Fault-induced client retrieval method and system using fault-to-corresponding-edge-server grouping
By grouping and dynamically allocating fault-edge servers, the problem of false detection in multi-client fault identification was solved, enabling accurate identification of DDoS attack initiator IPs and continuous network communication, thus reducing equipment and time losses.
Patent Information
- Application Number
- CN202410448542.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-21
- Filing Date
- 2020-08-20
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2040-08-20
AI Technical Summary
Existing technologies are prone to detection errors when identifying multiple clients simultaneously causing network failures, leading to false detections of non-faulty clients. This makes it impossible to effectively identify the IP address of the DDoS attack initiator, and traditional defense technologies cannot maintain continuous service.
By grouping the edge servers corresponding to the faults, and using multiple edge server groups and subgroups to replace the faulty edge servers, client retrieval is performed. Edge servers are dynamically allocated to identify the fault-inducing clients, and attack initiators are accurately retrieved through DNS resolution and client information monitoring.
It enables the maintenance of network communication continuity when the client part of the path fails, accurately identifies the IP of the DDoS attack initiator, reduces time loss and equipment costs, is applicable to a wide range of path specification systems, and defends against various DDoS attacks.
Smart Images

Figure CN118353764B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method and system for retrieving clients that induce network failures. As an invention for retrieving clients that induce network failures, it specifically retrieves faulty clients that induce network failures by grouping the edge servers corresponding to the failures. Background Technology
[0002] The client route control system is used to retrieve clients that cause network failures, such as identifying the IP address of the DDoS attack initiator. This is achieved by using multiple edge servers, client route control servers, and DNS (Domain Name Server). By specifying the edge server to which the user is connected, the client route is controlled to detect and identify DDoS attacks.
[0003] Generally speaking, DDoS attacks fall into two categories. The first type occurs when an excessive amount of workload enters the server, causing it to crash. In this case, the server becomes overwhelmed by the excessive workload and crashes.
[0004] The second type is network traffic flooding, rendering the network line itself completely unusable. This type of attack does not affect the server, but because the line connecting to the server is unusable, communication between the server and client is impossible. In other words, even if the server is functioning correctly, the network will experience problems, making it difficult to maintain service. While many DDoS security technologies have been developed to address this situation, none have fundamentally solved the real-world problem. Traditional DDoS defense technologies can block the DDoS attack itself, but they cannot search for and identify the IP address of the attacker who is directing the attack.
[0005] Furthermore, to prevent DDoS attacks, cutting off the line or IP band where the attack is occurring will prevent legitimate users belonging to that line and band from accessing the service. This will cause fatal cost and time losses for service providers such as financial institutions, public institutions, and gaming companies that require 24 / 7 service.
[0006] To address this issue, existing technologies have provided inventions for client-side retrieval that utilize an edge server configured with multiple stages and combine multiple paths. By providing each client with a unique path, the retrieval of the client causing the network failure is completed. (Korean Patent 10-1569857, 2015.11.11).
[0007] However, existing registered patents, which use client path control systems to retrieve faulty clients, are not significantly different from this invention if the client that caused the network failure is the same. But if multiple clients cause the network failure at the same time, then detection errors may occur, leading to such a possibility.
[0008] For example, according to existing patents, when an edge server group consisting of 6 edge servers is arranged in a 3x2 matrix to form a client edge server IP allocation matrix for searching for the cause of a fault, it can be combined with... Figure 11 The structure shown is the same. The edge server group has six edge servers, from edge server 1 to edge server 6. These six edge servers are used, and a 3x2 matrix is used to assign edge servers to clients, thus identifying eight clients (A to H). Specifically, edge server 1 is assigned to clients A to D, and edge server 4 is assigned to clients E to H. Furthermore, when edge server 1 fails, according to the edge server IP allocation matrix, clients A and B are assigned to edge server 2, and clients C and D are assigned to edge server 5. If edge server 5 fails, client C, affected by the edge server IP allocation matrix, is assigned to edge server 3, and client D is assigned to edge server 6. Then, when client 6 fails, client D is identified as the client that caused the failure.
[0009] But if Figure 12 As shown, when clients A and F fail simultaneously, under the influence of the edge server IP allocation matrix, the failures first occur on edge server 1 and edge server 4, then on edge server 2, and then on edge server 3 and edge server 6. Ultimately, if clients A and F fail simultaneously, failures will occur on edge servers 1, 2, 3, 4, and 6. In this case, client B, which is allocated to edge servers 1, 2, and 6, and client E, which is allocated to edge servers 4, 2, and 3, are also simultaneously identified as the clients that triggered the failures. That is, the actual clients that triggered the failures are clients A and F, but clients B and E are also considered to have triggered the failures. Summary of the Invention
[0010] The problem that the invention aims to solve
[0011] The present invention addresses the problems in existing technologies by providing a method and system for retrieving fault-inducing clients using a grouping of fault-corresponding edge servers. It first searches for fault-inducing clients that triggered network failures. To prevent servers from being affected by service failures caused by abnormal network failures, when a failure occurs on an edge server, a subgroup of fault-corresponding edge servers selected from a group of multiple fault-corresponding edge servers is used to replace the faulty edge server. If the replaced fault-corresponding edge server also fails, it is replaced by another subgroup of fault-corresponding edge servers. This process is repeated to retrieve the server that triggered the failure.
[0012] Solution for solving the problem
[0013] The present invention, created to address the aforementioned technical problem, utilizes a method for retrieving fault-inducing clients by grouping fault-corresponding edge servers. The method includes: distributing communication processing of a first client group consisting of multiple client terminals to an edge server; distributing communication processing of a second client group belonging to the first client group, containing at least one client terminal, to the fault-corresponding edge server when the edge server malfunctions; and determining whether the fault-corresponding edge server malfunctions during operation. Specifically, when the fault-corresponding edge server malfunctions, if the number of client terminals distributed to the fault-corresponding edge server exceeds a preset number, then the communication processing of a sub-client group belonging to the client group distributed to the fault-corresponding edge server, containing at least one client terminal, is distributed to the fault-corresponding edge server; when the fault-corresponding edge server malfunctions, if the number of client terminals distributed to the fault-corresponding edge server equals a preset number, then the predetermined number of client terminals is identified as fault-inducing clients.
[0014] The fault-corresponding edge server subgroup is characterized in that, when an edge server or a fault-corresponding edge server fails, the number of clients and connection records allocated to the failed edge server or fault-corresponding edge server are analyzed, and the subgroup is composed of multiple fault-corresponding edge servers based on the number of unallocated fault-corresponding edge servers in the fault-corresponding edge server group. The fault confirmation of the edge server or fault-corresponding edge server is characterized in that it is unrelated to or unaffected by DNS resolution received from clients, and the fault confirmation is performed based on monitoring the occurrence of the fault of the edge server or fault-corresponding edge server.
[0015] The fault-induced client detection method based on the fault-corresponding edge server grouping in this invention is characterized in that, when an edge server or a fault-corresponding edge server fails, the client IP or user information that is using the edge server or fault-corresponding edge server that has failed is searched. If a DNS resolution request is received, the fault-corresponding edge server selected from the fault-corresponding edge server group is provided to the searched client.
[0016] The plurality of clients are characterized in that they include: a proxy for sending DNS resolution, which, when an edge server or a fault-corresponding edge server fails, connects to a fault-corresponding edge server selected in the fault-corresponding edge server group; the proxy requests to send DNS resolution including user information, and if it receives DNS resolution from the client's proxy, it extracts user information from the client's DNS resolution and extracts user information from the fault-corresponding edge server group, and provides the client with the IP address of the fault-corresponding edge server selected in the fault-corresponding edge server group that corresponds to the extracted user information.
