Method, device and computer equipment for instant messaging
Patent Information
- Application Number
- CN202011073785.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-09
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2040-10-09
AI Technical Summary
但是,由于即时消息的客户端和服务端分别部署在企业所在私有网络(也可以称为局域网)和数据中心所在公共网络中,即时消息的传输过程需要跨越私有网和公共网络,存在即时消息内容被暴力破解,影响用户数据安全的问题
[0013] Secondly, this application provides an instant messaging transmission apparatus, the transmission apparatus comprising various modules for performing the instant messaging transmission method in the first aspect or any possible implementation of the first aspect.
Smart Images

Figure CN114422459B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus and computer device for instant messaging. Background Technology
[0002] With the development of cloud services, enterprise operations are gradually migrating to data centers. Data centers provide business services to enterprises in the form of services; for example, data centers can provide instant messaging services, that is, deploying the instant messaging server in the data center to reduce the enterprise's maintenance workload. This migration process can also be called the cloud deployment of instant messaging. Instant messaging (IM) is a service that enables real-time communication between users / organizations over a network, allowing two or more users (or organizations) to transmit messages in the form of text, files, images, voice, or video using tools or applications that support instant messaging services. However, because the instant messaging client and server are deployed in the enterprise's private network (also known as a local area network) and the data center's public network, respectively, the transmission of instant messages needs to cross these two networks, posing a risk of brute-force attacks on instant message content and impacting user data security. Therefore, providing a secure instant messaging transmission method has become an urgent technical problem to be solved. Summary of the Invention
[0003] This application provides a method, apparatus, and computer device for instant messaging, thereby providing a more secure method for instant messaging and improving the security of user data.
[0004] Firstly, a method for transmitting instant messages is provided. This method includes: an edge node first acquiring an instant message sent by a first client; then dividing the instant message into message data and signaling data, wherein the message data is used to indicate the content transmitted by the first client to a second client, and the signaling data is used to verify the security of the user to whom the first client belongs; and then transmitting the instant message to the second client according to preset rules. By setting up edge nodes within an organization, message data of instant messages involving sensitive data can be stored at the edge nodes, eliminating the need to transmit message data to a data center, thus improving the security of instant message transmission and storage.
[0005] In one possible implementation, the edge node has a pre-defined list of attribute tags. These attribute tags identify the sensitivity of at least one of the following: the user to whom the first client belongs, and the organization to which the first client belongs. By using these attribute tags, the sensitivity of users and / or organizations can be pre-defined. During instant messaging transmission, the edge node can determine the sensitivity of the instant message based on this pre-defined attribute list, and then select to store message data from sensitive users and / or sensitive organizations on the edge node. This ensures that the message data is not transmitted over local area networks or public networks, guaranteeing the security of user data.
[0006] In another possible implementation, when the preset attribute tags contain the user identifier of the first client's owner, the edge node stores the instant message data on the edge node; when the preset attribute tags do not contain the user identifier of the first client's owner, the edge node uploads the instant message data to the data center. Here, the user identifier is used to globally and uniquely identify a user. Through the above method, the edge node can identify sensitive users and ordinary users, storing instant messages sent by sensitive users on the edge node, thus improving the security of instant message transmission and storage for sensitive users.
[0007] In another possible implementation, when the preset attribute tags contain an identifier of the organization to which the first client belongs, the edge node stores the instant message data at the edge node; when the preset attribute tags do not contain an identifier of the organization to which the first client belongs, the edge node uploads the instant message data to the data center for storage. Through the above description, the edge node can identify sensitive and non-sensitive organizations, storing instant messages from sensitive organizations at the edge node, thus ensuring the security of instant message transmission and storage for sensitive organizations.
[0008] In another possible implementation, the edge node can also retrieve whether the message data includes sensitive fields and / or a preset format, wherein the preset format includes at least one of text, video, and voice; and perform instant message transmission based on the retrieval results.
[0009] In another possible implementation, when the retrieved message data contains sensitive fields and / or formats, the edge node identifies the instant message as a sensitive instant message and stores the message data of that instant message on the edge node; when the message data does not contain sensitive fields and / or formats, the edge node identifies the instant message as a normal instant message and uploads the message data of that instant message to the data center for storage. Through the above description, the sensitivity of instant messages can be identified based on the content contained in the message data, and sensitive instant messages can be stored on the edge node, thus improving the security of message data containing sensitive fields and / or formats.
[0010] In another possible implementation, edge nodes store message data in their own memory and periodically clean up the data stored there. Since the edge nodes are located within the organization, a local area network (LAN) is used within the same organization to establish communication connections between clients and edge nodes. Storing message data in the edge nodes effectively improves the security of real-time message storage. Furthermore, periodically updating the message data stored in the edge nodes facilitates efficient use of storage space.
[0011] In another possible implementation, before the edge node obtains the message data sent by the first client, it can obtain the message index of the first client. This message index indicates the order of the instant messages sent by the first client. The edge node sends the message index to the data center, instructing the data center to send the message index to the second client; then it receives the message index from the second client and sends the message data to the second client. By using the message index to identify the order of instant messages, the second client can accurately obtain the corresponding message data based on the message index, improving the efficiency of the instant message transmission process.
