Page access method and device, electronic device and storage medium
By using the page address characteristics corresponding to the restricted domain name in the target application to match the page address, determine its restriction, and block or forward according to the matching results, the poor information security problem when VPN accesses restricted domain name services is solved, and higher security and availability are achieved.
Patent Information
- Application Number
- CN202111044701.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-07
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-09-07
AI Technical Summary
When the prior art accesses services under a restricted domain name through a VPN, there is a problem of poor information security due to the restricted services under the domain name being accessible.
By obtaining the page access request to be sent by the target application, the page address feature corresponding to the target restricted domain name is matched with the page address of the target page to determine whether it is a restricted web page address. If it is a restricted web address, the blocking operation is performed; if it is a non-restricted web address, the page access request is forwarded through the target proxy node.
It effectively solves the problem of poor information security when VPN accesses services under restricted domain names, ensures that sensitive services under restricted domain names are not accessed, and improves the security and availability of service access.
Smart Images

Figure CN115801290B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and in particular to a method and device for accessing a page, an electronic device, and a storage medium. Background Art
[0002] Currently, under the protection of regional firewalls, all services under sensitive domain names are inaccessible. Under these sensitive domain names, there are some non-sensitive services (i.e., non-sensitive services), which can be accessed through the local VPN (Virtual Private Network) proxy on the operating system platform: the local VPN service can be started on the client, and the traffic can be intercepted and forwarded through the VPN virtual network card, making the service accessible.
[0003] However, on the operating system platform, VPN proxies are generally global. When non-sensitive services under sensitive domain names are accessed through VPN proxies, sensitive services under the domain names can also be accessed, thereby losing security.
[0004] It can be seen from this that the method of restricting services under a specific domain name through VPN in the related art has the problem of poor information security because the restricted services under the domain name can also be accessed. Summary of the invention
[0005] The embodiments of the present application provide a method and device for accessing a page, an electronic device, and a storage medium, so as to at least solve the problem of poor information security in the related art in which services under a restricted domain name are accessed through a VPN, because restricted services under the domain name can also be accessed.
[0006] According to one aspect of an embodiment of the present application, a page access method is provided, comprising: obtaining a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page; matching the page address of the target page with a page address feature corresponding to a target restricted domain name to obtain a page address matching result; when it is determined according to the page address matching result that the page address of the target page is a non-restricted web page address under the target restricted domain name, forwarding the page access request to a server of the target page through a target proxy node; when it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name, performing a shielding operation on the page access request.
[0007] According to another aspect of an embodiment of the present application, a page access device is also provided, including: a first acquisition unit, used to acquire a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page; a matching unit, used to match the page address of the target page using a page address feature corresponding to a target restricted domain name to obtain a page address matching result; a forwarding unit, used to forward the page access request to a server of the target page through a target proxy node when it is determined that the page address of the target page is a non-restricted web page address under the target restricted domain name according to the page address matching result; and an execution unit, used to perform a shielding operation on the page access request when it is determined that the page address of the target page is a restricted web page address under the target restricted domain name according to the page address matching result.
[0008] As an optional implementation scheme, the matching unit includes: a first matching module, used to use a first address feature corresponding to the restricted page address under the target restricted domain name to match the page address of the target page to obtain a first matching result, wherein the first address feature is an address feature contained in the restricted page address, and the page address matching result includes the first matching result.
[0009] As an optional implementation scheme, the matching unit includes: a second matching module, used to use a second address feature corresponding to the unrestricted page address under the target restricted domain name to match the page address of the target page to obtain a second matching result, wherein the second address feature is an address feature contained in the unrestricted page address, and the page address matching result includes the second matching result.
[0010] As an optional implementation scheme, the matching unit includes: a third matching module, used to use a target regular expression to match the page address of the target page to obtain the page address matching result, wherein the target regular expression includes a regular expression corresponding to the page address under the target restricted domain name, and the page address feature is a regular expression corresponding to the page address under the target restricted domain name.
[0011] As an optional implementation scheme, the page access request is transferred by the embedded browser of the target application; the device also includes: a detection unit, used to detect a trigger operation performed on the display interface of the embedded browser before using the page address characteristics corresponding to the target restricted domain name to match the page address of the target page, wherein the trigger operation is used to trigger access to the target page; a determination unit, used to respond to the trigger operation and determine the page address characteristics corresponding to the target restricted domain name, wherein the target restricted domain name is a restricted domain name allowed to be accessed by the embedded browser.
[0012] As an optional implementation scheme, the page access request is transferred by the embedded browser of the target application; the device also includes: a first selection unit, used to randomly select a communication port as a target port for the embedded browser before obtaining the page access request to be sent by the target application, wherein the page access request is monitored on the target port; a creation unit, used to create a target communication tunnel for the embedded browser on the target port, wherein the page access request is forwarded via the target proxy node through the target communication tunnel.
[0013] As an optional implementation scheme, the creation unit includes: a listening module, used to listen to the first connection request transferred from the embedded browser on the target port, wherein the first connection request is used to request to establish a communication connection with the target proxy node; a first sending module, used to respond to the first connection request and send a second connection request to the target proxy node, wherein the second connection request carries the port identifier of the target port and the target Internet Protocol IP address corresponding to the target application, and the second connection request is used to request the target proxy node to use the port identifier and the target IP address to establish the target communication tunnel; a first receiving module, used to receive a notification message returned by the target proxy node, wherein the notification message is used to notify the target that the communication tunnel is successfully established.
[0014] As an optional implementation scheme, the device also includes: a second acquisition unit, used to acquire a proxy node list before acquiring the page access request to be sent by the target application, wherein the proxy node list includes multiple proxy nodes in a virtual private network; a speed measurement unit, used to measure the speed of each of the multiple proxy nodes to obtain the speed measurement result of each proxy node; a second selection unit, used to select the target proxy node from the multiple proxy nodes based on the speed measurement result of each proxy node, wherein the page access request is forwarded to the server of the target page via the target proxy node in the virtual private network.
[0015] As an optional implementation scheme, the second selection unit includes: a second sending module, used to send the speed measurement results of each proxy node to the business server, so that the business server selects the target proxy node from the multiple proxy nodes based on the speed measurement results of each proxy node; a second receiving module, used to receive the node selection result returned by the business server, wherein the node selection result is used to indicate the target proxy node.
[0016] As an optional implementation scheme, the speed measurement result of each proxy node includes the parameter value of each network parameter in the multiple network parameters corresponding to each proxy node; the second selection unit includes: a sorting module, used to sort the multiple proxy nodes according to the parameter value of each network parameter, and obtain multiple sorting results, and the multiple network parameters correspond to the multiple sorting results one by one; a summing module, used to perform weighted summation of the multiple sorting results according to the weight corresponding to each network parameter, and obtain a target sorting result of the multiple proxy nodes; a selection module, used to select the proxy node with the highest ranking in the target sorting result to obtain the target proxy node.
[0017] As an optional implementation scheme, the device also includes: a sending unit, which is used to match the page address features corresponding to the target restricted domain name with the page address of the target page to obtain a page address matching result, and then, if it is determined according to the page address matching result that the page address of the target page does not belong to the target restricted domain name, send the page access request to the server of the target page.
[0018] According to another aspect of the embodiments of the present application, there is further provided an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the above-mentioned page access method through the computer program.
[0019] According to another aspect of the embodiments of the present application, a computer program product or a computer program is provided, the computer program product or the computer program includes a computer instruction, and the computer instruction is stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the above-mentioned page access method.
[0020] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the above-mentioned page access method when running.
