Message processing method, device, equipment, medium and product

By introducing an address translation mechanism in the security gateway, mapping the public network address into a private network address, the problem of low accuracy of message shunting in the existing technology is solved, and accurate message shunting and high-accurate message shunting are achieved.

CN120201004APending Publication Date: 2025-06-24CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510400084.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, the accuracy of message diversion is low, resulting in many messages that do not need to enter the intranet being diverted into the intranet, reducing the accuracy of message diversion.

Method used

By introducing an address translation mechanism in the security gateway, the public network address of the target website is dynamically mapped into a private network address, so that the diversion end can establish accurate diversion rules based on the private network address rather than the public network address.

Benefits of technology

Ensure that only the service packets that truly access the target website, that is, the message whose destination address is the private network address, will be directed to the intranet channel, while other non-target service packets that share the same public network address will be transmitted according to the normal path, fundamentally avoiding the problem of other packets entering the intranet, realizing precise diversion, and improving the accuracy of message diversion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201004A_ABST
    Figure CN120201004A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a message processing method and device, equipment, a medium and a product, and relates to the technical field of network communication. The method comprises the following steps: receiving a target address sent by an intranet end, and converting the target address into a private network address according to a preset first address conversion rule; sending the private network address to a shunting end, so that the shunting end optimizes a preset first shunting rule according to the private network address to obtain a second shunting rule; and sending the private network address to the user side, so that the user side optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule. According to the method, the public network address of the target website is dynamically mapped into the private network address, so that the shunting end can establish the accurate shunting rule based on the private network address instead of the shared public network address, thereby ensuring that only the service message really accessing the target website can be guided to the intranet channel, avoiding the problem that other messages enter the intranet, and improving the shunting efficiency. And the accurate distribution of the messages is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technologies, and in particular, to a method, apparatus, device, medium, and product for processing packets. Background Art

[0002] To cope with the growing demand for network traffic, network service providers generally adopt address sharing technologies, that is, multiple public network services are set up on a public network node, which alleviates the problem of tight address resources to a certain extent, and also poses higher requirements on the packet splitting mechanism. In the case where multiple services share the same address, how to ensure that the request packet can be accurately sent to the target service has become the key to improving network service quality.

[0003] In the prior art, when a user needs to access a website through the intranet, the website address will be queried first, and then the splitting end will add the website address to its own splitting rules. After that, once there is a packet with the website address as the target address, the splitting end will forward the packet to the intranet, and then send it to the public network node corresponding to the website address to realize the user's access to the website.

[0004] However, the prior art has the problem of low packet splitting accuracy. In the prior art, on the same public network node, there are multiple other public network services in addition to the website that the user wants to access. The splitting end has added the public network address to its own splitting rules. If the user accesses multiple other public network services, this packet will also first enter the intranet and then reach the public network. This causes many packets that do not need to enter the intranet to be split into the intranet, reducing the accuracy of packet splitting. Summary of the Invention

[0005] Embodiments of this application provide a method, apparatus, device, medium, and product for processing packets to solve the problem of low packet splitting accuracy in the prior art.

[0006] In a first aspect, embodiments of this application provide a method for processing packets, which is applied to a security gateway of a packet processing system. The packet processing system further includes a user side, a splitting end, a private network side, and an intranet side. The method includes:

[0007] Receiving a target address sent by the intranet side, and converting the target address into a private network address according to a preset first address conversion rule; wherein, the target address is determined by the intranet side according to a first request packet and a preset database, and the target address is the address of the target website queried by the first request packet;

[0008] Send the private network address to the shunt end, so that the shunt end optimizes a preset first shunt rule according to the private network address to obtain a second shunt rule; wherein, the second shunt rule is used for when the shunt end receives a first service message sent by the user end and the destination address of the first service message is the private network address, making the shunt end send the first service message to the private network end, and the destination address refers to the address of the server that the first service message finally reaches.

[0009] Send the private network address to the user end, so that the user end optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule; wherein, the second message generation rule is used for when the user end responds to a service message generation instruction and the service message is for accessing the target website, generating a first service message and setting the destination address of the first service message as the private network address.

[0010] In a possible design, before receiving the target address sent by the internal network end and converting the target address into a private network address according to a preset first address conversion rule, it further includes:

[0011] Receive the first request message sent by the private network end and send the first request message to the internal network end; wherein, the first request message is generated by the private network end according to a second request message and a preset second address conversion rule, and the second request message is generated by the user end according to the first message generation rule in response to a request message generation instruction.

[0012] In a possible design, the sending the first request message to the internal network end includes:

[0013] When the target address of the first request message is an internal network address and the message type of the first request message is a request message, send the first request message to the internal network end; wherein, the message type includes a request message and a service message, the request message is used to determine the address of the target website, and the service message is used to access the target website.

[0014] In a possible design, the sending the first request message to the internal network end includes:

[0015] Send the first request message to the internal network gateway device, so that the internal network gateway device sends the first request message to the internal network end.

[0016] In a possible design, after sending the private network address to the client so that the client optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule, it further includes:

[0017] Receiving the first service message sent by the private network end, and adjusting the address of the first service message according to the first address conversion rule to obtain a second service message; wherein, the first service message is generated by the client in response to a service message generation instruction, and the service message is generated according to the second message generation rule when accessing the target website;

[0018] Sending the second service message to the internal network end so that the internal network end accesses the target website according to the second service message to obtain first service information;

[0019] Receiving the first service information sent by the internal network end, and converting the target address of the first service information from a public network address to the private network address according to the first address conversion rule to obtain second service information;

[0020] Sending the second service information to the client.

