Long link message distribution method and system

By extracting the message length and verification fields to calculate the accuracy score, and dynamically adjusting the frame processing, the authentication logic bypass problem caused by sticky package unpacking in long-connected message distribution is solved, and the security and stability of the system are improved.

CN120342989AActive Publication Date: 2025-07-18GUANGZHOU STARLINK NETWORK ENGINEERING CO LTD
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510559529.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-18
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

In the existing long-connect message distribution technology, the sticking and unpacking of TCP communications leads to misalignment of the boundaries of authentication messages. Unauthorized users can bypass the authentication logic to access the system through exception messages, which poses serious security risks.

Method used

The server parses the received message, extracts the message length field and the verification field, calculates the accuracy score, dynamically adjusts the frame processing, and adapts to segment data through the sliding window to ensure the integrity of the authentication message boundaries and content.

Benefits of technology

Improve the security and stability of long-connect message distribution, prevent unauthorized users from pretending to be access, and enhance the system's adaptability and robustness in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342989A_ABST
    Figure CN120342989A_ABST
Patent Text Reader

Abstract

The invention discloses a long link message distribution method and system, and belongs to the technical field of information distribution. After a server establishes a long link and receives a first message, an authentication related field is analyzed, a message length field and a message verification field are extracted, comparison and verification are carried out on the extracted fields and actually received data, and the message length field and the message verification field are sent to the server; performing comprehensive calculation to obtain an accuracy score of message analysis; the correctness of framing processing is dynamically evaluated according to the accuracy score, when the score is lower than a preset threshold value, dynamic framing adjustment is executed, the integrity of authentication information and the correctness of boundaries are ensured by re-segmenting the data cache and independently analyzing the authentication information, and whether to continue the authentication process or disconnect the connection is determined according to a verification result. The accuracy and safety of framing processing in the authentication stage are effectively improved, the risk that an unauthorized user bypasses an authentication access system through package sticking and unpacking abnormities is reduced, and the safety of a long connection message distribution system is remarkably enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information distribution, and particularly to a long link message distribution method and system. Background Art

[0002] Long link message distribution means that after establishing a persistent connection (such as a TCP long connection or WebSocket), the server pushes messages to the client in real time through this stable connection. Compared with short links, long links can reduce the overhead of frequently establishing and closing connections, achieve efficient and low-latency message transmission, and are commonly used in scenarios that require real-time communication such as instant messaging, online games, and the Internet of Things.

[0003] The existing technologies have the following deficiencies:

[0004] In the existing long connection message distribution technology, due to the natural packet adhesion and packet splitting phenomena in TCP communication, if the server does not correctly perform frame splitting processing when receiving authentication messages and directly parses them only based on the received Buffer data, it is easy to cause the problem of message boundary misalignment. An attacker can quickly and continuously send authentication messages and ordinary service messages after establishing a connection. If the server mistakenly processes the service message content as authentication data, it may lead to the bypassing of the authentication logic, thus enabling unauthorized users to impersonate legitimate identities to access the system, bringing serious security risks. Summary of the Invention

[0005] The object of the present invention is to provide a long link message distribution method and system to solve the deficiencies in the background art.

[0006] To achieve the above object, the present invention provides the following technical solution: A long link message distribution method, comprising:

[0007] The server establishes a long link with the client and listens for the first message from the client;

[0008] The server parses the received message and extracts the field information related to authentication;

[0009] From the received field information, extract the message length field and the message verification field;

[0010] Based on the extracted message length field, perform a comparison calculation with the actual number of bytes of the received message, and based on the extracted message verification field, verify the message body, and comprehensively calculate the accuracy score of the current message parsing;

[0011] Evaluate the accuracy of the current frame splitting processing according to the accuracy score. When the accuracy score is lower than a preset threshold, perform dynamic frame splitting adjustment, including re-splitting the data cache according to the message length field and independently parsing the authentication message;

[0012] If the authentication information passes the verification after frame-by-frame adjustment, the subsequent authentication process continues; if the authentication information still fails the verification after frame-by-frame adjustment, the connection is disconnected and the client access is rejected.

