A message transmission method and related device

By using user host characteristic information and random salt values ​​to determine different CAR channels in the access gateway device, transmitting packets from the user host, solving the problem that packets that have not established a session are squeezed out by attack packets, and normal transmission and session establishment of legitimate user host messages are realized.

CN114374730BActive Publication Date: 2025-06-13HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011096588.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-10-14
Publication Date
2025-06-13
Estimated Expiration
2040-10-14

AI Technical Summary

Technical Problem

In the access gateway device, the packets that have not established a session cannot be distinguished from the legal user host and the illegal user host, resulting in the attack packets of the illegal user host and the packets of the legal user host have been hashed in the same CAR channel, resulting in the packets of the legal user host being squeezed by the attack packets and the session establishment cannot be completed.

Method used

By obtaining the first message and the second message sent by the same user host, different CAR channels are determined using the user host characteristic information and the randomly generated salt value, and the first message and the second message are transmitted respectively, so that the unsecured messages of the legitimate user host can enter the CAR channel where there is no or there are fewer attack messages.

Benefits of technology

It effectively avoids the crowding of packets from attack messages from illegal user hosts on legitimate user hosts, and ensures that the packets from unsecured sessions of the legitimate user hosts can be sent to the CPU to complete the process of establishing a session.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114374730B_ABST
    Figure CN114374730B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a message transmission method and an access gateway device. Embodiments of the present application can be applied to a system architecture with separated control plane and forwarding plane, and can be specifically implemented on an access gateway device. The method includes: The access gateway device determines the CAR channel corresponding to the message according to the user host characteristic information and the changed salt value or the characteristic sequence after random sorting of the bit positions of the user host characteristic information, so that messages sent by the same user host at different time periods can enter different CAR channels for transmission. Therefore, a legitimate user host can avoid the attack of an illegal user host and complete the process of establishing a session.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of network interconnection protocols, and in particular, to a message transmission method and related devices. Background Art

[0002] An access gateway device (AG) generally adopts a system architecture with a separated control plane and forwarding plane. Among them, the central processing unit (CPU) of the control plane has a weak ability to process messages. Once a network attack occurs, it will cause the CPU to be busy in processing, resulting in instability of the entire network. Generally, a committed access rate (CAR) rate limiting policy is adopted during the process of messages being sent from the forwarding plane to the control plane to ensure that the traffic of messages sent to the CPU is within the processing capacity of the CPU.

[0003] The host committed access rate (host-CAR) rate limiting technology is an anti-attack technology that limits the impact of user host attacks within a small range by restricting the traffic of messages sent from user hosts to the CPU. The messages sent to the CPU include messages of established sessions and messages of unestablished sessions. The host-CAR rate limiting technology divides the messages of established sessions and messages of unestablished sessions into different host-CAR areas. For the messages of established sessions, the user host forwarding table entries already generated on the forwarding plane are used to perform legal verification on the messages of established sessions to defend against network attacks from illegal user hosts. For the messages of unestablished sessions, since the user host has not yet undergone legal authentication, it is impossible to distinguish between legal user hosts and illegal attacking user hosts. The access gateway device does not distinguish user hosts for the messages of unestablished sessions and performs overall CAR rate limiting. The access gateway device hashes the messages of unestablished sessions of legal user hosts and the attack messages of unestablished sessions of illegal user hosts to different CAR channels according to a fixed hashing algorithm. When the sending rate of the message exceeds the threshold restricted by the CAR channel, the messages whose sending rate exceeds the threshold will be discarded to achieve the purpose of limiting the attack range of illegal user hosts.

[0004] However, when a large number of attack packets of unestablished sessions sent by an illegal user host appear in the host-CAR area of the packets of unestablished sessions, the access gateway device hashes the packets of unestablished sessions according to a fixed hashing algorithm, which will result in that the legitimate user hosts hashed in the same CAR channel as the attack packets of the illegal user host are fixed. The traffic of the attack packets of the illegal user host is very large, and the packets of the legitimate user hosts with small traffic will be discarded by CAR rate limiting, which will cause all the packets of unestablished sessions sent by the legitimate user hosts hashed in the same CAR channel as the attack packets of the illegal user host to be crowded out by the attack packets, and all the packets of unestablished sessions sent by the legitimate user hosts cannot complete the session establishment process. SUMMARY OF THE INVENTION

[0005] The embodiments of the present application provide a packet transmission method and an access gateway device, which can enable the packets of a legitimate user host to avoid the attack of an illegal user host and complete the process of creating a session.

[0006] The first aspect of the embodiments of the present application provides a packet transmission method:

[0007] First, the access gateway device obtains a first packet and a second packet sent by the same user host, and the first packet and the second packet carry the user host feature information of the user host. The first packet and the second packet are packets sent by the user host at different time periods, and the second packet is sent after the first packet. The access gateway device can pre-obtain the first packet and the second packet and then perform the transmission processing on the first packet and the second packet respectively, or obtain the first packet and transmit the first packet and then obtain the second packet and transmit the second packet. When in the first time period, the access gateway device can transmit the first packet through a pre-determined first CAR channel, and the first CAR channel is determined according to the user host feature information carried in the first packet and a randomly generated first salt value. When in the second time period, the second packet is transmitted through a pre-determined second CAR channel, and the second CAR channel is determined according to the user host feature information carried in the second packet and a randomly generated second salt value, and the second salt value is different from the first salt value.

[0008] It can be seen that transmitting the first packet and the second packet sent by the same user host at different time periods in the first CAR channel and the second CAR channel respectively can enable the packets of unestablished sessions sent by the legitimate user host to enter the CAR channel where there are no or fewer attack packets sent by the illegal user host, and be sent to the CPU to complete the session establishment process.

