Message processing method and system, electronic device and storage medium
By performing flow control detection and policy determination on messages to be transmitted in the cloud computer system, the shortcomings of resource gateways in terms of stability and security are resolved, achieving efficient and secure message processing and improving the overall stability and security of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ALIBABA CLOUD COMPUTING CO LTD
- Filing Date
- 2024-12-18
- Publication Date
- 2026-06-19
AI Technical Summary
The resource gateway in the cloud PC system has significant shortcomings in terms of stability and security, resulting in low message processing efficiency. In particular, its performance and protection mechanisms face challenges when facing extreme message traffic and illegal connection requests.
By acquiring the messages to be transmitted between the cloud PC management service and the cloud PC image, traffic control detection is performed to determine the appropriate traffic control strategy. Based on the detection results, the processing method is determined to achieve intelligent and dynamic traffic control.
It improves the communication efficiency and security of cloud computing systems, ensures stable and reliable service quality under high load and security threats, and reduces excessive resource consumption caused by illegal requests.
Smart Images

Figure CN122247933A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network technology, and more specifically, to a message processing method, system, electronic device, and storage medium. Background Technology
[0002] A cloud PC system is a remote desktop solution based on cloud computing technology. By separating the functions and services of a personal computer from traditional local hardware and transferring them to cloud servers, users can access a virtual computer running in the cloud via the internet to perform daily office work, entertainment, software development, and other operations. The resource gateway plays a crucial role in a cloud PC system, acting as a bridge between the management system and the cloud PC operating system image (GuestOS), responsible for maintaining a long-term, stable, two-way communication channel to ensure efficient and secure real-time interaction. However, the resource gateway design in related technologies has significant shortcomings in terms of stability and security, further impacting the message processing efficiency of the cloud PC system.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This application provides a message processing method, system, electronic device, and storage medium to at least solve the technical problems of poor stability and security and low message processing efficiency in cloud computer systems.
[0005] According to one aspect of the embodiments of this application, a message processing method is provided, including: obtaining a message to be transmitted between a cloud computer management service and a cloud computer image; performing traffic control detection on the message to be transmitted to obtain a detection result, wherein the detection result is used to determine the traffic control strategy suitable for the message to be transmitted; and determining the processing method of the message to be transmitted based on the detection result.
[0006] According to one aspect of the embodiments of this application, a message processing system is also provided, including: a cloud computer management service, a cloud computer image, and a gateway service; the cloud computer management service is used to interact with the cloud computer image via the gateway service; the gateway service is used to obtain the message to be transmitted between the cloud computer management service and the cloud computer image, perform flow control detection on the message to be transmitted to obtain the detection result, and determine the processing method of the message to be transmitted based on the detection result, wherein the detection result is used to determine the flow control strategy suitable for the message to be transmitted.
[0007] According to one aspect of the embodiments of this application, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes any message processing method of any one of the embodiments of this application when it runs.
[0008] According to one aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to execute any of the message processing methods in the embodiments of this application.
[0009] According to one aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the message processing methods of various embodiments of this application.
[0010] According to one aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the message processing methods of various embodiments of this application.
[0011] According to one aspect of the embodiments of this application, a computer program is also provided, which, when executed by a processor, implements the message processing methods of the various embodiments of this application.
[0012] In this embodiment, by acquiring the message to be transmitted between the cloud PC management service and the cloud PC image, and then performing flow control detection on the message to be transmitted to obtain the detection result, the appropriate flow control strategy for the message to be transmitted is determined. Subsequently, based on the detection result, the processing method of the message to be transmitted is determined. This realizes intelligent and dynamic flow control of message transmission in the cloud PC system by the resource gateway, effectively improving communication efficiency and security, and ensuring stable and reliable service quality even under high load and security threats. In this embodiment, by realizing refined and real-time flow management and secure communication, the challenges faced by the resource gateway in large-scale cloud PC system deployments are effectively addressed. It not only improves the overall message processing efficiency of the system, but also reduces excessive resource consumption caused by illegal requests by responding and adjusting the flow control strategy in a timely manner. This significantly enhances the stability and security of the cloud PC system, thereby solving the technical problems of poor stability and security and low message processing efficiency in message processing in cloud PC systems.
[0013] It is worth noting that the general description above and the detailed description that follow are merely for illustrative purposes and do not constitute a limitation on this application. Attached Figure Description
[0014] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0015] Figure 1 This is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a message processing method according to an embodiment of this application;
[0016] Figure 2 This is a schematic diagram illustrating an application scenario of a message processing method according to an embodiment of this application;
[0017] Figure 3 This is a flowchart of a message processing method according to an embodiment of this application;
[0018] Figure 4 This is a schematic diagram of a message processing system according to an embodiment of this application;
[0019] Figure 5 This is a structural block diagram of a message processing apparatus according to an embodiment of this application;
[0020] Figure 6 This is a structural block diagram of a computer terminal according to an embodiment of this application. Detailed Implementation
[0021] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0022] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0023] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:
[0024] Cloud PC: Cloud-based virtual desktop is a cloud computing service model that allows users to connect to a virtual computer environment hosted on a remote server via the Internet. Cloud PC services are usually provided by cloud service providers and run through professional data centers.
[0025] Cloud PC Management: The core management system for cloud PCs, responsible for creating, deleting, and maintaining the configuration and resources of cloud PCs, as well as managing the lifecycle of cloud PCs.
[0026] Cloud PC Operating System Image (GuestOS): A cloud PC system deployed in the cloud, such as Windows, Linux, Android, etc., and also includes some agent plugins required for the cloud PC to run.
[0027] Resource Gateway: The resource gateway is responsible for management and long-term connection services for the GuestOS, and is responsible for bidirectional communication between them to ensure a persistent and low-latency communication channel.
[0028] As a core component, the resource gateway bears the crucial responsibility of bridging the cloud PC management and control interface with the cloud PC image GuestOS. By maintaining a long-term, stable, two-way communication channel, it ensures the efficiency and security of real-time interaction. Its core functions include implementing a two-way asynchronous message passing mechanism and guaranteeing high security for communication between the Guest and the management plane.
[0029] However, resource gateways present several challenges in terms of stability, specifically in the following aspects:
[0030] Uneven message transmission load and insufficient congestion control: In certain scenarios, potential defects within GuestOS may lead to abnormally high message sending frequencies. This phenomenon is not limited to the massive delivery of a single type of message but also involves multiple nodes concurrently sending the same message, creating a concentrated and intense request storm on the resource gateway. Furthermore, when messages are broadcast to all nodes, the scale effect (i.e., the product of the number of messages and the number of nodes) significantly exacerbates gateway resource consumption, especially in large-scale cluster deployments, where gateway resource occupancy reaches a critical state. Some gateways, due to excessive centralization of connection management, handle node connections beyond their design capacity, further worsening performance bottlenecks.
[0031] The lack of protection during secure connection establishment: In the initial stage of connection establishment, the gateway faces the risk of unauthorized access and lacks an effective mechanism to identify and reject malicious or illegal connection requests. Therefore, it is necessary to embed stricter security policies into the handshake and authentication processes to ensure that only legitimate entities are allowed to access, thus strengthening the first line of defense for system stability from the entry point.
[0032] In summary, the resource gateway design in related technologies has significant shortcomings in terms of stability and security, especially when facing extreme message traffic and illegal connection requests, its performance and protection mechanisms face severe challenges.
