Router network control method and device, equipment and storage medium
By obtaining platform manipulation instructions and protocol stack firewalls, filtering and intercepting router's network access packets, the problem of poor network access control in the router bridge mode in the existing technology is solved, and comprehensive network access control and network security are improved for the router.
Patent Information
- Application Number
- CN202510141646.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-23
AI Technical Summary
The prior art is difficult to effectively control network access in the router's bridge mode, and cannot fully control the router's IPv4 and IPv6 data traffic, making it difficult to achieve network access control of all down-hook devices.
By obtaining platform manipulation instructions and protocol stack firewall, filtering network access data and performing packet interception, determining the intercepting packets, and controlling the router to block or restore network access based on these instructions and packets.
It realizes comprehensive network access control of the router in different working modes, enhances network security, improves the router's data processing efficiency, and supports multiple network protocols.
Smart Images

Figure CN120034486A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network communication and router control, and in particular to a router network control method, device, equipment and storage medium. Background Art
[0002] With the popularization of the Internet and the diversification of network services, operators have put forward higher requirements for the management and control of network equipment. Each operator has its own customized routing equipment for accessing the Internet. In order to ensure the security and stability of the network, operators need a technical means to effectively control the network access range of the router so that it can only run within the network of the operator, thereby preventing the abuse of network resources and improving the overall performance and security of the network. Therefore, it is necessary to completely control the router IPV4 / V6 data traffic to run only within the network of its own operator to achieve the effect of locking the network.
[0003] At present, the existing practice is mainly to control and forward the wired data of the router through the routing mode. However, the existing practice does not perform well in the bridge mode of the router. In the bridge mode, the wired data of the router will be directly forwarded through the switching chip. The router CPU will not receive the data packet, so it cannot be directly controlled. To control the data packet, it is necessary to control the CPU processing through the switching chip hard ACL control. The CPU cannot directly process the data packet, resulting in the inability to effectively control network access, and the inability to fully control the IPv4 and IPv6 data traffic of the router, making it difficult to achieve network access control for all downstream devices. Therefore, how to make the router bridge mode and routing mode compatible and fully and effectively control the router network has become an urgent problem to be solved.
[0004] The above contents are only used to assist in understanding the technical solution of the present application and do not constitute an admission that the above contents are prior art. Summary of the invention
[0005] The main purpose of this application is to provide a router network control method, device, equipment and storage medium, aiming to solve the technical problem of how to be compatible with router bridge mode and routing mode and comprehensively and effectively control the router network.
[0006] To achieve the above object, the present application proposes a router network control method, the method comprising:
[0007] Obtaining platform control instructions and a protocol stack firewall, wherein the platform control instructions include a platform network lock instruction and a platform unlock instruction;
[0008] Screening network access data based on the platform control instructions and the protocol stack firewall, and intercepting data packets to determine the intercepted data packets;
[0009] The router is controlled to block or restore network access based on the platform control instruction and the intercepted data packet.
[0010] In one embodiment, the step of obtaining the platform control instruction and the protocol stack firewall includes:
[0011] Obtaining router address information, platform address information, and a firewall screening rule set, wherein the router address information includes a media access control address and a public network address;
[0012] Identifying a device based on the router address information and the platform address information, and determining a platform control instruction;
[0013] A protocol stack firewall is constructed based on the firewall screening rule set.
[0014] In one embodiment, the step of screening network access data based on the platform control instruction and the protocol stack firewall and intercepting data packets, and determining to intercept data packets includes:
[0015] Triggering the router working mode based on the platform control instruction, and determining that the router filters the data packet;
[0016] The router filters and intercepts the data packet based on the protocol stack firewall to obtain the intercepted data packet.
[0017] In one embodiment, the step of triggering the router working mode based on the platform control instruction and determining that the router filters the data packet includes:
[0018] Get the router communication mode status and router filtering rules;
[0019] When the platform control instruction is a platform network lock instruction and the communication mode state of the router is a bridge mode, the router switching chip is controlled to perform an interactive operation on the port data packet based on the router screening rule to obtain a router screening data packet, wherein the interactive operation includes a screening operation, a forwarding operation and a clearing operation;
[0020] When the platform control instruction is a platform unlock instruction and the communication mode state of the router is a bridge mode, clearing the router screening rule, controlling the router switching chip to process the port data packet, and obtaining the router screening data packet;
[0021] When the platform control instruction is a platform network lock instruction and the router communication mode state is a routing mode or the platform control instruction is a platform unlock instruction and the router communication mode state is a routing mode, the router is controlled to process the port data packet to obtain a router screening data packet.
[0022] In one embodiment, the step of intercepting the router screening data packets based on the protocol stack firewall to obtain the intercepted data packets includes:
[0023] Based on the router screening the data packets to identify and forward the redirected data packets, determine the data packets to be intercepted;
[0024] The data packet to be intercepted is intercepted based on the protocol stack firewall to obtain an intercepted data packet, wherein the intercepted data packet includes a first intercepted data packet and a second intercepted data packet.
[0025] In one embodiment, the step of controlling the router to block or restore network access based on the platform control instruction and the intercepted data packet includes:
[0026] When the platform control instruction is a platform network lock instruction, the router is controlled based on the intercepted data packet to disable all downstream devices from accessing the network, and a window pops up on a designated page to prompt the customer that the customer is not in the correct network;
[0027] When the platform control instruction is a platform unlocking instruction, the router is controlled based on the intercepted data packet to restore network access for all downstream devices.
