Communication system for hiding an intranet service address and related method

By using a multi-hop link structure with the first and second gateways, the internal network service address is hidden, which solves the problem that the internal network service address is easily detected, realizes anonymous communication, and enhances network defense capabilities.

CN118573398BActive Publication Date: 2025-11-04BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410484577.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-22
Publication Date
2025-11-04
Estimated Expiration
2044-04-22

AI Technical Summary

Technical Problem

In existing technologies, intranet service addresses are easily detected by attackers, leading to an increased risk of network attacks and a lack of effective defense measures.

Method used

A communication system that hides the internal network service address uses a multi-hop link structure of a first gateway, node cluster, and second gateway to ensure that when the user communicates with the first server, neither the first gateway nor the second gateway can simultaneously obtain the user address and the server address, thus achieving anonymous communication.

Benefits of technology

Effectively defend against network reconnaissance activities, improve the concealment of internal network service addresses, and reduce the risk of network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118573398B_ABST
    Figure CN118573398B_ABST
Patent Text Reader

Abstract

The present disclosure provides a communication system for hiding internal network service address and a related method. Specifically, the communication system comprises a first gateway, a node cluster, a second gateway and at least one first server; wherein the first gateway is communicatively connected to the node cluster; the node cluster is communicatively connected to the first gateway and the second gateway; the second gateway is communicatively connected to the first server; wherein the first server is configured to provide the internal network service; the node cluster comprises at least one multi-hop link, and each multi-hop link corresponds to one internal network service; the multi-hop link comprises a first link and a second link which are communicatively connected, the first link is determined by the first gateway; and the second link is determined by the second gateway. Based on such a communication system, the first gateway, the node cluster and the second gateway cannot simultaneously learn the address of the user end and the address of the internal network service, thereby effectively ensuring the anonymity of the internal network service communication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network security, and in particular to a communication system for hiding internal network service address and a related method. BACKGROUND

[0002] At present, the attack means for internal network is increasing day by day, and reconnaissance activity is the first step to successfully implement the attack. Reconnaissance in network security refers to the continuous process of attackers collecting as much information as possible about target systems or networks, which can be used for various types of malicious activities. The nature of computer networks enables an adversary to conduct network reconnaissance and can identify vulnerabilities that can be exploited by network attacks. Efficient scanning strategies for network reconnaissance are known and have been analyzed in the context of computer worms, according to which up to 70% of attacks are preceded by adversarial scanning activities. Regardless of the attack mode, all need to obtain the address or related information of the attack target in advance through network reconnaissance to perform the next more specific attack. However, in the world of network security, deception as a more powerful defense strategy has not been fully developed. SUMMARY

[0003] Therefore, the purpose of the present disclosure is to provide a communication system for hiding internal network service address and a related method.

[0004] In order to achieve the above purpose, the present disclosure provides a communication system for hiding internal network service address, comprising a first gateway, a node cluster, a second gateway and at least one first server; wherein,

[0005] The first gateway is in communication connection with the node cluster; the node cluster is in communication connection with the first gateway and the second gateway; the second gateway is in communication connection with the first server; wherein, the first gateway is used for communication with a user end; and the first server is used for providing the internal network service;

[0006] The node cluster comprises at least one multi-hop link, and each multi-hop link corresponds to one internal network service; the multi-hop link comprises a first link and a second link in communication connection, the first link is determined by the first gateway; and the second link is determined by the second gateway.

[0007] Based on the same inventive concept, the present disclosure further provides a configuration method of a communication system for hiding internal network service address, the communication system comprising a first gateway, a second gateway, a node cluster and a controller; the first gateway comprises a first configuration file; and the second gateway comprises a second configuration file;

[0008] The configuration method comprises:

[0009] The controller acquires the first address to be hidden and forwards to the second gateway; wherein the first address corresponds to an intranet service;

[0010] The second gateway and the node cluster determine the corresponding link identifier, second port and second link according to the first address; and update the second configuration file according to the first address and the second port;

[0011] The first gateway and the node cluster acquire and determine the first port, first node and first link according to the link identifier; and update the first configuration file according to the first port and the first node; wherein the first link and the second link connect the first gateway and the second gateway; and

[0012] The controller acquires the first port, and stores the intranet service identifier corresponding to the first address, the IP address of the first gateway and the first port, so that the IP address of the first gateway and the first port can be acquired by the user terminal based on the intranet service identifier.

[0013] Based on the same inventive concept, the embodiments of the present disclosure also provide a communication method of a communication system based on hidden intranet service address, the communication system comprising a node cluster, a first gateway, a second gateway and at least one first server; the node cluster comprises at least one multi-hop link, and each multi-hop link corresponds to an intranet service; the multi-hop link comprises a first link and a second link connected in communication, the first link is determined by the first gateway; and the second link is determined by the second gateway;

[0014] The communication method comprises: the first gateway acquires a service access request of a user terminal and forwards to the node cluster; wherein the service access request corresponds to a multi-hop link;

[0015] The node cluster sends the service access request to the second gateway through the multi-hop link;

[0016] The second gateway receives the service access request and forwards to the first server; wherein the first server is used to provide the intranet service.

