Traffic guarantee method and device using sensing network, equipment, storage medium and product

By acquiring and sending user information and network-side ARN identifiers for ARN services, the instability of traffic services in cross-domain transmission in the ARN scheme is resolved, ensuring the consistency and reliability of traffic service performance from the server back to the source.

CN119363836BActive Publication Date: 2026-03-24CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-11
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, application-aware network (ARN) solutions have difficulty guaranteeing traffic services flowing back from the server to the source in situations involving cross-carrier, cross-border, and access to third-party services.

Method used

By acquiring user information from the ARN service, and based on the correspondence between the user-side ARN identifier and the service traffic, the network-side ARN identifier is determined and sent to the network edge device to identify and ensure the service performance of the return traffic data.

Benefits of technology

It ensures the consistency and reliability of traffic data service performance during cross-network domain transmission, and guarantees the quality of traffic service flowing back from the server to the source.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363836B_ABST
    Figure CN119363836B_ABST
Patent Text Reader

Abstract

The application discloses a traffic guarantee method and device of an application perception network, equipment, a storage medium and a product. The method comprises the following steps: a control device acquires user information of an ARN service, the user information is generated based on a user-side ARN identifier of a user subscribing to the ARN service, and is used for indicating the correspondence between the user-side ARN identifier and a traffic identifier of traffic of a guaranteed service; based on the user information and network service information of a network service, a network-side ARN identifier corresponding to the ARN service of the traffic of the service is determined; and the traffic identifier and the network-side ARN identifier are sent to a corresponding network edge device. In this way, the corresponding network edge device can acquire the traffic identifier and the network-side ARN identifier of the ARN service, can identify the traffic data flowing back from a server in the ARN service based on the traffic identifier, and can guarantee the service performance of the traffic data flowing back based on the network-side ARN identifier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network services, and more particularly to a method, apparatus, device, storage medium, and product for ensuring traffic in an Application-Aware Network (ARN). Background Technology

[0002] Application-Aware Networking (ARN), also known as Application Response Networking, is an end-to-end traffic differentiation guarantee solution based on network capabilities. ARN provides a model for programming differentiated service capabilities in the data plane, offering APIs (Application Programming Interfaces) similar to those used in software programming for applications to call network capabilities. By decoupling from network underlay resources, addresses, and service levels, ARN addresses a series of issues related to privacy, security, maintainability, scalability, and compatibility in existing technologies, enabling applications to proactively invoke network capabilities, rather than the network being aware of the application's capabilities.

[0003] In related technologies, ARN solutions rely on the source and server sides to carry identifiers. When deploying ARN, it is inevitable to encounter situations where traffic needs to cross carriers, cross borders, and access third-party services. In such cases, it is difficult to connect the end-to-end industry, making it difficult to guarantee the traffic service flowing back from the server to the source side. Summary of the Invention

[0004] In view of this, embodiments of this application provide a method, apparatus, device, storage medium, and product for ensuring traffic flow in application-aware networks, aiming to ensure the service performance of traffic data flowing back from the server in ARN services.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] In a first aspect, embodiments of this application provide a traffic assurance method for application sensing networks, applied to a control device, the method comprising:

[0007] Obtain user information for ARN services. The user information is generated based on the user-side ARN identifier of the user who subscribes to the ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic of the protected service.

[0008] Based on the user information and the network service information providing the network service, determine the network-side ARN identifier corresponding to the ARN service of the service traffic;

[0009] The traffic identifier and the network-side ARN identifier are sent to the corresponding network edge device.

[0010] In the above scheme, obtaining user information for the ARN service includes:

[0011] Receive user information sent by user equipment or user-side access equipment; or,

[0012] Receive user information from the business orchestration system.

[0013] In the above scheme, determining the network-side ARN identifier corresponding to the ARN service of the service traffic based on the user information and the network service information providing the network service includes:

[0014] Obtain network service information that provides network services;

[0015] Based on the user information and the network service information, the network edge device providing the protected service and the corresponding network-side ARN identifier are determined.

[0016] In the above scheme, the user information includes: the user-side ARN identifier, the traffic identifier, and the service type of the protected service; the network service information includes: a first information table representing the correspondence between the service type of the service and the network edge device, and a second information table representing the correspondence between the ARN service on the network edge device side and the network-side ARN identifier.

[0017] The step of determining the network edge device providing the protected service and the corresponding network-side ARN identifier based on the user information and the network service information includes:

[0018] Based on the service type of the protected service and the first information table, determine the network edge device that provides the service for the protected service;

[0019] The network-side ARN identifier of the network edge device is determined based on the second information table of the network edge device and the user's subscription to the ARN service.

[0020] Secondly, embodiments of this application provide a traffic guarantee method for Application Sensing Network (ARN), applied to network edge devices, the method comprising:

[0021] Receive the first traffic identifier and the corresponding first network-side ARN identifier from the control device;

[0022] If it is determined that the first data packet received from the external network matches the first traffic identifier, then the first network-side ARN identifier is encapsulated into the first data packet, and the first data packet is forwarded to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier.

