Data transmission method and system in software defined wide area network (SD-WAN)

CN116389018BActive Publication Date: 2026-09-22CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111658851.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-30
Publication Date
2026-09-22
Estimated Expiration
2041-12-30

AI Technical Summary

Technical Problem

[0005]本公开的目的在于提供一种软件定义广域网SD-WAN中的数据传输方法及系统、计算机存储介质和电子设备,进而至少在一定程度上避免和克服由于相关技术的缺陷而导致的SD-WAN边缘节点之间数据传输效率低、资源损耗高和传输路径不可选等问题

Benefits of technology

[0017]本公开的示例性实施例中的软件定义广域网SD-WAN中的数据传输方法,SD-WAN边缘节点接收SD-WAN控制器下发的互联网安全协议IPSec 隧道的配置参数,该配置参数中包括IPSec参数和用于指示报文传输至目的 SD-WAN边缘节点的传输结点路径和SRv6参数,SD-WAN边缘节点对用户报文封装包括IPSec参数和SRv6参数的报文头部得到封装报文,并将封装报文发送至互联网,以使封装报文按照传输结点路径传输至目的SD-WAN 边缘节点。一方面,SD-WAN边缘节点按照SD-WAN控制器下发的互联网安全协议IPSec隧道的配置参数对用户报文封装包括IPSec参数和SRv6参数的报文头部,而SRv6参数用于指示报文传输至目的SD-WAN边缘节点的传输结点路径,从而封装报文在互联网中的传输路径可编程化,通过 SD-WAN控制器实现对SD-WAN边缘节点之间数据传输路径的可选择性,能够根据不同的网络传输条件选取最优路径以IPSec隧道的配置参数的形式下发至SD-WAN边缘节点,从而可以实现传输路径的保护、路径分担等功能,协调数据传输效率和网络传输资源;另一方面,由于互联网中的IPv6 地址均为公网地址,因此避免了私有地址NAT(Network AddressTranslation, 网络地址转换)穿越的问题,同时也实现在SD-WAN网络中应用SRv6协议进行数据传输。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116389018B_ABST
    Figure CN116389018B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of communication, and relates to a data transmission method and system in a software-defined wide area network (SD-WAN), a storage medium and an electronic device. The method comprises: an SD-WAN edge node receiving configuration parameters of an Internet Protocol Security (IPSec) tunnel issued by an SD-WAN controller, at least including an IPSec parameter and an SRv6 parameter, the SRv6 parameter being used to indicate a transport node path of a message transmitted to a destination SD-WAN edge node; encapsulating a message header including the IPSec parameter and the SRv6 parameter to obtain an encapsulated message for a user message; and sending the encapsulated message to the Internet so that the encapsulated message is transmitted to the destination SD-WAN edge node according to the transport node path. In the present disclosure, the SD-WAN edge node specifies a forwarding path of a user message according to the configuration parameters of the IPSec tunnel issued by the SD-WAN controller, and a programmable network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and more specifically, to a data transmission method, a data transmission system, a computer storage medium, and an electronic device in a Software-Defined Wide Area Network (SD-WAN). Background Technology

[0002] SD-WAN (Software Defined Wide Area Network) is a service that applies SDN (Software Defined Network) technology to wide area network scenarios to connect enterprise networks, data centers, Internet applications, and cloud services across a wide geographical area.

[0003] In related technologies, SD-WAN edge nodes are connected via the Internet Protocol Security (IPSec). The propagation path of IPSec packets in the Internet is determined by the routing in the Internet switch. However, if the channel between SD-WAN edge nodes includes multiple IPSec tunnels, multiple IPSec decapsulation and recapsulation are required when transmitting data in each IPSec tunnel. This results in low transmission efficiency, resource consumption, and the data propagation path can only be uniquely determined by the routing in the Internet switch, making it impossible to make timely adjustments based on network transmission conditions.

[0004] It should be noted that the information in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0005] The purpose of this disclosure is to provide a data transmission method and system, computer storage medium and electronic device in Software-Defined Wide Area Network (SD-WAN), thereby at least to some extent avoiding and overcoming problems such as low data transmission efficiency, high resource consumption and unselectable transmission paths between SD-WAN edge nodes caused by the defects of related technologies.

