Service access method, device, electronic device and medium

By introducing a secure access module into the ARM server, determining the target proxy server based on access configuration information and conducting secure encrypted communication, the data security risk when the operation and maintenance server controls the ARM server is resolved, and security and convenience are improved.

CN115396436BActive Publication Date: 2025-09-23BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211008739.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-22
Publication Date
2025-09-23
Estimated Expiration
2042-08-22

AI Technical Summary

Technical Problem

When the ARM cloud operation and maintenance server controls the ARM server based on the proxy communication architecture, there is a data security risk. It is necessary to expose the service access interface of the proxy server to the outside world, resulting in insufficient data security.

Method used

By introducing a security access module into the ARM server, the module is used to determine the target proxy server based on the access configuration information of the candidate proxy server, and service access is performed through the unified service access interface of the security access module, avoiding direct exposure of the interface of the candidate proxy server and achieving secure encrypted communication.

Benefits of technology

It improves the security of service access and the convenience of equipment operation and maintenance, and ensures the security of communication data and the load balancing of operation and maintenance servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396436B_ABST
    Figure CN115396436B_ABST
Patent Text Reader

Abstract

The present disclosure provides a service access method, device, electronic device and medium, which relate to the field of artificial intelligence, specifically to the field of cloud computing, and can be applied to service access scenarios. The specific implementation scheme is: in response to a service access request received from an operation and maintenance server, based on the access configuration information of at least two candidate proxy servers in an ARM server, a target proxy server is determined for the service access request from the at least two candidate proxy servers; the service access request is sent to the target proxy server so that the target proxy server determines the service access result of the service access request; and the service access result is sent to the operation and maintenance server. The present disclosure can improve the security of service access and the convenience of equipment operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of artificial intelligence, specifically to the field of cloud computing, and can be used in service access scenarios. Background Art

[0002] ARM servers are the foundation of ARM Cloud's computing services. Featuring multi-core, high parallelism, low power consumption, and low cost, ARM servers are widely used in mobile computing, real-time video streaming, and other mobile communications applications. ARM Cloud's operations and maintenance servers operate and maintain ARM servers within the cloud, ensuring the highly reliable computing services ARM Cloud provides.

[0003] Most ARM cloud operation and maintenance servers are based on proxy communication architectures, such as the proxy-agent architecture, to access ARM servers within the ARM cloud and perform operations and maintenance on them. However, controlling ARM servers based on proxy communication architectures requires exposing the service access interfaces of the proxy servers within the ARM servers, posing data security risks to the ARM servers. Summary of the Invention

[0004] The present disclosure provides a service access method, device, electronic device, and medium.

[0005] According to one aspect of the present disclosure, a service access method is provided, the method comprising:

[0006] In response to a service access request received from the operation and maintenance server, determining a target proxy server for the service access request from the at least two candidate proxy servers based on access configuration information of the at least two candidate proxy servers in the ARM server;

[0007] sending the service access request to the target proxy server so that the target proxy server determines a service access result of the service access request;

[0008] The service access result is sent to the operation and maintenance server.

[0009] According to another aspect of the present disclosure, there is provided a service access device, comprising:

[0010] a proxy determination module, configured to, in response to a service access request received from the operation and maintenance server, determine a target proxy server for the service access request from among at least two candidate proxy servers in the ARM server based on access configuration information of the at least two candidate proxy servers;

[0011] A result determination module, configured to send the service access request to the target proxy server, so that the target proxy server determines a service access result of the service access request;

[0012] The result sending module is used to send the service access result to the operation and maintenance server.

[0013] According to another aspect of the present disclosure, an electronic device is provided, the electronic device comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the service access method described in any embodiment of the present disclosure.

[0017] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to enable a computer to execute the service access method described in any embodiment of the present disclosure.

[0018] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, wherein when the computer program is executed by a processor, the service access method according to any embodiment of the present disclosure is implemented.

[0019] According to the technology disclosed in the present invention, the security of service access and the convenience of equipment operation and maintenance can be improved.

[0020] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present disclosure.

