A Smart VPN Service Automatic Activation System and its Resource Conflict Detection Method

The intelligent VPN service automatic activation system uses the proportion of clock cycles to generate a control plane node set, quantifies the scope of resource conflicts, solves the problem of resource detection before VPN service activation, achieves secure isolation after VPN service activation, and improves the efficiency and security of VPN service activation.

CN119697021BActive Publication Date: 2025-10-28INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411818188.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-10-28
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

During the expansion of VPN services, the SDN controller has difficulty in defining dynamic resource detection limits before the VPN service is activated, making it difficult to achieve security isolation after the VPN service is activated.

Method used

Design an intelligent VPN service automatic provisioning system, including a network structure module, an interface protocol module, a node layering module, and a VPN service automatic provisioning detection and optimization module. By collecting the percentage of clock cycles inside the SDN controller, a control plane node set is generated, the scope of resource conflicts is quantified, and a recommended deployment configuration scheme is provided to avoid security isolation requirements.

Benefits of technology

It enables dynamic resource detection before VPN service activation, ensuring secure isolation after VPN service activation, and improving the efficiency and security of VPN service activation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119697021B_ABST
    Figure CN119697021B_ABST
Patent Text Reader

Abstract

This invention discloses an intelligent VPN service automatic activation system and its resource conflict detection method, belonging to the field of VPN service technology. The system includes: a network structure module for identifying SDN controllers and communication links in the network structure; an interface protocol module for defining service requirements using software protocols and capturing parameter characteristics of SDN controller operation; a node layering module for layering and dynamic updating of the control plane based on the time span of VPN service; and a VPN service automatic activation detection optimization module for detecting the resource conflict range of the SDN controller and optimizing the deployment configuration scheme before automatic VPN service activation. This invention enables the dynamic detection limits of SDN controller resources across nodes for different services to be defined before VPN service activation, which is beneficial for secure isolation after VPN service activation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of VPN service technology, specifically to an intelligent VPN service automatic activation system and its resource conflict detection method. Background Technology

[0002] VPN, or Virtual Private Network, refers to a private, secure data communication network built on top of public network infrastructure by an ISP or other NSP. This leased network is logical rather than physical. The SDN controller, as a network operating system, does not directly control the network hardware, but it runs as software, which facilitates automated network management and improves the efficiency of VPNs in allowing users to customize the network to best suit their needs.

[0003] When implementing centralized and intelligent SDN control strategies for VPN services, the increasing demand for VPN service expansion leads to a growing challenge in handling dynamic resource conflicts. Within the SDN controller, network protocol interactions are achieved through programming interfaces. The SDN controller, as a central node, isolates the control plane from the data plane to configure and manage VPN services. While defining service requirements through software protocols can improve the efficiency of integrated SDN control, it's difficult to define the dynamic resource detection limits across nodes and services on the SDN controller before VPN service activation, which hinders secure isolation after activation. Summary of the Invention

[0004] The purpose of this invention is to provide an intelligent VPN service automatic activation system and its resource conflict detection method to solve the problems mentioned in the background art.

[0005] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0006] A smart VPN service automatic activation system, comprising: a network structure module, an interface protocol module, a node layering module, and a VPN service automatic activation detection and optimization module;

[0007] The network structure module is used to compile and statistically analyze each SDN controller and communication link in the network structure.

[0008] The interface protocol module is used to provide an interaction protocol for the internal programming interface of the SDN controller, and to capture the communication links of the internal programming interface access between the SDN controllers based on the VPN service function; it is also used to collect the percentage of clock cycles generated by the SDN controller as the control plane node when the internal programming interface of the SDN controller accesses the communication link.

[0009] The node layering module is used to collect the clock cycle ratio and generate a control plane node set; it is also used to layer the VPN service time range and use the VPN service time range as the clock cycle range generated by each communication link from the start of access to the end of access, and to perform dynamic update operation of the control plane node set.

[0010] The VPN service auto-enabling detection and optimization module, based on the updated control plane node set, is used to detect the resource conflict range of the SDN controller and quantify the conflict overlap scale between SDN controllers; based on the conflict overlap scale, it recommends a deployment configuration scheme for automatic VPN service enabling.

