A PCEP protocol proxy method, device and equipment and readable storage medium

By processing and distributing PCEP protocol messages to heterogeneous execution entities, and combining this with a mimicry defense mechanism, security vulnerabilities in PCEP protocol communication are addressed, enabling defense against unknown threats and improving system security and stability.

CN116743454BActive Publication Date: 2026-04-21PURPLE MOUNTAIN LAB +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
PURPLE MOUNTAIN LAB
Filing Date
2023-06-09
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

The existing PCEP protocol communication has vulnerabilities and pre-installed backdoors. Attackers can use the PCEP protocol to calculate attacks and inject false information, causing communication paralysis. Existing security measures are insufficient to completely solve the security problem.

Method used

By acquiring the original PCEP protocol messages, processing them according to message attributes and chain establishment/dismantling information, generating target storage PCEP protocol messages and link message information, and copying and distributing them to heterogeneous executors, the mimicry defense mechanism is used to detect and clean up abnormal executors, thereby achieving defense against unknown threats.

Benefits of technology

It enhances the security of the PCEP protocol proxy, enabling it to cope with unknown threats, prevent further damage caused by unknown attacks, and maintain system stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743454B_ABST
    Figure CN116743454B_ABST
Patent Text Reader

Abstract

The application discloses a PCEP protocol agent method, device and equipment and a readable storage medium, and applies to the technical field of communication, and comprises the following steps: obtaining an original PCEP protocol message; processing a target message in the original PCEP protocol message according to a message attribute to obtain a target storage PCEP protocol message; processing a link establishment and disconnection message in the original PCEP protocol message according to link establishment and disconnection information to obtain link message information; and copying and distributing the target storage PCEP protocol message and the link message information to each heterogeneous executor. Compared with the current communication agent using the PCEP protocol, the original PCEP protocol message is processed, and then copied and distributed to each heterogeneous executor, so that the safety of the PCEP agent is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a PCEP protocol proxy method, apparatus, device, and readable storage medium. Background Technology

[0002] Currently, vulnerabilities and pre-installed backdoors in communication using the PCEP (Path Computation Element Communication Protocol) have seriously impacted network security. Attackers can use the PCEP communication protocol to perform calculations and inject false information, causing communication paralysis. As technology advances, attack methods are constantly evolving, and simply patching protocol vulnerabilities and adding security mechanisms is no longer sufficient to completely solve the security problems of communication using the PCEP protocol. Summary of the Invention

[0003] In view of this, the purpose of the present invention is to provide a PCEP protocol proxy method, apparatus, device and readable storage medium, which solves the technical problem of low security of PCEP protocol proxy in the prior art.

[0004] To address the aforementioned technical problems, this invention provides a PCEP protocol proxy method, comprising:

[0005] Obtain the original PCEP protocol message;

[0006] The target message in the original PCEP protocol message is processed according to the message attributes to obtain the target stored PCEP protocol message;

[0007] The link establishment and dismantling messages in the original PCEP protocol messages are processed based on the link establishment and dismantling information to obtain link message information;

[0008] The target storage PCEP protocol messages and the link message information are copied and distributed to each heterogeneous execution entity.

[0009] Optionally, the step of processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message includes:

[0010] The target sending entity corresponding to the target message is determined based on the message attributes; wherein, the target sending entity includes neighboring devices and heterogeneous execution entities;

[0011] The target message is processed according to the message type corresponding to the target sending entity to obtain the target stored PCEP protocol message.

[0012] Optionally, the step of processing the chain establishment and dismantling messages in the original PCEP protocol message according to the chain establishment and dismantling information to obtain link message information includes:

[0013] The connection information of the chain establishment and dismantling messages is determined based on the chain establishment and dismantling information.

[0014] Based on the connection information, establish and / or terminate the connection to obtain the link message information; wherein, the connection information includes the connection status and connection direction.

[0015] Optionally, the step of copying and distributing the target stored PCEP protocol messages and the link message information to each heterogeneous execution entity includes:

[0016] Modify the sequence field and acknowledgment character corresponding to the target stored PCEP protocol message and the link message information;

[0017] The modified target storage PCEP protocol message and link message information are encapsulated to obtain the encapsulated message;

[0018] The encapsulated message is copied and distributed to each heterogeneous execution entity.

[0019] Optionally, the step of processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message includes:

[0020] The target message is processed according to the message attributes to obtain the target stored PCEP protocol message; wherein, the message attributes include source IP, destination IP, source MAC and destination MAC.

[0021] Optionally, the step of processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message includes:

[0022] The target message is processed according to the message attributes to obtain the target stored PCEP protocol message; wherein, the target message includes PCEP update message, PCEP initialization message and PCEP response message.

[0023] Optionally, after copying and distributing the target stored PCEP protocol message and the link message information to each heterogeneous execution entity, the method further includes:

[0024] The dynamic heterogeneous redundancy framework components corresponding to each heterogeneous executor are adapted to the target PCEP protocol message; wherein, the target PCEP protocol message is a message that has established a PCEP connection with each heterogeneous executor.

[0025] The present invention also provides a PCEP protocol proxy device, comprising:

[0026] The original PCEP protocol message acquisition module is used to acquire the original PCEP protocol message;

[0027] The target message storage module is used to process the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message.

[0028] The link message information determination module is used to process the link establishment and dismantling messages in the original PCEP protocol message according to the link establishment and dismantling information to obtain the link message information.

[0029] The replication and distribution module is used to replicate and distribute the target stored PCEP protocol messages and the link message information to each heterogeneous execution entity.

[0030] The present invention also provides a PCEP protocol proxy device comprising:

[0031] Memory, used to store computer programs;

[0032] A processor is used to implement the PCEP protocol proxy method described above when executing the computer program.

[0033] The present invention also provides a computer-readable storage medium storing computer-executable instructions, which, when loaded and executed by a processor, implement the above-described PCEP protocol proxy method.

