Packet security policy matching method and device, electronic equipment and storage medium

CN117294516BActive Publication Date: 2026-09-29WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311356164.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-18
Publication Date
2026-09-29
Estimated Expiration
2043-10-18

AI Technical Summary

Technical Problem

但随着查询表中表项数量的增加,查询时间也会随之增加,如当表项增加一倍,则匹配的时间也会增加一倍,导致报文安全策略的匹配效率较低

Benefits of technology

通过配置本地元组排序表和安全策略地址索引表,可以针对目标五元组中各个目标元素,在本地元组排序表进行二分查找,以确定各个目标元素对应的符合项,进而可以通过安全策略地址索引表,分析与各个目标元素相匹配的安全策略的地址范围,以确定各个目标元素对应的第一索引信息,进而基于各个目标元素对应的第一索引信息,能够匹配报文的安全策略。由于采用二分查找,可以避免对本地查询表中的各个表项进行逐项分析,能够将五元组的范围匹配周期由表项数Num降低为Log2Num,降低匹配的时钟周期,提高报文安全策略的匹配效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117294516B_ABST
    Figure CN117294516B_ABST
Patent Text Reader

Abstract

The application provides a message security policy matching method and device, electronic equipment and a storage medium, and belongs to the technical field of computers.The method comprises the following steps: based on a target message, extracting a target five-tuple; for each target element in the target five-tuple, based on the target element and a local tuple sorting table, determining a matching item corresponding to the target element through binary search; based on a security policy address index table and the matching item corresponding to each target element, determining first index information corresponding to each target element, the first index information being used to represent an address range of a security policy matched with the target element; and based on the first index information corresponding to each target element, matching the security policy of the target five-tuple. By using binary search, each table item in the local query table is prevented from being analyzed item by item, the range matching period of the five-tuple is reduced from the table item number Num to Log2Num, and the matching efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer technology, and more specifically, relates to a message security policy matching method, apparatus, electronic device, and storage medium. Background Technology

[0002] With the rapid popularization of the Internet and the increasing demand for multimedia services, network link speeds have reached 10Gb / s or even higher. Therefore, researching high-speed routing lookup algorithms is crucial for designing routers that meet these network requirements.

[0003] In related technologies, a common approach is to use 5-tuple range matching to analyze each entry in a local lookup table to match the security policy of a message. However, as the number of entries in the lookup table increases, the query time also increases. For example, if the number of entries doubles, the matching time also doubles, resulting in low efficiency in matching message security policies. Summary of the Invention

[0004] To address the problems existing in the prior art, embodiments of the present invention provide a message security policy matching method, apparatus, electronic device, and storage medium.

[0005] In a first aspect, the present invention provides a message security policy matching method, comprising: Extract the target quintuple based on the target message; For each target element in the target quintuple, based on the target element and the local tuple sorting table, a binary search is used to determine the matching item corresponding to the target element. The local tuple sorting table is determined by sorting each element of the local tuple according to the element category and the element value. The matching item is the element with the smallest difference in value between the matching elements of the same category in the local tuple sorting table and the target element. Based on the security policy address index table and the corresponding entries for each target element, the first index information corresponding to each target element is determined. The security policy address index table is used to characterize the correspondence between each element of the local tuple and the storage address of the security policy. The first index information is used to characterize the address range of the security policy that matches the target element. Based on the first index information corresponding to each of the target elements, the security policy of the target quintuple is matched.

[0006] Optionally, according to a message security policy matching method provided by the present invention, the local tuple sorting table includes a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local maximum value element sorting sub-table is determined by sorting the maximum value elements belonging to the same category in descending order, and the maximum value element is used to indicate the upper limit of the value. The local minimum value element sorting sub-table is determined by sorting the minimum value elements belonging to the same category in ascending order, and the minimum value element is used to indicate the lower limit of the value. The matching items corresponding to the target element include maximum value matching items and minimum value matching items. The step of determining the matching item corresponding to the target element through binary search based on the target element and the local tuple sorting table includes: Based on the target element and the sorted sub-table of local maximum value tuple elements corresponding to the element category to which the target element belongs, the maximum value matching item corresponding to the target element is determined by binary search; Based on the target element and the local minimum value element sorting sub-table corresponding to the element category to which the target element belongs, the minimum value matching item corresponding to the target element is determined by binary search.

[0007] Optionally, according to a message security policy matching method provided by the present invention, the security policy address index table includes: an index sub-table corresponding to each sorted sub-table in the local tuple sorting table, wherein an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, the sub-table of the local tuple sorting table and the corresponding index sub-table adopt the same sorting method, and the index sub-table is used to group and store each index item in the table based on the number of index items in a preset group and the corresponding sorting method; For the index groups in the index sub-table, the first J bits of each index entry in the (N+1)th index group are determined based on the number of index entries in the preset group and the security policy address range defined by the Nth index group. The first J bits of each index entry in the 1st index group are 0. The last I bits of each index entry in the index group are determined based on the storage address of the corresponding security policy of the corresponding element in the sub-table of the local tuple sorting table. N is a positive integer, and the number of bits in one index entry is J+I. The step of determining the first index information corresponding to each target element based on the security policy address index table and the corresponding matching items of each target element includes: Based on the maximum value matching item and the minimum value matching item corresponding to the target element, and the index sub-table corresponding to the element category to which the target element belongs, determine the first index group corresponding to the maximum value matching item and the second index group corresponding to the minimum value matching item; The first J bits of each index entry in the first index group are concatenated to determine the address range of the first security policy, and the first J bits of each index entry in the second index group are concatenated to determine the address range of the second security policy. The address range of the third security policy is determined based on the last I bit values ​​of each index entry in the first index group, and the address range of the fourth security policy is determined based on the last I bit values ​​of each index entry in the second index group. Based on the first security policy address range and the third security policy address range, a fifth security policy address range adapted to the maximum value conformance item is determined; and based on the second security policy address range and the fourth security policy address range, a sixth security policy address range adapted to the minimum value conformance item is determined. Based on the address range of the fifth security policy and the address range of the sixth security policy, an AND operation is performed to determine the first index information corresponding to the target element.

[0008] Optionally, according to a message security policy matching method provided by the present invention, the step of matching the security policy of the target quintuple based on the first index information corresponding to each of the target elements includes: Based on the first index information corresponding to each of the target elements, a bitwise AND operation is performed to determine the second index information; Based on the second index information, determine one or more security policies that match the target quintuple; Based on a preset priority configuration, security policies that match the target quintuple are filtered to determine the security policy for the target quintuple.

