Data processing method, system, computer device and storage medium
By integrating connection identity scheduling functionality into the QUIC load balancing cluster and leveraging the encryption and decryption capabilities of nodes, the problem of additional deployment of scheduling devices in the QUIC protocol is solved, achieving low-cost, high-security QUIC protocol message transmission and session persistence.
Patent Information
- Application Number
- CN202310382541.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2043-03-31
AI Technical Summary
Existing technologies require additional deployment of scheduling equipment in QUIC protocol clusters, which increases deployment costs and operational complexity, and may compromise the security of the QUIC protocol in connection migration scenarios.
The connection identity scheduling function of QUIC protocol messages is integrated into the QUIC load balancing cluster. The encryption and decryption capabilities of the cluster nodes are used to obfuscate the connection identity, so as to achieve low-cost and high-security message calling and transmission.
No additional scheduling equipment is required, which reduces deployment costs and operational complexity, shortens service launch time, and ensures high security and session persistence of QUIC protocol messages.
Smart Images

Figure CN116389592B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, and particularly relates to a data processing method and system, a computer device and a storage medium. BACKGROUND
[0002] A quick network transmission protocol (QUIC) based on a user datagram protocol (UDP) can identify a connection identity document (CID) in a message, and then schedules the message according to the CID to realize a session maintenance capability of an application layer.
[0003] In related technologies, a scheduling device can be added before a QUIC protocol cluster, and the scheduling device is used to analyze the CID in the message by using a four-layer load balancing forwarding function of the scheduling device, and schedule the message according to the CID. However, this process not only needs to additionally deploy the scheduling device, but also needs to maintain an analysis key between the QUIC protocol cluster and the scheduling device, so that the deployment cost is introduced and the operation and maintenance complexity is increased. SUMMARY
[0004] Embodiments of the present application provide a data processing method, system, device, computer device and storage medium, which can reduce the deployment cost and operation and maintenance complexity.
[0005] According to a first aspect of embodiments of the present application, a data processing method is provided, which is applied to a first node, and the method can include:
[0006] receiving a QUIC protocol message sent by a user terminal through a link device;
[0007] decrypting a connection identity document of the QUIC protocol message by using a preset decryption parameter;
[0008] scheduling the QUIC protocol message according to whether the connection identity document carries a node identifier.
[0009] According to a second aspect of embodiments of the present application, a data processing system is provided, and the system can include:
[0010] a link device, configured to receive a QUIC protocol message, decrypt a connection identity document of the QUIC protocol message by using a preset decryption parameter, and determine a target node corresponding to a node identifier in a case where the connection identity document carries the node identifier, wherein the target node is a node in a QUIC load balancing cluster.
[0011] The link device is further configured to send a processing instruction to the target node, the processing instruction carrying the QUIC protocol message, and the processing instruction being used to instruct the target node to process the QUIC protocol message.
[0012] According to a third aspect of the embodiments of the present application, a data processing system is provided, wherein the system can include:
[0013] The link device is configured to send the preset decryption parameter and the QUIC protocol message to a first node in the QUIC load balancing cluster.
[0014] The first node is configured to decrypt, by using the preset decryption parameter, a connection identifier field of the QUIC protocol message to obtain a connection identity identifier of the QUIC protocol message, and send the QUIC protocol message to a second node in the QUIC load balancing cluster if a node identifier carried in the connection identity identifier matches a node identifier of the second node.
[0015] The second node is configured to process the QUIC protocol message sent by the first node.
[0016] According to a fourth aspect of the embodiments of the present application, a data processing system is provided, wherein the data processing system includes a QUIC load balancing cluster, and the QUIC load balancing cluster includes a first node.
[0017] The QUIC load balancing cluster is configured to, in a process of QUIC protocol connection negotiation, encode a target node identifier of a target node in the QUIC load balancing cluster and a random value to obtain an encoded connection identity identifier if an initial identifier sent by a user end is received, encrypt the encoded connection identity identifier by using a preset encryption algorithm to obtain a connection identity identifier, and send the connection identity identifier to the user end.
[0018] The first node is configured to receive the QUIC protocol message sent by the user end and forwarded by the link device, decrypt a connection identifier field of the QUIC protocol message by using a preset decryption parameter to obtain a connection identity identifier of the QUIC protocol message, and schedule the QUIC protocol message according to whether the connection identity identifier carries a node identifier, the node identifier being an identifier of a node in the QUIC load balancing cluster.
[0019] According to a fifth aspect of the embodiments of the present application, a data processing apparatus is provided, wherein the apparatus can include:
[0020] The receiving module is configured to receive the QUIC protocol message sent by the user end and forwarded by the link device.
