Data flow private network opening method and device, electronic equipment and storage medium

By acquiring and filtering network segment data through the data circulation service platform, and building private network channels using the network configuration center and data connectors, the problems of low connection efficiency and poor security of operator private network channels are solved. This achieves automated private network channel construction and resource isolation, and improves the flexibility and security of data transmission.

CN121333909APending Publication Date: 2026-01-13CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511391334.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In existing technologies, when connecting the local area networks of data suppliers and consumers through the operator's private network channel, there are problems such as low efficiency of offline communication and negotiation, inflexible static configuration, and low data flow efficiency and poor security due to the CE device's lack of support for IP conversion.

Method used

The system acquires candidate network segment data and transmission requirements through the data circulation business platform, determines target network segment data by applying network segment filtering rules, and builds private network channels through the network configuration center and data connectors, configuring virtual network ports and routing policies to achieve automated private network channel construction and resource isolation.

Benefits of technology

It improves the security, flexibility, and manageability of data transmission, solves the problems of low efficiency, error-proneness, and difficulty in expansion of traditional manual configuration, and enhances resource utilization and network resource reuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333909A_ABST
    Figure CN121333909A_ABST
Patent Text Reader

Abstract

The invention provides a data flow private network opening method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining first candidate network segment data uploaded by a first object in response to a data flow task, obtaining second candidate network segment data uploaded by a second object, and obtaining the data flow transmission demands of the first object and the second object; processing the first candidate network segment data and the second candidate network segment data based on a network segment screening rule to determine target network segment data; and sending the data to a network configuration center and a data connector for configuration based on the target network segment data and the data stream transmission demand. Through a technical chain of task driving, candidate network segment acquisition, intelligent screening and cooperative configuration, full-life-cycle automatic construction and resource isolation guarantee of a data circulation private network channel are realized, the problems that traditional manual configuration is low in efficiency, error-prone and difficult to expand are solved, and the security, flexibility and manageability of data transmission are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of transmission and bearer technology, and in particular to a method, apparatus, electronic device and storage medium for opening a dedicated data circulation network. Background Technology

[0002] In data circulation scenarios, besides using the internet for data transmission, data providers and consumers frequently utilize dedicated network channels from telecom operators for data delivery. This is commonly used for high-performance, high-reliability, and high-security data delivery. The virtual private network (VPN) transmission methods provided by telecom operators mainly include SRv6 / MPLS VPN leased lines, cloud interconnection, or SD-WAN. These methods, based on network virtual tunneling technology, connect the private networks of both data providers and consumers, achieving end-to-end peer-to-peer interconnection between their internal LAN segments. Simultaneously, different data delivery tasks can choose different tunnels for transmission, thus achieving isolated transmission. However, since different data delivery tasks use different dedicated network transmission channels, they often require different private network segments and mapping to different VPN tunnels; otherwise, network isolation is difficult to achieve. Summary of the Invention

[0003] This disclosure aims to at least partially address one of the technical problems in the related art.

[0004] Therefore, one objective of this disclosure is to propose a method for opening a dedicated data circulation network, which can be applied to a data circulation business platform.

[0005] The second objective of this disclosure is to propose a method for opening a dedicated data circulation network, which can be applied to a network configuration center.

[0006] The third objective of this disclosure is to propose a method for opening a dedicated data circulation network, which can be applied to a data circulation business platform.

[0007] The fourth objective of this disclosure is to provide an activation device for a dedicated data circulation network, which can be applied to a data circulation business platform.

[0008] The fifth objective of this disclosure is to provide an activation device for a dedicated data circulation network, which is applied to a network configuration center.

[0009] The sixth objective of this disclosure is to provide an activation device for a dedicated data circulation network, which can be applied to a data circulation business platform.

[0010] The seventh objective of this disclosure is to provide an electronic device.

[0011] The eighth objective of this disclosure is to provide a non-transitory computer-readable storage medium.

[0012] The ninth objective of this disclosure is to provide a computer program product.

[0013] To achieve the above objectives, the first aspect of this disclosure proposes a method for opening a dedicated data circulation network, applied to a data circulation service platform, comprising: responding to a data circulation task, acquiring first candidate network segment data uploaded by a first object, and acquiring second candidate network segment data uploaded by a second object, and acquiring data flow transmission requirements of the first object and the second object, wherein the first object is a data provider and the second object is a data receiver; processing the first candidate network segment data and the second candidate network segment data based on network segment filtering rules to determine target network segment data; and sending the target network segment data and the data flow transmission requirements to a network configuration center and a data connector for configuration, wherein the network configuration center is used to construct a dedicated network channel based on the target network segment data and the data flow transmission requirements, and the data connector is used to configure virtual network ports and routing policies based on the target network segment data and the data flow transmission requirements.