[0021] In a possible design, the adjusting the address of the first service message according to the first address conversion rule to obtain a second service message includes:

[0022] Converting the target address of the first service message from the private network address to the public network address according to the first address conversion rule to obtain the second service message.

[0023] In a second aspect, an embodiment of the present application provides a message processing device, which is applied to a security gateway of a message processing system. The message processing system further includes a client, a shunt end, a private network end, and an internal network end. The device includes:

[0024] A target address receiving module, configured to receive a target address sent by the internal network end, and convert the target address into a private network address according to a preset first address conversion rule; wherein, the target address is determined by the internal network end according to a first request message and a preset database, and the target address is the address of the target website queried by the first request message;

[0025] A first sending module, configured to send the private network address to the traffic splitting end, so that the traffic splitting end optimizes a preset first traffic splitting rule according to the private network address to obtain a second traffic splitting rule; wherein, the second traffic splitting rule is used for when the traffic splitting end receives a first service message sent by the user end and the destination address of the first service message is the private network address, causing the traffic splitting end to send the first service message to the private network end, and the destination address refers to the address of the server that the first service message finally reaches.

[0026] A second sending module, configured to send the private network address to the user end, so that the user end optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule; wherein, the second message generation rule is used for when the user end responds to a service message generation instruction and the service message is for accessing the target website, generating a first service message and setting the destination address of the first service message as the private network address.

[0027] In a possible design, the message processing device further includes:

[0028] A message receiving module, configured to receive the first request message sent by the private network end and send the first request message to the internal network end; wherein, the first request message is generated by the private network end according to a second request message and a preset second address conversion rule, and the second request message is generated by the user end according to the first message generation rule in response to a request message generation instruction.

[0029] In a possible design, the message receiving module includes:

[0030] A first request message sending unit, configured to send the first request message to the internal network end when the target address of the first request message is an internal network address and the message type of the first request message is a request message; wherein, the message type includes a request message and a service message, the request message is used to determine the address of the target website, and the service message is used to access the target website.

[0031] In a possible design, the first request message sending unit includes:

[0032] A gateway device sending component, configured to send the first request message to an internal network gateway device, so that the internal network gateway device sends the first request message to the internal network end.

[0033] In a possible design, the message processing device further includes:

[0034] The first service message receiving module is configured to receive the first service message sent by the private network side, and adjust the address of the first service message according to the first address conversion rule to obtain a second service message; wherein, the first service message is generated by the user side in response to a service message generation instruction, and the service message is generated according to the second message generation rule when accessing the target website;

[0035] The second service message sending module is configured to send the second service message to the internal network side, so that the internal network side accesses the target website according to the second service message to obtain first service information;

[0036] The address conversion module is configured to receive the first service information sent by the internal network side, and convert the target address of the first service information from a public network address to the private network address according to the first address conversion rule to obtain second service information;

[0037] The second service information sending module is configured to send the second service information to the user side.

[0038] In a possible design, the address conversion module includes:

[0039] The address conversion unit is configured to convert the target address of the first service message from the private network address to the public network address according to the first address conversion rule to obtain the second service message.

[0040] In a third aspect, the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0041] The memory stores computer-executable instructions;

[0042] When the processor executes the computer-executable instructions stored in the memory, it is configured to implement the message processing method according to any one of the first aspects.

[0043] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are configured to implement the message processing method according to any one of the first aspects.

[0044] In a fifth aspect, the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it is configured to implement the message processing method according to any one of the first aspects.

[0045] A message processing method, apparatus, device, medium and product provided by this application. The method includes: receiving a target address sent by the intranet end, and converting the target address into a private network address according to a preset first address conversion rule; sending the private network address to the shunt end, so that the shunt end optimizes a preset first shunt rule according to the private network address to obtain a second shunt rule; wherein, the second shunt rule is used to make the shunt end send a first service message to the private network end when the shunt end receives a first service message sent by the user end and the destination address of the first service message is the private network address, and the destination address refers to the address of the server that the first service message finally reaches; sending the private network address to the user end, so that the user end optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule; wherein, the second message generation rule is used to generate a first service message when the user end responds to a service message generation instruction and the service message is used to access the target website, and set the destination address of the first service message to the private network address. The message processing method of this application effectively solves the problem of low accuracy of message shunting in the prior art by introducing the address conversion mechanism of the security gateway. By dynamically mapping the public network address of the target website to a private network address, this method enables the shunt end to establish an accurate shunt rule based on the private network address rather than the public network address, so as to ensure that only the service messages that truly access the target website, that is, the messages with the destination address of the private network address, will be directed to the intranet channel, while other non-target service messages sharing the same public network address will be transmitted along the normal path, fundamentally avoiding the problem of other messages entering the intranet, realizing accurate shunting, and improving the accuracy of message shunting. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with this application and used together with the specification to explain the principles of this application.

[0047] Figure 1 It is a schematic diagram of the application scenario of the message processing method provided by an embodiment of this application;

[0048] Figure 2 It is a schematic flow chart of the message processing method provided by an embodiment of this application Figure 1 ;

[0049] Figure 3 It is a schematic flow chart of the message processing method provided by an embodiment of this application Figure 2 ;

[0050] Figure 4 It is a schematic structural diagram of the message processing apparatus provided by an embodiment of this application;

[0051] Figure 5 Schematic diagram of the hardware structure of the electronic device provided by the embodiment of the present application.

