Network operation and maintenance method, device, equipment, system and storage medium
By carrying device information in the negotiation message, the control device can send the failure reason to the user when the device and the control device fail, solving the problem that the user cannot perceive the connection failure and improving the connection success rate.
Patent Information
- Application Number
- CN202311865518.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-07-01
AI Technical Summary
In the operation and maintenance application scenario of the park network, when the connection between the device and the control device fails, the control device cannot handle the connection failure, resulting in the user being unable to perceive the cause of the failure and taking corresponding measures.
By carrying the device information of the network element device in the negotiation message, the control device can send the reason for the failure of the connection establishment to the terminal used by the user who operates and maintains the network element device when the connection establishment fails.
This allows users to perceive the failure of network element equipment to establish a connection failure, so as to take effective measures in a timely manner based on the failure reasons, and improve the success rate of network element equipment and control devices to establish a connection.
Smart Images

Figure CN120238558A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and particularly to methods, devices, equipment, systems, and storage media for network operation and maintenance. Background Art
[0002] With the development of communication technologies, campus networks have developed rapidly. In the operation and maintenance application scenarios of campus networks, devices need to actively connect to a control device. After a device successfully connects to the control device, the control device actively obtains the device information of the device, and then determines the user information corresponding to the device based on the device information of the device. However, for scenarios where the connection between a device and a control device fails, the control device cannot handle the connection failure. Summary of the Invention
[0003] This application provides a method, device, equipment, system, and storage medium for network operation and maintenance, which is used to notify the cause of connection failure to the terminal used by the user who maintains the device when the connection establishment between the device and the control device fails.
[0004] In a first aspect, a method for network operation and maintenance is provided. Taking the control device executing this method as an example, the control device receives a negotiation message sent by a network element device. The negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes the device information of the network element device; determines the user information corresponding to the network element device according to the device information, where the user information indicates the user who operates and maintains the network element device; and when the connection establishment with the network element device fails based on the negotiation message, sends the cause of connection establishment failure to the terminal used by the user who operates and maintains the network element device.
[0005] In this method, during the process of establishing a connection between the control device and the network element device based on the negotiation message, since the negotiation message sent by the network element device to the control device carries the device information of the network element device, the control device can determine the user who operates and maintains the network element device according to the device information before the connection is successfully established. Then, when the connection establishment fails, the control device can send the cause of connection establishment failure to the terminal used by the user. Thus, the user can perceive the cause of connection establishment failure of the network element device, and then the user can take effective measures in a timely manner according to the cause of connection failure to solve the connection failure problem, improving the success rate of establishing a connection between the network element device and the control device.
[0006] In a possible implementation, the control device stores the mapping relationship between device information and user information; the method for determining the user information corresponding to the network element device according to the device information in the negotiation message may be to determine the user information corresponding to the network element device according to the mapping relationship and the device information in the negotiation message. By pre-obtaining and storing the mapping relationship between device information and user information and determining the user information corresponding to the network element device based on this mapping relationship, the efficiency of determining the user information corresponding to the network element device is improved.
[0007] In a second aspect, a network operation and maintenance method is provided. Taking the network element device executing this method as an example, the network element device sends a negotiation message to the control device. The negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes the device information of the network element device. Among them, the device information is used for the control device to determine the user information corresponding to the network element device according to the device information, and the user information indicates the user who operates and maintains the network element device, so that when the controller fails to establish a connection with the network element device based on the negotiation message, the failure reason for the connection establishment failure is sent to the terminal used by the user.
[0008] In this method, the network element device carries the device information of the network element device in the negotiation message sent to the control device, so that the control device can determine the user who operates and maintains the network element device according to the device information. Furthermore, when the connection establishment fails, the control device can send the failure reason for the connection establishment failure to the terminal used by the user, so that the user can perceive the failure reason for the connection establishment failure of the network element device. Then, the user can take effective measures in time according to the connection failure reason to solve the connection failure problem, and improve the success rate of establishing a connection between the network element device and the control device.
[0009] In a third aspect, a network operation and maintenance method is provided. Taking the terminal executing this method as an example, the terminal is the terminal used by the user who operates and maintains the network element device. The method includes: when the connection between the network element device and the control device fails to be established, the terminal receives the failure reason for the connection establishment failure sent by the control device.
[0010] In this method, the user who operates and maintains the network element device can obtain the failure reason for the connection establishment failure between the network element device and the control device in time, so that the user can take effective measures in time according to the connection failure reason to solve the connection failure problem, and improve the success rate of the network element device connection.
[0011] In any possible implementation manner among the first to third aspects described above, the failure reason may include algorithm negotiation failure or certificate verification failure, etc. For the scenario where a connection between a network element device and a control device can be successfully established only after the algorithm negotiation of keys and consistent certificate verification, since both algorithm negotiation and certificate verification occur after determining the user information corresponding to the network element device, if the connection establishment fails due to algorithm negotiation failure or certificate verification failure, the control device can promptly notify the user of the failure reason so that the user can take effective measures to solve the problems of algorithm negotiation failure or certificate verification failure.
[0012] In any possible implementation manner among the first to third aspects described above, the negotiation message is the first message sent by the network element device to the control device during the process of establishing a connection between the network element device and the control device. This enables the control device to obtain device information immediately after the first message sent by the network element device to the control device. Furthermore, for any connection failure scenario after the first message sent by the network element device to the control device, the control device can send the connection failure reason to the user, improving the comprehensiveness and accuracy of notifying the connection failure reason.
[0013] In any possible implementation manner among the first to third aspects described above, the negotiation message may be a secure shell (SSH) protocol version exchange message or a transport layer security (TLS) handshake message. Optionally, if the SSH protocol version exchange message includes a comments field, the device information of the network element device can be carried in the comments field included in the SSH protocol version exchange message; or, if the SSH protocol version exchange message includes a data block field ending with a carriage return (CR) and a linefeed (LF) before the field starting with SSH, the device information of the network element device is carried in the data block field; or, if the TLS handshake message includes an extended definition field, the device information of the network element device is carried in the definition field.
[0014] Thus, through the above different methods, the device information can be flexibly carried in the negotiation message, improving the feasibility of the negotiation message to carry device information.
[0015] In any possible implementation manner among the first to third aspects described above, the device information includes at least one of an electronic serial number (ESN) or a medium access control (MAC) address. This method can be applicable to different representation forms of device information, making the method have high general applicability.
[0016] In a fourth aspect, a network operation and maintenance device is provided. The device is applied to a control device and includes:
[0017] A transceiver module, configured to perform operations related to reception and / or transmission performed by the control device in the first aspect or any possible implementation manner of the first aspect;
[0018] A processing module, configured to perform other operations other than the operations related to reception and / or transmission performed by the control device in the first aspect or any possible implementation manner of the first aspect.
[0019] In a possible implementation manner, the transceiver module includes a reception module and / or a transmission module. The reception module is configured to perform operations related to reception, and the transmission module is configured to perform operations related to transmission.