[0014] According to one embodiment of this disclosure, the process of processing the first candidate network segment data and the second candidate network segment data based on network segment filtering rules to determine target network segment data includes obtaining first occupied network segment data of the first object in the first candidate network segment data, and obtaining second occupied network segment data of the second object in the second candidate network segment data; determining unoccupied first target network segment data from the first candidate network segment data based on the first occupied network segment data and the second occupied network segment data, and determining unoccupied second target network segment data from the second candidate network segment data based on the first occupied network segment data and the second occupied network segment data; and determining the target network segment data based on the first target network segment data and the second target network segment data.

[0015] According to one embodiment of this disclosure, determining the target network segment data based on the first target network segment data and the second target network segment data includes: selecting a first target network segment from the first target network segment data, and selecting a second target network segment from the second target network segment data, and using the first target network segment and the second target network segment as the target network segment data, wherein the first target network segment and the second target network segment are different network segments.

[0016] According to one embodiment of this disclosure, the method further includes: in response to the end of the data circulation task, sending a first cancellation instruction to the network configuration center, the first cancellation instruction being used to instruct the network configuration center to cancel the private network channel; and sending a second cancellation instruction to the data connector, the second cancellation instruction being used to instruct the data connector to cancel the virtual network interface and the routing policy.

[0017] According to one embodiment of this disclosure, the method further includes: after the network configuration center cancels the private network channel, changing the status of the first target network segment and the second network segment to an idle state, and releasing the network resources of the first target network segment and the second network segment.

[0018] To achieve the above objectives, a second aspect of this disclosure proposes a method for opening a dedicated data circulation network, applied to a network configuration center, comprising: acquiring target network segment data and data flow transmission requirements sent by a data circulation service platform, wherein the target network segment data is generated by the data circulation service platform based on a data circulation task initiated by a first object and a second object; and establishing a dedicated network channel between the first object and the second object based on the target network segment data and the data flow transmission requirements.

[0019] According to one embodiment of this disclosure, the method further includes configuring the bandwidth, quality of service, and routing mechanism of the private network channel based on the target network segment data and the data stream transmission requirements.

[0020] According to one embodiment of this disclosure, the method further includes: obtaining a first cancellation instruction sent by the data circulation service platform, wherein the first cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; and canceling the private network channel based on the first cancellation instruction.

[0021] To achieve the above objectives, a third aspect of this disclosure proposes a method for opening a dedicated data circulation network, applied to a data connector, comprising: acquiring target network segment data and data flow transmission requirements sent by a data circulation service platform, wherein the target network segment data is generated by the data circulation service platform based on a data circulation task initiated by a first object and a second object; and configuring a virtual network interface and routing policy based on the target network segment data and the data flow transmission requirements.

[0022] According to one embodiment of this disclosure, the method further includes: obtaining a second cancellation instruction sent by the data circulation service platform, wherein the second cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; and canceling the virtual network interface and the routing policy based on the second cancellation instruction.

[0023] To achieve the above objectives, a fourth aspect of this disclosure provides an apparatus for opening a dedicated data circulation network, applied to a data circulation service platform, comprising: an acquisition module, configured to, in response to a data circulation task, acquire first candidate network segment data uploaded by a first object and second candidate network segment data uploaded by a second object, and acquire data flow transmission requirements of the first object and the second object, wherein the first object is a data provider and the second object is a data receiver; a processing module, configured to process the first candidate network segment data and the second candidate network segment data based on network segment filtering rules to determine target network segment data; and a sending module, configured to send the target network segment data and the data flow transmission requirements to a network configuration center and a data connector for configuration, wherein the network configuration center is configured to construct a dedicated network channel based on the target network segment data and the data flow transmission requirements, and the data connector is configured to configure virtual network ports and routing policies based on the target network segment data and the data flow transmission requirements.

[0024] To achieve the above objectives, a fifth aspect of this disclosure provides an apparatus for establishing a dedicated data circulation network, applied in a network configuration center, comprising: a first receiving module for receiving data from a data circulation service platform and data flow transmission requirements, wherein the target network segment data is generated by the data circulation service platform based on a data circulation task initiated by a first object and a second object; and an establishment module for establishing a dedicated network channel between the first object and the second object based on the target network segment data and the data flow transmission requirements.

[0025] To achieve the above objectives, a sixth aspect of this disclosure provides an activation device for a dedicated data circulation network, applied to a data connector, comprising: a second receiving module, configured to acquire target network segment data and data flow transmission requirements sent by a data circulation service platform, wherein the target network segment data is generated by the data circulation service platform based on a data circulation task initiated by a first object and a second object; and a configuration module, configured to configure virtual network ports and routing policies based on the target network segment data and the data flow transmission requirements.

