Data processing method, device, storage medium, and program product
By collaborating with the access device and the data authentication server to perform data authentication based on user identification and configuration information, the problem of poor data interception effect in the existing technology is solved, and data transmission with improved data security can be achieved without upgrading the terminal equipment.
Patent Information
- Application Number
- PCT/CN2025/082803
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-25
- Filing Date
- 2025-03-17
- Publication Date
- 2025-10-02
AI Technical Summary
In the existing technology, the method of intercepting data by integrating SDK on the client is difficult and costly to transform and upgrade, resulting in poor data interception effect and inability to effectively ensure data security.
The access device receives the access request of the terminal device, and uses the data authentication server to perform authentication processing based on the user identification and configuration information to determine whether to intercept or transmit data, avoiding the upgrade and modification of the terminal device.
It reduces the cost and difficulty of upgrading and transformation, improves the effect of data interception, and ensures the security of data transmission.
Smart Images

Figure CN2025082803_02102025_PF_FP_ABST
Abstract
Description
Data processing method, device, storage medium and program product
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on March 25, 2024, with application number 2024103544307 and application name “A method, device, storage medium and program product for data processing”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of computer technology, and specifically to data processing. Background Art
[0003] Cloud acceleration channels are a cloud service provided by cloud platforms. They can be understood as an acceleration channel established between the client and the server. Cloud acceleration channels rely on high-speed channels, forwarding clusters, and intelligent routing technologies between the cloud platform's own global nodes to achieve local access for users in all locations. By directly connecting to the source server region through high-speed channels, businesses can solve the problem of access lag or high latency for global users. Based on these advantages of cloud acceleration channels, many businesses (especially games with global servers or business systems of multinational enterprises) choose this solution when deploying. In recent years, with the increasing emphasis on the security protection of easily leaked data such as user personal information or other user-defined data, cloud acceleration channel businesses urgently need a convenient, flexible, and accurate data interception function to ensure the safe and legal collection, transmission, and use of data.
[0004] Traditional data interception methods typically involve integrating a software development kit (SDK) into the client to implement data interception functionality. This SDK is then used to process data, either intercepting data that is not permitted to be sent to the server or preventing data that is permitted to be sent to the server. However, the current approach of intercepting data by modifying and upgrading the client (i.e., integrating the SDK into the client) often hinders client upgrades due to the increased difficulty and cost of such modifications, resulting in poor data interception effectiveness and a failure to ensure data security. Summary of the Invention
[0005] The embodiments of the present application provide a data processing method, device, storage medium and program product, which can determine in advance whether to intercept or continue to transmit the first data at the access device based on the authentication result fed back by the data authentication server, without the need to upgrade and modify the client, which not only reduces the cost and difficulty of the upgrade and modification, but also improves the effect of data interception.
[0006] In a first aspect, an embodiment of the present application provides a method for data processing. The method can be applied to an access device. The method includes: receiving an access request sent by a terminal device, the access request including first data and a user identifier, the user identifier and configuration information having a mapping relationship, the configuration information being used to indicate whether dial-up type data is allowed to be transmitted to a target server; after detecting that there is a corresponding data authentication rule for the access request, forwarding the access request to a data authentication server, so that the data authentication server finds the configuration information based on the user identifier and the mapping relationship, and then performs authentication processing on the first data based on the configuration information to obtain an authentication result; after receiving the authentication result sent by the data authentication server, intercepting or transmitting the first data based on the authentication result.
[0007] In a second aspect, an embodiment of the present application provides a method for data processing. This method can be applied to a data authentication server. The method includes: receiving an access request sent by an access device, the access request including first data and a user identifier, the user identifier being mapped to configuration information, and the configuration information being used to indicate whether different types of data are allowed to be transmitted to a target server; searching for configuration information based on the user identifier and the mapping relationship in the access request; performing authentication processing on the first data based on the configuration information to obtain an authentication result; and sending the authentication result to the access device, where the authentication result is used by the access device to intercept or transmit the first data.
[0008] In a third aspect, an embodiment of the present application provides an access device. The access device includes a receiving unit, a sending unit, and a processing unit. The receiving unit is used to receive an access request sent by a terminal device, the access request including first data and a user identifier, the user identifier and the configuration information have a mapping relationship, and the configuration information is used to indicate whether different types of data are allowed to be transmitted to the target server; the sending unit is used to forward the access request to a data authentication server after detecting that there is a corresponding data authentication rule for the access request, so that the data authentication server finds the configuration information based on the user identifier and the mapping relationship, and then performs authentication processing on the first data based on the configuration information to obtain an authentication result; the processing unit is used to intercept or transmit the first data based on the authentication result after receiving the authentication result sent by the data authentication server.
[0009] In a fourth aspect, an embodiment of the present application provides a data authentication server. The data authentication server includes a receiving module, a processing module, and a sending module. The receiving module is used to receive an access request sent by an access device, the access request includes first data and a user identifier, and there is a mapping relationship between the user identifier and the configuration information, and the configuration information is used to indicate whether different types of data are allowed to be transmitted to the target server. The processing module is used to search for configuration information based on the user identifier and the mapping relationship in the access request. The processing module is used to authenticate the first data based on the configuration information to obtain an authentication result. The sending module is used to send the authentication result to the access device, and the authentication result is used by the access device to intercept or transmit the first data.
[0010] In another aspect, an embodiment of the present application provides a computer device, including:
[0011] Processor, communication interface, memory and communication bus;
[0012] Wherein, the processor, the communication interface and the memory complete communication with each other through the communication bus; the communication interface is an interface of the communication module;
[0013] The memory is used to store a computer program and transmit the computer program to the processor; the processor is used to call the computer program in the memory to execute the above method.
[0014] On the other hand, an embodiment of the present application provides a storage medium, which is used to store a computer program, and the computer program is used to execute the method of the above aspect.