[0052] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and more detailed descriptions will be given in the following text. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Specific Embodiments

[0053] Here, exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0054] In the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same or similar items with basically the same functions and roles. Those skilled in the art can understand that the terms "first" and "second" do not limit the quantity and execution order, and the terms "first" and "second" do not necessarily mean different. It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be interpreted as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way. In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more.

[0055] It should be noted that "when... " in the embodiments of the present application can be at the instant when a certain situation occurs, or within a period of time after a certain situation occurs. The embodiments of the present application do not make specific limitations on this. In addition, a message processing method, device, equipment, medium and product provided by the embodiments of the present application are only examples, and a message processing method, device, equipment, medium and product may also include more or less content.

[0056] To facilitate a clear description of the technical solutions of the embodiments of the present application, the following briefly introduces some terms and technologies involved in the embodiments of the present application:

[0057] Message: It refers to the data packets or messages transmitted in network communication, which contain the data for transmitting information and relevant control information, such as source address, destination address, and protocol type. It is the basic unit for communication between network devices and is used to exchange information between the sender and the receiver.

[0058] Security gateway: It is a network device or software system located between the internal network and the external network, responsible for monitoring, filtering, and controlling the data flow in and out of the network to protect the security of the internal network. By implementing security policies, such as firewall rules, intrusion detection, and antivirus scanning, it prevents unauthorized access and potential network threats, thus ensuring the security and integrity of the network environment.

[0059] Shunting rule: It refers to the set of policies or rules used to determine the data flow direction in network communication. According to specific conditions, such as source address, destination address, and protocol type, etc., it guides the message to different paths or processing nodes. Such rules can be used to optimize network performance, achieve load balancing, improve security, or meet specific business requirements.

[0060] Public network address: It refers to the address that uniquely identifies a device or server on the Internet. It is assigned by the Internet service provider and allows the device to communicate and exchange data globally. The public network address enables devices on the external network to directly access the device with this address and is usually used for hosting websites, servers, or other services that need to be accessed by Internet users.

[0061] Private network address: It refers to the address used within a local area network to identify and communicate devices within the network. Private network addresses are usually used in home, office, or enterprise internal networks for data exchange and communication between devices. To communicate with the Internet, private network addresses usually need to be converted to public network addresses through network address translation methods.

[0062] Internal network address: It usually refers to the address used in an organization's local area network, similar to the concept of a private network address. It is used to identify and manage the communication between devices within the network. After network address translation through devices such as routers or firewalls, the internal network address can communicate with the external network.

[0063] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.

[0064] The technical solution of the present invention will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present invention will be described below with reference to the accompanying drawings.

[0065] To clearly understand the technical solution of this application, the solutions of the prior art will be introduced in detail first. In the prior art, when a user needs to access a website through the intranet, the website address will be queried first, and then the shunt end will add the website address to its own shunt rules. After that, once there is a packet with the website address as the destination address, the shunt end will forward the packet to the intranet and then send it to the public network node corresponding to the website address to realize the user's access to the website.

[0066] However, the prior art has the problem of low packet shunting accuracy. In the prior art, on the same public network node, there are multiple other public network services in addition to the website that the user wants to access. The shunt end has added the public network address to its own shunt rules. If the user accesses multiple other public network services, this packet will also first enter the intranet and then reach the public network. This results in many packets that do not need to enter the intranet being shunted into the intranet, reducing the accuracy of packet shunting.

[0067] Therefore, in view of the problem of low packet shunting accuracy in the prior art, it is found in the research that to solve this problem, the address of the target website can be converted and the shunt rules can be optimized so that only the packets of specific target websites are shunted to the intranet, thereby improving the shunting accuracy: ① An address mapping mechanism can be introduced in the intranet to convert the public network address of the target website into a private network address. This method can ensure that only the packets of specific target websites are processed, avoiding the interference of other irrelevant public network services, thereby improving the shunting accuracy. ② A multi-level shunting strategy can be implemented. First, the packets are preliminarily screened at the shunt end, and then a secondary confirmation is performed at the intranet entrance. Through the multi-level filtering mechanism, the situation of mis-shunting can be effectively reduced, and the overall shunting accuracy can be improved. ③ An application layer gateway can be deployed to specifically handle the traffic of specific applications or websites. Through detailed control at the application layer, it can be ensured that only relevant packets are correctly shunted to the intranet.

[0068] Specifically:

[0069] An intelligent traffic management system can be designed. This system converts the public network address of the target website into a private network address dedicated to the intranet through dynamic address mapping technology to ensure the unique identification of traffic. The system can also integrate multi-level traffic filtering mechanisms, combined with real-time traffic analysis and intelligent policy adjustment, to ensure that only packets meeting specific conditions are guided to the intranet. In this way, the system can effectively distinguish and manage different types of packets and improve the accuracy of shunting.

