Metropolitan Area Network Networking Method, System, and Multi-Service Edge and Control Plane Network Elements

By creating a new control plane network element SU-MSE in the metropolitan area network, centrally managing and allocating static addresses, the address change problem of static address user terminals when changing uplink MSE is solved, improving customer perception and improving address utilization.

CN115622740BActive Publication Date: 2025-08-01CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211143828.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-20
Publication Date
2025-08-01
Estimated Expiration
2042-09-20

AI Technical Summary

Technical Problem

In the existing metropolitan area network structure, when the static address user terminal changes the uplink MSE, it needs to change the static address, increase the customer's workload, affect customer perception, and have low address utilization.

Method used

A new control plane network element SU-MSE is built in the metropolitan area network, and the static address management and control functions of MSE are stripped away, and static address allocation and authentication are concentrated on the SU-MSE. MSE is only responsible for data forwarding.

Benefits of technology

Static address user terminals do not need to change static addresses when changing uplink MSE, which improves customer perception, reduces address waste, and improves address utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115622740B_ABST
    Figure CN115622740B_ABST
Patent Text Reader

Abstract

The present application provides a method and system for metropolitan area network (MAN) networking, as well as a multi-service edge and control plane network element, aiming to solve the problems of poor customer perception and low address utilization rate existing in the existing MAN networking methods. The method is applied to a multi-service edge (MSE) and includes: receiving an external network access authentication request including virtual local area network (VLAN) information from a target terminal, where the target terminal is a user terminal accessing the MSE and waiting to be assigned a static address; sending the VLAN information of the target terminal to a control plane network element (SU-MSE), so that the SU-MSE allocates a static address to the target terminal according to a built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, where the static address is used to access the external network of the MAN.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet technology, and in particular to a metropolitan area network networking method, system, and multi-service edge and control plane network elements. Background Art

[0002] Currently, the metropolitan area network (MAN) architecture is primarily a tightly coupled network deployment structure centered around the Multi-Service Edge (MSE) device. This means that a single MSE device controls and forwards data for all connected user terminals. This networking architecture presents the following operational challenges:

[0003] 1. When a static address user terminal changes its uplink MSE, the new uplink MSE needs to reassign it a static address. Changing the static address increases the customer's workload and affects customer experience. 2. Address segments are allocated based on MSE units, resulting in low address utilization. Summary of the Invention

[0004] In view of the above problems, the embodiments of the present application provide a metropolitan area network networking method, system, and multi-service edge and control plane network elements to overcome the above problems or at least partially solve the above problems.

[0005] A first aspect of an embodiment of the present application provides a metropolitan area network networking method, applied to a multi-service edge (MSE), including:

[0006] Receiving an external network access authentication request including virtual local area network (VLAN) information from a target terminal, wherein the target terminal is a user terminal to be assigned a static address and accessing the MSE;

[0007] The VLAN information of the target terminal is sent to the control plane network element SU-MSE, so that the SU-MSE allocates a static address to the target terminal according to the built-in static address pool, and performs external network access authentication for the target terminal according to the VLAN information and static address of the target terminal. The static address is used to access the external network of the metropolitan area network.

[0008] Optionally, the sending the VLAN information of the target terminal to the control plane network element SU-MSE includes:

[0009] Determine virtual private network (VPN) dedicated line data including the VLAN information of the target terminal according to the VLAN information of the target terminal and information of the access interface used to access the target terminal, and establish the VPN dedicated line corresponding to the target terminal between the MSE and the SU-MSE;

[0010] Send the VPN dedicated line data to the SU-MSE through the VPN dedicated line corresponding to the target terminal.

[0011] Optionally, it further includes:

[0012] Receive service data from the user terminal;

[0013] In the case where the service data is a static address user data packet, send the static address user data packet to the SU-MSE, so that the SU-MSE processes the static address user data packet and sends the processed static address user data packet to the core router CR, and the CR is used to access the external network of the metropolitan area network;

[0014] In the case where the service data is a dynamic address user data packet, process the dynamic address user data packet and send the processed dynamic address user data packet to the CR.

[0015] Optionally, the sending the static address user data packet to the SU-MSE includes:

[0016] Determine the VPN dedicated line corresponding to the user terminal according to the VLAN information of the user terminal and the information of the access interface for accessing the user terminal;

[0017] Send the static address user data packet to the SU-MSE through the VPN dedicated line corresponding to the user terminal.

[0018] Optionally, the user terminal is an Internet static address user terminal and / or a cloud private network VPN user terminal.

