A disaster recovery fast failover system

By generating an internal network IP pass-through request on the disaster recovery management platform in the headquarters data center, and using the DN-AAA module and dedicated UPF to achieve internal network IP pass-through, the problem of low reliability of 5G private network disaster recovery lines is solved, and the stability and security of network connections are improved.

CN118748647BActive Publication Date: 2025-11-25CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411139665.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-19
Publication Date
2025-11-25
Estimated Expiration
2044-08-19

AI Technical Summary

Technical Problem

In existing technologies, the reliability of 5G private network disaster recovery lines is reduced, mainly because the CPE and optical modem cascade connection scheme is prone to CPE single-unit failure, and the terminal inter-access function of the virtual private network service platform or UPF does not support cross-province implementation.

Method used

By generating an intranet IP pass-through request on the disaster recovery management platform in the headquarters data center, using the DN-AAA module to obtain the network information of the intranet terminal, generating a Radius message and sending it to the dedicated UPF, the routing function of the dedicated UPF is enabled to identify the address information of the intranet terminal and send it to the 5G private network, thereby realizing the intranet IP pass-through.

Benefits of technology

It improves the reliability of 5G private network disaster recovery lines, ensuring that internal network terminals can access the 5G private network without changing their IP addresses, thus enhancing the stability and security of network connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118748647B_ABST
    Figure CN118748647B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of disaster recovery solid migration switching system, the system includes: headquarters data center and branch, through the internal network IP transparent request of disaster recovery management platform generation, DN-AAA module obtains the network information of multiple internal network terminals according to internal network IP transparent request, generates Radius message, Radius message is sent to exclusive UPF, exclusive UPF enables post-routing function according to Radius message, identifies the address information of internal network terminal, and the address information of internal network terminal is sent to 5G special network, realizes internal network IP transparent, improve the reliability of 5G special network disaster recovery line.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network communication, and in particular to a disaster recovery fixed migration switching system. BACKGROUND

[0002] For large and medium-sized chain enterprises with headquarters-branches, multiple data centers are usually set up in multiple places, which are divided into first-level data centers, second-level data centers and multiple points according to the importance level of the data centers. In order to deal with sudden failures, enterprises use 5G private network as a solution for dedicated line disaster recovery line. For the disaster recovery scheme of 5G private network, the problems of enterprise intranet IP transparent transmission and fixed migration switching need to be considered.

[0003] In the prior art, the three-layer interconnection between the end branch and the data center is realized based on the virtual private network service platform or the UPF terminal intercommunication, and the problem of enterprise intranet IP transparent transmission is solved. The CPE and the optical modem are connected in series to form a mixed link of 5G and dedicated line to solve the problem of fixed migration switching.

[0004] However, in the prior art, the scheme of connecting CPE and optical modem in series is prone to CPE single failure, and the terminal intercommunication function based on the virtual private network service platform or UPF does not support cross-province implementation, resulting in reduced reliability of 5G private network disaster recovery line. SUMMARY

[0005] The embodiments of the present application provide a disaster recovery fixed migration switching system to solve the problem of reduced reliability of 5G private network disaster recovery line in the prior art.

[0006] In a first aspect, the embodiments of the present application provide a disaster recovery fixed migration switching system, comprising: a headquarters data center and a branch;

[0007] The headquarters data center comprises a disaster recovery management platform and a dedicated UPF.

[0008] The disaster recovery management platform comprises a DN-AAA module.

[0009] The branch comprises a plurality of intranet terminals.

[0010] The disaster recovery management platform generates an intranet IP transparent transmission request, wherein the intranet IP transparent transmission request is generated after the plurality of intranet terminals are authenticated by the disaster recovery management platform.

[0011] The DN-AAA module obtains network information of the plurality of intranet terminals according to the intranet IP transparent transmission request, generates a Radius message according to the network information of the plurality of intranet terminals, and sends the Radius message to the dedicated UPF.

[0012] The exclusive UPF enables a post-routing function according to the Radius message, and identifies address information of the multiple intranet terminals according to the post-routing function;

[0013] The exclusive UPF sends the address information of the multiple intranet terminals to a 5G private network to realize intranet IP transparent transmission.