[0070] The message processing method according to the embodiments of the present application effectively solves the problem of low accuracy of message shunting in the prior art by introducing the address conversion mechanism of the security gateway. By dynamically mapping the public network address of the target website to a unique private network address, this method enables the shunting end to establish accurate shunting rules based on the private network address rather than the shared public network address, thereby ensuring that only the service messages that truly access the target website, that is, the messages with the destination address being the private network address, will be directed to the internal network channel, while other non-target service messages sharing the same public network address will be transmitted along the normal path, fundamentally avoiding the problem of other messages entering the internal network and achieving precise shunting.

[0071] Based on the above creative discovery, the technical solution of the present application is proposed.

[0072] The application scenario of the message processing method provided by the embodiments of the present invention will be introduced below. Figure 1 It is a schematic diagram of the application scenario of the message processing method provided by the embodiments of the present application. As Figure 1 shown, this application scenario includes a user terminal 101 and a server 102. The server 102 is provided with a shunting end 1021, a private network end 1022, a security gateway 1023, and an internal network end 1024.

[0073] The user terminal 101 generates a first request message according to the first message generation rule in response to a request message generation instruction, and sends the first request message to the shunting end 1021; the shunting end 1021 sends the first service message to the private network end 1022; the private network end 1022 converts the target address of the second request message from the public network address to the internal network address according to the second address conversion rule to obtain the first request message, and the private network end 1022 sends the first request message to the security gateway 1023; the security gateway 1023 sends the first request message to the internal network end 1024; the internal network end 1024 determines the target address according to the first request message and a preset database, and sends the target address to the security gateway 1023; the security gateway 1023 converts the target address to a private network address according to the preset first address conversion rule, and sends the private network address to the shunting end 1021 through the private network end 1022; the shunting end 1021 optimizes the preset first shunting rule according to the private network address to obtain a second shunting rule; the shunting end 1021 sends the private network address to the user terminal 101, and the user terminal 101 optimizes the preset first message generation rule according to the private network address to obtain a second message generation rule.

[0074] When the client 101 responds to a service message generation instruction and the service message is for accessing a target website, it generates a first service message, sets the destination address of the first service message to a private network address, and the client 101 sends the first service message to the shunt end 1021; the shunt end 1021 sends the first service message to the private network end 1022, the private network end 1022 sends the first service message to the security gateway 1023, the security gateway 1023 converts the target address of the first service message from a private network address to a public network address according to the first address conversion rule, obtains a second service message, and sends the second service message to the internal network end 1024; the internal network end 1024 accesses the target website according to the second service message, obtains the first service information, and the internal network end 1024 sends the first service information to the security gateway 1023; the security gateway 1023 converts the target address of the first service information from a public network address to a private network address according to the first address conversion rule, obtains the second service information, the security gateway 1023 sends the second service information to the private network end 1022, the private network end 1022 sends the second service information to the shunt end 1021, and the shunt end 1021 sends the second service information to the client 101.

[0075] The embodiments of the present invention will be described below with reference to the accompanying drawings of the specification.

[0076] Figure 2 Flow diagram of the message processing method provided by the embodiments of this application Figure 1 . As Figure 2 shown, in this embodiment, the execution subject of the embodiments of this application is the security gateway. Then the message processing method provided in this embodiment includes the following steps:

[0077] S201. Receive the target address sent by the internal network end, and convert the target address to a private network address according to a preset first address conversion rule; wherein, the target address is determined by the internal network end according to the first request message and a preset database, and the target address is the address of the target website queried by the first request message.

[0078] Specifically, an address conversion module can be configured in the security gateway. This module receives the target address from the internal network end and converts the target address to a corresponding private network address according to the preset first address conversion rule. This step is used to construct a network isolation layer, which not only hides the real public network address to prevent external detection, but also realizes the accurate shunting of messages through the private network address. Finally, while ensuring the security of the internal network, it ensures that the client can normally access the target website through the private network end.

[0079] Among them, the intranet side refers to a device or system operating in a closed or restricted network environment, which is usually used to process and manage internal network communications. The intranet side is responsible for receiving and sending data packets in the internal network and interacting with other network components to ensure the secure transmission and effective access of data. It is usually located behind a firewall or other security measures to protect the internal network from external threats.

[0080] S202. Send the private network address to the shunt end so that the shunt end optimizes the preset first shunt rule according to the private network address to obtain a second shunt rule; wherein, the second shunt rule is used to make the shunt end send the first service packet to the private network end when the shunt end receives the first service packet sent by the user end and the destination address of the first service packet is the private network address, and the destination address refers to the address of the server where the first service packet finally arrives.

[0081] Specifically, a communication module can be configured in the security gateway, and this module is responsible for sending the converted private network address to the shunt end. After receiving the private network address, the shunt end optimizes the preset first shunt rule according to this address to generate a second shunt rule. The shunt end can update its routing table or shunt policy so that when receiving the first service packet with the destination address being the private network address, it can correctly forward it to the private network end. The purpose of doing this is to ensure that the service packet can be efficiently and securely transmitted to the final server through the dedicated network path, thereby improving the utilization efficiency of network resources and the security of data transmission.

[0082] Among them, the shunt end is an intelligent packet guiding node deployed in the packet processing system, and its core function is to make real-time path decisions on service packets through dynamic rules, such as the second shunt rule. When detecting that the destination address of the packet is the private network address, it automatically guides the traffic to the private network end instead of the public network, thus achieving security domain isolation and optimal path selection.

[0083] S203. Send the private network address to the user end so that the user end optimizes the preset first packet generation rule according to the private network address to obtain a second packet generation rule; wherein, the second packet generation rule is used to generate the first service packet and set the destination address of the first service packet to the private network address when the user end responds to the service packet generation instruction and the service packet is used to access the target website.

