A method, apparatus, and system for establishing a network interface

By introducing network agents in the NFV MANO system, the network connection function of VNF network elements is divided into the agents, which solves the problems of complex and coupling of component deployment, and realizes independent component upgrades and improves system flexibility and efficiency.

CN113162785BActive Publication Date: 2025-05-27HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010076990.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-01-23
Publication Date
2025-05-27
Estimated Expiration
2040-01-23

AI Technical Summary

Technical Problem

In NFV MANO systems, the component deployment is complex, and the components are coupled greatly, and it cannot be upgraded independently, resulting in high resource consumption and difficult deployment.

Method used

By introducing a network proxy, the network connection function of the VNF network element is divided into the proxy, so that the VNF network element only performs business-related functions, thereby realizing independent upgrades of network connection functions and business functions. The specific method includes the first network agent receiving a connection request for the VNF network element, determining an attribute value of the network interface, and establishing a network interface through a forwarding plane to realize communication.

Benefits of technology

Reduces coupling and deployment complexity between components, allowing components to be upgraded independently, thereby improving system flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113162785B_ABST
    Figure CN113162785B_ABST
Patent Text Reader

Abstract

The present application discloses a method, apparatus, and system for establishing a network interface, which are used to solve the problems of complex component deployment, high coupling between components, and inability to be independently upgraded. By logically partitioning each function executed by the original VNF network element, the functions related to network connection originally executed by the VNF are deployed on the network proxy. In the VNF network element of the present application, only the functions related to the service need to be executed, and the functions related to network connection are executed by the network proxy. Thus, the functions related to the service and the functions related to network connection can be independently upgraded and developed. Furthermore, the coupling between components is reduced, and the deployment complexity is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communication technologies, and in particular, to a method, apparatus, and system for establishing a network interface. Background Art

[0002] Network Function Virtualization (NFV) provides a new way to design, deploy, and manage network services (NS). It decouples the implementation of some telecommunications network functions in general servers, switches, and memories, enabling fast and efficient deployment of NS. Since NFV requires a large amount of virtualization resources, it requires highly software management, which is called orchestration in the industry. Network Function Virtualization Management and Orchestrator (NFV MANO) is an architectural framework for managing and coordinating virtual network functions (VNF) and other software components.

[0003] Currently, the NFV MANO system adopts a centralized orchestration method. Users can orchestrate the network services they need according to their own requirements, and reference a series of VNF templates, virtual links (VL), and VNF Forwarding Graphs (VNFFG) during the orchestration process to form a standard-defined template. When deploying and distributing, the generated template is parsed to map and associate network service data and service resources, and the network function software involved is deployed to the network function virtualization infrastructure (NFVI) resource layer through standard interfaces. In the orchestration method adopted by NFV MANO, it emphasizes coordinating internal and external service interactions through an executable central process, and controlling the overall goals, operations, and service call sequences through the central process. Therefore, the NFV MANO orchestration system requires a large number of components, complex deployment, high resource consumption, large coupling between components, and cannot be independently upgraded. Summary of the Invention

[0004] The embodiments of the present application provide a method, apparatus, and system for establishing a network interface to solve the problems of complex component deployment, large coupling between components, and inability to be independently upgraded.

[0005] In a first aspect, an embodiment of the present application provides a method for establishing a network interface, including: a first network proxy receives a first connection request from a first virtualized network function (VNF) network element. The first network proxy is used to manage the first VNF network element, and the first VNF network element is a requester of a network service. The first connection request is used to request the establishment of a network interface, which is a network interface required to implement the network service. The first connection request carries requirement information of the network interface, and the requirement information of the network interface is used to describe the network interface required for the network service; the first network proxy sends a second connection request to a second network proxy. The second connection request carries the requirement information of the network interface; the second network proxy is used to manage a second VNF network element, and the second VNF network element is a provider of the network service; after receiving the second connection request, the second network proxy determines an attribute value of a first network interface according to the requirement information of the network interface carried in the second connection request. The first network interface is a network interface for the first VNF network element to perform network communication; then the second network proxy sends the attribute value of the first network interface to the first network proxy, and the first network proxy receives the attribute value of the first network interface sent by the second network proxy; after that, the first network proxy establishes the first network interface according to the attribute value of the first network interface, so that the first VNF network element can communicate through the first network interface.

[0006] Through the above solution, the various functions executed by the original VNF network element are logically divided, and the functions related to network connection originally executed by the VNF are deployed on the network proxy. The VNF network element in the embodiment of the present application only needs to execute the functions related to the service, so that the functions related to the service and the functions related to network connection can be independently upgraded and developed. Further, the coupling between components is reduced, and the deployment complexity is reduced.

[0007] In a possible design, the network proxy (the first network proxy and the second network proxy) and the VNF network element (the first VNF network element and the second VNF network element) are in the form of a container service. For example, the network proxy and the VNF network element can be deployed in the manner of a service mesh.

[0008] In a possible design, the requirement information of the network interface includes one or more of the following: the type of the network interface, the name of the network interface. With the above design, the VNF network element can request the network proxy to establish a network interface of a certain type according to the requirement, rather than in a static configuration manner, so that it can be adapted to different service scenarios.

[0009] In a possible design, the first connection request further carries an identifier defined by the network service; before the first network proxy sends a second connection request to the second network proxy, it further includes: the first network proxy queries, according to the identifier defined by the network service, from the configuration rule controller that the next-hop VNF element of the first VNF element in the network service is the second VNF element; wherein, the forwarding relationship information corresponding to the network service is included in the network service definition corresponding to the identifier defined by the network service. In the above design, the configuration rule controller is used to provide the forwarding relationship of the network service for the network proxy, and on-demand configuration can be realized.

[0010] In a possible design, the first network proxy adapts to at least one forwarding plane, and establishing the first network interface by the first network proxy according to the attribute value of the first network interface includes: the first network proxy calls the first forwarding plane in the at least one forwarding plane according to the attribute value of the first network interface to establish the first network interface. In the above design, by adapting to multiple forwarding planes, the network proxy can establish different types of network interfaces, provide different network services, and further adapt to different service scenarios.

[0011] Exemplarily, the at least one forwarding plane may include a forwarding plane based on flow table forwarding, a forwarding plane based on the forwarding model of traditional physical devices, and a forwarding plane based on physical network interfaces. For example, flow table forwarding can be implemented using a virtual switch based on openflow. For example, the forwarding of the forwarding model of traditional physical devices can be implemented based on DVR. Of course, it may also include forwarding planes implemented based on other technologies, which are not limited in the embodiments of the present application.

[0012] In a possible design, the first VNF element is deployed on a first node, and the second VNF element is deployed on a second node, and the method further includes: the first network proxy calls the forwarding plane to establish a first tunnel interface on the first node, and the first tunnel interface is used to connect to the second node.

[0013] In a possible design, the attribute value of the first network interface includes one or more of the following: the name of the first network interface, the type of the first network interface, and the IP address of the first network interface.

[0014] In a possible design, the first connection request further carries the network namespace identifier of the first VNF element; the method further includes: the first network proxy injects the established first network interface into the network namespace corresponding to the network namespace identifier.

[0015] In a possible design, it further includes: The first network agent receives a network service policy sent by a configuration rule controller, where the network service policy includes conditions for triggering network operations; The first network agent counts telemetry data according to the network service policy, and when determining that the conditions for triggering network operations are met based on the telemetry data, sends a first indication to the telemetry policy controller, where the first indication is used to indicate that the conditions for triggering network operations are met; When the first network agent receives a notification for executing the network operation sent by the telemetry policy controller, it executes the network operation.

[0016] In a second aspect, an embodiment of the present application provides a method for establishing a network interface, including: A second network agent receives a second connection request from a first network agent, where the second connection request carries requirement information for the network interface, and the second network agent is used to manage a second VNF element, and the second VNF element is a provider of network services; The first network agent is used to manage a first VNF element, and the first VNF element is a requester of network services, and the requirement information for the network interface is used to describe the network interface required to implement the network service; The second network agent determines the attribute value of the second network interface according to the requirement information for the network interface; The second network agent establishes the second network interface according to the attribute value of the second network interface, so that the second VNF element communicates through the second network interface.

[0017] Through the above solution, logical partitioning is performed according to each function executed by the original VNF element, and the relevant functions of network connection originally executed by the VNF are deployed on the network agent. The VNF element in the embodiment of the present application only needs to execute business-related functions, so that the business-related functions and the relevant functions of network connection can be independently upgraded and developed. Further, the coupling between components is reduced, and the deployment complexity is reduced.

[0018] In a possible design, it further includes: The second network agent determines the attribute value of the first network interface according to the requirement information for the network interface, and the first network interface is a network interface for the first VNF element to perform network communication; The second network agent sends the attribute value of the first network interface to the first network agent.

[0019] In a possible design, the second network agent adapts the forwarding plane, and the forwarding plane supports that the established network interface meets the network interface required by the network service. The second network agent establishes the second network interface according to the attribute value of the second network interface, including: The second network agent calls the forwarding plane to establish the second network interface according to the attribute value of the second network interface.

