Method and device for separating broadband access network service from user
By preconfiguring the connection between user-side equipment and information technology management platform in the broadband access network and based on SRv6 SID separation service, the problem that the broadband access network cannot adapt to the diversified service bearer and the rapid activation of new services through the QINQ separation service, and achieve more flexible and efficient service separation and bearer.
Patent Information
- Application Number
- CN202510215411.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-30
AI Technical Summary
With the large-scale commercialization of new metropolitan area networks, the broadband access network can no longer adapt to the needs of diversified service bearers and rapid opening of new services through QINQ.
By responding to the user-side device online instruction, the user-side device is preconfigured to establish a connection between the user-side device and the information technology management platform, which is configured with corresponding business codes. Based on the PD prefix and the business coding of the information technology management platform, the business identification of the information technology management platform is built, and the communication tunnel is determined based on this, and the service address corresponding to the information technology management platform is assigned to the user equipment.
Through the SRv6 SID (service SID) service separation service with different functions, the communication tunnel between client equipment and service anchor points is opened, and the problems of inflexible business adjustments and limited business anchor points coverage areas in the original QINQ solution are overcome, and the needs of diversified business bearers and rapid opening of new services are met.
Smart Images

Figure CN120075193A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular, to a method and apparatus for separating broadband access network services from users. Background Art
[0002] An operator's broadband metropolitan area network consists of a metropolitan area backbone network and a broadband access network. The broadband access network provides a layer-2 network channel from the user-side CPE to the service control point or service anchor point of the metropolitan area backbone network. Currently, the operator's broadband access network mainly uses the PON optical network single-fiber access method, supplemented by the LAN dual-fiber access method. The broadband access network is a multi-service bearing network that simultaneously bears multiple services such as dial-up Internet access, networking dedicated lines, Internet dedicated lines, IPTV, VoIP, and ITMS. Since the service control point or service anchor point needs to apply different control and forwarding policies for different services or users, it is necessary to separate services from users in the broadband access network. The broadband access network is a layer-2 Ethernet network, and the industry uses VLAN for service separation and user identification.
[0003] With the advent of the 5G and cloud eras, various services for thousands of industries have put forward differentiated guarantee requirements for the bearing network in terms of bandwidth, latency, jitter, security and reliability. The bearing network needs to adapt to the requirements of the transformation from the consumer Internet to the industrial Internet. At the metropolitan area network level, the traditional metropolitan area network is gradually evolving into a new type of metropolitan area network, aiming at cloud-network integration, to build a new type of metropolitan area information infrastructure of "the network moves with the cloud and the cloud and the network are integrated".
[0004] With the large-scale commercial use of the new type of metropolitan area network, the method of separating services from users in the broadband access network through QinQ can no longer meet the requirements of diversified service bearing and rapid opening of new services.
[0005] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0006] Embodiments of the present disclosure provide a method and apparatus for separating broadband access network services from users, so as to at least solve the technical problem that with the large-scale commercial use of the new type of metropolitan area network, the method of separating services from users in the broadband access network through QinQ can no longer meet the requirements of diversified service bearing and rapid opening of new services in the related art.
[0007] According to one aspect of the embodiments of the present disclosure, a method for separating broadband access network services from users is provided, including: in response to a user device online instruction, pre-configuring the user device, where the pre-configuration is used to establish a connection between the user device and an information technology management platform, and the information technology management platform is configured with a corresponding service code; constructing a service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform; determining a communication tunnel according to the service identifier of the information technology management platform and the service anchor identifier corresponding to the information technology management platform; and based on the communication tunnel, allocating a service address corresponding to the information technology management platform for the user device.
[0008] Optionally, in response to a user device online instruction, pre-configuring the user device includes: configuring a service code for the information technology management platform in the user device, where the service code corresponds to a service anchor identifier and a logical service gateway.
[0009] Optionally, constructing a service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform includes: obtaining a randomly generated field; and combining the PD prefix, the service code of the information technology management platform, and the randomly generated field to obtain the service identifier of the information technology management platform.
[0010] Optionally, based on the communication tunnel, allocating a service address corresponding to the information technology management platform for the user device includes: sending a Dynamic Host Configuration Protocol (DHCP) request message using the logical service gateway, where the request message is encapsulated into the communication tunnel for transmission; and the service anchor corresponding to the information technology management platform de-encapsulates the request message in the communication tunnel and allocates a service address corresponding to the information technology management platform for the user device.
[0011] Optionally, the method further includes: in response to a service activation instruction of the user device, using the information technology management platform to send the service anchor identifier, service code, and service gateway configuration corresponding to the service to be activated to the user device, where the service to be activated is included in the service activation instruction; constructing a service identifier of the service to be activated according to the service code of the service to be activated; and based on the service identifier, using the information technology management platform to send the port, service gateway, and communication tunnel binding relationship to the user device.
[0012] Optionally, the method further includes: sending a service request message through the service gateway; encapsulating the service request message into the communication tunnel and sending the encapsulated request message through the communication tunnel; determining a response message using the service anchor according to the encapsulated request message and sending the encapsulated response message through the communication tunnel; and completing gateway authentication using the user device according to the encapsulated response message.
[0013] Optionally, the services to be activated include one or more of the following: dial-up Internet access service, virtual reality game service.
[0014] According to one embodiment of the present disclosure, there is also provided a device for separating broadband access network services from users, including: a configuration module, configured to perform pre-configuration on a client device in response to a client device online instruction, where the pre-configuration is used to establish a connection between the client device and an information technology management platform, and the information technology management platform is configured with a corresponding service code; a construction module, configured to construct a service identifier of the information technology management platform according to a PD prefix and the service code of the information technology management platform; a determination module, configured to determine a communication tunnel according to the service identifier of the information technology management platform and the service anchor identifier corresponding to the information technology management platform; an allocation module, configured to allocate a service address corresponding to the information technology management platform for the client device based on the communication tunnel.
[0015] Optionally, the configuration module is further configured to: configure a service code for the information technology management platform in the client device, where the service code corresponds to a service anchor identifier and a logical service gateway.
[0016] Optionally, the construction module is further configured to: obtain a randomly generated field; combine the PD prefix, the service code of the information technology management platform, and the randomly generated field to obtain the service identifier of the information technology management platform.
[0017] Optionally, the allocation module is further configured to: send a Dynamic Host Configuration Protocol (DHCP) request message by using the logical service gateway, where the request message is encapsulated into the communication tunnel for transmission; the service anchor corresponding to the information technology management platform de-encapsulates the request message in the communication tunnel to allocate a service address corresponding to the information technology management platform for the client device.