[0034] As can be seen, compared to current communication proxies that rely on known risks for protection, this invention processes the original PCEP protocol messages, enabling them to be distributed to various heterogeneous executors. Because these heterogeneous executors can identify anomalous executors through a heterogeneous execution process combined with an internal adjudication algorithm, and then use feedback and scheduling mechanisms to clean up and reschedule these anomalous executors, the system can effectively prevent further substantial damage caused by unknown threats in real time. Therefore, compared to existing PCEP protocol proxies that can only defend against known threats, the PCEP protocol proxy provided by this invention, which focuses on mimicry defense, can address unknown threats and improve the security of PCEP mimicry proxies.

[0035] In addition, the present invention also provides a PCEP protocol proxy device, equipment and readable storage medium, which also have the above-mentioned beneficial effects. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0037] Figure 1 A flowchart of a PCEP protocol proxy method provided in an embodiment of the present invention;

[0038] Figure 2 This is a system architecture diagram corresponding to a PCEP protocol proxy method provided in an embodiment of the present invention;

[0039] Figure 3 A flowchart illustrating the processing of a message analysis module is provided in an embodiment of the present invention.

[0040] Figure 4 This is an example diagram illustrating the processing flow of a connection state management module receiving a neighbor message, provided in an embodiment of the present invention.

[0041] Figure 5 This is an example diagram illustrating the processing flow of a connection state management module receiving a heterogeneous execution entity message, provided in an embodiment of the present invention.

[0042] Figure 6 This is a flowchart illustrating a replication and distribution process in a stable, mimicry environment, as provided in an embodiment of the present invention.

[0043] Figure 7 This invention provides a flowchart illustrating the replication and distribution process for newly launched heterogeneous execution entities.

[0044] Figure 8 This invention provides a schematic diagram of the structure of a PCEP protocol proxy device according to an embodiment of the present invention;

[0045] Figure 9 This is a schematic diagram of the structure of a PCEP protocol proxy device provided in an embodiment of the present invention. Detailed Implementation

[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0047] Please refer to Figure 1 , Figure 1 A flowchart illustrating a PCEP protocol proxy method provided in an embodiment of the present invention. The method may include:

[0048] S100, obtain the original PCEP protocol message.

[0049] This embodiment does not limit the specific method of obtaining the original PCEP (Path Computation Element Communication Protocol) protocol messages. For example, TCP (Transmission Control Protocol) messages can be obtained first, and then the original PCEP protocol messages can be selected from the TCP messages based on the port number; or the original PCEP protocol messages can be obtained by directly using a sniff tool to capture only the TCP messages containing port 4189 on the neighbor interface in the inbound direction.

[0050] S101, Process the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message.

[0051] This embodiment does not limit the specific message attributes. The message attributes in this embodiment can be the source IP address (Internet Protocol Address) and the destination IP address; or the message attributes can be the source MAC address (Media Access Control, physical address) and the destination MAC address; or the message attributes can be the TCP port number, TCP flags, and the PCEP message type. It is understood that, to improve security and accuracy, the target message in the original PCEP protocol message is processed based on the source IP, destination IP, source MAC, and destination MAC to obtain the target stored PCEP protocol message.

[0052] It should be noted that this embodiment does not limit the specific process of processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message. For example, it can determine whether the message came from a neighboring device (a neighboring device refers to other storage devices within the same local area network, such as computers, routers, storage devices, etc.) or from a heterogeneous execution entity (a heterogeneous execution entity is an important carrier for providing application services in the mimicry defense system) based on the message attributes. Messages from neighboring devices and heterogeneous entities can then be processed separately.

[0053] When the message attributes determine that the received message is from a neighboring device, the system directly filters for PCUpd (path computation update request, PCEP update message) messages within the neighboring messages (i.e., messages sent by the neighboring device). If it is a PCUpd message, the PLSP-ID (PCEP path identifier) ​​field is extracted. The PLSP-ID field is then compared with local storage to see if a PCUpd message has been previously stored. If it has not been stored locally, it is added to local storage; otherwise, local storage is updated. If it is a PCEP initialization message (i.e., a PCInitiate message) sent by a neighboring device, the Remove field is first extracted from the SRP object (Spatial Reuse Protocol, i.e., a stateful PCE request parameter object). The Remove field is then used to determine whether an addition or deletion operation is performed. For deletion operations, the PCInitiate packets are deleted from local storage based on the key fields Source IPv4 Address, Destination IPv4 Address, and SYMBOLIC-PATH-NAME. For addition operations, the PCInitiate packets are added to local storage based on the key fields Source IPv4 Address, Destination IPv4 Address, and SYMBOLIC-PATH-NAME. This embodiment is not limited to directly filtering packets received from neighboring devices based on packet attributes. For example, a mapping table can be set for filtering; or filtering can be performed one by one based on the Message Type field.

[0054] When the received message is determined to be a heterogeneous execution entity message based on the message attributes, the MessageType field of the PCEP header is parsed to determine if it is a PCRpt (Path Computation Reply) message. If it is a PCRpt message, the PLSP-ID field is extracted, and the PLSP-ID field is compared with local storage to see if the PCRpt message has been stored before. If it has not been stored locally, it is added to local storage; otherwise, it is updated. This entire process can be understood as a message analysis and processing procedure. It is understood that this step requires corresponding storage and deletion of messages because when a new heterogeneous execution entity comes online, the stored messages are needed to restore the configuration of the newly online heterogeneous execution entity. Other protocol proxies do not currently store these messages. The protocol proxy determines whether to save the original PCEP protocol message based on the above key fields. The saved message becomes the target stored PCEP protocol message. If the connection of a heterogeneous execution entity is subsequently lost, the saved target stored PCEP protocol message will be used to establish a connection.