[0020] Exemplarily, at least one forwarding plane may include a forwarding plane based on flow table forwarding, a forwarding plane based on the forwarding model of traditional physical devices, and a forwarding plane based on physical network interfaces. For example, flow table forwarding can be implemented using a virtual switch based on OpenFlow. For example, the forwarding of the forwarding model of traditional physical devices can be implemented based on DVR. Of course, it may also include a forwarding plane implemented based on other technologies, which is not limited in the embodiments of the present application.

[0021] In a possible design, the first VNF network element is deployed on the first node, the second VNF network element is deployed on the second node, and the second connection request further carries the requirement information of the tunnel. The requirement information of the tunnel is used to describe the tunnel to be established between the first node and the second node. The method further includes: the second network agent calls the forwarding plane according to the requirement information of the tunnel to establish a second tunnel interface for the second node, and the second tunnel interface is used to connect the first node.

[0022] In a possible design, it further includes: the second network agent receives the service registration information sent by the second VNF network element, and the service registration information is used to describe the network interface capabilities that the second VNF network element can provide; the second network agent sends the service registration information to the configuration rule controller.

[0023] In the above design, the VNF network element as the network service provider reports the network interface capabilities it supports through the network agent, so that the configuration rule controller can select the VNF network element for providing network services according to the request of the network service initiator and the capabilities of the network service provider, realizing the adaptation to different scenarios according to requirements.

[0024] In a possible design, the service registration information includes one or more of the following: network protocol IP address allocation policy, IP address segment, supported network interface types.

[0025] In a possible design, the attribute values of the first network interface include one or more of the following: the name of the first network interface, the type of the first network interface, and the IP address of the first network interface.

[0026] In a possible design, the attribute value of the first network interface includes the IP address of the first network interface. The second network agent determines the attribute value of the first network interface according to the requirement information of the network interface, including: the second network agent sends the requirement information of the network interface to the second VNF network element; the second network agent receives the IP address of the first network interface sent by the second VNF network element.

[0027] In a possible design, the attribute values of the second network interface include one or more of the following: the name of the second network interface, the type of the second network interface, and the IP address of the second network interface.

[0028] In a possible design, the attribute value of the second network interface includes the IP address of the second network interface. The second network agent determines the attribute value of the second network interface according to the requirement information of the network interface, including: the second network agent sends the requirement information of the network interface to the second VNF network element; the second network agent receives the IP address of the second network interface sent by the second VNF network element.

[0029] In a possible design, the above method may further include: the second network agent configures the IP address of the second network interface for the second network interface.

[0030] In a possible design, the above method may further include: the second network agent receives the network service policy sent by the configuration rule controller, and the network service policy includes the conditions for triggering network operations; the second network agent counts the telemetry data according to the network service policy, and when it determines that the conditions for triggering network operations are met according to the telemetry data, it sends a second indication to the telemetry policy controller, and the second indication is used to indicate that the conditions for triggering network operations are met; when the second network agent receives the notification for performing network operations sent by the telemetry policy controller, it performs the network operations.

[0031] In a third aspect, an embodiment of the present application provides a method for establishing a network interface, including: a network agent receives a connection request sent by a VNF network element, the network agent is used to manage the VNF network element, the connection request is used to request to establish network interfaces for N network planes, and the connection request carries the identifier of each of the N network planes, where N is an integer greater than 1; the network agent queries the requirement information of the network interfaces corresponding to each of the N network planes from the configuration rule controller according to the identifiers of the N network planes; the requirement information of the network interface corresponding to each network plane is used to describe the network interfaces that need to be established for network connection using each network plane; the network agent establishes N network interfaces for the first VNF according to the requirement information of the network interfaces on each of the N network planes, and the N network interfaces correspond to the N network planes one by one.

[0032] Through the above solution, the network agent can establish network interfaces adapted to different network planes for the VNF network element according to requirements, adapt to various service scenarios, and improve flexibility.

[0033] Fourthly, an embodiment of the present application provides a method for establishing a network service connection, including: a network proxy receives network service definitions of N network planes from a configuration rule controller, where N is an integer greater than 1; among the network service definitions of the N network planes, the network service definition of each network plane includes requirement information of network interfaces of a first VNF network element on each network plane; the network proxy calls a forwarding plane to establish N network interfaces for the first VNF according to the network service definitions of the N network planes, and the N network interfaces correspond to the N network planes one by one.

[0034] Through the above solution, the network proxy can establish network interfaces adapting to different network planes for the VNF network element, adapt to multiple service scenarios, and improve flexibility.

[0035] In a possible design, the network service definition of each network plane among the network service definitions of the N network planes includes requirement information of network interfaces of a second VNF network element on each network plane, the first VNF is deployed on a first node, the second VNF is deployed on a second node, and the network service definitions of the N network planes further include requirement information of a tunnel between the first node and the second node; the method further includes: the network proxy calls a forwarding plane to establish N network interfaces for the second VNF according to the network service definitions of the N network planes; the network proxy calls a forwarding plane to establish tunnel interfaces for the first node and the second node respectively according to the requirement information of the tunnel.

[0036] Fifthly, an embodiment of the present application provides a device, and the device is used to execute the method described in the first aspect or any design of the first aspect, or is used to execute the method described in the second aspect or any design of the second aspect, or is used to execute the method described in the third aspect or any design of the third aspect, or is used to execute the method described in the fourth aspect.

[0037] Sixthly, an embodiment of the present application provides a device, including: a processor, the processor is coupled with a memory, and the memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the device is enabled to execute the method described in the first aspect or any design of the first aspect, or execute the method described in the second aspect or any design of the second aspect, or execute the method described in the third aspect or any design of the third aspect, or execute the method described in the fourth aspect.

[0038] In a seventh aspect, an embodiment of the present application provides a chip, including a memory and a processor. The memory is used to store a computer program, and the processor is used to call and run the computer program from the memory to execute the method described in the first aspect or any design of the first aspect, or execute the method described in the second aspect or any design of the second aspect, or execute the method described in the third aspect or any design of the third aspect, or execute the method described in the fourth aspect.

[0039] In an eighth aspect, an embodiment of the present application provides a system, including a first VNF network element, a first network agent for managing the first VNF network element, a second VNF network element, and a second network agent for managing the second VNF network element;

[0040] The first network agent is used to execute the method described in the first aspect or any design of the first aspect to establish a first network interface for the first VNF network element;

[0041] The first VNF network element is used to perform network communication with the second VNF network element through the first network interface;

[0042] The second network agent is used to execute the method described in the second aspect or any design of the second aspect to establish a second network interface for the second VNF network element;

[0043] The second VNF network element is used to perform network communication with the first VNF network element through the second network interface.

[0044] In a possible design, the system further includes a configuration rule controller. The configuration rule controller receives configurations from a network administrator, such as configuring network service definitions for network agents to query. Network service policies can also be configured for network agents (such as the first network agent and the second network agent). The first network agent receives the network service policy sent by the configuration rule controller, and the network service policy includes conditions for triggering network operations; the first network agent statistically analyzes telemetry data according to the network service policy, and when it determines that the conditions for triggering network operations are met based on the telemetry data, it sends a first indication to the telemetry policy controller, and the first indication is used to indicate that the conditions for triggering network operations are met; the telemetry policy controller triggers the execution of the network operation when receiving a notification for executing the network operation.

[0045] In a ninth aspect, the present application provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions are run on a computer, the computer is caused to execute the method described in the first aspect or any design of the first aspect, or execute the method described in the second aspect or any design of the second aspect, or execute the method described in the third aspect or any design of the third aspect, or execute the method described in the fourth aspect.

[0046] In a tenth aspect, the present application provides a computer program product, which includes computer program code. When the computer program code runs on a computer, it causes the computer to execute the method described in the first aspect or any design of the first aspect, or execute the method described in the second aspect or any design of the second aspect, or execute the method described in the third aspect or any design of the third aspect, or execute the method described in the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is an architecture diagram of an NFV MANO system;

[0048] Figure 2 It is an architecture diagram of an orchestration system in an embodiment of the present application;

[0049] Figure 3 It is a schematic diagram of VNF function splitting in an embodiment of the present application;

[0050] Figure 4 It is a schematic diagram of the method flow for establishing a network interface in an embodiment of the present application;

[0051] Figure 5 It is a schematic diagram of the structure of a network proxy in an embodiment of the present application;

[0052] Figure 6 It is a schematic diagram of the implementation of the control plane in an embodiment of the present application;

[0053] Figure 7 It is a schematic diagram of the scenario of a service chain in an embodiment of the present application;

[0054] Figure 8 It is a schematic diagram of system deployment in the scenario of a service chain in an embodiment of the present application;

[0055] Figure 9 It is a schematic diagram of the establishment process of a network interface in an embodiment of the present application;

[0056] Figure 10 It is a schematic diagram of the deployment of the forwarding plane implemented by an openflow vSwitch in an embodiment of the present application;

[0057] Figure 11 It is a schematic diagram of the deployment of the forwarding plane for a pure three-layer network connection implemented by a DVR in an embodiment of the present application;

[0058] Figure 12 It is a schematic diagram of multi-network plane deployment in an embodiment of the present application;

[0059] Figure 13Schematic diagram of the forwarding plane deployment for another OpenFlow vSwitch implementation in the embodiments of the present application;

[0060] Figure 14 Schematic diagram of the forwarding plane deployment for another pure Layer 3 network connection implementation of DVR in the embodiments of the present application;

[0061] Figure 15 Schematic diagram of the structure of the network proxy in the embodiments of the present application. Detailed implementation manners

[0062] Refer to Figure 1 , Figure 1 which is the architecture diagram of the NFV MANO system. As Figure 1 shown, NFV MANO has three main functional blocks, namely the NFV orchestrator, the VNF manager, and the virtualized infrastructure manager (VIM). Briefly speaking, the NFV orchestrator can orchestrate services and resources, can control new network services and integrate VNFs into the virtual architecture, and the NFV orchestrator can also verify and authorize resource requests for the NFV infrastructure. The VNF manager can manage the life cycle of VNFs. The VIM can control and manage the NFV infrastructure, including computing resources, storage resources, and network resources, etc. In order to make NFV MANO effective, it must be integrated with the application programming interface (API) in the existing system so as to use the technologies of multiple vendors across multiple network domains. Similarly, the operator's operation support system (OSS) and business support system (BSS) also need to interoperate with the NFV MANO system.

