A transmission method of an application layer protocol, a computer program product, an electronic device and a storage medium

By acquiring user access information for configuration conversion and channel map comparison, and parsing and encrypting transmitted data packets, the security and stability issues in application layer protocol transmission are resolved, enabling precise access control and data interaction.

CN119484513BActive Publication Date: 2025-12-12BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411705597.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-12-12
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

Existing technologies suffer from insufficient security and stability when transmitting application layer protocols, and cannot effectively control port access, resulting in inaccurate data interaction and increasing the risk of attacks.

Method used

By acquiring user access information, performing configuration transformation and channel map comparison, parsing target data packets and encrypting their transmission, precise control over access and accuracy of data interaction can be achieved.

Benefits of technology

It improves the security and stability of application layer protocol transmission, reduces the occurrence of attacks, enhances the accuracy of data interaction, and reduces risks in access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484513B_ABST
    Figure CN119484513B_ABST
Patent Text Reader

Abstract

The application provides a transmission method of an application layer protocol, a computer program product, an electronic device and a storage medium, and the method comprises the following steps: obtaining user access information containing application layer protocol information; performing configuration conversion according to the user access information to obtain first message stream data; comparing the first message stream data with a first channel map to obtain second message stream data; analyzing the second message stream data to obtain target data packets; and performing encrypted transmission on the target data packets. By implementing the application, the security and stability of the application layer protocol in the transmission process can be improved, the occurrence of attacks can be reduced, the control strength can be improved, the accuracy of data interaction can be improved, the protocol transmission is more reasonable and effective, multiple security risks can be avoided, and the risk of the user in the access control can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data transmission, in particular to a transmission method of application layer protocol, a computer program product, an electronic device and a storage medium. BACKGROUND

[0002] The application layer protocol of the prior art is usually transmitted in a command+data form multi-link mode such as File Transfer Protocol (FTP) and the like. If security control is to be performed when the protocol passes through a network boundary, an application layer gateway (ALG) needs to be used to achieve the security control. However, with the popularization of the Transport Layer Security (TLS), more and more application layer services support the TLS. Since an encryption operation is performed, the original ALG implementation cannot parse the sub-link information through normal means, and thus cannot play a gateway role.

[0003] The prior art can simplify the problem that the sub-link is easily intercepted by a firewall or other security software or device when a client accesses by using a passive mode, but at the same time, the passive mode increases the risk of access control of the server. As a result, the FTP cannot be decrypted, and thus the expected connection mode cannot be used to dynamically open a port to achieve control of access at the port level. The FTP service needs to open the access of the data port, but this can cause an attacker to attack the open port using an arbitrary IP, or the firewall needs to increase the rules to pass the access, but the control strength is usually large, and thus the data interaction is not accurate enough. SUMMARY

[0004] The present application aims to provide a transmission method of application layer protocol, a computer program product, an electronic device and a storage medium, which can improve the security and stability of the application layer protocol in the transmission process, reduce the occurrence of attacks, improve the control strength, and thus improve the accuracy of data interaction, so that the protocol transmission is more reasonable and effective, avoids multiple security risks, and reduces the risk of the user in the access control.

[0005] In a first aspect, an embodiment of the present application provides a transmission method of application layer protocol, and the method comprises:

[0006] obtaining user access information containing application layer protocol information;

[0007] performing configuration conversion according to the user access information to obtain first message stream data;

[0008] comparing the first message stream data with a first channel map to obtain second message stream data;

[0009] Analyzing the second message stream data to obtain target data packets;

[0010] Performing encrypted transmission on the target data packets.

[0011] In the above implementation process, the configuration conversion is performed according to the user access information, and the message stream data is compared with the channel map, and then encrypted transmission is realized, which can improve the security and stability of the application layer protocol in the transmission process, reduce the occurrence of attacks, improve the control strength, and then improve the accuracy of data interaction, so that the protocol transmission is more reasonable and effective, avoids multiple security risks, and reduces the risk of user access control.

[0012] Further, the step of performing configuration conversion according to the user access information to obtain first message stream data comprises:

[0013] Configuring an access control strategy corresponding to the user access information;

[0014] Registering a sub-link according to the access control strategy to obtain the first message stream data.

[0015] In the above implementation process, the access control strategy is configured, and the sub-link is registered according to the access control strategy, which can realize accurate control of access control and improve the usability of the access control strategy and the security of the user access information.

