Network address translation gateway implementation method and device based on flow control transmission protocol, equipment and medium

Through P4 technology, network packets are identified and processed, and internal addresses and port numbers are dynamically allocated, which solves the problem of incompatibility of SCTP packet forwarding, and realizes the smooth traversal and forwarding of SCTP packets, and improves the flexibility of NAT gateway.

CN120166094AInactive Publication Date: 2025-06-17SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510415043.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-17
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing NAT gateway lacks compatibility support for SCTP packet forwarding, which limits the application of SCTP on the wide-area public network.

Method used

By using P4 technology to identify and process network messages, dynamically assign unique internal addresses and port numbers to SCTP connections, and forwarding SCTP messages is realized in the NAT gateway.

Benefits of technology

Without modifying existing NAT gateway devices or introducing new devices, the smooth traversal and forwarding of SCTP messages is achieved, improving the NAT gateway's support capabilities and flexibility for the SCTP protocol.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166094A_ABST
    Figure CN120166094A_ABST
Patent Text Reader

Abstract

The invention discloses a network address translation gateway implementation method and device based on a flow control transmission protocol, equipment and a medium, and relates to the technical field of computer networks and data transmission, and the method comprises the following steps: after receiving a network message, identifying the network message by using a P4 technology through a message identification end, determining whether the network message is a target message of a flow control transmission protocol; if the network message is determined to be a target message, determining connection information of the target message by using a P4 technology through a message processing end, allocating a unique internal address and a port number for connection of the target message according to the connection information, and packaging the target message so as to send the packaged message to a gateway conversion end; and converting the internal address and the port number of the packaged message through a gateway conversion end so as to forward the converted message to a target address. Therefore, smooth traversal and forwarding of the SCTP message can be realized on the premise of not modifying the existing NAT gateway equipment or introducing new equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer networks and data transmission, and particularly relates to a method, device, equipment and medium for implementing a network address translation gateway based on the Stream Control Transmission Protocol (SCTP). Background Art

[0002] SCTP (Stream Control Transmission Protocol) is an emerging transport layer protocol that improves the stability and security of data transmission. However, existing NAT (Network Address Translation) gateways lack compatible support for SCTP packet forwarding, which limits the application of SCTP on wide-area public networks. To solve the compatibility problem of the SCTP protocol in the NAT gateway environment, various solutions have been proposed currently, such as the conversion method based on the application layer gateway and the conversion method based on protocol extension. However, these solutions all have their own limitations. Among them, the conversion method based on the application layer gateway requires modifying existing NAT gateway devices or introducing new middleware devices, which increases the complexity and cost of the system; while the conversion method based on protocol extension requires extending or modifying the SCTP protocol, which may affect the compatibility and standardization process of the protocol. Therefore, the support ability of NAT gateways for the SCTP protocol still needs to be improved.

[0003] In summary, how to achieve the smooth traversal and forwarding of SCTP packets without modifying existing NAT gateway devices or introducing new devices is an urgent problem to be solved currently. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a method, device, equipment and medium for implementing a network address translation gateway based on the Stream Control Transmission Protocol, which can achieve the smooth traversal and forwarding of SCTP packets without modifying existing NAT gateway devices or introducing new devices. The specific solutions are as follows:

[0005] In a first aspect, the present application provides a method for implementing a network address translation gateway based on the Stream Control Transmission Protocol, including:

[0006] After receiving a network packet to be recognized, use the P4 technology through the packet recognition end to recognize the network packet to determine whether the network packet is a target packet of the Stream Control Transmission Protocol;

[0007] If it is determined that the network packet is the target packet of the Stream Control Transmission Protocol (SCTP), the packet processing end uses the P4 technology to determine the connection information of the target packet, assigns a unique internal address and port number to the connection of the target packet according to the connection information, and encapsulates the target packet to send the encapsulated packet to the gateway conversion end;

[0008] The gateway conversion end converts the internal address and the port number of the received encapsulated packet so as to forward the obtained converted packet to the corresponding target address;

[0009] Moreover, after it is determined that the network packet is the target packet, the connection management end continuously tracks the connection status of the target packet so as to synchronize the connection status to a preset connection status table, and verifies the target packet according to the connection status table so as to perform corresponding processing according to the obtained verification result.

[0010] Optionally, the packet identification end, the packet processing end, the gateway conversion end, and the connection management end are independent of each other and are all functional ends encapsulated by a microservices architecture and containerization technology so that each functional end can be independently upgraded and replaced.

[0011] Optionally, using the P4 technology to identify the network packet to determine whether the network packet is the target packet of the Stream Control Transmission Protocol includes:

[0012] Using the P4 technology to extract the header information of the network packet;

[0013] Verifying the port number field and the protocol type field in the header information to make a preliminary judgment on the network packet and obtain a corresponding judgment result;

[0014] If the judgment result indicates that the network packet belongs to the Stream Control Transmission Protocol and is a transport layer protocol packet, parse the verification label in the header information and perform verification based on the verification label to obtain a corresponding verification result;

[0015] If the verification result indicates that the verification label meets the label verification conditions of the Stream Control Transmission Protocol, obtain the determination result that the network packet is the target packet of the Stream Control Transmission Protocol.

[0016] Optionally, converting the internal address and the port number of the received encapsulated packet so as to forward the obtained converted packet to the corresponding target address includes:

[0017] Determine the mapping information of the internal address and the port number of the received encapsulated packet;

[0018] While ensuring that the verification tag in the encapsulated message remains unchanged, convert the internal address and port number of the encapsulated message based on the mapping information, so as to forward the obtained converted message to the corresponding target address based on a preset connection multiplexing policy.

[0019] Optionally, after converting the internal address and port number of the received encapsulated message, it further includes:

[0020] Through the security policy end, encrypt the encapsulated message using a preset encryption technology, and verify the identity of the encrypted data using a preset identity verification technology. After confirming that the identity of the encrypted data is correct, trigger the step of forwarding the obtained converted message to the corresponding target address;

[0021] Among them, the security policy end is a functional end encapsulated through a microservice architecture and containerization technology, which is independent of the message recognition end, the message processing end, the gateway conversion end, and the connection management end, so that the security policy end can be independently upgraded and replaced.

[0022] Optionally, forwarding the obtained converted message to the corresponding target address includes:

[0023] Parse the obtained converted message to determine the field information of the converted message;

[0024] Use a preset hash algorithm to generate a corresponding hash value according to the field information;

[0025] Based on the hash value, search for a message forwarding rule that matches the hash value in a preset hash table to obtain a corresponding search result;

[0026] If the search result indicates that there is a message forwarding rule in the hash table that matches the hash value, forward the converted message to the corresponding target address according to the message forwarding rule;

[0027] If the search result indicates that there is no message forwarding rule in the hash table that matches the hash value, forward the converted message to the corresponding target address based on the longest prefix matching algorithm.

