Pcdn user identification and control method and device, and electronic equipment

By redirecting and processing user uplink traffic packets, combined with the service-aware SA business board and dual token bucket algorithm, PCDN users are identified and controlled, solving the problems of low identification efficiency and ineffective traffic control in existing technologies, and achieving efficient PCDN user management.

CN118802768BActive Publication Date: 2025-11-21HANDAN BRANCH OF CHINA MOBILE GRP HEBEI COMPANYLIMITED +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410377810.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-11-21
Estimated Expiration
2044-03-29

AI Technical Summary

Technical Problem

Existing technologies have low efficiency and accuracy in identifying PCDN users, and the methods of communication and negotiation to constrain PCDN users to use PCDN traffic are ineffective, resulting in wasted network resources and user complaints.

Method used

By redirecting and processing users' uplink traffic packets, the service-aware SA business board identifies PCDN users and sets traffic rate limiting policies based on the dual token bucket algorithm to automatically control the forwarding of target uplink traffic packets.

Benefits of technology

It improved the efficiency and accuracy of PCDN user identification, effectively limited PCDN traffic, optimized network resource allocation, and reduced network congestion and user complaints.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802768B_ABST
    Figure CN118802768B_ABST
Patent Text Reader

Abstract

The application provides a PCDN user identification and management method, device and electronic equipment, and belongs to the technical field of network security, wherein the method comprises: redirecting the uplink traffic message of a user, so that the uplink traffic message of the user passes through a service awareness (SA) service board; processing the uplink traffic message of the user to obtain a processed uplink traffic message, identifying a PCDN user based on the processed uplink traffic message; obtaining at least one traffic speed limiting strategy corresponding to a target uplink traffic message of the PCDN user, and setting a double token bucket based on each traffic speed limiting strategy to control the forwarding of the target uplink traffic message. The PCDN user identification and management method, device and electronic equipment provided by the application can efficiently and accurately identify PCDN users, have high automation, and can effectively limit PCDN traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a PCDN user identification and management method, apparatus and electronic device. Background Technology

[0002] Peer-to-Peer Content Delivery Network (PCDN), based on peer-to-peer (P2P) technology, combines with traditional Content Delivery Networks (CDNs) to distribute content delivery tasks among multiple user devices, thereby sharing bandwidth and resources and improving content delivery efficiency. However, the misconduct of some PCDN users can adversely affect operator networks, making the effective identification and management of PCDN users crucial. Currently, PCDN user identification typically relies on manual evidence collection, which is time-consuming, labor-intensive, and has low efficiency and accuracy. Restricting user PCDN usage through communication and negotiation is insufficient to effectively limit PCDN traffic. Summary of the Invention

[0003] This invention provides a PCDN user identification and management method, device, and electronic device to solve the shortcomings of existing technologies that use manual evidence collection to identify PCDN users, which is time-consuming, labor-intensive, and has low efficiency and accuracy; and that use communication and negotiation to restrict users' use of PCDN, which cannot effectively limit PCDN traffic.

[0004] In a first aspect, the present invention provides a PCDN user identification and management method, comprising:

[0005] Redirect the user's uplink traffic packets so that the user's uplink traffic packets pass through the Service Aware SA service board;

[0006] The uplink traffic packets of the user are processed to obtain processed uplink traffic packets, and the PCDN user is identified based on the processed uplink traffic packets;

[0007] Obtain at least one traffic rate limiting policy corresponding to the target uplink traffic packet of the PCDN user, and set up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packet.

[0008] In some embodiments, identifying PCDN users based on the processed uplink traffic packets includes:

[0009] Obtain specific information corresponding to the processed uplink traffic packet, wherein the specific information includes at least one of the following: specific port, specific signature, specific behavior, and specific protocol type;

[0010] Based on the specific information, PCDN users are identified.

[0011] In some embodiments, identifying PCDN users based on the processed uplink traffic packets includes:

[0012] PCDN users are identified based on the traffic value of the processed uplink traffic packets.

[0013] In some embodiments, identifying PCDN users based on the processed uplink traffic packets includes:

[0014] PCDN users are identified based on the number of sessions corresponding to the processed uplink traffic packets.

