Control strategy implementation method, storage medium and computer program product
By sending preset attribute fill policy in the access layer and extracting the fill attributes in the service request, and matching them with the flow control and black-and-white list policies, the problem of insufficient support for new attributes and business needs in the existing technology is solved, and the system flexibility and scalability are improved.
Patent Information
- Application Number
- CN202510145776.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-13
AI Technical Summary
When implementing flow control and black-and-white list control, the existing technology is difficult to support new attributes and business requirements, resulting in low flexibility and scalability of the system.
By sending preset attribute fill policy to the client, receiving and extracting the fill attributes in the service request, and matching these attributes with the preset flow control and black-and-white list policies, it is determined whether the service request is restricted.
It realizes flexible support for new attributes and business needs, improves the universality, flexibility and scalability of the system, and reduces development and maintenance costs.
Smart Images

Figure CN119995989A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a control strategy implementation method, a storage medium, and a computer program product. Background Art
[0002] In existing network technologies, in order to protect background services from abuse and overload, flow control and blacklist and whitelist control are usually required. This involves configuring a series of policies, which may be based on attributes such as the name of the background service being accessed, the interface name, the client IP address, and the user account. These policies are sent down to the access layer, which performs flow control and blacklist and whitelist control based on these policies.
[0003] However, in actual applications, this implementation usually has some limitations. The access layer is often hard-coded and can only parse currently known common attributes, such as service name, interface name, user account, etc. When it is necessary to control new attributes such as transaction type, the access layer usually cannot support it directly and needs to be updated and upgraded to achieve it. In addition, some attributes may exist in business binary messages, and the access layer cannot recognize all business protocols, so it cannot parse these attributes for matching flow control / blacklist and whitelist policies.
[0004] Due to these limitations, existing implementation methods are usually strongly bound to specific business logic, resulting in different business systems having to implement their own set of flow control and blacklist and whitelist control logic. This not only increases the cost of development and maintenance, but also reduces the flexibility and scalability of the system. Summary of the invention
[0005] The main purpose of this application is to provide a control strategy implementation method, storage medium and computer program product, aiming to solve the technical problems of low versatility, flexibility and scalability of flow control and black and white list control of business requests with new attributes.
[0006] To achieve the above objectives, the present application proposes a control strategy implementation method, which is applied to the access layer, and the method includes:
[0007] Send the preset attribute filling strategy to the client;
[0008] Receiving a service request obtained by a client based on the preset attribute filling strategy, and extracting the filling attributes of the client from the message of the service request;
[0009] Based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies, it is determined whether to restrict the service request.
[0010] Preferably, before the step of sending the preset attribute filling strategy to the client, the step includes:
[0011] Defining attribute population policies in the policy management system user interface;
[0012] Verify the validity and correctness of the attribute filling strategy;
[0013] The attribute filling policy that has passed the verification is saved in the policy management system;
[0014] Activate or set specific conditions to activate the saved attribute population strategy.
[0015] Preferably, before the step of sending the preset attribute filling strategy to the client, the step further includes:
[0016] A query request for a preset attribute filling strategy from a client based on an API interface is received, and the query request is parsed to obtain the filling attributes required by the client.
[0017] Preferably, the step of obtaining the service request by the client based on the preset attribute filling strategy includes:
[0018] Extracting required attributes from the service request based on the preset attribute filling strategy;
[0019] Fill the required attributes into the message header or metadata of the service request to obtain the service request after the attributes are filled.
[0020] Preferably, the step of extracting the client's fill attribute from the service request message includes:
[0021] Receive the attribute-filled service request sent by the client, and perform message parsing on the service request to extract the filled attributes of the client, wherein the message parsing at least includes parsing the protocol type of the message, parsing the message in text format, and parsing the message in binary format.
[0022] Preferably, the step of determining whether to restrict the service request based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies includes:
[0023] Query the preset flow control and blacklist and whitelist policies stored locally in the policy management system;
[0024] Comparing the fill attributes with the conditions defined in the preset flow control and blacklist and whitelist policies;
[0025] Determining whether the service request matches the preset flow control and blacklist and whitelist policies according to the comparison result;
[0026] If the two match, the matching policy and related filling attributes are recorded, otherwise the service request continues to be processed.
