A network connection processing method and device, electronic equipment and medium

CN122554495APending Publication Date: 2026-08-11GREE ELECTRIC APPLIANCE INC OF ZHUHAI +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-15
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

然而,静态阈值限流在恢复期容易出现放量过快导致再次过载;通用扩缩容存在冷启动和调度时延,难以在秒级风暴窗口稳定控制连接洪峰

Benefits of technology

[0017] In this embodiment, the network platform acquires indicator data associated with network connections over multiple consecutive acquisition cycles; the platform pressure value of the network platform is determined based on the indicator data for each acquisition cycle; the network connection mode of the network platform is adjusted based on the platform pressure value; when the network connection mode is a first mode for capacity recovery, the target recovery budget of the network platform in the next moment under the first mode is determined based on the platform pressure value; the security access limit for network connections in the network platform is determined based on the target recovery budget; and network connection control of the network platform is performed according to the security access limit. Through this embodiment, recovery capability can be explicitly modeled as a "recovery budget" state quantity, no longer relying on empirical thresholds for capacity expansion, reducing secondary impact peaks and connection rejection fluctuations, and shortening the recovery time to steady state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554495A_ABST
    Figure CN122554495A_ABST
Patent Text Reader

Abstract

This application discloses a method, apparatus, electronic device, and medium for processing network connections. The method includes: acquiring indicator data associated with network connections within multiple consecutive acquisition cycles in a network platform; determining the platform pressure value of the network platform within each acquisition cycle based on the indicator data; adjusting the network connection mode of the network platform based on the platform pressure value; when the network connection mode is a first mode for capacity recovery, determining the target recovery budget of the network platform in the next moment under the first mode based on the platform pressure value; determining the security access limit of network connections in the network platform based on the target recovery budget; and controlling the network connection of the network platform according to the security access limit. Through the embodiments of this application, recovery capability is explicitly modeled as a "recovery budget" state quantity, no longer relying on empirical thresholds for capacity recovery, reducing secondary impact peaks and connection rejection fluctuations, and shortening the recovery time to steady state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network connectivity technology, and specifically relates to a network connectivity processing method, apparatus, electronic device, and medium. Background Technology

[0002] In the field of IoT messaging communication and platform governance technology, the main methods for managing MQTTBroker connection storms in IoT scenarios with ultra-high connection volumes are static threshold rate limiting and general scaling up / down. However, static threshold rate limiting is prone to overload again during the recovery period due to excessively rapid capacity expansion; general scaling up / down suffers from cold start and scheduling latency, making it difficult to stably control connection surges within a second-level storm window. Summary of the Invention

[0003] The purpose of this application is to provide a network connection processing method, apparatus, electronic device, and medium that can solve the problems existing in current Internet of Things (IoT) network connections.

[0004] To solve the above-mentioned technical problems, this application is implemented as follows: In a first aspect, embodiments of this application provide a method for processing network connections, the method comprising: Within the network platform, acquire indicator data associated with network connectivity over multiple consecutive collection periods; The platform pressure value of the network platform within each collection cycle is determined based on the aforementioned indicator data; Adjust the network connection mode of the network platform based on the platform pressure value; When the network connection mode is the first mode for scaling up recovery, the target recovery budget of the network platform in the next moment is determined based on the platform pressure value, and the target recovery budget is the predicted pressure recovery value of the network platform. Determine the security access limit for network connections in the network platform based on the target recovery budget; Network connection control of the network platform shall be performed in accordance with the aforementioned security access limit.

[0005] Optionally, adjusting the network connection mode of the network platform based on the platform pressure value includes: If the platform pressure value is less than the second pressure threshold within M consecutive collection cycles, the network connection mode of the network will be adjusted to the first mode for volume recovery, where M is a positive integer greater than 1. If the platform pressure value is greater than the first pressure threshold within N consecutive collection cycles, the network connection mode of the network will be adjusted to the second mode, where N is a positive integer greater than 1. The second mode is a network connection mode used to ensure that the network platform is not overloaded and to maintain the availability of critical connections. The first pressure threshold is greater than the second pressure threshold.

[0006] Optionally, when the network connection mode is a first mode for scaling up recovery, determining the target recovery budget of the network platform in the next moment under the first mode based on the platform stress value includes: In the first mode, the current increase in network traffic is determined based on the platform pressure value; Obtain the current recovery budget and budget limit of the network platform; The target recovery budget for the network platform at the next moment is determined based on the current increase in throughput, the budget ceiling, and the current recovery budget.

[0007] Optionally, in the first mode, determining the current capacity increase of the network platform based on the platform pressure value includes: In the first mode, the volume increase at the previous moment is obtained; Calculate the first pressure difference between the first pressure threshold and the current pressure value based on the platform pressure value, and calculate the second pressure difference between the current pressure value and the previous pressure value. The current volume increase of the network platform is determined based on the volume increase of the previous moment, the first pressure difference, and the second pressure difference.

