CN114422459A - Method, apparatus and computer equipment for instant message transmission - Google Patents
Method, apparatus and computer equipment for instant message transmission Download PDFInfo
- Publication number
- CN114422459A CN114422459A CN202011073785.7A CN202011073785A CN114422459A CN 114422459 A CN114422459 A CN 114422459A CN 202011073785 A CN202011073785 A CN 202011073785A CN 114422459 A CN114422459 A CN 114422459A
- Authority
- CN
- China
- Prior art keywords
- client
- message
- instant message
- data
- edge node
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/04—Real-time or near real-time messaging, e.g. instant messaging [IM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Power Engineering (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Information Transfer Between Computers (AREA)
Abstract
一种即时消息通信方法,该方法包括:在组织中设置边缘节点,边缘节点可以获取第一客户端发送的即时消息,并将即时消息划分为消息数据和信令数据,其中,消息数据用于指示第一客户端向第二客户端传输的内容,信令数据用于验证第一客户端归属用户的安全性。然后,边缘节点按照预设规则向第二客户端传输即时消息。以此减少敏感度有效的即时消息上传至云端所带来的泄露的风险,增强整个通信过程中传输和存储消息数据的安全性。
An instant message communication method, the method includes: setting up an edge node in an organization, the edge node can acquire an instant message sent by a first client, and divide the instant message into message data and signaling data, wherein the message data is used for Indicates the content transmitted from the first client to the second client, and the signaling data is used to verify the security of the user belonging to the first client. Then, the edge node transmits the instant message to the second client according to the preset rule. In this way, the risk of leakage caused by uploading sensitive and effective instant messages to the cloud is reduced, and the security of message data transmission and storage during the entire communication process is enhanced.
Description
技术领域technical field
本申请涉及通信技术领域,特别涉及一种即时消息传输的方法、装置和计算机设备。The present application relates to the field of communication technologies, and in particular, to a method, apparatus and computer equipment for instant message transmission.
背景技术Background technique
随着云服务的发展,企业的业务逐渐迁移至数据中心,数据中心以服务形式向企业提供业务服务,例如,数据中心可以向企业提供即时消息服务,也就是将即时消息的服务端部署在数据中心,以便减轻企业的维护工作量,上述迁移过程也可以称为即时消息的云化部署。即时消息(instant messaging,IM)服务是一种通过网络进行用户/组织间实时通信的服务,允许两个或多个用户(或者组织)使用支持即时消息服务的工具或应用传输包括文字、文件、图像、语音或视频等形式的消息。但是,由于即时消息的客户端和服务端分别部署在企业所在私有网络(也可以称为局域网)和数据中心所在公共网络中,即时消息的传输过程需要跨越私有网和公共网络,存在即时消息内容被暴力破解,影响用户数据安全的问题。因此,如何提供一种安全的即时消息传输方法成为亟待解决的技术问题。With the development of cloud services, the business of enterprises is gradually migrated to the data center, and the data center provides business services to the enterprise in the form of services. For example, the data center can provide instant messaging services to the enterprise, that is, the instant messaging server is deployed on the data center. In order to reduce the maintenance workload of enterprises, the above migration process can also be called cloud deployment of instant messaging. Instant messaging (IM) service is a service for real-time communication between users/organizations through the network, allowing two or more users (or organizations) to use tools or applications that support instant messaging services to transmit text, files, Messages in the form of images, voice, or video. However, since the client and server of the instant message are deployed in the private network (also called the local area network) where the enterprise is located and the public network where the data center is located, the transmission process of the instant message needs to span the private network and the public network, and the content of the instant message exists. It is brute force cracked, which affects the security of user data. Therefore, how to provide a secure instant message transmission method has become an urgent technical problem to be solved.
发明内容SUMMARY OF THE INVENTION
本申请提供了一种即时消息传输的方法、装置和计算机设备,以此提供一种更安全的即时消息传输的方法,提升用户数据的安全性。The present application provides a method, apparatus and computer equipment for instant message transmission, thereby providing a more secure instant message transmission method and improving the security of user data.
第一方面,提供一种即时消息的传输方法,该方法包括:边缘节点先获取第一客户端发送的即时消息;再将即时消息划分为消息数据和信令数据,其中,消息数据用于指示所述第一客户端向第二客户端传输的内容,信令数据用于验证所述第一客户端归属用户的安全性;然后,按照预设规则向所述第二客户端传输所述即时消息。通过上述方法,在组织中设置边缘节点,将涉及敏感数据的即时消息的消息数据存储至边缘节点,无需将消息数据传输至数据中心,提高了即时消息传输和存储的安全性。A first aspect provides an instant message transmission method, the method comprising: an edge node first obtains an instant message sent by a first client; and then divides the instant message into message data and signaling data, wherein the message data is used to indicate The content transmitted by the first client to the second client, and the signaling data is used to verify the security of the user to which the first client belongs; then, transmit the instant message to the second client according to preset rules. information. Through the above method, an edge node is set up in the organization, and the message data of the instant message involving sensitive data is stored in the edge node, and the message data does not need to be transmitted to the data center, which improves the security of instant message transmission and storage.
在一种可能的实现方式中,边缘节点预设属性标签列表,其中,属性标签用于标识第一客户端归属用户、第一客户端归属用户所在组织中至少一种的敏感度。通过属性标签,可以预设用户和/或组织的敏感度,在即时消息传输过程中,边缘节点可以依据该预设属性列表确定即时消息的敏感度,进而选择将敏感类用户和/或敏感类组织的消息数据存储至边缘节点,使得消息数据不涉及局域网和公共网络的传输,保证用户数据的安全性。In a possible implementation manner, the edge node presets an attribute tag list, where the attribute tag is used to identify the sensitivity of at least one of the user to which the first client belongs and the organization to which the user belongs to the first client. Through the attribute label, the sensitivity of users and/or organizations can be preset. During the instant message transmission process, the edge node can determine the sensitivity of the instant message according to the preset attribute list, and then select sensitive users and/or sensitive users. The organization's message data is stored to the edge nodes, so that the message data does not involve the transmission of local area networks and public networks, ensuring the security of user data.
在另一种可能的实现方法中,当预设属性标签中存在第一客户端归属用户的用户标识时,边缘节点将即时消息的消息数据存储至边缘节点;当预设属性标签中不存在第一客户端归属用户的用户标识时,边缘节点将即时消息的消息数据上传至数据中心;其中,用户标识用于全局唯一标识一个用户。通过上述方法的描述,边缘节点可以识别敏感类用户和普通用户,将敏感类用户发送的即时消息存储在边缘节点中,提升敏感类用户的即时消息传输和存储的安全性。In another possible implementation method, when the user identifier of the user belonging to the first client terminal exists in the preset attribute tag, the edge node stores the message data of the instant message to the edge node; when the preset attribute tag does not contain the first When a client belongs to the user identifier of the user, the edge node uploads the message data of the instant message to the data center; wherein, the user identifier is used to globally uniquely identify a user. Through the description of the above method, edge nodes can identify sensitive users and ordinary users, and store instant messages sent by sensitive users in edge nodes, thereby improving the security of instant message transmission and storage for sensitive users.
在另一种可能的实现方法中,当预设属性标签中存在第一客户端归属用户所在组织的标识时,边缘节点将即时消息的消息数据存储至边缘节点;当预设属性标签中不存在第一客户端归属用户所在组织的标识时,边缘节点将即时消息的消息数据上传至数据中心存储。通过上述方法的描述,边缘节点可以识别敏感类组织和非敏感类组织,将敏感类组织的即时消息存储至边缘节点,保证敏感类组织的即时消息传输和存储的安全性。In another possible implementation method, when the identifier of the organization where the first client belongs to the user exists in the preset attribute tag, the edge node stores the message data of the instant message to the edge node; when the preset attribute tag does not exist When the first client belongs to the identity of the organization where the user belongs, the edge node uploads the message data of the instant message to the data center for storage. Through the description of the above method, edge nodes can identify sensitive organizations and non-sensitive organizations, store the instant messages of sensitive organizations to edge nodes, and ensure the security of instant message transmission and storage of sensitive organizations.
在另一种可能的实现方法中,边缘节点还可以检索消息数据是否包括敏感字段和/或预设格式,其中,预设格式包括文字、视频、语音中至少一种;并根据检索结果执行即时消息的传输。In another possible implementation method, the edge node can also retrieve whether the message data includes a sensitive field and/or a preset format, wherein the preset format includes at least one of text, video, and voice; transmission of messages.
