NAT detection method between network nodes, apparatus, device and storage medium

A method and device for NAT detection between network nodes that operate independently of key management protocols, enhancing security by simplifying NAT detection and preventing DoS attacks, while maintaining key management integrity.

JP7774353B2Active Publication Date: 2025-11-21CHINA IWNCOMM
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024540657
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-01-05
Filing Date
2022-12-09
Publication Date
2025-11-21
Estimated Expiration
2042-12-09

AI Technical Summary

Technical Problem

The tight coupling between NAT detection and key management protocols in IPsec makes it difficult to extend key management functions and creates security vulnerabilities.

Method used

A method and device for NAT detection between network nodes that operate independently of key management protocols, using IP messages to encapsulate and protect NAT detection requests and responses, allowing for separate and secure determination of NAT presence and location without affecting key management security.

Benefits of technology

This approach simplifies and enhances NAT detection, reducing communication volume, preventing internal address leakage, and protecting against DoS attacks, thereby strengthening network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007774353000003
    Figure 0007774353000003
  • Figure 0007774353000004
    Figure 0007774353000004
  • Figure 0007774353000005
    Figure 0007774353000005
Patent Text Reader

Abstract

The present invention discloses a method, apparatus, device and storage medium for NAT detection between network nodes. The method for NAT detection between network nodes includes the steps of: a requesting node acquires first node information, uses the acquired first node information as payload data of a NAT detection request message or payload data of a NAT detection result request message, encapsulates the NAT detection request message or the NAT detection result request message into an IP message, performs a protection process on the encapsulated NAT detection request packet message, and then transmits the IP message to a responding node; and the responding node acquires payload data of the NAT detection request message or the NAT detection result request message after performing a protection removal process on the received NAT detection request packet message, compares the acquired payload data with the corresponding content in the first IP header of the NAT detection request packet message, and determines a NAT detection result according to the comparison result. This solves the problem of the difficulty of expanding the key management function caused by the close coupling between detection and key management protocols between network nodes.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims priority from a Chinese patent application filed with the China Patent Office on January 5, 2022, bearing application number 202210005432.6 and entitled "Method, apparatus, device and storage medium for detecting NAT between network nodes," the entire disclosure of which is incorporated herein by reference.

[0002] [Technical field] The present invention relates to the field of communications technology, and more particularly to a method, apparatus, device and storage medium for detecting NAT between network nodes. [Background technology]

[0003] Since the early days of Internet network design, security was not a major consideration, resulting in significant security risks in network communications. However, as time passed and technology developed, the Internet became ubiquitous in people's lives, exposing security risks that threaten people's property and safety. In response, security communication protocols such as the Internet security protocol IPsec emerged to address the shortcomings of early network designs that did not take security requirements into account. However, because the Internet uses Network Address Translation (NAT), deploying security communication protocols such as IPsec in an environment without knowing whether or not a NAT device is present (the presence or absence of a NAT device determines the security of the communication), requires NAT detection methods to determine how secure communication protocols such as IPsec can ensure communication.

[0004] At present, there is no unified solution for NAT detection in security communication protocols. Key management protocols are generally used for NAT detection. For example, IPsec uses the key management protocol IKE (Internet Key Exchange) for NAT detection. However, NAT detection using IKE has the following drawbacks: Confusion and unclear boundaries surrounding the definition of functions do not help key management protocols to extend key management functions. For example, IPsec uses the "announcement payload" of the key management protocol IKE to perform NAT detection. The "advertisement payload" is part of the key management protocol, and when key management functions are extended (for example, to further enhance key management security), limited support for NAT detection functions poses a risk of exposing internal IP addresses, thereby reducing security. Summary of the Invention [Problem to be solved by the invention]

[0005] This is used to solve the problem of existing technology where, when IPsec uses IKE for NAT detection, NAT detection and the key management protocol are tightly coupled, making it difficult to extend the key management function and creating security loopholes.

[0006] The embodiments of the present invention provide a method, an apparatus, a device, and a storage medium for NAT detection between network nodes to solve the conventional problem that when IPsec uses IKE for NAT detection, a tight coupling between NAT detection and a key management protocol makes it difficult to extend key management functions and causes security vulnerabilities.

[0007] In a first aspect, a NAT detection method between network nodes provided by an embodiment of the present invention includes: a step in which the requesting node acquires first node information and sets the acquired first node information as payload data of a NAT detection request message or payload data of a NAT detection result request message; the request node encapsulating the NAT detection request message or the NAT detection result request message into an IP message, performing protection processing on the encapsulated NAT detection request packet message, and transmitting the encapsulated NAT detection request packet message to a response node; a response node receiving the NAT detection request packet message and performing a protection removal process on the received NAT detection request packet message; the responding node obtaining the NAT detection request message or the NAT detection result request message from the deprotected NAT detection request packet message, comparing payload data in the obtained NAT detection request message or the payload data in the NAT detection result request message with corresponding content in a first IP header of the NAT detection request packet message, and determining a NAT detection result based on the comparison result; a response node, upon acquiring the NAT detection request message from the deprotected NAT detection request packet message, acquires second node information including the IP address of the response node itself and the IP address of the requesting node acquired from the first IP header of the NAT detection request packet message, uses the second node information as payload data of a NAT detection response message, encapsulates the NAT detection response message in an IP message, performs protection processing on the encapsulated NAT detection response packet message, and then transmits it to the requesting node; or, upon acquiring the NAT detection result request message from the deprotected NAT detection request packet message, the response node includes the NAT detection result in a NAT detection result response message, encapsulates the NAT detection result response message in an IP message, performs protection processing on the encapsulated NAT detection response packet message, and then transmits it to the requesting node; a requesting node receiving the NAT detection response packet message and performing a deprotection process, and obtaining a NAT detection result response message from the deprotected NAT detection response packet message, obtaining a NAT detection result from the NAT detection result response message, or obtaining a NAT detection response message from the deprotected NAT detection response packet message, obtaining payload data of the NAT detection response message, and comparing the obtained payload data with corresponding content in a second IP header of the NAT detection response packet message, and determining a NAT detection result based on the comparison result; The first node information includes the requesting node's own IP address and the IP address of the configured responding node.

[0008] Optionally, the first node information further includes a port number of the requesting node itself and a port number of a configured responding node, or the first node information further includes a SID of the requesting node itself and a SID of a configured responding node; The second node information further includes a port number of the responding node itself and a port number of the requesting node obtained from the first IP header of the NAT detection request packet message, or the second node information further includes an SID of the responding node itself and an SID of the requesting node obtained from the first IP header of the NAT detection request packet message.

[0009] Optionally, the step of the requesting node encapsulating the NAT detection request message or the NAT detection result request message into an IP message includes: encapsulating the responding node's own SID and the NAT detection first node information into a first IP header of a NAT detection request packet message; encapsulating the NAT detection request message or the NAT detection result request message in the content of a first message of a NAT detection request packet message; The step of the response node encapsulating the NAT detection response message or the NAT detection result response message into an IP message includes: encapsulating the second node information in a second IP header of a NAT detection response packet message; and encapsulating the NAT detection response message or the NAT detection result response message into the content of a second message of a NAT detection response packet message.

[0010] Optionally, the NAT detection request message, the NAT detection result request message, or the NAT detection response message includes an identifier indicating a message type and length information for analyzing the number of IP addresses; The NAT detection result response message includes an identifier indicating whether or not a NAT exists between the requesting node and the responding node.

[0011] Optionally, the step of performing protection processing on the NAT detection request packet message by the requesting node comprises: a requesting node performing at least one of encryption, data obfuscation, and integrity verification on the NAT detection request packet message; The step of the response node performing a protection removal process on the NAT detection request packet message includes: The responding node responds to the NAT detection request packet message Decryption The method includes performing at least one of the following steps: decryption, data recovery, and integrity verification.

[0012] Optionally, the step of performing protection processing on the NAT detection response packet message by a response node comprises: a responding node performing at least one of encryption, data obfuscation, and integrity verification on the NAT detection response packet message; The step of the request node performing a protection removal process on the NAT detection response packet message includes: The requesting node responds to the NAT detection response packet message by Decryption The method includes performing at least one of the following steps: decryption, data recovery, and integrity verification.

[0013] Optionally, the step of determining a NAT detection result based on the comparison result by the responding node comprises: If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the first IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the first IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the first IP header, determining that a NAT exists between the requesting node and the network; otherwise, determining that a NAT does not exist between the requesting node and the network; If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the first IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the first IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the first IP header, determining that a NAT exists between the responding node and the network; otherwise, determining that no NAT exists between the responding node and the network.