[0009] Based on the first aspect, the embodiments of the present application also provide a first implementation manner of the first aspect:

[0010] The access gateway device has a pre - set program for randomly generating a salt value. The preset program randomly generates a first salt value. The access gateway device has pre - determined a target hash function for determining the CAR channel, and this target hash function does not change. Based on this target hash function, the access gateway device determines a first hash value according to the user host feature information obtained from the first packet and the randomly generated first salt value. Both the first CAR channel and the second CAR channel have their respective identifiers for differentiation, and the access gateway device has pre - set the corresponding relationship between the hash value and the CAR channel identifier. The access gateway device can determine the first CAR channel corresponding to the first packet according to the first hash value.

[0011] Based on the first aspect or the first implementation manner of the first aspect, the embodiments of the present application also provide a second implementation manner of the first aspect:

[0012] The access gateway device randomly generates a second salt value according to the pre - set program for randomly generating a salt value. The second salt value is different from the first salt value. The access gateway device determines a second hash value based on the pre - determined target hash function according to the user host feature information obtained from the second packet and the randomly generated second salt value. The access gateway device determines the second CAR channel corresponding to the second packet according to the pre - determined corresponding relationship between the hash value and the CAR channel and the second hash value.

[0013] It can be seen that in the embodiments of the present application, according to the user host feature information and the randomly generated salt value, packets sent by the same user host at different times enter different CAR channels. Since the salt value has a long string and high randomness, the repetition probability of the hash value can be greatly reduced, improving the feasibility of the solution.

[0014] Based on any one of the first aspect, the first implementation manner to the second implementation manner of the first aspect, the embodiments of the present application also provide a third implementation manner of the first aspect:

[0015] The user host feature information includes at least one of a VLAN tag or a MAC address.

[0016] Based on any one of the first aspect, the first implementation manner to the third implementation manner of the first aspect, the embodiments of the present application also provide a fourth implementation manner of the first aspect:

[0017] The first packet is a packet sent to the CPU. The packet sent to the CPU is an online interaction packet, an online detection packet, or a protocol packet.

[0018] Based on any one of the first aspect, the first implementation manner to the third implementation manner of the first aspect, the embodiments of the present application also provide a fourth implementation manner of the first aspect:

[0019] The second message is a message sent to the CPU, and the message sent to the CPU is an online interaction message, an online detection message, or a protocol message.

[0020] The second aspect of the embodiments of the present application provides a message transmission method:

[0021] The access gateway device obtains a first message and a second message sent by the same user host, and the first message and the second message carry the user host feature information of the user host. The first message and the second message are messages sent by the user host at different time periods, and the second message is sent after the first message. The access gateway device can pre-obtain the first message and the second message and then process the transmission of the first message and the second message respectively, or obtain the first message and transmit the first message and then obtain the second message to transmit the second message. When in the first time period, the access gateway device can transmit the first message through a pre-determined first CAR channel. The first CAR channel is determined by the access gateway device according to the first feature sequence. The access gateway device presets a program for randomly sorting bit positions. When in the first time period, the random sorting program randomly sorts at least two bit positions included in the user host feature information carried in the first message to obtain a first feature sequence. When in the second time period, the random sorting program randomly sorts at least two bit positions included in the user host feature information carried in the second message to obtain a second feature sequence. Although the second feature sequence and the first feature sequence are based on the same user host feature information, the second feature sequence and the first feature sequence are determined based on different random sorting methods, so the second feature sequence is different from the first feature sequence.

[0022] Based on the second aspect, the embodiments of the present application also provide a first implementation manner of the second aspect:

[0023] The access gateway device randomly sorts at least two bit positions included in the user host feature information obtained from the first message according to the random sorting program to obtain a first feature sequence. The access gateway device determines a first hash value based on a pre-determined target hash function according to the first feature sequence obtained by randomly sorting the user host feature information. The access gateway device determines the first CAR channel corresponding to the first message based on the corresponding relationship between the hash value and the CAR channel set in advance and the first hash value.

[0024] Based on the second aspect or the first implementation manner of the second aspect, the embodiments of the present application also provide a second implementation manner of the second aspect:

[0025] The access gateway device randomly sorts at least two bits included in the user host feature information obtained from the second message according to a random sorting program to obtain a second feature sequence, which is different from the first feature sequence. The access gateway device determines a second hash value based on a pre-determined target hash function according to the second feature sequence obtained by randomly sorting the user host feature information. The access gateway device determines a second CAR channel corresponding to the second message based on the correspondence between the hash value and the CAR channel set in advance and the second hash value.

[0026] It can be seen that in the embodiment of the present application, by randomly sorting the user host feature information itself, the messages sent by the same user host at different time periods enter different CAR channels, without the need to introduce an additional random step, improving the simplicity of the solution, reducing the operation time of the processor, and saving the computing resources of the processor.

[0027] Based on any one of the second aspect, the first implementation manner to the second implementation manner of the second aspect, the embodiment of the present application further provides a third implementation manner of the second aspect:

[0028] The user host feature information includes at least one of a VLAN tag or a MAC address.

[0029] Based on any one of the second aspect, the first implementation manner to the third implementation manner of the second aspect, the embodiment of the present application further provides a fourth implementation manner of the second aspect, specifically:

[0030] The first message is a message sent to the CPU, and the message sent to the CPU is an online interaction message, an online detection message, or a protocol message.

[0031] Based on any one of the second aspect, the second implementation manner to the third implementation manner of the second aspect, the embodiment of the present application further provides a fourth implementation manner of the second aspect:

[0032] The second message is a message sent to the CPU, and the message sent to the CPU is an online interaction message, an online detection message, or a protocol message.

[0033] The embodiment of the third aspect of the present application provides an access gateway device, which has the function of implementing the behavior of the access gateway device in the first aspect above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0034] In the fourth aspect of the embodiments of the present application, an access gateway device is provided. The access gateway device has the function of implementing the behavior of the access gateway device in the second aspect above. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0035] In the fifth aspect of the embodiments of the present application, a computer storage medium is provided. The computer storage medium is used to store computer software instructions for the above access gateway device, and it includes a program designed for the access gateway device.

