Application management method and device, storage medium, and electronic device

By obtaining and parsing the application's management configuration information and business data, determining policy control rules and establishing service quality levels, the problem of the inability to effectively manage applications in the existing technology is solved, and application management with high accuracy, flexibility and precision is achieved.

CN113608778BActive Publication Date: 2025-05-02CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110903695.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-06
Publication Date
2025-05-02
Estimated Expiration
2041-08-06

AI Technical Summary

Technical Problem

The existing technology cannot effectively manage applications and cannot meet users' ability to customize services, especially in the 5G era when user-side applications are diversified and complex.

Method used

By obtaining the application's management configuration information and business data, analyzing and processing generate connection table information, determining policy control rules based on the connection table information, establishing service quality levels, and using service quality levels to process the application.

Benefits of technology

It realizes the accuracy, flexibility and accuracy of application management, reduces the load, cost and complexity of management applications, and enriches the application scenarios of application management methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113608778B_ABST
    Figure CN113608778B_ABST
Patent Text Reader

Abstract

The present disclosure belongs to the field of network communication technology, and relates to an application management method and device, a storage medium, and an electronic device. The method includes: obtaining the management configuration information of the application, and obtaining the business data corresponding to the application; parsing the business data to generate connection table information, and determining the policy control rules corresponding to the application according to the connection table information; based on the policy control rules, establishing a service quality level corresponding to the application, and using the service quality level to process the application. The present disclosure can customize the processing rules for different applications according to user needs, and provide a data foundation for logical centralized management for implementing policy control of applications; on the other hand, establishing a service quality level to process applications according to the policy control rules improves the flexibility and accuracy of application management, reduces the load, cost and complexity of managing applications, and enriches the application scenarios of application management methods.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network communication technology, and in particular to an application management method and application management device, a computer-readable storage medium, and an electronic device. Background Art

[0002] With the maturity of 5G (5th Generation Mobile Communication Technology) technology and the improvement of the network, the 5G era has arrived. User-side applications are becoming more and more abundant and diversified, and users have higher requirements for the network's service capabilities.

[0003] Some users also have increasing demands for identification and control of business applications. For example, in the student group, parents hope to intelligently identify and control students' online applications; in the enterprise 5G intranet, the management hopes to manage applications on intranet terminals to improve production efficiency and security reliability. In response to this type of demand for user A to control user B's application access control, the current network's processing capabilities in this regard are still defective and cannot meet users' business customization needs.

[0004] In view of this, there is an urgent need in the art to develop a new application management method and device.

[0005] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0006] The purpose of the present disclosure is to provide an application management method, an application management device, a computer-readable storage medium and an electronic device, thereby overcoming the technical problem of being unable to manage application programs due to limitations of related technologies, at least to a certain extent.

[0007] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0008] According to a first aspect of an embodiment of the present invention, there is provided an application management method, the method comprising: obtaining management configuration information of an application program, and obtaining service data corresponding to the application program;

[0009] Parsing the service data to generate connection table information, and determining a policy control rule corresponding to the application according to the connection table information;

[0010] Based on the policy control rule, a service quality level corresponding to the application is established, and the application is processed using the service quality level.

[0011] In an exemplary embodiment of the present invention, the management configuration information includes: management configuration information determined according to package permission information corresponding to the application and management configuration information generated by autonomous configuration processing of the application.

[0012] In an exemplary embodiment of the present invention, the step of parsing the service data to generate connection table information includes:

[0013] Performing data mirroring processing on the business data to obtain mirrored data;

[0014] The mirror data is analyzed and processed to obtain protocol information, and connection table information is generated according to the protocol information.

[0015] In an exemplary embodiment of the present invention, the method further comprises:

[0016] The connection table information is acquired at preset time intervals and stored.

[0017] In an exemplary embodiment of the present invention, the determining of a policy control rule corresponding to the application according to the connection table information includes:

[0018] Acquire management name information in the management configuration information, and determine application name information in the connection table information according to protocol information in the connection table information;

[0019] The same management name information is determined according to the application name information, and a policy control rule is determined according to the management configuration information of the same management name information.

