Network configuration data auditing method and device, storage medium and electronic equipment

By generating network element and service twins through digital twin technology, network configuration data auditing centered on service objects is realized, which solves the problems of low auditing efficiency and poor reusability in existing technologies and improves auditing accuracy and real-time performance.

CN119520333BActive Publication Date: 2025-10-24CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411640358.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-10-24
Estimated Expiration
2044-11-15

AI Technical Summary

Technical Problem

Existing technologies rely on instructions for network configuration scheme auditing, resulting in a large workload, low auditing efficiency, difficulty in handling configuration differences among various network elements in complex networks, and tight coupling between auditing methods and business rules, making them difficult to reuse.

Method used

Digital twin technology is used to generate network element twins. Based on the network element and business twin models, they are encapsulated and associated to generate business objects. Audits are conducted through business instances, and the latest business twins in the current network are used as the verification standard.

Benefits of technology

It improves audit efficiency and accuracy, simplifies the audit process, is easily compatible with configuration differences across provinces, and provides a unified and reusable audit standard.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520333B_ABST
    Figure CN119520333B_ABST
Patent Text Reader

Abstract

The present disclosure provides an auditing method and device of network configuration data, a computer storage medium and an electronic device, and relates to the technical field of computers. The method comprises the following steps: generating a network element twin of an actual network element based on digital twin technology, wherein the network element twin contains at least instruction configuration data in the network element data; encapsulating the instruction configuration data according to a network element configuration model to obtain a network element configuration twin; generating a first service object based on a pre-constructed service twin model and the network element configuration twin, and further generating a service twin; for each instruction configuration data in a network configuration scheme to be issued, generating a configuration instance corresponding to each instruction configuration data according to the network element configuration model, and generating a second service object based on the service twin model and the configuration instance, and further generating an instance to be issued; and auditing the instance to be issued based on a service instance in an actual network. The present disclosure can reduce the workload of auditing network configuration data and improve the auditing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of computer, and particularly relates to a network configuration data auditing method, a network configuration data auditing device, a computer storage medium and an electronic device. BACKGROUND

[0002] In the process of daily network operation and service operation, various network configuration schemes are often issued under the existing network to realize the functions of network upgrade maintenance or service opening. The essence of the network configuration scheme is a set of configuration instructions, which specifically involves adding, deleting and modifying the existing network equipment. Therefore, auditing each network configuration scheme to ensure the correctness of the issued configuration instructions is of great significance to the normal operation of the network.

[0003] The related technical scheme often formulates verification rules according to the configuration specification to perform "instruction" level verification on each instruction in the network configuration scheme. However, the network configuration scheme takes a "service object" as the configuration object, and a service object needs to issue configuration instructions on multiple types of network elements. Moreover, the existing network is complex, and the number of network elements is large.

[0004] Therefore, the above related technical scheme needs to read the network configuration data from the scattered multiple types of network elements one by one and audit the parameter values of the configuration instructions, resulting in a large amount of work and low auditing efficiency. SUMMARY

[0005] The present disclosure provides a network configuration data auditing method, a network configuration data auditing device, a computer storage medium and an electronic device, thereby reducing the workload of auditing the network configuration data and achieving the technical effect of improving the auditing efficiency.

[0006] In a first aspect, an embodiment of the present disclosure provides a network configuration data auditing method, which comprises: generating a network element twin of an actual network element based on digital twinning technology, wherein the network element data corresponding to the network element twin at least contains instruction configuration data; encapsulating the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; associating multiple network element configuration twins based on a pre-constructed service twin model to generate a first service object and generate a service twin based on the first service object; wherein each service twin corresponds to a service instance in the actual network; for each instruction configuration data in a network configuration scheme to be issued, generating a configuration instance corresponding to each instruction configuration data according to the network element configuration model, and associating multiple configuration instances based on the service twin model to generate a second service object and generate a to-be-issued instance based on the second service object; and auditing the to-be-issued instance based on the service instance in the actual network to obtain an auditing result.

[0007] In a second aspect, an embodiment of the present disclosure provides an auditing device for network configuration data, the device comprising: a twin generation module configured to generate a network element twin of an actual network element based on a digital twin technology, the network element twin corresponding to network element data including at least instruction configuration data; an encapsulation module configured to encapsulate the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; a first service object generation module configured to associate a plurality of network element configuration twins based on a pre-constructed service twin model to generate a first service object, and generate a service twin based on the first service object; wherein each service twin corresponds to a service instance in an actual network; a second service object generation module configured to, for each instruction configuration data in a network configuration scheme to be delivered, generate a configuration instance corresponding to the instruction configuration data according to the network element configuration model, and associate a plurality of configuration instances based on the service twin model to generate a second service object, and generate a to-be-delivered instance based on the second service object; and an auditing module configured to audit the to-be-delivered instance based on a service instance in the actual network to obtain an auditing result.

[0008] In a third aspect, an embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the above-mentioned auditing method for network configuration data.

[0009] In a fourth aspect, an embodiment of the present disclosure provides an electronic device, comprising: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to execute the above-mentioned auditing method for network configuration data by executing the executable instructions.

[0010] In a fifth aspect, an embodiment of the present disclosure provides a computer program product comprising a computer program, the computer program being executed by a processor to implement the above-mentioned auditing method for network configuration data.