[0063] The network function virtualization orchestrator (NFVO) is used to implement the management and processing of network service descriptors (NSDs), virtual network function forwarding graphs (VNFFGs), the management of the life cycle of network services, and cooperate with the virtual network function manager (VNFM) to implement the management of the life cycle of virtual network functions (VNFs) and the global view function of virtual resources.

[0064] VNFM: Used to implement the management of the VNF lifecycle, including the management of VNF descriptors (VNFDs), the instantiation of VNFs, the elastic scaling of VNF instances (e.g., scaling out / up and / or scaling in / down), the healing of VNF instances, and the termination of VNF instances. VNFM also supports receiving scaling policies issued by the NFVO to implement automated elastic scaling of VNFs.

[0065] Virtualised Infrastructure Manager (VIM): Primarily responsible for the management (including reservation and allocation) of hardware resources and virtualised resources at the infrastructure layer, as well as the monitoring of virtual resource status and fault reporting, providing a virtualised resource pool to upper-layer applications.

[0066] Operations and Business Support Systems (OSS / BSS): Refers to the existing operation and maintenance systems of operators.

[0067] Element Manager (EM): Performs the functions of traditional fault, configuration, account, performance, and security management (FCAPS) for VNFs.

[0068] Virtualized Network Function (VNF): Corresponding to the Physical Network Function (PNF) in traditional non-virtualized networks. For example, nodes such as the Mobility Management Entity (MME), Service Gateway (SGW), and Packet Data Network Gateway (PGW) of the virtualized Evolved Packet Core (EPC). The functional behavior and state of network functions are independent of virtualization. The NFV technology requirements expect VNFs and PNFs to have the same functional behavior and external interfaces. Among them, a VNF can be composed of one or more VNF components (Virtual Network Function Component, VNFC) at a lower functional level. Therefore, a VNF can be deployed on multiple Virtual Machines (VMs), and each VM carries the function of a VNFC. A VNF can also be deployed on one VM.

[0069] NFV Infrastructure (NFVI): Composed of hardware resources, virtual resources, and a virtualization layer. From the perspective of VNFs, the virtualization layer and hardware resources appear as a complete entity that can provide the required virtual resources.

[0070] The orchestration method adopted by the NFV MANO system requires a large number of components, complex deployment, high resource consumption, and strong coupling between components, making it unable to be upgraded independently. Furthermore, the NFV MANO system is not very suitable for edge computing scenarios.

[0071] The applicant introduces the Service Mesh technology into the VNF orchestration system. Service Mesh is a dedicated infrastructure layer, a lightweight and high-performance network proxy. It provides secure, fast, and reliable communication between services, along with the actual application deployment, but is transparent to the application. Service Mesh can be considered as the TCP protocol in the era of microservices, so Service Mesh is widely used in Information Technical (IT) systems. However, VNF has many service governance-related contents different from IT applications. For example, in edge computing scenarios, VNF requires multiple network interfaces and supports multiple interface implementation types, and each interface has different quality attributes.

[0072] Based on this, an embodiment of the present application proposes a VNF orchestration system and method, which combines Service Mesh to establish a lightweight VNF orchestration solution. The VNF orchestration system proposed in the present application includes a data plane and a control plane. Refer to Figure 2 As shown, the data plane includes each VNF network element and is deployed in a distributed manner. The control plane can exist in a centralized manner and is used to implement service governance, such as service discovery, telemetry monitoring collection, network element health check, routing, and load balancing policy distribution.

[0073] Exemplarily, refer to Figure 2 As shown, the control plane can include a configuration rule controller, a telemetry policy controller, and a security controller. The configuration rule controller is the configuration center of the VNF network element and is used to send configuration data to the VNF network element. The telemetry policy controller is used to collect telemetry data sent by the VNF network element and perform policy control on the VNF network element, etc. The security controller is used for communication security control, such as including communication connection security, key management, file security, user authentication and authorization, etc.

[0074] Each function executed by the VNF network element can be divided into business logic, network protocol encoding and decoding, service registration and discovery, L2 / L3 layer network connection, and load balancing. In order for the business-related functions and network connection-related functions to be independently upgraded and developed, in the embodiment of the present application, the business-related functions and network connection-related functions in each VNF network element in the data plane are split and implemented through different service containers. Refer to Figure 2 and Figure 3As shown in the figure, each VNF network element in the data plane includes a VNF service and a network proxy. The VNF service is used to implement service-related functions, including service logic and network protocol encoding and decoding. The network proxy is used to implement functions related to network connections, including service registration and discovery, L2 / L3 layer network connections, and load balancing. The VNF service focuses on the service and is unaware of the network proxy. The network proxy focuses on the L2 / L3 layer basic network functions and ensuring the quality of service (QoS) of the service. The network proxy can operate in multiple environments, such as Kubernetes. Since different VNF network elements have different requirements for different services in terms of service forwarding. For example, some VNF network elements have low performance requirements for network interfaces, and ordinary kernel-mode interfaces can be used. For another example, some VNF network elements have high performance requirements for network interfaces and require physical network cards to pass through the user-mode protocol stack. Therefore, the network proxy provided in the embodiments of the present application can adapt to (or support) different network forwarding planes. Exemplarily, the forwarding plane can include one or more of a forwarding plane based on flow table forwarding, a forwarding plane based on the forwarding model of traditional physical devices, or a forwarding plane based on physical network interfaces. For example, flow table forwarding can be implemented using a virtual switch (vSwitch) based on OpenFlow. For example, the forwarding of the forwarding model of traditional physical devices can be implemented based on a distributed virtual router (DVR). For another example, the forwarding plane based on physical network interfaces can be implemented based on the allocation of physical network cards with Single Root I / O Virtualization (SR-IOV). Of course, it can also include a forwarding plane implemented based on other technologies, and the embodiments of the present application do not limit this.

[0075] Exemplarily, for example, the network proxy can support L2 layer network connections and / or L3 layer network connections. In the L2 layer network connection, it can adapt to (or support) a virtual switch based on OpenFlow and / or a software switch based on the forwarding model of traditional physical devices. In the L3 layer network connection, the network proxy supports the distributed virtual router (DVR) for pure L3 layer networks and / or the allocation of physical network cards with Single Root I / O Virtualization (SR-IOV). The network proxy can also be called a network manager, or it can have other names, and the present application does not limit this.

[0076] Taking two VNF network elements as an example, the establishment process of network interfaces in network services will be described below. The two VNF network elements can be divided into a requester of network services and a provider of network services according to their roles. In the embodiments of the present application, the requester of network services is denoted as NSC, and the provider of network services is denoted as NSE. When multiple network elements are connected in series, the VNF network element acts as both a requester of network services and a provider of network services. Refer to Figure 4 As shown, it is a schematic diagram of the process of network service connection.

[0077] After the VNF network element is established, the network administrator configures the network service definition and saves the network service definition in the configuration rule controller. For example, the network service definition may include one or more of the following: the forwarding relationship information corresponding to the network service (such as the source selector and destination selector of the network connection route), the type of forwarding plane, the type of network interface required for the network connection, and the payload type. The network service definition may also include network service policies. The network service policies may include one or more of an elastic scaling policy, a fusing rule, a traffic rule, etc. The elastic scaling policy is used to describe the rules for expanding or shrinking the VNF network element, and the elastic scaling policy includes an elastic expansion rule and / or an elastic contraction rule. The fusing rule is a rule used to describe the stop of neighbor establishment. The traffic rule is a rule used to count the traffic generated by the communication between the VNF network element and other VNF network elements.

[0078] As an example, in a scenario where multiple network planes need to be deployed, the network service definition may include the definition of multi-network plane network services and / or network service policies, etc. Among them, the definition of multi-network plane network services includes the network plane implementation type, payload type, and network definition. The network definition may include one or more of a network name, a subnet, an IP address, a gateway, and a virtual network identifier (vni).

[0079] When the NSE is started, it will register the network service with the configuration rule controller.

[0080] S401, the NSE initiates service registration information to the network proxy 2 (NSMgr2), and the service registration information is used to describe the network interface capabilities (NetworkServiceEndpoints) that the NSE can provide. For example, the service registration information may include one or more of an IP address allocation policy, an IP address segment, and the supported network interface types.