[0019] In the second aspect of the embodiments of the present application, another method for networking a metropolitan area network is provided, which is applied to a control plane network element SU-MSE and includes:

[0020] Receive the virtual local area network VLAN information of the target terminal sent by the multi-service edge MSE, where the target terminal is a user terminal with a static address to be allocated that accesses the MSE;

[0021] Allocate a static address to the target terminal according to the built-in static address pool, and perform external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

[0022] Optionally, the performing external network access authentication on the target terminal according to the VLAN information and static address of the target terminal includes:

[0023] Bind the VLAN information and static address of the target terminal, as well as the information of the physical interface used to receive the VLAN information of the target terminal;

[0024] Send the VLAN information and static address of the target terminal, as well as the information of the physical interface to the Remote Authentication Dial-In User Service (RADIUS) system, so that the RADIUS authenticates the legality of the target terminal;

[0025] In response to the successful authentication of the legality of the target terminal, the external network access authentication of the target terminal passes;

[0026] In response to the failure of the legality authentication of the target terminal, the external network access authentication of the target terminal fails.

[0027] Optionally, it further includes:

[0028] Receive a static address user data packet from the MSE, process the static address user data packet, and send the processed static address user data packet to the Core Router (CR), and the CR is used to access the external network of the metropolitan area network.

[0029] Optionally, the SU-MSE includes two SU-MSE devices, and the two SU-MSE devices are networked in a primary / backup mode or a stacking mode.

[0030] In the third aspect of the embodiments of the present application, a Multi-Service Edge (MSE) is provided, including:

[0031] An MSE receiving module, configured to receive an external network access authentication request including Virtual Local Area Network (VLAN) information from a target terminal, where the target terminal is a user terminal to which a static address is to be allocated and is connected to the MSE;

[0032] An MSE sending module, configured to send the VLAN information of the target terminal to the control plane network element SU-MSE, so that the SU-MSE allocates a static address to the target terminal according to a built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

[0033] In the fourth aspect of the embodiments of the present application, a control plane network element SU-MSE is provided, including:

[0034] An SU-MSE receiving module, configured to receive the VLAN information of a target terminal sent by the Multi-Service Edge (MSE), where the target terminal is a user terminal to which a static address is to be allocated and is connected to the MSE;

[0035] The SU-MSE processing module is used to allocate a static address to the target terminal according to the built-in static address pool, and perform external network access authentication on the target terminal according to the VLAN information and static address of the target terminal. The static address is used to access the external network of the metropolitan area network.

[0036] In a fifth aspect of the embodiments of the present application, a metropolitan area network networking system is provided, including a control plane network element SU-MSE and multiple multi-service edges MSEs, where:

[0037] Among the multiple multi-service edges MSEs, each MSR that receives an external network access authentication request including virtual local area network (VLAN) information from a target terminal executes the metropolitan area network networking method described in the first aspect, so that the SU-MSE allocates a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal. The static address is used to access the external network of the metropolitan area network.

[0038] In a sixth aspect of the embodiments of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the metropolitan area network networking method disclosed in the first aspect of the embodiments of the present application, or the processor executes the computer program to implement the metropolitan area network networking method disclosed in the second aspect of the embodiments of the present application.

[0039] In a seventh aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program / instructions are stored. When the computer program / instructions are executed by a processor, the metropolitan area network networking method disclosed in the first aspect of the embodiments of the present application is implemented, or when the computer program / instructions are executed by a processor, the metropolitan area network networking method disclosed in the second aspect of the embodiments of the present application is implemented.

[0040] In an eighth aspect of the embodiments of the present application, a computer program product is provided, including a computer program / instructions. When the computer program / instructions are executed by a processor, the metropolitan area network networking method disclosed in the first aspect of the embodiments of the present application is implemented, or when the computer program / instructions are executed by a processor, the metropolitan area network networking method disclosed in the second aspect of the embodiments of the present application is implemented.

[0041] The embodiments of the present application include the following advantages:

[0042] In this embodiment, based on the idea of separating data control and data forwarding, a control plane network element SU-MSE is newly built in the metropolitan area network. The management and control functions for static address user terminals are separated from the MSE and deployed on the new network element SU-MSE. That is, all static address user terminals in the metropolitan area network are assigned IP addresses and controlled to go online (i.e., external network access authentication) by the SU-MSE. Each MSE and its lower-layer devices in the metropolitan area network only undertake the data forwarding function for static address user terminals, enabling static address user terminals not to change their static addresses when changing the upstream MSE, which can improve the customer perception. Moreover, only the address segment needs to be assigned to the SU-MSE, effectively improving the address utilization rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the description of the embodiments of the present application. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0044] Figure 1 It is a flowchart of the steps of a metropolitan area network networking method in an embodiment of the present application;

