A message processing method, apparatus, device, and readable storage medium
By introducing a BGP proxy to the network device, calculating and processing the message verification data of neighboring devices, the problem of packet transmission errors and data inconsistencies is solved under the numerous routing connections, and efficient routing management and security protection is achieved.
Patent Information
- Application Number
- CN202211708823.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-12-29
AI Technical Summary
In the case of numerous and complicated routing connections, it is difficult to effectively manage the problem of packet transmission errors and data inconsistencies.
The BGP proxy is introduced in the network device, and by calculating the verification data of the messages sent by the neighbor device, and sending the messages to the slave executor with a communication connection for processing based on the verification data, simulating the neighbor device to forward the messages to each slave executor to realize routing management.
In the case of numerous and complicated routing connections, it is possible to manage messages transmitted from each route, reduce the probability of packet transmission errors and data inconsistencies, and improve the security and reliability of network equipment.
Smart Images

Figure CN116319539B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technologies, and particularly to a method, apparatus, device, and readable storage medium for message processing. Background Art
[0002] Currently, with the continuous development of Internet communication technologies, communication applications have been unprecedentedly popularized. Routing is the brain for information interaction between network devices, and a routing protocol is a protocol used for path selection. Through routing, data packet forwarding can be achieved. In the case of numerous and complex routing connections, it is difficult to manage the messages transmitted from each route, and problems such as message transmission errors and data inconsistency may occur.
[0003] Therefore, how to solve the message transmission errors and data inconsistency of different routes is a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a method, apparatus, device, and readable storage medium for message processing to solve the message transmission errors and data inconsistency of different routes. The specific solutions are as follows:
[0005] In a first aspect, this application provides a method for message processing, which is applied to a BGP proxy end in a network device, and includes:
[0006] Receiving a first message sent by a neighbor device of the network device;
[0007] If the first message carries a check option, and the neighbor device has established a communication connection with the main execution entity in the network device, and the first secret key of the neighbor device is locally recorded, then calculating the first check data of the first message;
[0008] Sending the first message to at least one slave execution entity having a communication connection with the BGP proxy end based on the first check data, so that the at least one slave execution entity processes the first message.
[0009] Optionally, calculating the first check data of the first message includes:
[0010] Constructing a pseudo-header based on the source IP address, destination IP address, protocol number, and TCP length of the first message;
[0011] Obtaining the first secret key from the locally preset configuration information;
[0012] Determining the TCP header fields and message payload of the first message;
[0013] Process the pseudo-header, the first secret key, the TCP header fields, and the message payload using the MD5 algorithm, and use the obtained MD5 value as the first verification data.
[0014] Optionally, establishing a communication connection between the neighbor device and the main executor, and between the BGP proxy and at least one slave executor includes:
[0015] Receiving a link establishment message sent by the neighbor device;
[0016] Storing the link establishment message, constructing a communication connection between the neighbor device and the main executor based on the link establishment message, and then constructing a communication connection between the BGP proxy and at least one slave executor based on the link establishment message.
[0017] Optionally, disconnecting the communication connection between the neighbor device and the main executor, and between the BGP proxy and at least one slave executor includes:
[0018] Receiving a link disconnection message sent by the neighbor device;
[0019] Storing the link disconnection message, disconnecting the communication connection between the neighbor device and the main executor based on the link disconnection message, and then disconnecting the communication connection between the BGP proxy and at least one slave executor based on the link disconnection message.
[0020] Optionally, sending the first message to at least one slave executor having a communication connection with the BGP proxy based on the first verification data includes:
[0021] Verifying the check option using the first verification data;
[0022] If the check option passes the verification, modify some TCP header fields of the first message to obtain a first forwarding message, calculate the forwarding verification data of the first forwarding message, encapsulate the forwarding verification data into the first forwarding message, and then send the first forwarding message encapsulated with the forwarding verification data to at least one slave executor;
[0023] If the check option fails the verification, modify some TCP header fields of the first message to obtain a second forwarding message, encapsulate the check option into the second forwarding message, and then send the second forwarding message encapsulated with the check option to at least one slave executor.
[0024] Optionally, it further includes:
[0025] Receiving a second message sent by any one of the at least one slave executors;
[0026] Calculate the second verification data of the second message;
[0027] If the verification option in the second message passes the verification using the second verification data, read and process the second message; otherwise, disconnect the communication connection with the current slave executor.
[0028] Optionally, it further includes:
[0029] Receive and store the third message sent by the master executor;
[0030] If the third message is a link establishment message and there is already a communication connection between the neighbor device and the master executor, retain the communication connection initiated by the party with the largest routing ID based on the third message, and delete other communication connections;
[0031] If the third message is a link disconnection message, after disconnecting the communication connection between the neighbor device and the master executor based on the third message, disconnect the communication connection between the BGP proxy end and the at least one slave executor based on the third message.
