Method and apparatus for intelligent management of MCNS topology using an orchestrator
By integrating multiple SASE services into the SD-WAN orchestrator through the SASE Connect orchestrator, and utilizing intelligent routing and real-time detection technologies, the problem of not being able to distinguish business needs in traditional SASE integration solutions is solved, and dynamic optimization of network performance and security is achieved.
Patent Information
- Application Number
- CN202510138296.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2045-02-07
AI Technical Summary
Traditional SASE integration solutions cannot differentiate between the needs of different services, resulting in the inability to provide personalized SASE services within the same network and the inability to dynamically adjust the topology based on network quality and security requirements.
By integrating multiple SASE services into the SD-WAN orchestrator through the SASE Connect orchestrator, and utilizing intelligent routing technology and real-time network quality detection technology, the service traffic allocation strategy and network topology can be dynamically adjusted to achieve fine-grained management and security optimization of different service traffic.
It enables dynamic adjustment of SASE service usage based on network conditions and security requirements, improving network performance, flexibility, and security, and meeting the personalized needs of different services.
Smart Images

Figure CN119945981B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method and apparatus for intelligently managing MCNS topology using an orchestrator. Background Technology
[0002] SASE, or Secure Access Service Edge, is a cloud-native architecture that unifies network and security functions as services into a single cloud-delivered service. It combines SD-WAN with security features to provide automated support for distributed remote and hybrid users, connecting to a nearby cloud gateway instead of backhauling traffic to the corporate data center. This allows organizations to access all applications with consistent security while maintaining full visibility and inspection of traffic across all ports and protocols. As part of a SASE integration solution, SD-WAN typically orchestrates CPE resources and binds them to cloud-native security services, meaning a specific network uses a specific SASE. While this approach is relatively simple to implement, it also introduces several challenges. These primarily stem from the inability to differentiate between different services within the same network. Different services may require different SASE services, different times may require different SASE services, different network qualities may necessitate different SASE services, and specific scenarios may require changes to the topology between SASE services—problems that traditional SASE integration solutions cannot address. Summary of the Invention
[0003] In view of this, this application proposes a method for intelligently managing the topology of MCNS using an orchestrator, in order to solve the problems reflected in the background technology.
[0004] According to one aspect of this application, a method for intelligently managing the topology of an MCNS using an orchestrator is provided, comprising the following steps:
[0005] Multiple SASE services can be integrated into an SD-WAN orchestrator to obtain a single SASE Connect orchestrator.
[0006] Service traffic in the customer-side CPE reaches the network-side aggregation CPE via SD-WAN;
[0007] The network-side aggregation CPE uses the SASE Connect orchestrator to distribute different service traffic to different SASEs;
[0008] When network congestion or SASE quality degrades, the SASE Connect orchestrator automatically modifies the allocation strategy;
[0009] When highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the network topology.
[0010] As an optional implementation of this application, the SASE Connect orchestrator may optionally support the concatenation of multiple SASE services in its SASE integration scheme.
[0011] As an optional implementation of this application, optionally, the network-side aggregation CPE distributes different service traffic to different SASEs through the SASE Connect orchestrator, including:
[0012] The SASE Connect orchestrator uses DPI technology in intelligent routing to distribute service traffic.
[0013] The DPI technology identifies and extracts key information in network transmission, diverting different service traffic to different SASEs.
[0014] As an optional implementation of this application, optionally, when network congestion or SASE quality degrades, the SASE Connect orchestrator automatically modifies the allocation strategy, including:
[0015] The SASE Connect orchestrator detects network quality based on real-time network quality detection technology in intelligent routing technology;
[0016] When high traffic volume leads to network congestion and a decline in SASE quality, the real-time network quality detection technology automatically adjusts the traffic allocation strategy based on the real-time situation.
[0017] As an optional implementation of this application, optionally, when highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the network topology, including:
[0018] When highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the current network topology based on DPI and real-time network quality detection technology in intelligent routing technology;
[0019] When the sensitive traffic service ends, the SASE Connect orchestrator automatically modifies the network topology back to the original topology.