[0011] Furthermore, the network structure module includes a network structure identification unit and a link information coordination unit:

[0012] The network structure identification unit is used to identify the SDN controller and each programming interface inside the SDN controller in the network structure, so as to uniformly encode and file each SDN controller and each programming interface respectively.

[0013] The link information coordination unit is used to separate each programming interface through the communication link to form a link interface set.

[0014] Furthermore, the interface protocol module includes a protocol access unit and a resource feature tag unit:

[0015] The protocol access unit is used to provide the interaction protocol between programming interfaces during VPN service. When a programming interface generates an access behavior to the communication link, the accessed programming interface is used to lock the SDN controller and capture the accessed communication link.

[0016] The resource feature tag unit is used to collect clock cycle feature parameters generated by the SDN controller during the period from the start of access to the end of access to the communication link. The clock cycle feature parameters are the sum of the number of clock cycles generated when each programming interface inside the SDN controller executes code programs. It is also used to collect the total number of clock cycles generated by the accessed communication link when the programming interface inside the SDN controller accesses the communication link.

[0017] Furthermore, the node hierarchical module includes a control plane node unit and a hierarchical update unit:

[0018] The control plane node unit is used to collect the percentage of clock cycles generated when the programming interface inside the SDN controller accesses each communication link, in order to generate a control plane node set.

[0019] The hierarchical update unit is used to pre-divide VPN service time range segments and use VPN service time range segments to hierarchically divide the clock cycle range generated during the period from the start of access to the end of access to the communication link, so as to meet the update requirements of the control plane node set.

[0020] Furthermore, the VPN service automatic activation detection and optimization module includes an activation detection unit and a resource conflict optimization unit:

[0021] The activation detection unit is used to select the maximum and minimum values ​​of the proportion of clock cycles in the updated control plane node set to quantify the upper and lower limits of the detected resource conflict range, and to calibrate the conflict overlap scale between SDN controllers based on the resource conflict range.

[0022] The resource conflict optimization unit determines whether there is a security isolation requirement between SDN controllers based on the conflict overlap scale. Based on the determination result, it does not recommend deploying and configuring VPN services on SDN controllers with security isolation requirements within the VPN service service time range.

[0023] A method for detecting resource conflicts in intelligent VPN services, comprising the following steps:

[0024] Step S1: Identify the SDN controller, the programming interface inside the SDN controller, and the communication links in the network structure;

[0025] Step S2: Using the SDN controller as the control plane, lock each SDN controller that generates VPN service behavior and capture the adapted communication links. Collect the percentage of clock cycles based on the capture results of the communication links.

[0026] Step S3: Record the percentage of collected clock cycles into the control plane node set, and update the control plane node set hierarchically based on the VPN service time range;

[0027] Step S4: Select the maximum and minimum values ​​of the clock cycle count percentage in the updated control plane node set to quantify the resource conflict range between SDN controllers. Analyze the conflict overlap of VPN services before activation based on the resource conflict range, and determine whether there is a security isolation requirement between SDN controllers based on the conflict overlap.

[0028] Furthermore, the specific implementation process of step S1 includes:

[0029] The SDN controller coordinates all programming interfaces and all communication links of each programming interface network, and performs unified encoding on the programming interfaces and communication links respectively. The i-th programming interface is denoted as M. i Let the r-th communication link be CL. r ;

[0030] The communication link includes the programming interface that provides VPN service, and is accessed via the communication link CL. r Grouping and capturing each programming interface, and forming a communication link CL r The set of link interfaces, denoted as L(CL) r )={M i |i∈[1,I]}, where I represents the total number of programming interfaces.

[0031] Furthermore, the specific implementation process of step S2 includes:

[0032] Treating an SDN controller as a control plane node, and leveraging the VPN service functions provided by the SDN controller's various programming interfaces, captures each communication link. If the communication is transmitted through the e-th SDN controller... e The internal programming interface accesses the communication link CL r Then for the communication link CL r Capture;

[0033] Based on the capture behavior of the communication link, through the e-th SDN controller SDN e Internal programming interface access to communication link CL r At that time, obtain the SDN controller SDN. e The percentage of clock cycles generated during access to the internal programming interface is denoted as h(SDN). e |CL r The percentage of clock cycles is as follows: in the communication link CL r From the start of access exploitation to the period when access exploitation ceases, the SDN controller SDN... e The internal programming interfaces access the communication link CL r The ratio of the sum of the number of clock cycles generated during the process to the total number of clock cycles, where the total number of clock cycles is the communication link CL. r The total number of clock cycles generated from the start of access to the end of access.

