A key agreement exception diagnosis method, device, equipment and storage medium
By generating and sending a service probe request on the service requesting party, determining the consistency of the network response message format, and performing protocol parsing, the difficulty of locating anomalies caused by network issues during key negotiation is resolved, achieving the effect of quickly locating anomalies.
Patent Information
- Application Number
- CN202411949860.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-12-27
AI Technical Summary
In existing technologies, anomalies caused by network issues during key negotiation cannot be quickly located, especially when VPN devices are deployed at headquarters and branch offices, requiring both parties to participate in the investigation, which makes it difficult to quickly locate the problem.
The service requester generates a service probe request based on the key negotiation diagnostic command from the management end, and determines whether the network response message format of the service responder is consistent with the format of the preset key negotiation diagnostic protocol, and performs protocol parsing to identify abnormal situations.
Quickly identify the cause of anomalies during key negotiation, reduce manpower and time costs, and improve the efficiency of problem localization.
Smart Images

Figure CN119696993B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, in particular to a key agreement exception diagnosis method and device, equipment and storage medium. BACKGROUND
[0002] The error notification mechanism provided by the current key exchange protocol mainly includes errors in protocol format, security alliance parameters, keys, certificates and the like. These errors are mainly used to locate the protocol implementation or configuration problems of the communication parties themselves. However, in actual deployment, there are still many problems such as key agreement failure or encrypted data communication after key agreement completion caused by network reasons, which cannot be quickly located. These network problems may be caused by the related strategies of firewall, router, encryption machine and other intermediate network equipment, and it is necessary to invest manpower to analyze and troubleshoot using some tool commands. Since the VPN (Virtual Private Network) equipment is generally deployed in the headquarters and branches respectively, both parties need to participate at the initial stage of troubleshooting, which causes the problems in the key agreement process to be unable to be quickly located. Therefore, how to quickly determine the cause of the exception in the key agreement process is a problem to be solved at present. SUMMARY
[0003] Therefore, the purpose of the present application is to provide a key agreement exception diagnosis method, device, equipment and storage medium applied to a service requester, which can quickly determine the cause of the exception in the key agreement process. The specific scheme is as follows:
[0004] In a first aspect, the present application discloses a key agreement exception diagnosis method applied to a service requester, comprising:
[0005] generating a service detection request for a service responder based on a key agreement diagnosis instruction issued by a management end, and sending the service detection request to the service responder;
[0006] obtaining a network response message sent by the service responder for the service detection request, and determining whether the message format of the network response message is consistent with the message format of a preset key agreement diagnosis protocol;
[0007] if the message format of the network response message is consistent with the message format of the preset key agreement diagnosis protocol, performing diagnosis protocol analysis on the network response message to obtain a corresponding protocol analysis result;
[0008] determining a service detection result based on the protocol analysis result, and sending the service detection result to the management end so that the management end determines a key agreement exception condition based on the service detection result.
[0009] Optionally, the key negotiation diagnosis instruction issued by the management end is used to generate a service probe request for the service responder, and the service probe request is sent to the service responder, including:
[0010] The key negotiation diagnosis instruction issued by the management end is acquired, and a service probe request for the service responder is generated based on the responder IP information in the key negotiation diagnosis instruction, and the service probe request is sent to the service responder.
[0011] Optionally, the key negotiation diagnosis instruction issued by the management end is used to generate a service probe request for the service responder, and the service probe request is sent to the service responder, including:
[0012] The key negotiation diagnosis instruction issued by the management end is used to generate a key negotiation service probe request for the service responder based on the responder IP information in the key negotiation diagnosis instruction, and the key negotiation service probe request is sent to the service responder.
[0013] Correspondingly, the service probe result is determined based on the protocol analysis result, and the service probe result is sent to the management end so that the management end determines the key negotiation abnormal situation based on the service probe result, including:
[0014] The message ID and the message type in the protocol analysis result are compared with the message ID and the message type of the key negotiation service probe request.
[0015] The key negotiation service running state is determined based on the comparison result, and the key negotiation service running state is sent to the management end so that the management end determines the key negotiation abnormal situation based on the key negotiation service running state.
[0016] Optionally, the key negotiation diagnosis instruction issued by the management end is used to generate a service probe request for the service responder, and the service probe request is sent to the service responder, including:
[0017] The NAT service probe request is generated based on the responder IP information and the responder port information in the key negotiation diagnosis instruction, and the local IP information and the local port information, and the NAT service probe request is sent to the service responder.
[0018] Correspondingly, the service probe result is determined based on the protocol analysis result, and the service probe result is sent to the management end so that the management end determines the key negotiation abnormal situation based on the service probe result, including:
[0019] The protocol analysis result is compared with IP information, port information, message type, and message ID in the NAT service probe request; the IP information includes the responder IP information and the local IP information, and the port information includes the responder port information and the local port information;
[0020] Based on the comparison result, the local NAT environment state and the NAT environment state corresponding to the service responder are determined, and the local NAT environment state and the NAT environment state corresponding to the service responder are sent to the management end, so that the management end determines the key agreement abnormal condition based on the local NAT environment state and the NAT environment state corresponding to the service responder.
[0021] Optionally, the service probe request for the service responder is generated based on the responder IP information in the key agreement diagnosis instruction, and the service probe request is sent to the service responder, including:
[0022] The maximum packet length probe request is generated based on the responder IP information in the key agreement diagnosis instruction and a preset minimum negotiation packet length, and the maximum packet length probe request is sent to the service responder;
[0023] Correspondingly, the service probe result is determined based on the protocol analysis result, and the service probe result is sent to the management end so that the management end determines the key agreement abnormal condition based on the service probe result, including:
[0024] It is judged whether the protocol analysis result is consistent with the maximum packet length probe request;
[0025] If the protocol analysis result is consistent with the maximum packet length probe request, the packet length of the maximum packet length probe request is increased based on a preset packet length increasing method to obtain a new maximum packet length probe request, and the step of sending the maximum packet length probe request to the service responder is jumped to, until the network response message sent by the service responder to the maximum packet length probe request is not acquired within a preset time, the maximum target packet length for communication with the service responder is determined;
[0026] The maximum target packet length is sent to the management end, so that the management end determines the key agreement abnormal condition based on the maximum target packet length.
