An information determination method, apparatus, device, computer storage medium, and computer program product

By acquiring and analyzing tunnel traffic and configuration information in the network topology, the direction of service traffic within the TE tunnel is determined, solving the traffic analysis problem in the TE tunnel scenario and realizing end-to-end traffic identification and fine-grained scheduling.

CN118827469BActive Publication Date: 2025-11-18CHINA MOBILE COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410238902.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-01
Publication Date
2025-11-18
Estimated Expiration
2044-03-01

AI Technical Summary

Technical Problem

Existing technologies cannot analyze the traffic flow of specific services in TE tunnel scenarios, and cannot achieve traffic engineering analysis of services within the tunnel.

Method used

By acquiring tunnel traffic data and configuration information in the network topology, the target routing information for each route is determined, and based on the network traffic data and configuration information, the virtual private network traffic of each service data in the path is calculated, thereby achieving refined analysis of service traffic within the TE tunnel.

Benefits of technology

It enables end-to-end traffic identification within TE tunnels, filling the functional gaps in fine-grained scheduling of service traffic and abnormal traffic monitoring in tunnel scenarios, and helping network maintenance personnel to identify network resource bottlenecks and adjust traffic paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827469B_ABST
    Figure CN118827469B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a method for determining information, which comprises: obtaining network traffic data of a tunnel in a to-be-processed network topology structure and configuration information of the tunnel; determining target routing information of each route corresponding to the to-be-processed network topology structure; and determining first virtual private network traffic of each service data based on the to-be-processed network topology structure, the network traffic data, the target routing information and the configuration information, wherein the first virtual private network traffic is virtual private network traffic required for transmission of the each service data in each sub-path of a first path. Embodiments of the present application also disclose an information determining apparatus, device, computer readable storage medium and computer program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to an information determination method, apparatus, device, computer storage medium, and computer program product. Background Technology

[0002] Existing technologies used in operator backbone networks can only achieve port-level traffic statistics. Specifically, traffic acquisition technologies mainly include traffic acquisition technology based on Simple Network Management Protocol (SNMP) and traffic acquisition technology based on network monitoring functions (i.e., NetFlow). Among them, SNMP-based traffic acquisition technology is only used to collect basic traffic information, thus only realizing overall traffic analysis of network device ports, and cannot analyze the traffic flow of specific services within Traffic Engineering (TE) tunnels. While NetFlow-based traffic acquisition technology can collect traffic at specific locations and analyze information such as source and destination addresses, it also cannot analyze the traffic flow of specific services within TE tunnels. Summary of the Invention

[0003] To address the aforementioned technical problems, this application aims to provide an information determination method, apparatus, device, computer storage medium, and computer program product that can solve the problem in related technologies of being unable to analyze the traffic flow of specific services within a TE tunnel.

[0004] The technical solution of this application is implemented as follows:

[0005] An information determination method, the method comprising:

[0006] Obtain network traffic data and configuration information of the tunnels in the network topology to be processed;

[0007] Determine the target routing information for each route corresponding to the network topology to be processed;

[0008] Based on the network topology to be processed, the network traffic data, the target routing information, and the configuration information, the first virtual private network traffic for each service data is determined; wherein, the first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

[0009] In the above scheme, determining the target routing information for each route corresponding to the network topology to be processed includes:

[0010] Collect the route information to be filtered for each route; wherein, the route information to be filtered includes at least the route destination and the route identifier;

[0011] The target routing information is obtained by merging the routing target and the routing identifier.

[0012] In the above scheme, determining the first virtual private network traffic for each service data based on the network topology to be processed, the network traffic data, the target routing information, and the configuration information includes:

[0013] Based on the configuration information, the second path corresponding to the tunnel is determined;

[0014] Based on the network topology to be processed, the network traffic data, the target routing information, and the second path, the first path is determined;

[0015] For each piece of service data, determine the first virtual private network traffic required for the transmission of the service data in each sub-path of the first path.

[0016] In the above scheme, determining the second path corresponding to the tunnel based on the configuration information includes...

[0017] The configuration information is analyzed to determine multiple paths to be selected for the tunnel;

[0018] The cost information of each of the paths to be screened is determined, and the second path is determined from the plurality of paths to be screened based on the multiple cost information; wherein the cost information characterizes the merits of the paths to be screened.

[0019] In the above scheme, determining the first path based on the network topology to be processed, the network traffic data, the target routing information, and the second path includes:

[0020] Based on the target routing information and the network traffic data, determine the first address of the source route in the network topology to be processed;

[0021] Based on the first address, the second address of the destination route in the network topology to be processed, and the network topology to be processed, the third path of the virtual private network traffic is determined;

[0022] The first path is determined based on the second path and the third path; wherein the network traffic data includes the second address.

