Traffic throttling method, device, equipment, medium, product and throttling system

CN117255060BActive Publication Date: 2026-09-22CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311268438.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-27
Publication Date
2026-09-22
Estimated Expiration
2043-09-27

AI Technical Summary

Technical Problem

[0004]本申请提供一种业务限流方法、装置、设备、介质、产品及限流系统,用以解决现有技术业务限流过程中难以保证复杂业务的完整性和有效性问题

Benefits of technology

[0043]本申请提供的业务限流方法、装置、设备、介质、产品及限流系统,通过获取目标业务的流量阻断策略,该流量阻断策略是根据为业务配置的入口和业务接口信息及其对应的各业务接口的实时流量监控数据,所生成的针对入口的流量阻断策略,利用该流量阻断策略对入口进行统一限流,实现了复杂业务多接口的联动限流控制,可以有效解决现有技术中存在的限流过程中所导致的业务中断问题,实现业务过程中请求的有效响应,进而提高业务的完整性和连续性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117255060B_ABST
    Figure CN117255060B_ABST
Patent Text Reader

Abstract

The application provides a service flow limiting method, device, equipment, medium, product and flow limiting system, and relates to the technical field of big data. The method comprises the following steps: acquiring a flow blocking strategy of a target service, wherein the flow blocking strategy is determined based on flow monitoring data corresponding to preconfigured information of the target service; wherein the preconfigured information comprises service entry information and at least one service interface information preconfigured for the target service, and the flow blocking strategy comprises a flow blocking strategy of an entry corresponding to the service entry information; and performing flow control on the entry based on the flow blocking strategy in response to the entry receiving a service request of the target service. Through the above technical solution, the problem of service interruption caused by the flow limiting process in the prior art can be effectively solved, effective response of the request in the service process is realized, and the integrity and continuity of the service are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of big data technology, and in particular to a business rate limiting method, device, equipment, medium, product and rate limiting system. Background Technology

[0002] With the continuous upgrading of Internet application systems and network architecture, the volume of application access services and external traffic is growing rapidly. Since the overall service resources of application systems are limited, the rate limiting mechanism to withstand the impact of high-concurrency and high-volume requests is an indispensable capability for Internet applications.

[0003] Current rate limiting mechanisms are mainly based on some general network characteristics or single server performance characteristics, without considering the continuity between multiple service requests for the same business (such as the bank account opening process), which makes it difficult to guarantee the integrity and effectiveness of complex business during rate limiting. Summary of the Invention

[0004] This application provides a service rate limiting method, apparatus, equipment, medium, product, and rate limiting system to solve the problem that it is difficult to guarantee the integrity and effectiveness of complex services during the service rate limiting process in the prior art.

[0005] Firstly, this application provides a method for limiting service flow, including:

[0006] Obtain the traffic blocking strategy for the target service, wherein the traffic blocking strategy is determined based on traffic monitoring data corresponding to the pre-configuration information of the target service; wherein the pre-configuration information includes service entry information and at least one service interface information pre-configured for the target service, and the traffic blocking strategy includes the traffic blocking strategy for the entry corresponding to the service entry information;

[0007] In response to the ingress receiving a service request from the target service, traffic control is applied to the ingress based on the traffic blocking policy.

[0008] In one implementation, determining the traffic blocking strategy for the target service includes:

[0009] Based on the pre-configured information, obtain the traffic monitoring data of the entry corresponding to the business entry information, and the traffic monitoring data of each business interface corresponding to each business interface information;

[0010] Based on the traffic monitoring data of the entry point and the traffic monitoring data of each service interface, a traffic blocking strategy for the target service is determined.

[0011] In one implementation, the traffic monitoring data includes the request concurrency of the ingress and / or the baseline concurrency, or the request concurrency of the service interface.

[0012] The method further includes: obtaining the delay time of the service request;

[0013] The traffic blocking strategy for the target service is determined based on the traffic monitoring data from the ingress point and the traffic monitoring data from each service interface, including:

[0014] When the latency of a service request at any service interface reaches a preset threshold, the limit concurrency of the entry point is determined based on the request concurrency of the corresponding service interface and the request concurrency and / or baseline concurrency of the entry point, and the traffic blocking strategy for the target service is determined based on the limit concurrency of the entry point.

[0015] In one implementation, the pre-configuration information further includes correlation weights and preset scaling factors among the various service interfaces pre-configured for the target service.

[0016] The traffic blocking strategy for the target service is determined based on the traffic monitoring data from the ingress point and the traffic monitoring data from each service interface, including:

[0017] The traffic blocking strategy for the target service is determined based on the correlation weight, the preset scaling factor, the traffic monitoring data of the ingress and the traffic monitoring data of each service interface.

[0018] In one implementation, the pre-configuration information includes monitoring node information pre-configured for the target service regarding each service interface and the entry point;

[0019] The step of obtaining traffic monitoring data for the entry point corresponding to the service entry information based on the pre-configured information, and traffic monitoring data for each service interface corresponding to each service interface information, includes:

[0020] Based on the monitoring node information, the corresponding monitoring node is determined, and based on the monitoring node, the traffic monitoring data of the entry corresponding to the business entry information and the traffic monitoring data of each business interface corresponding to each business interface information are obtained.

[0021] In one embodiment, the method further includes:

[0022] Obtain the acquisition period of the pre-configured traffic blocking policy;

[0023] The acquisition of the traffic blocking strategy for the target service includes: acquiring the traffic blocking strategy for the target service every acquisition period.