[0028] Optionally, performing corresponding processing according to the obtained verification result includes:

[0029] If the obtained verification result indicates that the current status information of the target message is inconsistent with the information in the connection status table, then discard the target message, and / or, perform corresponding error response feedback for the target message, and / or, record the current inconsistent event in the corresponding log.

[0030] In a second aspect, the present application provides a network address translation gateway implementation device based on the Stream Control Transmission Protocol (SCTP), including:

[0031] A packet identification module, configured to, when receiving a network packet to be identified, identify the network packet by using P4 technology through a packet identification end, so as to determine whether the network packet is a target packet of the Stream Control Transmission Protocol;

[0032] A packet encapsulation module, configured to, if it is determined that the network packet is a target packet of the Stream Control Transmission Protocol, determine connection information of the target packet by using the P4 technology through a packet processing end, allocate a unique internal address and port number for the connection of the target packet according to the connection information, and encapsulate the target packet, so as to send the encapsulated packet to a gateway conversion end;

[0033] An address translation module, configured to, through the gateway conversion end, translate the internal address and the port number of the received encapsulated packet, so as to forward the obtained translated packet to a corresponding target address;

[0034] A packet verification module, configured to, after determining that the network packet is the target packet, continuously track the connection state of the target packet through a connection management end, so as to synchronize the connection state to a preset connection state table, and verify the target packet according to the connection state table, so as to perform corresponding processing according to the obtained verification result.

[0035] In a third aspect, the present application provides an electronic device, including:

[0036] A memory, configured to store a computer program;

[0037] A processor, configured to execute the computer program to implement the foregoing network address translation gateway implementation method based on the Stream Control Transmission Protocol.

[0038] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program; wherein, when the computer program is executed by a processor, the foregoing network address translation gateway implementation method based on the Stream Control Transmission Protocol is implemented.

[0039] In this embodiment, after receiving a network packet to be recognized, the packet recognition end uses P4 technology to recognize the network packet to determine whether the network packet is a target packet of the Stream Control Transmission Protocol (SCTP); if it is determined that the network packet is a target packet of the SCTP, the packet processing end uses the P4 technology to determine the connection information of the target packet, assigns a unique internal address and port number to the connection of the target packet according to the connection information, and encapsulates the target packet to send the encapsulated packet to the gateway conversion end; through the gateway conversion end, the internal address and the port number of the received encapsulated packet are converted so that the obtained converted packet can be forwarded to the corresponding target address; and after it is determined that the network packet is the target packet, the connection management end continuously tracks the connection state of the target packet to synchronize the connection state to a preset connection state table and perform verification on the target packet according to the connection state table, so as to perform corresponding processing according to the obtained verification result. As can be seen from the above, after receiving a network packet to be recognized, this application uses the packet recognition end to determine whether the network packet is a target packet of the SCTP by using P4 technology, and after it is determined that the network packet is the target packet, the packet processing end uses the P4 technology to assign a unique internal address and port number to the connection of the target packet according to the connection information of the target packet and perform encapsulation to send the encapsulated packet to the gateway conversion end, and then through the gateway conversion end, the internal address and the port number of the encapsulated packet are converted so that it can be forwarded to the corresponding target address. At the same time, after it is determined that the network packet is the target packet, the connection management end continuously tracks the connection state of the target packet to synchronize the connection state to a preset connection state table and perform verification on the target packet according to the connection state table, so as to perform corresponding processing according to the obtained verification result.In this way, through the above process of this application, the identification and processing of network packets are carried out using P4 technology, the design of the data plane is implemented in a custom manner, the SCTP protocol is separated from the kernel protocol stack, and the processing of SCTP packets can be implemented on the switching device using a programmable data plane, further improving the flexibility and adaptability of the NAT gateway; at the same time, according to the connection information of the packets, a unique internal address and port number are dynamically assigned to each SCTP connection, ensuring that the packets can be correctly converted when passing through the NAT gateway, and avoiding the problem of address and port conflicts; in addition, in order to maintain the synchronization of the connection state, a connection state table is used to record the state information of each SCTP connection, enabling the NAT gateway to accurately track the state of each SCTP connection, perform checksum and synchronization on the packets, to ensure the stability and reliability of the connection, and then realize the smooth traversal and forwarding of SCTP packets without modifying the existing NAT gateway device or introducing new devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.

[0041] Figure 1 Schematic diagram of the system module applicable to the network address translation gateway implementation solution based on the Stream Control Transmission Protocol disclosed in this application;

[0042] Figure 2 Flowchart of a method for implementing a network address translation gateway based on the Stream Control Transmission Protocol disclosed in this application;

[0043] Figure 3 Flowchart of a specific method for implementing a network address translation gateway based on the Stream Control Transmission Protocol disclosed in this application;

[0044] Figure 4 Schematic diagram of the structure of a device for implementing a network address translation gateway based on the Stream Control Transmission Protocol disclosed in this application;

[0045] Figure 5 Structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0047] Existing NAT gateways lack compatible support for SCTP packet forwarding, which limits the application of SCTP on wide-area public networks. To solve the compatibility problem of the SCTP protocol in the NAT gateway environment, various solutions have been proposed currently, such as the conversion method based on the application layer gateway and the conversion method based on protocol extension. However, these solutions all have their own limitations. Among them, the conversion method based on the application layer gateway requires modifying the existing NAT gateway device or introducing a new middleware device, which increases the complexity and cost of the system; while the conversion method based on protocol extension requires extending or modifying the SCTP protocol, which may affect the protocol compatibility and standardization process. Therefore, the support ability of NAT gateways for the SCTP protocol still needs to be improved.

[0048] To overcome the above technical problems, the present application provides a method for implementing a network address translation gateway based on the Stream Control Transmission Protocol to achieve the smooth traversal and forwarding of SCTP packets without modifying the existing NAT gateway device or introducing new devices.

[0049] In the implementation solution of the network address translation gateway based on the Stream Control Transmission Protocol of the present application, the system modules adopted can be seen Figure 1 as shown, and specifically may include an SCTP protocol processing module, a NAT conversion module, a connection management module, a resource management module, and a security policy module.