在另一种可能的实现方式中,当检索消息数据存在敏感字段和/或格式时,边缘节点识别即时消息为敏感类即时消息,将该即时消息的消息数据存储至边缘节点;当消息数据不存在敏感字段和/或格式时,边缘节点将即时消息标识为普通类即时消息,将该即时消息的消息数据上传至数据中心存储。通过上述方法的描述,可以根据消息数据中所包含的内容识别即时消息的敏感度,将敏感类即时消息存储至边缘节点,提升包含敏感字段和/或格式的消息数据的安全性。In another possible implementation, when the retrieved message data has sensitive fields and/or formats, the edge node identifies the instant message as a sensitive instant message, and stores the message data of the instant message to the edge node; when the message data does not When there are sensitive fields and/or formats, the edge node identifies the instant message as a common instant message, and uploads the message data of the instant message to the data center for storage. Through the description of the above method, the sensitivity of the instant message can be identified according to the content contained in the message data, and the sensitive instant message can be stored to the edge node to improve the security of the message data containing sensitive fields and/or formats.
在另一种可能的实现方式中,边缘节点将消息数据存储至边缘节点的存储器,并周期性清理存储器中存储的数据。由于边缘节点被设置于组织内部,同一组织中使用局域网实现客户端和边缘节点的通信连接,将消息数据存储在边缘节点中,可以有效地提升即时消息存储的安全性。此外,周期性更新边缘节点中存储的消息数据,有利于存储空间的有效利用。In another possible implementation manner, the edge node stores the message data in the memory of the edge node, and periodically clears the data stored in the memory. Since the edge nodes are set inside the organization, the local area network is used in the same organization to realize the communication connection between the client and the edge nodes, and the message data is stored in the edge nodes, which can effectively improve the security of instant message storage. In addition, periodically updating the message data stored in the edge node is beneficial to the effective use of storage space.
在另一种可能的实现方式中,在边缘节点获取第一客户端发送的消息数据之前,边缘节点可以获取第一客户端的消息索引,其中,消息索引用于指示第一客户端所发送即时消息的顺序的标识。边缘节点向数据中心发送消息索引,以指示数据中心向第二客户端发送该消息索引;再接收第二客户端发送的消息索引,然后,向第二客户端发送消息数据。通过上述方法的描述,利用消息索引标识即时消息的顺序,第二客户端可以依据该消息索引准确地获取到对应的消息数据,提高了即时消息传输过程的效率。In another possible implementation manner, before the edge node obtains the message data sent by the first client, the edge node may obtain the message index of the first client, where the message index is used to indicate the instant message sent by the first client sequence identifier. The edge node sends the message index to the data center to instruct the data center to send the message index to the second client; and then receives the message index sent by the second client, and then sends the message data to the second client. Through the description of the above method, the sequence of the instant messages is identified by the message index, and the second client can accurately obtain the corresponding message data according to the message index, which improves the efficiency of the instant message transmission process.
在另一种可能的实现方式中,在边缘节点按照预设规则向第二客户端传输即时消息之前,边缘节点还可以向数据中心发送指令数据;再接收数据中心对根据指令数据对第一客户端身份的验证结果;当第一客户端身份验证结果为成功时,按照预设规则向第二客户端发送即时消息。通过上述方法的描述,本申请提供的即时消息传输方法可以验证第一客户端的安全性,能够降低非登录用户进行操作的风险,提高了即时消息传输的安全。In another possible implementation manner, before the edge node transmits the instant message to the second client according to preset rules, the edge node may also send instruction data to the data center; The authentication result of the terminal identity; when the authentication result of the first client is successful, send an instant message to the second client according to the preset rules. Through the description of the above method, the instant message transmission method provided by the present application can verify the security of the first client, can reduce the risk of non-login users performing operations, and improve the security of instant message transmission.
第二方面,本申请提供一种即时消息的传输装置,所述传输装置包括用于执行第一方面或第一方面任一种可能实现方式中的即时消息传输方法的各个模块。In a second aspect, the present application provides an instant message transmission apparatus, where the transmission apparatus includes various modules for executing the instant message transmission method of the first aspect or any possible implementation manner of the first aspect.
第三方面,本申请提供一种即时消息的传输系统,所述传输系统包括边缘节点和数据中心。边缘节点和数据中心分别用于实现如上述第一方面及第一方面任意一种可能实现方式中相应主体所执行的方法的操作步骤。通过上述即时消息的传输系统,在组织中设置边缘节点,将第一客户端发送的即时消息的消息数据存储在边缘节点中,提高了第一客户端与第二客户端之间即时消息传输和存储的安全性。In a third aspect, the present application provides an instant message transmission system, where the transmission system includes an edge node and a data center. The edge node and the data center are respectively used to implement the operation steps of the method performed by the corresponding subject in the above-mentioned first aspect and any possible implementation manner of the first aspect. Through the above instant message transmission system, an edge node is set in the organization, and the message data of the instant message sent by the first client is stored in the edge node, which improves the instant message transmission and efficiency between the first client and the second client. storage security.
第四方面,本申请提供一种计算机设备,所述计算机设备包括处理器和内存,所述内存中用于存储计算机执行指令,所述计算机设备运行时,所述处理器执行所述内存中的计算机执行指令以利用所述计算机设备中的硬件资源执行第一方面或第一方面任一种可能实现方式中所述方法的操作步骤。In a fourth aspect, the present application provides a computer device, the computer device includes a processor and a memory, the memory is used to store computer execution instructions, and when the computer device is running, the processor executes the memory in the memory. The computer executes the instructions to use hardware resources in the computer device to perform the operation steps of the method in the first aspect or any possible implementation manner of the first aspect.
第五方面,本申请提供一种计算机可读存储介质,所述计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机执行上述第一方面或第一方面任一种可能实现方式中所述方法的操作步骤。In a fifth aspect, the present application provides a computer-readable storage medium, where instructions are stored in the computer-readable storage medium to enable the computer to execute the first aspect or any one of the first aspects when it runs on a computer. Operation steps of the method described in the implementation manner.
第六方面,本申请提供了一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机执行第一方面或第一方面任一种可能实现方式中所述方法的操作步骤。In a sixth aspect, the present application provides a computer program product comprising instructions that, when run on a computer, cause the computer to perform the operation steps of the method described in the first aspect or any possible implementation manner of the first aspect.
本申请在上述各方面提供的实现方式的基础上,还可以进行进一步组合以提供更多实现方式。On the basis of the implementation manners provided by the above aspects, the present application may further combine to provide more implementation manners.
附图说明Description of drawings
图1是本申请实施例提供的一种即时消息通信系统100的结构示意图;FIG. 1 is a schematic structural diagram of an instant message communication system 100 provided by an embodiment of the present application;
图2是本申请实施例提供的一种即时消息通信方法200的流程示意图;FIG. 2 is a schematic flowchart of an instant
图3是本申请实施例提供的一种即时消息通信装置300的结构示意图;FIG. 3 is a schematic structural diagram of an instant message communication apparatus 300 provided by an embodiment of the present application;
图4是本申请实施例提供的一种计算机设备400的结构示意图。FIG. 4 is a schematic structural diagram of a
具体实施方式Detailed ways
下面结合附图对本申请提供的即时消息传输的方法、装置和设备作详细描述。The method, apparatus and device for instant message transmission provided by the present application will be described in detail below with reference to the accompanying drawings.
本申请所涉及的即时消息可以被区分为消息数据和信令数据。其中,消息数据用于指示用户所需向其他用户或组织发送的具体内容;而信令数据则用于指示除了消息数据以外的部分,例如,用户名、用户账号、用户密码或者消息中指定的接收方的用户标识(identifier,ID)等。即时消息的传输协议包括可扩展的信息和呈现协议(ExtensibleMessaging and Presence Protocol,XMPP)、可扩展通讯和表示协议(ExtensibleMessaging and Presence Protocol,EMPP)或会晤初始化协议的即时消息和呈现业务扩展(Session Initiation Protocol for Instant Messaging and Presence LeveragingExtensions,SIMPLE),也可以是自定义的基于传输控制协议(Transmission ControlProtocol,TCP)或用户数据报协议(User Datagram Protocol,UDP)。The instant message involved in this application can be divided into message data and signaling data. Among them, the message data is used to indicate the specific content that the user needs to send to other users or organizations; and the signaling data is used to indicate the part other than the message data, for example, user name, user account, user password or specified in the message. The receiver's user identifier (identifier, ID), etc. The transport protocols of instant messages include Extensible Messaging and Presence Protocol (XMPP), Extensible Messaging and Presence Protocol (EMPP) or Session Initiation Protocol (Session Initiation). Protocol for Instant Messaging and Presence LeveragingExtensions, SIMPLE), or can be customized based on Transmission Control Protocol (Transmission Control Protocol, TCP) or User Datagram Protocol (User Datagram Protocol, UDP).