[0026] To achieve the above objectives, a seventh aspect of this disclosure provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to implement the method for opening a dedicated data circulation network as described in the first, second, and third aspects of this disclosure.

[0027] To achieve the above objectives, an eighth aspect of this disclosure provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to implement the method for opening a data circulation private network as described in the first, second, and third aspects of this disclosure.

[0028] To achieve the above objectives, a ninth aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, is used to implement the method for opening a dedicated data circulation network as described in the first, second, and third aspects of this disclosure. Attached Figure Description

[0029] Figure 1 This is a schematic diagram of a method for opening a dedicated data circulation network according to one embodiment of the present disclosure, which is applied to a data circulation business platform;

[0030] Figure 2 This is an interactive diagram of a data circulation service platform, a network configuration center, and a data connector according to one embodiment of this disclosure;

[0031] Figure 3 This is a schematic diagram of another method for opening a data circulation private network according to one embodiment of this disclosure;

[0032] Figure 4 This is a schematic diagram of a method for opening a data circulation private network according to one embodiment of the present disclosure, which is applied to a network configuration center;

[0033] Figure 5 This is a schematic diagram of a method for opening a dedicated data circulation network according to one embodiment of the present disclosure, applied to a data connector;

[0034] Figure 6 This is a schematic diagram of a data circulation private network activation device according to one embodiment of the present disclosure, which is applied to a data circulation business platform;

[0035] Figure 7 This is a schematic diagram of a data circulation private network activation device according to one embodiment of the present disclosure, which is applied to a network configuration center;

[0036] Figure 8 This is a schematic diagram of an activation device for a private data circulation network according to one embodiment of the present disclosure, which is applied to a data connector;

[0037] Figure 9 This is a schematic diagram of an electronic device according to one embodiment of the present disclosure. Detailed Implementation

[0038] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.

[0039] The acquisition, storage, use, and processing of data in this disclosed technical solution all comply with the relevant provisions of relevant laws and regulations.

[0040] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.

[0041] In current technology, connecting the local area networks of data providers and consumers via a carrier's private network channel typically requires submitting the internal network segments to be connected by both parties (e.g., 10.xxx, 172.16.xx-172.31.xx, 192.168.xx, etc.) and connection bandwidth requirements. However, this existing technology has the following problems:

[0042] (1) Offline communication and manual adjustment of network segment configuration:

[0043] The data supply and demand parties are not well-known or have a stable relationship; they are usually different entities and cannot prepare and allocate network settings in advance. Each time data flows, neither party knows the configuration of the other's private network segment in advance, requiring offline communication and negotiation. If overlapping network segments occur, one party needs to make manual adjustments.

[0044] Since data circulation can happen at any time and frequent data transactions may occur over time, offline negotiation and manual adjustment each time will significantly reduce the efficiency of data circulation.

[0045] Meanwhile, users may have multiple parallel data transactions or have already connected to other private networks for their own business. The selection of user intranet segments needs to consider more possible conflicting and overlapping situations. Moreover, neither party can know the other's ongoing parallel data transactions or existing private network connections, making the negotiation and adjustment process more complicated.

[0046] (2) Static configuration of a globally unique network segment for each user

[0047] While private network configurations on each user's server and Customer Edge (CE) device are typically statically unique, this requires extensive upfront planning and unified configuration. It also necessitates consultation with users to ensure no conflict with their existing internal network segment plans. Furthermore, users cannot flexibly modify or add to these configurations, making it unsuitable for situations involving frequent and fluctuating user business operations. Additionally, these addresses need to be configured on the enterprise user's own equipment, and operators cannot detect and verify the uniqueness of the actual configured address segments, potentially leading to conflict issues.

[0048] (3) Convert to non-overlapping addresses on the CE device

[0049] While performing Internet Protocol (IP) translation on the user's CE (Customer Equipment) device (user-side router device) is feasible, not all user CE devices support this function. Furthermore, data flow protocols may require end-to-end message immutability, and the receiver may verify that the IP address of the received message conforms to the previous transaction protocol. If address translation occurs in the intermediate data link, it may lead to data delivery failure.

[0050] To address the aforementioned issues, this disclosure proposes a method for establishing a dedicated data circulation network, applicable to data circulation business platforms. Figure 1 This is a schematic diagram illustrating a method for opening a dedicated data circulation network according to one embodiment of this disclosure, as shown below. Figure 1 As shown, the method includes:

[0051] S101, in response to the data circulation task, obtain the first candidate network segment data uploaded by the first object and the second candidate network segment data uploaded by the second object, and obtain the data flow transmission requirements of the first object and the second object, wherein the first object is the data provider and the second object is the data receiver.