[0014] Optionally, the step of determining a NAT detection result based on the comparison result by the requesting node comprises: If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the second IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the second IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the second IP header, determining that a NAT exists between the responding node and the network; otherwise, determining that a NAT does not exist between the responding node and the network; If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the second IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the second IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the second IP header, determining that a NAT exists between the requesting node and the network; otherwise, determining that no NAT exists between the requesting node and the network.

[0015] Optionally, the NAT detection result determined by the requesting node or the responding node according to the comparison result is a second detection result, and the detection result included in the NAT detection result response message is a first detection result; the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node; The second detection result indicates whether or not a NAT exists between the request node and the response node, and also indicates the distribution location of the NAT if a NAT exists between the request node and the response node.

[0016] In a second aspect, a NAT detection device between network nodes, which is installed on a requesting node side, provided by an embodiment of the present invention, comprises: an acquisition module configured to acquire first node information including an IP address of the requesting node itself and an IP address of a configured responding node, and use the acquired first node information as payload data of a NAT detection request message or a NAT detection result request message; an encapsulation module configured to encapsulate the NAT detection request message or the NAT detection result request message into an IP message, perform protection processing on the encapsulated NAT detection request packet message, and send it to a response node; a determining module configured to receive a NAT detection response packet message, perform a deprotection process, and upon obtaining a NAT detection result response message from the deprotected NAT detection response packet message, obtain a NAT detection result from the NAT detection result response message; or upon obtaining a NAT detection response message from the deprotected NAT detection response packet message, obtain payload data of the NAT detection response message, compare the obtained payload data with corresponding content in a second IP header of the NAT detection response packet message, and determine a NAT detection result based on the comparison result.

[0017] In a third aspect, a NAT detection device between network nodes, which is installed on a responding node side, provided by an embodiment of the present invention, comprises: a receiving module configured to receive a NAT detection request packet message and perform a deprotection process on the received NAT detection request packet message; a determining module configured to obtain the NAT detection request message or the NAT detection result request message from the deprotected NAT detection request packet message, compare payload data in the obtained NAT detection request message or the NAT detection result request message with corresponding content in a first IP header of the NAT detection request packet message, and determine a NAT detection result based on the comparison result; and an acquiring module configured to: upon acquiring the NAT detection request message from the deprotected NAT detection request packet message, acquire second node information including the IP address of the responding node itself and the IP address of the requesting node acquired from the first IP header of the NAT detection request packet message, use the second node information as payload data of a NAT detection response message, encapsulate the NAT detection response message in an IP message, perform protection processing on the encapsulated NAT detection response packet message, and then transmit it to the requesting node; or upon acquiring the NAT detection result request message from the deprotected NAT detection request packet message, include the NAT detection result in a NAT detection result response message, encapsulate the NAT detection result response message in an IP message, perform protection processing on the encapsulated NAT detection response packet message, and then transmit it to the requesting node.

[0018] In a fourth aspect, an embodiment of the present invention further provides a NAT detection device between network nodes, installed in a requesting node, the device including: a memory for storing program instructions; and a processor configured to invoke the program instructions stored in the memory and perform steps of the NAT detection method between network nodes provided by the first aspect above in accordance with the obtained program.

[0019] In a fifth aspect, an embodiment of the present invention further provides a NAT detection device between network nodes, located in a responding node, the device including: a memory for storing program instructions; and a processor configured to invoke the program instructions stored in the memory and perform steps of the NAT detection method between network nodes provided by the first aspect above according to the obtained program.

[0020] In a sixth aspect, an embodiment of the present invention further provides a computer storage medium having stored thereon a computer program, which, when executed by a processor, performs the steps of the NAT detection method between network nodes provided in the first aspect. [Effects of the Invention]

[0021] The beneficial effects of the present invention are as follows:

[0022] The present invention provides a NAT detection method that exists independently of the key management protocol, and simply and reliably solves the problem of difficulty in expanding key management functions due to the confusion in function definitions and ambiguous boundaries caused by the close coupling of detection and key management protocols between network nodes. (For example, the NAT detection function of the present invention is completed by a protocol that includes an IP address independent of the key management protocol, or includes an IP address and a port number, or includes an IP address and a session identifier (SID). Key management is completed by a special key management protocol. Strengthening and extending key management security is not affected by the NAT detection function.) Furthermore, NAT detection of the present invention is performed by a separate protocol rather than by modifying the key management protocol itself, and modifying the NAT detection function does not affect the security function of the key management protocol itself. The present invention supports a variety of NAT detection methods, supporting various detection methods that simply determine whether a NAT exists or determine where a NAT is deployed. When only determining whether a NAT exists, the responding node only feeds back the NAT detection result, which reduces communication volume and is more suitable for traffic-sensitive network environments. It also helps protect the NAT detection process, avoids internal address leakage, and prevents attackers from modifying detection messages to cause DoS attacks and waste network resources, thereby enhancing the security of the entire system. [Brief explanation of the drawings]

[0023] [Figure 1]1 is a schematic flowchart of a NAT detection method between network nodes provided by an embodiment of the present invention; [Figure 2] 1 is a schematic diagram of a NAT distribution location when a NAT exists between a requesting node and a responding node provided by an embodiment of the present invention; [Figure 3] 2 is a schematic structural diagram of a NAT detection device installed in a requesting node provided by an embodiment of the present invention; [Figure 4] 2 is a schematic structural diagram of a NAT detection device installed in a response node provided by an embodiment of the present invention; [Figure 5] 2 is a schematic module diagram of a NAT detection device installed in a requesting node provided by an embodiment of the present invention; [Figure 6] 2 is a schematic module diagram of a NAT detection device installed in a response node provided by an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0024] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, a method, apparatus, device and storage medium for detecting NAT between network nodes provided by an embodiment of the present invention will be described in detail with reference to the accompanying drawings.

[0025] As shown in FIG. 1, an embodiment of the present invention provides a NAT detection method between network nodes, including the following steps.

[0026] S101: A requesting node acquires first node information, and uses the acquired first node information as payload data of a NAT detection request message or payload data of a NAT detection result request message, where the first node information includes the requesting node's own IP address and the configured responding node's IP address.

[0027] The above NAT detection request message has the same format as the NAT detection result request message, but it belongs to a different message type. However, if the requesting node needs to determine whether a NAT exists and, if a NAT exists, the distribution location of the NAT, it should send the NAT detection request message to the responding node. If the requesting node only needs to determine whether a NAT exists between it and the responding node, it should send the NAT detection result request message to the responding node.

[0028] The payload data of the above NAT detection request message or NAT detection result request message is the same, and the payload data content includes the IP address of the requesting node itself and the IP address of the responding node. Note that the address of the responding node can be set by the administrator. This is because the requesting node must first be explicitly notified which responding node to send to.

[0029] S102: The requesting node encapsulates the NAT detection request message or the NAT detection result request message into an IP message, performs protection processing on the encapsulated NAT detection request packet message, and transmits it to the responding node.

[0030] As an optional embodiment, when a requesting node needs to send a NAT detection request message to a responding node, encapsulating the NAT detection request message into an IP message can specifically include: The requesting node encapsulates first node information into a first IP header of a NAT detection request packet message, and encapsulates the NAT detection request message into the content of the first message of the NAT detection request packet message.

[0031] As another optional embodiment, when a requesting node needs to send a NAT detection result request message to a responding node, encapsulating the NAT detection result request message into an IP message specifically includes: The requesting node encapsulates first node information into a first IP header of a NAT detection request packet message, and encapsulates the NAT detection result request message into the content of the first message of the NAT detection request packet message.

[0032] When a NAT detection request packet message is constructed, the first node information of the requesting node is not only present in the first IP header but is also encapsulated in the first message content.

[0033] If the sender is a requesting node and the receiver is a responding node, when the requesting node encapsulates an IP message, it must first organize and form the payload data of a NAT detection request message or a NAT detection result request message, and then encapsulate the NAT detection request message or the NAT detection result request message into an IP message to form a NAT detection request packet.

[0034] In this invention, the address of the requesting node or responding node itself is called the private address, and the address encapsulated in the header when the requesting node or responding node sends a message on the network is called the public address. For the requesting node or responding node, if the message is sent through a NAT for network address translation, the public address and private address are different. If the message is sent without a NAT for network address translation, the public address and private address are the same address.

