A method, device, storage medium, and electronic device for source address translation
The method computes a conversion identifier for diverse IPv6 addresses, enabling flexible and efficient conversion, enhancing network security by supporting various address types and hiding internal network topology.
Patent Information
- Application Number
- CN202211689312.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-27
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-12-27
AI Technical Summary
The existing technology can only convert IPv6 subnet addresses, and requires that the address subnet prefixes before and after conversion are equal in length, and the versatility is poor, and it cannot adapt to IPv6 network management needs in different scenarios.
By calculating the source address to be converted, obtaining the conversion identification value, and finding the target conversion address from the address conversion array based on this value, it supports multiple types of source address conversion, including host address, subnet address, range address and address group, and flexibly dealing with cases of varying address counts.
It realizes efficient conversion of multiple types of source addresses, improves the universality and flexibility of conversion, can hide internal network topology, and improves network security.
Smart Images

Figure CN116055447B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology. Specifically, it relates to a method, device, storage medium, and electronic device for source address translation. Background Art
[0002] With the continuous expansion of the scale of network users, the use of IPv6 (Internet Protocol Version 6) is becoming more and more widespread. Since IPv6 effectively solves the problem of IP address shortage, the demand for the control and management of IPv6 networks is increasing.
[0003] Currently, in order to achieve the maintenance and management of IPv6 networks, generally, the address prefix in the IPv6 address is replaced, and the last 16 bits in the IPv6 address are modified to ensure that it can pass the verification, so as to achieve the translation of the IPv6 address. However, through research, it is found that the existing technology can only perform translations on IPv6 subnet addresses, and requires the subnet prefix lengths of the addresses before and after translation to be equal. This method has great limitations and poor generality.
[0004] Therefore, how to provide a technical solution for a source address translation method with high generality has become an urgent technical problem to be solved. Summary of the Invention
[0005] Some embodiments of this application aim to provide a method, device, storage medium, and electronic device for source address translation. Through the technical solutions of the embodiments of this application, it is possible to support the translation of various types of source addresses, with good generality and high translation efficiency, providing effective technical support for maintaining network security.
[0006] In a first aspect, some embodiments of this application provide a method for source address translation, including: obtaining a source address to be translated and an address translation array; calculating the conversion identification value for the source address to be translated; and based on the conversion identification value, searching for the target conversion address after translation of the source address to be translated in the address translation group.
[0007] Some embodiments of this application calculate the conversion identification value by calculating the source address to be translated, and then based on the conversion identification value, the target conversion address can be obtained in the address translation group. It is possible to support the translation of various types of source addresses, with good generality and high translation efficiency, providing effective technical support for maintaining network security.
[0008] In some embodiments, the types of the source address to be translated include: source host address, source subnet address, source range address, and source address group.
[0009] Some embodiments of the present application can support multiple types of source addresses to be converted, with high versatility.
[0010] In some embodiments, calculating the source address to be converted to obtain a conversion identification value includes: performing an equivalent calculation on the source address to be converted to obtain an equivalent address value of the source address to be converted; and obtaining the conversion identification value according to the equivalent address value and an adhesion parameter.
[0011] Some embodiments of the present application obtain a conversion identification value through the equivalent address value of the source address to be converted and an adhesion parameter, providing accurate data support for obtaining the target conversion address subsequently.
[0012] In some embodiments, obtaining the conversion identification value according to the equivalent address value and the adhesion parameter includes: if the adhesion parameter is in an enabled state, performing a calculation on the equivalent address value to obtain the conversion identification value.
[0013] Some embodiments of the present application calculate the conversion identification value by the state of the adhesion parameter for the equivalent address value, with simple and efficient calculation.
[0014] In some embodiments, obtaining the conversion identification value according to the equivalent address value and the adhesion parameter includes: if the adhesion parameter is in a disabled state, performing a calculation on the equivalent address value and a random parameter to obtain the conversion identification value.
[0015] Some embodiments of the present application calculate the conversion identification value by the state of the adhesion parameter for the equivalent address value and the random parameter, with simple and efficient calculation and high flexibility.
[0016] In some embodiments, finding the target conversion address after conversion of the source address to be converted from the address conversion group based on the conversion identification value includes: obtaining a pointer to the first address in the address conversion group; adding the pointer and the conversion identification value and then subtracting one to obtain an address subscript value; and using the address matching the address subscript value as the target conversion address.
