Routing device message processing method, routing device, storage medium and chip system

By reorganizing and identifying the segmented handshake packets in https requests, the routing device can identify and intercept non-secure URLs, solving the problem of interception failure in the existing technology and improving the security of electronic devices.

CN120263729APending Publication Date: 2025-07-04HUAWEI TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510048349.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

Existing routing devices fail when intercepting non-secure URLs, reducing the security of electronic devices.

Method used

The routing device reorganizes the URL of multiple segmented handshake messages in the https request and parses out the URLs requested by the electronic device. By presetting the URL blacklist and identification mechanism in the routing device, it identifies and intercepts the URLs that are not allowed to be accessed.

Benefits of technology

Effectively intercepting non-secure URLs improves the security of electronic devices and prevents attacks on electronic devices by non-secure URLs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263729A_ABST
    Figure CN120263729A_ABST
Patent Text Reader

Abstract

The invention provides a message processing method of routing equipment, the routing equipment, a storage medium and a chip system, and relates to the technical field of terminals. The method comprises the following steps: a routing device can perform website recombination on a plurality of segmented handshake messages in an https request, and parses a website requested to be accessed by an electronic device; in addition, the routing equipment can also intercept the websites which are not allowed to be accessed, so that the attack of non-secure websites on the electronic equipment is reduced, and the security of the electronic equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of terminals, and in particular, to a method for a routing device to process packets, a routing device, a storage medium, and a chip system. Background Art

[0002] An electronic device can be connected to the Internet through a routing device to access resources in a server. In some scenarios, some applications in the electronic device access non-secure URLs, and the routing device can intercept these non-secure URLs. Among them, a non-secure URL can be understood as a URL that the routing device does not allow to access.

[0003] However, in some implementations, the routing device may fail to intercept non-secure URLs, reducing the security of the electronic device. Summary of the Invention

[0004] This application provides a method for a routing device to process packets, a routing device, a storage medium, and a chip system. The routing device can recombine the URLs in multiple segmented handshake packets in an HTTPS request and parse out the URL requested by the electronic device to be accessed. The routing device can also intercept URLs that are not allowed to be accessed, thereby reducing the attack of non-secure URLs on the electronic device and enhancing the security of the electronic device.

[0005] In a first aspect, a method for a routing device to process packets is provided, which is applied to a routing device. The method includes:

[0006] Obtain N segmented packets from an electronic device and send the N segmented packets. Among them, the routing device cannot parse out a URL from the N segmented packets, and N is a positive integer greater than or equal to 1; obtain the (N + 1)th segmented packet from the electronic device and parse out a URL from the (N + 1)th segmented packet. Among them, the N segmented packets and the (N + 1)th segmented packet are packets in the same data stream; when the first information includes a URL, the routing device does not send the (N + 1)th segmented packet, and the first information includes one or more URLs that are not allowed to be accessed. In this way, even if the first segmented packet to the Nth segmented packet are sent out before, the server will not receive a complete packet, and thus cannot parse out a complete URL, making the electronic device unable to access non-secure URLs.

[0007] In a possible implementation, the method further includes: obtain the (N + 1)th segmented packet from the electronic device again, and the routing device does not send the (N + 1)th segmented packet. In this way, the routing device can intercept subsequent packets involved in this data stream, thereby intercepting retransmitted segmented packets and making the electronic device unable to access non-secure URLs.

[0008] In a possible implementation, the method further includes: when the first information includes a website address, adding an identifier to the data stream where the (N + 1)-th segmented packet is located, and the identifier is used to indicate that the data stream includes a website address that is not allowed to be accessed. By adding the identifier, the router can not only identify that the website address is an insecure website address, but also identify the data stream corresponding to the website address as an insecure data stream. In this way, when the segmented packet is retransmitted, the router can successfully intercept the retransmitted packet, so that the electronic device cannot access the insecure website address.

[0009] In a possible implementation, the method further includes: obtaining the (N + 1)-th segmented packet from the electronic device again, and based on the identifier, the routing device does not send the (N + 1)-th segmented packet. The routing device can determine, based on the identifier, that the data stream corresponding to the (N + 1)-th segmented packet is an insecure data stream, and the data stream includes a website address that is not allowed to be accessed. Then the routing device can not send the (N + 1)-th segmented packet, thereby implementing the interception of the insecure packet by the routing device.

[0010] In a possible implementation, obtaining N segmented packets from the electronic device and sending the N segmented packets includes: obtaining the i-th segmented packet from the electronic device; updating and saving the first anchor packet, where the first anchor packet is obtained based on the i segmented packets from the first segmented packet to the i-th segmented packet, and i is a positive integer less than or equal to N; sending the i-th segmented packet, where the routing device cannot resolve a website address from the first anchor packet. When a website address cannot be resolved based on the updated anchor packet, since the routing device cannot determine whether the packet sent by the electronic device contains an insecure website address, in order not to block network services, the routing device can back up the new anchor packet and send the i-th segmented packet.

[0011] In a possible implementation, the first anchor packet is obtained by combining the i segmented packets based on the sequence number and the next sequence number information. In this way, based on the sequence number and the next sequence number information, the routing device can append subsequent segmented packets on the basis of the first segment anchor packet copy, so as to gradually obtain a complete packet and implement the recombination of the packet.

[0012] In a possible implementation, the method further includes: when the first information includes a website address, deleting the second anchor packet, where the second anchor packet is obtained based on the N + 1 segmented packets from the first segmented packet to the (N + 1)-th segmented packet. In this way, more segmented packets of different data streams can be processed in a limited memory space for a long time, effectively controlling the space occupied by the routing device, and timely clearing unnecessary memory data in the router, thereby improving the operation efficiency of the router.

[0013] In a possible implementation, the method further includes: if the number of matches of the second information is greater than or equal to a preset number of matches, deleting the first anchor packet, where the second information is used to indicate that N segmented packets and the (N + 1)-th segmented packet are packets in the same data stream; or, if the time interval from obtaining the first segmented packet from the electronic device to determining that the first information includes a website address is greater than or equal to a preset matching duration, deleting the first anchor packet. In this way, a larger number of segmented packets of different data streams can be processed in a limited memory space for a long time, and unnecessary memory data in the router can be cleared in a timely manner. Thereby, the memory space of the router is saved, and the operating efficiency of the router is improved.

[0014] In a possible implementation, the second information includes five-tuple information of the data stream, the website address includes a website address of the Hypertext Transfer Protocol Secure (HTTPS) type, and the N segmented packets are handshake packets of the Secure Sockets Layer (SSL) protocol. The routing device can perform website address recombination on multiple segmented handshake packets of the SSL protocol in an HTTPS-type request, and parse out the website address requested by the electronic device based on the five-tuple information, etc. The routing device can also intercept website addresses that are not allowed to be accessed, thereby reducing attacks on the electronic device by non-secure website addresses and improving the security of the electronic device.

[0015] In a second aspect, a routing device is provided, which includes one or more processors and a memory. The memory is used to store one or more programs, and the one or more processors are used to call the one or more programs to execute the method described in the first aspect or any possible implementation manner of the first aspect.

[0016] In a third aspect, a chip or a chip system is provided. The chip or the chip system is applied to a routing device and includes one or more processors. The one or more processors are used to call instructions to execute the method described in the first aspect or any possible implementation manner of the first aspect. Among them, the communication interface in the chip can be an input / output interface, a pin, a circuit, etc.

[0017] In a possible implementation, the chip or the chip system described above in this application further includes at least one memory, and instructions are stored in the at least one memory. The memory can be an internal storage unit of the chip, such as a register, a cache, etc., or a storage unit of the chip (such as a read-only memory, a random access memory, etc.).

[0018] In a fourth aspect, a readable storage medium (which can also be referred to as a computer-readable storage medium) is provided. A program is stored in the readable storage medium. When the program runs on a routing device, the routing device is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect.

[0019] The fifth aspect provides a program product (which may also be referred to as a computer program product), and the program product includes a program. When the program runs on a routing device, the routing device is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect.

