Communication Method, Device, Electronic Device and Readable Storage Medium

By adding virtual private cloud identifier (VPC-ID) to the communication data packet and modifying the serial number and other fields, the problem that Tunnel ID cannot be authenticated across regions is solved, and service authentication for cross-region access is realized, which is suitable for TCP communication systems and other communication systems.

CN113965335BActive Publication Date: 2025-07-22ALIBABA GROUP HOLDING LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010632685.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-07-01
Publication Date
2025-07-22
Estimated Expiration
2040-07-01

AI Technical Summary

Technical Problem

In the prior art, the Tunnel ID is the internal identification information of the virtual network, and the user cannot perceive it, resulting in third-party cloud services being unable to perform effective service authentication. Moreover, the Tunnel ID is reused between multiple regions, and cannot support service authentication for cross-region access.

Method used

By adding authentication information, such as virtual private cloud identifier (VPC-ID), and modifying the data packet serial number and other fields according to the data volume of the authentication information, ensuring that the authentication information can be transmitted in full, and blocking the data length differences caused by adding authentication information, so as to achieve service authentication for cross-regional access.

Benefits of technology

It realizes the complete transmission of authentication information, supports authentication of third-party services, and does not require large-scale changes to the existing communication system. It is suitable for TCP communication systems and other communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113965335B_ABST
    Figure CN113965335B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose a communication method, apparatus, electronic device, and readable storage medium, including: receiving a first data packet from a first communication end; obtaining a second data packet by modifying a preset field of the first data packet according to the data volume of the authentication information of the first communication end and adding the authentication information to the first data packet; and sending the second data packet to a second communication end. According to the embodiments of the present disclosure, by adding the authentication information to the first data packet, the authentication information can be completely transmitted from the first communication end to the second communication end, and by modifying the preset field of the first data packet according to the data volume of the authentication information, the influence on the communication process caused by adding the authentication information to the first data packet can be shielded from the communication system, so that the existing communication system can implement the technical solution according to the present disclosure without major modifications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer application technologies, and particularly to a communication method, apparatus, electronic device, and readable storage medium. Background Art

[0002] With the development of cloud computing technology, Internet cloud services can provide services to multiple VPC (Virtual Private Cloud) tenants, and multiple tenants can be isolated from each other through their respective VPCs. When providing cloud services, service authentication is required to verify whether the VPC tenant that submits an access request has the right to access the cloud services.

[0003] In the prior art, the commonly used service authentication scheme is to obtain the Tunnel ID (tunnel identifier) of the VPC tenant through the server for service authentication. Since the Tunnel ID is internal identification information of the virtual network and users cannot perceive it, third-party cloud services cannot support this authentication method. Moreover, the Tunnel ID information is reused among VPCs in multiple regions and cannot support service authentication for cross-region access. Therefore, a more effective authentication method is needed to implement the authentication of the server's access to cloud services. Summary of the Invention

[0004] To solve the problems in the related art, embodiments of the present disclosure provide a communication method, apparatus, electronic device, and readable storage medium.

[0005] In a first aspect, embodiments of the present disclosure provide a communication method.

[0006] Specifically, the communication method includes:

[0007] Receiving a first data packet from a first communication end;

[0008] Obtaining a second data packet by modifying a preset field of the first data packet according to the data volume of the authentication information of the first communication end and adding the authentication information to the first data packet;

[0009] Sending the second data packet to a second communication end.

[0010] In combination with the first aspect, in a first implementation manner of the first aspect of the present disclosure, the preset field is related to the data volume sent by the first communication end before the first data packet; and / or modifying the preset field of the first data packet according to the data volume of the authentication information of the first communication end includes modifying the sequence number in the header field of the first data packet according to the data volume of the authentication information of the first communication end; and / or adding the authentication information to the first data packet includes adding the authentication information to the data field of the first data packet.

[0011] Combined with the first implementation manner of the first aspect, in the second implementation manner of the first aspect of the present disclosure, the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; the modifying the sequence number of the first data packet according to the data volume of the authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number.

[0012] Combined with the first aspect, in the third implementation manner of the first aspect of the present disclosure, the method further includes: before receiving the first data packet, receiving a third data packet from the first communication end, modifying the third data packet by subtracting the length of the authentication information from the sequence number of the third data packet to obtain a fourth data packet; and sending the fourth data packet to the second communication end.

[0013] Combined with the first aspect, in the fourth implementation manner of the first aspect of the present disclosure, the method further includes: receiving a fifth data packet from the second communication end as an acknowledgment of the fourth data packet, modifying the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information to obtain a sixth data packet, where the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet; and sending the sixth data packet to the first communication end.

[0014] Combined with the third implementation manner of the first aspect, in the fifth implementation manner of the first aspect of the present disclosure, the first data packet is an acknowledgment of the sixth data packet, where the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet; or the first data packet is a data packet sent after the acknowledgment packet of the sixth data packet.

[0015] Combined with the fifth implementation manner of the first aspect, in the sixth implementation manner of the first aspect of the present disclosure, at least one or more of the first to sixth data packets include identification information of the communication connection from the first communication end to the second communication end; and / or the third data packet is a synchronization data packet for establishing a connection between the first communication end and the second communication end.

[0016] Combined with the first aspect, in the seventh implementation manner of the first aspect of the present disclosure, the method further includes: obtaining a tunnel identifier of the first communication end, and determining a virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier.

[0017] Combined with the first aspect, in the eighth implementation manner of the first aspect of the present disclosure, the first communication end includes a client, and the second communication end includes a server.

[0018] In combination with the first aspect, in the ninth implementation manner of the first aspect of the present disclosure, the method further includes: after the authentication of the first communication end by the second communication end is passed, modifying the session information of the first communication end so that the first communication end directly communicates with the second communication end.