[0027] Preferably, if the two match, the step of recording the matching policy and related filling attributes includes:
[0028] Evaluate whether the current flow in the relevant fill attribute exceeds the threshold defined in the flow control policy;
[0029] If the current flow exceeds the threshold, a flow control operation is performed to limit the service request; otherwise, the service request continues to be processed.
[0030] Preferably, if the two match, the step of recording the matching policy and related filling attributes also includes:
[0031] Detecting whether there is an entry matching the blacklist and whitelist policy in the relevant fill attributes;
[0032] If the service request matches an entry in the blacklist, the service request is rejected, otherwise further checking whether it matches an entry in the whitelist;
[0033] If the service request matches an entry in the whitelist, the service request is allowed to pass;
[0034] If the service request matches neither the blacklist nor the whitelist, the default policy is executed;
[0035] The default policy is to allow all service requests that are not explicitly denied.
[0036] In addition, to achieve the above purpose, the present application also proposes a control strategy implementation device, the control strategy implementation device comprising:
[0037] A policy delivery module is used to send the preset attribute filling policy to the client;
[0038] An attribute extraction module receives a service request obtained by a client based on the preset attribute filling strategy, and extracts the filling attributes of the client from the message of the service request;
[0039] The decision execution module is used to determine whether to restrict the service request based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist strategies.
[0040] In addition, to achieve the above-mentioned purpose, the present application also proposes a control strategy implementation device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program is configured to implement the steps of the control strategy implementation method described above.
[0041] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the control strategy implementation method described above are implemented.
[0042] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps of the control strategy implementation method described above are implemented.
[0043] One or more technical solutions proposed in this application have at least the following technical effects:
[0044] Send the preset attribute filling strategy to the client; receive the service request obtained by the client based on the preset attribute filling strategy, and extract the client's filling attributes from the message of the service request; based on the matching result of the filling attributes and the preset flow control and blacklist and whitelist strategies, determine whether to restrict the service request. This allows system administrators or operation and maintenance personnel to dynamically configure and update flow control and blacklist and whitelist strategies without modifying the access layer code, which improves system flexibility, reduces the complexity and hard coding of the access layer, reduces the cost of development and maintenance, can adapt to new attributes and business needs, and enhances system scalability. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0046] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0047] Figure 1 A flowchart of the first embodiment of the control strategy implementation method of the present application is provided;
[0048] Figure 2 A flow chart of the second embodiment of the control strategy implementation method of the present application is provided;
[0049] Figure 3 A flowchart of the third embodiment of the control strategy implementation method of the present application is provided;
[0050] Figure 4 A flowchart of the fourth embodiment of the control strategy implementation method of the present application is provided;
[0051] Figure 5 A schematic diagram provided for a specific embodiment of the control strategy implementation method of this application;
[0052] Figure 6 This is a schematic diagram of the module structure of the control strategy implementation device of the present application embodiment;
[0053] Figure 7 Schematic diagram of the device structure of the hardware operating environment involved in the control strategy implementation method in the embodiment of the present application.
[0054] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0055] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0056] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0057] In this embodiment, for ease of description, the following description is made with the access layer as the execution entity.
[0058] The existing technologies for flow control and blacklist and whitelist control of business requests with newly added attributes have low versatility, flexibility and scalability.
[0059] The present application provides a solution, which includes sending a preset attribute filling strategy to a client; receiving a service request obtained by the client based on the preset attribute filling strategy, and extracting the client's filling attributes from the message of the service request; judging whether to restrict the service request based on the matching result of the filling attributes with the preset flow control and black and white list strategies, so that the system does not need to pay attention to the protocol details of the service request and perform hard-coded updates and upgrades on the access layer, and realizes the matching control of service requests with any newly added attributes or attribute combinations with flow control and black and white list strategies, with strong versatility, flexibility and scalability.
[0060] Based on this, the present application embodiment provides a control strategy implementation method, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the control strategy implementation method of the present application.
[0061] In this embodiment, the control strategy implementation method is applied to the access layer, including steps S10 to S30:
[0062] Step S10: Sending a preset attribute filling strategy to the client;
[0063] It should be noted that the policy management system can provide an API interface to allow the client to query the currently effective flow control and blacklist and whitelist policies; the attribute filling policy can be stored in an accessible location, such as a policy management system, a configuration server, or a database, and the preset attribute filling policy may need to be updated periodically.
