A method for preventing eavesdropping on a wireless router
By analyzing TCP/IP traffic in real time and generating fake frames, the problem of wireless routers' anti-eavesdropping cross-device deployment is solved, efficient and flexible defense strategy learning and fake frame generation are realized, and the defense capabilities of wireless routers are improved.
Patent Information
- Application Number
- CN202411860066.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2044-12-17
AI Technical Summary
Existing wireless router anti-eavesdropping methods are difficult to quickly promote and deploy, and cross-device deployment is difficult and adaptive injection is complex, resulting in IoT devices being continuously exposed to the risk of wireless fingerprint attacks.
Using a zero-knowledge self-evolution learning strategy, we use real-time collection and analysis of TCP/IP traffic, build Markov transfer matrix and transfer tensor, generate fake frames matching the real frame, and disguise them in the protocol, sequence logic and physical signal dimensions, and simulate real frame signal characteristics using customized operating system kernel and network card driver.
It realizes efficient and flexible defense of wireless routers, and can learn optimal defense strategies without prior knowledge, significantly improve deployment flexibility and defense intelligence, ensure consistency between fake frames and real frames, and enhance network security.
Smart Images

Figure CN119728557B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security and privacy protection, and particularly to a method for preventing eavesdropping on a wireless router. Background Art
[0002] Internet of Things (IoT) devices are widely used in daily life. They are usually connected to the Internet via a wireless router. Although these devices use encrypted communication to improve security, attackers can still identify device behaviors by analyzing the side-channel characteristics (such as frame length and transmission direction) of wireless data frames triggered by different device behaviors.
[0003] To defend against wireless fingerprint attacks, existing research usually adopts two strategies to obfuscate the side-channel traffic characteristics of IoT devices, by filling IP data packets to adjust their sizes and injecting wireless frames of specific sizes and directions. However, the defense strategy based on packet filling requires firmware modification on IoT devices, so the cost is high. And the defense strategy based on injection also faces challenges, that is, how to generate forged frames that adaptively match real wireless frames. Therefore, due to the obstacles of cross-device deployment and the complexity of adaptive injection, existing fingerprint defense methods are difficult to be quickly promoted and deployed, resulting in IoT devices being continuously exposed to the risk of wireless fingerprint attacks. Summary of the Invention
[0004] (1) Technical Problems to be Solved
[0005] Aiming at the deficiencies of the prior art, the present invention provides a method for preventing eavesdropping on a wireless router, which has the advantages of real-time identifying and predicting device traffic characteristics, generating forged frames that match real frames, and achieving efficient wireless traffic defense, and solves the above problems.
[0006] (2) Technical Solutions
[0007] To achieve the above object, the present invention provides the following technical solution: A method for preventing eavesdropping on a wireless router, comprising the following steps:
[0008] S1. Collect and analyze TCP / IP traffic generated by IoT devices in real time, divide these traffic into multiple data packet windows in a fine-grained manner according to device types and protocols, and calculate the traffic rate;
[0009] S2. Under each data packet window, predict the wireless traffic that the IoT device may send or receive in the future according to the current TCP / IP traffic, construct two independent Markov transition matrices and perform transition tensor definition, and finally splice the defined transition tensors into a complete data packet traffic prediction result;
[0010] S3. According to the traffic prediction result, analyze its fingerprint structure. If a specific fingerprint is identified, select and execute the optimal forged frame generation strategy; otherwise, take no action. After the identification action, calculate the fingerprint matching rate to evaluate the fingerprint recognition success rate;
[0011] S4. Disguise the forged frames generated by the strategy from three dimensions: protocol fields, sequence logic, and physical signals, and inject them into the network. Calculate the injection delay to verify the injection efficiency of the forged frames;
[0012] S5. Use a strategy evaluator to calculate the strategy success rate to evaluate the effect of this frame generation strategy;
[0013] S6. Store the evaluation results for subsequent strategy learning and optimization.
[0014] Preferably, the calculation formula of the traffic rate is as follows:
[0015]
[0016] In the formula, represents the traffic rate, represents the total number of data bytes transmitted within time and represents the time interval. The traffic rate is the amount of data transmitted by the network per unit time and is used to measure the bandwidth performance of the network.