[0017] It can be seen from the above that the communication system and related method for hiding the address of an intranet service are provided. The communication system comprises a first gateway, a node cluster, a second gateway and at least one first server. The first gateway is communicatively connected to the node cluster. The node cluster is communicatively connected to the first gateway and the second gateway. The second gateway is communicatively connected to the first server. The first gateway is configured to communicate with a user terminal. The first server is configured to provide the intranet service. The node cluster comprises at least one multi-hop link, and each multi-hop link corresponds to one intranet service. The multi-hop link comprises a first link and a second link which are communicatively connected. The first link is determined by the first gateway. The second link is determined by the second gateway. Based on the communication system, the user terminal directly communicates with the first gateway. The first gateway communicates with the second gateway through the multi-hop link of the node cluster. The second gateway communicates with the first server. The user address and the address of the first server cannot be learned by the first gateway, the node cluster and the second gateway at the same time, thereby effectively ensuring the anonymity of the intranet service communication. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present disclosure or the related art, the following will briefly introduce the drawings needed to be used in the embodiments or the related description. Obviously, the drawings in the following description are only embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without any creative effort based on these drawings.

[0019] Figure 1 A schematic diagram of a communication method of an intranet service in the related art is shown.

[0020] Figure 2 A structural schematic diagram of a communication system for hiding the address of an intranet service provided by an embodiment of the present disclosure is shown.

[0021] Figure 3 A flowchart of a configuration method of a communication system for hiding the address of an intranet service provided by an embodiment of the present disclosure is shown.

[0022] Figure 4 A communication path schematic diagram of a communication system for hiding the address of an intranet service provided by an embodiment of the present disclosure is shown.

[0023] Figure 5 A flowchart of a communication method of a communication system for hiding the address of an intranet service provided by an embodiment of the present disclosure is shown.

[0024] Figure 6 A structural schematic diagram of another communication system for hiding the address of an intranet service provided by an embodiment of the present disclosure is shown.

[0025] Figure 7 A structural schematic diagram of an electronic device provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0026] For the purposes of the present disclosure, technical solutions and advantages, the present disclosure is further described in detail below with reference to specific embodiments and with reference to the accompanying drawings.

[0027] It should be noted that, unless otherwise defined, technical terms or scientific terms used in the embodiments of the present disclosure should be understood as their common meanings to those skilled in the art to which the present disclosure belongs. The terms "first", "second", and similar terms used in the embodiments of the present disclosure do not represent any order, number, or importance, but are only used to distinguish different components. The terms "include" or "contain" and similar terms mean that the elements or objects before the terms encompass the elements or objects listed after the terms and their equivalents, and do not exclude other elements or objects. The terms "connect" or "connected" and similar terms are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. The terms "up", "down", "left", "right", and the like are only used to represent relative positional relationships, and when the absolute positions of the described objects change, the relative positional relationships can also change accordingly.

[0028] In order to facilitate understanding of the technical solutions of the present disclosure, some technical terms related to the present disclosure are introduced below.

[0029] Gateway (Gateway) is also called network connector or protocol converter, which is a computer system or device that acts as a conversion server, and is used between different communication protocols, data formats or languages, or even two systems with completely different architectures. Gateway realizes network interconnection above the network layer, and is a complex network interconnection device, which can be used for wide area network interconnection or local area network interconnection.

[0030] Server (Server) is a high-performance computer that provides various services on the network. As a node of the network, it stores and processes 80% of the data and information on the network, and is therefore also called the soul of the network. It can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and basic cloud computing services such as big data and artificial intelligence platforms.

[0031] The intranet refers to a network composed of multiple computers and network devices within a certain area, also known as a local area network (LAN). The scope of the intranet can be within a few meters or within a few kilometers, such as a home intranet, a campus network, a government network, etc. The intranet can achieve functions such as file management, application software sharing, printer sharing, email and fax communication services, etc.

[0032] A network node refers to a connection point or device in a network, used for sending, receiving, or forwarding data. It can be a hardware device (such as a computer, server, router, switch) or a software entity (such as a network application, service, or process). Network nodes are connected to each other through physical or logical connections, forming a network topology. The connection between nodes can be wired (such as Ethernet, optical fiber) or wireless (such as Wi-Fi, Bluetooth). Communication between network nodes follows specific protocols and rules to ensure efficient data transmission and exchange. The collection of network nodes forms a network, which connects and cooperates to achieve data transmission, processing, and management. The role of nodes is to ensure the normal operation of the network, reliable data transmission, and provide various network services.

[0033] Nginx (engine x) is a high-performance HTTP and reverse proxy web server that also provides IMAP / POP3 / SMTP services.

[0034] OpenResty is a high-performance web platform based on Nginx and Lua, which integrates a large number of excellent Lua libraries, third-party modules, and most dependencies. It is used to easily build dynamic web applications, web services, and dynamic gateways that can handle ultra-high concurrency and have extremely high scalability.

