Nfv asset management method, apparatus, and electronic device

By introducing authentication requests and encrypted transmission mechanisms into the NFV asset management system, and using pre-synchronized asset information from producers for identity verification and encrypted communication, the problems of low operational efficiency and high security risks in NFV asset management are solved, achieving a more efficient and secure management process.

CN116743456BActive Publication Date: 2026-04-07CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-12
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

In existing technologies, NFV asset management suffers from low operational efficiency and high security risks. In particular, under the C/S architecture, the installation and deployment of the management client requires manual operation or the use of third-party tools, and there are security vulnerabilities in the authentication between the management client and the server.

Method used

An NFV asset management method is adopted, which introduces authentication requests and encrypted transmission mechanisms between the management client and the server, uses pre-synchronized asset information for authentication, and conducts encrypted communication through a secure connection gateway to achieve dynamic access and control of the management client.

Benefits of technology

It enhances the security of NFV asset management, reduces management workload, effectively filters potential internal network attacks, and strengthens the communication security between management clients and servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743456B_ABST
    Figure CN116743456B_ABST
Patent Text Reader

Abstract

The application discloses an NFV asset management method and device, and belongs to the technical field of communication, and is used for solving the security problem of NFV asset management. The method is applied to an asset management system comprising a first server, a second server and a management client, and comprises the following steps: in response to an authentication request sent by the management client, the first server acquires first asset information of an NFV asset corresponding to the management client carried in the authentication request, and authenticates the first asset information based on second asset information synchronized by a producer of the NFV asset; and after the authentication is passed, the first server sends first connection information to the management client; and the second server performs asset management on the NFV asset corresponding to the management client based on an encryption transmission mode indicated by the first connection information. The method sets up a static default authentication access mechanism before the management client communicates with the server, dynamically accesses and controls the management client, and thus the communication security of the management client and the server is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a NFV asset management method and device, an electronic device and a computer readable storage medium. BACKGROUND

[0002] With the landing of new technologies such as core network, new metropolitan area network, 5G MEC (Multi-access Edge Computing) edge cloud, edge cloud, NFV (Network Functions Virtualization, abbreviated as NFV) technology is also accelerating landing. Virtual broadband access server, virtual image management system and other services are successively carried on the X86 virtualization platform. For the management and operation of these NFV asset management, new problems and challenges are also faced. In the prior art, the x86 host and virtual machine assets corresponding to the virtual network element and other virtualization assets of the NFV are uniformly managed, and centralized management is basically performed in the mode of C / S architecture. This management mode mainly has two defects: one is the operation and maintenance efficiency problem, and the installation and deployment of the management client need to be completed manually or with the help of third-party operation and maintenance tools, which is a large workload; the other is the asset security risk problem, and the management client basically communicates with the management server through the intranet, and the security problem of the management client and the management server is identified and verified by https, which must save the identity information of the management client in the proxy service of the management client, and there is a great security risk.

[0003] Therefore, an improved NFV asset management method is needed. SUMMARY

[0004] The embodiments of the present application provide an NFV asset management method and device, and an electronic device, which can improve the security of virtualization asset management and reduce the workload of NFV asset management.

[0005] In a first aspect, the embodiments of the present application disclose an NFV asset management method applied to an asset management system, the asset management system comprising a first server, a second server and a management client, and the method comprising:

[0006] In response to an authentication request sent by the management client, the first server acquires first asset information of an NFV asset corresponding to the management client carried in the authentication request;

[0007] The first server compares and verifies the first asset information based on second asset information pre-synchronized by a producer of the NFV asset, to obtain an authentication result;

[0008] In response to the authentication result indicating that the authentication is passed, the first service end sends first connection information to the management client;

[0009] The management client communicates with the second service end based on an encryption transmission mode indicated by the first connection information, to perform asset management on the NFV asset corresponding to the management client.

[0010] In a second aspect, the embodiments of the present application disclose a NFV asset management device, applied to an asset management system, the asset management system comprising a first service end, a second service end and a management client, the device comprising:

[0011] An authentication request analysis module, configured to, in response to an authentication request sent by the management client, acquire first asset information of an NFV asset corresponding to the management client carried in the authentication request by the first service end;

[0012] An authentication module, configured to compare and verify the first asset information based on second asset information pre-synchronized by a producer of the NFV asset by the first service end, to obtain an authentication result;

[0013] A secure connection sending module, configured to, in response to the authentication result indicating that the authentication is passed, send first connection information to the management client by the first service end;

[0014] An asset management module, configured to communicate with the second service end based on an encryption transmission mode indicated by the first connection information by the management client, to perform asset management on the NFV asset corresponding to the management client.