[0020] In an exemplary embodiment of the present invention, establishing a service quality level corresponding to the application based on the policy control rule includes:

[0021] If the policy control rule is a policy control rule for a blacklist application, a processing rule is established for discarding the service quality level of the message;

[0022] If the policy control rule is a policy control rule for whitelist application, a processing rule is established as a service quality level of priority forwarding.

[0023] In an exemplary embodiment of the present invention, the method further comprises:

[0024] Obtaining the end time of the priority forwarding processing for the whitelist application, and obtaining a time threshold corresponding to the end time;

[0025] If the end time is greater than the time threshold, the service quality level of the whitelist application is deleted.

[0026] According to a second aspect of an embodiment of the present invention, there is provided an application management device, the device comprising: an information acquisition module, configured to acquire management configuration information of an application program, and acquire service data corresponding to the application program;

[0027] a rule determination module, configured to parse the service data to generate connection table information, and determine a policy control rule corresponding to the application according to the connection table information;

[0028] The application processing module is configured to establish a service quality level corresponding to the application program based on the policy control rule, and process the application program using the service quality level.

[0029] According to a third aspect of an embodiment of the present invention, there is provided an electronic device, comprising: a processor and a memory; wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the application management method in any of the above exemplary embodiments is implemented.

[0030] According to a fourth aspect of an embodiment of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the application management method in any of the above exemplary embodiments is implemented.

[0031] It can be seen from the above technical solutions that the application management method, application management device, computer storage medium and electronic device in the exemplary embodiments of the present disclosure have at least the following advantages and positive effects:

[0032] In the method and apparatus provided in the exemplary embodiments of the present disclosure, on the one hand, the management configuration information set by the user for the application is obtained, and the processing rules for different applications can be customized according to user needs, providing a data basis for logical centralized management for implementing policy control of the application; on the other hand, service quality levels are established according to different policy control rules to process the application, which improves the accuracy, flexibility and precision of application management, reduces the load, cost and complexity of managing the application, and enriches the application scenarios of the application management method.

[0033] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0035] Figure 1 A schematic diagram schematically illustrates a flow chart of an application management method in an exemplary embodiment of the present disclosure;

[0036] Figure 2 A system module diagram schematically illustrating a method for generating management configuration information in an exemplary embodiment of the present disclosure;

[0037] Figure 3 A flowchart schematically illustrating a method for parsing processing in an exemplary embodiment of the present disclosure;

[0038] Figure 4 A system module diagram schematically illustrating generation and storage of connection table information in an exemplary embodiment of the present disclosure;

[0039] Figure 5 A flowchart schematically illustrating a method for determining a policy control rule in an exemplary embodiment of the present disclosure;

[0040] Figure 6 A flowchart schematically illustrating a method for establishing a service quality level in an exemplary embodiment of the present disclosure;

[0041] Figure 7 A system module diagram schematically illustrating an application program processing in an exemplary embodiment of the present disclosure;

[0042] Figure 8 A schematic flow chart schematically illustrating a method for reclaiming a whitelist service quality level configuration in an exemplary embodiment of the present disclosure;

[0043] Fig. 9 A schematic diagram schematically shows the structure of an application management device in an exemplary embodiment of the present disclosure;

[0044] Fig.10 An electronic device for implementing an application management method in an exemplary embodiment of the present disclosure is schematically shown;

[0045] Fig.11 A computer-readable storage medium for implementing an application management method in an exemplary embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION

[0046] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as being limited to the examples set forth herein; on the contrary, these embodiments are provided so that the present disclosure will be more comprehensive and complete, and the concepts of the example embodiments are fully conveyed to those skilled in the art. The described features, structures, or characteristics may be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced while omitting one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, known technical solutions are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0047] The terms "a", "an", "the" and "said" are used in this specification to indicate the presence of one or more elements / components / etc.; the terms "including" and "having" are used to express an open-ended inclusion and mean that additional elements / components / etc. may exist in addition to the listed elements / components / etc.; the terms "first" and "second" etc. are used only as labels and are not intended to limit the quantity of their objects.