[0055] Furthermore, to improve the accuracy of processing the original PCEP protocol messages, the above-mentioned processing of the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message may include:

[0056] The target sending entity corresponding to the target message is determined based on the message attributes; the target sending entity includes neighboring devices and heterogeneous execution entities.

[0057] The target message is processed according to the message type corresponding to the target sending subject to obtain the target stored PCEP protocol message.

[0058] This embodiment does not limit the specific message attributes. For example, the message attribute in this embodiment can be determined as an IP address; or the message attribute in this embodiment can also be a MAC address. It is understood that the IP addresses and MAC addresses of neighboring devices and heterogeneous execution entities are different, so the target sending entity corresponding to the target message can be determined based on the IP address and MAC address. This embodiment does not limit the specific type of the target message determined based on the message type. For example, the target message can be determined as a PCUpd (PCEP update message) message based on the message type; or the target message can be determined as a PCInitiate (PCEP initialization message) message based on the message type; or the target message can be determined as a PCRpt (PCEP response message) message based on the message type. It is understood that PCUpd, PCInitiate, and PCRpt messages are relatively critical messages in PCEP, so these three target messages are mainly processed. This embodiment does not limit the specific processing of the target message. For example, the target message can be deleted; or the target message can be stored; or the target message can be updated. This embodiment can improve the accuracy of processing original PCEP protocol messages because it can process target messages differently depending on the target sending entity.

[0059] Furthermore, to improve the accuracy of message processing, the above-mentioned processing of the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message may include:

[0060] The target message is processed according to its attributes to obtain the target stored PCEP protocol message; the message attributes include source IP, destination IP, source MAC and destination MAC.

[0061] It is understood that this embodiment processes packets based on source IP, destination IP, source MAC, and destination MAC simultaneously, making packet attributes more accurate and thus improving the accuracy of packet processing.

[0062] Furthermore, to improve processing efficiency, the above-mentioned processing of the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message may include:

[0063] The target message is processed according to its attributes to obtain the target PCEP protocol message for storage; the target message includes PCEP update message, PCEP initialization message and PCEP response message.

[0064] Understandably, PCUpd (PCEP update message), PCInitiate (PCEP initialization message), and PCEP response message (PCRpt) are key messages for the PCEP protocol proxy. Directly identifying these three messages as the target message can improve the efficiency of PCEP message processing.

[0065] S102, Process the chain establishment and dismantling messages in the original PCEP protocol messages according to the chain establishment and dismantling information to obtain the link message information.

[0066] This embodiment does not limit the specific chain establishment and dismantling information. For example, the chain establishment and dismantling information can be the PCEP protocol's open message for chain establishment (PCEP protocol chain establishment initial message); or the chain establishment and dismantling information can be the PCEP protocol's keepalive message for chain establishment (PCEP protocol keep-alive message). This embodiment does not limit the specific process of processing the chain establishment and dismantling messages in the original PCEP protocol message according to the chain establishment and dismantling information to obtain the link message information. For example, the link message information can be divided into a processing flow for receiving original PCEP protocol messages sent by neighboring devices and a processing flow for receiving original PCEP protocol messages sent by heterogeneous executors, depending on the sending entity. It is understood that the processing flow for receiving neighbor messages may include:

[0067] Step 1: Use a sniff tool to capture only TCP packets (raw PCEP protocol packets) on the incoming direction of the neighboring device's interface that contain port 4189.

[0068] Step 2: If the TCP connection establishment or disconnection message contains TCP SYN (TCP synchronization packet) / SYN+ACK (synchronization and acknowledgment packet) / ACK (acknowledgment) / FIN (end) / FIN+ACK (end acknowledgment packet), then store the TCP connection establishment or disconnection message for use in determining the TCP connection status with the TCP connection establishment and disconnection operations of heterogeneous executors.

[0069] Step 3: If it is an open / keepalive message for establishing a PCEP chain, save it for use when the protocol agent establishes a PCEP chain with a heterogeneous execution entity, to construct the PCEP open message (the initial message for establishing a PCEP chain) and keepalive message (the message for keeping the PCEP chain alive).

[0070] Step 4: If it is another message, it is necessary to check whether the heterogeneous executor has completed the chain establishment. If it has not been completed, the protocol proxy will not process these messages; if it has been completed, these messages will be distributed to the executor that has completed the chain establishment.

[0071] Furthermore, to improve the accuracy of link message processing, the link message information obtained by processing the link establishment and dismantling messages in the original PCEP protocol messages based on the link establishment and dismantling information may include:

[0072] Determine the connection information of the chain establishment and dismantling messages based on the chain establishment and dismantling information;

[0073] Based on the connection information, establish and / or terminate the connection to obtain link message information; the connection information includes connection status and connection direction.

[0074] This embodiment does not limit the specific chain establishment and dismantling information. For example, the chain establishment and dismantling information can be the PCEP protocol's open message for chain establishment (PCEP protocol chain establishment initial message); or the chain establishment and dismantling information can also be the PCEP protocol's keepalive message for chain establishment (PCEP protocol keep-alive message); or the chain establishment and dismantling information can also be the TCP chain establishment and dismantling message related to the PCEP protocol proxy. It should be noted that when the message is a TCP chain establishment and dismantling message related to the PCEP protocol proxy, other messages (messages other than TCP chain establishment and dismantling messages) are not processed. The TCP chain establishment and dismantling messages are used together with the neighbor's TCP chain establishment and dismantling messages to comprehensively analyze and determine the TCP connection status. If the TCP connection status is chain establishment successful, the protocol proxy determines whether it is necessary to initiate a TCP connection to the heterogeneous execution entity based on the TCP connection direction and initiates the PCEP chain establishment process; if the connection status is connection closed, the protocol proxy needs to initiate a chain disconnection operation to the heterogeneous execution entity that has already established a TCP connection. It is understood that this invention processes packets by combining connection status and connection direction, thus improving the accuracy of link packet processing. The TCP connection direction refers to whether the neighboring device actively connects to the heterogeneous execution entity or the heterogeneous execution entity actively connects to the neighboring device. If the neighboring device actively connects to the heterogeneous execution entity, the proxy needs to actively initiate a connection request to the heterogeneous execution entity. If the heterogeneous execution entity actively connects to the neighboring device, the proxy does not need to actively initiate a connection and can wait for the heterogeneous execution entity to initiate the connection.

