IP data processing method and device, computer storage medium and terminal

Through the parsing and search tree construction of bidirectional masked IP strings, the cumbersome IP configuration problem during device migration is solved, and efficient management of rapid device positioning and monitoring is achieved.

CN120372066APending Publication Date: 2025-07-25BEIJING VENUS INFORMATION SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510473470.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the IP and responsible person information need to be frequently reconfigured during equipment migration, resulting in the rapid positioning process of the responsible person using the equipment and the high information maintenance cost.

Method used

Using a bidirectional mask IP string, the first mask IP object and the bidirectional IP mask object are obtained through parsing, and an IP lookup tree and linked list are built to realize the rapid positioning and monitoring of the equipment, and reduce operation and maintenance pressure.

Benefits of technology

Re-registration is not required when equipment migration is not required, which improves the positioning and monitoring efficiency of equipment network access licenses and reduces information maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372066A_ABST
    Figure CN120372066A_ABST
Patent Text Reader

Abstract

The invention discloses an IP data processing method and device, a computer storage medium and a terminal.The bidirectional mask IP character string allocated to a user in the embodiment of the invention comprises a first mask for distinguishing the user and a second mask for distinguishing equipment, and the bidirectional mask IP character string is analyzed to obtain a first mask IP object and a bidirectional IP mask object; the first mask IP object and the bidirectional IP mask object are stored based on the lookup tree, and a basis is provided for rapid positioning of the network access IP; a first mask IP object is stored in a node of a lookup tree to provide data support for positioning a user to which the network access equipment belongs, and a bidirectional IP mask object is stored in a linked list of the node to provide data support for positioning the network access equipment; when the equipment is abnormal, the affiliated enterprise and specific equipment can be quickly positioned based on the search tree, and tracking is realized based on the positioning result, so that the efficiency of positioning and tracking the abnormal equipment is improved; the equipment does not need to be registered again when moving, and the first mask and the second mask do not need to be updated, so that the positioning and monitoring efficiency of the network access permission of the mobile equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to cloud computing technology, and particularly to a method, device, computer storage medium, and terminal for IP data processing. Background Art

[0002] In cloud computing, when performing business scenarios such as log analysis and audit analysis, it is necessary to locate the Internet access information of network devices; for example, where a certain laptop device accesses the Internet, whether Internet access is allowed, and whether there is an attack or being attacked situation; most of them are filtered and located through source / destination IP or device IP. To perform the location, an accurate IP look-up table is required. If the device moves to another network environment, the IP change will cause it to become invalid and require re-registration. Currently, only the calculation and use of one-way masks for IP are available. For example, 192.168.1.1 / 24 means that the left 24-bit binary numbers should be the same, and the use and logic of IP masks are implemented with reference to international standards.

[0003] With the popularization of the use of electronic devices and the Internet of Things, in the IP mask configuration in related technologies, it is necessary to first allocate an Internet access network segment through a mask, and then allocate an IP in this network segment to each device; if the device is moved to another location, it is necessary to continue to configure the network segment IP of the other location, and it is necessary to re-record the IP device information and the responsible person information; that is, the IP is allocated to the device, and the responsible person for using the IP is recorded, rather than directly binding the responsible person to the device.

[0004] In summary, in the IP mask configuration method in related technologies, each time a device is migrated, the IP needs to be reconfigured, and at the same time, the responsible person for configuring the IP. If it is an office device such as a laptop that needs to be frequently migrated to different work areas for logging in to the Internet, it is necessary to frequently apply for the use permission of the IP, and the process of quickly and conveniently locating the responsible person for using the device is cumbersome, and the information maintenance cost is high. How to improve the configuration efficiency of the IP mask and achieve the quick location of the responsible person for using the device has become a problem to be solved. Summary of the Invention