[0032] In a second aspect, the present application provides a message processing device applied to a BGP proxy end in a network device, including:
[0033] A receiving module, configured to receive a first message sent by a neighbor device of the network device;
[0034] A calculation module, configured to calculate the first verification data of the first message if the first message carries a verification option, and there is already a communication connection between the neighbor device and the master executor in the network device, and the first secret key of the neighbor device is locally recorded;
[0035] A processing module, configured to send the first message to at least one slave executor having a communication connection with the BGP proxy end based on the first verification data, so that the at least one slave executor processes the first message.
[0036] In a third aspect, the present application provides an electronic device, including:
[0037] A memory, configured to store a computer program;
[0038] A processor, configured to execute the computer program to implement the foregoing disclosed message processing method.
[0039] In a fourth aspect, the present application provides an electronic device, including: a BGP proxy end, a master executor, and at least one slave executor, where the BGP proxy end is configured to implement the foregoing disclosed message processing method.
[0040] Fifth aspect, the present application provides a readable storage medium for storing a computer program, wherein when the computer program is executed by a processor, it implements the aforementioned disclosed message processing method.
[0041] As can be seen from the above solutions, the present application provides a message processing method applied to the BGP proxy end in a network device, including: receiving a first message sent by a neighbor device of the network device; if the first message carries a verification option, and the neighbor device has established a communication connection with the main execution entity in the network device, and the first secret key of the neighbor device is locally recorded, then calculating first verification data of the first message; and sending the first message to at least one slave execution entity having a communication connection with the BGP proxy end based on the first verification data, so that the at least one slave execution entity processes the first message.
[0042] It can be seen that in the present application, a BGP proxy end is set in the network device. When the neighbor device has established a communication connection with the main execution entity in the current network device and the secret key of the neighbor device is locally recorded, the BGP proxy end can calculate corresponding first verification data for the first message carrying the verification option sent by the neighbor device, and then send the first message to at least one slave execution entity having a communication connection with the BGP proxy end based on the first verification data, so that at least one slave execution entity processes the first message. In this solution, the BGP proxy end simulates the neighbor device to forward messages to each slave execution entity, and can perform routing management on the messages sent by the neighbor device to the current network device, so that the messages sent by the neighbor device to the current network device can be successfully processed by the corresponding slave execution entity. In the case of many and complex routing connections, it is convenient to manage the messages transmitted by each route, and the probability of problems such as message transmission errors and data inconsistency can be reduced.
[0043] Correspondingly, a message processing device, device and readable storage medium provided by the present application also have the above technical effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for describing the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0045] Figure 1 It is a flowchart of a message processing method disclosed in the present application;
[0046] Figure 2 It is a schematic diagram of information recording disclosed in the present application;
[0047] Figure 3 Schematic diagram of an MD5 value calculation process disclosed in this application;
[0048] Figure 4 Another flowchart of a message processing method disclosed in this application;
[0049] Figure 5 Another flowchart of a message processing method disclosed in this application;
[0050] Figure 6 Another flowchart of a message processing method disclosed in this application;
[0051] Figure 7 Schematic diagram of data stream processing and direction disclosed in this application;
[0052] Figure 8 Schematic diagram of a network device disclosed in this application;
[0053] Figure 9 Schematic diagram of a message processing device disclosed in this application;
[0054] Figure 10 Schematic diagram of an electronic device disclosed in this application. Specific embodiments
[0055] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0056] Currently, in the case of numerous and complex routing connections, the messages transmitted by each route are difficult to manage, and problems such as message transmission errors and data inconsistency may occur. For this reason, this application provides a message processing solution that enables the BGP proxy end in the network device to simulate neighbor devices and forward messages to each slave execution body, thereby performing routing management on the messages sent by neighbor devices to the current network device. In the case of numerous and complex routing connections, it is convenient to manage the messages transmitted by each route and reduce the probability of problems such as message transmission errors and data inconsistency.
[0057] See Figure 1 As shown, an embodiment of this application discloses a message processing method applied to the BGP (Border Gateway Protocol) proxy end in a network device, including:
[0058] S101. Receive a first message sent by a neighbor device of the network device.
[0059] In this embodiment, the current network device may be a device such as a switch or a router, and its neighbor device is: a device having a topological connection with the current network device. Therefore, the neighbor device may be a switch, a router, a server, a terminal, etc.
[0060] S102: If the first packet carries a check option, and the neighbor device has established a communication connection with the main execution entity in the network device, and the first secret key of the neighbor device is locally recorded, then calculate the first check data of the first packet.
[0061] In this embodiment, when it is determined that the first packet sent by the neighbor device carries a check option, and the neighbor device has established a communication connection with the main execution entity in the network device, and the first secret key of the neighbor device is locally recorded by the network device, the BGP proxy end considers that the first packet needs to be checked. Therefore, the BGP proxy end calculates the first check data of the first packet. For details, refer to Figure 4 , such as Figure 4 As shown, if the first packet sent by the neighbor device carries a check option, but the neighbor device has not established a communication connection with the main execution entity in the network device or the first secret key of the neighbor device is not locally recorded, then packet checking is not performed. Correspondingly, if the packet comes from a slave execution entity, then when the secret key of the neighbor device related to the packet is locally recorded, the packet is normally processed after packet checking; otherwise, the communication connection between the relevant neighbor device and the main execution entity is disconnected, and at the same time, the communication connection between the slave execution entity and the BDP proxy end is disconnected. If the packet received by the BDP proxy end does not have an MD5 check option, then there is no need to perform packet checking either, and the packet can be processed according to the established rules.