[0035] Figure 1 A schematic diagram showing the communication method of the intranet service in the related art is shown. As shown in Figure 1 The access of the internal network service in the related art is that the user end directly accesses the resource server, such as a mail server, a Web server, etc. in a point-to-point form. As described in the background section, the attack means against the intranet is increasing day by day, Figure 1The shown resource server position is public and vulnerable to attack. In an intranet service, it is particularly important to hide the position of an intranet important server so that an attacker cannot directly obtain the position of the intranet server and thus cannot implement the next step of attack. Here, a user obtains an intranet service through a user terminal. Exemplarily, the user terminal includes but is not limited to a desktop computer, a mobile phone, a mobile computer, a tablet computer, a media player, a smart wearable device, a personal digital assistant (PDA), or other electronic devices capable of implementing the above functions, etc.

[0036] In view of this, the present disclosure provides a communication system and a related method for hiding an intranet service address. The communication system includes a first gateway, a node cluster, a second gateway, and at least one first server. The first gateway is communicatively connected to the node cluster. The node cluster is communicatively connected to the first gateway and the second gateway. The second gateway is communicatively connected to the first server. The first gateway is configured to communicate with a user terminal. The first server is configured to provide the intranet service. The node cluster includes at least one multi-hop link, and each multi-hop link corresponds to one intranet service. The multi-hop link includes a first link and a second link that are communicatively connected. The first link is determined by the first gateway. The second link is determined by the second gateway. Based on such a communication system, the user terminal directly communicates with the first gateway. The first gateway communicates with the second gateway through the multi-hop link of the node cluster. The second gateway communicates with the first server. The first gateway, the node cluster, and the second gateway cannot simultaneously learn the user address and the address of the first server, thereby effectively ensuring the anonymity of the intranet service communication.

[0037] In order to make the technical solutions of the present disclosure clearer and easier to understand, the structure of the communication system for hiding an intranet service address provided by the present disclosure is introduced below with reference to the accompanying drawings.

[0038] Figure 2 A structure schematic diagram of a communication system 200 for hiding an intranet service address provided by the present disclosure is shown. A user terminal can obtain an intranet service provided by a first server 206 (see reference Figure 4 ) through the communication system 200, such as a mail service, a Web service, etc. It should be understood that the first server 206 is a resource server of an intranet and can provide various services to a user, including but not limited to storage, mail, fax communication, etc.

[0039] As shown in Figure 2 , the communication system 200 includes a first gateway 201, a node cluster 202, a second gateway 203, a controller 204, a second server 205, and at least one first server (not shown in Figure 2 ).

[0040] In some embodiments, the first gateway 201 is an entry of the user terminal accessing the service, and the communication connects the user terminal and the node cluster 202; the second gateway 203 is the last layer gateway of the user terminal accessing the service, and can forward the user access data to the first server, and the second gateway 203 is in communication connection with the node cluster 202 and the first server. The controller 204 is in communication connection with the first gateway 201 and the second gateway 203, and is used for comprehensively controlling the first gateway 201 and the second gateway 203 to obtain the address of the internal network service to be hidden.

[0041] In some embodiments, the node cluster 202 includes a plurality of network nodes. Optionally, the network nodes in the node cluster 202 can be selected by the first gateway 201 and the second gateway 203 to form a multi-hop link for transmitting the user access service data. Exemplarily, the multi-hop link includes a first link determined by the first gateway 201 and a second link determined by the second gateway 203. By means of the first gateway 201 and the second gateway 203 respectively determining the first link and the second link, the first gateway 201 and the second gateway 203 cannot know the whole multi-hop link, which can effectively improve the concealment of the multi-hop link and ensure the address of the internal network service to be hidden. It should be noted that the address of the internal network service can be the IP address of the first server and the internal network service port, which are referred to as the first address in the embodiments of the present disclosure.

[0042] It should be noted that each network node in the node cluster 202 has normal communication function and is not different from other network nodes in the internal network, which helps to improve the concealment of the network nodes and thus improves the concealment of the communication system.

[0043] Further, referring to Figure 4 , the first link includes a first node 2021; and the second link includes a second node 2022. Here, the first node 2021 is directly in communication connection with the first gateway 201; and the second node 2022 is in communication connection with the first link.

[0044] In order to assist the first gateway 201 and the second gateway 203 to generate the multi-hop link, a second server 205 is introduced in the local area network where the node cluster 202 is located. The second server 205 is used to store the link identifier generated by the second gateway 203 based on the first address and the corresponding second node 2022, so that the first gateway 201 can query the second node 2022 according to the link identifier, thereby realizing the generation of the first link. Here, the link identifier is used to refer to the multi-hop link between the second gateway 203 and the first gateway 201. It should be understood that the form of the link identifier can be a domain name, a string, etc., which is not limited in the present disclosure.

[0045] In some embodiments, the communication system 200 further comprises a third server (not shown in the figure). Figure 2 The third server can be a network server, which is configured to dynamically adjust the network address of the nodes in the node cluster 202, such as the Internet Protocol Address (IP address). It should be noted that the third server only adjusts the network address of the network nodes that do not belong to any multi-hop link, thereby increasing the unpredictability of the subsequent multi-hop link while avoiding abnormality of the existing multi-hop link due to the change of the network address.

