Confusion network directory server hiding method for client

By using the IPFS network to hide the IP address of the directory server in the obfuscated network, the problems of the directory server being vulnerable to attacks and the inflexible expansion of the proxy layer are solved, real-time updates of directory information and flexibility of network expansion are achieved, and the security and stability of the system are enhanced.

CN120729636AActive Publication Date: 2025-09-30NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511195180.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-09-30
Estimated Expiration
2045-08-26

AI Technical Summary

Technical Problem

The IP address of the directory server in the existing obfuscated network is fixed and vulnerable to attacks, and the proxy layer is not flexible in expansion, making it difficult for clients to obtain real-time updated directory information.

Method used

The IPFS network is used to hide the real IP of the directory server. An IPFS network consisting of multiple IPFS nodes is built as an intermediate proxy layer to periodically synchronize directory files, and IPNS records are used to enable client-side directory file acquisition.

Benefits of technology

Effectively hide the real address of the directory server, reduce the risk of attacks, improve system security and stability, and achieve flexibility in network expansion and real-time directory information updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729636A_ABST
    Figure CN120729636A_ABST
Patent Text Reader

Abstract

The invention provides a confused network directory server hiding method for a client, relates to the technical field of privacy data security protection, and solves the problem of hiding limitation of a confused network directory server at present. The method comprises the following steps: constructing a hidden network corresponding to a directory server of a confusion network, wherein the hidden network is an IPFS network consisting of a plurality of IPFS nodes; the directory server issues the directory file to the IPFS network, and an IPFS node in the IPFS network periodically synchronizes the issued directory file by retrieving an IPNS record; the address of the IPFS node and the IPNS record are correspondingly configured for the client, and after the client is connected to the specified IPFS node, the directory file of the directory server is obtained through the IPNS record. According to the invention, the real IP of the network directory server can be hidden and confused by using the IPFS network, and the accessed client can obtain the latest directory information while the expansion flexibility is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of privacy data security protection, and in particular to a method for hiding an obfuscated network directory server for a client. Background Art

[0002] Internet users' growing demand for privacy protection has spawned obfuscation networks. These networks aim to provide privacy protection by concealing the identities and relationships of communicating entities through various technical means, such as message forwarding, data encryption, and traffic obfuscation. Directory servers play a key role in obfuscation networks, storing and distributing information about nodes within the network. This allows new users to access existing node information and smoothly connect to the obfuscation network. Currently, there are two main approaches to obfuscation network directory servers: centralized and decentralized.

[0003] Centralized directory servers, due to their fixed and public IP addresses, are vulnerable to various attacks, such as blocked communication channels and DDoS attacks. Furthermore, attackers can monitor inbound and outbound connections to the directory server to uncover user identities and threaten user privacy. Decentralized solutions, such as distributed directory servers, address the centralization issue to some extent. However, due to the lack of centralized control, the node discovery process is complex and poses security risks such as malicious node attacks and deanonymization attacks caused by differences in user network perception.

[0004] Currently, obfuscated networks, including the Tor network, use centralized directory servers, so how to hide the centralized directory servers is crucial. Figure 1 As shown, users directly access the obfuscated network directory server through the client to obtain the obfuscated network directory information; since the IP address of the directory server is fixed and public, attackers can prohibit users from accessing the obfuscated network by banning the directory server.

[0005] The proxy server's proxy node acts as a relay node between the client and the directory server, hiding the directory server's IP address. If there is only one proxy node, a failure of that node may cause the entire data transmission link to be interrupted, affecting communication between the client and the directory server.

[0006] In order to make the path from the proxy node to the corresponding node of the directory server non-single, a proxy layer with multiple proxy nodes is usually designed between the client and the directory server, such as Figure 2 As shown, although the client accesses from different proxy nodes, it can obtain the obfuscated network directory information from the directory server. Even if a proxy node is interrupted, it can still obtain the obfuscated network directory information in the directory server by accessing other proxy nodes.

[0007] However, when deploying multiple proxy nodes in a proxy layer, the directory server address must be configured in each proxy node's configuration file to ensure that the proxy node can forward requests to the directory server and obtain obfuscated network directory information. Therefore, this approach is cumbersome and inflexible when expanding the proxy layer, as each proxy node can only be configured to forward to the directory server address.