[0015] On the other hand, an embodiment of the present application provides a computer program product including a computer program, which, when executed on a computer, enables the computer to execute the above method.
[0016] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0017] In an embodiment of the present application, an access device receives an access request sent by a terminal device. The access request includes first data and a user identifier, and the user identifier is mapped to configuration information. The configuration information can be used to indicate whether different types of data are allowed to be transmitted to a target server. Upon detecting that a corresponding data authentication rule exists for the access request, the access device forwards the access request to a data authentication server. The data authentication server then locates the configuration information based on the user identifier and the mapping relationship and authenticates the first data based on the configuration information to obtain an authentication result. Thus, upon receiving the authentication result from the data authentication server, the access device intercepts or transmits the first data based on the authentication result. In this manner, before transmitting the access request, first data, etc. sent by the terminal device to the target server, the access device forwards the access request to the data authentication server. The authentication result, which is returned by the data authentication server after authenticating the first data, is then used to determine in advance whether to intercept or continue transmitting the first data. In other words, in this application, by adding a data authentication server, and then using the access device and the data authentication server to realize the function of data interception, it is possible to decide whether to intercept the first data in advance at the access device based on the authentication result feedback from the data authentication server before the first data is transmitted to the target server. There is no need to upgrade and transform the terminal device or the target server, which not only reduces the cost and difficulty of upgrading and transforming, but also improves the effect of data interception. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] FIG1 is a schematic diagram showing data transmission through an acceleration channel in a related solution;
[0019] FIG2 shows a schematic diagram of a system architecture for data processing provided by an embodiment of the present application;
[0020] FIG3 shows a flow chart of a data processing method provided by an embodiment of the present application;
[0021] FIG4 shows an optional schematic diagram of the first data provided in this application;
[0022] FIG5 shows an optional schematic diagram of the data authentication rules provided by this application;
[0023] FIG6 shows an optional schematic diagram provided by the present application when data needs to be intercepted;
[0024] FIG7 shows another optional flowchart of data processing provided by the present application;
[0025] FIG8 shows another optional flowchart of data processing provided by the present application;
[0026] FIG9 shows an optional schematic diagram of functional modules of an access device provided in an embodiment of the present application;
[0027] FIG10 shows an optional schematic diagram of the functional modules of the data authentication server provided in an embodiment of the present application;
[0028] FIG11 shows an optional schematic diagram of the hardware structure of a data processing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0029] The embodiments of the present application provide a data processing method, device, storage medium and program product, which can determine in advance whether to intercept or continue to transmit the first data at the access device based on the authentication result fed back by the data authentication server, without the need to upgrade and modify the client, which not only reduces the cost and difficulty of the upgrade and modification, but also improves the effect of data interception.
[0030] It is understandable that in the specific implementation of this application, related data such as user information is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0031] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0032] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of the present application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the implementation of the present application described herein can, for example, be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to such processes, methods, products, or apparatus.
[0033] Typically, sending data from a terminal device to a server, or vice versa, requires establishing a transmission channel between the terminal device and the server. Only after this channel is established can data be transmitted between the terminal device and the server. In some transmission scenarios, to increase transmission efficiency and enable local access for users in various locations, the use of cloud-based acceleration channels between terminal devices and servers has gradually evolved.
[0034] The described cloud acceleration channel can be understood as an acceleration channel established between the terminal device and the server using the cloud platform. Through the cloud acceleration channel, data can be quickly transmitted between the terminal device and the server. Figure 1 shows a schematic diagram of data transmission through the acceleration channel in the relevant scheme. As shown in Figure 1, taking the client as the terminal device as an example, when the terminal device needs to transmit data to the source station server, the terminal device first transmits the data to the acceleration channel access node, and then forwards the data to the acceleration channel forwarding node through the acceleration channel access node. Finally, the data is forwarded to the source station server through the acceleration channel forwarding node, so that the source station server receives the data sent by the terminal device.
[0035] During the above-mentioned data transmission process, the target object hopes that certain data that is easy to leak and needs to be protected or certain user-defined data does not need to be transmitted to the server. At this time, these data can be intercepted and processed on the transmission link shown in Figure 1 above to prevent the relevant data from being transmitted to the server. However, in the traditional data interception solution, it is necessary to rely on the SDK toolkit in the terminal device such as the client to verify whether the data should be intercepted. However, this interception method is very easy to cause the transmission of easy-to-leak or user-defined data that does not need to be transmitted to the server when using the current SDK toolkit to verify the data due to the difficulty and cost of modification and upgrading. It cannot effectively implement data interception, resulting in the inability to ensure data security. Moreover, it is necessary to modify and upgrade the terminal device such as the client to complete the data interception, which increases the difficulty and cost of modification and upgrading.
[0036] Therefore, to address the above-mentioned technical issues, embodiments of the present application provide a data processing method. This data processing method can be applied to the system architecture shown in FIG2 . As shown in FIG2 , the system architecture includes at least a terminal device, an access device, a data authentication server, a forwarding device, and a target server. The terminal device establishes a communication connection with the target server via the access device and the forwarding device, in sequence. Furthermore, the access device also establishes a communication connection with the data authentication server to implement data interception functionality via the access device and the data authentication server.
[0037] In this application, before the target object sends data to the target server through the terminal device, configuration information can be set in advance through the terminal device to identify which types of data can be transmitted to the target server and which types of data do not want to be transmitted to the target server, thereby constructing a mapping relationship between the user identifier and the configuration information of the data. The user identifier mentioned can be used to identify the target object. The configuration information mentioned can characterize the configuration of whether the target object corresponding to the user identifier is allowed to be transmitted to the target server for different types of data (such as the first data mentioned later). It should be noted that the first data mentioned in this application can be understood as any data when transmitted from the terminal device to the target server.
