A cloud outsourcing intelligent routing verification system
Through the cloud outsourcing intelligent routing verification system, the router sends network status information to the cloud server and requests path speculation, and uses version numbers and verification functions to ensure the efficiency and reliability of routing decisions, solving the problems of waste and security of computing resources in the existing technology, and realizing highly adaptable intelligent routing.
Patent Information
- Application Number
- CN202310154080.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-22
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2043-02-22
AI Technical Summary
In the prior art, centralized deployment and decentralized deployment of intelligent routing solutions have problems with waste of computing resources and security, and cannot effectively utilize the network routing link characteristics, and relying on SDN controllers or SDRs leads to the network vulnerability.
The cloud outsourcing intelligent routing verification system is adopted, and network status information is sent to the cloud server regularly through the router. The cloud server summarizes and stores the latest status information. The router maintains the routing table of the version number, and requests the cloud server to make path speculation when needed. It uses multiple verification functions to verify the correctness of the path and reduces the router's calculation pressure.
It realizes efficient, adaptable, highly compatible and reliable intelligent routing that does not rely on SDR and SDN, adapts to dynamic network changes and ensures the correctness and security of routing decisions.
Smart Images

Figure CN116389344B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a cloud outsourcing intelligent routing verification system. Background Art
[0002] With the rapid growth of data traffic, operators usually rely on hardware upgrades such as increasing the number of routers and links to improve the performance of the core network. This method may cause waste and squandering of hardware resources.
[0003] Among them, for emerging networks such as data center networks, traditional routing and traffic scheduling methods are difficult to make full use of the characteristics of network routing links. Due to the dynamic, high-dimensional and complex nature of the network state affected by various factors, network routing algorithms need to make stable responses to various network conditions to obtain the best routing results. When the network changes drastically, the routing algorithm should be able to learn and converge quickly.
[0004] To achieve the above objectives, researchers have proposed intelligent routing schemes based on machine learning, which can help routers make appropriate routing decisions according to the underlying network environment. With the increasing number of intelligent routing algorithms proposed, how to deploy intelligent routing algorithms in a real environment has also received special attention. The current deployment methods mainly include centralized deployment and decentralized deployment.
[0005] Among them, the centralized deployment method requires a central controller to be set up in the network. This central controller is responsible for collecting network state information and distributing the routing decision results to each router. With the continuous development of Software Defined Network (SDN), the network controller has obtained more computing power, which lays the foundation for the application of machine learning in the network and makes centralized deployment possible. Therefore, the central controller can be deployed on the SDN controller. Although the development of SDN provides an opportunity for centralized deployment, the centralized deployment method based on the SDN controller can only be used in SDN networks and faces a series of security problems. The SDN controller is essentially software installed on a Windows system or a Linux operating system, which makes the controller at risk of being attacked and unable to meet the full trust of users. If an attacker gains control of the SDN controller, or the controller stops working due to excessive computing (caused by a denial of service attack or a distributed denial of service attack), the entire network will be paralyzed.
[0006] Different from the centralized deployment method, the decentralized deployment method does not require a central controller and has better scalability than the centralized deployment. However, the decentralized deployment method requires the router to undertake the functions of training the model and predicting the route, which requires the router to have high computing power. Therefore, the decentralized deployment method highly depends on the development of the router and requires a Software Defined Router (SDR) with powerful computing power, resulting in a high deployment cost.
[0007] Therefore, there is an urgent need for an intelligent routing scheme that does not rely on an SDN controller or an SDR. Summary of the Invention
[0008] To solve the above problems existing in the prior art, the present invention provides a cloud outsourcing intelligent routing verification system.
