Message processing system and method

By introducing multi-priority message queues and rule configurations into the cloud firewall system, the problem of cloud firewalls being unable to meet the transmission priorities of different services is solved, and priority message transmission and performance improvement are achieved.

CN117812018BActive Publication Date: 2025-09-05CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311712862.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-13
Publication Date
2025-09-05
Estimated Expiration
2043-12-13

Smart Images

  • Figure CN117812018B_ABST
    Figure CN117812018B_ABST
Patent Text Reader

Abstract

The present invention provides a message processing system and method, comprising: a control component, a gateway device, and a cloud firewall device, wherein the cloud firewall device is pre-configured with a message queue set, the message queue set including message queues of multiple priorities; the control component receives rule configuration information, generates gateway rules based on the rule configuration information, and sends the gateway rules to the gateway device; the gateway device receives a message to be transmitted; sets a priority tag for the message based on the gateway rule to obtain a target message; and sends the target message to the cloud firewall device; the cloud firewall device determines a target message queue corresponding to the priority tag of the target message in the message queue set, and uses the target message queue to send the target message to a preset message transmission queue. This system can transmit messages based on their priority, meeting different message transmission requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a message processing system and method. Background Art

[0002] With the development of cloud computing technology, cloud firewalls have been increasingly widely used. Cloud firewalls have traffic forwarding and security protection functions, and play an important role in the safe and stable operation of cloud platforms.

[0003] When processing messages, existing cloud firewalls usually transmit messages in the order in which they are obtained, which cannot meet the message transmission priority requirements of different services. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a message processing system and method that can transmit messages according to their priority, thereby meeting the transmission requirements of different business messages. The specific solution is as follows:

[0005] A message processing system includes:

[0006] A control component, a gateway device, and a cloud firewall device, wherein the cloud firewall device is pre-configured with a message queue set, the message queue set including message queues of multiple priorities;

[0007] The control component is configured to receive rule configuration information, generate gateway rules according to the rule configuration information, and send the gateway rules to the gateway device;

[0008] The gateway device is configured to receive a message to be transmitted; set a priority tag for the message according to the gateway rule to obtain a target message; and send the target message to the cloud firewall device;

[0009] The cloud firewall device is used to determine the target message queue corresponding to the priority tag of the target message in the message queue set, and use the target message queue to send the target message to a preset message transmission queue.

[0010] In the above system, optionally, the gateway device is used to:

[0011] Determining the message type of the currently received message;

[0012] Determine the priority label corresponding to the message type according to the gateway rule;

[0013] A priority tag corresponding to the message type is set for the message to obtain a target message.

[0014] In the above system, optionally, the cloud firewall device is further used to:

[0015] Receive rule configuration information configured by the user through the preset interface;

[0016] The rule configuration information is sent to the control component.

[0017] In the above system, optionally, the cloud firewall device is used to:

[0018] Queue scheduling is performed according to the priority of the target message queue, so as to send the target message in the target message queue to a preset message transmission queue.

[0019] In the above system, optionally, the control component is further used to:

[0020] updating the gateway rule according to at least one of a queue congestion value of each of the message queues in the message queue set and a queue congestion value of the message transmission queue; the queue congestion value represents a congestion level of the queue to which it belongs; the message queue set includes primary message queues and alternative message queues of multiple priorities;

[0021] The updated gateway rules are sent to the gateway device.

[0022] In the above system, optionally, the control component is used to:

[0023] Determining a threshold range of a queue congestion value of the message transmission queue;

[0024] The gateway rule is updated according to configuration information corresponding to the threshold interval of the queue congestion value of the message transmission queue, wherein the configuration information includes a correspondence between a priority label and a message type corresponding to a message queue currently to be enabled in the message queue set.

[0025] In the above system, optionally, the control component is used to:

[0026] When the queue congestion value of the message transmission queue is within a first threshold interval, generating a first gateway rule by using first configuration information corresponding to the first threshold interval, and using the first gateway rule as a new gateway rule; the first configuration information includes a correspondence between priority labels and message types corresponding to primary message queues of respective priorities that currently need to be enabled in the message queue set, and a correspondence between priority labels and message types corresponding to first candidate message queues that currently need to be enabled in the message queue set;

[0027] When the queue congestion value of the message transmission queue is within a second threshold interval, a second gateway rule is generated using second configuration information corresponding to the second threshold interval, and the second gateway rule is used as a new gateway rule; the second configuration information includes a correspondence between a priority tag and a message type corresponding to a primary message queue of each priority currently required to be enabled in the message queue set, a correspondence between a priority tag and a message type corresponding to each first candidate message queue currently required to be enabled, and a correspondence between a priority tag and a message type corresponding to each second candidate message queue currently required to be enabled;

[0028] The maximum value of the first threshold interval is smaller than the minimum value of the second threshold interval, and the priority of the first candidate message queue is lower than the priority of the second candidate message queue.

