Access control method and apparatus, computer-readable medium, and electronic device
Patent Information
- Application Number
- CN202210932790.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-04
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-08-04
AI Technical Summary
这种方式不仅成本高,而且专线开通时间受运营商施工影响,同时对于经常移动或需要多地点部署的用户来讲非常不方便
[0012]在本申请的一些实施例所提供的技术方案中,通过由控制器向网络提供方的接入网关,以及网络接入方发送第一配置信息,以指示网络接入方通过核心网网元与接入网关建立第一传输隧道,并向接入网关及连接在接入网关和专有网络之间的转发设备发送第二配置信息,以指示接入网关与转发设备建立第二传输隧道,使得可以通过第一传输隧道将网络接入方的流量传输至接入网关,并通过第二传输隧道将网络接入方的流量传输至转发设备,以使转发设备将网络接入方的流量路由至专有网络。可见,在本申请实施例的技术方案中,通过控制器下发配置信息的方式就可以实现网络接入方对专有网络的接入,降低了接入专有网络时对传统专线网络的依赖,有效提高了网络接入速度。
Smart Images

Figure CN117560245B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of computer and communication technology, and more specifically, to an access control method, apparatus, computer-readable medium, and electronic device. Background Technology
[0002] In related technologies, if cloud users want to connect their local Internet Data Center (IDC) or network equipment to a Virtual Private Cloud (VPC) in the cloud and enjoy low latency, high bandwidth, and secure network quality, they can only do so by connecting to the nearest POP (Point of Presence) of their local ISP through a dedicated line, and then connecting to the cloud VPC via the ISP's dedicated line. This method is not only costly, but the time required for the dedicated line to be activated is also affected by the ISP's construction schedule, and it is also very inconvenient for users who frequently move or need to deploy in multiple locations. Summary of the Invention
[0003] The embodiments of this application provide an access control method, apparatus, computer-readable medium, and electronic device, which enable network access parties to access private networks by means of configuration information issued by the controller, thereby effectively improving network access speed.
[0004] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part by practice of this application.
[0005] In a first aspect, embodiments of this application provide an access control method, comprising: obtaining information about a private network (VPC) requested by a network access party; sending first configuration information to an access gateway of a network provider and the network access party to instruct the network access party to establish a first transmission tunnel with the access gateway through a core network element, wherein the first transmission tunnel is used to transmit the network access party's traffic to the access gateway; and, based on the information about the VPC, sending second configuration information to the access gateway and a forwarding device connected between the access gateway and the VPC to instruct the access gateway to establish a second transmission tunnel with the forwarding device, wherein the second transmission tunnel is used to transmit the network access party's traffic to the forwarding device, so that the forwarding device routes the network access party's traffic to the VPC.
[0006] Secondly, embodiments of this application provide an access control method, comprising: receiving first configuration information sent by a controller, the first configuration information being used to instruct a network access party to establish a first transmission tunnel with an access gateway through a core network element; establishing a first transmission tunnel between the access gateway and the network access party through the core network element according to the first configuration information, the first transmission tunnel being used to transmit the traffic of the network access party to the access gateway; receiving second configuration information sent by the controller, the second configuration information being used to instruct the access gateway to establish a second transmission tunnel with a forwarding device, the forwarding device being connected between the access gateway and a private network requested for access by the network access party; establishing a second transmission tunnel between the access gateway and the forwarding device according to the second configuration information, the second transmission tunnel being used to transmit the traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
[0007] Thirdly, embodiments of this application provide an access control device, comprising: an acquisition unit configured to acquire information about a private network (VPC) requested for access by a network access party; a configuration unit configured to send first configuration information to an access gateway of a network provider and the network access party, instructing the network access party to establish a first transmission tunnel with the access gateway through a core network element, wherein the first transmission tunnel is used to transmit the network access party's traffic to the access gateway; the configuration unit is further configured to: send second configuration information to the access gateway and a forwarding device connected between the access gateway and the VPC, based on the information of the VPC, instructing the access gateway to establish a second transmission tunnel with the forwarding device, wherein the second transmission tunnel is used to transmit the network access party's traffic to the forwarding device, so that the forwarding device routes the network access party's traffic to the VPC.
[0008] Fourthly, embodiments of this application provide an access control device, comprising: a receiving unit configured to receive first configuration information sent by a controller, the first configuration information being used to instruct a network access party to establish a first transmission tunnel with an access gateway through a core network element; and receiving second configuration information sent by the controller, the second configuration information being used to instruct the access gateway to establish a second transmission tunnel with a forwarding device, the forwarding device being connected between the access gateway and a private network to which the network access party requests access; and an establishing unit configured to establish, according to the first configuration information, a first transmission tunnel between the access gateway and the network access party through the core network element, the first transmission tunnel being used to transmit traffic of the network access party to the access gateway; and to establish, according to the second configuration information, a second transmission tunnel between the access gateway and the forwarding device, the second transmission tunnel being used to transmit traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
[0009] Fifthly, embodiments of this application provide a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the access control method as described in the above embodiments.
[0010] Sixthly, embodiments of this application provide an electronic device, including: one or more processors; and a storage device for storing one or more computer programs, wherein when the one or more computer programs are executed by the one or more processors, the electronic device implements the access control method as described in the above embodiments.
[0011] In a seventh aspect, embodiments of this application provide a computer program product comprising a computer program stored in a computer-readable storage medium. A processor of an electronic device reads from the computer-readable storage medium and executes the computer program, causing the electronic device to perform the access control methods provided in the various alternative embodiments described above.