[0020] It should be understood that the technical solutions of the second aspect to the fifth aspect of the present application correspond to those of the first aspect of the present application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation manners are similar and will not be elaborated herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 A schematic diagram of a routing device intercepting a non-secure website provided by an embodiment of the present application;

[0022] Figure 2 A schematic diagram of device interaction of a routing device intercepting a non-secure website provided by an embodiment of the present application;

[0023] Figure 3 Another schematic diagram of a routing device intercepting a non-secure website provided by an embodiment of the present application;

[0024] Figure 4 Another schematic diagram of a routing device intercepting a non-secure website provided by an embodiment of the present application;

[0025] Figure 5 A schematic flowchart of a method for a routing device to process a message provided by an embodiment of the present application;

[0026] Figure 6 A schematic diagram of a router parsing a handshake message provided by an embodiment of the present application;

[0027] Figure 7 A schematic diagram of a protocol retransmission mechanism provided by an embodiment of the present application;

[0028] Figure 8 A schematic diagram of a method for a routing device with a mark identifier to process a message provided by an embodiment of the present application;

[0029] Figure 9 A schematic diagram of a method for a routing device to process a message provided by an embodiment of the present application;

[0030] Figure 10 A schematic diagram of the structure of a routing device provided by an embodiment of the present application;

[0031] Figure 11 A schematic diagram of the structure of a chip system provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] To facilitate a clear description of the technical solutions of the embodiments of the present application, the following briefly introduces some terms and technologies involved in the embodiments of the present application:

[0033] 1. Terms

[0034] In the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. For example, the first chip and the second chip are only used to distinguish different chips, and do not limit their sequence. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different.

[0035] It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.

[0036] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the preceding and following associated objects. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (s) or multiple items (s). For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0037] An electronic device can be connected to the Internet through a routing device to access resources in a server. In some scenarios, some applications in the electronic device access non - secure URLs, and the routing device can intercept these non - secure URLs. Among them, a non - secure URL can be understood as a URL that the routing device does not allow to access.

[0038] In some implementations, as Figure 1 shown, for some applications in an electronic device, such as a browser, when accessing a server through a routing device, the routing device can perform domain name system (DNS) resolution on the URL to be accessed by the application and intercept non - secure URLs.

[0039] Exemplarily, as Figure 2 shown, a user can enter an insecure domain name in the browser of an electronic device. Suppose the insecure domain name is www.xxx.com. The browser can trigger the electronic device to initiate a DNS request to a server (referred to as the target server) through a routing device. Before the routing device forwards the DNS request, the routing device can intercept the DNS request and resolve the domain name in the DNS request. If the routing device determines that the resolved domain name is an insecure domain name, the routing device can intercept the insecure domain name and will not forward the insecure domain name to the target server.

[0040] However, in the above implementation process, the routing device may fail to intercept the insecure domain name. When the browser fails to obtain the response corresponding to the DNS request for a long time, for example, when the browser fails to obtain the IP address corresponding to the insecure domain name after a preset time, the browser may encapsulate the insecure domain name into a hypertext transfer protocol (http) request or a hypertext transfer protocol secure (https) request, and trigger the electronic device to access a proxy server through the routing device. The proxy server can be understood as an intermediary server, which can act as an intermediary between the electronic device and the target server.

[0041] After obtaining the http request or the https request, the proxy server can resolve the insecure domain name and initiate a DNS request to the server where the insecure domain name is located (referred to as the insecure server). The insecure server can return a DNS response to the proxy server, and the DNS response can include the IP address corresponding to the insecure domain name. Furthermore, the proxy server can request the content that is not allowed to be accessed from the insecure server based on the IP address, and the insecure server can return the content that is not allowed to be accessed. It can be understood that a website blacklist can be preset in the routing device, and the website blacklist includes one or more website addresses. The content that is not allowed to be accessed can be understood as the insecure content on the server corresponding to the one or more website addresses.

[0042] After obtaining content that is not allowed to be accessed, the proxy server can return an HTTP response or an HTTPS response to the electronic device through a routing device, and the HTTP response or HTTPS response can include the content that is not allowed to be accessed. In this way, the browser can trigger the electronic device to display the content that is not allowed to be accessed based on the HTTP response or HTTPS response. For example, if the HTTP response or HTTPS response includes hypertext markup language (HTML) content that is not allowed to be accessed, the electronic device can display the HTML content.

[0043] In some other implementations, such as Figure 3 shown, some routing devices can also intercept HTTP URLs.

[0044] Exemplarily, the routing device can not intercept DNS requests. In this way, the browser can obtain the IP address returned by the non-secure server, and the browser can encapsulate the IP address into the HTTP request. When the browser triggers the electronic device to initiate an HTTP request, since the HTTP request does not use the Secure Sockets Layer (SSL) protocol or the Transport Layer Security (TLS) protocol to encrypt data, the routing device can obtain the HTTP URL and intercept the HTTP URL. After identifying that the HTTP URL is a non-secure URL, the routing device can redirect the HTTP request to a resource pre-set locally on the routing device. Among them, the locally pre-set resource can be used to prompt the user that the website being accessed is a website that is not allowed to be accessed, a website that is not recommended to be accessed, or a risky website, etc. However, Figure 3 For the corresponding implementation process, the routing device can only intercept HTTP requests with a relatively high probability and cannot effectively intercept HTTPS requests successfully.

[0045] In still some other implementations, such as Figure 4 shown, some routing devices can also intercept HTTPS requests.

[0046] It can be understood that the data to be transmitted in the https request can be encrypted through the SSL protocol or the TLS protocol. For the sake of convenience of description, the SSL protocol will be taken as an example for illustration below. The implementation method using the TLS protocol is similar to that of the SSL protocol and will not be elaborated here. It can be understood that the handshake phase of the SSL protocol is not encrypted, that is, during the handshake phase of the SSL protocol, the electronic device and the server interact in plain text. Therefore, the routing device can obtain the server_name field in the handshake message of the SSL protocol, and this server_name field can be used to indicate the host name or server name. If the handshake message of the SSL protocol is a complete message, or the handshake message includes a complete https URL, the routing device can intercept the https URL to determine whether the https URL is an insecure URL.

[0047] However, in a possible scenario, the server_name field may be stored in the payload of the handshake message, and this payload can be used as a carrier for data transmission. When a handshake message cannot carry all the handshake information (which can also be called handshake data) of the SSL protocol, the electronic device will segment the handshake message, divide the handshake information of the SSL protocol into multiple payloads, and send them through multiple segmented handshake messages. In this case, what the routing device obtains are independent sk_buff structures, and each sk_buff structure can include a payload, and each payload corresponds to a part of the handshake information. Each sk_buff structure can be simply referred to as skb. That is to say, in this case, the routing device cannot obtain all the handshake information of the SSL protocol from one skb, that is, the routing device cannot obtain the complete URL from the segmented handshake message, so that the routing device cannot identify the insecure URL and fails to intercept the insecure URL.

[0048] In view of this, the embodiment of the present application provides a method for a routing device to process messages. The routing device can reorganize the URLs in multiple segmented handshake messages in the https request and parse out the URL requested by the electronic device to be accessed. The routing device can also intercept the URLs that are not allowed to be accessed, thereby reducing the attack of insecure URLs on the electronic device and improving the security of the electronic device.

[0049] It can be understood that the routing device in the embodiments of the present application can be used to forward data packets in a network. For example, it can forward data packets from one network interface to another network interface to ensure that data can be transmitted between electronic devices and network devices (such as servers). The routing device can include, but is not limited to: routers, gateway devices, optical modems, optical network terminals (ONTs), switches, bridges, repeaters, portable Wi-Fi devices, customer premise equipment (CPEs), firewalls, etc. The embodiments of the present application do not make any limitations. For the convenience of description, the subsequent routing devices will be described by taking routers as examples.