[0008] Optionally, determining the security access limit for network connections in the network platform based on the target recovery budget includes: Obtain the capacity change data of the network platform within a preset time period; The average capacity and capacity fluctuation value of the network platform are determined based on the capacity change data. The security access limit for network connections in the network platform is determined based on the average capacity, the capacity fluctuation value, and the target recovery budget.

[0009] Optionally, determining the platform pressure value of the network platform within each collection cycle based on the indicator data includes: Obtain the weight value corresponding to each indicator data; The platform pressure value of the network platform is determined based on the indicator data and the corresponding weight values ​​for each collection period.

[0010] Optionally, determining the platform pressure value of the network platform within each collection period based on the indicator data and corresponding weight values ​​includes: The normalized values ​​of each indicator are obtained by normalizing the indicator data based on the indicator data from multiple collection periods. Within each collection period, the normalized value of each indicator is weighted and summed with its corresponding weight value to obtain the platform pressure value of the network platform within the collection period.

[0011] Optionally, controlling the network connection of the network platform according to the security access limit includes: Obtain the group risk value for each device group or tenant group in the network platform; The group access quota for each device group or tenant group is determined based on the group risk value and the security access limit. Network connection control of the network platform is performed according to the group access quota.

[0012] Optionally, it also includes: In the second mode, connection tokens and handshake queue limits are configured according to the device groups or tenant groups in the network platform, and handshake throttling is performed for device groups or tenant groups with high risks, and preset degradation policies are implemented for existing sessions.

[0013] Secondly, embodiments of this application provide a network connectivity processing apparatus, the apparatus comprising: The indicator data acquisition module is used to acquire indicator data associated with the network connection within multiple consecutive collection periods on the network platform. The platform pressure value determination module is used to determine the platform pressure value of the network platform in each collection cycle based on the indicator data. A network connection mode determination module is used to adjust the network connection mode of the network platform based on the platform pressure value. The target recovery budget determination module is used to determine the target recovery budget of the network platform in the next moment under the first mode of the first mode for scaling up recovery, based on the platform pressure value, when the network connection mode is the first mode for scaling up recovery. The target recovery budget is the pressure recovery value predicted by the network platform. The security access limit determination module is used to determine the security access limit of network connections in the network platform based on the target recovery budget. The network connection control module is used to control the network connection of the network platform in accordance with the security access limit.

[0014] Thirdly, embodiments of this application provide an electronic device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the method described in the first aspect.

[0015] Fourthly, embodiments of this application provide a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect.

[0016] Fifthly, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the method as described in the first aspect.

[0017] In this embodiment, the network platform acquires indicator data associated with network connections over multiple consecutive acquisition cycles; the platform pressure value of the network platform is determined based on the indicator data for each acquisition cycle; the network connection mode of the network platform is adjusted based on the platform pressure value; when the network connection mode is a first mode for capacity recovery, the target recovery budget of the network platform in the next moment under the first mode is determined based on the platform pressure value; the security access limit for network connections in the network platform is determined based on the target recovery budget; and network connection control of the network platform is performed according to the security access limit. Through this embodiment, recovery capability can be explicitly modeled as a "recovery budget" state quantity, no longer relying on empirical thresholds for capacity expansion, reducing secondary impact peaks and connection rejection fluctuations, and shortening the recovery time to steady state. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the steps of a network connection processing method according to an embodiment of this application; Figure 2 This is a flowchart illustrating the steps of another network connection processing method in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of a network connection processing device according to an embodiment of this application; Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0020] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0021] The processing of network connections provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings, through specific implementation methods and application scenarios.

[0022] like Figure 1 The diagram shown is a flowchart illustrating the steps of a network connection processing method according to an embodiment of this application, which may specifically include the following steps: Step S101: In the network platform, acquire indicator data associated with the network connection within multiple consecutive collection periods; In practical applications, the network platform can be an IoT network platform, specifically an IoT network platform built from multiple home devices. This network platform may experience MQTTBroker connection storms in IoT scenarios with extremely high connection volumes. To manage these connection storms, it's possible to acquire network connection-related metrics data over multiple consecutive collection periods. The collection period can be set according to the actual scenario, and the network connection-related metrics data can specifically include any one or more of the following: CPU utilization, authentication queue length, authentication latency 95th percentile, reconnection count per second, and packet loss rate.