[0045] Figure 2 It is a schematic diagram of a metropolitan area network networking architecture in an embodiment of the present application;

[0046] Figure 3 It is a schematic diagram of the system data flow in an embodiment of the present application;

[0047] Figure 4 It is a flowchart of the steps of another metropolitan area network networking method in an embodiment of the present application;

[0048] Figure 5 It is a schematic diagram of the structure of a multi-service edge MSE in an embodiment of the present application;

[0049] Figure 6 It is a schematic diagram of the structure of a control plane network element SU-MSE in an embodiment of the present application;

[0050] Figure 7 It is a schematic diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0051] To make the above objects, features, and advantages of the present application more obvious and understandable, the following will further describe the present application in detail in conjunction with the drawings and specific embodiments.

[0052] Currently, the metropolitan area network (MAN) architecture primarily relies on a tightly coupled network deployment structure centered around the Multi-Service Edge (MSE) device, where a single MSE device controls and forwards data for all connected user terminals. As services expand, this network architecture presents the following operational challenges:

[0053] First, the Internet access static IP addresses of all Internet static address user terminals in the metropolitan area network are allocated centered on the MSE. A district or county generally deploys at least two MSEs. When an Internet static address user terminal needs to move across MSEs, the Internet access static IP address must be changed. In this era of Internet digitalization, many user services are carried on the Internet. Changing the Internet access static IP address means that users may need to change their own business systems, which will affect customer perception.

[0054] Similarly, when two or more locally deployed MSE devices need to adjust the network structure due to unbalanced business load or other reasons, the OLT (Optical Line Terminal) connected to a certain MSE also needs to be migrated to another MSE. At this time, all static address user terminals connected to the OLT have to change their IP addresses due to the change of the upstream MSE, which greatly increases the user's workload and seriously affects customer perception.

[0055] In addition, when networking the local network of the cloud private network VPN (Virtual Private Network), an address segment needs to be allocated to each MSE, but the number of addresses allocated to each local network or county is limited. The networking method of allocating addresses based on MSE will cause serious address waste (each MSE needs to be allocated a static address segment), resulting in a situation where the private network addresses planned by users are not enough, which limits the development of cloud private network services.

[0056] In response to the current metropolitan area network (MAN) networking structure's existing problems of requiring IP addresses to be changed when statically addressed user terminals migrate across MSEs / change the upstream MSE in engineering cutovers, and the serious address waste caused by the need to allocate addresses according to MSEs when establishing a WAN within the local network range of cloud private network users, this application proposes a new MAN networking solution based on the idea of data control and forwarding separation and modular networking.

[0057] Reference Figure 1 As shown, an embodiment of the present application provides a metropolitan area network networking method, which is applied to a multi-service edge MSE. The metropolitan area network networking method includes the following steps:

[0058] Step S11: Receive an external network access authentication request including Virtual Local Area Network (VLAN) information from a target terminal, where the target terminal is a user terminal to which a static address is to be assigned and is connected to the MSE.

[0059] Among them, the user terminal can be an Internet static address user terminal and / or a cloud private network VPN user terminal (such as an Internet dedicated line type static IP address user terminal, a cloud private network type static IPOE, and a single-arm static route, etc.), and the static address can be a static IP address.

[0060] In this embodiment, after the target terminal directly accesses or accesses the MSE through an aggregation device such as an OLT, it can send an external network access authentication request to the MSE to obtain the permission to access other networks outside the metropolitan area network (such as a wide area network or the Internet, etc.).

[0061] Step S12: Send the VLAN information of the target terminal to the control plane network element SU-MSE, so that the SU-MSE allocates a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal. The static address is used to access the external network of the metropolitan area network.

[0062] The embodiment of the present application provides a new network element (control plane network element SU-MSE) for managing and controlling static address user terminals. After receiving an external network access authentication request from a static address user terminal connected below, the MSE forwards the VLAN (Virtual Local Area Network) information carried in the external network access authentication request to the SU-MSE. The SU-MSE replaces the MSE to implement all relevant management functions and control functions for static address user terminals such as static address allocation and external network access authentication, so that the MSE and its lower-layer devices only undertake the data forwarding function for static address user terminals.

[0063] Since all static address user terminals in the metropolitan area network are controlled by the SU-MSE to go online (i.e., perform external network access authentication) and allocate static addresses, all static address user terminals in the metropolitan area network do not need to change the static address when replacing the MSE, and the static address pool is only established on the SU-MSE, which can effectively reduce the waste of address segments. Therefore, while solving the problem that the static address needs to be changed when changing the MSE during cross-MSE migration and OLT cutover, the utilization rate of static addresses can be greatly improved.