[0015] In some embodiments, the step of setting up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packets includes:

[0016] Based on the committed rate and the limited rate corresponding to each traffic rate limiting strategy, set the first token bucket and the second token bucket corresponding to each traffic rate limiting strategy.

[0017] The target uplink traffic packet is transmitted to the first token bucket and the second token bucket corresponding to each traffic rate limiting policy to obtain the token allocation status corresponding to each traffic rate limiting policy.

[0018] Based on the token allocation status corresponding to each traffic rate limiting strategy, the target uplink traffic packets are color-coded to obtain the color-coding result corresponding to each traffic rate limiting strategy.

[0019] Based on the color-coded result corresponding to each traffic rate limiting policy, the forwarding control of the target uplink traffic packets is performed.

[0020] In some embodiments, color-coding the target uplink traffic packets according to the token allocation status corresponding to each traffic rate limiting policy includes:

[0021] Based on the token allocation status corresponding to each traffic rate limiting policy, determine whether the target uplink traffic packet exceeds the committed rate and the limited rate corresponding to each traffic rate limiting policy;

[0022] If it is determined that the target uplink traffic packet does not exceed the committed rate corresponding to each traffic rate limiting policy, the target uplink traffic packet is marked as green;

[0023] If it is determined that the target uplink traffic packet exceeds the committed rate corresponding to each traffic rate limiting policy, but does not exceed the limited rate corresponding to each traffic rate limiting policy, the target uplink traffic packet is marked as yellow.

[0024] If it is determined that the target uplink traffic packet exceeds the rate limit corresponding to each traffic rate limiting policy, the target uplink traffic packet is marked in red.

[0025] In some embodiments, forwarding control of the target uplink traffic packets is performed based on the color-coded result corresponding to each traffic rate limiting policy, including:

[0026] If the color result corresponding to at least one traffic rate limiting policy is green, then the target uplink traffic packet is forwarded;

[0027] If the color result corresponding to any traffic rate limiting policy is not green, and the color result corresponding to at least one traffic rate limiting policy is red, then the target uplink traffic packet will be discarded.

[0028] If all traffic rate limiting policies are highlighted in yellow, then the target uplink traffic packet is forwarded.

[0029] Secondly, the present invention also provides a PCDN user identification and management device, comprising:

[0030] The redirection unit is used to redirect the user's uplink traffic packets so that the user's uplink traffic packets pass through the Service Aware SA service board;

[0031] The identification unit is used to process the user's uplink traffic packets to obtain processed uplink traffic packets, and to identify the point-to-point content delivery network (PCDN) user based on the processed uplink traffic packets.

[0032] The control unit is used to obtain at least one traffic rate limiting policy corresponding to the target uplink traffic packet of the PCDN user, and set up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packet.

[0033] Thirdly, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the PCDN user identification and control method described above.

[0034] Fourthly, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the PCDN user identification and management method described above.

[0035] This invention provides a PCDN user identification and control method, apparatus, and electronic device. By redirecting and processing the user's uplink traffic packets, the PCDN user is identified based on the processed uplink traffic packets, achieving high identification efficiency and accuracy. By acquiring the traffic rate limiting policies corresponding to the target uplink traffic packets of the PCDN user, and setting up dual token buckets according to each traffic rate limiting policy, the target uplink traffic packets are automatically forwarded and controlled, effectively limiting PCDN traffic. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0037] Figure 1 This is a flowchart illustrating the PCDN user identification and management method provided in an embodiment of the present invention;

[0038] Figure 2 This is a schematic diagram of the process for controlling the forwarding of target uplink traffic packets based on a rate limiting strategy for each traffic flow, provided in an embodiment of the present invention.

[0039] Figure 3 This is a schematic diagram of the PCDN user identification and control device provided in an embodiment of the present invention;

[0040] Figure 4 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0042] PCDN users' unauthorized use of the operator's broadband has the following adverse effects on the operator's network: chaotic scheduling strategies, resulting in disorderly traffic flooding and affecting user experience; causing network congestion and leading to complaints from other users; and affecting the operator's revenue.