[0033] According to an embodiment of this application, a method embodiment for message processing is also provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0034] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, or similar computing devices. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a message processing method is shown. Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor (MCU) or a field-programmable gate array (FPGA) or similar processing device), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0035] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0036] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the message processing method in this embodiment. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned message processing method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0037] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0038] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0039] Figure 1 The hardware structure block diagram shown can serve not only as an exemplary block diagram of the aforementioned computer terminal 10 (or mobile device), but also as an exemplary block diagram of the aforementioned server. In one optional embodiment, Figure 2 The use of the above is illustrated in a block diagram. Figure 1 The computer terminal 10 (or mobile device) shown is one embodiment of the receiving end. For example... Figure 2As shown, computer terminal 10 (or mobile device) can be connected to one or more servers via a data network connection or electronically. In one alternative embodiment, the computer terminal 10 (or mobile device) can be any mobile computing device. The data network connection can be a local area network (LAN) connection, a wide area network (WAN) connection, an Internet connection, or other types of data network connection. Computer terminal 10 (or mobile device) can perform network services to connect to a network service performed by a server (e.g., a security server) or a group of servers 20. The network server is a network-based user service, such as social networks, cloud resources, email, online payments, or other online applications.
[0040] Under the aforementioned operating environment, this application provides the following: Figure 3 The message processing method shown. Figure 3 This is a flowchart of a message processing method according to an embodiment of this application, such as... Figure 3 As shown, the method includes the following steps:
[0041] Step S31: Obtain the message to be transmitted between the cloud computer management service and the cloud computer image;
[0042] Step S32: Perform flow control detection on the message to be transmitted and obtain the detection result, wherein the detection result is used to determine the flow control strategy that the message to be transmitted is adapted to.
[0043] Step S33: Determine the processing method for the message to be transmitted based on the detection results.
[0044] The message processing method in this embodiment can be executed by the gateway service, and the cloud PC management service interacts with the cloud PC image via the gateway service. The cloud PC management service is the core management component of the cloud PC system, responsible for the lifecycle management of cloud PC instances, including but not limited to the creation, configuration, startup, shutdown, and deletion of cloud PCs. It also monitors the running status and resource usage of cloud PCs and provides a unified interface for user management and resource scheduling.
[0045] Cloud PC images can be pre-configured templates for cloud PC instances, including but not limited to operating systems, pre-installed software, and specific settings and configurations. Cloud PC images can be versions of various operating systems or contain industry-specific application software, such as design software and development tools. When a user requests a cloud PC, a suitable image is selected from the image library based on the user's needs, and a cloud PC instance is quickly created based on this image. Users can start using it immediately without waiting for a lengthy initialization or configuration process.
[0046] The messages to be transmitted can be data or instructions that need to be exchanged between the cloud PC management service and the cloud PC image. These messages may include, but are not limited to: system configuration updates, resource usage reports, user operation commands (such as power on, power off, log off, etc.), security event notifications, application status, and logs. Message transmission is fundamental to the operation and management of the cloud PC system, ensuring that the cloud PC management service can monitor and control the cloud PC image in real time, while the cloud PC image can also promptly report its operating status and events back to the cloud PC management service.
[0047] For example, the method of obtaining the message to be delivered usually relies on the communication mechanism inside the message processing system, including but not limited to: request-response communication mode, event-driven mechanism, and subscription-publish mode. Through the above communication mechanisms, the cloud computer management service and the cloud computer image can exchange the message to be delivered efficiently and securely, ensuring the smooth operation of the system and a good user experience.
[0048] Specifically, in the request-response communication model, the cloud PC management service sends a request to the gateway service, specifying the cloud PC image to receive or send messages. The gateway service then communicates with the corresponding cloud PC image based on the request content to obtain the message to be delivered. In the event-driven mechanism, cloud PC images generate various events during operation, such as changes in resource usage and application state changes. These events are reported to the gateway service via an event notification system, for example, through a message queue (MQ) service or an event bridge service, and then transmitted to the cloud PC management service. The cloud PC management service can adjust the configuration or state of the cloud PCs in real time based on the event information. In the subscription-publish model, cloud PC images can subscribe to specific types of messages. When the cloud PC management service has a message that needs to be sent to a cloud PC image, it broadcasts the message to all relevant subscribed cloud PC images through the gateway service's publishing function, thereby achieving efficient message delivery.
[0049] After obtaining the message to be transmitted, a flow control test is performed on the message to be transmitted to obtain the test results. The flow control strategy suitable for the message to be transmitted is determined based on the test results. The flow control strategy includes, but is not limited to, pre-embedded whitelist and blacklist strategies, multi-dimensional flow control strategies, etc.
[0050] For example, during the flow control detection of messages to be delivered, it is first necessary to collect real-time flow data about the messages to be delivered, including but not limited to message sending and receiving frequency (Queries Per Second, QPS), response time (RT), message type, message size, and cloud computer image identifier. Real-time flow data can be collected through Log Service (SLS) and undergo preliminary cleaning and preprocessing to ensure data accuracy and availability. Based on the collected real-time flow data, it is necessary to monitor message flow trends in real time. For this purpose, a series of preset thresholds can be set. When the real-time flow data reaches or exceeds the preset thresholds, the flow control mechanism is triggered. The preset thresholds should be adjusted according to the system's historical load, resource limitations, and service requirements to ensure that premature flow limiting does not affect normal service, and also avoids system overload.
[0051] By analyzing real-time and historical traffic data, traffic patterns and potential abnormal behaviors can be identified. This can be achieved using statistical analysis methods, machine learning models, or rule-based systems. For example, if a sudden surge in the QPS of a certain type of message is detected, it may mean that the system is suffering from abnormal behavior and requires emergency traffic throttling. Based on the results of traffic analysis, appropriate traffic control strategies are intelligently matched and selected. The decision-making process must consider service continuity and user experience to avoid unnecessary traffic restrictions that could disrupt normal operations.
[0052] Furthermore, after determining the appropriate traffic control policy for the message to be transmitted based on the detection results, the message is processed according to the traffic control policy, such as transmitting or intercepting the message, thereby ensuring information security and reasonable traffic management. When the message to be transmitted meets the conditions of the traffic control policy, the system can process the message normally and transmit it to the target. When the detected message traffic exceeds a preset threshold, a rate limiting policy can be activated to intercept or delay the excess messages. Rate limiting policies can be implemented through various mechanisms, such as the token bucket algorithm, leaky bucket algorithm, and sliding window algorithm, to ensure the stability and responsiveness of the gateway service.
[0053] Based on the detection results, the processing method for the message to be transmitted is determined, and the message to be transmitted is processed. This enables intelligent adaptation to actual traffic, ensuring the stable operation of the resource gateway, while guaranteeing the timeliness and security of critical service operations. It effectively manages and controls network traffic, avoiding service interruptions caused by overload or security vulnerabilities.