[0023] CPU utilization refers to the proportion of time the CPU is used to handle non-idle tasks (such as running the operating system, applications, interrupts, etc.) within a certain time interval; authentication queue length refers to the number of authentication requests waiting to be processed in the request queue of authentication services (such as username / password verification, TLS handshake, JWT verification); authentication latency 95th percentile is the time value at the 95th percentile when all authentication request processing times are sorted from smallest to largest within a certain period (e.g., the last 5 minutes). That is, 95% of authentication requests are completed within this time period; reconnection per second is the number of times per second the client actively or passively initiates the re-establishment of the MQTT connection due to network jitter, heartbeat timeout, broker restart, etc.; packet loss rate is the proportion of data packets lost during network transmission out of the total number of packets sent. In the MQTT scenario, it usually refers to the proportion of MQTT protocol packets (such as PUBLISH, CONNECT, etc.) that are dropped or fail to reach the other end at the TCP / IP layer.

[0024] This implementation can be applied to a high-connectivity IoT MQTT Broker platform, which can consist of an access layer, a Broker core layer, a state storage layer, and a governance and control layer. The access layer is responsible for connection establishment, authentication, and initial session allocation; the core layer is responsible for subscription matching and message routing; the state storage layer saves snapshots of sessions and control parameters; and the governance and control layer implements the MBRC control law. The governance and control layer includes an indicator collector, a stress estimator, a capacity estimator, a risk grouper, and a policy executor, forming a closed-loop control chain.

[0025] Step S102: Determine the platform pressure value of the network platform in each collection cycle based on the index data; After acquiring the indicator data, the platform pressure value for each collection period can be calculated based on the indicator data. The platform pressure value is used to quantitatively reflect the current network connection pressure status of the platform.

[0026] In one embodiment of this application, determining the platform pressure value of the network platform in each collection period based on the indicator data includes: obtaining the weight value corresponding to each indicator data; and determining the platform pressure value of the network platform in each collection period based on the indicator data and the corresponding weight value.

[0027] Different types of indicator data exert varying degrees of pressure on the network platform, thus allowing for the setting of different weight values. By combining each indicator data point with its weight value for weighted calculation, the platform pressure value for the network platform within the data collection period can be obtained.

[0028] In one embodiment of this application, determining the platform pressure value of the network platform in each collection period based on the indicator data and the corresponding weight value includes: normalizing each indicator data based on the indicator data in multiple collection periods to obtain a normalized indicator value; and in each collection period, weighting each normalized indicator value with the corresponding weight value and then adding them together to obtain the platform pressure value of the network platform in the collection period.

[0029] In practical applications, to avoid excessive differences in calculated values, the indicator data can be normalized. After normalization, the normalized indicator data can be weighted and summed using weight values ​​to obtain the platform pressure value within the application period.

[0030] The normalized value of the indicator is calculated as: truncation((current indicator value - moving median) / (moving median deviation + smoothing term), -3,3). The normalized value indicates how many robust scales a given indicator has deviated from its historical norm. The moving median is the median of the indicator data within the sampling period, and the moving median deviation represents the typical distance of each value within the window from the median; it is a robust estimate of dispersion (equivalent to replacing the standard deviation of the mean with the median).

[0031] The platform stress value is calculated as Σ(weight value k × indicator normalization value k), where Σ(weight value k) = 1. Essentially, the platform stress value is a comprehensive score reflecting the overall overload level after weighting and summing all stress indicators.

[0032] Step S103: Adjust the network connection mode of the network platform based on the platform pressure value; In this embodiment of the application, the network platform can be configured with a variety of different network connection modes to cope with different network scenarios. After determining the platform pressure value of the network platform, different network connection modes can be selected according to the platform pressure value.

[0033] In one embodiment of this application, adjusting the network connection mode of the network platform based on the platform pressure value includes: if the platform pressure value is less than a second pressure threshold within M consecutive acquisition cycles, then the network connection mode of the network is adjusted to a first mode for capacity recovery, where M is a positive integer greater than 1; if the platform pressure value is greater than the first pressure threshold within N consecutive acquisition cycles, then the network connection mode of the network is adjusted to a second mode, where N is a positive integer greater than 1, and the second mode is a network connection mode used to ensure that the network platform is not overloaded and to maintain the availability of critical connections.

[0034] In practical applications, the network platform can adopt a dual-threshold hysteresis state machine: when the platform pressure value is higher than the high pressure threshold for H consecutive windows, it enters storm mode; when the platform pressure value is lower than the low pressure threshold for K consecutive windows, it enters recovery mode, and the low pressure threshold (i.e., the second pressure threshold) is less than the high pressure threshold (i.e., the first pressure threshold) to avoid repeated switching of edge states.

[0035] The first mode can be recovery mode, and the second mode can be storm mode. Storm mode is characterized by a sharp increase in reconnection rate, longer authentication queue, increased CPU usage, and increased packet loss, accompanied by both short-term bursts and continuous congestion. Recovery mode is characterized by "monotonous, gradual, and constrained load increases; when the load is below the platform pressure value for K consecutive windows, it switches from storm mode to recovery mode."