[0017] The present invention, used to achieve the aforementioned technical problem, utilizes a fault-inducing client retrieval system that groups fault-corresponding edge servers. The system comprises: an edge server group, containing multiple edge servers located on the path connecting the client and the service server; and a fault-corresponding edge server group, consisting of fault-corresponding edge servers located on the path connecting the client and the service server, which replace the faulty edge server when it fails, and other fault-corresponding servers that replace the faulty edge server. Furthermore, when an edge server or a fault-corresponding edge server fails, the system includes a fault pair consisting of a larger number of fault-corresponding edge servers than the number of the faulty edge servers or the fault-corresponding edge servers. The system includes: an edge server subgroup; a DNS control unit that responds to DNS resolutions sent by the client, providing the edge server IP or the fault-corresponding edge server IP in the order of client IP or user information; a fault occurrence confirmation unit that confirms whether a fault has occurred on the edge server or the fault-corresponding edge server; and an edge server control unit that, when a fault occurs on the edge server or the fault-corresponding edge server, replaces the fault-causing edge server or the fault-corresponding edge server with the fault-corresponding edge server subgroup selected from the fault-corresponding edge server group, and sends this information to the client. If there is only one client corresponding to the fault-corresponding edge server, that unique client is identified as the fault-inducing client.
[0018] The fault confirmation unit is characterized by its ability to continuously monitor the faults of edge servers or the corresponding edge servers, unaffected by DNS resolution. When a fault occurs on the edge server or the corresponding edge server, the edge server control unit retrieves the IP address or user information of the client using the faulty edge server or the corresponding edge server, and assigns the selected fault-corresponding edge server IP address from the fault-corresponding edge server group to the retrieved client IP address or user information. If the client corresponding to the retrieved client IP address or user information requests DNS resolution, the DNS control unit, under the control of the edge server control unit, sends the assigned fault-corresponding edge server IP address to the retrieved client via a DNS server. Furthermore, the DNS control unit is unaffected by DNS resolution and, under the control of the edge server control unit, can transmit the assigned fault-corresponding edge server IP address to the retrieved client via a DNS server.
[0019] The client is characterized by including a proxy that, when an edge server or a fault-corresponding edge server fails, sends a DNS resolution containing user information in order to reconnect to a selected fault-corresponding edge server in the fault-corresponding edge server group. At this time, if the edge server control unit receives the DNS resolution from the client proxy, it extracts the user information from the client's DNS resolution. The edge server or fault-corresponding edge server is characterized by being connected to the client and server, and includes at least one of software, a server, and a hardware device with relay or service functions.
[0020] Furthermore, a client terminal connection control method for implementing the client terminal connection control device based on the present invention includes: a step of allocating communication processing of a first client group consisting of multiple client terminals to an edge server; a step of allocating communication processing of a second client group generated by splitting the first client group to the edge server corresponding to the fault when the edge server malfunctions; and a step of determining whether the malfunction of the edge server corresponding to the fault has occurred.
[0021] When the edge server corresponding to the fault experiences an operational failure, if there are multiple client terminals assigned to the edge server corresponding to the fault, the client group assigned to the edge server is split, and the communication processing of the resulting sub-client groups is assigned to the edge server corresponding to the fault.
[0022] When the edge server corresponding to the fault experiences an operational failure, if there is only one client terminal assigned to the edge server corresponding to the fault, then that client terminal is identified as the fault-inducing client terminal.
[0023] Furthermore, a client terminal connection control device based on the present invention is characterized by comprising: a communication unit for performing data communication with an edge server and a fault-corresponding edge server; and a processor for distributing communication processing of a first client group consisting of multiple client terminals to the edge server, and distributing communication processing of a second client group belonging to the first client group, which includes at least one client terminal, to the fault-corresponding edge server when the edge server malfunctions, thereby determining whether the fault-corresponding edge server has malfunctioned.
[0024] When the edge server corresponding to the fault malfunctions, if there are multiple client terminals assigned to the edge server, the processor will allocate communication processing of sub-client groups generated from the client groups assigned to the edge server to the edge server. If there is only one client terminal assigned to the edge server when the edge server malfunctions, the processor will identify that single client terminal as the fault-inducing client terminal.
[0025] In addition, in order to realize the description of the invention, the present invention also provides: a program that runs based on the control of a processor and a recording medium for reading the program based on the recording processor.
[0026] Invention Effects
[0027] This invention provides a method and system for retrieving fault-inducing clients by grouping fault-corresponding edge servers. This method searches for fault-inducing clients that trigger network faults, preventing the server from being affected by service failures caused by abnormal network faults. Therefore, it ensures the service provided to clients, and even if a fault occurs on a part of the client's path, the fault-corresponding edge servers maintain continuous network communication.
[0028] Furthermore, based on this invention, the edge server that caused the fault and the corresponding edge server are replaced by a subgroup of fault-corresponding edge servers. By accurately retrieving the client that triggered the fault, the IP address of the DDoS attack initiator can be more easily identified, thereby blocking the DDoS attack. That is, the edge server or fault-corresponding edge server used by each client is dynamically allocated by the fault-corresponding edge server subgroup. If a fault occurs on an edge server or fault-corresponding edge server, the server causing the fault can be identified immediately. In this way, only the client that caused the fault can be blocked, ensuring that users normally using network services are not affected. Moreover, the time spent on logarithmic analysis for DDoS retrieval can be reduced, thus minimizing time loss.
[0029] According to the present invention, since the path is specified based on client information, it is widely applicable. In other words, because the present invention specifies the path based on client information, it must be applicable to the path specification system and use the corresponding path regardless of the method used by the client. This approach has a much wider range of applications compared to ACL or Null Routing techniques that only use IP or port filtering.
[0030] Furthermore, based on this invention, a solution capable of defending against various forms of DDoS attacks can be obtained. In this invention, by using edge servers or fault-following servers, clients and servers can be prevented from directly connecting. This means that DDoS attack initiators cannot directly launch DDoS attacks on the server. Even if a DDoS attack initiator targets a network line, that line is only connected to the DDoS attack initiator; therefore, blocking only that line will not affect other lines, thus successfully completing the defense. Using a smaller number of edge servers, DDoS attack initiators can be identified. From this perspective, the cost of maintaining network security can be reduced, as can the necessary equipment, personnel, and time losses.
[0031] Furthermore, the edge server and fault-response edge server based on this invention are actually constructed using the same hardware / software. For system administrators, the structure of the edge server and fault-response edge server can be adaptively adjusted and managed according to different network environments. Specifically, to provide sufficient line traffic to network-connected client terminals, some fault-response edge servers are replaced with edge servers. Similarly, if it is inferred that a network-connected client terminal contains multiple fault-inducing clients, for network security, some edge servers can be converted into fault-response edge servers, thus quickly identifying the fault-inducing clients on the client terminals.
[0032] As described above, in the fault-inducing client retrieval method of this invention, the time complexity of searching for fault-inducing clients connected to an edge server is calculated using the formula (logsn), thus providing a retrieval environment for quickly retrieving fault-inducing clients. Here, s represents the number of edge servers corresponding to the fault, and n represents the number of clients connected to the edge servers. Attached Figure Description
[0033] Figure 1 This is a flowchart illustrating an embodiment of the system structure to which the present invention applies.
[0034] Figure 2 This is a flowchart illustrating a fault-inducing client retrieval method based on fault-corresponding edge server grouping in an embodiment of the present invention.
[0035] Figure 3 This is a flowchart illustrating a fault-inducing client retrieval method utilizing fault-corresponding edge server groups in an embodiment of the present invention.
[0036] Figure 4 The diagram shows a flowchart of an embodiment where, when a DNS resolution is received from a client, after confirming whether the edge server or the edge server corresponding to the fault has malfunctioned, an edge server subgroup is used to replace the faulty edge server or the edge server corresponding to the fault, and the client that caused the fault is retrieved.