[0018] Optionally, the allocation module is further configured to: in response to a service activation instruction of the client device, use the information technology management platform to issue a service anchor identifier, a service code, and a service gateway configuration corresponding to the service to be activated for the client device, where the service to be activated is included in the service activation instruction; construct a service identifier of the service to be activated according to the service code of the service to be activated; based on the service identifier, use the information technology management platform to issue a port, service gateway, and communication tunnel binding relationship to the client device.
[0019] Optionally, the allocation module is further configured to: send a service request message through the service gateway; encapsulate the service request message into the communication tunnel and send the encapsulated request message through the communication tunnel; determine a response message according to the encapsulated request message by using the service anchor and send the encapsulated response message through the communication tunnel; complete gateway authentication by using the client device according to the encapsulated response message.
[0020] Optionally, the services to be activated in the allocation module include one or more of the following: dial-up Internet access service and virtual reality game service.
[0021] According to one embodiment of the present disclosure, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein when the program is running, the method for separating broadband access network services and users in the embodiment of the present disclosure is executed.
[0022] According to one embodiment of the present disclosure, a computer-readable storage medium is also provided, which includes a stored executable program, wherein when the executable program runs, the device where the storage medium is located is controlled to execute the method of separating broadband access network services and users in the embodiment of the present disclosure.
[0023] According to one embodiment of the present disclosure, a computer program product is also provided, including a computer program, and when the computer program is executed by a processor, the method for separating broadband access network services and users in the embodiment of the present disclosure is implemented.
[0024] In the disclosed embodiment, in response to the user-end device online instruction, the user-end device is preconfigured, wherein the preconfiguration is used to establish a connection between the user-end device and the information technology management platform, and the information technology management platform is configured with a corresponding service code; the service identifier of the information technology management platform is constructed according to the PD prefix and the service code of the information technology management platform; the communication tunnel is determined according to the service identifier of the information technology management platform and the service anchor identifier corresponding to the information technology management platform; based on the communication tunnel, the service address corresponding to the information technology management platform is allocated to the user-end device. The access requirements of different services are separated by SRv6 SID (service SID) with different functions, and the communication tunnel from the client device to the service anchor point is opened, and the service message is encapsulated in the communication tunnel, which can overcome the problems of inflexible service adjustment and limited service anchor point coverage area in the original QINQ solution, and thus solve the technical problem in the related technology that with the large-scale commercial use of new metropolitan area networks, the method of broadband access networks using QINQ to separate services and users can no longer adapt to the needs of diversified service carrying and rapid opening of new services. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The illustrative embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation on the present disclosure. In the drawings:
[0026] Figure 1 is a flow chart of a method for separating broadband access network services and users according to one embodiment of the present disclosure;
[0027] Figure 2It is a schematic diagram of the broadband access network networking in the prior art;
[0028] Figure 3 It is a schematic diagram of the extension of the second-layer domain to the metropolitan area backbone network in the prior art;
[0029] Figure 4 It is a schematic diagram of the architecture of a method for separating broadband access network services and users according to one embodiment of the present disclosure;
[0030] Figure 5 It is a schematic diagram of the service identifier generation rule according to one embodiment of the present disclosure;
[0031] Figure 6 It is a schematic diagram of the service message encapsulation format according to one embodiment of the present disclosure;
[0032] Figure 7 It is a schematic diagram of the network topology structure according to one embodiment of the present disclosure;
[0033] Figure 8 It is a schematic diagram of the client device online process according to one embodiment of the present disclosure;
[0034] Figure 9 It is a structural block diagram of a device for separating broadband access network services and users according to one embodiment of the present disclosure. Detailed implementation manners
[0035] In order to enable those skilled in the art to better understand the solution of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure.
[0036] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0037] To facilitate the understanding of the present invention, the background art is described below: The operator's broadband metropolitan area network consists of two parts: the metropolitan backbone network and the broadband access network. The broadband access network provides a layer-2 network channel from the user-side CPE to the service control point or service anchor point of the metropolitan backbone network. Currently, the operator's broadband access network mainly adopts the PON optical network single-fiber access method, supplemented by the LAN dual-fiber access method. The broadband access network is a multi-service bearer network that simultaneously bears multiple services such as dial-up Internet access, networking dedicated lines, Internet dedicated lines, IPTV, VoIP, and ITMS. Since the service control point or service anchor point needs to apply different control and forwarding policies for different services or users respectively, it is necessary for the broadband access network to separate services and users. The broadband access network is a layer-2 Ethernet network, and the industry uses VLAN for service separation and user identification. According to the refined management and control requirements of different services, the operator's VLAN division schemes mainly include the following two types:
[0038] One is PSPV, that is, one VLAN ID per service. Different users share the service VLAN to achieve separation between services.
[0039] The other is PUPSPV, that is, one VLAN ID per user per service, which simultaneously realizes separation between services and identification of different users.
[0040] To adapt to the number of services and users, reduce the layer-2 broadcast domain, and achieve service and user isolation, the broadband access network adopts the QINQ technology to expand the number space of VLAN tags. QINQ is also known as 802.1ad. By adding a VLAN tag before the standard 802.1Q VLAN tag, the number of VLANs is increased to 4K * 4K. The network diagram is as Figure 2 shown.
[0041] The broadband access network devices include aggregation switches and OLTs. The aggregation switches are used to aggregate multiple OLTs and access the metropolitan backbone network, and the OLTs are used to access home / enterprise gateways (CPEs). According to the different requirements of the services carried, and at the same time to reduce the layer-2 broadcast domain, the broadband access network adopts a combination of the two VLAN division schemes of PSPV and PUPSPV to plan the VLAN segments of various services to separate services and users, and pre-configure the inner and outer layer VLAN segments of QINQ in the aggregation switches and OLTs respectively. In the traditional metropolitan area network, the service control point and service anchor point are both MSEs, directly connected to the broadband access network. The coverage area of a single MSE node usually does not exceed 50,000 users, and the types of services and the number of users to be separated are limited. The inner and outer layer VLAN configurations of QINQ can meet the management and control requirements of services and users. The main service types include dial-up Internet access, dedicated lines, IPTV, VoIP, ITMS, etc. The following is an example of VLAN planning in the aggregation switch scenario of the broadband access network (Table 1):
[0042] Table 1
[0043]
[0044] With the advent of the 5G and cloud eras, various services across all industries have put forward differentiated guarantee requirements for the bearer network in terms of bandwidth, latency, jitter, security and reliability, etc. The bearer network needs to adapt to the requirements of the transformation from the consumer Internet to the industrial Internet. At the metropolitan area network level, the traditional metropolitan area network is gradually evolving into a new type of metropolitan area network, aiming at cloud-network integration, to build a new type of metropolitan area information infrastructure of "networks moving with the cloud and cloud-network integration".
