Network policy management method, apparatus, device, and storage medium

By acquiring and optimizing network policy instances, conducting policy relationship analysis, and constructing knowledge graphs, the problem of the universality of policy expression methods in self-intelligent networks is solved, and systematic management of network policies is achieved, possessing strong universality and flexibility.

CN118827384BActive Publication Date: 2026-01-06CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410006798.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-02
Publication Date
2026-01-06
Estimated Expiration
2044-01-02

AI Technical Summary

Technical Problem

In existing technologies, the expression methods of network information graphs and domain-specific strategies lack universality and cannot be applied to the multi-layered, multi-domain flexible application and scalability requirements of self-intelligent networks.

Method used

By acquiring target strategy instances, strategy relationship analysis and optimization are performed, including verifying strategy effectiveness, analyzing scope of action, analyzing effectiveness relationships and execution relationships, deleting or deactivating invalid, redundant and low-priority strategies, constructing a strategy application knowledge graph, and achieving systematic strategy management.

Benefits of technology

It achieves systematic management of network policies, and has the advantages of strong versatility, high flexibility and on-demand expansion, meeting the operation and maintenance management needs of intelligent networks in various fields, at different levels and across fields.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827384B_ABST
    Figure CN118827384B_ABST
Patent Text Reader

Abstract

The application discloses a network policy management method, device, equipment and storage medium. The method comprises the following steps: obtaining at least one target policy instance for network management; performing policy relationship analysis on the at least one target policy instance and an existing policy instance based on policy application knowledge to obtain a policy relationship analysis result; and performing optimization processing on the at least one target policy instance and the existing policy instance based on the policy relationship analysis result. The method can realize policy systematization management of network policy, meet the systematization general management of operation and maintenance management policies in various network fields, hierarchical levels and cross fields, and has the advantages of strong universality, high flexibility and on-demand expansion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of policy management, and more particularly to a method, apparatus, device, and storage medium for managing network policies. Background Technology

[0002] "Self-Intelligent Networks" emerged in response to the development of a digital and intelligent society. Through the digital transformation and upgrading of network operations and maintenance, they meet the higher requirements of digital and intelligent products for network experience and agile support, leading information services to a new level. "Self-Intelligent Networks" aims to build automated and intelligent operation and maintenance capabilities throughout the entire network lifecycle, providing consumers and vertical industry clients with new network and ICT (Information and Communications Technology) services characterized by "zero waiting time, zero failures, and zero contact," and creating "self-configuration, self-repair, and self-optimization" digital operation and maintenance capabilities for intelligent network operations and maintenance.

[0003] In related technologies, solutions that combine knowledge-driven approaches with network operation and maintenance strategy management often simply combine network information graphs and specific domain-specific strategies with business logic. This approach lacks universality and cannot meet the multi-level, multi-domain flexible application and scalability requirements of the self-intelligent network strategy system management. Summary of the Invention

[0004] In view of this, embodiments of this application provide a method, apparatus, device, and storage medium for managing network policies, aiming to meet the needs of systematic management of network policies.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] In a first aspect, embodiments of this application provide a method for managing network policies, including:

[0007] Obtain at least one instance of a target policy for network management;

[0008] Based on the knowledge of strategy application, a strategy relationship analysis is performed on the at least one target strategy instance and the existing strategy instance to obtain the strategy relationship analysis results.

[0009] Based on the results of the strategy relationship analysis, the at least one target strategy instance and the existing strategy instance are optimized.

[0010] In the above scheme, obtaining at least one instance of a target policy for network management includes at least one of the following:

[0011] Obtain at least one instance of the target strategy imported from outside;

[0012] Obtain at least one instance of the target policy for internal monitoring.

[0013] The method in the above scheme further includes:

[0014] The policy application knowledge is constructed based on policy instance knowledge and / or network management object instance knowledge.

[0015] In the above scheme, the strategy application knowledge includes at least one of the following: object instance knowledge, strategy instance knowledge, and element instance knowledge. The object instance knowledge is used to represent object instances, the strategy instance knowledge is used to represent strategy instances, and the element instance knowledge is used to represent element instances. The step of performing strategy relationship analysis on the at least one target strategy instance and existing strategy instances based on the strategy application knowledge to obtain strategy relationship analysis results includes:

[0016] Based on the policy instance knowledge, the policy effectiveness of the at least one target policy instance is verified to obtain a set of policy instances with valid policies; and / or,

[0017] For the set of effective strategy instances and existing strategy implementations, a scope analysis is performed based on the object instance knowledge to obtain a set of strategy instances where the strategy is effective and their scopes overlap; and / or,

[0018] Perform effectiveness relationship analysis on the set of strategy instances where the strategy is effective and their scopes overlap to obtain a set of strategy instances that meet the defined effectiveness relationship; and / or,

[0019] An execution relationship analysis is performed on the set of strategy instances that conform to the set of performance relationships to obtain a set of strategy instances whose execution elements satisfy the set of execution relationships.

[0020] In the above scheme, the strategy instance knowledge includes: performance indicator information representing the expected effect of the strategy instance; and the performance relationship analysis of the set of strategy instances that are effective for the strategy and have overlapping scopes of action to obtain a set of strategy instances that conform to the set performance relationship includes:

[0021] Based on the performance indicator information, determine the relationship between performance indicators in the set of strategy instances where the strategy is effective and their scope of action overlaps.

[0022] Based on the relationship between the aforementioned performance indicators, a set of strategy instances that conform to the set performance relationship is obtained;

[0023] The established performance relationship includes at least one of the following: performance indicators conflict, performance indicators overlap, and performance indicators are included.

[0024] In the above scheme, the step of performing execution relationship analysis on the set of strategy instances that conform to the set of established performance relationships to obtain strategy instances whose execution elements satisfy the set of execution relationships includes:

[0025] Based on the knowledge of the element instances, determine the relationship between the execution elements in the set of strategy instances that conform to the set of effect relationships;

[0026] Based on the relationships between the execution elements, a set of strategy instances in which the execution elements satisfy the defined execution relationships is obtained;

[0027] The set execution relationship includes at least one of the following: conflicting execution elements, overlapping execution elements, and associated execution elements.

[0028] In the above scheme, the optimization process for the at least one target strategy instance and existing strategy instances based on the strategy relationship analysis results includes:

[0029] Based on the results of the strategy relationship analysis, the at least one target strategy instance and the existing strategy instance are automatically or manually optimized.

[0030] In the above scheme, based on the strategy relationship analysis results, automatic optimization processing is performed on the at least one target strategy instance and the existing strategy instance, including at least one of the following:

[0031] Delete and / or deactivate invalid policy instances;

[0032] Delete and / or deactivate redundant policy instances;

[0033] Based on priority policies, delete and / or deactivate low-priority policy instances.

[0034] In the above scheme, after optimizing the at least one target policy instance based on the strategy relationship analysis results, the method further includes:

[0035] Based on the results of the strategy relationship analysis, the strategy application knowledge is updated.

[0036] Secondly, embodiments of this application provide a network policy management device, including:

[0037] The acquisition module is used to acquire at least one instance of a target policy for network management;

[0038] The analysis module is used to perform strategy relationship analysis on the at least one target strategy instance and existing strategy instances based on strategy application knowledge, and obtain strategy relationship analysis results.