[0050] A router can include a kernel forwarding plane and a kernel control plane. Among them, the kernel forwarding plane can be responsible for operations such as the lookup, forwarding, and processing of data packets. The kernel forwarding plane can forward the data packets entering the router to the appropriate output interface based on the routing table generated by the kernel control plane. The kernel forwarding plane can also be simply referred to as the forwarding plane or the data plane. The kernel control plane can be responsible for network management and configuration, including route selection, the operation of network protocols, the construction and maintenance of the routing table, etc. The kernel control plane can also be simply referred to as the control plane.

[0051] A router can include a Wi-Fi network card and / or an Ethernet network card. The Wi-Fi network card and / or the Ethernet network card can be used to forward data between the server and the electronic device. In the embodiments of the present application, the Wi-Fi network card and / or the Ethernet network card can also be used to parse the server_name field in the SSL protocol handshake message and the host field in the http message. It can be understood that the router can support the electronic device to request a website using the ipv4 protocol or the ipv6 protocol, and can also receive escape characters. The connection between the router and the electronic device can be wired or wireless.

[0052] The electronic device can also be any form of device. For example, the electronic device can include: mobile phone, tablet computer, handheld computer, laptop computer, mobile internet device (MID), wearable device, virtual reality (VR) device, augmented reality (AR) device, device in industrial control, device in self-driving, device in remote medical surgery, device in smart grid, device in transportation safety, device in smart city, device in smart home, cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device, computing device or other processing devices connected to a wireless modem, vehicle-mounted device, device in a 5G network or device in a future evolved public land mobile network (PLMN), etc. The embodiments of the present application do not make any limitations in this regard.

[0053] In the embodiments of the present application, the electronic device can include a Wi-Fi network card and / or an Ethernet network card. The Wi-Fi network card and / or the Ethernet network card can be used to connect to a router for sending and receiving packets.

[0054] The method of the embodiments of the present application will be described in detail through specific embodiments below. The following embodiments can be combined with each other or implemented independently. For the same or similar concepts or processes, they may not be repeated in some embodiments.

[0055] Figure 5 The flowchart showing the method for a routing device to process packets in the embodiments of the present application is presented.

[0056] The method for a routing device to process packets in an embodiment of this application involves interactions among an electronic device, a router, a DNS server, and a resource server. Among them, the electronic device involves an application for accessing a website, such as a browser. The DNS server may include a DNS response system, which can be used to respond to DNS requests initiated by the electronic device. The resource server may include a web server system, which can be used to respond to resource access requests initiated by the electronic device.

[0057] The method for a routing device to process packets may include the following steps S501 to S510. It can be understood that Figure 5 For each process or step in the corresponding embodiment, it is not necessary to be executed in sequence. The execution order of steps S501 to S510 in the embodiment of this application is not limited, as long as the method for a routing device to process packets can be implemented.

[0058] S501. The electronic device requests a domain name.

[0059] In a possible scenario, the user can search for a certain domain name, such as www.xxx.com, in the browser of the electronic device. The browser of the electronic device can encapsulate the domain name into a packet and trigger the electronic device to send it to the server through the router.

[0060] S502. The router forwards the packet corresponding to the domain name.

[0061] After receiving the packet corresponding to the domain name, the router can forward the packet to the DNS server.

[0062] S503. The DNS server returns a response packet to the router.

[0063] In a possible implementation, the DNS server may locally cache a mapping table of domain names and IP addresses. After obtaining the packet requesting the domain name, the DNS server can query the IP address corresponding to the domain name, such as the IP address corresponding to www.xxx.com, from the mapping table. The DNS server can encapsulate the queried IP address into the response packet and return the response packet to the router.

[0064] S504. The router returns a response packet to the electronic device.

[0065] After receiving the response packet from the DNS server, the router can forward the response packet to the electronic device. Further, the browser in the electronic device can receive the response packet.

[0066] S505. The electronic device sends an http request or an https request.

[0067] The browser of the electronic device can trigger the electronic device to send an HTTP request or an HTTPS request based on the response message. For example, the browser of the electronic device can obtain the IP address corresponding to www.xxx.com from the response message and encapsulate it into an HTTP request or an HTTPS request. The browser can also trigger the electronic device to send an HTTP request or an HTTPS request.

[0068] S506. The router performs HTTP parsing or parsing of the handshake message of the SSL protocol.

[0069] The router's parsing of the handshake message of the SSL protocol can include processes such as identifying the first-segment anchor message of the handshake message, reorganizing segmented messages, and URL parsing. For the specific process of the router's parsing of the handshake message of the SSL protocol, reference can be made to the relevant descriptions in the following Figure 6 corresponding embodiments and will not be elaborated here. After parsing the URL, the router can execute step S507.

[0070] Of course, the router can also perform HTTP parsing and execute step S507. It can be understood that since the HTTP message is an unencrypted message and there is no handshake message. Therefore, when the router does not need to parse the handshake message, it can obtain the host identifier of the server domain name of the HTTP message.

[0071] S507. The router matches the parsed URL with the resource information.

[0072] The router can match the parsed URL with the resource information in the router to determine whether the parsed message should be intercepted. Among them, the resource information can be the information in the local memory of the router, and the resource information can include one or more non-secure URLs.

[0073] In a possible implementation, the router can convert string matching into tree-based numerical matching with resource information and combine it with collision string comparison to achieve the matching of the URL and the resource information. The tree-based numerical value can be understood as storing numerical values using a hash bucket.

[0074] Exemplarily, for one or more non-secure URLs, the router can store them in one or more hash buckets. A hash bucket is a basic unit in a hash table data structure and can be used to store elements in the hash table. It can be understood that each hash bucket can have a corresponding hash identifier, and different hash buckets have different corresponding hash identifiers. One or more non-secure URLs can be stored in each hash bucket, and the hash values corresponding to the one or more non-secure URLs stored in the same hash bucket are all the same. Optionally, the hash value corresponding to the one or more non-secure URLs can be used as the hash identifier of the hash bucket where the one or more non-secure URLs are located.

[0075] For example, the first hash bucket stores A non-secure URLs, and the hash values corresponding to the A non-secure URLs are all hashA. The hash identifier of the first hash bucket can be hashA. The second hash bucket stores B non-secure URLs, and the hash values corresponding to the B non-secure URLs are all hashB. The hash identifier of the second hash bucket can be hashB. And hashA is different from hashB, where A and B are positive integers respectively.

[0076] After the router parses the URL, it can process the URL through a hash function to obtain a hash value, and match the hash value with the hash identifiers of one or more hash buckets. If the hash value of the URL is the same as the hash identifier of a certain hash bucket, to prevent hash collisions, the router can further perform a string comparison between the URL and one or more non-secure URLs in the hash bucket. Among them, hash collision can be understood as two different strings obtaining the same hash value after being processed by a hash function.

[0077] If they are the same string, it means that the parsed URL matches the URL in the resource information successfully, that is, the URL is a non-secure URL, and the router can intercept the URL. Thus, while maintaining the interception success rate, the URL matching latency can be increased, and the speed of the router processing data can be improved.

[0078] In another possible implementation, the router can adopt a method of converting string matching into array numerical value matching with resource information to achieve the matching of the URL and the resource information.

[0079] Exemplarily, for one or more non-secure URLs, the router can store them in an array. Among them, each element of the array can be used to store an instance of a data structure. Each instance of the data structure can include a non-secure URL and the hash value corresponding to the non-secure URL. It can be understood that the hash values corresponding to different instances of the data structure can be the same or different.

[0080] For example, an instance of the first data structure can be the non-secure website C, and the hash value corresponding to the non-secure website C is hashC. An instance of the second data structure can be the non-secure website D, and the hash value corresponding to the non-secure website D is hashD. hashC and hashD can be the same or different.

[0081] When the router resolves the website address, it can process the website address through a hash function to obtain a hash value, and match the hash value with the hash value corresponding to the instance of the data structure in the array. If the hash value of the website address is the same as the hash value corresponding to an instance of a data structure, the router can further perform a string comparison between the website address and the non-secure website in the instance of the data structure. If they are the same string, it means that the resolved website address matches the website address in the resource information, that is, the website address is a non-secure website, and the router can intercept the website address.

