Intelligent communication method and system for public cloud and private cloud of e-commerce
Through the intelligent communication method based on free ARP, the security and technical specification limitations of interoperability between public and private clouds are solved, efficient and secure data communication and storage are achieved, and network security and efficiency are enhanced.
Patent Information
- Application Number
- CN202510429304.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The interoperability between public and private clouds has limitations of security and technical specifications, making it difficult to achieve efficient and secure data transmission and communication.
The intelligent communication method based on free ARP is adopted to realize ARP and UDP protocol data communication by configuring proxy ARP, ARP table entry index, and VHDL language, and adopting ARP two-way defense system to realize secure data exchange and storage between public clouds and private clouds.
It improves ARP usage rate, realizes secure and reliable data communication between public and private clouds, and enhances network security and efficiency.
Smart Images

Figure CN119945805A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to an intelligent communication method and system for an e-commerce public cloud and a private cloud. Background Art
[0002] Public cloud refers to cloud computing services provided by third-party service providers, while private cloud refers to cloud computing services built by enterprises themselves. Since public cloud and private cloud are provided by different service providers, their intercommunication needs to follow certain security and technical specifications.
[0003] Currently, the intercommunication between public clouds and private clouds in the market needs to comply with certain security and technical specifications, requires specific scenarios and specifications, and has certain limitations.
[0004] A common way is to use a virtual private network (VPN) to establish a secure tunnel for data transmission and communication between the public cloud and the private cloud. In addition, other services provided by the cloud platform, such as API gateways and message queues, can also be used to achieve data exchange and communication between the public cloud and the private cloud.
[0005] The communication mechanism between the public cloud and private cloud of scientific research e-commerce is a method of implementing proxy ARP based on free ARP to achieve secure communication between IPs. Through an ARP table indexing method, with the help of ARP ID, the ARP table indexing work is completed, effectively improving the ARP utilization rate. The satellite communication device that implements ARP and UDP protocol data communication based on VHDL language realizes the functions of inspection form, settlement form, subject information and export. The ARP two-way defense system and method are used to complete the exchange and storage of system data. Summary of the invention
[0006] To achieve the above objectives, this application provides the following technical solutions: According to a first aspect of the present invention, the present invention claims protection for an intelligent communication method between an e-commerce public cloud and a private cloud, comprising: S1, configures proxy ARP based on free ARP and performs secure communication between IPs; S2, based on the ARP ID, performs ARP table indexing; S3, based on VHDL language, implements ARP and UDP protocol data communication, completes the synchronization and export of inspection orders, settlement orders, and subject information; S4 uses ARP bidirectional defense to exchange and store configuration data.
[0007] Furthermore, the S1 further includes: The front-end equipment and basic network switching facilities for network access include the terminal IP host for accessing the network, the access switch responsible for monitoring network access dynamics, and the aggregation switch responsible for data aggregation and integration; When the terminal IP host accesses the network, it spontaneously broadcasts a free ARP message according to the network protocol, announcing its own IP address and notifying the network of its existence; The access switch captures the message by means of a built-in monitoring function, extracts the IP address information of the terminal IP host, and transmits it to the aggregation switch through an internal link; After receiving the information, the aggregation switch enters and maintains the information in the host IP address information table, and subsequently processes the ARP request message from the terminal IP host according to the host IP address information table to achieve reachability detection of the target terminal in the proxy ARP.
[0008] Furthermore, the S2 further includes: Gateway device identity ARP ID, ARP table entries for address mapping, and ARP hash mapping table for auxiliary fast indexing; When the gateway device port receives a service message that needs to be forwarded, it extracts its own ARP ID and searches the local ARP management module to see if there is a corresponding ARP table entry; If not found, start the ARP table entry learning process, and generate ARP table entries and matching ARP hash mapping tables based on the local preset ARP configuration information, including key parameters such as the network address segment and subnet mask; The ARP table entry is quickly located by using the ARP ID and ARP hash mapping table, and then encapsulated into the Ethernet message header to complete service message forwarding; The gateway device has data association with the aggregation switch in step S1, and refers to the host IP address information table maintained by the aggregation switch to determine the familiarity of the source or target IP address of the service message, and decides whether to trigger ARP table entry learning.
