Function deployment method, device and equipment for network twinning, and storage medium

CN116827945BActive Publication Date: 2026-08-18PENG CHENG LAB
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310751911.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-21
Publication Date
2026-08-18
Estimated Expiration
2043-06-21

AI Technical Summary

Technical Problem

[0004]本发明的主要目的在于提供了一种网络孪生的功能部署方法、装置、设备及存储介质,旨在解决现有技术中设备通过云原生网络中的边缘云来接入网络时,容易出现移动性、可靠性与安全性问题的技术问题

Benefits of technology

[0030]在本发明中,公开了在接收到用户发送的业务需求时,根据业务需求从预设镜像仓库中获取网络孪生服务容器镜像;将网络孪生服务容器镜像推送至基础设施资源中的目标资源位置,以运行网络孪生服务容器镜像;根据用户的移动位置和业务需求从网络孪生服务容器镜像中获取网络孪生服务的容器副本,并对容器副本进行动态配置;相较于现有技术中设备通过接入边缘云来接入网络时,面对网络边缘的多运营商、多异构接入、多异质传输手段,会给云原生网络带来安全性、移动性和可靠性的挑战,由于本发明根据用户发送的业务需求获取网络孪生服务容器镜像,将网络孪生服务容器镜像推送至目标资源位置并运行网络孪生服务容器镜像,再对从网络孪生服务容器镜像中获取的网络孪生服务的容器副本进行动态配置,从而解决了现有技术中设备通过云原生网络中的边缘云来接入网络时,容易出现移动性、可靠性与安全性问题的技术问题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116827945B_ABST
    Figure CN116827945B_ABST
Patent Text Reader

Abstract

The application discloses a network twin function deployment method and device, equipment and storage medium, the network twin is a basic service deployed in the network, and the function module comprises a security module, a transmission module, a mobility module and a resource module, the method comprises the following steps: pushing a network twin service container image obtained according to the service demand of a user to a target resource position, so as to run the network twin service container image; obtaining a container copy of the network twin service from the network twin service container image, and dynamically configuring the container copy; and the network twin service is a proxy of the user in a cloud native network. Through the steps of pushing the network twin service container image to the target resource position, running the network twin service container image, and dynamically configuring the container copy of the network twin service, the technical problem that when a device accesses the network through an edge cloud in the cloud native network, mobility, reliability and security problems are prone to occur is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication technology, and in particular to a method, apparatus, device, and storage medium for deploying network twin functions. Background Technology

[0002] The current internet is a combination of the bottom-level access network, the middle-level IP bearer network, and the top-level data center network working together to accomplish tasks. However, with the rapid growth of business demands, cloud service providers are becoming increasingly large and centralized, leading to an increasingly inefficient network structure. This can be addressed through cloud-native networks, which build the backbone network using core and edge clouds, with devices accessing the network through the edge clouds. However, the presence of multiple carriers, heterogeneous access methods, and diverse transmission techniques at the network edge presents challenges to cloud-native networks in terms of security, mobility, and reliability.

[0003] The above content is only used to help understand the technical solution of the present invention and does not represent an admission that the above content is prior art. Summary of the Invention

[0004] The main objective of this invention is to provide a method, apparatus, device, and storage medium for deploying network twins, aiming to solve the technical problems of mobility, reliability, and security issues that easily arise when devices access the network through the edge cloud in a cloud-native network.

[0005] To achieve the above objectives, the present invention provides a method for deploying network twin functions, which is applied to a cloud-native network cluster. The method includes:

[0006] Upon receiving a service request from a user, the system retrieves a network twin service container image from a pre-defined image repository based on the service request.

[0007] The network twin service container image is pushed to the target resource location in the infrastructure resources to run the network twin service container image;

[0008] Based on the user's mobile location and the business requirements, a container copy of the network twin service is obtained from the container image of the network twin service, and the container copy is dynamically configured. The network twin service serves as a proxy for the user in the cloud-native network.

[0009] Optionally, the cloud-native network cluster includes: a network twin service control engine and a network twin service; the network twin service control engine is located in the control plane of the cloud-native network cluster platform, and the network twin service is located in the data plane of the cloud-native network cluster platform;

[0010] The network twin service control engine is used to send corresponding configuration information to the network twin service when it detects management and control commands from the cloud-native network cluster platform. The network twin service monitors the user network behavior proxied by the network twin service through the configuration information.

