Network traffic processing method and device

By designing a data structure with triple information as the key and application information as the value in the SDP gateway, the problem of low permission verification efficiency caused by triple information corresponding to multiple applications is solved, and efficient permission verification and correct permission matching is achieved.

CN120223364APending Publication Date: 2025-06-27NEW H3C SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510275641.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

In the SDP gateway, there are situations where triples correspond to multiple applications, resulting in low permission verification efficiency, and it is difficult to improve efficiency while ensuring the correct permission matching.

Method used

A first data structure with triple information as the key and application information as the value is designed. By querying the data structure, the target application associated with the target triple is quickly determined, and the permission checksum processing operations are performed in combination with the access permission policy issued by the SDP controller.

Benefits of technology

It significantly improves the query efficiency of permission verification, ensures the correctness of permission matching, and improves the forwarding performance of the device's zero-trust function.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223364A_ABST
    Figure CN120223364A_ABST
Patent Text Reader

Abstract

The invention provides a network flow processing method and device. The method comprises the following steps: determining a target triple of access traffic flowing through an SDP gateway; a target application associated with the target triad is determined by querying a first data structure, a key of the first data structure is a triad, and a value is an application identifier associated with the triad; querying an access permission policy issued by the SDP controller, and determining the access permission of the current user to the target application; and executing a processing operation corresponding to the access permission on the access traffic. According to the method, the first data structure with the triple information as a key and the application information as a value is designed, the application associated with the target triple is queried from the first data structure under the condition that the application triple is overlapped, the query efficiency is remarkably improved on the premise of ensuring correct permission verification, and the forwarding performance of the zero-trust function of the equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a network traffic processing method and apparatus. Background Art

[0002] In the SDP (Software Defined Perimeter) solution, the SDP gateway is responsible for performing permission verification on the access traffic of users. Specifically, the SDP gateway determines the target application that the user wants to access according to the triple of the access traffic, and then determines whether the user has the access permission to the target application. In practical applications, there is a situation where one triple corresponds to multiple applications. In this case, how to improve the permission verification efficiency while ensuring correct permission matching is the key research direction in this field. Summary of the Invention

[0003] To overcome the problems existing in the related technologies, this application provides a network traffic processing method and apparatus.

[0004] According to the first aspect of the embodiments of this application, a network traffic processing method is provided. The method is applied to an SDP gateway, and the method includes:

[0005] Determine the target triple of the access traffic flowing through the SDP gateway, where the target triple includes a protocol type, an IP, and a port;

[0006] Determine the target application associated with the target triple by querying a first data structure, where the key of the first data structure is a triple, and the value of the first data structure is an application identifier associated with the triple;

[0007] Query the access permission policy issued by the SDP controller to determine the access permission of the current user to the target application;

[0008] Perform a processing operation corresponding to the access permission on the access traffic.

[0009] According to the second aspect of the embodiments of this application, a network traffic processing apparatus is provided. The apparatus is applied to an SDP gateway, and the apparatus includes:

[0010] A triple determination module, configured to determine the target triple of the access traffic flowing through the SDP gateway, where the target triple includes a protocol type, an IP, and a port;

[0011] A query module, configured to determine the target application associated with the target triple by querying a first data structure, where the key of the first data structure is a triple, and the value of the first data structure is an application identifier associated with the triple;

[0012] A permission determination module, configured to query the access permission policy sent by the SDP controller and determine the access permission of the current user to the target application;

[0013] A processing module, configured to perform a processing operation corresponding to the access permission on the access traffic.

[0014] According to a third aspect of the embodiments of the present application, there is provided an electronic device, including:

[0015] A memory and one or more processors; the memory is coupled to the processor; wherein, computer program code is stored in the memory, and the computer program code includes computer instructions. When the computer instructions are executed by the processor, the electronic device executes the method as described above.

[0016] According to a fourth aspect of the embodiments of the present application, there is provided a computer-readable storage medium, including computer instructions. When the computer instructions are run on an electronic device, the electronic device is caused to execute the method as described above.

[0017] According to a fifth aspect of the embodiments of the present application, there is provided a computer program product. When the computer program product is run on a computer, the computer is caused to execute the method as described above.

[0018] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:

[0019] In the network traffic processing method of the present application, a first data structure with triple information as the key and application information as the value is designed. In the case of overlapping application triples, the application associated with the triple of the access traffic is queried from the first data structure. Compared with other data structures, this data structure can significantly improve the query efficiency on the premise of ensuring correct permission verification and improve the forwarding performance of the zero-trust function of the device.

