Message forwarding method, message sending method, control method and related devices
By adding APN-ID to the application message and combining control policies, the access control management problem caused by the increase in the number of terminal devices and applications in the IP network is solved, and a more simplified access control management is achieved.
Patent Information
- Application Number
- CN202410088874.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-22
- Publication Date
- 2025-07-22
AI Technical Summary
In existing IP networks, with the increase in the number of terminal devices and applications, the number of five-tuples that the gateway needs to maintain increases rapidly, resulting in a greatly increasing difficulty in managing access control, especially when application relationships change, maintenance work is complicated and difficult.
By adding application-aware network identifiers (APN-IDs) to the application message, combining control strategies, determining the correspondence between source applications and destination applications, and adopting a coarse-grained control method to reduce the impact on changes in the number of terminal devices, number of applications and communication relationships.
The impact of changes in the number of terminal devices in the network, the number of applications on the terminal devices, and the changes in communication relationships between application groups on the access control maintenance work, and simplifies management difficulty.
Smart Images

Figure CN120358285A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method for forwarding packets, a method for sending packets, a control method, and related devices. Background Art
[0002] With the continuous emergence of new business fields, such as the Internet of Things, artificial intelligence, and big data analysis, enterprises usually need to develop more applications (such as enterprise internal business applications, client applications, mobile applications, cloud applications, etc.) to support and meet the growing business needs. As the number of applications increases, the business access scenarios between different applications become more complex and diverse.
[0003] For example, in the express payment scenario in the financial field: The user pre-binds a bank card or a payment account on a certain payment software (payment application A1), thereby determining the settlement banks available to the user on the UnionPay platform (such as Bank B1, Bank B2, Bank B3). When the user uses application A1 for express payment, it accesses the UnionPay platform through an Internet interface. After determining that the target bank is Bank B1 from all available settlement banks on the UnionPay platform, the UnionPay platform accesses the bank application C1 of Bank B1 for fund settlement. It can be seen from the above scenario that when there are multiple available settlement banks, there can be multiple combinations to achieve express payment, such as payment application A1 accessing bank application C1 of Bank B1, payment application A1 accessing bank application C2 of Bank B2, payment application A1 accessing bank application C3 of Bank B3, etc. Once the user unbinds the bank card or binds a new bank card, it will cause the available settlement banks to change, and thus cause the access relationship between payment application A1 and the bank application to change. Therefore, complex and changeable application access scenarios need to be supported in the express payment scenario.
[0004] In the existing IP network, the gateway controls the access between applications by means of an access control list (ACL) + five-tuple (source IP address, destination IP address, source port number, destination port number, transport protocol). Assuming that the above payment application A1 is installed on the user's terminal device A10, and the bank application C1 is installed on the computing device C10 of Bank BI, only by adding (the IP address of A10, the IP address of C10, the port number of A1 on A10, the port number of C1 on C10, TCP) to the ACL of the gateway can the access of payment application A1 to bank application C1 be achieved.
[0005] If new payment applications (such as payment application A2 and payment application A3) are installed on the terminal device A10, or the number of optional settlement banks increases, or the number of terminal devices installed with payment application A1 increases, quintuples corresponding to the newly added payment applications / bank applications / terminal devices need to be added to the ACL of the gateway to enable business access between different applications. Therefore, as the scale of the IP network expands and the number of applications accessing the IP network increases, the number of quintuples that the gateway needs to maintain is getting larger and larger, and the management difficulty is also increasing.
[0006] Application-aware networking (APN) can provide more refined network services based on applications, but it still lacks support for business access scenarios between different applications. Summary of the Invention
[0007] This application provides a method for forwarding packets, a method for sending packets, a control method, and related devices, which can reduce the maintenance difficulty of access control when at least one of the factors such as the number of terminal devices in the network, the number of applications on the terminal devices, and the communication relationships between multiple applications changes.
[0008] In a first aspect, this application provides a method for forwarding packets. The method includes: a network device receives an application packet, where the application packet includes a first application-aware network identifier APN-ID and a second APN-ID. Among them, the first APN-ID includes an identifier of a first application group that generates the application packet, and the second APN-ID includes an identifier of a second application group to which the application packet is to be accessed; the network device sends the above application packet to a device where the second application group is located based on a first control policy, where the first control policy includes a correspondence between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0009] In the above solution, by adding a second APN-ID to the application packet to specify the application group to be accessed, the network device can identify that the application group to be accessed is the second application group, and then can process the application packet according to the correspondence between the first application group and the second application group in the first control policy, thereby supporting business access scenarios between different application groups.
[0010] It can be seen that, compared with setting the access relationship between the source application and the destination application on two specific devices by means of ACL + five-tuple, in this technical solution, the APN-IDs of the source application and the destination application are marked on the application message, and in combination with the control policy based on the corresponding relationship between the source application and the destination application, the processing method for the application message can be determined. There is no need to restrict the device where the source application is located and the device where the destination application is located in the control policy. Therefore, this technical solution controls the application message with a coarser granularity, thereby reducing the impact caused by factors such as changes in the number of terminal devices in the network, changes in the number of application groups on the terminal device, and changes in the communication relationship between application groups on the maintenance work of access control.
[0011] In some possible implementation manners, the above-mentioned first application group and second application group are the same application group, or the first application group and the second application group are different application groups.
[0012] In some possible implementation manners, the above-mentioned first control policy includes the corresponding relationship between the source application identifier set and the destination application identifier set, and the first control policy is used to indicate that the application group indicated by any identifier in the source application identifier set is allowed to access the application group indicated by any identifier in the destination application identifier set, where the source application identifier set contains the identifier used to indicate the above-mentioned first application group, and the destination application identifier set contains the identifier used to indicate the above-mentioned second application group.
[0013] In some possible implementation manners, the identifiers in the source application identifier set and the identifiers in the destination application identifier set include at least one of the following two implementation manners: In the first implementation manner, the APN-ID is used as the identifier in the source application identifier set and the identifier in the destination application identifier set; in the second implementation manner, the identifier of the application group is used as the identifier in the source application identifier set and the identifier in the destination application identifier set.
[0014] In the above solution, multiple implementation manners of the identifiers in the source application identifier set and the identifiers in the destination application identifier set are provided. Therefore, it is possible to flexibly select a suitable implementation manner according to user requirements, so that the first control policy can be applied to different application scenarios.
[0015] In some possible implementation manners, the foregoing application message is an IPv6 message. If the application message includes an APN header, carrying the foregoing second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried by the Intent field in the APN header; in the second implementation manner, the second APN-ID is carried by the Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried by the APP-Group-ID field in the APN-ID field in the APN header.
[0016] In the foregoing solution, multiple implementation manners for carrying the second APN-ID are provided. Therefore, a suitable implementation manner can be flexibly selected according to user requirements, so that the application message carrying the first APN-ID and the second APN-ID can be applicable to different application scenarios.
[0017] In some possible implementation manners, the Flags field in the foregoing APN header is used to indicate that the access mode is a cross-application group access mode.
[0018] In the foregoing solution, by using the Flags field in the APN header of the application message, the network device can quickly identify the access mode after receiving the application message, thereby improving the recognition speed and processing speed of the application message.
[0019] In some possible implementation manners, the foregoing first APN-ID further includes the identifier of the first user group of the first application group, and the foregoing second APN-ID further includes the identifier of the second user group of the second application group.
[0020] The foregoing network device sends the foregoing application message to the device where the second application group is located based on the first control policy, including: the foregoing network device sends the foregoing application message to the device where the second application group of the second user group is located based on the first control policy and the second control policy; wherein, the second control policy includes the corresponding relationship between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0021] In the foregoing solution, by adding the second APN-ID to the application message to indicate the application to be accessed, the network device can identify that the application to be accessed is the second user group using the second application group, and further can process the application message according to the corresponding relationship between the first application group and the second application group in the first control policy, and the corresponding relationship between the first user group and the second user group in the second control policy, thereby supporting the service access scenario between different application groups.
[0022] It can be seen that, compared with the method of setting the access relationship between the source application and the destination application through ACL + five-tuple, this technical solution performs the same processing on application packets with the same first APN-ID and the same second APN-ID based on the corresponding relationship between the source application and the destination application, that is, it does not limit the devices where the source application is located and the devices where the destination application is located. Therefore, this technical solution controls application packets with a coarser granularity, thereby reducing the impact of factors such as changes in the number of terminal devices in the network, changes in the number of applications on terminal devices, and changes in the communication relationships between applications on the maintenance work of access control.
[0023] In some possible implementation manners, the second control policy includes the corresponding relationship between the source user identity set and the destination user identity set, and the second control policy is used to indicate that the user group indicated by any identity in the source user identity set is allowed to access the user group indicated by any identity in the destination user identity set, where the source user identity set includes the identity used to indicate the first user group, and the destination user identity set includes the identity used to indicate the second user group.
[0024] In some possible implementation manners, before the network device receives the application packet, the method further includes: the network device receives the first control policy sent by the management device.
[0025] In some possible implementation manners, the network device includes one or more of a gateway, a firewall, a router, a switch, and a load balancer.
[0026] In a second aspect, the present application provides a method for sending a packet, the method includes: a terminal device generates an application packet, the application packet includes a first Application Perception Network Identifier (APN-ID) and a second APN-ID, where the first APN-ID includes the identifier of the first application group that generates the application packet, and the second APN-ID includes the identifier of the second application group that the application packet is to access; the terminal device sends the application packet to a network device, and the first APN-ID and the second APN-ID in the application packet are used for the network device to send the application packet to the device where the second application group is located based on the first control policy, where the first control policy includes the corresponding relationship between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0027] In the above solution, by carrying the first APN-ID in the application message, the application group initiating the access can be specified, and by carrying the second APN-ID in the application message, the application group to be accessed can be specified, so that the network device can identify that the application group initiating the access is the first application group and the application group to be accessed is the second application group, and can send the application message to the device where the second application group is located based on the first control policy.
[0028] In some possible implementation manners, the above first control policy includes the correspondence between the source application identifier set and the destination application identifier set, and the first control policy is used to indicate that any application group indicated by an identifier in the source application identifier set is allowed to access any application group indicated by an identifier in the destination application identifier set, where the source application identifier set includes the identifier used to indicate the above first application group, and the destination application identifier set includes the identifier used to indicate the above second application group.
[0029] In some possible implementation manners, the above application message is an IPv6 message, and the application message includes an APN header. Then, carrying the above second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried through the Intent field in the APN header; in the second implementation manner, the second APN-ID is carried through the Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried through the APP-Group-ID field in the APN-ID field in the APN header.
[0030] In some possible implementation manners, the Flags field in the above APN header is used to indicate that the access mode is a cross-application-group access mode.
[0031] In some possible implementation manners, the above first APN-ID further includes the identifier of the first user group using the above first application group, and the above second APN-ID further includes the identifier of the second user group using the above second application group. The identifiers of the first user group and the second user group are used for the network device to send the above application message to the device where the second application group of the second user group is located based on the second control policy. The second control policy includes the correspondence between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0032] In some possible implementations, the second control policy includes the correspondence between the source user identifier set and the destination user identifier set, and the second control policy is used to indicate that the user group indicated by any identifier in the source user identifier set is allowed to access the user group indicated by any identifier in the destination user identifier set, where the source user identifier set includes the identifier for indicating the first user group, and the destination user identifier set includes the identifier for indicating the second user group.
[0033] Optionally, it may also be that the computing device generates the above application message and sends the above application message to the above network device.
[0034] In a third aspect, the present application provides a control method, which includes: a management device generates a control policy, the control policy includes the correspondence between a first application group and a second application group, and the control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0035] In the above solution, by determining the correspondence between two application groups in the control policy for forwarding application messages, the network device can, after receiving the control policy, process the application messages according to the correspondence between the two application groups in the control policy, thereby supporting the service access scenarios between different application groups.
[0036] It can be seen that, compared with the method of generating a control policy through ACL + five-tuple, the control policy in this technical solution can perform the same processing on application messages with the same information of the first application group and the same information of the second application group, that is, it does not limit the device where the source application is located and the device where the destination application is located. Therefore, the control policy in this technical solution has a coarser granularity. Adopting the control policy in this technical solution can avoid the impact on the maintenance work of access control caused by changes in the number of terminal devices in the network, and can also reduce the impact on the maintenance work of access control caused by factors such as changes in the number of application groups on terminal devices and changes in the communication relationship between application groups.
[0037] In some possible implementations, the control policy includes the correspondence between the source application identifier set and the destination application identifier set, and the control policy is used to indicate that the application group indicated by any identifier in the source application identifier set is allowed to access the application group indicated by any identifier in the destination application identifier set, where the source application identifier set includes the identifier for indicating the first application group, and the destination application identifier set includes the identifier for indicating the second application group.
[0038] In some possible implementations, the method further includes: the management device sends the control policy to the network device so that the network device forwards the message based on the control policy.
[0039] In some possible implementations, the above method further includes: the above management device sending the above control policy to the network controller.
[0040] In a fourth aspect, the present application provides a method for forwarding packets, the method including: a network device receiving an application packet, the application packet including a first Application Perception Network Identifier (APN-ID) and a second APN-ID, where the first APN-ID includes an identifier of a first user group that generates the application packet, and the second APN-ID includes an identifier of a second user group to which the application packet is to be accessed; the network device sending the above application packet to a device where the second user group is located based on a control policy, where the control policy includes a correspondence between the first user group and the second user group, and the control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0041] In the above solution, by adding the second APN-ID to the application packet to specify the user group to be accessed, the network device can identify that the user group to be accessed is the second user group, and then can process the application packet according to the correspondence between the first user group and the second user group in the control policy, thereby supporting service access scenarios between different user groups.
[0042] It can be seen that, compared with the method of setting the access relationship between the source user and the destination user through ACL + five-tuple, the present technical solution performs the same processing on application packets with the same first APN-ID and the same second APN-ID based on the correspondence between the source user and the destination user, that is, it does not limit the devices where the source user is located and the devices where the destination user is located. Therefore, the present technical solution controls application packets with a coarser granularity, thereby reducing the impact of factors such as changes in the number of terminal devices in the network, changes in the number of user groups on terminal devices, and changes in the communication relationship between user groups on the maintenance work of access control.
