Message forwarding method, device, equipment and storage medium
The method addresses the lack of dynamic port support in Ethernet/IP NAT environments by establishing connection mappings and performing address translations, ensuring reliable and efficient communication through fixed ports.
Patent Information
- Application Number
- CN202211227339.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-09
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-10-09
AI Technical Summary
Ethernet/IP implicit communication in existing NAT environments cannot support dynamic ports, resulting in unavailability in communication scenarios involving dynamic ports.
By receiving explicit connection requests from the master device in the firewall, network address conversion is carried out, connection mapping information is established, and network address conversion is carried out based on the connection mapping information during implicit communication, implicit communication between the master device and the slave device is realized.
It realizes the communication channel through explicit communication in the NAT environment, adapts to the communication scenario of dynamic ports, and improves the reliability and efficiency of implicit communication.
Smart Images

Figure CN115550044B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial control security communication technology. Specifically, it relates to a message forwarding method, device, equipment, and storage medium. Background Art
[0002] Ethernet / IP is an industrial Ethernet communication protocol, and the communication methods include explicit communication and implicit communication. Network Address Translation (NAT) is a method commonly applied to firewalls for network address conversion and network protection.
[0003] To implement the implicit communication of Ethernet / IP in a NAT environment, it is necessary to first use explicit communication to open a channel and agree on channel information in the application layer data.
[0004] However, the existing implicit communication of Ethernet / IP in a NAT environment does not support dynamic ports, and in some communication scenarios, it is necessary to create dynamic ports to achieve communication. Therefore, the existing implicit communication method of Ethernet / IP in a NAT environment is not applicable in communication scenarios involving dynamic ports. Summary of the Invention
[0005] The purpose of this application is to provide a message forwarding method, device, equipment, and storage medium to solve the problem that the implicit communication of Ethernet / IP in a NAT environment in the prior art cannot be used properly, aiming at the deficiencies in the above-mentioned prior art.
[0006] To achieve the above purpose, the technical solutions adopted in this application are as follows:
[0007] In a first aspect, this application provides a message forwarding method, which is applied to a firewall. The method includes:
[0008] Receiving an explicit connection request sent by a master device to a slave device to be connected, and parsing the explicit connection request to obtain a pre-conversion quadruple, where the pre-conversion quadruple includes: source IP, source port, destination IP, and destination port;
[0009] Performing network address conversion on the pre-conversion quadruple according to a target conversion strategy, where the target conversion strategy includes: a master device conversion strategy and a slave device conversion strategy;
[0010] Based on the quadruple before conversion and the quadruple after conversion, establish the first connection mapping information, send a converted explicit connection request including the quadruple after conversion to the slave device, and after receiving the converted explicit connection response returned by the slave device, send an explicit connection response to the master device, where the first connection mapping information includes: a first key and a first value, the first key includes: a first connection identifier and the quadruple before conversion, and the first value includes: the source IP and destination IP in the quadruple after conversion, and the source port and destination port in the quadruple before conversion;
[0011] Receive the implicit communication request sent by the master device to the slave device, and parse the implicit communication request to obtain the first connection identifier and the quadruple before conversion;
[0012] Based on the parsed first connection identifier, the quadruple before conversion, and the first connection mapping information, determine the first value, perform network address conversion on the implicit communication request according to the first value, and forward the converted implicit communication request to the slave device.
[0013] Optionally, after performing network address conversion on the quadruple before conversion according to the target conversion strategy to obtain the quadruple after conversion, it further includes:
[0014] Based on the quadruple before conversion and the quadruple after conversion, establish the second connection mapping information, where the second connection mapping information includes: a second key and a second value, the second key includes: a second connection identifier and the quadruple after conversion, and the second value includes: the quadruple before conversion.
[0015] Optionally, the method further includes:
[0016] Receive the implicit communication message sent by the slave device, and parse the implicit communication message to obtain the second connection identifier and the quadruple after conversion;
[0017] Based on the parsed second connection identifier, the quadruple after conversion, and the second connection mapping information, determine the second value, perform network address conversion on the implicit communication message according to the second value, and forward the converted implicit communication message to the master device.
[0018] Optionally, performing network address conversion on the quadruple before conversion according to the target conversion strategy to obtain the quadruple after conversion includes:
[0019] According to the master device conversion strategy, convert the source IP and source port in the quadruple before conversion to obtain the converted source IP and the converted source port;
[0020] According to the slave device conversion policy, convert the destination IP and destination port in the quadruple before conversion to obtain the converted destination IP and the converted destination port;
[0021] Combine the converted source IP, the converted source port, the converted destination IP, and the converted destination port into the converted quadruple.
[0022] Optionally, establishing first connection mapping information according to the quadruple before conversion and the quadruple after conversion includes:
[0023] Receive a first connection identifier;
[0024] Combine the first connection identifier and the quadruple before conversion into the first key;
[0025] Use the source IP and destination IP in the quadruple after conversion, and the source port and destination port in the quadruple before conversion as the first value.
