A network management method, device, system, storage medium and computer program product
By implementing encrypted firewall functions and obfuscation algorithms in the cloud, enterprises can fully delegate firewall policies to the cloud, solving the problem of weak cloud firewall functionality, improving protection capabilities, and reducing the risk of attacks and data breaches.
Patent Information
- Application Number
- CN202511285988.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-10
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2045-09-10
AI Technical Summary
Cloud firewalls, lacking comprehensive firewall policies, have weaker protective capabilities, increasing the risk of attacks and data breaches for businesses.
By implementing matching and obfuscation algorithms for encrypted firewall functions on the cloud server, enterprises can fully authorize firewall policies to the cloud, use homomorphic encryption obfuscation algorithms to obfuscate firewall rules, and determine target action information on the cloud server to achieve full authorization of firewall functions.
It enhances the protection capabilities of the cloud firewall, reduces the likelihood of enterprise attacks and data breaches, and ensures the security and integrity of enterprise firewall policies.
Smart Images

Figure CN120785655B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a network management method, apparatus, system, storage medium, and computer program product. Background Technology
[0002] To improve security and performance, modern enterprises deploy their own firewalls and perform corresponding maintenance and management. However, the management and maintenance of firewall infrastructure brings huge costs to enterprises, especially small businesses. Therefore, some enterprises often use cloud firewalls to reduce firewall management and deployment costs.
[0003] However, firewall policies are confidential information for enterprises. During the application deployment process, enterprises do not fully authorize the cloud to implement firewall policies. As a result, the cloud firewall cannot play its full role, making its data security protection function weak and leaving the enterprise vulnerable to attacks and data leaks. Summary of the Invention
[0004] To address the aforementioned technical problems, this application aims to provide a network management method, apparatus, system, storage medium, and computer program product. It solves the problem of weak firewall functionality caused by the inability of current cloud firewalls to obtain complete protection policies. The application proposes a method for configuring cloud firewall functions, enabling enterprises to fully authorize firewall policies to the cloud, thereby improving the protection capabilities of cloud firewalls and reducing the likelihood of enterprise attacks and data breaches.
[0005] The technical solution of this application is implemented as follows:
[0006] This application provides a network management method, the method being applied to a first cloud server that provides at least a first network function to a target device, the method comprising:
[0007] If a first data packet with the address of the target address is received, the first firewall matching function corresponding to the first data packet is matched; wherein, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server, and the target address corresponds to the target device;
[0008] The first data packet and the firewall rule identification information corresponding to the first firewall matching function are sent to the second cloud server; wherein, the firewall rule identification information is used to enable the second cloud server to determine the target action information corresponding to the first firewall matching function, and then process the first data packet according to the target action information, and the second cloud server provides at least a second network function to the target device.
[0009] In the above scheme, the step of matching the first firewall matching function corresponding to the first data packet if the first data packet with the address of the target address is received includes:
[0010] If the first data packet is received, determine multiple first rule matching functions corresponding to the target address;
[0011] The first data packet is matched with each of the first rule matching functions to obtain the matching result;
[0012] The first firewall matching function is determined to be the second rule matching function; wherein, the second rule matching function is the rule matching function whose matching result indicates a match among the plurality of first rule matching functions.
[0013] The method in the above scheme further includes:
[0014] The system receives multiple first rule matching functions provided by the target device; wherein the multiple first rule matching functions are obtained by the target device using an obfuscation algorithm to obfuscate the reference firewall of the target device, and are used to achieve the same function as the reference firewall.
[0015] Store the plurality of first rule matching functions.
[0016] In the above scheme, the obfuscation algorithm includes at least a homomorphic encryption obfuscation algorithm.
[0017] This application provides a network management method, which is applied to a second cloud server that provides at least a second network function to a target device, the method comprising:
[0018] The system receives a first data packet sent by a first cloud server and firewall rule identification information corresponding to a first firewall matching function; wherein, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server.
[0019] Based on the firewall rule identification information, the target action information is determined;
[0020] The operation corresponding to the target action information is executed for the first data packet.
[0021] In the above scheme, determining the target action information based on the firewall rule identifier information includes:
[0022] Based on the target address corresponding to the target device, determine the identification and action relationship information;
[0023] From the identifier and action relationship information, determine the target action information corresponding to the firewall rule identifier information.
[0024] The method in the above scheme further includes:
[0025] Receive the identifier and action relationship information sent by the target device; wherein, the identifier and action relationship information is used to record the rule identifier information of the firewall rule and the action information for managing the corresponding data packet;
[0026] Store the information relating the identifier to the action.
[0027] This application provides a first network management device, which is applied to a first cloud server that provides at least a first network function to a target device. The device includes: a matching unit and a sending unit; wherein:
[0028] The matching unit is configured to, if a first data packet with an address corresponding to a target address is received, match the first firewall matching function corresponding to the first data packet; wherein, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server, and the target address corresponds to the target device;
[0029] The sending unit is configured to, if the first firewall matching function exists, send the first data packet and the firewall rule identification information corresponding to the first firewall matching function to the second cloud server; wherein, the firewall rule identification information is used to enable the second cloud server to determine the target action information corresponding to the first firewall matching function, and then process the first data packet according to the target action information, and the second cloud server provides at least a second network function to the target device.