[0029] In the above system, optionally, the control component is used to:

[0030] When the queue congestion value in the first message queue is less than a preset first congestion threshold, a third gateway rule is generated using preset third configuration information, and the third gateway rule is used as a new gateway rule; the third configuration information includes a correspondence between priority tags and message types corresponding to primary message queues of respective priorities that currently need to be enabled in the message queue set, a correspondence between priority tags and message types corresponding to respective first candidate message queues that currently need to be enabled, and a correspondence between priority tags and message types corresponding to respective second candidate message queues that currently need to be enabled;

[0031] The first message queue is a main message queue with the lowest priority among the message queues, and the priority of the first candidate message queue is lower than the priority of the second candidate message queue.

[0032] In the above system, optionally, the control component is further used to:

[0033] When the queue congestion value of the message transmission queue is greater than a preset second congestion threshold, or when the queue congestion values ​​of the first message queue and the second message queue in each of the message queues are greater than the preset first congestion threshold, the dequeue rates of the first candidate message queue and the second candidate message queue are reduced; the primary message queues in the message queue set include the first message queue, the second message queue, and the third message queue, respectively. The priority of the first message queue is lower than that of the second message queue, and the priority of the second message queue is lower than that of the third message queue.

[0034] A message processing method is applied to a control component in a message processing system, wherein the message processing system further includes a gateway and a cloud firewall, and the method comprises:

[0035] receiving rule configuration information;

[0036] Generate gateway rules according to the rule configuration information;

[0037] The gateway rule is sent to the gateway device, so that when the gateway device receives a message to be transmitted, it sets a priority tag for the message according to the gateway rule to obtain a target message; the target message is sent to the cloud firewall device to trigger the cloud firewall device to determine the target message queue corresponding to the priority tag of the target message in each preset message queue, and use the target message queue to send the target message to the preset message transmission queue.

[0038] Compared with the prior art, the embodiments of the present invention have the following advantages:

[0039] An embodiment of the present invention provides a message processing system and method, comprising: a control component, a gateway device, and a cloud firewall device, wherein the cloud firewall device is pre-configured with a message queue set, the message queue set including message queues of multiple priorities; the control component receives rule configuration information, generates gateway rules based on the rule configuration information, and sends the gateway rules to the gateway device; the gateway device receives a message to be transmitted; sets a priority tag for the message based on the gateway rule to obtain a target message; and sends the target message to the cloud firewall device; the cloud firewall device determines a target message queue corresponding to the priority tag of the target message in the message queue set, and uses the target message queue to send the target message to a preset message transmission queue. Messages can be transmitted according to their priority, thereby ensuring that timely and important messages are transmitted first, thus meeting business needs. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0041] Figure 1 A schematic structural diagram of a message processing system provided by an embodiment of the present invention;

[0042] Figure 2 An example diagram of an implementation scenario provided for an embodiment of the present invention;

[0043] Figure 3 A schematic diagram of a data processing flow of a message processing system provided in an embodiment of the present invention;

[0044] Figure 4 An example diagram of data transmission of a message queue provided in an embodiment of the present invention;

[0045] Figure 5 A scheduling flow chart provided by an embodiment of the present invention;

[0046] Figure 6 A flowchart of a message processing method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0048] In this application, the terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0049] When processing messages, existing cloud firewalls usually process messages in the order in which they are obtained, without considering the message transmission requirements of different businesses. When business traffic is complex and the protection traffic increases, cloud firewalls are prone to performance bottlenecks, resulting in slow message transmission speeds, making it impossible for some time-sensitive messages and important business messages to be processed in a timely manner.