[0020] As an optional implementation of this application, the SASE Connect orchestrator's integration scheme for SASE may include the SASE Connect orchestrator not only integrating multiple SASE services, but also managing multiple sets of SASE services from different brands.
[0021] As an optional implementation of this application, the SASE Connect orchestrator is characterized in that it detects network quality based on real-time network quality detection technology in intelligent routing technology, including:
[0022] The real-time network quality detection technology allocates corresponding SASE services to service traffic based on different times and different network qualities.
[0023] According to two aspects of this application, an apparatus for intelligently managing MCNS topology using an orchestrator is provided, comprising the following modules:
[0024] The SASE module is integrated to combine multiple SASE services into an SD-WAN orchestrator, resulting in a SASEConnect orchestrator;
[0025] The service traffic aggregation module is used to aggregate the service traffic of the customer-side CPE to the network-side aggregation CPE;
[0026] The business traffic routing module is used by the SASE Connect orchestrator to route different business traffic to different SASE services;
[0027] The adjustment module is used by the SASE Connect orchestrator to adjust the allocation strategy and network topology according to different situations.
[0028] As an alternative implementation of this application, the module may be adjusted to include:
[0029] The adjustment strategy module is used by the SASE Connect orchestrator to adjust the allocation strategy in real time according to different situations;
[0030] The topology adjustment module allows the SASE Connect orchestrator to adjust the network topology in real time according to different situations.
[0031] According to three aspects of this application, an electronic device is proposed, comprising:
[0032] processor;
[0033] Memory used to store processor-executable instructions;
[0034] The processor is configured to implement, when executing the executable instructions, any one of the methods described above for intelligent management of MCNS topology using an orchestrator.
[0035] The beneficial effects of this application are:
[0036] This invention upgrades the SASE integration solution from SASE integrating SD-WAN to SD-WAN integrating SASE by incorporating multiple SASE services into an SD-WAN orchestrator. Through the SASE Connect orchestrator, the integration solution can fully utilize SASE resources. When traffic is high, some traffic destined for high-cost SASEs can be temporarily diverted to low-cost SASEs according to a predetermined strategy. When security priority is highest, all SASEs can be temporarily connected in series according to a predetermined strategy, and all traffic will flow through all SASEs for cleaning. Attached Figure Description
[0037] The accompanying drawings, which are included in and form part of this specification, illustrate exemplary embodiments, features, and aspects of this application together with the specification and serve to explain the principles of this application.
[0038] Figure 1 A flowchart illustrating a method for intelligently managing MCNS topology using an arranger, according to an embodiment of this application, is shown.
[0039] Figure 2 This invention illustrates a block diagram of an apparatus for intelligently managing the MCNS topology using an arranger, according to an embodiment of this application.
[0040] Figure 3 This illustration shows a scenario one of the methods for intelligently managing the MCNS topology using an orchestrator, according to an embodiment of this application.
[0041] Figure 4 This diagram illustrates scenario two of the method for intelligently managing the MCNS topology using an orchestrator, as described in an embodiment of this application.
[0042] Figure 5 Flowcharts illustrating scenarios one and two of the method for intelligently managing MCNS topology using an orchestrator, according to embodiments of this application, are shown.
[0043] Figure 6 This diagram illustrates scenario three of the method for intelligently managing the MCNS topology using an orchestrator, as described in an embodiment of this application.
[0044] Figure 7 This document illustrates a flowchart of scenario three in the method for intelligently managing the MCNS topology using an orchestrator, as described in an embodiment of this application. Detailed Implementation
[0045] Various exemplary embodiments, features, and aspects of this application will now be described in detail with reference to the accompanying drawings. The same reference numerals in the drawings denote elements that have the same or similar functions. Although various aspects of the embodiments are shown in the drawings, they are not necessarily drawn to scale unless specifically indicated otherwise.
[0046] It should be understood that the terms "center," "longitudinal," "lateral," "length," "width," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," "counterclockwise," "axial," "radial," and "circumferential" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this application or to simplify the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application.