[0024] In one implementation, the service entry information includes a service type identifier corresponding to the target service.

[0025] Secondly, this application provides a service flow limiting device, comprising:

[0026] The strategy acquisition module is configured to acquire the traffic blocking strategy of the target service. The traffic blocking strategy is determined based on the traffic monitoring data corresponding to the pre-configuration information of the target service. The pre-configuration information includes pre-configured service entry information and at least one service interface information for the target service. The traffic blocking strategy includes the traffic blocking strategy of the entry corresponding to the service entry information.

[0027] The access control module is configured to perform traffic control on the ingress based on the traffic blocking policy in response to the ingress receiving a service request from the target service.

[0028] In one implementation, determining the traffic blocking strategy for the target service specifically involves: obtaining traffic monitoring data of the entry point corresponding to the service entry information and traffic monitoring data of each service interface corresponding to each service interface information based on the pre-configured information; and determining the traffic blocking strategy for the target service based on the traffic monitoring data of the entry point and the traffic monitoring data of each service interface.

[0029] In one implementation, the traffic monitoring data includes the request concurrency of the ingress and / or the baseline concurrency, or the request concurrency of the service interface.

[0030] The device further includes: a delay acquisition module, configured to acquire the delay time of the service request;

[0031] The method of determining the traffic blocking strategy for the target service based on the traffic monitoring data of the entry point and the traffic monitoring data of each service interface is as follows: when the delay time of a service request at any service interface reaches a preset threshold, the limit concurrency of the entry point is determined based on the request concurrency of the corresponding service interface and the request concurrency and / or baseline concurrency of the entry point, and the traffic blocking strategy for the target service is determined based on the limit concurrency of the entry point.

[0032] Thirdly, this application also provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0033] The memory stores computer-executed instructions;

[0034] The processor executes computer execution instructions stored in the memory to implement the service rate limiting method.

[0035] Fourthly, this application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the aforementioned service rate limiting method.

[0036] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned service rate limiting method.

[0037] Sixthly, this application also provides a rate limiting system, comprising: a service rate limiting device and a rate limiting configuration device connected to the service rate limiting device; the rate limiting configuration device includes a configuration module, a monitoring module, and a decision module; the service rate limiting device includes a policy acquisition module and an access control module; wherein,

[0038] The configuration module is configured to configure pre-configuration information for the target service, the pre-configuration information including service entry information and at least one service interface information;

[0039] The monitoring module is configured to acquire traffic monitoring data corresponding to the pre-configured information.

[0040] The decision-making module is configured to determine the traffic blocking strategy for the target service based on the traffic monitoring data; wherein, the traffic blocking strategy includes the traffic blocking strategy for the entry point corresponding to the service entry information;

[0041] The policy acquisition module is configured to acquire the traffic blocking policy for the target service;

[0042] An access control module is configured to control the flow of the ingress based on the flow blocking policy in response to the ingress receiving a service request from the target service.

[0043] The service rate limiting method, apparatus, equipment, medium, product, and rate limiting system provided in this application obtain the traffic blocking strategy of the target service. This traffic blocking strategy is generated based on the entry point and service interface information configured for the service and the real-time traffic monitoring data of each corresponding service interface. It is a traffic blocking strategy for the entry point, and uses this traffic blocking strategy to uniformly limit the entry point, realizing the linkage rate limiting control of multiple interfaces of complex services. It can effectively solve the service interruption problem caused by rate limiting in the prior art, realize the effective response of requests in the service process, and thus improve the integrity and continuity of the service. Attached Figure Description

[0044] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0045] Figure 1 This is a schematic diagram illustrating a scenario of traffic limiting in related technologies;

[0046] Figure 2 One of the flowcharts illustrating the service rate limiting method provided in this application embodiment;

[0047] Figure 3 This is a flowchart illustrating the process of determining the traffic blocking strategy for the target service in an embodiment of this application.

[0048] Figure 4 A second schematic flowchart illustrating the service rate limiting method provided in this application embodiment;

[0049] Figure 5 A network framework diagram of a service rate limiting method is provided for an exemplary embodiment of this application;

[0050] Figure 6 This is a schematic diagram of the structure of the service flow limiting device provided in the embodiments of this application;

[0051] Figure 7 This is a schematic diagram of the current limiting system provided in an embodiment of this application;

[0052] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0053] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0054] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0055] First, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0056] The main technical concepts of this application are described below in conjunction with relevant technologies:

[0057] In the public internet domain, rate limiting mechanisms to withstand high-concurrency, high-volume request surges are an essential capability for large-scale internet applications. Therefore, various rate limiting devices exist on the market, such as firewalls, web firewalls, load balancing proxies, application-layer rate limiters (e.g., Spring Cloud's Sentinel component), and token bucket mechanisms.

[0058] The aforementioned rate limiting devices are often based on specific network characteristics, such as IP address, port, or individual components of network request addresses, or on mechanisms such as response time and timeout statistics of business interfaces. Their monitoring and control mechanisms are often based on some general network characteristics or single server performance characteristics, without considering issues such as business continuity (including multiple requests) of complex businesses.

[0059] In common business scenarios, when faced with a large number of concurrent requests, in order to ensure the integrity and effectiveness of the business, if it is impossible to satisfy all users' requests, it is usually expected that users who have entered a multi-stage business process (such as a bank account opening process) can effectively complete the entire process without frequent interruptions to user operations due to the excessive requests from subsequent users.