[0021] In an embodiment of the present application, a method of using a page address feature corresponding to a restricted domain name to determine whether the accessed page address is a restricted page address under a restricted domain name is adopted. After obtaining a page access request to be sent, the page address feature corresponding to the restricted domain name can be used to match the page address to be accessed to determine whether the page address to be accessed belongs to a restricted domain name and whether it belongs to a restricted page address of a restricted domain name. If it belongs to a restricted page address of a restricted domain name, the page access request is directly shielded. If it belongs to a non-restricted page address of a restricted domain name, the page access request is forwarded through a proxy node. Since the access request of the restricted page address under the restricted domain name is directly shielded, the security of information can be guaranteed and sensitive services under the restricted domain name can be avoided from being accessed. Since the access request of the non-restricted page address under the restricted domain name is forwarded through a proxy node, the availability of non-sensitive services under the restricted domain name can be guaranteed, and the technical effect of ensuring the availability of service access and improving the security of service access can be achieved, thereby solving the problem of poor information security caused by the restricted services under the domain name being accessible in the method of accessing services under the restricted domain name through VPN in the related art. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0023] Figure 1 is a schematic diagram of an application environment of an optional page access method according to an embodiment of the present application;
[0024] Figure 2 is a schematic diagram of a process of an optional page access method according to an embodiment of the present application;
[0025] Figure 3 is a schematic diagram of an optional URL rule according to an embodiment of the present application;
[0026] Figure 4 It is a schematic diagram of an optional method of matching page addresses using URL rules according to an embodiment of the present application;
[0027] Figure 5 is a schematic diagram of an optional real-time effect of an acceleration channel according to an embodiment of the present application;
[0028] Figure 6 is a schematic diagram of an optional Webview registration page according to an embodiment of the present application;
[0029] Figure 7 is a schematic diagram of an optional registration code verification according to an embodiment of the present application;
[0030] Figure 8 is a schematic diagram of a successful registration of an optional game account according to an embodiment of the present application;
[0031] Fig. 9 is a schematic diagram of an optional acceleration interface of a game accelerator according to an embodiment of the present application;
[0032] Fig.10 is a schematic diagram of an acceleration interface of another optional game accelerator according to an embodiment of the present application;
[0033] Fig.11 is a schematic diagram of the process of another optional page access method according to an embodiment of the present application;
[0034] Fig.12 is a schematic diagram of a process of another optional method for accessing a page according to an embodiment of the present application;
[0035] Fig.13 is a schematic diagram of an optional network architecture according to an embodiment of the present application;
[0036] Fig.14 is a schematic diagram of a process of another optional method for accessing a page according to an embodiment of the present application;
[0037] Fig.15 is a schematic diagram of an optional page access device according to an embodiment of the present application;
[0038] Fig.16 It is a schematic diagram of the structure of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0039] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0040] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0041] According to one aspect of the embodiment of the present application, a method for accessing a page is provided. Optionally, as an optional implementation, the method for accessing a page can be applied to, but is not limited to, Figure 1 In the environment shown, it may include but is not limited to: a terminal device 102, which may include but is not limited to a memory 104, a processor 106 and a display 108, and a target application may be running on the terminal device, which may be a target client; a proxy server 110, and a server 112 corresponding to a restricted domain name.
[0042] Exemplarily, the process of the above page access method may include the following steps:
[0043] In step S102, the target client may obtain a page access request to be sent by the target client, and the page access request may be used to request access to the target page.
[0044] Taking the scenario of registering a game account as an example, the user can fill in the required information items in the account registration interface and click Next, which can trigger the generation of a page access request for the target page to request a verification code for verification. The target client can determine whether the page address of the target page is a restricted page address under a restricted domain name based on the configured proxy rules, that is, whether the target page is a restricted page. If it is determined that the page address of the target page is a restricted page address under a restricted domain name (that is, the sensitive service under the restricted domain name is accessed), the page access request is blocked. If it is determined that the page address of the target page is a non-restricted page address under a restricted domain name (that is, the non-sensitive service under the restricted domain name is accessed), the page access request can be forwarded.
[0045] In step S104 to step S106 , the target client forwards the page access request to the server 112 corresponding to the restricted domain name via the proxy server 110 .
[0046] Step S108 , the server 112 corresponding to the restricted domain name obtains the page resource of the target page accessed by the page access request through the database 114 and the processing engine 116 .
[0047] In steps S110-S114, the server 112 corresponding to the restricted domain name sends the page resource of the target page to the target client via the proxy server 110, and the target client can display the target page (ie, display the obtained verification code) on its display interface.
[0048] Apart from Figure 1 In addition to the examples shown, the above steps can be completed independently by the target application on the terminal device 102, or can be executed by a browser running on the terminal device, or can be executed by other programs. This application does not limit the way in which the terminal device 102 implements the method for accessing the above pages.
[0049] Optionally, as an optional implementation, Figure 2 is a flow chart of an optional page access method according to an embodiment of the present application, such as Figure 2 As shown, the process of the method for accessing the page may include the following steps:
[0050] Step S202: obtaining a page access request to be sent by the target application, wherein the page access request includes a page address of the target page, and the page access request is used to request access to the target page.
[0051] The page access method in this embodiment can be applied to the scenario of accessing services under restricted domain names through applications (e.g., clients). A variety of services can be provided under restricted domain names, including sensitive services (e.g., information query services) and non-sensitive services (e.g., verification code services). Under the protection of a regional firewall, services under restricted domain names cannot be accessed.
[0052] In order to access non-sensitive services under restricted domain names, non-sensitive services under sensitive domain names can be accessed through the local VPN proxy on the operating system platform. For example, start the VPN service on the iOS client, intercept and forward traffic through the VPN virtual network card, so that the service can be accessed. However, due to the encryption characteristics of HTTPS (Hypertext Transfer Protocol Secure), only the domain name of the traffic can be obtained through the VPN service. For example, if you access the verification code service www.xx.com / recaptcha (a non-sensitive service) under a restricted domain name, the accessed traffic can only obtain the domain name www.xx.com, without recaptcha information. On the iOS platform, VPN is for traffic of all applications, not just one application. Therefore, if VPN forwards the traffic of this domain name, it will cause the traffic of the same domain name accessed by other software (browser access to sensitive service www.xx.com) to be forwarded, thereby exposing sensitive services and losing security.
[0053] In addition, non-sensitive services under restricted domain names can also be accessed through a global HTTP (Hypertext Transfer Protocol) tunnel proxy. The local browser sets up an HTTP tunnel proxy, and the browser's traffic is forwarded through the tunnel, making the service accessible. However, if a simple global HTTP tunnel proxy is used, all traffic accessed in the Webview (embedded browser, i.e., a web view that can be embedded in a mobile terminal) will pass through the proxy, which will expose sensitive services in the browser. For example, www.xx.com can be accessed in the browser, which loses security.
[0054] Optionally, in this embodiment, accurate traffic forwarding can be performed based on rules, and only non-sensitive service traffic under a specific domain name is forwarded, and sensitive service traffic is not forwarded, so that non-sensitive services under sensitive domain names restricted by regional firewalls can be safely accessed on the operating system platform (such as verification code services under restricted domain names). The above forwarding can be traffic related to accessing services under restricted domain names in the target application. The target application can be a target client installed on a terminal device. The target application can obtain a page access request to be sent by this application, and the above access request includes the page address of the target page to be accessed.
[0055] Step S204: Use the page address feature corresponding to the target restricted domain name to match the page address of the target page to obtain a page address matching result.
[0056] There may be one or more target applications, which may be applications that use non-sensitive services under restricted domain names (or applications that access non-sensitive services under restricted domain names). The target application may have multiple functions, some of which may use non-sensitive services under restricted domain names. For example, the target application may be an accelerator (e.g., a game accelerator, which may be a mobile game accelerator), which may provide a game account registration function, where the game account registration process may be verified using a verification code service under a restricted domain name.
[0057] Optionally, some functions of the target application may also use sensitive services under restricted domain names, or use services under unrestricted domain names. In order to determine the type of service involved in the target page, the target application may use page address rules to match the page address of the target page to obtain a page address matching result. The above-mentioned target restricted domain name may be a pre-configured restricted domain name, which may be a restricted domain name associated with the target application, or a commonly used restricted domain name configured based on experience.
[0058] The above-mentioned page address rules may be used to describe page address features, for example, they may include page address features corresponding to the target restricted domain name. The page address features corresponding to the target restricted domain name are used to represent the page address under the target restricted domain name. The page address under the target restricted domain name may be a page address corresponding to a sensitive service of the target restricted domain name, that is, a restricted page address under the target restricted domain name, or a page address corresponding to a non-sensitive service of the target restricted domain name, that is, a non-restricted page address under the target restricted domain name. In addition, the page address rules may also include page address features corresponding to non-restricted domain names, and the page address matching result may also include a matching result obtained by matching the page address of the target page using the page address features corresponding to the non-restricted domain name.