[0075] S103, copy and distribute the target stored PCEP protocol messages and link message information to each heterogeneous execution entity.

[0076] This embodiment replicates and distributes the target stored PCEP protocol messages and link message information to each heterogeneous execution entity. This embodiment does not limit the specific replication and distribution process. For example, connections can be established with heterogeneous execution entities based on the stored target stored PCEP protocol messages and link message information; alternatively, the replication and distribution process could involve obtaining the service interface index and the source and destination MAC addresses for communication between the proxy and each heterogeneous execution entity, and then encapsulating a new Layer 2 header on top of the original PCEP protocol messages. Based on the locally stored heterogeneous execution entity messages, the corresponding seq (sequence number), ack (acknowledgment character), and other information are modified. The online status and connection status of each execution entity are traversed, and the newly encapsulated messages for each execution entity are sent from the corresponding port to each heterogeneous execution entity.

[0077] The replication and distribution process can also be:

[0078] Step 1: Obtain the stored TCP connection establishment message, modify the seq and ack information, encapsulate a new Layer 2 header, and establish a TCP connection with the newly launched heterogeneous execution entity.

[0079] Step 2: Obtain the stored PCEP connection establishment open and keepalive messages, modify the seq and ack information, encapsulate a new Layer 2 header, and establish a PCEP connection with the newly launched heterogeneous execution entity.

[0080] The newly launched heterogeneous execution entity in this step refers to a heterogeneous execution entity that has not yet established a connection. Because all steps are synchronous, some heterogeneous execution entities may have already established a connection with the PCEP protocol message during replication and distribution. Therefore, "newly launched heterogeneous execution entity" is used here. This also corresponds to the later phrase "maintaining consistency with other heterogeneous execution entities".

[0081] Step 3: Obtain the PCUpd, PCInitiate, and PCRpt messages related to the stored PCEP service, modify the seq and ack information, encapsulate a new Layer 2 header, and send them to the newly launched heterogeneous execution entity to ensure that the service data of the newly launched heterogeneous execution entity is consistent with that of other heterogeneous execution entities.

[0082] Understandably, by implementing a pseudo-proxy for the PCEP protocol, the security of the PCEP protocol is guaranteed in the event of an attack; at the same time, the processing of key PCEP messages makes the existence of heterogeneous execution entities imperceptible to the outside world.

[0083] Furthermore, to improve the efficiency of replication and distribution, the above-mentioned replication and distribution of the target stored PCEP protocol messages and link message information to various heterogeneous execution entities may include:

[0084] Modify the sequence field and acknowledgment character corresponding to the target stored PCEP protocol message and link message information;

[0085] The modified target storage PCEP protocol message and link message information are encapsulated to obtain the encapsulated message;

[0086] The encapsulated message is copied and distributed to various heterogeneous execution entities.

[0087] In this embodiment, the sequence field and acknowledgment character of the stored target PCEP protocol message and link message information are modified. The modified target PCEP protocol message and link message information are then encapsulated to obtain an encapsulated message. The encapsulated message is then copied and distributed to each heterogeneous execution entity. It is understood that if the message is not encapsulated, there may be situations where connections cannot be established with heterogeneous execution entities. To ensure connections with heterogeneous execution entities, it is necessary to modify and encapsulate the sequence field and acknowledgment character corresponding to the target stored PCEP protocol message and link message information. It should be noted that the purpose of this step is to ensure that the original message can be sent to each heterogeneous execution entity. If no new Ethernet header is added, the Ethernet header of the original message needs to be modified. After receiving the message, the heterogeneous execution entity will remove the newly added Ethernet header, leaving the original message, which the heterogeneous execution entity can then process.

[0088] Furthermore, to enhance the security of defense using a mimicry architecture, after copying and distributing the target stored PCEP protocol messages and link message information to various heterogeneous execution entities, the following may also be included:

[0089] The dynamic heterogeneous redundancy framework components corresponding to each heterogeneous executor are adapted to the target PCEP protocol messages; wherein, the target PCEP protocol messages are messages that have established PCEP connections with each heterogeneous executor.

[0090] Understandably, the environment of heterogeneous executors can affect defense effectiveness. Therefore, it is necessary to adapt the dynamic heterogeneous redundant framework components to the business system to achieve anomaly detection and mitigation. After adaptation, components within the heterogeneous executor can interact and negotiate with PCEP protocol messages.

[0091] The PCEP protocol proxy method provided in this invention includes: acquiring the original PCEP protocol message; processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message; processing the chain establishment and dismantling messages in the original PCEP protocol message according to the chain establishment and dismantling information to obtain the link message information; and copying and distributing the target stored PCEP protocol message and the link message information to various heterogeneous execution entities. It can be seen that, compared with the current approach of using the PCEP protocol for communication proxy, which relies on preventing known risks, this invention processes the original PCEP protocol message, enabling it to be distributed to various heterogeneous execution entities. Since heterogeneous execution entities can perceive disturbances through their heterogeneous execution processes combined with a unique adjudication algorithm, and then use feedback and scheduling mechanisms to clean up and schedule abnormal heterogeneous execution entities, this ensures that when the system suffers from unknown threat attacks, it can terminate further substantial damage caused by threat exploitation in real time. Because it doesn't require disconnecting from neighboring clients or having clients send messages to refresh data, the existence of the mimicry architecture is imperceptible externally. Therefore, this invention elevates a solution that only defends against known threats to a PCEP mimicry proxy method capable of handling unknown threats. Furthermore, it can process target messages differently depending on the target sender, improving the accuracy of processing original PCEP protocol messages; it also processes messages based on source IP, destination IP, source MAC, and destination MAC, making message attributes more accurate; it combines connection status and connection direction to improve the accuracy of link message processing; it modifies and encapsulates the sequence fields and acknowledgment characters corresponding to the target stored PCEP protocol messages and link message information, ensuring successful connection establishment with heterogeneous executors; and it adapts and tests the dynamic heterogeneous redundancy framework components with the business system to achieve anomaly detection and mitigation.