[0054] Based on steps S31 to S33 above, by acquiring the message to be transmitted between the cloud computer management service and the cloud computer image, and then performing flow control detection on the message to be transmitted to obtain the detection result, the appropriate flow control strategy for the message to be transmitted is determined. Subsequently, the processing method of the message to be transmitted is determined based on the detection result. This realizes intelligent and dynamic flow control of message transmission in the cloud computer system by the resource gateway, effectively improving communication efficiency and security, and ensuring stable and reliable service quality even under high load and security threats. In this embodiment, by realizing refined and real-time flow management and secure communication, the challenges faced by the resource gateway in large-scale cloud computer system deployment are effectively addressed. It not only improves the overall message processing efficiency of the system, but also reduces excessive resource consumption caused by illegal requests by responding and adjusting the flow control strategy in a timely manner. This significantly enhances the stability and security of the cloud computer system, thereby solving the technical problems of poor stability and security and low message processing efficiency in message processing in cloud computer systems.
[0055] The message processing method in the embodiments of this application will be further described below.
[0056] In one optional embodiment, the message to be transmitted includes at least one of the following: a downlink message transmitted from the cloud PC management service to the cloud PC image; and an uplink message transmitted from the cloud PC image to the cloud PC management service.
[0057] Downlink messages refer to messages transmitted from the cloud PC management service to the cloud PC image. Downlink messages typically contain instructions or data issued by the cloud PC management service to the cloud PC image, such as system configuration updates, user operation requests (such as starting, stopping, or hibernating the cloud PC), or software deployments.
[0058] For example, in the downlink message processing flow, when a user operates through the management panel or the system needs to update the cloud PC status, a corresponding downlink message can be generated in the cloud PC management service. The cloud PC management service can send the downlink message to the gateway service's SendMsg interface via Hypertext Transfer Protocol (HTTP) for message transmission. After the downlink message arrives at the gateway service, a flow control check is first performed to verify whether the rate limiting mechanism has been triggered. If the rate limiting threshold is exceeded, the downlink message will be temporarily blocked and a retry will be prompted. The gateway service performs multi-dimensional flow management based on the message type of the downlink message and the traffic status of the cloud PC image to ensure that the downlink message can be processed according to priority and flow control policies. After flow control, the message will be sent to the corresponding cloud PC image through a websocket channel to complete the downlink message transmission. After receiving the message, the cloud PC image performs the corresponding operation or updates its status, completing the entire downlink message processing flow.
[0059] Uplink messages refer to messages transmitted from the cloud PC image to the cloud PC management service. Uplink messages can be status updates of the cloud PC image, operation feedback, error reports, or log data, typically reflecting the operating status of the cloud PC or the results of user operations. The processing flow of uplink messages is similar to that of downlink messages, the difference being that the starting point is the cloud PC image sending a message to the gateway service via the WebSocket channel. Subsequent traffic control, decision-making logic, and logging remain consistent, thus ensuring balanced management and control of bidirectional communication.
[0060] For example, in the uplink message processing flow, when the cloud PC image needs to report status changes to the management service or respond to user operations, it generates an uplink message. The cloud PC image sends the uplink message to the gateway service via a WebSocket long connection. After receiving the uplink message, the gateway service also performs flow control checks to ensure that message processing does not exceed the resource gateway's capacity. Based on the type of uplink message and the cloud PC's traffic status, the gateway service implements flow management strategies, including but not limited to queuing, rate limiting, or immediate processing. After flow control, the gateway service forwards the uplink message to the cloud PC management service, completing the uplink message transmission. After receiving the uplink message, the cloud PC management service performs corresponding processing based on the message content, such as updating cloud PC status information, recording operation logs, or triggering automatic responses.
[0061] When processing downlink and uplink messages, the message processing method must be dynamically adjusted based on real-time traffic conditions and security requirements to ensure the stability and responsiveness of the cloud computer system under high load and potential security threats.
[0062] In one optional embodiment, the traffic control strategy includes at least one of the following: a pre-embedded whitelist strategy, a pre-embedded blacklist strategy, and a multi-dimensional traffic control strategy.
[0063] The aforementioned traffic control strategies provide cloud PC systems with more comprehensive protection and more granular traffic management capabilities. These strategies can be used individually or in combination. A single strategy is suitable for scenarios where there is a clear understanding of specific types of traffic or security requirements. For example, in the initial stages of the system, where only the permission of legitimate messages needs to be granted, a pre-embedded whitelist strategy can be prioritized. However, when illegitimate traffic becomes the primary threat, a pre-embedded blacklist strategy will be more effective.
[0064] In complex and ever-changing network environments, combining traffic control strategies can provide a more flexible and powerful traffic control framework. For example, multi-dimensional traffic control strategies can be overlaid on top of pre-embedded whitelist strategies to ensure the rapid passage of legitimate traffic while dynamically adjusting traffic control parameters to cope with sudden high loads. Alternatively, multi-dimensional traffic control can be introduced on top of pre-embedded blacklist strategies to more granularly control the traffic of potential threat sources, avoiding a one-size-fits-all approach to blocking and maintaining the openness and availability of the system.
[0065] In an optional embodiment, the traffic control strategy includes: a pre-embedded whitelist strategy and a blacklist strategy. In step S33, determining the processing method for the message to be transmitted based on the detection results includes:
[0066] The response determines whether the message to be transmitted is compatible with the whitelist policy based on the detection results and then transmits the message; or, the response determines whether the message to be transmitted is compatible with the blacklist policy based on the detection results and then intercepts the message.
[0067] In long-connection communication scenarios, ensuring the stable transmission of critical messages such as "create" and "power on" is crucial. Therefore, the traffic control system includes pre-embedded blacklist and whitelist policies to ensure that core service messages can be prioritized for uninterrupted transmission even under traffic-limited conditions, thereby improving the overall service reliability and user experience.
[0068] The aforementioned whitelist policy is typically used to ensure that critical service messages or messages from trusted users are delivered securely and with priority. For example, when detection results show that a message to be delivered originates from a predefined whitelist, or that the message type belongs to a high-priority service, it can be determined that the message is compatible with the whitelist policy and is then delivered. Specifically, a traffic detection mechanism identifies whether a message to be delivered meets the whitelist criteria, including but not limited to checking the source IP, user identifier, message type, or service tag of the message. If the message is within the whitelist, standard traffic control restrictions are bypassed or relaxed, ensuring that the message can be delivered to the target cloud PC image or cloud PC management service in a timely and unimpeded manner. Furthermore, by recording the delivery status of whitelisted messages, including whether the delivery was successful and the delivery time, transparency of core service processes is maintained, and this information is used for subsequent analysis and optimization.
[0069] The aforementioned blacklist policy is used to identify and block potential malicious or abnormal traffic to protect system resources and data security. When the detection results show that a message to be transmitted meets the blacklist criteria, the message is intercepted. Specifically, abnormal behavior or unauthorized access attempts are identified by monitoring traffic data such as QPS, RT, and source IP access patterns. If a message to be transmitted is marked as a message within the blacklist range, it will be immediately intercepted, preventing further transmission and triggering system alerts or logging relevant information. Furthermore, additional security verification steps can be added during the handshake and authentication phases, such as multi-factor authentication, IP address filtering, or dynamic request verification, to prevent subsequent unauthorized access. For intercepted messages, error feedback can be provided to the message sender, and warnings can be sent to administrators or operations personnel through the detection system, indicating potential security threats or system abuse.
[0070] Based on the above optional embodiments, by employing whitelist and blacklist policies, the cloud computing system can intelligently filter and prioritize messages, ensuring the continuity and efficiency of important services while effectively protecting the system from illegal or abnormal traffic, thereby maintaining overall system stability and network security. Through dynamic adjustment and real-time application of these policies, relying on the system's powerful real-time monitoring and data analysis capabilities, as well as a flexible configuration update mechanism, the effectiveness and adaptability of the whitelist and blacklist policies are ensured.