[0020] In a possible implementation manner, the transceiver module is configured to receive a negotiation message sent by a network element device. The negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes device information of the network element device; the processing module is configured to determine user information corresponding to the network element device according to the device information, where the user information indicates a user for operating and maintaining the network element device; the transceiver module is further configured to, when a connection establishment with the network element device fails based on the negotiation message, send a failure reason for the connection establishment failure to a terminal used by the user.
[0021] In a possible implementation manner, the control device stores a mapping relationship between device information and user information; the processing module is configured to determine user information corresponding to the network element device according to the mapping relationship and the device information in the negotiation message.
[0022] In a fifth aspect, a network operation and maintenance device is provided. The device is applied to a network element device and includes:
[0023] A transceiver module, configured to perform operations related to reception and / or transmission performed by the network element device in the second aspect or any possible implementation manner of the second aspect;
[0024] A processing module, configured to perform other operations other than the operations related to reception and / or transmission performed by the network element device in the second aspect or any possible implementation manner of the second aspect.
[0025] In a possible implementation manner, the transceiver module includes a reception module and / or a transmission module. The reception module is configured to perform operations related to reception, and the transmission module is configured to perform operations related to transmission.
[0026] In a possible implementation, a transceiver module is configured to send a negotiation message to a control device. The negotiation message is used to establish a connection between a network element device and the control device. The negotiation message includes device information of the network element device. The device information is used by the control device to determine user information corresponding to the network element device. The user information indicates the user who operates and maintains the network element device, so that when the controller fails to establish a connection with the network element device based on the negotiation message, it sends the failure reason for the failed connection establishment to the terminal used by the user.
[0027] In a sixth aspect, a network operation and maintenance device is provided. The device is applied to a terminal, and the terminal is the terminal used by the user who operates and maintains the network element device. The device includes:
[0028] A transceiver module is configured to perform operations related to reception and / or transmission performed by the terminal in the third aspect or any possible implementation of the third aspect.
[0029] A processing module is configured to perform other operations other than the operations related to reception and / or transmission performed by the terminal in the third aspect or any possible implementation of the third aspect.
[0030] In a possible implementation, the transceiver module includes a reception module and / or a transmission module. The reception module is configured to perform operations related to reception, and the transmission module is configured to perform operations related to transmission.
[0031] In a possible implementation, the transceiver module is configured to receive the failure reason for the failed connection establishment sent by the control device when the connection establishment between the network element device and the control device fails.
[0032] In any possible implementation of the above fourth aspect to sixth aspect, the failure reason includes algorithm negotiation failure or certificate verification failure.
[0033] In any possible implementation of the above fourth aspect to sixth aspect, the negotiation message is the first message sent by the network element device to the control device during the process of establishing a connection between the network element device and the control device.
[0034] In any possible implementation of the above fourth aspect to sixth aspect, the negotiation message can be an SSH protocol version exchange message or a TLS handshake message. Optionally, if the SSH protocol version exchange message includes a comments field, the device information of the network element device can be carried in the comments field included in the SSH protocol version exchange message; or, if the SSH protocol version exchange message includes a data block field ending with CR and LF before the field starting with SSH, the device information of the network element device is carried in the data block field; or, if the TLS handshake message includes an extended definition field, the device information of the network element device is carried in the definition field.
[0035] In any possible implementation of the above fourth to sixth aspects, the device information includes at least one of the ESN or the MAC address.
[0036] In a seventh aspect, there is provided a device for network operation and maintenance. The device for network operation and maintenance includes: a processor, the processor is coupled to a memory, and at least one program instruction or code is stored in the memory. The at least one program instruction or code is loaded and executed by the processor so that the device for network operation and maintenance implements the method for network operation and maintenance according to any one of the first to third aspects above.
[0037] Optionally, the processor is one or more, and the memory is one or more.
[0038] Optionally, the memory may be integrated with the processor, or the memory is separately arranged from the processor.
[0039] In a specific implementation process, the memory may be a non-transitory memory, such as a read only memory (ROM). It may be integrated with the processor on the same chip, or may be separately arranged on different chips. The present application does not limit the type of the memory and the setting manner of the memory and the processor.
[0040] In a eighth aspect, there is provided a communication device. The device includes: a transceiver, a memory, and a processor. Among them, the transceiver, the memory, and the processor communicate with each other through an internal connection path. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals. And when the processor executes the instructions stored in the memory, the communication device executes the method according to the first aspect or any possible implementation manner of the first aspect, or executes the method according to the second aspect or any possible implementation manner of the second aspect, or executes the method according to the third aspect or any possible implementation manner of the third aspect.
[0041] In a ninth aspect, there is provided a network operation and maintenance system. The network operation and maintenance system includes a control device, a network element device, and a terminal;
[0042] The control device is used to execute the method according to the first aspect or any possible implementation manner of the first aspect. The network element device is used to execute the method according to the second aspect or any possible implementation manner of the second aspect. The terminal is used to execute the method according to the third aspect or any possible implementation manner of the third aspect.
[0043] In a tenth aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium and is loaded and executed by a processor to enable a computer to implement the method in the first aspect or any possible implementation manner of the first aspect, or to implement the method in the second aspect or any possible implementation manner of the second aspect, or to implement the method in the third aspect or any possible implementation manner of the third aspect.
[0044] In an eleventh aspect, a computer program (product) is provided. The computer program (product) includes computer program code which, when run on a computer, causes the computer to execute the methods in the above aspects.
[0045] In a twelfth aspect, a chip is provided, including a processor for calling and running instructions stored in a memory, so that a communication device equipped with the chip executes the methods in the above aspects.
[0046] In a thirteenth aspect, another chip is provided, including an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute code in the memory, and when the code is executed, the processor is configured to execute the methods in the above aspects.
[0047] It should be understood that for the beneficial effects achieved by the technical solutions and corresponding possible implementation manners in the fourth to thirteenth aspects of this application, reference may be made to the technical effects of the first to third aspects and their corresponding possible implementation manners above, and details are not elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 It is a schematic diagram of the networking of a campus network provided by an embodiment of this application;
[0049] Figure 2 It is a schematic diagram of a management system provided by an embodiment of this application;
[0050] Figure 3 It is an interaction schematic diagram of device onboarding provided by an embodiment of this application;
[0051] Figure 4 It is an interaction schematic diagram of a method for network operation and maintenance provided by an embodiment of this application;
[0052] Figure 5 It is a schematic diagram of a connection establishment process provided by an embodiment of this application;
[0053] Figure 6 It is a schematic structural diagram of a device for network operation and maintenance provided by an embodiment of this application;
[0054] Figure 7 This is a schematic structural diagram of a network device provided by an embodiment of the present application;
[0055] Figure 8 This is a schematic structural diagram of another network device provided by an embodiment of the present application. Detailed implementation manners
[0056] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0057] In the operation and maintenance application scenario of a campus network, due to the existence of a firewall or a network address translation (NAT) network, it is difficult for a control device to directly manage devices by planning Internet Protocol (IP) addresses. Instead, the devices need to actively connect to the control device using the callhome method. Moreover, most control devices in the campus network adopt a cloud-based management solution. For example, the control device is a controller such as a network control engine (NCE). The NCE divides the campus network into a three-level management system, and users at different levels have different permissions. The control device, as the administrator in the three-level management system, has the highest permission.