[0059] Optionally, the page address may be a URL (Uniform Resource Locator), and the page address rule may be a URL rule. The above URL rule may include at least one of the following: a proxy rule, a direct connection rule, and a shielding rule. The above URL rule may be constructed using a URL obtained by packet capture, wherein the constructed proxy rule represents a non-sensitive URL (i.e., a non-restricted URL) under a restricted domain name, the constructed direct connection rule represents a URL under a non-restricted domain name, and the constructed shielding rule represents a sensitive URL (restricted URL) under a restricted domain name (e.g., a screen domain name of a regional firewall), or a URL under a domain name for illegal purposes.
[0060] Step S206: when it is determined according to the page address matching result that the page address of the target page is an unrestricted web page address under the target restricted domain name, the page access request is forwarded to the server of the target page through the target proxy node.
[0061] According to the page address matching result, the target application can determine the page type to which the page address of the target page belongs, for example, a non-restricted web page address under the target restricted domain name, a restricted web page address under the target restricted domain name. If the page address of the target page is a non-restricted web page address under the target restricted domain name, then it can be determined that the page access request accesses a non-sensitive service under the restricted domain name.
[0062] In this case, the target application can forward the page access request to the server of the target page through the target proxy node. The above-mentioned target proxy node can be a background server for traffic forwarding. The target application can include multiple controls, and the page access request can be issued by the first control (such as Webview) among the multiple controls, and forwarding the page access request to the target proxy node can be performed by the second control (such as VPN service) corresponding to the target proxy node.
[0063] For example, the target proxy node is a VPN proxy server, and the second control is a VPN service in the target application. After monitoring the page access request transferred from the first control, when matching the URL of the request, if the proxy rule is hit, the client can determine that the request accesses a non-sensitive service under a restricted domain name, and then the request can be transferred to the second control through the communication connection between the first control and the second control, and the second control sends the request to the VPN proxy server through the HTTP tunnel between the second control and the VPN proxy server, that is, the request is forwarded to the port of the local HTTP tunnel, and then the request is forwarded by the background server to the server of the requested page through the HTTP tunnel.
[0064] Step S208: When it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name, a shielding operation is performed on the page access request.
[0065] If the page address of the target page is a restricted webpage address under the target restricted domain name, then it can be determined that what the page access request accesses is a sensitive service under the restricted domain name. In this case, the target application can shield the page access request.
[0066] For example, when matching the URL of a request, if a blocking rule is hit, the traffic can be blocked and the request will not be forwarded through the VPN.
[0067] Through the embodiments provided by the present application, a page access request to be sent by a target application is obtained, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page; a page address feature corresponding to a target restricted domain name is used to match the page address of the target page to obtain a page address matching result; when it is determined according to the page address matching result that the page address of the target page is a non-restricted web page address under the target restricted domain name, the page access request is forwarded to a server of the target page through a target proxy node; when it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name, a shielding operation is performed on the page access request, thereby solving the problem of poor information security caused by the fact that sensitive services under the domain name can also be accessed when accessing services under a restricted domain name through a VPN in the related art, thereby ensuring the availability of service access and improving the security of service access.
[0068] As an optional implementation scheme, after matching the page address feature corresponding to the target restricted domain name with the page address of the target page to obtain a page address matching result, the method further includes:
[0069] When it is determined according to the page address matching result that the page address of the target page does not belong to the target restricted domain name, a page access request is sent to the server of the target page.
[0070] Similar to the above-mentioned embodiment, based on the page address matching result, the target application can determine the page type to which the page address of the target page belongs, for example, a web page address under an unrestricted domain name. If the page address of the target page does not belong to the target restricted domain name, then it can be determined that the page access request accesses a service under an unrestricted domain name.
[0071] Optionally, there may be multiple ways to determine that the page address of the target page does not belong to the target restricted domain name based on the page address matching result. For example, the page address rule may include the above-mentioned direct connection rule. If the page address matching result indicates that the page address of the target page hits the direct connection rule, it can be determined that the page address of the target page belongs to the non-restricted domain name, and then it is determined that the page address of the target page does not belong to the target restricted domain name. For another example, the page address rule may include any one of the above-mentioned proxy rules and shielding rules. If the page address matching result indicates that the page address of the target page does not hit any of the page address rules, it can be determined that the page address of the target page does not belong to the target restricted domain name.
[0072] If it is determined that the page address of the target page does not belong to the target restricted domain name, the target application can directly send the page access request to the server of the target page without going through the proxy node. For example, if the page address of the target page hits the direct connection rule, the server of the target page can be directly connected; if none of them hits (that is, none of the direct connection rule, proxy rule, and shielding rule is hit), the server of the target page can be directly connected.
[0073] Through the embodiments provided in the present application, when the page address of a page does not belong to a restricted domain name, a direct connection is made with the server corresponding to the page to send traffic, thereby improving the convenience of traffic processing.
[0074] As an optional implementation scheme, the page address feature corresponding to the target restricted domain name is used to match the page address of the target page, and the page address matching result obtained includes:
[0075] A first address feature corresponding to a restricted page address under a target restricted domain name is used to match the page address of the target page to obtain a first matching result, wherein the first address feature is an address feature included in the restricted page address, and the page address matching result includes the first matching result.
[0076] The page address feature corresponding to the target restricted domain name may include a first address feature corresponding to the restricted page address under the target restricted domain name. The above-mentioned first address feature may be an address feature contained in the restricted page address under the target restricted domain name. For example, it may indicate which characters the page address contains is the restricted page address under the target restricted domain name.
[0077] The target application may use the first address feature to match the page address of the target page to obtain a first matching result, and the above-mentioned page address matching result may include the first matching result. The first matching result is used to indicate whether the page address of the target page is a restricted page address under the target restricted domain name.
[0078] Optionally, the first address feature corresponding to the restricted page address under the target restricted domain name may include one or more address features. In the case where the first address feature includes multiple first sub-address features, the target application may use each first sub-address feature to match the page address of the target page respectively, and obtain multiple first sub-matching results, each of which is used to indicate whether the page address of the target page is a restricted page address under the target restricted domain name. When multiple first sub-matching results are used to indicate that the page address of the target page is not a restricted page address under the target restricted domain name, it is determined that the page address of the target page is not a restricted page address under the target restricted domain name; otherwise, when a certain first sub-matching result is used to indicate that the page address of the target page is a restricted page address under the target restricted domain name, it is determined that the page address of the target page is a restricted page address under the target restricted domain name.
[0079] Through the embodiments provided in the present application, by using address features corresponding to restricted page addresses under restricted domain names to perform page address matching, the accuracy of page address matching can be guaranteed, thereby improving the security of service access.
[0080] As an optional implementation scheme, the page address feature corresponding to the target restricted domain name is used to match the page address of the target page, and the page address matching result obtained includes:
[0081] A second address feature corresponding to the unrestricted page address under the target restricted domain name is used to match the page address of the target page to obtain a second matching result, wherein the second address feature is an address feature included in the unrestricted page address, and the page address matching result includes the second matching result.
[0082] The page address feature corresponding to the target restricted domain name may include a second address feature corresponding to the unrestricted page address under the target restricted domain name. The above-mentioned second address feature may be an address feature contained in the unrestricted page address under the target restricted domain name. For example, it may indicate which characters the page address contains is the unrestricted page address under the target restricted domain name.
[0083] The target application can use the second address feature to match the page address of the target page to obtain a second matching result, and the above page address matching result includes the second matching result. The second matching result is used to indicate whether the page address of the target page is an unrestricted page address under the target restricted domain name.
[0084] Optionally, the second address feature corresponding to the restricted page address under the target restricted domain name may include one or more address features. In the case where the second address feature includes multiple second sub-address features, the target application may use each second sub-address feature to match the page address of the target page respectively, and obtain multiple second sub-matching results, each of which is used to indicate whether the page address of the target page is an unrestricted page address under the target restricted domain name. When multiple second sub-matching results are used to indicate that the page address of the target page is not an unrestricted page address under the target restricted domain name, it is determined that the page address of the target page is not an unrestricted page address under the target restricted domain name; otherwise, when a certain second sub-matching result is used to indicate that the page address of the target page is an unrestricted page address under the target restricted domain name, it is determined that the page address of the target page is an unrestricted page address under the target restricted domain name.
[0085] Through the embodiments provided in the present application, by using address features corresponding to non-restricted page addresses under restricted domain names to perform page address matching, the convenience of page address matching can be improved and the security of service access can be improved.
[0086] As an optional implementation scheme, the page address feature corresponding to the target restricted domain name is used to match the page address of the target page, and the page address matching result obtained includes:
[0087] A target regular expression is used to match the page address of the target page to obtain a page address matching result, wherein the target regular expression includes a regular expression corresponding to the page address under the target restricted domain name, and the page address feature is a regular expression corresponding to the page address under the target restricted domain name.
[0088] In this embodiment, the page address rule can be constructed based on a regular expression. Correspondingly, the page address feature corresponding to the target restricted domain name can be a regular expression corresponding to the page address under the target restricted domain name, and the target regular expression can be used for page matching, that is, the target application can use the target regular expression to match the page address of the target page to obtain a page address matching result.
[0089] Here, the target regular expression may include a regular expression corresponding to a page address under a target restricted domain name, and may also include a regular expression corresponding to a page address under an unrestricted domain name, and a regular expression corresponding to a page address under other restricted domain names except the target restricted domain name.
[0090] For example, Figure 3As shown, the URL rule may include at least one of the following: direct connection rule, proxy rule, shielding rule. The URL rule may be constructed based on a regular expression (which may include a regular expression of a direct connection rule, a regular expression of a proxy rule, and a regular expression of a shielding rule).
[0091] In this embodiment, page address matching is performed through regular expressions. After the page address rule is matched successfully, the page access request can be processed using the traffic operation strategy corresponding to the matched page address rule.
[0092] For example, if the regular expression in the rule matches the URL accessed in the Webview, the traffic is processed using the policy corresponding to the rule (for example, proxy, direct connection, or blocking).
[0093] For example, Figure 4 As shown in the figure, the URL to be accessed is the Webview traffic of www.xx.com / recaptcha / index.html. URL rule 1 and URL rule 2 are used to match them respectively. The regular expression of URL rule 2 can match www.xx.com / recaptcha / index.html, but the regular expression of URL rule 1 does not match it. Therefore, the policy agent associated with URL rule 2 is used to process this Webview traffic.
[0094] Through the embodiments provided in the present application, by using regular expressions to perform page address matching, the convenience and matching efficiency of page address matching can be improved.
[0095] As an optional implementation scheme, the page access request may be transferred from an embedded browser of the target application, where the embedded browser may be a Webview on the client. Correspondingly, before using the page address feature corresponding to the target restricted domain name to match the page address of the target page, the method may further include:
[0096] S11, detecting a trigger operation performed on a display interface embedded in a browser, wherein the trigger operation is used to trigger access to a target page;
[0097] S12, in response to the triggering operation, determining a page address feature corresponding to a target restricted domain name, wherein the target restricted domain name is a restricted domain name that the embedded browser is allowed to access.
[0098] The target application may detect a trigger operation performed on the display interface of the embedded browser, and the trigger operation is used to trigger access to the target page. The trigger operation may be a touch operation, such as clicking, double-clicking, sliding, etc., on a specific button or specific area of the display interface, or a non-touch operation, such as a voice input operation, a gesture operation, etc. In response to the detected trigger operation, the target application may generate the above-mentioned page access request.
[0099] For example, for a game accelerator, after the accelerator is successfully accelerated, you can enter the acceleration details page, such as Figure 5 As shown, the curve on the page shows the real-time effect of the current acceleration channel. Click the prompt message "The account supports logging in to game A and game B, please click to view details and register" at the top of the page to open the Webview to register.
[0100] In such Figure 6 In the registration page of Webview shown in the figure, fill in the corresponding account information and click Next. Through the proxy of the accelerator, the registration page in Webview can display the normal verification code normally, such as Figure 7 As shown, after checking the picture prompted on the page, click Next to verify the registration code. Based on the accelerated channel access verification service, after the verification is passed, the game account is successfully registered. Figure 8 shown.
[0101] Optionally, in response to detecting a trigger operation, the target application may also determine a page address feature corresponding to the target restricted domain name, and the page address feature may have been pulled into the terminal device or may be to be pulled into the terminal device. Since there may be multiple restricted domain names, if all acquired restricted domain names are determined as target restricted domain names, and the data volume of the page address feature corresponding to the target restricted domain name is large, then the storage space occupied by the page address feature is large, and the amount of calculation required for page address matching is also large.
[0102] In order to save storage space and reduce the amount of calculation required for feature matching, the restricted domain name allowed to be accessed by the embedded browser (or the target application) can be configured as the target restricted domain name. The operation of obtaining the page address feature corresponding to the target restricted domain name can be performed when the target application is installed or opened, or when the target operation is performed on the target application, for example, selecting the corresponding account registration channel to register an account, or it can be performed at other times, which is not limited in this embodiment.
[0103] For example, Fig. 9As shown, for the game accelerator, a specific game account registration channel, i.e., "game account Chinese registration channel" can be selected in the game accelerator, and the account registration acceleration can be started by clicking on the acceleration. In the initial stage, the proxy rules can be pulled from the background through the network, including the above-mentioned page address rules, including the above-mentioned proxy rules and shielding rules (an example of the page address characteristics corresponding to the target restricted domain name).
[0104] Through the embodiments provided by the present application, in response to a detected trigger operation of an embedded browser, page address features corresponding to restricted domain names allowed to be accessed by the embedded browser are determined, which can save storage space and reduce the amount of calculation required for feature matching.
[0105] As an optional implementation scheme, the page access request is transferred by an embedded browser of the target application; before obtaining the page access request to be sent by the target application, the method further includes:
[0106] S21, randomly selecting a communication port as a target port for the embedded browser, wherein the page access request is monitored on the target port;
[0107] S22, creating a target communication tunnel for the embedded browser on the target port, wherein the page access request is forwarded via the target proxy node through the target communication tunnel.
[0108] In this embodiment, the page access request can be forwarded to the server of the target page via the target proxy node through the target communication tunnel. Taking the embedded browser as Webview as an example, the target application can configure a Webview proxy for Webview so as to forward the traffic of non-sensitive services under the restricted domain name through the Webview proxy.
[0109] When the proxy configuration is ready (for example, configuring the proxy rules and the target proxy node), the target application can randomly select a communication port for the Webview (that is, select a local random port) to obtain the target port, through which the traffic to be forwarded that flows in from the Webview can be monitored. For example, the above page access request is monitored on the target port.
[0110] A target communication tunnel can be created for Webview on the selected random port. Through the established target communication tunnel, traffic can be forwarded to the background server, that is, the target proxy node, so that the traffic can be forwarded to the server of the target page through the target proxy node.
[0111] Optionally, the target communication tunnel can be an HTTP tunnel. The target application can select a local random port, create an HTTP tunnel proxy service on this port, and listen to the traffic to be forwarded from the Webview. Since the port is randomly selected, the port information can be considered as random anonymous HTTP tunnel access information. The communication tunnel established is an anonymous local HTTP tunnel proxy channel. What is constructed is a local anonymous Webview HTTP tunnel proxy, which can ensure the security of the HTTP tunnel.
[0112] Through the embodiments provided in the present application, by creating a communication tunnel (eg, HTTP tunnel) on a randomly selected port, the security of the communication tunnel can be guaranteed.