[0019] In combination with the first aspect, in the tenth implementation manner of the first aspect of the present disclosure, the method is executed by a network device in the same virtual private cloud as the first communication end and the second communication end.

[0020] In a second aspect, an embodiment of the present disclosure provides a communication device.

[0021] Specifically, the communication device includes:

[0022] A first receiving module, configured to receive a first data packet from a first communication end;

[0023] A first modifying module, configured to obtain a second data packet by modifying a preset field of the first data packet according to the data amount of the authentication information of the first communication end and adding the authentication information to the first data packet;

[0024] A first sending module, configured to send the second data packet to a second communication end.

[0025] In combination with the second aspect, in the first implementation manner of the second aspect of the present disclosure, the preset field is related to the data amount sent by the first communication end before the first data packet; and / or modifying the preset field of the first data packet according to the data amount of the authentication information of the first communication end includes modifying the sequence number in the header field of the first data packet according to the data amount of the authentication information of the first communication end; and / or adding the authentication information to the first data packet includes adding the authentication information to the data field of the first data packet.

[0026] In combination with the first implementation manner of the second aspect, in the second implementation manner of the second aspect of the present disclosure, the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; modifying the sequence number of the first data packet according to the data amount of the authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number.

[0027] In combination with the second aspect, in the third implementation manner of the second aspect of the present disclosure, the device further includes:

[0028] A second receiving module, configured to receive a third data packet from the first communication end before receiving the first data packet, modify the third data packet by subtracting the length of the authentication information from the sequence number of the third data packet, and obtain a fourth data packet;

[0029] A second sending module, configured to send the fourth data packet to the second communication end.

[0030] In combination with the second aspect, in the fourth implementation manner of the second aspect of the present disclosure, the apparatus further includes:

[0031] A third receiving module, configured to receive, from the second communication end, a fifth data packet that is an acknowledgment of the fourth data packet, modify the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information to obtain a sixth data packet, where the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet;

[0032] A third sending module, configured to send the sixth data packet to the first communication end.

[0033] In combination with the third implementation manner of the second aspect, in the fifth implementation manner of the second aspect of the present disclosure, the first data packet is an acknowledgment of the sixth data packet, where the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet; or the first data packet is a data packet sent after the acknowledgment packet of the sixth data packet.

[0034] In combination with the fifth implementation manner of the second aspect, in the sixth implementation manner of the second aspect of the present disclosure, at least one or more of the first to sixth data packets include identification information of a communication connection from the first communication end to the second communication end; and / or the third data packet is a synchronization data packet for establishing a connection between the first communication end and the second communication end.

[0035] In combination with the second aspect, in the seventh implementation manner of the second aspect of the present disclosure, the apparatus further includes: a determination module, configured to obtain a tunnel identifier of the first communication end, and determine a virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier.

[0036] In combination with the second aspect, in the eighth implementation manner of the second aspect of the present disclosure, the first communication end includes a client, and the second communication end includes a server.

[0037] In combination with the second aspect, in the ninth implementation manner of the second aspect of the present disclosure, the apparatus further includes: a second modification module, configured to modify session information of the first communication end after the second communication end authenticates the first communication end, so that the first communication end directly communicates with the second communication end.

[0038] In combination with the second aspect, in the tenth implementation manner of the second aspect of the present disclosure, the device is executed by a network device in the same virtual private cloud as the first communication end and the second communication end.

[0039] In a third aspect, an embodiment of the present disclosure provides an electronic device, including a memory and a processor. The memory is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor to implement the method described in any one of the first aspect, the first to tenth implementation manners of the first aspect.

[0040] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the method described in any one of the first aspect, the first to tenth implementation manners of the first aspect is implemented.

[0041] According to the technical solution provided by the embodiment of the present disclosure, by adding authentication information to the first data packet, the authentication information can be completely transmitted from the first communication end to the second communication end, so that the second communication end can authenticate the first communication end according to the authentication information.

[0042] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In combination with the accompanying drawings, through the following detailed description of non-limiting embodiments, other features, objects, and advantages of the present disclosure will become more obvious. In the drawings:

[0044] Figure 1A A schematic diagram of a network structure of a communication method according to an embodiment of the present disclosure is shown;

[0045] Figure 1B A schematic diagram of a data flow of a communication method according to an embodiment of the present disclosure is shown;

[0046] Figure 1C A schematic diagram of the structure of a TCP data packet of a communication method according to an embodiment of the present disclosure is shown;

[0047] Figure 2 A flowchart of a communication method according to an embodiment of the present disclosure is shown;

[0048] Figure 3 A block diagram of the structure of a communication device according to an embodiment of the present disclosure is shown;

[0049] Figure 4 A block diagram of the structure of an electronic device according to an embodiment of the present disclosure is shown;

[0050] Figure 5 The structural schematic diagram of a computer system suitable for implementing the method according to an embodiment of the present disclosure is shown. Detailed implementation manners

[0051] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings, so that those skilled in the art can easily implement them. In addition, for clarity, parts irrelevant to the description of the exemplary embodiments are omitted in the drawings.

[0052] In the present disclosure, it should be understood that terms such as "including" or "having" are intended to indicate the presence of features, numbers, steps, actions, components, parts, or combinations thereof disclosed in this specification, and do not intend to exclude the possibility of the presence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0053] In addition, it should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The present disclosure will be described in detail below with reference to the drawings and in combination with the embodiments.

[0054] In the present disclosure, if it involves operations of obtaining user information or user data or operations of presenting user information or user data to others, such operations are all operations authorized, confirmed by the user, or actively selected by the user.