[0022] Figure 1 is a flow chart of a service access method provided according to an embodiment of the present disclosure;

[0023] Figure 2 is a flowchart of another service access method provided according to an embodiment of the present disclosure;

[0024] Figure 3 is a structural diagram of a service access system provided according to an embodiment of the present disclosure;

[0025] Figure 4 is a structural diagram of a service access device provided according to an embodiment of the present disclosure;

[0026] Figure 5 It is a block diagram of an electronic device used to implement the service access method according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0027] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered as merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0028] Figure 1 This is a flow chart of a service access method provided according to an embodiment of the present disclosure. This embodiment of the present disclosure is applicable to the case where an ARM cloud operation and maintenance server performs service access to an ARM server in an ARM cloud. This method can be executed by a service access device, which can be implemented in software and / or hardware and can be integrated into an electronic device that carries the service access function. Figure 1 As shown, the service access method of this embodiment may include:

[0029] S101, in response to a service access request received from an operation and maintenance server, determining a target proxy server for the service access request from at least two candidate proxy servers in an ARM server based on access configuration information of the at least two candidate proxy servers;

[0030] S102, sending the service access request to the target proxy server, so that the target proxy server determines the service access result of the service access request;

[0031] S103: Send the service access result to the operation and maintenance server.

[0032] The operations and maintenance server is responsible for operating and maintaining the ARM servers. The ARM servers are the foundation for the ARM cloud's computing services. Service access requests are generated by the operations and maintenance server and sent to the ARM servers. These requests request candidate proxy servers within the ARM servers to control the ARM servers using their service capabilities.

[0033] The candidate proxy servers are located within the ARM servers, with each ARM server containing at least two candidate proxy servers. Different candidate proxy servers have varying service capabilities, enabling different control of the ARM servers. Exemplary service capabilities of the candidate proxy servers include command issuance, service upgrades, and service inspection capabilities.

[0034] The access configuration information is used to determine the service capabilities of the candidate proxy server. Each candidate proxy server has corresponding access configuration information, and the access configuration information of the candidate proxy server is configured in the ARM server where the candidate proxy server is located.

[0035] Optionally, the access configuration information of the candidate proxy server is configured in a security access module of the ARM server. The security access module in the ARM server executes the service access method provided by the embodiment of the present disclosure.

[0036] In the ARM server, the security access module and candidate proxy servers are independent of each other. There is a many-to-one relationship between candidate proxy servers and the security access module. That is, a single security access module can be configured with access configuration information for at least two candidate proxy servers. Optionally, the access configuration information includes a service access interface, and the security access module can access services on the candidate proxy servers based on the service access interface in the access configuration information.

[0037] The service access interface of the candidate proxy server in the ARM server is not open to the outside world and is only open to the security access module. In other words, the operation and maintenance server outside the ARM server cannot directly access the service of the candidate proxy server through the service access interface of the candidate proxy server.

[0038] The security access module has a corresponding service access interface. This service access interface serves as a unified service access interface for candidate proxy servers in the ARM server and is open to the outside world. This allows the operation and maintenance server to access the candidate proxy servers in the ARM server through the security access module. Specifically, the operation and maintenance server generates a service access request based on the service access interface of the security access module.

[0039] A security access module in the ARM server, in response to a service access request received from the operation and maintenance server, determines a target proxy server for the service access request from the at least two candidate proxy servers based on access configuration information of the at least two candidate proxy servers in the ARM server. The target proxy server is generated among the candidate proxy servers, and the service capabilities of the target proxy server are consistent with the service capabilities required by the service access request.

[0040] Once the target proxy server is determined, the security access module in the ARM server sends the service access request to the target proxy server. Based on the service access request, the target proxy server uses its own service capabilities to control the ARM server, determine the service access result for the service access request, and feed the service access result back to the security access module.

[0041] The security access module in the ARM server sends the service access results fed back by the target proxy server to the operation and maintenance server.

