Message processing method and device, computer device and storage medium

By establishing address associations and using semantic tags to optimize security policies in IPv4 and IPv6 coexisting networks, the high complexity of traditional network security policy management is solved, and intelligent security policy management of IPv4 and IPv6 protocols is realized.

CN120692333BActive Publication Date: 2026-08-25NEW H3C SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510947146.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2026-08-25
Estimated Expiration
2045-07-09

AI Technical Summary

Technical Problem

Traditional network security strategies cannot flexibly adapt to network environments where IPv4 and IPv6 coexist, resulting in a significant increase in the number of security policies, increased management complexity, and difficulty in detecting cross-protocol policy conflicts and vulnerability threats.

Method used

By establishing a pre-defined association between IPv4 and IPv6 addresses, integrating security processing information from the same devices, using semantic tags to replace address information, generating a pre-defined tree structure to optimize security policies, and implementing them on firewall devices.

Benefits of technology

It simplifies security policy configuration, reduces management complexity, improves cross-protocol conflict detection capabilities, reduces the number of policies, and enhances the intelligence of network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692333B_ABST
    Figure CN120692333B_ABST
Patent Text Reader

Abstract

The application provides a message processing method and device, computer equipment and a storage medium. The message processing method comprises the following steps: obtaining a to-be-processed message; the to-be-processed message comprises target address information, and the target address information is IPv4 address information or IPv6 address information; determining target security processing information corresponding to the target address information according to a preset association relationship; the preset association relationship comprises a plurality of security processing information, and each security processing information corresponds to one IPv4 address information and one IPv6 address information; and processing the to-be-processed message according to the target security processing information. The embodiment of the application can support communication of the IPv4 protocol and the IPv6 protocol at the same time, and can effectively reduce the number of the preset association relationship in a dual-protocol coexistence environment, thereby reducing the management complexity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, specifically to a message processing method, apparatus, computer equipment, and storage medium. Background Technology

[0002] With the rapid development of communication technology, the IPv6 (Internet Protocol version 6) protocol has gradually become more widespread. During the transition from the IPv4 (Internet Protocol version 4) protocol to the IPv6 protocol, there are many network environments where both protocols coexist.

[0003] However, traditional network security strategies are designed for single-protocol network environments and cannot flexibly adapt to network environments where IPv4 and IPv6 protocols coexist. Therefore, in a dual-protocol network environment, separate security policies need to be configured for IPv4 and IPv6, leading to an exponential increase in the amount of data required for these policies. For example, in an IPv4 and IPv6 coexisting environment, separate firewall rules for IPv4 and IPv6 need to be configured, significantly increasing management complexity. Summary of the Invention

[0004] In view of this, this application proposes a message processing method, apparatus, computer device, and storage medium to solve the problem in related technologies that the number of policies increases significantly due to configuring security policies separately for IPv4 and IPv6, thus increasing the complexity of policy management.

[0005] A first aspect of this application provides a message processing method, the method comprising:

[0006] Obtain the message to be processed; the message to be processed contains target address information, which is either IPv4 address information or IPv6 address information.

[0007] The target security processing information corresponding to the target address information is determined according to a preset association relationship; the preset association relationship includes multiple security processing information, and each security processing information corresponds to an IPv4 address information and an IPv6 address information.

[0008] The message to be processed is processed according to the target security processing information.

[0009] This application embodiment establishes a mapping relationship between IPv4 addresses and IPv6 addresses and security processing information in a preset association relationship, which can simultaneously support communication of IPv4 and IPv6 protocols; and since merging IPv4 addresses and IPv6 addresses into one association relationship, it can effectively reduce the number of preset association relationships in a dual-protocol coexistence environment, thereby reducing management complexity.

[0010] In this embodiment of the application, the IPv4 address information includes IPv4 source address information and IPv4 destination address information, and the IPv6 address information includes IPv6 source address information and IPv6 destination address information;

[0011] Before acquiring the message to be processed, the method further includes:

[0012] For any two of the multiple predefined associations, if the first IPv4 source address information of the first association and the second IPv6 source address information of the second association represent the same packet sending device, the first IPv4 destination address information of the first association and the second IPv6 destination address information of the second association represent the same packet receiving device, and the first security processing information in the first association and the second security processing information in the second association are the same, then the first association and the second association are merged to obtain a third association.

[0013] The third association is added to the preset association; the third association includes the association between the first IPv4 source address information and the second IPv6 source address information, the association between the first IPv4 destination address information and the second IPv6 destination address information, and the third security processing information; the third security processing information is the first security processing information or the second security processing information.