[0039] An optimization module is used to optimize the at least one target strategy instance and existing strategy instances based on the strategy relationship analysis results.

[0040] Thirdly, embodiments of this application provide an electronic device, including: a processor and a memory for storing a computer program capable of running on the processor, wherein, when the processor is used to run the computer program, it executes the steps of the method described in the first aspect of embodiments of this application.

[0041] Fourthly, embodiments of this application provide a computer storage medium storing a computer program, which, when executed by a processor, implements the steps of the method described in the first aspect of embodiments of this application.

[0042] The technical solution provided in this application embodiment obtains at least one target policy instance for network management; based on policy application knowledge, performs policy relationship analysis on the at least one target policy instance and existing policy instances to obtain policy relationship analysis results; and optimizes the at least one target policy instance and existing policy instances based on the policy relationship analysis results. In this way, policy relationship analysis can be performed on at least one target policy instance and existing policy instances for network management based on policy application knowledge, and optimization can be performed on at least one target policy instance and existing policy instances based on the policy relationship analysis results, achieving systematic management of network policies. This can meet the needs of systematic and universal management of network operation and maintenance policies in various fields, at different levels, and across different fields, and has the advantages of strong versatility, high flexibility, and on-demand scalability. Attached Figure Description

[0043] Figure 1 This is a flowchart illustrating the network policy management method according to an embodiment of this application;

[0044] Figure 2 This is a schematic diagram of the architecture of the network policy management system in this application embodiment;

[0045] Figure 3 This is a schematic diagram of the network policy management device according to an embodiment of this application;

[0046] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0047] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0048] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the application.

[0049] Before providing a further detailed description of the embodiments of this application, the nouns and terms used in the embodiments of this application are explained, and the nouns and terms used in the embodiments of this application shall be interpreted as follows:

[0050] Autonomous Networks aims to build automated and intelligent operation and maintenance capabilities throughout the entire network lifecycle, providing consumers and vertical industry customers with new network and ICT services characterized by "zero waiting time, zero failures, and zero contact," and creating digital and intelligent operation and maintenance capabilities of "self-configuration, self-repair, and self-optimization" for intelligent network operation and maintenance.

[0051] Management: A set of processes responsible for describing, organizing, controlling, and managing access to and management of information and organizational entities throughout their lifecycle.

[0052] Managed entities: Manageable objects related to products, services and / or resources.

[0053] Management Domain: A domain that uses a common set of management mechanisms to manage its contents. A management domain is a managed entity with three key characteristics: 1) It has a set of administrators defined to perform management operations on the managed entities it contains; 2) It defines a set of applications responsible for different management operations (such as monitoring, configuration, etc.); 3) It defines a common set of management mechanisms, such as policy rules, to manage the behavior of the managed entities contained in the management domain.

[0054] A policy (also known as a policy instance) is a set of rules used to manage and control changes to and / or maintain the state of one or more managed objects. Organizations are policy-driven entities. A policy is a set of rules and constraints that express behavior, and then a natural way to automatically enforce those rules and constraints. The purpose of a policy is to ensure consistent decisions are made to govern the behavior of the system.

[0055] Imperative strategy: A strategy type that uses statements to explicitly change the state of a set of target objects. The order of the statements constituting the strategy is explicitly defined. In various embodiments of this application, unless explicitly stated otherwise, "strategy" will refer to a class of imperative strategies, namely, strategies composed of events, conditions, and actions. The events, conditions, and actions are defined as follows:

[0056] Event: Anything that occurs on the timeline that is important to the management system (e.g., changes to the system and / or its environment).

[0057] Conditions: A set of attributes, characteristics, and / or values, compared with a known set of attributes, characteristics, and / or values ​​to determine the decision to be made.

[0058] Action: A set of operations that can be performed on a group of management entities, representing a transformation or process in the system being modeled.

[0059] Strategy is a key feature for enhancing the capabilities of self-intelligent networks. Related technologies define self-intelligent network levels to guide the automation and intelligence of networks and services, assess the value and advantages of self-intelligent network services, and guide operators and vendors in intelligent upgrades, as detailed below:

[0060] Manual operation and maintenance: Corresponding to L0 level, the system provides auxiliary monitoring capabilities, and all dynamic tasks need to be executed manually.

[0061] Assisted Operation and Maintenance: Corresponding to L1 level, the system can execute specific repetitive sub-tasks according to pre-configuration to improve execution efficiency.

[0062] Partially self-intelligent networks: Corresponding to Level 2, in specific external environments, the system can enable automated closed-loop operation and maintenance for specific units based on predefined rules / policies. Level 2 allows for static injection of rules, and policies to achieve automated closed-loop processes including event monitoring, condition analysis, and action execution.

[0063] Conditional Intelligent Networks: Corresponding to Level 3, building upon Level 2, the system can perceive environmental changes in real time and perform self-optimization and self-adjustment within specific network disciplines to adapt to the external environment. Level 3 can dynamically decouple rules, allowing operations and maintenance personnel to dynamically edit and import policy rules according to the formal specifications of the policies during the system execution phase. This means that the system needs to have the ability to systematically manage a larger number of policy rules from a wider range of sources and with more complex relationships.

[0064] Highly Intelligent Networks: Corresponding to Level 4, building upon Level 3, the system can achieve predictive or proactive closed-loop management of business and customer experience-driven networks in more complex multi-network environments, thereby performing analysis and making decisions. A typical feature of Level 4 is AI (Artificial Intelligence)-assisted rule generation, meaning that the policy rules themselves need to undergo automatic iteration through application monitoring and effectiveness evaluation.

[0065] Fully autonomous network: corresponding to Level 5, this level is the ultimate goal of telecommunications network evolution. The system has closed-loop autonomous capabilities for multiple services, multiple domains, and the entire lifecycle. The typical feature of Level 5 is adaptive evolution, which means that policy rules need to dynamically adapt to changes in the internal and external environment of the system and proactively evolve according to the dynamically evolving system goals.

[0066] It is understandable that with the technological evolution and development of self-intelligent networks, it is necessary to expand the policy management technology system of self-intelligent networks to achieve standardized formal expression of policy rules, systematic management, and enhanced dynamic evolution capabilities. Based on this, various embodiments of this application propose a knowledge-driven network policy management method that meets the general needs of systematic management of operation and maintenance management strategies in various domains, at different levels, and across different domains of self-intelligent networks. This method has advantages such as strong versatility, high flexibility, and on-demand scalability.

[0067] This application provides a method for managing network policies, which can be applied to electronic devices with data processing capabilities, such as a network policy management platform or a network policy management system. Figure 1 As shown, the management method includes:

[0068] Step 101: Obtain at least one target policy instance for network management.

[0069] Step 102: Based on the knowledge of strategy application, perform strategy relationship analysis on the at least one target strategy instance and the existing strategy instance to obtain the strategy relationship analysis results.

[0070] Step 103: Based on the strategy relationship analysis results, optimize the at least one target strategy instance and the existing strategy instance.

[0071] It is understood that the embodiments of this application can perform policy relationship analysis on at least one target policy instance and existing policy instance used for network management based on policy application knowledge, and optimize at least one target policy instance and existing policy instance based on the policy relationship analysis results, so as to realize the systematic management of network policies. It can meet the systematic and general management of network operation and maintenance management policies in various fields, hierarchical and cross-domain, and has the advantages of strong universality, high flexibility and on-demand expansion.

