Resource access processing method and apparatus, computer device, and readable storage medium

By introducing automated content identification and real-time blocking mechanisms into content delivery networks, the problem of low efficiency in handling abnormal content in content delivery networks has been solved, enabling rapid location and accurate identification of illegal resources, thereby improving network security and user experience.

CN119520145BActive Publication Date: 2026-02-03CHINA TELECOM CLOUD TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411748973.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-02
Publication Date
2026-02-03
Estimated Expiration
2044-12-02

AI Technical Summary

Technical Problem

In existing technologies, the processing efficiency of abnormal content in content delivery networks is low, relying on user reports and inspections by maintenance personnel. This makes it impossible to handle illegal resources in a timely and effective manner, resulting in user security risks and high maintenance pressure.

Method used

Introduce automated content identification and real-time blocking mechanisms into the content delivery network. The content distribution nodes identify uncached resources, promptly block abnormal content, and achieve network-wide blocking with the support of the identification server.

Benefits of technology

It improves the efficiency of handling abnormal content in the content delivery network, reduces the impact of harmful content on users, reduces the workload of operation and maintenance personnel, and enhances the security and health of the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520145B_ABST
    Figure CN119520145B_ABST
Patent Text Reader

Abstract

The application relates to a resource access processing method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: a content distribution node in a content distribution network receives a resource access request sent by a terminal, when the local end does not cache a target resource requested by the resource access request, the target resource is obtained from a source station server of the content distribution network; when the local end obtains the target resource from the source station server, content identification is carried out on the target resource, and a content identification result of the target resource is obtained; when the content identification result indicates that the target resource belongs to abnormal content, the target resource is banned in the content distribution network, so as to prevent the terminal from accessing the target resource through the resource access request. The method can improve the processing efficiency of abnormal content in the content distribution network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a resource access processing method, apparatus, computer device, computer-readable storage medium, and computer program product. Background Technology

[0002] With the rapid development of internet technology, Content Delivery Networks (CDNs) have become an indispensable part of the modern internet architecture, greatly accelerating data transmission globally and improving user access speed and experience. However, with the explosive growth of online content, inappropriate content and illegal resources frequently appear on CDNs, such as malware, pirated films and television programs, and infringing music. This content severely damages users' legitimate rights and interests, causing significant psychological distress and posing cybersecurity risks.

[0003] However, the detection of abnormal content currently relies on user reports and inspections by operations and maintenance personnel, resulting in low efficiency in handling abnormal content in content delivery networks. Summary of the Invention

[0004] Therefore, it is necessary to provide a resource access processing method, apparatus, computer equipment, computer-readable storage medium, and computer program product that can improve the efficiency of abnormal content processing in content delivery networks, in order to address the above-mentioned technical problems.

[0005] Firstly, this application provides a resource access processing method, applied to a content distribution node in a content delivery network, comprising:

[0006] Receive resource access requests sent by the terminal. If the local terminal does not cache the target resource requested by the resource access request, obtain the target resource from the origin server of the content delivery network.

[0007] When the local end obtains the target resource from the origin server, it performs content authentication on the target resource and obtains the content authentication result of the target resource.

[0008] When the content authentication result indicates that the target resource is abnormal content, the target resource is blocked in the content delivery network to prevent the terminal from accessing the target resource through a resource access request.

[0009] Secondly, this application also provides a resource access processing apparatus, applied to a content distribution node in a content delivery network, comprising:

[0010] The access request receiving module is used to receive resource access requests sent by the terminal. When the local terminal does not cache the target resource requested by the resource access request, it obtains the target resource from the origin server of the content delivery network.

[0011] The content identification module is used to identify the content of the target resource when the local end obtains the target resource from the origin server and obtain the content identification result of the target resource.

[0012] The resource blocking module is used to block the target resource in the content delivery network when the content authentication result indicates that the target resource is abnormal content, so as to prevent the terminal from accessing the target resource through resource access request.

[0013] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the resource access processing method described above.

[0014] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the steps of the above-described resource access processing method.

[0015] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the steps of the above-described resource access processing method.