[0035] As shown in Figure 2, the schematic diagram of the NAT distribution location when there is a NAT between the request node and the response node includes the following three situations:

[0036] Case 1: There is a NAT between the requesting node and the network, and there is no NAT between the responding node and the network.

[0037] The IP address of the requesting node encapsulated in the first IP header is a private address, and the IP address of the responding node is the responding node's own public address, which is also a private address. When the protected NAT detection request packet message passes through the NAT, the private IP address of the requesting node in the first IP header is changed to another public address by the NAT.

[0038] Case 2: There is no NAT between the requesting node and the network, and there is a NAT between the responding node and the network.

[0039] The IP address of the requesting node encapsulated in the first IP header is both the requesting node's own private address and a public address, and the IP address of the responding node is a public address. When the protected NAT detection request packet message passes through the NAT, the public IP address of the responding node in the first IP header is changed to another private address by the NAT.

[0040] Case 3: There is a NAT between the requesting node and the network, and there is a NAT between the responding node and the network.

[0041] The IP address of the requesting node encapsulated in the first IP header is a private address, and the IP address of the responding node is a public address. When the protected NAT detection request packet message passes through a NAT between the requesting node and the network, the private IP address of the requesting node in the first IP header is changed to another public address by the NAT. When the protected NAT detection request packet message passes through a NAT between the responding node and the network, the public IP address of the responding node in the first IP header is changed to another private address by the NAT.

[0042] If there is no NAT between the requesting node and the responding node, i.e., if there is no NAT between the requesting node and the network and no NAT between the responding node and the network, the IP address of the requesting node encapsulated in the first IP header is both the private address of the requesting node and the public address used in network transmission, and the IP address of the responding node is both the public address of the responding node and the public address used in network transmission.

[0043] The above is just an example to illustrate changing the IP address, the rules for changing the port and SID are the same as for the IP address, so we won't repeat them here.

[0044] As an optional embodiment, the requesting node performs a protection process on the NAT detection request packet message, specifically, The requesting node performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection request packet message. Specifically, the protection process on the NAT detection request packet message protects the content of a first message in the NAT detection request packet message, and does not protect a first IP header in the NAT detection request packet message.

[0045] The requesting node performs a protection process on the NAT discovery request packet message to form a protected NAT discovery request packet message. Because the NAT discovery request message may contain confidential information, protecting the NAT discovery request packet message can prevent the leakage of confidential information such as internal private IP addresses. Therefore, the NAT probe request packet message must undergo privacy and integrity verification processes during transmission. This prevents an attacker from tampering with information to launch a DoS attack (for example, because IPsec does not protect NAT discovery information, an attacker can launch a DoS attack by deleting or adding a NAT discovery (NAT-D) payload). It also solves the problem of bandwidth waste caused by an attacker tampering with information (for example, in the absence of a NAT in IPsec, an attacker can tamper with the NAT discovery message to force both negotiating parties to use the User Datagram Protocol (UDP) encapsulation mode, resulting in bandwidth waste).

[0046] S103: The responding node receives the NAT detection request packet message and performs a protection removal process on the received NAT detection request packet message.

[0047] As an optional embodiment, the responding node performs a deprotection process on the protected NAT detection request packet message, specifically, the responding node performs at least one of corresponding decryption, data recovery, and integrity verification on the protected NAT detection request packet message.

[0048] S104, the responding node obtains a NAT detection request message or a NAT detection result request message from the deprotected NAT detection request packet message, compares the payload data in the obtained NAT detection request message or the payload data in the NAT detection result request message with the corresponding content in the first IP header of the NAT detection request packet message, and determines a NAT detection result based on the comparison result.

[0049] The responding node determines whether the IP address of the requesting node or the responding node has been translated via a NAT during network transmission by comparing the first IP header with the IP address in the payload data of the NAT detection request message or the NAT detection result request message, thereby enabling analysis of the NAT detection result between the requesting node and the responding node.

[0050] S105: When the responding node acquires the NAT detection request message from the unprotected NAT detection request packet message, it acquires second node information including the responding node's own IP address and the IP address of the requesting node acquired from the first IP header of the NAT detection request packet message, uses the second node information as payload data of a NAT detection response message, encapsulates the NAT detection response message into an IP message, performs protection processing on the encapsulated NAT detection response packet message, and then transmits it to the requesting node.

[0051] S106: When the responding node acquires the NAT detection result request message from the unprotected NAT detection request packet message, it includes the NAT detection result in a NAT detection result response message, encapsulates the NAT detection result response message into an IP message, performs protection processing on the encapsulated NAT detection response packet message, and then sends it to the requesting node.

[0052] As an optional embodiment, the responding node encapsulates the NAT detection response message or the NAT detection result response message into an IP message, specifically: The response node encapsulates the second node information in a second IP header of a NAT detection response packet message, and encapsulates the NAT detection response message or the NAT detection result response message in the content of the second message of the NAT detection response packet message.

[0053] It should be noted that when the NAT detection response packet message is constructed, the second node information of the response node is not only present in the second IP header but is also encapsulated in the second message content.

[0054] When a responding node encapsulates an IP message, it first configures and forms payload data of the responding node's NAT detection response message or NAT detection result response message, and then encapsulates the NAT detection response message or NAT detection result response message into an IP message to form a NAT detection response packet message.

[0055] If there is a NAT between the responding node and the requesting node, there are three situations for the distribution location of the NAT, and for details, please refer to the explanation of the corresponding content in S102 (FIG. 2) above, which will not be repeated here.

[0056] As an optional embodiment, the response node performs a protection process on the NAT detection response packet message, specifically, The responding node performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection response packet. Protecting the NAT detection response packet message refers to protecting the content of the second message of the NAT detection response packet message, but not protecting the second IP header of the NAT detection response packet message.

[0057] It should be noted that the purpose of the protection process is the same as the protection process of the NAT detection request packet message by the requesting node described above, and therefore will not be described again here.

[0058] S107: The requesting node receives the NAT detection response packet message and performs a deprotection process, and upon obtaining a NAT detection result response message from the deprotected NAT detection response packet message, obtains a NAT detection result from the NAT detection result response message, or upon obtaining a NAT detection response message from the deprotected NAT detection response packet message, obtains payload data of the NAT detection response message, compares the obtained payload data with corresponding content in the second IP header of the NAT detection response packet message, and determines a NAT detection result based on the comparison result.

[0059] Among the NAT detection request packet messages sent from the requesting node to the responding node, a NAT detection request message or a NAT detection result request message can be encapsulated. Therefore, the responding node can execute S105 or S106 according to the actual situation, and the requesting node in S107 can obtain the NAT detection result in either way according to the actual situation.

[0060] As an optional embodiment, the requesting node performs a deprotection process on the protected NAT detection response packet message, specifically, the requesting node performs at least one of decryption, data recovery, and integrity verification on the protected NAT detection response packet message.

[0061] As an optional embodiment, the first node information further includes a port number of the requesting node itself and a port number of the configured responding node, or the first node information further includes a SID of the requesting node itself and a SID of the configured responding node.

[0062] As an optional embodiment, the second node information further includes the port number of the responding node itself and the port number of the requesting node obtained from the first IP header of the NAT detection request packet message, or the second node information further includes the SID of the responding node itself and the SID of the requesting node obtained from the first IP header of the NAT detection request packet message.

[0063] The IP address, port number, and SID of the responding node indicate the address from which data can be sent to the responding node. NAT detection supports not only protocols with PORTs but also non-port protocols. Some protocols do not have ports but have SIDs. For example, in SID (Session Identifier) ​​detection supporting TUE (Tunnel Universal Encapsulating), the responding node can determine the presence of a NAT based on any changes in the IP address, port, and SID carrying status in the first IP header. The requesting node can determine the presence of a NAT based on any changes in the IP address, port, and SID carrying status in the second IP header.

[0064] The present invention provides a NAT detection method that exists independently of the key management protocol, which is simple and reliable. This method solves the problems of the confusion in function definitions and the difficulty in expanding key management functions due to the ambiguous boundaries caused by the close coupling of detection and key management protocols between network nodes. (For example, the NAT detection function in this embodiment is completed by an independent protocol that carries IP addresses, or IP addresses and port numbers, or IP addresses and session identifiers (SIDs). Key management is completed by a special key management protocol. Strengthening and extending key management security is not affected by the NAT detection function.) In addition, NAT detection in this embodiment is performed by an independent protocol rather than by modifying the key management protocol itself. Modifying the NAT detection function does not affect the security function of the key management protocol itself. The present invention supports a variety of NAT detection methods, supporting different detection methods for determining only the presence of a NAT and for determining the distribution location of a NAT. When determining only the presence of a NAT, the responding node only feeds back the NAT detection result, thereby reducing communication volume and making it more suitable for traffic-sensitive network environments. It helps protect the NAT detection process, avoids internal address leakage, and prevents attackers from modifying detection messages to cause DoS attacks and waste network resources, enhancing the overall security of the system.