[0081] S402, the network proxy 2 sends the service registration information to the configuration rule controller. The configuration rule controller saves the relevant information of the NSE according to the received service registration information. For example, the relevant information of the NSE can be saved in the form of a service list, or in other forms, such as an array. Taking the form of saving in a service list as an example, the service list can include the relevant information of the NSE. The relevant information of the NSE can include the service registration information of the NSE, and can also include one or more of the NSMgr information to which the NSE belongs, the information of the node where the NSE is located, and the network element information of the NSE. The information of the node where the NSE is located can include one or more of the identifier of the node where the NSE is located, the network interface of the node where the NSE is located, etc. The network element information of the NSE can include the network element identifier of the NSE, etc.

[0082] In one example, the NSMgr information to which the NSE belongs, the information of the node where the NSE is located, and the network element information of the NSE can be carried in the service registration information and sent by the network proxy 2 to the configuration rule controller. In another example, the NSMgr information to which the NSE belongs and the information of the node where the NSE is located can be determined by the configuration rule controller according to the source of the service registration information. The network element information of the NSE can be carried in the service registration information and sent to the configuration rule controller.

[0083] S403, the NSC sends connection request 1 to network proxy 1 (NSMgr1). Connection request 1 can carry the requirement information of the NSC network service.

[0084] The requirement information of the NSC network service can include the requirement information of the network interface. The requirement information of the network interface can include the type of network interface required for the NSC network service, and can also include the network interface name of the NSC. When the requirement information of the network interface does not include the network interface name of the NSC, the network proxy can specify it for the NSC. The requirement information of the NSC network service can also include one or more of the identifier of the network service definition, the network namespace identifier corresponding to the NSC, the domain socket file identifier, and the labels. The identifier of the network service definition can be dynamically injected into the NSC during the deployment of the NSC.

[0085] Among them, the domain socket file corresponding to the domain socket file identifier is used to establish a call channel with the NSMgr ( Figure 4 NSMgr1 in the corresponding embodiment). The labels are used to locate and identify the VNF network element.

[0086] It should be noted that when the network service definition includes the network interface types required by the network service, the NSC network service requirement information may not include the network interface types required by the NSC network service. When the network service definition does not include the network interface types required by the network service, the NSC network service requirement information includes the network interface types required by the NSC network service.

[0087] When the NSC starts, it can initiate a connection request 1 to the NSMgr1 as needed through an init-container. The init-container can be automatically deleted by the container management platform after the network connection is established.

[0088] S404, after the network proxy 1 receives the connection request 1, it queries the VNF network elements passed by the network service from the configuration rule controller according to the NSC network service requirement information. Such as the firewall VNF and the gateway VNF.

[0089] Exemplarily, the network proxy 1 sends a query request to the configuration rule controller, and the query request can carry the NSC network service requirement information. The configuration rule controller queries the service list according to the NSC network service requirement information and determines that the next-hop VNF network element is the NSE, and the NSE is located on node2. Specifically, query the network service definition and parse the default destination selector corresponding to the network connection route to determine the first VNF network element to be connected (such as Firewall), and then query from the service list in the above configuration rule controller that the Firewall VNF is on the remote node2.

[0090] S405, the network proxy 1 on node1 sends a connection request 2 to the network proxy 2 on node2.

[0091] Among them, the connection request 2 may include the requirement information of the network interface.

[0092] Exemplarily, the connection request 2 may also carry the requirement information of the tunnel. The requirement information of the tunnel includes one or more of tunnel type information, tunnel establishment policy, and tunnel interface information, etc.

[0093] In one possible way, the requirement information of the tunnel can be included in the network service definition and sent to each network proxy by the configuration rule controller. In another possible way, the network proxy 1 can report the ability to establish a tunnel supported by itself to the configuration rule controller, so that the configuration rule controller determines the requirement information of the tunnel according to the ability to establish a tunnel supported by the network proxy 1 itself. In yet another possible way, the network proxy 1 can determine the tunnel requirement information according to the ability to establish a tunnel supported by itself.

[0094] Exemplarily, the tunnel type is a virtual extensible local area network (VXLAN). The tunnel type can also be other types such as generic routing encapsulation (GRE).

[0095] The tunnel type information includes identification information for identifying the virtual network to which the tunnel belongs. For example, the identification information for identifying the virtual network to which the tunnel belongs can be a virtual network identifier (VNID). The tunnel establishment policy can be configured as a forwarding policy based on a flow table for forwarding, a forwarding policy based on the forwarding model of a traditional physical device, or a forwarding policy based on a physical network interface according to the specific forwarding plane. The tunnel interface information can include the tunnel interface type, the tunnel interface name, the source IP address and the destination IP address of the tunnel interface (such as the IP address of a node), etc.

[0096] It should be understood that if the NSC and the NSE are located on the same node, the tunnel requirement information may not be carried in the connection request 2. If the NSC and the NSE are located on different nodes, it is necessary to establish a data transmission tunnel between different nodes, and the tunnel requirement information is carried in the connection request 2.

[0097] S406, the network proxy 2 determines the attribute value of the network interface according to the requirement information of the network interface.

[0098] Exemplarily, the network interface can include the network interface of the NSE and the network interface of the NSC.

[0099] The attribute value of the network interface can include one or more of the following:

[0100] 1) The network interface name. The name of the NSC network interface can be determined by the network proxy 2 according to the name of the NSC network interface carried in the connection request 2, or can be configured and sent to the network proxy 2 by the NSE. The name of the NSE network interface can be sent to the network proxy 2 by the NSE, or specified by the network proxy 2 for the NSE.

[0101] 2) The IP address of the network interface. The IP address allocation policy of the network interface can be sent down by the configuration rule controller or determined through negotiation between the network proxy 2 and the NSE. For example, if the NSE has the ability to allocate the IP address of the network interface, the NSE can be responsible for the allocation. Or if the NSE does not have the ability to allocate the IP address of the network interface, the network proxy 2 can perform the allocation. Or the NSE can specify that the network proxy 2 is to carry out the allocation, etc. Alternatively, the network proxy 2 can also determine who is to allocate the IP address of the network interface based on the payload type, that is, the IP address allocation policy of the network interface can be determined by the network proxy 2 based on the payload type to allocate the IP address of the network interface by the NSE or by the network proxy 2.

[0102] The IP address allocation policy of the network interface can also be to allocate IP addresses from a centralized IP address pool by the network proxy. The centralized IP address pool can be sent down to the network proxy by the configuration rule controller.

[0103] 3) The network interface type. The interface type can include a kernel-mode interface, a user-mode interface, and a physical interface.

[0104] Among them, the kernel-mode interface or the user-mode interface can be implemented through different interfaces, such as tap, KNI, dpdkvirtiouser, vhost-user, vhost-user-client, etc.

[0105] In one case, the type of the NSE network interface is consistent with the type of the network interface required in the network interface requirement information of the NSC. If the type of network interface supported by the NSE, and the quality of service required by this type of network interface is higher than the type of network interface required by the NSC, the type of the established network interface is the type of network interface supported by the NSE.

[0106] 4) The payload type. Generally, IP or Ethernet is selected. IP is used to indicate that a three-layer network connection needs to be established. Ethernet is used to indicate that a two-layer network connection needs to be established.

[0107] Exemplarily, if the payload type is Ethernet, indicating the establishment of an L2 layer network connection, the IP address of the network interface can be allocated by the NSE. If the payload type is IP, indicating the establishment of an L3 layer network connection, the network proxy 2 can allocate an IP address for the NSE from the centralized IP address pool.

[0108] S407, The network proxy 2 calls the forwarding plane to establish the NSE network interface and the node 2 (node2) tunnel interface. Configure the corresponding IP address for the established NSE network interface and configure the IP address for the node 2 tunnel interface. Exemplarily, the IP address of the node2 tunnel interface can be the IP address of node2. The network proxy 2 injects the established NSE network interface into the NSE network namespace.

[0109] S408, The network proxy 2 sends a connection response 2 to the network proxy 1, and the connection response 2 carries the attribute values of the NSC network interface. For example, it includes one or more of the IP address, the NSC network interface name, and the interface type.

[0110] S409, After receiving the connection response 2, the network proxy 1 calls the forwarding plane to establish the NSC network interface and the NSC tunnel interface, configure the IP address for the NSC network interface, and configure the tunnel interface IP address for the NSC tunnel interface. The network proxy 1 injects the established NSC network interface into the NSC network namespace.

[0111] S410, The network proxy 2 sends a connection response 1 to the NSC. The connection response 1 is used to notify that the network interface establishment is completed.

[0112] The network proxy can be multiple components. Exemplarily, see Figure 5 As shown, the network proxy can include a first communication module, a second communication module, a forwarding plane adaptation module, and a rule module. It should be noted that the functions of the following several components are briefly described below, and will be further described in combination with specific scenarios later.

[0113] The first communication module (Nsmd), which is the core component of the network connection, is responsible for initiating and receiving network service requests. Taking the network proxy 1 as an example, the nsmd in the network proxy 1 is used to receive the connection request 1 from the NSC and send the connection request 2 to the network proxy 2.

[0114] The second communication module (nsmd-k8s): responsible for communicating with the control plane, such as for network service registration and discovery. Taking the network proxy 2 as an example, the nsmd-k8s in the network proxy 2 is used to send the service registration information to the configuration rule controller.

[0115] The rule module (rule-agent): receives the configuration rules and configuration policies issued by the configuration rule controller and notifies the VNF network element.