[0092] For a clearer understanding of this invention, please refer to the following details. Figure 2 , Figure 2 The system architecture diagram corresponding to the PCEP protocol proxy method provided in this embodiment of the invention may specifically include:

[0093] The message analysis and processing module is used to analyze the source and attributes of messages, and then store and delete the messages.

[0094] The connection status management module is used to manage the connection status of messages.

[0095] The message replication and distribution module is used to replicate and distribute messages processed by the message analysis and processing module and the connection state management module to various heterogeneous execution entities, as well as to receive messages sent by various heterogeneous execution entities.

[0096] It should be noted that the message analysis and processing module in this embodiment corresponds to processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message. The connection state management module in this embodiment corresponds to processing the connection establishment and disconnection messages in the original PCEP protocol message according to the connection establishment and disconnection information to obtain the link message information. The connection state management message includes the connection initiation message of TCP itself and the connection initiation message of PCEP protocol itself. The message replication and distribution module in this embodiment corresponds to replicating and distributing the target stored PCEP protocol message and the link message information to each heterogeneous execution entity.

[0097] For a clearer understanding of this invention, please refer to the following details. Figure 3 , Figure 3 A flowchart illustrating the processing of a message analysis module provided in this embodiment of the invention may specifically include:

[0098] Step 1: Use a sniffing tool to capture TCP (Transmission Control Protocol) packets containing the path calculation unit communication protocol port number.

[0099] The message analysis module in this embodiment corresponds to a system architecture item in a PCEP protocol proxy method. The TCP (Transmission Control Protocol) message in this embodiment is a TCP message with a fixed port number of 4189.

[0100] Step 2: Determine the message sender based on the source Internet Protocol address, destination Internet Protocol address, source physical address, and destination physical address of the Transmission Control Protocol (TCP) message; the message sender includes neighboring devices and heterogeneous execution entities.

[0101] Step 3: When the sender is a neighboring device, parse the message type field, store or update the PCUpd message, and delete or add the PCInitiate message.

[0102] In this embodiment, upon receiving a TCP packet from a neighboring device, the Message Type field of the PCEP header is parsed to determine if it is a PCUpd packet (PCEP update packet). If it is a PCUpd packet, the PLSP-ID field (PCEP path identifier) ​​is extracted. The PLSP-ID field is compared with local storage to see if it has been previously stored. If the PCUpd packet is not stored locally, it is added to local storage; otherwise, it is updated. Similarly, upon receiving a packet from a neighboring device, the Message Type field of the PCEP header is parsed to determine if it is a PCInitiate packet. If it is a PCInitiate packet (PCEP initialization packet), the Remove field is extracted from the SRP object (Spatial Reuse Protocol object, i.e., a stateful PCE request parameter object). The Remove field is used to determine whether the operation is an addition or deletion. If it is a deletion operation, the local storage is deleted based on the key fields Source IPv4 Address, Destination IPv4 Address, and SYMBOLIC-PATH-NAME. If it is an addition operation, the local storage is added based on the key fields Source IPv4 Address, Destination IPv4 Address, and SYMBOLIC-PATH-NAME.

[0103] Step 4: When the sending entity is a heterogeneous executor, parse the message type field and store or update the PCRpt message.

[0104] In this embodiment, upon receiving a heterogeneous execution entity message, the Message Type field of the PCEP header is parsed to determine whether it is a PCRpt message (PCEP response message). If it is a PCRpt message, the PLSP-ID field is extracted, and the PLSP-ID field is compared with the local storage to see if the PCRpt message has been stored before. If it has not been stored locally, it is added to the local storage; if it has been stored locally, the local storage is updated.

[0105] In this embodiment, the message analysis module needs to store PCInitiate messages, PCRpt messages, and PCUpd messages.

[0106] For a clearer understanding of this invention, please refer to the following details. Figure 4 , Figure 4 An example diagram illustrating the processing flow of a connection state management module receiving a neighbor message, provided in an embodiment of the present invention, may specifically include:

[0107] It should be noted that, for ease of understanding, the following steps are consistent with... Figure 4 The flowchart shown is basically the corresponding text flowchart example.

[0108] Step 1: Use a sniff tool to capture TCP packets containing port 4189 in the inbound direction on the neighboring interface.

[0109] It is understandable that the PCEP protocol port number is 4189, and this invention is specifically designed for the PCEP protocol.

[0110] Step 2: Determine if it is a link establishment / removal message.

[0111] Step 3: If the message is a TCP SYN (synchronization) / SYN+ACK (synchronization and acknowledgment) / ACK (acknowledgment) / FIN (end) / FIN+ACK (end and acknowledgment), then store the message for use in determining the TCP connection status with the TCP connection establishment and dismantling operations of heterogeneous executors.

[0112] Step 4: When the connection status is determined to be successful, establish a connection with the heterogeneous execution entity based on the stored message.

[0113] Step 5: When it is determined that the connection status is a connection failure, the connection with the heterogeneous execution body is broken according to the stored message, and the corresponding connection table entry is deleted.

[0114] Step 6: If it is an open / keepalive message for establishing a chain using the PCEP protocol, save it for use when the protocol proxy establishes a chain with a heterogeneous executor using PCEP, to construct the PCEP open message (the initial message for establishing a chain using the PCEP protocol) and keepalive message (the message for keeping alive using the PCEP protocol).

