Application gateway system and method and computing device

Through the application gateway system based on microservice architecture, the problem of inefficient communication in the overseasization process of cross-border e-commerce application software is solved, efficient interface request processing and system expansion are realized, and the concurrency and maintainability of the system are improved.

CN120389930APending Publication Date: 2025-07-29阿里巴巴(中国)网络技术有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510352761.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

During the overseasization process of cross-border e-commerce application software, it is impossible to reuse the local gateway, resulting in low communication efficiency and unable to support all interface requests of the application software.

Method used

The application gateway system based on the microservice architecture is adopted, including client message processing module, container thread pool, application thread pool and cache module. The core process of the gateway is processed through the responsibility chain mode, and functions such as protocol conversion, interface routing, login authentication, unified monitoring, flow control and fuse are realized, and thread pool isolation between different applications is supported.

Benefits of technology

It improves the communication efficiency of the gateway between various devices, supports all interface requests of the application software, improves the system's concurrency processing capabilities and code readability, reduces code complexity, and realizes a system with high concurrency, high availability and easy-to-scaling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389930A_ABST
    Figure CN120389930A_ABST
Patent Text Reader

Abstract

The invention provides an application gateway system and method and a computing device, the system is based on a micro-service architecture, the system comprises a client message processing module, the client message processing module is configured to receive a request message sent by a client, pass through the request message and send a client return value; the container thread pool is used for processing the transparent transmission request message and distributing the transparent transmission request message to an application thread pool; the application thread pool is configured to process an application gateway task of a corresponding task type, the application thread pool comprises a responsibility chain module, and the responsibility chain module is configured to process a gateway core process in a pipeline form; and the caching module is configured to cache the message data. According to the technical scheme of the invention, the application gateway for independent processing can be provided, the communication efficiency of the gateway among the devices is improved, and all interface requests of application software are supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software development, and in particular, to an application gateway system and method and a computing device. Background Art

[0002] The e-commerce industry has shown strong development momentum and broad market prospects in recent years. Among them, cross-border e-commerce, as a representative of the new foreign trade business format, has shown strong growth momentum. Therefore, building an overseas version of the local application software and developing e-commerce applications for global countries or regions has become a top priority. With the continuous growth of the global mobile Internet user population and the popularity of smart phones, the mobile application market has shown a booming development trend. However, there are differences in culture, language, user habits, etc. between different countries and regions, which pose huge challenges to the overseas expansion of local Apps. Since overseas software needs to build an overseas membership system and cannot reuse the local gateway, and the domestic gateway has no overseas computer room and cannot be reused either, and the gateway involves issues such as budget, machines, and independent tenants, the application cannot be fully reused.

[0003] Therefore, a technical solution is needed that can provide an independently processed application gateway, improve the communication efficiency of the gateway between devices, and support all interface requests of the application software. Summary of the Invention

[0004] The present invention aims to provide an application gateway system and method and a computing device that can provide an independently processed application gateway, improve the communication efficiency of the gateway between devices, and support all interface requests of the application software.

[0005] According to one aspect of the present invention, there is provided an application gateway system. The system is based on a microservices architecture and includes:

[0006] A client message processing module configured to receive a request message transmitted from a client, transparently transmit it, and send a client return value;

[0007] A container thread pool for processing the transparently transmitted request message and distributing it to an application thread pool;

[0008] The application thread pool is configured to process application gateway tasks of corresponding task types. The application thread pool includes a responsibility chain module configured to process the core gateway process in a pipeline form;

[0009] A cache module configured to cache message data.

[0010] According to some embodiments, the client message processing module is further configured to:

[0011] The client message processing module splices the data of the request message into the path of the request URL through the first receiving method and / or the second receiving method, where the request message includes an application programming interface, version information, and parameter data.

[0012] According to some embodiments, the client message processing module is further configured to:

[0013] The client message processing module places the client return value and system parameters into the message header through the first receiving method and / or the second receiving method.

[0014] According to some embodiments, different applications are isolated using different application thread pools, so that the application gateway tasks are split into different thread pools for synchronous processing according to the application type.

[0015] According to some embodiments, the responsibility chain module is further configured to:

[0016] Execute each processing logic pipeline in a preset order;

[0017] Preprocess, limit the flow, authenticate, perform access control, split, etc. on the data of the processing logic pipeline, and pass the filtered message downward.