[0058] Among them, the campus network may refer to the network in a campus. Optionally, the campus includes, but is not limited to, a large campus composed of multiple buildings, a small campus composed of one building or one floor or several rooms in a building, etc. The network architecture of the campus network usually adopts a multi-layer network architecture. For example, it includes a tree-type network structure of an access layer network, an aggregation layer network, and a core layer network. The access layer network faces terminals and is used to connect the terminals in the campus to the network through wired or wireless connection methods. Usually, the access layer includes access switches. In the case where the terminal is a wireless terminal, the access layer switch may be a wireless access point (AP) device, and the AP device is used to connect the wireless terminal to the network.
[0059] The aggregation layer network is located between the access layer network and the core layer network and is used to forward packets within the campus network. Generally, the aggregation layer network includes aggregation switches. The core layer network is the core of campus data exchange. In addition to connecting to the aggregation layer network, it can also connect to other components of the campus network, such as the data center and the egress area of the campus network. Generally, the core layer network includes core switches. Thus, through the connection and communication with the aggregation layer network and the data center, the core layer network can achieve high-speed interconnection within the entire campus network; through the connection and communication with the aggregation layer network and the egress area, the core layer network can achieve high-speed interconnection between the campus network and the external network. Among them, the egress area of the campus network can include firewall (FW) devices and gateway devices of the campus, and the gateway device is, for example, a routing device, and the routing device is, for example, an access router (AR) device.
[0060] Exemplarily, refer to Figure 1 , Figure 1 which is a schematic diagram of the networking of a campus network provided by an embodiment of the present application. As Figure 1 shown, multiple campus networks such as campus network 1 to campus network N are connected to the control device through the Internet, and N is a positive integer greater than 2. The network architectures between different campus networks can be the same or different. Exemplarily, in campus network 1, the terminals are connected to the AP devices wirelessly, different AP devices are connected to the switch (SW) devices, the SW devices are connected to the AR devices, and the AR devices are connected to the control device through the network. Among them, the devices within any campus network need to actively establish a connection with the control device. After establishing a connection with the control device, that is, after the network element devices within the campus network are successfully online, the control device can manage the network element devices within the campus network.
[0061] Optionally, the control device may refer to control devices such as a controller or a control platform, such as NCE, etc., or it may be a part of the components on the control device, such as a single board or a line card on the control device, or it may be a functional module on the control device, or it may also be a chip for implementing the method of the embodiment of the present application. The present application does not make specific limitations. The network element devices within the campus network include but are not limited to the above-mentioned AP devices, SW devices, AR devices, or FW devices, etc. The terminals include but are not limited to general computer devices, tablet computers, or desktop computers, etc.
[0062] Taking the management of network element devices by the control device through a multi-service platform (MSP) as an example, refer to Figure 2 the schematic diagram of the management system shown, the control device manages multiple MSPs downward, Figure 2Taking MSP1 and MSP2 as examples, each MSP manages multiple users downward, and at least one network element device is maintained and operated under each user. Thus, through Figure 2 the management system shown, the control device maintains the association relationship between the users who maintain and operate the network element devices and the network element devices, that is, the mapping relationship between user information and device information. According to the mapping relationship between user information and device information, the control device can determine different users corresponding to the device information of different network element devices, and then can send operation and maintenance information related to the network element devices to the terminals used by the users. The operation and maintenance information may include the online status of the network element devices, etc. For example, if user 1 is used to maintain and operate network element device 1, the control device can send the operation and maintenance information related to network element device 1 to the terminal used by user 1. In the embodiments of the present application, the users who maintain and operate the network element devices may also refer to the users who lease the network element devices.
[0063] Refer to Figure 3 the interaction schematic diagram of the online of the network element device shown. First, the user needs to add a network element device to the control device, that is, register the device information of the network element device to the control device, so that the control device maintains the mapping relationship between the user information of the user and the device information of the network element device. Secondly, when the network element device officially accesses the network, it goes online through the registration center, that is, the network element device obtains the address information of the control device from the registration center and initiates a callhome connection to the control device based on the address information. After the callhome connection between the network element device and the control device is successfully established, that is, the network element device is successfully online, the control device starts to manage the network element device. Furthermore, the control device actively queries the device information of the network element device, and based on the device information returned by the network element device and the mapping relationship between the pre-registered user information and device information, determines the user corresponding to the network element device, so that the control device can associate the network element device and the user respectively to push the management information related to the network element device to the associated user.
[0064] However, since the control device starts to manage the network element device after the network element device goes online, the control device cannot manage the network element device during the online process. In other words, the control device can only manage the online network element devices, resulting in limited management capabilities for the network element devices. For the scenario where the callhome connection fails to be established, that is, the network element device fails to go online, since the control device has not started to manage the network element device, the control device cannot determine the user corresponding to the network element device, resulting in the user's ignorance of the reason for the connection failure of the network element device, and further resulting in the user's inability to take corresponding measures to improve the success rate of the network element device going online. Therefore, in the scenario where the connection between the network element device and the control device fails, how to handle the connection failure is an urgent problem to be solved.
[0065] An embodiment of the present application provides a method for network operation and maintenance. When the connection between a network element device and a control device fails, the control device can notify the user who operates and maintains the network element device of the reason for the connection failure. Taking the interaction between the control device, the network element device, and the terminal to execute this method as an example, see Figure 4 , Figure 4 which is an interaction schematic diagram of a method for network operation and maintenance provided by an embodiment of the present application. Among them, this method can be applied to the network architecture of the Figure 1 shown campus network. The control device can be the Figure 1 shown control device. The network element device can be the Figure 1 shown AP device, SW device, AR device, or FW device. The terminal can be the Figure 1 shown terminal. As Figure 4 shown, the method for network operation and maintenance includes the following steps 401-step 404.
[0066] Step 401, the network element device sends a negotiation message to the control device. The negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes the device information of the network element device.
[0067] In an embodiment of the present application, the network element device needs to establish a connection with the control device to complete the online operation of the network element device. Optionally, the connection can refer to a callhome connection initiated by the network element device to the control device. The types of callhome connections include, but are not limited to, network configuration protocol (NETCONF) connections or representational state transfer configuration protocol (RESTCONF) connections, etc. The embodiment of the present application does not limit the connection method.
[0068] Before the network element device sends a negotiation message to the control device, the network element device needs to obtain the address information of the control device. Exemplarily, taking the network element device in the embodiment of the present application as a newly factory-produced device or an empty-configured device as an example, the newly factory-produced device or the empty-configured device can adopt different zero touch provisioning (ZTP) startup methods to obtain the address information of the control device and automatically load the startup file. Among them, the startup file can include, but is not limited to, system software, configuration files, or patch files, etc. The startup methods include, but are not limited to, USB startup, dynamic host configuration protocol (DHCP) startup, or registration center startup, etc. A USB flash drive is the abbreviation of a universal serial bus (USB) flash drive.