[0072] For example, obtaining at least one instance of a target policy for network management includes at least one of the following:

[0073] Obtain at least one instance of the target strategy imported from outside;

[0074] Obtain at least one instance of the target policy for internal monitoring.

[0075] It is understood that the network policy management system can obtain at least one target policy instance imported from external sources and / or at least one target policy instance monitored internally, thereby achieving systematic management of policy instances based on at least one target policy instance. External imports can include policy instances imported from experts or policy instances imported from external system policy knowledge bases, while internal monitoring can be at least one target policy instance monitored by the network policy management system based on preset monitoring policies.

[0076] Exemplarily, the method further includes:

[0077] The policy application knowledge is constructed based on policy instance knowledge and / or network management object instance knowledge.

[0078] Here, the network policy management system can construct policy application knowledge based on policy instance knowledge and / or network management object instance knowledge. For example, policy application knowledge can be a policy application knowledge graph.

[0079] Knowledge graphs (KG) are an important branch of knowledge engineering. They structurally describe concepts and their relationships in the physical world in symbolic form. The basic structure of a knowledge graph is a triple of <entity, relation, entity>, where entities are interconnected through relations, forming a complex network of knowledge. A knowledge graph is a multi-relationship graph composed of entities and relations, with entities and relations considered as nodes and different types of edges, respectively. It can be understood that by mining the relationships between instances in policy modeling and / or policy management modeling, relationships between entities can be constructed, resulting in a policy application knowledge graph.

[0080] For example, the aforementioned policy instance knowledge and / or network management object instance knowledge can be described using the RDF (Resource Description Framework) language, and a policy application knowledge graph can be constructed. RDF is a resource description language influenced by metadata standards, framework systems, object-oriented languages, and other factors. It is used to describe various network resources, and its emergence provides a standard data description framework for publishing structured data on the Web. It can convert various network resources into triples and store them in a knowledge base.

[0081] For example, the strategy application knowledge includes at least one of the following: object instance knowledge, strategy instance knowledge, and feature instance knowledge, wherein the object instance knowledge is used to characterize object instances, the strategy instance knowledge is used to characterize strategy instances, and the feature instance knowledge is used to characterize feature instances. The step of performing strategy relationship analysis on the at least one target strategy instance and existing strategy instances based on the strategy application knowledge to obtain strategy relationship analysis results includes:

[0082] Based on the policy instance knowledge, the policy effectiveness of the at least one target policy instance is verified to obtain a set of policy instances with valid policies; and / or,

[0083] For the set of effective strategy instances and existing strategy implementations, a scope analysis is performed based on the object instance knowledge to obtain a set of strategy instances where the strategy is effective and their scopes overlap; and / or,

[0084] Perform effectiveness relationship analysis on the set of strategy instances where the strategy is effective and their scopes overlap to obtain a set of strategy instances that meet the defined effectiveness relationship; and / or,

[0085] An execution relationship analysis is performed on the set of strategy instances that conform to the set of performance relationships to obtain a set of strategy instances whose execution elements satisfy the set of execution relationships.

[0086] Understandably, based on policy application knowledge, performing policy relationship analysis on at least one target policy instance and existing policy instances allows for the classification and analysis of relationships among active policies of the same object or set, identifying policy relationship analysis results. For example, it can identify invalid policies, redundant policies, conflicting policies, and related policies. Invalid policies are those that cannot have a practical effect on any managed object instance due to applicability or other reasons; redundant policies are those included in other policies that can achieve the same effect without being triggered separately; conflicting policies are those that are triggered simultaneously with other policies but have inconsistent execution effects; and related policies are those that are triggered by the execution effects of other policies, creating a chain effect.

[0087] In one application example, policy application knowledge includes, but is not limited to: object instance knowledge, policy instance knowledge, and feature instance knowledge. The following is a description of each instance knowledge:

[0088] 1) Object instance knowledge

[0089] The strategy application knowledge graph can maintain instance information for the current management domain and its subordinate managed objects for subsequent comprehensive analysis, including but not limited to:

[0090] Management domain instance status: The instance status and hierarchical relationships of management domains at each level;

[0091] Instance status of managed objects: The instance status and subordinate relationships of individual managed objects under the jurisdiction of each level of management domain.

[0092] 2) Strategy Instance Knowledge

[0093] A strategy application knowledge graph can maintain information for each strategy instance for subsequent comprehensive analysis, including but not limited to:

[0094] Policy instance states: active / activated, suspended / deactivated, etc.;

[0095] The target scope of the strategy: the management domain and management objects to which the strategy is applied;

[0096] Effectiveness metrics for the strategy: Metrics for evaluating the effectiveness of the strategy application include, but are not limited to, metrics such as functionality, performance, security, scalability, and fairness.

[0097] The execution elements of a strategy include, but are not limited to, the subscribed triggering events, the condition variables on which it depends, and the execution operations that are invoked.

[0098] Relationship records for strategies: including but not limited to: information on other strategy instances with conflicting / redundant / related relationships, specific relationship types (e.g., conflicting performance indicators and / or conflicting execution elements) and related information descriptions (e.g., specific conflicting performance indicators or execution elements).

[0099] 3) Element Instance Knowledge

[0100] The strategy application knowledge graph can maintain information for each execution element instance referenced by the strategy, for subsequent comprehensive analysis, including but not limited to:

[0101] Event instance information: Can report event instances and relationships between event instances (derivation, mutual exclusion, etc.);

[0102] Condition instance information: can evaluate condition instances and the relationships between condition instances (containment, overlap, mutual exclusion, etc.);

[0103] Action instance information: executable action instances, relationships between action instances (inclusion, influence, mutual exclusion, etc.);

[0104] Performance indicator information (optional): The relationship between the expected target performance of the strategy application and the performance indicators (including, influence, mutual exclusion, etc.).

[0105] For example, the strategy instance knowledge includes: performance indicator information characterizing the expected effect of the strategy instance; the performance relationship analysis of the set of strategy instances that are effective for the strategy and have overlapping scopes of action to obtain a set of strategy instances that conform to the set performance relationship includes:

[0106] Based on the performance indicator information, determine the relationship between performance indicators in the set of strategy instances where the strategy is effective and their scope of action overlaps.

[0107] Based on the relationship between the aforementioned performance indicators, a set of strategy instances that conform to the set performance relationship is obtained;

[0108] The established performance relationship includes at least one of the following: performance indicators conflict, performance indicators overlap, and performance indicators are included.

[0109] Understandably, based on the above performance relationship analysis, a set of strategy instances that conform to the set performance relationship can be obtained, providing basic data for subsequent strategy optimization.

[0110] For example, the step of performing execution relationship analysis on the set of strategy instances that conform to the set of defined performance relationships to obtain strategy instances whose execution elements satisfy the set of execution relationships includes:

[0111] Based on the knowledge of the element instances, determine the relationship between the execution elements in the set of strategy instances that conform to the set of effect relationships;

[0112] Based on the relationships between the execution elements, a set of strategy instances in which the execution elements satisfy the defined execution relationships is obtained;

[0113] The set execution relationship includes at least one of the following: conflicting execution elements, overlapping execution elements, and associated execution elements.