[0050] Among them, the SCTP protocol processing module, as one of the core processing modules of the system, is located at the entrance and exit of the data stream. It is responsible for receiving SCTP packets from the external network, sending the processed packets, encapsulating the received data with the SCTP protocol, and decompressing the data before sending. At the same time, in some cases, it is necessary to convert SCTP protocol data into data of other protocols, or convert data of other protocols into SCTP protocol data; the NAT conversion module is located after the SCTP protocol processing module and is responsible for processing the conversion of internal addresses and port numbers. For example, converting the private address of the internal network into the public network address of the external network, or converting the public network address into the private address of the internal network. At the same time, when necessary, the transmission port is converted to ensure the correct transmission of data; the security policy module is located after the NAT conversion module and is responsible for the security processing of data. For example, encrypting the transmitted data to ensure the confidentiality of the data, authenticating the transmitted data to ensure the integrity and authenticity of the data; the connection management module runs through the entire system and is responsible for the management of SCTP connections. For example, establishing an SCTP connection, including initiating a connection request and receiving a connection request, maintaining the connection status after the connection is established, including monitoring the stability of the connection, handling exceptions in the connection, etc., disconnecting the SCTP connection, including normal disconnection and abnormal disconnection; the resource management module, as the support module of the system, is responsible for monitoring and managing the resource usage of the entire system. For example, real-time monitoring of the usage of resources such as the memory, CPU, and bandwidth of the system, and optimizing the resource allocation strategy according to the results of resource monitoring to improve resource utilization and system performance. That is, the SCTP protocol processing module passes the received SCTP packets to the NAT conversion module for address and port conversion, and cooperates with the connection management module to manage the status of the SCTP connection; the NAT conversion module receives the SCTP packets passed by the SCTP protocol processing module, performs address and port conversion, and can further pass the converted data to the security policy module for security processing such as encryption, and at the same time obtains and updates the connection status information through the connection management module to ensure the accuracy of address and port conversion; the security policy module receives the data passed by the NAT conversion module and performs security processing such as encryption and authentication through the resource support provided by the resource management module, such as the storage and management of encryption keys; the resource management module provides necessary resource support and monitoring information for other modules. For example, providing storage and management support for encryption keys for the security policy module, providing storage and management support for connection status for the connection management module, etc.

[0051] Furthermore, in the implementation solution of the network address translation gateway based on the stream control transmission protocol of the present application, a multi-stream processing module can be additionally provided: used to support the multi-stream feature of the SCTP protocol, enabling multiple independent data streams to be transmitted in parallel on the same SCTP connection, improving the efficiency and flexibility of data transmission; a congestion control module: used to adjust the data transmission rate according to the network congestion situation, avoid network congestion, and improve the stability and reliability of network transmission; a log recording module: used to record the operation logs of the NAT gateway system, including the reception, sending, conversion, and error information of data packets, etc., for facilitating fault troubleshooting and system maintenance; and a configuration management module: used to provide a user interface, allowing users to configure the parameters of the NAT gateway system, such as NAT rules, security policies, resource limitations, etc., to meet the needs of different users.

[0052] See Figure 2 As shown, an embodiment of the present invention discloses a method for implementing a network address translation gateway based on the stream control transmission protocol, including:

[0053] Step S11, when a network packet to be recognized is received, the packet recognition end uses P4 technology to recognize the network packet to determine whether the network packet is a target packet of the stream control transmission protocol.

[0054] In this embodiment, after a network packet to be recognized is received, the packet recognition end of this embodiment uses P4 (i.e., Programming Protocol-independent Packet Processors) technology to recognize the network packet to determine whether the network packet is a target packet belonging to the stream control transmission protocol. It can be understood that traditional NAT gateways are mainly designed based on TCP (i.e., Transmission Control Protocol) and UDP (i.e., User Datagram Protocol), and the support for the SCTP protocol is not complete, resulting in compatibility problems when SCTP packets pass through the NAT gateway. To overcome this challenge, in this embodiment, after a network packet is received, the packet recognition end can use P4 technology to recognize the target packets belonging to the stream control transmission protocol in the network packet, that is, SCTP packets, so as to perform special processing on the recognized SCTP packets and improve the support ability of the NAT gateway for the SCTP protocol.

[0055] It should be noted that an SCTP packet contains a common packet header and several data chunks. The packet header contains key information such as the source port number, destination port number, verification tag, etc. These data are crucial for identifying the SCTP packet. That is, identifying the target packet of the Stream Control Transmission Protocol depends on the detailed parsing of its header information. Therefore, the processing flow for identifying the network packet using P4 technology is as follows: Extract the header information of the network packet using P4 technology; verify the port number field and protocol type field in the header information to make a preliminary judgment on the network packet and obtain a corresponding judgment result; if the judgment result indicates that the network packet belongs to the Stream Control Transmission Protocol and is a transport layer protocol packet, then parse the verification tag in the header information and perform verification based on the verification tag to obtain a corresponding verification result; if the verification result indicates that the verification tag meets the label verification conditions of the Stream Control Transmission Protocol, then obtain the determination result that the network packet is the target packet of the Stream Control Transmission Protocol. Among them, the header information refers to the IP (i.e., Internet Protocol) header and transport layer header information, including but not limited to key fields such as source address, destination address, source port number, and destination port number. That is, the packet identification end uses P4 technology to extract the header information of the network packet. Then, since SCTP usually communicates using specific port numbers, the port number field in the header information can be checked to determine whether the network packet belongs to the SCTP protocol, and at the same time, the protocol type field in the header information can be checked to ensure that the network packet is a transport layer protocol packet, thereby obtaining a judgment result for a preliminary judgment on the network packet. If the judgment result indicates that the network packet belongs to the Stream Control Transmission Protocol and is a transport layer protocol packet, then further parse the verification tag in the header information to perform verification based on the verification tag, and finally confirm whether the network packet is the target packet of the Stream Control Transmission Protocol, that is, the SCTP packet.

[0056] It should be further pointed out that in this embodiment, the P4 technology is utilized, which has the characteristics of being protocol-independent and device-independent. It can realize the design of the data plane through a custom method for convenient programmable configuration. The SCTP protocol is separated from the kernel protocol stack, and the programmable data plane is used to process SCTP packets on the switching device, realizing the flexible configuration and deployment of the SCTP protocol on the NAT gateway, and further improving the flexibility and adaptability of the NAT gateway. In this way, after receiving the network packet to be recognized, in this embodiment, first through the packet recognition end, the P4 technology is used to accurately recognize the SCTP packet from numerous network packets for special processing, so as to enhance the support ability of the NAT gateway for the SCTP protocol; by separating the SCTP protocol from the kernel protocol stack by utilizing the characteristics of the P4 technology, the flexible configuration and deployment of the SCTP protocol on the NAT gateway are realized, and the flexibility and adaptability of the NAT gateway are further improved.

[0057] Step S12: If it is determined that the network packet is the target packet of the Stream Control Transmission Protocol, then through the packet processing end, use the P4 technology to determine the connection information of the target packet, allocate a unique internal address and port number for the connection of the target packet according to the connection information, and encapsulate the target packet to send the encapsulated packet to the gateway conversion end.

[0058] In this embodiment, if it is determined by the packet recognition end that the network packet is the target packet of the Stream Control Transmission Protocol, that is, the SCTP packet is recognized, then through the packet processing end, use the P4 technology to dynamically allocate a unique internal address and port number for the connection of the target packet according to the connection information of the target packet, and encapsulate the target packet to send the obtained encapsulated packet to the gateway conversion end. Among them, the connection information includes but is not limited to the source address, destination address, source port, destination port, and SCTP label, etc.