[0027] Optionally, after the network response message sent by the service responder to the maximum packet length probe request is not acquired within a preset time, the maximum target packet length for communication with the service responder is determined, including:
[0028] If the network response message sent by the service responder for the maximum message length detection request is not acquired within a preset time, a previous maximum message length detection request is acquired, and a message length in the previous maximum message length detection request is determined as a maximum target message length for communication with the service responder.
[0029] Optionally, the judging whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol comprises:
[0030] judging whether the message length of the network response message is greater than a preset byte length;
[0031] If the message length of the network response message is greater than the preset byte length, whether data on a preset byte bit of the network response message is consistent with data on a preset byte bit of the preset key negotiation diagnosis protocol is judged in sequence; the preset byte bit comprises a Cookie field and a preamble field.
[0032] In a second aspect, the application discloses a key negotiation exception diagnosis device, applied to a service requester, comprising:
[0033] a detection request sending module, configured to generate a service detection request for a service responder based on a key negotiation diagnosis instruction issued by a management end, and send the service detection request to the service responder;
[0034] a message format comparison module, configured to acquire a network response message sent by the service responder for the service detection request, and judge whether a message format of the network response message is consistent with a message format of a preset key negotiation diagnosis protocol;
[0035] a protocol analysis result acquisition module, configured to, if the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, perform diagnosis protocol analysis on the network response message to obtain a corresponding protocol analysis result;
[0036] a detection result sending module, configured to determine a service detection result based on the protocol analysis result, and send the service detection result to the management end so that the management end determines a key negotiation exception condition based on the service detection result.
[0037] In a third aspect, the application discloses an electronic device, comprising:
[0038] a memory, configured to save a computer program;
[0039] a processor, configured to execute the computer program to implement the key negotiation exception diagnosis method.
[0040] In a fourth aspect, the present application discloses a computer readable storage medium for storing a computer program, wherein the computer program is executed by a processor to implement the key negotiation exception diagnosis method.
[0041] In the present application, the service requester generates a service probe request for the service responder based on the key negotiation diagnosis instruction issued by the management end, and sends the service probe request to the service responder; then acquires the network response message sent by the service responder for the service probe request, and judges whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol; if the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, the network response message is analyzed according to the diagnosis protocol to obtain the corresponding protocol analysis result; finally, the service probe result is determined based on the protocol analysis result, and the service probe result is sent to the management end so that the management end determines the key negotiation exception condition based on the service probe result. It can be seen that in the present application, the service requester generates a service probe request by using the key negotiation diagnosis instruction issued by the management end, and then sends the service probe request to the service responder, and acquires the network response message sent by the service responder based on the service probe request, to judge whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, so as to determine the service probe result based on the judgment result and send the service probe result to the management end, so that the management end determines the key negotiation exception condition based on the service probe result. Since the service probe result is determined based on the message format of the network response message and the message format of the preset key negotiation diagnosis protocol, the management end can judge whether the service between the service requester and the service responder is abnormal based on the preset key negotiation diagnosis protocol after acquiring the service probe result, so as to quickly determine the reason for the abnormality in the key negotiation process. BRIEF DESCRIPTION OF DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on the provided drawings.
[0043] Figure 1 A key negotiation exception diagnosis method flow chart disclosed by the present application;
[0044] Figure 2 A message format diagram of a preset key negotiation diagnosis protocol disclosed by the present application;
[0045] Figure 3A message type definition diagram disclosed by the present application;
[0046] Figure 4 A network response message receiving and processing flow diagram disclosed by the present application;
[0047] Figure 5 A specific key negotiation exception diagnosis method flow chart disclosed by the present application;
[0048] Figure 6 A specific key negotiation exception diagnosis method flow chart disclosed by the present application;
[0049] Figure 7 A specific preset key negotiation diagnosis protocol message format diagram disclosed by the present application;
[0050] Figure 8 A specific key negotiation exception diagnosis method flow chart disclosed by the present application;
[0051] Figure 9 A specific key negotiation exception diagnosis method flow chart disclosed by the present application;
[0052] Figure 10 A specific preset key negotiation diagnosis protocol message format diagram disclosed by the present application;
[0053] Figure 11 An address type definition diagram disclosed by the present application;
[0054] Figure 12 A specific key negotiation exception diagnosis method flow chart disclosed by the present application;
[0055] Figure 13 A specific key negotiation exception diagnosis method flow chart disclosed by the present application;
[0056] Figure 14 A specific preset key negotiation diagnosis protocol message format diagram disclosed by the present application;
[0057] Figure 15 A key negotiation exception diagnosis device structure diagram disclosed by the present application;
[0058] Figure 16 An electronic device structure diagram disclosed by the present application. DETAILED DESCRIPTION
[0059] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described, obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work belong to the scope of protection of the present application.
[0060] Currently, when positioning the specific reasons for the failure of key negotiation caused by network problems or the failure to implement encrypted data communication after the completion of negotiation, since these network problems can be caused by the related strategies of intermediate network devices such as firewalls, routers, encryption machines, etc., it is necessary to invest manpower to analyze and troubleshoot by using some tool commands, and the VPN devices are generally deployed in the headquarters and branches, so that both parties need to participate at the same time at the initial stage of troubleshooting, which causes the problem in the key negotiation process to be unable to be quickly positioned. In order to solve the above technical problems, the present application discloses a key negotiation exception diagnosis method, device, equipment and storage medium, which is applied to a service requester and can quickly determine the cause of the exception in the key negotiation process.