[0045] Compared with the traditional metropolitan area network, the optimization of the new type of metropolitan area network is reflected in the metropolitan area backbone network, including the following characteristics:
[0046] 1. The metropolitan area Spine-Leaf architecture built on the basis of SRv6 realizes the horizontal elastic expansion of the network and the local rapid diversion of east-west traffic.
[0047] 2. The BRAS pooling under the separation architecture of control and forwarding, including the cloudified control plane (CP) and the pooled forwarding plane (UP). The functions of the traditional integrated control and forwarding MSE in the metropolitan area network are decomposed into a control plane and a forwarding plane. The control plane (i.e., the service control point) is centrally deployed, and the forwarding plane (i.e., the service anchor point) is pooled and deployed, providing the capabilities of rapid new function online and automated configuration management while improving resource utilization. The forwarding plane is deployed according to different service requirements, and the access network location is flexible and changeable, meeting the rapid access of edge clouds brought by the sinking of computing power, and realizing the network's initiative, rapidity, and flexibility to adapt to Internet applications.
[0048] With the large-scale commercial use of the new type of metropolitan area network, the method of separating services and users through QINQ in the broadband access network can no longer meet the requirements of diversified service bearing and rapid new service opening. The main reasons are as follows:
[0049] The diversification of service anchor points leads to an increasing number of service types that need to be separated, and the QINQ scheme cannot achieve rapid and flexible adjustment.
[0050] The QINQ solution is based on the existing business planning of inner and outer VLAN segments, and is pre-configured on the aggregation switch and OLT. In the traditional metropolitan area network, since the service control point and service anchor point are both MSE, the types of services that need to be separated are relatively fixed and limited in number (see Table 1), so this method can better meet the needs of service and user segmentation. The new metropolitan area network considers two aspects: service guarantee needs and resource utilization improvement, and separates different types of service anchor points. Some service anchor points can be deployed in the cloud, and the speed of new construction and expansion is fast. As new services continue to emerge, service anchor points will continue to increase, and the types of services that need to be separated in the broadband access network will also continue to increase. Therefore, the QINQ solution requires frequent adjustments to VLAN planning, and the configuration workload at the equipment level is large and may have an impact on existing services. At the same time, the relevant IT support system also needs to be transformed accordingly, and the adjustment speed is difficult to support the rapid opening of new services.
[0051] The service anchor point pooling deployment and flexible access network location, the QINQ solution cannot meet the needs of service and user segmentation due to the limited number of VLANs.
[0052] In order to improve resource utilization and service carrying reliability, some service anchor points of the new metropolitan area network are deployed in a centralized pool. In order to realize the Layer 2 network channel from CPE to service anchor points, the Layer 2 domain of the broadband access network needs to be extended to the metropolitan area backbone network. The metropolitan area backbone network adopts Layer 2 EVPN technology (VPLS, VPWS) to realize Layer 2 message transparent transmission. The network diagram is shown in the figure below. Figure 3 As shown:
[0053] Centralized deployment of service anchor points has greatly increased the coverage of service anchor points. Taking dial-up Internet access as an example, the coverage area of the traditional metropolitan area network MSE node usually does not exceed 50,000 users, while the coverage area of the new metropolitan area network UP pool reaches 300,000-400,000 users. The VLAN planning of the broadband access network needs to be significantly adjusted. The configuration workload at the equipment level is large and may have an impact on existing services. At the same time, the relevant IT support system also needs to be transformed accordingly. Due to the difficulty of transformation, the migration progress of the existing network services to the new metropolitan area network is affected. With the continuous emergence of new services, the number of VLANs will not be able to meet the requirements of service and user segmentation.
[0054] To sum up, with the large-scale commercial use of new metropolitan area networks and the emergence of new services, the QINQ method used by broadband access networks to separate services and users has gradually become unable to adapt to the needs of network architecture adjustments and business development after cloud-network integration.
[0055] According to an embodiment of the present disclosure, an embodiment of a method for partitioning broadband access network services and users is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0056] This method embodiment can be executed in an electronic device or a similar computing device including a memory and a processor. Taking running on a computer terminal as an example, the computer terminal may include one or more processors (the processor may include, but is not limited to, a processing device such as a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Digital Signal Processing (DSP) chip, a Micro Controller Unit (MCU), a Field Programmable Gate Array (FPGA), a Neural-network Processor Unit (NPU), a Tensor Processing Unit (TPU), an Artificial Intelligence (AI) type processor, etc.) and a memory for storing data. Optionally, the above computer terminal may further include a transmission device for communication functions, input and output devices, and a display device. Those of ordinary skill in the art can understand that the above structural description is only illustrative and does not limit the structure of the above computer terminal. For example, the computer terminal may further include more or fewer components than the above structural description, or have a configuration different from the above structural description.
[0057] The memory can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for partitioning broadband access network services and users in the embodiment of the present disclosure. The processor executes various functional applications and data processing by running the computer program stored in the memory, that is, implements the above method for partitioning broadband access network services and users. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely provided with respect to the processor, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise internal network, a local area network, a mobile communication network, and combinations thereof.
[0058] The transmission device is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of a mobile terminal. In one example, the transmission device includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0059] The display device can be, for example, a touch-screen liquid crystal display (Liquid Crustal Display, LCD) and a touch display (also known as a "touch screen" or "touch display screen"). The liquid crystal display enables a user to interact with the user interface of the mobile terminal. In some embodiments, the above-mentioned mobile terminal has a graphical user interface (Graphical User Interface, GUI), and the user can perform human-computer interaction with the GUI through finger contacts and / or gestures on the touch-sensitive surface. The human-computer interaction function here optionally includes the following interactions: creating web pages, drawing, word processing, creating electronic documents, games, video conferencing, instant messaging, sending and receiving emails, call interfaces, playing digital videos, playing digital music, and / or web browsing, etc. The executable instructions for performing the above human-computer interaction functions are configured / stored in a computer program product or a readable storage medium executable by one or more processors.
[0060] The explanations of the names related to the present invention are as follows:
[0061] IPv6: Internet Protocol Version 6, is the second-generation standard protocol of the network layer protocol. It is a set of specifications designed by the Internet Engineering Task Force (IETF).
[0062] SRv6: Segment Routing IPv6, is a protocol of segment routing that uses the IPv6 forwarding plane on the network based on the source routing concept.
[0063] SRv6 SID: SRv6 Segment Identifier, is in the form of an IPv6 address. The SRv6 SID consists of two parts, Locator and Function, and the format is Locator:Function. Among them, Locator occupies the high bits of the IPv6 address, and the Function part occupies the remaining part of the IPv6 address.