[0009] Furthermore, the S3 further includes: It is composed of multiple professional modules working together, including the Ethernet physical layer synchronization module responsible for connecting with the physical layer hardware to ensure stable data transmission, the ARP / UDP data parsing module with protocol identification capability, the parallel CRC check module to ensure data integrity, the ARP data parsing module focusing on in-depth analysis of ARP protocol data, the ARP learning control module that dynamically updates the ARP cache table based on the parsing results, the ARP receiving module responsible for receiving external ARP messages, the ARP sending and replying module that actively sends and responds to ARP requests, the UDP data control module that regulates the UDP data processing rhythm, the UDP data parsing module that deeply parses the UDP message structure, the UDP data receiving module responsible for receiving UDP messages, the UDP data sending module that completes the encapsulation and sending of UDP messages, and the ARP / UDP data sending selection module that controls the final stage of data outflow to ensure accurate delivery of protocol data. Each module processes the incoming ARP and UDP protocol data in an orderly manner according to the data flow direction and complex protocol processing requirements; When the gateway device in step S2 determines that the service message is UDP data and requires specific link transmission or ARP-related data interaction requirements, it diverts the service message, and after being processed by each module layer by layer, the data is returned to the gateway device or downstream node according to the network topology and transmission requirements.
[0010] Furthermore, the S4 further includes: Gateway server, and several connected terminal hosts; The gateway server has a built-in gateway ARP packet filtering module and a gateway ARP cache mapping table for storing key ARP interaction records, and the terminal host is equipped with a host ARP packet filtering module; During initialization, the terminal host actively requests the gateway server to obtain the gateway MAC address and stores it as a local trust reference; In daily operation, the gateway server records the incoming and outgoing ARP request packets and ARP reply packets in detail, stores them in the gateway ARP cache mapping table and attaches a timestamp; When receiving a new ARP message, the gateway server first searches the local spoofing record table through the gateway ARP packet filtering module, including pre-stored malicious IP and MAC address features. If a match is found, it is determined to be a malicious attack source host, blocked and an alarm is issued; If there is no match, the message is analyzed in depth, anomalies are identified according to the ARP protocol specification and historical data, and the block is marked and the fraud record table is updated; Monitor the received ARP messages in real time, compare them with the locally cached gateway MAC and legitimate host information, and discard them if they do not match and report an exception.
[0011] According to a second aspect of the present invention, the present invention claims protection for an intelligent communication system for an e-commerce public cloud and a private cloud, comprising: one or more processors; A memory having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the intelligent communication method for the e-commerce public cloud and private cloud.
[0012] The present application relates to the field of network security technology, and in particular to an intelligent communication method and system for e-commerce public cloud and private cloud, which configures proxy ARP based on free ARP to perform secure communication between IPs; performs ARP table indexing based on ARP ID; implements ARP and UDP protocol data communication based on VHDL language to complete the synchronization and export of inspection orders, settlement orders, and subject information; and adopts ARP bidirectional defense configuration data exchange and storage. The present invention comprehensively uses innovative management concepts and advanced information technology to integrate and optimize resource allocation and related management processes such as human resources, funds, and basic scientific research conditions, and build an effective management service information technology platform. Through the implementation of the ARP project, it further promotes management innovation, continuously improves the level and efficiency of management work, and promotes the maximization of scientific and technological innovation and talent training benefits. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 A flowchart of an intelligent communication method for an e-commerce public cloud and a private cloud as claimed in an embodiment of the present application; Figure 2 A schematic diagram of associated accounts for an intelligent communication method between an e-commerce public cloud and a private cloud as claimed in an embodiment of the present application; Figure 3 A schematic diagram of pushing an inspection order for an intelligent communication method between an e-commerce public cloud and a private cloud as claimed in an embodiment of the present application; Figure 4 A schematic diagram of ARP classification mapping for an intelligent communication method between an e-commerce public cloud and a private cloud claimed in an embodiment of the present application; Figure 5 A schematic diagram of settlement statement push for an intelligent communication method between an e-commerce public cloud and a private cloud as claimed in an embodiment of the present application. DETAILED DESCRIPTION
[0014] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0015] The terms "first", "second" and "third" in this application are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined as "first", "second" and "third" can explicitly or implicitly include at least one of the features. In the description of this application, the meaning of "multiple" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined. All directional indications (such as up, down, left, right, front, back...) in the embodiments of this application are only used to explain the relative position relationship, movement, etc. between the components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication also changes accordingly. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices.
[0016] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0017] According to the first embodiment of the present invention, the present invention claims protection for an intelligent communication method between an e-commerce public cloud and a private cloud, referring to Figure 1 ,include: S1, configures proxy ARP based on free ARP and performs secure communication between IPs; S2, based on the ARP ID, performs ARP table indexing; S3, based on VHDL language, implements ARP and UDP protocol data communication, completes the synchronization and export of inspection orders, settlement orders, and subject information; S4 uses ARP bidirectional defense to exchange and store configuration data.
[0018] Furthermore, the S1 further includes: The front-end equipment and basic network switching facilities for network access include the terminal IP host for accessing the network, the access switch responsible for monitoring network access dynamics, and the aggregation switch responsible for data aggregation and integration; When the terminal IP host accesses the network, it spontaneously broadcasts a free ARP message according to the network protocol, announcing its own IP address and notifying the network of its existence; The access switch captures the message by means of a built-in monitoring function, extracts the IP address information of the terminal IP host, and transmits it to the aggregation switch through an internal link; After receiving the information, the aggregation switch enters and maintains the information in the host IP address information table, and subsequently processes the ARP request message from the terminal IP host according to the host IP address information table to achieve reachability detection of the target terminal in the proxy ARP.