[0115] Step 7: If it is not a chain-building or chain-breaking message, it is necessary to check whether the heterogeneous executor has completed the chain building. If it has not been completed, the protocol proxy will not process these messages; if it has been completed, these messages will be distributed to other executors.

[0116] For a clearer understanding of this invention, please refer to the following details. Figure 5 , Figure 5 This invention provides an example flowchart of a connection state management module receiving a heterogeneous execution entity message, which may specifically include:

[0117] It should be noted that, for ease of understanding, the following steps are consistent with... Figure 5 The flowchart shown is basically the corresponding text flowchart example.

[0118] Step 1: Use a sniffing tool to capture Transmission Control Protocol (TCP) messages containing the path calculation unit's communication protocol port number.

[0119] Step 2: Determine the execution process based on the message source.

[0120] This embodiment can determine whether the source of a packet belongs to a heterogeneous execution entity based on the source IP, destination IP, source MAC, and destination MAC encapsulation information of the packet.

[0121] Step 3: When a message comes from a heterogeneous execution entity, the PCEP protocol agent stores the message and updates the connection status.

[0122] Understandably, in this embodiment, if the message originates from a heterogeneous execution entity, the PCEP protocol proxy only cares about the TCP connection establishment and dismantling messages, and does not process other messages. It uses the TCP connection establishment and dismantling messages together with the neighbor's TCP connection establishment and dismantling messages to comprehensively analyze and determine the TCP connection status. If the TCP connection is successfully established, the protocol proxy determines whether it is necessary to initiate a TCP connection to other heterogeneous execution entities based on the TCP connection direction and initiates the PCEP connection establishment process. If the connection is closed, the protocol proxy needs to initiate a disconnection operation to the heterogeneous execution entity with which the TCP connection has already been established.

[0123] Step 4: If the message does not originate from a heterogeneous execution entity, but is from another entity, then discard the message.

[0124] For a clearer understanding of this invention, please refer to the following details. Figure 6 , Figure 6 A flowchart illustrating a replication and distribution process in a stable, mimicry environment, provided as an embodiment of the present invention, may specifically include:

[0125] It should be noted that this embodiment corresponds to the message replication and distribution module and is an example of the message replication and distribution steps.

[0126] S600, obtain the service message corresponding to the PCEP protocol.

[0127] S601 obtains the interface index corresponding to the service message, as well as the source physical address and destination physical address for communication between the proxy protocol and each heterogeneous execution entity. It then encapsulates a new Layer 2 header on the basis of the original message to obtain the initial encapsulated message.

[0128] S602, based on the locally stored heterogeneous execution body message, modify the corresponding sequence and acknowledgment character of the initial encapsulated message to obtain the first target encapsulated message.

[0129] S603 iterates through the online and connection status of each heterogeneous execution entity and sends the first target encapsulated message from the corresponding port to each heterogeneous execution entity.

[0130] Understandably, the main steps of this embodiment are as follows: First, determine whether the TCP packet needs to be distributed to heterogeneous executors based on the packet attributes. Second, obtain the business interface index and the source and destination MAC addresses for communication between the proxy and each heterogeneous executor. Third, encapsulate a new Layer 2 header on top of the original packet. Fourth, modify the corresponding seq, ack, and other information based on the locally stored heterogeneous executor packets. Fifth, traverse the online and connection status of each executor and send the newly encapsulated packet for each executor from the corresponding port to each heterogeneous executor.

[0131] For a clearer understanding of this invention, please refer to the following details. Figure 7 , Figure 7 This invention provides a flowchart illustrating the replication and distribution process for newly launched heterogeneous execution entities, which may specifically include:

[0132] It should be noted that this embodiment corresponds to the message replication and distribution module and is an example of the message replication and distribution steps.

[0133] The S700 retrieves the stored TCP connection establishment message, modifies the seq and ack information, encapsulates a new Layer 2 header, and establishes a TCP connection with the newly launched heterogeneous execution entity.

[0134] S701 retrieves the stored PCEP connection establishment open and keepalive messages, modifies the seq and ack information, encapsulates a new Layer 2 header, and establishes a PCEP connection with the newly launched heterogeneous execution entity.

[0135] S702 retrieves the PCUpd, PCInitiate, and PCRpt messages related to the stored PCEP service, modifies the seq and ack information, encapsulates a new Layer 2 header, and sends it to the newly launched heterogeneous execution entity, ensuring that the service data of the newly launched heterogeneous execution entity remains consistent with that of other heterogeneous execution entities.

[0136] Understandably, the main steps of this embodiment are as follows: First, obtain the stored TCP connection establishment message, modify the seq and ack information, encapsulate a new Layer 2 header, and establish a TCP connection with the newly launched heterogeneous execution entity. Second, obtain the stored PCEP connection establishment open and keepalive messages, modify the seq and ack information, encapsulate a new Layer 2 header, and establish a PCEP connection with the newly launched heterogeneous execution entity. Third, obtain the stored PCEP service-related PCUpd, PCInitiate, and PCRpt messages, modify the seq and ack information, encapsulate a new Layer 2 header, and send them to the newly launched heterogeneous execution entity, ensuring that the service data of the newly launched heterogeneous execution entity remains consistent with that of other heterogeneous execution entities.

[0137] For ease of understanding, please refer to Table 1. Table 1 is an example diagram of a new layer 2 header encapsulation. In this diagram, the layer 2 protocol number of fptun is 0x2007, which is a layer 2 protocol number associated with the original message and includes data transmission information. It is typically 28 bytes long.

[0138] Table 1. Example diagram of a new type of double-layer header encapsulation.

[0139] New Ethernet header fptun head Original Ethernet header Ethernet load

[0140] The following describes a PCEP protocol proxy device provided by an embodiment of the present invention. The PCEP protocol proxy device described below and the PCEP protocol proxy method described above can be referred to and correspond to each other.