[0064] Step S20: receiving a service request obtained by the client based on the preset attribute filling strategy, and extracting the filling attributes of the client from the message of the service request;
[0065] It should be noted that the access layer can parse received business messages, such as HTTP headers, TCP or other network protocols, and binary message formats; extract attributes filled in by the client according to preset policies from the parsed messages, which may include service name, interface name, user account, client IP, transaction type, etc.; verify the received attributes to ensure that the received attributes meet the preset policy requirements; store the extracted filled attributes in memory or database for subsequent use.
[0066] Step S30: Based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies, determine whether to restrict the service request.
[0067] It should be noted that the access layer matches the extracted fill attributes with the flow control and blacklist and whitelist policies stored locally, which includes at least simple string comparison, regular expression matching or more complex logic; based on the matching results, the access layer determines whether the service request requires flow control and blacklist and whitelist control; if the access layer is deployed in a distributed manner, it involves distributed policy management and synchronization technology to ensure that all access layer nodes use the same policy.
[0068] This embodiment sends a preset attribute filling strategy to the client; receives a service request obtained by the client based on the preset attribute filling strategy, and extracts the client's filling attributes from the message of the service request; and determines whether to restrict the service request based on the matching result between the filling attributes and the preset flow control and blacklist and whitelist strategies. This allows system administrators or operation and maintenance personnel to dynamically configure and update flow control and blacklist and whitelist strategies without modifying the access layer code, thereby improving system flexibility, reducing the complexity and hard coding of the access layer, reducing development and maintenance costs, being able to adapt to newly added attributes and business requirements, and enhancing system scalability.
[0069] Further, refer to Figure 2 The second embodiment of the control strategy implementation method of this application provides a flow chart based on the above Figure 2The example diagram shown further refines the step of "sending the preset attribute filling policy to the client" in step S10, including steps A201 to A204:
[0070] Step A201: defining an attribute filling policy in the user interface of the policy management system;
[0071] It should be noted that, in addition to the existing attributes of the policy management system, the defined attribute filling strategy can also define new attributes that need to be filled in the user interface, including setting the value of the attribute or extracting rules.
[0072] Step A202: Verify the validity and correctness of the attribute filling strategy;
[0073] It should be noted that the policy management system can provide verification functions, including checking the policy syntax, the format of attribute values, and the consistency of policy logic.
[0074] Step A203: saving the attribute filling policy that has passed the verification in the policy management system;
[0075] It should be noted that when the attribute filling policy that has passed the verification is saved in the policy management system, the policy data is written into a database, a configuration file or a dedicated policy storage.
[0076] Step A204: Activate or set specific conditions to activate the saved attribute filling strategy.
[0077] It should be noted that the policy management system can realize activation or specific conditional activation of the saved attribute filling policy by setting the activation time, traffic threshold, specific time trigger, etc.
[0078] Specifically, in a flow control and blacklist and whitelist control based on the HTTP protocol, the administrator defines the attribute filling strategy in the user interface of the policy management system, such as defining the blacklist and whitelist rules for specific service names and interface names, and the flow control threshold for specific client IPs. After the definition is completed, verification can be performed, such as checking the policy syntax, the format of specific service names, interface names and client IPs, etc. The attribute filling strategy that passes the verification is saved to the policy management system, and the strategy is activated by setting a specific traffic threshold. At this time, the policy management system sends the configured strategy to the client and access layer through the API interface. According to the sent strategy, the client fills the attributes in the business request into the header of the HTTP request, such as filling the attributes such as the service name, interface name, user account, transaction type, and request rate into the custom field of the HTTP header. The access layer receives the HTTP request sent by the client, parses the HTTP header and request body, and extracts the attributes filled by the client.
[0079] In this embodiment, the administrator can flexibly define, verify, save and activate attribute filling policies, and the client can dynamically obtain and apply these policies, thereby achieving flexible management of flow control and blacklist and whitelist control.
[0080] Furthermore, before the step of sending the preset attribute filling strategy to the client, the step further includes:
[0081] A query request for a preset attribute filling strategy from a client based on an API interface is received, and the query request is parsed to obtain the filling attributes required by the client.