[0006] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.

[0007] According to one aspect of this disclosure, a data transmission method in a Software-Defined Wide Area Network (SD-WAN) is provided, comprising: an SD-WAN edge node receiving configuration parameters for an Internet Security Protocol (IPSec) tunnel issued by an SD-WAN controller, the configuration parameters including at least IPSec parameters and SRv6 parameters, the SRv6 parameters indicating a transmission node path for a packet to be transmitted to a destination SD-WAN edge node; encapsulating a header including the IPSec parameters and SRv6 parameters into a received user packet to obtain an encapsulated packet; and sending the encapsulated packet to the Internet so that the encapsulated packet is transmitted to the destination SD-WAN edge node according to the transmission node path.

[0008] In one exemplary embodiment of this disclosure, the step of encapsulating the received user packet with a packet header including the IPSec parameters and SRv6 parameters to obtain an encapsulated packet includes: encapsulating the user packet with an IPSec packet header according to the IPSec parameters; and encapsulating an Internet Protocol version 6 (IPv6) packet header with a Segmentation Routing Header (SRH) before the IPSec packet header according to the SRv6 parameters to obtain the encapsulated packet.

[0009] In one exemplary embodiment of this disclosure, the segmented routing header (SRH) includes at least a list of segmented routing nodes in chronological order, each node in the list having a corresponding IPv6 node address; sending the encapsulated packet to the Internet so that the encapsulated packet is transmitted to the destination SD-WAN edge node according to the transmission node path includes: sending the encapsulated packet to the Internet so that the encapsulated packet is transmitted sequentially to the IPv6 node addresses corresponding to each node, and finally transmitted to the destination SD-WAN edge node.

[0010] In one exemplary embodiment of this disclosure, the IPSec tunnel is used to connect the SD-WAN edge node and the user network corresponding to the destination SD-WAN edge node; when the SD-WAN edge node receives the configuration parameters of the Internet Security Protocol IPSec tunnel issued by the SD-WAN controller, the destination SD-WAN edge node corresponding to the SD-WAN edge node simultaneously receives the configuration parameters to decapsulate the received encapsulated message and send it to the corresponding user network.

[0011] In one exemplary embodiment of this disclosure, the configuration parameters are determined by the SD-WAN controller based on the network transmission conditions between the SD-WAN edge node and the destination SD-WAN edge node.

[0012] According to one aspect of this disclosure, a data transmission system in a Software-Defined Wide Area Network (SD-WAN) is provided. The system includes an SD-WAN controller, an SD-WAN edge node, and a destination SD-WAN edge node connected to the SD-WAN edge node via an Internet Security Protocol (IPSec) tunnel. The SD-WAN controller is configured to issue configuration parameters for the IPSec tunnel to the SD-WAN edge node. These configuration parameters include at least IPSec parameters and SRv6 parameters, where the SRv6 parameters indicate the transmission node path for packet transmission to the destination SD-WAN edge node. The SD-WAN edge node is configured to encapsulate a received user packet with a header including the IPSec parameters and SRv6 parameters to obtain an encapsulated packet, and transmit the encapsulated packet to the Internet, so that the encapsulated packet is transmitted to the destination SD-WAN edge node according to the transmission node path.

[0013] In one exemplary embodiment of this disclosure, the SD-WAN edge node includes: an IPSec encapsulation module, configured to encapsulate an IPSec header into the user packet according to the IPSec parameters; and an SRv6 encapsulation module, configured to encapsulate an Internet Protocol version 6 (IPv6) header with a Segmentation Routing Header (SRH) before the IPSec header according to the SRv6 parameters, to obtain the encapsulated packet; wherein the Segmentation Routing Header (SRH) includes at least a list of segmented routing nodes in a sequential order, each node in the list having a corresponding IPv6 node address; after the SD-WAN edge node sends the encapsulated packet to the Internet, the encapsulated packet is transmitted sequentially to the IPv6 node addresses corresponding to each node, and finally transmitted to the destination SD-WAN edge node.