[0012] In another possible implementation, before the edge node transmits the instant message to the second client according to preset rules, the edge node can also send instruction data to the data center; then receive the data center's verification result of the first client's identity based on the instruction data; when the first client's identity verification result is successful, the edge node sends the instant message to the second client according to preset rules. Through the above description, the instant message transmission method provided by this application can verify the security of the first client, reduce the risk of unauthorized user operations, and improve the security of instant message transmission.
[0013] Secondly, this application provides an instant messaging transmission apparatus, the transmission apparatus comprising various modules for performing the instant messaging transmission method in the first aspect or any possible implementation of the first aspect.
[0014] Thirdly, this application provides an instant messaging transmission system, which includes edge nodes and a data center. The edge nodes and data center are respectively used to implement the operational steps of the methods performed by the corresponding entities in the first aspect and any possible implementation of the first aspect described above. By setting up edge nodes within the organization through the aforementioned instant messaging transmission system and storing the message data of instant messages sent by the first client in the edge nodes, the security of instant message transmission and storage between the first client and the second client is improved.
[0015] Fourthly, this application provides a computer device, the computer device including a processor and a memory, the memory being used to store computer execution instructions, wherein when the computer device is running, the processor executes the computer execution instructions in the memory to perform the operation steps of the method in the first aspect or any possible implementation of the first aspect using the hardware resources in the computer device.
[0016] Fifthly, this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the operational steps of the method described in the first aspect or any possible implementation thereof.
[0017] In a sixth aspect, this application provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the operational steps of the method described in the first aspect or any possible implementation of the first aspect.
[0018] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the structure of an instant messaging communication system 100 provided in an embodiment of this application;
[0020] Figure 2 This is a flowchart illustrating an instant messaging communication method 200 provided in an embodiment of this application;
[0021] Figure 3 This is a schematic diagram of the structure of an instant messaging communication device 300 provided in an embodiment of this application;
[0022] Figure 4 This is a schematic diagram of the structure of a computer device 400 provided in an embodiment of this application. Detailed Implementation
[0023] The method, apparatus, and device for real-time message transmission provided in this application will now be described in detail with reference to the accompanying drawings.
[0024] The instant messaging involved in this application can be divided into message data and signaling data. Message data indicates the specific content a user intends to send to other users or organizations; while signaling data indicates parts other than message data, such as username, user account, user password, or the recipient's identifier (ID) specified in the message. The transmission protocol for instant messaging includes Extensible Messaging and Presence Protocol (XMPP), Extensible Messaging and Presence Protocol (EMPP), or Session Initiation Protocol for Instant Messaging and Presence Leveraging Extensions (SIMPLE), or it can be a custom protocol based on Transmission Control Protocol (TCP) or User Datagram Protocol (UDP).
[0025] Figure 1 A schematic diagram of the structure of an instant messaging communication system 100 provided in this application embodiment is shown in the figure. The system 100 includes a data center 101, a network 102, and edge nodes (e.g., Figure 1 Edge nodes 1031 and 1032 and clients 104-108, data center 101, edge nodes 103, and clients 104-108 communicate via network 102. Data center 101 refers to the system implementing the instant messaging service, which includes multiple devices, such as... Figure 1 Devices 1011-1013 are included. Specifically, data center 101 may include devices for implementing computing functions (e.g., servers), storage functions (e.g., storage arrays), and network functions (e.g., switches). Network 102 includes wired or wireless transmission methods, wherein wired transmission methods include data transmission using Ethernet, fiber optics, etc., and wireless transmission methods include mobile hotspot (Wi-Fi), Bluetooth, infrared, etc. In specific implementations, one or more switches and / or routers can be used to establish communication connections between data center 101 and the organization.
[0026] It should be understood that the number of devices in data center 101 does not constitute a limitation on this application. Figure 1This explanation uses a data center consisting of three devices as an example. Furthermore, this application does not limit the types of devices or virtualization management methods used in a data center.
[0027] Edge nodes are used to identify sensitivity markers, distinguish message data from instruction data in instant messages, and store and forward client instant messages. In specific implementations, edge node 1031 can be a software module deployed in a server, a single server, a server cluster consisting of several servers, or a cloud computing service center; this application embodiment does not limit this. A server, also called a server server server, is a device that provides computing services. In this application embodiment, the server can be an x86 server, also known as a complex instruction set computer (CISC) architecture server, which is commonly referred to as a personal computer (PC) server. It is based on the PC architecture and uses Intel... Or other x86-compatible processor chips and The operating system server.
[0028] Edge nodes can also be used to receive messages sent by clients within or outside the organization. For example, edge node 1031 can receive messages sent by clients 1041 and 1042 within organization 1, and can also receive messages sent by client 1043 outside organization 1.
[0029] Figure 1 The instant messaging system shown also includes one or more organizations. Within the same organization, a local area network (LAN) is used to establish communication connections between clients and edge nodes. A LAN (also known as a private network) is a computer network that interconnects multiple devices within a limited geographical area to enable data transmission and resource sharing. Each organization can be a company, a department within the same company, or a group. Each organization can set up an edge node for secure transmission and storage of instant messages.
