Service access control method, system and device, equipment and medium

By matching the client authorization status on the server and adopting the short TTL broadcast mechanism, the problem of inefficient service matching in the multicast DNS service discovery protocol is solved, and targeted service discovery and real-time authorization management are realized.

CN120378240APending Publication Date: 2025-07-25SHENZHEN COOCAA NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510410257.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the existing multicast DNS service discovery protocol, service discovery lacks targetedness and low matching efficiency, and the client cannot discover the newly updated service status in time.

Method used

The server matches the client's authorization status through multicast method, uses the authorization list to restrict access to non-authorized clients, and uses a short TTL broadcast mechanism to dynamically update the service status to ensure the real-time nature of authorization management.

Benefits of technology

It realizes targeted service discovery for specific clients, improves matching efficiency, guarantees user privacy, and ensures real-time service information and authorization management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378240A_ABST
    Figure CN120378240A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, in particular to a service access control method, system, device and equipment and a storage medium, and is used for solving the technical problems that the service matching efficiency is low and a client cannot timely discover a newly updated service state in a traditional scheme. The method comprises the steps that a server side responds to a service query request sent by a client side in a multicast mode, client side identification corresponding to the client side is matched with authorization range identification in an authorization list so as to confirm the authorization state of the client side, and the client side identification is uniquely bound with the corresponding authorization range identification; and when it is confirmed that the authorization state of the client is an unauthorized state, the server refuses to reply service detailed information responded by the service query request to the client, and records PTR with a pointer of broadcast service in a multicast mode regularly, and the TTL of the pointer records PTR is smaller than a preset duration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a service access control method, system, device, equipment, and storage medium. Background Art

[0002] In the existing Multicast DNS Service Discovery (mDNS-SD), the service discovery mechanism is to send a multicast service query request to the local area network, and all servers in the local area network can default to listen and respond to the service query request. However, this public broadcast discovery mechanism has the problems that all clients can discover and attempt to access services, the service discovery lacks pertinence, and the service matching efficiency is low; moreover, the client cannot timely discover the newly updated service status. Summary of the Invention

[0003] The present invention provides a service access control method, system, device, equipment, and storage medium, which are used to solve the technical problems that the service matching efficiency is low in the traditional solution and the client cannot timely discover the newly updated service status.

[0004] In a first aspect, a service access control method is provided. The method includes: The server responds to the service query request sent by the client in a multicast manner, and matches the client identifier corresponding to the client with the authorized range identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorized range identifier; When it is confirmed that the authorization status of the client is an unauthorized status, the server refuses to reply to the client with the service detailed information of the service query request response, and regularly broadcasts the pointer record PTR of the service in a multicast manner, where the time-to-live TTL of the pointer record PTR is less than a preset time.

[0005] In one implementation, after matching the client identifier corresponding to the client with the authorized range identifier in the authorization list to confirm the authorization status of the client, the method further includes: When it is confirmed that the authorization status of the client is an authorized status, the server replies to the client with the service detailed information of the service query request response in a unicast manner.

[0006] In one implementation, after regularly broadcasting the pointer record PTR of the service in a multicast manner, the method further includes: The server responds to the service query request re - sent by the client in a multicast manner, and matches the client identifier corresponding to the client with the authorization scope identifier in the latest authorization list to re - confirm the authorization status of the client. Among them, the re - sent service query request is triggered after the client queries that the time - to - live TTL of the pointer record PTR has expired; The server determines whether to reply to the client with the service details of the service query request response according to the re - confirmed authorization status of the client.

[0007] In one implementation, the client identifier includes the media access control address MAC, IP address or user credentials of the client. The matching of the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client includes: Matching the media access control address MAC, IP address or user credentials corresponding to the client with the authorization scope identifier in the authorization list; When there is an authorization scope identifier in the authorization list that matches the media access control address MAC, IP address or user credentials corresponding to the client, it is confirmed that the authorization status of the client is the authorized status; When there is no authorization scope identifier in the authorization list that matches the media access control address MAC, IP address or user credentials corresponding to the client, it is confirmed that the authorization status of the client is the unauthorized status.

[0008] In one implementation, the preset duration is less than or equal to 30 seconds.

[0009] In one implementation, the service query request includes a discovery request based on the multicast domain name system mDNS or a discovery request based on the domain name system service discovery DNS - SD.