[0012] In some embodiments of this application, the controller sends first configuration information to the network provider's access gateway and the network access party, instructing the network access party to establish a first transmission tunnel with the access gateway through core network elements. Second configuration information is then sent to the access gateway and the forwarding device connected between the access gateway and the VPC, instructing the access gateway to establish a second transmission tunnel with the forwarding device. This allows the network access party's traffic to be transmitted to the access gateway through the first transmission tunnel and to the forwarding device through the second transmission tunnel, enabling the forwarding device to route the network access party's traffic to the VPC. Therefore, in the technical solutions of this application, the network access party can access the VPC by sending configuration information from the controller, reducing reliance on traditional leased lines and effectively improving network access speed.
[0013] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0014] Figure 1 A schematic diagram of an exemplary system architecture to which the technical solutions of the embodiments of this application can be applied is shown;
[0015] Figure 2 A flowchart of an access control method according to an embodiment of this application is shown;
[0016] Figure 3 A flowchart of an access control method according to an embodiment of this application is shown;
[0017] Figure 4 A schematic diagram of an exemplary system architecture for which the access control scheme of the embodiments of this application can be applied is shown;
[0018] Figure 5 A schematic diagram illustrating the connection relationship between a CPE and an access GW according to an embodiment of this application is shown;
[0019] Figure 6 A schematic diagram illustrating the connection relationship between a UPF and an access GW according to an embodiment of this application is shown.
[0020] Figure 7 A schematic diagram illustrating the connection relationship between the access GW and the NGW according to an embodiment of this application is shown;
[0021] Figure 8 An interactive flowchart of an access control method according to an embodiment of this application is shown;
[0022] Figure 9A block diagram of an access control device according to an embodiment of this application is shown;
[0023] Figure 10 A block diagram of an access control device according to an embodiment of this application is shown;
[0024] Figure 11 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation
[0025] Exemplary embodiments will now be described in a more comprehensive manner with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to these examples; rather, these embodiments are provided so that this application will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art.
[0026] Furthermore, the features, structures, or characteristics described in this application can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to provide a full understanding of the embodiments of this application. However, those skilled in the art will recognize that when implementing the technical solutions of this application, not all the detailed features in the embodiments may be used, one or more specific details may be omitted, or other methods, elements, devices, steps, etc., may be employed.
[0027] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0028] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.
[0029] It should be noted that "multiple" in this article refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0030] The technical solutions of this application's embodiments relate to the field of cloud technology. Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to realize the computation, storage, processing, and sharing of data.
[0031] Cloud technology is a general term encompassing network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. The backend services of cloud technology network systems require substantial computing and storage resources, as seen in video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may eventually possess its own identification mark, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will all require robust system support, which can only be achieved through cloud computing.
[0032] In related technologies, if cloud users want to connect their local data center or network equipment to a cloud-based VPC and enjoy low latency, high bandwidth, and secure network quality, they can only do so by connecting to the nearest POP (Point of Presence) of their local ISP through a dedicated line, and then connecting to the cloud VPC via the ISP's dedicated line. This method is not only costly, but the time required for the dedicated line to be activated is also affected by the ISP's construction schedule, and it is also very inconvenient for users who frequently move or need to deploy in multiple locations.
[0033] Based on the problems existing in related technologies, this application proposes a new network access control scheme, which enables network access parties to access private networks by issuing configuration information through the controller. This reduces the dependence on traditional leased lines when accessing private networks and effectively improves network access speed.
[0034] Specifically, in a particular application scenario of this application, such as Figure 1 As shown, the system architecture includes a controller 101, a network access point 102, a mobile network core network element 103, a network provider, and a private network. The network provider deploys an access gateway (GW) 104 and a forwarding device 105.
[0035] Optionally, the controller 101 can be a server, which can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The network access point 102 can be a local data center or a terminal device capable of accessing the network. Terminal devices can be, for example, smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, vehicle terminals, aircraft, etc., but are not limited to these.
[0036] In one embodiment of this application, the controller 101 can obtain information about the private network requested by the network access party 102, such as by obtaining the information about the private network requested by the network access party 102 through a provided configuration interface or console.
[0037] In one embodiment of this application, after receiving information from the network access party 102 requesting access to a private network, the controller 101 can send first configuration information to the access gateway 104 of the network provider and the network access party 102 to instruct the network access party 102 to establish a first transmission tunnel with the access gateway 104 through the core network element 103. The first transmission tunnel is used to transmit the traffic of the network access party 102 to the access gateway 104.
[0038] Optionally, before sending the first configuration information to the access gateway 104 and the network access party 102, the controller 101 may also send third configuration information to the access gateway 104 and the core network element 103 to instruct the core network element 103 to establish a Generic Routing Encapsulation (GRE) tunnel with the access gateway 104. Then, the first transmission tunnel between the network access party 102 and the access gateway 104 can be load-loaded onto this GRE tunnel.
[0039] Optionally, to ensure data security, the first transmission tunnel can be an IPSec (Internet Protocol Security) tunnel.
[0040] In one embodiment of this application, the controller 101 may also send second configuration information to the access gateway 104 and the forwarding device 105 connected between the access gateway 104 and the VPC, to instruct the access gateway 104 and the forwarding device 105 to establish a second transmission tunnel. This second transmission tunnel is used to transmit the traffic of the network access party 102 to the forwarding device 105, so that the forwarding device 105 routes the traffic of the network access party 102 to the VPC. Optionally, since the access gateway 104 and the forwarding device 105 are within the network provider, encrypted transmission is not required. Therefore, the IPSec tunnel can be decapsulated on the access gateway 104, and then the user traffic can be transferred to a lighter VXLAN (Virtual Extensible Local Area Network) tunnel. That is, the second transmission tunnel can be a VXLAN tunnel.