[0014] In one exemplary embodiment of this disclosure, the SD-WAN controller is further configured to send the configuration parameters of the IPSec tunnel to the destination SD-WAN edge node at the same time as sending the configuration parameters of the IPSec tunnel to the SD-WAN edge node; the destination SD-WAN edge node is configured to receive the encapsulated packet, decapsulate the encapsulated packet, and send it to the corresponding user network.

[0015] According to one aspect of this disclosure, a computer storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the data transmission method in a Software-Defined Wide Area Network (SD-WAN) as described in any of the preceding claims.

[0016] According to one aspect of this disclosure, an electronic device is provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform a data transmission method in a Software-Defined Wide Area Network (SD-WAN) as described above by executing the executable instructions.

[0017] The data transmission method in a Software-Defined Wide Area Network (SD-WAN) according to an exemplary embodiment of this disclosure involves an SD-WAN edge node receiving configuration parameters for an Internet Security Protocol (IPSec) tunnel issued by an SD-WAN controller. These configuration parameters include IPSec parameters, a transmission node path for indicating packet transmission to the destination SD-WAN edge node, and SRv6 parameters. The SD-WAN edge node encapsulates a packet header including the IPSec parameters and SRv6 parameters into a packet to obtain an encapsulated packet, and sends the encapsulated packet to the Internet so that the encapsulated packet is transmitted to the destination SD-WAN edge node according to the transmission node path. On the one hand, SD-WAN edge nodes encapsulate user packets with headers including IPSec parameters and SRv6 parameters according to the IPSec tunnel configuration parameters issued by the SD-WAN controller. The SRv6 parameters indicate the transmission path of the packet to the destination SD-WAN edge node, thus making the transmission path of the encapsulated packet in the Internet programmable. The SD-WAN controller enables selectivity of the data transmission path between SD-WAN edge nodes, and can select the optimal path according to different network transmission conditions. The optimal path is issued to the SD-WAN edge nodes in the form of IPSec tunnel configuration parameters, thereby realizing transmission path protection, path sharing and other functions, and coordinating data transmission efficiency and network transmission resources. On the other hand, since IPv6 addresses in the Internet are all public addresses, the problem of NAT (Network Address Translation) traversal of private addresses is avoided, and the application of the SRv6 protocol for data transmission in the SD-WAN network is also realized.

[0018] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0019] The above and other objects, features, and advantages of this disclosure will become readily apparent from the following detailed description of exemplary embodiments, taken in conjunction with the accompanying drawings. Several embodiments of this disclosure are illustrated in the drawings by way of example and not limitation, in which:

[0020] Figure 1 A schematic diagram of the packet format in IPSec tunnel mode in related technologies is shown;

[0021] Figure 2 A schematic diagram of the SRv6 head structure in the related art is shown;

[0022] Figure 3 A schematic diagram of the structure of an SD-WAN network in related technologies is shown;

[0023] Figure 4 A flowchart illustrating a data transmission method in a software-defined wide area network (SD-WAN) according to an exemplary embodiment of the present disclosure is shown;

[0024] Figure 5 A schematic diagram of a message encapsulation method according to an exemplary embodiment of the present disclosure is shown;

[0025] Figure 6 A schematic diagram of user message transmission according to an exemplary embodiment of the present disclosure is shown;

[0026] Figure 7 A schematic diagram of a data transmission method in a software-defined wide area network (SD-WAN) according to an exemplary embodiment of the present disclosure is shown in a practical application scenario.

[0027] Figure 8 A schematic diagram of the structure of a data transmission system in a Software-Defined Wide Area Network (SD-WAN) according to an exemplary embodiment of the present disclosure is shown.

[0028] Figure 9 A schematic diagram of a storage medium according to an exemplary embodiment of the present disclosure is shown; and

[0029] Figure 10 A block diagram of an electronic device according to an exemplary embodiment of the present disclosure is shown.

[0030] In the accompanying drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed Implementation

[0031] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more comprehensive and complete, and will fully convey the concept of exemplary embodiments to those skilled in the art. The same reference numerals in the drawings denote the same or similar structures, and therefore their detailed description will be omitted.