[0010] In a second aspect, a service access control system is provided. The service access control system includes a server and a client; The client is used to send a service query request in a multicast manner; The server is used to respond to the service query request, match the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorization scope identifier; when it is confirmed that the authorization status of the client is the unauthorized status, it refuses to reply to the client with the service details of the service query request response, and regularly broadcasts the pointer record PTR of the service in a multicast manner, where the time - to - live TTL of the pointer record PTR is less than the preset duration.

[0011] In a third aspect, a service access control device is provided. The device includes: a receiving module, configured to receive a service query request sent by a client in a multicast manner a processing module, configured to respond to the service query request sent by the client in a multicast manner, match the client identifier corresponding to the client with the authorized scope identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorized scope identifier; when it is confirmed that the authorization status of the client is an unauthorized status, the service details of the service query request response are refused to be replied to the client, and a pointer record PTR of the broadcast service is periodically broadcast in a multicast manner, where the time-to-live TTL of the pointer record PTR is less than a preset time.

[0012] In a fourth aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the service access control method as described in any one of the foregoing are implemented.

[0013] In a fifth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the service access control method as described in any one of the foregoing are implemented. It can be seen that the present application provides a service access control solution. The server responds to the service query request sent by the client in a multicast manner, matches the client identifier corresponding to the client with the authorized scope identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorized scope identifier; when it is confirmed that the authorization status of the client is an unauthorized status, the server refuses to reply the service details of the service query request response to the client, and periodically broadcasts a pointer record PTR of the broadcast service in a multicast manner, where the time-to-live TTL of the pointer record PTR is less than a preset time. It can be seen that in the present application, after the client sends a service query request in a multicast manner, the server matches the client identifier corresponding to the client with the authorized scope identifier in the authorization list to confirm the authorization status of the client, introduces an authorization list for authorization management, restricts access to services by unauthorized clients, and while protecting user privacy, realizes targeted service discovery for specific clients, improving user matching efficiency; in addition, when it is confirmed that the authorization status of the client is an unauthorized status, the server refuses to reply the service details of the service query request response to the client, and periodically broadcasts a pointer record PTR of the broadcast service in a multicast manner, and dynamically updates the service status through a short TTL broadcast mechanism to ensure the real-time nature of service information and authorization management. Brief Description of the Drawings

[0014] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0015] Figure 1 is a flowchart of a service access control method in an embodiment of the present invention; Figure 2 is another flowchart of a service access control method in an embodiment of the present invention; Figure 3 is a structural diagram of a service access control device in an embodiment of the present invention; Figure 4 is a structural diagram of a computer device in an embodiment of the present invention. Detailed Embodiments

[0016] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0017] To solve the technical problems in the traditional service discovery mechanism, such as lack of pertinence in service discovery and low service matching efficiency; and the client cannot timely discover the newly updated service status. The embodiments of the present application provide a service access control solution, which will be described separately below.

[0018] In one embodiment, please refer to Figure 1 and Figure 2 As shown, a service access control method is provided, and the method includes the following steps; S101. The client sends a service query request in a multicast manner.

[0019] In this embodiment, the client refers to the client that needs to perform service discovery. When the client needs to perform service discovery, it can send a service query request to its local area network in a multicast manner.

[0020] Exemplarily, taking one specific hotel application scenario as an example, when a user enters a certain room in a hotel and the user requests services through a client, the client can send a service query request to the local area network of the hotel where it is located in a multicast manner to request services under the local area network of the hotel. For example, the service query request can be used to multicast queries to the local area network for service types such as "_http._tcp.local" or "_airplay._tcp.local", without specific limitations. By defining different service types, various client types can apply the solution of the embodiments of the present application, with better compatibility. For the client, it can also specifically discover services.

[0021] Among them, any service running based on HTTP (such as a local web server) can use _http._tcp.local for broadcasting, enabling other clients within the local area network to discover it. This is the service type broadcast by AirPlay devices (such as Apple TV) within the local area network. AirPlay is a wireless streaming media protocol that supports functions such as audio and video screen mirroring or screen casting. Through airplay._tcp.local, devices supporting AirPlay can automatically discover AirPlay servers (such as Apple TV or speakers supporting AirPlay) within the local area network.

[0022] S102. The server responds to the service query request sent by the client in a multicast manner, and matches the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorization scope identifier.

[0023] After the client sends a service query request in a multicast manner, the local area network will forward the service query request to the server, causing the server to respond to the service query request sent by the client in a multicast manner to check the authorization status of the client. Specifically, the server will respond to the service query request sent by the client, match the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorization scope identifier; when there is an authorization scope identifier in the authorization list that matches the client identifier, it is confirmed that the authorization status of the client is the authorized status; when there is no authorization scope identifier in the authorization list that matches the client identifier, it is confirmed that the authorization status of the client is the unauthorized status.