[0082] Optionally, the router can also sort the instances of each data structure in ascending order or descending order according to the size of the hash value corresponding to the instance of the data structure in the array. And use the binary search method to search for the hash value in the array based on the hash value of the website address. It can be understood that sorting the array and using the binary search method for website address matching can improve the search efficiency, reduce the time complexity and space complexity of the search, so as to improve the website address matching delay and enhance the data processing speed of the router on the premise of maintaining the interception success rate.

[0083] Of course, the router can also use other methods to implement the matching of the website address and the resource information, which is not limited in the embodiments of the present application.

[0084] S508. The router forwards the unmatched http request or https request to the resource server.

[0085] If the resolved website address does not successfully match the website address in the resource information, it means that the resolved website address is not a non-secure website and should not be intercepted. Then the router can forward the http request or https request to the resource server.

[0086] If the resolved website address successfully matches the website address in the resource information, it means that the resolved website address is a non-secure website and should be intercepted. Then the router does not forward the http request or https request to the resource server. In this way, the router can reorganize the website address in the segmented handshake message in the https request initiated by the electronic device and resolve the website domain name, so as to effectively intercept the access to the non-secure website.

[0087] S509. The resource server returns an http request response message or an https request response message to the router.

[0088] S510. The router returns an HTTP request response message or an HTTPS request response message to the electronic device.

[0089] After obtaining the HTTP request or HTTPS request, the resource server can query the accessed content based on the IP address in the request, encapsulate the queried accessed content into the response message, and return it to the browser of the electronic device through the router. Furthermore, the browser can trigger the electronic device to display the content in the response message.

[0090] Figure 6 The figure shows a schematic diagram of the router in the embodiment of the present application parsing the handshake message.

[0091] It can be understood that Figure 6 The implementation process of the corresponding embodiment may include the implementation processes of step S506 and step S507 in the above Figure 5 For example, it includes the process of the router parsing the handshake message of the SSL protocol. Figure 6 Each process or step in the corresponding embodiment does not necessarily need to be executed in sequence. The present application embodiment does not limit the execution order of steps S601 to S604, as long as the method for the routing device to process the message can be implemented. In a possible implementation, Figure 6 The corresponding embodiment may be executed by the kernel forwarding plane of the router. For ease of description, the following takes the kernel forwarding plane parsing the handshake message as an example for illustration.

[0092] S601. The kernel forwarding plane of the router introduces the forwarding message into the parsing logic of the IP_FORWARD node.

[0093] The kernel forwarding plane can introduce the forwarding message into the parsing logic of the IP_FORWARD node. Among them, the IP_FORWARD node can be used to control the forwarding of data packets.

[0094] Exemplarily, in the parsing logic of the IP_FORWARD node, the kernel forwarding plane can obtain the connection tracking corresponding to each skb from the IP_FORWARD node. It can be understood that during the process of network data transmission using protocols such as Transmission Control Protocol (TCP) or User Datagram Protocol (UDP), an end-to-end data flow can be established between the electronic device and the server, and the connection tracking table corresponding to the data flow can be saved inside the protocol. Information such as five-tuple and aging time is recorded in the connection tracking table for managing the status of network connections, etc. In the connection tracking table, one data flow can correspond to one connection tracking. One or more packets can be transmitted between the electronic device and the server based on the connection tracking.

[0095] The kernel forwarding plane can obtain the five-tuple information from the connection tracking corresponding to the packet. The five-tuple information can be understood as a set of five key fields used to uniquely identify the data flow. When combined together, these key fields can be used to distinguish different data flows. This set can include: source IP address, destination IP address, source port number, destination port number, and protocol type. Among them, the source IP address is used to indicate the IP address of the sender of the data packet. The destination IP address is used to indicate the IP address of the receiver of the data packet. The source port number is used to indicate the port number used by the sender. The destination port number is used to indicate the port number used by the receiver. The protocol type is used to indicate the protocol type used in the transport layer, such as TCP, UDP, etc.

[0096] The kernel forwarding plane can filter the packets with the destination port of 443 through the destination port in the five-tuple information. It can be understood that the packets with the destination port of 443 belong to https packets. Filtering the packets with the destination port of 443 can be understood as filtering https packets. If it is an http packet, the corresponding port can be 80 or 8080.

[0097] S602. The kernel forwarding plane of the router manages the fragmented handshake packets of the SSL protocol based on the data flow.

[0098] Exemplarily, the kernel forwarding plane can identify the first anchor packet of the handshake packet of the SSL protocol. This first anchor packet can be understood as the starting part of the handshake packet. The first anchor packet can include, but is not limited to, one or more of the following: the content type of the packet, the SSL protocol version, the length of the subsequent data, etc. Among them, the content type of the packet can include handshake packets, alert packets, application data packets, etc.

[0099] It can be understood that the https packet can include the headers of the packet, such as the mac header, IP header, TCP header, etc., and can also include the data body payload. Among them, the data body can include information such as the format and data of the handshake packet. The kernel forwarding plane can first determine whether the content type of the segmented packet parsed is a handshake packet. If the content type of the segmented packet parsed is the identifier of a handshake packet, the kernel forwarding plane can further determine whether the handshake message type of the handshake packet is Client Hello. This Client Hello is a message triggered by the browser for the electronic device to send to the server to indicate the start of the handshake process. If the handshake message type is Client Hello, the kernel forwarding plane can determine that this segmented packet is the first anchor packet, which can also be called the first segmented packet. For example, if the kernel forwarding plane determines that the content type content type of the segmented packet is the identifier Handshake of a handshake packet, and the handshake message type handshake type of the handshake packet is Client Hello, it means that this segmented packet is the first anchor packet, that is, the first segmented packet.

[0100] The kernel forwarding plane can also back up the first anchor packet. For example, the kernel forwarding plane can cache the backup of the first anchor packet in the data management (DM) flow table to facilitate the recombination of subsequent segmented packets. Among them, the backup of the first anchor packet can also be called the copy of the first anchor packet. The DM flow table can record information such as the five-tuple information of the first anchor packet, the number of matching times, and the buffer area for data backup.

[0101] The kernel forwarding plane can also release the backed-up first anchor packet, that is, send out the backed-up first anchor packet. It can be understood that since the kernel forwarding plane has not obtained the complete website address when obtaining the first anchor packet, the kernel forwarding plane cannot determine whether the current packet contains an insecure website address. In order not to block network services, the kernel forwarding plane can first release the first anchor packet after backing it up.

[0102] S603. The kernel forwarding plane of the router processes the subsequent segmented packets of the same data stream for the SSL protocol.

[0103] The kernel forwarding plane can identify subsequent fragmented packets of the same data stream based on information such as the five-tuple, sequence number (seq), and next sequence number (nseq). Subsequent fragmented packets can also be understood as subsequent data packets of the same data stream. It can be understood that the five-tuple information of the same packet is the same, that is, the five-tuple information of each fragmented packet of the same packet is the same. Therefore, it is possible to determine whether it is the same packet, that is, the same data stream, based on the five-tuple information.

[0104] The sequence number can be used to track the order of data packets, enabling the data to be reassembled in the correct order. The sequence number and next sequence number information can also be simply referred to as seq&nseq information. Among them, seq represents the sequence number of the current data packet, and nseq represents the sequence number of the next data packet expected to be received.

[0105] The kernel forwarding plane can also reassemble the subsequent fragmented packets with the copy of the first-segment anchor packet in the DM flow table to parse out the website address of the server_name field.

[0106] Exemplarily, the kernel forwarding plane can parse out the five-tuple information of the fragmented packets that conform to port 443 and determine whether the five-tuple information of the fragmented packet is the same as the five-tuple information of the cached copy of the first-segment anchor packet. If the five-tuple information of the fragmented packet is the same as the five-tuple information of the copy of the first-segment anchor packet, the kernel forwarding plane can determine that the fragmented packet is a subsequent fragmented packet of the first-segment anchor packet.

