A communication processing method, apparatus, medium, and device
Patent Information
- Application Number
- CN202611104357.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-24
- Publication Date
- 2026-09-04
AI Technical Summary
[0005]有鉴于此,本发明提供了一种通信处理方法、装置、介质及设备,主要目的在于解决目前通信处理效率低的问题
[0016] The communication processing method, apparatus, medium, and equipment in this application create a virtual server and associate several services using the virtual server, thereby realizing the automatic orchestration and combination of services. Subsequently, the client can quickly and accurately match the target service adapted to the client, effectively improving the overall communication processing efficiency.
Smart Images

Figure CN122698519A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a communication processing method, apparatus, medium, and device. Background Technology
[0002] The Model Context Protocol (MCP) is an open protocol proposed by Anthropic, aiming to standardize the interaction between AI models and external data sources and tools. In the MCP protocol, the server exposes three core capabilities / services to the client (usually an AI Agent or LLM application): Tools, Resources, and Prompts.
[0003] The MCP protocol defines a standard communication mechanism that supports multiple transport protocols, enabling AI applications to discover and invoke various server capabilities / services in a unified manner.
[0004] However, in existing communication processing methods, clients access backend / server services through a unified access point / endpoint of the MCP gateway. During the client's access to backend services, the MCP gateway returns a list of all backend services / capabilities for the client to choose from. This increases the cognitive burden on the client, making it difficult for the client to quickly and accurately determine the appropriate backend service / capability when faced with a large number of backend services, thus resulting in low communication processing efficiency. Summary of the Invention
[0005] In view of this, the present invention provides a communication processing method, apparatus, medium and device, the main purpose of which is to solve the problem of low efficiency in current communication processing.
[0006] To address the above problems, this application provides a communication processing method, comprising: In response to a virtual server creation request, several virtual servers are pre-created, and several services are associated with each virtual server; Receive the initial access request sent by the client for the target virtual server to be accessed; Based on the initial access request, the target virtual server to be accessed is determined, and the associated services of the target virtual server are determined. A service list containing the associated services is then fed back to the client so that the target client can determine the target service to be accessed based on the service list. The system receives a target access request sent by a client, which contains a target service identifier. Based on the target access request, the system uses a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0007] Optionally, in response to a virtual server creation request, several virtual servers are pre-created, and several services are associated with each virtual server, specifically including: For each virtual server, a creation request is received; Based on the basic information in the creation request and the creation record table storing historical creation records, duplicate creation detection is performed to obtain the detection result; When the detection result meets the predetermined detection conditions, a virtual server is created based on the basic information, and the basic information is stored in the creation record table; Based on the service identifiers of several services to be associated in the creation request and the virtual server identifiers of the corresponding virtual servers, establish a mapping relationship between the virtual server identifiers and each service identifier. The mapping relationship is stored in a predetermined service orchestration mapping table to associate several services with the virtual server.
[0008] Optionally, after creating and obtaining the virtual server, the method further includes: Receive update requests for virtual servers; Based on the update information of the virtual server in the update request, update the basic information of the virtual server, and / or based on the update information of the associated services in the update request, update each service associated with the virtual server.
[0009] Optionally, the communication processing method further includes: pre-configuring visibility levels for each virtual server; Before receiving the initial access request sent by the client for the target virtual server to be accessed, the method further includes: Receive access permission requests sent by clients; Based on the application request, an access credential is issued to the client so that the client can carry the access credential when sending the initial access request.
[0010] Optionally, after receiving the initial access request sent by the client for the target virtual server to be accessed, the method further includes: Obtain the target visibility level of the target virtual server; Based on the target visibility level and the access credentials carried in the access request, the client is verified to meet the predetermined access conditions, so that when the access conditions are met, the associated services associated with the target virtual server are determined.
[0011] Optionally, the associated services include any one or more of the following: resource services corresponding to the MCP service type, tool services corresponding to the MCP service type, prompt word template services corresponding to the MCP service type, and API interface services corresponding to non-MCP service types.
[0012] Optionally, the step of routing the client through the target virtual server to the target server corresponding to the target service for the target access request, using a routing method corresponding to the target service, so that the client can communicate with the target server, specifically includes: When the service type of the target service is MCP service type, the target access request is forwarded to the target server corresponding to the target service through the target virtual server, so that the client can communicate with the target server; When the service type of the target service is a non-MCP service type, the target access request is converted into a protocol format to obtain the current target access request in a predetermined protocol format. The current target access request is then forwarded to the target server corresponding to the target service through the target virtual server, so that the client can communicate with the target server.
[0013] To address the above problems, this application provides a communication processing apparatus, comprising: A creation module is used to pre-create several virtual servers in response to a virtual server creation request, and associate several services with each virtual server; The receiving module is used to receive the initial access request sent by the client to the target virtual server to be accessed; The determination module is used to determine the target virtual server to be accessed based on the initial access request, determine the associated services associated with the target virtual server, and feed back a service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list. The communication processing module is used to receive a target access request sent by a client, which contains a target service identifier, and, for the target access request, to use a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0014] To address the aforementioned problems, this application provides a storage medium storing a computer program that, when executed by a processor, implements the steps of any of the aforementioned communication processing methods.