[0024] In one embodiment, the client identifier includes the Media Access Control (MAC) address, IP address, or user credentials of the client. Matching the client identifier corresponding to the client with the authorized scope identifier in the authorization list to confirm the authorization status of the client includes: matching the MAC address, IP address, or user credentials corresponding to the client with the authorized scope identifier in the authorization list; when there is an authorized scope identifier in the authorization list that matches the MAC address, IP address, or user credentials corresponding to the client, it is confirmed that the authorization status of the client is the authorized status; when there is no authorized scope identifier in the authorization list that matches the MAC address, IP address, or user credentials corresponding to the client, it is confirmed that the authorization status of the client is the unauthorized status.

[0025] In this embodiment, the MAC address, IP address, or user credentials can be used as the client identifier to be dynamically bound to the authorized scope identifier for representing the authorized scope, and then the authorization status of the client is determined, ensuring the feasibility of the solution. For example, the client identifier can be dynamically bound to the authorized scope identifiers such as room numbers and usage scenarios, and then the purpose of binding the authorized scope to the scenario can be achieved to realize more accurate targeted service discovery. For example, in a hotel scenario, the client identifier of the client can be bound to the room number, and then it can be checked whether the client identifier matches the room number to determine whether the client has the authorization for the services of that room number. In specific implementation, the server can maintain a scenario mapping table as the authorization list (such as the mapping from room numbers to MAC addresses), and query this mapping table in real time during the authorization verification process to confirm the matching situation.

[0026] S103. When it is confirmed that the authorization status of the client is the unauthorized status, the server refuses to reply to the client with the service details of the service query request response, and regularly broadcasts the Pointer Record (PTR) of the service in a multicast manner, where the Time-To-Live (TTL) of the Pointer Record (PTR) is less than the preset duration.

[0027] The server responds to the service query request sent by the client via multicast, matches the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client. After that, when it is confirmed that the authorization status of the client is the unauthorized status, the server refuses to reply to the service details of the service query request response to the client, and periodically broadcasts the pointer record (PTR) of the service via multicast. Among them, the time-to-live (TTL) of the pointer record PTR is less than a preset time. The pointer record PTR is used to indicate the existence of the service. In mDNS-SD, the PTR record is used to list the devices or instances providing a certain service within the local area network, including information such as which devices provide a certain service type (such as http._tcp.local). For the time-to-live (TTL) of the pointer record PTR, the server will periodically re-broadcast the pointer record PTR to ensure availability before the expiration of the time-to-live (TTL). In this embodiment, by setting the time-to-live (TTL) of the pointer record PTR to be less than the preset time, a short TTL broadcast mechanism is implemented to dynamically update the service status, ensuring the real-time nature of service information and authorization management.

[0028] It can be seen that the present application provides a service access control method. After the client sends a service query request via multicast, the server matches the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client. By introducing an authorization list for authorization management, it restricts unauthorized clients from accessing the service, protects user privacy, and at the same time realizes targeted service discovery for specific clients, improving the user matching efficiency. In addition, when it is confirmed that the authorization status of the client is the unauthorized status, the server refuses to reply to the service details of the service query request response to the client, and periodically broadcasts the pointer record PTR of the service via multicast. The service status is dynamically updated through the short TTL broadcast mechanism to ensure the real-time nature of service information and authorization management. Moreover, based on the processing mechanism of the present application, the client for service discovery does not need to be modified and only the server needs to be implemented, making the client highly compatible, and many clients can be applied to the solution of the present application.

[0029] In one embodiment, after step S102, that is, after matching the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, the method further includes the following steps: S104. When it is confirmed that the authorization status of the client is the authorized status, the server replies to the service details of the service query request response to the client via unicast.

[0030] In this embodiment, the server responds to the service query request sent by the client in a multicast manner, matches the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, and then, when it is confirmed that the authorization status of the client is the authorized status, the server replies to the client with the service details of the service query request response in a unicast manner. Exemplarily, the service details include, for example, the IP address, port, service name, and MDNS TXT record of the server. The TXT record is used to store additional information (metadata) of the service, such as the version number, device function, supported protocols, etc.

