Power forward gatekeeper reverse penetration method and device, server, medium and product
Through splitting and redundant encoding, and using custom HTTP header fields to construct HTTP requests, the problem of low efficiency and security risks of reverse communication of power forward gate is solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510148960.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-06
AI Technical Summary
When the existing power forward gate realizes reverse communication, the transmission efficiency is low and not suitable for broadcast or multicast applications. Incorrect reverse proxy service configuration may expose the internal network structure and increase security risks.
By obtaining the target unit data of the production control area, if the forward gate protocol allows it, the data is split into multiple byte segments and generate redundant encoding, creating a custom HTTP header field to construct HTTP requests, and transmitting it to the proxy service of the management information area in reverse through the forward gate.
It realizes reverse secure data transmission based on the existing forward gate without changing the existing forward gate, reduces latency and intermediate links, reduces security risks, and is compatible with the existing HTTP protocol stack and Web server.
Smart Images

Figure CN119945624A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of electric power technology, and in particular to a method, device, server, medium and product for reverse penetration of an electric power forward network switch. Background Art
[0002] In the power industry, according to relevant standards, the power monitoring system is divided into the production control area and the management information area. In the critical infrastructure of power plants, network gates are widely used at the boundaries between the production control area and the management information area to ensure the security and reliability of data exchange. The forward network gate is to ensure the security of the power grid monitoring system and prevent attacks from the Internet or other low-security networks from penetrating into the monitoring system. The forward network gate only allows data to flow in one direction, that is, from a low-security network to a high-security network, thereby ensuring that data in the high-security network is not reversely penetrated.
[0003] Although the original intention of the forward network gate is to prevent any form of reverse data flow, in actual applications, it is sometimes necessary to implement certain specific reverse communication requirements. Currently, the commonly used methods to achieve reverse penetration of the forward network gate mainly include using the TCP protocol, the UDP protocol, and the reverse proxy service. Among them, the TCP protocol can provide reliable and orderly data transmission, so many forward network gates can support TCP protocol transmission, but the TCP protocol transmission efficiency is relatively low and is not suitable for broadcast or multicast application scenarios. The UDP protocol does not require the establishment of a connection, has low latency, supports broadcast and multicast, but does not guarantee the reliable arrival of data packets, data integrity, and transmission order. Reverse proxy services can be used to reverse penetrate HTTP / HTTPS traffic, but usually require specific protocol support and configuration to forward external HTTP / HTTPS requests to internal Web services. If improperly configured, it may expose the internal network structure and increase security risks. Summary of the invention
[0004] The embodiments of the present invention provide a method, device, server, medium and product for reverse penetration of a power forward network gate, so as to reversely and securely transmit data from a power plant production control area to a management information area without changing the forward network gate of the power plant.
[0005] In a first aspect, an embodiment of the present invention provides a method for reverse penetration of a power forward network gate, the method comprising:
[0006] Obtain target unit data in the production control area;
[0007] If the data transmission protocol used by the forward gateway allows the custom header field to pass, splitting the target unit data into multiple byte segments, and generating a corresponding redundant code for each of the byte segments;
[0008] Creating a first custom header field for each of the byte segments, and correspondingly creating a second custom header field for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segment sequence number of the byte segment;
[0009] Encode the byte segments and the redundant codes respectively using a preset encoding method, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment;
[0010] The first HTTP request is transmitted back through the forward network gate to the proxy service of the management information zone.
[0011] Optionally, after acquiring the target unit data of the production control area, the method further includes:
[0012] If the data transmission protocol used by the forward gateway does not allow the custom header field to pass, splitting the target unit data into multiple byte blocks and assigning a corresponding sequence number to each of the byte blocks;
[0013] Binary encode each of the byte blocks and the corresponding serial number according to a preset encoding format, and encode them in a text format using a preset encoding method to obtain encoded data corresponding to each of the byte blocks;
[0014] Inserting the encoded data into the carriage return position between the original header field and the actual data, and adding a third custom header field at the end of the original header field to construct a second HTTP request corresponding to each of the byte blocks;
[0015] The second HTTP request is transmitted back through the forward network gate to the proxy service of the management information area.