[0055] With the development of cloud computing technology, Internet cloud services can provide services to multiple VPC tenants, and multiple tenants can be isolated through VPC. When providing cloud services, service authentication is required to verify whether there is the right to access.

[0056] In the prior art, the commonly used service authentication scheme is to obtain the Tunnel ID through the server for service authentication. Since the Tunnel ID is the internal identification information of the virtual network and users cannot perceive it, third-party cloud services cannot support this authentication method. And the Tunnel ID information is reused among multiple regions and cannot support service authentication for cross-region access.

[0057] In view of the above defects, the technical solution provided by the embodiment of the present disclosure receives a first data packet from the first communication end; modifies a preset field of the first data packet according to the data volume of the authentication information of the first communication end, and adds the authentication information to the first data packet to obtain a second data packet; and sends the second data packet to the second communication end.

[0058] This technical solution adds authentication information to the first data packet, enabling the authentication information to be completely transmitted from the first communication end to the second communication end. Moreover, by modifying the preset field of the first data packet according to the data volume of the authentication information, the impact on the communication process caused by adding the authentication information to the first data packet can be shielded from the communication system, enabling the existing communication system to implement the technical solution according to the present disclosure without significant modification.

[0059] Figure 1A Schematic diagram of the network structure showing a communication method according to an embodiment of the present disclosure.

[0060] Figure 1B Schematic diagram of the data flow showing a communication method according to an embodiment of the present disclosure.

[0061] It can be understood that the principle of the present disclosure will be described below by taking a Transmission Control Protocol (TCP) communication system as an example, but the present disclosure is not limited thereto and is also applicable to other communication systems.

[0062] As Figure 1A shown, in a TCP communication system, a communication connection is established between the first communication end (e.g., a client) and the second communication end (e.g., a server) through a three-way handshake: arrows 1a, 1b, and 1c represent the first handshake based on a SYN (synchronization) data packet; arrows 2a and 2b represent the second handshake based on a SYN-ACK (synchronization-acknowledgment) data packet; arrows 3a and 3b represent the third handshake based on an ACK (acknowledgment) data packet.

[0063] As shown by arrow 1a, the virtual network switch encapsulates the SYN data packet in TCP format from the client into a SYN data packet in Vxlan (Virtual Extensible LAN) format and sends the SYN data packet to the network device provided by the embodiment of the present disclosure, which can be a physical machine or a virtual machine.

[0064] According to an embodiment of the present disclosure, the preset field is related to the data volume sent by the first communication end before the first data packet, and the second communication end can determine the order between the first data packet and other data packets received by the second communication end according to the preset field of the first data packet, and whether the data packets before the first data packet are completely received.

[0065] According to an embodiment of the present disclosure, the preset field of the SYN data packet includes a sequence number (seq) and an acknowledgment number (ack). Generally, this preset field can be located at the head of the SYN data packet, but it can also be located at other positions.

[0066] For the sake of simplicity, Figure 1BThe preset field is illustrated by way of example in the format of

aaa; bbb

[0067] As Figure 1B shown, the preset field of the SYN packet sent by the client is

seq; NULL

[0068] According to an embodiment of the present disclosure, the sequence number may be 4 bytes, and its value range is 0 to 2 32 -1. The specific value increases with the number of bytes in the data field of the packet sent by the client. When the sequence number reaches the maximum value, it can be reset to zero and then increase according to the number of bytes in the data field of the subsequent packet sent. Based on the sequence number, the server can sort and verify the received packets to ensure that the information from the client is received completely in the correct order. For example, if the sequence number of the packet A received by the server is 32 and the data field has 20 bytes, and the sequence number of the packet B received by the server is 52 (= 32 + 20), then the server can confirm that packet B is after packet A and the data field of packet A is complete.

[0069] According to an embodiment of the present disclosure, the authentication information may include the virtual private cloud identifier (VPC-ID) of the first communication end. Alternatively, the authentication information may include any other information that can uniquely identify the first communication end. According to an embodiment of the present disclosure, using the VPC-ID for authentication, since the VPC-ID is visible to the user, it can support the authentication of third-party services.

[0070] As Figure 1A shown, after receiving the SYN packet, the network device queries the mapping table through the Tunnel ID of the SYN packet to obtain the VPC-ID corresponding to the Tunnel ID, adjusts the sequence number of the SYN packet to the sequence number minus the length of the authentication information. For example, as Figure 1B shown, adjust seq to seq - len(VPC-ID), and send the adjusted SYN packet to the SLB (Server Load Balancing), as Figure 1Aas shown by arrow 1b in, where len(VPC-ID) represents the field length of the virtual private cloud identifier. For example, as Figure 1B shown, when len(VPC-ID) is 10, the adjusted SYN packet is [90; NULL].

[0071] After the SLB receives the SYN packet, it schedules the SYN packet to the server that provides services to the client, as Figure 1A shown by arrow 1c in.

[0072] After the server receives the SYN packet, it sends a SYN-ACK packet as an acknowledgment of the SYN packet. The SYN-ACK packet is encapsulated as a Vxlan packet by the virtual network switch and sent to the network device, as Figure 1A shown by arrow 2a in.

[0073] As Figure 1B shown, the preset field of the SYN-ACK packet is [server seq; seq-len(VPC-ID)+1]. The server sequence number (server seq) is similar to the principle of the client sequence number and can be used to represent the first byte number in the data field of the packet sent by the server, and then represent the order of the packet. The acknowledgment number is the client sequence number + 1, indicating that this SYN-ACK packet is an acknowledgment of the SYN packet sent by the client. For example, as Figure 1B shown, the preset field of the SYN-ACK packet sent by the server is [200; 91]. The server sequence number 200 indicates that the first byte of the data field is the 200th byte sent by the server, and the acknowledgment number is the sequence number 90 of the received SYN packet + 1 = 91.