[0062] Generally, the neighbor device may also send a handshake packet or a heartbeat packet without a check option to the network device. In this embodiment, packets such as handshake packets and heartbeat packets that do not carry specific network data (such as image data, etc.) are called notification messages. For example: The open packet and keepalive packet of BGP can both belong to notification messages. The communication connection relationship between BGP peers can be established through the open packet; while the keepalive packet is used to confirm the status of two communicating parties with an established communication connection, similar to heartbeat detection. Accordingly, it can be determined that the packet that does not belong to the notification message is: a packet carrying specific network data sent by the communication initiator, such as the first packet.
[0063] Among them, the check data of a certain message can be calculated by means such as the MD5 (Message-Digest Algorithm 5) algorithm, and the fields processed by the relevant algorithms can be defined by oneself. For example: Let the MD5 algorithm process the custom fields, the first secret key of the neighbor device, the TCP (Transmission Control Protocol) header field of the original message, and the message payload of the original message, and use the obtained MD5 value as the check data of the original message. Therefore, in one implementation manner, calculating the first check data of the first message includes: constructing a pseudo-header based on the source IP address, destination IP address, protocol number, and TCP length of the first message; obtaining the first secret key from the preset configuration information locally; determining the TCP header field and the message payload of the first message; using the MD5 algorithm to process the pseudo-header, the first secret key, the TCP header field, and the message payload, and using the obtained MD5 value as the first check data. Among them, both the protocol number and the TCP length in the pseudo-header occupy two bytes, and the protocol number is represented by all-zero data of two bytes. The TCP length in the pseudo-header is the length of the other content in the first message except the IP header. Therefore, subtracting the IP header length of the first message from the total message length of the first message can obtain the TCP length in the pseudo-header.
[0064] In one example, the BGP proxy end can call a preset MD5 module to calculate the first check data of the first message.
[0065] S103. Send the first message to at least one slave executor that has a communication connection with the BGP proxy end based on the first check data, so that at least one slave executor processes the first message.
[0066] In one embodiment, sending the first message to at least one slave executor having a communication connection with the BGP proxy based on the first verification data includes: verifying the verification option using the first verification data; if the verification option passes the verification, modifying some TCP header fields of the first message to obtain a first forwarding message, calculating the forwarding verification data of the first forwarding message, encapsulating the forwarding verification data into the first forwarding message, and then sending the first forwarding message encapsulated with the forwarding verification data to the at least one slave executor; if the verification option fails the verification, modifying some TCP header fields of the first message to obtain a second forwarding message, encapsulating the verification option into the second forwarding message, and then sending the second forwarding message encapsulated with the verification option to the at least one slave executor. Among them, when the BGP proxy verifies the verification option in the first message, the first verification data is calculated in the same manner as in step S102, and then the first verification data is compared with the verification option in the first message to check if they are consistent. If they are consistent, it is confirmed that the verification option in the first message passes the verification; otherwise, it is confirmed that the verification option in the first message fails the verification.
[0067] Considering that the BGP proxy needs to forward multiple messages sent by the same neighbor device, to avoid message forwarding errors, the BGP proxy does not forward according to the seq field of these messages, but forwards according to the arrival order of these messages. Therefore, the BGP proxy will modify fields such as the seq field in the original message to fields indicating the message arrival order. At the same time, the BGP proxy will also modify fields such as the source / destination MAC address, TCP port number, ack, tsecr, etc. Therefore, the BGP proxy needs to modify the first message to obtain a forwarding message and also needs to recalculate the verification value of the forwarding message. Among them, when the verification option in the first message fails the verification, the BGP proxy does not need to specifically modify the verification option in the first message to avoid changing the originally incorrect verification data in the first message to correct data and deceiving the slave executor.
[0068] In one embodiment, if the first message belongs to a notification message (e.g., the first message is an open message or a keepalive message), then store the first message and establish a communication connection between the BGP proxy end and at least one slave executor based on the first message. If the neighbor device has not established a communication connection with the master executor, then store the first message and establish a communication connection between the neighbor device and the master executor based on the first message. At this time, the first message may be a handshake message. Specifically, establishing a communication connection between the neighbor device and the master executor, and between the BGP proxy end and at least one slave executor includes: receiving a link establishment message sent by the neighbor device; storing the link establishment message, and after establishing a communication connection between the neighbor device and the master executor based on the link establishment message, establishing a communication connection between the BGP proxy end and at least one slave executor based on the link establishment message. Specifically, disconnecting the communication connection between the neighbor device and the master executor, and between the BGP proxy end and at least one slave executor includes: receiving a link disconnection message sent by the neighbor device; storing the link disconnection message, and after disconnecting the communication connection between the neighbor device and the master executor based on the link disconnection message, disconnecting the communication connection between the BGP proxy end and at least one slave executor based on the link disconnection message.
