Access control method and device
By allocating specific IP addresses and routes to user devices, the problem of unreasonable occupation of gateway network resources is solved, the rational allocation and use of network resources is achieved, and the processing efficiency of network equipment is improved.
Patent Information
- Application Number
- CN202010837047.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-19
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2040-08-19
AI Technical Summary
When multiple user devices correspond to the same active/standby gateway relationship, the network resources of the gateway may be unreasonably occupied, resulting in unbalanced allocation of network resources.
By assigning specific IP addresses and routes to user devices, the primary and backup gateways use different IP address segments to avoid resource sharing. A virtual BNG CP module is used to centrally manage IP address allocation in CU separation scenarios, or to perform access control on the BNG in CU-unseparated scenarios.
It effectively avoids the unreasonable occupation of gateway network resources, ensures the reasonable allocation and use of network resources, and improves the processing efficiency of network equipment.
Smart Images

Figure CN114079586B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to an access control method and device. Background Art
[0002] A user device can access the network through a gateway, such as a broadband network gateway (BNG). In some scenarios, a user device can access the network through two gateways, one of which is the primary gateway and the other is the backup gateway. When the primary gateway is available, the user device accesses the network using the primary gateway. When the primary gateway is unavailable, the user device accesses the network using the backup gateway.
[0003] When multiple user devices are associated with the same two gateways in a primary-backup relationship, the primary gateways corresponding to each user device may not be exactly the same. For example, for a first gateway and a second gateway in a primary-backup relationship, the first user's primary gateway is the first gateway and the backup gateway is the second gateway. The second user's primary gateway is the second gateway and the backup gateway is the first gateway. In this case, the network resources of one gateway may be unnecessarily occupied. Summary of the Invention
[0004] The embodiment of the present application provides an access control method, which can prevent the network resources of the gateway from being unreasonable occupied.
[0005] In a first aspect, embodiments of the present application provide an access control method that can be performed by a BNG CP. In one example, the BNG CP may receive a first message from a first user equipment (UE), requesting the first UE access a network. The first message is used by the first UE to access the network using a first BNG as its primary gateway and a second BNG as its backup gateway. Upon receiving the first message, the BNG CP may determine the IP address assigned to the first UE from a first network segment and send the IP address to the first UE. In this embodiment, the first network segment is used only to assign IP addresses to UEs that access the network using the first BNG as its primary gateway and the second BNG as its backup gateway. In other words, the first network segment is not used to assign IP addresses to UEs that access the network using the first BNG as its backup gateway and the second BNG as its primary gateway. Therefore, using the solution of this embodiment, even if the first BNG initially allows the UE to access the network, the network resources of the first BNG will not be unreasonably occupied.
[0006] In one implementation, the first BNG can form a master-slave relationship with multiple BNGs. For example, the first BNG and the second BNG can form a master-slave relationship; in another example, the first BNG and the third BNG can also form a master-slave relationship. To prevent unreasonable occupation of BNG network resources, for user devices that use the first BNG as the primary gateway and the third BNG as the backup gateway, an IP address can be assigned using the second network segment, where the first network segment and the second network segment are different. In this case, the BNG CP of the first BNG can also be the IP address of the second user device. In one example, the BNG CP of the first BNG can receive a second message from the second user device and determine the IP address assigned to the second user device from the second network segment. After the BNG CP of the first BNG determines the IP address assigned to the second user device, it can send the IP address of the second user device to the second user device.
[0007] In one implementation, the solution of the embodiments of the present application can be applied to a CU-separated network scenario, where the CP of the first BNG runs on a device independent of the first BNG. In this case, the BNG CP that executes the access control method can be a virtual BNG CP module.
[0008] In one implementation, the solution of the embodiment of the present application can be applied to a scenario where the CU is not separated, that is, the CP of the first BNG and the UP of the first BNG both run on the first BNG CP. In this case, the BNGCP that performs the access control method can run on the first BNG CP.
[0009] In one implementation, if the solution of the embodiments of the present application is applied to a network scenario with CU separation, the first BNG and the second BNG may correspond to the same vBNG CP module. In this case, the vBNG CP may also allocate an IP address to a third user device, where the third user device is a user device that uses the second BNG as the primary gateway and the first BNG as the backup gateway to access the network. In one example, the vBNG CP module may receive a third message from the third user device and determine the IP address allocated to the third user device from the third network segment. After the vBNG CP module determines the IP address allocated to the third user device, it may send the IP address of the third user device to the third user device.
[0010] In one implementation, the BNG CP may pre-acquire a correspondence between a primary gateway, a backup gateway, and a network segment. Upon receiving a message requesting network access for a user device, the BNG CP may allocate an IP address to the user device from the corresponding network segment based on the correspondence. This correspondence may include a correspondence between the first BNG, the second BNG, and the first network segment. Upon receiving the first message, the IP address allocated to the first user device may be determined from the first network segment. This correspondence may include a correspondence between the first BNG, the third BNG, and the second network segment. Upon receiving the second message, the IP address allocated to the second user device may be determined from the second network segment. This correspondence may include a correspondence between the second BNG, the first BNG, and the third network segment. Upon receiving the third message, the IP address allocated to the third user device may be determined from the third network segment.