[0043] In some possible implementations, the above control policy includes a correspondence between a source user identifier set and a destination user identifier set, and the above control policy is used to indicate that any user group indicated by an identifier in the source user identifier set is allowed to access any user group indicated by an identifier in the destination user identifier set, where the source user identifier set includes an identifier for indicating the above first user group, and the destination user identifier set includes an identifier for indicating the above second user group.
[0044] In some possible implementation manners, the above application message is an IPv6 message. If the application message includes an APN header, carrying the above second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried by the Intent field in the APN header; in the second implementation manner, the second APN-ID is carried by the Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried by the APP-Group-ID field in the APN-ID field in the APN header.
[0045] In some possible implementation manners, the Flags field in the above APN header is used to indicate that the access mode is a cross-user group access mode.
[0046] In a fifth aspect, the present application provides a forwarding message device, which includes: a receiving unit and a sending unit. The receiving unit is configured to receive an application message, where the application message includes a first Application Perception Network Identifier (APN-ID) and a second APN-ID. The first APN-ID includes the identifier of the first application group that generates the application message, and the second APN-ID includes the identifier of the second application group to which the application message is to be accessed. The sending unit is configured to send the above application message to the device where the second application group is located based on a first control policy. The first control policy includes the corresponding relationship between the first application group and the second application group, and is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0047] In some possible implementation manners, the above first application group and the second application group are the same application group, or the first application group and the second application group are different application groups.
[0048] In some possible implementation manners, the above first control policy includes the corresponding relationship between the source application identifier set and the destination application identifier set, and is used to indicate that any application group indicated by an identifier in the source application identifier set is allowed to access any application group indicated by an identifier in the destination application identifier set. The source application identifier set contains the identifier used to indicate the above first application group, and the destination application identifier set contains the identifier used to indicate the above second application group.
[0049] In some possible implementation manners, the identifiers in the above source application identifier set and the identifiers in the destination application identifier set include at least one of the following two implementation manners: In the first implementation manner, the APN-ID is used as the identifier in the source application identifier set and the identifier in the destination application identifier set; in the second implementation manner, the identifier of the application group is used as the identifier in the source application identifier set and the identifier in the destination application identifier set.
[0050] In some possible implementation manners, the above application message is an IPv6 message. If the application message includes an APN header, carrying the above second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried through the Intent field in the APN header; in the second implementation manner, the second APN-ID is carried through the Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried through the APP-Group-ID field in the APN-ID field in the APN header.
[0051] In some possible implementation manners, the Flags field in the above APN header is used to indicate that the access mode is a cross-application group access mode.
[0052] In some possible implementation manners, the above first APN-ID further includes the identifier of the first user group of the above first application group, the above second APN-ID further includes the identifier of the second user group of the above second application group, and the above sending unit is specifically configured to send the above application message to the device where the second application group of the second user group is located based on the above first control policy and the second control policy. The second control policy includes the corresponding relationship between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0053] In some possible implementation manners, the above second control policy includes the corresponding relationship between the source user identifier set and the destination user identifier set, and the second control policy is used to indicate that the user group indicated by any identifier in the source user identifier set is allowed to access the user group indicated by any identifier in the destination user identifier set, where the source user identifier set includes the identifier used to indicate the above first user group, and the destination user identifier set includes the identifier used to indicate the above second user group.
[0054] In some possible implementation manners, the above receiving unit is further configured to receive the above first control policy sent by the management device before receiving the above application message.
[0055] In some possible implementations, the above forwarding packet device includes one or more of a gateway, a firewall, a router, a switch, and a load balancer.
[0056] In a sixth aspect, the present application provides a packet sending device, which includes: a generating unit and a sending unit. The generating unit is configured to generate an application packet, and the application packet includes a first Application Perception Network Identifier (APN-ID) and a second APN-ID. The first APN-ID includes an identifier of a first application group that generates the application packet, and the second APN-ID includes an identifier of a second application group to which the application packet is to be accessed. The sending unit is configured to send the above application packet to a network device. The first APN-ID and the second APN-ID in the above application packet are used for the network device to send the above application packet to a device where the second application group is located based on a first control policy. The first control policy includes a corresponding relationship between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0057] In some possible implementations, the above first control policy includes a corresponding relationship between a source application identifier set and a destination application identifier set, and the first control policy is used to indicate that an application group indicated by any identifier in the source application identifier set is allowed to access an application group indicated by any identifier in the destination application identifier set. The source application identifier set includes an identifier for indicating the above first application group, and the destination application identifier set includes an identifier for indicating the above second application group.
[0058] In some possible implementations, the above application packet is an IPv6 packet. If the application packet includes an APN header, carrying the above second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried by an Intent field in the APN header; in the second implementation manner, the second APN-ID is carried by a Reserved field in an APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried by an APP-Group-ID field in an APN-ID field in the APN header.
[0059] In some possible implementations, the Flags field in the above APN header is used to indicate that the access mode is a cross-application group access mode.
[0060] In some possible implementation manners, the above-mentioned first APN-ID further includes an identifier of a first user group using the above-mentioned first application group, and the above-mentioned second APN-ID further includes an identifier of a second user group using the above-mentioned second application group. The identifier of the first user group and the identifier of the second user group are used for the above-mentioned network device to send the above-mentioned application message to a device where the second application group of the second user group is located based on a second control policy. Wherein, the second control policy includes a corresponding relationship between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0061] In some possible implementation manners, the above-mentioned second control policy includes a corresponding relationship between a source user identifier set and a destination user identifier set, and the second control policy is used to indicate that a user group indicated by any identifier in the source user identifier set is allowed to access a user group indicated by any identifier in the destination user identifier set. Wherein, the source user identifier set includes an identifier for indicating the above-mentioned first user group, and the destination user identifier set includes an identifier for indicating the above-mentioned second user group.
[0062] In a seventh aspect, the present application provides a control device, and the device includes: a generating unit. Wherein, the generating unit is used to generate a control policy, and the control policy includes a corresponding relationship between a first application group and a second application group, and the control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0063] In some possible implementation manners, the above-mentioned control policy includes a corresponding relationship between a source application identifier set and a destination application identifier set, and the control policy is used to indicate that an application group indicated by any identifier in the source application identifier set is allowed to access an application group indicated by any identifier in the destination application identifier set. Wherein, the source application identifier set includes an identifier for indicating the above-mentioned first application group, and the destination application identifier set includes an identifier for indicating the above-mentioned second application group.
[0064] In some possible implementation manners, the above-mentioned control device further includes a sending unit, and the sending unit is used to send the above-mentioned control policy to a network device so that the network device forwards a message based on the above-mentioned control policy.
[0065] In some possible implementation manners, the above-mentioned control device further includes a sending unit, and the sending unit is used to send the above-mentioned control policy to a network controller.
[0066] In an eighth aspect, the present application provides a device for forwarding packets, the device comprising: a receiving unit and a sending unit. The receiving unit is configured to receive an application packet, the application packet including a first Application Perception Network Identifier (APN-ID) and a second APN-ID, wherein the first APN-ID includes an identifier of a first user group that generates the application packet, and the second APN-ID includes an identifier of a second user group to which the application packet is to be accessed; the sending unit is configured to send the above application packet to a device where the second user group is located based on a control policy, wherein the control policy includes a corresponding relationship between the first user group and the second user group, and the control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0067] In some possible implementation manners, the above control policy includes a corresponding relationship between a source user identifier set and a destination user identifier set, and the above control policy is used to indicate that a user group indicated by any identifier in the source user identifier set is allowed to access a user group indicated by any identifier in the destination user identifier set, wherein the source user identifier set includes an identifier for indicating the above first user group, and the destination user identifier set includes an identifier for indicating the above second user group.
[0068] In some possible implementation manners, the above application packet is an IPv6 packet, and the application packet includes an APN header. Carrying the above second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried by an Intent field in the APN header; in the second implementation manner, the second APN-ID is carried by a Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried by an APP-Group-ID field in the APN-ID field in the APN header.
[0069] In some possible implementation manners, the Flags field in the above APN header is used to indicate that the access mode is a cross-user group access mode.
[0070] In a ninth aspect, the present application provides a communication device, including a processor and a memory, the memory is configured to store instructions, and the processor is configured to execute the instructions. When the processor executes the instructions, the method in the first aspect or any possible implementation manner of the first aspect is implemented, or the method in the second aspect or any possible implementation manner of the second aspect is implemented, or the method in the third aspect or any possible implementation manner of the third aspect is implemented, or the method in the fourth aspect or any possible implementation manner of the fourth aspect is implemented.
[0071] Tenth aspect, the present application provides a network system, including a network device and a terminal device. The network device executes the method in the first aspect or any possible implementation manner of the first aspect, or the network device executes the method in the fourth aspect or any possible implementation manner of the fourth aspect, and the terminal device executes the method in the second aspect or any possible implementation manner of the second aspect.
[0072] In some possible implementation manners, the above-mentioned network system further includes a management device, and the management device executes the method in the third aspect or any possible implementation manner of the third aspect.
[0073] Eleventh aspect, the present application provides a computer-readable storage medium, including computer program instructions. When the computer program instructions are executed by a computing device, the computing device executes the method in the first aspect or any possible implementation manner of the first aspect, or executes the method in the second aspect or any possible implementation manner of the second aspect, or executes the method in the third aspect or any possible implementation manner of the third aspect, or executes the method in the fourth aspect or any possible implementation manner of the fourth aspect.
[0074] Twelfth aspect, the present application provides a computer program product containing instructions. When the instructions are run by a computing device, the computing device is caused to execute the method in the first aspect or any possible implementation manner of the first aspect, or execute the method in the second aspect or any possible implementation manner of the second aspect, or execute the method in the third aspect or any possible implementation manner of the third aspect, or execute the method in the fourth aspect or any possible implementation manner of the fourth aspect. Description of the Drawings
[0075] Figure 1 is a schematic diagram of the format of the APN header in a message provided by an embodiment of the present application;
[0076] Figure 2 is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;
[0077] Figure 3 is a schematic diagram of the flow of a control method provided by an embodiment of the present application;
[0078] Figure 4 is a schematic diagram of the flow of a method for sending a message provided by an embodiment of the present application;
[0079] Figure 5A is a schematic diagram of the structure of the APN header carrying the second APN-ID provided by an embodiment of the present application;
[0080] Figure 5BIt is a schematic structural diagram of another APN header carrying a second APN-ID provided by an embodiment of the present application;
[0081] Figure 5C It is a schematic structural diagram of another APN header carrying a second APN-ID provided by an embodiment of the present application;
[0082] Figure 6A It is a schematic flowchart of a method for forwarding a message provided by an embodiment of the present application;
[0083] Figure 6B It is a schematic flowchart of another method for forwarding a message provided by an embodiment of the present application;
[0084] Figure 6C It is a schematic flowchart of another method for forwarding a message provided by an embodiment of the present application;
[0085] Figure 7 It is a schematic structural diagram of a control device provided by an embodiment of the present application;
[0086] Figure 8 It is a schematic structural diagram of a message sending device provided by an embodiment of the present application;
[0087] Figure 9 It is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application;
[0088] Figure 10 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. Detailed implementation manners
[0089] To facilitate understanding of the control method, message sending method, and message forwarding method provided by the embodiments of the present application, the format of the APN header will be introduced here first.
[0090] See Figure 1 , Figure 1 It is a schematic diagram of the format of the APN header in a message provided by an embodiment of the present application. As Figure 1 shown, the format of the APN header consists of the following fields:
[0091] Perceived Application Network Identification Type (APN-ID-Type): It is used to indicate the length type of the APN-ID and can occupy 8 bits (8-bit). Among them, Type I indicates that the APN-ID can occupy 32 bits (32-bit), Type II indicates that the APN-ID can occupy 64 bits (64-bit), and Type III indicates that the APN-ID can occupy 128 bits (128-bit).
[0092] Flags: Used to define some necessary operations or restrictions, etc., and can occupy 8 bits (8-bit).
[0093] APN-Para-Type (Perceived Application Network Parameter Type): Used to indicate the APN parameters corresponding to the APN-ID and can occupy 16 bits (16-bit). The network requirements are determined according to the setting results of each bit. Among them, when Bit 0 is set, it indicates the existence of a bandwidth requirement; when Bit 1 is set, it indicates the existence of a delay requirement; when Bit 2 is set, it indicates the existence of a jitter requirement; when Bit 3 is set, it indicates the existence of a packet loss rate requirement.
[0094] APN-ID (Perceived Application Network Identifier): Used to indicate the APN and can occupy 32 bits (32-bit).
[0095] Intent: Used to indicate the service requirements of the network and can occupy 32 bits (32-bit).
[0096] APN-Para (Perceived Application Network Parameter): A series of APN parameters specified by the APN-Para-Type.
[0097] In the APN header, the APN-ID is mandatory information, and the information after the APN-ID is optional information, such as Intent and APN-Para, etc.
[0098] Among them, the format of the above APN-ID field consists of the following three fields:
[0099] APP-Group-ID (Application Group Identifier): As the identifier of the application group, it is used to indicate the application group. Among them, the application group is a group of related applications. Usually, the applications belonging to the same application group have similar functions or services. For example, payment software belongs to the same application group, and bank applications belong to another application group. The number of applications in the application group can be one or more. When the number of applications in the application group is one, one APP-Group-ID is used to indicate one application; when the number of applications in the application group is multiple, one APP-Group-ID is used to indicate multiple applications.
[0100] User Group Identifier (USER-Group-ID): As the identifier of a user group, it is used to indicate the user group. Here, a user group is a group of related users. Generally, users belonging to the same user group have similar characteristics or permissions. For example, technology companies belong to the same user group, and banks belong to another user group. Or, employees from the same enterprise belong to the same user group, and employees from different enterprises belong to different user groups. The number of users in a user group can be one or more. When the number of users in a user group is one, one USER-Group-ID is used to indicate one user; when the number of users in a user group is multiple, one USER-Group-ID is used to indicate multiple users.
[0101] Reserved: Reserved field.