[0050] Based on this, see Figure 1 , an embodiment of the present invention provides a message processing system, including:

[0051] A control component 101, a gateway device 102, and a cloud firewall device 103, wherein the cloud firewall device 103 is pre-configured with a message queue set, and the message queue set includes message queues of multiple priorities;

[0052] The control component 101 is configured to receive rule configuration information, generate gateway rules based on the rule configuration information, and send the gateway rules to the gateway device 102. In this embodiment, the rule configuration information can be configured by the user and can include a correspondence between a priority tag and a message type corresponding to a message queue selected by the user to be activated. The priority tag can be a queue identifier carrying priority information and can be represented by a Differentiated Services Code Point (DSCP) value, for example, 0x10, 0x20, etc., where the queue corresponding to 0x10 has a higher priority than the queue corresponding to 0x20.

[0053] Optionally, the rule configuration information may be configuration information in a json format, and the rule configuration information may be parsed, and then the parsed rule configuration information may be converted into a gateway rule, and the gateway rule may be an iptables rule.

[0054] In this embodiment, the control component may establish a communication connection with the gateway device, and then send the gateway rule to the gateway device.

[0055] The gateway device 102 is used to receive the message to be transmitted; set a priority tag for the message according to the gateway rule to obtain the target message; and send the target message to the cloud firewall device; in this embodiment, the gateway rule can be used to identify the priority of the message to be transmitted, and set a corresponding priority tag for the message, and the message with the priority tag is used as the target message, and the target message is sent to the cloud firewall device.

[0056] Optionally, the gateway device 102 may be a Network Address Translation (NAT) gateway device.

[0057] The cloud firewall device 103 is used to determine the target message queue corresponding to the priority tag of the target message in the message queue set, and use the target message queue to send the target message to the preset message transmission queue. In this embodiment, each message queue in the message queue set has a different corresponding priority tag.

[0058] Optionally, the priority tag carried in the target message can be compared with the priority tag corresponding to each message queue in the message queue set, so as to determine the target message queue corresponding to the priority tag of the target message in the message queue set; after determining the target message queue, the target message can be placed in the target message queue to transmit the target message to a preset message transmission queue through the target message queue; the message transmission queue is used to send the message to user mode processing.

[0059] Optionally, the cloud firewall device can be implemented by software or hardware.

[0060] In the system provided by an embodiment of the present invention, the control component can receive rule configuration information, then generate gateway rules based on the rule configuration information, and send the gateway rules to the gateway device; when the gateway device receives a message to be transmitted, it sets a priority tag for the message according to the gateway rule to obtain a target message; and sends the target message to the cloud firewall device; so that the cloud firewall device determines the target message queue corresponding to the priority tag of the target message in the message queue set, and uses the target message queue to send the target message to the preset message transmission queue, which can transmit the message according to the priority of the message and meet the transmission priority requirements of different messages, thereby avoiding the situation where messages with high timeliness requirements and important business messages cannot be processed in time when a performance bottleneck occurs in the cloud firewall.

[0061] In an embodiment of the present invention, based on the above solution, optionally, the gateway device is configured to:

[0062] Determining the message type of the currently received message;

[0063] Determine the priority label corresponding to the message type according to the gateway rule;

[0064] A priority tag corresponding to the message type is set for the message to obtain a target message.

[0065] In this embodiment, different message types correspond to different priority labels.

[0066] Optionally, different services have different message types, and corresponding priority labels can be set for messages of different message types according to business requirements. The priority label can represent the transmission priority of the message; optionally, business requirements can include timeliness requirements and business importance information. The higher the timeliness requirement or the higher the business importance, the higher the priority represented by the priority label corresponding to the message type.

[0067] In some embodiments, the transmission priority represented by the priority tag may be the first priority, the second priority, or the third priority.

[0068] In an embodiment of the present invention, based on the above solution, optionally, the cloud firewall device is further configured to:

[0069] Receive rule configuration information configured by the user through the preset interface;

[0070] The rule configuration information is sent to the control component.

[0071] In this embodiment, the preset interface may be a cloud firewall web management page, through which the user may enter rule configuration information.

[0072] Optionally, the cloud firewall can use the data mirroring backup tool Rsync to trigger synchronization of the rule configuration information to the control component.

[0073] In an embodiment provided by the present invention, based on the above solution, optionally, the cloud firewall device is used to:

[0074] Queue scheduling is performed according to the priority of the target message queue, so as to send the target message in the target message queue to a preset message transmission queue.

