Tunneled remote intent mechanism
Customer premise equipment for receiving tunneled commands from a device management platform to execute. A remote management client is configured to establish a tunneled connection with a device management platform, to receive an encrypted command from the device management platform via the tunneled connection, and to decrypt the encrypted command to generate an unencrypted command. A command interface is configured to receive the unencrypted command from the remote management client, and to execute the command.
1 . A customer premise equipment device, comprising:
a memory storing computer-readable instructions; and
a processor configured to execute the computer-readable instructions to provide:
a remote management client configured to: (i) establish a tunneled connection with a device management platform via a local area network (LAN) interface of the customer premise equipment device; (ii) provide session communication with the device management platform using a Customer Premise Equipment (CPE) Wide Area Network (WAN) Management Protocol (CWMP) client provided by the remote management client such that the tunneled connection is initiated by the CWMP client; (iii) receive an encrypted command from the device management platform via the tunneled connection and the LAN interface; (iv) decrypt the encrypted command to generate an unencrypted command; and (v) send a response to the device management platform based on the encrypted command; and
a command interface configured to: (i) receive the unencrypted command from the remote management client; and (ii) execute the unencrypted command, wherein the unencrypted command is invoked based on a command file created by the CWMP client that is comprised of Android Debug Bridge (ADB) commands, wherein:
the command interface comprises an ADB;
the encrypted command specifies a predetermined Internet Protocol (IP) port for the ADB;
the encrypted command comprises an ADB shell command and an ADB intent command; and
the response comprises an ADB response.
2 . The customer premise equipment device of claim 1 , wherein the management client is configured to receive the encrypted command via a TR-069 (Technical Report 069) protocol or a TR-369 (Technical Report 369) protocol.
3 . The customer premise equipment device of claim 1 , wherein the remote management client comprises a user services platform (USP) agent.
4 . The customer premise equipment device of claim 1 , wherein:
the tunneled connection is a first tunneled connection;
the remote management client is configured to establish a second tunneled connection with the device management platform via the LAN interface; and
the second tunneled connection comprises a USP communications connection.
5 . The customer premise equipment device of claim 1 , wherein the encrypted command comprises a security wrapped command.
6 . The customer premise equipment device of claim 1 , wherein the device management platform comprises a controller configured to provide an auto-configuration server (ACS) or a USP controller.
7 . The customer premise equipment device of claim 1 , wherein the remote management client is configured to store data retrieved by the command interface for later retrieval.
8 . A method for providing execution of remote management commands at a customer premise equipment device, the method comprising:
establishing a tunneled connection between a remote management client and a device management platform via a local area network (LAN) interface of the customer premise equipment device;
providing session communication with the device management platform using a Customer Premise Equipment (CPE) Wide Area Network (WAN) Management Protocol (CWMP) client provided by the remote management client such that the tunneled connection is initiated by the CWMP client;
receiving, at the remote management client, an encrypted command from the device management platform via the tunneled connection and the LAN interface;
decrypting the encrypted command at the remote management client to generate an unencrypted command;
providing the unencrypted command by the remote management client to a command interface;
executing the unencrypted command at the command interface, wherein the unencrypted command is invoked based on a command file created by the CWMP client that is comprised of Android Debug Bridge (ADB) commands; and
sending a response to the device management platform based on the encrypted command, wherein:
the command interface comprises an ADB;
the encrypted command specifies a predetermined Internet Protocol (IP) port for the ADB;
the encrypted command comprises an ADB shell command and an ADB intent command; and
the response comprises an ADB response.
9 . The method of claim 8 , wherein the encrypted command is received from the device management platform via the tunneled connection via a TR-069 (Technical Report 069) protocol or a TR-369 (Technical Report 369) protocol.
10 . The method of claim 8 , wherein the remote management client comprises a user services platform (USP) agent.
11 . The method of claim 8 , wherein the encrypted command comprises a security wrapped command.
12 . The method of claim 8 , wherein the tunneled connection is established between the remote management client and a controller providing an auto-configuration server (ACS) or a USP controller.
13 . A non-transitory computer-readable medium having computer readable instructions stored thereon, which when executed by a processor cause the processor to perform operations comprising:
establishing a tunneled connection between a remote management client and a device management platform via a local area network (LAN) interface associated with the remote management client;
providing session communication with the device management platform using a Customer Premise Equipment (CPE) Wide Area Network (WAN) Management Protocol (CWMP) client provided by the remote management client such that the tunneled connection is initiated by the CWMP client;
receiving, at the remote management client; an encrypted command from the device management platform via the tunneled connection and the LAN interface;
decrypting the encrypted command at the remote management client to generate an unencrypted command;
providing the unencrypted command by the remote management client to a command interface;
executing the unencrypted command at the command interface, wherein the unencrypted command is invoked based on a command file created by the CWMP client that is comprised of Android Debug Bridge (ADB) commands; and
sending a response to the device management platform based on the encrypted command; wherein:
the command interface comprises an ADB;
the encrypted command specifies a predetermined Internet Protocol (IP) port for the ADB;
the encrypted command comprises an ADB shell command and an ADB intent command; and
the response comprises an ADB response.
14 . The non-transitory computer-readable medium of claim 13 , wherein the encrypted command is received via the tunneled connection via a TR-069 (Technical Report 069) protocol or a TR-369 (Technical Report 369) protocol.
15 . The non-transitory computer-readable medium of claim 13 , wherein the encrypted command comprises a security wrapped command.
16 . The non-transitory computer-readable medium of claim 13 , wherein the tunneled connection is established between the remote management client and a controller providing an auto-configuration server (ACS) or a USP controller.