[0008] Therefore, how to obtain the obfuscated network directory information on the directory server while hiding the directory server address and flexibly expand the intermediate proxy nodes of the proxy layer has become a key problem that needs to be solved urgently by those skilled in the art. Summary of the Invention

[0009] The purpose of the present invention is to solve the current hiding limitations faced by obfuscated network directory servers, including the fact that the IP address of the obfuscated network directory server is fixed and cannot be hidden, that even if the IP address is hidden, the proxy layer expansion is inflexible, and that the proxy layer topology is single, making it difficult for clients to obtain real-time updated obfuscated network directory information. Therefore, the present invention proposes a method for hiding an obfuscated network directory server for clients, which utilizes the IPFS network to hide the real IP address of the obfuscated network directory server, thereby reducing the risk of attack. The present invention is more flexible when expanding the IPFS network node between the client and the obfuscated network directory server, and can obtain obfuscated network directory information in real time. The IPFS network node itself periodically obtains the directory files on the obfuscated network directory server, allowing the connected client to obtain the latest directory information.

[0010] The present invention adopts the following technical solutions to achieve the purpose: A method for hiding an obfuscated network directory server from a client comprises the following steps: S1. Based on IPFS technology, a hidden network corresponding to the directory server of the obfuscated network is constructed. The hidden network is an IPFS network composed of multiple IPFS nodes. S2. Use the IPFS network as an intermediate proxy layer to connect the client and the directory server, and the directory server publishes the directory file to the IPFS network; S3. IPFS nodes in the IPFS network periodically synchronize directory files published by the directory server by retrieving IPNS records; S4. Configure the IPFS node address and IPNS record for the client. After connecting to the specified IPFS node, the client obtains the directory file of the directory server through the IPNS record.

[0011] Specifically, in step S1, each IPFS node has a built-in IPFS component, and the connection between each IPFS node is achieved through the connection of each IPFS component; the directory server of the obfuscated network also has a built-in IPFS component, and the directory server is connected to the IPFS node through its built-in IPFS component. The IPFS component of the directory server is used to publish and transmit directory files to the IPFS network; The topological connection structure composed of the IPFS network and the directory server meets the following constraints: there is at least one IPFS node in the IPFS network that is connected to the directory server, and the remaining IPFS nodes are connected to each other by building a connectivity graph; The client is configured to be able to access the address of any IPFS node in the IPFS network, so that the client can access the IPFS network; based on the topological connection relationship between the IPFS network and the directory server, any IPFS node configured by the client can access the directory server and transfer the obtained directory files to the client.

[0012] Preferably, during the construction or use phase of the IPFS network, the expansion of the IPFS network is carried out by adding new IPFS nodes. When a new IPFS node needs to be added, any existing IPFS node in the IPFS network is configured as a boot node. The boot node only needs to be directly or indirectly connected to the directory server. The expansion of the IPFS network is achieved by connecting the newly added IPFS node to the boot node.

[0013] Specifically, in step S2, the process of the directory server publishing the directory file to the IPFS network is as follows: First, the obfuscation nodes in the obfuscation network report their status information to the directory server. The directory server collects and aggregates the status information of the obfuscation network and generates the corresponding directory file. The directory server then uses the add command on the directory file through its built-in IPFS component to add the directory file to the IPFS network for separate storage and generate an access code corresponding to the directory file. It then uses the publish command to bind the directory file access code to its IPFS component and publish it to the IPFS network.

[0014] Preferably, when the directory server binds the directory file access code to its IPFS component, it pre-generates an IPNS record bound to the directory file access code and then publishes the IPNS record to the IPFS network; during the communication interaction process, as the directory file is continuously updated, the binding relationship between the directory file access code and the IPNS record to which it has been bound remains unchanged; when the client accesses any IPFS node in the IPFS network, it retrieves the corresponding IPNS record through the IPFS node to obtain the directory file.