[0107] To enable each fragmented packet to be reassembled in the correct order, the kernel forwarding plane can obtain the seq&nseq information of each fragmented packet. For the fragmented packets with the same parsed five-tuple information and matching sequence number order, the kernel forwarding plane can append them based on the copy of the first-segment anchor packet to gradually obtain the complete packet, thereby realizing the reassembly of the packet. It can be understood that if the fragmented handshake packet includes N segments, the kernel forwarding plane can reassemble the N segments of the packet until the website address corresponding to the server_name field is parsed out.

[0108] Exemplarily, in the case where the website address cannot be parsed out from the first-segment anchor packet, the kernel forwarding plane can back up the first-segment anchor packet in the DM flow table and release the first-segment anchor packet. That is to say, the kernel forwarding plane can save the copy of the first-segment anchor packet and send the first-segment anchor packet out.

[0109] After the kernel forwarding plane identifies the second fragmented packet of the handshake packet based on the five-tuple information and seq&nseq information, the kernel forwarding plane can append a copy of the second fragmented packet after the copy of the first-segment anchor packet (i.e., the first fragmented packet), and recombine the copy of the first-segment anchor packet and the copy of the second fragmented packet into a new anchor packet. At this time, it can be understood that the matching count of the first-segment anchor packet is 1. In the case where the URL cannot be parsed from the new anchor packet, the kernel forwarding plane can back up the new anchor packet and send out the second fragmented packet.

[0110] Similarly, after the kernel forwarding plane identifies the third fragmented packet of the handshake packet based on the five-tuple information and seq&nseq information, the kernel forwarding plane can append a copy of the third fragmented packet after the anchor packet (i.e., the anchor packet recombined from the copy of the first-segment anchor packet and the copy of the second fragmented packet), and recombine the anchor packet and the copy of the third fragmented packet into a new anchor packet. At this time, it can be understood that the matching count of the first-segment anchor packet is 2. In the case where the URL cannot be parsed from the new anchor packet, the kernel forwarding plane can back up the new anchor packet and send out the third fragmented packet.

[0111] By analogy, the kernel forwarding plane can recombine the packets of the fourth segment, …, the Nth segment until the URL corresponding to the server_name field is parsed, or until the preset matching count or preset matching duration is exceeded. Among them, if the anchor packet and the copy of the Nth fragmented packet can be recombined into a new anchor packet, it can be understood that the matching count of the first-segment anchor packet is N - 1.

[0112] It can be understood that after the URL corresponding to the server_name field is parsed, the kernel forwarding plane can match the parsed URL with the URL in the resource information to determine whether the parsed URL is an insecure URL, that is, whether it should be intercepted.

[0113] If the parsed URL does not match successfully with the URL in the resource information, it means that the parsed URL is not an insecure URL, then the kernel forwarding plane can not intercept the parsed URL. It can also be understood that if the parsed URL is not an insecure URL, the kernel forwarding plane can send out the last identified fragmented packet, so that the packet received by the server is a complete packet. For example, if the kernel forwarding plane recombines the copy of the Nth fragmented packet, parses the URL corresponding to the server_name field, and determines that the URL is not an insecure URL, then the kernel forwarding plane can send out the Nth fragmented packet. In this way, the server can receive a complete packet, thereby parsing out a complete URL, enabling the electronic device to access the URL.

[0114] If the parsed URL matches the URL in the resource information, it indicates that the parsed URL is an insecure URL, and the kernel forwarding plane of the router can intercept the parsed URL. It can also be understood that if the parsed URL is an insecure URL, the kernel forwarding plane will not send the last recognized fragmented packet, resulting in an incomplete packet received by the server. For example, if the kernel forwarding plane reassembles the Nth fragmented packet copy, parses the URL corresponding to the server_name field, and determines that the URL is an insecure URL, the kernel forwarding plane will not send the Nth fragmented packet. In this way, even if the first to the (N - 1)th fragmented packets are sent, the server will not receive a complete packet, thus unable to parse the complete URL and preventing the electronic device from accessing the insecure URL.

[0115] Optionally, in the embodiments of the present application, the router may perform reassembly, parsing, matching, interception, or forwarding on each fragmented packet at the network layer of the protocol.

[0116] S604. The kernel forwarding plane of the router performs memory management on the DM flow table.

[0117] Optionally, when the URL corresponding to the server_name field is parsed, the kernel forwarding plane may release the first anchor packet copy and subsequent fragmented packet copies in the DM flow table.

[0118] Optionally, when the number of matching times of the five-tuple information of the first anchor packet exceeds the preset number of matching times, it can also be understood that the number of matching times of the first anchor packet exceeds the preset number of matching times, indicating that the probability of reassembling the packet based on this first anchor packet is relatively small. To save memory space, the kernel forwarding plane may release the anchor packet in the DM flow table. The preset number of matching times can be pre-set by the router and can be determined according to experimental tests or empirical values. The specific value of the preset number of matching times is not limited in the embodiments of the present application.

[0119] Optionally, when the matching duration of the first anchor packet exceeds the preset matching duration, the kernel forwarding plane may release the anchor packet in the DM flow table. The preset matching duration can be pre-set by the router and can be determined according to experimental tests or empirical values. For example, it can be set to 2 seconds (s) or a value near 2s. The specific value of the preset matching duration is not limited in the embodiments of the present application.

[0120] Of course, the kernel forwarding plane can also periodically release the copies of the first-segment anchor packets and the subsequent fragmented packet copies in the DM flow table that meet the above conditions, which is not limited in the embodiments of this application. The process of releasing memory can also be understood as an aging process, or a process of destroying unneeded data or data that is no longer valid. In this way, fragmented packets of more different data streams can be processed in a limited memory space for a long time, effectively controlling the space occupancy of the DM flow table and timely clearing unnecessary memory data in the router. Thus, the memory space of the router can be saved and the operation efficiency of the router can be improved.

[0121] It can be understood that for protocols with a retransmission mechanism, there may still be a situation where the router cannot intercept non-secure URLs.

[0122] As Figure 7 shown, the electronic device can send a handshake packet of the SSL protocol to the router. However, when the length of the handshake information of the SSL protocol generated by the electronic device is greater than the maximum segment size (MSS), the electronic device can send data to the router using fragmented packets. For example, the fragmented packets include a first fragmented packet and a second fragmented packet. Among them, the first fragmented packet includes a mac header, an IP header, a TCP header, a first part of the data body, etc., and the second fragmented packet includes a mac header, an IP header, a TCP header, a second part of the data body, etc. In some implementations, the maximum segment size can be set to 1438 bytes, which is not limited in the embodiments of this application.

[0123] When the router receives the first fragmented packet, it can use it as the first-segment anchor packet. After backing up the first-segment anchor packet, the router can release the first-segment anchor packet. When the router receives and recognizes the second fragmented packet, it can recombine the copy of the first-segment anchor packet and the copy of the second fragmented packet. If the URL parsed after the recombination of the copy of the first-segment anchor packet and the copy of the second fragmented packet is a non-secure URL, the router can intercept the second fragmented packet and will not send the second fragmented packet out.

[0124] However, protocols such as SSL and TCP have retransmission mechanisms, such as including congestion control mechanisms, packet loss retransmission mechanisms, timeout retransmission mechanisms, etc. Taking the timeout retransmission mechanism as an example, when the electronic device detects that for the second fragmented packet sent by itself, after a preset time period, the electronic device has not received the response packet of the second fragmented packet, the electronic device can resend the second fragmented packet.

[0125] Since the router has already reorganized based on the copy of the first - segment anchor packet and the copy of the second - segment fragmented packet, and successfully parsed the URL, the router will delete the anchor packet generated based on the copy of the first - segment anchor packet and the copy of the second - segment fragmented packet from the DM flow table to save memory space. In this case, for the second - segment fragmented packet resent by the electronic device, since there is no anchor packet in the router's DM flow table to match with the second - segment fragmented packet. Therefore, the router will send out the second - segment fragmented packet. Then the server can receive all the fragmented packets, thus reorganizing the complete URL, making the router fail to intercept the non - secure URL.