[0016] The aforementioned resource access processing method, apparatus, computer equipment, computer-readable storage medium, and computer program product, when the local end of a content delivery node in a content delivery network does not cache the target resource requested by the resource access request, obtains the target resource from the origin server of the content delivery network, and performs content authentication on the obtained target resource. If the content authentication result indicates that the obtained target resource belongs to abnormal content, the target resource is blocked in the content delivery network to prevent the terminal from accessing the target resource through the resource access request. Thus, when the content delivery node obtains a target resource that belongs to abnormal content from the origin server, the target resource can be blocked in the content delivery network in a timely manner, improving the processing efficiency of abnormal content in the content delivery network. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is an application environment diagram of a resource access processing method in one embodiment;

[0019] Figure 2 This is a flowchart illustrating a resource access processing method in one embodiment;

[0020] Figure 3 This is a flowchart illustrating the resource pre-identification process in one embodiment;

[0021] Figure 4 This is a flowchart illustrating a resource access processing method in another embodiment;

[0022] Figure 5 This is a structural block diagram of a resource access processing device in one embodiment;

[0023] Figure 6 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0025] The resource access processing method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, terminal 102 communicates with content delivery node 104 in the content delivery network via a network. A data storage system connected to content delivery node 104 can store data that content delivery node 104 needs to process. This data storage system can be integrated onto content delivery node 104 or located in the cloud or on another network server. Content delivery node 104 communicates with origin server 106 in the content delivery network via a network. A data storage system connected to origin server 106 can store data that origin server 106 needs to process. This data storage system can be integrated onto origin server 106 or located in the cloud or on another network server.

[0026] A user can send a resource access request to a content delivery node 104 in the content delivery network via terminal 102 to request access to a target resource. If the content delivery node 104 determines that the target resource requested by the resource access request is not cached locally, the content delivery node 104 can obtain the target resource from the origin server 106. After obtaining the target resource from the origin server 106, the content delivery node 104 can perform content authentication on the obtained target resource. If the content authentication result indicates that the obtained target resource is abnormal content, the content delivery node 104 can block the target resource in the content delivery network to prevent terminal 102 from accessing the target resource through the resource access request.

[0027] The terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, smart in-vehicle systems, and projection devices. Portable wearable devices can include smartwatches, smart bracelets, and head-mounted displays. Head-mounted displays can be virtual reality (VR) devices, augmented reality (AR) devices, and smart glasses. The content distribution node 104 or the origin server 106 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0028] In one exemplary embodiment, such as Figure 2 As shown, a resource access processing method is provided, which is applied to... Figure 1 Taking the content distribution node in the process as an example, the explanation includes the following steps 202 to 206. Wherein:

[0029] Step 202: Receive a resource access request sent by the terminal. If the local terminal does not cache the target resource requested by the resource access request, obtain the target resource from the origin server of the content delivery network.

[0030] Content Delivery Network (CDN) is a technology that achieves efficient content distribution and accelerated transmission by deploying multiple node servers within a network. Content delivery nodes are node servers deployed within a CDN, used for content transmission between origin servers and terminals. Resource access requests are sent by the terminal to the content delivery nodes in the CDN, requesting the return of the required resource content. The target resource is the resource content requested by the user through the resource access request, which can specifically include various forms of resource content such as web pages, videos, images, and audio. Origin servers are servers in the CDN that store the original content. Origin servers store all the original data of a website or application, including static or dynamic resources such as web pages, images, videos, and audio. As the original provider of content, the origin server is the source of data distribution, specifically handling content distribution to terminals through content delivery nodes.

[0031] For example, a content delivery node in a content delivery network (CDN) can receive a resource access request sent by a terminal and determine the target resource requested by the user based on the resource access request. For instance, the resource access request may carry a resource identifier of the target resource, and the CDN can determine the target resource requested by the user based on this resource identifier. The CDN can query locally whether the target resource is cached, such as by querying locally according to the resource identifier of the target resource to determine whether the target resource is pre-cached locally. If it is determined that the target resource is not cached locally, the CDN can obtain the target resource from the origin server of the CDN. In some embodiments, the CDN can send a resource retrieval request to the origin server to request the target resource.

[0032] Step 204: When the local end obtains the target resource from the origin server, it performs content authentication on the target resource and obtains the content authentication result of the target resource.

[0033] The content authentication result is obtained by performing content authentication on the target resource. This can be done through third-party security services or a custom authentication algorithm. Optionally, the content distribution node can obtain the target resource from the origin server and perform content authentication on it to obtain the content authentication result. In some embodiments, the content distribution node can directly perform content authentication on the target resource to determine whether it contains abnormal content, such as whether it includes illegal or unlawful content. Alternatively, the content distribution node can send the target resource to a third party for content authentication and return the corresponding authentication result.