[0015] To address the aforementioned problems, this application provides an electronic device, comprising at least a memory and a processor, wherein the memory stores a computer program, and the processor, when executing the computer program in the memory, implements the steps of any of the aforementioned communication processing methods.
[0016] The communication processing method, apparatus, medium, and equipment in this application create a virtual server and associate several services using the virtual server, thereby realizing the automatic orchestration and combination of services. Subsequently, the client can quickly and accurately match the target service adapted to the client, effectively improving the overall communication processing efficiency.
[0017] This application pre-creates virtual servers and binds them to corresponding associated services, completing the pre-configuration of service resources and enabling custom orchestration and combination of services / capabilities. When a client initiates an access request, it eliminates the need for real-time retrieval and matching of massive service / capability resources; it can directly locate the target virtual server and provide a corresponding service list, allowing the client to quickly filter out the suitable target service. This significantly improves the speed of target service locking and lays the foundation for improved communication processing efficiency. Furthermore, this application employs a dedicated routing mechanism adapted to the service, matching corresponding routing methods for different target services. This accurately adapts to the communication transmission needs of various services, ensuring smooth routing of the client to the corresponding target server and guaranteeing the normal operation of communication processing. Thus, this application improves communication processing efficiency while ensuring normal operation of communication processing.
[0018] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0019] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This is a flowchart illustrating a communication processing method according to an embodiment of this application; Figure 2 This is an architecture diagram of the MCP gateway system platform in the embodiments of this application; Figure 3 This is a structural block diagram of a communication processing device according to an embodiment of this application; Figure 4 This is a structural block diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0020] Various embodiments and features of this application are described herein with reference to the accompanying drawings.
[0021] It should be understood that various modifications can be made to the embodiments described herein. Therefore, the above description should not be considered as limiting, but merely as an example of embodiments. Other modifications within the scope and spirit of this application will be apparent to those skilled in the art.
[0022] The accompanying drawings, which are included in and form part of this specification, illustrate embodiments of the present application and, together with the general description of the present application given above and the detailed description of the embodiments given below, serve to explain the principles of the present application.
[0023] These and other features of this application will become apparent from the following description of preferred forms of embodiments given as non-limiting examples, with reference to the accompanying drawings.
[0024] It should also be understood that although this application has been described with reference to some specific examples, those skilled in the art can certainly implement many other equivalent forms of this application.
[0025] The above and other aspects, features and advantages of this application will become more apparent when taken in conjunction with the accompanying drawings and in view of the following detailed description.
[0026] Specific embodiments of this application are described thereafter with reference to the accompanying drawings; however, it should be understood that the claimed embodiments are merely examples of this application, which can be implemented in various ways. Well-known and / or repeated functions and structures are not described in detail to avoid unnecessary or redundant details that could obscure the application. Therefore, the specific structural and functional details claimed herein are not intended to be limiting, but merely to serve as a representative basis for teaching those skilled in the art to use this application in a variety of substantially any suitable detailed structures.
[0027] This specification may use the phrases “in one embodiment,” “in another embodiment,” “in yet another embodiment,” or “in other embodiments,” all of which may refer to one or more of the same or different embodiments according to this application.
[0028] This application provides a communication processing method, which can be specifically applied to an MCP gateway platform / system, such as... Figure 1 As shown, the specific steps include the following: Step S101: In response to the virtual server creation request, several virtual servers are created in advance, and several services are associated with each virtual server; The creation request can include: basic information about the virtual server and service identifiers / capability identifiers of the backend capabilities / services to be associated. Specifically, a pre-defined interactive interface for creating virtual servers can be provided. Administrators of the pre-defined MCP gateway platform / system, tenants of a specific enterprise, or tenants of a specific team can all use this interface to input basic information about the virtual server and service identifiers of several services they wish to associate with it. This enables personalized service orchestration / combination for different enterprises and teams, achieving fine-grained combination of cross-source capabilities / services. Through the virtual server mechanism, backend services / capabilities from different sources can be freely combined into independent service nodes tailored to specific business scenarios / enterprises / teams.
[0029] The basic information of a virtual server may include: the virtual server's identifier / virtual server name. For example, if a company creates the virtual server, the virtual server identifier / virtual server name can be the company name, or it can be any other unique string used as the server's name / identifier.
[0030] In practice, after creating and obtaining virtual servers and associating each virtual server with its corresponding service, the mapping between the virtual server and its associated services can be stored in a predefined association list. Specifically, the virtual server identifier can be associated with the identifiers of the associated services.
[0031] Step S102: Receive the initial access request sent by the client for the target virtual server to be accessed; In the specific implementation of this step, when a client belonging to a member of the team wants to access the target virtual server corresponding to that team, the client can create an initial access request based on the virtual server identifier / virtual server name of the target virtual server and send the initial access request to the MCP gateway platform / system. The MCP gateway platform / system can then receive this initial access request.