[0018] According to some embodiments, the cache module is further configured to: the first layer of the cache module is a distributed cache, which caches the metadata that does not change frequently.

[0019] According to some embodiments, the cache module is further configured to: the second layer of the cache module is a local cache to ensure local cache consistency.

[0020] According to another aspect of the present invention, there is provided a method for an application gateway, which is used in a microservices architecture, and the method includes:

[0021] Receive a request message from the client through the client message processing module, transparently transmit it, and send the client return value;

[0022] Process the transparently transmitted request message through the container thread pool and distribute it to the application thread pool;

[0023] Process the application gateway tasks of the corresponding task type through the application thread pool, and the application thread pool includes the processing of the responsibility chain module to process the core gateway process in a pipeline form;

[0024] Cache the message data through the cache module.

[0025] According to another aspect of the present invention, there is provided a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method described in any one of the above.

[0026] According to another aspect of the present invention, there is provided a computing device, comprising:

[0027] a processor;

[0028] a memory storing a computer program which, when executed by the processor, implements the method described in any one of the above.

[0029] According to an embodiment of the present invention, the independent gateway system of the present invention improves the communication efficiency of the gateway among various devices and can support all interface requests of application software.

[0030] According to some embodiments, using a thread pool to asynchronously process application gateway tasks can effectively improve the concurrent processing ability of the system, avoid blocking, and increase the system throughput. Splitting the gateway core process into multiple independent processing nodes and connecting them in series through the responsibility chain pattern can achieve flexible configuration and expansion of the process, while improving the processing efficiency.

[0031] According to some embodiments, the responsibilities of each module are clear, and they can be developed, tested, and deployed independently, facilitating system expansion and maintenance. Splitting the complex gateway process into multiple simple processing nodes can reduce the code complexity and improve the readability and maintainability of the code.

[0032] According to some embodiments, the system of the present invention has the advantages of high concurrency, high availability, easy expansion, and easy maintenance, and can effectively support the development of overseas applications.

[0033] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments.

[0035] Figure 1 A schematic diagram showing an application gateway system according to an exemplary embodiment.

[0036] Figure 2 A schematic diagram showing a system thread pool according to an exemplary embodiment.

[0037] Figure 3 A schematic diagram showing the asynchronization of system gateway information according to an exemplary embodiment.

[0038] Figure 4 A schematic diagram showing the chained processing according to an exemplary embodiment.

[0039] Figure 5 A schematic diagram showing a system multi-layer cache and database according to an exemplary embodiment.

[0040] Figure 6 A schematic diagram showing the application gateway system architecture according to an exemplary embodiment.

[0041] Figure 7 A schematic diagram showing the existing application gateway architecture.

[0042] Figure 8 A block diagram showing a computing device according to an exemplary embodiment. Detailed implementation manners

[0043] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. Like reference numerals in the figures denote like or similar parts, and thus their repetitive description will be omitted.

[0044] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present invention. However, those skilled in the art will realize that the technical solutions of the present invention can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present invention.

[0045] The block diagrams shown in the drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0046] The flowcharts shown in the drawings are merely illustrative and do not necessarily include all the content and operations / steps, nor do they necessarily have to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.

[0047] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below may be referred to as the second component without departing from the teachings of the concept of the present invention. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0048] The user information involved in the present invention (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject.

[0049] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing the present invention. Therefore, they cannot be used to limit the protection scope of the present invention.

[0050] The overseas expansion of local e-commerce application software refers to the process of making a mobile application originally developed for a specific country or region adapt to the culture, language, user habits, etc. of the target market through means such as language translation, function adjustment, and interface optimization, so as to successfully enter and occupy the overseas market. The global mobile application market has huge potential, and the market size is expected to continue to grow in the next few years, which provides a broad market space for the overseas expansion of local e-commerce software. The competition in the domestic mobile application market is becoming increasingly fierce, and the customer acquisition cost is constantly rising, prompting more and more developers to turn their attention to the overseas market. Overseas users have increasingly diversified demands for mobile applications, putting forward higher requirements for the localization level of applications.

[0051] Since the overseas expansion of local e-commerce software requires the construction of an overseas membership system and cannot reuse the local gateway, and the domestic gateway has no overseas computer room and cannot be reused either, and the gateway involves issues such as budget, machines, and independent tenants, the application cannot be fully reused either.

[0052] Therefore, the present invention proposes an application gateway system that can provide an independently processed application gateway, improve the communication efficiency of the gateway among various devices, and support all interface requests of the application software.