[0064] Locator: A Locator is a component of an SRv6 SID and has a positioning function. After a node configures a Locator, the system generates a Locator network segment route and floods it within the SR domain through IGP. Other nodes in the network can locate this node through the Locator network segment route, and all SRv6 SIDs published by this node can also reach through this Locator network segment route.
[0065] Service Anchor Point: A service anchor point usually refers to a node in the network as the entry or exit point for a specific type of traffic flow. In the context of a new metropolitan area network scenario, the service anchor point implements the forwarding plane function (UP), which is responsible for routing the user's data packets to the correct network path. The service anchor point focuses on the actual transmission path of the data stream.
[0066] Service Control Point: The service control point is the node in the network responsible for decision-making and control policy execution. In the new metropolitan area network, the service control point implements the control plane function (CP), which is responsible for processing signaling messages, formulating and modifying service policies, coordinating network resources to meet specific quality of service requirements, and distributing relevant policies to the service anchor point. The service control point focuses on how to manage and control the data stream to ensure that they are transmitted according to the pre-defined policies and rules.
[0067] Figure 1 is a flowchart of a method for separating broadband access network services from users according to one embodiment of the present disclosure, as Figure 1 shown, the method includes the following steps:
[0068] Step S101, in response to the user device online instruction, pre-configure the user device, where the pre-configuration is used to establish a connection between the user device and the information technology management platform, and the information technology management platform is configured with a corresponding service code;
[0069] Step S102, construct the service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform;
[0070] Step S103, determine the communication tunnel according to the service identifier of the information technology management platform and the service anchor point identifier corresponding to the information technology management platform;
[0071] Step S104, based on the communication tunnel, allocate the service address corresponding to the information technology management platform for the user device.
[0072] In the disclosed embodiment, in response to the user-end device online instruction, the user-end device is preconfigured, wherein the preconfiguration is used to establish a connection between the user-end device and the information technology management platform, and the information technology management platform is configured with a corresponding service code; the service identifier of the information technology management platform is constructed according to the PD prefix and the service code of the information technology management platform; the communication tunnel is determined according to the service identifier of the information technology management platform and the service anchor identifier corresponding to the information technology management platform; based on the communication tunnel, the service address corresponding to the information technology management platform is allocated to the user-end device. The access requirements of different services are separated by SRv6 SID (service SID) with different functions, and the communication tunnel from the client device to the service anchor point is opened, and the service message is encapsulated in the communication tunnel, which can overcome the problems of inflexible service adjustment and limited service anchor point coverage area in the original QINQ solution, and thus solve the technical problem in the related technology that with the large-scale commercial use of new metropolitan area networks, the method of broadband access networks using QINQ to separate services and users can no longer adapt to the needs of diversified service carrying and rapid opening of new services.
[0073] Optionally, in response to an online instruction of the user-end device, the user-end device is pre-configured, including: configuring a service code for the information technology management platform in the user-end device, wherein the service code corresponds to a service anchor point identifier, and the service code corresponds to a logical service gateway.
[0074] Optionally, a business identifier of the information technology management platform is constructed based on the PD prefix and the business code of the information technology management platform, including: obtaining a randomly generated field; and combining the PD prefix, the business code of the information technology management platform and the randomly generated field to obtain the business identifier of the information technology management platform.
[0075] Optionally, based on the communication tunnel, a business address corresponding to the information technology management platform is allocated to the user-end device, including: using a logical business gateway to send a dynamic host configuration protocol request message, wherein the request message is encapsulated into the communication tunnel for transmission; the business anchor point corresponding to the information technology management platform decapsulates the request message in the communication tunnel and allocates a business address corresponding to the information technology management platform to the user-end device.
[0076] Optionally, the method also includes: responding to a service activation instruction of the user-end device, using the information technology management platform to send a service anchor point identifier, service code and service gateway configuration corresponding to the service to be activated to the user-end device, wherein the service to be activated is included in the service activation instruction; constructing a service identifier of the service to be activated based on the service code of the service to be activated; based on the service identifier, using the information technology management platform to send the port, service gateway and communication tunnel binding relationship to the user-end device.
[0077] Optionally, the method further includes: sending a service request message through a service gateway; encapsulating the service request message into a communication tunnel and sending the encapsulated request message through the communication tunnel; determining a response message using a service anchor based on the encapsulated request message and sending the encapsulated response message through the communication tunnel; and completing gateway authentication using a client device based on the encapsulated response message.
[0078] Optionally, the services to be activated include one or more of the following: dial-up Internet access service, virtual reality game service.
[0079] Based on the above embodiments, the present invention is specifically implemented as follows:
[0080] According to the access requirements of different services, different services are segmented by different SRv6 SIDs (Service SIDs), and the SRv6 tunnel from the CPE (Client Premises Equipment) to the service anchor is established. The services to be segmented are carried by different SRv6 tunnels. In the upstream direction of the service message, the CPE encapsulates the service message in the SRv6 tunnel, and the service anchor decapsulates the SRv6 tunnel message and performs subsequent processing on the service message based on the service SID. In the downstream direction of the service message, the service anchor encapsulates the service message in the SRv6 tunnel, and the CPE decapsulates the SRv6 tunnel message and performs subsequent processing on the service message based on the service SID.
[0081] SRv6 realizes the instructionization of network functions, and embeds the instructions expressing network functions into the 128-bit IPv6 address. In the SRv6 network, service requirements can be translated into an ordered list of instructions, which are executed by the network devices along the way, so as to achieve flexible orchestration and on-demand customization of network services. The SRv6 SID is a 128-bit value, which consists of three parts:
[0082] Locator (Location Identifier) is an identifier assigned to a network node in the network, which can be used for routing and forwarding data packets.
[0083] Function is an ID value assigned by the device to the local forwarding instruction. Different forwarding behaviors are expressed by different function IDs. This value can be used to express the forwarding action required when the device receives an SRv6 message, which is equivalent to the operation code of a computer instruction. Function determines whether to forward the data to a node, a link, perform decapsulation and look up the routing table for forwarding, or perform decapsulation and send it into an instance, etc.
[0084] Args (Optional) are the parameters required when the forwarding instruction is executed. These parameters may include flows, services, or any other relevant variable information.
[0085] According to different services, the present invention respectively defines the Function of the service SID. The service SID is used as the source and destination addresses of the SRv6 tunnel, and is used for the decapsulation of the SRv6 tunnel packets at both ends of the tunnel and the execution of the next operation. Different services are carried by different SRv6 tunnels to achieve service isolation.
[0086] The schematic architecture diagram of the method for isolating the broadband access network service from users is as Figure 4 shown. The construction of the SRv6 tunnel between the CPE and the service anchor point mainly includes three steps, namely, establishing a layer 2 network channel between the CPE and the ALEAF, the CPE obtaining the SRv6 tunnel address, and establishing an SRv6 tunnel between the CPE and the service anchor point.
[0087] 1. Establishing a layer 2 network channel between the CPE and the ALEAF
[0088] Different from the traditional QINQ scheme, in the present invention, the QINQ identifier is only used to isolate users (CPEs) and not to isolate services. The QINQ identifier corresponds to each user (CPE) one by one. The broadband access network assigns a QINQ identifier to each CPE to achieve user isolation. The CPE adds an inner VLAN tag to the packet, and the OLT or aggregation switch adds an outer VLAN tag to the packet to construct a layer 2 network channel between the CPE and the ALEAF.
[0089] The QINQ identifier is only used to isolate users, which simplifies the VLAN planning of the broadband access network and does not need to be adjusted with the change of isolated services. Therefore, the configuration of the broadband access network equipment and the relevant processes of the IT support system do not need to be modified accordingly due to VLAN adjustment, improving the stability of the services carried by the broadband access network. At the same time, the number of VLANs can meet the needs of large-scale user access after the centralized pooling deployment of service anchor points.
[0090] 2. The CPE obtaining the SRv6 tunnel address
[0091] To construct the SRv6 tunnel from the CPE to the service anchor point, the CPE needs to meet the following three necessary conditions:
[0092] (1) The CPE access authentication and obtaining an IPv6 address;
[0093] The CPE completes the access authentication and IPv6 address acquisition process through DHCPv6: The CPE initiates a DHCPv6 request and inserts the Option 16 option with "account / password" information in the DHCPv6 discovery message; the OLT inserts the Option 18 / 37 option with the CPE access "line / port" information in the DHCPv6 request message; the ALEAF is configured as a DHCP Relay to forward the DHCPv6 message to the DHCP Server; the DHCP Server extracts the Option information and converts it into relevant Radius protocol attributes, initiates an AAA authentication, and assigns a WAN interface IPv6 address and a LAN-side IPv6 PD prefix to the CPE after successful authentication. The AAA server records the corresponding information of the user account, access line / port, and IPv6 address for online and offline traceability.
[0094] (2) The CPE obtains the service SID of the service anchor point;
[0095] The CPE constructs an SRv6 tunnel to the service anchor point, and the services that need to be segmented are carried through different SRv6 tunnels respectively. For the upstream service packets, the CPE encapsulates them into the SRv6 tunnel, and the tunnel destination address is the service SID of the service anchor point. After the service anchor point de-encapsulates the SRv6 tunnel, it needs to process the service packets according to the Function in the service SID. Therefore, the CPE needs to obtain the service SID of the service anchor point for the tunnel destination address.
[0096] After the CPE access passes the AAA authentication, according to the service associated with the account, the ITMS platform sends the service SID of the service anchor point to the CPE through TR069.
[0097] (3) The CPE generates its own service SID.
[0098] For the downstream service packets, after the CPE de-encapsulates the SRv6 tunnel, it needs to process the service packets according to the Function in the service SID. Therefore, the CPE needs to generate its own service SID and announce it to the service anchor point.
[0099] The process for the CPE to generate its own service SID is as follows: After the CPE access passes the AAA authentication, according to the service associated with the account, the ITMS platform sends the Function field of the SRv6 SID to the CPE through TR069; for different services that need to be segmented, the Function fields are different; the CPE synthesizes its own service SID based on the PD prefix and the Function field. The generation rule is as Figure 5 shown:
[0100] Locator field: Obtained from the ALEAF through the IPoE PD method (seeFigure 3 )。
[0101] Function field: Based on the service coding of End.DX2, different services to be segmented have unique service codings.
[0102] 3. The service anchor obtains the service SID of the CPE
[0103] The service anchor automatically learns the service SID of the CPE through the service message sent by the CPE and adds it to the forwarding table. The process for the service anchor to obtain the CPE service SID is as follows:
[0104] The CPE has obtained the service SIDs of its own device and the service anchor, encapsulates the first service message into an SRv6 tunnel, where the source address of the tunnel is the CPE service SID and the destination address is the service SID of the service anchor;
[0105] The service SID of the service anchor is a newly defined SID, and the function corresponding to its Function field is to strip the outer header of the SRv6 tunnel, automatically learn the service SID of the CPE, and add it to the forwarding table;
[0106] After receiving the message, the service anchor adds the tunnel source address as the service SID of this CPE to the forwarding table and uses it as the destination address for encapsulating the SRv6 tunnel for the downstream service message.
[0107] 4. Establish an SRv6 tunnel between the CPE and the service anchor
[0108] An SRv6 tunnel is built between the CPE and the service anchor, and the service message is encapsulated in the SRv6 message. Different services to be segmented are carried through different SRv6 tunnels. The SRv6 tunnel adopts the BE mode, and the source and destination addresses are the service SIDs of the CPE and the service anchor respectively.
[0109] It should be noted that based on the SRv6 tunnel, the CPE constructs a layer-2 network channel between itself and the service anchor. The CPE and the service anchor encapsulate the layer-2 service message in the IPv6 header, and the encapsulation format is as Figure 6 shown, including the inner service header and the outer service header.
[0110] Specifically, as a user-side multi-service unified bearing device, the CPE needs to segment different services at the device level. The CPE is in the routing mode and is configured on both the WAN side and the LAN side. The WAN side includes the physical WAN port and the SRv6 tunnel from the CPE to the service anchor. The LAN side includes the physical LAN port and the logical service gateway. The physical WAN port uniformly bears all services, and different services are bound to different SRv6 tunnels, physical LAN ports, and logical service gateways.
[0111] The CPE online process is as follows:
[0112] S01. Pre-configuration of the CPE. Since it is necessary to establish the service channel from the CPE to the ITMS platform in advance, the CPE pre-configures the ITMS service code (Function field) for TR069. The ITMS service code is bound to the ITMS service gateway with the service SID of the service anchor point.
[0113] S02. The CPE obtains the SRv6 tunnel address. After the CPE goes online, it obtains the WAN port IPv6 address and the PD prefix through DHCPv6 to construct the SRv6 tunnel from the CPE to the service anchor point.
[0114] S03. Establish the TR069 channel. The CPE constructs the ITMS service SID based on the PD prefix and the ITMS service code, and this SID is bound to the ITMS service gateway. The ITMS service gateway sends a DHCP request message, and the CPE encapsulates this message into the SRv6 tunnel. The source address of this message is the ITMS service SID, and the destination address is the service SID of the ITMS service anchor point. The ITMS service anchor point de-encapsulates the SRv6 tunnel and assigns the ITMS service IP to the CPE through DHCP.
[0115] After the CPE goes online, according to each service subscribed by the user, the parameters sent by the ITMS platform to the CPE through TR069 include:
[0116] ① Configure the logical service gateway;
[0117] ② Service code (Function field of the service SID);
[0118] ③ Service anchor point SID;
[0119] ④ The binding relationship between the physical LAN port on the LAN side, the logical service gateway and the SRv6 tunnel on the WAN side;
[0120] The CPE constructs the service SID based on the PD prefix and the service code, and then constructs the SRv6 service tunnel by combining the service SID and the service anchor point SID. Different SRv6 service tunnels are distinguished based on the source and destination IPv6 combinations. The source and destination addresses are the service SIDs of the CPE and the service anchor point respectively. An example of the binding relationship between the physical LAN port on the LAN side, the logical service gateway and the SRv6 tunnel on the WAN side is shown in Table 2:
[0121] Table 2
[0122]
[0123] Based on Figure 7 the network topology structure shown, the exemplary implementation of the present invention is as follows:
[0124] Service Anchor 1 accesses the dial-up Internet service with service SID: 1000::1, Service Anchor 2 accesses the VR game service with service SID: 2000::1, and Service Anchor 3 accesses the ITMS service with service SID: 3000::1.
[0125] ALEAF allocates the IPv6 PD prefix 4000:1000:1000:1000:: / 64 and the local prefix 4001:1001:1001:1001:: / 64 for the CPE to access the new metropolitan area network.
[0126] The Function field (48-bit) allocated to each service of the CPE: Dial-up Internet service: 0000:0000:0001, VR game service: 0000:0000:0002, ITMS service: 0000:0000:0003.
[0127] Pre-configure the CPE: S01: Pre-configure the ITMS service code (Function field): 0000:0000:0003; S02: Pre-configure the service SID of the ITMS service anchor: 3000::1; S03: Pre-configure the ITMS service gateway and bind it to the ITMS service code and the service SID of the service anchor.
[0128] Refer to Figure 8 , the CPE online process is as follows:
[0129] ① The CPE sends a DHCPv6 request to the ALEAF and inserts the Option16 option with the "account / password" information in the DHCPv6 discovery message.
[0130] ② The OLT inserts the Option18 / 37 option with the "line / port" information for the CPE access in the DHCPv6 request message.
[0131] ③ The ALEAF acts as a DHCP Relay and forwards the DHCPv6 message to the DHCP Server.
[0132] ④ The DHCP Server extracts the Option option information, converts it into Radius protocol-related attributes, and initiates AAA authentication.
[0133] ⑤ After the AAA verifies the "account / password" and "line / port" (optional), it returns the authentication passed information to the DHCP Server.
[0134] ⑥ The DHCP Server allocates a WAN port address and a PD prefix for the CPE and sends the address allocation information to the ALEAF.
[0135] ⑦ALEAF configures the IP address of the CPE, including the WAN port address and PD prefix, as follows:
[0136] WAN port address: 4001:1001:1001:1001::2 / 64;
[0137] PD prefix: 4000:1000:1000:1000:: / 64;
[0138] ⑧The DHCP Server reports the IPv6 address obtained by the CPE to AAA; the AAA server records the corresponding information of the user account, access line / port, and IPv6 address for online and offline tracing.
[0139] After the CPE goes online, the TR069 channel needs to be opened. The process is as follows:
[0140] S01: CPE synthesizes ITMS service SID: 4000:1000:1000:1000:1000 according to the PD prefix (Locator field: 4000:1000:1000:1000), pre-configured ITMS service code (Function field: 0000:0000:0003), and randomly generated Arg field (0001): 4000:1000:1000:1000:0000:0000:0003:0001;
[0141] S02: CPE binds the ITMS service SID and the service SID of service anchor point 3 to the ITMS service gateway;
[0142] S03: The ITMS service gateway of the CPE initiates a DHCP request to the ITMS service anchor point;
[0143] S04: The CPE encapsulates the Layer 2 message containing DHCP in the SRv6 tunnel. The tunnel source address is the CPE service SID (4000:1000:1000:1000:0000:0000:0003:0001), and the destination address is the service SID of service anchor 3 (3000::1).
[0144] S05: Service anchor point 3 decapsulates the SRv6 tunnel, automatically learns the service SID and MAC of the CPE, adds them to the forwarding table, maps the service SID to the MAC, and allocates an IP address to the CPE through the DHCP module.
[0145] S06: Service anchor 3 encapsulates the Layer 2 message containing the DHCP response in the SRv6 tunnel. The tunnel source address is the CPE service SID (3000::1) and the destination address is the service SID of the service anchor (4000:1000:1000:1000:0000:0000:0003:0001).
[0146] S07: The CPE decapsulates the SRv6 tunnel, configures the IP of the ITMS service gateway, opens the TR069 channel, and the CPE and the ITMS server exchange information;
[0147] S08: The user subscribes to the dial-up Internet access and VR game services, and the ITMS server sends the relevant parameters to the CPE:
[0148] Dial-up Internet access service: The service SID (1000::1) of service anchor point 1, the service code (Function field: 0000:0000:0001), and the service gateway configuration parameters;
[0149] VR game service: The service SID (2000::1) of service anchor point 2, the service code (Function field: 0000:0000:0002), and the service gateway configuration parameters;
[0150] S09: The CPE generates the service SID:
[0151] Dial-up Internet access service: Based on the PD prefix and the service code, generate the service SID (4000:1000:1000:1000:0000:0000:0001:0001);
[0152] VR game service: Based on the PD prefix and the service code, generate the service SID (4000:1000:1000:1000:0000:0000:0002:0001);
[0153] S10: The ITMS server sends the port, service gateway, and SRv6 tunnel binding relationship to the CPE;
[0154] Dial-up Internet access service: The physical ports on the LAN side (LAN1, LAN2, SSID1), service gateway, and SRv6 tunnel (with source and destination addresses being the service SIDs of the CPE and service anchor point 1 respectively) are bound;
[0155] VR game service: The physical ports on the LAN side (LAN3, SSID2), service gateway, and SRv6 tunnel (with source and destination addresses being the service SIDs of the CPE and service anchor point 2 respectively) are bound.
[0156] After the above channels are constructed, the dial-up Internet access service process is as follows:
[0157] S01: The CPE initiates a PPPoE dial-up through the service gateway;
[0158] S02: The CPE encapsulates the SRv6 outer header for the PPPoE packet, encapsulates the layer 2 packet containing PPPoE in the SRv6 tunnel. The source address of the SRv6 tunnel is the service SID of the CPE (4000:1000:1000:1000:0000:0000:0001:0001), and the destination address is the service SID of service anchor 1 (1000::1).