[0114] Understandably, based on the above analysis of execution relationships, a set of strategy instances that conform to the set execution relationships can be obtained, providing basic data for subsequent strategy optimization.

[0115] In the above scheme, the optimization process for the at least one target strategy instance and existing strategy instances based on the strategy relationship analysis results includes:

[0116] Based on the results of the strategy relationship analysis, the at least one target strategy instance and the existing strategy instance are automatically or manually optimized.

[0117] For example, based on the results of strategy relationship analysis and relying on the strategy management framework, active strategies can be automatically or manually optimized based on the relationship classification results.

[0118] For example, based on the strategy relationship analysis results, automatic optimization processing is performed on the at least one target strategy instance and existing strategy instances, including at least one of the following:

[0119] Delete and / or deactivate invalid policy instances;

[0120] Delete and / or deactivate redundant policy instances;

[0121] Based on priority policies, delete and / or deactivate low-priority policy instances.

[0122] Understandably, based on the results of policy relationship analysis, the active policies can be automatically or manually optimized to achieve systematic management of network policies. This can meet the needs of systematic and general management of network operation and maintenance policies in various fields, at different levels and across different fields. It has the advantages of strong versatility, high flexibility and on-demand expansion.

[0123] For example, after optimizing the at least one target policy instance based on the strategy relationship analysis results, the method further includes:

[0124] Based on the results of the strategy relationship analysis, the strategy application knowledge is updated.

[0125] Understandably, updating the strategy application knowledge based on the strategy relationship analysis results can utilize the existing strategy rule knowledge in the strategy knowledge base and combine it with the newly input strategy rule knowledge. Through knowledge reasoning, mining and other technologies, new derived strategy knowledge can be created by combining, reasoning and creating new strategy knowledge, thereby improving the completeness of strategy knowledge.

[0126] The present application will be further described in detail below with reference to application examples.

[0127] The architecture diagram of the network policy management system in this application embodiment is shown below. Figure 2 As shown, a knowledge-driven policy management system is implemented based on the basic knowledge management functional architecture. This means the network policy management system can support the static import, application, and updating of policies. Specifically, it includes a policy fusion submodule and a policy knowledge base. It supports the import, application, and passive updating of policy knowledge from operation and maintenance experts and external systems.

[0128] In this application embodiment, the strategy knowledge base can be reused to implement the storage and retrieval functions of the aforementioned strategy application knowledge graph. The retrieval scenarios for the strategy application knowledge graph include:

[0129] Respond to policy application knowledge requests from various sub-modules within the policy system management and provide corresponding policy application knowledge;

[0130] In response to the knowledge sharing needs of external systems regarding policy application, provide corresponding policy application knowledge.

[0131] Here, the knowledge applied in the strategy includes, but is not limited to: object instance knowledge, strategy instance knowledge, and element instance knowledge. For details, please refer to the foregoing description, which will not be repeated here.

[0132] The following is an exemplary description of the strategy relationship analysis and strategy optimization process in this application embodiment:

[0133] I. Strategic Relationship Analysis

[0134] In this application example, the strategy relationship analysis includes the following four stages:

[0135] Phase 1 involves validating the input strategy and eliminating invalid strategies (strategies that are not executable, will not trigger, and therefore will not generate potential conflicts).

[0136] Phase Two involves analyzing the scope of all valid policies input, eliminating cases where the scopes of valid policies do not overlap. The scope of a valid policy refers to the managed objects (e.g., physical or virtual network resources, or network services or business operations) that it can affect or influence after being triggered. If the scopes of two valid policies do not overlap, meaning they will not act on the same managed object at any given time, then there will be no potential conflict between them.

[0137] Phase Three involves analyzing the effectiveness relationships of effective strategies with shared scopes of action, eliminating cases where the application performance indicator ranges for specific management objects within the shared scope are incompatible or irrelevant. An effective strategy's application performance indicator for a specific management object within its scope refers to the range of performance indicator values ​​that the strategy maker expects to ensure that the specific management object maintains within the strategy's effective period (e.g., using an automatic scaling-up / downsizing strategy to ensure that the average CPU utilization of a data center server remains between 40% and 80%). If two effective strategies with shared scopes of action have incompatible application performance indicator ranges for specific management objects, they cannot simultaneously achieve their respective performance indicators, indicating a potential strategy conflict. The effectiveness relationship analysis ends, and execution relationship analysis is conducted further. Otherwise, the inclusion relationship between the strategies' performance objectives is further eliminated before proceeding with execution relationship analysis.

[0138] Phase four involves analyzing the strategy execution relationships to identify policy relationships that will not be triggered simultaneously, will not be executed simultaneously, or may conflict, redundancy, inclusion, and derivative when executed simultaneously.

[0139] For example, the above-mentioned stage one is specifically executed as follows:

[0140] Knowledge graphs are used to apply policies to evaluate the effectiveness of input policies and eliminate ineffective policies. Ineffective policies include, but are not limited to, the following:

[0141] (1) Applicability

[0142] 1) The policy instance is in an inactive / deactivated state;

[0143] 2) The set of managed objects under the specified management domain for the policy objective scope is empty;

[0144] 3) The strategy execution elements specify that the triggering event, evaluation conditions, or execution action is not applicable or supported in the specified management domain / managed object;

[0145] (2) Effectiveness

[0146] 1) The evaluation methods specified for the strategy effectiveness indicators are not applicable or supported in the specified management domain / object;

[0147] 2) The current evaluation status of the strategy effectiveness indicators is ineffective.

[0148] For example, the second stage described above is specifically executed as follows:

[0149] By leveraging a knowledge graph applied to policies, the target scope relationship between input policies and existing policies is analyzed to identify any overlaps and eliminate policies with non-overlapping target scopes, thus preventing potential conflicts, overlaps, and derivative relationships. This scope relationship analysis includes, but is not limited to:

[0150] By leveraging the hierarchical relationships between management domains / objects within the object instance knowledge in the strategy application knowledge graph, the direct and indirect relationships of the strategy's target scope are derived, and the set of all management objects actually applied to each strategy is obtained through reasoning.

[0151] Find the intersection S1 of the actual management object sets of each strategy involved in the analysis. If the intersection is empty, exclude any overlapping relationships and end the strategy relationship analysis; otherwise, continue to the next step.

[0152] For example, the above-mentioned stage three is specifically implemented as follows:

[0153] By utilizing a knowledge graph applied to strategies, the relationships between performance indicators of input strategies are analyzed to identify any overlaps and to determine which strategies exhibit conflicting, overlapping, or inclusive relationships among their performance indicators. The steps involved in performance relationship analysis include, but are not limited to:

[0154] (1) By utilizing the inclusion, derivation, and association relationships among the effectiveness indicators in the strategy instance knowledge graph of strategy application, the direct and indirect relationships of the effectiveness indicators of the strategy are derived, and the set of all effectiveness indicators and their value ranges for each strategy in actual application are obtained.