[0009] Optionally, according to a message security policy matching method provided by the present invention, the local tuple sorting table includes a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local tuple sorting table is obtained through the following steps: Based on a pre-configured query table, the maximum value elements belonging to the same category are sorted in descending order to determine the local maximum value element sorting sub-table for each element category. The maximum value element is used to indicate the upper limit of the value. Based on a pre-configured query table, the minimum value elements belonging to the same category are sorted in ascending order to determine the local minimum value element sorting sub-table for each element category. The minimum value element is used to indicate the lower limit of the value. The query table includes multiple entries, and each entry includes an element representing the upper limit of the quintuple value, an element representing the lower limit of the quintuple value, and a security policy address corresponding to the entry.

[0010] Optionally, according to the message security policy matching method provided by the present invention, the security policy address index table is obtained through the following steps: Based on the storage addresses of each sorted sub-table in the local tuple sorting table and the corresponding security policies of each element in the sorted sub-table, an index sub-table corresponding to each sorted sub-table in the local tuple sorting table is determined. Based on each of the index sub-tables, the security policy address index table is determined; In this system, an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, and the sub-tables of the local tuple sorting table and the corresponding index sub-tables use the same sorting method.

[0011] Optionally, according to a message security policy matching method provided by the present invention, determining the index sub-table corresponding to each sorted sub-table in the local tuple sorting table based on each sorted sub-table in the local tuple sorting table and the storage address of the corresponding security policy of each element in the sorted sub-table includes: For any target sorted sub-table, based on the preset number of index items in the group, the elements in the target sorted sub-table are grouped in order to determine multiple element groups; Based on the storage address of the corresponding security policy of each element in the first element group, determine the last I bit value of each index entry in the first index group, and determine the security policy address range limited by the first index group. The first J bits of each index entry in the first index group are 0. Based on the number of index entries in the preset group and the security policy address range defined by the Nth index group, determine the first J bit values ​​of each index entry in the N+1th index group, and based on the storage address of the corresponding security policy of each element in the N+1th element group, determine the last I bit values ​​of each index entry in the N+1th index group, and determine the security policy address range defined by the N+1th index group. Based on the index group corresponding to each of the element groups, determine the target index sub-table corresponding to the target sorting sub-table; N is a positive integer, and the number of bits in one of the index entries is J+I. The value of J is determined based on the number of entries in the lookup table and the number of index entries in the preset group, and the value of I is determined based on the number of bits in the storage address of the security policy.

[0012] Secondly, the present invention also provides a message security policy matching device, comprising: The extraction module is used to extract the target quintuple based on the target message; The binary search module is used to determine the matching item corresponding to each target element in the target quintuple by means of binary search based on the target element and the local tuple sorting table. The index information determination module is used to determine the first index information corresponding to each target element based on the security policy address index table and the corresponding matching items of each target element; The security policy matching module is used to match the security policy of the target quintuple based on the first index information corresponding to each of the target elements.

[0013] Thirdly, the present invention also provides an electronic device, comprising: at least one memory for storing a program; and at least one processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to execute the method described in the first aspect or any possible implementation thereof.

[0014] Fourthly, the present invention also provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to perform the method described in the first aspect or any possible implementation thereof.

[0015] It is understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here.

[0016] In summary, the technical solutions conceived by this invention have the following beneficial effects compared with the prior art: By configuring a local tuple sorting table and a security policy address index table, a binary search can be performed on each target element in the target 5-tuple within the local tuple sorting table to determine the matching item for each target element. Then, the address range of the security policy matching each target element can be analyzed using the security policy address index table to determine the first index information corresponding to each target element. Based on this first index information, the security policy of the packet can be matched. Because a binary search is used, it avoids analyzing each entry in the local lookup table one by one, reducing the range matching cycle of the 5-tuple from Num (number of entries) to Log2Num, thus reducing the matching clock cycle and improving the matching efficiency of the packet security policy. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0018] Figure 1 This is a schematic diagram of the data structure of the query table provided by the relevant technology; Figure 2 This is a flowchart illustrating the message security policy matching method provided by the present invention; Figure 3 This is a schematic diagram of the data structure of the local tuple sorting table provided by the present invention; Figure 4 This is one of the data structure diagrams of the security policy address index table provided by the present invention; Figure 5 This is the second schematic diagram of the data structure of the security policy address index table provided by the present invention; Figure 6 This is the third schematic diagram of the data structure of the security policy address index table provided by the present invention; Figure 7 This is a schematic diagram of the message security policy matching device provided by the present invention. Detailed Implementation

[0019] To facilitate a clearer understanding of the various embodiments of the present invention, some relevant background knowledge will be introduced as follows.

[0020] Figure 1 This is a schematic diagram of the data structure of the query table provided by the relevant technology, such as... Figure 1 As shown, the query table can be a pre-configured local data table, and any item in the query table can include a local maximum value tuple (such as...). Figure 1 MAX_TUPLE in (and local minimum tuples such as Figure 1 In the `MIN_TUPLE` tuple, the local maximum value tuple includes an element representing the upper limit of the 5-tuple's value (the maximum value element), and the local minimum value tuple includes an element representing the lower limit of the 5-tuple's value (the minimum value element). A table entry in the query table corresponds to the storage address of a security policy; for example, such as... Figure 1 As shown, entry 0 corresponds to the storage address Add0 of security policy number SA_ID0, entry 1 corresponds to the storage address Add1 of security policy number SA_ID1, and so on. Based on the security policy number SA_ID, the corresponding security policy can be obtained by querying the address.

[0021] In related technologies, range matching of 5-tuples is generally used to analyze each entry in a local lookup table to match the security policy of the packet. For example, for the source IP address, each entry in the lookup table can represent the upper and lower limits of the maximum and minimum source IP address. During range matching, if the IP address to be matched (the IP address of the target 5-tuple, which is a target element of the target 5-tuple) is within the range of a certain entry, then the security policy index corresponding to that entry is valid. For example, as... Figure 1 As shown, if the target quintuple satisfies the ranges of table entry 0 and table entry 1, then the corresponding Add0 ( Figure 1 In the table, Add0 (representing the storage address of the security policy) and Add1 are valid indexes. The SA_ID stored in Add0 and Add1 is extracted, and the corresponding policy is retrieved based on the SA_ID to determine the processing method for the target packet. It is evident that as the number of entries in the query table increases, the query time also increases. For example, if the number of entries doubles, the matching time also doubles, resulting in low matching efficiency for packet security policies.