[0053] Before describing the embodiments of the present invention, some terms or concepts related to the embodiments of the present invention are explained.

[0054] Overseas member: A membership architecture system for overseas users.

[0055] Gateway: A gateway (Gateway) is a server that forwards the communication data of other servers. When it receives a request sent from a client, it processes the request just like a source server that owns resources.

[0056] Microservices: Microservices is a software architecture style that divides a large application into a set of small, independent services, with each service responsible for implementing a specific function. Each microservice can be developed, deployed, and scaled independently and usually interoperates through lightweight communication protocols (such as HTTP / REST, message queues, etc.). The microservices architecture makes the application more flexible and maintainable, allowing development teams to work in different technology stacks and supporting continuous delivery and rapid iteration. However, it also introduces complexities in aspects such as service management, data consistency, and network communication. Overall, microservices aim to improve development efficiency and enhance the scalability and reliability of the system.

[0057] Template Pattern: A behavioral design pattern that defines a template for an algorithm in an abstract class, with the specific steps implemented by subclasses. By fixing the framework of the algorithm in the parent class and allowing subclasses to customize specific steps, the template pattern promotes code reuse and consistency. Subclasses do not need to rewrite the overall logic of the algorithm and can easily modify or extend specific details.

[0058] Strategy Pattern: A behavioral design pattern that allows the behavior of an algorithm to be selected at runtime, defines a series of interchangeable algorithms, and encapsulates them in independent strategy classes. The client can select a specific strategy as needed, thus enabling flexible switching of algorithms. The main advantage of this pattern is to eliminate the complexity of conditional statements, improve the readability and maintainability of the code, and facilitate the extension of new strategies.

[0059] Chain of Responsibility Pattern: A behavioral design pattern used to decouple the sender and receiver of a request. It forms a chain of responsibility by connecting multiple processing objects into a chain, allowing the request to be passed sequentially along the chain until it is processed by a certain handler or the end of the chain is reached. Such a design allows for the dynamic addition or modification of handlers, enhancing the flexibility and scalability of the system and is suitable for scenarios involving the handling of multiple requests and responsibilities.

[0060] Communication Protocol Conversion: Refers to the conversion between communication protocols such as HTTP and Remote Procedure Call (RPC).

[0061] Interface Routing: Refers to the ability to route to different Application Programming Interfaces (APIs) according to certain strategies.

[0062] Login Authentication: Refers to judging whether the parameters of the current request meet the requirements for login / authorization.

[0063] Unified Logging: Print logs in a unified format.

[0064] Unified Monitoring: Configure API monitoring and alerts based on the logs printed in a unified format.

[0065] Degradation: When the system load is too high or a certain service is unavailable, the system actively reduces its functions and service quality to maintain the availability of core functions. For example, when a request for a dependent service fails, the system can return cached data, simplify the response format, or reduce the complexity of requests. Degradation strategies can prevent the entire system from crashing due to the exception of a certain service, thereby improving the overall user experience and system stability.

[0066] Flow control: It refers to restricting the requests entering the system to prevent system overload and resource exhaustion. The flow control mechanism can be based on different strategies, such as flow limiting, queuing, request retry, etc. Common flow control strategies include token buckets, leaky buckets, etc., which are used to control the number of requests that can be processed per unit time. The purpose of flow control is to maintain the stability and performance of the system and ensure that the system can still work properly under high load.

[0067] Circuit breaker: It is a mechanism to prevent cascading failures. It monitors the health status of the service and automatically cuts off requests to unhealthy services. Once the service experiences consecutive failures, the circuit breaker will "trip" the requests, temporarily preventing calls to that service, and attempt to restore the connection after a certain period of time (referred to as the half-open state). The circuit breaker mechanism can effectively prevent continuous requests from being initiated under high load or in case of failures, which may exacerbate the system pressure, thus protecting the stability and availability of the entire system.

[0068] API console: A configuration page that supports parameter configuration, parameter mapping, etc. for HTTP interfaces and RPC interfaces.

[0069] The exemplary embodiments of the present invention will be described below with reference to the accompanying drawings.

[0070] Figure 1 A schematic diagram of an application gateway system according to an exemplary embodiment is shown.