[0113] As an optional implementation, creating a target communication tunnel for the embedded browser on the target port includes:
[0114] S31, listening on a target port for a first connection request transferred from an embedded browser, wherein the first connection request is used to request to establish a communication connection with a target proxy node;
[0115] S32, in response to the first connection request, sending a second connection request to the target proxy node, wherein the second connection request carries a port identifier of the target port and a target Internet protocol IP address corresponding to the target application, and the second connection request is used to request the target proxy node to establish a target communication tunnel using the port identifier and the target IP address;
[0116] S33, receiving a notification message returned by the target proxy node, wherein the notification message is used to notify the target that the communication tunnel is successfully established.
[0117] The target communication tunnel can be created based on the monitored connection request. The target application can monitor traffic on a local random port, for example, TCP (Transmission Control Protocol) traffic. The embedded browser (for example, Webview) has a proxy set up, and the traffic therein will be forwarded to this port.
[0118] After receiving traffic on the target port, if the traffic is a first connection request for requesting to establish a communication connection with the target proxy node, in response to the first connection request, the target application may send a second connection request to the target proxy node to request to establish a connection with the target proxy node. The second connection request may carry a port identifier of the target port and a target IP (Internet Protocol) address corresponding to the target application, and the request is to establish a tunnel with the target proxy node, and the established communication tunnel is the target communication tunnel.
[0119] After receiving the second connection request, the target proxy node can extract the port identifier and the target IP address of the target port, establish a connection with the target port and the target IP address, that is, a target communication tunnel (which can be an HTTP tunnel), and send a notification message to the target application to notify that the connection (that is, the target communication tunnel) is successfully established. The target application receives the notification message and determines that the connection is successfully established. Optionally, after receiving the notification message, the target application can send a notification message to the embedded browser that the connection is successfully established.
[0120] For example, taking the game accelerator as an example, after selecting the Chinese registration channel for the game account and clicking on the acceleration to start the account registration acceleration, the game accelerator enters the acceleration preparation process, such as Fig.10 At this stage, the game accelerator will build a local HTTP tunnel proxy and access the acceleration channel in the background. When the game accelerator completes the preparation, the progress will reach 100%.
[0121] Traffic forwarding uses an HTTP tunnel proxy, such as Fig.11 As shown, the flow processing process may include the following steps:
[0122] In step S1102, the client listens to the traffic to be forwarded (i.e., TCP traffic) on a local random port. Since the Webview has a proxy set up, the traffic will be forwarded to this port.
[0123] Step S1104, the client receives the Webview forwarding traffic.
[0124] Step S1106, determine whether it is a CONNECT request, if so, execute step S1108, otherwise, execute step S1116.
[0125] Step S1108, establishing a connection with the background.
[0126] If it is a CONNECT request, the client can send the target IP and port to the backend (i.e., the target proxy node) to request to establish a tunnel with the backend. After receiving the request, the backend can establish a connection with the target IP and port, and notify the client after the connection is successfully established.
[0127] Step S1110: the background establishes a connection with the target server.
[0128] The target server may be a server corresponding to a restricted domain name that the client or Webview allows to access, which may be pre-configured in the background or pulled from the network.
[0129] Steps S1112 to S1114: receiving a background notification that the connection is successfully established, and notifying Webview that the tunnel is established.
[0130] After receiving the notification from the background, the client can reply to Webview that CONNECT is successful.
[0131] Steps S1116 to S1118, notify the tunnel to transfer traffic to the background, and the background forwards the traffic to the target server.
[0132] If it is not a CONNECT request, it means that the connection has been established and traffic needs to be forwarded. The client can send traffic to the backend through the previously created tunnel, and forward it to the target service through the backend.
[0133] Through the embodiments provided by the present application, by using the target IP and port to establish a communication tunnel for the embedded browser through the monitored connection request, the convenience and accuracy of connection establishment can be improved.
[0134] As an optional implementation scheme, before obtaining the page access request to be sent by the target application, the method further includes:
[0135] S41, obtaining a proxy node list, wherein the proxy node list includes a plurality of proxy nodes in a virtual private network;
[0136] S42, measuring the speed of each proxy node among the multiple proxy nodes to obtain a speed measurement result of each proxy node;
[0137] S43, selecting a target proxy node from multiple proxy nodes based on the speed test result of each proxy node, wherein the page access request is forwarded to the server of the target page via the target proxy node in the virtual private network.
[0138] The target proxy node may be pre-configured, for example, a proxy node through which traffic forwarding is pre-configured, or may be selected from multiple proxy nodes that are allowed to forward traffic. The multiple proxy nodes may be acquired when the target application is started, or after the target operation is performed on the target application (for example, when acceleration is started), or may be acquired at other times, which is not limited in this embodiment.
[0139] The target application can pull a proxy node list (e.g., a channel access node list) from a business backend (e.g., a business server) through the network. The proxy node list includes multiple proxy nodes, and the multiple proxy nodes can be located in a VPN. The page access request is forwarded to the target server via the target proxy node in the VPN. For any proxy node, the target application can measure its speed and obtain the speed measurement result of each proxy node.
[0140] The speed measurement of the proxy node can use the ICMP (Internet Control Message Protocol) protocol, the agreed UDP (User Datagram Protocol) protocol, or other protocols that can perform node speed measurement. Taking the ICMP protocol as an example, the client can use the ICMP protocol to perform a Ping (Packet Internet Groper) speed measurement on each proxy node. There can be multiple strategies for the speed measurement of the proxy node, which can be configured as needed. For example, 10 packets can be Pinged to the proxy node every 1 second for a total of 3 times.
[0141] Based on the speed measurement result of each proxy node, a target proxy node can be selected from multiple proxy nodes, and the target application can know the selected target proxy node. Optionally, the above-mentioned target proxy node can be selected by the target application. For example, the speed measurement result of each proxy node can be displayed on the target client, and in response to the detected selection operation performed on the target proxy node among the multiple proxy nodes, the target proxy node can be determined.
[0142] Through the embodiments provided by the present application, the proxy node for traffic forwarding is selected based on the speed measurement result of each proxy node, which can improve the rationality of the selection of the proxy node; and, by selecting the proxy node in the VPN for traffic forwarding, the security of data transmission can be guaranteed.
[0143] As an optional implementation scheme, selecting a target proxy node from multiple proxy nodes based on the speed measurement result of each proxy node includes:
[0144] S51, sending the speed measurement result of each proxy node to the business server, so that the business server selects a target proxy node from multiple proxy nodes based on the speed measurement result of each proxy node;
[0145] S52, receiving a node selection result returned by the service server, wherein the node selection result is used to indicate a target proxy node.
[0146] To ensure the flexibility of the node selection strategy, the proxy node can be selected in the background rather than on the client. The target application can send the speed test results of each proxy node to the business server through the network, requesting the business server to select a proxy node for traffic forwarding. In response to the received speed test results of each proxy node, the business server can select a target proxy node from multiple proxy nodes.
[0147] After selecting the target proxy node, the service server may return a node selection result to the target application, where the node selection result is used to indicate the selected target proxy node. Based on the received node selection result, the target application may determine the target proxy node.
[0148] Through the embodiments provided in the present application, the flexibility of node selection can be improved by selecting a proxy node for traffic forwarding in the background instead of on the client.
[0149] As an optional implementation scheme, the proxy node speed test may measure at least one network parameter, which may include but is not limited to at least one of the following: packet loss, delay, jitter, and load. The proxy node may be selected based on the parameter value of a network parameter. For example, a target proxy node is selected from multiple proxy nodes based on the load of each proxy node. Optionally, in this embodiment, the proxy node may be selected based on multiple network parameters. Correspondingly, the speed test result of each proxy node may include the parameter value of each network parameter in the multiple network parameters corresponding to it. There may be multiple ways to select a proxy node based on multiple network parameters. The proxy node may be selected based on a certain network parameter as a benchmark and other network parameters as a reference. Alternatively, the proxy node may be selected based on the parameter values of multiple network parameters.
[0150] For example, multiple proxy nodes may be sorted according to the first network parameter to obtain a first sorting result; and the proxy node at the top of the reference sorting result may be selected from the proxy nodes whose parameter values of the second network parameter are greater than or equal to the target parameter threshold according to the order of the multiple proxy nodes in the reference sorting result to obtain the target proxy node. Alternatively, the proxy nodes whose parameter values of the second network parameter are greater than or equal to the target parameter threshold may be sorted to obtain a second sorting result, and the proxy node at the top of the second sorting result may be determined as the target proxy node.