[0102] The APN-ID field is used to carry the Application Perception Network Identifier (APN-ID). The APN-ID can be used as an overall identifier or as a combination of multiple identifiers, including the identifier of the application group (APP-Group-ID), the identifier of the user group (USER-Group-ID), FLOW-ID, SLA, etc. Among them, in the APN-ID field, at least one of the APP-Group-ID and USER-Group-ID is carried. When the APN-ID field carries the APP-Group-ID, the APN-ID includes the APP-Group-ID. Therefore, the APN-ID can be used to indicate the application group. When the APN-ID field carries the USER-Group-ID, the APN-ID includes the USER-Group-ID. Therefore, the APN-ID can be used to indicate the user group.
[0103] In the specific implementation, the format of the APN header and the format of the APN-ID field in the APN header are not limited to the formats described above. The specific formats of the APN header and the APN-ID field adopted are determined according to actual needs, and this solution does not limit this.
[0104] Exemplarily, the APN header can be carried in the IPv6 extension header of the message. Here, this IPv6 extension header can be a hop-by-hop options header (HBH), a destination options header (DOH), a routing header (RH), or a segment routing header (SRH), etc.
[0105] The embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application.
[0106] See Figure 2 , Figure 2 which is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application. The communication system can be applied to an application-aware IPv6 networking (APN6). In APN6, the communication system can be used to generate application packets and forward application packets. Among them, the application packet is an IPv6 packet containing the above-mentioned Figure 1 APN header in
[0107] As Figure 2 shown, the communication system includes a terminal device, a computing device, a network device, and a network controller. Among them, the terminal device and the computing device, the terminal device and the network device, the computing device and the network device, and the network device and the network controller can communicate with each other by wired or wireless means.
[0108] In Figure 2 , the terminal device includes terminal device 111, terminal device 112, and terminal device 133. Among them, terminal device 111 and terminal device 112 are deployed in local area network 110, and terminal device 133 is deployed in local area network 130. The terminal device includes mobile devices (such as computers and mobile phones), Internet of Things devices (such as sensors, cameras, smart home devices, smart wearable devices, and smart vehicles), embedded devices (such as embedded systems, industrial control devices, and automation devices), and so on.
[0109] A plurality of applications are installed on the above-mentioned terminal device. Among them, APP1, APP2, and APP3 are installed on terminal device 111, APP1, APP2, and APP4 are installed on terminal device 112, and APP1, APP2, and APP5 are installed on terminal device 133.
[0110] In Figure 2 , the computing device includes computing device 134. Computing device 134 is deployed in local area network 130. The computing device includes servers, supercomputers, personal computers, workstations, and so on.
[0111] A plurality of applications are installed on the above-mentioned computing device. Among them, APP1, APP3, and APP4 are installed on computing device 134.
[0112] In Figure 2Among them, the network devices include network device 131, network device 121, network device 122, network device 123, network device 124, network device 131, and network device 132. Among them, network device 131 is deployed in local area network 110, network devices 121, 122, 123, and 124 are deployed in distributed network 120, and network devices 131 and 132 are deployed in local area network 130.
[0113] The above-mentioned network devices 113 and 131 serve as the edge devices in local area networks 110 and 130 respectively, and can be gateways, firewalls, routers, switches, load balancers, etc. The above-mentioned network devices 121, 122, 123, 124, and 132 include switches, routers, etc.
[0114] In Figure 2 Among them, network device 113 can communicate with the network devices (network devices 121, 122, 123, and 124) in distributed network 120 through protocols such as routing information protocol (RIP), open shortest path first (OSPF), border gateway protocol (BGP), and internet control message protocol (ICMP). Network device 131 can also communicate with the network devices (network devices 121, 122, 123, and 124) in distributed network 120 through protocols such as RIP, OSPF, BGP, and ICMP.
[0115] In Figure 2 Among them, the network controller includes network controller 140. Network controller 140 can centrally manage and configure various network devices in the communication system, including the parameters of network devices, network topology, routing policies, access control rules, etc., and send the configuration information to the corresponding network devices, so that the network devices can forward application messages according to the configuration information provided by network controller 140. This can simplify the management work and improve the management efficiency.
[0116] The above-mentioned network controller 140 can communicate with various network devices in the communication system through protocols such as data transfer protocols (such as TCP, UDP), network management protocols (such as SNMP), routing protocols (such as OSPF, BGP, RIP), and switching protocols (such as STP, RSTP).
[0117] In a specific implementation, the network controller 140 may be a boundary management controller (BMC). Then, the network controller 140 and boundary devices (such as network device 113 and network device 131) can communicate with each other through protocols such as the Simple Network Management Protocol (SNMP), Secure Shell Protocol (SSH), and Hypertext Transfer Protocol (HTTP).
[0118] In Figure 2 this example where the boundary management controller serves as the network controller 140, a communication connection is established between the network controller 140 and the network device 113 in the local area network 110, and a communication connection is established between the network controller 140 and the network device 131 in the local area network 130. Assume that the network device 113 is the head node for forwarding application messages. Then, the network controller 140 sends the configuration information 1130 to the network device 113, enabling the network device 113 to forward the application message 151 from the local area network 110 to a network device in the distributed network 120 according to the configuration information 1130, or the network device 113 can forward the application message 152 from the distributed network 120 to a terminal device in the local area network 110 according to the configuration information 1130. Among them, the application message 151 may be generated by the terminal device 111 in the local area network 110. The application message 152 may be generated by the computing device 134 in the local area network 130.
[0119] In a specific implementation, the above-mentioned configuration information 1130 includes a five-tuple—(source IP address, destination IP address, source port number, destination port number, transport protocol). Among them, the source IP address is used to indicate the IP address of the terminal device initiating the access; the destination IP address is used to indicate the IP address of the terminal device to be accessed; the source port number is used to indicate the port number of the application on the terminal device initiating the access, thereby identifying from which application the application message is sent; the destination port number is used to indicate the port number of the application on the terminal device to be accessed, thereby identifying which application the application message is handed to for processing; the transport protocol is used to indicate the protocol for transmitting the application message.
[0120] Therefore, after receiving the application message, the network device 113 matches the information carried in the application message with the five-tuple in the configuration information 1130. If the match is successful, the network device 113 forwards the application message; if the match fails, the network device 113 does not forward the application message.
[0121] When APP1 on the terminal device 111 initiates an access to APP2 on the terminal device 133, a five-tuple—(the IP address of the terminal device 111, the IP address of the terminal device 133, the port number of APP1 on the terminal device 111, the port number of APP2 on the terminal device 133, the transport protocol) needs to be added to the ACLs of the network device 113 and the network device 131 to enable this access.
[0122] When APP1 on the terminal device 112 initiates an access to APP2 on the terminal device 133, another five-tuple—(the IP address of the terminal device 112, the IP address of the terminal device 133, the port number of APP1 on the terminal device 112, the port number of APP2 on the terminal device 133, the transport protocol) also needs to be added to the ACLs of the network device 113 and the network device 131 to enable this access.
[0123] In summary, if the applications on the terminal device 111 continue to increase, or the terminal devices in the local area network 110 continue to increase, five-tuples corresponding to the newly added applications / terminal devices need to be added to the ACLs of the network device 113 and the network device 131 to enable access between different applications.
[0124] When the original communication relationships between multiple applications change, such as deleting the access relationship of APP1 to APP2 (that is, deleting the communication relationships between all terminal devices installed with APP1 and terminal devices installed with APP2), adding the access relationship of APP1 to APP5 (that is, adding the communication relationships between all terminal devices installed with APP1 and terminal devices installed with APP5), etc., a large number of five-tuples also need to be deleted or added in the ACLs of the network device 113 and the network device 131.
[0125] Therefore, as the scale of APN6 expands and the number of applications accessing APN6 increases, the number of five-tuples that the network device needs to maintain is increasing, and the management difficulty is also increasing.
[0126] To solve the above problems, the embodiments of the present application provide a method for sending a message, a method for forwarding a message, and related devices, which can reduce the impact of factors such as changes in the number of terminal devices in the network, changes in the number of applications on terminal devices, and changes in communication relationships between multiple applications on the maintenance work of access control.
[0127] It should be understood that the application scenarios of the method for sending a message and the method for forwarding a message provided by the embodiments of the present application are not limited to the Figure 2 communication system described above. Any scenario where the method for sending a message and the method for forwarding a message provided by the embodiments of the present application can be applied is within the protection scope of the present application.
[0128] To reduce the impact caused by the maintenance work of access control, an embodiment of the present application first defines a control policy. This control policy can be used as the basis for processing application messages. The control method for generating this control policy will be specifically introduced below.
[0129] See Figure 3 , Figure 3 which is a schematic flowchart of a control method provided by an embodiment of the present application. The control method provided by an embodiment of the present application can be applied to the above Figure 2 communication system. As Figure 3 shown, the control method provided by an embodiment of the present application includes:
[0130] S301: The management device generates a control policy.
[0131] In some possible implementation manners, the management device is used to manage and control applications, including firewalls, routers, switches, proxy servers, application delivery controllers (ADCs), and so on. The number of management devices can be one or more.
[0132] In some possible implementation manners, the management device generates a control policy specifically as follows: The management device generates a control policy based on the correspondence between the five-tuple, the application group / user group, and the APN-ID.
[0133] Among them, the five-tuple is (source IP address, destination IP address, source port number, destination port number, transport protocol). The five-tuple can be input by the user received by the management device, or the five-tuple can be obtained by the management device from a network device. Among them, the network device can be Figure 2 one or more of the network devices 113, 121, 122, 123, 124, 131, 132 in
[0134] The correspondence between the application group / user group and the APN-ID depends on the type of the device where the application group / user group is located and the type of the application group / user group.
[0135] The control policy includes a first control policy and / or a second control policy.
[0136] (1) First control policy
[0137] The first control policy includes the correspondence between the source application group and the destination application group. Moreover, the first control policy is used to indicate that any application group in the source application group is allowed to access any application group in the destination application group. Among them, the source application group includes one or more application groups that initiate access, and each application group in the source application group serves as a source application. The destination application group includes one or more application groups to be accessed, and each application group in the destination application group serves as a destination application.
[0138] In some possible implementation manners, the identifier used to indicate the application group may refer to the following implementation manner 1 and implementation manner 2:
[0139] Implementation manner 1: Use the APN-ID as the identifier to indicate the application group;
[0140] Implementation manner 2: Use the APP-Group-ID in the APN-ID as the identifier to indicate the application group.
[0141] When the application group has an identifier, the source application group corresponds to the source application identifier set, and the destination application group corresponds to the destination application identifier set. Then, the first control policy may include the correspondence between the source application identifier set and the destination application identifier set. Moreover, the first control policy is used to indicate that the application group indicated by any identifier in the source application identifier set is allowed to access the application group indicated by any identifier in the destination application identifier set.
[0142] If multiple application groups in the source application group have the same identifier, the number of application groups in the source application group is more than the number of identifiers in the corresponding source application identifier set; if each application group in the source application group has a different identifier, the number of application groups in the source application group is equal to the number of identifiers in the corresponding source application identifier set.
[0143] If multiple application groups in the destination application group have the same identifier, the number of application groups in the destination application group is more than the number of identifiers in the corresponding destination application identifier set; if each application group in the destination application group has a different identifier, the number of application groups in the destination application group is equal to the number of identifiers in the corresponding destination application identifier set.
[0144] (1.1) Generate the first control policy
[0145] Next, taking all the five-tuples obtained from the network device 113 in the Figure 2 medium communication system as an example of the five-tuples, the process of the management device generating the first control policy based on the correspondence between the five-tuples, the application group, and the APN-ID will be specifically introduced.
[0146] Refer to Table 1. The five-tuples in Table 1 are all the five-tuples obtained by the management device from the network device 113.
[0147] Table 1
[0148]
[0149] It should be understood that the above Table 1 is only an example of the five-tuple and is not a specific limitation on the storage format of the five-tuple in the network device here.
[0150] Assume that each application in Table 1 is regarded as an application group. It can be seen from Table 1 that the source applications include APP1, APP2, APP3, and APP4, and the destination applications include APP1, APP2, APP3, APP4, and APP5. The five-tuples in Table 1 can be converted into the access relationship between the source application and the destination application. See Table 2.
[0151] Table 2
[0152]
[0153] "√" indicates that the source application allows access to the destination application, that is, there is a corresponding five-tuple in Table 1.
[0154] It can be seen from Table 2 that:
[0155] ① The source applications APP1 and APP2 both allow access to the destination applications APP1 and APP3, so the first control policy A1 - [source application group (APP1, APP2), destination application group (APP1, APP3)] is generated;
[0156] ② The source application APP2 allows access to the destination application APP5, so the first control policy A2 - [source application group (APP2), destination application group (APP5)] is generated;
[0157] ③ The source application APP3 allows access to the destination applications APP1, APP2, APP3, and APP4, so the first control policy A3 - [source application group (APP3), destination application group (APP1, APP2, APP3, APP4)] is generated.
[0158] See Table 3. Table 3 is the corresponding relationship between the application group and the APN-ID, and the corresponding relationship between the application group and the APP-Group-ID in the APN-ID determined by the management device according to the type of the device where the application group is located and the type of the application group.
[0159] Table 3
[0160]
[0161] It should be understood that the above Table 3 is only an example of APN-ID and APP-Group-ID, and is not used as a specific limitation here. For example, the APN-ID can also be numerical values 1, 2, 3, 4..., or the APN-ID can also be letters A, B, C, D..., or the APN-ID can also be any combination of numerical values, letters, symbols, etc. The APP-Group-ID can also be letters A, B, C, D..., or the APP-Group-ID can also be any combination of numerical values, letters, symbols, etc.
[0162] Through the implementation method 1 in the above step S301 (1) the first control strategy: using the APN-ID as an identifier to indicate the application group, the first control strategies corresponding to the above first control strategies A1, A2, and A3 can be obtained, specifically:
[0163] ① The first control strategy A11—[source application identifier set (A1, A2), destination application identifier set (B1, B3)];
[0164] ② The first control strategy A21—[source application identifier set (A2), destination application identifier set (B5)];
[0165] ③ The first control strategy A31—[source application identifier set (A3), destination application identifier set (B1, B2, B3, B4)].