[0048] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the drawings represent the same or similar parts, and their repeated descriptions will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities.

[0049] In view of the problems existing in the related technologies, the present invention proposes an application management method. Figure 1 A flow chart of an application management method is shown, Figure 1 As shown, the application management method includes at least the following steps:

[0050] Step S110: Obtain management configuration information of the application, and obtain business data corresponding to the application.

[0051] Step S120: parse the service data to generate connection table information, and determine the policy control rules corresponding to the application program according to the connection table information.

[0052] Step S130: Based on the policy control rules, a service quality level corresponding to the application is established, and the application is processed using the service quality level.

[0053] In the exemplary embodiments of the present disclosure, on the one hand, the management configuration information set by the user for the application is obtained, and the processing rules for different applications can be customized according to user needs, providing a data foundation for logical centralized management for implementing policy control of the application; on the other hand, service quality levels are established according to different policy control rules to process the application, which improves the accuracy, flexibility and precision of application management, reduces the load, cost and complexity of managing the application, and enriches the application scenarios of the application management method.

[0054] The following is a detailed description of each step of the application management method.

[0055] In step S110, management configuration information of the application is obtained, and business data corresponding to the application is obtained.

[0056] In an exemplary embodiment of the present disclosure, the management configuration information may be black and white list information of an application configured by a user.

[0057] Figure 2 A system module diagram showing a method for generating management configuration information is shown. Figure 2 As shown, the system module for generating management configuration information includes CRM, user-side APP (application) and UDM (Unified Data Management) network element of the 5G core network.

[0058] Among them, 5GC (5G core network) supports a data storage architecture for separation of computing and storage. The Unified Data Repository (UDR) is the main database. The Unstructured Data Storage Function (UDSF) is introduced to store dynamic data.

[0059] CRM is a business system used by Chinese operators to handle services such as mobile bandwidth, etc. In addition, each province has its own separate CRM system.

[0060] In an optional embodiment, the management configuration information includes: management configuration information determined according to package permission information corresponding to the application and management configuration information generated by autonomous configuration processing of the application.

[0061] Therefore, the CRM system and the user-side APP work together to complete the user's setting of management configuration information according to the package permission information, and to generate management configuration information for autonomous configuration processing, so as to realize the application of user A for user B's application access control permission.

[0062] It is worth noting that user A and user B have already established a binding relationship, and user B and user A have a master-slave binding relationship.

[0063] The package permission information may be a template for management configuration information, in which a blacklist and a whitelist of applications are already specified, and the user may directly generate the same management configuration information as specified in the template.

[0064] The self-configuration process is that user B can set the blacklist and whitelist of applications in the application that provides application management to obtain the self-configured management configuration information.

[0065] After obtaining the management configuration information configured by the user, the UDM network element of 5GC can receive the management configuration information configured in the CRM and store the corresponding management configuration information in the UDM network element.

[0066] For example, the management configuration information defined by the blacklist and whitelist may include the basic information shown in Table (1):

[0067] User Groups Terminal Number Business APP Category Application Name Black and White List open** 1891234567 Instant Messaging WeChat Whitelist

[0068] Table (1)

[0069] The management configuration information includes user groups, terminal numbers, service APP categories, and application names. In addition, the management configuration information may also include other information, which is not specifically limited in this exemplary embodiment.

[0070] Furthermore, business data corresponding to the application can also be obtained.

[0071] In step S120, the service data is parsed to generate connection table information, and a policy control rule corresponding to the application is determined according to the connection table information.

[0072] In an exemplary embodiment of the present disclosure, after obtaining the management configuration information and service data of the application, the service data may be parsed to obtain the connection table information.

[0073] In an alternative embodiment, Figure 3 A flow chart of the method of parsing processing is shown, as Figure 3 As shown, the method at least includes the following steps: In step S310, data mirroring is performed on the business data to obtain mirrored data.

[0074] Since the business data generated by users in the process of using the application program will not be actively reported to the operator, the business data can be mirrored to obtain mirrored data.

[0075] Specifically, data mirroring processing may adopt the normalized mirror phase flow method of 5GC, or may adopt other methods, and this exemplary embodiment does not specifically limit this.