[0155] (2) Find the intersection S1 of the actual performance indicator ranges for each object i in the set of management objects with common scope of action for each strategy involved in the analysis. i2 And record:

[0156] A set of objects S3, where each object j, S j2Empty; that is, any performance indicator of management object i contained in object set S3 may not be able to simultaneously satisfy all participating analysis strategies;

[0157] A set of objects S4, where each object k, S k2 Not empty; that is, some performance indicators of the management object k contained in the object set S4 can simultaneously satisfy the value range S of all participating analysis strategies. k2 .

[0158] (3) Check set S3. If set S3 is not empty, it is determined that the expected effectiveness of the strategies related to set S3 cannot coexist. If they are triggered at the same time, there is a potential conflict. Then the effectiveness relationship analysis ends and the execution relationship analysis continues. Otherwise, the target indicators of all the analysis strategies have an intersection. Even if they are triggered at the same time, there is still room for further collaboration and there is no absolute conflict.

[0159] (4) Check set S4, and for each managed object m in it, check S m2 If the above relationship holds true for all managed objects included in S4, then the input strategy has been included by other strategies, the strategy relationship analysis ends, there is no strategy conflict, and there is no need to explicitly add the strategy; otherwise, it is preliminarily determined that there is a target overlap relationship between the strategies, and the subsequent execution relationship analysis continues. If necessary, the relevant strategies can be optimized in combination with the S4 records.

[0160] For example, the above-mentioned stage four is specifically executed as follows:

[0161] By leveraging knowledge graph information applied to strategies, the relationships between execution elements of input strategies are analyzed to identify related strategies with conflicting, overlapping, or correlated execution elements. The execution relationship analysis steps include, but are not limited to:

[0162] (1) By utilizing the conflict, overlap and association relationships between the execution elements in the element instance knowledge of the strategy application knowledge graph, the direct and indirect relationships between the events, conditions and operations associated with the execution elements of the strategy are derived, and the system context parameters (input conditions and output conditions) set of all execution elements and their value ranges in the actual application of each strategy are obtained.

[0163] (2) Use policy application knowledge graphs to determine whether there is a possibility that the input policy can be triggered simultaneously:

[0164] Take the intersection S5 of the triggering event of the strategy and all its derived events. If S5 is not empty, the strategy can be triggered simultaneously by any event contained in S5; otherwise, take the union S6 of the triggering event of the strategy and all its derived events. Further utilize the mutual exclusion relationship between events in the strategy application knowledge graph to eliminate events with mutual exclusion relationships one by one, resulting in S7. If S7 is empty, the input strategies cannot be triggered simultaneously; otherwise, check whether the remaining events in S7 can still trigger multiple input strategies simultaneously.

[0165] If there is no possibility that the input strategy can be triggered simultaneously, the strategy is determined to be irrelevant and the strategy execution relationship analysis is exited; otherwise, the evaluation condition relationship analysis is continued.

[0166] (3) Use the strategy application knowledge graph to determine whether there is a possibility that the input strategies will be executed simultaneously after being triggered at the same time:

[0167] Take the intersection of the value ranges of the evaluation conditions and their derived conditions for each strategy, and use S8 to record the set of evaluation conditions that have multiple strategy references; use S9 to record each evaluation condition m belonging to S8 and its value range S that enables multiple strategies simultaneously. 9m ;

[0168] If both S8 and S9 are empty, it is determined that the strategies are unrelated, and the strategy execution relationship analysis ends.

[0169] If S9 is not empty, the input policy may be executed simultaneously when the S9 condition is met, and the relationship between policy execution actions can be further analyzed.

[0170] (4) Use the knowledge graph of the strategy application to determine whether there is a possibility of execution conflict when the input strategy is triggered and executed at the same time:

[0171] Take the union of the actions executed by the input policy and their derived actions;

[0172] By leveraging the mutual exclusion relationships between actions in the knowledge graph, we identify each action that has a mutual exclusion relationship. If so, we determine that there is a conflict between the input strategies.

[0173] By leveraging the inclusion relationships between actions in the knowledge graph, we identify whether there are any inclusion relationships among the actions. If so, we determine that there are inclusion relationships between the input strategies and the included strategy is a redundant strategy.

[0174] By leveraging the inclusion relationships between actions in the knowledge graph, we identify each action that has a derivative relationship. If so, we determine that there is a derivative relationship between the input strategies.

[0175] II. Strategy Optimization Processing

[0176] In this application example, the policy optimization process includes two parts:

[0177] First, based on the analysis results of the strategy relationship analysis, automatic / manual dynamic optimization is performed on the input strategy set.

[0178] Secondly, based on the analysis results of the strategy relationship analysis, the relevant information in the strategy knowledge base is dynamically improved.

[0179] To address this, a strategy optimization meta-strategy approach can be adopted to achieve an automatic closed loop of iterative optimization of the strategy itself and its management knowledge; alternatively, a reporting mechanism can be used to notify experts or external systems of the strategy analysis results and execute their feedback on strategy / knowledge optimization suggestions.

[0180] Specific mechanisms for automated strategy optimization include, but are not limited to:

[0181] Deactivate ineffective policies and simultaneously record / update the status of the corresponding policy instance in the knowledge base;

[0182] Deactivate redundant (included) policies, and simultaneously record / update the relationships between corresponding policy instances in the knowledge base;

[0183] Eliminate policy mutual exclusion relationships based on priority or other predefined meta-policies. Based on the priority level specified by static configuration / dynamic specification, differentiate mutually exclusive policies of different priorities according to the source of the policy (VIP customer business protection takes precedence over routine management and maintenance), the target of the policy (primary equipment takes precedence over backup equipment), and the performance indicators (business protection takes precedence over energy saving). Activate the low-priority policy instance, and record / update the status and mutual exclusion relationships of the policy instance in the policy knowledge base.

[0184] The following example illustrates the application of knowledge in this application embodiment, including knowledge of construction object instances, knowledge of policy instances, and knowledge of element instances, as detailed below:

[0185] Object instance knowledge

[0186] The strategy application knowledge graph maintains instance information for the current management domain and its subordinate managed objects for subsequent comprehensive analysis, including but not limited to:

[0187] Management Domain Instance Status: The instance status and hierarchical relationship of each level of management domain. For example, Beijing, Fengtai District, Data Center No. 1, and server rooms on floors 1-3 are different management domains with a sequential inclusion relationship.

[0188] Managed object instance status: The instance status and hierarchical relationship of individual managed objects under the jurisdiction of each management domain. For example, the Huawei 5GC (5G core network) primary equipment in the North China region is deployed in the first floor of the No. 1 data center in Fengtai District, Beijing, and the backup equipment is deployed in the No. 2 data center; while the ZTE 5GC primary equipment in the North China region is deployed in the No. 3 data center, and the backup equipment is deployed in the No. 2 data center. On the one hand, from a network perspective, each 5GC managed object consists of different types of NF (Network Function) elements, such as SMF (Session Management Function), AMF (Access and Mobility Management Function), and UPF (User Plane Function), along with their specific network topology connections. Each NF instance corresponds to a VNF (Virtual Network Function) instance, and a VNF instance can contain multiple VNFC (Virtualized Network Function Component) components. Each VNFC component can consist of a group of VMs (virtual machines) interconnected through specific network topology connections. On the other hand, from a resource perspective, each active VM corresponds to a process on a physical server, sharing all the physical resources (CPU, memory, network, etc.) of that physical server. Each server corresponds to a specific access slot location on a rack, sharing the bandwidth resources and power efficiency of the rack's ToR (Top of Rack) switch.