[0060] Figure 1 This diagram illustrates application scenarios for traffic limiting in related technologies. For example... Figure 1 As shown, the application scenario includes: at least one rate limiting device 11 and at least one service processing node 12 (corresponding to the service interface); wherein, the rate limiting device 11 is, for example, a load balancer.

[0061] In existing technology, when a user-side business processing node 12 initiates a business request, the request first passes through a rate limiting device 11. Each rate limiting device 11 applies rate limiting to each business processing node 12. After rate limiting, the request reaches the business processing node 12. When multiple business requests initiated by the user are related requests for a complex business, the rate limiting device 11 only applies rate limiting to all requests based on the performance of the business processing node. This can lead to the control of certain business requests within a complex business request during the rate limiting process, potentially causing the interruption of the entire business process and affecting the integrity and effectiveness of the business.

[0062] To address the aforementioned technical problems, this application proposes a service rate limiting method, apparatus, device, medium, product, and rate limiting system. Its main technical concept is as follows: By acquiring the entry point and service interface information configured for the service, and monitoring the real-time traffic monitoring data of each service interface, a traffic blocking strategy for the entry point is generated. Through unified rate limiting of the entry point, coordinated rate limiting control of multiple interfaces for complex services is achieved. This solves the service interruption problem caused by rate limiting in existing technologies, enabling effective responses to requests during the service process, thereby improving the integrity and continuity of the service.

[0063] It should be noted that the business current limiting method, apparatus, equipment, medium, product, and current limiting system of this application can be used in the fintech field. They can also be used in any field other than fintech; the application areas of the business current limiting method, apparatus, equipment, medium, product, and current limiting system of this application are not limited.

[0064] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0065] Please refer to Figure 2 , Figure 2 The present application provides a business flow limiting method that can be applied to a banking business system. The method includes steps S201 and S202.

[0066] Step S201: Obtain the traffic blocking policy for the target service. The traffic blocking policy is determined based on the traffic monitoring data corresponding to the pre-configuration information of the target service. The pre-configuration information includes the service entry information and at least one service interface information pre-configured for the target service. The traffic blocking policy includes the traffic blocking policy of the entry point corresponding to the service entry information.

[0067] In related technologies, flow control schemes typically limit the rate of an interface based on specific network characteristics. For example, they might define the maximum number of requests an interface can allow, the current concurrent request volume, and control a portion of the current concurrent requests based on the maximum request volume. Alternatively, they might limit the request volume of an interface based on its response time; when the response time reaches a certain threshold, the request volume of that interface is restricted. However, this type of rate limiting does not consider the continuity between multiple requests for the same service.

[0068] In this embodiment, the traffic blocking strategy is targeted at the target service. Different traffic blocking strategies can be determined for different target services. The target service can be any service determined according to the actual application. In other words, the traffic blocking strategy in this embodiment is a strategy to block traffic for the entire service, so as to realize the linkage rate limiting control of each request of the service, and improve the service continuity on the basis of meeting the rate limiting requirements.

[0069] Optionally, for different business operations, complex business operations may include multiple business interfaces. These multiple business interfaces are distinguished into an entry point (interface) and other business interfaces besides that entry point. The entry point is the first request interface at the business logic level, and the other business interfaces are subsequent request interfaces for that business. For subsequent requests to the business, the entry point must be accessed before the corresponding business interface can be processed. By configuring corresponding entry point information and one or more business interface information corresponding to that entry point for each business, different business interfaces for different businesses can be distinguished. The number of business interfaces is determined according to the actual needs of the business. For example, the account opening business includes business processes such as identity authentication, account registration, and mobile phone verification. Each business process corresponds to one or more business interfaces, and the entry point is the first entry point for the account opening business, such as the identity authentication business interface.

[0070] Optionally, the traffic blocking strategy can be determined by the banking business system and implemented through internal transmission, or it can be determined by a dedicated terminal or server and implemented based on external transmission.

[0071] In this embodiment, the service entry information includes a service type identifier corresponding to the target service to distinguish entry points for different services. At least one service interface information can be information corresponding to all service interfaces required by the target service except for the entry point (this can be service interface address information or identifier information, etc.), or it can be information for some service interfaces that require traffic control. Optionally, during the configuration phase, in addition to configuring the service entry information and at least one service interface information, the baseline capacity of the entry point (e.g., maximum request concurrency) and the correlation weight between interfaces can also be configured, and it can also be used for other related rate limiting configurations.

[0072] Step S202: In response to the ingress receiving a service request from the target service, traffic control is performed on the ingress based on the traffic blocking policy.

[0073] In this embodiment, the business request of the target business can be the entry business request of the target business. Taking the account opening business as an example, the first business request that initiates the request is the identity authentication business request.

[0074] Optionally, after receiving a service request from a user, the system first identifies which target service the request corresponds to, then determines the entry point for that target service. The corresponding entry point receives the service request for the target service and decides whether to process or block it based on a traffic blocking policy. Since the blocking policy is determined based on traffic monitoring data from each service interface, overall rate limiting at the entry point can effectively prevent service interruptions caused by excessive subsequent request volume leading to rate limiting of some requests in the previous business process.

[0075] In this embodiment, the entry point is the first request interface at the business logic level, and other business interfaces are subsequent request interfaces for that business. For subsequent requests, the client program (i.e., the user end) needs to access the entry point before it can call the corresponding business interface and process data. If the entry point interface is blocked, the client program cannot call the subsequent interfaces, thereby achieving the purpose of unified rate limiting for all business interfaces by blocking traffic at the entry point interface.