[0034] Step 206: When the content identification result indicates that the target resource is abnormal content, the target resource is blocked in the content delivery network to prevent the terminal from accessing the target resource through a resource access request.

[0035] For example, when the content authentication result indicates that the target resource is abnormal content, it means that the target resource contains illegal or unlawful content, requiring access restrictions. The content distribution node can block the target resource within the content distribution network, such as removing it from the network, thereby preventing the terminal from accessing the target resource via a resource access request. In some embodiments, after blocking the target resource, the content distribution node can return an access failure message to the terminal, indicating that the access to the target resource has failed. In some embodiments, when the content authentication result indicates that the target resource is not abnormal content, meaning it is safe content, the content distribution node can send the obtained target resource to the terminal to handle resource access requests.

[0036] In the above resource access processing method, when the local end of the content distribution node in the content delivery network does not cache the target resource requested by the resource access request, the target resource is obtained from the origin server of the content delivery network, and the content of the obtained target resource is identified. If the content identification result indicates that the obtained target resource belongs to abnormal content, the target resource is blocked in the content delivery network to prevent the terminal from accessing the target resource through the resource access request. Thus, when the content distribution node obtains the target resource that belongs to abnormal content from the origin server, the target resource can be blocked in the content delivery network in a timely manner, which improves the processing efficiency of abnormal content in the content delivery network.

[0037] In an exemplary embodiment, when the local end obtains the target resource from the origin server, performs content authentication on the target resource, and obtains the content authentication result of the target resource, the process includes: determining the resource identification information of the target resource and the node information of the content distribution node; generating a content authentication request based on the resource identification information and the node information; sending the content authentication request to the content authentication server, the content authentication request being used to instruct the content authentication server to perform content authentication on the target resource and return the content authentication result; and obtaining the content authentication result for the target resource returned by the content authentication server.

[0038] The resource identification information is used to identify the target resource, and may include, but is not limited to, at least one of various identification information such as the resource name, resource ID (identification), and resource address. The node information is used to describe the content distribution node, and may include, but is not limited to, at least one of various information such as the network address, hardware address, and node identifier of the content distribution node. The content authentication request is used to request the content authentication server to perform content authentication on the target resource. The content authentication server can be a dedicated server for content authentication.

[0039] For example, a content delivery node can determine the resource identifier information of the target resource and the node information of the content delivery node, such as the URL (Uniform Resource Locator) of the target resource and the IP (Internet Protocol) address of the content delivery node. The content delivery node can generate a content authentication request based on the resource identifier information and the node information, and send the content authentication request to a content authentication server to instruct the content authentication server to perform content authentication on the target resource and return the content authentication result. In some embodiments, the content authentication server can obtain the target resource based on the content authentication request, perform content authentication on the obtained target resource, and return the obtained content authentication result to the content delivery node. The content delivery node can receive the content authentication result returned by the content authentication server and, based on the content authentication result, perform blocking or distribution processing on the target resource.

[0040] In some embodiments, the content distribution node can directly perform preliminary content assessment on the target resource. That is, the content distribution node can perform content assessment on the target resource locally to obtain a preliminary assessment result. If the preliminary assessment result indicates that the target resource is abnormal content, the content distribution node can send a content assessment request to the content assessment server to perform further in-depth content assessment on the target resource, and obtain the final content assessment result based on the in-depth assessment result returned by the content assessment server. In some embodiments, the content distribution node can perform multiple preliminary content assessments on the target resource locally and combine the results of the multiple preliminary content assessments to obtain the final preliminary assessment result. In some embodiments, the content distribution node can also set different weights for the local preliminary content assessment and the in-depth content assessment by the content assessment server, and combine the preliminary assessment result and the in-depth assessment result according to their respective weights to obtain the final content assessment result.

[0041] In this embodiment, the content distribution node generates a content authentication request based on the resource identifier information of the target resource and the node information of the content distribution node. The content authentication request instructs the content authentication server to perform content authentication on the target resource, thereby enabling accurate content authentication of the target resource and timely detection of resource content that needs to be blocked.

[0042] In an exemplary embodiment, the content authentication server is further configured to: upon receiving a content authentication request, determine a resource authentication database, the resource authentication database including various resources that have completed content authentication and their corresponding content authentication results; based on the resource identification information in the content authentication request, perform a query in the resource authentication database to obtain a query result; if the query result indicates that the target resource has not completed content authentication, perform content authentication on the target resource and return the obtained content authentication result to the content distribution node; if the query result indicates that the target resource has completed content authentication, obtain the content authentication result of the target resource from the resource authentication database and return the content authentication result to the content distribution node.