[0032] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced without one or more of the specific details described, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known structures, methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0033] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, or in one or more software-hardened modules, or in different network and / or processor devices and / or microcontroller devices.

[0034] IPSec is an open network layer security framework protocol developed by the Internet Engineering Task Force (IETF). It is not a single protocol, but rather a collection of protocols and services that provide security for IP networks; in other words, a set of network layer-based, cryptographically applied secure communication protocols. See also... Figure 1 The diagram illustrates the message format of the IPSec tunnel mode in related technologies. IPSec mainly includes: AH (Authentication Header), ESP (Encapsulating Security Payload), and IKE (Internet Key Exchange).

[0035] SRv6 (Segment Routing IPv6) is a next-generation IP transport protocol. Figure 2 A schematic diagram of the SRv6 head structure in the related art is shown, such as Figure 2 As shown, the SRv6 header structure includes a Segment List[0,n], which contains n segments, each of which is a 128-bit address and an IPv6 address. The Segment List is encoded according to the SRv6 policy. For example, a sample portion of the SRv6 header is as follows:

[0036] Address[0]:fc00:4::bb[next segment]

[0037] Address[1]:fc00:3::bb

[0038] Based on the SRv6 protocol, the output transmission is a hop-by-hop forwarding method.

[0039] In SD-WAN networks within related technologies, such as Figure 3 As shown, SD-WAN edge nodes are connected via IPSec tunnels. The propagation path of IPSec packets in the Internet is determined by the routing in the Internet switch. However, if the channel between SD-WAN edge nodes includes multiple IPSec tunnels, multiple IPSec decapsulation and encapsulation are required when transmitting data in each IPSec tunnel. This results in low transmission efficiency, resource consumption, and the data propagation path can only be uniquely determined by the routing in the Internet switch, making it impossible to make timely adjustments based on network transmission conditions. Furthermore, there is a NAT traversal problem for private addresses during data transmission.

[0040] Based on this, in the exemplary embodiments of this disclosure, a data transmission method in a Software-Defined Wide Area Network (SD-WAN) is first provided, applied to SD-WAN edge nodes in data transmission within an SD-WAN. (See reference...) Figure 4 As shown, the data transmission method in this software-defined wide area network (SD-WAN) includes the following steps:

[0041] Step S410: The SD-WAN edge node receives the configuration parameters of the Internet Security Protocol (IPSec) tunnel issued by the SD-WAN controller. The configuration parameters include at least the IPSec parameters and the SRv6 parameters. The SRv6 parameters are used to indicate the transmission node path of the packet to the destination SD-WAN edge node.

[0042] Step S420: Encapsulate the received user packet with a header including IPSec parameters and SRv6 parameters to obtain an encapsulated packet;

[0043] Step S430: Send the encapsulated message to the Internet so that the encapsulated message is transmitted to the destination SD-WAN edge node according to the transmission node path.

[0044] According to the data transmission method in Software-Defined Wide Area Network (SD-WAN) in this example embodiment, the SD-WAN edge node encapsulates the user packet with a header including IPSec parameters and SRv6 parameters according to the configuration parameters of the Internet Security Protocol (IPSec) tunnel issued by the SD-WAN controller. The SRv6 parameters are used to indicate the transmission node path of the packet to the destination SD-WAN edge node, thereby making the transmission path of the encapsulated packet in the Internet programmable. The SD-WAN controller enables selectivity of the data transmission path between SD-WAN edge nodes, and can select the optimal path according to different network transmission conditions. The optimal path is issued to the SD-WAN edge node in the form of IPSec tunnel configuration parameters, thereby realizing transmission path protection, path sharing and other functions, and coordinating data transmission efficiency and network transmission resources. Since the IPv6 addresses in the Internet are all public addresses, the problem of NAT (Network Address Translation) traversal of private addresses is avoided, and the application of the SRv6 protocol for data transmission in the SD-WAN network is also realized.

[0045] The following is combined with Figure 4 The data transmission method in a Software-Defined Wide Area Network (SD-WAN) according to an exemplary embodiment of this disclosure will be further described.