[0071] See Figure 1 , Figure 1 , which shows the application gateway system of the present invention. The application gateway system is based on a microservices architecture. The application gateway system includes: a client message processing module configured to receive request messages from the client, transparently transmit them, and send client return values; a container thread pool that processes the transparently transmitted request messages and distributes them to the application thread pool; the application thread pool configured to process application gateway tasks of corresponding task types, and the application thread pool includes a responsibility chain module configured to process the core gateway process in a pipeline form; and a cache module configured to cache message data.

[0072] According to some embodiments, the client message processing module splices the data of the request message into the path of the request URL through the first receiving method and / or the second receiving method, and places the client return value and system parameters in the message header. The request message includes an application programming interface, version information, parameter data, etc.

[0073] According to some embodiments, the first receiving method is the POST method, and the second receiving method is the GET method.

[0074] According to some embodiments, the application gateway system interacts with the client or the front end in two ways: POST and GET. Three parameters, namely the application programming interface (API), version information (Version), and parameter data (Protoco), are spliced into the path of the request URL (URL) as the path (Path), and the input parameters for other interactions with the gateway (Gateway) are placed in the message header (Header), and the system parameters are also placed in the Header. The Gateway will pass the parameters in the Header to the downstream. The application parameters for interacting with the downstream API are placed in the request message body (Body). For example, key = data, value = a JSON-formatted string.

[0075] According to some embodiments, the input parameter data of the client and the Gateway include API, Version, Protocol, Data, and system parameters.

[0076] API: The name of the API configured for each module, of type String, such as gateway.lc.test.sayHello2; Version: The version number of the API configured for each module, of type Integer; Protocol: The API protocol configured for each module, of type String, such as HSF (distributed service framework); Data: The API parameters configured for each module, a JSON-formatted string, and the values are all of type String to prevent serialization problems, such as {"orderId":"23095792384732695947","x":"y"};

[0077] System parameters: They are placed in the Header. The Gateway layer will store the data in the Header into the RPCContext of HSF. The key is gatewayContext, and the value is a JSON-formatted string. Downstream applications can obtain it through the RPCContext (it must be at the entrance. After obtaining, the variable will be destroyed by HSF, and passing through the thread pool in the middle will also cause parameter loss). The way to obtain it is RPCContext.getServerContext().getAttachment getAttachment("gatewayContext"). See Table 1 for the specific system parameters passed to downstream applications.

[0078] Table 1

[0079]

[0080] According to some embodiments, the value of Data is the client return value sent by the application gateway system. The implementation code is as follows:

[0081]

[0082]

[0083] See Table 2 for some of the content of the client return value.

[0084] Table 2

[0085]

[0086]

[0087] According to some embodiments, the application gateway can perform protocol conversion. Since RPC protocol is used for development in internal development and exposed to internal services, when external services need to use this interface, the RPC protocol often needs to be converted to the HTTP protocol.

[0088] According to some embodiments, the application gateway can perform data routing. Currently, since the same interface is used by both the local legacy system and the overseas new system, the request needs to be routed to the corresponding interface according to the request context.

[0089] According to some embodiments, the application gateway can perform unified authentication. For authentication operations that do not involve application logic, they can be processed at the gateway layer without reaching the lower-layer application logic. When a member logs in successfully, the client or front-end will record the token data returned by the member. Next, for requests initiated by the application gateway, as long as the API requires login, this token will be carried and placed in the Authorization field of the HTTP request, with the value being Bearer${token}.

[0090] According to some embodiments, the application gateway can perform unified monitoring. Since the gateway is the entry point for external services, data can be monitored here, such as input and output parameters, link time, etc.

[0091] According to some embodiments, the application gateway can implement flow control, degradation, and circuit breaking. For non-application logic such as traffic control, circuit breaking, and degradation, they can be unified and placed at the gateway layer. The application gateway can implement functions such as flow limiting and degradation according to resource points, using the API name (APIName) as the cluster point. Subsequently, the total queries per second (QPS), passed QPS, and rejected QPS of specific cluster points can be monitored, and rules for flow control, degradation, hotspots, etc. can be configured for the cluster points, taking effect in real time.

[0092] See Figure 2 , according to some embodiments, the application gateway is deployed using Tomcat, calls the HTTP protocol, and the requests are processed by the container thread pool and then distributed to the application thread pool for asynchronous processing. The container enables Servlet3.0 asynchronous processing, providing a large throughput. When designing the application thread pool, it is considered that different task executions may take different amounts of time, so the tasks are split into different thread pools to improve the concurrency of different types of tasks. For example, see Figure 3 , the thread pool is divided into CommonGroup, ExecutionGroup, and ResultGroup. CommonGroup executes general tasks, ExecutionGroup executes multi-protocol routing and call tasks, and ResultGroup executes result processing tasks, including exception results.