[0030] This application provides a second network management device, which is applied to a second cloud server that provides at least a second network function to a target device. The device includes: a first receiving unit, a determining unit, and an executing unit; wherein:
[0031] The first receiving unit is configured to receive a first data packet sent by the first cloud server and firewall rule identification information corresponding to the first firewall matching function; wherein, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server;
[0032] The determining unit is used to determine target action information based on the rule identification information;
[0033] The execution unit is used to perform the operation corresponding to the target action information in response to the first data packet.
[0034] This application provides a network management system, the system comprising at least: a first cloud server, a second cloud server, and a target device; wherein:
[0035] The target device is used to provide a first firewall matching function to the first cloud server and to provide target action information corresponding to the first firewall matching function to the second cloud server.
[0036] The first cloud server is used to implement the steps in the network management method described in any of the above items;
[0037] The second cloud server is used to implement the steps in the network management method described in any of the above.
[0038] This application provides a storage medium storing a network management program, which, when executed, implements the steps of the network management method as described in any of the preceding claims.
[0039] This application provides a computer program product, including a computer program, characterized in that, when the computer program is executed by a processor, it implements the steps of the network management method as described in any of the preceding claims.
[0040] This application provides a network management method, apparatus, system, storage medium, and computer program product. If a first cloud server receives a first data packet with a target address, it matches the first firewall matching function corresponding to the first data packet, and then sends the first data packet and the firewall rule identification information corresponding to the first firewall matching function to a second cloud server. After receiving the first data packet and the firewall rule identification information corresponding to the first firewall matching function sent by the first cloud server, the second cloud server determines the target action information based on the firewall rule identification information, and performs the operation corresponding to the target action information for the first data packet. In this way, by verifying the first data packet at the first cloud server, the first firewall matching function corresponding to the first data packet is determined. Then, the action information corresponding to the first firewall matching function is determined at the second cloud server. This achieves the goal that neither the first nor the second cloud server needs to know the specific firewall content. However, by matching the first data packet with the first firewall matching function through the first cloud server, and by directly determining the target action information based on the firewall rule identification information without processing the first data packet, the desired firewall function of the target device is realized. This reduces the risk of information leakage or attack due to firewall information leakage, and solves the problem that the current cloud firewall cannot obtain the complete firewall policy, resulting in weak firewall function. This proposes a method for cloud firewall function layout, which enables enterprises to fully authorize firewall policies to the cloud, improves the protection function of cloud firewall, and reduces the possibility of enterprise being attacked and data leakage. Attached Figure Description
[0041] Figure 1 A flowchart illustrating a network management method provided in an embodiment of this application;
[0042] Figure 2 A flowchart illustrating another network management method provided in an embodiment of this application;
[0043] Figure 3 This application provides a schematic diagram of the application scenario architecture for a network management method.
[0044] Figure 4 This is a schematic diagram of the structure of a first network management device provided in an embodiment of this application;
[0045] Figure 5 This is a schematic diagram of the structure of a second network management device provided in an embodiment of this application;
[0046] Figure 6 This is a schematic diagram of the structure of a network management system provided in an embodiment of this application. Detailed Implementation
[0047] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0048] Embodiments of this application provide a network management method, referring to... Figure 1 As shown, the method is applied to a first cloud server that provides at least a first network function to a target device, and the method includes the following steps:
[0049] Step 101: If a first data packet with the target address is received, match the first firewall matching function corresponding to the first data packet.
[0050] Among them, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server, and the target address corresponds to the target device.
[0051] In the embodiments of this application, the first cloud server and the second cloud server may typically belong to different cloud service providers, and the first cloud server and the second cloud server provide different services to the target device.
[0052] The target address can be an Internet Protocol (IP) address assigned to the target device. The target device is typically a user device such as an enterprise server. Enterprise servers implement firewall functionality through cloud servers to reduce the cost of operating and maintaining firewall functionality for the enterprise.
[0053] The first network function is the firewall function, which matches rules and functions. The firewall, as the crucial first line of defense against network attacks, plays a vital role in enterprise networks. It monitors and inspects incoming and outgoing network traffic within the internal network, preventing malicious packets from entering and effectively blocking them at the network's entry point.
[0054] The first data packet can typically be data sent from the Internet to the target device. For example, it can be various business request data used to access the enterprise, such as browsing, data acquisition, or business interaction information data.
[0055] The first firewall matching function is the encrypted firewall function corresponding to the encrypted firewall rule after the target device encrypts the corresponding firewall rule. It should be noted that the encrypted firewall rule does not affect its firewall function and can still achieve the same firewall function. In this way, the target device can completely authorize the first cloud server with the encrypted firewall function. Since the encrypted firewall function is encrypted by the target device, the first cloud server does not know the actual firewall rule. Therefore, there is no need to worry about the risk of the actual firewall rule being leaked on the first cloud server side.