[0016] Further, the step of comparing the first message stream data with the first channel map to obtain second message stream data comprises:

[0017] Comparing the first message stream data with the first channel map to determine whether the first message stream data hits the first channel map;

[0018] If yes, performing decryption processing on the first message stream data to obtain the second message stream data;

[0019] If no, comparing the first message stream data with a second channel map to determine whether the first message stream data hits the second channel map, and if the first message stream data does not hit the second channel map, determining that the request in the user access information is invalid, and intercepting the user request.

[0020] In the above implementation process, the first message stream data is compared with the first channel map, which can compare the first message stream data with the protocols, IP and other types of information in the first channel map and the second channel map, ensure the security of the first message stream, and improve the data transmission efficiency.

[0021] Further, the step of analyzing the second message stream data to obtain target data packets comprises:

[0022] According to the second packet flow data, the sub-link is called back to determine whether the quintuple information is successfully called back;

[0023] If yes, it is determined whether the second packet flow data needs conversion, and if the second packet flow data needs conversion, the second packet flow data is modified to obtain the target data packet.

[0024] In the above implementation process, according to the second packet flow data, the sub-link is called back to obtain the quintuple information, which can improve the granularity of data and improve the control of data transmission process, and accurately control the data channel interaction.

[0025] Further, the step of analyzing the second packet flow data to obtain the target data packet further comprises:

[0026] If the quintuple information is successfully called back, the quintuple information is added to the second channel map.

[0027] In the above implementation process, when the quintuple information is successfully called back, the quintuple information is added to the second channel map, so that the channel map can be more perfect, and the comparison accuracy of the packet flow data is further improved, so that the packet flow data is more accurate.

[0028] Further, the step of encrypting the target data packet comprises:

[0029] Detect whether there is a session between the target data packet and the server;

[0030] If yes, the target data packet is encrypted to obtain an encrypted message, and the encrypted message is transmitted;

[0031] If no, the target data packet is retransmitted.

[0032] In the above implementation process, when there is no session between the target data packet and the server, the target data packet is retransmitted to ensure the accurate and safe transmission of the target data packet, which can improve the stability and security of the application layer protocol transmission process.

[0033] Further, the step of retransmitting the target data packet comprises:

[0034] The target data packet is initialized to obtain an initialized target data packet;

[0035] The target data packet is encrypted to obtain an encrypted message, and the encrypted message is transmitted.

[0036] In the implementation process, the target data packet is initialized and then encrypted and transmitted, further improving the security performance in the transmission process, avoiding multiple security risks, and reducing the risk of users in access control.

[0037] In a second aspect, the embodiments of the present application provide a computer program product, which, when running on a computer, causes the computer to execute the method of any one of the first aspect.

[0038] In a third aspect, the embodiments of the present application provide an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the method of any one of the first aspect when executing the computer program.

[0039] In a fourth aspect, the embodiments of the present application provide a computer-readable storage medium, which stores instructions, and when the instructions run on a computer, the computer executes the method of any one of the first aspect.

[0040] In a fifth aspect, the embodiments of the present application further provide a transmission device of an application layer protocol, which includes:

[0041] An acquisition module is configured to acquire user access information containing application layer protocol information;

[0042] A configuration conversion module is configured to perform configuration conversion according to the user access information to obtain first message stream data;

[0043] A comparison module is configured to compare the first message stream data with a first channel map to obtain second message stream data;

[0044] An analysis module is configured to analyze the second message stream data to obtain target data packets;

[0045] A transmission module is configured to encrypt and transmit the target data packets.

[0046] In the implementation process, the configuration conversion is performed according to the user access information, and the message stream data is compared with the channel map, and then the encryption transmission is implemented, which can improve the security and stability of the application layer protocol in the transmission process, reduce the occurrence of attacks, improve the control strength, further improve the accuracy of data interaction, make the protocol transmission more reasonable and effective, avoid multiple security risks, and reduce the risk of users in access control.

[0047] Other features and advantages of the present disclosure will be described in the following description, or can be inferred or determined without doubt from the description, or can be known by implementing the above-mentioned technologies of the present disclosure.

[0048] and can be implemented according to the contents of the specification, which will be described in detail below with the preferred embodiments of the present application and in conjunction with the drawings. BRIEF DESCRIPTION OF DRAWINGS

[0049] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced as follows, and it should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0050] Figure 1 a flowchart of the transmission method of the application layer protocol provided by the embodiments of the present application;

[0051] Figure 2 a structural composition schematic diagram of the transmission device of the application layer protocol provided by the embodiments of the present application;

[0052] Figure 3 a structural composition schematic diagram of the electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION

[0053] The technical solutions of the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0054] It should be noted that: similar reference numerals and letters represent similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. Meanwhile, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing description, and cannot be understood as indicating or implying relative importance.