[0026] Optionally, establishing second connection mapping information according to the quadruple before conversion and the quadruple after conversion includes:
[0027] Receive a second connection identifier;
[0028] Combine the second connection identifier and the quadruple after conversion into the second key;
[0029] Use the source IP and destination IP in the quadruple before conversion, and the source port and destination port in the quadruple after conversion as the second value.
[0030] Optionally, performing network address translation on the implicit communication request according to the first value includes:
[0031] According to the first value, perform network address translation on the transport layer data and network layer data in the implicit communication request.
[0032] In a second aspect, the present application provides a message forwarding device, and the device includes:
[0033] A receiving module, configured to: receive an explicit connection request sent by a master device to a slave device to be connected, and parse the explicit connection request to obtain a quadruple before conversion, where the quadruple before conversion includes: source IP, source port, destination IP, and destination port;
[0034] A conversion module, configured to: perform network address translation on the quadruple before conversion according to a target conversion policy to obtain a quadruple after conversion, where the target conversion policy includes: a master device conversion policy and a slave device conversion policy;
[0035] A forwarding module, configured to: establish first connection mapping information according to the pre-conversion quadruple and the post-conversion quadruple, send a post-conversion explicit connection request including the post-conversion quadruple to the slave device, and send an explicit connection response to the master device after receiving the post-conversion explicit connection response returned by the slave device, where the first connection mapping information includes: a first key and a first value, the first key includes: a first connection identifier and the pre-conversion quadruple, and the first value includes: the source IP and destination IP in the post-conversion quadruple, and the source port and destination port in the pre-conversion quadruple;
[0036] The receiving module is further configured to: receive the implicit communication request sent by the master device to the slave device, and parse the implicit communication request to obtain the first connection identifier and the pre-conversion quadruple;
[0037] The conversion module is further configured to: determine the first value according to the parsed first connection identifier, the pre-conversion quadruple, and the first connection mapping information, perform network address conversion on the implicit communication request according to the first value, and forward the converted implicit communication request to the slave device.
[0038] Optionally, the conversion module is further configured to:
[0039] Convert the source IP and source port in the pre-conversion quadruple according to the master device conversion policy to obtain a post-conversion source IP and a post-conversion source port;
[0040] Convert the destination IP and destination port in the pre-conversion quadruple according to the slave device conversion policy to obtain a post-conversion destination IP and a post-conversion destination port;
[0041] Combine the post-conversion source IP, the post-conversion source port, the post-conversion destination IP, and the post-conversion destination port into the post-conversion quadruple.
[0042] Optionally, the forwarding module is further configured to:
[0043] Receive a first connection identifier;
[0044] Combine the first connection identifier and the pre-conversion quadruple into the first key;
[0045] Use the source IP and destination IP in the post-conversion quadruple, and the source port and destination port in the pre-conversion quadruple as the first value.
[0046] Optionally, the forwarding module is further configured to:
[0047] Receive a second connection identifier;
[0048] Combine the second connection identifier and the converted quadruple into the second key;
[0049] Use the source IP and destination IP in the quadruple before conversion, and the source port and destination port in the quadruple after conversion as the second value.
[0050] Optionally, the conversion module is further configured to:
[0051] Perform network address translation on the transport layer data and network layer data in the implicit communication request according to the first value.
[0052] In a third aspect, the present application provides an electronic device, including: a processor, a storage medium, and a bus. The storage medium stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the message forwarding method as described above.
[0053] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it performs the steps of the message forwarding method as described above.
[0054] The beneficial effects of the present application are as follows: The firewall receives an explicit connection request sent by the master device to the slave device, performs network address translation on the explicit connection request, establishes connection mapping information, and when receiving implicit communication between the master device and the slave device, performs network address translation on the implicit communication request according to the connection mapping information, and then forwards the converted implicit communication request. On the one hand, it can enable the implicit communication between the master device and the slave device to be carried out through a pre-agreed fixed port. On the other hand, it can achieve forwarding only for the implicit communication messages for which the connection mapping information is saved in the firewall, improving the reliability and efficiency of the implicit communication. Description of the Drawings
[0055] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0056] Figure 1 Shows an architectural schematic diagram of an application scenario of message forwarding provided by an embodiment of the present application;
[0057] Figure 2 Shows a flowchart of a message forwarding method provided by an embodiment of the present application;
[0058] Figure 3 Shows a flowchart of another message forwarding method provided by an embodiment of the present application;
[0059] Figure 4 Shows a schematic flowchart of a message forwarding method provided by an embodiment of the present application;
[0060] Figure 5 Shows a flowchart of a specific method for obtaining a converted quadruple in the message forwarding method provided by an embodiment of the present application;
[0061] Figure 6 Shows a flowchart of a method for determining first connection mapping information provided by an embodiment of the present application;
[0062] Figure 7 Shows a flowchart of a method for determining second connection mapping information provided by an embodiment of the present application;
[0063] Figure 8 Shows a flowchart of another message forwarding method provided by an embodiment of the present application;
[0064] Figure 9 Shows a schematic structural diagram of a message forwarding device provided by an embodiment of the present application;
[0065] Figure 10 Shows a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0066] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. It should be understood that the accompanying drawings in the present application are only for the purposes of illustration and description, and are not used to limit the protection scope of the present application. In addition, it should be understood that the schematic drawings are not drawn to actual scale. The flowcharts used in the present application show the operations implemented according to some embodiments of the present application. It should be understood that the operations in the flowchart may not be implemented in sequence, and steps without a logical context relationship may be reversed or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart or remove one or more operations from the flowchart under the guidance of the content of the present application.