[0038] In this way, after the mapping relationship between the data configuration information and the user identifier is set, the target object can send an access request to the target server through the terminal device, and the access request includes the first data and the user identifier. Since the terminal device needs to access the target server through the access device, the access request will be received by the access device before being obtained by the target server.
[0039] After receiving an access request, the access device does not directly forward the access request to the target server via the forwarding device. Instead, it first checks whether the access request matches a corresponding data authentication rule. After detecting the data authentication rule, the access device forwards the access request to the data authentication server. The data authentication server then searches for configuration information based on the user identifier and the mapping relationship. Once the configuration information is found, it authenticates the first data based on the configuration information, thereby determining an authentication result. The data authentication server then sends the authentication result to the access device.
[0040] After receiving the authentication result sent by the data authentication server, the access device intercepts the first data based on the authentication result or transmits the first data to the target server via the forwarding device. In other words, by adding a data authentication server and utilizing the access device and the data authentication server to implement the data interception function, the access device can decide whether to intercept the first data based on the authentication result fed back by the data authentication server before the first data is transmitted to the target server. This eliminates the need to upgrade or modify the terminal device, thus preventing data leakage and improving data security. It also reduces the difficulty and cost of modification and upgrade.
[0041] It should be noted that the access device mentioned in FIG. 2 may include but is not limited to the acceleration channel access node shown in FIG. 1 , or other access devices with acceleration functions, etc., which are not limited in this application. In addition, the forwarding device shown in FIG. 2 may include but is not limited to the acceleration channel forwarding node shown in FIG. 1 , or other forwarding devices with acceleration functions, etc., which are not limited in this application. The target server shown in FIG. 2 may include but is not limited to the source server shown in FIG. 1 , or other business servers, etc., which are not limited in this application. In addition, the data authentication server mentioned in FIG. 2 can be understood as a server or other device with data authentication functions, etc., which are not limited in this application. Optionally, the data authentication server mentioned in this application can also be a device with data authentication functions in an access device in actual applications. In the embodiment of this application, the data authentication server is only used as an example of an authentication device independent of the access device, and the existence of the data authentication server is not specifically limited.
[0042] The data processing method provided in the embodiments of the present application can be implemented by a computer device, which can be a terminal device or a server, wherein the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud computing, cloud database, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. Terminal devices include but are not limited to mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. Terminal devices and servers can be directly or indirectly connected via wired or wireless communication, and this application does not limit this.
[0043] Some embodiments are executed by a computer device serving as an access device, and some embodiments are executed by a computer device serving as a data authentication server.
[0044] For example, the data processing method provided in the embodiments of the present application can also be applied to various scenarios such as artificial intelligence, cloud technology, smart Internet of Things, Internet of Vehicles, virtual games, etc., which are not limited in this application.
[0045] The following describes a data processing method provided by an embodiment of the present application in conjunction with the accompanying drawings. FIG3 shows a flow chart of a data processing method provided by an embodiment of the present application, which can be executed by an access device. As shown in FIG3 , the data processing method may include the following steps:
[0046] 301. A terminal device sends an access request to an access device. The access request includes first data and a user identifier. There is a mapping relationship between the user identifier and configuration information. The configuration information is used to indicate whether different types of data are allowed to be transmitted to a target server.
[0047] In this example, before the target object sends data to the target server through the terminal device, it can set configuration information in advance through the terminal device. This configuration information identifies which types of data can be sent to the target server during the transmission process and which types of data are not expected to be transmitted to the target server. In this way, a mapping relationship between the user identifier and the configuration information can be established. In other words, in this application, the target object sets different configuration information for different types of data through the terminal device in advance, so that the configuration information indicates the configuration status of the target object corresponding to the user identifier when each type of data is allowed to be transmitted to the target server.
[0048] In order to accurately identify which types of data can be transmitted to the target server and which types of data cannot be transmitted to the target server, the configuration information described includes a configuration status. The configuration status can reflect the indication set when the target object sets whether a certain type of data is allowed to be transmitted to the target server. For example, the configuration status includes at least one of a first setting state or a second setting state. The first setting state mentioned can be understood as the target object not allowing a certain type of data to be transmitted to the target server. As a schematic description, for data information, developers and other target objects hope that some types of data will be stored in the local database, while some types of data will be allowed to be uploaded to the server for storage. Based on this, the target object sets different configuration states in the configuration information for different types of data.
[0049] For example, for personal information, other easily leaked or high-security data, etc., the target object usually wants to save it in a local database. Then, for this type of data, the target object can set the corresponding configuration state to the first setting state through the terminal device.
[0050] Conversely, the second setting state refers to the target user allowing certain types of data to be transmitted to the target server. For example, for non-security-related data such as files, images, audio, or other data with a lower security level, the target user is generally not concerned about the security of this data and may allow it to be transmitted to the target server. For this type of data, the target user can set the corresponding configuration state to the second setting state through the terminal device.
[0051] For example, Figure 4 shows an optional schematic diagram of the first data provided by this application. As shown in Figure 4, taking a certain service (for example, service A) and "personal information of service A" as the first data as an example, for the target object with the user name "12345", the target object does not want the "personal information of service A" to be transmitted to the server to help improve XXX products and services. As can be seen from parts (a) to (c) in Figure 4, the target object can find an option about "personal information of service A" through the "Personal Information -> Privacy Settings -> Personal Information Provision of Service A" setting, such as "used to help improve XXX products and services". After querying the option of the first data, the target object can set the status of the "personal information of service A", for example, set it to the first setting state. For example, as shown in part (c) in Figure 4, for the "personal information of service A", the target object can "uncheck" the corresponding setting option to set the configuration status corresponding to the "personal information of service A" to the first setting state.
[0052] In this way, the target object can set different settings for different types of data through the terminal device according to its own business needs. The terminal device can then generate configuration information corresponding to each type of data. Furthermore, the terminal device can also map this configuration information with the user identifier to determine the mapping relationship between the user identifier and the configuration information. This allows the subsequent data authentication server to quickly find the corresponding configuration information based on the mapping relationship after obtaining the user identifier carried in the access request, and then determine whether the first data needs to be transmitted to the target server through authentication.