[0069] Such as Figure 5 As shown, if it is confirmed that the neighbor device has sent a link establishment message or a link disconnection message, then the BGP proxy end changes the communication connection relationship between the master executor and the neighbor device based on this message, and at the same time changes the communication connection relationship between the corresponding slave executor and the BGP proxy end. For example: in the case of confirming that the neighbor device has sent a link disconnection message, delete the communication connection between the neighbor device and the master executor, and at the same time delete each slave executor used to process the messages sent by the neighbor device and the BGP proxy end accordingly. It can be seen that the connection between the slave executor and the BGP proxy end exists depending on the existence of the connection between the neighbor device and the master executor. If the latter exists, the former exists; if the latter is eliminated, the former should also be eliminated.
[0070] In one embodiment, when there is a communication connection between the master executor and the neighbor device, the BGP proxy end also receives a second message sent by any one of at least one slave executor; calculates the second check data of the second message; if the check option in the second message is verified to pass using the second check data, then reads and processes the second message; otherwise, disconnects the communication connection with the current slave executor. Among them, the calculation method of the second check data of the second message is the same as that in the foregoing step S102, and the corresponding check method is also the same, so it will not be elaborated here. In this example, the second message may be: the response data returned after the slave executor processes the first message.
[0071] In one embodiment, the BGP agent also receives and stores the third message sent by the main execution entity; if the third message is a link establishment message and there is already a communication connection between the neighbor device and the main execution entity, the communication connection initiated by the party with the largest retained routing ID is retained based on the third message, and other communication connections are deleted; if the third message is a link disconnection message, after disconnecting the communication connection between the neighbor device and the main execution entity based on the third message, the communication connection between the BGP agent and at least one slave execution entity is disconnected based on the third message.
[0072] It should be noted that the BGP agent in the network device can manage: the connection status between the main execution entity and the neighbor device, and the connection status between itself and other slave execution entities, and can process the messages sent by the neighbor device, the main execution entity or other slave execution entities according to the relevant connections. Therefore, it can conveniently manage the messages transmitted by each route and reduce the probability of problems such as message transmission errors and data inconsistency. Among them, the main execution entity and other slave execution entities in the network device are software or hardware with different network protection functions. That is: different execution entities can not only process messages, but also have different network protection capabilities. For example, one slave execution entity has strong defense capabilities against zombie viruses, while another slave execution entity has strong defense capabilities against route spoofing. This can reduce the probability that different execution entities in the network device are attacked simultaneously, achieving the effect of multi-party security protection. Moreover, all slave execution entities in the network device can be not online at the same time. For example: a total of 6 slave execution entities are set in a network device. After the network device is started, 3 of the 6 slave execution entities are selected to go online first. If one or several of the online slave execution entities fail, the corresponding number of slave execution entities are selected from the remaining 3 unused slave execution entities to make up for the online ones, so that there are always 3 slave execution entities in the network device in the online state.
[0073] According to the above principle, multiple dynamically heterogeneous redundant execution entities are introduced into the network mimicry device, and by scheduling and using different execution entities, various uncertain changes can be coped with. On the premise of differential design, the probability that different execution entities have exactly the same vulnerabilities or backdoors is extremely low. Even if an attacker controls some execution entities, other execution entities can identify their malicious behaviors. Therefore, the ability of the mimicry device to cope with network attacks can be improved. And the BGP agent in the network device can process various messages arriving at the current network device, and can realize the orderly and efficient processing of messages.
[0074] It can be seen that in the embodiment of the present application, a BGP proxy end is set in the network device. When a communication connection has been established between the neighbor device and the main execution entity in the current network device and the secret key of the neighbor device is locally recorded, the BGP proxy end can calculate corresponding first verification data for the first message carrying the verification option sent by the neighbor device, and then send the first message to at least one slave execution entity having a communication connection with the BGP proxy end based on the first verification data, so that the at least one slave execution entity processes the first message. In this solution, the BGP proxy end simulates the neighbor device to forward messages to each slave execution entity, and can perform routing management on the messages sent by the neighbor device to the current network device, so that the messages sent by the neighbor device to the current network device can be successfully processed by the corresponding slave execution entity. In the case of numerous and complex routing connections, it is convenient to manage the messages transmitted by each route, and the probability of problems such as message transmission errors and data inconsistency is reduced.
[0075] According to the above embodiment, a BGP proxy end can be set in the network device, and a configuration management module, an execution entity scheduling module, an MD5 module, a link state management module, and a message processing module are set in the BGP proxy end. Among them, the configuration management module is used to store the secret keys of neighbor devices and support operations such as adding, deleting, and modifying secret keys. The execution entity scheduling module is used to manage the online state and offline state of the execution entity. The MD5 module can sign or verify the signature of the message according to the secret key of the neighbor device. The link state management module is responsible for managing the TCP session state between the main execution entity and the neighbor device and the connection state between the BGP proxy end and each slave execution entity. The message processing module is responsible for forwarding and processing messages.