[0055] The specific embodiments of the present application will be further described in detail below in conjunction with the drawings and embodiments. The following embodiments are used to illustrate the present application, but not to limit the scope of the present application.

[0056] Embodiment one

[0057] Figure 1 a flowchart of the transmission method of the application layer protocol provided by the embodiments of the present application, as shown in Figure 1 the method comprises:

[0058] S1, obtaining user access information containing application layer protocol information;

[0059] S2, performing configuration conversion according to the user access information to obtain first message stream data;

[0060] S3, comparing the first message stream data with the first channel map to obtain second message stream data;

[0061] S4, parsing the second message stream data to obtain target data packets;

[0062] S5, performing encrypted transmission on the target data packets.

[0063] In the above implementation process, the configuration conversion is performed according to the user access information, the message stream data is compared with the channel map, and then the encrypted transmission is realized, which can improve the security and stability of the application layer protocol in the transmission process, reduce the occurrence of attacks, improve the control strength, and then improve the accuracy of data interaction, so that the protocol transmission is more reasonable and effective, avoids multiple security risks, and reduces the risk of user access control.

[0064] The embodiment of the application provides an access control method of a TLS-oriented multi-link application layer protocol, provides a configuration interface for a user, completes basic access control configuration and custom sub-link confirmation, completes the operation of restoring plaintext in the device and ensuring that the outside of the device is still ciphertext, completes the analysis of signaling on the command channel, sub-link confirmation and operating system network configuration to realize access interception.

[0065] Further, S2 includes:

[0066] Configuring an access control policy corresponding to the user access information;

[0067] Registering a sub-link according to the access control policy to obtain first message stream data.

[0068] In the above implementation process, the access control policy is configured, and the sub-link is registered according to the access control policy, which can realize accurate control of access control and improve the usability of the access control policy and the security of the user access information.

[0069] One access control policy is configured, and a sub-link confirmation conversion is registered. After being configured and issued, data items such as protocols, IPs, ports and the like are added in the first channel map.

[0070] Further, S3 includes:

[0071] Comparing the first message stream data with the first channel map to determine whether the first message stream data hits the first channel map;

[0072] If yes, performing decryption processing on the first message stream data to obtain second message stream data;

[0073] If not, the first message flow data is compared with the second channel map to determine whether the first message flow data hits the second channel map, and if the first message flow data does not hit the second channel map, it is determined that the request in the user access information is invalid, and the user request is intercepted.

[0074] In the implementation process, the first message flow data is compared with the first channel map, and the protocol, IP and other types of information in the first channel map and the second channel map can be compared to ensure the security of the first message flow and improve the data transmission efficiency.

[0075] In the embodiment of the application, the channel map (the first channel map and the second channel map) refers to parent_channel_map, and the parent_channel_map is a data structure for finding a connection.

[0076] In the first interaction, it is first determined whether the first message flow data can hit the first channel map, if not, it is considered that the request is invalid, and the device is intercepted, and if yes, the TLS offloading is performed, and the second message flow data (original message) is parsed from the first message flow data.

[0077] Further, S4 includes:

[0078] The sub-link is processed by callback according to the second message flow data to determine whether the five-tuple information is successfully called;

[0079] If yes, it is determined whether the second message flow data has a conversion requirement, and if yes, the second message flow data is modified to obtain target data packets.

[0080] In the implementation process, the sub-link is processed by callback according to the second message flow data to obtain the five-tuple information, which can improve the granularity of data and the control strength in the data transmission process, and accurately control the data channel interaction.

[0081] The five-tuple information of the sub-link to be established subsequently is obtained through the user registration sub-link conversion callback. If successful, the five-tuple information is added to the second channel map. Subsequently, the TLS does not perform any operation on the data after checking the second channel map hit by the message, and directly completes the forwarding.

[0082] Further, S4 further includes:

[0083] If the five-tuple information is successfully called, the five-tuple information is added to the second channel map.

[0084] In the implementation process, after the quintuple information is successfully called, the quintuple information is added to the first channel map, so that the channel map can be more perfect, further improving the comparison accuracy of the packet flow data, and making the packet flow data more accurate.

[0085] Further, S5 comprises:

[0086] detecting whether there is a session between the target data packet and the server;

[0087] If yes, the target data packet is encrypted to obtain an encrypted message, and the encrypted message is transmitted.