[0023] In the above scheme, determining the first address of the source route in the network topology to be processed based on the target routing information and the network traffic data includes:

[0024] Based on network hop information, virtual private network label, second address, and multiprotocol label switching label, a target route identifier is determined from the target routing information; wherein, the target routing information includes the network hop information and the virtual private network label, and the network traffic data includes the multiprotocol label switching label;

[0025] The address prefix is ​​determined from the target routing information based on the target routing identifier and the source address; wherein the target routing information includes the source address;

[0026] The first address is determined based on the address prefix and the network hop information.

[0027] In the above scheme, for each piece of service data, determining the first virtual private network traffic required for the transmission of the service data in each sub-path of the first path includes:

[0028] Determine the second virtual private network traffic between the first address and the second address;

[0029] For each of the service data, the first virtual private network traffic is determined based on the second virtual private network traffic.

[0030] An information determining device, the device comprising:

[0031] The acquisition unit is used to acquire network traffic data of tunnels in the network topology to be processed and the configuration information of the tunnels;

[0032] A determining unit is used to determine the target routing information for each route corresponding to the network topology to be processed;

[0033] The processing unit is configured to determine the first virtual private network traffic for each service data based on the network topology to be processed, the network traffic data, the target routing information, and the configuration information; wherein the first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

[0034] An information determining device, the device comprising: a processor, a memory, and a communication bus;

[0035] The communication bus is used to realize the communication connection between the processor and the memory;

[0036] The processor is used to execute the information determination program stored in the memory to implement the steps of the above-described information determination method.

[0037] A computer-readable storage medium storing one or more programs that can be executed by one or more processors to perform the steps of the information determination method described above.

[0038] A computer program product includes a computer program that, when executed by a processor, implements the steps of the information determination method described above.

[0039] The information determination method, apparatus, device, computer storage medium, and computer program product provided in this application first acquire network traffic data and tunnel configuration information of tunnels in the network topology to be processed. Then, it determines the target routing information of each route corresponding to the network topology to be processed. Subsequently, based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, it determines the first virtual private network traffic of each service data. The first virtual private network traffic is the virtual private network traffic required for the transmission of each service data in each sub-path of the first path. In this way, by acquiring and analyzing the tunnel configuration information, the traffic flow direction of specific services inside the tunnel can be determined. Based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, it is jointly determined that different services are transparently transmitted in the same TE tunnel, realizing end-to-end traffic identification throughout the entire process. This not only solves the traffic analysis problem in tunnel scenarios but also fills the functional gaps in fine-grained scheduling of service traffic and abnormal traffic monitoring in tunnel scenarios. Attached Figure Description

[0040] Figure 1 A flowchart illustrating an information determination method provided in an embodiment of this application;

[0041] Figure 2 This is a network topology diagram of an information determination method provided in an embodiment of this application;

[0042] Figure 3 A flowchart illustrating another information determination method provided in an embodiment of this application;

[0043] Figure 4 This is a schematic diagram of the structure of an information determination device provided in an embodiment of this application;

[0044] Figure 5 This is a schematic diagram of the structure of an information determination device provided in an embodiment of this application. Detailed Implementation

[0045] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0046] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.

[0047] It should be noted that the various services accessed by the operator's backbone network can be isolated using different Virtual Private Networks (VPNs). The operator's backbone network deploys Label Distribution Protocol (LDP) to generate Label Switched Paths (LSPs) (i.e., LDP LSPs) for label forwarding. In the core area of ​​the operator's backbone, Multiprotocol Label Switching Traffic Engineering (MPLS TE) technology is deployed, which uses LDP and MPLS TE (i.e., LDP over MPLS TE) for label forwarding. By establishing Traffic Engineering (TE) tunnels, the outgoing interface of the originating router selects the TE tunnel (logical port), and packets are transparently transmitted through the TE tunnel, achieving advantages such as path switching protection and path planning. In an MPLS TE VPN environment, different VPNs or different services under the same VPN can be transparently transmitted in the same TE tunnel. Therefore, traffic collection from the tunnel interface cannot be used to analyze the traffic of specific services. All devices in the TE tunnel forward traffic through tunnel labels, making it impossible to obtain VPN information contained in the traffic of all devices.

