Request processing method, task processing method, device and equipment
By identifying the target operating system user identifier within the AI agent and running the MCP service process accordingly, the data security risks caused by excessive privileges of the MCP service are resolved, achieving secure resource access control and a stable processing flow.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
- Filing Date
- 2026-01-27
- Publication Date
- 2026-05-08
AI Technical Summary
In existing technologies, when AI agents process complex business logic, excessive privileges granted by the MCP service lead to data security risks, making it difficult to effectively guarantee the security of resource access.
By receiving service call requests from intelligent agents, the target operating system user identifier is determined based on pre-configured mapping information. An MCP service process running under the target operating system user identifier is provided, and processing operations are performed according to its resource access permissions, ensuring that the MCP service only processes requests within its authorized scope.
It implements resource access control based on operating system identifiers, avoiding the risk of resource leakage caused by excessive MCP service permissions, and improving data security and system stability.
Smart Images

Figure CN121997306A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and particularly to a request processing method and a task processing method. This specification also relates to a request processing apparatus and a task processing apparatus, a computing device, a computer-readable storage medium, and a computer program product. Background Technology
[0002] With the rapid development of artificial intelligence, intelligent agents capable of autonomous decision-making and task execution are widely used in numerous fields such as finance, healthcare, and industrial control. These agents can invoke external resources or services to implement various complex business logics. However, in the process of AI agents processing complex business logic, data security risks may arise due to excessively high service privileges invoked.
[0003] Therefore, how to provide a highly secure request processing method is an urgent technical problem to be solved. Summary of the Invention
[0004] In view of this, one or more embodiments of this specification provide a request processing method and task processing method, apparatus, device and computer-readable medium to solve the problem of low data security in existing request processing methods.
[0005] According to a first aspect of one or more embodiments of this specification, a request processing method is provided, comprising: Receive service call requests from intelligent agents; Based on the pre-configured mapping relationship information, determine the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request; Provides an MCP service process running with the user ID of the target operating system; The MCP service process executes the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier.
[0006] According to a second aspect of one or more embodiments of this specification, a task processing method is provided, comprising: Obtain task information input by the user; The task information is analyzed using a large model to generate a service call request for the Model Context Protocol (MCP) service. The service call request is sent to the proxy service process; The process receives the processing result returned by the proxy service process, which is obtained by the proxy service process executing the request processing method.
[0007] According to a third aspect of one or more embodiments of this specification, a request processing apparatus is provided, comprising: The request receiving module is used to receive service call requests from intelligent agents; The user identifier determination module is used to determine the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request based on pre-configured mapping relationship information. A process providing module is used to provide an MCP service process running with the user ID of the target operating system; The request execution module is used by the MCP service process to execute the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier.
[0008] According to a fourth aspect of one or more embodiments of this specification, a task processing apparatus is provided, comprising: The task acquisition module is used to acquire task information input by the user. The request generation module is used to analyze the task information using a large model and generate a service call request for the Model Context Protocol (MCP) service. The request sending module is used to send the service call request to the proxy service process; The result receiving module is used to receive the processing result returned by the proxy service process, which is obtained by the proxy service process executing the request processing method.
[0009] According to a fifth aspect of one or more embodiments of this specification, a computing device is provided, including a memory, a processor, and computer instructions stored in the memory and executable on the processor, wherein the processor, when executing the computer instructions, implements the steps of the request processing method or the task processing method.
[0010] According to a sixth aspect of one or more embodiments of this specification, a computer-readable storage medium is provided that stores computer instructions that, when executed by a processor, implement the steps of the request processing method or the task processing method.
[0011] According to a seventh aspect of the embodiments of this specification, a computer program product is provided, including a computer program / instructions that, when executed by a processor, implement the steps of the request processing method or the task processing method described above.
[0012] At least one embodiment of this specification achieves the following beneficial effects: By receiving a service call request from an intelligent agent, and determining the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request based on a pre-configured mapping relationship, an MCP service process running with the target operating system user identifier is provided. The MCP service process then executes the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier. This enables the MCP service process to process service call requests based on the resources corresponding to the resource access permissions limited by the operating system identifier, ensuring resource security and avoiding the risk of resource information leakage and ultimately security problems caused by excessive MCP service permissions acquiring irrelevant resources. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a schematic diagram illustrating an application scenario of a request processing method provided in one embodiment of this specification; Figure 2 This is a flowchart illustrating a request processing method provided in one embodiment of this specification; Figure 3 This is a flowchart illustrating a task processing method provided in one embodiment of this specification; Figure 4 This is a swimlane diagram of a task processing method provided in one embodiment of this specification; Figure 5 This specification provides an embodiment corresponding to... Figure 2 A schematic diagram of the structure of a request processing device; Figure 6 This specification provides an embodiment corresponding to... Figure 3 A schematic diagram of the structure of a task processing device; Figure 7 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation
[0015] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0016] This specification uses specific terms to describe embodiments thereof. Terms such as "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic associated with at least one embodiment of this specification. Therefore, it should be emphasized and noted that references to "an embodiment," "one embodiment," or "an alternative embodiment" in different locations throughout this specification do not necessarily refer to the same embodiment. Furthermore, those skilled in the art can combine and integrate the different embodiments or examples described herein, as well as the features of those different embodiments or examples, without contradiction.
[0017] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “an,” “an,” “the,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification includes any or all possible combinations of one or more associated listed items.
[0018] The terms “comprising,” “including,” or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, product, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, product, or apparatus. Without further limitation, the presence of additional identical or equivalent elements in the process, method, product, or apparatus that includes said elements is not excluded.
[0019] Although the terms "first," "second," etc., may be used to describe various information in one or more embodiments of this specification, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, "first" may also be referred to as "second," and similarly, "second" may also be referred to as "first," without departing from the scope of one or more embodiments of this specification. Ordinal numbers such as "first," "second," etc., do not necessarily indicate order; often they are used to facilitate the distinction of objects. For example, "first server" and "second server" usually refer to two servers. To distinguish these two servers, they are described as "first server" and "second server." Of course, sometimes these two servers may be the same server.
[0020] Depending on the context, the word "if" as used here can be interpreted as "when," "when," or "in response to determination."
[0021] In this specification, unless explicitly stated otherwise, "receiving and sending data" does not necessarily mean direct receiving and sending; it can also mean indirect receiving and sending. For example, A receiving data sent by B can be understood as A directly receiving the data sent by B, or it can be understood as A indirectly receiving the data sent by B through other entities such as C. Similarly, B sending data to A can be understood as B sending the data directly to A, or it can be understood as B indirectly sending the data to A through other entities such as C. Here, C can be one entity, or it can be two or more entities.