[0071] In an optional embodiment, the flow control strategy includes a multi-dimensional flow regulation strategy. In step S33, determining the processing method for the message to be transmitted based on the detection results includes:
[0072] The response determines whether the message to be transmitted triggers the rate limiting rule and adapts to the multi-dimensional traffic control strategy based on the detection results, and determines whether the cloud computer dimension token and the message type dimension token have been obtained respectively; in response to obtaining the cloud computer dimension token and the message type dimension token respectively, the message to be transmitted is transmitted.
[0073] The aforementioned multi-dimensional traffic control strategies include cloud PC-level control strategies and message type-level control strategies. The cloud PC-level control strategies can adjust the traffic based on the traffic status of each cloud PC, while the message type-level control strategies can implement detailed traffic restrictions for different message types.
[0074] When the detection results determine that the message to be transmitted has reached the traffic limit, a rate limiting rule is triggered. The message to be transmitted is then adapted to a multi-dimensional traffic control strategy, determining whether it has obtained both cloud PC-level tokens and message type-level tokens. This is achieved by monitoring the traffic status of the cloud PC system in real time, including metrics such as QPS and RT, as well as specific behaviors of message types and cloud PCs. If the traffic exceeds a preset threshold, a rate limiting rule is triggered for the message to be transmitted, and a multi-dimensional traffic control strategy is employed to process the message, including traffic control based on the cloud PC dimension and traffic control based on the message type dimension.
[0075] For example, the system first attempts to obtain a token from the token bucket at the cloud PC level. The token bucket algorithm allocates a token pool to each cloud PC to control the message sending rate associated with that cloud PC. If a token is successfully obtained at the cloud PC level, it indicates that traffic control at the cloud PC level has passed. Subsequently, tokens are obtained from the token bucket at the message type level, which is used to refine the control of the sending frequency of different message types, ensuring reasonable resource allocation. If a token is successfully obtained at the message type level, traffic control at the message type level has passed.
[0076] When both the cloud PC dimension token and the message type dimension token are obtained, it indicates that the flow control for the message to be transmitted has passed the checks in both dimensions. At this point, it can be determined that the message can be transmitted securely and effectively without overloading the resource gateway. Based on the above assessment and decision, the message will be allowed to pass through the resource gateway and be sent to the target cloud PC image or cloud PC management service, completing the message transmission process.
[0077] Based on the above optional embodiments, multi-dimensional traffic control strategies can be intelligently adjusted and applied according to real-time traffic detection results, ensuring both the stable operation of the cloud PC system and maintaining the efficiency and security of message transmission. Through dynamic traffic control based on the token bucket algorithm, the challenges of high-concurrency requests and abnormal traffic can be effectively addressed, providing cloud PC users with a consistent and reliable interactive experience.
[0078] In one optional embodiment, the message processing method in this application includes:
[0079] If the cloud computer dimension token is not obtained, the message to be delivered will be intercepted; or, if the cloud computer dimension token is obtained but the message type dimension token is not obtained, the message to be delivered will be intercepted.
[0080] Specifically, the system monitors traffic in the cloud PC system in real time, including metrics such as QPS and RT, as well as message types and specific behaviors of the cloud PCs. If traffic exceeds a preset threshold, a rate-limiting rule is triggered for the message to be delivered, and a multi-dimensional traffic control strategy is employed to process the message. First, an attempt is made to obtain a token from the token bucket at the cloud PC level. If the current traffic of the cloud PC exceeds the set threshold, the token bucket may be empty or not ready for refilling, resulting in the inability to obtain a token at the cloud PC level, and the message to be delivered is then blocked. Even if a token at the cloud PC level is obtained, the token bucket at the message type level is further checked. If the traffic at the message type level exceeds the control range and a token at the message type level cannot be obtained, the message to be delivered is then blocked.
[0081] Furthermore, intercepted messages can be placed in a waiting queue or discarded directly, depending on the system configuration. Simultaneously, the interception event is recorded, including message representation, interception time, and reason for interception, facilitating subsequent analysis. After message interception, error information is sent to the sender, informing them that the message failed flow control, and providing possible retry strategies or suggestions to help the user understand the reason for message delivery failure and take appropriate measures. Based on the interception event, the token bucket algorithm parameters can also be dynamically adjusted, such as increasing the token generation rate or decreasing the threshold, to adapt to constantly changing traffic conditions, improving overall flow control efficiency and system performance.
[0082] Based on the above optional embodiments, the bidirectional communication between the cloud computer and the control plane can be precisely controlled, ensuring that the resource gateway can maintain a stable service level under high load or abnormal traffic conditions, while avoiding service degradation or interruption caused by excessive resource consumption. The interception decision is based on a multi-dimensional traffic control strategy, further realizing more refined and intelligent traffic management.
[0083] In an optional embodiment, in step S33, determining the processing method of the message to be transmitted based on the detection result includes: responding to the detection result that the message to be transmitted has not triggered the rate limiting rule, and transmitting the message to be transmitted.
[0084] By monitoring the traffic status of the cloud PC system in real time, including metrics such as QPS and RT, as well as message types and specific behaviors of the cloud PCs, if the traffic is detected to be within the preset threshold, it will be determined that the message to be transmitted has not triggered the rate limiting rules, and the message to be transmitted will be transmitted directly. That is, messages that have not reached the traffic limit will be forwarded successfully.
[0085] In an optional embodiment, the message processing method in this application further includes:
[0086] Receive alarm notifications reported by the log service. The alarm notifications are triggered when traffic anomalies are determined based on traffic log records. The traffic log records are used to record the current traffic status of the gateway service. In response to the alarm notification, recalculate the maximum number of tokens that the token bucket can hold and obtain the calculation result. Reset the token bucket based on the calculation result.
[0087] The log service automatically identifies abnormal traffic conditions by analyzing traffic log records. For example, excessively high QPS or RT may indicate that the system is facing a high-density request storm or potential security threats, such as a Distributed Denial-of-Service (DDoS) attack. When the log service confirms an abnormal traffic situation—that is, QPS or RT exceeds a preset threshold—it will trigger an alarm notification. The alarm notification will be sent to the gateway service layer or a dedicated management node to notify relevant components in the system. Upon receiving the alarm notification, the gateway service layer or management node initiates a response mechanism, which includes checking whether the current traffic control policy is sufficient to handle abnormal traffic and assessing whether the token bucket algorithm parameters need to be adjusted to cope with the new traffic conditions.
[0088] Based on the traffic anomaly information in the alarm notification, the maximum number of tokens the token bucket can hold is recalculated. This typically involves adjusting parameters such as the token generation rate, token pool capacity, or rate limiting threshold to accommodate higher traffic demands or stricter security controls. Based on the recalculated maximum token capacity, the token bucket is reset or updated to ensure it adapts to the current traffic conditions. For example, increasing the token generation rate or expanding the token pool capacity allows more messages to pass through; or reducing token generation or lowering the threshold for stricter traffic control. Simultaneously, the updated traffic control policy, including token bucket parameter adjustments, is propagated in real-time to all relevant gateway nodes. This can be achieved through a configuration update service to ensure all nodes synchronize the latest traffic control policies to handle abnormal traffic. By continuously monitoring traffic conditions and dynamically adjusting token bucket parameters as needed, while recording every policy adjustment and traffic anomaly event, data is provided for subsequent system improvements.
