Position Information Conversion Method, Gateway, Controller, Terminal, Device and Medium
By converting real-world network location identifiers to virtual identifiers using domain boundary gateways and controllers, the method addresses privacy risks in internet communication by ensuring secure communication within and outside domains, effectively reducing user location exposure.
Patent Information
- Application Number
- CN202011519896.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-21
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2040-12-21
AI Technical Summary
IP addresses on the Internet expose user location information and identity information, resulting in the risk of privacy leakage.
By establishing a mapping relationship between the real network location identification and the virtual network location identification between the domain boundary gateway and the location controller, the position identification in the data packet is converted to communicate using the real identifier within the domain and virtual identifier between the domains.
Effectively protect user location information, reduce the risk of privacy leakage, and ensure the reliability and security of communications.
Smart Images

Figure CN114726819B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication technologies, and in particular, to a method for converting location information, a gateway, a controller, a terminal, a device, and a medium. Background Art
[0002] The Internet uses Internet Protocol Address (IP address) as a unified communication identifier. Since the address exposed in the IP data packet header carries the user's location information and identity information, the IP address has become an important means for the public Internet to associate user identities with locations and further analyze user behaviors, making users face the risk of privacy exposure. Summary of the Invention
[0003] The main objective of the embodiments of the present invention is to propose a method for converting location information, a gateway, a controller, a terminal, a device, and a medium, aiming to hide the user's location information and thus avoid the leakage of user privacy.
[0004] To achieve the above objective, an embodiment of the present invention provides a method for converting network location information, which is applied to a domain border gateway and includes:
[0005] Obtaining a mapping relationship between a real network location identifier and a virtual network location identifier;
[0006] Receiving a data packet from or sent to the terminal; wherein the data packet includes a real network location identifier or a virtual network location identifier;
[0007] Converting the network location identifier of the data packet according to the mapping relationship.
[0008] To achieve the above objective, an embodiment of the present invention also proposes a method for converting network location information, which is applied to a location controller and includes:
[0009] Obtaining a real network location identifier;
[0010] Establishing a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier;
[0011] Sending the mapping relationship to the domain border gateway so that the domain border gateway executes the foregoing method.
[0012] To achieve the above objective, an embodiment of the present invention also proposes a method for converting network location information, which is applied to a service controller and includes:
[0013] Receiving a first access request from an access gateway;
[0014] Send a real network location identifier to the location controller according to the first access request, so that the location controller executes the foregoing method.
[0015] To achieve the above object, an embodiment of the present invention further provides a network location information conversion method, which is applied to an access gateway and includes:
[0016] Receive a data packet from a terminal;
[0017] Add a real network location identifier to the data packet from the terminal and then send it to the domain border gateway, so that the domain border gateway executes the foregoing method;
[0018] Or,
[0019] Receive a data packet from the domain border gateway; wherein, the data packet is obtained by the domain border gateway executing the foregoing method;
[0020] Delete the real network location identifier from the data packet from the domain border gateway and then send it to the terminal.
[0021] To achieve the above object, an embodiment of the present invention further provides a network location information conversion method, which is applied to a terminal and includes:
[0022] Send a data packet to the access gateway, so that the access gateway adds a real network location identifier to the data packet and then sends it to the domain border gateway;
[0023] Or,
[0024] Receive a data packet from the access gateway; wherein, the data packet is obtained by the access gateway deleting the real network location identifier in the data packet.
[0025] To achieve the above object, an embodiment of the present invention further provides a domain border gateway, which includes:
[0026] A first acquisition module, configured to acquire a mapping relationship between a real network location identifier and a virtual network location identifier;
[0027] A first receiving module, configured to receive a data packet from or sent to the terminal; wherein, the data packet includes a real network location identifier or a virtual network location identifier;
[0028] A conversion module, configured to perform network location identifier conversion on the data packet according to the mapping relationship.
[0029] To achieve the above object, an embodiment of the present invention further provides a location controller, which includes:
[0030] A second acquisition module, configured to acquire a real network location identifier;
[0031] A building module, configured to establish a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier;
[0032] A sending module, configured to send the mapping relationship to the aforementioned domain border gateway.
[0033] To achieve the above object, an embodiment of the present invention further provides a service controller, including:
[0034] A second receiving module, configured to receive a first access request from an access gateway;
[0035] A first sending module, configured to send a real network location identifier to the aforementioned location controller according to the first access request.
[0036] To achieve the above object, an embodiment of the present invention further provides an access gateway, including:
[0037] A third receiving module, configured to receive a data packet from a terminal;
[0038] A second sending module, configured to add a real network location identifier to the data packet from the terminal and then send it to the domain border gateway according to claim 20;
[0039] Or,
[0040] A fourth receiving module, configured to receive a data packet from the aforementioned domain border gateway.
[0041] To achieve the above object, an embodiment of the present invention further provides a terminal, including:
[0042] A third sending module, configured to send a data packet to the aforementioned access gateway;
[0043] Or,
[0044] A fifth receiving module, configured to receive a data packet from the aforementioned access gateway.
[0045] To achieve the above object, an embodiment of the present invention further provides an electronic device, where the electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, it implements:
[0046] The aforementioned network location information conversion method.
[0047] To achieve the above object, an embodiment of the present invention further provides a storage medium for computer-readable storage, where the storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the aforementioned network location information conversion method.
[0048] The location information conversion method proposed in the embodiments of the present invention obtains the mapping relationship between the real network location identifier and the virtual network location identifier through the domain border gateway, receives the data packets from the terminal, and converts the real network location identifier in the data packets into the virtual network location identifier according to the mapping relationship; or receives the data packets sent to the terminal, and converts the virtual network location identifier in the data packets into the real network location identifier according to the mapping relationship. By converting and hiding the real network location information at the domain border gateway, the embodiments of the present invention enable data communication within the domain through the real network location identifier and data communication between domains (i.e., outside the domain) through the virtual network location identifier, thereby achieving the purpose of protecting the user's location information and effectively reducing the risk of user privacy exposure.
[0049] Other features and advantages of the present application will be described in the subsequent specification, and part of them will become obvious from the specification or be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 It is a schematic diagram of the network architecture from the client to the server provided by an embodiment of the present invention.
[0051] Figure 2 It is a schematic flowchart of the network location information conversion method provided by an embodiment of the first aspect of the present invention;
[0052] Figure 3 It is a schematic diagram of the structure of a data packet provided by an embodiment of the present invention;
[0053] Figure 4 It is a schematic diagram of the structure of a data packet provided by another embodiment of the present invention;
[0054] Figure 5 It is a schematic diagram of the structure of a data packet provided by another embodiment of the present invention;
[0055] Figure 6 It is a schematic diagram of the structure of a data packet provided by another embodiment of the present invention;
[0056] Figure 7 It is a schematic flowchart of the network location information conversion method provided by another embodiment of the first aspect of the present invention;
[0057] Figure 8 It is a schematic diagram of the structure of a data packet provided by another embodiment of the present invention;
[0058] Figure 9 It is a schematic flowchart of the network location information conversion method provided by an embodiment of the second aspect of the present invention;
[0059] Figure 10 It is a schematic flow chart of a network location information conversion method provided by another embodiment of the second aspect of the present invention;
[0060] Figure 11 It is a schematic flow chart of a network location information conversion method provided by another embodiment of the second aspect of the present invention;
[0061] Figure 12 It is a schematic flow chart of a network location information conversion method provided by an embodiment of the third aspect of the present invention;
[0062] Figure 13 It is a schematic flow chart of a network location information conversion method provided by another embodiment of the third aspect of the present invention;
[0063] Figure 14 It is a schematic flow chart of a network location information conversion method provided by an embodiment of the fourth aspect of the present invention;
[0064] Figure 15 It is a schematic flow chart of a network location information conversion method provided by another embodiment of the fourth aspect of the present invention;
[0065] Figure 16 It is a schematic flow chart of a network location information conversion method provided by another embodiment of the fourth aspect of the present invention;
[0066] Figure 17 It is a schematic flow chart of a network location information conversion method provided by an embodiment of the fifth aspect of the present invention;
[0067] Figure 18 It is a schematic flow chart of a network location information conversion method provided by another embodiment of the fifth aspect of the present invention;
[0068] Figure 19 It is a schematic flow chart of a network location information conversion method provided by an embodiment of the present invention;
[0069] Figure 20 It is a schematic flow chart of a network location information conversion method provided by an embodiment of the present invention;
[0070] Figure 21 It is a schematic structural diagram of a domain border gateway provided by an embodiment of the sixth aspect of the present invention;
[0071] Figure 22 It is a schematic structural diagram of a location controller provided by an embodiment of the seventh aspect of the present invention;
[0072] Figure 23 It is a schematic structural diagram of a service controller provided by an embodiment of the eighth aspect of the present invention;
[0073] Figure 24 It is a schematic structural diagram of an access gateway provided by an embodiment of the ninth aspect of the present invention;
[0074] Figure 25 It is a schematic structural diagram of a terminal provided by an embodiment of the tenth aspect of the present invention.