[0075] In this embodiment, the priority of the target message queue can be compared with the priorities of other queues that need to transmit messages to determine the transmission order and message dequeue rate of the target message queue, and the target message in the target message queue is transmitted according to the transmission order and message dequeue rate.

[0076] In an embodiment provided by the present invention, based on the above solution, optionally, the control component is further used to:

[0077] updating the gateway rule according to at least one of a queue congestion value of each of the message queues in the message queue set and a queue congestion value of the message transmission queue; the queue congestion value represents a congestion level of the queue to which it belongs; the message queue set includes primary message queues and alternative message queues of multiple priorities;

[0078] The updated gateway rules are sent to the gateway device.

[0079] In this embodiment, the gateway rules can be dynamically adjusted and updated according to the queue congestion value of the message transmission queue or the queue congestion value of the message queue in the message queue set to increase the working message queue or reduce the working message queue so that the queue congestion value is within an appropriate range, thereby avoiding situations such as message transmission congestion and queue resource waste.

[0080] Optionally, the main message queue may include one or more; when the main message queue includes multiple, the priorities of different main message queues are different. For example, the main message queue may include at least one first message queue, a second message queue and a third message queue. The queue priority of the first message queue is higher than the queue priority of the second message queue, and the queue priority of the second message queue is higher than the queue priority of the third message queue.

[0081] Optionally, the alternative message queues may include one or more; when the alternative message queues include multiple, different alternative message queues have different priorities. For example, the alternative message queues may include at least one first alternative message queue and at least one second alternative message queue, and the queue priority of the first alternative message queue is lower than the queue priority of the second alternative message queue.

[0082] In an embodiment provided by the present invention, based on the above solution, optionally, the control component is used to:

[0083] Determining a threshold range of a queue congestion value of the message transmission queue;

[0084] The gateway rule is updated according to configuration information corresponding to the threshold interval of the queue congestion value, where the configuration information includes a correspondence between a priority label and a message type corresponding to a message queue currently to be enabled in the message queue set.

[0085] In this embodiment, different threshold intervals correspond to different numbers of message queues that need to be enabled in the configuration information; when the congestion value is higher, more message queues need to be enabled.

[0086] In an embodiment provided by the present invention, based on the above solution, optionally, the control component is used to:

[0087] When the queue congestion value of the message transmission queue is within a first threshold interval, generating a first gateway rule by using first configuration information corresponding to the first threshold interval, and using the first gateway rule as a new gateway rule; the first configuration information includes a correspondence between priority labels and message types corresponding to primary message queues of respective priorities that currently need to be enabled in the message queue set, and a correspondence between priority labels and message types corresponding to first candidate message queues that currently need to be enabled in the message queue set;

[0088] When the queue congestion value of the message transmission queue is within a second threshold interval, a second gateway rule is generated using second configuration information corresponding to the second threshold interval, and the second gateway rule is used as a new gateway rule; the second configuration information includes a correspondence between a priority tag and a message type corresponding to a primary message queue of each priority currently required to be enabled in the message queue set, a correspondence between a priority tag and a message type corresponding to each first candidate message queue currently required to be enabled, and a correspondence between a priority tag and a message type corresponding to each second candidate message queue currently required to be enabled;

[0089] The maximum value of the first threshold interval is smaller than the minimum value of the second threshold interval, and the priority of the first candidate message queue is lower than the priority of the second candidate message queue.

[0090] In this embodiment, the queue congestion value may be compared with various preset thresholds, so as to determine the threshold interval in which the queue congestion value is located.

[0091] In an embodiment provided by the present invention, based on the above solution, optionally, the control component is used to:

[0092] When the queue congestion value in the first message queue is less than a preset first congestion threshold, a third gateway rule is generated using preset third configuration information, and the third gateway rule is used as a new gateway rule; the third configuration information includes a correspondence between priority tags and message types corresponding to primary message queues of respective priorities that currently need to be enabled in the message queue set, a correspondence between priority tags and message types corresponding to respective first candidate message queues that currently need to be enabled, and a correspondence between priority tags and message types corresponding to respective second candidate message queues that currently need to be enabled;

[0093] The first message queue is a main message queue with the lowest priority among the message queues, and the priority of the first candidate message queue is lower than the priority of the second candidate message queue.