[0019] Among them, in this embodiment, the core entities include the IP host accessing the network, the access switch responsible for monitoring, and the aggregation switch responsible for data aggregation and management. The moment the IP host accesses the network, it automatically broadcasts a free ARP message to the outside, the purpose of which is to announce its own IP address and let other devices in the network know its existence. With the built-in monitoring function, the access switch captures this free ARP message in real time, accurately extracts the host IP address information from it, and then transmits the information to the aggregation switch through the internal high-speed link. After receiving the information, the aggregation switch immediately integrates and stores it in a specially constructed host IP address information table, which becomes the key information basis for subsequent network interactions.
[0020] Key points of logical connection: The host IP address information table generated and carefully maintained in this step is like the data cornerstone of the subsequent steps. For example, when the gateway device involved in the subsequent steps processes certain business messages, if it needs to determine the legitimacy and reachability of the source or destination IP address, it can refer to this information table and establish a close data association with it to ensure the continuity and accuracy of the entire communication process.
[0021] Detailed operation process: A. When an IP host is newly connected to the network, it actively sends a free ARP message according to the network protocol specification, which clearly carries its own IP address.
[0022] B. The access switch runs a monitoring program around the clock. Once a free ARP message from an IP host is detected, the information extraction module is quickly started to accurately capture the host IP address information in the message and efficiently transmit it to the aggregation switch through a pre-configured link.
[0023] C. After receiving the transmitted host IP address information, the aggregation switch enters or updates the data in the local host IP address information table to ensure the timeliness and accuracy of the information in the table. After that, whenever the aggregation switch receives an ARP request message from an IP host, it immediately compares the target IP address in the message with the host IP address information table. If the target IP address can be successfully matched in the table, it means that the target terminal is reachable. At this time, the aggregation switch quickly sends an ARP response message to the IP host in accordance with the ARP protocol specification to help the IP host locate the target smoothly; if the target IP address is not in the table, it is determined that the ARP request may be abnormal or point to an unreachable terminal. In order to avoid invalid network traffic occupation, the ARP request message is directly discarded.
[0024] Furthermore, the S2 further includes: Gateway device identity ARP ID, ARP table entries for address mapping, and ARP hash mapping table for auxiliary fast indexing; When the gateway device port receives a service message that needs to be forwarded, it extracts its own ARP ID and searches the local ARP management module to see if there is a corresponding ARP table entry; If not found, start the ARP table entry learning process, and generate ARP table entries and matching ARP hash mapping tables based on the local preset ARP configuration information, including key parameters such as the network address segment and subnet mask; The ARP table entry is quickly located by using the ARP ID and ARP hash mapping table, and then encapsulated into the Ethernet message header to complete service message forwarding; The gateway device has data association with the aggregation switch in step S1, and refers to the host IP address information table maintained by the aggregation switch to determine the familiarity of the source or target IP address of the service message, and decides whether to trigger ARP table entry learning.
[0025] Among them, in this embodiment, this step focuses on the gateway device. The gateway device is the core hub of network data flow, and the key elements surrounding it include ARP ID, ARP table items, and ARP hash mapping tables. When the gateway device receives a business message that needs to be forwarded, it first extracts its own ARP ID. This ARP ID is like a unique identity identifier, associated with a specific ARP table item. The gateway device uses the ARP ID to quickly search the local ARP management module to determine whether the corresponding ARP table item already exists. If the search result is empty, it means that an accurate address mapping has not yet been established for the business flow. At this time, the gateway device immediately starts the ARP table item learning process.
[0026] Logical connection insights: Closely connected to step S1, the host IP address information table carefully maintained by the convergence switch in step S1 can provide an important reference for the gateway device in the early stage of business message processing. For example, when the gateway device receives a business message from a new access network segment, it can first compare it with the known host IP address information table. If it is found that the source or target IP address of the message is unfamiliar, it will trigger the ARP table entry learning process here to ensure seamless connection of network communication. The ARP table entries and the supporting ARP hash mapping table generated by this step will provide accurate address mapping support for the efficient forwarding of subsequent business messages, ensuring that data can be accurately delivered to the target node along the optimal path.
[0027] Detailed operation process: A. After the port of the gateway device receives the service message that needs to be forwarded, the internal processing module immediately extracts the ARP ID of the gateway device and uses it as a search keyword to quickly query the local ARP management database to determine whether there is a corresponding ARP table entry.