[0047] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0048] The term “exemplary” as used herein means “serving as an example, embodiment, or illustration.” Any embodiment illustrated herein as “exemplary” is not necessarily to be construed as superior to or better than other embodiments.
[0049] Furthermore, to better illustrate this application, numerous specific details are provided in the following detailed embodiments. Those skilled in the art should understand that this application can be implemented without certain specific details. In some instances, methods, means, components, and circuits well-known to those skilled in the art have not been described in detail in order to highlight the main points of this application.
[0050] Example 1
[0051] Figure 1 A flowchart illustrating a method for intelligently managing an MCNS topology using an orchestrator according to Embodiment 1 of this application is shown. The MCNS (Multi-Cloud Native Security) is a multi-cloud native security service, such as... Figure 1 As shown, the flowchart includes:
[0052] S100 integrates multiple SASE services into an SD-WAN orchestrator to obtain a single SASE Connect orchestrator.
[0053] SASE is a cloud-native architecture that unifies network and security functions as services into a single cloud delivery service. The SD-WAN orchestrator, or SD-WAN Orchestrator, is one of the core components of the SD-WAN architecture, capable of coordinating all CPEs, all SASEs, and all network devices. By incorporating the multiple SASE services into the SD-WAN orchestrator, the SD-WAN orchestrator is upgraded to obtain a SASE Connect orchestrator.
[0054] S200: Service traffic in the customer-side CPE reaches the network-side aggregation CPE via SD-WAN.
[0055] The customer-side CPE is a CPE placed in the customer's office location, used to direct business traffic to the network-side aggregation CPE. The network-side aggregation CPE is a CPE deployed on the cloud platform, used to aggregate business traffic from multiple customer-side CPEs before transmitting it to the next-hop network.
[0056] The S300 and the network-side aggregation CPE use the SASE Connect orchestrator to distribute different service traffic to different SASEs.
[0057] After the network-side aggregation CPE completes the aggregation of service traffic, it will use intelligent routing technology to identify the service traffic and perform network quality checks on different SASEs. Finally, after network quality determination through intelligent routing technology, it will continue to distribute service traffic, diverting different service traffic to different SASEs.
[0058] S400. When network congestion occurs or SASE quality degrades, the SASE Connect orchestrator automatically modifies the allocation strategy.
[0059] When the overall network load is high, and new business traffic is still arriving, which may cause network congestion and degrade the quality of SASE services, the SASE Connect orchestrator will identify this problem based on network quality and automatically modify the strategy, such as temporarily abandoning some low-security-level services to bypass SASE, and adjusting some services with relatively low security levels to low-intensity SASE, etc.
[0060] S500: When highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the network topology.
[0061] When highly sensitive traffic requiring extreme security occurs at a low network load, the SASE Connect orchestrator can temporarily change the network topology according to a predetermined strategy, i.e., connect all SASEs in series. In this case, all service traffic will be cleaned by passing through all SASEs. After the highly sensitive traffic service ends, the SASE Connect orchestrator will switch the network topology back to the original topology and scenario.
[0062] As an optional implementation of this application, in step S100, the SASE Connect orchestrator's SASE integration scheme supports the concatenation of multiple SASE services.
[0063] In this implementation scheme, the concatenation of multiple SASE services enables unified management and monitoring, facilitating centralized control and management of the enterprise's network. Different SASE services may employ different optimization strategies and technologies; by concatenating these services, intelligent routing and optimization of business traffic can be achieved, improving network performance and response speed. Concatenating multiple SASE services allows for multi-layered and multi-faceted security checks and processing of business traffic, significantly enhancing network security. The SASE Connect orchestrator can dynamically select the optimal path to transmit business traffic, thus enabling the concatenation of multiple SASE services. This approach allows for dynamic routing adjustments based on network conditions and service quality, improving network flexibility and reliability.
[0064] As an optional implementation of this application, in step S300, the network-side aggregation CPE diverts different service traffic to different SASEs through the SASE Connect orchestrator, including: the SASE Connect orchestrator diverts service traffic based on DPI technology in intelligent routing technology; the DPI technology diverts different service traffic to different SASEs by identifying and extracting key information in network transmission.