[0032] Step S103: Based on the initial access request, determine the target virtual server to be accessed, determine the associated services associated with the target virtual server, and feed back a service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list. In the specific implementation of this step, the initial access request carries the target virtual server identifier. Therefore, the corresponding virtual server can be found based on the target virtual server identifier, and then the associated services associated with the virtual server identifier can be determined. In this way, a service list containing the service identifiers of each associated service is fed back to the client.
[0033] In other words, when employees / teams within an enterprise access relevant services, the MCP gateway platform / system no longer returns a complete list of backend services unrelated to that enterprise / team. Instead, it only returns a list of services associated with the virtual server corresponding to that enterprise / team. This allows the client to see only the set of capabilities / services associated with that virtual server. This enables the client to quickly and accurately identify the target backend service / capability that is compatible with it, achieving efficient communication processing. At the same time, it also provides security isolation capabilities in a multi-tenant environment, preventing the client from being aware of the existence of other virtual servers.
[0034] Step S104: Receive a target access request sent by the client containing a target service identifier, and for the target access request, use a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0035] In this step, after receiving the service list, the client can quickly and accurately identify the target service matching its access needs from the range of services provided in the list. Then, based on the target service identifier, it creates a target access request and sends it to the MCP gateway platform / system. The MCP gateway platform / system receives the target access request and, based on the target service identifier in the request, determines the target service the client wants to access. According to the target service, the MCP gateway platform / system routes the client through the target virtual server to the corresponding backend / target server, thus enabling communication between the client and the target server.
[0036] The method in this embodiment pre-creates virtual servers and binds them to corresponding associated services, completing the pre-configuration of service resources and enabling custom orchestration and combination of services / capabilities. When a client initiates an access request, it eliminates the need for real-time retrieval and matching of massive service / capability resources; it can directly locate the target virtual server and provide a corresponding service list, allowing the client to quickly filter out the suitable target service. This significantly improves the target service locking speed and lays the foundation for improving communication processing efficiency. Furthermore, this application employs a dedicated routing mechanism adapted to the service, matching corresponding routing methods for different target services. This accurately adapts to the communication transmission needs of various services, ensuring that the client is smoothly routed to the corresponding target server and guaranteeing the normal operation of communication processing. Thus, this application can improve communication processing efficiency while ensuring the normal operation of communication processing.
[0037] Based on the above embodiments, this application provides another embodiment of a communication processing method. In this embodiment, when creating several virtual services and associating several services with each virtual server, that is, when executing step S101, the method specifically includes the following steps: Step S101-1: For each virtual server, receive a creation request; In this step, a creation request containing basic information about the virtual server and a list of backend capability identifiers to be associated is received. The basic information should include: virtual server name / identifier, and a list of associated backend services / identifiers of the associated backend services.
[0038] This service list contains the service identifiers of each service to be associated. Specifically, the services / capabilities include: resource services corresponding to the MCP service type, tools services corresponding to the MCP service type, prompts services corresponding to the MCP service type, and API interface services corresponding to non-MCP service types, or any one or more of these.
[0039] Among them, non-MCP services can be REST API services or RPC services.
[0040] Since multiple services may provide the same service / capability, a service list can be created for each service. For example, a list of resources, a list of tools, and a list of prompts, etc.
[0041] Step S101-2: Based on the basic information in the creation request and the creation record table storing historical creation records, perform duplicate creation detection and obtain the detection result; In practice, this step can be used to perform name / identifier conflict checks based on key information of the virtual server, thus providing a safeguard against duplicate creation.
[0042] In other words, if the creation record table already contains a virtual server name / identifier that is the same as the virtual server name / identifier in the creation request, the detection result is that the creation is duplicated; conversely, if the creation record table does not contain a virtual server name / identifier that is the same as the virtual server name / identifier in the creation request, the detection result is that the creation is not duplicated.
[0043] Step S101-3: When the detection result meets the predetermined detection conditions, a virtual server is created based on the basic information, and the basic information is stored in the creation record table; In this step, if the current detection result indicates that the virtual server has not been duplicated, the predetermined detection conditions are met, and the virtual server can be created. This involves creating a virtual server record to store its basic information and access control attributes. If using a database, a new record is created in the table to store the virtual server's basic information, including its globally unique ID and name.
[0044] Step S101-4: Based on the service identifiers of several services to be associated in the creation request and the virtual server identifiers of the corresponding virtual servers, establish a mapping relationship between the virtual server identifiers and the corresponding service identifiers. Before performing step S1010-4, that is, before establishing the mapping relationship, the existence of each service to be associated can be pre-queried and verified based on each service identifier, and if each service exists, the mapping relationship between the virtual server identifier and each service identifier can be established. In the actual implementation process, the existence of each backend capability / backend service can be queried and verified based on the backend service list provided in the request.
[0045] Step S101-5: Store the mapping relationship in a predetermined service orchestration mapping table to associate several services with the virtual server.
[0046] In the specific implementation process, this step can establish records in the capability orchestration mapping table. For example, it can create mapping relationships between virtual servers and tools, virtual servers and resources, and virtual servers and prompts.