[0028] In one embodiment, the step of controlling the router to disable all downstream devices from accessing the network based on the intercepted data packet and popping up a window to a specified page to prompt the client that the client is not in the correct network includes:
[0029] Obtain communication request information and network hijacking status;
[0030] The communication request information is parsed based on the network hijacking status to limit domain name access and direct it to a router communication interface.
[0031] In addition, to achieve the above purpose, the present application also proposes a router network control device, the router network control device comprising:
[0032] An acquisition module is used to acquire platform control instructions and a protocol stack firewall, wherein the platform control instructions include platform network lock instructions and platform unlock instructions;
[0033] A processing module, used to screen network access data based on the platform control instruction and the protocol stack firewall, and intercept data packets to determine intercepted data packets;
[0034] The execution module is used to control the router to block or restore network access based on the platform control instruction and the intercepted data packet.
[0035] In addition, to achieve the above-mentioned purpose, the present application also proposes a router network control device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the router network control method as described above.
[0036] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the router network control method described above are implemented.
[0037] One or more technical solutions proposed in this application have at least the following technical effects:
[0038] This embodiment proposes a router network control method, which obtains platform control instructions and a protocol stack firewall, wherein the platform control instructions include a platform network locking instruction and a platform unlocking instruction; based on the platform control instructions and the protocol stack firewall, the network access data is screened, and data packets are intercepted to determine the intercepted data packets; based on the platform control instructions and the intercepted data packets, the router is controlled to block or restore network access. This application obtains platform control instructions, combines the protocol stack firewall to screen network access data and intercept data packets, thereby controlling the router to block or restore network access. Regardless of whether the device is working in bridge mode or routing mode, it can completely control the disconnection of all downstream devices from accessing the network, and after locking the network, all data forwarded through the router are closed, thereby achieving comprehensive network access control of the router in different working modes, and can also support multiple network protocols, effectively enhancing the security of the network, and improving the data processing efficiency of the router. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0040] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0041] Figure 1 A flowchart of the first embodiment of the router network control method of the present application is provided;
[0042] Figure 2 This is a data upload flow chart of the router network control method of this application;
[0043] Figure 3 This is the flow chart of router network locking for the router network control method of this application;
[0044] Figure 4 This is the router network control method and router unlocking network flow chart of this application;
[0045] Figure 5 A flowchart of the second embodiment of the router network control method of the present application is provided;
[0046] Figure 6 This is a schematic diagram of the module structure of the router network control device according to an embodiment of the present application;
[0047] Figure 7 Schematic diagram of the device structure of the hardware operating environment involved in the router network control method in the embodiment of the present application.
[0048] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0049] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0050] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0051] The main solution of the embodiment of the present application is: obtaining platform control instructions and a protocol stack firewall, the platform control instructions including platform network lock instructions and platform unlock instructions; based on the platform control instructions and the protocol stack firewall, filtering network access data, intercepting data packets, and determining intercepted data packets; based on the platform control instructions and the intercepted data packets, controlling the router to block or restore network access.
[0052] In this embodiment, for the convenience of description, the following description is made by taking the identification of the router network control device as the execution subject.
[0053] Because the existing technology performs poorly in the bridge mode of the router, the wired data of the router in the bridge mode will be forwarded directly through the switching chip, and the router CPU will not receive the data packet, so it cannot be directly controlled. In order to control the data packet, it is necessary to control the CPU processing through the switching chip hard ACL control. The CPU cannot directly process the data packet, resulting in the inability to effectively control network access, and the inability to fully control the IPv4 and IPv6 data traffic of the router, making it difficult to achieve network access control for all downstream devices.
[0054] The present application provides a solution, which obtains platform control instructions and a protocol stack firewall, wherein the platform control instructions include a platform network lock instruction and a platform unlock instruction; based on the platform control instructions and the protocol stack firewall, network access data is screened, and data packets are intercepted to determine the intercepted data packets; based on the platform control instructions and the intercepted data packets, a router is controlled to block or restore network access.
[0055] It can be seen from the above embodiments that the present application obtains platform control instructions, combines the protocol stack firewall to screen network access data and intercept data packets, thereby controlling the router to block or restore network access. Regardless of whether the device is working in bridge mode or routing mode, it can completely control the disconnection of all downstream devices from accessing the network, and after locking the network, all data forwarded through the router are blocked, thereby achieving comprehensive network access control of the router in different working modes, and can also support multiple network protocols, effectively enhancing the security of the network, and improving the data processing efficiency of the router.
[0056] Based on this, the embodiment of the present application provides a router network control method, referring to Figure 1 , Figure 1 This is a flowchart of the first embodiment of the router network control method of the present application.
[0057] In this embodiment, the router network control method includes steps S10 to S30:
[0058] Step S10, obtaining a platform control instruction and a protocol stack firewall, wherein the platform control instruction includes a platform network lock instruction and a platform unlock instruction;
[0059] It should be noted that the platform control instruction reflects the characteristics of the remote control instruction for the network access status of the router, and the protocol stack firewall reflects the characteristics of screening and intercepting network access data according to preset rules.
[0060] It can be understood that the platform control instructions can represent the router's execution of operations to block or restore network access, ensuring that the router can only operate within the network specified by the operator, and the protocol stack firewall can represent the refined management of network data traffic and achieve precise control of specific data packets.