[0076] In step S320, the mirror data is analyzed and processed to obtain protocol information, and connection table information is generated according to the protocol information.

[0077] After obtaining the mirror data, the mirror data can be further analyzed and processed to obtain the server protocol information of the APP corresponding to the business data. The protocol information can be the IP (Internet Protocol) information of the server, or other protocol information, which is not specifically limited in this exemplary embodiment.

[0078] Furthermore, the connection table information may be generated in a fixed format corresponding to the protocol information.

[0079] In this exemplary embodiment, connection table information can be generated through data mirroring and analysis processing, which solves the problem that the operator side cannot obtain actively reported business data and can also provide a data basis for subsequent determination of service quality levels.

[0080] In addition, the connection table information can be synchronized regularly.

[0081] In an optional embodiment, the connection table information is acquired at preset time intervals and stored.

[0082] Figure 4 A system module diagram showing generation and storage of connection table information is shown. Figure 4 As shown, the system module includes 5GC's UDM network, PCF (Policy Control Function) network element and DPI (Deep Packet Inspection) equipment.

[0083] Among them, the PCF network element supports a unified policy framework to manage network behavior, provides policy rules to network entities for implementation, accesses subscription information of the unified data warehouse UDR, etc.

[0084] DPI is a seven-layer protocol analysis technology that parses application layer data (including the header and payload content of IP / TCP / UDP packets) to match the protocol characteristics of the application, thereby determining the application to which the packet data flow belongs.

[0085] After the DPI device identifies the application to which the data flow belongs, it can perform precise routing control, security control, and analysis and statistics on the message according to the requirements of the usage scenario.

[0086] In addition, the detection of application information is usually completed by analyzing the 4-7 layers of DIP.

[0087] On the network, the DPI device is mounted next to the 5G core network system. The 5G core network system mirrors the user's business data to the DPI device. The DPI device analyzes the IP information of the APP corresponding to the server through the mirrored data and generates connection table information.

[0088] The PCF network element of the 5G core network system obtains the connection information table from the DPI device and caches it in the PCF network element. In addition, in order to ensure the accuracy of the connection table information, the PCF network element can regularly synchronize the connection table information with the DPI device.

[0089] It is worth noting that the DPI device relies on the DPI prior knowledge base to perform data mirroring and analysis on business data.

[0090] In addition, the generated connection table information includes information content as shown in Table (2):

[0091] Business APP Category Application Name Node destination IP Aging time (milliseconds) Instant Messaging WeChat 1.2.3.4 YYYYMMDDHHMMSSMS

[0092] Table (2)

[0093] The connection table information includes the service APP category, application name information, node destination IP and aging time (milliseconds). In addition, other information may be included according to actual settings, and this exemplary embodiment does not make special restrictions on this.

[0094] After the connection table information is obtained, the policy control rule corresponding to the application program may also be determined according to the connection table information.

[0095] In an alternative embodiment, Figure 5 A flow chart of a method for determining a policy control rule is shown. Figure 5 As shown, the method at least includes the following steps: In step S510, management name information in the management configuration information is acquired, and application name information in the connection table information is determined according to protocol information in the connection table information.

[0096] According to the information content of the management configuration information shown in Table (1), the application name therein can be obtained as the management name information. The management name information is the name information that determines the blacklist and whitelist.

[0097] Furthermore, in the connection table information shown in Table (2), the application name information for which the policy control rule is to be queried can be determined according to the protocol information. The application name information is the name information of the unknown black and white list.

[0098] In step S520, identical management name information is determined according to the application name information, and a policy control rule is determined according to management configuration information of the identical management name information.

[0099] Therefore, in order to determine the black and white list content corresponding to the application name information in the connection table information, the same management name information can be determined in the management name information, which is equivalent to querying the black and white list configuration content corresponding to the application name information.

[0100] Further, after the black and white list configuration content is determined according to the management configuration information of the same management name information, the policy control rules for the black and white list can be determined.

[0101] That is, the change policy control rule includes two kinds of rules, one is the policy control rule for the blacklist application, and the other is the policy control rule for the whitelist application.