[0022] To overcome the above-mentioned defects, the present invention provides a message security policy matching method, apparatus, electronic device and storage medium. By using binary search, the matching efficiency of message security policies can be improved.

[0023] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0024] In this article, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The symbol " / " in this article indicates that the related objects are in an "or" relationship; for example, A / B means A or B.

[0025] The terms "first" and "second," etc., used in the specification and claims herein are used to distinguish different objects, not to describe a specific order of objects. For example, "first response message" and "second response message," etc., are used to distinguish different response messages, not to describe a specific order of response messages.

[0026] In embodiments of the present invention, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" or "for example" in embodiments of the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0027] In the description of the embodiments of the present invention, unless otherwise stated, "multiple" means two or more, for example, multiple processing units means two or more processing units, multiple elements means two or more elements, etc.

[0028] Next, the technical solutions provided in the embodiments of the present invention will be introduced.

[0029] Figure 2 This is a flowchart illustrating the message security policy matching method provided by the present invention, as shown below. Figure 2 As shown, the execution entity of the message security policy matching method can be an electronic device, such as a Field-Programmable Gate Array (FPGA). The method includes: Step S101: Extract the target quintuple based on the target message.

[0030] Understandably, the elements of a quintuple include the source IP address, source port, destination IP address, destination port, and transport layer protocol number.

[0031] Step S102: For each target element in the target quintuple, based on the target element and the local tuple sorting table, a binary search is used to determine the matching item corresponding to the target element. The local tuple sorting table is determined by sorting each element of the local tuple according to the element category and the element value. The matching item is the element with the smallest difference in value between the matching elements of the same category in the local tuple sorting table and the target element.

[0032] Binary search, also known as half-interval search, is an algorithm for finding a specific element in an ordered array or sorted table.

[0033] A local tuple can be a tuple from an entry in a lookup table. A local tuple can be a local maximum tuple or a local minimum tuple.

[0034] Step S103: Based on the security policy address index table and the corresponding entries of each target element, determine the first index information corresponding to each target element. The security policy address index table is used to characterize the correspondence between each element of the local tuple and the storage address of the security policy. The first index information is used to characterize the address range of the security policy that matches the target element.

[0035] Optionally, when the execution entity is an FPGA, the local tuple sorting table and the security policy address index table can be stored in the FPGA's Block Random Access Memory (BRAM).

[0036] Step S104: Based on the first index information corresponding to each target element, match the security policy of the target quintuple.

[0037] Understandably, by configuring a local tuple sorting table and a security policy address index table, a binary search can be performed on each target element in the target 5-tuple within the local tuple sorting table to determine the matching item for each target element. Then, the address range of the security policy matching each target element can be analyzed using the security policy address index table to determine the first index information corresponding to each target element. Based on this first index information, the security policy of the packet can be matched. Because a binary search is used, it avoids analyzing each entry in the local lookup table one by one, reducing the range matching cycle of the 5-tuple from Num (number of entries) to Log2Num, thus reducing the matching clock cycle and improving the matching efficiency of the packet security policy.

[0038] Optionally, according to a message security policy matching method provided by the present invention, the local tuple sorting table includes a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local maximum value element sorting sub-table is determined by sorting the maximum value elements belonging to the same category in descending order, and the maximum value element is used to indicate the upper limit of the value. The local minimum value element sorting sub-table is determined by sorting the minimum value elements belonging to the same category in ascending order, and the minimum value element is used to indicate the lower limit of the value. The matching items corresponding to the target element include maximum value matching items and minimum value matching items. Based on the target element and the local tuple sorting table, a binary search is used to determine the matching items corresponding to the target element, including: Based on the target element and the sorted sub-table of the local maximum value tuple elements corresponding to the element category to which the target element belongs, a binary search is used to determine the maximum value matching item corresponding to the target element; Based on the target element and the sorted sub-table of local minimum value elements corresponding to the element category to which the target element belongs, a binary search is used to determine the minimum value matching item corresponding to the target element.

[0039] Specifically, the local tuple sorting table can include a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local maximum value element sorting sub-table is determined by sorting the maximum value elements belonging to the same category in descending order, and the maximum value element is used to indicate the upper limit of the value. The local minimum value element sorting sub-table is determined by sorting the minimum value elements belonging to the same category in ascending order, and the minimum value element is used to indicate the lower limit of the value. The matching items corresponding to the target element include maximum value matching items and minimum value matching items.

[0040] It is understandable that for the maximum value matching item corresponding to the target element, the maximum value matching item and the target element belong to the same element category (for example, both belong to the element category of source IP address), and the maximum value matching item matches the target element (if the value of the maximum value matching item is greater than or equal to the value of the target element, it means that they match), and the maximum value matching item is the element with the smallest difference between its value and the target element among the matching elements of the same category in the local maximum value element sorting sub-table.

[0041] It is understandable that for the minimum value matching item corresponding to the target element, the minimum value matching item and the target element belong to the same element category (for example, both belong to the element category of source IP address), and the minimum value matching item matches the target element (if the value of the minimum value matching item is less than or equal to the value of the target element, it means that they match), and the minimum value matching item is the element with the smallest difference between its value and the target element among the matching elements of the same category in the local minimum value element sorting sub-table.

[0042] Optionally, Figure 3 This is a schematic diagram of the data structure of the local tuple sorting table provided by the present invention, as shown below. Figure 3 As shown, for local maximum value elements, maximum value elements belonging to the same category can be sorted in descending order to determine the local maximum value element sorting sub-table. MAX_SRC0 is the maximum value in this sorting sub-table, and MAX_SRCN is the minimum value in this sorting sub-table.

[0043] Optionally, Figure 4 This is one of the data structure diagrams of the security policy address index table provided by the present invention, such as... Figure 4 As shown, an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, for example... Figure 4 The first index entry (with a value of 0X…00000020) corresponds to the element MAX_SRC0, the second index entry (with a value of 0X…00000120) corresponds to the element MAX_SRC1, and so on.

[0044] like Figure 4 As shown, the index entries of the local maximum value index sub-table can represent the security policy address range with the corresponding element's value as the upper limit. When the number of entries in the query table is 256, as shown... Figure 4As shown, an index entry can be represented by 256 bits. Each bit in the index entry corresponds to a security policy address. For example, the least significant bit of the index entry corresponds to the security policy address Add0, the most significant bit corresponds to the security policy address Add255, and so on. This allows us to obtain the correspondence between each bit in the index entry and the security policy address. Furthermore, if the least significant bit of the index entry is 1, it means that the security policy address range of the index entry includes the security policy address Add0. If the least significant bit of the index entry is 0, it means that the security policy address range of the index entry does not include the security policy address Add0, and so on. By judging the values ​​of each bit in the index entry, the security policy address range of the index entry can be determined.