[0028] B. If the query result shows that there is no corresponding ARP table entry, the gateway device immediately starts the ARP table entry learning program. It deeply reads the local pre-configured ARP configuration information, which covers key network parameters such as network address segmentation, subnet mask setting, default gateway pointing, etc. Based on these parameters, the gateway device uses complex algorithms and logical operations to accurately generate ARP table entries that meet business needs and the closely related ARP hash mapping table. Among them, the ARP table entry records in detail the precise mapping relationship between the target IP address of the business message and the corresponding MAC address, and the ARP hash mapping table cleverly establishes an ultra-fast index channel between the ARP ID and the ARP table entry, which facilitates the rapid location of the required ARP table entry in the subsequent massive data processing.
[0029] C. After completing ARP table learning and related mapping table construction, when the same business flow is required in the future, the gateway device can locate the corresponding ARP table entry in the ARP hash mapping table at a millisecond speed based on the ARP ID, and then perfectly encapsulate it into the Ethernet message header, ensuring that the business message can be efficiently forwarded along the optimal network path, greatly improving the efficiency of ARP use and reducing network delays.
[0030] Furthermore, the S3 further includes: It is composed of multiple professional modules working together, including the Ethernet physical layer synchronization module responsible for connecting with the physical layer hardware to ensure stable data transmission, the ARP / UDP data parsing module with protocol identification capability, the parallel CRC check module to ensure data integrity, the ARP data parsing module focusing on in-depth analysis of ARP protocol data, the ARP learning control module that dynamically updates the ARP cache table based on the parsing results, the ARP receiving module responsible for receiving external ARP messages, the ARP sending and replying module that actively sends and responds to ARP requests, the UDP data control module that regulates the UDP data processing rhythm, the UDP data parsing module that deeply parses the UDP message structure, the UDP data receiving module responsible for receiving UDP messages, the UDP data sending module that completes the encapsulation and sending of UDP messages, and the ARP / UDP data sending selection module that controls the final stage of data outflow to ensure accurate delivery of protocol data. Each module processes the incoming ARP and UDP protocol data in an orderly manner according to the data flow direction and complex protocol processing requirements; When the gateway device in step S2 determines that the service message is UDP data and requires specific link transmission or ARP-related data interaction requirements, it diverts the service message, and after being processed by each module layer by layer, the data is returned to the gateway device or downstream node according to the network topology and transmission requirements.
[0031] Among them, in this embodiment, this step focuses on a satellite communication device carefully designed based on VHDL language, which is composed of multiple modules with highly specialized functions and closely coordinated operations, including Ethernet physical layer synchronization module, ARP / UDP data parsing module, parallel CRC check module, ARP data parsing module, ARP learning control module, ARP receiving module, ARP sending and reply module, UDP data control module, UDP data parsing module, UDP data receiving module, UDP data sending module and ARP / UDP data sending selection module. Each module performs in-depth processing on the incoming ARP protocol data and UDP protocol data in an orderly manner according to the rigorous data flow rules and complex protocol processing requirements.
[0032] Logical connection analysis: Closely corresponding to step S2, the business message processed by the gateway device in step S2, once it involves the protocol type (ARP or UDP) supported by this satellite communication device, will be accurately directed to this device for in-depth analysis and professional processing according to the preset rules. For example, when the gateway device determines that a business message is UDP data and needs to be transmitted over long distances with the help of a satellite link, it will efficiently push it to the UDP data receiving module of the device according to the established process, thereby starting a series of subsequent sophisticated UDP data processing processes; similarly, for ARP-related data interaction requirements, it will also be accurately guided into the corresponding ARP processing module link according to the protocol characteristics. The data output by this device after layer-by-layer processing will be strictly transmitted back to the gateway device or other downstream target nodes in an orderly manner in accordance with the network topology and transmission requirements, ensuring the continuous and stable flow of data in the entire communication network.
[0033] Module in-depth explanation: Ethernet physical layer synchronization module: As the key interface between the satellite communication device and the physical layer hardware, it shoulders a vital mission. It achieves seamless connection with the physical layer hardware through highly precise clock synchronization technology, ensuring stable and high-speed data transmission at the physical link level. Whether it is an electrical signal or an optical signal from the external network, the module can accurately capture it and quickly convert it into a digital data format. At the same time, according to strict timing rules, the processed data is efficiently passed to the subsequent upper-layer modules, laying a solid foundation for the normal operation of the entire device.
[0034] ARP / UDP data analysis module: It is like an intelligent "gatekeeper" of the device, with super protocol recognition capabilities. When data frames flow in from the outside, it can quickly and accurately determine whether the incoming data belongs to the ARP protocol or the UDP protocol in nanoseconds based on the characteristic fields carried in the data frame header. Once the identification is completed, the data will be immediately diverted to the corresponding professional analysis module, such as the ARP data analysis module or the UDP data analysis module, to start a refined and professional processing flow to ensure the accuracy and efficiency of data processing.