[0043] Currently, there is a lack of effective means to identify PCDN users, and evidence is usually obtained through on-site packet capture or manual capture. On-site packet capture is time-consuming, can only capture real-time user data, is inefficient, and consumes a lot of manpower; manual capture can only analyze traffic characteristics and make judgments based on human judgment, which has low efficiency and accuracy; there are also situations where users are uncooperative and evidence cannot be obtained, which can easily lead to customer complaints and legal disputes. At present, the current method of communicating and negotiating with PCDN users to restrict their use of PCDN is not very effective, and the network side cannot effectively limit PCDN traffic.

[0044] To address this, embodiments of the present invention provide a PCDN user identification and control method, apparatus, and electronic device. By redirecting and processing the user's uplink traffic packets, the PCDN user is identified based on the processed uplink traffic packets, achieving high identification efficiency and accuracy. By acquiring the traffic rate limiting policies corresponding to the target uplink traffic packets of the PCDN user, and setting up dual token buckets according to each traffic rate limiting policy, the target uplink traffic packets are automatically forwarded and controlled, effectively limiting PCDN traffic.

[0045] Figure 1 This is a flowchart illustrating the PCDN user identification and management method provided in an embodiment of the present invention. Figure 1 As shown, a PCDN user identification and management method is provided, including the following steps: step 110, step 120, and step 130. This method's steps are merely one possible implementation of the present invention.

[0046] Step 110: Redirect the user's uplink traffic packets so that the user's uplink traffic packets pass through the Service Aware SA service board.

[0047] Uplink traffic messages refer to data traffic sent from terminal devices (such as smartphones, computers, etc.) to the network.

[0048] Among them, the Service Awareness (SA) service board refers to a dedicated hardware board or module that can realize service awareness function. SA service boards are usually used in network devices or systems to monitor, identify and process different types of data traffic, and classify, forward and optimize the data according to the characteristics of these data traffic and user needs, thereby realizing intelligent perception and management of services.

[0049] Step 120: Process the user's uplink traffic packets to obtain processed uplink traffic packets, and identify PCDN users based on the processed uplink traffic packets.

[0050] PCDN users refer to users who use peer-to-peer content delivery network services. PCDN users can share and exchange content with each other.

[0051] Optionally, the SA service board of the Broadband Remote Access Server (BRAS) performs basic user protocol identification on the user's uplink traffic packets, creates flow nodes, and obtains flow node information such as five-tuple information (source IP address, destination IP address, protocol type, source port and destination port), protocol, packet count, byte count, IP node, and flow summary information. The flow node information is then aggregated and stored.

[0052] In some embodiments, identifying PCDN users based on processed uplink traffic packets includes:

[0053] Obtain specific information corresponding to the processed uplink traffic packets. The specific information includes at least one of the following: specific port, specific signature, specific behavior, and specific protocol type.

[0054] Identify PCDN users based on specific information.

[0055] It should be noted that PCDN services may use specific ports for communication. For example, Hypertext Transfer Protocol (HTTP) typically uses port 80 or 8080, while Secure Hypertext Transfer Protocol (HTTPS) typically uses port 443. By monitoring specific port information in uplink traffic packets, PCDN user requests using these specific ports can be identified.

[0056] The specific signature can be a specific HTTP header, request parameter, or a custom identifier. By matching the specific signature, requests from PCDN users can be identified.

[0057] It should be noted that PCDN users may exhibit specific behavioral patterns, such as frequent large file transfers and continuous data requests. Potential PCDN users can be identified based on these specific behaviors.

[0058] It should be noted that the PCDN service may use specific protocol types for communication, such as HTTP and HTTPS. By monitoring the protocol type information in uplink traffic packets, PCDN user requests using these specific protocol types can be identified.

[0059] Optionally, PCDN users can be identified based on one or more of the following: a specific port, a specific signature, a specific behavior, a specific protocol type, and associated information.

[0060] In some embodiments, identifying PCDN users based on processed uplink traffic packets includes:

[0061] Identify PCDN users based on the traffic values ​​of the processed uplink traffic packets.

[0062] The processed uplink traffic packet includes the uplink video traffic value.

[0063] It should be noted that the traffic characteristics of PCDN nodes are as follows:

[0064] 1) Provides a large amount of traffic to external users, mainly video upload traffic;

[0065] 2) Serving public users involves a large number of session connections;

[0066] 3) Make full use of physical bandwidth to maximize benefits.

[0067] Optionally, the user can be determined as a PCDN user based on the traffic value of the processed uplink traffic packet and the preset traffic threshold under different application scenarios.