[0014] In a possible implementation, the disaster recovery fixed migration switching system further comprises an operator core network; before the disaster recovery management platform initiates the intranet IP transparent transmission request, the multiple intranet terminals further send a network connection request to the operator core network; the operator core network enables secondary authentication according to the network connection request, generates a Radius message, and sends the Radius message to the exclusive UPF; the exclusive UPF sends the Radius message to the DN-AAA module; the DN-AAA module performs secondary authentication on the multiple intranet terminals according to the Radius message; and if the secondary authentication is passed, the network connection of the multiple intranet terminals accessing the enterprise intranet is established.

[0015] In a possible implementation, the disaster recovery fixed migration switching system further comprises a secondary data center; the branch office further comprises a CPE device; the disaster recovery management platform further comprises a CPE management module; after the exclusive UPF sends the address information of the multiple intranet terminals to the 5G private network to realize intranet IP transparent transmission, the CPE management module further acquires parameter information of the CPE device, generates an execution script according to the parameter information, authenticates the CPE device according to a fixed migration switching strategy, generates a calling authority of the CPE device according to the CPE management module if the CPE device authentication is passed, and runs the execution script according to the calling authority of the CPE device to activate a communication interface of the CPE device to realize 5G connection when the secondary data center fails, or runs the execution script according to the calling authority of the CPE device to close the communication interface of the CPE device to realize dedicated line connection when the secondary data center is repaired.

[0016] In a possible implementation, the branch office further comprises a branch router and an optical modem; the multiple intranet terminals are in communication connection with the branch router, the branch router is connected in parallel with the optical modem, and the branch router is connected in parallel with the CPE device.

[0017] In a possible implementation, the CPE device internally deploys a network card, and the network card performs communication transmission with the exclusive UPF according to intranet identification.

[0018] In a possible implementation, the CPE management module has three working modes, and device information of the CPE device is acquired according to different working modes.

[0019] In a possible implementation, the operator core network further includes a session management module, the session management module is configured to receive a network connection request sent by the plurality of intranet terminals, and the session management module is configured to send the network connection request to the dedicated UPF.

[0020] In a possible implementation, the disaster recovery management platform further includes a shared database, and the shared database is configured to store the device information of the CPE device acquired by the CPE management module.

[0021] In a possible implementation, the headquarters data center further includes a network management platform, the network management platform is in communication connection with the disaster recovery management platform, and the network management platform internally stores the failover strategy.

[0022] In a possible implementation, the headquarters data center further includes a headquarters router and a switch, the dedicated UPF is in communication connection with the headquarters router, the headquarters router is in communication connection with the disaster recovery management platform and the switch respectively, and the switch is in communication connection with the network management platform.

[0023] The disaster recovery failover switching system provided by the embodiment of the present application generates an intranet IP transparent transmission request through a disaster recovery management platform, a DN-AAA module acquires network information of a plurality of intranet terminals according to the intranet IP transparent transmission request, generates a Radius message, sends the Radius message to a dedicated UPF, the dedicated UPF enables a post-routing function according to the Radius message, identifies address information of the intranet terminal, and sends the address information of the intranet terminal to a 5G private network, thereby realizing intranet IP transparent transmission and improving the reliability of a 5G private network disaster recovery line. BRIEF DESCRIPTION OF DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0025] Figure 1 The structure diagram of the disaster recovery failover switching system provided by the present application is shown in the figure;

[0026] Figure 2 The structure diagram of the intranet terminal management provided by the embodiment of the present application is shown in the figure;

[0027] Figure 3 A structure schematic diagram of the disaster recovery management platform provided by the embodiment of the present application is provided.

[0028] Figure 4 A structure schematic diagram of the improved fixed migration switching method provided by the embodiment of the present application is provided.

[0029] Reference signs:

[0030] 100: headquarters data center;

[0031] 101: disaster recovery management platform;

[0032] 102: exclusive UPF;

[0033] 103: headquarters router;

[0034] 104: switch;

[0035] 105: network management platform;

[0036] 106: DN-AAA module;

[0037] 107: CPE management module;

[0038] 108: shared database;

[0039] 200: branch;

[0040] 201: multiple intranet terminals;

[0041] 202: branch router;

[0042] 203: optical modem;

[0043] 204: CPE device;

[0044] 300: operator core network;

[0045] 301: session management module;

[0046] 400: secondary data center;

