A method and device for solving traffic orchestration of security resource pool through SRv6

The in-domain network element path is bound to the SID through SRv6 and connected to the SID in series by the cross-domain controller, which solves the problem of low traffic orchestration efficiency in edge cloud systems, and realizes simplified end-to-end path configuration and efficient service scheduling.

CN115914072BActive Publication Date: 2025-08-12CHINA UNITECHS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211422581.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-14
Publication Date
2025-08-12
Estimated Expiration
2042-11-14

AI Technical Summary

Technical Problem

The prior art realizes low traffic orchestration efficiency and complex configuration in edge cloud systems, making it difficult to meet end-to-end path creation in multi-domain and multi-controller management scenarios.

Method used

Through SRv6, the in-domain network element's own path is bound to the SID, and the cross-domain controller connects the SID in series to realize end-to-end cross-domain forwarding and simplify path configuration.

Benefits of technology

It realizes a simple and fast traffic orchestration process, improves the call efficiency of edge cloud value-added services, and supports on-demand network path settings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115914072B_ABST
    Figure CN115914072B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for solving the traffic orchestration of a security resource pool through SRv6, wherein the method includes: a security capability management platform module receives business information and sends the business information to a traffic orchestration module for parsing; the traffic orchestration module is built, the required data communication device nodes support SRv6 capabilities, and the network elements support SRv6 functions; the SID configuration of the resource pool in the edge cloud is completed; the traffic path is orchestrated according to the planned traffic orchestration sequence; the channel is configured according to the orchestrated traffic path so that the entire orchestrated path takes effect on the device; an actual traffic path is generated, and the business flow enters the security resource pool module for security processing; after the traffic is cleaned, it is returned to the target address through the pool outside routing. The method and device bind the network element's own path in the domain to the SID in a SRv6 manner, and then the cross-domain controller connects the SID in series for end-to-end cross-domain forwarding, which is simple, fast and easy to implement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security, and in particular to a method and device for solving traffic orchestration of a security resource pool through SRv6. Background Art

[0002] Amidst the booming 5G landscape, edge cloud services are also developing rapidly. Edge cloud systems include basic network switching equipment and deploy value-added service equipment, such as load balancers for security resource pools and intrusion prevention devices, to ensure network security and service scheduling. To meet the demands of diverse service flows and improve the efficiency of edge cloud value-added services, the system needs to support the use of service chains to set network paths for traffic on demand.

[0003] Currently implemented technologies mostly use packet editing methods like VXLAN, which is complex and inefficient in traffic orchestration. The primary technology is NSH (Network Service Header). This protocol implements SFP (Service Function Paths) functionality by adding header information to packets, providing a channel for exchanging metadata between different instances. Simply put, NSH is a network packet encapsulation technology used to provide a service chaining protocol within the SFC architecture. The entire traffic editing process is complex and configuration is tedious.

[0004] like Figure 1 As shown in the figure, SID (segment identifier) is bound to a segment identifier: an SR-TE trail can be associated with a SID on a head node. Other trails can reference this SID as a common trail segment.

[0005] To create an end-to-end path in a multi-domain, multi-controller management scenario, each controller in the domain binds the IGP path between its own cross-domain network devices to the BSID. The cross-domain controller then concatenates the BSIDs for end-to-end cross-domain forwarding.

[0006] Using SIDs significantly shortens the SRH (segment routing header) length of end-to-end paths. Each domain's path is delivered as the BSID of the headend PE / ASBR and is expanded only when forwarding within the domain, facilitating the division of management domains across multiple controllers. Using a single-domain, cross-domain hierarchical controller architecture simplifies upper-layer system control of longer, cross-domain, end-to-end SRv6 policy paths. Summary of the Invention

[0007] To solve the problems existing in the prior art, the present invention provides a method and device for solving the traffic orchestration of a security resource pool through SRv6. The path of the network element within the domain is bound to the SID through SRv6, and then the cross-domain controller concatenates the SID for end-to-end cross-domain forwarding, which is simple, fast and easy to implement.

[0008] To achieve the above object, the present invention adopts the following technical solutions:

[0009] In one embodiment of the present invention, a method for solving traffic orchestration of a security resource pool using SRv6 is proposed. The method includes:

[0010] S01. The security capability management platform module receives business information and sends it to the traffic orchestration module for analysis.

[0011] S02. The traffic orchestration module is built, and the data communication device nodes and network elements required to be delivered support SRv6 capabilities.

[0012] S03. Complete the SID configuration of the resource pool in the edge cloud;

[0013] S04. Arrange the traffic path according to the planned traffic arrangement sequence;

[0014] S05. Configure channels according to the orchestrated traffic path, so that the entire orchestrated path takes effect on the device.

[0015] S06. Generate an actual traffic path, and the business flow enters the security resource pool module for security processing;

[0016] S07: After the traffic is cleaned, it is injected back to the target address through the external routing of the pool.

[0017] Furthermore, the resource pool in S03 includes: an SSL resource pool, an IPS resource pool, and configuration SID information.

[0018] Furthermore, the traffic arrangement order in S04 is as follows: the traffic first enters the SSL resource pool and then enters the IPS resource pool.

[0019] Furthermore, the arrangement of the paths in S04: the paths are identified in the order of the system SIDs.

[0020] In one embodiment of the present invention, a device for orchestrating traffic in a security resource pool using SRv6 is also proposed. The device includes:

[0021] The security capability management platform module 110, the traffic orchestration module 120 and the security resource pool module 130, the security capability management platform module 110 is connected to the traffic orchestration module 120, and the traffic orchestration module 120 is connected to the security resource pool module 130, and all connections are bidirectional.

[0022] Furthermore, the security capability management platform module 110 is provided with a northbound interface, through which the security capability management platform module 110 sends and receives information to the traffic orchestration module 120. The information sent and received by the northbound interface includes: user registration, product registration, product ordering, product orchestration use, policy configuration and event reporting.

[0023] Furthermore, the traffic orchestration module 120 includes: a traffic editing component module 121, a controller module 122 and a southbound interface.

[0024] Furthermore, the traffic editing component module includes: a task scheduling module 1211 and a service orchestration module 1212 .

[0025] Furthermore, the controller module includes: a traffic orchestration module 1221 and an event notification module 1222 .

[0026] Furthermore, the southbound interface sends and receives information including: SRv6 tunnel creation, traffic injection and traction, and traffic orchestration strategy.

[0027] In one embodiment of the present invention, a computer device is also proposed, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the aforementioned method for orchestrating traffic in a security resource pool using SRv6 is implemented.

[0028] In one embodiment of the present invention, a computer-readable storage medium is further provided. The computer-readable storage medium stores a computer program for executing a method for solving traffic orchestration of a security resource pool through SRv6.

[0029] Beneficial effects:

[0030] The present invention uses a traffic orchestration module to orchestrate business traffic in a security capability management platform, obtains traffic orchestration status through it, and saves historical records of traffic orchestration. It receives orchestration requirements from the security capability management platform, and the traffic orchestration module manages the data communication equipment in the resource pool to establish SRv6 tunnels and business channels. It allows user traffic to flow to different security capability resource pools in sequence according to the business orchestration strategy of the traffic orchestration module. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 It is a schematic diagram of SID in the prior art;

[0032] Figure 2 This is a flow chart of a method for solving traffic orchestration in a security resource pool using SRv6 according to an embodiment of the present invention;

[0033] Figure 3 This is a schematic diagram of the structure of a traffic orchestration device for a security resource pool using SRv6 according to an embodiment of the present invention;

[0034] Figure 4 It is a schematic diagram of the structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0035] The principles and spirit of the present invention will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are provided solely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.

[0036] Those skilled in the art will appreciate that the embodiments of the present invention may be implemented as a system, apparatus, device, method, or computer program product. Therefore, the present disclosure may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, resident software, microcode, etc.), or in a combination of hardware and software.

[0037] According to an embodiment of the present invention, a method and device for solving traffic orchestration of a security resource pool through SRv6 are proposed. The path of the network element within the domain is bound to the SID through SRv6, and then the cross-domain controller concatenates the SID for end-to-end cross-domain forwarding, which is simple, fast and easy to implement.

[0038] The principles and spirit of the present invention are explained in detail below with reference to several representative embodiments of the present invention.

[0039] Figure 2 FIG. 1 is a flow chart of a method for orchestrating traffic in a security resource pool using SRv6 according to an embodiment of the present invention. Figure 2 As shown, the method includes:

[0040] S01. The security capability management platform module 110 receives business information and sends it to the traffic orchestration module 120 for analysis.

[0041] S02. The traffic orchestration module 120 is built, and the data communication device nodes required to be delivered support SRv6 capabilities, and the network elements support SRv6 functions;

[0042] S03. Complete the SID configuration of the resource pool in the edge cloud;

[0043] S04. Arrange the traffic path according to the planned traffic arrangement sequence;

[0044] S05. Configure channels according to the orchestrated traffic path, so that the entire orchestrated path takes effect on the device.

[0045] S06: Generate an actual traffic path, and the business flow enters the security resource pool module 130 for security processing;

[0046] S07: After the traffic is cleaned, it is injected back to the target address through the external routing of the pool.

[0047] The resource pools in S03 include: SSL resource pool, IPS resource pool, and configured SID information.

[0048] The traffic orchestration order in S04 is as follows: traffic first enters the SSL resource pool and then enters the IPS resource pool.

[0049] Arrangement of paths in S04: The paths are identified in the order of system SIDs.

[0050] It should be noted that although the operations of the method of the present invention are described in a specific order in the above embodiments and drawings, this does not require or imply that these operations must be performed in this specific order, or that all illustrated operations must be performed to achieve the desired results. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0051] To more clearly explain the traffic orchestration method for a security resource pool using SRv6, a specific embodiment is provided below. However, it should be noted that this embodiment is intended only to better illustrate the present invention and does not constitute an undue limitation on the present invention.

[0052] S01. The security capability management platform module 110 receives business information and sends it to the traffic orchestration module 120 for analysis.

[0053] S02. The traffic orchestration system is built, and the required data communication equipment (router) nodes are required to ensure that they support SRv6 capabilities, and that network elements support SRv6 functions;

[0054] is-levelleve1-2cost-stylewide

[0055] bfdal1-interfacesenablebgp-lsenablelovel-2

[0056] notwork-entity10.0100.0001.0011.00is-nameR1

[0057] import-routedirecttraffic-engleve1-2#

[0058] ipv6enabletopologyipv6ipv6bgp-lsenablelevel-2

[0059] ipv6advertiselinkattributesipv6bfdall-interfaces enableipv6traffic-englevel-2

[0060] segment-routingipv6locatorhw_locator01ipv6avoid-microloopsegment-routing

[0061] ipv6avoid-microloopsegment-routingrib-update-delay3000ipv6import-routedirect

[0062] ipvEfrr

[0063] ioop-free-alternatelevel-2ti-ifalevel-2

[0064] S03. Complete the SID configuration of the resource pool in the edge cloud, such as the SSL (Secure Sockets Layer) resource pool, IPS (Intrusion Prevention Systems) resource pool and other devices, and configure SID and other information;

[0065] The SSL resource pool is configured as SID1

[0066] The configuration is as follows:

[0067] locatorSID1ipv6-prefix10:1:1:1::13:80

[0068] opcode64end

[0069] SRv6 SID1 is 10:1:1:1::13:80

[0070] The IPS resource pool is configured as SID2

[0071] The configuration is as follows:

[0072] locatorSID2ipv6-prefix19:19::1

[0073] opcode64end

[0074] SRv6 SID2 is 19:19::1

[0075] S04. Plan the traffic path (SID1-SID2...) according to the planned traffic arrangement sequence (traffic first enters the SSL resource pool and then the IPS resource pool), and mark the path in the order of system SIDs;

[0076] Segment-list1

[0077] index1sidipv610:1:1:1::13:80

[0078] index2sidipv619:19::1

[0079] index3sidipv6_10:1:i:1::14:260

[0080] segment-list2

[0081] index1sidipv610:1:1:1::13:80

[0082] index2sidipv619:19::1

[0083] index3sidipv610:1:1:1::14:260index4sidipv6_20:20::1

[0084] segment-list3

[0085] index1sidipv610:1:1:1::14:260

[0086] index2sidipv622:22::1

[0087] index3sidipv620:20::1

[0088] S05. Configure the channel according to the previously orchestrated traffic path, so that the entire orchestrated path takes effect on the device.

[0089] dispcurrent-configurationconfigurationtrafficpolicy

[0090] #trafficpolicylist1

[0091] share-mode

[0092] statisticsenable

[0093] classifierFWbehaviorFWprecedence1

[0094] #trafficpolicylist2

[0095] share-mode

[0096] statisticsenable

[0097] classifierFWDPIbehaviorFWDPIprecedence1

[0098] #trafficpolicylist3

[0099] share-mode

[0100] statisticsenable

[0101] classifierFWDPI_ARMbehaviorFWDPI_ARMprecedence1

[0102] S06. After the previous configuration is completed, an actual traffic path will be generated, indicating which devices will be entered first and which devices will be entered later, etc. The business flow will gradually enter the corresponding security resource pool module for security processing;

[0103] S07: After the traffic is cleaned, it is injected back to the target address through the external routing of the pool.

[0104] Based on the same inventive concept, the present invention also proposes a traffic orchestration device for a secure resource pool using SRv6. The implementation of this device can refer to the implementation of the above-mentioned method, and any repetitions will not be repeated. The term "module" used below may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and contemplated.

[0105] Figure 3 This is a schematic diagram of the structure of a traffic orchestration device for a security resource pool using SRv6 according to an embodiment of the present invention.

[0106] like Figure 3As shown, the device includes:

[0107] The security capability management platform module 110, the traffic orchestration module 120 and the security resource pool module 130, the security capability management platform module 110 is connected to the traffic orchestration module 120, and the traffic orchestration module 120 is connected to the security resource pool module 130, and all connections are bidirectional.

[0108] The security capability management platform module 110 is provided with a northbound interface, through which the security capability management platform module 110 sends and receives information to the traffic orchestration module 120. The information sent and received by the northbound interface includes: user registration, product registration, product ordering, product orchestration use, policy configuration and event reporting.

[0109] The traffic orchestration module 120 includes: a traffic editing component module 121, a controller module 122 and a southbound interface.

[0110] The traffic editing component module includes: a task scheduling module 1211 and a service orchestration module 1212 .

[0111] The controller module includes: a traffic orchestration module 1221 and an event notification module 1222 .

[0112] The southbound interface sends and receives information including: SRv6 tunnel creation, traffic injection and traction, and traffic orchestration strategy.

[0113] It should be noted that while the detailed description above mentions several modules of the traffic orchestration apparatus for a secure resource pool using SRv6, this division is merely exemplary and not mandatory. In practice, according to embodiments of the present invention, the features and functions of two or more modules described above may be embodied in a single module. Conversely, the features and functions of a single module described above may be further divided and embodied by multiple modules.

[0114] Based on the above invention concept, Figure 4 As shown, the present invention also proposes a computer device 200, including a memory 210, a processor 220, and a computer program 230 stored in the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, the aforementioned method for solving the traffic orchestration of the security resource pool through SRv6 is implemented.

[0115] Based on the aforementioned inventive concept, the present invention further proposes a computer-readable storage medium storing a computer program for executing the aforementioned method for solving traffic orchestration of a security resource pool through SRv6.

[0116] The present invention proposes a method and device for solving the traffic orchestration problem of the security resource pool through SRv6. The method and device use a traffic orchestration module to orchestrate the service traffic in the security capability management platform, obtain the traffic orchestration status through the module, and save the historical records of the traffic orchestration. The method receives the orchestration requirements of the security capability management platform, and the traffic orchestration module manages the data communication equipment of the resource pool to implement the establishment of SRv6 tunnels and service channels. The method allows the user's traffic to flow to different security capability resource pools in sequence according to the service orchestration strategy of the traffic orchestration module.

[0117] Although the spirit and principles of the present invention have been described with reference to several specific embodiments, it should be understood that the present invention is not limited to the specific embodiments disclosed, and the division into various aspects does not mean that the features of these aspects cannot be combined to benefit. Such division is only for the convenience of expression. The present invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

[0118] Regarding the limitation of the protection scope of the present invention, those skilled in the art should understand that, based on the technical solution of the present invention, various modifications or variations that can be made by those skilled in the art without creative work are still within the protection scope of the present invention.

Claims

1. A method for solving traffic orchestration of a security resource pool through SRv6, characterized in that: The method includes: S01. The security capability management platform module receives business information and sends it to the traffic orchestration module for analysis. S02. The traffic orchestration module is built, and the data communication device nodes and network elements required to be delivered support SRv6 capabilities. S03. Complete the SID configuration of the resource pool in the edge cloud; S04. Arrange the traffic path according to the planned traffic arrangement sequence; S05. Configure channels according to the orchestrated traffic path, so that the entire orchestrated path takes effect on the device. S06. Generate an actual traffic path, and the business flow enters the security resource pool module for security processing; S07: After the traffic is cleaned, it is injected back to the target address through the external routing of the pool.

2. The method for solving traffic orchestration of a security resource pool through SRv6 according to claim 1 is characterized in that: The resource pool in S03 includes: an SSL resource pool, an IPS resource pool, and configuration SID information.

3. The method for solving traffic orchestration of a security resource pool through SRv6 according to claim 2, characterized in that: The traffic arrangement order in S04 is as follows: the traffic first enters the SSL resource pool and then enters the IPS resource pool.

4. The method for solving traffic orchestration of a security resource pool through SRv6 according to claim 1, characterized in that: The arrangement of the paths in S04: the paths are identified in the order of the system SIDs.

5. A traffic orchestration device for solving the security resource pool through SRv6, characterized in that: The device includes: The security capability management platform module 110, the traffic orchestration module 120 and the security resource pool module 130 are connected. The security capability management platform module 110 is connected to the traffic orchestration module 120, and the traffic orchestration module 120 is connected to the security resource pool module 130. All connections are bidirectional. The security capability management platform module 110 is used to receive business information and send the business information to the traffic orchestration module 120 for analysis; The traffic orchestration module 120 is used to complete the SID configuration of the resource pool in the edge cloud; plan the traffic path according to the planned traffic orchestration sequence; configure the channel according to the orchestrated traffic path, so that the entire orchestrated path is effective on the device; generate an actual traffic path, and the business flow enters the security resource pool module 130 for security processing; The security resource pool module 130 is used to complete traffic cleaning. After the traffic is cleaned, it is injected back to the target address through the external pool route.

6. The traffic orchestration device for solving the security resource pool through SRv6 according to claim 5 is characterized in that: The security capability management platform module 110 is provided with a northbound interface, through which the security capability management platform module 110 sends and receives information to the traffic orchestration module 120. The information sent and received by the northbound interface includes: user registration, product registration, product ordering, product orchestration use, policy configuration and event reporting.

7. The device for arranging traffic for a security resource pool using SRv6 according to claim 5, characterized in that: The traffic orchestration module 120 includes: a traffic editing component module, a controller module and a southbound interface.

8. The traffic orchestration device for solving the security resource pool through SRv6 according to claim 7 is characterized in that: The traffic editing component module includes: a task scheduling module and a business orchestration module.

9. The traffic orchestration device for solving the security resource pool problem through SRv6 according to claim 7, characterized in that: The controller module includes: a traffic orchestration module and an event notification module.

10. The traffic orchestration device for solving the security resource pool through SRv6 according to claim 7, characterized in that: The southbound interface sends and receives information including: SRv6 tunnel creation, traffic injection and traction, and traffic orchestration strategy.

11. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 4 is implemented.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program for executing the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Method and device for implementing lessee service traffic arrangement by safe resource pool, and electronic equipment

    CN107819683A

  • Service execution method, device and system

    CN113497758A