[0015] In a third aspect, the embodiments of the present application further disclose an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to implement the NFV asset management method of the embodiments of the present application.

[0016] In a fourth aspect, the embodiments of the present application disclose a computer readable storage medium, having a computer program stored thereon, and the program is executed by a processor to implement the steps of the NFV asset management method disclosed by the embodiments of the present application.

[0017] The NFV asset management method disclosed by the embodiments of the present application is applied to an asset management system, and the asset management system comprises a first server, a second server and a management client. The method comprises the following steps: in response to an authentication request sent by the management client, the first server acquires first asset information of an NFV asset corresponding to the management client carried in the authentication request; the first server compares and verifies the first asset information based on second asset information pre-synchronized by a producer of the NFV asset, and obtains an authentication result; in response to the authentication result indicating that the authentication is passed, the first server sends first connection information to the management client; and the management client communicates with the second server based on an encryption transmission mode indicated by the first connection information, so as to perform asset management on the NFV asset corresponding to the management client. The method pre-positions an access mechanism of single package authentication of the management client before the management client and the server communicate, realizes dynamic access control when the management client registers to the asset management center, can filter potential attacks from the internal network, and strengthens the communication security between the management client and the server.

[0018] The above description is only a summary of the technical solutions of the present application. In order to enable the technical means of the present application to be more clearly understood, and to be implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the present application to be more apparent and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to make the purposes, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be described clearly and completely in combination with the drawings of the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0020] Figure 1 is a flowchart of the NFV asset management method disclosed by the embodiments of the present application;

[0021] Figure 2 is one of the asset management system architecture schematic diagrams disclosed by the embodiments of the present application;

[0022] Figure 3 is another asset management system architecture schematic diagram disclosed by the embodiments of the present application;

[0023] Figure 4 is another flowchart of the NFV asset management method disclosed by the embodiments of the present application;

[0024] Figure 5is one of the application scenarios of the NFV resource management method disclosed by the embodiments of the present application;

[0025] Figure 6 is one of the NFV asset management device structure diagrams disclosed by the embodiments of the present application;

[0026] Figure 7 is another of the NFV asset management device structure diagrams disclosed by the embodiments of the present application;

[0027] Figure 8 a block diagram of an electronic device for performing the method according to the present application is schematically shown; and

[0028] Figure 9 a storage unit for holding or carrying program code for implementing the method according to the present application is schematically shown. DETAILED DESCRIPTION

[0029] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0030] The NFV asset management method disclosed by the embodiments of the present application is applied to an asset management system. As shown in the figure, Figure 2 the asset management system includes: a management client 210 corresponding to one NFV asset, a first server 220, a second server 230 and a secure connection gateway 240.

[0031] The management client 210 is integrated and deployed by the producer of the corresponding NFV asset. For example, the management client 210 and the corresponding NFV asset are integrated in a deployment file and deployed on the same resource node.

[0032] The functions of each component of the asset management system will be briefly described below.

[0033] The management client 210 is integrated in the deployment file of the NFV asset, used to collect asset information of the NFV asset (such as collecting basic information and communication information of a virtual switch), and report to the second server 230, and receive asset management instructions for managing the corresponding NFV asset issued by the second server 230, and execute the asset management instructions to implement the management of the NFV asset. For example, execute the blocking policy and ACL policy issued by the second server 230.

[0034] The first service end 220 is configured to perform asset registration and authentication management by the management client 210.

[0035] The second service end 230 is configured to receive factory parameters of the corresponding NFV asset collected and reported by the management client 210, and perform corresponding asset management operations according to the factory parameters. For example, asset running state display, asset visualization display, asset policy management, etc. The second service end 230 is also configured to issue asset management instructions to the management client 210, for performing asset management operations on the corresponding NFV asset.

[0036] For example, a virtualized outbound call service system of an NFV has 600 assets. The second service end 230 can collect all the internal and external communication flow directions of the 600 assets through the management client 210, and perform aggregation and calculation of all communication flows to calculate all the communication relationships between them, and depict a communication connection topology diagram for display.

[0037] As shown in Figure 3 The asset management system can further include an asset production end 250.

[0038] The asset production end 250 is configured to produce NFV assets, and integrate the management client 210 in the deployment file of the NFV asset in the process of producing the NFV asset, and deploy it to the resource node.