[0013] Preferably, the field information includes a Token, a user identifier, and a device identifier.

[0014] Preferably, after comparing the extracted message length field value with the actually received byte count, a byte comparison deviation index is generated. The generation method is as follows:

[0015] Extract the message length field from the received message and denote it as L expected , indicating the expected length declared by the message, and count the actually received data byte count, denoted as L actual ;

[0016] Calculate the absolute value difference of the length deviation, denoted as ΔL: ΔL = |L expected -L actual |; Calculate the byte comparison deviation index S, and the expression is: e is the base of the natural logarithm; k is the exponential decay coefficient.

[0017] Preferably, after comparing the recalculated check value with the extracted check field, a check value comparison anomaly index is generated. The generation method is as follows:

[0018] Denote the extracted check field as Cexpected and the recalculated check value as Cactual and convert them into binary bit string forms;

[0019] Perform an exclusive OR operation on Cexpected and Cactual bit by bit to obtain an exclusive OR result bit string;

[0020] Count the number of bits with a value of 1 in the exclusive OR result and denote it as the number of different bits d;

[0021] Count the total number of bits of the check value and denote it as n;

[0022] Calculate the check value comparison anomaly index R:

[0023] Preferably, the byte comparison deviation index and the check value comparison anomaly index are normalized so that they are both within [0, 1]. After weighted average summation calculation of the normalized byte comparison deviation index and the check value comparison anomaly index, the accuracy score of the current message parsing is obtained.

[0024] Preferably, the accuracy of the current frame-by-frame processing is evaluated according to the accuracy score. When the accuracy score is lower than the preset threshold, dynamic frame-by-frame adjustment is performed:

[0025] After the server completes the comprehensive scoring based on the message length field and the message verification field, it reads the accuracy score of the current message parsing;

[0026] The server sets a preset threshold;

[0027] The server compares the current accuracy score with the preset threshold;

[0028] When the accuracy score is higher than or equal to the preset threshold, it is determined that the current frame processing is accurate, no adjustment is required, and the normal authentication process is continued;

[0029] When the accuracy score is lower than the preset threshold, it is determined that there is an abnormality in the current frame processing and dynamic adjustment needs to be performed.

[0030] Preferably, the adjustment specific steps include:

[0031] Step 1: Extract the target message length Ltarget;

[0032] Step 2: Initialize the sliding window, set the starting pointer pstart to point to the starting position of the cache, and the window size is initially set to W = Ltarget;

[0033] Step 3: Apply the sliding window scan on the buffer area. Each scan content includes: starting from pstart, intercepting a data segment with a length of W; performing a quick pre-parse on the data segment;

[0034] Step 4: Dynamically adjust the window size according to the pre-parse result: if the data segment conforms to the expected protocol structure, it is determined that the current window area is a complete authentication message; if not, the window is slid backward by a small step length, and W bytes are intercepted again for verification; set the maximum sliding offset to prevent invalid scanning;

[0035] Step 5: After confirming the complete message boundary, cut the data as an independent authentication message for formal parsing, and perform independent parsing on the re-segmented authentication message, including basic field extraction, length comparison, and content verification;

[0036] Step 6: The remaining data continues to repeat the sliding window detection until all the data in the buffer area is correctly segmented or timed out and exits.

[0037] The present invention also provides a long connection message distribution system, including a connection management module, a message parsing module, a protocol field extraction module, an accuracy scoring module, a frame management module, and an authentication processing module;

[0038] Connection management module: The server establishes a long connection with the client and listens for the first message from the client;

[0039] Message parsing module: The server parses the received message and extracts the field information related to authentication;

[0040] Protocol field extraction module: Extracts the message length field and the message check field from the received field information;

[0041] Accuracy scoring module: Compares and calculates based on the extracted message length field and the number of bytes of the actually received message, and verifies the message body based on the extracted message check field, and comprehensively calculates the accuracy score of the current message parsing;

[0042] Framing management module: Evaluates the accuracy of the current framing process according to the accuracy score. When the accuracy score is lower than the preset threshold, perform dynamic framing adjustment, including re-segmenting the data cache according to the message length field and independently parsing the authentication message;

[0043] Authentication processing module: If the authentication information passes the verification after the framing adjustment, continue the subsequent authentication process; if the authentication information still fails to pass the verification after the framing adjustment, disconnect the connection and reject the client access.