[0015] Furthermore, in step S3, when any IPFS node needs to synchronously obtain the directory file published by the directory server, the IPNS record generated by the directory server is pre-configured for all IPFS nodes in the IPFS network; The IPFS node that needs to synchronously obtain the directory file decides whether to obtain the access code of the directory file corresponding to the IPNS record from other IPFS nodes that have cached the IPNS record through a query request based on whether it has cached the corresponding IPNS record, and then realizes the synchronous acquisition of the corresponding directory file based on the obtained access code.

[0016] Specifically, if the IPFS node that needs to synchronously obtain the directory file has cached the corresponding IPNS record, then directly parse the IPNS record and obtain the access code of the corresponding directory file; if the IPFS node does not cache the corresponding IPNS record, then use the IPFS distributed hash table DHT to search for the IPFS node that has cached the IPNS record in the IPFS network, and obtain the access code of the directory file corresponding to the IPNS record from it.

[0017] Specifically, after the IPFS node obtains the access code, it requests the IPFS network to access the corresponding stored directory file based on the access code. The IPFS network obtains the directory file based on the access code and returns it to the corresponding IPFS node, realizing the synchronous acquisition of the directory file by the IPFS node.

[0018] Specifically, in step S4, the process of the client obtaining the directory file through the IPNS record is as follows: after the client is connected to any specified IPFS node, it completes the configuration of the IPFS node address and the configuration of the IPNS record corresponding to the required directory file; the client sends a file request containing the IPNS record to the connected IPFS node. After receiving the file request from the client, the IPFS node extracts the corresponding IPNS record configuration, parses it into an access code, obtains the corresponding directory file according to the access code, and returns it to the client.

[0019] Specifically, the directory file can be stored in the storage of any one or more IPFS nodes in the IPFS network. When an IPFS node receives a file request from a client, it first searches whether it has stored the directory file corresponding to the IPNS record. If so, it directly returns the directory file to the client. If it does not have it stored, it searches and obtains the directory file corresponding to the IPNS record in the IPFS network according to the client's IPNS record configuration, and then returns the directory file to the client, thus realizing the process of the client obtaining the required directory file from the directory server.

[0020] In summary, due to the adoption of this technical solution, the beneficial effects of the present invention are as follows: This invention effectively hides the directory server's real physical address and port information by deploying the IPFS network between the client and the obfuscated network directory server. This mechanism significantly reduces the risk of direct network attacks on the directory server, preventing attackers from launching targeted threats through exposed IP addresses, thereby enhancing the overall security and stability of the relevant system.

[0021] Furthermore, the present invention achieves a high degree of flexibility in network expansion after the directory server is successfully connected to the IPFS network. During the startup configuration process, newly added IPFS nodes do not need to specify the specific address or port of the directory server. Instead, they simply connect to existing nodes in the IPFS network to automatically establish normal communication and data exchange with the directory server. This design not only significantly simplifies the operational process of network expansion but also enables the system to quickly respond to abnormal situations such as attackers attempting to discover and block IPFS nodes. It maintains service continuity by rapidly deploying new nodes, ensuring the network's efficient operation and adaptability in a dynamic environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The present invention further illustrates its implementation and technical solutions in detail through the following drawings, which specifically include 7 drawings as follows: Figure 1 A schematic diagram of a conventional method for a client to access an obfuscated network directory server in the prior art; Figure 2 A schematic diagram of a client accessing an obfuscated network directory server through a proxy node in the prior art; Figure 3 A schematic diagram briefly describing the overall process of the method for hiding an obfuscated network directory server according to the present invention; Figure 4 This is a schematic diagram of the topological structure of the hidden network of the directory server based on IPFS in the present invention; Figure 5 This is a schematic diagram of the specific process of the directory server in the present invention publishing directory files to the IPFS network; Figure 6 This is a schematic diagram of the specific process of the IPFS node obtaining directory files from the IPFS network in the present invention; Figure 7 This is a schematic diagram of the specific process of the client obtaining directory files from the IPFS node in the present invention. DETAILED DESCRIPTION

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0024] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort shall fall within the scope of protection of the present invention.

