A network switching method and device based on dynamic vertical slicing and a storage medium

By using a dynamic vertical slicing mechanism, network slices are dynamically divided and routes are randomly selected within each slice. This solves the security and cost issues of existing network slicing technologies, achieves efficient network protection and seamless service switching, and enhances network resilience and security.

CN118785289BActive Publication Date: 2025-11-25NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410790570.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-19
Publication Date
2025-11-25
Estimated Expiration
2044-06-19

AI Technical Summary

Technical Problem

Existing network slicing technologies suffer from insufficient security, inadequate resource isolation, and insufficient network robustness, making it difficult to meet high security protection requirements. Furthermore, hard slicing is costly and lacks flexibility.

Method used

A dynamic vertical slicing mechanism is adopted, which uniformly registers subnets through the management platform, dynamically divides network slices based on business and task requirements, constructs elastic network slices, randomly selects routes within slices for data packet transmission, and defines the slice transition period and destination slice by switching patterns to achieve dynamic network protection.

Benefits of technology

It enables seamless service switching under threats such as DDoS attacks, enhances the network's proactive defense capabilities, reduces the risk of network paralysis, improves the network's resilience and survivability, and solves the problems of insufficient security of soft slicing and high cost of hard slicing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118785289B_ABST
    Figure CN118785289B_ABST
Patent Text Reader

Abstract

The application discloses a network switching method based on dynamic vertical slicing, comprising the following steps: registering and admitting all subnets participating in dynamic security protection through a management platform; based on business and / or task communication guarantee requirements, subnets needing intercommunication are divided into the same subnet group, and logical / physical isolation is realized between different subnet groups; a vertical slicing mechanism is adopted to dynamically slice and divide the network; a switching pattern is created for the first subnet group, and the slices of the subnet group are switched according to the switching time interval and the target slice of the switching pattern; when data packets flow within the slice, a random route is selected from multiple reachable routes in the slice for data packet transmission. The application further discloses a network switching device based on dynamic vertical slicing and a storage medium. The application realizes network slicing through dynamic division of a bearing network routing device, realizes switching of the whole network, and improves the active defense capability of the network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of wireless communication networks, and more particularly to a network switching method based on dynamic vertical slicing, a device and a storage medium. BACKGROUND

[0002] Network slicing is to divide a physical network into multiple virtual networks containing specific network functions, composed of customized network topology and network resources, to meet the network needs of different application scenarios. Current 5G network slicing technology mainly includes soft slicing, hard slicing, etc., including IP / MPLS-based tunnels / pseudo-wires, soft slicing solutions based on VPN, VLAN, and other virtualization technologies, and hard slicing solutions based on flexible Ethernet technology FlexE, OTN technology, and WDM multi-transmission channels. However, the existing slicing methods have many problems, (1) the security of soft slicing cannot be guaranteed, and the resource isolation characteristics and overall network robustness and stability cannot meet the requirements of network high-security protection; (2) hard slicing has high construction and maintenance costs and poor flexibility; (3) the above soft and hard slicing are all "horizontal slicing" in principle, which cannot meet the requirements of security and resilience under high-intensity attacks. SUMMARY

[0003] To overcome at least one of the defects or improvement needs of the prior art, the present application provides a network switching method based on dynamic vertical slicing, a device and a storage medium, which can solve the problems of the prior art.

[0004] To achieve the above-mentioned purpose, according to the first aspect of the present application, a network switching method based on dynamic vertical slicing is provided, which comprises:

[0005] Register and admit all subnets participating in dynamic security protection through a management platform;

[0006] Based on the communication guarantee requirements of business and / or tasks, the subnets that need to interwork are divided into the same subnet group as the first subnet group;

[0007] Based on the requirements of security level, business characteristics and reliability, a vertical slicing mechanism is adopted to dynamically slice the network and build one or more elastic network slices for the first subnet group;

[0008] A switching pattern is created for the first subnet group, the switching pattern includes switching interval time and switching destination slice, and the slices of the subnet group are switched according to the switching time interval and the switching destination slice of the switching pattern;

[0009] When data packets flow within the slice, a random route is selected from multiple reachable routes within the slice for data packet transmission.