[0048] Currently, operator backbone networks only support interface-level traffic collection and lack related tunnel VPN traffic analysis technologies. Specifically, among related technologies, the first method involves obtaining routing tables from the target provider edge device (PE) and collecting traffic via NetFlow. Based on MPLS LDP labels and routing information, the address information of the source provider edge device (i.e., the source PE) is obtained, thus revealing VPN traffic. The second method is based on SNMP traffic collection technology. While SNMP collects basic traffic information and can only perform overall traffic analysis of network device ports, it cannot deeply analyze the traffic flow of specific services within a TE tunnel scenario. Although it can collect traffic from specific locations and analyze source and destination addresses, neither of these technologies can provide in-depth analysis of the specific service traffic flow within the tunnel.

[0049] Based on this, embodiments of this application provide an information determination method, which can be applied to an information determination device, as described above. Figure 1 As shown, the method includes the following steps:

[0050] Step 101: Obtain network traffic data and tunnel configuration information of the tunnels in the network topology to be processed.

[0051] In this embodiment, the network topology to be processed can refer to the topology of the VPN traffic to be determined, and the network topology to be processed can be collected through the Border Gateway Protocol-Link State (BGP-LS) protocol; network traffic data can be collected through NetFlow technology, specifically by first configuring the NetFlow v9 protocol on the sampling device and then performing NetFlow sampling at the sampling device to obtain network traffic data, and the network traffic data can include the target route PE address and Multiprotocol Label Switching (MPLS) label; the controller can collect tunnel configuration information at intermediate routes in the network topology to be processed.

[0052] In one feasible implementation, the network topology to be processed can be as follows: Figure 2 The topology shown specifically includes source route (PE1), destination route (PE2), intermediate routes (P1, P2, P3, and P4), and the tunnel (Tunnel1) can be established between P1 and P2 (i.e., the dashed line part); the sampling device can refer to the P device (P1) at the tunnel entrance.

[0053] It should be noted that the network traffic data collected by NetFlow technology is parsed and processed by the controller. As shown in Table 1 below, the fields 46-47 are defined for the target route PE address in the NetFlow v9 protocol. As shown in Table 2 below, the fields 70-79 are defined for the MPLS label in the NetFlow v9 protocol. The MPLS label is determined according to the bottom-of-stack attribute in the MPLS label.

[0054] Table 1

[0055]

[0056] Table 2

[0057]

[0058] Step 102: Determine the target routing information for each route corresponding to the network topology to be processed.

[0059] In this embodiment of the application, the target routing information may refer to the routing information of the obtained routes after processing; the routing information of each route (i.e., the routing information to be filtered) can be obtained through the BGP-LS protocol, and then the routing information to be filtered is processed to obtain the target routing information; it should be noted that the routing information of each route can be obtained through the BGP-LS protocol, specifically by establishing a BGP neighbor with the network route reflector (VPN RR) through the controller, thereby collecting the corresponding routing information to be filtered.

[0060] Step 103: Based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, determine the first virtual private network traffic for each service data.

[0061] The first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

[0062] In this embodiment, the tunnel configuration information can be processed first to obtain the processing result, and then the network topology, network traffic data, target routing information and processing result to be processed can be further processed to determine the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

[0063] It should be noted that by collecting target routing information and the network topology to be processed through the controller, analyzing the tunnel configuration information, and correlating the target routing information with network traffic data, the controller can perform single service traffic analysis in MPLS TE tunnel scenarios. This allows for in-depth analysis of the service situation and helps network maintenance personnel to promptly identify network resource bottlenecks, adjust traffic paths according to customer needs, and detect attack traffic within VPNs. This provides effective decision support for network maintenance personnel in fault location during network planning and daily operation and maintenance.

[0064] The information determination method provided in this application obtains and analyzes the tunnel configuration information to determine the traffic flow direction of specific services within the tunnel. Based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, it jointly determines that different services are transparently transmitted in the same TE tunnel, achieving end-to-end traffic identification throughout the entire process. This not only solves the traffic analysis problem in tunnel scenarios but also fills the functional gaps in fine-grained scheduling of service traffic and abnormal traffic monitoring in tunnel scenarios.

[0065] Based on the foregoing embodiments, embodiments of this application provide an information determination method, referring to... Figure 3 As shown, the method may include the following steps:

[0066] Step 201: The information determination device obtains network traffic data and tunnel configuration information of the tunnel in the network topology to be processed.

[0067] Step 202: The information determination device collects the route information to be filtered for each route.

[0068] The routing information to be filtered includes at least the routing target and the routing identifier.