[0046] In step S410, the SD-WAN edge node receives the configuration parameters of the Internet Security Protocol (IPSec) tunnel issued by the SD-WAN controller. The configuration parameters include at least the IPSec parameters and the SRv6 parameters. The SRv6 parameters are used to indicate the transmission node path of the packet to the destination SD-WAN edge node.

[0047] In an exemplary embodiment of this disclosure, an IPSec tunnel is used to connect an SD-WAN edge node and the user network corresponding to the destination SD-WAN edge node. The configuration parameters of the IPSec tunnel include at least IPSec parameters and SRv6 parameters. The IPSec parameters include at least the address information corresponding to the destination user network, and the SRv6 parameters include at least a segment list of routing nodes in chronological order. Each node in the segment list has a corresponding IPv6 node address, used to indicate the transmission node path of the packet to the destination SD-WAN edge node. For example, the sequence includes nodes 1, 2, 3, and 4 (node ​​1->node 2->node 3->node 4), meaning the packet's transmission path in the Internet is hop-by-hop according to the order of node 1->node 2->node 3->node 4, finally reaching the destination SD-WAN edge node.

[0048] In one exemplary embodiment, the configuration parameters of the IPSec tunnel are determined by the SD-WAN controller based on the network transmission conditions between the SD-WAN edge node and the destination SD-WAN edge node. For example, if the SD-WAN controller determines, based on the current network transmission conditions, that a user packet is transmitted from the SD-WAN edge node via node 1->node 2->node 3->node 4 to the destination SD-WAN edge node, and there may be a delay at node 2, then the SD-WAN controller can send the IPSec tunnel configuration parameters to the SD-WAN edge node. The SRv6 parameter in this parameter indicates that the transmission node path for the packet to reach the destination SD-WAN edge node is 1->node 5->node 3->node 4.

[0049] Through this exemplary embodiment, the SD-WAN controller sends different IPSec tunnel configuration parameters according to network transmission conditions to indicate the transmission node path of the packet to the destination SD-WAN edge node, realizing the editability, adjustability and selectability of the data transmission path. In this way, it can make real-time adjustments for different transmission node paths based on the actual network, transmission conditions, etc., and thus provide functions such as path protection and path sharing.

[0050] In step S420, the received user message is encapsulated with a header including IPSec parameters and SRv6 parameters to obtain an encapsulated message.

[0051] In an exemplary embodiment of this disclosure, when a user packet enters an SD-WAN edge node, the user packet is encapsulated with an IPSec header and an IPv6 packet header with a Segmented Routing Header (SRH) to obtain an encapsulated header.

[0052] Specifically, first, an IPSec header is encapsulated in the user packet according to the IPSec parameters. Second, an Internet Protocol version 6 (IPv6) header with a Segmentation Routing Header (SRH) is encapsulated before the IPSec header according to the SRv6 parameters, resulting in an encapsulated packet. See also... Figure 5 A schematic diagram of a message encapsulation method according to an exemplary embodiment of the present disclosure is shown, such as... Figure 5 As shown, this relates to message encapsulation formats in related technologies (see...). Figure 1 Compared to the previous embodiment, the exemplary embodiments of this disclosure add an Internet Protocol version 6 (IPv6) header encapsulated with a Segmentation Routing Header (SRH) to each protocol. Since the SRH includes at least a sequential list of segmented routing nodes, and each node in the list has a corresponding IPv6 node address, the encapsulated packet is sent to the Internet so that it is transmitted sequentially to the corresponding IPv6 node addresses, ultimately reaching the destination SD-WAN edge node. Figure 6 As shown, user packets are transmitted hop-by-hop from the SD-WAN edge node through IPv6 node 1, IPv6 node 2, IPv6 node 3, and IPv6 node 4 to the destination SD-WAN edge node. During the transmission of encapsulated packets within the IPSec tunnel, multiple decapsulation processes are unnecessary, and the IPv6 node addresses on the internet during transmission are all public addresses. Therefore, there is no issue of NAT traversal using private addresses during transmission.