[0047] 401: router. DETAILED DESCRIPTION

[0048] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0049] For large and medium-sized chain enterprises with headquarters-branch, multiple data centers are usually set up in multiple places, which are divided into first-level data centers, second-level data centers and multiple points according to the importance level of data centers. In order to deal with sudden failures, enterprises adopt 5G private network as a solution of dedicated line disaster recovery line. For the disaster recovery scheme of 5G private network, the problems of enterprise intranet IP transparent transmission and fixed mobile switching need to be considered. In the prior art, the three-layer interconnection between the end branch and the data center is realized based on the virtual private network service platform or the UPF terminal intercommunication, and the problem of enterprise intranet IP transparent transmission is solved. The CPE and the optical modem are connected in series to form a hybrid link of 5G and dedicated line to solve the problem of fixed mobile switching. However, in the prior art, the scheme of connecting CPE and optical modem in series is easy to cause CPE single fault, and the terminal intercommunication function based on virtual private network service platform or UPF does not support cross-province implementation, resulting in reduced reliability of 5G private network disaster recovery line.

[0050] To solve the above technical problems, the embodiments of the present application propose the following technical concept: the inventor considers creating a disaster recovery management platform to manage the intranet terminals of branch offices. After the intranet terminals are authenticated by the disaster recovery management platform, the disaster recovery management platform generates an intranet IP transparent transmission request, obtains network information of the intranet terminals through a DN-AAA module, generates a Radius message, and sends it to a dedicated UPF. The dedicated UPF enables the post-routing function according to the Radius message, identifies the address information of the intranet terminals, and sends the address information of the intranet terminals to the 5G private network, thereby realizing intranet IP transparent transmission and improving the reliability of the 5G private network disaster recovery line. The following detailed embodiments are described in detail.

[0051] First, the terms involved in the present application are explained:

[0052] Dedicated UPF: refers to User Plane Function (UPF), which is a key component in the core network architecture. UPF is responsible for processing user data traffic, performing data packet forwarding, routing and quality control functions.

[0053] DN-AAA: is the abbreviation of Data Network Authentication, Authorization, and Accounting. Through DN-AAA, the network can ensure that only authenticated users can access the network, and allocate resources and access control according to the user's permissions.

[0054] Radius: refers to Remote Authentication Dial-In User Service (Radius for short), which is a network protocol used for identity verification and authorization when remote users access enterprise network resources.

[0055] Figure 1 A structural diagram of a disaster recovery and solid migration switching system provided in the present application is shown in FIG. 1. Figure 1 As shown in the figure, the disaster recovery and solid migration switching system specifically includes a headquarters data center 100 and a branch 200.

[0056] The headquarters data center 100 includes a disaster recovery management platform 101 and a dedicated UPF 102.

[0057] The disaster recovery management platform includes a DN-AAA module 103.

[0058] The branch includes a plurality of intranet terminals 201.

[0059] The disaster recovery management platform generates an intranet IP transparent transmission request, wherein the intranet IP transparent transmission request is generated after the plurality of intranet terminals are authenticated by the disaster recovery management platform.

[0060] In the present embodiment, the disaster recovery management platform further includes a CPE management module 107.

[0061] In the present embodiment, the branch further includes a CPE device.

[0062] In the present embodiment, the disaster recovery management platform further includes a shared database 108.

[0063] The shared database is used to store device information of the CPE device obtained by the CPE management module.

[0064] In the present embodiment, the device information of the plurality of intranet terminals hung under the CPE device is obtained through a northbound interface of the CPE management module.

[0065] The device information includes but is not limited to device name, device online state, IP address and MAC address.

[0066] In the present embodiment, the branch further includes a branch router 202 and an optical modem 203.

[0067] The plurality of intranet terminals are in communication connection with the branch router, the branch router is connected in parallel with the optical modem, and the branch router is connected in parallel with the CPE device.

[0068] In the present embodiment, the optical modem is an optical network unit (ONU for short).

[0069] In the embodiment, the connection mode of the existing optical cat and CPE device is changed from series connection to parallel connection.

[0070] In the embodiment, the headquarters data center further comprises a network management platform 105.

[0071] The network management platform is in communication connection with the disaster recovery management platform.

[0072] In the embodiment, the network management platform and the disaster recovery management platform are in communication connection through wired or wireless communication.