[0046] The communication system 200 provided by the present disclosure can be used to hide multiple intranet service addresses. Based on different intranet service addresses (first addresses), the first gateway 201 and the second gateway 203 can construct corresponding multi-hop links and use these multi-hop links for different intranet services respectively.

[0047] Next, based on Figure 2 The communication system 200 shown in the figure for hiding the intranet service address, the configuration method of the communication system based on the hidden intranet service address provided by the embodiments of the present disclosure is described in detail.

[0048] Figure 3 A flowchart of a configuration method of a communication system for hiding an intranet service address is shown. Referring to Figure 3 The configuration method of the communication system shown in the flowchart comprises:

[0049] Firstly, when the owner (for example, a service provider) of the first server 206 has the demand for hiding the intranet service address, the controller 204 can be operated to input a request for hiding the intranet service. Exemplarily, the owner can input the request for hiding the intranet service through a graphical user interface. The request for hiding the intranet service comprises the IP address of the first server 206 and the intranet service port.

[0050] Next, S301: the controller 204 responds to the acquisition of the request for hiding the intranet service, and forwards the IP address of the first server 206 and the intranet service port (corresponding to the first address) included in the request for hiding the intranet service to the second gateway 203; it should be noted that based on the IP address and the intranet service port, an intranet service such as a Web service can be determined.

[0051] Then, in step S302: the second gateway 203, in response to obtaining the first address, determines the second port and, based on the second port, determines the corresponding hidden domain name (here, the hidden domain name is an optional form of link identifier); optionally, the second gateway 203 can store the mapping between the first address and the second port in a second configuration file; that is, based on the second configuration file, the second gateway 203 can query the corresponding first address according to the second port. It should be noted that the IP address and the second port of the second gateway 203 are the second address.

[0052] It should be understood that since the IP address in the second address remains unchanged, only the second port changes according to the different first addresses, the second configuration file can also store the correspondence between the second address and the first address to replace the correspondence between the second port and the first address. This disclosure does not limit this.

[0053] This setup establishes a correspondence between the first address and the second port (or second address) and the hidden domain name. Other communication nodes in the communication system 200 (such as the first gateway 201) only know the hidden domain name and are unaware of the first and second addresses (except for nodes in the multi-hop link that communicates directly with the second gateway 203), thus achieving the technical effect of hiding the first address and improving the concealment of the internal network service address.

[0054] Next, S303: The second gateway 203 communicates with the node cluster 202, and the node cluster 202 selects the second node 2022 (e.g., Figure 4 As shown in the diagram, a second link is generated to connect the second node 2022. Here, the second node 2022, the second link, and the hidden domain name are in one-to-one correspondence; in other words, different hidden domain names correspond to different second nodes 2022, second links, and second ports.

[0055] Optionally, the second link may include multiple nodes, such as four. Here, the second address communicates directly with the second link. Too many nodes will affect communication efficiency, while too few nodes will make it difficult to conceal the second address.

[0056] It should be noted that the embodiments disclosed herein do not limit the specific method of generating the second link. The appropriate generation method can be selected according to the configuration conditions of the node cluster 202.

[0057] Then, S304: The second gateway 203 sends the hidden domain name and the second node 2022 to the second server 205; and S305: The second gateway 203 sends the hidden domain name to the controller 204; here, the controller 204 only knows the hidden domain name and not the second node, making the subsequently generated multi-hop links completely isolated from the controller 204, which helps to conceal the multi-hop links. Optionally, the controller 204 and the second server 205 do not belong to the same internal network.

[0058] Next, S306: the controller 204 sends the anonymous domain name to the first gateway 201.

[0059] Then, S307: the first gateway 201 determines the first port corresponding to the anonymous domain name in response to obtaining the anonymous domain name, and determines the IP address of the first gateway 201 and the first port as the third address.

[0060] Next, S308: the first gateway 201 obtains the second node 2022 corresponding to the anonymous domain name from the second server 205 according to the anonymous domain name. For step S308, the present disclosure exemplarily illustrates as follows: the first gateway 201 sends an inquiry request to the second server 205; wherein the inquiry request includes the anonymous domain name; the second server 205 determines the second node 2022 according to the anonymous domain name and sends it to the first gateway 201.

[0061] Then, S309: the first gateway 201 and the node cluster communication 202 determine the first node 2021 directly communicating with the first gateway 201 and generate the first link; wherein the first link communicatively connects the first node 2021 and the second node 2022. Thus, the multi-hop link composed of the first link and the second link can communicatively connect the first gateway 201 and the second gateway 203. In addition, the first gateway 201 updates the first configuration file according to the correspondence between the first node and the first port, so that the first gateway 201 can determine the corresponding first node 2021 according to the first port during communication, and send the obtained service access request of the user to the first node 2021.