[0044] In the above technical solution, the technical effects and advantages provided by the present invention:

[0045] 1. After establishing a long connection between the server and the client, the present invention extracts fields, compares lengths, and verifies contents of the received authentication message, and combines to generate a byte comparison deviation index and a verification value comparison anomaly index, and comprehensively calculates the accuracy score of the message parsing, so as to dynamically evaluate the accuracy of the framing process. When detecting framing anomalies, the sliding window adaptive segmentation algorithm is used to intelligently adjust and independently parse the cached data to ensure the double integrity of the authentication message boundary and content, effectively solving the problem that the authentication logic is bypassed due to packet sticking and unpacking in the existing long connection message distribution.

[0046] 2. Through the method and system provided by the present invention, the security and stability in the long connection message distribution process can be significantly improved, preventing unauthorized users from confusing and impersonating authentication to access the system through abnormal messages. At the same time, through the dynamic framing and accuracy scoring mechanisms, the present invention enhances the adaptability of the system to message anomalies in complex network environments, improves the robustness and real-time protection capabilities in the authentication stage, and has good application and promotion value. Description of the Drawings

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0048] Figure 1 This is the method mind map of the present invention.

[0049] Figure 2 This is the system module mind map of the present invention. Specific embodiments

[0050] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0051] Example 1. Please refer to Figure 1 As shown, a long link message distribution method in this embodiment includes:

[0052] The server establishes a long link with the client and listens for the first message from the client;

[0053] The server parses the received message and extracts the field information related to authentication;

[0054] From the received field information, the message length field and the message verification field are extracted;

[0055] Based on the comparison calculation between the extracted message length field and the actual number of message bytes received, and based on the extracted message verification field, the message body is verified, and the accuracy score of the current message parsing is obtained through comprehensive calculation;

[0056] According to the accuracy score, the accuracy of the current frame processing is evaluated. When the accuracy score is lower than the preset threshold, dynamic frame adjustment is performed, including re-segmenting the data cache according to the message length field and independently parsing the authentication message;

[0057] If the authentication information passes the verification after frame adjustment, the subsequent authentication process continues; if the authentication information still fails to pass the verification after frame adjustment, the connection is disconnected and the client access is refused.

[0058] The server establishes a long link with the client through a communication protocol, and the communication protocol can be TCP protocol, WebSocket protocol or HTTP / 2 protocol. The process of establishing the connection includes:

[0059] The server receives a connection request from the client;

[0060] Verify the legality of the connection request initiated by the client, including but not limited to IP whitelist verification, port verification, connection rate limit, etc.;

[0061] After the verification passes, the server completes the connection handshake with the client and establishes a persistent two-way communication channel;

[0062] After the connection is established, the server initializes the connection session context and assigns a unique connection identifier for association during subsequent data communication;

[0063] The server enters the listening state and is ready to receive the first data message sent by the client on this connection;

[0064] The first message is defined as the initial active transmission by the client after the connection is established, and is used for authentication or session initialization.

[0065] The server parses the received message and extracts the basic field information related to authentication, including Token, user identifier, and device identifier;

[0066] When the server receives the first message from the client, the following detailed parsing steps are executed:

[0067] Parse the format of the received data, and the data format can be JSON format, Protobuf format, XML format, or custom binary format;

[0068] According to the predefined message structure protocol, locate and extract the basic field information related to authentication, specifically including:

[0069] Token field: Used to identify the client identity credential, usually a token issued by the server with timeliness and signature protection;

[0070] User identifier field: Used to identify the user entity corresponding to the current connection, which can be a digital ID, a string ID, or other unique identifier;

[0071] Device identifier field: Used to identify the terminal device used for the current connection, which can be the device unique serial number (such as IMEI, MAC address, device SN code, etc.);

[0072] Perform format integrity verification on the extracted basic field information, including whether the field exists, whether the field is empty, and whether the field type matches the expectation (for example, Token should be of string type, and UserID should be of numeric type or short string type);

[0073] If the verification passes, store the extracted Token, user identifier, and device identifier into the connection session context for subsequent authentication verification and message distribution;

[0074] If the verification fails, the authentication process is aborted, and the abnormal connection is handled according to the preset policy (such as directly disconnecting the connection, sending an error prompt message, etc.).