[0065] In this embodiment, after service traffic arrives at the network-side aggregation CPE, the SASE Connect orchestrator distributes the service traffic based on DPI (Deep Packet Inspection) technology within intelligent routing. DPI technology can deeply analyze the content of data packets, thereby achieving fine-grained classification and identification of network traffic. This classification and identification provides an accurate basis for traffic routing. Through DPI technology, the SASE Connect orchestrator can identify different types of network traffic, such as video streams, data streams, and voice streams, and select the optimal transmission path for them based on the characteristics and requirements of these traffic streams, achieving intelligent traffic allocation and optimization. Figure 3 In Scenario 1, multiple customer-side CPEs reach the "network-side aggregation CPE" via SD-WAN. Through "intelligent routing technology", traffic of services with low security levels (such as APP services provided by large companies such as Douyin that are not related to work) are diverted to low-intensity SASE (low cost), while traffic of services with high security levels is identified and diverted to high-intensity SASE (high cost).
[0066] As an optional implementation of this application, in step S400, when network congestion or SASE quality deteriorates, the SASE Connect orchestrator automatically modifies the allocation strategy, including: the SASE Connect orchestrator detects network quality based on real-time network quality detection technology in intelligent routing technology; when large service traffic leads to network congestion and SASE quality deterioration, the real-time network quality detection technology automatically adjusts the service traffic allocation strategy according to the real-time situation.
[0067] In this embodiment, when service traffic is high and network congestion occurs, the SASE Connect orchestrator uses real-time network quality detection technology based on intelligent routing to identify the network congestion and take appropriate action. Using this real-time network quality detection technology to distribute service traffic enables dynamic, efficient, and reliable network traffic management. Figure 4 In scenario two, building upon scenario one, a sudden increase in video conferencing traffic, with higher security requirements, should be identified by "intelligent routing technology" and allocated to a high-intensity SASE. However, the high-intensity SASE may be overwhelmed by the sudden increase in traffic. In this case, SASE Connect can identify this situation based on network quality and automatically modify its policy, temporarily allocating email traffic to a low-intensity SASE. Similarly, if the low-intensity SASE is also under heavy load, SASE Connect can also identify this based on network quality and temporarily bypass any SASE for TikTok traffic, reserving SASE resources for email traffic (this scenario will not be illustrated further).
[0068] As an optional implementation of this application, optionally, in step S500, when highly sensitive traffic with extremely high security occurs, the SASE Connect orchestrator automatically modifies the network topology, including: when highly sensitive traffic with extremely high security occurs, the SASE Connect orchestrator can automatically modify the current network topology based on DPI and real-time network quality detection technology in intelligent routing technology; when the service of the sensitive traffic ends, the SASE Connect orchestrator automatically modifies the network topology back to the original topology structure.
[0069] The processes for Scenario 1 and Scenario 2 are as follows: Figure 5 As shown, firstly, the customer-side CPE distributes traffic to the network-side aggregation CPE, then identifies the traffic, performs traffic splitting based on security level, and conducts network quality checks on low-intensity SASEs and high-intensity SASEs. Next, based on the check data, the network quality is determined, and traffic for high-security-level services is sent to high-intensity SASEs. At the same time, network quality checks are performed again on low-intensity SASEs and high-intensity SASEs. Finally, based on the check data, the network quality is determined again, and traffic for low-security-level services is sent to low-intensity SASEs.
[0070] In this embodiment, when high-security traffic occurs, the SASE Connect orchestrator can combine DPI (Distributed Traffic Indicator) and real-time network quality detection technology in intelligent routing to connect multiple SASE services, achieving multi-layered security protection for the traffic. After the high-security traffic process concludes, the SASE Connect orchestrator switches back to the original topology based on DPI and real-time network quality detection technology, fulfilling the requirement of diverting traffic of different security levels to different SASEs. Figure 6 In scenario three, during a period of low network load, a highly sensitive traffic instance with extremely high security requirements emerges. Considering that other traffic is absent, SASE Connect modifies the network topology by connecting two SASEs (low-intensity and high-intensity) in series. The sensitive traffic passes through two SASEs sequentially to meet security requirements. After the service is completed, the network switches back to the original topology and scenario.
[0071] As an optional implementation of this application, the SASE Connect orchestrator's integration scheme for SASE includes the ability of the SASE Connect orchestrator to not only integrate multiple SASE services, but also to manage multiple sets of SASE services from different brands.
[0072] In this implementation scheme, the SASE Connect orchestrator integration solution supports flexible configuration of multiple SASE services of the same brand according to actual needs, and also supports management of multiple SASE services of different brands, so as to fully enjoy the advantages brought by different brands of SASE.
[0073] As an optional implementation of this application, the SASE Connect orchestrator is characterized in that it detects network quality based on real-time network quality detection technology in intelligent routing technology, including: the real-time network quality detection technology can allocate appropriate SASE services to service traffic according to different times and different network qualities.
[0074] In this implementation scheme, the real-time network quality detection technology continuously monitors and analyzes the quality of network links, including key indicators such as packet loss rate, latency, and jitter, to evaluate the real-time performance status of each link and dynamically adjust the service traffic allocation strategy based on this data. Specifically, the real-time network quality detection technology utilizes probing mechanisms, such as firewalls periodically sending probe packets to destination IPs, to collect link quality data. Based on this data, it allocates appropriate SASE services to service traffic at different times and with different network quality conditions.
[0075] The process of Scenario 3 is as follows Figure 7 As shown, the customer-side CPE first sends traffic to the network-side aggregation CPE, then identifies the traffic and triggers a topology change request, and requests a topology change from the orchestrator. The orchestrator then performs topology changes on the low-intensity SASE and the high-intensity SASE in sequence. After the change is completed, the orchestrator sends a change completion message to the network-side aggregation CPE. Finally, the network-side aggregation CPE sends traffic to the low-intensity SASE, and then the low-intensity SASE sends traffic to the high-intensity SASE.
[0076] Example 2
[0077] Based on the same principle as the aforementioned method, a device for intelligently managing the MCNS topology using an orchestrator is also proposed, see [link to relevant documentation]. Figure 2 An apparatus 100 according to an embodiment of this disclosure includes:
[0078] The SASE module 110 is integrated to combine multiple SASE services into an SD-WAN orchestrator, resulting in a SASEConnect orchestrator.
[0079] The service traffic aggregation module 120 is used to aggregate the service traffic of the customer-side CPE to the network-side aggregation CPE.
[0080] The business traffic splitting module 130 is used by the SASE Connect orchestrator to split different business traffic to different SASE services.
[0081] The adjustment module 140 is used by the SASE Connect orchestrator to adjust the allocation strategy and network topology according to different situations.
[0082] As an alternative implementation of this application, the module may be adjusted to include:
[0083] The adjustment strategy module is used by the SASE Connect orchestrator to adjust the allocation strategy in real time according to different situations;
[0084] The topology adjustment module allows the SASE Connect orchestrator to adjust the network topology in real time according to different situations.
[0085] Obviously, those skilled in the art should understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the control methods described above. The modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device, or fabricating them separately as individual integrated circuit modules, or fabricating multiple modules or steps into a single integrated circuit module. Thus, the present invention is not limited to any specific hardware and software combination.
[0086] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the control methods described above. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), etc.; the storage medium can also include combinations of the above types of memory.
[0087] Example 3
[0088] Furthermore, an electronic device is proposed, comprising:
[0089] processor;
[0090] Memory used to store processor-executable instructions;
[0091] The processor is configured to implement the method for intelligent management of MCNS topology using an orchestrator as described in Embodiment 1 when executing the executable instructions.
[0092] The electronic device of this disclosure includes a processor and a memory for storing processor-executable instructions. The processor is configured to implement, when executing the executable instructions, any of the methods described above for intelligently managing the MCNS topology using an orchestrator.
[0093] It should be noted that the number of processors can be one or more. Furthermore, the electronic device in this embodiment may also include input devices and output devices. The processor, memory, input devices, and output devices can be connected via a bus or other means, without specific limitations herein.