[0074] As Figure 1A shown, after the network device receives the SYN-ACK packet, it modifies the preset field of the SYN-ACK packet to [server seq; seq+1] and sends the modified SYN-ACK packet to the client, as shown by arrow 2b. For example, as Figure 1B shown, the preset field of the modified SYN-ACK packet is [200; 101].

[0075] Next, after the client receives the SYN-ACK packet, it sends an ACK packet as an acknowledgment of the SYN-ACK, encapsulates the ACK packet in Vxlan format through the virtual network switch and sends it to the network device, as shown by arrow 3a. The preset fields of the ACK packet are [seq + 1; server seq + 1], where seq + 1 assumes that the data field of the SYN packet has only 1 byte, so the number of the first byte of the data field of the ACK packet is seq + 1. For example, as Figure 1B shown, the preset fields of the ACK packet can be [101; 201].

[0076] After the network device receives the ACK packet, it adds the obtained VPC-ID to the data field of the ACK packet, modifies the preset fields of the ACK packet to [seq - len(VPC-ID) + 1; server seq + 1] and forwards it to the server, as shown by arrow 3b. For example, as Figure 1B shown, the preset fields of the modified ACK packet are [91; 201].

[0077] According to an embodiment of the present disclosure, the network device can also send the VPC-ID in a packet after the ACK packet. The consideration for this is that the data field of the ACK packet may have been occupied by other information and there is not enough free field for inserting the VPC-ID. In this case, the VPC-ID can be sent in a packet after the ACK packet. The sequence number of the packet after the ACK packet sent by the network device can be the sequence number of the ACK packet sent by the network device + the number of bytes in the data field of the ACK packet.

[0078] After the server receives the ACK packet, the three-way handshake is completed. The server authenticates the client according to the authentication information (for example, VPC-ID) carried in the ACK packet (or the packet after the ACK packet). If the authentication passes, a communication connection with the client is established and services are provided to the client.

[0079] As Figure 1A shown by arrows 6a and 6b, after establishing the communication connection between the server and the client, the server can communicate with the client and provide services to the client.

[0080] Or, as Figure 1A shown by arrows 7 and 8, after the server authenticates the client successfully, the network device can modify the session information of the client so that the communication connection between the client and the server does not pass through the network device, so as to shorten the communication route between the client and the server and reduce the load of the network device.

[0081] As Figure 1BAs shown in the figure, assuming that the data field of the ACK packet also has only one byte, the number of the first byte of the data field of the first packet sent by the client after establishing the communication connection is seq + 2, that is, the sequence number of the first packet sent by the client after establishing the communication connection is seq + 2, for example, 102. For the server, the sequence number of the first packet sent by the client received by it after establishing the communication connection is also seq + 2, for example, 102. The sequence number of the ACK packet received by the server is seq - len(VPC-ID) + 1. Since the VPC-ID is added to the data field of the ACK packet, the sequence number of the first packet sent by the client that the server expects to receive should be seq - len(VPC-ID) + 1 + len(VPC-ID) + 1 = seq + 2, which is consistent with the sequence number of the first packet sent by the client after establishing the communication connection. That is, the embodiments of the present disclosure eliminate the difference in the data content length caused by inserting the VPD-ID in the data field of the packet through the sequence number conversion when the network device establishes the communication connection.

[0082] According to the embodiments of the present disclosure, the preset fields of the SYN packet sent by the client are [seq; NULL] (for example, [100; NULL]), the preset fields of the SYN-ACK packet received are [server seq; seq + 1] (for example, [200; 101]), the preset fields of the ACK packet sent are [seq + 1; server seq + 1], and the sequence number of the TCP packet sent is seq + 2. It can be seen that although a network device is added to the network, since the network device modifies the preset fields when transmitting the packet, for the client, the generation and verification logic of the preset fields of the packet are the same as when there is no network device, that is, it is not necessary to make major modifications to the existing client to implement the technical solution according to the present disclosure.

[0083] On the other hand, for the server, the preset fields of the received SYN data packet are [seq-len(VPC-ID); NULL] (for example, [90; NULL]), the preset fields of the sent SYN-ACK data packet are [server seq: seq-len(VPC-ID)+1] (for example, [200; 91]), the preset fields of the received ACK data packet are [seq-len(VPC-ID)+1; server seq+1], and the sequence number of the received TCP data packet is seq+2. It can be seen that although network devices are added to the network, since the network devices modify the preset fields when transmitting data packets, for the server, the generation and verification logic of the preset fields of the data packets are the same as those when there are no network devices, that is, it is not necessary to make major modifications to the existing server, and the technical solution according to the present disclosure can be implemented.

[0084] Figure 1C Schematic diagram of the structure of a TCP data packet showing a communication method according to an embodiment of the present disclosure.

[0085] As Figure 1C shown, the TCP data packet includes a 32-bit sequence number and a 32-bit acknowledgment number. Among them, the sequence number represents the sequence number of the first byte of the current data packet data, and the acknowledgment number represents the next expected sequence number. The TCP data packet also includes a data part, where the data part is optional. For example, authentication information can be stored in the data part to implement the transmission of authentication information.

[0086] Figure 2 Flowchart showing a communication method according to an embodiment of the present disclosure. As Figure 2 shown, the communication method includes the following steps S201 to S203:

[0087] In step S201, a first data packet is received from the first communication end;

[0088] In step S202, by modifying the preset fields of the first data packet according to the data amount of the authentication information of the first communication end and adding the authentication information to the first data packet, a second data packet is obtained;

[0089] In step S203, the second data packet is sent to the second communication end.