[0037] Figure 5 The diagram shows a flowchart of an embodiment in which, regardless of whether DNS resolution is received from the client, after confirming whether the edge server or the edge server corresponding to the fault has malfunctioned, an edge server subgroup is used to replace the faulty edge server or the edge server corresponding to the fault, and the client that caused the fault is retrieved.
[0038] Figure 6 This is an accompanying drawing illustrating an edge server allocation method according to an embodiment of the present invention.
[0039] Figure 7 This is an attached diagram showing how client 1 becomes a malfunctioning client when malicious code or a hacker attack occurs.
[0040] Figure 8 The diagram illustrates how clients 1, 4, and 7 are assigned to edge server subgroup 1 when the client connected to the attacked edge server 1 is replaced with the faulty edge server to address the problem.
[0041] Figure 9 The attached diagram illustrates how client 1 and client 4 are separated and then reassigned to the corresponding edge server subgroup 2 after the failure.
[0042] Figure 10 This is an illustration of the process of connecting to a faulty edge server and identifying a client that attacks the corresponding faulty edge server as the cause of the fault.
[0043] Figure 11 as well as Figure 12 The attached figure illustrates the fault-induced client retrieval method using a patented client path control system.
[0044] Figures 13 to 16The accompanying drawings illustrate the fault-inducing client retrieval method in this invention, which utilizes fault-corresponding edge server grouping.
[0045] Figures 17 to 18 The accompanying drawing illustrates a fault-inducing client retrieval method according to an embodiment of the present invention. Detailed Implementation
[0046] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings. The embodiments described in this specification and the structures illustrated in the drawings are merely examples of the present invention and do not represent all the core technical ideas of the present invention. Therefore, in applying for this invention, it should be considered that various equivalents and modified embodiments can be substituted to realize the core principles of the present invention.
[0047] Figure 1 This is a flowchart illustrating an embodiment of the system structure to which the present invention applies. The system to which the present invention applies includes: multiple clients 100; a DNS server 110; a client path control server 120; a service relay network 130; and a service server 140.
[0048] In this invention, the service relay network 130 includes: an edge server group 132, which comprises multiple edge servers or hardware devices having service relay functions or service functions; a gateway; a router; a switch; a hub; and other network devices. Furthermore, the service relay network 130 includes a fault-responding edge server group 134, which can replace the faulty edge server when a fault occurs on the edge server and retrieve the fault-inducing client.
[0049] Generally, a network includes: web servers; DNS servers and many other servers; and network devices such as gateways, routers, switches, and hubs. The server receives and processes client requests. The network devices, on the other hand, transmit data packets from the client. Each device sends the data packets received from the client to the server without loss, using the fastest transmission path. The server then quickly processes the client's request before retransmitting it. When a problem occurs on a device or line, the network's ability to handle the problem becomes vulnerable.
[0050] The edge server used in this invention is primarily for achieving the purposes of this invention. It consists of servers with service relay or service functions, such as proxy servers and cache servers, as well as hardware devices. Furthermore, the edge server includes programs with service relay or service functions and also serves as a service path for client connections, thus enabling clients to connect to the service server.
[0051] When client 100 connects to the server, most clients connect to service server 140 using DNS. This invention includes: an edge server and a fault-tolerant edge server, and a Client Route Control Server (CRCS) 120 that manages them.
[0052] Client 100 connects to service server 140 to receive services, and first receives the IP address of service server 140 through DNS server 110. For this purpose, client 100 sends DNS resolution to DNS server 110.
[0053] After receiving DNS resolution from clients 102 / 104, DNS server 110 will transmit the DNS resolution to client path control server 120 if the IP address of the corresponding service server is not stored.
[0054] The client path control server 120 receives the client's DNS resolution from the DNS server 110, assigns and transmits the IP of the edge server belonging to the service relay network 130 separately, and transmits the assigned edge server IP to the client through the DNS server 110.
[0055] To further explain the Client Path Control Server (CRCS) 120, it verifies the status of the edge server and the corresponding faulty edge server, and manages the data of the client, the edge server, and the corresponding faulty edge server. The client transmits data after specifying the IP address of either the edge server or the faulty edge server individually. The CRCS 120 receives DNS requests, verifies the status of the edge server and the corresponding faulty server, specifies the domain name and the client's IP address or the IP address of the edge server corresponding to the client's IP address or the faulty edge server's IP address, stores the specified information, and then transmits the DNS response.
[0056] The client 100 requesting DNS resolution receives the IP information of the edge server or the IP address of the faulty edge server, connects to the edge server or the faulty edge server, and receives services from the service server 140.
[0057] More specifically, client 100 sends a DNS resolution request to DNS server 110 to confirm the server address. If the requested domain name is not found on its own server, DNS server 110 sends a request to the upstream DNS server to search for the IP address corresponding to the domain name.
[0058] To further explain DNS server 110, it is a general DNS device that receives the domain name requested by the client and responds with the IP address corresponding to the domain name. It may also include related concepts and techniques. DNS server 110 transmits the IP address corresponding to the domain name to the client. Through this process, DNS resolution moves to CRCS 120, which contains the domain name requested by client 100 and the client's IP address. At this point, CRCS 120 prepares the IP addresses of applicable edge servers or fault-following servers on the inherent path according to the path control algorithm and the order of the client's IP addresses.
[0059] Figure 2 This is a flowchart illustrating a fault-inducing client retrieval method utilizing fault-corresponding edge server grouping according to an embodiment of the present invention. (Refer to...) Figure 2 This embodiment utilizes a fault-inducing client retrieval system 20 for fault-corresponding edge server groups in this invention, which includes: an edge server group 260; a fault-corresponding edge server group 270; and a client path control server 20.
[0060] Edge server group 260 contains multiple edge servers 260-1 and 260-n configured on the path connecting client 210 and service server 280. It monitors the communication traffic between the client and service server, and forwards packets from the client to the service server. It is a collection of edge servers performing this function. Each edge server can accommodate more than one client connection; the edge servers in the edge server group are assigned a server when a client first connects to the service server.
[0061] The fault-corresponding edge server group 270 is located on the path connecting the client 210 and the service server 280. It consists of fault-corresponding edge servers 270-1, 270-m, 270-nm, and 270-n, which replace the fault-causing edge server when a fault occurs on edge servers 260-1 and 260-n; and other fault-corresponding edge servers 270-1, 270-m, 270-nm, and 270-n that are replaced by the fault-corresponding edge servers. It also includes a fault-corresponding edge server subgroup 275, which consists of fault-corresponding edge servers 270-1 and 270-m. When a fault occurs on an edge server or a fault-corresponding edge server, the number of fault-corresponding edge servers exceeds the number of edge servers that caused the fault.
[0062] The fault-responsible edge server 270 is assigned to the edge server that caused the fault. When the client being used accepts the assignment from the edge server again, in order to retrieve the client that caused the fault, the fault-responsible edge server can accommodate more than one client connection as a combination of the assigned fault-responsible edge servers. The fault-responsible edge server is not normally assigned; it is only assigned when a client assigned to the fault-causing edge server requests the edge server assignment on the fault occurrence confirmation unit 240 of the client path control server 20.
[0063] When the fault-response edge server actually performs fault response, the fault-response edge server group 270 is not performed as a whole. Instead, the fault-response edge server subgroup control algorithm is used on the edge server control unit 250 of the client path control server 20 to generate fault-response edge server subgroups according to logic, and the fault-response edge servers are included in them. Then, the fault-response edge servers within the fault-response edge server subgroup 275 are allocated.