[0075] Reference numerals:
[0076] Client 110, First Access Gateway 120, First Service Controller 130, First Location Controller 140, First Domain Border Gateway 150, Server 210, Second Access Gateway 220, Second Service Controller 230, Second Location Controller 240, Second Domain Border Gateway 250, First Acquisition Module 310, First Reception Module 320, Conversion Module 330, Second Acquisition Module 410, Establishment Module 420, Distribution Module 430, Second Reception Module 510, First Transmission Module 520, Third Reception Module 610, Second Transmission Module 620, Fourth Reception Module 630, Third Transmission Module 710, Fifth Reception Module 720. Detailed implementation manners
[0077] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Without conflict, the embodiments in this application and the features in the embodiments can be combined arbitrarily with each other.
[0078] In subsequent descriptions, suffixes such as "module", "component" or "unit" used to represent elements are only for the convenience of describing the present invention and have no specific meaning in themselves. Therefore, "module", "component" or "unit" can be used interchangeably.
[0079] It should be noted that although functional module division is performed in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from the module division in the device or the order in the flowchart. Terms such as "first" and "second" in the specification, claims and the above drawings are used to distinguish similar objects and do not have to be used to describe a specific order or sequence.
[0080] The Internet uses Internet Protocol Address (IP address) as a unified communication identifier, and hosts are reachable through routing. Since the address exposed in the IP packet header carries the user's location information and identity information, the IP address has become an important means for the public Internet to associate user identities with locations and further analyze user behavior, exposing users to the risk of privacy leakage. Therefore, on the basis of ensuring the authenticity of user identities, protecting users' location privacy requires hiding users' location information.
[0081] Based on the above, embodiments of the present invention propose a location information conversion method, gateway, controller, terminal, device, and medium, which can hide users' location information, thereby avoiding the leakage of users' privacy.
[0082] It should be noted that in some embodiments, embodiments of the present invention are based on the identity information and location information separation technology to hide location information. The Internet inter-domain communication system involved in embodiments of the present invention can be terminal-to-terminal. The terminal can be a client or a server. Terminal-to-terminal can be client-to-client, client-to-server, server-to-server, or multiple clients to one or more servers.
[0083] In some embodiments, the terminal can be a client or a server. Among them, the client can be a mobile terminal device or a non-mobile terminal device. The mobile terminal device can be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle terminal device, wearable device, ultra-mobile personal computer, netbook, personal digital assistant, etc.; the non-mobile terminal device can be a personal computer, television, teller machine, or self-service machine, etc. The server can be an independent physical entity server or a logical entity. The implementation scheme of the present invention is not specifically limited. The following will only take the communication between the client and the server as an example for illustration.
[0084] For example, as Figure 1 shown, it is the network architecture from the client to the server involved in the present invention. The entire network is divided into the intra-domain and the extra-domain, and data communication can be carried out between the intra-domain and the extra-domain (i.e., the Internet). The present invention achieves the purpose of protecting users' location information by adopting the technical means of using real network location identifiers for data communication within the domain and virtual network location identifiers for data communication between domains (i.e., outside the domain).
[0085] Among them, the security domain of the client 110 (i.e., the terminal where the user is located) is denoted as domain A, which includes a first access gateway 120, a first service controller 130, a first location controller 140, and a first domain boundary gateway 150. The client 110 is connected to the first access gateway 120, the first access gateway 120 is respectively connected to the first service controller 130 and the first domain boundary gateway 150, the first service controller 130 is connected to the first location controller 140, and the first location controller 140 is connected to the first domain boundary gateway 150. The security domain of the server 210 is denoted as domain B, which includes a second access gateway 220, a second service controller 230, a second location controller 240, and a second domain boundary gateway 250. The server 210 is connected to the second access gateway 220, the second access gateway 220 is respectively connected to the second service controller 230 and the second domain boundary gateway 250, the second service controller 230 is connected to the second location controller 240, and the second location controller 240 is connected to the second domain boundary gateway 250.
[0086] It should be noted that the first location controller 140 of domain A can be independently deployed or can be deployed in combination with the first service controller 130. The second location controller 240 of domain B can be independently deployed or can be deployed in combination with the second service controller 230. The first location controller 140 of domain A and the second location controller 240 of domain B can be independently deployed or can be deployed in combination. The first service controller 130 of domain A and the second service controller 230 of domain B can be independently deployed or can be deployed in combination. Hereinafter, only the case where the first service controller 130 and the second service controller 230 are deployed in combination and the first location controller 140 and the second location controller 240 are deployed in combination will be taken as an example for description.
[0087] The technical solution of the present invention will be described below with reference to specific embodiments.
[0088] In a first aspect, an embodiment of the present invention provides a network location information conversion method, which is applied to a domain boundary gateway. The domain boundary gateway is a boundary device inside and outside the security domain, and is mainly used to map the real network location identifier LID inside the domain to the virtual network location identifier LID' outside the domain. For example, the domain boundary gateway can be the first domain boundary gateway of domain A or the second domain boundary gateway of domain B.
[0089] In some embodiments, as Figure 2 shown, the network location information conversion method includes:
[0090] Step S110: Obtain the mapping relationship between the real network location identifier and the virtual network location identifier;
[0091] Step S120: Receive a data packet from or sent to a terminal; wherein, the data packet includes a real network location identifier or a virtual network location identifier;
[0092] Step S130: Convert the network location identifier of the data packet according to the mapping relationship.
[0093] In some embodiments, the domain border gateway obtains the mapping relationship between the real network location identifier LID and the virtual network location identifier LID'. It receives the data packet from the terminal, and according to the mapping relationship, converts the real network location identifier LID in the data packet into the virtual network location identifier LID' and sends it outside the domain; or, it receives the data packet destined for the terminal, and according to the mapping relationship, converts the virtual network location identifier LID' in the data packet into the real network location identifier LID and sends it to the terminal. In the embodiments of the present invention, by converting and hiding the real network location information LID at the domain border gateway, data communication is carried out within the domain through the real network location identifier LID, and data communication is carried out between domains (i.e., outside the domain) through the virtual network location identifier LID', so as to achieve the purpose of protecting the user's location information, and further effectively reduce the risk of user privacy exposure.
[0094] In some embodiments, the mapping relationship between the real network location identifier LID and the virtual network location identifier LID' can be generated by the location controller and sent to the domain border gateway, or can be pre-stored by the domain border gateway.
[0095] In some embodiments, the client communicates with the server. When the client sends a data packet to the server through the first domain border gateway, the real network location identifier LID in the data packet includes the client real network location identifier LIDc and the server real network location identifier LIDs. As Figure 3 shown, it is a schematic structural diagram of the first domain border gateway receiving the data packet from the client. LIDc is the client real network location identifier, LIDs is the server real network location identifier, and payload is the service data carried by the data packet. When the data packet arrives at the first domain border gateway from the client, the first domain border gateway can, according to the mapping relationship, choose to hide only the client real network location identifier LIDc as needed, or only hide the server real network location identifier LIDs, or hide both the client real network location identifier LIDc and the server real network location identifier LIDs.