[0089] Based on the above optional embodiments, by receiving alarm notifications reported by the log service, and then responding to the alarm notifications, recalculating the upper limit of the number of tokens that the token bucket can hold, obtaining the calculation result, and finally resetting the token bucket based on the calculation result, the cloud computer system can realize real-time response and dynamic control to traffic anomalies, which not only ensures the stability and reliability of the system under high load, but also provides immediate protection against potential security threats, maintaining the efficient operation and data security of the entire system.
[0090] In one optional embodiment, the traffic log records include: a first traffic statistics data point and a second traffic statistics data point, wherein the first traffic statistics data point is used to count the number of request messages concurrently processed by the gateway service within a unit of time, and the second traffic statistics data point is used to count the time taken for the gateway service to process downlink messages transmitted from the cloud PC management service to the cloud PC image and uplink messages transmitted from the cloud PC image to the cloud PC management service.
[0091] The first traffic statistic mentioned above can be QPS (Queries Per Second) data, and the second traffic statistic can be RT (Response Time) data. The first traffic statistic records and tracks the number of concurrent request messages processed by the gateway service within a specific unit of time, typically reflecting the gateway service's load and processing capacity. By using the first traffic statistic, the QPS of the gateway service can be monitored in real time, allowing for timely detection of the potential impact of high-concurrency requests on the service, such as performance bottlenecks or signs of DDoS attacks. When the resource gateway encounters a large number of requests, the first traffic statistic helps identify whether a traffic control policy needs to be activated and how to dynamically adjust the token bucket algorithm parameters to avoid service overload or prolonged response times.
[0092] Secondary traffic statistics are used to record and analyze the average or longest time (RT) experienced by the gateway service in processing downlink and uplink messages. Downlink messages refer to messages transmitted from the cloud PC management service to the cloud PC image, while uplink messages are transmitted in reverse order. Secondary traffic statistics help assess message transmission efficiency and network latency, as well as the system's stability when processing bidirectional messages. When secondary traffic statistics show an abnormally high RT, it may indicate network congestion, insufficient resources, or bottlenecks in the processing logic. In this case, measures can be taken to improve the message processing flow, reduce latency, or adjust traffic control strategies to avoid further performance degradation.
[0093] Based on the above optional embodiments, the first traffic statistics recorded in the traffic log are used to count the number of concurrent request messages processed by the gateway service per unit time. This enables accurate monitoring and quantification of the real-time load of the gateway service, providing a basis for decision-making in dynamic traffic control strategies. The second traffic statistics are used to count the time taken for the gateway service to process downlink messages transmitted from the cloud PC management service to the cloud PC image and uplink messages transmitted from the cloud PC image to the cloud PC management service. This not only helps monitor message transmission latency but also identifies potential performance bottlenecks or communication anomalies. By combining the first and second traffic statistics, a comprehensive assessment of the gateway service's processing capabilities can be provided, including the frequency and efficiency of its request processing. Through continuous monitoring and analysis, traffic control strategies can be intelligently adjusted to maintain good network performance and user experience, while also addressing potential security threats and ensuring the stable operation of the cloud PC system.
[0094] In one alternative embodiment, traffic anomalies are determined based on a first traffic statistic exceeding a first preset threshold and / or a second traffic statistic exceeding a second preset threshold.
[0095] Specifically, when the first traffic statistics exceed the first preset threshold, it means that within a given time period, the number of request messages processed by the gateway service exceeds the system's preset upper limit. The first preset threshold can be set based on the gateway service's processing capacity and historical traffic data. Exceeding the first preset threshold indicates that the system is experiencing abnormal traffic conditions such as high load, performance bottlenecks, or DDoS attacks.
[0096] When the second traffic statistics exceed the second preset threshold, it reflects that the gateway service has exceeded the maximum allowed time in processing uplink and downlink messages. The second threshold is typically set to ensure the real-time performance and efficiency of message processing. If the response time is too long, it indicates problems such as network congestion, excessively complex processing logic, or improper resource allocation.
[0097] When either the first or second traffic statistics value exceeds its corresponding preset threshold, or both exceed their respective preset thresholds simultaneously, a traffic anomaly will be identified, triggering an appropriate emergency response mechanism, such as alarm notifications and dynamic traffic control policy adjustments. Specific response measures include increasing the token generation speed of the token bucket, adjusting the token pool capacity, enabling stricter flow control rules, or increasing cloud resources to mitigate the impact of abnormal traffic on system performance and restore normal service operation.
[0098] In an optional embodiment, the message processing method in this application further includes:
[0099] Receive configuration notifications pushed by the configuration center, which are used to update the traffic control configuration information of the gateway service; reset the token bucket of the gateway service based on the configuration notifications.
[0100] Specifically, when the configuration center detects changes in traffic control configuration information, including but not limited to adjusting token bucket parameters such as token generation rate, bucket capacity, or rate limiting threshold, it generates a configuration notification containing the updated traffic control configuration information.
[0101] The configuration center pushes configuration notifications to each gateway service in real time, which can be accomplished through an event-driven framework or service to ensure that all relevant components can obtain the latest configuration information in a timely manner. Upon receiving the configuration notification from the configuration center, the gateway service parses the configuration information in the notification and identifies the traffic control policies that need to be updated. Based on the new parameters in the configuration notification, the gateway service resets or updates the token bucket, such as clearing the current token pool, adjusting the generation rate, or modifying the maximum capacity, to ensure that the token bucket can adapt to the new traffic control requirements. After the token bucket is reset, traffic conditions are continuously monitored, and new traffic data is recorded and analyzed through a log service to verify the effect of the configuration changes. Parameters are adjusted based on real-time feedback to achieve dynamic traffic management.
[0102] Based on the above optional embodiments, by receiving configuration notifications pushed by the configuration center and then resetting the token bucket of the gateway service based on the configuration notifications, the gateway service can quickly respond to changes in the control policy of the configuration center and dynamically adjust the parameters of the token bucket to adapt to the ever-changing traffic demands and security environment. This enhances the security and stability of the system and ensures that efficient and secure communication services can be provided even under high load or potential security threats.
[0103] In an optional embodiment, the message processing method in this application further includes:
[0104] Verify whether the flow control function in the gateway service is active; in response to the flow control function being active, determine whether to perform flow control detection on the message to be transmitted.
[0105] Once the message to be transmitted enters the gateway service, the first step is to verify whether the flow control function is activated. If the flow control function is enabled, the flow assessment phase is entered to determine whether to perform flow control detection on the message to be transmitted.
[0106] Based on the above optional embodiments, the gateway service can intelligently determine whether traffic control detection of messages is required, and flexibly enable or adjust traffic management strategies according to the activation status of the traffic control function, so as to ensure the performance and response speed of the cloud computer system when facing high traffic and potential security threats.