[0064] The fault-responsible edge server subgroup 275 is a hypothetical fault-responsible edge server subgroup logically generated within the fault-responsible edge server subgroup 270. When a fault actually occurs on an edge server and fault-responsible edge servers are used to initiate the response, the fault-responsible edge server subgroup is not allocated as a whole. Instead, the fault-responsible edge server subgroup control algorithm of the edge server control unit 250 generates a fault-responsible edge server subgroup in a hypothetical form. It analyzes the number of clients and connection records already allocated to the edge server where the fault occurred, and considers the number of fault-responsible edge servers that have not been allocated in the fault-responsible edge server subgroup. After selecting an appropriate number, it allocates them to the fault-responsible edge server subgroup generated in a hypothetical form. Then, through the edge server grouping and allocation algorithm, it is allocated to the fault-responsible edge servers within the generated fault-responsible edge server subgroup 275.
[0065] After the fault-handling subgroup is deleted upon completion of the fault-handling process, the fault-handling edge servers assigned to it are placed on the unassigned fault-handling edge server group. The fault-handling edge server subgroup consists of hypothetical groups, which are generated only when necessary during fault-handling in the edge server group and are deleted after completion.
[0066] The edge server and the fault-corresponding edge server, acting as servers controlling the flow of information between the client and the service server, transmit link information between the client 210 and the service server 280, the edge server's own system information (CPU, memory, network, memory usage, utilization rate, etc.), and fault-related information to the client path control server 20. Under normal circumstances, the client contacts the service server 280 through the edge server; when a fault occurs, the client connects to the service server 280 through the fault-corresponding edge server. The edge server and the fault-corresponding edge server have the same structure.
[0067] The client path control server 20 controls the path, ensuring smooth communication between the client and the service server through edge servers. Furthermore, the client path control server allocates edge servers and fault-specific edge servers based on client requests via DNS, and receives communication-related information (connection, system status, line traffic information) from the edge servers and fault-specific edge servers to determine if a fault has occurred and retrieves the fault-inducing client. The client path control server 20 also manages a blacklist of fault-inducing clients, blocking DNS requests from clients recorded on the blacklist from accessing the service server via DNS. It also includes: a DNS control unit 230; a fault occurrence confirmation unit 240; and an edge server control unit 252. With this configuration, the client path control server 20 can function as a client terminal connection control device, controlling client terminal connections.
[0068] The DNS control unit 230 responds to the DNS resolution request from the client 100, providing the client's IP address or the IP address of another edge server or the IP address of the faulty edge server. Specifically, it receives the client's DNS request from the DNS server 220, requests the client path control server 20 to allocate an edge server, and sends the result received by the edge server control unit 250 to the DNS client 220.
[0069] The fault occurrence confirmation unit 240 confirms whether a fault has occurred on the edge server and the corresponding edge server. It receives communication-related information such as connection-related information, system status information, and traffic-related information from the edge server and the corresponding edge server, and confirms whether a fault has occurred on the edge server (including the corresponding edge server). Furthermore, based on fault-related policies, when the fault occurrence confirmation unit 240 determines that a fault has occurred on the corresponding edge server (including the corresponding edge server), it sends the information to the edge server control unit 250.
[0070] Furthermore, the fault confirmation unit 240 responds to DNS resolution and accepts control confirmation from the edge server control unit 250 to determine whether a fault has occurred on the edge server or the fault-corresponding edge server provided to the DNS control unit 230. If there is no fault on the provided edge server or the fault-corresponding edge server, the DNS control unit 230 sends the information of the edge server or the fault-corresponding edge server that has already been sent to the client 210 through the DNS server 220.
[0071] Furthermore, the fault confirmation unit 240 is unaffected by DNS resolution and can continuously monitor the faults of the edge server or the fault-corresponding edge server. When a fault occurs on the edge server or the fault-corresponding edge server, the edge server control unit 250 retrieves the client IP or user information of the client using the faulty edge server or the fault-corresponding edge server, and assigns the fault-corresponding edge server IP selected from the fault-corresponding edge server group 270 to the retrieved client IP or user information. If the client corresponding to the retrieved client IP or user information requests DNS resolution, the DNS control unit 230, under the control of the edge server control unit 250, sends the assigned fault-corresponding edge server IP to the retrieved client 100 through the DNS server 220. Furthermore, the DNS control unit 230 is unaffected by DNS resolution and, under the control of the edge server control unit 250, can transmit the assigned fault-corresponding edge server IP to the retrieved client 100 through the DNS server 220.
[0072] When a failure occurs on an edge server or a fault-corresponding edge server, the edge server control unit 252 replaces the fault-causing edge server or fault-corresponding edge server with the fault-corresponding edge server subgroup 275 selected from the fault-corresponding edge server group 270, and sends the replacement to the client. If there is only one client corresponding to the fault-corresponding edge server, that single client is identified as the fault-inducing client. The edge server allocation unit 252 includes a fault-corresponding edge server subgroup control unit 254 and a fault-inducing client retrieval unit 256.
[0073] When the edge server allocation unit 252 receives a DNS request from the client 210 via the DNS control unit 230, it allocates edge servers in the edge server group using the edge server grouping algorithm. The edge server allocation unit 252 identifies a fault-inducing client using a fault-inducing client retrieval algorithm, then adds the client to a blacklist. After retrieving a fault-inducing client, the client originally assigned to the fault-corresponding edge server is reassigned to an vacant edge server in the edge server group. If a client registered in the blacklist makes a DNS request, no edge server or fault-corresponding edge server is allocated.
[0074] After the fault occurrence confirmation unit 240 confirms the fault of the edge server, if the fault-response edge server subgroup control unit 254 receives a corresponding client DNS request, it generates a fault-response edge server subgroup 275 according to logical principles using the fault-response edge server subgroup control algorithm. This subgroup is used to retrieve the client that caused the fault. After assigning the fault-response edge server to this subgroup, the edge server is then logically allocated into the fault-response edge server subgroup 275 using the edge server grouping allocation algorithm.
[0075] The fault-inducing client retrieval unit 256 uses a fault-inducing client retrieval algorithm to analyze the allocation status of the edge server corresponding to the fault and the information of related clients, and identifies the fault-inducing client.
[0076] Client 210 may include agents 212 and 214. When an edge server or a fault-corresponding edge server fails, in order to reconnect to the selected fault-corresponding edge server in the fault-corresponding edge server group, it sends a DNS resolution containing user information. At this time, if the edge server control unit 250 receives the DNS resolution from client agents 212 and 214, it extracts the user information from the client's DNS resolution.
[0077] Client 210 consists of clients that connect to service server 280, and may include clients with an agent installed. The agent includes the client's user information, sends information about service server 280 to the DNS request, and after receiving information about the edge server or the fault-corresponding edge server, sends it to the client's network application.
[0078] According to one embodiment of the present invention, edge servers 260-1, 260-n or fault-corresponding edge servers 270-m, 270-m, 270-m, 270-n are connected to client 100 and service server 280. They can be specifically configured with programs, servers and hardware devices such as proxy servers and cache servers that have service relay or service functions. They are mainly used for the service path of client connection, and can also act as a service server for client connection.
[0079] In addition, edge server group 260 and fault-corresponding edge server group 270 can constitute a service relay network. The service relay network may include edge servers, fault-corresponding edge servers, gateways, routers, switches, multi-port repeaters, and other network devices that have service relay or service functions.
[0080] Figure 3This is a flowchart illustrating a fault-inducing client retrieval method utilizing fault-corresponding edge server groups according to an embodiment of the present invention. (Refer to...) Figures 1 to 3 The content describes in detail a client retrieval invention based on an embodiment that utilizes fault-corresponding edge server groups.