[0061] For ease of understanding, the example of obtaining platform control instructions and protocol stack firewall is used for explanation, wherein the information collection device is an information collection module, and the storage device is a memory.
[0062] The information collection module obtains the router address information, that is, after the router is connected to the network, it needs to report its own MAC and public network address to the operator platform, such as Figure 2 As shown, Figure 2For the data upload flow chart of the router network control method of this application, the device is turned on, the operator platform docking process is started, and its own status data, including MAC, is reported to the platform. The network address where it is running is obtained, that is, the operator platform will set the operator's internal IP, identify the device based on the router address information and the platform address information, and determine the platform control instruction. That is, the operator platform finds that the device's public network address is not the operator's internal IP and issues a network lock instruction to the device. After the router receives the network lock instruction, no matter whether the router works in bridge mode or routing mode, it needs to be able to disable all downstream devices from accessing the network, and pop up a window to the specified page to prompt the customer that they are not in the correct network. After the router receives the unlock instruction, it restores the ability of all downstream devices to access the network, obtains a firewall screening rule set, such as a layer 2 firewall and a layer 3 firewall, and builds a protocol stack firewall based on the firewall screening rule set, and performs subsequent processing based on the platform control instruction and the protocol stack firewall.
[0063] In a feasible implementation, step S10 may include steps A11 to A13:
[0064] Step A11, obtaining router address information, platform address information and a firewall screening rule set, wherein the router address information includes a media access control address and a public network address;
[0065] It should be noted that the router address information reflects the unique identity and location characteristics of the router in the network, the platform address information reflects the identity and network location characteristics of the operator-controlled platform, and the firewall screening rule set reflects the characteristics of intercepting specific data packets to manage network traffic.
[0066] It can be understood that the router address information is used to identify and locate the specific location of the router in the operator's network, the platform address information is used to ensure that the router can correctly connect to the operator's management platform and receive instructions, and the firewall screening rule set is used to define which data packets can be intercepted, released or redirected, thereby achieving precise control over network access.
[0067] Step A12, identifying a device based on the router address information and the platform address information, and determining a platform control instruction;
[0068] It can be understood that by combining the router address information and the platform address information, it is possible to accurately identify whether the router device is a device provided by the operator, thereby effectively preventing the router from being used illegally and restricting its operation to the network specified by the operator. The access policy can be flexibly adjusted according to different network environments and needs, significantly improving the degree of automation of network management and reducing operation and maintenance costs.
[0069] Step A13: Building a protocol stack firewall based on the firewall screening rule set.
[0070] It is understandable that by building a protocol stack firewall, comprehensive control of router network access can be achieved. Regardless of whether the router is in bridge mode or routing mode, it can effectively block illegal access and ensure the security and stability of the network. It also supports multiple network protocols, such as IPv4 and IPv6 protocols, which significantly enhances the adaptability of the router in complex network environments. At the same time, through precise data packet interception and processing, it significantly improves the operating efficiency of the router and enhances the user experience.
[0071] Step S20, screening network access data based on the platform control instruction and the protocol stack firewall, and intercepting data packets to determine intercepted data packets;
[0072] It should be noted that the intercepted data packets reflect the characteristics of the data packets after being screened by the protocol stack firewall and intercepted as the data packets that are identified as not complying with the network access policy.
[0073] For ease of understanding, the following is explained by taking the determination of intercepted data packets as an example, wherein the information collection device is an information collection module, the storage device is a memory, and the processing device is a processing module.
[0074] The information collection module obtains the communication mode status of the router, such as bridge mode and routing mode, and obtains the router filtering rules, such as the rule for filtering the CPU entering the protocol stack on http port 80 packets, the rule for filtering the CPU entering the protocol stack on https port 443 packets, the rule for allowing DHCP port 67 and 68 forwarding, the rule for filtering the CPU entering the protocol stack on DNS port 53 packets, and the rule for discarding all other IPV4 and IPV6 packets.
[0075] When the platform control instruction is a platform network locking instruction and the communication mode state of the router is a bridge mode, the router switching chip is controlled to perform interactive operations on the port data packet based on the router screening rule to obtain a router screening data packet. The interactive operation includes a screening operation, a forwarding operation and a clearing operation, that is, judging whether it is a bridge mode. In the bridge mode, the router wired data will be directly forwarded through the switching chip, and the router CPU will not receive the data packet, so it cannot be directly controlled. If you want to control the data packet, you need to control the CPU processing through the switching chip hard ACL control. At this time, the router screening rule is used to perform the network locking action to obtain a router screening data packet. When the platform control instruction is a platform unlocking instruction and the communication mode state of the router is a bridge mode, the router screening rule is cleared, and the router switching chip is controlled to process the port data packet to obtain a router screening data packet. When the platform control instruction is a platform network locking instruction and the communication mode state of the router is a routing mode or the platform control instruction is a platform unlocking instruction and the communication mode state of the router is a routing mode, the router is controlled to process the port data packet to obtain a router screening data packet.