[0056] The first cloud server can be a cloud server device or a virtual cloud server. The specific choice can be determined based on the actual situation, and no specific restrictions are made here.
[0057] For example, one application scenario is as follows: When the first cloud server is connected to the Internet and receives the first data packet sent to the target address by the Internet, it determines that the first data packet is sent to the target device. Here, the first cloud server device uses its firewall function to verify the first data packet and matches whether there is a matching firewall rule in the firewall function provided by the first cloud server for the target device. If there is, the corresponding first firewall matching function can be matched.
[0058] Step 102: Send the first data packet and the firewall rule identification information corresponding to the first firewall matching function to the second cloud server.
[0059] Among them, the firewall rule identification information is used to enable the second cloud server to determine the target action information corresponding to the first firewall matching function, and then process the first data packet according to the target action information. The second cloud server provides at least the second network function to the target device.
[0060] In this embodiment, the firewall rule identifier information is a unique identifier used to represent a firewall rule. For example, it can be the name, number, or sequence number of the firewall rule. After the first cloud server matches the first firewall matching function, it can determine the firewall rule identifier information of the firewall rule corresponding to the first firewall matching function. Thus, the first cloud server can send the received first data packet and the firewall rule identifier information of the corresponding firewall rule to the second cloud server.
[0061] When the first cloud server sends the first data packet and the firewall rule identifier information corresponding to the first firewall matching function, it may send them after packaging the first data packet and the firewall rule identifier information, or it may send them without packaging. When the first cloud server packages the first data packet and the firewall rule identifier information corresponding to the first firewall matching function, it can do so by adding the firewall rule identifier information corresponding to the first firewall matching function to the reserved bytes in the header file of the first data packet, or by using the firewall rule identifier information corresponding to the first firewall matching function to package the first data packet, or by directly packaging the firewall rule identifier information corresponding to the first firewall matching function and the first data packet into a compressed package. It should be noted that the specific method by which the first cloud server sends the first data packet and the firewall rule identifier information corresponding to the first firewall rule matching function can be determined according to the actual situation, and is not specifically limited here.
[0062] The second cloud server processes the first data packet. The specific processing method can be implemented based on the target action information in the firewall rules corresponding to the first data packet. During this process, the second cloud server does not store the specific firewall rules, but only the action information included in different firewall rules. Thus, after obtaining the firewall rule identifier information, the second cloud server can retrieve the corresponding target action information based on the firewall rule identifier information and perform the operation corresponding to the target action information on the first data packet. Alternatively, in some application scenarios, after receiving the firewall rule identifier information, the second cloud server can send the firewall rule identifier information to the target device so that the target device can provide the corresponding target action information. The second cloud server can then perform the operation on the first data packet based on the target action information fed back by the target device. For example, if the target action information indicates that the data packet should be discarded, the second cloud server will discard the first data packet.
[0063] Based on the foregoing embodiments, in other embodiments of this application, if step 101, which involves receiving a first data packet with the address of the target address, matches the first firewall matching function corresponding to the first data packet, it can be implemented by the following steps:
[0064] If the first data packet is received, determine the multiple first rule matching functions corresponding to the target address;
[0065] The first data packet is matched with each first rule matching function to obtain the matching result;
[0066] The first firewall matching function is determined to be the second rule matching function; wherein, the second rule matching function is the rule matching function whose matching result indicates a match among multiple first rule matching functions.
[0067] In this embodiment of the application, the first cloud server can provide multiple devices with the same firewall matching function matching service as the target device.
[0068] In some application scenarios, after receiving the first data packet, the first cloud server queries and retrieves multiple first rule matching functions based on the target address. For example, the target address can be used as an index to query the corresponding multiple first rule matching functions. In this case, the target address and multiple first rule matching functions are stored in the first cloud server using an index-based storage method, or a keyword-data storage method can be used, where the target address is used as the keyword to retrieve the corresponding data, which consists of multiple first rule matching functions. The number of multiple first rule matching functions can correspond to the total number of firewall rules corresponding to the target address. However, in some application scenarios where the firewall protection function is implemented in a distributed manner, i.e., when the first cloud server is only one of the cloud servers, the multiple first rule matching functions may only correspond to a portion of the firewall rules corresponding to the target address. The specific choice depends on the actual application scenario and is not specifically limited here.
[0069] The matching calculation between the first data packet and each first rule matching function can be implemented using a pre-set matching method. The matching method can take into account the characteristics of the encryption algorithm used to encrypt the rule matching function. The first data packet is matched against multiple first rule matching functions to obtain the matching result for each rule matching function. Based on the multiple matching results, the second rule matching function is determined from among the multiple first rule matching functions.
[0070] Based on the foregoing embodiments, in other embodiments of this application, the first cloud server is further configured to perform the following steps:
[0071] Receive multiple first rule matching functions provided by the target device; wherein, the multiple first rule matching functions are obtained by the target device using an obfuscation algorithm to obfuscate the target device's reference firewall, and are used to achieve the same function as the reference firewall;
[0072] Store multiple first-rule matching functions.