[0116] Forwarding plane adaptation module (dataplane-agent): Responsible for adapting different forwarding planes. For example, the forwarding plane may include one or more of a forwarding plane based on flow table forwarding, a forwarding plane based on the forwarding model of traditional physical devices, or a forwarding plane based on physical network interfaces.

[0117] Exemplarily, the network agent may further include:

[0118] Interface monitoring module (crossconnect-monitor): Responsible for monitoring the network interface status of the NSC. If an abnormality is found in the NSC interface, all network interfaces of the corresponding network service are cleared, and a connection request is re-initiated.

[0119] Telemetry module (telemetry-agent): Responsible for collecting telemetry data of VNF network elements.

[0120] Communication plugin (Nsmdp): Responsible for establishing a remote procedure call (RPC) channel between the VNF network element and the network agent. Specifically, it can be used to start the gRPC server deployed in the VNF network element.

[0121] SR-IOV control module (sriov-controller): Responsible for the allocation of SR-IOV physical network cards.

[0122] The division of modules in the embodiments of this application is illustrative, only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of this application, each functional module may be integrated in one processor, or may exist separately physically, or two or more modules may be integrated in one module. The above integrated modules may be implemented in the form of hardware or in the form of software functional modules.

[0123] As an example, the configuration rule controller, telemetry policy controller, and security controller included in the control plane can be implemented through Figure 6 the logical architecture shown.

[0124] The network element configuration, rule information, security information, policy information, network service definition generated by the network administrator, and the network registration information sent by the VNF network element through the network proxy are all sent to the logical storage layer. The logical storage layer may include multiple storage plane monitoring processes. Different storage plane monitoring processes are used to monitor different storage information received by the logical storage layer, and respectively store the information for filtering and encapsulation, and then send it to the controller engine. The controller engine reserves different processing pipelines at different processing stages. Different processing pipelines can implement the behavior of the control plane through different plugins. The function of the controller engine is simply implemented, and the specific business logic is implemented in different plugins, so the resource occupancy of the control plane is very small. The controller engine sends the configuration information to the network proxy through the network interface (dispatch component).

[0125] The specific solution provided by this application will be described in detail below in combination with specific application scenarios.

[0126] In a possible scenario, in an edge cloud, a virtual private network (VPN) client needs to connect to the company's enterprise intranet, and multiple VNF network elements will be passed through. For example, see Figure 7 As shown, the VNF network elements passed through include the VNF network element for implementing the firewall function (referred to as the firewall VNF) and the VNF network element for implementing the VPN gateway function (VPN Gateway VNF). An L2 / L3 layer network connection and data transmission tunnel are established between the VPN client, the firewall VNF, and the VPN gateway.

[0127] The control plane can define network services according to customer needs and associate them with specified VNF network elements, so as to establish a service chain between VNF network elements. For example, the network administrator can configure the API document or description file for describing the network service definition to the control plane, and the API document or description file indicates the VNF network elements that the required network service needs to pass through. Figure 7 In the scenario shown, it passes through the firewall VNF and the VPN gateway VNF.

[0128] It should be understood that the VPN client, the firewall VNF, and the VPN gateway can also be deployed on the same node, or can be deployed on different nodes, or two VNF network elements can be deployed on one node and the other VNF network element can be deployed on another node. The embodiments of this application do not make specific limitations in this regard. Among them, Figure 8Taking the deployment of the Chinese VPN client and the firewall VNF on node 1 and the deployment of the VPN gateway on node 2 as an example for illustration. Different VNF network elements deployed on the same node can use the same network proxy to proxy the VNF network elements to implement the basic network functions and QoS. Figure 8 Taking the network proxy 1 (NSMgr1) for proxying the VPN client and the firewall VNF and the network proxy 2 (NSMgr2) for proxying the VPN gateway as an example.

[0129] The following Figure 8 and Figure 9 are used to illustrate the establishment process of the network interface of the network service.

[0130] S901, the VPN client sends a connection request 1 to NSMgr1, and the connection request 1 carries the requirement information of the VPN client network service.

[0131] The requirement information of the VPN client network service includes the requirement information of the network interface. The requirement information of the network service can also include the identifier defined by the network service, the network namespace identifier of the VPN client, etc.

[0132] The requirement information of the network interface includes the interface type required for the network service connection and the network interface name of the VPN client.

[0133] S902, after receiving the connection request 1, the network proxy 1 queries the VNF network elements required for the network service from the configuration rule controller according to the requirement information of the VPN client network service. Figure 8 In the corresponding scenario, the next-hop VNF network element for the network service connection is the firewall VNF, and the next-hop of the firewall VNF is the VPN gateway VNF.

[0134] Exemplarily, the network proxy 1 sends a first query request to the configuration rule controller, and the first query request can carry the requirement information of the VPN client network service. The configuration rule controller queries the service list according to the requirement information of the VPN client network service to determine that the next-hop VNF network element is the firewall VNF, and determines that the firewall VNF is located on node1 according to the service list.

[0135] S903, the network proxy 1 on node1 sends a connection request 2 to the firewall VNF.

[0136] S904, the firewall VNF sends a connection response 2 to the network proxy 1.

[0137] In one example, the connection response 2 can carry the name and type of the network interface that the firewall VNF needs to establish.

[0138] In another example, the connection response 2 may carry the types of network interfaces supported by the firewall VNF and the naming rules for the supported network interfaces. The network proxy 1 generates a network interface name for the firewall. The network proxy 2 determines the type of network interface to be established for the firewall VNF based on the interface type required for the network service connection and the types of network interfaces supported by the firewall VNF.

[0139] Figure 9 In the corresponding embodiment, the firewall VNF and the VPN client belong to the same network proxy. The network proxy 1 can determine the VNF network elements passed by the network service connection from the configuration rule controller at one time. Of course, it can also query the next-hop VNF network element from the configuration rule controller.

[0140] When the firewall VNF and the VPN client belong to different network proxies, when the network proxy to which the firewall VNF belongs receives the service response message of the firewall VNF, it can query the next-hop VNF network element from the configuration rule controller. It is also possible that only the network proxy of the NSC queries the VNF network elements passed by the network service connection, and then carries the identification information of the VNF network elements passed by the network service connection in the connection request and sends it to the network proxy of the next-hop VNF network element.

[0141] S905, the network proxy 1 sends a connection request 3 to the network proxy 2 of node2. The connection request 3 carries the requirement information of the network interface.

[0142] Exemplarily, the connection request 2 may also carry the requirement information of the tunnel. The requirement information of the tunnel includes tunnel type information, tunnel establishment policy, and tunnel interface information. For example, the tunnel type is VXLAN. The tunnel type information may include VNID. The tunnel establishment policy can be configured with a forwarding policy based on flow table forwarding, a forwarding policy based on the forwarding model of traditional physical devices, or a forwarding policy based on physical network interfaces according to the different specific forwarding planes. The tunnel interface information may include tunnel interface type, tunnel interface name, source IP address, and destination IP address of the tunnel interface.

[0143] S906, the network proxy 2 sends a connection request 4 to the VPN gateway VNF. The connection request 4 carries the requirement information of the network interface.

[0144] S907, the VPN gateway VNF sends a connection response 4 to the network proxy 2. The connection response 4 carries the attribute information for the network interface.

[0145] Among them, the attribute information of the network interface includes the IP address, name, and interface type of the VPN gateway VNF network interface, and also includes the IP address of the network interface assigned to the VPN client. Specifically, the VPN gateway VNF can determine the attribute information of the network interface for network service connection according to the demand information of the VPN client network service.

[0146] S908, the network proxy 2 calls the forwarding plane to establish the network interface of the VPN gateway VNF, and configures the IP address for the established VPN gateway VNF network interface. The network proxy 2 injects the established VPN gateway VNF network interface into the VPN gateway VNF network namespace. For the determination of the VPN gateway VNF network namespace, in one way, when the VPN gateway VNF reports its own capability information to the configuration rule controller through the network proxy 2, it is sent to the network proxy 2 together. In another way, the connection response 4 can carry the identifier of the VPN gateway VNF network namespace.

[0147] S909, the network proxy 2 calls the forwarding plane to establish the second tunnel interface on node 2, and configures the IP address for the second tunnel interface on node 2. The IP address of the tunnel interface on node 2 can be the IP address of node 2.

[0148] S910, the network proxy 2 sends the connection response 3 to the network proxy 1, and the connection response 3 carries the IP address, name, and interface type of the VPN client network interface.

[0149] S911, after receiving the connection response 3, the network proxy 1 calls the forwarding plane to establish the network interface on the firewall VNF for communicating with the VPN gateway VNF. The network proxy 1 injects the established network interface on the firewall VNF for communicating with the VPN gateway VNF into the firewall VNF network namespace.

[0150] S912, the network proxy 1 establishes the first tunnel interface on node 1 according to the demand information of the tunnel, and configures the IP address for the first tunnel interface on node 1. For example, the IP address of the tunnel interface on node 1 can be the IP address of node 1.

[0151] S913, Network Agent 1 calls the forwarding plane to establish a network interface on the firewall VNF for connecting to the VPN client. Network Agent 1 injects the established network interface on the firewall VNF for connecting to the VPN client into the firewall VNF network namespace.