[0189] Strategy Example Knowledge

[0190] The strategy application knowledge graph maintains information for each strategy instance for subsequent comprehensive analysis, including but not limited to:

[0191] Policy instance status: Active, Suspended. For example, the VNFs, physical servers, ToR switches, routers, and other supporting equipment such as air conditioners in data centers 1 and 3, which host the primary equipment, are all in normal working condition, and their corresponding policy instances are all in an active state. Conversely, because the managed objects in data center 2 do not actually carry out business, the policy instances related to it are all in a suspended state.

[0192] The target scope of the strategy: the management domain and managed objects to which the strategy is applied. That is, the object instance knowledge mentioned above.

[0193] Effectiveness metrics for a strategy: These are indicators that evaluate the effectiveness of the strategy's application, such as functionality, performance, and availability. Examples include energy consumption metrics, business performance metrics, resource efficiency metrics, and redundancy assurance metrics.

[0194] The execution elements of the strategy are: the subscribed triggering event (e.g., time-driven events such as major holidays, specific times, seasons, and events), the condition variables on which it depends (e.g., threshold-driven conditions such as low energy efficiency, high load, and insufficient redundancy), and the execution operations invoked (e.g., VNF migration / shutdown / startup / reboot, link switching, physical shutdown / startup, increasing / decreasing redundancy, increasing / decreasing data center temperature, increasing CPU frequency / decreasing rack power consumption, etc.).

[0195] Element Instance Knowledge

[0196] The strategy application knowledge graph maintains information for each instance of the execution element referenced by the strategy, for subsequent comprehensive analysis, including but not limited to:

[0197] Event instance information: This allows reporting event instances and the relationships between them (derivative, mutual exclusion, etc.). For example, there is a derivative relationship between the National College Entrance Examination (Gaokao) and summer. There is a mutual exclusion relationship between the Gaokao and winter.

[0198] Condition instance information: This allows evaluation of condition instances and the relationships between them (inclusion, overlap, mutual exclusion, etc.). For example, simple conditions can be evaluated based on the inclusion, overlap, and mutual exclusion relationships between them due to the range of index values, while complex conditions can be evaluated based on the inclusion, overlap, and mutual exclusion relationships formed by the "AND," "OR," and "NOT" logical combinations of simple conditions.

[0199] Action instance information: Executable action instances and the relationships between action instances (inclusion, influence, mutual exclusion, etc.). For example, shrinking and expanding are mutually exclusive operations; physical shutdown includes the migration / shutdown of VNFs on it; increasing the CPU frequency of a server will potentially affect the power management operations of the rack it resides in.

[0200] Performance Indicator Information (Optional): The expected performance goals of the strategy application and the relationships between performance indicators (inclusion, influence, mutual exclusion, etc.). Similar to condition instance information, performance indicators can also be viewed as conditions or logical combinations of conditions, and therefore will also have interrelationships due to the indicator values ​​and the combination of conditions. For example, simple conditions may have inclusion, overlap, and mutual exclusion relationships due to the inclusion, overlap, and mutual exclusion relationships between them due to the "AND," "OR," and "NOT" logical combinations of simple conditions.

[0201] The following example illustrates the policy relationship analysis in this application embodiment. Taking a knowledge base for wireless network link resource pool management policies in a certain area as an example, some input policies are as follows:

[0202] Strategy A: From midnight to 6:00 AM daily, the bandwidth allocated to link A is adjusted to 300 Mbps; at other times, the bandwidth allocated to link A is restored to 500 Mbps. Performance metrics include link utilization (range: 50%-95%).

[0203] Strategy b: If the PRB utilization rate is greater than 50% during peak hours in the local cell, initiate load balancing between adjacent cells. Effectiveness metrics include PRB utilization rate (40%-60%).

[0204] Strategy c: When the link utilization of link A is greater than 85%, if the duration exceeds 60% of the runtime, the allocated bandwidth is adjusted to 800Mbps. Performance metrics include link utilization (range: 50%-95%).

[0205] Strategy d: During holidays, the bandwidth allocated to link A is adjusted to 800Mbps; during non-holiday periods, the bandwidth allocated to link A is restored to 500Mbps. Its effectiveness metrics include link utilization (range: 50%-95%).

[0206] Strategy e: From midnight to 6 a.m. each day, the bandwidth allocated to link B is adjusted to 300Mbps-500Mbps; at other times, the bandwidth allocated to link B is restored to 100Mbps-400Mbps. Its effectiveness metrics include link utilization (range: 50%-80%).

[0207] Strategy f allows devices X and Y to communicate via either link A or link B. When traffic between X and Y is low (below 200Mbps), link B is used exclusively; when traffic is between 200Mbps and 500Mbps, link A is used exclusively; and when traffic is high (above 500Mbps), link aggregation is employed. Effectiveness metrics include link utilization (ranging from 60% to 80%).

[0208] "Strategy Effectiveness Verification":

[0209] Among them, strategy b, "If the PRB utilization rate is greater than 50% during busy hours in this cell, enable load balancing between adjacent cells", is not applicable to the wireless network link resource pool management strategy knowledge base and is an invalid strategy in this knowledge base.

[0210] "Strategy Scope Relationship Analysis":

[0211] After validity verification, invalid strategy b was excluded. The remaining input strategy range relationships were analyzed, and the actual managed objects are as follows:

[0212] Strategy a, Link A

[0213] Strategy c, Link A

[0214] Strategy d, Link A

[0215] Strategy e, Link B

[0216] Strategy f, Link A and Link B

[0217] Analysis revealed that the management targets of the above strategies all overlap.

[0218] "Strategy Effectiveness Relationship Analysis":

[0219] Furthermore, a strategy effectiveness relationship analysis was conducted on strategies a, c, d, e, and f.

[0220] For the overlapping management objects, the analysis of the performance indicator link utilization rate is as follows:

[0221] Link utilization: The value ranges of strategies a, c, and d are consistent, while the value range of strategy e overlaps. Further analysis of the execution relationship is required.

[0222] "Strategy Execution Relationship Analysis"

[0223] Further analysis of the execution relationships of strategies a, c, d, e, and f:

[0224] Strategy a: From midnight to 6 a.m. every day, the bandwidth allocated to link A is adjusted to 300 Mbps; at other times, the bandwidth allocated to link A is restored to 500 Mbps.

[0225] The triggering event is from midnight to 6 a.m. every day; the evaluation condition is none; the action to be performed is to adjust the bandwidth allocated to link A to 500 Mbps.

[0226] Strategy c: When the link utilization of link A is greater than 85%, if the duration exceeds 60% of the running time, the allocated bandwidth is adjusted to 800Mbps.

[0227] Among them, the triggering event is when the link utilization of link A is greater than 85%; the evaluation condition is that the duration exceeds 60% of the running time; the action is to adjust the bandwidth to 800Mbps.

[0228] Strategy d: During holidays, the bandwidth allocated to link A is adjusted to 800Mbps; during non-holiday periods, the bandwidth allocated to link A is restored to 500Mbps.

[0229] Among them, the triggering event is: A link is running during holidays; the evaluation condition is: none; the action is: the bandwidth of A link is adjusted to 800Mbps.