[0021] The decryption module is configured to decrypt the connection identifier field of the QUIC protocol packet by using a preset decryption parameter to obtain a connection identity identifier of the QUIC protocol packet.
[0022] The scheduling module is configured to schedule the QUIC protocol packet according to whether the connection identity identifier carries the node identifier.
[0023] According to a sixth aspect of the embodiments of the present application, a computer device is provided, including a memory and a processor.
[0024] The memory is configured to store a computer program.
[0025] The processor is configured to execute the computer program stored in the memory, and the computer program, when running, causes the processor to perform the steps of the data processing method according to the first aspect.
[0026] According to a seventh aspect of the embodiments of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a program or instructions, which, when executed by a computer device, causes the computer device to perform the steps of the data processing method according to the first aspect.
[0027] According to an eighth aspect of the embodiments of the present application, a computer program product is provided, including a computer program, which, when executed by a computer device, causes the computer device to perform the steps of the data processing method according to the first aspect.
[0028] The data processing method, system, computer device and storage medium provided in the embodiments of the present application can decrypt the connection identifier field of the QUIC protocol packet received from the link device by using a preset decryption parameter to obtain a connection identity identifier of the QUIC protocol packet, and then schedule the QUIC protocol packet according to whether the connection identity identifier carries the node identifier. In this way, without deploying additional scheduling devices, the deployment cost is reduced, the operation and maintenance complexity is reduced, the service online time is shortened, and the low-cost QUIC protocol packet calling and transmission are realized. BRIEF DESCRIPTION OF DRAWINGS
[0029] The present application can be better understood from the following description of specific embodiments thereof, taken in conjunction with the accompanying drawings in which like reference numerals refer to like elements in which:
[0030] Figure 1 is a flow diagram illustrating a data processing process;
[0031] Figure 2 is a structural diagram illustrating a data processing system according to an embodiment;
[0032] Figure 3is a flow chart illustrating a data processing method according to one embodiment;
[0033] Figure 4 is a flow chart illustrating a data processing method according to one embodiment;
[0034] Figure 5 is a structural schematic diagram of a data processing apparatus according to one embodiment;
[0035] Figure 6 is a hardware structural schematic diagram of a computer device according to one embodiment. DETAILED DESCRIPTION
[0036] The features and exemplary embodiments of various aspects of the present application will be described below in detail, in order to make the purposes, technical solutions and advantages of the present application more clear. The following further describes the present application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are configured only to explain the present application, and are not configured to limit the present application. The present application can be implemented without some of the specific details by those skilled in the art. The following description of the embodiments is merely to provide a better understanding of the present application by showing examples of the present application.
[0037] It should be noted that, in this document, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the elements defined by the statement "include" do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0038] Quick UDP Internet Connections (QUIC) based on User Datagram Protocol (UDP) can identify five-tuple information of a packet, i.e., source address, source port, target address, target port and four-layer communication protocol, and schedule the packet according to the five-tuple information to realize the session maintenance capability of the application layer. However, when the five-tuple information changes, since the device on the link can only identify the changed five-tuple information, the packets of the same data stream and different five-tuple information will be sent to different processing nodes, thereby causing the session interruption provided by the Open System Interconnection (OSI).
[0039] In the related art, in order to solve the above problem, as shown in Figure 1 A layer of scheduling device such as QUIC-lb can be added between the link device and the QUIC protocol cluster, the QUIC-lb can be implemented by a reverse proxy Internet (web) server (nginx), and the CID in the QUIC protocol packet is uniformly forwarded and scheduled by using the four-layer forwarding capability of the nginx. However, this process not only needs to additionally deploy the scheduling device, but also needs to maintain the parsing key between the quic protocol cluster and the scheduling device, so that the additional deployment cost is introduced while the operation and maintenance complexity is increased. In addition, although the link device realizes the uniform forwarding based on the CID, in the connection migration scene, the new CID needs to carry the related information of the nodes in the QUIC protocol cluster to ensure that the link device selects consistent nodes, and the link device usually does not have computing capability, the new CID field cannot be confused and calculated, and cannot be desensitized, which damages the security of the QUIC protocol.
[0040] In order to solve the above problem, the embodiment of the present application provides a data processing method for maintaining the consistency of the QUIC protocol in the QUIC load balancing cluster, which does not need to add a scheduling device, only needs to deploy the nodes in the QUIC load balancing cluster, reduces the deployment cost, reduces the operation and maintenance complexity, and shortens the service online time. In addition, compared with the foregoing method, no additional scheduling device needs to be deployed, and the calling and transmission of the high-security QUIC protocol packet can be met.