[0069] In this embodiment, the route information to be filtered, as shown in Table 3 below, can be obtained through the BGP-LS protocol. Specifically, it includes the route's network hop information (Nexthop), virtual private network label (Label), route distinguisher (RD), route target (RT), and address prefix (Prefix):

[0070] Table 3

[0071] Prefix RD RT Label Nexthop 2.2.1.0 / 24 200:1 200:1 200:2 10 20.20.20.1 2.2.2.0 / 24 200:2 200:2 11 20.20.20.2 2.2.3.0 / 24 200:3 200:3 12 20.20.20.3 2.2.4.0 / 24 200:1 200:1 14 20.20.20.4

[0072] Step 203: The information determination device merges the routing information to be filtered based on the routing target and routing identifier to obtain the target routing information.

[0073] In this embodiment of the application, routes with the same RT but different RDs can be merged. Specifically, merging the routes with the same RT but different RDs in Table 3 above yields the target route information (i.e., the RD pseudo-route table) shown in Table 4 below:

[0074] Table 4

[0075] Prefix RD Label Nexthop 2.2.1.0 / 24 200:1 10 20.20.20.1 2.2.2.0 / 24 200:2 11 20.20.20.2 2.2.1.0 / 24 200:2 10 20.20.20.1 2.2.3.0 / 24 200:3 12 20.20.20.3 2.2.4.0 / 24 200:1 14 20.20.20.4

[0076] It should be noted that RT 200:2 in Table 3 above corresponds to RD 200:1 (e.g., Figure 2 ①) and RD 200:2 (as in Figure 2 If the routes in ②) are both included, then the pseudo-routing tables of RD 200:1 and RD 200:2 should both contain routes 2.2.1.0 / 24 and 2.2.2.0 / 24.

[0077] Step 204: The information determination device determines the second path corresponding to the tunnel based on the tunnel's configuration information.

[0078] In this embodiment of the application, the second path may refer to the actual network traffic forwarding topology corresponding to the tunnel; the second path may be determined based on configuration information and path cost information.

[0079] It should be noted that step 204 can be achieved in the following way:

[0080] Step 204A1: The information determination device analyzes the configuration information and determines multiple paths to be screened for the tunnel.

[0081] In one feasible implementation, the multiple paths to be filtered for the tunnel obtained by analyzing the configuration information can refer to, for example: Figure 2 P1-P2-P3 and P1-P4-P3 are shown.

[0082] Step 204A2: The information determination device determines the cost information of each path to be screened, and determines the second path from multiple paths to be screened based on multiple cost information.

[0083] Among them, cost information represents the merits of the path to be screened.

[0084] In this embodiment of the application, the cost information of each path to be screened can be determined based on the cost information (i.e., cost value) of the sub-paths in each path to be screened. Then, multiple cost information are compared to determine the path with the smallest cost information as the path corresponding to the tunnel (i.e., the second path).

[0085] In one feasible implementation, such as Figure 2 As shown, when the paths to be filtered are P1-P2-P3 and P1-P4-P3, and for the path to be filtered P1-P2-P3, the cost value of the sub-path from P1 to P2 is 100, and the cost value of the sub-path from P2 to P3 is 100, then the cost value of the path to be filtered P1-P2-P3 is 200; for the path to be filtered P1-P4-P3, the cost value of the sub-path from P1 to P4 is 110, and the cost value of the sub-path from P4 to P3 is 110, then the cost value of the path to be filtered P1-P4-P3 is 220. Therefore, it can be seen that the cost value of the path to be filtered P1-P2-P3 is greater than the cost value of the path to be filtered P1-P4-P3, so the path to be filtered P1-P2-P3 can be determined as the second path.

[0086] Step 205: The information determination device determines the first path based on the network topology to be processed, network traffic data, target routing information, and the second path.

[0087] In this embodiment of the application, a third path can be determined first based on the network topology to be processed, network traffic data and target routing information, and then a first path can be determined based on the third path and the second path.

[0088] It should be noted that step 205 can be achieved in the following way:

[0089] Step 205B1: The information determination device determines the first address of the source route in the network topology to be processed based on the target routing information and network traffic data.

[0090] In this embodiment of the application, the first address may refer to the address of the source route; the target route information and network traffic data can be associated to obtain the target route identifier, and then the first address of the source route can be determined based on the target route identifier.

[0091] It should be noted that by associating network traffic data with device tunnel configuration information and target routing information, it can be used to analyze VPN service traffic within the TE tunnel. Furthermore, it can analyze the entire path and traffic of all devices in a two-layer label traffic forwarding scenario where MPLS labels and Resource Reservation Protocol-Traffic Engineering (RSVP TE) labels are nested.