[0053] In this way, the terminal device generates an access request based on the business needs of the target object and sends it to the target server. Since the access device is in the data connection link between the terminal device and the target server, it will receive the access request first. For example, the access request can be sent to the target server through the cloud acceleration channel.
[0054] 302. After detecting that a corresponding data authentication rule exists for the access request, the access device forwards the access request to a data authentication server.
[0055] In this example, business operation and maintenance personnel can also configure access protocols, data authentication result fields, response fields and other information through access devices in advance based on business needs, so that the access device can generate data authentication rules based on access protocols, data authentication result fields, response fields and other information after obtaining the access protocols, data authentication result fields, response fields and other information.
[0056] Based on the authentication requirements for the data in the access request, data authentication rules will establish a correspondence with the access requests that require data authentication. This correspondence will then clarify which data in the access requests requires authentication. For example, for some types of access requests, some data may not be transmitted to the target server. In this case, a correspondence can be established between these types of access requests and data authentication rules. For other types of access requests, no data should be transmitted to the target server. In this case, a correspondence between these types of access requests and data authentication rules may not be established.
[0057] The access protocol described may include, but is not limited to, the Hyper Text Transfer Protocol (HTTP), etc., and is not limited in this application. As an illustrative description, this application only uses the HTTP protocol as an example of the access protocol. The HTTP protocol may include information such as a request header, a request body, and a request uniform resource locator (URL).
[0058] The data authentication result field may include fields indicating whether interception is required or not. For fields indicating whether interception is required, a corresponding first status code may be set. For example, using the HTTP protocol as an example, the first status code may be the HTTP response code 401. For fields indicating whether interception is required, a corresponding second status code may be set. For example, using the HTTP protocol as an example, the second status code may be the HTTP response code 200.
[0059] In addition, the described response field may include response fields in two situations, such as a response field that is fed back to the terminal device when interception is required, and a response field that is fed back to the terminal device when the data authentication server fails to access. For example, for the response field that is fed back to the terminal device when interception is required, it can be done by configuring a corresponding first response message, which includes a response header, a response body, and a response code. Alternatively, for the response field that is fed back to the terminal device when the data authentication server fails to access, it can be done by configuring a corresponding second response message, which includes a response header, a response body, and a response code. It should be noted that the difference between the first response message and the second response message is that the first response message is used to inform the terminal device that the access request has been responded to, so that the terminal device does not need to perceive that the access request has been intercepted; the second response message is used to inform the terminal device that the access request has failed to be accessed by the data authentication server and the access request needs to be retransmitted.
[0060] For example, Figure 5 shows an optional schematic diagram of the data authentication rules provided by this application. As shown in Figure 5, in the data authentication rule corresponding to the rule identity (ID) "11111", the authentication address is set to "http: / / gaap-filter.abc.com.cn", the default failure status corresponds to a response code of 500, and the corresponding default failure response message is "c2VydmV...". In addition, in this data authentication rule, the first status code when interception is required is response code 401, and the second status code when interception is not required is response code 200, etc.
[0061] The data authentication rule can be used to obtain specific information about the access request, such as forwarding rules, etc. Exemplarily, the access device may also store the data authentication rule.
[0062] After detecting that the access request has a corresponding data authentication rule, the access device can send an access request to the data authentication server.
[0063] In other words, whether the access request has a corresponding data authentication rule can accurately identify whether the data (e.g., the first data) carried in the access request has the possibility of being intercepted. When the access request has a corresponding data authentication rule, the access device knows that the first data carried in the access request may contain data that should not be transmitted to the target server and needs to be authenticated. When the access request does not have a corresponding data authentication rule, the access device knows that all the first data carried in the access request can be transmitted to the target server, and there is no need to authenticate the data in the access request through the data authentication server.
[0064] 303. The data authentication server searches for configuration information based on the user identifier and the mapping relationship in the access request.
[0065] In this example, after the access device sends an access request to the data authentication server, the data authentication server is able to obtain the access request. Upon receiving the access request, the data authentication server processes it and extracts the user identifier and first data contained in the access request. By comparing the user identifier with a known mapping relationship, the data authentication server is able to determine the configuration information related to the user identifier. Therefore, after obtaining the user identifier, the data authentication server can also search for the corresponding configuration information based on the user identifier and the mapping relationship.
[0066] It should be noted that the configuration information described here can be understood with reference to the configuration information described in the aforementioned step 301, and will not be described in detail here.
[0067] 304. The data authentication server performs authentication processing on the first data based on the configuration information to obtain an authentication result.
[0068] In this example, after finding the configuration information, the data authentication server also needs to perform authentication processing on the first data based on the configuration information to obtain an authentication result. Through the authentication result, it is possible to understand the processing strategy for the first data, such as interception processing or transmission processing. The described transmission processing can be understood as the access device continuing to transmit the first data to the target server. The described interception processing can be understood as the access device intercepting the first data, and the access device will not forward the first data to the target server, thereby preventing the first data from being transmitted to the target server.
[0069] Exemplarily, how the data authentication server performs authentication processing on the first data can be understood in the following manner, namely: the data authentication server first determines the configuration status of the configuration information, and the configuration status includes a first setting status and a second setting status. For example, the data authentication server can search for option settings related to the type of the first data in the configuration information. For example, if it is "checked", it means that the configuration status corresponding to the type of the first data is the second setting status; conversely, if it is "unchecked", it means that the configuration status corresponding to the type of the first data is the first setting status. It should be noted that the first setting status and the second setting status described here can be understood with reference to the content described in the aforementioned step 301, and will not be elaborated here. After determining the configuration status corresponding to the type of the first data from the configuration information, the data authentication server performs authentication processing on the first data based on the configuration status, thereby obtaining an authentication result.