[0041] Based on this, the data processing system provided by the embodiment of the present application will be described in detail. Figure 2
[0042] As shown in Figure 2 As shown, the data processing system provided in the embodiments of the present application can include a link device and a user datagram-based fast network transmission protocol load balancing cluster, wherein the user datagram-based fast network transmission protocol load balancing cluster can be referred to as a QUIC load balancing cluster in the embodiments of the present application.
[0043] Based on this, for the user end and the QUIC load balancing cluster, in the process of QUIC protocol connection negotiation, the user end sends an initial identifier such as S1 to the QUIC load balancing cluster first, so that the QUIC load balancing cluster encodes the target node identifier and the random value of the target node in the QUIC load balancing cluster when receiving the initial identifier S1, to obtain an encoded connection identity identifier; encrypts the encoded connection identity identifier through a preset encryption algorithm to obtain a connection identity identifier such as S3; and sends the connection identity identifier S3 to the user end, which is the identity identifier of the user end and the QUIC load balancing cluster for data transmission.
[0044] Therefore, the embodiments of the present application integrate the scheduling function of the connection identity identifier of the QUIC protocol message into the QUIC load balancing cluster to which the first node belongs, and use the encryption and decryption capabilities of the nodes in the QUIC load balancing cluster to confuse the connection identity identifier, thereby realizing the high-security calling and transmission of the QUIC protocol message.
[0045] Based on this, the following will be described in combination with Figure 2 The data processing system provided in the embodiments of the present application will be described in detail.
[0046] In one or more possible embodiments, the link device is an entrance of the QUIC load balancing cluster, and can be specifically used to receive the QUIC protocol message forwarded by the user end and forward the QUIC protocol message to each node in the QUIC load balancing cluster. The link device can also be used to send a preset decryption parameter to the first node in the QUIC load balancing cluster, and the preset decryption parameter can include at least one of the following: a key, a random value. It should be noted that the preset decryption parameter in the embodiments of the present application includes a key, which is dynamically updated and is not a fixed parameter.
[0047] The QUIC load balancing cluster (Load Balance Cluster) can be a cluster provided with load balancing capability by multiple nodes, wherein the QUIC load balancing cluster can specifically include at least one node, such as node 1, node 2, …, node N, N being a positive integer, wherein node 1 can be a first node or a second node, which is not limited here.
[0048] Specifically, since the CID is located in the data segment of a User Datagram Protocol (UDP), each node in the QUIC load balancing cluster can perform the following steps: receiving a QUIC protocol packet sent by a user end through a link device; decrypting a connection identification field of the QUIC protocol packet by using a preset decryption parameter to obtain a CID of the QUIC protocol packet, that is, a connection identity; and scheduling the QUIC protocol packet according to whether the connection identity carries a node identification.
[0049] At this time, in a case where the connection identity carries the node identification, it is determined whether the first node is a node corresponding to the node identification. If it is determined that the first node is the node corresponding to the node identification, the QUIC protocol packet is processed through the first node; if it is determined that the first node is not the node corresponding to the node identification, it is determined whether a second node is the node corresponding to the node identification, the second node being any node in the QUIC load balancing cluster to which the first node belongs. Further, if it is determined that the second node is not the node corresponding to the node identification, the QUIC protocol packet is processed through the first node; if it is determined that the second node is the node corresponding to the node identification, the QUIC protocol packet is sent to the second node, the second node being configured to process the QUIC protocol packet.
[0050] In another or more possible embodiments, the link device can be configured to receive a QUIC protocol packet; decrypt a connection identification field of the QUIC protocol packet by using a preset decryption parameter to obtain a connection identity of the QUIC protocol packet; in a case where it is determined that the connection identity carries a node identification, determine a target node corresponding to the node identification, wherein the node identification is an identification of a node in a QUIC load balancing cluster to which a first node belongs, and the target node is a node in the QUIC load balancing cluster; and send a processing instruction to the target node, the processing instruction carrying the QUIC protocol packet, and the processing instruction being configured to instruct the target node to process the QUIC protocol packet.
[0051] In yet another or more possible embodiments, the link device can be configured to send a preset decryption parameter and a QUIC protocol packet to a first node in a QUIC load balancing cluster. The first node is configured to decrypt a connection identification field of the QUIC protocol packet by using the preset decryption parameter to obtain a connection identity of the QUIC protocol packet; and in a case where it is determined that a node identification carried in the connection identity matches a node identification of a second node in the QUIC load balancing cluster, send the QUIC protocol packet to the second node. The second node is configured to process the QUIC protocol packet sent by the first node.