图1为本申请实施例提供的一种即时消息通信系统100的结构示意图,如图所示,系统100包括数据中心101、网络102、边缘节点(例如,图1中边缘节点1031和边缘节点1032)和客户端104-108,数据中心101、边缘节点103以及客户端104-108通过网络102进行通信。其中,数据中心101是指实现即时消息服务的系统,该系统包括多个设备,例如,图1中设备1011-设备1013。具体地,数据中心101中可以包括用于实现计算功能的设备(例如,服务器)、存储(例如,存储阵列)功能的设备和网络(例如,交换机)功能的设备。网络102包括有线或无线的传输方式,其中,有线的传输方式包括利用以太、光纤等形式进行数据传输,无线传输方式包括移动热点(Wi-Fi)、蓝牙、红外等传输方式。具体实施过程中,可以利用一个或多个交换机和/或路由器实现数据中心101和组织的通信连接。FIG. 1 is a schematic structural diagram of an instant messaging system 100 according to an embodiment of the present application. As shown in the figure, the system 100 includes a data center 101, a network 102, and edge nodes (for example, the
应当理解,数据中心101中设备的数量并不构成对本申请的限定,图1仅以数据中心包括三台设备为例进行说明。另外,对于数据中心中设备的类型、虚拟化管理方式本申请也不作限定。It should be understood that the number of devices in the data center 101 does not constitute a limitation to the present application, and FIG. 1 only takes the data center including three devices as an example for illustration. In addition, the present application also does not limit the types of devices and virtualization management methods in the data center.
边缘节点,用于识别敏感度标识、区分即时消息中消息数据和指令数据、存储和转发客户端即时消息等功能。具体实施中,边缘节点1031可以是部署在服务器中的软件模块,也可以是一台服务器,还可以是由若干台服务器组成的服务器集群,或者是一个云计算服务中心,本申请实施例对此不做限定。其中,服务器也称伺服器,是提供计算服务的设备。在本申请实施例中,所述服务器可以是X86服务器,X86服务器又称复杂指令集(complexinstruction set computer,CISC)架构服务器,即通常所讲的个人计算机(personalcomputer,PC)服务器,它是基于PC机体系结构,使用英特尔或其它兼容x86指令集的处理器芯片和操作系统的服务器。Edge nodes are used to identify sensitivity identifiers, distinguish message data and instruction data in instant messages, store and forward client instant messages, and other functions. In specific implementation, the
边缘节点还可以用于接收组织内或组织外的客户端发送的消息。例如,边缘节点1031可以接收组织1内客户端1041、客户端1042发送的消息,还可以接收组织1以外客户端1043发送的消息。Edge nodes can also be used to receive messages sent by clients within or outside the organization. For example, the
图1所示的即时消息通信系统中还包括一个或多个组织,同一组织中使用局域网实现客户端和边缘节点的通信连接,其中,局域网(也可以称为私有网络)是指一种在有限的地理范围内将多个设备互连实现数据传输和资源共享的计算机网络。每个组织可以是一个企业,也可以是同一企业的一个部门,还可以是一个团体。每个组织可以设置一个边缘节点,用于实现即时消息的安全传输和存储。The instant message communication system shown in FIG. 1 also includes one or more organizations, and the same organization uses a local area network to realize the communication connection between the client and the edge node. The local area network (also called a private network) refers to a limited A computer network that interconnects multiple devices to achieve data transmission and resource sharing within a geographical range. Each organization can be an enterprise, a department of the same enterprise, or a group. Each organization can set up an edge node for the secure transmission and storage of instant messages.
可选地,除了图1所示每个组织设置一个边缘节点外,多个组织也可以组成组织群,通过同一个边缘节点或多个边缘节点组成的集群实现即时消息的安全处理。Optionally, in addition to setting an edge node for each organization as shown in FIG. 1 , multiple organizations can also form an organization group, and secure instant message processing can be implemented through the same edge node or a cluster composed of multiple edge nodes.
每个组织包括一个或多个用户,每个用户通过客户端与其他用户进行消息交互。一个用户可以关联一个或多个用于发送和接收即时消息的客户端。同时,一个客户端也可以被一个或多个用户使用,但同一时刻只能被一个用户使用。例如,组织1的用户1052使用部署在组织1内客户端1042与其他用户进行通信,或者,组织1的用户1052也可以使用部署在组织外部的客户端1043与其他用户进行通信,例如,用户1052在家或出差过程中使用客户端1043与其他用户进行通信。当用户通过客户端与其他用户通信时,该用户也可以称为该客户端的归属用户。客户端是部署在设备中的代理程序,用于实现不同用户之间即时消息的发送和接收。部署客户端的设备可以为服务器、智能设备(例如,智能终端、平板电脑等)、个人电脑(personal computer,PC)。另外,部署了客户端的设备可以是相同类型的通信设备,也可以是不同的通信设备,本申请对此不做限定。Each organization includes one or more users, and each user interacts with other users through the client. A user can be associated with one or more clients for sending and receiving instant messages. At the same time, a client can also be used by one or more users, but can only be used by one user at a time. For example, user 1052 of
可选地,除了归属于组织的用户外,还存在不属于任何组织的用户,这类用户也可以称为独立用户。独立用户可以通过选择接入任意组织内的边缘节点,实现该用户归属的客户端利用该边缘节点实现即时消息安全处理的功能。其中,独立用户归属的客户端选择边缘节点的方式包括根据物理距离就近选择、随机选择和指定选择。例如,图1中用户1053为独立用户,客户端1043为用户1053归属的客户端,客户端1043可以选择与之进行消息传输的用户所在的组织1的边缘节点1031实现即时消息的传输。Optionally, in addition to users belonging to an organization, there are users who do not belong to any organization, and such users may also be called independent users. An independent user can choose to access an edge node in any organization, so that the client to which the user belongs can use the edge node to realize the function of instant message security processing. The manner in which the client to which the independent user belongs selects the edge node includes selection based on physical distance, random selection, and designated selection. For example, in FIG. 1 , user 1053 is an independent user, and client 1043 is a client to which user 1053 belongs. Client 1043 can select the
由于即时消息服务部署在数据中心后,涉及即时消息的消息数据需要跨局域网和公共网络进行传输,此外,即时消息的消息数据还会存储在数据中心,而依据于不同组织对数据安全需求的不同,可以按照以下方式中至少一种,根据敏感度将组织、用户、即时消息划分不同类别。Since the instant messaging service is deployed in the data center, the message data related to instant messages needs to be transmitted across the local area network and the public network. In addition, the message data of instant messages will also be stored in the data center, and according to the different data security requirements of different organizations , the organization, the user, and the instant message can be divided into different categories according to the sensitivity in at least one of the following manners.
方式一,根据组织的敏感度的不同将组织划分为敏感类组织和普通类组织。The first way is to divide the organizations into sensitive organizations and common organizations according to the different sensitivities of the organizations.
敏感类组织,需要对组织内用户发送即时消息的消息数据进行保护,不将即时消息的消息数据存储在数据中心。例如,涉及核心关键技术的组织可以归属于敏感类组织。除上述敏感类组织以外的组织均可以称为普通类组织。对于普通类组织,则无需对组织内用户发送即时消息的消息数据进行保护。Sensitive organizations need to protect the message data of instant messages sent by users in the organization, and do not store the message data of instant messages in the data center. For example, organizations involved in core critical technologies can be classified as sensitive organizations. Organizations other than the above-mentioned sensitive organizations can be called ordinary organizations. For ordinary organizations, there is no need to protect the message data of instant messages sent by users in the organization.
方式二,根据用户的敏感度将用户划分为敏感类用户和普通类用户。In the second method, users are divided into sensitive users and ordinary users according to their sensitivity.
敏感类用户,是指根据用户的属性将用户区分为不同安全级别,高安全级别的用户可能涉及敏感数据的发送和接收。例如,对于掌握核心商业信息的用户可以归属为敏感类用户。其中,用户的属性包括用户在组织中职位、工作性质(例如,是否涉及核心技术等)等涉及标识用户特征的信息。除上述敏感类用户以外的用户均可以称为普通类用户。Sensitive users refer to classifying users into different security levels according to their attributes. Users with high security levels may be involved in the sending and receiving of sensitive data. For example, users who have core business information can be classified as sensitive users. Among them, the attributes of the user include the user's position in the organization, the nature of work (for example, whether it involves core technology, etc.) and other information related to identifying the user's characteristics. Users other than the above-mentioned sensitive users can be called ordinary users.
方式三,根据即时消息的消息数据将即时消息划分为敏感类即时消息和普通类即时消息。In the third method, the instant messages are divided into sensitive instant messages and ordinary instant messages according to the message data of the instant messages.