[0067] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application usually described and illustrated in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application claimed, but only represents the selected embodiments of the present application. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.
[0068] It should be noted that the term "including" will be used in the embodiments of the present application to indicate the existence of the features stated thereafter, but does not exclude the addition of other features.
[0069] Ethernet / IP is a relatively commonly used industrial Ethernet communication protocol. The communication methods include explicit communication and implicit communication. Explicit communication is suitable for transmitting data with high accuracy and low timeliness, such as configuring device information, uploading or downloading programs, etc. Implicit communication is suitable for transmitting data with high real-time performance, such as motor control, sensor data, etc. In order to implement the implicit communication of Ethernet / IP in the NAT environment, it is necessary to first use explicit communication to open a channel and agree on the channel information in the application layer data.
[0070] In order to implement the implicit communication of Ethernet / IP in the NAT environment, some people have proposed to create dynamic ports to implement the transmission of application layer data. However, the ports for the implicit communication of Ethernat / Ip are fixed and immutable in many applications. Therefore, the existing implicit communication methods of Ethernet / IP in the NAT environment are not applicable in communication scenarios involving dynamic ports.
[0071] Based on the above problems, the present application proposes a message forwarding method, which can be applied to the scenario of Ethernet / IP communication in the NAT environment, such as Figure 1 As shown, in this scenario, it includes a master device, a slave device, and a firewall. The master device and the slave device can be in different networks. For example, the master device can be any device in the internal network environment, and the slave device can be any device in the external network environment. The firewall can be set at the network boundary between the master device and the slave device, and all communication messages between the master device and the slave device need to pass through the firewall. Among them, the master device can be, for example, a client, a control device, etc., and the slave device can be, for example, a server, an adaptation device, etc.
[0072] Next, in combination with Figure 2 the message forwarding method of the present application will be described. Among them, the message forwarding method of the present application can be applied to Figure 1 the firewall in the application scenario shown, such as Figure 2As shown, the method includes:
[0073] S201: Receive the explicit connection request sent by the master device to the slave device to be connected, and parse the explicit connection request to obtain the quadruple before conversion. The quadruple before conversion includes: source IP, source port, destination IP, and destination port.
[0074] Optionally, the explicit connection request may be an explicit communication message sent by the master device to the slave device, and this explicit communication message can be used to open the channel for implicit communication.
[0075] Optionally, the explicit connection request may include the configuration information for opening the implicit communication channel, that is, the ports, IPs, etc. agreed to be used by the master device and the slave device in subsequent communications. Exemplarily, it may include the source IP of the master device and the master device port used when the master device sends an implicit communication message to the slave device after sending the explicit connection request.
[0076] Optionally, the explicit connection request may include a quadruple, that is, source IP, source port, destination IP, and destination port. Among them, the source IP may be the IP address of the master device, the source port may be the master device port, the destination IP may be the IP address of the slave device, and the destination port may be the slave device port.
[0077] It should be noted that the firewall may include a parsing module. After receiving a data packet, the parsing module can determine whether it is explicit communication or implicit communication according to the protocol of the data packet. Explicit communication uses the Transmission Control Protocol (TCP), and implicit communication uses the User Datagram Protocol (UDP).
[0078] S202: Perform network address translation on the quadruple before conversion according to the target conversion strategy. The target conversion strategy includes: master device conversion strategy, slave device conversion strategy.
[0079] Optionally, the target conversion strategy may be a rule for performing network address translation on the quadruple in the communication message sent by the master device or the slave device in the firewall. Among them, the master device conversion strategy may be, for example, Destination Network Address Translation (DNAT), and the slave device conversion strategy may be, for example, Source Network Address Translation (SNAT).
[0080] In the above target conversion strategy, the specific network address translation method is not limited in this application.
[0081] S203: Based on the quadruple before conversion and the quadruple after conversion, establish the first connection mapping information, send a converted explicit connection request containing the quadruple after conversion to the slave device, and after receiving the converted explicit connection response returned by the slave device, send an explicit connection response to the master device, where the first connection mapping information includes: a first key and a first value, the first key includes: a first connection identifier and the quadruple before conversion, and the first value includes: the source IP and destination IP in the quadruple after conversion, and the source port and destination port in the quadruple before conversion.
[0082] Optionally, the first connection mapping information can be a rule when the master device sends a stealth communication message to the slave device. After receiving the stealth message sent by the master device, the firewall can determine the slave device that needs to forward according to the first connection mapping information and forward the message.