[0059] Specifically, this embodiment needs to track the status of each SCTP connection to determine the connection information of the target packet, and find or create a corresponding internal address and port mapping based on the connection information such as the source address, destination address, source port, and destination port of the packet, so as to dynamically allocate a unique internal address and port number for it. Through this dynamic allocation mechanism, it can be ensured that each SCTP connection has a unique internal representation, thus avoiding address and port conflicts. At the same time, in order to enable SCTP packets to traverse the NAT gateway, this embodiment needs to encapsulate the target packet in a UDP packet through P4 technology in the data plane of the NAT gateway for transmission to achieve end-to-end connection on the public network. It should be noted that in order to ensure the processing efficiency and stability of the NAT gateway, when processing a large number of SCTP connections, it is necessary to consider the issues of load balancing and resource optimization. Specifically, this embodiment can introduce a load balancing mechanism to ensure that the NAT gateway can distribute connection requests to multiple processing units to improve processing efficiency and stability. In this way, after this embodiment identifies the target packet, it first determines the connection information of the target packet, providing key data support for subsequent processing; and based on the connection information of the target packet, dynamically allocates a unique internal address and port number for each SCTP connection, ensuring that the packet can be correctly converted when traversing the NAT gateway and avoiding the problem of address and port conflicts; at the same time, through the load balancing mechanism, the processing efficiency and stability of the NAT gateway are improved.

[0060] Step S13: Through the gateway conversion end, convert the internal address and the port number of the encapsulated packet received, so as to forward the obtained converted packet to the corresponding target address.

[0061] In this embodiment, through the gateway conversion end, convert the internal address and the port number of the received encapsulated packet, so as to forward the obtained converted packet to its corresponding target address. It should be pointed out that in order to maintain the continuity of the connection, this embodiment also needs to be correctly converted when the packet traverses the NAT gateway. Specifically, during the NAT conversion process, this embodiment can perform special processing on some fields in the header information of the SCTP packet. For example, the verification tag, which is an important field in the SCTP packet header and is used to identify an SCTP connection. If the verification tag is changed or lost during the NAT conversion process, it will cause the connection to be interrupted. Therefore, the NAT gateway needs to ensure the invariance of the verification tag during the conversion process. In addition, for other fields that may affect the connection status, such as the sequence number, acknowledgment number, etc., corresponding processing and verification also need to be performed.

[0062] Specifically, the gateway conversion end determines the mapping information of the internal address and the port number of the received encapsulated message; under the condition of ensuring that the verification label in the encapsulated message remains unchanged, the internal address and the port number of the encapsulated message are converted based on the mapping information, so as to forward the obtained converted message to the corresponding target address based on the preset connection multiplexing strategy. That is, the gateway conversion end first determines the mapping information of the internal address and the port number of the received encapsulated message, and under the condition of ensuring that the verification label in the encapsulated message remains unchanged, the internal address and the port number of the encapsulated message are converted based on the mapping information, so as to forward the obtained converted message to the corresponding target address based on the preset connection multiplexing strategy. In this embodiment, a function is extended on the protocol stack of the transceiver end of the NAT gateway, and a new NAT mapping transmission method for SCTP messages is introduced. By using the protocol-aware mapping rule, the mapping based on the SCTP association identifier and the multi-homed address is realized beyond the five-tuple. It can be understood that in order to optimize resource usage, the NAT gateway can adopt the preset connection multiplexing strategy to reduce unnecessary resource consumption. For example, when multiple internal connection requests access the same external resource and need to use the same internal address and port, the NAT gateway can reduce resource occupancy by multiplexing connections, that is, reducing the number of parallel connections to the same external resource in the internal network. In addition, this embodiment can also adopt a connection timeout strategy. For example, when a certain SCTP connection is inactive for a long time, the NAT gateway can mark it as timed out and release the relevant resources.

[0063] It should be noted that considering the security of data, a security policy end can also be added in this embodiment, and its processing flow is as follows: through the security policy end, the encapsulated message is encrypted by using a preset encryption technology, and the identity of the encrypted data is verified by using a preset authentication technology, so as to trigger the step of forwarding the obtained converted message to the corresponding target address after confirming that the identity of the encrypted data is correct. That is, the security policy end encrypts the encapsulated message by using a preset encryption technology to prevent the data from being stolen or tampered with during transmission, and verifies the identity of the encrypted data by using a preset authentication technology, so as to trigger the step of forwarding the obtained converted message to the corresponding target address after confirming that its identity is correct, thereby avoiding transmitting unauthorized suspicious data.

[0064] It should be further pointed out that the security policy and the protection mechanism complement each other. Among them, the security policy provides guidance and direction for the protection mechanism, and the protection mechanism is the specific implementation and guarantee of the security policy. Therefore, other security policies and protection mechanisms can also be set on the security policy side. For example, in terms of security policies, the principle of least privilege can be set, that is, users or systems only have the minimum permissions required to complete their tasks; the principle of minimum disclosure, that is, only the minimum information required to complete the task is provided to users or systems; the multi-level security policy, that is, according to the sensitivity and importance of information, data is divided into different security levels and corresponding protection measures are implemented. At the same time, in terms of protection mechanisms, a firewall can be used to monitor and control the data traffic in and out of the network and prevent unauthorized access; the intrusion detection and prevention system can be used to monitor the network traffic in real time, identify and block suspicious activities, and respond to potential security threats in a timely manner; the security information and event management mechanism can be added to centrally collect and analyze security event logs to help the organization detect and respond to security threats in a timely manner; regular vulnerability scanning and penetration testing can be carried out to discover potential security risks and repair them in a timely manner. In addition, management protection measures can also be added, such as formulating clear network security policies and standards to ensure that all employees follow them, enhancing the overall security awareness; regularly training employees on network security to improve their security awareness and response capabilities; formulating a detailed emergency response plan to ensure that security incidents can be handled quickly and effectively when they occur; regularly auditing and evaluating network security measures to timely discover deficiencies and make improvements. It should be noted that as technology and threats continue to change, both the security policy and the protection mechanism need to be continuously adjusted and updated. Specifically, the effectiveness of its security policy and protection mechanism can be regularly evaluated and adjusted and optimized as needed. In this way, in this embodiment, the internal address and port number dynamically allocated by the gateway conversion end for the encapsulated message are converted, avoiding the problem of address and port conflicts; during the conversion process, certain fields of the message are specially processed to ensure correct conversion; the connection multiplexing and connection timeout policies are used to reduce unnecessary resource consumption, thereby optimizing resource usage; the security policy end is introduced, and through functions such as message encryption, authentication, intrusion detection, and firewall. It can effectively prevent malicious attacks and unauthorized access, ensure the confidentiality and integrity of the message, and provide a more secure and reliable network communication environment for users.