[0022] In this specification, unless explicitly stated otherwise, the relationships between structures can be direct or indirect. For example, when describing "A is connected to B," unless it is explicitly stated that A and B are directly connected, it should be understood that A can be directly connected to B or indirectly connected to B. Similarly, when describing "A is on top of B," unless it is explicitly stated that A is directly above B (AB is adjacent and A is above B), it should be understood that A can be directly above B or indirectly above B (AB is separated by other elements, and A is above B). And so on.
[0023] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties. The collection, use and processing of related data shall comply with the relevant laws, regulations and standards of the relevant regions, and corresponding operation entry points shall be provided for users to choose to authorize or refuse.
[0024] The following explains the terms and concepts used in one or more embodiments of this specification.
[0025] Large Language Model (LLM): This is an artificial intelligence model. It is a very large deep learning model pre-trained on a large amount of data, capable of understanding and generating natural language.
[0026] Artificial Intelligence Agent (AI Agent) is a software system used to complete user-specified tasks. It is capable of independent thinking, calling tools, and executing tasks.
[0027] Model Context Protocol (MCP) is a standardized communication bridge for AI agents to interact with external tools or resources. MCP overcomes the limitation of large models relying solely on training data, enabling AI agents to access and manipulate local and remote data, and providing an interface for AI agents to make external calls and access.
[0028] MCP service permissions: MCP services are software developed and released by various service providers, capable of performing related functions. MCP service permissions refer to the permissions that MCP service software has when it is executed.
[0029] A sandbox is an isolated execution environment built using technologies such as virtualization and containerization, which restricts a program's access to the host system's real resources. It confines program execution to its own environment, monitoring program behavior while preventing malicious code or abnormal behavior from damaging the external real system.
[0030] In related technologies, MCP services can be run using a security sandbox, allowing the sandbox to isolate the MCP service through security isolation rules. However, this method requires the sandbox to run on the AI agent's computer. Running such a sandbox typically requires high privileges, which the AI agent's computer may not possess, preventing the sandbox from running smoothly and thus failing to isolate the MCP service. Furthermore, if the AI agent's computer version varies, the security sandbox struggles to achieve compatibility across different versions, resulting in poor versatility.
[0031] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.
[0032] Figure 1 This is a schematic diagram illustrating an application scenario of a request processing method provided in an embodiment of this specification.
[0033] like Figure 1As shown, the agent can interact with the proxy server, which can receive service call requests sent by the agent. The proxy server can communicate with multiple MCP services to determine the target MCP service corresponding to the service call request and send the service call request to the corresponding target MCP service. For example, if the target MCP service is MCP service 1, the proxy server can send the service call request to MCP service 1. An MCP service is a service process that can run with a corresponding operating system user ID. For example, MCP service 1 can be a process running with a user ID of operating system A; MCP service 2 can be a process running with a user ID of operating system B; and MCP service 3 can be a process running with a user ID of operating system C. Different operating system user IDs can have different resource access permissions, so the resources that MCP service processes running with different operating system user IDs can call are also different. Continuing the example above, if the target MCP service is MCP service 1, then MCP service 1 can only call or access resource 1, which is limited by the user ID of operating system A, and cannot call or access resources 2 and 3. The target MCP service can invoke the corresponding operation call or access the resources specified by the user identifier to process service call requests and obtain the processing results. The target MCP service can send the processing results to the proxy server, and the proxy server can then feed the processing results back to the agent. The MCP service and resources can be deployed on the proxy server; or they can be independent of the proxy server but deployed on the same computing device as the proxy server. The agent and the proxy server can be deployed on different computing devices, or they can be deployed on the same computing device.
[0034] In such Figure 1 In the application scenarios shown, the proxy server can connect to one or more intelligent agents (i.e., connect to the computing devices where the intelligent agents are located) through local area network (LAN) connections, wide area network (WAN) connections, Internet connections, or other types of data networks. Figure 1 The proxy server in the context can include, but is not limited to, any device, equipment, platform, or device cluster with computing and processing capabilities.
[0035] This application provides a request processing method and a task processing method. This application also relates to a request processing apparatus and a task processing apparatus, a computing device, a computer-readable storage medium, and a computer program product, which will be described in detail in the following embodiments.
[0036] Figure 2 This is a flowchart illustrating a request processing method provided in an embodiment of this specification.
[0037] From a programming perspective, the executor of the process can be a program hosted on an application server, computing device, proxy server, or task processing system. From a hardware perspective, the executor of the process can be a server, computing device, or task processing system capable of processing requests. It can be understood that this method can be executed by any device, equipment, platform, or cluster of devices with computing and processing capabilities.
[0038] like Figure 2 As shown, the process may include the following steps: Step 202: Receive the service call request from the intelligent agent.
[0039] In the embodiments of this specification, a service invocation request can be a request for invoking a service processing task. The service invocation request includes at least some information about the service to be invoked. This information may be at least one of the following: service name, service identifier, service address, and service function.
[0040] Step 204: Based on the pre-configured mapping relationship information, determine the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request.
[0041] In the embodiments described in this specification, the mapping relationship information can be a mapping relationship between MCP services and operating system user identifiers. The mapping relationship information can include the association relationships between multiple MCP services and their respective corresponding operating system user identifiers. The mapping relationship information can be pre-configured.
[0042] In the embodiments of this specification, the operating system user identifier is used to implement process-level resource access control. The operating system user identifier is a numerical label used within the operating system to uniquely identify a user. It can be a User Identifier (UID) or a Group Identifier (GID). A UID can be a unique non-negative integer corresponding to each operating system user, serving as the user's digital identity card. For example, UID=0 could be a super administrator user, the root user, who has the highest system privileges and can perform any operation; UID=1 could be a system user, a virtual user, who can be used to run services but is not allowed to log in to the system by default; UID=1000 could be a regular user, a user created by the administrator, who can be used for daily operations with limited permissions. A GID can be a unique numerical number corresponding to each user group, used for batch management of user permissions. Each operating system user belongs to at least one user group.
[0043] Step 206: Provide an MCP service process running with the target operating system user ID.
[0044] In the embodiments described in this specification, the resource access permissions of the MCP service process can be determined by the UID when the MCP service is running. The MCP service process is an independent execution instance loaded by the kernel when the MCP service runs on a computing device; it is the specific process that carries the functionality of the MCP service. The functionality of the MCP service depends on the collaborative implementation of multiple components, and the MCP service process can be the core carrier for the runtime of these components. Starting the MCP service process indicates the start of the MCP service; terminating the MCP service process indicates the stop of the MCP service.
[0045] In the embodiments described in this specification, running with an operating system user ID indicates that the MCP service can automatically obtain file, memory, and network access permissions from that operating system user. Providing an MCP service process running with an operating system user ID may include starting or reusing an MCP service process running with an operating system user ID.