[0073] In this application embodiment, a process is defined for a first cloud server to obtain multiple first rule matching functions. This process is typically configured by the target device for the first cloud server. Specifically, the target device uses an obfuscation encryption algorithm to obfuscate a reference firewall, obtaining an obfuscated firewall rule corresponding to each firewall rule included in the reference firewall. The obfuscated firewall rule includes a first rule matching function. Thus, the target device can send the first rule matching function included in each obfuscated firewall rule to the first cloud server. In this way, the first cloud server can obtain multiple first rule matching functions. In this way, the target device uses the first cloud server to verify the received data packets using the firewall matching function, thereby implementing firewall functionality for the target device on the cloud server.
[0074] After obtaining multiple first rule matching functions from the first cloud server, the first rule matching functions are stored using a preset storage method, such as dictionary database, index storage, or list storage, and an association relationship is established between them and the target address.
[0075] Based on the foregoing embodiments, in other embodiments of this application, the obfuscation algorithm includes at least: a homomorphic encryption obfuscation algorithm.
[0076] In this embodiment, the target device encrypts its configured firewall rules. Homomorphic encryption obfuscation algorithms can be used to achieve this obfuscation. In this way, the obfuscated firewall rules still function as the firewall rules before obfuscation.
[0077] The network management method provided in this application involves a first cloud server receiving a first data packet with a target address. The first cloud server matches the first firewall matching function corresponding to the first data packet and then sends the first data packet and the firewall rule identification information corresponding to the first firewall matching function to a second cloud server. This allows the first cloud server to verify the first data packet and determine the corresponding first firewall matching function, and the second cloud server to determine the action information corresponding to the first firewall matching function. Neither the first nor the second cloud server needs to know the specific firewall content. The first cloud server obtains the first firewall matching function by matching the first data packet, and the second cloud server does not need to process the first data packet. It directly determines the target action information based on the firewall rule identification information, thus achieving the desired firewall function for the target device. This reduces the risk of information leakage or attack due to firewall information leakage and solves the problem of weak firewall functionality caused by the inability of current cloud firewalls to obtain complete firewall policies. This method proposes a cloud firewall function layout method that allows enterprises to fully authorize firewall policies to the cloud, improving the protection function of cloud firewalls and reducing the possibility of enterprise attacks and data leakage.
[0078] Based on the foregoing embodiments, this application provides a network management method, referring to... Figure 2 As shown, the method is applied to a second cloud server that provides at least a second network function to the target device, and the method includes the following steps:
[0079] Step 201: Receive the first data packet sent by the first cloud server and the firewall rule identification information corresponding to the first firewall matching function.
[0080] The first firewall matching function is an encrypted firewall function set by the target device in the first cloud server.
[0081] In this embodiment, the second network function is a firewall protection function that determines the action information in the firewall rules. The second cloud server connects to the target device and can also provide the target device with database services, application services, etc., which can be determined according to the actual situation and are not specifically limited here.
[0082] The first cloud server and the second cloud server can communicate via the Internet.
[0083] When the first cloud server sends the first data packet and the firewall rule identification information corresponding to the first firewall matching function, it may send the first data packet and the firewall rule identification information after packaging them together, or it may send them without packaging. When the first cloud server directly sends the first data packet and the firewall rule identification information corresponding to the first firewall matching function, the second cloud server can directly obtain the first data packet and the firewall rule identification information corresponding to the first firewall matching function. When the first cloud server packages the first data packet and the firewall rule identification information corresponding to the first firewall matching function before sending it, the second cloud server can use a parsing method corresponding to the packaging method of the first cloud server to parse the packaged content and obtain the first data packet and the firewall rule identification information corresponding to the first firewall matching function. The specific method can be determined based on the actual situation and is not specifically limited here.
[0084] Step 202: Determine the target action information based on the firewall rule identification information.
[0085] In this embodiment, the second cloud server obtains the firewall rule identification information sent by the first cloud server, and determines the corresponding target action information for processing the data based on the firewall rule identification information. The target action information may be, for example, operation information such as discarding, forwarding, modifying, or adding, which can be determined according to the actual situation and is not specifically limited here.
[0086] In some application scenarios, the second cloud server can retrieve the corresponding target action information from the local storage unit based on the firewall rule identification information. In other scenarios, the second cloud server can obtain the target action information from a non-local storage unit. One implementation method is for the second cloud server to send a request to the target device and obtain the target action information corresponding to the firewall rule identification information from the target device. The specific implementation depends on the actual situation and is not specifically limited here.
[0087] Step 203: Perform the operation corresponding to the target action information for the first data packet.
[0088] In this embodiment of the application, after the second cloud server determines that it has obtained the target action information, it performs the operation corresponding to the target action information on the first data packet. For example, if the target action information is to discard, the second cloud server performs a discard operation on the first data packet and discards the first data packet. If the target action information is to forward data to the target device, the second cloud server forwards the first data packet to the target device so that the target device can perform data parsing processing on the first data packet.
[0089] Based on the foregoing embodiments, in other embodiments of this application, step 202, which determines the target action information based on firewall rule identification information, can be implemented by the following steps:
[0090] Based on the target address corresponding to the target device, determine the relationship information between the identifier and the action;
[0091] From the relationship information between identifiers and actions, determine the target action information corresponding to the firewall rule identifier information.