[0084] Specifically, a communication module can be configured in the security gateway to send the converted private network address to the user side. After receiving the private network address, the user side optimizes its preset first message generation rule based on this address to form a second message generation rule. The user side can update its message generation logic so that when responding to a service message generation instruction, the destination address of the generated first service message is set to the private network address. This mechanism can ensure that the service messages generated by the user side can be correctly routed to the shunt end and access the target website through the private network end, while protecting the privacy and security of the target address.

[0085] A message processing method provided in this embodiment includes: receiving a target address sent by the internal network end and converting the target address into a private network address according to a preset first address conversion rule; wherein, the target address is determined by the internal network end based on the first request message and a preset database, and the target address is the address of the target website queried by the first request message; sending the private network address to the shunt end so that the shunt end optimizes a preset first shunt rule according to the private network address to obtain a second shunt rule; wherein, the second shunt rule is used to make the shunt end send the first service message to the private network end when the shunt end receives the first service message sent by the user side and the destination address of the first service message is the private network address, and the destination address refers to the address of the server where the first service message finally arrives; sending the private network address to the user side so that the user side optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule; wherein, the second message generation rule is used to generate a first service message and set the destination address of the first service message to the private network address when the user side responds to a service message generation instruction and the service message is used to access the target website. A message processing method achieves the following technical effects: By introducing the address conversion mechanism of the security gateway, it effectively solves the problem of low accuracy of message shunting in the prior art. This method dynamically maps the public network address of the target website to a unique private network address, enabling the shunt end to establish an accurate shunt rule based on the private network address rather than the public network address, so as to ensure that only the service messages that truly access the target website, that is, the messages with the destination address being the private network address, will be directed to the internal network channel, while other non-target service messages sharing the same public network address will be transmitted along the normal path, fundamentally avoiding the problem of other messages entering the internal network, achieving accurate shunting, and improving the accuracy of message shunting.

[0086] Figure 3 Schematic flow of the message processing method provided in the embodiment of the present application Figure 2 。In this embodiment, on the basis of Figure 3 the embodiment provided, the message processing method is further explained. Then the message processing method includes:

[0087] S301. Receive the first request message sent by the private network side and send the first request message to the internal network side. The first request message is generated by the private network side according to the second request message and the preset second address conversion rule, and the second request message is generated by the user side in response to the request message generation instruction according to the first message generation rule.

[0088] Specifically, a request processing module can be configured in the security gateway. This module is responsible for receiving the first request message from the private network side and forwarding it to the internal network side. The process of generating the first request message by the private network side involves conversion according to the second request message sent by the user side and the preset second address conversion rule. The second request message generated by the user side is in response to the request message generation instruction and is created based on the first message generation rule. The purpose of this process is to establish a communication link between the private network side and the internal network side, enabling the internal network side to determine the target address according to the first request message, so as to perform address conversion and traffic management in subsequent steps. This mechanism helps to achieve effective request transfer and address resolution between different network regions.

[0089] The technical effect of this solution in this embodiment is: By establishing a complete message processing link, a closed-loop address conversion mechanism from the user side request to the internal network side response is realized. When the user side initiates a domain name query request, the private network side performs the first address conversion on the second request message, that is, the conversion from the public network address to the internal network address, so that after the security gateway can obtain the real public network address of the target website on the internal network side, it further converts it into a private network address, thus providing an accurate address mapping basis for the subsequent shunt side and the user side. This preprocessing process ensures the consistency of the address conversion rules in the whole system and avoids the problem of shunt failure caused by the address mapping fault.

[0090] In a possible design, sending the first request message to the internal network side in S301 includes:

[0091] S3011. When the target address of the first request message is an internal network address and the message type of the first request message is a request message, send the first request message to the internal network side. The message type includes a request message and a service message. The request message is used to determine the address of the target website, and the service message is used to access the target website.

[0092] Specifically, a packet filtering and forwarding module can be configured in the security gateway. This module is responsible for checking the destination address and packet type of the received first request packet. When it detects that the destination address is an internal network address and the packet type is a request packet, the module forwards the first request packet to the internal network side. The distinction of packet types can be achieved through the domain name information in the packet. Request packets are used to determine the address of the target website, while service packets are used for actual access to the target website. The purpose of this process is to ensure that only eligible request packets are sent to the internal network side, so that the internal network side can perform destination address resolution and subsequent address conversion operations, thereby achieving effective network resource management and security control.

[0093] In this embodiment, the technical effect of this solution is as follows: By introducing a dual verification mechanism for packet types and destination addresses, intelligent filtering of request packets is achieved. When the security gateway receives a packet, by judging the two conditions that the packet type is a request packet and the destination address is an internal network address, it ensures that only the packets that meet the requirements are sent to the internal network side, while intercepting other irrelevant or abnormal packets. This dual verification mechanism not only ensures the efficient processing of packets but also avoids interference from service packets or other invalid packets to the system.

[0094] In a possible design, sending the first request packet to the internal network side in S3011 includes:

[0095] S30111: Send the first request packet to the internal network gateway device so that the internal network gateway device sends the first request packet to the internal network side.