[0069] Taking the case where the network element device starts with a registration center as an example, the network element device obtains the address information of the registration center through the preset information inside the network element device, and accesses the registration center based on the address information of the registration center; the corresponding relationship between the network element device and the control device is configured in the registration center, and the registration center determines the control device corresponding to the network element device according to the corresponding relationship between the network element device and the control device, and sends the address information of the control device to the network element device; the network element device initiates a connection to the control device according to the address information of the control device. The address information involved in the embodiments of the present application may include at least one of a uniform resource locator (URL) address, an IP address, or a port number.
[0070] After the network element device obtains the address information of the control device, the network element device establishes a connection by sending a negotiation message to the control device based on the address information of the control device. For different connection establishment methods, the negotiation message may refer to different messages for establishing a connection. Taking the connection as a NETCONF connection and the NETCONF connection process including an algorithm negotiation process as an example, the algorithm negotiation process needs to establish a secure channel based on a secure transmission protocol, that is, the network element device and the control device need to send negotiation messages to each other based on the secure transmission protocol to ensure the security and integrity of data transmission through the secure channel. Optionally, the secure transmission protocols supported by the algorithm negotiation process include but are not limited to the SSH protocol and the TLS protocol, etc.
[0071] When the secure transmission protocol is the SSH protocol, the negotiation message may refer to an SSH protocol version exchange message. In this case, since the network element device actively initiates a connection to the control device, the control device acts as an SSH client and the network element device acts as an SSH server. The network element device adds the device information of the network element device to the SSH protocol version exchange message sent to the control device. The embodiments of the present application do not limit the position where the device information of the network element device is added to the SSH protocol version exchange message.
[0072] According to the relevant introduction of the SSH protocol version exchange message in Section 4.2 of the Request for Comments (RFC) 4254, an identification string needs to be sent between the SSH server and the SSH client. The identification string corresponds to the SSH protocol version exchange message in the embodiments of this application. The format of the identification string is: SSH-protoversion-softwaversion SP comments CR LF, that is, it starts with SSH, and then successively includes the protoversion (protocol version) field, the softwaversion (software version) field, the SP (space) field, the comments field, and ends with CR and LF. Among them, the comments field is optional. If the comments field needs to be included, the SP field needs to separate the softwaversion field and the comments field. CR refers to a single carriage return, and LF refers to a single line feed. Therefore, the device information of the network element device can be added to the comments field of the SSH protocol version exchange message.
[0073] In addition, Section 4.2 of RFC4254 also introduces that other data blocks can be added before the identification string sent by the SSH server. Each data block ends with CR and LF, and each data block does not start with SSH. That is, the format of the SSH protocol version exchange message is: data block CR LF SSH-protoversion-softwaversion SP comments CRLF. Thus, when the SSH protocol version exchange message includes a data block field before the field starting with SSH and the data block field ends with CR and LF, the device information of the network element device can be added to the data block field.
[0074] In the case where the secure transmission protocol is the TLS protocol, the negotiation message can refer to the TLS handshake message. The device information of the network element device can be added to the TLS handshake message by defining an extension. That is, the TLS handshake message includes an extended definition field, and the device information of the network element device is added to the definition field.
[0075] Thus, through the above different methods, device information can be flexibly carried in the negotiation message, improving the feasibility of the negotiation message to carry device information. Optionally, regardless of the position where the device information of the network element device is carried in the negotiation message, the device information can be carried in the negotiation message in the form of a key-value pair. Among them, the key-value pair is used to indicate the mapping relationship between the key and the value, and one key corresponds to one value.
[0076] The embodiments of this application do not limit the content of the device information. The device information of the network element device can be used to distinguish different network element devices. Optionally, the device information may include at least one of the ESN or the MAC address. Thus, this method can be applicable to different representation forms of device information, making this method have high general applicability.
[0077] In a possible implementation manner, regardless of the connection establishment method adopted, the negotiation message can be the first message sent by the network element device to the control device during the process of establishing a connection between the network element device and the control device. So that the control device can obtain the device information after the first message sent by the network element device to the control device. Furthermore, for any connection failure scenario after the first message sent by the network element device to the control device, the control device can send the connection failure reason to the user, improving the comprehensiveness and accuracy of notifying the connection failure reason.
[0078] Step 402, the control device receives the negotiation message sent by the network element device, and determines the user information corresponding to the network element device according to the device information. The user information indicates the user who operates and maintains the network element device.
[0079] After the control device receives the negotiation message sent by the network element device, since the negotiation message includes the device information of the network element device, the control device can then determine the user information of the user who operates and maintains the network element device according to the device information. Thus, the control device can associate the network element device with the user before successfully establishing a connection with the network element device. Optionally, the user who operates and maintains the network element device may also refer to the user who rents the network element device.
[0080] In a possible implementation, the control device stores the mapping relationship between device information and user information. Exemplarily, before receiving the negotiation message sent by the network element device, the user who maintains the network element device registers the device information of the network element device with the control device, so that the control device can pre-maintain the mapping relationship between device information and user information. Furthermore, the method for determining the user information corresponding to the network element device according to the device information in the negotiation message can be to determine the user information corresponding to the network element device according to the mapping relationship and the device information in the negotiation message. By determining the user information corresponding to the network element device through the pre-obtained mapping relationship between device information and user information, the determination efficiency of the user information corresponding to the network element device is improved.
[0081] In the case where the control device does not include the mapping relationship between device information and user information, the control device can broadcast the device information of the network element device within each campus network. If the terminal used by the user who leases the network element device receives the device information of the network element device, the user information of the user who leases the network element device is returned to the control device. Thus, the control device can also determine the user information corresponding to the network element device according to the device information.
[0082] Step 403, when the control device fails to establish a connection with the network element device based on the negotiation message, the control device sends the failure reason for the failed connection establishment to the terminal used by the user.
[0083] In the embodiments of the present application, the control device continues to establish a connection with the network element device based on the negotiation message. The connection establishment process may include multiple processes such as an algorithm negotiation process and a certificate authentication process. If there are no problems in the entire connection establishment process, the connection between the network element device and the control device is successfully established. On the contrary, if any process in the connection establishment process has a problem, the connection between the network element device and the control device fails to be established.
[0084] Taking the connection establishment process including an algorithm negotiation process and a certificate authentication process as an example, the failure reason for the failed connection establishment can be an algorithm negotiation failure or a certificate verification failure. Thus, for the scenario where the network element device and the control device need to successfully establish a connection by negotiating keys through algorithms and having consistent certificate verification, since both the algorithm negotiation and the certificate verification occur after determining the user information corresponding to the network element device, if the connection establishment fails due to an algorithm negotiation failure or a certificate verification failure, the control device can promptly notify the user of the failure reason so that the user can take effective measures to solve the problem of algorithm negotiation failure or certificate verification failure.
[0085] In the embodiment of the present application, the terminal used by the user is connected to the control device, so that the control device can send the failure reason for the connection establishment failure to the terminal used by the user. Optionally, the terminal used by the user and the control device can be directly connected or connected through a network device, and the network device is a device that has successfully established a connection with the control device. For example, before the network element device maintained by the user starts to establish a connection with the control device, the terminal used by the user successfully establishes a connection with the control device through an online method, so that the control device includes the user information of the user, and further the control device can determine the terminal used by the user according to the user information.