[0159] S03: The CPE sends the SRv6 packet through the WAN port.
[0160] S04: After receiving the SRv6 packet, the service anchor de-encapsulates the SRv6 tunnel, sends the layer 2 packet containing PPPoE to the PPPoE function module for processing. At the same time, service anchor 1 automatically learns the service SID and MAC of the CPE, adds them to the forwarding table, and associates the service SID of the CPE with the MAC.
[0161] S05: The service anchor encapsulates the SRv6 outer header for the PPPoE response packet, encapsulates the layer 2 packet containing PPPoE in the SRv6 tunnel. The source address of the SRv6 tunnel is the SID of service anchor 1 (1000::1), and the destination address is the service SID of the CPE; (4000:1000:1000:1000:0000:0000:0001:0001);
[0162] S06: After receiving the SRv6 packet, the CPE de-encapsulates the SRv6 tunnel and sends the layer 2 packet containing PPPoE to the service gateway for processing.
[0163] S07: After the service gateway completes authentication and obtains the service IP, the user can access the Internet normally.
[0164] The online process of the VR game service is as follows:
[0165] S01: The CPE initiates a DHCP request through the service gateway.
[0166] S02: The CPE encapsulates the SRv6 outer header for the DHCP packet, encapsulates the layer 2 packet containing DHCP in the SRv6 tunnel. The source address of the SRv6 tunnel is the service SID of the CPE (4000:1000:1000:1000:0000:0000:0002:0001), and the destination address is the service SID of service anchor 2 (2000::1).
[0167] S03: The CPE sends the SRv6 packet through the WAN port.
[0168] S04: After receiving the SRv6 packet, Service Anchor Point 2 decapsulates the SRv6 tunnel and sends the layer-2 packet containing DHCP to the PPPoE function module for processing. At the same time, Service Anchor Point 2 automatically learns the service SID and MAC of the CPE, adds them to the forwarding table, and associates the service SID of the CPE with the MAC.
[0169] S05: Service Anchor Point 2 encapsulates the DHCP response packet with an SRv6 outer header and encapsulates the layer-2 packet containing DHCP in the SRv6 tunnel. The source address of the SRv6 tunnel is the SID of Service Anchor Point 2 (2000::1), and the destination address is the service SID of the CPE; (4000:1000:1000:1000:0000:0000:0002:0001).
[0170] S06: After receiving the SRv6 packet, the CPE decapsulates the SRv6 tunnel and sends the layer-2 packet containing DHCP to the service gateway for processing.
[0171] S07: After the service gateway completes authentication and obtains the service IP, it can normally play VR games.
[0172] Based on the description of the above embodiments, it can be understood that:
[0173] 1) The method for partitioning different services in the broadband access network based on SRv6 realizes the layer-2 network channel between the CPE and the service anchor point through the SRv6 tunnel. Different services are partitioned by using SRv6 SIDs (service SIDs) with different functions, the SRv6 tunnel between the CPE and the service anchor point is established, the layer-2 service packet is encapsulated in the SRv6 tunnel, and the CPE and the service anchor point at both ends of the tunnel decapsulate the SRv6 packet. This method solves the problems existing in the QINQ scheme of the original operator's broadband access network, such as inflexible service adjustment and limited coverage area of the service anchor point, enabling the broadband access network to better adapt to the new metro backbone network and meet the requirements for carrying various future new services.
[0174] 2) The method for the service anchor point to automatically learn the service SID of the CPE. When the CPE encapsulates the service packet into the SRv6 tunnel, it uses the service SID as the source address of the tunnel and sends it to the service anchor point. The service anchor point analyzes the SRv6 packet with the outer-layer encapsulated service by automatically learning the first service packet sent by the CPE, and uses its source address as the service SID of the CPE. At the same time, it decapsulates the SRv6 tunnel and learns the source MAC of the layer-2 service packet. The service anchor point automatically writes the correspondence between the service SID of the CPE and the MAC of the CPE into the MAC forwarding table to realize the automatic learning of the service SID and MAC of the CPE by the service anchor point.
[0175] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present disclosure, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present disclosure.
[0176] In an embodiment of the present disclosure, there is also provided a device for separating broadband access network services from users. This device is used to implement the above embodiments and preferred implementation methods, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0177] Figure 9 is a structural block diagram of a device for separating broadband access network services from users according to an embodiment of the present disclosure, as Figure 9 shown, the device includes:
[0178] The configuration module 201 is configured to, in response to a user device online instruction, pre-configure the user device, where the pre-configuration is used to establish a connection between the user device and the information technology management platform, and the information technology management platform is configured with a corresponding service code; a construction module 202, configured to construct a service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform; a determination module 203, configured to determine a communication tunnel according to the service identifier of the information technology management platform and the service anchor point identifier corresponding to the information technology management platform; and an allocation module 204, configured to allocate a service address corresponding to the information technology management platform for the user device based on the communication tunnel.
[0179] Optionally, the configuration module 201 is further configured to: configure a service code for the information technology management platform in the user device, where the service code corresponds to a service anchor point identifier and a logical service gateway.
[0180] Optionally, the construction module 202 is further configured to: obtain a randomly generated field; and combine the PD prefix, the service code of the information technology management platform, and the randomly generated field to obtain the service identifier of the information technology management platform.
[0181] Optionally, the allocation module 204 is further configured to: send a Dynamic Host Configuration Protocol (DHCP) request message by using a logical service gateway, where the request message is encapsulated into a communication tunnel for transmission; and a service anchor corresponding to the Information Technology Management Platform decapsulates the request message in the communication tunnel to allocate a service address corresponding to the Information Technology Management Platform to the client device.
[0182] Optionally, the allocation module 204 is further configured to: in response to a service activation instruction of the client device, use the Information Technology Management Platform to send a service anchor identifier, a service code, and a service gateway configuration corresponding to the service to be activated to the client device, where the service to be activated is included in the service activation instruction; construct a service identifier of the service to be activated according to the service code of the service to be activated; and based on the service identifier, use the Information Technology Management Platform to send a port, service gateway, and communication tunnel binding relationship to the client device.
[0183] Optionally, the allocation module 204 is further configured to: send a service request message through a service gateway; encapsulate the service request message into a communication tunnel and send the encapsulated request message through the communication tunnel; determine a response message by using a service anchor according to the encapsulated request message, and send the encapsulated response message through the communication tunnel; and complete gateway authentication by using the client device according to the encapsulated response message.
[0184] Optionally, the services to be activated in the allocation module 204 include one or more of the following: dial-up Internet access service, virtual reality game service.
[0185] It should be noted that the above-mentioned modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above-mentioned modules are all located in the same processor; or, the above-mentioned modules are respectively located in different processors in any combination form.
[0186] According to one embodiment of the present disclosure, an electronic device is further provided, including: a memory storing an executable program; and a processor configured to run the program, where when the program runs, it executes the method for partitioning broadband access network services and users in the embodiments of the present disclosure.
[0187] Optionally, in this embodiment, the above-mentioned processor may be configured to execute the following steps by a computer program:
[0188] Step S101, in response to a client device online instruction, perform pre-configuration on the client device, where the pre-configuration is used to establish a connection between the client device and the Information Technology Management Platform, and the Information Technology Management Platform is configured with a corresponding service code;
[0189] Step S102, construct a service identifier of the Information Technology Management Platform according to the PD prefix and the service code of the Information Technology Management Platform;
[0190] Step S103: Determine a communication tunnel according to the service identifier of the information technology management platform and the service anchor point identifier corresponding to the information technology management platform.
[0191] Step S104: Based on the communication tunnel, allocate a service address corresponding to the information technology management platform for the client device.
[0192] According to one embodiment of the present disclosure, there is also provided a computer-readable storage medium. The computer-readable storage medium includes a stored executable program. When the executable program runs, it controls the device where the storage medium is located to execute the method for separating broadband access network services from users in the embodiments of the present disclosure.
[0193] Optionally, in this embodiment, the above storage medium may be set to store a computer program for executing the following steps:
[0194] Step S101: In response to the client device online instruction, perform pre-configuration on the client device. The pre-configuration is used to establish a connection between the client device and the information technology management platform, and the information technology management platform is configured with a corresponding service code.
[0195] Step S102: Construct the service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform.
[0196] Step S103: Determine a communication tunnel according to the service identifier of the information technology management platform and the service anchor point identifier corresponding to the information technology management platform.
[0197] Step S104: Based on the communication tunnel, allocate a service address corresponding to the information technology management platform for the client device.
[0198] Optionally, in this embodiment, the above storage medium may include but is not limited to: various media that can store computer programs such as USB flash drives, read-only memories (ROM), random access memories (RAM), external hard drives, magnetic disks, or optical discs.
[0199] According to one embodiment of the present disclosure, there is also provided a computer program product, including a computer program that implements the method for separating broadband access network services from users in the embodiments of the present disclosure when executed by a processor.
[0200] Optionally, in this embodiment, the above computer program product may be set to execute a computer program for the following steps:
[0201] Step S101, in response to the online instruction of the client device, pre-configure the client device, where the pre-configuration is used to establish a connection between the client device and the information technology management platform, and the information technology management platform is configured with a corresponding service code;
[0202] Step S102, construct the service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform;
[0203] Step S103, determine the communication tunnel according to the service identifier of the information technology management platform and the corresponding service anchor point identifier of the information technology management platform;
[0204] Step S104, based on the communication tunnel, allocate the service address corresponding to the information technology management platform for the client device.
[0205] The serial numbers of the embodiments of the present invention above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0206] In the above embodiments of the present disclosure, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0207] In several embodiments provided by the present disclosure, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division, and in actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces, and the indirect couplings or communication connections of the units or modules can be in an electrical or other form.
[0208] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0209] In addition, the functional units in the various embodiments of the present disclosure can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0210] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs.
[0211] The above are only the preferred embodiments of the present disclosure. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present disclosure, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present disclosure.
Claims
1. A method for separating broadband access network services and users, characterized in that: include: In response to a user terminal device online instruction, pre-configure the user terminal device, wherein the pre-configuration is used to establish a connection between the user terminal device and an information technology management platform, and the information technology management platform is configured with a corresponding service code; Construct the business identification of the information technology management platform according to the PD prefix and the business code of the information technology management platform; Determining a communication tunnel according to a service identifier of the information technology management platform and a service anchor identifier corresponding to the information technology management platform; Based on the communication tunnel, a service address corresponding to the information technology management platform is allocated to the user terminal device.
2. The method for separating broadband access network services and users according to claim 1, characterized in that: The pre-configuring the user terminal device in response to the user terminal device online instruction includes: A service code is configured for the information technology management platform in the user terminal device, wherein the service code corresponds to a service anchor point identifier, and the service code corresponds to a logical service gateway.
3. The method for separating broadband access network services and users according to claim 1, characterized in that: The constructing the service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform includes: Get the randomly generated field; The service identifier of the information technology management platform is obtained by combining the PD prefix, the service code of the information technology management platform and the randomly generated field.
4. The method for separating broadband access network services and users according to claim 2, characterized in that: The allocating a service address corresponding to the information technology management platform to the user terminal device based on the communication tunnel includes: Using the logical service gateway to send a dynamic host configuration protocol request message, wherein the request message is encapsulated into the communication tunnel for transmission; The service anchor point corresponding to the information technology management platform decapsulates the request message in the communication tunnel and allocates a service address corresponding to the information technology management platform to the user terminal device.
5. The method for separating broadband access network services and users according to claim 1, characterized in that: Also includes: In response to a service activation instruction of the user terminal device, using the information technology management platform to issue a service anchor point identifier, a service code, and a service gateway configuration corresponding to the service to be activated to the user terminal device, wherein the service to be activated is included in the service activation instruction; Constructing a service identifier of the service to be activated according to the service code of the service to be activated; Based on the service identifier, the information technology management platform is used to send the port, service gateway and communication tunnel binding relationship to the user terminal device.
6. The method for separating broadband access network services and users according to claim 5, characterized in that: The method further comprises: Sending a service request message through the service gateway; Encapsulating the service request message into the communication tunnel, and sending the encapsulated request message through the communication tunnel; Determine a response message according to the encapsulated request message by using a service anchor point, and send the encapsulated response message through the communication tunnel; According to the encapsulated response message, gateway authentication is completed using the user terminal device.
7. The method for separating broadband access network services and users according to claim 5, characterized in that: The services to be activated include one or more of the following: dial-up Internet access service and virtual reality game service.
8. A device for separating broadband access network services from users, characterized in that: include: A configuration module, for pre-configuring the user terminal device in response to a user terminal device online instruction, wherein the pre-configuration is used to establish a connection between the user terminal device and an information technology management platform, and the information technology management platform is configured with a corresponding service code; A construction module, used for constructing a service identifier of the information technology management platform according to the PD prefix and the service code of the information technology management platform; A determination module, configured to determine a communication tunnel according to a service identifier of the information technology management platform and a service anchor identifier corresponding to the information technology management platform; The allocation module is used to allocate a service address corresponding to the information technology management platform to the user terminal device based on the communication tunnel.
9. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 7 when running.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is executed, the device where the storage medium is located is controlled to execute the method according to any one of claims 1 to 7.
11. A computer program product, characterized in that The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 7.