[0096] Specifically, a routing and forwarding module can be configured in the security gateway. This module is responsible for sending the first request packet to the internal network gateway device. After receiving the packet, the internal network gateway device further forwards the first request packet to the internal network side according to its internal routing table or forwarding rules. The purpose of this process is to use the internal network gateway device as an intermediary to ensure that the request packet can accurately reach the internal network side in a complex network environment. This helps to achieve flexible packet transfer and effective network resource management in the network architecture, ensuring that the internal network side can process requests in a timely manner and perform destination address resolution and subsequent operations.

[0097] Among them, the gateway device is a key component in network communication, acting as an interface between different networks, used to connect and convert networks with different protocols or architectures. It is responsible for receiving, processing, and forwarding data packets to ensure that data can be smoothly transmitted in different network environments. The gateway device can perform multiple functions, including protocol conversion, traffic control, security filtering, and address translation, thereby promoting seamless communication between different networks while protecting network security.

[0098] In this embodiment, the technical effect of this solution is as follows: By setting up a gateway device between the security gateway and the intranet side, reliable transmission of request messages and network isolation are achieved. When the security gateway identifies a first request message that meets the conditions, that is, the destination address is an intranet address and the message type is a request message, it is relayed and forwarded through this dedicated node, the gateway device. The gateway device realizes the security isolation between the internal and external networks and provides a data source for subsequent address conversion and service diversion.

[0099] S302. Receive the destination address sent by the intranet side, and convert the destination address into a private network address according to the preset first address conversion rule; wherein, the destination address is determined by the intranet side based on the first request message and the preset database, and the destination address is the address of the target website queried by the first request message.

[0100] S303. Send the private network address to the diversion end, so that the diversion end optimizes the preset first diversion rule according to the private network address to obtain a second diversion rule; wherein, the second diversion rule is used to make the diversion end send the first service message to the private network end when the diversion end receives the first service message sent by the user end and the destination address of the first service message is the private network address, and the destination address refers to the address of the server where the first service message finally arrives.

[0101] S304. Send the private network address to the user end, so that the user end optimizes the preset first message generation rule according to the private network address to obtain a second message generation rule; wherein, the second message generation rule is used to generate a first service message and set the destination address of the first service message as the private network address when the user end responds to a service message generation instruction and the service message is for accessing the target website.

[0102] S302 - S304 is similar to S201 - S203, and will not be elaborated in this embodiment.

[0103] S305. Receive the first service message sent by the private network end, and adjust the address of the first service message according to the first address conversion rule to obtain a second service message; wherein, the first service message is generated according to the second message generation rule when the user end responds to a service message generation instruction and the service message is for accessing the target website.

[0104] Specifically, an address conversion module can be configured in the security gateway. This module is responsible for receiving the first service message from the private network end and adjusting its address according to the preset first address conversion rule, thereby generating a second service message. This processing ensures that the service message can be correctly transmitted between different network regions and can be recognized and processed by the intranet side, so as to successfully access the target website and obtain the required service information.

[0105] S306. Send the second service message to the intranet side so that the intranet side can access the target website according to the second service message and obtain the first service information.

[0106] Specifically, a message forwarding module can be configured in the security gateway. This module is responsible for sending the second service message after address adjustment to the intranet side. After receiving the second service message, the intranet side initiates an access request to the target website according to the target address and other relevant information contained therein, so as to obtain the first service information. The purpose of this process is to ensure that the service message after appropriate conversion can be correctly recognized and processed in the intranet, so that the intranet side can successfully access the external target website and obtain the required data. This mechanism helps to achieve effective resource access and information acquisition in the network architecture while maintaining the security and reliability of network communication.

[0107] S307. Receive the first service information sent by the intranet side, and according to the first address conversion rule, convert the target address of the first service information from the public network address to the private network address to obtain the second service information.

[0108] Specifically, an address conversion module can be configured in the security gateway. This module is responsible for receiving the first service information from the intranet side and converting the target address therein from the public network address to the corresponding private network address according to the preset first address conversion rule, so as to generate the second service information. The purpose of this process is to appropriately convert the address in the service information before returning it to the user side to ensure communication using the private network address in the internal network. This conversion helps to protect the address information inside the network, enhance privacy and security, and at the same time ensure that the user side can correctly recognize and process the returned service information.

[0109] S308. Send the second service information to the user side.

[0110] Specifically, a message transmission module can be configured in the security gateway. This module is responsible for sending the second service information after address conversion to the user side. After receiving the second service information, the user side can perform corresponding processing and display according to the content therein. The purpose of this process is to ensure that the user side can obtain the service information after security processing while maintaining the privacy and security of the internal network address. In this way, the user side can successfully receive and use the service information obtained from the target website without exposing the actual address structure of the internal network.

[0111] In this embodiment, the technical effect of this solution is as follows: By establishing a bidirectional address conversion mechanism, precise routing and response feedback of service packets from the user side to the target website are achieved throughout the process. During the service access phase, the security gateway performs reverse conversion of the service packets sent from the user side from the private network address to the public network address to ensure that the internal network side can correctly identify the target website; at the same time, the returned service information is converted back to the private network address format again, so that the shunt side and the user side always communicate based on a unified private network address system. This closed-loop address conversion not only maintains the perceptual isolation of the external network from the real public network address but also ensures the consistency of the internal system processing logic, realizing reliable end-to-end transmission of service packets.

[0112] In a possible design, the address adjustment of the first service packet according to the first address conversion rule in S305 to obtain the second service packet includes:

[0113] S3051. According to the first address conversion rule, convert the destination address of the first service packet from the private network address to the public network address to obtain the second service packet.

