Message transmission method and device
By verifying the destination address of the service message in the security module of the server, the problem of difficulty in preventing malicious network attacks in the prior art is solved, and effective security protection for the service network is achieved.
Patent Information
- Application Number
- CN202410516422.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-04-26
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art is difficult to effectively prevent malicious network attacks in the business network, especially when the service packets accessing services do not have the authentication capabilities, it is difficult to prevent network attacks caused by zombie attacks and Trojan programs.
By receiving service messages sent by the client in the security module of the server, and verifying the verification fields in the message according to the preset verification rules, only service messages that pass through the destination address are allowed to access the target service, thereby preventing traffic from attack sources.
Ensure that only legitimate service packets can access the target service, effectively prevent malicious attacks, and enhance the security of the service network.
Smart Images

Figure CN120034346A_ABST
Abstract
Description
[0001] This application claims priority to Chinese patent application No. 202311558273.3, filed on November 21, 2023, and entitled “A method, device and other equipment for data processing”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of security technology, and in particular to a message transmission method and device. Background Art
[0003] Current business networks (such as traditional / new data centers, commercial Internet websites, application services, industrial Internet, smart cities, smart terminals and other business networks in various scenarios) will face malicious network attacks for various purposes. For example, the business network has no restrictions on clients accessing services, and clients in all regions can access it, while the relevant technology can only generate corresponding regional filtering policies to filter attack messages after a malicious attack occurs. For another example, the Internet protocol (IP) address of the node providing services in the business network is exposed on the network, and the IP address is bound to the service, so it is easy to be attacked maliciously. For another example, in the relevant technology, the business network has no authentication capability for business messages accessing services, so it is difficult to prevent zombie attacks. For another example, the whitelist routing in the relevant technology has a certain attack prevention capability, but the relevant technology is powerless against network attacks launched by whitelist users who have become zombie hosts after being infected with Trojan programs.
[0004] Therefore, how to ensure the security of the business network in the process of accessing services provided by the business network through business messages is an issue that needs to be urgently addressed. Summary of the invention
[0005] The present application provides a message transmission method and device, which can ensure that only business messages that pass destination address verification can access the target service, thereby preventing traffic from the attack source from accessing the target service, thereby ensuring the security of the business network where the target service is deployed.
[0006] The technical solutions provided by this application are as follows:
[0007] In a first aspect, the present application provides a message transmission method, which is applied to a security module of a server, and the server is used to provide a target service to a client, and the target service runs on at least one server in at least one cloud data center located in one of multiple regions. The method includes: receiving a target business message sent by a client for accessing a target service, the target business message including a verification field; verifying the verification field included in the target business message according to a preset target verification rule; and in response to successful verification, sending the target business message to the server. Wherein, successful verification is used to indicate that the destination address of the target business message is the address configured for the client to access the target service.
[0008] Through the method provided by the present application, the destination address of the business message in the forwarding process can be verified according to the verification field carried by the business message, and the business message can be forwarded normally when the destination address of the business message is the access address configured for the client that initiates the business message to access the target service. That is, the method can ensure that only business messages with passed destination address verification can access the target service, so that traffic from the attack source can be prevented from accessing the target service, thereby ensuring the security of the business network where the target service is deployed.
[0009] In one possible design, the verification field included in the target business message is verified according to the preset target verification rules, including: calculating the target verification field according to the target verification rules; comparing the target verification field with the verification field included in the target business message; and determining that the verification is successful when the target verification field and the verification field included in the target business message are the same.
[0010] In another possible design, the target verification field is obtained by calculating according to the target verification rule, including: parsing the calculation factor indicated by the target verification rule from the target service message; and calculating the calculation factor using the preset algorithm indicated by the target verification rule to obtain the target verification field. The preset algorithm is an encryption algorithm or a hash algorithm.
[0011] Through the above two possible designs, the gateway on the server side can calculate the verification field for each received business message to verify the business message, and verify the destination address of the business message through the calculated verification field and the verification field included in the business message. Moreover, when the preset algorithm is a hash algorithm or an encryption algorithm, encryption of the calculation factor can be achieved. Therefore, when the business message includes a verification field obtained after hashing or encrypting the calculation factor, and the verification field is verified during the transmission of the business message, the security verification of the destination address of the business message can be achieved, so that the business message can be guaranteed to be a legal and secure business message, thereby ensuring the security of the business network where the service accessed by the business message is deployed.
[0012] In another possible design, the calculation factors include at least one of the following: a service identifier (ID) of the target service, an operator of the network to which the client belongs, a service level of the client, a reputation of the client, a reputation of a gateway of the client, a reputation of an area where the client is located, an Internet protocol (IP) address of the client, an area where the client is located, a subnet number of a network to which the client belongs, a device type of the client, a device ID of the client, a gateway type of the client, a time when the client generates a service message, and a validity period of a target verification rule.
[0013] In another possible design, the calculation factors include a service level factor and a security verification factor. Among them, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes at least one of the following: the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a service message, and the effective time of the verification rule. The above preset algorithm is used to calculate the security verification factor to obtain a security verification field in the target verification field for verifying security.
[0014] Through the above two possible designs, when the calculation factor contains different information, the verification field obtained after calculating the calculation factor using a preset algorithm can distinguish the service messages initiated by the client at different granularities. In one example, when the calculation factor includes at least the relevant information of the target service, the verification field calculated based on the calculation factor can distinguish the service messages initiated by the client at the granularity of the service. In other words, the service messages of the same client accessing different services can be distinguished by the verification fields carried by each service message. In another example, when the calculation factor includes at least the service level of the client, the verification field calculated based on the calculation factor can distinguish the service messages initiated by the client at the granularity of the service level of the client. In other words, the service messages of clients with different service levels accessing the same service can be distinguished by the verification fields carried by each service message. In another example, when the calculation factor includes at least the attribute information of the client (such as the client device type or the client device ID), the verification field calculated based on the calculation factor can distinguish the messages initiated by the client at the granularity of the client. In other words, the service messages of different clients accessing the same service can be distinguished by the verification fields carried by the service messages. In another example, when the calculation factor includes at least the client's geographical information (such as the region where the client is located), the verification field calculated based on the calculation factor can distinguish business messages initiated by clients in different regions based on the region. In other words, business messages from clients in different regions accessing the same service can be distinguished by the verification field carried by the business message.
[0015] In another possible design, before parsing the calculation factor indicated by the target validation rule from the target service message, the method further includes: determining the target validation rule corresponding to the preset field according to the preset field included in the destination address of the target service message. The preset field includes the network prefix and subnet address of the destination address.
[0016] In another possible design, the method further includes: querying a release list according to the source address of the target business message and the destination address of the target business message, the release list including at least one release record for recording the source address and the destination address accessed by the source address. The method of determining the target verification rule corresponding to the preset field according to the preset field included in the destination address of the target business message includes: when the release list does not include the first release record, determining the target verification rule corresponding to the preset field according to the preset field included in the destination address of the target business message. The first release record is used to record the source address of the target business message and the destination address of the target business message.
[0017] In yet another possible design, the above method further includes: adding a first release record to the release list when the verification field included in the target service message passes the verification according to the target verification rule.
[0018] Through the above possible design, the security module of the server can subsequently quickly perform security verification on the destination address of the received service message using the release list.
[0019] In yet another possible design, the above method further includes: setting a valid duration for the first release record.
[0020] Through this possible design, when setting a valid duration or valid period for the release record, it is possible to increase the difficulty for the attack source to resolve the access address of the target service to attack the target service, thereby enhancing the network security of the business network where the target service is located. For example, when the attack source resolves the access address of the target service, the valid duration of the release record has expired, and at this time, the attack source still cannot access the target service based on the resolved address.
[0021] In yet another possible design, the security module of the server is deployed in the gateway of the server. The above method further includes: sending the target verification rule to the forwarding node reachable by the gateway; or, sending the first release record to the forwarding node.
[0022] Through this possible design, the forwarding nodes reachable by the server gateway can obtain a combination including the preset field and the verification rule, and / or obtain the access address (i.e., the release record) of the target service calculated based on the preset field and the verification rule. Subsequently, these forwarding nodes can execute the method provided in this application for the received service messages, thereby realizing the forwarding or blocking of these service messages, and thus being able to filter attack traffic at a position close to the client (i.e., the source end), so as to improve the impact of network attacks on the communication network between the client and the service gateway.
[0023] In yet another possible design, the above method further includes: sending the target service message to the server when the release list includes the first release record.
[0024] In yet another possible design, the above sending the target service message to the server includes: performing network address translation (NAT) on the destination address of the target service message; sending the target service message to the NATed address. The NATed address is the address of the server.
[0025] In another possible design, the address after NAT is an Internet Protocol version 6 (IPv6) address or an Internet Protocol version 4 (IPv4) address.
[0026] Through this possible design, the purpose of flexibly deploying the real IP address of the backend service can be achieved.
[0027] In another possible design, the above method also includes: in response to a verification failure, and / or when the destination address of the target business message exists in a blocking list, blocking the target business message, and the blocking list is used to record the destination address of the business message that is prohibited from being forwarded to the next hop node.
[0028] In another possible design, the above-mentioned blocking of the target service message includes: discarding the target service message, forwarding the target service message to the honeypot node, or marking the target service message as a suspicious message.
[0029] Through this possible design, when the server gateway redirects the traffic that fails the verification to the honeypot node, the honeypot node can parse the traffic to obtain attack information (such as attack traffic characteristics, attack characteristics, attack source address, etc.). Furthermore, this attack information can be applied to various security devices after analysis and processing.
[0030] In another possible design, when the destination address of the target service message is an IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes a verification field of the target service message. Alternatively, when the destination address of the target service message is an IPv4 address, the option field of the target service message includes a verification field of the target service message.
[0031] Through this possible design, the purpose of flexibly carrying the verification field in the message can be achieved.
[0032] In a second aspect, the present application provides a message transmission method, which is applied to a client accessing a target service, wherein the target service is a service provided by a server, and the target service runs on at least one server in at least one cloud data center located in one of multiple regions. The method includes: obtaining a destination address of a target service message to be sent and a verification field corresponding to the destination address, wherein the destination address is an address configured for the client to access the target service, and the verification field is calculated based on a target verification rule corresponding to the destination address. Send a target service message, wherein the target service message includes a verification field, and the target service message is used to access the target service.
[0033] In one possible design, the above-mentioned sending of the target service message includes: sending the target service message within the valid duration of the destination address of the target service message.
[0034] In another possible design, the client is preset with a target validation rule and multiple preset fields, and the preset fields include the network prefix of the business network where the target service is deployed and the subnet address of the server providing the target service in the business network. If the destination address of the target business message includes a validation field, the above-mentioned acquisition of the destination address of the target business message to be sent and the validation field corresponding to the destination address includes: selecting a target preset field from multiple preset fields; calculating the validation field according to the target validation rule; and concatenating the target preset field and the validation field to obtain the destination address of the target business message.
[0035] In another possible design, the client is configured with target verification rules and multiple access addresses of the target service. The above-mentioned acquisition of the destination address of the target business message to be sent and the verification field corresponding to the destination address includes: selecting the destination address of the target business message from multiple access addresses; and calculating the verification field according to the target verification rules.
[0036] In another possible design, the verification field is obtained by calculating according to the target verification rule, including: using the preset algorithm indicated by the target verification rule to calculate the calculation factor indicated by the target verification rule to obtain the verification field. The preset algorithm is an encryption algorithm or a hash algorithm. The calculation factor includes at least one of the following: the service identifier ID of the target service, the operator of the network to which the client belongs, the service level of the client, the credibility of the client, the credibility of the gateway of the client, the credibility of the area where the client is located, the Internet Protocol IP address of the client, the area where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates the service message, and the effective time of the target verification rule.
[0037] In another possible design, the calculation factors include a service level factor and a security verification factor. Among them, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes at least one of the following: the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a service message, and the effective time of the verification rule. The above preset algorithm is used to calculate the security verification factor to obtain a security verification field in the target verification field for verifying security.
[0038] In another possible design, the above-mentioned acquisition of the destination address of the target business message to be sent and the verification field corresponding to the destination address includes: sending an address request, the address request is used to request to obtain the destination address of the target business message; receiving the destination address of the target business message, the destination address carries the verification field corresponding to the destination address.
[0039] In another possible design, when the destination address of the target service message is an IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes a verification field of the target service message. Alternatively, when the destination address of the target service message is an IPv4 address, the option field of the target service message includes a verification field of the target service message.
[0040] It can be understood that the beneficial effects achieved by the method provided by the second aspect and any possible design method in the second aspect can be referred to the technical effects of the corresponding solutions provided by the first aspect and any possible design method in the first aspect, and will not be repeated here.
[0041] In a third aspect, the present application provides a message transmission device, which is applied to a security module of a server, and the server is used to provide a target service to a client, and the target service runs on at least one server in at least one cloud data center located in one of multiple regions. The device includes: a receiving unit, which is used to receive a target business message sent by a client for accessing the target service, and the target business message includes a verification field; a processing unit, which is used to verify the verification field included in the target business message according to a preset target verification rule; and a sending unit, which is used to send the target business message to the server in response to a successful verification. Wherein, a successful verification is used to indicate that the destination address of the target business message is the address configured for the client to access the target service.
[0042] In one possible design, the processing unit is specifically used to calculate a target verification field according to a target verification rule, compare the target verification field with the verification field included in the target business message, and determine that the verification is successful when the target verification field and the verification field included in the target business message are the same.
[0043] In another possible design, the processing unit is further specifically used to parse the calculation factor indicated by the target verification rule from the target service message, and calculate the calculation factor using the preset algorithm indicated by the target verification rule to obtain the target verification field. The preset algorithm is an encryption algorithm or a hash algorithm.
[0044] In another possible design, the calculation factors include at least one of the following: a service identifier (ID) of the target service, an operator of the network to which the client belongs, a service level of the client, a reputation of the client, a reputation of a gateway of the client, a reputation of an area where the client is located, an Internet protocol (IP) address of the client, an area where the client is located, a subnet number of a network to which the client belongs, a device type of the client, a device ID of the client, a gateway type of the client, a time when the client generates a service message, and a validity period of a target verification rule.
[0045] In another possible design, the calculation factors include a service level factor and a security verification factor. Among them, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes at least one of the following: the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a service message, and the effective time of the verification rule. The above preset algorithm is used to calculate the security verification factor to obtain a security verification field in the target verification field for verifying security.
[0046] In another possible design, the processing unit is further configured to determine the target validation rule corresponding to the preset field according to the preset field included in the destination address of the target service message before parsing the calculation factor indicated by the target validation rule from the target service message, wherein the preset field includes the network prefix and subnet address of the destination address.
[0047] In another possible design, the processing unit is further used to query a release list according to the source address of the target business message and the destination address of the target business message, the release list includes at least one release record for recording the source address and the destination address accessed by the source address, and, when the release list does not include the first release record, determine the target verification rule corresponding to the preset field according to the preset field included in the destination address of the target business message. The first release record is used to record the source address of the target business message and the destination address of the target business message.
[0048] In another possible design, the processing unit is further used to add a first release record to the release list when the verification field included in the target business message is successfully verified according to the target verification rule.
[0049] In yet another possible design, the processing unit is further configured to set a validity period for the first release record.
[0050] In another possible design, the security module of the server is deployed in the gateway of the server, and the sending unit is further used to send the target verification rule to the forwarding node that can reach the gateway, or to send the first release record to the forwarding node.
[0051] In another possible design, the sending unit is further specifically used to send the target service message to the server when the release list includes the first release record.
[0052] In another possible design, the sending unit is specifically configured to perform network address translation (NAT) on the destination address of the target service message and send the target service message to the address after NAT, wherein the address after NAT is the address of the server.
[0053] In another possible design, the address after NAT is an IPv6 address or an IPv4 address.
[0054] In another possible design, the processing unit is also used to block the target business message in response to a verification failure and / or when the destination address of the target business message exists in a blocking list, and the blocking list is used to record the destination addresses of the business messages that are prohibited from being forwarded to the next hop node.
[0055] In yet another possible design, the processing unit is further specifically configured to discard the target service message, forward the target service message to the honeypot node, or mark the target service message as a suspicious message.
[0056] In another possible design, when the destination address of the target service message is an IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes a verification field of the target service message. Alternatively, when the destination address of the target service message is an IPv4 address, the option field of the target service message includes a verification field of the target service message.
[0057] It can be understood that the beneficial effects achieved by the message transmission device provided by the third aspect and any possible design method in the third aspect can be referred to the technical effects of the corresponding solutions provided by the first aspect and any possible design method in the first aspect, and will not be repeated here.
[0058] In a fourth aspect, the present application provides a message transmission device, which is applied to a client accessing a target service, wherein the target service is a service provided by a server, and the target service runs on at least one server in at least one cloud data center located in one of multiple regions. The device includes: an acquisition unit, which is used to acquire a destination address of a target service message to be sent and a verification field corresponding to the destination address, wherein the destination address is an address configured for the client to access the target service, and the verification field is calculated based on a target verification rule corresponding to the destination address. A sending unit, which is used to send a target service message, wherein the target service message includes a verification field, and the target service message is used to access the target service.
[0059] In one possible design, the sending unit is specifically used to send the target service message within the valid duration of the destination address of the target service message.
