the first local area network; through the VPN channel , receiving the second data packet sent by the edge device.
  • inventions of the present application provide an edge device that implements communication connections with at least one industrial device in a first local area network.
  • the edge device includes: an acquisition unit configured to acquire from In the first data packet of the terminal device, the first data packet includes a destination address.
  • the destination address in the first data packet is the Internet Protocol IP address of the target industrial device in the first local area network.
  • the target industrial device is One of at least one industrial device; a transceiver unit, configured to send the first data packet to the target industrial device.
  • a server including: a transceiver unit configured to send first configuration information to an edge device.
  • the first configuration information carries information about a network segment of a second local area network.
  • the network segment of the second local area network Segment is the local area network used for communication through the VPN channel;
  • the transceiver unit is also used to forward the first data packet from the terminal device to the edge device.
  • the first data packet includes a source address and a destination address.
  • the first data packet The source address in is the IP address of the terminal device in the second local area network, and the destination address in the first data packet is the IP address of the target industrial equipment in the first local area network, and the target industrial equipment is in the first local area network.
  • a terminal device including: a transceiver unit configured to send a first data packet to an edge device through a VPN channel.
  • the first data packet includes a source address and a destination address.
  • the first data packet The source address in the packet is the IP address of the terminal device in the second local area network.
  • the destination address in the first data packet is the IP address of the target industrial equipment in the first local area network.
  • the target industrial equipment is in the first local area network.
  • One of at least one industrial device that implements communication connection with the edge device; the transceiver unit is also used to receive the second data packet sent by the edge device through the VPN channel.
  • embodiments of the present application provide an electronic device, including: at least one processor and a memory; the memory stores computer execution instructions; the at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor Perform a method as provided in the first aspect, the second aspect or the third aspect.
  • embodiments of the present application provide a computer-readable storage medium.
  • Computer-executable instructions are stored in the computer-readable storage medium.
  • the processor executes the computer-executable instructions, the implementation of the first aspect, the second aspect, or The method provided by the third aspect.
  • embodiments of the present application provide a computer program product, which includes computer instructions.
  • the computer instructions are executed by a processor, the method provided in the first aspect, the second aspect, or the third aspect is implemented.
  • encrypted communication is performed between the edge device and the terminal device through a VPN channel, and then the edge device sends the first data packet sent by the terminal device to the target industrial device in the first LAN.
  • the edge device When exposed to the public network, communication between terminal devices and edge devices is realized, improving the security of remote communication of industrial equipment.
  • Figure 1 is a schematic diagram of a remote communication scenario 100 of industrial equipment provided by an embodiment of the present application
  • Figure 2 is a schematic interactive flow diagram of a remote communication method 200 for industrial equipment provided by an embodiment of the present application
  • Figure 3 is a schematic interactive flow diagram of a remote communication method 300 for industrial equipment provided by an embodiment of the present application
  • Figure 4 is a schematic block diagram of an electronic device 400 provided by an embodiment of the present application.
  • Figure 5 is a schematic structural diagram of an electronic device 500 provided by an embodiment of the present application.
  • Figure 6 is a schematic structural diagram of a cloud server 600 provided by an exemplary embodiment of the present application.
  • Industry is a material-generating industry that mines and collects natural resources and processes various raw materials. This can generally include, but is not limited to, light industry, heavy industry and chemical industry.
  • Light industry may include but is not limited to: light industry using agricultural products as raw materials, such as food manufacturing, tobacco processing, textiles, papermaking, printing, etc.; light industry using non-agricultural products as raw materials, such as cultural, educational and sporting goods, chemical manufacturing, synthetic fiber manufacturing, and daily necessities Manufacturing, hand tool manufacturing, medical device manufacturing, etc.
  • Heavy industry can include, but is not limited to, energy mining, metal smelting and processing, cement processing, electricity, etc.
  • the chemical industry can include, but is not limited to, plastic and rubber products, coatings, chemical waste treatment, etc.
  • the industrial equipment in the embodiments of the present application can be applied to any of the above-mentioned industrial fields to achieve industrial production or maintenance.
  • Industrial equipment includes but is not limited to Computerized Numerical Control Machine (CNC)
  • industrial equipment In the current implementation of industrial automation, industrial equipment is often controlled through industrial control devices to achieve industrial production or maintenance. It should be understood that the industrial control device here may be independent of the industrial equipment, or may be integrated with the industrial equipment. When industrial equipment is integrated with industrial control devices, the industrial equipment can be called industrial control equipment (abbreviated as industrial control equipment).
  • the industrial control device may be, for example, a programmable logic controller (PLC).
  • the edge device and the remote terminal equipment communicate through VPN, and then the edge device communicates with the industrial control device in the first LAN.
  • the IP of the industrial control device does not need to be exposed to the public network to achieve communication with the remote terminal device.
  • FIG. 1 is a schematic diagram of a remote communication scenario 100 of industrial equipment provided by an embodiment of the present application.
  • the edge device 110 and at least one industrial device 120 implement communication connections within the first local area network.
  • the edge device 110 can be implemented as a gateway.
  • the industrial equipment 120 can be implemented as the above-mentioned industrial control equipment, or the industrial equipment 120 Can be replaced by the above industrial control devices.
  • the edge device 110 and the terminal device 130 are connected through a virtual private network (Virtual Private Network, VPN) channel.
  • VPN Virtual Private Network
  • VPN is a private network established on a public network.
  • the VPN channel can realize encrypted communication between the edge device 110 and the terminal device 130.
  • a VPN channel can be established between the edge device 110 and the terminal device 130 through the VPN server 140, and communication between the edge device 110 and the terminal device 130 is implemented based on the forwarding of the VPN server 140.
  • the terminal device 130 and the edge device 110 pass A second LAN can be used for VPN channel communication.
  • the VPN server 140 can be integrated into the terminal device 130 or the edge device 110 in the form of a functional module, which is not limited in this application.
  • the VPN server 140 can be implemented as an ordinary server, a server cluster, or a cloud server or a server cluster.
  • the number of terminal devices 130 may be one or more, and this application does not limit this.
  • the multiple terminal devices 130 can communicate with the edge device 110 through the VPN server 140.
  • the multiple terminal devices 130 can be in the same local area network (such as the second local area network above) Encrypted communication is performed with the edge device 110, and the IP addresses of the multiple terminal devices 130 all belong to the network segment of the second local area network.
  • the edge device 110 may forward the received data packet from the terminal device 130 to at least one of the industrial devices 120, or may forward the received data packet from the industrial device 120 to the terminal device 130 to implement the terminal device Communication between 130 and industrial equipment 120.
  • a VPN client is deployed in both the edge device 110 and the terminal device 130; a VPN server is deployed in the VPN server 140.
  • first and second in the above-mentioned first LAN and second LAN are used to distinguish different LANs. They do not represent the order, nor do they limit the types of the first LAN and the second LAN.
  • the method provided by the embodiment of the present application is described in detail by taking the interaction between terminal equipment, edge equipment, and industrial equipment as an example.
  • the terminal device may be, for example, the terminal device 130 in FIG. 1
  • the edge device may be, for example, the edge device 110 in FIG. 1
  • the industrial device may be, for example, the industrial device 120 in FIG. 1 .
  • a VPN server also participates in the interaction to implement the method provided by the embodiments of this application.
  • the VPN server may be, for example, the VPN server 140 in Figure 1 .
  • the terminal device shown in the following embodiments can also be replaced with components in the terminal device, such as a chip, a chip system, or other functional modules that can call and execute programs.
  • the edge device can also be replaced with components in the edge device. , such as chips, chip systems or other functional modules that can call and execute programs.
  • Industrial equipment can also be replaced by components in the industrial equipment, such as chips, chips System or other functional modules that can call and execute programs.
  • the VPN server can be replaced by components in the VPN server, such as chips, chip systems, or other functional modules that can call and execute programs.
  • FIG. 2 is a schematic interactive flow diagram of a remote communication method 200 for industrial equipment provided by an embodiment of the present application. As shown in Figure 2, the method 200 includes some or all of the following processes:
  • S210 The terminal device sends the first data packet to the edge device through the VPN channel.
  • the edge device obtains the first data packet from the terminal device through the VPN channel.
  • S220 The edge device sends the first data packet to the target industrial device.
  • the first data packet at least includes a destination address
  • the destination address in the first data packet is the IP address of the target industrial device in the first local area network.
  • the industrial equipment and the edge device realize communication connection in the first local area network
  • the target industrial equipment can be any one of the at least one industrial equipment that realizes communication connection with the edge device in the first local area network
  • the terminal device passes The destination address in the first packet indicates the destination industrial device.
  • the edge device sends the first data packet to the target industrial device indicated by the destination address in the first data packet.
  • the edge device and the target industrial device may communicate through the first LAN based on their IP addresses in the first LAN.
  • the data in the first data packet can be used to control or maintain the target industrial equipment.
  • the number of target industrial equipment may be one or more, and this application does not limit this.
  • the terminal device can send the first data packet corresponding to each target industrial device to the edge device, and then the edge device forwards each first data packet to the corresponding target industrial device.
  • the first data packet may also include a source address.
  • the source address in the first data packet may be used as the destination address.
  • the source address in the first data packet is the IP address of the terminal device in the second LAN, that is, the virtual IP address under the VPN. In this case, the target industrial equipment connected to the first LAN cannot transmit the second data.
  • the packet is sent to the terminal device.
  • the edge device in order to ensure that after sending the first data packet to the target industrial device, the edge device can forward the second data packet from the target industrial device to the terminal device, the edge device may forward the first data packet before forwarding the first data packet. Modify the source address in the first data packet to the IP address of the edge device in the first LAN, and then send the modified data packet to the target industrial device, so that the target industrial device can identify the IP address of the edge device in the first LAN. The IP address is used as the destination address to send the second data packet.
  • the modification of the source address in the first data packet by the edge device may include the following possible implementations: after receiving the first data packet sent by the terminal device, the edge device may determine whether the first data packet comes from the VPN channel. For example, the edge device determines whether it belongs to the network segment of the second LAN based on the network segment to which the source address in the first data packet belongs. If the network segment to which the source address in the first data packet belongs belongs to the network segment of the second LAN, then the The first packet comes from The VPN channel, or the terminal device sends the first data packet through the VPN client. In this case, the edge device can modify the source address in the first data packet.
  • the network segment of the second LAN is 192.168.40.x
  • the source address in the first data packet is 192.168.40.4.
  • the edge device determines that the source address in the first data packet belongs to the network segment of the second LAN, and then modifies the The source address in the first packet.
  • the edge device can modify the source address in the first data packet to the IP address of the edge device in the second LAN according to the preconfigured Source Network Address Translation (SNAT) entry.
  • SNAT Source Network Address Translation
  • the SNAT entry can be understood as a SNAT policy, which can include the edge device in the first The mapping relationship between the IP address in the LAN and the network segment of the second LAN.
  • TCP Transmission Control Protocol
  • IP IP
  • the edge device modifies the source address in the first data packet, which is only an example and not a limiting explanation.
  • the edge device may also add the edge device's IP address within the first local area network as an additional source address to the first data packet.
  • Modifying the source address in the first data packet based on SNAT is also just an example and not a limiting explanation.
  • the edge device can be based on the preset network segment of the second LAN, and the edge device can be on the first LAN.
  • the mapping relationship between IP addresses is modified to modify the source address in the first packet.
  • the method 200 further includes the following steps S230 and S240.
  • S230 The target industrial device sends the second data packet to the edge device.
  • the edge device receives the second data packet sent by the target industrial device.
  • S240 The edge device sends the second data packet to the terminal device through the VPN channel.
  • the terminal device receives the second data packet through the VPN channel.
  • the above-mentioned process of transmitting the first data packet and the process of transmitting the second data packet may overlap in time.
  • the edge device forwards the first data packet sent by the terminal device to the target industrial device, it also forwards the target industrial device to the target industrial device.
  • the second data packet sent by the industrial equipment is forwarded to the terminal device; or the above-mentioned process of transmitting the first data packet and the process of transmitting the second data packet may not overlap in time.
  • the second data packet is based on the data in the first data packet.
  • the edge device can forward the first data packet from the terminal device to the target industrial device, and then forward the second data packet from the target industrial device to the terminal device. This application does not limit this.
  • the second data packet may include a destination address, a source address and data.
  • the destination address of the second data packet may be the source address of the received first data packet, and the source address of the second data packet may be the destination address of the received first data packet.
  • the destination address of the second data packet may be the IP address of the edge device in the first local area network, and the source address of the second data packet may be the IP address of the target industrial device in the first local area network.
  • the target industrial equipment transmits the second data packet within the first local area network.
  • the edge device After receiving the second data packet sent by the target industrial equipment, the edge device can modify the destination address in the second data packet to the IP address of the terminal device in the second LAN, and then forward the second data packet to end terminal equipment. For example, when the edge device modifies the source address of the first data packet, it can retain the source address modification record of the first data packet.
  • the source address modification record of the first data packet can at least include the original source address of the first data packet. (i.e., the IP address of the terminal device in the second LAN) and the destination address (i.e., the IP address of the target industrial device in the first LAN). Furthermore, the edge device can modify the record and the second data according to the source address of the first data packet.
  • the source address of the packet (that is, the IP address of the target industrial device in the first LAN), and the destination address of the second data packet is modified to the IP address of the terminal device in the second LAN.
  • the edge device can When the source address is consistent with the destination address in the source address modification record of the first data packet, the destination address of the second data packet is modified to the IP address of the terminal device in the third LAN.
  • the edge device may send the second data packet to the terminal device through the VPN channel based on the IP address of the terminal device in the second local area network.
  • the edge device receives the second data packet sent by the target industrial device through the first LAN, and sends the second data packet to the terminal device through the VPN channel, without exposing the industrial device to the public network. It improves the communication between terminal devices and edge devices and improves the security of remote communication of industrial equipment.