[0166] Through the implementation method 2 in the above step S301 (1) the first control strategy: using the APP-Group-ID in the APN-ID as an identifier to indicate the application group, the first control strategies corresponding to the above first control strategies A1, A2, and A3 can be obtained, specifically:
[0167] ① The first control strategy A12—[source application identifier set (1, 2), destination application identifier set (5)];
[0168] ② The first control strategy A22—[source application identifier set (2), destination application identifier set (7)];
[0169] ③ The first control strategy A32—[source application identifier set (3), destination application identifier set (5, 6)].
[0170] In summary, the embodiments of the present application provide various implementation methods for the identifier of the application group, including: using the APN-ID as an identifier to indicate the application group, and using the identifier of the application group (APP-Group-ID) as an identifier to indicate the application group. Therefore, the appropriate implementation method can be flexibly selected according to user needs, so that the first control strategy can be applied to different application scenarios.
[0171] (2) The second control policy
[0172] The second control policy includes the correspondence between the source user group and the destination user group. Moreover, the second control policy is used to indicate that any user group in the source user group is allowed to access any user group in the destination user group. Among them, the source user group includes one or more user groups that initiate access, and each user group in the source user group serves as a source user. The destination user group includes one or more user groups to be accessed, and each user group in the destination user group serves as a destination user.
[0173] In some possible implementation manners, the identifiers used to indicate user groups may refer to the following implementation manner 1 and implementation manner 2:
[0174] Implementation manner 1: Use the APN-ID as the identifier to indicate the user group;
[0175] Implementation manner 2: Use the USER-Group-ID in the APN-ID as the identifier to indicate the user group.
[0176] When the user group has an identifier, the source user group corresponds to the source application identifier set, and the destination user group corresponds to the destination application identifier set. Then, the second control policy may include the correspondence between the source user identifier set and the destination user identifier set. Moreover, the second control policy is used to indicate that the user group indicated by any identifier in the source user identifier set is allowed to access the user group indicated by any identifier in the destination user identifier set.
[0177] If multiple user groups in the source user group have the same identifier, the number of user groups in the source user group is more than the number of identifiers in the corresponding source user identifier set; if each user group in the source user group has a different identifier, the number of user groups in the source user group is equal to the number of identifiers in the corresponding source user identifier set.
[0178] If multiple user groups in the destination user group have the same identifier, the number of user groups in the destination user group is more than the number of identifiers in the corresponding destination user identifier set; if each user group in the destination user group has a different identifier, the number of user groups in the destination user group is equal to the number of identifiers in the corresponding destination user identifier set.
[0179] (2.1) Generate the second control policy
[0180] Next, continue to use the five-tuple in Table 1 as an example to specifically introduce the process of the management device generating the second control policy based on the correspondence between the five-tuple, the user group, and the APN-ID.
[0181] Assume that the same applications on different devices in the same network belong to the same user group. If the terminal device 111 and the terminal device 112 in the above Table 1 are in the local area network 110, then the same applications on the terminal device 111 and the terminal device 112 belong to the same user group. If the terminal device 133 and the computing device 134 are in the local area network 130, then the same applications on the terminal device 133 and the computing device 134 belong to the same user group. Therefore, the five-tuples in Table 1 can be converted into the access relationship between the source user and the destination user, as shown in Table 4.
[0182] Table 4
[0183]
[0184] "√" indicates that the source user is allowed to access the destination user, that is, there is a corresponding five-tuple in Table 1.
[0185] It can be seen from Table 4 that:
[0186] ① If the source users USER11 and USER12 are both allowed to access the destination users USER21 and USER23, then the second control policy B1 - [source user group (USER11, USER12), destination user group (USER21, USER23)] is generated;
[0187] ② If the source user USER12 is allowed to access the destination user USER25, then the second control policy B2 - [source user group (USER12), destination user group (USER25)] is generated;
[0188] ③ If the source user USER13 is allowed to access the destination users USER21, USER22, USER23, and USER24, then the second control policy B3 - [source user group (USER13), destination application group (USER21, USER22, USER23, USER24)] is generated.
[0189] Refer to Table 5. Table 5 is the corresponding relationship between the user group and the APN-ID, and the corresponding relationship between the user group and the USER-Group-ID in the APN-ID, based on the corresponding relationship between the application group and the APN-ID in the above Table 2.
[0190] Table 5
[0191]
[0192] It should be understood that the above Table 5 is only an example of APN-ID and USER-Group-ID, and is not used as a specific limitation here. For example, the APN-ID can also be numerical values 1, 2, 3, 4..., or the APN-ID can also be letters A, B, C, D..., or the APN-ID can also be any combination of numerical values, letters, symbols, etc. The USER-Group-ID can also be letters A, B, C, D..., or the USER-Group-ID can also be any combination of numerical values, letters, symbols, etc.
[0193] Through the implementation method 1 in the second control policy in the above step S301: using the APN-ID as an identifier to indicate the user group, the second control policies corresponding to the above second control policies B1, B2, and B3 can be obtained, specifically:
[0194] ① The second control policy B11—[source user identifier set (A1, A2), destination user identifier set (B1, B3)];
[0195] ② The second control policy B21—[source user identifier set (A2), destination user identifier set (B5)];
[0196] ③ The second control policy B31—[source user identifier set (A3), destination user identifier set (B1, B2, B3, B4)].
[0197] Through the implementation method 2 in the second control policy in the above step S301: using the USER-Group-ID in the APN-ID as an identifier to indicate the user group, the second control policies corresponding to the above second control policies B1, B2, and B3 can be obtained, specifically:
[0198] ① The second control policy B12—[source application identifier set (1, 2), destination application identifier set (5, 7)];
[0199] ② The second control policy B22—[source user identifier set (2), destination user identifier set (8)];
[0200] ③ The second control policy B32—[source user identifier set (3), destination user identifier set (5, 6, 7)].
[0201] In summary, the embodiments of the present application provide various implementation manners for the identification of user groups, including: using the APN-ID as the identification to indicate the user group, and using the identification of the user group (USER-Group-ID) as the identification to indicate the user group. Therefore, the appropriate implementation manner can be flexibly selected according to user requirements, so that the second control policy can be applied to different application scenarios.
[0202] S302: The management device sends a control policy to the network controller.
[0203] Among them, the network controller may be the network controller 140 in the above Figure 2 communication system.
[0204] In some possible implementation manners, the management device sending a control policy to the network controller mainly includes the following three situations:
[0205] Situation 1: The management device sends a first control policy to the network controller;
[0206] Situation 2: The management device sends a second control policy to the network controller;
[0207] Situation 3: The management device sends a first control policy and a second control policy to the network controller.
[0208] In some possible implementation manners, there are various ways to send the control policy. Taking Situation 1 as an example, the way to send the control policy is specifically introduced below. The way for the management device to send the first control policy can refer to the following Sending Methods 1-3:
[0209] Sending Method 1: The management device sends multiple first control policies to the network controller one by one. Correspondingly, the network controller receives the first control policies one by one.
[0210] Sending Method 2: The management device aggregates multiple first control policies and sends them to the network controller in the form of a table. Correspondingly, the network controller receives the control policy table. Each entry in the control policy table is a first control policy. Taking the first control policy A11, the first control policy A21, and the first control policy A31 in the above step S301 as examples of the first control policy, a control policy table aggregating multiple first control policies is provided, as shown in Table 6.
[0211] Table 6
[0212]
[0213] Sending method 3: The management device converts each of the multiple first control policies into an application identity pair, and sends the obtained multiple application identity pairs to the network controller one by one, or aggregates the obtained multiple application identity pairs into a table and sends the table to the network controller. Each application identity pair includes only one source application identity and one destination application identity. Each application identity pair is used to indicate that the application group indicated by the source application identity is allowed to access the application group indicated by the destination application identity.
[0214] Continuing with the first control policy A11 in step S301 above as an example, the sending method 3 in step S302 above will be specifically introduced below.
[0215] For the first control policy A11—[source application identity set (A1, A2), destination application identity set (B1, B3)], the first control policy A11 can be converted into four application identity pairs, specifically: application identity pair C1 (A1, B1), application identity pair C2 (A1, B3), application identity pair C3 (A2, B1), application identity pair C4 (A2, B3). Among them, the application identity pair C1 (A1, B1) is used to indicate that the application group indicated by A1 is allowed to access the application group indicated by B1; the application identity pair C2 (A1, B3) is used to indicate that the application group indicated by A1 is allowed to access the application group indicated by B3; the application identity pair C3 (A2, B1) is used to indicate that the application group indicated by A2 is allowed to access the application group indicated by B1; the application identity pair C4 (A2, B3) is used to indicate that the application group indicated by A2 is allowed to access the application group indicated by B3.
[0216] Subsequently, the management device sends the application identity pair C1, the application identity pair C2, the application identity pair C3, and the application identity pair C4 to the network controller one by one. Alternatively, the management device aggregates the application identity pair C1, the application identity pair C2, the application identity pair C3, and the application identity pair C4 into four entries in the application identity pair table, and then sends the application identity pair table to the network controller. The application identity pair table can be seen in Table 7.
[0217] Table 7
[0218]
[0219] It should be understood that the above three sending methods for the first control policy are only examples and are not specifically limited here.
[0220] It should be understood that the sending method of the management device for the second control policy in case 2 of step S302 above, and the sending methods of the management device for the first control policy and the second control policy in case 3 of step S302 above are similar to the sending method of the management device for the first control policy in case 1 of step S302 above. For the sake of simplicity of the specification, they will not be elaborated here.
[0221] S303: The network controller sends a control policy to the network device so that the network device forwards application messages based on the control policy.
[0222] In some possible implementation manners, the control policy received by the network controller from the management device includes a first control policy and / or a second control policy. The control policy may be the configuration information 1130 in the above-mentioned Figure 2 communication system.
[0223] In some possible implementation manners, after receiving the control policy, the network controller determines the control policy corresponding to the network device according to the network where the network device is located. Subsequently, the network controller sends the corresponding control policy to the network device so that the network device can forward application messages based on the control policy.
[0224] The following takes the network device in the above-mentioned Figure 2 communication system as an example of the network device, and takes the first control policy as an example of the control policy, and specifically introduces the determination process of the control policy corresponding to the network device.
[0225] If the network where the network device is located is a local area network, the network controller sends the first control policy including the source application identifier and / or the destination application identifier corresponding to the application in the local area network to the network device; if the network where the network device is located is a distributed network, the network controller sends all the first control policies to the network device.
[0226] For example, the network where the network device 113 is located is the local area network 110, and the source application identifiers corresponding to the applications in the local area network 110 are as shown in Table 3 above. The source application identifier APN-ID includes A1, A2, A3, A4. Then the network controller sends the first control policy including A1, A2, A3, A4, including the first control policy A11, the first control policy A21, and the first control policy A31, to the network device 113.
[0227] For example, the network where the network device 121 is located is the distributed network 120, then the network controller sends all the first control policies to the network device 121.
[0228] It should be understood that the sending manner of the first control policy by the network controller, the sending manner of the second control policy by the network controller, and the sending manner of the first control policy and the second control policy by the network controller are similar to the sending manner of the first control policy by the management device in the above step S302. For the sake of simplicity of the specification, it will not be elaborated here.
[0229] In summary, by determining the correspondence between two application groups or two user groups in the control policy for forwarding application messages, a network device can process application messages according to the correspondence between the two application groups or the two user groups in the control policy, thereby supporting service access scenarios between different application groups or service access scenarios between different user groups.
[0230] It can be seen that, compared with the method of generating a control policy through ACL + five-tuple, the control policy in this technical solution can perform the same processing on application messages with the same first APN-ID and the same second APN-ID, that is, it does not limit the device where the application is located. Therefore, the control policy in this technical solution has a coarser granularity. Adopting the control policy in this technical solution can avoid the impact on the maintenance work of access control caused by changes in the number of terminal devices in the network, and can also reduce the impact on the maintenance work of access control caused by factors such as changes in the number of application groups on terminal devices and changes in the communication relationship between application groups.
[0231] In some possible implementation manners, the above management device and network controller are the same device. Then, the management device executes the above steps S301, S302, and S303. That is, after the management device generates the control policy in step S301, it determines the control policy corresponding to the network device according to the network where the network device is located. Subsequently, the management device sends the corresponding control policy to the network device so that the network device can forward application messages based on the control policy. Among them, the manner in which the management device sends the control policy to the network device is similar to the manner in which the management device sends the control policy to the network controller in step S302. For the sake of simplicity of the specification, it will not be elaborated here.
[0232] In some possible implementation manners, the management device is further configured to generate an encapsulation table and send the encapsulation table to the terminal device so that the terminal device can generate application messages according to the encapsulation table. Specifically, the management device generates the encapsulation table by determining the matching conditions, encapsulation rules, output interfaces, etc. in the encapsulation table. Among them, the matching conditions are used to specify the information carried by the application message, including the identifier of the application group / user group that generates the application message, the identifier of the application group / user group that the application message is to access, source IP address, destination IP address, protocol type, port number, etc. The encapsulation rules are used to specify the format and content of the application message, including specifying the added protocol header (such as APN header), specifying the modified fields (such as the semantics of the field, the value of the field), etc. The output interface is used to specify the network interface for sending the application message.
[0233] SeeFigure 4 , Figure 4 is a schematic flow chart of a method for sending a message provided by an embodiment of the present application. The method for sending a message provided by an embodiment of the present application can be applied to the above-mentioned Figure 2 communication system. As Figure 4 shown, the method for sending a message provided by an embodiment of the present application includes:
[0234] S401: The terminal device generates an application message.
[0235] Among them, the terminal device can be Figure 2 the terminal device 111, terminal device 112 or terminal device 133 in
[0236] In some possible implementation manners, the application message includes a first APN-ID and a second APN-ID. Among them, the first APN-ID includes at least one of the identifier of the first application group (i.e., the first APP-Group-ID) and the identifier of the first user group (i.e., the first USER-Group-ID). The second APN-ID includes at least one of the identifier of the second application group (i.e., the second APP-Group-ID) and the identifier of the second user group (i.e., the second USER-Group-ID).