[0036] In the sixth aspect of the embodiments of the present application, a computer program product is provided. The computer program product includes computer software instructions, and these computer software instructions can be loaded by a processor to implement the processes in the message transmission method in any one of the first aspect to the second aspect above.

[0037] As can be seen from the above technical solutions, the embodiments of the present application have the following advantages: obtaining the first message and the second message of the same user host. When in the first time period, determining the first CAR channel according to the user host feature information and the first salt value, and transmitting the first message through the first CAR channel. When in the second time period, determining the second CAR channel according to the user host feature information and the second salt value, and transmitting the second message through the second CAR channel. According to the user host feature information and the dynamically changing salt value, the messages without established sessions sent by legitimate user hosts can be hashed in different CAR channels. In the CAR channels without attack messages from illegal user hosts, the messages without established sessions sent by legitimate user hosts can be sent to the CPU to complete the process of establishing a session. Description of the Drawings

[0038] Figure 1 It is an architecture diagram of the access gateway device;

[0039] Figure 2 It is a schematic diagram of an embodiment of the message transmission method in the embodiments of the present application;

[0040] Figure 3 It is a schematic diagram of another embodiment of the message transmission method in the embodiments of the present application;

[0041] Figure 4 It is a schematic diagram of another embodiment of the message transmission method in the embodiments of the present application;

[0042] Figure 5 It is a schematic diagram of an embodiment of the access gateway device in the embodiments of the present application;

[0043] Figure 6 It is a schematic diagram of another embodiment of the access gateway device in the embodiments of the present application;

[0044] Figure 7 Schematic diagram of another embodiment of the access gateway device according to an embodiment of the present application;

[0045] Figure 8 Schematic diagram of another embodiment of the access gateway device according to an embodiment of the present application;

[0046] Figure 9 Schematic diagram of another embodiment of the access gateway device according to an embodiment of the present application. Detailed implementation manners

[0047] The embodiment of the present application provides a message transmission method, which enables the messages without established sessions sent by legitimate user hosts to be hashed in different CAR channels. In the CAR channels where there are no or few attack messages sent by illegal user hosts, the messages without established sessions sent by legitimate user hosts can be sent to the CPU to complete the process of establishing sessions.

[0048] The host committed access rate (host-CAR) rate limiting technology is an anti-attack technology that limits the impact of user host attacks to a small range by restricting the traffic of messages sent by user hosts to the CPU. The messages sent to the CPU include the messages with established sessions and the messages without established sessions. The host-CAR rate limiting technology divides the messages with established sessions and the messages without established sessions into different host-CAR regions. The message transmission method provided by the embodiment of the present application is applied to the transmission of messages in the host-CAR region without established sessions.

[0049] For the messages without established sessions, since the user hosts have not undergone legitimacy authentication, the access gateway device cannot distinguish between legitimate user hosts and illegal user hosts. Therefore, the access gateway device does not distinguish user hosts for the messages without established sessions. The access gateway device can hash the messages without established sessions sent by different user hosts to different CAR channels according to the hash algorithm, perform CAR rate limiting within the CAR channels, and transmit the messages passing through the CAR channels to the entity that can process the messages.

[0050] The message transmission method provided by the embodiment of the present application is applied to a device architecture, which includes a forwarding plane device and a control plane device.

[0051] The forwarding plane device is used for encapsulating and forwarding data messages. Exemplarily, after the system receives an IP message, the forwarding plane device performs operations such as de-encapsulating the IP message, looking up the routing table, and forwarding from the outgoing interface. For example, the forwarding plane device can be a network processor, and the network processor can adopt a committed access rate (CAR) rate limiting policy for the messages that need to be locally processed and received, and then send the rate-limited messages to the control plane device.

[0052] A control plane device for transmitting instructions and calculating table entries. For example, routing protocol learning, routing table entry maintenance, protocol message forwarding, protocol table entry calculation, maintenance, etc. Exemplarily, the control plane device may be a central processing unit, which can receive messages sent by a forwarding plane device.

[0053] It can be understood that the forwarding plane device and the control plane device in the embodiments of the present application can be a processor or a chip. The forwarding plane device and the control plane device can be separately configured or configured in one device, and the present application does not limit this. Here, only the case where the forwarding plane device and the control plane device are configured in one device is taken as an example for illustration. Exemplarily, the device may be an access gateway device.

[0054] Exemplarily, the access gateway device 100 adopts a system architecture with a separated control plane and forwarding plane. The forwarding plane is used to implement the function of message forwarding, and the control plane is used to implement the control of message forwarding, such as Figure 1 As shown, the forwarding plane of the access gateway device includes: a network processor 101, a physical interface card 102, and a forwarding table entry memory 103, and the control plane includes: a central processing unit 104.

[0055] Among them, the network processor 101 is a programmable processor designed specifically for processing data packets and can be used for the management of routing tables, system configuration, and management. The network processor 101 usually consists of several microcode processors and several hardware coprocessors inside. Multiple microcode processors process in parallel inside the network processor, and the processing flow is controlled by pre-compiled microcode. For complex operations (such as memory operations, routing table lookup algorithms, QoS congestion control algorithms, traffic scheduling algorithms, etc.), hardware coprocessors are used to further improve the processing performance, thus realizing the organic combination of service flexibility and high performance.

[0056] The physical interface card 102 provides a physical connection between the access gateway device 100 and a specific type of network medium, and the interface of the physical interface card 102 can be flexibly upgraded and changed according to actual needs.