[0010] Further, the network switching method based on dynamic vertical slicing, which adopts the vertical slicing mechanism to dynamically slice the network, specifically includes the following steps:

[0011] S1 The slice control receives a slice task creation request of a northbound interface, which includes access routing node information of source and sink subnets of the slice, generation level information of the slice, and use cycle information of the slice, and specifies to generate a shared slice between two subnets or multiple subnets;

[0012] S2 The slice control forwards the slice task creation request to a slice policy unit to request to calculate a network slice; the slice policy unit requests to obtain a topology of all established slices from the slice topology; the network slice topology accesses slice topology and routing node information in a data storage; the network slice topology sends the network slice topology and core routing node information to the slice policy unit; the slice policy unit generates a slice according to a currently set slice policy;

[0013] S3 The slice policy unit sends the generated slice to a slice resource configuration, and issues corresponding slice attributes to corresponding slice node devices for corresponding marking; the slice resource configuration sends slice configuration information to the devices through a flow table of an SBI interface; the SBI interface returns a core network node configuration success response;

[0014] S4 The slice resource configuration returns complete information of the slice to the slice controller; the slice control saves this time slice creation task information to a slice task storage; the slice control returns a success response of this time network slice task completion, and returns details of the created network slice.

[0015] Further, the network switching method based on dynamic vertical slicing, the network slice topology accesses slice topology and routing node information in a data storage, specifically includes:

[0016] Reading device information of a specific core routing node;

[0017] Reading currently allocated network slice information.

[0018] Further, the network switching method based on dynamic vertical slicing, which generates a slice according to a currently set slice policy, specifically includes the following constraints:

[0019] The generated slice does not overlap between different subnets;

[0020] The generated slice needs to ensure network reachability between PE routers;

[0021] The routing node included in the slice needs to meet the security level requirement of the slice task.

[0022] Further, the network switching method based on dynamic vertical slicing, when the sub-net group slice switches, checks whether the original slice contains a state abnormal routing node, and if so, eliminates the state abnormal routing node.

[0023] Further, the network switching method based on dynamic vertical slicing, the step of randomly selecting a routing from the multiple routings in the slice for data packet transmission specifically includes:

[0024] The slice K includes n inter-subnet shared communications, and the nth sub-net PE routing is PE n Configuring the link cost of the core network, and taking the slice K as the input topology of the PCE path calculation unit in the core network control node;

[0025] Based on the KSP algorithm, a pair of PE nodes of the sub-nets in the slice K are selected as source and sink nodes, and the K optimal path in the slice K is calculated;

[0026] The set of reachable paths is M={p1, p2, …, pk}, where pk represents the Kth optimal path, and according to the switching period, a certain optimal path is selected as the path of the current pair of sub-nets;

[0027] The above steps are repeated until a certain path is determined between all sub-nets, and a path set is generated;

[0028] Based on the openflow interface, all paths in the path set are configured and deployed using the flow table, so that the next hop forwarding address of the device is the forwarding address of the calculated path.

[0029] Further, the network switching method based on dynamic vertical slicing, the step of repeating the above steps until a certain path is determined between all sub-nets, and generating a path set, includes:

[0030] According to the switching period, a certain optimal path is selected as the path of the current pair of sub-nets as L1;

[0031] Select another pair of inter-subnet PE nodes as source and sink nodes, and calculate the K optimal path, and according to the hop change period, a certain optimal path is selected as the path of the current pair of sub-nets as L2;

[0032] The above steps are repeated until the path L(n*(n-1) / 2) is obtained;

[0033] All sub-nets have a certain path, and the path set is N={L1, L2, …, L(n*(n-1) / 2)}.

[0034] Further, in the dynamic protection process, the network switching method based on dynamic vertical slicing can switch the slice interventionally through unified network management intervention in case of emergency or special task.

[0035] According to a second aspect of the present application, there is also provided a network switching device based on dynamic vertical slicing, comprising at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program which, when executed by the processing unit, causes the processing unit to perform the steps of any of the above-mentioned methods.

