Access control method, device and system

By encoding the service group of the target service into the same bitmap, the network device can quickly determine the access rights of the user device, solving the problem of forwarding performance degradation caused by multiple lookups and achieving efficient access control.

CN120675728APending Publication Date: 2025-09-19HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410316188.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-19
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In the prior art, when a network device processes multiple service groups, it needs to search the UCL rule table multiple times, resulting in a decrease in forwarding performance.

Method used

At least one service group of the target service is encoded into the same bitmap, and the access rights of the user device to the service group can be determined through one search, thereby reducing the number of searches.

Benefits of technology

It ensures the forwarding performance of network devices, reduces the number of lookups, and lowers resource overhead and storage costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675728A_ABST
    Figure CN120675728A_ABST
Patent Text Reader

Abstract

The invention discloses an access control method, device and system, and belongs to the technical field of networks. A network device receives a first message from a user equipment, the first message comprising user information and service information, the user information being used for indicating the user equipment, and the service information being used for indicating a target service accessed by the user equipment. The network equipment determines an access range according to the service information, the access range comprises a first bitmap, the first bitmap is used for indicating at least one service group comprising the target service, each service group comprises at least one service, and the at least one service group comprises the first service group. And the network equipment determines the access authority of the user equipment to the first service group according to the user information and the access range. In the application, the number of times of searching in the process of determining the access authority of the user equipment to the first service group by the network equipment is relatively small, so that the forwarding performance of the network equipment can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network technology, and in particular to an access control method, device, and system. Background Art

[0002] Network devices can process messages from user devices for accessing network services based on user control list (UCL) rules to control access to the user devices. UCL rules typically include the identifier of a user group, the identifier of a service group, and the access rights granted to the user group to access the service group. UCL rules are typically stored as table entries in network devices.

[0003] For example, after a network device receives a message from a user device, the network device determines the user group to which the user device belongs based on the source Internet Protocol (IP) address of the message. The network device determines the service group to which the service accessed by the user device belongs based on the destination IP address of the message. The network device searches the UCL rule table based on the identifier of the user group to which the user device belongs and the identifier of the service group to which the service accessed by the user device belongs, so as to determine a UCL rule table entry that matches both the identifier of the user group to which the user device belongs and the identifier of the service group to which the service accessed by the user device belongs. The network device determines the access right of the user device to the service group based on the UCL rule table entry that matches both the identifier of the user group to which the user device belongs and the identifier of the service group to which the service accessed by the user device belongs. The network device processes the message based on the access right.

[0004] However, when a service belongs to multiple service groups, the network device needs to search the UCL rule table multiple times to determine the user device's access rights to the service group to which the service accessed by the user device belongs, which can easily lead to a decrease in the forwarding performance of the network device. Summary of the Invention

[0005] The present application provides an access control method, device, and system. The technical solution of the present application is as follows.

[0006] In a first aspect, an access control method is provided, the method comprising: receiving a first message from a user device, the first message comprising user information and service information, the user information being used to indicate the user device, and the service information being used to indicate a target service accessed by the user device; determining an access scope based on the service information, the access scope comprising a first bitmap being used to indicate at least one service group including the target service, each service group comprising at least one service, the at least one service group comprising a first service group; and determining the user device's access rights to the first service group based on the user information and the access scope. The method is performed by a network device.

[0007] For example, the first bitmap includes multiple bits, at least one bit of the multiple bits corresponds one-to-one with the at least one service group. For example, the multiple bits correspond one-to-one with multiple service groups, and the multiple service groups include the at least one service group.

[0008] The technical solution provided by this application includes a first bitmap in the access scope, which is used to indicate at least one service group including the target service. That is, at least one service group including the target service is encoded in the same bitmap. Therefore, after the network device determines the access scope based on the service information indicating the target service in the first message, the network device can determine the user device's access rights to the first service group in the at least one service group through a single lookup based on the access scope and the user information in the first message. The network device requires fewer searches to determine the user device's access rights to the first service group, thereby ensuring the network device's forwarding performance.

[0009] Optionally, determining the access scope according to the service information includes: determining the access scope according to the service information and a first mapping relationship, where the first mapping relationship includes a mapping relationship between the service information and the access scope.

[0010] Optionally, the method further includes: receiving a first mapping relationship sent by the controller.