[0035] Parallel CRC verification module: It plays the role of "data guard" at each key node of data transmission, and adopts advanced parallel processing technology to greatly improve the verification speed. Whether it is ARP protocol data or UDP protocol data, it must be strictly verified by this module at the initial stage of entering the device, during the flow between internal modules, and at the last moment before it is transmitted out of the device. It uses a complex CRC algorithm to conduct a comprehensive test on the integrity and accuracy of the data. Once a verification error is found, it immediately triggers the preset retransmission or error correction mechanism to ensure that there are no errors in the data transmission process and guarantee the communication quality.
[0036] ARP data analysis module: Focuses on in-depth analysis of ARP protocol data, like a professional "detective" who does not miss any details. It deeply mines the key fields in the ARP protocol data frame, including the source IP address, target IP address, source MAC address, target MAC address and other core information, and organizes this information into structured data, providing an accurate data source for subsequent ARP learning control, sending and replying operations, ensuring that the ARP protocol can be accurately executed throughout the communication process.
[0037] ARP learning control module: Based on the accurate information provided by the ARP data analysis module, combined with the pre-stored network configuration information and intelligent learning strategy of the device, the internal ARP cache table is dynamically updated and optimized. For example, when a new ARP reply packet is received and it is found through comparison that the information has not been recorded in the local cache, the fast entry program is immediately started to accurately enter the new address mapping relationship into the ARP cache table, ensuring that subsequent ARP requests for the same target can achieve ultra-fast responses, significantly improving network communication efficiency.
[0038] ARP receiving module: As the "front line" for the device to receive external ARP messages, it is responsible for efficiently capturing ARP messages from external networks, temporarily caching them, and then quickly passing them to the ARP data parsing module for subsequent in-depth processing. At the same time, it maintains close cooperation with the ARP sending and replying modules to ensure that the ARP interaction process is bidirectional and smooth within the device, avoiding data congestion or poor interaction.
[0039] ARP sending and reply module: Based on the real-time needs of network communication, it has the ability to take the initiative and can send ARP request messages accurately and timely to obtain the MAC address information of unknown targets and open up a path for data transmission; at the same time, for the received ARP requests, it can rely on local cache or through quickly learned information to quickly generate and return ARP reply messages that comply with the ARP protocol specifications, ensuring two-way reachability between network nodes and ensuring the stability of the communication link.
[0040] UDP data control module: plays the role of "commander" of the entire UDP data processing process, and accurately regulates the working rhythm between the UDP data parsing module, the receiving module and the sending module. It reasonably allocates resources based on the pre-set business logic and real-time network status to ensure that UDP data can be processed in an orderly manner according to the predetermined process. For example, it intelligently diverts data according to the port number of the UDP message and guides data of different business types to the corresponding processing module; at the same time, it can also dynamically control the data transmission rate according to the network congestion situation to ensure the stability and efficiency of UDP data transmission.
[0041] UDP data parsing module: It goes deep into the internal structure of UDP packets and fully parses their header information and payload data. It can accurately extract key information such as source port, destination port, data length, checksum, etc., and organize this information into a format that is convenient for subsequent processing, providing a solid foundation for further processing of data at the application layer. After the parsing is completed, it will pass the data to the corresponding business processing module according to business needs, or directly push it to the UDP data sending module for outward forwarding.
[0042] UDP data receiving module: accurately captures UDP packets from complex network environments and safely transfers them to the UDP data parsing module for in-depth analysis. In this process, it carefully maintains the receiving buffer, prevents data loss or overflow through advanced cache management technology, ensures the stability and reliability of UDP data reception, and provides sufficient data protection for subsequent business processing.
[0043] UDP data sending module: According to the precise instructions issued by the UDP data control module, the UDP data to be sent is carefully encapsulated into the standard UDP message format, and necessary header information is added, such as source port, destination port, checksum, etc. Then, through close cooperation with the Ethernet physical layer synchronization module, the encapsulated UDP message is sent to the target network node at the fastest speed, completing the outward transmission task of UDP data and ensuring that the data can be accurately delivered to the destination.
[0044] ARP / UDP data transmission selection module: It is the last checkpoint of the device data outflow and shoulders the important task of "gatekeeper". It uses intelligent algorithms to make accurate judgments based on the real-time needs of the upper-level business system and the protocol type of the data, and selects the most appropriate transmission path to ensure that ARP protocol data and UDP protocol data can flow to their respective target nodes accurately without interfering with each other, avoiding data confusion and erroneous delivery, and ensuring the stability of the entire communication system.