[0062] Finally, S310: the first gateway 201 sends the first port to the controller 204. The controller 204 can store the intranet service identifier corresponding to the first address, the first port and the IP address of the first gateway (corresponding to the third address). Wherein, the intranet service identifier is determined based on the first address. Here, the controller 204 can determine the IP address of the first gateway based on the communication line for obtaining the first port, of course, the first gateway 201 can also send its IP address at the same time of sending the first port.

[0063] It should be noted that the third address and the intranet service identifier corresponding thereto can be stored in a database, here, the database can be part of the controller 204, or can be an independent database, and the present disclosure does not limit it.

[0064] Here, the intranet service identifier represents the intranet service. Exemplarily, the form of the intranet service identifier can be an intranet service domain name or a string. It should be understood that the owner of the intranet service notifies the user end of the intranet service identifier, so that the user end obtains the third address based on the intranet service identifier. For example, in the process of obtaining the intranet service, the user end first communicates with the controller 204 to obtain the third address corresponding to the required intranet service identifier, and then communicates with the first gateway 201 based on the third address. It should be noted that if the user end already knows the third address, it can directly communicate with the first gateway 201. In other words, the step of the user end communicating with the controller 204 to obtain the third address is an optional step.

[0065] As can be seen, the real address (the first address) of the intranet service is first mapped to the IP address of the second gateway 203 and the second port (i.e., the second address); next, the second address is mapped to the second node; then, the second node is mapped to the first node and the third address corresponding to the first node, and the third address becomes the only address for the user end to access the intranet service provided by the first server 206. Through multiple mappings, the technical effect of hiding the first address from the user end is achieved. At the same time, the multi-hop link between the first gateway 201 and the second gateway 203 is determined by the first gateway 201 as the first link and by the second gateway 203 as the second link, so that the first gateway 201 and the second gateway 203 do not know the entire path of the multi-hop link, increasing the anonymity of the communication path and further increasing the difficulty of tracking the first address of the first server 206, thereby improving the anonymity of the first address.

[0066] Based on the foregoing configuration method, the intranet service matches the first address, and the first address corresponds to the second port, the hidden domain name, the second node, the second link, the first node, the first link, and the first port. Thus, the communication path when the communication system based on the hidden intranet service address communicates the intranet service can be obtained. Figure 4 A communication path schematic diagram of a communication system based on a hidden intranet service address provided by an embodiment of the present disclosure is shown. As shown in Figure 4 As shown, the user end 207 first communicates with the controller 204 to determine the third address corresponding to the intranet service to be requested, and then communicates with the first gateway 201 based on the third address. The first gateway 201 communicates with the first node 2021, the first node 2021 communicates with the second node 2022 according to the first link, the second node 2022 communicates with the second gateway 203 according to the second link, the second gateway 203 determines the first address according to the second port of the second address, and communicates with the first server 206 according to the first address. Here, the first gateway 201 determines the first node 2021 corresponding to the first port based on the first configuration file. The second gateway 203 determines the first address corresponding to the second port based on the second configuration file.

[0067] The entire communication process of hiding the intranet service address, the user end takes the third address as the address of the intranet service, communicates with the first gateway 201 according to the third address, and is not aware of the first address and the first gateway 201; the first gateway 201 knows that the first node also does not know the first address; the second gateway 203 knows the first address and communicates with the first server 206 according to the first address, but does not know the user end address, that is, the entire communication process does not exist The communication node (such as the first gateway 201, the second gateway 203, and the node in the multi-hop link) that knows the user end address and the first address at the same time, the entire communication process has strong concealment, can effectively prevent reconnaissance activities, and avoid network attacks on the intranet service.

[0068] It should be noted that for different intranet services, the owner can respectively send a hidden intranet service request to start the above configuration method to obtain a corresponding hidden intranet service address communication path.

[0069] Based on the same inventive concept, the disclosure also provides a communication method of a communication system based on a hidden intranet service address corresponding to the configuration method and the communication system of any of the above embodiments.

[0070] Figure 5 A flowchart of a communication method of a communication system based on a hidden intranet service address provided by an embodiment of the disclosure is shown. Referring to Figure 5 , the communication method comprises:

[0071] S502: The first gateway 201 obtains the service access request of the user end and forwards it to the node cluster 202; wherein the service access request corresponds to a multi-hop link;

[0072] S504: The node cluster 202 sends the service access request to the second gateway 203 through the multi-hop link; it should be noted that the node cluster 202 transmits the service access request according to the multi-hop link corresponding to the service access request.

[0073] S506: The second gateway 203 receives the service access request and forwards it to the first server 206; wherein the first server is used to provide the intranet service.

[0074] In some embodiments, the first link includes a first node 2021; the first gateway 201 includes a first configuration file; the first configuration file includes at least a first port and a first node corresponding to the first port;

[0075] S502: The acquisition of the service access request of the user end and the forwarding to the node cluster 202 comprises:

[0076] According to the first port of the service access request and the first configuration file, a first node 2021 corresponding to the first port is determined.

[0077] The service access request is sent to the first node 2021.