[0088] If no, the target data packet is retransmitted.

[0089] In the implementation process, when there is no session between the target data packet and the server, the target data packet is retransmitted to ensure the accurate and safe transmission of the target data packet, and the stability and security of the application layer protocol transmission process can be improved.

[0090] Further, the step of retransmitting the target data packet comprises:

[0091] initializing the target data packet to obtain an initialized target data packet;

[0092] encrypting the target data packet to obtain an encrypted message, and transmitting the encrypted message.

[0093] In the implementation process, the target data packet is initialized and then encrypted for transmission, further improving the security performance in the transmission process, avoiding multiple security risks, and reducing the risk of user access control.

[0094] After receiving the target data packet, the TLS writes the second packet flow data on the TLS encryption channel established with the server side to realize encrypted transmission.

[0095] Exemplarily, taking FTPS passive mode as an example, a user issues a gateway configuration whitelist for FTPS Server2.2.2.2:21 on a device, registers a sub-link confirmation mode as a command message hitting PASV (the ipv4 is taken as an example in the embodiment of the application, and the passive mode command of ipv6 extension is not considered), and the server response message 【227Entering Passive Mode(10,2,169,101,118,110)】 can use 256*118+110 to confirm the connection port number.

[0096] The first message stream data is transmitted to the TLS, and it is checked whether the gateway configured white list 2.2.2.2:21 is transmitted to the server. If not, the first message stream data is discarded as illegal message. If yes, the first channel map is searched, and the second message stream data (such as the original command / response message stream) is restored. If the first channel map cannot be found, the second channel map is searched subsequently. After the first channel map is found, the message is directly forwarded to 2.2.2.2:21 through the operating system, and no additional processing is performed.

[0097] The second message stream data is transmitted by the protocol such as user\pwd (login), list (list) and the like. Since the PASV check cannot be hit, the normal forwarding is transmitted to the TLS to restore the encrypted message and communicate with 2.2.2.2:21. Until the PASV is hit, the sub-link is parsed as yyyy. The device adds 2.2.2.2:yyyy to the second channel map, and prepares for the subsequent sub-link interaction. Then, the message is transmitted to the TLS to restore the encrypted transmission.

[0098] It is checked whether the original message (the second message stream data) exists syn. If yes, the TLS environment is initialized with 2.2.2.2:21, and the plaintext message (target data packet) is written in the encrypted form on this basis.

[0099] The embodiment of the application realizes that the multi-link protocol on the TLS passes through the application layer gateway, the fine control strength, the accurate control data channel interaction, the TLS unloading and loading are completed, the original message processing is realized, and a kind of fast, accurate, safe protocol data control, transmission mode is realized.

[0100] Embodiment two

[0101] The computer program product provided in the embodiment of the application makes the computer execute the method of any one of the embodiment one when the computer program product runs on the computer.

[0102] Embodiment three

[0103] In order to execute the method corresponding to the above-mentioned embodiment one, to realize the function and technical effect of response, the following provides an application layer protocol transmission device, as shown in Figure 2 The device comprises:

[0104] The acquisition module 1 is used to acquire user access information containing application layer protocol information;

[0105] The configuration conversion module 2 is used to perform configuration conversion according to the user access information, and obtain first message stream data;

[0106] The comparison module 3 is used to compare the first message stream data with the first channel map, and obtain second message stream data;

[0107] The analysis module 4 is configured to analyze the second message stream data to obtain target data packets;

[0108] The transmission module 5 is configured to encrypt and transmit the target data packets.

[0109] In the above implementation process, the configuration conversion is performed according to the user access information, and the message stream data is compared with the channel map, and then the encrypted transmission is realized, which can improve the security and stability of the application layer protocol in the transmission process, reduce the occurrence of attacks, improve the control strength, and then improve the accuracy of data interaction, so that the protocol transmission is more reasonable and effective, avoids multiple security risks, and reduces the risk of user access control.

[0110] Further, the configuration conversion module 2 is further configured to:

[0111] configure an access control policy corresponding to the user access information;

[0112] register a sub-link according to the access control policy to obtain first message stream data.

[0113] In the above implementation process, the access control policy is configured, and the sub-link is registered according to the access control policy, which can realize accurate control of access control and improve the usability of the access control policy and the security of the user access information.

