User power and domain management method based on OTN device resources

By creating multi-level management users and region identifiers in OTN devices to form a user resource table and performing dual verification, the accuracy problem of hierarchical and domain-based management of OTN devices is solved, and the accuracy and real-time performance of device configuration are improved.

CN116156361BActive Publication Date: 2026-06-23CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
Filing Date
2022-12-29
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing technologies cannot effectively manage the hierarchical and domain-based management of OTN devices, leading to errors in user permission operations and affecting the accuracy of device configuration and service delivery.

Method used

A user-based hierarchical and domain-based management method based on OTN device resources is adopted. By creating multi-level management users and region identifiers, a user resource table is formed, and a dual verification mechanism is implemented to ensure the accuracy of configuration operations.

Benefits of technology

It implements dual verification for OTN device configuration operations, reduces the risk of permission operation errors, improves the accuracy and real-time performance of device operations, and supports centralized and unified management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116156361B_ABST
    Figure CN116156361B_ABST
Patent Text Reader

Abstract

The application discloses a kind of user power distribution subarea management methods based on OTN equipment resource, comprising the following steps: creating user, user includes the multi-level management user with area identification, set in each management user under ordinary user, wherein, the area identification of upper management user in multi-level management user contains the area identification of lower management user;OTN equipment is distributed to corresponding management user according to area identification same and contained, and user resource table corresponding to user and equipment resource is formed simultaneously;Management user carries out resource allocation to lower management user or subordinate ordinary user to OTN equipment, and adjusts user resource table simultaneously according to allocation;User issues instruction to configure operation under subordinate equipment, and the device authority of user is secondly checked according to user resource table during configuration operation, and instruction is issued after verification, otherwise, configuration operation is stopped.The application has the beneficial effect of improving the accuracy of equipment operation in real time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information transmission network management technology. More specifically, this invention relates to a user-based, hierarchical management method for OTN device resources. Background Technology

[0002] With the continued rapid growth of high-bandwidth data services, there is an urgent need for information transmission networks with higher capacity. OTN technology, as an optoelectronic networking technology that inherits the advantages of SDH and WDM, is currently the best optical network transmission technology to meet the needs of new transmission services. One of the characteristics of OTN equipment is its wide distribution and large data volume. There can be tens of thousands of devices nationwide, and the corresponding number of boards and ports will be in the millions or tens of millions. Considering various types of ports (physical ports PTP, floating ports FTP, and link ports CTP), the resource quantity will be even higher. A large number of maintenance personnel are needed at all management levels for daily maintenance and operation management, which will also include operation and maintenance management in overlapping areas across provinces and cities. Faced with such a large number of access OTN devices that span across provinces and regions nationwide, and with management and operation and maintenance personnel at all levels, the management of OTN equipment, especially the decentralized and domain-based management of OTN equipment, is particularly important.

[0003] Current technologies lack coverage for this type of OTN equipment, which has more granular resource details, but current technology cannot meet these needs. Furthermore, given the nationwide transmission network, any disruption can have far-reaching consequences. During equipment configuration or service deployment, user error due to system display issues or other reasons could lead to numerous adverse effects. Summary of the Invention

[0004] One object of the present invention is to solve at least the above-mentioned problems and to provide at least the advantages that will be described later.

[0005] Another objective of this invention is to provide a user-based hierarchical management method for OTN device resources, which implements a dual verification and insurance mechanism for device configuration operations. During the verification process, the granularity level is reduced to ensure real-time operation while improving the accuracy of device operations.

[0006] To achieve these objectives and other advantages of the present invention, a user-based hierarchical management method for OTN device resources is provided, comprising the following steps: creating users, including multi-level management users with regional identifiers and ordinary users under each management user, wherein the regional identifier of the upper-level management user in the multi-level management user includes the regional identifier of the lower-level management user;

[0007] OTN devices are assigned to corresponding management users based on the same area identifier and whether they are included, and a user resource table corresponding to user and device resources is formed simultaneously.

[0008] The management user allocates resources of OTN devices to lower-level management users or ordinary users under its jurisdiction, and adjusts the user resource table accordingly.

[0009] Users issue commands to configure devices under their jurisdiction. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the command is issued; otherwise, the configuration operation is aborted.