[0030] Alternatively, in addition to Figure 1 As shown, in addition to each organization setting up one edge node, multiple organizations can also form an organization group to achieve secure processing of instant messages through the same edge node or a cluster of multiple edge nodes.
[0031] Each organization comprises one or more users, and each user interacts with other users through a client. A user can associate with one or more clients for sending and receiving instant messages. Simultaneously, a client can be used by one or more users, but only one user can use it at a time. For example, user 1052 of organization 1 uses client 1042 deployed within organization 1 to communicate with other users, or user 1052 of organization 1 can also use client 1043 deployed outside the organization to communicate with other users, for example, user 1052 using client 1043 to communicate with other users while at home or traveling. When a user communicates with other users through a client, that user can also be referred to as the owner of that client. A client is an agent program deployed on a device to enable the sending and receiving of instant messages between different users. The device where the client is deployed can be a server, a smart device (e.g., a smart terminal, tablet, etc.), or a personal computer (PC). Furthermore, the devices where the client is deployed can be the same type of communication device or different communication devices; this application does not limit this.
[0032] Optionally, besides users belonging to an organization, there are also users who do not belong to any organization; these users can also be called independent users. Independent users can choose to connect to an edge node within any organization, enabling their clients to securely process instant messages using that edge node. The methods for selecting an edge node for an independent user's client include selecting based on physical proximity, random selection, and designated selection. For example, Figure 1 User 1053 is an independent user, and client 1043 is the client to which user 1053 belongs. Client 1043 can choose the edge node 1031 of the organization 1 to which the user with whom message transmission is located to realize the transmission of instant messages.
[0033] Since instant messaging services are deployed in data centers, message data involving instant messages needs to be transmitted across local area networks and public networks. In addition, instant message data is also stored in data centers. Depending on the different data security needs of different organizations, organizations, users, and instant messages can be classified into different categories based on sensitivity using at least one of the following methods.
[0034] Method 1: Divide organizations into sensitive organizations and ordinary organizations based on their sensitivity.
[0035] Sensitive organizations need to protect the message data of instant messages sent by users within the organization and should not store instant message data in the data center. For example, organizations involving core and critical technologies can be classified as sensitive organizations. Organizations other than those in the sensitive category can be called ordinary organizations. Ordinary organizations do not need to protect the message data of instant messages sent by users within the organization.
[0036] Method 2: Divide users into sensitive users and ordinary users based on their sensitivity level.
[0037] Sensitive users are those categorized into different security levels based on their attributes. Users at higher security levels may be involved in sending and receiving sensitive data. For example, users who possess core business information could be classified as sensitive users. User attributes include information identifying the user's characteristics, such as their position within the organization and the nature of their work (e.g., whether it involves core technologies). Users other than those in the sensitive user category can be referred to as ordinary users.
[0038] Method 3: Divide instant messages into sensitive instant messages and ordinary instant messages based on the message data.
[0039] In other words, if message data contains sensitive content, such as fields like "password," "account," or "customer identity information," or if the message data includes instructions for a preset format (e.g., an image), then the instant message carrying such message data is classified as a sensitive instant message. All other message data can be called ordinary message data. In practice, sensitive content can be pre-configured by various organizations or maintenance personnel through the data center's management node and sent to edge nodes. The edge nodes can then identify the sensitivity of the message based on preset sensitive fields or formats, and thus complete the instant message transmission according to that sensitivity level.
[0040] The above classification of organizations and users is only an example. In the actual implementation process, the classification method and classification rules can be further refined according to business needs, and the transmission of instant messages can be carried out according to the classification results.
[0041] It is worth noting that, Figure 1 The instant messaging system architecture shown is merely an example to better illustrate the system architecture provided by the instant messaging method of this application, and does not constitute a limitation on the embodiments of this application.
[0042] This application provides an instant messaging communication method. After migrating the instant messaging service to a data center for unified deployment, an edge node is introduced. The edge node distinguishes the instant messages sent by users into message data and instruction data, and performs instant message transmission processing according to preset rules based on the sensitivity of the sending enterprise organization, the sensitivity of the sending user, or the sensitivity of the instant message, thereby improving the security of the instant message transmission process.
[0043] Next, based on Figure 1 The system shown is further combined with Figure 2 This application provides a detailed description of the instant messaging communication method. Figure 2 This application provides a flowchart illustrating an instant messaging communication method. Taking the example of a first client sending an instant message to a second client, thus enabling the first client's owner to send an instant message to the second client's owner, the technical solution to be protected by this application is further described. The method includes two stages: initialization and message transmission, as shown in the figure. The specific method includes:
[0044] S201, The first client sends user information to the data center.
[0045] S202, The data center sends the user identifier and token to the first client.
[0046] Before users can transmit instant messages using the client, they need to complete the user initialization process in the data center, including user login and edge node configuration. The user login process is described in steps S201 to S202, and the edge node configuration is described in steps S203 to S204.