[0046] In practical applications, after configuring the components required to implement the MCP service in the computing device, the MCP service can be started and the MCP service process can be run based on the user identity corresponding to the operating system user identifier that has a mapping relationship with the MCP service. When processing service call requests, the MCP service process corresponding to the target operating system user identifier can be used to handle the service call request. For example, the MCP service 1 process corresponding to the user identifier of operating system A can be used to handle the MCP service 1 call request; and the MCP service 2 process corresponding to the user identifier of operating system B can be used to handle the MCP service 2 call request.
[0047] Step 208: The MCP service process executes the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier.
[0048] In the embodiments of this specification, resource access permissions are used to grant different users a range of permitted operations on system resources. Resource access permissions determine whether a user or program can access, modify, or execute target resources. The server can pre-define the various resources that operating system users can access, such as files, directories, devices, processes, and network ports; the server can also pre-define the operations that operating system users can perform on resources, such as read operations, modification / deletion operations, and execution operations. The server can grant corresponding resource access permissions to operating system users based on the functionality of the MCP service corresponding to the operating system user identifier. The MCP service process can respond to service call requests and perform corresponding processing operations within the resource access permission range defined by the operating system user identifier.
[0049] In the embodiments described in this specification, the MCP service process is started with the user identity corresponding to the operating system user identifier. Therefore, the MCP service process can use the system resources corresponding to the user identity to complete the processing of service call requests, thereby avoiding the MCP service having excessive privileges and calling resources unrelated to the function implementation of the MCP service.
[0050] While one or more embodiments of this specification provide method steps as described in the embodiments or flowcharts, it is understood that the order of steps listed in the embodiments or flowcharts is merely one possible execution order among many steps and does not represent the only possible execution order. The order of some steps may be adjusted according to actual needs, or some steps may be omitted. When the claims involve method steps, changes in the order of such steps, or parallel execution between steps, are also within the scope of protection of the claims.
[0051] Figure 2 The method described herein receives service call requests from intelligent agents, determines the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request based on pre-configured mapping information, and provides an MCP service process running under the target operating system user identifier. The MCP service process then executes the processing operations corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier. This ensures the security of resources and avoids the risk of resource information leakage and ultimately security problems caused by the MCP service acquiring irrelevant resources due to excessive privileges.
[0052] based on Figure 2 In addition to the method described herein, this specification also provides some improved implementation methods, which will be described below.
[0053] In one or more embodiments of this specification, the server can process the MCP service process accordingly based on the running status of the MCP service. Optionally, providing an MCP service process running with the target operating system user ID may specifically include: if a persistent MCP service process running with the operating system user ID exists, then reusing the persistent MCP service process; otherwise, creating an MCP service process running with the target operating system user ID.
[0054] In the embodiments of this specification, the resident MCP service process can refer to an MCP service process that exists in the computing device and has been previously started. A resident MCP service process can refer to an MCP service process that runs again using the target operating system user identifier.
[0055] In the embodiments of this specification, if there is no resident MCP service process running with the target operating system user ID, it may mean that there is no MCP service process started with the target operating system user ID on the computing device, and then an MCP service process running with the target operating system user ID can be created.
[0056] In the embodiments described in this specification, if the MCP service in the computing device is in a stopped state when no request is processed, the proxy server can start the MCP service process as needed when it receives a service call request. Specifically, after receiving the service call request, it can determine the UID with a mapping relationship based on the target MCP service contained in the service call request; and reuse the service process of the corresponding target MCP service using the UID. Reuse can mean restarting. This allows the MCP service process to be started as needed, avoiding resource waste.
[0057] In the embodiments of this specification, after each MCP service is created, the corresponding MCP service process can be started based on the pre-configured mapping relationship information and the operating system user identifier. This allows the MCP service process to be started immediately after each MCP service is created, thus keeping it in a always-on state. When the proxy server receives a service call request, it can directly use the MCP service process to process the service call request, improving the efficiency of request processing and the overall system stability. This avoids problems such as "process startup failure", "port occupation" or "resource not released" that are prone to occur during startup and shutdown, thereby improving the availability of the MCP service.
[0058] In practical applications, the proxy server can start the MCP service process before receiving a service call request; alternatively, the proxy server can start the MCP service process when receiving a service call request; or the proxy server can start the MCP service process after receiving a service call request, for example, by pre-starting the MCP service process during computing device initialization, or by starting the MCP service process on demand upon receiving a request. Providing an MCP service process can include, but is not limited to: creating and starting a new MCP service process, allocating an existing MCP service process from an MCP service process pool, waking up a dormant MCP service process, or ensuring that an existing MCP service process is in a serviceable state.
[0059] In one or more embodiments of this specification, during the construction of an operating system for handling requests in a computing device, it is necessary to construct a proxy server for communicating with the agent, so that the agent process can communicate with the proxy server to complete the requests given by the agent. Optionally, before receiving the service call request from the agent, the process may further include: starting the agent's proxy service process based on the root user identifier; and having the proxy service process load the mapping relationship information between each MCP service and its corresponding operating system user identifier according to the configuration file.
[0060] In the embodiments of this specification, the root user identifier can represent the Root UID, which can be a unique identifier for the super user. The user corresponding to this identifier has the highest privileges of the operating system and can perform all system operations and access all resources. The root user identifier is the highest level identifier for permission control.
[0061] The proxy service process can send requests to various MCP service processes based on the target MCP service contained in the received service call request. The proxy service process can be the operating system's proxy server. Since the proxy server needs to interact with various MCP services and agents, it needs to be started with a high-privilege user, such as the root user, to avoid situations where insufficient privileges prevent interaction with certain MCP services or agents, thus causing request processing failures.
[0062] The proxy service process serves as an intermediary bridge between the intelligent agent and the underlying MCP service, responsible for core operations such as permission allocation, start-up or shutdown control, and communication relay. The proxy service process differs from the MCP service process; the proxy service process focuses on control and management, while the MCP service process focuses on specific business execution.
[0063] In the embodiments described in this specification, the operating system root user triggers a startup instruction for the proxy service process via a computing device or system startup script. This instruction includes at least the core startup parameters for the proxy service process. Upon receiving the startup instruction, the operating system kernel verifies whether the initiator of the instruction has root user privileges. After determining that the initiator has root user privileges, the kernel initializes the process control block, sets the root user identifier of the process, and starts the proxy service process. After starting, the proxy service process can enter a running state and listen for MCP service call requests.
[0064] In practical applications, if the agent service process starts successfully, it can send a signal to the operating system indicating that the startup was successful; if the agent service process fails to start, it can exit the configuration of the agent service process and record the error log.
