Method, device, equipment and medium for obfuscation encryption based on network traffic

By identifying the transmission protocol type and adapting the TLS and HTTP protocols, the poor performance and security risks of network traffic obfuscation encryption methods in the prior art are solved, and efficient and secure network traffic transmission is achieved.

CN120498833APending Publication Date: 2025-08-15ZIXUN TECHNOLOGY (FUJIAN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510790113.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing network traffic obfuscated encryption methods have low performance and security risks during transmission, mainly due to the additional negotiation and encryption processing, which leads to poor transmission efficiency and easy identification of protocol features.

Method used

By identifying the transmission protocol type, adaptation processing is performed for TLS and HTTP protocols respectively. The TLS protocol uses random character association request information, the HTTP protocol adds forwarding information in the header, and other protocols adds encryption information, skips the proxy protocol handshake, maintains the original traffic characteristics, improves transmission efficiency and enhances security.

Benefits of technology

The transmission speed is achieved close to the original request speed, improving performance by 50%, while maintaining traffic security and normal operation of the proxy server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498833A_ABST
    Figure CN120498833A_ABST
Patent Text Reader

Abstract

The invention provides a method, a device, equipment and a medium for obfuscation encryption based on network traffic, and the method comprises the steps: a proxy client receives request traffic data, and judges the type of a transmission protocol; if the transmission protocol is a TLS protocol, obtaining a set character and a real SNI in the request data, sending the set character and the real SNI to the proxy server, converting the request flow data into simulation request data, and sending the simulation request data to the proxy server; restoring the simulation request data into request flow data according to the real SNI and a set character, and forwarding the request flow data to a corresponding website; if the transmission protocol is an HTTP protocol, the proxy client adds forwarding information to request traffic data and then sends the request traffic data to the proxy server, the proxy server performs identity authentication, deletes the forwarding information in the forwarding traffic data after passing the authentication to obtain the request traffic data, and the proxy server sends the request traffic data to a corresponding website. The method is faster and safer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network communication technology, and in particular to a method, device, equipment and medium based on network traffic obfuscation encryption. Background Art

[0002] The existing network traffic obfuscation and encryption methods all add additional handshake information externally or authenticate the transmission traffic through additional network handshakes without parsing the original network flow.

[0003] The Socks5 protocol requires extensive preparation before forwarding network traffic, such as selecting an authentication method, performing identity verification, and communicating with the forwarding destination. Each interaction consumes time and performance, and a single request must go through so many twists and turns, making forwarding efficiency unpredictable. Furthermore, these negotiations are a hallmark of the SOCKS5 protocol, with multiple small traffic transmissions preceding each large-scale transmission, a highly noticeable characteristic. Furthermore, SOCKS5 is a plaintext protocol, and the actual requesting address can be seen from the traffic, making it a highly insecure transmission protocol.

[0004] SSL (socks5+tls) protocol: It was created to make up for the shortcomings of socks5 plain text. It adds a layer of tls encryption to socks5. Although it eliminates the shortcoming of plain text, the corresponding transmission efficiency is lower (each transmitted traffic requires additional encryption and decryption processing), and it has all the traffic characteristics of socks5.

[0005] Existing methods for obfuscating and encrypting network traffic suffer from two major drawbacks: performance and characteristics. Transmission through a proxy server requires additional negotiation and encryption, resulting in poor transmission performance. Furthermore, this negotiation is also a characteristic, allowing attackers to infer the protocol used in network transmission, posing a security risk. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide a method, device, equipment and medium based on network traffic obfuscation encryption to ensure the network traffic transmission speed and the security of network data.

[0007] In a first aspect, the present invention provides a method based on network traffic obfuscation encryption, including a proxy server and a proxy client, comprising the following steps:

[0008] Step 1: The proxy client receives the requested traffic data and determines the transmission protocol type;

[0009] Step 2: If the transmission protocol is TLS, obtain the set characters and the real SNI in the request data, send the set characters and the real SNI to the proxy server, and convert the request traffic data into simulated request data and send it to the proxy server; the proxy server restores the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website;

[0010] If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website.

[0011] In a second aspect, the present invention provides a device based on network traffic obfuscation encryption, comprising:

[0012] A protocol determination module, wherein the proxy client receives the request flow data and determines the transmission protocol type;

[0013] The obfuscation encryption module, if the transmission protocol is the TLS protocol, obtains the set characters and the real SNI in the request data, sends the set characters and the real SNI to the proxy server, and converts the request traffic data into simulated request data and sends it to the proxy server; the proxy server restores the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website;

[0014] If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website.