[0011] The technical scheme of the present disclosure has the following beneficial effects:

[0012] The method generates a network element twin of an actual network element based on a digital twin technology, the network element twin corresponding network element data at least including instruction configuration data; encapsulates the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; associates a plurality of network element configuration twins based on a pre-constructed service twin model to generate a first service object, and generates a service twin based on the first service object; wherein each service twin corresponds to a service instance in an actual network; for each instruction configuration data in a network configuration scheme to be issued, generates a configuration instance corresponding to each instruction configuration data according to the network element configuration model, and associates a plurality of configuration instances based on the service twin model to generate a second service object, and generates a to-be-issued instance based on the second service object; audits the to-be-issued instance based on the service instance in the actual network to obtain an audit result. The method changes the original instruction-based auditing method to a service object-centered auditing method, thereby avoiding the technical problem of low auditing efficiency caused by long time consumption and large workload caused by auditing a large number of network elements one by one. Moreover, the configuration data of the latest service twin in the existing network is used as a verification standard for scheme auditing, thereby improving the auditing accuracy and real-time performance. On the other hand, the method changes the current situation that the traditional configuration scheme auditing lacks a unified and reusable auditing standard. It is easy to be compatible with the configuration differences existing in the existing networks of various provinces.

[0013] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and are not limiting of the disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0014] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments consistent with the present disclosure and serve to explain the principles of the present disclosure. It is apparent that the accompanying drawings in the following description are only some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor based on these drawings.

[0015] Figure 1 An application scenario schematic diagram of an auditing requirement for network configuration data of a customized DNN service in the present exemplary embodiment is shown;

[0016] Figure 2 An architecture diagram of an auditing system for network configuration data in the present exemplary embodiment is shown;

[0017] Figure 3 A flowchart of an auditing method for network configuration data in the present exemplary embodiment is shown;

[0018] Figure 4A A structure schematic diagram of a customized DNN service in the present exemplary embodiment is shown;

[0019] Figure 4B A schematic diagram illustrating a network element configuration model for customizing a DNN service configuration instruction in this exemplary embodiment;

[0020] Figure 5 A schematic diagram illustrating a method for constructing a business twin model for a customized DNN business instance in this exemplary embodiment is shown;

[0021] Figure 6 A schematic diagram illustrating the structure of a network configuration data auditing device in this exemplary embodiment is shown;

[0022] Figure 7 The following schematically shows a structural diagram of an electronic device in this exemplary embodiment. DETAILED DESCRIPTION

[0023] The exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; on the contrary, these embodiments are provided so that the present disclosure will be more comprehensive and complete and the concepts of the exemplary embodiments will be fully conveyed to those skilled in the art. The described features, structures, or characteristics may be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced while omitting one or more of the specific details, or that other methods, components, devices, steps, etc. may be employed. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0024] In addition, the accompanying drawings are merely schematic illustrations of the present disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0025] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all steps. For example, some steps may be decomposed, while some steps may be combined or partially combined, so the actual execution order may change according to actual circumstances.

[0026] In the relevant technical context, routine network maintenance and service operations often involve issuing various network configuration plans to existing networks to implement network upgrades, maintenance, or service activation. A network configuration plan is essentially a collection of instructions, involving operations such as adding, deleting, and modifying existing network devices. Therefore, auditing each network configuration plan to ensure the correctness of issued instructions is crucial to the normal operation of the network.

[0027] The audit of network configuration plans mainly includes: auditing the integrity of instructions, verifying the conflicts of instruction parameter values, and verifying the dependencies of instruction parameter values.

[0028] In related technical solutions, the audit of network configuration solutions often involves formulating verification rules based on pre-set configuration specifications, and verifying each instruction in a series of instruction sets one by one.

[0029] In order to facilitate those skilled in the art to understand the audit process of the above network configuration scheme, the following will be combined with Figure 1 Taking the network configuration scheme of the customized Domain Name Network (DNN) service as an example, the audit method of the existing network configuration scheme is exemplified.

[0030] Figure 1 A schematic diagram of an application scenario of an audit requirement for network configuration data of a customized DNN service in this exemplary embodiment is shown, referring to Figure 1 As shown in the figure, the steps for customizing a DNN configuration specification typically include configuring the DNN, configuring an address pool, and binding the DNN to the address pool. The process of customizing a DNN configuration specification involves configuring each network element, configuring the content, and customizing the DNN activation plan for each network element in provinces A and B. Figure 1 The figure shows the instruction sets for each configuration network element in different configuration steps in provinces A and B.

[0031] When auditing the network configuration data of the customized DNN service, it is usually necessary to respectively check the integrity of the instructions, check the conflict of the instruction parameter values, and check the dependency of the instruction parameter values. Among them, the integrity of the instructions is checked according to the network configuration basis of each provincial region to determine the instruction integrity. For example, by comparing the configuration specification, the address pool instruction is missing in the customized DNN opening scheme of A province, but the address pool group "iot_pg1_fj" has been configured in the existing network, so it can be determined that the instruction is complete. For the conflict checking of the instruction parameter values, taking the DNN name of A province as an example, the configuration specification requires that the DNN name be unified throughout the network, which is "Micar.ctiot", so it can be determined that the instruction parameter values are not in conflict. For the dependency checking of the instruction parameter values, taking the DNN binding slice of B province as an example, the configuration specification requires that the pre-configuration of the existing network has been completed, that is, "NSIDX = 123" shown in the above formula (1), so the dependency checking of the instruction parameter values is completed. Figure 1

[0032] However, the inventors have found that the above technical solutions mainly face the following technical problems:

[0033] 1) The above related technical solutions take "instructions" as the auditing objects, and the configuration scheme takes "service objects" as the configuration objects. However, one service object needs to issue configuration instructions on multiple types of network elements. The existing network is complex, the number of network elements is large, and the auditing of the instruction parameter values needs to read data from the network elements, resulting in a large amount of work and low auditing efficiency.