[0093] According to some embodiments, in the case of full-link asynchrony, the impact between different applications is very small. However, if some synchronous calls are made in the provided custom filter (FiIlter), once timeouts occur frequently, it will affect other applications. Therefore, an application isolation solution needs to be adopted to reduce the mutual influence between applications.

[0094] Application isolation includes semaphore isolation, cluster isolation, and thread pool isolation. If semaphore isolation is used, only the total concurrency is restricted. The service still makes synchronous calls in the main thread, and remote call timeouts will still affect the main thread, thus affecting other applications. Therefore, if you only want to limit the total concurrent call volume of a certain service or the called service does not involve remote calls, you can use a lightweight semaphore to achieve this. If cluster isolation is used, if some applications are really important later, you can apply for a separate cluster or multiple clusters for this series of applications to isolate them among machines.

[0095] According to some embodiments, different applications are isolated using different application thread pools, so that the application gateway tasks are split into different thread pools for synchronous processing according to the application types.

[0096] According to some embodiments, the thread pool isolation adopted by the application gateway of the present invention processes relatively important applications, such as products or orders, separately through thread pools. Different applications are isolated by different thread pools. If there is a problem with the application interface, since the thread pools are already isolated, other applications will not be affected.

[0097] Since it is a unified gateway platform with a large number of application lines, almost all need separate thread pool isolation. If developed using the Java language, threads are relatively heavy resources, and too many thread pools need to be isolated, so it is not very suitable for Java development. If some other languages are used, such as using Golang to develop the gateway, threads are relatively light resources, so it is more suitable to use thread pool isolation.

[0098] See Figure 3 , Figure 3 shows the asynchronization of system gateway information. For the gateway layer of the application gateway of the present invention, the requirement for throughput is not high, so generally synchronous request calls are sufficient. However, for the unified gateway layer, asynchronization is required to improve more throughput and enable more services to be accessed with fewer machines.

[0099] According to some embodiments, there are generally two strategies for asynchronization. The first is Netty + NIO, and the second is Tomcat / Jetty + NIO + servlet3. Netty is designed for high concurrency, with a throughput of more than 300,000 per second, while Tomcat has a throughput of 130,000 +. It can be seen that there is a certain gap. If more emphasis is placed on throughput, Netty can be adopted, but Netty needs to handle the HTTP protocol by itself. The second strategy is more commonly used and is suitable for HTTP. Asynchronous processing can be enabled in Servlet3. The present invention uses the second strategy. For scenarios where there are many HTTP requests for the gateway, Servlet is adopted, and Servlet has a more mature way to handle the HTTP protocol.

[0100] See Figure 4 , Figure 4 shows a schematic diagram of chained processing. According to some embodiments, each processing logic pipeline is executed in a preset order; the data of the processing logic pipeline is preprocessed, rate-limited, authenticated, access-controlled, split, etc., and the filtered message is passed downwards.

[0101] According to some embodiments, the present invention adopts the responsibility chain pattern to implement the core processing flow of the gateway. Each processing logic is regarded as a pipe (Pipe), and each Pipe is executed in a preset order successively, referring to the open-source Zuul1.x. The responsibility chain adopts the PRPE mode, namely preprocessing (Pre), routing (Routing), postprocessing (Post), and error handling (Error).

[0102] See Figure 4 , Pre is divided into a preprocessing pipeline (PrePipe), a rate limit pipeline (RateLimitPipe), an authentication pipeline (AuthPipe), an access control list pipeline (AclPipe), a flow separation pipeline (FlowSepPipe), etc. These Pipes perform operations such as preprocessing, rate-limiting, authentication, access control, and splitting on the data, and pass the filtered message (Context) downwards.

[0103] See Figure 4 , Routing is divided into HsfPipe, HttpPipe, TppPipe, etc. These Pipes process RPC protocol, HTTP protocol routing, and calls respectively. Post is ResultPipe, which is used to process normal return values and statistical logging. Error is ErrorPipe, which is used to handle abnormal scenarios.

[0104] See Figure 5 , Figure 5Shows a system's multi - layer cache and database. According to some embodiments, the first layer of the cache module is a distributed cache that caches metadata that does not change frequently; the second layer is a local cache to ensure local cache consistency; and finally, a Mysql database is used to store all data.