[0092] It should be noted that step 205B1 can be achieved in the following way:

[0093] Step 205b1: The information determining device determines the target route identifier from the target routing information based on network hop information, virtual private network label, second address and multiprotocol label switching label.

[0094] The target routing information includes network hop information and virtual private network labels, while the network traffic data includes multiprotocol label switching labels.

[0095] It should be noted that, in addition to the destination route PE address and MPLS label, network traffic data may also include source address, destination address, and other data (such as traffic volume), as shown in Table 5 below:

[0096] Table 5

[0097] Source address Destination address Second address MPLS tags Other data 2.2.1.1 2.2.4.1 20.20.20.4 14 ... 2.2.1.2 2.2.2.1 20.20.20.2 11 ...

[0098] In this embodiment of the application, the target route identifier is determined by matching the target route PE address and MPLS label in the network traffic data with the target route information shown in Table 4 above. The target route PE address in the network traffic data corresponds to the Nexthop of the target route information shown in Table 4 above, and the MPLS label in the network traffic data corresponds to the Virtual Private Network label (Label) of the target route information shown in Table 4 above.

[0099] Step 205b2: The information determining device determines the address prefix from the target routing information based on the target routing identifier and the source address.

[0100] The target routing information includes the source address.

[0101] In this embodiment of the application, based on the source address and the target route identifier determined in step 205b1 above, the address prefix of the corresponding VPN is found from the target route information shown in Table 4 above using the longest route matching algorithm.

[0102] Step 205b3: The information determining device determines the first address based on the address prefix and network hop information.

[0103] In this embodiment of the application, network jump information can be determined based on the address prefix, and then the network jump information can be determined as the first address (that is, the network jump information is the first address).

[0104] It should be noted that the data table obtained after associating the target routing information and network traffic data is shown in Table 6 below:

[0105] Table 6

[0106] Source address Destination address Second address MPLS tags Other data RD First address 2.2.1.1 2.2.4.1 20.20.20.4 14 ... 200:1 20.20.20.1 2.2.1.2 2.2.2.1 20.20.20.2 11 ... 200:2 20.20.20.1

[0107] Step 205B2: The information determining device determines the third path of the virtual private network traffic based on the first address, the second address of the destination route in the network topology to be processed, and the network topology to be processed.

[0108] The network traffic data includes the second address of the destination route.

[0109] In this embodiment of the application, the network topology to be processed is as follows: Figure 2 In the case shown, by combining the first address of the source route, the second address of the destination route, and the network topology to be processed, the third path can be calculated as PE1-P1-Tunnel1-P3-PE2.

[0110] Step 205B3: The information determination device determines the first path based on the second and third paths.

[0111] In this embodiment, the tunnel in the third path can be replaced by the second path to obtain the first path; in one feasible implementation, the third path is as follows: Figure 2 Given the path PE1-P1-Tunnel1-P3-PE2 and the second path is P1-P2-P3, then the first path is PE1-P1-P2-P3-PE2.

[0112] Step 206: For each service data, the information determination device determines the first virtual private network traffic required for the transmission of the service data in each sub-path of the first path.

[0113] In this embodiment of the application, the first virtual private network traffic can refer to the virtual private network traffic (i.e., VPN traffic) required for the transmission of service data in each sub-path of the first path; the VPN traffic from the source route to the destination route in the first path can be obtained by analysis first, and then the first virtual private network traffic of each sub-path can be determined based on the traffic consistency principle.

[0114] It should be noted that step 206 can be achieved in the following way:

[0115] Step 206C1: The information determination device determines the second virtual private network traffic between the first address and the second address.

[0116] In this embodiment of the application, the second virtual private network traffic between the first address and the second address is the VPN traffic from the source route to the destination route (i.e., PE1-PE2); the VPN traffic obtained from PE1-PE2 can be analyzed based on the principle of traffic consistency.

[0117] Step 206C2: For each service data, the information determination device determines the first virtual private network traffic based on the second virtual private network traffic.

[0118] In this embodiment of the application, after obtaining the second VPN traffic of PE1-PE2, the VPN traffic of the intermediate route (i.e., the first VPN traffic) can be estimated. By iterating through the traffic size P1-P2, P2-P3, and P3-PE2, the first VPN traffic required for the transmission of service data in each sub-path can be determined, thereby realizing end-to-end traffic analysis of the corresponding VPN path.

[0119] It should be noted that when P1-P2 is interrupted, the TE primary path (i.e., P1-P2-P3) becomes invalid. The TE backup path (i.e., PE1-P1-P4-P3-PE2) is calculated through the Internet Gateway Protocol (IGP) and takes effect. The traffic is estimated and iterated to P1-P2, P3-P4, and P4-PE2.