[0092] In this embodiment, the identifier and action relationship information is the relationship between action information corresponding to different firewall rule identifier information that is stored in advance. It can be in the form of a list or a database, etc., which can be determined according to the actual situation and is not specifically limited here.
[0093] Determine the identifier and action relationship information corresponding to the target address of the target device. For example, the target address can be used as the keyword to obtain the corresponding data identifier and action relationship information, or the identifier and action relationship information corresponding to the target address can be queried from the list. The specific method can be determined by the storage method when storing the target address, identifier and action relationship information, and no specific limitation is made here.
[0094] After the second cloud server determines the relationship information between the identifier and the action, it queries the action information corresponding to the firewall rule identifier information from the relationship information to obtain the target action information.
[0095] Based on the foregoing embodiments, in other embodiments of this application, the second cloud server can also be used to perform the following steps:
[0096] Receive the identification and action relationship information sent by the target device; wherein, the identification and action relationship information is used to record the rule identification information of the firewall rules and the action information for managing the corresponding data packets;
[0097] Store information about the relationship between identifiers and actions.
[0098] In this embodiment, one implementation process for the second cloud server to obtain the identification information and action relationship information is as follows: After the target device obtains obfuscated firewall rules through obfuscation processing, it determines the rule identification information and corresponding action information of each firewall rule from the obfuscated firewall rules. Based on the obtained correspondence between the rule identification information and action information, it generates identification and action relationship information including the rule identification information and action information. After obtaining the identification and action relationship information, the second cloud server stores the identification and action relationship information using a preset storage method. For example, the identification and action information can be stored in a local storage unit or a cloud storage unit accessible to the second cloud server. The specific method can be determined according to the actual situation and is not specifically limited here.
[0099] It should be noted that when the steps or terms in this embodiment are the same as those in the foregoing embodiments, the explanations and descriptions in the foregoing embodiments can be referred to, and will not be repeated in detail here.
[0100] The network management method provided in this embodiment receives a first data packet sent by a first cloud server and firewall rule identification information corresponding to a first firewall matching function from a second cloud server. Based on the firewall rule identification information, it determines the target action information and executes the operation corresponding to the target action information on the first data packet. In this way, by verifying the first data packet at the first cloud server to determine the corresponding first firewall matching function, and then determining the action information corresponding to the first firewall matching function at the second cloud server, neither the first nor the second cloud server needs to know the specific firewall content. However, by matching the first data packet with the first firewall matching function at the first cloud server, and by directly determining the target action information based on the firewall rule identification information without processing the first data packet, the desired firewall function of the target device is achieved. This reduces the risk of information leakage or attack due to firewall information leakage, and solves the problem of weak firewall functionality caused by the inability of current cloud firewalls to obtain complete firewall policies. This method proposes a cloud firewall function layout method, enabling enterprises to fully authorize firewall policies to the cloud, improving the protection function of cloud firewalls, and reducing the possibility of enterprise attacks and data leakage.
[0101] Based on the foregoing embodiments, this application provides a schematic diagram of an application scenario architecture for a network method, referring to... Figure 3 As shown, it includes an external site, cloud server A, and cloud server B. The external site corresponds to the aforementioned Internet, and cloud server B is used to provide enterprise data services and network function services. Figure 3In the context of cloud service provider B, "Enterprise" refers to an enterprise that outsources its infrastructure to cloud service provider B. For privacy and security reasons, it also outsources network functions such as firewalls, load balancing, and network address translation to cloud service provider B. In other words, the enterprise uses Infrastructure as a Service (IaaS) to outsource most of its Information Technology (IT) infrastructure, such as database servers and application servers, to cloud service provider B, while splitting network function services into two parts and outsourcing them to cloud service provider A and cloud service provider B respectively. Cloud service provider A is provided by cloud service provider A, while cloud service provider B is a different cloud service provider than cloud service provider A. Cloud service providers A and B cooperate to provide network function services to the enterprise. All data packets destined for the enterprise must first pass through cloud service provider A and then through cloud service provider B. This process ensures that data packets are protected by cloud service providers A and B before reaching the enterprise's network. The specific data flow can be found in [reference needed]. Figure 3 The solid arrows in the diagram indicate the path, while the dashed arrows indicate the path used to represent the data flow from enterprise data output to the internet. Based on Figure 3 The application scenario architecture diagram shown generally consists of three steps in its implementation process: obfuscation, matching, and action. The following steps can be referenced:
[0102] Step a11, the obfuscation stage.
[0103] Enterprise administrators build an obfuscator for the enterprise's desired firewall f. Specifically, the obfuscator can be a cryptographic obfuscator O, used to transform a program P into another new program P'. Thus, a semantically equivalent secure firewall f' is constructed using obfuscator O, making f' have the same functionality as f, but the original f cannot be recovered from f'. This solves the privacy protection firewall problem in cloud-based environments.