[0014] In this embodiment of the application, before obtaining the message to be processed, the method further includes:

[0015] The system receives a first configuration instruction related to the association. The first configuration instruction includes first device information of the message sending device, second device information of the message receiving device, and fourth security processing information. The first device information includes a first device name, an IPv4 source address, and an IPv6 source address. The second device information includes a second device name, an IPv4 destination address, and an IPv6 destination address.

[0016] In response to the first configuration instruction, a first semantic tag corresponding to the first device name is generated, and a second semantic tag corresponding to the second device name is generated; the first semantic tag is used to characterize the device's attribute as a message sending device, and the second semantic tag is used to characterize the device's attribute as a message receiving device;

[0017] A fourth association relationship is established between the first semantic tag, the IPv4 source address, and the IPv6 source address, and a fifth association relationship is established between the second semantic tag, the IPv4 destination address, and the IPv6 destination address;

[0018] Establish a sixth association between the first semantic tag, the second semantic tag, and the fourth security processing information, and add the sixth association to the preset association.

[0019] In this embodiment of the application, the method further includes:

[0020] Receive an address change instruction; the address change instruction includes a target semantic tag corresponding to the name of the device to be changed and a change address; the device to be changed includes a message sending device and / or a message receiving device;

[0021] Filter out the target fourth association relationship corresponding to the target semantic tag from multiple fourth association relationships, and / or filter out the target fifth association relationship corresponding to the target semantic tag from multiple fifth association relationships;

[0022] The IPv4 source address and / or IPv6 source address in the target fourth association are changed according to the changed address, and / or the IPv4 destination address and / or IPv6 destination address in the target fifth association are changed according to the changed address.

[0023] In this embodiment of the application, determining the target security processing information corresponding to the target address information based on a preset association relationship includes:

[0024] The target first semantic tag corresponding to the source address information of the message to be processed is determined according to the fourth association relationship; the source address information is the IPv4 source address information or the IPv6 source address information;

[0025] Based on the fifth association relationship, a target second semantic tag corresponding to the destination address information of the message to be processed is determined; the destination address information is the IPv4 destination address information or the IPv6 destination address information.

[0026] The fourth security processing information corresponding to the first semantic tag and the second semantic tag of the target, which is selected from the preset association relationship, is used as the target security processing information.

[0027] In this embodiment of the application, before obtaining the message to be processed containing IPv4 address information or IPv6 address information, the method further includes:

[0028] In response to a second configuration instruction of the security policy, a preset tree structure is generated based on the message type, address information, and security processing information in the second configuration instruction; the address information includes IPv4 address information and / or IPv6 address information; each branch node of the preset tree structure is used to represent the corresponding message type, and the child nodes of each branch node are used to represent the security processing information corresponding to the corresponding address information under the corresponding message type;

[0029] The preset tree structure is decomposed into multiple tasks according to the number of nodes; each node is a task; each task is used to determine whether the message to be processed meets the node requirements; the node requirements are message type requirements or address requirements.

[0030] The priority of each task is determined based on the dependencies between nodes in the preset tree structure;

[0031] A security policy is generated based on the multiple tasks and the priority of each task; the security policy is used to process the messages to be processed.

[0032] In this embodiment of the application, the method includes:

[0033] Under the condition that the first message and the second message are obtained at the same time, the fifth security processing information corresponding to the IPv4 source address and IPv4 destination address of the first message is filtered out from the preset association relationship, and the sixth security processing information corresponding to the IPv6 source address and IPv6 destination address of the second message is filtered out.

[0034] If the IPv4 source address and the IPv6 source address represent the same packet sending device, the IPv4 destination address and the IPv6 destination address represent the same packet receiving device, and the fifth security processing information and the sixth security processing information are different, then a protocol conflict warning message is generated.

[0035] A second aspect of this application provides a message forwarding apparatus, the apparatus comprising:

[0036] The message acquisition module is used to acquire messages to be processed; the messages to be processed contain target address information, which is either IPv4 address information or IPv6 address information.

[0037] The target security processing information determination module is used to determine the target security processing information corresponding to the target address information according to a preset association relationship; the preset association relationship includes multiple security processing information, and each security processing information corresponds to an IPv4 address and an IPv6 address.

[0038] The message processing module is used to process the message to be processed according to the target security processing information.

[0039] An embodiment of the third aspect of this application provides a computer device including a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the message processing method described in the first aspect by executing the computer instructions.