[0020] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings herein are incorporated into the specification and constitute a part of this application, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0022] Figure 1 It is a schematic flowchart of a network traffic processing method provided by an embodiment of the present application;

[0023] Figure 2 It is a schematic functional diagram of a network traffic processing device provided by an embodiment of the present application;

[0024] Figure 3 A schematic structural diagram of an electronic device provided by an embodiment of the present application. Specific implementation manners

[0025] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to limit the present application.

[0026] It should be noted that "at least one" in the present application means one or more, and "a plurality" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The terms "first", "second", "third", etc. (if any) in the specification, claims and drawings of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0027] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or more advantageous than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific manner.

[0028] The permission verification method of the SDP gateway is as follows: check the user's access request, extract the protocol type, IP, and port information therein (hereinafter referred to as the triple), query the target application that the user is accessing according to the triple, and then check whether the user has the access permission to the application.

[0029] For the case where the application triples do not overlap, the above method can find the correct application and perform permission matching. However, in most scenarios, often one triple can find multiple applications. If the permission is matched according to the first application found, it may lead to incorrect permission matching; if all applications that meet the triple are found and then the permission is matched, the efficiency is extremely low.

[0030] To solve the above problem of low efficiency, the current solution is: restrict the configuration of applications on the SDP controller to avoid the situation of application overlap. On the SDP gateway, after finding the first application, perform permission matching. If the permission cannot be matched, continue to search for other applications backward until the allowed permission is found or all applications are searched.

[0031] However, restricting application overlap on the SDP controller is complex, increasing the configuration difficulty and offering no experience at all. Additionally, there are practical usage scenarios for application overlap. For example, multiple applications (Application A, Application B) use the same Redis (Remote Dictionary Server) server. Therefore, when configuring applications on the SDP controller, multiple addresses will be configured for the two applications, and there is an overlapping part of the addresses (the address of the Redis server) between the two applications. Finally, for application triple overlap, the efficiency of searching for applications one by one and performing permission verification is unacceptable.

[0032] In view of the above problems, the present application provides a network traffic processing method and device.

[0033] Next, the embodiments of the present application will be described in detail.

[0034] An embodiment of the present application provides a network traffic processing method, which is applied to an SDP gateway, as Figure 1 shown. The method may include the following steps:

[0035] Step 110: Determine the target triple of the access traffic flowing through the SDP gateway, where the target triple includes the protocol type, IP, and port;

[0036] Step 120: Determine the target application associated with the target triple by querying the first data structure, where the key of the first data structure is the triple and the value is the application identifier associated with the triple;

[0037] Step 130: Query the access permission policy issued by the SDP controller to determine the access permission of the current user to the target application;

[0038] Step 140: Perform a processing operation corresponding to the access permission on the access traffic.

[0039] In this embodiment, the SDP controller is responsible for the management of application and user access permissions, dynamically generates permission access policies, and issues them to the SDP gateway; the SDP gateway, as an execution unit, performs permission verification on the user's access traffic based on the permission access policy issued by the SDP controller to achieve application-level access control.

[0040] In this embodiment, a first data structure is pre-created. The first data structure is used to record triples and the applications associated with the triples. Among them, the triple information (such as the hash value of the triple) serves as the key of the first data structure, and the application information (such as the application identifier) serves as the value of the first data structure. In the first data structure, the number of values corresponding to the same key is one or more.

[0041] Therefore, the number of target applications associated with the target triple obtained by querying the first data structure, that is, the applications that the user wants to access, may be one or more. Based on this first data structure with triple information as the key and application information as the value, this embodiment can quickly query the target application associated with the target triple. Compared with the traditional data structure with application information as the key and triple information as the value, this embodiment greatly improves the query efficiency.

[0042] In this embodiment, the access permission policy issued by the SDP controller records the authorized applications of the user, that is, which applications the user has access permissions to. By matching the target application with the authorized applications of the current user recorded in the access permission policy, the access permission of the current user to the target application can be determined, and then the processing operation corresponding to the access permission can be performed on the access traffic.

[0043] As a specific implementation manner, when selecting the hash value of the triple as the key of the first data structure, this embodiment specifically queries the first data structure in the following way: calculate the hash value of the target triple, use the hash value of the target triple as the query condition, and determine the target application associated with the target triple by querying the first data structure, where the key of the first data structure is the hash value of the triple, and the value of the first data structure is the application identifier associated with the triple.

[0044] As described above, the traditional data structure for recording the association relationship between triples and applications uses application information as the key and triple information as the value. For the convenience of description, this embodiment refers to this data structure as the second data structure.