[0083] It should be noted that in the stealth communication of Ethernet / IP, since the message is transmitted through the User Datagram Protocol (UDP), and UDP is a connectionless transport protocol, in the above step S201, the master device can agree on the connection identifier for communicating with the slave device in the explicit connection request to improve the accuracy of subsequent stealth communication.
[0084] Optionally, the first connection identifier can be the connection identifier when the master device sends a communication message to the slave device.
[0085] Optionally, the firewall can also traverse in the explicit connection request according to the source IP in the quadruple after conversion and the converted source IP, and modify the source IP to the converted source IP. On the one hand, this can ensure that all source IPs in the message received by the slave device are the converted source IPs. On the other hand, it can avoid exposing the IP address of the master device on the slave device side, thereby improving the privacy of message forwarding.
[0086] Optionally, the master device can agree on the port used by the master device in the stealth communication in the explicit connection request. After receiving the explicit connection request forwarded by the firewall, the slave device can send an explicit connection response to the master device and agree on the port used by the slave device in the stealth communication in the explicit connection response.
[0087] Optionally, the firewall can save the first connection mapping information. For example, create a dynamic database. When the master device and the slave device establish a connection and communicate, save the first connection mapping information used for communication between the master device and the slave device in the form of key-value pairs in the dynamic database. After the communication is completed, the corresponding first connection mapping information can be deleted to save memory resources.
[0088] S204: Receive the implicit communication request sent by the master device to the slave device, and parse the implicit communication request to obtain the first connection identifier and the quadruple before conversion.
[0089] Optionally, after the master device and the slave device establish a channel through explicit communication, the master device can send an implicit communication request to the slave device through this channel. Exemplarily, the implicit communication request can be real-time I / O data, etc.
[0090] After the firewall receives the communication request sent by the master device to the slave device, when it can confirm that the data packet uses the UDP protocol through the parsing module, that is, the communication request is an implicit communication request, the firewall can parse the data packet of the implicit communication request and obtain the first connection identifier of the implicit communication request and the quadruple before conversion.
[0091] S205: Determine the first value according to the parsed first connection identifier, quadruple before conversion, and the first connection mapping information, perform network address translation on the implicit communication request according to the first value, and forward the converted implicit communication request to the slave device.
[0092] Optionally, the firewall can search for the parsed first connection identifier and the quadruple before conversion in the dynamic database saved in the above S203 step to obtain the first mapping information between the master device and the slave device, and determine the first value, that is, the source IP and destination IP in the quadruple after conversion, and the source port and destination port in the quadruple before conversion.
[0093] Optionally, the firewall can perform network address translation on the source IP and destination IP in the implicit communication request according to the found first value, and forward the converted implicit communication request to the slave device.
[0094] In the embodiment of the present application, the firewall receives the explicit connection request sent by the master device to the slave device, performs network address translation on the explicit connection request, establishes connection mapping information, and when receiving the implicit communication between the master device and the slave device, performs network address translation on the implicit communication request according to the connection mapping information, and then forwards the converted implicit communication request. By establishing connection mapping information and performing network address translation in the firewall, the implicit communication between the master device and the slave device can open a communication channel through explicit communication, and any port is pre-agreed, so as to realize the sending and receiving of implicit communication messages at the agreed port, thereby adapting to the communication scenario of dynamic ports and improving the reliability and efficiency of implicit communication.
[0095] Next, after performing network address translation on the quadruple before conversion according to the target conversion strategy to obtain the quadruple after conversion, the above S202 step further includes:
[0096] Based on the quadruple before conversion and the quadruple after conversion, second connection mapping information is established. The second connection mapping information includes: a second key and a second value. The second key includes: a second connection identifier and the quadruple after conversion. The second value includes: the quadruple before conversion.
[0097] Optionally, the second connection mapping information can be a rule when the slave device sends a stealth communication message to the master device. After the firewall receives the stealth message sent by the slave device, it can determine the master device that needs to forward the message according to the second connection mapping information and forward the message.
[0098] Optionally, the second connection identifier can be the connection identifier when the slave device sends a communication message to the master device.
[0099] As Figure 3 shown, after the above-mentioned second connection mapping information is established, the message forwarding method of the present application further includes:
[0100] S301: Receive the stealth communication message sent by the slave device, and parse the stealth communication message to obtain the second connection identifier and the quadruple after conversion.
[0101] Optionally, the stealth communication message can be a response of the firewall to the stealth communication request sent by the master device to the slave device in the above S204 step, or a stealth communication message actively sent by the slave device to the master device.
[0102] Optionally, the firewall can receive the stealth communication message sent by the slave device. When it is determined that the UDP protocol is used by parsing the data packet through the parsing module, that is, the communication message is a stealth communication message, the firewall can parse the data packet of the stealth communication message and obtain the second connection identifier and the quadruple after conversion of the stealth communication message.