也就是说,消息数据如果含有敏感内容,例如,带有“密码”、“账号”、或“客户身份信息”等敏感字段,或者,消息数据中包括用于指示预设格式(例如,图片),则携带该消息数据的即时消息属于敏感类即时消息。除上述敏感类消息数据以外消息数据均可以称为普通类消息数据。具体实施中,敏感内容可以由各个组织或维护人员通过数据中心的管理节点预先配置,并发送至边缘节点,以便边缘节点可以根据预设的敏感字段或预设格式标识即使消息的敏感度,进而按照该敏感度完成即时消息的传输。That is to say, if the message data contains sensitive content, for example, with sensitive fields such as "password", "account number", or "customer identity information", or, the message data includes information used to indicate a preset format (for example, a picture) , the instant message carrying the message data belongs to the sensitive instant message. Message data other than the above-mentioned sensitive message data may be referred to as common message data. In the specific implementation, the sensitive content can be pre-configured by each organization or maintenance personnel through the management node of the data center, and sent to the edge node, so that the edge node can identify the sensitivity of the instant message according to the preset sensitive field or preset format, and then The transmission of instant messages is done according to this sensitivity.
上述对组织、用户的分类方式仅为一种示例,具体实施过程中还可以根据业务需求细化分类方式和分类规则,并按照分类结果执行即时消息的传输。The above classification method for organizations and users is only an example. In the specific implementation process, the classification method and classification rules can be refined according to business requirements, and the instant message transmission can be performed according to the classification result.
值得说明的是,图1所示的即时消息通信系统架构仅仅是为了更好的说明本申请所提供的即时消息通信方法所提供的系统架构的示例,并不构成对本申请实施例的限定。It should be noted that the instant message communication system architecture shown in FIG. 1 is only an example of the system architecture provided by the instant message communication method provided by the present application, and does not constitute a limitation to the embodiments of the present application.
本申请提供一种即时消息通信方法,在将即时消息服务迁移至数据中心统一部署后,引入边缘节点,由边缘节点将用户发送的即时消息区分为消息数据和指令数据,并根据发送消息的企业组织的敏感度,或发送消息的用户的敏感度,或即时消息的敏感度,按照预设规则执行即时消息的传输处理,由此提升即时消息传输过程中的安全性。The present application provides an instant message communication method. After the instant message service is migrated to a data center for unified deployment, an edge node is introduced, and the edge node divides the instant message sent by the user into message data and instruction data, and according to the enterprise sending the message The sensitivity of the organization, or the sensitivity of the user who sends the message, or the sensitivity of the instant message, executes the instant message transmission processing according to the preset rules, thereby improving the security during the instant message transmission process.
接下来,基于图1所示系统,进一步结合图2详细介绍本申请提供的即时消息通信的方法。图2为本申请提供的一种即时消息通信方法的流程示意图,以第一客户端向第二客户端发送即时消息,实现第一客户端归属用户向第二客户端归属用户发送即时消息为例进一步介绍本申请所要保护的技术方案。该方法包括初始化和消息传输两个阶段,如图所示,具体方法包括:Next, based on the system shown in FIG. 1 , the instant message communication method provided by the present application is described in detail with reference to FIG. 2 . FIG. 2 is a schematic flowchart of an instant message communication method provided by the present application, taking the example of a first client sending an instant message to a second client, and realizing that a user of the first client sends an instant message to a home user of the second client as an example The technical solutions to be protected by this application are further introduced. The method includes two stages of initialization and message transmission, as shown in the figure, and the specific methods include:
S201、第一客户端向数据中心发送用户信息。S201. The first client sends user information to the data center.
S202、数据中心向第一客户端发送用户标识和令牌。S202. The data center sends the user identifier and the token to the first client.
用户在利用客户端传输即时消息前,需要先完成用户在数据中心的初始化过程,包括用户登录和边缘节点配置。用户登录过程参见步骤S201至S202的描述,边缘节点配置则可以参见步骤S203至S204的描述。Before users use the client to transmit instant messages, they need to complete the user initialization process in the data center, including user login and edge node configuration. For the user login process, refer to the description of steps S201 to S202, and for the configuration of the edge node, refer to the description of steps S203 to S204.
每个用户可以通过其所在客户端向数据中心101发送用户信息,进而完成用户在即时消息服务的登录操作,数据中心101可以为用户分配唯一的用户标识,并保存用户的用户信息。用户标识为数据中心101根据用户登录顺序或者用户信息为每一位用户生成的编号,通常由数字和/或字母组成,例如00001或者SZ000001。数据中心101还可以为用户生成一个令牌(token),将该令牌返回给对应的客户端,以便在后续即时消息传输过程中,利用该令牌完成该用户的身份校验。可选地,数据中心101还可以周期性为每个用户生成一个令牌,用以提升用户身份校验的安全性。令牌也可以称为鉴权标识。可选地,除了使用令牌外,数据中心还可以利用其他形式验证用户身份。Each user can send user information to the data center 101 through the client where the user is located, and then complete the user's login operation in the instant messaging service. The data center 101 can assign a unique user ID to the user and save the user's user information. The user ID is a number generated by the data center 101 for each user according to the user login sequence or user information, and is usually composed of numbers and/or letters, such as 00001 or SZ000001. The data center 101 may also generate a token for the user, and return the token to the corresponding client, so as to use the token to complete the identity verification of the user in the subsequent instant message transmission process. Optionally, the data center 101 may also periodically generate a token for each user, so as to improve the security of user identity verification. Tokens can also be called authentication tokens. Optionally, in addition to using tokens, the data center may utilize other forms of authenticating user identities.
用户信息包括但不限于下述数据中的一种或者多种:用户名、用户昵称、用户账号、用户密码、用户所属职位名称、用户所属组织名称。在本申请实施例中,客户端可以为用户提供登录界面,用户可以通过登录界面的输入框输入用户信息,以此向数据中心进行登录。User information includes, but is not limited to, one or more of the following data: user name, user nickname, user account, user password, job title to which the user belongs, and organization name to which the user belongs. In this embodiment of the present application, the client terminal may provide the user with a login interface, and the user may log in to the data center by inputting user information through an input box of the login interface.
可选地,用户登录的过程,除了用户通过客户端向数据中心发送用户信息进行登录外,登录的过程还可以是第一客户端向数据中心发送用户的联系方式(例如,手机号或邮箱),由数据中心向第一客户端发送验证码,再由用户通过客户端输入验证码向数据中心进行验证,由此能够降低他人冒充目标用户进行操作的风险,提升通信安全。Optionally, in the process of user login, in addition to the user logging in by sending user information to the data center through the client, the login process may also be that the first client sends the user's contact information (for example, a mobile phone number or email address) to the data center. , the data center sends a verification code to the first client, and then the user enters the verification code through the client to verify the data center, thereby reducing the risk of others pretending to be the target user to operate, and improving communication security.
S203、第一客户端向数据中心发送边缘节点配置命令。S203. The first client sends an edge node configuration command to the data center.
S204、数据中心向第一客户端返回边缘节点地址。S204. The data center returns the edge node address to the first client.
用户通过客户端登录即时消息服务之后,数据中心还需为客户端配置一个边缘节点,用于传输和存储该客户端发送的即时消息。根据用户类型的不同,配置方法可以采用以下方法中任意一种:After the user logs in to the instant messaging service through the client, the data center needs to configure an edge node for the client to transmit and store the instant messages sent by the client. Depending on the user type, the configuration method can be any of the following methods:
方法一:当第一客户端归属用户具有归属组织时,由数据中心直接根据用户所属组织名称检索部署于该组织内的边缘节点,并向第一客户端返回该边缘节点的互联网协议(Internet Protocol,IP)地址。Method 1: When the user to which the first client belongs has an organization, the data center directly retrieves the edge node deployed in the organization according to the name of the organization to which the user belongs, and returns the Internet Protocol (Internet Protocol) of the edge node to the first client. , IP) address.
方法二:当第一客户端归属用户为独立用户时,数据中心可以选择就近的边缘节点实现该用户的即时消息的传输。具体地,客户端向数据中心发送配置命令,数据中获取该客户端的地理位置,再依据该地理位置选择与该第一客户端距离最近的边缘节点传输该用户的即时消息,并将所选择的边缘节点的IP地址发送给第一客户端。Method 2: When the home user of the first client is an independent user, the data center may select a nearby edge node to transmit the instant message of the user. Specifically, the client sends a configuration command to the data center, obtains the geographic location of the client from the data, and then selects an edge node closest to the first client based on the geographic location to transmit the instant message of the user, and sends the selected The IP address of the edge node is sent to the first client.
可选地,用户还可以通过随机方式配置边缘节点,具体步骤包括:用户通过客户端发送随机选择命令给数据中心,数据中随机选择一个边缘节点作为该用户的边缘节点,并将所选择的边缘节点的IP地址发送给第一客户端。Optionally, the user can also configure the edge node in a random manner, and the specific steps include: the user sends a random selection command to the data center through the client, randomly selects an edge node in the data as the user's edge node, and uses the selected edge node. The IP address of the node is sent to the first client.
可选地,客户端也可以不配置边缘节点,此时第一客户端直接向数据中心发送即时消息,由数据中心完成即时消息的传输过程。Optionally, the client may not be configured with an edge node. In this case, the first client directly sends an instant message to the data center, and the data center completes the instant message transmission process.