[0078] Exemplarily, the first gateway 201 can be implemented by using a proxy server technology, such as nginx or OpenResty. By modifying the configuration file of the proxy server, the service access request can be forwarded to the first node 2021 corresponding to the first port. The node cluster 202 includes a multi-hop link, and the multi-hop link includes the first node 2021.

[0079] In some embodiments, with reference to Figure 4 The second gateway 203 includes a second configuration file; the second configuration file includes at least one second port and a first address corresponding to the second port.

[0080] S502 The service access request is sent to the node cluster, specifically including:

[0081] According to the third address of the service access request and the first configuration file, a second address corresponding to the third address of the service access request is determined.

[0082] According to the second address, the first node is determined.

[0083] The service access request is sent to the first node 2021.

[0084] In some embodiments, the second gateway 203 includes a second configuration file; the second configuration file includes at least one second address and a first address corresponding thereto.

[0085] S506: The second gateway 203 receives the service access request and forwards it to the first server 206, specifically including:

[0086] According to the second port of the service access request and the second configuration file, a corresponding first address is determined.

[0087] The service access request is sent to the first server corresponding to the first address.

[0088] It is to be understood that the foregoing description is directed to some embodiments of the disclosure. Other embodiments fall within the scope of the following claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still accomplish the desired result. In addition, the process depicted in the figures does not necessarily require the particular order shown, or sequential order to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous.

[0089] The embodiments of the disclosure further provide a communication system for hiding an internal network service address. Figure 6 A structure schematic diagram of another communication system 600 for hiding an internal network service address provided by the embodiments of the disclosure is shown. As shown in Figure 6 , the communication system 600 comprises a first gateway 201, a node cluster 202, a second gateway 203 and at least one first server 206; wherein the first gateway 201 is communicatively connected to the node cluster 202; the node cluster 202 is communicatively connected to the first gateway 201 and the second gateway 203; the second gateway 203 is communicatively connected to the first server 206; wherein the first gateway 201 is configured to communicate with a user terminal (not shown in the figure); the first server 206 is configured to provide the internal network service; the node cluster 202 comprises at least one multi-hop link, and each multi-hop link corresponds to one internal network service; the multi-hop link comprises a first link and a second link which are communicatively connected, the first link is determined by the first gateway 201; the second link is determined by the second gateway 203. Figure 6

[0090] In some embodiments, referring to Figure 4 , the first link comprises a first node 2021; the first node 2021 is communicatively connected to the first gateway 201; the first gateway 201 comprises a first configuration file, the first configuration file comprises at least one first port and a first node corresponding to the first port; the first port and the first node 2021 correspond to the unique internal network service.

[0091] In some embodiments, the second gateway 203 comprises a second configuration file, the second configuration file comprises at least one second port and a first address corresponding to the second port; the second gateway 203 determines the first address based on the second configuration file; wherein the first address corresponds to one internal network service.

[0092] In some embodiments, referring to Figure 2 and Figure 3 , the second link comprises a second node 2022; wherein the second node 2022 is communicatively connected to the first link; the communication system further comprises a controller 204, which is configured to:

[0093] ​obtain a first address (e.g. IP of a first server and a service port in an intranet) to be hidden and forward to the second gateway 203, so that the second gateway 203 determines a corresponding link identifier (which can be an anonymous link), a second port, a second node and a second link according to the first address, and updates the second configuration file;

[0094] send the link identifier fed back by the second gateway 203 to the first gateway 201, so that the first gateway 201 determines a corresponding first port, a first node and a first link based on the link identifier, and updates the first configuration file; and

[0095] receive the first port sent by the first gateway 201, and store an intranet service identifier corresponding to the first address, an IP address of the first gateway and the first port, so that the IP address of the first gateway and the first port can be acquired by the user end based on the intranet service identifier.

[0096] In some embodiments, referring to Figure 2 to 4 the second server 205 is further configured to:

[0097] obtain the link identifier and the second node 2022 sent by the second gateway 203; and

[0098] obtain the link identifier sent by the first gateway 201, and send the second node 2022 to the first gateway 201, so that the first gateway 201 determines the first link according to the second node 2022; wherein the node cluster 202 and the second server 205 are located in the same local area network.

[0099] Optionally, the controller 204 and the second server 205 can be located in different local area networks.

[0100] In some embodiments, the node cluster 202 includes at least one node; a network address of the node is configured to be dynamically switched. It should be noted that the first gateway 201 and the second gateway 203 can select the first node 2021 and the second node 2022 from the at least one node of the node cluster 202, and select part of the nodes to generate the first link and the second link.

[0101] The communication system of the above embodiments is used to implement the corresponding configuration method and communication method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which are not repeated here.