[0103] It should be noted that the quadruple after conversion here is relative to the quadruple before conversion parsed from the data packet sent by the master device to the firewall. The quadruples carried in the communication messages between the master device and the firewall can all be the quadruples before conversion, and the quadruples carried in the communication messages between the firewall and the slave device can all be the quadruples after conversion. In this way, the unilateral transparency of the IP address in the message can be ensured, and the privacy of message communication can be improved.
[0104] S302: Determine the second value according to the parsed second connection identifier, the quadruple after conversion and the second connection mapping information, perform network address conversion on the stealth communication message according to the second value, and forward the converted stealth communication message to the master device.
[0105] Optionally, the firewall can search in the dynamic database saved in step S203 above according to the second connection identifier parsed from the implicit communication message and the transformed quadruple, first determine the second connection mapping information for the communication between the corresponding slave device and the master device, and determine the second value according to the second connection mapping information, that is, the source IP and destination IP in the quadruple before transformation, and the source port and destination port in the quadruple after transformation.
[0106] Optionally, after determining the second value, the firewall can perform network address translation on the transformed source IP and transformed destination IP in the implicit communication message according to the second value to obtain the source IP before transformation and the destination IP before transformation, and forward the transformed implicit communication message to the master device.
[0107] It should be noted that in explicit communication, since the data packet itself carries address information, during transformation, as in step S202 above, both the IP address and port in the quadruple can be transformed to ensure the privacy of message forwarding. In implicit communication, since the explicit communication has opened a channel, that is, the master device and the slave device have agreed on the communication port, and the message itself does not include address information, but only determines the object to be forwarded according to the connection identifier. Therefore, only the IP address can be transformed, and the port is not transformed, thereby improving the efficiency of message forwarding.
[0108] As Figure 4 shown, it is a flowchart of implicit communication of Ethernet / IP in a NAT environment given in this application. Next, in combination with Figure 4 , the message forwarding method of this application will be further described.
[0109] Referring to Figure 4 , in the figure, 401 is the step of opening the implicit communication channel through TCP explicit communication in steps S201 - S203 above. The explicit connection request sent by the master device to the slave device can include the IP address and port used by the master device in the agreed implicit communication. The explicit connection request can also include the first connection identifier and the second connection identifier for communication between the master device and the slave device. After receiving and parsing the explicit connection request, the firewall can transform the parsed quadruple, and store the quadruple before transformation, the quadruple after transformation, and the connection identifier as connection mapping information. After the firewall transforms the explicit connection request, it can forward the transformed explicit connection request to the slave device. After receiving the request, the slave device can record the agreed address and port in the request, and send a transformed explicit connection response to the master device to agree on the port used by the slave device in subsequent implicit communication. The firewall transforms this response and sends it to the master device. Thus, the establishment of the implicit communication channel is completed.
[0110] Continuing to refer to Figure 4, where step 402 in the figure shows the UDP implicit communication process between the master device and the slave device. After receiving the implicit communication request sent by the master device, the firewall can determine the slave device to which the request needs to be forwarded based on the connection mapping information stored during explicit communication, convert the request, obtain the converted implicit communication request, and forward it to the slave device. The slave device can send a corresponding response message according to the converted implicit communication request, or directly send the converted implicit communication message to the master device actively based on the established stealth channel, and the firewall will convert and forward this message according to the connection mapping information, thus completing the implicit communication.
[0111] The following is an explanation of the steps for performing network address translation on the pre-conversion quadruple according to the above target conversion strategy to obtain the post-conversion quadruple, as Figure 5 shown, the above step S202 includes:
[0112] S501: According to the master device conversion strategy, convert the source IP and source port in the pre-conversion quadruple to obtain the post-conversion source IP and the post-conversion source port.
[0113] Optionally, the master device conversion strategy can be, for example, destination network address translation. This strategy can convert the destination IP and destination port in the pre-conversion quadruple to obtain the post-conversion destination IP and the post-conversion destination port. Exemplarily, the destination IP can be the public network address assigned by the firewall to the slave device, and the post-conversion destination IP can be the private network address of the slave device, and a matching post-conversion destination port is assigned to the destination port.
[0114] S502: According to the slave device conversion strategy, convert the destination IP and destination port in the pre-conversion quadruple to obtain the post-conversion destination IP and the post-conversion destination port.
[0115] Optionally, the slave device conversion strategy can be, for example, source network address translation. This strategy can convert the source IP and source port in the pre-conversion quadruple to obtain the post-conversion source IP and the post-conversion source port. Exemplarily, the source IP can be the private address of the master device, and the post-conversion source IP can be the public network address assigned by the firewall to it, and a matching post-conversion source port is assigned to the source port.
[0116] S503: Combine the post-conversion source IP, the post-conversion source port, the post-conversion destination IP, and the post-conversion destination port into a post-conversion quadruple.
[0117] Optionally, the firewall can combine the post-conversion source IP, the post-conversion source port, the post-conversion destination IP, and the post-conversion destination port to obtain a post-conversion quadruple.