  • the VPN channel in the above embodiment may be a network channel established and implemented based on the VPN server. The following is explained in conjunction with Figure 3.
  • FIG. 3 is a schematic interactive flow diagram of a remote communication method 300 for industrial equipment provided by an embodiment of the present application.
  • the method 300 may include some or all of the following processes:
  • the VPN server may obtain the second client configuration request.
  • the VPN server obtains the second client configuration request input by the user.
  • the second client configuration request is used to request to configure a VPN environment corresponding to at least one terminal device.
  • the second client configuration request may carry the number and/or identification of the terminal devices.
  • the VPN server may determine the network segment of the second local area network and the VPN certificate corresponding to each terminal device.
  • the VPN server carries the information of the network segment of the second LAN and at least one VPN certificate respectively in at least one third configuration information, or carries the IP address and one VPN certificate of the network segment belonging to the second LAN in a third party. configuration information.
  • the second method allows the terminal device to determine its own IP address from the third configuration information without requiring the terminal device to determine the IP address from the network segment of the second LAN. own IP address.
  • the VPN server can send the third configuration information to the terminal device.
  • the VPN server can send multiple third configuration information to the corresponding terminals respectively. equipment.
  • the terminal device can determine its own IP address in the second local area network based on the third configuration information, and install the certificate, thereby completing the configuration of the VPN environment.
  • the server deployed in the VPN server can be set to bridge (TAP) mode so that the server can be implemented as a Secure Sockets Layer (SSL) server.
  • the client deployed in the terminal device may be an SSL client.
  • the VPN server receives the first client configuration request sent by the edge device.
  • the first client The configuration request is used to request the VPN server to send second configuration information.
  • the first client configuration request may be sent by the edge device when it is powered on for the first time.
  • the first client configuration request may also be sent by the edge device in response to user input. The request sent by the command.
  • the second configuration information may include: at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction.
  • the edge device can install the VPN client by running the VPN client installation package in the second configuration information; the edge device can install the VPN certificate in the second configuration information; the edge device can also respond to the VPN client in the second configuration information.
  • the VPN start command starts the VPN client.
  • edge devices need to configure SNAT entries.
  • the edge device may configure the SNAT entry according to the network segment of the second LAN to establish a mapping relationship between the network segment of the second LAN and the IP address of the edge device in the first LAN.
  • the network segment of the second LAN may be preset in the edge device, or the edge device may receive a message sent by the VPN server.
  • the VPN server determines the network segment of the second LAN in response to the second client configuration request, carries the network segment information of the second LAN in the first configuration information, and sends it to the edge device.
  • data transmission on the VPN channel can be realized between the terminal device and the edge device through the VPN server.
  • the terminal device can send a first data packet to the VPN server, and the VPN server forwards the first data packet sent by the terminal device to the edge device, so that the terminal device sends the first data to the edge device through the VPN channel; and/or the edge
  • the device sends the second data packet to the VPN server, and the VPN server forwards the received second data packet to the terminal device, so that the edge device sends the second data packet to the terminal device through the VPN channel.
  • communication between the edge device and the target industrial device is still implemented through the first local area network.
  • the implementation method can be referred to the communication method between the edge device and the target industrial device in any of the above embodiments.
  • the edge device modifies the source address in the first data packet to the IP address of the edge device in the first LAN, it sends the first data packet to the target industrial device.
  • the edge device receives the third packet sent by the target industrial device. After receiving the second data packet, modify the destination address in the second data packet to the IP address of the terminal device in the second LAN and then send it to the terminal device through the VPN channel.
  • FIG. 4 is a schematic block diagram of an electronic device 400 provided by an embodiment of the present application.
  • the electronic device 300 can be implemented as an execution subject in the above method embodiment, such as an edge device, a VPN server or a terminal device.
  • the electronic device 400 at least includes a transceiver unit 410.
  • the electronic device 400 may also include an acquisition unit 420 and/or a processing unit 430.
  • the electronic device 400 may correspond to the edge device in the above method embodiment, for example, it may be an implementation of the edge device, or a component (such as a chip or chip system) configured in the edge device.
  • the obtaining unit 420 can be used to obtain the first data packet from the terminal device through the virtual private network VPN channel, the first data packet includes a destination address, and the destination address in the first data packet is the target industrial device in the The Internet Protocol IP address in the first local area network, the target industrial device is one of the at least one industrial device; the transceiver unit 410 is used to send the first data packet to the target industrial device.
  • the first data packet further includes a source address.
  • the source address in the first data packet is the IP address of the terminal device in a second local area network.
  • the second local area network is used for communication through a VPN channel.
  • the local area network; the transceiver unit 410 is specifically configured to: modify the source address in the first data packet to the IP address of the edge device in the first local area network; and send the first data packet to the target industrial device.
  • the transceiver unit 410 is specifically configured to: when the source address in the first data packet belongs to the network segment of the second LAN, convert the SNAT entry according to the preconfigured source network address, and convert the first The source address in the data packet is modified to the IP address of the edge device in the second LAN, and the SNAT entry is used to indicate that the source address of the network segment belonging to the second LAN is modified to the IP address of the edge device.
  • the transceiver unit 420 is further configured to: receive first configuration information sent by the VPN server, where the first configuration information carries information about the network segment of the second local area network; and the processing unit 430 is configured to receive the first configuration information according to the first configuration information. Configuration information, configure the SNAT entry.
  • the obtaining unit 420 is specifically configured to: receive the first data packet forwarded by the VPN server.
  • the transceiver unit 410 is also used to receive the second data packet sent by the target industrial device.
  • the second data packet includes a source address and a destination address.
  • the destination in the second data packet The address is the IP address of the edge device in the first LAN;
  • the processing unit 430 is also configured to modify the record according to the source address of the first data packet and the source address of the second data packet, and modify the destination of the second data packet.
  • the address is modified to the IP address of the terminal device in the second local area network; the transceiver unit 410 is also used to send the second data packet to the terminal device through the VPN channel.
  • the transceiver unit 410 is also configured to receive second configuration information sent by the VPN server, where the second configuration information carries at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction; process Unit 430 is also used to configure the VPN environment according to the second configuration information to build the VPN channel.
  • the transceiver unit 410 before receiving the second configuration information sent by the VPN server, the transceiver unit 410 It is also used to send a first client configuration request to the VPN server when it is powered on for the first time.
  • the first client configuration request is used to request the VPN server to send the second configuration information.
  • the electronic device 400 may correspond to the VPN server in the above method embodiment, for example, it may be an implementation of the VPN server, or a component (such as a chip or chip system) configured in the VPN server.
  • the transceiver unit 410 may be configured to: send first configuration information to the edge device, where the first configuration information carries information about a network segment of a second local area network, and the network segment of the second local area network is a local area network used when communicating through a VPN channel. ; Forward the first data packet from the terminal device to the edge device.
  • the first data packet includes a source address and a destination address.
  • the source address in the first data packet is the IP of the terminal device in the second local area network.
  • Address, the destination address in the first data packet is the IP address of the target industrial device in the first local area network, and the target industrial device is one of at least one industrial device that communicates with the edge device in the first local area network.
  • the transceiver unit 410 is further configured to send second configuration information to the edge device, where the second configuration information carries at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction.
  • the transceiver unit 410 is also configured to: receive a first client configuration request sent by the edge device when it is powered on for the first time.
  • the first client configuration request is used to request the VPN server to send the second configuration information. .
  • the obtaining unit 420 is used to obtain a second client configuration request
  • the second client request is used to request the configuration of a VPN environment corresponding to at least one terminal device
  • the processing unit 430 is used to obtain a VPN environment corresponding to at least one terminal device according to the second client request.
  • a terminal configuration request is generated to generate the first configuration information and/or at least one third configuration information respectively corresponding to the at least one terminal device.
  • the third configuration information includes the network segment of the second LAN and/or the VPN corresponding to the terminal device.
  • the certificate; transceiving unit 410 is also configured to send the third configuration information to the at least one terminal device respectively.
  • the VPN server is configured in bridge mode.
  • the electronic device 400 may correspond to the terminal device in the above method embodiment, and may be, for example, an implementation of the terminal device, or a component (such as a chip or chip system) configured in the terminal device.
  • the transceiver unit 410 may be configured to: send a first data packet to the edge device through the VPN channel, the first data packet includes a source address and a destination address, and the source address in the first data packet is the terminal device in the third. 2. IP addresses in the local area network.
  • the destination address in the first data packet is the IP address of the target industrial device in the first local area network.
  • the target industrial device is at least one industrial device that communicates with the edge device in the first local area network. One of the devices; receives the second data packet sent by the edge device through the VPN channel.
  • FIG. 5 is a schematic structural diagram of an electronic device 500 provided by an embodiment of the present application.
  • the electronic device 500 shown in Figure 5 can be implemented as a terminal device, an edge device or a VPN server, and is used to implement the steps performed by the terminal device, edge device or VPN server in the above method embodiment.
  • the electronic device 500 includes a processor 520, and the processor 520 can call and run a computer program from the memory to implement the method in the embodiment of the present application.
  • the electronic device 500 may also include a memory 530 .
  • the processor 520 can call and run the computer program from the memory 530 to implement the method in the embodiment of the present application.
  • the memory 530 may be a separate device independent of the processor 520 , or may be integrated into the processor 520 .
  • the electronic device 500 may also include a transceiver 510, and the processor 520 may control the transceiver 510 to communicate with other devices, specifically, may send information or data to other devices, or Receive information or data from other devices.
  • the transceiver 510 may include a transmitter and a receiver.
  • the transceiver 510 may further include an antenna, and the number of antennas may be one or more.
  • the electronic device 500 can implement the corresponding processes of each method on the terminal device, edge device or VPN server side in the embodiments of this application. For the sake of brevity, details are not repeated here.
  • FIG. 6 is a schematic structural diagram of a cloud server 600 provided by an exemplary embodiment of the present application.
  • the cloud server 600 may be an implementation of the VPN server in the above method embodiment.
  • the VPN server 600 includes: a memory 610 and a processor 620 .
  • Memory 610 is used to store computer programs and may be configured to store various other data to support operations on the VPN server.
  • the storage 610 may be an object storage (Object Storage Service, OSS).
  • the processor 620 is coupled to the memory 610 and is used to execute the computer program in the memory 610 to implement the method implemented by the VPN server in the above method embodiment.
  • the VPN server also includes: a firewall 630, a load balancer 640, a communication component 650, a power supply component 660 and other components. Only some components are schematically shown in Figure 6, which does not mean that the VPN server only includes the components shown in Figure 6.
  • VPN server 500 shown in Figure 6 can implement various processes related to the VPN server in the above method embodiment.
  • the operations and/or functions of each module in the VPN server 500 are respectively intended to implement the corresponding processes in the above method embodiments.
  • This application also provides a processing device, including at least one processor, the at least one processor is used to execute a computer program stored in the memory, so that the processing device executes the terminal device, edge device or VPN in the above method embodiment.
  • An embodiment of the present application also provides a processing device, including a processor and an input and output interface.
  • the input and output interface is coupled to the processor.
  • the input and output interface is used to input and/or output information.
  • the information includes at least one of instructions and data.
  • the processor is used to execute a computer program, so that the processing device executes the method executed by the terminal device, edge device or VPN server in the above method embodiment.
  • An embodiment of the present application also provides a processing device, including a processor and a memory.
  • the memory is used to store a computer program
  • the processor is used to call and run the computer program from the memory, so that the processing device performs the method performed by the terminal device, edge device or VPN server in the above method embodiment.
  • the above-mentioned processing device may be one or more chips.
  • the processing device may be a field programmable gate array (FPGA) or an application specific integrated chip (application specific integrated circuit (ASIC), system on chip (SoC), central processor unit (CPU), network processor (NP), or digital signal
  • the processing circuit digital signal processor, DSP
  • each step of the above method can be completed by instructions in the form of hardware integrated logic circuits or software in the processor.
  • the steps of the methods disclosed in conjunction with the embodiments of the present application can be directly implemented by a hardware processor for execution, or can be executed by a combination of hardware and software modules in the processor.
  • the software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
  • the processor in the embodiment of the present application may be an integrated circuit chip with signal processing capabilities.
  • each step of the above method embodiment can be completed through an integrated logic circuit of hardware in the processor or instructions in the form of software.
  • the above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
  • DSP digital signal processor
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • a general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
  • the steps of the method disclosed in conjunction with the embodiments of the present application can be directly implemented by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor.
  • the software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
  • non-volatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable programmable read-only memory (erasable PROM, EPROM), electrically removable memory. Erase electrically programmable read-only memory (EPROM, EEPROM) or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache.
  • RAM random access memory
  • RAM static random access memory
  • DRAM dynamic random access memory
  • SDRAM synchronous dynamic random access memory
  • double data rate SDRAM double data rate SDRAM
  • DDR SDRAM double data rate SDRAM
  • ESDRAM enhanced synchronous dynamic random access memory
  • SLDRAM synchronous link dynamic random access memory
  • direct rambus RAM direct rambus RAM
  • the present application also provides a computer program product.
  • the computer program product includes: computer program code.
  • the computer program code When the computer program code is run on a computer, it causes the computer to execute the steps in the above method embodiment. The method performed by the end device, edge device or VPN server.
  • the present application also provides a computer-readable storage medium.
  • the computer-readable storage medium stores program code.
  • the program code When the program code is run on a computer, it causes the computer to execute the above method embodiment.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