[0045] For example, such as Figure 4 As shown, after performing a binary search on the source IP address in the target quintuple, the corresponding value is located between MAX_SRC2 and MAX_SRC3. Therefore, MAX_SRC2 is the matching item corresponding to the source IP address in the target quintuple, indicating that Add5, Add8, and Add13 meet the conditions. The value 0x...00002120 corresponding to MAX_SRC2 in the security policy address index table can be retrieved (in the case of an FPGA, this corresponds to a BRAM read) and this value 0x...00002120 can be used as the first index information corresponding to the source IP address in the target quintuple.

[0046] Optionally, taking a local maximum value element sorting sub-table for a certain element category (e.g., source IP address, source port, destination IP address, destination port, or transport layer protocol number) as an example, the local maximum value element sorting sub-table is determined by sorting the maximum value elements belonging to the same category in descending order. First, the target element in the tuple to be matched (target 5-tuple) can be compared with the element at address 128 in the local maximum value element sorting sub-table (assuming this sub-table has 256 items). If the former is greater than the latter, it means that the values ​​of elements with addresses greater than 128 are all less than the target element. Then, it can be compared with the value of the element at address 64 in the local maximum value element sorting sub-table. If the value of the target element is less than the value at address 64... The element value of 4 indicates that not all elements in the local maximum element sorting sub-table between addresses 128 and 64 are greater than the target element. The next step is to compare it with the element at address 96, the middle address between 128 and 64. This binary search continues until the address of the target element in the local maximum element sorting sub-table is obtained (i.e., the address corresponding to the maximum matching item; in the maximum element sorting sub-table, the value of the maximum matching item is greater than or equal to the value of the target element, the value of the element before the maximum matching item is greater than the value of the target element, and the value of the element after the maximum matching item is less than the value of the target element). In other words, the element before the maximum matching item in the local maximum element sorting matches the target element. Accordingly, the security policy corresponding to the element before the maximum matching item in the local maximum element sorting is met.

[0047] Optionally, taking a local minimum value element sorting sub-table for a certain element category (e.g., source IP address, source port, destination IP address, destination port, or transport layer protocol number) as an example, the local minimum value element sorting sub-table is determined by sorting minimum value elements belonging to the same category in ascending order. First, the target element in the tuple to be matched (target 5-tuple) can be compared with the element at address 128 in the local minimum value element sorting sub-table (assuming this sub-table has 256 items). If the former is greater than the latter, it means that the values ​​of elements with addresses greater than 128 are all greater than the target element. Then, it can be compared with the value of the element at address 64 in the local minimum value element sorting sub-table. If the value of the target element is greater than the value at address 64... The element value of 4 indicates that not all elements in the local minimum element sorting sub-table between addresses 128 and 64 are less than the target element. The next step is to compare it with the element at address 96, the middle address between 128 and 64. This binary search continues until the address of the target element in the local minimum element sorting sub-table is obtained (i.e., the address corresponding to the minimum value matching item; in the minimum element sorting sub-table, the value of the minimum value matching item is less than or equal to the value of the target element, the value of elements preceding the minimum value matching item is less than the value of the target element, and the value of elements following the minimum value matching item is greater than the value of the target element). In other words, the element preceding the minimum value matching item in the local minimum element sorting matches the target element. Accordingly, the security policy corresponding to the element preceding the minimum value matching item in the local minimum element sorting is met.

[0048] Optionally, according to the message security policy matching method provided by the present invention, the security policy address index table includes: an index sub-table corresponding to each sorted sub-table in the local tuple sorting table, wherein an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, the sub-table of the local tuple sorting table and the corresponding index sub-table adopt the same sorting method, and the index sub-table is used to group and store each index item in the table based on the number of index items in a preset group and the corresponding sorting method; For the index groups in the index sub-table, the first J bits of each index entry in the (N+1)th index group are determined based on the number of index entries in the preset group and the security policy address range defined by the Nth index group. The first J bits of each index entry in the 1st index group are 0. The last I bits of each index entry in the index group are determined based on the storage address of the corresponding security policy of the corresponding element in the sub-table of the local tuple sorting table. N is a positive integer, and the number of bits in an index entry is J+I. Based on the security policy address index table and the corresponding matches for each target element, the first index information for each target element is determined, including: Based on the maximum and minimum matching items corresponding to the target element, and the index sub-table corresponding to the element category to which the target element belongs, determine the first index group corresponding to the maximum matching item and the second index group corresponding to the minimum matching item; The first J bits of each index entry in the first index group are concatenated to determine the address range of the first security policy, and the first J bits of each index entry in the second index group are concatenated to determine the address range of the second security policy. The address range of the third security policy is determined based on the last I bits of each index entry in the first index group, and the address range of the fourth security policy is determined based on the last I bits of each index entry in the second index group. Based on the first security policy address range and the third security policy address range, a fifth security policy address range suitable for the maximum value matching item is determined; and based on the second security policy address range and the fourth security policy address range, a sixth security policy address range suitable for the minimum value matching item is determined. Based on the address ranges of the fifth and sixth security policies, an AND operation is performed to determine the first index information corresponding to the target element.

[0049] It is understandable that if the local tuple sorting table includes a local maximum value sorting subtable and a local minimum value sorting subtable for a certain element category (such as the source IP address element category), then the security policy address index table includes the index subtable corresponding to the local maximum value sorting subtable for the corresponding element category, and the index subtable corresponding to the local minimum value sorting subtable for the corresponding element category.

[0050] Optionally, when the number of entries in the query table is 256, the number of entries in the local maximum value element sorting sub-table, the number of entries in the local minimum value element sorting sub-table, and the number of entries in the security policy address index table are also 256.

[0051] Optionally, Figure 5 This is the second schematic diagram of the data structure of the security policy address index table provided by the present invention, as shown below. Figure 5 As shown, when the number of entries in the lookup table is 256, the value of I can be 8, meaning that the index entry uses 8 bits to represent the storage address of the corresponding security policy for the element. In this case, the number of index entries in the preset group can be 4, and correspondingly, the value of J can be 64 (256 / 4). In this case, the number of bits in the index entry is 72 (64+8).