[0104] For example, an encryption obfuscation process using the EIGamal homomorphic encryption method can be implemented as follows: Set the basic encryption parameters of the EIGamal cryptosystem, with the public key being pk and the private key being sk. The modulus is N, and... (m) represents encrypting the matching function m in firewall rule r=(m,a) using the public key pk. For example, it can be written as: (m)= Where 'a' represents action information. For a given firewall rule... ,for The i-th bit n] can be generated into two pairs of codes according to the following formulas (1) and (2):
[0105] (1)
[0106] (2)
[0107] In equations (1) and (2), r i,0 r i,1 ∈Zn* are all obtained by random and uniform selection; b=m(i), 1-b. If b equals *, then E pk (b)=E pk ( )=E pk (0).
[0108] To complete the fuzzification, it is also necessary to randomly select r(n+1)∈Z. N * This produces an additional pair of codes as shown in formula (3):
[0109] (3)
[0110] Thus, the obfuscated firewall policies are obtained, and each policy can be represented as shown in formula (4):
[0111] (4)
[0112] The target device uses the matching function within it. Send to cloud server A, Send to cloud server B.
[0113] Step a12, Matching Phase.
[0114] Cloud server A received Afterwards, they began providing firewall services to enterprises. For each received packet... The cloud server A checks the packet data x. One specific implementation method can be achieved by calculating using the following two formulas (5) and (6):
[0115] (5)
[0116] (6)
[0117] In the formula, Let x be the content of the i-th bit in the packet. If the LHS and RHS calculated by the packet x and a certain matching function u are equal, then x and the matching function u are a match. The matching function u is a certain... At this point, the cloud server can determine the firewall policy number corresponding to the matching function u, and then determine that the firewall policy number corresponding to the matching function u is the identification information of the firewall rule corresponding to the packet x. In this way, cloud server A can send the packet x together with the firewall policy number matched by packet x to cloud server B.
[0118] Step a13, Action Phase.
[0119] When cloud server B receives packet x and the firewall policy number matching packet x from cloud server A, cloud server B looks up the action function table according to the firewall policy number matching packet x, obtains the corresponding action function a from the action function table, then uses action function a to determine the action information a(x) corresponding to packet x, and finally cloud server B uses action information a(x) for processing.
[0120] In this way, cloud server A only knows which rule the data packet matches, but not the rule or the corresponding action. Cloud server B processes the data packet based solely on the corresponding action information, without checking the packet header. Therefore, it knows nothing about the firewall rules except for the action, ensuring the security of enterprise privacy. This dual-cloud model allows sensitive data to be stored in a private cloud deployment while leveraging the flexibility and resources of the public cloud. Furthermore, it allows for the rational allocation of resources according to actual needs, minimizing costs. Moreover, it allows for migration to another vendor if one provider encounters problems, reducing enterprise risk. Simultaneously, the EIGamal cryptographic system is used to obfuscate the firewall. This obfuscated firewall is then outsourced to the cloud server, preventing the cloud server from reverting to the original firewall policy from the obfuscated one, yet still enabling it to provide firewall services to the enterprise based on the obfuscated firewall, effectively guaranteeing enterprise privacy security.
[0121] Based on the foregoing embodiments, embodiments of this application provide a first network management device, which can be applied to... Figure 1 In the network management method provided in the corresponding embodiment, the device is applied to a first cloud server that provides at least a first network function to the target device, referring to... Figure 4 As shown, the first network management device 2 may include: a matching unit 21 and a sending unit 22; wherein:
[0122] The matching unit 21 is used to match the first firewall matching function corresponding to the first data packet if a first data packet with the address of the target address is received; wherein, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server, and the target address corresponds to the target device;
[0123] The sending unit 22 is used to send a first data packet and firewall rule identification information corresponding to the first firewall matching function to the second cloud server if a first firewall matching function exists; wherein, the firewall rule identification information is used to enable the second cloud server to determine the target action information corresponding to the first firewall matching function, and then process the first data packet according to the target action information, and the second cloud server provides at least a second network function to the target device.
[0124] In other embodiments of this application, the matching unit is specifically used to implement the following steps:
[0125] If the first data packet is received, determine the multiple first rule matching functions corresponding to the target address;
[0126] The first data packet is matched with each first rule matching function to obtain the matching result;
[0127] The first firewall matching function is determined to be the second rule matching function; wherein, the second rule matching function is the rule matching function whose matching result indicates a match among multiple first rule matching functions.
[0128] In other embodiments of this application, the first network management device further includes: a second receiving unit and a first storage unit; wherein:
[0129] The second receiving unit is used to receive multiple first rule matching functions provided by the target device; wherein, the multiple first rule matching functions are obtained by the target device using an obfuscation algorithm to obfuscate the target device's reference firewall, and are used to achieve the same function as the reference firewall;
[0130] The first storage unit is used to store multiple first rule matching functions.
[0131] In other embodiments of this application, the obfuscation algorithm includes at least a homomorphic encryption obfuscation algorithm.
[0132] It should be noted that the process of information interaction between units and modules in this embodiment can be referred to the description in other embodiments, and will not be repeated here.