Provided in the present application are remote communication methods for an industrial device, apparatuses and devices A method comprises: an edge device acquiring a first data packet from a terminal device via a VPN channel, the first data packet comprising a destination address, the destination address in the first data packet being an IP address of a target industrial device in a first local area network, and the target industrial device being one of at least one industrial device, and sending the first data packet to the target industrial device. Without exposing an industrial device to a public network, communication between a terminal device and an edge device is achieved, so that the security of remote communication of the industrial device is improved.

Description

工业设备的远程通信方法、装置以及设备Remote communication methods, devices and equipment for industrial equipment
本申请要求于2022年03月30日提交中国专利局、申请号为202210334472.5、申请名称为“工业设备的远程通信方法、装置以及设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims priority to the Chinese patent application filed with the China Patent Office on March 30, 2022, with the application number 202210334472.5 and the application title "Remote communication method, device and equipment for industrial equipment", the entire content of which is incorporated by reference. in this application.
技术领域Technical field
本申请涉及云计算技术领域,尤其涉及一种工业设备的远程通信方法、装置以及设备。The present application relates to the field of cloud computing technology, and in particular to a remote communication method, device and equipment for industrial equipment.
背景技术Background technique
在一些工业制造场景中,需要通过终端设备远程控制各工业控制器件,以实现对工业设备的控制。目前,终端设备和工业设备之间的远程通信方案,需要通过路由器以端口映射的方式将工业设备暴露在公网中,以建立远程的终端设备与工业设备之间的通信链路。此种情况下,为工业生成、维护带来较大的安全隐患。因此,如何实现工业设备的远程通信,以确保工业设备远程通信的安全性,是当前亟待解决的问题。In some industrial manufacturing scenarios, various industrial control devices need to be remotely controlled through terminal devices to control industrial equipment. Currently, the remote communication solution between terminal equipment and industrial equipment requires the industrial equipment to be exposed to the public network through port mapping through a router to establish a communication link between the remote terminal equipment and industrial equipment. In this case, it brings great safety risks to industrial production and maintenance. Therefore, how to realize remote communication of industrial equipment to ensure the security of remote communication of industrial equipment is an issue that needs to be solved urgently.
发明内容Contents of the invention
本申请实施例提供的一种工业设备的远程通信方法、装置以及设备,以期提高工业设备远程通信的安全性。Embodiments of the present application provide a remote communication method, device and equipment for industrial equipment, in order to improve the security of remote communication of industrial equipment.
第一方面,本申请实施例提供一种工业设备的远程通信方法,应用于边缘设备,该边缘设备与至少一个工业设备在第一局域网内实现通信连接,包括:通过虚拟专用网络(Virtual Private Network,VPN)通道,获取来自于终端设备的第一数据包,该第一数据包包括目的地址,该第一数据包中的目的地址为目标工业设备在该第一局域网内的网际互联协议(Internet Protocol,IP)地址,该目标工业设备为该至少一个工业设备中的一个;将该第一数据包发送至该目标工业设备。In a first aspect, embodiments of the present application provide a remote communication method for industrial equipment, which is applied to an edge device. The edge device implements a communication connection with at least one industrial device in a first local area network, including: through a virtual private network (Virtual Private Network) , VPN) channel, obtain the first data packet from the terminal device, the first data packet includes a destination address, and the destination address in the first data packet is the Internet Protocol (Internet Protocol) of the target industrial equipment in the first local area network. Protocol, IP) address, the target industrial device is one of the at least one industrial device; send the first data packet to the target industrial device.
第二方面,本申请实施例提供一种工业设备的远程通信方法,应用于VPN服务器,包括:向边缘设备发送第一配置信息,该第一配置信息携带第二局域网的网段的信息,该第二局域网的网段为通过VPN通道进行通信时采用的局域网;向该边缘设备转发来自于终端设备的第一数据包,该第一数据包包括源地址和目的地址,该第一数据包中的源地址为该终端设备的在该第二局域网内的IP地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,该目标工业设备为在第一局域网内与该边缘设备实现通信连接的至少一个工业设备中的一个。In a second aspect, embodiments of the present application provide a remote communication method for industrial equipment, applied to a VPN server, including: sending first configuration information to an edge device, the first configuration information carrying information about a network segment of a second local area network, the The network segment of the second LAN is the LAN used for communication through the VPN channel; the first data packet from the terminal device is forwarded to the edge device. The first data packet includes a source address and a destination address. In the first data packet The source address is the IP address of the terminal device in the second LAN, the destination address in the first data packet is the IP address of the target industrial equipment in the first LAN, and the target industrial equipment is in the first LAN One of at least one industrial device that implements communication connection with the edge device.
第三方面,本申请实施例提供一种工业设备的远程通信方法,应用于终端设备,包括: 通过VPN通道,向边缘设备发送第一数据包,该第一数据包包括源地址和目的地址,该第一数据包中的源地址为该终端设备的在第二局域网内的IP地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,该目标工业设备为在第一局域网内与该边缘设备实现通信连接的至少一个工业设备中的一个;通过该VPN通道,接收该边缘设备发送的第二数据包。In the third aspect, embodiments of the present application provide a remote communication method for industrial equipment, applied to terminal equipment, including: Send a first data packet to the edge device through the VPN channel. The first data packet includes a source address and a destination address. The source address in the first data packet is the IP address of the terminal device in the second local area network. The third data packet includes a source address and a destination address. The destination address in a data packet is the IP address of a target industrial device in the first local area network, and the target industrial device is one of at least one industrial device that communicates with the edge device in the first local area network; through the VPN channel , receiving the second data packet sent by the edge device.
第四方面,本申请实施例提供一种边缘设备,该边缘设备与至少一个工业设备在第一局域网内实现通信连接,该边缘设备包括:获取单元,用于通过虚拟专用网络VPN通道,获取来自于终端设备的第一数据包,该第一数据包包括目的地址,该第一数据包中的目的地址为目标工业设备在该第一局域网内的网际互联协议IP地址,该目标工业设备为该至少一个工业设备中的一个;收发单元,用于将该第一数据包发送至该目标工业设备。In a fourth aspect, embodiments of the present application provide an edge device that implements communication connections with at least one industrial device in a first local area network. The edge device includes: an acquisition unit configured to acquire from In the first data packet of the terminal device, the first data packet includes a destination address. The destination address in the first data packet is the Internet Protocol IP address of the target industrial device in the first local area network. The target industrial device is One of at least one industrial device; a transceiver unit, configured to send the first data packet to the target industrial device.
第五方面,本申请实施例提供一种服务器,包括:收发单元,用于向边缘设备发送第一配置信息,该第一配置信息携带第二局域网的网段的信息,该第二局域网的网段为通过VPN通道进行通信时采用的局域网;该收发单元还用于向该边缘设备转发来自于终端设备的第一数据包,该第一数据包包括源地址和目的地址,该第一数据包中的源地址为该终端设备的在该第二局域网内的IP地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,该目标工业设备为在第一局域网内与该边缘设备实现通信连接的至少一个工业设备中的一个。In a fifth aspect, embodiments of the present application provide a server, including: a transceiver unit configured to send first configuration information to an edge device. The first configuration information carries information about a network segment of a second local area network. The network segment of the second local area network Segment is the local area network used for communication through the VPN channel; the transceiver unit is also used to forward the first data packet from the terminal device to the edge device. The first data packet includes a source address and a destination address. The first data packet The source address in is the IP address of the terminal device in the second local area network, and the destination address in the first data packet is the IP address of the target industrial equipment in the first local area network, and the target industrial equipment is in the first local area network. One of at least one industrial device that implements communication connection with the edge device.
第六方面,本申请实施例提供一种终端设备,包括:收发单元,用于通过VPN通道,向边缘设备发送第一数据包,该第一数据包包括源地址和目的地址,该第一数据包中的源地址为该终端设备的在第二局域网内的IP地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,该目标工业设备为在第一局域网内与该边缘设备实现通信连接的至少一个工业设备中的一个;该收发单元还用于通过该VPN通道,接收该边缘设备发送的第二数据包。In a sixth aspect, embodiments of the present application provide a terminal device, including: a transceiver unit configured to send a first data packet to an edge device through a VPN channel. The first data packet includes a source address and a destination address. The first data packet The source address in the packet is the IP address of the terminal device in the second local area network. The destination address in the first data packet is the IP address of the target industrial equipment in the first local area network. The target industrial equipment is in the first local area network. One of at least one industrial device that implements communication connection with the edge device; the transceiver unit is also used to receive the second data packet sent by the edge device through the VPN channel.
第七方面,本申请实施例提供一种电子设备,包括:至少一个处理器和存储器;该存储器存储计算机执行指令;该至少一个处理器执行该存储器存储的计算机执行指令,使得该至少一个处理器执行如第一方面、第二方面或第三方面提供的方法。In a seventh aspect, embodiments of the present application provide an electronic device, including: at least one processor and a memory; the memory stores computer execution instructions; the at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor Perform a method as provided in the first aspect, the second aspect or the third aspect.
第八方面,本申请实施例提供一种计算机可读存储介质,该计算机可读存储介质中存储有计算机执行指令,当处理器执行该计算机执行指令时,实现如第一方面、第二方面或第三方面提供的方法。In an eighth aspect, embodiments of the present application provide a computer-readable storage medium. Computer-executable instructions are stored in the computer-readable storage medium. When the processor executes the computer-executable instructions, the implementation of the first aspect, the second aspect, or The method provided by the third aspect.
第九方面,本申请实施例提供一种计算机程序产品,包括计算机指令,该计算机指令被处理器执行时实现第一方面、第二方面或第三方面提供的方法。In a ninth aspect, embodiments of the present application provide a computer program product, which includes computer instructions. When the computer instructions are executed by a processor, the method provided in the first aspect, the second aspect, or the third aspect is implemented.
在本申请实施例中,边缘设备与终端设备之间通过VPN通道进行加密通信,再由边缘设备在第一局域网中将终端设备发送的第一数据包发送至目标工业设备,在不将工业设备暴露于公网的情况下,实现了终端设备与边缘设备之间的通信,提高了工业设备的远程通信的安全性。 In the embodiment of this application, encrypted communication is performed between the edge device and the terminal device through a VPN channel, and then the edge device sends the first data packet sent by the terminal device to the target industrial device in the first LAN. When exposed to the public network, communication between terminal devices and edge devices is realized, improving the security of remote communication of industrial equipment.
附图说明Description of drawings
图1为本申请是实施例提供的一种工业设备的远程通信场景100的示意图;Figure 1 is a schematic diagram of a remote communication scenario 100 of industrial equipment provided by an embodiment of the present application;
图2为本申请实施例提供的一种工业设备的远程通信方法200的交互流程示意图;Figure 2 is a schematic interactive flow diagram of a remote communication method 200 for industrial equipment provided by an embodiment of the present application;
图3为本申请实施例提供的一种工业设备的远程通信方法300的交互流程示意图;Figure 3 is a schematic interactive flow diagram of a remote communication method 300 for industrial equipment provided by an embodiment of the present application;
图4为本申请实施例提供的一种电子设备400的示意性框图;Figure 4 is a schematic block diagram of an electronic device 400 provided by an embodiment of the present application;
图5为本申请实施例提供的一种电子设备500的示意性结构图;Figure 5 is a schematic structural diagram of an electronic device 500 provided by an embodiment of the present application;
图6为本申请示例性实施例提供的一种云服务器600的结构示意图。Figure 6 is a schematic structural diagram of a cloud server 600 provided by an exemplary embodiment of the present application.
具体实施方式Detailed ways
工业(industry)是对自然资源的开采、采集和对各种原材料进行加工的物质生成产业。通常可以包括但不限于轻工业、重工业和化工业。轻工业可以包括但不限于:以农产品为原料的轻工业,例如食品制造、烟草加工、纺织、造纸、印刷等;以非农产品为原料的轻工业,例如文教体育用品、化学药品制造、合成纤维制造、日用品制造、手工工具制造、医疗器械制造等。重工业可以包括但不限于能源开采、金属冶炼及加工、水泥加工、电力等。化工业可以包括但不限于塑料及橡胶制品、涂料、化学废料处理等。本申请实施例中的工业设备可应用于上述任一工业领域,以实现工业生产或维护。工业设备包括但不限于计算机数字控制机床(Computerised Numerical Control Machine,CNC)Industry is a material-generating industry that mines and collects natural resources and processes various raw materials. This can generally include, but is not limited to, light industry, heavy industry and chemical industry. Light industry may include but is not limited to: light industry using agricultural products as raw materials, such as food manufacturing, tobacco processing, textiles, papermaking, printing, etc.; light industry using non-agricultural products as raw materials, such as cultural, educational and sporting goods, chemical manufacturing, synthetic fiber manufacturing, and daily necessities Manufacturing, hand tool manufacturing, medical device manufacturing, etc. Heavy industry can include, but is not limited to, energy mining, metal smelting and processing, cement processing, electricity, etc. The chemical industry can include, but is not limited to, plastic and rubber products, coatings, chemical waste treatment, etc. The industrial equipment in the embodiments of the present application can be applied to any of the above-mentioned industrial fields to achieve industrial production or maintenance. Industrial equipment includes but is not limited to Computerized Numerical Control Machine (CNC)
在目前工业自动化的实现中,常通过工业控制器件对工业设备进行控制,以实现工业生产或维护。应理解,这里的工业控制器件可以独立于工业设备,或者可以集成于工业设备。当工业设备集成有工业控制器件时,该工业设备可称作工业控制设备(简称工控设备)。工业控制器件例如可以是可编程逻辑控制器(Programmable Logic Controller,PLC)。In the current implementation of industrial automation, industrial equipment is often controlled through industrial control devices to achieve industrial production or maintenance. It should be understood that the industrial control device here may be independent of the industrial equipment, or may be integrated with the industrial equipment. When industrial equipment is integrated with industrial control devices, the industrial equipment can be called industrial control equipment (abbreviated as industrial control equipment). The industrial control device may be, for example, a programmable logic controller (PLC).
为便于说明,下文将以工业控制器件集成于工业设备为例。For ease of explanation, the following takes an industrial control device integrated into industrial equipment as an example.
针对目前工业制造场景中,通过路由器将工业设备暴露在公网中以实现对工业设备的远程通信,导致工业设备的远程通信安全性差的问题,本申请实施例中,边缘设备与远程的终端设备之间通过VPN进行通信,再由边缘设备在第一局域网内与工控设备进行通信,工控设备的IP不需要暴露于公网中即可实现与远程的终端设备之间的通信。In view of the problem that in current industrial manufacturing scenarios, industrial equipment is exposed to the public network through routers to achieve remote communication with industrial equipment, resulting in poor remote communication security of industrial equipment, in the embodiment of this application, the edge device and the remote terminal equipment They communicate through VPN, and then the edge device communicates with the industrial control device in the first LAN. The IP of the industrial control device does not need to be exposed to the public network to achieve communication with the remote terminal device.
同样由于借助路由器实现工业设备的远程通信,需要在路由器中进行配置,以实现工业设备与终端设备之间的路由关系,然而当工业设备数量较多时,配置过程较为复杂。而本申请实施例中,不同工业设备可以复用边缘设备与终端设备之间建立的VPN通道,不需要每个工业设备均与终端设备建立连接,降低了配置的复杂度,并且,基于VPN通道实现的边缘设备与终端设备之间的通信具有较高的网络穿透性。Also, since remote communication of industrial equipment is achieved with the help of routers, configuration needs to be performed in the router to realize the routing relationship between industrial equipment and terminal equipment. However, when the number of industrial equipment is large, the configuration process is more complicated. In the embodiment of this application, different industrial devices can reuse the VPN channel established between the edge device and the terminal device. It is not necessary for each industrial device to establish a connection with the terminal device, which reduces the complexity of the configuration. Moreover, based on the VPN channel The communication between the edge device and the terminal device has high network penetration.