[0023] In the above scheme, the step of forwarding the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier includes:

[0024] Based on the correspondence between the first network-side ARN identifier and the preset network-side ARN identifier and the routing tunnel of the internal network to which the network edge device belongs, the target routing tunnel is determined;

[0025] The first data packet is forwarded to the target routing tunnel.

[0026] The method in the above scheme further includes:

[0027] If it is determined that the second data packet received from the internal network to which the network edge device belongs carries a second network-side ARN identifier, then the second network-side ARN identifier and the second traffic identifier corresponding to the second data packet are recorded, and the source address of the second data packet is replaced with the network address of the network edge device before being sent out.

[0028] The method in the above scheme further includes:

[0029] If it is determined that the traffic identifier of the received third data packet from the external network matches the second traffic identifier recorded, then the destination address of the third data packet is replaced with the source address, the second network-side ARN identifier is encapsulated into the third data packet, and the third data packet is forwarded to the corresponding routing tunnel of the internal network based on the second network-side ARN identifier.

[0030] Thirdly, embodiments of this application provide a traffic assurance device for application sensing networks, applied to a control device, the device comprising:

[0031] The acquisition module is used to acquire user information for the ARN service. The user information is generated based on the user-side ARN identifier of the user subscribing to the ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic of the protected service.

[0032] The determination module is used to determine the network-side ARN identifier corresponding to the ARN service of the service traffic based on the user information and the network service information providing the network service;

[0033] The sending module is used to send the traffic identifier and the network-side ARN identifier to the corresponding network edge device.

[0034] Fourthly, embodiments of this application provide a traffic assurance device for application-aware networks, applied to network edge devices, the device comprising:

[0035] The receiving module is used to receive the first traffic identifier and the corresponding first network-side ARN identifier from the control device;

[0036] The processing module is configured to, if it is determined that the received first data packet from the external network matches the first traffic identifier, encapsulate the first network-side ARN identifier into the first data packet, and forward the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier.

[0037] Fifthly, embodiments of this application provide a control device, including: a processor and a memory for storing a computer program capable of running on the processor, wherein, when the processor is used to run the computer program, it executes the steps of the method described in the first aspect of embodiments of this application.

[0038] In a sixth aspect, embodiments of this application provide a network edge device, including: a processor and a memory for storing a computer program capable of running on the processor, wherein, when the processor is used to run the computer program, it executes the steps of the method described in the second aspect of embodiments of this application.

[0039] In a seventh aspect, embodiments of this application provide a computer storage medium storing a computer program, which, when executed by a processor, implements the steps of the method described in any aspect of embodiments of this application.

[0040] Eighthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in any aspect of embodiments of this application.

[0041] The technical solution provided in this application embodiment involves a control device acquiring user information for an ARN service. This user information is generated based on the user-side ARN identifier of the user's subscribed ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic being protected. Based on the user information and the network service information providing the network service, the control device determines the network-side ARN identifier corresponding to the ARN service of the service traffic. The traffic identifier and the network-side ARN identifier are then sent to the corresponding network edge device. In this way, the corresponding network edge device can obtain the traffic identifier and the network-side ARN identifier of the ARN service, identify the traffic data flowing back from the server in the ARN service based on the traffic identifier, and ensure the service performance of the flowing traffic data based on the network-side ARN identifier. Attached Figure Description

[0042] Figure 1 A schematic diagram illustrating the advantages of ARN design in related technologies;

[0043] Figure 2 This is a schematic diagram of the overall architecture of ARN in related technologies;

[0044] Figure 3 This is a flowchart illustrating a traffic guarantee method for using a sensing network according to an embodiment of this application.

[0045] Figure 4 This is a flowchart illustrating another embodiment of the traffic guarantee method for applying a sensing network in this application;

[0046] Figure 5 This is a schematic diagram illustrating an application embodiment of this application for ARN deployment.

[0047] Figure 6 This is a schematic diagram illustrating an ARN deployment scenario, another application embodiment of this application.

[0048] Figure 7 This is a schematic diagram of the structure of a traffic protection device using a sensing network according to an embodiment of this application;

[0049] Figure 8 This is a schematic diagram of a traffic protection device for using a sensing network according to another embodiment of this application;

[0050] Figure 9 This is a schematic diagram of the structure of the control device according to an embodiment of this application;

[0051] Figure 10 This is a schematic diagram of the structure of a network edge device according to an embodiment of this application. Detailed Implementation

[0052] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0053] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the application.

[0054] In related technologies, ARN provides an innovative and smoothly compatible converged architecture for relatively separate service and network systems. It offers concise and efficient network capability interfaces for service and application sides, and provides application-level granular resource views and scheduling capabilities for the basic network. ARN aims to provide applications with the ability to call network functions, much like Windows software programming. Typically, upper-layer software needs to request a handle and obtain permissions before calling underlying Windows library functions, and then use that handle as an API parameter to complete the library function's processing. In the ARN scenario, if user applications are considered upper-layer software and network capabilities are considered encapsulated underlying library functions, then the ARN ID (ARN identifier) ​​is similar to a software handle. After obtaining calling permissions by requesting an ARN ID, users can call network capabilities by carrying that ARN ID in their packets.