[0061] Referring to Figure 1 The embodiments of the present application disclose a key negotiation exception diagnosis method, device, equipment and storage medium, which are applied to a service requester and include the following steps:
[0062] Step S11, generating a service detection request for a service responder based on the key negotiation diagnosis instruction issued by the management end, and sending the service detection request to the service responder.
[0063] In the present embodiment, the administrator will issue different key negotiation diagnosis instructions to the service requester through the management end based on the diagnosis requirements, and the information contained in different key negotiation diagnosis instructions can be different. Specifically, the key negotiation diagnosis instruction issued by the management end needs to contain the responder IP (Internet Protocol) information, so that the service requester can generate a service detection request for the service responder based on the responder IP information. If the management end needs to diagnose whether there is a NAT (Network Address Translation) environment in the network of the service requester and the network of the service responder, the key negotiation diagnosis instruction needs to contain the responder IP information and the responder port information. After receiving the key negotiation diagnosis instruction issued by the management end, the service requester will generate a service detection request for the service responder based on the preset key negotiation diagnosis protocol and the key negotiation diagnosis instruction, and send the service detection request to the service responder, so that the service responder can generate a corresponding network response message based on the service detection request.
[0064] In step S12, the network response message sent by the service responder to the service probe request is acquired, and it is determined whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnostic protocol.
[0065] In this embodiment, the service requester can acquire the network response message sent by the service responder to the service probe request based on a preset time. If the service requester acquires the network response message within the preset time, it is determined whether the network response message is the network response message sent by the service responder to the service probe request based on the message format of the preset key negotiation diagnostic protocol.
[0066] Since the service probe request sent by the service requester is generated based on the preset key negotiation diagnostic protocol, the protocol shares the ports 500 and 4500 with the IKE (Internet key exchange), and in order to ensure that the key negotiation service can normally parse the two protocols on the same port, the protocol format of the preset key negotiation diagnostic protocol is as shown in the following table. Figure 2 The Cookie field corresponds to the initiator Cookie field in the header of the IKE, has a length of 8 bytes, and is used to distinguish the IKE, and the value of the Cookie field is 0. The preamble is used to identify the protocol together with the Cookie field, has a length of 2 bytes, and the value is 0xFF, 0xFF. The version field is used to identify the version of the protocol, has a length of 1 byte, and the value is 0x01, indicating the first version of the protocol. The length field is used to identify the length of the entire message including the message header, has a length of 2 bytes, and is calculated by Figure 2 It is known that the length of the message constructed based on the protocol is 18+N bytes, wherein N represents the length of the message content, and 18 bytes is the length of the message header. The message type is used to identify the type of the message, has a length of 1 byte, Figure 3 The message ID (Identity document) field is a random number generated by the service requester, is used to associate the service probe request and the network response message, has a length of 4 bytes, and is used to define the message type. The flowchart of the process in which the service requester receives and processes the network response message is as shown in the following figure. Figure 4As shown, the service requester first judges whether the message length of the network response message is greater than the preset byte length, i.e. 18 bytes, after obtaining the network response message. If the message length of the network response message is greater than 18 bytes, the service requester successively judges whether the data on the preset byte bit of the network response message is consistent with the data on the preset byte bit of the preset key negotiation diagnostic protocol. The preset byte bit includes a Cookie field and a preamble field, i.e. judges whether the first 8 bytes of the network message is 0. If the first 8 bytes is 0, judges whether the preamble is 0xFF, 0xFF. If the preamble is 0xFF, 0xFF, it indicates that the message format of the network response message is consistent with the message format of the preset key negotiation diagnostic protocol.
[0067] In addition, if the message length of the network response message is not greater than 18 bytes, or the message length is greater than 18 bytes but the preamble is not 0xFF, 0xFF, it indicates that the message format of the network response message is incorrect. If the message length of the network message is greater than 28 bytes and the first 8 bytes is not 0, it indicates that the network response message is IKE. The network response message is parsed to complete the corresponding key negotiation processing. Meanwhile, if the service requester does not obtain the corresponding network response message within a preset time, it is considered that the obtaining is timed out, and the corresponding service detection result is directly generated and sent to the management end, so that the management end determines the key negotiation abnormal condition based on the service detection result.
[0068] Step S13, if the message format of the network response message is consistent with the message format of the preset key negotiation diagnostic protocol, the network response message is parsed according to the diagnostic protocol to obtain the corresponding protocol analysis result.
[0069] In this embodiment, as shown in Figure 4 If the message format of the network response message received by the service requester is consistent with the message format of the preset key negotiation diagnostic protocol, it indicates that the network response message is a key negotiation diagnostic protocol. The network response message is parsed to obtain the corresponding protocol diagnostic result, and the corresponding operation is performed based on the protocol diagnostic result.
[0070] Step S14, based on the protocol analysis result, a service detection result is determined, and the service detection result is sent to the management end so that the management end determines the key negotiation abnormal condition based on the service detection result.
[0071] In this embodiment, after obtaining the protocol analysis result, the service requester determines whether the network response message corresponds to the service detection request based on the message type and the message ID in the protocol analysis result. If the message type and the message ID of the network response message correspond to the message type and the message ID of the service detection request, it is determined that the network response message is the network response message sent by the service responder to the service detection request, and a service detection result indicating that the current service detection is successful is generated. If the message type and the message ID of the network response message do not correspond to the message type and the message ID of the service detection request, it is determined that the network response message is not the network response message sent by the service responder to the service detection request, and a service detection result indicating that the current service detection fails is generated. After obtaining the service detection result, the service requester sends the service detection result to the management end, so that the management end determines the cause of the key agreement exception based on the service detection result.