[0025] A method for hiding the server of obfuscated network directory for clients. Figure 3 The overall process steps of the method are shown, which can be viewed simultaneously. The key steps are summarized as follows: S1. Based on IPFS technology, a hidden network corresponding to the directory server of the obfuscated network is constructed. The hidden network is an IPFS network composed of multiple IPFS nodes. S2. Use the IPFS network as an intermediate proxy layer to connect the client and the directory server, and the directory server publishes the directory file to the IPFS network; S3. IPFS nodes in the IPFS network periodically synchronize directory files published by the directory server by retrieving IPNS records; S4. Configure the IPFS node address and IPNS record for the client. After connecting to the specified IPFS node, the client obtains the directory file of the directory server through the IPNS record.

[0026] In specific applications, this implementation requires hiding the obfuscated network directory server, which can be simply referred to as the directory server. In addition to the directory server, this implementation also involves the IPFS network and clients. The directory server is responsible for collecting, aggregating, and publishing directory files on the obfuscated network, which contain the relevant directory information required by the client. The IPFS network, composed of multiple IPFS nodes, is responsible for storing and synchronizing directory files. Clients access directory files through the IPFS network to support subsequent business applications.

[0027] IPFS (InterPlanetary File System) is a peer-to-peer distributed file system technology that transforms how information is distributed and stored on the internet. It combines distributed hash tables, an incentive layer, a Merkle DAG tree data structure, version control, and self-certified naming to create a unique file storage and sharing system. This implementation utilizes this technology, with adaptive improvements, for the hidden task of obfuscating network directory servers.

[0028] In general, the method of this embodiment first constructs a hidden network of directory servers based on IPFS nodes. The hidden network is an IPFS network composed of multiple IPFS nodes. In addition, the directory server also has corresponding IPFS components, making it Figures 5 to 7 In the specific process, it can also be considered an IPFS node, thereby being able to connect with other IPFS nodes to achieve data communication interaction. In this embodiment, the IPFS network acts as an intermediate proxy layer connecting the client and the directory server. By utilizing the distributed and decentralized characteristics of the IPFS network, the purpose of decentralized storage of directory files on the directory server can be achieved; by utilizing the P2P characteristics of the IPFS network, the client can indirectly access the directory server by accessing the IPFS node, thereby achieving the hiding of directory server IP address, port and other information from the client.

[0029] Therefore, based on the constructed IPFS network, the directory server first generates a directory file from the collected and aggregated obfuscated network directory information, then adds the directory file to the IPFS network and generates an access code. Finally, the directory file is published to generate an IPNS record. The IPNS record itself is a naming system in IPFS technology that allows users to create a mutable and readable name to point to content in IPFS. The IPNS record can be thought of as a fixed but mutable reference that can point to any IPFS hash. Even if the underlying IPFS content changes, as long as the IPNS record is updated to point to the new hash, users can still access the latest content through the same IPNS address. This provides a mechanism for maintaining persistent references to dynamic content while preserving the security and integrity of content addressing.

[0030] In this implementation, IPFS nodes periodically synchronize directory files from the IPFS network based on the initially configured IPNS records. During this period, the relevant IPFS nodes can retrieve IPNS records through the distributed hash table (DHT). Finally, the client connects to the designated IPFS node based on the configured IPFS node address and IPNS record and retrieves the directory files from the directory server through the IPNS record.

[0031] Since the topology of the obfuscated network itself is constantly changing during the application process, the directory server will periodically generate directory files for the obfuscated network. When the directory server publishes a new directory file, the IPFS node may cache the previous obfuscated network directory file. Therefore, in order to ensure that the directory file obtained by the client is always the latest version updated in real time, the IPFS node also periodically synchronizes the IPNS record of the directory server to obtain the latest directory file, thereby ensuring that the directory file obtained by the client is also real-time and up-to-date.

[0032] This embodiment will now provide a detailed description of each step in the method. Figure 4 As shown, in step S1, each IPFS node has a corresponding built-in IPFS component, and the connection between each IPFS node is achieved through the connection of each IPFS component; the directory server of the obfuscated network also has a corresponding built-in IPFS component, and the directory server is connected to the IPFS node through its built-in IPFS component. The IPFS component of the directory server is used to publish and transmit directory files to the IPFS network.

[0033] The topological connection structure composed of the IPFS network and the directory server meets the following constraints: there is at least one IPFS node in the IPFS network that is connected to the directory server, and the remaining IPFS nodes are connected to each other by building a connectivity graph, which enables the remaining IPFS nodes to indirectly access the directory server when accessing the IPFS network.