[0076] In one implementation, the traffic blocking strategy is determined uniformly based on the traffic status of the ingress point and each service interface to meet business concurrency requirements and request processing efficiency. Specifically, the traffic blocking strategy for the target service is determined, such as... Figure 3 As shown, the following steps may be included:

[0077] Step S301: Based on the pre-configuration information, obtain the traffic monitoring data of the entry point corresponding to the business entry information, and the traffic monitoring data of each business interface corresponding to each business interface information;

[0078] Step S302: Determine the traffic blocking strategy for the target service based on the traffic monitoring data of the ingress point and the traffic monitoring data of each service interface.

[0079] In this embodiment, the pre-configured information includes corresponding entry information and service interface information. Based on the entry information and service interface information, the entry point of the target service and each service interface receiving the request can be quickly located. By obtaining the traffic monitoring data of the entry point and each interface, the traffic blocking strategy of the target service can be determined.

[0080] In some embodiments, the traffic blocking strategy can also be determined in real time based on other information. For example, if the target business requires a certain processing speed, and the ingress baseline capacity is fixed, if the processing speed of requests is guaranteed, the latency time can be shortened by reducing the number of requests allowed at the ingress.

[0081] For example, taking the threshold N for the number of allowed requests at the entry point as an example, for each allowed request, the number of allowed requests decreases by N-1, until N=0 and the request is rejected. Here, N represents the traffic blocking strategy determined based on the traffic monitoring data of the entry point. In this embodiment, the traffic blocking strategy is jointly determined by the entry point and each business interface, and it can be a dynamically changing value determined based on the traffic monitoring data of the entry point and each business interface. In one implementation, a preset number N of concurrent requests allowed within a time period K is defined. At startup, N is written to the system's cache at time intervals K. Each time an entry request is received, an atomic operation of decrementing N by 1 is performed. When the read result is less than 0, the request is rejected (the traffic monitoring data of the entry point, i.e., the real-time allowed number of requests at the entry point). The traffic monitoring data of each business interface is monitored. When the traffic monitoring data of any business interface exceeds the set threshold range, a new value of N is determined based on the business request and the entry request, i.e., the real-time blocking strategy is determined.

[0082] Those skilled in the art will understand that the business requests corresponding to the various business interfaces of the target business are related. When the capacity of a certain business interface reaches a set threshold, it will affect the entire process. By implementing unified rate limiting at the entry point, the smooth operation of each business interface can be ensured, while preventing the business interruption caused by rate limiting in subsequent high-volume business requests.

[0083] In one implementation, to further optimize the traffic control effect, the traffic monitoring data in this embodiment includes the request concurrency of the ingress and / or the baseline concurrency, or the request concurrency of the business interface.

[0084] The method may also include the following steps: obtaining the latency of the business request;

[0085] Based on the traffic monitoring data from the ingress point and the traffic monitoring data from each service interface, a traffic blocking strategy for the target service is determined, including:

[0086] When the latency of a business request at any business interface reaches a preset threshold, the limit concurrency of the entry point is determined based on the request concurrency of the corresponding business interface, the request concurrency of the entry point, and / or the baseline concurrency. Based on the limit concurrency of the entry point, the traffic blocking strategy for the target business is determined.

[0087] Optionally, those skilled in the art can determine the baseline capacity (i.e., the maximum concurrent requests) for different service entry points by considering factors such as the actual throughput of the application system. In this embodiment, the latency of service requests is obtained, that is, the latency of service requests for each service interface is obtained separately.

[0088] Furthermore, the pre-configuration information also includes the correlation weights and preset scaling factors between various business interfaces pre-configured for the target business;

[0089] Based on the traffic monitoring data from the ingress point and the traffic monitoring data from each service interface, a traffic blocking strategy for the target service is determined, including:

[0090] Based on relevance weights, preset scaling factors, and traffic monitoring data from the entry point and each business interface, the traffic blocking strategy for the target business is determined.

[0091] Those skilled in the art will understand that the various business interfaces are related interfaces, and the arrival of a request from one interface at the next interface is probabilistic, not guaranteed. Those skilled in the art can adaptively set the relevance weights between the various business interfaces based on practical applications and existing technologies. Optionally, the relevance weights between the various business interfaces can be determined by combining the relevance weights of the business requests and the entry requests for each business interface. These weights are determined based on actual business statistics or business forecasts, specifically the effective proportion of requests that can reach the interface from the entry request.

[0092] Taking the above-mentioned exemplary scheme for determining the traffic blocking strategy as an example, combined with the relevance weight and the preset scaling factor, the traffic blocking strategy can be as follows: when the delay time of a business request on a certain business interface reaches the preset threshold, the traffic monitoring data (request concurrency, hereinafter referred to as concurrency) of the business request is multiplied by the relevance weight and then multiplied by a scaling factor (i.e., the preset scaling factor, which can be adaptively determined according to existing technology and actual application) as the new N value. N can be adjusted every time O until all request monitoring data returns to a reasonable response threshold range.

[0093] For example, N = monitoring concurrency * correlation weight * scaling ratio. Taking payment business as an example, if at a certain moment the concurrency of merchant acquiring requests is 100 times / second, the average latency of the request is 2 seconds, exceeding the preset threshold of 1.8 seconds. In order to bring the request into the normal threshold range, the concurrency of the ingress request is adjusted according to the technical solution of this application. Since the correlation ratio between merchant acquiring requests and customer order placement requests is 0.95, we use 100 times * 0.95, and then multiply by the scaling ratio of 0.9. The principle is that the system expects an average latency response time of 1.8 seconds, while the current latency reaches 0.2 seconds, close to 10%. By reducing the ingress traffic by 10%, the response speed of the business interface is guaranteed. In some embodiments, the request latency of multiple business interfaces is similar. The traffic blocking strategy can be further adjusted by summing or other methods, which will not be elaborated here.