[0072] It can be seen that, in the present application, the service requester generates a service detection request by using the key agreement diagnosis instruction issued by the management end, and then sends the service detection request to the service responder, and obtains the network response message sent by the service responder based on the service detection request, to determine whether the message format of the network response message is consistent with the message format of the preset key agreement diagnosis protocol, so as to determine the service detection result based on the determination result and send the service detection result to the management end, so that the management end determines the key agreement exception based on the service detection result. Since the service detection result is determined based on the message format of the network response message and the message format and the protocol analysis result of the preset key agreement diagnosis protocol, the management end can determine whether the service between the service requester and the service responder is abnormal based on the preset key agreement diagnosis protocol after obtaining the service detection result, so as to quickly determine the cause of the abnormality in the key agreement process.
[0073] Based on the above embodiment, the present application discloses a key agreement exception diagnosis method applied to a service requester, which can quickly determine the cause of the abnormality in the key agreement process. Next, a specific key agreement exception diagnosis process will be described.
[0074] Referring to Figure 5 The present application discloses a specific key agreement exception diagnosis method applied to a service requester, which includes:
[0075] In step S21, a key agreement diagnosis instruction issued by the management end is obtained, and a key agreement service detection request for a service responder is generated based on the responder IP information in the key agreement diagnosis instruction, and the key agreement service detection request is sent to the service responder.
[0076] In this embodiment, the process of key agreement service detection can refer to Figure 6The key negotiation service probe request is used to probe whether the network of the service responder is reachable and the key negotiation service is normally started. Therefore, the IP information of the responder needs to be included in the key negotiation diagnosis instruction issued by the management end and acquired by the service request end, so as to generate the key negotiation service probe request for the service responder. The message format of the key negotiation service probe request is as shown in the following table 1. Figure 7 As shown in the table 1, only the message type needs to be indicated in the message header, and the message content does not need the data field. Among them, the value of the message type field of the key negotiation service probe request is 1. Figure 3
[0077] Step S22, acquiring the network response message sent by the service responder for the key negotiation service probe request, and judging whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol.
[0078] Step S23, if the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, performing diagnosis protocol analysis on the network response message to obtain the corresponding protocol analysis result.
[0079] Step S24, comparing the message ID and the message type in the protocol analysis result with the message ID and the message type of the key negotiation service probe request.
[0080] In the embodiment, if the message ID and the message type in the protocol analysis result correspond to the message ID and the message type in the key negotiation service probe request, it is indicated that the network response message is the network response message sent by the service responder for the key negotiation service probe request, and the network of the service responder is reachable and the key negotiation service is normally started. If the message ID and / or the message type in the protocol analysis result do not correspond to the message ID and / or the message type in the key negotiation service probe request, it is indicated that the network response message is not the network response message sent by the service responder for the key negotiation service probe request. That is, if the value of the message type field in the protocol analysis result is 2 and the message ID is consistent with the message ID in the key negotiation service probe request, it is indicated that the network response message is the network response message sent by the service responder for the key negotiation service probe request, and the network of the service responder is reachable and the key negotiation service is normally started. Otherwise, it is indicated that an abnormality occurs in the key negotiation service probe process.
[0081] Step S25, determining the running state of the key negotiation service based on the comparison result, and sending the running state of the key negotiation service to the management end, so that the management end determines the key negotiation abnormality based on the running state of the key negotiation service.
[0082] The more specific processing procedures of the above steps S22, S23 and S25 can refer to the corresponding contents disclosed in the foregoing embodiments, which will not be described here in detail.
[0083] It can be seen that, in the embodiment, the message ID and the message type in the protocol analysis result are compared with the message ID and the message type in the key negotiation service probe request to obtain a comparison result, and it is determined whether the key negotiation service is normally running based on the comparison result, the running state of the key negotiation service is sent to the management end so that the management end determines a key negotiation abnormal condition based on the running state of the key negotiation service, and corresponding operations are performed based on the key negotiation abnormal condition.
[0084] As shown in Figure 8 The application discloses a specific key negotiation abnormality diagnosis method, which is applied to a service requester and includes the following steps.
[0085] In step S31, a key negotiation diagnosis instruction issued by the management end is acquired, a NAT service probe request is generated based on the responder IP information and the responder port information in the key negotiation diagnosis instruction and the local IP information and the local port information, and the NAT service probe request is sent to the service responder.
[0086] In the embodiment, the specific process of the NAT service probe can refer to Figure 9 As shown in the figure, the NAT probe is used to probe the network communication environment of both parties, the service requester sends a NAT probe request carrying the IP information and the port information of both parties, the service responder returns the IP and port information seen by itself to the requester after receiving the message, and the requester compares the IP information and the port information provided by both parties to confirm whether there is a NAT environment in the respective network. Therefore, the key negotiation diagnosis instruction issued by the management end needs to include the responder IP information and the responder port information, the service requester generates a corresponding NAT service probe request based on the responder IP information and the responder port information and the local IP information and the local port information saved locally, and sends the NAT service probe request to the service responder. The message format of the NAT service probe request is as shown in the figure. Figure 10 As shown in the figure, the address type field is used to identify the address type used for communication, and the length is 1 byte. The address type definition is as follows. Figure 11The requestor IP field is used to identify the service requestor IP, and its length is determined according to the address type field. When the address type is IPv4, the length is 4 bytes; and when the address type is IPv6, the length is 16 bytes. The requestor port field is used to identify the service requestor port, and its length is 2 bytes. The response IP field is used to identify the service response IP, and its length is determined according to the address type field. When the address type is IPv4, the length is 4 bytes; and when the address type is IPv6, the length is 16 bytes. The response port field is used to identify the response port, and its length is 2 bytes. The message type field in the NAT service probe request message is 3. Figure 3 The value of the message type field in the NAT service probe request message is 3. Figure 9 A1 and A1' in the NAT service probe request and the network response message respectively represent the local IP information and the local IP information in the network response message, A2 and A2' respectively represent the response IP information in the NAT service probe request and the response IP information in the network response message, B1 and B1' respectively represent the local port information in the NAT service probe request and the local port information in the network response message, and B2 and B2' respectively represent the response information in the NAT service probe request and the response information in the network response message.