图1为本申请是实施例提供的一种工业设备的远程通信场景100的示意图。结合图1所示,边缘设备110与至少一个工业设备120在第一局域网内实现通信连接。其中,边缘设备110可以实现为一种网关。工业设备120可以实现为上述工控设备,或者工业设备120 可以替换为上述工业控制器件。FIG. 1 is a schematic diagram of a remote communication scenario 100 of industrial equipment provided by an embodiment of the present application. As shown in FIG. 1 , the edge device 110 and at least one industrial device 120 implement communication connections within the first local area network. Among them, the edge device 110 can be implemented as a gateway. The industrial equipment 120 can be implemented as the above-mentioned industrial control equipment, or the industrial equipment 120 Can be replaced by the above industrial control devices.
边缘设备110与终端设备130通过虚拟专用网络(Virtual Private Network,VPN)通道连接,VPN是在公用网络上建立的专用网络,VPN通道可以实现边缘设备110与终端设备130之间的加密通信。The edge device 110 and the terminal device 130 are connected through a virtual private network (Virtual Private Network, VPN) channel. VPN is a private network established on a public network. The VPN channel can realize encrypted communication between the edge device 110 and the terminal device 130.
一般来说,边缘设备110和终端设备130之间可以通过VPN服务器140建立VPN通道,并基于VPN服务器140的转发实现边缘设备110与终端设备130之间的通信,终端设备130和边缘设备110通过VPN通道进行通信时可以采用第二局域网。当然,VPN服务器140可以以功能模块的形式集成于终端设备130或边缘设备110中,本申请对此不做限定。Generally speaking, a VPN channel can be established between the edge device 110 and the terminal device 130 through the VPN server 140, and communication between the edge device 110 and the terminal device 130 is implemented based on the forwarding of the VPN server 140. The terminal device 130 and the edge device 110 pass A second LAN can be used for VPN channel communication. Of course, the VPN server 140 can be integrated into the terminal device 130 or the edge device 110 in the form of a functional module, which is not limited in this application.
VPN服务器140可以实现为普通服务器、服务器集群,或者云端服务器、服务器集群。The VPN server 140 can be implemented as an ordinary server, a server cluster, or a cloud server or a server cluster.
终端设备130的数量可以是一个或者多个,本申请对此不做限定。在终端设备130的数量为多个时,多个终端设备130可以通过VPN服务器140与边缘设备110进行通信,具体而言,多个终端设备130可以在同一局域网(例如上文中的第二局域网)内与边缘设备110进行加密通信,多个终端设备130的IP地址均属于该第二局域网的网段内。The number of terminal devices 130 may be one or more, and this application does not limit this. When the number of terminal devices 130 is multiple, the multiple terminal devices 130 can communicate with the edge device 110 through the VPN server 140. Specifically, the multiple terminal devices 130 can be in the same local area network (such as the second local area network above) Encrypted communication is performed with the edge device 110, and the IP addresses of the multiple terminal devices 130 all belong to the network segment of the second local area network.
边缘设备110可以将接收到的来自于终端设备130的数据包转发给工业设备120中的至少一个,也可以将接收到的来自于工业设备120的数据包转发给终端设备130,以实现终端设备130和工业设备120之间的通信。The edge device 110 may forward the received data packet from the terminal device 130 to at least one of the industrial devices 120, or may forward the received data packet from the industrial device 120 to the terminal device 130 to implement the terminal device Communication between 130 and industrial equipment 120.
示例性的,边缘设备110和终端设备130中均部署有VPN的客户端;VPN服务器140中部署有VPN的服务端。For example, a VPN client is deployed in both the edge device 110 and the terminal device 130; a VPN server is deployed in the VPN server 140.
上述第一局域网和第二局域网中的“第一”、“第二”用于区分不同的局域网,不代表先后顺序,也不限定第一局域网和第二局域网的类型不同。The "first" and "second" in the above-mentioned first LAN and second LAN are used to distinguish different LANs. They do not represent the order, nor do they limit the types of the first LAN and the second LAN.
需要说明的是,图1所示场景仅作为一种示例给出了本申请实施例相关场景的组成部分,并不对本申请构成任何限定。It should be noted that the scenario shown in Figure 1 is only used as an example to provide components of scenarios relevant to the embodiments of the present application, and does not constitute any limitation to the present application.
下面将结合附图对本申请实施例提供的工业设备的远程通信方法做详细说明。The remote communication method for industrial equipment provided by the embodiment of the present application will be described in detail below with reference to the accompanying drawings.
应理解,下文仅为便于理解和说明,以终端设备、边缘设备和工业设备之间的交互为例详细说明本申请实施例所提供的方法。该终端设备例如可以是图1中的终端设备130,边缘设备例如可以是图1中的边缘设备110,工业设备例如可以是图1中的工业设备120。在一些实施例中,VPN服务器也参与交互以实现本申请实施例提供的方法,该VPN服务器例如可以是图1中的VPN服务器140。It should be understood that the following is only for convenience of understanding and explanation. The method provided by the embodiment of the present application is described in detail by taking the interaction between terminal equipment, edge equipment, and industrial equipment as an example. The terminal device may be, for example, the terminal device 130 in FIG. 1 , the edge device may be, for example, the edge device 110 in FIG. 1 , and the industrial device may be, for example, the industrial device 120 in FIG. 1 . In some embodiments, a VPN server also participates in the interaction to implement the method provided by the embodiments of this application. The VPN server may be, for example, the VPN server 140 in Figure 1 .
但应理解,这不应对本申请提供的方法的执行主体构成任何限定。只要能够通过运行记录有本申请实施例的提供的方法的代码的程序,以实现本申请实施例提供的方法,便可以作为本申请实施例提供的方法的执行主体。例如,下文实施例所示的终端设备也可以替换为该终端设备中的部件,比如芯片、芯片系统或其他能够调用程序并执行程序的功能模块,边缘设备也可以替换为该边缘设备中的部件,比如芯片、芯片系统或其他能够调用程序并执行程序的功能模块,工业设备也可以替换为该工业设备中的部件,比如芯片、芯片 系统或其他能够调用程序并执行程序的功能模块,VPN服务器可以替换为该VPN服务器中的部件,比如芯片、芯片系统或其他能够调用程序并执行程序的功能模块。However, it should be understood that this should not constitute any limitation on the execution subject of the method provided in this application. As long as the method provided by the embodiment of the present application can be implemented by running a program that records the code of the method provided by the embodiment of the present application, it can be used as the execution subject of the method provided by the embodiment of the present application. For example, the terminal device shown in the following embodiments can also be replaced with components in the terminal device, such as a chip, a chip system, or other functional modules that can call and execute programs. The edge device can also be replaced with components in the edge device. , such as chips, chip systems or other functional modules that can call and execute programs. Industrial equipment can also be replaced by components in the industrial equipment, such as chips, chips System or other functional modules that can call and execute programs. The VPN server can be replaced by components in the VPN server, such as chips, chip systems, or other functional modules that can call and execute programs.
图2为本申请实施例提供的一种工业设备的远程通信方法200的交互流程示意图。如图2所示,该方法200包括以下部分或者全部过程:FIG. 2 is a schematic interactive flow diagram of a remote communication method 200 for industrial equipment provided by an embodiment of the present application. As shown in Figure 2, the method 200 includes some or all of the following processes:
S210,终端设备通过VPN通道向边缘设备发送第一数据包。S210: The terminal device sends the first data packet to the edge device through the VPN channel.
相应的,边缘设备通过VPN通道,获取来自于终端设备的第一数据包。Correspondingly, the edge device obtains the first data packet from the terminal device through the VPN channel.
S220,边缘设备将第一数据包发送至目标工业设备。S220: The edge device sends the first data packet to the target industrial device.
本申请实施例中,该第一数据包至少包括目的地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址。如前所述,工业设备与边缘设备在第一局域网内实现通信连接,而目标工业设备可以是在第一局域网内与边缘设备实现通信连接的至少一个工业设备中的任意一个,而终端设备通过第一数据包中的目标地址指示了该目标工业设备。In this embodiment of the present application, the first data packet at least includes a destination address, and the destination address in the first data packet is the IP address of the target industrial device in the first local area network. As mentioned above, the industrial equipment and the edge device realize communication connection in the first local area network, and the target industrial equipment can be any one of the at least one industrial equipment that realizes communication connection with the edge device in the first local area network, and the terminal device passes The destination address in the first packet indicates the destination industrial device.
边缘设备将该第一数据包发送至该第一数据包中的目的地址所指示的目标工业设备。示例性的,边缘设备和目标工业设备之间可以基于二者在第一局域网的IP地址,通过第一局域网进行通信。The edge device sends the first data packet to the target industrial device indicated by the destination address in the first data packet. For example, the edge device and the target industrial device may communicate through the first LAN based on their IP addresses in the first LAN.
第一数据包中的数据可以用于控制或维护目标工业设备。目标工业设备的数量可以是一个或者多个,本申请对此不做限定。当目标工业设备的数量不止一个时,终端设备可以向边缘设备发送各目标工业设备对应的第一数据包,再由边缘设备分别将各第一数据包转发至对应的目标工业设备。The data in the first data packet can be used to control or maintain the target industrial equipment. The number of target industrial equipment may be one or more, and this application does not limit this. When there is more than one target industrial device, the terminal device can send the first data packet corresponding to each target industrial device to the edge device, and then the edge device forwards each first data packet to the corresponding target industrial device.
因此,在上述S210和S220中,边缘设备与终端设备之间通过VPN通道进行加密通信,再由边缘设备在第一局域网中将终端设备发送的第一数据包发送至目标工业设备,在不将工业设备暴露于公网的情况下,实现了终端设备与边缘设备之间的通信,提高了工业设备的远程通信的安全性。Therefore, in the above-mentioned S210 and S220, encrypted communication is performed between the edge device and the terminal device through the VPN channel, and then the edge device sends the first data packet sent by the terminal device to the target industrial device in the first LAN. When industrial equipment is exposed to the public network, communication between terminal equipment and edge devices is realized, improving the security of remote communication of industrial equipment.
可以理解的是,第一数据包中除目的地址和数据之外,还可以包括源地址,在目标工业设备接收到第一数据包后,可以将第一数据包中的源地址作为目的地址,并向该目的地址发送数据包(如下文中的第二数据包),以实现信息交互。而第一数据包中的源地址为终端设备在第二局域网内的IP地址,也即VPN下的虚拟IP地址,此种情况下,连接于第一局域网内的目标工业设备无法将第二数据包发送至该终端设备。因此,在一些实施例中,边缘设备为了确保在向目标工业设备发送第一数据包之后,能够将来自于目标工业设备的第二数据包转发至该终端设备,可以在转发第一数据包之前将第一数据包中的源地址修改为该边缘设备在第一局域网内的IP地址,再将修改后的一数据包发送至目标工业设备,以使目标工业设备将边缘设备在第一局域网内的IP地址作为目的地址发送第二数据包。It can be understood that in addition to the destination address and data, the first data packet may also include a source address. After the target industrial equipment receives the first data packet, the source address in the first data packet may be used as the destination address. And send a data packet (such as the second data packet below) to the destination address to realize information exchange. The source address in the first data packet is the IP address of the terminal device in the second LAN, that is, the virtual IP address under the VPN. In this case, the target industrial equipment connected to the first LAN cannot transmit the second data. The packet is sent to the terminal device. Therefore, in some embodiments, in order to ensure that after sending the first data packet to the target industrial device, the edge device can forward the second data packet from the target industrial device to the terminal device, the edge device may forward the first data packet before forwarding the first data packet. Modify the source address in the first data packet to the IP address of the edge device in the first LAN, and then send the modified data packet to the target industrial device, so that the target industrial device can identify the IP address of the edge device in the first LAN. The IP address is used as the destination address to send the second data packet.
上述边缘设备对第一数据包中的源地址的修改可以包括以下可能的实现方式:边缘设备在接收到终端设备发送的第一数据包后,可以对第一数据包是否来自于VPN通道进行判断,例如边缘设备根据第一数据包中的源地址所属的网段确定是否属于第二局域网的网段,若第一数据包中的源地址所属的网段属于第二局域网的网段,则该第一数据包来自于 VPN通道,或者说终端设备通过VPN客户端发送了该第一数据包,此种情况下,边缘设备可以对第一数据包中的源地址进行修改。例如,第二局域网的网段为192.168.40.x,第一数据包中的源地址为192.168.40.4,则边缘设备确定第一数据包中的源地址属于第二局域网的网段,进而修改该第一数据包中的源地址。The modification of the source address in the first data packet by the edge device may include the following possible implementations: after receiving the first data packet sent by the terminal device, the edge device may determine whether the first data packet comes from the VPN channel. For example, the edge device determines whether it belongs to the network segment of the second LAN based on the network segment to which the source address in the first data packet belongs. If the network segment to which the source address in the first data packet belongs belongs to the network segment of the second LAN, then the The first packet comes from The VPN channel, or the terminal device sends the first data packet through the VPN client. In this case, the edge device can modify the source address in the first data packet. For example, the network segment of the second LAN is 192.168.40.x, and the source address in the first data packet is 192.168.40.4. The edge device determines that the source address in the first data packet belongs to the network segment of the second LAN, and then modifies the The source address in the first packet.
接续上述可能的实现方式,边缘设备可以根据预配置的源网络地址转换(Source Network Address Translation,SNAT)条目,将第一数据包中的源地址修改为边缘设备在第二局域网内的IP地址。需要说明的是,该SNAT条目用于指示将属于第二局域网的网段的源地址修改为该边缘设备的IP地址,该SNAT条目可以理解为一种SNAT策略,其中可以包括边缘设备在第一局域网内的IP地址与第二局域网的网段的映射关系。Continuing with the above possible implementation methods, the edge device can modify the source address in the first data packet to the IP address of the edge device in the second LAN according to the preconfigured Source Network Address Translation (SNAT) entry. It should be noted that the SNAT entry is used to indicate that the source address of the network segment belonging to the second LAN is modified to the IP address of the edge device. The SNAT entry can be understood as a SNAT policy, which can include the edge device in the first The mapping relationship between the IP address in the LAN and the network segment of the second LAN.
通过结合VPN通道和SNAT的方式建立终端设备与工业设备之间的网络隧道,使通信在传输控制协议(Transmission Control Protocol,TCP)/IP网络层进行,而不对三层网络以上的网络产生影响。By combining VPN channels and SNAT, a network tunnel is established between terminal equipment and industrial equipment, so that communication is carried out at the Transmission Control Protocol (TCP)/IP network layer without affecting networks above the three-layer network.
当然,上述可能的实现方式中,边缘设备修改第一数据包中的源地址,仅为一种示例而非限制性的说明。例如,边缘设备还可以将边缘设备在第一局域网内的IP地址作为附加源地址添加至第一数据包。基于SNAT的方式修改第一数据包中的源地址,同样仅为一种示例而非限制性的说明,例如边缘设备可以基于预设的第二局域网的网段,与,边缘设备在第一局域网的IP地址之间的映射关系,修改第一数据包中的源地址。Of course, in the above possible implementation manner, the edge device modifies the source address in the first data packet, which is only an example and not a limiting explanation. For example, the edge device may also add the edge device's IP address within the first local area network as an additional source address to the first data packet. Modifying the source address in the first data packet based on SNAT is also just an example and not a limiting explanation. For example, the edge device can be based on the preset network segment of the second LAN, and the edge device can be on the first LAN. The mapping relationship between IP addresses is modified to modify the source address in the first packet.
在一些实施例中,该方法200还包括如下步骤S230和S240。In some embodiments, the method 200 further includes the following steps S230 and S240.
S230,目标工业设备向边缘设备发送第二数据包。S230: The target industrial device sends the second data packet to the edge device.
相应的,边缘设备接收目标工业设备发送的第二数据包。Correspondingly, the edge device receives the second data packet sent by the target industrial device.
S240,边缘设备通过VPN通道,将第二数据包发送至终端设备。S240: The edge device sends the second data packet to the terminal device through the VPN channel.
相应的,终端设备通过VPN通道,接收第二数据包。Correspondingly, the terminal device receives the second data packet through the VPN channel.
需要说明的是,上述传输第一数据包的过程和传输第二数据包的过程可以是时间重叠的,例如边缘设备将终端设备发送的第一数据包转发至目标工业设备的同时,还将目标工业设备发送的第二数据包转发至终端设备;或者上述传输第一数据包的过程和传输第二数据包的过程可以不是时间重叠的,例如第二数据包是基于第一数据包中的数据生成的,此种情况下,边缘设备可以向目标工业设备转发来自终端设备的第一数据包,再向终端设备转发来自于目标工业设备的第二数据包。本申请对此不做限定。It should be noted that the above-mentioned process of transmitting the first data packet and the process of transmitting the second data packet may overlap in time. For example, while the edge device forwards the first data packet sent by the terminal device to the target industrial device, it also forwards the target industrial device to the target industrial device. The second data packet sent by the industrial equipment is forwarded to the terminal device; or the above-mentioned process of transmitting the first data packet and the process of transmitting the second data packet may not overlap in time. For example, the second data packet is based on the data in the first data packet. In this case, the edge device can forward the first data packet from the terminal device to the target industrial device, and then forward the second data packet from the target industrial device to the terminal device. This application does not limit this.