[0047] In this embodiment, after associating the virtual server with the service, an access port / access identifier can be configured for the virtual server. That is, after the virtual server is created, the system assigns it a unique identifier (visual_server_id), which clients can use to access predefined independent virtual server endpoints, as shown in the following example: / mcpgw / {visual_server_id} / mcp: Streamable HTTP transport endpoint.
[0048] / mcpgw / {visual_server_id} / sse: SSE transport endpoint.
[0049] In addition, the creation result can be returned to the tenant / administrator object to indicate whether the creation was successful or failed.
[0050] In the specific implementation of this embodiment, after creating and obtaining the virtual server, the method further includes: receiving an update request for the virtual server; updating the basic information of the virtual server based on the update information of the virtual server in the update request, and / or updating each service associated with the virtual server based on the update information of the associated services in the update request. Specifically, when updating, the update can be performed based on a concurrent control lock to prevent data inconsistency caused by concurrent updates. That is, when receiving an update request, the concurrent control lock corresponding to the virtual server identifier can be obtained according to the virtual server identifier in the update request; then, permission verification is further performed, that is, verifying whether the requesting user has the permission to change the virtual server, and updating the virtual server based on a non-control lock if the user has the permission to change the virtual server. The update content includes: updating associated services or updating the relevant information of the virtual server itself. Updating associated services includes: (1) removing the association between the virtual server and existing capabilities / services; that is, deleting the service identifier associated with the virtual server identifier in the service orchestration mapping table. (2) Verify the existence of the new associated capability; (3) Establish the association between the virtual server and the new capability / service; that is, establish the mapping relationship between the virtual server identifier and the service identifier of the new associated service, and store the mapping relationship in the service orchestration mapping table.
[0051] This application introduces a "virtual server" as a logical abstraction layer in the MCP gateway. Through a many-to-many association mechanism, it combines scattered tools, resources, and prompt templates into independent logical service nodes, generating an independent MCP transmission endpoint for each virtual server. When a client accesses the network, the access control module identifies and authenticates its identity, and implements access control mechanisms in the stages of capability discovery, tool invocation, resource access, and prompt acquisition to ensure that the client can only access the capability set associated with the virtual server.
[0052] Another embodiment of this application provides a communication processing method. In this embodiment, after creating and obtaining a virtual server, an independent access endpoint / MCP transmission endpoint can be configured for the virtual server to provide services externally. The access endpoint can be a Streamable HTTP endpoint or an SSE endpoint. Specifically: Streamable HTTP endpoint: used for request-response based communication. SSE endpoint: used for server push based communication. Thus, clients connect to specific virtual servers through these independent endpoints, rather than through a unified global entry point.
[0053] Another embodiment of the application provides a communication processing method. In this embodiment, when creating a virtual server, the method further includes: configuring a visibility level for each virtual server. The visibility levels include the following three types: Publicly visible: This virtual server is visible to all tenants and visitors within the platform and does not belong to any specific tenant. It is suitable for scenarios that require providing general services to the entire platform.
[0054] Tenant Visible: This virtual server is only visible to members of its owning tenant; members of other tenants are unaware of its existence. When creating a tenant-visible virtual server, the identity of its owning tenant must be specified. Virtual servers with the same name can be created under different tenants; the uniqueness of the name is limited to within the tenant, not globally.
[0055] Private: This virtual server is only visible to its creator; no other user is aware of its existence. Suitable for personal development and testing scenarios.
[0056] In this embodiment, when creating a virtual server, the visibility level and tenant identifier can be obtained from the parsing of the virtual server creation request. The tenant refers to different business objects such as a certain enterprise or a certain team corresponding to the virtual server.
[0057] After parsing the visibility level from the creation request, the MCP gateway system / platform can perform creation verification according to the corresponding verification method based on the visibility level. If the creation verification is successful, it will create a virtual server, associate several services with the virtual server, and configure the visibility level for the virtual server.
[0058] Specifically, the verification methods include a first method corresponding to public visibility, a second method corresponding to tenant visibility, and a third method corresponding to private visibility.
[0059] The first method is to check if the virtual server name conflicts globally. If a publicly visible virtual server with the same name already exists, the creation verification fails; otherwise, if no publicly visible virtual server with the same name exists, the creation verification succeeds. After the creation verification passes / successfully, the virtual server is created, several services are associated with it, and its visibility level is set to public, not belonging to any tenant.
[0060] The second method is as follows: (1) Check if the tenant identifier is empty. If it is empty, the check fails and an error message "The virtual server visible to the tenant must specify the owner tenant" is returned; (2) If the tenant identifier is not empty, check if the specified tenant exists in the system. If it does not exist, the check fails; (3) If the tenant identifier exists in the system, check if the creator is a member of the tenant and has the owner role. If not, the check fails; (4) If the creator is a member of the tenant and has the owner role, check if the virtual server name conflicts within the same tenant. If a virtual server with the same name already exists under the same tenant, the check fails; otherwise, if a virtual server with the same name exists under different tenants, creation is allowed, i.e., the check succeeds. This is because the uniqueness of the name is limited to within the tenant. After the check passes, a virtual server record is created, its visibility is set to be visible to the tenant, and its owner tenant identifier is written into the record.