[0060] In another possible design, the client is preset with a target validation rule and multiple preset fields, and the preset fields include the network prefix of the business network where the target service is deployed and the subnet address of the server providing the target service in the business network. Then, when the destination address of the target business message includes the validation field, the acquisition unit is specifically used to select the target preset field from the multiple preset fields, calculate the validation field according to the target validation rule, and concatenate the target preset field and the validation field to obtain the destination address of the target business message.
[0061] In another possible design, the client is configured with target verification rules and multiple access addresses of the target service, and the acquisition unit is specifically used to select the destination address of the target service message from the multiple access addresses, and calculate the verification field according to the target verification rules.
[0062] In another possible design, the acquisition unit is specifically used to use the preset algorithm indicated by the target verification rule to calculate the calculation factor indicated by the target verification rule to obtain the verification field. The preset algorithm is an encryption algorithm or a hash algorithm. The calculation factor includes at least one of the following: the service identifier ID of the target service, the operator of the network to which the client belongs, the service level of the client, the credibility of the client, the credibility of the gateway of the client, the credibility of the area where the client is located, the Internet Protocol IP address of the client, the area where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates the service message, and the effective time of the target verification rule.
[0063] In another possible design, the calculation factors include a service level factor and a security verification factor. Among them, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes at least one of the following: the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a service message, and the effective time of the verification rule. The above preset algorithm is used to calculate the security verification factor to obtain a security verification field in the target verification field for verifying security.
[0064] In another possible design, the sending unit is further used to send an address request, the address request is used to request to obtain the destination address of the target service message. The obtaining unit is specifically used to receive the destination address of the target service message, the destination address carries a verification field corresponding to the destination address.
[0065] In another possible design, when the destination address of the target service message is an IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes a verification field of the target service message. Alternatively, when the destination address of the target service message is an IPv4 address, the option field of the target service message includes a verification field of the target service message.
[0066] It can be understood that the beneficial effects achieved by the message transmission device provided by the fourth aspect and any possible design method in the fourth aspect can be referred to the technical effects of the corresponding solutions provided by the second aspect and any possible design method in the second aspect, and will not be repeated here.
[0067] In a fifth aspect, the present application provides a computing device, comprising: a memory, a communication interface and one or more processors, the one or more processors receiving or sending data through the communication interface, the one or more processors being configured to read program instructions stored in the memory to execute a method as provided in the first aspect and any possible design of the first aspect, or to execute a method as provided in the second aspect and any possible design of the second aspect.
[0068] In a sixth aspect, the present application provides a computing device cluster, the computing device cluster comprising at least one computing device, each computing device comprising a processor and a memory. The processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster performs the method provided in the first aspect and any possible design of the first aspect, or performs the method provided in the second aspect and any possible design of the second aspect.
[0069] In a seventh aspect, the present application provides a message transmission system, which includes a security module on a server side and a client side. The security module on the server side is used to execute the method provided in the first aspect and any possible design method in the first aspect. The client side is used to execute the method provided in the second aspect and any possible design method in the second aspect. In a specific design, the security module on the server side is implemented as the message transmission device provided in the third aspect or the fifth aspect, and the client side is implemented as the message transmission device provided in the fourth aspect or the fifth aspect.
[0070] In an eighth aspect, the present application provides a chip, the chip comprising a processor, when the processor runs a program instruction or code, the chip comprising the processor or the device comprising the chip executes the method provided in the first aspect and any possible design method in the first aspect, or executes the method provided in the second aspect and any possible design method in the second aspect. Exemplarily, the chip also includes: an input interface, an output interface and a memory. Among them, the input interface, output interface, processor and memory of the chip are connected through the internal connection path of the chip, the memory in the chip is used to store the program instructions or code run by the processor, and the input interface and output interface of the chip are used for the connection and communication between the chip and other chips or devices.
[0071] In a ninth aspect, the present application provides a computer-readable storage medium, which is a non-volatile computer-readable storage medium, and the computer-readable storage medium includes computer program instructions. When the computer program instructions are executed by a computing device or a processor, the computing device or the processor executes the method provided in the first aspect and any possible design method in the first aspect, or executes the method provided in the second aspect and any possible design method in the second aspect.
[0072] In the tenth aspect, the present application provides a computer program product comprising instructions, which, when executed by a processor, causes a computing device or a processor to execute a method as provided in the first aspect and any possible design method in the first aspect, or to execute a method as provided in the second aspect and any possible design method in the second aspect.
[0073] It can be understood that any of the message transmission devices, systems, computing devices, computing device clusters, computer-readable storage media, computer program products or chips provided above can be applied to the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods and will not be repeated here.
[0074] In this application, the names of the above-mentioned message transmission device, message transmission system, etc. do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear with other names. As long as the functions of each device or functional module are similar to those of this application, they all fall within the protection scope of this application. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] Figure 1 It is a schematic diagram of an implementation environment of the method provided in the embodiment of the present application;
[0076] Figure 2 It is a schematic diagram of another implementation environment of the method provided in the embodiment of the present application;
[0077] Figure 3 It is a schematic diagram of another implementation environment of the method provided in the embodiment of the present application;
[0078] Figure 4 It is a schematic diagram of another implementation environment of the method provided in the embodiment of the present application;
[0079] Figure 5 is a schematic diagram of determining a first access address provided by an embodiment of the present application;
[0080] Figure 6 is a schematic diagram of determining a second access address provided in an embodiment of the present application;
[0081] Figure 7 This is a schematic diagram of a process for obtaining a target service access address provided by an embodiment of the present application;
[0082] Figure 8 It is a flowchart of a message transmission method provided in an embodiment of the present application;
[0083] Fig. 9 It is a flowchart of another message transmission method provided in an embodiment of the present application;
[0084] Fig.10 It is a flowchart of another message transmission method provided in an embodiment of the present application;
[0085] Fig.11 This is a process diagram of another message transmission method provided in an embodiment of the present application;
[0086] Fig.12 It is a schematic diagram of an implementation framework of an application message transmission method provided in an embodiment of the present application;
[0087] Fig.13 is a schematic diagram of an application example provided in an embodiment of the present application;
[0088] Fig.14 is a schematic diagram of another application example provided in an embodiment of the present application;
[0089] Fig.15 is a schematic diagram of another application example provided by an embodiment of the present application;
[0090] Fig.16 is a schematic diagram of another application example provided by an embodiment of the present application;
[0091] Fig.17 is a schematic diagram of another application example provided by an embodiment of the present application;
[0092] Fig.18 is a schematic diagram of another application example provided by an embodiment of the present application;
[0093] Fig.19 is a schematic diagram of another application example provided by an embodiment of the present application;
[0094] Fig. 20 is a schematic diagram of another application example provided by an embodiment of the present application;
[0095] Fig.21 is a schematic diagram of another application example provided by an embodiment of the present application;
[0096] Fig. 22 It is a schematic diagram of the implementation form of the execution subject provided in the embodiment of the present application;
[0097] Fig.23 It is a structural schematic diagram of a message transmission device provided in an embodiment of the present application;
[0098] Fig.24 It is a structural schematic diagram of another message transmission device provided in an embodiment of the present application;
[0099] Fig.25 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application;
[0100] Fig.26 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0101] Fig. 27 This is a network connection diagram of one or more computing devices in a computing device cluster provided in an embodiment of the present application. DETAILED DESCRIPTION
[0102] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0103] To facilitate understanding, the technology and background involved in the embodiments of the present application are first explained below.
[0104] 1) Zero Trust
[0105] Zero trust is a security model used to protect organizations. Its concept is that no person or device is trusted by default, even if the person or device is already within the organization's network. Therefore, for a network that applies the zero trust security model (i.e., a zero trust network (ZTN)), strict authentication and authorization are enforced throughout the ZTN network (not just on the trusted boundary) to eliminate implicit trust. Implicit trust means that messages with certain characteristics are verified by default. In other words, each request to access ZTN resources is considered to come from an untrusted network, so ZTN will check each request to access resources to authenticate and verify the request.
[0106] 2) Zombie Attack
[0107] A zombie attack is when an attacker spreads a "zombie program" through various channels and infects the user's host with the "zombie program", so that the attacker can control these infected hosts to carry out network attacks.
[0108] Among them, a zombie program refers to a malicious process that takes up some system resources but does not display any tasks or windows. Zombies are usually caused by viruses, worms or other types of malware, all of which have specific functions and characteristics. Zombies run on the user's computer and may modify system files and change system configurations. In essence, zombie programs may destroy system functions or affect system performance, sometimes damage hardware, make the computer unusable, or may threaten the user's data security (such as leaking confidential information). Usually, zombie programs cannot be installed on computers by themselves. Zombies are usually malicious codes hidden in other applications, such as mouse hover windows, network (web) browsers, and email attachments. Attackers can use zombie programs to send malicious programs to computers and do other things that cannot be controlled.
[0109] 3) Distributed denial of service (DDOS) attacks
[0110] A DDOS attack generally refers to a network attack that uses reasonable service requests to occupy too many service resources, thereby preventing legitimate users from receiving service responses.
[0111] Currently common but difficult to defend DDOS attacks include but are not limited to the following: A. Elephant flow attack: refers to an attack that conducts a large amount of continuous access to the target service through a network connection. Since the elephant flow attack focuses on one network connection, it is difficult to divert the attack to multiple central processing units (CPUs) for prevention; B. Real source attack: refers to an attack using many real hosts as attack sources, so the attack behavior of these hosts is difficult to distinguish from that of normal and legitimate users; C. Segment sweep attack: between the elephant flow attack and the real source attack, the segment sweep attack performs a scanning attack on continuous Internet protocol (IP) address segments, so the traffic of the segment sweep attack is dispersed on multiple target IP addresses. The traffic attacking each target IP address is not very large, but the traffic attacking all target IP addresses added together is very large. It is generally difficult to discover the attack pattern and prevent it.
[0112] 4) Network address translation (NAT)
[0113] NAT is a technology used to use private addresses in a local network and switch to global IP addresses when connecting to the Internet.
[0114] For example, when a host in a local network sends a message to the Internet, the local network uses NAT on a border device located at the network boundary to convert the source address of the message into the global IP address of the local network in the Internet, and the source address before NAT in the message is the private address of the host in the local network. For another example, when a message from the Internet is sent to a host in a local network, the local network uses NAT on a border device located at the network boundary to convert the destination address of the message into the private address of the host in the local network, and the destination address before NAT in the message is the global IP address of the local network in the Internet.
[0115] 5) Closed network
[0116] A closed network refers to a network in which the connections between nodes are relatively closed, that is, the connections between nodes are relatively independent and restricted. In a closed network, the connection relationship between nodes is usually determined in advance, and communication is often only allowed between specific nodes. This network structure is common in some private networks and local area networks, such as internal networks within enterprises, home networks, etc.
[0117] 6), high defense
[0118] High Defense is a protection measure against network attacks. High Defense can help organizations implement efficient and effective security protection by using firewalls, intrusion detection systems (IDS), vulnerability scanning and other security technologies. High Defense can block technical attacks like this, intercept suspicious network traffic, and detect and respond to unknown threats through a multi-layered threat defense system.
[0119] 7) IP reputation
[0120] The degree of IP trust is measured based on the threat posed to the network by the endpoint corresponding to the IP address, so that the IP address can be identified or classified. Usually, the degree of IP trust is expressed through a scoring evaluation mechanism, which is also called IP reputation.
[0121] Currently, network systems that provide services to the outside world allocate one or a group of fixed IP addresses to each service. These IP addresses are directly exposed on the Internet and face the following risks: (1) There are no restrictions on clients accessing the service, and clients from all regions can access the service. Currently, only corresponding regional filtering policies can be generated to filter attack packets after a malicious attack occurs; (2) The IP addresses of the nodes providing services are exposed on the Internet, and the IP addresses are bound to the services, so they are easily attacked by malicious attacks; (3) In the related technology, there is no authentication capability for business packets accessing the services, making it difficult to prevent zombie attacks; (4) The whitelist routing in the related technology has a certain attack prevention capability, but it is powerless against network attacks launched by whitelist users who have become zombie hosts after being infected with Trojan programs.
[0122] In some related technologies, cloud services (such as content delivery network (CDN), high-defense, cloud firewalls, etc.) can alleviate certain network attack threats, but cloud service itself is also a kind of network service, so cloud service also faces the same network attack threats, and therefore the protection capabilities and effects of cloud services are also facing challenges.
[0123] In other related technologies, the protection system of the server treats all clients accessing the services provided by the server equally, so the protection system is prone to mistakenly kill business messages due to misidentification when performing algorithm recognition attacks. For example, when a client accesses a certain service, due to business needs, the client initiates 500 business messages per second. If the algorithm designed by the protection system to prevent DDOS attacks is to limit the number of messages transmitted through the same network connection to 200 per second, at this time, the protection system will block the business messages normally transmitted by the client through the network connection between itself and the server.
[0124] Based on this, an embodiment of the present application provides a message transmission method, which includes: pre-configuring an access address for accessing a target service for a client, and customizing a verification field for the client, so that the client can initiate a business message for accessing the target service based on the access address, and the business message includes the aforementioned verification field; the security module of the server verifies the verification field carried by the business message for accessing the target service, and when the verification is successful, determines that the destination address of the business message is the access address configured for accessing the target service for the client that initiates the business message, and then the security module forwards the business message to the server. Through this method, the destination address of the business message in the forwarding process can be verified according to the verification field carried by the business message, and it can ensure that the business message is forwarded normally when the destination address of the business message is the access address configured for accessing the target service for the client that initiates the business message, that is, the method can ensure that only the business message with the destination address verified can access the target service, so that the traffic from the attack source can be prevented from accessing the target service, thereby ensuring the security of the business network where the target service is deployed.
[0125] refer to Figure 1 , Figure 1 A schematic diagram of an implementation environment of the method provided in the embodiment of the present application is shown. Figure 1 As shown, the implementation environment is implemented as a message transmission system including a client and a server. Among them, the client transmits a business message to the business network where the server is located through a transmission link, and the business message is used to access the service provided by the server through the gateway of the business network. For example, the client 110 located in region 1 accesses the service provided by the server through a transmission link through gateway R1, the client 120 located in region 2 accesses the service provided by the server through a transmission link through gateway R2, and the client 130 located in region 3 accesses the service provided by the server through a transmission link through gateway R3. Among them, the transmission link can adopt wireless communication or wired communication, which is not limited. By applying the method provided in the embodiment of the present application in the system, it can be ensured that only the business message that passes the destination address verification can access the service provided by the server, so that the traffic from the attack source can be prevented from accessing the service provided by the server, thereby ensuring the security of the business network where the server is deployed.
[0126] Exemplarily, the service end includes but is not limited to an application server that provides any one or more services and is deployed on the cloud or offline, without limitation. The services provided by the application server include but are not limited to game services, e-commerce services, media services, social services, etc. In one example, the service provided by the application server can be run on at least one server in at least one cloud data center located in one of the multiple regions, without limitation.
[0127] As another example, the client serves as the initiator of the service, including but not limited to a terminal device that provides client functions, such as a mobile phone, a laptop computer, a tablet, a desktop computer, a car device or other smart devices.
[0128] Optional, Figure 1 The network to which the client belongs and the network to which the server belongs can be the same or different. Figure 1 When the network to which the client belongs and the network to which the server belongs may be the same, it indicates that the network to which the client and server belong is a closed network.
[0129] refer to Figure 2 , Figure 2 A schematic diagram showing another implementation environment of the method provided in the embodiment of the present application is shown. Figure 1 ,like Figure 2 As shown, the implementation environment also includes a network controller of the business network, and the network controller is used to manage and / or control the business network. For example, the network controller is the network manager of the business network, or a traditional business centralized management platform, but is not limited thereto. Optionally, the network controller is an independent node device in the business network, or the function of the network controller is assumed by a server or forwarding node in the business network, but is not limited thereto. Based on this, each client that needs to access the services provided by the server can obtain from the network controller an access address for accessing the services provided by the server, as well as verification fields customized for each client or related information for configuring the verification fields. Among them, the detailed description of the access address for accessing the services provided by the server and the verification fields customized for each client obtained by the client from the network controller, all refer to the relevant descriptions of steps 101 to 102 below, and will not be repeated here.
[0130] In addition, in the process of the network controller configuring an access address (referred to as access address 110) for accessing the service provided by the server and a verification field customized for client 110 (referred to as verification field 110) for any client (such as client 110), the network controller also sends the access address 110 and verification field 110 (or related information for configuring the verification field 110) to the gateway (such as R1) in the business network used to forward the business message of client 110 to the server. For a detailed description, please refer to the relevant description of step 103 below and will not be repeated here.
[0131] refer to Figure 3 , Figure 3 A schematic diagram of another implementation environment of the method provided in the embodiment of the present application is shown. Figure 1 ,like Figure 3As shown, the implementation environment also includes a domain name system (DNS). In this way, each client that needs to access the service provided by the server can obtain the access address for accessing the service provided by the server from the DNS, as well as the verification field customized for each client or the related information for configuring the verification field. Among them, the detailed description of the client obtaining the access address for accessing the service provided by the server from the DNS and the verification field customized for each client, all refer to the description of the "third possible situation" below, and will not be repeated here.
[0132] In addition, in the process of DNS configuring an access address (access address 110) for accessing the service provided by the server and a verification field customized for the client 110 (referred to as verification field 110) for any client (such as client 110), the DNS also sends the access address 110 and the verification field 110 (or related information for configuring the verification field 110) to the gateway (such as R1) in the business network used to forward the business message of the client 110 to the server.