[0057] The routing table entry memory 103 stores the routing table of the access gateway device 100, which is generated according to the routing table of the control plane, and its table items and routing table items have a direct correspondence, but the format of the routing table is different from that of the routing table, and it is more suitable for realizing fast search. The routing table entry memory 103 can specifically include a volatile memory (volatile memory, VM), such as a random access memory (random-access memory, RAM); the memory can also include a non-volatile memory (non-volatile memory, NVM), a flash memory (flash memory, FM), a hard disk (hard disk drive, HDD) or a solid-state drive (solid-state drive, SSD); the routing table entry memory 103 can also include a combination of the above-mentioned types of memory.

[0058] The central processing unit 104 is the core component of the access gateway device, which can be used to execute the instructions of the routing operating system, interpret and execute the commands input by the user host, and complete the work related to computing.

[0059] Understandably, Figure 1 This is only an exemplary description. In actual applications, the access gateway device 100 may include Figure 1 More or fewer components as shown, Figure 1 The structure shown does not impose any limitation on the access gateway device provided in the embodiment of the present application.

[0060] In an embodiment of the present application, an access gateway device receives a message sent by a user host, dynamically adjusts a hash algorithm according to characteristic information of the user host, and transmits messages sent by the same user host in different time periods through different CAR channels.

[0061] It should be noted that, in the present application, the transmission of the first message and the second message is used as an example for explanation. In practical applications, more CAR channels can be used for transmission. In the present application, the first time period and the second time period are used as examples for explanation. In practical applications, more different time periods can be used for transmission. These are all for illustration and should not be understood as limiting the present application.

[0062] In order to facilitate the understanding of this application, some definitions of terms involved in this application are introduced below.

[0063] 1. Committed access rate (CAR) speed limit;

[0064] The CAR speed limit acts at the network entrance to control the traffic of a certain type of packets entering the network and allows packets that meet the traffic regulations to enter the network. The CAR speed limit can ensure that packets meeting the traffic regulations enter the network. For packets exceeding the traffic regulations, they can be either directly discarded according to the current network resource usage situation or re-marked (i.e., their priority is reduced) and then forwarded. When congestion occurs, these packets will be preferentially discarded:

[0065] 2. Salt value;

[0066] The salt value is a randomly generated set of strings, which can include random uppercase and lowercase letters, numbers, or characters, and the number of digits can vary according to requirements.

[0067] 3. CAR channel;

[0068] The CAR channel is a channel with CAR function. A channel refers to a processor that is independent of the CPU and is specifically used for input / output control.

[0069] 4. Bit;

[0070] A bit is the smallest storage unit in a computer, and its value is represented by 0 or 1.

[0071] 5. Hash function;

[0072] A hash function is a function that describes the correspondence between the key value of a data element and the storage location of that element.

[0073] 6. Input key value;

[0074] The input key value refers to the input value used for hash function operations.

[0075] 7. Virtual Local Area Network (VLAN) tag;

[0076] The VLAN tag is used to indicate the members of a VLAN and is encapsulated in frames that can traverse the local area network.

[0077] 8. Media Access Control (MAC) address;

[0078] The MAC address uniquely identifies a network card in the network. If a device has one or more network cards, each network card needs and will have a unique MAC address.

[0079] 9. Protocol packet;

[0080] The protocol packet refers to various network protocol packets.

[0081] 10. Online interaction packet;

[0082] Online interaction message: An interaction message sent by the client to establish a session with the access device.

[0083] 11. Online detection message;

[0084] Online detection message: After the client completes establishing a session with the access device, the client and the access gateway device send hello detection messages to each other to sense the status of the peer.

[0085] 12. First time period and second time period;

[0086] In this embodiment, the first time period and the second time period are different time periods. The durations of the first time period and the second time period can be the same or different. In this embodiment, it is taken as an example that the first time period and the second time period are the same. There can be only one process of determining the CAR channel corresponding to the message within the first time period or the second time period, and the durations of the first time period and the second time period must meet the time required for the message to be transmitted through the CAR channel to the CPU and complete the process of establishing a session. The start and end points of the time are not specifically limited.

[0087] Combined with the above introduction, the message transmission method provided by the present application will be introduced below through embodiments of different methods for determining the CAR channel. The message transmission method can determine the CAR channel corresponding to the message in various ways. For example, it can be determined through the user host characteristic information and the salt value, or for example, it can be determined through the characteristic sequence obtained by randomly sorting the bit positions of the user host characteristic information. The following will be described separately:

[0088] 1. Determine the CAR channel corresponding to the message according to the user host characteristic information and the changing salt value;

[0089] In this embodiment, the access gateway device obtains the user host characteristic information according to the message, determines the CAR channel corresponding to the message according to the user host characteristic information and the changing salt value, and transmits the corresponding message through the CAR channel.

[0090] Please refer to Figure 2 , the embodiment of the message transmission method in the embodiment of the present application includes:

[0091] 201. Obtain the first message and the user host characteristic information carried by the first message.

[0092] When in the first time period, the access gateway device obtains the first message sent by the user host, and the user host characteristic information of the user host is carried in the first message. Assume that the user host is a legitimate user host.

[0093] It can be understood that the first message can be an online interaction message, or other messages sent to the CPU, such as an online detection message or a protocol message. Specifically, it is not limited here.

[0094] It is understandable that the user host characteristic information may be a VLAN tag or an identifier of other user hosts, such as a MAC address, and is not specifically limited here.

[0095] It is understandable that in this application, the first message transmitted may be one or more, which is not limited here.

[0096] 202. Randomly generate a first salt value.

[0097] The access gateway device has a pre-set program to randomly generate a salt value at fixed time intervals and generates a first salt value. Specifically, taking the fixed time interval of 5 seconds as an example, assume that at the 10th second, the first salt value is randomly generated by the pre-set program, and at the 15th second, the second salt value is generated by the pre-set program.

[0098] It is understandable that step 202 can be executed after step 201 or before step 201, as long as it is executed before step 203.

[0099] 203. Determine a first hash value according to the user host characteristic information and the first salt value.