[0045] Furthermore, the S4 further includes: Gateway server, and several connected terminal hosts; The gateway server has a built-in gateway ARP packet filtering module and a gateway ARP cache mapping table for storing key ARP interaction records, and the terminal host is equipped with a host ARP packet filtering module; During initialization, the terminal host actively requests the gateway server to obtain the gateway MAC address and stores it as a local trust reference; In daily operation, the gateway server records the incoming and outgoing ARP request packets and ARP reply packets in detail, stores them in the gateway ARP cache mapping table and attaches a timestamp; When receiving a new ARP message, the gateway server first searches the local spoofing record table through the gateway ARP packet filtering module, including pre-stored malicious IP and MAC address features. If a match is found, it is determined to be a malicious attack source host, blocked and an alarm is issued; If there is no match, the message is analyzed in depth, anomalies are identified according to the ARP protocol specification and historical data, and the block is marked and the fraud record table is updated; Monitor the received ARP messages in real time, compare them with the locally cached gateway MAC and legitimate host information, and discard them if they do not match and report an exception.
[0046] Among them, in this embodiment, this part carefully constructs an ARP two-way defense system with a gateway server as the core and several hosts working closely together. The gateway server integrates a powerful gateway ARP packet filtering module and a gateway ARP cache mapping table for storing key data, and each host connected to it is equipped with a dedicated host ARP packet filtering module. At the beginning of system startup, the host actively sends a request to the gateway server to obtain the gateway MAC address of the gateway server, and properly stores it in the local cache as a trust benchmark for a series of subsequent ARP interactions. At the same time, during daily operation, the gateway server will record every incoming and outgoing ARP request packet and ARP response packet in detail, store this valuable information in the gateway ARP cache mapping table, and accurately record the corresponding timestamp.
[0047] Key points of logical connection: Based on the stable communication link established by steps S1 - S3, this step cleverly adds an indestructible security protection layer. For example, when the gateway server receives or forwards any ARP-related message, it will first introduce the message into the gateway ARP packet filtering module for strict screening. In this process, the gateway ARP packet filtering module will make full use of the massive historical records in the gateway ARP cache mapping table and the built-in intelligent deception detection algorithm to make in-depth judgments on the legitimacy and security of the message. Once any suspicious signs are found, decisive measures will be taken to block them immediately, and abnormalities will be marked in time to prevent malicious messages from spreading indiscriminately in the network, effectively ensuring the security of the entire cloud communication system. At the same time, the host ARP packet filtering module on the host side does not exist in isolation. It works closely with the gateway server to form a solid line of defense at the terminal level, effectively preventing possible ARP deception attacks, thereby building an all-round, no-dead-angle two-way defense mechanism.
[0048] Detailed operation process: A. During the system initialization phase, after each host is turned on, it immediately sends a request to the gateway server according to the preset procedure. After receiving the request, the gateway server accurately sends its own gateway MAC address to the host. After receiving it, the host stores it in a specially opened local cache area as a trust anchor point in the subsequent ARP interaction process.
[0049] B. The gateway server pays close attention to the incoming and outgoing ARP request packets and ARP reply packets at every moment of daily operation. It uses the built-in high-speed data acquisition and storage module to store the detailed information of these packets, including the source IP address, destination IP address, source MAC address, destination MAC address, and key data such as sending and receiving time, in the gateway ARP cache mapping table to ensure the integrity and timeliness of the data.
[0050] C. When the gateway server receives a new ARP message, the gateway ARP packet filtering module is immediately activated. The module will first quickly search the local deception record table, which pre-stores a large number of known malicious IP addresses and MAC address features. If the source IP address or MAC address of the new message matches it, it will immediately determine that the message comes from the malicious attack source host, decisively block its transmission path, and quickly send an alarm to the network administrator so that timely countermeasures can be taken. If no abnormality is found in the deception record table, the message content will be further analyzed in depth. Based on the rigorous ARP protocol specifications and the massive historical data cached locally, an intelligent algorithm will be used to identify whether there are abnormal ARP messages in the message, such as frequently changing MAC addresses, unreasonable IP address allocation, and other suspicious situations. Once an abnormality is found, the message will be immediately marked as an abnormality, its propagation path in the network will be blocked, and the relevant abnormal information will be updated to the deception record table, continuously improving the system's ability to prevent similar attacks.
[0051] D. On the host side, the host ARP packet filtering module also remains vigilant and monitors the ARP messages received locally in real time. It strictly compares the received messages with the locally cached gateway MAC and the legitimate host information that has been interacted with before. If the source MAC address of the message is found to be inconsistent with the expectation, or there are obvious signs of tampering in the message content, the message will be discarded immediately and decisively, and the abnormal information will be fed back to the gateway server in a timely manner, and the gateway server will work together to maintain a safe and stable network environment.
[0052] Through the above-mentioned all-round and refined optimization and integration of each step, the communication mechanism between the public cloud and private cloud of this scientific research e-commerce has successfully realized the closed-loop management of the entire process from device access to data transmission, from protocol processing to security defense. The various modules work closely together and complement each other, providing a rock-solid guarantee for the cloud communication needs in the field of scientific research e-commerce.