[0055] like Figure 1 As shown, the ARN design has the following advantages:

[0056] 1) Separation of Internet and Business

[0057] ARNs encapsulate and expose network capabilities, and perform network tunnel / slice selection on the network side based on ARN IDs, thereby separating network services from business services and providing application-level granular scheduling capabilities for the basic network.

[0058] 2) Privacy

[0059] ARN-based scheduling of network services using ARN IDs can avoid exposing private information such as network tunnels / slices, while also hiding user application privacy.

[0060] 3) Scalability

[0061] ARN can be aggregated, supports ultra-large-scale deployments, and is highly scalable.

[0062] 4) Security

[0063] ARN supports access control and lifecycle management, and can also handle lost or reissued network services subscribed to by users, providing strong security.

[0064] 5) Compatibility

[0065] Even when user services do not support ARN, normal forwarding is not affected, demonstrating strong compatibility.

[0066] 6) Application Innovation

[0067] ARN supports any future application, and the underlying network can remain unchanged as the application changes.

[0068] 7) Cross-domain

[0069] ARN supports cross-domain network operations and network connectivity.

[0070] 8) QoS Orthogonal

[0071] ARN can be used in conjunction with QoS (Quality of Service) to enable network resource scheduling and allocation.

[0072] Figure 2 A schematic diagram of the overall architecture of ARN is shown below. Figure 2 The overall architecture of ARN includes a network controller, user edge devices located between user equipment and cloud service equipment, and network edge devices in each network domain. The network controller is responsible for managing ARN on the control plane, while the network edge devices are responsible for providing ARN services based on ARN IDs on the forwarding plane.

[0073] Specifically, the network controller compiles a list of ARN services available for user subscription based on existing network capabilities. Users can subscribe to the service guarantees they require, i.e., select ARN services at different network service levels. Once a user determines their desired service, the network controller generates a user-side ARN identifier and maps it to the network-side ARN identifier corresponding to the actual network resources, ensuring that the user's customized needs are accurately implemented on the network devices. The division of network resources can be path planning information, such as segment routing policies (SRPolicies), where each SRP policy corresponds to a network path, which can be marked using segment routing identifiers (e.g., BISD (BindingSegment Identification)).

[0074] After generating the user-side ARN identifier, the network controller distributes the user-side ARN identifier to the user equipment or user edge device. The user equipment or user edge device then labels the relevant service data and encapsulates the user-side ARN identifier in the data packet before sending it. In addition, the network controller also distributes the mapping relationship between the user-side ARN identifier and the network-side ARN identifier, as well as the corresponding path planning information, to the network edge device.

[0075] Next, during data transmission, the data packets sent by the user side carry the user-side ARN identifier. The network edge device then provides corresponding quality of service (QoS) guarantees in the ARN based on this user-side ARN identifier. For example, when the network edge device receives a data packet sent by the user side, it retrieves the user-side ARN identifier from the data packet and aggregates the ARN services. This involves mapping user-side ARN identifiers with the same network capability requirements to the network-side ARN identifier, and providing corresponding network service guarantees based on the network-side ARN identifier during forwarding. When a data packet needs to cross network domains, the network edge device at the egress point finds the network edge device in the next network domain based on the cross-domain mapping information and performs cross-domain ARN identifier conversion as needed. In other words, when a data packet crosses different network regions, the network-side ARN identifier is remapped to adapt to different network environments, ensuring consistent QoS throughout the entire transmission path. Finally, the data packet successfully arrives at the server. The entire process achieves seamless integration from user request to service delivery, ensuring service efficiency and reliability. This process involves interactions between users and network controllers, roles of network devices, application-layer data transmission, and cross-domain communication, using ARN identifiers to manage and optimize network services.

[0076] It should be noted that the above cross-network domain process involves constructing the mapping relationship between network-side ARN identifiers of the same guaranteed service in different network domains. For example, the ARN cross-domain coordinator can be responsible for constructing the mapping relationship between network-side ARN identifiers of the same guaranteed service in different domains, such as the mapping relationship between metropolitan area network ARN identifiers and backbone network ARN identifiers. This mapping relationship can be distributed to network edge devices by the network controller, thereby realizing service convergence (i.e., mapping between network-side ARN identifiers) between different network domains. This allows the network-side ARN identifiers to be remapped to adapt to the network environment of different network domains, ensuring the consistency of service quality throughout the entire transmission path.

[0077] It should be noted that the ARN solution relies on the source (i.e., the requesting end) and the server to carry the ARN identifier. However, in actual applications, there are often situations where the server is connected to different operators, crosses borders, or accesses third-party services. This makes it difficult to connect the industries involved on the content source side. As a result, the data packets flowing back from the server to the source are difficult to carry the relevant ARN identifier, making it difficult to guarantee the traffic service flowing back from the server to the source.