[0237] When the first APN-ID includes the first APP-Group-ID, does not include the first USER-Group-ID, and the second APN-ID includes the second APP-Group-ID, does not include the second USER-Group-ID, the first APN-ID is used to indicate the first application group, and the second APN-ID is used to indicate the second application group. Or, the first APP-Group-ID is used to indicate the first application group, and the second APP-Group-ID is used to indicate the second application group. Among them, the first application group is the application group that generates the application message, and the second application group is the application group to which the application message is to be accessed.
[0238] When the first APN-ID includes the first USER-Group-ID, does not include the first APP-Group-ID, and the second APN-ID includes the second USER-Group-ID, does not include the second APP-Group-ID, the first APN-ID is used to indicate the first user group, and the second APN-ID is used to indicate the second user group. Or, the first USER-Group-ID is used to indicate the first user group, and the second USER-Group-ID is used to indicate the second user group. Among them, the first user group is the user group that generates the application message, and the second user group is the user group to which the application message is to be accessed.
[0239] When the first APN-ID includes a first APP-Group-ID and a first USER-Group-ID, and the second APN-ID includes a second APP-Group-ID and a second USER-Group-ID, the first APP-Group-ID is used to indicate the first application group, the second APP-Group-ID is used to indicate the second application group, the first USER-Group-ID is used to indicate the first user group, the second USER-Group-ID is used to indicate the second user group, the first APN-ID is used to indicate the first application group of the first user group, and the second APN-ID is used to indicate the second application group of the second user group.
[0240] As an example, the application message is an IPv6 message, and the first APN-ID and the second APN-ID are carried in the APN header of the IPv6 message.
[0241] Since the APN-ID field in the APN header already carries the first APN-ID, the following will focus on introducing the carrying method of the second APN-ID in the APN header. The carrying method of the second APN-ID in the APN header of the application message can refer to the following carrying methods 1 - 3:
[0242] Carrying method 1: Use the Intent field in the APN header to carry the second APN-ID.
[0243] Specifically, see Figure 5A , Figure 5A which is a schematic structural diagram of an APN header carrying the second APN-ID provided by an embodiment of the present application.
[0244] In the case where the first APN-ID includes a first APP-Group-ID and does not include a first USER-Group-ID, the second APN-ID may include a second APP-Group-ID and not include a second USER-Group-ID, that is, the Intent field may only carry the second APP-Group-ID, and then the second APN-ID is used to indicate the second application group to be accessed by the application message.
[0245] In the case where the first APN-ID includes a first USER-Group-ID and does not include a first APP-Group-ID, the second APN-ID may include a second USER-Group-ID and not include a second APP-Group-ID, that is, the Intent field may only carry the second USER-Group-ID, and then the second APN-ID is used to indicate the second user group to be accessed by the application message.
[0246] When the first APN-ID includes a first APP-Group-ID and a first USER-Group-ID, the second APN-ID includes a second APP-Group-ID and a second USER-Group-ID. That is, the Intent field carries the second APP-Group-ID and the second USER-Group-ID. Then, the second APN-ID is used to indicate the second application group of the second user group to which the application message is to be accessed.
[0247] In summary, the second APN-ID includes at least one of the second APP-Group-ID and the second USER-Group-ID.
[0248] Carrying method 2: Use the Reserved field in the APN-ID field in the APN header to carry the second APN-ID.
[0249] Specifically, see Figure 5B , Figure 5B which is a schematic structural diagram of another APN header carrying the second APN-ID provided by an embodiment of the present application.
[0250] When the first APN-ID includes a first APP-Group-ID and does not include a first USER-Group-ID, the second APN-ID may include a second APP-Group-ID and not include a second USER-Group-ID. That is, the Reserved field may carry only the second APP-Group-ID.
[0251] When the first APN-ID includes a first USER-Group-ID and does not include a first APP-Group-ID, the second APN-ID may include a second USER-Group-ID and not include a second APP-Group-ID. That is, the Reserved field may carry only the second USER-Group-ID.
[0252] When the first APN-ID includes a first APP-Group-ID and a first USER-Group-ID, the second APN-ID includes a second APP-Group-ID and a second USER-Group-ID. That is, the Reserved field carries the second APP-Group-ID and the second USER-Group-ID.
[0253] Carrying method 3: Use the APP-Group-ID field in the APN-ID field of the APN header to carry the second APP-Group-ID, and / or use the USER-Group-ID field in the APN-ID field to carry the second USER-Group-ID, thereby implementing the carrying of the second APN-ID by the APN-ID field.
[0254] Specifically, refer to Figure 5C , Figure 5C which is a schematic structural diagram of another APN header carrying the second APN-ID provided by an embodiment of the present application.
[0255] In the case where the first APN-ID includes the first APP-Group-ID and does not include the first USER-Group-ID, expand the semantics of the APP-Group-ID field in the extended APN-ID field. For example, define the length of the APP-Group-ID field as 32 bits, where the first 16 bits are used to indicate the first application group, and the last 16 bits are used to indicate the second application group. That is, the ID corresponding to the combination of the first 16 bits is the first APP-Group-ID, and the ID corresponding to the combination of the last 16 bits is the second APP-Group-ID, thereby implementing the carrying of the second APN-ID by the APP-Group-ID field in the APN-ID field.
[0256] In the case where the first APN-ID includes the first USER-Group-ID and does not include the first APP-Group-ID, expand the semantics of the USER-Group-ID field in the extended APN-ID field. For example, define the length of the USER-Group-ID field as 32 bits, where the first 16 bits are used to indicate the first user group, and the last 16 bits are used to indicate the second user group. That is, the ID corresponding to the combination of the first 16 bits is the first USER-Group-ID, and the ID corresponding to the combination of the last 16 bits is the second USER-Group-ID, thereby implementing the carrying of the second APN-ID by the USER-Group-ID field in the APN-ID field.
[0257] When the first APN-ID includes a first APP-Group-ID and a first USER-Group-ID, the semantics of the APP-Group-ID field and the USER-Group-ID field in the extended APN-ID field are extended. For example, the length of the APP-Group-ID field is defined as 16 bits, and the length of the USER-Group-ID field is defined as 16 bits. The first 8 bits in the APP-Group-ID field are used to indicate the first application group, and the last 8 bits are used to indicate the second application group. That is, the ID corresponding to the combination of the first 8 bits in the APP-Group-ID field is the first APP-Group-ID, and the ID corresponding to the combination of the last 8 bits is the second APP-Group-ID. The first 8 bits in the USER-Group-ID field are used to indicate the first user group, and the last 8 bits are used to indicate the second user group. That is, the ID corresponding to the combination of the first 8 bits in the USER-Group-ID field is the first USER-Group-ID, and the ID corresponding to the combination of the last 8 bits is the second USER-Group-ID. Thus, the APP-Group-ID field and the USER-Group-ID field in the APN-ID field carry the second APN-ID.
[0258] In some possible implementation manners, the above-mentioned first application group and second application group are the same application group, or the first application group and the second application group are different application groups.
[0259] In a specific implementation manner, when the value of the field carrying the second APP-Group-ID is the first value (for example, all 0s), this field is used to indicate that the second application group is the first application group. When the value of the field carrying the second APP-Group-ID is the second value (for example, all 1s), this field is used to indicate that the second application group is all application groups.
[0260] In the first carrying manner in step S401 above, when the value of the Intent field carrying the second APP-Group-ID is the first value, it is used to indicate that the second application group is the first application group. When the value of the Intent field carrying the second APP-Group-ID is the second value, it is used to indicate that the second application group is all application groups.
[0261] In the second carrying manner in step S401 above, when the value of the Reserved field carrying the second APP-Group-ID is the first value, it is used to indicate that the second application group is the first application group. When the value of the Reserved field carrying the second APP-Group-ID is the second value, it is used to indicate that the second application group is all application groups.
[0262] In the third bearer mode in step S401 above, the values of some APP-Group-ID fields carrying the second APP-Group-ID are the first value, which is used to indicate that the second application group is the first application group. The values of some APP-Group-ID fields carrying the second APP-Group-ID are the second value, which is used to indicate that the second application group is all application groups.
[0263] In some possible implementation manners, the first user group and the second user group are the same user group, or the first user group and the second user group are different user groups.
[0264] In a specific implementation manner, when the value of the field carrying the second USER-Group-ID is the first value (for example, all 0s), this field is used to indicate that the second user group is the first user group. When the value of the field carrying the second USER-Group-ID is the second value (for example, all 1s), this field is used to indicate that the second user group is all user groups.
[0265] In the first bearer mode in step S401 above, the value of the Intent field carrying the second USER-Group-ID is the first value, which is used to indicate that the second user group is the first user group. The value of the Intent field carrying the second USER-Group-ID is the second value, which is used to indicate that the second user group is all user groups.
[0266] In the second bearer mode in step S401 above, the value of the Reserved field carrying the second USER-Group-ID is the first value, which is used to indicate that the second user group is the first user group. The value of the Reserved field carrying the second USER-Group-ID is the second value, which is used to indicate that the second user group is all user groups.
[0267] In the third bearer mode in step S401 above, the values of some USER-Group-ID fields carrying the second USER-Group-ID are the first value, which is used to indicate that the second user group is the first user group. The values of some USER-Group-ID fields carrying the second USER-Group-ID are the second value, which is used to indicate that the second user group is all user groups.
[0268] In some possible implementation manners, the access mode is indicated by using the Flags field in the APN header. The access mode may include a cross-application group access mode, a cross-user group access mode, a cross-application group + user group access mode, and so on. Different values in the Flags field may indicate different access modes. For example, the first two bits (Bit 0 and Bit 1) in the Flags field are used to indicate the access mode. Among them, 00 indicates the cross-application group access mode, 01 indicates the cross-user group access mode, and 10 indicates the cross-application group + user group access mode.
[0269] The above-mentioned cross-application group access mode corresponds to the case where the first APN-ID includes the first APP-Group-ID and does not include the first USER-Group-ID, and the second APN-ID includes the second APP-Group-ID and does not include the second USER-Group-ID.
[0270] The above-mentioned cross-user group access mode corresponds to the case where the first APN-ID includes the first USER-Group-ID and does not include the first APP-Group-ID, and the second APN-ID includes the second USER-Group-ID and does not include the second APP-Group-ID.
[0271] The above-mentioned cross-application group + user group access mode corresponds to the case where the first APN-ID includes the first APP-Group-ID and the first USER-Group-ID, and the second APN-ID includes the second APP-Group-ID and the second USER-Group-ID.
[0272] By using the Flags field in the APN header of the application message, the network device can quickly identify its access mode after receiving the application message, thereby improving the recognition speed and processing speed of the application message.
[0273] It should be understood that the above-mentioned carrying the first APN-ID and the second APN-ID in the APN header of the IPv6 message is only an example, and does not limit that the first APN-ID and the second APN-ID can only be carried in the APN header of the IPv6 message. In some possible embodiments, the first APN-ID and the second APN-ID may also be carried in other extension headers in the IPv6 message.
[0274] In some possible implementation manners, the terminal device generates the above-mentioned application message according to the encapsulation table. Among them, the encapsulation table is composed of the above Figure 3In step S301 of [the above], the management device generates data structures for providing encapsulation operations and decapsulation operations, including matching conditions, encapsulation rules, output interfaces, etc. The terminal device encapsulates the information generated by the first application group according to the content in the encapsulation table, forms the above application message, and sends the application message to the network device through a specified network interface.
[0275] S402: The terminal device sends an application message to the network device.
[0276] Among them, the network device can be Figure 2 network device 113 or network device 131 in the [above] communication system.
[0277] In some possible implementation manners, it can also be that a computing device generates the above Figure 4 application message in step S401 of [the above], and sends the application message to the network device. Among them, the computing device can be Figure 2 computing device 134 in the [above] communication system.
[0278] In summary, by carrying the second APN-ID in the application message, the application group / user group to be accessed can be specified, so that the network device can identify the application group / user group that initiates the access and the application group / user group to be accessed. On the other hand, the embodiments of the present application provide various implementation manners for carrying the second APN-ID. Therefore, it is possible to flexibly select a suitable implementation manner according to user requirements, so that the application message carrying the first APN-ID and the second APN-ID can be applicable to different application scenarios.
[0279] In the case of generating a first control policy based on the Figure 3 shown control method and generating an application message carrying the first APN-ID and the second APN-ID based on the Figure 4 shown message sending method, a forwarding message method for processing the application message carrying the first APN-ID and the second APN-ID according to the first control policy is specifically introduced below. This forwarding message method can support service access scenarios between different application groups.
[0280] See Figure 6A , Figure 6A which is a schematic flowchart of a forwarding message method provided by an embodiment of the present application. The forwarding message method provided by the embodiment of the present application can be applied to the above Figure 2 communication system. As Figure 6A shown, the forwarding message method provided by the embodiment of the present application includes:
[0281] S601: The terminal device sends an application message to the network device.
[0282] Accordingly, the network device receives application packets from the terminal device.
[0283] Among them, the terminal device can be Figure 2 the terminal device 111, terminal device 112, or terminal device 133 in Figure 2 When the terminal device is terminal device 111 or terminal device 112, the network device can be the network device 113 in the communication system of Figure 2 When the terminal device is terminal device 133, the network device can be the network device 132 in the communication system of
[0284] In some possible implementation manners, the application packet includes a first APN-ID and a second APN-ID. The first APN-ID includes the identifier of the first application group that generates the application packet (i.e., the first APP-Group-ID), and the second APN-ID includes the identifier of the second application group to which the application packet is to access (i.e., the second APP-Group-ID). Among them, the application packet can be Figure 4 the application packet in step S401 in
[0285] As an example, the application packet is an IPv6 packet, and the first APN-ID and the second APN-ID are carried in the APN header of the IPv6 packet.