[0094] In one implementation, in order to improve the accuracy of traffic blocking strategy determination and further optimize traffic limiting efficiency, corresponding monitoring data can be obtained based on monitoring node information. The pre-configured information includes monitoring node information about each service interface and entry point pre-configured for the target service.

[0095] The above-mentioned acquisition of traffic monitoring data for the entry point corresponding to the business entry point information based on pre-configured information, and traffic monitoring data for each business interface corresponding to each business interface information, may include the following steps:

[0096] Based on the monitoring node information, the corresponding monitoring node is determined, and based on the monitoring node, the traffic monitoring data of the entry point corresponding to the business entry information and the traffic monitoring data of each business interface corresponding to each business interface information are obtained.

[0097] In this embodiment, the monitoring node information can be the node's IP address or other identifying information that can be used to identify the monitoring node.

[0098] In one implementation, monitoring nodes can be deployed on the outer layer of all business request interfaces. There can be one or more monitoring nodes, capable of monitoring all requests related to the target business (including entry requests). The scope of the monitoring server can be determined, and the monitoring interface response guarantees the number of concurrent requests and the maximum number of concurrent requests, as well as the request latency range, for example, 80-120 ms. Here, the guaranteed concurrency represents the minimum business processing capacity promised by the business request interface, the maximum concurrency represents the maximum possible business processing capacity promised by the business request interface, and the request latency range (i.e., the latency time reaching a preset threshold in this embodiment) represents the reasonable time required for the interface to complete a business request based on the business requirements.

[0099] Optionally, such as Figure 4 As shown, Figure 4 This is another flowchart illustrating the business rate limiting method. Based on the above technical solution, considering the time-dependent nature of business request processing, this embodiment adopts a periodic approach to obtain and control traffic blocking strategies to avoid unnecessary determination and acquisition processes. Specifically, the method provided in this embodiment further includes step S401, and step S201 is further divided into step S201a.

[0100] Step S401: Obtain the acquisition period of the pre-configured traffic blocking policy for the target service;

[0101] Step S201a: At each acquisition cycle, acquire the traffic blocking strategy of the target service.

[0102] In this embodiment, the acquisition period of the traffic blocking strategy and the determination period of the traffic blocking strategy are the same. Based on the above example, N corresponding to the traffic blocking strategy can be adjusted within this period. In other words, after the traffic blocking strategy is determined periodically, the corresponding traffic blocking strategy can be obtained in real time through internal transmission or external transmission.

[0103] Those skilled in the art can configure the acquisition period in conjunction with practical applications and existing technologies. For example, they can configure the corresponding acquisition period by combining historical business request data, which may include data such as the request concurrency and its changes within a time period. In some embodiments, the determination and acquisition period of the traffic blocking strategy can also be determined by adopting other methods.

[0104] Furthermore, after performing the flow control steps, the blocking time interval and the number of blocking times can be recorded and reported at specific intervals, which makes it easier for users to understand the flow control process and can also be used as historical business request data to determine the corresponding period.

[0105] To facilitate understanding of the embodiments of this application, this application provides an exemplary embodiment, the network architecture of which is as follows: Figure 5 As shown, this network architecture deploys multiple server nodes and can be applied to real-time rate limiting devices for multi-task requests. The network architecture includes a service entry point (distinct from the entry point (interface) in this embodiment; this service entry point is a gateway entry point, while the entry point (interface) in this embodiment is an entry request interface for a specific service), a configuration module, a (request) monitoring module, a (statistical) decision module, and an access control module.

[0106] Configuration module: Can be deployed independently and is used for all business configurations of the real-time rate limiting device, such as configuring the associated interfaces of the business (i.e., business interfaces), the entry point (interface), the base capacity of the entry point, the correlation weight between interfaces, etc.

[0107] The monitoring module (which may include 1-N nodes, each node being used to monitor traffic data for each business interface) can be deployed on the outer layer of all business (request) interfaces, using either a request filter or a front-end proxy. It monitors the frequency, latency, etc., of each individual business request (business request service nodes 1-J, i.e., all service nodes other than the ingress request service node), obtains traffic monitoring data, and reports it to the decision-making module.

[0108] Decision module: Can be deployed independently, used to determine traffic blocking strategies in real time or periodically based on configuration information, traffic monitoring data, and preset rules.

[0109] An access control module (which may include 1-M nodes, each node used to control the access control of an entry request for a target service) can be deployed in front of the entry point (request device) of a complex service. It can be deployed in the form of a request filter or a standalone front-end proxy device. Based on the instructions of the decision module, it executes the pass / fail operation or server-side active rejection operation for each request (initiated by the 1-K nodes of the entry request service, i.e., the corresponding entry interface). Based on the above network architecture, this exemplary embodiment includes the following business process:

[0110] I. Configuration Phase

[0111] Based on specific business information (such as account opening), the configuration module configures the following content, i.e., pre-configuration information:

[0112] Entry information: Request type identifier, monitoring server range, which can be one or more servers. The request type identifier can be all or part of the URL address of the HTTP request.