[0090] According to an embodiment of the present disclosure, the first communication end includes a client, and the second communication end includes a server. The server realizes the authentication of the client by obtaining the second data packet containing the authentication information of the client. As Figure 1AAs shown, the first data packet can be, for example, an ACK data packet, and the authentication information of the first communication end can be, for example, the VPC-ID of the client. The network device receives the ACK data packet from the client, modifies the preset field of the ACK data packet according to the VPC-ID of the client, adds the obtained VPC-ID to the data field of the data packet, and sends the modified ACK data packet to the server.

[0091] With the solution of the embodiments of the present disclosure, the authentication information (such as VPC-ID) can be completely transmitted from the first communication end to the second communication end. At the same time, since the preset field of the data packet is modified, the difference in the length of the data field caused by adding the authentication information is avoided, so that the client and the server do not have to modify the original sequence number generation and verification logic.

[0092] According to an embodiment of the present disclosure, modifying the preset field of the first data packet according to the data volume of the authentication information of the first communication end includes modifying the sequence number in the header field of the first data packet according to the data volume of the authentication information of the first communication end; and / or adding the authentication information to the first data packet includes adding the authentication information to the data field of the first data packet. For example, as Figure 1B shown, when the first data packet is an ACK data packet, the preset field of the ACK data packet before modification is [seq+1; server seq+1], where "seq+1" represents the sequence number of the header field of the ACK data packet. Modifying the preset field of the first data packet according to the authentication information (such as VPC-ID) of the first communication end, the preset field of the modified ACK data packet is [seq-len(VPC-ID)+1; server seq+1]. When adding the authentication information to the first data packet, taking Figure 1A as an example, the client adds the obtained VPC-ID to the data field of the data packet, and can transmit the VPC-ID completely to the server for authentication.

[0093] According to an embodiment of the present disclosure, the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; modifying the sequence number of the first data packet according to the data volume of the authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number. As Figure 1BAs shown, when the first data packet is an ACK data packet, for example, the sequence number of the first byte of the data field of the ACK data packet is 101 and the length value of the VPC-ID is 10, then the sequence number of the ACK data packet is modified to 101 - 10, and the preset field of the modified ACK data packet is [91; 201]. Since the authentication information (such as VPC-ID) needs to be added to the first data packet, the data length of the data packet received by the second communication end will be longer than the data length of the data packet sent by the first communication end. By modifying the preset field of the first data packet, it is possible to avoid problems such as the second communication end being unable to recognize the order of the data packets sent by the first communication end or a checksum error due to the difference in the data content length after adding the authentication information.

[0094] According to an embodiment of the present disclosure, the method further includes: obtaining the tunnel identifier of the first communication end, and determining the virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier. After the network device receives the SYN data packet, the VPC-ID can be obtained by querying the mapping table through the Tunnel ID. Using the VPC-ID as the authentication information can support third-party service authentication. At the same time, different from the Tunnel ID which may be reused among multiple regions, the VPC-ID has global uniqueness, that is, it is different among multiple regions. Therefore, service authentication for cross-region access can be achieved through the VPC-ID.

[0095] According to an embodiment of the present disclosure, before receiving the first data packet, a third data packet is received from the first communication end, the third data packet is modified by subtracting the length of the authentication information from the sequence number of the third data packet to obtain a fourth data packet; and the fourth data packet is sent to the second communication end.

[0096] According to an embodiment of the present disclosure, the third data packet may be a SYN data packet. For example, as Figure 1B shown, the preset field of the SYN data packet received from the client is [100; NULL], the sequence number 100 is subtracted by len(VPC-ID), for example, len(VPC-ID) is 10, then the preset field of the modified SYN data packet (i.e., the fourth data packet) is [90; NULL].

[0097] According to an embodiment of the present disclosure, the method further includes: receiving a fifth data packet from the second communication end as an acknowledgment of the fourth data packet, modifying the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information to obtain a sixth data packet, where the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet; and sending the sixth data packet to the first communication end.

[0098] According to an embodiment of the present disclosure, the fifth data packet may be a SYN-ACK data packet. As Figure 1B shown, the preset field of the SYN-ACK data packet before modification is [server seq; seq-len(VPC-ID)+1], for example [200; 91]. Among them, the acknowledgment number 91 of the SYN-ACK data packet is obtained by adding 1 to the sequence number 90 of the modified SYN data packet. As Figure 1B shown, the preset field of the modified SYN-ACK data packet (i.e., the sixth data packet) is [200; 101], where the modified acknowledgment number 101 is obtained by adding the length 10 of the VPC-ID to the acknowledgment number 91 of the SYN-ACK data packet.

[0099] According to an embodiment of the present disclosure, the first data packet is an acknowledgment of the sixth data packet, where the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet; or the first data packet is a data packet sent after the acknowledgment data packet of the sixth data packet. For example, as Figure 1B shown, the first data packet is the ACK data packet before modification, and the sixth data packet is the modified SYN-ACK data packet. When the preset field of the sixth data packet is [200; 101], the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet, and the preset field of the first data packet is [101; 201].

[0100] According to an embodiment of the present disclosure, at least one or more of the first to sixth data packets include identification information of the communication connection from the first communication end to the second communication end; and / or the third data packet is a synchronization data packet for establishing a connection between the first communication end and the second communication end.

[0101] For example, at least one or more of the first to sixth data packets include identification information of the communication connection from the first communication end to the second communication end. The identification information is, for example, the five-tuple of the TCP connection to be established between the first communication end and the second communication end, that is, the source IP address, the first port, the destination IP address, the destination port, and the transport layer protocol. After the second communication end authenticates the first communication end successfully, the communication connection can be established according to the identification information.

[0102] According to an embodiment of the present disclosure, the third data packet is a SYN data packet, the fifth data packet is a SYN-ACK data packet, and the first data packet is an ACK data packet. The SYN data packet can be used to establish a connection between the client and the server.