[0034] 2) The business rules are hidden inside the configuration instructions, and the auditing rules involve implicit business rules. The operation personnel / operation and maintenance personnel need to understand complex business rules, thereby having a high technical threshold requirement, resulting in high auditing complexity.

[0035] 3) The existing network configuration schemes of different provincial regions have large differences, and the above related technical solutions are difficult to flexibly cope with the above configuration differences.

[0036] 4) The auditing method is tightly coupled with the configuration instructions of specific services, that is, one service corresponds to a set of configuration schemes and a set of business rules, which is difficult to reuse to other services.

[0037] ​The exemplary embodiment of the present disclosure considers the above problems, and proposes a network configuration data auditing method, which converts the original instruction-oriented auditing method into a service object-centered auditing method, thereby avoiding the technical problem of low auditing efficiency caused by long time consumption and large workload caused by auditing a large number of network elements one by one. Moreover, the latest service twin configuration data of the existing network is used as the verification standard for scheme auditing, thereby improving the auditing accuracy and real-time performance. On the other hand, the method changes the current situation that the traditional configuration scheme auditing lacks a set of unified and reusable auditing standards, and is easy to be compatible with the configuration differences existing in the existing network of each province.

[0038] The following will be described in combination with Figure 2 The network configuration data auditing method and device proposed by the present disclosure are applied to Figure 2 The system architecture of the exemplary application environment shown in the exemplary application environment is exemplarily illustrated.

[0039] Figure 2 The architecture diagram of a network configuration data auditing system in the exemplary embodiment is shown in FIG. 1. Figure 2 As shown in FIG. 2, an application scenario schematic diagram provided by the embodiment of the present disclosure is shown, which can include a terminal device 101 and a server 102.

[0040] The terminal device 101 can be any device related to triggering the auditing of network configuration data, such as a mobile phone, a tablet computer (PAD), a notebook computer, a desktop computer, a smart television, a smart vehicle device, a smart wearable device, a smart television, and an aircraft, etc. The terminal device 101 can be installed with a target application, which can have the functions of network configuration scheme, presenting the auditing result of the network configuration scheme, etc. The application related by the embodiment of the present disclosure can be a software client, a web page, a small program, etc. The server 102 is a server corresponding to the software or the web page, the small program, etc., and the specific type of the client is not limited.

[0041] The server 102 can be a background server of the target application, which is used to provide corresponding background services, such as the service of auditing the network configuration data and generating the auditing result. It can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content distribution networks (CDN), and big data and artificial intelligence platforms, etc. basic cloud computing services, but is not limited thereto.

[0042] It should be noted that the network configuration data auditing method in the embodiments of the present disclosure can be performed by the terminal device 101 or the server 102 alone, or can be performed by the server 102 and the terminal device 101 together. In actual application, specific configuration can be made according to the situation, and the present disclosure does not make specific limitation here.

[0043] The server 102 and the terminal device 101 can each include one or more processors, memories, and I / O interfaces for interaction, etc. In addition, the server 102 can also be configured with a database, which can be used to store the parameters of the network element twin model and the network element configuration model, etc. The memories of the server 102 and the terminal device 101 can also store program instructions required for the respective execution of the network configuration data auditing method provided by the embodiments of the present disclosure, and these program instructions can be used to implement the network configuration data auditing process provided by the embodiments of the present disclosure when executed by the processor.

[0044] It should be noted that when the network configuration data auditing method provided by the embodiments of the present disclosure is performed by the server 102 or the terminal device 101 alone, the application scenarios described above can also only include a single device of the server 102 or the terminal device 101, or the server 102 and the terminal device 101 can be considered as the same device. Of course, in actual application, when the network configuration data auditing method provided by the embodiments of the present disclosure is performed by the server 102 and the terminal device 101 together, the server 102 and the terminal device 101 can also be the same device, i.e., the server 102 and the terminal device 101 can be different functional modules of the same device, or virtual devices virtualized by the same physical device.

[0045] In the embodiments of the present disclosure, the terminal device 101 and the server 102 can be directly or indirectly connected through one or more networks 103. The network 103 can be a wired network or a wireless network, for example, the wireless network can be a mobile cellular network or a wireless fidelity (WIFI) network, and of course can also be other possible networks, which are not limited in the embodiments of the present disclosure. It should be noted that, Figure 1 The above figure is only illustrative, and in fact the number of terminal devices and servers is not limited, which is not specifically limited in the embodiments of the present disclosure.

[0046] For example, in an example embodiment, a network element twin of an actual network element is generated based on digital twin technology, the network element twin corresponding network element data containing at least instruction configuration data; the instruction configuration data is encapsulated according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; a plurality of network element configuration twins are associated based on a pre-constructed service twin model to generate a first service object, and a service twin is generated based on the first service object; wherein each service twin corresponds to a service instance in an actual network; for each instruction configuration data in a network configuration scheme to be issued, a configuration instance corresponding to each instruction configuration data is generated according to the network element configuration model, and a plurality of configuration instances are associated based on the service twin model to generate a second service object, and a to-be-issued instance is generated based on the second service object; the to-be-issued instance is audited based on the service instance in the actual network to obtain an audit result.

[0047] However, those skilled in the art will readily understand that the above application scenarios are only for example, and the example embodiments are not limited thereto.

[0048] Next, the method provided by the example embodiments of the present disclosure will be described in combination with the above-described application scenarios and with reference to the accompanying drawings. It should be noted that the above-described application scenarios are only shown to facilitate understanding of the spirit and principles of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. It should be noted that the following method can be executed by the terminal device or the server, or by the terminal device and the server together, and here the terminal device or the server is taken as an example.

