CN105744555A - Terminal maintenance method, maintenance device and network management server - Google Patents

Terminal maintenance method, maintenance device and network management server Download PDF

Info

Publication number
CN105744555A
CN105744555A CN201410767645.8A CN201410767645A CN105744555A CN 105744555 A CN105744555 A CN 105744555A CN 201410767645 A CN201410767645 A CN 201410767645A CN 105744555 A CN105744555 A CN 105744555A
Authority
CN
China
Prior art keywords
terminal
attending device
server
mark
sending
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201410767645.8A
Other languages
Chinese (zh)
Other versions
CN105744555B (en
Inventor
杨宇
程金松
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN201410767645.8A priority Critical patent/CN105744555B/en
Publication of CN105744555A publication Critical patent/CN105744555A/en
Application granted granted Critical
Publication of CN105744555B publication Critical patent/CN105744555B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Mobile Radio Communication Systems (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The invention discloses a terminal maintenance method, a maintenance device and a network management server. The method comprises steps that a connection authentication request is sent by the maintenance device to the network management server, and legality of the maintenance device is verified by the network management server; if the verification result is yes, an identification of a first terminal is sent by the maintenance device to the network management server, and the network management server is set in the connection management authority of the maintenance device for the first terminal; connection and management control on the first terminal is carried out by the maintenance device on the basis of the connection management authority. Through the method, the maintenance process becomes more convenient, and the time is further saved.