[0047] Each user can send user information to data center 101 through their client to complete the login process for the instant messaging service. Data center 101 can assign a unique user identifier to each user and store the user information. The user identifier is a number generated by data center 101 for each user based on the login order or user information, and is usually composed of numbers and / or letters, such as 00001 or SZ000001. Data center 101 can also generate a token for each user and return the token to the corresponding client for use in subsequent instant messaging transmissions to verify the user's identity. Optionally, data center 101 can also periodically generate a token for each user to enhance the security of user identity verification. The token can also be called an authentication identifier. Optionally, in addition to using tokens, the data center can also use other methods to verify user identity.
[0048] User information includes, but is not limited to, one or more of the following: username, nickname, account, password, job title, and organization name. In this embodiment, the client can provide a login interface for the user, who can enter user information through the input boxes on the login interface to log in to the data center.
[0049] Optionally, in addition to the user sending user information to the data center through the client to log in, the user login process can also involve the first client sending the user's contact information (e.g., mobile phone number or email address) to the data center, the data center sending a verification code to the first client, and then the user entering the verification code through the client to verify with the data center. This can reduce the risk of others impersonating the target user and improve communication security.
[0050] S203, The first client sends an edge node configuration command to the data center.
[0051] S204. The data center returns the edge node address to the first client.
[0052] After a user logs into the instant messaging service via a client, the data center also needs to configure an edge node for the client to transmit and store the instant messages sent by that client. Depending on the user type, the configuration method can be any of the following:
[0053] Method 1: When the user to which the first client belongs has an affiliated organization, the data center directly retrieves the edge nodes deployed within that organization based on the name of the user's organization and returns the Internet Protocol (IP) address of that edge node to the first client.
[0054] Method 2: When the first client belongs to an independent user, the data center can select the nearest edge node to transmit the user's instant messages. Specifically, the client sends a configuration command to the data center, which obtains the client's geographical location. Based on this geographical location, the data center selects the edge node closest to the first client to transmit the user's instant messages and sends the IP address of the selected edge node to the first client.
[0055] Optionally, users can also configure edge nodes in a random manner. The specific steps include: the user sends a random selection command to the data center through the client, randomly selects an edge node from the data as the user's edge node, and sends the IP address of the selected edge node to the first client.
[0056] Alternatively, the client may not configure edge nodes. In this case, the first client directly sends instant messages to the data center, and the data center completes the transmission process of the instant messages.
[0057] The above steps complete the initialization phase of the instant messaging service. Next, users can use the client to transmit and store instant messages through matched edge nodes. This process, also known as the message transmission phase, includes:
[0058] S205, The edge node obtains the instant message sent by the first client.
[0059] The client can be Figure 1 Any client, for example, any one of clients 1041-1045.
[0060] Optionally, the instant message may also include a user identifier and / or organization name. Edge nodes can determine the sensitivity of the instant message based on whether the user identifier and / or organization name are present in the attribute label, as detailed in step S206.
[0061] Optionally, the instant message may also include a message index, which indicates the order in which the first client sent the message. Specifically, when a client sends an instant message, the data center generates a message index associated with that instant message to indicate the order in which the client sends instant messages. During message reception, the client receiving the instant message can retrieve the corresponding message data from the edge node using the message index.
[0062] In addition, a user can send an instant message from one client to another, allowing the users belonging to both clients to communicate via instant messaging. Furthermore, the user belonging to the first client can simultaneously send multiple instant messages to the users belonging to multiple clients, enabling communication between the users belonging to the first client and the users belonging to the other clients via instant messaging.
[0063] S206. Edge nodes identify the sensitivity of instant messages and execute the transmission of instant messages based on the sensitivity.
[0064] Edge nodes can pre-define a list of attribute tags, which are used to identify the sensitivity of at least one of the following: the user to whom the client belongs, and the organization to which the user belongs. Edge nodes can determine the sensitivity of instant messages based on the attribute tags and the user identifier and / or organization name carried in the instant message.
[0065] In practice, the list of preset attribute tags can be set by maintenance personnel during the enterprise planning phase according to needs, or it can be based on the sensitivity specified by the user in advance. In addition, the list of preset attribute tags can be dynamically adjusted according to business needs. For example, user identifiers or organization names can be added or deleted from the preset attribute tags based on the sensitivity of the enterprise or user, as well as changes in sensitive fields or preset formats.
[0066] For example, Table 1 shows a preset attribute label list provided in an embodiment of this application. As shown in the table, at least one of the user identifier and organization name can be used to indicate the sensitivity of an instant message. When the preset attribute label list contains the user identifier and / or organization name included in the instant message, the sensitivity of the instant message is valid, and the edge node stores the message data from the instant message sent by the user to the edge node. When the preset attribute label list does not contain the user identifier and / or organization name included in the instant message, the sensitivity of the instant message is invalid, and the edge node uploads the message data from the instant message sent by the user to the data center. For example, the edge node stores two threshold attribute lists, preset attribute list 1 and preset attribute list 2. Preset attribute list 1 is used to record user identifiers with sensitivity, and preset attribute list 2 is used to record organization names with sensitivity. That is, when the instant message includes the user identifier 00001 or the organization name Enterprise 1 or Enterprise 2, the sensitivity of the instant message is valid. At this time, the edge node will further divide the instant message into message data and instruction data, and store the message data to the edge node.