[0036] According to a third aspect of the present application, there is also provided a storage medium storing a computer program executable by a network switching device based on dynamic vertical slicing, which, when running on the network switching device based on dynamic vertical slicing, causes the network switching device based on dynamic vertical slicing to perform the steps of any of the above-mentioned methods.

[0037] Overall, the above technical solutions conceived by the present application can achieve the following beneficial effects compared with the prior art:

[0038] (1) The network switching method based on dynamic vertical slicing provided by the present application realizes network slicing by dynamically dividing the bearing network routing device, and the upper-layer service transmission can be dynamically switched from one network slice to another, without service interruption and perception, thereby realizing the switching of the entire network, making various threats including DDoS attacks in the original network slice invalid, and improving the active defense capability of the network.

[0039] (2) By using the network switching method based on dynamic vertical slicing provided by the present application, the communication parties can dynamically switch the core network slice for service transmission in the communication process, and the switching period can be dynamically adjusted. In different hopping periods, the network slice will be dynamically divided again, effectively preventing the risk of network paralysis caused by large-scale DDoS attacks, and different services can be safely isolated by dividing different slices. In normal times, the fixed network slice and the routing in the slice are cooperatively hopped to realize security protection, and when a major security task is started, a task network slice can be temporarily constructed according to the needs, and when the core network node is subjected to a major attack or disaster damage, the core network slice can be real-time transformed and reorganized to complete the security task.

[0040] (3) The network switching method based on the dynamic vertical slicing provided by the application can revoke the network slice and release the network resources after the task is completed. The network vertical slicing method proposed in the application effectively solves the problems of insufficient security of soft slicing and high cost and poor flexibility of hard slicing, realizes uninterrupted and non-perceptual bearing service in the slicing jump process, effectively reduces the network collapse security risk, and improves the network elasticity and anti-destroying capability based on the dynamic generation and revocation of network slices based on the business or task. BRIEF DESCRIPTION OF DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort.

[0042] Figure 1 A flowchart of a network switching method based on dynamic vertical slicing provided by an embodiment of the present application is shown in the figure.

[0043] Figure 2 A vertical network slicing method provided by an embodiment of the present application is shown in the figure.

[0044] Figure 3 A dynamic routing within a slice provided by an embodiment of the present application is shown in the figure.

[0045] Figure 4 A path calculation within a slice provided by an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical solutions and advantages of the present application more clear, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.

[0047] The terms "first", "second", "third" and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, and are not used to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0048] Figure 1 is a flow diagram of a network switching method based on dynamic vertical slicing provided by an embodiment of the present application, as shown, comprising: Figure 1

[0049] 101. Register and admit all subnets participating in dynamic security protection through a management platform.

[0050] Specifically, register and admit all subnets, data centers, and business terminals participating in dynamic security protection through a management platform.

[0051] 102. Based on business and / or task communication guarantee requirements, classify subnets that need to interwork into the same subnet group as a first subnet group.

[0052] Specifically, according to business and / or task communication guarantee requirements, classify subnets that need to interwork into the same subnet group as a first subnet group, which constitutes an independent business domain and corresponds to an Overlay network; and communication between different subnet groups is logically / physically isolated.

[0053] 103. Based on security level, business characteristics, and reliability requirements, use a vertical slicing mechanism to dynamically slice the network to build one or more elastic network slices for the first subnet group.

[0054] Specifically, the core network dynamically slices the network according to different security levels or classification levels, business characteristics, and reliability requirements to build one or more elastic network slices for the first subnet group, and implements full life cycle management of the slices by creating, deleting, and switching the elastic network slices.

[0055] The slicing creation or division uses a vertical slicing mechanism, that is, the core routing node receives instructions from the core network control node, operates node Openflow flow table items, and dynamically belongs to different elastic network slices. As shown, Figure 2 Business domain A subnet group and business domain B subnet group are at the same classification level and share slice K1, and a subnet group composed of subnet 6 and subnet 7 uses slice K2 for transmission.

[0056] 104. Create a switching pattern for the first subnet group, and the switching pattern includes switching interval time and switching destination slice, and the slices of the subnet group are switched according to the switching time interval and switching destination slice of the switching pattern.