[0034] Furthermore, the specific implementation process of step S3 includes:

[0035] SDN controller SDN e When viewed as a control plane node, collect SDN controller SDN data. e The percentage of clock cycles generated when the internal programming interface accesses each communication link, and the generation of the control plane node set P (SDN) e )={h(SDN e |CL r )|r∈[1,R]}, where R represents the total number of communication links;

[0036] The VPN service time range is pre-divided, and the x-th VPN service time range is used as the clock cycle range generated for each communication link from the start of access to the end of access. Within the clock cycle range, each control plane node set is updated, and the control plane node set P(SDN) is updated. e The updated control plane node set is denoted as P. x (SDN e ).

[0037] Furthermore, the specific implementation process of step S4 includes:

[0038] Quantitative Analysis of SDN Controller Based on Control Plane Node Set e Range of resource conflicts across different clock cycle ranges:

[0039] In the control plane node set P x (SDN e In the formula, the maximum and minimum values ​​of the percentage of clock cycles are selected respectively, and denoted as ma{P}. x (SDN e )} and mi{P x (SDN e Based on the maximum and minimum values, calculate the SDN controller SDN. e The upper limit of the scope of resource conflicts Computational SDN controller SDN e The lower limit of the scope of resource conflicts SDN controller SDN e The range of resource conflicts within the x-th clock cycle is represented as RCR(SDN). e |x)=[mi(e,x),ma(e,x)]; where, This represents the average percentage of clock cycles, and σ represents the standard deviation of the percentage of clock cycles, and E represents the total number of SDN controllers;

[0040] According to the above method, the clock cycle is the most basic and smallest unit of time in a computer. It is a fixed-length time interval defined by the CPU clock to represent the time that the processor takes from one point in time to the next same point in time. Within one clock cycle, the CPU completes a basic action. In the process of the SDN controller implementing VPN service through software protocol, it cannot do without the operation of software programs. The performance and expansion requirements of the VPN service carried by the communication link are essentially consumed by the proportion of clock cycles. In the process of studying the proportion of clock cycles, the Nair criterion is combined. The Nair criterion is used to detect outliers in the data, also known as gross errors. It evaluates whether a certain maximum or minimum value in a set of measurements deviates significantly from other values ​​through an infinite loop. It can be regarded as an outlier and removed. This invention does not need an infinite loop to remove outliers. It only needs to obtain the resource conflict range through the maximum and minimum values. The purpose is to obtain the conflict overlap scale so as to realize the conflict judgment before VPN service is opened between different SDN controller configurations.

[0041] Quantify the scope of resource conflict (RCR) in SDN e |x) and Resource Conflict Scope RCR (SDN) e+1 The conflict and overlap scale between |x) is MD[RCR(SDN) e |x), RCR(SDN) e+1 |x)]=q{ma(e,x),ma(e+1,x)}-Q{mi(e,x),mi(e+1,x)}, where ma(e+1,x) represents the SDN controller. e+1 The upper limit of the resource conflict range, mi(e+1, x) represents the SDN controller SDN. e+1 The lower bound of the resource conflict range, q{} represents the minimum value selection function, and Q{} represents the maximum value selection function;

[0042] Preset scale factor, if conflicting and overlapping scales MD[RCR(SDN) e |x), RCR(SDN) e+1 If |x)] is greater than or equal to the scaling factor, it indicates that the SDN controller SDN is within the range of the x-th clock cycle. e With SDN controller SDN e+1 If security isolation is required, then it is not recommended to use the SDN controller (SDN) during the xth VPN service time segment. e With SDN controller SDN e+1 To deploy and configure VPN services.

[0043] Compared with existing technologies, the beneficial effects achieved by this invention are as follows: The intelligent VPN service automatic activation system and its resource conflict detection method provided by this invention include: a network structure module for identifying SDN controllers and communication links in the network structure; an interface protocol module for defining service requirements using software protocols and capturing parameter characteristics of SDN controller operation; a node layering module for layering and dynamic updating of the control plane based on the time span of VPN service; and a VPN service automatic activation detection optimization module for detecting the resource conflict range of the SDN controller and optimizing the deployment configuration scheme before automatic VPN service activation. This invention can dynamically define the resource detection limits of the SDN controller across nodes for different services before VPN service activation, which is beneficial for secure isolation after VPN service activation. Attached Figure Description

[0044] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.