[0053] In this embodiment, it also includes: Through OSS configuration, select the push content of ARP docking: inspection order push, settlement order push After binding with an existing account, change the account source of the mall account, save the email address and user ID to the account, and then the email address will jump directly to the account through the Technology Cloud login link.
[0054] After binding with an existing account, change the account source of the mall account, save the email address and user ID to the account, and then the email address will jump directly to the account through the Technology Cloud login link.
[0055] You can choose to associate an existing mall account or create a new mall account.
[0056] Reference Figure 2 , select I am PI in the associated account diagram; Verify whether the current unit (in the account that has been approved and enabled) of the research group name exists; Verify whether the user id exists; Enter the user ID and call the interface to obtain the name, mobile phone number, and department; Mailbox automatically imported; After the pI account is submitted, it will be automatically reviewed and approved Select I am a buyer: Fuzzy query of research group, supports querying by research group name or the name of the main account of the research group; After the purchaser's account is submitted, a sub-account under the research group is generated, and the OSS background and the main account can review it.
[0057] ARP Inspection Order Warehousing: After enabling the push of inspection orders, both self-inspection and unified inspection will follow the push logic; For those with material attributes enabled and split inspection by purchasing category, we will not consider it for now and inspect according to the original logic: Status of the incoming order: not pushed, being pushed, pushed but not entered into the warehouse, draft, being reviewed, reviewed, other (returned, revoked, disagreed, abnormally terminated, completed, invalidated); Scheduled task, for the inventory receipt in the reviewed status, query the reimbursement amount of the cumulative reimbursement order (status is 70) corresponding to the inventory receipt, match the settlement amount of the inspection order under the inventory receipt according to the cumulative reimbursement amount, if the totals are the same, change the payment status of the mall inspection order to paid.
[0058] Reference Figure 3 , the inspection list push diagram includes: Inspection orders in the draft and later states cannot be used for after-sales service. Click on the after-sales prompt; The merchant agrees to the after-sales service and synchronizes the buffer message. When processing the message, if the inspection form has been associated with the warehouse entry form (draft or later), the message will not be processed. On the contrary, if the buffer information is updated and all products are after-sales, the inspection form in the buffer will be deleted; if some products are after-sales, the corresponding products and quantities will be deleted; ARP unit of measurement: Click Update to adjust the ARP interface to obtain the latest data; If the mall has a measurement unit that the interface returns but does not have, the mall will perform a logical deletion; If the mall does not have it but the interface has it, the mall will add it; if both sides have it, we will not process it; Reference Figure 4 , ARP classification mapping includes: Import template: mall final category id, mall final category name, ARP final category name, ARP final category id; A mall final category can only correspond to one arp final category; an arp final category can correspond to multiple mall categories; When adding and batch importing, the above logic verification should be added; Reference Figure 5 , the settlement statement push diagram includes: ARP settlement sheet push data; Push logic: Under the confirmed settlement form, add the filtering and list display of reimbursement form status; Reimbursement form status: not pushed, pushing, pushed but not associated, draft, business review, financial review, completed and waiting for payment, paid; Check "Reimbursed", the button will change to "Push to ARP", click "Push" to change the reimbursement form status, but not the settlement form status, the settlement form will still be confirmed; When processing a push message, check the status of the reimbursement form of the current order number. If it is in the draft or later status, the message will not be processed and will be deleted. In the selected settlement form, if the reimbursement form status is draft or later, it will be automatically skipped and no message will be pushed.
[0059] The reimbursement button in the settlement statement details and summary pages is hidden.
[0060] According to a second embodiment of the present invention, the present invention claims protection for an intelligent communication system for an e-commerce public cloud and a private cloud, comprising: one or more processors; A memory having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the intelligent communication method for the e-commerce public cloud and private cloud.
[0061] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0062] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units. The above is only an implementation method of the present application, and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the specification and drawings of this application, or directly or indirectly used in other related technical fields, is also included in the patent protection scope of the present application.
[0063] The specific implementation methods of the invention are described in detail above, but they are only examples, and the present application is not limited to the specific implementation methods described above. For those skilled in the art, any equivalent modification or substitution of the invention is also within the scope of the present application, and therefore, the equalization, modification, and improvement made without departing from the spirit and principle of the present application should be included in the scope of the present application.
Claims
1. An intelligent communication method for e-commerce public cloud and private cloud, characterized in that: include: S1, configures proxy ARP based on free ARP and performs secure communication between IPs; S2, based on the ARP ID, performs ARP table indexing; S3, based on VHDL language, implements ARP and UDP protocol data communication, completes the synchronization and export of inspection orders, settlement orders, and subject information; S4 uses ARP bidirectional defense to exchange and store configuration data.