[0036] In one embodiment of this application, a ramp-up recovery can be performed in the first mode, while in the second mode, connection tokens and handshake queue limits are configured according to the device groups or tenant groups in the network platform, handshake throttling is performed for device groups or tenant groups with high risks, and a preset degradation strategy is executed on existing sessions.

[0037] In storm mode, tiered admission and handshake throttling are implemented first, followed by degradation strategies for existing sessions. Tiered admission configures connection tokens and handshake queue limits by device group or tenant group, prioritizing tightening for high-risk groups. Session degradation strategies include limiting the resend rate of low-priority offline messages, reducing the concurrent delivery limit for non-critical topics, and imposing minimum reconnection intervals on high-failure-rate connections. The goal of this phase is to ensure the system is not overloaded and to maintain the availability of critical connections. The degradation strategy process involves first limiting new access, then protecting core sessions, then reducing priority traffic, and finally lengthening the reconnection interval for high-failure connections.

[0038] Step S104: When the network connection mode is the first mode for scaling up recovery, determine the target recovery budget of the network platform in the next moment under the first mode based on the platform pressure value. When the network platform's actual network connection mode is in the first mode, the target recovery budget for the next moment can be determined based on the calculated platform pressure value. The target recovery budget is the predicted pressure recovery value (or pressure release value) of the network platform. Specifically, the numerical relationship between the platform pressure value and the target recovery budget can be predetermined. Then, based on the platform pressure value and the data relationship, the target recovery budget for the next moment can be calculated. That is, given the current platform pressure value, the pressure value that the network platform can recover or release in the next moment can be predicted based on the current platform pressure value. The recovered or released pressure value can alleviate the pressure on the network platform to a certain extent.

[0039] In one embodiment of this application, when the network connection mode is a first mode for scaling up recovery, determining the target recovery budget of the network platform in the next moment under the first mode based on the platform pressure value includes: in the first mode, determining the current scaling up increment of the network platform based on the platform pressure value; obtaining the current recovery budget and budget limit of the network platform; and determining the target recovery budget of the network platform in the next moment based on the current scaling up increment, the budget limit, and the current recovery budget.

[0040] In one embodiment of this application, determining the current capacity increase of the network platform based on the platform pressure value in the first mode includes: In the first mode, the volume increase at the previous moment is obtained; Calculate the first pressure difference between the first pressure threshold and the current pressure value based on the platform pressure value, and calculate the second pressure difference between the current pressure value and the previous pressure value. The current volume increase of the network platform is determined based on the volume increase of the previous moment, the first pressure difference, and the second pressure difference.

[0041] In practical applications, under the second mode, "restore budget" can be used for volume control. The next time step restore budget = min(budget upper limit, current restore budget + current volume increment).

[0042] At the same time, the following preset constraints must be met: 0 <= current volume increment <= volume limit, and |current volume increment - previous volume increment| <= change limit.

[0043] The feedback update method for volume increment is: Current volume increment = Cut-off (Previous volume increment + Proportional coefficient × (Low pressure threshold - Current pressure value) - Differential coefficient × (Current pressure value - Previous pressure value), 0, Volume cap). The above constraints limit both the volume rate and volume acceleration, which can suppress overshoot during the recovery period.

[0044] Step S105: Determine the security access limit for network connections in the network platform based on the target recovery budget; After obtaining the target recovery budget, the security access limit can be calculated based on the preset functional relationship between the target recovery budget and the security access limit.

[0045] In one embodiment of this application, determining the security access limit for network connections in the network platform based on the target recovery budget includes: acquiring capacity change data of the network platform within a preset time period; determining the average capacity and capacity fluctuation value of the network platform based on the capacity change data; and determining the security access limit for network connections in the network platform based on the average capacity, the capacity fluctuation value, and the target recovery budget.

[0046] In this embodiment, the capacity estimator calculates the mean capacity estimate and the capacity fluctuation estimate based on the online throughput samples: mean capacity estimate = (1 - smoothing coefficient 1) × mean capacity estimate of the previous time step + smoothing coefficient 1 × current throughput sample; capacity fluctuation estimate = sqrt((1 - smoothing coefficient 2) × capacity fluctuation estimate of the previous time step^2 + smoothing coefficient 2 × (current throughput sample - mean capacity estimate)^2).

[0047] The safety access cap is calculated as follows: Safety access cap = max(0, min(current recovery budget, average capacity estimate - safety factor × capacity fluctuation estimate, access cap)).

[0048] Among them, the security access limit is the new connection limit that the current network platform can safely accept. The security access limit can be used to set a master gate for global access and quotas for each group.

[0049] Step S106: Control the network connection of the network platform according to the security access limit.

[0050] Once the security access limit is obtained, network connection control can be performed based on the security access limit.

[0051] In one embodiment of this application, the step of controlling the network connection of the network platform according to the security access limit includes: obtaining the group risk value of each device group or tenant group in the network platform; The group access quota for each device group or tenant group is determined based on the group risk value and the security access limit; network connection control of the network platform is performed according to the group access quota.