[0087] In step S32, the network response message sent by the service response to the NAT service probe request is acquired, and it is determined whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol.
[0088] In step S33, if the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, the network response message is diagnosed and analyzed to obtain a corresponding protocol analysis result.
[0089] In step S34, the protocol analysis result is compared with the IP information, the port information, the message type and the message ID in the NAT service probe request. The IP information includes the response IP information and the local IP information, and the port information includes the response port information and the local port information.
[0090] In the embodiment, if the message ID and the message type in the protocol analysis result correspond to the message ID and the message type in the key negotiation service probe request, it is indicated that the NAT service probe request and the network response message are corresponding, and it is determined whether there is a NAT environment in the network of the service requestor and the service response based on the IP information and the port information in the protocol analysis result. That is, if the value of the message type field in the protocol analysis result is 4, and the message ID in the protocol analysis result is consistent with the message ID in the NAT service probe request, it is indicated that the network response message is the network response message sent by the service response to the NAT service probe request.
[0091] Step S35, determining the local NAT environment state and the NAT environment state corresponding to the service responder based on the comparison result, and sending the local NAT environment state and the NAT environment state corresponding to the service responder to the management end, so that the management end determines the key agreement exception condition based on the local NAT environment state and the NAT environment state corresponding to the service responder.
[0092] In this embodiment, if the local IP information and the local port information in the protocol analysis result are inconsistent with the local IP information and the local port information in the NAT service detection request, it indicates that there is a NAT environment in the network of the service requester; if the responder IP information and the responder port information in the protocol analysis result are inconsistent with the responder IP information and the responder port information in the NAT service detection request, it indicates that there is a NAT environment in the network of the service responder; if the IP information and the port information in the protocol analysis result are inconsistent with the IP information and the port information in the NAT service detection request, it indicates that both the service responder and the service requester have a NAT environment. That is, if the IP information and the port information in the protocol analysis result are inconsistent with the corresponding IP information and port information in the NAT service detection response, and both the network of the service responder and the network of the service requester have a NAT environment, otherwise, it indicates that at least one of the service responder and the service requester does not have a NAT environment.
[0093] The more specific processing procedures of steps S32, S33 and S35 will be described in detail in the following embodiments.
[0094] It can be seen that, in this embodiment, the message type, message ID, IP information and port information in the protocol analysis result are compared with the message type, message ID, IP information and port information in the NAT service detection request to obtain a comparison result, and whether the service requester and the service responder have a NAT environment is determined based on the comparison result, so as to determine the NAT environment states of the two parties. The NAT environment states are sent to the management end so that the management end determines the key agreement exception condition based on the NAT environment states, and performs corresponding operations based on the key agreement exception condition.
[0095] Referring to Figure 12 The application discloses a specific key agreement exception diagnosis method, which is applied to a service requester and includes the following steps.
[0096] Step S41, obtaining a key agreement diagnosis instruction issued by a management end, generating a maximum packet length detection request based on responder IP information in the key agreement diagnosis instruction and a preset minimum negotiation packet length, and sending the maximum packet length detection request to a service responder.
[0097] In this embodiment, as shown in Figure 13 The maximum message length detection request is used to detect the maximum IP message length that can be passed by the network of both parties, and the result can be obtained by repeated detection multiple times. The service request party sends the maximum message length detection request carrying data of a specific length, and the service response party returns the same data after receiving the maximum message length detection request. If the detection response is received within the preset time, it indicates that the network of both parties supports the transmission of the message of the length, otherwise it is considered as not supporting. The message format of the maximum message length detection request is as shown in Figure 14 It can be known from Figure 3 that the value of the message type field of the maximum message length detection request is 5. The data field is filled with data of a specified length according to the detection requirement, and the service response party returns the same data. In order to better determine the maximum IP message length that can be passed by the network of both parties, the first sent maximum message length detection request can be generated based on the preset minimum negotiation message length of the service request party.
[0098] Step S42, obtaining the network response message sent by the service response party for the maximum message length detection request, and judging whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnostic protocol.
[0099] Step S43, if the message format of the network response message is consistent with the message format of the preset key negotiation diagnostic protocol, performing diagnostic protocol analysis on the network response message to obtain the corresponding protocol analysis result.
[0100] Step S44, judging whether the protocol analysis result is consistent with the maximum message length detection request.
[0101] In the embodiment, if the message type in the protocol analysis result corresponds to the message type in the maximum message length detection request, and the message length and the message ID in the protocol analysis result are consistent with the message length and the message ID in the maximum message length detection request, it is indicated that the network response message is the network response message sent by the service response party in response to the maximum message length detection request, and the message length of the message of the maximum message length detection request can be released by both networks; if the message type in the protocol analysis result does not correspond to the message type in the maximum message length detection request and / or the message length and / or the message ID in the protocol analysis result are inconsistent with the message length and / or the message ID in the maximum message length detection request, it is indicated that the network response message is not the network response message sent by the service response party in response to the maximum message length detection request. That is, if the value of the message type field in the protocol analysis result is 6, and the message length and the message ID in the protocol analysis result are consistent with the message length and the message ID in the maximum message length detection request, it is indicated that the network response message is the network response message sent by the service response party in response to the maximum message length detection request, and the message length of the message of the maximum message length detection request can be released by both networks, otherwise, it is indicated that the message length that can be released by the network of the service response party is less than the message length of the maximum message length detection request.
[0102] In step S45, if the protocol analysis result is consistent with the maximum message length detection request, the message length of the maximum message length detection request is increased based on a preset message length increasing method to obtain a new maximum message length detection request, and the step of sending the maximum message length detection request to the service response party is jumped to, until the network response message sent by the service response party in response to the maximum message length detection request is not acquired within a preset time, and the maximum target message length for communication with the service response party is determined.