[0031] It can be seen that in this embodiment, only when it is confirmed that the authorization status of the client is the authorized status, the server replies to the client with the service details of the service query request response in a unicast manner, thereby introducing authorization management, providing access services for authorized clients, and making service discovery more targeted. In addition, when the server determines that the client is authorized, it also adopts a unicast reply mechanism, that is, it unicast returns the service details only to the authorized clients, thereby reducing the multicast bandwidth occupancy and improving the broadband utilization rate.

[0032] In one embodiment, after regularly broadcasting the pointer record PTR of the service in a multicast manner, the method further includes: S105. The client sends a service query request again in a multicast manner, where the service query request sent again is triggered after the client detects that the time-to-live TTL of the pointer record PTR has expired; S106. The server responds to the service query request sent again by the client in a multicast manner, matches the client identifier corresponding to the client with the authorization scope identifier in the latest authorization list to reconfirm the authorization status of the client; S107. The server determines whether to reply to the client with the service details of the service query request response according to the reconfirmed authorization status of the client.

[0033] In this embodiment, after regularly broadcasting the pointer record PTR of the service in a multicast manner, after the client detects that the time-to-live TTL in the service information has expired, it will initiate a service query request for the service details again, so that the server can decide whether to provide detailed service information to the client according to the latest authorization status. By regularly broadcasting the pointer record PTR and combining the short time-to-live TTL strategy, the service discovery status is dynamically updated, so the user experience can be optimized and the real-time performance of the service can be ensured.

[0034] Combined with the above embodiments, in one embodiment, the preset duration is less than or equal to 30 seconds. This 30 seconds is an empirical value and can specifically be other numbers, such as 35 seconds, etc., without specific limitation.

[0035] In one embodiment, the service query request includes a discovery request based on the Multicast Domain Name System (mDNS) or a discovery request based on the Domain Name System Service Discovery (DNS-SD). For example, the service query request can be used to query services such as "_http._tcp.local" or "_airplay._tcp.local" through local area network multicast, without specific limitation. By defining different service types, the solutions of this application embodiment can be applicable to various client types, with better compatibility. For clients, they can also specifically discover services. Among them, any service running based on HTTP (such as a local web server) can use "_http._tcp.local" for broadcasting, enabling other clients within the local area network to discover it. This is the service type broadcast by AirPlay devices (such as Apple TV) within the local area network. AirPlay is a wireless streaming media protocol that supports functions such as audio and video screen mirroring or screen mirroring. Through "airplay._tcp.local", devices supporting AirPlay can automatically discover AirPlay servers (such as Apple TV or speakers supporting AirPlay) within the local area network.

[0036] In one embodiment, a service access control system is provided. The service access control system includes a server and a client. The client is used to send a service query request in a multicast manner. The server is used to, in response to the service query request, match the client identifier corresponding to the client with the authorized range identifier in the authorization list to confirm the authorization status of the client. Among them, the client identifier is uniquely bound to the corresponding authorized range identifier. When it is confirmed that the authorization status of the client is the unauthorized status, the server refuses to reply to the service detailed information of the service query request response to the client and regularly broadcasts the pointer record (PTR) of the service in a multicast manner, where the time-to-live (TTL) of the pointer record (PTR) is less than the preset duration.

[0037] In one embodiment, in this service access control system, The server is further used to: after matching the client identifier corresponding to the client with the authorized range identifier in the authorization list to confirm the authorization status of the client, when it is confirmed that the authorization status of the client is the authorized status, the server replies to the service detailed information of the service query request response to the client in a unicast manner.

[0038] In one embodiment, after periodically recording the pointer record PTR of the broadcast service by multicast: The server responds to a service query request sent again by the client by multicast, and matches the client identifier corresponding to the client with the authorization scope identifier in the latest authorization list to confirm the authorization status of the client again. Among them, the service query request sent again is triggered after the client queries that the time-to-live TTL of the pointer record PTR has expired; The server determines whether to reply to the service detailed information of the service query request response to the client according to the authorization status of the client confirmed again.

[0039] In one embodiment, the client identifier includes the media access control address MAC, IP address or user credential of the client, and the server is further configured to: Match the media access control address MAC, IP address or user credential corresponding to the client with the authorization scope identifier in the authorization list; When there is an authorization scope identifier in the authorization list that matches the media access control address MAC, IP address or user credential corresponding to the client, it is confirmed that the authorization status of the client is the authorized status; When there is no authorization scope identifier in the authorization list that matches the media access control address MAC, IP address or user credential corresponding to the client, it is confirmed that the authorization status of the client is the unauthorized status.

[0040] In one embodiment, the preset duration is less than or equal to 30 seconds.