[0065] In the embodiments described in this specification, the proxy service process opens the configuration file, parses the configuration file to obtain the mapping relationship information stored in the configuration file, and determines whether the MCP service contained in the configuration file already exists in the operating system. If the MCP service exists in the operating system, the MCP service process can be started using the operating system identifier in the configuration file that has a mapping relationship with the MCP service. If the MCP service does not exist in the operating system, the MCP service can be left unprocessed. Each MCP service in the configuration file can have a unique correspondence with an operating system user identifier. One MCP service can correspond to one or more MCP service processes. One or more MCP service processes belonging to the same MCP service are used to provide the same MCP service, thereby enabling requests to be processed serially or in parallel.
[0066] The embodiments in this specification can start the proxy service process through the root user identifier. The proxy service process starts each MCP service according to the operating system user identifier corresponding to each MCP service in the operating system in the configuration file. In this way, the proxy service process and the service process of the MCP service can be used to process requests, and the processing can be completed stably and efficiently.
[0067] In one or more embodiments of this specification, the proxy service process can receive MCP service call requests from AI agents and perform processing operations corresponding to the MCP service call requests. The proxy service process can use the MCP service process to process MCP service call requests through forwarding, routing, or delegation. For example, the proxy service process can act as the caller, and the MCP service can act as the callee; the proxy service process can call the MCP service process based on the interface contract between them, utilize the MCP service process to process the service call request, and obtain the processing result returned by the MCP service process. Alternatively, the request can be sent to the MCP service process via an asynchronous message queue; specifically, a message can be forwarded to the message queue for consumption by the MCP service process; or it can be event-driven; specifically, an event identifying the processing of the service call request can be published; or an HTTP reverse proxy can be used to route the request to the MCP service process; or the MCP service process can be delegated through a work queue.
[0068] In one or more embodiments of this specification, the computing device can build a container instance within an operating system, isolating it from the external real system and preventing damage to the external real system. Optionally, before starting the agent's proxy service process, the process may further include: obtaining an agent image that encapsulates the resources required for the agent to run; creating a container instance based on the agent image; and specifically, starting the agent's proxy service process may include: starting the proxy service process within the container instance.
[0069] In the embodiments described in this specification, the agent image may contain complete resources and startup instructions required for the agent to run. It is a read-only file package that conforms to the container image specification, serving as a standardized carrier for the agent's runtime environment, and is a static file. The resources required for the agent to run can be a collection of all software and hardware dependencies used to support the normal operation of the agent. These resources may include the agent's main program, the agent service process executable file, the MCP service binary package, system libraries, third-party components, configuration files, agent service startup parameter files, and environmental resources.
[0070] In the embodiments described in this specification, a container instance can be a dynamic runtime environment created by a container engine based on an agent image, and is a writable copy of the agent image. Container instances can achieve resource isolation from the host, avoiding resource contention and mutual interference between agent processes and host processes. Container instances can also store temporary data generated during agent operation; this temporary data does not affect the resources stored in the agent image.
[0071] In the embodiments described in this specification, the operating system can create a dynamic container instance based on a static agent image, start a proxy service process in the container instance, thereby enabling the processing of agent service call requests in the container instance and avoiding competition with or interference with the host's resources.
[0072] In one or more embodiments of this specification, optionally, before loading the mapping relationship information between each MCP service and its corresponding operating system user identifier according to the configuration file, the method may further include: creating a corresponding operating system user identifier for each MCP service; configuring resource access permissions for each of the operating system user identifiers; and saving the correspondence between the MCP service identifier of the MCP service, the operating system user identifier, and the resource access permissions to the configuration file.
[0073] In the embodiments described in this specification, a corresponding operating system user identifier is created for each MCP service. Specifically, the system can traverse all registered MCP services, extract the MCP service identifier for each registered MCP service, generate a unique operating system username for each MCP service identifier, call the operating system user management interface to create a system user corresponding to the operating system username, and record the UID and username of the created system user. This allows for the allocation of an independent operating system user identifier for each MCP service.
[0074] In practical applications, developers can send instructions to the system to generate operating system users for each MCP service. If the instructions include the operating system username and UID for each MCP service, the system can create a corresponding operating system user for each MCP service based on the mapping in the instructions and create a configuration file containing the mapping relationship between the two. If the instructions do not include the operating system username and UID for each MCP service, the system can iterate through each MCP service and randomly create an operating system user for each MCP service; alternatively, it can create operating system users according to a preset format, such as generating the operating system username based on the MCP service name and generating the operating system user identifier for each MCP service based on the iteration order. There is a unique correspondence between MCP services and operating system users.
[0075] In the embodiments of this specification, the resource access permissions of each operating system user identifier can be configured based on the resources required to implement the functions of the MCP service, which can prevent the MCP service from accessing irrelevant resources and causing security risks to the resources.
[0076] In practical applications, the system can determine the list of resources that the MCP service needs to access based on the functional requirements of the MCP service, such as log directories and device files; and set corresponding resource access permissions for operating system users that have a mapping relationship with the MCP service. For example, an operating system user named MCP_user_audio with UID 1001 is created for MCP_audio. Since MCP_audio needs to access audio devices, the resource access permissions corresponding to the audio devices can be configured for the operating system user.
[0077] In the embodiments described in this specification, the mapping relationship in the configuration file can be a mapping relationship between the MCP service identifier, the operating system user identifier, and resource access permissions. This allows the proxy service process to start the MCP service corresponding to the MCP service identifier based on the mapping relationship between the MCP service identifier and the operating system user identifier in the configuration file, using the user identity represented by the operating system user identifier. When the MCP service processes requests using the MCP service process, it can access the corresponding resources based on the resource access permissions corresponding to the operating system user identifier. This prevents the MCP service process from accessing unrelated resources and damaging other resources, thus enhancing the system's operational reliability and security governance capabilities. Furthermore, it allows the configuration file to automatically rebuild the relationship between users and resource access permissions during system restarts or service migrations. In practical applications, the configuration file can be configured with permissions, such as allowing the root user only read and write permissions, effectively preventing the configuration file from being tampered with.
[0078] In practical applications, users can configure resource access permissions on computing devices. In response to resource access permission configuration operations, the system can create the above-mentioned correspondence and save it to the configuration file.
[0079] In one or more embodiments of this specification, the resources accessible to the MCP service can be determined based on the operating system user identifier, and the task contained in the service call request can be processed based on the accessed resources. Optionally, the service call request carries a target task; the processing operation corresponding to the service call request may specifically include: the MCP service process accessing the target resource within the resource access permission range of the target operating system user identifier; and processing the target task based on the target resource.