[0126] For Figure 7 this situation, the embodiment of the present application can, after reorganizing the fragmented packet and parsing out the non - secure URL, add a mark identifier to the connection tracking of the data stream corresponding to the URL to indicate that the data stream corresponding to the URL is a non - secure data stream. Then the router can intercept the subsequent packets involved in the data stream based on the mark identifier, thereby achieving the interception of the re - transmitted fragmented packet.

[0127] Exemplarily, as Figure 8 shown, in the network layer of the protocol, there may be an IP_FORWARD node. The IP_FORWARD node can be used to control the forwarding of data packets. For example, before the data packet is forwarded, it allows the router to process the data packet to be forwarded. In a possible implementation, the kernel forwarding plane of the router can introduce the forwarding packet into the parsing logic of the IP_FORWARD node.

[0128] In the parsing logic of the IP_FORWARD node, when the router receives a fragmented packet, the kernel forwarding plane of the router can obtain the five - tuple information from the connection tracking. On the one hand, this five - tuple information can be used to filter out the packets with the destination port 443 (i.e., https packets). On the other hand, this five - tuple information can be used to find the connection tracking corresponding to the five - tuple information in the connection tracking table and determine whether the connection tracking includes a mark identifier.

[0129] If the connection tracking includes a mark identifier, it indicates that the data stream where the fragmented packet is located is identified as a data stream containing a non - secure URL, and this fragmented packet needs to be discarded. Then the router can intercept this fragmented packet.

[0130] If the connection tracking does not include a mark identifier, it indicates that the data stream where the fragmented packet is located is not identified as a data stream containing a non - secure URL. Then the kernel forwarding plane can further process this fragmented packet.

[0131] If the kernel forwarding plane identifies that the fragmented packet includes the Client Hello identifier, it indicates that the fragmented packet is the first-segment anchor packet, i.e., the first fragmented packet. Then, the kernel forwarding plane can cache a copy of the first-segment anchor packet in the DM flow table and send the first-segment anchor packet. For the specific method of identifying the first-segment anchor packet, reference can be made to Figure 6 the relevant description in step S602 of the corresponding embodiment, which will not be elaborated here.

[0132] If the kernel forwarding plane does not identify the Client Hello identifier, the kernel forwarding plane can match the fragmented packet with the copy of the first-segment anchor packet (i.e., the copy of the first fragmented packet) in the DM flow table. In the case of identifying the subsequent fragmented packets of the first-segment anchor packet based on the five-tuple information and seq&nseq information, the kernel forwarding plane can cache the copies of the subsequent fragmented packets in the DM flow table and recombine them with the copy of the first-segment anchor packet. For the specific method of identifying the subsequent fragmented packets, reference can be made to Figure 6 the relevant description in step S603 of the corresponding embodiment, which will not be elaborated here.

[0133] For the subsequent fragmented packets, if the parsed URL after recombination is a non-secure URL, on the one hand, the router can intercept the subsequent fragmented packets and add a mark identifier in the connection tracking table. It can be understood that through the mark identifier, the router can not only identify that the URL is a non-secure URL, but also identify the data stream corresponding to the URL as a non-secure data stream. In this way, when the fragmented packet is retransmitted, the router can successfully intercept the retransmitted fragmented packet, preventing the electronic device from accessing the non-secure URL.

[0134] On the other hand, the router can timely clear the relevant information such as the copy of the first-segment anchor packet and the copies of the subsequent fragmented packets in the DM flow table. It can be understood that timely clearing the information in the DM flow table can process the fragmented packets of more different data streams in a limited memory space for a long time, effectively controlling the space occupancy of the DM flow table, thereby saving the memory space of the router and improving the operation efficiency of the router.

[0135] Exemplarily, when an electronic device divides a handshake message into three segmented messages for transmission, and the server_name field is in the third segmented message, in a possible implementation, relevant information about the three segmented messages sent by the electronic device can be obtained through the wireshark packet capture tool. The segmented messages sent by the router can also be obtained by means of packet capture on the WAN side. The method of packet capture on the WAN side can include obtaining the segmented messages sent by the router based on the switch mirroring packet capture function. Since the server_name field is in the third segmented message, when the router obtains the third segmented message, the website address can be parsed. In the case where the parsed website address is determined to be a non-secure website, the router can intercept the third segmented message, that is, the third segmented message is not sent. In this way, the segmented messages sent by the router obtained through the switch mirroring packet capture function do not include the third segmented message, so it can be considered that the router has intercepted the non-secure website address.

[0136] The router can also add a mark identifier to the data stream where the third segmented message is located. When the electronic device triggers the retransmission mechanism, the electronic device can retransmit the third segmented message, and then relevant information about the third segmented message sent by the electronic device multiple times can be obtained through the wireshark packet capture tool. Since the router can block the retransmission of the third segmented message based on the mark identifier, that is, for the third segmented message retransmitted by the electronic device, the router can still successfully intercept it. Therefore, even if the electronic device retransmits the third segmented message, the segmented messages sent by the router obtained through the switch mirroring packet capture function still do not include the third segmented message. Through the above method, it can be verified that by using the method for processing messages by the routing device according to the embodiments of the present application, the router can successfully intercept non-secure website addresses. Thereby, the attack on the electronic device by non-secure website addresses can be reduced, and the security of the electronic device can be improved.

[0137] Figure 9 The method for processing messages by the routing device according to the embodiments of the present application is shown. Applied to a routing device, the method includes:

[0138] S901. The routing device obtains N segmented messages from an electronic device and sends the N segmented messages, where the routing device cannot parse a website address from the N segmented messages, and N is a positive integer greater than or equal to 1.

[0139] In the embodiments of the present application, the N segmented packets may include the N segmented handshake packets of the SSL protocol mentioned above. Taking the N segmented handshake packets as an example, the routing device may obtain the N segmented handshake packets based on the N sk_buff structures. Any one of the N segmented handshake packets only contains a part of the handshake information, and the routing device cannot obtain all the handshake information of the SSL protocol from one packet. In this case, the routing device needs to recombine the segmented handshake packets to resolve the complete website address. Among them, the N segmented packets may also be referred to as N-segment segmented packets.

[0140] For the specific identification, recombination, and parsing of segmented packets by the routing device, reference may be made to Figure 6 the relevant descriptions of steps S602 and S603 in the corresponding embodiments, which will not be elaborated here. It can be understood that if the routing device cannot resolve the website address from the N segmented packets, it cannot determine whether the packets sent by the electronic device contain non-secure website addresses. To avoid blocking network services, the routing device may send the N segmented packets.

[0141] S902. The routing device obtains the (N + 1)-th segmented packet from the electronic device and resolves the website address from the (N + 1) segmented packets, where the N segmented packets and the (N + 1)-th segmented packet are packets in the same data stream.

[0142] S903. When the first information includes the website address, the routing device does not send the (N + 1)-th segmented packet, and the first information includes one or more non-accessible website addresses.

[0143] The first information can be understood as the resource information in the router mentioned above. The resource information may be the information in the local memory of the routing device, and the resource information may include one or more non-secure website addresses.

[0144] For the specific process of the routing device resolving the website address from the (N + 1) segmented packets, reference may be made to Figure 6 the relevant descriptions of the subsequent segmented packet processing in step S603 of the corresponding embodiment, which will not be elaborated here.

[0145] When the routing device resolves the website address from the (N + 1) segmented packets, the routing device may match the resolved website address with the website addresses in the first information to determine whether the resolved website address is a non-secure website address, that is, whether it should be intercepted. For the specific process of the routing device matching the resolved website address with the website addresses in the first information, reference may be made to Figure 5 the relevant descriptions in step S507 of the corresponding embodiment, and Figure 6 the relevant descriptions in step S603 of the corresponding embodiment, which will not be elaborated here.