[0045] As a specific implementation manner, the generation method of the first data structure may be: generated according to the query result of the second data structure. In practical applications, since the query efficiency of the first data structure is higher than that of the second data structure, the target triple is first queried from the first data structure. If it cannot be queried, then the second data structure is queried for the target triple, and if the target triple is queried in the second data structure, the first data structure also needs to be updated according to the query result.

[0046] Specifically, this embodiment specifically determines the target application associated with the target triple in the following way: determine whether the target triple exists in the first data structure; if the determination result is yes, determine the target application associated with the target triple in the first data structure; if the determination result is no, determine the target application associated with the target triple by querying the second data structure, and record the target triple and the application identifier of the target application into the first data structure. Wherein, the key of the second data structure is the application identifier, and the value of the second data structure is the triple associated with the application corresponding to the application identifier.

[0047] As a preferred embodiment, in this embodiment, the second data structure is queried specifically in the following manner: query the access permission policy issued by the SDP controller to determine the authorized applications of the current user; filter the second data structure using the application identifier of the authorized application as a screening condition, and determine the target application associated with the target triple by querying the filtered second data structure. In this way, the triple information of unauthorized applications in the second data structure is filtered out, thereby improving the efficiency of querying the application for the target triple.

[0048] Furthermore, in this embodiment, applications are classified according to the number of triples they are associated with. If an application is only associated with one triple, it is called a simple application. Conversely, if an application is associated with more than two triples, it is called a complex application (that is, for a complex application, there is no definite triple, and its IP address may be a network segment, an address + mask, multiple addresses, etc.). As a specific implementation manner, the second data structure in this embodiment is further divided into a simple application data structure and a complex application data structure, and simple applications and complex applications are recorded respectively through them. Among them, the key of the simple application data structure is the simple application identifier, and the value of the simple application data structure is the triple associated with the simple application corresponding to the simple application identifier. It can be understood that the number of triples associated with a simple application is one; the key of the complex application data structure is the complex application identifier, and the value of the complex application data structure is the triple associated with the complex application corresponding to the complex application identifier. It can be understood that the number of triples associated with a complex application is multiple.

[0049] Specifically, when it is determined that the target triple needs to be queried from the second data structure, the simple application data structure is queried first, and if it cannot be found, the complex application data structure is queried. Therefore, in this embodiment, the target application associated with the target triple is determined by querying the second data structure specifically in the following manner: determine the target application associated with the target triple by querying the simple application data structure; if the target triple cannot be found in the simple application data structure, determine the target application associated with the target triple by querying the complex application data structure.

[0050] Next, taking an actual application as an example, the network traffic processing method of this application will be described in detail. The steps include:

[0051] Step 1, the SDP controller performs repeated checks on simple applications;

[0052] Step 2: The SDP gateway receives the access permission policy issued by the SDP controller and stores simple applications and complex applications as two data structures. Simple data is stored in a HASH manner to obtain a simple application data structure; complex applications are stored in a HASH manner by application identifier, and the triple information of the application is stored in a RADIX tree within the application to obtain a complex application data structure;

[0053] Step 3: When the user's access request arrives at the SDP gateway, the SDP gateway first extracts the target triple; then it searches for the application in the simple application data structure through the target triple (the search is fast through HASH). If found, it matches the access permission policy. If the match is successful, the traffic is allowed to pass; if not, it proceeds to Step 4;

[0054] Step 4: Determine the user's authorized application list. For complex applications, search in the RADIX tree of the complex application data structure through the target triple until all are traversed. If found, match the access permission policy. If the match is successful, the traffic is allowed to pass;

[0055] Step 5: During the process of matching applications in Step 3 and Step 4, the applications that match are stored in the conflict HASH linked list in a HASH manner using the triple, and all application identifiers that can match this triple are stored in the conflict node to obtain the first data structure. For subsequent access requests, the SDP gateway first queries the conflict HASH linked list. If the conflict node exists, traverse the stored application IDs for permission matching. If the triple cannot be matched in the conflict HASH linked list, then go back to Step 1.