[0068] For example, if the upstream P2P video traffic value, HTTP video traffic value, and non-HTTP video weekly traffic value corresponding to the processed upstream traffic packet are determined, and any one of them exceeds the preset traffic threshold of 700GB, then the user is determined to be a PCDN user.

[0069] For example, the system obtains the uplink video traffic value and the downlink video traffic value. If the ratio of the uplink video traffic value to the downlink video traffic value is greater than a preset ratio, the user is determined to be a PCDN user.

[0070] For example, if during periods of high network load, the bandwidth utilization of uplink video traffic continuously exceeds a preset standard value, and the duration exceeds a first preset time threshold, then the user is identified as a PCDN user.

[0071] In some embodiments, identifying PCDN users based on processed uplink traffic packets includes:

[0072] Identify PCDN users based on the number of sessions corresponding to the processed uplink traffic packets.

[0073] Optionally, if the number of sessions exceeds a preset threshold and the duration exceeds a second preset time threshold during peak network hours, the user is identified as a PCDN user.

[0074] Step 130: Obtain at least one traffic rate limiting policy corresponding to the target uplink traffic packet of the PCDN user, and set up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packet.

[0075] Traffic limiting is a common method in network management used to control and manage the transmission speed of different types of traffic on a network. By limiting the traffic, network resource allocation can be balanced, network congestion can be avoided, and network performance and user experience can be improved. Different traffic types require different traffic limiting strategies.

[0076] Optionally, traffic limiting strategies can be determined based on user needs.

[0077] Optionally, traffic limiting policies can be generated through the SA system of the BRAS. Based on each traffic limiting policy, the color-coded result corresponding to the target uplink traffic packet can be obtained. The decision on whether to forward the packet can be made based on a comprehensive assessment of multiple color-coded results.

[0078] In this embodiment of the invention, by redirecting and processing the user's uplink traffic packets, PCDN users are identified based on the processed uplink traffic packets, achieving high identification efficiency and accuracy. By obtaining the traffic rate limiting policies corresponding to the target uplink traffic packets of PCDN users, and setting up dual token buckets according to each traffic rate limiting policy, the target uplink traffic packets are automatically forwarded and controlled, effectively limiting PCDN traffic.

[0079] It should be noted that each embodiment of the present invention can be freely combined, rearranged, or executed individually, and does not need to rely on or depend on a fixed execution order.

[0080] Figure 2 This is a schematic diagram illustrating the process of forwarding target uplink traffic packets based on a per-traffic rate limiting strategy, as provided in an embodiment of the present invention. Figure 2 As shown, in some embodiments, step 130, based on each traffic rate limiting policy, sets up dual token buckets to control the forwarding of target uplink traffic packets, including:

[0081] Step 131: Based on the committed rate and the limited rate corresponding to each traffic rate limiting policy, set the first token bucket and the second token bucket corresponding to each traffic rate limiting policy;

[0082] Step 132: Transmit the target uplink traffic packets to the first and second token buckets corresponding to each traffic rate limiting policy to obtain the token allocation status corresponding to each traffic rate limiting policy.

[0083] Step 133: Based on the token allocation status corresponding to each traffic rate limiting strategy, color-code the target uplink traffic packets to obtain the color-coding result corresponding to each traffic rate limiting strategy.

[0084] Step 134: Based on the color-coded results corresponding to each traffic rate limiting policy, control the forwarding of target uplink traffic packets.

[0085] It should be noted that the basic principle of achieving maximum rate limiting and minimum bandwidth guarantee based on dual token bucket technology is as follows:

[0086] 1) Tokens are placed into the token bucket at a set speed, and the token bucket has a set capacity. When the number of tokens in the token bucket exceeds the capacity of the token bucket, the number of tokens will no longer increase.

[0087] 2) Token bucket method for message processing: If there are enough tokens in the token bucket, the message is marked as "token obtained", and the number of tokens in the token bucket is reduced accordingly according to the length of the message; if there are not enough tokens in the token bucket or the token bucket is empty, the message that cannot obtain enough forwarding tokens will be marked as "token not obtained", and the number of tokens in the token bucket will not change.