[0045] Figure 1 This is a schematic diagram illustrating the steps of an intelligent VPN service automatic activation system and its resource conflict detection method according to the present invention. Detailed Implementation

[0046] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0047] In this first embodiment: an intelligent VPN service automatic activation system is provided, which includes: a network structure module, an interface protocol module, a node layering module, and a VPN service automatic activation detection and optimization module;

[0048] The network structure module is used to compile and analyze the various SDN controllers and communication links in the network structure.

[0049] Priority is given to the network structure module, which includes a network structure identification unit and a link information coordination unit:

[0050] The network structure identification unit is used to identify the SDN controller and its internal programming interfaces in the network structure, so as to uniformly encode and file each SDN controller and its programming interface.

[0051] The link information coordination unit is used to separate the various programming interfaces through the communication link to form a link interface set;

[0052] The interface protocol module is used to provide the interaction protocol for the internal programming interface of the SDN controller, and based on the VPN service function, to capture the communication links of the internal programming interface access between the SDN controllers; it is used to collect the percentage of clock cycles generated by the SDN controller as the control plane node when the internal programming interface of the SDN controller accesses the communication link.

[0053] Prior to this, the interface protocol module includes a protocol access unit and a resource feature tag unit:

[0054] The protocol access unit is used to provide the interaction protocol between programming interfaces during VPN service. When a programming interface generates access to the communication link, the accessed programming interface is used to lock the SDN controller and capture the accessed communication link.

[0055] The resource feature tag unit is used to collect clock cycle feature parameters generated by the SDN controller during the period from the start of access to the end of access to the communication link. The clock cycle feature parameters are the sum of the number of clock cycles generated when each programming interface inside the SDN controller executes the code program; it is also used to collect the total number of clock cycles generated by the accessed communication link when the programming interface inside the SDN controller accesses the communication link.

[0056] The node hierarchical module is used to collect the percentage of clock cycles and generate a control plane node set; it is used to hierarchically define the VPN service time range and use the VPN service time range as the clock cycle range generated by each communication link from the start of access to the end of access, and to perform dynamic update operations on the control plane node set.

[0057] Preferably, the node hierarchical module includes control plane node units and hierarchical update units:

[0058] The control plane node unit is used to collect the percentage of clock cycles generated when the programming interface inside the SDN controller accesses each communication link, in order to generate a control plane node set.

[0059] The hierarchical update unit is used to pre-divide VPN service time range segments and hierarchically divide the communication link from the start of access and utilization to the period of no access and utilization based on the VPN service time range segments, so as to meet the update requirements of the control plane node set.

[0060] The VPN service auto-enabling detection and optimization module, based on the updated control plane node set, is used to detect the resource conflict range of the SDN controller and quantify the conflict overlap scale between SDN controllers; based on the conflict overlap scale, it recommends a deployment configuration scheme for VPN service auto-enabling.

[0061] Preferably, the VPN service automatic activation detection and optimization module includes an activation detection unit and a resource conflict optimization unit:

[0062] The detection unit is activated to select the maximum and minimum values ​​of the proportion of clock cycles in the updated control plane node set, so as to quantify the upper and lower limits of the detected resource conflict range, and to calibrate the conflict overlap scale between SDN controllers based on the resource conflict range.

[0063] The resource conflict optimization unit determines whether there is a security isolation requirement between SDN controllers based on the conflict overlap scale. Based on the judgment result, it does not recommend deploying and configuring VPN services on SDN controllers with security isolation requirements within the VPN service service time range.

[0064] Please see Figure 1 In this second embodiment: a method for detecting intelligent VPN service resource conflicts is provided, which includes the following steps:

[0065] Step S1: Identify the SDN controller, the programming interface inside the SDN controller, and the communication links in the network structure;

[0066] For example, all programming interfaces provided by the SDN controller and all communication links of each programming interface network are coordinated, and the programming interfaces and communication links are uniformly encoded. The i-th programming interface is denoted as M. i Let the r-th communication link be CL. r ;

[0067] The communication link includes a programming interface for providing VPN services, which is accessed via the communication link CL. r Grouping and capturing each programming interface, and forming a communication link CL r The set of link interfaces, denoted as L(CL) r )={M i |i∈[1,I]}, where I represents the total number of programming interfaces;

[0068] Step S2: Using the SDN controller as the control plane, lock each SDN controller that generates VPN service behavior and capture the adapted communication links. Collect the percentage of clock cycles based on the capture results of the communication links.

[0069] For example, an SDN controller can be considered as a control plane node. Based on the VPN service functions provided by the various programming interfaces of the SDN controller, each communication link can be captured. If the communication is transmitted through the e-th SDN controller... e The internal programming interface accesses the communication link CL r Then for the communication link CL r Capture;

[0070] Based on the capture behavior of the communication link, through the e-th SDN controller. e Internal programming interface access to communication link CL r At that time, obtain the SDN controller SDN. e The percentage of clock cycles generated during access to the internal programming interface is denoted as h(SDN). e |CL r The percentage of clock cycles in the communication link CL is as follows: r From the start of access exploitation to the period when access exploitation ceases, the SDN controller SDN... e The internal programming interfaces access the communication link CL r The sum of the number of clock cycles generated during the process is the ratio of the total number of clock cycles, where the total number of clock cycles is the communication link CL. r The total number of clock cycles generated from the start of access to the end of access;

[0071] Step S3: Record the percentage of collected clock cycles into the control plane node set, and update the control plane node set hierarchically based on the VPN service time range;

[0072] For example, the SDN controller SDN e When viewed as a control plane node, collect SDN controller SDN data. e The percentage of clock cycles generated when the internal programming interface accesses each communication link, and the generation of the control plane node set P (SDN) e )={h(SDN e |CL r )|r∈[1,R]}, where R represents the total number of communication links;

[0073] Pre-divide VPN service time range segments, and use the x-th VPN service time range segment as the clock cycle range generated for each communication link from the start of access to the end of access. Update each control plane node set within the clock cycle range, and set the control plane node set P(SDN) e The updated control plane node set is denoted as P. x (SDN e );

[0074] Step S4: Select the maximum and minimum values ​​of the clock cycle count ratio in the updated control plane node set to quantify the resource conflict range between SDN controllers. Analyze the conflict overlap of VPN services before activation based on the resource conflict range, and determine whether there is a security isolation requirement between SDN controllers based on the conflict overlap.

[0075] For example, based on the control plane node set, quantitative analysis of SDN controller SDN is performed.e Range of resource conflicts across different clock cycle ranges:

[0076] In the control plane node set P x (SDN e In the formula, the maximum and minimum values ​​of the percentage of clock cycles are selected respectively, and denoted as ma{P}. x (SDN e )} and mi{P x (SDN e Based on the maximum and minimum values, calculate the SDN controller SDN. e The upper limit of the scope of resource conflicts Computational SDN controller SDN e The lower limit of the scope of resource conflicts SDN controller SDN e The range of resource conflicts within the x-th clock cycle is represented as RCR(SDN). e |x)=[mi(e,x),ma(e,x)]; where, This represents the average percentage of clock cycles, and σ represents the standard deviation of the percentage of clock cycles, and E represents the total number of SDN controllers;

[0077] Quantify the scope of resource conflict (RCR) in SDN e |x) and Resource Conflict Scope RCR (SDN) e+1 The conflict and overlap scale between |x) is MD[RCR(SDN) e |x), RCR(SDN) e+1 |x)]=q{ma(e,x),ma(e+1,x)}-Q{mi(e,x),mi(e+1,x)}, where ma(e+1,x) represents the SDN controller. e+1 The upper limit of the resource conflict range, mi(e+1, x) represents the SDN controller SDN. e+1 The lower bound of the resource conflict range, q{} represents the minimum value selection function, and Q{} represents the maximum value selection function;

[0078] Preset scale factor, if conflicting and overlapping scales MD[RCR(SDN) e |x), RCR(SDN) e+1 If |x)] is greater than or equal to the scaling factor, it indicates that the SDN controller SDN is within the range of the x-th clock cycle. e With SDN controller SDN e+1 If security isolation is required, then it is not recommended to use the SDN controller (SDN) during the xth VPN service time segment.e With SDN controller SDN e+1 To deploy and configure VPN services.

[0079] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0080] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A smart VPN service automatic activation system, characterized in that, The system includes: a network structure module, an interface protocol module, a node layering module, and a VPN service automatic activation detection and optimization module; The network structure module is used to compile and statistically analyze each SDN controller and communication link in the network structure. The interface protocol module is used to provide an interaction protocol for the internal programming interface of the SDN controller, and to capture the communication links of the internal programming interface access between the SDN controllers based on the VPN service function; it is also used to collect the percentage of clock cycles generated by the SDN controller as the control plane node when the internal programming interface of the SDN controller accesses the communication link. The node layering module is used to collect the clock cycle ratio and generate a control plane node set; it is also used to layer the VPN service time range and use the VPN service time range as the clock cycle range generated by each communication link from the start of access to the end of access, and to perform dynamic update operation of the control plane node set. The VPN service auto-enabling detection and optimization module, based on the updated control plane node set, is used to detect the resource conflict range of the SDN controller and quantify the conflict overlap scale between SDN controllers; based on the conflict overlap scale, it recommends a deployment configuration scheme for automatic VPN service enabling.

2. The intelligent VPN service automatic activation system according to claim 1, characterized in that, The network structure module includes a network structure identification unit and a link information coordination unit: The network structure identification unit is used to identify the SDN controller and each programming interface inside the SDN controller in the network structure, so as to uniformly encode and file each SDN controller and each programming interface respectively. The link information coordination unit is used to separate each programming interface through the communication link to form a link interface set.

3. The intelligent VPN service automatic activation system according to claim 2, characterized in that, The interface protocol module includes a protocol access unit and a resource feature tag unit: The protocol access unit is used to provide the interaction protocol between programming interfaces during VPN service. When a programming interface generates an access behavior to the communication link, the accessed programming interface is used to lock the SDN controller and capture the accessed communication link. The resource feature tag unit is used to collect clock cycle feature parameters generated by the SDN controller during the period from the start of access to the end of access to the communication link. The clock cycle feature parameters are the sum of the number of clock cycles generated when each programming interface inside the SDN controller executes the code program. Used to collect the total number of clock cycles generated by the accessed communication link when the internal programming interface of the SDN controller accesses the communication link.

4. The intelligent VPN service automatic activation system according to claim 3, characterized in that, The node hierarchical module includes control plane node units and hierarchical update units: The control plane node unit is used to collect the percentage of clock cycles generated when the programming interface inside the SDN controller accesses each communication link, in order to generate a control plane node set. The hierarchical update unit is used to pre-divide VPN service time range segments and use VPN service time range segments to hierarchically divide the clock cycle range generated during the period from the start of access to the end of access to the communication link, so as to meet the update requirements of the control plane node set.

5. The intelligent VPN service automatic activation system according to claim 4, characterized in that, The VPN service automatic activation detection and optimization module includes an activation detection unit and a resource conflict optimization unit: The activation detection unit is used to select the maximum and minimum values ​​of the proportion of clock cycles in the updated control plane node set to quantify the upper and lower limits of the detected resource conflict range, and to calibrate the conflict overlap scale between SDN controllers based on the resource conflict range. The resource conflict optimization unit determines whether there is a security isolation requirement between SDN controllers based on the conflict overlap scale. Based on the determination result, it does not recommend deploying and configuring VPN services on SDN controllers with security isolation requirements within the VPN service service time range.

6. A method for detecting resource conflicts in intelligent VPN services, applied to an intelligent VPN service automatic activation system as described in any one of claims 1-5, characterized in that, The method includes: Step S1: Identify the SDN controller, the programming interface inside the SDN controller, and the communication links in the network structure; Step S2: Using the SDN controller as the control plane, lock each SDN controller that generates VPN service behavior and capture the adapted communication links. Collect the percentage of clock cycles based on the capture results of the communication links. Step S3: Record the percentage of collected clock cycles into the control plane node set, and update the control plane node set hierarchically based on the VPN service time range; Step S4: Select the maximum and minimum values ​​of the clock cycle count percentage in the updated control plane node set to quantify the resource conflict range between SDN controllers. Analyze the conflict overlap of VPN services before activation based on the resource conflict range, and determine whether there is a security isolation requirement between SDN controllers based on the conflict overlap.

7. The intelligent VPN service resource conflict detection method according to claim 6, characterized in that, The specific implementation process of step S1 includes: The SDN controller coordinates all programming interfaces and all communication links of each programming interface network, and performs unified encoding on the programming interfaces and communication links respectively. The i-th programming interface is denoted as M. i Let the r-th communication link be CL. r ; The communication link includes the programming interface that provides VPN service, and is accessed via the communication link CL. r Grouping and capturing each programming interface, and forming a communication link CL r The set of link interfaces, denoted as L(CL) r )={M i |i∈[1,I]}, where I represents the total number of programming interfaces.

8. The intelligent VPN service resource conflict detection method according to claim 7, characterized in that, The specific implementation process of step S2 includes: Treating an SDN controller as a control plane node, and leveraging the VPN service functions provided by the SDN controller's various programming interfaces, captures each communication link. If the communication is transmitted through the e-th SDN controller... e The internal programming interface accesses the communication link CL r Then for the communication link CL r Capture; Based on the capture behavior of the communication link, through the e-th SDN controller SDN e Internal programming interface access to communication link CL r At that time, obtain the SDN controller SDN. e The percentage of clock cycles generated during access to the internal programming interface is denoted as h(SDN). e |CL r The percentage of clock cycles is as follows: in the communication link CL r From the start of access exploitation to the period when access exploitation ceases, the SDN controller SDN... e The internal programming interfaces access the communication link CL r The ratio of the sum of the number of clock cycles generated during the process to the total number of clock cycles, where the total number of clock cycles is the communication link CL. r The total number of clock cycles generated from the start of access to the end of access.

9. The intelligent VPN service resource conflict detection method according to claim 8, characterized in that, The specific implementation process of step S3 includes: SDN controller SDN e When viewed as a control plane node, collect SDN controller SDN data. e The percentage of clock cycles generated when the internal programming interface accesses each communication link, and the generation of the control plane node set P (SDN) e )={h(SDN e |CL r )|r∈[1,R]}, where R represents the total number of communication links; The VPN service time range is pre-divided, and the x-th VPN service time range is used as the clock cycle range generated for each communication link from the start of access to the end of access. Within the clock cycle range, each control plane node set is updated, and the control plane node set P(SDN) is updated. e The updated control plane node set is denoted as P. x (SDN e ).

10. The intelligent VPN service resource conflict detection method according to claim 9, characterized in that, The specific implementation process of step S4 includes: Quantitative Analysis of SDN Controller Based on Control Plane Node Set e Range of resource conflicts across different clock cycle ranges: In the control plane node set P x (SDN e In the formula, the maximum and minimum values ​​of the percentage of clock cycles are selected respectively, and denoted as ma{P}. x (SDN e )} and mi{P x (SDN e Based on the maximum and minimum values, calculate the SDN controller SDN. e The upper limit of the scope of resource conflicts Computational SDN controller SDN e The lower limit of the scope of resource conflicts SDN controller SDN e The range of resource conflicts within the x-th clock cycle is represented as RCR(SDN). e |x)=[mi(e,x),ma(e,x)]; where, This represents the average percentage of clock cycles, and σ represents the standard deviation of the percentage of clock cycles. E represents the total number of SDN controllers; Quantify the scope of resource conflict (RCR) in SDN e |x) and Resource Conflict Scope RCR (SDN) e+1 The conflict and overlap scale between |x) is MD[RCR(SDN) e |x), RCR(SDN) e+1 |x)]=q{ma(e,x),ma(e+1,x)}-Q{mi(e,x),mi(e+1,x)}, where ma(e+1,x) represents the SDN controller. e+1 The upper limit of the resource conflict range, mi(e+1, x) represents the SDN controller SDN. e+1 The lower bound of the resource conflict range, q{} represents the minimum value selection function, and Q{} represents the maximum value selection function; Preset scale factor, if conflicting and overlapping scales MD[RCR(SDN) e |x), RCR(SDN) e+1 If |x)] is greater than or equal to the scaling factor, it indicates that the SDN controller SDN is within the range of the x-th clock cycle. e With SDN controller SDN e+1 If security isolation is required, then it is not recommended to use the SDN controller (SDN) during the xth VPN service time segment. e With SDN controller SDN e+1 To deploy and configure VPN services.

Citation Information

Patent Citations

  • Implementation method of VPN (virtual private network) on basis of SDN (software defined network)

    CN105357099A

  • SDN architecture based extension device accessing method, controller and SDN system

    CN106470111A