[0102] Specifically, by summarizing the management configuration information in Table (1) and the connection table information in Table (2), the corresponding relationship between the management name information, the application name information and the protocol information shown in Table (3) can be obtained:

[0103]

[0104] Table (3)

[0105] Therefore, according to the correspondence between the management name information, application name information and protocol information in Table (3), the configuration content of the black and white list can be determined to determine the corresponding policy control rules.

[0106] In this exemplary embodiment, the policy control rules of the application can be determined based on the connection table information. The determination method is simple and accurate, and the policy control rules are set completely, ensuring the control accuracy of the subsequent processing of the application using the policy control rules.

[0107] In step S130, a service quality level corresponding to the application is established based on the policy control rule, and the application is processed using the service quality level.

[0108] In an exemplary embodiment of the present disclosure, after the policy control rule is determined, a service quality level corresponding to the application may be established.

[0109] In an alternative embodiment, Figure 6 A flow chart of a method for establishing a service quality level is shown, Figure 6 As shown, the method at least includes the following steps: In step S610, if the policy control rule is a policy control rule for blacklist application, a processing rule is established to discard the service quality level of the message.

[0110] When the determined policy control rule is a policy control rule of a blacklist application, a service quality level dedicated to the blacklist application may be established.

[0111] The quality of service level may be a QoS (Quality of Service) flow.

[0112] QoS refers to a network's ability to use various basic technologies to provide better service capabilities for specified network communications. It is a network security mechanism and a technology used to solve problems such as network delays and congestion. QoS guarantees are very important for networks with limited capacity, because these applications often require a fixed transmission rate and are also sensitive to delays.

[0113] For blacklist applications, the processing rule of the dedicated QoS flow is to discard the message. Specifically, when the application used by the user is a blacklist application, the dedicated QoS flow will be matched to lose the message, so that the user cannot use the blacklist application.

[0114] In step S620, if the policy control rule is a policy control rule for whitelist application, a processing rule is established as a service quality level of priority forwarding.

[0115] When the determined policy control rule is a policy control rule of a whitelist application, a service quality level dedicated to the whitelist application may be established, and the service quality level may be a QoS flow.

[0116] For whitelist applications, the processing rule of the dedicated QoS flow is priority forwarding. Specifically, when the application used by the user is a whitelist application, the dedicated QoS flow will be matched and used to implement priority forwarding processing.

[0117] In this exemplary embodiment, corresponding service quality levels can be established for different policy control rules to ensure accurate processing of blacklist applications and whitelist applications, and customized access rules to distinguish different application programs.

[0118] Therefore, after the service quality level is established, the service quality level can be used to process the corresponding blacklist application or whitelist application application.

[0119] Figure 7 A system module diagram for processing an application is shown, such as Figure 7 As shown, user service detection and control are divided into two functions: user service detection and user service control.

[0120] First, the user service detection function is jointly implemented by the 5G core network SMF (Session Management Function) network element, UPF network element, PCF network element and UDM network element.

[0121] Among them, the SMF network element can support customized mobility management solutions together with the AMF (Access and Mobility management Function) network element, such as "Mobile Initiated Connection Only" (MICO) or RAN enhancements, such as the "RRC Inactive" state. Its main tasks include session management; UE IP address allocation and management; UPF selection and control; configuring flow control in UPF to route traffic to the appropriate destination; policy execution and QoS control; downlink data notification.

[0122] When a user establishes a PDU (Protocol Data Unit) session, the 5G core network system SMF network element obtains the management configuration information of the blacklist and whitelist from the UDM network element, and obtains the corresponding policy control rules from the PCF module.

[0123] The policy control rule may be a PCC (Policy and Charging Control) rule. The PCC rule includes two categories, namely, a dynamic PCC rule and a static predefined PCC rule.

[0124] Furthermore, for blacklist and whitelist applications, a dedicated QoS flow is established and sent to the UPF network element of the 5G core network system, which monitors and processes the usage of user blacklist and whitelist services.

[0125] Second, the user service control function is implemented by the UPF network element and SMF network element of the 5G core network system.