通过上述操作过程,可以完成即时消息服务初始化阶段的处理,接下来,用户可以利用客户端通过与其匹配的边缘节点完成即时消息的传输和存储,该过程也可以称为消息传输阶段,具体包括:Through the above operation process, the processing of the instant message service initialization phase can be completed. Next, the user can use the client to complete the transmission and storage of the instant message through the matching edge node. This process can also be called the message transmission phase, which includes:
S205、边缘节点获取第一客户端发送的即时消息。S205. The edge node acquires the instant message sent by the first client.
客户端可以是图1中任意一个客户端,例如,客户端1041-1045中任意一个。The client can be any one of the clients in FIG. 1, for example, any one of the clients 1041-1045.
可选地,即时消息中还可以包括用户标识和/或组织名称,边缘节点可以根据属性标签中是否存在用户标识和/或组织名称判断即时消息的敏感度,详见步骤S206。Optionally, the instant message may further include a user ID and/or an organization name, and the edge node may determine the sensitivity of the instant message according to whether the user ID and/or organization name exists in the attribute tag, as detailed in step S206.
可选地,即时消息中还可以包括消息索引(index),消息索引用于指示第一客户端发送消息的顺序标识。具体地,客户端在发送即时消息的时,数据中心会生成一个与该即时消息关联的消息索引,用于指示客户端所发送即时消息的顺序,在消息接收过程中,接收即时消息的客户端可以通过消息索引在该边缘节点中获取对应的消息数据。Optionally, the instant message may further include a message index (index), where the message index is used to indicate the sequence identifier of the message sent by the first client. Specifically, when a client sends an instant message, the data center will generate a message index associated with the instant message, which is used to indicate the sequence of instant messages sent by the client. Corresponding message data can be obtained from the edge node through the message index.
此外,用户可以通过第一客户端向另一个客户端发送一条即时消息,此时,两个客户端的归属用户可以进行即时消息通信。另外,第一客户端的归属用户也可以同时向多个客户端的归属用户发送多条即时消息,此时,第一客户端的归属用户和其他客户端的归属用户之间可以通过即时消息进行通信。In addition, the user can send an instant message to another client through the first client, and at this time, the home users of the two clients can communicate with the instant message. In addition, the home user of the first client can also send multiple instant messages to the home users of multiple clients at the same time. At this time, the home user of the first client and the home users of other clients can communicate through instant messages.
S206、边缘节点识别即时消息的敏感度,并根据敏感度执行即时消息的传输。S206, the edge node identifies the sensitivity of the instant message, and executes the transmission of the instant message according to the sensitivity.
边缘节点可以预设属性标签列表,属性标签用于标识客户端归属用户、客户端归属用户所在组织中至少一种的敏感度。边缘节点可以根据属性标签和即时消息中携带用户标识和/或组织名称判断即时消息的敏感度。The edge node may preset a list of attribute labels, and the attribute labels are used to identify the sensitivity of at least one of the user to which the client belongs and the organization to which the user belongs to the client. The edge node can judge the sensitivity of the instant message according to the attribute label and the user ID and/or organization name carried in the instant message.
具体实施中,预设属性标签列表可以是企业规划阶段由维护人员根据需求设置,也可以是由用户预先指定的敏感度。此外,预设属性标签列表还可以根据业务需求动态调整,例如,根据企业或用户的敏感度、以及敏感字段或预设格式的变化,添加或删除预设属性标签中用户标识或组织名称。In a specific implementation, the preset attribute label list may be set by maintenance personnel according to requirements in the enterprise planning stage, or may be a sensitivity pre-specified by a user. In addition, the list of preset attribute labels can also be dynamically adjusted according to business requirements. For example, according to the sensitivity of the enterprise or user, and changes in sensitive fields or preset formats, user IDs or organization names in the preset attribute labels can be added or deleted.
示例地,表1为本申请实施例提供的一种预设属性标签列表,如表所示,用户标识和组织名称中至少一种均可以用于指示即时消息的敏感度。当预设属性标签列表中存在即时消息中包括的用户标识和/或组织名称时,该即时消息的敏感度为有效,边缘节点将该用户发送的即时消息中的消息数据存储至边缘节点。当预设属性标签列表中不存在即时消息中包括的用户标识和/或组织名称时,该即时消息的敏感度为无效,边缘节点将该用户发送的即时消息中消息数据上传至数据中心。例如,边缘节点中存储有两个阈值属性列表,预设属性列表1和预设属性列表2,预设属性列表1用于记录带有敏感度的用户标识,预设属性列表2则用于记录带有敏感度的组织名称。也就是说,当即时消息中包括用户标识为00001或组织名称为企业1、企业2时,该即时消息的敏感度为有效,此时,边缘节点会进一步将该即时消息划分为消息数据和指令数据,并将消息数据存储至边缘节点。Exemplarily, Table 1 is a list of preset attribute labels provided by this embodiment of the present application. As shown in the table, at least one of a user ID and an organization name can be used to indicate the sensitivity of the instant message. When the user ID and/or organization name included in the instant message exists in the preset attribute tag list, the sensitivity of the instant message is valid, and the edge node stores the message data in the instant message sent by the user to the edge node. When the user ID and/or organization name included in the instant message does not exist in the preset attribute tag list, the sensitivity of the instant message is invalid, and the edge node uploads the message data in the instant message sent by the user to the data center. For example, the edge node stores two threshold attribute lists,
表1、预设属性标签列表1Table 1. List of preset attribute labels 1
表2、预设属性标签列表2Table 2. List of preset attribute labels 2
可选地,边缘节点除了预设如表1和表2所示的属性标签列表外,还可以预设敏感字段或预设格式的列表,用于识别第一客户端归属用户发送的即时消息的敏感度,其中,敏感字段包括“密码”、“账号”、“电话”等涉及用户个人敏感信息的敏感字段;预设格式包括图片、音频、视频等格式中至少一种。Optionally, in addition to the preset attribute label lists shown in Table 1 and Table 2, the edge node can also preset a list of sensitive fields or preset formats, which are used to identify the instant message sent by the user belonging to the first client. Sensitivity, where the sensitive fields include "password", "account", "phone" and other sensitive fields related to the user's personal sensitive information; the preset format includes at least one of image, audio, video and other formats.
边缘节点还可以对即时消息进行检索,并根据检索结果执行即时消息的传输。具体地,当即时消息中存在敏感字段或敏感格式中任意一种时,该即时消息的敏感度为有效,边缘节点将即时消息进一步划分为消息数据和指令数据,并将消息数据存储至边缘节点,利用指令数据向数据中心进行身份验证,并完成消息数据的传输过程。当即时消息中不存在敏感字段或敏感格式中任意一种时,该即时消息的敏感度为无效,边缘节点则将即时消息发送至数据中心,由数据中心完成即时消息的传输。Edge nodes can also retrieve instant messages, and execute instant message transmission according to the retrieval results. Specifically, when any one of sensitive fields or sensitive formats exists in the instant message, the sensitivity of the instant message is valid, and the edge node further divides the instant message into message data and instruction data, and stores the message data in the edge node. , use the instruction data to authenticate to the data center, and complete the message data transmission process. When there is no sensitive field or sensitive format in the instant message, the sensitivity of the instant message is invalid, and the edge node sends the instant message to the data center, and the data center completes the transmission of the instant message.
作为一种可能的实现方式,如果即时消息中同时包括用户标识和组织名称时,只要预设属性标签列表中存在其中一项,则认为该即时消息的敏感度有效。As a possible implementation, if the instant message includes both the user ID and the organization name, as long as there is one item in the preset attribute label list, the sensitivity of the instant message is considered to be valid.
下面具体解释边缘节点如何根据敏感度执行即时消息的传输的过程:The following is a detailed explanation of how the edge node performs the transmission of instant messages according to the sensitivity:
S2061、边缘节点按照预设规则向第二客户端传输即时消息。S2061. The edge node transmits an instant message to the second client according to a preset rule.
第二客户端是即时消息的接收端,边缘节点可以根据预设规则将即时消息传输至第二客户端。其中,预设规则是指边缘节点可以根据预设属性标签的敏感度分别完成即时消息的传输,具体包括以下两种情况:The second client is the receiver of the instant message, and the edge node can transmit the instant message to the second client according to a preset rule. Among them, the preset rule means that the edge node can complete the instant message transmission according to the sensitivity of the preset attribute label, which specifically includes the following two situations:
情况一:当即时消息的敏感度有效时,边缘节点将即时消息中消息数据存储至边缘节点。Case 1: When the sensitivity of the instant message is valid, the edge node stores the message data in the instant message to the edge node.
情况二:当即时消息的敏感度无效时,边缘节点将即时消息发送至数据中心。Case 2: When the sensitivity of the instant message is invalid, the edge node sends the instant message to the data center.
对于情况二,即时消息可以直接将即时消息发送至数据中心,由数据中心完成即时消息的传输。For the second case, the instant message can be directly sent to the data center, and the data center completes the transmission of the instant message.