[0052] In this embodiment, the network platform acquires indicator data associated with network connections over multiple consecutive acquisition cycles; the platform pressure value of the network platform is determined based on the indicator data for each acquisition cycle; the network connection mode of the network platform is adjusted based on the platform pressure value; when the network connection mode is a first mode for capacity recovery, the target recovery budget of the network platform in the next moment under the first mode is determined based on the platform pressure value; the security access limit for network connections in the network platform is determined based on the target recovery budget; and network connection control of the network platform is performed according to the security access limit. Through this embodiment, recovery capability can be explicitly modeled as a "recovery budget" state quantity, no longer relying on empirical thresholds for capacity expansion, reducing secondary impact peaks and connection rejection fluctuations, and shortening the recovery time to steady state.

[0053] like Figure 2 The diagram shown is a flowchart illustrating another network connection processing method according to an embodiment of this application, which may specifically include the following steps: Step S201: In the network platform, acquire indicator data associated with the network connection within multiple consecutive collection periods; In practical applications, the network platform can be an IoT network platform, specifically an IoT network platform built from multiple home devices. This network platform may experience MQTTBroker connection storms in IoT scenarios with extremely high connection volumes. To manage these connection storms, it's possible to acquire network connection-related metrics data over multiple consecutive collection periods. The collection period can be set according to the actual scenario, and the network connection-related metrics data can specifically include any one or more of the following: CPU utilization, authentication queue length, authentication latency 95th percentile, reconnection count per second, and packet loss rate.

[0054] CPU utilization refers to the proportion of time the CPU is used to handle non-idle tasks (such as running the operating system, applications, interrupts, etc.) within a certain time interval; authentication queue length refers to the number of authentication requests waiting to be processed in the request queue of authentication services (such as username / password verification, TLS handshake, JWT verification); authentication latency 95th percentile is the time value at the 95th percentile when all authentication request processing times are sorted from smallest to largest within a certain period (e.g., the last 5 minutes). That is, 95% of authentication requests are completed within this time period; reconnection per second is the number of times per second the client actively or passively initiates the re-establishment of the MQTT connection due to network jitter, heartbeat timeout, broker restart, etc.; packet loss rate is the proportion of data packets lost during network transmission out of the total number of packets sent. In the MQTT scenario, it usually refers to the proportion of MQTT protocol packets (such as PUBLISH, CONNECT, etc.) that are dropped or fail to reach the other end at the TCP / IP layer.

[0055] This implementation can be applied to a high-connectivity IoT MQTT Broker platform, which can consist of an access layer, a Broker core layer, a state storage layer, and a governance and control layer. The access layer is responsible for connection establishment, authentication, and initial session allocation; the core layer is responsible for subscription matching and message routing; the state storage layer saves snapshots of sessions and control parameters; and the governance and control layer implements the MBRC control law. The governance and control layer includes an indicator collector, a stress estimator, a capacity estimator, a risk grouper, and a policy executor, forming a closed-loop control chain.

[0056] Step S202: Determine the platform pressure value of the network platform in each collection cycle based on the index data; After acquiring the indicator data, the platform pressure value for each collection period can be calculated based on the indicator data. The platform pressure value is used to quantitatively reflect the current network connection pressure status of the platform.

[0057] Step S203: Adjust the network connection mode of the network platform based on the platform pressure value; In this embodiment of the application, the network platform can be configured with a variety of different network connection modes to cope with different network scenarios. After determining the platform pressure value of the network platform, different network connection modes can be selected according to the platform pressure value.

[0058] Step S204: When the network connection mode is the first mode for performing volume recovery, determine the target recovery budget of the network platform in the next moment under the first mode based on the platform pressure value. When the actual network connection mode of the network platform is the first mode, the target recovery budget for the next moment can be determined based on the calculated platform pressure value.

[0059] Step S205: Determine the security access limit for network connections in the network platform based on the target recovery budget; After obtaining the target recovery budget, the security access limit can be calculated based on the preset functional relationship between the target recovery budget and the security access limit. The security access limit is the maximum number of new connections that the current network platform can securely accept; it can be used to set a general gate for global access and individual packet quotas.

[0060] Step S206: Obtain the group risk value for each device group or tenant group in the network platform; In this embodiment, the group risk value = coefficient 1 × reconnection burst rate + coefficient 2 × authentication failure rate + coefficient 3 × connection entropy value. Coefficients 1, 2, and 3 can be set according to the actual scenario, and the reconnection burst rate, authentication failure rate, and connection entropy value can be obtained from data on the actual network platform.

[0061] Step S207: Determine the group access quota for each device group or tenant group based on the group risk value and the security access limit; Among them, the group access quota means that the total access volume is allocated to each device group or tenant group according to the risk score, so as to avoid high-risk traffic crowding out global resources.