[0102] The present disclosure further provides a configuration method of a communication system for hiding an intranet service address. Referring to Figure 2 and Figure 3The communication system comprises a first gateway 201, a second gateway 203, a node cluster 202, a controller 204; the first gateway comprises a first configuration file; the second gateway comprises a second configuration file; the configuration method comprises:

[0103] The controller 204 acquires the first address to be hidden and forwards it to the second gateway 203; wherein the first address corresponds to an intranet service;

[0104] The second gateway 203 and the node cluster 202 determine the corresponding link identifier, second port and second link according to the first address; and update the second configuration file according to the first address and the second port;

[0105] The first gateway 201 and the node cluster 202 acquire and determine the first port, first node and first link according to the link identifier; and update the first configuration file according to the first port and the first node; wherein the first link and the second link connect the first gateway and the second gateway; and

[0106] The controller 204 acquires the first port, stores the intranet service identifier corresponding to the first address, the IP address of the first gateway and the first port (corresponding to the third address), so that the IP address of the first gateway and the first port can be acquired by the user terminal based on the intranet service identifier.

[0107] In some embodiments, the communication system further comprises a second server 205;

[0108] The determination of the corresponding link identifier, second node, second port and second link according to the first address comprises:

[0109] The second gateway 203 determines the corresponding link identifier and second port according to the first address; determines the second node and second link by using the node cluster 202; sends the link identifier and the second node to the second server 205; and sends the link identifier to the controller 204;

[0110] The acquisition and determination of the first port, first node and first link according to the link identifier comprises:

[0111] The first gateway 201 acquires the link identifier sent by the controller 204, determines the first port based on the link identifier; sends the link identifier to the second server 205, receives the second node fed back by the second server 205 according to the link identifier; determines the first node and first link by using the node cluster 202 according to the second node; and sends the first port to the controller.

[0112] The communication system obtained through the configuration method of the above embodiment is used to implement the communication method of any one of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which are not repeated here.

[0113] Based on the same inventive concept, the disclosure also provides an electronic device corresponding to the method of any one of the above embodiments, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements part of the steps of the configuration method or the communication method of any one of the above embodiments when executing the program.

[0114] Figure 7 A more specific hardware structure of an electronic device provided by the embodiment is shown, which can include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 for communication within the device.

[0115] The processor 1010 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits, etc., for executing related programs to implement the technical solutions provided by the embodiments of the present specification.

[0116] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs, and when the technical solutions provided by the embodiments of the present specification are implemented through software or firmware, the related program codes are stored in the memory 1020 and executed by the processor 1010.

[0117] The input / output interface 1030 is used to connect input / output modules to realize information input and output. The input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. The input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0118] The communication interface 1040 is configured to connect a communication module (not shown in the figure) to realize the communication interaction between the device and other devices. The communication module can realize communication through wired mode (such as USB, network cable, etc.), or can realize communication through wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0119] The bus 1050 includes a path for transmitting information between various components (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040) of the device.

[0120] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device can also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device can also only contain the components necessary to implement the embodiments of the present disclosure, and does not have to contain all the components shown in the figure.

[0121] The electronic device of the above embodiment is used to implement part of the steps of the corresponding configuration method or communication method in any of the preceding embodiments, and has the beneficial effects of the corresponding method embodiments, which are not described here.

[0122] Those skilled in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the present disclosure (including claims) is limited to these examples; under the idea of the present disclosure, the above embodiments or technical features in different embodiments can also be combined, the steps can be implemented in any order, and there are many other changes of different aspects of the embodiments of the present disclosure as described above. In order to be brief, they are not provided in detail.

[0123] In addition, in order to simplify the description and discussion, and so as not to make the embodiments of the present disclosure difficult to understand, the known power / ground connections of integrated circuit (IC) chips and other components can or can not be shown in the provided drawings. In addition, the devices can be shown in the form of block diagrams in order to avoid making the embodiments of the present disclosure difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform to be implemented the embodiments of the present disclosure (i.e. these details should be fully within the understanding of those skilled in the art). Where specific details (such as circuits) are set forth in order to describe an exemplary embodiment of the present disclosure, it will be apparent to those skilled in the art that the embodiments of the present disclosure can be implemented without these specific details or with variations on these specific details. Therefore, these descriptions should be considered as illustrative rather than limiting.

[0124] While the present disclosure has been described in connection with certain embodiments thereof, many modifications, substitutions, and variations will be apparent to those of ordinary skill in the art from the foregoing description. For instance, other memory architectures (e.g., dynamic RAM (DRAM)) can use the embodiments discussed.

[0125] Embodiments of the disclosure are intended to cover all such alternatives, modifications, and variations as falling within the broad scope of the appended claims. Accordingly, any one or more of the above-described embodiments can be combined with any one or more of the above-described embodiments in any manner within the scope of the disclosure.

Claims

1. A communication system for hiding internal network service addresses, characterized in that, include: A first gateway, a node cluster, a second gateway, and at least one first server; wherein, The first gateway is communicatively connected to the node cluster; the node cluster is communicatively connected to the first gateway and the second gateway; the second gateway is communicatively connected to the first server; wherein, the first gateway is used to communicate with the user terminal; the first server is used to provide the intranet service; The node cluster includes at least one multi-hop link, and each multi-hop link corresponds to one of the intranet services; the multi-hop link includes a first link and a second link for communication connection, wherein the first link is determined by the first gateway; and the second link is determined by the second gateway. Wherein, the first link includes a first node; the first node and the first gateway are communicatively connected; the first gateway includes a first configuration file, the first configuration file includes at least one first port of the first gateway and a first node corresponding to the first port; the first port and the first node correspond to a unique intranet service; The second gateway includes a second configuration file, which includes at least one second port of the second gateway and a first address corresponding to the second port; the second gateway determines the first address based on the second configuration file; wherein, the first address corresponds to one of the intranet services; The second link includes a second node; wherein the second node is communicatively connected to the first link.