[0011] In one implementation, when the solution of the embodiment of the present application is applied to a network scenario with CU separation, the BNG CP is a virtual BNG CP module. In this case, the virtual BNG CP module can send the IP address of the first user device to the first user device via the first BNG. In other words, the virtual BNG CP module can send the IP address of the first user device to the first BNG. After receiving the IP address of the first user device, the first BNG can send the IP address of the first user device to the first user device. In addition, the first BNG can also publish the corresponding first network segment route as the primary route to reach the first user device to other network devices, so that other network devices can use this route to send data to the first user device. In addition, the second BNG can publish the corresponding first network segment route as a backup route to reach the first user device to other network devices.
[0012] In one implementation, when the solution of the embodiments of the present application is applied to a network scenario where CUs are not separated, the BNG CP runs on a first BNG. The BNG CP may further publish the route corresponding to the first network segment as the primary route to the first user equipment to other network devices, so that the other network devices can use the route to send data to the first user equipment. The route corresponding to the first network segment is the route that passes through the first BNG to reach the first user equipment.
[0013] In a second aspect, an embodiment of the present application provides an access control device, which is applied to a broadband network gateway control plane BNG CP, and the device includes: a receiving unit, used to receive a first message from a first user device, the first message being used to request the first user device to access the network, the primary gateway for the first user device to access the network is the first BNG, and the backup gateway for the first user device to access the network is the second BNG; a determination unit, used to determine, based on the first message, an Internet Protocol IP address allocated to the first user device from a first network segment, the first network segment being used to allocate an IP address to a user device that accesses the network with the first BNG as the primary gateway and the second BNG as the backup gateway, and the first network segment is not used to allocate an IP address to a user device that uses the first BNG as the backup gateway and the second BNG as the primary gateway; a sending unit, used to send the IP address of the first user device to the first user device.
[0014] In one implementation, the receiving unit is further used to receive a second message from a second user device, where the second message is used to request the second user device to access the network, where the primary gateway for the second user device to access the network is the first BNG, and the backup gateway for the second user device to access the network is the third BNG; the determining unit is further used to determine, based on the second message, an IP address allocated to the second user device from a second network segment, where the second network segment is used to allocate an IP address to a user device that accesses the network with the first BNG as the primary gateway and the third BNG as the backup gateway, and the first network segment is different from the second network segment; the sending unit is further used to send the IP address of the second user device to the second user device.
[0015] In one implementation, the BNG CP is a virtual BNG CP module, or the BNG CP runs on the first BNG.
[0016] In one implementation, when the BNG CP is a virtual BNG CP module, the receiving unit is further configured to receive a third message from a third user equipment, the third message being used to request the third user equipment to access a network, the active BNG used by the third user equipment to access the network being the second BNG, and the backup BNG used by the third user equipment to access the network being the first BNG; the determining unit is further configured to determine, based on the third message, an IP address to be allocated to the third user equipment from a third network segment, the third network segment being used to allocate an IP address to a user equipment that accesses the network using the second BNG as an active gateway and the first BNG as a backup gateway, the first network segment, the second network segment, and the third network segment being different, and the second network segment being used to allocate an IP address to a user equipment that accesses the network using the first BNG as an active gateway and the third BNG as a backup gateway; and the sending unit is further configured to send the IP address of the third user equipment to the third user equipment.
[0017] In one implementation, the device further includes: an acquisition unit, configured to acquire a correspondence between a primary gateway, a backup gateway, and a network segment, the correspondence including one or more of the following: a correspondence between the first BNG, the second BNG, and the first network segment; and a correspondence between the first BNG, the third BNG, and the second network segment; and a correspondence between the second BNG, the first BNG, and the third network segment.
[0018] In an implementation, when the BNG CP is a virtual BNG CP module, the sending unit is configured to send the IP address of the first user equipment to the first user equipment via the first BNG.
[0019] In one implementation, when the BNG CP runs on the first BNG, the sending unit is further used to: publish the route corresponding to the first network segment as the primary route to reach the first user equipment to other network devices, and the route corresponding to the first network segment is the route to reach the first user equipment through the first BNG.
[0020] In a third aspect, an embodiment of the present application provides a device. The device includes a processor and a memory. The memory is configured to store instructions or computer programs. The processor is configured to execute the instructions or computer programs in the memory to perform any of the methods described in the first aspect above.
[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, comprising instructions or a computer program, which, when executed on a computer, enables the computer to execute any one of the methods described in the first aspect above.
[0022] In a fifth aspect, an embodiment of the present application provides a computer program product comprising instructions or a computer program, which, when executed on a computer, enables the computer to execute any one of the methods described in the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0024] Figure 1 A schematic diagram of an exemplary application scenario provided in an embodiment of the present application;
[0025] Figure 2 A schematic diagram of the structure of a BNG provided in an embodiment of the present application;
[0026] Figure 3 A flowchart of an access control method provided in an embodiment of the present application;
[0027] Figure 4 A schematic diagram of an exemplary application scenario provided in an embodiment of the present application;
[0028] Figure 5 A schematic diagram of the structure of an access control device provided in an embodiment of the present application;
[0029] Figure 6 A schematic diagram of the structure of a device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0030] The embodiment of the present application provides an access control method, which can prevent the network resources of the gateway from being unreasonable occupied.