[0070] For example, the data authentication server can determine that the authentication result for the first data is a first status code when the configuration state is the first setting state. The described first status code is used to represent the response code when the first data needs to be intercepted, such as but not limited to the response code 401 in the HTTP protocol. In some optional examples, after determining that the authentication result for the first data includes the first status code, the data authentication server can also add the first response information corresponding to the first status code to the authentication result, thereby enabling the first response information corresponding to the first status code to be sent to the access device in the subsequent process of sending the authentication result to the access device. After the described first response information is forwarded to the terminal device by the access device, the terminal device can be informed that the access request has been responded to.
[0071] For example, Figure 6 shows an optional schematic diagram provided by this application when data interception is required. As shown in Figure 6, for the access request "X-GAAP-Request-Host:abcd.cn; X-GAAP-Request-Uri: / test / post_request_auth_failed_with_json_response", the data authentication server can determine that the authentication result includes a first status code, such as "HTTP / 1.1 401 Unauthorized". Accordingly, the corresponding first response information is "X-GAAP-Filter-Auth-Http-Status-code:200; X-GAAP-Filter-Auth-Http-Content-type:application / json; X-GAAP-Filter-Auth-Http-X-abc-Environment:test; X-GAAP-Filter-Auth-Http-Body:eyJjb2Rlljox...".
[0072] Alternatively, the data authentication server may determine, based on the data authentication rules, that the authentication result is a second status code when the configuration state is determined to be the second setting state. The second status code is used to indicate a response code when interception of the first data is not required, including, for example, but not limited to, the aforementioned response code 200.
[0073] 305. The data authentication server sends the authentication result to the access device.
[0074] In this example, after determining the authentication result, the data authentication server may send the authentication result to the access device.
[0075] 306. The access device intercepts or transmits the first data based on the authentication result.
[0076] In this example, after the data authentication server sends the authentication result to the access device, the access device can obtain the authentication result. In this way, the access device can intercept or transmit the first data based on the authentication result. For example, since the authentication result includes a first status code or a second status code, and the first status code can indicate that the first data needs to be intercepted, the second status code indicates that the first data does not need to be intercepted. Therefore, after obtaining the authentication result, the access device decides whether to intercept or transmit the first data by judging whether the authentication result is the first status code or the second status code. For specific understanding, please refer to the contents of the following situation ① and situation ②, that is:
[0077] Case ①: The authentication result includes the first status code
[0078] Exemplarily, when the access device determines that the authentication result includes a first status code, it intercepts the first data based on the first status code. The interception processing includes not forwarding the first data, for example, forwarding it to a subsequent forwarding device in the link to avoid forwarding the first data to the target server through the subsequent forwarding device.
[0079] Optionally, when the authentication result includes a first status code, the authentication result also includes first response information corresponding to the first status code. After the data authentication server sends the authentication result to the access device, the access device may further extract the first response information from the authentication result, and after intercepting the first data based on the first status code, send the first response information to the terminal device. This first response information notifies the terminal device that the access request has been responded to, eliminating the need for the terminal device to be aware that the access request has been intercepted by the access device.
[0080] Case 2: The authentication result includes the second status code
[0081] For example, if the access device determines that the authentication result includes the second status code, it may transmit the first data to the target server via the cloud acceleration channel based on the second status code. For example, the access device may forward the first data to the forwarding device via the cloud acceleration channel, and the forwarding device may continue to send the first data to the target server.
[0082] Thus, by using different status codes to distinguish different authentication results, the access device can accurately determine whether to intercept the first data in the access request based on the status code, avoiding additional parsing and processing. Furthermore, when a specific response code is agreed upon, it is easier for the access device to identify the status code, improving response efficiency.
[0083] In this way, after receiving the first data sent by the access device, the target server responds to and processes the first data to obtain second data corresponding to the first data. In this way, the target server maps the second data into an access response message and sends the access response message to the access device via the forwarding device. As a result, the access device can also receive an access response message sent by the target server after transmitting the first data to the target server via the cloud acceleration channel based on the second status code, and send the access response message to the terminal device, so that the terminal device can obtain the second data corresponding to the first data.
[0084] In addition to being able to specifically intercept the data in the access request when the terminal device accesses the target server, the access device can also accurately forward the second data to the terminal device when the target server returns the second data after processing the access request, thereby improving the integrity of the system. In other optional examples, in addition to the above-mentioned situation ① or situation ②, if the data authentication server cannot be accessed normally due to equipment failure, network connection failure, etc., the access device still needs to feedback a response to the terminal device so that the terminal device can know that the access request has failed. In this case, the access device can also obtain the second response information after detecting the data authentication rule. The second response information can indicate the response when the access request to the data authentication server fails. After obtaining the second response information, the access device also needs to send the second response information to the terminal device so that the terminal device can retransmit the access request under the instruction of the second response information.
[0085] In other optional examples, if the access device detects no data authentication rules, then interception of the first data is unnecessary. In this case, the access device directly forwards the access request to the forwarding device, which then transmits the access request to the target server. The target server then responds to the access request and transmits the response to the terminal device via the forwarding device and the access device.
[0086] FIG7 shows another optional flow diagram of data processing provided by the present application. As shown in FIG7 , the flow includes at least the following steps:
[0087] 701. The terminal device sends an access request to the access device. The access request includes first data and a user identifier. There is a mapping relationship between the user identifier and configuration information. The configuration information is used to indicate whether different types of data are allowed to be transmitted to the target server.
[0088] 702. After detecting the existence of a data authentication rule, the access device forwards the access request to the data authentication server.
[0089] 703. The data authentication server searches for configuration information based on the user identifier and the mapping relationship in the access request.
[0090] 704. The data authentication server performs authentication processing on the first data based on the configuration information to obtain an authentication result.