[0053] In one exemplary embodiment, when the SD-WAN edge node receives the configuration parameters for the IPSec tunnel from the SD-WAN controller, the corresponding destination SD-WAN edge node simultaneously receives these configuration parameters to decapsulate the received encapsulated packet and send it to the corresponding user network. See also... Figure 6 When the encapsulated message is transmitted to the destination SD-WAN edge node, the destination SD-WAN edge node decapsulates the encapsulated message based on the configuration parameters of the received IPSec tunnel, and sends the decapsulated user message to the user network 2.

[0054] Through this exemplary embodiment, by simply sending the configuration parameters of the IPSec tunnel to both the SD-WAN edge node and the corresponding destination SD-WAN edge node simultaneously through the SD-WAN controller, data transmission between the SD-WAN edge node and the corresponding destination SD-WAN edge node based on IPSec over SRv6 can be achieved. Not only is the transmission path selectable and programmable, but path protection, path sharing, and network resource regulation can also be performed through path selection.

[0055] In step S430, the encapsulated message is sent to the Internet so that the encapsulated message is transmitted to the destination SD-WAN edge node according to the transmission node path.

[0056] In an exemplary embodiment of this disclosure, after the SD-WAN edge node sends the encapsulated packet to the Internet, the encapsulated packet is transmitted sequentially to the corresponding IPv6 node addresses of each node in the Internet, and finally transmitted to the destination SD-WAN edge node. This has been described in step S420 and will not be repeated here.

[0057] Figure 7 The illustration shows a schematic diagram of a data transmission method in a software-defined wide area network (SD-WAN) according to an exemplary embodiment of the present disclosure in a practical application scenario, such as... Figure 7Based on the IPSec tunnel configuration parameters issued by the SD-WAN controller, user packets sent by network user 1 (Host1) are transmitted from Shenzhen to Beijing via an IPv6 node (Shanghai) on the Internet, and then arrive at network user 2 (Host2). Conversely, if the SD-WAN controller detects network latency in this transmission path, it can issue another IPSec tunnel configuration parameter to instruct user packets sent by network user 1 (Host1) to be transmitted from Shenzhen to Beijing via an IPv6 node (Hangzhou) on the Internet, and then arrive at network user 2 (Host2), thus enabling selectable and programmable data transmission paths.

[0058] It should be noted that the number of nodes included in the transmission node path in the above example is only exemplary. The number of nodes in the segmented routing node list with sequential order in this disclosure can be set according to the actual data transmission requirements, and this disclosure does not impose any special limitations on this.

[0059] In exemplary embodiments of this disclosure, a data transmission system in a Software-Defined Wide Area Network (SD-WAN) is also provided. (See reference...) Figure 8 As shown, the data transmission system 800 in the software-defined wide area network (SD-WAN) may include an SD-WAN controller 810, an SD-WAN edge node 820, and a destination SD-WAN edge node 840 connected to the SD-WAN edge node 810 via an Internet Security Protocol (IPSec) tunnel 830. Specifically,

[0060] The SD-WAN controller 810 is used to send configuration parameters for the IPSec tunnel to the SD-WAN edge node 820. The configuration parameters include at least Internet Security Protocol (IPSec) parameters and SRv6 parameters. The SRv6 parameters are used to indicate the transmission node path for packet transmission to the destination SD-WAN edge node 840.

[0061] The SD-WAN edge node 820 encapsulates the received user packets with a packet header including IPSec parameters and SRv6 parameters to obtain an encapsulated packet, and sends the encapsulated packet to the Internet so that the encapsulated packet is transmitted to the destination SD-WAN edge node 840 according to the transmission node path.

[0062] In one exemplary embodiment, the SD-WAN edge node may include: an IPSec encapsulation module, used to encapsulate an IPSec header into a user packet according to IPSec parameters; and an SRv6 encapsulation module, used to encapsulate an Internet Protocol version 6 (IPv6) header with a segmented routing header (SRH) before the IPSec header according to SRv6 parameters, to obtain an encapsulated packet; wherein the segmented routing header (SRH) includes at least a list of segmented routing nodes in a sequential order, each node in the segmented routing node list having a corresponding IPv6 node address, and after the SD-WAN edge node 820 sends the encapsulated packet to the Internet, the encapsulated packet is transmitted sequentially to the IPv6 node addresses corresponding to each node, and finally transmitted to the destination SD-WAN edge node 840.