[0113] Monitoring node information: All requests involved in the target business (including entry requests), monitoring server scope, guaranteed concurrency and maximum concurrency of interface responses, and request latency range, for example: 80-120 (ms).

[0114] The guaranteed concurrency level represents the minimum business processing capacity promised by the business request interface; the maximum concurrency level represents the maximum possible business processing capacity promised by the business request interface; and the request delay range represents the reasonable time for the interface to complete the business based on the business requirements.

[0115] Relevance weight: The relevance weight of each business request to the ingress request. This weight is determined based on the effective proportion of requests that can reach the interface from the ingress request, according to actual business statistics or business forecasts.

[0116] Rules: Used to determine traffic blocking strategies. For example, in subsequent steps, the traffic blocking strategy for inbound requests is determined based on actual traffic monitoring data, relevance weights, and corresponding rules. These rules can be determined according to the actual situation.

[0117] One possible rule: Preset the allowed concurrent request count N for inbound requests within a time interval K. At startup, write N to the high-speed cache of the admission control module at time intervals K. Upon receiving an inbound request, perform an atomic operation to read N by -1. If the read result is less than 0, the request is rejected. When the monitoring data of any business interface exceeds the set threshold range, multiply the monitoring concurrency of that business request by the correlation weight, and then by a scaling factor to obtain the new value of N. Adjust N every time interval O until all request monitoring data returns to a reasonable response threshold range.

[0118] II. Monitoring and Reporting Phase

[0119] The monitoring module can be deployed as a standalone agent or an embedded module. In agent mode, one or more nodes can be deployed. In embedded module mode, one embedded module is deployed on each service node in the corresponding business system.

[0120] After the monitoring module starts, it listens to the configured interfaces during the request process, records the start time and end time of each request, and calculates the response time.

[0121] Based on the above data, the number of requests within a time period T on this deployment instance can be counted. This may also include the maximum / minimum, average, and 99th / 95th percentile values ​​of the request duration. In other embodiments, other monitoring values ​​may be set according to business characteristics.

[0122] The traffic monitoring data mentioned above is reported to the statistical decision module at time intervals T.

[0123] III. Statistical Decision-Making Stage

[0124] After the decision-making module starts, it first sets the preset value N as the initial preset value according to the configuration; then it receives data sent back periodically by the monitoring module and records it locally; it aggregates and statistically analyzes the statistical data of multiple request nodes of the target business, which may include: total number of executions, total maximum and minimum duration, average duration weighted by the number of executions, 95th percentile, 99th percentile duration, etc.

[0125] Based on the rules preset during the configuration phase, the value of the maximum number of requests allowed per period N is adjusted, which is the latest traffic blocking policy. The latest traffic blocking policy is sent to the admission control module at time intervals K.

[0126] IV. Access Control Phase

[0127] After the access control module starts, it receives the entry (identifier) ​​information described in the configuration information, refreshes the time interval K, and receives the dynamic allowed request count threshold N periodically transmitted by the decision module. Optionally, to ensure the stability of this module itself, under the premise of unstable interaction between the two modules, an access count refresh mechanism can be added to this module to ensure the normal execution of the independent module when the interaction between the modules fails occasionally.

[0128] The access control module can monitor the entry point and perform a count after each operation. When the count exceeds the threshold of the blocking policy within a period, a single blocking operation is performed.

[0129] Furthermore, the access control module can also report the blocking time interval and the number of blocking times to the decision control module at specific intervals.

[0130] As can be seen, this application's embodiments, based on business relevance, utilize multi-interface monitoring linkage and ingress blocking mechanisms to overcome the limitations of conventional firewalls and rate limiting devices' single-rule limitations. It can achieve overall linkage control of related services and effectively guarantee the performance of multi-node services in execution.

[0131] Please refer to Figure 6 , Figure 6 A schematic diagram of a service rate limiting device 60 provided in this application embodiment includes:

[0132] The policy acquisition module 61 is configured to acquire the traffic blocking policy of the target service. The traffic blocking policy is determined based on the traffic monitoring data corresponding to the pre-configuration information of the target service. The pre-configuration information includes the service entry information and at least one service interface information pre-configured for the target service. The traffic blocking policy includes the traffic blocking policy of the entry corresponding to the service entry information.

[0133] The access control module 62 is configured to control the flow of the ingress based on a flow blocking policy in response to the ingress receiving an ingress service request from the target service.

[0134] In one implementation, determining the traffic blocking strategy for the target service specifically involves: obtaining traffic monitoring data of the entry point corresponding to the service entry point information and traffic monitoring data of each service interface corresponding to each service interface information based on pre-configured information; and determining the traffic blocking strategy for the target service based on the traffic monitoring data of the entry point and the traffic monitoring data of each service interface.

[0135] In one implementation, traffic monitoring data includes the request concurrency of the ingress and / or the baseline concurrency, or the request concurrency of the business interface.

[0136] The device also includes: a delay acquisition module, which is configured to acquire the delay time of service requests; and to determine the traffic blocking strategy for the target service based on the traffic monitoring data of the inlet and the traffic monitoring data of each service interface. Specifically, when the delay time of a service request at any service interface reaches a preset threshold, the limited concurrency of the inlet is determined based on the request concurrency of the corresponding service interface and the request concurrency and / or baseline concurrency of the inlet, and the traffic blocking strategy for the target service is determined based on the limited concurrency of the inlet.