[0078] Based on this, in various embodiments of this application, a traffic assurance method for application-aware networks is provided, which aims to ensure the service performance of traffic data flowing back from the server in ARN services.

[0079] This application provides a traffic guarantee method for application sensing networks, applied to a control device, which can be understood as... Figure 2 The network controller shown is, for example Figure 3 As shown, the method includes:

[0080] Step 301: Obtain user information for the ARN service. The user information is generated based on the user-side ARN identifier for the user's subscription to the ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic of the protected service.

[0081] Here, because users have diverse needs for network services, ARN services can provide network services of various service levels, such as low-latency network services and high-bandwidth network services. These network services can be further subdivided based on service level, without specific limitations here.

[0082] Understandably, users can subscribe to ARN services through control devices, thereby obtaining a user-side ARN identifier corresponding to the subscribed ARN service. This user-side ARN identifier can be a random number generated by the control device based on the user's subscription request, serving as a unique identifier for the user to invoke the subscribed ARN service without exposing the user's privacy information. After obtaining this user-side ARN identifier, the user can allocate it to the services that need protection. Based on this, the user information of the ARN service obtained by the control device needs to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic of the protected service, thereby clarifying the service traffic corresponding to the ARN service.

[0083] Step 302: Based on the user information and the network service information providing the network service, determine the network-side ARN identifier corresponding to the ARN service of the service traffic.

[0084] Here, after the control device obtains the user information, it needs to determine the network-side ARN identifier corresponding to the ARN service of the protected service traffic based on the user information and the network service information it maintains.

[0085] Step 303: Send the traffic identifier and the network-side ARN identifier to the corresponding network edge device.

[0086] Here, the control device sends the traffic identifier and the network-side ARN identifier to the corresponding network edge device based on the determined traffic identifier. In this way, the corresponding network edge device can obtain the traffic identifier and the network-side ARN identifier of the ARN service, identify the traffic data flowing back from the server in the ARN service based on the traffic identifier, and ensure the service performance of the flowing traffic data based on the network-side ARN identifier.

[0087] For example, obtaining user information for the ARN service includes:

[0088] Receive user information sent by user equipment or user-side access equipment; or,

[0089] Receive user information from the business orchestration system.

[0090] In one application example, the control device can receive user information sent by the user equipment or the user-side access device. For example, when the user equipment or the user-side access device sends a data packet for a service request, if a user-side ARN identifier is allocated in the data packet, the user equipment or the user-side access device can generate user information based on the traffic identifier of the service request and the user-side ARN identifier and report it to the control device, thereby realizing the reporting of user information one by one.

[0091] In another application example, the service orchestration system can collect the user-side ARN identifiers assigned to each user, thereby collecting the user information of each user under the service, and uniformly distributing the user information corresponding to the service to the control device. In this way, the centralized distribution of user information can be achieved, reducing the data interaction between user equipment or user-side access equipment and control device, thereby saving network resource consumption.

[0092] For example, determining the network-side ARN identifier corresponding to the ARN service of the service traffic based on the user information and the network service information providing the network service includes:

[0093] Obtain network service information that provides network services;

[0094] Based on the user information and the network service information, the network edge device providing the protected service and the corresponding network-side ARN identifier are determined.

[0095] Here, the network service information that provides network services can be the network service information that the control device has maintained in advance, such as the network-side ARN identifiers of each ARN service in different network domains and the network edge devices corresponding to each service.

[0096] Here, the control device can search the network service information based on user information, select the network edge device of the service being protected and the corresponding network-side ARN identifier, and then send the traffic identifier and network-side ARN identifier only to the selected network edge device, thereby effectively controlling the scope of information propagation and reducing network load.

[0097] For example, the user information includes: the user-side ARN identifier, the traffic identifier, and the service type of the protected service; the network service information includes: a first information table representing the correspondence between the service type of the service and the network edge device, and a second information table representing the correspondence between the ARN service on the network edge device side and the network-side ARN identifier.

[0098] The step of determining the network edge device providing the protected service and the corresponding network-side ARN identifier based on the user information and the network service information includes:

[0099] Based on the service type of the protected service and the first information table, determine the network edge device that provides the service for the protected service;

[0100] The network-side ARN identifier of the network edge device is determined based on the second information table of the network edge device and the user's subscription to the ARN service.

[0101] Here, the control device can search the first information table based on the service type of the protected service to select the network edge device providing the service. The control device then searches the second information table for the user-side ARN identifier within the network domain of the selected network edge device, thus determining the network-side ARN identifier of the user's subscribed ARN service on the network edge device. It can then send the traffic identifier of the protected service's traffic and the corresponding network-side ARN identifier to the selected network edge device. Upon receiving the traffic identifier and network-side ARN identifier, the network edge device can identify the traffic data flowing back from the server in the ARN service based on the traffic identifier and ensure the service performance of the flowing traffic data based on the network-side ARN identifier.