[0057] Specifically, create a switching (jumping) pattern for the first subnet group, which defines how often the slice switches (jumps) and the destination slice of the switching, etc. To achieve the effect of resilience against damage, the number of network slices of the subnet group should be greater than or equal to 2, and to achieve the effect of dynamic protection, the number of slices should be greater than or equal to 3. The basic design of the slice jumping pattern is shown in Table 1.​

[0058] Table 1 slice switching (hopping) pattern

[0059]

[0060] Note: 1. slice represents slice logical number, there are three slices in the pattern in the table, which are slice 0, slice 1 and slice 2.

[0061] 2. waittime represents slice running time in seconds, and after timeout, it is automatically switched to the next slice in the pattern.

[0062] 3. The switching sequence of the slices 0, 2, 1, 2, 0... and the slice running time sequence 20, 30, 40, 20, 50... can be generated by a random sequence algorithm such as a chaotic sequence.

[0063] After starting, the slices of the subnet group are sequentially effective according to the rules defined in the pattern, thereby preventing an attacker from eavesdropping on a certain group of routing nodes to intercept communication messages.

[0064] 105、When the data packet flows within the slice, a random route is selected from multiple reachable routes in the slice for data packet transmission.

[0065] Specifically, when the data packet flows within the slice, a single fixed routing path is not used, but a random route is selected from multiple reachable routes, so that the actual path of each communication is different, as shown in Figure 3 The path from subnet 4 to subnet 5 in slice K2 is path 1 in T0 period and path 2 in T1 period, thereby further improving the protection capability of the dynamic slice.

[0066] Optionally, based on the current Dijkstra algorithm and KSP (K shortest path) algorithm, a certain shortest path can be selected, and the repetition rate of the path can be reduced when the path hops.

[0067] The network switching method based on dynamic vertical slicing provided by the embodiment of the application realizes network slicing by dynamically dividing the network routing device, and when the upper layer service is transmitted, it can be dynamically switched from the network slice to another network slice, the service is not interrupted and is not perceived, thereby realizing the switching of the entire network, making various threats including DDoS attacks in the original network slice invalid, and improving the active defense capability of the network.

[0068] Optionally, the network switching method based on dynamic vertical slicing provided by the embodiment of the application adopts a vertical slicing mechanism to dynamically divide the network, and specifically includes the following steps:

[0069] The S1 slice control receives a slice task creation request of a northbound interface of the slice, and the slice task creation request includes access routing node information of source and sink subnets of the slice, generation level information of the slice, and use cycle information of the slice, and is specified as a shared slice generated between two subnets or multiple subnets.

[0070] The S2 slice control forwards the slice task creation request to a slice policy unit to request calculation of a network slice; the slice policy unit requests all topologies of currently established slices from the slice topology; the network slice topology accesses slice topology and routing node information in data storage; the network slice topology sends the network slice topology and core routing node information to the slice policy unit; the slice policy unit performs slice calculation according to a currently set slice policy, and generates a slice.

[0071] The S3 slice policy unit sends the generated slice to a slice resource configuration, and sends corresponding slice attributes to corresponding slice node devices, and makes corresponding marks; the slice resource configuration sends slice configuration information to the devices through a flow table of an SBI interface; the SBI interface returns a core network node configuration success response.

[0072] The S4 slice resource configuration returns complete information of the slice to the slice controller; the slice control saves this time slice creation task information to a slice task storage; the slice control returns a success response of this time network slice task completion, and returns details of the created network slice.

[0073] Optionally, the network switching method based on the dynamic vertical slice provided in the embodiment of the application accesses slice topology and routing node information in data storage, and specifically includes the following steps.

[0074] Reading device information of a specific core routing node;

[0075] Reading currently allocated network slice information.

[0076] Specifically, the device information of the core routing node includes IP, port, security level, and other configuration information. The network slice information includes slice name, node and link information included in the slice, and other information.

[0077] Optionally, the network switching method based on the dynamic vertical slice provided in the embodiment of the application performs slice calculation according to a currently set slice policy, and generates a slice, wherein constraint conditions for generating the slice include the following.