[0017] Some embodiments of the present application calculate the address subscript value through the conversion identification value, and then obtain the target conversion address, which can achieve accurate and effective conversion of the source address to be converted, with good versatility and high efficiency.
[0018] In some embodiments, the method further includes: obtaining a source port and a port conversion parameter; and obtaining the target conversion port after conversion of the source port according to the port conversion parameter.
[0019] Some embodiments of the present application can achieve effective conversion of the source port by obtaining the source port and the port conversion parameter.
[0020] In some embodiments, obtaining the target conversion port after the source port is converted according to the port conversion parameter includes: if it is confirmed that the port parameter is in the first state, selecting the target conversion port and converting the source port into the target conversion port; if it is confirmed that the port parameter is in the second state, using the source port as the target conversion port; if it is confirmed that the port parameter is in the third state and the source port is not occupied, using the source port as the target conversion port; if it is confirmed that the port parameter is in the third state and the source port is occupied, selecting the target conversion port and converting the source port into the target conversion port.
[0021] In some embodiments of the present application, the state of the port parameter can be used to convert the source port in different ways, with relatively high flexibility and good applicability.
[0022] In a second aspect, some embodiments of the present application provide an apparatus for source address conversion, including: an acquisition module configured to acquire a source address to be converted and an address conversion array; a calculation module configured to calculate the source address to be converted to obtain a conversion identification value; a search module configured to search for the target conversion address after the source address to be converted from the address conversion group based on the conversion identification value.
[0023] In some embodiments, the types of the source address to be converted include: source host address, source subnet address, source range address, and source address group.
[0024] In some embodiments, the calculation module is configured to perform an equivalent calculation on the source address to be converted to obtain an equivalent address value of the source address to be converted; and obtain the conversion identification value according to the equivalent address value and the adhesion parameter.
[0025] In some embodiments, the calculation module is configured to, if the adhesion parameter is in an enabled state, calculate the equivalent address value to obtain the conversion identification value.
[0026] In some embodiments, the calculation module is configured to, if the adhesion parameter is in a disabled state, calculate the equivalent address value and a random parameter to obtain the conversion identification value.
[0027] In some embodiments, the search module is configured to obtain a pointer pointing to the first address in the address conversion group; add the pointer and the conversion identification value and then subtract one to obtain an address subscript value; and use the address matching the address subscript value as the target conversion address.
[0028] In some embodiments, an acquisition module is configured to acquire a source port and port conversion parameters; the source address conversion apparatus further includes: a conversion module configured to obtain a target conversion port after conversion of the source port according to the port conversion parameters.
[0029] In some embodiments, the conversion module is configured to, if it is confirmed that the port parameters are in a first state, select the target conversion port and convert the source port to the target conversion port; if it is confirmed that the port parameters are in a second state, use the source port as the target conversion port; if it is confirmed that the port parameters are in a third state and the source port is not occupied, use the source port as the target conversion port; if it is confirmed that the port parameters are in a third state and the source port is occupied, select the target conversion port and convert the source port to the target conversion port.
[0030] In a third aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, the method described in any embodiment of the first aspect can be implemented.
[0031] In a fourth aspect, some embodiments of the present application provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the method described in any embodiment of the first aspect can be implemented.
[0032] In a fifth aspect, some embodiments of the present application provide a computer program product, the computer program product including a computer program, wherein when the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented. Description of the Drawings
[0033] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the drawings required to be used in some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0034] Figure 1 A system diagram of source address conversion provided for some embodiments of the present application;
[0035] Figure 2 One of the method flowcharts of source address conversion provided for some embodiments of the present application;
[0036] Figure 3 Another method flowchart of source address conversion provided for some embodiments of the present application;
[0037] Figure 4 Block diagram of the source address translation device provided for some embodiments of the present application;
[0038] Figure 5 Schematic diagram of an electronic device provided for some embodiments of the present application. Detailed implementation manners
[0039] The following will describe the technical solutions in some embodiments of the present application with reference to the accompanying drawings in some embodiments of the present application.