[0065] As an optional embodiment, the NAT detection request message, the NAT detection result request message, or the NAT detection response message includes an identifier indicating a message type and length information for analyzing the number of IP addresses. The message type identifier can distinguish the above three messages. The NAT detection result response message includes an identifier indicating whether a NAT exists between the requesting node and the responding node. According to the identifier indicating whether a NAT exists between the requesting node and the responding node, the message type is a NAT detection result response message, and the presence or absence of a NAT can be determined.

[0066] Note that the length information can include the length of the payload data, or the payload data can include the number of request node / response node addresses or the length of the message. Different types of length information can be used to analyze the number of IP addresses.

[0067] As an optional embodiment, the format of the NAT Detection Request Message / NAT Detection Response Message / NAT Detection Result Request Message / NAT Detection Result Response Message includes the following fields:

[0068] The identification field has multiple values, and the values ​​are defined as shown in Table 1 below.

[0069] [Table 1]

[0070] Here, the identifier value indicating the message type in the NAT detection request message is 1, the identifier value indicating the message type in the NAT detection response message is 2, and the identifier value indicating the message type in the NAT detection result request message is 3. If no NAT exists, the identifier value in the NAT detection result response message is 4, and if a NAT exists, the identifier value in the NAT detection result response message is 5.

[0071] The length information field is an optional field, and the length field allows the number of IP addresses in the payload data to be analyzed.

[0072] For example, in a multi-host environment, a requesting node or responding node may have multiple active and available IP addresses at the same time, so when constructing a NAT Discovery Request message or a NAT Discovery Response message, information about these IP addresses must be included. If the value of the above Identification field is 1, 2, or 3, the Length Information field for analyzing the number of IP addresses is a required field. If the value of the above Identification field is 4 or 5, the Length Information field is invalid.

[0073] The payload data field is a variable-length optional field that indicates the payload data of the NAT detection request message / NAT detection response message / NAT detection result request message. If the value of the above identification field is 1, 2, or 3, the payload data field is a required field. If the value of the above identification field is 4 or 5, the payload data field is invalid.

[0074] For example, the payload data field is used as payload data of a NAT detection request message, a NAT detection result request message, or a NAT detection response message, and the specific format is shown in the table below.

[0075] [Table 2]

[0076] where: DST_PORT(SID): This is an optional field with a length of 2 octets that indicates the peer port number or peer SID in the NAT Detection Request message, NAT Detection Result Request message, or NAT Detection Response message. If the current environment is IPv4, this field is required. If the current environment is IPv6, this field is not present.

[0077] DST_IP: Indicates the peer IP address in the NAT Detection Request message, NAT Detection Result Request message, or NAT Detection Response message. The length of the field depends on the IP version of the current communication. If IPv4 communication is currently being used, it is 4 octets long; if IPv6 communication is currently being used, it is 16 octets long.

[0078] SRC_PORT(SID): This is an optional field with a length of 2 octets that indicates the source port number or source SID in the NAT Detection Request message, NAT Detection Result Request message, or NAT Detection Response message. If the current environment is IPv4, this field is required. If the current environment is IPv6, this field is not present.

[0079] SRC_IP1|SRC_IP2 |...|SRC_IPn: Indicates the local IP addresses available for use in the current communication, and the length depends on the IP version of the current communication and the number of available IP addresses (n). If IPv4 communication is currently used, the length is 4*n octets long. If IPv6 communication is currently used, the length is 16*n octets long. "|": Indicates a connector.

[0080] For example, if there is one available local IP address, n is equal to 1. For a requesting node, SSRC_Ipn is the requesting node's own IP address, and SRC_PORT(SID) is the requesting node's port number or the requesting node's SID. DST_IP is the responding node's IP address, and DST_PORT(SID) is the responding node's port number or SID. For a responding node, SRC_IPn is the responding node's own IP address, SRC_PORT(SID) is the responding node's port number or the responding node SID, and DST_IP is the requesting node's IP address, and DST_PORT(SID) is the requesting node's port number or SID. Note that one or more SRC_IPs cannot be IPv4 and IPv6 simultaneously, and must be IPv4-only or IPv6-only, depending on the IP version of the current communication. A node can have one or more local IP addresses, but the specific IP addresses used during the communication process are unknown in advance and are not known until the communication is complete.

[0081] The following describes a possible implementation method for a corresponding responding node to determine a NAT detection result based on the comparison result in combination with a situation in which the number of source IP addresses in a NAT detection request message is different.

[0082] 1. The sender is a requesting node, the receiver is a responding node, and the number of IP addresses of the requesting node in the NAT detection request message is 1. The responding node determines the NAT detection result based on the comparison result, including any of the following steps:

[0083] Step A: If the IP address of the requesting node in the acquired payload data is different from the IP address of the requesting node in the first IP header, or if the port number of the requesting node in the acquired payload data is different from the port number of the requesting node in the first IP header, or if the SID of the requesting node in the acquired payload data is different from the SID of the requesting node in the first IP header, it determines that a NAT exists between the requesting node and the network; otherwise, it determines that no NAT exists between the requesting node and the network.

[0084] When the requesting node composes the payload data, the number of IP addresses of the requesting node is 1. The responding node determines that a NAT exists between the requesting node and the network if any of the following conditions are met in the comparison process:

[0085] 1) When the first node information to be used as payload data stores the IP address of the requesting node, the IP address of the requesting node in the payload data is different from the IP address of the requesting node in the first IP header.

[0086] 2) When the first node information to be used as payload data stores the IP address and port number of the requesting node, the IP address of the requesting node in the payload data is different from the IP address of the requesting node in the first IP header, and / or the port number of the requesting node in the payload data is different from the port number of the requesting node in the first IP header.

[0087] 3) When the first node information to be used as payload data stores the IP address and SID of the requesting node, the IP address of the requesting node in the payload data is different from the IP address of the requesting node in the first IP header, and / or the SID of the requesting node in the payload data is different from the SID of the requesting node in the first IP header.

[0088] Step B: If the IP address of the responding node in the payload data acquired by the responding node is different from the IP address of the responding node in the first IP header, or the port number of the responding node in the acquired payload data is different from the port number of the responding node in the first IP header, or the SID of the responding node in the acquired payload data is different from the SID of the responding node in the first IP header, determine that a NAT exists between the responding node and the network; otherwise, determine that no NAT exists between the responding node and the network.

[0089] When the requesting node composes the payload data, the number of IP addresses of the requesting node is 1, and for the responding node, if any of the following conditions is analyzed in the comparison process, it is determined that a NAT exists between the responding node and the network.

[0090] 1) When the first node information to be the payload data stores the IP address of the responding node, the IP address of the responding node in the payload data is different from the IP address of the responding node in the first IP header.

[0091] 2) When the first node information to be used as payload data stores the IP address and port number of the responding node, the IP address of the responding node in the payload data is different from the IP address of the responding node in the first IP header, and / or the port number of the responding node in the payload data is different from the port number of the responding node in the first IP header.

[0092] 3) When the first node information to be used as payload data stores the IP address and SID of the responding node, the IP address of the responding node in the payload data is different from the IP address of the responding node in the first IP header, and / or the SID of the responding node in the payload data is different from the SID of the responding node in the first IP header.

[0093] 2. When the sender is a requesting node and the receiver is a responding node, and the number of IP addresses of the requesting node in the NAT detection request message is greater than 1, the responding node determining the NAT detection result based on the comparison result includes any of the following steps:

[0094] Step A: if all IP addresses of the requesting nodes in the payload data acquired by the responding node are different from the IP addresses of the requesting nodes in the first IP header, or the port numbers of the requesting nodes in the acquired payload data are different from the port numbers of the requesting nodes in the first IP header, or the SIDs of the requesting nodes in the acquired payload data are different from the SIDs of the requesting nodes in the first IP header, it is determined that a NAT exists between the requesting nodes and the network; otherwise, it is determined that no NAT exists between the requesting nodes and the network.