[0052] Optionally, such as Figure 5 As shown, the second index group (such as...) Figure 5 The first J bits of each index item in group 2) are based on the preset number of index items in the group and the first index group (e.g., ...). Figure 5The address range of the security policy defined by the middle group 1) is determined by the first J bits of each index entry in the first index group being 0, and the last I bits of each index entry in the index group being determined by the storage address of the corresponding security policy of the corresponding element in the sub-table of the local tuple sorting table.

[0053] Optionally, such as Figure 5 As shown, when the number of table entries in the query table is 256 and the number of index entries in the preset group is 4, based on the maximum value matching item corresponding to the target element, the storage address of the maximum value matching item in the local maximum value element sorting sub-table can be determined. After performing a bitwise AND operation on this storage address with 0b11111100 to mask the lower two bits, the index group number corresponding to the maximum value matching item can be determined. Based on the index sub-table corresponding to the element category to which the target element belongs and the index group number corresponding to the maximum value matching item, the first index group corresponding to the maximum value matching item can be determined.

[0054] Optionally, when the number of entries in the query table is 256 and the number of index entries in the preset group is 4, based on the minimum value matching item corresponding to the target element, the storage address of the minimum value matching item in the local minimum value element sorting sub-table can be determined. After performing a bitwise AND operation on this storage address with 0b11111100 to mask the lower two bits, the index group number corresponding to the minimum value matching item can be determined. Based on the index sub-table corresponding to the element category to which the target element belongs and the index group number corresponding to the minimum value matching item, the second index group corresponding to the minimum value matching item can be determined.

[0055] Optionally, when the number of entries in the lookup table is 256 and the number of index entries in the preset group is 4, after determining the first index group corresponding to the maximum value matching item, the first J bits of each index entry in the first index group can be concatenated to determine the first security policy address range (the security policy address range defined by the index group preceding the first index group). The first security policy address range has 256 bits (64×4). Based on the index entry corresponding to the maximum value matching item (which is an index entry in the first index group) and the last I bits of each index entry in the first index group, the last I bits of the index entries preceding the index entry corresponding to the maximum value matching item in the first index group can be decoded to convert the address represented by the I bits into an address represented by 256 bits, obtaining one or more decoding results (each decoding result has 256 bits). By performing an OR operation on all decoding results, the third security policy address range (the security policy address range defined by the index entries preceding the index entry corresponding to the maximum value matching item in the first index group) can be determined. Then, based on the address range of the first security policy and the address range of the third security policy, an OR operation can be performed to determine the address range of the fifth security policy that matches the maximum value.

[0056] For example, such as Figure 5As shown, when the maximum value matches MAX_SRC5, the first index group is group 2. The first index entry (the last 8 bits store Add7) and the second index entry (the last 8 bits store Add9) in group 2 are the index entries preceding the index entry corresponding to MAX_SRC5. Therefore, the Add7 address represented by 8 bits can be transformed into the Add7 address represented by 256 bits, and the Add9 address represented by 8 bits can be transformed into the Add9 address represented by 256 bits, obtaining two decoding results (each decoding result has 256 bits). By performing an OR operation on all decoding results, the address range of the third security policy can be determined.

[0057] The fifth security policy address range includes: the security policy address range defined by the index group preceding the first index group, and the security policy address range defined by the index entry preceding the index entry corresponding to the maximum value in the first index group.

[0058] Therefore, by resolving the addresses of each index entry in the first index group, the address range of the fifth security policy can be determined.

[0059] Optionally, when the number of entries in the lookup table is 256 and the number of index entries in the preset group is 4, after determining the second index group corresponding to the minimum value matching item, the first J bits of each index entry in the second index group can be concatenated to determine the second security policy address range (the security policy address range defined by the index group preceding the second index group). The second security policy address range has 256 bits (64×4). Based on the index entry corresponding to the minimum value matching item (which is an index entry in the second index group) and the last I bits of each index entry in the second index group, the last I bits of the index entries preceding the index entry corresponding to the minimum value matching item in the second index group can be decoded, converting the address represented by the I bits into an address represented by 256 bits, obtaining one or more decoding results (each decoding result has 256 bits). By performing an OR operation on all decoding results, the fourth security policy address range (the security policy address range defined by the index entries preceding the index entry corresponding to the minimum value matching item in the second index group) can be determined. Then, based on the address ranges of the second and fourth security policies, an OR operation can be performed to determine the address range of the sixth security policy that matches the minimum value.

[0060] The sixth security policy address range includes: the security policy address range defined by the index group preceding the second index group, and the security policy address range defined by the index entry preceding the index entry corresponding to the minimum value in the second index group.

[0061] Therefore, by resolving the addresses of each index entry in the second index group, the address range of the sixth security policy can be determined.

[0062] Understandably, when the FPGA acts as the execution entity, decoding one index item requires one clock cycle. Similarly, with a preset group containing four index items, decoding all four index items in a group requires four clock cycles.

[0063] When the FPGA acts as the execution entity, performing an OR operation on the first and third security policy address ranges (to determine the fifth security policy address range that matches the maximum value) requires one clock cycle. Similarly, performing an OR operation on the second and fourth security policy address ranges (to determine the sixth security policy address range that matches the minimum value) requires one clock cycle.

[0064] Optionally, Figure 6 This is the third schematic diagram of the data structure of the security policy address index table provided by the present invention, as shown below. Figure 6 As shown, based on the address range of the fifth security policy (such as...) Figure 6 The maximum value in the value matches the full policy address range of the item and the sixth security policy address range (e.g., Figure 6 By performing a bitwise AND operation on the minimum value in the list (which matches the full policy address range of the item), the first index information corresponding to the target element can be determined.

[0065] Understandably, assuming the query table has 256 entries, when using... Figure 4 In the data structure shown, the number of bits occupied by an index entry in the index sub-table is 256. When using a data structure such as... Figure 5 In the case of the data structure shown (the index sub-table is used to group and store each index item in the table based on the number of index items in the preset group and the corresponding sorting method), the number of bits occupied by one index item in the index sub-table is 72. It can be seen that the method of storing index items in groups can save storage space.

[0066] Optionally, according to a message security policy matching method provided by the present invention, the security policy of the target quintuple is matched based on the first index information corresponding to each target element, including: Based on the first index information corresponding to each target element, perform an AND operation to determine the second index information; Based on the second index information, determine one or more security policies that match the target quintuple; Based on the preset priority configuration, the security policies that match the target quintuple are filtered to determine the security policy for the target quintuple.