[0146] It can be understood that the first piece of information includes a website address. If the parsed website address is an insecure website address, the routing device can intercept the parsed website address. It can also be understood that if the parsed website address is an insecure website address, the routing device will not send the last recognized segmented packet, so that the packet received by the server is an incomplete packet. In this way, even if the first segmented packet to the Nth segmented packet are sent out before, the server will not receive a complete packet, and thus cannot parse out the complete website address, making the electronic device unable to access the insecure website address.

[0147] Optionally, based on the Figure 9 corresponding embodiment, the method may further include: obtaining the (N + 1)th segmented packet from the electronic device again, and the routing device does not send the (N + 1)th segmented packet.

[0148] It can be understood that some network protocols have a retransmission mechanism. When the electronic device detects that for the (N + 1)th segmented packet sent out, and after a preset time period, the electronic device has not received the response packet of the (N + 1)th segmented packet, the electronic device can resend the second segmented packet. Then the routing device can obtain the (N + 1)th segmented packet from the electronic device again.

[0149] In the embodiment of the present application, for the (N + 1)th segmented packet obtained again from the electronic device, the routing device can still not send the (N + 1)th segmented packet. Exemplarily, after the routing device parses out an insecure website address, it can add a mark identifier to the connection tracking of the data stream corresponding to the website address, which is used to indicate that the data stream corresponding to the website address is an insecure data stream. For the specific interception of the retransmitted segmented packet by the routing device, reference can be made to the Figure 8 relevant description in the corresponding embodiment, which will not be elaborated here. In this way, the routing device can intercept the subsequent packets involved in the data stream, so as to realize the interception of the retransmitted segmented packet, making the electronic device unable to access the insecure website address.

[0150] Optionally, based on the Figure 9 corresponding embodiment, the method may further include: when the first piece of information includes a website address, adding an identifier to the data stream where the (N + 1)th segmented packet is located, and the identifier is used to indicate that the data stream includes a website address that is not allowed to be accessed.

[0151] In the embodiment of the present application, the identifier can be understood as the mark identifier mentioned above. This mark identifier can be used to indicate that the data stream includes a website address that is not allowed to be accessed, and it can also be understood that the data stream corresponding to the website address is an insecure data stream. For the specific process of adding an identifier to the data stream where the (N + 1)th segmented packet is located, reference can be made to the Figure 8 relevant description in the corresponding embodiment, which will not be elaborated here.

[0152] It can be understood that by adding an identifier, the router can not only identify that a website is an insecure website, but also identify the data stream corresponding to the website as an insecure data stream. In this way, when a fragmented packet is retransmitted, the router can successfully intercept the retransmitted packet, preventing the electronic device from accessing the insecure website.

[0153] Optionally, based on Figure 9 the corresponding embodiment, the method may further include: obtaining the (N + 1)-th fragmented packet from the electronic device again, and based on the identifier, the routing device does not send the (N + 1)-th fragmented packet.

[0154] When the routing device obtains the (N + 1)-th fragmented packet from the electronic device again, the routing device may, based on the identifier, determine that the data stream corresponding to the (N + 1)-th fragmented packet is an insecure data stream, and the data stream includes a website that is not allowed to be accessed. Then the routing device may not send the (N + 1)-th fragmented packet. Thus, the routing device can intercept the insecure packet.

[0155] Optionally, based on Figure 9 the corresponding embodiment, obtaining N fragmented packets from the electronic device and sending the N fragmented packets may include: obtaining the i-th fragmented packet from the electronic device; updating and saving the first anchor packet, where the first anchor packet is obtained based on the i fragmented packets from the first fragmented packet to the i-th fragmented packet, and i is a positive integer less than or equal to N; sending the i-th fragmented packet, where the routing device cannot parse a website from the first anchor packet.

[0156] The first anchor packet can be understood as the anchor packet generated by the routing device during the process of obtaining N fragmented packets. The first anchor packet can be continuously updated as the received fragmented packets.

[0157] Exemplarily, when the routing device obtains the first fragmented packet, the routing device may identify a copy of the first fragmented packet as the first-segment anchor packet. When the routing device obtains the second fragmented packet, the routing device may recombine a copy of the first-segment anchor packet and a copy of the second fragmented packet into a new anchor packet. When the routing device obtains the third fragmented packet, the routing device may recombine the previously updated anchor packet and a copy of the third fragmented packet into a new anchor packet, thereby realizing the continuous update of the anchor packet. The specific update and saving of the anchor packet may refer to Figure 6 the relevant description in step S603 of the corresponding embodiment, which will not be elaborated here.

[0158] It can be understood that when the updated anchor message cannot be parsed to obtain the website address, since the routing device cannot determine whether the message sent by the electronic device contains a non-secure website address. To avoid blocking network services, the routing device can back up the new anchor message and send out the i-th segmented message.

[0159] Optionally, based on Figure 9 the corresponding embodiment, the first anchor message is obtained by combining i segmented messages based on the sequence number and the next sequence number information.

[0160] The sequence number and the next sequence number information (seq&nseq information) can be used to track the order of the segmented messages, so that the segmented messages can be recombined in the correct order to obtain the first anchor message. Specifically, regarding the sequence number and the next sequence number information, and the implementation of obtaining the first anchor message based on the sequence number and the next sequence number information, reference can be made to Figure 6 the relevant description in step S603 of the corresponding embodiment, which will not be elaborated here.

[0161] In this way, based on the sequence number and the next sequence number information, the routing device can append the subsequent segmented messages on the basis of the copy of the first-segment anchor message, so as to gradually obtain the complete message and realize the recombination of the message.

[0162] Optionally, based on Figure 9 the corresponding embodiment, the method may further include: when the website address is included in the first information, deleting the second anchor message, where the second anchor message is obtained based on N + 1 segmented messages from the first segmented message to the (N + 1)-th segmented message.

[0163] The second anchor message can be understood as the anchor message generated by the routing device based on the first anchor message and the (N + 1)-th segmented message when obtaining the (N + 1)-th segmented message. The routing device can parse the website address from the second anchor message.

[0164] In the embodiment of the present application, when the routing device parses the website address, the second anchor message can be released. In this way, more segmented messages of different data streams can be processed in a limited memory space for a long time, effectively controlling the space occupied by the routing device, and timely cleaning up unnecessary memory data in the router, thereby improving the operation efficiency of the router.

[0165] Optionally, based on Figure 9Based on the corresponding embodiments, the method may further include: if the number of matches of the second information is greater than or equal to a preset number of matches, deleting the first anchor packet, where the second information is used to indicate that the N segmented packets and the (N + 1)-th segmented packet are packets in the same data stream; or, if the time interval from obtaining the first segmented packet from the electronic device to determining that the first information includes a website address is greater than or equal to a preset matching duration, deleting the first anchor packet.

[0166] The second information can be understood as the five-tuple information mentioned above. The five-tuple information can be used to uniquely identify a data stream, and based on the five-tuple information, it can be determined that the N segmented packets and the (N + 1)-th segmented packet are packets in the same data stream. Since the routing device starts matching from the first segmented packet, the number of matches of the second information can be understood as the number of matches of the five-tuple information of the first segmented packet (the first anchor packet).

[0167] In the embodiments of the present application, when the number of matches of the five-tuple information of the first anchor packet exceeds the preset number of matches, it indicates that the probability of reassembling packets based on this first anchor packet is relatively small. To save memory space, the routing device can delete the first anchor packet.

[0168] The time interval from obtaining the first segmented packet from the electronic device to determining that the first information includes a website address can also be understood as the matching duration of the first anchor packet. When the matching duration exceeds the preset matching duration, the routing device can delete the first anchor packet.

[0169] Among them, the preset number of matches and the preset matching duration can refer to Figure 6 the relevant descriptions in step S604 of the corresponding embodiments, which will not be elaborated here. In this way, a relatively large number of segmented packets of different data streams can be processed in a limited memory space for a long time, and unnecessary memory data in the router can be cleared in a timely manner. Thus, the memory space of the router is saved, and the operating efficiency of the router is improved.