Description

A kind of terminal maintenance method, attending device and NM server
Technical field
The present invention relates to communication technical field, particularly relate to a kind of terminal maintenance method, attending device and NM server.
Background technology
Due to the mobility of mobile terminal, so the physical location of mobile terminal can often change, even can move in the world, as: smart mobile phone, car-mounted terminal, Shipborne terminal etc., this will bring extreme difficulties to the maintenance of mobile terminal.Conventional maintenance method returns factory repair after it is frequently necessary to attendant's on-site maintenance or removing, when attendant's distance safeguard on-the-spot distant or faulty equipment from producer distant time, all will be greatly increased and safeguard duration so that maintenance process is convenient not, save the time not.
Summary of the invention
The embodiment of the present invention provides a kind of terminal maintenance method, attending device and NM server, it is possible to makes maintenance process become more convenient, and saves the time.
First aspect present invention provides a kind of terminal maintenance method, including:
Attending device sends connection certification and asks NM server, so that described NM server verifies the legitimacy of described attending device;
When the result is legal, the mark of first terminal is sent to described NM server by described attending device, so that described NM server arranges the described attending device connection management authority to described first terminal;
Described first terminal is attached based on set connection management authority and manages control by described attending device.
In the implementation that the first is possible, described first terminal is attached based on set connection management authority and manages control by described attending device, including:
Described attending device receives the Connecting quantity of the described first terminal that described NM server sends, and according to described Connecting quantity transmission connection request to described first terminal;
Described attending device receives the connection response that described first terminal returns, to set up the annexation with described first terminal;
Described attending device sends management control command to described first terminal, so that described first terminal responds described management control command.
In conjunction with first aspect, or the first possible implementation of first aspect, in the implementation that the second is possible, also include:
Described attending device generates mass-sending administration order, and obtains the mark of multiple second terminal;
Mark and the mass-sending administration order of the plurality of second terminal are sent to described NM server by described attending device, so that described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling.
Second aspect present invention provides a kind of terminal maintenance method, including:
NM server receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
When the result is legal, described NM server receives the mark of the first terminal that described attending device sends,
And the mark according to described first terminal arranges the described attending device connection management authority to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device.
In the implementation that the first is possible, the described mark according to described first terminal arranges the described attending device connection management authority to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device, including:
Described NM server sends security policy information to described first terminal according to the mark of described first terminal, so that described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information;
Described NM server obtains the Connecting quantity of described first terminal according to the mark of described first terminal;
Described NM server sends the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection according to described Connecting quantity and described first terminal, and it is managed controlling to described first terminal based on described connection management authority;
Wherein, described security policy information includes the mark of described attending device and described connection management authority.
In conjunction with second aspect, or the first possible implementation of second aspect, in the implementation that the second is possible, also include:
Described NM server receives the mark mass-sending administration order and multiple second terminal that described attending device sends;
The effectiveness of described mass-sending administration order and the mark of the plurality of second terminal is verified by described NM server;
When the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling.
Third aspect present invention provides a kind of attending device, including:
Certification sending module, is used for sending connection certification and asks NM server, so that described NM server verifies the legitimacy of described attending device;
Mark sending module, for when the result is legal, sending the mark of first terminal to described NM server, so that described NM server arranges the described attending device connection management authority to described first terminal;
Connection management module, for being attached described first terminal based on set connection management authority and managing control.
In the implementation that the first is possible, described connection management module includes:
Connect unit, for receiving the Connecting quantity of the described first terminal that described NM server sends, and according to described Connecting quantity transmission connection request to described first terminal;
Described connection unit, is additionally operable to receive the connection response that described first terminal returns, to set up the annexation with described first terminal;
Management control unit, is used for sending management control command to described first terminal, so that described first terminal responds described management control command.
In conjunction with the third aspect, or the first possible implementation of the third aspect, in the implementation that the second is possible, also include:
Generate acquisition module, be used for generating mass-sending administration order, and obtain the mark of multiple second terminal;
Mass-sending order sending module, for the mark of the plurality of second terminal and mass-sending administration order are sent to described NM server, so that described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling.
Fourth aspect present invention provides a kind of NM server, including:
Certification receiver module, for receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
Mark receiver module, for when the result is legal, receiving the mark of the first terminal that described attending device sends;
Module is set, for arranging the described attending device connection management authority to described first terminal according to the mark of described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device.
In the implementation that the first is possible, the described module that arranges includes:
Policy information transmitting element, sends security policy information to described first terminal for the mark according to described first terminal, so that described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information;
Connecting quantity acquiring unit, for obtaining the Connecting quantity of described first terminal according to the mark of described first terminal;
Connecting quantity transmitting element, for sending the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection according to described Connecting quantity and described first terminal, and it is managed controlling to described first terminal based on described connection management authority;
Wherein, described security policy information includes the mark of described attending device and described connection management authority.
In conjunction with fourth aspect, or the first possible implementation of fourth aspect, in the implementation that the second is possible, also include:
Command id receiver module, for receiving the mark mass-sending administration order and multiple second terminal that described attending device sends;
Validation verification module, for being verified the effectiveness of described mass-sending administration order and the mark of the plurality of second terminal;
Order sending module, for when the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, sending described mass-sending administration order to the plurality of second terminal, to be managed the plurality of second terminal controlling.
Therefore, by NM server, attending device is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time.
Accompanying drawing explanation
In order to be illustrated more clearly that the embodiment of the present invention or technical scheme of the prior art, the accompanying drawing used required in embodiment or description of the prior art will be briefly described below, apparently, accompanying drawing in the following describes is only some embodiments of the present invention, for those of ordinary skill in the art, under the premise not paying creative work, it is also possible to obtain other accompanying drawing according to these accompanying drawings.
Fig. 1 is the schematic flow sheet of a kind of terminal maintenance method that the embodiment of the present invention provides;
Fig. 2 is the schematic flow sheet of the another kind of terminal maintenance method that the embodiment of the present invention provides;
Fig. 3 is the time diagram of a kind of terminal maintenance method that the embodiment of the present invention provides;
Fig. 4 is the time diagram of the another kind of terminal maintenance method that the embodiment of the present invention provides;
Fig. 5 is the structural representation of a kind of attending device that the embodiment of the present invention provides;
Fig. 6 is the structural representation of a kind of connection management module that the embodiment of the present invention provides;
Fig. 7 is the structural representation of a kind of NM server that the embodiment of the present invention provides;
Fig. 8 is a kind of structural representation arranging module that the embodiment of the present invention provides;
Fig. 9 is the structural representation of the another kind of attending device that the embodiment of the present invention provides;
Figure 10 is the structural representation of the another kind of NM server that the embodiment of the present invention provides;
Figure 11 is the structural representation of a kind of terminal maintenance system that the embodiment of the present invention provides.
Detailed description of the invention
Below in conjunction with the accompanying drawing in the embodiment of the present invention, the technical scheme in the embodiment of the present invention is clearly and completely described, it is clear that described embodiment is only a part of embodiment of the present invention, rather than whole embodiments.Based on the embodiment in the present invention, the every other embodiment that those of ordinary skill in the art obtain under not making creative work premise, broadly fall into the scope of protection of the invention.
The terminal that described attending device involved by the embodiment of the present invention can use for attendant, namely may be used for the terminal safeguarded;NM server involved by the embodiment of the present invention can be the back-stage management server of a certain Terminal Type, such as, the car-mounted terminal of a certain type may be coupled to same NM server, and by the mark of NM server each car-mounted terminal of unified management, positional information etc.;Described first terminal and the plurality of second terminal involved by the embodiment of the present invention can be all need maintained terminal, and described first terminal and the plurality of second terminal are has annexation and the terminal being managed by described NM server with described NM server.
Referring to Fig. 1, be the schematic flow sheet of a kind of terminal maintenance method that the embodiment of the present invention provides, described method may include that
S101, attending device sends connection certification and asks NM server, so that described NM server verifies the legitimacy of described attending device;
Concrete, described attending device can pass through the Internet and remotely connect the NM server of certain system, before described attending device establishes a connection with described NM server, described attending device can first send connection certification and ask described NM server, described connection certification request carries the mark of described attending device, the mark of described attending device can include the equipment Serial Number of described attending device, user account etc., described NM server can according to the legitimacy of attending device described in the identity verification of described attending device, namely the legitimacy of the user that described attending device is corresponding is verified.It is alternatively possible to store legal terminal list in advance in described NM server, described legal terminal list includes the mark of multiple attending device with legitimacy.Described NM server is when verifying the legitimacy of described attending device, it is possible to that detects described attending device entrained in described connection certification request identifies whether exist in described legal terminal list, if existing, then certification is passed through, otherwise authentification failure.Wherein, when described NM server verify described attending device possess legitimacy time, described NM server can establish a connection with described attending device so that described attending device can add the mobile network at described NM server place.Wherein, described NM server can adopt any one authentication techniques common, and this is not limited by the present invention.
S102, when the result is legal, the mark of first terminal is sent to described NM server by described attending device, so that described NM server arranges the described attending device connection management authority to described first terminal;