[0133] The first network management device provided in this application embodiment, when a first cloud server receives a first data packet with a target address, matches the first firewall matching function corresponding to the first data packet, and then sends the first data packet and the firewall rule identification information corresponding to the first firewall matching function to a second cloud server. In this way, by verifying the first data packet at the first cloud server to determine the first firewall matching function corresponding to the first data packet, and then determining the action information corresponding to the first firewall matching function at the second cloud server, neither the first nor the second cloud server needs to know the specific firewall content. However, by matching the first data packet to obtain the first firewall matching function, and without processing the first data packet, the second cloud server directly determines the target action information based on the firewall rule identification information, thus realizing the desired firewall function of the target device. This reduces the risk of information leakage or attack due to firewall information leakage, and solves the problem that current cloud firewalls cannot obtain complete firewall policies, resulting in weak firewall functionality. This proposes a method for cloud firewall function layout, enabling enterprises to fully authorize firewall policies to the cloud, improving the protection function of cloud firewalls, and reducing the possibility of enterprise attacks and data leakage.
[0134] Based on the foregoing embodiments, this application provides a second network management device, which can be applied to... Figure 2 In the network management method provided in the corresponding embodiments, the device is applied to a second cloud server that provides at least a second network function to the target device, referring to... Figure 5 As shown, the second network management device 3 includes at least: a first receiving unit 31, a determining unit 32, and an execution unit 33; wherein:
[0135] The first receiving unit 31 is used to receive the first data packet sent by the first cloud server and the firewall rule identification information corresponding to the first firewall matching function; wherein, the first firewall matching function is an encrypted firewall function set by the target device in the first cloud server;
[0136] The determining unit 32 is used to determine the target action information based on the rule identification information;
[0137] The execution unit 33 is used to perform the operation corresponding to the target action information for the first data packet.
[0138] In other embodiments of this application, the determining unit is specifically used to implement the following steps:
[0139] Based on the target address corresponding to the target device, determine the relationship information between the identifier and the action;
[0140] From the relationship information between identifiers and actions, determine the target action information corresponding to the firewall rule identifier information.
[0141] In other embodiments of this application, the second network management device further includes: a second storage unit; wherein:
[0142] The first receiving unit is also used to receive identification and action relationship information sent by the target device; wherein, the identification and action relationship information is used to record the rule identification information of the firewall rules and the action information for managing the corresponding data packets;
[0143] The second storage unit is used to store information about the relationship between the identifier and the action.
[0144] It should be noted that the process of information interaction between units and modules in this embodiment can be referred to the description in other embodiments, and will not be repeated here.
[0145] The second network management device provided in this embodiment receives the first data packet sent by the first cloud server and the firewall rule identification information corresponding to the first firewall matching function through the second cloud server. Based on the firewall rule identification information, it determines the target action information and executes the operation corresponding to the target action information for the first data packet. In this way, by verifying the first data packet at the first cloud server to determine the first firewall matching function corresponding to the first data packet, and then determining the action information corresponding to the first firewall matching function at the second cloud server, neither the first nor the second cloud server needs to know the specific firewall content. However, by matching the first data packet with the first firewall matching function through the first cloud server, and by directly determining the target action information based on the firewall rule identification information without processing the first data packet, the desired firewall function of the target device is achieved. This reduces the risk of information leakage or attack due to firewall information leakage, and solves the problem of weak firewall functionality caused by the inability of current cloud firewalls to obtain complete firewall policies. This proposes a method for cloud firewall function layout, enabling enterprises to fully authorize firewall policies to the cloud, improving the protection function of cloud firewalls, and reducing the possibility of enterprise attacks and data leakage.
[0146] Based on the foregoing embodiments, embodiments of this application provide a network management system, referring to... Figure 6 As shown, the network management system 4 may include at least: a first cloud server 41, a second cloud server 42, and a target device 43; wherein:
[0147] Target device 43 is used to provide the first firewall matching function to the first cloud server and to provide the target action information corresponding to the first firewall matching function to the second cloud server.
[0148] The first cloud server 41 is used to implement, for example... Figure 1 The implementation process of the network management method provided in the corresponding embodiments will not be elaborated here;
[0149] The second cloud server 42 is used to implement, for example... Figure 2 The implementation process of the network management method provided in the corresponding embodiments will not be described in detail here.
[0150] Based on the foregoing embodiments, embodiments of this application provide a computer-readable storage medium, simply referred to as a storage medium, which stores one or more programs that can be executed by one or more processors to implement the reference. Figure 1 or Figure 2 The implementation process of the network management method provided in the corresponding embodiments will not be described in detail here.
[0151] Based on the foregoing embodiments, this application also provides a computer program product, including a computer program that can be executed by the processor of the first cloud server 41 or the processor of the second cloud server 42 to complete any of the foregoing method steps.
[0152] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of hardware embodiments, software embodiments, or embodiments combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0153] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0154] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0155] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0156] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.