[0120] In other embodiments of this application, custom traffic query analysis can also be performed. Specifically, by using the collected data (i.e., network traffic data, tunnel configuration information, and target routing information), custom query content such as source address, destination address, MPLS label, etc. can be used to perform corresponding traffic flow analysis. The corresponding query content, such as source address, destination address, MPLS label, etc., can be selected on the controller to realize the analysis of corresponding average flow rate, average packet rate, and flow rate ratio.

[0121] In other embodiments of this application, end-to-end traffic flow analysis of VPN services can also be performed. Specifically, end-to-end traffic flow analysis of VPN services can be achieved through correlation analysis of network traffic data (i.e., NetFlow data). The corresponding VPN link information can be displayed on the controller, and the service traffic data of the corresponding VPN on each link can be viewed. Statistical analysis and visualization of dimensions such as traffic component trend chart and average traffic component bar chart can be achieved separately.

[0122] The information determination method provided in this application obtains and analyzes the tunnel configuration information to determine the traffic flow direction of specific services within the tunnel. Based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, it jointly determines that different services are transparently transmitted in the same TE tunnel, achieving end-to-end traffic identification throughout the entire process. This not only solves the traffic analysis problem in tunnel scenarios but also fills the functional gaps in fine-grained scheduling of service traffic and abnormal traffic monitoring in tunnel scenarios.

[0123] Based on the foregoing embodiments, this application provides an information determining device, which can be applied to... Figure 1 and Figure 3 In the information determination method provided in the corresponding embodiment, refer to Figure 4 As shown, the information determination 3 may include: an acquisition unit 31, a determination unit 32, and a processing unit 33, wherein:

[0124] The acquisition unit 31 is used to acquire network traffic data and tunnel configuration information of the tunnel in the network topology to be processed;

[0125] The determining unit 32 is used to determine the target routing information for each route corresponding to the network topology to be processed.

[0126] The processing unit 33 is used to determine the first virtual private network traffic for each service data based on the network topology to be processed, network traffic data, target routing information and configuration information; wherein, the first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

[0127] In other embodiments of this application, the determining unit 32 is further configured to perform the following steps:

[0128] Collect the route information to be filtered for each route; the route information to be filtered includes at least the route destination and the route identifier;

[0129] The target routing information is obtained by merging the routing target and routing identifier.

[0130] In other embodiments of this application, the processing unit 33 is further configured to perform the following steps:

[0131] Based on the configuration information, determine the second path corresponding to the tunnel;

[0132] Based on the network topology to be processed, network traffic data, target routing information, and the second path, determine the first path;

[0133] For each piece of service data, determine the first virtual private network traffic required for the service data to be transmitted in each sub-path of the first path.

[0134] In other embodiments of this application, the processing unit 33 is further configured to perform the following steps:

[0135] Analyze the configuration information to identify multiple paths to be selected for the tunnel;

[0136] The cost information of each path to be screened is determined, and a second path is determined from multiple paths to be screened based on multiple cost information; wherein, the cost information characterizes the merits of the paths to be screened.

[0137] In other embodiments of this application, the processing unit 33 is further configured to perform the following steps:

[0138] Based on the target routing information and network traffic data, determine the first address of the source route in the network topology to be processed;

[0139] Based on the first address, the second address of the destination route in the network topology to be processed, and the network topology to be processed, determine the third path of the virtual private network traffic;

[0140] Based on the second and third paths, the first path is determined; wherein, the network traffic data includes the second address.

[0141] In other embodiments of this application, the processing unit 33 is further configured to perform the following steps:

[0142] The target route identifier is determined from the target routing information based on network hop information, virtual private network label, second address, and multiprotocol label switching label; wherein the target routing information includes network hop information and virtual private network label, and network traffic data includes multiprotocol label switching label;

[0143] The address prefix is ​​determined from the destination routing information based on the destination route identifier and the source address; wherein, the destination routing information includes the source address;

[0144] The first address is determined based on the address prefix and network hop information.

[0145] In other embodiments of this application, the processing unit 33 is further configured to perform the following steps:

[0146] Determine the second virtual private network traffic between the first address and the second address;

[0147] For each piece of business data, the first virtual private network traffic is determined based on the second virtual private network traffic.

[0148] It should be noted that a detailed explanation of the steps performed by each unit can be found in [reference needed]. Figure 1 and Figure 3 The information determination method provided in the corresponding embodiments will not be described again here.