[0065] Step S14, after determining that the network message is the target message, continuously track the connection status of the target message through the connection management end, so as to synchronize the connection status to a preset connection status table, and verify the target message according to the connection status table, so as to perform corresponding processing according to the obtained verification result.

[0066] In this embodiment, after the target packet is identified, the connection management end is used to continuously track the connection status of the target packet, so as to synchronize the connection status to a preset connection status table, and verify the target packet according to the connection status table, so as to perform corresponding processing according to the obtained verification result. That is, due to the characteristics of the SCTP protocol that support multi-stream and multi-homing, in order to maintain the synchronization of the connection status, this embodiment introduces a connection status table, which is used to record the status information of each SCTP connection, such as key information such as connection ID, sequence number, and acknowledgment number, so that when the packet passes through the NAT gateway, the NAT gateway can accurately track the status of each SCTP connection, verify and synchronize the packet according to this information, so as to ensure the stability and reliability of the connection.

[0067] Specifically, in order to maintain the synchronization of the connection status, the NAT gateway needs to update the status table when receiving each SCTP packet, and check the legality of the packet to perform corresponding processing. The processing flow is as follows: if the obtained verification result indicates that the current status information of the target packet is inconsistent with the information in the connection status table, the target packet is discarded, and / or, a corresponding error response feedback is made for the target packet, and / or, the current inconsistent event is recorded in the corresponding log. That is, if the verification result indicates that the current status information of the target packet is inconsistent with the information in the connection status table, the target packet is discarded, and / or, a corresponding error response feedback is made for the target packet, and / or, the current inconsistent event is recorded in the corresponding log, thereby avoiding the occurrence of connection interruption or data loss caused by improper NAT conversion. In addition, in order to avoid network congestion, this embodiment can adjust the data transmission rate according to the network congestion situation.

[0068] It should be noted that the message recognition end, the message processing end, the gateway conversion end, the connection management end, and the security policy end in this embodiment are independent of each other, and are all functional ends encapsulated through a microservices architecture and containerization technology, so that each functional end can be independently upgraded and replaced. Among them, the SCTP protocol processing module is used for the message processing end and the message recognition end; the NAT conversion module is used for the gateway conversion end; the connection management module is used for the connection management end; the security policy module is used for the security policy end. This embodiment divides the system into multiple independent modules, and each module is responsible for a specific function. Since new functions can be added to the existing system as new modules without modifying other modules, the maintainability and scalability of the system are improved. In addition, this embodiment can also adopt a microservices architecture to split the system into a series of small and independent services, which can ensure that each service can run, update, and expand independently; at the same time, containerization technology can be used to package the application program and its dependencies into an independent container. Since the container can be quickly deployed and run in different environments, the portability and flexibility of the application program are improved, and the effective utilization and isolation of resources are promoted; in order to facilitate interoperability with other systems and devices, this embodiment also needs to follow open standards and protocols, which can easily integrate new devices or services into the existing system, contributing to the scalability of the system; using scalable data processing and analysis frameworks such as distributed computing frameworks, stream processing technologies, or machine learning algorithms to meet the needs of large amounts of data, which helps the system quickly respond to data changes and changes in business requirements. The experimental results show that the method for implementing a network address translation gateway based on the Stream Control Transmission Protocol in this application has a UDP packet loss rate that never exceeds 1% under the maximum 10 Mbps bandwidth allowed by the test topology, meeting the normal needs of Internet access on the public network, and can provide a feasible solution for the public network deployment of the SCTP protocol, making the SCTP suitable for use as the next-generation transport layer protocol and having broad application prospects. In this way, in this embodiment, the connection management end additionally makes the NAT gateway accurately track the status of each SCTP connection according to the connection status of the message when the message traverses the NAT gateway, and performs checksum and synchronization on the message based on this information to ensure the stability and reliability of the connection; at the same time, corresponding processing is performed according to the obtained checksum result to avoid connection interruption or data loss caused by improper NAT conversion; in addition, the system is divided into multiple independent modules, and each module is responsible for a specific function. Since new functions can be added to the existing system as new modules without modifying other modules, the maintainability and scalability of the system are improved, and design principles such as microservices architecture and containerization technology are adopted, which can build a more robust, flexible, and scalable system, facilitating better adaptation to changing business needs and technical environments, and providing users with more efficient and reliable services.

[0069] As can be seen from the above, after receiving the network packet to be recognized, the embodiment of the present application uses the P4 technology through the packet recognition end to determine whether the network packet is a target packet of the Stream Control Transmission Protocol (SCTP). After determining that the network packet is the target packet, through the packet processing end, using the P4 technology, a unique internal address and port number are allocated for the connection of the target packet according to the connection information of the target packet, and encapsulation is performed to send the encapsulated packet to the gateway conversion end. Then, through the gateway conversion end, the internal address and the port number of the encapsulated packet are converted to forward it to the corresponding target address. At the same time, after determining that the network packet is the target packet, the connection management end continuously tracks the connection status of the target packet to synchronize the connection status to a preset connection status table, and verifies the target packet according to the connection status table to perform corresponding processing according to the obtained verification result. In this way, through the above process of the embodiment of the present application, on the one hand, the P4 technology is used for the recognition and processing of network packets, and the data plane design is realized in a custom manner, separating the SCTP protocol from the kernel protocol stack, enabling the processing of SCTP packets on the switching device using the programmable data plane, further improving the flexibility and adaptability of the NAT gateway; on the one hand, according to the connection information of the packet, a unique internal address and port number are dynamically allocated for each SCTP connection, ensuring that the packet can be correctly converted when passing through the NAT gateway and avoiding the problem of address and port conflicts; on the one hand, through the load balancing mechanism, the processing efficiency and stability of the NAT gateway are improved; on the one hand, during the conversion process, some fields of the packet are specially processed to ensure correct conversion; on the one hand, connection multiplexing and connection timeout strategies are used to reduce unnecessary resource consumption, thereby optimizing resource usage; a security policy end is introduced, with functions such as packet encryption, authentication, intrusion detection, and firewall.It can effectively prevent malicious attacks and illegal access, ensure the confidentiality and integrity of packets, and provide users with a more secure and reliable network communication environment. On the one hand, in order to maintain the synchronization of connection states, a connection state table is used to record the state information of each SCTP connection, enabling the NAT gateway to accurately track the state of each SCTP connection, perform checksum and synchronization on packets to ensure the stability and reliability of the connection. On the other hand, corresponding processing is carried out according to the obtained checksum results to avoid connection interruption or data loss caused by improper NAT conversion. On the other hand, the system is divided into multiple independent modules, each module responsible for a specific function. Since new functions can be added as new modules to the existing system without modifying other modules, the maintainability and scalability of the system are improved. By adopting design principles such as microservice architecture and containerization technology, a more robust, flexible and scalable system can be built, which is convenient for better adapting to the changing business requirements and technical environment, providing users with more efficient and reliable services, and then realizing the smooth traversal and forwarding of SCTP packets without modifying the existing NAT gateway device or introducing new devices.