[0103] In the embodiment, if the protocol analysis result is consistent with the maximum message length detection request, the message length of the maximum message length detection request is increased based on a preset message length increasing method to obtain a new maximum message length detection request, and the new maximum message length request is sent to the service response party to obtain a new network response message, wherein the preset message increasing method can be determined by the management end based on its own needs.
[0104] In a specific embodiment, if the current maximum message length probe request is generated based on the preset minimum negotiation message length of the service requester, and the service requester does not obtain the network response message sent by the service responder within the preset time, the service requester directly returns the detection result representing detection error to the management end; if the service requester obtains the network response message sent by the service responder within the preset time, and the protocol analysis result obtained by analyzing the network response message is consistent with the maximum message length probe request, the message length of the maximum message length probe request is increased based on the preset message length increasing method to obtain a new maximum message length probe request, and the new maximum message length probe request is sent to the service responder to obtain a new network response message. In addition, if the message length in the current maximum message length probe request is greater than the preset minimum negotiation message length, and the service requester does not obtain the network response message sent by the service responder within the preset time, the message length in the current maximum message length probe request is determined as a first target message length, and the last maximum message length probe request is obtained. The message length in the last maximum message length probe request is determined as a second target message length, the next maximum message length probe request is determined based on the first target message length and the second target message length by using the dichotomy method, and the step of sending the maximum message length probe request to the service responder is jumped to until the final maximum target message length is determined.
[0105] In this embodiment, the preset message increasing method can be determined by the management end based on its own needs. Specifically, assuming that the preset minimum negotiation message length is 550 bytes, the preset message length increasing method is to increase 200 bytes each time, the service requester generates the first maximum message length detection request, and the message length of the maximum message length detection request is 550 bytes; after the service requester obtains the network response message sent by the service responder in response to the message length detection request, a maximum message length detection request with a message length of 750 bytes is generated and sent to the service responder, and after obtaining the network response message sent by the service responder in response to the message length detection request, a maximum message length detection request with a message length of 750 bytes is generated and sent to the service responder. In this way, until the network response message sent by the service responder in response to the current maximum message length detection request is not obtained within a preset time, if the message length of the current maximum message length detection request is 1550 bytes, the message length of the last maximum message length detection request is 1350 bytes, that is, the service requester receives the network response message sent by the service responder in response to the maximum message length detection request with a message length of 1350 bytes within a preset time, but the network response message sent by the service responder in response to the maximum message length detection request with a message length of 1550 bytes is not obtained within a preset time, 1550 bytes is taken as the first target message length, 1350 bytes is taken as the second target message length, and then the binary method is used to generate and send a maximum message length detection request with a message length of 1450 bytes. If the service requester does not obtain the network response message sent by the service responder in response to the maximum message length detection request with a message length of 1450 bytes within a preset time, 1450 bytes is taken as the new first target message length, and the second target message length is still 1350 bytes; if the service requester obtains the network response message sent by the service responder in response to the maximum message length detection request with a message length of 1450 bytes within a preset time, 1450 bytes is taken as the new second target message length, and the first target message length is still 1550 bytes. After determining the new first target message length and the second target message length, the binary method is continued to generate a new maximum message length detection request until the difference between the first target message length and the second target message length is less than the preset accuracy, and the last second target message length is taken as the final maximum message length.
[0106] Step S46, sending the maximum target message length to the management end, so that the management end determines the key negotiation exception condition based on the maximum target message length.
[0107] Wherein, the more specific processing process of the above-mentioned step S42, step S43, step S46 can refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.
[0108] It can be seen that in the embodiment, the message length of the message sent by the service requester and the service responder is compared, and the message length is increased to determine a new maximum message length detection request in the case that the network of both parties allows the message length of the currently sent message, and the maximum message length detection request is sent to the service responder. The maximum target message length is determined by repeated detection multiple times, and the maximum target message length is sent to the management end, so that the management end determines the key agreement abnormal condition based on the maximum target message length.
[0109] Referring to Figure 15 The application discloses a key agreement abnormality diagnosis device, which is applied to a service requester and comprises:
[0110] The detection request sending module 11 is configured to generate a service detection request for the service responder based on the key agreement diagnosis instruction issued by the management end, and send the service detection request to the service responder.
[0111] The message format comparison module 12 is configured to obtain a network response message sent by the service responder in response to the service detection request, and determine whether the message format of the network response message is consistent with the message format of a preset key agreement diagnosis protocol.
[0112] The protocol analysis result acquisition module 13 is configured to perform diagnosis protocol analysis on the network response message to obtain a corresponding protocol analysis result if the message format of the network response message is consistent with the message format of the preset key agreement diagnosis protocol.
[0113] The detection result sending module 14 is configured to determine a service detection result based on the protocol analysis result, and send the service detection result to the management end so that the management end determines a key agreement abnormal condition based on the service detection result.
[0114] It can be seen that in the application, the service requester generates a service detection request by using the key agreement diagnosis instruction issued by the management end, and then sends the service detection request to the service responder, and obtains a network response message sent by the service responder based on the service detection request, to determine whether the message format of the network response message is consistent with the message format of a preset key agreement diagnosis protocol, so as to determine a service detection result based on the determination result and send the service detection result to the management end, so that the management end determines a key agreement abnormal condition based on the service detection result. Since the service detection result is determined based on the message format of the network response message and the message format of the preset key agreement diagnosis protocol, the management end can determine whether the service between the service requester and the service responder is abnormal based on the preset key agreement diagnosis protocol after obtaining the service detection result, so as to quickly determine the reason for the abnormality in the key agreement process.
[0115] In an embodiment, the probe request sending module 11 can specifically include:
[0116] The probe request sending sub-module is configured to acquire a key negotiation diagnosis instruction issued by the management end, generate a service probe request for a service responder based on responder IP information in the key negotiation diagnosis instruction, and send the service probe request to the service responder.