[0040] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0041] In the related art, IPv6 is an effective solution to the problem of IP address shortage. With the continuous expansion of the scale of network users, the use of IPv6 is becoming more and more widespread, and thus the demand for the control and management of IPv6 networks is also increasing. NAT (Network Address Translation) technology not only alleviates the problem of IP address shortage, but also can hide and protect the computers inside the network, effectively avoiding attacks from outside the network. Through NAT technology and IPv6 addresses, the maintenance and management costs of IPv6 networks can be effectively reduced, and hacker attacks can be reduced. When the prior art converts IPv6 addresses, it converts the IPv6 addresses by replacing the address prefix in the IPv6 address and modifying the subsequent 16 bits to ensure that the checksum remains unchanged. Due to the limitations of this conversion algorithm, it only supports the conversion of IPv6 subnet addresses and requires the subnet prefix lengths before and after conversion to be equal. Another prior art determines the position of the converted address by looking up the offset in the address pool, and then performs a one-to-one IPv6 address conversion. This method requires the address pool sizes of the addresses before and after conversion to be equal. From the above related technologies, it can be seen that when the prior art converts addresses, first, the number of IPv6 addresses before and after conversion needs to be equal to ensure the feasibility of the algorithm. Second, neither of them supports the conversion of address groups. Therefore, the prior art is limited by the algorithm, greatly limiting the application scenarios. When there are fewer public network addresses and more private network addresses, the source NAT conversion of IPv6 addresses cannot be performed, and the versatility is poor.
[0042] In view of this, some embodiments of the present application provide a source address conversion method. This method calculates the conversion identification value by calculating the source address to be converted. Then, based on the conversion identification value, the target conversion address after the conversion of the source address to be converted can be found from the address conversion array. Some embodiments of the present application can implement the conversion of various types of source addresses. The number of addresses before and after conversion can be equal or unequal, and the applicable range is relatively wide. Moreover, through the conversion identification value of the source address, the user can clearly obtain the target conversion address after conversion or randomly obtain the target conversion address. Some embodiments of the present application support conversion diversity and can also hide the internal network topology, with relatively high security.
[0043] The following combines the appendix Figure 1 Exemplarily elaborate on the system composition structure of a source address conversion provided by some embodiments of the present application.
[0044] As Figure 1 shown, some embodiments of the present application provide a source address conversion system. The source address conversion system includes: a terminal 100 and a server 200. Among them, the terminal 100 is used to store the source IPv6 address to be converted (as a specific example of the source address to be converted). The server 200 can read or receive the source IPv6 address to be converted from the terminal 100. After that, the server 200 calculates the source IPv6 address to be converted to obtain the conversion identification value. Finally, the server 200 can obtain the target conversion address that matches the source IPv6 address to be converted from the address conversion array based on the conversion identification value. Through some embodiments of the present application, the source IPv6 address to be converted can be converted into the target conversion address.
[0045] In some embodiments of the present application, the type of the source IPv6 address to be converted can be a source IPv6 host address (as a specific example of the source host address), a source IPv6 subnet address (as a specific example of the source subnet address), a source IPv6 range address (as a specific example of the source range address), a source IPv6 address group (as a specific example of the source address group), and so on. As can be seen from the above, some embodiments of the present application can not only implement the conversion of a single source address, but also implement the conversion of a batch of source addresses, with relatively high efficiency and good versatility.
[0046] In some embodiments of the present application, the terminal 100 can be a mobile terminal or a non-portable computer terminal, and the present application does not make specific limitations here.
[0047] The following combines the appendix Figure 2 Exemplarily elaborate on the implementation process of the source address conversion method executed by the server 200 provided by some embodiments of the present application.
[0048] Please refer to the appendix Figure 2 ,Figure 2 A flowchart of a source address conversion method provided for some embodiments of the present application. The source address conversion method includes:
[0049] S210, obtain the source address to be converted and the address conversion array.
[0050] For example, in some embodiments of the present application, the server 200 obtains the user source IPv6 address src_ip_addr (as a specific example of the source address to be converted), the converted address object trans_addr, and the address quantity pool_size. All addresses in trans_addr are stored in an address conversion array. ip_addr is a pointer to the first address in the address conversion array, and pool_size is the number of addresses stored in the address conversion array. Among them, the address conversion array includes multiple converted addresses, and each converted address corresponds to a unique address subscript value.
[0051] In some embodiments of the present application, before S210, the source address conversion method further includes: detecting whether the type of the source address object to be converted is an IPv6 address type. If so, execute S210. Among them, the IPv6 address type includes source IPv6 host address type, source IPv6 subnet address type, source IPv6 range address type, or source IPv6 address group type.
[0052] S220, calculate the to-be-converted source address to obtain a conversion identification value.