[0043] The resource identification database is used to record various resources that have completed content identification and their corresponding content identification results. In other words, resources that have completed content identification can be recorded through the resource identification database.

[0044] For example, after receiving a content authentication request, the content authentication server can determine a pre-built resource authentication database and query it to determine whether the database stores a content authentication record for the target resource. Optionally, the content authentication server can extract resource identification information from the content authentication request and perform a matching query in the resource authentication database according to the resource identification information to obtain the corresponding query results. When the query result indicates that the target resource has not completed content authentication, i.e., the resource authentication database does not contain a content authentication record for the target resource, the content authentication server can perform content authentication on the target resource. For example, the content authentication server can obtain the target resource from the content distribution node according to the resource identification information and node information in the content authentication request, perform content authentication on the target resource, obtain the corresponding content authentication result, and return it to the content distribution node. In some embodiments, when the query result indicates that the target resource has completed content authentication, i.e., the resource authentication database already stores a content authentication record for the target resource, indicating that the target resource has already completed content authentication, the content authentication server can directly obtain the content authentication result of the target resource from the resource authentication database and return it to the content distribution node.

[0045] In some embodiments, the resource identification database may only store content identification records corresponding to resources that are not anomalous content. That is, if the resource identification database does not include a content identification record for resource A, it indicates that resource A may be anomalous content or content that has not yet been identified. In this case, the content identification server needs to trigger content identification processing. On the other hand, if the resource identification database includes a content identification record for resource B, it indicates that resource B is not anomalous content. In this case, the content identification server can directly obtain the content identification result for resource B.

[0046] In this embodiment, the content identification server queries the resource identification database to see if there is a content identification record for the target resource. If there is a corresponding content identification record, the corresponding content identification result can be obtained directly from the resource identification database, thereby improving the processing efficiency of content identification.

[0047] In an exemplary embodiment, when the content authentication result indicates that the target resource is abnormal content, the target resource is blocked in the content delivery network to prevent the terminal from accessing the target resource through a resource access request. This includes: when the content authentication result indicates that the target resource is abnormal content, sending a blocking instruction to each node in the content delivery network, the blocking instruction being used to instruct each node to block access to the target resource.

[0048] The blocking command is used to instruct each node to block access to the target resource. Specifically, it can be propagated by the content distribution node in the content distribution network, or by the content authentication server that performs content authentication among the various content distribution nodes in the content distribution network.

[0049] For example, when the content authentication result indicates that the target resource is abnormal content, it suggests that the target resource may pose a security risk and needs to be blocked. The content distribution node can send blocking instructions to various nodes in the content distribution network to instruct them to block access to the target resource. In some embodiments, when the content authentication result indicates that the target resource is abnormal content, the content distribution node can return a blocking instruction to the content authentication server or the source server, which will then send blocking instructions to various nodes in the content distribution network, thereby blocking access to the target resource within the content distribution network. In some embodiments, after receiving the blocking instruction, each node in the content distribution network can delete the target resource cached locally and prevent the terminal from accessing the target resource.

[0050] In this embodiment, when the content identification result indicates that the target resource is abnormal content, a blocking instruction is sent to each node in the content delivery network to instruct each node to block access to the target resource. This allows for timely blocking of the target resource at each node in the content delivery network, improving the processing efficiency of abnormal content in the content delivery network.

[0051] In an exemplary embodiment, the resource access processing method further includes: when the target resource requested by the resource access request has been cached on the local end, obtaining the target resource from the local end; and sending the target resource to the terminal according to the resource access request.

[0052] For example, if the target resource requested by the resource access request has been cached in the local end of the content distribution node, it indicates that the target resource is not abnormal content. That is, when any node in the content distribution network caches the target resource, it has not blocked the target resource. In this case, the content distribution node can directly obtain the target resource from the local end and distribute the target resource to the terminal to realize the response processing of the resource access request.

[0053] In this embodiment, when the target resource is already cached on the local end of the content distribution node, the content distribution node can directly distribute the target resource to the corresponding terminal, thereby enabling the terminal to quickly access the target resource.

[0054] In one exemplary embodiment, such as Figure 3 As shown, the resource access processing method also includes resource pre-identification processing, specifically steps 302 to 306. Wherein:

[0055] Step 302: When the content identification triggering conditions are detected, obtain the resource to be identified from the content distribution network.