[0107] Figure 4 This is a schematic diagram of a message processing system according to an embodiment of this application, such as... Figure 4 As shown, the message processing system includes: a cloud PC management service, a cloud PC image, and a gateway service. The cloud PC management service interacts with the cloud PC image via the gateway service. The gateway service acquires messages to be transmitted between the cloud PC management service and the cloud PC image, performs flow control detection on these messages to obtain the detection results, and determines the processing method for the messages based on the detection results. The detection results are used to determine the appropriate flow control strategy for the messages to be transmitted. Messages to be transmitted include at least one of the following: downlink messages from the cloud PC management service to the cloud PC image; and uplink messages from the cloud PC image to the cloud PC management service. The gateway service can send messages to be transmitted to the corresponding cloud PC image via a WebSocket channel.
[0108] The log service in the message processing system is used to report alarm notifications. Alarm notifications are triggered when traffic anomalies are detected based on traffic log records. Traffic log records document the current traffic status of the gateway service. In response to alarm notifications, the gateway service recalculates the maximum number of tokens the token bucket can hold and resets the token bucket based on the calculation result. Traffic control policies include multi-dimensional traffic regulation policies, specifically cloud PC-level and message type-level policies. The system responds by determining whether to trigger rate limiting rules for messages to be transmitted based on detection results and adapting to the multi-dimensional traffic regulation policies, and then determines whether cloud PC-level and message type-level tokens have been acquired respectively. Upon acquiring both cloud PC-level and message type-level tokens, the message to be transmitted is transmitted. The message processing system can also utilize the configuration center to push configuration notifications to update the gateway service's traffic control configuration information. The gateway service can reset its token bucket based on these configuration notifications.
[0109] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0110] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0111] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0112] According to an embodiment of this application, a message processing apparatus for implementing the above-described message processing method is also provided. Figure 5 This is a structural block diagram of a message processing apparatus according to an embodiment of this application, such as... Figure 5 As shown, the device includes:
[0113] Module 501 is used to acquire messages to be transmitted between the cloud PC management service and the cloud PC image.
[0114] The detection module 502 is used to perform flow control detection on the message to be transmitted and obtain the detection result, wherein the detection result is used to determine the flow control strategy that the message to be transmitted is adapted to.
[0115] The determination module 503 is used to determine the processing method of the message to be transmitted based on the detection results.
[0116] Optionally, the message to be transmitted includes at least one of the following: a downlink message from the cloud PC management service to the cloud PC image; or an uplink message from the cloud PC image to the cloud PC management service.
[0117] Optionally, the traffic control strategy includes at least one of the following: a pre-embedded whitelist strategy, a pre-embedded blacklist strategy, or a multi-dimensional traffic control strategy.
[0118] Optionally, the determining module 503 is further configured to: respond to determining that the message to be transmitted is adapted to a whitelist policy based on the detection results, and transmit the message to be transmitted; or, respond to determining that the message to be transmitted is adapted to a blacklist policy based on the detection results, and intercept the message to be transmitted.
[0119] Optionally, the determining module 503 is further configured to: respond to determining, based on the detection results, that the message to be transmitted triggers a rate limiting rule and adapts to a multi-dimensional traffic control strategy, determine whether the cloud computer dimension token and the message type dimension token have been obtained respectively; and respond to obtaining the cloud computer dimension token and the message type dimension token respectively, transmit the message to be transmitted.
[0120] Optionally, the determining module 503 is further configured to: intercept the message to be transmitted in response to the failure to obtain the cloud computer dimension token; or, intercept the message to be transmitted in response to the acquisition of the cloud computer dimension token but the failure to obtain the message type dimension token.
[0121] Optionally, the determining module 503 is also used to: respond to a determination based on the detection result that the message to be transmitted has not triggered the rate limiting rule, and transmit the message to be transmitted.
[0122] Optionally, the message processing device further includes: a receiving module 504, used to receive alarm notifications reported by the log service, wherein the alarm notification is triggered when a traffic anomaly is determined based on traffic log records, and the traffic log records are used to record the current traffic status of the gateway service; a processing module 505, used to recalculate the upper limit of the number of tokens that the token bucket can hold in response to the alarm notification, and obtain the calculation result; and a reset module 506, used to reset the token bucket based on the calculation result.
[0123] Optionally, the traffic log records include: a first traffic statistics data point and a second traffic statistics data point, wherein the first traffic statistics data point is used to count the number of request messages concurrently processed by the gateway service within a unit of time, and the second traffic statistics data point is used to count the time taken for the gateway service to process downlink messages transmitted from the cloud PC management service to the cloud PC image and uplink messages transmitted from the cloud PC image to the cloud PC management service.
[0124] Optionally, traffic anomalies are determined based on a first traffic statistic exceeding a first preset threshold and / or a second traffic statistic exceeding a second preset threshold.
[0125] Optionally, the receiving module 504 is also used to receive a configuration notification pushed by the configuration center, wherein the configuration notification is used to update the traffic control configuration information of the gateway service; the reset module 506 is also used to reset the token bucket of the gateway service based on the configuration notification.
[0126] Optionally, the message processing device further includes: a verification module 507 for verifying whether the flow control function in the gateway service is active; and a detection module 502 for determining to perform flow control detection on the message to be transmitted in response to the flow control function being active.
[0127] It should be noted that the acquisition module 501, detection module 502, and determination module 503 mentioned above correspond to steps S31 to S33 in the embodiments. The three modules and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of the device and run in the computer terminal 10 provided in the embodiments.
[0128] Embodiments of this application may provide a message processing system, including: a cloud computer management service, a cloud computer image, and a gateway service; the cloud computer management service is used to interact with the cloud computer image via the gateway service; the gateway service is used to obtain messages to be transmitted between the cloud computer management service and the cloud computer image, perform flow control detection on the messages to be transmitted to obtain detection results, and determine the processing method of the messages to be transmitted based on the detection results, wherein the detection results are used to determine the flow control strategy suitable for the messages to be transmitted.
[0129] Optionally, the message processing system in this application embodiment further includes: a log service; the log service is used to report alarm notifications, wherein the alarm notification is triggered when traffic anomalies are determined based on traffic log records, and the traffic log records are used to record the current traffic status of the gateway service; the gateway service is also used to respond to the alarm notification, recalculate the upper limit of the number of tokens that the token bucket can hold to obtain the calculation result, and reset the token bucket based on the calculation result.
[0130] Optionally, the message processing system in this embodiment further includes: a configuration center; the configuration center is used to push configuration notifications, wherein the configuration notifications are used to update the traffic control configuration information of the gateway service; the gateway service is also used to reset the token bucket of the gateway service based on the configuration notifications.
[0131] Embodiments of this application may provide a computer terminal, which may be any computer terminal device in a group of computer terminals. Optionally, in this embodiment, the aforementioned computer terminal may also be replaced by a mobile terminal or other terminal device.
[0132] Optionally, in this embodiment, the computer terminal may be located in at least one of a plurality of network devices in a computer network.
[0133] In this embodiment, the computer terminal described above can execute the program code for the following steps in the message processing method: obtaining the message to be transmitted between the cloud computer management service and the cloud computer image; performing flow control detection on the message to be transmitted and obtaining the detection result, wherein the detection result is used to determine the flow control strategy suitable for the message to be transmitted; and determining the processing method of the message to be transmitted based on the detection result.
[0134] Optionally, Figure 6 This is a structural block diagram of a computer terminal according to an embodiment of this application. Figure 6 As shown, the computer terminal may include: one or more (only one is shown in the figure) processors 62, memory 64, memory controller, and peripheral interfaces, wherein the peripheral interfaces are connected to a radio frequency module, an audio module, and a display.