[0096] In some embodiments, if a user accesses open websites such as baidu.com or google.com using a personal computer, only the client's real network location identifier LIDc may be hidden. If a user accesses a local area network or a network with confidentiality requirements using a public computer, only the server's real network location identifier LIDs may be hidden. If a user accesses a local area network or a network with confidentiality requirements using a personal computer, both the client's real network location identifier LIDc and the server's real network location identifier LIDs need to be hidden.
[0097] The following details the above three solutions:
[0098] (1) Only hiding the client's real network location identifier LIDc, correspondingly, step S130 includes:
[0099] Obtain the client's real network location identifier LIDc in the data packet from the terminal;
[0100] According to the mapping relationship, find the client's virtual network location identifier LIDc' corresponding to the client's real network location identifier LIDc;
[0101] Convert the client's real network location identifier LIDc in the data packet from the terminal to the client's virtual network location identifier LIDc'.
[0102] Or,
[0103] Obtain the client's virtual network location identifier LIDc' in the data packet sent to the terminal;
[0104] According to the mapping relationship, find the client's real network location identifier LIDc corresponding to the client's virtual network location identifier LIDc';
[0105] Convert the client's virtual network location identifier LIDc' in the data packet sent to the terminal to the client's real network location identifier LIDc.
[0106] In some embodiments, the first domain border gateway obtains the client's real network location identifier LIDc in the data packet Z from the client, according to the mapping relationship, finds the client's virtual network location identifier LIDc' corresponding to the client's real network location identifier LIDc, converts the client's real network location identifier LIDc in the data packet Z to the client's virtual network location identifier LIDc', the server's real network location identifier LIDs remains unchanged, and the structure of the converted data packet Z' is as Figure 4 shown, and sends the converted data packet Z' outside the domain, and reaches the second domain border gateway via outside the domain;
[0107] The second domain border gateway obtains the client virtual network location identifier LIDc' in the data packet Z'. According to the mapping relationship, it looks up the client real network location identifier LIDc corresponding to the client virtual network location identifier LIDc', restores the client virtual network location identifier LIDc' in the data packet Z' to the client real network location identifier LIDc, and sends the restored data packet Z to the server.
[0108] Correspondingly, when the server returns the data packet Y to the client, it includes:
[0109] The second domain border gateway obtains the client real network location identifier LIDc in the data packet Y returned to the client. According to the mapping relationship, it looks up the client virtual network location identifier LIDc' corresponding to the client real network location identifier LIDc, converts the client real network location identifier LIDc in the data packet Y to the client virtual network location identifier LIDc', keeps the server real network location identifier LIDs unchanged, and sends the converted data packet Y' outside the domain, and reaches the first domain border gateway via outside the domain;
[0110] The first domain border gateway obtains the client virtual network location identifier LIDc' in the data packet Y'. According to the mapping relationship, it looks up the client real network location identifier LIDc corresponding to the client virtual network location identifier LIDc', restores the client virtual network location identifier LIDc' in the data packet Y' to the client real network location identifier LIDc, and sends the restored data packet Y to the client.
[0111] (2) Only hide the server real network location identifier LIDs. Correspondingly, step S300 includes:
[0112] Obtain the server real network location identifier in the data packet from the terminal;
[0113] According to the mapping relationship, look up the server virtual network location identifier LIDs' corresponding to the server real network location identifier LIDs;
[0114] Convert the server real network location identifier LIDs in the data packet from the terminal to the server virtual network location identifier LIDs';
[0115] Or,
[0116] Obtain the server virtual network location identifier LIDs' in the data packet sent to the terminal;
[0117] According to the mapping relationship, look up the server real network location identifier LIDs corresponding to the server virtual network location identifier LIDs';
[0118] Convert the server virtual network location identifiers LIDs' in the data packet sent to the terminal into the server real network location identifiers LIDs.
[0119] In some embodiments, the first domain border gateway obtains the server real network location identifiers LIDs in the data packet Z from the client, looks up the corresponding server virtual network location identifiers LIDs' of the server real network location identifiers LIDs according to the mapping relationship, converts the server real network location identifiers LIDs in the data packet Z into the server virtual network location identifiers LIDs', keeps the client real network location identifier LIDc unchanged, and the structure of the converted data packet Z' is as Figure 5 shown, and sends the converted data packet Z' outside the domain, and reaches the second domain border gateway via outside the domain;
[0120] The second domain border gateway obtains the server virtual network location identifiers LIDs' in the data packet Z', looks up the corresponding server real network location identifiers LIDs of the server virtual network location identifiers LIDs' according to the mapping relationship, restores the server virtual network location identifiers LIDs' in the data packet Z' to the server real network location identifiers LIDs, and sends the restored data packet Z to the server.
[0121] Correspondingly, when the server returns the data packet Y to the client, it includes:
[0122] The second domain border gateway obtains the server real network location identifiers LIDs in the data packet Y returned to the client, looks up the corresponding server virtual network location identifiers LIDs' of the server real network location identifiers LIDs according to the mapping relationship, converts the server real network location identifiers LIDs in the data packet Y into the server virtual network location identifiers LIDs', keeps the client real network location identifier LIDc unchanged, and sends the converted data packet Y' outside the domain, and reaches the first domain border gateway via outside the domain;
[0123] The first domain border gateway obtains the server virtual network location identifiers LIDs' in the data packet Y', looks up the corresponding server real network location identifiers LIDs of the server virtual network location identifiers LIDs' according to the mapping relationship, restores the server virtual network location identifiers LIDs' in the data packet Y' to the server real network location identifiers LIDs, and sends the restored data packet Y to the client.
[0124] (3) Hide both the client real network location identifier LIDc and the server real network location identifier LIDs. Correspondingly, step S130 includes:
[0125] Obtain the client's real network location identifier LIDc and the server's real network location identifier LIDs in the data packet from the terminal;
[0126] According to the mapping relationship, find the client's virtual network location identifier LIDc' corresponding to the client's real network location identifier LIDc, and the server's virtual network location identifier LIDs' corresponding to the server's real network location identifier LIDs;
[0127] Convert the client's real network location identifier LIDc in the data packet from the terminal to the client's virtual network location identifier LIDc', and convert the server's real network location identifier LIDs to the server's virtual network location identifier LIDs';
[0128] Or,
[0129] Obtain the client's virtual network location identifier LIDc' and the server's virtual network location identifier LIDs' in the data packet sent to the terminal;
[0130] According to the mapping relationship, find the client's real network location identifier LIDc corresponding to the client's virtual network location identifier LIDc', and the server's real network location identifier LIDs corresponding to the server's virtual network location identifier LIDs';
[0131] Convert the client's virtual network location identifier LIDc' in the data packet sent to the terminal to the client's real network location identifier LIDc, and convert the server's virtual network location identifier LIDs' to the server's real network location identifier LIDs.
[0132] In some embodiments, the first domain border gateway obtains the client's real network location identifier LIDc and the server's real network location identifier LIDs in the data packet Z from the client. According to the mapping relationship, it finds the client's virtual network location identifier LIDc' corresponding to the client's real network location identifier LIDc, and the server's virtual network location identifier LIDs' corresponding to the server's real network location identifier LIDs. It converts the client's real network location identifier LIDc in the data packet Z to the client's virtual network location identifier LIDc', and converts the server's real network location identifier LIDs to the server's virtual network location identifier LIDs'. The structure of the converted data packet Z' is as Figure 6 shown, and sends the converted data packet Z' outside the domain. It reaches the second domain border gateway via outside the domain;
[0133] The second domain border gateway obtains the client virtual network location identifier LIDc' and the server virtual network location identifier LIDs' in the data packet Z'. According to the mapping relationship, it looks up the client real network location identifier LIDc corresponding to the client virtual network location identifier LIDc', and the server real network location identifier LIDs corresponding to the server virtual network location identifier LIDs'. It restores the client virtual network location identifier LIDc' in the data packet Z' to the client real network location identifier LIDc, and restores the server virtual network location identifier LIDs' to the server real network location identifier LIDs, and sends the restored data packet Z to the server.