[0039] Taking an NFV virtual machine as an example, the asset production end 250 is configured to perform operations such as opening of the NFV virtual machine, including resource pool arrangement and template management. The management client 210 is integrated through template management to automatically complete the installation and deployment of the necessary management segment in the process of production of the NFV asset. For example, different configurations of the initialization management client are integrated through template management, different management clients are initialized according to different businesses, and the management client is placed together with the original NFV asset generation technology to create.

[0040] The first service end 220 and the second service end 230 can be deployed in the same hardware device, or can be deployed in different hardware devices. The secure connection gateway 240 can be a soft gateway or a physical gateway. When the secure connection gateway 240 is a soft gateway, the first service end 220, the second service end 230, and the secure connection gateway 240 can be deployed in the same hardware device, or can be deployed in different hardware devices.

[0041] Next, the specific implementation of the NFV asset management method disclosed in the embodiments of the present application will be illustrated by way of example in combination with the asset management system.

[0042] AsFigure 1 As shown, the embodiment of the present application discloses a NFV asset management method, comprising steps 110 to 140.

[0043] In step 110, in response to an authentication request sent by the management client, the first server acquires first asset information of a NFV asset corresponding to the management client carried in the authentication request.

[0044] The NFV asset corresponding to the management client is an NFV asset integrated with the management client.

[0045] In some embodiments of the present application, the management client 210 can be generated according to configuration information when the NFV asset is produced, and the generated management client 210 is integrated in the deployment file of the NFV asset and deployed to the resource node together. The resource node is used to run the NFV asset. For example, the management client 210 can be integrated in the deployment file of the NFV asset through, for example, an image file or an installation script, and deployed to the resource node together.

[0046] Optionally, the management client 210 is automatically started and executed when the NFV asset is started. Optionally, the management client is a virtualization agent. The virtualization agent has an automatic execution instruction, and when the detection function of the virtualization agent detects that the virtualization agent itself is in a non-running state, the virtualization agent will automatically execute. For example, when the NFV asset integrated with the management client 210 is started and executed, the management client 210 is triggered and automatically executes a default script.

[0047] After the management client 210 is triggered and executed, the factory parameters of the NFV asset integrated by the management client 210 (i.e., the corresponding NFV asset) are acquired according to a pre-configured execution mode, which is denoted as "first asset information" in the embodiments of the present application.

[0048] Optionally, the first asset information includes but is not limited to one or more of the following information: MAC address (Media Access Control Address), IP address (Internet Protocol Address), and time of appearance of the NFV asset.

[0049] Then, the management client 210 performs encryption processing on the first asset information according to a preset encryption algorithm to obtain encrypted first asset information, and then generates an authentication request based on the encrypted first asset information. The management client 210 sends the generated authentication request to the first server 220.

[0050] Optionally, the first server 220 acquires the first asset information of the NFV asset corresponding to the management client 210 carried in the authentication request, comprising: the first server 220 adopts a preset decryption method to perform decryption processing on the authentication request, and acquires the first asset information of the NFV asset corresponding to the management client 210 carried in the authentication request.

[0051] In the embodiment of the application, the management client 210 and the first server 220 pre-agree an encryption method and a decryption method to encrypt and decrypt the data transmitted by each other. In the embodiment of the application, the preset decryption method and the preset encryption algorithm are not limited, as long as the preset decryption algorithm adopted by the first server 220 is a decryption algorithm matched with the preset encryption algorithm adopted by the management client 210.

[0052] Step 120, the first server compares and verifies the first asset information based on the second asset information pre-synchronized by the producer of the NFV asset, and obtains an authentication result.

[0053] Optionally, as shown in Figure 4 Before the step that the first server compares and verifies the first asset information based on the second asset information pre-synchronized by the producer of the NFV asset, and obtains an authentication result, the method further comprises step 100.

[0054] Step 100, in the production link of the NFV asset, the first server receives the second asset information of the NFV asset synchronized by the producer of the NFV asset.

[0055] Optionally, the producer comprises the asset production end.

[0056] For example, in the production link of the NFV asset, the asset production end 250 can synchronize the factory parameters of the generated NFV asset to the first server 220, denoted as "second asset information". The second asset information comprises but is not limited to one or more of the following information: MAC address, IP address, and time of the NFV asset. The first server 220 stores the second asset information of each NFV asset for factory, which is used for subsequent identity authentication of the management client.

[0057] Optionally, the second asset information comprises factory parameters of the NFV asset.