[0135] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the message processing method and apparatus in this application embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the aforementioned message processing method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0136] The processor can access information and applications stored in the memory via the transmission device to perform the following steps: obtain the message to be transmitted between the cloud computer management service and the cloud computer image; perform flow control detection on the message to be transmitted and obtain the detection result, wherein the detection result is used to determine the flow control policy suitable for the message to be transmitted; and determine the processing method of the message to be transmitted based on the detection result.
[0137] Optionally, the message to be transmitted includes at least one of the following: a downlink message from the cloud PC management service to the cloud PC image; or an uplink message from the cloud PC image to the cloud PC management service.
[0138] Optionally, the traffic control strategy includes at least one of the following: a pre-embedded whitelist strategy, a pre-embedded blacklist strategy, or a multi-dimensional traffic control strategy.
[0139] Optionally, the processor may also execute program code that performs the following steps: responds to determine that the message to be transmitted is compatible with the whitelist policy based on the detection result, and transmits the message to be transmitted; or, responds to determine that the message to be transmitted is compatible with the blacklist policy based on the detection result, and intercepts the message to be transmitted.
[0140] Optionally, the processor may also execute program code that performs the following steps: responds to determining, based on the detection results, that the message to be transmitted triggers a rate limiting rule and adapts to a multi-dimensional traffic control strategy, and determines whether the cloud computer dimension token and the message type dimension token are obtained respectively; and responds to obtaining the cloud computer dimension token and the message type dimension token respectively, transmits the message to be transmitted.
[0141] Optionally, the processor may also execute program code that performs the following steps: intercepting the message to be delivered in response to not obtaining the cloud computer dimension token; or, intercepting the message to be delivered in response to obtaining the cloud computer dimension token but not the message type dimension token.
[0142] Optionally, the processor may also execute program code that performs the following steps: based on the detection result, if it is determined that the message to be transmitted has not triggered the rate limiting rule, the message to be transmitted is transmitted.
[0143] Optionally, the processor may also execute program code that performs the following steps: receiving alarm notifications reported by the log service, wherein the alarm notification is triggered when traffic anomalies are determined to have occurred based on traffic log records, and the traffic log records are used to record the current traffic status of the gateway service; in response to the alarm notification, recalculating the upper limit of the number of tokens that the token bucket can hold, and obtaining the calculation result; and resetting the token bucket based on the calculation result.
[0144] Optionally, the traffic log records include: a first traffic statistics data point and a second traffic statistics data point, wherein the first traffic statistics data point is used to count the number of request messages concurrently processed by the gateway service within a unit of time, and the second traffic statistics data point is used to count the time taken for the gateway service to process downlink messages transmitted from the cloud PC management service to the cloud PC image and uplink messages transmitted from the cloud PC image to the cloud PC management service.
[0145] Optionally, traffic anomalies are determined based on a first traffic statistic exceeding a first preset threshold and / or a second traffic statistic exceeding a second preset threshold.
[0146] Optionally, the processor may also execute program code that performs the following steps: receiving a configuration notification pushed by the configuration center, wherein the configuration notification is used to update the traffic control configuration information of the gateway service; and resetting the token bucket of the gateway service based on the configuration notification.
[0147] Optionally, the processor may also execute program code that performs the following steps: verifying whether the flow control function in the gateway service is active; and determining to perform flow control detection on the message to be transmitted in response to the flow control function being active.
[0148] This application's embodiments acquire messages to be transmitted between the cloud PC management service and the cloud PC image, then perform flow control detection on these messages to determine the appropriate flow control strategy. Based on the detection results, the processing method for the messages is then determined. This achieves intelligent and dynamic flow control of message transmission in the cloud PC system by the resource gateway, effectively improving communication efficiency and security, and ensuring stable and reliable service quality even under high load and security threats. In this application's embodiments, by implementing refined, real-time flow management and secure communication, the challenges faced by resource gateways in large-scale cloud PC system deployments are effectively addressed. This not only improves the overall message processing efficiency of the system but also reduces excessive resource consumption caused by illegal requests by timely response and adjustment of flow control strategies. This significantly enhances the stability and security of the cloud PC system, thus solving the technical problems of poor stability and security and low message processing efficiency in related technologies when processing messages in cloud PC systems.
[0149] Those skilled in the art will understand that Figure 6 The structure shown is for illustrative purposes only. The computer terminal can also be a smartphone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, or a mobile Internet device (MID). Figure 6 This does not limit the structure of the aforementioned electronic devices. For example, a computer terminal may also include components that are more... Figure 6 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 6 The different configurations shown.
[0150] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0151] Embodiments of this application also provide a computer-readable storage medium. Optionally, in this embodiment, the storage medium can be used to store the program code executed by the message processing method provided in the above embodiments.
[0152] Optionally, in this embodiment, the storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.
[0153] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: obtaining a message to be transmitted between the cloud computer management service and the cloud computer image; performing flow control detection on the message to be transmitted to obtain a detection result, wherein the detection result is used to determine the flow control strategy suitable for the message to be transmitted; and determining the processing method of the message to be transmitted based on the detection result.
[0154] Optionally, the message to be transmitted includes at least one of the following: a downlink message from the cloud PC management service to the cloud PC image; or an uplink message from the cloud PC image to the cloud PC management service.
[0155] Optionally, the traffic control strategy includes at least one of the following: a pre-embedded whitelist strategy, a pre-embedded blacklist strategy, or a multi-dimensional traffic control strategy.
[0156] Optionally, the storage medium is configured to store program code for performing the following steps: responding to determine that the message to be transmitted is compatible with a whitelist policy based on the detection result, and transmitting the message to be transmitted; or, responding to determine that the message to be transmitted is compatible with a blacklist policy based on the detection result, and intercepting the message to be transmitted.
[0157] Optionally, the storage medium is configured to store program code for performing the following steps: responding to determine, based on the detection results, that the message to be transmitted triggers a rate limiting rule and adapts to a multi-dimensional traffic control strategy, and determining whether the cloud computer dimension token and the message type dimension token are obtained respectively; responding to the acquisition of the cloud computer dimension token and the message type dimension token respectively, transmitting the message to be transmitted.
[0158] Optionally, the storage medium is configured to store program code for performing the following steps: intercepting the message to be delivered in response to not obtaining a cloud computer dimension token; or, intercepting the message to be delivered in response to obtaining a cloud computer dimension token but not a message type dimension token.
[0159] Optionally, the storage medium is configured to store program code for performing the following steps: the response determines, based on the detection result, that the message to be delivered has not triggered the rate limiting rule, and then delivers the message to be delivered.
[0160] Optionally, the storage medium is configured to store program code for performing the following steps: receiving alarm notifications reported by the log service, wherein the alarm notification is triggered when a traffic anomaly is determined based on traffic log records, and the traffic log records are used to record the current traffic status of the gateway service; in response to the alarm notification, recalculating the maximum number of tokens that the token bucket can hold, and obtaining the calculation result; and resetting the token bucket based on the calculation result.
[0161] Optionally, the traffic log records include: a first traffic statistics data point and a second traffic statistics data point, wherein the first traffic statistics data point is used to count the number of request messages concurrently processed by the gateway service within a unit of time, and the second traffic statistics data point is used to count the time taken for the gateway service to process downlink messages transmitted from the cloud PC management service to the cloud PC image and uplink messages transmitted from the cloud PC image to the cloud PC management service.