与第一数据包类似的,第二数据包可以包括目的地址、源地址和数据。第二数据包的目的地址可以是接收到的第一数据包的源地址,第二数据包的源地址可以是接收到的第一数据包的目的地址。具体而言,第二数据包的目的地址可以是边缘设备在第一局域网内的IP地址,第二数据包的源地址可以是目标工业设备在第一局域网内的IP地址。目标工业设备在第一局域网内传输该第二数据包。Similar to the first data packet, the second data packet may include a destination address, a source address and data. The destination address of the second data packet may be the source address of the received first data packet, and the source address of the second data packet may be the destination address of the received first data packet. Specifically, the destination address of the second data packet may be the IP address of the edge device in the first local area network, and the source address of the second data packet may be the IP address of the target industrial device in the first local area network. The target industrial equipment transmits the second data packet within the first local area network.
边缘设备接收到目标工业设备发送的第二数据包后,可以将第二数据包中的目的地址修改为终端设备在第二局域网内的IP地址,进而通过VPN通道,将第二数据包转发至终 端设备。示例性的,边缘设备在修改第一数据包的源地址时,可以保留第一数据包的源地址修改记录,该第一数据包的源地址修改记录至少可以包括第一数据包的原始源地址(即终端设备在第二局域网内的IP地址)和目的地址(即目标工业设备在第一局域网内的IP地址),进而,边缘设备可以根据第一数据包的源地址修改记录和第二数据包的源地址(即目标工业设备在第一局域网内的IP地址),将第二数据包的目的地址修改为终端设备在第二局域网内的IP地址,例如边缘设备可以在第二数据包的源地址与第一数据包的源地址修改记录中的目的地址一致时,将第二数据包的目的地址修改为终端设备在第而局域网内的IP地址。进而,边缘设备可以基于终端设备在第二局域网内的IP地址,通过VPN通道向终端设备发送第二数据包。After receiving the second data packet sent by the target industrial equipment, the edge device can modify the destination address in the second data packet to the IP address of the terminal device in the second LAN, and then forward the second data packet to end terminal equipment. For example, when the edge device modifies the source address of the first data packet, it can retain the source address modification record of the first data packet. The source address modification record of the first data packet can at least include the original source address of the first data packet. (i.e., the IP address of the terminal device in the second LAN) and the destination address (i.e., the IP address of the target industrial device in the first LAN). Furthermore, the edge device can modify the record and the second data according to the source address of the first data packet. The source address of the packet (that is, the IP address of the target industrial device in the first LAN), and the destination address of the second data packet is modified to the IP address of the terminal device in the second LAN. For example, the edge device can When the source address is consistent with the destination address in the source address modification record of the first data packet, the destination address of the second data packet is modified to the IP address of the terminal device in the third LAN. Furthermore, the edge device may send the second data packet to the terminal device through the VPN channel based on the IP address of the terminal device in the second local area network.
本实施例中,边缘设备通过第一局域网接收目标工业设备发送的第二数据包,并通过VPN通道将第二数据包发送至终端设备,在不将工业设备暴露于公网的情况下,实现了终端设备与边缘设备之间的通信,提高了工业设备的远程通信的安全性。In this embodiment, the edge device receives the second data packet sent by the target industrial device through the first LAN, and sends the second data packet to the terminal device through the VPN channel, without exposing the industrial device to the public network. It improves the communication between terminal devices and edge devices and improves the security of remote communication of industrial equipment.
上述实施例中的VPN通道可以是基于VPN服务器建立并实现通信的网络通道。下面结合图3进行说明。The VPN channel in the above embodiment may be a network channel established and implemented based on the VPN server. The following is explained in conjunction with Figure 3.
图3为本申请实施例提供的一种工业设备的远程通信方法300的交互流程示意图。该方法300可以包括以下部分或者全部过程:FIG. 3 is a schematic interactive flow diagram of a remote communication method 300 for industrial equipment provided by an embodiment of the present application. The method 300 may include some or all of the following processes:
首先对VPN服务器配置终端设备的VPN环境进行示例性的说明。First, an exemplary description of the VPN environment in which the VPN server configures the terminal device is provided.
VPN服务器可以获取第二客户端配置请求,例如图3所示,VPN服务器获取用户输入的第二客户端配置请求。该第二客户端配置请求用于请求配置至少一个终端设备分别对应的VPN环境,例如第二客户配置请求可以携带有终端设备的数量和/或标识等。VPN服务器响应于第二客户端配置请求,可以确定第二局域网的网段以及各终端设备分别对应的VPN证书。进一步地,VPN服务器将第二局域网的网段的信息和至少一个VPN证书分别携带于至少一个第三配置信息,或者将属于第二局域网的网段的IP地址和一个VPN证书携带于一个第三配置信息,其中,第二种方式相比于第一种方式而言,终端设备从第三配置信息中可以之间确定自身的IP地址,而不需要终端设备从第二局域网的网段中确定自身的IP地址。The VPN server may obtain the second client configuration request. For example, as shown in Figure 3, the VPN server obtains the second client configuration request input by the user. The second client configuration request is used to request to configure a VPN environment corresponding to at least one terminal device. For example, the second client configuration request may carry the number and/or identification of the terminal devices. In response to the second client configuration request, the VPN server may determine the network segment of the second local area network and the VPN certificate corresponding to each terminal device. Further, the VPN server carries the information of the network segment of the second LAN and at least one VPN certificate respectively in at least one third configuration information, or carries the IP address and one VPN certificate of the network segment belonging to the second LAN in a third party. configuration information. Compared with the first method, the second method allows the terminal device to determine its own IP address from the third configuration information without requiring the terminal device to determine the IP address from the network segment of the second LAN. own IP address.
接续上述终端设备的VPN环境部署方式,VPN服务器可以将第三配置信息发送至终端设备,当VPN服务器连接有多个终端设备时,VPN服务器可以将多个第三配置信息分别发送至对应的终端设备。进而,终端设备可以根据第三配置信息确定自身在第二局域网内IP地址,以及进行证书安装,已完成VPN环境的配置。Continuing with the VPN environment deployment method of the terminal device mentioned above, the VPN server can send the third configuration information to the terminal device. When the VPN server is connected to multiple terminal devices, the VPN server can send multiple third configuration information to the corresponding terminals respectively. equipment. Furthermore, the terminal device can determine its own IP address in the second local area network based on the third configuration information, and install the certificate, thereby completing the configuration of the VPN environment.
VPN服务器中部署的服务端可以设置为桥接(TAP)模式,以使服务端实现为安全套接字协议(Secure Sockets Layer,SSL)服务端。相应的,终端设备中部署的客户端可以是SSL客户端。The server deployed in the VPN server can be set to bridge (TAP) mode so that the server can be implemented as a Secure Sockets Layer (SSL) server. Correspondingly, the client deployed in the terminal device may be an SSL client.
针对VPN服务器配置边缘设备的VPN环境进行示例性的说明。This is an exemplary description of the VPN environment in which the VPN server is configured as an edge device.
结合图3所示,VPN服务器接收边缘设备发送的第一客户端配置请求,该第一客户端 配置请求用于请求VPN服务器发送第二配置信息。该第一客户端配置请求可以是边缘设备在初次上电时发送的,当然,这不应理解为对本申请的任何限定,例如,第一客户端配置请求也可以是边缘设备响应于用户输入的指令发送的请求。As shown in Figure 3, the VPN server receives the first client configuration request sent by the edge device. The first client The configuration request is used to request the VPN server to send second configuration information. The first client configuration request may be sent by the edge device when it is powered on for the first time. Of course, this should not be understood as any limitation on this application. For example, the first client configuration request may also be sent by the edge device in response to user input. The request sent by the command.
需要说明的是,第二配置信息可以包括:VPN客户端安装包、VPN证书、VPN启动指令中的至少之一。示例性的,边缘设备可以通过运行第二配置信息中的VPN客户端安装包安装VPN客户端;边缘设备可以通过安装第二配置信息中的VPN证书;边缘设备还可以响应于第二配置信息中的VPN启动指令启动VPN客户端。It should be noted that the second configuration information may include: at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction. For example, the edge device can install the VPN client by running the VPN client installation package in the second configuration information; the edge device can install the VPN certificate in the second configuration information; the edge device can also respond to the VPN client in the second configuration information. The VPN start command starts the VPN client.
在一些实施例中,边缘设备需要配置SNAT条目。边缘设备可以根据第二局域网的网段进行SNAT条目的配置,以建立第二局域网的网段与边缘设备在第一局域网内的IP地址之间的映射关系。In some embodiments, edge devices need to configure SNAT entries. The edge device may configure the SNAT entry according to the network segment of the second LAN to establish a mapping relationship between the network segment of the second LAN and the IP address of the edge device in the first LAN.
第二局域网的网段可以是边缘设备中预设置的,或者是边缘设备接收VPN服务器发送的。例如VPN服务器响应于第二客户端配置请求确定第二局域网的网段,并将第二局域网的网段的信息携带于第一配置信息,发送至边缘设备。The network segment of the second LAN may be preset in the edge device, or the edge device may receive a message sent by the VPN server. For example, the VPN server determines the network segment of the second LAN in response to the second client configuration request, carries the network segment information of the second LAN in the first configuration information, and sends it to the edge device.
上述结合图3所说明的VPN环境的部署仅为一种示例性的说明,并不对本申请构成任何限定,例如上述VPN环境的部署方式中的部分或者全部过程还可以是响应于用户输入的配置而完成的。The deployment of the VPN environment described above in conjunction with Figure 3 is only an exemplary description and does not constitute any limitation on the present application. For example, part or all of the process in the deployment method of the VPN environment may also be configured in response to user input. And completed.
终端设备和边缘设备部署VPN的服务端后,终端设备和边缘设备之间可以通过VPN服务器实现VPN通道上的数据传输。例如,终端设备可以向VPN服务器发送第一数据包,VPN服务器将终端设备发送的第一数据包转发至边缘设备,以实现终端设备通过VPN通道向边缘设备发送第一数据;和/或,边缘设备向VPN服务器发送第二数据包,VPN服务器将接收到的第二数据包转发至终端设备,以实现边缘设备通过VPN通道向终端设备发送第二数据包。After the terminal device and edge device deploy the VPN server, data transmission on the VPN channel can be realized between the terminal device and the edge device through the VPN server. For example, the terminal device can send a first data packet to the VPN server, and the VPN server forwards the first data packet sent by the terminal device to the edge device, so that the terminal device sends the first data to the edge device through the VPN channel; and/or the edge The device sends the second data packet to the VPN server, and the VPN server forwards the received second data packet to the terminal device, so that the edge device sends the second data packet to the terminal device through the VPN channel.
在图3所示实施例中,边缘设备与目标工业设备之间仍通过第一局域网实现通信,其实现方式可以参见上述任一实施例中的边缘设备与目标工业设备之间的通信方式。例如,边缘设备将第一数据包中的源地址修改为边缘设备在第一局域网内的IP地址后,将第一数据包发送至目标工业设备,再例如,边缘设备接收目标工业设备发送的第二数据包后,将第二数据包中的目的地址修改为终端设备在第二局域网内的IP地址后通过VPN通道发送至终端设备。In the embodiment shown in FIG. 3 , communication between the edge device and the target industrial device is still implemented through the first local area network. The implementation method can be referred to the communication method between the edge device and the target industrial device in any of the above embodiments. For example, after the edge device modifies the source address in the first data packet to the IP address of the edge device in the first LAN, it sends the first data packet to the target industrial device. For another example, the edge device receives the third packet sent by the target industrial device. After receiving the second data packet, modify the destination address in the second data packet to the IP address of the terminal device in the second LAN and then send it to the terminal device through the VPN channel.
本申请实施例中,在工业设备的数量不止一个时,可以将多个工业设备和边缘设备部署于同一局域网中,即可通过边缘设备与终端设备之间的VPN通道,实现远程通信。相比于现有技术中针对每个工业设备建立通信链路而言,提高了远程部署的便利性。In the embodiment of this application, when there is more than one industrial device, multiple industrial devices and edge devices can be deployed in the same local area network, and remote communication can be realized through the VPN channel between the edge device and the terminal device. Compared with the existing technology that establishes a communication link for each industrial device, the convenience of remote deployment is improved.
需要说明的是,本文中的“第一”、“第二”“第三”等描述,是用于区分不同的局域网、数据包、配置信息、请求等,不代表先后顺序,也不限定“第一”和“第二”是不同的类型。It should be noted that descriptions such as "first", "second" and "third" in this article are used to distinguish different LANs, data packets, configuration information, requests, etc., and do not represent the order or limit " "First" and "Second" are different types.
在本申请的各个实施例中,如果没有特殊说明以及逻辑冲突,各个实施例之间的术语 和/或描述具有一致性、且可以相互引用,不同的实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。In the various embodiments of this application, if there is no special explanation or logical conflict, the terminology between the various embodiments And/or the descriptions are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
图4为本申请实施例提供的一种电子设备400的示意性框图。如图4所示,该电子设备300可以实现为上述方法实施例中的执行主体,例如边缘设备、VPN服务器或终端设备。该电子设备400至少包括收发单元410,在一些实施例中,电子设备400还可以包括获取单元420和/或处理单元430。FIG. 4 is a schematic block diagram of an electronic device 400 provided by an embodiment of the present application. As shown in Figure 4, the electronic device 300 can be implemented as an execution subject in the above method embodiment, such as an edge device, a VPN server or a terminal device. The electronic device 400 at least includes a transceiver unit 410. In some embodiments, the electronic device 400 may also include an acquisition unit 420 and/or a processing unit 430.
可选的,该电子设备400可对应于上文方法实施例中的边缘设备,例如可以为边缘设备的一种实现,或者配置于边缘设备中的部件(如芯片或芯片系统等)。Optionally, the electronic device 400 may correspond to the edge device in the above method embodiment, for example, it may be an implementation of the edge device, or a component (such as a chip or chip system) configured in the edge device.
其中,获取单元420可以用于通过虚拟专用网络VPN通道,获取来自于终端设备的第一数据包,该第一数据包包括目的地址,该第一数据包中的目的地址为目标工业设备在该第一局域网内的网际互联协议IP地址,该目标工业设备为该至少一个工业设备中的一个;收发单元410,用于将该第一数据包发送至该目标工业设备。Wherein, the obtaining unit 420 can be used to obtain the first data packet from the terminal device through the virtual private network VPN channel, the first data packet includes a destination address, and the destination address in the first data packet is the target industrial device in the The Internet Protocol IP address in the first local area network, the target industrial device is one of the at least one industrial device; the transceiver unit 410 is used to send the first data packet to the target industrial device.
在一些实施例中,该第一数据包还包括源地址,该第一数据包中的源地址为该终端设备在第二局域网内的IP地址,该第二局域网为通过VPN通道进行通信时采用的局域网;该收发单元410具体用于:将该第一数据包中的源地址修改为该边缘设备在该第一局域网内的IP地址;将该第一数据包发送至该目标工业设备。In some embodiments, the first data packet further includes a source address. The source address in the first data packet is the IP address of the terminal device in a second local area network. The second local area network is used for communication through a VPN channel. The local area network; the transceiver unit 410 is specifically configured to: modify the source address in the first data packet to the IP address of the edge device in the first local area network; and send the first data packet to the target industrial device.
在一些实施例中,该收发单元410具体用于:在该第一数据包中的源地址属于第二局域网的网段的情况下,根据预配置的源网络地址转换SNAT条目,将该第一数据包中的源地址修改为该边缘设备在该第二局域网内的IP地址,该SNAT条目用于指示将属于第二局域网的网段的源地址修改为该边缘设备的IP地址。In some embodiments, the transceiver unit 410 is specifically configured to: when the source address in the first data packet belongs to the network segment of the second LAN, convert the SNAT entry according to the preconfigured source network address, and convert the first The source address in the data packet is modified to the IP address of the edge device in the second LAN, and the SNAT entry is used to indicate that the source address of the network segment belonging to the second LAN is modified to the IP address of the edge device.
在一些实施例中,该收发单元420还用于:接收该VPN服务器发送的第一配置信息,该第一配置信息携带该第二局域网的网段的信息;处理单元430用于根据该第一配置信息,配置该SNAT条目。In some embodiments, the transceiver unit 420 is further configured to: receive first configuration information sent by the VPN server, where the first configuration information carries information about the network segment of the second local area network; and the processing unit 430 is configured to receive the first configuration information according to the first configuration information. Configuration information, configure the SNAT entry.
在一些实施例中,该获取单元420具体用于:接收该VPN服务器转发的该第一数据包。In some embodiments, the obtaining unit 420 is specifically configured to: receive the first data packet forwarded by the VPN server.