[0041] In one embodiment, the service query request includes a discovery request based on the multicast domain name system mDNS or a discovery request based on the domain name system service discovery DNS-SD.

[0042] It can be seen that the present application provides a service access control system. After the client sends a service query request in a multicast manner, the server matches the client identifier corresponding to the client with the authorized scope identifier in the authorization list to confirm the authorization status of the client. By introducing an authorization list for authorization management, unauthorized clients are restricted from accessing the service, ensuring user privacy while achieving targeted service discovery for specific clients and improving user matching efficiency. Additionally, when it is confirmed that the authorization status of the client is the unauthorized status, the server refuses to reply to the client with the service detailed information of the service query request response, and regularly broadcasts the pointer record PTR of the service in a multicast manner, and dynamically updates the service status through a short TTL broadcast mechanism to ensure the real-time nature of service information and authorization management. Moreover, based on the processing mechanism of the present application, the client for service discovery does not need to be modified and only the server needs to be implemented, making the client highly compatible and many clients can be applied in the solution of the present application.

[0043] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0044] In one embodiment, as Figure 3 shown, the present application also provides a service access control device, and the service access control device includes a receiving module 101, a processing module 102, and a sending module 102: The receiving module 101 is configured to receive a service query request sent by a client in a multicast manner The processing module 102 is configured to respond to a service query request sent by a client in a multicast manner, match the client identifier corresponding to the client with the authorized scope identifier in the authorization list to confirm the authorization status of the client, wherein the client identifier is uniquely bound to the corresponding authorized scope identifier; The sending module 102 is configured to, when it is confirmed that the authorization status of the client is the unauthorized status, refuse to reply to the client with the service detailed information of the service query request response, and regularly broadcast the pointer record PTR of the service in a multicast manner, wherein the time-to-live TTL of the pointer record PTR is less than a preset time length.

[0045] In one embodiment, the sending module 102 is further configured to: When it is confirmed that the authorization status of the client is the authorized status, reply to the client with the service detailed information of the service query request response in a unicast manner.

[0046] In one embodiment, after the regularly broadcasting the pointer record PTR of the service in a multicast manner: The processing module 102 is further configured to respond to a service query request re - sent by the client in a multicast manner, match the client identifier corresponding to the client with the authorization scope identifier in the latest authorization list to re - confirm the authorization status of the client, where the re - sent service query request is triggered after the client queries that the time - to - live (TTL) of the pointer record (PTR) has expired; and determine whether to reply to the client with the service details of the service query request response based on the re - confirmed authorization status of the client.

[0047] In one embodiment, the client identifier includes the media access control address (MAC) of the client, the IP address, or the user credentials. The processing module 102 is further configured to: Match the media access control address (MAC), IP address, or user credentials corresponding to the client with the authorization scope identifier in the authorization list; When there is an authorization scope identifier in the authorization list that matches the media access control address (MAC), IP address, or user credentials corresponding to the client, confirm that the authorization status of the client is the authorized status; When there is no authorization scope identifier in the authorization list that matches the media access control address (MAC), IP address, or user credentials corresponding to the client, confirm that the authorization status of the client is the unauthorized status.

[0048] In one embodiment, the preset duration is less than or equal to 30 seconds.

[0049] In one embodiment, the service query request includes a discovery request based on the multicast domain name system (mDNS) or a discovery request based on the domain name system service discovery (DNS - SD).

[0050] It can be seen that the present application provides a service access control device that matches the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, introduces an authorization list for authorization management, restricts unauthorized clients from accessing services, protects user privacy, and at the same time realizes targeted service discovery for specific clients, improving the user matching efficiency; in addition, when it is confirmed that the authorization status of the client is the unauthorized status, the server refuses to reply to the client with the service details of the service query request response, and regularly broadcasts the pointer record (PTR) of the service in a multicast manner, and dynamically updates the service status through the short TTL broadcast mechanism to ensure the real - time nature of service information and authorization management. And, based on the processing mechanism of the present application, the client for service discovery does not need to be modified, and only the server needs to be implemented, making the client highly compatible, and many clients can be applied to the solution of the present application.

[0051] For the specific limitations of the service access control device, reference may be made to the limitations of the service access control method in the foregoing text, which will not be elaborated here. Each module in the above service access control device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.

[0052] In one embodiment, a computer device is provided, and its internal structure diagram can be as Figure 4 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the processor can be used to communicate with an external server or database through a network connection. When the computer program is executed by the processor, it implements a service access control method.