[0152] S914, Network Agent 1 calls the forwarding plane to establish a VPN client network interface for the VPN client. Network Agent 1 injects the established VPN client network interface into the VPN client network namespace.

[0153] S915, Network Agent 1 sends Connection Response 1 to the NSC. Connection Response 1 is used to notify the NSC that the network service connection has been established.

[0154] In one example, take the vSwitch implemented by openflow in the forwarding plane as an example. The vSwitch can be regarded as a special VNF network element. Each node will have a vSwitch, which is the data path (or data tunnel) between VNF network elements and determines the forwarding path of the data flow between VNF network elements. The vSwitch supports L2 layer network connections. In one way, data interaction between VNF network elements and the vSwitch is carried out through an interface pair, where one interface is in the VNF network element and the other interface is on the vSwitch. In another way, the vSwitch and the VNF network element share a network interface, or rather, the vSwitch establishes a network interface for the VNF network element and injects the established network interface into the VNF network element. Data can be transmitted between different nodes through the VXLAN interface, or rather, network connections between different nodes are achieved through the VXLAN packet encapsulation technology. The vSwitch realizes network interconnection through a bridge and a kernel state interface (or user state interface).

[0155] See Figure 10 as shown, the VPN client passes through Figure 10The connection in it and the VPN Gateway establish an L2 layer network connection. Only the eth1 network interfaces of the VPN client and the VPN Gateway are configured with IP addresses. Each node consists of 3 vswitch bridges. The (ingress bridge) br-int is responsible for establishing network interfaces and flow table rules. The tunnel bridge (br-tun) is responsible for establishing tunnels. The egress bridge (br-ex) is responsible for connecting to the physical network interface. Inside the Firewall VNF, the linux bridge and iptables rules are used to simulate the firewall function. In addition, the network interfaces used by the VNF network elements (VPN client, VPN Gateway VNF, or Firewall VNF) can be either kernel-mode interfaces or user-mode interfaces. If it is a user-mode interface, the user-mode protocol stack will run inside the VNF network element.

[0156] See Figure 11 As shown, take the pure L3 network connection implemented based on DVR in the forwarding plane as an example. For a pure L3 network connection, the connection between VNF network elements needs to pass through routing (each VNF network element needs to be configured with routing rules). Therefore, not only network isolation is required but also different network segments need to be allocated, and each network interface needs to be configured with an IP address. As Figure 11 shown, in order to perform network isolation, 2 L3 VPNs are established, namely vpna and vpnb. Static routes are configured inside the VPN. The network IP segment given in the network service definition of the service chain is 192.168.1.0 / 24. When a VPN client requests this network service, the network proxy (Network Proxy 1 or Network Proxy 2) allocates n subnets with a network mask of 30 bits under this network segment. The adjacent interfaces of every two adjacent network elements are in 2 subnets. For example, the network interfaces of the VPN Client and the Firewall VNF are in the 192.168.1.0 / 30 subnet and the 192.168.1.4.0 / 30 subnet respectively, and the Firewall VNF and the VPN Gateway VNF are in the 192.168.1.8 / 30 and 192.168.1.12 / 30 subnets respectively. In this way, the VPN Client can perform L3 network communication with the VPN Gateway VNF. In addition, the network interfaces used by the VNF network elements can be either kernel-mode interfaces or user-mode interfaces. If it is a user-mode interface, the user-mode protocol stack will run inside the network element. Figure 11 In it, BD represents the broadcast domain or bridge domain (BridgeDomain, BD), which is the L2 broadcast domain for forwarding data packets in the VXLAN network. BDIF: The L3 logical interface established based on BD. By configuring the IP address through the BDIF interface, communication between different network segments of VXLANs, between VXLAN and non-VXLAN, and the access from the L2 network to the L3 network can be achieved.

[0157] In another possible scenario, for the VNF multi-network plane scenario. The types of network planes can include the base plane, fabric plane, external connection management plane, external connection data plane, etc. Different types of network planes have different quality attribute requirements. For example, different types of network planes have different requirements for network interface types, payload types, and routing types (such as vSwitch, DVR). Taking any GW (XGW) network element as an example, multiple VNF network elements are deployed in the XGW network element. See Figure 12 as shown. For example, multiple VNF network elements are divided into two categories, namely control services and business services. Control services are Figure 12 referred to as management & control (M&C) in Figure 12 and business services are Figure 12 referred to as interface process unit (IPU) in Figure 12 Taking the XGW network element deploying 6 VNF network elements as an example in

[0158] they are M&C1, M&C2, and IPU1 - IPU4 respectively. Taking two network planes as an example in

[0159] they are the base plane and the fabric plane respectively. It is required that different network planes in the XGW network element be isolated from each other.

[0160] In another possible way, the VNF network element requests to establish network interfaces for N network planes as needed. The network proxy receives the connection request sent by the VNF network element. The network proxy is used to manage the VNF network element. The connection request is used to request the establishment of network interfaces for N network planes. The connection request carries the identifiers of each of the N network planes. N is an integer greater than 1. The network proxy queries the configuration rule controller for the requirement information of the network interfaces corresponding to each of the N network planes based on the identifiers of the N network planes. The requirement information of the network interface corresponding to each network plane is used to describe the network interfaces that need to be established for network connection using each network plane. The network proxy establishes N network interfaces for the first VNF according to the requirement information of the network interfaces on each of the N network planes. The N network interfaces correspond one by one to the N network planes.

[0161] When a tunnel needs to be established, in one way, the network proxy establishes tunnel interfaces for each node in the system. In another way, when the network proxy receives a tunnel interface establishment request from a certain VNF network element (deployed on node 1) to node 2, it establishes a tunnel interface for node 1 where the VNF is located and a tunnel interface for node 2.

[0162] In one example, as Figure 13 shown, taking the forwarding plane implemented by the openflow vSwitch as an example, the IP address segment configured for the base plane is 10.56.217.XX. The IP address segment configured for the fabric plane is 10.56.218.XX. Figure 13Taking the example where M&C1 and IPU1 are located at node1, and M&C2 and IPU2 are located at node2. For the base plane, the network proxy assigns the IP address 10.56.217.10 to the network interface (eth1) of M&C1, the IP address 10.56.217.11 to the network interface (eth1) of M&C2, the IP address 10.56.217.15 to the network interface (eth1) of IPU1, and the IP address 10.56.217.12 to the network interface (eth1) of IPU2. For the fabric plane, the network proxy assigns the IP address 10.56.218.5 to the network interface (eth2) of M&C1, the IP address 10.56.217.7 to the network interface (eth2) of M&C2, the IP address 10.56.217.6 to the network interface (eth2) of IPU1, and the IP address 10.56.217.8 to the network interface (eth2) of IPU2. An L2 layer network connection is established between M&C1 and IPU1 in node1 and M&C2 and IPU2 in node2 through VXLAN. Each node consists of 3 vswitch bridges. Br-int is responsible for establishing network interfaces and flow table rules, br-tun is responsible for establishing tunnels, and br-ex is responsible for connecting to physical network interfaces.

[0163] In another example, as Figure 14 shown, taking the example where the forwarding plane is implemented through DVR. It is an example diagram of establishing a pure L3 network connection based on DVR between M&C1 and IPU1 in node1 and M&C2 and IPU2 in node2.

[0164] In another possible scenario, the network administrator configures network service policies and configures the network service policies to the configuration rule controller. The network service policies include conditions for triggering network operations. For example, the network service policies include one or more of an elastic scaling policy, a fusing rule, a traffic rule, etc. The elastic scaling policy is used to describe the rules for expanding or shrinking VNF network elements, including the conditions for expanding or shrinking VNF network elements. The elastic scaling policy includes an elastic expansion rule and / or an elastic contraction rule. The fusing rule is used to describe the rule for stopping neighbor establishment, including the conditions for triggering a VNF network element to stop neighbor establishment.

[0165] After receiving the network service policy, the configuration rule controller sends the network service policy to each network agent (such as the above-mentioned network agent 1 and network agent 2). After receiving the network service policy, the network agent regularly statistics telemetry data according to the network service policy, and determines whether the conditions for triggering network operations specified in the network service policy are met based on the statistics telemetry data. When it is determined that the conditions are met, an indication that the conditions for triggering network operations are met is sent to the telemetry policy controller. When the telemetry policy controller receives the indication of the conditions for triggering network operations, it executes the network operation.

[0166] In one example, the network administrator configures a trigger fuse rule for the configuration rule controller. The trigger fuse rule includes the maximum number of tolerable neighbors and the maximum number of virtual routing forwarding (VRF). The configuration rule controller sends the trigger fuse rule to the network agent, and the network agent statistics telemetry data, that is, statistics the number of neighbors and the number of VRFs of the VNF network element. When the network agent determines that the number of neighbors of the VNF network element reaches the maximum number of tolerable neighbors and the number of VRFs reaches the maximum number of VNFs, the network agent sends an indication that the conditions for triggering the fuse are reached to the telemetry policy controller. When the telemetry policy controller receives the indication that the conditions for triggering the fuse are reached, it sends a stop neighbor establishment instruction to the VNF network element through the network agent. Furthermore, after the VNF network element receives the stop neighbor establishment instruction, it no longer triggers the process of establishing a neighbor connection. The telemetry policy controller can also send an alarm message.