[0118] In the embodiment of the present application, the firewall performs network address translation on the quadruple before conversion according to the target conversion policy, which can avoid communication errors caused by unrecognized addresses and improve the reliability of communication.
[0119] Next, the steps of establishing the first connection mapping information are described as follows. Figure 6 As shown, step S203 includes:
[0120] S601: Receive the first connection identifier.
[0121] Optionally, the firewall can parse the first connection identifier from the explicit connection request sent by the master device and store it in the dynamic database.
[0122] S602: Combine the first connection identifier and the quadruple before conversion into the first key.
[0123] Optionally, the firewall can use the first connection identifier and the quadruple before conversion as the key in the key-value pair and store it in the dynamic database.
[0124] S603: Use the source IP and destination IP in the quadruple after conversion, and the source port and destination port in the quadruple before conversion as the first value.
[0125] Optionally, the firewall can use the source IP and destination IP in the quadruple after conversion, and the source port and destination port in the quadruple before conversion as the first value corresponding to the first key.
[0126] The following is the description of the steps of establishing the second connection mapping information. Figure 7 As shown, this step includes:
[0127] S701: Receive the second connection identifier.
[0128] Optionally, the firewall can parse the second connection identifier from the implicit communication message sent by the slave device and store it in the dynamic database.
[0129] S702: Combine the second connection identifier and the quadruple after conversion into the second key.
[0130] Optionally, the firewall can use the second connection identifier and the quadruple after conversion as the key in the key-value pair and store it in the dynamic database.
[0131] S703: Use the source IP and destination IP in the quadruple before conversion, and the source port and destination port in the quadruple after conversion as the second value.
[0132] Optionally, the firewall may use the source IP and destination IP in the quadruple before translation, as well as the source port and destination port in the quadruple after translation, as the first value corresponding to the first key.
[0133] In the embodiment of the present application, the firewall establishes connection mapping information between the master device and the slave device and saves the connection mapping information, so that the connection mapping information corresponding to the implicit communication message can be quickly determined during implicit communication, and accurate message forwarding can be performed according to the connection mapping information, thereby improving the efficiency and accuracy of message forwarding.
[0134] The step of performing network address translation on the implicit communication request according to the first value includes:
[0135] Perform network address translation on the transport layer data and network layer data in the implicit communication request according to the first value.
[0136] Optionally, the firewall may modify the source IP, destination IP, source port, and destination port in the transport layer and network layer data according to the quadruple after translation in the first value, recalculate the checksum of the IP header, and write it back to the check field of the IP header. When the peer receives the packet, it will use this value to check the IP header. If the check passes, the packet will be further parsed or read, otherwise the packet will be discarded.
[0137] Next, in combination with Figure 8 The message forwarding method of the present application will be further described.
[0138] As Figure 8 shown, when the firewall receives a communication message, it can first parse the protocol packet of the message to determine whether the message is an explicit message or an implicit message. If it is an explicit message, the firewall can first perform network address translation on its quadruple and determine whether the message is an action to establish an implicit channel. If so, the firewall can modify the IP address in the application layer data of the message, establish connection mapping information for it, and store the connection mapping information in the dynamic database. If not, it will be forwarded according to the processing method of the explicit message.
[0139] If the firewall receives an implicit message, it can match the corresponding connection mapping information in the dynamic database. If the match is successful, the message will be forwarded according to the connection mapping information. If the match fails, that is, there is no connection mapping message in the dynamic database corresponding to it, the firewall can consider it an illegal message and discard the message, so as to block illegal implicit communication. Before message forwarding, the firewall can also adaptively modify the data packet according to the result of network address translation, such as modifying the checksum of the IP header, and finally forward the data packet.
[0140] Based on the same inventive concept, an embodiment of the present application further provides a message forwarding apparatus corresponding to the message forwarding method. Since the principle of problem-solving of the apparatus in the embodiment of the present application is similar to that of the above-mentioned message forwarding method in the embodiment of the present application, the implementation of the apparatus can refer to the implementation of the method, and the repeated parts will not be elaborated.
[0141] Refer to Figure 9 As shown in the figure, it is a schematic diagram of a message forwarding apparatus provided by an embodiment of the present application. The apparatus includes: a receiving module 901, a conversion module 902, and a forwarding module 903, where:
[0142] The receiving module 901 is configured to: receive a dominant connection request sent by the master device to the slave device to be connected, and parse the dominant connection request to obtain a pre-conversion quadruple, where the pre-conversion quadruple includes: source IP, source port, destination IP, and destination port;
[0143] The conversion module 902 is configured to: perform network address conversion on the pre-conversion quadruple according to a target conversion policy to obtain a post-conversion quadruple, where the target conversion policy includes: a master device conversion policy and a slave device conversion policy;
[0144] The forwarding module 903 is configured to: establish first connection mapping information according to the pre-conversion quadruple and the post-conversion quadruple, send a post-conversion dominant connection request including the post-conversion quadruple to the slave device, and send a dominant connection response to the master device after receiving the post-conversion dominant connection response returned by the slave device. The first connection mapping information includes: a first key and a first value. The first key includes: a first connection identifier and the pre-conversion quadruple. The first value includes: the source IP and destination IP in the post-conversion quadruple, and the source port and destination port in the pre-conversion quadruple;
[0145] The receiving module 901 is further configured to: receive a recessive communication request sent by the master device to the slave device, and parse the recessive communication request to obtain a first connection identifier and a pre-conversion quadruple;
[0146] The conversion module 902 is further configured to: determine the first value according to the parsed first connection identifier, pre-conversion quadruple, and first connection mapping information, perform network address conversion on the recessive communication request according to the first value, and forward the converted recessive communication request to the slave device. Optionally, the conversion module is further configured to:
[0147] Convert the source IP and source port in the pre-conversion quadruple according to the master device conversion policy to obtain a post-conversion source IP and a post-conversion source port;
[0148] Convert the destination IP and destination port in the pre-conversion quadruple according to the slave device conversion policy to obtain a post-conversion destination IP and a post-conversion destination port;
[0149] Combine the translated source IP, translated source port, translated destination IP, and translated destination port into a translated quadruple.
[0150] Optionally, the forwarding module 903 is further configured to:
[0151] Receive a first connection identifier;
[0152] Combine the first connection identifier and the quadruple before translation into a first key;
[0153] Use the source IP and destination IP in the translated quadruple, and the source port and destination port in the quadruple before translation as a first value.
[0154] Optionally, the forwarding module 903 is further configured to:
[0155] Receive a second connection identifier;
[0156] Combine the second connection identifier and the translated quadruple into a second key;
[0157] Use the source IP and destination IP in the quadruple before translation, and the source port and destination port in the translated quadruple as a second value.
[0158] Optionally, the conversion module 902 is further configured to:
[0159] Perform network address translation on the transport layer data and network layer data in the implicit communication request according to the first value.
[0160] Optionally, the device may further include an establishment module and a parsing module, where:
[0161] The establishment module is specifically configured to: establish second connection mapping information according to the quadruple before translation and the translated quadruple. The second connection mapping information includes: a second key and a second value. The second key includes: a second connection identifier and the translated quadruple. The second value includes: the quadruple before translation.
[0162] The parsing module is specifically configured to:
[0163] Receive an implicit communication message sent by a slave device, and parse the implicit communication message to obtain a second connection identifier and a translated quadruple;
[0164] Determine a second value according to the parsed second connection identifier, translated quadruple, and second connection mapping information, perform network address translation on the implicit communication message according to the second value, and forward the translated implicit communication message to the master device.
[0165] For the description of the processing flow of each module in the device and the interaction flow between modules, reference may be made to the relevant descriptions in the above method embodiments, which will not be elaborated here.
[0166] In the embodiment of the present application, the firewall receives the explicit connection request sent by the master device to the slave device, performs network address translation on the explicit connection request, establishes connection mapping information, and when receiving the implicit communication between the master device and the slave device, performs network address translation on the implicit communication request according to the connection mapping information, and then forwards the translated implicit communication request, so that the implicit communication between the master device and the slave device can open a communication channel through the explicit communication, and an arbitrary port is pre-agreed to realize the sending and receiving of implicit communication messages at the agreed port, thereby adapting to the communication scenario of dynamic ports, and only forwarding the implicit communication messages for which the connection mapping information is saved in the firewall, improving the reliability and efficiency of the implicit communication.
[0167] The embodiment of the present application also provides an electronic device, as Figure 10 shown, which is a schematic structural diagram of the electronic device provided by the embodiment of the present application, including: a processor 1001, a memory 1002, and a bus. The memory 1002 stores machine-readable instructions executable by the processor 1001 (for example, Figure 8 the execution instructions corresponding to the receiving module, the conversion module, and the forwarding module in the device in ), when the computer device runs, the processor 1001 communicates with the memory 1002 through the bus, and when the machine-readable instructions are executed by the processor 1001, the processing of the above message forwarding method is executed.
[0168] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is run by a processor, the steps of the above message forwarding method are executed.
[0169] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the method embodiments, which will not be repeated in the present application. In the several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces, and the indirect coupling or communication connection of the devices or modules may be in an electrical, mechanical or other form.
[0170] In addition, each functional unit in various embodiments of the present application may be integrated into one processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit. If the function is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0171] The above are only specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application.
Claims
1. A message forwarding method, characterized in that, Applied to a firewall, the method includes: Receiving an explicit connection request sent by a master device to a slave device to be connected, and parsing the explicit connection request to obtain a pre-conversion quadruple, the pre-conversion quadruple including: source IP, source port, destination IP, and destination port, the explicit connection request including configuration information for opening an implicit communication channel, the configuration information including ports to be used by the agreed master device and slave device in subsequent communications; Performing network address translation on the pre-conversion quadruple according to a target translation policy, the target translation policy including: a master device translation policy, a slave device translation policy; Establishing first connection mapping information according to the pre-conversion quadruple and the post-conversion quadruple, sending a post-conversion explicit connection request including the post-conversion quadruple to the slave device, and sending an explicit connection response to the master device after receiving a post-conversion explicit connection response returned by the slave device, wherein the first connection mapping information includes: a first key and a first value, the first key including: a first connection identifier and the pre-conversion quadruple, the first value including: the source IP and destination IP in the post-conversion quadruple, and the source port and destination port in the pre-conversion quadruple; Receiving an implicit communication request sent by the master device to the slave device, and parsing the implicit communication request to obtain the first connection identifier and the pre-conversion quadruple; Determining the first value according to the parsed first connection identifier, the pre-conversion quadruple, and the first connection mapping information, performing network address translation on the implicit communication request according to the first value, and forwarding the translated implicit communication request to the slave device.
2. The method according to claim 1, wherein After performing network address translation on the pre-conversion quadruple according to the target translation policy to obtain a post-conversion quadruple, it further includes: Establishing second connection mapping information according to the pre-conversion quadruple and the post-conversion quadruple, the second connection mapping information including: a second key and a second value, the second key including: a second connection identifier and the post-conversion quadruple, the second value including: the pre-conversion quadruple.
3. The method according to claim 2, wherein The method further includes: Receiving an implicit communication message sent by the slave device, and parsing the implicit communication message to obtain the second connection identifier and the post-conversion quadruple; Determining the second value according to the parsed second connection identifier, the post-conversion quadruple, and the second connection mapping information, performing network address translation on the implicit communication message according to the second value, and forwarding the translated implicit communication message to the master device.
4. The method according to claim 1, wherein The performing network address translation on the pre-conversion quadruple according to the target translation policy to obtain a post-conversion quadruple includes: Converting the source IP and source port in the pre-conversion quadruple according to the master device translation policy to obtain a post-conversion source IP and a post-conversion source port; Converting the destination IP and destination port in the pre-conversion quadruple according to the slave device translation policy to obtain a post-conversion destination IP and a post-conversion destination port; Combine the converted source IP, converted source port, converted destination IP, and converted destination port into the converted quadruple.
5. The method according to claim 1, wherein Establish first connection mapping information according to the pre-conversion quadruple and the converted quadruple, including: Receive a first connection identifier; Combine the first connection identifier and the pre-conversion quadruple into the first key; Use the source IP and destination IP in the converted quadruple, and the source port and destination port in the pre-conversion quadruple as the first value.
6. The method according to claim 2, wherein Establish second connection mapping information according to the pre-conversion quadruple and the converted quadruple, including: Receive a second connection identifier; Combine the second connection identifier and the converted quadruple into the second key; Use the source IP and destination IP in the pre-conversion quadruple, and the source port and destination port in the converted quadruple as the second value.
7. The method according to any one of claims 1-6, characterized in that, Perform network address translation on the implicit communication request according to the first value, including: According to the first value, perform network address translation on the transport layer data and network layer data in the implicit communication request.
8. A message forwarding device, characterized in that, Applied to a firewall, the device includes: A receiving module, configured to: receive an explicit connection request sent by a master device to a slave device to be connected, and parse the explicit connection request to obtain a pre-conversion quadruple, where the pre-conversion quadruple includes: source IP, source port, destination IP, and destination port, and the explicit connection request includes configuration information for opening an implicit communication channel, and the configuration information includes ports agreed to be used by the master device and the slave device in subsequent communications; A conversion module, configured to: perform network address translation on the pre-conversion quadruple according to a target conversion strategy to obtain a converted quadruple, where the target conversion strategy includes: a master device conversion strategy, a slave device conversion strategy; A forwarding module, configured to: establish first connection mapping information according to the pre-conversion quadruple and the converted quadruple, send a converted explicit connection request including the converted quadruple to the slave device, and after receiving a converted explicit connection response returned by the slave device, send an explicit connection response including a first connection identifier to the master device, where the first connection mapping information includes: a first key and a first value, the first key includes: a first connection identifier and the pre-conversion quadruple, and the first value includes: the source IP and destination IP in the converted quadruple, and the source port and destination port in the pre-conversion quadruple; The receiving module is further configured to: receive an implicit communication request sent by the master device to the slave device, and parse the implicit communication request to obtain the first connection identifier and the pre-conversion quadruple; The conversion module is further configured to: determine the first value according to the parsed first connection identifier, the pre-conversion quadruple, and the first connection mapping information, perform network address translation on the implicit communication request according to the first value, and forward the converted implicit communication request to the slave device.
9. An electronic device, characterized in that, Including: A processor, a storage medium, and a bus, wherein the storage medium stores program instructions executable by the processor. When the electronic device is running, the processor communicates with the storage medium via the bus, and the processor executes the program instructions to perform the steps of the message forwarding method according to any one of claims 1 to 7 when executed.
10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by the processor, it performs the steps of the message forwarding method according to any one of claims 1 to 7.
Citation Information
Patent Citations
AP device, network address conversion method and communication system
CN106713524A
NAT (Network Address Translation) method and device, network security equipment and storage medium
CN110855810A