[0114] Specifically, an address conversion module can be configured in the security gateway. This module is responsible for converting the destination address in the packet from the private network address to the public network address according to the preset first address conversion rule, thereby generating the second service packet. The purpose of this process is to enable the service packet to be correctly forwarded on the public network so that the internal network side can access external target websites. This conversion ensures the privacy of the internal network address while allowing the packet to be normally transmitted and processed in the public network, thus realizing effective access to external resources.

[0115] In this embodiment, the technical effect of this solution is as follows: Through an accurate address reverse conversion mechanism, seamless mapping of service packets from the internal private network address to the external public network address is achieved. When the first service packet carrying the private network address sent by the user side arrives at the security gateway, the system, according to the preset first address conversion rule, accurately restores the destination address of the packet from the internal private network address to the original public network address. This key conversion not only ensures that the internal network side can access the target website based on the real public network address but also maintains the complete transparency of the external network to the internal address conversion mechanism, enhancing the security of the system.

[0116] Figure 4 It is a schematic structural diagram of the packet processing device provided in the embodiment of the present application. As Figure 4 shown, the packet processing device includes:

[0117] The target address receiving module 401 is configured to receive the target address sent by the intranet side and convert the target address into a private network address according to a preset first address conversion rule; wherein, the target address is determined by the intranet side according to the first request message and a preset database, and the target address is the address of the target website queried by the first request message.

[0118] The first sending module 402 is configured to send the private network address to the traffic splitting end, so that the traffic splitting end optimizes a preset first traffic splitting rule according to the private network address to obtain a second traffic splitting rule; wherein, the second traffic splitting rule is used for the traffic splitting end to send the first service message to the private network end when receiving the first service message sent by the user end and the destination address of the first service message is the private network address, and the destination address refers to the address of the server that the first service message finally reaches.

[0119] The second sending module 403 is configured to send the private network address to the user end, so that the user end optimizes a preset first message generation rule according to the private network address to obtain a second message generation rule; wherein, the second message generation rule is used for the user end to generate a first service message and set the destination address of the first service message as the private network address when responding to a service message generation instruction and the service message is used to access the target website.

[0120] In a possible design, the message processing device further includes:

[0121] The message receiving module is configured to receive the first request message sent by the private network end and send the first request message to the intranet side; wherein, the first request message is generated by the private network end according to the second request message and a preset second address conversion rule, and the second request message is generated by the user end according to the first message generation rule in response to a request message generation instruction.

[0122] In a possible design, the message receiving module includes:

[0123] The first request message sending unit is configured to send the first request message to the intranet side when the target address of the first request message is an intranet address and the message type of the first request message is a request message; wherein, the message type includes a request message and a service message, the request message is used to determine the address of the target website, and the service message is used to access the target website.

[0124] In a possible design, the first request message sending unit includes:

[0125] The gateway device sending component is configured to send the first request message to the intranet gateway device, so that the intranet gateway device sends the first request message to the intranet side.

[0126] In a possible design, the message processing device further includes:

[0127] The first service message receiving module is configured to receive a first service message sent by the private network side, and adjust the address of the first service message according to a first address conversion rule to obtain a second service message; wherein, the first service message is generated by the user side in response to a service message generation instruction, and the service message is generated according to a second message generation rule when accessing a target website.

[0128] The second service message sending module is configured to send the second service message to the internal network side, so that the internal network side accesses the target website according to the second service message to obtain first service information.

[0129] The address conversion module is configured to receive the first service information sent by the internal network side, and convert the target address of the first service information from a public network address to a private network address according to the first address conversion rule to obtain second service information.

[0130] The second service information sending module is configured to send the second service information to the user side.

[0131] In a possible design, the address conversion module includes:

[0132] The address conversion unit is configured to convert the target address of the first service message from a private network address to a public network address according to the first address conversion rule to obtain a second service message.

[0133] The message processing device provided in this embodiment can execute Figure 2 and Figure 3 the technical solutions of the message processing method embodiments shown, and its implementation principle and technical effects are similar to Figure 2 and Figure 3 the message processing method embodiments shown, and will not be elaborated here one by one.

[0134] Figure 5 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiment of the present application. As Figure 5 shown, the electronic device includes: at least one processor 510 and a memory 520. The electronic device also includes a communication component 530. Among them, the processor 510, the memory 520, and the communication component 530 are connected through a bus 540.

[0135] In the specific implementation process, at least one processor 510 executes the computer execution instructions stored in the memory 520, so that at least one processor 510 is used to implement the message processing method of the above embodiment.

[0136] The specific implementation process of the processor 510 can refer to the above method embodiment, and its implementation principle and technical effects are similar, and will not be elaborated here in this embodiment.

[0137] In the above embodiments, it should be understood that the processor 510 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by a hardware processor, or can be implemented by a combination of hardware and software modules in the processor.

[0138] The memory 520 may include high-speed RAM memory and may also include non-volatile storage NVM, such as at least one disk memory.

[0139] The bus 540 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus 540 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, the bus 540 in the drawings of this application is not limited to only one bus or one type of bus.

[0140] The functions implemented for the electronic device and the main control device are described above for the solution provided by the embodiments of the present invention. It can be understood that in order for the electronic device or the main control device to implement the above functions, it includes the corresponding hardware structures and / or software modules for executing each function. Combining the units and algorithm steps of each example described in the embodiments disclosed in the embodiments of the present invention, the embodiments of the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiments of the present invention.