[0076] Based on the router screening data packets, identifying and forwarding redirected data packets, determining the data packets to be intercepted, that is, the routing mode data packets will automatically go to the CPU for protocol stack processing, sending the access data of ports 80, 443, and 53 of the wired device in bridge mode to the CPU for entering the protocol stack, and the wireless WIFI access data will automatically enter the protocol stack regardless of whether it is in bridge mode or routing mode. WIFI uses other interfaces to connect to the CPU, such as PCIE, to obtain the data packets to be intercepted, that is, to enter the protocol stack data, and intercept the data packets to be intercepted based on the protocol stack firewall to obtain intercepted data packets, and the intercepted data packets include a first intercepted data packet and a second intercepted data packet. Data packets, the first intercepted data packet is regarded as the data packet obtained after being intercepted by the second-layer firewall, and the second intercepted data packet is regarded as the data packet obtained after being intercepted by the third-layer firewall. The data entering the protocol stack is first captured by the second-layer firewall. The second-layer firewall controls the data packets accessing ports 80 and 443 to be directly discarded and redirected by the third-layer. The second layer no longer checks, and the second-layer firewall discards all IPV6 data packets. The second-layer firewall allows ARP, DNS, DHCP and other IPV4 data packets to be forwarded normally. The purpose is to allow the router-mounted devices to obtain IP normally and perform DNS resolution. Then, the data packet is captured by the third-layer firewall, and all other IPV4 IPV6 data packets are discarded. The data packet of interest at port 80 443 is redirected to the router LAN port IP to obtain the intercepted data packet. The router LAN port IP is the logical IP on the LAN side of the device. This IP exists in both routing mode and bridge mode, and subsequent processing is performed based on the intercepted data packet.
[0077] Step S30, controlling the router to block or restore network access based on the platform control instruction and the intercepted data packet.
[0078] It is understandable that by controlling instructions and intercepting data packets on the platform, comprehensive, flexible and precise control over router network access can be achieved. By intercepting data packets that do not comply with regulations, user privacy and data security can be effectively protected. Network traffic can also be better monitored and managed, network performance can be optimized, operation and maintenance costs can be reduced, and the degree of automation of network management can be improved.
[0079] For ease of understanding, the example of obtaining platform control instructions and intercepting data packets is used for explanation, wherein the information collection device is the information collection module, the storage device is the memory, and the execution device is the execution module.
[0080] The information collection module obtains platform control instructions and intercepts data packets, such as Figure 3 As shown, Figure 3The router network control method of this application is a flow chart of router network locking. The platform docking process receives the platform network locking instruction and determines whether it is in bridge mode. If not, it enters the routing mode and directly passes through the protocol stack layer 2 firewall ebtables to enable the 80 443 port data packet to be processed on the third layer. If so, the router switch chip hardware access control list ACL is turned on. The router switch chip filters the http 80 port data packet on the CPU. The router switch chip filters the http 443 port data packet on the CPU. The router switch chip allows DHCP67 and 68 port forwarding. The router switch chip filters DNS 53 port data packet on the CPU. The router switch chip discards all IPV4 data packets and then passes through the protocol stack layer 2 firewall ebtables to enable the 80 443 port data packet to be processed on the third layer. Regardless of whether it is in bridge mode or routing mode, the protocol stack layer 2 firewall ebtables allows ARP DNS (UDP 53) DHCP (UDP67, 68) forwarding. Through the protocol stack layer 3 firewall ebtables, IPV4 IPV6 data packet forwarding is discarded. Through the protocol stack layer 3 firewall ebtables, all access to 80 is redirected. 443 port data to the router LAN port IP, domain name hijacking is enabled, all domain names are resolved into the router LAN IP, the router LAN port receives 80 443 access in the network lock mode, returns the network lock prompt page to the customer, the action is completed, the router receives the platform network lock instruction, executes the network lock action, and obtains the communication request information and the network hijacking status when the platform control instruction is the platform network lock instruction. Based on the network hijacking status, the communication request information is parsed to limit the domain name access and guide it to the router communication interface, that is, DNS hijacking is enabled. Regardless of the wired or wireless hanging device, the DNS request is resolved into the router's own LAN port IP. All domain name access of the hanging device is directed to the router LAN port. In the network lock mode, the router LAN port receives 80 or 443 port access and responds to the prompt page to the customer, such as Figure 4 As shown, Figure 4For the router network control method of this application, the router unlocking network flow chart, the platform docking process receives the platform unlocking instruction, determines whether it is bridge mode, if not, enters the routing mode and directly clears the second-layer firewall ebtables, and promotes the third-layer rules for 80 443 port data packets. If so, the router clears the CPU rules for filtering http 80 port data packets, clears the CPU rules for filtering http 443 port data packets, clears the rules for allowing DHCP 67, 68 port forwarding, clears the CPU rules for filtering DNS 53 port data packets, clears the rules for discarding all IPV6 data packets, clears the second-layer firewall ebtables, and promotes the third-layer processing rules for 80 443 port data packets, clears the second-layer firewall ebtables to discard all IPV6 data packets, clears the second-layer firewall ebtables to allow ARP DNS (UDP 53) DHCP (UDP67, 68) forwarding rules, clears the third-layer firewall ebtables, discards IPV4 IPV6 data packet forwarding rules, clears the third-layer firewall ebtables, redirects all access to 80 The data of port 443 is sent to the IP rule of the router LAN port, domain name hijacking is turned off, the router UI resumes normal access mode, the action is completed, the router receives the platform unlocking instruction, executes the unlocking action, and when the platform control instruction is the platform unlocking instruction, the router is controlled based on the intercepted data packet to resume network access for all downstream devices, clear all rules executed by the lock network, restore normal network status, access the router through ports 80 and 443, and the UI interface can respond to normal information.