[0117] In an embodiment, the probe request sending sub-module can specifically include:
[0118] The first probe request sending unit is configured to generate a key negotiation service probe request for a service responder based on responder IP information in the key negotiation diagnosis instruction, and send the key negotiation service probe request to the service responder.
[0119] Correspondingly, the probe result sending module 14 can specifically include:
[0120] The first comparison unit is configured to compare the message ID and the message type in the protocol analysis result with the message ID and the message type of the key negotiation service probe request.
[0121] The first state determination unit is configured to determine a key negotiation service running state based on the comparison result, and send the key negotiation service running state to the management end so that the management end determines a key negotiation abnormal condition based on the key negotiation service running state.
[0122] In an embodiment, the probe request sending sub-module can specifically include:
[0123] The second probe request sending unit is configured to generate a NAT service probe request based on responder IP information and responder port information in the key negotiation diagnosis instruction, local IP information and local port information, and send the NAT service probe request to a service responder.
[0124] Correspondingly, the probe result sending module 14 can specifically include:
[0125] The second comparison unit is configured to compare the protocol analysis result with IP information, port information, message type and message ID in the NAT service probe request; the IP information includes the responder IP information and the local IP information, and the port information includes the responder port information and the local port information.
[0126] The second state determining unit is configured to determine the local NAT environment state and the NAT environment state corresponding to the service responder based on the comparison result, and send the local NAT environment state and the NAT environment state corresponding to the service responder to the management terminal, so that the management terminal determines the key agreement abnormal condition based on the local NAT environment state and the NAT environment state corresponding to the service responder.
[0127] In a specific embodiment, the probe request sending sub-module can specifically include:
[0128] The third probe request sending unit is configured to generate a maximum packet length probe request based on the responder IP information in the key agreement diagnosis instruction and a preset minimum negotiation packet length, and send the maximum packet length probe request to the service responder.
[0129] Correspondingly, the probe result sending module 14 can specifically include:
[0130] The judging sub-module is configured to judge whether the protocol analysis result is consistent with the maximum packet length probe request.
[0131] The length determining sub-module is configured to increase the packet length of the maximum packet length probe request based on a preset packet length increasing method to obtain a new maximum packet length probe request if the protocol analysis result is consistent with the maximum packet length probe request, and jump to the step of sending the maximum packet length probe request to the service responder until it is determined that the maximum target packet length for communication with the service responder after not obtaining the network response message sent by the service responder in response to the maximum packet length probe request within a preset time.
[0132] The third state determining sub-module is configured to send the maximum target packet length to the management terminal, so that the management terminal determines the key agreement abnormal condition based on the maximum target packet length.
[0133] In a specific embodiment, the length determining sub-module can specifically include:
[0134] The packet length determining unit is configured to obtain the last maximum packet length probe request and determine the packet length in the last maximum packet length probe request as the maximum target packet length for communication with the service responder if the network response message sent by the service responder in response to the maximum packet length probe request is not obtained within a preset time.
[0135] In a specific embodiment, the message format comparison module 12 can specifically include:
[0136] a byte length judging unit, configured to judge whether the message length of the network response message is greater than a preset byte length;
[0137] a data judging unit, configured to, if the message length of the network response message is greater than the preset byte length, judge in sequence whether the data on the preset byte bit of the network response message is consistent with the data on the preset byte bit of the preset key agreement diagnosis protocol; the preset byte bit includes a Cookie field and a preamble field.
[0138] Further, the embodiment of the application further discloses an electronic device, Figure 16 is a structural diagram of an electronic device 20 according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation on the use range of the application.
[0139] Figure 16 A structural diagram of an electronic device 20 is provided in the embodiment of the application. The electronic device 20 specifically can include at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26. The memory 22 is used for storing a computer program, and the computer program is loaded and executed by the processor 21 to realize the related steps in the key agreement exception diagnosis method disclosed in any of the preceding embodiments. In addition, the electronic device 20 in the embodiment can be an electronic computer.
[0140] In the embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the application, which is not limited specifically herein; the input / output interface 25 is used to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which is not limited specifically herein.
[0141] In addition, the memory 22 as a carrier for resource storage can be a read-only memory, a random access memory, a magnetic disk or an optical disk, etc., and the resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage mode can be temporary storage or permanent storage.
[0142] The operating system 221 is configured to manage and control the various hardware devices on the electronic device 20, and the computer program 222 can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of performing the key agreement exception diagnosis method disclosed in any of the preceding embodiments by the electronic device 20, the computer program 222 can further include computer programs capable of performing other specific tasks.
[0143] Further, the present application also discloses a computer readable storage medium for storing a computer program; wherein the computer program is executed by a processor to implement the key agreement exception diagnosis method disclosed in the preceding embodiments. For the specific steps of the method, please refer to the corresponding content disclosed in the preceding embodiments, which will not be repeated here.
[0144] The embodiments in the present specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. For the same or similar parts between the embodiments, please refer to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and please refer to the method part for the relevant content.
[0145] The skilled person can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in the present specification can be realized by electronic hardware, computer software or a combination of both. In order to clearly show the interchangeability of hardware and software, the components and steps of the examples have been described in the above description. Whether the functions are realized by hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0146] The steps of the method or algorithm described in combination with the embodiments disclosed in the present specification can be directly implemented by hardware, a software module executed by a processor, or a combination of both. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0147] Finally, it needs to be pointed out that in this document, relational terms such as first and second and the like can only be intended to distinguish one entity or operation from another entity or operation without necessarily requiring or implying any actual such relationship or order between such entities or operations. Moreover, the terms "comprising", "including", or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can also include other elements not expressly listed or inherent to such process, method, article, or apparatus. Without more limitations, an element defined by the statement "comprising a" does not exclude the existence of additional identical elements in the process, method, article, or apparatus including the stated element.