[0137] In one implementation, the pre-configuration information also includes the correlation weights and preset scaling factors among the various service interfaces pre-configured for the target service; the traffic blocking strategy for the target service is determined based on the traffic monitoring data of the ingress and the traffic monitoring data of each service interface, specifically: the traffic blocking strategy for the target service is determined based on the correlation weights, preset scaling factors, and the traffic monitoring data of the ingress and the traffic monitoring data of each service interface.

[0138] In one implementation, the pre-configuration information includes monitoring node information about each service interface and entry point pre-configured for the target service;

[0139] Based on pre-configured information, traffic monitoring data of the entry point corresponding to the business entry point information and traffic monitoring data of each business interface corresponding to each business interface information are obtained. Specifically, the corresponding monitoring node is determined based on the monitoring node information, and based on the monitoring node, traffic monitoring data of the entry point corresponding to the business entry point information and traffic monitoring data of each business interface corresponding to each business interface information are obtained.

[0140] In one embodiment, the device further includes: a period determination module, which sets the acquisition period for acquiring the target service traffic blocking strategy;

[0141] The strategy acquisition module is specifically configured to acquire the traffic blocking strategy for the target business at regular intervals.

[0142] In one implementation, the business entry information includes a business type identifier corresponding to the target business.

[0143] Please refer to Figure 7 , Figure 7 A rate limiting system 10 provided in this application embodiment includes: a service rate limiting device 60 and a rate limiting configuration device 70 connected to the service rate limiting device; the rate limiting configuration device 70 includes a configuration module 71, a monitoring module 72, and a decision module 73; the service rate limiting device includes a policy acquisition module 61 and an access control module 62; wherein,

[0144] Configuration module 71 is configured to configure the pre-configuration information of the target service. The pre-configuration information includes service entry information and at least one service interface information.

[0145] Monitoring module 72 is configured to acquire traffic monitoring data corresponding to pre-configured information;

[0146] The decision module 73 is configured to determine the traffic blocking strategy for the target service based on traffic monitoring data; wherein, the traffic blocking strategy includes the traffic blocking strategy for the entry point corresponding to the service entry information;

[0147] The policy acquisition module 61 is configured to acquire the traffic blocking policy of the target service;

[0148] The access control module 62 is configured to control the flow of the ingress based on a flow blocking policy in response to the ingress receiving an ingress service request from the target service.

[0149] The apparatus or system provided in this application embodiment can be used to execute the technical solution of the service rate limiting method in the above embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.

[0150] It should be noted that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, these modules can be implemented entirely in software via processing element calls; they can be fully implemented in hardware; or some modules can be implemented by processing element calls to software, while others are implemented in hardware. For example, the strategy acquisition module 61 can be a separate processing element, or it can be integrated into a chip in the above device. Alternatively, it can be stored as program code in the memory of the above device, and its function can be called and executed by a processing element of the above device. The implementation of other modules is similar. Moreover, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed through integrated logic circuits in the hardware of the processor element or through software instructions.

[0151] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 8 As shown, the electronic device may include: a processor 81, a memory 82, and a transceiver 83.

[0152] Processor 81 executes computer execution instructions stored in memory, causing processor 81 to perform the scheme in the above embodiments. Processor 81 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0153] The memory 82 is connected to the processor 81 via the system bus and completes communication between them. The memory 82 is used to store computer program instructions.

[0154] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the diagram, but this does not indicate that there is only one bus or one type of bus. Transceivers are used to enable communication between database access devices and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and may also include non-volatile memory.

[0155] The electronic device provided in this application embodiment can be the real-time flow limiting device or banking business system described in the above embodiments.

[0156] This application also provides a chip for executing instructions, which is used to execute the technical solution of the service rate limiting method in the above embodiments.

[0157] This application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed on a computer, the computer performs the technical solution of the service rate limiting method described in the above embodiments.

[0158] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solution of the service rate limiting method in the above embodiments.

[0159] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0160] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to implement the solution of this embodiment according to actual needs.

[0161] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The unit composed of the above modules can be implemented in hardware or in the form of hardware plus software functional units.

[0162] The integrated modules described above, implemented as software functional modules, can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application.

[0163] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.

[0164] The memory may include high-speed RAM, and may also include non-volatile storage (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.

[0165] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0166] The aforementioned storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0167] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. The processor and storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic control unit or main control device.

[0168] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0169] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A method for limiting service flow, characterized in that, include: Obtain the traffic blocking strategy for the target service, wherein the traffic blocking strategy is determined based on traffic monitoring data corresponding to the pre-configuration information of the target service; wherein the pre-configuration information includes pre-configured service entry information and at least one service interface information for the target service, and the traffic blocking strategy includes the traffic blocking strategy for the entry corresponding to the service entry information; wherein the service entry is the first request interface at the logical layer of the target service, and the at least one service interface is a subsequent request interface of the target service; In response to the service entry point receiving a service request from the target service, traffic control is performed on the service entry point based on the traffic blocking policy; Determine the traffic blocking strategy for the target service, including: Based on the pre-configured information, obtain the traffic monitoring data of the entry corresponding to the business entry information, and the traffic monitoring data of each business interface corresponding to each business interface information; Based on the traffic monitoring data of the business entry point and the traffic monitoring data of each business interface, determine the traffic blocking strategy for the target business. The traffic monitoring data includes the request concurrency and / or baseline concurrency of the service entry point, and the request concurrency of the service interface. The method further includes: obtaining the delay time of the service request; The process of determining the traffic blocking strategy for the target service based on traffic monitoring data from the service entry point and traffic monitoring data from each service interface includes: When the latency of a service request at any service interface reaches a preset threshold, the limit concurrency of the service entry is determined based on the request concurrency of the corresponding service interface and the request concurrency and / or baseline concurrency of the service entry, and the traffic blocking strategy for the target service is determined based on the limit concurrency of the service entry.