[0133] refer to Figure 4 , Figure 4 A schematic diagram of another implementation environment of the method provided in the embodiment of the present application is shown. Figure 1 ,like Figure 4 As shown, the implementation environment also includes a network controller and a DNS. In this way, each client that needs to access the services provided by the server can obtain the access address for accessing the services provided by the server from the DNS, as well as the verification field customized for each client or the related information for configuring the verification field. In addition, when receiving a business message, the gateway of the business network can obtain the verification rules corresponding to the preset fields in the destination address from the network controller according to the destination address of the business message, so as to verify the verification fields carried by the business message according to the obtained verification rules, thereby realizing the verification of the destination address of the business message. For detailed descriptions, please refer to the relevant descriptions of step 204 in the method below, which will not be repeated here. In addition, the detailed descriptions of the access address for accessing the services provided by the server and the verification fields customized for each client obtained by the client from the DNS are all referred to the description of the "third possible situation" below, which will not be repeated here.
[0134] It should be understood that the above content is an illustrative description of the implementation environment of the method provided in the embodiment of the present application, and does not constitute a limitation on the implementation environment of the method. A person of ordinary skill in the art can know that as business needs change, the implementation environment can be adjusted according to application requirements, and the embodiments of the present application do not list them one by one.
[0135] The present application also provides a message transmission device, which can be implemented by hardware and / or software. For example, the device can be implemented as independent software, independent hardware, a combination of software and hardware, an embedded chip, an embedded software development kit (SDK), etc.
[0136] The above device can be applied to the security module of the server or the client accessing the service provided by the server, so that the security module of the server and the client execute the corresponding steps of the method described below. Figure 1 , Figure 2 , Figure 3 or Figure 4 The server is shown, and the client can be Figure 1 , Figure 2 , Figure 3 or Figure 4 Any client shown.
[0137] When the above-mentioned device is applied to the security module of the server, the above-mentioned device can be implemented as a security module deployed in the server or a functional module in the security module. Exemplarily, the security module is a firewall installed on the server. In this case, the above-mentioned device can be implemented as a functional module of the firewall. Alternatively, the above-mentioned device can also be implemented as a forwarding node that forwards business messages from the client to the server or a functional module in the forwarding node, which is not limited to this. Among them, the forwarding node can be any node / device with message forwarding processing capabilities. As an example, the forwarding node is a network device such as a router, switch, gateway, etc. on the communication link from the client to the server, but is not limited to this.
[0138] When the above device is applied to a client accessing services provided by a server, the device may be a terminal device for implementing client functions, or a functional module in the terminal device, without limitation. The terminal device includes but is not limited to a mobile phone, a laptop computer, a tablet, a desktop computer, a vehicle-mounted device or other smart device.
[0139] The following describes the implementation process of the message transmission method provided in the embodiment of the present application.
[0140] First, before accessing the service provided by the server (such as the target service), the client needs to obtain the access address of the target service and the verification field customized for itself. In this way, the client can use the obtained access address as the destination address to send a business message for accessing the target service, and the business message carries the verification field customized for the client.
[0141] Among them, the verification field customized for the client can be calculated based on any verification rule. In an embodiment of the present application, the verification rule indicates that the calculation factor is calculated using a preset algorithm to obtain the corresponding verification field. The embodiment of the present application does not specifically limit the preset algorithm. For example, the preset algorithm is any hash algorithm or any encryption algorithm, etc., but is not limited to this. The calculation factor includes relevant information of the target service and / or relevant information of the client requesting to obtain the target service access address.
[0142] Exemplarily, the calculation factors include, but are not limited to, at least one of the following: a service identifier (ID) of the target service, the operator of the network to which the client belongs, the service level of the client, the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a business message including a verification field, the time when the client obtains the verification rule, the effective duration of the verification rule, the effective duration or random value of the verification field calculated based on the verification rule, etc.
[0143] Among them, the service ID of the target service is used to uniquely identify the target service. The service level of the client can be the quality of service (QoS) level required by the client for the target service, or the IP reputation of the client, etc., which is not limited to this. The reputation of the client can be understood as the IP reputation of the client, the reputation of the gateway of the client can be understood as the IP reputation of the gateway of the client, and the reputation of the region where the client is located can be understood as the average IP reputation of all IP addresses in the geographical area where the client is located, etc., which is not limited to this. The region where the client is located refers to the geographical area where the client is located. The device type of the client includes but is not limited to a mobile terminal or a computing terminal, a mobile terminal is such as a mobile phone, and a computing terminal is such as a laptop computer, a desktop computer, etc., and is not limited to this. The gateway of the client refers to the access gateway that connects the client to the network, and the type of the gateway of the client includes but is not limited to any one of a home gateway, an enterprise gateway, a gateway that supports NAT, a proxy node or a base station. The detailed process of collecting the IP reputation of each endpoint is not described in detail in the embodiment of the present application.
[0144] It should be understood that when the calculation factor contains different information, the verification field obtained after calculating the calculation factor using a preset algorithm can distinguish the service messages initiated by the client at different granularities. In one example, when the calculation factor includes at least the relevant information of the target service, the verification field calculated based on the calculation factor can distinguish the service messages initiated by the client at the granularity of the service. In other words, the service messages of the same client accessing different services can be distinguished by the verification fields carried by each service message. In another example, when the calculation factor includes at least the service level of the client, the verification field calculated based on the calculation factor can distinguish the service messages initiated by the client at the granularity of the service level of the client. In other words, the service messages of clients with different service levels accessing the same service can be distinguished by the verification fields carried by each service message. In another example, when the calculation factor includes at least the attribute information of the client (such as the client device type or the client device ID), the verification field calculated based on the calculation factor can distinguish the messages initiated by the client at the granularity of the client. In other words, the service messages of different clients accessing the same service can be distinguished by the verification fields carried by the service messages. In another example, when the calculation factor includes at least the client's regional information (such as the region where the client is located), the verification field calculated based on the calculation factor can distinguish the service messages initiated by clients in different regions at the granularity of region. In other words, the service messages of clients in different regions accessing the same service can be distinguished by the verification field carried by the service message. It should also be understood that the calculation factors in the aforementioned examples can also be used in combination. In this case, the verification field calculated based on the calculation factor can distinguish the service messages initiated by clients in different regions at the granularity of the service, the service level of the client, the client, and the region where the client is located. No more details.
[0145] In addition, when the preset algorithm is a hash algorithm or an encryption algorithm, encryption of the calculation factor can be achieved. Therefore, the business message includes a verification field obtained after hashing or encrypting the calculation factor, and the verification field is verified during the transmission of the business message, which can achieve security verification of the destination address of the business message, so that the business message can be guaranteed to be a legal and secure business message, thereby ensuring the security of the business network deployed with the service accessed by the business message. Among them, the hash algorithm, also known as the hash algorithm or the message digest algorithm, is a basic technology used for information storage and query. It is a file construction method based on the hash function, which can realize fast random access to records. The hash algorithm can map a given arbitrary long keyword to a fixed-length hash value, which is generally used for authentication, certification, encryption, indexing, etc.
[0146] Optionally, in an embodiment of the present application, hash calculation or encryption calculation may be performed on only part of the above-mentioned calculation factors, while the other part of the calculation factors are not processed, or only simple addition processing / merging processing is performed. For example, when the other part of the calculation factors only includes one calculation factor, no calculation processing is performed on the other part of the calculation factors. For another example, when the other part of the calculation factors includes at least two calculation factors, the values of the at least two calculation factors are added, or the values of the at least two calculation factors are spliced and merged. Based on this, the above-mentioned calculation factors can be divided into service level factors and security verification factors. Among them, the service level factor includes relevant information of the target service. Exemplarily, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes relevant information of the client requesting to obtain the access address of the target service. Exemplarily, the security verification factor includes at least one of the following: the credibility of the client, the credibility of the gateway of the client, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a business message including a verification field, the time when the client obtains the verification rule, the effective duration of the verification rule, the effective duration or random value of the verification field calculated based on the verification rule, etc. In this case, the above-mentioned preset algorithm includes a first algorithm and a second algorithm. Among them, the first algorithm is an addition / merging algorithm, and is used to calculate the business level factor to obtain a business level field in the verification field for indicating the business level. The second algorithm is an encryption algorithm or a hash algorithm, and is used to calculate the security verification factor to obtain a security verification field in the verification field for verifying security.
[0147] In one possible implementation, the access address of the target service obtained by the client is an Internet Protocol version 4 (IPv4) address. At this time, optionally, in the option field / extension field of the service message initiated by the client with the access address as the destination address, a verification field customized for the client is carried. The option field of the service message is, for example, the option field in the IP header of the service message, which is not limited to this. The extension field of the service message is, for example, a field specially extended to carry the verification field, which is not limited to this.
[0148] In another possible implementation, the access address of the target service obtained by the client is an Internet Protocol version 6 (IPv6) address. At this time, the access address may include a verification field customized for the client, or, in the option field / extension field of the service message initiated by the client with the access address as the destination address, a verification field customized for the client is carried. Among them, the option field of the service message is, for example, an option field in the IP header of the service message, which is not limited to this. It should be understood that when the access address of the target service is an IPv6 address, based on the transformation of the access address with a length of 128 bits (bit), the verification field customized for the client can be carried in the access address, so the access address can also be understood as an address customized for the client to access the target service. Since most of the addresses between discrete addresses are idle in the huge address space of IPv6, when each client that needs to access the target service is configured with an access address exclusive to each client, it can effectively reduce the attack source from using the client to access the target service, thereby ensuring the security of the service network where the target service is deployed.
[0149] Taking the case where the access address of the target service is an IPv6 address and the access address includes a verification field customized for the client as an example, for any access address configured for the target service, the length of the access address is 128 bits, and is composed of a preset field and a verification field. Among them, the embodiment of the present application configures at least one preset field for the target service. In some examples, the preset field is composed of the network prefix of the business network where the server providing the target service is located and the real subnet address of the server in the business network (such as a subnet address with a length of 8 bits, 16 bits or 32 bits), and this is not limited. Optionally, different preset fields configured for the target service can be used to configure the access address of the target service for clients located in different regions. Among them, different preset fields refer to different combinations of network prefixes and real subnet addresses.
[0150] Exemplarily, taking the access address of the target service as the first access address as an example, the first access address is composed of a first preset field configured for the target service and a first verification field calculated according to the first verification rule. Figure 5 , Figure 5 FIG. 4 shows a schematic diagram of determining a first access address. Figure 5As shown, when the calculation factor is calculated using a preset algorithm to obtain a first verification field with a length of 32 bits, and the first preset field configured for the target service includes a business network where the target service is deployed, a network prefix with a length of 64 bits, and a real subnet address with a length of 32 bits of the service end providing the target service in the business network, then the network prefix in the first preset field, the first verification field, and the real subnet address in the first preset field are concatenated to obtain the first access address. In an example, Figure 5 The field carrying the actual subnet address may also be located between the network prefix and the first verification field, which is not limited.
[0151] As another example, taking the access address of the target service as the second access address, the second access address is composed of a second preset field configured for the target service and a second verification field calculated according to a second verification rule. Figure 6 , Figure 6 FIG. 4 shows a schematic diagram of determining a second access address. Figure 6 As shown, when the above-mentioned first algorithm is used to calculate the service level factor, a service level field with a length of 8 bits in the second verification field is obtained, and the above-mentioned second algorithm is used to calculate the security verification factor, a security verification field with a length of 24 bits in the second verification field is obtained, and the second preset field configured for the target service includes a service network in which the target service is deployed, and a network prefix with a length of 64 bits, and a real subnet address with a length of 32 bits of the service end providing the target service in the service network, then the network prefix in the second preset field, the service level field in the second verification field, the security verification field in the second verification field, and the real subnet address in the second preset field are concatenated to obtain the second access address. It can be understood that the embodiment of the present application does not specifically limit the order of the network prefix field, the service level field, the security verification field, and the real subnet address field. For example, Figure 6 The real subnet address field shown may also be located between the network prefix field and the second verification field. Figure 6 The real subnet address field shown is located between the service level field and the security verification field.
[0152] It is understandable that, when the access address of the target service is an IPv6 address and the access address includes a verification field customized for the client, when the content of the calculation factor is different, it means that the access address containing the verification field calculated based on the calculation factor can be used to distinguish the service messages initiated by the client at different granularities, and no further elaboration is given. Furthermore, when the access address containing the verification field distinguishes different service messages at the service granularity, the purpose of isolating different services by access address can be achieved, thereby avoiding the situation where a service deployed in the service network is attacked and affects other services deployed in the service network.
[0153] That is to say, the embodiment of the present application applies the relevant information of the service (such as the target service) to construct multiple IPv6 access addresses of the target service (recorded as the IPv6 address pool of the target service), so as to achieve isolation of different services through the IPv6 address pools of different services, thereby conveniently achieving differentiated processing of services, and being able to alleviate the risk of harm to other services caused by attacks on a single service. In addition, the embodiment of the present application puts the hash value of the service-related information or the client-related information into the constructed IPv6 access address, so as to enhance the security protection capability of the service end.
[0154] In addition, by applying the reputation of the client and / or client gateway and / or the region where the client is located when constructing the IPv6 access address of the service, it is possible to configure the IPv6 access address of the service for clients requesting access to the service at granularities such as different clients, client gateways, and regions to which the clients belong. In this way, different clients, clients under different gateways, and clients in different regions can obtain different IPv6 access addresses for the same service, thereby improving the network isolation capability and alleviating the scale of zombie attacks.
[0155] For ease of description, the following embodiments of the present application are described by taking the case where the access address of the target service is an IPv6 address and the access address includes a verification field customized for the client as an example. Figure 1 , Figure 2 , Figure 3 or Figure 4 The implementation environment shown introduces the process of the client obtaining the access address of the target service (such as the first address) and the verification field customized for itself (referred to as the first verification field).
[0156] The first possible situation, combined with Figure 1In the implementation environment shown, the client and the service gateway are both preset with at least one combination, and the at least one combination preset by the client is the same as the at least one combination preset by the server, and in the at least one combination, each combination includes one of the multiple verification rules and one of the multiple preset fields configured for the target service. Exemplarily, the at least one combination configured in the client and the service gateway may be pre-configured manually or pre-imported from a third device (such as a storage device), which is not limited to this. The detailed description of the preset fields and the verification rules can be referred to above and will not be repeated here. It should be understood that since the preset fields include the network prefix of the business network and the subnet address of the server providing the target service in the business network, the preset fields in the aforementioned at least one combination can be regarded as an address pool configured for the business network.
[0157] In one example, when the client needs to access the target service, the client selects a preset field as the first preset field from the multiple preset fields configured for the target service according to the first strategy. Then, the client selects a combination containing the first preset field as the first combination from at least one preset combination, and determines the verification rule in the first combination as the first verification rule. In another example, when the client needs to access the target service, the client selects a combination as the first combination from the multiple preset combinations according to the second strategy, determines the preset field in the first combination as the first preset field, and determines the verification rule in the first combination as the first verification rule corresponding to the first preset field. Furthermore, the client determines the first verification field according to the first verification rule, and concatenates the first preset field and the first verification field to obtain the first address. Subsequently, the client can send a service message with the first address as the destination address. Optionally, the client can also set a valid duration for the determined first address. In this way, the client can send service messages using the first address as the destination address within the valid period, and after the valid period ends, reselect a combination of preset fields and verification rules, such as the second combination, and re-determine the access address of the target service, such as the second address.
[0158] Among them, the embodiments of the present application do not specifically limit the first strategy and the second strategy. For example, the first strategy is a polling strategy. For another example, the first strategy includes: selecting preset field 1 in time period 1, selecting preset field 2 in time period 2, etc. For another example, the first strategy is a strategy for selecting different preset fields according to the region where the client is located, such as selecting preset field 1 when the region where the client is located is region 1, and selecting preset field 2 when the region where the client is located is region 2. Not limited to this. The second strategy can refer to the description of the first strategy, and the second strategy and the first strategy can be the same or different, and there is no limitation on this. In addition, the detailed description of how the client finally obtains the first address according to the first preset field and the first verification rule can be referred to. Figure 5Get the first access address or Figure 6 The description of obtaining the second access address is omitted here.
[0159] It should be understood that in the first possible scenario, since both the client and the service gateway are pre-installed with the above-mentioned combination for determining the target service access address, neither the client nor the service gateway needs to interact with other devices to obtain the access address of the target service. Therefore, based on the solution provided in this embodiment, since the service gateway needs to verify the destination address of the business message, that is, the service gateway and the back-end server are authorized to access, when the client in the implementation environment accesses the target service deployed in the business network, the business network can be regarded as a completely hidden trusted network, that is, this embodiment can create a completely hidden trusted business network.
[0160] The second possible situation, combined with Figure 2 In the implementation environment shown in FIG. 1 , for a network controller of a business network in which a target service is deployed, when the network controller has multiple validation rules preset in it and multiple preset fields configured for the target service, refer to Figure 7 , Figure 7 A schematic diagram of a process for obtaining a target service access address provided by an embodiment of the present application is shown. For the sake of simplicity, the following is an example of a client accessing a certain service (referred to as the target service) and a security module of a server providing the target service executing the corresponding steps of the method described in the embodiment of the present application. The process includes the following steps.
[0161] Step 101: The client sends an address acquisition request to the network controller.
[0162] When the client needs to access the target service, it can send an address acquisition request to the network controller of the business network where the target service is deployed. The request carries the service ID of the target service, and the request is used to request the access address of the target service (recorded as the first address). It should be understood that in this case, the access address of the network controller is preset in the client. Alternatively, the client can easily address the access address of the network controller exposed to the network, and the access address is, for example, a domain name address or an IP address, which is not limited to this. The process of the client addressing the access address of the network controller in the embodiment of the present application is not described in detail.