[0056] Example of simple application data structure:

[0057] Application ID = 1: Triple = https 1.1.1.1 443

[0058] Example of complex application data structure:

[0059] Application ID = 2: Triple = https 1.1.1.0 / 24 443

[0060] Application ID = 3: Triple = https 1.1.0.0 / 16 443

[0061] Application ID = 4: Triple = https 2.1.0.0 / 16 443

[0062] Application ID = 5: Triple = https 3.1.0.0 / 16 443

[0063] Example of the first data structure:

[0064] Triple information = https 1.1.1.1 443: Application identifiers = 1, 2, 3

[0065] Triple information = https 1.1.1.2 443: Application identifiers = 1, 2

[0066] Triple information = https 1.1.2.1 443: Application identifier = 1

[0067] Examples of access permission policies and target triples:

[0068] User a permission 2, 3 REQUEST https: / / 1.1.1.1

[0069] User b permission 4, 5, 6 REQUEST https: / / 2.1.1.1

[0070] User c permission 3, 5, 7 REQUEST https: / / 1.1.1.1

[0071] As can be seen from the above technical solutions, the network traffic processing method of the present application designs a first data structure with triple information as the key and application information as the value. In the case of overlapping application triples, the application associated with the triple of the access traffic is preferentially queried from the first data structure. Compared with other data structures, this data structure can improve the query efficiency, ensure the correct permission verification of the SDP gateway, and improve the forwarding performance of the zero-trust function of the device.

[0072] Based on the same inventive concept, the present application also provides a network traffic processing device, which is applied to an SDP gateway, and its structural schematic diagram is as Figure 2 shown, and specifically includes:

[0073] A triple determination module 210, configured to determine a target triple of access traffic flowing through the SDP gateway, where the target triple includes a protocol type, an IP, and a port;

[0074] A query module 220, configured to determine a target application associated with the target triple by querying a first data structure, where the key of the first data structure is a triple, and the value of the first data structure is an application identifier associated with the triple;

[0075] A permission determination module 230, configured to query an access permission policy issued by the SDP controller to determine the access permission of the current user to the target application;

[0076] A processing module 240, configured to perform a processing operation corresponding to the access permission on the access traffic.

[0077] As a specific implementation manner, the query module 220 specifically includes:

[0078] A judgment unit: configured to judge whether the target triple exists in the first data structure;

[0079] A first query unit, configured to, when the judgment result is yes, determine the target application associated with the target triple in the first data structure;

[0080] A second query unit, configured to, when the judgment result is no, determine the target application associated with the target triple by querying a second data structure, where the key of the second data structure is an application identifier, and the value of the second data structure is the triple associated with the application corresponding to the application identifier.

[0081] As a specific implementation manner, the second query unit specifically determines the target application associated with the target triple by querying the second data structure in the following manner:

[0082] Judge whether the target triple exists in the second data structure; if the judgment result is yes, determine the target application associated with the target triple in the second data structure, and record the target triple and the application identifier of the target application into the first data structure.

[0083] As a specific implementation manner, the second data structure includes a simple application data structure and a complex application data structure, and the second query unit specifically determines the target application associated with the target triple by querying the second data structure in the following manner:

[0084] Determine the target application associated with the target triple by querying the simple application data structure, where the key of the simple application data structure is a simple application identifier, the value of the simple application data structure is the triple associated with the simple application corresponding to the simple application identifier, and the number of triples associated with the simple application is one; if the target triple cannot be queried in the simple application data structure, determine the target application associated with the target triple by querying the complex application data structure, where the key of the complex application data structure is a complex application identifier, the value of the complex application data structure is the triple associated with the complex application corresponding to the complex application identifier, and the number of triples associated with the complex application is multiple.

[0085] As a specific implementation manner, the second query unit specifically queries the second data structure in the following manner:

[0086] Query the access permission policy issued by the SDP controller to determine the authorized applications of the current user; filter the second data structure using the application identifier of the authorized application as a filtering condition, and determine the target application associated with the target triple by querying the filtered second data structure.

[0087] As a specific implementation manner, the first query unit queries the first data structure in the following specific way:

[0088] Using the hash value of the target triple as a query condition, determine the target application associated with the target triple by querying the first data structure, where the key of the first data structure is the hash value of the triple, and the value of the first data structure is the application identifier associated with the triple.

[0089] As a specific implementation manner, the permission determination module 230 determines the access permission of the current user to the target application in the following specific way:

[0090] Query the access permission policy issued by the SDP controller to determine the authorized applications of the current user; match the authorized application with the target application, and determine the access permission of the current user to the target application according to the matching result.

[0091] An embodiment of the present application provides an electronic device, which may include: a memory and one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. When the processor executes the computer instructions, the electronic device can perform each function or step of the above method embodiment.

[0092] The structure of this electronic device can refer to Figure 3 the structure of the electronic device 100 shown.

[0093] The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0094] An embodiment of the present application also provides a computer-readable storage medium, which includes computer instructions. When the computer instructions run on an electronic device, the electronic device is enabled to execute each function or step of the above method embodiment.

[0095] The above computer-readable storage medium includes, but is not limited to, any one of the following: USB flash drive, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc., various media that can store program codes.