[0088] It should be noted that a first token bucket is set based on the promised rate for each traffic rate limiting policy; and a second token bucket is set based on the limited rate for each traffic rate limiting policy. The promised rate is less than or equal to the limited rate.

[0089] The token allocation status includes the allocation status of the target uplink traffic packets in the first token bucket and the second token bucket.

[0090] Understandably, by using the dual token bucket algorithm for scheduling and color-coding, it is possible to achieve fine-grained control over traffic rate limiting policies, improve network performance, ensure service quality, and guarantee the rational use of network resources.

[0091] In some embodiments, the target uplink traffic packets are color-coded according to the token allocation status corresponding to each traffic rate limiting policy, including:

[0092] Based on the token allocation status corresponding to each traffic rate limiting policy, determine whether the target uplink traffic packet exceeds the promised rate and the limited rate corresponding to each traffic rate limiting policy;

[0093] If it is determined that the target uplink traffic packet does not exceed the committed rate corresponding to each traffic rate limiting policy, the target uplink traffic packet will be marked as green.

[0094] If it is determined that the target uplink traffic packet exceeds the promised rate corresponding to each traffic rate limiting policy, but does not exceed the limited rate corresponding to each traffic rate limiting policy, the target uplink traffic packet will be marked as yellow.

[0095] If it is determined that the target uplink traffic packet exceeds the rate limit corresponding to each traffic rate limiting policy, the target uplink traffic packet will be marked in red.

[0096] Optionally, for each traffic rate limiting policy, check the number of tokens in the current dual token buckets, calculate the size of the target uplink traffic packet, i.e. the number of tokens required, and determine whether there are enough tokens in the dual token buckets to support the transmission of the traffic based on the token allocation status. If there are enough tokens in the first token bucket, the promised rate has not been exceeded; if there are enough tokens in the second token bucket, the limited rate has not been exceeded.

[0097] Understandably, color-coding target uplink traffic packets allows for quick identification of which traffic is restricted and which can be transmitted normally, which helps monitor and manage network traffic and ensures the effective implementation of rate limiting policies.

[0098] In some embodiments, forwarding control of target uplink traffic packets is performed based on the color-coded result corresponding to each traffic rate limiting policy, including:

[0099] If at least one traffic rate limiting policy corresponds to a green color, then forward the target uplink traffic packet.

[0100] If the color result corresponding to any traffic rate limiting policy is not green, and the color result corresponding to at least one traffic rate limiting policy is red, then the target uplink traffic packet will be discarded.

[0101] If all traffic rate limiting policies are highlighted in yellow, then the target uplink traffic packet is forwarded.

[0102] Understandably, based on the principle of prioritizing committed rates, controlling the forwarding of target uplink traffic packets by combining different color-coded results can effectively limit PCDN traffic and maintain the normal operation and quality of service of the network.

[0103] The PCDN user identification and control device provided in the embodiments of the present invention is described below. The PCDN user identification and control device described below can be referred to in correspondence with the PCDN user identification and control method described above.

[0104] Figure 3 This is a schematic diagram of the PCDN user identification and control device provided in an embodiment of the present invention, as shown below. Figure 3 As shown, the PCDN user identification and control device 300 includes:

[0105] Redirection unit 310 is used to redirect the user's uplink traffic packets so that the user's uplink traffic packets pass through the service-aware SA service board;

[0106] The identification unit 320 is used to process the user's uplink traffic packets to obtain the processed uplink traffic packets, and to identify the point-to-point content delivery network (PCDN) user based on the processed uplink traffic packets.

[0107] The control unit 330 is used to obtain at least one traffic rate limiting policy corresponding to the target uplink traffic packet of the PCDN user, and set up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packet.

[0108] Optionally, based on the processed uplink traffic packets, PCDN users are identified, including:

[0109] Obtain specific information corresponding to the processed uplink traffic packets. The specific information includes at least one of the following: specific port, specific signature, specific behavior, and specific protocol type.

[0110] Identify PCDN users based on specific information.

[0111] Optionally, based on the processed uplink traffic packets, PCDN users are identified, including:

[0112] Identify PCDN users based on the traffic values ​​of the processed uplink traffic packets.

[0113] Optionally, based on the processed uplink traffic packets, PCDN users are identified, including:

[0114] Identify PCDN users based on the number of sessions corresponding to the processed uplink traffic packets.