[0105] According to some embodiments, using a multi - layer cache can further improve the performance of the gateway. The first - layer distributed cache is implemented by borrowing the distributed key - value storage system TAIR, which caches some API metadata that does not change frequently. This not only reduces the number of interactions between the application and the database DB but also speeds up the reading efficiency. Secondly, considering the instability factor of the TAIR cluster, a second - layer local cache is added, so that the reading can be reduced from the millisecond level (ms level) to the nanosecond level (ns level). To achieve local cache consistency across multiple machines, a distributed coordination service ZK (ZooKeeper) is used to listen for node changes to update the local caches of each machine.

[0106] According to some embodiments, to build an overseas membership system for overseas e - commerce applications, the group gateway cannot be reused. Therefore, the present invention independently constructs a set of gateways for overseas applications, which provides communication capabilities for downstream microservice systems. The overall design pattern adopts the template pattern + strategy pattern + responsibility chain pattern to achieve communication between the client, front - end, and server. Functionally, it supports communication protocol conversion, interface routing, login authentication, unified logging, unified monitoring, degradation, flow control, circuit breaker, API console, and other functions. The present invention provides a set of general solutions. As long as the interface is configured through the API management platform, a HTTP request can be used to call an RPC interface, such as a DUBBO interface, for example. Moreover, the system of the present invention has security functions such as thread isolation, web protection, flow - limiting, circuit - breaking, and degradation, so that the application system does not need to worry about security issues.

[0107] Figure 6 Shows a schematic diagram of the application gateway system architecture according to an exemplary embodiment.

[0108] The API gateway is a unified communication management system introduced after splitting the traditional large monolithic application (All in one) into numerous microservices. It is a traffic entry point between external HTTP requests and internal RPC services, and realizes various common general services such as protocol conversion, parameter verification, authentication, traffic shaping, circuit breaker, flow control, monitoring, and risk control for external requests.

[0109] This invention uses software such as Nginx as a front-end to handle the traffic load-balanced by SLB. Its functions include reverse proxy, cluster load balancing, forwarding, log collection, etc. Then, the requests of Nginx are proxied to the APIGateway for unified gateway processing.

[0110] According to some embodiments, the gateway includes a traffic gateway and an application gateway. The traffic gateway refers to the part that has nothing to do with specific backend application systems and services, such as security policies, global traffic control policies, traffic distribution policies, etc. The application gateway is for specific backend application systems or parts that have a certain relevance to services and applications (policy gateway), and is generally directly deployed in front of the application service. For example, traffic control policies for a certain system, a certain service, or a certain user classification, caching policies for a certain type of service, authentication methods for a specific system, request filtering for certain user condition judgments, data aggregation and encapsulation for specific related APIs, and so on.

[0111] The application gateway is generally deployed after the traffic gateway and before the application system, and is closer to the application system than the traffic gateway. In most cases, the API gateway, in a narrow sense, refers to the application gateway. If the scale of the system is small, we will also combine the two into one and use one gateway to handle all the work.

[0112] According to some embodiments, the traditional approach is to develop a corresponding WEB service on top of the RPC service. These WEB services can be Spring Boot projects. The RPC service is called in the Spring Boot project, and finally an HTTP interface is provided for use in applications such as H5, WEB, applets, and APPs. The general system architecture of the gateway is as Figure 7 shown.

[0113] See Figure 7 , the layers of H5 / WEB / applets / APP represent different scenarios of users and will not be elaborated here. Below the technical support, there are Netty 4.x, Ratelimiter, etc., all of which are open-source technology middleware. Niginx in the middle is also open-source middleware for complex balancing. NIO and RPC below refer to network request methods, and SPI refers to a standard extensible interface form, which means that through this extension ability, rapid development of new functions can be achieved.

[0114] According to some embodiments, the application gateway needs to maintain the access capability for a large volume of traffic Inbound requests, that is, both short and long connections. For example, for a normal WEB request, a connection is established after the three-way handshake. After sending data packets and obtaining the results returned by the server, it is closed and disconnected through the four-way handshake between the client and the server. This is a short connection. Different from the short connection, due to the three-way handshake for connection and the four-way handshake for disconnection, in the case of frequent requests, the overhead of connection requests and disconnection requests is relatively large, affecting efficiency. Therefore, the long connection method is adopted. After performing the three-way handshake to establish a connection, the connection is not disconnected, and the communication between the client and the server is maintained until the server times out and automatically disconnects the connection, or the client actively disconnects the connection.