[0076] Please refer to Figure 2 , the configuration management module uses the peer_password_dic data structure to record the secret keys of each neighbor device. For each neighbor device, a key-value pair is formed by its IP address and password (the secret key of the neighbor device) and stored as a piece of data. As Figure 2 shown, the configuration management module can record the key-value pairs corresponding to N neighbor devices.
[0077] Specifically, when the network device is initialized, the passwords of all neighbors of the current network device can be recorded and stored in the peer_password_dic structure. Then a child thread can be created, and this child thread is used to receive the password modification information of a certain neighbor, that is: when a secret key is configured for a certain neighbor or a secret key of a certain neighbor is deleted, this child thread will capture this event and delete or add the neighbor's secret key according to the current operation.
[0078] The MD5 module performs MD5 decryption processing on the received packets according to the neighbor key; for the packets to be sent out, it performs MD5 encryption processing according to the neighbor key. During the encryption process, the calculated MD5 value is inserted into the packet as an option of the TCP packet.
[0079] Please refer to Figure 3 , the MD5 value calculation process includes:
[0080] 1. Construct a TCP pseudo-header from the input packet. The TCP pseudo-header consists of some fields of the IP header of the input packet, and the construction order is the source IP address, destination IP address, protocol number, and TCP length of the input packet in sequence. Among them, the protocol number is filled with all-zero data. Both the TCP length and the protocol number occupy 2 bytes. The TCP length is obtained by subtracting the IP header length of the input packet from the total length of the input packet.
[0081] 2. Extract some fields of the TCP header of the input packet. The extracted fields include: source port, destination port, sequence number, acknowledgment number, TCP header length, FLAG flag, window size, checksum (set to zero), and urgent pointer. It can be seen that the extracted fields are: other fields except the options in the TCP header.
[0082] 3. Extract the TCP payload of the input packet.
[0083] 4. Determine the key value of the neighbor device that sends the current input packet.
[0084] Input the above four parts into the MD5 algorithm in sequence to obtain the MD5 value.
[0085] Please refer to Figure 4, for the packets sent by the neighbor device, the MD5 module first determines whether a TCP connection is established between the neighbor device sending the current packet and the main execution entity. If the connection is not established, the current packet may be a notification message such as a handshake message, and the MD5 value verification may not be performed, so that the MD5 value verification is completed by the protocol stacks at both ends. If the connection between the neighbor device and the main execution entity has been established and the connection between the slave execution entity and the BGP proxy has also been established, then the MD5 value is verified. After that, the current packet is modified to obtain a forwarding packet, and a new MD5 value is calculated according to the foregoing process. After being encapsulated into the forwarding packet, the forwarding packet is sent to the slave execution entity. Among them, in the case of verification failure, the MD5 value option in the original packet is not specifically modified, so that the slave execution entity can obtain the MD5 value that has failed verification but has not been changed, so as to avoid deceiving the slave execution entity. If the verification is successful, the seq and other fields of the current packet are modified to obtain a forwarding packet, and a new MD5 value is regenerated and encapsulated in the option of the forwarding packet and forwarded to the slave execution entity. For the TCP packets sent by the slave execution entity, the destination address in the current TCP packet is used to look up the corresponding password in the peer_password_dic structure, and then the MD5 value is calculated according to the above steps. If the currently calculated MD5 value is the same as the MD5 value in the current TCP packet, the authentication passes, and at this time, the authenticated TCP packet can be stored. If the currently calculated MD5 value is different from the MD5 value in the current TCP packet, the connection between the current BGP proxy and the current slave execution entity is disconnected. For the packets sent by the main execution entity, no MD5 verification or modification is performed, and the useful information is extracted and stored.
[0086] The link status management module is responsible for managing the TCP session status between the execution entity and the neighbor device, initializing the cache management of the packets, generating TCP connection information, etc. Considering that when the BGP protocol is applied under the RFC standard, both the neighbor device and the main execution entity may initiate TCP connections to each other, then there may be 2 TCP connections between them at the same time. The link status management module closes the TCP connection with the smaller originator route ID according to the protocol rules and retains the TCP connection with the larger originator route ID. In the initial stage of link establishment, the TCP connection information of these two TCP connections will be recorded in the port-list list. After one of them is closed, the closed TCP connection information is deleted from the port-list list. Among them, a binary group composed of actor-ip (the IP address of the current network device) and peer-ip (the IP address of the neighbor device) can be used as the KEY, and a binary group composed of actor-port (the port number of the current network device) and peer-port (the port number of the neighbor device) can be used as the value of the KEY, and thus a TCP connection information in the port-list list can be obtained.