获取来自于终端设备的第一数据包,该收发单元410还用于接收该目标工业设备发送的第二数据包,该第二数据包包括源地址和目的地址,该第二数据包中的目的地址为该边缘设备在该第一局域网内的IP地址;处理单元430还用于根据该第一数据包的源地址修改记录和该第二数据包的源地址,将该第二数据包的目的地址修改为该终端设备在该第二局域网内的IP地址;收发单元410还用于通过该VPN通道,将该第二数据包发送至该终端设备。Obtain the first data packet from the terminal device. The transceiver unit 410 is also used to receive the second data packet sent by the target industrial device. The second data packet includes a source address and a destination address. The destination in the second data packet The address is the IP address of the edge device in the first LAN; the processing unit 430 is also configured to modify the record according to the source address of the first data packet and the source address of the second data packet, and modify the destination of the second data packet. The address is modified to the IP address of the terminal device in the second local area network; the transceiver unit 410 is also used to send the second data packet to the terminal device through the VPN channel.
在一些实施例中,该收发单元410还用于接收该VPN服务器发送的第二配置信息,该第二配置信息携带有VPN客户端安装包、VPN证书、VPN启动指令中的至少之一;处理单元430还用于根据该第二配置信息,配置VPN环境,以搭建该VPN通道。In some embodiments, the transceiver unit 410 is also configured to receive second configuration information sent by the VPN server, where the second configuration information carries at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction; process Unit 430 is also used to configure the VPN environment according to the second configuration information to build the VPN channel.
在一些实施例中,在该接收该VPN服务器发送的第二配置信息之前,该收发单元410 还用于:在初次上电时,向该VPN服务器发送第一客户端配置请求,该第一客户端配置请求用于请求该VPN服务器发送该第二配置信息。In some embodiments, before receiving the second configuration information sent by the VPN server, the transceiver unit 410 It is also used to send a first client configuration request to the VPN server when it is powered on for the first time. The first client configuration request is used to request the VPN server to send the second configuration information.
可选的,该电子设备400可对应于上文方法实施例中的VPN服务器,例如可以为VPN服务器的一种实现,或者配置于VPN服务器中的部件(如芯片或芯片系统等)。Optionally, the electronic device 400 may correspond to the VPN server in the above method embodiment, for example, it may be an implementation of the VPN server, or a component (such as a chip or chip system) configured in the VPN server.
其中,收发单元410可以用于:向边缘设备发送第一配置信息,该第一配置信息携带第二局域网的网段的信息,该第二局域网的网段为通过VPN通道进行通信时采用的局域网;向该边缘设备转发来自于终端设备的第一数据包,该第一数据包包括源地址和目的地址,该第一数据包中的源地址为该终端设备的在该第二局域网内的IP地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,该目标工业设备为在第一局域网内与该边缘设备实现通信连接的至少一个工业设备中的一个。The transceiver unit 410 may be configured to: send first configuration information to the edge device, where the first configuration information carries information about a network segment of a second local area network, and the network segment of the second local area network is a local area network used when communicating through a VPN channel. ; Forward the first data packet from the terminal device to the edge device. The first data packet includes a source address and a destination address. The source address in the first data packet is the IP of the terminal device in the second local area network. Address, the destination address in the first data packet is the IP address of the target industrial device in the first local area network, and the target industrial device is one of at least one industrial device that communicates with the edge device in the first local area network.
在一些实施例中,该收发单元410还用于:向该边缘设备发送第二配置信息,该第二配置信息携带有VPN客户端安装包、VPN证书、VPN启动指令中的至少之一。In some embodiments, the transceiver unit 410 is further configured to send second configuration information to the edge device, where the second configuration information carries at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction.
在一些实施例中,收发单元410还用于:接收该边缘设备在初次上电时发送的第一客户端配置请求,该第一客户端配置请求用于请求该VPN服务器发送该第二配置信息。In some embodiments, the transceiver unit 410 is also configured to: receive a first client configuration request sent by the edge device when it is powered on for the first time. The first client configuration request is used to request the VPN server to send the second configuration information. .
在一些实施例中,该获取单元420用于获取第二客户端配置请求,该第二客户端请求用于请求配置至少一个终端设备分别对应的VPN环境;处理单元430用于根据该第二客户端配置请求,生成该第一配置信息和/或该至少一个终端设备分别对应的至少一个第三配置信息,该第三配置信息包括该第二局域网的网段和/或该终端设备对应的VPN证书;收发单元410还用于向该至少一个终端设备分别发送该第三配置信息。In some embodiments, the obtaining unit 420 is used to obtain a second client configuration request, the second client request is used to request the configuration of a VPN environment corresponding to at least one terminal device; the processing unit 430 is used to obtain a VPN environment corresponding to at least one terminal device according to the second client request. A terminal configuration request is generated to generate the first configuration information and/or at least one third configuration information respectively corresponding to the at least one terminal device. The third configuration information includes the network segment of the second LAN and/or the VPN corresponding to the terminal device. The certificate; transceiving unit 410 is also configured to send the third configuration information to the at least one terminal device respectively.
在一些实施例中,该VPN服务器被配置为桥接模式。In some embodiments, the VPN server is configured in bridge mode.
可选的,该电子设备400可对应于上文方法实施例中的终端设备,例如可以为终端设备的一种实现,或者配置于终端设备中的部件(如芯片或芯片系统等)。Optionally, the electronic device 400 may correspond to the terminal device in the above method embodiment, and may be, for example, an implementation of the terminal device, or a component (such as a chip or chip system) configured in the terminal device.
其中,收发单元410可以用于:通过VPN通道,向边缘设备发送第一数据包,该第一数据包包括源地址和目的地址,该第一数据包中的源地址为该终端设备的在第二局域网内的IP地址,该第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,该目标工业设备为在第一局域网内与该边缘设备实现通信连接的至少一个工业设备中的一个;通过该VPN通道,接收该边缘设备发送的第二数据包。Wherein, the transceiver unit 410 may be configured to: send a first data packet to the edge device through the VPN channel, the first data packet includes a source address and a destination address, and the source address in the first data packet is the terminal device in the third. 2. IP addresses in the local area network. The destination address in the first data packet is the IP address of the target industrial device in the first local area network. The target industrial device is at least one industrial device that communicates with the edge device in the first local area network. One of the devices; receives the second data packet sent by the edge device through the VPN channel.
应理解,各单元执行上述相应步骤的具体过程在上述方法实施例中已经详细说明,为了简洁,在此不再赘述。It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
图5为本申请实施例提供的一种电子设备500的示意性结构图。图5所示的电子设备500可以实现为终端设备、边缘设备或VPN服务器,用于实现上文方法实施例中终端设备、边缘设备或VPN服务器所执行的步骤。该电子设备500包括处理器520,处理器520可以从存储器中调用并运行计算机程序,以实现本申请实施例中的方法。FIG. 5 is a schematic structural diagram of an electronic device 500 provided by an embodiment of the present application. The electronic device 500 shown in Figure 5 can be implemented as a terminal device, an edge device or a VPN server, and is used to implement the steps performed by the terminal device, edge device or VPN server in the above method embodiment. The electronic device 500 includes a processor 520, and the processor 520 can call and run a computer program from the memory to implement the method in the embodiment of the present application.
在一些实施例中,如图5所示,电子设备500还可以包括存储器530。其中,处理器520可以从存储器530中调用并运行计算机程序,以实现本申请实施例中的方法。 In some embodiments, as shown in FIG. 5 , the electronic device 500 may also include a memory 530 . The processor 520 can call and run the computer program from the memory 530 to implement the method in the embodiment of the present application.
其中,存储器530可以是独立于处理器520的一个单独的器件,也可以集成在处理器520中。The memory 530 may be a separate device independent of the processor 520 , or may be integrated into the processor 520 .
在一些实施例中,如图5所示,电子设备500还可以包括收发器510,处理器520可以控制该收发器510与其他设备进行通信,具体地,可以向其他设备发送信息或数据,或接收其他设备发送的信息或数据。In some embodiments, as shown in Figure 5, the electronic device 500 may also include a transceiver 510, and the processor 520 may control the transceiver 510 to communicate with other devices, specifically, may send information or data to other devices, or Receive information or data from other devices.
其中,收发器510可以包括发射机和接收机。收发器510还可以进一步包括天线,天线的数量可以为一个或多个。Among them, the transceiver 510 may include a transmitter and a receiver. The transceiver 510 may further include an antenna, and the number of antennas may be one or more.
在一些实施例中,该电子设备500可以实现本申请实施例中终端设备、边缘设备或VPN服务器侧的各个方法的相应流程,为了简洁,在此不再赘述。In some embodiments, the electronic device 500 can implement the corresponding processes of each method on the terminal device, edge device or VPN server side in the embodiments of this application. For the sake of brevity, details are not repeated here.
图6为本申请示例性实施例提供的一种云服务器600的结构示意图。该云服务器600可以为上文方法实施例中VPN服务器的一种实现。如图6所示,该VPN服务器600包括:存储器610和处理器620。Figure 6 is a schematic structural diagram of a cloud server 600 provided by an exemplary embodiment of the present application. The cloud server 600 may be an implementation of the VPN server in the above method embodiment. As shown in FIG. 6 , the VPN server 600 includes: a memory 610 and a processor 620 .
存储器610,用于存储计算机程序,并可被配置为存储其它各种数据以支持在VPN服务器上的操作。该存储器610可以是对象存储(Object Storage Service,OSS)。Memory 610 is used to store computer programs and may be configured to store various other data to support operations on the VPN server. The storage 610 may be an object storage (Object Storage Service, OSS).
处理器620,与存储器610耦合,用于执行存储器610中的计算机程序,以用于实现上文方法实施例中由VPN服务器实现的方法。The processor 620 is coupled to the memory 610 and is used to execute the computer program in the memory 610 to implement the method implemented by the VPN server in the above method embodiment.
进一步,如图6所示,该VPN服务器还包括:防火墙630、负载均衡器640、通信组件650、电源组件660等其它组件。图6中仅示意性给出部分组件,并不意味着VPN服务器只包括图6所示组件。Further, as shown in Figure 6, the VPN server also includes: a firewall 630, a load balancer 640, a communication component 650, a power supply component 660 and other components. Only some components are schematically shown in Figure 6, which does not mean that the VPN server only includes the components shown in Figure 6.
应理解,图6所示的VPN服务器500能够实现上文方法实施例中涉及VPN服务器的各个过程。VPN服务器500中的各个模块的操作和/或功能,分别为了实现上述方法实施例中的相应流程。具体可参见上述方法实施例中的描述,为避免重复,此处适当省略详细描述。It should be understood that the VPN server 500 shown in Figure 6 can implement various processes related to the VPN server in the above method embodiment. The operations and/or functions of each module in the VPN server 500 are respectively intended to implement the corresponding processes in the above method embodiments. For details, please refer to the description in the above method embodiment. To avoid repetition, the detailed description is appropriately omitted here.
本申请还提供了一种处理装置,包括至少一个处理器,所述至少一个处理器用于执行存储器中存储的计算机程序,以使得所述处理装置执行上述方法实施例中终端设备、边缘设备或VPN服务器执行的方法。This application also provides a processing device, including at least one processor, the at least one processor is used to execute a computer program stored in the memory, so that the processing device executes the terminal device, edge device or VPN in the above method embodiment. The method executed by the server.
本申请实施例还提供了一种处理装置,包括处理器和输入输出接口。所述输入输出接口与所述处理器耦合。所述输入输出接口用于输入和/或输出信息。所述信息包括指令和数据中的至少一项。所述处理器用于执行计算机程序,以使得所述处理装置执行上述方法实施例中终端设备、边缘设备或VPN服务器执行的方法。An embodiment of the present application also provides a processing device, including a processor and an input and output interface. The input and output interface is coupled to the processor. The input and output interface is used to input and/or output information. The information includes at least one of instructions and data. The processor is used to execute a computer program, so that the processing device executes the method executed by the terminal device, edge device or VPN server in the above method embodiment.
本申请实施例还提供了一种处理装置,包括处理器和存储器。所述存储器用于存储计算机程序,所述处理器用于从所述存储器调用并运行所述计算机程序,以使得所述处理装置执行上述方法实施例中终端设备、边缘设备或VPN服务器执行的方法。An embodiment of the present application also provides a processing device, including a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory, so that the processing device performs the method performed by the terminal device, edge device or VPN server in the above method embodiment.
应理解,上述处理装置可以是一个或多个芯片。例如,该处理装置可以是现场可编程门阵列(field programmable gate array,FPGA),可以是专用集成芯片(application specific  integrated circuit,ASIC),还可以是系统芯片(system on chip,SoC),还可以是处理器(central processor unit,CPU),还可以是网络处理器(network processor,NP),还可以是数字信号处理电路(digital signal processor,DSP),还可以是微控制器(micro controller unit,MCU),还可以是可编程控制器(programmable logic device,PLD)或其他集成芯片。It should be understood that the above-mentioned processing device may be one or more chips. For example, the processing device may be a field programmable gate array (FPGA) or an application specific integrated chip (application specific integrated circuit (ASIC), system on chip (SoC), central processor unit (CPU), network processor (NP), or digital signal The processing circuit (digital signal processor, DSP) can also be a microcontroller unit (micro controller unit, MCU), a programmable logic device (PLD), or other integrated chips.
在实现过程中,上述方法的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。结合本申请实施例所公开的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤。为避免重复,这里不再详细描述。During the implementation process, each step of the above method can be completed by instructions in the form of hardware integrated logic circuits or software in the processor. The steps of the methods disclosed in conjunction with the embodiments of the present application can be directly implemented by a hardware processor for execution, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
应注意,本申请实施例中的处理器可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法实施例的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器可以是通用处理器、数字信号处理器(DSP)、专用集成电路(ASIC)、现场可编程门阵列(FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。结合本申请实施例所公开的方法的步骤可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤。It should be noted that the processor in the embodiment of the present application may be an integrated circuit chip with signal processing capabilities. During the implementation process, each step of the above method embodiment can be completed through an integrated logic circuit of hardware in the processor or instructions in the form of software. The above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. . Each method, step and logical block diagram disclosed in the embodiment of this application can be implemented or executed. A general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly implemented by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
可以理解,本申请实施例中的存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(read-only memory,ROM)、可编程只读存储器(programmable ROM,PROM)、可擦除可编程只读存储器(erasable PROM,EPROM)、电可擦除可编程只读存储器(electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(random access memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(static RAM,SRAM)、动态随机存取存储器(dynamic RAM,DRAM)、同步动态随机存取存储器(synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(double data rate SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(synchlink DRAM,SLDRAM)和直接内存总线随机存取存储器(direct rambus RAM,DR RAM)。应注意,本文描述的系统和方法的存储器旨在包括但不限于这些和任意其它适合类型的存储器。It can be understood that the memory in the embodiment of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, non-volatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable programmable read-only memory (erasable PROM, EPROM), electrically removable memory. Erase electrically programmable read-only memory (EPROM, EEPROM) or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of illustration, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synchlink DRAM, SLDRAM) ) and direct memory bus random access memory (direct rambus RAM, DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
根据本申请实施例提供的方法,本申请还提供一种计算机程序产品,该计算机程序产品包括:计算机程序代码,当该计算机程序代码在计算机上运行时,使得该计算机执行上述方法实施例中的终端设备、边缘设备或VPN服务器执行的方法。 According to the method provided by the embodiment of the present application, the present application also provides a computer program product. The computer program product includes: computer program code. When the computer program code is run on a computer, it causes the computer to execute the steps in the above method embodiment. The method performed by the end device, edge device or VPN server.
根据本申请实施例提供的方法,本申请还提供一种计算机可读存储介质,该计算机可读存储介质存储有程序代码,当该程序代码在计算机上运行时,使得该计算机执行上述方法实施例中的终端设备、边缘设备或VPN服务器执行的方法。According to the method provided by the embodiment of the present application, the present application also provides a computer-readable storage medium. The computer-readable storage medium stores program code. When the program code is run on a computer, it causes the computer to execute the above method embodiment. A method performed by an end device, edge device, or VPN server.
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。 The above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application. should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims (14)