[0126] For the user's blacklist application, when the user establishes a PDU session, the SMF network element will send a dedicated QoS flow to the UPF network element. The processing rule of this dedicated QoS network element is to discard the message. When the user uses the application of the blacklist application, it will match the dedicated QoS flow. When the data reaches the UPF network element, the UPF network element will discard the message according to the processing rule, so that the user cannot use the blacklist application.

[0127] For the user's whitelist application, when the user establishes a PDU session, the SMF network element will send a dedicated QoS flow to the UPF network element. The dedicated QoS flow sets the corresponding QoS flow priority according to the user's business needs to achieve bandwidth guarantee. The processing rule of the dedicated QoS flow is priority forwarding. When the user uses an application on the whitelist, the dedicated QoS flow will be matched and used for forwarding processing.

[0128] In addition, for whitelist applications, the session QoS flow configuration can be recycled by ending the duration to control the number of saved UPF sessions.

[0129] In an alternative embodiment, Figure 8 A flow chart showing a method for reclaiming a whitelist service quality level configuration is shown, such as Figure 8 As shown, the method at least includes the following steps: in step S810, the end duration of the priority forwarding processing for the whitelist application is obtained, and a duration threshold corresponding to the end duration is obtained.

[0130] For example, application 1 is a whitelist application. When the user switches from application 1 to application 2, the end duration of application 1 starts to be counted to obtain the corresponding end duration.

[0131] Furthermore, a duration threshold may be set according to the end duration as a threshold value for limiting the end duration of the session of application 1 .

[0132] In step S820, if the end time is greater than the time threshold, the service quality level of the whitelist application is deleted.

[0133] Furthermore, the end time can be compared with the time threshold. When the comparison result is that the end time is greater than the time threshold, the corresponding session QoS flow configuration can be recycled, that is, the service quality level of the whitelist application is deleted.

[0134] In this exemplary embodiment, the configured service quality level is deleted according to the end length of the whitelist, which can ensure that the number of saved sessions of the UPF network element is limited to a certain range, reduce the number of entries of the currently activated IP session policy of the UPF network element, and greatly reduce the load of the UPF network element.

[0135] The application management method in this application scenario, on the one hand, uses PCF control policy network elements to deploy service flow admission control, and only performs destination IP policy control on the current session, which can greatly reduce the UPF load. In addition, the DPI prior knowledge base is continuously improved by normalized flow mirror analysis, avoiding the two major problems of domain name-based inability to parse application without host messages such as "HTTPS protocol for game or host message encryption" and incompleteness based on IP manual maintenance.

[0136] On the other hand, based on the judgment of the DPI prior knowledge base, the completeness of the admission control judgment of the business flow is greatly improved. The application identification capability of 5GC is no longer limited by the application protocol identification capability of UPF itself, and can respond based on the mature application identification capability of the industry. In addition, the admission control judgment is moved to the PCF network element, and the PCF sends the current session node IP policy, which greatly releases UPF resources and reduces the investment cost of UPF.

[0137] On the other hand, rule control is unified in the PCF network element, and no local configuration is required for the UPF, which is conducive to the deployment and expansion of the UPF network element. Based on PCF rule control, a single UPF can implement the granular control function of service sessions without the need to add additional UPF network element configuration functions, which increases the complexity of network element design. At the same time, only for the current session, the number of matching plans for UPF will be reduced to a minimum. Furthermore, application identification of global traffic based on independent DPI can ensure the consistency of application identification policies in multiple UPFs, avoid deviations in application identification policies of multiple UPFs due to static rule configuration, and realize logical centralized management of application identification and policy control.

[0138] Furthermore, in an exemplary embodiment of the present disclosure, an application management device is also provided. Fig. 9 A schematic diagram of the structure of the application management device is shown in FIG. Fig. 9 As shown, the application management device 900 may include: an information acquisition module 910, a rule determination module 920 and an application processing module 930. Among them:

[0139] The information acquisition module 910 is configured to obtain the management configuration information of the application and obtain the business data corresponding to the application; the rule determination module 920 is configured to parse the business data to generate connection table information, and determine the policy control rules corresponding to the application based on the connection table information; the application processing module 930 is configured to establish a service quality level corresponding to the application based on the policy control rules, and use the service quality level to process the application.