[0115] According to some embodiments, the application gateway needs to maximize the reuse of the HTTP connection capability for traffic Outbound, such as the asynchronous HttpClient implementation based on HttpClient4.

[0116] According to some embodiments, the present invention needs to perform generalized invocation. Generalized invocation usually appears in distributed systems or service-oriented architectures (SOA), especially in scenarios that need to support different protocols, data formats, or interface specifications. It refers to initiating remote service calls in a more general way without relying on specific API interface definitions (such as IDL, WSDL, or interfaces in specific languages). This way allows service consumers to interact with service providers in a flexible and dynamic manner without having to know the specific implementation details of the service in advance.

[0117] According to some embodiments, the service consumer serializes the request object in its own working thread and places the serialized content into the request communication object, which also contains the request ID, EagleEye context, and other content. The request communication object is submitted to the I / O thread, where encoding is completed and finally sent to the service provider. After that, the client waits for the result to be returned.

[0118] According to some embodiments, the I / O thread of the service provider receives the binary content, decodes it to generate a communication request object, and submits it to the HSF server thread. The HSF server thread deserializes it to restore the request object and then initiates a reflection call to obtain the result, that is, the response object. The response object is serialized in the HSF server thread and placed into the communication response object. The HSF server thread submits the communication response object to the I / O thread, where encoding is completed and finally sent back to the service consumer.

[0119] According to some embodiments, the service consumer receives binary content, completes decoding in the I / O thread, generates a response communication object, and wakes up the client thread. The client thread will complete deserialization according to the content in the response communication object and finally obtain the response object, ending a remote call. This can effectively reduce the dependence on second-party packages of platform-based applications, thus realizing the lightweight operation of the application system.

[0120] According to some embodiments, the application gateway system of the present invention is configured by the application party through the management platform. The front end will provide a simple configuration page for each application party to configure by themselves. The management platform accesses the monitoring and alarm system Sunfire through the log, and configures the call volume, success volume, failure volume, and elapsed time of each Pipe of the application gateway and each downstream system API.

[0121] According to some embodiments, the security prevention and control realizes the ability of request signing & verification. Using the Wireless Bodyguard SDK, the client realizes signing according to the method of the Wireless Bodyguard, and then realizes verification on the traffic gateway through the policy configuration of the Baxia platform.

[0122] According to some embodiments, the application gateway of the present invention can conveniently and flexibly implement various policies such as security, verification, filtering, aggregation, flow limiting, and monitoring.

[0123] According to some embodiments, the application gateway of the present invention can realize the unified upgrade of technical components. For example, in a company, if a certain technical component needs to be upgraded, it is necessary to communicate with each application line, which usually takes several months. For the security authentication at the entrance, there are major security risks that need to be upgraded. If the upgrade speed is too slow, it will affect the application efficiency. Using a unified gateway can accelerate the upgrade speed.

[0124] According to some embodiments, the application gateway of the present invention can realize unified service access. For example, the company has developed relatively stable service components and is vigorously promoting them in the company. The promotion period will be extremely long. Through the unified gateway, unified access can be achieved, saving access time.

[0125] According to some embodiments, the application gateway of the present invention can save resources. Different applications in different departments need to use different gateways. For example, if a company has 100 applications and each application is equipped with 4 machines, then 400 machines are needed, and each application needs to develop a gateway layer and maintain it at any time, increasing the manpower. The application gateway of the present invention realizes a unified gateway, thus saving a lot of resources to solve the work of the application gateway, and application R & D personnel do not need to pay attention to the development and online steps at any time, saving manpower.

[0126] Figure 8 A block diagram of a computing device according to an exemplary embodiment is shown.

[0127] As Figure 8As shown, computing device 30 includes a processor 12 and a memory 14. Computing device 30 may also include a bus 22, a network interface 16, and an I / O interface 18. The processor 12, the memory 14, the network interface 16, and the I / O interface 18 may communicate with each other via the bus 22.

[0128] The processor 12 may include one or more general-purpose CPUs (Central Processing Units), microprocessors, or application-specific integrated circuits, etc., for executing relevant program instructions. According to some embodiments, computing device 30 may also include a high-performance display adapter (GPU) 20 for accelerating the processor 12.