[0040] An embodiment of the fourth aspect of this application provides a computer-readable storage medium storing computer instructions for causing a computer to perform the message processing method described in the first aspect above.

[0041] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0042] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings.

[0043] In the attached diagram:

[0044] Figure 1 A schematic flowchart of a message processing method provided in an embodiment of this application is shown;

[0045] Figure 2 A schematic diagram of a preset tree structure provided in an embodiment of this application is shown;

[0046] Figure 3 This invention provides a schematic diagram of the structure of a message forwarding device according to an embodiment of the present application.

[0047] Figure 4 This invention provides a schematic diagram of the structure of a computer device according to an embodiment of the present application.

[0048] Figure 5 A schematic diagram of a storage medium provided in one embodiment of this application is shown. Detailed Implementation

[0049] Exemplary embodiments of this application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of this application are shown in the drawings, it should be understood that this application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of this application and to fully convey the scope of this application to those skilled in the art.

[0050] It should be noted that, unless otherwise stated, the technical or scientific terms used in this application shall have the ordinary meaning as understood by one of ordinary skill in the art to which this application pertains.

[0051] The technical scenarios involved in the embodiments of this application are described below.

[0052] With the rapid development of the internet and the increasing prevalence of the IPv6 protocol, the transition from IPv4 to IPv6 has led to a large number of dual-stack devices in the network. In this environment where both protocols coexist, network security management faces new challenges. Traditional network security strategies are often designed for a single protocol and cannot flexibly adapt to the mixed traffic of IPv4 and IPv6. This limitation may lead to the following problems:

[0053] Management Complexity: Administrators need to configure security policies separately for IPv4 and IPv6, resulting in an exponential increase in the number of rules, making unified control difficult with existing policies. For example, combining 100 IPv4 rules with 100 IPv6 rules requires maintaining 10,000 cross-rules. Conflict Detection Limitations: Existing tools can only detect rule conflicts within a single protocol; cross-protocol policy conflicts (such as allowing IPv4 but denying IPv6) are difficult to detect. Vulnerability Threats: If security policies are not updated synchronously, security vulnerabilities under a certain protocol may arise. For example, both IPv4 and IPv6 security policies need to reference DPI-related security services; sometimes, when administrators configure firewalls to strictly control IPv4 traffic, they may overlook potential threats from IPv6 traffic. Insufficient Protocol Compatibility: Traditional firewalls cannot automatically associate the semantic equivalence of IPv4 and IPv6 (e.g., 192.168.1.1 and 2001::db8:1 point to the same service). They also cannot recognize encapsulation protocols such as IPv4-over-IPv6, leading to policy failures or false blocking. Low level of intelligence: rule matching relies on a fixed list of IPs and cannot be dynamically optimized based on traffic characteristics; administrators need to directly manipulate the underlying IP addresses, which has a high learning cost and is prone to misconfiguration.

[0054] Therefore, how to intelligently manage these two protocols without affecting network security has become an urgent problem to be solved.

[0055] The main objective of this invention is to provide an intelligent security policy management method and system that supports both IPv4 and IPv6 dual-protocol stacks. This system can simultaneously support secure access for both IPv4 and IPv6 protocols in modern network environments, simplifying configuration processes, reducing operational costs, and addressing the challenges and shortcomings in current network security management. This invention belongs to the field of network security and communication technology, and is specifically applicable to complex network environments such as enterprise networks, cloud computing, and 5G core networks.

[0056] According to an embodiment of this application, a message processing method embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0057] This embodiment provides a packet processing method that can be applied to firewall devices. Figure 1 This is a flowchart of a message processing method according to an embodiment of this application, such as... Figure 1 As shown, the process includes the following steps:

[0058] Step S101: Obtain the message to be processed.

[0059] In this embodiment, the message to be processed includes destination address information, which is either IPv4 address information or IPv6 address information. The IPv4 address information includes IPv4 source address information and IPv4 destination address information, while the IPv6 address information includes IPv6 source address information and IPv6 destination address information. Both the IPv4 and IPv6 source address information are used to identify the message sending device, and both the IPv4 and IPv6 destination address information are used to identify the message receiving device.

[0060] Prior to step S101 above, the method further includes steps S201-S202:

[0061] Step S201: For any two of the multiple predefined association relationships, if the first IPv4 source address information of the first association relationship and the second IPv6 source address information of the second association relationship represent the same packet sending device, the first IPv4 destination address information of the first association relationship and the second IPv6 destination address information of the second association relationship represent the same packet receiving device, and the first security processing information in the first association relationship and the second security processing information in the second association relationship are the same, then the first association relationship and the second association relationship are merged to obtain a third association relationship.

[0062] Step S202: Add the third association to the preset association.

[0063] Specifically, the third association includes the association between the first IPv4 source address information and the second IPv6 source address information, the association between the first IPv4 destination address information and the second IPv6 destination address information, and the third security processing information; the third security processing information is either the first security processing information or the second security processing information.

[0064] In this embodiment of the application, the user can pre-configure multiple predefined associations on the firewall device. Each association includes the address information of the packet sending device, the address information of the packet receiving device, and the corresponding security processing information. By configuring the associations, the firewall device can process the passing packets accordingly. For example, when the firewall device receives packet 1, it will determine the security processing information (e.g., allow or deny) corresponding to the source address information and destination address information of packet 1 from the configured associations. When the security processing information is allow, packet 1 is allowed to pass; when the security processing information is deny, packet 1 is denied to pass.

[0065] In a network environment where IPv4 and IPv6 coexist, firewall devices need to be configured with associations applicable to both IPv4 and IPv6 separately. This significantly increases the number of security policies (i.e., the aforementioned associations) and greatly increases the complexity of policy management. For example, when configuring an association that allows packet sending device 1 to send packets to packet receiving device 2, the following two associations need to be assigned: Association 1: IPv4 source address of packet sending device 1 — IPv4 destination address of packet receiving device 2 — security processing information (“Allow”); Association 2: IPv6 source address of packet sending device 1 — IPv6 destination address of packet receiving device 2 — security processing information (“Allow”).

[0066] To address the aforementioned issues, this application embodiment filters and merges all associations configured on the firewall device. Specifically, when the following two associations occur, they can be merged:

[0067] The first IPv4 source address information of the first association and the second IPv6 source address information of the second association represent the same packet sending device; the first IPv4 destination address information of the first association and the second IPv6 destination address information of the second association represent the same packet receiving device; and the first security processing information in the first association and the second security processing information in the second association are the same.

[0068] The third association obtained after fusion contains both two source address information (i.e., IPv4 source address and IPv6 source address) and two destination address information (i.e., IPv4 destination address and IPv6 destination address), which allows the firewall device to adapt to both IPv4 and IPv6 communication environments with only one association, thereby reducing the complexity of association management.

[0069] In some specific embodiments, before step S101 described above, the method further includes steps S301-S304:

[0070] Step S301: Receive the first configuration instruction for the association relationship.

[0071] Specifically, the first configuration instruction includes first device information of the message sending device, second device information of the message receiving device, and fourth security processing information; the first device information includes a first device name, an IPv4 source address, and an IPv6 source address; the second device information includes a second device name, an IPv4 destination address, and an IPv6 destination address.

[0072] Step S302: In response to the first configuration instruction, generate a first semantic tag corresponding to the first device name and generate a second semantic tag corresponding to the second device name.

[0073] Specifically, the first semantic tag is used to characterize the device's attribute as a message sending device, and the second semantic tag is used to characterize the device's attribute as a message receiving device.

[0074] Step S303: Establish a fourth association relationship between the first semantic tag, the IPv4 source address, and the IPv6 source address, and establish a fifth association relationship between the second semantic tag, the IPv4 destination address, and the IPv6 destination address.

[0075] Step S304: Establish a sixth association relationship between the first semantic tag, the second semantic tag, and the fourth security processing information, and add the sixth association relationship to the preset association relationship.

[0076] In this embodiment, by establishing an association between the device's semantic tags and two types of address information (i.e., IPv4 and IPv6), the semantic tags can replace the two types of address information, thereby directly determining the corresponding security processing information. Furthermore, by establishing a sixth association between the first semantic tag, the second semantic tag, and the fourth security processing information, the security processing information is associated with the device's semantic attributes (message sending device or message receiving device). This makes the management of security processing information no longer dependent on specific device addresses, but based on the device's role attributes. The semantic tags allow direct determination of the corresponding security processing information, simplifying the configuration and management of security policies.

[0077] In some specific embodiments, before step S101 above, the method further includes steps S401-S404:

[0078] Step S401: In response to the second configuration instruction of the security policy, a preset tree structure is generated according to the message type, address information and security processing information in the second configuration instruction.

[0079] Specifically, the address information includes IPv4 address information and / or IPv6 address information; each branch node of the preset tree structure is used to represent the corresponding packet type, for example... Figure 2 The "HTTP traffic" and "FTP traffic" are listed in the code; the child nodes of each branch node are used to represent the security processing information corresponding to the corresponding address information under the corresponding message type, for example... Figure 2 As shown: Under the FTP traffic node, when the source address of the packet is 192.168.1.0 / 24 and the destination address is 203.0.113.20, the packet is rejected; similarly, when the source address of the packet is 2001.db8:1:: / 64 and the destination address is 2001:db8:2::20, the packet is rejected.

[0080] Step S402: Decompose the preset tree structure into multiple tasks according to the number of nodes.

[0081] Specifically, each node is a task; each task is used to determine whether the message to be processed meets the node requirements; the node requirements are message type requirements or address requirements.

[0082] Step S403: Determine the priority of each task based on the dependency relationships between nodes in the preset tree structure;

[0083] Step S404: Generate a security policy based on the multiple tasks and the priority of each task; the security policy is used to process the message to be processed.

[0084] In this embodiment of the application, the judgment logic of each node is treated as a task, for example... Figure 2 As shown: the root node is used to determine whether a packet belongs to HTTP or FTP traffic. For example, the source address node under the HTTP traffic node is used to determine whether the source address of the packet is 192.168.1.0 / 24 or 2001:db8:1:: / 64. The dependencies between different nodes can serve as the execution priority between tasks. For example, the root node might be used to determine the packet's traffic type first, and then the source address node for the corresponding traffic type might be used to determine the packet's specific source address information, or the destination address node for the corresponding traffic type might be used to determine the packet's specific destination address information. Based on multiple tasks and their priorities, a security policy is generated so that when the firewall receives a packet, it can determine the appropriate security processing information based on the security policy, the packet's source address information, and its destination address information, and then process the packet accordingly.

[0085] Step S102: Determine the target security processing information corresponding to the target address information according to the preset association relationship.

[0086] In this embodiment of the application, the preset association relationship includes multiple security processing information, each security processing information corresponding to an IPv4 address and / or an IPv6 address.

[0087] In some specific embodiments, step S102 above includes steps S1021-S1023:

[0088] Step S1021: Determine the target first semantic tag corresponding to the source address information of the message to be processed according to the fourth association relationship; the source address information is the IPv4 source address information or the IPv6 source address information;

[0089] Step S1022: Determine the target second semantic tag corresponding to the destination address information of the message to be processed according to the fifth association relationship; the destination address information is the IPv4 destination address information or the IPv6 destination address information;

[0090] Step S1023: The fourth security processing information corresponding to the first semantic tag and the second semantic tag of the target, which is filtered from the preset association relationship, is used as the target security processing information.

[0091] In this embodiment, the target first semantic tag corresponding to the source address information (IPv4 or IPv6) of the packet to be processed can be quickly determined through the fourth association relationship (the association relationship between source address information and the first semantic tag). This means that the system does not need to parse complex address information every time, but can directly find the corresponding semantic tag through the established association relationship, which greatly improves the processing speed.

[0092] Preferably, by pre-setting association relationships, the corresponding fourth security processing information can be directly filtered out based on the target's first semantic tag and second semantic tag, and used as the target security processing information. This semantic tag-based security processing information filtering mechanism makes the configuration of security policies more intuitive and concise. Administrators can quickly understand and configure security policies through semantic tags without needing to delve into specific address information.

[0093] Step S103: Process the message to be processed according to the target security processing information.

[0094] Specifically, security processing information includes allow and deny, which are used by firewall devices to allow or deny the passage of corresponding messages.

[0095] In some specific embodiments, the method further includes steps S501-S502:

[0096] Step S501: Under the condition that the first packet and the second packet are obtained at the same time, the fifth security processing information corresponding to the IPv4 source address and IPv4 destination address of the first packet is filtered out from the preset association relationship, and the sixth security processing information corresponding to the IPv6 source address and IPv6 destination address of the second packet is filtered out.

[0097] Step S502: If the IPv4 source address and the IPv6 source address represent the same packet sending device, the IPv4 destination address and the IPv6 destination address represent the same packet receiving device, and the fifth security processing information and the sixth security processing information are different, then a protocol conflict warning message is generated.

[0098] In this embodiment, after receiving a protocol conflict warning, the user or administrator can promptly modify the association relationships defined by the firewall device. Steps S501-S502 effectively address the limitation of conflict detection, namely, "existing tools can only detect rule conflicts within a single protocol, and cross-protocol policy conflicts (such as IPv4 allowing but IPv6 denying) are difficult to detect."