[0009] The technical problems to be solved by the present invention are realized through the following technical solutions:
[0010] A cloud outsourcing intelligent routing verification system includes: a plurality of routers and a cloud server;
[0011] The router is configured to periodically send its first network status information and a time stamp to the cloud server;
[0012] The cloud server is configured to summarize the first network status information sent by each router according to the time stamp to obtain second network status information, and locally store the latest second network status information; and is further configured to send the latest second network status information to each router;
[0013] The router is configured to receive and forward a routing path packet sent by the previous hop node; wherein, the routing path packet includes: routing information and a corresponding version number, and the version number identifies the second network status information corresponding to the routing information;
[0014] The router is further configured to maintain the routing information and the corresponding version number in the local routing table, and when the version number corresponding to the required routing information in the routing table is lower than the current latest version number, initiate a path speculation request to the cloud server;
[0015] The cloud server is configured to, in response to the path speculation request, input the latest second network status information into a pre-trained target intelligent routing model, so that the target intelligent routing model outputs an intelligent routing result; and return a speculated path to the router that initiates the path speculation request according to the intelligent routing result;
[0016] The router is further configured to, after receiving the speculated path returned by the cloud server, use a new version number to identify the routing information included in the received speculated path, and verify the next-hop node in the speculated path by using a plurality of verification functions according to the latest second network status information; when the verification is passed, update the local routing table according to the routing information and the corresponding version number included in the speculated path, and generate a routing path packet sent to the next-hop node.
[0017] Optionally, the system further includes: a trusted server;
[0018] The trusted server is configured to generate and store verification functions;
[0019] The router is further configured to interact with the trusted server to obtain the plurality of verification functions.
[0020] Optionally, a plurality of verification functions are configured in each router, and the verification functions of different routers do not have to be the same.
[0021] Optionally, the verification function is expressed as:
[0022] d Hamm (f(tp), h(s)) ≤ μ;
[0023] where h(·) represents a locality-sensitive hashing (LSH) function family, s represents an intelligent routing result, f(·) represents a pre-constructed multi-layer perceptron corresponding to h(·), tp represents the second network status information, μ is a preset threshold, and d Hamm (·) is a function for calculating the Hamming distance.
[0024] Optionally, the generation method of the verification function includes:
[0025] Obtain a training set and construct an LSH function family; wherein, the training samples in the training set are the second network status information, and the labels of the training samples are label vectors representing the intelligent routing results corresponding to the second network status information;
[0026] Normalize the training set and construct a first matrix according to the normalized training set;
[0027] For each LSH function in the LSH function family, perform LSH calculation on each label vector in the training set by using the LSH function, and construct a second matrix according to the LSH calculation results of the label vectors;
[0028] Construct a multi-layer perceptron with the first matrix as the input and the second matrix as the output;
[0029] Use the constructed multi-layer perceptron and the LSH function used in the process of constructing the multi-layer perceptron as the verification function.
[0030] Optionally, the target intelligent routing model is trained based on the training set.
[0031] Optionally, the routing path packet further includes: the checksum of the data contained in the routing path packet;
[0032] The router is further configured to check the checksum of the routing path packet when receiving the routing path packet sent by the previous hop node, so as to verify the integrity of the routing path packet.
[0033] Optionally, the path speculation request carries the request node number and the destination node number;
[0034] The cloud server is further configured to, in response to the path speculation request, find a target intelligent routing model corresponding to the request node number and the destination node number from a plurality of pre-trained intelligent routing models;
[0035] Wherein, the plurality of intelligent routing models are all intelligent routing models that generate routing paths hop by hop.
[0036] Optionally, when the version number corresponding to the required routing information in the routing table is lower than the current latest version number, the router sends a path speculation request to the cloud server, including:
[0037] When it is necessary to use the routing information in the routing table, determine whether the version number corresponding to the routing information in the self-maintained routing table is the current latest version number, and send a path speculation request to the cloud server when the determination result is negative.
[0038] Optionally, the cloud server includes: an SDN controller.