Claims
1. A network management method, characterized in that, The method is applied to a first cloud server that provides at least a first network function to a target device, and the method includes: If a first data packet with the address of the target address is received, the first firewall matching function corresponding to the first data packet is matched; wherein, the first firewall matching function is the encrypted firewall function corresponding to the firewall rule obtained by the target device after encrypting the corresponding firewall rule, the target address corresponds to the target device, and the first network function is the firewall function corresponding to the first firewall matching function; The first data packet and the firewall rule identification information corresponding to the first firewall matching function are sent to the second cloud server; wherein, the firewall rule identification information is used to enable the second cloud server to determine the target action information corresponding to the first firewall matching function, and then process the first data packet according to the target action information; the second cloud server provides at least a second network function to the target device, and the second network function is a firewall protection function that determines the action information in the firewall rule and executes it.
2. The method according to claim 1, characterized in that, The step of matching the first firewall matching function corresponding to the first data packet if the address of the first data packet to the target address is received includes: If the first data packet is received, determine multiple first rule matching functions corresponding to the target address; The first data packet is matched with each of the first rule matching functions to obtain the matching result; The first firewall matching function is determined to be the second rule matching function; wherein, the second rule matching function is the rule matching function whose matching result indicates a match among the plurality of first rule matching functions.
3. The method according to claim 1, characterized in that, The method further includes: The system receives multiple first rule matching functions provided by the target device; wherein the multiple first rule matching functions are obtained by the target device using an obfuscation algorithm to obfuscate the reference firewall of the target device, and are used to achieve the same function as the reference firewall. Store the plurality of first rule matching functions.
4. The method according to claim 3, characterized in that, The obfuscation algorithm includes at least the following: homomorphic encryption obfuscation algorithm.
5. A network management method, characterized in that, The method is applied to a second cloud server that provides at least a second network function to a target device, and the method includes: The system receives a first data packet sent by a first cloud server and firewall rule identification information corresponding to a first firewall matching function; wherein, the first firewall matching function is an encrypted firewall function corresponding to the firewall rule obtained by the target device after encrypting the corresponding firewall rule; and the second network function is a firewall protection function that determines the action information in the firewall rule and executes it. Based on the firewall rule identification information, the target action information is determined; The operation corresponding to the target action information is executed for the first data packet.
6. The method according to claim 5, characterized in that, The determination of target action information based on the firewall rule identification information includes: Based on the target address corresponding to the target device, determine the identification and action relationship information; From the identifier and action relationship information, determine the target action information corresponding to the firewall rule identifier information.
7. The method according to claim 5 or 6, characterized in that, The method further includes: Receive the identifier and action relationship information sent by the target device; wherein, the identifier and action relationship information is used to record the rule identifier information of the firewall rule and the action information for managing the corresponding data packet; Store the information relating the identifier to the action.
8. A first network management device, characterized in that, The apparatus is used in a first cloud server that provides at least a first network function to a target device, and the apparatus includes: a matching unit and a sending unit; wherein: The matching unit is used to match the first firewall matching function corresponding to the first data packet if a first data packet with the address of the target address is received; wherein, the first firewall matching function is the encrypted firewall function corresponding to the firewall rule obtained by the target device after encrypting the corresponding firewall rule; the target address corresponds to the target device; and the first network function is the firewall function corresponding to the first firewall matching function. The sending unit is configured to, if the first firewall matching function exists, send the first data packet and the firewall rule identification information corresponding to the first firewall matching function to the second cloud server; wherein, the firewall rule identification information is used to enable the second cloud server to determine the target action information corresponding to the first firewall matching function, and then process the first data packet according to the target action information; the second cloud server provides at least a second network function to the target device, and the second network function is a firewall protection function that determines the action information in the firewall rule and executes it.
9. A second network management device, characterized in that, The apparatus is used in a second cloud server that provides at least a second network function to a target device, and the apparatus includes: a first receiving unit, a determining unit, and an executing unit; wherein: The first receiving unit is used to receive a first data packet sent by the first cloud server and firewall rule identification information corresponding to the first firewall matching function; wherein, the first firewall matching function is an encrypted firewall function corresponding to the firewall rule obtained by the target device after encrypting the corresponding firewall rule, and the second network function is a firewall protection function that determines the action information in the firewall rule and executes it. The determining unit is used to determine target action information based on the rule identification information; The execution unit is used to perform the operation corresponding to the target action information in response to the first data packet.
10. A network management system, characterized in that, The system includes at least: a first cloud server, a second cloud server, and a target device; wherein: The target device is used to provide a first firewall matching function to the first cloud server and to provide target action information corresponding to the first firewall matching function to the second cloud server. The first cloud server is used to implement the steps in the network management method as described in any one of claims 1 to 4; The second cloud server is used to implement the steps in the network management method as described in any one of claims 5 to 7.
11. A storage medium, characterized in that, The storage medium stores a network management program, which, when executed, implements the steps of the network management method as described in any one of claims 1 to 4, or claims 5 to 7.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the network management method as described in any one of claims 1 to 4, or claims 5 to 7.
Citation Information
Patent Citations
Firewall strategy control method and device, electronic equipment and storage medium
CN111835794A
Information forwarding method, forwarding node and storage medium
CN119363414A