[0081] In a feasible implementation, step S30 may include steps B11 to B12:
[0082] Step B11, when the platform control instruction is a platform network lock instruction, based on the intercepted data packet, the router is controlled to disable all downstream devices from accessing the network, and a window pops up on a designated page to prompt the customer that the customer is not in the correct network;
[0083] It can be understood that by identifying the platform network lock instruction, the router can explicitly execute the operation of disabling all downstream devices from accessing the network, ensuring strict control of network access, and intercepting data packets to accurately identify data traffic that does not comply with network access policies, thereby blocking specific traffic and enhancing network security.
[0084] In a feasible implementation, step B11 may include steps C11 to C13:
[0085] Step C11, obtaining communication request information and network hijacking status;
[0086] It should be noted that the communication request information reflects the characteristics of the network access request initiated by the user equipment, and the network hijacking status reflects the characteristics of the router intervening and controlling the network access request.
[0087] It can be understood that the communication request information may include the request source, request destination address, request protocol type and request specific content. The request source may include the device IP address and MAC address, the request destination address may include the target domain name and IP address, the request protocol type may include HTTP and HTTPS protocols, and the request specific content may include accessed web pages and service types. The network hijacking status can indicate whether the router has activated the DNS hijacking function, as well as the target address after hijacking, such as the router's own LAN port IP, thereby determining whether the DNS request of the user device is redirected to the specified prompt page, thereby guiding and managing user access behavior.
[0088] Step C12, parsing the communication request information based on the network hijacking status to limit domain name access and direct it to the router communication interface.
[0089] It is understandable that by accurately identifying communication request information and combining it with the network hijacking status, the network access behavior of user devices can be effectively managed and controlled to ensure that it complies with the operator's network policy. When users try to access a network that does not comply with the policy, they are directed to the same router communication interface and informed of the current network status in a timely manner through a pop-up prompt page, thereby avoiding unnecessary troubles for users due to network restrictions.
[0090] Step B12, when the platform control instruction is a platform unlock instruction, based on the intercepted data packet, the router is controlled to restore network access for all downstream devices.
[0091] It is understandable that the platform control instructions are the core of the operation, which are used to limit or restore the access ability of the network and ensure the flexibility of network access. The unlocking instructions not only restore the transmission of data packets, but also clear all rules related to locking the network, so that the router returns to normal working state and ensures that all downstream devices can access the network normally.
[0092] This embodiment proposes a method for controlling a router network, which obtains a platform control instruction and a protocol stack firewall, wherein the platform control instruction includes a platform network lock instruction and a platform unlock instruction; based on the platform control instruction and the protocol stack firewall, the network access data is screened, and data packets are intercepted to determine the intercepted data packets; based on the platform control instruction and the intercepted data packets, the router is controlled to block or restore network access. The technical problem of how to effectively control the router network is solved. Compared with the prior art, the present application uses platform control instructions and a protocol stack firewall to screen network access data and intercept data packets that do not comply with the policy, thereby controlling the router to block or restore network access. It is not only compatible with bridge mode and routing mode, but also can effectively enhance network security, improve network management efficiency, optimize user experience, and significantly improve the adaptability and data processing efficiency of the router in a complex network environment.
[0093] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above-mentioned embodiment 1 can be referred to the above introduction and will not be repeated later.
[0094] In this embodiment, refer to Figure 5 , Figure 5 This is a flow chart of the second embodiment of the router network control method of the present application, wherein step S20 specifically includes steps S21 to S22:
[0095] Step S21, triggering the router working mode based on the platform control instruction, and determining that the router filters the data packet;
[0096] It should be noted that the router screening data packets reflects the characteristics of the router classifying and screening network traffic in different working modes.
[0097] It is understandable that the router filters data packets including the source of the data packet, the destination address, the protocol type and the transmission direction. The source of the data packet may include the MAC address and the IP address, the protocol type may include HTTP, HTTPS and DNS protocols, and the transmission direction may include upstream or downstream.
[0098] In addition, it should be noted that the rules for router data packet screening can be dynamically adjusted according to the platform control instructions to flexibly respond to different network policy requirements. Whether it is locking the network or unlocking it, it can respond and execute quickly, and effectively distinguish and control various network traffic, thereby improving the overall performance and security of the network.
[0099] For ease of understanding, the example of determining that a router filters data packets is used for explanation, wherein the information collection device is an information collection module, the storage device is a memory, and the processing device is a processing module.
[0100] The information collection module obtains the platform control instruction, triggers the router working mode based on the platform control instruction, obtains the router communication mode status, such as bridge mode and routing mode, and obtains the router screening rules, such as the CPU entry protocol stack rule for filtering http port 80 data packets, the CPU entry protocol stack rule for filtering https port 443 data packets, the rule of allowing DHCP67, 68 port forwarding, the rule of filtering DNS port 53 data packets for CPU entry protocol stack and the rule of discarding all other IPV4 and IPV6 data packets.