[0067] Specifically, the elements of the 5-tuple include the source IP address, source port, destination IP address, destination port, and transport layer protocol number. Correspondingly, the first index information corresponding to each target element includes the first index information corresponding to the source IP address of the target 5-tuple, the first index information corresponding to the source port of the target 5-tuple, the first index information corresponding to the destination IP address of the target 5-tuple, the first index information corresponding to the destination port of the target 5-tuple, and the first index information corresponding to the transport layer protocol number of the target 5-tuple.

[0068] By performing a bitwise AND operation on the first index information corresponding to each target element, the address range of the security policy that matches all target elements can be determined, which is the address range represented by the second index information. In turn, one or more security policies that match the target quintuple can be determined.

[0069] The preset priority configuration is used to indicate the priority among different security policies. Based on the preset priority configuration, security policies that match the target quintuple can be filtered to determine the target security policy for the target quintuple.

[0070] Optionally, according to the message security policy matching method provided by the present invention, the local tuple sorting table includes a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local tuple sorting table is obtained through the following steps: Based on a pre-configured query table, the maximum value elements belonging to the same category are sorted in descending order to determine the local maximum value element sorting sub-table for each element category. The maximum value element is used to indicate the upper limit of the value range. Based on a pre-configured query table, the minimum value elements belonging to the same category are sorted in ascending order to determine the local minimum value element sorting sub-table for each element category. The minimum value element is used to indicate the lower limit of the value. The query table includes multiple entries. Each entry includes an element representing the upper limit of the quintuple value, an element representing the lower limit of the quintuple value, and the security policy address corresponding to the entry.

[0071] Optionally, according to the message security policy matching method provided by the present invention, the security policy address index table is obtained through the following steps: Based on the storage addresses of each sorted sub-table in the local tuple sorting table and the corresponding security policies of each element in the sorted sub-table, determine the index sub-table corresponding to each sorted sub-table in the local tuple sorting table. Based on each index sub-table, determine the security policy address index table; In this system, an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, and the sub-tables of the local tuple sorting table and their corresponding index sub-tables use the same sorting method.

[0072] Specifically, the local maximum value index sub-table for each element category can be determined based on the local maximum value element sorting sub-table for each element category and the storage address of the corresponding security policy for each element in the local maximum value element sorting sub-table.

[0073] Based on the local minimum value element sorting sub-table for each element category and the storage address of the corresponding security policy for each element in the local minimum value element sorting sub-table, the local minimum value index sub-table for each element category can be determined.

[0074] Understandably, the storage address of the corresponding security policy for each element in the sorted subtable can be obtained by querying the table. For example, for Figure 4 By querying the sorted subtable, we can determine the storage address of the corresponding security policy for element MAX_SRC0 as Add5, the storage address of the corresponding security policy for element MAX_SRC1 as Add8, the storage address of the corresponding security policy for element MAX_SRC2 as Add13, the storage address of the corresponding security policy for element MAX_SRC3 as Add4, and the storage address of the corresponding security policy for element MAX_SRCN as Add77.

[0075] The following examples illustrate the correspondence between index items and elements, as well as the possible values ​​of index items. For instance, ... Figure 4 As shown, the index entries of the local maximum value index subtable can be represented by the corresponding element (e.g., Figure 4 The security policy address range is defined by the value of the first index entry (corresponding element to MAX_SRC0, the second index entry to MAX_SRC1, and so on) as the upper limit of the possible values. This applies when the number of entries in the query table is 256. Figure 4 As shown, an index entry can be represented by 256 bits. Each bit in the index entry corresponds to a security policy address. For example, the least significant bit of the index entry corresponds to the security policy address Add0, the most significant bit corresponds to the security policy address Add255, and so on. This allows us to obtain the correspondence between each bit in the index entry and the security policy address. Furthermore, if the least significant bit of the index entry is 1, it means that the security policy address range of the index entry includes the security policy address Add0. If the least significant bit of the index entry is 0, it means that the security policy address range of the index entry does not include the security policy address Add0, and so on. By judging the values ​​of each bit in the index entry, the security policy address range of the index entry can be determined.

[0076] For example, such as Figure 4 As shown, the corresponding element of the first index entry is MAX_SRC0. The first index entry represents the security policy address range with MAX_SRC0 as the upper limit. Figure 4 The security policy address range of the first index entry includes ADD5, and correspondingly, the value of the first index entry can be determined to be 0X…00000020 (a total of 256 bits). For example... Figure 4 As shown, the corresponding element of the second index entry is MAX_SRC1. The second index entry represents the security policy address range with MAX_SRC2 as the upper limit. Figure 4 The security policy address range of the second index entry includes ADD5 and ADD8. Accordingly, the value of the first index entry can be determined to be 0X…00000120 (256 bits in total). This process can be repeated to determine the values ​​of each index entry in the sub-table.

[0077] Optionally, according to a message security policy matching method provided by the present invention, based on each sorted sub-table in the local tuple sorting table and the storage address of the corresponding security policy of each element in the sorted sub-table, an index sub-table corresponding to each sorted sub-table in the local tuple sorting table is determined, including: For any target sorted sub-table, based on the preset number of index items in the group, the elements in the target sorted sub-table are grouped in order to determine multiple element groups; Based on the storage address of the corresponding security policy of each element in the first element group, determine the last I bit value of each index entry in the first index group, and determine the security policy address range limited by the first index group. The first J bits of each index entry in the first index group are 0. Based on the number of index entries in the preset group and the address range of the security policy defined by the Nth index group, determine the first J bits of each index entry in the N+1th index group, and based on the storage address of the corresponding security policy of each element in the N+1th element group, determine the last I bits of each index entry in the N+1th index group, and determine the address range of the security policy defined by the N+1th index group. Based on the index group corresponding to each element group, determine the target index sub-table corresponding to the target sorting sub-table; N is a positive integer. The number of bits in an index entry is J+I. The value of J is determined based on the number of entries in the lookup table and the number of index entries in the preset group. The value of I is determined based on the number of bits in the storage address of the security policy.

[0078] For example, such as Figure 5 As shown, based on the first element group (such as...) Figure 5The storage address of the corresponding security policy for each element in group 1) is determined, and the last I( ) of each index entry in the first index group is determined. Figure 5 The value of I is 8 bits, and the security policy address range defined by the first index group is determined. The first J (bits) of each index entry in the first index group Figure 5 The value of J is 64 bits, with 0 bits.