[0039] The cloud outsourcing intelligent routing verification system provided by the present invention outsources intelligent routing tasks to a cloud server, reducing the computing pressure on the router and reflecting the high efficiency of the present invention. Various intelligent routing algorithms for generating hop-by-hop forwarding paths or directly generating complete paths can be preset in the cloud server, which reflects the compatibility of the present invention. In addition, the router uses a version number to identify routing information, and this version number identifies the second network state information corresponding to the routing information; both the routing table locally maintained by the router and the routing path packets received / sent contain the version number corresponding to the routing information; in this way, the router can learn the timeliness of the routing information according to the version number, so as to adapt to the dynamic changes of the network, update the forwarding path in a timely manner, and make the routing decision adapt to the changes of the network state, reflecting the adaptability of the present invention. Moreover, the router in the present invention also uses multiple verification functions to verify the next-hop node in the speculative path obtained from the cloud server, so that even in the case of an untrusted cloud server, the correctness of the outsourced routing result can be ensured, reflecting the reliability of the present invention.
[0040] In summary, the present invention does not rely on SDR and SDN, and has multiple advantages such as high efficiency, strong adaptability, strong compatibility, and high reliability.
[0041] The following will further elaborate on the present invention in conjunction with the accompanying drawings. Description of the Drawings
[0042] Figure 1 is a schematic structural diagram of a cloud outsourcing intelligent routing verification system provided by an embodiment of the present invention;
[0043] Figure 2 is a schematic structural diagram of a cloud outsourcing intelligent routing verification system provided by an embodiment of the present invention;
[0044] Figure 3 shows Figure 2 each working stage of the system shown. Detailed Embodiment
[0045] The following further describes the present invention in detail with specific embodiments, but the embodiments of the present invention are not limited thereto.
[0046] In the prior art, for the deployment problem of intelligent routing algorithms, whether using a centralized deployment method or a non-centralized deployment method, a network controller or a software-defined router, such powerful computing accessories, is required to support deep learning tasks. Both of these methods have high requirements for the processing capabilities of the accessories, restricting the scale of their actual deployment.
[0047] In order not to rely on an SDN controller or SDR to implement intelligent routing, an embodiment of the present invention provides a cloud outsourcing intelligent routing verification system, which can relieve the computing pressure of routers and avoid trust problems caused by single-point failures or attacks in the central network.
[0048] See Figure 1 As shown, the cloud outsourcing intelligent routing verification system provided by the embodiment of the present invention includes: a plurality of routers and a cloud server.
[0049] The router is used to periodically send its first network status information and a time stamp to the cloud server.
[0050] Among them, the first network status information may include: the number of data packets arriving at the router per unit time, but is not limited thereto. Here, the unit time is the period for the cloud server to collect the first network status information from the router.
[0051] In practical applications, the router and the cloud server authenticate each other through a secure communication channel. In addition, through the application of existing security protocols, the communication between routers is also secure.
[0052] The cloud server is used to summarize the first network status information sent by each router according to the time stamp to obtain second network status information, and locally store the latest second network status information; it is also used to send the latest second network status information to each router;
[0053] It can be understood that the second network status information contains the first network status information of all routers in the network during the current period.
[0054] The router is used to receive and forward the routing path packet Pre-Path sent by the previous-hop node; among them, the routing path packet includes: routing information and a corresponding version number, and this version number identifies the second network status information corresponding to this routing information.
[0055] The router may receive two types of packets, one is a data packet, and the other is a routing path packet. The version number in the routing path packet can enable the router to distinguish which version of the second network status information the routing information corresponds to when it is generated, so that the timeliness of the routing information can be learned according to the version number. Simply put, the version number in the Pre-Path indicates in which version of the second network status information the routing information in the Pre-Path is obtained.
[0056] In addition, the routing path packet may further include: a checksum of the information contained in the routing path packet. Correspondingly, the router is also used to check the checksum of the routing path packet when receiving the routing path packet sent by the previous-hop node to verify the integrity of the routing path packet.
[0057] The checksum is integrity verification information generated instantaneously for the data structure of the current pre-Path, which enables the router receiving the pre-Path to verify whether the pre-Path has undergone unexpected changes during transmission. In practical applications, the router needs to recalculate the checksum each time the routing information or version number is updated.