[0016] Optionally, the preset encoding format is: [serial number length][serial number][byte block length][byte block].
[0017] Optionally, after the first HTTP request is transmitted back through the forward network gate to the proxy service of the management information zone, the method further includes:
[0018] Extracting the byte segment data of the first custom header field and the redundant coded data of the second custom header field in the first HTTP request and decoding them through the proxy service of the management information zone to obtain byte segment decoded data and redundant coded decoded data;
[0019] The byte segment decoded data is verified according to the redundant coding and decoding data through the proxy service of the management information zone, and the byte segment decoded data is reorganized in sequence to obtain complete unit data.
[0020] Optionally, after the second HTTP request is transmitted back through the forward network gate to the proxy service of the management information zone, the method further includes:
[0021] Extracting the encoded data of the third custom header field in the second HTTP request through the proxy service of the management information zone and decoding the encoded data to obtain binary data;
[0022] The agent service of the management information zone reorganizes the byte blocks in the binary data according to the serial number in the binary data to obtain the complete unit data.
[0023] Optionally, splitting the target unit data into multiple byte segments and generating a corresponding redundant code for each byte segment includes:
[0024] Determine the segment size according to the maximum capacity of the header field and the redundant coding ratio, and split the target unit data according to the segment size;
[0025] The redundant byte size is determined according to the redundant coding ratio and the segment size, and a corresponding redundant code is generated for each byte segment according to the redundant byte size.
[0026] In a second aspect, an embodiment of the present invention further provides a power forward network switch reverse penetration device, the device comprising:
[0027] Unit data acquisition module, used to obtain target unit data in the production control area;
[0028] A unit data segmentation module, for splitting the target unit data into a plurality of byte segments and generating a corresponding redundant code for each byte segment if the data transmission protocol used by the forward gateway allows the custom header field to pass;
[0029] A header field creation module, used to create a first custom header field for each of the byte segments, and correspondingly create a second custom header field for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment;
[0030] a first HTTP request construction module, configured to encode the byte segments and the redundant codes respectively using a preset encoding method, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment;
[0031] The first HTTP request transmission module is used to transmit the first HTTP request through the forward network gate in reverse direction to the proxy service of the management information zone.
[0032] In a third aspect, an embodiment of the present invention further provides a server, the server comprising:
[0033] one or more processors;
[0034] A memory for storing one or more programs;
[0035] When the one or more programs are executed by the one or more processors, the one or more processors implement the power forward network gate reverse penetration method provided by any embodiment of the present invention.
[0036] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the power forward network switch reverse penetration method provided by any embodiment of the present invention.
[0037] In a fifth aspect, an embodiment of the present invention further provides a computer program product, which includes a computer program, and when the program is executed by a processor, it implements the power forward network switch reverse penetration method provided by any embodiment of the present invention.
[0038] The embodiment of the present invention provides a method for reverse penetration of a power forward network gate. First, the target unit data of the production control area is obtained. If the data transmission protocol used by the forward network gate allows the custom header field to pass, the target unit data obtained is split into multiple byte segments, and a corresponding redundant code is generated for each byte segment. Then, a first custom header field is created for each byte segment, and a second custom header field is created for each redundant code. The names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment. Then, the byte segment and the redundant code are encoded respectively using a preset encoding method, and the encoded byte segment data is placed in the corresponding first custom header field, and the encoded redundant code data is placed in the corresponding second custom header field to construct a first HTTP request corresponding to each byte segment, so that the first HTTP request is reversely transmitted to the proxy service of the management information area through the forward network gate. The reverse penetration method of the power forward network gate provided by the embodiment of the present invention transmits data based on the HTTP protocol. The HTTP protocol itself is built on the TCP protocol, which can provide developers with a higher level of abstraction, so that developers do not need to care about the underlying network details. HTTP provides reliable transmission, ensures the order and integrity of data packets, and reduces the security risks that may be introduced through third-party agents. At the same time, by extending the HTTP header field, new functions can be supported without changing the protocol itself. In addition, there is no need to modify the existing HTTP protocol stack, it is compatible with existing Web servers and application servers, and there is no need to configure and manage reverse proxy servers, which also reduces the intermediate links in data transmission and reduces latency. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 A flow chart of a method for reverse penetration of a power forward network gate provided in the first embodiment of the present invention;
[0040] Figure 2 A schematic diagram of the organizational structure provided in Embodiment 1 of the present invention;
[0041] Figure 3 A schematic diagram of the structure of a reverse penetration device for a power forward network switch provided in the second embodiment of the present invention;
[0042] Figure 4 This is a schematic diagram of the structure of a server provided in Embodiment 3 of the present invention. DETAILED DESCRIPTION
[0043] The present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the present invention, rather than to limit the present invention. It should also be noted that, for ease of description, only parts related to the present invention, rather than all structures, are shown in the accompanying drawings.