[0079] For example, such as Figure 5 As shown, based on the preset number of index items within a group ( Figure 5 The number of index entries in the preset group is 4, and the security policy address range defined by the first index group is used to determine the second index group (e.g., Figure 5 The first J bits of each index entry in group 2), and the storage address based on the corresponding security policy of each element in the second element group (e.g., Figure 5 As shown, the storage address of the corresponding security policy of element MAX_SRC4 is Add7, the storage address of the corresponding security policy of element MAX_SRC5 is Add9, the storage address of the corresponding security policy of element MAX_SRC6 is Add25, and the storage address of the corresponding security policy of element MAX_SRC7 is Add33). Determine the last I bit value of each index item in the second index group, and determine the security policy address range limited by the second index group.

[0080] The message security policy matching device provided by the present invention is described below. The message security policy matching device described below and the message security policy matching method described above can be referred to in correspondence.

[0081] Figure 7 This is a schematic diagram of the message security policy matching device provided by the present invention, as shown below. Figure 7 As shown, the device includes: an extraction module 10, a binary search module 20, an index information determination module 30, and a security policy matching module 40, wherein: Extraction module 10 is used to extract target quintuples based on the target message; The binary search module 20 is used to determine the matching item corresponding to each target element in the target quintuple by binary search based on the target element and the local tuple sorting table. The local tuple sorting table is determined by sorting each element of the local tuple according to the element category and the element value. The matching item is the element with the smallest difference between the value of the target element and the matching element of the same category in the local tuple sorting table. The index information determination module 30 is used to determine the first index information corresponding to each target element based on the security policy address index table and the corresponding matching items of each target element. The security policy address index table is used to characterize the correspondence between each element of the local tuple and the storage address of the security policy. The first index information is used to characterize the address range of the security policy that matches the target element. The security policy matching module 40 is used to match the security policy of the target quintuple based on the first index information corresponding to each target element.

[0082] Specifically, the binary search module performs a binary search on each target element in the target quintuple based on the target element and the local tuple sorting table. This avoids analyzing each item in the local lookup table one by one, reducing the range matching period of the quintuple from the number of table entries Num to Log2Num, thus reducing the matching clock cycle and improving the matching efficiency of the message security policy.

[0083] It should be understood that the above-described device is used to execute the methods in the above embodiments. The implementation principle and technical effect of the corresponding program modules in the device are similar to those described in the above methods. The working process of the device can be referred to the corresponding process in the above methods, and will not be repeated here.

[0084] Based on the methods described in the above embodiments, this invention provides an electronic device. The device may include at least one memory for storing a program and at least one processor for executing the program stored in the memory. When the program stored in the memory is executed, the processor performs the methods described in the above embodiments.

[0085] Based on the methods in the above embodiments, this embodiment of the invention provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to execute the methods in the above embodiments.

[0086] Based on the methods in the above embodiments, this embodiment of the invention provides a computer program product that, when run on a processor, causes the processor to execute the methods in the above embodiments.

[0087] It is understood that the processor in the embodiments of the present invention can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0088] The method steps in these embodiments of the invention can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an ASIC.

[0089] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0090] It is understood that the various numerical designations used in the embodiments of the present invention are merely for the convenience of description and are not intended to limit the scope of the embodiments of the present invention.

[0091] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A message security policy matching method, characterized in that, include: Extract the target quintuple based on the target message; For each target element in the target quintuple, based on the target element and the local tuple sorting table, a binary search is used to determine the matching item corresponding to the target element. The local tuple sorting table is determined by sorting each element of the local tuple according to the element category and the element value. The matching item is the element with the smallest difference in value between the matching elements of the same category in the local tuple sorting table and the target element. Based on the security policy address index table and the corresponding entries for each target element, the first index information corresponding to each target element is determined. The security policy address index table is used to characterize the correspondence between each element of the local tuple and the storage address of the security policy. The first index information is used to characterize the address range of the security policy that matches the target element. Based on the first index information corresponding to each of the target elements, the security policy of the target quintuple is matched. The local tuple sorting table includes a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local maximum value element sorting sub-table is determined by sorting the maximum value elements belonging to the same category in descending order. The maximum value element is used to indicate the upper limit of the value. The local minimum value element sorting sub-table is determined by sorting the minimum value elements belonging to the same category in ascending order. The minimum value element is used to indicate the lower limit of the value. The matching items corresponding to the target element include maximum value matching items and minimum value matching items. The step of determining the matching item corresponding to the target element through binary search based on the target element and the local tuple sorting table includes: Based on the target element and the sorted sub-table of local maximum value tuple elements corresponding to the element category to which the target element belongs, the maximum value matching item corresponding to the target element is determined by binary search; Based on the target element and the local minimum value element sorting sub-table corresponding to the element category to which the target element belongs, the minimum value matching item corresponding to the target element is determined by binary search; The security policy address index table includes: an index sub-table corresponding to each sorted sub-table in the local tuple sorting table, wherein an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, the sub-table of the local tuple sorting table and the corresponding index sub-table adopt the same sorting method, and the index sub-table is used to group and store each index item in the table based on the number of index items in a preset group and the corresponding sorting method. For the index groups in the index sub-table, the first J bits of each index entry in the (N+1)th index group are determined based on the number of index entries in the preset group and the security policy address range defined by the Nth index group. The first J bits of each index entry in the 1st index group are 0. The last I bits of each index entry in the index group are determined based on the storage address of the corresponding security policy of the corresponding element in the sub-table of the local tuple sorting table. N is a positive integer, and the number of bits in one index entry is J+I. The step of determining the first index information corresponding to each target element based on the security policy address index table and the corresponding matching items of each target element includes: Based on the maximum value matching item and the minimum value matching item corresponding to the target element, and the index sub-table corresponding to the element category to which the target element belongs, determine the first index group corresponding to the maximum value matching item and the second index group corresponding to the minimum value matching item; The first J bits of each index entry in the first index group are concatenated to determine the address range of the first security policy, and the first J bits of each index entry in the second index group are concatenated to determine the address range of the second security policy. The address range of the third security policy is determined based on the last I bit values ​​of each index entry in the first index group, and the address range of the fourth security policy is determined based on the last I bit values ​​of each index entry in the second index group. Based on the first security policy address range and the third security policy address range, a fifth security policy address range adapted to the maximum value conformance item is determined; and based on the second security policy address range and the fourth security policy address range, a sixth security policy address range adapted to the minimum value conformance item is determined. Based on the address range of the fifth security policy and the address range of the sixth security policy, an AND operation is performed to determine the first index information corresponding to the target element.