[0010] Preferably, the user resource table includes a user network element table, a user board table, and a user port table;

[0011] The second verification is as follows:

[0012] Determine whether the device receiving the command is a port;

[0013] If so, check the user port table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0014] If not, determine whether the device receiving the instruction is a board;

[0015] If so, check the user's board table to see if the user has the necessary permissions. If so, issue the command if the verification passes; otherwise, abort the configuration operation.

[0016] If not, determine whether the device receiving the instruction is a network element;

[0017] If so, check the user's network element table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0018] If not, abort the configuration operation.

[0019] Preferably, the user port table is divided into multiple tables based on different user region identifiers;

[0020] The secondary verification process involves checking the user's port table to confirm whether the user has the necessary permissions.

[0021] Determine the region identifier of the user who issued the command;

[0022] Look up the user port table corresponding to the region identifier of the user who issued the command, and confirm whether the user has operation permissions based on the user port table.

[0023] Preferably, the user board tables are divided into multiple tables based on different user region identifiers;

[0024] The secondary verification process involves checking the user's board table to confirm whether the user has the necessary permissions.

[0025] Determine the region identifier of the user who issued the command;

[0026] Locate the user board table corresponding to the region identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user board table.

[0027] Preferably, the user network element table is divided into multiple tables based on different user area identifiers;

[0028] The secondary verification process involves checking the user's network element table to confirm whether the user has the necessary permissions.

[0029] Determine the region identifier of the user who issued the command;

[0030] Look up the user network element table corresponding to the area identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user network element table.

[0031] Preferably, before creating a user, system roles are also created, including regular roles and management roles;

[0032] To create a user, you need to bind a system role. When the bound system role is a regular role, the user is defined as a regular user; when the bound system role is an administrative role, the user is defined as an administrative user.

[0033] Preferably, the multi-level management users include a Level 1 management user, at least one Level 2 management user under the Level 1 management user, ..., at least one Level i+1 management user under each Level i management user, ..., at least one Level n management user under the Level n-1 management user, where n≥3.

[0034] Preferably, n=3, with Level 1 management users being group-level management users, Level 2 management users being provincial-level management users, and Level 3 management users being city-level management users.

[0035] Preferably, during the secondary verification process, before determining whether the device receiving the instruction is a port, it is determined whether the area identifier of the user who issued the instruction is equal to or contains the area identifier of the device receiving the instruction. If so, the verification passes and the instruction is issued; otherwise, it is determined whether the device receiving the instruction is a port. Attached Figure Description

[0036] Figure 1 This is a schematic diagram of the user's architecture according to one of the technical solutions of the present invention;

[0037] Figure 2 This is a schematic diagram of the secondary verification process according to one of the technical solutions of the present invention;

[0038] Figure 3 This is a schematic diagram of the secondary verification process according to one of the technical solutions of the present invention.

[0039] The present invention has at least the following beneficial effects:

[0040] A dual verification mechanism is implemented for device configuration operations to avoid user permission errors caused by system display issues or other reasons, thereby improving the accuracy of device operations. During the verification process, the verification is carried out sequentially based on the port, board, and network element, reducing the granularity level. Furthermore, the port is divided into regions during the hierarchical verification process to improve the real-time performance of the verification. Moreover, the relationship between the device region identifier and the user region identifier is prioritized for judgment, further improving the real-time performance of the verification.

[0041] In addition to dividing users into user groups based on regions, the system also divides users into hierarchical management levels, which facilitates the operator's overall allocation and centralized management.

[0042] Other advantages, objectives and features of the present invention will become apparent in part from the following description, and in part from those skilled in the art through study and practice of the invention. Detailed Implementation

[0043] The present invention will be further described in detail below with reference to embodiments, so that those skilled in the art can implement it based on the description.

[0044] <Example 1>

[0045] The user-based access control and domain management method based on OTN device resources includes the following steps:

[0046] S1. Create system roles. System roles include general roles and management roles. General roles include system maintenance roles, system operation roles, system monitoring roles, etc. Different roles can be flexibly configured with function operation permissions according to actual needs.

[0047] S2. Create a user and bind a system role to the created user, including:

[0048] When the bound system role is a regular role, it is defined as a regular user. Regular users are managed by their respective management users. Regular users cannot be automatically allocated resources; they can only be allocated resources through manual operation.