  1. 一种工业设备的远程通信方法,其特征在于,应用于边缘设备,所述边缘设备与至少一个工业设备在第一局域网内实现通信连接,包括:A remote communication method for industrial equipment, characterized in that it is applied to an edge device, and the edge device implements a communication connection with at least one industrial device in a first local area network, including:
    通过虚拟专用网络VPN通道,获取来自于终端设备的第一数据包,所述第一数据包包括目的地址,所述第一数据包中的目的地址为目标工业设备在所述第一局域网内的网际互联协议IP地址,所述目标工业设备为所述至少一个工业设备中的一个;Obtain the first data packet from the terminal device through the virtual private network VPN channel. The first data packet includes a destination address. The destination address in the first data packet is the address of the target industrial device in the first local area network. Internet Protocol IP address, the target industrial device is one of the at least one industrial device;
    将所述第一数据包发送至所述目标工业设备。Send the first data packet to the target industrial device.
  2. 根据权利要求1所述的方法,其特征在于,所述第一数据包还包括源地址,所述第一数据包中的源地址为所述终端设备在第二局域网内的IP地址,所述第二局域网为通过VPN通道进行通信时采用的局域网;The method of claim 1, wherein the first data packet further includes a source address, and the source address in the first data packet is the IP address of the terminal device in the second local area network, and the The second LAN is the LAN used for communication through the VPN channel;
    所述将所述第一数据包发送至所述目标工业设备,包括:The sending of the first data packet to the target industrial equipment includes:
    将所述第一数据包中的源地址修改为所述边缘设备在所述第一局域网内的IP地址;Modify the source address in the first data packet to the IP address of the edge device in the first local area network;
    将所述第一数据包发送至所述目标工业设备。Send the first data packet to the target industrial device.
  3. 根据权利要求2所述的方法,其特征在于,所述将所述第一数据包中的源地址修改为所述边缘设备在所述第二局域网内的IP地址,包括:The method of claim 2, wherein modifying the source address in the first data packet to the IP address of the edge device in the second local area network includes:
    在所述第一数据包中的源地址属于第二局域网的网段的情况下,根据预配置的源网络地址转换SNAT条目,将所述第一数据包中的源地址修改为所述边缘设备在所述第二局域网内的IP地址,所述SNAT条目用于指示将属于第二局域网的网段的源地址修改为所述边缘设备的IP地址。When the source address in the first data packet belongs to the network segment of the second LAN, convert the SNAT entry according to the preconfigured source network address, and modify the source address in the first data packet to the edge device. The IP address in the second local area network, and the SNAT entry is used to indicate that the source address of the network segment belonging to the second local area network is modified to the IP address of the edge device.
  4. 根据权利要求1至3任一项所述的方法,其特征在于,所述通过VPN通道,获取来自于终端设备的第一数据包,包括:The method according to any one of claims 1 to 3, characterized in that, obtaining the first data packet from the terminal device through the VPN channel includes:
    接收所述VPN服务器转发的所述第一数据包。Receive the first data packet forwarded by the VPN server.
  5. 根据权利要求2至3任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 2 to 3, characterized in that the method further includes:
    接收所述目标工业设备发送的第二数据包,所述第二数据包包括源地址和目的地址,所述第二数据包中的目的地址为所述边缘设备在所述第一局域网内的IP地址;Receive a second data packet sent by the target industrial device. The second data packet includes a source address and a destination address. The destination address in the second data packet is the IP of the edge device in the first local area network. address;
    根据所述第一数据包的源地址修改记录和所述第二数据包的源地址,将所述第二数据包的目的地址修改为所述终端设备在所述第二局域网内的IP地址;Modify the destination address of the second data packet to the IP address of the terminal device in the second local area network according to the source address modification record of the first data packet and the source address of the second data packet;
    通过所述VPN通道,将所述第二数据包发送至所述终端设备。The second data packet is sent to the terminal device through the VPN channel.
  6. 一种工业设备的远程通信方法,其特征在于,应用于VPN服务器,包括:A remote communication method for industrial equipment, characterized in that it is applied to a VPN server and includes:
    向边缘设备发送第一配置信息,所述第一配置信息携带第二局域网的网段的信息,所述第二局域网的网段为通过VPN通道进行通信时采用的局域网;Send first configuration information to the edge device, where the first configuration information carries information about a network segment of a second local area network, and the network segment of the second local area network is a local area network used for communication through the VPN channel;
    向所述边缘设备转发来自于终端设备的第一数据包,所述第一数据包包括源地址和目的地址,所述第一数据包中的源地址为所述终端设备的在所述第二局域网内的IP地址,所述第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,所述目标工业设备为在第一局域网内与所述边缘设备实现通信连接的至少一个工业设备中的一个。 Forward the first data packet from the terminal device to the edge device, where the first data packet includes a source address and a destination address, and the source address in the first data packet is the terminal device in the second The IP address in the local area network. The destination address in the first data packet is the IP address of the target industrial equipment in the first local area network. The target industrial equipment is at least one that implements communication connection with the edge device in the first local area network. A piece of industrial equipment.
  7. 根据权利要求6所述的方法,其特征在于,在所述向所述边缘设备转发来自于终端设备的第一数据包之前,所述方法还包括:The method according to claim 6, characterized in that before forwarding the first data packet from the terminal device to the edge device, the method further includes:
    向所述边缘设备发送第二配置信息,所述第二配置信息携带有VPN客户端安装包、VPN证书、VPN启动指令中的至少之一。Send second configuration information to the edge device, where the second configuration information carries at least one of a VPN client installation package, a VPN certificate, and a VPN startup instruction.
  8. 根据权利要求7所述的方法,其特征在于,在所述向所述边缘设备发送第二配置信息之前,所述方法还包括:The method according to claim 7, characterized in that before sending the second configuration information to the edge device, the method further includes:
    接收所述边缘设备在初次上电时发送的第一客户端配置请求,所述第一客户端配置请求用于请求所述VPN服务器发送所述第二配置信息。Receive a first client configuration request sent by the edge device when it is powered on for the first time, where the first client configuration request is used to request the VPN server to send the second configuration information.
  9. 根据权利要求6至8任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 6 to 8, characterized in that the method further includes:
    获取第二客户端配置请求,所述第二客户端请求用于请求配置至少一个终端设备分别对应的VPN环境;Obtain a second client configuration request, where the second client request is used to request configuration of a VPN environment corresponding to at least one terminal device;
    根据所述第二客户端配置请求,生成所述第一配置信息和/或所述至少一个终端设备分别对应的至少一个第三配置信息,所述第三配置信息包括所述第二局域网的网段和/或所述终端设备对应的VPN证书;According to the second client configuration request, generate the first configuration information and/or at least one third configuration information corresponding to the at least one terminal device, where the third configuration information includes the network number of the second local area network. segment and/or the VPN certificate corresponding to the terminal device;
    向所述至少一个终端设备分别发送所述第三配置信息。Send the third configuration information to the at least one terminal device respectively.
  10. 一种工业设备的远程通信方法,其特征在于,应用于终端设备,包括:A remote communication method for industrial equipment, characterized in that it is applied to terminal equipment and includes:
    通过VPN通道,向边缘设备发送第一数据包,所述第一数据包包括源地址和目的地址,所述第一数据包中的源地址为所述终端设备的在第二局域网内的IP地址,所述第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,所述目标工业设备为在第一局域网内与所述边缘设备实现通信连接的至少一个工业设备中的一个;Send a first data packet to the edge device through the VPN channel. The first data packet includes a source address and a destination address. The source address in the first data packet is the IP address of the terminal device in the second local area network. , the destination address in the first data packet is the IP address of the target industrial device in the first local area network, and the target industrial device is at least one industrial device that communicates with the edge device in the first local area network. one;
    通过所述VPN通道,接收所述边缘设备发送的第二数据包。Receive the second data packet sent by the edge device through the VPN channel.
  11. 一种边缘设备,其特征在于,所述边缘设备与至少一个工业设备在第一局域网内实现通信连接,所述边缘设备包括:An edge device, characterized in that the edge device communicates with at least one industrial device within a first local area network, and the edge device includes:
    获取单元,用于通过虚拟专用网络VPN通道,获取来自于终端设备的第一数据包,所述第一数据包包括目的地址,所述第一数据包中的目的地址为目标工业设备在所述第一局域网内的网际互联协议IP地址,所述目标工业设备为所述至少一个工业设备中的一个;The acquisition unit is configured to acquire the first data packet from the terminal device through the virtual private network VPN channel, the first data packet includes a destination address, and the destination address in the first data packet is the target industrial device in the The Internet Protocol IP address in the first local area network, the target industrial device is one of the at least one industrial device;
    收发单元,用于将所述第一数据包发送至所述目标工业设备。A transceiver unit, configured to send the first data packet to the target industrial equipment.
  12. 一种服务器,其特征在于,包括:A server, characterized by including:
    收发单元,用于向边缘设备发送第一配置信息,所述第一配置信息携带第二局域网的网段的信息,所述第二局域网的网段为通过VPN通道进行通信时采用的局域网;A transceiver unit configured to send first configuration information to the edge device, where the first configuration information carries information about a network segment of a second local area network, and the network segment of the second local area network is a local area network used when communicating through a VPN channel;
    所述收发单元还用于向所述边缘设备转发来自于终端设备的第一数据包,所述第一数据包包括源地址和目的地址,所述第一数据包中的源地址为所述终端设备的在所述第二局域网内的IP地址,所述第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,所述目标工业设备为在第一局域网内与所述边缘设备实现通信连接的至少一个工业设备中的一个。 The transceiver unit is also configured to forward a first data packet from a terminal device to the edge device. The first data packet includes a source address and a destination address. The source address in the first data packet is the terminal device. The IP address of the device in the second local area network. The destination address in the first data packet is the IP address of the target industrial equipment in the first local area network. The target industrial equipment is in the first local area network and is connected to the first local area network. An edge device implements a communication connection to one of at least one industrial device.
  13. 一种终端设备,其特征在于,包括:A terminal device, characterized by including:
    收发单元,用于通过VPN通道,向边缘设备发送第一数据包,所述第一数据包包括源地址和目的地址,所述第一数据包中的源地址为所述终端设备的在第二局域网内的IP地址,所述第一数据包中的目的地址为目标工业设备在第一局域网内的IP地址,所述目标工业设备为在第一局域网内与所述边缘设备实现通信连接的至少一个工业设备中的一个;A transceiver unit configured to send a first data packet to the edge device through the VPN channel, where the first data packet includes a source address and a destination address, and the source address in the first data packet is the second data packet of the terminal device. The IP address in the local area network. The destination address in the first data packet is the IP address of the target industrial equipment in the first local area network. The target industrial equipment is at least one that implements communication connection with the edge device in the first local area network. a piece of industrial equipment;
    所述收发单元还用于通过所述VPN通道,接收所述边缘设备发送的第二数据包。The transceiver unit is also configured to receive the second data packet sent by the edge device through the VPN channel.
  14. 一种电子设备,其特征在于,包括:至少一个处理器和存储器;An electronic device, characterized by including: at least one processor and memory;
    所述存储器存储计算机执行指令;The memory stores computer execution instructions;
    所述至少一个处理器执行所述存储器存储的计算机执行指令,使得所述至少一个处理器执行如权利要求1至10中任一项所述的方法。 The at least one processor executes computer-executable instructions stored in the memory, such that the at least one processor executes the method of any one of claims 1 to 10.
PCT/CN2023/084356 2022-03-30 2023-03-28 Remote communication methods for industrial device, apparatuses and devices WO2023185823A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202210334472.5 2022-03-30
CN202210334472.5A CN114615080B (en) 2022-03-30 2022-03-30 Remote communication method and device for industrial equipment and equipment