[0163] Exemplarily, the client may send an address acquisition request to the network controller through its own communication interface.
[0164] Step 102: The network controller determines a first combination in response to the address acquisition request, and returns the first combination to the client, or returns a first address determined based on the first combination to the client.
[0165] The first combination includes a first preset field and a first verification rule, and the first address is an access address of the target service determined based on the first preset field and the first verification rule in the first combination. The detailed description of the preset field, the verification rule and the access address can all be referred to above and will not be repeated here.
[0166] Optionally, after receiving the address acquisition request, the network controller performs a security check on the address acquisition request. The embodiment of the present application does not limit the specific implementation method of the network controller performing a security check on the address acquisition request. For example, the network controller can detect whether the source IP sending the address acquisition request is credible based on a preset IP reputation library. For another example, the network controller parses the address acquisition request sent by the client to determine whether the instance used to send the address acquisition request in the client is a real instance. For another example, the network controller determines whether the address acquisition request sent by the client is secure through the transport layer security (TLS). Not limited to this.
[0167] In one example, in response to an address acquisition request, the network controller first searches for multiple preset fields and multiple verification rules corresponding to the target service based on the service ID of the target service carried in the request. Next, the network controller selects a preset field from the multiple preset fields found as the first preset field according to the first strategy, and selects a verification field from the multiple verification rules found as the first verification rule according to the third strategy. Then, the network controller returns a first combination including the selected first preset field and the first verification rule to the client. Alternatively, the network controller determines the first address based on the selected first preset field and the first verification rule. For detailed description, please refer to Figure 5 or Figure 6 The description of is omitted. Then, the network controller returns the determined first address to the client. The third strategy is not specifically limited in the embodiment of the present application. The third strategy may be the same as the first strategy and the second strategy, or may be different, and there is no limitation on this.
[0168] In another example, when multiple verification rules preset in the network controller and multiple preset fields configured for the target service have been configured in the network controller in different combinations, in other words, multiple combinations are pre-configured in the network controller, and each combination includes one of the aforementioned multiple verification rules and one of the aforementioned preset fields configured for the target service. In this case, the network controller responds to the address acquisition request, first finds the pre-configured multiple combinations corresponding to the target service according to the ID of the target service carried by the request, and selects a combination from the multiple combinations as the first combination according to the second strategy. Alternatively, the network controller selects a preset field as the first preset field from the preset multiple preset fields according to the first strategy, and then selects the combination containing the first preset field as the first combination from the preset multiple combinations. Then, the network controller returns the selected first combination to the client. Alternatively, the network controller determines the first address based on the first preset field and the first verification rule in the selected first combination. For detailed description, please refer to Figure 5 or Figure 6 Then, the network controller returns the determined first address to the client.
[0169] Exemplarily, the network controller returns the first combination or the first destination address to the client through its own communication interface.
[0170] In response, after receiving the first combination, the client sets a valid duration or a valid period for the first combination. Alternatively, after receiving the first combination, the client determines the first address based on the first preset field and the first verification rule in the first combination, and sets a valid duration or a valid period for the determined first address. Alternatively, after receiving the first address, the client sets a valid duration or a valid period for the first address. The valid duration refers to a duration starting from any time and having a preset length. The valid period refers to a period starting from a specified time and having a preset duration. The specific value of the preset duration is not limited in the embodiments of the present application.
[0171] Optionally, the validity period set by the client for the first combination or the first address may take effect immediately after being set. Optionally, the validity period set by the client for the first combination takes effect when the client first uses the first address determined according to the first combination, such as the validity period set by the client for the first combination takes effect when the client first initiates a service message with the first address determined according to the first combination as the destination address. Optionally, the validity period set by the client for the first destination address takes effect when the client first uses the aforementioned first address, such as the validity period set by the client for the first address takes effect when the client first initiates a service message with the destination address being the first address.
[0172] In one example, the valid duration or valid period set by the client for the first combination or the first address can be implemented by a timer with a preset duration.
[0173] Step 103: The network controller sends a first combination or a first address to a security module at the server end.
[0174] Taking the example of a case where the security module of the server providing the target service is implemented by the service gateway of the business network where the target service is located, after the network controller determines the first combination or the first address in step 102, it also sends the first combination or the first address to the service gateway, so that the service gateway verifies the verification field carried in the received business message according to the first combination or the first address, thereby realizing security verification of the destination address of the business message.
[0175] Exemplarily, the network controller sends the first combination or the first address to all or part of the service gateways of the business network where the target service is located through its own communication interface.
[0176] In response, for any service gateway of the business network where the target service is located, after receiving the first combination, the service gateway sets a valid duration or valid period for the first combination. Alternatively, after receiving the first combination, the service gateway determines the first address based on the first preset field and the first verification rule in the first combination, and sets a valid duration or valid period for the determined first address. Alternatively, after receiving the first address, the service gateway sets a valid duration or valid period for the first address.
[0177] Optionally, the effective duration set by the service gateway for the first combination or the first address can take effect immediately after setting. Optionally, the effective duration set by the service gateway for the first combination takes effect when the service gateway uses the first combination for the first time, such as the effective duration set by the service gateway for the first combination takes effect when the service gateway uses the first combination for the first time to verify the destination address of the received business message. The effective duration set by the service gateway for the first address takes effect when the service gateway uses the first address for the first time, such as the effective duration set by the service gateway for the first address takes effect when the service gateway uses the first address for the first time to verify the destination address of the received business message.
[0178] It should be understood that when the service gateway sets an effective duration (or effective period) for the first combination, the client also sets an effective duration (or effective period) for the first combination, and the effective duration (or effective period) set by the service gateway for the first combination is the same as the effective duration (or effective period) set by the client for the first combination, and the effectiveness rules are the same. And, when the service gateway sets an effective duration (or effective period) for the first address, the client also sets an effective duration (or effective period) for the first address, and the effective duration (or effective period) set by the service gateway for the first address is the same as the effective duration (or effective period) set by the client for the first address, and the effectiveness rules are the same. Among them, the effectiveness rules are, for example, the immediate effectiveness or the first use effectiveness as described above, but are not limited to this.
[0179] In one example, the effective duration set by the service gateway for the first combination or the first address can be implemented by a timer with a preset duration.
[0180] In this way, when the client needs to access the target service, it can obtain the access address of the target service through steps 101 to 103, and the access address is the access address customized for the client, and the service gateway of the business network where the target service is located can also obtain the access address or the verification rules corresponding to the preset fields in the access address, and can perform security verification on the destination address of the received business message according to the access address, or perform security verification on the verification field carried in the business message according to the verification rules, thereby realizing security verification of the destination address of the business message. In this way, it can ensure that only legal and secure business messages can access the target service, thereby ensuring the network security of the business network where the target service is located.
[0181] It should be understood that in the second possible situation, since both the client and the service gateway need to obtain the access address of the target service or the combination used to determine the access address of the target service from the network controller, the client and the service gateway need to communicate and interact with the network controller to obtain the access address of the target service. Therefore, based on the solution provided by the embodiment of the present application, since the service gateway needs to verify the destination address of the service message, that is, the service gateway and the back-end server are both authorized to access, therefore, when the network controller is also set to authorized access (that is, security verification of the received message), when the client in the implementation environment accesses the target service deployed in the business network, the business network can be regarded as a trusted business network that is approximately completely hidden, that is, the embodiment of the present application can create a trusted business network that is approximately completely hidden.
[0182] The third possible situation, combined with Figure 3In the implementation environment shown, multiple verification rules and multiple preset fields configured for the target service are preset in the DNS, so when the client needs to access the target service, it obtains the first combination or the first address from the DNS through the communication link between the DNS, and when the DNS returns the first combination or the first address to the client, the DNS also sends the first combination or the first address to the service gateway. When the DNS is replaced with the above-mentioned network controller, the detailed description of the client obtaining the first combination or the first address from the DNS, and the DNS sending the first combination or the first address to the service gateway can refer to the relevant description of steps 101 to 103, which will not be repeated here.
[0183] The fourth possible situation, combined with Figure 4 In the implementation environment shown, multiple combinations are preset in the DNS and the network controller, and each combination includes one of the multiple verification rules and one of the multiple preset fields configured for the target service. Thus, the client can obtain the first combination or the first address from the DNS when it needs to access the target service. For detailed descriptions, please refer to the descriptions of steps 101 to 102, which will not be repeated here. When the service gateway receives any business message and cannot find the verification rule corresponding to the destination address locally according to the destination address in the business message, the service gateway can query the combination preset by the network controller from the network controller in real time based on the destination address, and obtain the first combination or the first verification rule in the first combination from the network controller when the first combination is queried, so as to verify the destination address of the business message. For detailed descriptions of the verification process, please refer to the relevant description in step 204 below, which will not be repeated here.
[0184] It should be understood that in the second possible situation, the third possible situation, and the fourth possible situation, the client and the service gateway need to communicate and interact with the network controller and / or DNS to obtain the access address of the target service. Therefore, based on the solution provided by the embodiment of the present application, since the service gateway needs to verify the destination address of the service message, that is, the service gateway and the back-end server are both authorized to access, therefore, when the network controller and DNS are also set to authorized access (that is, security verification of the received message), when the client in the implementation environment accesses the target service deployed in the business network, the business network can be regarded as a trusted business network that is approximately completely hidden, that is, the embodiment of the present application can create a trusted business network that is approximately completely hidden.
[0185] refer to Figure 8 , Figure 8 The following is a flow chart of a message transmission method provided by an embodiment of the present application. Optionally, the method can be applied to Figure 1 , Figure 2 , Figure 3 or Figure 4For the sake of simplicity, the following description is given by taking the corresponding steps of the method described in the embodiment of the present application performed by the security module of the client accessing the target service and the server providing the target service as an example. In one example, the target service runs on at least one server in at least one cloud data center located in one of the multiple regions, without limitation. Figure 8 As shown, the method includes the following steps.
[0186] Step 201: The client obtains the destination address of the target service message and the verification field corresponding to the destination address.
[0187] Among them, the destination address of the target business message is the access address configured for the client to access the target service, the verification field corresponding to the destination address is a verification field customized for the client, and the verification field is calculated based on the target verification rule corresponding to the destination address of the target business message, and is used to verify the destination address of the target business message.
[0188] Optionally, when the destination address of the target service message is an IPv6 address, and the destination address of the target service message includes a verification field corresponding to the destination address, the target verification pair corresponding to the destination address of the target service message refers to the verification rule used to calculate the verification field in the destination address of the target service message. In this case, when the client needs to access the target service, the destination address of the target service message including the verification field can be obtained by the method described in "the first possible case" to "the fourth possible case" above, which will not be repeated here.
[0189] Taking the first possible situation as an example, the client can first select a preset field from the preset multiple preset fields as the target preset field, and determine the combination including the target preset field as the target combination in the preset multiple combinations, and determine the verification rule in the target combination as the target verification rule. It should be understood that the client is preset with the target verification rule. Then, the client calculates the verification field corresponding to the above-mentioned destination address according to the target verification rule, and splices the target preset field and the calculated verification field to obtain the destination address of the target service message.
[0190] Optionally, when the destination address of the target service message is an IPv6 / IPv4 address and the destination address of the target service message does not include a verification field corresponding to the destination address, the following introduces how the client obtains the destination address of the target service message and the verification field corresponding to the destination address through different examples.
[0191] Example 1: Combination Figure 1In the described implementation environment, multiple access addresses and multiple verification rules configured for the target service are preset in the client, and the multiple access addresses and the multiple verification rules are configured according to different combinations. In this case, when the client needs to access the target service, it selects an access address from the multiple access addresses as the destination address of the target service message according to the fourth policy, and determines the verification rule included in the combination including the destination address of the target service message as the target verification rule corresponding to the destination address of the target service message. Furthermore, the client calculates the verification field corresponding to the above destination address according to the target verification rule. Specifically, after determining the target verification rule, the client obtains relevant information according to the calculation factors indicated by the target verification rule, so as to calculate the verification field customized for itself (i.e., the verification field corresponding to the above destination address). Among them, the detailed description of the fourth policy can refer to the description of the first policy mentioned above. The fourth policy can be the same as or different from the first policy, the second policy, and the third policy mentioned above, and will not be elaborated here. The client also sets an effective duration or an effective period for the determined destination address of the target service message and the target verification rule. For the detailed description, reference can be made to the relevant description of setting the effective duration or the effective period in step 102, and will not be elaborated here.
[0192] In this example, when the security module of the server providing the target service is implemented by the service gateway of the service network where the target service is located, the same combinations as those preset in the client are also preset in the service gateway. Each combination includes an access address of the target service and a verification rule. Optionally, when the access address and the verification rule in any combination preset in the service gateway are used to verify the destination address of the received service message, an effective duration or an effective period is also set for the combination.
[0193] Example 2. In combination with Figure 2In the implementation environment shown, the network controller of the business network where the target service is located is pre-set with multiple access addresses and multiple verification rules configured for the target service. In this case, when the client needs to access the target service, it sends an address acquisition request to the network controller, and the request carries the service ID of the target service. In response to the request, the network controller finds multiple access addresses and multiple verification rules configured for the target service represented by the service ID according to the service ID. Then, the network controller selects an access address as the destination address of the target service message from the multiple access addresses configured for the target service according to the fourth strategy, and selects a verification rule as the target verification rule corresponding to the destination address of the target service message from the multiple verification rules configured for the target service according to the third strategy. Then, the network controller returns the destination address and target verification rule of the target service message to the client. In response, the client receives the destination address and target verification rule of the target service message. Optionally, after receiving the destination address and target verification rule of the target service message, the client sets the effective duration or effective period for the destination address and target verification rule of the target service message. For detailed description, please refer to the relevant description of setting the effective duration or effective period in step 102, which will not be repeated.
[0194] In this example, when the security module of the service end providing the target service is implemented by the service gateway of the business network where the target service is located, the network controller, after selecting the destination address and target verification rule of the target business message, also sends the destination address and target verification rule of the target business message to the service gateway. In response, the service gateway receives the destination address and target verification rule of the target business message. Optionally, the service gateway also sets the effective duration or effective period for the destination address and target verification rule of the target business message after receiving the destination address and target verification rule of the target business message. For detailed description, please refer to the relevant description of setting the effective duration or effective period in step 103, which will not be repeated here.
[0195] Example 3: Combination Figure 3In the implementation environment shown, multiple access addresses and multiple verification rules configured for the target service are preset in the DNS. In this case, when the client needs to access the target service, it sends an address acquisition request to the DNS, and the request carries the domain name of the target service. In response to the request, the DNS finds multiple access addresses and multiple verification rules configured for the target service represented by the domain name according to the domain name. Then, the DNS selects an access address from the multiple access addresses configured for the target service as the destination address of the target business message according to the fourth strategy, and selects a verification rule from the multiple verification rules configured for the target service according to the third strategy as the target verification rule corresponding to the destination address of the target business message. Then, the DNS returns the destination address and target verification rule of the target business message to the client. In response, the client receives the destination address and target verification rule of the target business message. Optionally, after receiving the destination address and target verification rule of the target business message, the client sets the effective duration or effective period for the destination address and target verification rule of the target business message. For detailed description, please refer to the relevant description of setting the effective duration or effective period in step 102, which will not be repeated.
[0196] In this example, when the security module of the service end providing the target service is implemented by the service gateway of the business network where the target service is located, after the DNS selects the destination address and target verification rule of the target business message, it also sends the destination address and target verification rule of the target business message to the service gateway. In response, the service gateway receives the destination address and target verification rule of the target business message. Optionally, after receiving the destination address and target verification rule of the target business message, the service gateway sets the effective duration or effective period for the destination address and target verification rule of the target business message. For detailed description, please refer to the relevant description of setting the effective duration or effective period in step 103, which will not be repeated here.
[0197] Example 4: Combination Figure 4In the implementation environment shown, multiple access addresses and multiple verification rules configured for the target service are preset in the DNS and the network controller, and the multiple access addresses and the multiple verification rules are configured in different combinations. In this case, when the client needs to access the target service, it sends an address acquisition request to the DNS, and the request carries the domain name of the target service. In response to the request, the DNS finds multiple combinations of the target service configuration represented by the domain name according to the domain name, and selects an access address from the multiple access addresses as the destination address of the target service message according to the fourth strategy, and determines the verification rule included in the combination including the destination address of the target service message as the target verification rule corresponding to the destination address of the target service message. Then, the DNS returns the destination address and the target verification rule of the target service message to the client. In response, the client receives the destination address and the target verification rule of the target service message. Optionally, after receiving the destination address and the target verification rule of the target service message, the client sets the effective duration or effective period for the destination address and the target verification rule of the target service message. For detailed description, please refer to the relevant description of setting the effective duration or effective period in step 102, which will not be repeated.
[0198] In this example, when the security module of the server that provides the target service is implemented by the service gateway of the business network where the target service is located, the service gateway can receive any business message and when no verification rule corresponding to the destination address can be found locally based on the destination address in the business message, the service gateway can query the network controller for the combination preset by the network controller in real time based on the destination address, and when the combination including the destination address of the business message is queried, obtain the combination, and the verification rules in the combination are the target verification rules corresponding to the preset fields in the destination address of the business message.
[0199] Step 202: The client sends a target service message, which includes a verification field and is used to access a target service.