[0075] After extracting the basic fields (Token, user identifier, device identifier), the server continues to deeply parse the received data message to extract two important parameters representing different verification directions, which are used for subsequent data integrity verification and frame splitting accuracy evaluation.

[0076] The message length field is used to characterize the length information of the message data body, indicating the number of bytes of the effective payload declared in the current authentication message at the logical protocol layer;

[0077] The message length field can be located in the protocol header area. For example, in a custom binary protocol, Protobuf packet, or based on the HTTP / 2 frame format, it is usually read from a fixed offset position;

[0078] The server parses the specific value of this field according to the protocol specification, and compares it with the actual received data length to determine whether there are abnormal situations such as packet sticking, packet splitting, or truncation;

[0079] If the protocol format is a plaintext structure (such as JSON), the message length can be dynamically calculated by parsing the data structure or obtained based on external additional information.

[0080] The message verification field is used to characterize the data integrity or correctness information inside the message body, and it is an internal verification mechanism for the message content itself;

[0081] The message verification field can include but is not limited to:

[0082] Hash value (such as SHA-256, MD5 hash);

[0083] Signature value (such as HMAC signature, digital signature);

[0084] Checksum (such as CRC32, Adler-32);

[0085] After receiving the complete message body, the server extracts the verification field according to the protocol definition, and at the same time recalculates the message body content locally and compares it with the extracted verification field;

[0086] Through the comparison result, it is confirmed whether the message content has been tampered with, damaged, or there is a risk of incorrect parsing due to packet sticking during transmission.

[0087] The message length field focuses on data boundaries (physical layer consistency) to prevent misreading of messages caused by TCP packet sticking or packet splitting;

[0088] The message verification field focuses on the data content (logical layer correctness) to prevent the message content from being tampered with or spliced incorrectly in the network;

[0089] The dual extraction and verification mechanism ensures the parsing accuracy and integrity of the authentication message, reducing the risks of authentication bypass, security vulnerabilities, and system crashes.

[0090] In the present invention, by simultaneously extracting and comprehensively utilizing the message length field and the message verification field, this method can achieve two-way verification of the authentication message from two different directions of physical data integrity and logical data correctness, providing a reliable basis for subsequent frame accuracy evaluation and dynamic adjustment, and further improving the security and stability of the long connection message distribution system.

[0091] After extracting the message length field and the message verification field, the server performs the following detailed processing steps:

[0092] The server reads the message length field from the received message data according to the protocol definition; after comparing the extracted value of the message length field with the actually received byte count statistically, a byte comparison deviation index is generated, and the generation method is:

[0093] Extract the message length field from the received message, denoted as L expected , representing the expected length declared by the message, statistically count the actually received data byte count, denoted as L actual .

[0094] Calculate the absolute value difference of the length deviation, denoted as ΔL: ΔL = |L expected -L actual |; calculate the byte comparison deviation index S, and the expression is: e is the base of the natural logarithm, approximately equal to 2.71828; k is the exponential decay coefficient, controlling the sensitivity of the deviation; use the calculated deviation index S as a reference basis for message parsing accuracy.

[0095] If S is lower than the set deviation threshold, it is determined that the current frame processing is normal; if S is higher than the deviation threshold, it is determined that there is a risk of packet sticking or unpacking misalignment currently, and dynamic frame adjustment is triggered.