[0053] For example, in some embodiments of the present application, the server 200 can calculate the user source IPv6 address src_ip_addr to obtain an address hash value corresponding to the user source IPv6 address src_ip_addr (as a specific example of the conversion identification value).
[0054] In some embodiments of the present application, S220 may include: performing an equivalent calculation on the to-be-converted source address to obtain an equivalent address value of the to-be-converted source address; obtaining the conversion identification value according to the equivalent address value and the adhesion parameter.
[0055] For example, in some embodiments of the present application, the server 200 calls the jhash2 function (the jhash2 function is a general hash function) to calculate the equivalent value key_addr of src_ip_addr (as a specific example of the equivalent address value). The specific calculation formula is as follows:
[0056] key_addr = jhash2(src_ip_addr, 4, 0)
[0057] Among them, 4 represents the length of src_ip_addr, and 0 represents the base value of the hash algorithm.
[0058] After that, an address hash value is further obtained based on the key_addr and the status of the sticky parameter.
[0059] In some embodiments of the present application, before executing S220, the source address conversion method may further include: detecting whether the sticky parameter is in an enabled state or a disabled state.
[0060] It should be noted that the sticky parameter can be used to confirm whether to always convert the user source IPv6 address to the same address. If the sticky parameter is in the enabled state, the address hash value obtained each time is the same by hashing the user source IPv6 address, so as to ensure that the converted IP address remains unchanged. If the sticky parameter is in the disabled state, a random variable (as a specific example of a random parameter) can be added, and a hash value is calculated for random location selection to obtain the address hash value.
[0061] In some embodiments of the present application, S220 may include: if the sticky parameter is in the enabled state, calculate the equivalence address value to obtain the conversion identification value.
[0062] For example, in some embodiments of the present application, when the sticky parameter is in the enabled state, the address hash value Hash is calculated through the obtained equivalent value key_addr, and the specific calculation formula is as follows:
[0063] Hash = jhash_1word(key_addr, 0) % pool_size.
[0064] In some embodiments of the present application, S220 may include: if the sticky parameter is in the disabled state, calculate the equivalence address value and the random parameter to obtain the conversion identification value.
[0065] For example, in some embodiments of the present application, when the sticky parameter is in the disabled state, the random variable random is used as an input parameter to calculate the address hash value Hash, and the specific calculation formula is as follows:
[0066] Hash = jhash_2word(key_addr, random, 0) % pool_size.
[0067] S230, based on the conversion identification value, find the target conversion address after conversion of the source address to be converted from the address conversion group.
[0068] For example, in some embodiments of the present application, the server 200 can find a matching converted address (as a specific example of the target conversion address) in the address conversion array based on the address hash value Hash.
[0069] In some embodiments of the present application, S230 may include: obtaining a pointer to the first address in the address conversion group; adding the pointer and the conversion identification value and then subtracting one to obtain an address subscript value; and using the address matching the address subscript value as the target conversion address.
[0070] For example, in some embodiments of the present application, obtain a pointer ip_addr to the starting address trans_ip in the trans_addr address conversion array. According to the address type of trans_addr (such as host address, subnet address, range address, or address group), combined with the obtained address hash value Hash, the converted address subscript value ip_trans_addr = ip_addr + Hash - 1 can be calculated. Finally, the converted address corresponding to the address subscript value is used as the conversion result of the user source IPv6 address src_ip_addr.
[0071] In some embodiments of the present application, S210 may include: obtaining a source port and port conversion parameters.
[0072] For example, in some embodiments of the present application, the server 200 can also perform conversion on the source port. For example, the server 200 can obtain the source port src_port, the protocol number protocol, and the pat parameter (as a specific example of the port conversion parameter).
[0073] In some embodiments of the present application, the method for source address conversion further includes: obtaining a target conversion port after conversion of the source port according to the port conversion parameter.
[0074] For example, in some embodiments of the present application, by detecting the status of the pat parameter, the conversion method for src_port can be determined to obtain the target conversion port.
[0075] In some embodiments of the present application, obtaining the target conversion port after converting the source port according to the port conversion parameter includes: if it is confirmed that the port parameter is in the first state, selecting the target conversion port and converting the source port to the target conversion port; if it is confirmed that the port parameter is in the second state, using the source port as the target conversion port; if it is confirmed that the port parameter is in the third state and the source port is not occupied, using the source port as the target conversion port; if it is confirmed that the port parameter is in the third state and the source port is occupied, selecting the target conversion port and converting the source port to the target conversion port.