[0102] For example, embodiments of this application provide a traffic guarantee method for application-aware networks, applied to network edge devices, such as... Figure 4 As shown, the method includes:

[0103] Step 401: Receive the first traffic identifier and the corresponding first network-side ARN identifier from the control device.

[0104] Step 402: If it is determined that the first data packet received from the external network matches the first traffic identifier, then the first network-side ARN identifier is encapsulated into the first data packet, and the first data packet is forwarded to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier.

[0105] Here, after receiving the first traffic identifier and the corresponding first network-side ARN identifier of the service traffic that needs ARN service protection from the control device, the network edge device can identify the first data packet returning from the server in the ARN service based on the first traffic identifier, encapsulate the first network-side ARN identifier into the first data packet, and forward the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs, thereby ensuring the service performance of the returning traffic data.

[0106] For example, the step of forwarding the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier includes:

[0107] Based on the correspondence between the first network-side ARN identifier and the preset network-side ARN identifier and the routing tunnel of the internal network to which the network edge device belongs, the target routing tunnel is determined;

[0108] The first data packet is forwarded to the target routing tunnel.

[0109] Here, the network edge device maintains a correspondence between the network-side ARN identifier and the routing tunnel of its internal network. For example, it maintains a mapping relationship between the network-side ARN identifier and BISD. In this way, the target routing tunnel can be determined based on the first network-side ARN identifier and the correspondence, and then the first data packet can be forwarded to the target routing tunnel to provide the ARN network service of its internal network.

[0110] Exemplarily, the method further includes:

[0111] If it is determined that the received second data packet from the internal network carries a second network-side ARN identifier, then the second network-side ARN identifier and the second traffic identifier corresponding to the second data packet are recorded, and the source address of the second data packet is replaced with the network address of the network edge device before being sent out.

[0112] Here, the network edge device can also detect the second data packet from the internal network. If it is determined that the second data packet carries a network-side ARN identifier, for example, a second network-side ARN identifier, then the second network-side ARN identifier and the second traffic identifier corresponding to the second data packet are recorded. The source address of the second data packet is replaced with the network address of the network edge device before it is sent out. In this way, by replacing the source address, it can be ensured that the return traffic can still enter the internal network to which the network edge device belongs from the network edge device.

[0113] Exemplarily, the method further includes:

[0114] If it is determined that the traffic identifier of the received third data packet from the external network matches the second traffic identifier recorded, then the destination address of the third data packet is replaced with the source address, the second network-side ARN identifier is encapsulated into the third data packet, and the third data packet is forwarded to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the second network-side ARN identifier.

[0115] Understandably, network edge devices can also detect third data packets from external networks. If the traffic identifier of the third data packet matches the recorded second traffic identifier, the third data packet is determined to be traffic data flowing back from the second data packet. The destination address of the third data packet is replaced with the source address of the second data packet. The recorded second network-side ARN identifier is encapsulated into the third data packet. Based on the second network-side ARN identifier, the third data packet is forwarded to the corresponding routing tunnel in the internal network to which the network edge device belongs, thereby ensuring the service performance of traffic data flowing back from the server in the ARN service.

[0116] The present application will be further described in detail below with reference to application examples.

[0117] Application Example 1

[0118] In this application embodiment, the network controller issues a mapping relationship between the network-side ARN identifier and the traffic identifier for the guaranteed service to the network edge device, thereby ensuring the performance of traffic service from the content source to the user.

[0119] like Figure 5 As shown, the network controller can manage and control the service provider's internal network. The method in this application embodiment specifically includes:

[0120] 1) After assigning an ARN ID to the user, the user-side access device uploads the mapping relationship between the user and the ARN ID to the network controller;

[0121] Here, the user-side access device can receive the user-side ARN identifier issued by the network controller. This user-side ARN identifier corresponds to the ARN service subscribed by the user. After the user-side access device assigns the user-side ARN identifier to the service that needs to be protected, it can generate user information and upload it to the network controller.

[0122] For example, the user information is shown in Table 1 below:

[0123] Table 1

[0124]

[0125] Among them, the traffic 5-tuple information is the traffic identifier, and the policy information is used to represent the network path corresponding to the ARN service. It can be understood that, based on this user information, the network controller can maintain information such as the user, the user-side ARN identifier assigned to the user, the type of service to be protected, and the service traffic that needs to be protected.

[0126] It should be noted that the network controller also maintains network service information, which includes: a first information table representing the correspondence between service types and network edge devices, and a second information table representing the correspondence between ARN services on the network edge device side and ARN identifiers on the network side.

[0127] For example, the format of the first information table is shown in Table 2 below:

[0128] Table 2

[0129] Border router IP address Service Categories Service Subcategories 10.1.1.1 Games Game A

[0130] Understandably, the network controller can select a matching network edge device (i.e., border router) from the first information table based on the type of the protected service in the user information. The network controller then selects the network-side ARN identifier corresponding to the matching network edge device based on the second information table and the ARN ID in the user information.