[0094] In an embodiment provided by the present invention, based on the above solution, optionally, the control component is further used to:

[0095] When the queue congestion value of the message transmission queue is greater than a preset second congestion threshold, or when the queue congestion values ​​of the first message queue and the second message queue in each of the message queues are greater than the preset first congestion threshold, the dequeue rates of the first candidate message queue and the second candidate message queue are reduced; the primary message queues in the message queue set include the first message queue, the second message queue, and the third message queue, respectively. The priority of the first message queue is lower than that of the second message queue, and the priority of the second message queue is lower than that of the third message queue.

[0096] In this embodiment, by reducing the outgoing rates of the first candidate message queue and the second candidate message queue, it is possible to effectively ensure that messages in the high-priority message queue are transmitted first, thereby avoiding congestion of messages in the high-priority queue.

[0097] See also Figure 2, which is an example diagram of an implementation scenario provided by an embodiment of the present invention, shows an implementation scenario including a Controller (control component), a NAT gateway device, a cloud firewall, a DVR distributed routing, a cloud desktop, and an Internet terminal.

[0098] Specifically, you can add a controller namespace, create a virtual private cloud (VPC) through the computing service component OpenStack, and enable Layer 2 communication between the NAT gateway, cloud firewall, and controller.

[0099] In this embodiment, a monitoring process, a configuration synchronization process, and a configuration delivery process are run on the control component Controller. The monitoring process can be used to monitor the busyness of the firewall.

[0100] See also Figure 3 The control component Controller establishes TCP long connection channels with the NAT gateway device and the cloud firewall respectively. Among them, the NAT gateway device side is the real-time rule distribution channel, and the cloud firewall side is the user configuration fast synchronization channel.

[0101] In this embodiment, the NAT gateway rule is sent to add a priority tag to the message.

[0102] Optionally, the cloud firewall obtains the user's priority configuration on the web management console and synchronizes it to the control component Controller for parsing in the form of JSON configuration. The Controller sends the parsed configuration to the NAT gateway in the form of iptables rules. The rules identify packets of different priorities and modify different DSCP values.

[0103] In this embodiment, the cloud firewall device can initialize new backup queues and message identification rules. During service initialization, the cloud firewall device initializes multiple newly added backup queues corresponding to high, medium, and low priority levels for message diversion. Matching rules are issued based on different DSCP values ​​(priority tags) to send messages with different DSCP values ​​to different message queues. A scheduling algorithm then sends messages in the message queues to the NFQ message transmission queue for user-mode processing.

[0104] The following uses a user service process as an example to illustrate the solution provided by the embodiment of the present invention:

[0105] When you activate the Cloud Firewall service, a new namespace is created to serve as the Controller component. The Controller runs the monitoring process FW_detect, the configuration synchronization process Config_sync, and the configuration distribution process Rules_issue. A new VPC and a gatewayless (--gatewaynone) management subnet are created. Ports are created on the NAT gateway, Controller, and Cloud Firewall, enabling Layer 2 connectivity and enabling the Controller to proactively establish persistent TCP connections with the NAT gateway and Cloud Firewall.

[0106] In this embodiment, the cloud firewall initializes 7 new message queues, such as Figure 4 As shown, these are the Q1 high-priority queue, Q2-Q4 medium-priority queues, and Q5-Q7 low-priority queues. The cloud firewall initially issues iptables rules to identify seven different DSCP values ​​for packets, corresponding to seven different packet queues. These seven packet queues are then sent to the NFQ (Non-Frequency Queue) through a scheduling algorithm. The Q1 queue, as the high-priority queue, guarantees immediate entry and exit. The medium-priority queues are dequeued based on the NFQ congestion level, and the low-priority queues are dequeued based on the medium-priority queue's congestion level.

[0107] The cloud firewall web management console provides users with five-tuple packet configuration items. User configurations are synchronized to the control component Controller via Rsync triggering. After identifying the configurations, the control component Controller issues iptables rules through a persistent connection established with the NAT gateway. In the forward chain, the DSCP field of the modified packet is sent for priority differentiation (-j DSCP --set-dscp 0x10 / 20 / 30). Users can configure three priorities: high, medium, and low, corresponding to DSCP values ​​of Q1, Q2, and Q5, respectively.