[0015] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the program.

[0016] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the method described in the first aspect when the program is executed by a processor.

[0017] One or more technical solutions provided by the present invention have at least the following technical effects or advantages:

[0018] 1. The present invention only processes the first packet of an original request flow, and does not interfere with the subsequent packets of the original request flow. The transmission speed is infinitely close to the original request speed;

[0019] 2. The present invention utilizes the fact that the original traffic is already encrypted (TLS) and does not require additional encryption to improve transmission efficiency;

[0020] 3. The present invention utilizes the handshake action of the HTTPS TLS layer to skip the step of the proxy protocol handshake, thereby reducing the overhead caused by the proxy protocol handshake and improving the transmission efficiency;

[0021] 4. The present invention retains all fingerprint features of the original request traffic to ensure the normal operation of the proxy server.

[0022] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0024] Figure 1 This is a flowchart of the method in Example 1 of the present invention;

[0025] Figure 2 This is a schematic diagram of the structure of the device in Example 2 of the present invention. DETAILED DESCRIPTION

[0026] The embodiments of the present application provide a method, apparatus, device and medium based on network traffic obfuscation encryption to ensure the security and stable transmission of traffic data when using a proxy service; and to ensure the efficiency of traffic data transmission.

[0027] The technical solutions in the embodiments of this application have the following general ideas:

[0028] Starting with identifying the specific traffic being transmitted, the proxy is adapted for different application layer protocols, initially identifying the following three protocols: TLS, HTTP, and other. Upon receiving traffic, the program analyzes it. If it identifies TLS, it transmits it using the TLS protocol mode. If it identifies HTTP, it forwards it using the HTTP protocol mode. If it identifies neither of the above two protocols, it forwards it using the default other protocol mode.

[0029] 1. TLS protocol transmission solution

[0030] If the forwarded traffic uses the TLS protocol, it will enter the TLS protocol transmission solution. A random and unique character in the TLS protocol is used to associate the request sending the proxy information with the actual request, eliminating the need for an additional handshake. Furthermore, the TLS request itself is encrypted, eliminating the need for additional encryption. Currently, 98% of websites use TLS, which can improve performance by 50%, with transmission speeds very close to those of the original request. The TCP connection that sends the actual domain name information can use a different route from the main line (as long as it ultimately reaches the same server). This allows the main line connection to appear to be a single, fully-connected TLS connection.

[0031] 2.HTTP protocol transmission solution

[0032] If the forwarded traffic is HTTP protocol, it will enter the HTTP protocol transmission solution. Compared with TLS protocol, HTTP protocol forwarding is much simpler. The forwarding information is hidden in a header of HTTP protocol and brought to the server. In this way, there is no need for additional handshake to transmit forwarding information.

[0033] 3.Other protocol transmission solutions

[0034] If forwarded traffic doesn't match any of the above solutions, it will fall through the "other" protocol transmission solution. This "other" protocol acts as a fallback, and generally very little traffic falls through it. This solution essentially adds encrypted forwarding information to the original traffic before sending it to the server. This also eliminates the time-consuming protocol handshake and improves transmission performance.

[0035] The performance is maximized while preserving the original traffic characteristics.

[0036] Example 1

[0037] like Figure 1 As shown, this embodiment provides a method based on network traffic obfuscation encryption, including a proxy server and a proxy client, including the following steps:

[0038] Step 1: The proxy client receives the requested traffic data and determines the transmission protocol type;

[0039] Step 2: If the transmission protocol is TLS, obtain the set characters and the real SNI in the request data, send the set characters and the real SNI to the proxy server, and convert the request traffic data into simulated request data and send it to the proxy server; the proxy server restores the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website;

[0040] If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website.

[0041] This embodiment preferably also includes step 3: if the transmission protocol is not TLS or HTTP, the proxy client and the proxy server establish an ss protocol tunnel, the proxy client encrypts the request traffic data and sends it to the proxy server, the proxy server decrypts it and sends it to the corresponding website, and then the proxy server obtains the return data and sends the return data to the client through the proxy client.