[0101] When the platform control instruction is a platform network locking instruction and the communication mode state of the router is a bridge mode, the router switching chip is controlled to perform interactive operations on the port data packet based on the router screening rule to obtain a router screening data packet. The interactive operation includes a screening operation, a forwarding operation and a clearing operation, that is, judging whether it is a bridge mode. In the bridge mode, the router wired data will be directly forwarded through the switching chip, and the router CPU will not receive the data packet, so it cannot be directly controlled. If you want to control the data packet, you need to control the CPU processing through the switching chip hard ACL control. At this time, the router screening rule is used to perform the network locking action to obtain a router screening data packet. When the platform control instruction is a platform unlocking instruction and the communication mode state of the router is a bridge mode, the router screening rule is cleared, and the router switching chip is controlled to process the port data packet to obtain a router screening data packet. When the platform control instruction is a platform network locking instruction and the communication mode state of the router is a routing mode or the platform control instruction is a platform unlocking instruction and the communication mode state of the router is a routing mode, the router is controlled to process the port data packet to obtain a router screening data packet.
[0102] In a feasible implementation, step S21 may include steps D11 to D14:
[0103] Step D11, obtaining the router communication mode status and router screening rules;
[0104] It should be noted that the router communication mode state reflects the characteristics of the router's current working mode, and the router screening rules reflect the characteristics of the specific rules for the router to classify and screen data packets according to platform control instructions and preset strategies.
[0105] It can be understood that the router communication mode states include bridge mode and routing mode. In bridge mode, the router's wired data is directly forwarded through the switching chip, and the data packets are not processed by the CPU. Therefore, traffic control is required through hardware ACL. In routing mode, the data packets will enter the CPU protocol stack for processing and can be directly controlled by software rules. The router screening rules are used to screen the data on the switching chip to achieve network control.
[0106] Step D12, when the platform control instruction is a platform network lock instruction and the communication mode state of the router is a bridge mode, based on the router screening rule, the router switching chip is controlled to perform an interactive operation on the port data packet to obtain a router screening data packet, and the interactive operation includes a screening operation, a forwarding operation and a clearing operation;
[0107] It can be understood that by implementing traffic screening in bridge mode through hardware ACL, data packets that comply with the operator's policy can pass through, effectively preventing illegal access and network abuse, and enhancing network security. The platform control instructions can dynamically adjust the behavior of the router, making network management more flexible, able to quickly respond to changes in the operator's policy, and adapt to different network environments and needs.
[0108] Step D13, when the platform control instruction is a platform unlock instruction and the communication mode state of the router is a bridge mode, clear the router screening rule, control the router switching chip to process the port data packet, and obtain the router screening data packet;
[0109] It is understandable that through the platform unlocking command, network access can be quickly restored, ensuring that users can flexibly access the network when needed, and quickly clearing filtering rules and restoring network access, reducing user waiting time and avoiding inconvenience caused by network restrictions.
[0110] Step D14, when the platform control instruction is a platform network lock instruction and the router communication mode state is a routing mode or the platform control instruction is a platform unlock instruction and the router communication mode state is a routing mode, control the router to process the port data packet to obtain a router screening data packet.
[0111] It is understandable that by dynamically adjusting the processing rules of data packets according to the platform control instructions, the router can flexibly control network access in routing mode, and can respond and execute quickly whether locking or unlocking the network.
[0112] Step S22: intercepting the data packet screened by the router based on the protocol stack firewall to obtain an intercepted data packet.
[0113] It can be understood that the intercepted data packet can represent the data packet obtained after intercepting and screening illegal access requests, unauthorized network traffic or specific protocol data packets that do not comply with the operator's regulations, ensuring that only traffic that complies with the regulations can pass through the router, effectively preventing illegal or unauthorized network access, and ensuring that the router can only operate within the network specified by the operator, significantly enhancing the security of the network, preventing network attacks and illegal access, and avoiding unnecessary traffic from occupying network resources, thereby improving privacy and security.
[0114] For ease of understanding, the example of obtaining a protocol stack firewall and a router to filter data packets is used for explanation, wherein the information collection device is an information collection module, the storage device is a memory, and the processing device is a processing module.
[0115] The information acquisition module obtains the protocol stack firewall and the router to filter the data packets, identifies and forwards the redirected data packets based on the router filtering data packets, determines the data packets to be intercepted, that is, the routing mode data packets will automatically go to the CPU for protocol stack processing, and sends the access data of ports 80, 443, and 53 of the wired device in bridge mode to the CPU to enter the protocol stack. The wireless WIFI access data will automatically enter the protocol stack regardless of whether it is in bridge mode or routing mode. WIFI uses other interfaces to connect to the CPU, such as PCIE, to obtain the data packets to be intercepted, that is, enter the protocol stack data, intercept the data packets to be intercepted based on the protocol stack firewall, and obtain the intercepted data packets, which include The first intercepted data packet and the second intercepted data packet, the first intercepted data packet is regarded as the data packet obtained after being intercepted by the second-layer firewall, and the second intercepted data packet is regarded as the data packet obtained after being intercepted by the third-layer firewall. The data entering the protocol stack is first captured by the second-layer firewall. The second-layer firewall controls the data packets accessing ports 80 and 443 to be directly discarded and redirected by the third-layer. The second layer no longer checks, and the second-layer firewall discards all IPV6 data packets. The second-layer firewall allows ARP, DNS, DHCP and other IPV4 data packets to be forwarded normally. The purpose is to allow the router's downstream devices to obtain IP normally and perform DNS resolution. Then, the data packet is captured by the third-layer firewall, and all other IPV4 IPV6 data packets are discarded. The data packets of interest on ports 80 and 443 are redirected to the router LAN port IP, thereby obtaining the intercepted data packet.