[0100] In this embodiment, the access gateway device uses the user host characteristic information obtained from the first message and the randomly generated first salt value as the input key values of the target hash function, and generates the first hash value of the first message based on the target hash function.

[0101] It is understandable that the user host characteristic information may be a VLAN tag or an identifier of other user hosts, such as a MAC address, and is not specifically limited here.

[0102] It is understandable that the VLAN tag or the MAC address can be used alone as the input key value of the target hash function, or other combinations of user host characteristic information can be used. For example, the VLAN tag and the MAC address are sequentially concatenated as the input key value of the target hash function, or the MAC address and the VLAN tag are sequentially concatenated as the input key value of the target hash function, which is not specifically limited here.

[0103] 204. Determine a first CAR channel according to the first hash value.

[0104] The access gateway device determines the first CAR channel corresponding to the first hash value. Each CAR channel has an identifier used to represent different CAR channels, and these identifiers of the CAR channels correspond to the hash values.

[0105] 205. Transmit the first message through the first CAR channel.

[0106] In the first CAR channel, the access gateway device will perform overall CAR rate limiting on all packets ready to be transmitted through the first CAR channel, so that the transmission rate of the packets is less than the preset rate in the first CAR channel, and transmit the packets that meet the rate through the CAR channel. When there are a large number of attack packets sent by an illegal user host in the first CAR channel, the first packet will be discarded due to CAR rate limiting and cannot be sent to the CPU, and the session establishment process of the legal user host (assuming that the user host sending the first packet is a legal user host) cannot be completed.

[0107] 206. Obtain the second packet and the user host feature information carried by the second packet.

[0108] Assume that in step 205, the legal user host that sent the first packet fails to establish a session, and this legal user host will try to send a packet again, which is called the second packet here.

[0109] When in the second time period, the user host that sent the first packet sends the second packet to the access gateway device in the second time period, and the access gateway device obtains the second packet and the user host feature information carried by the second packet that is the same as the user host feature information carried by the first packet. Among them, the second time period is different from the first time period.

[0110] It can be understood that the number of transmitted second packets can be one or more, which is not limited here.

[0111] It can be understood that the user host feature information can be a VLAN tag or an identifier of other user hosts, such as a MAC address, which is not specifically limited here.

[0112] 207. Randomly generate a second salt value.

[0113] The access gateway device has a program for randomly generating salt values at regular time intervals and generates a second salt value, which is different from the first salt value.

[0114] 208. Determine the second hash value according to the user host feature information and the second salt value.

[0115] The access gateway device uses the user host feature information obtained from the second packet and the randomly generated second salt value as the input keyword values of the target hash function, and obtains the second hash value of the second packet based on the target hash function.

[0116] In this embodiment, the user host feature information can be a VLAN tag or an identifier of other user hosts, such as a MAC address, which is not specifically limited here.

[0117] In this embodiment, the VLAN tag or the MAC address can be used alone as the input keyword value of the target hash function, or it can be other combination methods of the user host feature information. For example, the VLAN tag and the MAC address are sequentially concatenated as the input keyword value of the target hash function, or the MAC address and the VLAN tag are sequentially concatenated as the input keyword value of the target hash function. Specifically, it is not limited here.

[0118] 209. Determine a second CAR channel according to the second hash value.

[0119] The access gateway device determines the second CAR channel corresponding to the second hash value. Each CAR channel has an identifier for indicating different CAR channels, and the identifiers of these CAR channels correspond to the hash values.

[0120] 210. Transmit the second message through the second CAR channel.

[0121] Within the second CAR channel, the access gateway device will perform overall CAR rate limiting on all messages to be transmitted through the second CAR channel, so that the transmission rate of the messages is less than the preset rate within the second CAR channel, and transmit the messages that meet the rate through the CAR channel. The first message sent by the user host in the first time period was crowded out and discarded by an illegal user host, and the user host did not complete the session establishment process. In the second time period, due to the change of the salt value causing the change of the hash value, the second message sent by the user host enters the second CAR channel. There are no or few attack messages sent by illegal user hosts within the second CAR channel. After the second message is sent to the CPU, the user host completes the session establishment process.

[0122] From the above technical solutions, it can be seen that the embodiments of the present application have the following advantages: Obtain the first message and the second message of the same user host. When in the first time period, determine the first CAR channel according to the user host feature information and the first salt value, and transmit the first message through the first CAR channel. When in the second time period, determine the second CAR channel according to the user host feature information and the second salt value, and transmit the second message through the second CAR channel. According to the user host feature information and the dynamically changing salt value, the messages sent by the legitimate user host that have not established a session can be hashed in different CAR channels. Within the CAR channel where there are no or few attack messages sent by illegal user hosts, the messages sent by the legitimate user host that have not established a session can be sent to the CPU to complete the session establishment process.

[0123] II. Determine the CAR channel corresponding to the message according to the feature sequence re-ordered according to the user host feature information;

[0124] In this embodiment, the access gateway device obtains the user host feature information according to the packet, determines the CAR channel corresponding to the packet according to the feature sequence obtained by randomly sorting the bit positions of the user host feature information, and transmits the corresponding packet through the CAR channel. Access gateway device.

[0125] Please refer to Figure 3 , the embodiment of the packet transmission method in the embodiment of the present application includes:

[0126] 301. Obtain the first packet and the user host feature information carried by the first packet.

[0127] Step 301 in this embodiment is similar to step 201 in the foregoing Figure 2 illustrated embodiment, and will not be elaborated here.

[0128] 302. Randomly sort the bit positions included in the user host feature information.

[0129] The access gateway device may randomly sort the bit positions of the user host feature information carried in the second packet that are the same as those in the first packet to obtain a first feature sequence.

[0130] In this embodiment, the access gateway device may randomly sort two bit positions included in the user host feature information to obtain a first feature sequence, or may randomly sort multiple bit positions included in the user host feature information. For example, randomly sort two bit positions included in the user host feature information, and specifically, it is not limited here.