[0052] In still another or more possible embodiment, the QUIC load balancing cluster is used to encode the target node identifier of the target node in the QUIC load balancing cluster and a random value to obtain an encoded connection identity identifier in the process of QUIC protocol connection negotiation in the case of receiving an initial identification sent by the user end. The encoded connection identity identifier is encrypted by a preset encryption algorithm to obtain a connection identity identifier. The connection identity identifier is sent to the user end. Any node (here, the first node is taken as an example for illustration) in the QUIC load balancing cluster, the first node, is used to receive a QUIC protocol packet sent by the user end through a link device forwarding. The connection identity identifier of the QUIC protocol packet is decrypted by a preset decryption parameter to obtain the connection identity identifier of the QUIC protocol packet. The connection identity identifier is scheduled according to whether the connection identity identifier carries a node identifier. The node identifier is the identifier of the node in the QUIC load balancing cluster.
[0053] In this way, without additional deployment of a scheduling device, the deployment cost is reduced, the operation and maintenance complexity is reduced, the service online time is shortened, the scheduling function of the connection identity identifier of the QUIC protocol packet is integrated into the QUIC load balancing cluster to which the first node belongs, and the encryption and decryption capability of the node is used to confuse the connection identity identifier, so that the QUIC protocol packet is called and transmitted at low cost and high security.
[0054] It should be noted that the data processing system provided by the embodiments of the present application can be applied to the session maintenance application scenario of the QUIC protocol of the QUIC load balancing cluster, and can also be applied to the application scenario when connection migration, data migration or link device re-scheduling occurs. Here, the data processing system provided by the embodiments of the present application considers session security, and the CID in the QUIC protocol packet is desensitized as much as possible. The QUIC protocol requires that the CID needs to be updated synchronously when the connection changes. This process is called connection migration (Connection Migration).
[0055] Based on the data processing system and application scenario as shown in Figure 2 , the data processing method provided by the embodiments of the present application will be described in detail. Figures 3-4
[0056] Figure 3 is a flowchart showing a data processing method according to one embodiment.
[0057] As shown in Figure 3 , the data processing method can be applied to the data processing system as shown in Figure 2 , and specifically can be applied to the node in the cluster. Here, the first node in the cluster is taken as an example for illustration. Based on this, the method can include:
[0058] Step 310, the receiving link device forwards the QUIC protocol message sent by the user end; step 320, the connection identification field of the QUIC protocol message is decrypted by the preset decryption parameter, and the connection identity of the QUIC protocol message is obtained; step 330, according to whether the connection identity carries the node identification, the QUIC protocol message is scheduled.
[0059] The above steps are described in detail as follows.
[0060] Firstly, step 310 is involved, in one or more possible embodiments, the first node can be configured as a node with connection identity in the QUIC load balancing cluster, based on which, before step 310, the data processing method can further include:
[0061] In the process of QUIC protocol connection negotiation, in the case of receiving the initial identification sent by the user end, the first node identification and the random value of the first node are encoded to obtain the encoded connection identity;
[0062] The encoded connection identity is encrypted by a preset encryption algorithm to obtain the connection identity;
[0063] The connection identity is sent to the user end.
[0064] Therefore, without additional deployment of scheduling equipment, the deployment cost is reduced, the operation and maintenance complexity is reduced, the service online time is shortened, the scheduling function of the connection identity of the QUIC protocol message is integrated into the QUIC load balancing cluster to which the first node belongs, and the encryption and decryption capability of the first node is used to confuse the connection identity, so that the low-cost QUIC protocol message calling and transmission is realized.
[0065] Secondly, step 320 is involved, the present application provides at least two embodiments to obtain the connection identity, as shown below.
[0066] In one or more possible embodiments, the preset decryption parameter includes the QUIC load balancing cluster to which the first node belongs, based on which, the step 320 can specifically include:
[0067] According to the key and the random value, the connection identification field of the QUIC protocol message is decrypted to obtain the connection identity of the QUIC protocol message.
[0068] In another or more possible embodiments, the step 320 can specifically include:
[0069] According to the preset decryption parameter, the decryption algorithm is obtained;
[0070] The connection identity field of the QUIC protocol packet is decrypted by the decryption algorithm to obtain the connection identity of the QUIC protocol packet.
[0071] Then, step 330 is involved, which in one or more possible embodiments can specifically include:
[0072] Step 3301, in the case that the connection identity carries the node identity, determining whether the first node is the node corresponding to the node identity.
[0073] Step 33021, if it is determined that the first node is the node corresponding to the node identity, processing the QUIC protocol packet through the first node.
