Network data acquisition request processing method and device and computer equipment

By intercepting the digital code multiple times and generating network protocol addresses in multiple bit formats, the problem of insufficient security of digital codes in the existing technology is solved, and more efficient and secure data transmission is achieved.

CN120602532APending Publication Date: 2025-09-05TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410258078.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-04
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In the prior art, the digital code security of network data acquisition requests is relatively low, and a single digital code verification method is difficult to effectively ensure the security of data transmission.

Method used

By parsing the preset fields of the network data acquisition request, the digital code is truncated multiple times using the truncated digit set to generate truncated sub-codes and remaining sub-codes in multiple digit forms, and a network protocol address set is generated while meeting the legal conditions of the network protocol address. Finally, a request is sent when there is an intersection in the whitelist set.

Benefits of technology

It improves the diversity of digital coding and the accuracy of verification, enhances the security of data transmission, saves data storage space and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602532A_ABST
    Figure CN120602532A_ABST
Patent Text Reader

Abstract

The invention relates to a network data acquisition request processing method and device and computer equipment. The method comprises the following steps: in response to a network data acquisition request sent by a terminal, performing interception processing matched with an interception bit number on a digital code based on the interception bit number in an interception bit number set to obtain an interception sub-code and a residual sub-code after interception, under the condition that both the intercepted sub-codes and the remaining sub-codes meet the legal condition of the network protocol address, continuing to perform interception processing matched with the interception bits on the intercepted sub-codes until all the digital codes are intercepted; and under the condition that the network protocol address set and a stored network protocol address white list set have an intersection, sending the network data acquisition request to a network data server, and sending response data returned by the network data server to the terminal. According to the embodiment of the invention, the diversity of digital coding can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a method, apparatus, computer equipment, storage medium, and computer program product for processing network data acquisition requests. Background Art

[0002] Terminals can obtain required data by sending requests to internet data centers. This typically involves two methods: directly accessing an open server URL via HTTP (Hypertext Transfer Protocol) requests; and accessing data on the server via RPC (Remote Procedure Call) protocols. Both methods can be used simultaneously. Related technologies use a network protocol address whitelist verification method to verify the digital code carried in the request. However, this digital code is relatively simple and lacks security. Summary of the Invention

[0003] Based on this, it is necessary to provide a method, device, computer equipment, computer-readable storage medium and computer program product for processing network data acquisition requests that can improve the diversity of digital coding in response to the above technical problems.

[0004] In a first aspect, the present application provides a method for processing a network data acquisition request. Applied to a server, the method comprises:

[0005] In response to a network data acquisition request sent by a terminal, parsing a preset field of the network data acquisition request to obtain a digital code for authentication;

[0006] Based on the number of truncated digits in the truncated digit set, the digital code is subjected to a truncation process that matches the number of truncated digits to obtain a truncated subcode and a remaining subcode after truncation. If both the truncated subcode and the remaining subcode satisfy the legality condition of the network protocol address, the truncation process that matches the number of truncated digits is continued on the truncated subcode until all the digital codes are truncated. The truncated digit set includes at least two truncated digits within a legal range of digits corresponding to the network protocol address, and both the truncated subcode and the remaining subcode satisfy the legality condition of the network protocol address, including that the truncated subcode is within a legal range of values ​​for the network protocol address, and that the number of digits of the remaining subcode is within a corresponding legal range of digits.

[0007] Based on each intercepted sub-code, a network protocol address set is obtained. When there is an intersection between the network protocol address set and a stored network protocol address whitelist set, the network data acquisition request is sent to a network data server, and the response data returned by the network data server is sent to the terminal.

[0008] In one embodiment, the digital code is subjected to truncation processing based on the number of truncation digits in the truncation digit set to match the number of truncation digits to obtain a truncation subcode and a remaining subcode after truncation, and if both the truncation subcode and the remaining subcode meet the legality condition of the network protocol address, the truncation processing of the truncation subcode to match the number of truncation digits is continued until all the digital codes are truncation is completed, including:

[0009] Selecting the digital code as a root node, obtaining truncated digits from the truncated digit set, truncating the digital code according to the truncated digits, and obtaining truncated sub-codes corresponding to all first-level branch nodes and remaining sub-codes after truncation; wherein the first-level branch nodes are child nodes of the root node;

[0010] It is judged whether the truncated subcode and the remaining subcode corresponding to each first-layer branch node meet the legal conditions of the network protocol address, and the truncated bit number is continuously obtained from the truncated bit number set. The remaining subcode corresponding to each legal first-layer branch node is truncated according to the truncated bit number, and the truncated subcodes corresponding to all second-layer branch nodes and the truncated remaining subcodes are obtained, until all the remaining subcodes corresponding to the last-layer branch nodes are truncated.

[0011] In one embodiment, after determining whether the intercepted subcode and the remaining subcode corresponding to each first-layer branch node meet the legality condition of the network protocol address, the method further includes:

[0012] If at least one of the intercepted subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, determining that the first-layer branch node is illegal;

[0013] Delete the illegal first-layer branch nodes.

[0014] In one embodiment, a network protocol address set is obtained based on each intercepted sub-code, including:

[0015] Traversing the intercepted sub-codes corresponding to the branch nodes at each layer on the node path to obtain multiple intercepted sub-codes;

[0016] Mark two adjacent intercepted sub-codes with a separator to obtain the corresponding network protocol address;

[0017] Based on the network protocol addresses corresponding to the paths of each node, a network protocol address set is obtained.

[0018] In one embodiment, the truncation processing of the digital code to match the truncation digits in the truncation digit set includes:

[0019] Get the legal bit range corresponding to the network protocol address;

[0020] In a case where the number of digits of the digital code is within the legal range of digits of the network protocol address, the digital code is subjected to a truncation process that matches the number of truncation digits based on the number of truncation digits in the truncation digit set.

[0021] In one embodiment, after obtaining the network protocol address set, the method further includes:

[0022] If there is an intersection between the network protocol address set and the whitelist set and there is a target remote call task in the link where the network data acquisition request is located, adding the target remote call task to the message queue;

[0023] Calculate the ticket allocation waiting time of the target remote call task based on the order in which the remote call tasks are added to the message queue and the number of service tickets required by each remote call task;

[0024] Return the ticket allocation waiting time, configure the business ticket of the target remote call task, call the corresponding call module based on the configured business ticket, obtain the call data corresponding to the network data acquisition request, and return the call data and the response data corresponding to the network data acquisition request.

[0025] In one embodiment, the ticket allocation waiting time of the target remote call task is calculated based on the order in which the remote call tasks are added to the message queue and the number of service tickets required by each remote call task, including:

[0026] Determine the array identifier corresponding to each remote call task based on the order in which each remote call task is added to the message queue, and obtain the current remote call task from the message queue;

[0027] When the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, determining the time taken for the current remote call task to be completed when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the call module corresponding to the current remote call task and the number of calls of the data module corresponding to the target remote call task;

[0028] If the array identifier of the current remote call task is greater than the array identifier of the target remote call task, subtract a preset threshold from the number of calls of the data module corresponding to the target remote call task to obtain a reference amount, and determine the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount;

[0029] The call task consuming time corresponding to each remote call task in the message queue is accumulated to obtain the ticket allocation waiting time of the remote call task.

[0030] In one embodiment, the time taken by the current remote call task when the remote call task ticket allocation is completed is determined based on the minimum value of the number of calls to the data module corresponding to the current remote call task and the number of calls to the data module corresponding to the target remote call task.

[0031] Obtaining a minimum value between the number of calls to the data module corresponding to the current remote call task and the number of calls to the data module corresponding to the remote call task;

[0032] The minimum value is combined with the average processing time of the data module to obtain the current remote call task time when the target remote call task ticket allocation is completed.

[0033] In one embodiment, determining the time consumption of the current remote call task when the target remote call task ticket allocation is completed based on the number of calls of the data module corresponding to the current remote call task and the minimum value of the reference amount includes:

[0034] The minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount;

[0035] The minimum value is combined with the average ticket allocation time of the data module to obtain the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed.

[0036] In one embodiment, configuring the business ticket of the target remote call task includes:

[0037] Sorting the remote call tasks based on the order in which they are added to the message queue to obtain an arrangement order;

[0038] According to the arrangement order, the current calling modules of the target remote calling task and the previous remote calling task are sequentially configured; if all calling modules of the target remote calling task have not been configured, the current calling modules of the remote calling tasks after the target remote calling task are sequentially configured;

[0039] The next calling module of the target remote calling task and the previous remote calling task is configured in sequence until all calling modules of the target remote calling task are configured.

[0040] In a second aspect, the present application provides a method for processing a network data acquisition request. Applied to a terminal, the method comprises:

[0041] Send a network data acquisition request to the server;

[0042] The server is used to parse the preset field of the network data acquisition request to obtain a digital code for authentication, wherein the digital code includes a truncated digit based on a truncated digit set, performing a truncation process on the digital code to match the truncated digit, obtaining a truncated subcode and a remaining subcode after truncation, and when both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, continuing to perform truncation process on the truncated subcode to match the truncated digit until all the digital codes are truncated; wherein the truncated digit set includes at least two truncated digits in a legal digit range corresponding to the network protocol address, and both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address and that the digits of the remaining subcode are within the corresponding legal digit range; based on each truncated subcode, a network protocol address set is obtained, and when there is an intersection between the network protocol address set and a whitelist set, the network data acquisition request is sent to the network data server;

[0043] Receive response data returned by the server.

[0044] In one embodiment, the link where the network data acquisition request is located also includes a target remote call task, and receiving the response data returned by the server includes:

[0045] Receive the ticket allocation waiting time and corresponding data returned by the server; wherein, the ticket allocation waiting time includes the ticket allocation waiting time of the target remote call task calculated by the server by adding the target remote call task to the message queue, based on the order of adding each remote call task in the message queue, and the number of business tickets required for each remote call task.

[0046] In one embodiment, before sending a network data acquisition request to a server, the method further includes:

[0047] Obtain a network protocol address whitelist set, and select any network protocol address from the whitelist set;

[0048] The separator of the network protocol address is removed to obtain a digital code for authentication.

[0049] In a third aspect, the present application further provides a device for processing network data acquisition requests. Applied to a server, the device comprises:

[0050] a parsing module, configured to respond to a network data acquisition request sent by a terminal, parse a preset field of the network data acquisition request, and obtain a digital code for authentication;

[0051] a truncation processing module, configured to perform truncation processing on the digital code based on the number of truncation digits in the truncation digit set to match the number of truncation digits, thereby obtaining a truncation subcode and a remaining subcode after truncation; and, if both the truncation subcode and the remaining subcode satisfy a network protocol address legality condition, continue to perform truncation processing on the truncation subcode to match the number of truncation digits until all of the digital code is truncation; wherein the truncation digit set includes at least two truncation digits within a legal range of digits corresponding to the network protocol address, and the truncation subcode and the remaining subcode satisfying the network protocol address legality condition include the truncation subcode being within a legal range of values ​​for the network protocol address, and the number of digits of the remaining subcode being within a corresponding legal range of digits;

[0052] The verification module is used to obtain a network protocol address set based on each intercepted sub-code, and when there is an intersection between the network protocol address set and a stored network protocol address whitelist set, send the network data acquisition request to the network data server, and send the response data returned by the network data server to the terminal.

[0053] In one embodiment, the interception processing module is further configured to:

[0054] Selecting the digital code as a root node, truncating the minimum truncated digit of the digital code based on the minimum truncated digit in the truncated digit set, and obtaining a truncated sub-code corresponding to a first-level branch node and a remaining sub-code after truncating; wherein the first-level branch node is a child node of the root node;

[0055] When the truncated subcode and the remaining subcode corresponding to the first-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the first-layer branch node to obtain the truncated subcode and the remaining subcode corresponding to the second-layer branch node. When the truncated subcode and the remaining subcode corresponding to the second-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the second-layer branch node until all the digital codes are intercepted.

[0056] In one embodiment, the interception processing module is further configured to:

[0057] If at least one of the truncated subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, the first-layer branch node is deleted, and the minimum truncated bit number is added to the unit step size to obtain an updated truncated bit number;

[0058] truncating the number of truncated bits of the digital code for the first update to obtain a truncated sub-code corresponding to another first-layer branch node and a remaining sub-code after truncating;

[0059] When the node path corresponding to the other first-layer branch node is completely intercepted, the number of intercepted bits of the first update is added to the unit step size to obtain the number of intercepted bits of the second update;

[0060] The number of truncated digits of the second update of the digital code is truncated until all the digital codes are truncated.

[0061] In one embodiment, the interception processing module is further configured to:

[0062] Selecting the digital code as a root node, obtaining truncated digits from the truncated digit set, truncating the digital code according to the truncated digits, and obtaining truncated sub-codes corresponding to all first-level branch nodes and remaining sub-codes after truncation; wherein the first-level branch nodes are child nodes of the root node;

[0063] It is judged whether the truncated subcode and the remaining subcode corresponding to each first-layer branch node meet the legal conditions of the network protocol address, and the truncated bit number is continuously obtained from the truncated bit number set. The remaining subcode corresponding to each legal first-layer branch node is truncated according to the truncated bit number, and the truncated subcodes corresponding to all second-layer branch nodes and the truncated remaining subcodes are obtained, until all the remaining subcodes corresponding to the last-layer branch nodes are truncated.