[0076] For example, in some embodiments of the present application, the pat parameter has three states, yes (as a specific example of the first state), no (as a specific example of the second state), and try_orig_port (as a specific example of the third state). Yes means to force the conversion of the source port and randomly select an available port as the target conversion port. No means that the value of the source port does not need to be modified, that is, using the source port src_port as the target conversion port. Try_orig_port means to give priority to using the source port. If the source port is occupied, randomly select an available port as the target conversion port again. If the source port is not occupied, the source port src_port can be used as the target conversion port.
[0077] The following Figure 3 exemplarily elaborates on the specific implementation process of the source address conversion method provided by some embodiments of the present application.
[0078] Please refer to the Figure 3 , Figure 3 which is a flowchart of a source address conversion method provided by some embodiments of the present application.
[0079] The following exemplarily elaborates on the above process.
[0080] S310, obtain the source address to be converted and the address conversion array.
[0081] S320, perform an equivalent calculation on the source address to be converted to obtain the equivalent address value of the source address to be converted.
[0082] S330, determine whether the status of the adhesion parameter is enabled. If so, execute S340; otherwise, execute S350.
[0083] S340, perform a calculation on the equivalent address value to obtain the conversion identification value.
[0084] S350, perform a calculation on the equivalent address value and the random parameter to obtain the conversion identification value.
[0085] S360, obtain a pointer to the first address in the address translation group.
[0086] S370, add the pointer and the conversion identification value and then subtract one to obtain an address subscript value.
[0087] S380, use the address that matches the address subscript value as the target conversion address, and convert the source address to be converted into the target conversion address.
[0088] It should be understood that the implementation processes of S310 to S380 can refer to Figure 2 the method embodiments provided, and for the sake of avoiding repetition, the detailed descriptions are appropriately omitted here.
[0089] From some embodiments of the present application, it can be seen that the present application also supports the conversion of address groups on the basis of host addresses, range addresses, and subnet addresses. In addition, the method provided by the embodiments of the present application does not require the number of addresses before and after conversion to be equal. Whether the addresses before conversion are more or less than the addresses after conversion does not affect the subsequent address adaptation strategy, and the applicable range is relatively wide. Moreover, the present application calculates the key value for the source address to be converted, and then calculates the Hash value. At the same time, the sticky parameter is supported. Users can clearly obtain the converted address or randomly (introducing random) obtain the converted address. Therefore, the present application supports conversion diversity and can also hide the internal network topology, with relatively high security. In addition, the present application uses the jhash function to calculate the equivalent value from the source address to replace the dependence on the equal address pool, thereby expanding the usage range of NAT and having good versatility.
[0090] Please refer to Figure 4 , Figure 4 which shows the block diagram of the composition of the source address conversion device provided by some embodiments of the present application. It should be understood that this source address conversion device corresponds to the above method embodiments and can execute each step involved in the above method embodiments. The specific functions of this source address conversion device can be seen in the above description. For the sake of avoiding repetition, the detailed descriptions are appropriately omitted here.
[0091] Figure 4 The source address conversion device of
[0092] In some embodiments of the present application, the types of the source addresses to be converted include: source host addresses, source subnet addresses, source range addresses, and source address groups.
[0093] In some embodiments of the present application, the calculation module 420 is configured to perform an equivalence calculation on the source address to be converted to obtain an equivalent address value of the source address to be converted; and obtain the conversion identification value according to the equivalent address value and the sticky parameter.
[0094] In some embodiments of the present application, the calculation module 420 is configured to calculate the equivalent address value to obtain the conversion identification value if the sticky parameter is in an enabled state.
[0095] In some embodiments of the present application, the calculation module 420 is configured to calculate the equivalent address value and a random parameter to obtain the conversion identification value if the sticky parameter is in a disabled state.
[0096] In some embodiments of the present application, the lookup module 430 is configured to obtain a pointer to the first address in the address conversion group; add the pointer and the conversion identification value and then subtract one to obtain an address subscript value; and use the address that matches the address subscript value as the target conversion address.
[0097] In some embodiments of the present application, the acquisition module 410 is configured to acquire a source port and a port conversion parameter; the apparatus for source address conversion further includes: a conversion module (not shown in the figure), which is configured to obtain the target conversion port after conversion of the source port according to the port conversion parameter.