[0141] Please refer to the details. Figure 8 , Figure 8 A schematic diagram of a PCEP protocol proxy device provided in an embodiment of the present invention may include:

[0142] The original PCEP protocol message acquisition module 100 is used to acquire the original PCEP protocol message;

[0143] The target message storage module 200 is used to process the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message.

[0144] The link message information determination module 300 is used to process the link establishment and dismantling messages in the original PCEP protocol message according to the link establishment and dismantling information to obtain the link message information.

[0145] The replication and distribution module 400 is used to replicate and distribute the target stored PCEP protocol messages and the link message information to each heterogeneous execution entity.

[0146] Furthermore, based on the above embodiments, the target message storage module 200 may include:

[0147] A target sending entity determination unit is used to determine the target sending entity corresponding to the target message based on the message attributes; wherein, the target sending entity includes neighboring devices and heterogeneous execution entities;

[0148] The target message storage unit is used to process the target message according to the message type corresponding to the target sending subject to obtain the target stored PCEP protocol message.

[0149] Furthermore, based on any of the above embodiments, the link message information determination module 300 may include:

[0150] A link message information determination unit is used to determine the connection information of the link establishment and dismantling message based on the link establishment and dismantling information.

[0151] The link message information determination unit is used to perform link establishment and / or link termination operations based on the connection information to obtain the link message information; wherein, the connection information includes connection status and connection direction.

[0152] Furthermore, based on any of the above embodiments, the copy distribution module 400 may include:

[0153] The message information modification unit is used to modify the sequence field and acknowledgment character corresponding to the target stored PCEP protocol message and the link message information;

[0154] The encapsulation unit is used to encapsulate the modified target storage PCEP protocol message and link message information to obtain the encapsulated message;

[0155] The copy and distribution unit is used to copy and distribute the encapsulated message to each heterogeneous execution entity.

[0156] Furthermore, based on any of the above embodiments, the target message storage module 200 may include:

[0157] The target message processing unit is used to process the target message according to the message attributes to obtain the target stored PCEP protocol message; wherein, the message attributes include source IP, destination IP, source MAC and destination MAC.

[0158] Furthermore, based on any of the above embodiments, the target message storage module 200 may include:

[0159] The feature target message processing unit is used to process the target message according to the message attributes to obtain the target stored PCEP protocol message; wherein, the target message includes PCEP update message, PCEP initialization message and PCEP response message.

[0160] Furthermore, based on any of the above embodiments, the PCEP protocol proxy device may further include:

[0161] An adaptation module is used to adapt the dynamic heterogeneous redundancy framework components corresponding to each heterogeneous execution entity to the target PCEP protocol message; wherein, the target PCEP protocol message is a message that has established a PCEP connection with each heterogeneous execution entity.

[0162] It should be noted that the order of the modules and units in the aforementioned PCEP protocol proxy device can be changed without affecting the logic.

[0163] The PCEP protocol proxy device provided in this embodiment of the invention may include: an original PCEP protocol message acquisition module 100, used to acquire original PCEP protocol messages; a target message storage module 200, used to process target messages in the original PCEP protocol messages according to message attributes to obtain target stored PCEP protocol messages; a link message information determination module 300, used to process link establishment and dismantling messages in the original PCEP protocol messages according to link establishment and dismantling information to obtain link message information; and a replication and distribution module 400, used to replicate and distribute the target stored PCEP protocol messages and the link message information to various heterogeneous execution entities. It can be seen that, compared with the current approach of using the PCEP protocol for communication proxy, which relies on known risks for prevention, this invention processes the original PCEP protocol messages, enabling them to be distributed to various heterogeneous execution entities. Since heterogeneous execution entities can perceive disturbances through heterogeneous execution processes combined with unique adjudication algorithms, and then use feedback and scheduling mechanisms to clean and schedule abnormal processing units online and offline, it ensures that the system can terminate further substantial damage caused by threat exploitation in real time when subjected to unknown threat attacks. Therefore, this invention extends the security of PCEP mimicry proxies from defending against known threats to being able to handle unknown threats. Furthermore, it can process target packets differently depending on the target sender, improving the accuracy of processing original PCEP protocol packets; it also processes packets based on source IP, destination IP, source MAC, and destination MAC, making packet attributes more accurate; it further improves the accuracy of link packet processing by combining connection status and connection direction; it modifies and encapsulates the sequence fields and acknowledgment characters corresponding to the target stored PCEP protocol packets and link packet information, ensuring successful connection establishment with heterogeneous executors; and it adapts and tests the dynamic heterogeneous redundancy framework components with the business system to achieve anomaly detection and mitigation.

[0164] The following describes a PCEP protocol proxy device provided by an embodiment of the present invention. The PCEP protocol proxy device described below and the PCEP protocol proxy method described above can be referred to in correspondence.

[0165] Please refer to Figure 9 , Figure 9 A schematic diagram of a PCEP protocol proxy device provided in an embodiment of the present invention may include:

[0166] Memory 10 is used to store computer programs;

[0167] Processor 20 is used to execute computer programs to implement the PCEP protocol proxy method described above.

[0168] The memory 10, processor 20, and communication interface 30 all communicate with each other through the communication bus 40.

[0169] In this embodiment of the invention, the memory 10 is used to store one or more programs. The programs may include program code, which includes computer operation instructions. In this embodiment of the invention, the memory 10 may store programs for implementing the following functions:

[0170] Obtain the original PCEP protocol message;

[0171] The target message in the original PCEP protocol message is processed according to the message attributes to obtain the target stored PCEP protocol message;

[0172] Based on the chain establishment and dismantling information, the chain establishment and dismantling messages in the original PCEP protocol messages are processed to obtain the link message information;

[0173] The target storage PCEP protocol messages and link message information are copied and distributed to various heterogeneous execution entities.