[0062] Step S208: Perform network connection control of the network platform according to the group access quota.

[0063] In one embodiment of this application, the controller employs a primary and backup dual-instance deployment during cluster deployment. Each node reports metrics and receives quotas every second. If the controller experiences a short-term disconnection, the nodes automatically switch to a conservative threshold to ensure security. Stress test results show that this implementation can reduce access fluctuations and secondary impact peaks during the recovery period and shorten the recovery time to steady state in scenarios with millions of concurrent reconnections.

[0064] Million-level concurrent reconnection scenarios refer to a large number of terminals initiating reconnection within tens of seconds to several minutes due to network jitter, data center switching, broker restart, certificate refresh, or intermittent outages by the operator. Its characteristics include: a high instantaneous surge in connection requests, authentication links being saturated first, the overlap of session recovery and offline message resending, significant differences in behavior among different tenants and device types, and the susceptibility to "secondary impacts" during the recovery period.

[0065] For example, a platform has 3 million online devices, of which 1.2 million reconnect within 90 seconds due to edge network jitter. Normally, there are about 3,000 connections per second, but during anomalies, the peak reaches 80,000 connections per second; the 95th percentile latency of the authentication service increases from 40ms to 1.8s, and Broker CPU usage rises from 45% to 92%. The offline message resending flow and the reconnection flow overlap. If access is directly opened up, the authentication queue will be filled up again during the recovery phase, triggering a second round of congestion.

[0066] In this embodiment, the network platform acquires indicator data associated with network connections over multiple consecutive acquisition periods; determines the platform pressure value of the network platform in each acquisition period based on the indicator data; adjusts the network connection mode of the network platform based on the platform pressure value; when the network connection mode is the first mode for capacity recovery, determines the target recovery budget of the network platform in the next moment under the first mode based on the platform pressure value; determines the security access limit for network connections in the network platform based on the target recovery budget; acquires the capacity change data of the network platform within a preset time period; determines the average capacity and capacity fluctuation value of the network platform based on the capacity change data; and determines the security access limit for network connections in the network platform based on the average capacity, the capacity fluctuation value, and the target recovery budget. Access allocation can be performed according to group risk values ​​under a global access limit, achieving both global stability and local isolation, prioritizing connections to critical devices. This can reduce resource crowding by high-risk connection groups, improve critical connection retention rates, and enhance multi-tenant fairness.

[0067] It should be noted that the network connection processing method provided in this application embodiment can be executed by a network connection processing device, or a control module within the network connection processing device for executing the method of loading a network connection. This application embodiment uses the execution of the method of loading a network connection by a network connection processing device as an example to illustrate the network connection processing method provided in this application embodiment.

[0068] like Figure 3 The diagram shown is a structural schematic of a network connection processing device according to an embodiment of this application, which may specifically include the following structure: The indicator data acquisition module 301 is used to acquire indicator data associated with the network connection within multiple consecutive collection periods on the network platform. Platform pressure value determination module 302 is used to determine the platform pressure value of the network platform in each collection cycle based on the index data; The network connection mode determination module 303 is used to adjust the network connection mode of the network platform based on the platform pressure value. The target recovery budget determination module 304 is used to determine the target recovery budget of the network platform in the next moment under the first mode of the first mode for performing capacity recovery, based on the platform pressure value, when the network connection mode is the first mode for performing capacity recovery. The target recovery budget is the pressure recovery value predicted by the network platform. The security access limit determination module 305 is used to determine the security access limit of network connections in the network platform based on the target recovery budget. The network connection control module 306 is used to control the network connection of the network platform in accordance with the security access limit.

[0069] In one embodiment of this application, the network connection mode determination module 303 may include: The first mode submodule is used to adjust the network connection mode of the network to the first mode for capacity recovery if the platform pressure value is less than the second pressure threshold within M consecutive collection cycles, where M is a positive integer greater than 1. The second mode submodule is used to adjust the network connection mode of the network to the second mode if the platform pressure value is greater than the first pressure threshold within N consecutive collection cycles, where N is a positive integer greater than 1. The second mode is a network connection mode used to ensure that the network platform is not overloaded and to maintain the availability of critical connections, and the first pressure threshold is greater than the second pressure threshold.

[0070] In one embodiment of this application, the target recovery budget determination module 304 may include: The current volume increase submodule is used to determine the current volume increase of the network platform based on the platform pressure value in the first mode. The budget data acquisition submodule is used to obtain the current recovery budget and budget limit of the network platform; The target recovery budget submodule is used to determine the target recovery budget of the network platform in the next moment based on the current increase in throughput, the budget limit, and the current recovery budget.