可选地,对于情况二,为了进一步提升即时消息传输过程的安全性,也可以由边缘节点将即时消息划分为消息数据和指令数据,然后,将消息数据存储至边缘节点,并利用指令数据对第一客户端进行身份验证,再按照敏感度有效的处理过程完成即时消息的传输。Optionally, for the second case, in order to further improve the security of the instant message transmission process, the edge node can also divide the instant message into message data and instruction data, and then store the message data in the edge node, and use the instruction data to pair the instant messages. The first client performs identity verification, and then completes the instant message transmission according to the processing procedure with effective sensitivity.
对于情况一,边缘节点在向第二客户端传输即时消息时,还需要利用即时消息中指令数据完成第一客户端的身份验证,具体过程包括:边缘节点向数据中心发送第一客户端携带的令牌;数据中心验证令牌的有效性,并向边缘节点发送验证结果;当第一客户端的身份验证成功后,边缘节点可以继续向第二客户端传输即时消息。详细过程如下:For
S20611、数据中心通知第二客户端接收即时消息。S20611. The data center notifies the second client to receive the instant message.
可选地,数据中心也可以将数据中心为即时消息生成的消息索引发送给第二客户端。Optionally, the data center may also send the message index generated by the data center for the instant message to the second client.
可选地,数据中心还可以将边缘节点的IP地址发送给第二客户端。Optionally, the data center may also send the IP address of the edge node to the second client.
S20612、第二客户端向边缘节点发送消息索引,请求获取对应的消息数据,同时携带第二客户端归属用户的鉴权标识。S20612. The second client sends a message index to the edge node, requesting to obtain corresponding message data, and carries the authentication identifier of the user to which the second client belongs.
S20613、边缘节点根据第二客户端归属用户的鉴权标识验证第二客户端的安全性。S20613. The edge node verifies the security of the second client according to the authentication identifier of the home user of the second client.
边缘节点验证第二客户端的安全性的过程与验证第一客户端的安全性的过程类似,也是通过向数据中心发送第二客户端归属用户的鉴权标识(例如,令牌)进行身份验证,为了简洁,在此不再赘述。The process of verifying the security of the second client by the edge node is similar to the process of verifying the security of the first client, and the authentication is also performed by sending the authentication identifier (for example, a token) of the home user of the second client to the data center. It is concise and will not be repeated here.
S20614、当第二客户端身份验证成功后,边缘节点向第二客户端发送消息数据。S20614. After the authentication of the second client is successful, the edge node sends message data to the second client.
通过上述过程的描述可知,本申请通过在局域网中增加边缘节点,由边缘节点识别即时消息的敏感度,按照不同敏感度完成即时消息的传输,保证敏感度有效的即时消息的消息数据仅存储在边缘节点,避免将敏感数据存储至数据中心过程中所带来的安全隐患,提升数据处理过程的安全性。进一步地,边缘节点可以将即时消息划分为消息数据和指令数据,对敏感数据可以直接存储至边缘节点,不将消息数据传输至数据中心,减少了敏感数据在网络传输过程中被拦截而暴力破解的风险,也保证了即时消息服务传输过程中的安全性。It can be seen from the description of the above process that in this application, by adding edge nodes in the local area network, the edge nodes identify the sensitivity of instant messages, and complete the transmission of instant messages according to different sensitivities, so as to ensure that the message data of instant messages with effective sensitivity are only stored in the Edge nodes avoid potential security risks in the process of storing sensitive data in the data center and improve the security of data processing. Further, edge nodes can divide instant messages into message data and instruction data, and store sensitive data directly to edge nodes without transmitting message data to the data center, reducing sensitive data being intercepted and brute force cracking during network transmission. risks, and also ensures the security of the instant messaging service during the transmission process.
作为一种可能的实现方式,除了按照上述步骤S20611至S20614的过程传输即时消息外,边缘节点也可以根据即时消息中携带的第二客户端的标识确定第二客户端的IP地址,然后,通过第二客户端的IP地址传输即时消息。具体的,边缘节点可以向数据中心发送查询第二客户端的请求,该请求中携带第二客户端的标识,数据中心可以根据第二客户端的标识向边缘节点返回第二客户端的IP地址,以此实现边缘节点根据第二客户端的IP地址向第二客户端传输即时消息的过程。As a possible implementation manner, in addition to transmitting the instant message according to the process of the above steps S20611 to S20614, the edge node can also determine the IP address of the second client according to the identifier of the second client carried in the instant message, and then, through the second client The IP address of the client to transmit instant messages. Specifically, the edge node can send a request for querying the second client to the data center, the request carries the identifier of the second client, and the data center can return the IP address of the second client to the edge node according to the identifier of the second client, so as to realize A process in which the edge node transmits an instant message to the second client according to the IP address of the second client.
作为一种可能的实现方案,本申请还提供一种图形用户界面(graphical userinterface,GUI),该图形用户界面的程序可以部署在边缘节点和/或数据中心,为维护人员提供添加或更新组织、用户或敏感内容、预设格式的可视化界面,维护人员可以通过上述图形用户界面查看、修改预设属性标签。可选地,上述可视化界面还可以呈现带有索引标识的即时消息的敏感度识别结果,包括各个索引标识关联即时消息的敏感度是否有效和该即时消息的存储位置。As a possible implementation solution, the present application also provides a graphical user interface (GUI), and the program of the GUI can be deployed in edge nodes and/or data centers to provide maintenance personnel with adding or updating organizations, A visual interface for users or sensitive content and preset formats. Maintenance personnel can view and modify preset attribute labels through the above-mentioned graphical user interface. Optionally, the above-mentioned visual interface can also present the sensitivity identification results of the instant messages with index identifiers, including whether the sensitivity of the instant messages associated with each index identifier is valid and the storage location of the instant messages.
接下来,结合图1所示系统,分三种场景进一步解释本申请所要保护的技术方案。Next, with reference to the system shown in FIG. 1 , the technical solutions to be protected by the present application are further explained in three scenarios.
场景一:归属于相同组织的两个用户之间进行即时消息传输。Scenario 1: Instant message transmission between two users belonging to the same organization.
在此场景中,边缘节点与第一客户端和第二客户端归属于同一个组织,两个用户之间通信流程与图2所示的流程类似,即时消息的传输过程由该组织中边缘节点识别即时消息的敏感度,并按照该敏感度执行即时消息的传输,为了简洁,在此不再赘述。In this scenario, the edge node belongs to the same organization as the first client and the second client. The communication process between the two users is similar to that shown in Figure 2. The instant message transmission process is performed by the edge node in the organization. The sensitivity of the instant message is identified, and the transmission of the instant message is performed according to the sensitivity. For the sake of brevity, details are not repeated here.
场景二:归属于不同组织的两个用户之间进行即时消息传输。Scenario 2: Instant message transmission between two users belonging to different organizations.
在此场景中每个组织可能设置一个边缘节点。例如,第一客户端与第一边缘节点归属于同一个组织,第二客户端与第二边缘节点归属于另一个组织。可选地,也可以仅在其中一个组织内设置边缘节点,由边缘节点实现第一客户端和第二客户端的即时消息传输。In this scenario each organization may have one edge node. For example, the first client and the first edge node belong to the same organization, and the second client and the second edge node belong to another organization. Optionally, an edge node may also be set in only one of the organizations, and the edge node implements instant message transmission between the first client and the second client.
当第一边缘节点和第二边缘节点分布设置于不同组织时,第一边缘节点向第二客户端传输即时消息的过程具体包括:When the first edge node and the second edge node are distributed in different organizations, the process of the first edge node transmitting the instant message to the second client specifically includes:
步骤1:第一边缘节点向数据中心发送索引消息。Step 1: The first edge node sends an index message to the data center.
步骤2:数据中心向第二边缘节点发送索引消息。Step 2: The data center sends an index message to the second edge node.
步骤3:第二边缘节点向第二客户端发送索引消息。Step 3: The second edge node sends an index message to the second client.
步骤4:第二客户端向第二边缘节点发送获取消息数据的请求,该请求中包括索引消息和第二客户端的鉴权标识。Step 4: The second client sends a request for acquiring message data to the second edge node, where the request includes the index message and the authentication identifier of the second client.
步骤5:第二边缘节点根据第二客户端的鉴权标识向数据中心验证第二客户端的安全性。Step 5: The second edge node verifies the security of the second client to the data center according to the authentication identifier of the second client.
步骤6:当第二客户端身份验证通过后,第二边缘节点向第一边缘节点发送消息索引。Step 6: After the authentication of the second client is passed, the second edge node sends the message index to the first edge node.
步骤7:第一边缘节点根据消息索引向第二边缘节点发送即时消息的消息数据。Step 7: The first edge node sends the message data of the instant message to the second edge node according to the message index.