[0200] The client first generates a target service message based on the service content / data and the destination address of the target service message obtained, and sends the target service message, which carries a verification field. In one possible scenario, the destination address in the target service message includes the verification field. In another possible scenario, the option field / extension field of the target service message includes the verification field.
[0201] Exemplarily, the client sends a target service message including a verification field through its own communication interface.
[0202] Optionally, the client generates and sends the target service message within a valid duration or valid period of the destination address of the target service message.
[0203] It should be understood that the client sets a valid duration or valid period for the destination address of the target business message in advance, and the detailed description of the client setting the valid duration or valid period for the destination address of the target business message can refer to the relevant description of step 102 or step 201 above, which will not be repeated. Since the access address of the target service (i.e., the destination address of the target business message) pre-acquired by the client is set with a valid duration or valid period, it can increase the difficulty for the attack source to resolve the access address of the target service to attack the target service, thereby enhancing the network security of the business network where the target service is located. For example, when the attack source resolves the access address of the target service, the valid duration of the release record has expired, and the attack source still cannot access the target service according to the resolved address.
[0204] Step 203: The security module of the server receives the target service message.
[0205] Taking the example that the security module of the server providing the target service is implemented by the service gateway of the service network where the target service is located, in response to step 202, the service gateway receives the target service message for accessing the target service through its own communication interface.
[0206] Step 204: The security module of the server verifies the verification field included in the target service message according to the preset target verification rule, and in response to successful verification, sends the target service message to the server.
[0207] The successful verification is used to indicate that the destination address of the target service message is the address configured for the client to access the target service.
[0208] Taking the example that the security module of the server providing the target service is implemented by the service gateway of the service network where the target service is located, after receiving the target service message, the service gateway extracts the destination address of the target service message and obtains the target verification rule corresponding to the preset field in the destination address of the target service message. The target verification rule can be a verification rule preset by the security module of the server, or a verification rule pre-acquired based on the relevant description of step 201 above, which is not limited to this.
[0209] When the access address of the target service is an IPv6 address and the access address of the target service includes a verification field, the service gateway pre-acquires the destination address of the target service message or is used to calculate the destination address, and includes a combination of preset fields and verification rules. A detailed description can be referred to the description of the service gateway obtaining the first address or the first combination in the methods described in the above "first possible situation" to "fourth possible situation", and no further details will be given.
[0210] For example, when the service gateway pre-acquires an access address of a target service, such as the first address described in the "first possible scenario" to the "fourth possible scenario" above, the service gateway sets a release list based on the pre-acquired access address of the target service. The release list includes at least one release record, and each release record includes an access address of the target service. For another example, in the "second possible scenario" and the "third possible scenario" above, when the network controller or DNS sends the first combination or the first address to the service gateway, it also sends the source address of the client requesting to obtain the first address to the service gateway. In this case, for any release record in the release list, the release record includes the target service access address configured for the client and the source address of the client requesting to obtain the access address. For another example, when the network controller or DNS sends the first combination or the first address to the service gateway, it also sends the source address of the client requesting to obtain the first address to the service gateway. At this time, it can be understood that the first combination obtained by the service gateway includes preset fields, verification rules and the source address of the client. It should be understood that the client represented by the source address of the client in the first combination refers to the client requesting to obtain the first address calculated based on the preset fields and verification rules in the first combination.
[0211] In the first possible implementation method, when the service gateway pre-acquires multiple combinations including preset fields and verification rules, and the service gateway is also configured with a release list, and the release record of the release list only includes the access address of the target service, after the service gateway receives the target business message and extracts the destination address of the target business message, the service gateway queries the release list according to the destination address of the target business message to determine whether the destination address of the target business message exists in the release list.
[0212] When the destination address of the target service message exists in the release list, it means that the destination address of the target service message carried by the service message is successfully verified. At this time, in response to the successful verification, the service gateway sends the target service message to the server providing the target service.
[0213] When the destination address of the target service message does not exist in the release list, optionally, the service gateway can directly block the target service message according to the interception strategy. Optionally, the service gateway can also first determine the target verification rule corresponding to the preset field in the destination address of the target service message according to the preset field in the destination address of the target service message. Exemplarily, the service gateway can query the combination of preset fields and verification rules obtained in advance by the service gateway according to the preset field in the destination address of the target service message, and the verification rule included in the combination of preset fields in the destination address of the target service message is determined as the target verification rule corresponding to the preset field in the destination address of the target service message. Then, the service gateway parses the calculation factor indicated by the target verification rule from the target service message within the effective duration of the combination or within the effective period (that is, the effective duration or effective period of the verification rule in the combination), and calculates the calculation factor obtained by the analysis according to the preset algorithm indicated by the target verification rule, thereby calculating the target verification field. Then the service gateway compares the verification field included in the target verification field and the target service message to determine whether the verification field included in the target verification field and the target service message is the same. When the verification field included in the target verification field and the target business message is different, it means that the destination address verification of the target business message fails. At this time, in response to the verification failure, the service gateway blocks the target business message according to the interception strategy. And, when the verification field included in the target verification field and the target business message is the same, it means that the destination address verification of the target business message is successful. At this time, the service gateway sends the target business message to the service end providing the target service. Optionally, the service gateway also adds the destination address of the target business message to the release list. In this way, the service gateway can use the release list to quickly perform security verification on the destination address of the received business message later. In addition, when the service gateway does not find the corresponding target verification rule according to the preset field in the destination address of the target business message, it also means that the verification of the destination address of the target business message fails. At this time, the service gateway blocks the target business message according to the interception strategy.
[0214] The interception strategy includes any of the following strategies: dropping the service message, changing the forwarding direction of the service message (such as forwarding the service message to the honeypot node), marking the service message as a forbidden message, or marking the service message as an unreachable message, etc. The honeypot node is usually a node for collecting network security information. The security information collected by the honeypot node can be referenced by other attack prevention systems in the security information system.
[0215] Optionally, a general interception strategy may be preset in the service gateway.
[0216] Optionally, when the service gateway obtains the verification rules, each verification rule obtained is configured with an interception strategy. Among them, the interception strategy corresponding to the verification rule can be configured by the service gateway after obtaining the verification rule, or the interception strategy corresponding to the verification rule can be configured by the network controller or DNS for each verification rule, so that when the service end obtains the verification rule, it also obtains the corresponding interception strategy. In this way, when the service gateway fails to check the destination address of the service message according to a certain verification rule, the interception strategy corresponding to the verification rule is used to block the service message.
[0217] In a second possible implementation, when the service gateway pre-acquires multiple combinations including preset fields, verification rules and the source address of the client, and the service gateway is also configured with a release list, and the release record of the release list includes the access address of the target service and the source address of the client requesting the access address, after the service gateway receives the target business message and extracts the source address and destination address of the target business message, it queries the release list based on the source address and destination address of the target business message to determine whether there is a first release record including the source address and the destination address in the release list.
[0218] When the first release record exists in the release list, it means that the destination address and source address of the target service message have been successfully verified. At this time, the service gateway sends the target service message to the server that provides the target service. By performing security verification on both the source address and the destination address of the service message, it is possible to prevent illegal clients from impersonating legitimate clients to access the target service, thereby ensuring the network security of the target service and further ensuring the network security of the service network where the target service is located.
[0219] When the first release record does not exist in the release list, optionally, the service gateway can directly block the target business message according to the above-mentioned interception strategy. Optionally, the service gateway can also first determine the corresponding target verification rule according to the source address and destination address of the target business message. Exemplarily, the service gateway can query the service gateway according to the preset field in the source address and destination address of the target business message, including the combination of preset fields, verification rules and client source address, and the verification rules included in the combination of preset fields in the source address and destination address of the target business message are determined as the target verification rules corresponding to the source address and destination address of the target business message. Then, the service gateway parses the calculation factor indicated by the target verification rule from the target business message within the effective duration or effective period of the combination (that is, the effective duration or effective period of the verification rule in the combination), and calculates the calculation factor obtained by the analysis according to the preset algorithm indicated by the target verification rule, thereby calculating the target verification field, and then the service gateway compares the verification field included in the target verification field and the target business message to determine whether the verification field included in the target verification field and the target business message is the same. When the verification field included in the target verification field and the target business message is different, it means that the destination address verification of the target business message fails, and the service gateway blocks the target business message according to the above-mentioned interception strategy. And, when the verification field included in the target verification field and the target business message is the same, it means that the destination address verification of the target business message is successful, and the service gateway sends the target business message to the service end providing the target service. Optionally, the service gateway also adds the source address and destination address of the target business message as a release record (i.e., the first release record) to the release list. In this way, the service gateway can use the release list to quickly perform security verification on the source address and destination address of the received business message. In addition, when the service gateway does not find the corresponding verification rule according to the preset field in the source address and destination address of the target business message, it also means that the verification of the destination address of the target business message fails, and the service gateway blocks the target business message according to the interception strategy.
[0220] In the third possible implementation, the service gateway only obtains multiple combinations of preset fields and validation rules in advance, or only obtains multiple combinations of preset fields, validation rules and the source address of the client. In this case, for each service message received, such as the target service message, the service gateway determines the corresponding target validation rule according to the destination address of the target service message, and parses the calculation factor indicated by the target validation rule from the target service message within the effective duration or effective period of the determined target validation rule, and calculates the calculated factor obtained by parsing according to the preset algorithm indicated by the target validation rule, thereby calculating the target validation field. Alternatively, the service gateway determines the corresponding target validation rule according to the source address and destination address of the target service message, and parses the calculation factor indicated by the target validation rule from the target service message within the effective duration or effective period of the determined target validation rule, and calculates the calculated factor obtained by parsing according to the preset algorithm indicated by the target validation rule, thereby calculating the target validation field. Furthermore, the service gateway compares the target verification field and the verification field included in the target business message to determine whether the target verification field and the verification field included in the target business message are the same, and performs corresponding processing according to the comparison result, such as normal forwarding or blocking. No more details are given. In addition, when the service gateway fails to find the corresponding target verification rule according to the preset field in the destination address of the target business message, it also means that the verification of the destination address of the target business message has failed. At this time, the service gateway blocks the target business message according to the interception strategy.
[0221] In addition, when the access address of the target service is an IPv6 / IPv4 address and the access address of the target service does not include a verification field, the service gateway sets a release list according to the access address of the target service obtained in advance. Each release record of the release list includes an access address of the target service and a verification rule corresponding to the access address. Among them, the detailed description of the service gateway obtaining the access address of the target service can refer to the relevant description of Examples 1 to 4 in step 201. Optionally, in the cases described in "Example 2" and "Example 3" above, when the network controller or DNS sends the destination address of the target service message and the verification rule corresponding to the destination address of the target service message to the service gateway, it also sends the source address of the client requesting to obtain the destination address of the target service message to the service gateway. In this case, for any release record of the release list, the release record includes the target service access address configured for the client, the source address of the client requesting to obtain the access address, and the verification rule corresponding to the access address.
[0222] In the first possible implementation method, when each release record in the release list includes only an access address of the target service and the verification rules corresponding to the access address, after the service gateway receives a business message whose destination address is the destination address of the target business message, the service gateway queries the release list based on the destination address of the target business message to determine whether there is a release record in the release list that contains the destination address of the target business message.
[0223] When the service gateway determines that there is no release record containing the destination address of the target business message, it means that the service gateway has not found the verification rule corresponding to the destination address of the target business message, that is, the verification of the destination address of the target business message has failed. At this time, the service gateway blocks the target business message according to the above-mentioned interception strategy.
[0224] When the service gateway determines that there is a release record containing the destination address of the target service message, the service gateway determines the verification rule in the release record as the target verification rule corresponding to the destination address of the target service message. Then, the service gateway parses the calculation factor indicated by the target verification rule from the target service message within the effective duration or effective period of the target verification rule, and calculates the calculation factor obtained by parsing according to the preset algorithm indicated by the target verification rule, thereby calculating the target verification field, and then the service gateway compares the target verification field and the verification field included in the target service message (such as the verification field carried by the option field / extension field of the target service message) to determine whether the target verification field and the verification field included in the target service message are the same. In the case where the verification field included in the target verification field and the target service message is different, it means that the destination address of the target service message is not the access address configured for the client that initiates the target service message, that is, it means that the destination address verification of the target service message fails, and the service gateway blocks the target service message according to the above-mentioned interception strategy. Also, when the target verification field and the verification field included in the target business message are the same, it means that the destination address of the target business message is the access address configured for the client that initiates the target business message, which means that the destination address verification of the target business message is successful. At this time, the service gateway sends the target business message to the server that provides the target service.
[0225] In a second possible implementation, when each release record in the release list includes an access address of the target service, a verification rule corresponding to the access address, and a source address of the client requesting the access address, after receiving the target business message, the service gateway queries the release list based on the source address and destination address of the target business message to determine whether there is a release record containing the source address and the destination address in the release list.
[0226] When the service gateway determines that there is no release record containing the source address and destination address of the target business message, it means that the service gateway has not found the target verification rule corresponding to the source address and the destination address, that is, the verification of the destination address of the target business message has failed. At this time, the service gateway blocks the target business message according to the above-mentioned interception strategy.
[0227] When the service gateway determines that there is a release record containing the source address and destination address of the target service message, the service gateway determines the verification rule in the release record as the target verification rule corresponding to the source address and the destination address. Then, the service gateway parses the calculation factor indicated by the target verification rule from the target service message within the effective duration or effective period of the target verification rule, and calculates the calculation factor obtained by parsing according to the preset algorithm indicated by the target verification rule, thereby calculating the target verification field, and then the service gateway compares the target verification field and the verification field included in the target service message (such as the verification field carried by the option field / extension field of the target service message) to determine whether the target verification field and the verification field included in the target service message are the same. In the case where the verification field included in the target verification field and the target service message is different, it means that the destination address of the target service message is not the access address configured for the client that initiates the target service message, that is, it means that the destination address verification of the target service message fails, and the service gateway blocks the target service message according to the above-mentioned interception strategy. Also, when the target verification field and the verification field included in the target business message are the same, it means that the destination address of the target business message is the access address configured for the client that initiates the target business message, which means that the destination address of the target business message is verified successfully. At this time, the service gateway sends the business message of the target business message to the server that provides the target service.
[0228] In some embodiments, the service gateway is also pre-set with a blocking list, which is used to record the destination addresses of the service messages that are prohibited from being forwarded to the next hop node. Exemplarily, the addresses in the blocking list can be IP addresses collected based on the collected network attack information, or they can be the destination addresses of the service messages blocked by the service gateway in history. For example, the service gateway blocks the service messages sent to a certain destination address for multiple consecutive times according to the above implementation method. When the number of blocking times exceeds the threshold, the service gateway adds the destination address to the blocking list.
[0229] In this case, for any service message received by the service gateway, the service gateway also traverses the blocking list according to the destination address extracted from the service message to determine whether the destination address exists in the blocking list. When the service gateway determines that the destination address exists in the blocking list, it means that the service message containing the destination address is a message with security issues. At this time, the service gateway blocks the service message according to the interception strategy described above.
[0230] Optionally, in a scenario where the service gateway supports NAT conversion, the service gateway also performs NAT conversion on the destination address of the target business message when determining that the destination address verification of the target business message is successful, and uses the address after NAT of the destination address of the target business message as the new destination address of the target business message to send the business message, that is, the service gateway sends the business message to the address after NAT of the destination address of the target business message, which is not repeated here.
[0231] When the service gateway performs NAT conversion on the message accessing the target service, the real IP address of the target service can be an IPv4 address or an IPv6 address, without limitation. It should be understood that the real IP address of the target service refers to the private network address of the server providing the target service in the business network.
[0232] Optionally, the service gateway also sends the target service message to the server that provides the target service at the back end according to the load balancing strategy when determining that the destination address verification of the target service message is successful.
[0233] It should be understood that in the embodiment of the present application, when the access address and the corresponding verification rules configured for the target service are preset in the client and the service gateway, and the service gateway blocks the service message by default, and performs a security check on the destination address of each service message received according to the several verification processes described in step 204 for each service message received, so that a completely hidden trusted service network can be created. Alternatively, when the client and the service gateway obtain the access address and the corresponding verification rules configured for the target service through the DNS or the network controller, and the DNS and the network controller exposed to the network are both authorized access, and then when the service gateway blocks the service message by default, and performs a security check on the destination address of each service message received according to the several verification processes described in step 204 for each service message received, so that a nearly completely hidden trusted service network can be created. In other words, the embodiment of the present application can reduce or even avoid the risk of attack on the service network by creating a completely hidden or nearly completely hidden trusted service network on the Internet. In other words, by applying the method provided in the embodiment of the present application, a relatively trusted network environment can be constructed in an untrusted network, thereby reducing the risk of network attacks on services exposed on the network, and effectively defending against network attacks.
[0234] In summary, through the method described in steps 201 to 204, it can be achieved that when the client needs to access the target service, both the client and the server of the target service can obtain the access address configured for the target service, as well as the verification rules customized for the client. In this way, the client can obtain a dedicated address and verification field for accessing the target service, and the server can verify the verification field carried by each received business message according to the access address and verification rules configured for the target service obtained in advance, thereby achieving security verification of the destination address of the business message, and forwarding the business message normally when the destination address verification of the business message succeeds, and blocking the business message when the destination address verification of the business message fails. In other words, through this method, the destination address of the business message in the forwarding process can be verified through the verification field carried by the business message, and it can ensure that the business message is forwarded normally when the destination address of the business message is the access address configured for the client that initiates the business message to access the target service. That is, this method can ensure that only business messages with successful destination address verification can access the target service, thereby preventing traffic from the attack source from accessing the target service, thereby ensuring the security of the business network where the target service is deployed.