[0049] When the bound system role is an administrator role, it is defined as an administrator user, who is the manager of the system and devices. When devices come online, they will be automatically assigned to this type of user name. Each administrator user has a region identifier, and they are divided into multiple levels according to the inclusion relationship of the region identifier. In a multi-level administrator user, the region identifier of the upper-level administrator user includes the region identifier of the lower-level administrator user. Specifically: a multi-level administrator user includes a level 1 administrator user, at least one level 2 administrator user under the level 1 administrator user, ..., at least one level i+1 administrator user under each level i administrator user, ..., at least one level n administrator user under the level n-1 administrator user, where n≥3;

[0050] In one embodiment, such as Figure 1 As stated above, n=3, Level 1 management users are group-level management users, which is the highest level of management in the entire system. The region identifier is the highest level, encompassing all regions, meaning it has all provincial-level management users and other management users and ordinary users that may exist depending on the actual situation. Figure 1 (Not shown), by default, they possess all the system's device resources; Level 2 management users are provincial management users, whose regional identifier corresponds to a specific province. By default, they possess all the device resources within that province and are the highest level of management within that province. Below them are all the corresponding city-level management users within the province, as well as other management users and ordinary users that may exist depending on the actual situation. Figure 1 (Not shown); Level 3 management users are city-level management users, representing the highest level of management within the city. By default, they possess all device resources within the city, and have corresponding ordinary users below them, as well as any city-level management users that may exist depending on the actual situation. Figure 1 (Not explicitly stated), it is included layer by layer, which allows for centralized and unified management across all levels;

[0051] It is important to emphasize that while users have highlighted the concept of region, when allocating device resources, users can manage devices across provinces and regions. This can be achieved by having management users with different region identifiers perform resource allocation operations on the user. In other words, a management user may have two region identifiers with different ratings. For example, a provincial management user may have allocation permissions for devices in two provinces at the same time.

[0052] S3 and OTN devices are assigned to corresponding management users based on the same area identifier and whether they are included in the same area. A user resource table corresponding to user and device resources is simultaneously generated. Specifically:

[0053] For a new OTN device (which is a network element), each network element includes multiple cards, each card corresponds to multiple ports, and each OTN device has its own location identifier (region identifier). According to the region identifier, the network element, cards, and port resources of the OTN device are uniformly allocated to the management user with the same region identifier by default. The device resources will also be allocated to the superior user of the management user (the user whose region identifier includes the management user's region identifier).

[0054] For example, if a new OTN device is identified as Zhengzhou, Henan Province, all its resources will first be entered into the database according to network elements, boards, and ports. The backend will identify the device as a device in Zhengzhou, Henan Province based on the region identifier. The system will automatically classify it into group-level management users, provincial-level management users (Henan Province management users), and city-level management users (Zhengzhou, Henan Province management users). Then, each level of management user will allocate the resources to its subordinate management users or ordinary users as needed. All management users have allocation authority, but generally, the allocation is done by the direct management user, that is, by the city-level management user.

[0055] When OTN equipment is put into storage and allocated, a user resource table is generated during storage, which includes a user network element table, a user board table, and a user port table. The user network element table is a table showing the affiliation relationship between network elements and users; the user board table is a table showing the affiliation relationship between boards and users; and the user port table is a table showing the affiliation relationship between ports and users.

[0056] S4. Management users allocate resources of OTN devices to lower-level management users or ordinary users under their jurisdiction, and adjust the user resource table accordingly.

[0057] S5. Users issue instructions to their subordinate devices to perform configuration operations. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the instruction is issued; otherwise, the configuration operation is aborted.

[0058] like Figure 2 As shown, the secondary verification is specifically as follows:

[0059] Determine whether the device receiving the command is a port;

[0060] If so, check the user port table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0061] If not, determine whether the device receiving the instruction is a board;

[0062] If so, check the user's board table to see if the user has the necessary permissions. If so, issue the command if the verification passes; otherwise, abort the configuration operation.

[0063] If not, determine whether the device receiving the instruction is a network element;

[0064] If so, check the user's network element table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0065] If not, abort the configuration operation.