[0087] The connection directions between different execution entities and their neighbors may be different. For example, the source ports in the five-tuples of the connections initiated by the current network device to the neighbor device and those initiated by the neighbor device to the current network device are different, and different connection initiation times will also result in different states. Among them, the five-tuple includes: source IP, destination IP, source port, destination port, and connection direction. A TCP connection information may also include: the packets during connection establishment, specifically: the packets from TCP syn to before BGPupdate.
[0088] It should be noted that the main execution entity can find the corresponding TCP connection information in the port-list for both the neighbors and each slave execution entity. The establishment of the connection is triggered by the syn packet of the main execution entity or the neighbor, and the connection direction is determined by the link establishment direction between the main execution entity and the neighbor.
[0089] Among them, for the processing of packets by the link state management module, please refer to Figure 5 and Figure 6 . Please refer to Figure 5 . Since the port number of the BGP protocol is 179, the link state management module captures the TCP packets on the incoming direction of port 179 of the neighbor device's interface through the scapy function. If the current TCP packet is a packet for link establishment or disconnection, the packet is stored and can be used later for: TCP link establishment or disconnection operations with the slave execution entity, and correlation analysis of the link establishment or disconnection packets of the main execution entity to determine the TCP connection state. If the current TCP packet is an open / keepalive packet of the BGP protocol, it is saved for constructing the open and keepalive of the BGP protocol when the BGP proxy end establishes a link with the slave execution entity. For other packets, it is necessary to check whether the slave execution entity has completed link establishment. If not, the BGP proxy end does not process these packets and directly discards them; if it has been completed, these packets are distributed to other slave execution entities.
[0090] Please refer to Figure 6, if the packet comes from the main executor, the BGP proxy only cares about the TCP connection establishment or disconnection packets and does not process other packets. The BGP proxy can comprehensively analyze the TCP connection establishment or disconnection packets sent by the main executor and the TCP connection establishment or disconnection packets sent by the neighbor to obtain the TCP connection status between the two. If the connection is successfully established, the BGP proxy determines whether to initiate a TCP connection to the slave executor based on the TCP connection direction (initiator). If the connection is closed, the BGP proxy needs to initiate a disconnection operation to the slave executor with an established TCP connection and delete the table entries related to the connection information. It can be seen that the proxy also disconnects and establishes connections based on the disconnection and connection establishment packets sent by the main executor to the neighbor. If the packet comes from the slave executor, the BGP proxy needs to determine the connection status between the neighbor and the main executor. If the connection between the neighbor and the main executor is established, store the packet from the slave executor for constructing fields such as seq, ack, and stamp in the packet during subsequent interaction with the slave executor. If the connection between the neighbor and the main executor has not been established, discard the packet sent by the slave executor.
[0091] Specifically, the packet processing module is responsible for copying the packet and distributing it to each executor, receiving the packets sent by each executor, and determining the source of the packet based on the MAC / IP address of the packet. If it is determined that the packet comes from a neighbor, the packet can be a connection establishment or disconnection packet, so the packet can be stored to perform TCP connection establishment or disconnection operations on other executors, or jointly determine the connection status between the main executor and the neighbor based on the connection establishment or disconnection packets sent by the main executor. If it is an open / keepalive packet, perform TCP connection establishment or disconnection operations on other executors based on the packet. If it is an ordinary packet for transmitting specific data, copy and distribute the packet to each executor. When distributing the packet, modify the source and destination MAC addresses, modify the TCP port number according to the BGP connection information, modify ack and tsecr corresponding to seq and tsval of the original packet, and modify fields such as seq. Then recalculate the MD5 value and modify the option filled with the MD5 value in the packet. If it is determined that the packet comes from the main executor, jointly determine the connection status between the main executor and the neighbor for the connection establishment or disconnection packet sent by the main executor and the connection establishment or disconnection packet sent by the neighbor. If it is determined that the packet comes from other executors, store the corresponding packet, which can be used for ack modification when distributing the packet sent by the neighbor.
[0092] Please refer to Figure 7, the packets sent by the neighbor device enter the BGP proxy, and the BGP proxy distributes the packets to 3 slave executors. After these 3 slave executors process the packets respectively, they return the response data to the BGP proxy, and then the BGP proxy replies the relevant response data to the neighbor device. Specifically, two storage queues, In / out, can be set. These two queues store the packets in the order of arrival of the packets, rather than sorting by the packet seq. The BGP proxy, the master executor, and each slave executor all correspond to two storage queues, In / out, and each queue only stores the currently received and sent packets. Please refer to Figure 8 , a network device may include a BGP proxy, a master executor, and each slave executor.
[0093] In this embodiment, by setting a BGP proxy in the mimic device, the packet processing between the external neighbor and each executor in the mimic device is realized, and the communication between each executor and the external neighbor is realized. The BGP proxy supports the basic functions of receiving and sending BGP packets, and can distribute the packets sent by the neighbor to each executor; and performs encryption and decryption processing on the encrypted BGP packets through the encryption and authentication functions. At the same time, the BGP proxy supports IPv4 / v6 dual-stack, and can process BGP4 and BGP4+ simultaneously; supports the rotation of executors to go online. After any executor goes online again, it can simulate the neighbor to establish a link with this executor, and send a routing update message through the configuration command to notify the neighbor to re-send the routing update.