[0230] Strategy e: From midnight to 6 a.m. every day, the bandwidth allocated to the B link is adjusted to 300Mbps-500Mbps; at other times, the bandwidth allocated to the B link is restored to 100Mbps-400Mbps.

[0231] Among them, the triggering event is from midnight to 6 a.m. every day; the evaluation condition is none; the action is to adjust the bandwidth allocated to link B to 300Mbps-500Mbps.

[0232] Strategy f: Devices X and Y can communicate via either link A or link B. When the traffic between X and Y is low (below 200Mbps), only link B is used; when the traffic between X and Y is between 200Mbps and 500Mbps, only link A is used; when the traffic between X and Y is too high (greater than 500Mbps), link aggregation is employed.

[0233] The triggering event is when the traffic between X and Y is too high; the evaluation condition is none; and the action to be performed is link aggregation.

[0234] For the managed objects with intersection, take the intersection of the triggering events of strategies a, c, d, e, and f, where:

[0235] The intersection of strategies a and c is triggered when the link utilization of link A is greater than 85% between midnight and 6 a.m. every day.

[0236] The intersection of strategies a and d triggers the event from midnight to 6 a.m. during holidays.

[0237] The intersection of strategies c and d is triggered when link A is running during holidays and the link utilization rate is greater than 85%.

[0238] Furthermore, the intersection of the evaluation conditions for strategies a, c, and d is taken respectively, where:

[0239] Strategies a and d have no evaluation conditions.

[0240] Finally, by taking the union of the execution actions of strategies a, c, and d and performing mutual exclusion and inclusion checks on each action, the analysis yields the following results:

[0241] Strategies a and c are mutually exclusive when the triggering event is between midnight and 6 a.m. every day, and the link utilization of link A is greater than 85%, thus constituting conflict strategies.

[0242] Strategies a and d are mutually exclusive in their actions when the triggering event is a holiday, from midnight to 6 a.m., making them conflicting strategies.

[0243] When strategies c and d are triggered during holidays and link A is running, and the link utilization is greater than 85%, the same action is taken: allocating bandwidth to maintain 30MHz. This is a derivative relationship.

[0244] For the management objects that intersect, the implicit relationship between link A and link B is obtained through knowledge reasoning for strategy f. That is, when the traffic between X and Y is too large (greater than 500Mbps), the link utilization rate of the aggregated link A and link B is between 60% and 80%.

[0245] Analysis of the superposition of strategies a, c, d, e, and f:

[0246] The intersection of strategies a, e, and f is triggered by the following event: from midnight to 6 a.m. every day, when the traffic between X and Y is too high (greater than 500 Mbps);

[0247] The intersection of strategies d, e, and f is triggered by the following event: from midnight to 6 a.m. during holidays, when the traffic between X and Y is too high (greater than 500 Mbps).

[0248] The intersection of strategies c, e, and f is triggered by the following event: from midnight to 6 a.m. every day, when the traffic between X and Y is too high (greater than 500 Mbps) and the link utilization of link A is greater than 85%.

[0249] Furthermore, taking the intersection of the evaluation conditions, only strategy c has evaluation conditions if the duration exceeds 60% of the runtime.

[0250] Finally, by taking the union of the execution actions of strategies a, c, d, e, and f and performing mutual exclusion and inclusion checks on each action, the analysis yields the following results:

[0251] Strategies a, e, and f have overlapping actions when the triggering event is between midnight and 6 a.m. every day. This is a derivative relationship.

[0252] Strategies d, e, and f have overlapping actions when the triggering event is from midnight to 6 a.m. on a holiday, which constitutes a derivative relationship.

[0253] Strategies c, e, and f have overlapping actions when link A is run during a holiday period and the link utilization is greater than 85%. This is a derivative relationship.

[0254] In order to implement the method of the embodiments of this application, the embodiments of this application also provide a network policy management device, which corresponds to the network policy management method described above. The steps in the embodiments of the network policy management method described above are also fully applicable to the embodiments of the network policy management device.

[0255] like Figure 3As shown, the network policy management device includes: an acquisition module 301, an analysis module 302, and an optimization module 303. The acquisition module 301 acquires at least one target policy instance for network management; the analysis module 302 performs policy relationship analysis on the at least one target policy instance and existing policy instances based on policy application knowledge to obtain policy relationship analysis results; the optimization module 303 optimizes the at least one target policy instance and existing policy instances based on the policy relationship analysis results.

[0256] For example, the acquisition module 301 acquires at least one instance of a target policy for network management, including at least one of the following:

[0257] Obtain at least one instance of the target strategy imported from outside;

[0258] Obtain at least one instance of the target policy for internal monitoring.

[0259] For example, the network policy management device further includes a construction module 304, which is used to construct the policy application knowledge based on policy instance knowledge and / or network management object instance knowledge.

[0260] For example, the strategy application knowledge includes at least one of the following: object instance knowledge, strategy instance knowledge, and feature instance knowledge, wherein the object instance knowledge is used to characterize object instances, the strategy instance knowledge is used to characterize strategy instances, and the feature instance knowledge is used to characterize feature instances. The analysis module 302 is specifically used for:

[0261] Based on the policy instance knowledge, the policy effectiveness of the at least one target policy instance is verified to obtain a set of policy instances with valid policies; and / or,

[0262] For the set of effective strategy instances and existing strategy implementations, a scope analysis is performed based on the object instance knowledge to obtain a set of strategy instances where the strategy is effective and their scopes overlap; and / or,

[0263] Perform effectiveness relationship analysis on the set of strategy instances where the strategy is effective and their scopes overlap to obtain a set of strategy instances that meet the defined effectiveness relationship; and / or,

[0264] An execution relationship analysis is performed on the set of strategy instances that conform to the set of performance relationships to obtain a set of strategy instances whose execution elements satisfy the set of execution relationships.

[0265] For example, the strategy instance knowledge includes: performance indicator information representing the expected effect of the strategy instance; the analysis module 302 performs performance relationship analysis on the set of strategy instances where the strategy is effective and their scope of action overlaps, to obtain a set of strategy instances that conform to the set performance relationship, including:

[0266] Based on the performance indicator information, determine the relationship between performance indicators in the set of strategy instances where the strategy is effective and their scope of action overlaps.

[0267] Based on the relationship between the aforementioned performance indicators, a set of strategy instances that conform to the set performance relationship is obtained;

[0268] The established performance relationship includes at least one of the following: performance indicators conflict, performance indicators overlap, and performance indicators are included.

[0269] For example, the analysis module 302 performs execution relationship analysis on the set of strategy instances that conform to the set of set performance relationships, and obtains strategy instances whose execution elements satisfy the set execution relationships, including:

[0270] Based on the knowledge of the element instances, determine the relationship between the execution elements in the set of strategy instances that conform to the set of effect relationships;

[0271] Based on the relationships between the execution elements, a set of strategy instances in which the execution elements satisfy the defined execution relationships is obtained;

[0272] The set execution relationship includes at least one of the following: conflicting execution elements, overlapping execution elements, and associated execution elements.

[0273] For example, the optimization module 303 is specifically used for:

[0274] Based on the results of the strategy relationship analysis, the at least one target strategy instance and the existing strategy instance are automatically or manually optimized.