[0061] The third method is to check whether the creator is a member of the tenant and has the owner role. If the creator is a member of the tenant and has the owner role, the verification is successful; otherwise, if the creator is not a member of the group or does not have the owner role, the verification fails.
[0062] In this embodiment, virtual servers are created by combining visibility levels. Thus, when a client queries the list of virtual servers, the MCP gateway platform / system can filter each virtual server according to the tenant to which the member / client belongs and the visibility level of each virtual server, ensuring that the member / client can only see the virtual servers that it is authorized to see, thereby achieving tenant isolation at the virtual server level.
[0063] In this embodiment, a publicly visible virtual server refers to one that is visible to all tenant members.
[0064] A tenant-visible virtual server is one that is only visible to members of the tenant to which it belongs. The MCP gateway platform / system queries the tenant list to which the member belongs. If the tenant list to which the member belongs contains the tenant identifier of the virtual server, then the virtual server is visible to the member; otherwise, it is not visible, and the member is unaware of the existence of the virtual server.
[0065] A privately visible virtual server is one that is only visible to its creator. The system verifies whether the member's identity matches that of the virtual server's creator.
[0066] In practice, before sending the initial access request, the client can send a virtual server list query request to the MCP gateway to obtain the virtual server list. That is, before receiving the initial access request, the MCP gateway platform can return the virtual server list to the client. This process is as follows: Step 1: The MCP gateway platform receives virtual server list query requests sent by members / clients; Step 2: The MCP gateway platform obtains the client's identity information from the query request, including: the tenant list to which the member / client belongs and the user / client identifier.
[0067] Step 3: MCP gateway platform constructs query conditions and filters virtual servers that meet any of the following conditions: (1) Visibility is public; (2) Visibility is tenant visible and the client / member identifier is in the tenant list; (3) Visibility is private visible and the creator is consistent with the member user identifier.
[0068] Step 4: The MCP gateway platform / system returns the filtered list of virtual servers to the client / member.
[0069] In this embodiment, the member / client is unaware of the existence of a virtual server that does not meet the conditions.
[0070] In this embodiment, by configuring the corresponding visibility level for the virtual server, fine-grained permission isolation can be achieved, reducing the risk of data leakage.
[0071] Another embodiment of this application provides a communication processing method. To prevent malicious access to services associated with virtual servers, access control can be implemented on each access request. Specifically, before receiving the initial access request sent by the client for the target virtual server to be accessed, that is, before executing step S102, the method further includes: receiving the client's request for access permissions; and issuing an access credential API Key to the client based on the request, so that the client can carry the access credential when sending the initial access request.
[0072] After receiving the initial access request sent by the client for the target virtual server to be accessed, that is, after executing step S102, the method further includes: obtaining the target visibility level of the target virtual server; based on the target visibility level and the access credentials carried in the access request, verifying whether the client meets the predetermined access conditions, so that when the access conditions are met, the associated services of the target virtual server are determined, and a service list containing each of the associated services is fed back to the client, so that the target client can determine the target service to be accessed based on the service list.
[0073] The access credential API Key carries access domain declaration information, which identifies which tenants' virtual servers the API Key can access.
[0074] The method in this embodiment can ensure that when a client accesses a specific virtual server, the tenant declaration of its API Key must match the tenant to which the target virtual server belongs, thereby achieving fine-grained access control from the perspective of access authorization and avoiding malicious access.
[0075] The communication processing method in this application will be described below with reference to specific embodiments: In step S201, the MCP gateway platform responds to each creation request of the virtual server, creates a corresponding virtual server for each tenant object, associates several services with each virtual server, and configures a visibility level for each virtual server. Step S202: The MCP gateway platform receives an access permission request sent by the client; based on the request, it issues an access credential API Key to the client so that the client can carry the access credential when sending the initial access request. In this step, the access credential API Key carries access domain declaration information. That is, before accessing a virtual server, the client needs to apply for an API Key from the MCP gateway platform. The API Key issued by the platform is encoded in JWT (JSON Web Token) format, which carries access domain declaration information. The access domain declaration contains information about which tenant's virtual servers the API Key can access; in other words, the access domain declaration contains identification information of the accessible virtual servers, and its scope is determined by the applicant's tenant membership and cannot exceed the scope of the applicant / client's actual tenant. Access domain declarations include the following: An empty access domain declaration means the API Key is not bound to any tenant. Clients holding this API Key can only access publicly visible virtual servers and cannot access any tenant-visible or privately visible virtual servers.
[0076] The access domain statement contains one or more tenant identifiers: the API Key is bound to a specified tenant, and the client holding the API Key can access the following virtual servers: (1) publicly visible virtual servers; (2) tenant-visible virtual servers whose tenant identifier is in the API Key access domain statement. Tenant virtual servers not included in the access domain statement are inaccessible to the client.
[0077] In its specific implementation, step S202 includes the following steps: Step S202-1: Receive the access permission request sent by the client; The request includes: a list of tenant identifiers that the client expects to access, and the client's identity information.
[0078] Step S202-2: Based on the client identity information and tenant identifier list in the application request, verify whether the client is a member of each tenant in the tenant identifier list; if the verification is successful, proceed to step S202-3; if the verification fails, end the communication processing flow.