2. According to claim 1, an intelligent communication method for e-commerce public cloud and private cloud, characterized in that: Said S1 further comprises: The front-end equipment and basic network switching facilities for network access include the terminal IP host for accessing the network, the access switch responsible for monitoring network access dynamics, and the aggregation switch responsible for data aggregation and integration; When the terminal IP host accesses the network, it spontaneously broadcasts a free ARP message according to the network protocol, announcing its own IP address and notifying the network of its existence; The access switch captures the message by means of a built-in monitoring function, extracts the IP address information of the terminal IP host, and transmits it to the aggregation switch through an internal link; After receiving the information, the aggregation switch enters and maintains the information in the host IP address information table, and subsequently processes the ARP request message from the terminal IP host according to the host IP address information table to achieve reachability detection of the target terminal in the proxy ARP.
3. According to claim 1, an intelligent communication method for e-commerce public cloud and private cloud, characterized in that: Said S2 further comprises: Gateway device identity ARP ID, ARP table entries for address mapping, and ARPhash mapping table for auxiliary fast indexing; When the gateway device port receives a service message that needs to be forwarded, it extracts its own ARP ID and searches the local ARP management module to see if there is a corresponding ARP table entry; If not found, start the ARP table entry learning process, and generate ARP table entries and matching ARP hash mapping tables based on the local preset ARP configuration information, including key parameters such as the network address segment and subnet mask; The ARP table entry is quickly located by using the ARP ID and ARP hash mapping table, and then encapsulated into the Ethernet message header to complete service message forwarding; The gateway device has data association with the aggregation switch in step S1, and refers to the host IP address information table maintained by the aggregation switch to determine the familiarity of the source or target IP address of the service message, and decides whether to trigger ARP table entry learning.
4. According to claim 1, the intelligent communication method for e-commerce public cloud and private cloud is characterized in that: The S3 further includes: It is composed of multiple professional modules working together, including the Ethernet physical layer synchronization module responsible for connecting with the physical layer hardware to ensure stable data transmission, the ARP / UDP data parsing module with protocol identification capability, the parallel CRC check module to ensure data integrity, the ARP data parsing module focusing on in-depth analysis of ARP protocol data, the ARP learning control module that dynamically updates the ARP cache table based on the parsing results, the ARP receiving module responsible for receiving external ARP messages, the ARP sending and replying module that actively sends and responds to ARP requests, the UDP data control module that regulates the UDP data processing rhythm, the UDP data parsing module that deeply parses the UDP message structure, the UDP data receiving module responsible for receiving UDP messages, the UDP data sending module that completes the encapsulation and sending of UDP messages, and the ARP / UDP data sending selection module that controls the final stage of data outflow to ensure accurate delivery of protocol data. Each module processes the incoming ARP and UDP protocol data in an orderly manner according to the data flow direction and complex protocol processing requirements; When the gateway device in step S2 determines that the service message is UDP data and requires specific link transmission or ARP-related data interaction requirements, it diverts the service message, and after being processed by each module layer by layer, the data is returned to the gateway device or downstream node according to the network topology and transmission requirements.
5. The intelligent communication method for e-commerce public cloud and private cloud according to claim 1, characterized in that: The S4 further includes: Gateway server, and several connected terminal hosts; The gateway server has a built-in gateway ARP packet filtering module and a gateway ARP cache mapping table for storing key ARP interaction records, and the terminal host is equipped with a host ARP packet filtering module; During initialization, the terminal host actively requests the gateway server to obtain the gateway MAC address and stores it as a local trust reference; In daily operation, the gateway server records the incoming and outgoing ARP request packets and ARP reply packets in detail, stores them in the gateway ARP cache mapping table and attaches a timestamp; When receiving a new ARP message, the gateway server first searches the local spoofing record table through the gateway ARP packet filtering module, including pre-stored malicious IP and MAC address features. If a match is found, it is determined to be a malicious attack source host, blocked and an alarm is issued; If there is no match, the message is analyzed in depth, anomalies are identified according to the ARP protocol specification and historical data, and the block is marked and the fraud record table is updated; Monitor the received ARP messages in real time, compare them with the locally cached gateway MAC and legitimate host information, and discard them if they do not match and report an exception.
6. An intelligent communication system for e-commerce public cloud and private cloud, characterized in that: include: one or more processors; A memory having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement an intelligent communication method for an e-commerce public cloud and a private cloud according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method and system for realizing proxy address resolution protocol (ARP) based on gratuitous ARP
CN102572013A
ARP bidirectional defense system and method
CN110022303A
ARP table entry indexing method and system
CN112073552A
Satellite-borne communication device for realizing ARP and UDP protocol data communication based on VHDL language
CN113452804A
Communication method, gateway and management method and apparatus in hybrid cloud environment
WO2024125332A1