[0151] For another example, a proxy node may be randomly selected from the proxy nodes whose parameter values of corresponding network parameters are greater than or equal to the corresponding parameter thresholds to obtain the target proxy node.
[0152] As an optional method, selecting a target proxy node from multiple proxy nodes based on the speed measurement result of each proxy node includes:
[0153] S61, sorting the plurality of proxy nodes according to the parameter value of each network parameter to obtain a plurality of sorting results, wherein the plurality of network parameters correspond to the plurality of sorting results one by one;
[0154] S62, performing weighted summation on the multiple sorting results according to the weight corresponding to each network parameter to obtain target sorting results of the multiple proxy nodes;
[0155] S63, selecting the proxy node with the highest ranking in the target sorting result to obtain the target proxy node.
[0156] In order to select the best node, the target application (which may also be the service server in the above embodiment) may sort the multiple proxy nodes according to the parameter value of each network parameter to obtain multiple sorting results, and the multiple network parameters correspond to the multiple sorting results one by one. For example, the speed test results (such as Ping results) may be ranked according to packet loss, delay, jitter, and load to obtain four ranking results.
[0157] For multiple sorting results, the multiple sorting results can be weighted and summed according to the weight corresponding to each network parameter to obtain the target sorting results of multiple proxy nodes. Here, the multiple proxy nodes can be sorted according to the parameter value of each network parameter according to the same sorting standard, and the above same sorting standard can be sorted in order from best to worst.
[0158] Each network parameter can be assigned a corresponding weight. When performing weighted summation on multiple sorting results, each proxy node can be weighted summed according to its ranking in each sorting result and the corresponding weight to obtain the weighted result of the proxy node. The target sorting result can be obtained by sorting the weighted results from small to large. The target application can select the proxy node with the highest ranking in the target sorting result to obtain the target proxy node.
[0159] For example, the number of proxy nodes is 4, namely node 1, node 2, node 3 and node 4, and the network parameters and corresponding weights are: packet loss 3; delay 1; jitter 2; load 1. In order to ensure the availability of the proxy channel, the proxy channel can be routed, including speed measurement and selection, such as Fig.12 As shown, the process of proxy node speed measurement and selection may include the following steps:
[0160] Step S1202: The client obtains the access node list of the proxy channel from the background through the protocol.
[0161] Step S1204: The client uses the ICMP protocol to perform a ping test on the access nodes in the access node list.
[0162] Step S1206, determine whether there are any access nodes whose speed has not been measured, if so, continue to execute step S1204, otherwise, execute step S1208.
[0163] Step S1208: After all access nodes have completed speed measurement, the speed measurement results of all access nodes are sent to the background, requesting the background to select.
[0164] Step S1210, after receiving the speed measurement result, the background selects the optimal node based on the strategy.
[0165] There are many strategies for selecting the best node. For example, the speed test results can be ranked according to packet loss, delay, jitter, and load, and the ranking results are: node 1 [1, 2, 2, 1]; node 2 [4, 3, 4, 4]; node 3 [2, 1, 1, 2]; node 4 [3, 4, 3, 3]. Then, according to the aforementioned weighted sorting, the weighted sum result is: node 1 10; node 2 27; node 3 11; node 4 22, and the final ranking result of the four proxy nodes is: node 1, node 3, node 4, node 2. Finally, the node with the highest ranking is selected, and the selected proxy node is node 1.
[0166] In step S1212, the client receives the optimal node selected by the background, and uses the optimal node for traffic forwarding, for example, accesses the acceleration channel between the optimal node, and accesses non-sensitive services under the restricted domain name through the optimal node.
[0167] Through the embodiments provided in the present application, the access nodes are sorted respectively based on different network parameters, and a weighted sum is taken for multiple sorting results, which can improve the rationality of the selection of the proxy node.
[0168] The following is an explanation of the access method of the above page in conjunction with an optional example. In this optional example, the target application is a game accelerator, the embedded browser is Webview, and the target communication tunnel is an HTTP tunnel. The page address characteristics corresponding to the target restricted domain name include proxy rules and shielding rules in the URL rules, and the URL rules also include: direct connection rules.
[0169] This optional example provides a secure access solution for restricted pages on the iOS platform. It builds a local anonymous Webview HTTP tunnel proxy based on rules, so that restricted non-sensitive services under sensitive domain names can be used in Webview, solving the availability problem while ensuring security. During the access process, routing is selected based on policies to ensure the availability and acceleration effect of the proxy.
[0170] The page access method in this optional example can be applied to Fig.13 The network architecture shown in Figure 1 is as follows. Fig.13 As shown, the network architecture may include: a client running on a terminal device, which may include a Webview and a VPN service; a background server (ie, the aforementioned target access node); and a target server, which may be a server corresponding to a restricted domain name.
[0171] like Fig.14As shown, the process of the page access method in this optional example may include the following steps:
[0172] Step S1402, start.
[0173] Step S1404 to step S1406, at the start stage, the proxy rules and the access node list of the channel are pulled from the background through the network.
[0174] Step S1408 to step S1410: test the speed of the access nodes, and select the best access point based on the speed test results.
[0175] Step S1412, when the proxy configuration is ready, select a local random port, create an HTTP tunnel proxy service on this port, connect to the background acceleration channel, and monitor the traffic to be forwarded that flows in from Webview.
[0176] Step S1414 to step S1418, when the HTTP tunnel proxy service is ready, set the URL rule and proxy service information of Webview, and the Webview proxy is established successfully.
[0177] URL rules are built based on regular expressions and contain strategies for operating traffic, including proxy rules, direct connection rules, and shielding rules. The proxy service information is the IP and port of the local HTTP tunnel proxy access. After setting the above information, the Webview proxy is successfully established.
[0178] Step S1420, when the Webview proxy is successfully established, wait for the user to access the restricted page through the Webview.
[0179] Steps S1422 to S1424, when the user starts to access a page, the currently accessed URL is obtained through the Webview proxy, and the URL is matched with the URL rule based on a regular expression.
[0180] Step S1426, determine whether the proxy rule is hit, if so, execute step S1428, otherwise, execute step S1434.
[0181] Step S1428: If the proxy rule is matched, the request is forwarded to the port of the local HTTP tunnel.
[0182] Step S1430 to step S1432, forwarding the request to the background server through the tunnel, and the background server forwarding the request to the target server.
[0183] Step S1434, determine whether the direct connection rule is hit, if so, execute step S1436, otherwise, execute step S1438.
[0184] Step S1436: If the direct connection rule is matched, a direct connection is made to the target server (the server requested to be accessed), and the request is sent to the target server.
[0185] Step S1438, determine whether the shielding rule is hit, if so, execute step S14340, otherwise, execute step S1442.
[0186] Step S1440: If the blocking rule is matched, the traffic is blocked.
[0187] Step S1442: If there is no hit, directly connect to the target server and send the request to the target server.
[0188] Step S1444, end.
[0189] Through this optional example, based on the rule-based Webview proxy (HTTP proxy process), traffic is forwarded to the anonymous local HTTP tunnel proxy channel in a precise and secure manner. Non-sensitive services are made available while shielding sensitive services with the same domain name, thereby ensuring the legitimacy and security of service access. The anonymous establishment process of the HTTP tunnel based on policy routing ensures the availability and confidentiality of the HTTP tunnel, thereby solving the problem of non-sensitive services under sensitive domain names being unavailable on the page on the iOS platform.
[0190] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.
[0191] According to another aspect of the embodiment of the present application, a device for accessing a page for implementing the above-mentioned method for accessing a page is also provided. Fig.15 As shown, the device comprises:
[0192] A first acquisition unit 1502 is used to acquire a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page;
[0193] A matching unit 1504 is used to match the page address of the target page using the page address feature corresponding to the target restricted domain name to obtain a page address matching result;
[0194] The forwarding unit 1506 is used to forward the page access request to the server of the target page through the target proxy node when it is determined that the page address of the target page is an unrestricted web page address under the target restricted domain name according to the page address matching result;
[0195] The execution unit 1508 is used to perform a shielding operation on the page access request when it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name.