[0103] According to an embodiment of the present disclosure, the method further includes: after the authentication of the first communication end by the second communication end is passed, modifying the session information of the first communication end so that the first communication end directly communicates with the second communication end. For example, as Figure 1A shown, arrows 7 and 8 indicate that the server obtains the VPC-ID for authentication. After the authentication of the client is completed through the VPC-ID, the session information on the virtual network switch where the client is located is modified, enabling the client to directly communicate with the server. Through the above method, direct transmission between the first communication end and the second communication end can be achieved, thereby shortening the communication route between the client and the server and reducing the load on network devices.

[0104] According to an embodiment of the present disclosure, the method is executed by a network device in the same virtual private cloud as the first communication end and the second communication end. Since the network device is a role in the virtual private cloud, changes in the virtual private cloud are synchronously updated to the network device in real time, avoiding authentication failures caused by untimely updates of the mapping relationship between the Tunnel ID and the VPC-ID when adding a new virtual private cloud.

[0105] Figure 3 The structural block diagram of a communication device according to an embodiment of the present disclosure is shown. Among them, the device can be implemented as part or all of an electronic device through software, hardware, or a combination of both.

[0106] As Figure 3 shown, the communication device 300 includes a first receiving module 310, a first modifying module 320, and a first sending module 330.

[0107] The first receiving module 310 is configured to receive a first data packet from the first communication end;

[0108] The first modifying module 320 is configured to modify a preset field of the first data packet according to the data volume of the authentication information of the first communication end, and add the authentication information to the first data packet to obtain a second data packet;

[0109] The first sending module 330 is configured to send the second data packet to the second communication end.

[0110] According to an embodiment of the present disclosure, the first communication end includes a client, and the second communication end includes a server. The server realizes the authentication of the client by obtaining a second data packet containing the authentication information of the client. As Figure 1AAs shown, the first data packet may be an ACK data packet, for example, and the authentication information of the first communication end may be the VPC-ID of the client. The network device receives the ACK data packet from the client, modifies a preset field of the ACK data packet according to the VPC-ID of the client, adds the obtained VPC-ID to the data field of the data packet, and sends the modified ACK data packet to the server.

[0111] With the solution of the embodiments of the present disclosure, the authentication information (such as VPC-ID) can be completely transmitted from the first communication end to the second communication end, so that the second communication end can authenticate the first communication end according to the authentication information.

[0112] According to an embodiment of the present disclosure, the preset field is related to the amount of data sent by the first communication end before the first data packet; and / or the preset field modifies the preset field of the first data packet according to the amount of data of the authentication information of the first communication end, including modifying the sequence number in the header field of the first data packet according to the amount of data of the authentication information of the first communication end; and / or adding the authentication information to the first data packet includes adding the authentication information to the data field of the first data packet. For example, as Figure 1B shown, when the first data packet is an ACK data packet, the preset field of the ACK data packet before modification is [seq + 1; server seq + 1], where "seq + 1" represents the sequence number of the header field of the ACK data packet. Modify the preset field of the first data packet according to the authentication information (such as VPC-ID) of the first communication end, then the preset field of the modified ACK data packet is [seq - len(VPC-ID) + 1; server seq + 1]. When adding the authentication information to the first data packet, Figure 1A for example, the client adds the obtained VPC-ID to the data field of the data packet, and can transmit the VPC-ID completely to the server for authentication.

[0113] According to an embodiment of the present disclosure, the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; modifying the sequence number of the first data packet according to the amount of data of the authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number. As Figure 1BAs shown, when the first data packet is an ACK data packet, for example, the sequence number of the first byte of the data field of the ACK data packet is 101 and the length value of the VPC-ID is 10, then the sequence number of the ACK data packet is modified to 101 - 10 = 91, and the preset field of the modified ACK data packet is [91; 201]. Since it is necessary to add authentication information (such as VPC-ID) to the first data packet, the data length of the data packet received by the second communication end will be longer than the data length of the data packet sent by the first communication end. By modifying the preset field of the first data packet, it is possible to avoid problems such as the second communication end being unable to recognize the order of the data packets sent by the first communication end or a checksum error due to the difference in the data content length after adding the authentication information.

[0114] According to an embodiment of the present disclosure, as Figure 3 shown, the communication device 300 further includes: a determination module 380, configured to obtain the tunnel identifier of the first communication end, and determine the virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier. After the network device receives the SYN data packet, the VPC-ID can be obtained by querying the mapping table through the Tunnel ID. Using the VPC-ID as the authentication information can support third-party service authentication. At the same time, different from the Tunnel ID which may be reused among multiple regions, the VPC-ID has global uniqueness, that is, it is different among multiple regions. Therefore, service authentication for cross-region access can be achieved through the VPC-ID.

[0115] According to an embodiment of the present disclosure, as Figure 3 shown, the communication device 300 further includes:

[0116] A second receiving module 340, configured to receive a third data packet from the first communication end before receiving the first data packet, modify the third data packet by subtracting the length of the authentication information from the sequence number of the third data packet, and obtain a fourth data packet;

[0117] A second sending module 350, configured to send the fourth data packet to the second communication end.

[0118] According to an embodiment of the present disclosure, the third data packet may be a SYN data packet. For example, as Figure 1B shown, the preset field of the SYN data packet received from the client is [100; NULL]. Subtract len(VPC-ID) from the sequence number 100. For example, if len(VPC-ID) is 10, then the preset field of the modified SYN data packet (i.e., the fourth data packet) is [90; NULL].