[0067] Table 1. List of Preset Attribute Labels
[0068] 00001 00002 00005 00010 00021
[0069] Table 2, List of Preset Attribute Labels
[0070] Company 1 Company 2
[0071] Optionally, in addition to the attribute label lists shown in Tables 1 and 2, the edge nodes can also preset a list of sensitive fields or preset formats to identify the sensitivity of instant messages sent by the user to whom the first client belongs. The sensitive fields include sensitive fields involving sensitive personal information of the user, such as "password", "account", and "telephone". The preset formats include at least one of the following formats: image, audio, and video.
[0072] Edge nodes can also retrieve instant messages and transmit them based on the retrieval results. Specifically, if an instant message contains any of the sensitive fields or sensitive formats, its sensitivity is valid. The edge node further divides the instant message into message data and instruction data, stores the message data at the edge node, uses the instruction data to authenticate with the data center, and completes the message data transmission process. If an instant message does not contain any of the sensitive fields or sensitive formats, its sensitivity is invalid, and the edge node sends the instant message to the data center for transmission.
[0073] As one possible implementation, if an instant message includes both a user identifier and an organization name, the instant message is considered to have valid sensitivity as long as one of them exists in the preset attribute tag list.
[0074] The following explains in detail how edge nodes execute the transmission of real-time messages based on sensitivity:
[0075] S2061. Edge nodes transmit real-time messages to the second client according to preset rules.
[0076] The second client is the receiver of instant messages. Edge nodes can transmit instant messages to the second client according to preset rules. These preset rules refer to the edge nodes transmitting instant messages based on the sensitivity of preset attribute tags, specifically including the following two scenarios:
[0077] Scenario 1: When the sensitivity of instant messaging is valid, the edge node stores the message data in the instant messaging to the edge node.
[0078] Scenario 2: When the sensitivity of instant messaging is invalid, the edge node will send the instant message to the data center.
[0079] In scenario two, instant messages can be sent directly to the data center, where the data center will handle the transmission.
[0080] Optionally, for scenario two, in order to further enhance the security of the instant messaging transmission process, the edge node can divide the instant messaging into message data and instruction data. Then, the message data is stored in the edge node, and the instruction data is used to authenticate the first client. Finally, the instant messaging is transmitted according to the sensitive and effective processing procedure.
[0081] In scenario one, when the edge node transmits an instant message to the second client, it also needs to use the instruction data in the instant message to complete the authentication of the first client. The specific process includes: the edge node sending the token carried by the first client to the data center; the data center verifying the validity of the token and sending the verification result back to the edge node; once the first client's authentication is successful, the edge node can continue transmitting instant messages to the second client. The detailed process is as follows:
[0082] S20611, The data center notifies the second client to receive instant messages.
[0083] Alternatively, the data center can also send the message index generated by the data center for instant messaging to a second client.
[0084] Optionally, the data center can also send the IP address of the edge node to a second client.
[0085] S20612. The second client sends a message index to the edge node to request the corresponding message data, while also carrying the authentication identifier of the user to whom the second client belongs.
[0086] S20613. The edge node verifies the security of the second client based on the authentication identifier of the user to whom the second client belongs.
[0087] The process of edge nodes verifying the security of the second client is similar to that of verifying the security of the first client. It also involves authentication by sending the authentication identifier (e.g., a token) of the user to whom the second client belongs to the data center. For the sake of brevity, it will not be described in detail here.
[0088] S20614. After the second client successfully authenticates, the edge node sends message data to the second client.
[0089] As described above, this application adds edge nodes to the local area network (LAN). These edge nodes identify the sensitivity of instant messages and transmit them accordingly. This ensures that the message data of sensitive instant messages is stored only at the edge nodes, avoiding the security risks associated with storing sensitive data in the data center and improving the security of the data processing process. Furthermore, the edge nodes can divide instant messages into message data and instruction data. Sensitive data can be directly stored at the edge nodes instead of transmitting message data to the data center. This reduces the risk of sensitive data being intercepted and brute-forced during network transmission and also ensures the security of the instant messaging service transmission process.
[0090] As one possible implementation, besides transmitting instant messages according to steps S20611 to S20614 described above, the edge node can also determine the IP address of the second client based on the identifier of the second client carried in the instant message, and then transmit the instant message through the second client's IP address. Specifically, the edge node can send a query request to the data center to find the second client, which carries the identifier of the second client. The data center can then return the IP address of the second client to the edge node based on the identifier, thereby enabling the edge node to transmit instant messages to the second client based on the second client's IP address.
[0091] As one possible implementation, this application also provides a graphical user interface (GUI). The GUI program can be deployed on edge nodes and / or data centers, providing maintenance personnel with a visual interface for adding or updating organizations, users, or sensitive content in preset formats. Maintenance personnel can view and modify preset attribute tags through the GUI. Optionally, the visual interface can also present the sensitivity identification results of instant messages with index identifiers, including whether the sensitivity of the instant message associated with each index identifier is valid and the storage location of the instant message.