[0096] The server extracts the preset verification field from the message body according to the protocol requirements; the server recalculates the verification value for the received message body part using the corresponding verification algorithm (such as hash algorithm, signature algorithm, or checksum algorithm);

[0097] After comparing the recalculated verification value with the extracted verification field, a verification value comparison anomaly index is generated, and the generation method is:

[0098] The extracted check field is denoted as Cexpected and the recalculated check value is denoted as Cactual, which are converted into binary bit string forms;

[0099] Perform an exclusive OR (XOR) operation on Cexpected and Cactual bit by bit to obtain the XOR result bit string;

[0100] Count the number of bits with a value of 1 in the XOR result, denoted as the number of different bits d, which represents how many bits the two check values differ in;

[0101] Count the total number of bits of the check value, denoted as n;

[0102] Calculate the check value comparison exception index R: It is used to evaluate the consistency and integrity of the current message content.

[0103] Normalize the byte comparison deviation index and the check value comparison exception index so that they are both within [0, 1]. After weighted average summation calculation of the normalized byte comparison deviation index and the check value comparison exception index, obtain the accuracy score for the current message parsing.

[0104] Evaluate the accuracy of the current frame processing according to the accuracy score. When the accuracy score is lower than the preset threshold, perform dynamic frame adjustment:

[0105] After the server completes the comprehensive scoring based on the message length field and the message check field, read the accuracy score of the current message parsing;

[0106] The server sets a preset threshold, and the threshold can be a reasonable score determined according to the actual application scenario;

[0107] The server compares the current accuracy score with the preset threshold to judge the reliability of the current authentication message parsing.

[0108] When the accuracy score is higher than or equal to the preset threshold, it is determined that the current frame processing is accurate, no adjustment is required, and the normal authentication process continues to be executed;

[0109] When the accuracy score is lower than the preset threshold, it is determined that there is an abnormality in the current frame processing, and packet sticking, packet splitting, or data misalignment may occur, and dynamic adjustment needs to be performed.

[0110] Traditional segmentation methods usually directly take a fixed-length data block from the data buffer according to the extracted message length field. This method is prone to errors in cases of packet sticking, packet splitting, or streaming out-of-order. To improve the correctness of segmentation in an abnormal network environment, this method adopts a sliding window adaptive segmentation algorithm, combined with the message length field, to achieve more robust data buffer cutting.

[0111] The specific steps are as follows:

[0112] Step 1: Extract the length of the target message Ltarget;

[0113] Step 2: Initialize the sliding window, set the starting pointer pstart to point to the start position of the buffer, and initially set the window size to W = Ltarget;

[0114] Step 3: Apply the sliding window scan on the buffer. Each scan includes:

[0115] Starting from pstart, intercept a data segment with a length of W;

[0116] Perform a quick pre-parse on the data segment (such as structural integrity check, local checksum field verification).

[0117] Step 4: Dynamically adjust the window size according to the pre-parse result: If the data segment conforms to the expected protocol structure, determine that the current window area is a complete authentication message; if not, slide the window backward by a small step (such as 1 - 4 bytes), and re-intercept W bytes and continue the verification; set the maximum sliding offset (such as not exceeding 10% of Ltarget) to prevent invalid scans.

[0118] Step 5: After confirming the boundary of the complete message, cut this segment of data as an independent authentication message for formal parsing. Independently parse the re-segmented authentication message, including basic field extraction, length comparison, and content verification.

[0119] Step 6: Continue to repeat the sliding window detection for the remaining data until all the data in the buffer is correctly segmented or timed out and exits.

[0120] According to the verification result of the authentication information after frame adjustment, perform subsequent processing:

[0121] After completing the re-segmentation of the data buffer according to the message length field and independently parsing the authentication message, the server verifies the authentication data obtained from the re-parsing;

[0122] The authentication information verification includes but is not limited to: verification of basic fields (Token, user identification, device identification), message integrity verification (such as length comparison, checksum field comparison), and protocol specification compliance verification.

[0123] If the authentication information after frame adjustment is verified to conform to the expectation, that is, the verification passes, the server continues to execute the subsequent authentication process;

[0124] The subsequent authentication process includes but is not limited to:

[0125] Mark the current connection as the authentication success status;

[0126] Bind the user identification, device identification, and connection ID.