[0078] The generated slice does not overlap between different subnets;

[0079] The generated slice needs to ensure network reachability between PE routers;

[0080] The routing node included in the slice needs to meet the security level requirement of the slice task.

[0081] Specifically, the generated slice involves no overlap between slices among different subnets, such as no overlap between slice A among subnet 1, subnet 2, and subnet 3 and slice B among subnet 4 and subnet 5.

[0082] Optionally, the network switching method based on dynamic vertical slicing provided by the embodiment of the present application includes the following steps.

[0083] Specifically, when the subnet group slice switches, the original slice automatically checks and recovers or removes the state abnormal routing node, ensures that the slice routing node is normal next time, and prevents the problem or fault node from continuously affecting subsequent communication.

[0084] Optionally, the network switching method based on dynamic vertical slicing provided by the embodiment of the present application includes the following steps.

[0085] Slice K includes shared communication among n subnets, and the PE routing of the nth subnet is PE n Configure the link cost of the core network, and take slice K as the input topology of the PCE path calculation unit in the input core network control node.

[0086] Based on the KSP algorithm, a pair of PE nodes of the subnets in slice K are selected as source and sink nodes, and the K optimal path in the slice is calculated.

[0087] The set of reachable paths is M={p1, p2, …, pk}, where pk represents the K optimal path, and according to the switching period, a certain optimal path is selected as the path of the current pair of subnets.

[0088] Repeat the above steps until all subnets have determined paths, and generate a path set.

[0089] Based on the openflow interface, all paths in the path set are configured and deployed using the flow table, so that the next hop forwarding address of the device is the forwarding address calculated by the path.

[0090] Optionally, the network switching method based on dynamic vertical slicing provided by the embodiment of the present application includes the following steps.

[0091] According to the switching period, a certain optimal path is selected as the path of the current pair of subnets.

[0092] select another pair of PE nodes as source and destination nodes, calculate K shortest paths, and select one of the K shortest paths as the path L2 between the two subnets according to the hop variation period;

[0093] Repeat the above steps until the path L(n*(n-1) / 2) is obtained.

[0094] All the paths between the subnets are determined, and the path set N = {L1, L2,..., L(n*(n-1) / 2)} is generated.

[0095] Specifically, in an embodiment, a route is randomly selected from a plurality of reachable routes in a slice for packet transmission, and the specific steps include the following steps:

[0096] Suppose that the slice K includes shared communication between n subnets, and the PE route of the nth subnet is represented as PE n .

[0097] The link cost of the core network is configured, and the link cost can be set based on distance, delay, and other factors. The slice K generated by the hop variation includes the topology of its nodes and links, and is used as an input topology into the PCE path calculation unit of the core network control node for processing.

[0098] The KSP algorithm, i.e., the algorithm for calculating K shortest paths, is enabled. A pair of PE nodes of the subnets in the slice K is selected as source and destination nodes, for example, PE1 and PE2 are selected to calculate the K shortest paths in the slice. The D algorithm is repeatedly called to generate the 1st, 2nd,..., and Kth shortest paths. The set of reachable paths M = {p1, p2, p3,..., pk} is obtained, where pk represents the Kth shortest path. According to the hop variation period, one of the K shortest paths is selected as the path (between PE1 and PE2) between the current subnet 1 and subnet 2, which is assumed to be L1. Another pair of PE nodes between the subnets is selected as source and destination nodes, and the above steps are repeated to calculate the K shortest paths. According to the hop variation period, one of the K shortest paths is selected as the path between the current subnets until the path L(n*(n-1) / 2) is obtained.

[0099] When all the paths between the subnets are determined, the set of the K shortest paths N = {L1, L2,..., L(n*(n-1) / 2)} is generated.

[0100] Through the Openflow interface, all the paths in the set N are configured using a flow table to ensure that the next hop forwarding address of the device is the forwarding address of the calculated path, thereby specifying the transmission path.

[0101] In an embodiment, as Figure 4As shown, for slice 1 alone, the paths of the hopping subnetwork 1 and the hopping subnetwork 2 are calculated, and when the transmission path from the source PE to the sink PE is calculated in the topology of slice 1, the set M = {p1, p2, p3, p4} is obtained.