[0092] Next, combined Figure 1 The system shown is further explained in three scenarios to illustrate the technical solution to be protected in this application.
[0093] Scenario 1: Instant messaging between two users belonging to the same organization.
[0094] In this scenario, the edge node belongs to the same organization as the first and second clients, and the communication process between the two users is the same. Figure 2 The process is similar. The transmission of instant messages is determined by the edge nodes in the organization, which identify the sensitivity of the instant message and execute the transmission of the instant message according to the sensitivity. For the sake of simplicity, it will not be described in detail here.
[0095] Scenario 2: Instant messaging between two users belonging to different organizations.
[0096] In this scenario, each organization may set up one edge node. For example, the first client and the first edge node belong to the same organization, while the second client and the second edge node belong to a different organization. Alternatively, the edge node can be set up only within one of the organizations, enabling real-time message transmission between the first and second clients.
[0097] When the first edge node and the second edge node are distributed across different organizations, the process of the first edge node transmitting real-time messages to the second client specifically includes:
[0098] Step 1: The first edge node sends an index message to the data center.
[0099] Step 2: The data center sends an index message to the second edge node.
[0100] Step 3: The second edge node sends an index message to the second client.
[0101] Step 4: The second client sends a request to the second edge node to obtain message data. This request includes an index message and the authentication identifier of the second client.
[0102] Step 5: The second edge node verifies the security of the second client with the data center based on the authentication identifier of the second client.
[0103] Step 6: After the second client is successfully authenticated, the second edge node sends a message index to the first edge node.
[0104] Step 7: The first edge node sends the message data of the instant message to the second edge node according to the message index.
[0105] Through the above operation process, the first client and the second client can respectively complete authentication and instant message transmission through their matched edge nodes. Message data involving sensitive information is not transmitted to the data center, nor is it stored in the data center, thus ensuring the security of the instant message data transmission and storage process.
[0106] Scenario 3: Instant messaging between users belonging to an organization and independent users.
[0107] In this scenario, there are two edge nodes: one deployed within the organization of the user to whom the first client belongs, and the other configured by the data center for an independent user. When the two edge nodes happen to be the same node, the communication process between the two users is exactly the same as in Scenario 1; when the two edge nodes are not the same node, the communication process between the two users is exactly the same as in Scenario 2, and will not be elaborated further here.
[0108] In summary, the instant messaging communication method provided in this application can deploy edge nodes within an organization. These edge nodes identify the sensitivity of instant messages based on at least one of three dimensions: user, organization, and message data within the instant message. Sensitive user, organization, and instant message data are stored internally within the edge nodes, while other message data is uploaded to the data center. This ensures that the data center does not receive or process sensitive content during message interaction between the client and the data center, effectively preventing leakage during message data transmission to the data center and mitigating the instability caused by storing message data in the data center, thus improving the security of the entire communication process.
[0109] It is worth noting that, for the sake of simplicity, the above method embodiments are described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions.
[0110] Other reasonable combinations of steps that can be conceived by those skilled in the art based on the above description also fall within the scope of protection of this application. Furthermore, those skilled in the art should also be aware that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to this application.
[0111] The above text combines Figure 1 and Figure 2 The present application describes in detail the instant messaging method provided according to the embodiments of this application. The following will be combined with... Figure 3 and Figure 4 The present application further describes the apparatus and computer device for real-time messaging provided according to embodiments thereof.
[0112] Figure 3 A schematic diagram of an instant messaging transmission device 300 provided in this application includes an acquisition unit 310, a processing unit 320, and a transmission unit 330.
[0113] Acquisition unit 310 is used to acquire instant messages sent by the first client.
[0114] The processing unit 320 is used to divide the instant message acquired by the acquisition unit 310 into message data and signaling data, wherein the message data is used to indicate the content transmitted by the first client to the second client, and the signaling data is used to verify the security of the user to whom the first client belongs.
[0115] The transmission unit 330 is used to transmit the instant message to the second client according to preset rules.
[0116] It should be understood that the transmission device 300 in this application embodiment can be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can also be implemented using software. Figure 2 In the instant messaging method shown, the transmission device 300 and its various modules can also be software modules.
[0117] Optionally, the processing unit 320 is further configured to preset an attribute tag list, wherein the attribute tags are used to identify the sensitivity of at least one of the user to whom the first client belongs and the organization to which the user to whom the first client belongs.
[0118] Optionally, when the attribute tag is used to identify the sensitivity of the user to which the first client belongs, the transmission unit 330 is further configured to store the message data of the instant message in the edge node when the user identifier of the user to which the first client belongs exists in the preset attribute tag; and to upload the message data of the instant message to the data center when the user identifier of the user to which the first client belongs does not exist in the preset attribute tag; wherein the user identifier is used to globally and uniquely identify a user.
[0119] Optionally, when the attribute tag is used to identify the sensitivity of the organization to which the first client belongs, the transmission unit 330 is further configured to store the message data of the instant message in the edge node when the preset attribute tag contains the identifier of the organization to which the first client belongs; and to upload the message data of the instant message to the data center for storage when the preset attribute tag does not contain the identifier of the organization to which the first client belongs.