[0096] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, the computer is enabled to execute each function or step of the above method embodiment.

[0097] Among them, the electronic device, computer-readable storage medium, and computer program product provided by the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.

[0098] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0099] In several embodiments provided by the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the module or unit is only a logical function division, and there can be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, indirect coupling or communication connection of modules or units, and can be in electrical, mechanical or other forms.

[0100] In addition, each functional unit in the embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0101] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.

Claims

1. A network traffic processing method, characterized in that: The method is applied to an SDP gateway, and the method comprises: Determine a target triplet of access traffic flowing through the SDP gateway, wherein the target triplet includes a protocol type, an IP address, and a port number; Determine the target application associated with the target triplet by querying a first data structure, wherein the key of the first data structure is the triplet, and the value of the first data structure is the application identifier associated with the triplet; Query the access permission policy issued by the SDP controller to determine the current user's access permission to the target application; A processing operation corresponding to the access permission is performed on the access traffic.

2. The method according to claim 1, characterized in that The method specifically determines the target application associated with the target triplet in the following manner: Determining whether the target triple exists in the first data structure; If the judgment result is yes, determining the target application associated with the target triplet in the first data structure; If the judgment result is no, the target application associated with the target triplet is determined by querying a second data structure, wherein the key of the second data structure is the application identifier, and the value of the second data structure is the triplet associated with the application corresponding to the application identifier.

3. The method according to claim 2, characterized in that The method specifically determines the target application associated with the target triplet by querying the second data structure in the following manner: Determine whether the target triple exists in the second data structure; If the judgment result is yes, the target application associated with the target triplet in the second data structure is determined, and the target triplet and the application identifier of the target application are recorded in the first data structure.

4. The method according to claim 2, characterized in that: The second data structure includes a simple application data structure and a complex application data structure. The method specifically determines the target application associated with the target triple by querying the second data structure in the following manner: Determine the target application associated with the target triplet by querying a simple application data structure, wherein the key of the simple application data structure is a simple application identifier, the value of the simple application data structure is a triplet associated with the simple application corresponding to the simple application identifier, and the number of triples associated with the simple application is one; If the target triplet cannot be found in the simple application data structure, the target application associated with the target triplet is determined by querying the complex application data structure, wherein the key of the complex application data structure is the complex application identifier, the value of the complex application data structure is the triplet associated with the complex application corresponding to the complex application identifier, and the number of triples associated with the complex application is multiple.

5. The method according to claim 2, characterized in that: The method specifically queries the second data structure in the following manner: Query the access permission policy issued by the SDP controller to determine the authorized applications of the current user; The second data structure is screened using the application identifier of the authorized application as a screening condition, and the target application associated with the target triplet is determined by querying the screened second data structure.

6. The method according to any one of claims 1 to 5, characterized in that: The method specifically queries the first data structure in the following manner: Taking the hash value of the target triple as the query condition, the target application associated with the target triple is determined by querying the first data structure, wherein the key of the first data structure is the hash value of the triple, and the value of the first data structure is the application identifier associated with the triple.

7. The method according to claim 1, characterized in that The method specifically determines the access rights of the current user to the target application in the following manner: Query the access permission policy issued by the SDP controller to determine the authorized applications of the current user; The authorized application is matched with the target application, and the access rights of the current user to the target application are determined according to the matching result.

8. A network traffic processing device, characterized in that: The device is applied to an SDP gateway, and the device includes: A triplet determination module, used to determine a target triplet of access traffic flowing through the SDP gateway, wherein the target triplet includes a protocol type, an IP address, and a port number; A query module, configured to determine a target application associated with the target triplet by querying a first data structure, wherein a key of the first data structure is a triplet, and a value of the first data structure is an application identifier associated with the triplet; The permission determination module is used to query the access permission policy issued by the SDP controller to determine the current user's access permission to the target application; A processing module is used to perform a processing operation corresponding to the access permission on the access traffic.

9. The device according to claim 8, characterized in that The query module specifically includes: A judging unit: used for judging whether the target triple exists in the first data structure; A first query unit, configured to determine a target application associated with the target triplet in the first data structure when the judgment result is yes; A second query unit is used to determine the target application associated with the target triplet by querying a second data structure when the judgment result is no, wherein the key of the second data structure is the application identifier, and the value of the second data structure is the triplet associated with the application corresponding to the application identifier.

10. An electronic device, characterized in that: include: A memory and one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described in any one of claims 1-7.

11. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 7.

12. A computer program product, characterized in that When the computer program product is executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 7.