[0235] In some embodiments, in order to filter attack traffic at a location close to the source, when the access address of the target service carries a verification field, reference Fig. 9 , Fig. 9 The flowchart of another message transmission method provided by the embodiment of the present application is shown. Optionally, the method can be applied to Figure 1 , Figure 2 , Figure 3 or Figure 4 The implementation environment shown. For the sake of simplicity, the following description is based on an example in which a client accessing a service provided by a server (referred to as the target service) and the security module of the server perform the corresponding steps of the method described in the embodiment of the present application, and the security module of the server is implemented by a service gateway. In one example, the target service runs on at least one server in at least one cloud data center located in one of the multiple regions, without limitation. Fig. 9 As shown, the method includes the following steps.
[0236] Step 301: The service gateway obtains a combination of preset fields and validation rules, and / or the service gateway obtains an access address of a target service calculated based on the preset fields and validation rules.
[0237] For detailed explanations, please refer to the relevant descriptions in “the first possible situation” to “the fourth possible situation” above, which will not be repeated here.
[0238] Step 302: The service gateway sends the access address of the target service including the combination of preset fields and verification rules and / or calculated based on the preset fields and verification rules to the forwarding node reachable to itself.
[0239] In one example, after obtaining the target verification rule described above, the service gateway sends the target verification rule to the forwarding node that can reach itself.
[0240] Optionally, the forwarding node reachable to the service gateway includes all nodes reachable to the service gateway on the network, or the forwarding node reachable to the service gateway includes a node that forwards messages between the client accessing the target service and the service gateway. For example, the forwarding node is any message forwarding device such as a router or switch reachable to the service gateway, which is not limited to this.
[0241] In one example, the service gateway sends the acquired combination and / or access address to the forwarding node reachable to itself through management channels such as YANG, thereby implementing point-to-point configuration of the combination and / or access address acquired by the service gateway to the node reachable to the service gateway.
[0242] In another example, the service gateway can carry the combination and / or access address obtained by the service gateway through the extended field after extending the relevant technical protocol, thereby sending the combination and / or access address obtained by the service gateway to the forwarding node that can reach the service gateway. Among them, the relevant technical protocols include but are not limited to: extended border gateway protocol (BGP), network layer reachability information (NLRI) protocol, BGP flow description (BGP flowspec) protocol, etc.
[0243] In another example, the service gateway may extend the outer tunnel of the data message, thereby utilizing the interactive data message to passively send the combination and / or access address acquired by the service gateway to the forwarding node that can reach the service gateway.
[0244] In addition, since the service gateway can configure a release list including the target service access address according to the access address obtained in advance, the description of the release list refers to the relevant description in step 204. Therefore, "the service gateway sends the access address of the target service calculated based on the preset field and the verification rule to the forwarding node that can reach itself", it can also be understood that the service gateway sends the release record in the release list containing the target service access address to the forwarding node that can reach itself. For example, after the service gateway adds the first release record to the release list in step 204, it sends the first release record to the forwarding node that can reach the service gateway. Optionally, the service gateway also sends the valid duration or valid period of the first release record to the forwarding node that can reach itself. It should be understood that after the service gateway adds the first release record to the release list in step 204, the valid duration or valid period can be set for the first release record. For detailed description, please refer to the description of setting the valid duration or valid period for the access address or combination above, which will not be repeated.
[0245] Optionally, when the service gateway sends the access address of the target service calculated based on the preset fields and verification rules and / or the combination of preset fields and verification rules to the forwarding nodes reachable to itself, it also sends the source address of the client requesting the aforementioned access address to these forwarding nodes.
[0246] By executing steps 301 to 302, it is achieved that when the access address of the target service carries a verification field, after the forwarding node obtains a combination of preset fields and verification rules and a client source address requesting an access address calculated based on the combination, and / or after the forwarding node obtains the access address of the target service calculated based on the preset fields and verification rules and a client source address requesting the access address, these forwarding nodes can execute the relevant description in the above step 204 for the received business messages, thereby realizing forwarding or blocking of these business messages, thereby being able to filter attack traffic at a location close to the client (i.e., the source end), thereby improving the impact of network attacks on the communication network between the client and the service gateway.
[0247] In some other embodiments, in order to filter attack traffic at a location close to the source, when the access address of the target service does not carry a verification field, reference Fig.10 , Fig.10 The flowchart of another message transmission method provided by the embodiment of the present application is shown. Optionally, the method can be applied to Figure 1 , Figure 2 , Figure 3 or Figure 4The implementation environment shown. For the sake of simplicity, the following description is based on an example in which a client accessing a service provided by a server (referred to as the target service) and the security module of the server perform the corresponding steps of the method described in the embodiment of the present application, and the security module of the server is implemented by a service gateway. In one example, the target service runs on at least one server in at least one cloud data center located in one of the multiple regions, without limitation. Fig.10 As shown, the method includes the following steps.
[0248] Step 401: The service gateway obtains the access address configured for the target service and the verification rules corresponding to the access address.
[0249] For detailed description, please refer to the relevant descriptions of "Example 1" to "Example 4" in step 201 above, which will not be repeated here.
[0250] Step 402: The service gateway sends the access address configured for the target service and the verification rules corresponding to the access address to the forwarding node reachable to itself.
[0251] For detailed description, please refer to the description of step 302, which will not be repeated here.
[0252] By executing steps 401 to 402, it is achieved that when the access address of the target service does not carry the verification field, after the forwarding nodes that forward messages between the client accessing the target service and the service gateway obtain the access address configured for the target service, the verification rules corresponding to the access address, and the client source address requesting the access address, these forwarding nodes can execute the relevant description in the above step 204 for the received business messages, thereby realizing forwarding or blocking of these business messages, thereby being able to filter attack traffic at a location close to the client (i.e., the source end), thereby improving the impact of network attacks on the communication network between the client and the service gateway.
[0253] In order to deepen the understanding of the method provided in the embodiment of the present application, the method is further described below through specific examples.
[0254] In an example, the access address of the target service is an IPv6 address, and the access address carries a verification field, the business network where the target service is located is configured with a network controller, the network controller is preset with multiple preset fields and multiple verification rules, and the security module of the service side providing the target service is implemented by the gateway of the service side (i.e., the service gateway), as an example, refer to Fig.11 , Fig.11 A schematic diagram of another message transmission method provided by an embodiment of the present application is shown. In one example, the target service runs on at least one server in at least one cloud data center located in one of the multiple regions, which is not limited to this. Figure 2The implementation environment shown is Fig.11 As shown, the method includes the following steps.
[0255] S1. The client 1101 sends an address acquisition request to the network controller 1102.
[0256] S2. The network controller 1102 determines a target combination including a target preset field, a target verification rule, and a client source address in response to the address acquisition request, and calculates a target access address according to the target combination.
[0257] The target access address is the access address of the target service.
[0258] S3. The network controller 1102 returns the target access address to the client 1101.
[0259] S4. The network controller 1102 sends the target combination to the service gateway 1103.
[0260] The detailed description of S1-S4 can refer to the relevant description in step 201, which will not be repeated here. It should be understood that the embodiment of the present application does not limit the execution order of S3 and S4, such as S3 is executed before S4, or S3 is executed after S4, or S3 and S4 are executed at the same time.
[0261] S5. The client 1101 generates a first target service message according to the target access address.
[0262] S6. The client 1101 sends a first target service message.
[0263] For the detailed description of S5-S6, please refer to the relevant description in step 202, which will not be repeated here.
[0264] S7. The service gateway 1103 receives the first target service message, and performs a security check on the destination address (ie, the target access address) of the first target service message according to the target combination.
[0265] S8. When the verification fails, the service gateway 1103 blocks the first target service message.
[0266] S9. When the verification is successful, the service gateway 1103 sends the first target service message to the server 1104.
[0267] S10. When the verification is successful, the service gateway 1103 also adds the source address and destination address (ie, target access address) of the target service message to the release list.
[0268] S11. The client 1101 generates a second target service message whose destination address is the target access address.
[0269] After the client 1101 generates and sends the first target service message, it generates a second target service message with the destination address being the target access address.
[0270] S12. The client 1101 sends the second target service message.
[0271] S13. The service gateway 1103 receives the second target service message and queries the release list based on the source address and destination address (i.e., the target access address) of the second target service message to forward or block the second target service message.
[0272] Among them, the detailed description of S7 - S13 can refer to the relevant descriptions in steps 203 - 204 above and will not be elaborated here.
[0273] In another example, taking the access address of the target service as an IPv6 address and the access address carrying a verification field, the business network where the target service is located is configured with a network controller. The network controller pre - sets multiple preset fields and multiple verification rules, and the security module of the server providing the target service is implemented by the gateway of the server (i.e., the service gateway) as an example, refer to Fig.12 , Fig.12 shows a schematic diagram of an implementation framework of a message transmission method in an application provided by an embodiment of the present application.
[0274] As Fig.12 shown, N clients are located in different regions, the business network provides M services, and the business network is provided with a network controller. Among them, N and M are positive integers respectively. Further, when clients in different regions need to access the target service (for example, any one of services 1 - M), the clients in different regions execute S1 and S3 described above through communication with the network controller, so that the clients in different regions can obtain different access addresses of the target service. At the same time, the network controller executes S4 to implement sending a combination including preset fields, verification rules, and the source address of the client to the service gateway. Then, the clients in different regions execute S6 or S12 based on the access addresses of the target service they obtain respectively, and the server executes S7 - S8 to send the service message initiated by the client to the server providing the target service, receive the response message of the service message returned by the target service, and return the response message of the service message to the client that initiated the service message.
[0275] The beneficial effects of the method provided by the embodiments of the present application will be described below through specific application examples.
[0276] Application Example 1
[0277] Refer to Fig.13, the business network 1300 is deployed with service 1, the access address of service 1 is an IPv6 address, the access address of service 1 includes a verification field, and the business network 1300 is configured with three service gateways (including R1 to R3) distributed in different regions for the server that provides service 1. In addition, the business network 1300 is provided with a network controller.
[0278] In this application example, when client A1 located in region A needs to access service 1, it executes the method provided in the embodiment of the present application through interaction with the network controller to obtain the access address 1 of service 1, and in this example, the network controller sends the preset field 1 and the corresponding verification rule 1 in the access address 1 to all service gateways R1 to R3 of service 1. Based on the near-source strategy, client A1 accesses service 1 through service gateway R1 based on access address 1, and R1 executes the method provided in the embodiment of the present application to perform security verification on the destination address of the service message received from the client, thereby implementing near-source filtering of attack traffic. For detailed process, please refer to the relevant description of steps 201 to 204.
[0279] Similarly, when client B1 located in region B needs to access service 1, it executes the method provided in the embodiment of the present application through interaction with the network controller to obtain the access address 2 of service 1, and in this example, the network controller sends the preset field 2 and the corresponding verification rule 2 in the access address 2 to all service gateways R1 to R3 of service 1. Based on the near-source strategy, client B1 accesses service 1 through service gateway R3 based on access address 2, and R3 executes the method provided in the embodiment of the present application to perform security verification on the destination address of the service message received from the client, thereby implementing near-source filtering of attack traffic. For detailed process, please refer to the relevant description of steps 201 to 204.
[0280] It can be seen that clients distributed in different regions can obtain different access addresses of service 1 from the network controller, and the network controller will send preset fields and corresponding verification rules in different access addresses to service gateways distributed in different regions of service 1, so that clients in different regions can access service 1 through the service gateway closest to the client region based on the near-source strategy, thereby achieving near-source filtering of attack traffic. In this way, a distributed near-source security service network can be created, such as CDN, application delivery network (ADN), high-defense network, secure access service edge (SASE) network, edge security network, etc.
[0281] Application Example 2
[0282] Combination Fig.13,refer to Fig.14 , the business network 1300 is deployed with service 1, the access address of service 1 is an IPv6 address, the access address of service 1 includes a verification field, and the business network 1300 is configured with three service gateways (including R1 to R3) distributed in different regions for the server that provides service 1. In addition, the business network 1300 is provided with a network controller.
[0283] In this application example, when client A1 located in region A needs to access service 1, it executes the method provided in the embodiment of the present application through interaction with the network controller to obtain the access address 1 of service 1, and the network controller only sends the preset field 1 and the corresponding verification rule 1 in the access address 1 to the service gateway R1 deployed at the location closest to region A. At this point, it can also be understood that the network controller sends the preset field 1 and verification rule 1 to the service gateway at the local location of service 1. Therefore, client A1 in region A can access service 1 through service gateway R1 based on access address 1, and R1 executes the method provided in the embodiment of the present application to perform security verification on the destination address of the service message received from client A1. For the detailed process, please refer to the relevant description of steps 201 to 204.
[0284] Among them, after the service gateway R1 receives the preset field 1 and the verification rule 1, it also publishes the preset field 1 and the verification rule 1 to other service gateways (including R2 and R3) that can reach itself. For a detailed description, please refer to the description of steps 301 to 302, which will not be repeated here. In this way, the preset field 1 and the verification rule 1 obtained by the service gateway at the local location of service 1 are published to other forwarding nodes that can reach the service gateway. Then R2 and R3 can perform near-source filtering on the received service messages according to the received preset field 1 and verification rule 1. For example, a zombie host located in region B wants to access service 1 through R3, and R3 executes the method provided in the embodiment of the present application, thereby verifying the destination address of the service message received from the zombie host according to the received preset field 1 and verification rule 1, and refusing the zombie host's message to access service 1 when the verification fails. For another example, client A1 in region A roams to region C, then client A1 roaming to region C can access service 1 through R2 based on the near-source policy. Since R2 has pre-received the preset field 1 and verification rule 1 published by R1, R2 executes the method provided in the embodiment of the present application so that it can perform a security check on the destination address of the service message initiated by the client A1 in the roaming area C according to the received preset field 1 and verification rule 1, and forward the service message to the server providing service 1 when the check is successful.
[0285] It can be seen that in this application example, the release rules (including preset fields and verification rules) obtained by the local node can be published to other forwarding nodes that can reach the local node, so that by executing the method provided by the embodiment of the present application by other forwarding nodes, illegal access traffic (such as attack traffic initiated by zombie hosts) can be rejected and discarded near the source end, thereby avoiding the illegal access traffic from converging to the server end and affecting the business network.
[0286] Application Example 3
[0287] refer to Fig.15 , Fig.15 Any service among the services 1 to M shown is a target service, the access address of the target service is an IPv6 address, the access address of the target service includes a verification field, and the service network where the target service is deployed is provided with a network controller.
[0288] like Fig.15 As shown, client A1 in region A obtains access address 1 of the target service from network control by executing the method provided in the embodiment of the present application, and the network controller in the method provided in the embodiment of the present application sends the preset fields and corresponding verification rules in access address 1 to the service gateway of the target service. At this time, client A1 is an authorized user of the target service. Therefore, when client A1 uses access address 1 to initiate a service message to access the target service, the service gateway can successfully verify the destination address of the service message by executing the method provided in the embodiment of the present application, so that the service gateway forwards the service message to access the target service to the target service, and returns a response message of the service message to access the target service to client A1.
[0289] like Fig.15 As shown, Fig.15 Client A2 in region A, client B1 and client B2 in region B do not obtain the access address of the target service from the network controller, so the network controller will naturally not send the corresponding preset fields and verification rules to the service gateway of the target service. Therefore, client A2, client B1 and client B2 are unauthorized users of the target service. Therefore, the destination address of the service message initiated by client A2, client B1 and client B2 to access the target service fails to be verified in the service gateway, so the service gateway rejects the service message initiated by client A2, client B1 and client B2.
[0290] By executing the method provided in the embodiment of the present application, the service gateway can verify the destination address of the business message according to the preset fields and verification rules obtained, so that users authorized by the service can access the service normally, while unauthorized users cannot access the back-end service, thereby achieving the purpose of hiding the service on the network.
[0291] Application Example 4
[0292] Combination Figure 6 ,refer to Fig.16 , client A1 in region A executes the method provided in the embodiment of the present application to obtain address 1 for accessing service 1, and the service level field of address 1 is configured based on the service ID of service 1, and client A1 executes the method provided in the embodiment of the present application to obtain address 2 for accessing service 2, and the service level field of address 2 is configured based on the service ID of service 2. In this way, different services can be isolated by access address, thereby avoiding the risk of affecting other services when a service is attacked.
[0293] In addition, client A2 in region A executes the method provided in the embodiment of the present application to obtain the address 3 of access service 2, and client B1 in region B executes the method provided in the embodiment of the present application to obtain the address 4 of access service 2, and the security verification field of address 2 of access service 2 is calculated based on the relevant information of client A1, the security verification field of address 3 of access service 2 is calculated based on the relevant information of client A2, and the security verification field of address 4 of access service 2 is calculated based on the relevant information of client B1. In this way, the embodiment of the present application can realize that different clients use different access addresses to access the same service, which can greatly reduce the exposure risk of the service access address.
