You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service上使用MIP SDK 1.17.158解密PDF文件速度极慢的问题求助

Azure App Service上使用MIP SDK 1.17.158解密PDF文件速度极慢的问题求助

大家好,我最近碰到一个非常棘手的性能问题,想请教下有没有遇到过类似情况的朋友:

我们的服务基于.NET搭建,使用MIP SDK 1.17.158处理受保护文件,流程是接收Angular客户端上传的文件,通过On-behalf-of委托用户权限判断文件是否受保护,解密后用字节流做后续业务处理。支持的文件类型包括.pdf、.xlsx、.docx、.pptx,最大支持100MB文件。

问题现象

  • 本地Visual Studio运行时,解密38MB的PDF文件仅需3秒;
  • 部署到Azure App Service后,同样的38MB PDF解密耗时居然在2到14分钟浮动(最近一次测试耗时822710毫秒);
  • 对比之下,5MB的.docx文件不管是本地还是部署后,解密都只需要200ms左右,完全正常。

出问题的核心代码行是:

await File.ReadAllBytesAsync(await handler.GetDecryptedTemporaryFileAsync());

相关配置代码

Startup.cs/Program.cs 服务注册

services.AddSingleton<ApplicationInfo>(x => {
    ApplicationInfo appInfo = new() {
        ApplicationId = ClientId,
        ApplicationName = "MyApplication",
        ApplicationVersion = "1.0.0"
    };
    return appInfo;
});

MIP.Initialize(MipComponent.File);

services.AddSingleton<MipContext>(x => {
    ApplicationInfo appInfo = x.GetRequiredService<ApplicationInfo>();
    return MIP.CreateMipContext(new(appInfo, "mip_data", Microsoft.InformationProtection.LogLevel.Trace, false, CacheStorageType.InMemory));
});

services.AddSingleton<IFileProfile>(x => {
    MipContext mipContext = x.GetRequiredService<MipContext>();
    FileProfileSettings profileSettings = new(mipContext, CacheStorageType.OnDisk, new ConsentDelegateImplementation());
    return Task.Run(async () => await MIP.LoadFileProfileAsync(profileSettings)).Result;
});

services.AddScoped<AuthDelegateUserImplementation>(x => {
    IHttpContextAccessor httpContextAccessor = x.GetService<IHttpContextAccessor>();
    ApplicationInfo appInfo = x.GetRequiredService<ApplicationInfo>();
    string secret = Configuration.GetValue<string>("MICROSOFT_PROVIDER_AUTHENTICATION_SECRET"); //Deployed version
    return new(appInfo, httpContextAccessor, secret);
});

services.AddScoped<IFileEngine>(x => //IDisposable
{
    IHttpContextAccessor httpContextAccessor = x.GetService<IHttpContextAccessor>();
    IFileProfile fileProfile = x.GetRequiredService<IFileProfile>();
    
    // Ensure the name is unique and set
    string email = httpContextAccessor.HttpContext?.User?.Identity?.Name;
    string engineName = $"{email}_{Guid.NewGuid().ToString("N")}";
    Identity id = new(email, engineName);
    
    TelemetryClient logger = x.GetRequiredService<TelemetryClient>();
    AuthDelegateUserImplementation AuthDelegate = x.GetRequiredService<AuthDelegateUserImplementation>();
    
    FileEngineSettings engineSettings = new(engineName, AuthDelegate, string.Empty, "en-US") {
        Identity = id,
        DelegatedUserEmail = email,
        LoggerContext = logger
    };
    
    IFileEngine fileEngine = Task.Run(() => fileProfile.AddEngineAsync(engineSettings)).Result;
    return new FileEngineWithDelegate(fileProfile, fileEngine, AuthDelegate, id, logger);
});

services.AddScoped<MyClass>();

委托实现类

同意委托

class ConsentDelegateImplementation : IConsentDelegate {
    public Consent GetUserConsent(string url) {
        return Consent.Accept;
    }
}

认证委托(On-behalf-of流程)

public class AuthDelegateUserImplementation(ApplicationInfo appInfo, IHttpContextAccessor httpContextAccessor, string ApiSecret, TelemetryClient LoggingClient) : IAuthDelegate {
    private static readonly string tenant = "our tenant id";
    private string DocClientSecret { get; init; } = ApiSecret;
    private UserAssertion Assertion { get; init; } = httpContextAccessor?.HttpContext is null 
        ? null 
        : new UserAssertion(httpContextAccessor.HttpContext.GetTokenAsync("access_token").Result, "urn:ietf:params:oauth:grant-type:jwt-bearer");
    private ApplicationInfo AppInfo { get; init; } = appInfo;

    public string AcquireToken(Identity identity, string authority, string resource, string claims) {
        var authorityUri = new Uri(authority);
        authority = string.Format("https://{0}/{1}", authorityUri.Host, tenant);
        
        IConfidentialClientApplication ClientApp = ConfidentialClientApplicationBuilder.Create(AppInfo.ApplicationId)
            .WithAuthority(authority)
            .WithClientSecret(DocClientSecret)
            .Build();
            
        string[] scopes = [resource[resource.Length - 1].Equals('/') ? $"{resource}.default" : $"{resource}/.default"];
        string newAccessToken = ClientApp.AcquireTokenOnBehalfOf(scopes, Assertion)
            .ExecuteAsync()
            .ConfigureAwait(false)
            .GetAwaiter()
            .GetResult()
            .AccessToken;
            
        return newAccessToken;
    }
}

FileEngine包装类

public class FileEngineWithDelegate(IFileProfile fileProfile, IFileEngine innerEngine, IAuthDelegate authDelegate, Identity id, TelemetryClient LoggingClient) : IFileEngine, IDisposable {
    private readonly IFileEngine _innerEngine = innerEngine ?? throw new ArgumentNullException(nameof(innerEngine));
    // Hold strong reference to avoid GC
    private readonly IAuthDelegate _authDelegate = authDelegate;
    
    // 省略IFileEngine接口的其他实现方法
}

已排查方向

目前我已经确认:

  1. 相同的PDF文件本地解密完全正常,排除文件本身的问题;
  2. 其他文件类型(如docx)在Azure环境下性能正常,说明基础的MIP SDK集成和认证流程是通的;
  3. 日志开了Trace级别,但暂时没看到明显的错误或超时提示,主要就是解密PDF的步骤耗时异常长。

想请教下:

  • Azure App Service的环境(比如磁盘IO限制、内存、沙箱机制)会不会影响MIP SDK的PDF解密性能?
  • MIP SDK的缓存配置(当前MipContext用InMemory,FileProfile用OnDisk)是否在Azure环境下有优化空间?
  • 有没有可能是PDF的保护类型(比如特定的加密算法)导致部署后性能骤降?

希望有经验的朋友能给点思路,谢谢!

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.07 09:28:04