[0073] The network management platform internally stores a fixed migration switching strategy.

[0074] In the embodiment, the fixed migration switching strategy is a switching strategy of switching the dedicated line to a 5G backup line.

[0075] In the embodiment, the headquarters data center further comprises a headquarters router 103 and a switch 104.

[0076] The dedicated UPF is in communication connection with the headquarters router.

[0077] In the embodiment, the dedicated UPF is connected with the headquarters router through wired communication.

[0078] The headquarters router is in communication connection with the disaster recovery management platform and the switch respectively.

[0079] In the embodiment, the headquarters router is connected with the DN-AAA module in the disaster recovery management platform through wired communication.

[0080] In the embodiment, the headquarters router is connected with the switch through wired communication.

[0081] The switch is in communication connection with the network management platform.

[0082] In the embodiment, the switch is connected with the network management platform through wired communication.

[0083] Specifically, the intranet terminal sends the intranet request information to the CPE device through the headquarters router, the CPE device sends the intranet request information to the session management module of the operator core network, the session management module sends the intranet request information to the dedicated UPF of the headquarters data center, the dedicated UPF sends the intranet request information to the headquarters router of the headquarters data center, and the headquarters router of the headquarters data center sends the intranet request information to the DN-AAA module of the disaster recovery management platform. The DN-AAA module authenticates the CPE device, and generates an intranet IP transparent transmission request after the authentication is passed.

[0084] The DN-AAA module obtains network information of the plurality of intranet terminals according to the intranet IP transparent transmission request, generates a Radius message according to the network information of the plurality of intranet terminals, and sends the Radius message to the dedicated UPF.

[0085] In the embodiment, the network information of the intranet terminal includes but is not limited to IP address information, routing segment information and MAC address information.

[0086] The dedicated UPF enables the post-routing function according to the Radius message, and identifies address information of the plurality of intranet terminals according to the post-routing function.

[0087] In the embodiment, the dedicated UPF reads the network information of the plurality of intranet terminals recorded in the Radius message through the post-routing function, and identifies the IP address information of the plurality of intranet terminals.

[0088] The dedicated UPF sends the address information of the plurality of intranet terminals to the 5G private network to realize intranet IP transparent transmission.

[0089] Specifically, the dedicated UPF sends the IP address information of the plurality of intranet terminals to the 5G private network, and the 5G private network creates a 5G network channel according to the IP address information of the intranet terminal, so as to realize access of the intranet terminal to the 5G private network without changing the IP address of the intranet terminal.

[0090] Reference Figure 2 , Figure 2 The structure diagram of the intranet terminal management provided by the embodiment of the application is shown.

[0091] As shown in Figure 2 , the plurality of intranet terminals 201 in the branch office 200 send a network connection request to the branch router 202, the branch router 202 sends the network connection request to the CPE device 204, the CPE device 204 sends the network connection request to the session management module 301 of the operator core network 300, the session management module 301 enables secondary authentication according to the network connection request, generates a Radius message, sends the Radius message to the dedicated UPF 102 of the headquarters data center 100, the dedicated UPF 102 sends the Radius message to the DN-AAA module 106 of the disaster recovery management platform 101 through the headquarters router 103, the DN-AAA module 106 performs secondary authentication operation, and after the authentication is passed, the plurality of intranet terminals 201 under the CPE device 204 access the intranet are established.

[0092] From the above embodiment, it can be seen that the in-network IP transparent transmission request is generated through the disaster management platform, the network information of the plurality of in-network terminals is obtained by the DN-AAA module according to the in-network IP transparent transmission request, the Radius message is generated, the Radius message is sent to the dedicated UPF, the post-routing function is enabled by the dedicated UPF according to the Radius message, the address information of the in-network terminal is identified, the address information of the in-network terminal is sent to the 5G private network, the in-network IP transparent transmission is realized, and the reliability of the 5G private network disaster recovery line is improved.

[0093] In an embodiment of the present application, the disaster recovery migration switching system further comprises an operator core network, and before the disaster management platform initiates the in-network IP transparent transmission request, the disaster recovery migration switching system further comprises:

[0094] The plurality of in-network terminals send the network connection request to the operator core network.

[0095] In the embodiment, the plurality of in-network terminals send the network connection request to the session management module of the operator core network through the CPE device.