2. The communication system according to claim 1, characterized in that, The communication system also includes a controller configured to: Obtain the first address to be hidden and forward it to the second gateway, so that the second gateway can determine the corresponding link identifier, second port, second node and second link based on the first address, and update the second configuration file; The link identifier fed back by the second gateway is sent to the first gateway, so that the first gateway can determine the corresponding first port, first node and first link based on the link identifier, and update the first configuration file; as well as The system receives the first port sent by the first gateway, stores the intranet service identifier corresponding to the first address, the IP address of the first gateway, and the first port, so that the IP address of the first gateway and the first port can be obtained by the user terminal based on the intranet service identifier.

3. The communication system according to claim 2, characterized in that, Also includes: The second server is configured as follows: Obtain the link identifier and the second node sent by the second gateway; as well as The second node is obtained and sent to the first gateway based on the link identifier sent by the first gateway, so that the first gateway determines the first link based on the second node; wherein the node cluster and the second server are located in the same local area network.

4. The communication system according to claim 1, characterized in that, The node cluster includes at least one node; the network address of the node is configured to switch dynamically.

5. A configuration method for a communication system that hides internal network service addresses, characterized in that, The communication system includes a first gateway, a second gateway, a node cluster, and a controller; the first gateway includes a first configuration file; the second gateway includes a second configuration file. The configuration method includes: The controller obtains the first address to be hidden and forwards it to the second gateway; wherein, the first address corresponds to an intranet service; The second gateway and the node cluster determine the corresponding link identifier, the second port of the second gateway, and the second link based on the first address; and update the second configuration file based on the first address and the second port. The first gateway and the node cluster acquire and determine the first port, first node, and first link of the first gateway based on the link identifier; update the first configuration file based on the first port and the first node; wherein the first link and the second link connect the first gateway and the second gateway; wherein the first link includes the first node; the first node and the first gateway are communicatively connected; the second link includes a second node, and the second node is communicatively connected to the first link; and The controller acquires the first port, stores the intranet service identifier corresponding to the first address, the IP address of the first gateway, and the first port, so that the IP address of the first gateway and the first port can be acquired by the user terminal based on the intranet service identifier.

6. The configuration method according to claim 5, characterized in that, The communication system also includes a second server; The step of determining the corresponding link identifier, second node, second port, and second link based on the first address includes: The second gateway determines the corresponding link identifier and second port based on the first address; uses the node cluster to determine the second node and the second link; sends the link identifier and the second node to the second server; and sends the link identifier to the controller. The step of obtaining and determining the first port, first node, and first link based on the link identifier includes: The first gateway obtains the link identifier sent by the controller, determines the first port based on the link identifier, sends the link identifier to the second server, and receives the second node fed back by the second server based on the link identifier; according to the second node, uses the node cluster to determine the first node and the first link; and sends the first port to the controller.

7. A communication method for a communication system based on a hidden intranet service address, characterized in that, The communication system includes a node cluster, a first gateway, a second gateway, and at least one first server; the node cluster includes at least one multi-hop link, and each multi-hop link corresponds to an intranet service; the multi-hop link includes a first link and a second link for communication connection, and the first link is determined by the first gateway; The second link is determined by the second gateway; The first link includes a first node; the first node and the first gateway are communicatively connected; the first gateway includes a first configuration file, the first configuration file includes at least one first port of the first gateway and a first node corresponding to the first port; the first port and the first node correspond to a unique intranet service; the second gateway includes a second configuration file, the second configuration file includes at least one second port of the second gateway and a first address corresponding to the second port; the second gateway determines the first address based on the second configuration file; wherein, the first address corresponds to an intranet service; The second link includes a second node; wherein the second node is communicatively connected to the first link; The communication method includes: The first gateway obtains the service access request from the user and forwards it to the node cluster; wherein, the service access request corresponds to one of the multi-hop links; The node cluster sends the service access request to the second gateway through the multi-hop link; The second gateway receives the service access request and forwards it to the first server; wherein the first server is used to provide the intranet service.

8. The communication method according to claim 7, characterized in that, The step of obtaining the service access request from the user and forwarding it to the node cluster includes: Based on the first port for obtaining the service access request and the first configuration file, determine the first node corresponding to the first port; Send the service access request to the first node.

9. The communication method according to claim 7, characterized in that, Receiving the service access request and forwarding it to the first server includes: Based on the second port used to obtain the service access request and the second configuration file, the corresponding first address is determined; Send the service access request to the first server corresponding to the first address.

Citation Information

Patent Citations

  • IM communication system and communication method thereof

    CN109462605A

  • Anonymous communication method, terminal equipment and computer readable storage medium

    CN115913654A