[0044] It should be mentioned before discussing the exemplary embodiments in more detail that some exemplary embodiments are described as processes or methods depicted as flow charts. Although the flow charts describe the steps as sequential processes, many of the steps therein can be implemented in parallel, concurrently or simultaneously. In addition, the order of the steps can be rearranged. The process can be terminated when its operation is completed, but can also have additional steps not included in the accompanying drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.
[0045] Embodiment 1
[0046] Figure 1 Flow chart of the reverse penetration method of the power forward network gate provided in the first embodiment of the present invention. This embodiment can be applied to the case where the data of the production control area is transmitted reversely to the management information area on the existing power plant forward network gate. The method can be executed by the reverse penetration device of the power forward network gate provided in the embodiment of the present invention. The device can be implemented by hardware and / or software, and can generally be integrated in the server, and can specifically be a proxy service of the production control area. Figure 1 As shown, the specific steps include:
[0047] S11. Obtain target unit data of the production control area.
[0048] S12. If the data transmission protocol used by the forward gateway allows the custom header field to pass, the target unit data is split into multiple byte segments, and a corresponding redundant code is generated for each byte segment.
[0049] S13. Create a first custom header field for each of the byte segments, and create a second custom header field correspondingly for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment.
[0050] S14. Use a preset encoding method to encode the byte segment and the redundant code respectively, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field to construct a first HTTP request corresponding to each byte segment.
[0051] S15, reversely transmitting the first HTTP request through the forward network gate to the proxy service of the management information area.
[0052] Specifically, based on the existing power plant forward network gate, it can be used in the production control area (such as Figure 2Add data collection service and proxy service A to the positive network gate side of the production zone I / II in the management information zone (such as Figure 2 In the management zone III, add proxy service B on the positive network gate side. The specific organizational structure is as follows: Figure 2 As shown. When the monitoring system of the management information area needs to obtain various real-time data of the unit from the production control area through the forward network gate, it can first collect the target unit data of the production control area in real time through the data collection service and send it to the proxy service A. After receiving the target unit data, the proxy service A can determine whether the data transmission protocol currently used by the forward network gate allows the custom header field in HTTP to pass. If it allows, the proxy service A can use the HTTP segmented redundant encoding algorithm to encode the target unit data.
[0053] For the HTTP segmented redundant coding algorithm, the target unit data can be first split into multiple byte segments, and a corresponding redundant code can be generated for each byte segment. Then a first custom header field is created for each byte segment, and a second custom header field is created for each redundant code. Exemplarily, the name of the first custom header field is X-Data-Fragment-n, and the name of the second custom header field is X-Redundancy-Fragment-n, where n represents the segment sequence number of the byte segment, so that the order of each byte segment can be determined for subsequent reorganization. Then, each byte segment and each redundant code are encoded using a preset encoding method, and the encoded byte segment data can be placed in the first custom header field of the corresponding segment sequence number, and the encoded redundant coding data can be placed in the second custom header field of the corresponding segment sequence number, so as to obtain the first HTTP request corresponding to each byte segment according to the corresponding header construction, wherein the preset encoding method can be Base64. Then the constructed first HTTP request can be sent to the proxy service B of the management information area, so that the unit data of the production control area can be reorganized by the proxy service B according to the received first HTTP request.