[0096] The operator core network enables secondary authentication according to the network connection request, generates a Radius message, and sends the Radius message to the dedicated UPF.

[0097] Specifically, the session management module of the operator core network enables secondary authentication according to the network connection request, sends an authentication request to the Radius server, the Radius server authenticates the plurality of in-network terminals according to the authentication request, if the authentication is successful, generates a Radius message, sends the Radius message to the session management module, and the session management module sends the Radius message to the dedicated UPF.

[0098] In the embodiment, the operator core network further comprises a session management module.

[0099] The session management module is configured to receive the network connection request sent by the plurality of in-network terminals, and the session management module is configured to send the network connection request to the dedicated UPF.

[0100] In the embodiment, the operator core network further comprises a unified data management (UDM) module and an access and mobility management (AMF) module.

[0101] The dedicated UPF sends the Radius message to the DN-AAA module.

[0102] Specifically, the dedicated UPF sends the Radius message to the DN-AAA module in a wireless communication manner.

[0103] The DN-AAA module performs secondary authentication on the multiple intranet terminals according to the Radius message.

[0104] Specifically, the DN-AAA module sends the Radius message to the Radius server to perform secondary authentication on the multiple intranet terminals, and if the authentication is passed, the Radius server generates and returns authentication success information.

[0105] If the secondary authentication is passed, the network connection of the multiple intranet terminals accessing the enterprise intranet is established.

[0106] From the above embodiment, it can be known that the network connection request sent by the multiple intranet terminals is received by the session management module, the Radius message is generated, and the DN-AAA module is used to perform secondary authentication on the intranet terminals according to the Radius message, and if the authentication is passed, the multiple intranet terminals are allowed to access the intranet, and the security of the intranet access is improved.

[0107] In an embodiment of the present application, the disaster recovery fixed migration switching system further comprises: a secondary data center; the branch office further comprises: a CPE device; the disaster recovery management platform further comprises a CPE management module; the exclusive UPF sends address information of the multiple intranet terminals to the 5G private network to realize intranet IP transparent transmission, and further comprises:

[0108] The CPE management module acquires parameter information of the CPE device, and generates an execution script according to the parameter information.

[0109] In the embodiment, the parameter information of the CPE device includes but is not limited to a hanging device static IP, a hanging device port, a LAN port start-stop, and a NAT enablement.

[0110] In the embodiment, the southbound interface of the CPE management module collects parameters of different CPE devices to generate an automatic execution script.

[0111] Reference Figure 3 , Figure 3 A structure schematic diagram of the disaster recovery management platform provided in the embodiment of the present application is shown.

[0112] As shown in Figure 3 , the disaster recovery management platform comprises a DN-AAA module and a CPE management module.

[0113] The DN-AAA module interacts with the exclusive UPF through Radius messages, including secondary authentication, IP address allocation, and post-routing functions. The DN-AAA module interacts with the CPE management module to obtain the routing segment information of the intranet terminal hung under the CPE through a shared database or an API interface. The DN-AAA module interacts with the network management platform to generate an automated execution script by configuring the static IP of the CPE hung device and the port of the hung device, and a worker executes the automated script to manually configure the static IP of the CPE hung device and the routing segment.

[0114] The CPE management module interacts with the CPE device to collect CPE device information through SNMP, TR069, Syslog, and other protocols, and to monitor the CPE device status and 5G link quality in real time. The CPE management module interacts with the DN-AAA module to obtain the routing segment information of the CPE hung device through a shared database or an API interface. The CPE management module interacts with the network management platform to enable or disable the 5G backup network of all branch offices.

[0115] In this embodiment, the CPE device internally deploys a network card, and the network card communicates and transmits data with the exclusive UPF according to the intranet identifier.

[0116] The internal network card is pre-signed with an enterprise intranet dedicated DNN in the card by a worker, and points to the N4 port address of the exclusive UPF.

[0117] In this embodiment, the CPE management module has three working modes to obtain device information of the CPE device according to different working modes.

[0118] In this embodiment, the three working modes of the CPE management module include an active reporting mode, a login background mode, and a login front-end mode.

[0119] The active reporting mode is that the CPE device actively reports device information to the CPE management module of the disaster recovery management platform through TR069 or MQTT and other protocols. The active reporting mode is suitable for CPE devices that cannot open the background and / or block the front-end uplink interface.