[0127] Allow the client to subsequently send business messages or receive push messages normally.

[0128] If the authentication information after frame adjustment fails the verification, that is, there are still problems such as abnormal format, field errors, verification failures, or incomplete data in the authentication message;

[0129] Then the server immediately aborts the current authentication process and performs a secure disconnection process, including but not limited to:

[0130] Disconnect the current client connection;

[0131] Release the server-side resources associated with this connection;

[0132] Optionally record the exception event log (including connection IP, timestamp, reason for the exception, etc.) for subsequent analysis;

[0133] Optionally take further security measures such as banning, traffic limiting, and alarming for the abnormal client.

[0134] In the present invention, it is ensured that only when the authentication data is complete and correct can the connection enter the business processing stage; for connections that fail the verification, they are disconnected in a timely manner, effectively preventing system risks caused by malicious data, transmission anomalies, or protocol attacks; aborting immediately when the verification fails after frame adjustment is a security design that conforms to the principle of minimum trust and is particularly suitable for long connection message distribution systems with high security requirements.

[0135] Example 2, please refer to Figure 2 As shown, a long connection message distribution system in this embodiment includes a connection management module, a message parsing module, a protocol field extraction module, an accuracy scoring module, a frame management module, and an authentication processing module;

[0136] Connection management module: The server establishes a long connection with the client and listens for the first message from the client;

[0137] Message parsing module: The server parses the received message and extracts the field information related to authentication;

[0138] Protocol field extraction module: Extract the message length field and the message verification field from the received field information;

[0139] Accuracy scoring module: Compare and calculate based on the extracted message length field and the number of message bytes actually received, and verify the message body based on the extracted message verification field, and comprehensively calculate the accuracy score of the current message parsing;

[0140] Frame management module: evaluate the accuracy of the current frame processing according to the accuracy score. When the accuracy score is lower than the preset threshold, perform dynamic frame adjustment, including re-segmenting the data cache according to the message length field and independently parsing the authentication message;

[0141] Authentication processing module: If the authentication information passes the verification after frame adjustment, continue the subsequent authentication process; if the authentication information still fails to pass the verification after frame adjustment, disconnect the connection and reject the client access.

[0142] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0143] It should be understood that the term "and / or" in this article is only an association relationship describing associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. These three situations, where A and B can be singular or plural. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship. For specific understanding, please refer to the context before and after.

[0144] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but this implementation should not be considered to exceed the scope of this application.

[0145] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, and all should be covered by the protection scope of this application.

Claims

1. A long link message distribution method, characterized in that: Including: The server establishes a long connection with the client and listens for the first message from the client. The server parses the received message and extracts the field information related to authentication. From the received field information, the message length field and the message check field are extracted. Based on the comparison calculation between the extracted message length field and the actual number of received message bytes, and based on the extracted message check field to verify the message body, a comprehensive calculation is performed to obtain the accuracy score of the current message parsing. According to the accuracy score, evaluate the accuracy of the current frame processing. When the accuracy score is lower than the preset threshold, perform dynamic frame adjustment, including re-splitting the data cache according to the message length field and independently parsing the authentication message. If the authentication information passes the verification after frame adjustment, continue the subsequent authentication process; if the authentication information still fails to pass the verification after frame adjustment, disconnect the connection and reject the client access.

2. The long link message distribution method according to claim 1, characterized in that: The field information includes Token, user identification, and device identification.

3. A long link message distribution method according to claim 1, characterized in that: Compare the value of the extracted message length field with the statistically actual number of received bytes to generate a byte comparison deviation index. The generation method is as follows: Extract the message length field from the received message, denoted as L expected , representing the expected length declared by the message, and count the actual number of data bytes received, denoted as L actual ; Calculate the absolute value difference of the length deviation, denoted as ΔL: ΔL = |L expected -L actual |; Calculate the byte comparison deviation index S, with the expression: e is the base of the natural logarithm; k is the exponential decay coefficient.