[0294] Application Example 5
[0295] Combination Figure 6 ,refer to Fig.17 , client A1 in region A executes the method provided in the embodiment of the present application to obtain address 1 for accessing service 1, client A2 in region A executes the method provided in the embodiment of the present application to obtain address 2 for accessing service 1, client A3 in region A executes the method provided in the embodiment of the present application to obtain address 3 for accessing service 1, and client B1 in region B executes the method provided in the embodiment of the present application to obtain address 4 for accessing service 1. When the destination address of the service message for accessing service 1 is security-verified in the embodiment of the present application, the source address of the client that initiates the service message is also verified. In this case, when a client obtains the access address configured for other clients to access the service, the client cannot access the service. For example, Fig.17 When client B1 in the example obtains address 3 configured for client A3, although address 3 itself is a legal access address configured for service 1, client B1 cannot access service 1 through address 3 because the source address of the service message is also verified.
[0296] It can be seen that in this example, different service access addresses are assigned to different clients accessing the same service, so even if a client obtains the access address configured for other clients to access the service, the client cannot access the service. That is, the embodiment of the present application can reduce deception or counterfeit attacks.
[0297] Application Example 6
[0298] Combination Figure 6 ,refer to Fig.18 , when client A1 in region A executes the method provided in the embodiment of the present application to configure the access address of service 1 for itself, the historically configured access address is recorded as address 1. Since the method provided in the embodiment of the present application sets a valid time for each configured access address when configuring the access address of the service, address 1 will become invalid after the valid time. Therefore, after the valid time is reached, client A1 in region A re-executes the method provided in the embodiment of the present application to configure the access address of service 1 for itself, recorded as address 2, and then client A1 accesses service 1 based on address 2.
[0299] It can be seen that by executing the method provided in the embodiment of the present application, the access address of the service will become invalid at a certain time, thereby avoiding playback attacks by clients in the same area.
[0300] Application Example 7
[0301] Combination Figure 6 ,refer to Fig.19 Since region A has a high IP reputation, each of all clients in region A (including client A1, client A2...) can execute the method provided in the embodiment of the present application to configure and obtain address 1 for accessing service 1.
[0302] In addition, region B has a low IP reputation, so multiple clients in region B can configure multiple addresses for accessing service 1 by executing the method provided in the embodiment of the present application. For example, client B1 executes the method provided in the embodiment of the present application to configure address 2 for accessing service 1, and client B3 executes the method provided in the embodiment of the present application to configure address 4 for accessing service 1. And because the IP reputation of client B2 is too low, the embodiment of the present application will not configure the access address of service 1 for client B2. Therefore, client B2 Fig.19 When the address 3 shown accesses service 1, the gateway of service 1 will block the access of client B2 after implementing the solution of the embodiment of the present application.
[0303] It can be seen that in the embodiment of the present application, the access address of the service can be configured for the client in combination with the IP reputation of the client itself and the IP reputation of the region where the client is located. If the IP reputation of a certain region decreases, the embodiment of the present application can allocate IP addresses of finer regional granularity to the clients in that region. If the IP reputation of a certain region improves, the embodiment of the present application can allocate IP addresses of larger regional granularity to the clients in that region. Therefore, by improving the IP reputation of the region, the embodiment of the present application can allocate IP addresses of larger regional granularity to the clients in that region, that is, allocate a smaller number of IP addresses, thereby alleviating the capacity of the address pool configured for the service and alleviating the verification performance of the service gateway for the destination address of the service message.
[0304] Application Example 8
[0305] Combination Figure 6 ,refer to Fig. 20 In the embodiment of the present application, clients in different regions can be configured with different access addresses of service 1, such as client A1 in region A executes the method provided in the embodiment of the present application to obtain address 1 for accessing service 1, client C in region C executes the method provided in the embodiment of the present application to obtain address 3 for accessing service 1, and client B in region B executes the method provided in the embodiment of the present application to obtain address 4 for accessing service 1. Moreover, clients in the same region can also be configured with different access addresses of service 1, such as client A1 in region A executes the method provided in the embodiment of the present application to obtain address 1 for accessing service 1, and client A2 in region A executes the method provided in the embodiment of the present application to obtain address 2 for accessing service 1. Therefore, when a zombie attack occurs, different zombie hosts are likely to fall into different regions, that is, the probability of zombie hosts falling into the same region is small, which can effectively reduce the scale of zombie attacks in a region.
[0306] For example, when Fig. 20 The address 4 shown is exposed to the network and is obtained by the zombie host. Therefore, after the zombie host in region A obtains address 4, it initiates a service message with the destination address being address 4. At this time, the service gateway in region A executes the method provided in the embodiment of the present application to verify both the source address and the destination address, thereby rejecting the service message initiated by the zombie host in region A. For another example, after the zombie host in region B obtains address 4, it initiates a service message with the destination address being address 4. At this time, the service gateway in region B executes the method provided in the embodiment of the present application to verify both the source address and the destination address, thereby rejecting the service message initiated by the zombie host in region B.
[0307] Application Example 9
[0308] Combination Figure 6 ,refer to Fig.21, the clients in region A (including client A1 and client A2) respectively execute the method provided in the embodiment of the present application to obtain the address 1 of access service 1, and the client B in region B executes the method provided in the embodiment of the present application to obtain the address 4 of access service 1. Furthermore, in the embodiment of the present application, the service gateway can use the release list (equivalent to the whitelist) including address 1 and address 4 to filter the received business messages. It can be seen that the embodiment of the present application can filter traffic based on the whitelist in the business network, with low misjudgment rate and simple protection.
[0309] Furthermore, when address 4 is exposed to the network and obtained by a zombie host, when a zombie host in region A uses address 4 to access service 1, the service gateway in region A will determine that the destination address of the service message is illegal based on the release list and the service message is filtered. When a zombie host in region B uses address 4 to access service 1, the service gateway in region B will determine that the zombie host is an unauthorized user based on the release list (i.e., the source address verification of the zombie host fails) and the service gateway in region B will filter the zombie host.
[0310] Application Example 10
[0311] Combination Fig.21 In the embodiment of the present application, for traffic that fails to be verified by the service gateway, traffic whose access address does not exist in the release list, or traffic whose access address is expired, the embodiment of the present application can redirect these traffic to the back-end information collection node (such as a honeypot node), and the information collection node parses these traffic to obtain attack information (such as attack traffic characteristics, attack characteristics, attack source address, etc.). Furthermore, the embodiment of the present application reports the attack information to the attack information collection center, which can be applied to various security devices after analysis, sorting and processing.
[0312] The following is a description of the implementation form of the execution subject involved in executing the embodiment of the present application.
[0313] refer to Fig. 22 In the embodiment of the present application, when the client and the service provider belong to the same closed network, the client includes a service initiator and a gateway of the service initiator. Fig. 22 When the service initiator shown in the figure performs the corresponding steps as the client in the above method, the service initiator can be implemented as independent software, independent hardware, embedded chip, embedded SDK, etc. Fig. 22 When the service initiator gateway shown performs the corresponding steps as the client described in the above method, the service initiator accesses the external network by source NAT or proxy, and the service initiator gateway can be implemented as: ① independent software, independent hardware, embedded chip, embedded SDK, etc.; ② a component deployed on an enterprise gateway, a home gateway or a base station.
[0314] Fig. 22 When the network controller shown executes the method of the embodiment of the present application to configure the access address of the distribution service for the client and issue the release rules to the service gateway, the network controller can be implemented as independent software, independent hardware, embedded chip, embedded SDK, etc. Among them, the release rules include the preset fields, verification rules and client source addresses mentioned above for verifying the destination address of the service message, and the release rules also include the interception strategy after verification.
[0315] Fig. 22 The service gateway shown can be implemented as independent software, independent hardware, embedded chip, embedded SDK, etc. when executing the method provided in the embodiment of the present application.
[0316] Fig. 22 The implementation form of the service shown refers to the relevant technology, and the embodiments of the present application are not limited to this.
[0317] In addition, when the client is a client of an open network, the implementation form of the client can refer to related technologies, and the embodiments of the present application do not limit this.
[0318] The above mainly introduces the solution provided in the embodiment of the present application from the perspective of method.
[0319] To achieve the above functions, refer to Fig.23 , Fig.23 FIG. 1 shows a schematic diagram of the structure of a message transmission device provided in an embodiment of the present application. Fig.23 As shown, the message transmission device 2300 is applied to the security module of the server, and the server is used to provide a target service to the client, and the target service runs on at least one server of at least one cloud data center located in one of the multiple regions. The message transmission device 2300 is specifically used to execute the message transmission method described above, for example, to execute Figure 7 to Figure 11 The steps in the method shown are performed by the security module of the server. The message transmission device 2300 may include a receiving unit 2301 , a processing unit 2302 and a sending unit 2303 .
[0320] The receiving unit 2301 is used to receive a target service message sent by a client for accessing a target service, wherein the target service message includes a verification field. The processing unit 2302 is used to verify the verification field included in the target service message according to a preset target verification rule. The sending unit 2303 is used to send the target service message to the server in response to successful verification. The successful verification is used to indicate that the destination address of the target service message is the address configured for the client to access the target service.
[0321] As an example, combining Figure 8, the receiving unit 2301 can be used to execute step 203, and the processing unit 2302 and the sending unit 2303 can be used to execute step 204.
[0322] Optionally, the processing unit 2302 is specifically used to calculate a target verification field according to a target verification rule, compare the target verification field with a verification field included in a target business message, and determine that verification is successful when the target verification field and the verification field included in the target business message are the same.
[0323] As an example, combining Figure 8 , processing unit 2302 can be used to execute step 204.
[0324] Optionally, the processing unit 2302 is further specifically configured to parse the calculation factor indicated by the target verification rule from the target service message, calculate the calculation factor using the preset algorithm indicated by the target verification rule, and obtain the target verification field, wherein the preset algorithm is an encryption algorithm or a hash algorithm.
[0325] As an example, combining Figure 8 , processing unit 2302 can be used to execute step 204.
[0326] Optionally, the calculation factors include at least one of the following: service ID of the target service, operator of the network to which the client belongs, service level of the client, credibility of the client, credibility of the gateway of the client, credibility of the region where the client is located, IP address of the client, region where the client is located, subnet number of the network to which the client belongs, device type of the client, device ID of the client, gateway type of the client, time when the client generates a service message, and validity period of the target verification rule.
[0327] Optionally, the calculation factors include a service level factor and a security verification factor. Among them, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes at least one of the following: the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a service message, and the effective time of the verification rule. The above preset algorithm is used to calculate the security verification factor to obtain a security verification field in the target verification field for verifying security.
[0328] Optionally, the processing unit 2302 is further configured to determine the target verification rule corresponding to the preset field according to the preset field included in the destination address of the target service message before parsing the calculation factor indicated by the target verification rule from the target service message, wherein the preset field includes the network prefix and subnet address of the destination address.
[0329] Optionally, the processing unit 2302 is further configured to query a release list according to the source address of the target service message and the destination address of the target service message, the release list including at least one release record for recording the source address and the destination address accessed by the source address, and, when the release list does not include the first release record, determine a target verification rule corresponding to the preset field according to the preset field included in the destination address of the target service message. The first release record is used to record the source address of the target service message and the destination address of the target service message.
[0330] Optionally, the processing unit 2302 is further configured to add a first release record to the release list when the verification field included in the target business message is successfully verified according to the target verification rule.
[0331] Optionally, the processing unit 2302 is further configured to set a valid duration for the first release record.
[0332] Optionally, the security module of the server is deployed in the gateway of the server, and the sending unit 2303 is further used to send the target verification rule to the forwarding node that can reach the gateway, or to send the first release record to the forwarding node.
[0333] As an example, combining Fig. 9 , the sending unit 2303 can be used to execute step 302.
[0334] Optionally, the sending unit 2303 is further specifically configured to send a target service message to the server when the release list includes the first release record.
[0335] Optionally, the sending unit 2303 is specifically configured to perform NAT on the destination address of the target service message and send the target service message to the address after NAT, wherein the address after NAT is the address of the server.
[0336] Optionally, the address after NAT is an IPv6 address or an IPv4 address.
[0337] Optionally, processing unit 2302 is also used to block the target business message in response to a verification failure and / or when the destination address of the target business message exists in a blocking list, and the blocking list is used to record the destination address of the business message that is prohibited from being forwarded to the next hop node.
[0338] Optionally, the processing unit 2302 is further specifically configured to discard the target service message, forward the target service message to the honeypot node, or mark the target service message as a suspicious message.
[0339] Optionally, when the destination address of the target service message is an IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes a verification field of the target service message. Alternatively, when the destination address of the target service message is an IPv4 address, the option field of the target service message includes a verification field of the target service message.
[0340] For the specific description of the above optional methods, please refer to the above method embodiments, which will not be repeated here. In addition, the explanation of any of the message transmission devices 2300 provided above and the description of the beneficial effects can refer to the above corresponding method embodiments, which will not be repeated here.
[0341] As an example, in combination with the following Fig.25 The functions implemented by the receiving unit 2301 and the sending unit 2303 in the message transmission device 2300 can be realized by Fig.25 The functions implemented by the processing unit 2302 in the message transmission device 2300 can be realized by Fig.25 Processor 2504 in the Fig.25 The program code in the memory 2506 is implemented.
[0342] refer to Fig.24 , Fig.24 FIG. 2 shows a schematic diagram of the structure of another message transmission device provided in an embodiment of the present application. Fig.24 As shown, the message transmission device 2400 is applied to a client accessing a target service, the target service is a service provided by a server, and the target service runs on at least one server in at least one cloud data center located in one of the multiple regions. The message transmission device 2400 is specifically used to execute the message transmission method described above, for example, to execute Figure 7 to Figure 11 The steps in the method shown are performed by the client. The message transmission device 2400 may include an acquisition unit 2401 and a sending unit 2402.
[0343] The acquisition unit 2401 is used to acquire the destination address of the target service message to be sent and the verification field corresponding to the destination address, the destination address is the address configured for the client to access the target service, and the verification field is calculated based on the target verification rule corresponding to the destination address. The sending unit 2402 is used to send the target service message, the target service message includes the verification field, and the target service message is used to access the target service.
[0344] As an example, combining Figure 8 , the acquiring unit 2401 can be used to execute step 201, and the sending unit 2402 can be used to execute step 202.
[0345] Optionally, the sending unit 2402 is specifically configured to send the target service message within a valid time period of the destination address of the target service message.
[0346] As an example, combining Figure 8 , the sending unit 2402 can be used to execute step 202.
[0347] Optionally, the client is preset with a target validation rule and multiple preset fields, and the preset fields include the network prefix of the business network where the target service is deployed and the subnet address of the server providing the target service in the business network. Then, when the destination address of the target business message includes the validation field, the acquisition unit 2401 is specifically used to select a target preset field from multiple preset fields, calculate the validation field according to the target validation rule, and concatenate the target preset field and the validation field to obtain the destination address of the target business message.
[0348] Optionally, the client is configured with a target verification rule and multiple access addresses of the target service, and the acquisition unit 2401 is specifically used to select a destination address of the target service message from the multiple access addresses, and calculate the verification field according to the target verification rule.
[0349] Optionally, the acquisition unit 2401 is specifically used to use the preset algorithm indicated by the target verification rule to calculate the calculation factor indicated by the target verification rule to obtain the verification field. The preset algorithm is an encryption algorithm or a hash algorithm. The calculation factor includes at least one of the following: the service identifier ID of the target service, the operator of the network to which the client belongs, the service level of the client, the credibility of the client, the credibility of the gateway of the client, the credibility of the area where the client is located, the Internet Protocol IP address of the client, the area where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates the service message, and the effective time of the target verification rule.
[0350] Optionally, the calculation factors include a service level factor and a security verification factor. Among them, the service level factor includes at least one of the following: the service ID of the target service, the operator of the network to which the client belongs, or the service level of the client. The security verification factor includes at least one of the following: the credibility of the client, the credibility of the client's gateway, the credibility of the region where the client is located, the IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates a service message, and the effective time of the verification rule. The above preset algorithm is used to calculate the security verification factor to obtain a security verification field in the target verification field for verifying security.
[0351] Optionally, the sending unit 2402 is further configured to send an address request, the address request being used to request to obtain the destination address of the target service message. The obtaining unit 2401 is specifically configured to receive the destination address of the target service message, the destination address carrying a verification field corresponding to the destination address.
[0352] Optionally, when the destination address of the target service message is an IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes a verification field of the target service message. Alternatively, when the destination address of the target service message is an IPv4 address, the option field of the target service message includes a verification field of the target service message.
[0353] For the detailed description of the above optional methods, please refer to the above method embodiments, which will not be repeated here. In addition, the explanation of any of the above message transmission devices 2400 and the description of the beneficial effects can refer to the above corresponding method embodiments, which will not be repeated here.
[0354] As an example, in combination with the following Fig.25 The function implemented by the acquisition unit 2401 in the message transmission device 2400 can be achieved by Fig.25 Processor 2504 in the Fig.25 2506 in the memory 2506, or by Fig.25 The functions implemented by the sending unit 2402 in the message transmission device 2400 can be realized by Fig.25 Communications interface 2508 implementation is shown.
[0355] Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0356] It should be noted that Fig.23 or Fig.24 The division of modules / units in the above is schematic and is only a logical function division. There may be other division methods in actual implementation. For example, two or more functions may be integrated into one processing module. The above integrated modules may be implemented in the form of hardware or software function modules.
[0357] For example, the following Fig.23 Taking the processing unit 2302 of the message transmission device 2300 as an example, the implementation of the processing unit 2302 is introduced. Similarly, Fig.23 The implementation of the receiving unit 2301 and the sending unit 2303 shown may refer to the implementation of the processing unit 2302 .