[0167] In another example, the network administrator configures an elastic expansion rule for the configuration rule controller. The trigger condition included in the elastic expansion rule is the maximum number of tolerable neighbors. The configuration rule controller sends the elastic expansion rule to the network agent, and the network agent statistics telemetry data, that is, statistics the number of neighbors of the VNF network element. When the network agent determines that the number of neighbors of the VNF network element reaches the maximum number of tolerable neighbors, it sends an indication that the conditions for elastic expansion are reached to the telemetry policy controller. When the telemetry policy controller receives the indication that the conditions for elastic expansion are reached, it sends an expansion policy to the VNF network element through the network agent, so that the VNF network element performs an expansion operation according to the expansion policy.

[0168] Next, in combination with Figure 5 the schematic diagram of the device of the network agent provided, the functions of the network agent will be described in detail. Figure 5 The network agent shown is used to implement the above Figure 4 or Figure 9 the method described in the embodiments shown.

[0169] In a possible scenario, Figure 5 the device shown applies network agent 1.

[0170] The first communication module is used to receive a first connection request from the first virtualized network function (VNF) network element. The network proxy 1 is used to manage the first VNF network element. The first VNF network element is the requester of the network service (NSC). The first connection request is used to request the establishment of a network interface, which is the network interface required to implement the network service. The first connection request carries the requirement information of the network interface, and the requirement information of the network interface is used to describe the network interface required by the network service.

[0171] The first communication module is further used to send a second connection request to the network proxy 2, and the requirement information of the network interface is carried in the second connection request. The network proxy 2 is used to manage the second VNF network element, and the second VNF network element is the provider of the network service.

[0172] The first communication module is further used to receive the attribute value of the first network interface sent by the network proxy 2, and the attribute value of the first network interface is determined by the network proxy 2 according to the requirement information of the network interface.

[0173] The forwarding plane adaptation module calls the forwarding plane to establish the first network interface according to the attribute value of the first network interface, so that the first VNF network element communicates through the first network interface.

[0174] In a possible example, the requirement information of the network interface includes one or more of the following: the type of the network interface, the name of the network interface.

[0175] In a possible example, the first connection request further carries the identifier of the network service definition.

[0176] The second communication module is used to query, according to the identifier of the network service definition, the next-hop VNF network element of the first VNF network element in the network service as the second VNF network element from the configuration rule controller before sending the second connection request to the network proxy 2.

[0177] Among them, the network service definition corresponding to the identifier of the network service definition includes the forwarding relationship information corresponding to the network service.

[0178] In a possible example, the forwarding plane adaptation module is used to adapt the forwarding plane. The forwarding plane supports the establishment of a network interface that meets the network interface required by the network service. The forwarding plane adaptation module calls the forwarding plane to establish the first network interface according to the attribute value of the first network interface.

[0179] In a possible example, the first VNF network element is deployed on a first node, the second VNF network element is deployed on a second node, and the forwarding plane adaptation module calls the forwarding plane to establish a first tunnel interface on the first node, and the first tunnel interface is used to connect to the second node.

[0180] In a possible example, the attribute value of the first network interface includes one or more of the following:

[0181] The name of the first network interface, the type of the first network interface, and the IP address of the first network interface.

[0182] In a possible example, the first connection request further carries the network namespace identifier of the first VNF network element;

[0183] The forwarding plane adaptation module is used to inject the established first network interface into the network namespace corresponding to the network namespace identifier.

[0184] In a possible example, the rule module is used to receive a network service policy sent by a configuration rule controller, and the network service policy includes conditions for triggering network operations;

[0185] The telemetry module is used to count telemetry data according to the network service policy, and when it is determined that the conditions for triggering network operations are met according to the telemetry data, send a first indication to the telemetry policy controller, and the first indication is used to indicate that the conditions for triggering network operations are met; when receiving a notification for executing the network operation sent by the telemetry policy controller, trigger the execution of the network operation.

[0186] In another possible scenario, Figure 5 The shown device is applied to Network Agent 2.

[0187] The first communication module is used to receive a second connection request from Network Agent 1. The second connection request carries demand information of a network interface. Network Agent 2 is used to manage a second VNF network element, and the second VNF network element is a provider of a network service; Network Agent 1 is used to manage a first VNF network element, and the first VNF network element is a requester of the network service. The demand information of the network interface is used to describe the network interface required to implement the network service;

[0188] The first communication module is further used to determine the attribute value of the second network interface according to the demand information of the network interface;

[0189] The forwarding plane adaptation module is used to call an adapted forwarding plane to establish the second network interface according to the attribute value of the second network interface, so that the second VNF network element communicates through the second network interface.

[0190] In a possible example, it further includes:

[0191] The first communication module is further configured to determine the attribute value of the first network interface according to the requirement information of the network interface, where the first network interface is the network interface for the first VNF network element to perform network communication;

[0192] The first communication module is configured to send the attribute value of the first network interface to the network proxy 1.

[0193] In a possible example, the forwarding plane adaptation module adapts the forwarding plane, and the forwarding plane supports the established network interface to meet the network interface required by the network service. The forwarding plane adaptation module calls the forwarding plane to establish the second network interface according to the attribute value of the second network interface.

[0194] In a possible example, the first VNF network element is deployed on the first node, the second VNF network element is deployed on the second node, and the second connection request further carries the requirement information of the tunnel, where the requirement information of the tunnel is used to describe the tunnel to be established between the first node and the second node; the forwarding plane adaptation module calls the forwarding plane to establish a second tunnel interface for the second node according to the requirement information of the tunnel, and the second tunnel interface is used to connect to the first node.

[0195] In a possible example, the second communication module receives the service registration information sent by the second VNF network element, where the service registration information is used to describe the network interface capabilities that the second VNF network element can provide; and sends the service registration information to the configuration rule controller.

[0196] In a possible example, the service registration information includes one or more of the following: network protocol IP address allocation policy, IP address segment, supported network interface types.

[0197] In a possible example, the attribute value of the first network interface includes one or more of the following:

[0198] The name of the first network interface, the type of the first network interface, and the IP address of the first network interface.

[0199] In a possible example, the attribute value of the first network interface includes the IP address of the first network interface. The network proxy 2 determines the attribute value of the first network interface according to the requirement information of the network interface, including:

[0200] The first communication module sends the requirement information of the network interface to the second VNF network element and receives the IP address of the first network interface sent by the second VNF network element.

[0201] In a possible example, the attribute value of the second network interface includes one or more of the following: the name of the second network interface, the type of the second network interface, and the IP address of the second network interface.

[0202] In a possible example, the attribute value of the second network interface includes the IP address of the second network interface. The first communication module sends the requirement information of the network interface to the second VNF network element and receives the IP address of the second network interface sent by the second VNF network element.

[0203] In a possible example, the first communication module configures the IP address of the second network interface for the second network interface.

[0204] In a possible example, the rule module receives the network service policy sent by the configuration rule controller. The network service policy includes the conditions for triggering network operations. The telemetry module statistically analyzes the telemetry data according to the network service policy and, when determining that the conditions for triggering network operations are met based on the telemetry data, sends a second indication to the telemetry policy controller. The second indication is used to indicate that the conditions for triggering network operations are met. When receiving the notification for executing the network operation sent by the telemetry policy controller, it triggers the execution of the network operation.

[0205] In yet another possible scenario, for the network proxy in a multi-plane scenario.

[0206] The first communication module receives a connection request sent by the VNF network element. The network proxy is used to manage the VNF network element. The connection request is used to request the establishment of network interfaces for N network planes. The connection request carries the identifiers of each of the N network planes, where N is an integer greater than 1. It queries the requirement information of the network interfaces corresponding to each of the N network planes from the configuration rule controller according to the identifiers of the N network planes.

[0207] The requirement information of the network interface corresponding to each network plane is used to describe the network interfaces that need to be established for network connection using each network plane.

[0208] The forwarding plane adaptation module establishes N network interfaces for the first VNF according to the requirement information of the network interfaces on each of the N network planes. The N network interfaces correspond one-to-one with the N network planes.

[0209] Figure 15It is a schematic structural diagram of a network proxy applicable to the embodiments of the present application. As Figure 15 shown, the network proxy includes: one or more processors 1501, one or more memories 1502, and one or more communication interfaces 1503. The processor 1501 is used to control the communication interface 1503 to send and receive signals, the memory 1502 is used to store computer programs, and the processor 1501 is used to call and run the computer programs from the memory 1502, so that the network proxy executes the corresponding processes and / or operations performed by the network proxy, network proxy 1, and network proxy 2 in the network interface establishment method of the present application.

[0210] In addition, the present application also provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions run on a computer, the computer executes the corresponding processes and / or operations performed by the network proxy, network proxy 1, and network proxy 2 in the network interface establishment method of the present application.

[0211] In addition, the present application also provides a chip, including a memory and a processor. The memory is used to store computer programs, and the processor is used to call and run the computer programs from the memory, so that a network device installed with the chip executes the corresponding processes and / or operations performed by the network proxy, network proxy 1, and network proxy 2 in the network interface establishment method of the present application.

[0212] In addition, the present application also provides a computer program product, which includes computer program code. When the computer program code runs on a computer, the computer executes the corresponding processes and / or operations performed by the network proxy, network proxy 1, and network proxy 2 in the network interface establishment method of the present application.