[0074] Step 33022, if it is determined that the first node is not the node corresponding to the node identity, determining whether the second node is the node corresponding to the node identity, the second node being a node in a QUIC load balancing cluster to which the first node belongs.
[0075] It should be noted that step 3301 can specifically include: determining whether the first node is the node corresponding to the node identity according to the association information between the preset node identity and the node.
[0076] Based on the above step 33022, in one possible example, the data processing method can further include:
[0077] Step 330221, if it is determined that the second node is not the node corresponding to the node identity, processing the QUIC protocol packet through the first node.
[0078] Step 330222, if it is determined that the second node is the node corresponding to the node identity, sending the QUIC protocol packet to the second node, the second node being used for processing the QUIC protocol packet.
[0079] Specifically, the QUIC protocol packet can be sent to the second node through a tunneling technology.
[0080] For example, if the first node, i.e., a non-self node, processes, it needs to be dispatched to another node for processing, wherein the dispatching process can select a tunneling technology such as IPIP, IPV6, and IPV4 to send the QUIC protocol packet to the second node.
[0081] Step 330 is involved, which in another or more possible embodiments can specifically include:
[0082] In the case that the connection identity does not carry the node identity, processing the QUIC protocol packet through the first node.
[0083] Based on this, in one example, the preset decryption parameter includes a random value, and the data processing method can further include:
[0084] Encoding the node identifier of the first node and the random value into the connection identifier of the QUIC protocol packet to obtain a target connection identifier;
[0085] Encrypting the target connection identifier by using a preset encryption algorithm to obtain an encrypted connection identifier;
[0086] Synchronizing the encrypted connection identifier to the user end corresponding to the QUIC protocol packet.
[0087] Illustratively, since the connection identifier of the QUIC protocol packet does not carry the node identifier or the carried node identifier is not the identifier of the node in the QUIC load balancing cluster to which the first node belongs, the node identifier of the node (such as the first node) to be processed and the random value can be encoded into the connection identifier of the QUIC protocol packet to obtain a target connection identifier, and then the target connection identifier used for communication is encrypted by using a preset encryption algorithm to obtain an encrypted connection identifier, thereby realizing desensitization and secure data transmission. In this way, when connection migration occurs or link equipment is rescheduled, because the node information of the node processing the QUIC protocol packet is encoded in the connection identifier of the QUIC protocol packet, the nodes in the QUIC load balancing cluster can be accurately scheduled, thereby ensuring uninterrupted session.
[0088] Based on the above content, the embodiments of the present application combine Figure 4 The data processing method performed by any node such as the first node in the QUIC load balancing cluster is described in detail as follows.
[0089] Step 401, the first node performs an initialization operation.
[0090] Step 402, the first node that has undergone the initialization operation can receive a preset decryption parameter issued by the QUIC load balancing cluster, and the preset decryption parameter includes a key and a random value.
[0091] Step 403, the first node receives a QUIC protocol packet sent by a user end and forwarded by a link device.
[0092] It should be noted that steps 402 and 403 can be executed in sequence or simultaneously, and are not limited in this regard.
[0093] Step 404, the first node decrypts the connection identifier field of the QUIC protocol packet by using the key received in step 402 to obtain a connection identifier of the QUIC protocol packet.
[0094] Step 405, it is determined whether the connection identity carries the node identifier. If yes, step 406 is executed, and if no, step 408 is executed. It is pointed out that the node identifier in the embodiment of the application is the identifier of the node in the QUIC load balancing cluster to which the first node belongs.
[0095] Step 406, the first node determines whether the first node is the node corresponding to the node identifier. If yes, step 408 is executed, that is, the QUIC protocol packet is processed by the first node; otherwise, if no, step 407 is executed.
[0096] Step 407, the first node determines whether the second node is the node corresponding to the node identifier. If yes, step 409 is executed, that is, the first node sends the QUIC protocol packet to the second node, so that the second node processes the QUIC protocol packet; otherwise, if no, step 408 is executed.
[0097] It is pointed out that after step 408 is executed in the case where the connection identity does not carry the node identifier, the following steps can also be executed, that is, the QUIC protocol packet is processed by the first node, and the node identifier of the first node and the random value are encoded into the connection identity of the QUIC protocol packet to obtain a target connection identity; the target connection identity is encrypted by a preset encryption algorithm to obtain an encrypted connection identity; and the encrypted connection identity is synchronized to the user end corresponding to the QUIC protocol packet.