[0063] In one exemplary embodiment, the SD-WAN controller 810 is further configured to send the configuration parameters of the IPSec tunnel to the destination SD-WAN edge node 840 at the same time as sending the configuration parameters of the IPSec tunnel to the SD-WAN edge node 820; the destination SD-WAN edge node 840 is configured to receive the encapsulated packet, decapsulate the encapsulated packet and send it to the corresponding user network.

[0064] Since the functional modules of the data transmission system in the exemplary embodiment of the present disclosure are the same as those in the above-described embodiments of the data transmission method in the software-defined wide area network (SD-WAN), they will not be described again here.

[0065] It should be noted that although several modules or units of the data transmission system in Software-Defined Wide Area Network (SD-WAN) have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0066] Furthermore, in exemplary embodiments of this disclosure, a computer storage medium capable of implementing the above-described methods is also provided. A program product capable of implementing the methods described in this specification is stored thereon. In some possible embodiments, various aspects of this disclosure can also be implemented as a program product including program code, which, when run on a terminal device, causes the terminal device to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of this disclosure.

[0067] refer to Figure 9As shown, a program product 900 for implementing the above-described method according to an exemplary embodiment of the present disclosure is described. This product may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto. In this document, the readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0068] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0069] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0070] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0071] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0072] Furthermore, in exemplary embodiments of this disclosure, an electronic device capable of implementing the above-described methods is also provided. Those skilled in the art will understand that various aspects of this disclosure can be implemented as systems, methods, or program products. Therefore, various aspects of this disclosure can be specifically implemented as entirely hardware embodiments, entirely software embodiments (including firmware, microcode, etc.), or embodiments combining hardware and software aspects, collectively referred to herein as "circuit," "module," or "system."

[0073] The following reference Figure 10 To describe an electronic device 1000 according to such an embodiment of the present disclosure. Figure 10 The electronic device 1000 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.

[0074] like Figure 10 As shown, the electronic device 1000 is manifested in the form of a general-purpose computing device. The components of the electronic device 1000 may include, but are not limited to: at least one processing unit 1010, at least one storage unit 1020, a bus 1030 connecting different system components (including storage unit 1020 and processing unit 1010), and a display unit 1040.

[0075] The storage unit stores program code that can be executed by the processing unit 1010, causing the processing unit 1010 to perform the steps described in the "Exemplary Methods" section above according to various exemplary embodiments of this disclosure.

[0076] Storage unit 1020 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 1021 and / or a cache memory unit 1022, and may further include a read-only memory unit (ROM) 1023.

[0077] Storage unit 1020 may also include a program / utility 1024 having a set (at least one) program module 1025, such program module 1025 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0078] Bus 1030 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the multiple bus structures.

[0079] Electronic device 1000 can also communicate with one or more external devices 1100 (e.g., keyboard, pointing device, Bluetooth device, etc.), one or more devices that enable a user to interact with electronic device 1000, and / or any device that enables electronic device 1000 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1050. Furthermore, electronic device 1000 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1060. As shown, network adapter 1060 communicates with other modules of electronic device 1000 via bus 1030. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0080] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0081] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of this disclosure and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0082] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.

[0083] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A data transmission method in a Software-Defined Wide Area Network (SD-WAN), characterized in that, include: The SD-WAN edge node receives configuration parameters for the IPSec tunnel from the SD-WAN controller. These configuration parameters are determined by the SD-WAN controller based on the network transmission conditions between the SD-WAN edge node and the destination SD-WAN edge node. The configuration parameters include at least IPSec parameters and SRv6 parameters. The SRv6 parameters include at least a list of segmented routing nodes in a sequential order, and each node in the segmented routing node list has a corresponding IPv6 node address, used to indicate the transmission node path for packet transmission to the destination SD-WAN edge node. Encapsulate the received user message with a header including the IPSec parameters and SRv6 parameters to obtain an encapsulated message; The encapsulated message is sent to the Internet so that the encapsulated message is transmitted to the destination SD-WAN edge node according to the transmission node path; The process of encapsulating the received user packet with a header including the IPSec parameters and SRv6 parameters yields an encapsulated packet, including: Encapsulate the user packet with an IPSec header according to the IPSec parameters; The encapsulated packet is obtained by encapsulating an Internet Protocol version 6 (IPv6) header with a segmented routing header (SRH) before the IPSec packet header according to the SRv6 parameters; wherein the segmented routing header (SRH) includes at least a list of segmented routing nodes in a sequential order, and each node in the list of segmented routing nodes has a corresponding IPv6 node address.