[0114] Further, the comparison module 3 is further configured to:

[0115] compare the first message stream data with the first channel map to determine whether the first message stream data hits the first channel map;

[0116] If yes, the first message stream data is decrypted to obtain second message stream data;

[0117] If not, the first message stream data is compared with the second channel map to determine whether the first message stream data hits the second channel map, and if the first message stream data does not hit the second channel map, it is determined that the request in the user access information is invalid, and the user request is intercepted.

[0118] In the above implementation process, the first message stream data is compared with the first channel map, which can compare the protocols, IP and other types of information in the first message stream data and the first channel map, ensure the security of the first message stream, and improve the data transmission efficiency.

[0119] Further, the analysis module 4 is further configured to:

[0120] According to the second message stream data, the sub-link is called back to determine whether the five-tuple information is successfully called;

[0121] If yes, it is judged whether the second packet flow data has conversion requirement, and if yes, the second packet flow data is modified to obtain target data packet.

[0122] In the implementation process, the sub-link is called back according to the second packet flow data to obtain the quintuple information, which can improve the data granularity and the control strength in the data transmission process, and accurately control the data channel interaction.

[0123] Further, the parsing module 4 is further used for:

[0124] If the quintuple information is successfully called, the quintuple information is added to the second channel map.

[0125] In the implementation process, after the quintuple information is successfully called, the quintuple information is added to the first channel map, so that the channel map can be more perfect, further improving the comparison accuracy of the packet flow data, and making the packet flow data more accurate.

[0126] Further, S5 includes:

[0127] It is judged whether there is a session between the target data packet and the server;

[0128] If yes, the target data packet is encrypted to obtain an encrypted message, and the encrypted message is transmitted;

[0129] If no, the target data packet is retransmitted.

[0130] In the implementation process, when there is no session between the target data packet and the server, the target data packet is retransmitted to ensure the accurate and safe transmission of the target data packet, which can improve the stability and security in the application layer protocol transmission process.

[0131] Further, the transmission module 5 is further used for:

[0132] The target data packet is initialized to obtain an initialized target data packet;

[0133] The target data packet is encrypted to obtain an encrypted message, and the encrypted message is transmitted.

[0134] In the implementation process, the target data packet is initialized and then encrypted and transmitted, which further improves the security performance in the transmission process, avoids multiple security risks, and reduces the risk of user access control.

[0135] The application layer protocol transmission device described above can implement the method of the above-mentioned embodiment one. The options in the above-mentioned embodiment one are also applicable to this embodiment, which will not be described in detail here.

[0136] The remaining contents of the embodiments of the present application can refer to the contents of the above-mentioned embodiment one. In the present embodiment, no longer be described.

[0137] Embodiment four

[0138] The embodiments of the present application provide an electronic device, comprising a memory and a processor, the memory is used for storing a computer program, and the processor runs the computer program to make the electronic device execute the transmission method of the application layer protocol of embodiment one.

[0139] Optionally, the electronic device can be a server.

[0140] Please refer to Figure 3 , Figure 3 The structural composition schematic diagram of the electronic device provided by the embodiments of the present application is shown. The electronic device can include a processor 31, a communication interface 32, a memory 33 and at least one communication bus 34. Wherein, the communication bus 34 is used to realize the direct connection communication of these components. Wherein, the communication interface 32 of the device in the embodiments of the present application is used to communicate with other node devices. The processor 31 can be an integrated circuit chip with signal processing capability.

[0141] The processor 31 described above can be a general processor, including a central processing unit (CPU), a network processor (NP) and the like; It can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a ready programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. Can realize or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general processor can be a microprocessor or the processor 31 can also be any conventional processor or the like.

[0142] The memory 33 can be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read only memory (PROM), an erasable programmable read only memory (EPROM), an electrically erasable programmable read only memory (EEPROM) and the like. The memory 33 stores computer readable instructions, when the computer readable instructions are executed by the processor 31, the device can execute the above-mentioned Figure 1The method embodiment relates to each step.

[0143] Optionally, the electronic device can further include a storage controller, an input / output unit. The memory 33, the storage controller, the processor 31, the peripheral interface, the input / output unit are electrically connected with each other directly or indirectly to realize data transmission or interaction. For example, the elements can be electrically connected with each other through one or communication buses 34. The processor 31 is used to execute the executable modules stored in the memory 33, for example, software function modules or computer programs included by the device.

[0144] The input / output unit is used to provide a user with a creation task and create a start optional period or a preset execution time for the task to realize the interaction between the user and the server. The input / output unit can be, but is not limited to, a mouse, a keyboard and the like.