[0275] For example, the optimization module 303 automatically optimizes the at least one target policy instance and the existing policy instance based on the strategy relationship analysis results, including at least one of the following:

[0276] Delete and / or deactivate invalid policy instances;

[0277] Delete and / or deactivate redundant policy instances;

[0278] Based on priority policies, delete and / or deactivate low-priority policy instances.

[0279] For example, the optimization module 303 is also used for:

[0280] Based on the results of the strategy relationship analysis, the strategy application knowledge is updated.

[0281] In practical applications, the acquisition module 301, analysis module 302, optimization module 303, and construction module 304 can be implemented by the processor in the network policy management device. Of course, the processor needs to run the computer program in memory to implement its functions.

[0282] It should be noted that the network policy management device provided in the above embodiments is only illustrated by the division of the above program modules when managing network policies. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the network policy management device and the network policy management method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0283] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide an electronic device. Figure 4 The diagram shows only an exemplary structure of the electronic device, not the entire structure; implementation is possible as needed. Figure 4 The structure shown may be part or all of the structure.

[0284] like Figure 4 As shown, the electronic device 400 provided in this application embodiment includes: at least one processor 401, a memory 402, a user interface 403, and at least one network interface 404. The various components in the electronic device 400 are coupled together via a bus system 405. It can be understood that the bus system 405 is used to implement communication between these components. In addition to a data bus, the bus system 405 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 4 The general designated all buses as Bus System 405.

[0285] The user interface 403 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.

[0286] The memory 402 in this embodiment is used to store various types of data to support the operation of the electronic device. Examples of such data include any computer program used to operate on the electronic device.

[0287] The network policy management method disclosed in this application embodiment can be applied to or implemented by processor 401. Processor 401 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the network policy management method can be completed by integrated logic circuits in the hardware of processor 401 or by instructions in software form. The processor 401 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 401 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, specifically memory 402. Processor 401 reads information from memory 402 and, in conjunction with its hardware, completes the steps of the network policy management method provided in the embodiments of this application.

[0288] In an exemplary embodiment, the electronic device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0289] It is understood that memory 402 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), Sync Link Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.

[0290] In an exemplary embodiment, this application also provides a computer storage medium, specifically a computer-readable storage medium, such as a memory 402 storing a computer program, which can be executed by a processor 401 of an electronic device to complete the steps described in the method of this application embodiment. The computer-readable storage medium can be a ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.

[0291] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0292] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0293] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method of managing network policies, characterized by, The method comprises the following steps: acquiring at least one target policy instance for network management; performing policy relationship analysis on the at least one target policy instance and existing policy instances based on policy application knowledge, to obtain a policy relationship analysis result; performing optimization processing on the at least one target policy instance and the existing policy instances based on the policy relationship analysis result; the policy application knowledge comprises at least one of object instance knowledge, policy instance knowledge and element instance knowledge, the object instance knowledge is used to represent object instances, the policy instance knowledge is used to represent policy instances, and the element instance knowledge is used to represent element instances, and the policy relationship analysis based on the policy application knowledge comprises the following steps: verifying the policy effectiveness of the at least one target policy instance based on the policy instance knowledge, to obtain a set of policy instances with policy effectiveness; performing scope analysis on the set of policy instances with policy effectiveness and the existing policy instances based on the object instance knowledge, to obtain a set of policy instances with policy effectiveness and scope intersection; performing effectiveness relationship analysis on the set of policy instances with policy effectiveness and scope intersection, to obtain a set of policy instances meeting a set effectiveness relationship; performing execution relationship analysis on the set of policy instances meeting the set effectiveness relationship, to obtain a set of policy instances meeting a set execution relationship.

2. The method of claim 1, wherein, The method further comprises the following steps: constructing the policy application knowledge based on policy instance knowledge and / or network management object instance knowledge. The policy instance knowledge comprises effectiveness index information representing the expected effect of policy instances, and the effectiveness relationship analysis on the set of policy instances with policy effectiveness and scope intersection comprises the following steps:

3. The method of claim 1, wherein, determining the relationship between effectiveness indexes in the set of policy instances with policy effectiveness and scope intersection based on the effectiveness index information; obtaining the set of policy instances meeting the set effectiveness relationship based on the relationship between the effectiveness indexes; 4. The method of claim 1, wherein, wherein the set effectiveness relationship comprises at least one of the following: effectiveness index conflict, effectiveness index overlap and effectiveness index inclusion. The execution relationship analysis on the set of policy instances meeting the set effectiveness relationship comprises the following steps: determining the relationship between execution elements in the set of policy instances meeting the set effectiveness relationship based on the element instance knowledge; obtaining the set of policy instances meeting the set execution relationship based on the relationship between the execution elements; 5. The method of claim 1, wherein, wherein the set execution relationship comprises at least one of the following: execution element conflict, execution element overlap and execution element association. The optimization processing on the at least one target policy instance and the existing policy instances based on the policy relationship analysis result comprises the following steps: ​ ​ 6. The method of claim 1, wherein, ​ Based on the policy relationship analysis result, the at least one target policy instance and the existing policy instances are automatically or manually optimized.

7. The method of claim 6, wherein, Based on the policy relationship analysis result, the at least one target policy instance and the existing policy instances are automatically optimized, including at least one of the following: deleting and / or deactivating non-effective policy instances; deleting and / or deactivating redundant policy instances; deleting and / or deactivating low-priority policy instances based on priority policy.

8. The method of claim 1, wherein, After the optimization of the at least one target policy instance based on the policy relationship analysis result, the method further includes: updating the policy application knowledge based on the policy relationship analysis result.

9. A network policy management apparatus characterized by comprising: including: an acquisition module configured to acquire at least one target policy instance for network management; an analysis module configured to analyze policy relationship of the at least one target policy instance and the existing policy instances based on policy application knowledge, to obtain a policy relationship analysis result; an optimization module configured to optimize the at least one target policy instance and the existing policy instances based on the policy relationship analysis result; The policy application knowledge includes at least one of the following: object instance knowledge, policy instance knowledge and element instance knowledge, the object instance knowledge is used to represent object instances, the policy instance knowledge is used to represent policy instances, and the element instance knowledge is used to represent element instances, and the analysis module is specifically configured to: verify policy effectiveness of the at least one target policy instance based on the policy instance knowledge, to obtain a set of policy instances with effective policies; based on the object instance knowledge, analyze the set of policy instances with effective policies and the existing policy instances in terms of action scope, to obtain a set of policy instances with effective policies and intersecting action scopes; analyze the set of policy instances with effective policies and intersecting action scopes in terms of effectiveness relationship, to obtain a set of policy instances meeting set effectiveness relationship; analyze the set of policy instances meeting set effectiveness relationship in terms of execution relationship, to obtain a set of policy instances with execution elements meeting set execution relationship.

10. An electronic device, comprising: including: a processor and a memory for storing a computer program capable of running on the processor, wherein, the processor is configured to execute the computer program to perform the steps of the method of any one of claims 1 to 8.

11. A computer storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 8.

Citation Information

Patent Citations

  • Policy management method, device, equipment and system for network slicing

    CN109768875A

  • Intelligent security policy configuration method based on target perception

    CN113328996A