Concrete, when the result is legal, illustrate that described attending device possesses legitimacy, described attending device can be successfully established annexation with described NM server, now, described attending device can receive the online terminal list that described NM server sends, described online terminal list can include multiple and described NM server to be had annexation and is in the mark of terminal of line states, such as, if described NM server is the background server in certain vehicle netbios, then the mark of the multiple terminals in described online terminal list can be the mark of multiple car-mounted terminals being currently running.After described attending device receives described online terminal list, described attending device can obtain the mark of the first terminal with described NM server with annexation from online terminal list.Attendant can also input the information needing maintained terminal on described attending device, and now, described attending device can obtain the mark of described first terminal from the information needing maintained terminal of attendant's input.The mark of first terminal can be serial number, or IMSI (InternationalMobileSubscriberIdentificationNumber, international mobile subscriber identity), or media interviews control (MediaAccessControl is called for short MAC) address etc..
Described attending device is after getting the mark of described first terminal, it is possible to send the mark of described first terminal to described NM server.After described NM server receives the mark of described first terminal, security policy information can be sent to described first terminal by described NM server, described first terminal is able to receive that and responds connection request and the management control command that described attending device sends, that is, described first terminal can arrange the described attending device connection management authority to described first terminal according to described security policy information.Described security policy information can include the mark of described attending device and described connection management authority, described security policy information can be based on access and control list (AccessControlList, it is called for short ACL) or the self-defining command format of system, it is achieved the described attending device connection management authority to described first terminal.
S103, described first terminal is attached based on set connection management authority and manages control by described attending device;
Concrete, described attending device can receive the Connecting quantity of the described first terminal that described NM server sends, and generates and sends connection request to described first terminal further according to described Connecting quantity.Described Connecting quantity is accessed according to the mark of described first terminal by described NM server, and described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.
Described attending device receives the connection response that described first terminal returns again, to set up the annexation with described first terminal.Wherein, described attending device may include that Telnet (remote terminal protocol), containment agreement (SecureShell is called for short SSH), Web (the Internet) or other modes with the connected mode of described first terminal.Described connection response is generated based on described connection management authority by described first terminal.
After described attending device and described first terminal establish annexation, described attending device can send management control command to the first terminal with described attending device with annexation, so that described first terminal responds described management control command according to described connection management authority, described attending device obtains and shows the described first terminal command response message to described management control command, and described command response message can include the fault message of described first terminal, configuration information, log information etc..
Alternatively, when described NM server detects that described attending device actively exits or extremely exits the mobile network at described NM server place, described NM server can send for the order cancelling security policy information to described first terminal, so that described first terminal can cancel the described attending device connection management authority to described first terminal, to prevent other users illegal control to described first terminal.Wherein, the situation that described exception exits may include that when the duration described first terminal not being managed control when described attending device exceedes default duration threshold value, and described NM server controls described attending device and exits the mobile network at described NM server place.
The described method that the embodiment of the present invention provides is possible not only to the point-to-point monitor model including the described attending device described by above-mentioned S101 to S103 to described first terminal, and described method can also include the following attending device point-to-multipoint monitor model to multiple second terminals.Specifically, described method also includes:
Described attending device generates mass-sending administration order, and obtains the mark of multiple second terminal;
Mark and the mass-sending administration order of the plurality of second terminal are sent to described NM server by described attending device, so that described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling;
Concrete, described attending device can generate mass-sending administration order, the management control command that described mass-sending administration order can send for multicast mode, it is also possible to the many parts of management control commands that mode of unicast sends.It is identical with the mode of the mark that described attending device obtains described first terminal that described attending device obtains the mode of the mark of the plurality of second terminal;Can obtain from the online terminal list that described NM server provides, it is also possible to from the information needing maintained terminal of attendant's input, obtain the mark of the plurality of second terminal, be not discussed here.
Described attending device is after getting the mark of the plurality of second terminal, it is possible to send the mark of the plurality of second terminal and mass-sending administration order to described NM server in the lump.Described NM server verifies the mark of the plurality of second terminal and when described mass-sending administration order is respectively provided with effectiveness, described NM server can send described mass-sending administration order to the plurality of second terminal, so that described mass-sending administration order is carried out resolving and response command operation by each second terminal respectively.
Further, described attending device can also receive and show and mass-send the command response result that administration order returns described in each second terminal response.Described command response result can include fault message, configuration information, log information etc..
Described point-to-point monitor model is applicable to certain is needed maintained terminal to detect, the operation such as reconfigures, and described point-to-multipoint monitor model is applicable to the terminal that multiple needs are maintained is carried out the operations such as identical configuration, detection.
Therefore, by NM server, attending device is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time;Meanwhile, first terminal can be controlled by attendant without the device password and address knowing first terminal, and first terminal can be controlled by attendant without the assistance of network manager, thus further increasing maintenance efficiency;Multiple second terminals can also be carried out identical attended operation by described NM server by described attending device simultaneously, and this mode is effectively improved maintenance efficiency especially.
Referring to Fig. 2 again, be the schematic flow sheet of another terminal maintenance method that the embodiment of the present invention provides, described method may include that
S201, NM server receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
Concrete, described attending device can pass through the Internet and remotely connect the NM server of certain system, before described attending device establishes a connection with described NM server, described NM server can receive the connection certification request that attending device is sent to, described connection certification request carries the mark of described attending device, the mark of described attending device can include the equipment Serial Number of attending device, user account etc., described NM server can according to the legitimacy of attending device described in the identity verification of described attending device, namely the legitimacy of the user that described attending device is corresponding is verified.It is alternatively possible to store legal terminal list in advance in described NM server, described legal terminal list includes the mark of multiple attending device with legitimacy.Described NM server is when verifying the legitimacy of described attending device, it is possible to that detects described attending device entrained in described connection certification request identifies whether exist in described legal terminal list, if existing, then certification is passed through, otherwise authentification failure.Wherein, when described NM server verify described attending device possess legitimacy time, described NM server can establish a connection with described attending device so that described attending device can add the mobile network at described NM server place.Wherein, described NM server can adopt any one authentication techniques common, and this is not limited by the present invention.
S202, when the result is legal, described NM server receives the mark of the attending device that described attending device sends;
Concrete, when described attending device possesses legitimacy, described attending device and described NM server are successfully established annexation, and now, described NM server can receive the mark of the first terminal with described NM server with annexation that described attending device gets.Described NM server is before receiving the mark of the described first terminal that described attending device sends, described NM server can first send online terminal list to described attending device, described online terminal list can include multiple and described NM server to be had annexation and is in the mark of terminal of line states, such as, if described NM server is the background server in certain vehicle netbios, then the mark of the multiple terminals in described online terminal list can be the mark of multiple car-mounted terminals being currently running.After described attending device receives described online terminal list, described attending device can obtain the mark of the first terminal with described NM server with annexation from online terminal list.Attendant can also input the information needing maintained terminal on described attending device, and now, described attending device can obtain the mark of described first terminal from the information needing maintained terminal of attendant's input.The mark of first terminal can be serial number, or IMSI, or media access control address etc..Described attending device is after getting the mark of described first terminal, and described NM server can receive the mark of the described first terminal that described attending device sends.
S203, arranges the described attending device connection management authority to described first terminal according to the mark of described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device;
Concrete, it is legal at the result, and described NM server receive described first terminal mark after, described NM server can according to the mark transmission security policy information of described first terminal to described first terminal, described first terminal is able to receive that and responds connection request and the management control command that described attending device sends, that is, described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information.Described security policy information includes the mark of described attending device and described connection management authority, described security policy information can be based on access and control list or the self-defining command format of system, it is achieved the described attending device connection management authority to described first terminal.
Described NM server is while sending described security policy information, described NM server can also obtain the Connecting quantity of described first terminal according to the mark of described first terminal, and send the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection based on described connection management authority and according to described Connecting quantity and described first terminal, described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.After described attending device and described first terminal establish annexation, described attending device can send management control command to the first terminal with described attending device with annexation, so that described first terminal responds described management control command according to described connection management authority.
Alternatively, when described NM server detects that described attending device actively exits or extremely exits the mobile network at described NM server place, namely, when detecting that the connection with described first terminal of the described attending device disconnects, described NM server can cancel the set described attending device connection management authority to described first terminal.The detailed process cancelling described connection management authority can be: described NM server can send for the order cancelling security policy information to described first terminal, so that described first terminal can cancel the described attending device connection management authority to described first terminal, to prevent other users illegal control to described first terminal.Wherein, the situation that described exception exits may include that when the duration described first terminal not being managed control when described attending device exceedes default duration threshold value, and described NM server controls described attending device and exits the mobile network at described NM server place.
The described method that the embodiment of the present invention provides is possible not only to the point-to-point monitor model including the described attending device described by above-mentioned S201 to S203 to described first terminal, and described method can also include the following attending device point-to-multipoint monitor model to multiple second terminals.Specifically, described method also includes: described NM server receives the mark mass-sending administration order and multiple second terminal that described attending device sends;