[0058] The router is also used to maintain the routing information and the corresponding version number in the local routing table. When the version number corresponding to the required routing information in the routing table is lower than the latest version number, a path speculation request is sent to the cloud server.
[0059] Specifically, as shown in Figure 1 , the routers are numbered in sequence; the router maintains a routing table locally. In the embodiment of the present invention, a new type of routing table and its update mechanism are proposed, and the version number is added as a new attribute to the routing table to help the router record network changes; among them, the structure of the routing table can be seen as follows:
[0060] Dst nxt v-t
[0061] In this routing table, a row of data represents that in the network state of version v_t, the next hop of the data packet with dst as the destination node is nxt. The destination node Dst serves as the primary key of the routing table and can uniquely indicate a piece of data.
[0062] Specifically, when the router needs to use the routing information in the routing table, the router determines whether the version number corresponding to the routing information in the locally maintained routing table is the current latest version number, and sends a path speculation request to the cloud server when the judgment result is negative.
[0063] When the router receives a routing path packet sent by the previous hop node, it maintains the information contained therein in the local routing table; when the router needs to use the routing information in the routing table, that is, when the router needs to determine the next hop nxt to reach the destination node Dst according to the routing table, it judges whether the version number v-t of the row where Dst and nxt are located in the routing table is the current latest version number in the routing table, and sends a path speculation request to the cloud server when the judgment result is negative.
[0064] It is understandable that, under the same network state, for data packets sent from the same source node to the same destination node, the routing paths calculated by the cloud server through the intelligent routing model are the same. When a router receives a data packet with the same destination node, if the router repeatedly initiates a path speculation request to the cloud server, many identical interactions may be generated. Therefore, in order to reduce redundant interactions between routers and cloud servers, the embodiment of the present invention limits each router to sending a path information request for the same data packet with the same destination node at most once when the network state does not change.
[0065] It can be seen that based on the new routing table and its update mechanism proposed in the embodiment of the present invention, repeated verification can be avoided; in comparison, the related technology uses a flooding method to transmit network status information, which will cause a large amount of communication consumption.
[0066] The path speculation request initiated by the router carries a request node number and a destination node number. The request node number is the number of the router that issued the path speculation request, and the destination node number is the number of the router to which the data packet received by the router is to go.
[0067] The cloud server is used to respond to the path speculation request, input the latest second network status information into the pre-trained target intelligent routing model, so that the target intelligent routing model outputs the intelligent routing result; and return the speculated path to the router that initiated the path speculation request according to the intelligent routing result.
[0068] It is understandable that outsourcing the model training and path prediction tasks of intelligent routing to the cloud server can effectively reduce the local computing consumption of the router.
[0069] Among them, there are various intelligent routing models that can be used as the target intelligent routing model. For example, Ruesk et al. combined a graph neural network (GNN) and a long short-term memory (LSTM) network model to establish a model that helps heuristic routing optimization to obtain a routing strategy, which can be applied to centralized networks. Zhuang et al. proposed a graph-aware deep learning (GADL) solution for centralized networks based on a deep learning model; this solution uses a topology-based feature extraction method, enabling GADL to reduce the model training time. At the same time, it has a higher accuracy than DBN and CNN. Xu et al. proposed a traffic engineering solution called DRL-TE (Deep Reinforcement Learning Traffic Engineering), which is based on deep reinforcement learning and can be applied to centralized networks that require performance optimization, such as data centers and backbone networks. This solution uses traditional methods to generate paths, and then uses deep reinforcement learning to predict the future changes in traffic based on the current traffic information and dynamically adjust the traffic on each path, thereby improving the utilization rate of network links. Valadarsk et al. proposed a solution based on historical traffic information to predict future traffic and calculate routing strategies, which can be applied to centralized networks. In this solution, a matrix composed of historical traffic is input, and the weights of each link are output through training. The reinforcement learning model realizes the load balancing of the link and improves the utilization rate of the network link by learning and predicting the magnitude of future traffic and continuously adjusting and outputting the link weights. Xu et al. also proposed a method to continuously adjust and output link weights to optimize network performance. However, it is different from the direct output of each link weight in the solution of Valadarsk et al. The weights are discretized and trained using the multi-agent deep deterministic policy gradient (MADDPG) algorithm, which further reduces the average waiting time of the router. Geyer et al. proposed a solution that combines a gated recurrent unit (GRU) and GNN. This solution adds router interface parameters to the model, enabling the trained model to be well applied to distributed routing decision scenarios. Basagni et al. proposed an intelligent routing model MARLIN-Q based on Q-Learning. Q-learning is a model-free reinforcement learning algorithm that was first used in a routing algorithm in the work of Boyan et al. [9] and is applied to distributed routing scenarios and can support different types of QoS requirements. The MARLIN-Q model effectively avoids the occurrence of failed retransmissions. However, this model has some limitations and is not suitable for network routing with high output dimensions and complex calculations, and the packet-level routing control method it adopts is not feasible for backbone networks.