[0042] In the disclosed embodiment, the operation and maintenance server of the ARM cloud performs service access to the candidate proxy servers in the ARM cloud through the security access module in the ARM server, avoiding the disclosure of the service access interface of the candidate proxy service in the ARM server to the outside world, and effectively ensuring the security of service access. In the disclosed embodiment, the service access interface of the security access module is used as the service access interface of the ARM server as the unified service access interface of each candidate proxy server in the ARM server, so that the operation and maintenance server can no longer distinguish between candidate proxy servers and directly send the service access request to the corresponding candidate proxy server through the security access module. The candidate proxy server uses its own service capabilities to perform service access to the ARM server, effectively improving the convenience of equipment operation and maintenance.

[0043] In an optional embodiment, sending the service access result to the operation and maintenance server includes: encrypting the service access result using a preset encryption key; and sending the encrypted service access result to the operation and maintenance server so that the operation and maintenance server can decrypt the encrypted service access result using a preset decryption key.

[0044] The preset encryption key is used to encrypt the service access results. Conversely, the preset decryption key is used to decrypt the service access results. The preset encryption key and the preset decryption key constitute an encryption / decryption key pair. The preset encryption key and the preset decryption key can be determined based on a symmetric encryption algorithm or an asymmetric encryption algorithm, depending on actual business needs and are not limited here. For example, the preset encryption key can be an SSH (Secure Shell) public key, and the corresponding preset decryption key is an SSH private key.

[0045] The security access module in the ARM server uses a preset encryption key to encrypt the service access result and sends the encrypted service access result to the operation and maintenance server. The operation and maintenance server decrypts the encrypted service access result using a preset decryption key.

[0046] This technical solution encrypts the communication data between the ARM server and the operations server through the secure access module, ensuring the security of the communication data and service access. Even if the communication data between the ARM server and the operations server is intercepted, it can still be guaranteed not to be leaked.

[0047] In an optional embodiment, the service access request is sent to the ARM server by the pressure-sharing proxy server of the operation and maintenance server; the candidate proxy server in the ARM server is a user proxy server.

[0048] The pressure-sharing proxy server is a hierarchical structure used to share the pressure on the operation and maintenance server. It can act on behalf of the operation and maintenance server to access services on candidate proxy servers within the ARM server. The candidate proxy server reports the service access results determined by the candidate proxy server to the operation and maintenance server, reducing the load on the operation and maintenance server. Optionally, the pressure-sharing proxy server is a proxy server. After generating a service access request, the operation and maintenance server sends the service access request to the ARM server via the pressure-sharing proxy service.

[0049] The candidate proxy server in the ARM server is a user proxy server. The user proxy server refers to a user-level proxy server. Optionally, the user proxy server is an agent server.

[0050] The disclosed embodiments are applicable to scenarios where an operations and maintenance server accesses an ARM server based on a proxy communication architecture. Specifically, the operations and maintenance server can access services from a user proxy server (e.g., an agent server) within the ARM server using a pressure-sharing proxy server (e.g., a proxy server). Controlling the ARM server through the user proxy server ensures the applicability of the service access method across various scenarios.

[0051] Figure 2 This is a flowchart of another service access method provided according to an embodiment of the present disclosure; this embodiment is an optional solution proposed based on the above embodiment. The embodiment of the present disclosure provides another service access method, which is an optional solution proposed based on the above embodiment. Specifically, the embodiment of the present disclosure refines the operation of "determining a target proxy server for the service access request from the at least two candidate proxy servers based on the access configuration information of at least two candidate proxy servers in the ARM server."

[0052] See also Figure 2 , the service access method provided in this embodiment includes:

[0053] S201, in response to a service access request received from an operation and maintenance server, matching an access service type in the service access request with at least two candidate access service types in the access configuration information, and determining the successfully matched candidate access service type as a target access service type.

[0054] The target proxy server that the operation and maintenance server needs to access can be determined based on the access service type. The access service type is determined by the operation and maintenance server based on actual business needs. The access service type in the service access request represents the service capability that the operation and maintenance server requests from the candidate proxy server. The candidate access service type in the access configuration information represents the service capability that the candidate proxy server can provide to the operation and maintenance server. It is understood that a candidate proxy server may not necessarily provide the service capability required by the operation and maintenance server.