[0134] Correspondingly, when the server returns the data packet Y to the client, it includes:
[0135] The second domain border gateway obtains the client real network location identifier LIDc and the server real network location identifier LIDs in the data packet Y returned to the client. According to the mapping relationship, it looks up the client virtual network location identifier LIDc' corresponding to the client real network location identifier LIDc, and the server virtual network location identifier LIDs' corresponding to the server real network location identifier LIDs. It converts the client real network location identifier LIDc in the data packet Y to the client virtual network location identifier LIDc', and converts the server real network location identifier LIDs to the server virtual network location identifier LIDs', and sends the converted data packet Y' outside the domain, and reaches the first domain border gateway through outside the domain;
[0136] The first domain border gateway obtains the client virtual network location identifier LIDc' and the server virtual network location identifier LIDs' in the data packet Y'. According to the mapping relationship, it looks up the client real network location identifier LIDc corresponding to the client virtual network location identifier LIDc', and the server real network location identifier LIDs corresponding to the server virtual network location identifier LIDs'. It restores the client virtual network location identifier LIDc' in the data packet Y' to the client real network location identifier LIDc, and restores the server virtual network location identifier LIDs' to the server real network location identifier LIDs, and sends the restored data packet Y to the client.
[0137] In the above three solutions, in the two processes of the client sending a data packet to the server and the server returning a data packet to the client, data communication is realized within the domain through the real network location identifier LID, and data communication is realized between domains (i.e., outside the domain) through the virtual network location identifier LID', achieving the purpose of protecting the user's location information, and thus effectively reducing the risk of user privacy exposure.
[0138] In some embodiments, such as Figure 7As shown, after step S110, it further includes:
[0139] Step S140: Receive routing information from the location controller; wherein, the routing information is generated by the location controller according to the virtual network location identifier;
[0140] Step S150: Advertise the routing information outside the domain to make the virtual network location identifier reachable by routing.
[0141] In some embodiments, the location controller receives the real network location identifier LID passed by the service controller, establishes a mapping relationship between the real network location identifier LID and the virtual network location identifier LID', generates routing information according to the virtual network location identifier LID', and distributes the routing information of the virtual network location identifier LID' to the domain border gateway. The domain border gateway receives the routing information distributed by the location controller and advertises the routing information outside the domain to make the virtual network location identifier LID' reachable by routing. The purpose is to enable the routers between domains to know which domain border gateway the virtual network location identifier LID' in the data packet comes from when transmitting data packets, so that when transmitting the data packets returned by the server, they can accurately return to the corresponding domain border gateway, improving the reliability of data packet transmission.
[0142] In some embodiments, as Figure 8 shown, the data packet further includes a client network identity identifier NIDc and a server network identity identifier NIDs. The network identity identifier (abbreviated as NID) represents the identity of the client or server on the network and can uniquely identify the client or server on the network. The format can be an IP address, an OID (Object Identifier), etc. Encapsulating the client network identity identifier NIDc and the server network identity identifier NIDs in the data packet can, on the one hand, identify the source of the data packet and the server to which it is to be sent, improving the reliability of data packet transmission. On the other hand, the network identity identifier NID and the network location identifier LID are separately encapsulated in the data packet, which can better protect the user's location privacy during external transmission.
[0143] In a second aspect, an embodiment of the present invention provides a network location information conversion method, which is applied to a location controller. The location controller is respectively connected to the service controller and the domain border gateway, and is mainly used for receiving the real network location identifier LID passed by the service controller, establishing a mapping relationship between the real network location identifier LID and the virtual network location identifier LID', and distributing it to the domain border gateway. For example, the location controller can be the first location controller of domain A or the second location controller of domain B.
[0144] In some embodiments, as Figure 9As shown in the figure, the network location information conversion method includes:
[0145] Step S210: Obtain the real network location identifier;
[0146] Step S220: According to the real network location identifier, establish a mapping relationship between the real network location identifier and the virtual network location identifier;
[0147] Step S230: Send the mapping relationship to the domain border gateway so that the domain border gateway executes the method described in the first aspect.
[0148] In some embodiments, as described in the first aspect, the location controller receives the real network location identifier LID passed by the service controller, and according to the real network location identifier LID, generates a corresponding virtual network location identifier LID', thereby establishing a mapping relationship between the real network location identifier LID and the virtual network location identifier LID'. The location controller sends this mapping relationship to the first domain border gateway so that the first domain border gateway executes the method described in the first aspect. For the specific execution steps, please refer to the description of the first aspect and will not be elaborated here.
[0149] In some embodiments, if the first service controller and the second service controller are deployed separately, and the first location controller and the second location controller are deployed separately, then the first service controller also sends the real network location identifier LID to the second service controller, and then the second service controller sends it to the second location controller. The second location controller receives the real network location identifier LID passed by the second service controller, and according to the real network location identifier LID, generates a corresponding virtual network location identifier LID', thereby establishing a mapping relationship between the real network location identifier LID and the virtual network location identifier LID'. The second location controller sends this mapping relationship to the second domain border gateway so that the second domain border gateway executes the method described in the first aspect. For the specific execution steps, please refer to the description of the first aspect and will not be elaborated here.
[0150] In some embodiments, as described in the first aspect, the real network location identifier LID includes the client real network location identifier LIDc and / or the server real network location identifier LIDs, that is, it can be selected as needed to only hide the client real network location identifier LIDc, or only hide the server real network location identifier LIDs, or hide both the client real network location identifier LIDc and the server real network location identifier LIDs.
[0151] Correspondingly, as Figure 10 shown, step S220 includes:
[0152] Step S221: Establish a mapping relationship between the client's real network location identifier and the client's virtual network location identifier according to the client's real network location identifier;
[0153] and / or,
[0154] Step S222: Establish a mapping relationship between the server's real network location identifier and the server's virtual network location identifier according to the server's real network location identifier.
[0155] That is, only the client's real network location identifier LIDc is hidden, then the location controller only needs to establish a mapping relationship between the client's real network location identifier LIDc and the client's virtual network location identifier LIDc'; only the server's real network location identifier LIDs is hidden, then the location controller only needs to establish a mapping relationship between the server's real network location identifier LIDs and the server's virtual network location identifier LIDs'; both the client's real network location identifier LIDc and the server's real network location identifier LIDs are hidden, then the location controller needs to establish a mapping relationship between the client's real network location identifier LIDc and the client's virtual network location identifier LIDc', and, a mapping relationship between the server's real network location identifier LIDs and the server's virtual network location identifier LIDs'. It can be understood that the above is a relatively preferred method. The location controller can also pre - establish all mapping relationships and perform conversions as needed when converting the real network location identifier in the data packet.
[0156] In some embodiments, the network location information conversion method further includes:
[0157] Obtain the service identifier:
[0158] Correspondingly, step S220 includes:
[0159] Establish a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier and the service identifier.
[0160] In some embodiments, the location controller also receives the service identifier SID passed by the service controller. The service identifier SID represents the service that the client wants to access, that is, the service published by the server, such as domain name, uniform resource identifier, application protocol interface identifier, etc. The location controller establishes a mapping relationship between the real network location identifier LID and the virtual network location identifier LID' according to the real network location identifier LID and the service identifier SID, which can realize that the real network location identifier LID is mapped to different virtual network location identifiers LID' based on different services to be accessed, so as to realize the dynamic transformation of the virtual network location identifier LID', with higher flexibility and better protection of the user's location privacy.
[0161] In some embodiments, as Figure 11 shown, the network location information conversion method further includes:
[0162] Step S240: Obtain a virtual network location identifier;
[0163] Step S250: Generate routing information according to the virtual network location identifier;
[0164] Step S260: Send the routing information to the domain border gateway.
[0165] In some embodiments, the location controller generates a corresponding virtual network location identifier LID' according to the real network location identifier LID, then generates routing information according to the virtual network location identifier LID', and sends the routing information of the virtual network location identifier LID' to the domain border gateway. The domain border gateway receives the routing information sent by the location controller and advertises the routing information outside the domain so that the virtual network location identifier LID' is reachable by routing.
[0166] In a third aspect, an embodiment of the present invention provides a network location information conversion method, which is applied to a service controller. The service controller is respectively connected to an access gateway and a location controller, and is mainly used to pre-register the service identifier SID of the service end, authorize according to the request of the client, return the network identity identifier NID and the real network location identifier LID corresponding to the service identifier SID, and receive the real network location identifier LID sent by the access gateway and transfer it to the location controller. For example, the service controller may be the first service controller in domain A or the second service controller in domain B.