[0162] Optionally, traffic anomalies are determined based on a first traffic statistic exceeding a first preset threshold and / or a second traffic statistic exceeding a second preset threshold.
[0163] Optionally, the storage medium is configured to store program code for performing the following steps: receiving a configuration notification pushed by the configuration center, wherein the configuration notification is used to update the traffic control configuration information of the gateway service; and resetting the token bucket of the gateway service based on the configuration notification.
[0164] Optionally, the storage medium is configured to store program code for performing the following steps: verifying whether the flow control function in the gateway service is active; and determining to perform flow control detection on the message to be transmitted in response to the flow control function being active.
[0165] This application's embodiments acquire messages to be transmitted between the cloud PC management service and the cloud PC image, then perform flow control detection on these messages to determine the appropriate flow control strategy. Based on the detection results, the processing method for the messages is then determined. This achieves intelligent and dynamic flow control of message transmission in the cloud PC system by the resource gateway, effectively improving communication efficiency and security, and ensuring stable and reliable service quality even under high load and security threats. In this application's embodiments, by implementing refined, real-time flow management and secure communication, the challenges faced by resource gateways in large-scale cloud PC system deployments are effectively addressed. This not only improves the overall message processing efficiency of the system but also reduces excessive resource consumption caused by illegal requests by timely response and adjustment of flow control strategies. This significantly enhances the stability and security of the cloud PC system, thus solving the technical problems of poor stability and security and low message processing efficiency in related technologies when processing messages in cloud PC systems.
[0166] Embodiments of this application also provide a computer program product. Optionally, in this embodiment, the computer program product may include a computer program that, when executed by a processor, implements the methods provided in the embodiments described above.
[0167] Embodiments of this application also provide a computer program product. Optionally, the computer program product may include a non-volatile computer-readable storage medium, which can be used to store a computer program that, when executed by a processor, implements the method provided in the above embodiments.
[0168] Embodiments of this application also provide a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it implements the method provided in the above embodiments.
[0169] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0170] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0171] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0172] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0173] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0174] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0175] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A message processing method, characterized in that, include: Retrieve pending messages between the cloud PC management service and the cloud PC image; The message to be transmitted is subjected to flow control detection to obtain a detection result, wherein the detection result is used to determine the flow control strategy suitable for the message to be transmitted; The processing method for the message to be transmitted is determined based on the detection results.
2. The message processing method according to claim 1, characterized in that, The message to be transmitted includes at least one of the following: Downlink messages transmitted from the cloud computer management service to the cloud computer image; Uplink messages transmitted from the cloud computer image to the cloud computer management service.
3. The message processing method according to claim 1, characterized in that, The traffic control strategy includes at least one of the following: a pre-embedded whitelist strategy, a pre-embedded blacklist strategy, and a multi-dimensional traffic control strategy.
4. The message processing method according to claim 1, characterized in that, The traffic control strategy includes: a pre-embedded whitelist strategy and a blacklist strategy. The method for processing the message to be transmitted based on the detection results includes: The response determines, based on the detection results, that the message to be transmitted is compatible with the whitelist policy, and then transmits the message; or... The response determines, based on the detection results, that the message to be delivered is compatible with the blacklist policy and intercepts the message to be delivered.
5. The message processing method according to claim 1, characterized in that, The flow control strategy includes: a multi-dimensional flow regulation strategy, wherein determining the processing method of the message to be transmitted based on the detection results includes: Based on the detection results, the response determines that the message to be transmitted triggers the rate limiting rule and adapts to the multi-dimensional traffic control strategy, and determines whether the cloud computer dimension token and the message type dimension token are obtained respectively. In response to obtaining the cloud computer dimension token and the message type dimension token respectively, the message to be transmitted is transmitted.
6. The message processing method according to claim 5, characterized in that, The method further includes: In response to the failure to obtain the cloud computer dimension token, the message to be transmitted is intercepted; or, In response to having obtained the cloud computer dimension token but not the message type dimension token, the message to be delivered is intercepted.
7. The message processing method according to claim 1, characterized in that, The processing method for the message to be transmitted, determined based on the detection results, includes: The response determines, based on the detection result, that the message to be transmitted has not triggered the rate limiting rule, and then transmits the message to be transmitted.
8. The message processing method according to claim 1, characterized in that, The message processing method further includes: Receive alarm notifications reported by the log service, wherein the alarm notification is triggered when traffic anomalies are determined to have occurred based on traffic log records, and the traffic log records are used to record the current traffic status of the gateway service; In response to the alarm notification, the maximum number of tokens that the token bucket can hold is recalculated, and the calculation result is obtained; The token bucket is reset based on the calculation results.
9. The message processing method according to claim 8, characterized in that, The traffic log records include: a first traffic statistics data point and a second traffic statistics data point, wherein the first traffic statistics data point is used to count the number of concurrent request messages processed by the gateway service within a unit of time, and the second traffic statistics data point is used to count the time taken for the gateway service to process downlink messages transmitted from the cloud computer management service to the cloud computer image and uplink messages transmitted from the cloud computer image to the cloud computer management service.
10. The message processing method according to claim 9, characterized in that, The traffic anomaly is determined based on the first traffic statistics exceeding a first preset threshold and / or the second traffic statistics exceeding a second preset threshold.
11. The message processing method according to any one of claims 1-10, characterized in that, The message processing method further includes: Receive configuration notifications pushed by the configuration center, wherein the configuration notifications are used to update the traffic control configuration information of the gateway service; The token bucket of the gateway service is reset based on the configuration notification.
12. The message processing method according to any one of claims 1-10, characterized in that, The message processing method further includes: Verify that the flow control function in the gateway service is active. In response to the flow control function being in the activated state, it is determined that flow control detection will be performed on the message to be transmitted.
13. A message processing system, characterized in that, include: Cloud PC management and control services, cloud PC image and gateway services; The cloud computer management service is used to interact with the cloud computer image via the gateway service. The gateway service is used to obtain the message to be transmitted between the cloud computer management service and the cloud computer image, perform traffic control detection on the message to be transmitted to obtain the detection result, and determine the processing method of the message to be transmitted based on the detection result, wherein the detection result is used to determine the traffic control strategy adapted to the message to be transmitted.
14. The message processing system according to claim 13, characterized in that, The message processing system also includes: a log service; The log service is used to report alarm notifications, wherein the alarm notification is triggered when traffic anomalies are determined based on traffic log records, and the traffic log records are used to record the current traffic status of the gateway service; The gateway service is also configured to, in response to the alarm notification, recalculate the upper limit of the number of tokens that the token bucket can hold to obtain a calculation result, and reset the token bucket based on the calculation result.
15. The message processing system according to claim 13, characterized in that, The message processing system also includes: a configuration center; The configuration center is used to push configuration notifications, wherein the configuration notifications are used to update the traffic control configuration information of the gateway service; The gateway service is also used to reset the token bucket of the gateway service based on the configuration notification.
16. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the message processing method according to any one of claims 1 to 12.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein, when the executable program is executed, it controls the device on which the computer-readable storage medium is located to perform the message processing method according to any one of claims 1 to 12.
18. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the message processing method according to any one of claims 1 to 12.