[0091] 705. The data authentication server sends an authentication result to the access device, where the authentication result includes a first status code and first response information corresponding to the first status code.
[0092] It should be noted that the above-mentioned steps 701 to 705 can be understood with reference to the contents described in steps 301 to 305 in FIG. 3 , and are not described in detail here.
[0093] 706. The access device intercepts and processes the first data based on the first status code.
[0094] In this example, the first status code described can be understood with reference to the description of step 304 in FIG. 3 and is not further described here. After receiving the authentication result sent by the data authentication server, if the access device determines that the authentication result is the first status code, it can intercept the first data based on the first status code to prevent the first data from being forwarded to the target server through the cloud acceleration channel, thereby ensuring data security.
[0095] 707. The access device sends first response information to the terminal device.
[0096] In this example, since the first data has been intercepted by the access device, a response still needs to be fed back to the terminal device to ensure that the terminal device is unaware that the access request corresponding to the first data has been intercepted. For example, the data authentication server adds the first response information corresponding to the first status code to the authentication result and sends it to the access device. Thus, after receiving the authentication result, the access device intercepts and processes the first data according to the first status code and then feeds the first response information back to the terminal device.
[0097] FIG7 above mainly describes the implementation process of data interception from the perspective of an embodiment. The following will describe the process of not intercepting data from the perspective of an embodiment. FIG8 shows another optional flow diagram of data processing provided by this application. As shown in FIG8, the flow includes at least the following steps:
[0098] 801. A terminal device sends an access request to an access device. The access request includes first data and a user identifier. There is a mapping relationship between the user identifier and configuration information. The configuration information is used to indicate whether different types of data are allowed to be transmitted to a target server.
[0099] 802. After detecting the existence of a data authentication rule, the access device forwards the access request to a data authentication server.
[0100] 803. The data authentication server searches for configuration information based on the user identifier in the access request and the mapping relationship.
[0101] 804. The data authentication server performs authentication processing on the first data based on the configuration information to obtain an authentication result.
[0102] 805. The data authentication server sends an authentication result to the access device, where the authentication result includes a second status code.
[0103] It should be noted that the above-mentioned steps 801 to 805 can be understood with reference to the contents described in steps 301 to 305 in FIG. 3 , and are not described in detail here.
[0104] 806. The access device transmits the first data to the target server through the cloud acceleration channel based on the second status code.
[0105] In this example, the second status code described can be understood with reference to the content described in step 304 in Figure 3 above, and will not be described in detail here. After the access device receives the authentication result sent by the data authentication server, if it determines that the authentication result is the second status code, it can be determined that there is no need to intercept the first data. At this time, the access device can transmit the first data to the target server through the cloud acceleration channel. For example, the access device forwards the first data to the forwarding device, and then the forwarding device forwards the first data to the target server.
[0106] 807. The target server responds to the first data and obtains an access response message.
[0107] In this example, after receiving the first data sent by the access device, the target server processes the first data in response to obtain second data corresponding to the first data. In this way, the target server maps the second data into an access response message and sends the access response message to the access device via the forwarding device.
[0108] 808. The target server sends an access response message to the access device.
[0109] 809. The access device sends an access response message to the terminal device.
[0110] In this example, after determining the access response message, the target server may send the access response message to the access device via the forwarding device, so that the access device can then send the access message to the terminal device.
[0111] In an embodiment of the present application, before the access request, first data, etc. sent by the terminal device are sent to the target server, the access device first forwards the access request and data authentication rules to the data authentication server. Then, the authentication result fed back by the data authentication server after authenticating the configuration information is used to determine in advance whether to intercept the first data or continue to transmit the first data. In other words, the present application utilizes the access device and the data authentication server to implement the data interception function. Before the first data is transmitted to the target server, the access device can determine in advance whether to intercept the first data based on the authentication result fed back by the data authentication server. This eliminates the need to upgrade or modify the terminal device, thus avoiding data leakage and improving data security, and reducing the difficulty and cost of modification and upgrade.
[0112] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of method. It can be understood that in order to realize the above functions, the hardware structure and / or software modules corresponding to the execution of each function are included. Those skilled in the art should easily realize that, in combination with the modules and algorithm steps of each example described in the embodiment disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0113] The embodiment of the present application can divide the functional modules of the device according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. In actual implementation, there may be other division methods.
[0114] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program that has a predetermined function and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0115] The access device in the embodiment of the present application is described in detail below. Figure 9 is an optional schematic diagram of the functional modules of the access device provided in the embodiment of the present application. As shown in Figure 9, the access device may include a receiving unit 901, a sending unit 902, and a processing unit 903.
[0116] Among them, the receiving unit 901 is used to receive an access request sent by a terminal device, the access request includes first data and a user identifier, there is a mapping relationship between the user identifier and the configuration information, and the configuration information is used to indicate whether different types of data are allowed to be transmitted to the target server.
[0117] The sending unit 902 is used to forward the access request to the data authentication server after detecting the existence of the data authentication rule, so that the data authentication server finds the configuration information based on the user identifier and the mapping relationship, and then authenticates the first data based on the configuration information to obtain an authentication result.
[0118] The processing unit 903 is configured to, after receiving the authentication result sent by the data authentication server, perform interception processing or transmission processing on the first data based on the authentication result.
[0119] In some optional embodiments, the processing unit 903 is used to intercept the first data based on the first status code when the authentication result includes a first status code, so as not to send the first data to the target server, and the first status code is used to represent a response code when the first data needs to be intercepted.
[0120] In other optional implementations, the first status code is response code 401.
[0121] In other optional embodiments, the authentication result also includes first response information corresponding to the first status code; the sending unit 902 is also used to send the first response information to the terminal device after intercepting the first data based on the first status code, and the first response information is used for the terminal device to know that the access request has been responded to.