[0056] The content identification trigger conditions are used to determine whether to trigger content identification processing for a resource. These trigger conditions can be flexibly set according to actual needs, and may include trigger conditions such as identification cycle and resource popularity. The resource to be identified is the resource that needs to be identified.

[0057] For example, a content distribution node can detect whether preset content authentication triggering conditions are met, such as whether a preset authentication period has been reached, or whether there are unauthenticated popular resources. When the content authentication triggering conditions are met, the content distribution node can obtain the resource to be authenticated from the content distribution network. For example, the content distribution node can obtain resources from the content distribution network within the authentication period, or obtain popular resources from the content distribution network whose popularity exceeds a popularity threshold.

[0058] Step 304: Perform content identification on the resource to be identified to obtain the content identification result corresponding to the resource to be identified.

[0059] Optionally, the content distribution node can trigger content authentication for the resource to be authenticated. Specifically, the content distribution node can directly perform content authentication on the resource to be authenticated, or the content authentication server can perform content authentication on the resource to be authenticated, thereby obtaining the content authentication result corresponding to the resource to be authenticated.

[0060] Step 306: When the content identification result of the resource to be identified indicates that the resource to be identified is abnormal content, the resource to be identified is blocked in the content delivery network to prevent access to the resource to be identified.

[0061] For example, when the content identification result of the resource to be identified indicates that the resource to be identified is abnormal content, the content distribution node can block the resource to be identified in the content distribution network. For example, the content distribution node can send a blocking instruction to each node in the content distribution network to instruct each node to block access to the resource to be identified.

[0062] In this embodiment, the content distribution node can perform content authentication on the resource to be authenticated in the content distribution network when the content authentication triggering condition is met. This allows content authentication to be performed before the terminal accesses the content, thus improving the processing efficiency of abnormal content in the content distribution network.

[0063] This application also provides an application scenario in which the above-described resource access processing method is applied. Specifically, the resource access processing method is applied in this application scenario as follows:

[0064] With the rapid development of internet technology, Content Delivery Networks (CDNs) have become an important tool for improving website access speed and performance. A CDN is a network that distributes resources needed by users and provides services to customers based on proximity. However, when websites accelerated by domains cached by CDN nodes are filled with malicious resources, existing technologies often fall short. Currently, after detecting abnormal resources, CDN nodes typically adopt a reactive mechanism, waiting for customer reports before maintenance personnel urgently go online and delete the abnormal resources across the entire network. This approach is not only inefficient and unable to respond promptly and eliminate adverse effects, but it may also lead to users encountering malicious content during their visits, causing customer complaints and dissatisfaction. Therefore, existing CDN caching management mechanisms have significant limitations and shortcomings in dealing with malicious resources. To solve these problems, we urgently need a system and device capable of timely identification and effective blocking of user-accessed content. This system and device should have the ability to automatically identify abnormal resources in real time and automatically issue blocking measures upon detection to ensure the purity and security of user-accessed content.

[0065] Based on this, this embodiment provides a solution that can automatically identify illegal resources and issue real-time network-wide blocking, overcoming the drawback of current CDN nodes needing to manually delete illegal resources after discovery. With the increasing complexity and diversity of network environments, harmful content and illegal resources frequently appear on the network, causing significant inconvenience and security risks to users. Traditional handling methods often rely on user reports and manual operations by maintenance personnel, which are inefficient and unable to effectively curb the spread of illegal resources in a timely manner. Therefore, this application aims to achieve rapid location, accurate identification, and immediate processing of illegal resources by introducing automatic identification technology and a real-time blocking mechanism. The resource access processing method provided in this application will monitor cached resources in CDN nodes in real time. Once illegal content is detected, the system will immediately initiate an automatic blocking process, completely removing the relevant resources from the CDN network to ensure the purity and security of content accessed by users. Based on the resource access processing method provided in this application, the efficiency of CDN nodes in processing illegal resources can be significantly improved, the impact of harmful content on users can be reduced, the workload of maintenance personnel can be alleviated, and the overall health and security of the network environment can be improved.