[0099] Corresponding to the above implementation methods for message processing, this application also provides a message forwarding device for executing the message processing methods described in any of the above embodiments. For example... Figure 3 As shown, the message forwarding device includes:

[0100] The message acquisition module is used to acquire messages to be processed; the messages to be processed contain target address information, which is either IPv4 address information or IPv6 address information.

[0101] The target security processing information determination module is used to determine the target security processing information corresponding to the target address information according to a preset association relationship; the preset association relationship includes multiple security processing information, and each security processing information corresponds to an IPv4 address and an IPv6 address.

[0102] The message processing module is used to process the message to be processed according to the target security processing information.

[0103] Optionally, the IPv4 address information includes IPv4 source address information and IPv4 destination address information, and the IPv6 address information includes IPv6 source address information and IPv6 destination address information. The association fusion module is used to, before acquiring the packet to be processed, for any two of a plurality of predefined association relationships, if the first IPv4 source address information of the first association relationship and the second IPv6 source address information of the second association relationship represent the same packet sending device, the first IPv4 destination address information of the first association relationship and the second IPv6 destination address information of the second association relationship represent the same packet receiving device, and the first security processing information in the first association relationship and the second security processing information in the second association relationship are the same, then the first association relationship and the second association relationship are fused to obtain a third association relationship; the third association relationship is added to the preset association relationships; the third association relationship includes the association relationship between the first IPv4 source address information and the second IPv6 source address information, the association relationship between the first IPv4 destination address information and the second IPv6 destination address information, and third security processing information; the third security processing information is either the first security processing information or the second security processing information.

[0104] Optionally, the association configuration module is used to receive a first configuration instruction for association before acquiring the message to be processed; the first configuration instruction includes first device information of the message sending device, second device information of the message receiving device, and fourth security processing information; the first device information includes a first device name, an IPv4 source address, and an IPv6 source address; the second device information includes a second device name, an IPv4 destination address, and an IPv6 destination address; in response to the first configuration instruction, a first semantic tag corresponding to the first device name and a second semantic tag corresponding to the second device name are generated; the first semantic tag is used to characterize the device's attribute as a message sending device, and the second semantic tag is used to characterize the device's attribute as a message receiving device; a fourth association relationship is established between the first semantic tag, the IPv4 source address, and the IPv6 source address, and a fifth association relationship is established between the second semantic tag, the IPv4 destination address, and the IPv6 destination address; a sixth association relationship is established between the first semantic tag, the second semantic tag, and the fourth security processing information, and the sixth association relationship is added to the preset association relationship.

[0105] Optionally, the apparatus further includes an address modification module for receiving an address modification instruction; the address modification instruction includes a target semantic tag corresponding to the name of the device to be modified and a modification address; the device to be modified includes a message sending device and / or a message receiving device; filtering out a target fourth association corresponding to the target semantic tag from a plurality of fourth associations, and / or filtering out a destination target fifth association corresponding to the target semantic tag from a plurality of fifth associations; modifying the IPv4 source address and / or IPv6 source address in the target fourth association according to the modification address, and / or modifying the IPv4 destination address and / or IPv6 destination address in the target fifth association according to the modification address.

[0106] Optionally, the target security processing information determination module is further configured to determine a target first semantic label corresponding to the source address information of the packet to be processed based on the fourth association relationship; the source address information is the IPv4 source address information or the IPv6 source address information; determine a target second semantic label corresponding to the destination address information of the packet to be processed based on the fifth association relationship; the destination address information is the IPv4 destination address information or the IPv6 destination address information; and use the fourth security processing information corresponding to the target first semantic label and the target second semantic label selected in the preset association relationship as the target security processing information.

[0107] Optionally, a security policy configuration module is used to respond to a second configuration instruction of the security policy, and generate a preset tree structure based on the packet type, address information, and security processing information in the second configuration instruction; the address information includes IPv4 address information and / or IPv6 address information; each branch node of the preset tree structure is used to represent a corresponding packet type, and the child nodes of each branch node are used to represent the security processing information corresponding to the corresponding address information under the corresponding packet type; the preset tree structure is decomposed into multiple tasks according to the number of nodes; each node is a task; each task is used to determine whether the packet to be processed meets the node requirements; the node requirements are packet type requirements or address requirements; the priority of each task is determined according to the dependency relationship between nodes in the preset tree structure; a security policy is generated according to the multiple tasks and the priority of each task; the security policy is used to process the packet to be processed.

[0108] Optionally, the protocol conflict warning generation module is used to, under the condition of simultaneously acquiring the first packet and the second packet, filter out the fifth security processing information corresponding to the IPv4 source address and IPv4 destination address of the first packet from the preset association relationship, and filter out the sixth security processing information corresponding to the IPv6 source address and IPv6 destination address of the second packet; if the IPv4 source address and the IPv6 source address represent the same packet sending device, the IPv4 destination address and the IPv6 destination address represent the same packet receiving device, and the fifth security processing information and the sixth security processing information are different, then a protocol conflict warning message is generated.

[0109] The message forwarding device provided in the above embodiments of this application and the message processing method provided in the embodiments of this application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0110] This application also provides a computer device for performing the above-described message processing method. Please refer to... Figure 4 This illustrates a schematic diagram of a computer device provided by some embodiments of this application. For example... Figure 4 As shown, the computer device 4 includes: a processor 400, a memory 401, a bus 402, and a communication interface 403. The processor 400, the communication interface 403, and the memory 401 are connected via the bus 402. The memory 401 stores a computer program that can run on the processor 400. When the processor 400 runs the computer program, it executes the message processing method provided in any of the foregoing embodiments of this application.

[0111] The memory 401 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between this system network element and at least one other network element is achieved through at least one communication interface 403 (which can be wired or wireless), such as the Internet, wide area network, local area network, or metropolitan area network.

[0112] Bus 402 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 401 is used to store programs. After receiving an execution instruction, the processor 400 executes the program. The message processing method disclosed in any of the foregoing embodiments can be applied to the processor 400, or implemented by the processor 400.

[0113] The processor 400 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 400 or by instructions in software form. The processor 400 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 401. The processor 400 reads the information in memory 401 and, in conjunction with its hardware, completes the steps of the above method.

[0114] The computer device and message processing method provided in this application are based on the same inventive concept and have the same beneficial effects as the methods they employ, operate, or implement.

[0115] This application also provides a computer-readable storage medium corresponding to the message processing method provided in the foregoing embodiments. Please refer to... Figure 5The computer-readable storage medium shown is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it executes the message processing method provided in any of the foregoing embodiments.

[0116] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.

[0117] The computer-readable storage medium provided in the above embodiments of this application and the message processing method provided in the embodiments of this application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.

[0118] It should be noted that:

[0119] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this application may be practiced without these specific details. In some instances, well-known structures and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0120] Similarly, it should be understood that, for the sake of brevity and to aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of this application, various features of this application are sometimes grouped together in a single embodiment, figure, or description thereof. However, this disclosure should not be construed as reflecting a schematic diagram in which the claimed application requires more features than expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of this application.

[0121] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features but not others included in other embodiments, combinations of features from different embodiments are intended to be within the scope of this application and form different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.

[0122] The above description is merely a preferred embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A message processing method, characterized in that, The method includes: Obtain the message to be processed; the message to be processed contains target address information, which is either IPv4 address information or IPv6 address information. The target security processing information corresponding to the target address information is determined according to a preset association relationship; the preset association relationship includes multiple security processing information, and each security processing information corresponds to an IPv4 address information and an IPv6 address information. The message to be processed is processed according to the target security processing information; The IPv4 address information includes IPv4 source address information and IPv4 destination address information, and the IPv6 address information includes IPv6 source address information and IPv6 destination address information; Before acquiring the message to be processed, the method further includes: For any two of the multiple predefined associations, if the first IPv4 source address information of the first association and the second IPv6 source address information of the second association represent the same packet sending device, the first IPv4 destination address information of the first association and the second IPv6 destination address information of the second association represent the same packet receiving device, and the first security processing information in the first association and the second security processing information in the second association are the same, then the first association and the second association are merged to obtain a third association. The third association is added to the preset association; the third association includes the association between the first IPv4 source address information and the second IPv6 source address information, the association between the first IPv4 destination address information and the second IPv6 destination address information, and the third security processing information; the third security processing information is the first security processing information or the second security processing information.

2. The method according to claim 1, characterized in that, Before acquiring the message to be processed, the method further includes: The system receives a first configuration instruction related to the association. The first configuration instruction includes first device information of the message sending device, second device information of the message receiving device, and fourth security processing information. The first device information includes a first device name, an IPv4 source address, and an IPv6 source address. The second device information includes a second device name, an IPv4 destination address, and an IPv6 destination address. In response to the first configuration instruction, a first semantic tag corresponding to the first device name is generated, and a second semantic tag corresponding to the second device name is generated; the first semantic tag is used to characterize the device's attribute as a message sending device, and the second semantic tag is used to characterize the device's attribute as a message receiving device; A fourth association relationship is established between the first semantic tag, the IPv4 source address, and the IPv6 source address, and a fifth association relationship is established between the second semantic tag, the IPv4 destination address, and the IPv6 destination address; Establish a sixth association between the first semantic tag, the second semantic tag, and the fourth security processing information, and add the sixth association to the preset association.

3. The method according to claim 2, characterized in that, The method further includes: Receive an address change instruction; the address change instruction includes a target semantic tag corresponding to the name of the device to be changed and a change address; the device to be changed includes a message sending device and / or a message receiving device; Filter out the target fourth association relationship corresponding to the target semantic tag from multiple fourth association relationships, and / or filter out the target fifth association relationship corresponding to the target semantic tag from multiple fifth association relationships; The IPv4 source address and / or IPv6 source address in the target fourth association are changed according to the changed address, and / or the IPv4 destination address and / or IPv6 destination address in the target fifth association are changed according to the changed address.

4. The method according to claim 2, characterized in that, Based on a preset association relationship, target security processing information corresponding to the target address information is determined, including: The target first semantic tag corresponding to the source address information of the message to be processed is determined according to the fourth association relationship; the source address information is the IPv4 source address information or the IPv6 source address information; Based on the fifth association relationship, a target second semantic tag corresponding to the destination address information of the message to be processed is determined; the destination address information is the IPv4 destination address information or the IPv6 destination address information. The fourth security processing information corresponding to the first semantic tag and the second semantic tag of the target, which is selected from the preset association relationship, is used as the target security processing information.

5. The method according to claim 1, characterized in that, Before acquiring the pending packet containing IPv4 address information or IPv6 address information, the method further includes: In response to a second configuration instruction of the security policy, a preset tree structure is generated based on the message type, address information, and security processing information in the second configuration instruction; the address information includes IPv4 address information and / or IPv6 address information; each branch node of the preset tree structure is used to represent the corresponding message type, and the child nodes of each branch node are used to represent the security processing information corresponding to the corresponding address information under the corresponding message type; The preset tree structure is decomposed into multiple tasks according to the number of nodes; each node is a task; each task is used to determine whether the message to be processed meets the node requirements; the node requirements are message type requirements or address requirements. The priority of each task is determined based on the dependencies between nodes in the preset tree structure; A security policy is generated based on the multiple tasks and the priority of each task; the security policy is used to process the messages to be processed.

6. The method according to claim 1, characterized in that, The method includes: Under the condition that the first message and the second message are obtained at the same time, the fifth security processing information corresponding to the IPv4 source address and IPv4 destination address of the first message is filtered out from the preset association relationship, and the sixth security processing information corresponding to the IPv6 source address and IPv6 destination address of the second message is filtered out. If the IPv4 source address and the IPv6 source address represent the same packet sending device, the IPv4 destination address and the IPv6 destination address represent the same packet receiving device, and the fifth security processing information and the sixth security processing information are different, then a protocol conflict warning message is generated.

7. A message forwarding device, characterized in that, The device includes: The message acquisition module is used to acquire messages to be processed; the messages to be processed contain target address information, which is either IPv4 address information or IPv6 address information. The target security processing information determination module is used to determine the target security processing information corresponding to the target address information according to a preset association relationship; the preset association relationship includes multiple security processing information, and each security processing information corresponds to an IPv4 address and an IPv6 address. The message processing module is used to process the message to be processed according to the target security processing information; The IPv4 address information includes IPv4 source address information and IPv4 destination address information, and the IPv6 address information includes IPv6 source address information and IPv6 destination address information; Before obtaining the message to be processed, the following steps are also included: For any two of the multiple predefined associations, if the first IPv4 source address information of the first association and the second IPv6 source address information of the second association represent the same packet sending device, the first IPv4 destination address information of the first association and the second IPv6 destination address information of the second association represent the same packet receiving device, and the first security processing information in the first association and the second security processing information in the second association are the same, then the first association and the second association are merged to obtain a third association. The third association is added to the preset association; the third association includes the association between the first IPv4 source address information and the second IPv6 source address information, the association between the first IPv4 destination address information and the second IPv6 destination address information, and the third security processing information; the third security processing information is the first security processing information or the second security processing information.

8. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the message processing method of any one of claims 1 to 6 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the message processing method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Concurrent communication method for embedded equipment supporting IPv4 / IPv6 protocol

    CN102006338A

  • Method for identifying audit log asset in internet protocol version 6 (IPv6) mixed network

    CN102724068A