[0079] In this step, if the client does not belong to a tenant in a certain declaration, the verification fails and the tenant identifier is refused to be written into the access domain declaration. Conversely, if the client is a member of each tenant in the tenant list, the verification succeeds.
[0080] Step S202-3: Based on the list of tenant identifiers in the application request, generate an API Key in JWT format, write the list of verified tenant identifiers into the access domain declaration field of the JWT, write the permission scope into the permission declaration field of the JWT, and sign the JWT. Step S202-4: Return the API Key to the client so that the client can carry the API Key as an identity credential in subsequent requests.
[0081] Step S203: Receive the initial access request sent by the client for the target virtual server to be accessed; In this step, the initial access request carries information such as the API Key, client identity information, and the target server identifier of the target server to be accessed.
[0082] Step S204: Based on the client's identity information in the initial access request, authenticate the client. If authentication is successful, proceed to step S205; otherwise, terminate the communication processing flow. Step S205: Based on the initial access request, obtain the target visibility level of the target virtual server; In the specific implementation process, this step can determine the target virtual server to be accessed based on the virtual server identifier in the initial access request, and then obtain the corresponding target visibility level for the target virtual server.
[0083] Step S206: Based on the target visibility level and the access credential APIKey carried in the access request, verify whether the client meets the predetermined access conditions, so as to determine the associated services associated with the target virtual server when the access conditions are met. In the specific implementation process, this step, when verifying whether the client meets the predetermined access conditions, specifically includes the following procedures: Step S206-1: Parse the API Key from the initial access request, verify the signature validity of the API Key, and extract the access domain declaration and permission declaration from the JWT when the verification is successful. Step S206-2: Based on the target virtual server identifier in the initial access request, query the tenant identifier of the target virtual server. Step S206-3: Based on the tenant identifier of the target virtual server, the target visibility level, the access domain declaration, and the permission declaration, verify whether the client meets the predetermined access conditions. In this step, the following access condition checks can be performed based on the visibility level of the virtual server: If the target virtual server is publicly visible, then the client is deemed to meet the access requirements.
[0084] If the target virtual server is visible to the tenant: verify whether the access domain declaration of the API Key contains the owner tenant identifier of the target virtual server. If it does, the client is deemed to meet the access conditions; if it does not, the client is deemed to not meet the access conditions.
[0085] If the virtual server is private and visible: verify that the user identifier / client identifier in the API Key matches the creator of the virtual server. If they match, the client meets the access requirements; if they do not match, the client does not meet the access requirements.
[0086] Step S207: Determine the associated services of the target virtual server, and feed back the service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list; Step S208: Receive a target access request sent by the client containing a target service identifier, and for the target access request, use a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0087] In this step, the associated services include any one or more of the following: resource services corresponding to the MCP service type, tool services corresponding to the MCP service type, prompt word template services corresponding to the MCP service type, and API interface services corresponding to non-MCP service types.
[0088] When the service type of the target service is an MCP service type, the target access request is forwarded to the target server corresponding to the target service through the target virtual server, so that the client can communicate with the target server; when the service type of the target service is not an MCP service type, the target access request is converted into a protocol format to obtain a current target access request in a predetermined protocol format, and the current target access request is forwarded to the target server corresponding to the target service through the target virtual server, so that the client can communicate with the target server.
[0089] For tool services, the detailed process of routing the client to the backend service is as follows: When a client accesses the target tool service, the MCP gateway routes the target access request to the backend service: 1. Obtain the tool's configuration information (including tool type, backend service address, authentication information, etc.).
[0090] 2. If the tool type is an external API, the request will be converted to the corresponding protocol format and forwarded.
[0091] 3. If the tool type is an MCP service, then a connection is established with the backend service through an MCP session and requests are forwarded.
[0092] 4. Receive the response from the backend service and return it to the client.
[0093] The method in this embodiment introduces a "virtual server" as a logical abstraction layer. This allows for the free combination of MCP services / capabilities (tools, resources, prompts) or non-MCP services / capabilities from different sources into virtual servers tailored to specific business scenarios. Specifically, corresponding virtual servers can be created for different enterprise / department tenants, and each virtual server exposes an independent MCP transmission endpoint. AI Agents / clients / members, by accessing the endpoints of the virtual servers, can only see the set of capabilities associated with that virtual server, achieving business scenario-level capability isolation and independent governance.
[0094] This application addresses the lack of a unified entry point and management capabilities in the direct connection mode by providing a unified capability access point for AI clients through an MCP gateway. It also solves the problem that existing unified MCP gateways cannot achieve fine-grained combination of cross-source capabilities, using a virtual server mechanism to freely combine / orchestrate various services / capabilities from different sources into independent service nodes tailored to specific business scenarios. Furthermore, this application improves security isolation capabilities in multi-tenant environments, ensuring that clients accessing through virtual server endpoints can only see the capability set associated with that virtual server and are unaware of the existence of other virtual servers. Finally, this application enables virtual server-level tenant isolation, access control, capability combination, and precise routing.