[0098] In summary, the data processing method provided by the embodiment of the application does not need to additionally deploy a quic-lb device, only needs to configure each node in the QUIC load balancing cluster to have the session keeping capability of the QUIC protocol, has no additional deployment cost, has no challenge to the existing network architecture, has small operation and maintenance pressure, and has greatly shortened service online time. In addition, the scheduling capability of the connection identity of the QUIC protocol packet can be integrated on the QUIC load balancing cluster, and the encryption and decryption capability of the QUIC load balancing cluster itself is used to confuse the connection identity of the QUIC protocol packet, so that low-cost and secure QUIC protocol transmission is achieved.
[0099] It should be clear that the application is not limited to the specific configurations and processes described in the foregoing embodiments and shown in the drawings. For the convenience and brevity of description, detailed descriptions of known methods are omitted, and the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be described here in detail.
[0100] Based on the same inventive concept, the embodiments of the application provide a data processing apparatus corresponding to the data processing method described above. The data processing apparatus will be described in detail in combination with Figure 5 the foregoing method embodiments.
[0101] Figure 5 is a structural schematic diagram of a data processing apparatus according to an embodiment.
[0102] As Figure 5 shown, the data processing apparatus 50 is applied to a data processing system as Figure 2 shown, and the data processing apparatus 50 specifically can include:
[0103] The receiving module 501 is configured to receive a QUIC protocol packet sent by a user end forwarded by a link device.
[0104] The decryption module 502 is configured to decrypt a connection identifier field of the QUIC protocol packet by using a preset decryption parameter, to obtain a connection identity identifier of the QUIC protocol packet.
[0105] The scheduling module 503 is configured to schedule the QUIC protocol packet according to whether the connection identity identifier carries a node identifier.
[0106] Based on this, the data processing apparatus 50 provided by the embodiments of the present application is described in detail below.
[0107] In one or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a first encoding module, a first encryption module and a first sending module; wherein,
[0108] The first encoding module is configured to, in a process of QUIC protocol connection negotiation, encode a first node identifier of the first node and a random value to obtain an encoded connection identity identifier, in a case where an initial identifier sent by the user end is received.
[0109] The first encryption module is configured to encrypt the encoded connection identity identifier by using a preset encryption algorithm to obtain the connection identity identifier.
[0110] The first sending module is configured to send the connection identity identifier to the user end.
[0111] In another one or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a first determining module and a first processing module; wherein,
[0112] The first determining module is configured to, in a case where the connection identity identifier carries the node identifier, determine whether the first node is a node corresponding to the node identifier.
[0113] The first processing module is configured to, if it is determined that the first node is the node corresponding to the node identifier, process the QUIC protocol packet by using the first node.
[0114] In yet another or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a second determining module and a second processing module; wherein,
[0115] The second determining module is configured to determine whether the second node is the node corresponding to the node identifier if it is determined that the first node is not the node corresponding to the node identifier, the second node being a node in a QUIC load balancing cluster to which the first node belongs;
[0116] The second processing module is configured to process the QUIC protocol packet through the first node if it is determined that the second node is not the node corresponding to the node identifier.
[0117] In yet another or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a second sending module; wherein,
[0118] The second sending module is configured to send the QUIC protocol packet to the second node if it is determined that the second node is the node corresponding to the node identifier, the second node being configured to process the QUIC protocol packet.
[0119] In yet another or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a third sending module; wherein,
[0120] The third sending module is configured to send the QUIC protocol packet to the second node through a tunneling technology.
[0121] In yet another or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a third processing module; wherein,
[0122] The third processing module is configured to process the QUIC protocol packet through the first node if the connection identifier does not carry the node identifier.
[0123] In yet another or more possible embodiments, the data processing apparatus 50 provided by the embodiments of the present application can further include a second encoding module, a second encryption module and a synchronization module; wherein,
[0124] The second encoding module is configured to encode the node identifier of the first node and a random value into a connection identifier of the QUIC protocol packet to obtain a target connection identifier.
[0125] The second encryption module is configured to encrypt the target connection identifier through a preset encryption algorithm to obtain an encrypted connection identifier.
[0126] The synchronization module is configured to synchronize the encrypted connection identifier to a user end corresponding to the QUIC protocol packet.
[0127] In another or more possible embodiments, the data processing apparatus 50 provided in this application embodiment may further include a first decryption module; wherein,
[0128] The first decryption module is used to decrypt the connection identifier field of the QUIC protocol message according to the key, given that the preset decryption parameters include the key issued by the QUIC load balancing cluster to which the first node belongs, to obtain the connection identity identifier of the QUIC protocol message.