[0098] In some embodiments of the present application, the conversion module is configured to select the target conversion port and convert the source port to the target conversion port if it is confirmed that the port parameter is in the first state; use the source port as the target conversion port if it is confirmed that the port parameter is in the second state; use the source port as the target conversion port if it is confirmed that the port parameter is in the third state and the source port is not occupied; and select the target conversion port and convert the source port to the target conversion port if it is confirmed that the port parameter is in the third state and the source port is occupied.
[0099] Some embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the operations corresponding to any of the methods provided in the above embodiments of the above method can be implemented.
[0100] Some embodiments of the present application also provide a computer program product, which includes a computer program. When the computer program is executed by a processor, it can implement the operations corresponding to any of the methods provided in the above-mentioned embodiments of the above methods.
[0101] As Figure 5 shown, some embodiments of the present application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520. When the processor 520 reads the program from the memory 510 through a bus 530 and executes the program, it can implement the methods of any of the above embodiments.
[0102] The processor 520 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 520 can be a microprocessor.
[0103] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 520 of the embodiments of the present disclosure can be used to execute the instructions in the memory 510 to implement the methods shown above. The memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.
[0104] The above are only the embodiments of the present application and are not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0105] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0106] It should be noted that, in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the said element.
Claims
1. A method for source address translation, characterized in that, Including: Obtain the source address to be converted and the address conversion array; Calculate the to-be-converted source address to obtain a conversion identification value; Based on the conversion identification value, search for the target conversion address after conversion of the to-be-converted source address from the address conversion group; The calculating the to-be-converted source address to obtain a conversion identification value includes: performing an equivalent calculation on the to-be-converted source address to obtain an equivalent address value of the to-be-converted source address; Obtain the conversion identification value according to the equivalent address value and the adhesion parameter.
2. The method according to claim 1, wherein The types of the to-be-converted source address include: source host address, source subnet address, source range address, and source address group.
3. The method according to claim 1 or 2, characterized in that, The obtaining the conversion identification value according to the equivalent address value and the adhesion parameter includes: If the adhesion parameter is in the enabled state, calculate the equivalent address value to obtain the conversion identification value.
4. The method according to claim 1 or 2, characterized in that, The obtaining the conversion identification value according to the equivalent address value and the adhesion parameter includes: If the adhesion parameter is in the disabled state, calculate the equivalent address value and the random parameter to obtain the conversion identification value.
5. The method according to claim 1 or 2, characterized in that, The searching for the target conversion address after conversion of the to-be-converted source address from the address conversion group based on the conversion identification value includes: Obtain a pointer pointing to the first address in the address conversion group; Add the pointer and the conversion identification value and then subtract one to obtain an address subscript value; Use the address matching the address subscript value as the target conversion address.
6. The method according to claim 1 or 2, characterized in that, The method further includes: Obtain the source port and the port conversion parameter; Obtain the target conversion port after conversion of the source port according to the port conversion parameter.
7. The method according to claim 6, characterized in that, The obtaining the target conversion port after conversion of the source port according to the port conversion parameter includes: If it is confirmed that the port parameter is in the first state, select the target conversion port and convert the source port to the target conversion port; If it is confirmed that the port parameter is in the second state, use the source port as the target conversion port; If it is confirmed that the port parameter is in the third state and the source port is not occupied, use the source port as the target conversion port; If it is confirmed that the port parameter is in the third state and the source port is occupied, select the target conversion port and convert the source port to the target conversion port.
8. A device for source address translation, characterized in that The device for executing the method according to claim 1 includes: An obtaining module, configured to obtain the source address to be converted and the address conversion array; A calculating module, configured to calculate the to-be-converted source address to obtain a conversion identification value; A searching module, configured to search for the target conversion address after conversion of the to-be-converted source address from the address conversion group based on the conversion identification value.
9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, wherein the computer program, when run by a processor, executes the method according to any one of claims 1-7.
10. An electronic device, characterized in that, Including a memory, a processor, and a computer program stored on the memory and running on the processor, wherein the computer program, when run by the processor, executes the method according to any one of claims 1-7.
Citation Information
Patent Citations
IPV6 address conversion method and device based on address pool offset, equipment and medium
CN114710466A
Address conversion method for simultaneously supporting one-to-one and many-to-many under the PAT mode
CN1477825A