[0094] It can be seen that the BGP proxy can ensure the diversification of BGP routing data, can realize routing control. The BGP protocol uses TCP as the transport layer protocol (port number 179), which improves the reliability of the protocol; each executor with different defense capabilities designed differently can achieve a higher-strength and more comprehensive network security protection.
[0095] Next, a packet processing device provided by an embodiment of the present application will be introduced. The packet processing device described below can be referred to each other with the packet processing method described above.
[0096] Refer to Figure 9 As shown in, an embodiment of the present application discloses a packet processing device, which is applied to the BGP proxy end in a network device, and includes:
[0097] A receiving module 901, configured to receive a first packet sent by a neighbor device of the network device;
[0098] A calculating module 902, configured to calculate first check data of the first packet if the first packet carries a check option, and the neighbor device has established a communication connection with the master executor in the network device, and a first secret key of the neighbor device is locally recorded;
[0099] A processing module 903, configured to send the first message to at least one slave execution entity that has a communication connection with the BGP agent end based on the first verification data, so that the at least one slave execution entity processes the first message.
[0100] In a specific embodiment, the calculation module is specifically configured to:
[0101] Construct a pseudo-header based on the source IP address, destination IP address, protocol number, and TCP length of the first message;
[0102] Obtain a first secret key from the preset configuration information locally;
[0103] Determine the TCP header fields and message payload of the first message;
[0104] Process the pseudo-header, the first secret key, the TCP header fields, and the message payload using the MD5 algorithm, and use the obtained MD5 value as the first verification data.
[0105] In a specific embodiment, the communication connection establishment process includes: receiving a link establishment message sent by a neighbor device; storing the link establishment message, and based on the link establishment message, constructing a communication connection between the neighbor device and the main execution entity, and then constructing a communication connection between the BGP agent end and at least one slave execution entity based on the link establishment message.
[0106] In a specific embodiment, the communication connection disconnection process includes: receiving a link disconnection message sent by a neighbor device; storing the link disconnection message, and based on the link disconnection message, disconnecting the communication connection between the neighbor device and the main execution entity, and then disconnecting the communication connection between the BGP agent end and at least one slave execution entity based on the link disconnection message.
[0107] In a specific embodiment, the processing module is specifically configured to:
[0108] Verify the verification option using the first verification data;
[0109] If the verification option passes the verification, modify some TCP header fields of the first message to obtain a first forwarding message, calculate the forwarding verification data of the first forwarding message, encapsulate the forwarding verification data into the first forwarding message, and then send the first forwarding message encapsulated with the forwarding verification data to the at least one slave execution entity;
[0110] If the verification option fails the verification, modify some TCP header fields of the first message to obtain a second forwarding message, encapsulate the verification option into the second forwarding message, and then send the second forwarding message encapsulated with the verification option to the at least one slave execution entity.
[0111] In a specific embodiment, it further includes:
[0112] Another processing module, configured to receive a second message sent by any slave executor among at least one slave executor; calculate second check data of the second message; if the check option in the second message is verified to be passed using the second check data, read and process the second message; otherwise, disconnect the communication connection with the current slave executor.
[0113] In a specific embodiment, it further includes:
[0114] Another processing module, configured to receive and store a third message sent by the master executor; if the third message is a link establishment message and there is already a communication connection between the neighbor device and the master executor, retain the communication connection initiated by the party with the largest routing ID based on the third message, and delete other communication connections; if the third message is a link disconnection message, after disconnecting the communication connection between the neighbor device and the master executor based on the third message, disconnect the communication connection between the BGP proxy end and at least one slave executor based on the third message.
[0115] Wherein, for the more specific working processes of each module and unit in this embodiment, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.
[0116] It can be seen that this embodiment provides a message processing device, which can facilitate the management of messages transmitted by each route and reduce the probability of problems such as message transmission errors and data inconsistency.
[0117] Next, an electronic device provided by an embodiment of the present application will be introduced. The electronic device described below can be referred to in mutual reference with the message processing method and device described above.
[0118] See Figure 10 As shown, an embodiment of the present application discloses an electronic device, including:
[0119] A memory 1001, configured to store a computer program;
[0120] A processor 1002, configured to execute the computer program to implement the method disclosed in any of the foregoing embodiments.
[0121] Next, a readable storage medium provided by an embodiment of the present application will be introduced. The readable storage medium described below can be referred to in mutual reference with the message processing method, device, and equipment described above.
[0122] A readable storage medium, configured to store a computer program, wherein the computer program, when executed by a processor, implements the message processing method disclosed in the foregoing embodiments. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.
[0123] The "first", "second", "third", "fourth", etc. (if any) involved in this application are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods or devices.