[0011] Optionally, the network twin service control engine includes: a security configuration policy module;

[0012] The security configuration policy module is used to obtain a security configuration policy when a configuration command is detected from the cloud-native network cluster platform, and send the security configuration policy to the user. The security configuration policy is used to configure network security for the user.

[0013] Optionally, the network twin service control engine further includes: an authentication and authorization management module;

[0014] The authentication and authorization management module is used to send a target identity root to the user when it detects the identity authentication command of the cloud-native network cluster platform. The target identity root is used for user identity authentication.

[0015] Optionally, the network twin service control engine further includes: a service orchestration module;

[0016] The service orchestration module is used to obtain personalized demand information of the network twin service and to perform service operation and maintenance orchestration of the network twin service according to the personalized demand information. The service operation and maintenance orchestration is used to perform online migration and dynamic expansion of the network twin service to ensure that users are always online.

[0017] Optionally, the network twin service includes: a security module, a resource module, and a transmission module;

[0018] The security module is used to perform security authentication on the user when a user access request is detected, so that the user can be connected to the network when the authentication is successful.

[0019] The resource module is used to obtain the operator service resources required by the user's service needs according to the user's service needs when the user accesses the network.

[0020] The resource module is also used to generate a service instance set based on the operator service resources, and the service instance set is used to support service transmission.

[0021] The transmission module is used to integrate and control the transmission capabilities of the service transmission during service transmission.

[0022] Optionally, the network twin service further includes: a mobile module;

[0023] The mobility module is used to establish a mobility strategy based on the service requirements and to schedule service transmission according to the mobility strategy.

[0024] Furthermore, to achieve the above objectives, the present invention also proposes a network twin functional deployment apparatus, the apparatus comprising:

[0025] The container image acquisition module is used to acquire the network twin service container image from a preset image repository according to the business requirements when a user sends a business request.

[0026] The container image execution module is used to push the network twin service container image to a target resource location in the infrastructure resources to run the network twin service container image;

[0027] The container replica configuration module is used to obtain a container replica of the network twin service from the network twin service container image according to the user's mobile location and the business requirements, and to dynamically configure the container replica. The network twin service is a proxy for the user in the cloud-native network.

[0028] Furthermore, to achieve the above objectives, the present invention also proposes a network twin functional deployment device, the device comprising: a memory, a processor, and a network twin functional deployment program stored in the memory and executable on the processor, the network twin functional deployment program being configured to implement the steps of the network twin functional deployment method described above.

[0029] Furthermore, to achieve the above objectives, the present invention also proposes a storage medium storing a network twin function deployment program, wherein when the network twin function deployment program is executed by a processor, it implements the steps of the network twin function deployment method described above.

[0030] This invention discloses a method for obtaining a network twin service container image from a preset image repository upon receiving a user's service request; pushing the network twin service container image to a target resource location in the infrastructure resources to run the network twin service container image; and obtaining a container copy of the network twin service from the network twin service container image based on the user's mobile location and service request, and dynamically configuring the container copy. Compared to existing technologies where devices access the network via edge cloud, which present challenges to the security, mobility, and reliability of cloud-native networks due to multiple operators, heterogeneous access methods, and heterogeneous transmission methods at the network edge, this invention solves the technical problems of mobility, reliability, and security issues that easily arise when devices access the network via edge cloud in cloud-native networks. This is because the invention obtains the network twin service container image based on the user's service request, pushes the network twin service container image to the target resource location and runs the network twin service container image, and then dynamically configures the container copy of the network twin service obtained from the network twin service container image. Attached Figure Description

[0031] Figure 1 This is a schematic diagram of the structure of a network twin functional deployment device for the hardware operating environment involved in the embodiments of the present invention;

[0032] Figure 2 This is a flowchart illustrating the first embodiment of the network twin functional deployment method of the present invention;

[0033] Figure 3 This is a flowchart illustrating the second embodiment of the network twin functional deployment method of the present invention;

[0034] Figure 4 This is a schematic diagram illustrating the deployment of network twin services on a cloud-native network cluster platform in the second embodiment of the network twin functional deployment method of the present invention.

[0035] Figure 5 This is a flowchart illustrating the third embodiment of the network twin functional deployment method of the present invention;

[0036] Figure 6 This is a functional module diagram of the network twin service in the third embodiment of the network twin functional deployment method of the present invention;

[0037] Figure 7 This is a schematic diagram illustrating the location and function of the network twin service in a cloud-native network in the third embodiment of the network twin deployment method of the present invention.

[0038] Figure 8 This is a structural block diagram of the first embodiment of the network twin functional deployment device of the present invention.

[0039] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0040] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.

[0041] Reference Figure 1 , Figure 1 This is a schematic diagram of the network twin functional deployment device structure of the hardware operating environment involved in the embodiments of the present invention.

[0042] like Figure 1 As shown, the network twin's functional deployment device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be high-speed random access memory (RAM) or stable non-volatile memory (NVM), such as a disk storage device. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0043] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on the functional deployment of network twins and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0044] like Figure 1 As shown, the memory 1005, which serves as a storage medium, may include an operating system, a network communication module, a user interface module, and a network twin function deployment program.

[0045] exist Figure 1In the network twin functional deployment device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the network twin functional deployment device of the present invention can be set in the network twin functional deployment device, and the network twin functional deployment device calls the network twin functional deployment program stored in the memory 1005 through the processor 1001 and executes the network twin functional deployment method provided in the embodiment of the present invention.

[0046] This invention provides a method for deploying network twin functionality, referring to... Figure 2 , Figure 2 This is a flowchart illustrating the first embodiment of the network twin functional deployment method of the present invention.

[0047] In this embodiment, the network twin deployment method includes the following steps:

[0048] Step S10: Upon receiving a service request from a user, retrieve the network twin service container image from a preset image repository according to the service request.

[0049] It should be noted that the execution subject of the method in this embodiment can be a cloud-native network cluster that deploys network twins, or other network twin deployment systems that can achieve the same or similar functions and include the cloud-native network cluster. This embodiment does not limit this.

[0050] It should be understood that the aforementioned preset image repository can be a repository that stores container images of network twin services.

[0051] It is understandable that the aforementioned network twin service container image can serve as a carrier for running business logic code.

[0052] In practice, the microservice-based business logic code of the network twin service and all its dependent runtime environments can be first packaged into a container image and pushed to the image repository in the cloud-native network cluster to form a preset image repository. When a user sends a business request (such as a business location relocation), the corresponding network twin service container image can be directly pulled from the preset image repository according to the business requirement.

[0053] Step S20: Push the network twin service container image to the target resource location in the infrastructure resources to run the network twin service container image.

[0054] It is understood that the aforementioned infrastructure resources can be independent resources allocated for network twin services within a cloud-native network cluster, such as physical resources like CPU, storage, and network. This embodiment does not impose any restrictions on this.

[0055] It should be noted that the target resource location mentioned above can be the location in the basic settings resources where the container image of the network twin service is running.

[0056] In practical implementation, infrastructure resources can provide the basic environment for container operation, realize the physical isolation of network twin services, and ensure the secure operation of network twin services. After pushing the network twin service container image to the target resource location in the infrastructure resources, the network twin service container image can be generated in the target resource location.

[0057] Step S30: Obtain a container copy of the network twin service from the network twin service container image according to the user's mobile location and the business requirements, and dynamically configure the container copy. The network twin service is the user's proxy in the cloud-native network.

[0058] It should be understood that the aforementioned location can be the user's current location after moving.

[0059] It is understandable that the aforementioned container copy can be a copy consisting of business logic code and runtime environment information pulled from the network twin service container image.

[0060] It should be noted that the aforementioned proxies may include: transport proxies, mobile proxies, security proxies, and data proxies, etc. In this embodiment, the network twin service can serve as a transport proxy, mobile proxy, security proxy, and data proxy for users (devices / terminals) in a cloud-native network. It is a fundamental service deployed and running on the edge cloud and core cloud in a cloud-native network to support upper-layer applications. Deploying the network twin service in a cloud-native network can solve security, transport, and mobility issues in cloud-native networks.

[0061] In practice, the container copy of the network twin can be dynamically configured according to the user's mobile location and user needs to achieve online migration and dynamic expansion of the network twin service, ensuring the reliable operation of the network twin service.

[0062] This embodiment discloses a method for obtaining a network twin service container image from a preset image repository upon receiving a user's service request; pushing the network twin service container image to a target resource location in the infrastructure resources to run the network twin service container image; and obtaining a container copy of the network twin service from the network twin service container image based on the user's mobile location and service request, and dynamically configuring the container copy. Compared to the prior art where devices access the network through the edge cloud, which presents challenges to the security, mobility, and reliability of cloud-native networks due to multiple operators, heterogeneous access methods, and heterogeneous transmission methods at the network edge, this embodiment solves the technical problems of mobility, reliability, and security issues that easily arise when devices access the network through the edge cloud in a cloud-native network.

[0063] refer to Figure 3 , Figure 3 This is a flowchart illustrating the second embodiment of the network twin functional deployment method of the present invention.

[0064] Based on the first embodiment described above, in order to ensure the secure, reliable, and efficient operation of the user's network twin service, in this embodiment, the cloud-native network cluster includes: a network twin service control engine and a network twin service; the network twin service control engine is located in the control plane of the cloud-native network cluster platform, and the network twin service is located in the data plane of the cloud-native network cluster platform.

[0065] Step S01: The network twin service control engine is used to send the corresponding configuration information to the network twin service when it detects the management and control command of the cloud-native network cluster platform. The network twin service monitors the user network behavior proxied by the network twin service through the configuration information.

[0066] It should be noted that the aforementioned network twin service control engine is a module for managing and controlling a user's network twin service. In practical applications, the network twin service control engine can interact in real time with the controller of the cloud-native network cluster platform's control plane, thereby sensing the control commands of the cloud-native network cluster platform and transmitting the configuration requirements of the network twin service. Furthermore, the network twin service control engine can manage and control a user's network twin service, such as configuring and distributing personalized security policies, authenticating and authorizing network twin identities and managing the root of trust, and dynamically orchestrating services according to the user's personalized needs for the network twin service (mobility, resource constraints, security, and reliability, etc.), ensuring the secure, reliable, and efficient operation of the user's network twin service.

[0067] It should be understood that the aforementioned management and control commands can be used to manage and control the network twin service. In practical applications, the network twin service control engine can achieve self-monitoring of the user's network twin service and ensure its security by pushing the user's network twin service management configuration information to the user's network twin service.

[0068] It is understood that in cloud-native networks, this embodiment can deploy network twin services in a cloud-native manner based on a cloud-native network cluster platform. The cloud-native network cluster platform supports cloud-native deployment modes for applications and is not limited to the Kubernetes container platform.

[0069] In the specific implementation, refer to Figure 4 , Figure 4 This is a schematic diagram illustrating the deployment of the network twin service on a cloud-native network cluster platform in the second embodiment of the network twin functional deployment method of the present invention. Figure 4 As shown, the network twin service control engine is located in the control plane of the cloud-native network cluster platform, while the network twin service is located in the data plane of the same platform. The network twin service control engine includes a security configuration policy module, an authentication and authorization management module, and a service orchestration module; the network twin service includes a security module, a transport module, a mobility module, and a resource module. Furthermore, the network twin service exists as Pods (clusters) within the cloud-native network cluster platform, enabling containerized deployment. Security is ensured between network twin services through physical resource isolation and container isolation.

[0070] Furthermore, in order to enable the user's network twin service to monitor its own behavior in the cloud-native network, the network twin service control engine includes a security configuration policy module.

[0071] The security configuration policy module is used to obtain a security configuration policy when a configuration command is detected from the cloud-native network cluster platform, and send the security configuration policy to the user. The security configuration policy is used to configure network security for the user.

[0072] It should be noted that the above configuration distribution command can be an instruction to the security configuration policy module to send configuration information to the corresponding network twin service.

[0073] In practical implementation, when the network twin service control engine detects management and control commands from the cloud-native network cluster platform, it can transmit the personalized configuration requirements of the network twin service, sending the configuration information of each user's network twin service to that service. This enables user network twin services to monitor their own behavior within the cloud-native network and perform secure management and maintenance of the network twin service. If the command is a configuration issuance command, it can combine cloud-native network security configuration policies to perform network security configuration for users.

[0074] Furthermore, in order to perform secure and reliable identity authentication for users, the network twin service control engine also includes an authentication and authorization management module.

[0075] The authentication and authorization management module is used to send a target identity root to the user when it detects the identity authentication command of the cloud-native network cluster platform. The target identity root is used for user identity authentication.

[0076] It should be understood that the aforementioned authentication instructions can be instructions used to instruct users to authenticate their identities. In practical applications, when the authentication and authorization management module detects an instruction to instruct users to authenticate their identities, it can provide the user with a secure and trusted identity root to achieve secure and trusted identity authentication for the user.

[0077] Furthermore, to address user mobility issues, the network twin service control engine also includes a service orchestration module.

[0078] The service orchestration module is used to obtain personalized demand information of the network twin service and to perform service operation and maintenance orchestration of the network twin service according to the personalized demand information. The service operation and maintenance orchestration is used to perform online migration and dynamic expansion of the network twin service to ensure that users are always online.

[0079] It is understood that the aforementioned personalized requirements may include user needs such as mobility, resource constraints, security, and reliability, and this implementation does not impose any restrictions on these.

[0080] In practical implementation, the service orchestration module can efficiently deploy and orchestrate user network twin services in the cloud-native environment based on users' personalized needs such as mobility, resource constraints, security, and reliability. This enables online migration and dynamic scaling of user network twin services, ensuring that users' network twin services are always online. This solves users' mobility problems and ensures that users can access the cloud-native network and obtain services from it anytime, anywhere.

[0081] In this embodiment, the cloud-native network cluster includes a network twin service control engine and a network twin service. The network twin service control engine is located in the control plane of the cloud-native network cluster platform, while the network twin service is located in the data plane of the cloud-native network cluster platform. When the network twin service control engine detects management and control commands from the cloud-native network cluster platform, it sends the corresponding configuration information to the network twin service. The network twin service monitors network behavior using the configuration information, thereby ensuring the secure, reliable, and efficient operation of the user's network twin service. Specifically, the security configuration module in the network twin service control engine can send security configuration policies to the user, providing network security policies. The authentication and authorization management module in the network twin service control engine can provide the user with an identity root when authentication is required, thus enabling user authentication. Furthermore, the service orchestration module in the network twin service control engine can orchestrate the service operation and maintenance of the network twin service according to the user's personalized needs, thereby addressing user mobility issues.

[0082] refer to Figure 5 , Figure 5 This is a flowchart illustrating the third embodiment of the network twin functional deployment method of the present invention.

[0083] Based on the above embodiments, in this embodiment, the network twin service includes: a security module, a resource module, and a transmission module.

[0084] Step S100: The security module is used to perform security authentication on the user when it detects a user access request sent by the user, so that the user can access the network when the authentication is successful.

[0085] It should be noted that the above user access request can be a request sent by the user to access the cloud-native network.

[0086] It should be understood that the security module in a network twin service can be used for management from endpoint access to application management, including real-name internet access with name-address separation, and authentication and authorization for application and resource access permissions. In practical applications, when a user accesses the internet, they can send a user access request. After detecting the user access request, the security module can perform dynamic security authentication on the user, thereby solving the network security problems caused by anonymous internet access. (Refer to...) Figure 6 , Figure 6 This is a functional module diagram of the network twin service in the third embodiment of the network twin deployment method of the present invention. (See diagram below.) Figure 6 As shown, the security module has functions such as authentication and access control (e.g., identity authentication, internal authentication, visitor authentication, and IoT terminal authentication), application management and access control, behavior auditing (e.g., application identification and log analysis), and risk awareness (e.g., identity security awareness, traffic flow monitoring, and security encryption).

[0087] Step S200: The resource module is used to obtain the operator service resources required by the user's service needs according to the user's service needs when the user accesses the network.

[0088] It is understood that the aforementioned operator service resources can be the service resources that the resource module negotiates with the service provider based on business needs. The operator can be a cloud service provider, a telecom operator, or a service provider capable of providing the resources required for the business; this embodiment does not impose any restrictions on this.

[0089] Step S300: The resource module is further configured to generate a service instance set based on the operator service resources, the service instance set being used to support service transmission.

[0090] It should be noted that, as Figure 6 As shown, the resource module in a network twin service can manage user assets and provide services externally. Furthermore, it can negotiate resources with other network twins or service providers. In practical applications, it can negotiate cloud-to-edge communication, computing, and storage resources with cloud service providers; edge-to-edge transmission resources with telecom operators; additional service resources such as edge-to-edge transmission resources and communication enhancement services with telecom operators; and service resources (such as AI models, data, and information) required by other users' network twins. The order and method of resource negotiation are unrestricted; it can precede negotiations with cloud service providers, telecom operators, or other service providers.

[0091] It should be understood that, in this embodiment, a service instance set can also be generated based on the service resources obtained through resource negotiation in the network twin service to support the operation and transmission of personalized user services.

[0092] In the specific implementation, refer to Figure 7 , Figure 7 This is a schematic diagram illustrating the location and function of the network twin service in a cloud-native network in the third embodiment of the network twin deployment method of the present invention. Figure 7As shown, after accessing the network, a user can initiate personalized service requests (users can access the network via cellular or WiFi and through the edge cloud). At this time, the resource module in the network twin service can calculate the service resources required to guarantee the current service based on the service needs. That is, it negotiates resources with the service provider, obtains the required service resources, and generates a service instance set based on the required service resources to support the operation and transmission of the user's personalized service. The functions and characteristics of network twins can include: mobility, storage, AI models, computing, and latency prediction, etc.

[0093] Step S400: The transmission module is used to integrate and control the transmission capabilities of the service transmission during service transmission.

[0094] It is understandable that, such as Figure 6 As shown, the transmission module in the network twin service can include various access methods such as limited access and wireless access, as well as transmission mechanisms (such as end-to-end transmission). Furthermore, the transmission module can also integrate and manage transmission capabilities. Transmission management can include: transmission cooperation methods (such as redundancy, handover, switching, or aggregation), transmission management (such as interfaces, ports, and security), and transmission cost control. This embodiment does not impose any limitations on these aspects.

[0095] Furthermore, the network twin service also includes a mobile module.

[0096] The mobility module is used to establish a mobility strategy based on the service requirements and to schedule service transmission according to the mobility strategy.

[0097] It should be noted that, as Figure 6 As shown, the mobile module in the network twin service can manage the user's location and identity, and quickly establish mobile policies for transmission scheduling based on user needs.

[0098] In its implementation, when a user accesses the internet, the security module within the network twin service performs dynamic security authentication, resolving network security issues arising from anonymous internet access. The resource module can flexibly negotiate available resources with multiple operators based on the user's personalized integrated service needs, achieving efficient matching and flexible scheduling of cloud-edge service resources and edge-end transmission resources, ensuring the service quality of personalized services. Simultaneously, the resource module can record user behavior data in both physical and cyberspace, allowing users to own their data and establish ownership of their digital assets, thus protecting their privacy and exercising control over their data. Furthermore, besides addressing security, transmission, and mobility issues, the network twin service brings a fundamental change: the establishment of ownership of personal digital assets. Moreover, based on the user's personal data, intelligent assistants can provide truly personalized services.

[0099] In this embodiment, the network twin service includes a security module, a resource module, and a transmission module. The security module performs security authentication on the user upon detecting a user access request, allowing the user to access the network upon successful authentication. The resource module, upon user access to the network, acquires the necessary operator service resources based on the user's service requirements and generates a service instance set based on these resources. This service instance set supports service transmission. The transmission module integrates and manages the transmission capabilities of the service transmission, thereby solving the technical problem in the prior art where devices access the network through the edge cloud in a cloud-native network, which easily leads to mobility, reliability, and security issues.

[0100] Furthermore, this embodiment of the invention also proposes a storage medium storing a network twin function deployment program, which, when executed by a processor, implements the steps of the network twin function deployment method described above.

[0101] Reference Figure 8 , Figure 8 This is a structural block diagram of the first embodiment of the network twin functional deployment device of the present invention.

[0102] like Figure 8 As shown, the network twin functional deployment device proposed in this embodiment of the invention includes:

[0103] The container image acquisition module 801 is used to acquire the network twin service container image from a preset image repository according to the business requirements when a user sends a business request.

[0104] The container image execution module 802 is used to push the network twin service container image to a target resource location in the infrastructure resources to run the network twin service container image;

[0105] The container replica configuration module 803 is used to obtain a container replica of the network twin service from the network twin service container image according to the user's mobile location and the business requirements, and to dynamically configure the container replica. The network twin service is a proxy for the user in the cloud-native network.

[0106] This embodiment of the network twin deployment apparatus discloses that, upon receiving a user's service request, it retrieves a network twin service container image from a preset image repository based on the service request; pushes the network twin service container image to a target resource location in the infrastructure resources to run the network twin service container image; and retrieves a container copy of the network twin service from the network twin service container image based on the user's mobile location and service request, and dynamically configures the container copy. Compared to the prior art where devices access the network through the edge cloud, which presents challenges to the security, mobility, and reliability of cloud-native networks due to multiple operators, heterogeneous access methods, and heterogeneous transmission methods at the network edge, this embodiment solves the technical problems of mobility, reliability, and security issues that easily arise when devices access the network through the edge cloud in a cloud-native network, by retrieving the network twin service container image based on the user's service request, pushing the network twin service container image to the target resource location and running the network twin service container image, and dynamically configuring the container copy of the network twin service obtained from the network twin service container image.

[0107] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0108] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0109] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0110] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A method for deploying network twin functions, characterized in that, The network twin deployment method is applied to cloud-native network clusters, and the method includes: Upon receiving a service request from a user, the system retrieves a network twin service container image from a pre-defined image repository based on the service request. The network twin service container image is pushed to the target resource location in the infrastructure resources to run the network twin service container image; Based on the user's mobile location and the business requirements, a container copy of the network twin service is obtained from the network twin service container image, and the container copy is dynamically configured. The network twin service serves as the user's proxy in the cloud-native network. The cloud-native network cluster includes: a network twin service control engine and a network twin service; the network twin service control engine is set in the control plane of the cloud-native network cluster platform and is used to interact with the controller of the control plane in real time; the network twin service is set in the data plane of the cloud-native network cluster platform; the network twin service is deployed in a cloud-native manner based on the cloud-native network cluster platform and exists in the cloud-native network cluster platform in the form of a cluster. The network twin service control engine is used to send corresponding configuration information to the network twin service when it detects management and control commands from the cloud-native network cluster platform. The network twin service monitors the user network behavior proxied by the network twin service through the configuration information.

2. The network twin functional deployment method as described in claim 1, characterized in that, The network twin service control engine includes: a security configuration policy module; The security configuration policy module is used to obtain a security configuration policy when a configuration command is detected from the cloud-native network cluster platform, and send the security configuration policy to the user. The security configuration policy is used to configure network security for the user.

3. The network twin functional deployment method as described in claim 1, characterized in that, The network twin service control engine also includes: an authentication and authorization management module; The authentication and authorization management module is used to send a target identity root to the user when it detects the identity authentication command of the cloud-native network cluster platform. The target identity root is used for user identity authentication.

4. The network twin functional deployment method as described in claim 1, characterized in that, The network twin service control engine also includes: a service orchestration module; The service orchestration module is used to obtain personalized demand information of the network twin service and to perform service operation and maintenance orchestration of the network twin service according to the personalized demand information. The service operation and maintenance orchestration is used to perform online migration and dynamic expansion of the network twin service to ensure that users are always online.

5. The network twin functional deployment method according to any one of claims 1 to 4, characterized in that, The network twin service includes: a security module, a resource module, and a transmission module; The security module is used to perform security authentication on the user when a user access request is detected, so that the user can be connected to the network when the authentication is successful. The resource module is used to obtain the operator service resources required by the user's service needs according to the user's service needs when the user accesses the network. The resource module is also used to generate a service instance set based on the operator service resources, and the service instance set is used to support service transmission. The transmission module is used to integrate and control the transmission capabilities of the service transmission during service transmission.

6. The network twin functional deployment method as described in claim 5, characterized in that, The network twin service also includes: a mobile module; The mobility module is used to establish a mobility strategy based on the service requirements and to schedule service transmission according to the mobility strategy.

7. A network twin functional deployment device, characterized in that, The device includes: The container image acquisition module is used to acquire the network twin service container image from a preset image repository according to the business requirements when a user sends a business request. The container image execution module is used to push the network twin service container image to a target resource location in the infrastructure resources to run the network twin service container image; The container replica configuration module is used to obtain a container replica of the network twin service from the network twin service container image according to the user's mobile location and the business requirements, and to dynamically configure the container replica. The network twin service is the user's proxy in the cloud-native network. The cloud-native network cluster includes: a network twin service control engine and a network twin service; the network twin service control engine is set in the control plane of the cloud-native network cluster platform and is used to interact with the controller of the control plane in real time; the network twin service is set in the data plane of the cloud-native network cluster platform; the network twin service is deployed in a cloud-native manner based on the cloud-native network cluster platform and exists in the cloud-native network cluster platform in the form of a cluster. The network twin service control engine is used to send corresponding configuration information to the network twin service when it detects management and control commands from the cloud-native network cluster platform. The network twin service monitors the user network behavior proxied by the network twin service through the configuration information.

8. A network twin functional deployment device, characterized in that, The device includes: a memory, a processor, and a network twin function deployment program stored on the memory and executable on the processor, the network twin function deployment program being configured to implement the steps of the network twin function deployment method as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium stores a network twin functional deployment program, which, when executed by a processor, implements the steps of the network twin functional deployment method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Virtual-real fusion space authentication method for 4G network

    CN115567936A