[0095] Another embodiment of this application provides an MCP gateway platform / system. For example... Figure 2 As shown, MCP transmission module: Provides endpoint access for standard transmission protocols, supports independent endpoints of virtual servers, and is responsible for receiving client requests and returning responses; Access control module: responsible for client identity verification (JWT / Bearer token or API key verification), access control, rate limiting, and blacklist / whitelist filtering; Virtual Server Module: Contains multiple virtual server instances. Each virtual server is designed for a specific business scenario; that is, different enterprises / departments or other tenant objects can correspond to one virtual server. Backend capabilities from different sources are combined through a capability orchestration and mapping mechanism. For example... Figure 2 Virtual server 1 combines tool A, resource A, and prompt A from MCP service 1; virtual server 2 combines tool C, tool D, and resource B from MCP service 2; virtual server 3 is associated with API service E / api; virtual server 4 is associated with API service X / api; and virtual server 5 is associated with RPC service Y. Furthermore, a virtual server can also be associated with REST API service X and tool B from MCP service 2, meaning that REST API service X and tool B from MCP service 2 will be combined into an independent logical service node.
[0096] Virtual Server Management Module: Responsible for creating, querying, updating, and deleting virtual servers, and maintaining the orchestration mapping relationship between virtual servers and backend capabilities / services; for MCP services, it discovers exposed tools, resources, and prompt word templates through configuration or registration, and directly incorporates them into the tool library, resource library, and prompt word template library; for REST API services, it adapts each API interface into a tool, extracts its request parameter structure to generate an input schema (JSONSchema), and incorporates it into the unified tool library; for RPC services, it automatically discovers service methods through the service reflection protocol, adapts each method into a tool, and incorporates it into the unified tool library. Protocol conversion module: Converts the company's existing non-MCP protocol services such as REST API and RPC to the MCP protocol, enabling the AI Agent to discover and invoke them uniformly; for native MCP services, it does not involve MCP protocol conversion, but rather MCP protocol routing. Request routing module: When the virtual server receives an MCP request from a client and routes it to a backend service, if the target backend service is a REST API or RPC service, the protocol conversion module converts the MCP request into the corresponding protocol format and forwards the route; if the target backend service is an MCP service, the request routing module directly routes the request to the backend service through the MCP protocol without protocol conversion.
[0097] In other words, the AI Agent or LLM application or client communicates with the MCP gateway via the MCP protocol. The AI Agent or LLM application or client connects to a specific service under a specific virtual server through an endpoint with a virtual server identifier (such as " / mcpgw / vs1 / mcp").
[0098] Another embodiment of this application provides a communication processing device, such as... Figure 3 As shown, it includes: The creation module 11 is used to pre-create a number of virtual servers in response to a virtual server creation request, and associate a number of services with each of the virtual servers; The receiving module 12 is used to receive the initial access request sent by the client to the target virtual server to be accessed; The determination module 13 is used to determine the target virtual server to be accessed based on the initial access request, determine the associated services associated with the target virtual server, and feed back a service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list. The communication processing module 14 is used to receive a target access request sent by a client, which contains a target service identifier, and, for the target access request, to use a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0099] Another embodiment of this application provides a storage medium storing a computer program, which, when executed by a processor, implements the following method steps: Step 1: In response to the virtual server creation request, several virtual servers are created in advance, and several services are associated with each virtual server; Step 2: Receive the initial access request sent by the client for the target virtual server to be accessed; Step 3: Based on the initial access request, determine the target virtual server to be accessed, determine the associated services of the target virtual server, and feed back the service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list. Step 4: Receive the target access request sent by the client, which contains the target service identifier, and for the target access request, use the routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0100] The specific implementation process of the above method steps can be found in the embodiments of any of the above communication processing methods, and will not be repeated here.
[0101] This application pre-creates virtual servers and binds them to corresponding associated services, completing the pre-configuration of service resources and enabling custom orchestration and combination of services / capabilities. When a client initiates an access request, it eliminates the need for real-time retrieval and matching of massive service / capability resources; it can directly locate the target virtual server and provide a corresponding service list, allowing the client to quickly filter out the suitable target service. This significantly improves the speed of target service locking and lays the foundation for improved communication processing efficiency. Furthermore, this application employs a dedicated routing mechanism adapted to the service, matching corresponding routing methods for different target services. This accurately adapts to the communication transmission needs of various services, ensuring smooth routing of the client to the corresponding target server and guaranteeing the normal operation of communication processing. Thus, this application improves communication processing efficiency while ensuring normal operation of communication processing.
[0102] Another embodiment of this application provides an electronic device, such as... Figure 4As shown, it includes at least a memory 1 and a processor 2. The memory 1 stores a computer program, and the processor 2 performs the following method steps when executing the computer program in the memory 1: Step 1: In response to the virtual server creation request, several virtual servers are created in advance, and several services are associated with each virtual server; Step 2: Receive the initial access request sent by the client for the target virtual server to be accessed; Step 3: Based on the initial access request, determine the target virtual server to be accessed, determine the associated services of the target virtual server, and feed back the service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list. Step 4: Receive the target access request sent by the client, which contains the target service identifier, and for the target access request, use the routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
[0103] The specific implementation process of the above method steps can be found in the embodiments of any of the above communication processing methods, and will not be repeated here.