[0031] For ease of understanding, the possible application scenarios of the embodiments of the present application are first introduced.
[0032] See also Figure 1 , which is a schematic diagram of an exemplary application scenario provided in an embodiment of the present application.
[0033] exist Figure 1In the illustrated scenario, user equipment 101 can communicate with BNG 103 via access node (AN) 102. Furthermore, user equipment 101 can access the network via BNG 103. In some embodiments, the BNG functions similarly to a broadband remote access server (BRAS). In some embodiments, no other devices may be located between access node 102 and BNG 103. In some embodiments, a convergence node may be located between access node 102 and BNG 103.
[0034] When the user device 101 accesses the network through the BNG 103, the BNG 103 can authenticate the user device 101 and allocate an Internet Protocol (IP) address to the user device 101. Figure 2 To understand, Figure 2 A schematic diagram of the structure of a BNG provided in an embodiment of the present application.
[0035] Figure 2 The BNG shown may include an access management module 201, a session management module 202, an authentication and authorization accounting (AAA) management module 203, an address allocation module 204, and a service policy control module 205.
[0036] The access management module 201 and session management module 202 are used to process request messages from user devices. The AAA management module 204 is used to authenticate user devices and obtain information such as the user device's service level agreement (SLA). The address allocation module 204 is used to allocate IP addresses to user devices. The service policy control module 205 is used to determine the user device's quality of service (QoS).
[0037] The access management module 201, session management module 202, AAA management module 203, address allocation module 204 and service policy control module 205 belong to the control plane (CP) of the BNG, which can also be called a control plane.
[0038] Figure 2The BNG shown may also include a user plane (UP) 207, which may also be referred to as a forwarding plane or forwarding plane. The user plane includes functional modules for implementing data forwarding and functional modules that interact with the control plane, such as a routing control module and a forwarding control module.
[0039] In one example, a user device can send a request message to the BNG, requesting network access. After receiving the request message, the BNG's forwarding plane sends it to the access management module 201 of the control plane. The access management module 201 and session management module 202 of the control plane process the received request message and, after authenticating the user device using the AAA management module 203, the address allocation module 204 allocates an IP address to the user device. After allocating the IP address to the user device, the address allocation module 204 sends the IP address to the user plane via the access management module 201, which then sends the IP address to the user device.
[0040] In addition, the control plane also needs to send the network segment route corresponding to the IP address to the user plane, and the user plane sends the network segment route to other forwarding devices in the network, such as network devices in the core network, so that the network devices that receive the network segment route can forward the data to the user device through the network segment route.
[0041] With the advancement of network technology, the control plane of the BNG can be separated from the BNG and deployed on other devices, such as control management devices or servers. In other words, the control plane and user plane of the BNG are separated, referred to as CU (control plane and user plane) separation. In the CU separation scenario, the control plane separated from the BNG and deployed on other devices can also be called a virtual broadband network gateway control plane (vBNG CP) module. In the CU separation scenario, a vBNG CP module can correspond to multiple BNGs. In other words, a vBNG CP module can process request messages from multiple BNGs for user equipment to access the network and allocate IP addresses to the user equipment corresponding to the request messages based on the request messages.
[0042] The functions of the vBNG CP module are similar to those of the BNG control plane. For details, refer to the description of the BNG control plane above and will not be repeated here.
[0043] The interaction between the vBNG CP module and the BNG is actually the interaction between the vBNG CP module and the BNG UP. For details, please refer to the description of the interaction between the control plane and user plane of the BNG above, and will not be repeated here.
[0044] In some network scenarios, a user device may correspond to two gateways, one of which is the primary gateway and the other is the backup gateway. When multiple user devices correspond to the same two gateways in a primary-backup relationship, the primary gateways corresponding to each user device may not be exactly the same. For example, for a first BNG and a second BNG in a primary-backup relationship, the primary gateway for the first user is the first BNG and the backup gateway is the second BNG; the primary gateway for the second user is the second BNG and the backup gateway is the first BNG. In this case, the first BNG and the second BNG share a network segment, such as network segment 1. The control plane of the first BNG uses network segment 1 to assign IP addresses to user devices with the first BNG as the primary gateway, and the control plane of the second BNG uses network segment 1 to assign IP addresses to user devices with the second BNG as the primary gateway.
[0045] In the case where the first BNG and the second BNG share network segment 1, if the first BNG allows the user device to access the network first, the first BNG's network resources will be unreasonably occupied. If the second BNG allows the user device to access the network first, the second BNG's network resources will be unreasonably occupied. The following example uses the example of the first BNG allowing the user device to access the network first:
[0046] For user device A, which uses the first BNG as the primary route, after receiving an access request from user device A, the control plane of the first BNG will assign an IP address to user device A using network segment 1. Accordingly, the forwarding plane of the first BNG can advertise route 1, corresponding to network segment 1, to other devices as the primary route to user device A. The forwarding path indicated by route 1 passes through the first BNG. The forwarding plane of the second BNG can advertise route 2, corresponding to network segment 1, to other devices as the backup route to user device A. The forwarding path indicated by route 2 passes through the second BNG.