[0119] According to an embodiment of the present disclosure, as Figure 3 shown, the communication device 300 further includes:

[0120] A third receiving module 360, configured to receive, from the second communication end, a fifth data packet as an acknowledgment of the fourth data packet, modify the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information to obtain a sixth data packet, where the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet;

[0121] A third sending module 370, configured to send the sixth data packet to the first communication end.

[0122] According to an embodiment of the present disclosure, the fifth data packet may be a SYN-ACK data packet. As Figure 1B shown, the preset field of the SYN-ACK data packet before modification is [server seq; seq-len(VPC-ID)+1], for example [200; 91]. Among them, the acknowledgment number 91 of the SYN-ACK data packet is obtained by adding 1 to the sequence number 90 of the modified SYN data packet. As Figure 1B shown, the preset field of the modified SYN-ACK data packet (i.e., the sixth data packet) is [200; 101], where the modified acknowledgment number 101 is obtained by adding the length 10 of the VPC-ID to the acknowledgment number 91 of the SYN-ACK data packet.

[0123] According to an embodiment of the present disclosure, the first data packet is an acknowledgment of the sixth data packet, where the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet; or the first data packet is a data packet sent after the acknowledgment data packet of the sixth data packet. For example, as Figure 1B shown, the first data packet is the ACK data packet before modification, and the sixth data packet is the modified SYN-ACK data packet. When the preset field of the sixth data packet is [200; 101], the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet, and the preset field of the first data packet is [101; 201].

[0124] According to an embodiment of the present disclosure, at least one or more of the first to sixth data packets include identification information of the communication connection from the first communication end to the second communication end; and / or the third data packet is a synchronization data packet for establishing a connection between the first communication end and the second communication end. For example, the third data packet is a SYN data packet, which includes a tunnel identifier of the client, the fifth data packet is a SYN-ACK data packet, and the first data packet is an ACK data packet, which includes a virtual private cloud identifier of the client. The SYN data packet can be used to establish a connection between the client and the server.

[0125] According to an embodiment of the present disclosure, asFigure 3 As shown, the communication device 300 further includes: a second modification module 390, configured to modify the session information of the first communication end after the authentication of the first communication end by the second communication end, so that the first communication end directly communicates with the second communication end. For example, as Figure 1A shown, arrows 7 and 8 indicate that the server obtains the VPC-ID for authentication. After completing the authentication of the client through the VPC-ID, the session information on the virtual network switch where the client is located is modified, enabling the client to directly communicate with the server. Through the above method, direct transmission between the first communication end and the second communication end can be achieved, thereby shortening the communication route between the client and the server and reducing the load on network devices.

[0126] According to an embodiment of the present disclosure, the device is executed by a network device in the same virtual private cloud as the first communication end and the second communication end. Since the network device is a role in the virtual private cloud, changes in the virtual private cloud are synchronously updated to the network device in real time, avoiding authentication failures caused by untimely updates of the mapping relationship between the Tunnel ID and the VPC-ID when adding a new virtual private cloud.

[0127] The present disclosure also discloses an electronic device, Figure 4 showing a structural block diagram of the electronic device according to an embodiment of the present disclosure.

[0128] As Figure 4 shown, the electronic device 400 includes a memory 401 and a processor 402. Among them, the memory 401 is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor 402 to implement the method according to an embodiment of the present disclosure.

[0129] According to an embodiment of the present disclosure, the one or more computer instructions are executed by the processor 402 to implement the following method steps:

[0130] Receive a first data packet from the first communication end;

[0131] Obtain a second data packet by modifying a preset field of the first data packet according to the data volume of the authentication information of the first communication end and adding the authentication information to the first data packet;

[0132] Send the second data packet to the second communication end.

[0133] According to an embodiment of the present disclosure, the preset field is related to the amount of data sent by the first communication end before the first data packet; and / or modifying the preset field of the first data packet according to the amount of authentication information of the first communication end includes modifying the sequence number in the header field of the first data packet according to the amount of authentication information of the first communication end; and / or adding the authentication information to the first data packet includes adding the authentication information to the data field of the first data packet.

[0134] According to an embodiment of the present disclosure, the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; modifying the sequence number of the first data packet according to the amount of authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number.

[0135] According to an embodiment of the present disclosure, the one or more computer instructions are executed by the processor 402 to implement the following method steps:

[0136] Before receiving the first data packet, receive a third data packet from the first communication end, modify the third data packet by subtracting the length of the authentication information from the sequence number of the third data packet, and obtain a fourth data packet;

[0137] Send the fourth data packet to the second communication end.

[0138] According to an embodiment of the present disclosure, the one or more computer instructions are executed by the processor 402 to implement the following method steps:

[0139] Receive a fifth data packet from the second communication end as an acknowledgment of the fourth data packet, modify the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information, and obtain a sixth data packet, where the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet;

[0140] Send the sixth data packet to the first communication end.

[0141] According to an embodiment of the present disclosure, the first data packet is an acknowledgment of the sixth data packet, where the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet; or the first data packet is a data packet sent after the acknowledgment packet of the sixth data packet.

[0142] According to an embodiment of the present disclosure, at least one or more of the first to sixth data packets contain identification information of the communication connection from the first communication end to the second communication end; and / or the third data packet is a synchronization data packet for establishing a connection between the first communication end and the second communication end.

[0143] According to an embodiment of the present disclosure, the one or more computer instructions are executed by the processor 402 to implement the following method steps: obtaining a tunnel identifier of the first communication end, and determining a virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier.

[0144] According to an embodiment of the present disclosure, the first communication end includes a client, and the second communication end includes a server.

[0145] According to an embodiment of the present disclosure, the one or more computer instructions are executed by the processor 402 to implement the following method steps: after the authentication of the first communication end by the second communication end is passed, modifying the session information of the first communication end so that the first communication end directly communicates with the second communication end.