[0131] 303. Determine a first hash value according to the first feature sequence.

[0132] The access gateway device takes the first feature sequence obtained by randomly sorting two bit positions included in the user host feature information as the input key value of the target hash function, and generates a first hash value of the first packet based on the target hash function.

[0133] 304. Determine a first CAR channel according to the first hash value.

[0134] 305. Transmit the first packet through the first CAR channel.

[0135] 306. Obtain the second packet and the user host feature information carried by the second packet.

[0136] Steps 304 to 306 in this embodiment are similar to steps 204 to 206 in the foregoing Figure 2 illustrated embodiment, and will not be elaborated here.

[0137] 307. Randomly sort the bit positions included in the user host feature information.

[0138] The access gateway device randomly sorts the bit positions of the same user host feature information carried in the second message as that carried in the first message to obtain a second feature sequence.

[0139] In this embodiment, the second feature sequence is different from the first feature sequence. The reordering is based on a random program preset in the access gateway device, which can ensure that the same feature sequence is not generated during operation.

[0140] 308. Determine a second CAR channel according to the second hash value.

[0141] 309. Transmit the second message through the second CAR channel.

[0142] Steps 308 to 309 in this embodiment are similar to steps 209 to 210 in the foregoing Figure 2 illustrated embodiment, and will not be elaborated here.

[0143] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages: obtaining a first message and a second message of the same user host. When in the first time period, determining a first CAR channel according to the user host feature information and the first salt value, and transmitting the first message through the first CAR channel. When in the second time period, determining a second CAR channel according to the user host feature information and the second salt value, and transmitting the second message through the second CAR channel. According to the user host feature information and the dynamically changing salt value, the messages without established sessions sent by legal user hosts can be hashed into different CAR channels. In the CAR channels where there are no or few attack messages sent by illegal user hosts, the messages without established sessions sent by legal user hosts can be sent to the CPU to complete the process of establishing a session.

[0144] The above is the flow schematic diagram of the message transmission method provided by the embodiments of the present application. The following is a specific application scenario schematic diagram of the message transmission method provided by the embodiments of the present application, where Figure 4 Figure (A) corresponds to the first time period of the message transmission method of the embodiments of the present application, Figure 4 and Figure (B) corresponds to the second time period of the message transmission method of the embodiments of the present application.

[0145] Based on the content introduced in the above embodiments, the following will combine Figure 4 to introduce an application scenario of the message transmission method. Please refer to Figure 4In Figure (A), during the first time period, several user hosts that have not established a session send packets to the CPU in the host-CAR area where no session has been established. In this embodiment, four user hosts, namely A, B, C, and D, are taken as examples. User hosts A, C, and D are legitimate user hosts. A sends N packets, C sends S packets, and D sends P packets; B is an illegal user host and sends M packets. Since B is an illegal user host, the number of attack packets it sends is very large. For example, M is 100,000, N is 3,000, S is 2,000, and P is 1,500.

[0146] Packets of the same user host can only enter the same CAR channel. To save transmission resources, there can be packets of several user hosts in the same CAR channel. Packets of user host A and user host B enter CAR channel 1, packets of user host C enter CAR channel 2, and packets of user host D enter CAR channel 3.

[0147] A CAR speed limit will be preset in the CAR channel. Packets whose transmission rate exceeds the preset rate will be discarded. The S packets sent by user host C and the P packets sent by user host D have normal rates and successfully pass through the CAR channel and are sent to the CPU. The large number of attack packets sent by the illegal user host B have a very fast rate. The total rate of the packets sent by user host A and user host B exceeds the preset rate threshold of CAR channel 1, and the CAR channel performs CAR speed limit on the packets of user host A and user host B.

[0148] The N packets of user host A are very small in number compared to the M packets sent by user host B and are discarded due to CAR speed limit. After the M packets of user host B are CAR speed limited, a large number of packets are discarded, and the remaining W packets of user host B that meet the preset rate pass through the CAR channel and attack the CPU.

[0149] After the packets of user host C and user host D are sent to the CPU, user host C and user host D complete the process of establishing a session and pass the legality authentication, and will not transmit in the host-CAR area of the packets where no session has been established and do not participate in the transmission in the host-CAR area of the packets where no session has been established in the next time period. The packets of user host A are still transmitted in this area.

[0150] Please refer to Figure 4 In Figure (B), during the second time period, the packets of user host A are not sent to the CPU and are still transmitted in this area. The S packets sent by user host E and the P packets sent by user host F enter the access gateway device.

[0151] The dynamically changing hash algorithm causes the CAR channels corresponding to the packets to change. N packets of user host A enter the CAR channel 3 for transmission, P packets sent by user host F enter the CAR channel 1 for transmission, S packets of user host E and M packets of user host B enter the CAR channel 2 for transmission.

[0152] All S packets sent by user host E are discarded, and most of the M packets sent by user host B are discarded, leaving W packets that meet the preset rate threshold. The packets of user host A are no longer in the same CAR channel as the packets of the illegal user host B and are discarded.

[0153] The packets of user host A are sent to the CPU to complete the process of establishing a session.

[0154] Among them, in the above process, the transmission of the packets depends on the determination of the CAR channels through which the packets sent by the same user host at different time periods need to pass. There are two cases for determining the CAR channels. The first is determined by the hash algorithm determined according to the user host characteristic information and the randomly generated salt value. The specific method is as Figure 2 described in the embodiment, which will not be elaborated here. The second is determined by the hash algorithm determined according to the characteristic sequence obtained by randomly sorting the bit positions included in the user host characteristic information. The specific method is as Figure 3 described in the embodiment, which will not be elaborated here.