[0053] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: In response to a service query request sent by a client in a multicast manner, match the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, where the client identifier is uniquely bound to the corresponding authorization scope identifier; When it is confirmed that the authorization status of the client is an unauthorized status, reject replying to the service detailed information of the service query request response to the client, and regularly broadcast the pointer record PTR of the service in a multicast manner, where the time-to-live TTL of the pointer record PTR is less than a preset time.

[0054] In one embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, it implements a service access control method mentioned in any of the above embodiments, which will not be repeated here.

[0055] In this embodiment, a method is provided for a device or medium to match the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client. By introducing an authorization list for authorization management, unauthorized clients are restricted from accessing services, ensuring user privacy while achieving targeted service discovery for specific clients and improving user matching efficiency. Additionally, when it is confirmed that the authorization status of the client is unauthorized, the server refuses to reply to the client with the detailed service information of the service query request response, and periodically broadcasts the pointer record PTR of the service in a multicast manner, and dynamically updates the service status through a short TTL broadcast mechanism to ensure the real-time nature of service information and authorization management. Moreover, based on the processing mechanism of this application, the client for service discovery does not need to be modified, and only the server needs to be implemented, making the client highly compatible, and many clients can be applied to the solution of this application.

[0056] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0057] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above.

[0058] The above-described embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A service access control method, characterized in that The method includes; The server responds to a service query request sent by the client in a multicast manner, and matches the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, wherein the client identifier is uniquely bound to the corresponding authorization scope identifier; When it is confirmed that the authorization status of the client is an unauthorized status, the server refuses to reply to the service details of the service query request response to the client, and regularly broadcasts the pointer record PTR of the service in a multicast manner, wherein the time-to-live TTL of the pointer record PTR is less than a preset time.

2. The service access control method according to claim 1, wherein After matching the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, the method further includes: When it is confirmed that the authorization status of the client is an authorized status, the server replies to the service details of the service query request response to the client in a unicast manner.

3. The service access control method according to claim 1, wherein After regularly broadcasting the pointer record PTR of the service in a multicast manner, the method further includes: The server responds to a service query request sent by the client again in a multicast manner, and matches the client identifier corresponding to the client with the authorization scope identifier in the latest authorization list to reconfirm the authorization status of the client, wherein the service query request sent again is triggered after the client queries that the time-to-live TTL of the pointer record PTR has expired; The server determines whether to reply to the service details of the service query request response to the client according to the reconfirmed authorization status of the client.

4. The service access control method according to claim 1, wherein The client identifier includes the media access control address MAC, IP address or user credentials of the client, and matching the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client includes: The server matches the media access control address MAC, IP address or user credentials corresponding to the client with the authorization scope identifier in the authorization list; When there is an authorization scope identifier in the authorization list that matches the media access control address MAC, IP address or user credentials corresponding to the client, the server confirms that the authorization status of the client is an authorized status; When there is no authorization scope identifier in the authorization list that matches the media access control address MAC, IP address or user credentials corresponding to the client, the server confirms that the authorization status of the client is an unauthorized status.

5. The service access control method according to any one of claims 1-4, characterized in that, The preset time is less than or equal to 30 seconds.

6. The service access control method according to any one of claims 1-4, characterized in that The service query request includes a discovery request based on the multicast domain name system mDNS or a discovery request based on the domain name system service discovery DNS-SD.

7. A service access control system, characterized in that, The service access control system includes a server and a client; The client is used to send a service query request in a multicast manner; The server is configured to respond to the service query request, match the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, wherein the client identifier is uniquely bound to the corresponding authorization scope identifier; when it is confirmed that the authorization status of the client is an unauthorized status, the server refuses to reply to the client with the service details of the service query request response, and regularly broadcasts the pointer record PTR of the service in a multicast manner, wherein the time-to-live TTL of the pointer record PTR is less than a preset time length.

8. A service access control device, characterized in that, The device includes; a receiving module, configured to receive a service query request sent by a client in a multicast manner a processing module, configured to respond to the service query request sent by the client in a multicast manner, match the client identifier corresponding to the client with the authorization scope identifier in the authorization list to confirm the authorization status of the client, wherein the client identifier is uniquely bound to the corresponding authorization scope identifier; when it is confirmed that the authorization status of the client is an unauthorized status, the processing module refuses to reply to the client with the service details of the service query request response, and regularly broadcasts the pointer record PTR of the service in a multicast manner, wherein the time-to-live TTL of the pointer record PTR is less than a preset time length.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the service access control method according to any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the service access control method according to any one of claims 1 to 6 are implemented.