[0017] Preferably, the transition tensor of the Markov transition matrix is defined as follows:
[0018]
[0019] Among them, represents the transition tensor of the Markov transition matrix , represents the conditional probability, that is, the probability of the transition matrix in the state at time and in the state at time , represents the state of dimension and and at time represents the state of dimension and and at time represents the state to be predicted.
[0020] Preferably, the transition tensor of the Markov transition matrix is defined as follows:
[0021]
[0022] Among them, represents the transition tensor of the Markov transition matrix of represents the conditional probability, that is, at time and the probability of the transition matrix at the state at time at the state at time represents the state of dimension at time represents the state of dimension at time represents the state to be predicted.
[0023] Preferably, the transition tensor of the Markov transition matrix is concatenated with the transition tensor of the Markov transition matrix to obtain the complete data packet traffic prediction result.
[0024] Preferably, the formula for calculating the fingerprint matching rate is as follows:
[0025]
[0026] In the formula, represents the fingerprint matching rate, represents the number of fingerprints successfully matched, represents the number of mis-matched fingerprints.
[0027] Preferably, the formula for calculating the injection delay is as follows:
[0028]
[0029] In the formula, represents the injection delay, represents the transmission delay, represents the processing delay, represents the queuing delay, represents the number of data packet retransmissions, represents the proportion of successfully received data packets.
[0030] Preferably, the formula for calculating the success rate of the calculation strategy is as follows:
[0031]
[0032] In the formula, Indicates the success rate of the strategy, Indicates the number of events of successful interference, Indicates the number of eligible events without interference, Indicates the number of events of incorrect interference.
[0033] A wireless router anti-eavesdropping system is used to implement the wireless router anti-eavesdropping method in the above embodiment, and specifically includes a traffic prediction module, a traffic fingerprint erasure module, a wireless frame camouflage module, and a strategy evaluation module;
[0034] The traffic prediction module is used to predict the wireless data frames sent or received by the device within the future data packet window, and reserve buffer time for subsequent frame injection;
[0035] The traffic fingerprint erasure module is used to analyze the fingerprint structure of the predicted traffic. If a specific fingerprint is identified, the best frame generation strategy is selected to generate forged frames to erase the traffic fingerprint. Otherwise, no action is taken;
[0036] The wireless frame camouflage module is used to camouflage the forged frames in three dimensions: protocol field, sequence logic, and physical signal, so that the forged frames are indistinguishable from the real frames;
[0037] The strategy evaluation module is used to evaluate the defense effect of the frame generation strategy.
[0038] Preferably, the traffic prediction module learns the data packet transfer rules in, and then predicts the future data packets in. First, the data packet status in is mapped to the state space , where represents the status of each data packet, is the data packet length, is the data packet direction, is the relative time of the data packet in , and the size of the data packet is defined as the length of the data packet. To distinguish the direction of the data packet, the size of the data packet sent by the device is defined as a positive value, and the received one is a negative value. Since there is a limit on the maximum transmission unit of the data packet, the data packet size is set within .