[0034] exist Figure 4 In the topology shown, node C is directly connected to the obfuscated network directory server, and their IPFS connection is implemented based on their respective IPFS components; nodes B and D are both connected to node C, and node A is connected to node B. Although nodes A, B, and D are not directly connected to the directory server, they can obtain the directory server's address through addressing to communicate.

[0035] The client only needs to connect to node A to obtain the directory files published by the directory server, that is, configure the client to be able to access the address of any IPFS node in the IPFS network, so that the client can access the IPFS network; based on the topological connection relationship between the IPFS network and the directory server, any IPFS node configured by the client can access the directory server and transmit the obtained directory files to the client.

[0036] As a preferred embodiment of this embodiment, during the construction or use phase of the IPFS network, the expansion of the IPFS network is carried out by adding new IPFS nodes. When a new IPFS node needs to be added, any existing IPFS node in the IPFS network is configured as a boot node. The boot node only needs to be directly or indirectly connected to the directory server. The expansion of the IPFS network is achieved by connecting the newly added IPFS node to the boot node. Therefore, the expansion process of the IPFS network node is more flexible than the expansion configuration of the related proxy server in the prior art.

[0037] Since the directory server itself has built-in IPFS components, it can be regarded as an IPFS node to implement related functions, which is reflected in Figure 5 and subsequent flow charts. Figure 5 As shown in Figure 2, in step S2, the directory server publishes the directory file to the IPFS network, specifically: First, the obfuscated nodes in the obfuscated network report status information to the directory server. The directory server collects and summarizes the status information of the obfuscated network and generates a corresponding directory file. The summarized status information can include relevant data information such as traffic sending and receiving rates, CPU usage, and memory usage.

[0038] The directory server then uses its built-in IPFS component to add the directory file using the add command, adding the directory file to the IPFS network for separate storage and generating an access code corresponding to the directory file. The IPFS network can store the directory file directly on one or more pre-set IPFS nodes, or in a completely independent storage device belonging to the network, allowing the directory file to be retrieved and called with the access code. After the storage generation is completed, the directory server uses the publish command to bind the directory file access code to its IPFS component, which will generate the corresponding IPNS record and publish it to the IPFS network.

[0039] In this implementation, when a directory server binds a directory file access code to its IPFS component, it pre-generates an IPNS record bound to the directory file access code and then publishes the IPNS record to the IPFS network. During communication, as directory files are continuously updated, the binding relationship between the directory file access code and its bound IPNS record remains unchanged. When a client accesses any IPFS node in the IPFS network, it retrieves the directory file by retrieving the corresponding IPNS record through that IPFS node.

[0040] like Figure 6As shown, in step S3, when any IPFS node needs to synchronously obtain the directory file published by the directory server, the IPNS record generated by the directory server is pre-configured for all IPFS nodes in the IPFS network.

[0041] IPNS records can usually be configured on the IPFS node connected to the directory server, for example Figure 4 Node C in the IPFS network; If no IPNS record is configured on any IPFS node in the IPFS network, when an IPFS node requests to resolve the IPNS record, it can press Figure 6 As shown in the figure, the request is made step by step until the IPFS component of the directory server is queried. At this time, the directory server is also regarded as an IPFS node.

[0042] When an IPFS node is configured with an IPNS record, that is, an IPNS record is manually specified in the configuration file, the mapping between the IPNS record and the access code can only be obtained and saved when the node actively requests the IPNS record from the IPFS network. When the directory server publishes the directory file and generates the corresponding IPNS record, it will publish the record to the IPFS network, but other IPFS nodes need to obtain the record from the network through queries. Because directory files may change in real time, IPFS nodes will periodically request IPNS records from the IPFS network to update the access code corresponding to the IPNS record, thereby ensuring that the directory file is obtained synchronously based on the latest access code.

[0043] Therefore, the IPFS node that needs to synchronously obtain the directory file decides whether to obtain the access code of the directory file corresponding to the IPNS record from the other IPFS nodes that have cached the IPNS record through a query request based on whether it has cached the corresponding IPNS record, and then realizes the synchronous acquisition of the corresponding directory file based on the obtained access code.