[0167] In some embodiments, the service controller may adopt a distributed deployment method, deploy service controllers within different domains, and interconnect and communicate with each other to form a service control network.
[0168] In some embodiments, as Figure 12 shown, the network location information conversion method includes:
[0169] Step S310: Receive a first access request from the access gateway;
[0170] Step S320: According to the first access request, send the real network location identifier to the location controller so that the location controller executes the method described in the second aspect.
[0171] In some embodiments, the service controller receives a first access request from the access gateway, and the first access request carries the real network location identifier LID. According to the first access request, the service controller sends the real network location identifier LID to the location controller so that the location controller establishes a mapping relationship between the real network location identifier LID and the virtual network location identifier LID'.
[0172] In some embodiments, the first access request carries the client's real network location identifier LIDc; correspondingly, step S320 includes:
[0173] Send the client's real network location identifier to the location controller according to the first access request.
[0174] In some embodiments, the client sends a request to the access gateway, and the access gateway generates a first access request according to the request sent by the client and sends it to the service controller. The first access request carries the client's real network location identifier LIDc. After receiving the client's real network location identifier LIDc, the service controller sends it to the location controller, so that the location controller establishes a mapping relationship between the client's real network location identifier LIDc and the client's virtual network location identifier LIDc' according to the client's real network location identifier LIDc.
[0175] In some embodiments, the first access request further carries a service identifier SID; correspondingly, step S320 includes:
[0176] According to the first access request, search the pre-stored database to obtain the server's real network location identifier LIDs corresponding to the service identifier SID; wherein, the pre-stored database pre-stores the corresponding relationship between the service identifier SID and the server's real network location identifier LIDs;
[0177] Send the server's real network location identifier LIDs to the location controller.
[0178] In some embodiments, the service controller has pre-registered and stored the corresponding relationship between the service identifier SID of the server and the server's real network location identifier LIDs, and stores it in the pre-stored database. The first access request further carries the service identifier SID. After receiving the service identifier SID, the service controller searches the pre-stored database to obtain the server's real network location identifier LIDs corresponding to the service identifier SID, and sends the server's real network location identifier LIDs to the location controller, so that the location controller establishes a mapping relationship between the server's real network location identifier LIDs and the server's virtual network location identifier LIDs' according to the server's real network location identifier LIDs.
[0179] In some embodiments, the first access request further carries the client's network identity identifier NIDc; correspondingly, as Figure 13 shown, the method further includes:
[0180] Step S330: according to the first access request, searching the pre-stored database to obtain the server network identity corresponding to the client network identity and the service identity; wherein the pre-stored database pre-stores the correspondence between the client network identity, the service identity and the server network identity;
[0181] Step S340: Send the server network identity and the server real network location to the access gateway, so that the access gateway records the server network location and sends the server network identity to the terminal.
[0182] In some embodiments, it should be noted that before executing the method, the client is authenticated by the first access gateway, and the first access gateway performs authentication according to the client attributes and the service being accessed. The authentication process can adopt 802.1x, extensible identity authentication protocol, WEB portal and other authentication methods or protocols. If the authentication is passed, the client requests the service controller to allocate the client network identity NIDc through the first access gateway, and the service controller generates a client network identity NIDc and allocates it to the client through the first access gateway. When the client initiates a request to the first access gateway, it also carries the client network identity NIDc, and the first access request generated by the first access gateway also carries the client network identity NIDc. The service controller pre-stores the correspondence between the client network identity NIDc, the service identifier SID, and the server network identity NIDs, and stores it in a pre-stored database. The service controller receives the client network identity NIDc and the service identifier SID, searches the pre-stored database to obtain the server network identity NIDs corresponding to the client network identity NIDc and the service identifier SID, and sends the server network identity NIDs and the server real network location identifier LIDs to the first access gateway. The first access gateway records the server network location identifier LIDs and sends the server network identity identifier NIDs to the client. The above steps realize the separation of the network identity identifier NID and the network location identifier LID, thereby better protecting the user's location privacy.
[0183] In a fourth aspect, an embodiment of the present invention provides a network location information conversion method, which is applied to an access gateway. The access gateway is a boundary device for a client or server to access the Internet, a node for a client or server to interact with a communication peer and a service controller, and participates in a network identity NID allocation process and an access request process. For example, the access gateway may be the first access gateway of domain A or the second access gateway of domain B.
[0184] In some embodiments, Figure 14 As shown, the network location information conversion method includes:
[0185] Step S410: Receive a data packet from a terminal;
[0186] Step S420: Add a real network location identifier to the data packet from the terminal and then send it to the domain border gateway, so that the domain border gateway executes the method described in the first aspect;
[0187] Or, as Figure 15 shown, it includes:
[0188] Step S430: Receive a data packet from the domain border gateway; wherein, the data packet is obtained by the domain border gateway executing the method described in the first aspect;
[0189] Step S440: Delete the real network location identifier from the data packet from the domain border gateway and then send it to the terminal.
[0190] In some embodiments, when the terminal is a client, the first access gateway receives a data packet from the client, adds a real network location identifier LID to the data packet from the client and then sends it to the first domain border gateway, so that the first domain border gateway converts the real network location identifier LID in the data packet into a virtual network location identifier LID' according to the mapping relationship between the real network location identifier LID and the virtual network location identifier LID', and sends it outside the domain; or, the first access gateway receives a data packet from the first domain border gateway, deletes the real network location identifier LID from the data packet from the first domain border gateway and then sends it to the client. The above steps implement data communication within the domain through the real network location identifier LID and data communication between domains (i.e., outside the domain) through the virtual network location identifier LID', thereby achieving the purpose of protecting the user's location information.
[0191] In some embodiments, when the terminal is a server, the second access gateway receives a data packet from the server, adds a real network location identifier LID to the data packet from the server and then sends it to the second domain border gateway, so that the second domain border gateway converts the real network location identifier LID in the data packet into a virtual network location identifier LID' according to the mapping relationship between the real network location identifier LID and the virtual network location identifier LID', and sends it outside the domain; or, the second access gateway receives a data packet from the second domain border gateway, deletes the real network location identifier LID from the data packet from the second domain border gateway and then sends it to the server. The above steps implement data communication within the domain through the real network location identifier LID and data communication between domains (i.e., outside the domain) through the virtual network location identifier LID', thereby achieving the purpose of protecting the user's location information.
[0192] In some embodiments, before step S410 or step S430, it further includes:
[0193] Receive a second access request from a terminal;
[0194] Generate a first access request according to the second access request and send it to the service controller, so that the service controller executes the method described in the third aspect.
[0195] In some embodiments, before the access gateway receives a data packet from a terminal (client or server) or receives a data packet from the domain border gateway, it also receives a second access request from the terminal, generates a first access request according to the second access request, and sends it to the service controller, so that the service controller sends the real network location identifier to the location controller according to the first access request.
[0196] In some embodiments, as Figure 16 shown, the network location information conversion method further includes:
[0197] Step S450: Receive the server network identity identifier from the service controller;
[0198] Step S460: Forward the server network identity identifier to the terminal.
[0199] In some embodiments, as described in the third aspect, the service controller sends the server network identity identifiers NIDs and the real server network location identifiers LIDs to the access gateway. The access gateway receives the server network identity identifiers NIDs and the real server network location identifiers LIDs, records the real server network location identifiers LIDs, and forwards the server network identity identifiers NIDs to the terminal. When sending service data, the terminal encapsulates its own client network identity identifier NIDc, the server network identity identifier NIDs, and the service data payload to form a data packet and sends it out.
[0200] In a fifth aspect, an embodiment of the present invention provides a network location information conversion method applied to a terminal. The terminal can be a client or a server. The client is the initiator of data communication. After the client accesses the first access gateway and passes the identity authentication and authorization process, the service controller in domain A assigns the client network identity identifier NIDc to the client. When accessing a service, the client uses the service identifier SID to request the client network identity identifier NIDc corresponding to the service identifier SID from the service controller, and uses the client network identity identifier NIDc to send service data to the server.