[0039] Compared with the prior art, the present invention provides a method for preventing eavesdropping on a wireless router, which has the following beneficial effects:
[0040] The present invention adopts an independent deployment method. Through a zero-knowledge self-evolving learning strategy, it can learn the optimal defense strategy under specific traffic conditions without any prior knowledge, effectively solving the problem of cross-device deployment. In addition, it disguises wireless frames in multiple dimensions, including using a customized operating system kernel and network card driver to ensure that the forged frames are consistent with the real frames in terms of protocol specifications and logical order, and using a network card scheduling algorithm to simulate the signal characteristics of real frames, thus overcoming the problem of adaptive injection, significantly improving the deployment flexibility and defense intelligence of wireless router anti-eavesdropping, and being able to achieve defense efficiently and accurately. Brief Description of the Drawings
[0041] Figure 1 It is a schematic diagram of the method steps of the present invention. Detailed Embodiment
[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0043] Aiming at the problem that the existing fingerprint defense methods are difficult to be quickly promoted and deployed, resulting in Internet of Things devices being continuously exposed to the risk of wireless fingerprint attacks, a method for wireless router anti-eavesdropping is proposed. Please refer to Figure 1 , including the following steps:
[0044] S1. Collect and analyze the TCP / IP traffic generated by Internet of Things devices in real time, divide these traffic into multiple data packet windows in detail according to device types and protocols, and calculate the traffic rate;
[0045] The wireless router anti-eavesdropping system supports three deployment forms: integrated mode, companion mode, and air mode. According to the characteristics of each deployment form, the data preprocessing of the system is also different. In the integrated mode, the system directly processes the TCP / IP traffic of each device connected to the router, and maps the traffic of a specific device and a specific protocol to the corresponding data packet window. In the companion mode, the input of the system is the outgoing traffic of the router, which does not include the internal communication traffic of the local area network. By analyzing the external public network IP communicating with the router and the size difference between the TCP / IP data packet and the wireless data frame, the traffic of different devices is distinguished, and the PW is divided according to a specific device and a specific protocol. In the air mode, the input of the system is the wireless traffic of each device. After filtering out management frames and control frames, the data frames with specific physical addresses are mapped to the corresponding PW;
[0046] Among them, the calculation formula of the traffic rate is as follows:
[0047]
[0048] By calculating the traffic rate, the load condition of the network can be monitored in real time, which helps to identify whether there is abnormal traffic. For example, a sudden increase in traffic may indicate potential security threats or attack behaviors. In the formula, represents the traffic rate, represents the total number of bytes of data transmitted within time , represents the time interval. The traffic rate is the amount of data transmitted by the network per unit time and is used to measure the network bandwidth performance. A rapidly changing traffic rate can be used as an indicator for security protection, enabling quick identification and response to potential eavesdropping or data leakage;
[0049] S2. Under each packet window, predict the wireless traffic that the Internet of Things device may send or receive in the future based on the current TCP / IP traffic, construct two independent Markov transition matrices and define the transition tensors, and finally splice the defined transition tensors into the complete packet traffic prediction result;
[0050] Use the traffic prediction module to learn the packet transition rules in, and then predict the future packets in. First, the packet states in are mapped to the state space , where represents the state of each packet, is the packet length, is the packet direction, is the relative time of the packet in . The size of the packet is defined as the length of the packet. To distinguish the direction of the packet, the size of the packet sent by the device is defined as a positive value, and the received one is a negative value. Since there is a limit on the maximum transmission unit of the packet, the packet size is set within and is further divided into several intervals. Packets within the same interval can be regarded as having the same size and direction;
[0051] Subsequently, construct two independent Markov transition matrices, and , where focuses on capturing the transition probability of the size and direction of the packet, focuses on capturing the transition probability of the relative time of the packet, and the transition tensors in are defined as follows:
[0052]
[0053] Among them, represents the transition tensor of the Markov transition matrix of represents the conditional probability, that is, at time and state, the probability of the transition matrix at the state at time ; represents the state of dimension and at time ; represents the state of dimension and at time ; represents the state to be predicted.