[0086] After determining the terminal used by the user, if the terminal used by the user is directly connected to the control device, the control device directly sends the failure reason for the connection establishment failure to the terminal used by the user; if the terminal used by the user is connected to the control device through a network device, the control device sends the failure reason for the connection establishment failure to the terminal used by the user based on the network device.
[0087] Step 404, the terminal receives the failure reason for the connection establishment failure sent by the control device.
[0088] Thus, in the case where the connection establishment between the network element device and the control device fails, the terminal can receive the failure reason for the connection establishment failure sent by the control device, so that the user can take effective measures in time according to the connection failure reason to solve the connection failure problem, and the success rate of the network element device connection is improved. Optionally, if the terminal used by the user is directly connected to the control device, the terminal used by the user directly receives the failure reason for the connection establishment failure sent by the control device; if the terminal used by the user is connected to the control device through at least one network element device, the terminal used by the user receives the failure reason for the connection establishment failure sent by the control device based on the network device.
[0089] Exemplarily, refer to Figure 5Schematic diagram of the connection establishment process shown. First, the network element device is started and connected to the network. The network element device can automatically obtain the address information of the control device from the registration center; the network element device initiates a connection to the control device; the control device, as an SSH client, sends an SSH protocol version exchange message or a TLS handshake message to the network element device. The network element device, as an SSH server, returns an SSH protocol version exchange message or a TLS handshake message to the control device. The SSH protocol version exchange message or the TLS handshake message includes the device information of the network element device; after receiving the SSH protocol version exchange message or the TLS handshake message, the control device saves the device information of the network element device and associates the network element device with the user in advance, that is, determines the user information corresponding to the network element device according to the correspondence between the device information and the user information; if the authentication fails during the authentication process between the network element device and the control device, it is determined that the connection establishment fails due to inconsistent certificate verification, saves the failure reason for the connection establishment failure, and the control device sends the failure reason to the terminal used by the user. Figure 5 is schematically shown by sending the failure reason to the user; if the authentication is successful during the authentication process between the network element device and the control device, an SSH channel or a TLS session is successfully established.
[0090] In this method, the network element device carries the device information of the network element device in the negotiation message sent to the control device, so that the control device can determine the user who maintains the network element device according to the device information before the connection is successfully established. Furthermore, in the case of a connection establishment failure, the control device can send the failure reason for the connection establishment failure to the terminal used by the user. Thus, the user can perceive the failure reason for the network element device to establish a connection, and then the user can take effective measures in time according to the connection failure reason to solve the connection failure problem, improving the success rate of establishing a connection between the network element device and the control device.
[0091] The method of network operation and maintenance in the embodiments of the present application is introduced above. Corresponding to the above method, the embodiments of the present application also provide a device for network operation and maintenance. Figure 6 It is a schematic structural diagram of a device for network operation and maintenance provided by an embodiment of the present application. This device can be applied to Figure 1 or Figure 4 the control device, network element device or terminal shown. Based on Figure 6 the following multiple modules shown, this Figure 6 shown device for network operation and maintenance can implement Figure 4 all or part of the operations of the method shown. It should be understood that this device may include more additional modules than the modules shown or omit some of the modules shown. The embodiments of the present application do not limit this. As Figure 6 shown, this device includes a transceiver module 601 and a processing module 602.
[0092] A transceiver module 601, configured to perform Figure 4 the receiving and / or sending related operations performed by the control device in the method shown, or configured to perform Figure 4 the receiving and / or sending related operations performed by the network element device in the method shown, or configured to perform Figure 4 the receiving and / or sending related operations performed by the terminal in the method shown;
[0093] A processing module 602, configured to perform Figure 4 other operations except the receiving and / or sending related operations performed by the control device in the method shown, or configured to perform Figure 4 other operations except the receiving and / or sending related operations performed by the network element device in the method shown, or configured to perform Figure 4 other operations except the receiving and / or sending related operations performed by the terminal in the method shown.
[0094] In a possible implementation, the transceiver module 601 includes a receiving module and / or a sending module. The receiving module is configured to perform receiving related operations, and the sending module is configured to perform sending related operations.
[0095] In Figure 6 the case where the network operation and maintenance device shown is applied to a control device, the transceiver module 601 is configured to receive a negotiation message sent by a network element device, the negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes device information of the network element device; the processing module 602 is configured to determine user information corresponding to the network element device according to the device information, and the user information indicates the user who maintains the network element device; the transceiver module 601 is further configured to, in the case of a failure to establish a connection with the network element device based on the negotiation message, send the reason for the connection establishment failure to the terminal used by the user.
[0096] In a possible implementation, the control device stores a mapping relationship between device information and user information; the processing module 602 is configured to determine user information corresponding to the network element device according to the mapping relationship and the device information in the negotiation message.
[0097] In Figure 6 the case where the network operation and maintenance device shown is applied to a network element device, the transceiver module 601 is configured to send a negotiation message to a control device, the negotiation message is used to establish a connection between the network element device and the control device, the negotiation message includes device information of the network element device, and the device information is used for the control device to determine user information corresponding to the network element device according to the device information, and the user information indicates the user who maintains the network element device, so that when the controller fails to establish a connection with the network element device based on the negotiation message, the reason for the connection establishment failure is sent to the terminal used by the user.
[0098] When Figure 6 the device for network operation and maintenance shown is applied to a terminal, the transceiver module 601 is configured to receive, when the connection establishment between the network element device and the control device fails, the failure reason for the connection establishment failure sent by the control device.
[0099] In a possible implementation manner, the failure reason includes algorithm negotiation failure or certificate verification failure.
[0100] In a possible implementation manner, the negotiation message is the first message sent by the network element device to the control device during the process of establishing a connection between the network element device and the control device.
[0101] In a possible implementation manner, the negotiation message can be an SSH protocol version exchange message or a TLS handshake message. Optionally, if the SSH protocol version exchange message includes a comments field, the device information of the network element device can be carried in the comments field included in the SSH protocol version exchange message; or, if the SSH protocol version exchange message includes a data block field ending with CR and LF before the field starting with SSH, the device information of the network element device is carried in the data block field; or, if the TLS handshake message includes an extended definition field, the device information of the network element device is carried in the definition field.
[0102] In a possible implementation manner, the device information includes at least one of ESN or MAC address.
[0103] It should be understood that when Figure 7 the above-provided device realizes its functions, only the division of the above function modules is used for illustration. In actual application, the above functions can be allocated to different function modules according to needs, that is, the internal structure of the device is divided into different function modules to complete all or part of the functions described above. In addition, the device provided in the above embodiment and the method embodiment belong to the same concept. For the specific implementation process, please refer to the method embodiment, which will not be elaborated here. Figure 7 For the beneficial effects of the provided device, please refer to Figure 4 the beneficial effects of the method shown, which will not be elaborated here.
[0104] Refer to Figure 7 , Figure 7 which shows a schematic structural diagram of a network device 2000 provided by an exemplary embodiment of the present application. Figure 7 The network device 2000 shown is used to perform the operations involved in the above Figure 4 shown network operation and maintenance method. The network device 2000 is, for example, a switch, a router, etc., and the network device 2000 can be implemented by a general bus architecture.
[0105] As Figure 7 shown, the network device 2000 includes at least one processor 2001, a memory 2003, and at least one communication interface 2004.
