Resource access control method, system and device and storage medium
Patent Information
- Application Number
- CN202510151524.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-30
Smart Images

Figure CN120067481A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and specifically relates to a resource access control method, system, device, and storage medium. Background Art
[0002] In an Internet content platform, picture resources must pass content compliance reviews before they can be displayed in an application. However, currently, some non-compliant picture resources are often identified and blocked only after being reported by users. These resources may have been saved as links by external users or cached by a content delivery network (CDN). Therefore, even if the resources are blocked, the non-compliant content can still be accessed through these saved links or caches, which causes serious content compliance and security problems.
[0003] Currently, the common practice in the industry is to clear the CDN resource cache or delete non-compliant pictures.
[0004] For the method of clearing the CDN resource cache, it has the disadvantage of weak reliability in resource blocking. Due to the complexity of the CDN architecture and the fact that most CDN services are provided by third parties, problems such as third-party interface compatibility or cache synchronization delays are often encountered when clearing the cache, which may result in incomplete cache clearing and thus lead to the leakage of blocked data.
[0005] For the method of deleting non-compliant pictures, it has the disadvantage of being irrecoverable after deletion. Using the physical deletion method will cause the resources to be unable to be restored in the business process once they are deleted. This means that once the resources are prohibited, users cannot apply for restoration and must re-upload the resources, which increases the operation burden on users and may affect the user experience. Summary of the Invention
[0006] To solve the above technical problems, the present invention provides a resource access control method, system, device, and storage medium, which perform audits on access requests by configuring a request audit service on the CDN side to ensure that blocked resources cannot be accessed.
[0007] In a first aspect, the present invention provides a resource access control method, which includes:
[0008] Receiving an access request for accessing a resource sent to the CDN, where the access request includes resource identification information;
[0009] Invoking an audit service according to the access request to query whether the requested resource is allowed to be accessed;
[0010] The CDN responds to the access request according to the query result.
[0011] Optionally, calling an audit service according to the access request to query whether the requested resource is allowed to be accessed includes:
[0012] The CDN calls an audit service according to the access request;
[0013] The audit service obtains the resource identification information of the access request, queries the resource ban set of prohibited access, and returns the query result to the CDN.
[0014] Optionally, the resource ban set is stored in a Redis database.
[0015] In a second aspect, the present invention provides a resource access control system, and the system includes:
[0016] A receiving module, configured to receive an access request for requesting access to a resource from the CDN, where the access request includes resource identification information;
[0017] An audit module, configured to call an audit service according to the access request to query whether the requested resource is allowed to be accessed;
[0018] A response module, configured to enable the CDN to respond to the access request according to the query result.
[0019] Optionally, the audit module includes:
[0020] A calling sub-module, configured to enable the CDN to call an audit service according to the access request;
[0021] A query sub-module, configured to enable the audit service to obtain the resource identification information of the access request, query the resource ban set of prohibited access, and return the query result to the CDN.
[0022] Optionally, the resource ban set is stored in a Redis database.
[0023] In a third aspect, the present invention provides an electronic device, and the electronic device includes:
[0024] At least one processor; and
[0025] A memory communicatively connected to the at least one processor; wherein,
[0026] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the above-mentioned resource access control method.
[0027] In a fourth aspect, the present invention provides a computer-readable storage medium, and the computer-readable storage medium stores computer instructions, and when the computer instructions are executed by a processor, the above-mentioned resource access control method is implemented.
[0028] The following beneficial effects can be achieved in this embodiment:
[0029] In this embodiment, each access request of the user is returned after passing through the CDN request review service, ensuring that the resource obtains the latest query (verification) result and guaranteeing that the blocked resources are not leaked. This method is transparent to the service and does not require any modification to the place where the resource is requested, which is very friendly to scenarios with a large number of resource entrances. Since this method blocks non-physical deletion through the identification of the data status, when the review results in a wrong block, the user can choose to appeal or other means to unblock the resource again.
[0030] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0032] Figure 1 is a flowchart of the resource access control method provided in Embodiment 1 of the present invention;
[0033] Figure 2 is a timing example diagram of the resource access control process provided in Embodiment 1 of the present invention;
[0034] Figure 3 is a schematic structural diagram of the resource access control system provided in Embodiment 2 of the present invention;
[0035] Figure 4 is a schematic structural diagram of the electronic device provided in Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0036] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0037] Refer to Figure 1The flowchart of the resource access control method provided in the first embodiment of the present invention. This embodiment can be applied to a resource access control system, such as Figure 1 As shown, this embodiment may include the following steps:
[0038] Step 101, receive an access request for accessing a resource sent to the CDN. The access request contains resource identification information.
[0039] CDN (Content Delivery Network) is a network composed of globally distributed server nodes. By caching content to nodes closer to users, it realizes fast and secure content distribution. Its core functions are: 1. Accelerate access, reduce the physical distance between users and the origin server, and reduce latency. 2. Load balancing, disperse traffic pressure, and avoid overloading of the origin server. 3. Security protection, resist threats such as DDoS attacks, hotlinking, and malicious crawlers.
[0040] When a user sends an access request for accessing a resource to the CDN through a terminal device, such as a mobile phone, tablet computer, laptop, mobile Internet device, etc., the local DNS server will resolve the domain name of the URL carried in the access request and direct the user's access request to the CDN node closest to the geographical location of the user's terminal device. The CDN node closest to the geographical location of the user's terminal device receives the access request.
[0041] The access request contains resource identification information. The resource identification information is a unique identifier, such as a resource ID, used to distinguish and manage resources to ensure that each resource can be accurately identified and traced. The resource requested to be accessed can be a picture, video, audio, HTML file, etc.
[0042] Step 102, call the audit service according to the access request to query whether the requested resource is allowed to be accessed.
[0043] When the access request reaches the CDN node, the CDN first calls the audit service according to the access request, forwards the access request to the audit service, and decides whether to return the resource to the user only after being judged by the audit service.
[0044] After the review service receives an access request, it obtains the resource identification information of the access request, queries the resource ban set of prohibited access, and returns the query result to the CDN. For example, after the review service obtains the URI in the access request of the CDN, such as / xxx / xxx / 2733796280377538332.jpg, it intercepts the resource ID part 2733796280377538332, and then queries the BLOCKED_SET set. If the resource ID exists in the BLOCKED_SET set, it means the resource is banned, and it returns the status code 403, HTTP content: 403. Otherwise, it returns the status code 200, HTTP content: 200.
[0045] The resource ban set can be generated / updated in the following way: Artificial intelligence and / or reviewers review the resources. If the resources are non-compliant, the resources are banned, and the resource identification information is stored in the resource ban set of prohibited access. For example, if the picture resources uploaded by the user are non-compliant, the reviewer bans the picture through the review background, and the review background stores the resource ID in the redis database that stores the resource ban set. If the ID of the picture is 2733796280377538332, the review background writes this ID into the BLOCKED_SET set. If the user applies to lift the ban on the resource through means such as appeal, after the reviewer verifies the situation and it is true, the reviewer can lift the ban on the resource through the review background, and the review background deletes the corresponding resource ID in the BLOCKED_SET set.
[0046] Step 103, the CDN responds to the access request according to the query result.
[0047] After the review service confirms that the resource is accessible, if the CDN has cached the resource requested for access, it directly returns it to the user. If not, the CDN node fetches the resource from the origin server, returns it to the user, and caches it.
[0048] Now refer to Figure 2 , and describe in detail the interaction process among the various participants in resource access control in the form of a sequence diagram.
[0049] First, the user can send an access request to access the resource to the CDN through the browser of the terminal device.
[0050] Then, the CDN node closest to the user's terminal device geographically receives the access request and forwards the access request to an independent review server. Setting up an independent review server is applicable to scenarios with complex logic that require accessing the database.
[0051] Subsequently, the review server queries whether the requested resource is allowed to be accessed. If the resource is valid and can be accessed, it returns 200 to the CDN node; if the resource is invalid and access is prohibited, it returns 403 to the CDN node.
[0052] Finally, the CDN node responds to the access request according to the query result. If the resource is allowed to be accessed and the CDN has cached the resource requested by the access request, it will be directly returned to the user. If the CDN has not cached it, the CDN will redirect to the resource server (i.e., the origin server) to pull the resource and return it to the user. If the resource is prohibited from being accessed, the CDN will return the message "Resource cannot be accessed" to the user.
[0053] In this embodiment, each access request of the user goes through the CDN request review service and then returns, ensuring that the resource obtains the latest query (verification) result and ensuring that the blocked resources are not leaked. This method is transparent to the service and does not require any changes to the places where resources are requested, which is very friendly to scenarios with many resource entrances. Since this method blocks non-physical deletions through the identification of the data status, when the review is mis-blocked, the user can choose to appeal or other methods to unblock the resource again.
[0054] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0055] Corresponding to the resource access control method in the present invention, the present invention also provides a resource access control system. Figure 3 It is a schematic structural diagram of the resource access control system provided in the second embodiment of the present invention. As Figure 3 shown, the resource access control system includes:
[0056] A receiving module 201, configured to receive an access request for accessing a resource from the CDN, where the access request includes resource identification information;
[0057] An auditing module 202, configured to call an auditing service according to the access request to query whether the requested resource is allowed to be accessed;
[0058] A response module 203, configured to enable the CDN to respond to the access request according to the query result.
[0059] In one embodiment, the auditing module 202 includes:
[0060] A calling sub-module, configured to enable the CDN to call an auditing service according to the access request;
[0061] A querying sub-module, configured to obtain the resource identification information of the access request by the auditing service, query the resource blocking set of prohibited access, and return the query result to the CDN.
[0062] In one embodiment, the resource blocking set is stored in a Redis database.
[0063] A resource access control system provided by an embodiment of the present invention can execute a resource access control method provided by any embodiment of the present invention, and has function modules and beneficial effects corresponding to the execution of the method.
[0064] Figure 4 FIG. shows a schematic structural diagram of an electronic device 30 that can be used to implement an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, a personal digital processor, a cellular phone, a smart phone, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0065] As Figure 4 shown, the electronic device 30 includes at least one processor 31, and a memory communicatively connected to the at least one processor 31, such as a read-only memory (ROM) 32, a random access memory (RAM) 33, etc. The memory stores a computer program executable by the at least one processor. The processor 31 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 32 or the computer program loaded from the storage unit 38 into the random access memory (RAM) 33. In the RAM 33, various programs and data required for the operation of the electronic device 30 can also be stored. The processor 31, the ROM 32, and the RAM 33 are connected to each other through a bus 34. The input / output (I / O) interface 35 is also connected to the bus 34.
[0066] Multiple components in the electronic device 30 are connected to the I / O interface 35, including: an input unit 36, such as a keyboard, a mouse, etc.; an output unit 37, such as various types of displays, speakers, etc.; a storage unit 38, such as a magnetic disk, an optical disk, etc.; and a communication unit 39, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 39 allows the electronic device 30 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0067] The processor 31 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 31 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 31 executes the various methods and processes described above, such as the resource access control method.
[0068] In some embodiments, the resource access control method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 38. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 30 via the ROM 32 and / or the communication unit 39. When the computer program is loaded into the RAM 33 and executed by the processor 31, one or more steps of the resource access control method described above can be executed. Alternatively, in other embodiments, the processor 31 can be configured to execute the resource access control method by any other suitable means (e.g., by means of firmware).
[0069] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-a-chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor, that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0070] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0071] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0072] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0073] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0074] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0075] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.
[0076] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A resource access control method, characterized in that: The method comprises: Receiving an access request to a CDN for accessing a resource, wherein the access request includes resource identification information; Call the audit service based on the access request to check whether the requested resource is allowed to be accessed; CDN responds to the access request based on the query results.
2. The method according to claim 1, characterized in that The invoking of the audit service according to the access request to query whether the requested resource is allowed to be accessed includes: CDN calls the audit service based on the access request; The audit service obtains the resource identification information of the access request, queries the prohibited resource block set, and returns the query result to the CDN.
3. The method according to claim 2, characterized in that: The resource ban set is stored in the Redis database.
4. A resource access control system, characterized in that: The system comprises: A receiving module, configured to receive an access request from a CDN for accessing a resource, wherein the access request includes resource identification information; The audit module is used to call the audit service according to the access request to query whether the requested resource is allowed to be accessed; The response module is used to enable the CDN to respond to the access request according to the query result.
5. The system according to claim 4, characterized in that The audit module includes: The calling submodule is used to enable the CDN to call the audit service according to the access request; The query submodule is used to review the resource identification information of the service access request, query the resource block set that is prohibited from access, and return the query results to the CDN.
6. The system according to claim 5, characterized in that: The resource ban set is stored in the Redis database.
7. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the resource access control method described in any one of claims 1 to 3.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the resource access control method according to any one of claims 1 to 3 when executed.