[0080] In the embodiments described in this specification, the target resource can be a resource that the MCP service has access to. The target task can be user input received by the AI agent from a human user. Since the MCP service process runs with the user identity represented by the target operating system user identifier, it can access the target resource corresponding to the resource access permissions held by the target operating system user identifier. Therefore, after the MCP service process obtains a service call request, it can directly access the corresponding target resource to process the target task and obtain the task processing result. This ensures that the MCP service, in processing the target task, can access resources it has permission to access, and will not access other resources it does not have permission to access, thus guaranteeing the security of each resource and preventing tampering or leakage.
[0081] In one or more embodiments of this specification, the method may further include: returning the processing result of the processing operation to the intelligent agent.
[0082] In the embodiments described in this specification, the processing result can be the result information obtained by the MCP service process after processing the target task contained in the service call request using the target resource. After the MCP service process has processed the target task and obtained the processing result, it can feed back the processing result to the proxy service process, so that the proxy service process can return the processing result to the intelligent agent, enabling the intelligent agent to obtain the processing result.
[0083] Figure 3 This is a flowchart illustrating a task processing method provided in an embodiment of this specification.
[0084] From a programming perspective, the executor of the process can be a program hosted on an application server, computing device, task processing system, or user terminal. From a hardware perspective, the executor of the process can be a server, computing device, task processing system, or user terminal with deployed intelligent agents. It can be understood that this method can be executed by any device, equipment, platform, or cluster of devices with computing and processing capabilities.
[0085] like Figure 3 As shown, the process may include the following steps: Step 302: Obtain the task information input by the user.
[0086] In the embodiments of this specification, task information can be information input by the user on the terminal device. Task information can include at least one of text information and image information. The terminal device can display an interactive interface for user interaction with the intelligent agent, where the user can input task information. The user can input various types of tasks on the interactive interface, such as query tasks, question-and-answer tasks, image generation tasks, shopping tasks, ticket purchase tasks, etc.
[0087] Step 304: Analyze the task information using the large model and generate a service call request for the Model Context Protocol (MCP) service.
[0088] In the embodiments of this specification, the large model can be a multimodal large model, capable of analyzing and processing task information containing one or more modalities to obtain a service invocation request that can handle the task. The service invocation request may include task information and the MCP service identifier of the target MCP service used to process the task information.
[0089] Step 306: Send the service call request to the proxy service process.
[0090] In the embodiments described in this specification, the proxy service process can be a service process deployed in a container instance that is capable of communicating with the agent. After receiving a service call request, the proxy service process can use the MCP service process to process the service call request. Specific request processing methods can be found in the detailed explanation above, and will not be discussed further here.
[0091] Step 308: Receive the processing result returned by the proxy service process.
[0092] The processing result is obtained by the proxy service process executing the above request processing method.
[0093] In the embodiments described in this specification, after receiving the processing result, the intelligent agent can display the processing result on the interactive interface so that the user can view the processing result for the task information.
[0094] Figure 3The method described above acquires user-input task information, analyzes it using a large model, generates a service call request for the MCP service, and sends the request to a proxy service process. This proxy process then executes the request processing method, allowing the agent to receive the processing results for the user to view. On one hand, the MCP service can be used to process task information and obtain the results. On the other hand, service call requests can be handled through resources within the container instance, eliminating the need to modify resources on the host system. This avoids issues such as modifying host system resources or resource contention, and also improves the data security of the host system.
[0095] based on Figure 3 In addition to the method described herein, this specification also provides some improved implementation methods, which will be described below.
[0096] In one or more embodiments of this specification, the step of using a large model to analyze the task information and generate a service call request for a Model Context Protocol (MCP) service may specifically include: obtaining functional description information of multiple MCP services; inputting the task information and the functional description information into the large model to obtain at least one subtask determined by the large model for the task information and the target MCP service corresponding to each subtask; and generating the service call request based on the subtask and the target MCP service.
[0097] In the embodiments of this specification, the functional description information can represent descriptive text information such as the business capabilities and processing logic scope that the MCP service can perform. The functional description information may also include the corresponding MCP service identifier, so that the large model can understand the correspondence between the MCP service identifier and the functional description information, avoiding confusion between the MCP service identifier and the functional description information and generating incorrect service call requests. For example, the MCP service identifier used for ticket purchase can be mcp_12306, and the corresponding functional description can be that this service supports processing tasks related to the 12306 railway system, which may include parsing the departure point, destination, date, and seat class in the user's natural language; calling the internal ticketing interface to obtain the remaining ticket information for a specified train; and synchronizing the user's 12306 order status, etc.
[0098] In the embodiments of this specification, subtasks can be generated by decomposing task information from a large model, and can be completed independently by a single MCP service. For example, the task information is "analyze intersection camera video, identify vehicles running red lights and record license plates", which can be decomposed into three subtasks: "video frame extraction", "license plate recognition" and "behavior judgment".
[0099] In the embodiments of this specification, a subtask corresponds to a target MCP service for processing the subtask. Therefore, a service call request can be generated based on a subtask and its corresponding target MCP service. An agent can generate one or more service call requests for a given task information. Continuing the previous example, service call requests can be generated that can invoke an MCP service with video frame extraction capabilities, an MCP service with license plate recognition capabilities, and an MCP service with behavior judgment capabilities.
[0100] In the embodiments described in this specification, the large model can decompose task information into various sub-tasks. The large model can also determine the target MCP service capable of handling each sub-task based on the functional description information of each MCP service. The large model can provide each sub-task and its corresponding target MCP service to the agent, which can then generate a service call request based on the sub-task and its corresponding target MCP service. In practical applications, the large model can also generate a service call request based on the analyzed sub-task and its corresponding target MCP service, and directly feed the service call request back to the agent, enabling the agent to send the service call request to the proxy service process for processing. On the one hand, this allows for fine-grained processing of task information, avoiding the problem of processing confusion and inaccurate results caused by calling multiple MCP services to process the same task information at once. On the other hand, it can also improve the accuracy of the generated service call request based on the functional description information of the sub-task and MCP service, avoiding the invocation of incorrect MCP services and resulting in task processing failure.
[0101] In one or more embodiments of this specification, if there are multiple subtasks that need to be processed, the subtasks can be processed in a certain order. Optionally, the subtasks include a first subtask and a second subtask; the execution of the second subtask depends on the execution result of the first subtask; the target MCP service includes a first target MCP service corresponding to the first subtask and a second target MCP service corresponding to the second subtask; the method may further include: generating a first service call request based on the first subtask and the first target MCP service; sending the first service call request to the proxy service process; receiving the first subtask processing result returned by the proxy service process in response to the first service call request; generating a second service call request based on the first subtask processing result, the second subtask, and the second target MCP service; sending the second service call request to the proxy service process; and receiving the second subtask processing result returned by the proxy service process in response to the second service call request.