[0106] The processor 2001 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of this application. For example, the processor 2001 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute various logic blocks, modules, and circuits described in connection with the disclosed content of the embodiments of the present invention. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on.
[0107] Optionally, the network device 2000 further includes a bus. The bus is used to transfer information between the components of the network device 2000. The bus can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 7 only one line is shown in, but it does not mean that there is only one bus or one type of bus.
[0108] The memory 2003 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, such as a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, such as an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2003 is, for example, standalone and connected to the processor 2001 via a bus. The memory 2003 can also be integrated with the processor 2001.
[0109] The communication interface 2004 uses any device such as a transceiver for communicating with other devices or communication networks, which can be an Ethernet, a radio access network (RAN) or a wireless local area network (WLAN), etc. The communication interface 2004 can include a wired communication interface and can also include a wireless communication interface. Specifically, the communication interface 2004 can be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface or a combination thereof. In the embodiments of the present application, the communication interface 2004 can be used for the network device 2000 to communicate with other devices.
[0110] In a specific implementation, as an embodiment, the processor 2001 can include one or more CPUs, such as Figure 7CPU0 and CPU1 shown in []. Each of these processors can be a single-core CPU or a multi-core CPU. Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0111] In a specific implementation, as an example, network device 2000 may include multiple processors, such as Figure 7 processor 2001 and processor 2005 shown in []. Each of these processors can be a single-core CPU or a multi-core CPU. Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0112] In a specific implementation, as an example, network device 2000 may also include an output device and an input device. The output device communicates with processor 2001 and can display information in various ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device communicates with processor 2001 and can receive user input in various ways. For example, the input device can be a mouse, a keyboard, a touch screen device, or a sensing device, etc.
[0113] In some embodiments, memory 2003 is used to store program code 2010 for executing the solution of this application, and processor 2001 can execute the program code 2010 stored in memory 2003. That is, network device 2000 can implement the network operation and maintenance method provided by the method embodiment through processor 2001 and program code 2010 in memory 2003. The program code 2010 may include one or more software modules. Optionally, processor 2001 itself can also store the program code or instructions for executing the solution of this application.
[0114] In a specific embodiment, network device 2000 of the embodiment of this application can correspond to the control device in each of the above method embodiments. The processor 2001 in network device 2000 reads the instructions in memory 2003, so that Figure 7 the network device 2000 shown can perform all or part of the operations performed by the control device.
[0115] Specifically, the processor 2001 is configured to receive a negotiation message sent by a network element device. The negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes device information of the network element device. The processor 2001 is further configured to determine user information corresponding to the network element device according to the device information, where the user information indicates the user who maintains the network element device. In the case where the connection establishment with the device fails based on the negotiation message, the processor 2001 is configured to send the failure reason for the connection establishment failure to the terminal used by the user.
[0116] For other optional implementation manners, for the sake of brevity, they will not be elaborated here.
[0117] For another example, the network device 2000 in the embodiments of the present application may correspond to the network element device in each of the above method embodiments. The processor 2001 in the network device 2000 reads the instructions in the memory 2003, so that Figure 7 the network device 2000 shown is capable of performing all or part of the operations performed by the network element device.
[0118] Specifically, the processor 2001 is configured to send a negotiation message to the control device. The negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes device information of the network element device. The device information is used for the control device to determine user information corresponding to the network element device according to the device information, where the user information indicates the user who maintains the network element device, so that when the connection establishment between the controller and the network element device fails based on the negotiation message, the controller sends the failure reason for the connection establishment failure to the terminal used by the user.
[0119] For other optional implementation manners, for the sake of brevity, they will not be elaborated here.
[0120] For another example, the network device 2000 in the embodiments of the present application may correspond to the terminal in each of the above method embodiments. The processor 2001 in the network device 2000 reads the instructions in the memory 2003, so that Figure 7 the network device 2000 shown is capable of performing all or part of the operations performed by the terminal.
[0121] Specifically, the processor 2001 is configured to receive the failure reason for the connection establishment failure sent by the control device in the case where the connection establishment between the network element device and the control device fails.
[0122] For other optional implementation manners, for the sake of brevity, they will not be elaborated here.
[0123] The network device 2000 may also correspond to the Figure 6 network operation and maintenance device shown above. Each functional module in the network operation and maintenance device is implemented by software of the network device 2000. In other words, the functional modules included in the network operation and maintenance device are generated after the processor 2001 of the network device 2000 reads the program code 2010 stored in the memory 2003.
[0124] Among them, Figure 4 Each step of the network operation and maintenance method shown is completed by the integrated logic circuit of the hardware in the processor of the network device 2000 or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware processor, or executed and completed by the combination of the hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.
[0125] Refer to Figure 8 , Figure 8 which shows a schematic structural diagram of a network device 2100 provided by another exemplary embodiment of the present application. Figure 8 The network device 2100 shown is used to execute all or part of the operations involved in the above Figure 4 shown network operation and maintenance method. The network device 2100 is, for example, a switch, a router, etc., and the network device 2100 can be implemented by a general bus architecture.
[0126] As Figure 8 shown, the network device 2100 includes: a main control board 2110 and an interface board 2130.
[0127] The main control board is also called a main processing unit (MPU) or a route processor card. The main control board 2110 is used for the control and management of each component in the network device 2100, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 2110 includes: a central processor 2111 and a memory 2112.
[0128] The interface board 2130 is also referred to as a line processing unit (LPU), a linecard, or a service board. The interface board 2130 is used to provide various service interfaces and implement the forwarding of data packets. The service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc. The Ethernet interface is, for example, a Flexible Ethernet Clients (FlexE Clients). The interface board 2130 includes: a central processing unit 2131, a network processor 2132, a forwarding table entry memory 2134, and a physical interface card (PIC) 2133.
[0129] The central processing unit 2131 on the interface board 2130 is used to control and manage the interface board 2130 and communicate with the central processing unit 2111 on the main control board 2110.
[0130] The network processor 2132 is used to implement the forwarding processing of packets. The form of the network processor 2132 can be a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented by an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 2132 is used to forward the received packets based on the forwarding table stored in the forwarding table entry memory 2134. If the destination address of the packet is the address of the network device 2100, the packet is sent to the CPU (such as the central processing unit 2131) for processing; if the destination address of the packet is not the address of the network device 2100, the next hop and the outgoing interface corresponding to the destination address are found from the forwarding table according to the destination address, and the packet is forwarded to the outgoing interface corresponding to the destination address. Among them, the processing of the upstream packets can include: the processing of the packet incoming interface, the forwarding table lookup; the processing of the downstream packets can include: the forwarding table lookup, etc. In some embodiments, the central processing unit can also perform the function of the forwarding chip, such as implementing software forwarding based on a general CPU, so that there is no need for a forwarding chip in the interface board.
[0131] The physical interface card 2133 is used to implement the docking function at the physical layer. The original traffic enters the interface board 2130 from here, and the processed packets are sent out from this physical interface card 2133. The physical interface card 2133, also known as a daughter card, can be installed on the interface board 2130. It is responsible for converting optical and electrical signals into packets, performing a legality check on the packets, and then forwarding them to the network processor 2132 for processing. In some embodiments, the central processor 2131 can also execute the functions of the network processor 2132. For example, software forwarding is implemented based on a general-purpose CPU, so the network processor 2132 is not required in the physical interface card 2133.
[0132] Optionally, the network device 2100 includes multiple interface boards. For example, the network device 2100 further includes an interface board 2140. The interface board 2140 includes: a central processor 2141, a network processor 2142, a forwarding table entry memory 2144, and a physical interface card 2143. The functions and implementation manners of the components in the interface board 2140 are the same as or similar to those of the interface board 2130, and will not be elaborated here.
[0133] Optionally, the network device 2100 further includes a switching fabric board 2120. The switching fabric board 2120 can also be referred to as a switch fabric unit (SFU). In the case where the network device 2100 has multiple interface boards, the switching fabric board 2120 is used to complete data exchange between the interface boards. For example, the interface board 2130 and the interface board 2140 can communicate through the switching fabric board 2120.
[0134] The main control board 2110 is coupled to the interface boards. For example. The main control board 2110, the interface board 2130, the interface board 2140, and the switching fabric board 2120 are interconnected through a system bus and a system backplane. In a possible implementation manner, an inter-process communication (IPC) channel is established between the main control board 2110 and the interface board 2130 and the interface board 2140, and the main control board 2110 communicates with the interface board 2130 and the interface board 2140 through the IPC channel.
[0135] Logically, the network device 2100 includes a control plane and a forwarding plane. The control plane includes a main control board 2110 and a central processing unit 2111. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 2134, a physical interface card 2133, and a network processor 2132. The control plane executes functions such as acting as a router, generating a forwarding table, processing signaling and protocol messages, configuring and maintaining the status of the network device, etc. The control plane sends the generated forwarding table to the forwarding plane. In the forwarding plane, the network processor 2132 looks up and forwards the messages received by the physical interface card 2133 based on the forwarding table sent by the control plane. The forwarding table sent by the control plane can be stored in the forwarding table entry memory 2134. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.
[0136] It is worth noting that there may be one or more main control boards. When there are multiple main control boards, they may include an active main control board and a standby main control board. There may be one or more interface boards. The stronger the data processing capacity of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching fabric board, or there may be one or more switching fabric boards. When there are multiple switching fabric boards, they can jointly achieve load sharing and redundant backup. In a centralized forwarding architecture, the network device may not require a switching fabric board, and the interface board undertakes the processing function of the service data of the entire system. In a distributed forwarding architecture, the network device may have at least one switching fabric board, and data exchange between multiple interface boards is achieved through the switching fabric board, providing a large-capacity data exchange and processing capacity. Therefore, the data access and processing capabilities of network devices with a distributed architecture are greater than those of network devices with a centralized architecture. Optionally, the form of the network device can also be a single board, that is, without a switching fabric board, and the functions of the interface board and the main control board are integrated on this single board. At this time, the central processing units on the interface board and the main control board can be combined into one central processing unit on this single board to execute the functions after superposition. The data exchange and processing capabilities of this form of network device are relatively low (for example, network devices such as low-end switches or routers). Which architecture to specifically adopt depends on the specific networking deployment scenario, and no specific limitation is made here.
[0137] In a specific embodiment, the network device 2100 corresponds to the Figure 6 network operation and maintenance device shown above. In some embodiments, Figure 6 the transceiver module 601 in the network operation and maintenance device shown above is equivalent to the physical interface card 2133 in the network device 2100, and the processing module 602 is equivalent to the central processing unit 2111 or the network processor 2132 in the network device 2100.
[0138] An embodiment of the present application further provides a device for network operation and maintenance. The device for network operation and maintenance includes: a processor, the processor is coupled to a memory, and at least one program instruction or code is stored in the memory. The at least one program instruction or code is loaded and executed by the processor so that the device for network operation and maintenance implements Figure 4 the method shown. The device for network operation and maintenance may be Figure 7 the network device 2000 shown or Figure 8 the network device 2100 shown.
[0139] An embodiment of the present application further provides a system for network operation and maintenance. The system for network operation and maintenance includes: a control device, a network element device, and a terminal. For example, the control device is Figure 7 the network device 2000 shown or Figure 8 the network device 2100 shown, the network element device is Figure 7 the network device 2000 shown or Figure 8 the network device 2100 shown, and the terminal is Figure 7 the network device 2000 shown. The method for network operation and maintenance executed by the control device, the network element device, and the terminal can refer to the relevant descriptions of the above Figure 4 shown embodiment, and will not be elaborated here.
[0140] An embodiment of the present application further provides a communication device. The device includes: a transceiver, a memory, and a processor. Among them, the transceiver, the memory, and the processor communicate with each other through an internal connection path. The memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals. And when the processor executes the instructions stored in the memory, the processor executes Figure 4 the method that needs to be executed in the shown embodiment.
[0141] It should be understood that the above-mentioned processor may be a CPU, or may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the advanced RISC machines (ARM) architecture.
[0142] Further, in an alternative embodiment, the above-mentioned memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.
[0143] The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0144] The embodiments of the present application also provide a computer-readable storage medium, in which at least one instruction is stored, and the instruction is loaded and executed by a processor to enable a computer to implement any one of the above network operation and maintenance methods.
[0145] The embodiments of the present application also provide a computer program (product), when the computer program is executed by a computer, it may cause the processor or the computer to execute the corresponding steps and / or processes in the above method embodiments.
[0146] The embodiments of the present application also provide a chip, including a processor, which is used to call and run the instructions stored in the memory from the memory, so that a communication device installed with the chip executes any one of the above network operation and maintenance methods.
[0147] Another chip provided by an embodiment of the present application includes: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute the code in the memory. When the code is executed, the processor is configured to execute the method for network operation and maintenance as described in any of the foregoing.
[0148] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, a data center, etc. that includes one or more integrated available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk).
[0149] Those of ordinary skill in the art can realize that, in combination with the method steps and modules described in the embodiments disclosed herein, they can be implemented by software, hardware, firmware, or any combination thereof. To clearly illustrate the interchangeability of hardware and software, the steps and components of the embodiments have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0150] Those of ordinary skill in the art can understand that all or part of the steps for implementing the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk, an optical disc, etc.
[0151] When implemented using software, it may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the methods of the embodiments of the present application may be described in the context of machine-executable instructions, such as program modules executed in devices included in a target real or virtual processor. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In various embodiments, the functions of the program modules may be combined or split among the described program modules. The machine-executable instructions for the program modules may be executed within a local or distributed device. In a distributed device, the program modules may be located in both local and remote storage media.
[0152] The computer program code for implementing the methods of the embodiments of the present application may be written in one or more programming languages. These computer program codes may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program code is executed by the computer or other programmable data processing device, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code may be executed entirely on the computer, partially on the computer, as a stand-alone software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.
[0153] In the context of the embodiments of the present application, the computer program code or related data may be carried by any suitable carrier so that the device, apparatus, or processor can perform the various processes and operations described above. Examples of the carrier include signals, computer-readable media, and the like.
[0154] Examples of signals may include electrical, optical, radio, acoustic, or other forms of propagating signals, such as carrier waves, infrared signals, etc.