[0141] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are executed by a processor, they are used to implement a message processing method in the above embodiments. Among them, in the specific implementation of the foregoing message processing method, each module can be implemented as a processor.

[0142] The above-readable storage medium may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk. The readable storage medium may be any available medium accessible by a general-purpose or special-purpose computer.

[0143] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium may also be a component of the processor. The processor and the readable storage medium may be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium may also exist as discrete components in an electronic device or a master device.

[0144] The embodiments of the present application also provide a computer program product, including a computer program, which, when executed by a processor, is used to implement a message processing method in the above embodiments.

[0145] The computer program is stored in a readable storage medium. At least one processor may read the computer program from the readable storage medium, and at least one processor executes the computer program to execute the solution provided in any of the above embodiments.

[0146] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments may be completed by hardware related to program instructions. The foregoing program may be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes various media that can store program codes, such as ROM, RAM, magnetic disks, or optical disks.

[0147] So far, the technical solutions of the present application have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments. The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A message processing method, characterized in that: A security gateway applied to a message processing system, wherein the message processing system further comprises a user terminal, a shunt terminal, a private network terminal and an intranet terminal, and the method comprises: Receive the target address sent by the intranet end, and convert the target address into a private network address according to a preset first address conversion rule; wherein the target address is determined by the intranet end according to the first request message and a preset database, and the target address is the address of the target website queried by the first request message; Send the private network address to the diversion end, so that the diversion end optimizes the preset first diversion rule according to the private network address to obtain a second diversion rule; wherein the second diversion rule is used to enable the diversion end to send the first service message to the private network end when the diversion end receives the first service message sent by the user end, and the destination address of the first service message is the private network address, and the destination address refers to the address of the server where the first service message finally arrives; The private network address is sent to the user terminal so that the user terminal optimizes the preset first message generation rule according to the private network address to obtain a second message generation rule; wherein the second message generation rule is used to generate a first business message when the user terminal responds to a business message generation instruction and the business message is used to access the target website, and the destination address of the first business message is set to the private network address.

2. The message processing method according to claim 1, characterized in that: Before receiving the target address sent by the intranet terminal and converting the target address into a private network address according to a preset first address conversion rule, the method further includes: Receive the first request message sent by the private network end, and send the first request message to the intranet end; wherein, the first request message is generated by the private network end according to the second request message and a preset second address conversion rule, and the second request message is generated by the user end in response to the request message generation instruction and according to the first message generation rule.

3. The message processing method according to claim 2, characterized in that: The sending the first request message to the intranet end includes: When the target address of the first request message is an intranet address and the message type of the first request message is a request message, the first request message is sent to the intranet end; wherein the message type includes a request message and a service message, the request message is used to determine the address of the target website, and the service message is used to access the target website.

4. The message processing method according to claim 3, characterized in that: The sending the first request message to the intranet end includes: Send the first request message to the intranet gateway device, so that the intranet gateway device sends the first request message to the intranet end.

5. The message processing method according to claim 4, characterized in that: The sending of the private network address to the user terminal so that the user terminal optimizes the preset first message generation rule according to the private network address to obtain the second message generation rule further includes: receiving the first service message sent by the private network end, and adjusting the address of the first service message according to the first address conversion rule to obtain a second service message; wherein the first service message is generated by the user end in response to a service message generation instruction, and the service message is used to access the target website, according to the second message generation rule; Sending the second service message to the intranet terminal, so that the intranet terminal accesses the target website according to the second service message to obtain the first service information; receiving the first service information sent by the intranet terminal, and converting the target address of the first service information from a public network address to the private network address according to the first address conversion rule, to obtain second service information; Sending the second service information to the user terminal.

6. The message processing method according to claim 5, characterized in that: The step of adjusting the address of the first service message according to the first address conversion rule to obtain a second service message includes: According to the first address conversion rule, the target address of the first service message is converted from the private network address to the public network address to obtain the second service message.

7. A message processing device, characterized in that: The message processing device is applied to a security gateway of a message processing system, the message processing system further includes a user end, a shunt end, a private network end and an intranet end, and the device includes: A target address receiving module, used to receive the target address sent by the intranet end, and convert the target address into a private network address according to a preset first address conversion rule; wherein the target address is determined by the intranet end according to the first request message and a preset database, and the target address is the address of the target website queried by the first request message; A first sending module is used to send the private network address to the shunt end, so that the shunt end optimizes the preset first shunt rule according to the private network address to obtain a second shunt rule; wherein the second shunt rule is used to enable the shunt end to send the first service message sent by the user end to the private network end when the shunt end receives the first service message sent by the user end, and the destination address of the first service message is the private network address, and the destination address refers to the address of the server where the first service message finally arrives; The second sending module is used to send the private network address to the user terminal, so that the user terminal optimizes the preset first message generation rule according to the private network address to obtain the second message generation rule; wherein the second message generation rule is used to generate a first business message when the user terminal responds to a business message generation instruction and the business message is used to access the target website, and the destination address of the first business message is set to the private network address.

8. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; When the processor executes the computer-executable instructions stored in the memory, it is used to implement the message processing method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the message processing method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program is used to implement the message processing method according to any one of claims 1 to 6.