[0102] In the embodiments of this specification, the large model can output the execution dependencies or execution order between the decomposed subtasks, enabling the agent to send various service call requests to the proxy service process based on the dependencies or execution order. A dependency can indicate that the execution of a second subtask depends on the execution result of the first subtask; an execution order can indicate the execution order in which the first subtask is executed first, followed by the second subtask. The execution order can contain subtasks with the same execution order. A consistent execution order indicates that the results of these subtasks are independent of each other and can be executed in parallel or sequentially. For example, if the task is "to query the top ten trending search results," subtask 1 queries information from application A; subtask 2 queries information from application B; and subtask 3 determines the top ten trending search results from the query results of tasks 1 and 2, then service call request 1 can be generated based on subtask 1 and its corresponding mcp_A, and service call request 2 can be generated based on subtask 2 and its corresponding mcp_B. Since the execution order of subtasks 1 and 2 is 1, and the execution order of subtask 3 is 2, service call request 1 can be used to obtain the top ten trending search results for application A; service call request 2 can be used to obtain the top ten trending search results for application B; and service call request 3 can be generated based on the top ten trending search results for application A, application B, subtask 3, and its corresponding mcp_C, and then service call request 3 can be used to determine the target top ten trending search results.
[0103] In the embodiments of this specification, a first service call request may represent a request to process a first subtask using a first target MCP service. A second service call request may represent a request to process a second subtask using a second target MCP service based on the processing result of the first subtask. If the second subtask is the final subtask, the processing result of the second subtask can be used as the processing result corresponding to the task information and sent to the terminal device for display. If the second subtask is not the final subtask, the next subtask can be processed until the final subtask is reached, and the processing result corresponding to the final subtask can be sent to the terminal device. This allows for the safe, orderly, and reliable execution of complex tasks through phased processing and dependencies, improving the accuracy and reliability of the obtained processing results.
[0104] The various technical features in the above embodiments can be combined arbitrarily, as long as there is no conflict or contradiction between the combinations of features. However, due to space limitations, they have not been described one by one. Therefore, the arbitrary combination of various technical features in the above embodiments is also within the scope of this specification.
[0105] According to the above explanation, Figure 4 This is a swimlane diagram of a task processing method provided in the embodiments of this specification. For example... Figure 4As shown, the system comprises three main components: a terminal device, an agent, and a computing device. These three components can belong to the same task processing system. The terminal device can be a hardware device used by the user to interact with the agent. The agent can be a software system used to complete user-specified tasks. The agent can be deployed on the terminal device or on a cloud server communicatively connected to the terminal device. The computing device (Agent computer) can be a hardware device capable of providing the agent with computing resources to complete user-specified tasks. The computing device can communicate with the cloud server where the agent is deployed, or the computing device and the cloud server where the agent is deployed can be the same device (cluster). The computing device can run proxy server processes and MCP service processes; it can also contain resources for completing tasks. Figure 4 It may also include a container configuration phase and a task processing phase, and the process may include: The computing device can perform step 402: obtain an agent image containing the resources required for the agent to run.
[0106] Step 404: Create a container instance based on the agent image.
[0107] Step 406: In the container instance, start the proxy service process based on the root user identifier.
[0108] Step 408: Start the MCP service in the container instance based on the operating system user identifier in the configuration file.
[0109] In the embodiments of this specification, the computing device can obtain the intelligent agent image to create a container instance, and pre-start the agent service process using the root user. This allows the agent service process to start the corresponding MCP service using the operating system user identifier according to the mapping relationship between the operating system user identifier and the MCP service contained in the configuration file. This enables the MCP service to be used directly to process tasks in the future.
[0110] In practical applications, before or during container instance creation, the agent's developer can create a corresponding operating system user for each MCP service. Specifically, the developer can issue a creation command for the MCP service, which may include relevant operating system user information for each MCP service. The task processing system can respond to the creation command, creating operating system users mapped to each MCP service and storing this mapping information in a configuration file. The operating system user information may include the user name and identifier. The mapping information may include the mapping relationship between each MCP service and each operating system user identifier. Each MCP service has a unique mapping to each operating system user identifier.
[0111] In practical applications, after establishing the mapping relationship, for any MCP service, the target resources required to implement the functionality of that MCP service can be determined. Resource access permissions for the corresponding target resources are then configured for the operating system user with the mapping relationship to that MCP service. This ensures that any MCP service started by an operating system user can only access resources corresponding to the resource access permissions held by that operating system user. Resources can be related files, programs, etc., on a computing device. Each MCP service can access certain resources based on the corresponding operating system user's resource access permissions to complete its business logic.
[0112] In practical applications, after a computing device creates a container instance using an agent image, the device can start a proxy service process as the root user of the operating system. This allows the proxy service process to obtain mapping information from the configuration file, determine the operating system user identifier that maps to the MCP service deployed in the container instance, and start the corresponding MCP service as the user corresponding to that operating system user identifier, thus putting the container instance in the computing device into a running state. A variety of different MCP services can be deployed in the container instance, such as the mcp-shell service that can directly execute various commands, or the mcp-12306 service that can purchase train tickets.
[0113] The terminal device can perform step 410: send the task information entered by the user in the terminal device.
[0114] In the embodiments described in this specification, the terminal device can display an interactive interface for user interaction with the intelligent agent, where the user can input task information. Here, "user" refers to a human user, which is different from the operating system user represented by the operating system user identifier mentioned above.
[0115] The agent can perform step 412: obtain task information input by the user.
[0116] Step 414: Obtain the functional description information of multiple MCP services.
[0117] Step 416: Analyze the task information and function description information using the large model to generate service call requests.
[0118] In the embodiments described in this specification, the large model can decompose task information into multiple subtasks; and determine the target MCP service that can be used to process the subtasks based on the functional description of each MCP service. Service call requests are generated based on the subtasks and their corresponding target MCP services, and are requests that can be used to process the subtasks. If the task information cannot be decomposed, a single service call request can be generated; if the task information is decomposed into multiple subtasks, individual service call requests can be generated for each subtask. If there are multiple subtasks, each subtask can be processed according to the dependencies between them.
[0119] In practical applications, large models can be deployed on agents, or agents can communicate and connect with large models. Large models can feed back the decomposed subtasks, the target MCP services used to process each subtask, and the execution order of each subtask to agents, enabling agents to generate corresponding service call requests. Alternatively, large models can output service call requests and feed them back to agents.
[0120] The computing device can perform step 418: receiving a service call request from an intelligent agent.
[0121] Step 420: Determine the target operating system user identifier associated with the target MCP service corresponding to the service call request.
[0122] Step 422: The MCP service process that provides the target MCP service.
[0123] Step 424: The MCP service process executes the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier, and obtains the processing result.