[0095] Here, all IP addresses of the requesting node are encapsulated in the content of the first message, and when sending, the system adds only one IP address that needs to be used to the first IP header.For the responding node, it determines that there is a NAT between the requesting node and the network when any of the following conditions is analyzed in the comparison process:

[0096] 1) When the first node information to be the payload data stores all IP addresses of the requesting node, all IP addresses of the requesting node in the payload data are different from the IP addresses of the requesting node in the first IP header.

[0097] 2) When the first node information to be used as payload data stores all IP addresses and port numbers of the requesting node, all IP addresses of the requesting node in the payload data are different from the IP addresses of the requesting node in the first IP header, and / or the port numbers of the requesting node in the payload data are different from the port numbers of the requesting node in the first IP header.

[0098] 3) When the first node information to be used as payload data stores all IP addresses and SIDs of the requesting node, all IP addresses of the requesting node in the payload data are different from the IP addresses of the requesting node in the first IP header, and / or the SIDs of the requesting node in the payload data are different from the SIDs of the requesting node in the first IP header.

[0099] Step B: if the IP address of the responding node in the payload data acquired by the responding node is different from the IP address of the responding node in the first IP header, or the port number of the responding node in the acquired payload data is different from the port number of the responding node in the first IP header, or the SID of the responding node in the acquired payload data is different from the SID of the responding node in the first IP header, it is determined that a NAT exists between the responding node and the network; otherwise, it is determined that no NAT exists between the responding node and the network.

[0100] For a specific explanation, when the request node configures the payload data, please refer to the comparison process of response node information of the payload data when the number of IP addresses of the request node is 1, so the explanation will be omitted here.

[0101] There are two ways for the requesting node to obtain the final NAT detection result: Method 1: When the responding node feeds back a NAT detection response message to the requesting node, the requesting node determines the NAT detection result based on the comparison result; Method 2: When the responding node feeds back a NAT detection result response message to the requesting node, the requesting node obtains the NAT detection result directly from the NAT detection result response message.

[0102] The following describes possible implementation methods for a corresponding requesting node to determine a NAT detection result based on the comparison result in combination with a situation in which the number of source IP addresses in the NAT detection response message is different.

[0103] 1. When the sender is a responding node and the receiver is a requesting node, the number of IP addresses of the responding node in the NAT detection response message is 1, and the requesting node determines the NAT detection result based on the comparison result, specifically, the process includes the following steps:

[0104] Step A: If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the second IP header, or the port number of the responding node in the acquired payload data is different from the port number of the responding node in the second IP header, or the SID of the responding node in the acquired payload data is different from the SID of the responding node in the second IP header, determine that a NAT exists between the responding node and the network; otherwise, determine that a NAT does not exist between the responding node and the network.

[0105] In addition, when the responding node composes the payload data, the number of IP addresses of the responding node is 1, and in the case of the requesting node, if any of the following conditions is analyzed in the comparison process, it is determined that a NAT exists between the responding node and the network.

[0106] 1) When the second node information to be the payload data stores the IP address of the responding node, the IP address of the responding node in the payload data is different from the IP address of the responding node in the second IP header.

[0107] 2) When the second node information to be used as payload data stores the IP address and port number of the responding node, the IP address of the responding node in the payload data is different from the IP address of the responding node in the second IP header, and / or the port number of the responding node in the payload data is different from the port number of the responding node in the second IP header.

[0108] 3) When the second node information to be used as payload data stores the IP address and SID of the responding node, the IP address of the responding node in the payload data is different from the IP address of the responding node in the second IP header, and / or the SID of the responding node in the payload data is different from the SID of the responding node in the second IP header.

[0109] Step B: If the IP address of the requesting node in the payload data acquired by the requesting node is different from the IP address of the requesting node in the second IP header, or the port number of the requesting node in the acquired payload data is different from the port number of the requesting node in the second IP header, or the SID of the requesting node in the acquired payload data is different from the SID of the requesting node in the second IP header, determine that a NAT exists between the requesting node and the network; otherwise, determine that no NAT exists between the requesting node and the network.

[0110] In addition, when the responding node composes the payload data, the number of IP addresses of the responding node is 1, and in the case of the requesting node, if any of the following conditions is analyzed in the comparison process, it is determined that a NAT exists between the requesting node and the network.

[0111] 1) When the second node information to be used as payload data stores the IP address of the requesting node, the IP address of the requesting node in the payload data is different from the IP address of the requesting node in the second IP header.

[0112] 2) When the second node information to be used as payload data stores the IP address and port number of the requesting node, the IP address of the requesting node in the payload data is different from the IP address of the requesting node in the second IP header, and / or the port number of the requesting node in the payload data is different from the port number of the requesting node in the second IP header.

[0113] 3) When the second node information to be used as payload data stores the IP address and SID of the requesting node, the IP address of the requesting node in the payload data is different from the IP address of the requesting node in the second IP header, and / or the SID of the requesting node in the payload data is different from the SID of the requesting node in the second IP header.

[0114] 2. When the sender is a responding node and the receiver is a requesting node, and the number of IP addresses of the responding nodes in the NAT detection response message is greater than 1, the requesting node determines the NAT detection result based on the comparison result, specifically including the following steps:

[0115] Step A: If all IP addresses of the response nodes in the payload data acquired by the requesting node are different from the IP addresses of the response nodes in the second IP header, or the port numbers of the response nodes in the acquired payload data are different from the port numbers of the response nodes in the second IP header, or the SIDs of the response nodes in the acquired payload data are different from the SIDs of the response nodes in the second IP header, it is determined that a NAT exists between the response nodes and the network; otherwise, it is determined that no NAT exists between the response node and the network.

[0116] Here, all the IP addresses of the responding node are encapsulated in the content of the second message, and when sending, the system only needs to add one IP address that needs to be used in the second IP header. For the requesting node, it is determined that a NAT exists between the responding node and the network if any of the following conditions are analyzed in the comparison process:

[0117] 1) When the second node information to be the payload data stores all the IP addresses of the response nodes, all the IP addresses of the response nodes in the payload data are different from the IP addresses of the response nodes in the second IP header.

[0118] 2) When the second node information to be used as payload data stores all IP addresses and port numbers of the responding node, all IP addresses of the responding node in the payload data are different from the IP addresses of the responding node in the second IP header, and / or the port numbers of the responding node in the payload data are different from the port numbers of the responding node in the second IP header.

[0119] 3) When the second node information in the payload data stores all IP addresses and SIDs of the responding nodes, all IP addresses of the responding nodes in the payload data are different from the IP addresses of the responding nodes in the second IP header, and / or the SIDs of the responding nodes in the payload data are different from the SIDs of the responding nodes in the second IP header.

[0120] Step B: If the IP address of the requesting node in the payload data acquired by the requesting node is different from the IP address of the requesting node in the second IP header, or the port number of the requesting node in the acquired payload data is different from the port number of the requesting node in the second IP header, or the SID of the requesting node in the acquired payload data is different from the SID of the requesting node in the second IP header, determine that a NAT exists between the requesting node and the network; otherwise, determine that no NAT exists between the requesting node and the network.

[0121] For a specific explanation, please refer to the comparison process of request node information in payload data when the above response node constitutes payload data and the number of IP addresses of the response node is 1, so a repeated explanation will be omitted here.

[0122] It should be noted that it is not necessary to store all the NAT detection result information, and for subsequent encapsulation and communication of the data security channel, the responding node can selectively store the NAT detection result information and obtain a first result or a second detection result based on the selectively stored different NAT detection result information. The NAT detection result determined by the requesting node or the responding node according to the comparison result is the second detection result, and the detection result included in the NAT detection result response message is the first detection result.

[0123] Here, the first detection result is a detection result indicating whether there is a NAT between the request node and the response node, and the second detection result indicates whether there is a NAT between the request node and the response node, and whether there is a NAT between the request node and the response node, and indicates the distribution location of the NAT if there is a NAT between the request node and the response node.

[0124] As an optional embodiment, for a responding node, if the IP address of the requesting node in the acquired payload data is different from the IP address of the requesting node in the first IP header, but the port number / SID of the requesting node in the payload data is the same as the port number / SID of the requesting node in the first IP header, corresponding log information of the detection process is generated and stored.

[0125] Or, if the IP address of the response node in the acquired payload data is different from the IP address of the response node in the first IP header, but the port number / SID of the response node in the payload data is the same as the port number / SID of the response node in the first IP header, corresponding log information of the detection process is generated and stored.

[0126] If the IP address of the requesting node in the payload data acquired by the responding node from the NAT detection request packet message is different from the IP address of the requesting node in the first IP header, conventionally, this would prove the existence of a NAT between the requesting node and the network, or if the port number or SID of the requesting node in the payload data is the same as the port number or SID of the requesting node in the first IP header, NAT mapping may fail. The present invention classifies this situation as a situation in which the NAT between the requesting node and the network does not support traversal. When the requesting node sends a message to the responding node, the NAT between the requesting node and the network changes the requesting node's own port number or SID to the NAT's port number or SID, but the port number or SID of the requesting node in the first IP header remains unchanged. This means that the NAT between the requesting node and the network may fail when performing address mapping (for example, the NAT does not support UDP traversal). In this case, corresponding log information must be generated and stored. This allows administrators to later check the log and troubleshoot situations in which NAT traversal is not supported.

[0127] Based on the same inventive idea, an embodiment of the present invention further provides a NAT detection device between network nodes, which is installed in a requesting node. As shown in Figure 3, the device comprises: an acquiring module 301 configured to acquire first node information and set the acquired first node information as payload data of a NAT detection request message or payload data of a NAT detection result request message; an encapsulation module 302 configured to encapsulate the NAT detection request message or the NAT detection result request message into an IP message, perform protection processing on the encapsulated NAT detection request packet message, and send it to a response node; a determining module 303 configured to receive a NAT detection response packet message, perform a deprotection process, and upon obtaining a NAT detection result response message from the deprotected NAT detection response packet message, obtain a NAT detection result from the NAT detection result response message; or upon obtaining a NAT detection response message from the deprotected NAT detection response packet message, obtain payload data of the NAT detection response message, compare the obtained payload data with corresponding content in a second IP header of the NAT detection response packet message, and determine a NAT detection result based on the comparison result.

[0128] The first node information includes the requesting node's own IP address and the IP address of the configured responding node.

[0129] Optionally, the first node information further includes a port number of the requesting node itself and a port number of the configured responding node, or the first node information further includes a SID of the requesting node itself and a SID of the configured responding node.

[0130] Optionally, the encapsulation module 302 encapsulating the NAT detection request message or the NAT detection result request message into an IP message specifically includes: encapsulating the first node information in a first IP header of a NAT detection request packet message; The NAT detection request message or the NAT detection result request message is encapsulated in the content of a first message of a NAT detection request packet message.

[0131] Optionally, the NAT detection request message, the NAT detection result request message, or the NAT detection response message includes an identifier indicating a message type and length information for analyzing the number of IP addresses.

[0132] The NAT detection result response message includes an identifier indicating whether or not a NAT exists between the requesting node and the responding node.

[0133] Optionally, the encapsulation module 302 performs a protection process on the NAT detection request packet message, specifically: The encapsulation module 302 performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection request packet message.

[0134] Optionally, the determining module 303 performing deprotection processing on the NAT detection response packet message specifically includes: The determination module 303 performs at least one of decryption, data recovery, and integrity verification on the NAT detection response packet message.

[0135] Optionally, the determining module 303 determining the NAT detection result based on the comparison result specifically includes: If the IP address of the response node in the acquired payload data is different from the IP address of the response node in the second IP header, or the port number of the response node in the payload data is different from the port number of the response node in the second IP header, or the SID of the response node in the payload data is different from the SID of the response node in the second IP header, determine that a NAT exists between the response node and the network; otherwise, determine that no NAT exists between the response node and the network; If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the second IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the second IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the second IP header, it is determined that a NAT exists between the requesting node and the network; otherwise, it is determined that no NAT exists between the requesting node and the network.

[0136] Optionally, the NAT detection result determined by the determination module 303 based on the comparison result is a second detection result, and the detection result included in the NAT detection result response message is a first detection result; the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node; The second detection result indicates whether or not a NAT exists between the request node and the response node, and also indicates the distribution location of the NAT if a NAT exists between the request node and the response node.

[0137] An embodiment of the present invention further provides a NAT detection device between network nodes, which is located in a responding node. As shown in Figure 4, the device includes: a receiving module 401 configured to receive a NAT detection request packet message and perform a deprotection process on the received NAT detection request packet message; a determining module 402 configured to obtain the NAT detection request message or the NAT detection result request message from the deprotected NAT detection request packet message, compare payload data in the obtained NAT detection request message or the NAT detection result request message with corresponding content in a first IP header of the NAT detection request packet message, and determine a NAT detection result based on the comparison result; and an acquiring module 403 configured to: upon acquiring the NAT detection request message from the deprotected NAT detection request packet message, acquire second node information including the IP address of the responding node itself and the IP address of the requesting node acquired from the first IP header of the NAT detection request packet message, use the second node information as payload data of a NAT detection response message, encapsulate the NAT detection response message in an IP message, perform protection processing on the encapsulated NAT detection response packet message, and then send it to the requesting node; or upon acquiring the NAT detection result request message from the deprotected NAT detection request packet message, include the NAT detection result in a NAT detection result response message, encapsulate the NAT detection result response message in an IP message, perform protection processing on the encapsulated NAT detection response packet message, and then send it to the requesting node.

[0138] Optionally, the second node information further includes a port number of the responding node itself and a port number of the requesting node obtained from the first IP header of the NAT detection request packet message, or the second node information further includes a SID of the responding node itself and a SID of the requesting node obtained from the first IP header of the NAT detection request packet message.

[0139] Optionally, the obtaining module 403 encapsulating the NAT detection response message or the NAT detection result response message into an IP message specifically includes: encapsulating the second node information in a second IP header of a NAT detection response packet message; The NAT detection response message or the NAT detection result response message is encapsulated in the content of a second message of the NAT detection response packet message.

[0140] Optionally, the receiving module 401 performing deprotection processing on the NAT detection request packet message specifically includes: The receiving module 401 performs at least one of decryption, data recovery and integrity verification on the NAT detection request packet message.

[0141] Optionally, the obtaining module 403 performs a protection process on the NAT detection response packet message, specifically: The acquisition module 403 performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection response packet message.

[0142] Optionally, the determining module 402 determining the NAT detection result based on the comparison result includes any of the following steps:

[0143] If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the first IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the first IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the first IP header, determine that a NAT exists between the requesting node and the network; otherwise, determine that a NAT does not exist between the requesting node and the network; If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the first IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the first IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the first IP header, it is determined that a NAT exists between the responding node and the network; otherwise, it is determined that no NAT exists between the responding node and the network.

[0144] Optionally, the NAT detection result determined by the determination module 402 based on the comparison result is a second detection result, and the detection result included in the NAT detection result response message is a first detection result; the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node; The second detection result includes whether or not a NAT exists between the request node and the response node, and, if a NAT exists between the request node and the response node, a distribution location of the NAT.

[0145] Based on the same inventive idea, an embodiment of the present invention further provides a NAT detection device between network nodes, which is installed in a requesting node. As shown in Figure 5, the device includes: a memory 501 for storing program instructions; and a processor 502 configured to call the program instructions stored in the memory and perform the following processes according to the obtained program: the processor 502 acquires first node information, and uses the acquired first node information as payload data of a NAT detection request message or payload data of a NAT detection result request message, the first node information including an IP address of the requesting node itself and an IP address of a configured responding node; encapsulating the NAT detection request message or the NAT detection result request message into an IP message, performing a protection process on the encapsulated NAT detection request packet message, and sending it to a responding node; receive a NAT detection response packet message, perform a deprotection process, obtain a NAT detection result response message from the deprotected NAT detection response packet message, obtain a NAT detection result from the NAT detection result response message, or obtain a NAT detection response message from the deprotected NAT detection response packet message, obtain payload data of the NAT detection response message, compare the obtained payload data with corresponding content in the second IP header of the NAT detection response packet message, and determine a NAT detection result based on the comparison result.

[0146] Optionally, the first node information further includes a port number of the requesting node itself and a port number of the configured responding node, or the first node information further includes a SID of the requesting node itself and a SID of the configured responding node.

[0147] Specifically, the encapsulation of the NAT detection request message or the NAT detection result request message into an IP message includes: encapsulating the first node information in a first IP header of a NAT detection request packet message; The NAT detection request message or the NAT detection result request message is encapsulated in the content of a first message of a NAT detection request packet message.

[0148] Optionally, the NAT detection request message or the NAT detection result request message or the NAT detection response message includes an identifier indicating a message type and length information for analyzing the number of IP addresses, and the NAT detection result response message includes an identifier indicating whether a NAT exists between the requesting node and the responding node.

[0149] Specifically, performing a protection process on the NAT detection request packet message includes performing at least one of encryption, data obfuscation, and integrity verification on the NAT detection request packet message.

[0150] Performing a deprotection process on the NAT detection response packet message specifically includes performing at least one of decryption, data recovery, and integrity verification on the NAT detection response packet message.

[0151] Determining a NAT detection result based on the comparison result includes determining that a NAT exists between the response node and the network if the IP address of the response node in the acquired payload data is different from the IP address of the response node in the second IP header, or if the port number of the response node in the payload data is different from the port number of the response node in the second IP header, or if the SID of the response node in the payload data is different from the SID of the response node in the second IP header; otherwise, determining that a NAT does not exist between the response node and the network; If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the second IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the second IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the second IP header, it is determined that a NAT exists between the requesting node and the network; otherwise, it is determined that no NAT exists between the requesting node and the network.

[0152] The NAT detection result determined based on the comparison result is a second detection result, the detection result included in the NAT detection result response message is a first detection result, the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node, and the second detection result includes whether or not a NAT exists between the request node and the response node and the distribution location of the NAT if a NAT exists between the request node and the response node.

[0153] Based on the same inventive idea, an embodiment of the present invention further provides a NAT detection device between network nodes, which is installed in a responding node. As shown in Figure 6, the device includes: a memory 601 for storing program instructions; and a processor 602 configured to call the program instructions stored in the memory and perform the following processes according to the obtained program: The processor 602 receives a NAT detection request packet message, and performs a protection removal process on the received NAT detection request packet message; Obtaining the NAT detection request message or the NAT detection result request message from the deprotected NAT detection request packet message, comparing payload data in the obtained NAT detection request message or the payload data in the NAT detection result request message with corresponding content in a first IP header of the NAT detection request packet message, and determining a NAT detection result based on the comparison result; When the NAT detection request message is obtained from the deprotected NAT detection request packet message, second node information including the responding node's own IP address and the IP address of the requesting node obtained from the first IP header of the NAT detection request packet message is obtained, the second node information is used as payload data of a NAT detection response message, the NAT detection response message is encapsulated in an IP message, and protection processing is performed on the encapsulated NAT detection response packet message before sending it to the requesting node; alternatively, when the NAT detection result request message is obtained from the deprotected NAT detection request packet message, the NAT detection result is included in a NAT detection result response message, the NAT detection result response message is encapsulated in an IP message, and protection processing is performed on the encapsulated NAT detection response packet message before sending it to the requesting node.

[0154] Optionally, the second node information further includes a port number of the responding node itself and a port number of the requesting node obtained from the first IP header of the NAT detection request packet message, or the second node information further includes a SID of the responding node itself and a SID of the requesting node obtained from the first IP header of the NAT detection request packet message.

[0155] Encapsulating the NAT detection response message or the NAT detection result response message into an IP message specifically involves encapsulating the second node information into a second IP header of a NAT detection response packet message, and encapsulating the NAT detection response message or the NAT detection result response message into the content of the second message of the NAT detection response packet message.

[0156] Performing a deprotection process on the NAT detection request packet message specifically performs at least one of decryption, data recovery, and integrity verification on the NAT detection request packet message, and performing a protection process on the NAT detection response packet message specifically performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection response packet message.

[0157] Determining the NAT detection result based on the comparison result specifically includes determining that a NAT exists between the requesting node and the network if the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the first IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the first IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the first IP header; otherwise, determining that a NAT does not exist between the requesting node and the network; If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the first IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the first IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the first IP header, it is determined that a NAT exists between the responding node and the network; otherwise, it is determined that no NAT exists between the responding node and the network.

[0158] The NAT detection result determined based on the comparison result is a second detection result, the detection result included in the NAT detection result response message is a first detection result, the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node, and the second detection result includes whether or not a NAT exists between the request node and the response node and the distribution location of the NAT if a NAT exists between the request node and the response node.

[0159] Based on the same inventive idea, an embodiment of the present invention further provides a computer storage medium storing a computer program, which, when executed by a processor, implements the steps of the NAT detection method between network nodes provided in the above embodiment 1.

[0160] It should be understood that the disclosed systems, devices, and methods in some embodiments provided in the present application can be implemented in other ways. For example, the above-described device embodiments are merely examples, and the division of the units is merely a logical division of functions. In actual implementation, other division methods are possible. For example, the division of these units is merely a logical division of functions. In actual implementation, multiple modules or components may be combined or integrated into another system, or some functions may be ignored or not performed. In other respects, the illustrated or described couplings or direct couplings or communication connections between each other may be indirect couplings or communication connections via some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0161] Modules described as separate components may or may not be physically separated, and components shown as modules may or may not be physical modules, i.e., they may be located in one location or distributed across multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the objectives of the solution of this example.

[0162] Furthermore, each functional module in each embodiment of the present invention can be integrated into one processing module, each module can exist physically alone, or two or more modules can be integrated into one module. The above-mentioned integrated module can be implemented in the form of a hardware or software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium.

[0163] The above embodiments may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. If implemented using software, they may be implemented in whole or in part in the form of a computer program product.

[0164] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored on a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optics, digital subscriber line (DSL)), or wireless (e.g., infrared, radio, microwave) means. The computer-readable storage medium may be any available medium on which a computer can store data, or a data storage device such as a server or data center integrated with one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0165] The technical solutions provided by the present invention have been introduced in detail above. In the present invention, specific examples are used to explain the principles and implementation methods of the present application. The above description of the embodiments is only used to understand the method and its core concept. At the same time, those skilled in the art will encounter changes in the specific implementation and application scope based on the concept of the present application, which will be understood as limitations of the present invention.

Claims

1. A method for NAT detection between network nodes, comprising: a step in which the requesting node acquires first node information including its own IP address and the IP address of the configured responding node, and sets the acquired first node information as payload data of a NAT detection request message or payload data of a NAT detection result request message; the requesting node encapsulates the NAT detection request message or the NAT detection result request message into an IP message, performs protection processing on the encapsulated NAT detection request packet message, and sends it to a responding node; a response node receiving the NAT detection request packet message and performing a protection removal process on the received NAT detection request packet message; the responding node obtaining the NAT detection request message or the NAT detection result request message from the deprotected NAT detection request packet message, comparing payload data in the obtained NAT detection request message or the NAT detection result request message with corresponding content in a first IP header of the NAT detection request packet message, and determining a NAT detection result based on the comparison result; When the responding node acquires the NAT detection request message from the deprotected NAT detection request packet message, it acquires second node information including its own IP address and the IP address of the requesting node acquired from the first IP header of the NAT detection request packet message, uses the second node information as payload data of a NAT detection response message, encapsulates the NAT detection response message in an IP message, performs protection processing on the encapsulated NAT detection response packet message, and then transmits it to the requesting node; or when the responding node acquires the NAT detection result request message from the deprotected NAT detection request packet message, it includes the NAT detection result in a NAT detection result response message, encapsulates the NAT detection result response message in an IP message, performs protection processing on the encapsulated NAT detection response packet message, and then transmits it to the requesting node; the requesting node receives the NAT detection response packet message and performs a deprotection process, and upon obtaining a NAT detection result response message from the deprotected NAT detection response packet message, obtains a NAT detection result from the NAT detection result response message, or upon obtaining the NAT detection response message from the deprotected NAT detection response packet message, obtains payload data of the NAT detection response message, compares the obtained payload data with corresponding content in a second IP header of the NAT detection response packet message, and determines a NAT detection result based on the comparison result.

2. The first node information further includes a port number of the request node itself and a port number of the configured response node, or the first node information further includes an SID of the request node itself and an SID of the configured response node; 2. The NAT detection method between network nodes according to claim 1, wherein the second node information further includes a port number of the responding node itself and a port number of the requesting node acquired from the first IP header of the NAT detection request packet message, or the second node information further includes an SID of the responding node itself and an SID of the requesting node acquired from the first IP header of the NAT detection request packet message.

3. The step of the requesting node encapsulating the NAT detection request message or the NAT detection result request message into an IP message includes: encapsulating the first node information in a first IP header of a NAT discovery request packet message; encapsulating the NAT detection request message or the NAT detection result request message into the content of a first message of a NAT detection request packet message; The step of the responding node encapsulating the NAT detection response message or the NAT detection result response message into an IP message includes: encapsulating the second node information in a second IP header of a NAT detection response packet message; 3. The method for NAT detection between network nodes according to claim 1, further comprising the step of: encapsulating the NAT detection response message or the NAT detection result response message in the content of a second message of a NAT detection response packet message.

4. the NAT detection request message, the NAT detection result request message, or the NAT detection response message includes an identifier indicating a message type and length information for analyzing the number of IP addresses; 2. The method of claim 1, wherein the NAT detection result response message includes an identifier indicating whether a NAT exists between the requesting node and the responding node.

5. The step of the requesting node performing a protection process on the NAT detection request packet message includes: the requesting node performing at least one of encryption, data obfuscation, and integrity verification on the NAT detection request packet message; The step of performing a protection removal process on the NAT detection request packet message by the response node includes: the responding node performing at least one of decryption, data recovery, and integrity verification on the NAT detection request packet message; The step of the response node performing a protection process on the NAT detection response packet message includes: the responding node performing at least one of encryption, data obfuscation, and integrity verification on the NAT detection response packet message; The step of performing a protection removal process on the NAT detection response packet message by the requesting node includes:

2. The method of claim 1, further comprising the step of the requesting node performing at least one of decryption, data recovery, and integrity verification on the NAT detection response packet message.

6. The step of the responding node determining a NAT detection result based on the comparison result includes: If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the first IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the first IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the first IP header, determining that a NAT exists between the requesting node and the network; otherwise, determining that a NAT does not exist between the requesting node and the network; determining that a NAT exists between the responding node and the network if the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the first IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the first IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the first IP header, and otherwise determining that a NAT does not exist between the responding node and the network; The step of the requesting node determining a NAT detection result based on the comparison result includes: If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the second IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the second IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the second IP header, determining that a NAT exists between the responding node and the network; otherwise, determining that a NAT does not exist between the responding node and the network; 3. The method for detecting a NAT between network nodes according to claim 2, further comprising: determining that a NAT exists between the requesting node and the network if the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the second IP header, or if the port number of the requesting node of the payload data is different from the port number of the requesting node in the second IP header, or if the SID of the requesting node of the payload data is different from the SID of the requesting node in the second IP header, and otherwise determining that a NAT does not exist between the requesting node and the network.

7. the NAT detection result determined by the requesting node or the responding node according to the comparison result is a second detection result, and the detection result included in the NAT detection result response message is a first detection result; the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node; 5. The NAT detection method between network nodes according to claim 1, wherein the second detection result includes whether or not a NAT exists between the request node and the response node, and, if a NAT exists between the request node and the response node, a distribution location of the NAT.

8. A NAT detection device between network nodes, which is installed in a requesting node, an acquisition module configured to acquire first node information including an IP address of the requesting node itself and an IP address of a configured responding node, and to use the acquired first node information as payload data of a NAT detection request message or a NAT detection result request message; an encapsulation module configured to encapsulate the NAT detection request message or the NAT detection result request message into an IP message, perform protection processing on the encapsulated NAT detection request packet message, and send it to a responding node; a determination module for receiving a NAT detection response packet message, performing a deprotection process, and upon obtaining a NAT detection result response message from the deprotected NAT detection response packet message, obtaining a NAT detection result from the NAT detection result response message, or upon obtaining a NAT detection response message from the deprotected NAT detection response packet message, obtaining payload data of the NAT detection response message, comparing the obtained payload data with corresponding content in a second IP header of the NAT detection response packet message, and determining a NAT detection result based on a comparison result.

9. The first node information further includes a port number of the request node itself and a port number of the configured response node, or the first node information further includes an SID of the request node itself and an SID of the configured response node; The determining module determines a NAT detection result based on the comparison result, If the IP address of the responding node in the acquired payload data is different from the IP address of the responding node in the second IP header, or the port number of the responding node in the payload data is different from the port number of the responding node in the second IP header, or the SID of the responding node in the payload data is different from the SID of the responding node in the second IP header, determine that a NAT exists between the responding node and the network; otherwise, determine that a NAT does not exist between the responding node and the network; 9. The NAT detection device between network nodes according to claim 8, further comprising: determining that a NAT exists between the requesting node and the network if the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the second IP header, or if the port number of the requesting node of the payload data is different from the port number of the requesting node in the second IP header, or if the SID of the requesting node of the payload data is different from the SID of the requesting node in the second IP header, and otherwise determining that a NAT does not exist between the requesting node and the network.

10. the NAT detection request message, the NAT detection result request message, or the NAT detection response message includes an identifier indicating a message type and length information for analyzing the number of IP addresses; The NAT detection result response message includes an identifier indicating whether or not a NAT exists between the request node and the response node, The encapsulation module performs a protection process on the NAT detection request packet message, the encapsulation module performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection request packet message; The determination module performs a deprotection process on the NAT detection response packet message, 9. The NAT detection device between network nodes according to claim 8, wherein the determination module performs at least one of decryption, data recovery, and integrity verification on the NAT detection response packet message.

11. the NAT detection result determined by the determination module based on the comparison result is a second detection result, and the detection result included in the NAT detection result response message is a first detection result; the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node; 11. The NAT detection device between network nodes according to claim 8, wherein the second detection result includes whether or not a NAT exists between the request node and the response node, and a distribution location of the NAT if a NAT exists between the request node and the response node.

12. A NAT detection device between network nodes, which is installed in a response node, a receiving module configured to receive a NAT detection request packet message and perform a deprotection process on the received NAT detection request packet message; a determining module configured to obtain a NAT detection request message or a NAT detection result request message from the deprotected NAT detection request packet message, compare payload data in the obtained NAT detection request message or the NAT detection result request message with corresponding content in a first IP header of the NAT detection request packet message, and determine a NAT detection result based on the comparison result; and an acquisition module configured to: upon acquiring the NAT detection request message from a deprotected NAT detection request packet message, acquire second node information including an IP address of a responding node itself and an IP address of a requesting node acquired from a first IP header of the NAT detection request packet message, use the second node information as payload data of a NAT detection response message, encapsulate the NAT detection response message into an IP message, perform protection processing on the encapsulated NAT detection response packet message, and then transmit it to the requesting node; or upon acquiring the NAT detection result request message from the deprotected NAT detection request packet message, include the NAT detection result in a NAT detection result response message, encapsulate the NAT detection result response message into an IP message, perform protection processing on the encapsulated NAT detection response packet message, and then transmit it to the requesting node.

13. the second node information further includes a port number of the responding node itself and a port number of the requesting node acquired from the first IP header of the NAT detection request packet message, or the second node information further includes an SID of the responding node itself and an SID of the requesting node acquired from the first IP header of the NAT detection request packet message; The determining module determines a NAT detection result based on the comparison result, If the IP address of the requesting node of the acquired payload data is different from the IP address of the requesting node in the first IP header, or the port number of the requesting node of the payload data is different from the port number of the requesting node in the first IP header, or the SID of the requesting node of the payload data is different from the SID of the requesting node in the first IP header, determine that a NAT exists between the requesting node and the network; otherwise, determine that a NAT does not exist between the requesting node and the network; 13. The NAT detection device between network nodes according to claim 12, further comprising: determining that a NAT exists between the responding node and the network if an IP address of a responding node in the acquired payload data is different from the IP address of the responding node in the first IP header, or a port number of the responding node in the payload data is different from the port number of the responding node in the first IP header, or an SID of the responding node in the payload data is different from the SID of the responding node in the first IP header; and otherwise determining that a NAT does not exist between the responding node and the network.

14. The receiving module performs a protection removal process on the NAT detection request packet message, The receiving module performs at least one of decryption, data recovery, and integrity verification on the NAT detection request packet message; The acquisition module performs a protection process on the NAT detection response packet message, 13. The NAT detection device between network nodes according to claim 12, wherein the acquisition module performs at least one of encryption, data obfuscation, and integrity verification on the NAT detection response packet message.

15. the NAT detection result determined by the determination module based on the comparison result is a second detection result, and the detection result included in the NAT detection result response message is a first detection result; the first detection result is a detection result indicating whether or not a NAT exists between the request node and the response node; 15. The NAT detection device between network nodes according to claim 12, wherein the second detection result includes whether or not a NAT exists between the request node and the response node, and a distribution location of the NAT if a NAT exists between the request node and the response node.

Citation Information

Patent Citations

  • NAT type determination method, device and system and storage medium

    CN111935333A

  • Peer-to-peer network communication with network address translation (nat)

    JP2005525751A

  • Network configuration evaluation

    US20030212772A1