[0049] Referring to Figure 3 Fig. 1 is a flowchart of a network configuration data auditing method provided by an embodiment of the present disclosure. The method can be executed by a computer device, which can be a terminal device or a server as shown in Fig. 1. The specific implementation process of the method includes the following steps 301 to 305. Figure 2

[0050] Step 301, generating a network element twin of an actual network element based on digital twin technology, the network element twin corresponding network element data containing at least instruction configuration data.

[0051] Step 302, encapsulating the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data.

[0052] Step 303, associating a plurality of network element configuration twins based on a pre-constructed service twin model to generate a first service object, and generating a service twin based on the first service object; wherein each service twin corresponds to a service instance in an actual network.

[0053] ​In step 304, for each instruction configuration data in the network configuration scheme to be issued, a configuration instance corresponding to each instruction configuration data is generated according to the network element configuration model, and a plurality of configuration instances are associated based on the service twin model to generate a second service object, and the second service object is used to generate an instance to be issued.

[0054] In step 305, the instance to be issued is audited based on the service instance in the actual network, and an auditing result is obtained.

[0055] In the technical solution provided in some embodiments of the present disclosure, a network element twin corresponding to an actual network element is generated based on digital twin technology, and the network element data corresponding to the network element twin at least includes instruction configuration data; the instruction configuration data is encapsulated according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; a plurality of network element configuration twins are associated based on a pre-constructed service twin model to generate a first service object, and a service twin is generated based on the first service object; each service twin corresponds to a service instance in an actual network; for each instruction configuration data in a network configuration scheme to be issued, a configuration instance corresponding to each instruction configuration data is generated according to the network element configuration model, and a plurality of configuration instances are associated based on the service twin model to generate a second service object, and the second service object is used to generate an instance to be issued; the instance to be issued is audited based on the service instance in the actual network, and an auditing result is obtained. This method changes the original instruction-based auditing method to a service object-centered auditing method, thereby avoiding the technical problems of long time consumption and large workload caused by auditing a large number of network elements one by one, and low auditing efficiency. Moreover, the latest configuration data of the service twin in the existing network is used as the verification standard for scheme auditing, which improves the auditing accuracy and real-time performance. On the other hand, this method changes the current situation that the traditional configuration scheme auditing lacks a unified and reusable auditing standard, and is easy to be compatible with the configuration differences existing in the existing networks of various provinces.

[0056] The specific implementation of each step in the embodiments will be described in detail below in combination with specific embodiments: Figure 3

[0057] In step 301, a network element twin corresponding to an actual network element is generated based on digital twin technology, and the network element data corresponding to the network element twin at least includes instruction configuration data.

[0058] The actual network element is a network element device in a real network (i.e., an actual network / actual networking), the network element twin is a network element device in a digital twin environment constructed for the network element device in the real network, and the network element twin in the digital twin environment has the same network relationship, network element data, and other parameters as the network elements in the actual physical network.

[0059] ​For example, a network element twin of an actual network element can be generated using digital twin technology, and the network element data collected in real time from the actual network element can be synchronized to the network element twin to obtain the network element data corresponding to the network element twin. The instruction configuration data contained in the network element data can be configuration instructions issued to the network element.

[0060] It should be noted that when generating network element twins of actual network elements based on digital twin technology, network element twins can be created for some network elements in the actual networking, or for all network elements. The specific details can be determined based on actual conditions, and the embodiments of the present disclosure do not impose any special restrictions on this.

[0061] In step 302, the instruction configuration data is encapsulated according to the pre-built network element configuration model to obtain the network element configuration twin corresponding to the instruction configuration data.

[0062] Among them, the network element configuration model is used to describe the configuration instructions (i.e., instruction configuration data) supported by a type of network element, and a configuration instruction on the network element corresponds to a network element configuration model. Correspondingly, each instruction configuration data on the network element twin corresponds to a network element configuration twin.

[0063] When executing step 302, in an optional embodiment, target instruction configuration data with instruction configuration parameters is searched from all instruction configuration data on the network element twin to encapsulate the target instruction configuration data and obtain the network element configuration twin corresponding to the target instruction configuration data.

[0064] by Figure 4B The command configuration parameters of the Session Management Function (SMF) network element shown correspond to attributes, such as the APN (Access Point Name) corresponding to attribute 1.

[0065] In this embodiment, since the audit of the network element configuration plan mainly focuses on the instruction configuration parameters, constructing network element configuration twins only for network element twins with instruction configuration parameters can reduce the amount of calculation and improve the audit efficiency.

[0066] In an optional embodiment of the present disclosure, the constructed network element configuration model includes one or more of a configuration model name, a configuration specification, a command parameter list, and a parameter constraint condition.

[0067] The configuration specification is composed of the "network element type" and "command keyword" corresponding to the network element configuration model. For example, "network element type_command keyword", for example, the configuration specification for the SMF network element may be "SMF_APN".

[0068] The instruction parameter list represents the parameter list contained in the configuration instruction. It should be noted that the instruction parameter list can be a parameter list generated by modeling part or all parameters of the configuration instruction. Whether to model can be adjusted according to actual needs.

[0069] The parameter constraint condition is used to describe the limitation of the instruction parameter value, and is usually used to realize the conflict check of the parameter value. Figure 1 As shown in the DNN name, the parameter constraint condition can limit the DNN name in A province to be unique.