[0066] Specifically, the resource access processing method provided in this embodiment focuses on the automatic identification and real-time blocking of illegal resources. CDN resources are fetched layer by layer from edge nodes to parent nodes and then to the origin server to achieve efficient content distribution. To ensure the legality and security of the content, the resource access processing method provided in this embodiment introduces content authentication processing after the resource is first cached in the parent layer. Specifically, when a resource is first cached in the parent node, an authentication request is automatically triggered to the content authentication center. The authentication request includes the IP address of the device where the resource to be authenticated is located and the unique identifier of the resource. The content authentication center is responsible for receiving the authentication request and, after obtaining the resource from the specified device, calling external interfaces to authenticate the resource content. These external interfaces may include, but are not limited to, various security scanning tools, virus detection services, or content filtering APIs (Application Programming Interfaces). Once the content authentication center detects an anomaly in the resource through the external interface, such as containing malicious code, viruses, or pornographic content, it will immediately initiate a network-wide blocking process. The blocking task will be directly issued by the content authentication center to all CDN devices, including edge nodes and parent nodes, to ensure that abnormal resources are quickly isolated and removed across the entire network.

[0067] Furthermore, to improve the system's response speed and accuracy, the resource access processing method provided in this embodiment also introduces cache preheating and content pre-inspection mechanisms. Specifically, before a resource is requested by a user, the system can retrieve the resource to the parent node in advance and perform content authentication, thereby ensuring that legitimate and secure content can be provided immediately upon user request.

[0068] Specifically, when the resource access processing method provided in this embodiment is applied to a CDN system, it can automatically identify and block illegal resources in real time, thereby ensuring the legality and security of the content accessed by users. For example... Figure 4 As shown, when a CDN node caches resources for the first time, it can send a resource verification request to the content verification center. The content verification center's resource verification interface then pulls the resource to be verified from the CDN node and initiates an external call to perform content verification. For any abnormal resources identified, a network-wide blocking command can be issued, allowing all CDN nodes to block them. Specifically, this can include the following processing:

[0069] 1. Resource fetching: When a user requests a resource for the first time, if the cache misses (i.e., the parent cache device's ctl-cache-status response header is miss), the CDN system will fetch the resource from the origin server, cache it on the parent node, respond to the user, and asynchronously start the content review logic. If the cache hits (i.e., the parent cache device's ctl-cache-status response header is hit), the system will directly respond to the user and skip the content review logic.

[0070] 2. Authentication Request: Once a resource is successfully cached for the first time on the parent node, the system will automatically send an authentication request to the content authentication center. This request will contain the resource's unique identifier (such as a URL or file hash value), the IP address of the parent device where the resource resides, and other necessary metadata information; among which, the URL contains the resource's address, location information, etc., used to uniquely identify a resource;

[0071] 3. Content Verification: Upon receiving a verification request, the content verification center uses the provided unique identifier and the resource's IP address to retrieve the corresponding resource from the CDN node's cache and calls external interfaces to verify the resource content. These external interfaces can be third-party security services or custom verification algorithms. If a resource is identified as abnormal, such as content related to pornography, terrorism, or violence as determined by AI (Artificial Intelligence) algorithms, the content verification center will generate a blocking command. This blocking command can be an HTTP (Hypertext Transfer Protocol) interface call containing the resource's unique identifier. To ensure the uniqueness of resource verification and save on verification interface usage costs, a global database is deployed at the content verification center. Before each resource verification is initiated, the database is queried for the verification results. If a match is found, it indicates that the resource has already been verified; otherwise, the external interface verification is initiated.

[0072] 4. Network-wide Block: The blocking command will be issued to all CDN devices by the Content Authentication Center via API call. These devices will immediately remove the abnormal resource from the cache and prevent subsequent users from accessing the resource. Simultaneously, the system will record relevant logs for subsequent analysis and auditing.

[0073] 5. Cache Preheating and Content Pre-inspection: To improve system response speed and accuracy, the system can periodically or as needed perform cache preheating and content pre-inspection for popular resources. This means that before a resource is requested by a user, the system has already retrieved it from the parent node and performed content verification. Therefore, when a user requests these resources, the system can immediately provide legitimate and secure content.

[0074] The resource access processing method provided in this embodiment aims to achieve a highly efficient and accurate automatic content review system. This system can detect the content transmitted in the CDN network in real time and immediately block abnormal resources. Specifically, it includes:

[0075] Real-time monitoring and detection: The system monitors the traffic and content transmission of CDN nodes in real time. After the resource is cached on the CDN network for the first time, a verification mechanism is initiated. Once abnormal resources are detected, such as those containing malicious code, pornographic content, or infringing information, the review mechanism is immediately triggered.