[0286] The carrying manners of the first APN-ID and the second APN-ID can refer to the following carrying manners 1 to 3:
[0287] Carrying manner 1: The APN-ID field in the APN header carries the first APN-ID, and the Intent field in the APN header carries the second APN-ID;
[0288] Carrying manner 2: The APN-ID field in the APN header carries the first APN-ID, and the Reserved field in the APN-ID field in the APN header carries the second APN-ID;
[0289] Carrying manner 3: The APP-Group-ID field in the APN-ID field in the APN header carries the identifier of the first application group (i.e., the first APP-Group-ID) in the first APN-ID and the identifier of the second application group (i.e., the second APP-Group-ID) in the second APN-ID.
[0290] It should be understood that carrying the first APN-ID and the second APN-ID in the APN header of the IPv6 packet as described above is merely an example, and does not limit that the first APN-ID and the second APN-ID can only be carried in the APN header of the IPv6 packet. In some possible embodiments, the first APN-ID and the second APN-ID can also be carried in other extension headers of the IPv6 packet.
[0291] S602: The network device sends an application packet to the device where the second application group is located based on the first control policy.
[0292] Among them, the first control policy can be Figure 3 the first control policy in step S301 in
[0293] In some possible implementation manners, the network device sending an application packet to the device where the second application group is located based on the first control policy includes: when it is determined based on the first control policy that the first application group as the source application is allowed to access the second application group as the destination application, sending an application packet to the device where the second application group is located.
[0294] As an example, the first control policy includes the correspondence between the source application identifier set and the destination application identifier set.
[0295] In a specific implementation manner, the identifiers in the source application identifier set and the identifiers in the destination application identifier set are both APN-IDs. The first APN-ID can indicate the first application group, and the second APN-ID can indicate the second application group. When the first APN-ID belongs to the source application identifier set and the second APN-ID belongs to the destination application identifier set, the network device determines that the first application group as the source application is allowed to access the second application group as the destination application. When the first APN-ID does not belong to the source application identifier set, or the second APN-ID does not belong to the destination application identifier set, the network device determines that the first application group as the source application is not allowed to access the second application group as the destination application, and then the network device does not send an application packet to the device where the second application group is located.
[0296] Next, taking Figure 2 the network device 113 in Figure 3 as an example of the network device, and taking the first control policy A11, the first control policy A21, and the first control policy A31 in step S301 in
[0297] as examples of the first control policy received by the network device, the process of the network device sending an application packet to the device where the second application group is located based on the first control policy is specifically introduced.
[0298] For the first control policy A11—[source application identifier set (A1, A2), destination application identifier set (B1, B3)], since the first APN-ID does not belong to the source application identifier set in the first control policy A11, and the second APN-ID does not belong to the destination application identifier set in the first control policy A11, therefore, the network device does not send application messages to the device where the second application group (i.e., B2) is located (such as Figure 3 the terminal device 133 in Table 3 in step S301 in
[0299] For the first control policy A21—[source application identifier set (A2), destination application identifier set (B5)], since the first APN-ID does not belong to the source application identifier set in the first control policy A21, and the second APN-ID does not belong to the destination application identifier set in the first control policy A21, therefore, the network device does not send application messages to the device where the second application group (B2) is located (such as the terminal device 133).
[0300] For the first control policy A31—[source application identifier set (A3), destination application identifier set (B1, B2, B3, B4)], since the first APN-ID belongs to the source application identifier set in the first control policy A31, and the second APN-ID belongs to the destination application identifier set in the first control policy A31, therefore, the network device determines that the first application group (i.e., A3) as the source application is allowed to access the second application group (i.e., B2) as the destination application, then the network device sends application messages to the device where the second application group (i.e., B2) is located (such as the terminal device 133).
[0301] In summary, regardless of whether the number of application messages carrying the first APN-ID as A3 and the second APN-ID as B2 is one or more, and regardless of whether the device generating the application message is Figure 2 the terminal device 111 or the terminal device 112 in
[0302] In another specific implementation manner, the identifiers in the source application identifier set and the identifiers in the destination application identifier set are both identifiers of application groups. The identifier of the first application group (i.e., the first APP-Group-ID) can indicate the first application group, and the identifier of the second application group (i.e., the second APP-Group-ID) can indicate the second application group. When the first APP-Group-ID belongs to the source application identifier set and the second APP-Group-ID belongs to the destination application identifier set, the network device determines that the first application group as the source application is allowed to access the second application group as the destination application. When the first APP-Group-ID does not belong to the source application identifier set, or the second APP-Group-ID does not belong to the destination application identifier set, the network device determines that the first application group as the source application is not allowed to access the second application group as the destination application, and then the network device does not send application messages to the device where the second application group is located.
[0303] In summary, by adding the second APN-ID to the application message to indicate the application group to be accessed, the network device can identify that the application group to be accessed is the second application group, and then can process the application message according to the corresponding relationship between the first application group and the second application group in the first control policy, thereby supporting the service access scenario between different application groups.
[0304] It can be seen that, compared with setting the access relationship between the source application and the destination application in the way of ACL + five-tuple, this technical solution performs the same processing on application messages with the same first APN-ID and the same second APN-ID based on the corresponding relationship between the source application and the destination application, that is, it does not limit the device where the source application is located and the device where the destination application is located. Therefore, this technical solution controls application messages with a coarser granularity, thereby reducing the impact of factors such as changes in the number of terminal devices in the network, changes in the number of application groups on the terminal device, and changes in the communication relationship between application groups on the maintenance work of access control.
[0305] Based on Figure 3 the shown control method to generate the first control policy and the second control policy, Figure 4 and the shown message sending method to generate application messages carrying the first APN-ID and the second APN-ID, the following specifically introduces a forwarding message method for processing application messages carrying the first APN-ID and the second APN-ID according to the first control policy and the second control policy. This forwarding message method can support both the service access scenario between different application groups and the service access scenario between different user groups.
[0306] See Figure 6B , Figure 6BIt is a schematic flowchart of another method for forwarding packets provided by an embodiment of the present application. The method for forwarding packets provided by the embodiment of the present application can be applied to the above-mentioned Figure 2 communication system. As Figure 6B shown, the method for forwarding packets provided by the embodiment of the present application includes:
[0307] S611: The terminal device sends an application packet to the network device.
[0308] Correspondingly, the network device receives the application packet from the terminal device.
[0309] Among them, the terminal device may be Figure 2 the terminal device 111, terminal device 112 or terminal device 133 in Figure 2 . When the terminal device is the terminal device 111 or terminal device 112, the network device may be Figure 2 the network device 113 in the communication system of
[0310] In some possible implementation manners, the application packet includes a first APN-ID and a second APN-ID. The first APN-ID includes an identifier of a first application group for generating the application packet (i.e., the first APP-Group-ID) and an identifier of a first user group using the first application group (i.e., the first USER-Group-ID). The second APN-ID includes an identifier of a second application group to which the application packet is to be accessed (i.e., the second APP-Group-ID) and an identifier of a second user group using the second application group (i.e., the second USER-Group-ID).
[0311] As an example, the application packet is an IPv6 packet, and the first APN-ID and the second APN-ID are carried in the APN header of the IPv6 packet.
[0312] The carrying manners of the first APN-ID and the second APN-ID can refer to the following carrying manners 1 - 3:
[0313] Carrying manner 1: The APN-ID field in the APN header carries the first APN-ID, and the Intent field in the APN header carries the second APN-ID;
[0314] Carrying manner 2: The APN-ID field in the APN header carries the first APN-ID, and the Reserved field in the APN-ID field in the APN header carries the second APN-ID;
[0315] Carrying method 3: The APP-Group-ID field in the APN-ID field in the APN header carries the identifier of the first application group in the first APN-ID (i.e., the first APP-Group-ID) and the identifier of the second application group in the second APN-ID (i.e., the second APP-Group-ID), and the USER-Group-ID field in the APN-ID field in the APN header carries the identifier of the first user group in the first APN-ID (i.e., the first USER-Group-ID) and the identifier of the second user group in the second APN-ID (i.e., the second USER-Group-ID).
[0316] It should be understood that the above carrying the first APN-ID and the second APN-ID in the APN header of the IPv6 packet is only an example, and does not limit that the first APN-ID and the second APN-ID can only be carried in the APN header of the IPv6 packet. In some possible embodiments, the first APN-ID and the second APN-ID can also be carried in other extension headers in the IPv6 packet.
[0317] S612: The network device sends an application packet to the device where the second application group of the second user group is located based on the first control policy and the second control policy.
[0318] Among them, the first control policy can be Figure 3 the first control policy in step S301 in Figure 3 The second control policy can be
[0319] In some possible implementation manners, the network device sends an application packet to the device where the second application group of the second user group is located based on the first control policy and the second control policy, including: when it is determined based on the first control policy that the first application group as the source application is allowed to access the second application group as the destination application, and it is determined based on the second control policy that the first user group as the source user is allowed to access the second user group as the destination user, sending an application packet to the device where the second application group of the second user group is located.
[0320] As an example, the first control policy includes the correspondence between the source application identifier set and the destination application identifier set, and the second control policy includes the correspondence between the source user identifier set and the destination user identifier set.
[0321] In a specific implementation, the identifiers in the source application identifier set and the identifiers in the destination application identifier set are both identifiers of application groups, and the identifiers in the source user identifier set and the identifiers in the destination user identifier set are both identifiers of user groups. The identifier of the first application group (i.e., the first APP-Group-ID) can indicate the first application group, the identifier of the first user group (i.e., the first USER-Group-ID) can indicate the first user group, and the first APN-ID can indicate the first application group of the first user group. The identifier of the second application group (i.e., the second APP-Group-ID) can indicate the second application group, the identifier of the second user group (i.e., the second USER-Group-ID) can indicate the second user group, and the second APN-ID is used to indicate the second application group of the second user group.
[0322] When the first APP-Group-ID belongs to the source application identifier set, the second APP-Group-ID belongs to the destination application identifier set, the first USER-Group-ID belongs to the source user identifier set, and the second USER-Group-ID belongs to the destination user identifier set, the network device determines that the first application group as the source application is allowed to access the second application group as the destination application, and the first user group as the source user is allowed to access the second user group as the destination user.
[0323] When the first APP-Group-ID does not belong to the source application identifier set, or the second APP-Group-ID does not belong to the destination application identifier set, the network device determines that the first application group as the source application is not allowed to access the second application group as the destination application. When the first USER-Group-ID does not belong to the source user identifier set, or the second USER-Group-ID does not belong to the destination user identifier set, the network device determines that the first user group as the source user is not allowed to access the second user group as the destination user. When the first application group is not allowed to access the second application group, or the first user group is not allowed to access the second user group, the network device does not send an application message to the device where the second application group of the second user group is located.
[0324] In summary, by adding the second APN-ID to the application message to specify the application to be accessed, the network device can identify that the application to be accessed is the second user group using the second application group, and then can process the application message according to the corresponding relationship between the first application group and the second application group in the first control policy, and the corresponding relationship between the first user group and the second user group in the second control policy, so as to support the service access scenarios between different application groups or support the service access scenarios between different user groups.
[0325] It can be seen that, compared with the method of setting the access relationship between the source application and the destination application through ACL + five-tuple, the technical solution in this application performs the same processing on application packets with the same first APN-ID and the same second APN-ID based on the corresponding relationship between the source application and the destination application, that is, it does not limit the devices where the source application is located and the devices where the destination application is located. Therefore, the technical solution in this application controls application packets with a coarser granularity, thereby reducing the impact of factors such as changes in the number of terminal devices in the network, changes in the number of applications on terminal devices, and changes in the communication relationships between applications on the maintenance work of access control.
[0326] When generating a second control policy based on the Figure 3 control method shown, and Figure 4 generating an application packet carrying the first APN-ID and the second APN-ID based on the sending packet method shown, the following specifically introduces a forwarding packet method for processing the application packet carrying the first APN-ID and the second APN-ID according to the second control policy. This forwarding packet method can support service access scenarios between different user groups.
[0327] Refer to Figure 6C , Figure 6C which is a schematic flowchart of another forwarding packet method provided by an embodiment of this application. The forwarding packet method provided by an embodiment of this application can be applied to the Figure 2 communication system described above. As Figure 6C shown, the forwarding packet method provided by an embodiment of this application includes:
[0328] S621: The terminal device sends an application packet to the network device.
[0329] Correspondingly, the network device receives the application packet from the terminal device.
[0330] In some possible implementation manners, the application packet includes a first APN-ID and a second APN-ID. The first APN-ID includes the identifier of the first user group that generates the application packet (i.e., the first USER-Group-ID), and the second APN-ID includes the identifier of the second user group that the application packet is to access (i.e., the second USER-Group-ID). Among them, the application packet can be the Figure 4 application packet in step S401 in
[0331] As an example, the application packet is an IPv6 packet, and the first APN-ID and the second APN-ID are carried in the APN header of the IPv6 packet.
[0332] The carrying manners of the first APN-ID and the second APN-ID can refer to the following carrying manners 1 - 3:
[0333] Carrying method 1: The APN-ID field in the APN header carries the first APN-ID, and the Intent field in the APN header carries the second APN-ID;
[0334] Carrying method 2: The APN-ID field in the APN header carries the first APN-ID, and the Reserved field in the APN-ID field in the APN header carries the second APN-ID;
[0335] Carrying method 3: The USER-Group-ID field in the APN-ID field in the APN header carries the identifier of the first user group (i.e., the first USER-Group-ID) in the first APN-ID and the identifier of the second user group (i.e., the second USER-Group-ID) in the second APN-ID.
[0336] It should be understood that carrying the first APN-ID and the second APN-ID in the APN header of the IPv6 packet is only an example, and does not limit that the first APN-ID and the second APN-ID can only be carried in the APN header of the IPv6 packet. In some possible embodiments, the first APN-ID and the second APN-ID can also be carried in other extension headers in the IPv6 packet.
[0337] S622: The network device sends an application packet to the device where the second user group is located based on the control policy.
[0338] Among them, the control policy can be Figure 3 the second control policy in step S301 in
[0339] In some possible implementation manners, the network device sends an application packet to the device where the second user group is located based on the second control policy, including: when it is determined based on the second control policy that the first user group as the source user is allowed to access the second user group as the destination user, sending an application packet to the device where the second user group is located.
[0340] As an example, the second control policy includes the correspondence between the source user identifier set and the destination user identifier set.