[0070] In the embodiments of the present invention, the model structure of the intelligent routing model is not limited, and any existing intelligent routing model can be used. For this reason, the specific form and content of the first network state information are not limited in the embodiments of the present invention, because the specific form and content of the first network state information are mainly determined by the second network state information input into the intelligent routing model, that is, it is adapted to the intelligent routing model.
[0071] The target intelligent routing model is obtained by the cloud server through offline training based on a training set. The training samples in the training set are the second network state information, and the labels of the training samples are label vectors representing the intelligent routing results corresponding to the second network state information. For the specific training method, please refer to the relevant existing technologies, and the embodiments of the present invention will not elaborate.
[0072] The intelligent routing result includes the probability distribution result of each hop calculated by the cloud server through the target intelligent routing model, presented in matrix form. The number of its columns is the same as the number of routers in the network, and each row represents the result of a routing path inference. Through the probability distribution result of each row, the router can obtain the specific forwarding path. According to the output result form of the deep learning model, the sum of each row of the intelligent routing result is 1, as follows:
[0073]
[0074] Among them, P is the intelligent routing result, N is the number of routers, and p ij represents the probability that the i-th hop in the routing result is router j.
[0075] It can be understood that the second network state information corresponding to the speculated path is the second network state information input into the target intelligent routing model when the cloud server uses the target intelligent routing model to speculate the speculated path, and it is also the latest second network state information locally stored by the cloud server.
[0076] The router is also used to, after receiving the speculated path returned by the cloud server, use the new version number to identify the routing information included in the received speculated path, and verify the next-hop node in the speculated path using multiple verification functions according to the latest second network state information; when the verification passes, update the local routing table according to the routing information and the corresponding version number included in the speculated path, and generate a routing path packet sent to the next-hop node.
[0077] It can be understood that the router defaults that the speculated path returned by the cloud server corresponds to the latest second network state information. Therefore, the router identifies the routing information included in the speculated path with the latest version number.
[0078] Among them, the form of the routing path packet is roughly the same as the intelligent routing result. The difference is that before each router sends the routing path packet, it will delete the routing path that is only related to itself, that is, discard the first row of the matrix P as the routing path packet. Therefore, for each router, the routing path packet sent by it can indicate the next hop of the packet.
[0079] Since the cloud server is outsourced, it may use a simple model or return random results to save computing costs, that is, the cloud server is lazy and it may deceive the router in terms of routing result decision-making. Therefore, it cannot be fully trusted. In contrast, the router is honest. Therefore, when the intelligent routing result returned by the cloud server may not be completely credible, the router can verify the correctness of the intelligent routing result returned by the cloud server through verification.
[0080] In practice, when the router uses multiple functions to verify the next hop, only when all verification functions are established will it be considered that the speculated path is valid, that is, the verification passes.
[0081] Among them, in an optional implementation, multiple verification functions can be configured in each router, and the verification functions of different routers do not have to be the same. That is, each router can implement its specific verification function.