[0076] Instant blocking and isolation: For confirmed abnormal resources, the system will immediately issue a blocking command, notifying all CDN devices across the network to ensure that the abnormal resources are quickly isolated and removed. Simultaneously, the system will record relevant logs for subsequent analysis and auditing.

[0077] Uniqueness of resource verification: In order to save on the high cost of API interface calls, the authentication request is only initiated when the parent node caches the resource for the first time, and a secondary deduplication mechanism is implemented in the content authentication center to ensure the uniqueness of resource verification.

[0078] In the resource access processing method provided in this embodiment, through real-time monitoring and automated review, the system can promptly detect and process illegal content, effectively curbing the spread of harmful information and protecting users from the harm of harmful content, thus improving content security. Moreover, traditional content review methods typically require manual intervention, which is time-consuming and prone to errors. The resource access processing method provided in this embodiment can quickly and accurately complete content review, greatly improving review efficiency. Furthermore, the automated review system reduces the need for manual review, lowering the company's labor costs. Simultaneously, because the system can detect and process abnormal resources in real time, it reduces complaints and disputes caused by illegal content, further reducing the company's operating costs. Furthermore, by improving content security and review efficiency, the resource access processing method provided in this embodiment can provide users with more secure and efficient network services. When using the CDN network, users can enjoy a cleaner and healthier network environment, thereby improving user experience. In addition, the resource access processing method provided in this embodiment is highly adaptable, capable of adapting to different types of CDN networks and diverse content formats. Whether it is text, images, or multimedia content such as videos, the system can effectively review and block them. Finally, the resource access processing method provided in this embodiment has low authentication cost, initiates authentication upon initial resource caching, and the content authentication center supports a deduplication mechanism for authentication, which effectively ensures one-time verification of all network resources and greatly saves API call costs.

[0079] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0080] Based on the same inventive concept, this application also provides a resource access processing apparatus for implementing the resource access processing method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more resource access processing apparatus embodiments provided below can be found in the limitations of the resource access processing method described above, and will not be repeated here.

[0081] In one exemplary embodiment, such as Figure 5 As shown, a resource access processing device 500 is provided, applied to a content distribution node in a content delivery network, including: an access request receiving module 502, a content authentication module 504, and a resource blocking module 506, wherein:

[0082] The access request receiving module 502 is used to receive resource access requests sent by the terminal. When the local terminal does not cache the target resource requested by the resource access request, it obtains the target resource from the origin server of the content delivery network.

[0083] The content authentication module 504 is used to perform content authentication on the target resource when the local end obtains the target resource from the origin server, and obtain the content authentication result of the target resource.

[0084] The resource blocking module 506 is used to block the target resource in the content delivery network when the content authentication result indicates that the target resource is abnormal content, so as to prevent the terminal from accessing the target resource through a resource access request.

[0085] In an exemplary embodiment, the content identification module 504 is further configured to determine the resource identification information of the target resource and the node information of the content distribution node; generate a content identification request based on the resource identification information and the node information; send the content identification request to the content identification server, the content identification request being used to instruct the content identification server to perform content identification for the target resource and return the content identification result; and obtain the content identification result for the target resource returned by the content identification server.

[0086] In an exemplary embodiment, the content authentication server is further configured to, upon receiving a content authentication request, determine a resource authentication database, which includes various resources that have completed content authentication and their corresponding content authentication results; query the resource authentication database based on the resource identification information in the content authentication request to obtain query results; if the query result indicates that the target resource has not completed content authentication, perform content authentication on the target resource and return the obtained content authentication result to the content distribution node; if the query result indicates that the target resource has completed content authentication, obtain the content authentication result of the target resource from the resource authentication database and return the content authentication result to the content distribution node.

[0087] In an exemplary embodiment, the resource blocking module 506 is further configured to send blocking instructions to each node in the content distribution network when the content identification result indicates that the target resource belongs to abnormal content. The blocking instructions are used to instruct each node to block access to the target resource.

[0088] In an exemplary embodiment, a resource distribution module is further included, which is used to obtain the target resource from the local end when the target resource requested by the resource access request has been cached on the local end; and to send the target resource to the terminal according to the resource access request.

[0089] In an exemplary embodiment, a pre-identification module is further included, which is used to obtain the resource to be identified from the content distribution network when the content identification trigger condition is detected; to perform content identification on the resource to be identified and obtain the content identification result corresponding to the resource to be identified; and when the content identification result corresponding to the resource to be identified indicates that the resource to be identified belongs to abnormal content, to block the resource to be identified in the content distribution network to prevent access to the resource to be identified.