[0064] In one embodiment, the interception processing module is further configured to:

[0065] If at least one of the intercepted subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, determining that the first-layer branch node is illegal;

[0066] Delete the illegal first-layer branch nodes.

[0067] In one embodiment, the network protocol address includes multiple fields, and a separator is provided between two adjacent fields; the interception processing module is further configured to:

[0068] Determining a legal value range of the corresponding field according to the type of the network protocol address and the position of the corresponding field of the intercepted subcode;

[0069] When the intercepted subcode is within the legal value range of the corresponding field, it is determined that the intercepted subcode is within the legal value range of the network protocol address.

[0070] In one embodiment, the network protocol address includes multiple fields, and a separator is provided between two adjacent fields; the interception processing module is further configured to:

[0071] Obtain the number of fields corresponding to the remaining subcodes, and perform algorithmic processing on the number of fields and the maximum number of bits allowed in a field of a network protocol address to obtain a legal range of bits;

[0072] In a case where the number of bits of the remaining subcode is within the legal range of bits, it is determined that the number of bits of the remaining subcode is within the legal range of bits of a network protocol address.

[0073] In one embodiment, the verification module is further configured to:

[0074] Traversing the intercepted sub-codes corresponding to the branch nodes at each layer on the node path to obtain multiple intercepted sub-codes;

[0075] Mark two adjacent intercepted sub-codes with a separator to obtain the corresponding network protocol address;

[0076] Based on the network protocol addresses corresponding to the paths of each node, a network protocol address set is obtained.

[0077] In one embodiment, the interception processing module is further configured to:

[0078] Get the legal bit range corresponding to the network protocol address;

[0079] In a case where the number of digits of the digital code is within the legal range of digits of the network protocol address, the digital code is subjected to a truncation process that matches the number of truncation digits based on the number of truncation digits in the truncation digit set.

[0080] In one embodiment, the apparatus further comprises:

[0081] A selection module, configured to select any network protocol address from a stored network protocol address whitelist set;

[0082] The digital code generating module is used to remove the separator of the network protocol address to obtain the digital code for authentication, and send the digital code to the terminal.

[0083] In one embodiment, the apparatus further comprises:

[0084] an adding module, configured to add the target remote call task to the message queue if there is an intersection between the network protocol address set and the whitelist set and there is a target remote call task in the link where the network data acquisition request is located;

[0085] A calculation module, configured to calculate a ticket allocation waiting time for the target remote call task based on the order in which the remote call tasks are added to the message queue and the number of service tickets required for each remote call task;

[0086] The data return module is used to return the ticket allocation waiting time, configure the business ticket of the target remote call task, call the corresponding call module based on the configured business ticket, obtain the call data corresponding to the network data acquisition request, and return the call data and the response data corresponding to the network data acquisition request.

[0087] In one embodiment, the calculation module is further configured to:

[0088] Determine the array identifier corresponding to each remote call task based on the order in which each remote call task is added to the message queue, and obtain the current remote call task from the message queue;

[0089] When the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, determining the time taken for the current remote call task to be completed when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the call module corresponding to the current remote call task and the number of calls of the data module corresponding to the target remote call task;

[0090] If the array identifier of the current remote call task is greater than the array identifier of the target remote call task, subtract a preset threshold from the number of calls of the data module corresponding to the target remote call task to obtain a reference amount, and determine the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount;

[0091] The call task consuming time corresponding to each remote call task in the message queue is accumulated to obtain the ticket allocation waiting time of the remote call task.

[0092] In one embodiment, the calculation module is further configured to:

[0093] Obtaining a minimum value between the number of calls to the data module corresponding to the current remote call task and the number of calls to the data module corresponding to the remote call task;

[0094] The minimum value is combined with the average processing time of the data module to obtain the current remote call task time when the target remote call task ticket allocation is completed.

[0095] In one embodiment, the calculation module is further configured to:

[0096] The minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount;

[0097] The minimum value is combined with the average ticket allocation time of the data module to obtain the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed.

[0098] In one embodiment, the data return module is further configured to:

[0099] Sorting the remote call tasks based on the order in which they are added to the message queue to obtain an arrangement order;

[0100] According to the arrangement order, the current calling modules of the target remote calling task and the previous remote calling task are sequentially configured; if all calling modules of the target remote calling task have not been configured, the current calling modules of the remote calling tasks after the target remote calling task are sequentially configured;

[0101] The next calling module of the target remote calling task and the previous remote calling task is configured in sequence until all calling modules of the target remote calling task are configured.

[0102] In a fourth aspect, the present application further provides a device for processing a network data acquisition request. Applied to a terminal, the device comprises:

[0103] A sending module is used to send a network data acquisition request to the server;

[0104] The server is used to parse the preset field of the network data acquisition request to obtain a digital code for authentication, wherein the digital code includes a truncated digit based on a truncated digit set, performing a truncation process on the digital code to match the truncated digit, obtaining a truncated subcode and a remaining subcode after truncation, and when both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, continuing to perform truncation process on the truncated subcode to match the truncated digit until all the digital codes are truncated; wherein the truncated digit set includes at least two truncated digits in a legal digit range corresponding to the network protocol address, and both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address and that the digits of the remaining subcode are within the corresponding legal digit range; based on each truncated subcode, a network protocol address set is obtained, and when there is an intersection between the network protocol address set and a whitelist set, the network data acquisition request is sent to the network data server;

[0105] The receiving module is used to receive the response data returned by the server.

[0106] In one embodiment, the receiving module is further configured to:

[0107] Receive the ticket allocation waiting time and corresponding data returned by the server; wherein, the ticket allocation waiting time includes the ticket allocation waiting time of the target remote call task calculated by the server by adding the target remote call task to the message queue, based on the order of adding each remote call task in the message queue, and the number of business tickets required for each remote call task.

[0108] In one embodiment, the apparatus further comprises:

[0109] An acquisition module is used to acquire a network protocol address whitelist set and select any network protocol address from the whitelist set;

[0110] The digital code generating module is used to remove the separator of the network protocol address to obtain the digital code for authentication.

[0111] In a fifth aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the method for processing a network data acquisition request as described in any embodiment of the present disclosure when executing the computer program.

[0112] In a sixth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for processing a network data acquisition request as described in any embodiment of the present disclosure.

[0113] In a seventh aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the method for processing a network data acquisition request as described in any embodiment of the present disclosure.

[0114] The above-mentioned processing method, apparatus, computer equipment, storage medium and computer program product for network data acquisition request carry an unsigned integer type digital code in the network data acquisition request, and obtain the digital code for authentication by parsing the request, which can save data storage space and improve the efficiency of data processing. Furthermore, the embodiment of the present disclosure performs interception processing on the digital code based on the interception bit number in the interception bit set, wherein the interception bit number can select at least two interception bit numbers in the legal bit range corresponding to the network protocol address, that is, the interception sub-code can be in a variety of bit number forms, such as 1 bit or 3 bits, so that the generated network protocol address field is richer and more diverse. For example, for the traditional IPv4 decimal digital code, the above-mentioned decoding method can relax the number of bits of the digital code to 4-12 bits, greatly improving the diversity of the digital code, thereby increasing the accuracy and reliability of verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0115] Figure 1 This is a diagram of an application scenario in a related technology where a terminal requests data from a network data center;

[0116] Figure 2 This is a diagram of an application scenario in which a terminal requests data from a network data center in one embodiment;

[0117] Figure 3 This is a diagram of an application scenario in which a terminal requests data from a network data center in one embodiment;

[0118] Figure 4 This is a diagram of an application scenario in which a terminal requests data from a network data center in one embodiment;

[0119] Figure 5 A flowchart of a method for processing a network data acquisition request in one embodiment is shown;

[0120] Figure 6 A flowchart of a digital code capture process in one embodiment;

[0121] Figure 7 A flowchart of a method for processing a network data acquisition request in one embodiment is shown;

[0122] Figure 8 A flowchart of a method for processing a network data acquisition request in one embodiment is shown;

[0123] Figure 9 A schematic diagram of a structure in which a remote call task is added to a message queue in one embodiment;

[0124] Figure 10 This is an application scenario diagram of remotely calling task ticket verification in one embodiment;

[0125] Figure 11 This is a diagram of a configuration interface for a business ticket in one embodiment;

[0126] Figure 12 A flowchart of a method for processing a network data acquisition request in one embodiment is shown;

[0127] Figure 13 A schematic diagram of a remote call task in a message queue in one embodiment;

[0128] Figure 14 A schematic diagram of a traversal process for calculating the time consumption of a remote call task in one embodiment;

[0129] Figure 15 A schematic diagram of a traversal process for calculating the time consumption of a remote call task in one embodiment;

[0130] Figure 16 A schematic diagram of a traversal process for calculating the time consumption of a remote call task in one embodiment;

[0131] Figure 17 A schematic diagram of a traversal process for calculating the time consumption of a remote call task in one embodiment;

[0132] Figure 18 A schematic diagram of a traversal process for calculating the time consumption of a remote call task in one embodiment;

[0133] Figure 19 A schematic diagram of a traversal process for calculating the time consumption of a remote call task in one embodiment;

[0134] Figure 20 A flowchart of a method for processing a network data acquisition request in one embodiment is shown;

[0135] Figure 21 A flowchart of a method for processing a network data acquisition request in one embodiment is shown;

[0136] Figure 22 It is a structural block diagram of a device for processing a network data acquisition request in one embodiment;

[0137] Figure 23 It is a structural block diagram of a device for processing a network data acquisition request in one embodiment;

[0138] Figure 24 is a diagram of the internal structure of a computer device in one embodiment;

[0139] Figure 25 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0140] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0141] In order to facilitate those skilled in the art to understand the technical solution provided by the embodiments of the present disclosure, the technical environment in which the technical solution is implemented is described below.

[0142] The terminal obtains the data of the website through http requests and RPC calls, but both methods have the problem of exceeding authority. In the related art, for open website resources, command line tools or file download tools are generally used on the terminal to obtain the data of open resources, such as the curl command line tool or the wget file download tool. The above method can obtain data quickly and conveniently, but it cannot obtain some non-public core data. Therefore, for some non-public core data, in order to ensure the security of the data, the user's access rights are limited by setting a network protocol address (IP address) whitelist. For example, the network protocol addresses 9.187.123.43, 9.187.123.44, and 30.17.13.46 are set as whitelists, then the terminals with the above three network protocol addresses can obtain the website data. Reference Figure 1 As shown, the terminal directly requests data from the Internet Data Center (IDC), but the request fails because the IP address is not in the whitelist.

[0143] In the specific implementation process, the network protocol address of the terminal device is usually not set in the whitelist of the network data center. It needs to be connected through the authentication server (brokersvr) as an intermediate bridge. The network protocol address of the authentication server is set in the whitelist of the network data center. The terminal can log in to the authentication server and then request data from the network data center. For example, refer to Figure 2As shown, the terminal logs in to the authentication server, which verifies the terminal's network protocol address using a whitelist of network protocol addresses. If the verification is successful, the authentication server sends the terminal's request to the network data center. The network data center verifies the authentication server's network protocol address using a whitelist of network protocol addresses. If the verification is successful, the network data center returns the corresponding response data to the authentication server. Finally, the authentication server returns the response data to the terminal.

[0144] In the specific implementation process, the data acquisition function of the authentication server can also be encapsulated into an interface, and the terminal obtains the data of the network data center by calling the interface of the authentication server. Figure 3 As shown, the terminal calls the authentication server's interface. The authentication server verifies the terminal's network protocol address using a whitelist of network protocol addresses. If the verification succeeds, the authentication server sends the terminal's request to the network data center. The network data center verifies the authentication server's network protocol address using a whitelist of network protocol addresses. If the verification succeeds, the network data center returns the corresponding response data to the authentication server. Finally, the authentication server returns the response data to the terminal.

[0145] In the related art, the network protocol address of the terminal contains separators and fields, such as 192.163.28.36, where "." represents the separator and "192" represents the field. This representation with both characters and numeric fields requires a larger storage space than the unsigned integer type. In addition, in modern computer architecture, numbers are usually stored in memory according to a specific size. The unsigned integer type can achieve efficient alignment and access and can be directly applied to bit operations. Therefore, the network protocol address of the terminal can be stripped of separators and sent to the authentication server with the request in the form of a digital code of the unsigned integer type. However, in order to conveniently decode the digital code of the unsigned integer type into the network protocol address, the total number of bits of the digital code needs to reach the maximum legal number of bits of the network protocol address. For example, the maximum legal number of IPv4 is 12 bits, and the digital code needs to be written in 12 bits, such as 255.218.134.124. This limits the diversity of digital codes to a certain extent and also reduces the difficulty of implementing illegal network data acquisition requests.

[0146] Based on actual technical requirements similar to those described above, this application provides a method for processing network data acquisition requests.

[0147] The method for processing network data acquisition requests provided in the embodiment of the present application can be applied to Figure 4In the application environment shown, the terminal communicates with the server via a network. The terminal may be, but is not limited to, various desktop computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, smart car-mounted devices, etc. Portable wearable devices may include smart watches, smart bracelets, head-mounted devices, etc. The server may be implemented as a standalone server or a server cluster consisting of multiple servers. The server includes a module for authentication services and a module for remote procedure calls. The authentication service module is used to verify the whitelist of digital codes carried in terminal requests. The remote procedure call module may further include an MQ service (Message Queue), service A module to service N module. Service A module to service N module are call modules traversed during the acquisition of call data. The number and type of call modules are related to the remote procedure call task. The network data server can store the data required by the terminal.