[0066] <Example 2>

[0067] The user-based access control and domain management method based on OTN device resources includes the following steps:

[0068] S1-S4 are the same as in Implementation Example 1, except that the user port tables are divided into multiple tables based on different user area identifiers;

[0069] S5. Users issue instructions to their subordinate devices to perform configuration operations. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the instruction is issued; otherwise, the configuration operation is aborted.

[0070] The second verification is as follows:

[0071] Determine whether the device receiving the command is a port;

[0072] If so, determine the region identifier of the user who issued the command, look up the user port table corresponding to the region identifier of the user who issued the command, and confirm whether the user has operation permissions based on the user port table. If yes, the verification passes and the command is issued; otherwise, the configuration operation is aborted.

[0073] If not, determine whether the device receiving the instruction is a board;

[0074] If so, check the user's board table to see if the user has the necessary permissions. If so, issue the command if the verification passes; otherwise, abort the configuration operation.

[0075] If not, determine whether the device receiving the instruction is a network element;

[0076] If so, check the user's network element table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0077] If not, abort the configuration operation.

[0078] <Example 3>

[0079] The user-based access control and domain management method based on OTN device resources includes the following steps:

[0080] S1-S4 are the same as in Implementation 1, except that the user port table and user board table are divided into multiple tables based on different user area identifiers;

[0081] S5. Users issue instructions to their subordinate devices to perform configuration operations. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the instruction is issued; otherwise, the configuration operation is aborted.

[0082] The second verification is as follows:

[0083] Determine whether the device receiving the command is a port;

[0084] If so, determine the region identifier of the user who issued the command, look up the user port table corresponding to the region identifier of the user who issued the command, and confirm whether the user has operation permissions based on the user port table. If yes, the verification passes and the command is issued; otherwise, the configuration operation is aborted.

[0085] If not, determine whether the device receiving the instruction is a board;

[0086] If so, search the user board table corresponding to the region identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user board table. If so, the instruction is issued after verification; otherwise, the configuration operation is aborted.

[0087] If not, determine whether the device receiving the instruction is a network element;

[0088] If so, check the user's network element table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0089] If not, abort the configuration operation.

[0090] <Example 4>

[0091] The user-based access control and domain management method based on OTN device resources includes the following steps:

[0092] S1-S4 are the same as in Implementation 1, except that the user port table, user board table, and user network element table are all divided into multiple tables based on different user area identifiers.

[0093] S5. Users issue instructions to their subordinate devices to perform configuration operations. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the instruction is issued; otherwise, the configuration operation is aborted.

[0094] The second verification is as follows:

[0095] Determine whether the device receiving the command is a port;

[0096] If so, determine the region identifier of the user who issued the command, look up the user port table corresponding to the region identifier of the user who issued the command, and confirm whether the user has operation permissions based on the user port table. If yes, the verification passes and the command is issued; otherwise, the configuration operation is aborted.

[0097] If not, determine whether the device receiving the instruction is a board;

[0098] If so, search the user board table corresponding to the region identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user board table. If so, the instruction is issued after verification; otherwise, the configuration operation is aborted.

[0099] If not, determine whether the device receiving the instruction is a network element;

[0100] If so, search the user network element table corresponding to the area identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user network element table. If yes, the instruction is issued after verification; otherwise, the configuration operation is aborted.

[0101] <Example 5>

[0102] The user-based access control and domain management method based on OTN device resources includes the following steps:

[0103] S1-S4 are the same as in Implementation Example 1, except that the user port tables are divided into multiple tables based on different user area identifiers;

[0104] S5. Users issue instructions to their subordinate devices to perform configuration operations. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the instruction is issued; otherwise, the configuration operation is aborted.

[0105] like Figure 3 As shown, the secondary verification is specifically as follows:

[0106] Determine whether the region identifier of the user issuing the command is equal to or contains the region identifier of the device receiving the command. If yes, the verification passes and the command is issued. If no, determine whether the device receiving the command is a port.

[0107] Determine whether the device receiving the command is a port;

[0108] If so, determine the region identifier of the user who issued the command, look up the user port table corresponding to the region identifier of the user who issued the command, and confirm whether the user has operation permissions based on the user port table. If yes, the verification passes and the command is issued; otherwise, the configuration operation is aborted.

[0109] If not, determine whether the device receiving the instruction is a board;

[0110] If so, check the user's board table to see if the user has the necessary permissions. If so, issue the command if the verification passes; otherwise, abort the configuration operation.