4. The long link message distribution method according to claim 3, wherein: Compare the recalculated check value with the extracted check field to generate a check value comparison anomaly index. The generation method is as follows: Record the extracted check field as Cexpected and the recalculated check value as Cactual and convert them into binary bit string forms. Perform an exclusive OR operation on Cexpected and Cactual bit by bit to obtain an exclusive OR result bit string. Count the number of bits with a value of 1 in the exclusive OR result, denoted as the number of different bits d. Count the total number of bits of the check value, denoted as n. Calculate the comparison anomaly index R of the check value:

5. A long link message distribution method according to claim 4, characterized in that: Normalize the byte comparison deviation index and the check value comparison anomaly index so that they are both within [0, 1]. Perform a weighted average summation calculation on the normalized byte comparison deviation index and the check value comparison anomaly index to obtain the accuracy score of the current message parsing.

6. The long link message distribution method according to claim 5, characterized in that: According to the accuracy score, evaluate the accuracy of the current frame processing. When the accuracy score is lower than the preset threshold, perform dynamic frame adjustment: After the server completes the comprehensive scoring based on the message length field and the message check field, read the accuracy score of the current message parsing. The server sets a preset threshold. The server compares the current accuracy score with the preset threshold. When the accuracy score is higher than or equal to the preset threshold, determine that the current frame processing is accurate, no adjustment is required, and continue to execute the normal authentication process. When the accuracy score is lower than the preset threshold, determine that there is an anomaly in the current frame processing and dynamic adjustment needs to be performed.

7. A long link message distribution method according to claim 6, characterized in that: The specific adjustment steps include: Step 1: Extract the target message length Ltarget. Step 2: Initialize the sliding window, set the starting pointer pstart to point to the starting position of the cache, and the initial window size is set to W = Ltarget. Step 3: Apply the sliding window scan on the buffer area. Each scan content includes: starting from pstart, intercept a data segment with a length of W; perform a quick pre-parse on the data segment. Step 4: Dynamically adjust the window size according to the pre-parsing result: If the data segment conforms to the expected protocol structure, it is determined that the current window area is a complete authentication message; if not, the window is slid backward by a small step size, and W bytes are intercepted again for continued verification; set the maximum sliding offset to prevent invalid scanning; Step 5: After confirming the boundary of the complete message, cut the data as an independent authentication message for formal parsing, and perform independent parsing on the re-segmented authentication message, including basic field extraction, length comparison, and content verification; Step 6: The remaining data continues to repeat the sliding window detection until all the data in the buffer is correctly segmented or the timeout exits.

8. A long link message distribution system for implementing the long link message distribution method according to any one of claims 1-7, characterized in that: Including a connection management module, a message parsing module, a protocol field extraction module, an accuracy scoring module, a frame management module, and an authentication processing module; Connection management module: The server establishes a long connection with the client and listens for the first message from the client; Message parsing module: The server parses the received message and extracts the field information related to authentication; Protocol field extraction module: Extract the message length field and the message verification field from the received field information; Accuracy scoring module: Calculate the comparison based on the extracted message length field and the number of message bytes actually received, and verify the message body based on the extracted message verification field, and comprehensively calculate the accuracy score of the current message parsing; Frame management module: Evaluate the accuracy of the current frame processing according to the accuracy score. When the accuracy score is lower than the preset threshold, perform dynamic frame adjustment, including re-segmenting the data buffer according to the message length field and independently parsing the authentication message; Authentication processing module: If the authentication information passes the verification after frame adjustment, continue the subsequent authentication process; if the authentication information still fails to pass the verification after frame adjustment, disconnect the connection and reject the client access.

Citation Information

Patent Citations

  • TCP-based data subcontracting and sticking processing method

    CN109347825A

  • Bidirectional authentication method and system

    CN112242993A

  • TCP packet sticking processing method and system and storage medium

    CN113556331A

  • Information transmission method, device and equipment

    CN116233016A

  • Network communication method and system based on zero trust

    CN117768151A