[0148] In one embodiment, Figure 5 As shown, a method for processing network data acquisition requests is provided, and the method is applied to Figure 5 The following steps are used as an example to illustrate the server in the example:

[0149] Step S501: In response to a network data acquisition request sent by a terminal, a preset field of the network data acquisition request is parsed to obtain a digital code for authentication.

[0150] The terminal may include a user terminal with a network data acquisition requirement, such as a terminal of a service developer or a terminal of a data user. The terminal may send a network data acquisition request to the server by logging in or calling a server interface.

[0151] The data format of a network data retrieval request can include a request line, a request header, and a request body. The request line conveys the request method, requested URL, and protocol version; the request header conveys information about the client, the request, and the requested resources; and the request body transmits data, such as form data or JSON data, to the server. In one exemplary embodiment, a digital code for authentication can be written into the request body and obtained by parsing predefined fields in the network data retrieval request.

[0152] The digital code used for authentication may include an unsigned integer type code. Optionally, the uint64 digital type is used as the digital code, such as 25525511135.

[0153] Step S503: Based on the truncated digits in the truncated digit set, the digital code is truncated to match the truncated digits to obtain a truncated sub-code and a remaining sub-code after truncation. When both the truncated sub-code and the remaining sub-code satisfy the legal conditions of the network protocol address, the truncated sub-code is continuously truncated to match the truncated digits until all the digital codes are truncated. The truncated digit set includes at least two truncated digits in the legal range of digits corresponding to the network protocol address, and both the truncated sub-code and the remaining sub-code satisfy the legal conditions of the network protocol address, including that the truncated sub-code is within the legal value range of the network protocol address and that the digits of the remaining sub-code are within the corresponding legal range of digits.

[0154] The network protocol address can include different versions of network protocol addresses, such as IPv4 and IPv6. Taking IPv4 as an example, it uses a 32-bit binary representation, which can be expressed as four decimal numbers separated by the delimiter ".". Each decimal number has a value range of 0-255, such as 210.21.196.6. Therefore, since the value range is fixed, the number of bits used to intercept the digital code after receiving it is limited. For the network protocol address IPv4, the interception bit can include 1 bit, 2 bits, or 3 bits. In this case, the interception set can include 1 bit, 2 bits, and 3 bits. It will be understood that the above interception bit is for IPv4 expressed in decimal. When IPv4 is expressed in binary, the interception bit increases. For example, the decimal number 210 is represented as the binary number 11010010, and the interception bit increases from 3 bits to 8 bits. It should be noted that due to different versions of the network protocol address, the value range of the field will also change. For example, the value range of each field in IPv6 is 0-FFFF (hexadecimal), and the truncated bit number can include 1 bit, 2 bits, 3 bits, and 4 bits. Therefore, the truncated bit number is related to the version of the network protocol address and the base number used. Inspired by the technical essence of this application, technical personnel in the relevant field can select the truncated bit number set according to the network protocol address version and the base number used. However, as long as the functions and effects achieved are the same or similar to those of this application, they should be covered within the scope of protection of this application.

[0155] In the disclosed embodiment, the truncated subcode may include the code obtained after each truncation operation of the digital code occurs, and the remaining subcode may include the subcode remaining after the truncation subcode corresponding to each truncation operation is removed from the digital code. For example, in the digital code "25525511135", if one digit is truncated, the resulting truncated subcode is "2", and the remaining subcode is "5525511135". If two digits are truncated, the resulting truncated subcode is "25", and the remaining subcode is "525511135".

[0156] In the embodiment of the present disclosure, the truncated subcode and the remaining subcode both meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address, and the number of digits of the remaining subcode is within the corresponding legal digit range. In an exemplary embodiment, taking the decimal network protocol address of IPv4 as an example, the legal value range of the field is 0-255. When the digital code "25525511135" is truncated by 1 bit for the first time, the truncated subcode "2" is obtained. Since "2" is within the legal value range of 0-255, the truncated subcode is within the legal value range of the network protocol address.

[0157] In an exemplary embodiment, each field of an IPv4 decimal network protocol address has a maximum of 3 digits and a minimum of 1 digit, with a total of 4 fields. Therefore, the legal range of digits for an IPv4 decimal network protocol address is 4-12 digits. The corresponding remaining subcode after the first interception corresponds to 3 fields. Therefore, the legal range of digits for the network protocol address corresponding to the remaining subcode of the first interception is 3-9 digits. Similarly, the legal range of digits for the network protocol address corresponding to the remaining subcode of the second interception is 2-6 digits. The legal range of digits for the network protocol address corresponding to the remaining subcode of the third interception is 1-3 digits. When the digital code "25525511135" is truncated by 1 bit for the first time to obtain the remaining subcode "5525511135", and the legal range of digits of the network protocol address corresponding to the remaining subcode of the first truncation is 3-9, the remaining subcode "5525511135" is 10, which exceeds the above legal range of digits of 3-9. Therefore, the remaining subcode corresponding to the first truncation does not meet the legal range of digits of the network protocol address.

[0158] In an exemplary embodiment, when both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, the truncated subcode is continuously truncated to match the number of truncated digits until all the digital codes are truncated. For example, the digital code "25525511135" is truncated for the first time by 3 digits to obtain the truncated subcode "255" and the remaining subcode "25511135", wherein the truncated subcode "255" is within the legal value range of 0-255 of the network protocol address, and the number of digits of the remaining subcode "25511135" is also within the legal number of digits of the network protocol address 3-9, then the remaining subcode "25511135" can be truncated, for example, 3 digits are also truncated for the second time to obtain the truncated subcode "255" and the remaining subcode "11135", and the truncated subcode "255" is truncated. The legal value range of the network protocol address is 0-255, and the remaining subcode "11135" is within the legal bit range of the network protocol address, 2-6 bits. The remaining subcode "11135" can be intercepted. For example, 2 bits are intercepted for the third time to obtain the intercepted subcode "11" and the remaining subcode "135". The intercepted subcode "11" and the remaining subcode "135" still meet the legal conditions of the network protocol address. The interception is completed, and the network protocol address 255.255.11.135 is obtained according to each intercepted subcode.

[0159] Step S505: Based on each intercepted sub-code, a network protocol address set is obtained. If there is an intersection between the network protocol address set and the stored network protocol address whitelist set, the network data acquisition request is sent to the network data server, and the response data returned by the network data server is sent to the terminal.

[0160] In the disclosed embodiment, the number of interceptions of the digital code varies depending on the version of the network protocol address. For example, IPv4 uses three "." delimiters to divide the network protocol address into four fields, while IPv6 uses four ":" delimiters to divide the network protocol address into eight fields. Therefore, the total number of interceptions for different versions of the network protocol address can be different. In the disclosed embodiment, each interception sub-code includes the sum of the legal interception sub-codes obtained for each interception, given the total number of interceptions that matches the version of the network protocol address. Of course, the number of intercepted bits can vary, and there are many ways to intercept the digital code. For example, interception method A: intercept 1 bit the first time, intercept 2 bits the second time... Interception method B: intercept 2 bits the first time, intercept 2 bits the second time... Regardless of how the interception is performed subsequently, interception method A and interception method B are considered different interception methods. In an exemplary embodiment, each interception sub-code includes the legal interception sub-codes obtained from all possible interception methods of the corresponding digital code.

[0161] In one exemplary embodiment, the legal interception subcodes corresponding to the same interception method are concatenated to obtain the corresponding network protocol address. For example, the digital code "25525511135" is intercepted using the first interception method, i.e., intercepting 3 digits for the first time, intercepting 3 digits for the second time, and intercepting 2 digits for the third time, resulting in four interception subcodes: "255," "255," "11," and "135," respectively. Based on these four interception subcodes, the network protocol address is: 255.255.11.135. For another example, the digital code "25525511135" is intercepted using the second interception method, i.e., intercepting 3 digits for the first time, intercepting 3 digits for the second time, and intercepting 3 digits for the third time, resulting in four interception subcodes: "255," "255," "111," and "35," respectively. Based on these four interception subcodes, the network protocol address is: 255.255.111.35. Both the network protocol address 255.255.11.135 and the network protocol address 255.255.111.35 can be added to the network protocol address set.

[0162] In one exemplary embodiment, if the network protocol address set intersects with a stored network protocol address whitelist, indicating that the terminal has access rights, a network data acquisition request is sent to the network data server. The network data acquisition request is sent to the network data server, and the response data returned by the network data server is sent to the terminal. In another exemplary embodiment, if the network protocol address set does not intersect with the stored network protocol address whitelist, indicating that the terminal does not have access rights, the network data acquisition request can be directly intercepted.

[0163] In the above embodiment, an unsigned integer type digital code is carried in a network data acquisition request, and a digital code for authentication is obtained by parsing the request, which can save data storage space and improve the efficiency of data processing. Furthermore, the embodiment of the present disclosure performs interception processing on the digital code based on the interception bit number in the interception bit set, wherein the interception bit number can select at least two interception bit numbers in the legal bit range corresponding to the network protocol address, that is, the interception sub-code can be in a variety of bit numbers, such as 1 bit or 3 bits, etc., so that the generated network protocol address field is richer and more diverse. For example, compared with the traditional IPv4 decimal digital code that needs to be written in full 12 bits, the above decoding method can relax the number of bits of the digital code to 4-12 bits, which greatly improves the diversity of the digital code, thereby increasing the accuracy and reliability of verification.

[0164] In one embodiment, the digital code is subjected to a truncation process based on the number of truncation digits in the truncation digit set to match the number of truncation digits, to obtain a truncation subcode and a remaining subcode after truncation, and if both the truncation subcode and the remaining subcode satisfy a legal condition for a network protocol address, the truncation process is continued on the truncation subcode to match the number of truncation digits until all the digital codes are truncation, including:

[0165] The digital code is selected as the root node, and based on the minimum truncated bit number in the truncated bit number set, the minimum truncated bit number of the digital code is truncated to obtain the truncated sub-code corresponding to the first-level branch node and the remaining sub-code after truncation; wherein the first-level branch node is a child node of the root node.

[0166] When the truncated subcode and the remaining subcode corresponding to the first-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the first-layer branch node to obtain the truncated subcode and the remaining subcode corresponding to the second-layer branch node. When the truncated subcode and the remaining subcode corresponding to the second-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the second-layer branch node until all the digital codes are intercepted.

[0167] Specifically, refer to Figure 6As shown, taking the IPv4 decimal digital code "25525511135" as an example, this digital code is selected as the root node. As described in the above embodiment, for the network protocol address IPv4, the number of truncated bits can include 1 bit, 2 bits, and 3 bits. In this case, the truncated set can include 1 bit, 2 bits, and 3 bits. In an exemplary embodiment, starting from the minimum truncated bit, the number of truncated bits increases successively during subsequent truncations. Specifically, the minimum truncated bit in the truncated set is 1 bit. 1 bit is truncated from the digital code "25525511125", resulting in the truncated sub-code "2" and the remaining sub-code "5525511135". The truncated sub-code "2" is within the legal value range of 0-255 for the network protocol address, and the remaining sub-code "5525511135" does not meet the legal value range of 3-9 bits for the network protocol address, so the first-level branch node is deleted. In one exemplary embodiment, two bits are taken from the truncated set and truncated from the digital code "25525511135," resulting in a truncated subcode "25" and a remaining subcode "525511135." The truncated subcode "25" is within the legal range of 0-255 for network protocol addresses, while the remaining subcode "525511135" is within the legal range of 3-9 bits for network protocol addresses. The truncated subcode "25" is used as the first-level branch node. Next, 1 bit is truncated from the remaining subcode "525511135" corresponding to the first-level branch node "25" to obtain the truncated subcode "5" and the remaining subcode "25511135". The truncated subcode "5" is within the legal value range of 0-255 for the network protocol address, and the remaining subcode "25511135" does not meet the legal bit range of 2-6 for the network protocol address. The second-level branch node "5" is deleted. For the same reason, the second-level branch node "52" is deleted. In an exemplary embodiment, The remaining subcode "525511135" corresponding to the first-level branch node "25" is truncated by three digits to obtain the truncated subcode "525" and the remaining subcode "511135". The truncated subcode "525" does not meet the legal value range of 0-255 for network protocol addresses, so the second-level branch node "525" is deleted. Because the remaining subcode "525511135" corresponding to the first-level branch node "25" cannot be truncated to a subnode that meets the legal conditions for network protocol addresses, the first-level branch node "25" is deleted.

[0168] In one exemplary embodiment, one bit is truncated from the remaining subcode "11135" corresponding to the second-layer branch node "255," resulting in the truncated subcode "1" and the remaining subcode "1135." Since the remaining subcode "1135" does not fall within the legal range of 1-3 bits for a network protocol address, the third-layer branch node "1" is deleted. Two bits are truncated from the remaining subcode "11135" corresponding to the second-layer branch node "255," resulting in the truncated subcode "11" and the remaining subcode "135." Both the truncated subcode "11" and the remaining subcode "135" meet the legal requirements for a network protocol address, and the truncated subcode "11" is used as the third-layer branch node. Because IPv4 network protocol addresses correspond to three delimiters, truncating "25525511135" three times indicates that the network protocol address can be generated, and there is no need to truncate the remaining subcode "135." In one exemplary embodiment, three digits of the remaining subcode "11135" corresponding to the second-level branch node "255" are truncated to obtain the truncated subcode "111" and the remaining subcode "35." Both the truncated subcode "111" and the remaining subcode "35" meet the legal requirements for network protocol addresses, and the truncated subcode "111" is used as the third-level branch node. The fact that "25525511135" has been truncated three times indicates that the network protocol address can be generated, and there is no need to continue truncating the remaining subcode "35." Furthermore, since all possible ways of truncating the digital code "25525511135" have been truncated, it indicates that the digital code has been completely truncated.