Publications (1)

Publication Number Publication Date
WO2023185823A1 true WO2023185823A1 (en) 2023-10-05

Family

ID=81867176

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/084356 WO2023185823A1 (en) 2022-03-30 2023-03-28 Remote communication methods for industrial device, apparatuses and devices

Country Status (2)

Country Link
CN (1) CN114615080B (en)
WO (1) WO2023185823A1 (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114615080B (en) * 2022-03-30 2023-12-05 阿里巴巴(中国)有限公司 Remote communication method and device for industrial equipment and equipment
CN116347437B (en) * 2023-05-22 2023-08-04 深圳市优博生活科技有限公司 Method and device for implementing exposure elimination protocol based on industrial client equipment

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016119747A1 (en) * 2015-01-30 2016-08-04 Huawei Technologies Co., Ltd. System and method for communicating in an ssl vpn
CN110166450A (en) * 2019-05-17 2019-08-23 固高科技(深圳)有限公司 Data transmission method, device and communication equipment based on Industrial Ethernet
CN113992440A (en) * 2021-12-28 2022-01-28 北京安博通科技股份有限公司 Gateway equipment and method for transmitting local data into IPsec tunnel
CN114244906A (en) * 2021-12-15 2022-03-25 中国电信股份有限公司 Data flow shunting method, device, equipment and medium
CN114615080A (en) * 2022-03-30 2022-06-10 阿里巴巴(中国)有限公司 Remote communication method and device for industrial equipment and equipment

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101567831B (en) * 2008-04-21 2011-11-16 成都市华为赛门铁克科技有限公司 Method and device for transmitting and receiving messages among local area networks and communication system
JP4802263B2 (en) * 2009-07-17 2011-10-26 株式会社日立製作所 Encrypted communication system and gateway device
US10135789B2 (en) * 2015-04-13 2018-11-20 Nicira, Inc. Method and system of establishing a virtual private network in a cloud service for branch networking
CN104994331B (en) * 2015-05-13 2018-05-01 浙江宇视科技有限公司 Flow sending method and system between a kind of network of suitable low speed chain circuit
CN106899474B (en) * 2016-12-07 2020-06-09 新华三技术有限公司 Message forwarding method and device
CN108390937B (en) * 2018-03-01 2021-01-05 深圳市腾讯计算机系统有限公司 Remote monitoring method, device and storage medium
CN108769292B (en) * 2018-06-29 2021-04-13 北京百悟科技有限公司 Message data processing method and device
EP3605958B1 (en) * 2018-08-02 2021-09-22 Nokia Solutions and Networks Oy Ip routed virtual private lan
CN112671938B (en) * 2019-10-15 2023-06-20 华为云计算技术有限公司 Business service providing method and system and remote acceleration gateway

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2016119747A1 (en) * 2015-01-30 2016-08-04 Huawei Technologies Co., Ltd. System and method for communicating in an ssl vpn
CN110166450A (en) * 2019-05-17 2019-08-23 固高科技(深圳)有限公司 Data transmission method, device and communication equipment based on Industrial Ethernet
CN114244906A (en) * 2021-12-15 2022-03-25 中国电信股份有限公司 Data flow shunting method, device, equipment and medium
CN113992440A (en) * 2021-12-28 2022-01-28 北京安博通科技股份有限公司 Gateway equipment and method for transmitting local data into IPsec tunnel
CN114615080A (en) * 2022-03-30 2022-06-10 阿里巴巴(中国)有限公司 Remote communication method and device for industrial equipment and equipment

Also Published As

Publication number Publication date
CN114615080A (en) 2022-06-10
CN114615080B (en) 2023-12-05

Similar Documents

Publication Publication Date Title
WO2023185823A1 (en) Remote communication methods for industrial device, apparatuses and devices
EP3313025B1 (en) Data packet forwarding
US10110490B2 (en) Method and apparatus for forwarding packet
CN107646185B (en) Method, system and storage medium for operation maintenance management in an overlay environment
CN105577548B (en) Message processing method and device in a kind of software defined network
EP3282649B1 (en) Data packet forwarding
US20150358232A1 (en) Packet Forwarding Method and VXLAN Gateway
EP3001635B1 (en) Method, device and system for controlling access of user terminal
KR101938623B1 (en) Openflow communication method, system, controller, and service gateway
US11888818B2 (en) Multi-access interface for internet protocol security
JP2007215090A (en) Network system, terminal and gateway device
CN106101617A (en) A kind of message transmitting method, Apparatus and system
CN109547350B (en) Route learning method and gateway equipment
WO2020220459A1 (en) Vxlan and openflow-based method and system for sharing virtual home network
CN112565476A (en) Virtual machine creation method, ARP proxy gateway and VTEP
CN113938486B (en) Method for realizing bidirectional safety communication on unidirectional network for edge calculation
CN107733800A (en) A kind of SDN message transmitting method and its device
CN112887187B (en) Method, system, device, equipment and medium for establishing communication between equipment
CN109246016B (en) Cross-VXLAN message processing method and device
JP4996514B2 (en) Network system and message transfer method
CN106656810B (en) MAC address learning method and device
CN116436731B (en) Multi-internal network two-layer data stream communication method
WO2024188167A1 (en) Tunnel technology-based packet processing method and apparatus
US20230117218A1 (en) Cloud-edge forwarding in a network
US11870685B2 (en) Packet capsulation method and packet capsulation device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23778188

Country of ref document: EP

Kind code of ref document: A1