[0042] In this embodiment, preferably, if the transmission protocol in step 2 is the TLS protocol, obtaining the set characters and the real SNI in the request data, sending the set characters and the real SNI to the proxy server, and converting the request traffic data into simulated request data and sending it to the proxy server; the proxy server restores the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website. Specifically,

[0043] If the transmission protocol is the TLS protocol, obtain the set characters and the real SNI in the request data, where the set characters are random and unique characters in the TLS protocol, send the set characters and the real SNI to the proxy server, and convert the request traffic data into simulated request data, that is, replace the real SNI in the request traffic data with a simulated domain name to obtain simulated request data, and send the simulated request data to the proxy server; the proxy server restores the corresponding simulated request data to request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website, after which the proxy server obtains the return data; if the TLS protocol is version 1.3 or below, send the simulated request data to the website where the simulation is set, obtain simulated response data, and send both the proxy server simulated response data and the return data to the client through the proxy client; if the TLS protocol is version 1.3 or above, send the return data to the client through the proxy client.

[0044] In this embodiment, preferably, in step 2, if the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website as follows:

[0045] If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data, that is, the setting header of the http protocol, obtains the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the client through the proxy client.

[0046] Based on the same inventive concept, this application also provides a device corresponding to the method in Example 1, see Example 2 for details.

[0047] Example 2

[0048] like Figure 2 As shown, in this embodiment, a device based on network traffic obfuscation encryption is provided, including a proxy server and a proxy client, including:

[0049] A protocol determination module, wherein the proxy client receives the request flow data and determines the transmission protocol type;

[0050] The obfuscation encryption module, if the transmission protocol is the TLS protocol, obtains the set characters and the real SNI in the request data, sends the set characters and the real SNI to the proxy server, and converts the request traffic data into simulated request data and sends it to the proxy server; the proxy server restores the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website;

[0051] If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website.

[0052] This embodiment preferably also includes a supplementary module. If the transmission protocol is not TLS protocol or HTTP protocol, the proxy client and the proxy server establish an ss protocol tunnel. The proxy client encrypts the request traffic data and sends it to the proxy server. The proxy server decrypts it and sends it to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the client through the proxy client.

[0053] In this embodiment, preferably, if the transmission protocol is the TLS protocol, the obfuscated encryption module obtains the set characters and the real SNI in the request data, sends the set characters and the real SNI to the proxy server, and converts the request traffic data into simulated request data and sends it to the proxy server; the proxy server restores the simulated request data to request traffic data according to the real SNI and the set characters, and forwards it to the corresponding website. Specifically:

[0054] If the transmission protocol is the TLS protocol, obtain the set characters and the real SNI in the request data, where the set characters are random and unique characters in the TLS protocol, send the set characters and the real SNI to the proxy server, and convert the request traffic data into simulated request data, that is, replace the real SNI in the request traffic data with a simulated domain name to obtain simulated request data, and send the simulated request data to the proxy server; the proxy server restores the corresponding simulated request data to request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website, after which the proxy server obtains the return data; if the TLS protocol is version 1.3 or below, send the simulated request data to the website where the simulation is set, obtain simulated response data, and send both the proxy server simulated response data and the return data to the client through the proxy client; if the TLS protocol is version 1.3 or above, send the return data to the client through the proxy client.

[0055] In this embodiment, preferably, if the transmission protocol in the obfuscation encryption module is the HTTP protocol, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website as follows:

[0056] If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data, that is, the setting header of the http protocol, obtains the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the client through the proxy client.

[0057] Since the device described in the second embodiment of the present invention is used to implement the method of the first embodiment of the present invention, those skilled in the art will be able to understand the specific structure and variations of the device based on the method described in the first embodiment of the present invention, and therefore will not be described in detail here. All devices used in the method of the first embodiment of the present invention fall within the scope of protection of the present invention.

[0058] Based on the same inventive concept, this application provides an electronic device embodiment corresponding to the first embodiment, see the third embodiment for details.

[0059] Example 3

[0060] This embodiment provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, any implementation method in the first embodiment can be implemented.

[0061] Since the electronic device described in this embodiment is the device used to implement the method in Example 1 of this application, based on the method described in Example 1 of this application, those skilled in the art will be able to understand the specific implementation of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of this application will not be described in detail here. As long as the device used by those skilled in the art to implement the method in the embodiment of this application falls within the scope of protection to be provided by this application.

[0062] Based on the same inventive concept, this application provides a storage medium corresponding to Example 1, see Example 4 for details.

[0063] Example 4

[0064] This embodiment provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, any implementation method in the first embodiment can be implemented.

[0065] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0066] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0067] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0068] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0069] Although the specific embodiments of the present invention are described above, those skilled in the art should understand that the specific embodiments described are merely illustrative and are not intended to limit the scope of the present invention. Equivalent modifications and changes made by those skilled in the art in accordance with the spirit of the present invention should be included within the scope of protection of the claims of the present invention.