[0052] The data circulation private network activation method of this application embodiment can be applied to scenarios where multiple clients establish a data private network. The execution entity for activating the data circulation private network of this application embodiment can be the data circulation private network activation device of this application embodiment, which can be installed on an electronic device.

[0053] It should be noted that the data circulation business platform refers to a comprehensive service platform that integrates task management, network scheduling, security control, resource coordination, and compliance auditing for data element circulation scenarios. It is responsible for coordinating multiple entities such as data providers, data users, operators, and connectors to achieve automated, manageable, and controllable secure delivery of data from the "source" to the "end".

[0054] In this embodiment of the disclosure, the data circulation task is a task established by the user when initiating a new data delivery on the data circulation platform. Upon receiving the data circulation task, the data circulation service platform enters the network preparation phase.

[0055] It should be noted that the first candidate network segment data and the second candidate network segment data are lists of multiple private IP network segments that can be used for this private network communication for the first object and the second object, respectively.

[0056] The first and second candidate network segment data are pre-designed and can be pre-configured on the local CE device / data connector.

[0057] In one possible implementation, based on the potential parallelism requirements of data circulation, the data supply and demand parties pre-set the first candidate network segment data and the second candidate network segment data to be synchronized to the data connector, and then reported to the data circulation business platform through the data connector.

[0058] Data transmission requirements refer to a set of technical indicators regarding bandwidth, latency, security, Quality of Service (QoS), and availability for this data transmission, proposed by the data provider or user based on the business scenario, or automatically identified by the system based on the data type. The content included in data transmission requirements can be determined according to actual design needs or the current transmission scenario; no limitations are imposed here. For example, data transmission requirements may include the data shown in the table below:

[0059]

[0060]

[0061] S102, based on the network segment filtering rules, process the first candidate network segment data and the second candidate network segment data to determine the target network segment data.

[0062] In this embodiment of the disclosure, after obtaining the first candidate network segment data and the second candidate network segment data, not all network segments are available due to reasons such as network segment occupation, conflict, or failure. It is necessary to select and determine the target network segment data according to the network segment filtering rules.

[0063] It should be noted that the network segment filtering rules are preset conflict detection and matching strategies, used to filter out the network segments available for this data flow task from the first candidate network segment data and the second candidate network segment data.

[0064] It should be noted that there are various network segment filtering rules, and no restrictions are imposed here. The specific rules can be determined based on the actual data flow tasks or design requirements.

[0065] S103, based on the data and data flow transmission requirements of the target network segment, sends configuration information to the network configuration center and data connector. The network configuration center is used to build a private network channel based on the data and data flow transmission requirements of the target network segment, and the data connector is used to configure virtual network interfaces and routing policies based on the data and data flow transmission requirements of the target network segment.

[0066] It should be noted that the data connector is deployed at the boundary of the enterprise intranet of the data provider or data receiver, and is usually directly integrated with or attached to the CE device to create virtual interfaces according to platform instructions.

[0067] The network configuration center, deployed on the operator's side or platform side, is a network automation management system that serves as the "scheduling brain" of the private network channel. It is used to call upon the operator's network capabilities, create point-to-point VPN tunnels, and has functions such as setting bandwidth guarantees, priority queues, and low-latency forwarding.

[0068] For example, the interaction between the data circulation service platform, the network configuration center, and the data connector can be as follows: Figure 2 As shown.

[0069] In this embodiment, in response to a data circulation task, first candidate network segment data uploaded by a first object and second candidate network segment data uploaded by a second object are acquired, along with the data flow transmission requirements of the first and second objects. The first object is the data provider, and the second object is the data receiver. Then, the first and second candidate network segment data are processed based on network segment filtering rules to determine the target network segment data. Finally, the target network segment data and data flow transmission requirements are sent to the network configuration center and data connector for configuration. The network configuration center is used to construct a dedicated network channel based on the target network segment data and data flow transmission requirements, and the data connector is used to configure virtual network interfaces and routing policies based on the target network segment data and data flow transmission requirements. Thus, this disclosure, through a technical chain of "task-driven + candidate network segment acquisition + intelligent filtering + collaborative configuration," achieves automated construction and resource isolation protection throughout the entire lifecycle of the dedicated data circulation network channel. This solves the problems of low efficiency, error-proneness, and difficulty in expansion associated with traditional manual configuration, significantly improving the security, flexibility, and manageability of data transmission.

[0070] In this embodiment of the disclosure, in response to the end of the data circulation task, a first cancellation instruction is sent to the network configuration center, which is used to instruct the network configuration center to cancel the private network channel, and a second cancellation instruction is sent to the data connector, which is used to instruct the data connector to cancel the virtual network interface and routing policy.

[0071] Canceling private network channels allows for "on-demand creation and destruction" of these channels, improving resource utilization and reducing the waste of private network IP addresses, thus increasing the reuse rate of network resources.