[0146] According to an embodiment of the present disclosure, the method is executed by a network device in the same virtual private cloud as the first communication end and the second communication end.

[0147] Figure 5 A schematic structural diagram of a computer system suitable for implementing the method according to an embodiment of the present disclosure is shown.

[0148] As Figure 5 shown, the computer system 500 includes a processing unit 501, which can execute various methods in the above embodiments according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage section 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the system 500 are also stored. The processing unit 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0149] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs a communication process via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed so that a computer program read from it can be installed into the storage section 508 as needed. Among them, the processing unit 501 can be implemented as a processing unit such as a CPU, a GPU, a TPU, an FPGA, an NPU, etc.

[0150] In particular, according to an embodiment of the present disclosure, the methods described above can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product that tangibly includes a computer program on a machine-readable medium, the computer program including program code for performing the above-described method. In such an embodiment, the computer program can be downloaded and installed from a network via a communication section 509, and / or installed from a removable medium 511.

[0151] The flowcharts and block diagrams in the accompanying drawings illustrate the architectures, functions, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that includes one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0152] The units or modules involved in the embodiments described in the present disclosure can be implemented in software or in programmable hardware. The units or modules described can also be provided in a processor, and the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.

[0153] As another aspect, the present disclosure also provides a computer-readable storage medium, which may be the computer-readable storage medium included in the electronic device or computer system in the above embodiments; or it may exist separately and not be assembled into the device. The computer-readable storage medium stores one or more programs, and the one or more programs are used by one or more processors to execute the methods described in the present disclosure.

[0154] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) disclosed in the present disclosure that have similar functions.

Claims

1. A communication method, comprising: Receiving a first data packet from a first communication end; Obtaining a second data packet by modifying a preset field of the first data packet according to the data volume of the authentication information of the first communication end and adding the authentication information to the first data packet; the preset field is the sequence number in the header field of the first data packet, and the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; The modifying the sequence number of the first data packet according to the data volume of the authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number; Sending the second data packet to a second communication end.

2. The method according to claim 1, wherein: The preset field is related to the data volume sent by the first communication end before the first data packet; and / or The adding the authentication information to the first data packet includes adding the authentication information to the data field of the first data packet.

3. The method according to claim 1, further comprising: Before receiving the first data packet, receiving a third data packet from the first communication end, and modifying the third data packet by subtracting the length of the authentication information from the sequence number of the third data packet to obtain a fourth data packet; Sending the fourth data packet to the second communication end.

4. The method according to claim 3, further comprising: Receiving a fifth data packet from the second communication end as an acknowledgment of the fourth data packet, and modifying the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information to obtain a sixth data packet, wherein the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet; Sending the sixth data packet to the first communication end.

5. The method according to claim 3, wherein: The first data packet is an acknowledgment of the sixth data packet, wherein the sequence number of the first data packet is determined according to the acknowledgment number of the sixth data packet; or The first data packet is a data packet sent after the acknowledgment packet of the sixth data packet.

6. The method according to claim 5, wherein: At least one or more of the first data packet to the sixth data packet contain identification information of the communication connection from the first communication end to the second communication end; and / or The third data packet is a synchronization data packet for establishing a connection between the first communication end and the second communication end.

7. The method according to claim 1, further comprising: Obtaining the tunnel identifier of the first communication end, and determining the virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier.

8. The method according to claim 1, wherein: The first communication end includes a client, and the second communication end includes a server.

9. The method according to claim 1, further comprising: After the second communication end authenticates the first communication end, modifying the session information of the first communication end so that the first communication end and the second communication end communicate directly.

10. The method according to claim 1, wherein, The method is executed by a network device in the same virtual private cloud as the first communication end and the second communication end.

11. A communication device, comprising: A first receiving module, configured to receive a first data packet from a first communication end; A first modifying module, configured to obtain a second data packet by modifying a preset field of the first data packet according to the data volume of the authentication information of the first communication end and adding the authentication information to the first data packet; the preset field is the sequence number in the header field of the first data packet, and the sequence number of the first data packet represents the sequence number of the first byte of the data field of the first data packet; modifying the sequence number of the first data packet according to the data volume of the authentication information of the first communication end includes subtracting the length value of the authentication information from the sequence number; A first sending module, configured to send the second data packet to a second communication end.

12. The device according to claim 11, further comprising: A second receiving module, configured to receive a third data packet from the first communication end before receiving the first data packet, and modify the third data packet by subtracting the length of the authentication information from the sequence number of the third data packet to obtain a fourth data packet; A second sending module, configured to send the fourth data packet to the second communication end.

13. The device according to claim 12, further comprising: A third receiving module, configured to receive a fifth data packet from the second communication end as an acknowledgment of the fourth data packet, and modify the fifth data packet by adding the acknowledgment number of the fifth data packet to the authentication information to obtain a sixth data packet, wherein the acknowledgment number of the fifth data packet is determined according to the sequence number of the fourth data packet; A third sending module, configured to send the sixth data packet to the first communication end.

14. The device according to claim 11, further comprising: A determining module, configured to obtain a tunnel identifier of the first communication end and determine a virtual private cloud identifier of the first communication end as the authentication information according to the tunnel identifier.

15. The device according to claim 11, further comprising: A second modifying module, configured to modify the session information of the first communication end after the second communication end authenticates the first communication end, so that the first communication end directly communicates with the second communication end.

16. An electronic device, comprising a memory and a processor; wherein, The memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the method steps of any one of claims 1-10.

17. A readable storage medium, on which computer instructions are stored, and when the computer instructions are executed by a processor, the method steps of any one of claims 1-10 are implemented.

Citation Information

Patent Citations

  • Method and device for sending and receiving information in peripheral sensing network

    CN106713253A