[0071] In one embodiment of this application, the current volume increase submodule may include: The previous time increment unit is used to obtain the previous time increment in the first mode; The pressure difference calculation unit is used to calculate a first pressure difference between a first pressure threshold and the current pressure value based on the platform pressure value, and to calculate a second pressure difference between the current pressure value and the previous pressure value. The current volume increment determination unit is used to determine the current volume increment of the network platform based on the volume increment of the previous moment, the first pressure difference, and the second pressure difference.

[0072] In one embodiment of this application, the security access limit determination module 305 may include: The capacity change data acquisition submodule is used to acquire the capacity change data of the network platform within a preset time period; The capacity parameter determination submodule is used to determine the average capacity and capacity fluctuation value of the network platform based on the capacity change data. The security access limit determination submodule is used to determine the security access limit of network connections in the network platform based on the average capacity, the capacity fluctuation value, and the target recovery budget.

[0073] In one embodiment of this application, the platform pressure value determination module 302 may include: The weight value acquisition submodule is used to obtain the weight value corresponding to each indicator data. The platform pressure value submodule is used to determine the platform pressure value of the network platform in each collection period based on the indicator data and the corresponding weight value.

[0074] In one embodiment of this application, the platform pressure value submodule may include: The normalization processing unit is used to normalize each indicator data based on indicator data from multiple collection periods to obtain the normalized indicator value. The platform pressure value unit is used to add the normalized value of each indicator to its corresponding weight value in each collection period, and then obtain the platform pressure value of the network platform in the collection period.

[0075] In one embodiment of this application, the network connection control module 306 may include: The group risk value acquisition submodule is used to acquire the group risk value of each device group or tenant group in the network platform. The group access quota determination submodule is used to determine the group access quota for each device group or tenant group based on the group risk value and the security access limit. The network connection control submodule is used to control the network connection of the network platform according to the group access quota.

[0076] In one embodiment of this application, the apparatus further includes: The second mode control module is used to configure connection tokens and handshake queue limits according to the device groups or tenant groups in the network platform in the second mode, perform handshake throttling for high-risk device groups or tenant groups, and execute preset degradation strategies for existing sessions.

[0077] In this embodiment, the network platform acquires indicator data associated with network connections over multiple consecutive acquisition cycles; the platform pressure value of the network platform is determined based on the indicator data for each acquisition cycle; the network connection mode of the network platform is adjusted based on the platform pressure value; when the network connection mode is a first mode for capacity recovery, the target recovery budget of the network platform in the next moment under the first mode is determined based on the platform pressure value; the security access limit for network connections in the network platform is determined based on the target recovery budget; and network connection control of the network platform is performed according to the security access limit. Through this embodiment, recovery capability can be explicitly modeled as a "recovery budget" state quantity, no longer relying on empirical thresholds for capacity expansion, reducing secondary impact peaks and connection rejection fluctuations, and shortening the recovery time to steady state.

[0078] The network connection processing device in this application embodiment can be a device, or a component, integrated circuit, or chip in a terminal. The device can be a mobile electronic device or a non-mobile electronic device. For example, mobile electronic devices can be mobile phones, tablets, laptops, PDAs, in-vehicle electronic devices, wearable devices, ultra-mobile personal computers (UMPCs), netbooks, or personal digital assistants (PDAs), etc., while non-mobile electronic devices can be servers, network attached storage (NAS), personal computers (PCs), televisions (TVs), ATMs, or self-service machines, etc. This application embodiment does not impose specific limitations.

[0079] The network connection processing device in this application embodiment can be a device with an operating system. The operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit the specific operating system.

[0080] The network connection processing device provided in this application embodiment can achieve... Figures 1 to 2 The various processes implemented by the network connection processing device in the method embodiment will not be described again here to avoid repetition.

[0081] Optionally, this application embodiment also provides an electronic device, including a processor 1010, a memory 1009, and a program or instructions stored in the memory 1009 and executable on the processor 1010. When the program or instructions are executed by the processor 1010, they implement the various processes of the above-described network connection processing method embodiment and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0082] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.

[0083] Figure 4 A schematic diagram of the hardware structure of an electronic device to implement an embodiment of this application.

[0084] The electronic device 1000 includes, but is not limited to, components such as: radio frequency unit 1001, network module 1002, audio output unit 1003, input unit 1004, sensor 1005, display unit 1006, user input unit 1007, interface unit 1008, memory 1009, and processor 1010.

[0085] The memory 1009 includes applications and an operating system; the user input unit 1007 may include a touch panel 10071 and other input devices 10072; the input unit 1004 may include an image processor 10041 and a microphone 10042; and the display unit 1006 may include a display panel 10061.

[0086] Those skilled in the art will understand that the electronic device 1000 may also include a power supply (such as a battery) for supplying power to various components. The power supply may be logically connected to the processor 1010 through a power management system, thereby enabling functions such as managing charging, discharging, and power consumption through the power management system. Figure 4 The electronic device structure shown does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0087] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described network connection processing method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.