[0122] In other optional embodiments, the processing unit 903 is used to transmit the first data to the target server through the cloud acceleration channel based on the second status code when the authentication result includes a second status code, and the second status code is used to represent a response code when the first data does not need to be intercepted.
[0123] In some other optional implementations, the second status code is response code 200.
[0124] In other optional embodiments, receiving unit 901 is further configured to receive an access response message sent by the target server after transmitting the first data to the target server via the cloud acceleration channel based on the second status code, the access response message including the second data, the second data being data obtained by the target server in response to the first data. Sending unit 902 is configured to forward the access response message to the terminal device.
[0125] In other optional implementations, the receiving unit 901 is further configured to, after detecting the existence of the data authentication rule, obtain second response information, where the second response information indicates a response when accessing the data authentication server fails in response to the access request. The sending unit 902 is configured to send the second response information to the terminal device, where the second response information instructs the terminal device to retransmit the access request.
[0126] The access device in the embodiment of the present application is described above from the perspective of modular functional entities. The data authentication server in the embodiment of the present application is described below from the perspective of modular functional entities. Figure 10 is an optional schematic diagram of the functional modules of the data authentication server provided in the embodiment of the present application. As shown in Figure 10, the data authentication server may include a receiving module 1001, a processing module 1002, and a sending module 1003.
[0127] Among them, the receiving module 1001 is used to receive an access request sent by the access device, the access request includes first data and a user identifier, there is a mapping relationship between the user identifier and the configuration information, and the configuration information is used to indicate whether different types of data are allowed to be transmitted to the target server.
[0128] The processing module 1002 is configured to search for configuration information based on the user identifier and the mapping relationship in the access request. The processing module is configured to perform authentication processing on the first data based on the configuration information to obtain an authentication result.
[0129] The sending module 1003 is used to send the authentication result to the access device, and the authentication result is used by the access device to intercept or transmit the first data.
[0130] In some optional embodiments, the processing module 1002 is used to: determine the configuration status of the configuration information, for the first data type of the first data, the configuration status includes a first setting status or a second setting status, the first setting status is used to indicate that data of the first data type is not allowed to be transmitted to the target server, and the second setting status is used to indicate that data of the first data type is allowed to be transmitted to the target server; authenticate the first data based on the configuration status to obtain an authentication result.
[0131] In some other optional implementations, the processing module 1002 is used to determine that the authentication result is a first status code when the configuration state is the first setting state, and the first status code is used to represent a response code when the first data needs to be intercepted.
[0132] In other optional implementations, the authentication result also includes first response information corresponding to the first status code, so that the access device forwards the first response information to the terminal device, and the first response information is used by the terminal device to know that the access request has been responded to.
[0133] In some other optional implementations, the processing module 1002 is used to: when the configuration state is the second setting state, determine that the authentication result is a second status code, and the second status code is used to represent a response code when the first data does not need to be intercepted.
[0134] The access device and data authentication server in the embodiments of the present application are described above from the perspective of modular functional entities. The data processing device in the embodiments of the present application is described below from the perspective of hardware processing. Figure 11 is a schematic diagram of the structure of the data processing device provided in the embodiments of the present application. The data processing device may vary significantly due to different configurations or performance, including but not limited to the access device shown in Figure 9 and the data authentication server shown in Figure 10.
[0135] As shown in FIG11 , the data processing device 300 may vary significantly due to different configurations or performances, and may include one or more central processing units (CPUs) 322 (e.g., one or more processors) and memory 332, and one or more storage media 330 (e.g., one or more mass storage devices) for storing applications 342 or data 344. The memory 332 and storage medium 330 may be either short-term storage or persistent storage. The program stored in the storage medium 330 may include one or more modules (not shown), each of which may include a series of instruction operations on the data processing device. Furthermore, the CPU 322 may be configured to communicate with the storage medium 330 and execute a series of instruction operations in the storage medium 330 on the data processing device 300. For example, the CPU 322 is configured to execute the application 342 stored in the storage medium 330, thereby implementing the data processing method provided in the above-mentioned embodiment of the present application.
[0136] The data processing device 300 may further include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input and output interfaces 358, and / or one or more operating systems 341, such as Windows Server 2003 or Windows Server 2003R. TM, Mac OS X TM , Unix TM , Linux TM , FreeBSD TM etc.
[0137] Exemplarily, the central processing unit 322 in FIG. 11 may call the computer-executable instructions stored in the memory 332 to enable the data processing device to execute the methods in the method embodiments corresponding to FIG. 3 to FIG. 8 .
[0138] Specifically, the functions / implementation processes of the processing unit 903 in FIG. 9 and the processing module 1002 in FIG. 10 can be implemented by the central processing unit 322 in FIG. 11 calling computer-executable instructions stored in the memory 332. The functions / implementation processes of the receiving unit 901 and the sending unit 902 in FIG. 9 and the receiving module 1001 and the sending module 1003 in FIG. 10 can be implemented by the input / output interface 358 in FIG. 11.
[0139] The steps executed by the data processing device in the above embodiments may be based on the data processing device structure shown in FIG11 .
[0140] In addition, an embodiment of the present application further provides a storage medium, which is used to store a computer program, and the computer program is used to execute the method provided by the above embodiment.
[0141] An embodiment of the present application further provides a computer program product including a computer program, which, when executed on a computer, enables the computer to execute the method provided in the above embodiment.
[0142] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product.
[0143] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0144] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0145] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0146] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0147] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the relevant technology, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.
[0148] The computer program product includes one or more computer instructions. When the computer is loaded and executed on the computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The computer instruction can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instruction can be transmitted from a website, a computer, a server or a data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode to another website, a computer, a server or a data center. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server or a data center that includes one or more available media integrations. Available media can be magnetic media, (such as floppy disk, hard disk, tape), optical media (such as DVD) or semiconductor media (such as SSD)) etc.