[0094] The memory, as a computer-readable storage medium for the method of intelligently managing the MCNS topology using an orchestrator, can be used to store software programs, computer-executable programs, and various modules, such as the program or module corresponding to the method of intelligently managing the MCNS topology using an orchestrator according to embodiments of this disclosure. The processor executes various functional applications and data processing of the electronic device by running the software program or module stored in the memory.
[0095] Input devices can be used to receive input digital numbers or signals. These signals can be key signals related to user settings and function control of the device / terminal / server. Output devices can include display devices such as screens.
[0096] The various embodiments of this application have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is chosen to best explain the principles, practical application, or improvement of the technology in the market, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A method for intelligently managing the topology of an MCNS using an orchestrator, characterized in that... The method for transforming from SASE integration with SD-WAN to SD-WAN integration with SASE includes the following steps: Multiple SASE services can be integrated into an SD-WAN orchestrator to obtain a single SASE Connect orchestrator. Service traffic in the customer-side CPE reaches the network-side aggregation CPE via SD-WAN; The network-side aggregation CPE uses the SASE Connect orchestrator to distribute different service traffic to different SASEs, including: The SASE Connect orchestrator uses DPI technology in intelligent routing to distribute service traffic. The DPI technology identifies and extracts key information in network transmission, diverting different service traffic to different SASEs. When network congestion or SASE quality degrades, the SASE Connect orchestrator automatically modifies the allocation strategy, including: The SASE Connect orchestrator uses real-time network quality detection technology in intelligent routing technology to detect network quality. When high traffic volume leads to network congestion and a decrease in SASE quality, the real-time network quality detection technology automatically adjusts the traffic allocation strategy according to the real-time situation. When highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the network topology by connecting all SASEs in series. At this time, all service traffic will be cleaned by passing through all SASEs. When the sensitive traffic service ends, the SASE Connect orchestrator automatically modifies the network topology back to the original topology.
2. The method for intelligently managing MCNS topology using an orchestrator as described in claim 1, characterized in that, The SASE Connect orchestrator's SASE integration solution supports the concatenation of multiple SASE services.
3. The method for intelligently managing MCNS topology using an orchestrator as described in claim 1, characterized in that, When highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the network topology, including: When highly sensitive traffic with extremely high security requirements occurs, the SASE Connect orchestrator automatically modifies the current network topology based on DPI and real-time network quality detection technology in intelligent routing technology.
4. The method for intelligently managing MCNS topology using an orchestrator as described in claim 2, characterized in that, The SASE Connect orchestrator's SASE integration solution includes the ability of the SASE Connect orchestrator to not only integrate multiple SASE services, but also manage multiple SASE services from different brands.
5. The method for intelligently managing MCNS topology using an orchestrator as described in claim 1, characterized in that, The SASE Connect orchestrator detects network quality based on real-time network quality detection technology in intelligent routing technology, including: The real-time network quality detection technology allocates corresponding SASE services to service traffic based on different times and different network qualities.
6. An apparatus for implementing the method of intelligently managing MCNS topology using an arranger as described in claim 1, comprising: The SASE module is integrated to combine multiple SASE services into an SD-WAN orchestrator, resulting in a SASE Connect orchestrator. The service traffic aggregation module is used to aggregate the service traffic of the customer-side CPE to the network-side aggregation CPE; The business traffic routing module is used by the SASE Connect orchestrator to route different business traffic to different SASE services; The adjustment module is used by the SASE Connect orchestrator to adjust the allocation strategy and network topology according to different situations; The adjustment strategy module is used by the SASE Connect orchestrator to adjust the allocation strategy in real time according to different situations; The topology adjustment module allows the SASE Connect orchestrator to adjust the network topology in real time according to different situations.
7. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to implement, when executing the executable instructions, a method for intelligently managing MCNS topology using an orchestrator, as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Data authority control method and system for big data
CN114978627A
Dynamic traffic scheduling method and system based on SD-WAN technology
CN119232666A