[0169] The above embodiment establishes a tree model of digital codes, i.e., using the digital code as the root node and intercepting child nodes as branch nodes at each level. Starting with the smallest interception number, interception is performed vertically from top to bottom until the number of interceptions meets the legal requirements of the corresponding network protocol address. Then, returning to the root node, interception is continued vertically from top to bottom, thereby improving the comprehensiveness of the digital code interception method and ensuring that no possible network protocol addresses are missed.

[0170] In one embodiment, reference Figure 7 As shown, after obtaining the truncated sub-code corresponding to the first-layer branch node and the remaining sub-code after truncating, the method further includes:

[0171] Step S701: If at least one of the truncated subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legal conditions of the network protocol address, the first-layer branch node is deleted, and the minimum truncated bit number is added to the unit step size to obtain an updated truncated bit number.

[0172] Step S703: truncate the updated truncation bit number of the digital code to obtain a truncation sub-code corresponding to another first-layer branch node and the remaining sub-code after truncation.

[0173] In the specific implementation process, the unit step size may include 1 bit, 2 bits, 3 bits, etc., as long as all the truncated bits in the truncated bit set are traversed, and the present disclosure does not impose any restrictions on this. Figure 6 As shown, the remaining subcode "5525511135" corresponding to the first-level branch node "2" does not meet the legal requirements of the network protocol address, so the first-level branch node "2" is deleted. The unit step size (1 bit) is added to the minimum truncation bit number (1), resulting in an updated truncation bit number of 2. The truncation bit number (25525511135) is truncated to the updated truncation bit number (2), resulting in another first-level branch node "25" and the corresponding remaining subcode "525511135."

[0174] Step S705 , when the node path corresponding to the other first-layer branch node is completely intercepted, the number of intercepted bits updated once is added to the unit step length to obtain the number of intercepted bits updated twice.

[0175] Specifically, for example, in the above embodiment, the node paths corresponding to another first-level branch node "25" may include three branch paths, namely, the three branch paths obtained by truncating the remaining subcode "525511135" corresponding to the other first-level branch node "25" by 1, 2, and 3 bits, respectively: 25->5; 25->52; and 25->525. When the node paths are truncated, the number of truncated bits (2 bits) in the first update is added to the unit step size (1 bit), resulting in a second-updated number of truncated bits (3 bits).

[0176] Step S707: intercepting the second updated intercepted digits of the digital code until all the digital codes are intercepted.

[0177] Specifically, for example, in the above embodiment, the truncated digital code "25525511135" is truncated twice with 3 digits of the truncated digits updated twice to obtain another first-level branch node "255" and the corresponding remaining sub-code "25511135".

[0178] It should be noted that in the embodiment of the present disclosure, when the node path corresponding to the other first-level branch node is completely truncated, the number of truncated bits of the first update is added to the unit step size to obtain the number of truncated bits of the second update. This is applicable not only to the first-level branch nodes, but also to the branch nodes of other levels. For example, 1 bit is truncated from the remaining child node "11135" of the second-level branch node to obtain the third-level branch node "1". When the node path of the third-level branch node "1" is completely truncated, 2 bits are truncated from the remaining child node "11135" of the second-level branch node to obtain the third-level branch node "11". When the node path of the third-level branch node "11" is completely truncated, 3 bits are truncated from the remaining child node "11135" of the second-level branch node to obtain the third-level branch node "111".

[0179] In the above embodiment, a tree model of digital codes is established, that is, the digital code is used as the root node, and the child nodes are intercepted as branch nodes of each layer. Starting from the smallest interception bit, the nodes are intercepted in the vertical direction from top to bottom until the number of interceptions meets the legal conditions of the corresponding network protocol address. Then, the tree model returns to the root node and continues to intercept in the vertical direction from top to bottom. In the process of vertical interception from top to bottom, if a situation is encountered that the legal conditions of the network protocol address are not met, the branch node of this layer can be directly deleted to ensure that the branch nodes in the tree model are legal branch nodes, which facilitates the subsequent generation of network protocol addresses.

[0180] In one embodiment, the digital code is subjected to a truncation process based on the number of truncation digits in the truncation digit set to match the number of truncation digits, to obtain a truncation subcode and a remaining subcode after truncation, and if both the truncation subcode and the remaining subcode satisfy a legal condition for a network protocol address, the truncation process is continued on the truncation subcode to match the number of truncation digits until all the digital codes are truncation, including:

[0181] Selecting the digital code as a root node, obtaining each truncated digit from the truncated digit set, truncating the digital code according to the truncated digit, and obtaining truncated sub-codes corresponding to all first-level branch nodes and remaining sub-codes after truncation; wherein the first-level branch nodes are child nodes of the root node;

[0182] It is judged whether the subcode and the remaining subcode corresponding to each first-layer branch node meet the legal conditions of the network protocol address, and the truncated bit number is continuously obtained from the truncated bit number set. The remaining subcode corresponding to each legal first-layer branch node is truncated according to the truncated bit number, and the truncated subcodes corresponding to all second-layer branch nodes and the truncated remaining subcodes are obtained, until all the remaining subcodes corresponding to the last-layer branch nodes are truncated.

[0183] Specifically, refer to Figure 6 As shown, taking the IPv4 version decimal digital code "25525511135" as an example, this digital code is selected as the root node. As described in the above embodiment, for the network protocol address IPv4, the number of truncated bits can include 1 bit, 2 bits and 3 bits. In this case, the truncated set can include 1 bit, 2 bits and 3 bits. In an exemplary embodiment, the digital code "25525511135" is truncated by 1 bit, 2 bits and 3 bits respectively to obtain all the first-level branch nodes "2", "25" and "255". It is judged whether the sub-codes and remaining sub-codes corresponding to the first-level branch nodes meet the legal conditions of the network protocol address. The specific judgment method has been explained in detail above and will not be repeated here. The legal first-level branch nodes "25" and "255" are obtained. In one exemplary implementation, the remaining subcode "525511135" corresponding to the legal first-level branch node "25" is truncated by 1 bit, 2 bits, and 3 bits, respectively, to obtain the second-level branch nodes "5," "52," and "525." Similarly, the remaining subcode "25511135" corresponding to the legal first-level branch node "255" is truncated by 1 bit, 2 bits, and 3 bits, respectively, to obtain the second-level branch nodes "2," "25," and "255."

[0184] In one exemplary embodiment, for the legal second-level branch node "255," 1, 2, and 3 digits are truncated, respectively, to obtain the third-level branch nodes "1," "11," and "111." This continues in this manner until the final branch node, the fourth-level branch nodes "135" and "35." The remaining sub-codes corresponding to these nodes are both empty, thus completing the complete truncation of the digital code "25525511135."

[0185] The above embodiment establishes a tree model of digital codes, i.e., using the digital code as the root node and extracting subnodes as branch nodes at each level. Each truncated digit is obtained from the truncated digit set, and all possible subnodes of the previous branch node are spread out layer by layer from top to bottom, until all remaining subcodes corresponding to the last branch node are extracted. This improves the comprehensiveness of the digital code extraction method and ensures that no possible network protocol addresses are missed.

[0186] In one embodiment, after determining whether the intercepted subcode and the remaining subcode corresponding to each first-layer branch node meet the legality condition of the network protocol address, the method further includes:

[0187] If at least one of the intercepted subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, determining that the first-layer branch node is illegal;

[0188] Delete the illegal first-layer branch nodes.

[0189] Specifically, if at least one of the intercepted subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legal conditions of the network protocol address, that is, the intercepted subcode exceeds the legal value range of the network protocol address, and / or the number of bits of the remaining subcode exceeds the corresponding legal number range, the first-layer branch node is determined to be illegal. The illegal first-layer branch node is deleted. For example, Figure 6 In the example, the first-level branch node "2" is illegal. Figure 6 As shown, all the child nodes "5", "52" and "525" of the first-level branch node "25" are illegal, then the interception of the first-level branch node "25" can be invalidated, and the first-level branch node "25" can be deleted. It should be noted that in the embodiment of the present disclosure, when at least one of the intercepted subcode and the remaining subcode corresponding to the first-level branch node does not meet the legal conditions of the network protocol address, the processing method of deleting the first-level branch node is not only applicable to the first-level branch node, but also when at least one of the subcode and the remaining subcode corresponding to any layer branch node does not meet the legal conditions of the network protocol address, any layer can be deleted. Optionally, when all the child nodes corresponding to any layer branch node do not meet the legal conditions of the network protocol address, the branch node of any layer is deleted.

[0190] In the above embodiment, a tree model of digital codes is established, i.e., the digital code is used as the root node, and child nodes are intercepted as branch nodes at each layer. Each intercepted bit is obtained from the intercepted bit set, and all possible child nodes of the branch node at the previous layer are spread out layer by layer from top to bottom, until all remaining sub-codes corresponding to the branch nodes at the last layer are intercepted. For any branch node at any layer that does not meet the legal conditions for the network protocol address, the branch node at that layer can be directly deleted, ensuring that the branch nodes in the tree model are legal branch nodes, facilitating the subsequent generation of the network protocol address.

[0191] In one embodiment, the network protocol address includes multiple fields, with a separator between two adjacent fields; the intercepted subcode is within the legal value range of the network protocol address, including:

[0192] Determining a legal value range of the corresponding field according to the type of the network protocol address and the position of the corresponding field of the intercepted subcode;

[0193] When the intercepted subcode is within the legal value range of the corresponding field, it is determined that the intercepted subcode is within the legal value range of the network protocol address.

[0194] Specifically, according to the version classification, the categories of network protocol addresses can be divided into IPv4 and IPv5, etc. According to the purpose classification, for example: IPv4 categories can be divided into five categories: A, B, C, D, and E. Among them, A, B, and C are more commonly used network protocol addresses, and D and E are network protocol addresses for special purposes.

[0195] In an exemplary embodiment, if the subdivision of IPv4 is not considered, the legal value range of each field for IPv4 is between 0-255. The legal value range of each field for IPv6 is between 0-FFFF. In an exemplary embodiment, if the subdivision of IPv4 is considered, the legal value range of the first field of the network protocol address of Class A is between 1-126, and the legal value range of the remaining fields is between 0-255. The legal value range of the first field of the network protocol address of Class B is between 128-191, and the legal value range of the remaining fields is between 0-255. The legal value range of the first field of the network protocol address of Class C is between 192-223, and the legal value range of the remaining fields is between 0-255. The legal value range of the first field of the network protocol address of Class D is between 224-239, and the legal value range of the remaining fields is between 0-255. The legal value range of the first field of the network protocol address of Class E is between 240-255, and the legal value range of the remaining fields is between 0-255.

[0196] Wherein, if the network protocol address is expressed as XXX.XXX.XXX.XXX, XXX represents a field, and "." represents a separator. It can be understood that the first field can be understood as the first XXX field counted from left to right. In the embodiment of the present disclosure, the intercepted subcode corresponds to the number of interceptions, and therefore, the intercepted subcode obtained by the first interception corresponds to the first field. When the intercepted subcode is within the legal value range of the corresponding field, it is determined that the intercepted subcode is within the legal value range of the network protocol address. For example, when the intercepted subcode is 129 and is within the value range of the first field of a Class B network protocol address, the intercepted subcode is within the legal value range of the network protocol address.

[0197] The above embodiment determines the legal value range of the corresponding field based on the type of the network protocol address and the position of the corresponding field of the intercepted subcode, which helps to increase the diversity of the whitelist verification rules and improve the security of data access.

[0198] In one embodiment, the network protocol address includes multiple fields, with a separator between two adjacent fields; the number of bits of the remaining subcode is within the legal range of bits of the network protocol address, including:

[0199] The number of fields corresponding to the remaining subcodes is obtained, and the number of fields and the maximum number of digits allowed in a field of a network protocol address are processed algorithmically to obtain a legal range of digits.

[0200] In a case where the number of bits of the remaining subcode is within the legal range of bits, it is determined that the number of bits of the remaining subcode is within the legal range of bits of a network protocol address.

[0201] Specifically, taking the IPv4 decimal network protocol address as an example, the remaining sub-code corresponding to the first interception corresponds to 3 fields, and the minimum value of the legal range of digits of the network protocol address corresponding to the remaining sub-code of the first interception is ; Maximum value Therefore, the legal range of the number of digits of the network protocol address corresponding to the remaining sub-code intercepted for the first time is 3-9. Similarly, the minimum value of the legal range of the number of digits of the network protocol address corresponding to the remaining sub-code intercepted for the second time is ; Maximum value , the legal range of digits of the network protocol address corresponding to the remaining subcode intercepted for the second time is 2-6 digits. Similarly, the legal range of digits of the network protocol address corresponding to the remaining subcode intercepted for the third time is 1-3 digits. For example, when the above-mentioned digital code "25525511135" is intercepted for the first time by 2 digits to obtain the remaining subcode "525511135", and the legal range of digits of the network protocol address corresponding to the remaining subcode intercepted for the first time is 3-9, the remaining subcode "5525511135" is 9, and is within the above-mentioned legal range of digits of 3-9. Therefore, the remaining subcode corresponding to the first interception meets the legal range of digits of the network protocol address.