[0104] This application pre-creates virtual servers and binds them to corresponding associated services, completing the pre-configuration of service resources and enabling custom orchestration and combination of services / capabilities. When a client initiates an access request, it eliminates the need for real-time retrieval and matching of massive service / capability resources; it can directly locate the target virtual server and provide a corresponding service list, allowing the client to quickly filter out the suitable target service. This significantly improves the speed of target service locking and lays the foundation for improved communication processing efficiency. Furthermore, this application employs a dedicated routing mechanism adapted to the service, matching corresponding routing methods for different target services. This accurately adapts to the communication transmission needs of various services, ensuring smooth routing of the client to the corresponding target server and guaranteeing the normal operation of communication processing. Thus, this application improves communication processing efficiency while ensuring normal operation of communication processing.
[0105] The above embodiments are merely exemplary embodiments of this application and are not intended to limit this application. Those skilled in the art can make various modifications or equivalent substitutions to this application within the scope and nature of this application, and such modifications or equivalent substitutions should also be considered to fall within the scope of protection of this application.
Claims
1. A communication processing method, characterized in that, include: In response to a virtual server creation request, several virtual servers are pre-created, and several services are associated with each virtual server; Receive the initial access request sent by the client for the target virtual server to be accessed; Based on the initial access request, the target virtual server to be accessed is determined, and the associated services of the target virtual server are determined. A service list containing the associated services is then fed back to the client so that the target client can determine the target service to be accessed based on the service list. The system receives a target access request sent by a client, which contains a target service identifier. Based on the target access request, the system uses a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
2. The method as described in claim 1, characterized in that, In response to a virtual server creation request, several virtual servers are pre-created, and several services are associated with each virtual server, specifically including: For each virtual server, a creation request is received; Based on the basic information in the creation request and the creation record table storing historical creation records, duplicate creation detection is performed to obtain the detection result; When the detection result meets the predetermined detection conditions, a virtual server is created based on the basic information, and the basic information is stored in the creation record table; Based on the service identifiers of several services to be associated in the creation request and the virtual server identifiers of the corresponding virtual servers, establish a mapping relationship between the virtual server identifiers and each service identifier. The mapping relationship is stored in a predetermined service orchestration mapping table to associate several services with the virtual server.
3. The method as described in claim 1, characterized in that, After creating and obtaining the virtual server, the method further includes: Receive update requests for virtual servers; Based on the update information of the virtual server in the update request, update the basic information of the virtual server, and / or based on the update information of the associated services in the update request, update each service associated with the virtual server.
4. The method as described in claim 1, characterized in that, The method also includes: pre-configuring visibility levels for each virtual server; Before receiving the initial access request sent by the client for the target virtual server to be accessed, the method further includes: Receive access permission requests sent by clients; Based on the application request, an access credential is issued to the client so that the client can carry the access credential when sending the initial access request.
5. The method as described in claim 4, characterized in that, After receiving the initial access request sent by the client for the target virtual server to be accessed, the method further includes: Obtain the target visibility level of the target virtual server; Based on the target visibility level and the access credentials carried in the access request, the client is verified to meet the predetermined access conditions, so that when the access conditions are met, the associated services associated with the target virtual server are determined.
6. The method as described in claim 1, characterized in that, The associated services include any one or more of the following: resource services corresponding to the MCP service type, tool services corresponding to the MCP service type, prompt word template services corresponding to the MCP service type, and API interface services corresponding to non-MCP service types.
7. The method as described in claim 6, characterized in that, The step of routing the client through the target virtual server to the target server corresponding to the target service in response to the target access request, using a routing method corresponding to the target service, so that the client can communicate with the target server, specifically includes: When the service type of the target service is MCP service type, the target access request is forwarded to the target server corresponding to the target service through the target virtual server, so that the client can communicate with the target server; When the service type of the target service is a non-MCP service type, the target access request is converted into a protocol format to obtain the current target access request in a predetermined protocol format. The current target access request is then forwarded to the target server corresponding to the target service through the target virtual server, so that the client can communicate with the target server.
8. A communication processing device, characterized in that, include: A creation module is used to pre-create several virtual servers in response to a virtual server creation request, and associate several services with each virtual server; The receiving module is used to receive the initial access request sent by the client to the target virtual server to be accessed; The determination module is used to determine the target virtual server to be accessed based on the initial access request, determine the associated services associated with the target virtual server, and feed back a service list containing the associated services to the client so that the target client can determine the target service to be accessed based on the service list. The communication processing module is used to receive a target access request sent by a client, which contains a target service identifier, and, for the target access request, to use a routing method corresponding to the target service to route the client through the target virtual server to the target server corresponding to the target service, so that the client can communicate with the target server.
9. A storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the steps of the communication processing method according to any one of claims 1-7.
10. An electronic device, characterized in that, It includes at least a memory and a processor, wherein the memory stores a computer program, and the processor, when executing the computer program in the memory, implements the steps of the communication processing method according to any one of claims 1-7.