[0088] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0089] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described network connection processing method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0090] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0091] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0092] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0093] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. A processing method of network connection, characterized by, The method includes: Within the network platform, acquire indicator data associated with network connectivity over multiple consecutive collection periods; The platform pressure value of the network platform within each collection cycle is determined based on the aforementioned indicator data; Adjust the network connection mode of the network platform based on the platform pressure value; When the network connection mode is the first mode for scaling up recovery, the target recovery budget of the network platform in the next moment is determined based on the platform pressure value, and the target recovery budget is the predicted pressure recovery value of the network platform. Determine the security access limit for network connections in the network platform based on the target recovery budget; Network connection control of the network platform shall be performed in accordance with the aforementioned security access limit.

2. The method of claim 1, wherein, Adjusting the network connection mode of the network platform based on the platform pressure value includes: If the platform pressure value is less than the second pressure threshold within M consecutive collection cycles, the network connection mode of the network will be adjusted to the first mode for volume recovery, where M is a positive integer greater than 1. If the platform pressure value is greater than the first pressure threshold within N consecutive collection cycles, the network connection mode of the network will be adjusted to the second mode, where N is a positive integer greater than 1. The second mode is a network connection mode used to ensure that the network platform is not overloaded and to maintain the availability of critical connections. The first pressure threshold is greater than the second pressure threshold.

3. The method of claim 1, wherein, When the network connection mode is the first mode for capacity recovery, the target recovery budget of the network platform in the next moment under the first mode is determined based on the platform pressure value, including: In the first mode, the current increase in network traffic is determined based on the platform pressure value; Obtain the current recovery budget and budget limit of the network platform; The target recovery budget for the network platform at the next moment is determined based on the current increase in throughput, the budget ceiling, and the current recovery budget.

4. The method of claim 3, wherein, In the first mode, determining the current capacity increase of the network platform based on the platform pressure value includes: In the first mode, the volume increase at the previous moment is obtained; Calculate the first pressure difference between the first pressure threshold and the current pressure value based on the platform pressure value, and calculate the second pressure difference between the current pressure value and the previous pressure value. The current volume increase of the network platform is determined based on the volume increase of the previous moment, the first pressure difference, and the second pressure difference.

5. The method of claim 1, wherein, The step of determining the security access limit for network connections in the network platform based on the target recovery budget includes: Obtain the capacity change data of the network platform within a preset time period; The average capacity and capacity fluctuation value of the network platform are determined based on the capacity change data. The security access limit for network connections in the network platform is determined based on the average capacity, the capacity fluctuation value, and the target recovery budget.

6. The method of claim 1, wherein, The step of determining the platform pressure value of the network platform within each collection cycle based on the indicator data includes: Obtain the weight value corresponding to each indicator data; The platform pressure value of the network platform is determined based on the indicator data and the corresponding weight values ​​for each collection period.

7. The method according to claim 6, characterized in that, The step of determining the platform pressure value of the network platform in each collection period based on the indicator data and the corresponding weight value includes: The normalized values ​​of each indicator are obtained by normalizing the indicator data based on the indicator data from multiple collection periods. Within each collection period, the normalized value of each indicator is weighted and summed with its corresponding weight value to obtain the platform pressure value of the network platform within the collection period.

8. The method according to claim 1, characterized in that, The control of network connections on the network platform in accordance with the security access limit includes: Obtain the group risk value for each device group or tenant group in the network platform; The group access quota for each device group or tenant group is determined based on the group risk value and the security access limit. Network connection control of the network platform is performed according to the group access quota.

9. The method of claim 2, wherein, Also includes: In the second mode, connection tokens and handshake queue limits are configured according to the device groups or tenant groups in the network platform, and handshake throttling is performed for device groups or tenant groups with high risks, and preset degradation policies are implemented for existing sessions.

10. A network-connected processing device, comprising: The device includes: The indicator data acquisition module is used to acquire indicator data associated with the network connection within multiple consecutive collection periods on the network platform. The platform pressure value determination module is used to determine the platform pressure value of the network platform in each collection cycle based on the indicator data. A network connection mode determination module is used to adjust the network connection mode of the network platform based on the platform pressure value. The target recovery budget determination module is used to determine the target recovery budget of the network platform in the next moment under the first mode of the first mode for scaling up recovery, based on the platform pressure value, when the network connection mode is the first mode for scaling up recovery. The target recovery budget is the pressure recovery value predicted by the network platform. The security access limit determination module is used to determine the security access limit of network connections in the network platform based on the target recovery budget. The network connection control module is used to control the network connection of the network platform in accordance with the security access limit.

11. An electronic device, comprising: It includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the processing method for network connectivity as described in any one of claims 1 to 9.

12. A readable storage medium, characterized by, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the network connection processing method as described in any one of claims 1 to 9.