[0155] The above describes the packet transmission method in the embodiment of the present application. Next, the access gateway device in the embodiment of the present application will be described:

[0156] Please refer to Figure 5 , an embodiment of the access gateway device in the embodiment of the present application includes:

[0157] The first acquisition unit 501 is used to acquire a first packet, where the first packet carries user host characteristic information;

[0158] The second acquisition unit 503 is used to acquire a second packet, where the second packet carries the user host characteristic information;

[0159] The first transmission unit 502 is used to transmit the first packet through the first committed access rate (CAR) channel when in the first time period, where the first CAR channel is determined according to the user host characteristic information and the first salt value;

[0160] The second transmission unit 504 is used to transmit the second packet through the second CAR channel when in the second time period, where the second CAR channel is determined according to the user host characteristic information and the second salt value, and the second salt value is different from the first salt value.

[0161] Please refer to Figure 6 , another embodiment of the access gateway device in the embodiments of the present application includes:

[0162] A first acquisition unit 601, a second acquisition unit 603, a first transmission unit 602, and a second transmission unit 604. The functions of these four units are similar to those described in the embodiment shown in the foregoing Figure 5 and will not be elaborated herein.

[0163] A first generation unit 605, configured to randomly generate a first salt value;

[0164] A first determination unit 606, based on a target hash function, configured to determine a first hash value according to the user host feature information and the first salt value;

[0165] A second determination unit 607, configured to determine the first CAR channel corresponding to the first message according to the first hash value, where the first CAR channel has a corresponding relationship with the first hash value.

[0166] A second generation unit 608, configured to randomly generate a second salt value;

[0167] A third determination unit 609, based on the target hash function, configured to determine a second hash value according to the user host feature information and the second salt value;

[0168] A fourth determination unit 610, configured to determine the second CAR channel corresponding to the second message according to the second hash value, where the second CAR channel has a corresponding relationship with the second hash value.

[0169] Please refer to Figure 7 , another embodiment of the access gateway device in the embodiments of the present application includes:

[0170] A first acquisition unit 701, configured to acquire a first message, where the first message carries user host feature information, and the user host feature information includes at least two bit positions;

[0171] A second acquisition unit 703, configured to acquire a second message, where the second message carries the user host feature information;

[0172] A first transmission unit 702, configured to transmit the first message through a first CAR channel when in a first time period, where the first CAR channel is determined according to a first feature sequence, and the first feature sequence is obtained by randomly sorting at least two bit positions included in the user host feature information;

[0173] A second transmission unit 704, configured to transmit the second message through a second CAR channel when in a second time period, where the second CAR channel is determined according to a second feature sequence, and the second feature sequence is obtained by randomly sorting at least two bits included in the user host feature information.

[0174] Please refer to Figure 8 , another embodiment of the access gateway device in the embodiments of the present application includes:

[0175] A first acquisition unit 801, a second acquisition unit 803, a first transmission unit 802, and a second transmission unit 804. The functions of these four units are similar to those described in the foregoing Figure 8 embodiment shown and will not be elaborated herein.

[0176] A first sorting unit 805, configured to randomly sort at least two bits included in the user host feature information to obtain the first feature sequence;

[0177] A first determination unit 806, based on a target hash function, configured to determine a first hash value according to the first feature sequence;

[0178] A second determination unit 907, configured to determine the first CAR channel corresponding to the first message according to the first hash value, where the first CAR channel has a corresponding relationship with the first hash value.

[0179] A second sorting unit 808, configured to randomly sort at least two bits included in the user host feature information to obtain the second feature sequence;

[0180] A third determination unit 809, based on a target hash function, configured to determine a second hash value according to the second feature sequence;

[0181] A fourth determination unit 810, configured to determine the second CAR channel corresponding to the second message according to the second hash value, where the second CAR channel has a corresponding relationship with the second hash value.

[0182] Figure 9 is a schematic structural diagram of an access gateway device provided by an embodiment of the present application. The access gateway device 900 may include one or more central processing units (CPUs) 901 and a memory 905, and one or more application programs or data are stored in the memory 905.

[0183] Among them, the memory 905 can be volatile storage or persistent storage. The programs stored in the memory 905 can include one or more modules, and each module can include a series of instruction operations on the server. Further, the central processing unit 901 can be set to communicate with the memory 905 and execute a series of instruction operations in the memory 905 on the access gateway device 900.

[0184] The access gateway device 900 can also include one or more power supplies 902, one or more wired or wireless network interfaces 903, one or more input / output interfaces 904, and / or one or more operating systems, such as Windows Server TM , Mac OS X TM , Unix TM , Linux TM , FreeBSD TM and so on.

[0185] The central processing unit 901 can perform the operations executed by the access gateway device in the foregoing Figures 2 to 4 illustrated embodiments, and the details are not described herein again.

[0186] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and are not described herein again.

[0187] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings, direct couplings, or communication connections shown or discussed with each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can be in electrical, mechanical, or other forms.

[0188] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0189] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0190] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical discs that can store program codes.

Claims

1. A message transmission method, characterized in that, it includes: Obtain a first message, where the first message carries user host characteristic information; Obtain a second message, where the second message carries the user host characteristic information; When in a first time period, transmit the first message through a first Committed Access Rate (CAR) channel, where the first CAR channel is determined according to the user host characteristic information and a first salt value; When in a second time period, transmit the second message through a second CAR channel, where the second CAR channel is determined according to the user host characteristic information and a second salt value, and the second salt value is different from the first salt value.

2. The message transmission method according to claim 1, characterized in that, after obtaining the first message and before transmitting the first message through the first CAR channel, the method further includes: Randomly generate a first salt value; Based on a target hash function, determine a first hash value according to the user host characteristic information and the first salt value; Determine the first CAR channel corresponding to the first message according to the first hash value, and the first CAR channel has a corresponding relationship with the first hash value.