[0129] The memory 14 may include a machine system-readable medium in the form of volatile memory, such as random access memory (RAM), read-only memory (ROM), and / or cache memory. The memory 14 is used to store one or more programs containing instructions and data. The processor 12 may read the instructions stored in the memory 14 to execute the methods according to the embodiments of the present invention described above.

[0130] Computing device 30 may also communicate with one or more networks via the network interface 16. The network interface 16 may be a wireless network interface.

[0131] The bus 22 may include an address bus, a data bus, a control bus, etc. The bus 22 provides a path for exchanging information between components.

[0132] It should be noted that in the specific implementation process, computing device 30 may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above devices may also only include the components necessary to implement the solutions of the embodiments of this specification, and do not necessarily include all the components shown in the figure.

[0133] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the above method are implemented. The computer-readable storage medium may include, but is not limited to, any type of disk, including floppy disks, optical disks, DVDs, CD-ROMs, microdrives, and magneto-optical disks, ROMs, RAMs, EPROMs, EEPROMs, DRAMs, VRAMs, flash memory devices, magnetic cards or optical cards, nanosystems (including molecular memory ICs), network storage devices, cloud storage devices, or any type of medium or device suitable for storing instructions and / or data.

[0134] The embodiments of the present invention also provide a computer program product, which includes a computer program, and the computer program is operable to cause a computer to execute some or all of the steps of any one of the methods described in the above method embodiments.

[0135] Those skilled in the art can clearly understand that the technical solution of the present invention can be implemented by means of software and / or hardware. The "units" and "modules" in this specification refer to software and / or hardware that can independently complete or cooperate with other components to complete specific functions, where the hardware can be, for example, a field programmable gate array, an integrated circuit, etc.

[0136] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0137] In the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0138] In several embodiments provided by the present invention, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some service interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.

[0139] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0140] In addition, the functional units in each embodiment of the present invention can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0141] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention.

[0142] In the above embodiments, the descriptions of the various embodiments each have their own emphasis. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0143] The above specifically shows and describes the exemplary embodiments of the present invention. It should be understood that the present invention is not limited to the detailed structures, setting manners, or implementation methods described herein; on the contrary, the present invention is intended to cover various modifications and equivalent settings included within the spirit and scope of the appended claims.

Claims

1. An application gateway system, the system is based on a microservices architecture, and the system includes: A client message processing module, which is configured to receive a request message from a client, transparently transmit it, and send a client return value; A container thread pool, which processes the transparently transmitted request message and distributes it to an application thread pool; The application thread pool, which is configured to process application gateway tasks of corresponding task types. The application thread pool includes a responsibility chain module, and the responsibility chain module is configured to process the gateway core process in the form of a pipeline; A cache module, which is configured to cache message data.

2. The system according to claim 1, wherein The client message processing module is further configured to: The client message processing module splices the data of the request message into the path of the request URL through a first receiving method and / or a second receiving method, where the request message includes an application programming interface, version information, and parameter data.

3. The system according to claim 1, wherein The client message processing module is further configured to: The client message processing module places the client return value and system parameters into the message header through a first receiving method and / or a second receiving method.

4. The system according to claim 1, wherein Different applications are isolated by different application thread pools, so that the application gateway tasks are split into different thread pools for synchronous processing according to the application type.

5. The system according to claim 1, wherein The responsibility chain module is further configured to: Execute each processing logic pipeline in a preset order; Preprocess, limit traffic, authenticate, control access, split traffic, etc. on the data of the processing logic pipeline, and pass the filtered message downwards.

6. The system according to claim 1, characterized in that, The cache module is further configured to: The first layer of the cache module is a distributed cache, which caches stable metadata.

7. The system according to claim 6, wherein The cache module is further configured to: The second layer of the cache module is a local cache, which ensures local cache consistency.

8. A method for an application gateway, the method is used for a microservices architecture, and the method includes: Receiving a request message from a client through a client message processing module, transparently transmitting it, and sending a client return value; Processing the transparently transmitted request message through a container thread pool and distributing it to an application thread pool; Processing application gateway tasks of corresponding task types through an application thread pool. The application thread pool includes a responsibility chain module for processing the gateway core process in the form of a pipeline; Caching message data through a cache module.

9. A computer program product, characterized in that, Including a computer program, which, when executed by a processor, implements the method according to any one of claims 8.

10. A computing device, characterized in that, Including: A processor; A memory, storing a computer program, which, when executed by the processor, implements the method according to any one of claims 8.