[0054] Among them, optionally, splitting the target unit data into multiple byte segments and generating corresponding redundant codes for each byte segment includes: determining the segment size according to the maximum capacity of the header field and the redundant code ratio, and splitting the target unit data according to the segment size; determining the redundant byte size according to the redundant code ratio and the segment size, and generating corresponding redundant codes for each byte segment according to the redundant byte size.
[0055] Specifically, the maximum capacity of each header field and the ratio of redundant coding can be determined in advance, and the size of the actual data (payload) can also be determined based on the acquired target unit data. The segment size can be determined based on the maximum capacity of the header field and the ratio of redundant coding, wherein the sum of the size of each byte segment obtained by segmentation and the corresponding redundant coding should be less than the maximum capacity of the header field. Then, the target unit data can be split into multiple smaller byte segments according to the actual data size and the segment size. At the same time, the redundant byte size can be determined based on the redundant coding ratio and the obtained segment size, so that the corresponding redundant coding can be generated for each byte segment obtained by splitting according to the redundant byte size.
[0056] Optionally, after transmitting the first HTTP request in reverse through the forward network gate to the proxy service of the management information area, it also includes: extracting the byte segment data of the first custom header field and the redundant coding data of the second custom header field in the first HTTP request and decoding them through the proxy service of the management information area to obtain byte segment decoding data and redundant coding decoding data; verifying the byte segment decoding data according to the redundant coding decoding data through the proxy service of the management information area, and reorganizing the byte segment decoding data in sequence to obtain complete unit data.
[0057] Specifically, after proxy service B receives the first HTTP request sent by proxy service A, it can determine the data encoding type. If the data uses the HTTP segmented redundant encoding algorithm, proxy service B can reorganize the data and verify the redundant encoding. Specifically, the byte segment data can be extracted from the first custom header field, and the redundant encoding data can be extracted from the second custom header field. Then the extracted data is decoded according to the preset encoding method to obtain byte segment decoding data and redundant encoding decoding data. The redundant encoding decoding data can be used to verify the integrity of the byte segment decoding data. If disorder or packet loss is found, it can also be restored through the redundant encoding decoding data. After the verification is completed, all byte segment decoding data are reorganized in the correct order to obtain the complete unit data. Proxy service B can then send the complete unit data to the monitoring system of the management information area for staff to view and analyze.
[0058] On the basis of the above technical solution, optionally, after obtaining the target unit data of the production control area, it also includes: if the data transmission protocol used by the forward network gate does not allow the custom header field to pass, the target unit data is split into multiple byte blocks, and a corresponding serial number is assigned to each byte block; each byte block and the corresponding serial number are binary-encoded according to a preset encoding format, and a text format is encoded using a preset encoding method to obtain the encoded data corresponding to each byte block; the encoded data is inserted into the carriage return position between the original header field and the actual data, and a third custom header field is added at the end of the original header field to construct a second HTTP request corresponding to each byte block; the second HTTP request is transmitted back through the forward network gate to the proxy service of the management information area.
[0059] Specifically, if the proxy service A determines that the data transmission protocol used by the forward network gate does not allow the custom header field in HTTP to pass, the proxy service A can use the HTTP segmented binary encoding algorithm to encode the target unit data. For the HTTP segmented binary encoding algorithm, the target unit data can be first split into multiple byte blocks of a preset size (N bytes) based on the payload size, and a corresponding serial number is assigned to each byte block. For the allocation of serial numbers, a variable with an initial value of 0 can be created for tracking, and incremented after each byte block is allocated, so as to assign a unique serial number to each byte block. After the splitting and serial number allocation are completed, for each byte block, it can be binary encoded together with the corresponding serial number according to the preset encoding format. Among them, optionally, the preset encoding format is: [serial number length] [serial number] [byte block length] [byte block], so that the length field therein can facilitate the extraction of data of the correct length during subsequent decoding. Since the HTTP header requires a text format, the result of the above binary encoding can be converted into a text format using a preset encoding method to obtain printable ASCII characters, that is, the encoded data corresponding to each byte block, wherein the preset encoding method can be Base64 or Hex. Then, for the encoded data of each byte block, it can be inserted into the carriage return position between the original header field and the actual data, and the original header field is modified at the same time, and a third custom header field is added to the end of the original header field. Exemplarily, the third custom header field is X-Data-Chunk: [encoded data], and the header information finally obtained can be stored by creating an empty list. Then, for each byte block, a second HTTP request can be constructed according to the corresponding header, and a blank line is left between the header and the payload in each second HTTP request, that is, a carriage return and a line feed CRLF. Then, the constructed second HTTP request can be sent to the proxy service B of the management information area, so that the unit data of the production control area can be reorganized by the proxy service B according to the received second HTTP request.