[0124] In the embodiments described in this specification, the agent service process in the computing device can receive service call requests from intelligent agents and send the service call requests to the corresponding target MCP service's MCP service process. The MCP service process can access target resources based on the resource access permissions of the target operating system user running the MCP service, and use the target resources to process the service call request and obtain the processing result.
[0125] In practical applications, different operating system users have different resource access permissions. The task processing system can set a mapping between operating system user identifiers and resource access permissions. The resources corresponding to the resource access permissions can be resources required to implement the MCP service functions. Resources that cannot be used to implement the MCP service functions will not be granted the corresponding access permissions by the operating system user corresponding to that MCP service. This allows the MCP service process to access the target resource using the resource access permissions limited by the operating system user identifier corresponding to the target MCP service when processing service call requests, enabling the MCP service process to process service call requests based on the target resource. Resource access permissions can be set during the container configuration phase.
[0126] The agent can perform step 426: obtain the processing result.
[0127] The terminal device can perform step 428: display the processing result.
[0128] In the embodiments described in this specification, the proxy service process can obtain the processing result of the MCP service process on the service call request, and feed the processing result back to the intelligent agent. After obtaining the processing result, the intelligent agent feeds the processing result back to the terminal device, enabling the terminal device to display the processing result in the interactive interface. The aforementioned terminal device, intelligent agent, and computing device can belong to the same task processing system.
[0129] In the embodiments described in this specification, some steps are the same as or similar to those in the foregoing embodiments, and can be referred to the foregoing embodiments, which will not be repeated here. The order of some of the above steps can be changed or adjusted, or some steps can be omitted.
[0130] Through the above methods, on the one hand, after configuring container instances on different versions of computing devices or systems, the permissions of each MCP service can be restricted using the operating system user identifier. This achieves fine-grained control over MCP service permissions, preventing MCP services from unauthorized access to data or from stealing sensitive files by executing malicious code, thus avoiding data security risks. It also ensures that running container instances are compatible with different versions of computing devices or systems, eliminating the need to set dedicated security rules for different devices or systems. On the other hand, the MCP services within the container instance can be used to process task information received by the intelligent agent, isolating it from the real resources in the host system. This avoids damage to the host system's resources while enabling accurate and efficient task processing.
[0131] Based on the same idea, embodiments of this specification also provide apparatus corresponding to the above methods.
[0132] Figure 5 The embodiments provided in this specification correspond to Figure 2A schematic diagram of the structure of a request processing device.
[0133] like Figure 5 As shown, the device may include: The request receiving module 502 is used to receive service call requests from intelligent agents; User identifier determination module 504 is used to determine the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request based on pre-configured mapping relationship information. Process providing module 506 is used to provide an MCP service process running with the user ID of the target operating system; The request execution module 508 is used by the MCP service process to execute the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier.
[0134] based on Figure 5 The embodiments of this specification also provide some specific implementation schemes of the method, which are described below.
[0135] Optionally, the process providing module can be specifically used to: if there is an MCP service resident process running with the user ID of the operating system, reuse the MCP service resident process; otherwise, create an MCP service process running with the user ID of the target operating system.
[0136] Optionally, the device can also be used to: start the agent's proxy service process based on the root user identifier; and have the proxy service process load the mapping relationship information between each MCP service and its corresponding operating system user identifier according to the configuration file.
[0137] Optionally, the device can also be used to: obtain an agent image containing resources required for the agent to run; create a container instance based on the agent image; and start the agent's agent agent service process, specifically including: starting the agent agent service process in the container instance.
[0138] Optionally, the apparatus can also be used to: create corresponding operating system user identifiers for each MCP service; configure resource access permissions for each operating system user identifier; and save the correspondence between the MCP service identifier of the MCP service, the operating system user identifier, and the resource access permissions to the configuration file.
[0139] Optionally, the service call request carries the target task; the request execution module can be specifically used to: allow the MCP service process to access the target resource within the resource access permission range of the target operating system user identifier; and process the target task based on the target resource.
[0140] Optionally, the device can also be used to: return the processing result of the processing operation to the intelligent agent.
[0141] It is understood that the modules mentioned above refer to computer programs or program segments used to perform one or more specific functions. Furthermore, the distinction between these modules does not imply that the actual program code must also be separate.
[0142] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more of these specifications, the functions of each module or unit can be implemented in the same or different software and / or hardware, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.
[0143] The above is an illustrative scheme of a request processing device according to this embodiment. It should be noted that the technical solution of this request processing device and the technical solution of the above-described request processing method belong to the same concept. For details not described in detail in the technical solution of the request processing device, please refer to the description of the technical solution of the above-described request processing method.
[0144] Figure 6 The embodiments provided in this specification correspond to Figure 3 A schematic diagram of the structure of a task processing device.
[0145] like Figure 6 As shown, the device may include: Task acquisition module 602 is used to acquire task information input by the user; The request generation module 604 is used to analyze the task information using a large model and generate a service call request for the Model Context Protocol (MCP) service. The request sending module 606 is used to send the service call request to the proxy service process; The result receiving module 608 is used to receive the processing result returned by the proxy service process, the processing result being obtained by the proxy service process executing the aforementioned request processing method.
[0146] based on Figure 6 The embodiments of this specification also provide some specific implementation schemes of the method, which are described below.
[0147] Optionally, the request generation module may be specifically used to: obtain functional description information of multiple MCP services; input the task information and the functional description information into the large model to obtain at least one subtask determined by the large model for the task information and the target MCP service corresponding to each subtask; and generate the service call request based on the subtask and the target MCP service.
[0148] Optionally, the subtask includes a first subtask and a second subtask; the execution of the second subtask depends on the execution result of the first subtask; the target MCP service includes a first target MCP service corresponding to the first subtask and a second target MCP service corresponding to the second subtask; the device can also be used to: generate a first service call request based on the first subtask and the first target MCP service; send the first service call request to the proxy service process; receive the first subtask processing result returned by the proxy service process for the first service call request; generate a second service call request based on the first subtask processing result, the second subtask, and the second target MCP service; send the second service call request to the proxy service process; and receive the second subtask processing result returned by the proxy service process for the second service call request.
[0149] It is understood that the modules mentioned above refer to computer programs or program segments used to perform one or more specific functions. Furthermore, the distinction between these modules does not imply that the actual program code must also be separate.
[0150] For ease of description, the above devices are described by dividing them into various modules or units based on their functions. Of course, when implementing one or more of these specifications, the functions of each module or unit can be implemented in the same or different software and / or hardware, or a module that performs the same function can be implemented by a combination of multiple sub-modules or sub-units, etc. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.
[0151] The above is an illustrative scheme of a task processing device according to this embodiment. It should be noted that the technical solution of this task processing device and the technical solution of the task processing method described above belong to the same concept. For details not described in detail in the technical solution of the task processing device, please refer to the description of the technical solution of the task processing method described above.