[0082] In another implementation, in order to further reduce the computing overhead and storage overhead of the router, see Figure 2 As shown, the cloud outsourcing intelligent routing verification system provided by the embodiments of the present invention may further include: a trusted server; the trusted server is used to generate and store verification functions; correspondingly, the router is further used to interact with the trusted server to obtain multiple verification functions used when verifying the speculated path obtained from the cloud server.
[0083] Figure 3 is shown in Figure 2 Each working stage of the system shown, including three stages: the verification function generation stage, the model training stage, and the routing stage. Among them, in the verification function generation stage, the verification function can be generated either by other trusted servers or by the router. The cloud server is assigned to use the training set to train the intelligent routing model in the model training stage. The router does not need to pay attention to the specific details of the cloud server training the model, nor does it need to pay attention to the parameters of these models. In the routing stage, the router makes routing decisions based on the Pre-Path or the speculated path obtained from the cloud server. Obviously, except for the routing stage, the other two stages can be executed offline without interacting with the router.
[0084] Among them, the generation method of the verification function includes the following steps:
[0085] (1) Obtain a training set and construct a family of LSH functions; wherein, the training samples in the training set are the second network state information, and the labels of the training samples are label vectors representing the intelligent routing results corresponding to the second network state information.
[0086] Among them, the family of LSH functions can refer to the CheckNet scheme proposed by Comiter et al. CheckNet uses two techniques to achieve verification, including HashCheck and CrossCheck. Among them, HashCheck constructs a pair of hash functions that are respectively associated with the input and output, allowing the verifier to perform a quick computational integrity check by judging whether the two hash values are equal, which is used to ensure that the inference calculation is actually performed on the given input. CrossCheck is used to verify whether the output has been maliciously tampered with, ensuring that an untrusted third party has not forged the true output of the inference calculation or changed the prediction result in any way. In the embodiments of the present invention, the cloud is lazy but not malicious, so only HashCheck is referred to to focus on whether the cloud server has performed the correct inference calculation on the given input.
[0087] It can be seen that the training set used by the trusted server to generate the verification function is the same as the training set used by the cloud server to train the target intelligent routing model.
[0088] (2) Standardize the training set and construct a first matrix according to the standardized training set.
[0089] Here, the first matrix contains the second network state information represented by all the training samples in the training set.
[0090] (3) For each LSH function in the family of LSH functions, perform LSH calculations on each label vector in the training set using the LSH function, and construct a second matrix according to the LSH calculation results of each label vector.
[0091] Here, the second matrix contains the LSH calculation results of all the label vectors in the training set;
[0092] (4) Construct a multi-layer perceptron with the first matrix as the input and the second matrix as the output.
[0093] A multi-layer perceptron (MLP, Multilayer Perceptron) is a feedforward artificial neural network that maps an input vector to an output vector. An MLP consists of at least three layers of nodes: an input layer, a hidden layer, and an output layer. Except for the input nodes, each node in the network is a neuron using a non-linear activation function. The neurons in the hidden layer are fully connected to the inputs of the input layer, and the neurons in the output layer are also fully connected to the neurons in the hidden layer. The MLP is trained using the backpropagation supervised learning technique. In the embodiments of the present invention, an MLP is used to learn two vectors connecting a first matrix and a second matrix.
[0094] (5) Use the constructed multi-layer perceptron and the LSH function used in the process of constructing the multi-layer perceptron as a verification function.
[0095] Based on the generation method of the verification function, it can be seen that the embodiments of the present invention use a verification mechanism based on the consistency detection of the input-output mapping distance to verify the correctness of the deep learning model, which has no precedent in the field of network security technology.
[0096] The generated verification function is expressed as:
[0097] d Hamm (f(tp), h(s)) ≤ μ;
[0098] In the verification function, h(·) represents the local sensitive hashing LSH function family, s represents the intelligent routing result, f(·) represents the pre-constructed multi-layer perceptron corresponding to h(·), tp represents the second network state information, μ is a preset threshold, and d Hamm (·) is a function for calculating the Hamming distance.