[0145] It can be understood that, Figure 3 The structure shown is only schematic, and the electronic device can further include more or less components than those shown in the figures, or have a different configuration of components than those shown in the figures. Figure 3 The components shown in the figures can be realized in hardware, software or a combination thereof. Figure 3 The components shown in the figures can be realized in hardware, software or a combination thereof. Figure 3 The components shown in the figures can be realized in hardware, software or a combination thereof.

[0146] In addition, the embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to realize the transmission method of the application layer protocol in the embodiment one.

[0147] The embodiment of the present application further provides a computer program product, which runs on a computer to make the computer execute the method in the method embodiment.

[0148] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented by other manners. The apparatus embodiments described above are only illustrative, for example, the flowcharts and block diagrams in the drawings show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment or a part of code, which contains one or more executable instructions for implementing the specified logic function. It should also be noted that in some alternative implementation manners, the functions noted in the blocks can also occur in different order from that noted in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can also be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based apparatus performing the specified function or action, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0149] In addition, the function modules in the embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0150] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk, and various program code storage media.

[0151] The above only describes the embodiments of the present application and does not limit the protection scope of the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0152] The above descriptions are merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0153] It should be noted that the relative terms, such as first and second, and the like, are used herein only to distinguish one entity or action from another, and do not necessarily require or imply any actual such relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without further limitation, an element defined by an "includes a..." statement does not exclude the existence of additional identical elements in the process, method, article, or apparatus that includes the element.

Claims

1. A method of transmitting an application layer protocol, characterized by, The method comprises: Obtaining user access information containing application layer protocol information; Conducting configuration conversion according to the user access information to obtain first message stream data; Comparing the first message stream data with a first channel map to obtain second message stream data; Analyzing the second message stream data to obtain target data packets; Encrypting and transmitting the target data packets; The step of comparing the first message stream data with the first channel map to obtain second message stream data comprises: Comparing the first message stream data with the first channel map to determine whether the first message stream data hits the first channel map; If yes, decrypting and processing the first message stream data to obtain the second message stream data; If no, comparing the first message stream data with a second channel map to determine whether the first message stream data hits the second channel map, and if the first message stream data does not hit the second channel map, determining that the request in the user access information is invalid and intercepting the user request; The first channel map and the second channel map are a data structure for searching for a connection; An access control policy is configured, and a sub-link confirmation conversion is registered, and after being configured and delivered, protocol, IP, and port data items are added in the first channel map; Through a sub-link conversion callback registered by a user, five-tuple information of a subsequent sub-link to be established is obtained, and if the five-tuple information is successfully called, the five-tuple information is added to the second channel map, and after the second channel map is checked, no operation is performed on the data, and forwarding is directly completed.

2. The transport method of application layer protocol according to claim 1, wherein, The step of conducting configuration conversion according to the user access information to obtain first message stream data comprises: Configuring an access control policy corresponding to the user access information; Registering a sub-link according to the access control policy to obtain the first message stream data.

3. The transport method of application layer protocol according to claim 1, wherein, The step of analyzing the second message stream data to obtain target data packets comprises: Performing callback processing on the sub-link according to the second message stream data to determine whether five-tuple information is successfully called; If yes, determining whether the second message stream data has conversion requirements, and if the second message stream data has conversion requirements, modifying the second message stream data to obtain the target data packets.

4. The transport method of application layer protocol according to claim 1, wherein, The step of encrypting and transmitting the target data packets comprises: Determining whether a session exists between the target data packets and a server; If yes, encrypting the target data packets to obtain encrypted messages, and transmitting the encrypted messages; If no, retransmitting the target data packets.

5. The transport method of application layer protocol according to claim 4, wherein, The step of retransmitting the target data packets comprises: Initializing the target data packets to obtain initialized target data packets; Encrypting the target data packets to obtain encrypted messages, and transmitting the encrypted messages.

6. A computer program product, characterised in that, The computer program product, when running on a computer, causes the computer to execute the method according to any one of claims 1 to 5.

7. An electronic device, comprising: An electronic device comprising a memory for storing a computer program and a processor for running the computer program to cause the electronic device to perform the transmission method of the application layer protocol according to any one of claims 1 to 5.

8. A storage medium, characterized by A computer program product, which stores a computer program, the computer program being executed by a processor to implement the transmission method of the application layer protocol according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Message processing method and device, electronic equipment and storage medium

    CN112055032A

  • Security gateway, system and method for verifying egress traffic in computer network system

    CN119011257A