[0070] Based on the foregoing embodiments, it can be seen that through the method of the present application, when forwarding the obtained converted packet to the corresponding target address, the exact match and longest prefix match algorithms can be combined for forwarding to speed up the forwarding speed and thus improve the forwarding efficiency. Therefore, this embodiment elaborates in detail on how to combine the exact match and longest prefix match algorithms for forwarding. Refer to Figure 3 As shown, an implementation method of a network address translation gateway based on the Stream Control Transmission Protocol is disclosed in an embodiment of the present invention, including:

[0071] Step S21: When receiving a network packet to be recognized, through the packet recognition end, use P4 technology to recognize the network packet to determine whether the network packet is a target packet of the Stream Control Transmission Protocol.

[0072] Step S22: If it is determined that the network packet is a target packet of the Stream Control Transmission Protocol, then through the packet processing end, use the P4 technology to determine the connection information of the target packet, allocate a unique internal address and port number for the connection of the target packet, and encapsulate the target packet to send the encapsulated packet to the gateway conversion end.

[0073] Step S23: Through the gateway conversion end, convert the internal address and the port number of the received encapsulated packet to obtain a corresponding converted packet.

[0074] Among them, the specific implementation processes of steps S21, S22 and S23 can refer to the content in the foregoing embodiments and will not be elaborated here.

[0075] Step S24: Parse the converted message to determine the field information of the converted message. Use a preset hash algorithm to generate a corresponding hash value based on the field information, and search for a message forwarding rule that matches the hash value from a preset hash table to obtain a corresponding search result.

[0076] In this embodiment, parse the converted message to obtain the field information of the converted message. Use a preset hash algorithm to generate a corresponding hash value based on the field information, and search for a message forwarding rule that matches the hash value from a preset hash table to obtain a corresponding search result. Among them, the field information includes but is not limited to information such as source IP address, destination IP address, source port number, destination port number, and protocol type. That is, this embodiment uses the exact matching technology in combination with the hash algorithm. Hash the matching value of the field information to generate a corresponding unique hash value, which is used as an index or keyword to quickly find the corresponding message forwarding rule in the hash table, thereby accelerating the search speed. It can be understood that although the hash algorithm can accelerate the search speed, it may also introduce the problem of hash collision. When different matching values generate the same hash value, additional hash collision resolution strategies need to be adopted to solve the collision to ensure the accuracy of exact matching. Among them, the hash collision resolution strategies include but are not limited to the chaining method, open addressing method, etc. In this way, this embodiment combines the exact matching technology and the hash algorithm to search for the corresponding message forwarding rule, which can accelerate the search speed.

[0077] Step S25: If the search result indicates that there is a message forwarding rule in the hash table that matches the hash value, forward the converted message to the corresponding target address according to the message forwarding rule.

[0078] Step S26: If the search result indicates that there is no message forwarding rule in the hash table that matches the hash value, forward the converted message to the corresponding target address based on the longest prefix matching algorithm.

[0079] In this embodiment, if the search result indicates that there is no message forwarding rule in the hash table that matches the hash value, use the longest prefix matching algorithm to forward the converted message to the corresponding target address. Among them, the longest prefix matching algorithm is used to search for the longest prefix that matches the destination address in the routing table, which helps to determine the best message forwarding path and thus improve the message forwarding efficiency.

[0080] It should be noted that in modern network devices, packet forwarding usually involves hardware processing such as network cards or DPUs (i.e., Data Processing Units). Therefore, this embodiment can also introduce a hardware processing module to provide specialized functions for network packet processing, which can significantly improve the packet forwarding efficiency. Specifically, by offloading some packet processing tasks to the hardware for execution, for example, using the hardware for encryption / decryption, compression / decompression, etc., the burden on the CPU (i.e., Central Processing Unit) can be reduced, and the packet forwarding speed can be increased. At the same time, this embodiment can also adopt a pipeline processing model to divide the packet processing process into multiple independent stages, each stage completed by different processing units or logical cores, separating CPU-intensive and I / O (i.e., Input / Output) intensive operations to improve the concurrency efficiency. In addition, this embodiment can also select the corresponding forwarding framework and strategy according to the situation, and formulate appropriate packet forwarding strategies according to the network environment and business requirements. For example, in scenarios that require high throughput and low latency, the pipeline model can be adopted to divide the packet processing into different logical units and distribute them on different physical cores, which has higher concurrency efficiency and flexibility; while in scenarios with limited resources or where simplified configuration is required, the RTC model (a model that provides terminal services) can be adopted to process the entire packet life cycle on one CPU core. It should be further noted that this embodiment can also adopt Vxlan technology to optimize the packet forwarding performance. Specifically, through the encapsulation step set and learning mechanism, the Vxlan technology can learn the processing behavior of the packet and save the learning result to the driver module, so that in the subsequent packet forwarding process, the learned driver module can be directly used for efficient forwarding. At the same time, this embodiment can also perform intelligent scheduling according to factors such as the priority of the packet and the QOS level to ensure that critical packets can be forwarded first, and by dispersing the packet forwarding tasks to multiple processing units or links, the single-point overload and bottleneck problems can be avoided, which helps to improve the throughput and stability of the entire network. In this way, when there is no matching forwarding rule in the hash table in this embodiment, the longest prefix matching algorithm is used to forward the packet, which helps to determine the best packet forwarding path and can quickly forward the SCTP packet from the input interface to the output interface, thereby improving the packet forwarding efficiency; at the same time, the pipeline processing model, concurrent processing, and load balancing strategies are adopted, enabling the NAT gateway to process multiple SCTP connections and packets simultaneously, thus improving the throughput and stability of the network, not only enhancing the traversal efficiency of SCTP packets in the NAT gateway environment, but also providing users with a more smooth and stable network communication experience.