The effectiveness of described mass-sending administration order and the mark of the plurality of second terminal is verified by described NM server;
When the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling;
Concrete, described NM server can receive the mark mass-sending administration order and multiple second terminal that described attending device sends, the management control command that described mass-sending administration order can send for multicast mode, it is also possible to the many parts of management control commands that mode of unicast sends.Wherein, the mode of the mark of the plurality of second terminal of described attending device acquisition is identical with the mode of the mark that described attending device obtains described first terminal;Can obtain from the online terminal list that described NM server provides, it is also possible to from the information needing maintained terminal of attendant's input, obtain the mark of the plurality of second terminal, be not discussed here.
After described NM server receives the mark mass-sending administration order and multiple second terminal that described attending device sends, it is possible to the effectiveness of described mass-sending administration order and the mark of the plurality of second terminal is verified;When the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, described NM server can send described mass-sending administration order to the plurality of second terminal, so that described mass-sending administration order is carried out resolving and response command operation by each second terminal respectively.
Further, described NM server can also receive mass-sends the command response result that administration order returns described in each second terminal response in the plurality of second terminal, each command response result is sent to described attending device by described NM server again, so that described attending device can show each command response result described.Described command response result can include fault message, configuration information, log information etc..
Described point-to-point monitor model is applicable to certain is needed maintained terminal to detect, the operation such as reconfigures, and described point-to-multipoint monitor model is applicable to the terminal that multiple needs are maintained is carried out the operations such as identical configuration, detection.
Therefore, by NM server, attending device is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time;Meanwhile, first terminal can be controlled by attendant without the device password and address knowing first terminal, and first terminal can be controlled by attendant without the assistance of network manager, thus further increasing maintenance efficiency;Multiple second terminals can also be carried out identical attended operation by described NM server by described attending device simultaneously, and this mode is effectively improved maintenance efficiency especially.
Refer to Fig. 3, be the time diagram of a kind of terminal maintenance method that provides of the embodiment of the present invention, the embodiment of the present invention from attending device side, first terminal side, NM server side jointly set forth the idiographic flow of terminal maintenance method, described method may include that
S301, described attending device sends to described NM server and connects certification request;
S302, described NM server sends authentication response by message to described attending device;
Concrete, when described NM server passes through the certification to described attending device, it is possible to send authentication response by message to described attending device, to inform that described attending device certification has passed through, meanwhile, described NM server can establish a connection with described attending device.
S303, described attending device sends online terminal list and asks described NM server;
S304, described NM server is according to the described online terminal list request online terminal list of transmission to described attending device;
Wherein, described online terminal list can include multiple and described NM server and has annexation and be in the mark of terminal of line states.
S305, described attending device obtains the mark of first terminal from online terminal list or input information;
S306, the mark getting described first terminal is sent to described NM server by described attending device;
S307, security policy information is sent to described first terminal by described NM server according to the mark of described first terminal;
Wherein, described security policy information includes the mark of described attending device and described connection management authority.
S308, described first terminal arranges connection management authority according to described security policy information;
Concrete, described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information so that described first terminal is able to receive that and responds connection request and the management control command of described attending device transmission.
S309, described NM server sends the Connecting quantity of first terminal to described attending device;
Concrete, described NM server first obtains the Connecting quantity of described first terminal according to the mark of described first terminal, then the Connecting quantity of described first terminal is sent to described attending device.Described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.S309 step and S307 step can perform simultaneously.
S310, described attending device generates connection request according to the Connecting quantity of described first terminal, and sends described connection request to described first terminal;
S311, described connection request is responded by described first terminal based on described connection management authority, to establish a connection with described attending device;
S312, described first terminal is managed controlling by described attending device;
Concrete, described attending device can send management control command to described attending device, so that described first terminal responds described management control command according to described connection management authority.
S313, described attending device sends and exits request to described NM server;
S314, described NM server sends removes security policy information to described first terminal;
Concrete, described NM server detects when described attending device to exit connection, and described NM server can send removal security policy information to described first terminal.
S315, described first terminal cancels connection management authority according to described removal security policy information;
Concrete, described first terminal can delete described security policy information according to described removal security policy information, to cancel the described attending device connection management authority to described first terminal.
S316, the request of exiting of described attending device is responded by described NM server, to disconnect the connection with described attending device.
Refer to Fig. 4, it it is the time diagram of a kind of terminal maintenance method that the embodiment of the present invention provides, the embodiment of the present invention from attending device side, multiple second end side, NM server side jointly set forth the idiographic flow of terminal maintenance method, the embodiment of the present invention is for two the second terminals, and described method may include that
S401, described attending device sends to described NM server and connects certification request;
S402, described NM server sends authentication response by message to described attending device;
Concrete, when described NM server passes through the certification to described attending device, it is possible to send authentication response by message to described attending device, to inform that described attending device certification has passed through, meanwhile, described NM server can establish a connection with described attending device.
S403, described attending device sends online terminal list and asks described NM server;
S404, described NM server is according to the described online terminal list request online terminal list of transmission to described attending device;
Wherein, described online terminal list can include multiple and described NM server and has annexation and be in the mark of terminal of line states.
S405, described attending device obtains the mark of multiple second terminal from online terminal list or input information;
S406, described attending device sends the mark of the plurality of second terminal and mass-sending administration order to described NM server;
S407, described mass-sending administration order is sent to the second terminal by described NM server;
S408, described mass-sending administration order is sent to the second terminal by described NM server;
Concrete, S407 and S408 performs simultaneously, wherein, the quantity of the plurality of second terminal is 2, described NM server is when verifying selected two the second terminal and mass-sending administration order is to have effectiveness, and described mass-sending administration order is respectively sent to two the second terminals by described NM server.
S409, the second terminal feedback command response result is to described NM server;
S410, the second terminal feedback command response result is to described NM server;
Concrete, S409 step and S410 step are that described mass-sending administration order is responded by two the second terminals respectively, and to obtain command response result, corresponding command response result is sent to described NM server by two the second terminals respectively.
S411, each command response result is fed back to described attending device by described NM server;
S412, described attending device sends and exits request to described NM server;
S413, the request of exiting of described attending device is responded by described NM server, to disconnect the connection with described attending device.
Alternatively, any instant after step S404, it is also possible to synchronize to perform the S305-S316 in above-mentioned Fig. 3 correspondence embodiment;Similarly, any instant after the step S304 in above-mentioned Fig. 3 correspondence embodiment, it is also possible to synchronize to perform S405-S413.
Referring to Fig. 5, be the structural representation of a kind of attending device that the embodiment of the present invention provides, described attending device 1 may include that certification sending module 11, mark sending module 12, connection management module 13;
Described certification sending module 11, is used for sending connection certification and asks NM server, so that described NM server verifies the legitimacy of described attending device 1;
Concrete, described attending device 1 can pass through the Internet and remotely connect the NM server of certain system, before described attending device 1 establishes a connection with described NM server, described certification sending module 11 can first send connection certification and ask described NM server, described connection certification request carries the mark of described attending device 1, the mark of described attending device 1 can include the equipment Serial Number of attending device 1, user account etc., described NM server can according to the legitimacy of attending device 1 described in the identity verification of described attending device 1, namely the legitimacy of the user of described attending device 1 correspondence is verified.It is alternatively possible to store legal terminal list in advance in described NM server, described legal terminal list includes the mark of multiple attending device 1 with legitimacy.Described NM server is when verifying the legitimacy of described attending device 1, it is possible to that detects described attending device 1 entrained in described connection certification request identifies whether exist in described legal terminal list, if existing, then certification is passed through, otherwise authentification failure.Wherein, when described NM server verify described attending device 1 possess legitimacy time, described NM server can establish a connection with described attending device 1 so that described attending device 1 can add the mobile network at described NM server place.Wherein, described NM server can adopt any one authentication techniques common, and this is not limited by the present invention.
Described mark sending module 12, for when the result is legal, sending the mark of first terminal to described NM server, so that described NM server arranges the described attending device 1 connection management authority to described first terminal;
Concrete, when the result is legal, illustrate that described attending device 1 possesses legitimacy, described attending device 1 can be successfully established annexation with described NM server, now, described mark sending module 12 can receive the online terminal list that described NM server sends, described online terminal list can include multiple and described NM server to be had annexation and is in the mark of terminal of line states, such as, if described NM server is the background server in certain vehicle netbios, then the mark of the multiple terminals in described online terminal list can be the mark of multiple car-mounted terminals being currently running.After described mark sending module 12 receives described online terminal list, described mark sending module 12 can obtain the mark of the first terminal with described NM server with annexation from online terminal list.Attendant can also input the information needing maintained terminal on described attending device 1, and now, described mark sending module 12 can obtain the mark of described first terminal from the information needing maintained terminal of attendant's input.The mark of first terminal can be serial number, or IMSI, or media access control address etc..
Described mark sending module 12 is after getting the mark of described first terminal, it is possible to send the mark of described first terminal to described NM server.After described NM server receives the mark of described first terminal, security policy information can be sent to described first terminal by described NM server, described first terminal is able to receive that and responds connection request and the management control command that described attending device 1 sends, that is, described first terminal can arrange the described attending device 1 connection management authority to described first terminal according to described security policy information.Described security policy information can include the mark of described attending device 1 and described connection management authority, described security policy information can be based on access and control list or the self-defining command format of system, it is achieved the described attending device connection management authority to described first terminal.