2. The service rate limiting method according to claim 1, characterized in that, The pre-configuration information also includes the correlation weights and preset scaling factors among the various service interfaces pre-configured for the target service; The process of determining the traffic blocking strategy for the target service based on traffic monitoring data from the service entry point and traffic monitoring data from each service interface includes: The traffic blocking strategy for the target service is determined based on the correlation weight, the preset scaling factor, the traffic monitoring data of the service entry point, and the traffic monitoring data of each service interface.

3. The service rate limiting method according to claim 1, characterized in that, The pre-configured information includes monitoring node information for each service interface and the service entry point, which is pre-configured for the target service. The step of obtaining traffic monitoring data for the entry point corresponding to the service entry information based on the pre-configured information, and traffic monitoring data for each service interface corresponding to each service interface information, includes: Based on the monitoring node information, the corresponding monitoring node is determined, and based on the monitoring node, the traffic monitoring data of the entry corresponding to the business entry information and the traffic monitoring data of each business interface corresponding to each business interface information are obtained.

4. The service rate limiting method according to claim 1, characterized in that, Also includes: Obtain the acquisition period of the pre-configured traffic blocking policy; The acquisition of the traffic blocking strategy for the target service includes: acquiring the traffic blocking strategy for the target service every acquisition period.

5. The service rate limiting method according to claim 1, characterized in that, The business entry information includes the business type identifier corresponding to the target business.

6. A service flow limiting device, characterized in that, include: The strategy acquisition module is configured to acquire the traffic blocking strategy of the target service. The traffic blocking strategy is determined based on traffic monitoring data corresponding to the pre-configured information of the target service. The pre-configured information includes pre-configured service entry information and at least one service interface information for the target service. The traffic blocking strategy includes the traffic blocking strategy of the entry corresponding to the service entry information. The service entry is the first request interface at the logical layer of the target service, and the at least one service interface is a subsequent request interface of the target service. An access control module is configured to perform traffic control on the service entry point based on the traffic blocking policy in response to the service entry point receiving a service request from the target service. The traffic blocking strategy for the target service is determined as follows: based on the pre-configured information, traffic monitoring data of the entry point corresponding to the service entry information and traffic monitoring data of each service interface corresponding to each service interface information are obtained; the traffic blocking strategy for the target service is determined based on the traffic monitoring data of the service entry point and the traffic monitoring data of each service interface. The traffic monitoring data includes the request concurrency and / or baseline concurrency of the service entry point, and the request concurrency of the service interface. The device further includes: a delay acquisition module, configured to acquire the delay time of the service request; The method of determining the traffic blocking strategy for the target service based on the traffic monitoring data of the service entry point and the traffic monitoring data of each service interface is as follows: when the delay time of a service request at any service interface reaches a preset threshold, the limit concurrency of the service entry point is determined based on the request concurrency of the corresponding service interface and the request concurrency and / or baseline concurrency of the service entry point, and the traffic blocking strategy for the target service is determined based on the limit concurrency of the service entry point.

7. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the service rate limiting method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the service rate limiting method as described in any one of claims 1-5.

9. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the traffic limiting method according to any one of claims 1-5.

10. A current limiting system, characterized in that, include: A service rate limiting device and a rate limiting configuration device connected to the service rate limiting device; the rate limiting configuration device includes a configuration module, a monitoring module, and a decision module; the service rate limiting device includes a policy acquisition module and an access control module; wherein... The configuration module is configured to configure pre-configuration information for the target service. The pre-configuration information includes service entry information and at least one service interface information. The service entry is the first request interface at the logical layer of the target service, and the at least one service interface is a subsequent request interface for the target service. The monitoring module is configured to acquire traffic monitoring data corresponding to the pre-configured information. The decision-making module is configured to determine the traffic blocking strategy for the target service based on the traffic monitoring data; wherein, the traffic blocking strategy includes the traffic blocking strategy for the entry point corresponding to the service entry information; The strategy acquisition module is configured to acquire the traffic blocking strategy of the target service; The access control module is configured to perform traffic control on the service entry based on the traffic blocking policy in response to the service entry receiving a service request from the target service. The strategy acquisition module is specifically configured to: acquire traffic monitoring data of the entry point corresponding to the service entry information and traffic monitoring data of each service interface corresponding to each service interface information based on the pre-configuration information; and determine the traffic blocking strategy for the target service based on the traffic monitoring data of the service entry point and the traffic monitoring data of each service interface. The traffic monitoring data includes the request concurrency and / or baseline concurrency of the service entry point, and the request concurrency of the service interface. The strategy acquisition module is further configured to: acquire the delay time of the business request; The method of determining the traffic blocking strategy for the target service based on the traffic monitoring data of the service entry point and the traffic monitoring data of each service interface is as follows: when the delay time of a service request at any service interface reaches a preset threshold, the limit concurrency of the service entry point is determined based on the request concurrency of the corresponding service interface and the request concurrency and / or baseline concurrency of the service entry point, and the traffic blocking strategy for the target service is determined based on the limit concurrency of the service entry point.

Citation Information

Patent Citations

  • Flow control method and apparatus

    CN106603256A

  • Method and device for controlling flow

    CN110430142A