[0041] Optionally, core network element 103 can be a UPF (User Plane Function). The UPF is an important component of the 3GPP 5G core network system architecture, primarily responsible for routing and forwarding user plane data packets in the 5G core network. Forwarding device 105 can be an NGW (Next Generation Gateway), mainly used in scenarios such as hybrid cloud private line access, inter-domain interconnection, and public cloud interconnection to achieve high-performance forwarding, support multi-tenant access, support TGRE (Tunnel-GRE), VXLAN tunneling protocols, and also support features such as fragmentation, reassembly, and rate limiting.
[0042] exist Figure 1 In the system architecture shown, the network access party 102 can access the private network by issuing configuration information through the controller 101, which reduces the dependence on the traditional leased line network when accessing the private network and effectively improves the network access speed.
[0043] The implementation details of the technical solutions in the embodiments of this application are described in detail below:
[0044] Figure 2 A flowchart of an access control method according to an embodiment of this application is shown. This access control method can be executed by a controller, which may be... Figure 1 The controller 101 shown is illustrated. (Refer to...) Figure 2 As shown, this access control method includes at least S210 to S230, which are described in detail below:
[0045] In S210, information about the private network that the network access party requests to access is obtained.
[0046] In some alternative embodiments, the network access party can send information requesting access to the private network to the controller through a configuration interface or console. The network access party can be a tenant of the private network, specifically through a CPE (Customer Premises Equipment) to send the information requesting access to the private network to the controller.
[0047] In S220, first configuration information is sent to the access gateway of the network provider and the network access party to instruct the network access party to establish a first transmission tunnel with the access gateway through the core network element. The first transmission tunnel is used to transmit the network access party's traffic to the access gateway.
[0048] In some alternative embodiments, the first transport tunnel may be an IPSec tunnel, which ensures the security of the data from the network access party during transmission to the network provider.
[0049] In some optional embodiments, the network provider may deploy at least two access gateways. In this case, the process of the controller sending the first configuration information to the network provider's access gateways and the network access party may be as follows: the controller sends the first configuration information to the network access party and at least two access gateways to instruct the network access party to establish a first transmission tunnel with each of the at least two access gateways, and to instruct the first transmission tunnel established between the network access party and the at least two access gateways to be in the form of equal cost multi-path (ECMP) routing. This allows for seamless replacement of service traffic through other access gateways when any access gateway fails, ensuring the continuity and stability of service traffic transmission.
[0050] Optionally, the aforementioned core network element can be a UPF. The network access party can connect to the UPF through access network equipment (such as a base station) and then establish a first transmission tunnel with the access gateway through the UPF.
[0051] In one embodiment of this application, before sending the first configuration information to the access gateway of the network provider and the network access party, the controller also needs to instruct the access gateway and the core network element to establish a transmission tunnel first. Specifically, the controller can send third configuration information to the access gateway and the core network element to instruct the core network element to establish a GRE tunnel with the access gateway. In this case, the first transmission tunnel between the network access party and the access gateway can be overloaded onto a generic routing encapsulation tunnel. For example, if the first transmission tunnel is an IPSec tunnel, then in the transmission tunnel established between the network access party and the access gateway, the transmission tunnel between the core network element and the access gateway is an IPSec over GRE tunnel.
[0052] In some optional embodiments, the network provider may deploy at least two access gateways. In this case, the controller may send third configuration information to the at least two access gateways and at least two core network elements to instruct each core network element to establish a common route encapsulation tunnel with each of the at least two access gateways, and to instruct that the common route encapsulation tunnel established between each core network element and the at least two access gateways is an equal-cost multipath route. This embodiment's technical solution enables efficient utilization of the forwarding capabilities between access gateways and core network elements, and also allows for ensuring the reliability and stability of network transmission through ECMP in the event of anomalies in some core network elements or access gateways.
[0053] In S230, based on the information of the private network, second configuration information is sent to the access gateway and the forwarding device connected between the access gateway and the private network to instruct the access gateway and the forwarding device to establish a second transmission tunnel. The second transmission tunnel is used to transmit the traffic of the network access party to the forwarding device so that the forwarding device can route the traffic of the network access party to the private network.
[0054] In some alternative embodiments, the forwarding device can be a gateway device, such as an NGW device. The forwarding device is connected to the access gateway and the private network, and can forward the user traffic to the private network after receiving the user traffic forwarded by the access gateway.
[0055] In some optional embodiments, the network provider may deploy at least two access gateways and at least two forwarding devices. In this case, the process of the controller sending second configuration information to the access gateways and the forwarding devices connected between the access gateways and the VPC may specifically involve sending second configuration information to the at least two access gateways and at least two forwarding devices to instruct each access gateway to establish a second transmission tunnel with at least two forwarding devices, and to instruct that the second transmission tunnel established by each access gateway with at least two forwarding devices is an equal-cost multipath route. This embodiment's technical solution enables efficient utilization of the forwarding capabilities between the access gateways and forwarding devices, and also allows for ensuring the reliability and stability of network transmission through ECMP in the event of anomalies in some forwarding devices or access gateways.
[0056] In some alternative embodiments, since the access gateway and the forwarding device are within the network provider's premises, encrypted transmission is not required, so the second transmission tunnel can be a lightweight VXLAN tunnel. If the first transmission tunnel is an IPSec tunnel, the access gateway can decapsulate the IPSec tunnel and then forward user traffic into the VXLAN tunnel, which then routes it to the forwarding device, which then transmits it to the dedicated gateway.
[0057] It should be noted that, Figure 2 The execution order between S220 and S230 shown is not specifically limited; for example, it can be executed in the following order: Figure 2 The order shown is to execute S220 first, then S230; or S230 can be executed first, then S220; or S220 and S230 can be executed simultaneously.
[0058] Figure 2 The technical solution of the embodiment shown enables network access parties to access the private network by issuing configuration information through the controller, reducing the dependence on traditional leased lines when accessing the private network and effectively improving network access speed.
[0059] The following details the implementation of the technical solution in this application from the perspective of the access gateway:
[0060] Figure 3 A flowchart of an access control method according to an embodiment of this application is shown. This access control method can be executed by an access gateway, which may be... Figure 1 The access gateway 104 is shown in the diagram. (Refer to...) Figure 3 As shown, this access control method includes at least S310 to S340, which are described in detail below:
[0061] In S310, the receiving controller sends first configuration information, which is used to instruct the network access party to establish a first transmission tunnel with the access gateway through the core network element.
[0062] In some optional embodiments, the first transmission tunnel can be an IPSec tunnel, which ensures the security of data transmitted from the network access party to the network provider. Optionally, the core network element can be a UPF, and the network access party can connect to the UPF through access network equipment (such as a base station), and then establish the first transmission tunnel with the access gateway through the UPF.
[0063] In one embodiment of this application, before receiving the first configuration information sent by the controller, the access gateway may establish a transmission tunnel with the core network element according to the controller's instructions. Specifically, before receiving the first configuration information sent by the controller, the access gateway may also receive third configuration information sent by the controller. This third configuration information is used to instruct the core network element to establish a GRE tunnel with the access gateway. The access gateway can then establish a general routing encapsulation tunnel between the access gateway and the core network element according to the third configuration information. In this case, the first transmission tunnel between the network access party and the access gateway can be overloaded onto the general routing encapsulation tunnel. For example, if the first transmission tunnel is an IPSec tunnel, then in the transmission tunnel established between the network access party and the access gateway, the transmission tunnel between the core network element and the access gateway is an IPSec over GRE tunnel.
[0064] In some optional embodiments, when there are at least two core network elements, the process of establishing a general route encapsulation tunnel between the access gateway and the core network element based on the third configuration information can be to establish general route encapsulation tunnels between the access gateway and at least two core network elements respectively, based on the third configuration information. In this case, the forwarding capabilities between the access gateway and the core network element can be utilized efficiently, and the GRE tunnels established between each core network element and at least two access gateways can be configured as equal-cost multipath routes. This allows ECMP to ensure the reliability and stability of network transmission in the event of anomalies in some core network elements or access gateways.
[0065] In S320, a first transmission tunnel is established between the access gateway and the network access party through the core network element based on the first configuration information. This first transmission tunnel is used to transmit the traffic of the network access party to the access gateway.
[0066] In S330, a second configuration information is sent by the receiving controller. This second configuration information is used to instruct the access gateway to establish a second transmission tunnel with the forwarding device, which is connected between the access gateway and the private network requested by the network access party.
[0067] In some alternative embodiments, the forwarding device can be a gateway device, such as an NGW device. The forwarding device is connected to the access gateway and the private network, and can forward the user traffic to the private network after receiving the user traffic forwarded by the access gateway.
[0068] In S340, a second transmission tunnel is established between the access gateway and the forwarding device according to the second configuration information. This second transmission tunnel is used to transmit the traffic of the network access party to the forwarding device so that the forwarding device can route the traffic of the network access party to the private network.
[0069] In some optional embodiments, the network provider may deploy at least two forwarding devices. The access gateway can then establish second transmission tunnels with each of the at least two forwarding devices based on the second configuration information, and configure these second transmission tunnels as equal-cost multipath routes. This embodiment's technical solution enables efficient utilization of the forwarding capabilities between the access gateway and the forwarding devices, and also ensures the reliability and stability of network transmission through ECMP in the event of anomalies in some forwarding devices or some access gateways.
[0070] In some alternative embodiments, since the access gateway and the forwarding device are within the network provider's premises, encrypted transmission is not required, so the second transmission tunnel can be a lightweight VXLAN tunnel. If the first transmission tunnel is an IPSec tunnel, the access gateway can decapsulate the IPSec tunnel and then forward the decapsulated user traffic into the VXLAN tunnel, which then routes it to the forwarding device, which then transmits it to the dedicated gateway.
[0071] It should be noted that, Figure 3 The execution order of the process of receiving the first configuration information in S310 and the process of receiving the second configuration information in S330 is not specifically limited. For example, they can be executed in the following order: Figure 3 The sequence shown is as follows: first, the process of receiving the first configuration information in S310 is executed, and then the process of receiving the second configuration information in S330 is executed; or the process of receiving the second configuration information in S330 is executed first, and then the process of receiving the first configuration information in S310 is executed; or the process of receiving the second configuration information in S330 and the process of receiving the first configuration information in S310 are executed simultaneously.
[0072] Figure 3 The technical solution of the embodiment shown enables network access parties to access the private network by issuing configuration information through the controller, reducing the dependence on traditional leased lines when accessing the private network and effectively improving network access speed.
[0073] The following combination Figures 4 to 8 The network access scheme of this application embodiment will be described in detail again in conjunction with specific application scenarios:
[0074] exist Figure 4 In the application scenario shown, the controller is divided into a CPE controller, a gateway controller, and a cloud controller. These controllers collectively implement the functions of the controller described in the previous embodiments. The cloud tenant side refers to the user who leases a Virtual Private Cloud (VPC), i.e., the network access party in the previous embodiments; the UPF refers to the core network element in the previous embodiments; the access GW refers to the access gateway in the previous embodiments; and the NGW refers to the forwarding device in the previous embodiments.
[0075] Figure 4 The technical solution of the illustrated embodiment mainly adopts the design concept of separation of control and relay in NFV (Network Functions Virtualization), which consists of a controller on the cloud (i.e., CPE controller + gateway controller + cloud controller) and lower-layer network devices. The network devices include mobile CPEs on the cloud tenant side for accessing the network; base stations, UPFs, etc. on the operator side; and access gateways, NGWs, etc. on the cloud provider side.
[0076] In NFV networks, an x86 server architecture is adopted, which encapsulates different network functions such as routers, switches, firewalls, and load balancers into independent modular software. By running different modular software on hardware devices, diverse network functions can be implemented on a single hardware device. The NFV architecture consists of three parts: Network Functions Virtualization Infrastructure (NFVI), Virtual Network Functions (VNF), and Management Automation and Orchestration (MANO).
[0077] The Basic Network Functions Virtualization (NFVI) architecture is similar to the mobile phone operating systems offered by various manufacturers. It provides hardware devices with basic components and supports the software or container management platforms required for network applications.
[0078] Virtual Network Functions (VNFs) are software applications that implement network functions (forwarding services, IP configuration, etc.), similar to apps on terminal devices. In the NFV architecture, various VNFs are implemented on top of NFVI. Because NFVI is a standardized architecture, different VNFs gain universality and no longer depend on the original black-box devices.
[0079] Management Automation and Network Orchestration (MANO) is a unified framework for managing various VNFs and NFVIs, facilitating service orchestration and device management for operations and maintenance personnel.
[0080] Compared to traditional physical network devices, the advantages of NFV are shown in Table 1 below:
[0081]
[0082]
[0083] Table 1
[0084] based on Figure 4In the application scenario shown, when a cloud tenant accesses the network, the tenant can connect its CPE device (or a private IDC data center mounted under the CPE) to the network closest to the user, such as a mobile network, specifically a 4G or 5G network. However, since the air interface network is carried over the public network, user data needs to be encrypted. Therefore, an IPsec tunnel can be used between the user CPE and the cloud access gateway. The encrypted tunnel passes directly through the operator's network to the cloud access gateway, making the tunnel invisible to the operator's public network and internal network links, thus maximizing the security of user data.
[0085] In some alternative embodiments, such as Figure 5 As shown, in a cloud provider's network, two (or more) dual-master access gateways are deployed for network reliability. Both gateways operate simultaneously, each handling a portion of the network traffic. If one gateway fails, the other can take over all service traffic without failover. The user's CPE can establish IPSec tunnels with both access gateways, and ECMP can be configured on the CPE to ensure equal-cost routing between the two IPSec tunnels.
[0086] In some alternative embodiments, in the connection between the cloud provider and the carrier network, the carrier typically provides a generic GRE tunnel for network encapsulation to differentiate its different users. One end of the GRE tunnel is the carrier's UPF, and the other end is the cloud provider's access GW. The GRE tunnel is used to carry IPsec tunnels established by the user's CPE.
[0087] Specifically, such as Figure 6 As shown, operators typically provide two or more UPFs (using two as an example below) for access. In this case, GRE tunnels can be established between the two UPFs and the two GWs through the gateway controller, with both tunnels using ECMP on their respective devices. This efficiently utilizes the forwarding capabilities of network devices and ensures high network reliability and stability even in abnormal situations.
[0088] In this scenario, the GRE tunnel is invisible to the user. The IPSEC tunnel established by the user's CPE will automatically be loaded onto the GRE tunnel when passing through the UPF, i.e., accessing the cloud gateway in the form of IPSEC over GRE.
[0089] In some optional embodiments, when user traffic reaches the access GW, it needs to pass through the NGW to reach the VPC. A VXLAN tunnel can be used between the access GW and the NGW. The VXLAN VNI (VXLAN Network Identifier) has 24 bits and can support over 16 million user accesses, far exceeding the 12 bits of a VLAN (Virtual Local Area Network). Therefore, VXLAN tunnels are well-suited for tenant segmentation when cloud providers access the network. Furthermore, since the network traffic has already entered the cloud provider's internal network, encrypted transmission is unnecessary. Therefore, IPsec tunneling can be decapsulated at the access GW, redirecting user traffic to the lighter VXLAN tunnel.
[0090] Specifically, such as Figure 7 As shown, cloud providers typically offer two or more access gateways (GWs) and next-generation network controllers (NGWs) (using two as an example below). In this case, the cloud controller can establish VXLAN tunnels between the two GWs and two NGWs, with each tunnel using ECMP on its respective device. This efficiently utilizes the forwarding capabilities of the network devices and ensures high network reliability and stability even in abnormal situations.
[0091] Based on the aforementioned system architecture and related configurations, this embodiment adopts the concept of control-control separation. That is, all configuration information is orchestrated and distributed through a cloud-based controller. The underlying network devices do not need to concern themselves with the services; they only need to provide standard control interfaces and configure the network according to the controller's orchestration instructions. A schematic processing flow is as follows: Figure 8 As shown, it includes the following steps:
[0092] S801, during initialization, the controller sends configuration information to the UPF and the access GW. Specifically, the controller connects the operator's UPF and the cloud provider's access GW, that is, it establishes a GRE tunnel between the UPF and the GW.
[0093] S802 allows users (i.e., cloud tenants) to configure the VPC network that their CPE wants to access via the cloud console when they need to use it.
[0094] The S803 controller sends configuration information to the access GW and NGW to configure a VXLAN tunnel between them, thereby establishing a connection between the access GW and NGW.
[0095] S804: The controller allocates dedicated IPSEC tunnel resources to the user and configures them on the CPE and access GW to establish a connection between the CPE and the access GW.
[0096] After completing the above configuration, users can access the cloud VPC via mobile network through CPE.
[0097] As can be seen, in the embodiments of this application, the user CPE can quickly and efficiently access the cloud VPC, fully utilizing the low latency and high bandwidth characteristics of 4G / 5G networks, replacing the reliance on traditional leased lines when accessing a dedicated gateway in related technologies. Simultaneously, in terms of network architecture, different network tunnels are configured between different nodes, and orchestration instructions are issued by the controller to ensure the security of network transmission. This also ensures the reliability of service data in the event of network device or link anomalies.
[0098] The following describes an apparatus embodiment of this application, which can be used to execute the access control method in the above embodiments of this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the access control method described above.
[0099] Figure 9 A block diagram of an access control device according to an embodiment of this application is shown. The access control device may be disposed within a controller, which may be... Figure 1 The controller 101 shown is shown.
[0100] Reference Figure 9 As shown, an access control device 900 according to an embodiment of this application includes: an acquisition unit 902 and a configuration unit 904.
[0101] The acquisition unit 902 is configured to acquire information about the private network requested by the network access party; the configuration unit 904 is configured to send first configuration information to the access gateway of the network provider and the network access party, instructing the network access party to establish a first transmission tunnel with the access gateway through a core network element, wherein the first transmission tunnel is used to transmit the traffic of the network access party to the access gateway; the configuration unit 904 is further configured to: send second configuration information to the access gateway and a forwarding device connected between the access gateway and the private network according to the information of the private network, instructing the access gateway to establish a second transmission tunnel with the forwarding device, wherein the second transmission tunnel is used to transmit the traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
[0102] In some embodiments of this application, based on the foregoing scheme, the configuration unit 904 is further configured to: send third configuration information to the access gateway and the core network element before sending the first configuration information to the access gateway of the network provider and the network access party, so as to instruct the core network element to establish a general routing encapsulation tunnel with the access gateway; wherein, the first transmission tunnel between the network access party and the access gateway is loaded onto the general routing encapsulation tunnel.
[0103] In some embodiments of this application, based on the foregoing scheme, the network provider deploys at least two access gateways; the configuration unit 904 sends third configuration information to the access gateways and the core network element to instruct the core network element to establish a general routing encapsulation tunnel with the access gateway, including:
[0104] Send third configuration information to the at least two access gateways and the at least two core network elements to instruct each core network element to establish the general routing encapsulation tunnel with the at least two access gateways, and to instruct that the general routing encapsulation tunnel established between each core network element and the at least two access gateways is an equivalent multipath route.
[0105] In some embodiments of this application, based on the foregoing scheme, the network provider deploys at least two access gateways; the process by which the configuration unit 904 sends first configuration information to the network provider's access gateway and the network access party to instruct the network access party to establish a first transmission tunnel with the access gateway through a core network element includes:
[0106] Send first configuration information to the network access party and the at least two access gateways to instruct the network access party to establish the first transmission tunnel with the at least two access gateways respectively, and to instruct the first transmission tunnel established between the network access party and the at least two access gateways to be an equal-cost multipath route.
[0107] In some embodiments of this application, based on the foregoing scheme, the network provider deploys at least two access gateways and at least two forwarding devices; the configuration unit 904 sends second configuration information to the access gateway and the forwarding device connected between the access gateway and the VPC to instruct the access gateway and the forwarding device to establish a second transmission tunnel, including:
[0108] Send second configuration information to the at least two access gateways and at least two forwarding devices to instruct each access gateway to establish the second transmission tunnel with the at least two forwarding devices, and to instruct the second transmission tunnel established by each access gateway with the at least two forwarding devices to be an equal-cost multipath route.
[0109] In some embodiments of this application, based on the foregoing scheme, the first transmission tunnel includes an Internet Security Protocol tunnel.
[0110] In some embodiments of this application, based on the foregoing scheme, the second transmission tunnel includes a virtual extended LAN tunnel, which is used to transmit the traffic after the access gateway decapsulates the Internet Security Protocol tunnel to the forwarding device.
[0111] Figure 10 A block diagram of an access control device according to an embodiment of this application is shown. The access control device can be disposed within an access gateway, which may be... Figure 1 The access gateway 104 shown is shown.
[0112] Reference Figure 10 As shown, an access control device 1000 according to an embodiment of this application includes: a receiving unit 1002 and an establishing unit 1004.
[0113] The receiving unit 1002 is configured to receive first configuration information sent by the controller, the first configuration information being used to instruct the network access party to establish a first transmission tunnel with the access gateway through a core network element; and to receive second configuration information sent by the controller, the second configuration information being used to instruct the access gateway to establish a second transmission tunnel with a forwarding device, the forwarding device being connected between the access gateway and the private network requested by the network access party; the establishing unit 1004 is configured to establish a first transmission tunnel between the access gateway and the network access party through the core network element according to the first configuration information, the first transmission tunnel being used to transmit the traffic of the network access party to the access gateway; and to establish a second transmission tunnel between the access gateway and the forwarding device according to the second configuration information, the second transmission tunnel being used to transmit the traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
[0114] In some embodiments of this application, based on the aforementioned scheme, the first transmission tunnel includes an Internet Security Protocol tunnel, and the second transmission tunnel includes a Virtual Extended Local Area Network (VLAN) tunnel; the access control device 1000 further includes: a processing unit configured to, after receiving traffic transmitted through the Internet Security Protocol tunnel, decapsulate the traffic transmitted through the Internet Security Protocol tunnel; and transmit the decapsulated traffic to the forwarding device through the VLAN tunnel.
[0115] In some embodiments of this application, based on the foregoing scheme, the receiving unit 1002 is further configured to: receive third configuration information sent by the controller before the first configuration information sent by the receiving controller, wherein the third configuration information is used to instruct the core network element to establish a general routing encapsulation tunnel with the access gateway;
[0116] The establishment unit 1004 is further configured to: establish a general routing encapsulation tunnel between the access gateway and the core network element according to the third configuration information, wherein the first transmission tunnel between the network access party and the access gateway is loaded onto the general routing encapsulation tunnel.
[0117] In some embodiments of this application, based on the foregoing scheme, when there are at least two core network elements, the establishment unit 1004 is configured to: establish a general routing encapsulation tunnel between the access gateway and at least two core network elements according to the third configuration information.
[0118] In some embodiments of this application, based on the aforementioned scheme, the network provider deploys at least two forwarding devices; the process by which the establishment unit 1004 establishes a second transmission tunnel between the access gateway and the forwarding devices according to the second configuration information includes: establishing a second transmission tunnel between the access gateway and the at least two forwarding devices respectively according to the second configuration information, and setting the second transmission tunnel established between the access gateway and the at least two forwarding devices as an equal-cost multipath routing method.
[0119] Figure 11 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown.
[0120] It should be noted that, Figure 11 The computer system 1100 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0121] like Figure 11As shown, the computer system 1100 includes a Central Processing Unit (CPU) 1101, which can perform various appropriate actions and processes based on programs stored in Read-Only Memory (ROM) 1102 or programs loaded from storage portion 1108 into Random Access Memory (RAM) 1103, such as performing the methods described in the above embodiments. Various programs and data required for system operation are also stored in RAM 1103. The CPU 1101, ROM 1102, and RAM 1103 are interconnected via bus 1104. An Input / Output (I / O) interface 1105 is also connected to bus 1104.
[0122] The following components are connected to I / O interface 1105: an input section 1106 including a keyboard, mouse, etc.; an output section 1107 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1108 including a hard disk, etc.; and a communication section 1109 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to I / O interface 1105 as needed. Removable media 1111, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1110 as needed so that computer programs read from them can be installed into storage section 1108 as needed.
[0123] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1109, and / or installed from removable medium 1111. When the computer program is executed by central processing unit (CPU) 1101, it performs various functions defined in the system of this application.
[0124] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. The transmitted data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0125] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and a computer program.
[0126] The units described in the embodiments of this application can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.
[0127] In another aspect, this application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable medium carries one or more computer programs, which, when executed by the electronic device, cause the electronic device to perform the methods described in the above embodiments.
[0128] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0129] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, touch terminal, or network device, etc.) to execute the method according to the embodiments of this application.
[0130] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.
[0131] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. An access control method, characterized in that, The access control method is executed by the controller, and the access control method includes: Receive information from the network access direction sent by the controller requesting access to the private network; Send first configuration information to the network provider's access gateway and the network access party to instruct the network access party to establish a first transmission tunnel with the access gateway through a core network element. The first transmission tunnel is used to transmit the network access party's traffic to the access gateway. A general routing encapsulation tunnel is established between the core network element and the access gateway, and the first transmission tunnel is loaded onto the general routing encapsulation tunnel. Based on the information of the private network requested by the network access party, second configuration information is sent to the access gateway and the forwarding device connected between the access gateway and the private network to instruct the access gateway to establish a second transmission tunnel with the forwarding device. The second transmission tunnel is used to transmit the traffic of the network access party to the forwarding device so that the forwarding device routes the traffic of the network access party to the private network.
2. The access control method according to claim 1, characterized in that, Before sending the first configuration information to the network provider's access gateway and the network access party, the method further includes: Send third configuration information to the access gateway and the core network element to instruct the core network element to establish the general routing encapsulation tunnel with the access gateway.
3. The access control method according to claim 2, characterized in that, The network provider deploys at least two access gateways; the step of sending third configuration information to the access gateways and the core network element to instruct the core network element to establish a general routing encapsulation tunnel with the access gateway includes: Send third configuration information to the at least two access gateways and the at least two core network elements to instruct each core network element to establish the general routing encapsulation tunnel with the at least two access gateways, and to instruct that the general routing encapsulation tunnel established between each core network element and the at least two access gateways is an equivalent multipath route.
4. The access control method according to claim 1, characterized in that, The network provider deploys at least two access gateways; sending first configuration information to the network provider's access gateways and the network access party to instruct the network access party to establish a first transmission tunnel with the access gateways through core network elements includes: Send first configuration information to the network access party and the at least two access gateways to instruct the network access party to establish the first transmission tunnel with the at least two access gateways respectively, and to instruct the first transmission tunnel established between the network access party and the at least two access gateways to be an equal-cost multipath route.
5. The access control method according to claim 1, characterized in that, The network provider deploys at least two access gateways and at least two forwarding devices; sending second configuration information to the access gateways and the forwarding devices connected between the access gateways and the VPC to instruct the access gateways to establish a second transmission tunnel with the forwarding devices includes: Send second configuration information to the at least two access gateways and at least two forwarding devices to instruct each access gateway to establish the second transmission tunnel with the at least two forwarding devices, and to instruct the second transmission tunnel established by each access gateway with the at least two forwarding devices to be an equal-cost multipath route.
6. The access control method according to any one of claims 1 to 5, characterized in that, The first transmission tunnel includes an Internet Security Protocol tunnel.
7. The access control method according to claim 6, characterized in that, The second transmission tunnel includes a virtual extended LAN tunnel, which is used to transmit the traffic after the access gateway decapsulates the Internet security protocol tunnel to the forwarding device.
8. An access control method, characterized in that, The access control method is executed by the network provider's access gateway, and the access control method includes: The receiver receives first configuration information sent by the controller. The first configuration information is used to instruct the network access party to establish a first transmission tunnel with the access gateway through the core network element. A general routing encapsulation tunnel is established between the core network element and the access gateway, and the first transmission tunnel is loaded onto the general routing encapsulation tunnel. Based on the first configuration information, a first transmission tunnel is established between the access gateway and the network access party through the core network element. The first transmission tunnel is used to transmit the traffic of the network access party to the access gateway. The controller sends second configuration information, which instructs the access gateway to establish a second transmission tunnel with the forwarding device. The forwarding device is connected between the access gateway and the private network that the network access party requests to access. A second transmission tunnel is established between the access gateway and the forwarding device according to the second configuration information. The second transmission tunnel is used to transmit the traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
9. The access control method according to claim 8, characterized in that, The first transmission tunnel includes an Internet Security Protocol tunnel, and the second transmission tunnel includes a Virtual Extended Local Area Network (VLAN) tunnel. The method further includes: Upon receiving the traffic transmitted via the Internet Security Protocol tunnel, the traffic transmitted via the Internet Security Protocol tunnel is decapsulated. The decapsulated traffic is transmitted to the forwarding device through the virtual extended LAN tunnel.
10. The access control method according to claim 8, characterized in that, Before receiving the first configuration information sent by the receiver controller, the method further includes: The controller sends third configuration information, which is used to instruct the core network element to establish a general routing encapsulation tunnel with the access gateway. A general routing encapsulation tunnel is established between the access gateway and the core network element according to the third configuration information, wherein the first transmission tunnel between the network access party and the access gateway is loaded onto the general routing encapsulation tunnel.
11. The access control method according to claim 10, characterized in that, In the presence of at least two core network elements, a general routing encapsulation tunnel is established between the access gateway and the core network element based on the third configuration information, including: Based on the third configuration information, establish general routing encapsulation tunnels between the access gateway and at least two core network elements.
12. The access control method according to any one of claims 8 to 11, characterized in that, The network provider has deployed at least two forwarding devices; Establishing a second transmission tunnel between the access gateway and the forwarding device based on the second configuration information includes: Based on the second configuration information, a second transmission tunnel is established between the access gateway and the at least two forwarding devices, and the second transmission tunnel established between the access gateway and the at least two forwarding devices is configured as an equal-cost multipath routing method.
13. An access control device, characterized in that, The access control device is applied to the controller, and the access control device includes: The acquisition unit is configured to receive information about a private network request sent by the network access direction to the controller. The configuration unit is configured to send first configuration information to the access gateway of the network provider and the network access party, instructing the network access party to establish a first transmission tunnel with the access gateway through a core network element. The first transmission tunnel is used to transmit the traffic of the network access party to the access gateway. A general routing encapsulation tunnel is established between the core network element and the access gateway, and the first transmission tunnel is loaded onto the general routing encapsulation tunnel. The configuration unit is further configured to: send second configuration information to the access gateway and the forwarding device connected between the access gateway and the private network according to the information of the private network requested by the network access party, so as to instruct the access gateway and the forwarding device to establish a second transmission tunnel, the second transmission tunnel being used to transmit the traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
14. An access control device, characterized in that, The access control device is applied to the access gateway of the network provider, and the access control device includes: The receiving unit is configured to receive first configuration information sent by the controller, the first configuration information being used to instruct the network access party to establish a first transmission tunnel with the access gateway through a core network element; and to receive second configuration information sent by the controller, the second configuration information being used to instruct the access gateway to establish a second transmission tunnel with a forwarding device, the forwarding device being connected between the access gateway and the private network requested for access by the network access party; wherein a general routing encapsulation tunnel is established between the core network element and the access gateway, and the first transmission tunnel is load-balanced onto the general routing encapsulation tunnel; The establishment unit is configured to establish a first transmission tunnel between the access gateway and the network access party through the core network element according to the first configuration information, wherein the first transmission tunnel is used to transmit the traffic of the network access party to the access gateway; and to establish a second transmission tunnel between the access gateway and the forwarding device according to the second configuration information, wherein the second transmission tunnel is used to transmit the traffic of the network access party to the forwarding device, so that the forwarding device routes the traffic of the network access party to the private network.
15. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the access control method as described in any one of claims 1 to 12.
16. An electronic device, characterized in that, include: One or more processors; A memory for storing one or more computer programs that, when executed by one or more processors, cause the electronic device to implement the access control method as described in any one of claims 1 to 12.
17. A computer program product, characterized in that, The computer program product includes a computer program stored in a computer-readable storage medium, wherein a processor of an electronic device reads from and executes the computer program, causing the electronic device to perform the access control method as described in any one of claims 1 to 12.
Citation Information
Patent Citations
Private network access method, device and system
CN102186168A
Data message transmission method, device and system
CN110061899A
SD-WAN network architecture, networking method and message forwarding method
CN110290093A
Route generation method, route processing method and device
CN113872843A