[0070] In an embodiment, the network element configuration model usually contains a configuration model name, a configuration specification, an instruction parameter list, and the parameter constraint condition can exist or not exist. In order to facilitate the understanding of those skilled in the art, the same custom DNN service is taken as an example, and the network element configuration model of the configuration instruction related to the custom DNN service is described in combination with Figure 4B The network element configuration model of the configuration instruction related to the custom DNN service is described in combination with

[0071] Based on Figure 1 The network element configuration model of the configuration instruction related to the custom DNN service is described in combination with Figure 4A Fig. 1 shows a structure diagram of a custom DNN service in an example embodiment; and Figure 4A The network element configuration model of the configuration instruction related to the custom DNN service is described in combination with Figure 4B Fig. 1 shows a structure diagram of a custom DNN service in an example embodiment; and Figure 4B As shown in Fig. 1, Figure 4B The network element configuration model of the configuration instruction related to the custom DNN service is described in combination with Figure 4A Corresponding to the network structure for executing the custom DNN service, at least containing SMF network element, UPF network element, AMF network element, PCF network element, etc., taking the SMF network element and the UPF network element as an example, Figure 4B The network element configuration model of the configuration instruction related to the custom DNN service is described in combination with

[0072] The network element configuration model of the configuration instruction related to the custom DNN service is described in combination with Figure 4BFor the SMF network element's DNN binding slice's configuration instruction, the generated network element configuration model contains a configuration model name "SMF network element DNN binding slice", a configuration specification "SMF_NSDNN", and instruction parameters "NSIDX", "DNN" in the instruction parameter list, and the corresponding parameter constraint condition is the default state. For the SMF network element's configuration DNN instruction, the generated network element configuration model contains a configuration model name "SMF network element configuration DNN", a configuration specification "SMF_APN", and instruction parameters "APN" in the instruction parameter list, and the corresponding parameter constraint condition is "APN value "provincial unique"".

[0073] In step 303, the plurality of network element configuration twin bodies are associated based on the pre-constructed service twin model to generate a first service object, and a service twin body is generated based on the first service object; wherein each service twin body corresponds to a service instance in an actual network.

[0074] The service twin model is used to fuse a plurality of network element configuration twin bodies of multiple types of network elements, thereby realizing a service twin body for a service object, so as to establish a fused service twin model for a service object.

[0075] In an optional embodiment of the present disclosure, the service twin model further contains a service identifier of a service, a service object, a mapping relationship between the service object and the network element configuration twin body, and a constraint condition of the network element configuration twin body.

[0076] The above-mentioned service identifier, i.e. a unique service identifier for a service instance, can also realize retrieval of all sub-service object instances contained in a service instance through the service identifier.

[0077] For the above-mentioned service object, each service instance can contain one or more service objects. For example Figure 4B The customized DNN service instance shown contains three service objects "DNN", "slice", and "address pool".

[0078] Based on the mapping relationship between the above-mentioned service object and the network element configuration twin body, the instruction configuration data of one service object is usually scattered in different types of network element twin bodies, so one service object can be mapped to a plurality of network element configuration twin bodies of multiple types of network elements.

[0079] Based on the constraint condition of the network element configuration twin body, the constraint condition is used to define the value association relationship of the instruction configuration parameters between two network element configuration twin bodies; the constraint condition of the network element configuration twin body is usually used to realize parameter value dependency check in a network configuration scheme.

[0080] In order to facilitate understanding of the above-mentioned service twin model, the following will be described in the above-mentionedFigure 4A 、 Figure 4B Based on the customized DNN service instance shown in FIG. 8, combined with the service twin model shown in FIG. 9, the process of constructing the service twin model is exemplarily illustrated. Figure 5

[0081] Figure 5 FIG. 10 shows a schematic diagram of constructing a service twin model for a customized DNN service instance in the present exemplary embodiment, referring to FIG. 10, the service name, service identifier, service object, and constraint condition of the network element configuration twin are labeled in the figure, and the value association relationship of the instruction configuration parameter between the network element configuration twins is defined. Figure 5

[0082] Exemplarily, since the instruction configuration data of one service object is usually scattered in different types of network element twins, after generating the network element configuration twins, the multiple network element configuration twins corresponding to the cross-type network element twins can be associated to generate the first service object, so as to assemble the service twin corresponding to the first service object, and one service twin is mapped to one service instance in the actual network element.

[0083] In step 304, for each instruction configuration data in the network configuration scheme to be delivered, the configuration instance corresponding to each instruction configuration data is generated according to the network element configuration model, and the multiple configuration instances are associated based on the service twin model to generate the second service object, and the instance to be delivered is generated based on the second service object.

[0084] Exemplarily, the network configuration scheme to be delivered is a set of configuration instructions, that is, it contains multiple instruction configuration data. By generating the configuration instance corresponding to each instruction configuration data in the network configuration scheme to be delivered according to the network element configuration model, and associating the multiple configuration instances based on the service twin model, the second service object is generated, and one instance to be delivered is assembled based on the second service object.

[0085] In step 305, the instance to be delivered is audited based on the service instance in the actual network, and the audit result is obtained.

[0086] In an optional embodiment of the present disclosure, based on the audit request for the network configuration scheme to be delivered, the operation type for the network configuration scheme to be delivered is judged; the instance to be delivered is audited based on the operation type, and the audit result is obtained.

[0087] Exemplarily, the operation type is determined according to the instruction, which includes operation types such as ADD, DEL, and MOD. The following will be described respectively in combination with specific embodiments.

[0088] Embodiment 1:

[0089] ​​If the operation type is an addition operation, according to the instance to be issued, a search is performed from the service instance in the actual network, so as to search for the same service instance as the instance to be issued, and if the same service instance is searched, the audit result is an audit failure.