[0196] It should be noted that the first acquisition unit 1502 in this embodiment can be used to execute the above step S202, the matching unit 1504 in this embodiment can be used to execute the above step S204, the forwarding unit 1506 in this embodiment can be used to execute the above step S206, and the execution unit 1508 in this embodiment can be used to execute the above step S208.
[0197] Through the embodiments provided by the present application, a page access request to be sent by a target application is obtained, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page; a page address feature corresponding to a target restricted domain name is used to match the page address of the target page to obtain a page address matching result; when it is determined according to the page address matching result that the page address of the target page is a non-restricted web page address under the target restricted domain name, the page access request is forwarded to a server of the target page through a target proxy node; when it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name, a shielding operation is performed on the page access request, thereby solving the problem of poor information security caused by the restricted services under the domain name being accessible through a VPN in the related art, thereby ensuring the availability of service access and improving the security of service access.
[0198] As an optional implementation, the matching unit 1504 includes:
[0199] The first matching module is used to use the first address feature corresponding to the restricted page address under the target restricted domain name to match the page address of the target page to obtain a first matching result, wherein the first address feature is the address feature contained in the restricted page address, and the page address matching result includes the first matching result.
[0200] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0201] As an optional implementation, the matching unit 1504 includes:
[0202] The third matching module is used to use the second address feature corresponding to the unrestricted page address under the target restricted domain name to match the page address of the target page to obtain a second matching result, wherein the second address feature is the address feature contained in the unrestricted page address, and the page address matching result includes the second matching result.
[0203] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0204] As an optional implementation, the matching unit 1504 includes:
[0205] The third matching module is used to use the target regular expression to match the page address of the target page to obtain a page address matching result, wherein the target regular expression includes a regular expression corresponding to the page address under the target restricted domain name, and the page address feature is a regular expression corresponding to the page address under the target restricted domain name.
[0206] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0207] As an optional implementation scheme, the page access request is transferred by an embedded browser of the target application; the above-mentioned device also includes:
[0208] a detection unit, configured to detect a trigger operation performed on a display interface of the embedded browser before matching the page address of the target page using a page address feature corresponding to the target restricted domain name, wherein the trigger operation is used to trigger access to the target page;
[0209] The determination unit is used to respond to the trigger operation and determine the page address feature corresponding to the target restricted domain name, wherein the target restricted domain name is a restricted domain name that the embedded browser is allowed to access.
[0210] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0211] As an optional implementation scheme, the page access request is transferred by an embedded browser of the target application; the above-mentioned device also includes:
[0212] A first selection unit is used to randomly select a communication port as a target port for the embedded browser before obtaining a page access request to be sent by a target application, wherein the page access request is monitored on the target port;
[0213] The creation unit is used to create a target communication tunnel for the embedded browser on the target port, wherein the page access request is forwarded via the target proxy node through the target communication tunnel.
[0214] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0215] As an optional implementation scheme, the creation unit includes:
[0216] A monitoring module, used for monitoring a first connection request transferred from an embedded browser on a target port, wherein the first connection request is used for requesting to establish a communication connection with a target proxy node;
[0217] A first sending module, configured to respond to the first connection request and send a second connection request to a target proxy node, wherein the second connection request carries a port identifier of a target port and a target Internet protocol IP address corresponding to a target application, and the second connection request is used to request the target proxy node to establish a target communication tunnel using the port identifier and the target IP address;
[0218] The first receiving module is used to receive a notification message returned by a target proxy node, wherein the notification message is used to notify the target communication tunnel that is successfully established.
[0219] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0220] As an optional implementation scheme, the above device also includes:
[0221] A second acquisition unit is used to acquire a proxy node list before acquiring a page access request to be sent by a target application, wherein the proxy node list includes a plurality of proxy nodes in a virtual private network;
[0222] A speed measuring unit, used to measure the speed of each proxy node among the multiple proxy nodes to obtain a speed measuring result of each proxy node;
[0223] The second selection unit is used to select a target proxy node from multiple proxy nodes based on the speed test result of each proxy node, wherein the page access request is forwarded to the server of the target page via the target proxy node in the virtual private network.
[0224] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0225] As an optional implementation scheme, the second selection unit includes:
[0226] A second sending module is used to send the speed measurement result of each proxy node to the business server, so that the business server selects a target proxy node from multiple proxy nodes based on the speed measurement result of each proxy node;
[0227] The second receiving module is used to receive the node selection result returned by the business server, wherein the node selection result is used to indicate the target proxy node.
[0228] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0229] As an optional implementation scheme, the speed measurement result of each proxy node includes a parameter value of each network parameter among a plurality of network parameters corresponding to each proxy node; and the second selection unit includes:
[0230] A sorting module is used to sort the multiple proxy nodes according to the parameter value of each network parameter to obtain multiple sorting results, and the multiple network parameters correspond to the multiple sorting results one by one;
[0231] A summing module is used to perform weighted summing of multiple sorting results according to the weight corresponding to each network parameter to obtain target sorting results of multiple proxy nodes;
[0232] The selection module is used to select the proxy node with the highest ranking in the target sorting result to obtain the target proxy node.
[0233] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0234] As an optional implementation scheme, the above device also includes:
[0235] The sending unit is used to match the page address of the target page with the page address feature corresponding to the target restricted domain name, and after obtaining the page address matching result, if it is determined according to the page address matching result that the page address of the target page does not belong to the target restricted domain name, send the page access request to the server of the target page.
[0236] Optional examples of this implementation scheme can refer to the examples shown in the above-mentioned page access method, which will not be described in detail in this implementation scheme.
[0237] According to another aspect of the embodiment of the present application, an electronic device for implementing the above-mentioned page access method is also provided. The electronic device may be Figure 1 The terminal device or server shown in the figure. This embodiment is described by taking the electronic device as a server as an example. Fig.16As shown, the electronic device includes a memory 1602 and a processor 1604. The memory 1602 stores a computer program, and the processor 1604 is configured to execute the steps in any of the above method embodiments through the computer program.
[0238] Optionally, in this embodiment, the electronic device may be located in at least one network device among a plurality of network devices of a computer network.
[0239] Optionally, in this embodiment, the processor may be configured to perform the following steps through a computer program:
[0240] S1, obtaining a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page;
[0241] S2, using the page address feature corresponding to the target restricted domain name to match the page address of the target page to obtain a page address matching result;
[0242] S3, when it is determined according to the page address matching result that the page address of the target page is an unrestricted web page address under the target restricted domain name, forwarding the page access request to the server of the target page through the target proxy node;
[0243] S4, when it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name, a shielding operation is performed on the page access request.
[0244] Alternatively, a person skilled in the art may understand that: Fig.16 The structure shown is for illustration only, and the electronic device may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (Mobile Internet Devices, MID), a PAD, or other terminal devices. Fig.16 The structure of the electronic device is not limited. Fig.16 More or fewer components (such as network interfaces, etc.) as shown in, or with Fig.16 Different configurations are shown.
[0245] Among them, the memory 1602 can be used to store software programs and modules, such as the program instructions / modules corresponding to the page access method and device in the embodiment of the present application. The processor 1604 executes various functional applications and data processing by running the software programs and modules stored in the memory 1602, that is, realizing the above-mentioned page access method. The memory 1602 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 1602 may further include a memory remotely located relative to the processor 1604, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. As an example, Fig.16 As shown, the memory 1602 may include but is not limited to the first acquisition unit 1502, matching unit 1504, forwarding unit 1506 and execution unit 1508 in the page access device. In addition, other module units in the page access device may also be included but are not limited to, which will not be repeated in this example.
[0246] Optionally, the transmission device 1606 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wired network and a wireless network. In one example, the transmission device 1606 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices and routers via a network cable so as to communicate with the Internet or a local area network. In one example, the transmission device 1606 is a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0247] In addition, the electronic device further includes: a display 1608 for displaying a target page, and can also be used to display a display interface of an embedded browser; and a connection bus 1610 for connecting various module components in the electronic device.