[0044] In this embodiment, specifically, if the IPFS node that needs to synchronously obtain the directory file has cached the corresponding IPNS record, the IPFS record is directly parsed to obtain the access code of the corresponding directory file; if the IPFS node does not cache the corresponding IPNS record, the IPFS distributed hash table DHT is used to search for the IPFS node that has cached the IPNS record in the IPFS network, and the access code of the directory file corresponding to the IPNS record is obtained from it.

[0045] After obtaining the access code, the principle of obtaining the corresponding directory file based on the access code is similar to obtaining IPNS records. It depends on the storage location of the directory file. It may be stored on an IPFS node in the IPFS network, stored in an independent storage of the IPFS network, or even not sent and stored on the IPFS network. In this case, it is necessary to access the IPFS component corresponding to the directory server and treat the directory server as an IPFS node for processing. Based on the access code, the IPFS network is requested to access the corresponding stored directory file. The IPFS network obtains the directory file based on the access code and returns it to the corresponding IPFS node, thus achieving synchronous acquisition of the directory file by the IPFS node.

[0046] Finally, in step S4, Figure 7 As shown, to obtain the directory files on the obfuscated network, the client directly connects to one or more IPFS nodes. The IPFS nodes connected to the client then use step S3 to obtain the required directory files. Once the client connects to any designated IPFS node, it must first configure the IPFS node address and the IPNS record corresponding to the required directory files. The client then sends a file request containing the IPNS record to the connected IPFS node. This file request can be in the form of an HTTP request.

[0047] After receiving the file request from the client, the IPFS node extracts the corresponding IPNS record configuration and checks whether it has the relevant cache. If not, it searches for the required IPNS record according to step S3, and finally parses it to obtain the access code. It then obtains the corresponding directory file based on the access code and returns it to the client.

[0048] In this process of this embodiment, since the directory file can be stored in the storage of any one or more IPFS nodes in the IPFS network, when an IPFS node receives a file request from a client, after confirming that the IPNS record and access code are correct, it can first search whether it has stored the directory file corresponding to the IPNS record. If so, it will directly return the directory file to the client; if it has not stored it, it will search and obtain the directory file corresponding to the IPNS record in the IPFS network according to the client's IPNS record configuration, and then return the directory file to the client, realizing the process of the client obtaining the required directory file from the directory server.

[0049] The obfuscated network directory server hiding method of this embodiment can be applied to a corresponding computer system, which includes a memory, a processor and a computer program stored in the memory; when the processor executes the computer program, the steps of the aforementioned obfuscated network directory server hiding method are implemented.

[0050] These computer programs or instructions in this embodiment can be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that can implement the functions specified by one or more steps in the method.

Claims

1. A method for hiding an obfuscated network directory server for a client, characterized in that: The steps include: S1. Based on IPFS technology, a hidden network corresponding to the directory server of the obfuscated network is constructed. The hidden network is an IPFS network composed of multiple IPFS nodes. S2. Use the IPFS network as an intermediate proxy layer to connect the client and the directory server, and the directory server publishes the directory file to the IPFS network; S3. IPFS nodes in the IPFS network periodically synchronize directory files published by the directory server by retrieving IPNS records; S4. Configure the IPFS node address and IPNS record for the client. After connecting to the specified IPFS node, the client obtains the directory file of the directory server through the IPNS record.

2. The method for hiding an obfuscated network directory server according to claim 1, wherein: In step S1, each IPFS node has a built-in IPFS component, and the connection between each IPFS node is achieved through the connection of each IPFS component; the directory server of the obfuscated network also has a built-in IPFS component, and the directory server is connected to the IPFS node through its built-in IPFS component. The IPFS component of the directory server is used to publish and transmit directory files to the IPFS network; The topological connection structure composed of the IPFS network and the directory server meets the following constraints: there is at least one IPFS node in the IPFS network that is connected to the directory server, and the remaining IPFS nodes are connected to each other by building a connectivity graph; Configure the client to be able to access the address of any IPFS node in the IPFS network, so that the client can access the IPFS network; Based on the topological connection relationship between the IPFS network and the directory server, any IPFS node configured by the client can access the directory server and transfer the obtained directory files to the client.