[0140] In an exemplary embodiment of the present invention, the management configuration information includes: management configuration information determined according to package permission information corresponding to the application and management configuration information generated by autonomous configuration processing of the application.

[0141] In an exemplary embodiment of the present invention, the step of parsing the service data to generate connection table information includes:

[0142] Performing data mirroring processing on the business data to obtain mirrored data;

[0143] The mirror data is analyzed and processed to obtain protocol information, and connection table information is generated according to the protocol information.

[0144] In an exemplary embodiment of the present invention, the method further comprises:

[0145] The connection table information is acquired at preset time intervals and stored.

[0146] In an exemplary embodiment of the present invention, the determining of a policy control rule corresponding to the application according to the connection table information includes:

[0147] Acquire management name information in the management configuration information, and determine application name information in the connection table information according to protocol information in the connection table information;

[0148] The same management name information is determined according to the application name information, and a policy control rule is determined according to the management configuration information of the same management name information.

[0149] In an exemplary embodiment of the present invention, establishing a service quality level corresponding to the application based on the policy control rule includes:

[0150] If the policy control rule is a policy control rule for a blacklist application, a processing rule is established for discarding the service quality level of the message;

[0151] If the policy control rule is a policy control rule for whitelist application, a processing rule is established as a service quality level of priority forwarding.

[0152] In an exemplary embodiment of the present invention, the method further comprises:

[0153] Obtaining the end time of the priority forwarding processing for the whitelist application, and obtaining a time threshold corresponding to the end time;

[0154] If the end time is greater than the time threshold, the service quality level of the whitelist application is deleted.

[0155] The specific details of the above-mentioned application management device 900 have been described in detail in the corresponding application management method, so they will not be repeated here.

[0156] It should be noted that although several modules or units of the application management device 900 are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiment of the present disclosure, the features and functions of two or more modules or units described above can be concretized in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units for concretization.

[0157] In addition, in an exemplary embodiment of the present disclosure, an electronic device capable of implementing the above method is also provided.

[0158] Refer to the following Fig.10 The electronic device 1000 according to such an embodiment of the present invention will be described. Fig.10 The electronic device 1000 shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0159] like Fig.10 As shown, the electronic device 1000 is in the form of a general computing device. The components of the electronic device 1000 may include but are not limited to: the at least one processing unit 1010, the at least one storage unit 1020, a bus 1030 connecting different system components (including the storage unit 1020 and the processing unit 1010), and a display unit 1040.

[0160] The storage unit stores program codes, which can be executed by the processing unit 1010, so that the processing unit 1010 executes the steps according to various exemplary embodiments of the present invention described in the above “Exemplary Method” section of this specification.

[0161] The storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 1021 and / or a cache memory unit 1022 , and may further include a read-only memory unit (ROM) 1023 .

[0162] The storage unit 1020 may also include a program / utility 1024 having a set (at least one) of program modules 1025, such program modules 1025 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0163] Bus 1030 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0164] The electronic device 1000 may also communicate with one or more external devices 1200 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1000, and / or communicate with any device that enables the electronic device 1000 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 1050. Furthermore, the electronic device 1000 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 1060. As shown, the network adapter 1040 communicates with other modules of the electronic device 1000 via a bus 1030. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0165] Through the description of the above embodiments, it is easy for those skilled in the art to understand that the example embodiments described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the embodiment of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, and includes several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiment of the present disclosure.

[0166] In an exemplary embodiment of the present disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the above method of the present specification is stored. In some possible embodiments, various aspects of the present invention can also be implemented in the form of a program product, which includes a program code, and when the program product is run on a terminal device, the program code is used to enable the terminal device to perform the steps according to various exemplary embodiments of the present invention described in the above "Exemplary Method" section of the present specification.