[0072] Cancelling virtual network interfaces and routing policies can effectively prevent security risks caused by "residual configurations." For example, if old routes are not deleted, new task traffic may mistakenly enter closed channels; if virtual network interfaces are not deleted, they may be maliciously exploited.

[0073] It should be noted that after the network configuration center cancels the private network channel, it will change the status of the first target network segment and the second network segment to idle state and release the network resources of the first target network segment and the second network segment.

[0074] In the above embodiments, the first candidate network segment data and the second candidate network segment data are processed based on network segment filtering rules to determine the target network segment data. Furthermore, it can be achieved through... Figure 3 To further explain, the method includes:

[0075] S301, obtain the first occupied network segment data of the first object in the first candidate network segment data, and obtain the second occupied network segment data of the second object in the second candidate network segment data.

[0076] In this embodiment of the disclosure, in order to prevent routing confusion, it is first necessary to exclude the already occupied network segments, thereby eliminating conflicting combinations during the network segment matching stage, ensuring that the network segments used by new tasks are isolated from existing tasks, and guaranteeing the security and stability of multi-task parallel transmission.

[0077] S302, determine unoccupied first target network segment data from first candidate network segment data based on first occupied network segment data and second occupied network segment data, and determine unoccupied second target network segment data from second candidate network segment data based on first occupied network segment data and second occupied network segment data.

[0078] In this embodiment of the disclosure, based on the first occupied network segment data and the second occupied network segment data, conflict detection can be performed on each candidate network segment in the first candidate network segment data to exclude candidate network segments that overlap with the network segment used by either party's current data delivery task. The first target network segment data for this data circulation task can be selected from the remaining available network segments. Similarly, based on the first occupied network segment data and the second occupied network segment data, conflict detection can be performed on the second candidate network segment data to select the second target network segment data that does not conflict.

[0079] S303, determine the target network segment data based on the first target network segment data and the second target network segment data.

[0080] In this embodiment of the disclosure, a first target network segment can be selected from first target network segment data, and a second target network segment can be selected from second target network segment data. The first target network segment and the second target network segment are used as target network segment data, wherein the first target network segment and the second target network segment are different network segments.

[0081] In this embodiment, the system first acquires the first occupied network segment data of the first object from the first candidate network segment data, and acquires the second occupied network segment data of the second object from the second candidate network segment data. Then, based on the first and second occupied network segment data, it determines the first unoccupied target network segment data from the first candidate network segment data, and the second unoccupied target network segment data from the second candidate network segment data. Finally, it determines the target network segment data based on the first and second target network segment data. Thus, by filtering the target network segment data using network segment filtering rules, dynamic isolation of network resources under multi-task parallelism can be achieved, preventing cross-task network segment conflicts, improving system robustness, and enabling automated pre-decision making for end-to-end private network channels.

[0082] Figure 4 This is a schematic diagram illustrating a method for opening a dedicated data circulation network according to one embodiment of this disclosure, as shown below. Figure 4 As shown, applied to a network configuration center, this method includes:

[0083] S401, Obtain the target network segment data and data stream transmission requirements sent by the data circulation service platform. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object.

[0084] S402, establish a private network channel between the first object and the second object based on the data and data stream transmission requirements of the target network segment.

[0085] In this embodiment of the disclosure, the bandwidth, quality of service, and routing mechanism of the private network channel can be configured based on the data and data stream transmission requirements of the target network segment.

[0086] After the data circulation task is completed, the network configuration center can also obtain the first cancellation instruction sent by the data circulation service platform, and then cancel the private network channel based on the first cancellation instruction.

[0087] Figure 5 This is a schematic diagram illustrating a method for opening a dedicated data circulation network according to one embodiment of this disclosure, as shown below. Figure 5 As shown, applied to a data connector, the method includes:

[0088] S501, Obtain the target network segment data and data stream transmission requirements sent by the data circulation service platform. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object.

[0089] S502 configures virtual network interfaces and routing policies based on the data and data flow transmission requirements of the target network segment.

[0090] In this embodiment of the disclosure, after the data circulation task is completed, the data connector can also obtain a second cancellation instruction sent by the data circulation service platform, and then cancel the virtual network interface and routing policy based on the second cancellation instruction.

[0091] Corresponding to the data circulation private network activation methods provided in the above embodiments, one embodiment of this disclosure also provides a data circulation private network activation device, applied to a data circulation business platform. Since the data circulation private network activation device provided in this disclosure corresponds to the data circulation private network activation methods provided in the above embodiments, the implementation methods of the above data circulation private network activation methods are also applicable to the data circulation private network activation device provided in this disclosure, and will not be described in detail in the following embodiments.