[0082] It should be noted that the policy management system receives an API request from the client, which is intended to query the latest attribute filling policy; the system parses the API request and extracts request parameters, such as client ID, version number, etc.; in addition, in addition to the API interface, the preset attribute filling policy can also be queried through configuration files, database queries, Web services, real-time push, etc.; the policy management system retrieves the corresponding attribute filling policy from the storage according to the request parameters in the client, formats the retrieved policy into a format that the client can understand and apply, and sends the formatted attribute filling policy to the client through the API interface.
[0083] In one embodiment, referring to Figure 3 The third embodiment of the control strategy implementation method of this application provides a flow chart based on the above Figure 3 The example diagram shown further refines the step of "the client obtains a service request based on the preset attribute filling strategy" in step S20, including steps A301 to A302:
[0084] Step A301: extracting required attributes from the service request based on the preset attribute filling strategy;
[0085] It should be noted that the client extracts the required attributes from the business request according to the preset attribute filling strategy, and can verify the extracted attributes to ensure that they meet the preset policy requirements, including checking the existence of the attributes, the correctness of the format, the validity of the value, etc.
[0086] Step A302: Fill the required attributes into the message header or metadata of the service request to obtain the service request with the attributes filled in.
[0087] The client fills the extracted attributes into the message header or metadata of the business request, including modifying the HTTP header message, adding JSON or XML fields, updating the binary message format, etc. The client constructs a complete business request message, including the original request content and the newly filled attributes.
[0088] Furthermore, the step of extracting the client's fill attribute from the service request message includes:
[0089] Receive the attribute-filled service request sent by the client, and perform message parsing on the service request to extract the filled attributes of the client, wherein the message parsing at least includes parsing the protocol type of the message, parsing the message in text format, and parsing the message in binary format.
[0090] It should be noted that when the access layer parses the business request, it first identifies the protocol type of the request, such as HTTP, TCP, UDP, WebScoket, etc.; when the request is in text format, such as HTTP request, the access layer parses the HTTP header, request body, etc., and extracts the attributes filled in by the client; when the request is in binary format, the access layer parses the binary data according to the predefined message format and extracts the attributes filled in by the client; extracts the attributes filled in by the client from the parsed message, which may include service name, interface name, user account, client IP, transaction type, etc., and verifies the received attributes.
[0091] In one embodiment, referring to Figure 4 The fourth embodiment of the control strategy implementation method of this application provides a flow chart based on the above Figure 4 The example diagram shown further refines the step of "determining whether to restrict the service request based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies" in step S30, including steps A401 to A404:
[0092] Step A401: query the preset flow control and blacklist and whitelist policies stored locally in the policy management system;
[0093] It should be noted that the preset strategy can be stored in memory, database or configuration file.
[0094] Step A402: Compare the fill attribute with the conditions defined in the preset flow control and blacklist and whitelist policies;
[0095] The access layer compares the extracted attributes with the conditions defined in the policy, including string matching, regular expression matching, etc.
[0096] Step A403: determining whether the service request matches the preset flow control and blacklist and whitelist policies according to the comparison result;
[0097] The access layer determines whether the request matches any policy and, if so, logs the matching policy and related information.
[0098] Step A404: If the two match, the matching policy and related filling attributes are recorded, otherwise the service request continues to be processed.
[0099] If the request matches the policy, the access layer performs corresponding control measures, such as limiting the flow, rejecting the request, etc. If the request does not match any policy, the request continues to run.
[0100] In this embodiment, the access layer can perform effective flow control on the service request according to the preset flow control and blacklist and whitelist strategies.
[0101] Furthermore, if the two match, the step of recording the matching policy and related filling attributes includes:
[0102] Evaluate whether the current flow in the relevant fill attribute exceeds the threshold defined in the flow control policy;
[0103] If the current flow exceeds the threshold, a flow control operation is performed to limit the service request; otherwise, the service request continues to be processed.
[0104] It should be noted that the access layer evaluates whether the current traffic exceeds the threshold defined in the flow control policy, which involves calculating the request rate, number of concurrent connections, etc. If the current traffic exceeds the threshold, the access layer performs flow control operations, such as delaying the processing of requests, discarding requests, or returning error responses. If the current traffic does not exceed the threshold, or the flow control operation has been completed, the access layer allows the request to continue to other parts of the system.