2. The method according to claim 1, characterized in that, Sending the encapsulated message to the Internet so that the encapsulated message is transmitted to the destination SD-WAN edge node according to the transmission node path includes: The encapsulated message is sent to the Internet so that the encapsulated message is transmitted sequentially to the IPv6 node address corresponding to each node, and finally transmitted to the destination SD-WAN edge node.

3. The method according to claim 1 or 2, characterized in that, The IPSec tunnel is used to connect the SD-WAN edge node and the user network corresponding to the destination SD-WAN edge node; When the SD-WAN edge node receives the configuration parameters of the Internet Security Protocol (IPSec) tunnel issued by the SD-WAN controller, the corresponding destination SD-WAN edge node also receives the configuration parameters to decapsulate the received encapsulated message and send it to the corresponding user network.

4. A data transmission system in a Software-Defined Wide Area Network (SD-WAN), characterized in that, The system includes an SD-WAN controller, an SD-WAN edge node, and a destination SD-WAN edge node connected to the SD-WAN edge node via an IPSec tunnel. The SD-WAN controller is used to issue IPSec tunnel configuration parameters to the SD-WAN edge node. The configuration parameters are determined by the SD-WAN controller based on the network transmission conditions between the SD-WAN edge node and the destination SD-WAN edge node. The configuration parameters include at least Internet Security Protocol (IPSec) parameters and SRv6 parameters. The SRv6 parameters include at least a segmented routing node list with a sequential order, and each node in the segmented routing node list has a corresponding IPv6 node address, which is used to indicate the transmission node path for packet transmission to the destination SD-WAN edge node. The SD-WAN edge node is used to encapsulate the received user packets with a packet header including the IPSec parameters and SRv6 parameters to obtain an encapsulated packet, and sends the encapsulated packet to the Internet so that the encapsulated packet is transmitted to the destination SD-WAN edge node according to the transmission node path; the SD-WAN edge node includes: an IPSec encapsulation module, used to encapsulate the user packets with an IPSec packet header according to the IPSec parameters; and an SRv6 encapsulation module, used to encapsulate the IPSec packet header with an Internet Protocol version 6 (IPv6) packet header with a Segmentation Routing Header (SRH) before the IPSec packet header according to the SRv6 parameters to obtain the encapsulated packet; The segmented routing header (SRH) includes at least a list of segmented routing nodes in chronological order, and each node in the segmented routing node list has a corresponding IPv6 node address.

5. The system according to claim 4, characterized in that, After the SD-WAN edge node sends the encapsulated packet to the Internet, the encapsulated packet is transmitted sequentially to the IPv6 node address corresponding to each node, and finally transmitted to the destination SD-WAN edge node.

6. The system according to claim 4, characterized in that, The SD-WAN controller is also configured to send the configuration parameters of the IPSec tunnel to the destination SD-WAN edge node at the same time as sending the configuration parameters of the IPSec tunnel to the SD-WAN edge node; The destination SD-WAN edge node is used to receive the encapsulated message, decapsulate the encapsulated message, and send it to the corresponding user network.

7. A storage medium having a computer program stored thereon, said computer program, when executed by a processor, implementing the data transmission method in a software-defined wide area network (SD-WAN) according to any one of claims 1 to 3.

8. An electronic device, characterized in that, include: processor; and memory for storing the executable instructions of the processor; The processor is configured to execute the data transmission method in a software-defined wide area network (SD-WAN) according to any one of claims 1 to 3 by executing the executable instructions.

Citation Information

Patent Citations

  • End-to-end SR control method and system in SD-WAN scene and readable storage medium

    CN112671650A

  • Network communication method and system and storage medium

    CN113852552A