[0108] When NFQ is not busy, user services will only occupy the three main packet queues, Q1, Q2, and Q5. The monitoring process on the Controller monitors the congestion of each queue on the cloud firewall in real time. Based on the varying levels of congestion, it updates the rules for the NAT gateway, modifying the DSCP values ​​of medium- and low-priority packets using a hash method (i.e., 0x21 / 22 for medium-priority packets and 0x31 / 32 for low-priority packets). This frees up the remaining medium- and low-priority queues (i.e., the second backup packet queues Q3 / Q4 for medium-priority packets and the first backup packet queues Q6 / Q7 for low-priority packets), thus reducing NFQ processing pressure.

[0109] In this embodiment, the scheduling process of data transmission is as follows: Figure 5 As shown, the details are as follows:

[0110] (1) Initially, the Q1, Q2, and Q5 queues are occupied, and the remaining message queues are idle. The congestion value Qval of the NFQ queue is less than K. The first message queue Q1, the second message queue Q2, and the third message queue Q5 are normally enqueued and dequeued, and there is no buffer in the queue. Here, k is the first congestion threshold.

[0111] (2) When K <= Qval < L, the Controller monitors and senses, updates and issues the NAT gateway rules, HASHes the three low-priority DSCP values, and enables the first alternative message queue. The high, medium, and low queues dequeue in a 1:1:1 round-robin manner. For the low-priority queue at this time, one is selected for dequeue in a polling manner. Here, L is the second congestion threshold.

[0112] (3) When L <= Qval < M or the congestion value of the low-priority queue reaches the threshold m, the Controller monitors and senses, updates and issues the NAT gateway rules, HASHes the three medium-priority DSCP values, and enables the second alternative message queue. Enqueue and dequeue while ensuring that the congestion value of the low-priority queue does not increase, and discard the extra enqueued messages. The high, medium, and low queues as a whole still dequeue in a 1:1:1 round-robin manner. For the medium- and low-priority queues at this time, one is selected for dequeue in a polling manner. Here, M is the third threshold.

[0113] (4) When the congestion value Qval of the NFQ queue >= M, or the congestion of the medium- and low-priority queues both reaches the threshold m, reduce the dequeue rate of all backup queues until the medium-priority queue is full and there is a buffer in the high-priority queue. At this time, all newly enqueued messages in the medium-priority queue are discarded until the congestion of the NFQ queue is alleviated.

[0114] When the congestion of the NFQ queue is gradually alleviated, perform reverse processing according to (2) to (4) until the state of (1) is restored after alleviation.

[0115] See Figure 6 , which is the flowchart of a message processing method provided by an embodiment of the present invention. This message processing method can be applied to the control component in the above message processing system. The method includes:

[0116] S601: Receive rule configuration information.

[0117] S602: Generate gateway rules according to the rule configuration information.

[0118] S603: Send the gateway rules to the gateway device, so that when the gateway device receives a message to be transmitted, set a priority label for the message according to the gateway rules to obtain a target message; send the target message to the cloud firewall device to trigger the cloud firewall device to determine the target message queue corresponding to the priority label of the target message in each preset message queue, and use the target message queue to send the target message to the preset message transmission queue.

[0119] By applying the method provided in the embodiment of the present invention, messages can be transmitted according to their priorities, thus meeting different message transmission requirements.

[0120] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similarities between the various embodiments can be referred to in conjunction with each other. For device embodiments, since they are generally similar to method embodiments, their description is relatively simple, and for relevant details, reference can be made to the description of the method embodiments.

[0121] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0122] For the convenience of description, the above device is described as being divided into various units according to their functions. Of course, when implementing the present invention, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0123] From the above description of the embodiments, it can be seen that those skilled in the art can clearly understand that the present invention can be implemented by means of software plus the necessary general hardware platform. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present invention or certain parts of the embodiments.

[0124] The above is a detailed introduction to a message processing system provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

Claims

1. A message processing system, characterized in that: include: A control component, a gateway device, and a cloud firewall device, wherein the cloud firewall device is pre-configured with a message queue set, the message queue set including message queues of multiple priorities; The control component is configured to receive rule configuration information, generate gateway rules according to the rule configuration information, and send the gateway rules to the gateway device; The gateway device is used to receive a message to be transmitted; set a priority tag for the message according to the gateway rule to obtain a target message; Sending the target message to the cloud firewall device; The cloud firewall device is configured to determine a target message queue corresponding to the priority tag of the target message in the message queue set, and send the target message to a preset message transmission queue using the target message queue; The control component is further used to: The gateway rule is updated according to at least one of the queue congestion values ​​of each of the message queues in the message queue set and the queue congestion value of the message transmission queue; the queue congestion value represents the congestion level of the queue to which it belongs; the message queue set includes primary message queues and alternative message queues of multiple priorities; and the updated gateway rule is sent to the gateway device.