[0105] Furthermore, if the two match, the step of recording the matching policy and related filling attributes also includes:
[0106] Detecting whether there is an entry matching the blacklist and whitelist policy in the relevant fill attributes;
[0107] If the service request matches an entry in the blacklist, the service request is rejected, otherwise further checking whether it matches an entry in the whitelist;
[0108] If the service request matches an entry in the whitelist, the service request is allowed to pass;
[0109] If the service request matches neither the blacklist nor the whitelist, the default policy is executed;
[0110] The default policy is to allow all service requests that are not explicitly denied.
[0111] Specifically, the access layer can detect whether the extracted attributes match the entries in the blacklist and whitelist policies by string comparison, regular expression matching, etc. If the request matches an entry in the blacklist, the access layer rejects the request and records the corresponding rejection operation; if the request does not match an entry in the blacklist, the access layer continues to check whether the request matches an entry in the whitelist; if the request matches an entry in the whitelist, the access layer runs the request through and records the corresponding permission operation; if the request matches neither the blacklist nor the whitelist, the access layer executes the default policy, which usually allows service requests that are not explicitly rejected. The access layer can effectively control access to service requests based on the preset blacklist and whitelist policies.
[0112] In one embodiment, the configuration example is:
[0113] {"policy":"trading_type=query&trading_stock_code=60006","qps":100},
[0114] The access layer configures a flow control policy to limit the transaction type to query and the request with transaction code 60006 to 100QPS.
[0115] In addition, the configuration sample for the configuration attribute filling strategy is:
[0116]
[0117] The message protocol is in json format, and the type and stock_code attributes under the trading_info object in the json message are filled into the trading_type and trading_stock_code attributes in the message header respectively. Figure 5 As shown, the specific steps of the control strategy implementation method include:
[0118] Step P1: The client queries the access layer for attribute filling policy;
[0119] Step P2: The client sends a business request, and fills the trading_type and trading_stock_code attributes in the header of each business request according to the filling strategy;
[0120] Step P3: The access layer directly obtains the attributes filled in by the client in the message header to match the flow control and blacklist and whitelist policies. If the trading_type attribute is "query" and the trading_stock_code attribute is 60006, the request rate is limited to no more than 100QPS, otherwise there is no limit.
[0121] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the implementation method of the control strategy of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.
[0122] In addition, this application also provides a control strategy implementation device, please refer to Figure 6 , the control strategy implementation device comprises:
[0123] The policy sending module 10 is used to send the preset attribute filling policy to the client;
[0124] The attribute extraction module 20 receives a service request obtained by the client based on the preset attribute filling strategy, and extracts the filling attributes of the client from the message of the service request;
[0125] The decision execution module 30 is used to determine whether to restrict the service request based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies.
[0126] The control strategy implementation device provided by the present application adopts the control strategy implementation method in the above-mentioned embodiment, which can solve the technical problems of low versatility, flexibility and scalability of flow control and blacklist and whitelist control for service requests with newly added attributes. Compared with the prior art, the beneficial effects of the control strategy implementation device provided by the present application are the same as the beneficial effects of the control strategy implementation method provided by the above-mentioned embodiment, and the other technical features in the control strategy implementation device are the same as the features disclosed in the above-mentioned embodiment method, which will not be repeated here.
[0127] In addition, the present application provides a control strategy implementation device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the control strategy implementation method in the above-mentioned embodiment one.
[0128] Reference below Figure 7 , which shows a schematic diagram of the structure of a control strategy implementation device suitable for implementing the embodiment of the present application. The control strategy implementation device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The control strategy implementation device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0129] like Figure 7 As shown, the control strategy implementation device may include a processing device 1001 (e.g., a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 to a random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the control strategy implementation device are also stored. The processing device 1001, ROM1002, and RAM1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the control strategy implementation device to communicate wirelessly or wired with other devices to exchange data. Although the control strategy implementation device with various systems is shown in the figure, it should be understood that it is not required to be in real time or have all the systems shown. More or fewer systems can be implemented or provided instead.
[0130] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0131] The control strategy implementation device provided by the present application adopts the control strategy implementation method in the above embodiment, which can solve the technical problems of low versatility, flexibility and scalability of flow control and blacklist and whitelist control for business requests with newly added attributes. Compared with the prior art, the beneficial effects of the control strategy implementation device provided by the present application are the same as the beneficial effects of the control strategy implementation method provided by the above embodiment, and the other technical features in the control strategy implementation device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0132] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0133] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0134] In addition, the present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the control strategy implementation method in the above-mentioned embodiment.
[0135] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0136] The computer-readable storage medium may be included in the control strategy implementation device; or may exist independently without being assembled into the control strategy implementation device.
[0137] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the control policy implementation device, the control policy implementation device: sends a preset attribute filling strategy to the client; receives a service request obtained by the client based on the preset attribute filling strategy, and extracts the client's filling attributes from the message of the service request; based on the matching result of the filling attributes with the preset flow control and black and white list strategies, determines whether to restrict the service request.
[0138] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0139] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0140] The modules involved in the embodiments described in the present application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0141] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned control strategy implementation method, and can solve the technical problems of low versatility, flexibility, and scalability of flow control and blacklist and whitelist control of service requests with newly added attributes. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the control strategy implementation method provided by the above-mentioned embodiment, and will not be elaborated here.
[0142] In addition, the present application also provides a computer program product, including a computer program, which implements the steps of the control strategy implementation method as described above when executed by a processor.
[0143] The computer program product provided by the present application can solve the technical problems of low versatility, flexibility and scalability of flow control and blacklist and whitelist control of service requests with newly added attributes. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as the beneficial effects of the control strategy implementation method provided by the above embodiment, which will not be elaborated here.
[0144] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A control strategy implementation method, characterized in that: Applied to the access layer, the method comprises: Send the preset attribute filling strategy to the client; Receiving a service request obtained by a client based on the preset attribute filling strategy, and extracting the filling attributes of the client from the message of the service request; Based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies, it is determined whether to restrict the service request.
2. The method according to claim 1, characterized in that The step of sending the preset attribute filling strategy to the client includes: Defining attribute population policies in the policy management system user interface; Verify the validity and correctness of the attribute filling strategy; The attribute filling policy that has passed the verification is saved in the policy management system; Activate or set specific conditions to activate the saved attribute population strategy.
3. The method according to claim 2, characterized in that Before the step of sending the preset attribute filling strategy to the client, the method further includes: A query request for a preset attribute filling strategy from a client based on an API interface is received, and the query request is parsed to obtain the filling attributes required by the client.
4. The method according to claim 3, characterized in that The step of obtaining the service request by the client based on the preset attribute filling strategy includes: Extracting required attributes from the service request based on the preset attribute filling strategy; Fill the required attributes into the message header or metadata of the service request to obtain the service request after the attributes are filled.
5. The method according to claim 4, characterized in that The step of extracting the client's fill attribute from the service request message comprises: Receive a service request with attributes filled in from a client, parse the service request, and extract the filled attributes of the client. The message parsing includes at least parsing the protocol type of the message, parsing the message in text format, and parsing the message in binary format.
6. The method according to claim 5, characterized in that The step of determining whether to restrict the service request based on the matching result between the filling attribute and the preset flow control and blacklist and whitelist policies comprises: Query the preset flow control and blacklist and whitelist policies stored locally in the policy management system; Comparing the fill attributes with the conditions defined in the preset flow control and blacklist and whitelist policies; Determine whether the service request matches the preset flow control and blacklist and whitelist policies according to the comparison result; If the two match, the matching policy and related filling attributes are recorded, otherwise the service request continues to be processed.
7. The method according to claim 6, characterized in that If the two match, the step of recording the matching policy and related filling attributes includes: Evaluate whether the current flow in the relevant fill attribute exceeds the threshold defined in the flow control policy; If the current flow exceeds the threshold, a flow control operation is performed to limit the service request; otherwise, the service request continues to be processed.
8. The method according to claim 6, characterized in that If the two match, the step of recording the matching policy and related filling attributes also includes: Detecting whether there is an entry matching the blacklist and whitelist policy in the relevant fill attributes; If the service request matches an entry in the blacklist, the service request is rejected, otherwise further checking whether it matches an entry in the whitelist; If the service request matches an entry in the whitelist, the service request is allowed to pass; If the service request matches neither the blacklist nor the whitelist, the default policy is executed; The default policy is to allow all service requests that are not explicitly denied.
9. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the control strategy implementation method according to any one of claims 1 to 8 are implemented.
10. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the control strategy implementation method according to any one of claims 1 to 8 are implemented.