[0092] Figure 6 This is a schematic diagram of a data circulation private network activation device according to one embodiment of the present disclosure, applied to a data circulation service platform, such as... Figure 6 As shown, the data circulation private network activation device 600 includes: an acquisition module 610, a processing module 620, and a sending module 630.

[0093] The acquisition module 610 is used to respond to the data circulation task, acquire the first candidate network segment data uploaded by the first object, acquire the second candidate network segment data uploaded by the second object, and acquire the data stream transmission requirements of the first object and the second object, wherein the first object is the data provider and the second object is the data receiver.

[0094] The processing module 620 is used to process the first candidate network segment data and the second candidate network segment data based on the network segment filtering rules to determine the target network segment data.

[0095] The sending module 630 is used to send the target network segment data and the data flow transmission requirements to the network configuration center and the data connector for configuration. The network configuration center is used to build a private network channel based on the target network segment data and the data flow transmission requirements. The data connector is used to configure virtual network ports and routing policies based on the target network segment data and the data flow transmission requirements.

[0096] In this embodiment of the disclosure, the processing module 620 is further configured to: obtain first occupied network segment data of a first object in the first candidate network segment data, and obtain second occupied network segment data of a second object in the second candidate network segment data; determine unoccupied first target network segment data from the first candidate network segment data based on the first occupied network segment data and the second occupied network segment data, and determine unoccupied second target network segment data from the second candidate network segment data based on the first occupied network segment data and the second occupied network segment data; and determine target network segment data based on the first target network segment data and the second target network segment data.

[0097] In this embodiment of the disclosure, the processing module 620 is further configured to: select a first target network segment from the first target network segment data, and select a second target network segment from the second target network segment data, and use the first target network segment and the second target network segment as target network segment data, wherein the first target network segment and the second target network segment are different network segments.

[0098] In this embodiment of the present disclosure, the apparatus is further configured to: in response to the completion of the data flow task, send a first cancellation instruction to the network configuration center, the cancellation instruction being used to instruct the network configuration center to cancel the private network channel; and send a second cancellation instruction to the data connector, the second cancellation instruction being used to instruct the data connector to cancel the virtual network interface and routing policy.

[0099] In this embodiment of the disclosure, the device is further configured to: after the network configuration center cancels the private network channel, change the status of the first target network segment and the second network segment to an idle state, and release the network resources of the first target network segment and the second network segment.

[0100] Corresponding to the data circulation private network activation methods provided in the above embodiments, one embodiment of this disclosure also provides a data circulation private network activation device, applied to a network configuration center. Since the data circulation private network activation device provided in this disclosure corresponds to the data circulation private network activation methods provided in the above embodiments, the implementation methods of the above data circulation private network activation methods are also applicable to the data circulation private network activation device provided in this disclosure, and will not be described in detail in the following embodiments.

[0101] Figure 7 This is a schematic diagram of a data circulation private network activation device according to one embodiment of the present disclosure, applied in a network configuration center, such as... Figure 7 As shown, the data circulation private network activation device 700 includes: a first receiving module 710 and an establishment module 720.

[0102] The first receiving module 710 is used as a receiving module to obtain the target network segment data and data stream transmission requirements sent by the data circulation service platform. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object.

[0103] Module 720 is established to create a private network channel between the first and second objects based on the data and data stream transmission requirements of the target network segment.

[0104] In this embodiment of the disclosure, the apparatus is also used to configure the bandwidth, quality of service, and routing mechanism of the private network channel based on the data and data stream transmission requirements of the target network segment.

[0105] In this embodiment of the present disclosure, the apparatus is further configured to: obtain a first cancellation instruction sent by the data circulation service platform, wherein the first cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; and cancel the private network channel based on the first cancellation instruction.

[0106] Corresponding to the data circulation private network activation methods provided in the above embodiments, one embodiment of this disclosure also provides a data circulation private network activation device applied to a data connector. Since the data circulation private network activation device provided in this disclosure corresponds to the data circulation private network activation methods provided in the above embodiments, the implementation methods of the above data circulation private network activation methods are also applicable to the data circulation private network activation device provided in this disclosure, and will not be described in detail in the following embodiments.

[0107] Figure 8 This is a schematic diagram of an activation device for a private data circulation network according to one embodiment of this disclosure, applied to a data connector, such as... Figure 8 As shown, the data circulation private network activation device 800 includes: a second receiving module 810 and a configuration module 820.

[0108] The second receiving module 810 is used to acquire the target network segment data and data stream transmission requirements sent by the data circulation service platform. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object.

[0109] Configuration module 820 is used to configure virtual network interfaces and routing policies based on the data and data flow transmission requirements of the target network segment.