[0115] Optionally, based on each traffic rate limiting policy, a dual token bucket is set up to control the forwarding of target uplink traffic packets, including:

[0116] Based on the committed rate and the limited rate corresponding to each traffic rate limiting policy, set the first token bucket and the second token bucket corresponding to each traffic rate limiting policy.

[0117] Transmit the target uplink traffic packets to the first and second token buckets corresponding to each traffic rate limiting policy to obtain the token allocation status corresponding to each traffic rate limiting policy.

[0118] Based on the token allocation status corresponding to each traffic rate limiting policy, the target uplink traffic packets are color-coded to obtain the color-coding result corresponding to each traffic rate limiting policy.

[0119] Based on the color-coded results corresponding to each traffic rate limiting policy, forwarding control is applied to the target uplink traffic packets.

[0120] Optionally, the target uplink traffic packets are color-coded according to the token allocation status corresponding to each traffic rate limiting policy, including:

[0121] Based on the token allocation status corresponding to each traffic rate limiting policy, determine whether the target uplink traffic packet exceeds the promised rate and the limited rate corresponding to each traffic rate limiting policy;

[0122] If it is determined that the target uplink traffic packet does not exceed the committed rate corresponding to each traffic rate limiting policy, the target uplink traffic packet will be marked as green.

[0123] If it is determined that the target uplink traffic packet exceeds the promised rate corresponding to each traffic rate limiting policy, but does not exceed the limited rate corresponding to each traffic rate limiting policy, the target uplink traffic packet will be marked as yellow.

[0124] If it is determined that the target uplink traffic packet exceeds the rate limit corresponding to each traffic rate limiting policy, the target uplink traffic packet will be marked in red.

[0125] Optionally, based on the color-coded result corresponding to each traffic rate limiting policy, forwarding control is performed on the target uplink traffic packets, including:

[0126] If at least one traffic rate limiting policy corresponds to a green color, then forward the target uplink traffic packet.

[0127] If the color result corresponding to any traffic rate limiting policy is not green, and the color result corresponding to at least one traffic rate limiting policy is red, then the target uplink traffic packet will be discarded.

[0128] If all traffic rate limiting policies are highlighted in yellow, then the target uplink traffic packet is forwarded.

[0129] It should be noted that the PCDN user identification and control device provided in this embodiment of the invention can implement all the method steps implemented in the above PCDN user identification and control method embodiment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.

[0130] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention, such as... Figure 4As shown, the electronic device may include a processor 410, a communications interface 420, a memory 430, and a communication bus 440. The processor 410, communications interface 420, and memory 430 communicate with each other via the communication bus 440. The processor 410 can call logical instructions in the memory 430 to execute a PCDN user identification and control method. This method includes: redirecting the user's uplink traffic packets so that the user's uplink traffic packets pass through the service-aware SA service board; processing the user's uplink traffic packets to obtain processed uplink traffic packets; identifying the PCDN user based on the processed uplink traffic packets; obtaining at least one traffic rate limiting policy corresponding to the target uplink traffic packets of the PCDN user; and setting up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packets.

[0131] Furthermore, the logical instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0132] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the PCDN user identification and control method provided by the above methods. The method includes: redirecting the user's uplink traffic packets so that the user's uplink traffic packets pass through the service-aware SA service board; processing the user's uplink traffic packets to obtain processed uplink traffic packets; identifying the PCDN user based on the processed uplink traffic packets; obtaining at least one traffic rate limiting policy corresponding to the target uplink traffic packets of the PCDN user; setting up dual token buckets based on each traffic rate limiting policy; and performing forwarding control on the target uplink traffic packets.

[0133] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0134] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A PCDN user identification and control method, characterized in that, include: Redirect the user's uplink traffic packets so that the user's uplink traffic packets pass through the Service Aware SA service board; The user's uplink traffic packets are processed to obtain processed uplink traffic packets. Based on the processed uplink traffic packets, the point-to-point content delivery network (PCDN) user is identified. Obtain at least one traffic rate limiting policy corresponding to the target uplink traffic packet of the PCDN user, and set up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packet; The method of setting up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packets includes: Based on the committed rate and the limited rate corresponding to each traffic rate limiting strategy, set the first token bucket and the second token bucket corresponding to each traffic rate limiting strategy. The target uplink traffic packet is transmitted to the first token bucket and the second token bucket corresponding to each traffic rate limiting policy to obtain the token allocation status corresponding to each traffic rate limiting policy. Based on the token allocation status corresponding to each traffic rate limiting strategy, the target uplink traffic packets are color-coded to obtain the color-coding result corresponding to each traffic rate limiting strategy. Based on the color-coded result corresponding to each traffic rate limiting policy, the forwarding control of the target uplink traffic packets is performed.