[0116] In a feasible implementation, step S22 may include steps E11 to E12:
[0117] Step E11, based on the router screening the data packets, identifying and forwarding the redirected data packets, determining the data packets to be intercepted;
[0118] It should be noted that the data packets to be intercepted reflect the characteristics of the data packets that meet specific conditions and need to be further processed after being screened by the router.
[0119] It can be understood that the data packets to be intercepted are mainly data packets of HTTP and HTTPS protocols, and are mainly uplink data packets, that is, request data packets sent from devices hanging under the router to the external network. They are common application layer protocols in network access and are used for operations such as web browsing and data transmission. They can be devices hanging under the router, such as user terminals, and the destination address is usually a server in the external network.
[0120] Step E12: intercepting the data packet to be intercepted based on the protocol stack firewall to obtain an intercepted data packet, wherein the intercepted data packet includes a first intercepted data packet and a second intercepted data packet.
[0121] It can be understood that by accurately identifying and intercepting data packets that do not comply with the operator's policies, illegal access and network abuse can be effectively prevented, ensuring that the router can only operate within the network specified by the operator, significantly enhancing the security of the network, supporting not only the IPv4 protocol, but also the IPv6 protocol, being able to adapt to complex network environments, and enhancing the adaptability of routers under different network conditions.
[0122] This embodiment proposes a router network control method, which triggers the router working mode based on the platform control instruction, determines the router to filter the data packet; intercepts the router filter data packet based on the protocol stack firewall to obtain the intercepted data packet. It solves the technical problem of how to be compatible with the router bridge mode and the routing mode and perform router network control more comprehensively. Compared with the prior art, this application triggers the router working mode through the platform control instruction, is compatible with the router bridge mode and the routing mode, and uses the protocol stack firewall to intercept the filtered data packet, so as to achieve the fine management of the data packet that does not meet the operator's policy, significantly enhance the network security, improve the flexibility of network management and the data processing efficiency, and optimize the user experience.
[0123] This application also provides a router network control device, please refer to Figure 6 , the router network control device comprises:
[0124] An acquisition module 10 is used to acquire platform control instructions and a protocol stack firewall, wherein the platform control instructions include a platform network lock instruction and a platform unlock instruction;
[0125] The processing module 20 is used to screen the network access data based on the platform control instruction and the protocol stack firewall, and intercept the data packet to determine the intercepted data packet;
[0126] The execution module 30 is used to control the router to block or restore network access based on the platform control instruction and the intercepted data packet.
[0127] The acquisition module 10 is further used to acquire router address information, platform address information and a firewall screening rule set, wherein the router address information includes a media access control address and a public network address;
[0128] Identifying a device based on the router address information and the platform address information, and determining a platform control instruction;
[0129] A protocol stack firewall is constructed based on the firewall screening rule set.
[0130] The processing module 20 is further used to trigger the router working mode based on the platform control instruction and determine that the router filters the data packet;
[0131] The router filters and intercepts the data packet based on the protocol stack firewall to obtain the intercepted data packet.
[0132] The processing module 20 is also used to obtain the router communication mode status and router screening rules;
[0133] When the platform control instruction is a platform network lock instruction and the communication mode state of the router is a bridge mode, the router switching chip is controlled to perform an interactive operation on the port data packet based on the router screening rule to obtain a router screening data packet, wherein the interactive operation includes a screening operation, a forwarding operation and a clearing operation;
[0134] When the platform control instruction is a platform unlock instruction and the communication mode state of the router is a bridge mode, clearing the router screening rule, controlling the router switching chip to process the port data packet, and obtaining the router screening data packet;
[0135] When the platform control instruction is a platform network lock instruction and the router communication mode state is a routing mode or the platform control instruction is a platform unlock instruction and the router communication mode state is a routing mode, the router is controlled to process the port data packet to obtain a router screening data packet.
[0136] The processing module 20 is further used to identify and forward redirected data packets based on the data packets screened by the router, and determine the data packets to be intercepted;
[0137] The data packet to be intercepted is intercepted based on the protocol stack firewall to obtain an intercepted data packet, wherein the intercepted data packet includes a first intercepted data packet and a second intercepted data packet.
[0138] The execution module 30 is further configured to, when the platform control instruction is a platform network lock instruction, control the router based on the intercepted data packet to disable all downstream devices from accessing the network, and pop up a window to a specified page to prompt the customer that the customer is not in the correct network;
[0139] When the platform control instruction is a platform unlocking instruction, the router is controlled based on the intercepted data packet to restore network access for all downstream devices.
[0140] The execution module 30 is also used to obtain communication request information and network hijacking status;
[0141] The communication request information is parsed based on the network hijacking status to limit domain name access and direct it to a router communication interface.
[0142] The router network control device provided by the present application adopts the router network control method in the above embodiment, which can solve the technical problem of how to be compatible with the router bridge mode and the routing mode and comprehensively and effectively perform router network control. Compared with the prior art, the beneficial effects of the router network control device provided by the present application are the same as the beneficial effects of the router network control method provided by the above embodiment, and the other technical features in the router network control device are the same as the features disclosed in the above embodiment method, which will not be repeated here.
[0143] The present application provides a router network control device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the router network control method in the above-mentioned embodiment 1.