[0090] Each module in the aforementioned resource access processing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can invoke and execute the operations corresponding to each module.

[0091] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores various data involved in resource access processing methods. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a resource access processing method.

[0092] Those skilled in the art will understand that Figure 6The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0093] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.

[0094] In one embodiment, a computer-readable storage medium is provided storing a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0095] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0096] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0097] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0098] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0099] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A resource access processing method, characterized in that, The method, applied to content distribution nodes in a content delivery network, includes: Receive a resource access request sent by a terminal; if the local terminal does not cache the target resource requested by the resource access request, obtain the target resource from the origin server of the content delivery network. When the local end obtains the target resource from the origin server, it performs multiple preliminary content assessments on the target resource locally, obtains a preliminary assessment result based on the assessment results of the multiple preliminary content assessments, and when the preliminary assessment result indicates that the target resource belongs to abnormal content, it sends a content assessment request to the content assessment server so that the content assessment server can perform a deep content assessment on the target resource, and obtains the content assessment result of the target resource based on the deep assessment result returned by the content assessment server. When the content identification result indicates that the target resource is abnormal content, the target resource is blocked in the content distribution network to prevent the terminal from accessing the target resource through the resource access request.

2. The method according to claim 1, characterized in that, The step of sending a content authentication request to a content authentication server, so that the content authentication server can perform deep content authentication on the target resource and obtain the content authentication result of the target resource, includes: Determine the resource identifier information of the target resource and the node information of the content distribution node; A content authentication request is generated based on the resource identification information and node information; The content authentication request is sent to the content authentication server, which instructs the content authentication server to perform deep content authentication on the target resource and return the deep authentication result.

3. The method according to claim 2, characterized in that, The content authentication server is also used for: Upon receiving the content authentication request, the resource authentication database is determined. The resource authentication database includes various resources that have completed content authentication and their corresponding content authentication results. Based on the resource identification information in the content identification request, a query is performed in the resource identification database to obtain the query results; When the query result indicates that the target resource has not completed content identification, content identification is performed on the target resource, and the obtained content identification result is returned to the content distribution node; When the query result indicates that the target resource has completed content identification, the content identification result of the target resource is obtained from the resource identification database and returned to the content distribution node.

4. The method according to claim 1, characterized in that, When the content authentication result indicates that the target resource is abnormal content, the target resource is blocked in the content distribution network to prevent the terminal from accessing the target resource through the resource access request, including: When the content identification result indicates that the target resource is abnormal content, a blocking instruction is sent to each node in the content distribution network. The blocking instruction is used to instruct each node to block access to the target resource.

5. The method according to claim 1, characterized in that, The method further includes: If the target resource requested by the resource access request has been cached on the local end, the target resource is obtained from the local end. The target resource is sent to the terminal according to the resource access request.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: When the content identification triggering conditions are detected, the resource to be identified is obtained from the content distribution network; Content identification is performed on the resource to be identified, and the content identification result corresponding to the resource to be identified is obtained. When the content identification result of the resource to be identified indicates that the resource to be identified is abnormal content, the resource to be identified is blocked in the content distribution network to prevent access to the resource to be identified.

7. A resource access processing apparatus, characterized in that, The device is used as a content distribution node in a content delivery network, and includes: An access request receiving module is used to receive resource access requests sent by a terminal. When the local terminal does not cache the target resource requested by the resource access request, the module obtains the target resource from the origin server of the content delivery network. The content identification module is used to perform multiple preliminary content identifications on the target resource when the local end obtains the target resource from the origin server, obtain a preliminary identification result based on the identification results of the multiple preliminary content identifications, and send a content identification request to the content identification server when the preliminary identification result indicates that the target resource belongs to abnormal content, so that the content identification server can perform deep content identification on the target resource, and obtain the content identification result of the target resource based on the deep identification result returned by the content identification server. The resource blocking module is used to block the target resource in the content distribution network when the content identification result indicates that the target resource is abnormal content, so as to prevent the terminal from accessing the target resource through the resource access request.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Resource management method and system and storage medium

    CN111327606A

  • Network distribution content detection processing device, method, system and electronic equipment

    CN111600772A

  • CDN resource banning method and device, electronic equipment and storage medium

    CN114070652A