[0155] A machine-readable medium may be any tangible medium that contains or stores a program for or related to an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More detailed examples of machine-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0156] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0157] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed couplings, direct couplings, or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or modules, and can also be in electrical, mechanical, or other forms of connection.
[0158] The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they can be located in one place, or can be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present application. In addition, in each embodiment of the present application, the functional modules can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules.
[0159] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0160] In this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions. It should be understood that there is no logical or chronological dependency between "first", "second", and "nth", nor is the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various examples, the first image can be called the second image, and similarly, the second image can be called the first image. Both the first image and the second image can be images, and in some cases, they can be separate and different images.
[0161] It should also be understood that in various embodiments of this application, the magnitude of the serial numbers of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not impose any limitation on the implementation process of the embodiments of this application.
[0162] In this application, the meaning of the term "at least one" refers to one or more, and the meaning of the term "multiple" refers to two or more. For example, multiple second messages refer to two or more second messages. In this text, the terms "system" and "network" are often used interchangeably.
[0163] It should be understood that the terms used in the description of various examples herein are only for describing specific examples and are not intended to be limiting. As used in the description of various examples and the appended claims, the singular forms "a", "an", and "the" are also intended to include the plural forms unless the context clearly indicates otherwise.
[0164] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items. The term "and / or" is a relational term describing the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this application generally represents an "or" relationship between the associated objects before and after.
[0165] It should also be understood that the term "comprises" (also known as "includes", "including", "comprises", and / or "comprising") when used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups.
[0166] It should also be understood that the terms "if" and "when" can be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined that..." or "if [the stated condition or event] is detected" can be interpreted to mean "when it is determined that..." or "in response to determining..." or "when [the stated condition or event] is detected" or "in response to detecting [the stated condition or event]".
[0167] It should be understood that determining B based on A does not mean determining B solely based on A. B can also be determined based on A and / or other information.
[0168] It should also be understood that the "one embodiment", "an embodiment", and "a possible implementation" mentioned throughout the specification mean that the specific features, structures, or characteristics related to the embodiment or implementation are included in at least one embodiment of the present application. Therefore, the "in one embodiment" or "in an embodiment", "a possible implementation" that appear throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures, or characteristics can be combined in one or more embodiments in any suitable manner.
[0169] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall be included within the protection scope of the present application.
Claims
1. A method for network operation and maintenance, characterized in that, The method is applied to a control device, and the method includes: Receiving a negotiation message sent by a network element device, where the negotiation message is used to establish a connection between the network element device and the control device, and the negotiation message includes device information of the network element device; Determining user information corresponding to the network element device according to the device information, where the user information indicates a user who operates and maintains the network element device; In the case that the connection with the network element device cannot be established based on the negotiation message, sending a failure reason for the failed connection establishment to a terminal used by the user.
2. The method according to claim 1, wherein The control device stores a mapping relationship between device information and user information; the determining user information corresponding to the network element device according to the device information in the negotiation message includes: Determining user information corresponding to the network element device according to the mapping relationship and the device information in the negotiation message.
3. A method for network operation and maintenance, characterized in that, The method is applied to a network element device, and the method includes: Sending a negotiation message to a control device, where the negotiation message is used to establish a connection between the network element device and the control device, the negotiation message includes device information of the network element device, and the device information is used for the control device to determine user information corresponding to the network element device according to the device information, where the user information indicates a user who operates and maintains the network element device, so that when the controller fails to establish a connection with the network element device based on the negotiation message, the controller sends a failure reason for the failed connection establishment to a terminal used by the user.
4. A method for network operation and maintenance, characterized in that, The method is applied to a terminal, where the terminal is a terminal used by a user who operates and maintains a network element device, and the method includes: In the case that the connection between the network element device and the control device fails to be established, receiving a failure reason for the failed connection establishment sent by the control device.
5. The method according to any one of claims 1-4, characterized in that The failure reason includes algorithm negotiation failure or certificate verification failure.
6. The method according to any one of claims 1-5, characterized in that The negotiation message is the first message sent by the network element device to the control device during the process of establishing a connection between the network element device and the control device.
7. The method according to any one of claims 1-6, characterized in that The negotiation message is a Secure Shell (SSH) protocol version exchange message, and the SSH protocol version exchange message includes a comments field, and the device information of the network element device is carried in the comments field.
8. The method according to any one of claims 1-6, characterized in that, The negotiation message is a Secure Shell (SSH) protocol version exchange message, and the SSH protocol version exchange message includes a data block field ending with CR and LF before a field starting with SSH, and the device information of the network element device is carried in the data block field.
9. The method according to any one of claims 1-6, characterized in that, The negotiation message is a Transport Layer Security (TLS) handshake message, and the TLS handshake message includes an extended definition field, and the device information of the network element device is carried in the definition field.
10. The method according to any one of claims 1-9, characterized in that The device information includes at least one of an Electronic Serial Number (ESN) or a Media Access Control (MAC) address.
11. A device for network operation and maintenance, characterized in that, The device includes: A transceiver module, configured to perform receiving and / or transmitting related operations that are performed by the control device in any one of the methods recited in claims 1, 2, 5-10, or configured to perform receiving and / or transmitting related operations that are performed by the network element device in any one of the methods recited in claims 3, 5-10, or configured to perform receiving and / or transmitting related operations that are performed by the terminal in any one of the methods recited in claims 4-10; A processing module, configured to perform other operations than the receiving and / or transmitting related operations that are performed by the control device in any one of the methods recited in claims 1, 2, 5-10, or configured to perform other operations than the receiving and / or transmitting related operations that are performed by the network element device in any one of the methods recited in claims 3, 5-10, or configured to perform other operations than the receiving and / or transmitting related operations that are performed by the terminal in any one of the methods recited in claims 4-10.
12. A device for network operation and maintenance, characterized in that, The device for network operation and maintenance includes: a processor, the processor is coupled to a memory, and at least one program instruction or code is stored in the memory, and the at least one program instruction or code is loaded and executed by the processor, so that the device for network operation and maintenance implements the network operation and maintenance method recited in any one of claims 1, 2, 5-10, or so that the device for network operation and maintenance implements the network operation and maintenance method recited in any one of claims 3, 5-10, or so that the device for network operation and maintenance implements the network operation and maintenance method recited in any one of claims 4-10.
13. A system for network operation and maintenance, characterized in that, The network operation and maintenance system includes a control device, a network element device, and a terminal; The control device is configured to perform the network operation and maintenance method recited in any one of claims 1, 2, 5-10, the network element device is configured to perform the network operation and maintenance method recited in any one of claims 3, 5-10, and the terminal is configured to perform the network operation and maintenance method recited in any one of claims 4-10.
14. A computer-readable storage medium, characterized in that, At least one instruction is stored in the computer storage medium, and the at least one instruction is loaded and executed by a processor, so that the computer implements the network operation and maintenance method recited in any one of claims 1-10.
15. A computer program product, characterized in that, The computer program product includes: computer program code, and the computer program code is loaded and executed by a computer, so that the computer implements the network operation and maintenance method recited in any one of claims 1-10.