[0081] As can be seen from the above, after receiving the network packet to be recognized, the embodiment of the present application determines whether the network packet is a target packet of the Stream Control Transmission Protocol (SCTP) through the packet recognition end by using the P4 technology. After determining that the network packet is the target packet, through the packet processing end, using the P4 technology, a unique internal address and port number are assigned to the connection of the target packet according to the connection information of the target packet, and encapsulation is performed to send the encapsulated packet to the gateway conversion end. Then, through the gateway conversion end, the internal address and the port number of the encapsulated packet are converted, and the field information of the converted packet is determined, so as to generate a hash value that can be generated according to the field information by using a preset hash algorithm, and a matching packet forwarding rule is searched from a preset hash table based on the hash value. If a match is found, the converted packet is forwarded to the corresponding target address according to the packet forwarding rule. If no match is found, the converted packet is forwarded to the corresponding target address based on the longest prefix matching algorithm. In this way, through the above process of the embodiment of the present application, on the one hand, by combining the exact matching technology and the hash algorithm to search for the corresponding packet forwarding rule, the search speed can be accelerated; on the other hand, when there is no matching forwarding rule in the hash table, using the longest prefix matching algorithm to forward the packet helps to determine the best packet forwarding path, and can quickly forward the SCTP packet from the input interface to the output interface, thereby improving the packet forwarding efficiency; on the other hand, by adopting the pipeline processing model, concurrent processing and load balancing strategies, the NAT gateway can process multiple SCTP connections and packets simultaneously, thereby improving the network throughput and stability, not only improving the traversal efficiency of the SCTP packet in the NAT gateway environment, but also providing users with a more smooth and stable network communication experience, so as to accelerate the forwarding speed and further improve the forwarding efficiency.

[0082] Correspondingly, referring to Figure 4 As shown, the embodiment of the present application further provides a network address translation gateway implementation device based on the Stream Control Transmission Protocol, including:

[0083] A packet recognition module 11, configured to, after receiving a network packet to be recognized, recognize the network packet through a packet recognition end by using the P4 technology to determine whether the network packet is a target packet of the Stream Control Transmission Protocol;

[0084] A packet encapsulation module 12, configured to, if it is determined that the network packet is the target packet of the Stream Control Transmission Protocol, determine the connection information of the target packet through a packet processing end by using the P4 technology, assign a unique internal address and port number to the connection of the target packet according to the connection information, and encapsulate the target packet to send the encapsulated packet to the gateway conversion end;

[0085] An address translation module 13 is configured to convert the internal address and the port number of the encapsulated packet received through the gateway conversion end, so as to forward the obtained converted packet to the corresponding target address;

[0086] A packet verification module 14 is configured to continuously track the connection status of the target packet through the connection management end after determining that the network packet is the target packet, so as to synchronize the connection status to a preset connection status table, and verify the target packet according to the connection status table, so as to perform corresponding processing according to the obtained verification result.

[0087] As can be seen from the above, after receiving the network packet to be recognized in the embodiment of the present application, through the packet recognition end, the P4 technology is used to determine whether the network packet is the target packet of the Stream Control Transmission Protocol (SCTP). After determining that the network packet is the target packet, through the packet processing end, using the P4 technology, a unique internal address and port number are allocated for the connection of the target packet according to the connection information of the target packet, and encapsulation is performed to send the encapsulated packet to the gateway conversion end. Then, through the gateway conversion end, the internal address and the port number of the encapsulated packet are converted so as to forward it to the corresponding target address. At the same time, after determining that the network packet is the target packet, the connection status of the target packet is continuously tracked through the connection management end, so as to synchronize the connection status to a preset connection status table, and the target packet is verified according to the connection status table, so as to perform corresponding processing according to the obtained verification result. In this way, through the above process of the embodiment of the present application, the P4 technology is used to recognize and process network packets, and the data plane design is implemented in a custom manner. The SCTP protocol is separated from the kernel protocol stack, and the processing of SCTP packets can be implemented on the switching device using a programmable data plane, which further improves the flexibility and adaptability of the NAT gateway. At the same time, according to the connection information of the packet, a unique internal address and port number are dynamically allocated for each SCTP connection, ensuring that the packet can be correctly converted when passing through the NAT gateway, and avoiding the problem of address and port conflicts. In addition, in order to maintain the synchronization of the connection status, a connection status table is used to record the status information of each SCTP connection, so that the NAT gateway can accurately track the status of each SCTP connection, verify and synchronize the packets to ensure the stability and reliability of the connection. Furthermore, without modifying the existing NAT gateway device or introducing new devices, the smooth traversal and forwarding of SCTP packets are achieved.

[0088] In some specific embodiments, the message recognition end, the message processing end, the gateway conversion end, and the connection management end are independent of each other and are all functional ends encapsulated through a microservices architecture and containerization technology, so that each functional end can be independently upgraded and replaced.

[0089] In some specific embodiments, the message recognition module 11 may specifically include:

[0090] An information extraction unit for extracting the header information of the network message using P4 technology;

[0091] A field verification unit for verifying the port number field and the protocol type field in the header information to make a preliminary judgment on the network message and obtain a corresponding judgment result;

[0092] A label verification unit for, if the judgment result indicates that the network message belongs to the Stream Control Transmission Protocol (SCTP) and is a transport layer protocol message, parsing the verification label in the header information and performing verification based on the verification label to obtain a corresponding verification result;

[0093] A result determination unit for, if the verification result indicates that the verification label meets the label verification conditions of the SCTP, obtaining a determination result that the network message is the target message of the SCTP.

[0094] In some specific embodiments, the address conversion module 13 may specifically include:

[0095] An information determination unit for determining the mapping information of the internal address and the port number of the received encapsulated message;

[0096] A port number conversion unit for, while ensuring that the verification label in the encapsulated message remains unchanged, converting the internal address and the port number of the encapsulated message based on the mapping information, so as to forward the obtained converted message to the corresponding target address based on a preset connection multiplexing strategy.

[0097] In some specific embodiments, the network address translation gateway implementation device based on the SCTP may further include:

[0098] An identity verification unit for, through a security policy end, encrypting the encapsulated message using a preset encryption technology and verifying the identity of the encrypted data using a preset identity verification technology, so as to trigger the step of forwarding the obtained converted message to the corresponding target address after confirming that the identity of the encrypted data is correct;

[0099] Among them, the security policy end is a functional end encapsulated through a microservices architecture and containerization technology, and is independent of the packet identification end, the packet processing end, the gateway conversion end, and the connection management end, so that the security policy end can be independently upgraded and replaced.

[0100] In some specific embodiments, the address translation module 13 may specifically include:

[0101] A packet parsing unit, configured to parse the obtained translated packet to determine the field information of the translated packet;

[0102] A hash value generation unit, configured to generate a corresponding hash value according to the field information by using a preset hash algorithm;

[0103] A rule lookup unit, configured to look up a packet forwarding rule matching the hash value from a preset hash table based on the hash value to obtain a corresponding lookup result;

[0104] A first packet forwarding unit, configured to, if the lookup result indicates that there is a packet forwarding rule matching the hash value in the hash table, forward the translated packet to a corresponding target address according to the packet forwarding rule;

[0105] A second packet forwarding unit, configured to, if the lookup result indicates that there is no packet forwarding rule matching the hash value in the hash table, forward the translated packet to a corresponding target address based on the longest prefix matching algorithm.