[0144] Reference below Figure 7 , which shows a schematic diagram of the structure of a router network control device suitable for implementing the embodiment of the present application. The router network control device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The router network control device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0145] like Figure 7As shown, the router network control device may include a processing device 1001 (e.g., a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in a ROM (Read Only Memory) 1002 or a program loaded from a storage device 1003 to a RAM (Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the router network control device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the router network control device to communicate with other devices wirelessly or wired to exchange data. Although the figure shows a router network control device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or provided instead.
[0146] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0147] The router network control device provided by the present application adopts the router network control method in the above embodiment, which can solve the technical problem of how to be compatible with the router bridge mode and the routing mode and comprehensively and effectively perform router network control. Compared with the prior art, the beneficial effects of the router network control device provided by the present application are the same as the beneficial effects of the router network control method provided by the above embodiment, and the other technical features in the router network control device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0148] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0149] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0150] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the router network control method in the above-mentioned embodiment.
[0151] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0152] The computer-readable storage medium may be included in the router network control device; or may exist independently without being assembled into the router network control device.
[0153] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the router network control device, the router network control device: obtains platform control instructions and a protocol stack firewall, wherein the platform control instructions include platform network lock instructions and platform unlock instructions; based on the platform control instructions and the protocol stack firewall, screens network access data, intercepts data packets, and determines intercepted data packets; and controls the router to block or restore network access based on the platform control instructions and the intercepted data packets.
[0154] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0155] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0156] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0157] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned router network control method, and can solve the technical problem of how to be compatible with the router bridge mode and the routing mode, and comprehensively and effectively perform router network control. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the router network control method provided by the above-mentioned embodiment, and will not be repeated here.
[0158] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A router network control method, characterized in that: The method includes: Obtaining platform control instructions and a protocol stack firewall, wherein the platform control instructions include a platform network lock instruction and a platform unlock instruction; Screening network access data based on the platform control instructions and the protocol stack firewall, and intercepting data packets to determine the intercepted data packets; The router is controlled to block or restore network access based on the platform control instruction and the intercepted data packet.
2. The method according to claim 1, characterized in that The step of obtaining platform control instructions and protocol stack firewall includes: Obtaining router address information, platform address information, and a firewall screening rule set, wherein the router address information includes a media access control address and a public network address; Identifying a device based on the router address information and the platform address information, and determining a platform control instruction; A protocol stack firewall is constructed based on the firewall screening rule set.
3. The method according to claim 1, characterized in that The step of screening network access data based on the platform control instruction and the protocol stack firewall and intercepting data packets, and determining to intercept data packets includes: Triggering the router working mode based on the platform control instruction, and determining that the router filters the data packet; The router filters and intercepts the data packet based on the protocol stack firewall to obtain the intercepted data packet.
4. The method according to claim 3, characterized in that The step of triggering the router working mode based on the platform control instruction and determining that the router filters the data packet comprises: Get the router communication mode status and router filtering rules; When the platform control instruction is a platform network lock instruction and the communication mode state of the router is a bridge mode, the router switching chip is controlled to perform an interactive operation on the port data packet based on the router screening rule to obtain a router screening data packet, wherein the interactive operation includes a screening operation, a forwarding operation and a clearing operation; When the platform control instruction is a platform unlock instruction and the communication mode state of the router is a bridge mode, clearing the router screening rule, controlling the router switching chip to process the port data packet, and obtaining the router screening data packet; When the platform control instruction is a platform network lock instruction and the router communication mode state is a routing mode or the platform control instruction is a platform unlock instruction and the router communication mode state is a routing mode, the router is controlled to process the port data packet to obtain a router screening data packet.
5. The method according to claim 3, characterized in that The step of intercepting the router screening data packets based on the protocol stack firewall to obtain the intercepted data packets comprises: Based on the router screening the data packets to identify and forward the redirected data packets, determine the data packets to be intercepted; The data packet to be intercepted is intercepted based on the protocol stack firewall to obtain an intercepted data packet, wherein the intercepted data packet includes a first intercepted data packet and a second intercepted data packet.
6. The method according to claim 1, characterized in that The step of controlling the router to block or restore network access based on the platform control instruction and the intercepted data packet includes: When the platform control instruction is a platform network lock instruction, the router is controlled based on the intercepted data packet to disable all downstream devices from accessing the network, and a window pops up on a designated page to prompt the customer that the customer is not in the correct network; When the platform control instruction is a platform unlocking instruction, the router is controlled based on the intercepted data packet to restore network access for all downstream devices.
7. The method according to claim 6, characterized in that The steps of controlling the router to disable all downstream devices from accessing the network based on the intercepted data packet and popping up a window to a designated page to prompt the client that the client is not in the correct network include: Obtain communication request information and network hijacking status; The communication request information is parsed based on the network hijacking status to limit domain name access and direct it to a router communication interface.
8. A router network control device, characterized in that: The device comprises: An acquisition module is used to acquire platform control instructions and a protocol stack firewall, wherein the platform control instructions include platform network lock instructions and platform unlock instructions; A processing module, used to screen network access data based on the platform control instruction and the protocol stack firewall, and intercept data packets to determine intercepted data packets; The execution module is used to control the router to block or restore network access based on the platform control instruction and the intercepted data packet.
9. A router network control device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the router network control method according to any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the router network control method according to any one of claims 1 to 7 are implemented.