[0110] In this embodiment of the disclosure, the apparatus is further configured to: obtain a second cancellation instruction sent by the data circulation service platform, the second cancellation instruction being generated by the data circulation service platform after the data circulation task is completed; and cancel the virtual network interface and routing policy based on the second cancellation instruction.

[0111] Therefore, this disclosure achieves automated construction and resource isolation protection of the entire lifecycle of the data circulation private network channel through a technical chain of "task-driven + candidate network segment collection + intelligent filtering + collaborative configuration". It solves the problems of low efficiency, error-proneness and difficulty in expansion of traditional manual configuration, and significantly improves the security, flexibility and manageability of data transmission.

[0112] To implement the above embodiments, this disclosure also proposes an electronic device 900. Figure 9 This is a schematic diagram of an electronic device according to one embodiment of the present disclosure, such as... Figure 9 As shown, the electronic device 900 includes: a processor 901 and a memory 902 communicatively connected to the processor. The memory 902 stores instructions executable by at least one processor. The instructions are executed by at least one processor 901 to achieve the functions described in this disclosure. Figures 1-5 The method for opening a dedicated data circulation network in this embodiment.

[0113] To implement the above embodiments, this disclosure also proposes a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to implement the present disclosure. Figures 1-5 The method for opening a dedicated data circulation network in this embodiment.

[0114] To implement the above embodiments, this disclosure also proposes a computer program product, including a computer program, which, when executed by a processor, implements the features of this disclosure. Figures 1-5 The method for opening a dedicated data circulation network in this embodiment.

[0115] It should be noted that personal information collected from users should be used for legitimate and reasonable purposes and should not be shared or sold outside of these legitimate uses. Furthermore, such collection / sharing should only be conducted after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign an agreement / authorization that includes authorization of relevant user information before the user uses the function. In addition, any necessary steps must be taken to protect and safeguard access to such personal information data and ensure that others with access to personal information data comply with their privacy policies and procedures.

[0116] This application is intended to provide an implementation scheme for users to selectively prevent the use or access to their personal information data. Specifically, this disclosure is intended to provide hardware and / or software to prevent or block access to such personal information data. Once personal information data is no longer needed, risks can be minimized by restricting data collection and deleting data. Furthermore, where applicable, such personal information is de-identified to protect user privacy.

[0117] In the foregoing descriptions of the embodiments, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0118] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0119] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0120] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that contains, stores, communicates, propagates, or transmits programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0121] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0122] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0123] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0124] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A method for opening a dedicated data circulation network, characterized in that, Applications to data circulation business platforms include: In response to the data circulation task, the system acquires the first candidate network segment data uploaded by the first object and the second candidate network segment data uploaded by the second object, and acquires the data flow transmission requirements of the first object and the second object, wherein the first object is the data provider and the second object is the data receiver. The first candidate network segment data and the second candidate network segment data are processed based on the network segment filtering rules to determine the target network segment data; Based on the target network segment data and the data flow transmission requirements, the data is sent to the network configuration center and the data connector for configuration. The network configuration center is used to build a private network channel based on the target network segment data and the data flow transmission requirements. The data connector is used to configure virtual network ports and routing policies based on the target network segment data and the data flow transmission requirements.

2. The method according to claim 1, characterized in that, The process of processing the first candidate network segment data and the second candidate network segment data based on network segment filtering rules to determine the target network segment data includes: Obtain the first occupied network segment data of the first object in the first candidate network segment data, and obtain the second occupied network segment data of the second object in the second candidate network segment data; Based on the first occupied network segment data and the second occupied network segment data, determine the first unoccupied target network segment data from the first candidate network segment data, and determine the second unoccupied target network segment data from the second candidate network segment data based on the first occupied network segment data and the second occupied network segment data; The target network segment data is determined based on the first target network segment data and the second target network segment data.

3. The method according to claim 2, characterized in that, The step of determining the target network segment data based on the first target network segment data and the second target network segment data includes: Select a first target network segment from the first target network segment data, and select a second target network segment from the second target network segment data, and use the first target network segment and the second target network segment as the target network segment data, wherein the first target network segment and the second target network segment are different network segments.

4. The method according to claim 3, characterized in that, The method further includes: In response to the completion of the data flow task, a first cancellation command is sent to the network configuration center, the first cancellation command instructing the network configuration center to cancel the private network channel; and... Send a second cancellation command to the data connector, the second cancellation command being used to instruct the data connector to cancel the virtual network interface and the routing policy.

5. The method according to claim 4, characterized in that, The method further includes: After canceling the private network channel, the network configuration center changes the status of the first target network segment and the second network segment to an idle state and releases the network resources of the first target network segment and the second network segment.

6. A method for opening a dedicated data circulation network, characterized in that, Applied to network configuration centers, including: The target network segment data and data stream transmission requirements sent by the data circulation service platform are obtained. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object. A private network channel is established between the first object and the second object based on the target network segment data and the data stream transmission requirements.

7. The method according to claim 6, characterized in that, The method further includes: The bandwidth, quality of service, and routing mechanism of the private network channel are configured based on the target network segment data and the data stream transmission requirements.

8. The method according to claim 6, characterized in that, The method further includes: Obtain a first cancellation instruction sent by the data circulation service platform, wherein the first cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; The private network channel is cancelled based on the first cancellation instruction.

9. A method for opening a dedicated data circulation network, characterized in that, Applications to data connectors include: The target network segment data and data stream transmission requirements sent by the data circulation service platform are obtained. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object. Configure virtual network interfaces and routing policies based on the target network segment data and the data flow transmission requirements.

10. The method according to claim 9, characterized in that, The method further includes: Obtain a second cancellation instruction sent by the data circulation service platform, wherein the second cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; The virtual network interface and the routing policy are cancelled based on the second cancellation command.

11. A device for activating a dedicated data circulation network, characterized in that, Applications to data circulation business platforms include: The acquisition module is used to respond to the data circulation task, acquire the first candidate network segment data uploaded by the first object, acquire the second candidate network segment data uploaded by the second object, and acquire the data stream transmission requirements of the first object and the second object, wherein the first object is the data provider and the second object is the data receiver; The processing module is used to process the first candidate network segment data and the second candidate network segment data based on the network segment filtering rules to determine the target network segment data; The sending module is used to send the target network segment data and the data flow transmission requirements to the network configuration center and the data connector for configuration. The network configuration center is used to build a private network channel based on the target network segment data and the data flow transmission requirements. The data connector is used to configure virtual network ports and routing policies based on the target network segment data and the data flow transmission requirements.

12. The apparatus according to claim 11, characterized in that, The processing module is further configured to: Obtain the first occupied network segment data of the first object in the first candidate network segment data, and obtain the second occupied network segment data of the second object in the second candidate network segment data; Based on the first occupied network segment data and the second occupied network segment data, determine the first unoccupied target network segment data from the first candidate network segment data, and determine the second unoccupied target network segment data from the second candidate network segment data based on the first occupied network segment data and the second occupied network segment data; The target network segment data is determined based on the first target network segment data and the second target network segment data.

13. The apparatus according to claim 12, characterized in that, The processing module is further configured to: Select a first target network segment from the first target network segment data, and select a second target network segment from the second target network segment data, and use the first target network segment and the second target network segment as the target network segment data, wherein the first target network segment and the second target network segment are different network segments.

14. The apparatus according to claim 13, characterized in that, The device is also used for: In response to the completion of the data flow task, a first cancellation command is sent to the network configuration center, the cancellation command instructing the network configuration center to cancel the private network channel; and... Send a second cancellation command to the data connector, the second cancellation command being used to instruct the data connector to cancel the virtual network interface and the routing policy.

15. The apparatus according to claim 14, characterized in that, The device is also used for: After canceling the private network channel, the network configuration center changes the status of the first target network segment and the second network segment to an idle state and releases the network resources of the first target network segment and the second network segment.

16. A device for activating a dedicated data circulation network, characterized in that, Applied to network configuration centers, including: The first receiving module is used to receive data from the data circulation service platform and to obtain the target network segment data and data stream transmission requirements sent by the data circulation service platform. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object. A module is established to create a private network channel between the first object and the second object based on the target network segment data and the data stream transmission requirements.

17. The apparatus according to claim 16, characterized in that, The device is also used for: The bandwidth, quality of service, and routing mechanism of the private network channel are configured based on the target network segment data and the data stream transmission requirements.

18. The apparatus according to claim 16, characterized in that, The device is also used for: Obtain a first cancellation instruction sent by the data circulation service platform, wherein the first cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; The private network channel is cancelled based on the first cancellation instruction.

19. A device for activating a dedicated data circulation network, characterized in that, Applications to data connectors include: The second receiving module is used to acquire target network segment data and data stream transmission requirements sent by the data circulation service platform. The target network segment data is generated by the data circulation service platform based on the data circulation task initiated by the first object and the second object. The configuration module is used to configure virtual network interfaces and routing policies based on the target network segment data and the data flow transmission requirements.

20. The apparatus according to claim 19, characterized in that, The device is also used for: Obtain a second cancellation instruction sent by the data circulation service platform, wherein the second cancellation instruction is generated by the data circulation service platform after the data circulation task is completed; The virtual network interface and the routing policy are cancelled based on the second cancellation command.

21. An electronic device, characterized in that, Including memory and processor; The processor reads executable program code stored in the memory to run a program corresponding to the executable program code, so as to implement the method as described in any one of claims 1-10.

22. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-10.