[0090] This embodiment is to check the existence of the service instance, that is, according to the service identifier of the service to be issued, the service twin in the existing network is searched; if the same service instance is searched, the audit result is an audit failure.

[0091] And / or, if there is a configuration instance in the instance to be issued that is not defined by the service twin model, the audit result is an audit failure.

[0092] In this embodiment, the redundant instructions of the service to be issued are checked. Specifically, if there is a configuration instance in the instance to be issued that is not defined by the service twin model, it is a redundant instruction, and the audit fails.

[0093] And / or, based on the instruction configuration parameter in the instance to be issued, the associated configuration instance is not searched in the service instance in the actual network, and the audit result is an audit failure.

[0094] In this embodiment, the parameter value dependency check of the service to be issued is implemented. Specifically, according to the association relationship of the configuration model, if the value of a parameter is not searched in the "predecessor configuration instance" of the "to-be-issued" service instance, and is also not searched in the "predecessor configuration instance" of the existing network, it is a missing instruction, and the audit fails.

[0095] And / or, based on the attribute constraint condition of the configuration instance in the instance to be issued, the corresponding service twin is not searched from the service instance in the actual network, and the audit result is an audit failure.

[0096] In this embodiment, the parameter value conflict check of the service to be issued is implemented: according to the attribute constraint condition defined in the "configuration model", the service twin in the existing network is searched, and it is determined whether there is a parameter value that conflicts with the existing network.

[0097] Embodiment 2:

[0098] If the operation type is a modification operation or a deletion operation, according to the instance to be issued, a search is performed from the service instance in the actual network, so as to search for the same service instance as the instance to be issued, and if the same service instance is searched, the audit result is an audit failure;

[0099] And / or, if there is a configuration instance in the instance to be issued that is not defined by the service twin model, the audit result is an audit failure.

[0100] And / or, based on the instruction configuration parameter in the instance to be issued, the associated configuration instance is not searched in the service instance in the actual network, and the audit result is an audit failure.

[0101] And / or, based on the attribute constraint condition of the configuration instance in the to-be-deployed instance, the corresponding service twin is not searched from the service instance in the actual network, and the audit result is audit failure.

[0102] That is, through the above embodiment, the existence verification of the service instance, the redundant instruction verification, the parameter value dependency verification, and the parameter value conflict verification can be performed. Among them, the existence verification of the service instance is that the same service instance as the to-be-deployed instance is not searched from the service instance in the actual network, and then the modification, deletion and other operations cannot be performed, and it can be judged that the audit fails.

[0103] In order to implement the above network configuration data auditing method, one embodiment of the present disclosure provides a network configuration data auditing device. Figure 6 The schematic architecture diagram of the network configuration data auditing device is schematically shown.

[0104] The network configuration data auditing device 600 comprises a twin generation module 601, an encapsulation module 602, a first service object generation module 603 and a second service object generation module 604, and an auditing module 605.

[0105] The twin generation module 601 is configured to generate a network element twin of an actual network element based on a digital twin technology, wherein the network element data corresponding to the network element twin at least comprises instruction configuration data; the encapsulation module 602 is configured to encapsulate the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; the first service object generation module 603 is configured to associate a plurality of network element configuration twins based on a pre-constructed service twin model to generate a first service object, and generate a service twin based on the first service object; wherein each service twin corresponds to a service instance in an actual network; the second service object generation module 604 is configured to, for each instruction configuration data in a to-be-deployed network configuration scheme, generate a configuration instance corresponding to each instruction configuration data according to the network element configuration model, and associate a plurality of configuration instances based on the service twin model to generate a second service object, and generate a to-be-deployed instance based on the second service object; and the auditing module 605 is configured to audit the to-be-deployed instance based on the service instance in the actual network to obtain an audit result.

[0106] In an optional embodiment of the present disclosure, the network element configuration model comprises one or more of a configuration model name, a configuration specification, an instruction parameter list, and a parameter constraint condition; wherein the configuration specification is composed of a network element type and an instruction keyword corresponding to the network element configuration model, and each instruction configuration data corresponds to one network element configuration model.

[0107] In an optional embodiment of the present disclosure, the encapsulation module 602 is specifically configured to search for target instruction configuration data with instruction configuration parameters from all instruction configuration data on the network element twin, encapsulate the target instruction configuration data, and obtain a network element configuration twin corresponding to the target instruction configuration data.

[0108] In an optional embodiment of the present disclosure, the service twin model comprises a service identifier of the service, a service object, a mapping relationship between the service object and the network element configuration twin, and a constraint condition of the network element configuration twin; each service comprises one or more service objects.

[0109] In an optional embodiment of the present disclosure, the auditing module 605 is specifically configured to determine an operation type of the network configuration scheme to be delivered based on an auditing request for the network configuration scheme to be delivered, and perform auditing on the instance to be delivered based on the operation type, to obtain an auditing result.

[0110] In an optional embodiment of the present disclosure, the auditing module 605 is specifically configured to, if the operation type is an addition operation, search for the instance to be delivered from service instances in an actual network, and if the same service instance as the instance to be delivered is searched, the auditing result is an auditing failure.

[0111] And / or, if there is a configuration instance in the instance to be delivered that is not defined by the service twin model, the auditing result is an auditing failure.

[0112] And / or, if an associated configuration instance is not searched from the service instances in the actual network based on the instruction configuration parameter in the instance to be delivered, the auditing result is an auditing failure.

[0113] And / or, if a corresponding service twin is not searched from the service instances in the actual network based on the attribute constraint condition of the configuration instance in the instance to be delivered, the auditing result is an auditing failure.

[0114] In an optional embodiment of the present disclosure, the auditing module 605 is specifically configured to, if the operation type is a modification operation or a deletion operation, search for the instance to be delivered from service instances in an actual network, and if the same service instance as the instance to be delivered is not searched, the auditing result is an auditing failure.

[0115] And / or, if there is a configuration instance in the instance to be delivered that is not defined by the service twin model, the auditing result is an auditing failure.

[0116] And / or, if an associated configuration instance is not searched from the service instances in the actual network based on the instruction configuration parameter in the instance to be delivered, the auditing result is an auditing failure.

[0117] And / or, based on the attribute constraint condition of the configuration instance in the instance to be issued, the corresponding service twin is not searched from the service instance in the actual network, and the audit result is an audit failure.

[0118] The network configuration data auditing apparatus 600 provided by the embodiments of the present disclosure can implement the technical solutions of the network configuration data auditing method in any of the above embodiments, and the implementation principles and beneficial effects thereof are similar to those of the network configuration data auditing method. For details, refer to the implementation principles and beneficial effects of the network configuration data auditing method, which will not be described here again.

[0119] In the exemplary embodiments of the present disclosure, a computer readable storage medium having a program product stored thereon capable of implementing the above-mentioned method of the present disclosure is also provided. In some possible implementation manners, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program codes for causing a terminal device to perform the steps described in the above-mentioned “Exemplary Method” section of the present disclosure according to various exemplary embodiments of the present disclosure when the program product is run on the terminal device.

[0120] The program product for implementing the above-mentioned method according to the embodiments of the present disclosure can adopt a portable compact disc read-only memory (CD-ROM) and include program codes, and can be run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited to this, and in the present document, the readable storage medium can be any tangible medium containing or storing a program, which can be used by or in conjunction with an instruction execution system, apparatus or device.

[0121] The program product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium may, for example, be but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus or device, or any combination of the above. More specific examples (non-exhaustive list) of readable storage media include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0122] The computer readable medium can include a computer-readable signal medium and / or computer-readable storage medium. A computer readable signal medium can include a propagated data signal with computer executable instructions. A computer readable storage medium can include any non-transitory medium that can store computer executable instructions such as volatile memory or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, or a combination of the two.

[0123] Program code embodied on a computer readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, Radio Frequency (RF), etc., or any suitable combination of the foregoing.

[0124] Program code, used by or in connection with the described embodiments, can be written in any suitable programming language such as object oriented programming languages, like Java, C++, and the like, conventional procedural programming languages, such as the "C" programming language, or the like, and / or combinations of the foregoing. Program code can execute entirely on a user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote cloud device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any suitable network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device such as through the Internet using an Internet Service Provider (ISP).

[0125] In an exemplary embodiment of the present disclosure, an electronic device capable of implementing the above-described method is also provided.

[0126] Those skilled in the art can understand that each aspect of the present disclosure can be implemented as a system, a method or a program product. Therefore, each aspect of the present disclosure can be embodied as a whole hardware embodiment, a whole software embodiment (including firmware, microcode, etc.), or a combination of hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system".

[0127] The electronic device 700 according to this embodiment of the present disclosure will be described below with reference to Figure 7 Figure 7 The electronic device 700 shown is merely an example and should not limit the function and usage of the embodiments of the present disclosure.

[0128] As Figure 7 ​As shown, the electronic device 700 is in the form of a general computing device. Components of the electronic device 700 can include, but are not limited to, the at least one processing unit 710 described above, the at least one storage unit 720 described above, a bus 730 that connects the various system components, including the storage unit 720 and the processing unit 710, a display unit 740.

[0129] The storage unit stores program code that can be executed by the processing unit 710 such that the processing unit 710 performs the steps according to various exemplary embodiments of the present application described in the "Exemplary Methods" section of the present specification. For example, the processing unit 710 can execute the steps 301 to 305 as shown in FIG. 3. Figure 3 The processing unit 710 can execute the steps 401 to 405 as shown in FIG. 4.

[0130] The storage unit 720 can include a readable medium in the form of volatile storage such as a random access memory (RAM) 7201 and / or cache memory 7202, and can further include a non-volatile storage such as read-only memory (ROM) 7203.

[0131] The storage unit 720 can further include program / utility 7204 having a set of at least one program modules 7205 including operating system, one or more application programs, other program modules, and program data, and can include implementations of a network environment, each or a combination thereof.

[0132] The bus 730 can be representative of one or more of several types of bus structures, including a storage bus or bus controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of a variety of bus structures.

[0133] The electronic device 700 can also communicate with one or more external devices 1000 such as a keyboard or pointing device, a Bluetooth device, or a device for reading media. Communication with one or more devices for enabling a user to interact with the electronic device 700 can be performed through input / output (I / O) interface 750. Also, the electronic device 700 can communicate with one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or the public network, such as the Internet, through network adapter 760. As depicted, network adapter 760 is in communication with the other components of electronic device 700 through bus 730. It should be appreciated that other hardware and / or software modules can be used in conjunction with the electronic device 700, including but not limited to microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.

[0134] From the above description of the embodiments, it is easy for those skilled in the art to understand that the example embodiments described herein can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, etc.) or a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.

[0135] In addition, the above-described diagrams are only schematic illustrations of the processes included in the method according to the example embodiments of the present application, and are not intended to be limiting. It is easy to understand that the processes shown in the above-described diagrams do not indicate or limit the time sequence of the processes. In addition, it is also easy to understand that the processes can be executed synchronously or asynchronously, for example, in multiple modules.