Described connection management module 13, for being attached described first terminal based on set connection management authority and managing control;
Concrete, described connection management module 13 can receive the Connecting quantity of the described first terminal that described NM server sends, and generates and sends connection request to described first terminal further according to described Connecting quantity.Described Connecting quantity is accessed according to the mark of described first terminal by described NM server, and described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.
Described connection management module 13 receives the connection response that described first terminal returns again, to set up the annexation with described first terminal.Wherein, described attending device 1 may include that Telnet, containment agreement, Web or other modes with the connected mode of described first terminal.Described connection response is generated based on described connection management authority by described first terminal.
After described connection management module 13 and described first terminal establish annexation, described connection management module 13 can send management control command to the first terminal with described attending device 1 with annexation, so that described first terminal responds described management control command according to described connection management authority, described connection management module 13 obtains and shows the described first terminal command response message to described management control command, and described command response message can include the fault message of described first terminal, configuration information, log information etc..
Alternatively, when described NM server detects that described attending device 1 actively exits or extremely exits the mobile network at described NM server place, described NM server can send for the order cancelling security policy information to described first terminal, so that described first terminal can cancel the described attending device 1 connection management authority to described first terminal, to prevent other users illegal control to described first terminal.Wherein, the situation that described exception exits may include that when the duration described first terminal not being managed control when described attending device 1 exceedes default duration threshold value, and described NM server controls described attending device 1 and exits the mobile network at described NM server place.
Further, described attending device 1 can also include: generates acquisition module 14, mass-sending order sending module 15;
Described generation acquisition module 14, is used for generating mass-sending administration order, and obtains the mark of multiple second terminal;
Concrete, described generation acquisition module 14 can generate mass-sending administration order, the management control command that described mass-sending administration order can send for multicast mode, it is also possible to the many parts of management control commands that mode of unicast sends.It is identical with the mode of the mark that described attending device 1 obtains described first terminal that described generation acquisition module 14 obtains the mode of the mark of the plurality of second terminal;Can obtain from the online terminal list that described NM server provides, it is also possible to from the information needing maintained terminal of attendant's input, obtain the mark of the plurality of second terminal, be not discussed here.
Described mass-sending order sending module 15, for the mark of the plurality of second terminal and mass-sending administration order are sent to described NM server, so that described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling;
Concrete, described generation acquisition module 14 is after getting the mark of the plurality of second terminal, and the mark of the plurality of second terminal and mass-sending administration order can be sent to described NM server by described mass-sending order sending module 15 in the lump.Described NM server verifies the mark of the plurality of second terminal and when described mass-sending administration order is respectively provided with effectiveness, described NM server can send described mass-sending administration order to the plurality of second terminal, so that described mass-sending administration order is carried out resolving and response command operation by each second terminal respectively.
Further, described attending device 1 can also receive and show and mass-send the command response result that administration order returns described in each second terminal response.Described command response result can include fault message, configuration information, log information etc..
Further, then referring to Fig. 6, be the structural representation of a kind of connection management module 13 that the embodiment of the present invention provides, described connection management module 13 may include that
Connect unit 131, for receiving the Connecting quantity of the described first terminal that described NM server sends, and according to described Connecting quantity transmission connection request to described first terminal;
Wherein, described Connecting quantity is accessed according to the mark of described first terminal by described NM server, and described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.
Described connection unit 131, is additionally operable to receive the connection response that described first terminal returns, to set up the annexation with described first terminal;
Management control unit 132, is used for sending management control command to described first terminal, so that described first terminal responds described management control command;
Concrete, described management control unit 132 can send management control command to the first terminal with described attending device 1 with annexation, so that described first terminal responds described management control command according to described connection management authority, described management control unit 132 can also obtain and show that described first terminal responds the command response result that described management control command returns, and described command response result can include fault message, configuration information, log information etc..
Therefore, by NM server, attending device 1 is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device 1 by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time;Meanwhile, first terminal can be controlled by attendant without the device password and address knowing first terminal, and first terminal can be controlled by attendant without the assistance of network manager, thus further increasing maintenance efficiency;Multiple second terminals can also be carried out identical attended operation by described NM server by described attending device 1 simultaneously, and this mode is effectively improved maintenance efficiency especially.
Referring to Fig. 7, be the structural representation of a kind of NM server that the embodiment of the present invention provides, described NM server 2 may include that certification receiver module 21, mark receiver module 22, arranges module 23;
Described certification receiver module 21, for receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
Concrete, described attending device can pass through the Internet and remotely connect the NM server 2 of certain system, before described attending device establishes a connection with described NM server 2, described certification receiver module 21 can receive the connection certification request that attending device is sent to, described connection certification request carries the mark of described attending device, the mark of described attending device can include the equipment Serial Number of attending device, user account etc., described certification receiver module 21 can according to the legitimacy of attending device described in the identity verification of described attending device, namely the legitimacy of the user that described attending device is corresponding is verified.It is alternatively possible to store legal terminal list in advance in described NM server 2, described legal terminal list includes the mark of multiple attending device with legitimacy.Described certification receiver module 21 is when verifying the legitimacy of described attending device, it is possible to that detects described attending device entrained in described connection certification request identifies whether exist in described legal terminal list, if existing, then certification is passed through, otherwise authentification failure.Wherein, when described certification receiver module 21 verify described attending device possess legitimacy time, described NM server 2 can establish a connection with described attending device so that described attending device can add the mobile network at described NM server 2 place.Wherein, described NM server 2 can adopt any one authentication techniques common, and this is not limited by the present invention.
Described mark receiver module 22, for when the result is legal, receiving the mark of the first terminal that described attending device sends;
Concrete, when described attending device possesses legitimacy, described attending device and described NM server 2 are successfully established annexation, and now, described mark receiver module 22 can receive the mark of the first terminal with described NM server 2 with annexation that described attending device gets.Described mark receiver module 22 is before receiving the mark of the described first terminal that described attending device sends, described mark receiver module 22 can first send online terminal list to described attending device, described online terminal list can include multiple and described NM server 2 to be had annexation and is in the mark of terminal of line states, such as, if described NM server 2 is the background server 2 in certain vehicle netbios, then the mark of the multiple terminals in described online terminal list can be the mark of multiple car-mounted terminals being currently running.After described attending device receives described online terminal list, described attending device can obtain the mark of the first terminal with described NM server 2 with annexation from online terminal list.Attendant can also input the information needing maintained terminal on described attending device, and now, described attending device can obtain the mark of described first terminal from the information needing maintained terminal of attendant's input.The mark of first terminal can be serial number, or IMSI, or media access control address etc..Described attending device is after getting the mark of described first terminal, and described mark receiver module 22 can receive the mark of the described first terminal that described attending device sends.
Described module 23 is set, the described attending device connection management authority to described first terminal is set for the mark according to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device;
Concrete, it is legal at the result, and described mark receiver module 22 receive described first terminal mark after, the described module 23 that arranges can according to the mark transmission security policy information of described first terminal to described first terminal, described first terminal is able to receive that and responds connection request and the management control command that described attending device sends, that is, described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information.Described security policy information includes the mark of described attending device and described connection management authority, described security policy information can be based on access and control list or the self-defining command format of system, it is achieved the described attending device connection management authority to described first terminal.
The described module 23 that arranges is while sending described security policy information, the described module 23 that arranges can also obtain the Connecting quantity of described first terminal according to the mark of described first terminal, and send the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection based on described connection management authority and according to described Connecting quantity and described first terminal, described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.After described attending device and described first terminal establish annexation, described attending device can send management control command to the first terminal with described attending device with annexation, so that described first terminal responds described management control command according to described connection management authority.
Alternatively, when described NM server 2 detects that described attending device actively exits or extremely exits the mobile network at described NM server 2 place, namely, when detecting that the connection with described first terminal of the described attending device disconnects, the described module 23 that arranges can cancel the set described attending device connection management authority to described first terminal.The detailed process cancelling described connection management authority can be: the described module 23 that arranges can send for the order cancelling security policy information to described first terminal, so that described first terminal can cancel the described attending device connection management authority to described first terminal, to prevent other users illegal control to described first terminal.Wherein, the situation that described exception exits may include that when the duration described first terminal not being managed control when described attending device exceedes default duration threshold value, described NM server 2 controls described attending device and exits the mobile network at described NM server 2 place.
Further, described NM server 2 can also include: command id receiver module 24, validation verification module 25, order sending module 26;
Described command id receiver module 24, for receiving the mark mass-sending administration order and multiple second terminal that described attending device sends;