3. The message transmission method according to any one of claims 1 to 2, characterized in that, after obtaining the second message and before transmitting the second message through the second CAR channel, the method further includes: Randomly generate a second salt value; Based on a target hash function, determine a second hash value according to the user host characteristic information and the second salt value; Determine the second CAR channel corresponding to the second message according to the second hash value, and the second CAR channel has a corresponding relationship with the second hash value.

4. The message transmission method according to any one of claims 1 to 2, characterized in that, the user host characteristic information includes at least one of a Virtual Local Area Network (VLAN) tag and a Media Access Control (MAC) address.

5. The message transmission method according to any one of claims 1 to 2, characterized in that, the first message is an upload CPU message; the upload CPU message is an online interaction message, an online detection message or a protocol message.

6. The message transmission method according to any one of claims 1 to 2, characterized in that, the second message is an upload CPU message; the upload CPU message is an online interaction message, an online detection message or a protocol message.

7. A message transmission method, characterized in that, it includes: Obtain a first message, where the first message carries user host characteristic information, and the user host characteristic information includes at least two bit positions; Obtain a second message, where the second message carries the user host characteristic information; When in a first time period, transmit the first message through a first CAR channel, where the first CAR channel is determined according to a first characteristic sequence, and the first characteristic sequence is obtained by randomly sorting at least two bit positions included in the user host characteristic information; When in the second time period, the second message is transmitted through the second CAR channel, where the second CAR channel is determined according to a second feature sequence, and the second feature sequence is obtained by randomly sorting at least two bit positions included in the user host feature information.

8. The message transmission method according to claim 7, wherein, after obtaining the first message and before transmitting the first message through the first CAR channel, the method further includes: randomly sorting at least two bit positions included in the user host feature information to obtain the first feature sequence; determining a first hash value based on a target hash function according to the first feature sequence; determining the first CAR channel corresponding to the first message according to the first hash value, and the first CAR channel has a corresponding relationship with the first hash value.

9. The message transmission method according to any one of claims 7 to 8, wherein, after obtaining the second message and before transmitting the second message through the second CAR channel, the method further includes: randomly sorting at least two bit positions included in the user host feature information to obtain the second feature sequence; determining a second hash value based on a target hash function according to the second feature sequence; determining the second CAR channel corresponding to the second message according to the second hash value, and the second CAR channel has a corresponding relationship with the second hash value.

10. The message transmission method according to any one of claims 7 to 8, wherein, the user host feature information includes at least one of a VLAN tag and a MAC address.

11. The message transmission method according to any one of claims 7 to 8, wherein, the first message is a message sent to the CPU; the message sent to the CPU is an online interaction message, an online detection message, or a protocol message.

12. The message transmission method according to any one of claims 7 to 8, wherein, the second message is a message sent to the CPU; the message sent to the CPU is an online interaction message, an online detection message, or a protocol message.

13. An access gateway device, wherein, comprising: a first acquisition unit for acquiring a first message, where the first message carries user host feature information; a second acquisition unit for acquiring a second message, where the second message carries the user host feature information; a first transmission unit for transmitting the first message through a first committed access rate (CAR) channel when in a first time period, where the first CAR channel is determined according to the user host feature information and a first salt value; a second transmission unit for transmitting the second message through a second CAR channel when in a second time period, where the second CAR channel is determined according to the user host feature information and a second salt value, and the second salt value is different from the first salt value.

14. The access gateway device according to claim 13, wherein, the access gateway device further includes: The first generation unit is configured to randomly generate a first salt value; The first determination unit, based on a target hash function, is configured to determine a first hash value according to the user host feature information and the first salt value; The second determination unit is configured to determine the first CAR channel corresponding to the first message according to the first hash value, and the first CAR channel has a corresponding relationship with the first hash value.

15. The access gateway device according to any one of claims 13 to 14, wherein, the access gateway device further includes: The second generation unit is configured to randomly generate a second salt value; The third determination unit, based on a target hash function, is configured to determine a second hash value according to the user host feature information and the second salt value; The fourth determination unit is configured to determine the second CAR channel corresponding to the second message according to the second hash value, and the second CAR channel has a corresponding relationship with the second hash value.

16. An access gateway device, wherein, it includes: The first acquisition unit is configured to acquire a first message, wherein the first message carries user host feature information, and the user host feature information includes at least two bit positions; The second acquisition unit is configured to acquire a second message, wherein the second message carries the user host feature information; The first transmission unit is configured to transmit the first message through a first CAR channel when in a first time period, wherein the first CAR channel is determined according to a first feature sequence, and the first feature sequence is obtained by randomly sorting at least two bit positions included in the user host feature information; The second transmission unit is configured to transmit the second message through a second CAR channel when in a second time period, wherein the second CAR channel is determined according to a second feature sequence, and the second feature sequence is obtained by randomly sorting at least two bit positions included in the user host feature information.

17. The access gateway device according to claim 16, wherein, the access gateway device further includes: The first sorting unit is configured to randomly sort at least two bit positions included in the user host feature information to obtain the first feature sequence; The first determination unit, based on a target hash function, is configured to determine a first hash value according to the first feature sequence; The second determination unit is configured to determine the first CAR channel corresponding to the first message according to the first hash value, and the first CAR channel has a corresponding relationship with the first hash value.

18. The access gateway device according to any one of claims 16 to 17, wherein, the access gateway device further includes: The second sorting unit is configured to randomly sort at least two bit positions included in the user host feature information to obtain the second feature sequence; The third determination unit, based on a target hash function, is configured to determine a second hash value according to the second feature sequence; The fourth determination unit is configured to determine the second CAR channel corresponding to the second message according to the second hash value, and the second CAR channel has a corresponding relationship with the second hash value.

19. A computer-readable storage medium comprising instructions that, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 12.

20. A computer program product comprising instructions that, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Flood attack prevention method and device

    CN102014109A

  • Committed access rate management method, service board and main control board

    CN108737150A