2. The message security policy matching method according to claim 1, characterized in that, The security policy for matching the target quintuple based on the first index information corresponding to each of the target elements includes: Based on the first index information corresponding to each of the target elements, a bitwise AND operation is performed to determine the second index information; Based on the second index information, determine one or more security policies that match the target quintuple; Based on a preset priority configuration, security policies that match the target quintuple are filtered to determine the security policy for the target quintuple.

3. The message security policy matching method according to any one of claims 1-2, characterized in that, The local tuple sorting table includes a sub-table of local maximum value elements for each element category and a sub-table of local minimum value elements for each element category. The local tuple sorting table is obtained through the following steps: Based on a pre-configured query table, the maximum value elements belonging to the same category are sorted in descending order to determine the local maximum value element sorting sub-table for each element category. The maximum value element is used to indicate the upper limit of the value. Based on a pre-configured query table, the minimum value elements belonging to the same category are sorted in ascending order to determine the local minimum value element sorting sub-table for each element category. The minimum value element is used to indicate the lower limit of the value. The query table includes multiple entries, and each entry includes an element representing the upper limit of the quintuple value, an element representing the lower limit of the quintuple value, and a security policy address corresponding to the entry.

4. The message security policy matching method according to claim 3, characterized in that, The security policy address index table is obtained through the following steps: Based on the storage addresses of each sorted sub-table in the local tuple sorting table and the corresponding security policies of each element in the sorted sub-table, an index sub-table corresponding to each sorted sub-table in the local tuple sorting table is determined. Based on each of the index sub-tables, the security policy address index table is determined; In this system, an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, and the sub-tables of the local tuple sorting table and the corresponding index sub-tables use the same sorting method.

5. The message security policy matching method according to claim 4, characterized in that, The step of determining the index sub-table corresponding to each sorted sub-table in the local tuple sorting table based on the storage address of each sorted sub-table and the corresponding security policy of each element in the sorted sub-table includes: For any target sorted sub-table, based on the preset number of index items in the group, the elements in the target sorted sub-table are grouped in order to determine multiple element groups; Based on the storage address of the corresponding security policy of each element in the first element group, determine the last I bit value of each index entry in the first index group, and determine the security policy address range limited by the first index group. The first J bits of each index entry in the first index group are 0. Based on the number of index entries in the preset group and the security policy address range defined by the Nth index group, determine the first J bit values ​​of each index entry in the N+1th index group, and based on the storage address of the corresponding security policy of each element in the N+1th element group, determine the last I bit values ​​of each index entry in the N+1th index group, and determine the security policy address range defined by the N+1th index group. Based on the index group corresponding to each of the element groups, determine the target index sub-table corresponding to the target sorting sub-table; N is a positive integer, and the number of bits in one of the index entries is J+I. The value of J is determined based on the number of entries in the lookup table and the number of index entries in the preset group, and the value of I is determined based on the number of bits in the storage address of the security policy.

6. A message security policy matching device, characterized in that, include: The extraction module is used to extract the target quintuple based on the target message; The binary search module is used to determine the matching item corresponding to each target element in the target quintuple by means of binary search based on the target element and the local tuple sorting table. The index information determination module is used to determine the first index information corresponding to each target element based on the security policy address index table and the corresponding matching items of each target element; The security policy matching module is used to match the security policy of the target quintuple based on the first index information corresponding to each of the target elements. The local tuple sorting table includes a local maximum value element sorting sub-table for each element category and a local minimum value element sorting sub-table for each element category. The local maximum value element sorting sub-table is determined by sorting the maximum value elements belonging to the same category in descending order. The maximum value element is used to indicate the upper limit of the value. The local minimum value element sorting sub-table is determined by sorting the minimum value elements belonging to the same category in ascending order. The minimum value element is used to indicate the lower limit of the value. The matching items corresponding to the target element include maximum value matching items and minimum value matching items. The step of determining the matching item corresponding to the target element through binary search based on the target element and the local tuple sorting table includes: Based on the target element and the sorted sub-table of local maximum value tuple elements corresponding to the element category to which the target element belongs, the maximum value matching item corresponding to the target element is determined by binary search; Based on the target element and the local minimum value element sorting sub-table corresponding to the element category to which the target element belongs, the minimum value matching item corresponding to the target element is determined by binary search; The security policy address index table includes: an index sub-table corresponding to each sorted sub-table in the local tuple sorting table, wherein an element in a sub-table of the local tuple sorting table corresponds to an index item in the index sub-table, the sub-table of the local tuple sorting table and the corresponding index sub-table adopt the same sorting method, and the index sub-table is used to group and store each index item in the table based on the number of index items in a preset group and the corresponding sorting method. For the index groups in the index sub-table, the first J bits of each index entry in the (N+1)th index group are determined based on the number of index entries in the preset group and the security policy address range defined by the Nth index group. The first J bits of each index entry in the 1st index group are 0. The last I bits of each index entry in the index group are determined based on the storage address of the corresponding security policy of the corresponding element in the sub-table of the local tuple sorting table. N is a positive integer, and the number of bits in one index entry is J+I. The step of determining the first index information corresponding to each target element based on the security policy address index table and the corresponding matching items of each target element includes: Based on the maximum value matching item and the minimum value matching item corresponding to the target element, and the index sub-table corresponding to the element category to which the target element belongs, determine the first index group corresponding to the maximum value matching item and the second index group corresponding to the minimum value matching item; The first J bits of each index entry in the first index group are concatenated to determine the address range of the first security policy, and the first J bits of each index entry in the second index group are concatenated to determine the address range of the second security policy. The address range of the third security policy is determined based on the last I bit values ​​of each index entry in the first index group, and the address range of the fourth security policy is determined based on the last I bit values ​​of each index entry in the second index group. Based on the first security policy address range and the third security policy address range, a fifth security policy address range adapted to the maximum value conformance item is determined; and based on the second security policy address range and the fourth security policy address range, a sixth security policy address range adapted to the minimum value conformance item is determined. Based on the address range of the fifth security policy and the address range of the sixth security policy, an AND operation is performed to determine the first index information corresponding to the target element.

7. An electronic device, characterized in that, include: At least one memory for storing programs; At least one processor is configured to execute a program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to perform the method as described in any one of claims 1-5.

8. A non-transitory computer-readable storage medium storing a computer program, characterized in that, When the computer program is run on the processor, it causes the processor to perform the method as described in any one of claims 1-5.