[0167] refer to Fig.11 As shown, a program product 1100 for implementing the above method according to an embodiment of the present invention is described, which can adopt a portable compact disk read-only memory (CD-ROM) and include program code, and can be run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, a readable storage medium can be any tangible medium containing or storing a program, which can be used by or in combination with an instruction execution system, an apparatus or a device.

[0168] The program product may use any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0169] Computer readable signal media may include data signals propagated in baseband or as part of a carrier wave, in which readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Readable signal media may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0170] The program code embodied on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0171] Program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0172] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary technical means in the art that are not disclosed in the present disclosure. The specification and examples are to be considered as exemplary only, and the true scope and spirit of the present disclosure are indicated by the claims.

Claims

1. An application management method, characterized in that: The method comprises: Obtaining management configuration information of an application and obtaining service data corresponding to the application; the management configuration information includes: management configuration information determined according to package authority information corresponding to the application and management configuration information generated by autonomous configuration processing of the application; the management configuration information is used to determine policy control rules; The service data is parsed to generate connection table information, and a policy control rule corresponding to the application is determined according to the connection table information; the policy control rule corresponding to the application according to the connection table information comprises: obtaining management name information in the management configuration information, and determining application name information in the connection table information according to protocol information in the connection table information; determining the same management name information according to the application name information, and determining the policy control rule according to the management configuration information of the same management name information; Establishing a quality of service level corresponding to the application based on the policy control rule, and processing the application using the quality of service level; The parsing of the business data to generate connection table information includes: Performing data mirroring processing on the business data to obtain mirrored data; Analyzing and processing the mirror data to obtain protocol information, and generating connection table information according to the protocol information; The establishing of a service quality level corresponding to the application based on the policy control rule comprises: If the policy control rule is a policy control rule for a blacklist application, a processing rule is established for discarding the service quality level of the message; If the policy control rule is a policy control rule for whitelist application, a processing rule is established as a service quality level of priority forwarding; The method further comprises: Obtaining the end time of the priority forwarding processing for the whitelist application, and obtaining a time threshold corresponding to the end time; If the end time is greater than the time threshold, the service quality level of the whitelist application is deleted.

2. The application management method according to claim 1, characterized in that: The method further comprises: The connection table information is acquired at preset time intervals and stored.

3. An application management device, characterized in that: include: An information acquisition module, configured to acquire management configuration information of an application program and acquire business data corresponding to the application program; The management configuration information includes: management configuration information determined according to the package authority information corresponding to the application and management configuration information generated by autonomous configuration processing of the application; the management configuration information is used to determine the policy control rules; A rule determination module is configured to parse the business data to generate connection table information, and determine the policy control rule corresponding to the application according to the connection table information; the determination of the policy control rule corresponding to the application according to the connection table information is configured to: obtain the management name information in the management configuration information, and determine the application name information in the connection table information according to the protocol information in the connection table information; determine the same management name information according to the application name information, and determine the policy control rule according to the management configuration information of the same management name information; an application processing module, configured to establish a service quality level corresponding to the application program based on the policy control rule, and process the application program using the service quality level; The parsing of the business data to generate connection table information is configured as follows: Performing data mirroring processing on the business data to obtain mirrored data; Analyzing and processing the mirror data to obtain protocol information, and generating connection table information according to the protocol information; The establishing of a service quality level corresponding to the application program based on the policy control rule is configured as follows: If the policy control rule is a policy control rule for a blacklist application, a processing rule is established for discarding the service quality level of the message; If the policy control rule is a policy control rule for whitelist application, a processing rule is established as a service quality level of priority forwarding; The device is also configured to: Obtaining the end time of the priority forwarding processing for the whitelist application, and obtaining a time threshold corresponding to the end time; If the end time is greater than the time threshold, the service quality level of the whitelist application is deleted.

4. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the application management method described in any one of claims 1 to 2 is implemented.

5. An electronic device, characterized in that: include: processor; A memory, configured to store executable instructions of the processor; The processor is configured to execute the application management method according to any one of claims 1 to 2 by executing the executable instructions.

Citation Information

Patent Citations

  • Method and device for controlling quality-of-service level of wireless local area network

    CN104427556A

  • Policy-based application management

    WO2014084967A1