[0341] In a specific implementation, the identifiers in the source user identifier set and the identifiers in the destination user identifier set are both APN-IDs. The first APN-ID may indicate a first user group, and the second APN-ID may indicate a second user group. When the first APN-ID belongs to the source user identifier set and the second APN-ID belongs to the destination user identifier set, the network device determines that the first user group as the source user is allowed to access the second user group as the destination user. When the first APN-ID does not belong to the source user identifier set, or the second APN-ID does not belong to the destination user identifier set, the network device determines that the first user group as the source user is not allowed to access the second user group as the destination user, and then the network device does not send user packets to the device where the second user group is located.
[0342] In another specific implementation, the identifiers in the source user identifier set and the identifiers in the destination user identifier set are both identifiers of user groups. The identifier of the first user group (i.e., the first USER-Group-ID) may indicate the first user group, and the identifier of the second user group (i.e., the second USER-Group-ID) may indicate the second user group. When the first USER-Group-ID belongs to the source user identifier set and the second USER-Group-ID belongs to the destination user identifier set, the network device determines that the first user group as the source user is allowed to access the second user group as the destination user. When the first USER-Group-ID does not belong to the source user identifier set, or the second USER-Group-ID does not belong to the destination user identifier set, the network device determines that the first user group as the source user is not allowed to access the second user group as the destination user, and then the network device does not send user packets to the device where the second user group is located.
[0343] In summary, by adding the second APN-ID to the application packet to indicate the user group to be accessed, the network device can identify that the user group to be accessed is the second user group, and then can process the application packet according to the corresponding relationship between the first user group and the second user group in the control policy, so as to support the service access scenarios between different user groups.
[0344] It can be seen that, compared with setting the access relationship between the source user and the destination user through the ACL+five-tuple method, this technical solution performs the same processing on application packets with the same first APN-ID and the same second APN-ID based on the corresponding relationship between the source user and the destination user, that is, it does not limit the device where the source user is located and the device where the destination user is located. Therefore, this technical solution controls application packets with a coarser granularity, thereby reducing the impact of factors such as changes in the number of terminal devices in the network, changes in the number of user groups on terminal devices, and changes in the communication relationship between user groups on the maintenance work of access control.
[0345] In some possible implementations, the network device in step S601 above may also receive application messages from a computing device. Among them, the computing device may be Figure 6A the computing device 134 in the communication system of Figure 2 . The network device may be Figure 2 the network device 132 in the communication system of Figure 4 . The application message may be Figure 6B the application message in step S401 above. Similarly, the network device in step S611 above may also receive application messages from a computing device. The above Figure 6C The network device in step S621 may also receive application messages from a computing device.
[0346] In some other possible implementations, the network device in step S601 above may also receive application messages from another network device. Among them, these two network devices may be in the same network. For example, Figure 6A the network device 121 and the network device 122 in Figure 2 ; Figure 2 the network device 131 and the network device 132 in Figure 2 . Or, these two network devices may be in different networks. For example, Figure 2 the network device 113 and the network device 121 in Figure 4 ; Figure 6B the network device 124 and the network device 131 in Figure 6C . The application message may be
[0347] Referring to Figure 7 , Figure 7 is a schematic structural diagram of a control device provided by an embodiment of the present application. The control device 700 may be used to implement the foregoing Figure 3 control method. As shown in Figure 7 , the control device 700 includes: a generating unit 701,
[0348] The generating unit 701 is used to generate a control policy. The control policy includes the correspondence between the first application group and the second application group, and the control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0349] In some possible implementations, the control policy includes the correspondence between the set of source application identifiers and the set of destination application identifiers, and the control policy is used to indicate that the application group indicated by any identifier in the set of source application identifiers is allowed to access the application group indicated by any identifier in the set of destination application identifiers, where the set of source application identifiers includes an identifier for indicating a first application group, and the set of destination application identifiers includes an identifier for indicating a second application group.
[0350] In some possible implementations, the control device 700 further includes a sending unit 702, and the sending unit 702 is configured to send a control policy to a network device so that the network device forwards packets based on the control policy.
[0351] In some possible implementations, the control device 700 further includes a sending unit 702, and the sending unit 702 is configured to send a control policy to a network controller.
[0352] Among them, the above-mentioned generating unit 701 and sending unit 702 can be implemented by software or by hardware. Exemplarily, next, taking the generating unit 701 as an example, the implementation manner of the generating unit 701 will be introduced. Similarly, the implementation manner of the sending unit 702 can refer to the implementation manner of the generating unit 701.
[0353] Taking the unit as an example of a software functional unit, the generating unit 701 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the generating unit 701 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically adjacent data centers. Among them, generally one region may include multiple AZs.
[0354] Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same virtual private cloud (VPC), or may be distributed in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.
[0355] As an example of a hardware functional unit, the generating unit 701 may include at least one computing device, such as a server, etc. Alternatively, the generating unit 701 may also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0356] The multiple computing devices included in the generating unit 701 may be distributed in the same region or in different regions. The multiple computing devices included in the generating unit 701 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the generating unit 701 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0357] It should be noted that in other embodiments, the generating unit 701 may be used to execute any step in the control method, the sending unit 702 may be used to execute any step in the control method, and the steps to be implemented by the generating unit 701 and the sending unit 702 may be specified as needed. The control device 700 realizes all its functions by implementing different steps in the control method through the generating unit 701 and the sending unit 702 respectively.
[0358] See Figure 8 , Figure 8 is a schematic structural diagram of a message sending device provided by an embodiment of the present application. The message sending device 800 may be used to implement the foregoing Figure 4 message sending method. As Figure 8 shown, the message sending device 800 includes: a generating unit 801 and a sending unit 802,
[0359] The generating unit 801 is used to generate an application message, and the application message includes a first APN-ID and a second APN-ID. Among them, the first APN-ID includes the identifier of the first application group that generates the application message, and the second APN-ID includes the identifier of the second application group to be accessed by the application message;
[0360] The sending unit 802 is configured to send application messages to a network device. The first APN-ID and the second APN-ID in the application messages are used for the network device to send application messages to the devices where the second application group is located based on a first control policy. The first control policy includes the corresponding relationship between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0361] In some possible implementation manners, the first control policy includes the corresponding relationship between the source application identifier set and the destination application identifier set, and the first control policy is used to indicate that the application group indicated by any identifier in the source application identifier set is allowed to access the application group indicated by any identifier in the destination application identifier set. The source application identifier set includes an identifier for indicating the first application group, and the destination application identifier set includes an identifier for indicating the second application group.
[0362] In some possible implementation manners, the application message is an IPv6 message. The application message includes an APN header. Carrying the second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried through the Intent field in the APN header; in the second implementation manner, the second APN-ID is carried through the Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried through the APP-Group-ID field in the APN-ID field in the APN header.
[0363] In some possible implementation manners, the Flags field in the APN header is used to indicate that the access mode is a cross-application group access mode.
[0364] In some possible implementation manners, the first APN-ID further includes the identifier of the first user group using the first application group, and the second APN-ID further includes the identifier of the second user group using the second application group. The identifier of the first user group and the identifier of the second user group are used for the network device to send application messages to the devices where the second application group of the second user group is located based on a second control policy. The second control policy includes the corresponding relationship between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0365] In some possible implementation manners, the second control policy includes the correspondence between the source user identity set and the destination user identity set, and the second control policy is used to indicate that the user group indicated by any identity in the source user identity set is allowed to access the user group indicated by any identity in the destination user identity set, where the source user identity set includes the identity used to indicate the first user group, and the destination user identity set includes the identity used to indicate the second user group.
[0366] Among them, the above-mentioned generating unit 801 and sending unit 802 can be implemented by software or by hardware. Exemplarily, next, taking the generating unit 801 as an example, the implementation manner of the generating unit 801 will be introduced. Similarly, the implementation manner of the sending unit 802 can refer to the implementation manner of the generating unit 801.
[0367] As an example of a software functional unit, the generating unit 801 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the generating unit 801 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs.
[0368] Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same virtual private cloud (VPC), or may be distributed in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is realized through the communication gateway.
[0369] As an example of a hardware functional unit, the generating unit 801 may include at least one computing device, such as a server or the like. Alternatively, the generating unit 801 may also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0370] The multiple computing devices included in the generating unit 801 may be distributed in the same region or in different regions. The multiple computing devices included in the generating unit 801 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the generating unit 801 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0371] It should be noted that in other embodiments, the generating unit 801 may be used to execute any step in the method of sending a message, and the sending unit 802 may be used to execute any step in the method of sending a message. The steps implemented by the generating unit 801 and the sending unit 802 can be specified as needed, and all functions of the message sending device 800 are implemented by respectively implementing different steps in the message sending method through the generating unit 801 and the sending unit 802.
[0372] See Figure 9 , Figure 9 is a schematic structural diagram of a message forwarding device provided by an embodiment of the present application. As Figure 9 shown, the message forwarding device 900 includes: a receiving unit 901 and a sending unit 902.
[0373] In one implementation manner, the message forwarding device 900 is the network device in the above embodiment. The message forwarding device 900 executes the method on the network device side described in the above Figure 6A embodiment or Figure 6B embodiment.
[0374] Among them, the receiving unit 901 is used to receive an application message, and the application message includes a first APN-ID and a second APN-ID. Among them, the first APN-ID includes the identifier of the first application group that generates the application message, and the second APN-ID includes the identifier of the second application group to which the application message is to be accessed; the sending unit 902 is used to send the application message to the device where the second application group is located based on the first control policy. Among them, the first control policy includes the corresponding relationship between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
[0375] In some possible implementation manners, the first application group and the second application group are the same application group, or the first application group and the second application group are different application groups.
[0376] In some possible implementation manners, the first control policy includes the corresponding relationship between the source application identifier set and the destination application identifier set, and the first control policy is used to indicate that the application group indicated by any identifier in the source application identifier set is allowed to access the application group indicated by any identifier in the destination application identifier set. Among them, the source application identifier set contains the identifier used to indicate the first application group, and the destination application identifier set contains the identifier used to indicate the second application group.
[0377] In some possible implementation manners, the identifiers in the source application identifier set and the identifiers in the destination application identifier set include at least one of the following two implementation manners: In the first implementation manner, the APN-ID is used as the identifier in the source application identifier set and the identifier in the destination application identifier set; in the second implementation manner, the identifier of the application group is used as the identifier in the source application identifier set and the identifier in the destination application identifier set.
[0378] In some possible implementation manners, the application message is an IPv6 message, and the application message includes an APN header. Then, carrying the second APN-ID includes at least one of the following three implementation manners: In the first implementation manner, the second APN-ID is carried through the Intent field in the APN header; in the second implementation manner, the second APN-ID is carried through the Reserved field in the APN-ID field in the APN header; in the third implementation manner, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried through the APP-Group-ID field in the APN-ID field in the APN header.
[0379] In some possible implementation manners, the Flags field in the APN header is used to indicate that the access mode is a cross-application group access mode.
[0380] In some possible implementations, the receiving unit 901 is further configured to receive a first control policy sent by a management device before receiving an application message.
[0381] In some possible implementations, the message forwarding device 900 includes one or more of a gateway, a firewall, a router, a switch, and a load balancer.
[0382] Exemplarily, the message forwarding device 900 is configured to implement Figure 6A the method on the network device side described in the embodiment. In Figure 6A the embodiment, the receiving unit 901 is configured to execute S601, and the sending unit 902 is configured to execute S602. In some possible embodiments, the message forwarding device 900 is configured to implement Figure 6B the method on the network device side described in the embodiment. In Figure 6B the embodiment, the receiving unit 901 is configured to execute S611, and the sending unit 902 is configured to execute S612, which will not be elaborated herein.
[0383] In another implementation, the message forwarding device 900 is the network device in the above embodiment. The message forwarding device 900 executes the Figure 6C method on the network device side described in the above embodiment.
[0384] The receiving unit 901 is configured to receive an application message, where the application message includes a first APN-ID and a second APN-ID. The first APN-ID includes an identifier of a first user group that generates the application message, and the second APN-ID includes an identifier of a second user group to which the application message is to be accessed.
[0385] The sending unit 902 is configured to send the above application message to the device where the second user group is located based on a control policy. The control policy includes a corresponding relationship between the first user group and the second user group, and the control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
[0386] In some possible implementations, the control policy includes a corresponding relationship between a source user identifier set and a destination user identifier set, and the control policy is used to indicate that any user group indicated by an identifier in the source user identifier set is allowed to access any user group indicated by an identifier in the destination user identifier set. The source user identifier set includes an identifier for indicating the first user group, and the destination user identifier set includes an identifier for indicating the second user group.
[0387] In some possible implementations, the application message is an IPv6 message. If the application message includes an APN header, carrying the second APN-ID includes at least one of the following three implementations: In the first implementation, the second APN-ID is carried in the Intent field in the APN header; in the second implementation, the second APN-ID is carried in the Reserved field in the APN-ID field in the APN header; in the third implementation, the identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are carried in the APP-Group-ID field in the APN-ID field in the APN header.
[0388] In some possible implementations, the Flags field in the APN header is used to indicate that the access mode is a cross-user group access mode.
[0389] Exemplarily, the forwarding message device 900 is used to implement Figure 6C the method on the network device side described in the embodiment. In Figure 6C the embodiment, the receiving unit 901 is used to execute S621, and the sending unit 902 is used to execute S622.
[0390] Among them, the above receiving unit 901 and sending unit 902 can both be implemented by software or can be implemented by hardware. Exemplarily, next, taking the receiving unit 901 as an example, the implementation manner of the receiving unit 901 is introduced. Similarly, the implementation manner of the sending unit 902 can refer to the implementation manner of the receiving unit 901.
[0391] As an example of a software functional unit, the receiving unit 901 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance may be one or more. For example, the receiving unit 901 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region, or may be distributed in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ), or may be distributed in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally a region may include multiple AZs.
[0392] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, one VPC is set up in one region. To enable cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC, and the interconnection between VPCs is achieved through the communication gateway.
[0393] As an example of a hardware functional unit, the receiving unit 901 may include at least one computing device, such as a server. Alternatively, the receiving unit 901 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0394] The multiple computing devices included in the receiving unit 901 can be distributed in the same region or in different regions. The multiple computing devices included in the receiving unit 901 can be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the receiving unit 901 can be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0395] It should be noted that in other embodiments, the receiving unit 901 can be used to execute any step in the method of forwarding packets, and the sending unit 902 can be used to execute any step in the method of forwarding packets. The steps to be implemented by the receiving unit 901 and the sending unit 902 can be specified as needed. By implementing different steps in the method of forwarding packets through the receiving unit 901 and the sending unit 902 respectively, all functions of the packet forwarding device 900 can be realized.
[0396] See Figure 10 , Figure 10 is a schematic structural diagram of a communication device provided by an embodiment of the present application. As Figure 10As shown in the figure, the communication device 1000 provided by the embodiment of the present application includes: a bus 1001, a processor 1002, a memory 1003, and a communication interface 1004. The processor 1002, the memory 1003, and the communication interface 1004 communicate with each other through the bus 1001. The communication device 1000 may be a server or a terminal device. It should be understood that the embodiment of the present application does not limit the number of processors and memories in the communication device 1000.
[0397] In a specific implementation manner, the communication device 1000 is the management device in the foregoing Figure 3 control method and can be used to implement the foregoing Figure 3 control method.
[0398] In another specific implementation manner, the communication device 1000 is the terminal device in the foregoing Figure 4 method for sending packets and can be used to implement the foregoing Figure 4 method for sending packets.
[0399] In another specific implementation manner, the communication device 1000 is the network device in the foregoing Figure 6A method for forwarding packets and can be used to execute the steps performed by the network device in the foregoing Figure 6A method for forwarding packets. Or, the communication device 1000 is the network device in the foregoing Figure 6B method for forwarding packets and can be used to execute the steps performed by the network device in the foregoing Figure 6B method for forwarding packets. Or, the communication device 1000 is the network device in the foregoing Figure 6C method for forwarding packets and can be used to execute the steps performed by the network device in the foregoing Figure 6C method for forwarding packets.
[0400] The bus 1001 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 10 only one line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus. The bus 1001 may include a path for transmitting information between various components of the communication device 1000 (for example, the memory 1003, the processor 1002, and the communication interface 1004).
[0401] The processor 1002 may include any one or more of processors such as a central processing unit (CPU), a graphics processing unit (GPU), a micro processor (MP), or a digital signal processor (DSP).
[0402] The memory 1003 may include a volatile memory, such as a random access memory (RAM). The memory 1003 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0403] The memory 1003 stores executable program codes, and the processor 1002 executes the executable program codes to respectively implement the functions of the foregoing generating unit 701 and sending unit 702, thereby implementing the foregoing Figure 3 control method. That is, the memory 1003 stores instructions for executing the control method.
[0404] Alternatively, the memory 1003 stores executable program codes, and the processor 1002 executes the executable program codes to respectively implement the functions of the foregoing generating unit 801 and sending unit 802, thereby implementing the foregoing Figure 4 message sending method. That is, the memory 1003 stores instructions for executing the message sending method.
[0405] Alternatively, the memory 1003 stores executable program codes, and the processor 1002 executes the executable program codes to respectively implement the functions of the foregoing receiving unit 901 and sending unit 902, thereby executing the steps performed by the network device in the foregoing Figure 6A message forwarding method, or executing the steps performed by the network device in the foregoing Figure 6B message forwarding method, or executing the steps performed by the network device in the foregoing Figure 6C message forwarding method. That is, the memory 1003 stores instructions for executing the message forwarding method.
[0406] The communication interface 1004 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the communication device 1000 and other communication devices or communication networks.
[0407] The embodiment of the present application also provides a network system, which includes a terminal device and a network device. Among them, the terminal device is used to implement the foregoing Figure 4 method for sending packets. The network device is used to implement the steps executed by the network device in the foregoing Figure 6A method for forwarding packets, or the network device is used to implement the steps executed by the network device in the foregoing Figure 6B method for forwarding packets, or the network device is used to implement the steps executed by the network device in the foregoing Figure 6C method for forwarding packets.
[0408] In some possible implementation manners, the network system further includes a management device. The management device is used to implement the foregoing Figure 3 control method.
[0409] The embodiment of the present application also provides a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on a computing device, it causes the computing device to execute one or more of the foregoing control methods, packet sending methods, and packet forwarding methods.
[0410] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute one or more of the foregoing control methods, packet sending methods, and packet forwarding methods.
[0411] It should be understood that in the embodiments of the present invention, "when...", "... when", or "if" all refer to the device making corresponding processing under a certain objective situation, which does not limit the time, and it is not required that the device must have a judgment action when implemented, nor does it mean that there are other limitations.
[0412] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for forwarding packets, characterized in that, The method includes: Receiving an application message, where the application message includes a first Application Perception Network Identifier (APN-ID) and a second APN-ID. Among them, the first APN-ID includes the identifier of the first application group that generates the application message, and the second APN-ID includes the identifier of the second application group to which the application message is to be accessed; Sending the application message to the device where the second application group is located based on a first control policy. Among them, the first control policy includes the correspondence between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
2. The method according to claim 1, wherein The first application group and the second application group are different application groups.
3. The method according to claim 1 or 2, characterized in that The first control policy includes the correspondence between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application, including: The first control policy includes the correspondence between a source application identifier set and a destination application identifier set. The first control policy is used to indicate that any application group indicated by an identifier in the source application identifier set is allowed to access any application group indicated by an identifier in the destination application identifier set. Among them, the source application identifier set contains the identifier used to indicate the first application group, and the destination application identifier set contains the identifier used to indicate the second application group.
4. The method according to claim 3, wherein The identifiers in the source application identifier set and the identifiers in the destination application identifier set are both APN-IDs.
5. The method according to claim 3, characterized in that, The identifiers in the source application identifier set and the identifiers in the destination application identifier set are both identifiers of application groups.
6. The method according to any one of claims 1-5, characterized in that, The application message is an IPv6 message. The application message includes an APN header, and the APN header includes an Intent field, and the second APN-ID is carried by the Intent field.
7. The method according to any one of claims 1-5, characterized in that, The application message is an IPv6 message. The application message includes an APN header, and the APN header includes an APN-ID field, and the second APN-ID is carried by the Reserved field in the APN-ID field.
8. The method according to any one of claims 1-5, characterized in that The application message is an IPv6 message. The application message includes an APN header, and the APN header includes an APN-ID field. The identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are both carried by the Application Group Identifier (APP-Group-ID) field in the APN-ID field.
9. The method according to any one of claims 1-8, characterized in that, The application message is an IPv6 message. The application message includes an APN header, and the Flags field in the APN header indicates that the access mode is a cross-application group access mode.
10. The method according to any one of claims 1-9, characterized in that, The first APN-ID further includes the identifier of the first user group using the first application group, and the second APN-ID further includes the identifier of the second user group using the second application group. Sending the application message to the device where the second application group is located based on the first control policy includes: Send the application message to the device where the second application group of the second user group is located based on the first control policy and the second control policy; Among them, the second control policy includes the correspondence between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
11. The method according to claim 10, wherein The second control policy includes the correspondence between the first user group and the second user group, and the second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user, including: The second control policy includes the correspondence between the source user identifier set and the destination user identifier set, and the second control policy is used to indicate that any user group indicated by an identifier in the source user identifier set is allowed to access any user group indicated by an identifier in the destination user identifier set, where the source user identifier set contains an identifier for indicating the first user group, and the destination user identifier set contains an identifier for indicating the second user group.
12. The method according to any one of claims 1-11, characterized in that, Before receiving the application message, the method further includes: Receive the first control policy sent by the management device.
13. The method according to any one of claims 1-12, characterized in that, The method is applied to one or more of a gateway, a firewall, a router, a switch, and a load balancer.
14. A method for sending a message, characterized in that, The method includes: Generate an application message, where the application message includes a first Application Perception Network Identifier (APN-ID) and a second APN-ID. Among them, the first APN-ID includes the identifier of the first application group that generates the application message, and the second APN-ID includes the identifier of the second application group that the application message is to access; Send the application message to the network device. The first APN-ID and the second APN-ID in the application message are used for the network device to send the application message to the device where the second application group is located based on the first control policy. Among them, the first control policy includes the correspondence between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
15. The method according to claim 14, wherein The first control policy includes the correspondence between the first application group and the second application group, and the first control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application, including: The first control policy includes the correspondence between the source application identifier set and the destination application identifier set, and the first control policy is used to indicate that any application group indicated by an identifier in the source application identifier set is allowed to access any application group indicated by an identifier in the destination application identifier set, where the source application identifier set contains an identifier for indicating the first application group, and the destination application identifier set contains an identifier for indicating the second application group.
16. The method according to claim 14 or 15, characterized in that, The application message is an IPv6 message, the application message includes an APN header, the APN header includes an Intent field, and the second APN-ID is carried by the Intent field.
17. The method according to claim 14 or 15, characterized in that, The application message is an IPv6 message. The application message includes an APN header. The APN header includes an APN-ID field. The second APN-ID is carried by the Reserved field in the APN-ID field.
18. The method according to claim 14 or 15, characterized in that, The application message is an IPv6 message. The application message includes an APN header. The APN header includes an APN-ID field. The identifier of the first application group in the first APN-ID and the identifier of the second application group in the second APN-ID are both carried by the APP-Group-ID field in the APN-ID field.
19. The method according to any one of claims 14-18, characterized in that, The application message is an IPv6 message. The application message includes an APN header. The Flags field in the APN header indicates that the access mode is a cross-application group access mode.
20. The method according to any one of claims 14 - 19, characterized in that, The first APN-ID further includes the identifier of the first user group using the first application group. The second APN-ID further includes the identifier of the second user group using the second application group. The identifier of the first user group and the identifier of the second user group are used for the network device to send the application message to the device where the second application group of the second user group is located based on a second control policy. Wherein, the second control policy includes the corresponding relationship between the first user group and the second user group. The second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
21. The method according to claim 20, characterized in that, The second control policy includes the corresponding relationship between the first user group and the second user group. The second control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user, including: The second control policy includes the corresponding relationship between the source user identifier set and the destination user identifier set. The second control policy is used to indicate that any user group indicated by an identifier in the source user identifier set is allowed to access any user group indicated by an identifier in the destination user identifier set. Wherein, the source user identifier set contains the identifier used to indicate the first user group, and the destination user identifier set contains the identifier used to indicate the second user group.
22. A control method, characterized in that, The method includes: Generating a control policy. The control policy includes the corresponding relationship between the first application group and the second application group. The control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application.
23. The method according to claim 22, wherein The control policy includes the corresponding relationship between the first application group and the second application group. The control policy is used to indicate that the first application group as the source application is allowed to access the second application group as the destination application, including: The control policy includes the correspondence between the source application identifier set and the destination application identifier set. The control policy is used to indicate that the application group indicated by any identifier in the source application identifier set is allowed to access the application group indicated by any identifier in the destination application identifier set, where the source application identifier set contains the identifier for indicating the first application group, and the destination application identifier set contains the identifier for indicating the second application group.
24. The method according to claim 22 or 23, characterized in that The method further includes: Sending the control policy to a network device so that the network device forwards application packets based on the control policy.
25. The method according to claim 22, characterized in that, The method further includes: Sending the control policy to a network controller.
26. A method for forwarding packets, characterized in that, The method includes: Receiving an application packet, where the application packet includes a first Application Perception Network Identifier (APN-ID) and a second APN-ID. The first APN-ID includes the identifier of the first user group that generates the application packet, and the second APN-ID includes the identifier of the second user group that the application packet is to access. Sending the application packet to the device where the second user group is located based on a control policy, where the control policy includes the correspondence between the first user group and the second user group, and the control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user.
27. The method according to claim 26, wherein The control policy includes the correspondence between the first user group and the second user group, and the control policy is used to indicate that the first user group as the source user is allowed to access the second user group as the destination user, including: The control policy includes the correspondence between the source user identifier set and the destination user identifier set. The control policy is used to indicate that the user group indicated by any identifier in the source user identifier set is allowed to access the user group indicated by any identifier in the destination user identifier set, where the source user identifier set contains the identifier for indicating the first user group, and the destination user identifier set contains the identifier for indicating the second user group.
28. The method according to claim 26 or 27, characterized in that, The application packet is an IPv6 packet. The application packet includes an APN header, and the APN header includes an Intent field, and the second APN-ID is carried by the Intent field.
29. The method according to claim 26 or 27, characterized in that, The application packet is an IPv6 packet. The application packet includes an APN header, and the APN header includes an APN-ID field, and the second APN-ID is carried by the Reserved field in the APN-ID field.
30. The method according to claim 26 or 27, characterized in that, The application packet is an IPv6 packet. The application packet includes an APN header, and the APN header includes an APN-ID field. The identifier of the first user group in the first APN-ID and the identifier of the second user group in the second APN-ID are both carried by the User Group Identifier (USER-Group-ID) field in the APN-ID field.
31. The method according to any one of claims 26 - 30, characterized in that, The application packet is an IPv6 packet. The application packet includes an APN header, and the Flags field in the APN header indicates that the access mode is a cross-user-group access mode.
32. A communication device, characterized in that, The device includes a memory and a processor. The memory stores computer program instructions, and the processor runs the computer program instructions to cause the device to execute the method according to any one of claims 1-13, or execute the method according to any one of claims 14-21, or execute the method according to any one of claims 22-25, or execute the method according to any one of claims 26-31.
33. A network system, characterized in that, It includes a network device and a terminal device. The network device is used to implement the method according to any one of claims 1-13, or the network device is used to implement the method according to any one of claims 26-31, and the terminal device is used to implement the method according to any one of claims 14-21.
34. The system according to claim 33, wherein The system further includes a management device, and the management device is used to implement the method according to any one of claims 22-25.
35. A computer-readable storage medium, characterized in that, It includes computer program instructions, which, when run by a processor, implement the method according to any one of claims 1-13, or implement the method according to any one of claims 14-21, or implement the method according to any one of claims 22-25, or implement the method according to any one of claims 26-31.