[0202] The above method of performing algorithmic processing on the number of fields and the maximum number of digits allowed in the field of the network protocol address to obtain the legal digit range corresponding to the remaining sub-codes is conducive to deleting illegal network protocol addresses and decoding legal network protocol addresses more quickly.

[0203] In one embodiment, based on each intercepted subcode, a network protocol address set is obtained, including:

[0204] Traversing the intercepted subcodes corresponding to the branch nodes at each layer on the node path to obtain multiple intercepted subcodes; marking two adjacent intercepted subcodes with a separator to obtain the corresponding network protocol address; and obtaining a network protocol address set based on the network protocol address corresponding to each node path.

[0205] The node path may include paths containing branch nodes at each layer, and in a node path, only one branch node at the same layer is selected. In two different node paths, at least one branch node is different. For example, Figure 6 In the example, the node path may include a node path composed of a first-level branch node "255", a second-level branch node "255", a third-level branch node "11", and a fourth-level branch node "135". The node path may also include a node path composed of a first-level branch node "255", a second-level branch node "255", a third-level branch node "111", and a fourth-level branch node "35". It should be noted that the digitally encoded tree model established in accordance with the above embodiment only retains the branch nodes corresponding to the legal intercepted sub-codes, so illegal branch nodes will not form a network protocol address. For example Figure 6 The node path in: the first-level branch node "255", the second-level branch node "255", and the third-level branch node "1" do not constitute a node path.

[0206] In the above embodiment, the intercepted subcodes corresponding to the branch nodes at each layer on the node path are traversed to obtain multiple intercepted subcodes; two adjacent intercepted subcodes are marked with a separator, so that a non-repeated network protocol address can be obtained conveniently and quickly.

[0207] In one embodiment, the performing truncation processing on the digital code to match the truncation digits based on the truncation digits in the truncation digit set includes:

[0208] Get the legal bit range corresponding to the network protocol address;

[0209] In a case where the number of digits of the digital code is within the legal range of digits of the network protocol address, the digital code is subjected to a truncation process that matches the number of truncation digits based on the number of truncation digits in the truncation digit set.

[0210] Specifically, the legal digit range of network protocol addresses expressed in different versions and different bases may be different. For example, IPv4 consists of 4 fields, each of which may consist of 1-3 decimal digits. The legal decimal digit range of IPv4 is 4-12 digits, while the legal binary digit range of IPv4 is 4-32 digits. In an exemplary embodiment, after parsing the digital code, the number of digits of the digital code may be calculated first, and then the digital code may be processed if the number of digits is within the legal digit range of the network protocol address. In another exemplary embodiment, when the number of digits of the parsed digital code does not meet the legal digit range of the network protocol address, for example, the total number of digits of the digital code "126" is 3 digits, which is outside the legal digit range, i.e., it cannot be decoded into a legal network protocol address, and therefore, the request may be directly intercepted.

[0211] In the above embodiment, by setting the legal digit range of the network protocol address, the legality of the digital code is filtered in advance according to the legal digit range before the digital code is intercepted, thereby improving the efficiency of the whitelist verification mechanism.

[0212] In one embodiment, before responding to the network data acquisition request sent by the terminal, the method further includes:

[0213] Select a network protocol address from the stored network protocol address whitelist set;

[0214] The separator of the network protocol address is removed to obtain a digital code for authentication, and the digital code is sent to the terminal.

[0215] Specifically, the network protocol address whitelist may include the terminal's actual network protocol address or a virtual network protocol address, such as a virtual network protocol address obtained by masking the actual network protocol address. In one exemplary embodiment, the network protocol address whitelist may include: 9.187.123.43; 9.187.123.44; and 30.17.13.46. In one exemplary embodiment, any network protocol address from the whitelist, such as 9.187.123.43, may be selected, and the delimiter of the network protocol address may be removed to obtain the digital code used for authentication: 918712343.

[0216] In the above embodiment, a network protocol address is randomly selected from a stored whitelist of network protocol addresses; the delimiters in the network protocol address are removed to obtain a digital code for authentication, and the digital code is sent to a legitimate terminal. Thus, the terminal includes the digital code in a network data acquisition request, and the corresponding network protocol address can be parsed. At least one of the parsed network protocol addresses belongs to the whitelist. For illegitimate terminals, the digital code is not sent to them, and they fail whitelist verification.

[0217] In one embodiment, reference Figure 8 As shown, after obtaining the network protocol address set, it also includes:

[0218] Step S801 : When there is an intersection between the network protocol address set and the whitelist set and there is a target remote call task in the link where the network data acquisition request is located, the target remote call task is added to a message queue.

[0219] Specifically, the network data acquisition request and the target remote call task (RPC) can be transmitted based on the TCP / IP link, and the existence of the target remote call task in the link can be determined by identifying the identifier of the remote call task. In an exemplary embodiment, if the target remote call task exists, the target remote call task is added to the message queue. For example, referring to Figure 9 As shown, add Task 1, Task 2, and Task 3 to the MQ message queue.

[0220] Step S803 : Calculate the ticket allocation waiting time of the target remote call task based on the order in which the remote call tasks are added to the message queue and the number of service tickets required by each remote call task.

[0221] Step S805, returns the ticket allocation waiting time, configures the business ticket of the target remote call task, calls the corresponding call module based on the configured business ticket, obtains the call data corresponding to the request, and returns the call data and the response data corresponding to the request.

[0222] In an exemplary embodiment, an asynchronous ticket allocation method can be used to allocate tickets for each remote call task in the message queue. Figure 9 As shown, Task 1 is first configured with the first business ticket. If Task 1 still has remaining business tickets to configure, it is placed at the end of the queue, awaiting sequential ticket allocation. Then, Task 2 is configured with the first business ticket. If Task 2 still has remaining business tickets to configure, it is placed at the end of the queue, awaiting sequential ticket allocation. Finally, Task 3 is configured with the first business ticket. If Task 3 still has remaining business tickets to configure, it is placed at the end of the queue, awaiting sequential ticket allocation. Next, Task 1 is configured with the second business ticket. This cycle repeats until all three remote call tasks in the message queue are configured.

[0223] In the disclosed embodiment, the number of business tickets required for the remote call task is consistent with the number of modules called by the remote call task. For example, if you need to obtain the shipping data of the XX e-commerce platform, you can use the remote call task to call the service A module, the service B module, the payment service module, and the shipping service module in sequence. Among them, the role of the business ticket is authentication. For example, in the above embodiment, the remote call task directly calls the shipping service, then skips the payment service module, which will cause serious unauthorized access problems. In order to ensure that the remote call task is carried out in an orderly manner, a business ticket is configured for each calling module, such as Figure 10 As shown, the remote call task is called by the service A module to the service B module. The service B module will check the ticket. If there is no business ticket, the remote call task will be intercepted and returned. If the ticket is passed, it will continue to execute.

[0224] In an exemplary embodiment, the basic information of the business ticket can be filled in at the terminal, for example, Figure 11 As shown, the business ticket contains SubType, which indicates the identification information of the business ticket; Business Name, which indicates the service using the business ticket; Person in charge, which indicates the actual person in charge of the business ticket; Validity Period, which indicates the validity period of the business ticket after each planting; PerHour, which indicates the maximum frequency of applying for business tickets per hour; PerDay, which indicates the maximum frequency of applying for business tickets per day; Business Function, which indicates the purpose of using the business ticket; and Application Reason, which indicates the reason for applying for the business ticket. The basic information of the business ticket can be sent to the server along with the request. The server allocates tickets for remote call tasks, that is, configures the calling module (business ticket planting module) and the called module (business ticket verification module). For example, Figure 10 In this example, service A is called the calling module, and service B is called the called module.

[0225] In the embodiment of the present disclosure, before allocating the business tickets for the remote call task, the server can pre-calculate the ticket allocation waiting time of the target task. In the specific implementation process, based on the order in which each remote call task is added to the message queue, determine which remote call tasks exist before the target call task is added, and which remote call tasks exist after the target call task is added. Furthermore, based on the number of business tickets required for each remote call task and the average ticket allocation time for each business ticket, calculate the total number of business tickets configured by the server when all business tickets for the target remote call task are configured, and use this total number and the average ticket allocation time to calculate and obtain the ticket allocation waiting time for the target call task.

[0226] In the above embodiment, before allocating a business ticket for a remote call task, the server can pre-calculate the ticket allocation waiting time of the target task and send the ticket allocation waiting time to the terminal, which is beneficial for the terminal to view the ticket allocation waiting time information in a timely manner.

[0227] In one embodiment, reference Figure 12 As shown, based on the order in which each remote call task is added to the message queue and the number of service tickets required by each remote call task, the ticket allocation waiting time of the target remote call task is calculated, including:

[0228] Step S1201 : determining the array identifier corresponding to each remote call task based on the order in which each remote call task is added to the message queue, and obtaining the current remote call task from the message queue.

[0229] Specifically, refer to Figure 13As shown in the figure, the order in which remote call tasks are added to the message queue is A, B, C, D, E, and F. Remote call task A has a total of 6 different call modules and needs to configure 6 business tickets; remote call task B has a total of 2 different call modules and needs to configure 2 business tickets; remote call task C has a total of 3 different call modules and needs to configure 3 business tickets; remote call task D has a total of 4 different call modules and needs to configure 4 business tickets; remote call task E has a total of 5 different call modules and needs to configure 5 business tickets; remote call task F has a total of 1 different call module and needs to configure 1 business ticket.

[0230] In one embodiment, the remote call task D is used as the target remote call task. Therefore, for the terminal of the target remote call task, it is mainly concerned with the ticket allocation waiting time of the remote call task D. In the embodiment of the present disclosure, an array is used to identify each remote call task, and the order in which the target remote call tasks are added is consistent with the identification information of the array. For example, Figure 13 In the example, the target remote call task D is added as the fourth one, and the array of target remote call tasks is represented as ticket[4].

[0231] Step S1203, when the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, based on the minimum value of the number of calls of the call module corresponding to the current remote call task and the number of calls of the data module corresponding to the target remote call task, determine the time consumed by the current remote call task when the ticket allocation of the target remote call task is completed.

[0232] Among them, the current remote call task can include any remote call task in the message queue, for example: ticket[i] can be used to represent the current remote call task, and ticket[k] identifies the target remote call task. In an exemplary embodiment, if the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, it means that the current remote call task is in front of the target remote call task. In an exemplary embodiment, obtain the number of tickets required to be configured for the current remote call task: ticket[i] corresponds to the number of tickets, obtain the number of tickets required to be configured for the target remote call task: ticket[k] corresponds to the number of tickets. Then when the target remote call task ticket[k] is allocated with tickets, the number of tickets allocated for the current remote call task is: min(number of tickets corresponding to tickets[k], number of tickets corresponding to tickets[i]).

[0233] In an exemplary embodiment, the minimum value is combined with the average processing time of the data module to obtain the current remote call task time when the target remote call task ticket allocation is completed. For example, when the target remote call task ticket[k] is allocated, the time taken for the current remote call task tickets[i] is min(number of tickets corresponding to tickets[k], number of tickets corresponding to tickets[i]) T. Where T represents the average ticket allocation time.

[0234] In a specific embodiment, reference Figure 13 and Figure 14 , the array identifier of the target remote call task D is ticket[k], k=3. The array identifier of the current remote call task A is ticket[i], i=0. Since i is less than k at this time, the corresponding number of tickets for ticket[0] is 5, and the corresponding number of tickets for ticket[3] is 4, and the minimum value is 4. That is, when the target remote call task D completes the ticket allocation, the remote call task A has already allocated 4 tickets. Further, refer to Figure 15 As shown, the array identifier of the current remote call task B is ticket[i], i=1. Since i is less than k at this time, the corresponding number of tickets for ticket[1] is 2, and the corresponding number of tickets for ticket[3] is 4, taking the minimum value of 2. That is, when the target remote call task D completes the ticket allocation, the remote call task B has already been allocated 2 tickets. Further, refer to Figure 16 As shown, the array identifier of the current remote call task C is ticket[i], i=2. Since i is less than k at this time, the number of tickets corresponding to ticket[1] is 3, and the number of tickets corresponding to ticket[3] is 4, taking the minimum value of 3. That is, when the target remote call task D completes the ticket allocation, the remote call task C has already been allocated 3 tickets. Further, refer to Figure 17 As shown in the figure, the array identifier of the current remote call task D is ticket[i], where i = 3. Since i is equal to k at this time, that is, the current remote call task is the same as the target remote call task, the minimum value is 4. That is, when the target remote call task D completes ticket allocation, the remote call task D has already been allocated 4 tickets.

[0235] Step S1205: When the array identifier of the current remote call task is greater than the array identifier of the target remote call task, the number of calls of the data module corresponding to the target remote call task is reduced by a preset threshold to obtain a reference amount. Based on the minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount, the time consumed by the current remote call task when the ticket allocation of the target remote call task is completed is determined.