[0054]
[0055] Among them, represents the transition tensor of the Markov transition matrix of represents the conditional probability, that is, at time and state, the probability of the transition matrix at the state at time ; represents the state of dimension at time ; represents the state of dimension at time ; represents the state to be predicted;
[0056] Finally, splice the transition tensors and into the complete data packet prediction result;
[0057] S3. According to the traffic prediction result, analyze its fingerprint structure. If a specific fingerprint is identified, select the optimal forged frame generation strategy and execute it. Otherwise, take no action. After the identification action, calculate the fingerprint matching rate to evaluate the fingerprint recognition success rate;
[0058] Using the traffic fingerprint erasure module, analyze and predict the fingerprint structure of the traffic. If a specific traffic fingerprint is identified, select the optimal forged frame generation strategy and execute it; otherwise, take no action. Specifically, the traffic fingerprint erasure module includes two types of frame forgery strategies, namely frame-by-frame forgery and sequence-by-sequence forgery. These two types of frame forgery strategies can be further divided into six categories. The first is to inject a single random forged frame, where the length and direction of the forged frame are randomly generated, and its sequence number is the same as the sequence number of the next data frame of the device. The second is to inject a group of random forged frames, where the length and direction of the forged frames are randomly generated, and the sequence numbers of this group of forged frames are connected to the sequence number of the next data frame of the device. The third is to replay a single forged frame of a non-target device, where the length and direction of the forged frame conform to the typical data frame characteristics of the non-target device. The fourth is to replay a sequence of forged frames of a non-target device, where the length and direction of the sequence of forged frames conform to the typical data frame sequence characteristics of the non-target device. The fifth is to clone the current data frame, where the length and direction of the forged frame are randomly generated, and the sequence number is the same as the sequence number of the current data frame. The sixth is sequence transformation, where regardless of the current traffic state, a sequence of data frames with a preset, fixed length and direction is injected;
[0059] Among them, the formula for calculating the fingerprint matching rate is as follows:
[0060]
[0061] By calculating the fingerprint matching rate, the accuracy of the system in identifying various devices can be measured. A high matching rate indicates that the system can effectively distinguish and identify legal devices and illegal devices, thereby enhancing network security. In the formula, represents the fingerprint matching rate, represents the number of successfully matched fingerprints, represents the number of mis-matched fingerprints. By analyzing the historical fingerprint matching rate data, the device behavior can be effectively evaluated and predicted, providing data support for future security protection decisions;
[0062] S4. Disguise the forged frames generated by the strategy from three dimensions: protocol fields, sequence logic, and physical signals, inject them into the network, and calculate the injection delay to verify the injection efficiency of the forged frames;
[0063] The wireless frame camouflage module is used to accurately keep the forged frame consistent with the real frame in terms of protocol fields, sequence logic and physical signals, making the forged frame indistinguishable from the real frame. First, the module adjusts the various protocol fields of the forged frame, such as the frame control field and address field, to ensure that it fully matches the real frame. Second, the module captures the serial number of the device's current communication in real time, and flexibly adjusts the serial number of the forged frame through a customized operating system kernel and network card driver, so that it can be seamlessly inserted into the current communication. Finally, the module uses the network card scheduling framework to perceive the physical signal characteristics of the real frame, and through the optimal scheduling algorithm, matches the network card with appropriate power to inject the forged frame. After three-dimensional fine camouflage, the module improves the concealment of the forged frame, making it indistinguishable from the real frame.
[0064] The calculation formula for injection delay is as follows:
[0065]
[0066] Calculating the injection delay can evaluate whether the injection of forged traffic is within an acceptable delay range, which is crucial for effectively interfering with malicious traffic. In the formula, Indicates injection delay, Indicates the transmission delay, Indicates processing delay, Indicates queue delay. Indicates the number of times the data packet is retransmitted. Indicates the proportion of successfully received data packets. If the injection delay is too high, the jamming strategy can be quickly adjusted based on real-time data to select a more optimized injection solution, ensuring the flexibility of attack and defense measures.
[0067] S5. Using a strategy evaluator, calculate the strategy success rate to evaluate the effectiveness of this frame generation strategy;
[0068] The effectiveness of the frame forgery strategy is evaluated using an evaluation module. This module includes a hierarchical feature extraction and multi-scale window classification mechanism. For each time window, the module extracts traffic features from three dimensions: frame level, sequence level, and window level.