[0081] First, a service relay network 130 with multiple edge servers is set up on the path connecting client 210 and service server 280. Fault confirmation unit 240 confirms whether the edge server on the relay network 130 has failed (step S310). If the result is that a fault has occurred on the edge server, edge server control unit 250 sends a fault-corresponding edge server subgroup 275 to the client that replaces the fault-causing edge server and connects to the fault-causing edge server (step S320). The fault-corresponding edge server subgroup 275 consists of more fault-corresponding edge servers selected from the fault-corresponding edge server group than the number of fault-causing servers.
[0082] Then, the fault occurrence confirmation unit 240 confirms the occurrence of the fault by sending the fault-corresponding edge server to each client. (Step S330) If the fault occurrence confirmation result shows that a fault occurred on the alternative fault-corresponding edge server, the edge server control unit 250 sends other fault-corresponding edge server subgroups that were not sent to the clients on the fault-corresponding edge server group 270 to the clients after replacing the fault-corresponding edge server that caused the fault. (Step S340) Here, if a fault occurs on an edge server or a fault-corresponding edge server, the fault-corresponding edge server subgroup 275 can analyze the number of clients and connection records assigned to the faulty edge server or fault-corresponding edge server, and form multiple fault-corresponding edge servers based on the number of unassigned fault-corresponding edge servers in the fault-corresponding edge server group.
[0083] The fault occurrence confirmation unit 240 confirms the occurrence of a fault in the corresponding edge server sent to the client (step S350). Each time a fault occurs in the corresponding edge server, the edge server control unit 250 generates a subgroup of fault-corresponding edge servers that have not been sent to the client in the fault-corresponding edge server group 270, replacing the fault-corresponding edge server that has failed. If there is only one client assigned to the fault-corresponding edge server, that single client is identified as the fault-inducing client (step S360).
[0084] When confirming the occurrence of a fault in the edge server or the edge server corresponding to the fault, the confirmation of the fault can be performed based on monitoring the occurrence of the fault in the edge server or the edge server corresponding to the fault, regardless of whether DNS resolution is received from the client or not.
[0085] Figure 4 This is a flowchart illustrating one embodiment. In this embodiment, when a DNS resolution is received from a client, after confirming whether the edge server or the edge server corresponding to the fault has malfunctioned, an edge server subgroup is used to replace the faulty edge server or the edge server corresponding to the fault, and the client that caused the fault is retrieved. (Refer to...) Figure 2 and Figure 4 The DNS control unit 230 receives DNS resolution from the DNS server 220 (step S410) and checks whether user information is present in the received DNS resolution (step S415). If the user information exists, it is extracted (step S420).
[0086] In the edge server control 250, the edge server allocation unit 252 allocates the edge server IP corresponding to the extracted user information. (Step S430)
[0087] On the other hand, if no user information is found in the DNS resolution during step S415, the edge server allocation unit 252 provides the assigned edge server IP to the client requesting DNS resolution. (Step S425)
[0088] When an edge server IP is assigned, the fault confirmation unit 240 confirms whether a fault has occurred on the assigned edge server. (Step S435)
[0089] Based on the inspection results of the fault confirmation unit 240 (step S440), if no fault has occurred, the edge server IP assigned by the edge server allocation unit 252 or the edge server IP corresponding to the fault will be provided.
[0090] (Step S445)
[0091] If a failure occurs, verify whether there is only one client assigned to the edge server or the edge server corresponding to the failure. (Step S450) If there is only one client assigned to the edge server or the edge server corresponding to the failure, then retrieve that client as the failure-inducing client. (Step S460) If there are multiple clients assigned to the edge server or the edge server corresponding to the failure, then replace the failed edge server or the edge server corresponding to the failure with the fault-corresponding edge server group. (Step S455)
[0092] Figure 5 This is a flowchart illustrating one embodiment. Regardless of whether DNS resolution is received from the client, after confirming whether the edge server or the faulty edge server has failed, a subgroup of edge servers is used to replace the failed edge server or the faulty edge server, and the client that triggered the failure is retrieved. Furthermore, if the edge server or the faulty edge server fails again after being replaced by the faulty edge server subgroup, the IP address or user information of the client using the failed edge server or the faulty edge server is retrieved. Upon receiving a DNS resolution request, the selected faulty edge server from the faulty edge server subgroup is sent to the retrieved client.
[0093] Reference Figure 2 and Figure 5 Regardless of whether DNS resolution is received, the fault confirmation unit 240 must monitor whether a fault has occurred on the edge server or the edge server corresponding to the fault. (Step S510)
[0094] If a failure occurs on the edge server or the corresponding edge server (step S520), the edge server control unit 250 retrieves clients that used the failed edge server or the corresponding edge server as a path to the connection service server 280, and stores the client information (step S530).
[0095] Then, it is confirmed whether there is only one client assigned to the edge server or the fault-corresponding edge server. (Step S540) If there is only one client assigned to the edge server or the fault-corresponding edge server, then that client is identified as the fault-inducing client. (Step S550) If there are multiple clients assigned to the edge server or the fault-corresponding edge server, then the fault-corresponding edge server or the fault-corresponding edge server group is used to replace the faulty edge server or the fault-corresponding edge server. (Step S560)
[0096] Then, if a DNS resolution is received from the retrieved client (step S570), the DNS control unit 230 provides the client requesting the DNS resolution with the assigned edge server IP or the faulty edge server IP. (step S580)
[0097] On the other hand, the client includes agents 212 and 214, which are used to connect to the selected fault-corresponding edge server in the fault-corresponding edge server group and send DNS resolutions when the edge server or the fault-corresponding edge server fails. Agents 212 and 214 can request to send DNS resolutions containing user information. The user information that may be included in the DNS resolution includes information that can identify the user or the device, which may include at least one of the following: login ID, device ID (MAC, CPU ID, HDD Serial, etc.), phone number, and IP address.
[0098] When the edge server control unit 250 receives DNS resolution from the client agent, it can extract user information from the client DNS resolution and provide the client with the IP address of the fault-corresponding edge server selected from the fault-corresponding edge server group that corresponds to the extracted user information.
[0099] Furthermore, regarding one embodiment of the present invention, a method for retrieving faulty clients by grouping them according to faulty edge servers, and a method for retrieving faulty clients within the system, will be described in more detail. First, in one embodiment of the present invention, the allocation of edge servers can be performed as follows. Figure 6 This illustration depicts an edge server allocation method according to an embodiment of the present invention. (Refer to...) Figure 6 When client 610 requests information from service server 650 through DNS server 620, DNS server 620 transmits client 610's DNS resolution request to client path control server 630. The edge server allocation unit (not shown) of client path control server 620 sequentially allocates the client receiving the request to the edge servers within the managed edge server group 640. Client 1 (611) is allocated to edge server 1 (641), client 2 (612) to edge server 2 (642), client 3 (613) to edge server 3 (643), and so on. If a client receives more requests than the number of edge servers within edge server group 640, the edge servers within the edge server group will be reallocated. If there are 3 edge servers within the edge server group, and clients 1-3 have already received allocations to all three, then client 4 (614) will be reallocated to edge server 1 (641), and client 5 (615) will be reallocated to edge server 2 (642). Clients that have already been assigned can use the assigned edge server without any changes. An edge server can accommodate more than one client, and its maximum capacity is affected by the overall system performance of the edge server.
[0100] In addition, after the edge server is assigned, in the event of a failure on the edge server, the failure-inducing client can be retrieved in the following manner. Figure 7 The illustration shows a scenario where client 1 (611) becomes a faulty client due to malicious code or hacking. (See also...) Figure 7 If the edge server 1 (641) connecting clients 1, 4, and 7 suffers a line traffic attack from client 1 (611), the state of edge server 1 (611) will become unstable. Edge server 1 (641) will transmit system information, traffic information, client connection information, and other communication-related information to the fault confirmation unit (not shown) of client path control server 630. The fault confirmation unit (not shown) of client path control server 630 will then transmit the corresponding information to the edge server control unit (not shown) of client path control server 630.