[0111] If not, determine whether the device receiving the instruction is a network element;

[0112] If so, check the user's network element table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation.

[0113] If not, abort the configuration operation.

[0114] Although embodiments of the present invention have been disclosed above, they are not limited to the applications listed in the specification and embodiments. They can be applied to various fields suitable for the present invention. For those skilled in the art, other modifications can be easily made. Therefore, without departing from the general concept defined by the claims and their equivalents, the present invention is not limited to the specific details and illustrations shown and described herein.

Claims

1. A user-based access control and domain-based management method for OTN device resources, characterized in that: Includes the following steps: Create users, which include multi-level management users with regional identifiers and ordinary users under each management user. Among them, the regional identifier of the upper-level management user in the multi-level management user includes the regional identifier of the lower-level management user. OTN devices are assigned to corresponding management users based on the same area identifier and whether they are included, and a user resource table corresponding to user and device resources is formed simultaneously. The management user allocates resources of OTN devices to lower-level management users or ordinary users under its jurisdiction, and adjusts the user resource table accordingly. Users issue commands to configure devices under their jurisdiction. During the configuration operation, the user's device permissions are verified twice based on the user's resource table. If the verification is successful, the command is issued; otherwise, the configuration operation is aborted. The user resource table includes the user network element table, the user board table, and the user port table. The second verification is as follows: Determine whether the device receiving the command is a port; If so, check the user port table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation. If not, determine whether the device receiving the instruction is a board; If so, check the user's board table to see if the user has the necessary permissions. If so, issue the command if the verification passes; otherwise, abort the configuration operation. If not, determine whether the device receiving the instruction is a network element; If so, check the user's network element table to see if the user has the necessary permissions. If yes, issue the command if the verification passes; otherwise, abort the configuration operation. If not, abort the configuration operation.

2. The user-based hierarchical and domain-based management method for OTN device resources as described in claim 1, characterized in that, The user port table is divided into multiple tables based on different user region identifiers; The secondary verification process involves checking the user's port table to confirm whether the user has the necessary permissions. Determine the region identifier of the user who issued the command; Look up the user port table corresponding to the region identifier of the user who issued the command, and confirm whether the user has operation permissions based on the user port table.

3. The user-based hierarchical and domain-based management method for OTN device resources as described in claim 2, characterized in that, The user board table is divided into multiple categories based on different user region identifiers; The secondary verification process involves checking the user's board table to confirm whether the user has the necessary permissions. Determine the region identifier of the user who issued the command; Locate the user board table corresponding to the region identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user board table.

4. The user-based hierarchical and domain-based management method for OTN device resources as described in claim 3, characterized in that, The user network element table is divided into multiple tables based on different user area identifiers; The secondary verification process involves checking the user's network element table to confirm whether the user has the necessary permissions. Determine the region identifier of the user who issued the command; Look up the user network element table corresponding to the area identifier of the user who issued the instruction, and confirm whether the user has operation permissions based on the user network element table.

5. The user-based hierarchical and domain-based management method for OTN device resources as described in claim 1, characterized in that, Before creating a user, you also need to create system roles, which include regular roles and management roles. To create a user, you need to bind a system role. When the bound system role is a regular role, the user is defined as a regular user; when the bound system role is an administrative role, the user is defined as an administrative user.

6. The user-based hierarchical and domain-based management method for OTN device resources as described in any one of claims 2-4, characterized in that, Multi-level management users include Level 1 management users, at least one Level 2 management user under the jurisdiction of Level 1 management users, ..., at least one Level n management user under the jurisdiction of Level n-1 management users, where n≥3.

7. The user-based hierarchical and domain-based management method for OTN device resources as described in claim 6, characterized in that, n=3, Level 1 management users are group-level management users, Level 2 management users are provincial-level management users, and Level 3 management users are city-level management users.

8. The user-based hierarchical and domain-based management method for OTN device resources as described in claim 7, characterized in that, During the secondary verification process, before determining whether the device receiving the instruction is a port, it is determined whether the area identifier of the user who issued the instruction is equal to or contains the area identifier of the device receiving the instruction. If so, the verification passes and the instruction is issued; otherwise, it is determined whether the device receiving the instruction is a port.

Citation Information

Patent Citations

  • CN114339810A