[0047] After user device A accesses the network through the first BNG, if user device B, using the second BNG as its primary gateway, requests network access, the second BNG's control plane will assign an IP address to user device B using network segment 1. In this case, since both the primary and backup routes corresponding to network segment 1 have already been published, if other devices on the network send a message to user device B, the message will first be sent to the first BNG. After parsing the message and determining that user device B's primary gateway is the second BNG, the first BNG will forward the message to the second BNG, which will then forward it to user device B. This shows that the message sent by the network device to user device B is forwarded by the first BNG, user device B's backup gateway, to the second BNG, user device B's primary gateway, resulting in unreasonable usage of the first BNG's network resources.
[0048] In the above example, the control plane of the first BNG can run on the first BNG, that is, the CU is not separated. The control plane of the first BNG can also run on other devices, that is, the CU is separated. In the CU separation scenario, the control plane of the first BNG and the control plane of the second BNG can correspond to the same vBNG CP module.
[0049] It should be noted that in a CU-separated scenario, the forwarding plane of the first BNG can, for example, receive the IP address of the user device from the vBNG CP module and publish route 1 corresponding to network segment 1 as the primary route to user device A to other devices. Correspondingly, the forwarding plane of the second BNG can publish route 2 corresponding to network segment 1 as the backup route to user device A to other devices.
[0050] In order to solve the problem of unreasonable occupation of the network resources of the first BNG, an embodiment of the present application provides an access control method, which is described below with reference to the accompanying drawings.
[0051] The user devices mentioned in the embodiments of the present application may include mobile terminals such as smart phones and tablet computers, and may also include terminal devices such as personal computers and smart TVs, and the embodiments of the present application do not make specific limitations.
[0052] See also Figure 3 , which is a flow chart of an access control method provided in an embodiment of the present application.
[0053] Figure 3 The method shown can be performed by a BNG CP. In a scenario where the CU is not separated, the BNG CP can run on the BNG. In a scenario where the CU is separated, the BNG CP can be a vBNG CP module running on a device independent of the BNG. The method may include the following steps:
[0054] S101: Receive a first message from a first user equipment, where the first message is used to request the first user equipment to access a network. The primary gateway used by the first user equipment to access the network is a first BNG, and the backup gateway used by the first user equipment to access the network is a second BNG.
[0055] In some embodiments, the first user equipment may send the first message to the BNG CP via a residential gateway (RG) and an access node. In a scenario where the CU is separated, the first user equipment may send the first message to the RG, which then sends the first message to the AN, which then sends the first message to the BNG, which then sends the first message to the vBNG CP module. In a scenario where the CU is not separated, the first user equipment may send the first message to the RG, which then sends the first message to the AN, which then sends the first message to the BNG UP, which then sends the first message to the BNG CP.
[0056] In an embodiment of the present application, the first message is used to request the first user equipment to access the network. The first message can be a Point to Point Protocol over Ethernet (PPPoE) message or an Internet Protocol over Ethernet (IPoE) message, which is not specifically limited in this embodiment of the present application.
[0057] In an embodiment of the present application, the gateway for a first user equipment to access a network includes a first BNG and a second BNG, wherein the first BNG is the primary gateway for the first user equipment to access the network, and the second BNG is the backup gateway for the first user equipment to access the network. In some embodiments, the first user equipment may send a first message to the BNG CP of the first BNG and the BNG CP of the second BNG, and the BNG CP of the first BNG and the BNG CP of the second BNG may determine whether it is the primary gateway or the backup gateway for the first user equipment. As an example, the BNG CP of the first BNG and the BNG CP of the second BNG may determine whether it is the primary gateway or the backup gateway for the first user equipment based on the media access control (MAC) address of the first user equipment. As another example, the BNG CP of the first BNG and the BNG CP of the second BNG may determine whether it is the primary gateway or the backup gateway for the first user equipment based on the user identifier of the first user equipment.
[0058] In this embodiment of the present application, steps S101-S103 are executed by the BNG CP of the primary gateway of the first user equipment, that is, by the BNG CP of the first BNG. If the CU is separated, steps S101-S103 are executed by the vBNG CP module, which runs on a device independent of the first BNG. If the CU is not separated, steps S102 and S103 are executed by the BNG CP of the first BNG.
[0059] S102: Determine an IP address allocated to a first user equipment from a first network segment according to the first message, where the first network segment is used to allocate IP addresses to user equipment that accesses a network using a first BNG as a primary gateway and a second BNG as a backup gateway.
[0060] After receiving the first message, the BNG CP of the first BNG can allocate an IP address to the first user equipment. In this embodiment of the present application, to prevent the first and second BNGs from sharing a network segment, which could lead to undue occupation of the network resources of one of the BNGs mentioned above, the first and second BNGs no longer share the same network segment. Instead, network segments are associated with active and backup gateways. When the first BNG is the active gateway and the second BNG is the backup gateway, it corresponds to the first network segment. This first network segment is only used to allocate IP addresses to user equipment with the first BNG as the active gateway and the second BNG as the backup gateway. In other words, the first network segment no longer allocates IP addresses to user equipment with the first BNG as the backup gateway and the second BNG as the active gateway. In one example, for user equipment with the first BNG as the backup gateway and the second BNG as the active gateway, a network segment different from the first network segment can be used to allocate IP addresses to them. For example, a third network segment can be used to allocate IP addresses to user equipment with the first BNG as the backup gateway and the second BNG as the active gateway.
[0061] In one implementation of the embodiment of the present application, the BNG CP of the first BNG may determine the first network segment based on a predetermined correspondence between the primary gateway, the backup gateway, and the network segment, and further determine the IP address to allocate to the first user equipment from the first network segment. The correspondence includes at least a correspondence between the first BNG, the second BNG, and the first network segment.
[0062] S103: Send the IP address of the first user equipment to the first user equipment.
[0063] After the BNG CP of the first BNG determines the IP address allocated to the first user equipment, it may send the IP address of the first user equipment to the first user equipment so that the first user equipment can access the network using the IP address. The IP address of the first user equipment mentioned here is the IP address allocated to the first user equipment determined by the BNG CP of the first BNG in S102.
[0064] In this embodiment of the present application, if the BNG CP is a virtual BNG CP module, that is, in a CU separation scenario, the virtual BNG CP module may send the IP address of the first user equipment to the first user equipment via the first BNG. In other words, the virtual BNG CP module may send the IP address of the first user equipment to the first BNG. After receiving the IP address of the first user equipment, the first BNG may send the IP address of the first user equipment to the first user equipment.
[0065] In addition, the first BNG can also publish the route corresponding to the first network segment as the primary route to the first user device to other network devices, so that other network devices can use this route to send data to the first user device. Correspondingly, the second BNG can publish the route corresponding to the first network segment as the backup route to the first user device to other network devices.
[0066] As can be seen from the above description, since the first and second BNGs no longer share the same network segment, user devices with the first BNG as the primary gateway and the second BNG as the backup gateway can use the first network segment to assign IP addresses; user devices with the first BNG as the backup gateway and the second BNG as the primary gateway can use the third network segment to assign IP addresses. Even if the first BNG initially allows the first user device to access the network, since the routes advertised by the first BNG correspond to the first network segment, when the second BNG allows a user device, such as a third user device, to access the network, the routes advertised by the second BNG correspond to the third network segment, rather than the first network segment as in conventional technology. Therefore, when a network device sends a message to the third user device, the message can be sent to the third user device via the second BNG, rather than being forwarded to the first BNG and then to the second BNG. This prevents undue occupation of the first BNG's network resources.
[0067] In an embodiment of the present application, if the CUs are separated, the first and second BNGs may correspond to the same vBNG CP module. If the aforementioned S101-S103 are performed by the vBNG CP module, the vBNG CP may also allocate an IP address to a third user device, where the third user device is a user device that uses the second BNG as the primary gateway and the first BNG as the backup gateway to access the network. In one example, the vBNG CP module may receive a third message from the third user device and determine the IP address allocated to the third user device from the third network segment. After determining the IP address allocated to the third user device, the vBNG CP module may send the IP address of the third user device to the third user device.
[0068] Regarding the specific implementation of the vBNG CP module receiving the third message from the third user equipment, its principle is similar to the implementation principle of the vBNG CP module receiving the first message from the first user equipment. Therefore, the specific implementation of the vBNG CP module receiving the third message from the third user equipment can be referred to the description of S101 above and will not be detailed here.
[0069] Regarding the third network segment, please refer to the description of the third network segment in S102 above, and the description will not be repeated here.
[0070] After the vBNG CP module determines the IP address allocated to the third user device from the third network segment, it can send the IP address of the third user device to the third user device via the second BNG. In other words, the virtual BNG CP module can send the IP address of the third user device to the second BNG. After receiving the IP address of the third user device, the second BNG can send the IP address of the third user device to the third user device.
[0071] In addition, the second BNG can also publish the route corresponding to the third network segment as the primary route to the third user device to other network devices, so that other network devices can use this route to send data to the third user device. In addition, the first BNG can publish the route corresponding to the third network segment as the backup route to the third user device to other network devices.
[0072] In some embodiments, the first BNG can form a master-slave relationship with multiple BNGs. For example, as described above, the first BNG and the second BNG can form a master-slave relationship; in another example, the first BNG and the third BNG can also form a master-slave relationship. To prevent unreasonable occupation of BNG network resources, in an embodiment of the present application, for user devices using the first BNG as the primary gateway and the third BNG as the backup gateway, an IP address can be assigned using the second network segment, where the first network segment, the second network segment, and the third network segment are different. In this case, the BNG CP of the first BNG can also be the IP address of the second user device. In one example, the BNG CP of the first BNG can receive a second message from the second user device and determine the IP address assigned to the second user device from the second network segment. After determining the IP address assigned to the second user device, the BNG CP of the first BNG can send the IP address of the second user device to the second user device.
[0073] Regarding the specific implementation of the BNG CP of the first BNG receiving the second message from the second user equipment, its principle is similar to the implementation principle of the BNG CP of the first BNG receiving the first message from the first user equipment. Therefore, the specific implementation of the BNG CP of the first BNG receiving the second message from the second user equipment can be referred to the description of S101 above and will not be described in detail here.
[0074] After the BNG CP of the first BNG determines the IP address to be allocated to the second UE from the second network segment, it can send the IP address of the second UE to the second UE via the first BNG. In other words, the virtual BNG CP module can send the IP address of the second UE to the first BNG. After receiving the IP address of the second UE, the first BNG can send the IP address of the second UE to the second UE.
[0075] In addition, the first BNG can also publish the route corresponding to the second network segment as the primary route to the second user device to other network devices, so that other network devices can use this route to send data to the second user device. In addition, the third BNG can publish the route corresponding to the second network segment as the backup route to the second user device to other network devices.
[0076] The access control method provided in the embodiment of the present application is introduced above. Next, the method provided in the embodiment of the present application is introduced in combination with specific application scenarios.
[0077] See also Figure 4 , which is a schematic diagram of an exemplary application scenario provided by the embodiment of this application. Figure 4In the scenario shown, CU is separated and vBNG CP module 401 runs on the network management device. vBNG CP module 401 corresponds to multiple BNGs, such as Figure 4 As shown, vBNG CP module 401 corresponds to BNG 402 , BNG 403 , and BNG 404 .
[0078] exist Figure 4 In the scenario shown, BNG 402 and BNG 403 are in a master-slave relationship, and BNG 402 and BNG 404 are in a master-slave relationship. The vBNG CP module 401 pre-stores the corresponding relationship shown in Table 1 below.
[0079] Table 1
[0080] Primary gateway Backup Gateway network segment BNG 402 BNG 403 Network segment 1 BNG 402 BNG 404 Network segment 2 BNG 403 BNG 402 Network segment 3
[0081] Regarding Table 1, it should be noted that network segment 1 is used to allocate IP addresses to user devices that access the network using BNG 402 as the primary gateway and BNG 403 as the backup gateway; network segment 2 is used to allocate IP addresses to user devices that access the network using BNG 402 as the primary gateway and BNG 404 as the backup gateway; and network segment 3 is used to allocate IP addresses to user devices that access the network using BNG 403 as the primary gateway and BNG 404 as the backup gateway.
[0082] vBNG CP module 401 can execute the access control methods provided in the above embodiments of this application to assign IP addresses to user devices accessing the network through BNG 402 or BNG 403. When vBNG CP module 401 can execute the access control methods provided in the above embodiments of this application, BNG 402 can correspond to the first BNG in the above embodiments, BNG 403 can correspond to the second BNG in the above embodiments, and BNG 404 can correspond to the third BNG in the above embodiments. Network segment 1 can correspond to the first network segment in the above embodiments, network segment 2 can correspond to the second network segment in the above embodiments, and network segment 3 can correspond to the third network segment in the above embodiments.
[0083] Based on the access control method provided in the above embodiment, the embodiment of the present application also provides a corresponding device, which is described below with reference to the accompanying drawings.
[0084] See also Figure 5 , which is a structural diagram of an access control device provided in an embodiment of the present application. Figure 5 The access control device 500 shown in the figure can be applied to a BNG CP, for example, to execute the access control method executed by the BNG CP in the above method embodiment. Figure 5As shown, the access control device 500 includes: a receiving unit 501 , a determining unit 502 and a sending unit 503 .
[0085] The receiving unit 501 is used to receive a first message from a first user device, where the first message is used to request the first user device to access a network. The primary gateway for the first user device to access the network is a first BNG, and the backup gateway for the first user device to access the network is a second BNG.
[0086] The determination unit 502 is used to determine the Internet Protocol IP address allocated to the first user equipment from the first network segment based on the first message, where the first network segment is used to allocate IP addresses to user equipment that accesses the network with the first BNG as the primary gateway and the second BNG as the backup gateway, and the first network segment is not used to allocate IP addresses to user equipment that uses the first BNG as the backup gateway and the second BNG as the primary gateway.
[0087] The sending unit 503 is configured to send the IP address of the first user equipment to the first user equipment.
[0088] In one implementation,
[0089] The receiving unit 501 is also used to receive a second message from a second user equipment, where the second message is used to request the second user equipment to access the network, the primary gateway for the second user equipment to access the network is the first BNG, and the backup gateway for the second user equipment to access the network is the third BNG.
[0090] The determination unit 502 is further used to determine the IP address allocated to the second user equipment from the second network segment based on the second message, the second network segment is used to allocate an IP address to the user equipment that accesses the network with the first BNG as the main gateway and the third BNG as the backup gateway, and the first network segment is different from the second network segment.
[0091] The sending unit 503 is further configured to send the IP address of the second user equipment to the second user equipment.
[0092] In one implementation, the BNG CP is a virtual BNG CP module, or the BNG CP runs on the first BNG.
[0093] In one implementation, when the BNG CP is a virtual BNG CP module,
[0094] The receiving unit 501 is further used to receive a third message from a third user equipment, where the third message is used to request the third user to access the network. The primary BNG used by the third user equipment to access the network is the second BNG, and the backup BNG used by the third user equipment to access the network is the first BNG.
[0095] The determination unit 502 is further used to determine, based on the third message, an IP address allocated to the third user equipment from a third network segment, where the third network segment is used to allocate an IP address to a user equipment that accesses the network using the second BNG as a primary gateway and the first BNG as a backup gateway, the first network segment, the second network segment, and the third network segment are different, and the second network segment is used to allocate an IP address to a user equipment that accesses the network using the first BNG as a primary gateway and the third BNG as a backup gateway.
[0096] The sending unit 503 is further configured to send the IP address of the third user equipment to the third user equipment.
[0097] In one implementation, the apparatus further includes: an acquisition unit.
[0098] The acquiring unit is configured to acquire a correspondence between the primary gateway, the backup gateway, and the network segment, wherein the correspondence includes one or more of the following:
[0099] The correspondence between the first BNG, the second BNG, and the first network segment; and
[0100] The correspondence between the first BNG, the third BNG and the second network segment; and
[0101] A correspondence between the second BNG, the first BNG, and the third network segment.
[0102] In one implementation, when the BNG CP is a virtual BNG CP module, the sending unit 503 is configured to:
[0103] The IP address of the first user equipment is sent to the first user equipment via the first BNG.
[0104] In one implementation, when the BNG CP runs on the first BNG, the sending unit 503 is further configured to:
[0105] The route corresponding to the first network segment is published as a primary route to the first user equipment to other network devices, where the route corresponding to the first network segment is a route to the first user equipment via the first BNG.
[0106] Since the device 500 is a device corresponding to the routing processing method provided in the above method embodiment, the specific implementation of each unit of the device 500 is based on the same concept as the above method embodiment. Therefore, regarding the specific implementation of each unit of the device 500, reference can be made to the description of the access control method in the above method embodiment, which will not be repeated here.
[0107] It should be noted that the hardware structure of the access control device 500 mentioned above can be as follows: Figure 6 The structure shown, Figure 6 A schematic diagram of the structure of a device provided in an embodiment of the present application.
[0108] See also Figure 6 As shown, the device 600 includes: a processor 610, a communication interface 620 and a memory 630. The number of the processor 610 in the device 600 can be one or more. Figure 6 In the embodiment of the present application, the processor 610, the communication interface 620 and the memory 630 may be connected via a bus system or other means, wherein: Figure 6 The connection via bus system 640 is taken as an example.
[0109] Processor 610 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. Processor 610 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0110] Memory 630 may include volatile memory, such as random-access memory (RAM); non-volatile memory, such as flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or a combination of these types of memory. Memory 630 may, for example, store the aforementioned correspondence between the primary gateway, backup gateway, and network segment.
[0111] Optionally, the memory 630 stores an operating system and programs, executable modules, or data structures, or subsets thereof, or extended sets thereof. The programs may include various operating instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and processing hardware-based tasks. The processor 610 may read the programs in the memory 630 to implement the access control method provided in the embodiments of the present application.
[0112] The bus system 640 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus system 640 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0113] An embodiment of the present application further provides a computer-readable storage medium, including instructions or a computer program, which, when executed on a computer, enables the computer to execute the access control method provided in the above embodiment.
[0114] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0115] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0116] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical business division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0117] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0118] In addition, each business unit in each embodiment of the present application can be integrated into a processing unit, each unit can exist physically separately, or two or more units can be integrated into a single unit. The above-mentioned integrated units can be implemented in the form of hardware or software business units.
[0119] If the integrated unit is implemented in the form of a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0120] Those skilled in the art will appreciate that, in one or more of the above examples, the services described herein can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these services can be stored on a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, including any medium that facilitates the transmission of computer programs from one location to another. Storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0121] The above specific implementation methods further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above are only specific implementation methods of the present invention.
[0122] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. An access control method, characterized in that: The method is performed by a broadband network gateway control plane (BNG CP), wherein the BNG CP is a virtual BNG CP module. The virtual BNG CP module is a control plane of the BNG in a scenario where the control plane and the user plane CU are separated. The method includes: receiving a first message from a first user equipment, where the first message is used to request the first user equipment to access a network, where a primary gateway for the first user equipment to access the network is a first BNG, and a backup gateway for the first user equipment to access the network is a second BNG; Determining, based on the first message, an Internet Protocol IP address to be allocated to the first user equipment from a first network segment, where the first network segment is used to allocate IP addresses to user equipment that accesses a network using the first BNG as an active gateway and the second BNG as a backup gateway, and the first network segment is not used to allocate IP addresses to user equipment that accesses a network using the second BNG as an active gateway and the first BNG as a backup gateway; Send the IP address of the first user equipment to the first user equipment.
2. The method according to claim 1, characterized in that The method further comprises: receiving a second message from a second user equipment, where the second message is used to request the second user equipment to access a network, where a primary gateway for the second user equipment to access the network is the first BNG, and a backup gateway for the second user equipment to access the network is a third BNG; Determining, according to the second message, an IP address to be allocated to the second user equipment from a second network segment, where the second network segment is used to allocate IP addresses to user equipment that accesses a network using the first BNG as an active gateway and the third BNG as a standby gateway, the first network segment being different from the second network segment; Send the IP address of the second user equipment to the second user equipment.
3. The method according to claim 1, characterized in that The method further comprises: receiving a third message from a third user equipment, where the third message is used to request the third user equipment to access a network, where the primary BNG used by the third user equipment to access the network is the second BNG, and the backup BNG used by the third user equipment to access the network is the first BNG; Determining, according to the third message, an IP address to be allocated to the third user equipment from a third network segment, the third network segment being used to allocate an IP address to a user equipment that accesses the network using the second BNG as a primary gateway and the first BNG as a backup gateway, the first network segment, the second network segment, and the third network segment being different, and the second network segment being used to allocate an IP address to a user equipment that accesses the network using the first BNG as a primary gateway and the third BNG as a backup gateway; The IP address of the third user equipment is sent to the third user equipment.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Obtain a correspondence between the primary gateway, the backup gateway, and the network segment, where the correspondence includes one or more of the following: The correspondence between the first BNG, the second BNG, and the first network segment; and The corresponding relationship between the first BNG, the third BNG and the second network segment; and The correspondence between the second BNG, the first BNG and the third network segment.
5. The method according to claim 1, wherein The sending the IP address of the first user equipment to the first user equipment includes: The IP address of the first user equipment is sent to the first user equipment via the first BNG.
6. An access control device, characterized in that: Applied to a broadband network gateway control plane BNG CP, the BNG CP is a virtual BNG CP module, the virtual BNG CP module is the control plane of the BNG in a scenario where the control plane and user plane CU are separated, and the device includes: a receiving unit, configured to receive a first message from a first user equipment, where the first message is used to request the first user equipment to access a network, where a primary gateway for the first user equipment to access the network is a first BNG, and a backup gateway for the first user equipment to access the network is a second BNG; a determining unit, configured to determine, based on the first message, an Internet Protocol IP address to be allocated to the first user equipment from a first network segment, the first network segment being used to allocate IP addresses to user equipment that accesses a network using a first BNG as a primary gateway and a second BNG as a backup gateway, and the first network segment not being used to allocate IP addresses to user equipment that uses the first BNG as a backup gateway and the second BNG as a primary gateway; A sending unit is configured to send the IP address of the first user equipment to the first user equipment.
7. The device according to claim 6, characterized in that The receiving unit is further configured to receive a second message from a second user equipment, where the second message is used to request the second user equipment to access a network, where the primary gateway for the second user equipment to access the network is the first BNG, and the backup gateway for the second user equipment to access the network is a third BNG; The determining unit is further configured to determine, based on the second message, an IP address to be allocated to the second user equipment from a second network segment, where the second network segment is used to allocate IP addresses to user equipment that accesses a network using the first BNG as a primary gateway and the third BNG as a backup gateway, the first network segment being different from the second network segment; The sending unit is further configured to send the IP address of the second user equipment to the second user equipment.
8. The device according to claim 6, characterized in that The receiving unit is further configured to receive a third message from a third user equipment, where the third message is used to request the third user equipment to access the network, the primary BNG used by the third user equipment to access the network is the second BNG, and the backup BNG used by the third user equipment to access the network is the first BNG; The determining unit is further configured to determine, based on the third message, an IP address to be allocated to the third user equipment from a third network segment, the third network segment being used to allocate an IP address to a user equipment that accesses the network using the second BNG as a primary gateway and the first BNG as a backup gateway, the first network segment, the second network segment, and the third network segment being different, and the second network segment being used to allocate an IP address to a user equipment that accesses the network using the first BNG as a primary gateway and the third BNG as a backup gateway; The sending unit is further configured to send the IP address of the third user equipment to the third user equipment.
9. The device according to any one of claims 6 to 8, characterized in that The device further comprises: An acquiring unit is configured to acquire a correspondence between a primary gateway, a backup gateway, and a network segment, wherein the correspondence includes one or more of the following: The correspondence between the first BNG, the second BNG, and the first network segment; and The corresponding relationship between the first BNG, the third BNG and the second network segment; and The correspondence between the second BNG, the first BNG and the third network segment.
10. The device according to claim 6, characterized in that The sending unit is configured to: The IP address of the first user equipment is sent to the first user equipment via the first BNG.
11. A computer-readable storage medium, characterized in that The method comprises instructions or computer programs, which, when executed on a computer, enable the computer to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method, device and system for establishing and using floating segments
CN102651711A
Traffic monitoring dispatching method and device, server and storage medium
CN109428780A