[0101] Figure 8 This diagram illustrates how, when clients connected to the attacked edge server 1 are replaced with those connected to the faulty edge server, clients 1, 4, and 7 are assigned to edge server subgroup 1. (See attached diagram.) Figure 8 Using the fault-corresponding edge server subgroup control algorithm of the edge server control unit (not shown), after confirming that there are 3 clients connected to the faulty edge server 1 (641), the fault-corresponding edge server subgroup 1 (810) is generated logically within the fault-corresponding edge server group (not shown); after including the fault-corresponding edge server 1 (812) and the fault-corresponding edge server 2 (814) into the corresponding fault-corresponding edge server 1 (814), they are assigned to the fault-corresponding edge server subgroup 1 (810).
[0102] If clients 1 (611), 4 (614), and 7 (617), assigned to edge server 1 (641), submit a DNS request to reassign to an edge server, the edge server allocation unit (not shown) of the client path control server 630 will assign them to the fault-corresponding edge server subgroup 1 (810) within the fault-corresponding edge server subgroup. Here, fault-corresponding edge server subgroup 1 (810) contains two fault-corresponding edge servers, 812 and 814. (According to the fault-corresponding edge server subgroup control algorithm, fault-corresponding edge server subgroup 1 (810) contains two fault-corresponding edge servers.)
[0103] Since there are three clients (clients 1, 4, and 7) assigned to edge server 1 (641), clients 1 (611) and 4 (614) are assigned to fault-corresponding edge server 1 (812), and client 7 (617) is also assigned to fault-corresponding edge server 1 (812). The fault-corresponding edge server 1 (812), which connects clients 1 and 4, becomes highly unstable due to a line traffic attack from client 1 (611). Fault-corresponding edge server 1 (812) transmits communication-related information to the fault occurrence confirmation unit (not shown) of client path control server 630. The fault occurrence confirmation unit (not shown) of client path control server 630 transmits the relevant information to the edge server control unit (not shown) of client path control server 630. Here, the fault-inducing client retrieval algorithm within the edge server control unit of the client path control server retains the judgment until the time point when the fault-corresponding edge server and client are assigned in a one-to-one ratio.
[0104] Afterwards, the client connected to the fault-fault edge server group 1 (812) of the attacked fault-fault edge server group 1 (810) is separated, and a new fault-fault edge server subgroup 2 (910) is generated according to logic using the fault-fault edge server group control algorithm of the edge server control unit (not shown). Then, the fault-fault edge server group 3 (912) and the fault-fault edge server 4 (914) are incorporated into the fault-fault edge server subgroup 2 (910) and assigned to the fault-fault edge server subgroup 2 (910).
[0105] Figure 9 This is an illustration showing the separation of client 1 (611) and client 4 (614) and their redistribution to the faulty edge server subgroup 2 (910). See attached diagram. Figure 9 If clients 1 (611) and 4 (614) of fault-corresponding edge server 1 (812) assigned to fault-corresponding edge server subgroup 1 (810) submit a DNS request for edge server allocation again, the client path control server 630's edge server allocation unit (not shown) will allocate them to a fault-corresponding edge server that is not in fault-corresponding edge server subgroup 1 (810) but in fault-corresponding edge server subgroup 2 (910). Here, fault-corresponding edge server subgroup 2 (910) contains two fault-corresponding edge servers 912 and 914. (According to the fault-corresponding edge server subgroup control algorithm, fault-corresponding edge server subgroup 2 contains two fault-corresponding edge servers.)
[0106] Furthermore, since client 7 (617) connected to fault-response edge server 2 (814) of fault-response edge server subgroup 1 (810) is not a fault-inducing client, the edge server allocation unit (not shown) of client path control server 630 will allocate a new edge server 4 (644) to the edge server group. This allocation will either be made to an empty edge server or, among the already allocated edge servers, to an edge server with sufficient capacity in the system.
[0107] Since there are two clients, Client 1 and Client 4, assigned to Fault Response Edge Server 1 (812) of Fault Response Edge Server Subgroup 1 (810), and there are also two Fault Response Edge Servers belonging to Fault Response Edge Server Subgroup 2 (910), Client 1 (611) is assigned to Fault Response Edge Server 3 (912), and Client 4 (614) is assigned to Fault Response Edge Server 4 (914). The edge server allocation unit (not shown) of Client Path Control Server 630 transmits the corresponding allocation information to the fault-inducing client retrieval unit (not shown) of Client Path Control Server 630. Fault Response Edge Server 3 (912) connected to Client 1 (611) suffers a line traffic attack from Client 1 (611), causing the system state to become unstable. Fault Response Edge Server 3 (912) transmits communication-related information to the fault occurrence confirmation unit (not shown) of Client Path Control Server 630, and the fault occurrence confirmation unit of Client Path Control Server 630 transmits the relevant information to the edge server control unit (not shown) of Client Path Control Server 630.
[0108] Figure 10 This is an attached diagram illustrating the process of connecting to a faulty edge server and identifying a client attacking the faulty edge server as the cause of the fault. (Refer to...) Figure 10 The fault-inducing client retrieval unit (not shown) of the client path control server 630 has a fault-corresponding edge server and client allocation ratio of 1:1. Since the fault-corresponding edge server 1 (812) has failed, client 1 (611) connected to the fault-corresponding edge server 1 (812) is the fault-causing client. The fault-inducing client retrieval unit (not shown) of the client path control server 630 records client 1 (611) on a blacklist and transmits the information to the edge server allocation unit (not shown) of the client path control server 630. Furthermore, since client 4 (614) is not the fault-inducing client, the edge server allocation unit (not shown) of the client path control server 630 can allocate it to the more available edge server 4 (644) in the edge server group.
[0109] The fault cause registered on the blacklist is that even when client 1 (611) makes a DNS request to obtain service server 650 information again, the edge server allocation unit (not shown) of client path control server 630 does not allocate an edge server, but instead responds with null. Therefore, it cannot obtain an edge server allocation and thus cannot connect to service server 650.
[0110] Furthermore, the differences between the fault-induced client retrieval method using the client path control system in existing registered patents and the fault-induced client retrieval method using the grouping of edge servers corresponding to the fault in this invention will be explained in more detail.
[0111] The methods in existing patents and the method of this invention are not significantly different if only one client malfunctions. However, if multiple clients malfunction simultaneously, there will be a significant difference in the retrieval method and accuracy, and this invention can accurately retrieve the client that caused the malfunction.
[0112] Figure 11 as well as Figure 12 The attached figure illustrates the fault-induced client retrieval method using a patented client path control system. Figures 13 to 16 The accompanying drawings illustrate the fault-inducing client retrieval method in this invention, which utilizes fault-corresponding edge server grouping.
[0113] The background technology of the present invention is as described above, referring to... Figure 11 When the edge server group 11, consisting of 6 edge servers, is arranged in a 3x2 matrix to form a matrix 12 for searching for the client causing the failure, its main structure is as follows. As described in the matrix, when clients A to H are assigned edge servers, if clients A and F are the clients causing the failure, then edge servers 1, 2, 3, 4, and 6 in the edge server group will fail because of clients A and F.
[0114] but Figure 12 Looking at the matrix, not only clients A and F, but also other clients on the edge server group that experienced failures and were assigned to edge servers 1, 2, 3, 4, and 6 are designated as the clients that caused the failures. Therefore, clients B and E will also be considered as the clients causing the failures. That is, clients B and E can be mistakenly identified as the clients that caused the failures.