[0058] In the running stage of the NFV asset, the first service end 220 can verify the identity of the NFV asset by comparing the first asset information sent by the management client 210 with the second asset information of each NFV asset pre-stored in the first service end 220. If the second asset information is matched, it is considered that the current management client 210 and the NFV asset are authenticated successfully, and the first service end 220 obtains an authentication result indicating that the authentication is successful. If no second asset information is matched, it is considered that the current management client 210 and the NFV asset are authenticated unsuccessfully, and the first service end 220 obtains an authentication result indicating that the authentication is unsuccessful.

[0059] In step 130, in response to the authentication result indicating that the authentication is successful, the first service end sends first connection information to the management client.

[0060] In the case of successful authentication, the first service end 220 sends first connection information to the management client 210.

[0061] Optionally, the first connection information includes an IP address of the secure connection gateway 240 and security check information.

[0062] Optionally, the first connection information is used to inform the management client 210 to access the IP address based on the security check information, to report preset data of the corresponding NFV asset and / or to receive an asset management instruction issued by the service end, so that the management client performs a corresponding asset management operation according to the asset management instruction.

[0063] In step 140, the management client communicates with the second service end based on the encryption transmission mode indicated by the first connection information, to perform asset management on the NFV asset corresponding to the management client.

[0064] As described above, the first connection information includes an IP address of the secure connection gateway and security check information.

[0065] Optionally, the encryption transmission mode indicated by the first connection information includes encryption transmission based on the secure connection gateway.

[0066] Correspondingly, the management client communicates with the second service end based on the encryption transmission mode indicated by the first connection information, to perform asset management on the NFV asset corresponding to the management client, including sub-step 1403 and / or sub-step 1404.

[0067] In sub-step 1403, the management client sends preset data of the NFV asset corresponding to the management client to the second service end through the secure connection gateway.

[0068] The preset data is sent to the second server by the following method: the management client accesses the IP address based on the security check information, and sends the preset data of the corresponding NFV asset to the second server.

[0069] Optionally, the preset data includes but is not limited to one or more of the following data: business data, running state data, running parameters, etc.

[0070] In the substep 1404, the management client receives the asset management instruction issued by the second server through the secure connection gateway, so that the management client performs the corresponding asset management operation according to the asset management instruction.

[0071] In the embodiment of the application, the second server 230 and the management client 210 perform encrypted communication through the secure connection gateway 240 to ensure data security. For example, the management client 210 connects the secure connection gateway 240 based on the security check information, sends the preset data of the collected NFV asset to the secure connection gateway 240, and the secure connection gateway 240 encrypts and transmits the preset data to the second server 230. For another example, the second server 230 sends an asset management instruction to the secure connection gateway 240, and the secure connection gateway 240 encrypts and sends the asset management instruction to the corresponding management client 210.

[0072] Optionally, as shown in Figure 4 After the first server sends the first connection information to the management client, the method further includes step 135.

[0073] In step 135, the first server sends the second connection information corresponding to the management client to the secure connection gateway.

[0074] Optionally, the second connection information includes identity information of the management client, gateway parameters for connection, etc.

[0075] After the management client 210 obtains the information of the secure connection gateway 240, it will subsequently report information to the secure connection gateway 240. Therefore, in the registration link, the first server 220 needs to send the identity information of the management client 210 that passes the authentication and the connection parameters for accessing the secure connection gateway 240 and other information to the secure connection gateway 240, to inform the secure connection gateway 240 that there is a new management client 210 that needs to be connected.

[0076] Correspondingly, the management client communicates with the second server based on the encryption transmission mode indicated by the first connection information to perform asset management on the NFV asset corresponding to the management client, and further includes substep 1401 and substep 1402.

[0077] In substep 1401, the management client accesses the IP address based on the security check information, and initiates a request for establishing an encrypted tunnel connection to the secure connection gateway.

[0078] In substep 1402, in response to the request for establishing an encrypted tunnel connection, the secure connection gateway authenticates the management client based on the second connection information, and establishes an encrypted tunnel after the authentication is passed.

[0079] After the management client 210 receives the first connection information sent by the first service end 220, the management client 210 accesses the IP address included in the first connection information according to the security check information included in the first connection information, connects to the corresponding secure connection gateway 240, and sends a request for establishing an encrypted tunnel connection to the secure connection gateway 240, so as to request the secure connection gateway 240 to establish an encrypted tunnel for the management client 210 itself.

[0080] Optionally, the request for establishing an encrypted tunnel connection at least includes identity information of the management client 210 and gateway parameters.

[0081] Optionally, the secure connection gateway 240 verifies the identity information carried in the request for establishing an encrypted tunnel connection, or verifies the identity information and the gateway parameters. For example, the secure connection gateway 240 compares the identity information carried in the request for establishing an encrypted tunnel connection, or the identity information and the gateway parameters, with the identity information and the gateway parameters in the second connection information sent by the first service end 220 in advance. After the authentication is passed, the secure connection gateway 240 establishes an encrypted tunnel corresponding to the management client 210 according to the corresponding gateway parameters.

[0082] Correspondingly, the management client sends the preset data of the NFV asset corresponding to the management client to the second service end through the secure connection gateway, including that the management client sends the preset data of the NFV asset corresponding to the management client to the second service end through the encrypted tunnel.

[0083] During the operation of the NFV asset, the management client 210 collects preset data (such as preset service data) of the NFV asset according to a preset data collection mechanism (such as collecting according to a preset period), and sends a connection request to the second service end 230 through the encrypted tunnel established for the management client 210. Then, the secure connection gateway 240 forwards the connection request sent by the management client 210 to the corresponding second service end 230 through the encrypted tunnel, so as to establish a communication connection between the management client 210 and the second service end 230.

[0084] After the communication connection is successfully established, the management client 210 reports the preset data of the collected NFV assets to the second service end 230 through the communication connection. The secure connection gateway 240 forwards the preset data sent by the management client 210 to the corresponding second service end 230 through the encrypted tunnel.

[0085] Optionally, the asset management system includes a plurality of second service ends, each of which corresponds to a different asset management function. The management client 210 can establish a connection with each second service end 230 respectively to report the corresponding data.

[0086] Correspondingly, the management client receives the asset management instruction issued by the second service end through the secure connection gateway, including that the management client receives the asset management instruction issued by the second service end through the established encrypted tunnel.

[0087] Similarly, after the communication connection is successfully established, the second service end 230 issues an asset management instruction to the management client 210 through the communication connection. The secure connection gateway 240 forwards the asset management instruction issued by the second service end 230 to the management client 210 through the encrypted tunnel.

[0088] In the embodiment of the application, the first service end 220 is further configured to perform version management on the management client 210.

[0089] The following describes the implementation of the NFV asset management method disclosed in the embodiments of the application in combination with an implementation scenario shown in Figure 5

[0090] The NFV asset management method disclosed in the embodiments of the application includes the following steps:

[0091] Step 1: Integrated production.

[0092] The asset production end 250 defines the integrated deployment scheme of the management client 210 and the NFV virtual machine (i.e., NFV asset) through the template management module, such as an image file or an installation script, and arranges the resource pool for the NFV virtual machine. Then, the asset production end 250 performs integrated production on the NFV virtual machine and the management client 210, and issues them to the resource node for installation and deployment.

[0093] Step 2: Synchronization of production information.

[0094] When the asset production end 250 produces the NFV virtual machine, it synchronizes the factory parameters (i.e., first asset information) of the NFV virtual machine (i.e., NFV asset), such as MAC address, IP address, factory time, and other asset information, and the related information of the management client 210 to the asset registration center of the first service end 220.​

[0095] The first service end 220 performs version management on the management client through the version management center.

[0096] Step 3, authentication.

[0097] When the NFV virtual machine is installed and started, the management client 210 is started synchronously. The management client 210 uses an agreed encryption mode to send an authentication request to the asset registration center of the first service end 220 according to the factory parameters of the NFV virtual machine (i.e. the NFV asset) itself.

[0098] After the asset registration center receives the authentication request sent by the management client 210, the factory parameters (i.e. the first asset information) carried in the authentication request are extracted using an agreed decryption mode, and the factory parameters (i.e. the second asset information) pre-synchronized with the asset production end 250 are verified and compared. If the verification is passed, the management client 210 is returned with the security connection information, and the security connection gateway 240 is notified; if the verification is not passed, it is directly discarded.

[0099] Step 4, secure connection.

[0100] The management client 210 sends an encrypted tunnel connection request to the security connection gateway 240 according to the security connection information returned after the verification is passed. The security connection gateway 240 performs identity verification on the management client 210 according to the identity information carried in the encrypted tunnel connection request, and establishes the encrypted tunnel corresponding to the management client 210 if the weak verification is passed.

[0101] Step 5, asset management.

[0102] The management client 210 sends a connection request to the service end of each operation management module in the second service end 230 through the encrypted tunnel; the security connection gateway 240 forwards the corresponding request to the service end of the operation management module to complete the business data processing. In addition, the resource management instructions issued by the second service end 230 are forwarded to the corresponding management client 210 through the encrypted tunnel.

[0103] The NFV asset management method disclosed by the embodiments of the present application is applied to an asset management system, and the asset management system comprises a first server, a second server and a management client. The method comprises the following steps: in response to an authentication request sent by the management client, the first server acquires first asset information of an NFV asset corresponding to the management client carried in the authentication request; the first server performs comparison verification on the first asset information based on second asset information of the NFV asset pre-synchronized by a producer of the NFV asset, and obtains an authentication result; in response to the authentication result indicating that the authentication is passed, the first server sends first connection information to the management client; and the management client communicates with the second server based on an encryption transmission mode indicated by the first connection information, so as to perform asset management on the NFV asset corresponding to the management client. The method pre-positions an access mechanism of single package static authentication of the management client before the management client and the server communicate, realizes dynamic access control when the management client registers with the asset management center, can greatly filter potential attacks from the internal network, and strengthens the communication security of the management client and the server.

[0104] Further, by using the factory parameters of the NFV asset such as the MAC address, the IP address, the factory time and the encryption mode for single package verification, the difficulty of forgery is greatly improved, and the communication security of the management client and the server is further improved.

[0105] Meanwhile, the method is linked with an asset production system, integrates the implementation of the management client in the production process of the asset, and improves the efficiency of deployment of the client.

[0106] Correspondingly, the embodiments of the present application also disclose an NFV asset management device applied to an asset management system, wherein the asset management system comprises a first server, a second server and a management client, the management client corresponds to one NFV asset, and the device comprises: Figure 6

[0107] An authentication request analysis module 610 is configured to acquire first asset information of an NFV asset corresponding to the management client carried in the authentication request in response to an authentication request sent by the management client.

[0108] An authentication module 620 is configured to perform comparison verification on the first asset information based on second asset information of the NFV asset pre-synchronized by a producer of the NFV asset, and obtain an authentication result.

[0109] A secure connection sending module 630 is configured to send first connection information to the management client in response to the authentication result indicating that the authentication is passed.

[0110] ​The asset management module 640 is configured to enable the management client to communicate with the second server based on the encryption transmission mode indicated by the first connection information, so as to perform asset management on the NFV asset corresponding to the management client.

[0111] Optionally, the asset management system further comprises a secure connection gateway, the first connection information comprises an IP address of the secure connection gateway and security check information, and the asset management module 640 is further configured to:

[0112] The management client sends preset data of the NFV asset corresponding to the management client to the second server through the secure connection gateway; and the preset data is sent to the second server by the following method: the management client accesses the IP address based on the security check information, and sends the preset data of the corresponding NFV asset to the second server; and / or,

[0113] The management client receives an asset management instruction issued by the second server through the secure connection gateway, so that the management client performs a corresponding asset management operation according to the asset management instruction.

[0114] Optionally, as shown in Figure 7 The apparatus further comprises:

[0115] The secure connection establishment module 635 is configured to enable the first server to send second connection information corresponding to the management client to the secure connection gateway;

[0116] Optionally, the asset management module 640 is further configured to:

[0117] The management client accesses the IP address based on the security check information, and initiates an encrypted tunnel connection request to the secure connection gateway;

[0118] In response to the encrypted tunnel connection request, the secure connection gateway performs identity verification on the management client based on the second connection information, and establishes an encrypted tunnel after the identity verification is passed.

[0119] Optionally, the management client sends preset data of the NFV asset corresponding to the management client to the second server through the secure connection gateway, including:

[0120] The management client sends the preset data of the NFV asset corresponding to the management client to the second server through the encrypted tunnel.

[0121] Optionally, the management client receives the asset management instruction issued by the second service end through the secure connection gateway, and the asset management instruction comprises:

[0122] The management client receives the asset management instruction issued by the second service end through the established encryption tunnel.

[0123] Optionally, the authentication request analysis module 610 is further used for:

[0124] The first service end uses a preset decryption method to decrypt and process the authentication request, and obtains the first asset information of the management client corresponding to the NFV asset carried in the authentication request.

[0125] Optionally, as shown in Figure 7 Before the first service end compares and verifies the first asset information based on the second asset information pre-synchronized by the producer of the NFV asset to obtain the authentication result, the device further comprises:

[0126] The asset information registration module 600 is used for receiving, at a production link of the NFV asset, the second asset information of the NFV asset synchronized by the producer of the NFV asset.

[0127] Optionally, the management client is integrated and deployed by the producer corresponding to the NFV asset.

[0128] The NFV asset management device disclosed in the embodiments of the present application is used for implementing the NFV asset management method disclosed in the embodiments of the present application, and the specific implementation manners of the modules of the device will not be described again, and can be referred to the specific implementation manners of the corresponding steps of the method embodiments.

[0129] The embodiment of the application discloses a kind of NFV asset management device, it is applied to asset management system, the asset management system includes: first server, second server and management client, the device is by responding to the authentication request sent by the management client, the first server obtains the first asset information of the NFV asset corresponding to the management client carried in the authentication request;The first server compares and verifies the first asset information based on the second asset information that the producer of the NFV asset is pre-synchronized, obtains authentication result;In response to the authentication result indicating that authentication passes, the first server sends first connection information to the management client;The management client is based on the encryption transmission mode indicated by the first connection information and the second server communication, to carry out asset management to the NFV asset corresponding to the management client.This method is by in the management client of NFV asset and server communication before, preposition a management client single package static default access mechanism, realizes the dynamic access control when management client registers to asset management center, can filter potential attack from intranet substantially, strengthens the communication security of management client and server.

[0130] Further, by using NFV asset factory parameters, such as MAC address, IP address, factory time, and encryption mode for single package verification, the difficulty of forgery is greatly improved, and the communication security of the management client and the server is further improved.

[0131] Meanwhile, the device is linked with the asset production system, and the implementation of the management client is integrated in the production process of the asset, so that the efficiency of client deployment is improved.

[0132] Each of the embodiments in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments, and the same or similar parts between each embodiment can be referred to each other.For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts refer to the part of the method embodiment.

[0133] The above describes in detail the NFV asset management method and device provided by the application, the principle and implementation mode of the application are described in the text by applying specific examples;The above embodiment is only used to help understand the method and a core idea of the application;Meanwhile, for those skilled in the art, according to the idea of the application, there will be changes in specific implementation mode and application range, and the above description should not be understood as limiting the application.

[0134] The apparatus embodiments described above are only illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment according to actual needs. Those skilled in the art can understand and implement without creative labor.

[0135] The various component embodiments of the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art will understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the electronic device according to the embodiments of the present application. The present application can also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present application can be stored on a computer readable medium or can have the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or in any other form.

[0136] For example, Figure 8 An electronic device that can implement the methods according to the present application is shown. The electronic device can be a PC, a mobile terminal, a personal digital assistant, a tablet computer, etc. The electronic device traditionally comprises a processor 810 and a memory 820 and program code 830 stored on the memory 820 and executable on the processor 810, which when executed by the processor 810 implements the methods described in the above embodiments. The memory 820 can be a computer program product or a computer readable medium. The memory 820 can be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk, or a ROM. The memory 820 has a storage space 8201 for program code 830 of computer programs for performing any of the method steps in the above methods. For example, the storage space 8201 for program code 830 can comprise individual computer programs for implementing the various steps in the above methods, respectively. The program code 830 is computer readable code. The computer programs can be read out from or written into one or more computer program products. The computer program products comprise program code carriers such as hard disks, compact discs (CDs), memory cards, or floppy disks. The computer programs comprise computer readable code which, when executed on an electronic device, causes the electronic device to perform the methods according to the above embodiments.

[0137] The embodiment of the present application further discloses a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the steps of the NFV asset management method.

[0138] Such a computer program product can be a computer readable storage medium having stored thereon, a computer program comprising program instructions. The program instructions can be executed by one or more processors of a computer so as to cause the computer to carry out at least some of the steps of the above-described methods. Figure 8 The computer readable storage medium can have a similar arrangement of storage segments, storage spaces, etc. as the memory 820 in the electronic device shown. The program code can be stored in the computer readable storage medium, for example, in a compressed form. The computer readable storage medium is typically a portable or stationary storage unit as described with reference to Figure 9 The computer readable storage medium typically comprises computer readable code 830' which is code that is read by the processor, which, when executed by the processor, implements the individual steps of the above-described methods.

[0139] Reference herein to "one embodiment", "an embodiment" or "one or more embodiments” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" in various places in the specification are not necessarily all referring to the same embodiment.

[0140] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been shown in detail in order not to obscure an understanding of this description.

[0141] In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps other than those listed in a claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In a unit claim, several devices can be listed with a comma. Such listing does not imply that the devices must be co-located. The word "first", "second", "third", etc. does not imply any order. The terms "first", "second", "third", etc. are to be interpreted according to their meaning in the context of the specific embodiment and are not to be interpreted as a ranking of the elements.

[0142] Finally, it should be noted that the above examples are only used to illustrate the technical solutions of the present application, and are not intended to limit the same; although the present application has been described in detail with reference to the foregoing examples, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing examples, or make equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An NFV asset management method, characterized in that, Applied to an asset management system, the asset management system comprising: a first server, a second server, and a management client, the method comprising: In response to the authentication request sent by the management client, the first server obtains the first asset information of the NFV asset corresponding to the management client carried in the authentication request; The first server compares and verifies the first asset information based on the second asset information pre-synchronized by the producer of the NFV asset, and obtains the authentication result. In response to the authentication result indicating successful authentication, the first server sends first connection information to the management client; The management client communicates with the second server based on the encrypted transmission method indicated by the first connection information in order to manage the NFV assets corresponding to the management client. The first asset information is the corresponding factory parameters obtained by the management client from the NFV assets integrated within it; the second asset information is the factory parameters of the NFV asset synchronized from the asset production terminal to the first server during the production process. Before the first server compares and verifies the first asset information based on the second asset information pre-synchronized by the producer of the NFV asset to obtain the authentication result, the following steps are also included: In the production process of the NFV asset, the first server receives the second asset information of the NFV asset synchronized by the producer of the NFV asset; The management client is integrated and deployed by the producer of the corresponding NFV asset.

2. The method according to claim 1, characterized in that, The asset management system further includes: a secure connection gateway, wherein the first connection information includes: the IP address of the secure connection gateway and security verification information; the management client communicates with the second server based on the encrypted transmission method indicated by the first connection information to perform asset management on the NFV assets corresponding to the management client, including: The management client sends preset data of the NFV assets corresponding to the management client to the second server through the secure connection gateway. The preset data is sent to the second server via the following method: the management client accesses the IP address based on the security verification information and sends the preset data of the corresponding NFV assets to the second server; and / or, The management client receives asset management instructions from the second server through the secure connection gateway, enabling the management client to perform corresponding asset management operations according to the asset management instructions.

3. The method according to claim 2, characterized in that, After the first server sends the first connection information to the management client, it also includes: The first server sends the second connection information corresponding to the management client to the secure connection gateway; The management client communicates with the second server based on the encrypted transmission method indicated by the first connection information to manage the NFV assets corresponding to the management client, and further includes: The management client accesses the IP address based on the security verification information and initiates an encrypted tunnel connection request to the secure connection gateway; In response to the encrypted tunnel connection request, the secure connection gateway authenticates the management client based on the second connection information, and establishes an encrypted tunnel after successful authentication; The management client sends preset data of the NFV asset corresponding to the management client to the second server through the secure connection gateway, including: The management client sends preset data of the NFV asset corresponding to the management client to the second server through the encrypted tunnel; The management client receives asset management instructions from the second server through the secure connection gateway, including: The management client receives asset management instructions from the second server through the established encrypted tunnel.

4. The method according to claim 1, characterized in that, The first server obtains the first asset information of the NFV asset corresponding to the management client carried in the authentication request, including: The first server uses a preset decryption method to decrypt the authentication request and obtain the first asset information of the NFV asset corresponding to the management client carried in the authentication request.

5. The method according to claim 1, characterized in that, The management client starts automatically when the NFV asset is started.

6. An NFV asset management device, characterized in that, The device is applied to an asset management system, which includes a first server, a second server, and a management client. The authentication request parsing module is used to respond to the authentication request sent by the management client. The first server obtains the first asset information of the NFV asset corresponding to the management client carried in the authentication request. The first asset information is the corresponding factory parameters obtained by the management client from the NFV assets integrated by itself. The authentication module is used by the first server to compare and verify the first asset information based on the second asset information pre-synchronized by the producer of the NFV asset, and obtain the authentication result; the second asset information is the factory parameters of the NFV asset synchronized from the asset producer to the first server during the production process. A secure connection sending module is used to send first connection information to the management client in response to the authentication result indicating that authentication is successful. The asset management module is used by the management client to communicate with the second server based on the encrypted transmission method indicated by the first connection information, so as to manage the NFV assets corresponding to the management client. The asset information registration module is used in the production process of the NFV asset, whereby the first server receives the second asset information of the NFV asset synchronized by the producer of the NFV asset. The management client is integrated and deployed by the producer of the corresponding NFV asset.

7. An electronic device, comprising a memory, a processor, and program code stored in the memory and executable on the processor, characterized in that, When the processor executes the program code, it implements the NFV asset management method according to any one of claims 1 to 5.

8. A computer-readable storage medium having program code stored thereon, characterized in that, When the program code is executed by the processor, it implements the steps of the NFV asset management method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Access method of Virtual Private Network and Virtual Private Network client

    CN102984045A

  • Resource management method, device and system, electronic equipment and readable storage medium

    CN113992387A