通过上述操作过程,第一客户端和第二客户端可以分别通过与其匹配的边缘节点完成身份验证和即时消息的传输,涉及敏感信息的消息数据并没有传输至数据中心,也没有在数据中心存储,保证即时消息的数据传输和存储过程的安全性。Through the above operation process, the first client and the second client can respectively complete authentication and instant message transmission through their matching edge nodes, and the message data involving sensitive information is neither transmitted to the data center nor stored in the data center. , to ensure the security of instant message data transmission and storage process.
场景三:归属于组织的用户与独立用户之间进行即时消息传输。Scenario 3: IM transmission between users belonging to the organization and independent users.
在此场景中存在两个边缘节点,一个部署于第一客户端归属用户所在组织中,另一个是数据中心为独立用户配置的边缘节点。当两个边缘节点恰巧为同一个节点时,两个用户之间通信流程与场景一的流程完全一致;当两个边缘节点不为同一个节点时,两个用户之间通信流程与场景二流程完全一致,在此不再赘述。In this scenario, there are two edge nodes, one is deployed in the organization where the user of the first client belongs, and the other is an edge node configured for independent users in the data center. When the two edge nodes happen to be the same node, the communication process between the two users is exactly the same as the process in
综上所述,本申请实施例提供的即时消息通信方法,可以在组织中部署边缘节点,边缘节点通过用户、组织和即时消息中消息数据三个维度中至少一种识别即时消息的敏感度,将敏感类用户、敏感类组织和敏感类即时消息的消息数据存储在边缘节点内部中,其他的消息数据才上传至数据中心存储。使得客户端与数据中心的消息交互过程中,数据中心不涉及接收和处理敏感内容,有效防止消息数据传输至数据中心过程中的泄露以及在数据中心中存储消息数据所带来的不稳定性,提升整个通信过程的安全性。To sum up, the instant message communication method provided by the embodiments of this application can deploy edge nodes in an organization, and the edge nodes can identify the sensitivity of instant messages through at least one of the three dimensions of user, organization, and message data in instant messages, The message data of sensitive users, sensitive organizations, and sensitive instant messages is stored in the edge node, and other message data is uploaded to the data center for storage. In the process of message interaction between the client and the data center, the data center is not involved in receiving and processing sensitive content, effectively preventing the leakage of message data during transmission to the data center and the instability caused by storing message data in the data center. Improve the security of the entire communication process.
值得说明的是,对于上述方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本申请并不受所描述的动作顺序的限制。It should be noted that, for the sake of simple description, the above method embodiments are expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited by the described action sequence.
本领域的技术人员根据以上描述的内容,能够想到的其他合理的步骤组合,也属于本申请的保护范围内。其次,本领域技术人员也应该熟悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作并不一定是本申请所必须的。Other reasonable step combinations that those skilled in the art can think of based on the above description also fall within the protection scope of the present application. Secondly, those skilled in the art should also be familiar with that, the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the present application.
上文中结合图1和图2,详细描述了根据本申请实施例所提供的即时消息的传输方法,下面将结合图3和图4,进一步介绍根据本申请实施例所提供的即时消息传输的装置和计算机设备。The instant message transmission method provided according to the embodiment of the present application is described in detail above with reference to FIG. 1 and FIG. 2 , and the apparatus for instant message transmission provided according to the embodiment of the present application will be further described below with reference to FIG. 3 and FIG. 4 . and computer equipment.
图3为本申请提供的一种即时消息的传输装置300的示意图,包括获取单元310、处理单元320和传输单元330。FIG. 3 is a schematic diagram of an instant message transmission apparatus 300 provided by this application, including an
获取单元310,用于获取第一客户端发送的即时消息。The obtaining
处理单元320,用于将获取单元310获取的即时消息划分为消息数据和信令数据,其中,消息数据用于指示第一客户端向第二客户端传输的内容,信令数据用于验证所述第一客户端归属用户的安全性。The
传输单元330,用于按照预设规则向第二客户端传输所述即时消息。The
应理解的是,本申请实施例的传输装置300可以通过专用集成电路(application-specific integrated circuit,ASIC)实现,或可编程逻辑器件(programmable logicdevice,PLD)实现,上述PLD可以是复杂程序逻辑器件(complex programmable logicaldevice,CPLD),现场可编程门阵列(field-programmable gate array,FPGA),通用阵列逻辑(generic array logic,GAL)或其任意组合。也可以通过软件实现图2所示的即时消息传输方法时,传输装置300及其各个模块也可以为软件模块。It should be understood that the transmission apparatus 300 in this embodiment of the present application may be implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), and the above-mentioned PLD may be a complex program logic device (complex programmable logical device, CPLD), field-programmable gate array (field-programmable gate array, FPGA), general array logic (generic array logic, GAL) or any combination thereof. When the instant message transmission method shown in FIG. 2 can also be implemented by software, the transmission apparatus 300 and its respective modules can also be software modules.
可选地,处理单元320,还用于预设属性标签列表,所述属性标签用于标识所述第一客户端归属用户、所述第一客户端归属用户所在组织中至少一种的敏感度。Optionally, the
可选地,当所述属性标签用于标识所述第一客户端归属用户的敏感度时,所述传输单元330,还用于当所述预设属性标签中存在所述第一客户端归属用户的用户标识时,将所述即时消息的消息数据存储至所述边缘节点;以及,当所述预设属性标签中不存在所述第一客户端归属用户的用户标识时,将所述即时消息的消息数据上传至数据中心;其中,所述用户标识用于全局唯一标识一个用户。Optionally, when the attribute label is used to identify the sensitivity of the user to which the first client belongs, the
可选地,当所述属性标签用于标识所述第一客户端归属用户所在组织的敏感度时,所述传输单元330,还用于当所述预设属性标签中存在所述第一客户端归属用户所在组织的标识时,将所述即时消息的消息数据存储至所述边缘节点;以及,当所述预设属性标签中不存在所述第一客户端归属用户所在组织的标识时,将所述即时消息的消息数据上传至数据中心存储。Optionally, when the attribute label is used to identify the sensitivity of the organization where the first client belongs to the user, the
可选地,所述处理单元320,还用于检索所述消息数据是否包括敏感字段和/或预设格式,所述预设格式包括文字、视频、语音中至少一种;并根据检索结果执行所述即时消息的传输。Optionally, the
可选地,所述处理单元320,还用于当所述消息数据存在敏感字段和/或格式时,识别所述即时消息为敏感类即时消息,所述传输单元330,还用于将所述即时消息的所述消息数据存储至所述边缘节点;以及,Optionally, the
所述处理单元320,还用于当所述消息数据不存在敏感字段和/或格式时,识别所述即时消息为普通类即时消息,所述传输单元330,还用于将所述即时消息的所述消息数据上传至数据中心存储。The
可选地,传输装置300还包括存储单元340,用于将所述消息数据存储至所述边缘节点的存储器,并周期性清理所述存储器中存储的数据。Optionally, the transmission apparatus 300 further includes a
可选地,所述获取单元310,还用于在获取第一客户端发送的消息数据之前,获取所述第一客户端的消息索引,所述消息索引用于指示所述第一客户端所发送消息的顺序的标识;Optionally, the obtaining
所述传输单元330,还用于向所述数据中心发送所述消息索引,以指示所述数据中心向所述第二客户端发送所述消息索引;以及,接收所述第二客户端发送的所述消息索引,向所述第二客户端发送所述消息数据。The
可选地,所述处理单元320,还用于在按照预设规则向所述第二客户端传输所述即时消息之前,向所述数据中心发送所述指令数据;接收所述数据中心对所述第一客户端身份验证结果;以及,当所述第一客户端身份验证结果为成功时,所述传输单元按照所述预设规则向所述第二客户端发送所述即时消息。Optionally, the
根据本申请实施例的传输装置300可对应于执行本申请实施例中描述的方法,并且传输装置300中的各个单元的上述和其它操作和/或功能分别为了实现图2中的各个方法的相应流程,为了简洁,在此不再赘述。The transmission apparatus 300 according to the embodiments of the present application may correspond to executing the methods described in the embodiments of the present application, and the above-mentioned and other operations and/or functions of the various units in the transmission apparatus 300 are respectively to implement the corresponding methods of the respective methods in FIG. 2 . The process, for the sake of brevity, will not be repeated here.
综上所述,本申请实施例提供的传输装置300,处理单元可以从多个维度,将敏感类用户和归属于敏感类组织的用户发送的即时消息,以及消息数据中包含敏感内容的即时消息识别出来,存储在存储单元中,减少了组织内部的敏感信息的泄露风险,增强整个通信过程和消息数据的安全性,可适用于具有敏感信息的组织内部通信或者与其他外部组织的通信的服务场景。To sum up, in the transmission device 300 provided by the embodiment of the present application, the processing unit can, from multiple dimensions, send instant messages sent by sensitive users and users belonging to sensitive organizations, and instant messages containing sensitive content in the message data. It is identified and stored in the storage unit, which reduces the risk of leakage of sensitive information within the organization, enhances the security of the entire communication process and message data, and can be applied to the service of internal communication with sensitive information or communication with other external organizations Scenes.