Concrete, described command id receiver module 24 can receive the mark mass-sending administration order and multiple second terminal that described attending device sends, the management control command that described mass-sending administration order can send for multicast mode, it is also possible to the many parts of management control commands that mode of unicast sends.Wherein, the mode of the mark of the plurality of second terminal of described attending device acquisition is identical with the mode of the mark that described attending device obtains described first terminal;Can obtain from the online terminal list that described NM server 2 provides, it is also possible to from the information needing maintained terminal of attendant's input, obtain the mark of the plurality of second terminal, be not discussed here.
Described validation verification module 25, for being verified the effectiveness of described mass-sending administration order and the mark of the plurality of second terminal;
Described order sending module 26, during for being respectively provided with effectiveness when the mark verifying described mass-sending administration order and the plurality of second terminal, described mass-sending administration order is sent to the plurality of second terminal, to be managed the plurality of second terminal controlling;
Concrete, after described command id receiver module 24 receives the mark mass-sending administration order and multiple second terminal that described attending device sends, the effectiveness of described mass-sending administration order and the mark of the plurality of second terminal can be verified by described validation verification module 25;When the mark that described validation verification module 25 verifies described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, described order sending module 26 can send described mass-sending administration order to the plurality of second terminal, so that described mass-sending administration order is carried out resolving and response command operation by each second terminal respectively.
Further, described NM server 2 can also receive mass-sends the command response result that administration order returns described in each second terminal response in the plurality of second terminal, each command response result is sent to described attending device by described NM server 2 again, so that described attending device can show each command response result described.Described command response result can include fault message, configuration information, log information etc..
Further, then referring to Fig. 8, be a kind of structural representation arranging module 23 of embodiment of the present invention offer, the described module 23 that arranges may include that
Policy information transmitting element 231, sends security policy information to described first terminal for the mark according to described first terminal, so that described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information;
Wherein, described security policy information includes the mark of described attending device and described connection management authority, and described security policy information can be based on acl rule or the self-defining command format of system of standard.
Connecting quantity acquiring unit 232, for obtaining the Connecting quantity of described first terminal according to the mark of described first terminal;
Wherein, described Connecting quantity can include the mobile communication information such as the address of described first terminal, port, IMSI number.
Connecting quantity transmitting element 233, for sending the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection according to described Connecting quantity and described first terminal, and it is managed controlling to described first terminal based on described connection management authority.
Therefore, by NM server 2, attending device is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time;Meanwhile, first terminal can be controlled by attendant without the device password and address knowing first terminal, and first terminal can be controlled by attendant without the assistance of network manager, thus further increasing maintenance efficiency;Multiple second terminals can also be carried out identical attended operation by described NM server 2 by described attending device simultaneously, and this mode is effectively improved maintenance efficiency especially.
Refer to Fig. 9, it it is the structural representation of the another kind of attending device that the embodiment of the present invention provides, described attending device 1000 can include processor 1001, communication interface 1002 and memorizer 1003 (quantity of the processor 1001 in attending device 1000 can be one or more, for a processor 1001 in Fig. 9).In some embodiments of the present invention, processor 1001, communication interface 1002 and memorizer 1003 can be connected by communication bus or other modes, and wherein, Fig. 9 is to be connected as example by communication bus.
Wherein, described communication interface 1002, for communicating with NM server and first terminal;
Described memorizer 1003 is used for storing program;Specifically, program can include program code, and described program code includes computer-managed instruction.Memorizer 1003 is likely to comprise random access memory (randomaccessmemory is called for short RAM), it is also possible to also include nonvolatile memory (non-volatilememory), for instance at least one disk memory.
Described processor 1001 is used for performing described program, to realize the terminal maintenance method that the embodiment of the present invention provides, including:
Send connection certification and ask NM server, so that described NM server verifies the legitimacy of described attending device;
When the result is legal, the mark of first terminal is sent to described NM server, so that described NM server arranges the described attending device connection management authority to described first terminal;
Based on set connection management authority described first terminal it is attached and manages control.
Wherein, described based on set connection management authority, described first terminal it be attached and manage control, specifically including:
Receive the Connecting quantity of the described first terminal that described NM server sends, and according to described Connecting quantity transmission connection request to described first terminal;
Receive the connection response that described first terminal returns, to set up the annexation with described first terminal;
Send management control command to described first terminal, so that described first terminal responds described management control command.
Further, described method also includes:
Generate mass-sending administration order, and obtain the mark of multiple second terminal;
The mark of the plurality of second terminal and mass-sending administration order are sent to described NM server, so that described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling.
Above-mentioned processor 1001 can be general processor, including central processing unit (CentralProcessingUnit is called for short CPU), network processing unit (NetworkProcessor is called for short NP) etc.;Can also is that digital signal processor (DSP), special IC (ASIC), field programmable gate array (FPGA) or other PLDs, discrete gate or transistor logic, discrete hardware components.
Therefore, by NM server, attending device 1000 is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device 1000 by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time;Meanwhile, first terminal can be controlled by attendant without the device password and address knowing first terminal, and first terminal can be controlled by attendant without the assistance of network manager, thus further increasing maintenance efficiency;Multiple second terminals can also be carried out identical attended operation by described NM server by described attending device 1000 simultaneously, and this mode is effectively improved maintenance efficiency especially.
Refer to Figure 10, it it is the structural representation of the another kind of NM server that the embodiment of the present invention provides, described NM server 2000 can include processor 2001, communication interface 2002 and memorizer 2003 (quantity of the processor 2001 in NM server 2000 can be one or more, for a processor 2001 in Figure 10).In some embodiments of the present invention, processor 2001, communication interface 2002 and memorizer 2003 can be connected by communication bus or other modes, and wherein, Figure 10 is to be connected as example by communication bus.
Wherein, described communication interface 2002, for communicating with attending device, first terminal and multiple second terminal;
Described memorizer 2003 is used for storing program;Specifically, program can include program code, and described program code includes computer-managed instruction.Memorizer 2003 is likely to comprise RAM, it is also possible to also include nonvolatile memory, for instance at least one disk memory.
Described processor 2001 is used for performing described program, to realize the terminal maintenance method that the embodiment of the present invention provides, including:
Receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
When the result is legal, receive the mark of the first terminal that described attending device sends,
And the mark according to described first terminal arranges the described attending device connection management authority to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device.
Wherein, the described mark according to described first terminal arranges the described attending device connection management authority to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device, including:
Mark according to described first terminal sends security policy information to described first terminal, so that described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information;
Mark according to described first terminal obtains the Connecting quantity of described first terminal;
Send the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection according to described Connecting quantity and described first terminal, and be managed controlling to described first terminal based on described connection management authority;
Wherein, described security policy information includes the mark of described attending device and described connection management authority.
Further, described method also includes:
Receive the mark mass-sending administration order and multiple second terminal that described attending device sends;
The effectiveness of described mass-sending administration order and the mark of the plurality of second terminal is verified;
When the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, described mass-sending administration order is sent to the plurality of second terminal, to be managed the plurality of second terminal controlling.
Above-mentioned processor 2001 can be general processor, including central processing unit, network processing unit etc.;Can also is that digital signal processor (DSP), special IC (ASIC), field programmable gate array (FPGA) or other PLDs, discrete gate or transistor logic, discrete hardware components.
Therefore, by NM server 2000, attending device is authenticated, and after certification is passed through, can be managed controlling to first terminal by attending device by attendant, attendant is made to safeguard without arriving maintenance scene again, return factory repair again without after being removed by first terminal, so that maintenance process becomes more convenient, and save the time;Meanwhile, first terminal can be controlled by attendant without the device password and address knowing first terminal, and first terminal can be controlled by attendant without the assistance of network manager, thus further increasing maintenance efficiency;Multiple second terminals can also be carried out identical attended operation by described NM server 2000 by described attending device simultaneously, and this mode is effectively improved maintenance efficiency especially.
Refer to Figure 11, it it is the structural representation of a kind of terminal maintenance system that the embodiment of the present invention provides, described system can include attending device, NM server, first terminal and multiple second terminal, described attending device can pass through the Internet and described NM server and the communication connection of described first terminal, and described NM server can pass through the Internet and be connected with described first terminal and the plurality of second terminal communication.The structure of described attending device in described system, function and the structure of attending device 1 described by Fig. 5, function are identical;The structure of the NM server in described system, function and the structure of NM server 2 described by Fig. 7, function are identical;The embodiment of the present invention does not repeat.Or, the structure of described attending device in described system, function and the structure of attending device 1000 described by Fig. 9, function are identical;The structure of the NM server in described system, function and the structure of NM server 2000 described by Figure 10, function are identical;The embodiment of the present invention does not repeat.
Wherein, described first terminal in described system can arrange the described attending device connection management authority to described first terminal according to the security policy information that described NM server sends so that described first terminal can be attached and manage control by described attending device.The plurality of second terminal in described system can receive the mass-sending administration order that described NM server forwards, and described mass-sending administration order is responded so that the plurality of second terminal can be managed controlling by described NM server by described attending device.
One of ordinary skill in the art will appreciate that all or part of flow process realizing in above-described embodiment method, can be by the hardware that computer program carrys out instruction relevant to complete, described program can be stored in a computer read/write memory medium, this program is upon execution, it may include such as the flow process of the embodiment of above-mentioned each side method.Wherein, described storage medium can be magnetic disc, CD, read only memory (Read-OnlyMemory is called for short ROM) or RAM etc..
Above disclosed it is only present pre-ferred embodiments, certainly can not limit the interest field of the present invention, the equivalent variations therefore made according to the claims in the present invention with this, still belong to the scope that the present invention contains.