[0136] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such a division is not mandatory. Indeed, according to the embodiments of the present disclosure, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into embodied by multiple modules or units.

[0137] Other embodiments of the disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. It is intended that the disclosure be construed as including any paterns of this disclosure that can be derived from the description and illustrations presented herein without departing from the scope and spirit of the disclosure. The specification and examples given are considered exemplary only, and the true scope and spirit of the disclosure are indicated by the claims.

[0138] It is to be understood that the disclosure is not limited to the precise construction described above and shown in the attached drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the disclosure is limited only by the claims that follow.

Claims

1. A method of auditing network configuration data, characterized by, The method comprises the following steps: generating a network element twin of an actual network element based on a digital twin technology, wherein the network element twin contains at least instruction configuration data in corresponding network element data; encapsulating the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; associating a plurality of network element configuration twins based on a pre-constructed service twin model to generate a first service object, and generating a service twin based on the first service object, wherein each service twin corresponds to a service instance in an actual network; for each instruction configuration data in a network configuration scheme to be delivered, generating a configuration instance corresponding to each instruction configuration data according to the network element configuration model, and associating a plurality of configuration instances based on the service twin model to generate a second service object, and generating a to-be-delivered instance based on the second service object; auditing the to-be-delivered instance based on the service instance in the actual network to obtain an audit result.

2. The method of claim 1, wherein, The network element configuration model contains one or more of a configuration model name, a configuration specification, an instruction parameter list, and a parameter constraint condition; wherein the configuration specification is composed of a network element type and an instruction keyword corresponding to the network element configuration model, and each instruction configuration data corresponds to one network element configuration model.

3. The method according to claim 1 or 2, characterized in that, The method of encapsulating the instruction configuration data according to the pre-constructed network element configuration model to obtain the network element configuration twin corresponding to the instruction configuration data comprises: finding target instruction configuration data with instruction configuration parameters from all instruction configuration data on the network element twin, and encapsulating the target instruction configuration data to obtain the network element configuration twin corresponding to the target instruction configuration data.

4. The method of claim 1, wherein, The service twin model contains a service identifier, a service object, a mapping relationship between the service object and the network element configuration twin, and a constraint condition of the network element configuration twin of the service; wherein each service contains one or more service objects.

5. The method of claim 1, wherein, The method of auditing the to-be-delivered instance based on the service instance in the actual network to obtain an audit result comprises: judging an operation type of the to-be-delivered network configuration scheme based on an audit request for the to-be-delivered network configuration scheme; auditing the to-be-delivered instance based on the operation type to obtain an audit result.

6. The method of claim 5, wherein, The method of auditing the to-be-delivered instance based on the operation type to obtain an audit result comprises: if the operation type is an addition operation, searching for the to-be-delivered instance from the service instance in the actual network, and if the same service instance as the to-be-delivered instance is searched, the audit result is an audit failure; and / or, if there is a configuration instance in the to-be-delivered instance that is not defined by the service twin model, the audit result is an audit failure; and / or, if an associated configuration instance is not searched from the service instance in the actual network based on the instruction configuration parameter in the to-be-delivered instance, the audit result is an audit failure. And / or, based on the attribute constraint condition of the configuration instance in the to-be-deployed instance, if a corresponding service twin is not searched from the service instance in the actual network, the audit result is an audit failure.

7. The method of claim 5, wherein, The audit method comprises the following steps: If the operation type is a modification operation or a deletion operation, the to-be-deployed instance is searched from the service instance in the actual network, and if a service instance identical to the to-be-deployed instance is not searched, the audit result is an audit failure; And / or, if there is a configuration instance in the to-be-deployed instance that is not defined by the service twin model, the audit result is an audit failure; And / or, based on the instruction configuration parameter in the to-be-deployed instance, if an associated configuration instance is not searched from the service instance in the actual network, the audit result is an audit failure; And / or, based on the attribute constraint condition of the configuration instance in the to-be-deployed instance, if a corresponding service twin is not searched from the service instance in the actual network, the audit result is an audit failure.

8. An auditing apparatus of network configuration data, characterized by, The device comprises: A twin generation module configured to generate a network element twin of an actual network element based on a digital twin technology, wherein the network element twin corresponds to network element data containing at least instruction configuration data; An encapsulation module configured to encapsulate the instruction configuration data according to a pre-constructed network element configuration model to obtain a network element configuration twin corresponding to the instruction configuration data; A first service object generation module configured to associate a plurality of network element configuration twins based on a pre-constructed service twin model to generate a first service object, and generate a service twin based on the first service object, wherein each service twin corresponds to a service instance in an actual network; A second service object generation module configured to, for each instruction configuration data in a to-be-deployed network configuration scheme, generate a configuration instance corresponding to each instruction configuration data according to the network element configuration model, and associate a plurality of configuration instances based on the service twin model to generate a second service object, and generate a to-be-deployed instance based on the second service object; An audit module configured to audit the to-be-deployed instance based on a service instance in an actual network to obtain an audit result.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by a processor, implements the network configuration data audit method of any one of claims 1 to 7.

10. An electronic device, comprising: Comprise: A processor; And A memory for storing executable instructions of the processor; Wherein the processor is configured to execute the network configuration data audit method of any one of claims 1 to 7 by executing the executable instructions.

Citation Information

Patent Citations

  • Network element configuration data verification method and device, storage medium and system

    CN112583869A

  • Business interface generation method, business interface generation device, electronic equipment and medium

    CN116880840A