图4为本申请实施例提供的一种计算机设备400的示意图,如图所示,计算机设备400包括处理器401、存储器402、通信接口403总线404和内存405。其中,处理器401、存储器402、通信接口403、内存405通过总线404进行通信,也可以通过无线传输等其他手段实现通信。内存405用于存储计算机执行指令,处理器401用于执行内存405存储的计算机执行指令以实现下述操作步骤:4 is a schematic diagram of a
获取第一客户端发送的即时消息;Obtain the instant message sent by the first client;
将所述即时消息划分为消息数据和信令数据,所述消息数据用于指示所述第一客户端向第二客户端传输的内容,所述信令数据用于验证所述第一客户端归属用户的安全性;Divide the instant message into message data and signaling data, where the message data is used to indicate the content transmitted by the first client to the second client, and the signaling data is used to authenticate the first client the security of the attributable user;
按照预设规则向所述第二客户端传输所述即时消息。The instant message is transmitted to the second client according to a preset rule.
应理解,在本申请实施例中,该处理器401可以是CPU,该处理器401还可以是其他通用处理器、数字信号处理器(digital signal processing,DSP)、专用集成电路(application specific integrated circuit,ASIC)、现场可编程门阵列(fieldprogrammable gate array,FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。通用处理器可以是微处理器或者是任何常规的处理器等。It should be understood that in this embodiment of the present application, the
该存储器402可以包括只读存储器和随机存取存储器,并向处理器401提供指令和数据。存储器402还可以包括非易失性随机存取存储器。例如,存储器402还可以存储设备类型的信息。The
该存储器402可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(read-only memory,ROM)、可编程只读存储器(programmable ROM,PROM)、可擦除可编程只读存储器(erasable PROM,EPROM)、电可擦除可编程只读存储器(electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(random access memory,RAM),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(static RAM,SRAM)、动态随机存取存储器(DRAM)、同步动态随机存取存储器(synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(double data date SDRAM,DDR SDRAM)、增强型同步动态随机存取存储器(enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(synchlinkDRAM,SLDRAM)和直接内存总线随机存取存储器(direct rambus RAM,DR RAM)。The
该总线404除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为总线404。In addition to the data bus, the
应理解,根据本申请实施例的计算设备400可对应于本申请实施例中的传输装置300,并可以对应于执行根据本申请实施例中图2所示的方法200中的相应主体,并且计算设备400中的各个模块的上述和其它操作和/或功能分别为了实现图中的各个方法的相应流程,为了简洁,在此不再赘述。It should be understood that the
综上所述,本申请实施例提供的计算机设备,根据即时消息的敏感度将即时消息划分为消息数据和消息信令,存储即时消息敏感度有效的消息数据至边缘节点,保护了这类消息的传输和存储始终位于组织的局域网范围内中,减少了敏感度有效的即时消息的消息数据传输至数据中心过程中所带来的泄露风险,提升了即时消息传输过程中的安全性。To sum up, the computer equipment provided by the embodiments of the present application divides instant messages into message data and message signaling according to the sensitivity of instant messages, stores message data with effective instant message sensitivity to edge nodes, and protects such messages The transmission and storage of IM is always located within the organization's local area network, which reduces the risk of leakage caused by the transmission of sensitive and effective IM message data to the data center, and improves the security during IM transmission.
本申请还提供一种即时消息的传输系统,包括边缘节点和数据中心。边缘节点和数据中心分别用于实现上述传输装置或计算机设备中相应主体所执行的方法的操作步骤。通过上述即时消息的传输系统,在组织中设置边缘节点,将第一客户端发送的即时消息的消息数据存储在边缘节点中,提高了第一客户端与第二客户端之间即时消息传输和存储的安全性。The present application also provides an instant message transmission system, including an edge node and a data center. The edge node and the data center are respectively used to implement the operation steps of the method executed by the corresponding subject in the above-mentioned transmission apparatus or computer equipment. Through the above instant message transmission system, an edge node is set in the organization, and the message data of the instant message sent by the first client is stored in the edge node, which improves the instant message transmission and efficiency between the first client and the second client. storage security.
上述实施例,可以全部或部分地通过软件、硬件、固件或其他任意组合来实现。当使用软件实现时,上述实施例可以全部或部分地以计算机程序产品的形式实现。所述计算机程序产品包括一个或多个计算机指令。在计算机上加载或执行所述计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以为通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或数据中心通过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可用介质集合的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质(例如,软盘、硬盘、磁带)、光介质(例如,DVD)、或者半导体介质。半导体介质可以是固态硬盘(solid state drive,SSD)。The above embodiments may be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented in software, the above-described embodiments may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general purpose computer, special purpose computer, computer network, or other programmable device. The computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be downloaded from a website site, computer, server, or data center Transmission to another website site, computer, server or data center by wire (eg, coaxial cable, optical fiber, digital subscriber line, DSL) or wireless (eg, infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, a data center, or the like that contains one or more sets of available media. The usable media may be magnetic media (eg, floppy disks, hard disks, magnetic tapes), optical media (eg, DVDs), or semiconductor media. The semiconductor medium may be a solid state drive (SSD).
以上所述,仅为本申请的具体实施方式。熟悉本技术领域的技术人员根据本申请提供的具体实施方式,可想到变化或替换,都应涵盖在本申请的保护范围之内。The above descriptions are merely specific embodiments of the present application. Those skilled in the art can think of changes or substitutions based on the specific embodiments provided by the present application, which should all fall within the protection scope of the present application.
Claims (20)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011073785.7A CN114422459A (en) | 2020-10-09 | 2020-10-09 | Method, apparatus and computer equipment for instant message transmission |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202011073785.7A CN114422459A (en) | 2020-10-09 | 2020-10-09 | Method, apparatus and computer equipment for instant message transmission |
Publications (1)
Publication Number | Publication Date |
---|---|
CN114422459A true CN114422459A (en) | 2022-04-29 |
Family
ID=81260399
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202011073785.7A Pending CN114422459A (en) | 2020-10-09 | 2020-10-09 | Method, apparatus and computer equipment for instant message transmission |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN114422459A (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN118138308A (en) * | 2024-03-06 | 2024-06-04 | 广州市汇朗信息技术有限公司 | A user data intelligent collection and protection processing method based on the Internet of Things |
-
2020
- 2020-10-09 CN CN202011073785.7A patent/CN114422459A/en active Pending
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN118138308A (en) * | 2024-03-06 | 2024-06-04 | 广州市汇朗信息技术有限公司 | A user data intelligent collection and protection processing method based on the Internet of Things |
CN118138308B (en) * | 2024-03-06 | 2024-12-27 | 北京伊顺科技发展有限公司 | User data intelligent collection protection processing method based on Internet of things |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10110671B2 (en) | Method, system, and device for managing server hardware resources in a cloud scheduling environment | |
US11228590B2 (en) | Data processing method and apparatus based on mobile application entrance and system | |
CN107508795B (en) | Cross-container cluster access processing device and method | |
US10659453B2 (en) | Dual channel identity authentication | |
JP2022020946A (en) | Information processing device, information processing system, communication format determination method, and program | |
US20180359243A1 (en) | Methods and systems for single sign-on while protecting user privacy | |
US10785056B1 (en) | Sharing a subnet of a logically isolated network between client accounts of a provider network | |
CN113691575B (en) | Communication method, device and system | |
WO2022214019A1 (en) | Method and apparatus for deploying network device, and device, system and storage medium | |
CN108053088A (en) | A kind of Subscriber Management System, method and apparatus | |
US11363060B2 (en) | Email security in a multi-tenant email service | |
US20240244080A1 (en) | Method and apparatus for determining compromised host | |
US10462154B2 (en) | Restricting communications between subscriber machines | |
WO2015134933A1 (en) | Manage encrypted network traffic using spoofed addresses | |
US20150047009A1 (en) | Access control method, access control system and access control device | |
US20140089430A1 (en) | Data-sharing method, terminal, server, and system | |
CN114969045A (en) | Account creating method, Internet of things multi-tenant system, equipment, program and medium | |
CN114422459A (en) | Method, apparatus and computer equipment for instant message transmission | |
CN111953931B (en) | Data sharing method, device and storage medium | |
US20220086182A1 (en) | Risk-adaptive dns forwarder | |
WO2018032499A1 (en) | Load balancing method and associated device | |
WO2017020551A1 (en) | Method and device for managing wireless access point | |
CN116032762B (en) | Processing method, system and gateway equipment of network service | |
US20160248596A1 (en) | Reflecting mdns packets | |
US9294434B1 (en) | Connectionless communications |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination |