Stateless lightweight cross-target range network control method and system

By adding range gateway elements to the cross-range network topology and using boundary gateways for point-to-point exchange and encapsulation of traffic, the complex problem of the existing technology mid-to-cross-range network connection solution is solved, and simplified network deployment and efficient traffic management are achieved.

CN120281697AActive Publication Date: 2025-07-08SAINING WANGAN
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510781562.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-07-08
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

The existing cross-range network connection solution has high requirements for the basic network, complex processes, difficult coordination, and network adjustments are prone to unavailability, complex adaptation of the joint management center, and difficult development.

Method used

Adding the range gateway elements to the cross-range network topology, implementing point-to-point switching at the IP layer through the boundary gateway, encapsulating and decapsulating cross-range traffic, using private protocols for communication, and simplifying network connection configuration.

Benefits of technology

It reduces network deployment and maintenance costs, simplifies network construction processes, improves traffic security, reduces the coordination complexity of the joint management center, and is easy to maintain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281697A_ABST
    Figure CN120281697A_ABST
Patent Text Reader

Abstract

The invention discloses a stateless lightweight cross-target range network control method and a stateless lightweight cross-target range network control system. According to the invention, the configuration of cross-target range network connection is realized by adding target range gateway elements in the topology, wherein one target range gateway element is configured for each cross-target range network connection in each sub-target range scene; when the cross-target-range scene is started, the unique id of each element of the local topology is reported to the linkage management center after each sub-target-range network is constructed; the united management center issues a triple data record containing local and opposite end cross-target range port unique id and an opposite end boundary gateway IP address to a boundary gateway of a sub-target range; generating a corresponding record locally by the border gateway according to the received triple data, starting to monitor at a specified port, and packaging the monitored message content and the unique id of the cross-target port of the opposite end together for sending; and the opposite-end target range boundary gateway carries out de-encapsulation and forwarding. According to the invention, the realization difficulty of cross-target flow intercommunication can be reduced, and the cross-target scene maintenance convenience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a stateless lightweight cross-range network control method and system, belonging to the technical field of network security. Background Art

[0002] In the network range product, due to the limited equipment of a single station, there is a need to integrate the ranges in multiple locations into one range. The core of this need is to connect the networks of each sub-range. In the cross-range experimental scenario, a joint management center is usually set up to distribute and coordinate key network resources such as IP addresses and network topology of each range. At present, the cross-range network connection solution mainly relies on VLAN and VXLAN technology to connect the network, which has the following problems: 1. The use of VLAN technology requires that the network between sub-ranges be connected at the second layer; VXLAN is a virtual network, which requires that the network equipment of the ranges in various places have virtual network controllers, and the physical network across the range generally needs to cross regions and be geographically far apart. These two network solutions place high requirements on the basic network between ranges. 2. Using the network technology stack to achieve cross-range communication, each creation of a cross-range scenario is a small network cutover. Due to the long geographical distance, once there is a problem in the process, coordination and troubleshooting are difficult and time-consuming. 3. VLAN and VXLAN are both general network technologies. There is no business information of sub-target ranges. The joint management center needs to build an additional layer of management data for the target range and VLAN ID and coordinate the process, which makes development and joint debugging difficult. 4. When building the network, the joint management center needs to adapt to the local network environment of each sub-target range, such as virtual network controllers, switches, etc. The inconsistency of the network controller process protocols of each sub-target range will increase the adaptation complexity of the joint management center. 5. If the basic network needs to be adjusted, when performing network cutover, all network devices involved in the cross-target range network cutover need to have special configuration changes, which involves a large scope and may make the network unavailable after the cutover.

[0003] In summary, the types of networks managed by the Joint Management Center are diverse, and the ways of connecting networks are complicated. It is necessary to wait for and coordinate the network systems of each shooting range to ensure dynamic network interconnection when the scene is started. Given the complex and changing requirements of each station for network forms, the process arrangement of the Joint Management Center is also extremely complex. Therefore, it is urgent to introduce a stateless lightweight network control solution to realize the network connection function and effectively reduce the process complexity of the Joint Management Center. Summary of the invention

[0004] Purpose of the invention: In view of the problems existing in the above-mentioned prior art, the purpose of the present invention is to provide a stateless lightweight cross-range network control method and a cross-range network system, so as to reduce the difficulty of implementing cross-range traffic interconnection and improve the convenience of cross-range scenario maintenance.

[0005] Technical solution: To achieve the above-mentioned invention objectives, the present invention adopts the following technical solutions: In the first aspect, the present invention provides a stateless lightweight cross-range network control method, including the following steps: Configure the cross-range network connection by adding range gateway elements to the cross-range network topology, where one range gateway element is configured for each cross-range network connection in each sub-range scenario, and each range gateway element is connected to a cross-range port in the sub-range scenario and a range gateway element in the peer sub-range scenario; When the cross-range scenario starts, after each sub-range network is constructed, report the unique IDs of all elements in the local topology to the joint management center; The joint management center issues a triple data record containing the unique ID of the local cross-range port, the unique ID of the peer cross-range port, and the IP address of the peer border gateway to the border gateway of the sub-range; The border gateway generates corresponding records locally according to the received triple data, starts listening on the specified port, and encapsulates the content of the listened packet together with the unique ID of the peer cross-range port and sends it; After receiving the encapsulated data, the border gateway of the peer range performs decapsulation, obtains the unique ID of the cross-range port therein, and forwards the packet content to the corresponding port entity.

[0006] Preferably, the border gateways of each sub-range are applications deployed on any host in the virtual platform. This application forwards the traffic between sub-ranges by starting child processes, and opens and disconnects the cross-range network connection by creating and destroying child processes.

[0007] Preferably, when the network is constructed in the scenario, each sub-range starts a blank virtual machine instance under the network of the configured cross-range connection. This virtual machine instance is specified to be created on the host where the border gateway is located. After the virtual machine instance starts, its network card serves as the corresponding border gateway network card, and this network card will serve as the local cross-range port; after the network construction is completed, each sub-range reports all elements in the scenario topology to the joint management center, including the unique ID of the cross-range port.

[0008] Preferably, the border gateway finds the corresponding network card on the host according to the unique ID of the local cross-range port issued by the joint management center, starts a child process to listen for traffic, and re-encapsulates and sends the traffic.

[0009] Furthermore, when the cross-range scenario is destroyed, the joint management center issues a destruction instruction containing the unique ID of the local cross-range port in the triple to the border gateway. After receiving the destruction instruction, the border gateway stops the corresponding listening child process and deletes the corresponding triple record.

[0010] Preferably, the border gateway encapsulates the message in a custom format, directly encapsulating the communication information between sub-ranges in the message. When encapsulating the second and third layers of the network, the IP address of the peer border gateway is used for encapsulation. The fourth layer is a private cross-range protocol, including a network port identifier and a message segmentation identifier; the network port identifier is generated by converting the unique ID of the peer cross-range port; the message segmentation identifier is used to mark whether the message is segmented, the segmentation sequence, and the segmentation ID.

[0011] Preferably, the message is segmented at most once. In the message segmentation identifier, the bit indicating whether it is segmented occupies 1 bit, and the segmentation sequence occupies 1 bit.

[0012] In a second aspect, the present invention provides a cross-range network system, including at least two sub-ranges, each sub-range deploying a virtual platform; a joint management center, communicatively connected to each sub-range, for coordinating cross-range network resources; the sub-range includes a border gateway; the joint management center stores a cross-range network topology, and realizes the configuration of cross-range network connection by adding a range gateway element to the cross-range network topology, where one range gateway element is configured for each cross-range network connection in each sub-range scenario, and each range gateway element connects a cross-range port in the sub-range scenario and a range gateway element in the peer sub-range scenario; when the cross-range scenario is started, the joint management center and the border gateway of the sub-range perform the following steps: After the network construction of each sub-range is completed, report the unique ID of each element of the local topology to the joint management center; The joint management center issues a triple data record including the unique ID of the local cross-range port, the unique ID of the peer cross-range port, and the IP address of the peer border gateway to the border gateway of the sub-range; The border gateway generates a corresponding record locally according to the received triple data, and starts listening on the specified port, encapsulating the content of the listened message together with the unique ID of the peer cross-range port and sending it; The border gateway of the peer range unpacks the encapsulated data after receiving it, obtains the unique ID of the cross-range port therein, and forwards the message content to the corresponding port entity.

[0013] Further, when the cross-range scenario is destroyed, the joint management center and the border gateway of the sub-range perform the following steps: The joint management center issues an instruction to the border gateway to destroy the unique ID of the local cross-range port in the triple. After receiving the destruction instruction, the border gateway stops the corresponding listening sub-process and deletes the corresponding triple record.

[0014] Preferably, between the sub-ranges that need to realize cross-range network connection, only the border gateways need to communicate at the IP layer.

[0015] Beneficial effects: Through the configuration of the boundary gateways of the sub-ranges, the cross-range traffic is re-encapsulated by the boundary gateways and exchanged point-to-point, without the need to configure any changes to the network devices in the original sub-ranges, reducing the network deployment and maintenance costs. Compared with the prior art, the present invention has the following advantages: 1. Only three-layer network intercommunication of the boundary gateways is required between the sub-ranges. The communication topology between the sub-ranges is simple, with low requirements for basic network devices. Each time a scenario is created, the basic network is not adjusted, which is easy to maintain. 2. The cross-range network traffic can be redirected through the management network or the signaling network. When changes are made to the basic network, there is no need to adjust the network for cross-range traffic, reducing the complexity of network deployment and cutover. 3. The network connection between the sub-ranges relies on a standard program of the boundary gateway to forward traffic, without the need to adapt various routers, switches or SDN devices for network orchestration, reducing the adaptation workload. 4. When creating and destroying cross-range scenarios, only the data in the boundary gateway needs to be synchronized for creation and deletion. The boundary gateway is not aware of the topology and does not need to be aware of the status of other devices, reducing the complexity of the joint management center coordinating the networks of the sub-ranges. 5. The cross-range process can communicate using a private protocol, and even if the traffic is captured, it cannot be parsed, improving the security of the traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a schematic diagram of a cross-range network topology editing according to an embodiment of the present invention.

[0017] Figure 2 It is a schematic diagram of the implementation of a cross-range scenario networking according to an embodiment of the present invention.

[0018] Figure 3 It is a schematic diagram of the boundary gateway message encapsulation according to an embodiment of the present invention.

[0019] Figure 4 It is another schematic diagram of a cross-range network topology editing according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the accompanying drawings and specific embodiments.

[0021] The embodiment of the present invention discloses a stateless lightweight cross-range network control method, which realizes the configuration of cross-range network connection by adding a range gateway element to the cross-range network topology, wherein a range gateway element is configured for each cross-range network connection in each sub-range scenario, and each range gateway element connects a cross-range port in the sub-range scenario and a range gateway element in the opposite sub-range scenario. When the cross-range scenario is started, after each sub-range network is constructed, the unique ID of each element of the local topology is reported to the joint management center; the joint management center sends a triple data record containing the local cross-range port unique ID, the opposite cross-range port unique ID and the opposite border gateway IP address to the border gateway of the sub-range; the border gateway generates a corresponding record locally according to the received triple data, and starts to listen at the designated port, encapsulates the intercepted message content and the opposite cross-range port unique ID together and sends it; the opposite range border gateway decapsulates the encapsulated data after receiving it, obtains the cross-range port unique ID therein, and forwards the message content to the corresponding port entity.

[0022] Specifically, the border gateway of each sub-shooting range is an application deployed on any host machine of the virtual platform. The application forwards the traffic between sub-shooting ranges by starting sub-processes, and opens and disconnects the cross-shooting range network connection by creating and destroying sub-processes.

[0023] The stateless lightweight cross-range network control method described in the embodiment of the present invention only relies on the border gateway of each sub-range to reverse the business data. The border gateway of each sub-range has an independent operation status, and there is no need to record the status of other border gateways, and there is no topology concept. Any party does not need to notify the gateways of each sub-range when cutting over or even destroying the network, which reduces the requirements for the bearer network and simplifies the network construction process.

[0024] Figure 1 The diagram shows a cross-range network topology diagram of two sub-ranges. When building the network topology of the two sub-ranges, you need to drag the range gateway element to the network topology, configure which range and scene the range gateway leads to (for example, the range gateway of range 1-scene A leads to range 2-scene B), and each range gateway needs a point-to-point connection with the peer range gateway. Finally, the network to which the range gateway needs to connect (the network directly connected to the border gateway) is marked by the connection line. After the topology editing is completed, Figure 1 shown.

[0025] Figure 1 The networking implementation of the cross-range scenario shown is as follows Figure 2As shown in the figure. A border gateway is set up in the sub-range. In this embodiment, the border gateway is a continuously running application, which is deployed on any host of the virtual platform (such as an OpenStack cluster) so as to load any virtual network of the local range at any time. The business traffic of the ranges is exchanged between each other through the border gateway, and the three-layer interconnection of the border gateways between each sub-range is sufficient. The joint management center needs to communicate directly with the border gateway in order to issue interconnection instructions.

[0026] The execution process after the scenario is started includes the following steps: Step S1, the network construction process creates other elements except the border gateway. Specifically, the construction of each node and network in each sub-range scenario is the prior art and will not be elaborated here. It should be particularly noted that a network directly connected to the border gateway needs to be created, and the elements (such as switches and routers) directly connected to the border gateway in the scenario topology are added to this network.

[0027] Step S2, for each cross-range network connection, a network card listened by the border gateway needs to be created during the network construction process, denoted as the border gateway network card. The specific creation process is as follows: Taking OpenStack as an example, first create a cross-range port port: openstack port create --network <gateway_net> <gateway_port>. After creation, a 36-bit gateway_port_uuid will be returned. Then, a blank virtual machine instance is specified on the host where the border gateway is located to start the network card: openstack server create --flavor m1.nano --image cirros --nic port-id = <gateway_port_uuid> --availability-zone nova:compute01 gateway_blank_vm. In the above instructions, gateway_net is the network directly connected to the border gateway generated when constructing the network topology elements in Step S1, gateway_port is the network card provided for the border gateway of the range to listen, and gateway_port_uuid is the unique id of the local cross-range port.

[0028] Step S3, after the completion of the above steps S1 and S2, each sub-range will report the information of each element in the range to the joint management center, including the 36-bit gateway_port_uuid created in the above step S2. The joint management center will identify the uuid as a cross-range port and start the process of opening up the network between the sub-ranges, which is as follows: The joint management center sends the three metadata as a record to the border gateway of the sub-range. The specific triplet data is: local cross-range port uuid, peer cross-range port uuid, and peer border gateway IP address.

[0029] Step S4: The range border gateway receives the data sent by the joint management center and generates a corresponding record locally.

[0030] Step S5, the range border gateway obtains a network card named tap<the first 11 bits of the local cross-range port uuid> on its host machine, creates a child process to start listening to the traffic sent by the corresponding port of the network card, and encapsulates the intercepted message content and the opposite cross-range port uuid together and sends it out.

[0031] Step S6, the target range border gateway at the opposite end decapsulates the encapsulated data after receiving it, obtains the cross-target range port uuid therein and finds the corresponding port entity, and sends the message to be sent to the corresponding port entity.

[0032] The above steps S4 to S6 describe the network communication process in one direction, and the network communication process in the reverse direction is similar.

[0033] When the scene is destroyed, the joint management center sends a destruction instruction to the border gateway. The instruction only needs to include the local cross-range port uuid. After receiving the destruction instruction, the border gateway stops the listening subprocess of the above step S5 and deletes the record created in the above step S4.

[0034] Figure 3 The border gateway encapsulation message format is illustrated. When encapsulating the second and third layer networks, the IP address of the peer border gateway is used for encapsulation, and the protocol field value of the IP header is set to 200. When the peer border gateway receives a message with an IP header protocol value of 200, it uses the following message format for four-layer decapsulation.

[0035] The fourth layer is a private protocol, which is divided into two segments: a) The first segment is the network port identifier: convert the 36-bit uuid of the peer cross-range port into a 128-bit binary number. b) The second segment is the packet segmentation identifier: Since the cross-range service data itself conforms to the constraint of the maximum transmission unit (MTU), the outer encapsulation will cause the packet length to exceed the MTU, and the exceeded part is only the data of the second, third, and fourth layers. Therefore, only one packet segmentation is required. The packet segmentation identifier is divided into three segments: The segmentation flag bit being 0 indicates no segmentation, and the data can be directly forwarded. The segmentation flag being 1 indicates that segmentation is required. Packets with the same segmentation id are the same packet and need to be arranged and assembled according to the segmentation sequence.

[0036] Figure 4 Fig. shows a cross-range network topology of three sub-ranges. For the case of three or more sub-ranges, it is similar to the case of the above two sub-ranges. The scenarios within each range need to be individually dragged to the border gateway of the peer range scenario. For example, the cross-range network connection from Range 1 - Scenario A to Range 2 - Scenario B is configured through a range gateway element, and the cross-range network connection to Range 3 - Scenario C is configured through another range gateway element. When the scenario is started, the creation process of each border gateway is independent. For each creation process, it is not aware of the topology. They independently configure the local border gateway according to the user's configuration, reducing the difficulty of network construction and maintenance. Different range gateway elements within the same range scenario in the network topology can share a border gateway application. Different cross-range network connections create different border gateway network cards and corresponding listening and forwarding subprocesses to implement.

[0037] Based on the same inventive concept, an embodiment of the present invention also discloses a cross-range network system, including at least two sub-ranges, each sub-range is deployed with a virtual platform; a joint management center, communicatively connected to each sub-range, for coordinating cross-range network resources; the sub-range includes a border gateway; the joint management center stores a cross-range network topology, and configures cross-range network connections by adding range gateway elements to the cross-range network topology, where one range gateway element is configured for each cross-range network connection in each sub-range scenario, and each range gateway element connects a cross-range port in the sub-range scenario and a range gateway element in the peer sub-range scenario; when the cross-range scenario is started, the joint management center and the border gateway of the sub-range perform the following steps: After the network construction of each sub-range is completed, report the unique id of each element of the local topology to the joint management center; The joint management center issues a triple data record including the unique id of the local cross-range port, the unique id of the peer cross-range port, and the IP address of the peer border gateway to the border gateway of the sub-range; The border gateway generates corresponding records locally based on the received triple data, starts listening on the specified port, and sends the content of the listened packet encapsulated with the unique ID of the cross-range port of the peer end. After receiving the encapsulated data, the border gateway of the peer range performs decapsulation, obtains the unique ID of the cross-range port therein, and forwards the packet content to the corresponding port entity.

[0038] When the cross-range scenario is destroyed, the border gateways of the joint management center and the sub-ranges perform the following steps: The joint management center issues a destruction instruction to the border gateway that includes the unique ID of the local cross-range port in the triple. After receiving the destruction instruction, the border gateway stops the corresponding listening subprocess and deletes the corresponding triple record.

[0039] In the cross-range network system of this embodiment, between the sub-ranges that need to implement cross-range network connection, only the border gateways need to communicate at the IP layer.

Claims

1. A stateless lightweight cross-range network control method, characterized in that, The steps include: The configuration of the cross-range network connection is realized by adding a range gateway element to the cross-range network topology, wherein a range gateway element is configured for each cross-range network connection in each sub-range scenario, and each range gateway element connects a cross-range port in the sub-range scenario and a range gateway element in the opposite sub-range scenario; When the cross-range scenario is started, each sub-range network will report the unique ID of each element of the local topology to the joint management center after the network is built; The joint management center sends a triple data record containing the local cross-range port unique ID, the peer cross-range port unique ID and the peer border gateway IP address to the border gateway of the sub-range; The border gateway generates a corresponding record locally based on the received triplet data, and starts to listen at the specified port, encapsulating the intercepted message content and the unique ID of the peer cross-range port together and sending it; After receiving the encapsulated data, the border gateway of the other end range decapsulates it, obtains the unique ID of the cross-range port, and forwards the message content to the corresponding port entity.

2. The stateless lightweight cross-range network control method according to claim 1, characterized in that, The border gateway of each sub-range is an application deployed on any host machine of the virtual platform. The application forwards the traffic between sub-ranges by starting sub-processes and opens and closes the cross-range network connection by creating and destroying sub-processes.

3. A stateless lightweight cross-range network control method according to claim 2, characterized in that When the network is constructed, each sub-range starts a blank virtual machine instance under the configured cross-range connection network. The virtual machine instance is created on the host where the border gateway is located. When the virtual machine instance is started, its network card will be used as the corresponding border gateway network card, and the network card will be used as the local cross-range port. After the network is built, each sub-range will report each element in the scene topology to the joint management center, including the unique ID of the cross-range port.

4. A stateless lightweight cross-range network control method according to claim 1, characterized in that The border gateway finds the corresponding network card on the host machine based on the local cross-range port unique ID issued by the joint management center, starts a subprocess to monitor the traffic, and re-encapsulates the traffic before sending it out.

5. A stateless lightweight cross-range network control method according to claim 1, characterized in that When the cross-range scenario is destroyed, the joint management center sends a destruction instruction to the border gateway containing the unique ID of the local cross-range port in the triplet. After receiving the destruction instruction, the border gateway stops the corresponding listening subprocess and deletes the corresponding triplet record.

6. A stateless lightweight cross-range network control method according to claim 1, characterized in that The border gateway encapsulates the message in a custom format, and directly encapsulates the communication information between the sub-ranges in the message. When encapsulating the second and third layer networks, the IP address of the peer border gateway is used for encapsulation. The fourth layer is a private cross-range protocol, including a network port identifier and a message segmentation identifier; the network port identifier is generated by converting the unique ID of the cross-range port on the opposite end; the message segmentation identifier is used to mark whether the message is segmented, the segmentation sequence and the segmentation ID.

7. A stateless lightweight cross-range network control method according to claim 6, characterized in that The message is segmented at most once, and the segmentation flag of the message occupies 1 bit to indicate whether the message is segmented, and the segmentation sequence occupies 1 bit.

8. A cross-range network system, including at least two sub-ranges, each sub-range is deployed with a virtual platform; a joint management center, communicatively connected to each sub-range for coordinating cross-range network resources; characterized in that, The said sub-range includes a border gateway; the joint management center stores a cross-range network topology, and realizes the configuration of cross-range network connection by adding range gateway elements to the cross-range network topology. One range gateway element is configured for each cross-range network connection in each sub-range scenario. Each range gateway element connects a cross-range port in the sub-range scenario to a range gateway element in the peer sub-range scenario; when starting the cross-range scenario, the joint management center and the border gateway of the sub-range execute the following steps: After the network construction of each sub-range is completed, report the unique IDs of all elements of the local topology to the joint management center; The joint management center issues a triple data record including the unique ID of the local cross-range port, the unique ID of the peer cross-range port, and the IP address of the peer border gateway to the border gateway of the sub-range; The border gateway generates a corresponding record locally according to the received triple data, starts listening on the specified port, and encapsulates the content of the listened packet with the unique ID of the peer cross-range port and sends it; After receiving the encapsulated data, the border gateway of the peer range performs decapsulation, obtains the unique ID of the cross-range port therein, and forwards the packet content to the corresponding port entity.

9. The cross-range network system according to claim 8, wherein When destroying the cross-range scenario, the joint management center and the border gateway of the sub-range execute the following steps: the joint management center issues a destruction instruction including the unique ID of the local cross-range port in the triple to the border gateway. After receiving the destruction instruction, the border gateway stops the corresponding listening subprocess and deletes the corresponding triple record.

10. A cross-range network system according to claim 8, wherein, Between sub-ranges that need to implement cross-range network connection, only the border gateways need to communicate at the IP layer.

Citation Information

Patent Citations

  • Data synchronization method, device and equipment based on federated target range and storage medium

    CN116319835A

  • Target range cascading method, device and system and storage medium

    CN117035277A

  • Multi-network range collaborative data transmission method, device, equipment and medium

    CN117811840A

  • Cross-region multi-target-range real equipment networking method and system

    CN119094481A

  • Scalable emulated cyber range environment

    US20230168646A1