[0102] It is assumed that the current time is T, and the slice internal routing hopping period is t0, then:

[0103] At time T+t0, the optimal path p1 is selected as L1.

[0104] At time T+2t0, the optimal path p2 is selected as L1.

[0105] At time T+3t0, the optimal path p3 is selected as L1.

[0106] At time T+4t0, the optimal path p4 is selected as L1.

[0107] …

[0108] At time T+k*t0, the available paths are exhausted, and the first optimal path p1 is selected as L1.

[0109] At time T+(k+1)*t0, the above process is repeated to select an optimal path.

[0110] Optionally, the network switching method based on dynamic vertical slicing provided by the embodiment of the application can intervene in slice switching through unified network management intervention in the dynamic protection process if an emergency or a special task occurs.

[0111] Specifically, after the special communication task is completed, the network slice used for the task can be deleted to release the routing node resources. In the above dynamic protection process, if an emergency or a special task occurs, the slice hopping can be intervened through unified network management intervention to switch the slice used for communication.

[0112] The application also provides a computer readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the steps of the above method. The computer readable storage medium can include, but is not limited to, any type of disk, including a floppy disk, an optical disk, a DVD, a CD-ROM, a micro drive, and a magneto-optical disk, a ROM, a RAM, an EPROM, an EEPROM, a DRAM, a VRAM, a flash memory device, a magnetic card or an optical card, a nanosystem (including a molecular memory IC), or any type of medium or device suitable for storing instructions and / or data.

[0113] It should be noted that, for the foregoing method embodiments, the sequences of the described actions are not necessarily required to achieve the objects of the application, and certain steps can be performed in other sequences or even concurrently. Additionally, the described embodiments are merely provided as examples, and not all of the actions described are necessarily required to achieve desired results.

[0114] In the above embodiments, the description of each embodiment is focused on different aspects, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0115] In several embodiments provided in the present application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, another division manner can be adopted. For example, a plurality of units or components can be combined or integrated into another system, or some features can be omitted or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some service interfaces, devices or units, and can be electrical or other forms.

[0116] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e. can be located in one place or distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0117] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0118] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable memory. Based on such understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The aforementioned memory includes: a U disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0119] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing relevant hardware, and the program can be stored in a computer readable memory, which can include a flash disk, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, etc.

[0120] The above is only exemplary embodiments of the present disclosure, and cannot limit the scope of the present disclosure. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure are still within the scope of the present disclosure. Those skilled in the art will easily think of embodiments of the present disclosure after considering the specification and practicing the disclosure herein. The present application is intended to cover any variations, uses or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or conventional technical means in the technical field not described in the present disclosure. The specification and examples are only considered as exemplary, and the scope and spirit of the present disclosure are defined by the claims.

[0121] The technical features of the above embodiments can be combined in any way. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not contradict, they should be considered within the scope of the present disclosure.

[0122] Those skilled in the art readily understand that the above only describes preferred embodiments of the present application and is not intended to limit the present application. Any modification, equivalent replacement and improvement made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A network switching method based on dynamic vertical slicing, characterized in that, include: All subnets participating in dynamic security protection will be uniformly registered and granted access through the management platform; Based on business and / or task communication assurance requirements, subnets that need to communicate with each other are grouped into the same subnet group, which is designated as the first subnet group. Based on the requirements of security level, business characteristics and reliability, a vertical slicing mechanism is adopted to dynamically divide the network into slices and build one or more elastic network slices for the first subnet group. A switching pattern is created for the first subnet group, the switching pattern including a switching interval and a target slice to be switched, and the slices of the subnet group are switched according to the switching interval of the switching pattern and the target slice to be switched; When data packets flow within a slice, a route is randomly selected from multiple reachable routes within the slice for data packet transmission.

2. The network switching method based on dynamic vertical slicing as described in claim 1, characterized in that, The vertical slicing mechanism dynamically divides the network into slices, specifically including the following steps: S1. The slice control unit receives a slice task creation request from the northbound interface. The slice task creation request includes the access routing node information of the source and destination subnets of the slice, the slice generation level information, and the slice usage period information, specifying that a shared slice is generated between two or more subnets. S2. The slice control unit forwards the slice task creation request to the slice strategy unit to request the calculation of network slices; The slice strategy unit requests topology information for all currently established slices from the slice topology management unit; The slice topology management unit accesses slice topology information and core routing node information in the topology data storage unit; The slice topology management unit sends slice topology information and core routing node information to the slice policy unit; The slicing strategy unit calculates slices according to the currently set slicing strategy, generates slices, and returns the configuration information of the slices to the slicing control unit; S3. The slice control unit forwards the slice configuration information to the slice resource configuration unit, and the slice resource configuration unit sends the slice configuration information to the core network node through the flow table of the SBI interface. The SBI interface returned a successful configuration response for the core network node. S4. The slice resource configuration unit returns complete information about all nodes within the slice to the slice control unit; The slice control unit saves the slice creation task information to the slice task storage unit; The slice control unit returns a success response indicating the completion of this network slice task, along with details of the created network slice.

3. The network switching method based on dynamic vertical slicing as described in claim 2, characterized in that, The slice topology management unit accesses the slice topology and topology information and core routing node information in the topology data storage unit, specifically including: Read the device information of specific core routing nodes; Read the currently allocated network slice information.

4. The network switching method based on dynamic vertical slicing as described in claim 2, characterized in that, The step involves calculating and generating slices based on the currently set slicing strategy, wherein the constraints for generating slices include: The generated slices involve slices from different subnets that do not overlap; The generated slices must ensure network reachability between PE routers; The routing nodes included in the slice must meet the security level requirements of the slice task.

5. The network switching method based on dynamic vertical slicing as described in claim 1, characterized in that, When switching slices in a subnet group, the original slice is checked to see if it contains a routing node with an abnormal state. If so, the routing node containing the abnormal state is removed.

6. The network switching method based on dynamic vertical slicing as described in claim 1, characterized in that, The step of randomly selecting one route from multiple reachable routes within a slice for data packet transmission specifically includes: Slice K includes shared communication between n subnets, where the PE route of the nth subnet is PE. n Configure the link cost of the core network and use slice K as the input topology processed by the PCE path calculation unit in the core network control node; Based on the KSP algorithm, a pair of PE nodes of subnets are selected as source and sink nodes in slice K, and the K-optimal path in the slice is calculated. The set of reachable paths is M = {p1, p2, ..., pk}, where pk represents the Kth optimal path. Based on the switching cycle, a certain optimal path is selected as the current path of the pair of subnets. Repeat the above steps until all subnets have defined paths, generating a path set; Based on the OpenFlow interface, all paths in the path set are configured using flow tables, so that the next-hop forwarding address of the device is the forwarding address of the calculated path.

7. The network switching method based on dynamic vertical slicing as described in claim 6, characterized in that, The above steps are repeated until all subnets have defined paths, generating a path set, including: Based on the switching cycle, a preferred path is selected as the current path for the pair of subnets, designated as L1. Select another PE node between subnets, and use it as the source and destination node again. Calculate the K-optimal path, and select an optimal path as the current path L2 for the pair of subnets based on the transition period. Repeat the above steps until the path L(n*(n-1) / 2) is obtained; There are already defined paths between all subnets, and the set of paths is N={L1, L2, ..., L(n*(n-1) / 2)}.

8. The network switching method based on dynamic vertical slicing as described in claim 1, characterized in that, During dynamic protection, in case of emergency or special task situations, the slice switching can be intervened through unified network management.

9. A network switching device based on dynamic vertical slicing, characterized in that, It includes at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program that, when executed by the processing unit, causes the processing unit to perform the steps of the method according to any one of claims 1 to 8.

10. A storage medium, characterized in that, It stores a computer program executable by a network switching device based on dynamic vertical slicing, which, when run on the network switching device based on dynamic vertical slicing, causes the network switching device based on dynamic vertical slicing to perform the steps of the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Network isolation method and system and proxy device

    CN114338119A

  • Power communication service resource allocation method and device based on flexible Ethernet

    CN115277429A