[0120] Optionally, the processing unit 320 is further configured to retrieve whether the message data includes sensitive fields and / or a preset format, wherein the preset format includes at least one of text, video, and voice; and to execute the transmission of the instant message based on the retrieval result.
[0121] Optionally, the processing unit 320 is further configured to identify the instant message as a sensitive instant message when the message data contains sensitive fields and / or formats; the transmission unit 330 is further configured to store the message data of the instant message in the edge node; and,
[0122] The processing unit 320 is further configured to identify the instant message as a normal instant message when the message data does not contain sensitive fields and / or formats, and the transmission unit 330 is further configured to upload the message data of the instant message to the data center for storage.
[0123] Optionally, the transmission device 300 further includes a storage unit 340 for storing the message data in the memory of the edge node and periodically clearing the data stored in the memory.
[0124] Optionally, the acquisition unit 310 is further configured to acquire the message index of the first client before acquiring the message data sent by the first client, wherein the message index is used to indicate the order of messages sent by the first client;
[0125] The transmission unit 330 is further configured to send the message index to the data center to instruct the data center to send the message index to the second client; and to receive the message index sent by the second client and send the message data to the second client.
[0126] Optionally, the processing unit 320 is further configured to send the instruction data to the data center before transmitting the instant message to the second client according to a preset rule; receive the authentication result of the first client from the data center; and, when the authentication result of the first client is successful, the transmission unit sends the instant message to the second client according to the preset rule.
[0127] The transmission device 300 according to the embodiments of this application can correspond to the execution of the method described in the embodiments of this application, and the above and other operations and / or functions of each unit in the transmission device 300 are respectively for implementing Figure 2 For the sake of brevity, the corresponding processes of each method in the code will not be elaborated here.
[0128] In summary, the transmission device 300 provided in this application embodiment can identify instant messages sent by sensitive users and users belonging to sensitive organizations, as well as instant messages containing sensitive content in the message data, from multiple dimensions and store them in the storage unit. This reduces the risk of leakage of sensitive information within the organization, enhances the security of the entire communication process and message data, and is applicable to service scenarios of internal communication within organizations with sensitive information or communication with other external organizations.
[0129] Figure 4 This is a schematic diagram of a computer device 400 provided in an embodiment of this application. As shown in the figure, the computer device 400 includes a processor 401, a memory 402, a communication interface 403, a bus 404, and a memory 405. The processor 401, memory 402, communication interface 403, and memory 405 communicate via the bus 404, or via other means such as wireless transmission. The memory 405 stores computer execution instructions, and the processor 401 executes the computer execution instructions stored in the memory 405 to implement the following operation steps:
[0130] Get the instant message sent by the first client;
[0131] The instant message is divided into message data and signaling data. The message data is used to indicate the content transmitted by the first client to the second client, and the signaling data is used to verify the security of the user to whom the first client belongs.
[0132] The instant message is transmitted to the second client according to preset rules.
[0133] It should be understood that in the embodiments of this application, the processor 401 may be a CPU, but it may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0134] The memory 402 may include read-only memory and random access memory, and provides instructions and data to the processor 401. The memory 402 may also include non-volatile random access memory. For example, the memory 402 may also store device type information.
[0135] The memory 402 can be volatile memory or non-volatile memory, or it can include both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0136] In addition to the data bus, bus 404 may also include a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled as bus 404 in the diagram.
[0137] It should be understood that the computing device 400 according to the embodiments of this application may correspond to the transmission device 300 in the embodiments of this application, and may correspond to the execution of the embodiment of this application. Figure 2 The corresponding entities in method 200 and the various modules in computing device 400, as well as the above and other operations and / or functions, are respectively for implementing the corresponding processes of the various methods in the figure. For the sake of brevity, they will not be described in detail here.
[0138] In summary, the computer device provided in this application divides instant messages into message data and message signaling according to their sensitivity, and stores the message data with high sensitivity to edge nodes. This protects the transmission and storage of such messages, ensuring that they are always within the organization's local area network. This reduces the risk of leakage during the transmission of sensitive instant message data to the data center and improves the security of instant message transmission.
[0139] This application also provides an instant messaging transmission system, including edge nodes and a data center. The edge nodes and data center are respectively used to implement the operational steps of the methods performed by corresponding entities in the aforementioned transmission device or computer equipment. By setting up edge nodes within the organization through the aforementioned instant messaging transmission system, and storing the message data of instant messages sent by the first client in the edge nodes, the security of instant message transmission and storage between the first client and the second client is improved.
[0140] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive (SSD).
[0141] The above description is merely a specific embodiment of this application. Any variations or substitutions conceived by those skilled in the art based on the specific embodiments provided in this application should be covered within the protection scope of this application.