[0152] Based on the same idea, this specification also provides devices corresponding to the above methods in its embodiments.
[0153] Figure 7 A structural block diagram of a computing device provided in one embodiment of this specification is shown.
[0154] The computing device 700 includes: Memory 710 and processor 720; The memory 710 is used to store computer programs / instructions, and the processor 720 is used to execute the computer programs / instructions. When the computer programs / instructions are executed by the processor 720, they implement the steps of the request processing method or the task processing method.
[0155] Specifically, the components of the computing device 700 include, but are not limited to, a memory 710 and a processor 720. The processor 720 is connected to the memory 710 via a bus 730, and the database 750 is used to store data.
[0156] The computing device 700 also includes an access device 740, which enables the computing device 700 to communicate via one or more networks 760. Examples of these networks include Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or combinations of communication networks such as the Internet. The access device 740 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Wi-MAX (Worldwide Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.
[0157] In one embodiment of this specification, the above-described components of the computing device 700 and Figure 7 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 7The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this application. Those skilled in the art can add or replace other components as needed.
[0158] The computing device 700 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 700 can also be a mobile or stationary server.
[0159] The processor 720 implements the steps of the request processing method or the task processing method when executing the computer instructions.
[0160] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device belongs to the same concept as the technical solution of the above-described request processing method or task processing method. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the above-described request processing method or task processing method.
[0161] An embodiment of this specification also provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the steps of the request processing method or the task processing method described above.
[0162] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium belongs to the same concept as the technical solution of the above-described request processing method or task processing method. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the above-described request processing method or task processing method.
[0163] An embodiment of this specification also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the above-described request processing method or task processing method.
[0164] The above is an illustrative scheme of a computer program product according to this embodiment. It should be noted that the technical solution of this computer program product belongs to the same concept as the technical solution of the above-described request processing method or task processing method. For details not described in detail in the technical solution of the computer program product, please refer to the description of the technical solution of the above-described request processing method or task processing method.
[0165] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the embodiments of apparatus, devices, computer-readable storage media, and computer program products, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The apparatus, devices, computer-readable storage media, and computer program products provided in the embodiments of this specification correspond to the methods, and therefore the apparatus, devices, computer-readable storage media, and computer program products also have similar beneficial technical effects as the corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the corresponding apparatus, devices, computer-readable storage media, and computer program products will not be repeated here.
[0166] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0167] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0168] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0169] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0170] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.
[0171] Those skilled in the art will understand that one or more embodiments of this specification can be provided as a method, system, or computer program product. Therefore, the invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0172] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0173] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0174] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0175] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0176] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0177] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital character versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0178] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0179] The above description is merely an embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.
Claims
1. A request processing method, comprising: Receive service call requests from intelligent agents; Based on the pre-configured mapping relationship information, determine the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request; Provides an MCP service process running with the user ID of the target operating system; The MCP service process executes the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier.
2. The method according to claim 1, wherein providing the MCP service process running with the target operating system user ID specifically includes: If a persistent MCP service process exists running with the user ID of the operating system, then the persistent MCP service process is reused. Otherwise, create an MCP service process that runs with the target operating system user ID.
3. The method according to claim 1, further comprising, before receiving the service invocation request from the intelligent agent: The agent's proxy service process is initiated based on the root user identifier; The proxy service process loads the mapping information between each MCP service and its corresponding operating system user identifier according to the configuration file.
4. The method according to claim 3, further comprising, before initiating the agent's proxy service process: Obtain an image of the intelligent agent that encapsulates the resources required for the operation of the intelligent agent; Create a container instance based on the agent image; The process of initiating the agent's proxy service specifically includes: Start the proxy service process in the container instance.
5. The method according to claim 3, before loading the mapping relationship information between each MCP service and its corresponding operating system user identifier according to the configuration file, it further includes: Create corresponding operating system user identifiers for each MCP service; Configure resource access permissions for each of the aforementioned operating system user identifiers; The mapping relationship between the MCP service identifier of the MCP service, the operating system user identifier, and the resource access permissions is saved to the configuration file.
6. The method according to claim 1, wherein the service invocation request carries a target task; the execution of the processing operation corresponding to the service invocation request specifically includes: The MCP service process accesses the target resources within the resource access permissions of the target operating system user identifier; The target task is processed based on the target resource.
7. The method according to claim 1, further comprising: The processing result of the processing operation is returned to the intelligent agent.
8. A task processing method, comprising: Obtain task information input by the user; The task information is analyzed using a large model to generate a service call request for the Model Context Protocol (MCP) service. The service call request is sent to the proxy service process; The process receives the processing result returned by the proxy service process, which is obtained by the proxy service process executing the request processing method as described in any one of claims 1-7.
9. The method according to claim 8, wherein analyzing the task information using a large model to generate a service call request for the Model Context Protocol (MCP) service specifically includes: Obtain functional description information for multiple MCP services; The task information and the function description information are input into the large model to obtain at least one sub-task determined by the large model for the task information and the target MCP service corresponding to each sub-task; Based on the subtask and the target MCP service, the service call request is generated.
10. The method according to claim 9, wherein the subtask includes a first subtask and a second subtask; the execution of the second subtask depends on the execution result of the first subtask; the target MCP service includes a first target MCP service corresponding to the first subtask and a second target MCP service corresponding to the second subtask; The method further includes: Based on the first subtask and the first target MCP service, generate a first service call request; Send the first service call request to the proxy service process; Receive the first subtask processing result returned by the proxy service process in response to the first service call request; Based on the processing result of the first subtask, the second subtask, and the second target MCP service, a second service invocation request is generated. Send the second service call request to the proxy service process; Receive the second subtask processing result returned by the proxy service process in response to the second service call request.
11. A request processing apparatus, comprising: The request receiving module is used to receive service call requests from intelligent agents; The user identifier determination module is used to determine the target operating system user identifier associated with the target Model Context Protocol (MCP) service corresponding to the service call request based on pre-configured mapping relationship information. A process providing module is used to provide an MCP service process running with the user ID of the target operating system; The request execution module is used by the MCP service process to execute the processing operation corresponding to the service call request based on the resource access permissions limited by the target operating system user identifier.
12. A task processing apparatus, comprising: The task acquisition module is used to acquire task information input by the user. The request generation module is used to analyze the task information using a large model and generate a service call request for the Model Context Protocol (MCP) service. The request sending module is used to send the service call request to the proxy service process; The result receiving module is used to receive the processing result returned by the proxy service process, wherein the processing result is obtained by the proxy service process executing the request processing method as described in any one of claims 1-7.
13. A computing device, comprising: Memory and processor; The memory is used to store computer programs / instructions, and the processor is used to execute the computer programs / instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 10.