[0124] It should be noted that the descriptions involving "first", "second", etc. in this application are only for descriptive purposes, and should not be construed as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement it. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0125] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0126] The steps of the method or algorithm described in connection with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of readable storage medium known in the technical field.
[0127] Specific examples are used in this article to elaborate on the principles and implementation manners of this application. The descriptions of the above embodiments are only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, based on the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A message processing method, characterized in that, Applied to the BGP proxy end in a network device, including: Receiving a first message sent by a neighbor device of the network device; If the first message carries a check option, and the neighbor device has established a communication connection with the main execution entity in the network device, and the first secret key of the neighbor device is locally recorded, then calculating the first check data of the first message; Sending the first message to at least one slave execution entity having a communication connection with the BGP proxy end based on the first check data, so that the at least one slave execution entity processes the first message; Wherein, the main execution entity and the slave execution entities are dynamically heterogeneous redundant execution entities; the BGP proxy end supports the rotation and online of execution entities. After any execution entity goes online again, the BGP proxy end simulates the neighbor device to establish a link with this execution entity, and sends a route update message through a configuration command to notify the neighbor device to re-send the route update.
2. The method according to claim 1, wherein The calculating the first check data of the first message includes: Constructing a pseudo-header based on the source IP address, destination IP address, protocol number, and TCP length of the first message; Obtaining the first secret key from the preset configuration information locally; Determining the TCP header fields and the message payload of the first message; Processing the pseudo-header, the first secret key, the TCP header fields, and the message payload by using the MD5 algorithm, and taking the obtained MD5 value as the first check data.
3. The method according to claim 1, characterized in that, The neighbor device establishing a communication connection with the main execution entity and the BGP proxy end establishing a communication connection with the at least one slave execution entity include: Receiving a link establishment message sent by the neighbor device; Storing the link establishment message, constructing the communication connection between the neighbor device and the main execution entity based on the link establishment message, and then constructing the communication connection between the BGP proxy end and the at least one slave execution entity based on the link establishment message.
4. The method according to claim 1, wherein The neighbor device disconnecting the communication connection with the main execution entity and the BGP proxy end disconnecting the communication connection with the at least one slave execution entity include: Receiving a link disconnection message sent by the neighbor device; Storing the link disconnection message, disconnecting the communication connection between the neighbor device and the main execution entity based on the link disconnection message, and then disconnecting the communication connection between the BGP proxy end and the at least one slave execution entity based on the link disconnection message.
5. The method according to claim 1, wherein The sending the first message to at least one slave execution entity having a communication connection with the BGP proxy end based on the first check data includes: Checking the check option by using the first check data; If the check option passes the check, then modifying some TCP header fields of the first message to obtain a first forwarding message, calculating the forwarding check data of the first forwarding message, encapsulating the forwarding check data into the first forwarding message, and then sending the first forwarding message encapsulated with the forwarding check data to the at least one slave execution entity; If the verification of the verification option fails, modify some TCP header fields of the first message to obtain a second forwarding message. After encapsulating the verification option into the second forwarding message, send the second forwarding message with the encapsulated verification option to the at least one slave executor.
6. The method according to any one of claims 1 to 5, characterized in that Further included: Receive a second message sent by any one of the at least one slave executor; Calculate the second verification data of the second message; If the verification of the verification option in the second message passes using the second verification data, read and process the second message; otherwise, disconnect the communication connection with the current slave executor.
7. The method according to any one of claims 1 to 5, characterized in that Further included: Receive and store a third message sent by the master executor; If the third message is a link establishment message and there is already a communication connection between the neighbor device and the master executor, retain the communication connection initiated by the party with the largest routing ID based on the third message, and delete other communication connections; If the third message is a link disconnection message, after disconnecting the communication connection between the neighbor device and the master executor based on the third message, disconnect the communication connection between the BGP proxy end and the at least one slave executor based on the third message.
8. A message processing device, characterized in that Applied to the BGP proxy end in a network device, including: A receiving module, configured to receive a first message sent by a neighbor device of the network device; A calculating module, configured to calculate the first verification data of the first message if the first message carries a verification option, and there is already a communication connection between the neighbor device and the master executor in the network device, and the first secret key of the neighbor device is locally recorded; A processing module, configured to send the first message to at least one slave executor having a communication connection with the BGP proxy end based on the first verification data, so that the at least one slave executor processes the first message; Wherein, the master executor and the slave executors are dynamically heterogeneous redundant executors; The BGP proxy end supports the rotation and online of executors. After any executor goes online again, the BGP proxy end simulates the neighbor device to establish a link with the executor, and sends a routing update message through a configuration command to notify the neighbor device to re-send the routing update.
9. An electronic device, characterized in that, Including: A memory, configured to store a computer program; A processor, configured to execute the computer program to implement the method according to any one of claims 1 to 7.
10. A readable storage medium, characterized in that, For saving a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
BGP message processing method and device of stack system
CN105591951A
Capability notification method and related equipment
CN113938403A