2. The system according to claim 1, wherein: The gateway device is used to: Determining the message type of the currently received message; Determine the priority label corresponding to the message type according to the gateway rule; A priority tag corresponding to the message type is set for the message to obtain a target message.

3. The system according to claim 1, wherein: The cloud firewall device is further used to: Receive rule configuration information configured by the user through the preset interface; The rule configuration information is sent to the control component.

4. The system according to claim 1, wherein: The cloud firewall device is used to: Queue scheduling is performed according to the priority of the target message queue, so as to send the target message in the target message queue to a preset message transmission queue.

5. The system according to claim 1, wherein: The control component is used to: Determining a threshold range of a queue congestion value of the message transmission queue; The gateway rule is updated according to configuration information corresponding to the threshold interval of the queue congestion value, where the configuration information includes a correspondence between a priority label and a message type corresponding to a message queue currently to be enabled in the message queue set.

6. The system according to claim 5, characterized in that The control component is used to: When the queue congestion value of the message transmission queue is within a first threshold interval, generating a first gateway rule by using first configuration information corresponding to the first threshold interval, and using the first gateway rule as a new gateway rule; the first configuration information includes a correspondence between priority labels and message types corresponding to primary message queues of respective priorities that currently need to be enabled in the message queue set, and a correspondence between priority labels and message types corresponding to first candidate message queues that currently need to be enabled in the message queue set; When the queue congestion value of the message transmission queue is within a second threshold interval, a second gateway rule is generated using second configuration information corresponding to the second threshold interval, and the second gateway rule is used as a new gateway rule; the second configuration information includes a correspondence between a priority tag and a message type corresponding to a primary message queue of each priority currently required to be enabled in the message queue set, a correspondence between a priority tag and a message type corresponding to each first candidate message queue currently required to be enabled, and a correspondence between a priority tag and a message type corresponding to each second candidate message queue currently required to be enabled; The maximum value of the first threshold interval is smaller than the minimum value of the second threshold interval, and the priority of the first candidate message queue is lower than the priority of the second candidate message queue.

7. The system according to claim 1, wherein: The control component is used to: When the queue congestion value in the first message queue is less than a preset first congestion threshold, a third gateway rule is generated using preset third configuration information, and the third gateway rule is used as a new gateway rule; the third configuration information includes a correspondence between priority tags and message types corresponding to primary message queues of respective priorities that currently need to be enabled in the message queue set, a correspondence between priority tags and message types corresponding to respective first candidate message queues that currently need to be enabled, and a correspondence between priority tags and message types corresponding to respective second candidate message queues that currently need to be enabled; The first message queue is a main message queue with the lowest priority among the message queues, and the priority of the first candidate message queue is lower than the priority of the second candidate message queue.

8. The system according to claim 6 or 7, characterized in that The control component is further used to: When the queue congestion value of the message transmission queue is greater than a preset second congestion threshold, or when the queue congestion values ​​of the first message queue and the second message queue in each of the message queues are greater than the preset first congestion threshold, the dequeue rates of the first candidate message queue and the second candidate message queue are reduced; the primary message queues in the message queue set include the first message queue, the second message queue, and the third message queue, respectively. The priority of the first message queue is lower than that of the second message queue, and the priority of the second message queue is lower than that of the third message queue.

9. A message processing method, characterized in that: Applied to the message processing system as claimed in claim 1, the message processing system further comprising a gateway device and a cloud firewall, the method comprising: receiving rule configuration information; Generate gateway rules according to the rule configuration information; The gateway rule is sent to the gateway device, so that when the gateway device receives a message to be transmitted, it sets a priority tag for the message according to the gateway rule to obtain a target message; the target message is sent to the cloud firewall to trigger the cloud firewall to determine the target message queue corresponding to the priority tag of the target message in each preset message queue, and use the target message queue to send the target message to the preset message transmission queue.

Citation Information

Patent Citations

  • Message control method and device

    CN106411780A

  • The invention relates to a method for guaranteeing QoS under a multi-core network of a trunking communication system

    CN108990115A