[0131] 2) The network controller binds user information with the traffic 5-tuple information that needs to ensure business traffic and then sends it to the relevant network edge devices;

[0132] Here, the network controller can distribute the traffic quintuple information and the corresponding network-side ARN identifier to the aforementioned determined network edge devices. For example, based on the guarantee service of game A, the network controller determines that the matching network edge devices are PE2 and PE4, and distributes the traffic quintuple information and the corresponding network-side ARN identifier to PE2 and PE4.

[0133] 3) The network edge device receives and stores the traffic quintuple information and the corresponding network-side ARN identifier and other information issued by the network controller;

[0134] 4) After receiving external traffic, the network edge device identifies the five-tuple information of the traffic. If it is determined to be matching service traffic, the network-side ARN identifier is encapsulated in the data packet, and the data packet is forwarded according to the protection requirements.

[0135] Application Example 2

[0136] In this application embodiment, the network edge device receives and records the packet data, and then ensures that the traffic still enters the internal network from the network edge device by source address replacement, thereby providing ARN service protection for the return traffic.

[0137] like Figure 6 As shown, the network controller can manage and control the service provider's internal network. The method in this application embodiment specifically includes:

[0138] 1) When a data packet accesses a content source from the user side, if the data packet enters the external network from the PE2 device as the exit point, the PE2 device checks whether the data packet carries an ARN ID. If it does, it records the ARN ID and traffic identifier of the data packet.

[0139] For example, the information recorded by the network edge device is shown in Table 3 below:

[0140] Table 3

[0141]

[0142] 2) The PE2 device changes the source address of the traffic to the device's local address, and then forwards the packets to other networks;

[0143] 3) When the PE2 device receives a data packet from the external network, it looks up the information stored locally, replaces the destination address of the data packet with the address of the initial user, encapsulates the corresponding ARN ID into the data packet, and forwards the data packet to the internal network device.

[0144] Understandably, by using source address replacement, network edge devices can ensure that backhaul traffic still enters the internal network from the network edge device. In turn, they can provide ARN services for backhaul traffic based on the recorded ARN ID, thus ensuring the service performance of backhaul traffic.

[0145] To implement the method of the embodiments of this application, the embodiments of this application also provide a traffic assurance device for application-aware networks. This traffic assurance device for application-aware networks corresponds to the traffic assurance method for application-aware networks on the control device side described above. The steps in the embodiments of the traffic assurance method for application-aware networks on the control device side are also fully applicable to the embodiments of this traffic assurance device for application-aware networks.

[0146] like Figure 7As shown, the traffic protection device for the application-aware network includes: an acquisition module 701, a determination module 702, and a sending module 703. The acquisition module 701 acquires user information for the ARN service. This user information is generated based on the user-side ARN identifier of the user's subscribed ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic being protected. The determination module 702 determines the network-side ARN identifier corresponding to the ARN service of the service traffic based on the user information and the network service information providing the network service. The sending module 703 sends the traffic identifier and the network-side ARN identifier to the corresponding network edge device.

[0147] For example, the acquisition module 701 is specifically used for:

[0148] Receive user information sent by user equipment or user-side access equipment; or,

[0149] Receive user information from the business orchestration system.

[0150] For example, the determining module 702 is specifically used for:

[0151] Obtain network service information that provides network services;

[0152] Based on the user information and the network service information, the network edge device providing the protected service and the corresponding network-side ARN identifier are determined.

[0153] For example, the user information includes: the user-side ARN identifier, the traffic identifier, and the service type of the protected service; the network service information includes: a first information table representing the correspondence between the service type of the service and the network edge device, and a second information table representing the correspondence between the ARN service on the network edge device side and the network-side ARN identifier.

[0154] The determination module 702 is specifically used for:

[0155] Based on the service type of the protected service and the first information table, determine the network edge device that provides the service for the protected service;

[0156] The network-side ARN identifier of the network edge device is determined based on the second information table of the network edge device and the user's subscription to the ARN service.

[0157] In practical applications, the acquisition module 701, the determination module 702, and the transmission module 703 can be implemented by a processor in the control device. Of course, the processor needs to run a computer program in memory to perform its functions.

[0158] To implement the method of the embodiments of this application, the embodiments of this application also provide a traffic assurance device for application-aware networks. This traffic assurance device for application-aware networks corresponds to the traffic assurance method for application-aware networks on the network edge device side described above. The steps in the embodiments of the traffic assurance method for application-aware networks on the network edge device side are also fully applicable to the embodiments of this traffic assurance device for application-aware networks.

[0159] like Figure 8 As shown, the traffic protection device for the application-aware network includes a receiving module 801 and a processing module 802. The receiving module 801 is used to receive a first traffic identifier and a corresponding first network-side ARN identifier from a control device; the processing module 802 is used to, if it is determined that a first data packet received from an external network matches the first traffic identifier, encapsulate the first network-side ARN identifier into the first data packet, and forward the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier.