[0213] In the above embodiments, "and / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Where A and B can be singular or plural.

[0214] In this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and effects. It should be understood that there is no logical or chronological dependency between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be restricted by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various examples described, the first image can be referred to as the second image, and similarly, the second image can be referred to as the first image. The first image and the second image can both be images, and in some cases, they can be separate and different images.

[0215] In the above embodiments, the processor can be a CPU, a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the solution of this application, etc. For example, the processor can include a digital signal processor device, a microprocessor device, an analog-to-digital converter, a digital-to-analog converter, etc. The processor can allocate the functions of controlling and signal processing of the mobile device among these devices according to their respective functions. In addition, the processor can include the function of operating one or more software programs, and the software programs can be stored in the memory.

[0216] The functions of the processor can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0217] The memory can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer.

[0218] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0219] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0220] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0221] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0222] Obviously, those skilled in the art can make various modifications and variations to the embodiments of the present application without departing from the scope of the embodiments of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.

Claims

1. A method for establishing a network interface, characterized in that, it includes: A first network agent receives a first connection request from a first virtual network function (VNF) network element. The first network agent is used to manage the first VNF network element. The first VNF network element is a requester of a network service. The first connection request is used to request the establishment of a network interface required to implement the network service. The first connection request carries requirement information of the network interface, and the requirement information of the network interface is used to describe the network interface required to implement the network service; The first network agent sends a second connection request to a second network agent, and the second connection request carries the requirement information of the network interface; the second network agent is used to manage a second VNF network element, and the second VNF network element is the provider of the network service; The first network agent receives an attribute value of a first network interface sent by the second network agent, and the attribute value of the first network interface is determined by the second network agent according to the requirement information of the network interface; The first network agent establishes the first network interface according to the attribute value of the first network interface, so that the first VNF network element communicates through the first network interface.

2. The method according to claim 1, characterized in that, the requirement information of the network interface includes one or more of the following: the type of the network interface, the name of the network interface.

3. The method according to claim 1, characterized in that, the first connection request also carries an identifier of a network service definition; before the first network agent sends the second connection request to the second network agent, it further includes: the first network agent queries, according to the identifier of the network service definition, a next-hop VNF network element of the first VNF network element in the network service as the second VNF network element from a configuration rule controller; wherein, the network service definition corresponding to the identifier of the network service definition includes forwarding relationship information corresponding to the network service.

4. The method according to any one of claims 1-3, characterized in that, the first network agent adapts to at least one forwarding plane, and the first network agent establishing the first network interface according to the attribute value of the first network interface includes: the first network agent calls a first forwarding plane in the at least one forwarding plane to establish the first network interface according to the attribute value of the first network interface.

5. The method according to claim 4, characterized in that, the first VNF network element is deployed on a first node, the second VNF network element is deployed on a second node, and the method further includes: the first network agent calls the forwarding plane to establish a first tunnel interface on the first node, and the first tunnel interface is used to connect to the second node.

6. The method according to any one of claims 1-3, 5, characterized in that, the attribute value of the first network interface includes one or more of the following: the name of the first network interface, the type of the first network interface, the IP address of the first network interface.

7. The method according to any one of claims 1-3, 5, characterized in that, The first connection request further carries the network namespace identifier of the first VNF network element; The method further includes: The first network proxy adds the established first network interface to the network namespace corresponding to the network namespace identifier.

8. The method according to any one of claims 1-3, 5, characterized in that it further includes: The first network proxy receives a network service policy sent by a configuration rule controller, and the network service policy includes conditions for triggering network operations; The first network proxy statistically analyzes telemetry data according to the network service policy, and when it determines that the conditions for triggering network operations are met according to the telemetry data, it sends a first indication to the telemetry policy controller, and the first indication is used to indicate that the conditions for triggering network operations are met; When the first network proxy receives a notification for performing the network operation sent by the telemetry policy controller, it performs the network operation.

9. A method for establishing a network interface, characterized in that it includes: A second network proxy receives a second connection request from a first network proxy. The second connection request is used to request the establishment of a network interface required to implement a network service. The second connection request carries requirement information of the network interface. The second network proxy is used to manage a second VNF network element, and the second VNF network element is the provider of the network service; the first network proxy is used to manage a first VNF network element, and the first VNF network element is the requester of the network service. The requirement information of the network interface is used to describe the network interface required to implement the network service; The second network proxy determines the attribute value of the second network interface according to the requirement information of the network interface; The second network proxy establishes the second network interface according to the attribute value of the second network interface, so that the second VNF network element communicates through the second network interface.

10. The method according to claim 9, characterized in that it further includes: The second network proxy determines the attribute value of a first network interface according to the requirement information of the network interface, and the first network interface is the network interface for the first VNF network element to perform network communication; The second network proxy sends the attribute value of the first network interface to the first network proxy.

11. The method according to claim 9, characterized in that The second network proxy adapts at least one forwarding plane. The second network proxy establishes the second network interface according to the attribute value of the second network interface, including: The second network proxy calls a first forwarding plane in the at least one forwarding plane to establish the second network interface according to the attribute value of the second network interface.

12. The method according to claim 11, characterized in that The first VNF network element is deployed on a first node, the second VNF network element is deployed on a second node, and the second connection request further carries requirement information of a tunnel, and the requirement information of the tunnel is used to describe the tunnel required to be established between the first node and the second node; The method further includes: The second network agent invokes the forwarding plane according to the requirement information of the tunnel to establish a second tunnel interface for the second node, and the second tunnel interface is used to connect the first node.

13. The method according to any one of claims 9-12, characterized in that, further comprising: The second network agent receives service registration information sent by the second VNF network element, and the service registration information is used to describe the network interface capabilities provided by the second VNF network element; The second network agent sends the service registration information to the configuration rule controller.

14. The method according to claim 13, characterized in that, The service registration information includes one or more of the following: Network protocol IP address allocation policy, IP address segment, supported network interface types.

15. The method according to any one of claims 9-12, 14, characterized in that, The attribute values of the first network interface include one or more of the following: The name of the first network interface, the type of the first network interface, the IP address of the first network interface.

16. The method according to claim 15, characterized in that, The attribute value of the first network interface includes the IP address of the first network interface, and the second network agent determines the attribute value of the first network interface according to the requirement information of the network interface, including: The second network agent sends the requirement information of the network interface to the second VNF network element; The second network agent receives the IP address of the first network interface sent by the second VNF network element.

17. The method according to any one of claims 9-12, 14, 16, characterized in that, The attribute values of the second network interface include one or more of the following: The name of the second network interface, the type of the second network interface, the IP address of the second network interface.

18. The method according to claim 17, characterized in that, The attribute value of the second network interface includes the IP address of the second network interface, and the second network agent determines the attribute value of the second network interface according to the requirement information of the network interface, including: The second network agent sends the requirement information of the network interface to the second VNF network element; The second network agent receives the IP address of the second network interface sent by the second VNF network element.

19. The method according to claim 17, characterized in that, further comprising: The second network agent configures the IP address of the second network interface for the second network interface.

20. The method according to any one of claims 9-12, 14, 16, 18-19, characterized in that, further comprising: The second network agent receives a network service policy sent by the configuration rule controller, and the network service policy includes conditions for triggering network operations; The second network agent statistically analyzes telemetry data according to the network service policy, and when it determines that the conditions for triggering network operations are met according to the telemetry data, it sends a second indication to the telemetry policy controller, and the second indication is used to indicate that the conditions for triggering network operations are met; When the second network agent receives the notification sent by the telemetry policy controller for performing the network operation, it performs the network operation.

21. A method for establishing a network interface, Characterized in that, Comprising: A network agent receives a connection request sent by a VNF network element. The network agent is used to manage the VNF network element. The connection request is used to request the establishment of network interfaces for N network planes. The connection request carries the identifier of each of the N network planes, and N is an integer greater than 1; The network agent queries the configuration rule controller for the requirement information of the network interface corresponding to each of the N network planes according to the identifiers of the N network planes. The requirement information of the network interface corresponding to each network plane is used to describe the network interface that needs to be established for network connection using each network plane; The network agent establishes N network interfaces for the VNF network element according to the requirement information of the network interface corresponding to each of the N network planes. The N network interfaces correspond one-to-one to the N network planes.

22. A device, Characterized in that, Comprising: A processor, the processor is coupled to a memory. The memory is used to store programs or instructions. When the programs or instructions are executed by the processor, the device is caused to execute the method according to any one of claims 1 to 21.

23. A system, Characterized in that, Comprising a first VNF network element, a first network agent for managing the first VNF network element, a second VNF network element, and a second network agent for managing the second VNF network element; The first network agent is used to establish a first network interface for the first VNF network element by executing the method according to any one of claims 1-8; The first VNF network element is used to perform network communication with the second VNF network element through the first network interface; The second network agent is used to establish a second network interface for the second VNF network element by executing the method according to any one of claims 9-20; The second VNF network element is used to perform network communication with the first VNF network element through the second network interface.

24. A computer-readable medium, on which a computer program or instruction is stored, Characterized in that, When the computer program or instruction is executed, the computer is caused to execute the method according to any one of claims 1 to 21.

Citation Information

Patent Citations

  • Frameworks and interfaces for offload device-based packet processing

    CN104054067A

  • Communication method and device

    CN109714425A