[0148] The above detailed description of the technical solutions provided by the present application has been provided, and the principles and implementation modes of the present application have been described by applying specific examples. The above description of the examples is only for the purpose of helping to understand the method of the present application and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation mode and application range will be changed, and the above description of the content of the specification should not be understood as a limitation of the present application.
Claims
1. A method of diagnosing a key agreement anomaly, characterized by, The application is applied to a service requester, and comprises: Based on the key negotiation diagnosis instruction issued by the management end, a service detection request for the service responder is generated, and the service detection request is sent to the service responder, comprising: obtaining the key negotiation diagnosis instruction issued by the management end, and generating a service detection request for the service responder based on the responder IP information in the key negotiation diagnosis instruction; the service detection request is a key negotiation service detection request; Obtaining the network response message sent by the service responder to the service detection request, and determining whether the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol; If the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, the network response message is analyzed according to the diagnosis protocol to obtain the corresponding protocol analysis result, comprising: determining whether the message length of the network response message is greater than the preset byte length; if the message length of the network response message is greater than the preset byte length, it is judged in turn whether the data on the preset byte bit of the network response message is consistent with the data on the preset byte bit of the preset key negotiation diagnosis protocol; the preset byte bit includes Cookie field and preamble field; Based on the protocol analysis result, a service detection result is determined, and the service detection result is sent to the management end so that the management end determines the key negotiation abnormal condition based on the service detection result, comprising: comparing the message ID and message type in the protocol analysis result with the message ID and message type of the key negotiation service detection request; based on the comparison result, the key negotiation service running state is determined, and the key negotiation service running state is sent to the management end so that the management end determines the key negotiation abnormal condition based on the key negotiation service running state.
2. The key agreement anomaly diagnosis method according to claim 1, characterized in that, Based on the key negotiation diagnosis instruction issued by the management end, a service detection request for the service responder is generated, and the service detection request is sent to the service responder, comprising: Based on the key negotiation diagnosis instruction issued by the management end, a service detection request for the service responder is generated, and the service detection request is sent to the service responder, comprising:
3. The key agreement anomaly diagnosis method according to claim 1, characterized in that, Based on the key negotiation diagnosis instruction issued by the management end, a service detection request for the service responder is generated, and the service detection request is sent to the service responder, comprising: Based on the key negotiation diagnosis instruction issued by the management end, a service detection request for the service responder is generated, and the service detection request is sent to the service responder, comprising: Based on the protocol analysis result, a service detection result is determined, and the service detection result is sent to the management end so that the management end determines the key negotiation abnormal condition based on the service detection result, comprising: Determine whether the protocol analysis result is consistent with the maximum packet length detection request; If the protocol analysis result is consistent with the maximum message length detection request, the message length of the maximum message length detection request is increased based on a preset message length increasing method to obtain a new maximum message length detection request, and the step of sending the maximum message length detection request to a service responder is jumped to, until after a network response message sent by the service responder in response to the maximum message length detection request is not acquired within a preset time, a maximum target message length for communication with the service responder is determined. The maximum target message length is sent to the management end, so that the management end determines a key negotiation exception condition based on the maximum target message length.
4. The key agreement anomaly diagnosis method according to claim 3, characterized in that, After the network response message sent by the service responder in response to the maximum message length detection request is not acquired within a preset time, the maximum target message length for communication with the service responder is determined, including: If the network response message sent by the service responder in response to the maximum message length detection request is not acquired within a preset time, a previous maximum message length detection request is acquired, and the message length in the previous maximum message length detection request is determined as the maximum target message length for communication with the service responder. 5.A key agreement anomaly diagnosis apparatus applied to a service requester, characterized by comprising: a key agreement anomaly diagnosis unit configured to diagnose a key agreement anomaly based on a key agreement anomaly diagnosis result of a key agreement anomaly diagnosis apparatus applied to a service provider. Including: The detection request sending module is configured to generate a service detection request for a service responder based on a key negotiation diagnosis instruction issued by the management end, and send the service detection request to the service responder, including: acquiring the key negotiation diagnosis instruction issued by the management end, and generating the service detection request for the service responder based on responder IP information in the key negotiation diagnosis instruction, and sending the service detection request to the service responder; the service detection request is a key negotiation service detection request; The message format comparison module is configured to acquire a network response message sent by the service responder in response to the service detection request, and determine whether the message format of the network response message is consistent with the message format of a preset key negotiation diagnosis protocol; The protocol analysis result acquisition module is configured to, if the message format of the network response message is consistent with the message format of the preset key negotiation diagnosis protocol, perform diagnosis protocol analysis on the network response message to obtain a corresponding protocol analysis result, including: determining whether the message length of the network response message is greater than a preset byte length; if the message length of the network response message is greater than the preset byte length, in turn determining whether the data on a preset byte bit of the network response message is consistent with the data on a preset byte bit of the preset key negotiation diagnosis protocol; the preset byte bit includes a Cookie field and a preamble field; The probe result sending module is configured to determine a service probe result based on the protocol analysis result, and send the service probe result to the management end so that the management end determines a key agreement abnormal condition based on the service probe result, including: comparing a message ID and a message type in the protocol analysis result with a message ID and a message type of the key agreement service probe request; determining a key agreement service running state based on a comparison result, and sending the key agreement service running state to the management end so that the management end determines a key agreement abnormal condition based on the key agreement service running state.
6. An electronic device, comprising: The method comprises the following steps: a memory for storing a computer program; a processor for executing the computer program to implement the key agreement abnormality diagnosis method according to any one of claims 1 to 4.
7. A computer readable storage medium characterized in that, a memory for storing a computer program, wherein the computer program is executed by a processor to implement the key agreement abnormality diagnosis method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Safety network time synchronizing method and device
CN107395312A
Method and device for detecting NAT between network nodes and storage medium
CN116455863A