[0149] The information determination device provided in the embodiments of this application determines the traffic flow direction of specific services inside the tunnel by acquiring and analyzing the tunnel configuration information. Based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, it jointly determines that different services are transparently transmitted in the same TE tunnel, realizing end-to-end traffic identification throughout the entire process. This not only solves the traffic analysis problem in tunnel scenarios but also fills the functional gaps in fine-grained scheduling of service traffic and abnormal traffic monitoring in tunnel scenarios.

[0150] Based on the foregoing embodiments, embodiments of this application provide an information determining device, which can be applied to... Figure 1 and Figure 3 In the information determination method provided in the corresponding embodiment, refer to Figure 5 As shown, the information determining device 4 may include: a processor 41, a memory 42, and a communication bus 43, wherein:

[0151] Communication bus 43 is used to realize the communication connection between processor 41 and memory 42;

[0152] The processor 41 is used to execute the information determination program in the memory 42 to perform the following steps:

[0153] Obtain network traffic data and tunnel configuration information for tunnels in the network topology to be processed;

[0154] Determine the target routing information for each route corresponding to the network topology to be processed;

[0155] Based on the network topology to be processed, network traffic data, target routing information, and configuration information, the first virtual private network traffic for each service data is determined; wherein, the first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

[0156] In other embodiments of this application, the processor 41 is used to execute the information determination program in the memory 42 to determine the target routing information for each route corresponding to the network topology to be processed, including:

[0157] Collect the route information to be filtered for each route; the route information to be filtered includes at least the route destination and the route identifier;

[0158] The target routing information is obtained by merging the routing target and routing identifier.

[0159] In other embodiments of this application, the processor 41 is configured to execute an information determination program stored in the memory 42 to determine the first virtual private network traffic for each service data based on the network topology to be processed, network traffic data, target routing information, and configuration information, in order to implement the following steps:

[0160] Based on the configuration information, determine the second path corresponding to the tunnel;

[0161] Based on the network topology to be processed, network traffic data, target routing information, and the second path, determine the first path;

[0162] For each piece of service data, determine the first virtual private network traffic required for the service data to be transmitted in each sub-path of the first path.

[0163] In other embodiments of this application, the processor 41 is used to execute the information determination program in the memory 42 to determine the second path corresponding to the tunnel based on configuration information, so as to implement the following steps:

[0164] Analyze the configuration information to identify multiple paths to be selected for the tunnel;

[0165] The cost information of each path to be screened is determined, and a second path is determined from multiple paths to be screened based on multiple cost information; wherein, the cost information characterizes the merits of the paths to be screened.

[0166] In other embodiments of this application, the processor 41 is used to execute the information determination program in the memory 42 to determine a first path based on the network topology to be processed, network traffic data, target routing information, and a second path, in order to implement the following steps:

[0167] Based on the target routing information and network traffic data, determine the first address of the source route in the network topology to be processed;

[0168] Based on the first address, the second address of the destination route in the network topology to be processed, and the network topology to be processed, determine the third path of the virtual private network traffic;

[0169] Based on the second and third paths, the first path is determined; wherein, the network traffic data includes the second address.

[0170] In other embodiments of this application, processor 41 is used to execute an information determination program in memory 42 to determine the first address of the source route in the network topology to be processed based on target routing information and network traffic data, in order to implement the following steps:

[0171] The target route identifier is determined from the target routing information based on network hop information, virtual private network label, second address, and multiprotocol label switching label; wherein the target routing information includes network hop information and virtual private network label, and network traffic data includes multiprotocol label switching label;

[0172] The address prefix is ​​determined from the destination routing information based on the destination route identifier and the source address; wherein the destination routing information includes the source address;

[0173] The first address is determined based on the address prefix and network hop information.

[0174] In other embodiments of this application, processor 41 is configured to execute an information determination program in memory 42 for each piece of service data, determining the first virtual private network traffic required for the transmission of service data in each sub-path of the first path, to perform the following steps:

[0175] Determine the second virtual private network traffic between the first address and the second address;

[0176] For each piece of business data, the first virtual private network traffic is determined based on the second virtual private network traffic.

[0177] It should be noted that a detailed description of the steps performed by the processor can be found in [reference needed]. Figure 1 and Figure 3 The information determination method provided in the corresponding embodiments will not be described again here.