[0248] In other embodiments, the terminal device or server may be a node in a distributed system, wherein the distributed system may be a blockchain system, and the blockchain system may be a distributed system formed by connecting the multiple nodes through network communication. Among them, the nodes may form a peer-to-peer (P2P, Peer To Peer) network, and any form of computing device, such as a server, terminal and other electronic devices, may become a node in the blockchain system by joining the peer-to-peer network.
[0249] According to one aspect of the present application, a computer program product or computer program is provided, the computer program product or computer program includes computer instructions, the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs the methods provided in the above various optional implementations, wherein the computer program is configured to perform the steps of any of the above method embodiments when running.
[0250] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for performing the following steps:
[0251] S1, obtaining a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page;
[0252] S2, using the page address feature corresponding to the target restricted domain name to match the page address of the target page to obtain a page address matching result;
[0253] S3, when it is determined according to the page address matching result that the page address of the target page is an unrestricted web page address under the target restricted domain name, forwarding the page access request to the server of the target page through the target proxy node;
[0254] S4, when it is determined according to the page address matching result that the page address of the target page is a restricted web page address under the target restricted domain name, a shielding operation is performed on the page access request.
[0255] Optionally, in this embodiment, a person of ordinary skill in the art may understand that all or part of the steps in the various methods of the above embodiments may be completed by instructing hardware related to the terminal device through a program, and the program may be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.
[0256] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0257] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application.
[0258] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0259] In the several embodiments provided in the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0260] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0261] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, each unit may exist physically separately, or at least two units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0262] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for accessing a page, characterized in that: include: Obtaining a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page; When the target communication tunnel is created, at least one page address feature carried in at least one page address rule matching the target communication tunnel is used to match the page address of the target page to obtain a page address matching result; In the case where the page address matching result indicates that the page address of the target page matches the non-restricted web page address feature carried in the first page address rule, the page access request is forwarded to the server of the target page; When the page address matching result indicates that the page address of the target page matches the unrestricted web page address feature under the target restricted domain name carried in the second page address rule, forwarding the page access request to a target proxy node through the target communication tunnel, wherein the target proxy node is used to forward the page access request to a server of the target page; When the page address matching result indicates that the page address of the target page matches the restricted web page address feature under the target restricted domain name carried in the second page address rule, a shielding operation is performed on the page access request.
2. The method according to claim 1, characterized in that The using at least one page address feature carried in at least one page address rule matching the target communication tunnel to match the page address of the target page to obtain a page address matching result includes: A first address feature corresponding to the restricted page address under the target restricted domain name is used to match the page address of the target page to obtain a first matching result, wherein the first address feature is an address feature contained in the restricted page address, and the page address matching result includes the first matching result.
3. The method according to claim 1, characterized in that The using at least one page address carried in at least one page address rule matching the target communication tunnel to perform matching to obtain a page address matching result includes: A second address feature corresponding to the unrestricted page address under the target restricted domain name is used to match the page address of the target page to obtain a second matching result, wherein the second address feature is an address feature contained in the unrestricted page address, and the page address matching result includes the second matching result.
4. The method according to claim 1, characterized in that The using at least one page address feature carried in at least one page address rule matching the target communication tunnel to match the page address of the target page to obtain a page address matching result includes: A target regular expression is used to match the page address of the target page to obtain the page address matching result, wherein the target regular expression includes a regular expression corresponding to the page address under the target restricted domain name, and the page address feature is a regular expression corresponding to the page address under the target restricted domain name.
5. The method according to claim 1, characterized in that The page access request is transferred by the embedded browser of the target application; before matching the page address of the target page with at least one page address feature carried in at least one page address rule matched with the target communication tunnel, the method further includes: Detecting a trigger operation performed on the display interface of the embedded browser, wherein the trigger operation is used to trigger access to the target page; In response to the triggering operation, the page address feature corresponding to the target restricted domain name is determined, wherein the target restricted domain name is a restricted domain name that the embedded browser is allowed to access.
6. The method according to claim 1, characterized in that The page access request is transferred by the embedded browser of the target application; before obtaining the page access request to be sent by the target application, the method further includes: Randomly selecting a communication port as a target port for the embedded browser, wherein the page access request is monitored on the target port; A target communication tunnel is created for the embedded browser on the target port, wherein the page access request is forwarded via the target proxy node through the target communication tunnel.
7. The method according to claim 6, characterized in that The creating a target communication tunnel for the embedded browser on the target port comprises: Listening on the target port for a first connection request transferred from the embedded browser, wherein the first connection request is used to request to establish a communication connection with the target proxy node; In response to the first connection request, sending a second connection request to the target proxy node, wherein the second connection request carries a port identifier of the target port and a target Internet Protocol IP address corresponding to the target application, and the second connection request is used to request the target proxy node to use the port identifier and the target IP address to establish the target communication tunnel; A notification message returned by the target proxy node is received, wherein the notification message is used to notify the target communication tunnel that establishment is successful.
8. The method according to claim 1, characterized in that Before obtaining the page access request to be sent by the target application, the method further includes: Obtaining a proxy node list, wherein the proxy node list includes a plurality of proxy nodes in a virtual private network; Performing speed measurement on each proxy node among the plurality of proxy nodes to obtain a speed measurement result of each proxy node; The target proxy node is selected from the multiple proxy nodes based on the speed measurement result of each proxy node, wherein the page access request is forwarded to the server of the target page via the target proxy node in the virtual private network.
9. The method according to claim 8, characterized in that The selecting a target proxy node from the plurality of proxy nodes based on the speed measurement result of each proxy node includes: Sending the speed measurement result of each proxy node to the service server, so that the service server selects the target proxy node from the multiple proxy nodes based on the speed measurement result of each proxy node; A node selection result returned by the service server is received, wherein the node selection result is used to indicate the target proxy node.
10. The method according to claim 8, characterized in that The speed measurement result of each proxy node includes a parameter value of each network parameter among a plurality of network parameters corresponding to each proxy node; The selecting a target proxy node from the plurality of proxy nodes based on the speed measurement result of each proxy node includes: Sorting the plurality of proxy nodes respectively according to the parameter value of each network parameter to obtain a plurality of sorting results, wherein the plurality of network parameters correspond to the plurality of sorting results one by one; Performing weighted summation on the multiple sorting results according to the weight corresponding to each of the network parameters to obtain target sorting results of the multiple proxy nodes; The proxy node with the highest ranking in the target sorting result is selected to obtain the target proxy node.
11. The method according to any one of claims 1 to 10, characterized in that After matching the page address of the target page using at least one page address feature carried in at least one page address rule matching the target communication tunnel to obtain a page address matching result, the method further includes: When it is determined according to the page address matching result that the page address of the target page does not belong to the target restricted domain name, the page access request is sent to the server of the target page.
12. A device for accessing a page, characterized in that: include: A first acquisition unit, configured to acquire a page access request to be sent by a target application, wherein the page access request includes a page address of a target page, and the page access request is used to request access to the target page; a matching unit, configured to, when the target communication tunnel is created, match the page address of the target page using at least one page address feature carried in at least one page address rule matching the target communication tunnel to obtain a page address matching result; A forwarding unit, configured to forward the page access request to a server of the target page when the page address matching result indicates that the page address of the target page matches the non-restricted web page address feature carried in the first page address rule; When the page address matching result indicates that the page address of the target page matches the unrestricted web page address feature under the target restricted domain name carried in the second page address rule, forwarding the page access request to a target proxy node through the target communication tunnel, wherein the target proxy node is used to forward the page access request to a server of the target page; An execution unit is used to perform a shielding operation on the page access request when the page address matching result indicates that the page address of the target page matches the restricted web page address under the target restricted domain name carried in the second page address rule.
13. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the method according to any one of claims 1 to 11 through the computer program.
14. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.
15. A computer-readable storage medium, the computer-readable storage medium comprising a stored program, wherein: When the program is executed, the method described in any one of claims 1 to 11 is executed.
Citation Information
Patent Citations
VPN resource access method, device, electronic equipment and medium
CN113347072A