A method, apparatus, electronic device, and storage medium for offloading encrypted messages
By building a configuration linked list and a general private key linked list, and automatically matching the private key after the server IP or port has been changed, the problems of cumbersome and error-prone private key configuration in the existing technology are solved, and efficient offloading and security detection of encrypted packets are realized.
Patent Information
- Application Number
- CN202211505415.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-11-28
AI Technical Summary
When existing network security devices change their server IP or port, they need to reconfigure their private keys, resulting in cumbersome configuration and error-prone, affecting the security detection of encrypted traffic.
By building a configuration linked list, the linked list is configured and updated according to the daemon process, a general private key linked list is obtained, and then a structure is constructed based on the server port information, and the master key is obtained for uninstalling encrypted packets.
The detection process of encrypted packets is simplified, the security during the uninstallation of encrypted packets is improved, the efficiency of querying private keys is improved, and the cumbersome process of frequently changing private keys is avoided, which is not prone to errors.
Smart Images

Figure CN115801278B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technologies, and more particularly, to a method, apparatus, electronic device, and computer storage medium for offloading encrypted packets. Background Art
[0002] With the development of information technology, it is extremely easy to steal and tamper with the content of data packets when transmitting data in plain text in the network. Therefore, the application of encrypted packets is becoming more and more widespread. Encryption based on SSL / TLS ensures the confidentiality, reliability, and integrity of communication. However, the subsequent problem is that malicious traffic uses SSL / TLS to hide in encrypted traffic, making detection difficult. This poses a challenge to network security. Therefore, an offloading function for encrypted packets is required to solve the problem of security detection of encrypted traffic. To implement the offloading of encrypted packets by a network security device, it is necessary to save the private key provided by the server. To improve the query efficiency of the server private key, currently, it is stored in a hash table based on the server IP + server port. This method has high query efficiency. However, when the server IP or port is changed, the corresponding private key cannot be found, and the private key needs to be reconfigured. When the server IP or port is changed frequently and there are many private keys, configuring the private key on the network security device faces the problems of being cumbersome and error-prone. Summary of the Invention
[0003] The purpose of the embodiments of the present application is to provide a method, apparatus, electronic device, and storage medium for offloading encrypted packets, which can simplify the detection process of encrypted packets, improve the security during the offloading process of encrypted packets, improve the query efficiency of private keys, avoid the cumbersome process of frequently changing and reconfiguring private keys, and is not prone to errors.
[0004] In a first aspect, an embodiment of the present application provides a method for offloading encrypted packets, the method including:
[0005] Construct a configuration linked list;
[0006] Update the configuration of the configuration linked list according to a daemon process to obtain a general private key linked list;
[0007] Construct a structure according to the port information of the server;
[0008] Obtain a master key according to the general private key linked list and the structure;
[0009] Offload the encrypted packet according to the master key.
[0010] In the above implementation process, after updating the configuration linked list, a general private key linked list is obtained, and then the master key is obtained according to the general private key linked list, so that the encrypted message can be unloaded according to the master key, which can simplify the detection process of the encrypted message, improve the security during the encrypted message unloading process, improve the query efficiency of the private key, avoid the cumbersome process of frequently changing the private key and reconfiguring the private key, and is not prone to errors.
[0011] Further, the step of constructing the configuration linked list includes:
[0012] Obtain a general private key file and private key description information;
[0013] Add the general private key file and the private key description information to the linked list to obtain the configuration linked list.
[0014] In the above implementation process, adding the private key file and the private key description to the linked list to obtain the configuration linked list does not require specifying the server IP and port number, simplifies the configuration process, and facilitates the configuration update of the configuration linked list.
[0015] Further, the step of updating the configuration linked list according to the daemon process to obtain a general private key linked list includes:
[0016] Create the daemon process;
[0017] Judge whether the polling task list in the daemon process is updated;
[0018] If so, use the pre-registered hook function to update the configuration linked list to obtain the general private key linked list.
[0019] In the above implementation process, updating the configuration linked list according to the daemon process ensures data security, can achieve a secure update of the configuration linked list, shorten the update time, and ensure the validity of the general private key linked list.
[0020] Further, the step of using the pre-registered hook function to update the configuration linked list to obtain the general private key linked list includes:
[0021] Release the original general private key linked list and then traverse the configuration linked list;
[0022] Use the hook function to update the traversed configuration linked list to obtain the general private key linked list.
[0023] In the above implementation process, switch the currently used configuration linked list to the original general private key linked list to ensure that the currently used configuration linked list will not be immediately released, but will be released during the next configuration update, avoiding problems caused by releasing the configuration linked list being accessed.
[0024] Further, the step of obtaining the master key according to the general private key linked list and the structure includes:
[0025] Obtain a hash table according to the structure;
[0026] Obtain a specified private key linked list;
[0027] Query for the target private key in the specified private key linked list according to the hash table;
[0028] Determine whether the query is successful;
[0029] If not, obtain the master key according to the general private key linked list and the hash table.
[0030] In the above implementation process, querying the specified private key linked list according to the hash table to query the target private key enables the target private key to be quickly identified, shortens the query time, balances the efficient query and general matching of the target private key, and simplifies the operation process.
[0031] Further, the step of obtaining the master key according to the general private key linked list and the hash table includes:
[0032] Query for the target private key in the general private key linked list according to the hash table;
[0033] Determine whether the query is successful;
[0034] If so, traverse the general private key linked list to obtain a preliminary master key;
[0035] Obtain the master key according to the preliminary master key.
[0036] In the above implementation process, querying the general private key linked list according to the hash table to query the target private key ensures that the target private key can also be quickly identified when it does not exist in the specified private key linked list, improves the query efficiency of the target private key, and ensures the security during the uninstallation process.
[0037] Further, the step of traversing the general private key linked list to obtain a preliminary master key includes:
[0038] Traverse the general private key linked list;
[0039] Determine whether the target private key exists in the general private key linked list;
[0040] If so, obtain a preliminary master key according to the general private key linked list;
[0041] If not, traverse the general private key linked list again.
[0042] In the above implementation process, the preliminary master key is obtained after traversing the general private key linked list, which improves the subsequent offloading efficiency of the encrypted message and ensures the accuracy and security of offloading.
[0043] In a second aspect, an embodiment of the present application further provides an offloading device for encrypted messages, where the device includes:
[0044] A construction module, configured to construct a configuration linked list; and further configured to construct a structure according to the port information of the server;
[0045] An update module, configured to perform configuration update on the configuration linked list according to the daemon process to obtain a general private key linked list;
[0046] A data acquisition module, configured to obtain a master key according to the general private key linked list and the structure;
[0047] An offloading module, configured to offload the encrypted message according to the master key.
[0048] In the above implementation process, after performing configuration update on the configuration linked list to obtain a general private key linked list, and then obtaining a master key according to the general private key linked list, so as to offload the encrypted message according to the master key, which can simplify the detection process of the encrypted message, improve the security during the offloading process of the encrypted message, improve the query efficiency of the private key, avoid the cumbersome process of frequently changing the private key and reconfiguring the private key, and is not prone to errors.
[0049] In a third aspect, an electronic device provided by an embodiment of the present application includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, where when the processor executes the computer program, the steps of the method described in any item of the first aspect are implemented.
[0050] In a fourth aspect, a computer-readable storage medium provided by an embodiment of the present application has instructions stored thereon, and when the instructions are run on a computer, the computer is made to execute the method described in any item of the first aspect.
[0051] In a fifth aspect, a computer program product provided by an embodiment of the present application, when run on a computer, causes the computer to execute the method described in any item of the first aspect.
[0052] Other features and advantages of the present disclosure will be described in the subsequent specification, or, some features and advantages can be inferred from the specification without doubt, or can be known by implementing the above technologies of the present disclosure.
[0053] And it can be implemented according to the content of the specification. The following will be described in detail with reference to the preferred embodiments of the present application and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and thus should not be regarded as limiting the scope value. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0055] Figure 1 It is a schematic flowchart of the method for offloading encrypted packets provided by the embodiments of the present application;
[0056] Figure 2 It is a schematic diagram of the query process of the target private key provided by the embodiments of the present application;
[0057] Figure 3 It is a schematic diagram of the structural composition of the device for offloading encrypted packets provided by the embodiments of the present application;
[0058] Figure 4 It is a schematic diagram of the structural composition of the electronic device provided by the embodiments of the present application. Specific Embodiments
[0059] The following will describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application.
[0060] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0061] The following will further describe the specific embodiments of the present application in detail in conjunction with the drawings and embodiments. The following embodiments are used to illustrate the present application, but are not used to limit the scope value of the present application.
[0062] Embodiment 1
[0063] Figure 1 It is a schematic flowchart of the method for offloading encrypted packets provided by the embodiments of the present application. As Figure 1 shown, the method includes:
[0064] S1. Construct a configuration linked list;
[0065] S2. Update the configuration of the configuration linked list according to the daemon process to obtain a general private key linked list;
[0066] S3. Construct a structure according to the port information of the server;
[0067] S4. Obtain the master key according to the general private key linked list and the structure.
[0068] S5. Unload the encrypted message according to the master key.
[0069] In the above implementation process, after the configuration linked list is updated, the general private key linked list is obtained, and then the master key is obtained according to the general private key linked list, so as to unload the encrypted message according to the master key. This can simplify the detection process of the encrypted message, improve the security during the unloading process of the encrypted message, improve the query efficiency of the private key, avoid the cumbersome process of frequently changing the private key and reconfiguring the private key, and is not prone to errors.
[0070] The technical solution provided by the embodiment of the present application aims at the problem of cumbersome and error-prone configuration caused by frequent changes of the server IP or port and numerous private keys. By creating a general private key, it can be automatically matched after the server IP or port is changed, and the SSL unloading work can be completed without reconfiguration, achieving the goal of simplifying the configuration work of the configuration personnel.
[0071] Outside the specified private key linked list and hash table, a general private key linked list is established, and the configured general private keys are saved on this linked list. After the query of the specified private key linked list fails, the general private key linked list is traversed until the master key is successfully calculated to implement SSL unloading.
[0072] Further, S1 includes:
[0073] Obtain the general private key file and the private key description information;
[0074] Add the general private key file and the private key description information to the linked list to obtain the configuration linked list.
[0075] In the above implementation process, adding the private key file and the private key description to the linked list to obtain the configuration linked list does not require specifying the server IP and port number, simplifies the configuration process, and is convenient for updating the configuration of the configuration linked list.
[0076] Import the general private key file through the configuration command. It is not necessary to specify the server IP and port number. Only the general private key file and the private key description information need to be imported, and the server private key information and the private key description information are saved in the linked list.
[0077] Further, S2 includes:
[0078] Create a daemon process;
[0079] Judge whether the polling task list in the daemon process is updated;
[0080] If so, update the configuration of the configuration linked list through the pre-registered hook function to obtain the general private key linked list.
[0081] In the above implementation process, the configuration list is configured and updated according to the daemon process, which ensures the security of data, enables the secure update of the configuration list, shortens the update time, and ensures the validity of the general private key list.
[0082] In the embodiment of the present application, the daemon process is notified to perform configuration update by updating the task list shared with the SSL task process. Specifically, in order to ensure the security of shared data, a daemon process needs to be created to perform secure configuration update:
[0083] When the SSL module is initialized, an SSL task process is created as the daemon process. It is judged whether the polling task list in the daemon process is updated. If an update is detected, a pre-registered hook function is called to execute the task of configuration update.
[0084] Further, the steps of performing configuration update on the configuration list by the generally pre-registered hook function to obtain the general private key list include:
[0085] After releasing the original general private key list, traverse the configuration list;
[0086] Perform configuration update on the traversed configuration list through the hook function to obtain the general private key list.
[0087] In the above implementation process, the currently used configuration list is switched to the original general private key list, which ensures that the configuration list that is already in use will not be immediately released, but will be released during the next configuration update, avoiding problems caused by releasing the configuration list that is being accessed.
[0088] Release the old general private key list of the previous round, that is, release the original general private key list, traverse the information in the configuration list, and create a new general private key list. The embodiment of the present application can avoid the coredump problem caused by releasing the general private key that is being accessed.
[0089] Use the new general private key list for the SSL uninstallation process. After the configuration of the general private key list is completed, the general private key list is successfully created and safely enters the access and use process.
[0090] Further, S4 includes:
[0091] Obtain the hash table according to the structure;
[0092] Obtain the specified private key list;
[0093] Query the target private key in the specified private key list according to the hash table;
[0094] Judge whether the query is successful;
[0095] If not, obtain the master key according to the general private key list and the hash table.
[0096] In the above implementation process, the target private key is queried according to the hash table in the specified private key linked list, so that the target private key can be quickly identified, the query time is shortened, the efficient query and general matching of the target private key are taken into account, and the operation process is simplified.
[0097] Further, the steps of obtaining the master key according to the general private key linked list and the hash table include:
[0098] Query the target private key in the general private key linked list according to the hash table;
[0099] Judge whether the query is successful;
[0100] If so, traverse the general private key linked list to obtain the preliminary master key;
[0101] Obtain the master key according to the preliminary master key.
[0102] In the above implementation process, the target private key is queried according to the hash table in the general private key linked list, ensuring that the target private key can also be quickly identified when it does not exist in the specified private key linked list, improving the query efficiency of the target private key and ensuring the security during the uninstallation process.
[0103] Further, the steps of traversing the general private key linked list to obtain the preliminary master key include:
[0104] Traverse the general private key linked list;
[0105] Judge whether the target private key exists in the general private key linked list;
[0106] If so, obtain the preliminary master key according to the general private key linked list;
[0107] If not, traverse the general private key linked list again.
[0108] In the above implementation process, the preliminary master key is obtained after traversing the general private key linked list, improving the subsequent uninstallation efficiency of the encrypted message and ensuring the accuracy and security of the uninstallation.
[0109] Extract the server IP and port information and save them to a structure. Based on the information stored in this structure and the structure length, a hash table is calculated. Use this hash table to query the target private key in the specified private key linked list. If the query is successful, use the specified private key linked list to perform the SSL uninstallation process.
[0110] If the query fails, judge whether there is a general private key linked list. If it exists, traverse the general private key linked list and calculate the preliminary master key until the calculation is successful or the traversal ends. After the calculation of the preliminary master key is successful, calculate the master key and use the master key to uninstall the encrypted message. The process of querying the target private key is as Figure 2 shown.
[0111] When changing the server IP or port in the embodiments of the present application, it is not necessary to reconfigure all the affected private keys. Through the established general private key linked list, the corresponding target private key is matched to perform the master key calculation and the offloading of the encrypted message.
[0112] In the embodiments of the present application, a specified private key linked list and a general private key linked list are respectively established. When the server IP or port changes, it is not necessary to reconfigure the affected target private keys one by one. When performing SSL offloading on the encrypted message, first query the specified private key linked list according to the IP + port. If the query fails, then traverse the general linked list to perform SSL offloading. It takes into account the efficient query and general matching of private keys, and simplifies the configuration operation.
[0113] Embodiment 2
[0114] In order to execute the method corresponding to Embodiment 1 above to achieve the corresponding functions and technical effects, the following provides a device for offloading encrypted messages, as Figure 3 shown. The device includes:
[0115] A construction module 1, configured to construct a configuration linked list; and also configured to construct a structure according to the port information of the server;
[0116] An update module 2, configured to perform configuration update on the configuration linked list according to the daemon process to obtain a general private key linked list;
[0117] A data acquisition module 3, configured to obtain a master key according to the general private key linked list and the structure;
[0118] An offloading module 4, configured to offload the encrypted message according to the master key.
[0119] In the above implementation process, after performing configuration update on the configuration linked list to obtain a general private key linked list, and then obtaining the master key according to the general private key linked list, so as to offload the encrypted message according to the master key, which can simplify the detection process of the encrypted message, improve the security during the offloading process of the encrypted message, improve the query efficiency of the private key, avoid the cumbersome process of frequently changing and reconfiguring the private key, and is not prone to errors.
[0120] Further, the construction module 1 is further configured to:
[0121] Obtain a general private key file and private key description information;
[0122] Add the general private key file and the private key description information to the linked list to obtain a configuration linked list.
[0123] In the above implementation process, adding the private key file and the private key description to the linked list to obtain a configuration linked list does not require specifying the server IP and port number, simplifies the configuration process, and is convenient for performing configuration update on the configuration linked list.
[0124] Further, the update module 2 is also used for:
[0125] Create a daemon process;
[0126] Determine whether the polling task list in the daemon process is updated;
[0127] If so, the commonly pre-registered hook function updates the configuration linked list to obtain the common private key linked list.
[0128] In the above implementation process, updating the configuration linked list according to the daemon process ensures data security, enables secure updating of the configuration linked list, shortens the update time, and ensures the validity of the common private key linked list.
[0129] Further, the update module 2 is also used for:
[0130] Release the original common private key linked list and then traverse the configuration linked list;
[0131] Update the traversed configuration linked list through the hook function to obtain the common private key linked list.
[0132] In the above implementation process, switching the currently used configuration linked list to the original common private key linked list ensures that the currently used configuration linked list will not be immediately released, but will be released during the next configuration update, avoiding problems caused by releasing the configuration linked list being accessed.
[0133] Further, the data acquisition module 3 is also used for:
[0134] Obtain a hash table according to the structure;
[0135] Obtain the specified private key linked list;
[0136] Query the target private key in the specified private key linked list according to the hash table;
[0137] Determine whether the query is successful;
[0138] If not, obtain the master key according to the common private key linked list and the hash table.
[0139] In the above implementation process, querying the target private key in the specified private key linked list according to the hash table enables the target private key to be quickly identified, shortens the query time, balances the efficient query of the target private key and general matching, and simplifies the operation process.
[0140] Further, the data acquisition module 3 is also used for:
[0141] Query the target private key in the common private key linked list according to the hash table;
[0142] Determine whether the query is successful;
[0143] If so, traverse the general private key linked list to obtain a preliminary master key;
[0144] Obtain the master key according to the preliminary master key.
[0145] In the above implementation process, query the general private key linked list according to the hash table to query the target private key, ensuring that the target private key can be quickly identified even when it does not exist in the specified private key linked list, improving the query efficiency of the target private key and ensuring the security during the offloading process.
[0146] Furthermore, the data acquisition module 3 is further configured to:
[0147] Traverse the general private key linked list;
[0148] Determine whether the target private key exists in the general private key linked list;
[0149] If so, obtain the preliminary master key according to the general private key linked list;
[0150] If not, traverse the general private key linked list again.
[0151] In the above implementation process, obtaining the preliminary master key after traversing the general private key linked list improves the subsequent offloading efficiency of the encrypted message and ensures the accuracy and security of the offloading.
[0152] The above-mentioned offloading device for encrypted messages can implement the method of Embodiment 1. The optional items in Embodiment 1 also apply to this embodiment and will not be elaborated here.
[0153] The remaining content of the embodiments of the present application can refer to the content of Embodiment 1 and will not be repeated in this embodiment.
[0154] Embodiment 3
[0155] The embodiment of the present application provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the offloading method for encrypted messages in Embodiment 1.
[0156] Optionally, the above-mentioned electronic device may be a server.
[0157] Please refer to Figure 4 , Figure 4 , which is a schematic structural composition diagram of the electronic device provided by the embodiment of the present application. The electronic device may include a processor 41, a communication interface 42, a memory 43, and at least one communication bus 44. Among them, the communication bus 44 is used to realize the direct connection and communication of these components. Among them, the communication interface 42 of the device in the embodiment of the present application is used to communicate with other node devices in terms of signaling or data. The processor 41 may be an integrated circuit chip with signal processing capabilities.
[0158] The above-mentioned processor 41 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor 41 may also be any conventional processor, etc.
[0159] The memory 43 may be, but is not limited to, a Random Access Memory (RAM), a Read Only Memory (ROM), a Programmable Read-Only Memory (PROM), an Erasable Programmable Read-Only Memory (EPROM), an Electric Erasable Programmable Read-Only Memory (EEPROM), etc. Computer-readable instructions are stored in the memory 43. When the computer-readable instructions are executed by the processor 41, the device can execute the Figure 1 various steps involved in the method embodiments.
[0160] Optionally, the electronic device may further include a storage controller and an input / output unit. The memory 43, the storage controller, the processor 41, the peripheral interface, and the input / output unit are electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components may be electrically connected to each other through one or more communication buses 44. The processor 41 is used to execute the executable modules stored in the memory 43, such as software function modules or computer programs included in the device.
[0161] The input / output unit is used to provide the user with the creation of tasks and the creation of a start optional period or a preset execution time for the task to achieve the interaction between the user and the server. The input / output unit may be, but is not limited to, a mouse and a keyboard, etc.
[0162] It can be understood that Figure 4 the structure shown is only schematic, and the electronic device may further include more or fewer components than those Figure 4 shown, or have a different configuration from that Figure 4 shown. Figure 4Each component shown in the figure may be implemented by hardware, software, or a combination thereof.
[0163] In addition, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the method for offloading encrypted messages in the first embodiment.
[0164] The embodiment of the present application further provides a computer program product, which when running on a computer causes the computer to execute the method described in the method embodiment.
[0165] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods may also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based device for performing the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.
[0166] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0167] If the function is implemented in the form of a software functional module and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0168] The above are only embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0169] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0170] It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
Claims
1. A method for offloading encrypted packets, characterized in that, the method includes: Construct a configuration linked list; Update the configuration of the configuration linked list according to the daemon process to obtain a general private key linked list; Construct a structure according to the port information of the server; Obtain the master key according to the general private key linked list and the structure; Offload the encrypted packet according to the master key.
2. The method for offloading encrypted packets according to claim 1, characterized in that, the step of constructing the configuration linked list includes: Obtain the general private key file and the private key description information; Add the general private key file and the private key description information to the linked list to obtain the configuration linked list.
3. The method for offloading encrypted packets according to claim 1, characterized in that, the step of updating the configuration of the configuration linked list according to the daemon process to obtain a general private key linked list includes: Create the daemon process; Judge whether the polling task list in the daemon process is updated; If so, update the configuration of the configuration linked list with the pre-registered hook function to obtain the general private key linked list.
4. The method for offloading encrypted packets according to claim 3, characterized in that, the step of updating the configuration of the configuration linked list with the pre-registered hook function to obtain a general private key linked list includes: Release the original general private key linked list and then traverse the configuration linked list; Update the configuration of the traversed configuration linked list with the hook function to obtain the general private key linked list.
5. The method for offloading encrypted packets according to claim 1, characterized in that, the step of obtaining the master key according to the general private key linked list and the structure includes: Obtain a hash table according to the structure; Obtain the specified private key linked list; Query the target private key in the specified private key linked list according to the hash table; Judge whether the query is successful; If not, obtain the master key according to the general private key linked list and the hash table.
6. The method for offloading encrypted packets according to claim 5, characterized in that, the step of obtaining the master key according to the general private key linked list and the hash table includes: Query the target private key in the general private key linked list according to the hash table; Judge whether the query is successful; If so, traverse the general private key linked list to obtain a preliminary master key; Obtain the master key according to the preliminary master key.
7. The method for offloading encrypted packets according to claim 6, characterized in that, the step of traversing the general private key linked list to obtain a preliminary master key includes: Traverse the general private key linked list; Judge whether the target private key exists in the general private key linked list; If so, obtain the preliminary master key according to the general private key linked list; If not, traverse the general private key linked list again.
8. An apparatus for offloading encrypted packets, characterized in that, the apparatus includes: A construction module, configured to construct a configuration linked list; and also configured to construct a structure according to the port information of the server; An update module, configured to update the configuration of the configuration linked list according to the daemon process to obtain a general private key linked list; A data acquisition module, configured to obtain the master key according to the general private key linked list and the structure; An unloading module, configured to unload the encrypted message according to the master key.
9. An electronic device, characterized in that it includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the method for unloading the encrypted message according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that it stores a computer program, and when the computer program is executed by a processor, it implements the method for unloading the encrypted message according to any one of claims 1 to 7.
Citation Information
Patent Citations
Key pair infrastructure for secure messaging
CN110050435A
Communication method and device, electronic equipment and storage medium
CN112511550A