[0060] Further optionally, after the second HTTP request is transmitted reversely through the forward network gate to the proxy service of the management information zone, it also includes: extracting the encoded data of the third custom header field in the second HTTP request through the proxy service of the management information zone and decoding it to obtain binary data; and reorganizing the byte blocks in the binary data according to the serial number in the binary data through the proxy service of the management information zone to obtain complete unit data.
[0061] Specifically, after proxy service B receives the second HTTP request sent by proxy service A, it can determine the data encoding type. If the data uses the HTTP segmented binary encoding algorithm, proxy service B can reorganize the data and verify the binary encoding. Specifically, the encoded data can be extracted from the third custom header field, and the extracted data can be decoded according to the preset encoding method to restore the original binary data. Then, the individual byte blocks can be reassembled according to the serial number therein to obtain the complete unit data. If packet loss occurs during transmission, it can also be detected based on the serial number and request retransmission of the lost byte blocks. If the byte blocks arrive out of order, they can also be reordered according to the serial number. Proxy service B can then send the complete unit data to the monitoring system of the management information area for staff to view and analyze.
[0062] The technical solution provided by the embodiment of the present invention first obtains the target unit data of the production control area. If the data transmission protocol used by the forward network gate allows the custom header field to pass, the obtained target unit data is split into multiple byte segments, and a corresponding redundant code is generated for each byte segment. Then, a first custom header field is created for each byte segment, and a second custom header field is created for each redundant code, wherein the names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment. Then, the byte segment and the redundant code are encoded respectively using a preset encoding method, and the encoded byte segment data is placed in the corresponding first custom header field, and the encoded redundant code data is placed in the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment, thereby transmitting the first HTTP request to the proxy service of the management information area through the forward network gate in reverse. By transmitting data based on the HTTP protocol, the HTTP protocol itself is built on the TCP protocol, which can provide developers with a higher level of abstraction, so that developers do not need to care about the underlying network details. HTTP provides reliable transmission, ensures the order and integrity of data packets, and reduces the security risks that may be introduced through third-party agents. At the same time, by extending the HTTP header field, new functions can be supported without changing the protocol itself. In addition, there is no need to modify the existing HTTP protocol stack, it is compatible with existing Web servers and application servers, and there is no need to configure and manage reverse proxy servers, which also reduces the intermediate links in data transmission and reduces latency.
[0063] Embodiment 2
[0064] Figure 3This is a schematic diagram of the structure of the power forward network gate reverse penetration device provided in the second embodiment of the present invention. The device can be implemented by hardware and / or software, and can generally be integrated into a server. Specifically, it can be a proxy service of a production control area, which is used to execute the power forward network gate reverse penetration method provided in any embodiment of the present invention. Figure 3 As shown, the device comprises:
[0065] The unit data acquisition module 31 is used to acquire the target unit data of the production control area;
[0066] The unit data segmentation module 32 is used for splitting the target unit data into multiple byte segments and generating corresponding redundant codes for each byte segment if the data transmission protocol used by the forward gateway allows the custom header field to pass;
[0067] A header field creation module 33, used to create a first custom header field for each of the byte segments, and correspondingly create a second custom header field for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment;
[0068] A first HTTP request construction module 34 is used to encode the byte segment and the redundant code respectively using a preset encoding method, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment;
[0069] The first HTTP request transmission module 35 is used to transmit the first HTTP request in reverse direction to the proxy service of the management information area through the forward network gate.