[0099] When the router verifies that the next-hop verification is passed, the router updates the local routing table according to the routing information and the corresponding version number included in the speculated path, generates a routing path packet sent to the next-hop node, and then sends it to the next-hop node.
[0100] It can be understood that in the routing stage, the router can obtain the entire packet forwarding path through the routing path packet or by sending a path speculation request to the cloud, and verify whether the path is correct. If the verification is passed, the router updates the routing information, updates the pointer to point to the next-hop node, and then sends the new routing path packet to the next-hop node.
[0101] The cloud outsourcing intelligent routing verification system provided by the embodiment of the present invention outsources the intelligent routing task to the cloud server, reduces the computing pressure of the router, and reflects the high efficiency of the present invention. Various intelligent routing algorithms for generating hop-by-hop forwarding paths or directly generating complete paths can be preset in the cloud server, which reflects the compatibility of the present invention. In addition, the router uses a version number to identify the routing information, and the version number identifies the second network state information corresponding to the routing information; the routing table maintained locally by the router and the received / sent routing path package both contain the version number corresponding to the routing information; in this way, the router can learn the timeliness of the routing information based on the version number, thereby adapting to the dynamic changes of the network, updating the forwarding path in time, and adapting the routing decision to the changes in the network state, which reflects the adaptability of the embodiment of the present invention. In addition, the router in the embodiment of the present invention also uses multiple verification functions to verify the next hop node in the inferred path obtained from the cloud server, so that even if the cloud server is dishonest, the correctness of the outsourced routing result can be ensured, which reflects the reliability of the present invention.
[0102] Optionally, in one implementation, it is known that the path speculation request carries a request node number and a destination node number; the cloud server can also be used to respond to the path speculation request and find a target intelligent routing model corresponding to the request node number and the destination node number from multiple pre-trained intelligent routing models; wherein the multiple intelligent routing models mentioned here are all intelligent routing models that generate routing paths hop by hop. Figure 2 M1~Mn in the figure represent multiple intelligent routing models preset in the cloud server.
[0103] Specifically, in the intelligent routing algorithm that generates routing paths hop by hop, there is a deep learning model between every two nodes, and the cloud server will record the nodes corresponding to each model when training the deep learning model. Therefore, when the router initiates a path speculation request, the cloud server extracts the request node number and the destination node number from it, and can determine the corresponding target intelligent routing model based on these two node numbers.
[0104] It is understandable that for different intelligent routing algorithms, the cloud can perform multiple different model training tasks, and can execute independent training tasks in parallel.
[0105] Optionally, in one implementation, the cloud server may include: an SDN controller, but is not limited thereto, and may be other servers, for example.
[0106] It should be noted that when the cloud server is an SDN controller, even the SDN controller is not completely trustworthy due to potential network attacks. Therefore, it is still necessary to verify the inferred path fed back by the cloud server in the router.
[0107] In summary, the present invention does not rely on SDR and SDN, and has various advantages such as high efficiency, strong adaptability, strong compatibility, and high reliability.
[0108] It should be noted that the terms "first", "second", etc. are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described here can be implemented in an order other than those illustrated or described here. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are only examples of devices and methods consistent with some aspects of the present disclosure.