[0201] In some embodiments, as Figure 17 shown, the network location information conversion method includes:
[0202] Step S510: Send a data packet to the access gateway so that the access gateway adds the real network location identifier to the data packet and then sends it to the domain border gateway;
[0203] Or, as Figure 18 shown, including:
[0204] Step S520: Receive a data packet from an access gateway; wherein, the data packet is obtained by the access gateway deleting the real network location identifier in the data packet.
[0205] In some embodiments, when the terminal is a client, the client sends a data packet to a first access gateway so that the first access gateway adds a real network location identifier to the data packet and then sends it to a first domain border gateway; or, the client receives a data packet from the first access gateway, wherein the data packet is obtained by the first access gateway deleting the real network location identifier in the data packet. For the specific execution process, please refer to the description of the above embodiments and will not be elaborated here.
[0206] In some embodiments, when the terminal is a server, the server sends a data packet to a second access gateway so that the second access gateway adds a real network location identifier to the data packet and then sends it to a second domain border gateway; or, the server receives a data packet from the second access gateway, wherein the data packet is obtained by the second access gateway deleting the real network location identifier in the data packet. For the specific execution process, please refer to the description of the above embodiments and will not be elaborated here.
[0207] In some embodiments, before step S510 or step S520, it further includes:
[0208] Send a second access request to the access gateway so that the access gateway generates a first access request according to the second access request and sends it to the service controller.
[0209] In some embodiments, before the terminal (client or server) sends a data packet to the access gateway or the terminal receives a data packet from the access gateway, the terminal also sends a second access request to the access gateway so that the access gateway generates a first access request according to the second access request and sends it to the service controller. For the specific execution process, please refer to the description of the above embodiments and will not be elaborated here.
[0210] The following uses four specific application examples to illustrate the network location information conversion method described in the first to fifth aspects of the embodiments of the present invention. It should be noted that in the four specific application examples, only one service controller and one location controller are set, that is, the service controller and the location controller manage and control the client and the server at the same time.
[0211] Application Example 1
[0212] The first stage: The stage of establishing the mapping relationship between the real network location identifier and the virtual network location identifier
[0213] AsFigure 19 As shown, including:
[0214] Step S610: The client host goes online and interacts with the service controller through the first access gateway to perform identity authentication. Only after the authentication is passed can the subsequent NIDc allocation process be performed;
[0215] Step S620: the host of the client initiates a service authorization request to the service controller through the first access gateway, requesting allocation of a client network identity NIDc;
[0216] Step S630: The service controller detects that the access service of the client is a cross-domain access, and the real network location identifier needs to be hidden from the outside of the domain. The service controller initiates a real network location hiding request for this access to the location controller; and sends information such as the service identifier SID, the client network identity identifier NIDc, and the client real network location identifier LIDc to the location controller;
[0217] Step S640: the location controller establishes a mapping relationship between the client real network location identifier LIDc and the client virtual network location identifier LIDc' according to the service identifier SID, the client network identity identifier NIDc, the client real network location identifier LIDc and other information, and sends this mapping relationship (LIDc<—>LIDc') to the first domain border gateway and the second domain border gateway;
[0218] Step S650: The location controller receives the location hiding request initiated by the service controller and returns a location hiding response to the service controller;
[0219] Step S660: the service controller sends the access rule to the second access gateway according to the location hiding response;
[0220] Step S670: The service controller sends a service authorization response to the first access gateway.
[0221] Step S680: The first access gateway sends a service authorization response to the client;
[0222] Step S690: The client initiates a service access to the server.
[0223] Phase 2: Business access between terminals and servers
[0224] like Figure 20 As shown, including:
[0225] Step S710: The client initiates service access and sends a data packet, which carries the network identity NIDs of the target server and its own client network identity NIDc, wherein NIDs is obtained by the service access authorization request process, and NIDc is obtained by the NID allocation process;
[0226] Step S720: The data packet arrives at the first access gateway. The first access gateway encapsulates the data according to the service - side real network location identifier LIDs and its own client - side real network location identifier LIDc obtained from the service access authorization request process, adds the location identifier <LIDc, LIDs>, and sends it within domain A.
[0227] Step S730: Route and address within domain A using the network location identifier LIDs of the target server. The data packet arrives at the first domain - border gateway. The first domain - border gateway converts the client - side real network location identifier LIDc in the data packet into the client - side virtual network location identifier LIDc' and the server - side real network location identifier LIDs into the server - side virtual network location identifier LIDs' according to the mapping tables (LIDc -> LIDc') and (LIDs -> LIDs'), completing the hiding of the real network location identifier, i.e., <LIDc, LIDs> -> <LIDc', LIDs'>, and continues to send the data packet outside the domain (Internet).
[0228] Step S740: Route and address outside the domain according to the server - side virtual network location identifier LIDs'. The data packet arrives at the second domain - border gateway. The second domain - border gateway restores the virtual network location identifier <LIDc', LIDs'> in the data packet to the real network location identifier <LIDc, LIDs> according to the mapping tables (LIDc' -> LIDc) and (LIDs' -> LIDs), and sends the restored data packet to the in - network of domain B on the server - side.
[0229] Step S750: Route within domain B to the second access gateway according to the server - side real network location identifier LIDs. The second access gateway deletes the real network location identifier <LIDc, LIDs> and sends the data packet carrying the network identity identifier <NIDc, NIDs> to the server, completing a one - way service access process.
[0230] Step S760: The service response process from the server to the client is the same as the client's service access process, and the second domain - border gateway completes the hiding of the real network location identifier. This is not elaborated here.
[0231] In some embodiments, both the server domain and the client domain are assumed to be secure domains. The real network location identifiers LIDc and LIDs are transparent within the domain and hidden outside the domain. The routing information of the real network location identifiers LIDc and LIDs is advertised within the secure domain (client domain, server domain), and the routing is reachable. The routing information of the virtual network location identifiers LIDc' and LIDs' is advertised outside the secure domain, and the routing is reachable. The routing destination outside the domain is the domain - border gateway.
[0232] This embodiment provides a complete hiding service for both the client's true network location identifier LIDc and the server's true network location identifier LIDs. In different application scenarios, it is also possible to only provide a hiding service for the client's true network location identifier LIDc, or only provide a hiding service for the server's true network location identifier LIDs, according to needs.
[0233] Application Example 2
[0234] If only a hiding service is provided for the client's true network location identifier LIDc, then in step S640, only the mapping relationship between the client's true network location identifier LIDc and the client's virtual network location identifier LIDc' is established (LIDc <—> LIDc'). When hiding the true network location at the first domain border gateway on the client side, only LIDc is modified to LIDc', and LIDs remains unchanged. The network location identifier in the out-of-domain data packet is <LIDc', LIDs>. At the second domain border gateway on the server side, only the client's virtual network location identifier LIDc' needs to be restored to the client's true network location identifier LIDc.
[0235] For other steps, please refer to Application Example 1 and will not be elaborated here.
[0236] Application Example 3
[0237] If only a hiding service is provided for the server's true network location identifier LIDc, then in step S640, only the mapping relationship between the server's true network location identifier LIDs and the server's virtual network location identifier LIDs' is established (LIDs <—> LIDs'). When hiding the true network location at the first domain border gateway on the client side, only LIDs is modified to LIDs', and LIDc remains unchanged. The network location identifier in the out-of-domain data packet is <LIDc, LIDs'>. At the second domain border gateway on the server side, only the server's virtual network location identifier LIDs' needs to be restored to the server's true network location identifier LIDs.
[0238] For other steps, please refer to Application Example 1 and will not be elaborated here.
[0239] Application Example 4
[0240] Provide hiding services only for the client's real network location identifier LIDc, and the client's real network location identifier is not restored in the server domain, then the domain border gateway on the server side can be trimmed. Similar to Application Example 2, step S640 only establishes the mapping relationship between the client's real network location identifier LIDc and the client's virtual network location identifier LIDc' (LIDc <—> LIDc'). When hiding the real network location at the first domain border gateway on the client side, only modify LIDc to LIDc', and LIDs remain unchanged. The network location identifier in the out-of-domain data packet is <LIDc', LIDs>. Since there is no domain border gateway on the server side, the data packet is directly routed to the second access gateway on the server side. The second access gateway deletes the network location identifier <LIDc', LIDs> in step S750 and sends the service data to the server.