[0236] In an exemplary embodiment, if the array identifier of the current remote call task is greater than the array identifier of the target remote call task, it indicates that the current remote call task is behind the target remote call task. In an exemplary embodiment, the number of tickets required for the current remote call task is obtained: the number of tickets corresponding to ticket[i], and the number of tickets required for the target remote call task is obtained: the number of tickets corresponding to ticket[k]. Then, when the target remote call task ticket[k] is allocated tickets, the number of tickets allocated for the current remote call task is: min(number of tickets corresponding to tickets[k] - 1, number of tickets corresponding to tickets[i]).

[0237] In an exemplary embodiment, the minimum value is combined with the average processing time of the data module to obtain the current remote call task time when the target remote call task ticket allocation is completed. For example, when the target remote call task ticket[k] is allocated, the time taken for the current remote call task tickets[i] is min(tickets[k] corresponds to the number of tickets - 1, tickets[i] corresponds to the number of tickets) T. T represents the average ticket allocation time, and tickets[k] corresponds to the number of tickets - 1, which represents the reference amount.

[0238] In a specific embodiment, reference Figure 18 As shown, the array identifier of the current remote call task E is ticket[i], i=4. Since i is greater than k at this time, the corresponding number of tickets for ticket[4] is 6. The reference quantity is: the corresponding number of tickets for ticket[3] minus 1 is 3, and the minimum value is 3. That is, when the target remote call task D completes the ticket allocation, the remote call task E has already been allocated 3 tickets. Figure 19 As shown in the figure, the array identifier of the current remote call task F is ticket[i], where i=5. Since i is greater than k at this time, the corresponding ticket number of ticket[5] is 1. The reference quantity is: the corresponding ticket number of ticket[3] minus 1 is 3, and the minimum value is 1. That is, when the target remote call task D completes the ticket allocation, the remote call task F has already been allocated 1 ticket.

[0239] Step S1207: Accumulate the call task consuming time corresponding to each remote call task in the message queue to obtain the ticket allocation waiting time of the target remote call task.

[0240] In an exemplary embodiment, when the target remote call task D in the above embodiment is allocated tickets, the remote call task A needs to take 4×T, the remote call task B needs to take 2×T, the remote call task C needs to take 3×T, the remote call task D needs to take 4×T, the remote call task E needs to take 3×T, and the remote call task F needs to take 1×T, for a total of 17×T. Wherein T represents the average ticket allocation time. In another exemplary embodiment, the remote call task A needs to be configured with 4 tickets, the remote call task B needs to be configured with 2 tickets, the remote call task C needs to be configured with 3 tickets, the remote call task D needs to be configured with 4 tickets, the remote call task E needs to be configured with 3 tickets, and the remote call task F needs to be configured with 1 ticket, for a total of 17 tickets. Assuming the average ticket allocation time is T, the total time required is 17×T.

[0241] In the above embodiment, the current calling task is divided into two types: the calling task before the target calling task and the calling task after the target calling task. The time consumption of the former is equal to the minimum value of the number of votes corresponding to the target calling task and the current calling task before the target calling task is allocated. The time consumption of the latter is equal to the minimum value of the number of votes corresponding to the target calling task after deducting the preset threshold from the current calling task. It complies with the mechanism of asynchronous polling ticket allocation and can accurately calculate the ticket allocation waiting time of the target remote calling task.

[0242] In one embodiment, reference Figure 20 As shown, the business ticket of the target remote call task is configured, including:

[0243] Step S2001 : sorting the remote call tasks based on the order in which the remote call tasks are added to the message queue to obtain an arrangement order.

[0244] Specifically, for example, refer to Figure 13 As shown, the order in which the remote call tasks are added to the message queue includes: A, B, C, D, E, F. The target remote call task is assumed to be remote call task D.

[0245] Step S2003, configure the current calling modules of the target remote calling task and the previous remote calling task in sequence according to the arrangement order. If all calling modules of the target remote calling task have not been configured, configure the current calling modules of the remote calling tasks after the target remote calling task in sequence.

[0246] Specifically, for example, ticket allocation is performed sequentially for ticket 1 of remote call task A, ticket allocation is performed for ticket 1 of remote call task B, ticket allocation is performed for ticket 1 of remote call task C, and ticket allocation is performed for ticket 1 of remote call task D. Since remote call task D requires a total of four tickets, ticket allocation for remote call task D is not completed, and ticket allocation continues for ticket 1 of remote call task E and ticket 1 of remote call task F.

[0247] Step S2005 , sequentially configuring the target remote calling task and the next calling module of the previous remote calling task until all calling modules of the target remote calling task are configured.

[0248] Specifically, for example, ticket allocation is performed sequentially for remote call task A's ticket 2, remote call task B's ticket 2, remote call task C's ticket 2, and remote call task D's ticket 2. Since remote call task D requires a total of four tickets, and remote call task D has not yet completed ticket allocation, ticket allocation continues for remote call task E's ticket 2, and then for remote call task F's ticket 2. This continues in this order. Once ticket allocation is completed for remote call task D's ticket 4, ticket allocation for the target remote call task D is complete.

[0249] In one embodiment, a method for processing a network data acquisition request is proposed, which is applied to a terminal and includes:

[0250] A network data acquisition request is sent to a server; wherein the server is used to parse a preset field of the network data acquisition request to obtain a digital code for authentication, wherein the digital code includes a truncated digit based on a truncated digit set, performing a truncation process on the digital code to match the truncated digit, obtaining a truncated subcode and a remaining subcode after truncation, and when the truncated subcode and the remaining subcode both meet the legal conditions of the network protocol address, continuing to perform truncation process on the truncated subcode to match the truncated digit until all the digital codes are truncated; wherein the truncated digit set includes at least two truncated digits in a legal digit range corresponding to the network protocol address, and the truncated subcode and the remaining subcode both meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address and that the digits of the remaining subcode are within the corresponding legal digit range; based on each truncated subcode, a network protocol address set is obtained, and when there is an intersection between the network protocol address set and a whitelist set, the network data acquisition request is sent to a network data server.

[0251] Receive response data returned by the server.

[0252] Specifically, the terminal may include a user terminal with a network data acquisition requirement, such as a terminal of a service developer or a terminal of a data user. The terminal may send a network data acquisition request to the server by logging in or calling a server interface.

[0253] In an exemplary embodiment, a digital code for authentication can be written in the request body. The server obtains the digital code for authentication by parsing network data to obtain a preset field in the request. The digital code for authentication can include an unsigned integer type code, and optionally, a uint64 type code can be used as the digital code.

[0254] The network protocol address can include different versions of network protocol addresses, such as IPv4 and IPv6. Taking IPv4 as an example, it uses a 32-bit binary representation, which can be expressed as four decimal numbers separated by the delimiter ".". Each decimal number has a value range of 0-255, such as 210.21.196.6. Therefore, since the value range is fixed, the number of bits used to intercept the digital code after receiving it is limited. For the network protocol address IPv4, the interception bit can include 1 bit, 2 bits, or 3 bits. In this case, the interception set can include 1 bit, 2 bits, and 3 bits. It will be understood that the above interception bit is for IPv4 expressed in decimal. When IPv4 is expressed in binary, the interception bit increases. For example, the decimal number 210 is represented as the binary number 11010010, and the interception bit increases from 3 bits to 8 bits. It should be noted that due to different versions of the network protocol address, the value range of the field will also change. For example, the value range of each field in IPv6 is 0-FFFF (hexadecimal), and the truncated bit number can include 1 bit, 2 bits, 3 bits, and 4 bits. Therefore, the truncated bit number is related to the version of the network protocol address and the base number used. Inspired by the technical essence of this application, technical personnel in the relevant field can select the truncated bit number set according to the network protocol address version and the base number used. However, as long as the functions and effects achieved are the same or similar to those of this application, they should be covered within the scope of protection of this application.

[0255] In the disclosed embodiment, the truncated subcode may include the code obtained after each truncation operation of the digital code occurs, and the remaining subcode may include the subcode remaining after the truncation subcode corresponding to each truncation operation is removed from the digital code. For example, in the digital code "25525511135", if one digit is truncated, the resulting truncated subcode is "2", and the remaining subcode is "5525511135". If two digits are truncated, the resulting truncated subcode is "25", and the remaining subcode is "525511135".

[0256] In an exemplary embodiment, taking the decimal network protocol address of IPv4 as an example, the legal value range of the field is 0-255. When the above digital code "25525511135" is truncated by 1 bit for the first time and the truncated sub-code "2" is obtained, since "2" is in the legal value range of 0-255, the truncated sub-code is in the legal value range of the network protocol address.

[0257] In an exemplary embodiment, each field of the IPv4 decimal network protocol address has a maximum of 3 digits and a minimum of 1 digit, with a total of 4 fields. Therefore, the legal range of digits of the IPv4 decimal network protocol address is 4-12 digits. The corresponding remaining subcode after the first interception corresponds to 3 fields. Therefore, the legal range of digits of the network protocol address corresponding to the remaining subcode intercepted for the first time is 3-9 digits. Similarly, the legal range of digits of the network protocol address corresponding to the remaining subcode intercepted for the second time is 2-6 digits. The legal range of digits of the network protocol address corresponding to the remaining subcode intercepted for the third time is 1-3 digits. In an exemplary embodiment, when the intercepted subcode and the remaining subcode both meet the legal conditions of the network protocol address, the intercepted subcode continues to be intercepted to match the intercepted digits until all of the digital codes are intercepted.

[0258] In the disclosed embodiment, the number of interceptions of the digital code varies depending on the version of the network protocol address. For example, IPv4 uses three "." delimiters to divide the network protocol address into four fields, while IPv6 uses four ":" delimiters to divide the network protocol address into eight fields. Therefore, the total number of interceptions for different versions of the network protocol address can be different. In the disclosed embodiment, each interception sub-code includes the sum of the legal interception sub-codes obtained for each interception, given the total number of interceptions that matches the version of the network protocol address. Of course, the number of intercepted bits can vary, and there are many ways to intercept the digital code. For example, interception method A: intercept 1 bit the first time, intercept 2 bits the second time... Interception method B: intercept 2 bits the first time, intercept 2 bits the second time... Regardless of how the interception is performed subsequently, interception method A and interception method B are considered different interception methods. In an exemplary embodiment, each interception sub-code includes the legal interception sub-codes obtained from all possible interception methods of the corresponding digital code.

[0259] In one exemplary embodiment, the legal interception subcodes corresponding to the same interception method are concatenated to obtain the corresponding network protocol address. For example, the digital code "25525511135" is intercepted using the first interception method, i.e., intercepting 3 digits for the first time, intercepting 3 digits for the second time, and intercepting 2 digits for the third time, resulting in four interception subcodes: "255," "255," "11," and "135," respectively. Based on these four interception subcodes, the network protocol address is: 255.255.11.135. For another example, the digital code "25525511135" is intercepted using the second interception method, i.e., intercepting 3 digits for the first time, intercepting 3 digits for the second time, and intercepting 3 digits for the third time, resulting in four interception subcodes: "255," "255," "111," and "35," respectively. Based on these four interception subcodes, the network protocol address is: 255.255.111.35. Both the network protocol address 255.255.11.135 and the network protocol address 255.255.111.35 can be added to the network protocol address set.

[0260] In one exemplary embodiment, if the network protocol address set intersects with a stored network protocol address whitelist, indicating that the terminal has access rights, a network data acquisition request is sent to the network data server. The network data acquisition request is sent to the network data server, and the response data returned by the network data server is sent to the terminal. In another exemplary embodiment, if the network protocol address set does not intersect with the stored network protocol address whitelist, indicating that the terminal does not have access rights, the network data acquisition request can be directly intercepted.

[0261] In the above embodiment, an unsigned integer type digital code is carried in a network data acquisition request, and a digital code for authentication is obtained by parsing the request, which can save data storage space and improve the efficiency of data processing. Furthermore, the embodiment of the present disclosure performs interception processing on the digital code based on the interception bit number in the interception bit set, wherein the interception bit number can select at least two interception bit numbers in the legal bit range corresponding to the network protocol address, that is, the interception sub-code can be in a variety of bit numbers, such as 1 bit or 3 bits, etc., so that the generated network protocol address field is richer and more diverse. For example, compared with the traditional IPv4 decimal digital code that needs to be written in full 12 bits, the above decoding method can relax the number of bits of the digital code to 4-12 bits, which greatly improves the diversity of the digital code, thereby increasing the accuracy and reliability of verification.

[0262] In one embodiment, the link where the network data acquisition request is located also includes a target remote call task, and receiving the response data returned by the server includes:

[0263] Receive the ticket allocation waiting time and corresponding data returned by the server; wherein, the ticket allocation waiting time includes the ticket allocation waiting time of the target remote call task calculated by the server by adding the target remote call task to the message queue, based on the order of adding each remote call task in the message queue, and the number of business tickets required for each remote call task.

[0264] Specifically, the network data acquisition request and the target remote call task (RPC) can be transmitted based on the TCP / IP link, and the existence of the target remote call task in the link can be determined by identifying the identifier of the remote call task. In an exemplary embodiment, if the target remote call task exists, the target remote call task is added to the message queue. For example, referring to Figure 9 As shown, add Task 1, Task 2, and Task 3 to the MQ message queue.

[0265] In an exemplary embodiment, an asynchronous ticket allocation method can be used to allocate tickets for each remote call task in the message queue. Figure 9 As shown, Task 1 is first configured with the first business ticket. If Task 1 still has remaining business tickets to configure, it is placed at the end of the queue, awaiting sequential ticket allocation. Then, Task 2 is configured with the first business ticket. If Task 2 still has remaining business tickets to configure, it is placed at the end of the queue, awaiting sequential ticket allocation. Finally, Task 3 is configured with the first business ticket. If Task 3 still has remaining business tickets to configure, it is placed at the end of the queue, awaiting sequential ticket allocation. Next, Task 1 is configured with the second business ticket. This cycle repeats until all three remote call tasks in the message queue are configured.