[0178] The information determination device provided in the embodiments of this application determines the traffic flow direction of specific services within the tunnel by acquiring and analyzing the tunnel configuration information. Based on the network topology to be processed, network traffic data, target routing information, and tunnel configuration information, it jointly determines that different services are transparently transmitted in the same TE tunnel, realizing end-to-end traffic identification throughout the entire process. This not only solves the problem of traffic analysis in tunnel scenarios but also fills the functional gaps in fine-grained scheduling of service traffic and abnormal traffic monitoring in tunnel scenarios.

[0179] Based on the foregoing embodiments, this application provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to achieve... Figure 1 and Figure 3 The steps in the information determination method provided in the corresponding embodiment.

[0180] Based on the foregoing embodiments, this application also provides a computer program product, including a computer program that can be executed by the processor 41 of device 4 to achieve... Figure 1 and Figure 3 The steps of the information determination method provided in the embodiments.

[0181] It should be noted that the aforementioned computer-readable storage media can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM), etc.; or it can be various electronic devices that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0182] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0183] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0184] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0185] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0186] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0187] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0188] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A method for determining information, characterized in that, The method includes: Obtain network traffic data and configuration information of the tunnels in the network topology to be processed; Determine the target routing information for each route corresponding to the network topology to be processed; Based on the network topology to be processed, the network traffic data, the target routing information, and the configuration information, the first virtual private network traffic for each service data is determined; wherein, the first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

2. The method according to claim 1, characterized in that, The step of determining the target routing information for each route corresponding to the network topology to be processed includes: Collect the route information to be filtered for each route; wherein, the route information to be filtered includes at least the route destination and the route identifier; The target routing information is obtained by merging the routing target and the routing identifier.

3. The method according to claim 1, characterized in that, The step of determining the first virtual private network traffic for each service data based on the network topology to be processed, the network traffic data, the target routing information, and the configuration information includes: Based on the configuration information, the second path corresponding to the tunnel is determined; Based on the network topology to be processed, the network traffic data, the target routing information, and the second path, the first path is determined; For each piece of service data, determine the first virtual private network traffic required for the transmission of the service data in each sub-path of the first path.

4. The method according to claim 3, characterized in that, The step of determining the second path corresponding to the tunnel based on the configuration information includes... The configuration information is analyzed to determine multiple paths to be selected for the tunnel; The cost information of each of the paths to be screened is determined, and the second path is determined from the plurality of paths to be screened based on the multiple cost information; wherein the cost information characterizes the merits of the paths to be screened.

5. The method according to claim 3, characterized in that, The step of determining the first path based on the network topology to be processed, the network traffic data, the target routing information, and the second path includes: Based on the target routing information and the network traffic data, determine the first address of the source route in the network topology to be processed; Based on the first address, the second address of the destination route in the network topology to be processed, and the network topology to be processed, the third path of the virtual private network traffic is determined; The first path is determined based on the second path and the third path; wherein the network traffic data includes the second address.

6. The method according to claim 5, characterized in that, The step of determining the first address of the source route in the network topology to be processed based on the target routing information and the network traffic data includes: Based on network hop information, virtual private network label, second address, and multiprotocol label switching label, a target route identifier is determined from the target routing information; wherein, the target routing information includes the network hop information and the virtual private network label, and the network traffic data includes the multiprotocol label switching label; The address prefix is ​​determined from the target routing information based on the target routing identifier and the source address; wherein the target routing information includes the source address; The first address is determined based on the address prefix and the network hop information.

7. The method according to claim 6, characterized in that, For each piece of service data, determine the first virtual private network traffic required for the transmission of the service data in each sub-path of the first path, including: Determine the second virtual private network traffic between the first address and the second address; For each of the service data, the first virtual private network traffic is determined based on the second virtual private network traffic.

8. An information determining device, characterized in that, The device includes: The acquisition unit is used to acquire network traffic data of tunnels in the network topology to be processed and the configuration information of the tunnels; A determining unit is used to determine the target routing information for each route corresponding to the network topology to be processed; The processing unit is configured to determine the first virtual private network traffic for each service data based on the network topology to be processed, the network traffic data, the target routing information, and the configuration information; wherein the first virtual private network traffic is the virtual private network traffic required for each service data to be transmitted in each sub-path of the first path.

9. An information determining device, characterized in that, The device includes: a processor, a memory, and a communication bus; The communication bus is used to realize the communication connection between the processor and the memory; The processor is used to execute the information determination program stored in the memory to implement the steps of the information determination method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The storage medium stores one or more programs, which can be executed by one or more processors to implement the steps of the information determination method as described in any one of claims 1 to 7.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the information determination method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Visual presentation method and device and storage medium

    CN116366454A

  • MPLS network management system and method thereof

    KR1020030089604A