[0120] The login background mode is that the CPE device opens the management background permission of the CPE management module of the disaster recovery management platform. The CPE management module of the disaster recovery management platform collects relevant information through the SNMP protocol. The login background mode is suitable for router-type CPE devices that support 5G modules.

[0121] The login front-end mode is that the CPE management module of the disaster recovery management platform remotely logs in the CPE Web management page through an SSH command, and collects device information through a crawler technology, and is suitable for CPE devices that cannot open a background and / or only support non-standard and private protocols.

[0122] The CPE management module authenticates the CPE device according to the fixed-migration switching strategy, and if the CPE device passes the authentication, generates the calling authority of the CPE device according to the CPE management module.

[0123] Specifically, if the authentication passes, the CPE management module executes an automatic execution script on the CPE device according to the fixed-migration switching strategy, and realizes the unified enabling or disabling of the LAN port of the CPE device.

[0124] For example, the CPE management module remotely logs in the CPE management background through SSH or Telnet, and batch issues CPE LAN port enabling and disabling commands.

[0125] For example, the CPE management module logs in the CPE Web management page through the CPE WAN port, and simulates the front-end page to batch click the LAN port enabling and disabling buttons.

[0126] In this embodiment, the disaster recovery management platform is connected with the network management platform, a staff member logs in the network management platform, sets the default link priority of the 5G backup line to the highest, sets the link priority of the dedicated line access mode to the lowest, generates a fixed-migration switching strategy, screens the CPE devices of branch organizations from a shared database, and remotely executes a LAN port automatic configuration script, to realize the activation and deactivation operations of the LAN ports of the CPE devices of the branch organizations.

[0127] When the secondary data center fails, the CPE management module runs an execution script according to the calling authority of the CPE device, to activate the communication interface of the CPE device, and realizes 5G connection.

[0128] In this embodiment, the secondary data center 400 further includes a router 401.

[0129] Specifically, when the secondary data center fails, a staff member logs in the disaster recovery management platform, screens all CPE devices of branch organizations from a shared database, and remotely executes a LAN port “enable” automatic configuration script, to realize the activation operation of the CPE LAN ports of all branch organizations. Since the default link priority of the 5G backup line in the fixed-migration strategy is the highest, the network service is switched from the dedicated line to the 5G backup line.

[0130] When the secondary data center is repaired, the CPE management module runs an execution script according to the calling authority of the CPE device, to close the communication interface of the CPE device, and realizes dedicated line connection.

[0131] Specifically, when the secondary data center is repaired, the staff logs in the disaster recovery management platform, filters all branch CPE devices from the shared database, remotely executes the LAN port "deactivation" automation configuration script, thereby realizing the deactivation operation of the CPE LAN port of all branches. At this time, the 5G backup line is restored to the standby state, and the service is switched to be borne by the dedicated line.

[0132] Reference Figure 4 , Figure 4 The improved solid migration switching method provided by the embodiment of the application is shown in a structural schematic diagram.

[0133] As Figure 4 shown, when the secondary data center fails, the branch needs to switch the 5G backup line, the staff calls the CPE management module of the disaster recovery management platform through the network management platform of the headquarters data center, executes the automation configuration script through the CPE management module, calls each CPE device in the branch, switches the 5G backup line of the CPE device, and realizes network connection; when the secondary data center is repaired, the staff calls the CPE management module of the disaster recovery management platform through the network management platform, executes the automation configuration script through the CPE management module, calls each CPE device in the branch, and switches to the dedicated line communication line.

[0134] From the above embodiment, it can be known that the information of the CPE device is obtained through the CPE management module, the 5G backup link priority is set to the highest, the dedicated line link priority is set to the lowest, the LAN port of the CPE device is remotely activated through the CPE management module when the secondary data center fails, the 5G backup line is switched according to the solid migration strategy, the LAN port of the CPE device is remotely deactivated through the CPE management module when the secondary data center is repaired, and the dedicated line is switched according to the solid migration switching strategy. Compared with the prior art, the false judgment probability caused by the threshold value of network quality in the prior art is reduced, the workload and misconfiguration probability of the staff in configuring different link priorities are simplified, and the reliability of the 5G private network disaster recovery line is improved.

[0135] Finally, it should be noted that: other embodiments of the application will be easily conceived by those skilled in the art after considering the specification and practicing the application disclosed herein. The application is intended to cover any variations, uses or adaptations of the application that follow the general principles of the application and include known or customary technical means in the art that are not disclosed in the application, and is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the application is only limited by the appended claims.

Claims

1. A disaster recovery failover switching system, comprising: The application relates to a disaster recovery and migration switching system. The system comprises: a headquarters data center and a branch office; wherein the headquarters data center comprises a disaster recovery management platform and a dedicated UPF; wherein the disaster recovery management platform comprises a DN-AAA module; wherein the branch office comprises a plurality of intranet terminals; the disaster recovery management platform generates an intranet IP transmission request, wherein the intranet IP transmission request is generated after the plurality of intranet terminals are authenticated by the disaster recovery management platform; the DN-AAA module acquires network information of the plurality of intranet terminals according to the intranet IP transmission request, generates a Radius message according to the network information of the plurality of intranet terminals, and sends the Radius message to the dedicated UPF; the dedicated UPF enables a post-routing function according to the Radius message, and identifies address information of the plurality of intranet terminals according to the post-routing function; 2. The failover switching system of claim 1, wherein, the dedicated UPF sends the address information of the plurality of intranet terminals to a 5G private network to realize intranet IP transmission. The disaster recovery and migration switching system further comprises an operator core network. Before the disaster recovery management platform initiates the intranet IP transmission request, the system further comprises: the plurality of intranet terminals send a network connection request to the operator core network; the operator core network enables secondary authentication according to the network connection request, generates a Radius message, and sends the Radius message to the dedicated UPF; the dedicated UPF sends the Radius message to the DN-AAA module; the DN-AAA module performs secondary authentication on the plurality of intranet terminals according to the Radius message; 3. The failover switching system of claim 1, wherein, if the secondary authentication is passed, the network connection of the plurality of intranet terminals accessing the enterprise intranet is established. The disaster recovery and migration switching system further comprises a secondary data center. The branch office further comprises a CPE device. The disaster recovery management platform further comprises a CPE management module. After the dedicated UPF sends the address information of the plurality of intranet terminals to the 5G private network to realize intranet IP transmission, the system further comprises: the CPE management module acquires parameter information of the CPE device, and generates an execution script according to the parameter information; the CPE management module authenticates the CPE device according to a migration switching strategy, and if the CPE device is authenticated, generates a calling permission of the CPE device according to the CPE management module; when the secondary data center fails, the CPE management module runs the execution script according to the calling permission of the CPE device to activate a communication interface of the CPE device and realize 5G connection; 4. The failover switching system of claim 3, wherein, when the secondary data center is repaired, the CPE management module runs the execution script according to the calling permission of the CPE device to close the communication interface of the CPE device and realize dedicated line connection. The branch office further comprises a branch router and an optical modem. The plurality of intranet terminals are in communication connection with the branch router, the branch router is in parallel connection with the optical modem, and the branch router is in parallel connection with the CPE device.

5. The failover switching system of claim 3, wherein, The CPE device is internally deployed with a network card, which communicates with the exclusive UPF according to an intranet identifier.

6. The failover switching system of claim 3, wherein, The CPE management module is provided with three working modes, and device information of the CPE device is acquired according to different working modes.

7. The failover switching system of claim 2, wherein, The operator core network further comprises a session management module. The session management module is configured to receive network connection requests sent by the plurality of intranet terminals, and send the network connection requests to the exclusive UPF.

8. The failover switching system of claim 3, wherein, The disaster recovery management platform further comprises a shared database. The shared database is configured to store the device information of the CPE device acquired by the CPE management module.

9. The failover switching system of claim 1, wherein, The headquarters data center further comprises a network management platform. The network management platform is in communication connection with the disaster recovery management platform. The network management platform internally stores a switchover strategy.

10. The failover switching system of claim 9, wherein, The headquarters data center further comprises a headquarters router and a switch. The exclusive UPF is in communication connection with the headquarters router. The headquarters router is in communication connection with the disaster recovery management platform and the switch respectively. The switch is in communication connection with the network management platform.

Citation Information

Patent Citations

  • System, method and network device for VPN customer to access public network

    WO2007112691A1

  • Configuration method and apparatus for wireless backhaul IP address

    WO2010096963A1