[0266] In the embodiment of the present disclosure, before allocating the business tickets for the remote call task, the server can pre-calculate the ticket allocation waiting time of the target task. In the specific implementation process, based on the order in which each remote call task is added to the message queue, determine which remote call tasks exist before the target call task is added, and which remote call tasks exist after the target call task is added. Furthermore, based on the number of business tickets required for each remote call task and the average ticket allocation time for each business ticket, calculate the total number of business tickets configured by the server when all business tickets for the target remote call task are configured, and use this total number and the average ticket allocation time to calculate and obtain the ticket allocation waiting time for the target call task.

[0267] In the above embodiment, before allocating a business ticket for a remote call task, the server can pre-calculate the ticket allocation waiting time of the target task, which is helpful for the terminal to view the information of the ticket allocation waiting time in a timely manner.

[0268] In one embodiment, before sending the network data acquisition request to the server, the method further includes:

[0269] Obtain a network protocol address whitelist set, and select any network protocol address from the whitelist set;

[0270] The separator of the network protocol address is removed to obtain a digital code for authentication.

[0271] Specifically, the network protocol address whitelist may include the terminal's actual network protocol address or a virtual network protocol address, such as a virtual network protocol address obtained by masking the actual network protocol address. In one exemplary embodiment, the network protocol address whitelist may include: 9.187.123.43; 9.187.123.44; and 30.17.13.46. In one exemplary embodiment, any network protocol address from the whitelist, such as 9.187.123.43, may be selected, and the delimiter of the network protocol address may be removed to obtain the digital code used for authentication: 918712343.

[0272] In the above embodiment, a network protocol address is randomly selected from a stored whitelist of network protocol addresses; the delimiters in the network protocol address are removed to obtain a digital code for authentication. The terminal then carries this digital code in a network data acquisition request, thereby resolving the corresponding network protocol address. At least one of the resolved network protocol addresses must be in the whitelist. Illegal terminals cannot obtain a whitelist address and therefore cannot pass whitelist verification.

[0273] In a specific embodiment, the method of the present application can be applied to scenarios where data is obtained through requests and remote procedure calls. In the prior art, digital codes are carried in requests for whitelist verification. Among them, the total number of digits in the digital code needs to reach the maximum legal number of digits of the network protocol address. For example, the maximum legal number of digits for IPv4 is 12 digits, and the digital code needs to be filled with 12 digits, such as 255.218.134.124. This limits the diversity of digital codes to a certain extent, and also reduces the difficulty of implementing illegal network data acquisition requests. The present application provides a method for processing network data acquisition requests, which can increase the diversity of digital codes.

[0274] refer to Figure 21 As shown, the embodiment of the present disclosure includes the following stages: request acquisition stage, digital encoding and decoding stage, whitelist verification stage, remote call task confirmation stage, remote call task waiting time calculation stage, ticket allocation and data return stage.

[0275] During the request acquisition phase, the terminal can send a network data acquisition request to the server by logging in or calling the server interface.

[0276] In the digital code decoding stage, the digital code is selected as the root node, and based on the minimum truncated digit in the truncated digit set, the minimum truncated digit of the digital code is truncated to obtain the truncated subcode corresponding to the first-level branch node and the remaining subcode after truncating; wherein the first-level branch node is a child of the root node. If the truncated subcode and the remaining subcode corresponding to the first-level branch node both meet the legal conditions of the network protocol address, the minimum truncated digit of the remaining subcode corresponding to the first-level branch node is continued to be truncated to obtain the truncated subcode and the remaining subcode corresponding to the second-level branch node. If the truncated subcode and the remaining subcode corresponding to the second-level branch node both meet the legal conditions of the network protocol address, the minimum truncated digit of the remaining subcode corresponding to the second-level branch node is continued to be truncated until the digital code is completely truncated.

[0277] In the case that at least one of the truncated subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legal conditions of the network protocol address, the first-layer branch node is deleted, and the minimum truncated bit number is added to the unit step size to obtain the truncated bit number for one update. The truncated bit number for the one update of the digital code is intercepted to obtain the truncated subcode corresponding to another first-layer branch node and the remaining subcode after truncation. In the case that the node path corresponding to the other first-layer branch node is completely intercepted, the truncated bit number for the one update is added to the unit step size to obtain the truncated bit number for the second update. The truncated bit number for the second update of the digital code is intercepted until all the digital codes are completely intercepted.

[0278] During the whitelist verification phase, if the network protocol address set intersects with the stored network protocol address whitelist, the terminal has access rights and a network data acquisition request is sent to the network data server. The network data acquisition request is sent to the network data server, and the response data returned by the network data server is sent to the terminal. If the network protocol address set does not intersect with the stored network protocol address whitelist, the terminal does not have access rights and the network data acquisition request is directly intercepted.

[0279] In the remote call task confirmation phase, the network data acquisition request and the target remote call task (RPC) can be transmitted over a TCP / IP link. The identification of the remote call task can be used to determine whether the target remote call task exists in the link. If the target remote call task exists, it is added to the message queue.

[0280] During the remote call task waiting time calculation phase, the array identifiers corresponding to each remote call task are determined based on the order in which the remote call tasks were added to the message queue, and the current remote call task is retrieved from the message queue. If the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, the duration of the current remote call task when ticket allocation for the target remote call task is completed is determined based on the minimum of the number of calls to the call module corresponding to the current remote call task and the number of calls to the data module corresponding to the target remote call task. If the array identifier of the current remote call task is greater than the array identifier of the target remote call task, the number of calls to the data module corresponding to the target remote call task is subtracted by a preset threshold to obtain a reference value. Based on the minimum of the number of calls to the data module corresponding to the current remote call task and the reference value, the duration of the current remote call task when ticket allocation for the target remote call task is completed is determined. The duration of the call tasks corresponding to each remote call task in the message queue is accumulated to obtain the ticket allocation waiting time for the target remote call task.

[0281] During the ticket allocation and data return phase, the remote call tasks are sorted based on the order in which they were added to the message queue to obtain a ranking order. Following this ranking order, the current calling modules of the target remote call task and the previous remote call task are sequentially configured. If all calling modules of the target remote call task have not been configured, the current calling modules of the remote call task following the target remote call task are sequentially configured. The next calling modules of the target remote call task and the previous remote call task are sequentially configured until all calling modules of the target remote call task are configured.

[0282] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0283] Based on the same inventive concept, embodiments of the present application also provide a network data acquisition request processing device for implementing the aforementioned method for processing network data acquisition requests. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of the one or more network data acquisition request processing device embodiments provided below can be found in the limitations of the network data acquisition request processing method described above and will not be repeated here.

[0284] In one embodiment, Figure 22 As shown, a device 2200 for processing a network data acquisition request is provided, which is applied to a server and includes:

[0285] The parsing module 2201 is configured to respond to a network data acquisition request sent by a terminal, parse a preset field of the network data acquisition request, and obtain a digital code for authentication;

[0286] The interception processing module 2203 is configured to perform interception processing on the digital code based on the number of intercepted digits in the interception digit set to match the number of intercepted digits, thereby obtaining a intercepted subcode and a remaining subcode after the interception, and, if both the intercepted subcode and the remaining subcode satisfy the legality condition of the network protocol address, continue to perform interception processing on the intercepted subcode to match the number of intercepted digits until all of the digital code is intercepted. The interception digit set includes at least two intercepted digits within a legal range of digits corresponding to the network protocol address, and both the intercepted subcode and the remaining subcode satisfy the legality condition of the network protocol address, including that the intercepted subcode is within a legal range of values ​​for the network protocol address and that the number of digits of the remaining subcode is within a corresponding legal range of digits.

[0287] The verification module 2205 is used to obtain a network protocol address set based on each intercepted sub-code, and when there is an intersection between the network protocol address set and the stored network protocol address whitelist set, send the network data acquisition request to the network data server, and send the response data returned by the network data server to the terminal.

[0288] In one embodiment, the interception processing module is further configured to:

[0289] Selecting the digital code as a root node, truncating the minimum truncated digit of the digital code based on the minimum truncated digit in the truncated digit set, and obtaining a truncated sub-code corresponding to a first-level branch node and a remaining sub-code after truncating; wherein the first-level branch node is a child node of the root node;

[0290] When the truncated subcode and the remaining subcode corresponding to the first-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the first-layer branch node to obtain the truncated subcode and the remaining subcode corresponding to the second-layer branch node. When the truncated subcode and the remaining subcode corresponding to the second-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the second-layer branch node until all the digital codes are intercepted.

[0291] In one embodiment, the interception processing module is further configured to:

[0292] If at least one of the truncated subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, the first-layer branch node is deleted, and the minimum truncated bit number is added to the unit step size to obtain an updated truncated bit number;

[0293] truncating the number of truncated bits of the digital code for the first update to obtain a truncated sub-code corresponding to another first-layer branch node and a remaining sub-code after truncating;

[0294] When the node path corresponding to the other first-layer branch node is completely intercepted, the number of intercepted bits of the first update is added to the unit step size to obtain the number of intercepted bits of the second update;

[0295] The number of truncated digits of the second update of the digital code is truncated until all the digital codes are truncated.

[0296] In one embodiment, the interception processing module is further configured to:

[0297] Selecting the digital code as a root node, obtaining truncated digits from the truncated digit set, truncating the digital code according to the truncated digits, and obtaining truncated sub-codes corresponding to all first-level branch nodes and remaining sub-codes after truncation; wherein the first-level branch nodes are child nodes of the root node;

[0298] It is judged whether the truncated subcode and the remaining subcode corresponding to each first-layer branch node meet the legal conditions of the network protocol address, and the truncated bit number is continuously obtained from the truncated bit number set. The remaining subcode corresponding to each legal first-layer branch node is truncated according to the truncated bit number, and the truncated subcodes corresponding to all second-layer branch nodes and the truncated remaining subcodes are obtained, until all the remaining subcodes corresponding to the last-layer branch nodes are truncated.

[0299] In one embodiment, the interception processing module is further configured to:

[0300] If at least one of the intercepted subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, determining that the first-layer branch node is illegal;

[0301] Delete the illegal first-layer branch nodes.

[0302] In one embodiment, the network protocol address includes multiple fields, and a separator is provided between two adjacent fields; the interception processing module is further configured to:

[0303] Determining a legal value range of the corresponding field according to the type of the network protocol address and the position of the corresponding field of the intercepted subcode;

[0304] When the intercepted subcode is within the legal value range of the corresponding field, it is determined that the intercepted subcode is within the legal value range of the network protocol address.

[0305] In one embodiment, the network protocol address includes multiple fields, and a separator is provided between two adjacent fields; the interception processing module is further configured to:

[0306] Obtain the number of fields corresponding to the remaining subcodes, and perform algorithmic processing on the number of fields and the maximum number of bits allowed in a field of a network protocol address to obtain a legal range of bits;

[0307] In a case where the number of bits of the remaining subcode is within the legal range of bits, it is determined that the number of bits of the remaining subcode is within the legal range of bits of a network protocol address.

[0308] In one embodiment, the verification module is further configured to:

[0309] Traversing the intercepted sub-codes corresponding to the branch nodes at each layer on the node path to obtain multiple intercepted sub-codes;

[0310] Mark two adjacent intercepted sub-codes with a separator to obtain the corresponding network protocol address;

[0311] Based on the network protocol addresses corresponding to the paths of each node, a network protocol address set is obtained.

[0312] In one embodiment, the interception processing module is further configured to:

[0313] Get the legal bit range corresponding to the network protocol address;

[0314] In a case where the number of digits of the digital code is within the legal range of digits of the network protocol address, the digital code is subjected to a truncation process that matches the number of truncation digits based on the number of truncation digits in the truncation digit set.

[0315] In one embodiment, the apparatus further comprises:

[0316] A selection module, configured to select any network protocol address from a stored network protocol address whitelist set;

[0317] The digital code generating module is used to remove the separator of the network protocol address to obtain the digital code for authentication, and send the digital code to the terminal.

[0318] In one embodiment, the apparatus further comprises:

[0319] an adding module, configured to add the target remote call task to the message queue if there is an intersection between the network protocol address set and the whitelist set and there is a target remote call task in the link where the network data acquisition request is located;

[0320] A calculation module, configured to calculate a ticket allocation waiting time for the target remote call task based on the order in which the remote call tasks are added to the message queue and the number of service tickets required for each remote call task;

[0321] The data return module is used to return the ticket allocation waiting time, configure the business ticket of the target remote call task, call the corresponding call module based on the configured business ticket, obtain the call data corresponding to the network data acquisition request, and return the call data and the response data corresponding to the network data acquisition request.

[0322] In one embodiment, the calculation module is further configured to:

[0323] Determine the array identifier corresponding to each remote call task based on the order in which each remote call task is added to the message queue, and obtain the current remote call task from the message queue;

[0324] When the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, determining the time taken for the current remote call task to be completed when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the call module corresponding to the current remote call task and the number of calls of the data module corresponding to the target remote call task;

[0325] If the array identifier of the current remote call task is greater than the array identifier of the target remote call task, subtract a preset threshold from the number of calls of the data module corresponding to the target remote call task to obtain a reference amount, and determine the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount;

[0326] The call task consuming time corresponding to each remote call task in the message queue is accumulated to obtain the ticket allocation waiting time of the remote call task.