[0358] As an example of a software functional unit, the processing unit 2302 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the processing unit 2302 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region (region) or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple data centers with close geographical locations. Among them, usually a region may include multiple AZs.
[0359] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0360] As an example of a hardware functional unit, the processing unit 2302 may include at least one computing device, such as a server, etc. Alternatively, the processing unit 2302 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0361] The multiple computing devices included in the processing unit 2302 can be distributed in the same region or in different regions. The multiple computing devices included in the processing unit 2302 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the processing unit 2302 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0362] It should be noted that, in other embodiments, the processing unit 2302 can be used to execute any step related to data / message processing in the message transmission method described in the embodiment of the present application, the receiving unit 2301 can be used to execute any step related to the receiving operation in the message transmission method described in the embodiment of the present application, and the sending unit 2303 can be used to execute any step related to the sending operation in the message transmission method described in the embodiment of the present application. The steps that the receiving unit 2301, the processing unit 2302 and the sending unit 2303 are responsible for implementing can be specified as needed. The receiving unit 2301, the processing unit 2302 and the sending unit 2303 respectively implement different steps in the message transmission method described in the embodiment of the present application to realize all the functions of the message transmission device.
[0363] The embodiment of the present application also provides a message transmission system, which includes a security module of a server and a client. The security module of the server is used to execute the part of the message transmission method described above that is executed by the security module of the server. The client is used to execute the part of the message transmission method described above that is executed by the client.
[0364] The security module of the server and the client can be implemented by software or hardware. As an example, the implementation of the security module of the server is introduced below. Similarly, the implementation of the client can refer to the implementation of the security module of the server.
[0365] As an example of a software functional unit, the security module on the server side may include code running on a computing instance. Among them, the computing instance may be at least one of a physical host (computing device), a virtual machine, a container and other computing devices. Furthermore, the above-mentioned computing device may be one or more. For example, the security module on the server side may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the application may be distributed in the same region or in different regions. The multiple hosts / virtual machines / containers used to run the code may be distributed in the same AZ or in different AZs, and each AZ includes a data center or multiple data centers with close geographical locations. Among them, usually a region may include multiple AZs.
[0366] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same VPC or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway must be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0367] As an example of a hardware functional unit, the security module of the server side may include at least one computing device, such as a server, etc. Alternatively, the security module of the server side may also be a device implemented by ASIC or PLD, etc. The PLD may be implemented by CPLD, FPGA, GAL or any combination thereof.
[0368] The multiple computing devices included in the security module of the server can be distributed in the same region or in different regions. The multiple computing devices included in the security module of the server can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the security module of the server can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0369] The present application embodiment provides a computing device. Fig.25 As shown, the computing device 2500 includes: a bus 2502, a processor 2504, a memory 2506, and a communication interface 2508. The processor 2504, the memory 2506, and the communication interface 2508 are connected to each other through the bus 2502.
[0370] The bus 2502 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.25 The bus 2502 may include a path for transmitting information between various components of the computing device 2500 (eg, the memory 2506, the processor 2504, and the communication interface 2508).
[0371] Processor 2504 may include a general processor and / or a dedicated hardware chip. A general processor may include: a central processing unit (CPU), a microprocessor (MP) or a graphics processing unit (GPU). The CPU is, for example, a single-core processor (single-CPU), or a multi-core processor (multi-CPU). A dedicated hardware chip is a hardware module for high-performance processing. Dedicated hardware chips include digital signal processors (DSP), data processors (DPU), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, neural processing units (NPU), tensor processing units (TPU), artificial intelligence (artificial intelligent) chips or network processors (NP). Processor 2504 may also be an integrated circuit chip with signal processing capabilities. During the implementation process, part or all of the functions of the method provided in the embodiment of the present application can be completed through the hardware integrated logic circuit in the processor 2504 or the instructions in the form of software.
[0372] The memory 2506 may include a volatile memory, such as a random access memory (RAM). The memory 2506 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0373] The memory 2506 stores executable program codes, and the processor 2504 executes the executable program codes to respectively implement Fig.23The functions of the receiving unit 2301, the processing unit 2302, and the sending unit 2303 are implemented to realize the method part executed by the security module of the server in the message transmission method described in the embodiment of the present application. That is, the memory 2506 stores instructions for executing the method of the functions implemented by the receiving unit 2301, the processing unit 2302, and the sending unit 2303 in the message transmission method described in the embodiment of the present application.
[0374] Alternatively, the memory 2506 stores executable codes, and the processor 2504 executes the executable program codes to respectively implement Fig.24 The functions of the acquisition unit 2401 and the sending unit 2402 are shown, thereby realizing the method part executed by the client in the message transmission method described in the embodiment of the present application. That is, the memory 2506 stores instructions for executing the method of the functions realized by the acquisition unit 2401 and the sending unit 2402 in the message transmission method described in the embodiment of the present application.
[0375] The communication interface 2508 uses a transceiver module such as, but not limited to, a transceiver to achieve communication with other devices or communication networks. For example, the communication interface 2508 can be any one or any combination of the following devices: a network interface (such as an Ethernet interface), a wireless network card, and other devices with network access functions. The communication interface 2508 includes a receiving unit for receiving data / messages, and a sending unit for sending data / messages.
[0376] It should be noted that the above-mentioned multiple devices can be respectively arranged on independent chips, or at least partially or completely arranged on the same chip. Whether to independently arrange each device on different chips or to integrate and arrange it on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation form of the above-mentioned devices. The descriptions of the processes corresponding to the above-mentioned figures have different focuses. For the parts not described in detail in a certain process, please refer to the relevant descriptions of other processes.
[0377] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product providing the program development platform includes one or more computer instructions, and when these computer program instructions are loaded and executed on the computing device 2500, all or part of the functions of the message transmission method provided in the embodiments of the present application are implemented.
[0378] Furthermore, computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, computer instructions may be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium stores computer program instructions that provide a program development platform.
[0379] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0380] like Fig.26 As shown, the computing device cluster includes at least one computing device 2500. The memory 2506 in one or more computing devices 2500 in the computing device cluster may store the same instructions for executing the message transmission method described above.
[0381] In some possible implementations, the memory 2506 of one or more computing devices 2500 in the computing device cluster may also store instructions for executing the message transmission method described above. In other words, the combination of one or more computing devices 2500 may jointly execute instructions for executing the message transmission method described above.
[0382] It should be noted that the memory 2506 in different computing devices 2500 in the computing device cluster may store different instructions, which are respectively used to execute the above Fig.23 Part of the functions of the message transmission device. That is, the instructions stored in the memory 2506 in the different computing devices 2500 can be implemented Fig.23 The functions of one or more unit modules in the receiving unit 2301, the processing unit 2302 and the sending unit 2303 are shown.
[0383] Alternatively, the memory 2506 in different computing devices 2500 in the computing device cluster may store different instructions for executing the above instructions respectively. Fig.24 Part of the functions of the message transmission device. That is, the instructions stored in the memory 2506 in the different computing devices 2500 can be implemented Fig.24 The functions of one or more unit modules in the acquisition unit 2401 and the sending unit 2402 are shown.
[0384] In some possible implementations, one or more computing devices in the computing device cluster may be connected via a network, which may be a wide area network or a local area network. Fig. 27 A possible implementation is shown. Fig. 27 As shown, two computing devices 2500A and 2500B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this possible implementation, Fig.23 , the memory 2506 in the computing device 2500A stores the implementation Fig.23 The instructions for the functions of the processing unit 2302 are shown. At the same time, the memory 2506 in the computing device 2500B stores the instructions for implementing Fig.23 Instructions for the functions of the receiving unit 2301 and the sending unit 2303 are shown.
[0385] Fig. 27 The connection method between the computing device clusters shown can be based on the need to perform relevant calculations on the destination address of the received message in the method steps executed by the security module of the server in the message transmission method provided in the embodiment of the present application. Therefore, it is considered that the functions implemented by the processing unit 2302 are executed by the computing device 2500A, and other operations (such as receiving, sending, etc.) are executed by the computing device 2500B.
[0386] It should be understood that Fig. 27 The functions of the computing device 2500A shown in FIG. 2 may also be completed by multiple computing devices 2500. Similarly, the functions of the computing device 2500B may also be completed by multiple computing devices 2500, which is not limited thereto.
[0387] The present application embodiment also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to that of Fig.26 and Fig. 27 The connection mode of the computing device cluster is different in that the memory 2506 in one or more computing devices 2500 in the computing device cluster may store the same instructions for executing the message transmission method described in the embodiment of the present application.
[0388] In some possible implementations, the memory 2506 of one or more computing devices 2500 in the computing device cluster may also store some instructions for executing the message transmission method described in the embodiment of the present application. In other words, the combination of one or more computing devices 2500 can jointly execute the instructions for executing the message transmission method described in the embodiment of the present application.
[0389] It should be noted that the memory 2506 in different computing devices 2500 in the computing device cluster can store different instructions for executing some functions of the message transmission system described in the embodiment of the present application. That is, the instructions stored in the memory 2506 in different computing devices 2500 can implement the functions of the security module of the server and one or more device modules in the client described above.
[0390] The embodiment of the present application also provides a computer program product including instructions. The computer program product may be a software or program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the message transmission method described in the embodiment of the present application.
[0391] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to execute the message transmission method provided in the embodiment of the present application.
[0392] The embodiment of the present application also provides a chip, which includes a processor. When the processor runs a program instruction or code, the chip including the processor or the device including the chip executes the message transmission method described above. Exemplarily, the chip also includes: an input interface, an output interface, and a memory. Among them, the input interface, output interface, processor, and memory of the chip are connected through the internal connection path of the chip, the memory in the chip is used to store the program instructions or code run by the processor, and the input interface and output interface of the chip are used for the connection and communication between the chip and other chips or devices.
[0393] In the embodiments of the present application, the terms "first", "second" and "third" are used for descriptive purposes only and should not be understood as indicating or implying relative importance. The term "at least one" means one or more, and the term "plurality" means a plurality, unless otherwise expressly defined.
[0394] The term "and / or" in this application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0395] It should be understood that the terms used in the description of the various examples herein are only for describing specific examples and are not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0396] It should be understood that determining B based on A does not mean determining B only based on A. B can also be determined based on A and / or other information.
[0397] It should be understood that the term “comprise” (also known as “includes”, “including”, “comprises” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0398] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0399] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the concept and principle of the present application shall be included in the protection scope of the present application.
[0400] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0401] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A message transmission method, characterized in that: A security module applied to a server, the server being used to provide a target service to a client, the target service running on at least one server in at least one cloud data center located in one of the multiple regions, the method comprising: receiving a target service message sent by the client, wherein the target service message is used to access the target service, and the target service message includes a verification field; Verifying the verification field included in the target service message according to the preset target verification rule; In response to successful verification, the target service message is sent to the server, and the successful verification is used to indicate that the destination address of the target service message is the address configured for the client to access the target service.
2. The method according to claim 1, characterized in that The verifying the verification field included in the target service message according to the preset target verification rule includes: Calculate the target verification field according to the target verification rule; Comparing the target verification field with the verification field included in the target service message; When the target verification field and the verification field included in the target service message are identical, it is determined that the verification is successful.
3. The method according to claim 2, characterized in that The step of calculating the target verification field according to the target verification rule includes: Parsing the calculation factor indicated by the target verification rule from the target service message; The calculation factor is calculated using a preset algorithm indicated by the target verification rule to obtain a target verification field; wherein the preset algorithm is an encryption algorithm or a hash algorithm.
4. The method according to claim 3, characterized in that The calculation factor includes at least one of the following: The service identifier ID of the target service, the operator of the network to which the client belongs, the service level of the client, the reputation of the client, the reputation of the gateway of the client, the reputation of the region where the client is located, the Internet Protocol IP address of the client, the region where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generated the service message, and the validity period of the target verification rule.
5. The method according to claim 3 or 4, characterized in that Before parsing the calculation factor indicated by the target verification rule from the target service message, the method further includes: According to a preset field included in the destination address of the target service message, a target verification rule corresponding to the preset field is determined, wherein the preset field includes a network prefix and a subnet address of the destination address.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Querying a release list according to a source address of the target service message and a destination address of the target service message, wherein the release list includes at least one release record for recording a source address and a destination address accessed by the source address; The step of determining a target verification rule corresponding to a preset field according to a preset field included in a destination address of the target service message comprises: In the case that the release list does not include the first release record, a target verification rule corresponding to the preset field is determined according to the preset field; wherein the first release record is used to record the source address of the target business message and the destination address of the target business message.
7. The method according to claim 6, characterized in that The method further comprises: When the verification field included in the target service message is successfully verified according to the target verification rule, the first release record is added to the release list.
8. The method according to claim 7, characterized in that The security module is deployed in the gateway of the server, and the method further includes: sending the target verification rule to a forwarding node that is reachable to the gateway; or, Send the first release record to the forwarding node.
9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: In response to a verification failure, and / or when the destination address of the target service message exists in a blocking list, the target service message is blocked, and the blocking list is used to record the destination addresses of service messages that are prohibited from being forwarded to the next hop node.
10. The method according to any one of claims 1 to 9, characterized in that When the destination address of the target service message is an Internet Protocol version 6 IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes the verification field of the target service message; When the destination address of the target service message is an Internet Protocol version 4 IPv4 address, the option field of the target service message includes a verification field of the target service message.
11. A message transmission method, characterized in that: A method for accessing a target service provided by a server and running on at least one server in at least one cloud data center in one of multiple regions includes: Obtaining a destination address of a target service message to be sent and a verification field corresponding to the destination address, wherein the destination address is an address configured for the client to access the target service, and the verification field is calculated based on a target verification rule corresponding to the destination address; The target service message is sent, where the target service message includes the verification field, and the target service message is used to access the target service.
12. The method according to claim 11, characterized in that The sending of the target service message comprises: The target service message is sent within the validity period of the destination address of the target service message.
13. The method according to claim 11 or 12, characterized in that: The client is pre-set with the target verification rule and a plurality of pre-set fields, wherein the pre-set fields include a network prefix of a business network where the target service is deployed and a subnet address of a server providing the target service in the business network; In a case where the destination address of the target service message includes the verification field, the acquiring the destination address of the target service message to be sent and the verification field corresponding to the destination address includes: Selecting a target preset field from the plurality of preset fields; Calculate the verification field according to the target verification rule; The target preset field and the verification field are concatenated to obtain the destination address of the target service message.
14. The method according to claim 11 or 12, characterized in that: The client is configured with the target verification rule and multiple access addresses of the target service, and the obtaining of the destination address of the target service message to be sent and the verification field corresponding to the destination address includes: Selecting a destination address of the target service message from the multiple access addresses; The verification field is calculated according to the target verification rule.
15. The method according to claim 13 or 14, characterized in that The step of calculating the verification field according to the target verification rule includes: Using a preset algorithm indicated by the target verification rule, calculating the calculation factor indicated by the target verification rule to obtain the verification field; Among them, the preset algorithm is an encryption algorithm or a hash algorithm; the calculation factors include at least one of the following: the service identifier ID of the target service, the operator of the network to which the client belongs, the service level of the client, the credibility of the client, the credibility of the gateway of the client, the credibility of the area where the client is located, the Internet Interconnection Protocol IP address of the client, the area where the client is located, the subnet number of the network to which the client belongs, the device type of the client, the device ID of the client, the gateway type of the client, the time when the client generates the service message, and the effective duration of the target verification rule.
16. The method according to claim 11 or 12, characterized in that: The obtaining of the destination address of the target service message to be sent and the verification field corresponding to the destination address includes: Sending an address request, where the address request is used to request to obtain the destination address of the target service message; Receive the destination address of the target service message, where the destination address carries a verification field corresponding to the destination address.
17. The method according to any one of claims 11 to 16, characterized in that When the destination address of the target service message is an Internet Protocol version 6 IPv6 address, the destination address includes a verification field of the target service message, or the option field of the target service message includes the verification field of the target service message; or, When the destination address of the target service message is an Internet Protocol version 4 IPv4 address, the option field of the target service message includes a verification field of the target service message.
18. A message transmission device, characterized in that: A security module applied to a server, the server being used to provide a target service to a client, the target service running on at least one server in at least one cloud data center located in one of the multiple regions, the device comprising: A receiving unit, configured to receive a target service message sent by the client, wherein the target service message is used to access the target service, and the target service message includes a verification field; A processing unit, configured to verify the verification field included in the target service message according to a preset target verification rule; A sending unit is used to send the target service message to the server in response to successful verification, wherein the successful verification is used to indicate that the destination address of the target service message is the address configured for the client to access the target service.
19. A message transmission device, characterized in that: A client for accessing a target service, wherein the target service is a service provided by a server, and the target service is run on at least one server in at least one cloud data center located in one of multiple regions, wherein the device comprises: an acquisition unit, configured to acquire a destination address of a target service message to be sent and a verification field corresponding to the destination address, wherein the destination address is an address configured for the client to access the target service, and the verification field is calculated based on a target verification rule corresponding to the destination address; A sending unit is used to send the target service message, where the target service message includes the verification field, and the target service message is used to access the target service.
20. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 10 or claims 11 to 17.
21. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device, the computing device is caused to perform the method according to any one of claims 1 to 10 or claims 11 to 17.
22. A computer-readable storage medium, characterized in that: The method comprises computer program instructions which, when executed by a computing device, cause the computing device to perform the method of any one of claims 1 to 10 or claims 11 to 17.
Citation Information
Cited By
Automatic flight data updating method and system based on message source
CN120950509A