[0129] In another or more possible embodiments, the data processing apparatus 50 provided in this application may further include an acquisition module and a second decryption module; wherein,
[0130] The acquisition module is used to acquire the decryption algorithm based on preset decryption parameters;
[0131] The second decryption module is used to decrypt the connection identifier field of the QUIC protocol message using a decryption algorithm to obtain the connection identity identifier of the QUIC protocol message.
[0132] Therefore, the data processing device provided in this embodiment can decrypt the QUIC protocol messages received from the link device by pre-setting decryption parameters to obtain the connection identifier field of the QUIC protocol message. Then, based on whether the connection identifier carries the node identifier of the node in the QUIC load balancing cluster to which the first node belongs, the QUIC protocol messages are scheduled. In this way, no additional scheduling equipment needs to be deployed, which reduces deployment costs, operational complexity, and service launch time. Furthermore, the scheduling function of the connection identifier of the QUIC protocol message is integrated into the QUIC load balancing cluster to which the first node belongs, and the connection identifier is obfuscated by the node's encryption and decryption capabilities, so as to achieve low-cost and high-security invocation and transmission of QUIC protocol messages.
[0133] Figure 6 This is a schematic diagram illustrating the hardware structure of a computer device according to one embodiment.
[0134] like Figure 6 As shown, the computer device 600 includes an input device 601, an input interface 602, a processor 603, a memory 604, an output interface 605, and an output device 606.
[0135] The input interface 602, the processor 603, the memory 604, and the output interface 605 are connected to each other through the bus 610, the input device 601 and the output device 606 are connected to the bus 610 through the input interface 602 and the output interface 605 respectively, and then connected to other components of the computer device 600. Specifically, the input device 601 receives input information from the outside, and transmits the input information to the processor 603 through the input interface 602; the processor 603 processes the input information based on the computer executable instructions stored in the memory 604 to generate output information, temporarily or permanently stores the output information in the memory 604, and then transmits the output information to the output device 606 through the output interface 605; the output device 606 outputs the output information to the outside of the computer device 600 for use by the user.
[0136] In one embodiment, Figure 6 The computer device 600 shown can be implemented as a data processing device, which can include a memory configured to store a program, and a processor configured to run the program stored in the memory to perform the data processing method described in the above embodiments. The data processing device can be an electronic device, but is not limited thereto, and can also be a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or other devices other than a terminal. For example, the electronic device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle-mounted electronic device, a mobile Internet device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc. The electronic device can also be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application are not limited in this regard.
[0137] The data processing device in the embodiments of the present application can be a device with an operating system. The operating system can be an Android operating system, an IOS operating system, or other possible operating systems, and the embodiments of the present application are not limited in this regard.
[0138] According to embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as computer-readable storage media. For example, embodiments of the present application include a computer-readable storage medium comprising a program or instructions stored on the computer-readable storage medium that, when executed by a computer device, cause the computer device to perform the steps of the data processing method described above.
[0139] According to embodiments of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present application include a computer program product comprising a computer program tangibly embodied on a machine-readable medium, the computer program containing program code for executing the methods illustrated by the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network and / or installed from a removable storage medium.
[0140] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions that, when executed on a computer, cause the computer to perform the methods described in the various embodiments above. When the computer program instructions are loaded and executed on the computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media (such as solid-state disks), etc.
[0141] The device embodiments described above are only schematic, wherein the units illustrated as separate components can or can not be physically separate, and the components illustrated as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purposes of the embodiments. Those skilled in the art can understand and implement without creative labor.
[0142] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit the same. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or make equivalent replacements for some or all of the technical features therein. Such modifications or replacements do not cause the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A data processing method applied to a first node, comprising: receiving a QUIC protocol packet forwarded by a link device from a user end; decrypting a connection identifier field of the QUIC protocol packet by using a preset decryption parameter to obtain a connection identity of the QUIC protocol packet; scheduling the QUIC protocol packet according to whether the connection identity carries a node identifier, including: in a case where the connection identity carries the node identifier, determining whether the first node is a node corresponding to the node identifier; if it is determined that the first node is the node corresponding to the node identifier, processing the QUIC protocol packet by using the first node; if it is determined that the first node is not the node corresponding to the node identifier, determining whether a second node is the node corresponding to the node identifier, the second node being a node in a QUIC load balancing cluster to which the first node belongs; if it is determined that the second node is not the node corresponding to the node identifier, processing the QUIC protocol packet by using the first node.
2. The method of claim 1, wherein, Before the receiving the QUIC protocol packet forwarded by the link device from the user end, the method further comprises: in a process of QUIC protocol connection negotiation, in a case where an initial identifier sent by the user end is received, encoding a first node identifier of the first node and a random value to obtain an encoded connection identity; encrypting the encoded connection identity by using a preset encryption algorithm to obtain the connection identity; sending the connection identity to the user end.