[0070] The technical solution provided by the embodiment of the present invention first obtains the target unit data of the production control area. If the data transmission protocol used by the forward network gate allows the custom header field to pass, the obtained target unit data is split into multiple byte segments, and a corresponding redundant code is generated for each byte segment. Then, a first custom header field is created for each byte segment, and a second custom header field is created for each redundant code, wherein the names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment. Then, the byte segment and the redundant code are encoded respectively using a preset encoding method, and the encoded byte segment data is placed in the corresponding first custom header field, and the encoded redundant code data is placed in the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment, thereby transmitting the first HTTP request to the proxy service of the management information area through the forward network gate in reverse. By transmitting data based on the HTTP protocol, the HTTP protocol itself is built on the TCP protocol, which can provide developers with a higher level of abstraction, so that developers do not need to care about the underlying network details. HTTP provides reliable transmission, ensures the order and integrity of data packets, and reduces the security risks that may be introduced through third-party agents. At the same time, by extending the HTTP header field, new functions can be supported without changing the protocol itself. In addition, there is no need to modify the existing HTTP protocol stack, it is compatible with existing Web servers and application servers, and there is no need to configure and manage reverse proxy servers, which also reduces the intermediate links in data transmission and reduces latency.
[0071] On the basis of the above technical solution, optionally, the device further includes:
[0072] A unit data block module is used for, after acquiring the target unit data of the production control zone, if the data transmission protocol used by the forward network gate does not allow the custom header field to pass, splitting the target unit data into multiple byte blocks and assigning a corresponding sequence number to each byte block;
[0073] A unit data encoding module, used to perform binary encoding on each of the byte blocks and the corresponding serial number according to a preset encoding format, and perform text format encoding using a preset encoding method to obtain encoded data corresponding to each of the byte blocks;
[0074] A second HTTP request construction module, used for inserting the encoded data into the carriage return position between the original header field and the actual data, and adding a third custom header field at the end of the original header field, so as to construct a second HTTP request corresponding to each byte block;
[0075] The second HTTP request transmission module is used to transmit the second HTTP request through the forward network gate in reverse direction to the proxy service of the management information zone.
[0076] Based on the above technical solution, optionally, the preset encoding format is: [serial number length][serial number][byte block length][byte block].
[0077] On the basis of the above technical solution, optionally, the device further includes:
[0078] A first decoding module, configured to extract and decode the byte segment data of the first custom header field and the redundant coded data of the second custom header field in the first HTTP request through the proxy service of the management information zone after the first HTTP request is reversely transmitted to the proxy service of the management information zone through the forward network gate, so as to obtain byte segment decoded data and redundant coded decoded data;
[0079] The first reorganization module is used to verify the byte segment decoded data according to the redundant encoding and decoding data through the proxy service of the management information area, and reorganize the byte segment decoded data in sequence to obtain complete unit data.
[0080] On the basis of the above technical solution, optionally, the device further includes:
[0081] A second decoding module is used for extracting and decoding the encoded data of the third custom header field in the second HTTP request through the proxy service of the management information zone after the second HTTP request is reversely transmitted to the proxy service of the management information zone through the forward network gate to obtain binary data;
[0082] The second reorganization module is used to reorganize the byte blocks in the binary data according to the sequence numbers in the binary data through the proxy service of the management information area to obtain complete unit data.
[0083] On the basis of the above technical solution, optionally, the unit data segmentation module is specifically used for:
[0084] Determine the segment size according to the maximum capacity of the header field and the redundant coding ratio, and split the target unit data according to the segment size;
[0085] The redundant byte size is determined according to the redundant coding ratio and the segment size, and a corresponding redundant code is generated for each byte segment according to the redundant byte size.