[0064] Adopting the technical solution of the embodiment of the present application, based on the idea of separating data control and data forwarding, by newly building a control plane network element SU-MSE in the metropolitan area network, the management and control functions for static address user terminals are separated from the MSE and deployed on the new network element SU-MSE. That is, all static address user terminals in the metropolitan area network are assigned IP addresses by SU-MSE and controlled to go online (i.e., external network access authentication). Each MSE and its lower-layer devices in the metropolitan area network only undertake the data forwarding function for static address user terminals, enabling static address user terminals not to change their static addresses when changing the upstream MSE, which can improve the customer perception. And only the address segment needs to be assigned to SU-MSE, effectively improving the address utilization rate.

[0065] Among them, to improve the reliability of the overall network, the SU-MSE may include two SU-MSE devices. The two SU-MSE devices can be networked in a primary and standby manner, that is, the two SU-MSE devices are divided into a primary SU-MSE device and a standby SU-MSE device. The standby SU-MSE device serves as the backup of the primary SU-MSE device. When the primary SU-MSE device fails, the backup SU-MSE device will take over all the work of the primary SU-MSE device. The two SU-MSE devices can also be networked in a stacking manner, that is, the two SU-MSE devices are virtualized into one SU-MSE for operation, so as to share the load.

[0066] Exemplarily, taking two SU-MSE devices networked in a primary and standby manner as an example, the above-mentioned metropolitan area network networking method is described.

[0067] As Figure 2 shown, two primary and standby SU-MSE devices are deployed above the existing MSE in the metropolitan area network as the control layer for static address user terminals. The two new SU-MSE devices can be interconnected by optical fibers. At the same time, the upstream outlets of the two new SU-MSE devices are both connected to the CR (Core Router). And the two SU-MSE devices are respectively connected to all MSEs in the metropolitan area network through physical lines, so as to realize the control function and forwarding routing function for static address user terminals through the deployed SU-MSE devices, and realize the centralized online control for Internet static address user terminals and cloud private network VPN user terminals.

[0068] Among them, Figure 2The static address users hanging down to the OLT in the middle and lower layers can be static address user terminals such as static IP (IPv4 / IPv6) addresses. For static address users (i.e., target terminals) without assigned static addresses, after they are connected to the MSE through VLAN (single-layer VLAN / double-layer VLAN), in the existing metropolitan area network networking solution, it is the MSE accessing the target terminal that assigns a static address to the target terminal and performs external network access authentication. In the metropolitan area network networking solution provided by the embodiments of the present application, the MSE accessing the target terminal is only responsible for forwarding the VLAN information of the target terminal to the SU-MSE, and the SU-MSE assigns a static address to the target terminal and performs external network access authentication.

[0069] Optionally, the sending the VLAN information of the target terminal to the control plane network element SU-MSE includes:

[0070] Determine virtual private network (VPN) dedicated line data including the VLAN information of the target terminal according to the VLAN information of the target terminal and the information of the access interface used to access the target terminal, and establish a VPN dedicated line corresponding to the target terminal between the MSE and the SU-MSE;

[0071] Send the VPN dedicated line data to the SU-MSE through the VPN dedicated line corresponding to the target terminal.

[0072] Among them, the VPN dedicated line can be a layer-2 VPN dedicated line or a layer-3 VPN dedicated line.

[0073] As Figure 2 shown, taking the layer-2 VPN dedicated line as an example to illustrate the steps of the MSE forwarding the VLAN information is as follows.

[0074] After receiving an external network access authentication request carrying VLAN information from the target terminal, the MSE makes layer-2 VPN dedicated line data carrying VPN information according to the information of the access interface accessing the target terminal (which can also be the access interface used to receive the VLAN information forwarded by the OLT) and the VLAN information, and establishes a layer-2 VPN connection (i.e., establishes a layer-2 VPN dedicated line) with the SU-MSE, and transmits the layer-2 VPN dedicated line data to the SU-MSE through the layer-2 VPN dedicated line.

[0075] Among them, as Figure 2 shown, the VPN dedicated line is established between the physical interfaces where the SU-MSE and the MSE are connected, and all static address user terminals in the metropolitan area network have their own independent VPN dedicated lines.

[0076] Further, after the SU-MSE receives the VLAN information of the target terminal, it allocates a static address for the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and the static address of the target terminal.

[0077] As a possible implementation manner, performing external network access authentication on the target terminal according to the VLAN information and the static address of the target terminal:

[0078] Bind the VLAN information and the static address of the target terminal, and the information of the physical interface used to receive the VLAN information of the target terminal;

[0079] The SU-MSE sends the VLAN information and the static address of the target terminal, and the information of the physical interface to the RADIUS (Remote Authentication Dial In User Service) to enable the RADIUS to perform legality authentication on the target terminal; in response to the legality authentication of the target terminal passing, the external network access authentication of the target terminal passes; in response to the legality authentication of the target terminal not passing, the external network access authentication of the target terminal does not pass.

[0080] In this embodiment, the SU-MSE makes the static user data corresponding to the target terminal according to the information of the physical interface connected to the MSE by the SU-MSE (that is, the physical interface used to receive the VLAN information of the target terminal), and binds the static address, the information of the corresponding physical interface, and the VLAN information, and sends the static user data and the bound static address to the RADIUS. The RADIUS verifies the legality of the target terminal and the static address according to the received information. If the RADIUS determines that the target terminal passes the legality authentication, the SU-MSE controls the target terminal to go online on the SU-MSE (that is, determines that the target terminal passes the external network access authentication). If the RADIUS determines that the target terminal does not pass the legality authentication, the SU-MSE determines that the target terminal does not pass the external network access authentication).

[0081] In addition, as Figure 2 and Figure 3 shown, the MSE will process user data with different characteristics separately according to the data characteristics.

[0082] For a static address user terminal connected to the SU-MSE, that is, when the received service data is a static address user data packet, the static address user data packet is sent to the SU-MSE, so that the SU-MSE processes the static address user data packet and sends the processed static address user data packet to the core router CR to leave the metropolitan area network.

[0083] As a possible implementation manner, the sending the static address user data packet to the SU-MSE includes:

[0084] Determine the VPN dedicated line corresponding to the user terminal according to the VLAN information of the user terminal and the information of the access interface used to access the user terminal;

[0085] Send the static address user data packet to the SU-MSE through the VPN dedicated line corresponding to the user terminal.

[0086] In this embodiment, the MSE sends the static address user data packet to the SU-MSE through the VPN dedicated line. This VPN dedicated line is established when authenticating the external network access of the static address user terminal and is used for the MSE to send VLAN information to the SU-MSE.

[0087] Furthermore, for a dynamic address user terminal, that is, when the service data is a dynamic address user data packet, the MSE processes the dynamic address user data packet and sends the processed dynamic address user data packet to the CR.

[0088] Since all static address user terminals in the metropolitan area network are controlled by the SU-MSE for online connection and IP address allocation, the static address pool can be established only on the SU-MSE. All static address user terminals in the metropolitan area network can move across MSEs within the metropolitan area network without changing the static address, thus avoiding the need for major transformation of the user network system to ensure the realization of network functions, greatly reducing the difficulty of service opening and change, and further making the metropolitan area network more flexible in networking and better in service scalability.

[0089] The metropolitan area network networking method for cloud private network static address user terminals is similar to the above method. The static address is centrally allocated and controlled by the SU-MSE for online connection, achieving the purpose that users can move across MSEs without changing the static address. At the same time, it can also reduce the waste of address segments and achieve the purpose of saving static addresses.

[0090] The metropolitan area network (MAN) networking method provided by the embodiments of this application does not change the original user access and networking methods (such as the access and networking methods from the multi-service edge (MSE) to the optical line terminal (OLT) to the user), does not change the original data packet encapsulation format, has a small network transformation workload, and is easy to implement.

[0091] In addition, due to the particularity of the static address user terminal, a dedicated network element (i.e., the SU-MSE) is added to centrally process the online control of the static address user terminal, so that the static address allocation of the static address user terminal is not restricted by the access geographical location. With the development of MAN technology, the MAN networking method provided by this application can uniformly process the static address user terminals across the province or even the whole country. By using technologies such as EVPN (Ethernet Virtual Private Network, the next-generation VPN solution for full-service bearer) and SRv6 (Segment Routing IPv6, segment routing based on IPv6), the static address user terminals are uniformly processed by the dedicated network element, enabling the static address to permanently follow the user terminal without being restricted by the geographical location.

[0092] As Figure 4 shown, the embodiments of this application also provide another MAN networking method, which is applied to the control plane network element SU-MSE. This MAN networking method includes the following steps:

[0093] Step S21: Receive the virtual local area network (VLAN) information of the target terminal sent by the multi-service edge (MSE), where the target terminal is a user terminal with a static address to be allocated that accesses the MSE;

[0094] Step S22: Allocate a static address to the target terminal according to the built-in static address pool, and perform external network access authentication on the target terminal according to the VLAN information and static address of the target terminal. The static address is used to access the external network of the MAN.

[0095] Adopting the technical solution of the embodiments of this application, based on the idea of separating data control and data forwarding, a control plane network element SU-MSE is newly built in the MAN. The management and control functions for the static address user terminals are separated from the MSE and deployed on the new network element SU-MSE. That is, all the static address user terminals in the MAN are assigned IP addresses and controlled to go online (i.e., external network access authentication) by the SU-MSE. Each MSE and its underlying devices in the MAN only undertake the data forwarding function for the static address user terminals, so that the static address user terminal does not need to change the static address when changing the upstream MSE, which can improve the customer perception. And only the address segment needs to be allocated to the SU-MSE, effectively improving the address utilization rate.

[0096] Optionally, performing external network access authentication on the target terminal according to the VLAN information and static address of the target terminal includes:

[0097] Binding the VLAN information and static address of the target terminal, and the information of the physical interface used to receive the VLAN information of the target terminal;

[0098] Sending the VLAN information and static address of the target terminal, and the information of the physical interface to the Remote Authentication Dial-In User Service (RADIUS) system, so that the RADIUS performs legality authentication on the target terminal;

[0099] In response to the legality authentication of the target terminal passing, the external network access authentication of the target terminal passes;

[0100] In response to the legality authentication of the target terminal failing, the external network access authentication of the target terminal fails.

[0101] Optionally, it further includes:

[0102] Receiving a static address user data packet from the MSE, processing the static address user data packet, and sending the processed static address user data packet to the Core Router (CR), where the CR is used to access the external network of the metropolitan area network.

[0103] Optionally, the SU-MSE includes two SU-MSE devices, and the two SU-MSE devices are networked in a primary / backup mode or a stacking mode.

[0104] The implementation manner of the metropolitan area network networking method on the SU-MSE side is similar to the implementation manner in the relevant embodiments of the metropolitan area network networking method on the MSE side, and will not be elaborated here.

[0105] For the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present application are not limited by the described action sequence, because according to the embodiments of the present application, some steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.

[0106] Figure 5 It is a schematic structural diagram of a Multi-Service Edge (MSE) according to an embodiment of the present application. The MSE includes:

[0107] The MSE receiving module is used to receive an external network access authentication request including virtual local area network (VLAN) information from a target terminal, where the target terminal is a user terminal that accesses the MSE and whose static address is to be allocated.

[0108] The MSE sending module is used to send the VLAN information of the target terminal to the control plane network element SU-MSE, so that the SU-MSE allocates a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal. The static address is used to access the external network of the metropolitan area network.

[0109] By adopting the technical solution of the embodiment of the present application, based on the idea of separating data control and data forwarding, a control plane network element SU-MSE is newly built in the metropolitan area network. The management and control functions of static address user terminals are separated from the MSE and deployed on the new network element SU-MSE. That is, all static address user terminals in the metropolitan area network are allocated IP addresses and controlled to go online (i.e., external network access authentication) by the SU-MSE. Each MSE and its underlying devices in the metropolitan area network only undertake the data forwarding function of static address user terminals, so that static address user terminals do not need to change their static addresses when changing the upstream MSE, which can improve the customer perception. And only the address segment needs to be allocated to the SU-MSE, effectively improving the address utilization rate.

[0110] Optionally, the MSE sending module is specifically used to determine virtual private network (VPN) dedicated line data including the VLAN information of the target terminal according to the VLAN information of the target terminal and the information of the access interface used to access the target terminal, and establish a VPN dedicated line corresponding to the target terminal between the MSE and the SU-MSE; and send the VPN dedicated line data to the SU-MSE through the VPN dedicated line corresponding to the target terminal.

[0111] Optionally, it further includes:

[0112] The first receiving module is used to receive service data from a user terminal; [[ID=ID=17]]

[0113] The first processing module is used to, when the service data is a static address user data packet, send the static address user data packet to the SU-MSE, so that the SU-MSE processes the static address user data packet and sends the processed static address user data packet to the core router CR, where the CR is used to access the external network of the metropolitan area network; when the service data is a dynamic address user data packet, process the dynamic address user data packet and send the processed dynamic address user data packet to the CR.

[0114] Optionally, the first processing module is specifically configured to determine the VPN dedicated line corresponding to the user terminal according to the VLAN information of the user terminal and the information of the access interface used to access the user terminal; and send the static address user data packet to the SU-MSE through the VPN dedicated line corresponding to the user terminal.

[0115] Optionally, the user terminal is an Internet static address user terminal and / or a cloud private network VPN user terminal.

[0116] Figure 6 FIG. is a schematic structural diagram of a control plane network element SU-MSE according to an embodiment of the present application. The SU-MSE includes:

[0117] An SU-MSE receiving module, configured to receive the virtual local area network VLAN information of a target terminal sent by a multi-service edge MSE, where the target terminal is a user terminal to which a static address is to be allocated and accesses the MSE;

[0118] An SU-MSE processing module, configured to allocate a static address to the target terminal according to a built-in static address pool, and perform external network access authentication on the target terminal according to the VLAN information and the static address of the target terminal, where the static address is used to access the external network of the metropolitan area network.

[0119] Adopting the technical solution of the embodiment of the present application, based on the idea of separating data control and data forwarding, by creating a new control plane network element SU-MSE in the metropolitan area network, the management and control functions for static address user terminals are separated from the MSE and deployed on the new network element SU-MSE. That is, all static address user terminals in the metropolitan area network are assigned IP addresses by the SU-MSE and controlled to go online (i.e., external network access authentication). Each MSE and its underlying devices in the metropolitan area network only undertake the data forwarding function for static address user terminals, so that static address user terminals do not need to change the static address when changing the upstream MSE, which can improve the customer perception, and only need to allocate an address segment to the SU-MSE, effectively improving the address utilization rate.

[0120] Optionally, the SU-MSE processing module is specifically configured to bind the VLAN information and the static address of the target terminal, and the information of the physical interface used to receive the VLAN information of the target terminal; send the VLAN information and the static address of the target terminal, and the information of the physical interface to a remote user dial authentication system RADIUS, so that the RADIUS performs legality authentication on the target terminal; in response to the legality authentication of the target terminal passing, the external network access authentication of the target terminal passes; in response to the legality authentication of the target terminal not passing, the external network access authentication of the target terminal does not pass.

[0121] Optionally, it further includes:

[0122] A second processing module, configured to receive the static address user data packet from the MSE, process the static address user data packet, and send the processed static address user data packet to the core router CR, where the CR is used to access the external network of the MAN.

[0123] Optionally, the SU-MSE includes two SU-MSE devices, and the two SU-MSE devices are networked in a primary / backup mode or a stacking mode.

[0124] An embodiment of the present application further provides a MAN networking system, including a control plane network element SU-MSE and multiple multi-service edges MSEs, where:

[0125] Among the multiple multi-service edges MSEs, each MSR that receives an external network access authentication request including virtual local area network (VLAN) information from a target terminal executes the MAN networking method as described in steps S11 to S12, so that the SU-MSE allocates a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, where the static address is used to access the external network of the MAN.

[0126] It should be noted that the device embodiment is similar to the method embodiment, so the description is relatively simple. For related parts, please refer to the method embodiment.

[0127] An embodiment of the present application further provides an electronic device, referring to Figure 7 , Figure 7 is a schematic diagram of the electronic device proposed in the embodiment of the present application. As Figure 7 shown, the electronic device 100 includes: a memory 110 and a processor 120. The memory 110 and the processor 120 are communicatively connected through a bus. A computer program is stored in the memory 110, and the computer program can run on the processor 120 to implement the steps in the MAN networking method disclosed in the embodiment of the present application.

[0128] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program / instructions are stored, and when the computer program / instructions are executed by a processor, the MAN networking method disclosed in the embodiment of the present application is implemented.

[0129] An embodiment of the present application further provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the MAN networking method disclosed in the embodiment of the present application is implemented.

[0130] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.

[0131] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0132] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, systems, devices, storage media, and program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0133] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0134] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, such that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0135] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.

[0136] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or terminal device comprising the element.

[0137] The above has introduced in detail a method for forming a metropolitan area network, a system, and a multi-service edge and control plane network element provided by the present application. Specific examples are used in this text to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation on the present application.

Claims

1. A method for networking a metropolitan area network, characterized in that, Applied to multi-service edge MSE, including: Receiving an external network access authentication request including virtual local area network (VLAN) information from a target terminal, where the target terminal is a user terminal to which a static address is to be assigned and is connected to the MSE; Sending the VLAN information of the target terminal to the control plane network element SU-MSE, so that the SU-MSE assigns a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

2. The method according to claim 1, wherein The sending the VLAN information of the target terminal to the control plane network element SU-MSE includes: Determining virtual private network (VPN) dedicated line data including the VLAN information of the target terminal according to the VLAN information of the target terminal and the information of the access interface used to access the target terminal, and establishing a VPN dedicated line corresponding to the target terminal between the MSE and the SU-MSE; Sending the VPN dedicated line data to the SU-MSE through the VPN dedicated line corresponding to the target terminal.

3. The method according to claim 1, wherein It also includes: Receiving service data from a user terminal; In the case where the service data is a static address user data packet, sending the static address user data packet to the SU-MSE, so that the SU-MSE processes the static address user data packet and sends the processed static address user data packet to the core router CR, and the CR is used to access the external network of the metropolitan area network; In the case where the service data is a dynamic address user data packet, processing the dynamic address user data packet and sending the processed dynamic address user data packet to the CR.

4. The method according to claim 3, characterized in that, The sending the static address user data packet to the SU-MSE includes: Determining the VPN dedicated line corresponding to the user terminal according to the VLAN information of the user terminal and the information of the access interface used to access the user terminal; Sending the static address user data packet to the SU-MSE through the VPN dedicated line corresponding to the user terminal.

5. The method according to any one of claims 1-4, characterized in that, The user terminal is an Internet static address user terminal and / or a cloud private network VPN user terminal.

6. A method for networking a metropolitan area network, characterized in that, Applied to the control plane network element SU-MSE, including: Receiving the virtual local area network (VLAN) information of a target terminal sent by the multi-service edge MSE, where the target terminal is a user terminal to which a static address is to be assigned and is connected to the MSE; Assigning a static address to the target terminal according to the built-in static address pool, and performing external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

7. The method according to claim 6, wherein The performing external network access authentication on the target terminal according to the VLAN information and static address of the target terminal includes: Binding the VLAN information and static address of the target terminal, and the information of the physical interface used to receive the VLAN information of the target terminal. Send the VLAN information, static address of the target terminal, and information of the physical interface to the Remote Authentication Dial In User Service (RADIUS) system, so that the RADIUS authenticates the legality of the target terminal; In response to the successful authentication of the legality of the target terminal, the external network access authentication of the target terminal is passed; In response to the failure of the authentication of the legality of the target terminal, the external network access authentication of the target terminal fails.

8. The method according to claim 6, wherein It further includes: Receive the static address user data packet from the MSE, process the static address user data packet, and send the processed static address user data packet to the Core Router (CR), and the CR is used to access the external network of the metropolitan area network.

9. The method according to any one of claims 6 - 8, characterized in that, The SU-MSE includes two SU-MSE devices, and the two SU-MSE devices are networked in a primary / backup mode or a stacking mode.

10. A multi-service edge MSE, characterized in that, It includes: An MSE receiving module, configured to receive an external network access authentication request including Virtual Local Area Network (VLAN) information from a target terminal, where the target terminal is a user terminal to which a static address is to be assigned and is connected to the MSE; An MSE sending module, configured to send the VLAN information of the target terminal to the control plane network element SU-MSE, so that the SU-MSE assigns a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

11. A control plane network element SU-MSE, characterized in that, It includes: An SU-MSE receiving module, configured to receive the VLAN information of the target terminal sent by the Multi-Service Edge (MSE), where the target terminal is a user terminal to which a static address is to be assigned and is connected to the MSE; An SU-MSE processing module, configured to assign a static address to the target terminal according to the built-in static address pool, and perform external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

12. A metropolitan area network networking system, characterized in that, It includes a control plane network element SU-MSE and multiple Multi-Service Edge (MSEs), where: Among the multiple Multi-Service Edge (MSEs), each MSR that receives an external network access authentication request including VLAN information from a target terminal executes the metropolitan area network networking method according to any one of claims 1 to 5, so that the SU-MSE assigns a static address to the target terminal according to the built-in static address pool, and performs external network access authentication on the target terminal according to the VLAN information and static address of the target terminal, and the static address is used to access the external network of the metropolitan area network.

13. An electronic device, comprising a memory, a processor, and a computer program stored on the memory, wherein, The processor executes the computer program to implement the metropolitan area network networking method according to any one of claims 1 to 5, or the processor executes the computer program to implement the metropolitan area network networking method according to any one of claims 6 to 9.

14. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by a processor, they implement the metropolitan area network networking method according to any one of claims 1 to 5, or when the computer program / instructions are executed by a processor, they implement the metropolitan area network networking method according to any one of claims 6 to 9.

15. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, they implement the metropolitan area network networking method according to any one of claims 1 to 5, or when the computer program / instructions are executed by a processor, they implement the metropolitan area network networking method according to any one of claims 6 to 9.

Citation Information

Patent Citations

  • Internet Protocol (IP) address allocation methods, device, server and terminal

    CN105208137A

  • Method and device for statically configuring VPN routing

    CN105939261A