[0106] In some specific embodiments, the packet verification module 14 may specifically include:

[0107] An event recording unit, configured to, if the obtained verification result indicates that the current status information of the target packet is inconsistent with the information in the connection status table, discard the target packet, and / or perform a corresponding error response feedback for the target packet, and / or record the current inconsistent event in a corresponding log.

[0108] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 5It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation to the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the method for implementing a network address translation gateway based on the stream control transmission protocol disclosed in any of the foregoing embodiments. Additionally, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0109] In this embodiment, the power supply 23 is used to provide working voltages for the various hardware devices on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.

[0110] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method can be transient storage or permanent storage.

[0111] Among them, the operating system 221 is used to manage and control the various hardware devices and the computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. The computer program 222, in addition to including a computer program capable of implementing the method for implementing a network address translation gateway based on the stream control transmission protocol executed by the electronic device 20 disclosed in any of the foregoing embodiments, may further include a computer program capable of performing other specific tasks.

[0112] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the method for implementing a network address translation gateway based on the stream control transmission protocol disclosed above. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated here.

[0113] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For related parts, reference can be made to the description in the method section.

[0114] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0115] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0116] Finally, it should also be noted that in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0117] The above has introduced the technical solutions provided in this application in detail. Specific examples are used in this article to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A method for implementing a network address translation gateway based on a stream control transmission protocol, characterized in that: include: After receiving the network message to be identified, the message identification terminal uses the P4 technology to identify the network message to determine whether the network message is a target message of the stream control transmission protocol; If it is determined that the network message is a target message of the stream control transmission protocol, the message processing end uses the P4 technology to determine the connection information of the target message, assigns a unique internal address and port number to the connection of the target message according to the connection information, and encapsulates the target message to send the encapsulated message to the gateway conversion end; The internal address and the port number of the received encapsulated message are converted through the gateway conversion end so as to forward the converted message to the corresponding target address; Furthermore, after determining that the network message is the target message, the connection status of the target message is continuously tracked through the connection management terminal so as to synchronize the connection status to a preset connection status table, and verify the target message according to the connection status table so as to perform corresponding processing according to the obtained verification result.

2. The method for implementing a network address translation gateway based on a stream control transmission protocol according to claim 1, characterized in that: The message identification end, the message processing end, the gateway conversion end and the connection management end are independent of each other and are all functional ends encapsulated through microservice architecture and containerization technology, so that each functional end can be independently upgraded and replaced.

3. The method for implementing a network address translation gateway based on a stream control transmission protocol according to claim 1, characterized in that: The using of the P4 technology to identify the network message to determine whether the network message is a target message of the stream control transmission protocol includes: Extracting the header information of the network message by using P4 technology; Verifying the port number field and the protocol type field in the header information to make a preliminary judgment on the network message and obtain a corresponding judgment result; If the judgment result indicates that the network message belongs to the stream control transmission protocol and is a transport layer protocol message, parsing the verification tag in the header information, and performing verification based on the verification tag to obtain a corresponding verification result; If the verification result indicates that the verification tag satisfies the tag verification condition of the stream control transmission protocol, a determination result is obtained that the network message is a target message of the stream control transmission protocol.

4. The method for implementing a network address translation gateway based on a stream control transmission protocol according to claim 1, characterized in that: The converting the internal address and the port number of the received encapsulated message so as to forward the converted message to the corresponding target address includes: Determine mapping information between the internal address and the port number of the received encapsulated message; While ensuring that the verification tag in the encapsulated message remains unchanged, the internal address and the port number of the encapsulated message are converted based on the mapping information, so that the converted message is forwarded to the corresponding target address based on a preset connection multiplexing strategy.

5. The method for implementing a network address translation gateway based on a stream control transmission protocol according to claim 1, characterized in that: After converting the internal address and the port number of the received encapsulated message, the method further includes: The encapsulated message is encrypted by using a preset encryption technology through the security policy end, and the identity of the encrypted data is verified by using a preset identity verification technology, so as to trigger the step of forwarding the obtained converted message to the corresponding target address after confirming that the identity of the encrypted data is correct; Among them, the security policy end is a functional end encapsulated by microservice architecture and containerization technology, and is independent of the message identification end, the message processing end, the gateway conversion end and the connection management end, so that the security policy end can be independently upgraded and replaced.

6. The method for implementing a network address translation gateway based on a stream control transmission protocol according to claim 1, characterized in that: The step of forwarding the converted message to a corresponding target address includes: Parsing the converted message to determine the field information of the converted message; Using a preset hash algorithm, a corresponding hash value is generated according to the field information; Based on the hash value, searching a preset hash table for a message forwarding rule that matches the hash value to obtain a corresponding search result; If the search result indicates that there is a message forwarding rule matching the hash value in the hash table, forwarding the converted message to the corresponding target address according to the message forwarding rule; If the search result indicates that there is no message forwarding rule matching the hash value in the hash table, the converted message is forwarded to the corresponding target address based on a longest prefix matching algorithm.

7. The method for implementing a network address translation gateway based on the stream control transmission protocol according to any one of claims 1 to 6, characterized in that: The corresponding processing according to the obtained verification result includes: If the obtained verification result indicates that the current status information of the target message is inconsistent with the information in the connection status table, the target message is discarded, and / or a corresponding error response feedback is performed for the target message, and / or the current inconsistent event is recorded in the corresponding log.

8. A network address translation gateway implementation device based on stream control transmission protocol, characterized in that: include: A message identification module is used to identify the network message to be identified by using the P4 technology through the message identification terminal after receiving the network message to be identified, so as to determine whether the network message is a target message of the stream control transmission protocol; A message encapsulation module, for determining the connection information of the target message by using the P4 technology through the message processing end if it is determined that the network message is the target message of the stream control transmission protocol, assigning a unique internal address and port number to the connection of the target message according to the connection information, and encapsulating the target message to send the encapsulated message to the gateway conversion end; An address conversion module, used for converting the internal address and the port number of the received encapsulated message through the gateway conversion end, so as to forward the converted message to the corresponding target address; The message verification module is used to continuously track the connection status of the target message through the connection management terminal after determining that the network message is the target message, so as to synchronize the connection status to a preset connection status table, and verify the target message according to the connection status table, so as to perform corresponding processing according to the obtained verification result.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the network address translation gateway implementation method based on the stream control transmission protocol according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the network address translation gateway implementation method based on the stream control transmission protocol as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method for implementing traversing of stream control transmission protocol message to network address translation equipment

    CN101834805A

  • SCTP-based network address conversion method

    CN106713523A

  • Communication method, apparatus and system based on stream control transmission protocol (SCTP)

    CN108432212A

  • NAT tester and test method for automatically testing NAT equipment in forwarding SCTP message

    CN113794608A

  • Encapsulating an SCTP packet in a UDP packet

    US20240187966A1

Cited By

  • Network security visualization system

    CN121356867A