[0327] In one embodiment, the calculation module is further configured to:

[0328] Obtaining a minimum value between the number of calls to the data module corresponding to the current remote call task and the number of calls to the data module corresponding to the remote call task;

[0329] The minimum value is combined with the average processing time of the data module to obtain the current remote call task time when the target remote call task ticket allocation is completed.

[0330] In one embodiment, the calculation module is further configured to:

[0331] The minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount;

[0332] The minimum value is combined with the average ticket allocation time of the data module to obtain the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed.

[0333] In one embodiment, the data return module is further configured to:

[0334] Sorting the remote call tasks based on the order in which they are added to the message queue to obtain an arrangement order;

[0335] According to the arrangement order, the current calling modules of the target remote calling task and the previous remote calling task are sequentially configured; if all calling modules of the target remote calling task have not been configured, the current calling modules of the remote calling tasks after the target remote calling task are sequentially configured;

[0336] The next calling module of the target remote calling task and the previous remote calling task is configured in sequence until all calling modules of the target remote calling task are configured.

[0337] In a fourth aspect, the present application also provides a device for processing a network data acquisition request. Figure 23 As shown, applied to a terminal, the device 2300 includes:

[0338] The sending module 2301 is used to send a network data acquisition request to the server;

[0339] The server is used to parse the preset field of the network data acquisition request to obtain a digital code for authentication, wherein the digital code includes a truncated digit based on a truncated digit set, performing a truncation process on the digital code to match the truncated digit, obtaining a truncated subcode and a remaining subcode after truncation, and when both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, continuing to perform truncation process on the truncated subcode to match the truncated digit until all the digital codes are truncated; wherein the truncated digit set includes at least two truncated digits in a legal digit range corresponding to the network protocol address, and both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address and that the digits of the remaining subcode are within the corresponding legal digit range; based on each truncated subcode, a network protocol address set is obtained, and when there is an intersection between the network protocol address set and a whitelist set, the network data acquisition request is sent to the network data server;

[0340] The receiving module 2303 is configured to receive the response data returned by the server.

[0341] In one embodiment, the receiving module is further configured to:

[0342] Receive the ticket allocation waiting time and corresponding data returned by the server; wherein, the ticket allocation waiting time includes the ticket allocation waiting time of the target remote call task calculated by the server by adding the target remote call task to the message queue, based on the order of adding each remote call task in the message queue, and the number of business tickets required for each remote call task.

[0343] In one embodiment, the apparatus further comprises:

[0344] An acquisition module is used to acquire a network protocol address whitelist set and select any network protocol address from the whitelist set;

[0345] The digital code generating module is used to remove the separator of the network protocol address to obtain the digital code for authentication.

[0346] Each module in the aforementioned network data acquisition request processing device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.

[0347] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 24 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store processing data of network data acquisition requests. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for processing network data acquisition requests is implemented.

[0348] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 25 As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal via wired or wireless communication, and the wireless communication can be achieved via Wi-Fi, a mobile cellular network, NFC (near-field communication), or other technologies. When executed by the processor, the computer program implements a method for processing network data acquisition requests. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse, etc.

[0349] Those skilled in the art will understand that Figure 25The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0350] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0351] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0352] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0353] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for processing a network data acquisition request, characterized in that: Applied to a server, the method includes: In response to a network data acquisition request sent by a terminal, parsing a preset field of the network data acquisition request to obtain a digital code for authentication; Based on the number of truncated digits in the truncated digit set, the digital code is subjected to a truncation process that matches the number of truncated digits to obtain a truncated subcode and a remaining subcode after truncation. If both the truncated subcode and the remaining subcode satisfy the legality condition of the network protocol address, the truncation process that matches the number of truncated digits is continued on the truncated subcode until all the digital codes are truncated. The truncated digit set includes at least two truncated digits within a legal range of digits corresponding to the network protocol address, and both the truncated subcode and the remaining subcode satisfy the legality condition of the network protocol address, including that the truncated subcode is within a legal range of values ​​for the network protocol address, and that the number of digits of the remaining subcode is within a corresponding legal range of digits. Based on each intercepted sub-code, a network protocol address set is obtained. When there is an intersection between the network protocol address set and a stored network protocol address whitelist set, the network data acquisition request is sent to a network data server, and the response data returned by the network data server is sent to the terminal.

2. The method according to claim 1, characterized in that The method further comprises: performing a truncation process on the digital code to match the number of truncation digits based on the number of truncation digits in the truncation digit set to obtain a truncation subcode and a remaining subcode after truncation; and continuing to perform a truncation process on the truncation subcode to match the number of truncation digits when both the truncation subcode and the remaining subcode meet the legality condition of the network protocol address until all the digital codes are truncation is completed. Selecting the digital code as a root node, and based on a minimum truncated digit in a truncated digit set, truncating the minimum truncated digit of the digital code to obtain a truncated sub-code corresponding to a first-level branch node and a remaining sub-code after truncating; wherein the first-level branch node is a child node of the root node; When the truncated subcode and the remaining subcode corresponding to the first-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the first-layer branch node to obtain the truncated subcode and the remaining subcode corresponding to the second-layer branch node. When the truncated subcode and the remaining subcode corresponding to the second-layer branch node both meet the legal conditions of the network protocol address, continue to intercept the minimum number of truncated digits of the remaining subcode corresponding to the second-layer branch node until all the digital codes are intercepted.

3. The method according to claim 2, characterized in that After obtaining the truncated subcode corresponding to the first-layer branch node and the remaining truncated subcode, the method further includes: If at least one of the truncated subcode and the remaining subcode corresponding to the first-layer branch node does not meet the legality condition of the network protocol address, the first-layer branch node is deleted, and the minimum truncated bit number is added to the unit step size to obtain an updated truncated bit number; truncating the number of truncated bits of the digital code for the first update to obtain a truncated sub-code corresponding to another first-layer branch node and a remaining sub-code after truncating; When the node path corresponding to the other first-layer branch node is completely intercepted, the number of intercepted bits of the first update is added to the unit step size to obtain the number of intercepted bits of the second update; The number of truncated digits of the second update of the digital code is truncated until all the digital codes are truncated.

4. The method according to claim 1, wherein The method further comprises: performing a truncation process on the digital code to match the number of truncation digits based on the number of truncation digits in the truncation digit set to obtain a truncation subcode and a remaining subcode after truncation; and continuing to perform a truncation process on the truncation subcode to match the number of truncation digits when both the truncation subcode and the remaining subcode meet the legality condition of the network protocol address until all the digital codes are truncation is completed. Selecting the digital code as a root node, obtaining truncated digits from the truncated digit set, truncating the digital code according to the truncated digits, and obtaining truncated sub-codes corresponding to all first-level branch nodes and remaining sub-codes after truncation; wherein the first-level branch nodes are child nodes of the root node; It is judged whether the truncated subcode and the remaining subcode corresponding to each first-layer branch node meet the legal conditions of the network protocol address, and the truncated bit number is continuously obtained from the truncated bit number set. The remaining subcode corresponding to each legal first-layer branch node is truncated according to the truncated bit number, and the truncated subcodes corresponding to all second-layer branch nodes and the truncated remaining subcodes are obtained, until all the remaining subcodes corresponding to the last-layer branch nodes are truncated.

5. The method according to claim 1, characterized in that The network protocol address includes multiple fields, with a separator between two adjacent fields; the intercepted sub-code is within the legal value range of the network protocol address, including: Determining a legal value range of the corresponding field according to the type of the network protocol address and the position of the corresponding field of the intercepted subcode; When the intercepted subcode is within the legal value range of the corresponding field, it is determined that the intercepted subcode is within the legal value range of the network protocol address.

6. The method according to claim 1, characterized in that The network protocol address includes multiple fields, with a separator between two adjacent fields; the number of bits of the remaining sub-code is within the legal range of bits of the network protocol address, including: Obtain the number of fields corresponding to the remaining subcodes, and perform algorithmic processing on the number of fields and the maximum number of bits allowed in a field of a network protocol address to obtain a legal range of bits; In a case where the number of bits of the remaining subcode is within the legal range of bits, it is determined that the number of bits of the remaining subcode is within the legal range of bits of a network protocol address.

7. The method according to claim 1, characterized in that Before responding to the network data acquisition request sent by the terminal, the method further includes: Select a network protocol address from the stored network protocol address whitelist set; The separator of the network protocol address is removed to obtain a digital code for authentication, and the digital code is sent to the terminal.

8. The method according to claim 1, characterized in that After obtaining the network protocol address set, it also includes: If there is an intersection between the network protocol address set and the whitelist set and there is a target remote call task in the link where the network data acquisition request is located, adding the target remote call task to the message queue; Calculate the ticket allocation waiting time of the target remote call task based on the order in which the remote call tasks are added to the message queue and the number of service tickets required by each remote call task; Return the ticket allocation waiting time, configure the business ticket of the target remote call task, call the corresponding call module based on the configured business ticket, obtain the call data corresponding to the network data acquisition request, and return the call data and the response data corresponding to the network data acquisition request.

9. The method according to claim 8, characterized in that Based on the order in which each remote call task is added to the message queue and the number of service tickets required by each remote call task, the ticket allocation waiting time of the target remote call task is calculated, including: Determine the array identifier corresponding to each remote call task based on the order in which each remote call task is added to the message queue, and obtain the current remote call task from the message queue; When the array identifier of the current remote call task is less than or equal to the array identifier of the target remote call task, determining the time taken for the current remote call task to be completed when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the call module corresponding to the current remote call task and the number of calls of the data module corresponding to the target remote call task; If the array identifier of the current remote call task is greater than the array identifier of the target remote call task, subtract a preset threshold from the number of calls of the data module corresponding to the target remote call task to obtain a reference amount, and determine the time consumption of the current remote call task when the ticket allocation of the target remote call task is completed based on the minimum value of the number of calls of the data module corresponding to the current remote call task and the reference amount; The call task consuming time corresponding to each remote call task in the message queue is accumulated to obtain the ticket allocation waiting time of the remote call task.

10. A method for processing a network data acquisition request, characterized in that: Applied to a terminal, the method includes: Send a network data acquisition request to the server; The server is used to parse the preset field of the network data acquisition request to obtain a digital code for authentication, wherein the digital code includes a truncated digit based on a truncated digit set, performing a truncation process on the digital code to match the truncated digit, obtaining a truncated subcode and a remaining subcode after truncation, and when both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, continuing to perform truncation process on the truncated subcode to match the truncated digit until all the digital codes are truncated; wherein the truncated digit set includes at least two truncated digits in a legal digit range corresponding to the network protocol address, and both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address and that the digits of the remaining subcode are within the corresponding legal digit range; based on each truncated subcode, a network protocol address set is obtained, and when there is an intersection between the network protocol address set and a whitelist set, the network data acquisition request is sent to the network data server; Receive response data returned by the server.

11. A device for processing network data acquisition requests, characterized in that: Applied to a server, the device includes: a parsing module, configured to respond to a network data acquisition request sent by a terminal, parse a preset field of the network data acquisition request, and obtain a digital code for authentication; a truncation processing module, configured to perform truncation processing on the digital code based on the number of truncation digits in the truncation digit set to match the number of truncation digits, thereby obtaining a truncation subcode and a remaining subcode after truncation; and, if both the truncation subcode and the remaining subcode satisfy a network protocol address legality condition, continue to perform truncation processing on the truncation subcode to match the number of truncation digits until all of the digital code is truncation; wherein the truncation digit set includes at least two truncation digits within a legal range of digits corresponding to the network protocol address, and the truncation subcode and the remaining subcode satisfying the network protocol address legality condition include the truncation subcode being within a legal range of values ​​for the network protocol address, and the number of digits of the remaining subcode being within a corresponding legal range of digits; The verification module is used to obtain a network protocol address set based on each intercepted sub-code, and when there is an intersection between the network protocol address set and a stored network protocol address whitelist set, send the network data acquisition request to the network data server, and send the response data returned by the network data server to the terminal.

12. A device for processing network data acquisition requests, characterized in that: Applied to a terminal, the device includes: A sending module is used to send a network data acquisition request to the server; The server is used to parse the preset field of the network data acquisition request to obtain a digital code for authentication, wherein the digital code includes a truncated digit based on a truncated digit set, performing a truncation process on the digital code to match the truncated digit, obtaining a truncated subcode and a remaining subcode after truncation, and when both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, continuing to perform truncation process on the truncated subcode to match the truncated digit until all the digital codes are truncated; wherein the truncated digit set includes at least two truncated digits in a legal digit range corresponding to the network protocol address, and both the truncated subcode and the remaining subcode meet the legal conditions of the network protocol address, including that the truncated subcode is within the legal value range of the network protocol address and that the digits of the remaining subcode are within the corresponding legal digit range; based on each truncated subcode, a network protocol address set is obtained, and when there is an intersection between the network protocol address set and a whitelist set, the network data acquisition request is sent to the network data server; The receiving module is used to receive the response data returned by the server.

13. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 9 or the steps of the method according to any one of claim 10 are implemented.

14. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 or the steps of the method according to any one of claim 10 are implemented.

15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 or the steps of the method according to any one of claim 10 are implemented.