[0160] For example, the processing module 802 is specifically used for:

[0161] Based on the correspondence between the first network-side ARN identifier and the preset network-side ARN identifier and the routing tunnel of the internal network to which the network edge device belongs, the target routing tunnel is determined;

[0162] The first data packet is forwarded to the target routing tunnel.

[0163] For example, the processing module 802 is further configured to:

[0164] If it is determined that the received second data packet from the internal network carries a second network-side ARN identifier, then the second network-side ARN identifier and the second traffic identifier corresponding to the second data packet are recorded, and the source address of the second data packet is replaced with the network address of the network edge device before being sent out.

[0165] For example, the processing module 802 is further configured to:

[0166] If it is determined that the traffic identifier of the received third data packet from the external network matches the second traffic identifier recorded, then the destination address of the third data packet is replaced with the source address, the second network-side ARN identifier is encapsulated into the third data packet, and the third data packet is forwarded to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the second network-side ARN identifier.

[0167] In practical applications, the receiving module 801 and the processing module 802 can be implemented by a processor in the network edge device. Of course, the processor needs to run a computer program in memory to perform its functions.

[0168] It should be noted that the traffic assurance device for application-aware networks provided in the above embodiments is only illustrated by the division of the above-described program modules when performing traffic assurance for application-aware networks. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the traffic assurance device for application-aware networks provided in the above embodiments and the traffic assurance method embodiments for application-aware networks belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.

[0169] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a control device. Figure 9 The structure of this control device is shown as an example only, not the entire structure; it can be implemented as needed. Figure 9 The structure shown may be part or all of the structure.

[0170] like Figure 9 As shown, the control device 900 provided in this embodiment includes at least one processor 901, a memory 902, a user interface 903, and at least one network interface 904. The various components in the control device 900 are coupled together via a bus system 905. It can be understood that the bus system 905 is used to implement communication between these components. In addition to a data bus, the bus system 905 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in… Figure 9 The general labeled all buses as Bus System 905.

[0171] The user interface 903 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.

[0172] The memory 902 in this embodiment is used to store various types of data to support the operation of the control device. Examples of such data include any computer program used to operate on the control device.

[0173] The application-aware network traffic assurance method disclosed in this application embodiment can be applied to or implemented by processor 901. Processor 901 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the application-aware network traffic assurance method can be completed by integrated logic circuits in the hardware or by instructions in software form within processor 901. The processor 901 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 901 can implement or execute the methods, steps, and logic block diagrams disclosed in this application embodiment. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this application embodiment can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, specifically memory 902. Processor 901 reads information from memory 902 and, in conjunction with its hardware, completes the steps of the application-aware network traffic assurance method provided in this application embodiment.

[0174] In an exemplary embodiment, the control device 900 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0175] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, the embodiments of this application also provide a network edge device. Figure 10 This is only an exemplary structure of the network edge device, not the entire structure; implementation is possible as needed. Figure 10 The structure shown may be part or all of the structure.

[0176] like Figure 10As shown, the network edge device 1000 provided in this embodiment includes at least one processor 1001, a memory 1002, a user interface 1003, and at least one network interface 1004. The various components in the network edge device 1000 are coupled together via a bus system 1005. It can be understood that the bus system 1005 is used to implement communication between these components. In addition to a data bus, the bus system 1005 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in… Figure 10 The general labeled all buses as Bus System 1005.

[0177] The user interface 1003 may include a monitor, keyboard, mouse, trackball, click wheel, buttons, touchpad, or touch screen.

[0178] The memory 1002 in this embodiment is used to store various types of data to support the operation of the network edge device. Examples of such data include any computer program used to operate on the network edge device.

[0179] The application-aware network traffic assurance method disclosed in this application embodiment can be applied to, or implemented by, processor 1001. Processor 1001 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the application-aware network traffic assurance method can be completed by integrated logic circuits in the hardware of processor 1001 or by instructions in software form. The processor 1001 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 1001 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in memory 1002. The processor 1001 reads the information in memory 1002 and, in conjunction with its hardware, completes the steps of the traffic guarantee method for application-aware networks provided in this application embodiment.

[0180] In an exemplary embodiment, the network edge device 1000 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0181] It is understood that memories 902 and 1002 can be volatile or non-volatile memories, or both. Non-volatile memories can be read-only memories (ROM), programmable read-only memories (PROM), erasable programmable read-only memories (EPROM), electrically erasable programmable read-only memories (EEPROM), ferromagnetic random access memories (FRAM), flash memories, magnetic surface memories, optical discs, or compact disc read-only memories (CD-ROM); magnetic surface memories can be disk storage or magnetic tape storage. Volatile memories can be random access memories (RAM), used as external caches. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), Sync Link Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.