[0086] The power forward network switch reverse penetration device provided in the embodiment of the present invention can execute the power forward network switch reverse penetration method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0087] It is worth noting that in the above-mentioned embodiment of the power forward network switch reverse penetration device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0088] Embodiment 3
[0089] Figure 4 The schematic diagram of the structure of the server provided in the third embodiment of the present invention shows a block diagram of an exemplary server suitable for implementing the implementation mode of the present invention. Figure 4 The server shown is only an example and should not limit the functions and scope of use of the embodiments of the present invention. Figure 4 As shown, the server includes a processor 41, a memory 42, an input device 43 and an output device 44; the number of processors 41 in the server can be one or more. Figure 4 Taking a processor 41 as an example, the processor 41, memory 42, input device 43 and output device 44 in the server can be connected through a bus or other means. Figure 4 The example of connecting through bus is taken in the following.
[0090] The memory 42, as a computer-readable storage medium, can be used to store software programs, computer executable programs and modules, such as program instructions / modules corresponding to the power forward network gate reverse penetration method in the embodiment of the present invention (for example, the unit data acquisition module 31, the unit data segmentation module 32, the header field creation module 33, the first HTTP request construction module 34 and the first HTTP request transmission module 35 in the power forward network gate reverse penetration device). The processor 41 executes various functional applications and data processing of the server by running the software programs, instructions and modules stored in the memory 42, that is, realizing the above-mentioned power forward network gate reverse penetration method.
[0091] The memory 42 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system and at least one application required for a function; the data storage area may store data created according to the use of the server, etc. In addition, the memory 42 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 42 may further include a memory remotely arranged relative to the processor 41, and these remote memories may be connected to the server via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0092] The input device 43 can be used to obtain target unit data of the production control area, and generate key signal input related to the user settings and function control of the server, etc. The output device 44 can be used to send HTTP requests to the proxy service of the management information area, etc.
[0093] Embodiment 4
[0094] Embodiment 4 of the present invention further provides a storage medium containing computer executable instructions, wherein the computer executable instructions are used to execute a method for reverse penetration of a power forward network gate when executed by a computer processor, the method comprising:
[0095] Obtain target unit data in the production control area;
[0096] If the data transmission protocol used by the forward gateway allows the custom header field to pass, splitting the target unit data into multiple byte segments, and generating a corresponding redundant code for each of the byte segments;
[0097] Creating a first custom header field for each of the byte segments, and correspondingly creating a second custom header field for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segment sequence number of the byte segment;
[0098] Encode the byte segments and the redundant codes respectively using a preset encoding method, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment;
[0099] The first HTTP request is transmitted back through the forward network gate to the proxy service of the management information zone.
[0100] The storage medium may be any of various types of memory devices or storage devices. The term "storage medium" is intended to include: installation media, such as CD-ROM, floppy disk or tape device; computer system memory or random access memory, such as DRAM, DDR RAM, SRAM, EDO RAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media (such as hard disk or optical storage); registers or other similar types of memory elements, etc. The storage medium may also include other types of memory or combinations thereof. In addition, the storage medium may be located in the computer system in which the program is executed, or may be located in a different second computer system, which is connected to the computer system via a network (such as the Internet). The second computer system may provide program instructions to the computer for execution. The term "storage medium" may include two or more storage media that may reside in different locations (e.g., in different computer systems connected via a network). The storage medium may store program instructions (e.g., embodied as a computer program) that may be executed by one or more processors.
[0101] Of course, the computer executable instructions of a storage medium including computer executable instructions provided in an embodiment of the present invention are not limited to the method operations described above, and can also execute related operations in the power forward network switch reverse penetration method provided in any embodiment of the present invention.
[0102] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0103] The program code embodied on the computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0104] Through the above description of the implementation methods, the technicians in the relevant field can clearly understand that the present invention can be implemented by means of software and necessary general hardware, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk or optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0105] Embodiment 5
[0106] Embodiment 5 of the present invention also provides a computer program product, which includes a computer program (also referred to as code, instruction), which can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it is used to execute the power forward network switch reverse penetration method provided in any of the above embodiments, and has the corresponding beneficial effects of the execution method.