[0069] Frame level: Each independent 802.11 wireless data frame is converted into a data frame vector FV, whose specific attributes include data frame length, direction and time, expressed as ;
[0070] Sequence level: Multiple consecutive 802.11 wireless data frames are converted into a sequence vector SV, represented as ;
[0071] Window level: Extract statistical features of data frames within a time window, including 11-dimensional features such as total length and length variance of the data frame;
[0072] To flexibly capture the traffic characteristics from high-frequency interaction devices to low-frequency communication devices, this module adopts a multi-scale window classifier. Specifically, the traffic in the time window T is further divided into sub-windows of different scales. The j-th time sub-window of the i-th layer scale is labeled as , and each sub-window adopts hierarchical feature extraction and inputs the extracted features into a random classifier. The classification result can be expressed as . Finally, a weight-based voting strategy is adopted to comprehensively combine the classification results of each sub-window to determine the most likely device type under the time window T;
[0073] Among them, the calculation formula for the success rate of the strategy is as follows:
[0074]
[0075] Based on the calculation of the success rate of the strategy, the existing protection measures can be quickly adjusted or optimized to improve the overall defense ability and response time. In the formula, represents the success rate of the strategy, represents the number of events with successful interference, represents the number of eligible events without interference, represents the number of events with wrong interference. Based on the historical data of the success rate of the strategy, it can provide important reference for formulating future security strategies and continuously adjust and improve the protection measures;
[0076] S6. Store the evaluation results for subsequent policy learning and optimization;
[0077] Based on the existing policy evaluation results, continuously explore the best mapping from the device traffic state to the frame forgery policy, and at the same time adopt an advanced reinforcement learning algorithm to effectively handle discrete frame forgery actions. Specifically, the exploration process can be described as a series of decision tuples , where the state S is defined as the initial packet state in the PW and the executed frame forgery policy, the action A is defined as the set of all possible frame forgery policies in the state S, and the reward R is defined as the immediate feedback obtained by executing the action A in the state S. Each time a frame forgery policy is executed, the current experience (traffic state, frame forgery action, reward value) is stored in the experience area for the reinforcement learning agent to learn and optimize the policy.
[0078] Steps S1 to S6 are integrated into a reinforcement learning-based framework to construct a process for iteratively optimizing the policy. This framework collects and analyzes the IoT device traffic in real time, predicts device behavior, selects and executes the optimal forgery policy, and continuously optimizes through evaluation feedback to finally achieve the best match between the traffic state and the forgery policy;
[0079] A wireless router anti-eavesdropping system, which can be used to implement the wireless router anti-eavesdropping method in the above embodiments, specifically includes a traffic prediction module, a traffic fingerprint erasure module, a wireless frame camouflage module, and a policy evaluation module.
[0080] The traffic prediction module is used to predict the wireless data frames that the device may send or receive within the future data packet window, and reserve buffer time for subsequent frame injection.
[0081] The traffic fingerprint erasure module is used to analyze the fingerprint structure of the predicted traffic. If a specific fingerprint is identified, the best frame generation strategy is selected to generate forged frames to erase the traffic fingerprint; otherwise, no action is taken.
[0082] The wireless frame camouflage module is used to camouflage the forged frames in three dimensions: protocol field, sequence logic, and physical signal, so that the forged frames are indistinguishable from the real frames.
[0083] The policy evaluation module is used to evaluate the defense effect of the frame generation strategy.
[0084] Through the application of the above method, the optimal defense strategy under a specific traffic state can be learned without any prior knowledge, effectively solving the problem of cross-device deployment. In addition, the wireless frames are camouflaged in multiple dimensions, including using a customized operating system kernel and network card driver to ensure that the forged frames are consistent with the real frames in terms of protocol specifications and logical order, and using a network card scheduling algorithm to simulate the signal characteristics of the real frames, thereby overcoming the problem of adaptive injection, significantly improving the deployment flexibility and defense intelligence of the wireless router anti-eavesdropping, and being able to achieve defense efficiently and accurately.
[0085] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for preventing eavesdropping of a wireless router, characterized in that, It includes the following steps: S1. Collect and analyze the TCP / IP traffic generated by IoT devices in real time. Divide this traffic into multiple packet windows in a fine-grained manner according to device type and protocol, and calculate the traffic rate to help identify whether there is abnormal traffic; S2. Under each data packet window, predict the future possible wireless traffic that the Internet of Things device may send or receive according to the current TCP / IP traffic, and construct two independent Markov transition matrices, namely and , where focuses on capturing the transition probability of the size and direction of the data packet, focuses on capturing the transition probability of the relative time of the data packet, and defines the transition tensor. Finally, splice the defined transition tensors into the complete data packet traffic prediction result; among them, the data packet state is mapped to the state space , where represents the state of each data packet, is the data packet length, is the data packet direction, is the relative time of the data packet in each data packet window . The size of the data packet is defined as the length of the data packet. To distinguish the direction of the data packet, the size of the data packet sent by the device is defined as a positive value, and the received one is a negative value. Since there is a limit on the maximum transmission unit of the data packet, the data packet size is set within ; S3. According to the traffic prediction result, analyze its fingerprint structure. If a specific fingerprint is identified, select the optimal forged frame generation strategy and execute it. Otherwise, take no action. After the identification action, calculate the fingerprint matching rate to evaluate the fingerprint recognition success rate; The forged frame generation strategy includes frame-by-frame forgery and sequence-by-sequence forgery; S4. Disguise the forged frames generated by the strategy from three dimensions: protocol field, sequence logic, and physical signal, and inject them into the network. Calculate the injection delay to verify the injection efficiency of the forged frames; S5. Adopt a strategy evaluator to calculate the strategy success rate to evaluate the effect of the current frame generation strategy; S6. Store the evaluation results for subsequent strategy learning and optimization.
2. The method for preventing eavesdropping of a wireless router according to claim 1, wherein: The Markov transition matrix has a transition tensor defined as follows: Among them, represents the Markov transition matrix of the transition tensor, represents the conditional probability, that is, at time and under the state, the probability of the transition matrix at the state at time is represents at time the state of dimensions and ; represents at time the state of dimensions and ; represents the state to be predicted; The Markov transition matrix has a transition tensor defined as follows: Among them, represents the transition tensor of the Markov transition matrix , represents the conditional probability, that is, at time and state, the probability of the transition matrix at time state, represents the state at time in dimension , represents the state at time in dimension , represents the state to be predicted.
3. A method for preventing eavesdropping of a wireless router according to claim 2, characterized in that: The Markov transition matrix of the transition tensor is concatenated with the Markov transition matrix of the transition tensor to obtain the complete prediction result of the data packet traffic.
4. A method for preventing eavesdropping of a wireless router according to claim 3, characterized in that: The formula for calculating the fingerprint matching rate is as follows: In the formula, represents the fingerprint matching rate, represents the number of successfully matched fingerprints, represents the number of mis-matched fingerprints.
5. A method for preventing eavesdropping of a wireless router according to claim 4, characterized in that: The formula for calculating the injection delay is as follows: In the formula, represents the injection delay, represents the transmission delay, represents the processing delay, represents the queuing delay, represents the number of times of packet retransmission, represents the ratio of successfully received packets.
6. The method for preventing eavesdropping of a wireless router according to claim 5, characterized in that: The formula for calculating the strategy success rate is as follows: In the formula, represents the policy success rate, represents the number of events of successful interference, represents the number of eligible events without interference, represents the number of events of incorrect interference.
7. A wireless router anti-eavesdropping system for implementing the wireless router anti-eavesdropping method described in any one of claims 1-6, characterized in that: It includes a traffic prediction module, a traffic fingerprint erasure module, a wireless frame disguise module, and a strategy evaluation module; The traffic prediction module is used to predict the future wireless data frames sent or received by the device within the data packet window, and reserve buffer time for subsequent frame injection; The traffic fingerprint erasure module is used to analyze the fingerprint structure according to the traffic prediction result. If a specific fingerprint is identified, select the optimal forged frame generation strategy and execute it. Otherwise, take no action. After the identification action, calculate the fingerprint matching rate to evaluate the fingerprint recognition success rate; The wireless frame disguise module is used to disguise the forged frames in three dimensions: protocol field, sequence logic, and physical signal, so that the forged frames are indistinguishable from the real frames; The strategy evaluation module is used to evaluate the defense effect of the frame generation strategy.
8. The anti-eavesdropping system for a wireless router according to claim 7, characterized in that: The flow prediction module learns the packet transfer rules in to predict the future packets in First, the packet status in is mapped to the state space where represents the status of each packet, is the packet length, is the packet direction, is the relative time of the packet in The size of the packet is defined as the length of the packet. To distinguish the packet direction, the size of the packet sent by the device is defined as a positive value, and the received one is a negative value. Since there is a limit on the maximum transmission unit of the packet, the packet size is set within
Citation Information
Patent Citations
Markov signal game-based moving target defense strategy selection method and equipment
CN110460572A
Intranet attack defense method based on dynamic spoofing
CN114157479A