[0005] An embodiment of the present application provides a method for IP data processing, including: Parsing a two-way mask IP string allocated to a user to obtain a first mask IP object and a two-way IP mask object. Among them, the two-way mask IP string includes: a first mask for distinguishing users and a second mask for distinguishing devices. The two-way IP mask object includes: a valid first byte array containing the first mask and the second mask after mask processing of the two-way mask IP string, and a second byte array determined according to the first byte array. The second byte array is used to distinguish the valid data position and the invalid data position of the Internet access IP of the Internet access device. The valid data position is the string position of the first mask and the second mask in the Internet access IP. Construct an IP search tree for positioning the incoming network IP, store the first masked IP object in the nodes of the IP search tree, and store the two-way IP mask object in the linked list of the nodes.

[0006] On the other hand, an embodiment of the present application further provides a computer storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the above method for IP data processing is implemented.

[0007] On yet another aspect, an embodiment of the present application further provides a terminal, including: a memory and a processor, where a computer program is stored in the memory; wherein, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the above method for IP data processing is implemented.

[0008] On still another aspect, an embodiment of the present application further provides an IP data processing device, including: a parsing unit and a construction unit; wherein, The parsing unit is configured to: parse the two-way masked IP string assigned to the user to obtain a first masked IP object and a two-way IP mask object, where the two-way masked IP string includes: a first mask for distinguishing users and a second mask for distinguishing devices, and the two-way IP mask object includes: a valid first byte array containing the first mask and the second mask after masking the two-way masked IP string, and a second byte array determined according to the first byte array, where the second byte array is used to distinguish the valid data position and the invalid data position of the incoming network IP of the incoming network device, and the valid data position is the string position of the first mask and the second mask in the incoming network IP; The construction unit is configured to: construct an IP search tree for positioning the incoming network IP, store the first masked IP object in the nodes of the IP search tree, and store the two-way IP mask object in the linked list of the nodes.

[0009] The two-way masked IP string assigned to a user in an embodiment of the present disclosure includes a first mask for differentiating users, a second mask for differentiating devices. By parsing the two-way masked IP string, a first masked IP object and a two-way IP mask object are obtained. Storing the first masked IP object and the two-way IP mask object based on a lookup tree provides a basis for the rapid positioning of the incoming network IP. The first masked IP object stored in the nodes of the IP lookup tree provides data support for positioning the user to which the incoming network device belongs. The two-way IP mask object is stored in the linked list of the nodes. The first byte array and the second byte array in the two-way IP mask object provide data support for positioning the specific incoming network device. When a device is prohibited from accessing the network or has abnormal behavior information due to an attack, the enterprise to which it belongs and the specific device can be quickly located based on the IP lookup tree, and subsequent tracking processing can be implemented based on the positioning result, improving the efficiency of positioning and tracking abnormal devices. When the device moves, there is no need to re-register, and the first mask and the second mask do not need to be updated, reducing the operation and maintenance pressure and the information maintenance cost, and improving the positioning and monitoring efficiency of the incoming network permission of the moving device.

[0010] Other features and advantages of the present application will be described in the following specification, and in part will be obvious from the specification, or will be understood by implementing the present application. Other advantages of the present application can be achieved and obtained through the solutions described in the specification and the drawings. Description of the Drawings

[0011] The drawings are used to provide an understanding of the technical solutions of the present application, and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solutions of the present application, and do not constitute a limitation to the technical solutions of the present application.

[0012] Figure 1 It is a flowchart of the method for IP data processing in an embodiment of the present disclosure; Figure 2 It is a schematic diagram of the composition of the two-way masked IP string in an embodiment of the present disclosure; Figure 3 It is a flowchart of parsing the two-way masked IP string in an embodiment of the present disclosure; Figure 4 It is a structural block diagram of the device for IP data processing in an embodiment of the present disclosure; Figure 5 It is a schematic diagram of the composition of the first masked IP object in an embodiment of the present disclosure. Detailed Embodiments

[0013] This application describes multiple embodiments, but the description is exemplary rather than restrictive, and it will be apparent to those of ordinary skill in the art that there can be more embodiments and implementation solutions within the scope of the embodiments described in this application. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically restricted, any feature or element of any embodiment can be used in combination with any other feature or element in any other embodiment, or can replace any other feature or element in any other embodiment.

[0014] This application includes and contemplates combinations with features and elements known to those of ordinary skill in the art. The embodiments, features, and elements already disclosed in this application can also be combined with any conventional features or elements to form a unique inventive solution. Any feature or element of any embodiment can also be combined with features or elements from other inventive solutions to form another unique inventive solution. Therefore, it should be understood that any feature shown and / or discussed in this application can be implemented alone or in any suitable combination. Therefore, the embodiments are not subject to other limitations except those made according to the appended claims and their equivalents. In addition, various modifications and changes can be made within the scope of the appended claims.

[0015] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not depend on the specific order of the steps described herein, the method or process should not be limited to the specific order of steps. As will be understood by those of ordinary skill in the art, other step orders are possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation on the claims. In addition, the claims directed to the method and / or process should not be limited to performing their steps in the order written, and those skilled in the art can easily understand that these orders can vary and still remain within the spirit and scope of the embodiments of this application.

[0016] Figure 1 For the flowchart of the method for IP data processing in the embodiments of this disclosure, as Figure 1 shown, it includes: Step 101: Parse the two-way masked IP string assigned to the user to obtain a first masked IP object and a two-way IP mask object. The two-way masked IP string includes a first mask for distinguishing users and a second mask for distinguishing devices. The two-way IP mask object includes a valid first byte array containing the first mask and the second mask after masking the two-way masked IP string, and a second byte array determined according to the first byte array. The second byte array is used to distinguish the valid data position and the invalid data position of the incoming network IP of the incoming network device. The valid data position is the string position of the first mask and the second mask in the incoming network IP. Step 102: Construct an IP search tree for positioning the incoming network IP, store the first masked IP object in the node of the IP search tree, and store the two-way IP mask object in the linked list of the node.

[0017] The two-way masked IP string assigned to the user in the embodiment of the present disclosure includes a first mask for distinguishing users and a second mask for distinguishing devices. Parsing the two-way masked IP string obtains a first masked IP object and a two-way IP mask object, and storing the first masked IP object and the two-way IP mask object based on the search tree provides a basis for the rapid positioning of the incoming network IP; the first masked IP object stored in the node of the IP search tree provides data support for positioning the user to which the incoming network device belongs, and the two-way IP mask object is stored in the linked list of the node. The first byte array and the second byte array in the two-way IP mask object provide data support for positioning a specific incoming network device; when the device is prohibited from accessing the Internet or has abnormal behavior information due to an attack, the enterprise to which it belongs and the specific device can be quickly located based on the IP search tree, and subsequent tracking processing can be implemented based on the positioning result, improving the efficiency of positioning and tracking abnormal devices; when the device moves, there is no need to re-register, and the first mask and the second mask do not need to be updated, reducing the operation and maintenance pressure and the information maintenance cost, and improving the positioning and monitoring efficiency of the incoming network permission of the moving device.

[0018] In an exemplary instance, the two-way masked IP string in the embodiment of the present disclosure further includes a region code for identifying the region where the device is located. The region code in the embodiment of the present disclosure can be set with reference to related technologies and can be set automatically by software or configured manually.

[0019] In an exemplary instance, the embodiment of the present disclosure can set the data format of the two-way masked IP string according to the information included in the two-way masked IP string. Figure 2 This is a schematic diagram of the composition of the two-way masked IP string in the embodiment of the present disclosure, as Figure 2As shown, the two-way masked IP string in the embodiments of the present disclosure may be: area code / first mask / second mask, or may be: area code, first mask, second mask, as long as the information of each part can be effectively distinguished according to the set data format, and the embodiments of the present disclosure do not limit this.

[0020] In an exemplary instance, the embodiments of the present disclosure may set a first mask with a first preset number of bits and a second mask with a second preset number of bits based on the functions of distinguishing users and devices required by the first mask and the second mask. For example, the number of bits of the first mask is set to 32 bits, and the number of bits of the second mask may be 48 or 64 bits.

[0021] In an exemplary instance, the second byte array in the embodiments of the present disclosure includes: a byte array that makes the numerical value of the valid data position of the first byte array 1 and the numerical value of the invalid data position 0; The embodiments of the present disclosure process the valid data position and the invalid data position of the incoming network IP of the incoming network device through the second byte array to obtain a third byte array. By comparing the third byte array with the first byte array, the incoming network device can be located according to the incoming network IP.

[0022] The embodiments of the present disclosure may determine the second byte array by performing a bitwise AND operation on the first byte array.

[0023] Figure 3 This is a flowchart for parsing the two-way masked IP string in the embodiments of the present disclosure. As Figure 3 shown, the embodiments of the present disclosure parse the two-way masked IP string assigned to the user to obtain a first masked IP object and a two-way IP mask object, including: Step 301, perform prefix and suffix mask processing on the two-way masked IP string; Step 302, determine the IP type of the two-way masked IP string after prefix and suffix mask processing, and generate a first masked IP object according to the determined IP type. The first masked IP object is the IP address corresponding to the determined IP type; Step 303, determine a first byte array and a second byte array according to the two-way masked IP string after prefix and suffix mask processing, and obtain a two-way IP mask object according to the determined first byte array and second byte array.

[0024] In an exemplary instance, the first byte array and the second byte array in the embodiments of the present disclosure may be binary.

[0025] In an exemplary instance, the embodiments of the present disclosure construct an IP search tree for locating the incoming network IP, including: constructing an IP search tree corresponding to each IP type; For the first masked IP object and the bidirectional IP mask object obtained by parsing each bidirectional masked IP string, the following processing is performed respectively: Determine the IP type of the first masked IP object; Store the first masked IP object in the node of the corresponding IP search tree according to the determined IP type, and store the bidirectional IP mask object in the linked list of the node; Among them, when the first masked IP objects obtained by parsing different bidirectional masked IP strings are the same, they are merged into the same node in the IP search tree, and the bidirectional IP mask objects obtained by parsing different bidirectional masked IP strings are stored in the linked list of the node.

[0026] In an exemplary instance, the search tree in the embodiments of the present disclosure may include a red-black tree or a trie tree.

[0027] In an exemplary instance, the embodiments of the present disclosure may store the first masked IP object through the node of the red-black tree, and store the bidirectional IP mask object through the linked list in the node. The embodiments of the present disclosure store the first masked IP object into the node of the red-black tree (or trie tree) respectively according to the value range, and store the bidirectional IP mask object of the first masked IP object with the same value range in the linked list of the node, and utilize the characteristics of the red-black tree ordered balanced binary tree to realize the storage of the left masked IP object and the bidirectional IP mask object of the enterprise.

[0028] In an exemplary instance, the embodiments of the present disclosure perform masking processing on the first mask and the second mask according to the number of bits of the first mask and the second mask.

[0029] In an exemplary instance, the embodiments of the present disclosure may determine the corresponding first mask for each user respectively with reference to the related art, for example, store the first mask of each user through a mapping table; the users in the embodiments of the present disclosure may include enterprises or groups.

[0030] In an exemplary instance, the second mask in the embodiments of the present disclosure may be composed of a part of the MAC address plus the custom marking information with a preset third number of bits, or may be composed of the second number of bits in the MAC address of the network access device; for example, a 48-bit or 64-bit MAC. The embodiments of the present disclosure can distinguish the network access devices of users through the above second mask.

[0031] When the device in the embodiments of the present disclosure accesses the network at any location, only the area code needs to be updated to quickly locate the network access information of the device, and there is no need to re-register and apply for network access every time, providing a more friendly network configuration scheme for confidentiality units or companies sensitive to network access.

[0032] In an exemplary instance, the method in the embodiments of the present disclosure further includes: When receiving the access IP of an access device, determine the IP type of the access IP; According to the IP type, determine the IP search tree of this IP type for positioning the access IP; In the determined IP search tree for positioning the access IP, determine the node that is the same as the first mask IP object of the access IP; Obtain the second byte array of the bidirectional IP mask object from the linked list of the determined node, and obtain the fourth byte array of the valid data position from the third byte array of the access IP according to the obtained second byte array; When the fourth byte array is the same as the first byte array after comparison, realize IP positioning; Wherein, the third byte array is the byte array in which the first mask and the second mask in the access IP are valid.

[0033] In an exemplary instance, the first byte array and the second byte array are binary byte arrays, and the second byte array is the byte array that makes the numerical value of the valid data position of the first byte array be 1 and the numerical value of the invalid data position be 0. The method of the embodiment of the present disclosure further includes: When receiving the access IP of an access device, determine the IP type of the access IP; According to the IP type, determine the IP search tree of this IP type for positioning the access IP; In the determined IP search tree for positioning the access IP, determine the node that is the same as the first mask IP object of the access IP; Obtain the second byte array of the bidirectional IP mask object from the linked list of the determined node, and perform a bitwise AND operation on the third byte array of the access IP according to the obtained second byte array; When the result of performing the bitwise AND operation on the third byte array of the access IP according to the obtained second byte array is all 0, realize IP positioning; Wherein, the third byte array is the byte array in which the first mask and the second mask in the access IP are valid.

[0034] Figure 4 It is the structural block diagram of the IP data processing device in the embodiment of the present disclosure, as Figure 4 shown, including: a parsing unit and a construction unit; wherein, The parsing unit is configured to parse the two-way masked IP string assigned to the user to obtain a first masked IP object and a two-way IP mask object. The two-way masked IP string includes a first mask for distinguishing users and a second mask for distinguishing devices. The two-way IP mask object includes a valid first byte array containing the first mask and the second mask after masking the two-way masked IP string, and a second byte array determined according to the first byte array. The second byte array is used to distinguish the valid data position and the invalid data position of the incoming network IP of the incoming network device. The valid data position is the string position of the first mask and the second mask in the incoming network IP. The building unit is configured to build an IP search tree for positioning the incoming network IP, store the first masked IP object in the node of the IP search tree, and store the two-way IP mask object in the linked list of the node.

[0035] In an exemplary instance, the two-way masked IP string in the embodiments of the present disclosure further includes a region code for identifying the region where the device is located.

[0036] In an exemplary instance, the first byte array and the second byte array in the embodiments of the present disclosure are binary byte arrays. The second byte array includes a byte array that makes the value of the valid data position of the first byte array 1 and the value of the invalid data position 0.

[0037] In an exemplary instance, the parsing unit in the embodiments of the present disclosure is configured to: Perform prefix and suffix masking processing on the two-way masked IP string; Judge the IP type of the two-way masked IP string after prefix and suffix masking processing, and generate a first masked IP object according to the determined IP type. The first masked IP object is the IP address corresponding to the judged IP type; Determine the first byte array and the second byte array according to the two-way masked IP string after prefix and suffix masking processing; Obtain a two-way IP mask object according to the determined first byte array and second byte array.

[0038] In an exemplary instance, the building unit in the embodiments of the present disclosure is configured to: Build an IP search tree corresponding to each IP type; Perform the following processing on the first masked IP object and the two-way IP mask object obtained by parsing each two-way masked IP string respectively: Determine the IP type of the first masked IP object; Store the first masked IP object in the node of the corresponding IP search tree according to the determined IP type, and store the two-way IP mask object in the linked list of the node; When the first masked IP objects obtained by parsing different bidirectional masked IP strings are the same, they are merged into the same node in the IP lookup tree, and the linked list of this node stores the bidirectional IP mask objects obtained by parsing different bidirectional masked IP strings.

[0039] In an exemplary instance, the first mask in the embodiments of the present disclosure is a first preset number of bits, and the second mask is a second preset number of bits; the second mask includes: being composed of a part of the MAC address of the network access device plus a custom marking information of a third preset number of bits, or being composed of a second preset number of bits in the MAC address of the network access device.

[0040] In an exemplary instance, the device in the embodiments of the present disclosure further includes a positioning unit, which is set to: When receiving the network access IP of the network access device, judge the IP type of the network access IP; According to the IP type, determine the IP lookup tree for positioning the network access IP of this IP type; In the determined IP lookup tree for positioning the network access IP, determine the node that is the same as the first masked IP object of the network access IP; Obtain the second byte array of the bidirectional IP mask object from the linked list of the determined node, and obtain the fourth byte array of the valid data position from the third byte array of the network access IP according to the obtained second byte array; When the fourth byte array is compared with the first byte array and they are the same, IP positioning is achieved; Wherein, the third byte array is the byte array in which the first mask and the second mask in the network access IP are valid.

[0041] In an exemplary instance, the first byte array and the second byte array are binary byte arrays, and the second byte array is the byte array that makes the numerical value of the valid data position of the first byte array be 1 and the numerical value of the invalid data position be 0. The positioning unit in the embodiments of the present disclosure is further set to: When receiving the network access IP of the network access device, judge the IP type of the network access IP; According to the IP type, determine the IP lookup tree for positioning the network access IP of this IP type; In the determined IP lookup tree for positioning the network access IP, determine the node that is the same as the first masked IP object of the network access IP; Obtain the second byte array of the bidirectional IP mask object from the linked list of the determined node, and perform a bitwise AND operation on the third byte array of the network access IP according to the obtained second byte array; When the result of performing the bitwise AND operation on the third byte array of the network access IP according to the obtained second byte array is all 0, IP positioning is achieved; Among them, the third byte array is the byte array in which the first mask and the second mask included in the network access IP are valid.

[0042] An embodiment of the present disclosure further provides a computer storage medium. A computer program is stored in the computer storage medium. When the computer program is executed by a processor, the method for processing IP data described above is implemented.

[0043] An embodiment of the present disclosure further provides a terminal, including: a memory and a processor. A computer program is stored in the memory; among them, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the method for processing IP data as described above is implemented.

[0044] The following briefly describes the embodiments of the present disclosure through application examples. The application examples are only used to state the embodiments of the present disclosure and are not used to limit the protection scope of the embodiments of the present disclosure.

[0045] Application Example In this application example, it is assumed that the two-way mask IP information string represents the logic as area code / first mask bit number / second mask bit number; for example: 192.168.1.1 / 8 / 8 and fe80::f46f:4fc2:3152:a409 / 16 / 16. The first mask represents the first mask, and the second mask represents the second mask with the second preset number of bits starting from the right.

[0046] The embodiments of the present disclosure can parse the two-way mask IP information string through a parser to obtain a first mask IP object (IPAddressRange) and a two-way IP mask object (BothSubnetMask); the following briefly describes with examples: The following is a detailed description of the information of these two objects.

[0047] The embodiments of the present disclosure perform the following processing through a parser to obtain a first mask IP object: Perform prefix and suffix mask processing on the two-way mask IP string; Judge the IP type of the two-way mask IP string after prefix and suffix mask processing; Generate a first mask IP object according to the determined IP type. The first mask IP object is the IP address corresponding to the determined IP type; the process of generating the IPV4 and IPV6 address ranges (IP addresses corresponding to the IP type) in the embodiments of the present disclosure is the process of generating an IPAddressRange object.

[0048] Figure 5 For the composition schematic diagram of the first mask IP object in the embodiments of the present disclosure, as Figure 5As shown, the first masked IP object further includes: a starting IP value and an ending IP value. The starting IP value and the ending IP value are IP segment range description attributes. An IP can be converted into a digital description. If it is ipv6, it can also be represented by an overlong integer type. Therefore, the starting IP value represents the starting IP in the case of the first masked IP object, and the ending IP value represents the ending IP in the case of the first masked IP object. IP type (ipType). In the embodiments of the present disclosure, different search trees are constructed according to the IP type. The first masked IP objects and the bidirectional IP mask objects of the two IP types are stored in different search trees; IP character description information (ipInfo) is used to save the object described by the IP segment and record the data string format of the first masked IP object.

[0049] In the embodiments of the present disclosure, the parser performs the following processing to obtain the bidirectional IP mask object: Perform prefix and suffix masking processing on the bidirectional masked IP string; Determine the first byte array and the second byte array according to the bidirectional masked IP string obtained by the prefix and suffix masking processing; Obtain the bidirectional IP mask object according to the determined first byte array and second byte array.

[0050] In the embodiments of the present disclosure, calculating the second byte array is to convert the bidirectional masked IP string into a binary data group. For example, for the data 2.2.2.2 / 8 / 8 of a double-masked ipV4, obtain the IP address information 2.2.2.2 and convert it into the binary bit 00000010 00000010 00000010 00000010 data. This is an attempt to obtain the IP address bytes. Then, according to the / 8 / 8 expression information, it shows that the left 8 bits are fixed and the right 8 bits are fixed. Therefore, the effective position data of the bidirectional masked IP string obtained is the binary data of 00000010 00000000 00000000 00000010; remove the noise and invalid data content of the middle 9th to 23rd bits (all 0s). At the same time, generate a corresponding binary data group (maskByteArr) 11111111 00000000 00000000 11111111, the byte array data with all valid bits being 1. It corresponds to the content of the BothSubnetMask object in the following object description.

[0051] In the embodiment of the present disclosure, the search tree constructs the search tree logic through the start and end range attributes of the IPAddressRange. If the first masked IP object ranges are the same, the IPAddressRange will conflict. The data of each first masked IP object is stored in the nodes of the red-black tree. For the IPAddress with the same first masked IP object, the bidirectional IP mask object (BothSubnetMask) is stored through the linked list of the nodes, and all the bidirectional IP mask objects with the same first masked IP object are added to the linked list of this node.

[0052] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or one function or step may be executed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term "computer storage medium" includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and may include any information delivery medium.

Claims

1. A method for IP data processing, characterized in that, Including: Parsing the two-way masked IP string assigned to the user to obtain a first masked IP object and a two-way IP mask object, where the two-way masked IP string includes: a first mask for distinguishing users and a second mask for distinguishing devices, and the two-way IP mask object includes: a valid first byte array containing the first mask and the second mask after masking the two-way masked IP string, and a second byte array determined according to the first byte array, where the second byte array is used to distinguish the valid data position and the invalid data position of the incoming network IP of the incoming network device, and the valid data position is the string position of the first mask and the second mask in the incoming network IP; Constructing an IP search tree for positioning the incoming network IP, storing the first masked IP object in the node of the IP search tree, and storing the two-way IP mask object in the linked list of the node.

2. The method according to claim 1, characterized in that, The two-way masked IP string further includes: a region code identifying the region where the device is located.

3. The method according to claim 1, characterized in that, The first byte array and the second byte array are binary byte arrays, and the second byte array includes: A byte array that makes the value of the valid data position of the first byte array 1 and the value of the invalid data position 0.

4. The method according to claim 1, wherein The first mask is a first preset number of bits, and the second mask is a second preset number of bits; the second mask includes: being composed of a part of the MAC address of the incoming network device plus a custom marker information of a third preset number of bits, or being composed of the second preset number of bits in the MAC address of the incoming network device.

5. The method according to any one of claims 1 to 4, characterized in that The parsing of the two-way masked IP string assigned to the user to obtain a first masked IP object and a two-way IP mask object includes: Performing prefix and suffix masking processing on the two-way masked IP string; Judging the IP type of the two-way masked IP string after the prefix and suffix masking processing, and generating the first masked IP object according to the judged IP type, where the first masked IP object is an IP address corresponding to the judged IP type; Determining the first byte array and the second byte array according to the two-way masked IP string after the prefix and suffix masking processing; Obtaining the two-way IP mask object according to the determined first byte array and second byte array.

6. The method according to claim 5, characterized in that, The constructing of the IP search tree for positioning the incoming network IP includes: Constructing an IP search tree corresponding to each IP type; Performing the following processing on the first masked IP object and the two-way IP mask object obtained by parsing each two-way masked IP string respectively: Determining the IP type of the first masked IP object; Storing the first masked IP object in the node of the corresponding IP search tree according to the judged IP type, and storing the two-way IP mask object in the linked list of the node; Wherein, when the first masked IP objects obtained by parsing different two-way masked IP strings are the same, they are merged into the same node in the IP search tree, and the two-way IP mask objects obtained by parsing different two-way masked IP strings are stored in the linked list of the node.

7. The method according to claim 6, characterized in that, characterized in that, The method further includes: When receiving the access IP of an access device, determine the IP type of the access IP; According to the IP type, determine the IP search tree for positioning the access IP of this IP type; In the determined IP search tree for positioning the access IP, determine the node that is the same as the first masked IP object of the access IP; Obtain the second byte array of the bidirectional IP mask object from the linked list of the determined node, and obtain the fourth byte array of the valid data position from the third byte array of the access IP according to the obtained second byte array; When the comparison between the fourth byte array and the first byte array is the same, implement IP positioning; Wherein, the third byte array is the byte array in the access IP that is valid for the first mask and the second mask.

8. The method according to claim 6, characterized in that The first byte array and the second byte array are binary byte arrays. The second byte array is the byte array that makes the value of the valid data position of the first byte array be 1 and the value of the invalid data position be 0. The method further includes: When receiving the access IP of an access device, determine the IP type of the access IP; According to the IP type, determine the IP search tree for positioning the access IP of this IP type; In the determined IP search tree for positioning the access IP, determine the node that is the same as the first masked IP object of the access IP; Obtain the second byte array of the bidirectional IP mask object from the linked list of the determined node, and perform a bitwise AND operation on the third byte array of the access IP according to the obtained second byte array; When the result of performing the bitwise AND operation on the third byte array of the access IP according to the obtained second byte array is all 0, implement IP positioning; Wherein, the third byte array is the byte array in the access IP that is valid for the first mask and the second mask.

9. A computer storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method for IP data processing described in any one of claims 1 to 8 is implemented.

10. A terminal, comprising: A memory and a processor, and a computer program is stored in the memory; wherein, The processor is configured to execute the computer program in the memory; When the computer program is executed by the processor, the method for IP data processing described in any one of claims 1 to 8 is implemented.

11. An apparatus for IP data processing, comprising: A parsing unit and a construction unit; wherein, The parsing unit is set to: parse the bidirectional masked IP string allocated to a user to obtain a first masked IP object and a bidirectional IP mask object. The bidirectional masked IP string includes: a first mask for distinguishing users and a second mask for distinguishing devices. The bidirectional IP mask object includes: a first byte array containing the valid first mask and second mask after masking the bidirectional masked IP string, and a second byte array determined according to the first byte array. The second byte array is used to distinguish the valid data position and the invalid data position of the access IP of the access device. The valid data position is the string position of the first mask and the second mask in the access IP; The building unit is configured to: build an IP lookup tree for locating the incoming network IP, store the first masked IP object in the nodes of the IP lookup tree, and store the bidirectional IP mask object in the linked list of the nodes.