[0107] Note that the above are only preferred embodiments of the present invention and the technical principles used. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments, and may include more other equivalent embodiments without departing from the concept of the present invention, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. A method for reverse penetration of a power forward network gate, characterized in that: include: Obtain target unit data in the production control area; If the data transmission protocol used by the forward gateway allows the custom header field to pass, splitting the target unit data into multiple byte segments, and generating a corresponding redundant code for each of the byte segments; Creating a first custom header field for each of the byte segments, and correspondingly creating a second custom header field for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segment sequence number of the byte segment; Encode the byte segments and the redundant codes respectively using a preset encoding method, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment; The first HTTP request is transmitted back through the forward network gate to the proxy service of the management information zone.
2. The method for reverse penetration of a power forward network gate according to claim 1, characterized in that: After obtaining the target unit data of the production control area, the method further includes: If the data transmission protocol used by the forward gateway does not allow the custom header field to pass, splitting the target unit data into multiple byte blocks and assigning a corresponding sequence number to each of the byte blocks; Binary encode each of the byte blocks and the corresponding serial number according to a preset encoding format, and encode them in a text format using a preset encoding method to obtain encoded data corresponding to each of the byte blocks; Inserting the encoded data into the carriage return position between the original header field and the actual data, and adding a third custom header field at the end of the original header field to construct a second HTTP request corresponding to each of the byte blocks; The second HTTP request is transmitted back through the forward network gate to the proxy service of the management information area.
3. The method for reverse penetration of a power forward network gate according to claim 2, characterized in that: The preset encoding format is: [sequence number length][sequence number][byte block length][byte block].
4. The method for reverse penetration of a power forward network gate according to claim 1, characterized in that: After the first HTTP request is transmitted back through the forward network gate to the proxy service of the management information area, the method further includes: Extracting the byte segment data of the first custom header field and the redundant coded data of the second custom header field in the first HTTP request and decoding them through the proxy service of the management information zone to obtain byte segment decoded data and redundant coded decoded data; The byte segment decoded data is verified according to the redundant coding and decoding data through the proxy service of the management information zone, and the byte segment decoded data is reorganized in sequence to obtain complete unit data.
5. The method for reverse penetration of a power forward network gate according to claim 2, characterized in that: After the second HTTP request is transmitted back through the forward network gate to the proxy service of the management information area, the method further includes: Extracting the encoded data of the third custom header field in the second HTTP request through the proxy service of the management information zone and decoding the encoded data to obtain binary data; The agent service of the management information zone reorganizes the byte blocks in the binary data according to the serial number in the binary data to obtain the complete unit data.
6. The method for reverse penetration of a power forward network gate according to claim 1, characterized in that: The step of splitting the target unit data into a plurality of byte segments and generating a corresponding redundant code for each byte segment includes: Determine the segment size according to the maximum capacity of the header field and the redundant coding ratio, and split the target unit data according to the segment size; The redundant byte size is determined according to the redundant coding ratio and the segment size, and a corresponding redundant code is generated for each byte segment according to the redundant byte size.
7. A power forward network switch reverse penetration device, characterized in that: include: Unit data acquisition module, used to obtain target unit data in the production control area; A unit data segmentation module, for splitting the target unit data into a plurality of byte segments and generating a corresponding redundant code for each byte segment if the data transmission protocol used by the forward gateway allows the custom header field to pass; A header field creation module, used to create a first custom header field for each of the byte segments, and correspondingly create a second custom header field for each of the redundant codes; wherein the names of the first custom header field and the second custom header field both carry the segmentation sequence number of the byte segment; a first HTTP request construction module, configured to encode the byte segments and the redundant codes respectively using a preset encoding method, and put the encoded byte segment data into the corresponding first custom header field, and put the encoded redundant code data into the corresponding second custom header field, so as to construct a first HTTP request corresponding to each byte segment; The first HTTP request transmission module is used to transmit the first HTTP request through the forward network gate in reverse direction to the proxy service of the management information zone.
8. A computer device, characterized in that: include: one or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the power forward network gate reverse penetration method as described in any one of claims 1-6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the power forward network gate reverse penetration method as described in any one of claims 1-6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the computer program implements the power forward network gate reverse penetration method as described in any one of claims 1 to 6.
Citation Information
Cited By
Time series data cross-gatekeeper two-way transmission method, device and equipment
CN121000410A