[0115] Furthermore, if we explain the fault-inducing client retrieval method using the fault-corresponding edge server grouping according to the present invention compared to conventional methods, it is assumed that there are clients A to H identical to those in the matrix approach, and as... Figure 13As shown, there are two edge servers 1 and 2 in edge server group 13 used for grouping; there are nine fault-corresponding edge server groups 11 to 19 in fault-corresponding edge server group 14.
[0116] Reference Figure 14 Clients A through H have only two edge servers within the edge server group, therefore, as... Figure 14 As shown, the edge servers will be assigned and services will be provided. If clients A and F are the clients that cause the failure, edge servers 1 and 2 of edge server group 13 will both fail.
[0117] Based on the fault-response edge server subgroup control algorithm and edge server grouping allocation algorithm of the edge server control unit (not shown), fault-response edge server subgroups 1 and 2 are first generated on the fault-response edge server group. Fault-response edge server group 1 includes fault-response edge server groups 11 and 12; fault-response edge server group 2 includes fault-response edge server groups 13 and 14. Additionally, clients A to H, assigned to the faulty edge servers 1 and 2, are as follows: Figure 15 As shown, the fault is assigned to the corresponding edge server subgroups 1 and 2.
[0118] Reference Figure 15 Due to the fault, clients A and F were assigned to fault-corresponding edge server 11 in fault-corresponding edge server subgroup 1 (13-1) and fault-corresponding edge server 13 in fault-corresponding edge server subgroup 2 (13-2), so the corresponding fault-corresponding edge server will fail.
[0119] Based on the fault-corresponding edge server subgroup control mechanism and edge server grouping allocation algorithm of the edge server control unit (not shown), fault-corresponding edge server subgroup 3 (13-3) and fault-corresponding edge server 4 (13-4) are generated, as follows: Figure 16 As shown, among the unassigned fault-corresponding edge servers, fault-corresponding edge servers 15 and 16 are included in fault-corresponding edge server subgroup 3 (13-3), fault-corresponding edge servers 17 and 18 are included in fault-corresponding edge server subgroup 4 (13-4), and clients A, B, E, and F that want to connect to the fault-corresponding edge servers 11 and 13 that caused the fault are assigned.
[0120] Reference Figure 16Because fault-corresponding edge servers 15 and 18 in fault-corresponding edge server subgroups 3 (13-3) and 4 (13-4) experienced failures, a one-to-one mapping exists between clients and fault-corresponding edge servers. Therefore, client A, assigned to fault-corresponding edge server 15, and client F, assigned to fault-corresponding edge server 18, are identified as the fault-causing clients. In the above invention, only A and F are retrieved by the fault-inducing client, while clients B and E, which are incorrectly identified according to existing technologies, are not retrieved by the fault-inducing client.
[0121] Please refer to the following Figure 17 The method for client connection control using the fault-inducing client retrieval method described above, and related content, in this embodiment, will be explained in detail. The client terminal connection control device may include a client terminal; a communication unit for data communication with at least one of the edge server and the fault-corresponding edge server; and a processor for performing the following processes.
[0122] First, the client terminal connection control device can allocate communication processing of a first client group consisting of multiple client terminals to the edge server (S1710). Second, when the edge server malfunctions, the client terminal connection control device can allocate communication processing of a second client group belonging to the first client group and containing at least one client terminal to the faulty edge server (S1720). Here, the second client group can consist of at least one client terminal belonging to the first client group. Furthermore, the configuration of the second client group can be set to include at least one client terminal and another client terminal belonging to the first client group.
[0123] Next, the client terminal connection control device can determine whether the operation of the edge server corresponding to the fault has failed (S1730). The client terminal connection control device can control the connection of the client terminals based on whether a fault has occurred. For example, if the client terminal connection control device fails during the operation of the edge server corresponding to the fault, and the number of client terminals assigned to the edge server corresponding to the fault exceeds a preset number, the communication processing of at least one sub-client group belonging to the client group of the edge server corresponding to the fault can be assigned to the edge server corresponding to the fault. For example, the client terminal connection control device can assign the communication processing of the sub-client group to the edge server corresponding to the fault that has not failed. Here, the preset number can be 1 or 2, or any other set value.
[0124] More specifically, the client terminal connection control device can generate sub-client groups, which belong to at least one client group assigned to the fault-corresponding edge server, and simultaneously distribute the communication processing of the generated sub-client groups to the fault-corresponding edge server. As mentioned above, a sub-client group may include only at least one client terminal assigned to the fault-corresponding edge server. Alternatively, a sub-client group may be configured to belong to a client group assigned to the fault-corresponding edge server and include at least one client terminal and other client terminals.
[0125] On the other hand, if the edge server corresponding to the fault malfunctions and the number of client terminals assigned to the edge server corresponding to the fault is equal to a preset number, the client terminal connection control device can determine the preset number of clients as the client terminals that caused the fault.
[0126] refer to Figure 18 The client terminal connection control system in this embodiment utilizes the aforementioned fault-induced client retrieval method to execute client connection control, which will be described in detail below. The client terminal connection control system may include an edge server; a fault-corresponding edge server; and a connection control device.
[0127] First, the edge server can perform communication processing for a first client group consisting of multiple client terminals (S1810). Second, when the operation of the edge server fails, the edge server corresponding to the failure can perform communication processing for a second client group including at least one client terminal belonging to the first client group (S1820).
[0128] Secondly, the connection control device can determine whether the operation of the fault-corresponding edge server has failed (S1830). Then, the connection control device can control the connection of the client terminals based on whether a failure has occurred. For example, if the operation of the fault-corresponding edge server fails, and the number of client terminals assigned to the fault-corresponding edge server is equal to a preset number, the connection control device can allocate the communication processing of a sub-client group, containing at least one client terminal, from the client group assigned to the fault-corresponding edge server to the fault-corresponding edge server. For example, the connection control device can allocate the communication processing of the sub-client group to a fault-corresponding edge server that has not failed. Here, the preset number can be one or two, or any other set value.
[0129] On the other hand, if the edge server corresponding to the fault malfunctions and the number of client terminals assigned to the edge server corresponding to the fault is equal to a preset number, the connection control device can determine the preset number of clients as the client terminals that caused the fault.
[0130] The methods, apparatus, and systems described in the embodiments above can be implemented using computer-readable program code (including all devices with information processing capabilities). Computer-readable recording media include all types of recording devices that store data readable by a computer system. Examples of computer-readable recording devices include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage devices, etc.
[0131] While the present invention has been described with reference to the examples in the accompanying drawings, these are merely illustrative. Those skilled in the art can readily implement various modifications and equivalent embodiments. Therefore, the true scope of protection of this invention must be determined based on the technical concept within the scope of the authorized claims.