2. The PCDN user identification and control method according to claim 1, characterized in that, The process of identifying PCDN users based on the processed uplink traffic packets includes: Obtain specific information corresponding to the processed uplink traffic packet, wherein the specific information includes at least one of the following: specific port, specific signature, specific behavior, and specific protocol type; Based on the specific information, PCDN users are identified.

3. The PCDN user identification and control method according to claim 1, characterized in that, The process of identifying PCDN users based on the processed uplink traffic packets includes: PCDN users are identified based on the traffic value of the processed uplink traffic packets.

4. The PCDN user identification and control method according to claim 1, characterized in that, The process of identifying PCDN users based on the processed uplink traffic packets includes: PCDN users are identified based on the number of sessions corresponding to the processed uplink traffic packets.

5. The PCDN user identification and control method according to claim 1, characterized in that, The step of color-coding the target uplink traffic packets according to the token allocation status corresponding to each traffic rate limiting policy includes: Based on the token allocation status corresponding to each traffic rate limiting policy, determine whether the target uplink traffic packet exceeds the committed rate and the limited rate corresponding to each traffic rate limiting policy; If it is determined that the target uplink traffic packet does not exceed the committed rate corresponding to each traffic rate limiting policy, the target uplink traffic packet is marked as green; If it is determined that the target uplink traffic packet exceeds the committed rate corresponding to each traffic rate limiting policy, but does not exceed the limited rate corresponding to each traffic rate limiting policy, the target uplink traffic packet is marked as yellow. If it is determined that the target uplink traffic packet exceeds the rate limit corresponding to each traffic rate limiting policy, the target uplink traffic packet is marked in red.

6. The PCDN user identification and control method according to claim 5, characterized in that, Based on the color-coded result corresponding to each traffic rate limiting policy, forwarding control is performed on the target uplink traffic packets, including: If the color result corresponding to at least one traffic rate limiting policy is green, then the target uplink traffic packet is forwarded; If the color result corresponding to any traffic rate limiting policy is not green, and the color result corresponding to at least one traffic rate limiting policy is red, then the target uplink traffic packet will be discarded. If all traffic rate limiting policies are highlighted in yellow, then the target uplink traffic packet is forwarded.

7. A PCDN user identification and control device, characterized in that, include: The redirection unit is used to redirect the user's uplink traffic packets so that the user's uplink traffic packets pass through the Service Aware SA service board; The identification unit is used to process the user's uplink traffic packets to obtain processed uplink traffic packets, and to identify the point-to-point content delivery network (PCDN) user based on the processed uplink traffic packets. The control unit is used to obtain at least one traffic rate limiting policy corresponding to the target uplink traffic packet of the PCDN user, and set up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packet. The method of setting up dual token buckets based on each traffic rate limiting policy to control the forwarding of the target uplink traffic packets includes: Based on the committed rate and the limited rate corresponding to each traffic rate limiting strategy, set the first token bucket and the second token bucket corresponding to each traffic rate limiting strategy. The target uplink traffic packet is transmitted to the first token bucket and the second token bucket corresponding to each traffic rate limiting policy to obtain the token allocation status corresponding to each traffic rate limiting policy. Based on the token allocation status corresponding to each traffic rate limiting strategy, the target uplink traffic packets are color-coded to obtain the color-coding result corresponding to each traffic rate limiting strategy. Based on the color-coded result corresponding to each traffic rate limiting policy, the forwarding control of the target uplink traffic packets is performed.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the PCDN user identification and management method as described in any one of claims 1 to 6.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the PCDN user identification and management method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Detection method, system and device for discovering PCDN user and readable medium

    CN116962255A

  • Illegal user detection method and device, equipment and storage medium

    CN117118711A