[0149] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A data processing method, applied to an access device, comprising: Receiving an access request sent by a terminal device, the access request including first data and a user identifier, the user identifier being mapped to configuration information, the configuration information being used to indicate whether different types of data are allowed to be transmitted to a target server; After detecting that a corresponding data authentication rule exists for the access request, forwarding the access request to a data authentication server, so that the data authentication server finds the configuration information based on the user identifier and the mapping relationship, and then performs authentication processing on the first data based on the configuration information to obtain an authentication result; After receiving the authentication result sent by the data authentication server, interception processing or transmission processing is performed on the first data based on the authentication result.
2. The method according to claim 1, wherein intercepting or transmitting the first data based on the authentication result comprises: When the authentication result includes a first status code, the first data is intercepted based on the first status code so as not to send the first data to the target server. The first status code is used to represent a response code when the first data needs to be intercepted.
3. The method according to claim 2, wherein the first status code is response code 401.
4. The method according to any one of claims 2 to 3, wherein the authentication result further includes first response information corresponding to the first status code; after intercepting the first data based on the first status code, the method further includes: The first response information is sent to the terminal device, where the first response information is used for the terminal device to know that the access request has been responded to.
5. The method according to claim 1, wherein intercepting or transmitting the first data based on the authentication result comprises: When the authentication result includes a second status code, the first data is transmitted to the target server through the cloud acceleration channel based on the second status code, and the second status code is used to represent a response code when the first data does not need to be intercepted. The method according to claim 5 , wherein the second status code is a response code 200.
7. The method according to any one of claims 5 to 6, after transmitting the first data to the target server through the cloud acceleration channel based on the second status code, the method further comprises: receiving an access response message sent by the target server, where the access response message includes second data, where the second data is data obtained by the target server in response to the first data; The access response message is forwarded to the terminal device.
8. The method according to claim 1, after detecting that the access request has a corresponding data authentication rule, the method further comprises: Obtaining second response information, where the second response information is used to indicate a response when accessing the data authentication server to the access request fails; The second response information is sent to the terminal device, where the second response information is used to instruct the terminal device to retransmit the access request.
9. A data processing method, applied to a data authentication server, comprising: Receive an access request sent by an access device, the access request including first data and a user identifier, the user identifier being mapped to configuration information, the configuration information being used to indicate whether different types of data are allowed to be transmitted to a target server; searching for the configuration information based on the user identifier and the mapping relationship; Performing authentication processing on the first data based on the configuration information to obtain an authentication result; The authentication result is sent to the access device, where the authentication result is used to instruct the access device to intercept or transmit the first data.
10. The method according to claim 9, performing authentication processing on the first data based on the configuration information to obtain an authentication result, comprising: determining a configuration state of the configuration information, where, for a first data type of the first data, the configuration state includes a first setting state or a second setting state, the first setting state being used to indicate that data of the first data type is not allowed to be transmitted to the target server, and the second setting state being used to indicate that data of the first data type is allowed to be transmitted to the target server; Authentication processing is performed on the first data based on the configuration state to obtain an authentication result.
11. The method according to claim 10, wherein the performing authentication processing on the first data based on the configuration state to obtain an authentication result comprises: When the configuration state is the first setting state, the authentication result is determined to be a first status code, where the first status code is used to represent a response code when the first data needs to be intercepted.
12. According to the method according to claim 11, the authentication result also includes a first response information corresponding to the first status code, so that the access device forwards the first response information to the terminal device, and the first response information is used by the terminal device to know that the access request has been responded to.
13. The method according to claim 10, wherein the performing authentication processing on the first data based on the configuration state to obtain an authentication result comprises: When the configuration state is the second setting state, the authentication result is determined to be a second status code, where the second status code is used to represent a response code when there is no need to intercept the first data.
14. An access device comprising: a receiving unit, configured to receive an access request sent by a terminal device, the access request including first data and a user identifier, the user identifier being mapped to configuration information, the configuration information being used to indicate whether different types of data are allowed to be transmitted to a target server; a sending unit configured to, upon detecting that a corresponding data authentication rule exists for the access request, forward the access request to a data authentication server, so that the data authentication server finds the configuration information based on the user identifier and the mapping relationship, and then performs authentication processing on the first data based on the configuration information to obtain an authentication result; A processing unit is configured to, after receiving the authentication result sent by the data authentication server, intercept or transmit the first data based on the authentication result.
15. A data authentication server comprising: a receiving module, configured to receive an access request sent by an access device, the access request including first data and a user identifier, the user identifier being mapped to configuration information, the configuration information being used to indicate whether different types of data are allowed to be transmitted to a target server; A processing module, configured to search for the configuration information based on the user identifier and the mapping relationship; The processing module is configured to perform authentication processing on the first data based on the configuration information to obtain an authentication result; A sending module is used to send the authentication result to the access device, and the authentication result is used by the access device to intercept or transmit the first data.
16. A data processing device comprising: an input / output interface, a processor, and a memory, wherein the memory stores a computer program; The processor is configured to execute the computer program stored in the memory, and execute the method according to any one of claims 1 to 8; or execute the method according to any one of claims 9 to 13.
17. A computer-readable storage medium comprising a computer program, which, when executed on a computer device, causes the computer device to execute the method according to any one of claims 1 to 8; or execute the method according to any one of claims 9 to 13.
18. A computer program product, comprising a computer program, which, when executed on a computer device, causes the computer device to execute the method according to any one of claims 1 to 8; or execute the method according to any one of claims 9 to 13.
Citation Information
Patent Citations
Implementation method and server of home gateway service function
CN103650424A
Data packet processing method and device, network device and readable memory medium
CN107733908A
Data accelerated transmission method and device, computer equipment and storage medium
CN113507393A
Data processing method and device and smart home gateway
CN114928458A
Access control method and apparatus of non-independent private network, and storage medium
WO2023109337A1