[0241] In the reverse direction, when the response data returned by the server passes through the second access gateway on the server side, the second access gateway performs data encapsulation, adding the target client's virtual network location identifier LIDc' and its own virtual network location identifier LIDs' to form a data packet. This LIDc' can be generated by the self-learning method or sent down by the service controller according to the mapping relationship. In this embodiment, the client's virtual network location identifier LIDc' is reachable for routing within the server domain and is advertised outside the domain. The data packet reaches the first domain border gateway on the client side. The first domain border gateway only needs to modify the client's virtual network location identifier LIDc' to the client's real network location identifier LIDc, and LIDs' remain unchanged. The data packet reaches the first access gateway on the client side. The first access gateway deletes the network location identifier <LIDc, LIDs'> and sends the service data to the client.
[0242] In the sixth aspect, as Figure 21 shown, an embodiment of the present invention provides a domain border gateway, including:
[0243] A first acquisition module 310, configured to acquire the mapping relationship between the real network location identifier and the virtual network location identifier;
[0244] A first receiving module 320, configured to receive data packets from or sent to the terminal; wherein, the data packet includes a real network location identifier or a virtual network location identifier;
[0245] A conversion module 330, configured to perform network location identifier conversion on the data packet according to the mapping relationship.
[0246] In some embodiments, for the working principle of the domain border gateway, please refer to the description of the network location information conversion method in the first aspect, which will not be elaborated here.
[0247] In the seventh aspect, as Figure 22As shown in the figure, an embodiment of the present invention provides a location controller, including:
[0248] A second acquisition module 410, configured to acquire a real network location identifier;
[0249] An establishment module 420, configured to establish a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier;
[0250] A distribution module 430, configured to distribute the mapping relationship to the domain border gateway as described in the sixth aspect.
[0251] In some embodiments, for the working principle of the location controller, please refer to the description of the network location information conversion method in the second aspect, which will not be elaborated here.
[0252] In the eighth aspect, as Figure 23 shown in the figure, an embodiment of the present invention provides a service controller, including:
[0253] A second receiving module 510, configured to receive a first access request from an access gateway;
[0254] A first sending module 520, configured to send the real network location identifier to the location controller as described in the seventh aspect according to the first access request.
[0255] In some embodiments, for the working principle of the service controller, please refer to the description of the network location information conversion method in the third aspect, which will not be elaborated here.
[0256] In the ninth aspect, as Figure 24 shown in the figure, an embodiment of the present invention provides an access gateway, including:
[0257] A third receiving module 610, configured to receive data packets from a terminal;
[0258] A second sending module 620, configured to add the real network location identifier to the data packets from the terminal and then send them to the domain border gateway as described in the sixth aspect;
[0259] Or,
[0260] A fourth receiving module 630, configured to receive data packets from the domain border gateway as described in the sixth aspect.
[0261] In some embodiments, for the working principle of the access gateway, please refer to the description of the network location information conversion method in the fourth aspect, which will not be elaborated here.
[0262] In the tenth aspect, as Figure 25 shown in the figure, an embodiment of the present invention provides a terminal, including:
[0263] A third sending module 710, configured to send a data packet to an access gateway as described in the ninth aspect;
[0264] Or,
[0265] A fifth receiving module 720, configured to receive a data packet from an access gateway as described in the ninth aspect.
[0266] In some embodiments, for the working principle of the terminal, please refer to the description of the network location information conversion method in the fifth aspect, which will not be elaborated here.
[0267] Application Example Five
[0268] Application Example Five provides a network location information conversion system, including a domain border gateway as described in the sixth aspect, a location controller as described in the seventh aspect, a service controller as described in the eighth aspect, an access gateway as described in the ninth aspect, and a terminal as described in the tenth aspect.
[0269] In some embodiments, a second receiving module 510 of the service controller receives a first access request from an access gateway, and a first sending module 520 sends a real network location identifier to a second obtaining module 410 of the location controller according to the first access request. The second obtaining module 410 of the location controller obtains the real network location identifier and sends it to a establishing module 420. The establishing module 420 of the location controller establishes a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier, and sends it to a distributing module 430. The distributing module 430 of the location controller distributes the mapping relationship to a first obtaining module 310 of the domain border gateway. The first obtaining module 310 of the domain border gateway obtains the mapping relationship between the real network location identifier and the virtual network location identifier.
[0270] In some embodiments, a third sending module 710 of the terminal sends a data packet to a third receiving module 610 of the access gateway. The third receiving module 610 of the access gateway receives the data packet from the terminal and sends it to a second sending module 620. After adding the real network location identifier to the data packet from the terminal, the second sending module 620 of the access gateway sends it to a first receiving module 320 of the domain border gateway. The first receiving module 320 of the domain border gateway receives the data packet from or destined for the terminal and sends it to a conversion module 330. The conversion module 330 of the domain border gateway performs network location identifier conversion on the data packet according to the mapping relationship.
[0271] Or,
[0272] In some embodiments, the conversion module 330 of the domain border gateway converts the network location identifier of the data packet according to the mapping relationship and sends it to the fourth receiving module 630 of the access gateway. The fourth receiving module 630 of the access gateway receives the data packet from the domain border gateway and sends it to the fifth receiving module 720 of the terminal. The fifth receiving module 720 of the terminal receives the data packet from the access gateway.
[0273] In an eleventh aspect, an embodiment of the present invention provides an electronic device, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following is implemented:
[0274] The steps of the network location information conversion method as described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
[0275] In some embodiments, the electronic device can be a mobile terminal device or a non-mobile terminal device. The mobile terminal device can be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted terminal device, a wearable device, a super mobile personal computer, a netbook, a personal digital assistant, etc.; the non-mobile terminal device can be a personal computer, a television, a teller machine or a self-service machine, etc.; the specific implementation of the present invention is not limited.
[0276] In a twelfth aspect, an embodiment of the present invention provides a storage medium for computer-readable storage. The storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement:
[0277] The steps of the network location information conversion method as described in the first aspect or the second aspect or the third aspect or the fourth aspect or the fifth aspect.
[0278] Those of ordinary skill in the art can understand that all or some of the steps in the above-disclosed methods, and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware and their appropriate combinations.
[0279] In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component may have multiple functions, or one function or step may be executed by the cooperation of several physical components. Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes but is not limited to RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and may include any information delivery medium.
[0280] The preferred embodiments of the present invention have been described above with reference to the accompanying drawings, but this does not limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention shall fall within the scope of the present invention.
Claims
1. A network location information conversion method, applied to a domain border gateway, includes: Obtaining a mapping relationship between a real network location identifier and a virtual network location identifier, where the mapping relationship is established based on the real network location identifier and the service identifier; Receiving a data packet from or sent to the terminal; where the data packet includes a real network location identifier or a virtual network location identifier; According to the mapping relationship, converting the real network location identifier in the data packet from the terminal into a virtual network location identifier, or, according to the mapping relationship, converting the virtual network location identifier in the data packet sent to the terminal into a real network location identifier; Receiving routing information from a location controller; where the routing information is generated by the location controller according to the virtual network location identifier; Advertising the routing information outside the domain so that the virtual network location identifier is routable.
2. The network location information conversion method according to claim 1, wherein The real network location identifier includes a client real network location identifier; The converting the real network location identifier in the data packet from the terminal into a virtual network location identifier according to the mapping relationship includes: Obtaining the client real network location identifier in the data packet from the terminal; According to the mapping relationship, looking up the client virtual network location identifier corresponding to the client real network location identifier; Converting the client real network location identifier in the data packet from the terminal into a client virtual network location identifier; Or, The virtual network location identifier includes a client virtual network location identifier; The converting the virtual network location identifier in the data packet sent to the terminal into a real network location identifier according to the mapping relationship includes: Obtaining the client virtual network location identifier in the data packet sent to the terminal; According to the mapping relationship, looking up the client real network location identifier corresponding to the client virtual network location identifier; Converting the client virtual network location identifier in the data packet sent to the terminal into a client real network location identifier.