[0174] In one possible implementation, the memory 10 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and applications required for at least one function; and the data storage area may store data created during use.

[0175] Furthermore, memory 10 may include read-only memory and random access memory, providing instructions and data to the processor. A portion of the memory may also include NVRAM. The memory stores operating systems and operating instructions, executable modules, or data structures, or subsets thereof, or extended sets thereof, wherein the operating instructions may include various operating instructions for implementing various operations. The operating system may include various system programs for implementing various basic tasks and handling hardware-based tasks.

[0176] Processor 20 can be a central processing unit (CPU), an application-specific integrated circuit, a digital signal processor, a field-programmable gate array, or other programmable logic device. Processor 20 can be a microprocessor or any conventional processor. Processor 20 can call programs stored in memory 10.

[0177] The communication interface 30 can be an interface for the communication module, used to connect with other devices or systems.

[0178] Of course, it should be noted that, Figure 9 The structure shown does not constitute a limitation on the PCEP protocol proxy device in the embodiments of the present invention. In practical applications, a PCEP protocol proxy device may include more than Figure 9 More or fewer components as shown, or combinations of certain components.

[0179] The readable storage medium provided in the embodiments of the present invention is described below. The readable storage medium described below can be referred to in correspondence with the PCEP protocol proxy method described above.

[0180] The present invention also provides a readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the PCEP protocol proxy method described above.

[0181] The readable storage medium may include various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0182] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0183] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0184] Finally, it should be noted that in this document, relationships such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0185] The foregoing has provided a detailed description of a PCEP protocol proxy method, apparatus, device, and readable storage medium provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A PCEP protocol proxy method, characterized in that, include: Obtain the original PCEP protocol message; The target message in the original PCEP protocol message is processed according to the message attributes to obtain the target stored PCEP protocol message; The message attributes include source IP, destination IP, source MAC, and destination MAC; The connection information of the link establishment and disconnection messages is determined based on the link establishment and disconnection information, and the link establishment and / or disconnection operations are performed based on the connection information to obtain the link message information; wherein, the connection information includes the connection status and connection direction, and the connection direction refers to whether the neighboring device actively connects to the heterogeneous execution entity or the heterogeneous execution entity actively connects to the neighboring device. The target storage PCEP protocol messages and the link message information are copied and distributed to each heterogeneous execution entity; Specifically, when the received message is determined to be from a neighboring device based on the message attributes, if it is a PCUpd message from a neighboring device, the PLSP-ID field in the PCUpd message is extracted. The PLSP-ID field is compared with local storage to determine if a PCUpd message has been previously stored. If not, it is added to local storage; otherwise, it is updated. If the received message is a PCEP initialization message from a neighboring device, the delete field in the space reuse protocol object of the PCEP initialization message is extracted. The delete field determines whether an operation is added or deleted. If it is deleted, the PCEP initialization message is deleted from local storage based on the source IP address, destination IP address, and specified path name. If it is added, the PCEP initialization message is added to local storage based on the source IPv4 address, destination IPv4 address, and SYMBOLIC-PATH-NAME. When the message attributes determine that the received message is a heterogeneous execution entity message, the message type field of the PCEP header in the heterogeneous execution entity message is parsed to determine whether it is a PCEP response message. If it is a PCEP response message, the PLSP-ID field in the PCEP response message is extracted. The PLSP-ID field is compared with the local storage to determine whether the PCEP response message has been stored before. If it has not been stored locally, it is added to the local storage; if it has been stored locally, the local storage is updated.

2. The PCEP protocol proxy method according to claim 1, characterized in that, The step of processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message includes: The target sending entity corresponding to the target message is determined based on the message attributes; wherein, the target sending entity includes neighboring devices and heterogeneous execution entities; The target message is processed according to the message type corresponding to the target sending entity to obtain the target stored PCEP protocol message.

3. The PCEP protocol proxy method according to any one of claims 1 to 2, characterized in that, The step of copying and distributing the target stored PCEP protocol messages and the link message information to each heterogeneous execution entity includes: Modify the sequence field and acknowledgment character corresponding to the target stored PCEP protocol message and the link message information; The modified target storage PCEP protocol message and link message information are encapsulated to obtain the encapsulated message; The encapsulated message is copied and distributed to each heterogeneous execution entity.

4. The PCEP protocol proxy method according to claim 1, characterized in that, The step of processing the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message includes: The target message is processed according to the message attributes to obtain the target stored PCEP protocol message; wherein, the target message includes PCEP update message, PCEP initialization message and PCEP response message.

5. The PCEP protocol proxy method according to claim 1, characterized in that, After copying and distributing the target stored PCEP protocol message and the link message information to each heterogeneous execution entity, the method further includes: The dynamic heterogeneous redundancy framework components corresponding to each heterogeneous executor are adapted to the target PCEP protocol message; wherein, the target PCEP protocol message is a message that has established a PCEP connection with each heterogeneous executor.

6. A PCEP protocol proxy device, characterized in that, The PCEP protocol proxy method according to any one of claims 1 to 5 includes: The original PCEP protocol message acquisition module is used to acquire the original PCEP protocol message; The target message storage module is used to process the target message in the original PCEP protocol message according to the message attributes to obtain the target stored PCEP protocol message. The link message information determination module is used to process the link establishment and dismantling messages in the original PCEP protocol message according to the link establishment and dismantling information to obtain the link message information. The replication and distribution module is used to replicate and distribute the target stored PCEP protocol messages and the link message information to each heterogeneous execution entity.

7. A PCEP protocol proxy device, characterized in that, include: Memory, used to store computer programs; A processor for implementing the PCEP protocol proxy method as described in any one of claims 1 to 5 when executing the computer program.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when loaded and executed by a processor, implement the PCEP protocol proxy method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Protocol agent processing method and system based on mimicry defense

    CN111416865A

  • Message processing method and system

    CN112019491A