[0132] Explanation of reference numerals in the attached figures:
[0133] 100: Client Department
[0134] 102, 104: Client
[0135] 14: Agency
[0136] 110: DNS server
[0137] 120: Client Path Control Server
[0138] 130: Service Relay Network
[0139] 132: Edge Server Group
[0140] 134: Fault corresponds to the edge server group
[0141] 140: Service Server
[0142] 20: Client Path Control Server
[0143] 210: Client
[0144] 210-1: Client 1
[0145] 212: Agency
[0146] 201-n: Client n
[0147] 214: Agency
[0148] 220: DNS server
[0149] 230: DNS Control Department
[0150] 240: Fault Occurrence Confirmation Department
[0151] 250: Edge Server Control Department
[0152] 252: Edge Server Allocation Department
[0153] 254: Fault Response Edge Server Subgroup Control Unit
[0154] 256: Fault-induced client retrieval department
[0155] 260: Edge Server Group
[0156] 260-1: Edge Server 1
[0157] 260-n: Edge Server n
[0158] 270: Fault corresponds to the edge server group
[0159] 275: Fault corresponds to the edge server subgroup
[0160] 270-1: Fault corresponds to edge server 1
[0161] 270-m: Fault corresponds to edge server m
[0162] 270-nm: The edge server nm corresponding to the fault
[0163] 270-n: The edge server n corresponding to the fault
[0164] 610: Client Department
[0165] 611: Client 1
[0166] 612: Client 2
[0167] 613: Client 3
[0168] 614: Client 4
[0169] 615: Client 5
[0170] 620: DNS server
[0171] 630: Client Path Control Server
[0172] 640: Edge Server Group
[0173] 641: Edge Server 1
[0174] 642: Edge Server 2
[0175] 643: Edge Server 3
[0176] 644: Edge Server 4
[0177] 650: Service Server
[0178] 810: Fault corresponds to edge server subgroup 1
[0179] 812: Fault corresponds to edge server 1
[0180] 814: Fault corresponds to edge server 2
[0181] 910: Fault corresponds to edge server subgroup 2
[0182] 912: Fault corresponds to edge server 3
[0183] 914: Fault corresponds to edge server 4
[0184] 11: Edge Server Group
[0185] 12: Edge Server Allocation Matrix
[0186] 13: Edge Server Group
[0187] 14: Fault-related edge server group
[0188] 13-1: Fault corresponds to edge server subgroup 1
[0189] 13-2: Fault corresponds to edge server subgroup 2
[0190] 13-3: Fault corresponds to edge server subgroup 3
[0191] 13-4: The fault corresponds to the edge server subgroup 1.
[0192] Industrial applications: This invention can be used to retrieve various scenarios that induce network failures in clients.
Claims
1. A client terminal connection control method executed by a client terminal connection control device, characterized in that, include: The step of assigning communication processing of a first client group, which includes multiple client terminals, to an edge server; When the edge server malfunctions, a first fault handling edge server subgroup is generated, and the communication processing of a second client group belonging to the first client group, which contains at least one client terminal, is allocated to the first fault handling edge server of the first fault handling edge server subgroup. as well as The steps to determine whether the operation of the first fault handling edge server has failed; as well as When the first fault-handling edge server malfunctions, the step of performing either the first processing or the second processing is determined based on the number of client terminals assigned to the first fault-handling edge server. The first process involves identifying the client terminals assigned to the first fault handling edge server as faulty client terminals. Furthermore, the second process involves generating a second fault handling edge server subgroup and allocating communication processing of the sub-client group, which includes at least one client terminal and is assigned to the first fault handling edge server, to the second fault handling edge server of the second fault handling edge server subgroup. Specifically, if the number of client terminals assigned to the first fault handling edge server is greater than a preset number, it is determined that the second processing needs to be performed; if the number of client terminals assigned to the first fault handling edge server is equal to the preset number, it is determined that the first processing needs to be performed. Furthermore, the number of client terminals assigned to the second fault handling edge server is less than the number of client terminals assigned to the first fault handling edge server. When the first fault handling edge server is running without failure, the client terminals assigned to the first fault handling edge server will be assigned to edge servers that can be assigned client terminals.
2. The client terminal connection control method according to claim 1, characterized in that, The preset quantity is one.
3. A client terminal connection control device, characterized in that, include: The communications department performs data communication with the edge server, the first fault handling edge server, and the second fault handling edge server. The processor distributes communication processing for the first client group, which includes multiple client terminals, to the edge server. When the edge server malfunctions, a first fault-handling edge server subgroup is generated, and communication processing of a second client group belonging to the first client group, which includes at least one client terminal, is allocated to the first fault-handling edge server of the first fault-handling edge server subgroup. Determine whether the operation of the first fault-handling edge server has failed; When the first fault handling edge server malfunctions, the decision to perform either first or second processing is based on the number of client terminals assigned to the first fault handling edge server. The first process involves identifying the client terminal assigned to the first fault handling edge server as a faulty client terminal. The second process involves generating a second fault handling edge server subgroup and allocating communication processing of the sub-client group (containing at least one client terminal) assigned to the first fault handling edge server to the second fault handling edge server within the second fault handling edge server subgroup. Specifically, if the number of client terminals assigned to the first fault handling edge server is greater than a preset number, it is determined that the second processing needs to be performed; if the number of client terminals assigned to the first fault handling edge server is equal to the preset number, it is determined that the first processing needs to be performed. Furthermore, the number of client terminals assigned to the second fault handling edge server is less than the number of client terminals assigned to the first fault handling edge server. When the first fault handling edge server is running without failure, the client terminals assigned to the first fault handling edge server will be assigned to edge servers that can be assigned client terminals.
4. A client terminal connection control method executed by a client terminal connection control system comprising an edge server, a first fault-handling edge server, a second fault-handling edge server, and a connection control device, characterized in that, include: The edge server performs the communication processing steps of a first client group comprising multiple client terminals; When the edge server malfunctions, the connection control device generates a first fault-handling edge server subgroup. The first fault-handling edge server in the first fault-handling edge server subgroup performs communication processing steps for a second client group that belongs to the first client group and includes at least one client terminal. The connection control device determines whether the operation of the first fault processing edge server has failed. as well as When the first fault-handling edge server malfunctions, the connection control device determines whether to perform a first processing step or a second processing step based on the number of client terminals allocated to the first fault-handling edge server. The first process involves identifying the client terminals assigned to the first fault handling edge server as faulty client terminals. Furthermore, the second process involves generating a second fault handling edge server subgroup and allocating communication processing of the sub-client group, which includes at least one client terminal and is assigned to the first fault handling edge server, to the second fault handling edge server of the second fault handling edge server subgroup. Specifically, if the number of client terminals assigned to the first fault handling edge server is greater than a preset number, it is determined that the second processing needs to be performed; if the number of client terminals assigned to the first fault handling edge server is equal to the preset number, it is determined that the first processing needs to be performed. Furthermore, the number of client terminals assigned to the second fault handling edge server is less than the number of client terminals assigned to the first fault handling edge server. When the first fault handling edge server is running without failure, the client terminals assigned to the first fault handling edge server will be assigned to edge servers that can be assigned client terminals.
5. A client terminal connection control system, characterized in that, include: Edge servers; First fault handling edge server; Second fault handling edge server; as well as Connect control device; The edge server performs communication processing for a first client group comprising multiple client terminals. When the edge server malfunctions, the connection control device generates a first fault-handling edge server subgroup. The first fault-handling edge server in the first fault-handling edge server subgroup performs communication processing for a second client group belonging to the first client group and containing at least one client terminal. The connection control device determines whether the operation of the first fault-handling edge server has malfunctioned. When the first fault-handling edge server malfunctions, the connection control device determines whether to perform a first processing or a second processing based on the number of client terminals allocated to the first fault-handling edge server. The first process involves identifying the client terminals assigned to the first fault handling edge server as faulty client terminals. Furthermore, the second process involves generating a second fault handling edge server subgroup and allocating communication processing of the sub-client group, which includes at least one client terminal and is assigned to the first fault handling edge server, to the second fault handling edge server of the second fault handling edge server subgroup. Specifically, if the number of client terminals assigned to the first fault handling edge server is greater than a preset number, it is determined that the second processing needs to be performed; if the number of client terminals assigned to the first fault handling edge server is equal to the preset number, it is determined that the first processing needs to be performed. Furthermore, the number of client terminals assigned to the second fault handling edge server is less than the number of client terminals assigned to the first fault handling edge server. When the first fault handling edge server is running without failure, the client terminals assigned to the first fault handling edge server will be assigned to edge servers that can be assigned client terminals.
6. A non-transitory computer-readable recording medium storing a computer program that executes the method of claim 1.
7. A non-transitory computer-readable recording medium storing a computer program that executes the method of claim 4.
Citation Information
Patent Citations
Method and system for detecting failure-inducing client by using client route control system
CN106471772A