3. The method of claim 1, wherein, The scheduling the QUIC protocol packet according to whether the connection identity carries the node identifier includes: if it is determined that the second node is the node corresponding to the node identifier, sending the QUIC protocol packet to the second node, the second node being used for processing the QUIC protocol packet.
4. The method of claim 3, wherein, The sending the QUIC protocol packet to the second node includes: sending the QUIC protocol packet to the second node by using a tunneling technology.
5. The method of claim 1, wherein, The scheduling the QUIC protocol packet according to whether the connection identity carries the node identifier includes: in a case where the connection identity does not carry the node identifier, processing the QUIC protocol packet by using the first node.
6. The method of claim 5, wherein, The preset decryption parameter includes a random value; the method further comprises: encoding the node identifier of the first node and the random value into the connection identity of the QUIC protocol packet to obtain a target connection identity; encrypting the target connection identity by using a preset encryption algorithm to obtain an encrypted connection identity; synchronizing the encrypted connection identity to a user end corresponding to the QUIC protocol packet.
7. The method of claim 1, wherein, The preset decryption parameter includes a key issued by a QUIC load balancing cluster to which the first node belongs. The decrypting the connection identifier field of the QUIC protocol packet by using the preset decryption parameter to obtain the connection identity of the protocol packet includes: According to the key, the connection identification field of the QUIC protocol packet is decrypted to obtain the connection identity identification of the QUIC protocol packet.
8. The method of claim 1, wherein, The connection identification field of the QUIC protocol packet is decrypted by using the preset decryption parameter to obtain the connection identity identification of the protocol packet, including: According to the preset decryption parameter, a decryption algorithm is obtained; The connection identification field of the QUIC protocol packet is decrypted by using the decryption algorithm to obtain the connection identity identification of the QUIC protocol packet.
9. A data processing system, comprising: a link device configured to receive a QUIC protocol packet; The connection identification field of the QUIC protocol packet is decrypted by using the preset decryption parameter to obtain the connection identity identification of the QUIC protocol packet; in a case where it is determined that the connection identity identification carries a node identification, a target node corresponding to the node identification is determined, wherein the target node is a node in the QUIC load balancing cluster. The link device is further configured to send a processing instruction to the target node, wherein the processing instruction carries the QUIC protocol packet, and the processing instruction is used to instruct the target node to process the QUIC protocol packet.
10. A data processing system, comprising: a link device configured to send a preset decryption parameter and a QUIC protocol packet to a first node in a QUIC load balancing cluster; The first node is configured to decrypt the connection identification field of the QUIC protocol packet by using the preset decryption parameter to obtain the connection identity identification of the QUIC protocol packet; and in a case where it is determined that the node identification carried in the connection identity identification matches the node identification of a second node in the QUIC load balancing cluster, the QUIC protocol packet is sent to the second node; The second node is configured to process the QUIC protocol packet sent by the first node.
11. A data processing system comprising: A QUIC load balancing cluster, the QUIC load balancing cluster comprises a target node and a first node; wherein, The QUIC load balancing cluster is configured to, in a process of QUIC protocol connection negotiation, in a case where an initial identification sent by a user end is received, encode a target node identification of the target node and a random value to obtain an encoded connection identity identification; encrypt the encoded connection identity identification by using a preset encryption algorithm to obtain a connection identity identification; and send the connection identity identification to the user end; The first node is configured to receive a QUIC protocol packet sent by a link device forwarding a user end; decrypt the connection identification field of the QUIC protocol packet by using a preset decryption parameter to obtain the connection identity identification of the QUIC protocol packet; and according to whether the connection identity identification carries a node identification, the node identification being an identification of a node in the QUIC load balancing cluster, the QUIC protocol packet is dispatched.
12. The system of claim 11, wherein, The first node is further configured to, in a case where the connection identity of the QUIC protocol packet carries a node identifier and the carried node identifier is a target node identifier of the target node, send the QUIC protocol packet to the target node, and the target node is configured to process the QUIC protocol packet.
13. A computer device comprising: a memory and a processor, The memory is configured to store a computer program. The processor is configured to execute the computer program stored in the memory, and the computer program is configured to cause the processor to execute the steps of the data processing method in any one of claims 1 to 8 when the computer program runs.
14. A computer readable storage medium, the computer readable storage medium storing a program or instructions, the program or instructions causing a computer device to execute the steps of the data processing method in any one of claims 1 to 8 when the program or instructions are executed by the computer device.
Citation Information
Patent Citations
Data processing method, equipment, medium and device
CN110177082A