3. The method for hiding an obfuscated network directory server according to claim 2, characterized in that: During the construction or use phase of the IPFS network, the expansion of the IPFS network is carried out by adding new IPFS nodes. When a new IPFS node needs to be added, any existing IPFS node in the IPFS network is configured as a boot node. The boot node only needs to be directly or indirectly connected to the directory server. The expansion of the IPFS network is achieved by connecting the newly added IPFS node to the boot node.

4. The method for hiding an obfuscated network directory server according to claim 1, wherein: In step S2, the directory server publishes the directory file to the IPFS network, specifically: First, the obfuscation nodes in the obfuscation network report their status information to the directory server. The directory server collects and aggregates the status information of the obfuscation network and generates the corresponding directory file. The directory server then uses the add command on the directory file through its built-in IPFS component to add the directory file to the IPFS network for separate storage and generate an access code corresponding to the directory file. It then uses the publish command to bind the directory file access code to its IPFS component and publish it to the IPFS network.

5. The method for hiding an obfuscated network directory server according to claim 4, characterized in that: When the directory server binds the directory file access code to its IPFS component, it pre-generates the IPNS record bound to the directory file access code and publishes the IPNS record to the IPFS network; during the communication interaction process, as the directory file is continuously updated, the binding relationship between the directory file access code and its bound IPNS record remains unchanged; when the client accesses any IPFS node in the IPFS network, it retrieves the corresponding IPNS record through the IPFS node to obtain the directory file.

6. The method for hiding an obfuscated network directory server according to claim 5, characterized in that: In step S3, when any IPFS node needs to synchronously obtain the directory file published by the directory server, the IPNS record generated by the directory server is pre-configured for all IPFS nodes in the IPFS network; The IPFS node that needs to synchronously obtain the directory file decides whether to obtain the access code of the directory file corresponding to the IPNS record from other IPFS nodes that have cached the IPNS record through a query request based on whether it has cached the corresponding IPNS record, and then realizes the synchronous acquisition of the corresponding directory file based on the obtained access code.

7. The method for hiding an obfuscated network directory server according to claim 6, characterized in that: If the IPFS node that needs to synchronously obtain the directory file has cached the corresponding IPNS record, then directly parse the IPNS record and obtain the access code of the corresponding directory file; if the IPFS node does not cache the corresponding IPNS record, then use the IPFS distributed hash table DHT to search for the IPFS node that has cached the IPNS record in the IPFS network, and obtain the access code of the directory file corresponding to the IPNS record from it.

8. The method for hiding an obfuscated network directory server according to claim 6, wherein: After the IPFS node obtains the access code, it requests the IPFS network to access the corresponding stored directory file based on the access code. The IPFS network obtains the directory file based on the access code and returns it to the corresponding IPFS node, realizing the synchronous acquisition of the directory file by the IPFS node.

9. The method for hiding an obfuscated network directory server according to claim 6, wherein: In step S4, the process of the client obtaining the directory file through the IPNS record is as follows: after the client is connected to any specified IPFS node, it completes the configuration of the IPFS node address and the configuration of the IPNS record corresponding to the required directory file; the client sends a file request containing the IPNS record to the connected IPFS node. After receiving the file request from the client, the IPFS node extracts the corresponding IPNS record configuration, parses it into an access code, obtains the corresponding directory file according to the access code, and returns it to the client.

10. The method for hiding an obfuscated network directory server according to claim 9, characterized in that: Directory files can be stored on the storage of any one or more IPFS nodes in the IPFS network. When an IPFS node receives a file request from a client, it first searches whether it has stored the directory file corresponding to the IPNS record. If so, it directly returns the directory file to the client. If it does not have it stored, it searches and obtains the directory file corresponding to the IPNS record in the IPFS network according to the client's IPNS record configuration, and then returns the directory file to the client, thus realizing the process of the client obtaining the required directory file from the directory server.

Citation Information

Patent Citations

  • Domain name resolution system building and domain name query method

    CN110880966A

  • Privacy information management method and system based on block chain and IPFS technology

    CN112954000A

  • Method for hiding IP address based on named network

    CN114844670A

  • Data acess authenication

    US20190273781A1