[0109] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0110] Although the present application has been described in connection with various embodiments herein, however, in the process of implementing the claimed present application, those skilled in the art can understand and implement other changes of the disclosed embodiments by viewing the accompanying drawings and the disclosure content. In the description of the present invention, the word "comprising" does not exclude other components or steps, the word "a" or "an" does not exclude a plurality of cases, and the meaning of "a plurality" is two or more, unless otherwise specifically defined. In addition, certain measures are described in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0111] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. A cloud outsourcing intelligent routing verification system, characterized in that, include: Multiple routers and cloud servers; The router is used to periodically send its own first network status information and timestamp to the cloud server; The cloud server is used to aggregate the first network status information sent by each router according to the timestamp to obtain the second network status information, and store the latest second network status information locally; Also used to send the latest second network status information to each router; The router is used to receive and forward the routing path packet sent by the previous hop node; wherein the routing path packet includes: routing information and a corresponding version number, the version number identifying the second network state information corresponding to the routing information; The router is further configured to maintain the routing information and the corresponding version number in a local routing table, and to initiate a path speculation request to the cloud server when the version number corresponding to the required routing information in the routing table is lower than the current latest version number; wherein each router sends a path speculation request at most once for a data packet with the same destination node when the network state does not change; The cloud server is used to input the latest second network state information into a pre-trained target intelligent routing model in response to the path speculation request, so that the target intelligent routing model outputs an intelligent routing result; and return a speculated path to the router that initiated the path speculation request according to the intelligent routing result; The router is also used to, after receiving the inferred path returned by the cloud server, identify the routing information contained in the received inferred path using a new version number, and verify the next hop node in the inferred path using multiple verification functions according to the latest second network status information; when the verification passes, update the local routing table according to the routing information contained in the inferred path and the corresponding version number, and generate a routing path package to be sent to the next hop node.
2. The cloud outsourcing intelligent routing verification system according to claim 1, characterized in that Also includes: trusted server; The trusted server is used to generate and store the verification function; The router is further configured to interact with the trusted server to obtain the multiple verification functions.
3. The cloud outsourcing intelligent routing verification system according to claim 1, characterized in that, Multiple verification functions are configured in each router, and the verification functions of different routers do not have to be the same.
4. The cloud outsourcing intelligent routing verification system according to any one of claims 1 to 3, characterized in that, The verification function is expressed as: d Hamm (f(tp),h(s)) ≤ μ; Among them, h(·) represents the family of locality-sensitive hashing (LSH) functions, s represents the intelligent routing result, f(·) represents the pre-constructed multi-layer perceptron corresponding to h(·), tp represents the second network state information, μ is a preset threshold, and d Hamm (·) is a function for calculating the Hamming distance.
5. The cloud outsourcing intelligent routing verification system according to claim 4, wherein The generation method of the verification function includes: Obtain a training set and construct an LSH function family; wherein the training samples in the training set are the second network state information, and the labels of the training samples are label vectors representing the intelligent routing results corresponding to the second network state information; Standardize the training set and construct the first matrix based on the standardized training set; For each LSH function in the LSH function family, LSH calculation is performed on each label vector in the training set using the LSH function, and a second matrix is constructed according to the LSH calculation results of each label vector; Constructing a multilayer perceptron with the first matrix as input and the second matrix as output; The constructed multilayer perceptron and the LSH function used in the process of constructing the multilayer perceptron are used as verification functions.
6. The cloud outsourcing intelligent routing verification system according to claim 5, wherein The target intelligent routing model is obtained by training based on the training set.
7. The cloud outsourcing intelligent routing verification system according to claim 1, characterized in that The routing path packet also includes: a checksum of the data contained in the routing path packet; The router is also used to check the checksum of the routing path packet when receiving the routing path packet sent by the previous hop node, so as to verify the integrity of the routing path packet.
8. The cloud outsourcing intelligent routing verification system according to claim 1, wherein, The path speculation request carries a request node number and a destination node number; The cloud server is further configured to, in response to the path speculation request, find a target intelligent routing model corresponding to the request node number and the destination node number from a plurality of pre-trained intelligent routing models; The multiple intelligent routing models are all intelligent routing models that generate routing paths hop by hop.
9. The cloud outsourcing intelligent routing verification system according to claim 1, characterized in that: The router, when the version number corresponding to the required routing information in the routing table is lower than the current latest version number, initiates a path speculation request to the cloud server, including: When the routing information in the routing table needs to be used, it is determined whether the version number corresponding to the routing information in the routing table maintained by itself is the current latest version number, so as to initiate a path speculation request to the cloud server when the judgment result is no.
10. The cloud outsourcing intelligent routing verification system according to claim 1, wherein The cloud server includes: an SDN controller.
Citation Information
Patent Citations
Intelligent service quality control method for wireless router
CN104780149A
Routing protocol method, mobile ad hoc network, site and storage medium
CN114585041A