Claims (12)

1. a terminal maintenance method, it is characterised in that including:
Attending device sends connection certification and asks NM server, so that described NM server verifies the legitimacy of described attending device;
When the result is legal, the mark of first terminal is sent to described NM server by described attending device, so that described NM server arranges the described attending device connection management authority to described first terminal;
Described first terminal is attached based on set connection management authority and manages control by described attending device.
2. the method for claim 1, it is characterised in that described first terminal is attached based on set connection management authority and manages control by described attending device, including:
Described attending device receives the Connecting quantity of the described first terminal that described NM server sends, and according to described Connecting quantity transmission connection request to described first terminal;
Described attending device receives the connection response that described first terminal returns, to set up the annexation with described first terminal;
Described attending device sends management control command to described first terminal, so that described first terminal responds described management control command.
3. method as claimed in claim 1 or 2, it is characterised in that also include:
Described attending device generates mass-sending administration order, and obtains the mark of multiple second terminal;
Mark and the mass-sending administration order of the plurality of second terminal are sent to described NM server by described attending device, so that described mass-sending administration order is sent to described second terminal by described NM server, to be managed the plurality of second terminal controlling.
4. a terminal maintenance method, it is characterised in that including:
NM server receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
When the result is legal, described NM server receives the mark of the first terminal that described attending device sends,
And the mark according to described first terminal arranges the described attending device connection management authority to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device.
5. method as claimed in claim 4, it is characterized in that, the described mark according to described first terminal arranges the described attending device connection management authority to described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device, including:
Described NM server sends security policy information to described first terminal according to the mark of described first terminal, so that described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information;
Described NM server obtains the Connecting quantity of described first terminal according to the mark of described first terminal;
Described NM server sends the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection according to described Connecting quantity and described first terminal, and it is managed controlling to described first terminal based on described connection management authority;
Wherein, described security policy information includes the mark of described attending device and described connection management authority.
6. the method as described in claim 4 or 5, it is characterised in that also include:
Described NM server receives the mark mass-sending administration order and multiple second terminal that described attending device sends;
The effectiveness of described mass-sending administration order and the mark of the plurality of second terminal is verified by described NM server;
When the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling.
7. an attending device, it is characterised in that including:
Certification sending module, is used for sending connection certification and asks NM server, so that described NM server verifies the legitimacy of described attending device;
Mark sending module, for when the result is legal, sending the mark of first terminal to described NM server, so that described NM server arranges the described attending device connection management authority to described first terminal;
Connection management module, for being attached described first terminal based on set connection management authority and managing control.
8. device as claimed in claim 7, it is characterised in that described connection management module includes:
Connect unit, for receiving the Connecting quantity of the described first terminal that described NM server sends, and according to described Connecting quantity transmission connection request to described first terminal;
Described connection unit, is additionally operable to receive the connection response that described first terminal returns, to set up the annexation with described first terminal;
Management control unit, is used for sending management control command to described first terminal, so that described first terminal responds described management control command.
9. device as claimed in claim 7 or 8, it is characterised in that also include:
Generate acquisition module, be used for generating mass-sending administration order, and obtain the mark of multiple second terminal;
Mass-sending order sending module, for the mark of the plurality of second terminal and mass-sending administration order are sent to described NM server, so that described mass-sending administration order is sent to the plurality of second terminal by described NM server, to be managed the plurality of second terminal controlling.
10. a NM server, it is characterised in that including:
Certification receiver module, for receive attending device send connection certification request, and according to described connection certification requests verification the legitimacy of attending device;
Mark receiver module, for when the result is legal, receiving the mark of the first terminal that described attending device sends;
Module is set, for arranging the described attending device connection management authority to described first terminal according to the mark of described first terminal, so that described first terminal is attached based on set connection management authority and manages control by described attending device.
11. server as claimed in claim 10, it is characterised in that the described module that arranges includes:
Policy information transmitting element, sends security policy information to described first terminal for the mark according to described first terminal, so that described first terminal arranges the described attending device connection management authority to described first terminal according to described security policy information;
Connecting quantity acquiring unit, for obtaining the Connecting quantity of described first terminal according to the mark of described first terminal;
Connecting quantity transmitting element, for sending the Connecting quantity of described first terminal to described attending device, so that described attending device establishes a connection according to described Connecting quantity and described first terminal, and it is managed controlling to described first terminal based on described connection management authority;
Wherein, described security policy information includes the mark of described attending device and described connection management authority.
12. the server as described in claim 10 or 11, it is characterised in that also include:
Command id receiver module, for receiving the mark mass-sending administration order and multiple second terminal that described attending device sends;
Validation verification module, for being verified the effectiveness of described mass-sending administration order and the mark of the plurality of second terminal;
Order sending module, for when the mark verifying described mass-sending administration order and the plurality of second terminal is respectively provided with effectiveness, sending described mass-sending administration order to the plurality of second terminal, to be managed the plurality of second terminal controlling.
CN201410767645.8A 2014-12-12 2014-12-12 A kind of terminal maintenance method, maintenance device and NM server Active CN105744555B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410767645.8A CN105744555B (en) 2014-12-12 2014-12-12 A kind of terminal maintenance method, maintenance device and NM server