[0182] In exemplary embodiments, this application also provides a computer storage medium, specifically a computer-readable storage medium, such as a memory 902 storing a computer program, which can be executed by a processor 901 of a control device 900 to complete the steps described in the method of this application embodiment; or, for example, a memory 1002 storing a computer program, which can be executed by a processor 1001 of a network edge device 1000 to complete the steps described in the method of this application embodiment. The computer-readable storage medium can be a ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.

[0183] In an exemplary embodiment, this application also provides a computer program product, including a computer program that can be executed by a processor 901 of a control device 900 or by a processor 1001 of a network edge device 1000 to perform the steps described in the method of this application embodiment.

[0184] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0185] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0186] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for ensuring traffic flow using an ARN (Awareness Network), characterized in that, Applied to control equipment, the method includes: Obtain user information for the ARN service. The user information is generated based on the user-side ARN identifier of the user subscribing to the ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic of the protected service. The user information includes: the user-side ARN identifier, the traffic identifier, and the service type of the protected service. Obtain network service information that provides network services; the network service information includes: a first information table representing the correspondence between service types and network edge devices, and a second information table representing the correspondence between ARN services on the network edge device side and ARN identifiers on the network side; Based on the service type of the protected service and the first information table, determine the network edge device that provides the service for the protected service; The network-side ARN identifier of the network edge device is determined based on the second information table of the network edge device and the user's subscription to the ARN service. The traffic identifier and the network-side ARN identifier are sent to the corresponding network edge device.

2. The method according to claim 1, characterized in that, The user information obtained from the ARN service includes: Receive user information sent by user equipment or user-side access equipment; or, Receive user information from the business orchestration system.

3. A traffic guarantee method for applying ARN (Awareness Network), characterized in that, Applied to network edge devices, the method includes: The system receives a first traffic identifier and a corresponding first network-side ARN identifier from the control device. The first network-side ARN identifier is determined by the control device based on a second information table and the user's subscription to ARN services. The second information table represents the correspondence between ARN services on the network edge device side and network-side ARN identifiers. If it is determined that the first data packet received from the external network matches the first traffic identifier, then the first network-side ARN identifier is encapsulated into the first data packet, and the first data packet is forwarded to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier.

4. The method according to claim 3, characterized in that, The step of forwarding the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier includes: Based on the correspondence between the first network-side ARN identifier and the preset network-side ARN identifier and the routing tunnel of the internal network to which the network edge device belongs, the target routing tunnel is determined; The first data packet is forwarded to the target routing tunnel.

5. The method according to claim 3, characterized in that, The method further includes: If it is determined that the second data packet received from the internal network to which the network edge device belongs carries a second network-side ARN identifier, then the second network-side ARN identifier and the second traffic identifier corresponding to the second data packet are recorded, and the source address of the second data packet is replaced with the network address of the network edge device before being sent out.

6. The method according to claim 5, characterized in that, The method further includes: If it is determined that the traffic identifier of the received third data packet from the external network matches the second traffic identifier in the record, then the destination address of the third data packet is replaced with the source address, the second network-side ARN identifier is encapsulated into the third data packet, and the third data packet is forwarded to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the second network-side ARN identifier.

7. A traffic guarantee device for applying an ARN (Awareness Network), characterized in that, Applied to control equipment, the device includes: The acquisition module is used to acquire user information for the ARN service. The user information is generated based on the user-side ARN identifier of the user subscribing to the ARN service and is used to indicate the correspondence between the user-side ARN identifier and the traffic identifier of the service traffic of the protected service. The user information includes: the user-side ARN identifier, the traffic identifier, and the service type of the protected service. A determination module is used to obtain network service information that provides network services; the network service information includes: a first information table representing the correspondence between service types and network edge devices, and a second information table representing the correspondence between ARN services on the network edge device side and network-side ARN identifiers; based on the service type of the protected service and the first information table, the network edge device providing the protected service is determined; based on the second information table of the network edge device and the user-subscribed ARN service, the network-side ARN identifier of the network edge device is determined; The sending module is used to send the traffic identifier and the network-side ARN identifier to the corresponding network edge device.

8. A traffic guarantee device for applying an ARN (Awareness Network), characterized in that, The device, applied to network edge devices, includes: The receiving module is used to receive a first traffic identifier and a corresponding first network-side ARN identifier from the control device; the first network-side ARN identifier is determined by the control device based on a second information table and the user's subscription to ARN services; the second information table represents the correspondence between ARN services on the network edge device side and network-side ARN identifiers. The processing module is configured to, if it is determined that the received first data packet from the external network matches the first traffic identifier, encapsulate the first network-side ARN identifier into the first data packet, and forward the first data packet to the corresponding routing tunnel of the internal network to which the network edge device belongs based on the first network-side ARN identifier.

9. A control device, characterized in that, include: The processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 1 to 2.

10. A network edge device, characterized in that, include: A processor and memory for storing computer programs that can run on the processor, wherein, The processor, when running a computer program, performs the steps of the method according to any one of claims 3 to 6.

11. A computer storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Message forwarding method and device and communication network

    CN115442300A