[0170] Optionally, on the basis of Figure 9 the corresponding embodiments, the second information includes the five-tuple information of the data stream, the website address includes a Hypertext Transfer Protocol Secure (HTTPS) type website address, and the N segmented packets are handshake packets of the Secure Sockets Layer (SSL) protocol.

[0171] The method for a routing device to process packets provided by the embodiments of the present application enables the routing device to perform website address reassembly on multiple segmented handshake packets of the SSL protocol in an HTTPS type request, and parse out the website address requested by the electronic device to be accessed based on the five-tuple information, etc. The routing device can also intercept website addresses that are not allowed to be accessed, thereby reducing attacks on the electronic device by non-secure website addresses and enhancing the security of the electronic device.

[0172] The above specific embodiments have elaborated in detail the objectives, technical solutions, and beneficial effects of the embodiments of the present application. It should be understood that the above are merely specific embodiments of the embodiments of the present application and are not used to limit the protection scope of the embodiments of the present application. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the embodiments of the present application shall be included within the protection scope of the embodiments of the present application.

[0173] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to select authorization or rejection.

[0174] The above mainly introduced the technical solutions provided by the embodiments of the present application from the perspective of methods. To implement the above functions, it includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that the method steps described in combination with the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and software. Whether a certain function is executed in the way of hardware or software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described function for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0175] The embodiments of the present application provide a routing device. As Figure 10 shown, it is a schematic structural diagram of the routing device provided by the embodiments of the present application. The routing device 1000 may include one or more processors 1001 and a memory 1002. The memory 1002 may be used to store one or more programs. The one or more processors 1001 may call the one or more programs to enable the routing device 1000 to execute the technical solutions in the above embodiments.

[0176] The embodiments of the present application provide a chip system. The chip system is applied to a routing device, and the chip system may include one or more processors. The one or more processors may be used to call programs to enable the routing device to execute the technical solutions in the above embodiments.

[0177] Figure 11 It is a schematic structural diagram of a chip system provided by the embodiments of the present application. The chip system 1100 includes one or more processors 1101, communication lines 1102, communication interfaces 1103, and a memory 1104.

[0178] In some embodiments, the memory 1104 stores the following elements: executable modules or data structures, or subsets thereof, or extended sets thereof.

[0179] The methods described in the embodiments of the present application above can be applied to or implemented by the processor 1101. The processor 1101 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above methods can be completed by the integrated logic circuit in hardware or instructions in software form in the processor 1101. The above-mentioned processor 1101 may be a general-purpose processor (e.g., a microprocessor or a conventional processor), a DSP, an application-specific integrated circuit, a field-programmable gate array or other programmable logic devices, discrete gates, transistor logic devices or discrete hardware components. The processor 1101 can implement or execute the methods, steps and logic block diagrams related to processing in the embodiments of the present application.

[0180] The methods of the embodiments of the present application can be embodied as being executed by a hardware decoding processor or being executed by a combination of hardware and software modules in the decoding processor. Among them, the software module can be located in the memory 1104, and the processor 1101 can read the information in the memory 1104 and combine its hardware to complete the steps of the above methods. Communication can be carried out between the processor 1101, the memory 1104 and the communication interface 1103 through the communication line 1102.

[0181] The embodiments of the present application also provide a readable storage medium (which can also be referred to as a computer-readable storage medium). The readable storage medium includes a program. When the program runs on the routing device, it causes the routing device to execute the technical solutions in the above embodiments.

[0182] The methods described in the above embodiments can be implemented in whole or in part by software, hardware, firmware or any combination thereof. If implemented in software, the functions can be stored as one or more instructions or programs on a readable medium or transmitted on a readable medium. The readable medium can include a storage medium and a communication medium, and can also include any medium that can transfer a program from one place to another. The storage medium can be any accessible target medium.

[0183] In possible implementation manners, the readable medium can include a random access memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a compact disc read-only memory or other optical disc memories, etc. The readable medium can also include a magnetic disk memory or other magnetic disk storage devices, or any other medium targeted to carry or store the required program in the form of instructions or data structures and be accessible.

[0184] An embodiment of this application also provides a program product (which may also be referred to as a computer program product). The program product includes a program. When the program runs on a routing device, it causes the routing device to execute the technical solutions in the above embodiments.

[0185] In various embodiments of this application, if there is no special explanation and logical conflict, the terms and / or descriptions among the various embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0186] As described above, the above are only specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A method for a routing device to process packets, characterized in that, Applied to a routing device, the method includes: Obtaining N segmented packets from an electronic device and sending the N segmented packets, where the routing device cannot resolve a website address from the N segmented packets, and N is a positive integer greater than or equal to 1; Obtaining the (N + 1)th segmented packet from the electronic device and resolving the website address from the (N + 1)th segmented packet, where the N segmented packets and the (N + 1)th segmented packet are packets in the same data stream; When the first information includes the website address, the routing device does not send the (N + 1)th segmented packet, and the first information includes one or more website addresses that are not allowed to be accessed.

2. The method according to claim 1, wherein The method further includes: Obtaining the (N + 1)th segmented packet from the electronic device again, and the routing device does not send the (N + 1)th segmented packet.

3. The method according to claim 1 or 2, characterized in that, The method further includes: When the first information includes the website address, adding an identifier to the data stream where the (N + 1)th segmented packet is located, and the identifier is used to indicate that the data stream includes a website address that is not allowed to be accessed.

4. The method according to claim 3, characterized in that, The method further includes: Obtaining the (N + 1)th segmented packet from the electronic device again, and based on the identifier, the routing device does not send the (N + 1)th segmented packet.

5. The method according to any one of claims 1-4, characterized in that The obtaining N segmented packets from an electronic device and sending the N segmented packets includes: Obtaining the ith segmented packet from the electronic device; Updating and saving a first anchor packet, where the first anchor packet is obtained based on the i segmented packets from the first segmented packet to the ith segmented packet, and i is a positive integer less than or equal to N; Sending the ith segmented packet, where the routing device cannot resolve the website address from the first anchor packet.

6. The method according to claim 5, wherein The first anchor packet is obtained by combining the i segmented packets based on sequence number and next sequence number information.

7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: When the first information includes the website address, deleting a second anchor packet, where the second anchor packet is obtained based on the N + 1 segmented packets from the first segmented packet to the (N + 1)th segmented packet.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: If the number of matching times of the second information is greater than or equal to a preset matching number of times, deleting the first anchor packet, where the second information is used to indicate that the N segmented packets and the (N + 1)th segmented packet are packets in the same data stream; Or, if the time interval from obtaining the first segmented packet from the electronic device to determining that the first information includes the website address is greater than or equal to a preset matching duration, deleting the first anchor packet.

9. The method according to claim 8, wherein, The second information includes five-tuple information of the data stream, the website address includes a Hypertext Transfer Protocol Secure (HTTPS) type website address, and the N segmented packets are handshake packets of the Secure Sockets Layer (SSL) protocol.

10. A routing device, characterized in that, The routing device includes: one or more processors and a memory; The memory is used to store one or more programs, and the one or more processors call the one or more programs to enable the routing device to execute the method according to any one of claims 1 - 9.

11. A chip system, characterized in that, The chip system is applied to a routing device, and the chip system includes one or more processors, and the one or more processors are used to call instructions to cause the routing device to execute the method according to any one of claims 1-9.

12. A readable storage medium, characterized in that, The readable storage medium includes a program, and when the program runs on a routing device, it causes the routing device to execute the method according to any one of claims 1-9.

13. A program product, characterized in that, The program product includes a program, and when the program runs on a routing device, it causes the routing device to execute the method according to any one of claims 1-9.

Citation Information

Cited By

  • Method for processing packet by routing device, routing device, storage medium, and chip system

    WO2026148885A1