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410767645.8A CN105744555B (en) 2014-12-12 2014-12-12 A kind of terminal maintenance method, maintenance device and NM server

Publications (2)

Publication Number Publication Date
CN105744555A true CN105744555A (en) 2016-07-06
CN105744555B CN105744555B (en) 2019-05-28

Family

ID=56241379

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410767645.8A Active CN105744555B (en) 2014-12-12 2014-12-12 A kind of terminal maintenance method, maintenance device and NM server

Country Status (1)

Country Link
CN (1) CN105744555B (en)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107480511A (en) * 2016-11-02 2017-12-15 深圳市波普安创技术有限公司 The maintenance tamper resistant systems and its method of information safety devices
CN108376290A (en) * 2018-02-07 2018-08-07 深圳怡化电脑股份有限公司 A kind of control method, device and server that financial self-service equipment is safeguarded
CN108632090A (en) * 2018-05-08 2018-10-09 普联技术有限公司 Network management and system
CN108650122A (en) * 2018-05-08 2018-10-12 普联技术有限公司 Network management and computer storage media, network controller
CN108682087A (en) * 2018-05-04 2018-10-19 深圳怡化电脑股份有限公司 Terminal equipment failure maintaining method, system and computer readable storage medium
CN109194729A (en) * 2018-08-24 2019-01-11 国广东方网络(北京)有限公司 A kind of information communication system and method
CN111709538A (en) * 2020-05-25 2020-09-25 中国商用飞机有限责任公司 System and method for authenticating ground maintenance equipment of an aircraft

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1866874A (en) * 2006-03-28 2006-11-22 华为技术有限公司 Terminal device maintaining method and system
CN1866848A (en) * 2005-05-18 2006-11-22 上海华为技术有限公司 Method for realizing configuration of service frame data
CN101018155A (en) * 2007-02-08 2007-08-15 华为技术有限公司 Network element management method, system and network element
US20080089244A1 (en) * 2006-10-12 2008-04-17 Cameo Communications, Inc. Method for discovering network device
CN103974308A (en) * 2013-02-01 2014-08-06 中兴通讯股份有限公司 Base station maintenance equipment, method, device and system, mobile terminal and base station

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1866848A (en) * 2005-05-18 2006-11-22 上海华为技术有限公司 Method for realizing configuration of service frame data
CN1866874A (en) * 2006-03-28 2006-11-22 华为技术有限公司 Terminal device maintaining method and system
US20080089244A1 (en) * 2006-10-12 2008-04-17 Cameo Communications, Inc. Method for discovering network device
CN101018155A (en) * 2007-02-08 2007-08-15 华为技术有限公司 Network element management method, system and network element
CN103974308A (en) * 2013-02-01 2014-08-06 中兴通讯股份有限公司 Base station maintenance equipment, method, device and system, mobile terminal and base station

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107480511A (en) * 2016-11-02 2017-12-15 深圳市波普安创技术有限公司 The maintenance tamper resistant systems and its method of information safety devices
CN108376290A (en) * 2018-02-07 2018-08-07 深圳怡化电脑股份有限公司 A kind of control method, device and server that financial self-service equipment is safeguarded
CN108376290B (en) * 2018-02-07 2021-05-11 深圳怡化电脑股份有限公司 Financial self-service equipment maintenance control method and device and server
CN108682087A (en) * 2018-05-04 2018-10-19 深圳怡化电脑股份有限公司 Terminal equipment failure maintaining method, system and computer readable storage medium
CN108682087B (en) * 2018-05-04 2021-02-02 深圳怡化电脑股份有限公司 Method and system for maintaining fault of terminal equipment and computer readable storage medium
CN108632090A (en) * 2018-05-08 2018-10-09 普联技术有限公司 Network management and system
CN108650122A (en) * 2018-05-08 2018-10-12 普联技术有限公司 Network management and computer storage media, network controller
CN108632090B (en) * 2018-05-08 2021-09-10 普联技术有限公司 Network management method and system
CN109194729A (en) * 2018-08-24 2019-01-11 国广东方网络(北京)有限公司 A kind of information communication system and method
CN109194729B (en) * 2018-08-24 2021-07-09 国广东方网络(北京)有限公司 Information communication system and method
CN111709538A (en) * 2020-05-25 2020-09-25 中国商用飞机有限责任公司 System and method for authenticating ground maintenance equipment of an aircraft
CN111709538B (en) * 2020-05-25 2023-11-24 中国商用飞机有限责任公司 System and method for authenticating ground maintenance equipment of an aircraft

Also Published As

Publication number Publication date
CN105744555B (en) 2019-05-28

Similar Documents

Publication Publication Date Title
CN105744555A (en) Terminal maintenance method, maintenance device and network management server
CN112738805B (en) Device control method and apparatus, storage medium, and electronic device
JP6386069B2 (en) Connection management method, apparatus, electronic equipment, program, and recording medium
CN1988489B (en) Intelligent system and method for monitoring house
US10678950B2 (en) Authenticated backplane access
EP2814276B1 (en) Access authentication method and device for wireless local area network hotspot
CN101860534B (en) Method and system for switching network, access equipment and authentication server
EP2658207B1 (en) Authorization method and terminal device
CN111324672A (en) Block chain safety processing system and method
CN102271133B (en) Authentication method, device and system
CN106302415A (en) A kind of method verifying equipment validity and distribution automatic to legitimate device
CN108512870A (en) Access method, platform of internet of things and the internet of things equipment of platform of internet of things
CN106161385A (en) The long-range control method of a kind of equipment and device
CN105259771A (en) Authentication method and associated device
CN104052775A (en) Authority management method of cloud platform service, device and system
CN110719203A (en) Operation control method, device and equipment of intelligent household equipment and storage medium
CN105306320A (en) Method and device for binding clients to intelligent device
CN104065921A (en) Security and protection wide area network embedded type monitoring device and control method thereof
CN103067407A (en) Authentication method and authentication device of user terminal access network
CN114760112B (en) Wireless local area network-oriented intelligent home equipment networking method, system, equipment and storage medium
CN111901208A (en) Intelligent equipment control method and device, intelligent control panel and storage medium
CN113645257B (en) Identity authentication method and device, electronic equipment and storage medium
CN105812413A (en) Communication method and device
CN103138979B (en) Network access management method and network access equipment
WO2016202083A1 (en) Method and apparatus for controlling monitoring device

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant