Optical transport network control methods, devices, electronic equipment, and computer storage media

By adding an OVPN permission table to the domain controller (DC) of the OTN, the problem of decentralized control in optical transport networks is solved, accurate allocation and scheduling of resources are achieved, and resource isolation and end-to-end automatic activation are ensured under the two-level control architecture.

CN116132853BActive Publication Date: 2026-04-21CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2021-11-15
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In the two-level control architecture of Optical Transport Network (OTN), how to implement decentralized control to achieve resource isolation between users/systems with different permissions, especially in multi-vendor or multi-domain scenarios, is a challenge. Existing technologies cannot effectively achieve automatic decentralized control, resulting in mutual resource occupation and the inability to achieve end-to-end automatic activation.

Method used

Add an access control table for the Optical Virtual Private Network (OVPN) to the database of the Domain Controller (DC). This table includes the OVPN identifier, account, and IP address. Resource control is achieved through this access control table. Combined with the access control table creation request and resource control request of the super administrator account, this ensures accurate allocation and scheduling of resources.

Benefits of technology

It achieves resource isolation between users/systems with different permissions under a two-level control architecture, ensuring accurate allocation and scheduling of resources, avoiding mutual resource occupation, and supporting end-to-end automatic activation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132853B_ABST
    Figure CN116132853B_ABST
Patent Text Reader

Abstract

This embodiment discloses an optical transport network control method, apparatus, electronic device, and computer storage medium. The method includes: adding at least one OVPN permission table to the database of the DC, each OVPN permission table including an identifier of the OVPN, an account corresponding to the identifier of the OVPN, and an IP address corresponding to the identifier of the OVPN; upon receiving a first account login request from the DC, performing resource control on the OVPN according to the first account login request and the correspondence between the identifier and the account in the permission table; upon receiving a resource control request sent by the SC through the northbound interface, performing resource control on the OVPN according to the resource control request and the correspondence between the identifier and the IP address in the permission table.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to optical transmission technology, and more particularly to an optical transmission network control method, apparatus, electronic device, and computer storage medium. Background Technology

[0002] Currently, Software Defined Network (SDN) control technology has been introduced into Optical Transport Networks (OTNs), especially in multi-vendor or multi-domain scenarios, where it is necessary to... Figure 1 The two-tier control architecture shown implements access control for OTN. Figure 1 In this system, the two-tier control architecture includes a Domain Controller (DC) and a Super Controller (SC).

[0003] for Figure 1 The two-level control architecture shown presents a technical problem that urgently needs to be solved: how to achieve decentralized control. Summary of the Invention

[0004] This application provides a technical solution for optical transport network control, which can realize decentralized control in a two-level control architecture. This is beneficial for effectively isolating resources between users / systems with different permissions under a two-level control architecture.

[0005] This application provides a control method for an optical transport network, applied in the DC of an OTN, the method comprising:

[0006] Add at least one permission table for an Optical Virtual Private Network (OVPN) to the database of the DC. Each permission table includes the identifier of the OVPN, the account corresponding to the identifier of the OVPN, and the Internet Protocol (IP) IP address corresponding to the identifier of the OVPN.

[0007] Upon receiving a first account login request from the DC, resource control is performed on the OVPN based on the first account login request and the correspondence between the identifier and the account in the permission table; upon receiving a resource control request sent by the SC through the northbound interface, resource control is performed on the OVPN based on the resource control request and the correspondence between the identifier and the IP address in the permission table.

[0008] In some embodiments, adding at least one OVPN permission table to the database of the DC includes:

[0009] After logging into the DC using a second account login request based on the super administrator account, a permission table creation request corresponding to the super administrator account is received. The permission table creation request carries the identifier of each OVPN in the at least one OVPN, the account corresponding to the identifier of each OVPN, and the IP address corresponding to the identifier of each OVPN.

[0010] Based on the permission table creation request, add at least one OVPN permission table to the database of the DC.

[0011] In some embodiments, after adding the OVPN permission table to the DC's database, the method further includes:

[0012] Receive at least one OVPN creation request, each creation request is used to request the creation of an OVPN, and each creation request carries the resources of the corresponding OVPN;

[0013] Create the at least one OVPN based on the creation request of the at least one OVPN.

[0014] In some embodiments, the first account login request of the DC carries a user account;

[0015] The step of controlling OVPN resources based on the first account login request and the correspondence between identifiers and accounts in the permission table includes:

[0016] Based on the user account and the correspondence between the identifier and the account in the permission table, a first OVPN is determined, and the identifier of the first OVPN is the identifier of the OVPN corresponding to the user account.

[0017] Resource control is applied to the first OVPN based on its identifier.

[0018] In some embodiments, the method further includes: after logging into the DC based on the first account login request, receiving a resource acquisition request, wherein the resource acquisition request is used to request resources of the OVPN corresponding to the user account.

[0019] Accordingly, the step of performing resource control on the first OVPN based on the identifier of the first OVPN includes:

[0020] Based on the identifier of the first OVPN, the resources of the first OVPN are obtained, wherein the resources of the first OVPN are the resources of the OVPN corresponding to the user account.

[0021] In some embodiments, the method further includes:

[0022] After logging into the DC based on the first account login request, a resource scheduling request and the identifier of the first target OVPN are received. The resource scheduling request is used to request the scheduling of resources of the first target OVPN.

[0023] Accordingly, the step of performing resource control on the first OVPN based on the identifier of the first OVPN includes:

[0024] When the identifier of the first OVPN matches the identifier of the first target OVPN, resource scheduling is performed on the first OVPN according to the resource scheduling request.

[0025] In some embodiments, the resource control request carries the IP address of the source of the resource control request;

[0026] The step of controlling the OVPN's resources based on the resource control request and the mapping between identifiers and IP addresses in the permission table includes:

[0027] Based on the IP address of the source of the resource control request and the correspondence between the identifier and the IP address in the permission table, a second OVPN is determined, and the identifier of the second OVPN is the identifier of the OVPN corresponding to the IP address of the source of the resource control request.

[0028] Resource control is applied to the second OVPN based on its identifier.

[0029] In some embodiments, the resource control request is used to request resources from the OVPN corresponding to the IP address from which the resource control request originates;

[0030] Accordingly, the step of performing resource control on the second OVPN based on the identifier of the second OVPN includes:

[0031] Obtain the resources of the second OVPN, wherein the resources of the second OVPN are the resources of the OVPN corresponding to the IP address from which the resource control request originated.

[0032] In some embodiments, the resource control request further carries an identifier of the second target OVPN, and the resource control request is used to request the scheduling of resources of the second target OVPN;

[0033] Accordingly, the step of performing resource control on the second OVPN based on the identifier of the second OVPN includes:

[0034] When the identifier of the second OVPN matches the identifier of the second target OVPN, resource scheduling is performed on the second OVPN according to the resource control request.

[0035] In some embodiments, the method further includes:

[0036] When at least one OVPN has an OVPN that has experienced a resource change or alarm, the first account corresponding to the identifier of the OVPN that has experienced a resource change or alarm and the first IP address corresponding to the identifier of the OVPN that has experienced a resource change or alarm are determined according to the identifier of the OVPN that has experienced a resource change or alarm and the permission table.

[0037] The OVPN resource change information or alarm information is displayed on the interface of the first account; the OVPN resource change information or alarm information is sent to the SC through the northbound interface with the first IP address as the target address.

[0038] This application embodiment also provides an optical transport network control device, applied in the DC of an OTN, the device comprising:

[0039] The first processing module is used to add at least one OVPN permission table to the database of the DC. Each permission table includes the identifier of the OVPN, the account corresponding to the identifier of the OVPN, and the IP address corresponding to the identifier of the OVPN.

[0040] The second processing module is used to perform resource control on the OVPN when it receives a first account login request from the DC, based on the first account login request and the correspondence between the identifier and the account in the permission table; and to perform resource control on the OVPN when it receives a resource control request sent by the SC through the northbound interface, based on the resource control request and the correspondence between the identifier and the IP address in the permission table.

[0041] This application also provides an electronic device, including a processor and a memory for storing a computer program capable of running on the processor; wherein,

[0042] The processor is used to run the computer program to execute any of the above-described optical transport network control methods.

[0043] This application also provides a computer storage medium storing a computer program that, when executed by a processor, implements any of the above-described optical transport network control methods.

[0044] As can be seen from the embodiments of this application, the two-level control architecture of SC and DC can be used to realize the decentralized control of the two-level control architecture, which is conducive to effectively realizing resource isolation between users / systems with different permissions under the two-level control architecture. Attached Figure Description

[0045] Figure 1 This is a schematic diagram of a two-level control architecture in related technologies;

[0046] Figure 2 This is a schematic diagram of access control based on a two-level control architecture in related technologies.

[0047] Figure 3 This is another schematic diagram of access control based on a two-level control architecture in related technologies;

[0048] Figure 4 This is a schematic diagram illustrating the application scenario of the optical transport network control method in the embodiments of this application;

[0049] Figure 5 This is a flowchart of an optical transport network control method according to an embodiment of this application;

[0050] Figure 6 This is a schematic diagram illustrating the creation of an OVPN in an embodiment of this application;

[0051] Figure 7 This is another schematic diagram illustrating the creation of an OVPN in the embodiments of this application;

[0052] Figure 8 This is a schematic diagram of a process for obtaining OVPN resources in an embodiment of this application;

[0053] Figure 9 This is a schematic diagram of a process for scheduling OVPN resources in an embodiment of this application;

[0054] Figure 10 This is a schematic diagram of a process for obtaining resources based on a login account using a DC in an embodiment of this application;

[0055] Figure 11 This is a schematic diagram of a process for scheduling resources based on a DC login account in an embodiment of this application;

[0056] Figure 12 This is a schematic diagram of a process for obtaining resources based on an IP address using an SC in an embodiment of this application;

[0057] Figure 13 This is a schematic diagram of a process for scheduling resources based on IP addresses in an embodiment of this application;

[0058] Figure 14 This is a schematic diagram of the processing flow when resources change or alarms occur in the embodiments of this application;

[0059] Figure 15 This is a schematic diagram of the structure of the optical transport network control device according to an embodiment of this application;

[0060] Figure 16 This is a schematic diagram of the structure of the electronic device in the embodiments of this application. Detailed Implementation

[0061] Reference Figure 2 With the popularization of OTN and the diversification of services, there is a need for decentralized management of OTN, that is, the same OTN physical network is divided into two or more OVPNs, each OVPN can only be managed and controlled by designated operation and maintenance personnel, and resources are isolated between different virtual networks.

[0062] In related technologies, some manufacturers' domain controllers can perform hierarchical control based on user identity, but northbound interfaces cannot achieve hierarchical control. Figure 1 The two-tier control architecture shown cannot achieve automatic hierarchical control. The northbound interface is the interface for manufacturers or operators to access and manage the network; that is, the interface provided upwards.

[0063] Under a two-tiered management and control architecture, resource allocation can only be achieved through manual planning and agreements, which can easily lead to resource hogging between different maintenance personnel.

[0064] In related technologies, refer to Figure 3 The OTN leased line services provided by operators include intra-provincial leased lines and inter-provincial leased lines. Intra-provincial OTN leased line networks need to provide resources for both inter-provincial and intra-provincial leased lines simultaneously. Currently, intra-provincial OTN networks allocate resources for inter-provincial and intra-provincial leased lines manually. Because the northbound interface lacks a weighting function, the SC (Service Center) cannot call the intra-provincial controller through the interface, and the group's inter-provincial leased lines cannot achieve end-to-end automatic activation.

[0065] It can be seen that, in related technologies, access control for OTN can be implemented in the following two ways:

[0066] 1) Resources for different operations and maintenance personnel are planned and recorded manually, and operations are performed through the connection between SC and the DC of each domain. This makes it impossible to achieve strict resource isolation between different operations and maintenance personnel, which may lead to mutual resource occupation.

[0067] 2) Manually log in to each domain controller system and assign permissions through the domain controller account. This method cannot achieve end-to-end control; in multi-domain scenarios, services can only be enabled / controlled in segments through the control systems of each domain.

[0068] In view of the above-mentioned technical problems, the technical solutions of the embodiments of this application are proposed.

[0069] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments provided herein are merely illustrative of the present application and are not intended to limit the present application. Furthermore, the embodiments provided below are some embodiments for implementing the present application, and not all embodiments for implementing the present application. Unless otherwise specified, the technical solutions described in the embodiments of the present application can be implemented in any combination.

[0070] This application provides a control method for an optical transport network, which can be applied to the DC of an optical transport network (OTN). Figure 4 This is a schematic diagram illustrating the application scenario of the optical transport network control method in the embodiments of this application, such as... Figure 4 As shown, the DC of OTN can realize OVPN creation and resource isolation through the OVPN module. Different OVPN users (operation and maintenance personnel) can access the DC through SC or account to realize the management and control of the corresponding OVPN.

[0071] There are no new improvement requirements for the northbound interface in this embodiment of the application.

[0072] Figure 5 This is a flowchart illustrating the optical transport network control method according to an embodiment of this application, as shown below. Figure 5 As shown, the process may include:

[0073] Step 501: Add at least one OVPN permission table to the DC's database. Each permission table includes the identifier of the OVPN, the account corresponding to the identifier of the OVPN, and the IP address corresponding to the identifier of the OVPN.

[0074] In this embodiment of the application, the identifier of OVPN can be the name of OVPN, the identity document (ID) or other types of identifier; the account corresponding to the identifier of OVPN can be the login account of DC; and the IP address corresponding to the identifier of OVPN can be the IP address of SC.

[0075] In this embodiment, an OVPN access control module can be added to the DC to implement OVPN access control and OVPN CRUD operations. At least one OVPN access control table can also be added to the DC's database (see Table 1). The OVPN access control table may include an ovpnId field, which represents the OVPN identifier and is a primary key and a required field. For example, the OVPN access control table may also include an ipAdress field, which represents the SC's IP address and is optional. The OVPN access control table may also include a userId field, which represents the OVPN user account and is optional.

[0076] Table 1

[0077]

[0078] In some embodiments, an ovpnId field (foreign key) can be added to the existing resource (such as network element, board, port) database.

[0079] In some embodiments, the above implementation of adding at least one OVPN permission table to the DC's database may include:

[0080] After logging into the DC based on the super administrator account, a permission table creation request corresponding to the super administrator account is received. The permission table creation request carries at least one identifier of each OVPN in the OVPN, the account corresponding to the identifier of each OVPN, and the IP address corresponding to the identifier of each OVPN.

[0081] Based on the permission table creation request, add at least one OVPN permission table to the DC's database.

[0082] In this embodiment, the super administrator account is a preset account, as shown below. Figure 6 and Figure 7 After receiving a second account login request from the super administrator account, it can receive a permission table creation request corresponding to the super administrator account, thereby creating an OVPN permission table.

[0083] As can be seen, the super administrator can directly create the OVPN permission table on the DC through the super administrator account, which is beneficial for the subsequent creation of OVPN.

[0084] In some embodiments, after adding the OVPN permission table to the database of the DC, at least one OVPN creation request can be received. Each creation request is used to request the creation of an OVPN, and each creation request carries the resources of the corresponding OVPN. At least one OVPN is created according to the creation request of the at least one OVPN.

[0085] Reference Figure 6 and Figure 7 You can configure OVPN associated accounts to enable OVPN resources to be configured and scheduled in the DC. Here, the OVPN associated account can be the account in the OVPN permission table that corresponds to the identifier of each OVPN.

[0086] Reference Figure 6 and Figure 7 You can configure OVPN to associate with IP addresses, enabling OVPN to configure and schedule OVPN resources through the northbound interface.

[0087] Reference Figure 6 and Figure 7 Furthermore, it allows configuration of site resource ownership, where site resources represent the resources to be configured for OVPN. For example, if the target OVPN's ID is IDX, then the site resources can be configured to be assigned to the target OVPN by setting the site resource's ID to IDX. Exemplarily, site resources can be network elements, cards, ports, etc.

[0088] As can be seen, the embodiments of this application can accurately create an OVPN based on the OVPN creation request and configure OVPN resources.

[0089] Step 502: Upon receiving the first account login request from the DC, perform resource control on the OVPN based on the first account login request and the correspondence between the identifier and the account in the permission table; upon receiving the resource control request sent by the SC through the northbound interface, perform resource control on the OVPN based on the resource control request and the correspondence between the identifier and the IP address in the permission table.

[0090] In this embodiment, resource control of OVPN includes at least one of the following: OVPN resource synchronization, OVPN resource acquisition, OVPN resource access, and OVPN resource scheduling. For example, OVPN resource scheduling may include operations such as port configuration, OVPN-based service activation, and service bandwidth modification.

[0091] In some embodiments, the first account login request of the DC carries a user account; accordingly, the implementation of resource control of the OVPN based on the first account login request and the correspondence between the identifier and the account in the permission table may include: determining the first OVPN based on the user account and the correspondence between the identifier and the account in the permission table, wherein the identifier of the first OVPN is the identifier of the OVPN corresponding to the user account; and performing resource control on the first OVPN based on the identifier of the first OVPN.

[0092] After the super administrator creates an OVPN, ordinary administrators can access and schedule the OVPN resources associated with them through their accounts. For OVPN resource synchronization or acquisition scenarios, after logging into the DC based on the first account login request, a resource acquisition request can be received. The resource acquisition request is used to request the acquisition of OVPN resources corresponding to the user account.

[0093] Reference Figure 8After receiving the first account login request, the DC can parse the first account login request to obtain the user account, determine the ovpnId corresponding to the user account according to the OVPN permission table, and push all network resources (pre-configured site resources belonging to OVPN) corresponding to the ovpnId to the corresponding user account.

[0094] For scenarios involving access to or scheduling OVPN resources, after logging into the DC based on the first account login request, a resource scheduling request and the identifier of the first target OVPN can be received. The resource scheduling request is used to request the scheduling of resources from the first target OVPN. (Refer to...) Figure 9 The DC can receive the first account login request; then, by parsing the first account login request, it obtains the user account, and according to the OVPN's permission table, it determines whether the user account matches the first target OVPN (operation object). If the user account matches the operation object, it performs resource scheduling on the first target OVPN according to the operation instructions corresponding to the resource scheduling request; if the user account does not match the operation object, it can return a "no operation permission" response message to the user account.

[0095] As can be seen, the embodiments of this application can accurately determine the OVPN that needs resource control based on the DC's first account login request and the pre-created permission table, thereby achieving accurate control over OVPN resources.

[0096] In some embodiments, after logging into the DC based on the first account login request, a resource acquisition request is received. The resource acquisition request is used to request the acquisition of resources of the OVPN corresponding to the user account. Accordingly, resource control of the first OVPN according to the identifier of the first OVPN may include: acquiring the resources of the first OVPN according to the identifier of the first OVPN, wherein the resources of the first OVPN are the resources of the OVPN corresponding to the user account.

[0097] Reference Figure 10 Users or administrators can log in to the DC account through the user interface; the DC can determine the OVPN resources corresponding to the user account based on the user account, and push the OVPN resources corresponding to the user account to the user or administrator.

[0098] As can be seen, the embodiments of this application can accurately push OVPN resources to the corresponding user accounts based on the user accounts in the first account login request.

[0099] In some embodiments, after logging into the DC based on the first account login request, a resource scheduling request and an identifier of a first target OVPN can be received. The resource scheduling request is used to request the scheduling of resources of the first target OVPN. Accordingly, the step of performing resource control on the first OVPN based on the identifier of the first OVPN includes: when the identifier of the first OVPN matches the identifier of the first target OVPN, performing resource scheduling on the first OVPN based on the resource scheduling request.

[0100] Here, when the identifier of the first OVPN matches the identifier of the first target OVPN, the user account can be considered to match the target of the operation; when the identifier of the first OVPN does not match the identifier of the first target OVPN, the user account can be considered to not match the target of the operation.

[0101] Reference Figure 11 Users or administrators can log in to the DC through the user interface; the DC can determine the ovpnId corresponding to the user account based on the user account; if the user account and the operation object are successfully matched, the operation result is returned to the user or administrator; here, the operation result represents the result obtained by performing the corresponding operation according to the resource scheduling request; if the user account and the operation object do not match, the DC can return the response message "no operation permission" to the user or administrator.

[0102] As can be seen, the embodiments of this application can accurately push the results of the corresponding operation performed according to the resource scheduling request to the corresponding user account based on the user account in the first account login request, that is, accurately push the resource scheduling results to the corresponding user account.

[0103] In some embodiments, the resource control request carries the IP address of the source of the resource control request; correspondingly, the implementation of resource control on the OVPN based on the resource control request and the correspondence between identifiers and IP addresses in the permission table may include: determining a second OVPN based on the IP address of the source of the resource control request and the correspondence between identifiers and IP addresses in the permission table, wherein the identifier of the second OVPN is the identifier of the OVPN corresponding to the IP address of the source of the resource control request; and performing resource control on the second OVPN based on the identifier of the second OVPN.

[0104] After the super administrator creates an OVPN, the SC system can exercise resource control over the associated OVPN resources through the northbound interface. For OVPN resource synchronization or acquisition scenarios, the resource control request carries the IP address of the source of the resource control request.

[0105] Reference Figure 8The DC can receive resource control requests; then, by parsing the resource control requests, it obtains the IP address of the source of the resource control requests, determines the ovpnId corresponding to the source IP address of the resource control requests according to the OVPN permission table, and pushes all network resources (pre-configured site resources belonging to OVPN) corresponding to the ovpnId to the SC.

[0106] For scenarios involving access to or scheduling of OVPN resources, the resource control request also carries the identifier of the second target OVPN. This resource control request is used to request the scheduling of resources from the second target OVPN. (Refer to...) Figure 9 The DC can receive resource control requests; then, by parsing the resource control requests, it obtains the IP address of the source of the resource control requests. According to the OVPN's permission table, it determines whether the IP address of the source of the resource control requests matches the second target OVPN (the object of operation). If the IP address of the source of the resource control requests matches the object of operation, it performs resource scheduling on the second target OVPN according to the operation instructions corresponding to the resource scheduling request; if the IP address of the source of the resource control requests does not match the object of operation, it can return a "no operation permission" response message to the SC.

[0107] As can be seen, the embodiments of this application can accurately determine the OVPN that needs resource control based on the resource control request sent by the SC and the pre-created permission table, thereby achieving accurate control over OVPN resources.

[0108] In some embodiments, the resource control request carries the IP address of the source of the resource control request; correspondingly, resource control of the OVPN based on the resource control request and the correspondence between identifiers and IP addresses in the permission table may include: determining a second OVPN based on the IP address of the source of the resource control request and the correspondence between identifiers and IP addresses in the permission table, wherein the identifier of the second OVPN is the identifier of the OVPN corresponding to the IP address of the source of the resource control request; and performing resource control on the second OVPN based on the identifier of the second OVPN.

[0109] Reference Figure 12 The SC can send a resource control request to the DC through the northbound interface; the DC can determine the OVPN resource corresponding to the IP address based on the source IP address of the resource control request, and push the OVPN resource corresponding to the IP address to the SC.

[0110] As can be seen, the embodiments of this application can accurately push OVPN resources to the SC based on the IP address of the source of the resource control request.

[0111] In some embodiments, the resource control request further carries an identifier of the second target OVPN, and the resource control request is used to request the scheduling of resources of the second target OVPN; accordingly, resource control of the second OVPN based on the identifier of the second OVPN includes: when the identifier of the second OVPN matches the identifier of the second target OVPN, resource scheduling of the second OVPN is performed according to the resource control request.

[0112] Here, when the identifier of the second OVPN matches the identifier of the second target OVPN, it can be assumed that the source IP address of the resource control request matches the target of the operation; when the identifier of the second OVPN does not match the identifier of the second target OVPN, it can be assumed that the source IP address of the resource control request does not match the target of the operation.

[0113] Reference Figure 13 The SC can send resource control requests to the DC through the northbound interface; the DC can determine the ovpnId corresponding to the source IP address of the resource control request based on the source IP address; if the source IP address of the resource control request successfully matches the operation object, it returns the operation result to the SC; here, the operation result represents the result obtained by performing the corresponding operation according to the resource scheduling request; if the source IP address of the resource control request does not match the operation object, it can return a "no operation permission" response message to the SC.

[0114] As can be seen, the embodiments of this application can accurately push the results of the corresponding operations performed according to the resource scheduling request to the SC based on the IP address of the source of the resource control request.

[0115] In practical applications, steps 501 to 502 can be implemented using a DC processor. This processor can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), controller, microcontroller, or microprocessor. Understandably, other electronic devices can also implement the above processor functions, and this application embodiment does not impose limitations.

[0116] As can be seen, the embodiments of this application can realize the decentralized control of the two-level control architecture of SC and DC, which is conducive to effectively realizing resource isolation between users / systems with different permissions under the two-level control architecture.

[0117] In some embodiments, the method further includes:

[0118] When at least one OVPN has an OVPN that has experienced a resource change or alarm, the first account corresponding to the OVPN that has experienced a resource change or alarm and the first IP address corresponding to the OVPN that has experienced a resource change or alarm are determined based on the identifier of the OVPN that has experienced a resource change or alarm and the permission table.

[0119] The interface of the first account displays OVPN resource change information or alarm information; using the first IP address as the target address, the OVPN resource change information or alarm information is sent to the SC through the northbound interface.

[0120] Reference Figure 14 When OVPN resources change or trigger an alarm, the DC should proactively push the resource change or alarm message to the SC or DC's user interface. Upon a resource change or alarm, the DC retrieves the corresponding ovpnId from the resource database table, and then searches the OVPN permissions table to obtain the corresponding IP address list and user account list. Here, each IP address in the IP address list is the aforementioned first address, and each account in the user account list is the aforementioned first account.

[0121] After obtaining the corresponding IP address list and user account list, the corresponding resource change or alarm message can be reported sequentially to the SC in the corresponding IP address list through the northbound interface, or the corresponding resource change or alarm message can be pushed sequentially to the accounts in the corresponding account list, or the corresponding resource change or alarm message can be pushed sequentially to all super administrator accounts.

[0122] As can be seen, the embodiments of this application can accurately push resource change or alarm messages to the corresponding user accounts and SCs when OVPN resources change or alarms occur.

[0123] This application proposes a distributed control scheme for optical transport networks. At the data center (DC), permissions are assigned based on user accounts or the IP address of the northbound interface packets, and resources are mapped accordingly. Through a modular architecture design of the management system, an OVPN distributed control module is added between the northbound interface and the web interface to handle OVPN operations, resource permission allocation, and distributed control verification for all resources. An OVPN permission table and its fields are added to the database. An ovpnId field is added to all resources to represent the corresponding OVPN.

[0124] In related technologies, a robust mechanism for decentralized operation and resource isolation is lacking in multi-domain OTN network scenarios. The technical solution of this application embodiment can simultaneously achieve decentralized control based on domain management system accounts and SC IP addresses, effectively realizing resource isolation between users / systems with different permissions under a two-level control architecture (domain management system + SC) in a multi-domain OTN network.

[0125] Based on the optical transport network control method proposed in the foregoing embodiments, this application also proposes an optical transport network control device that can be applied in DC. Figure 15 This is a schematic diagram of the composition structure of an optical transport network control device according to an embodiment of this application, as shown below. Figure 15 As shown, the customer value determination device may include a first processing module 151 and a second processing module 152, wherein,

[0126] The first processing module 151 is used to add at least one OVPN permission table to the database of the DC. Each permission table includes the identifier of the OVPN, the account corresponding to the identifier of the OVPN, and the IP address corresponding to the identifier of the OVPN.

[0127] The second processing module 152 is used to perform resource control on the OVPN according to the first account login request and the correspondence between the identifier and the account in the permission table when it receives the first account login request from the DC; and to perform resource control on the OVPN according to the resource control request and the correspondence between the identifier and the IP address in the permission table when it receives the resource control request sent by the SC through the northbound interface.

[0128] In some embodiments, the first processing module 151 is specifically used for:

[0129] After logging into the DC using a second account login request based on the super administrator account, a permission table creation request corresponding to the super administrator account is received. The permission table creation request carries the identifier of each OVPN in the at least one OVPN, the account corresponding to the identifier of each OVPN, and the IP address corresponding to the identifier of each OVPN.

[0130] Based on the permission table creation request, add at least one OVPN permission table to the database of the DC.

[0131] In some embodiments, the first processing module 151 is further configured to receive a creation request for at least one OVPN after adding an OVPN permission table to the database of the DC, and create the at least one OVPN according to the creation request of the at least one OVPN; each creation request is used to request the creation of an OVPN, and each creation request carries the resources of the corresponding OVPN.

[0132] In some embodiments, the first account login request of the DC carries a user account; the second processing module 152 is specifically used for:

[0133] Based on the user account and the correspondence between the identifier and the account in the permission table, a first OVPN is determined, and the identifier of the first OVPN is the identifier of the OVPN corresponding to the user account.

[0134] Resource control is applied to the first OVPN based on its identifier.

[0135] In some embodiments, the second processing module 152 is further configured to:

[0136] After logging into the DC based on the first account login request, a resource acquisition request is received. The resource acquisition request is used to request the acquisition of OVPN resources corresponding to the user account.

[0137] The second processing module 152 is specifically used for:

[0138] Based on the identifier of the first OVPN, the resources of the first OVPN are obtained, wherein the resources of the first OVPN are the resources of the OVPN corresponding to the user account.

[0139] In some embodiments, the second processing module 152 is further configured to receive a resource scheduling request and an identifier of a first target OVPN after logging into the DC based on the first account login request, wherein the resource scheduling request is used to request the scheduling of resources of the first target OVPN;

[0140] The second processing module 152 is specifically used for:

[0141] When the identifier of the first OVPN matches the identifier of the first target OVPN, resource scheduling is performed on the first OVPN according to the resource scheduling request.

[0142] In some embodiments, the resource control request carries the IP address of the source of the resource control request;

[0143] The second processing module 152 is specifically used for:

[0144] Based on the IP address of the source of the resource control request and the correspondence between the identifier and the IP address in the permission table, a second OVPN is determined, and the identifier of the second OVPN is the identifier of the OVPN corresponding to the IP address of the source of the resource control request.

[0145] Resource control is applied to the second OVPN based on its identifier.

[0146] In some embodiments, the resource control request is used to request resources from the OVPN corresponding to the IP address from which the resource control request originates;

[0147] The second processing module 152 is specifically used for:

[0148] Obtain the resources of the second OVPN, wherein the resources of the second OVPN are the resources of the OVPN corresponding to the IP address from which the resource control request originated.

[0149] In some embodiments, the resource control request further carries an identifier of the second target OVPN, and the resource control request is used to request the scheduling of resources of the second target OVPN;

[0150] The second processing module 152 is specifically used for:

[0151] When the identifier of the second OVPN matches the identifier of the second target OVPN, resource scheduling is performed on the second OVPN according to the resource control request.

[0152] In some embodiments, the second processing module 152 is further configured to:

[0153] When at least one OVPN has an OVPN that has experienced a resource change or alarm, the first account corresponding to the identifier of the OVPN that has experienced a resource change or alarm and the first IP address corresponding to the identifier of the OVPN that has experienced a resource change or alarm are determined according to the identifier of the OVPN that has experienced a resource change or alarm and the permission table.

[0154] The OVPN resource change information or alarm information is displayed on the interface of the first account; the OVPN resource change information or alarm information is sent to the SC through the northbound interface with the first IP address as the target address.

[0155] In practical applications, both the first processing module 151 and the second processing module 152 can be implemented using a DC-connected processor. This processor can be at least one of an ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, or microprocessor. Understandably, other electronic devices can also implement the functions of the aforementioned processor, and this application embodiment does not impose any limitations.

[0156] It should be noted that the descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0157] It should be noted that, in the embodiments of this application, if the above methods are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a terminal, server, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0158] Correspondingly, this application embodiment further provides a computer program product, which includes computer-executable instructions for implementing any of the optical transport network control methods provided in this application embodiment.

[0159] Accordingly, this application embodiment further provides a computer storage medium storing computer-executable instructions, which are used to implement any of the optical transport network control methods provided in the above embodiments.

[0160] This application also provides an electronic device that can be used in a DC (Digital DC). Figure 16 A schematic diagram of an optional component structure of the electronic device provided in an embodiment of this application is shown below. Figure 16 As shown, the electronic device 160 includes:

[0161] Memory 161 is used to store executable instructions;

[0162] The processor 162 is used to implement any of the above-described optical transport network control methods when executing executable instructions stored in the memory 161.

[0163] The processor 162 mentioned above can be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, and microprocessor.

[0164] The aforementioned computer-readable storage medium / memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM), etc.; it can also be various terminals that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0165] It should be noted that the descriptions of the storage medium and device embodiments above are similar to those of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0166] It should be understood that the phrase "some embodiments" mentioned throughout the specification means that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, "some embodiments" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0167] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0168] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0169] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of the embodiments of this application, depending on actual needs.

[0170] In addition, each functional unit in the various embodiments of this application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0171] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause the device automatic test line to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0172] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0173] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0174] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A control method for an optical transport network, characterized in that, The method, applied in a domain controller (DC) of an optical transport network (OTN), includes: Add at least one permission table for an Optical Virtual Private Network (OVPN) to the database of the DC. Each permission table includes the identifier of the OVPN, the account corresponding to the identifier of the OVPN, and the Internet Protocol (IP) address corresponding to the identifier of the OVPN. Upon receiving a first account login request from the DC, resource control is performed on the OVPN based on the first account login request and the correspondence between the identifier and the account in the permission table; upon receiving a resource control request sent by the super controller SC through the northbound interface, resource control is performed on the OVPN based on the resource control request and the correspondence between the identifier and the IP address in the permission table.

2. The method according to claim 1, characterized in that, The step of adding at least one OVPN permission table to the database of the DC includes: After logging into the DC using a second account login request based on the super administrator account, a permission table creation request corresponding to the super administrator account is received. The permission table creation request carries the identifier of each OVPN in the at least one OVPN, the account corresponding to the identifier of each OVPN, and the IP address corresponding to the identifier of each OVPN. Based on the permission table creation request, add at least one OVPN permission table to the database of the DC.

3. The method according to claim 2, characterized in that, After adding the OVPN permission table to the database of the DC, the method further includes: Receive at least one OVPN creation request, each creation request is used to request the creation of an OVPN, and each creation request carries the resources of the corresponding OVPN; Create the at least one OVPN based on the creation request of the at least one OVPN.

4. The method according to claim 1, characterized in that, The first account login request of the DC carries the user account; The step of controlling OVPN resources based on the first account login request and the correspondence between identifiers and accounts in the permission table includes: Based on the user account and the correspondence between the identifier and the account in the permission table, a first OVPN is determined, and the identifier of the first OVPN is the identifier of the OVPN corresponding to the user account. Resource control is applied to the first OVPN based on its identifier.

5. The method according to claim 4, characterized in that, The method further includes: After logging into the DC based on the first account login request, a resource acquisition request is received. The resource acquisition request is used to request the acquisition of OVPN resources corresponding to the user account. Accordingly, the step of performing resource control on the first OVPN based on the identifier of the first OVPN includes: Based on the identifier of the first OVPN, the resources of the first OVPN are obtained, wherein the resources of the first OVPN are the resources of the OVPN corresponding to the user account.

6. The method according to claim 4, characterized in that, The method further includes: After logging into the DC based on the first account login request, a resource scheduling request and the identifier of the first target OVPN are received. The resource scheduling request is used to request the scheduling of resources of the first target OVPN. Accordingly, the step of performing resource control on the first OVPN based on the identifier of the first OVPN includes: When the identifier of the first OVPN matches the identifier of the first target OVPN, resource scheduling is performed on the first OVPN according to the resource scheduling request.

7. The method according to claim 1, characterized in that, The resource control request carries the IP address of the source of the resource control request; The step of controlling the OVPN's resources based on the resource control request and the mapping between identifiers and IP addresses in the permission table includes: Based on the IP address of the source of the resource control request and the correspondence between the identifier and the IP address in the permission table, a second OVPN is determined, and the identifier of the second OVPN is the identifier of the OVPN corresponding to the IP address of the source of the resource control request. Resource control is applied to the second OVPN based on its identifier.

8. The method according to claim 7, characterized in that, The resource control request is used to request the acquisition of OVPN resources corresponding to the IP address from which the resource control request originates; Accordingly, the step of performing resource control on the second OVPN based on the identifier of the second OVPN includes: Obtain the resources of the second OVPN, wherein the resources of the second OVPN are the resources of the OVPN corresponding to the IP address from which the resource control request originated.

9. The method according to claim 7, characterized in that, The resource control request also carries the identifier of the second target OVPN, and the resource control request is used to request the scheduling of resources of the second target OVPN; Accordingly, the step of performing resource control on the second OVPN based on the identifier of the second OVPN includes: When the identifier of the second OVPN matches the identifier of the second target OVPN, resource scheduling is performed on the second OVPN according to the resource control request.

10. The method according to any one of claims 1 to 9, characterized in that, The method further includes: When at least one OVPN has an OVPN that has experienced a resource change or alarm, the first account corresponding to the identifier of the OVPN that has experienced a resource change or alarm and the first IP address corresponding to the identifier of the OVPN that has experienced a resource change or alarm are determined according to the identifier of the OVPN that has experienced a resource change or alarm and the permission table. The OVPN resource change information or alarm information is displayed on the interface of the first account; the OVPN resource change information or alarm information is sent to the SC through the northbound interface with the first IP address as the target address.

11. A control device for an optical transmission network, characterized in that, The device, used in a domain controller (DC) of an optical transport network (OTN), includes: The first processing module is used to add at least one permission table for an Optical Virtual Private Network (OVPN) to the database of the DC. Each permission table includes the identifier of the OVPN, the account corresponding to the identifier of the OVPN, and the Internet Protocol (IP) address corresponding to the identifier of the OVPN. The second processing module is used to perform resource control on the OVPN when it receives a first account login request from the DC, based on the first account login request and the correspondence between the identifier and the account in the permission table; and to perform resource control on the OVPN when it receives a resource control request sent by the super controller SC through the northbound interface, based on the resource control request and the correspondence between the identifier and the IP address in the permission table.

12. An electronic device, characterized in that, Includes a processor and memory for storing computer programs that can run on the processor; wherein, The processor is used to run the computer program to perform the method according to any one of claims 1 to 10.

13. A computer storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the method described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • OVPN system, OVPN terminator, base apparatus, centralized conversion apparatus, and optical communication network

    JP2004193648A

  • METHODS, SYSTEMS AND APPARATUS FOR UTILIZING AN iSNS SERVER IN A NETWORK OF FIBRE CHANNEL OVER ETHERNET DEVICES

    US20120177370A1