Claims
1. A method of transmitting an instant message, characterized by, The method includes: Edge nodes acquire real-time messages sent by the first client; The edge node divides the instant message into message data and instruction data. The message data is used to indicate the content transmitted by the first client to the second client, and the instruction data is used to verify the security of the user to whom the first client belongs. The edge node sends the instruction data to the data center; The edge node receives the authentication result of the first client from the data center; When the authentication result of the first client is successful, the edge node transmits the instant message to the second client according to preset rules; The edge node transmits the instant message to the second client according to preset rules, including: When the preset attribute tag contains the user identifier of the user to which the first client belongs or the identifier of the organization to which the first client belongs, the edge node stores the message data of the instant message in the edge node; When the preset attribute tags do not contain the user identifier of the user to whom the first client belongs or the identifier of the organization to which the user to whom the first client belongs, the edge node will upload the message data of the instant message to the data center for storage. The user identifier is used to uniquely identify a user globally.
2. The method of claim 1, wherein, The edge node has a preset list of attribute labels, which are used to identify the sensitivity of at least one of the user to whom the first client belongs and the organization to which the user to whom the first client belongs.
3. The method of claim 1, wherein, The step of transmitting the instant message according to preset rules includes: The system retrieves whether the message data includes sensitive fields and / or a preset format, wherein the preset format includes at least one of text, video, and voice. The instant message is transmitted based on the search results.
4. The method of claim 3, wherein, The step of transmitting the instant message based on the search results includes: When the message data contains sensitive fields and / or formats, the edge node identifies the instant message as a sensitive instant message and stores the message data of the instant message in the edge node; When the message data does not contain sensitive fields and / or format, the edge node identifies the instant message as a normal instant message and uploads the message data of the instant message to the data center for storage.
5. The method according to claim 1, characterized in that, The edge node stores the message data in its memory and periodically cleans up the data stored in the memory.
6. The method according to claim 1, characterized in that, Before the edge node acquires the message data sent by the first client, the method further includes: The edge node obtains the message index of the first client, and the message index is used to indicate the order of instant messages sent by the first client; The edge node then transmits the instant message to the second client according to preset rules, including: The edge node sends the message index to the data center to instruct the data center to send the message index to the second client; The edge node receives the message index sent by the second client and sends the message data to the second client.
7. A device for transmitting instant messages, characterized in that, The device includes an acquisition unit, a processing unit, and a transmission unit: The acquisition unit is used to acquire the instant message sent by the first client; The processing unit is used to divide the instant message acquired by the acquisition unit into message data and instruction data. The message data is used to indicate the content transmitted by the first client to the second client, and the instruction data is used to verify the security of the user to whom the first client belongs. The transmission unit is used to send the instruction data to the data center; receive the authentication result of the first client from the data center; and when the authentication result of the first client is successful, transmit the instant message to the second client according to preset rules. The step of transmitting the instant message to the second client according to preset rules includes: When the preset attribute tags contain the user identifier of the user to whom the first client belongs or the identifier of the organization to which the user to whom the first client belongs, the message data of the instant message will be stored in the edge node. When the user identifier of the user to whom the first client belongs or the identifier of the organization to which the user to whom the first client belongs does not exist in the preset attribute tags, the message data of the instant message will be uploaded to the data center for storage. The user identifier is used to uniquely identify a user globally.
8. The apparatus according to claim 7, characterized in that, The processing unit is further configured to preset an attribute tag list, wherein the attribute tags are used to identify the sensitivity of at least one of the user to whom the first client belongs and the organization to which the user to whom the first client belongs.
9. The apparatus according to claim 7, characterized in that, The processing unit is further configured to retrieve whether the message data includes sensitive fields and / or a preset format, wherein the preset format includes at least one of text, video, and voice; and to execute the transmission of the instant message based on the retrieval results.
10. The apparatus according to claim 9, characterized in that, The processing unit is further configured to identify the instant message as a sensitive instant message when the retrieved message data contains sensitive fields and / or formats; Furthermore, when the retrieved message data does not contain sensitive fields and / or formats, the instant message is identified as a regular instant message; The transmission unit is further configured to store the message data of the instant message in the edge node when the processing unit identifies the instant message as a sensitive instant message; and to upload the message data of the instant message to the data center for storage when the processing unit identifies the instant message as a normal instant message.
11. The apparatus according to claim 7, characterized in that, The device further includes: A storage unit is used to store the message data in the memory of the edge node and periodically clean up the data stored in the memory.
12. The apparatus according to claim 7, characterized in that, The acquisition unit is further configured to acquire the message index of the first client before acquiring the message data sent by the first client, wherein the message index is used as an identifier indicating the order of messages sent by the first client; The transmission unit is further configured to send the message index to the data center to instruct the data center to send the message index to the second client; and to receive the message index sent by the second client and send the message data to the second client.
13. A computer device, characterized in that, The device includes a processor and memory, the memory being used to store computer execution instructions, the processor executing the computer execution instructions in the memory, causing the computer device to perform the operational steps of any of the methods described in claims 1-6.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes instructions that, when executed on a computer, cause the computer to perform the operational steps of any one of the methods described in claims 1 to 6.
Citation Information
Patent Citations
Application level security cross-domain communication method and system
CN108111536A
Cross-network communication method and device and storage medium
CN110290060A
Data transmission method, data control device and related equipment
CN118157896A