[0055] In response to a server access request received from an operations and maintenance server, the security access module in the ARM server matches the access service type in the service access request with at least two candidate access service types in the access configuration information. A successful match indicates that the candidate proxy server has the service capabilities required by the operations and maintenance server. The security access module determines the matching candidate access service type as the target access service type. The target access service type is the access service type required by the operations and maintenance server.

[0056] S202: Determine, according to the access configuration information, a target service access interface associated with the target access service type from at least two candidate service access interfaces in the ARM server.

[0057] The access configuration information includes the access service type and the associated service access interface. The service access interface is used to access the service capabilities of the candidate proxy server. Each candidate proxy server has a corresponding service access interface.

[0058] The security access module determines, according to the access configuration information, a target service access interface associated with the target access service type from at least two candidate service interfaces in the ARM server.

[0059] S203: Determine the candidate proxy server pointed to by the target service access interface as the target proxy server.

[0060] The target service access interface is used to access the target proxy server and request the target access service type from the target proxy server.

[0061] The security access module determines the candidate proxy server pointed to by the target service access interface as the target proxy server.

[0062] S204: Send the service access request to the target proxy server, so that the target proxy server determines a service access result of the service access request.

[0063] The security access module sends the service access request to the target proxy server. The target proxy server uses its own service capabilities to control the ARM server based on the service access request and determines the service access result for the service access request. The target proxy server feeds the service access result back to the security access module.

[0064] S205: Send the service access result to the operation and maintenance server.

[0065] The security access module sends the service access result to the operation and maintenance server.

[0066] In the disclosed embodiment, the security access module responds to a service access request received from an operation and maintenance server by determining a target access service type from candidate access service types in the access configuration information based on the access service type in the service access request. Based on the target access service type, the security access module then determines a target access interface, and subsequently a target proxy server. In the disclosed embodiment, the operation and maintenance server can generate a service access request directly based on the access service type, without distinguishing between candidate proxy servers. The security access module then controls the ARM server by invoking the service capabilities of the target proxy server in the ARM server based on the service access request, effectively improving the convenience of device operation and maintenance.

[0067] The service access method provided by the embodiment of the present disclosure is also applicable to situations where the business scenario of the ARM server changes. The service access method provided by the embodiment of the present disclosure supports changing the existing access configuration information in the ARM server.

[0068] Specifically, the service access method of this embodiment may also include: in response to receiving a service change request, based on the access configuration information of at least two candidate proxy servers in the ARM server and the access service type in the service change request, determining the proxy server to be changed from at least two candidate proxy servers in the ARM server; and changing the access configuration information according to the access enablement status and / or access interface data in the service change request.

[0069] The proxy server to be changed can be determined from the candidate proxy servers based on the access service type in the service change request. Specifically, the security access module matches the access service type in the service change request with the candidate access service types in the access configuration information, and determines the proxy server to be changed from the candidate proxy servers based on the matching result of the access service types.

[0070] The service change request is used to change the access configuration information of the proxy server to be changed in the ARM server. Specifically, based on the service change request, the access enablement state and / or access interface data in the access configuration information can be changed. The access enablement state is used to determine whether the service capability of the candidate proxy server is disabled. The access interface data refers to the service access interface of the candidate proxy server.

[0071] The security access module modifies the access configuration information based on the access enablement status and / or access interface data in the service change request. A service change request can be generated when the business scenario of the ARM server changes. Whether the service change request is used to modify the access enablement status or access interface data in the access configuration information depends on actual business needs and is not specified here.

[0072] In addition, the service access method provided in the embodiment of the present disclosure also supports adding new access configuration information in the ARM server.

[0073] Specifically, the service access method of this embodiment may further include: in response to receiving a service addition request, obtaining access configuration information of a newly added proxy server; and updating access configuration information of candidate proxy servers in the ARM server according to the access configuration information of the newly added proxy server.

[0074] Among them, the service addition request is used to add a new proxy server in the ARM server. The service addition request can be generated when the business scenario of the ARM server changes. In response to receiving the service addition request, the security access module obtains the access configuration information of the newly added proxy server, and the access configuration information of the newly added proxy server includes at least: the access service type and the access service interface. The security access module updates the access configuration information of the candidate proxy server in the ARM server based on the access configuration information of the newly added proxy server. Optionally, the security access module adds the access configuration information of the newly added proxy server to the existing access configuration information.

[0075] The above technical solution can realize adding and / or changing the proxy server in the ARM server by processing the access configuration information, which greatly improves the scalability of the proxy server in the ARM server.

[0076] In a specific embodiment, the present disclosure provides a structural diagram of a service access system, see Figure 3The service access system 300 includes: an operation and maintenance server 310 and an ARM server 320, wherein the service access system includes at least two ARM servers 320, each of which includes a security access module 321 and at least two user agent servers 322. The operation and maintenance server 310 includes a pressure-sharing agent server 311. Considering Figure 3 For the sake of neatness and readability, not shown, and not all of the ARM server 320, the secure access module 321, and the user agent server 322 are labeled.

[0077] The pressure-sharing proxy server 311 in the operation and maintenance server 310 is communicatively connected to the user proxy server 322 in the ARM server 320 through the security access module 321 in the ARM server 320 .

[0078] The security access module 321 in the ARM server is used to execute the service access method provided by the embodiment of the present disclosure.

[0079] Optionally, a security access module is used to respond to a service access request received from an operation and maintenance server, determine a target proxy server for the service access request from at least two candidate proxy servers based on access configuration information of at least two candidate proxy servers in the ARM server; send the service access request to the target proxy server so that the target proxy server determines a service access result of the service access request; and send the service access result to the operation and maintenance server.

[0080] In the disclosed embodiment, the operation and maintenance server of the ARM cloud performs service access to the candidate proxy servers in the ARM cloud through the security access module in the ARM server, avoiding the disclosure of the service access interface of the candidate proxy service in the ARM server to the outside world, and effectively ensuring the security of service access. In the disclosed embodiment, the service access interface of the security access module is used as the service access interface of the ARM server as the unified service access interface of each candidate proxy server in the ARM server, so that the operation and maintenance server can no longer distinguish between candidate proxy servers and directly send the service access request to the corresponding candidate proxy server through the security access module. The candidate proxy server uses its own service capabilities to perform service access to the ARM server, effectively improving the convenience of equipment operation and maintenance.

[0081] Figure 4 This is a schematic diagram of the structure of a service access device provided according to an embodiment of the present disclosure. The embodiment of the present disclosure is applicable to the case where the operation and maintenance server of the ARM cloud accesses the service of the ARM server in the ARM cloud. The device can be implemented by software and / or hardware, and the device can implement the service access method described in any embodiment of the present disclosure. Figure 4 As shown, the service access device 400 includes:

[0082] The proxy determination module 401 is configured to, in response to a service access request received from the operation and maintenance server, determine a target proxy server for the service access request from among at least two candidate proxy servers in the ARM server based on access configuration information of the at least two candidate proxy servers;

[0083] A result determination module 402 is configured to send the service access request to the target proxy server so that the target proxy server determines a service access result of the service access request;

[0084] The result sending module 403 is used to send the service access result to the operation and maintenance server.

[0085] In the disclosed embodiment, the operation and maintenance server of the ARM cloud performs service access to the candidate proxy servers in the ARM cloud through the security access module in the ARM server, avoiding the disclosure of the service access interface of the candidate proxy service in the ARM server, and effectively ensuring the security of service access. In the disclosed embodiment, the service access interface of the security access module is used as the service access interface of the ARM server as the unified service access interface of each candidate proxy server in the ARM server, so that the operation and maintenance server no longer needs to distinguish between candidate proxy servers and can directly perform service access to the candidate proxy servers in the ARM server through the security access module, effectively improving the convenience of equipment operation and maintenance.

[0086] Optionally, the proxy determination module 401 includes: a type matching sub-module, used to match the access service type in the service access request with at least two candidate access service types in the access configuration information, and determine the successfully matched candidate access service type as the target access service type; an interface determination sub-module, used to determine the target service access interface associated with the target access service type from at least two candidate service access interfaces in the ARM server according to the access configuration information; and a proxy determination sub-module, used to determine the candidate proxy server pointed to by the target service access interface as the target proxy server.

[0087] Optionally, the result sending module 403 includes: an encryption submodule, used to encrypt the service access result using a preset encryption key; and a result sending submodule, used to send the encrypted service access result to the operation and maintenance server, so that the operation and maintenance server can decrypt the encrypted service access result using a preset decryption key.

[0088] Optionally, the device also includes: a proxy to be changed determination module, used to determine the proxy server to be changed from at least two candidate proxy servers in the ARM server in response to receiving a service change request, based on the access configuration information of at least two candidate proxy servers in the ARM server and the access service type in the service change request; a configuration information change module, used to change the access configuration information according to the access enablement status and / or access interface data in the service change request.

[0089] Optionally, the device also includes: a configuration information acquisition module, used to obtain access configuration information of the newly added proxy server in response to receiving a new service request; a configuration information update module, used to update the access configuration information of the candidate proxy server in the ARM server based on the access configuration information of the newly added proxy server.

[0090] Optionally, the service access request is sent by the pressure-sharing proxy server of the operation and maintenance server to the ARM server; the candidate proxy server in the ARM server is a user proxy server.

[0091] The service access device provided by the embodiments of the present disclosure can execute the service access method provided by any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects for executing the service access method.

[0092] In the technical solution disclosed herein, the collection, storage, use, processing, transmission, provision and disclosure of access configuration information and service access results involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0093] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0094] Figure 5 A schematic block diagram of an example electronic device 500 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are provided as examples only and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0095] like Figure 5As shown, the electronic device 500 includes a computing unit 501, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. Various programs and data required for the operation of the electronic device 500 can also be stored in the RAM 503. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0096] Multiple components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a magnetic disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0097] The computing unit 501 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 501 performs the various methods and processes described above, such as the service access method. For example, in some embodiments, the service access method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the computing unit 501, one or more steps of the service access method described above can be performed. Alternatively, in other embodiments, the computing unit 501 can be configured to perform the service access method by any other appropriate means (e.g., by means of firmware).

[0098] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0099] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. Such program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable service access device, so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0100] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0101] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0102] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0103] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0104] Artificial intelligence (AI) is the study of how computers can simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, specialized AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily encompass computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graphs.

[0105] Cloud computing refers to a technology system that provides network access to elastically scalable shared pools of physical or virtual resources. These resources can include servers, operating systems, networks, software, applications, and storage devices, and can be deployed and managed on-demand in a self-service manner. Cloud computing technology provides efficient and powerful data processing capabilities for the application of technologies such as artificial intelligence and blockchain, as well as for model training.

[0106] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.

[0107] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A service access method, executed by a security access module in an ARM server, comprising: In response to a service access request received from an operation and maintenance server, determining a target proxy server for the service access request from the at least two candidate proxy servers in the ARM server based on access configuration information of the at least two candidate proxy servers; wherein the service access request includes an access service type, and the access service type is used to determine the target proxy server that the operation and maintenance server needs to access; sending the service access request to the target proxy server so that the target proxy server determines a service access result of the service access request; Sending the service access result to the operation and maintenance server; The service access interface of the candidate proxy server in the ARM server is not open to the outside world, but is only open to the security access module; the service access interface of the security access module will be open to the outside world as a unified service access interface of the candidate proxy server in the ARM server; the access configuration information includes the service access interface, and the security access module can perform service access to the candidate proxy server based on the service access interface in the access configuration information; wherein the access configuration information in the ARM server is constructed to support modification when the business scenario of the ARM server changes; Among them, different candidate proxy servers have different service capabilities, and different candidate proxy servers can be used to control the ARM server differently; the service capabilities of the candidate proxy servers include: command issuance capability, service upgrade capability, and business inspection capability.

2. The method according to claim 1, wherein The determining, based on access configuration information of at least two candidate proxy servers in the ARM server, a target proxy server for the service access request from the at least two candidate proxy servers comprises: Matching the access service type in the service access request with at least two candidate access service types in the access configuration information, and determining the candidate access service type that successfully matches as the target access service type; Determining, according to the access configuration information, a target service access interface associated with the target access service type from at least two candidate service access interfaces in the ARM server; The candidate proxy server pointed to by the target service access interface is determined as the target proxy server.

3. The method according to claim 1, wherein The sending the service access result to the operation and maintenance server includes: Encrypting the service access result using a preset encryption key; The encrypted service access result is sent to the operation and maintenance server, so that the operation and maintenance server decrypts the encrypted service access result using a preset decryption key.

4. The method according to claim 1, further comprising: In response to receiving the service change request, determining a proxy server to be changed from the at least two candidate proxy servers in the ARM server based on access configuration information of the at least two candidate proxy servers in the ARM server and the access service type in the service change request; The access configuration information is modified according to the access enablement state and / or access interface data in the service change request.

5. The method according to claim 1, further comprising: In response to receiving the service addition request, obtaining access configuration information of the newly added proxy server; According to the access configuration information of the newly added proxy server, the access configuration information of the candidate proxy server in the ARM server is updated.

6. The method according to any one of claims 1 to 5, wherein The service access request is sent by the pressure-sharing proxy server of the operation and maintenance server to the ARM server; the candidate proxy server in the ARM server is a user proxy server.

7. A service access device, configured in a security access module in an ARM server, comprising: a proxy determination module, configured to, in response to a service access request received from an operation and maintenance server, determine a target proxy server for the service access request from at least two candidate proxy servers in the ARM server based on access configuration information of the at least two candidate proxy servers; wherein the service access request includes an access service type, and the access service type is used to determine the target proxy server that the operation and maintenance server needs to access; A result determination module, configured to send the service access request to the target proxy server, so that the target proxy server determines a service access result of the service access request; A result sending module, used to send the service access result to the operation and maintenance server; The service access interface of the candidate proxy server in the ARM server is not open to the outside world, but is only open to the security access module; the service access interface of the security access module will be open to the outside world as a unified service access interface of the candidate proxy server in the ARM server; the access configuration information includes the service access interface, and the security access module can perform service access to the candidate proxy server based on the service access interface in the access configuration information; wherein the access configuration information in the ARM server is constructed to support modification when the business scenario of the ARM server changes; Among them, different candidate proxy servers have different service capabilities, and different candidate proxy servers can be used to control the ARM server differently; the service capabilities of the candidate proxy servers include: command issuance capability, service upgrade capability, and business inspection capability.

8. The device according to claim 7, wherein The agent determination module includes: a type matching submodule, configured to match the access service type in the service access request with at least two candidate access service types in the access configuration information, and determine the candidate access service type that is successfully matched as the target access service type; An interface determination submodule, configured to determine, based on the access configuration information, a target service access interface associated with the target access service type from at least two candidate service access interfaces in the ARM server; The proxy determination submodule is configured to determine the candidate proxy server pointed to by the target service access interface as the target proxy server.

9. The device according to claim 7, wherein The result sending module includes: An encryption submodule, configured to encrypt the service access result using a preset encryption key; The result sending submodule is used to send the encrypted service access result to the operation and maintenance server, so that the operation and maintenance server can decrypt the encrypted service access result using a preset decryption key.

10. The apparatus according to claim 7, further comprising: a proxy server to be changed determining module configured to, in response to receiving a service change request, determine a proxy server to be changed from the at least two candidate proxy servers in the ARM server based on access configuration information of the at least two candidate proxy servers in the ARM server and an access service type in the service change request; The configuration information changing module is used to change the access configuration information according to the access enabling state and / or access interface data in the service change request.

11. The apparatus according to claim 7, further comprising: A configuration information acquisition module, configured to acquire access configuration information of a newly added proxy server in response to receiving a service addition request; The configuration information updating module is used to update the access configuration information of the candidate proxy servers in the ARM server according to the access configuration information of the newly added proxy server.

12. The device according to any one of claims 7 to 11, wherein: The service access request is sent by the pressure-sharing proxy server of the operation and maintenance server to the ARM server; the candidate proxy server in the ARM server is a user proxy server.

13. An electronic device comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the service access method according to any one of claims 1 to 6.

14. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable a computer to execute the service access method according to any one of claims 1-6.

15. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the service access method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network request processing method and device

    CN108063714A

  • Node access method and device, computer equipment and storage medium

    CN110611725A