Claims

1. A method based on network traffic obfuscation encryption, including a proxy server and a proxy client, characterized in that: The steps include: Step 1: The proxy client receives the requested traffic data and determines the transmission protocol type; Step 2: If the transmission protocol is TLS, obtain the set characters and the real SNI in the request data, send the set characters and the real SNI to the proxy server, and convert the request traffic data into simulated request data and send it to the proxy server; The proxy server converts the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website; If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website.

2. The method according to claim 1, wherein: It also includes step 3. If the transmission protocol is not TLS or HTTP, the proxy client and the proxy server establish an ss protocol tunnel. The proxy client encrypts the request traffic data and sends it to the proxy server. The proxy server decrypts it and sends it to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the customer through the proxy client.

3. The method according to claim 1, wherein: In step 2, if the transmission protocol is TLS, the set characters and the real SNI in the request data are obtained, the set characters and the real SNI are sent to the proxy server, and the request traffic data is converted into simulated request data and sent to the proxy server; the proxy server restores the simulated request data into request traffic data according to the real SNI and the set characters, and forwards it to the corresponding website. Specifically: If the transmission protocol is TLS, obtain the set character and the real SNI in the request data, where the set character is a random and unique character in the TLS protocol, send the set character and the real SNI to the proxy server, convert the request traffic data into simulated request data, that is, replace the real SNI in the request traffic data with a simulated domain name to obtain simulated request data, and send the simulated request data to the proxy server; The proxy server converts the corresponding simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website. The proxy server then obtains the return data. If the TLS protocol is version 1.3 or below, the simulated request data is sent to the website where the simulation is set, and the simulated response data is obtained. The proxy server simulated response data and the return data are sent to the client through the proxy client. If the TLS protocol is version 1.3 or above, the return data is sent to the client through the proxy client.

4. The method according to claim 1, wherein: In step 2, if the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website as follows: If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data, that is, the setting header of the http protocol, obtains the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the client through the proxy client.

5. A device based on network traffic obfuscation encryption, comprising a proxy server and a proxy client, characterized in that: include: A protocol determination module, wherein the proxy client receives the request flow data and determines the transmission protocol type; The obfuscation encryption module obtains the set characters and the real SNI in the request data if the transmission protocol is the TLS protocol, sends the set characters and the real SNI to the proxy server, and converts the request traffic data into simulated request data and sends it to the proxy server; The proxy server converts the simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website; If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website.

6. The device based on network traffic obfuscation encryption according to claim 5, characterized in that: It also includes a supplementary module. If the transmission protocol is not TLS or HTTP, the proxy client and the proxy server establish an ss protocol tunnel. The proxy client encrypts the request traffic data and sends it to the proxy server. The proxy server decrypts it and sends it to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the customer through the proxy client.

7. The device based on network traffic obfuscation encryption according to claim 5, characterized in that: If the transmission protocol is TLS, the obfuscation encryption module obtains the set characters and the real SNI in the request data, sends the set characters and the real SNI to the proxy server, and converts the request traffic data into simulated request data and sends it to the proxy server; the proxy server restores the simulated request data into request traffic data according to the real SNI and the set characters, and forwards it to the corresponding website. If the transmission protocol is TLS, obtain the set character and the real SNI in the request data, where the set character is a random and unique character in the TLS protocol, send the set character and the real SNI to the proxy server, convert the request traffic data into simulated request data, that is, replace the real SNI in the request traffic data with a simulated domain name to obtain simulated request data, and send the simulated request data to the proxy server; The proxy server converts the corresponding simulated request data into request traffic data based on the real SNI and the set characters, and forwards it to the corresponding website. The proxy server then obtains the return data. If the TLS protocol is version 1.3 or below, the simulated request data is sent to the website where the simulation is set, and the simulated response data is obtained. The proxy server simulated response data and the return data are sent to the client through the proxy client. If the TLS protocol is version 1.3 or above, the return data is sent to the client through the proxy client.

8. The device based on network traffic obfuscation encryption according to claim 5, characterized in that: In the obfuscation encryption module, if the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data to obtain the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website as follows: If the transmission protocol is HTTP, the proxy client adds the forwarding information to the request traffic data, that is, the setting header of the http protocol, obtains the forwarding traffic data, and then sends it to the proxy server. The proxy server obtains the forwarding information from the forwarding traffic data and performs identity authentication. After the authentication is passed, the forwarding information in the forwarding traffic data is deleted to obtain the request traffic data. The proxy server sends the request traffic data to the corresponding website. After that, the proxy server obtains the return data and sends the return data to the client through the proxy client.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the method according to any one of claims 1 to 4 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.