3. The network location information conversion method according to claim 1, wherein The real network location identifier includes a server real network location identifier; The converting the real network location identifier in the data packet from the terminal into a virtual network location identifier according to the mapping relationship includes: Obtaining the server real network location identifier in the data packet from the terminal; According to the mapping relationship, looking up the server virtual network location identifier corresponding to the server real network location identifier; Converting the server real network location identifier in the data packet from the terminal into a server virtual network location identifier; Or, The virtual network location identifier includes a server virtual network location identifier; The converting the virtual network location identifier in the data packet sent to the terminal into a real network location identifier according to the mapping relationship includes: Obtaining the server virtual network location identifier in the data packet sent to the terminal; According to the mapping relationship, looking up the server real network location identifier corresponding to the server virtual network location identifier; Convert the server virtual network location identifier in the data packet sent to the terminal into a server real network location identifier.
4. The network location information conversion method according to claim 1, characterized in that the real network location identifier includes a client real network location identifier and a server real network location identifier; the converting the real network location identifier in the data packet from the terminal into a virtual network location identifier according to the mapping relationship includes: obtaining the client real network location identifier and the server real network location identifier in the data packet from the terminal; according to the mapping relationship, looking up the client virtual network location identifier corresponding to the client real network location identifier and the server virtual network location identifier corresponding to the server real network location identifier; converting the client real network location identifier in the data packet from the terminal into a client virtual network location identifier and converting the server real network location identifier into a server virtual network location identifier; or the virtual network location identifier includes a client virtual network location identifier and a server virtual network location identifier; the converting the virtual network location identifier in the data packet sent to the terminal into a real network location identifier according to the mapping relationship includes: obtaining the client virtual network location identifier and the server virtual network location identifier in the data packet sent to the terminal; according to the mapping relationship, looking up the client real network location identifier corresponding to the client virtual network location identifier and the server real network location identifier corresponding to the server virtual network location identifier; converting the client virtual network location identifier in the data packet sent to the terminal into a client real network location identifier and converting the server virtual network location identifier into a server real network location identifier.
5. The network location information conversion method according to any one of claims 1 to 4, characterized in that, The data packet further includes a client network identity identifier and a server network identity identifier.
6. A network location information conversion method applied to a location controller, comprising: obtaining a real network location identifier and a service identifier; establishing a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier and the service identifier; sending the mapping relationship to the domain border gateway so that the domain border gateway executes the method according to any one of claims 1 to 5; obtaining the virtual network location identifier; generating routing information according to the virtual network location identifier; sending the routing information to the domain border gateway.
7. The network location information conversion method according to claim 6, characterized in that, The real network location identifier includes a client real network location identifier and / or a server real network location identifier; correspondingly, the establishing a mapping relationship between the real network location identifier and the virtual network location identifier according to the real network location identifier includes: establishing a mapping relationship between the client real network location identifier and the client virtual network location identifier according to the client real network location identifier; and / or establishing a mapping relationship between the server real network location identifier and the server virtual network location identifier according to the server real network location identifier.
8. A network location information conversion method applied to a service controller, comprising: Receive a first access request from an access gateway; According to the first access request, send a real network location identifier to a location controller, so that the location controller executes the method according to any one of claims 6 to 7.
9. The network location information conversion method according to claim 8, characterized in that The first access request carries a client real network location identifier; The sending the real network location identifier to the location controller according to the first access request includes: According to the first access request, sending the client real network location identifier to the location controller.
10. The network location information conversion method according to claim 8 or 9, characterized in that The first access request carries a service identifier; The sending the real network location identifier to the location controller according to the first access request includes: According to the first access request, look up a pre-stored database to obtain a server real network location identifier corresponding to the service identifier; wherein, the pre-stored database pre-stores the correspondence between the service identifier and the server real network location identifier; Send the server real network location identifier to the location controller.
11. The network location information conversion method according to claim 10, characterized in that The first access request further carries a client network identity identifier; The method further includes: According to the first access request, look up a pre-stored database to obtain a server network identity identifier corresponding to the client network identity identifier and the service identifier; wherein, the pre-stored database pre-stores the correspondence between the client network identity identifier, the service identifier and the server network identity identifier; Send the server network identity identifier and the server real network location identifier to the access gateway, so that the access gateway records the server real network location identifier and sends the server network identity identifier to the terminal.
12. A network location information conversion method, applied to an access gateway, includes: Receive a data packet from a terminal; Add a real network location identifier to the data packet from the terminal and then send it to a domain border gateway, so that the domain border gateway executes the method according to any one of claims 1 to 5; Or, Receive a data packet from the domain border gateway; wherein, the data packet is obtained by the domain border gateway executing the method according to any one of claims 1 to 5; Delete the real network location identifier from the data packet from the domain border gateway and then send it to the terminal.
13. The network location information conversion method according to claim 12, wherein Before receiving the data packet from the terminal or receiving the data packet from the domain border gateway, it further includes: Receive a second access request from the terminal; According to the second access request, generate a first access request and send it to a service controller, so that the service controller executes the method according to any one of claims 8 to 11.
14. The network location information conversion method according to claim 13, wherein It further includes: Receive a server network identity identifier from the service controller; Forward the server network identity identifier to the terminal.
15. A network location information conversion method, applied to a terminal, includes: Send a data packet to an access gateway so that the access gateway adds a real network location identifier to the data packet and then sends it to a domain border gateway, causing the domain border gateway to execute the method according to any one of claims 1 to 5; Or, Receive a data packet from an access gateway; wherein, the data packet is obtained by the domain border gateway executing the method according to any one of claims 1 to 5 and then sent to the access gateway, and the real network location identifier in the data packet is deleted by the access gateway.
16. The network location information conversion method according to claim 15, wherein Before sending the data packet to the access gateway or receiving the data packet from the access gateway, it further includes: Send a second access request to the access gateway so that the access gateway generates a first access request according to the second access request and sends it to a service controller.
17. A domain border gateway, comprising: A first acquisition module, configured to acquire a mapping relationship between a real network location identifier and a virtual network location identifier, wherein the mapping relationship is established according to the real network location identifier and a service identifier; A first receiving module, configured to receive a data packet from or sent to the terminal; wherein, the data packet includes a real network location identifier or a virtual network location identifier; and receive routing information from a location controller, wherein the routing information is generated by the location controller according to the virtual network location identifier; A first sending module, configured to advertise the routing information outside the domain so that the virtual network location identifier is routeable; A conversion module, configured to convert the real network location identifier in the data packet from the terminal into a virtual network location identifier according to the mapping relationship, or convert the virtual network location identifier in the data packet sent to the terminal into a real network location identifier according to the mapping relationship.
18. A location controller, comprising: A second acquisition module, configured to acquire a real network location identifier; An establishment module, configured to establish a mapping relationship between a real network location identifier and a virtual network location identifier according to the real network location identifier; A distribution module, configured to distribute the mapping relationship to the domain border gateway according to claim 17.
19. A service controller, comprising: A second receiving module, configured to receive a first access request from an access gateway; A first sending module, configured to send a real network location identifier to the location controller according to claim 18 according to the first access request.
20. An access gateway, comprising: A third receiving module, configured to receive a data packet from a terminal; A second sending module, configured to add a real network location identifier to the data packet from the terminal and then send it to the domain border gateway according to claim 17; Or, A fourth receiving module, configured to receive a data packet from the domain border gateway according to claim 17.
21. A terminal, comprising: A third sending module, configured to send a data packet to the access gateway according to claim 20; Or, A fifth receiving module, configured to receive a data packet from the access gateway according to claim 20.
22. An electronic device, the electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, it realizes: The network location information conversion method according to any one of claims 1 to 16.
23. A storage medium for computer-readable storage, the storage medium storing one or more programs, the one or more programs being executable by one or more processors to implement: The network location information conversion method according to any one of claims 1 to 16.
Citation Information
Patent Citations
Method for achieving protection of passive optical network user based on separate mapping mechanism
CN103618749A
Location data processing method and device
CN107018491A