[0011] The technical solution provided by the present application is that the network device receives the first mapping relationship sent by the controller, which can facilitate the network device to determine the access scope according to the first mapping relationship and the service information used to indicate the target service.

[0012] Optionally, the access rights of the user device to the first service group are determined based on the user information and the access scope, including: determining the access rights of the user device to the first service group based on the user information, the access scope and a second mapping relationship, the second mapping relationship including a mapping relationship between the user information, information of the first service group and the access rights.

[0013] Optionally, the second mapping relationship is stored in a ternary content addressable memory (TCAM).

[0014] The technical solution provided by the present application is that since the access range includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service, and the second mapping relationship for recording user information, information of the first service group and access rights is stored in the TCAM. Therefore, after the network device determines the access range based on the service information used to indicate the target service in the first message, the network device can determine the user device's access rights to the first service group in the at least one service group by searching the TCAM once based on the access range and the user information in the first message. The network device needs to search the TCAM fewer times, which can ensure the forwarding performance of the network device.

[0015] Optionally, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group. For example, the bit width of the first bitmap is equal to the bit width of the second bitmap, the first bit in the first bitmap also corresponds to the first service group, and the position of the first bit in the first bitmap is the same as the position of the first bit in the second bitmap.

[0016] The technical solution provided by the present application can facilitate the network device to search for the second mapping relationship according to the access range and the user information in the first message, because the access range includes the first bitmap and the information of the first service group includes the second bitmap.

[0017] Optionally, the method further includes: receiving a second mapping relationship sent by the controller.

[0018] The technical solution provided by the present application is that the network device receives the second mapping relationship sent by the controller, which can facilitate the network device to determine the access rights of the user device to the first service group based on the user information, access scope and second mapping relationship used to indicate the user device.

[0019] Optionally, the second mapping relationship includes a user control list (UCL) rule table entry. For example, the mapping relationship among the user information, the information of the first service group and the access right is a UCL rule table entry. For example, the second mapping relationship is a UCL rule table, and the second mapping relationship includes at least one UCL rule table entry, each of the at least one UCL rule table entry includes a mapping relationship among user information (such as user group information), service group information and access rights. Since a service group includes at least one service, compared to recording the service group information in the UCL rule table, recording the service information in the service group in the UCL rule table will cause a UCL rule to expand into multiple UCL rule table entries. The present application records the service group information in the second mapping relationship (i.e., the UCL rule table) instead of recording the service information in the service group, which can avoid the expansion of the number of UCL rule table entries.

[0020] Optionally, the user information is a source address, for example, a source Internet Protocol (IP) address or a source Media Access Control (MAC) address. Determining, based on the user information and the access scope, access rights of the user device to the first service group includes: determining, based on the user information, a user group to which the user device belongs; and determining, based on information about the user group to which the user device belongs and the access scope, access rights of the user device to the first service group.

[0021] Optionally, determining the user group to which the user device belongs based on the user information includes: determining the user group to which the user device belongs based on the user information and a third mapping relationship, where the third mapping relationship includes a mapping relationship between the user information and information of the user group to which the user device belongs.

[0022] Optionally, the method further includes: receiving a third mapping relationship sent by the controller.

[0023] The technical solution provided by the present application is that the network device receives the third mapping relationship sent by the controller, which can facilitate the network device to determine the user group to which the user equipment belongs based on the third mapping relationship and the user information used to indicate the user equipment.

[0024] Optionally, the at least one service group further includes a second service group, and determining the access rights of the user device to the first service group based on the user information and the access scope includes: determining the access rights of the user device to the first service group and the second service group based on the user information and the access scope. For example, determining the access rights of the user device to the at least one service group based on the user information and the access scope.

[0025] The technical solution provided by the present application is that, since the access range includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service, and the at least one service group includes a first service group and a second service group. That is, the first service group including the target service and the second service group including the target service are encoded into the same bitmap. Therefore, after the network device determines the access range based on the service information indicating the target service in the first message, the network device can determine the user device's access rights to the first service group and the second service group through a single search based on the access range and the user information in the first message. The network device needs to search fewer times in the process of determining the user device's access rights to the first service group and the second service group, which can ensure the forwarding performance of the network device.

[0026] Optionally, the access range further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

[0027] The meaning of each bit in the first bitmap is unique within the bitmap domain to which the first bitmap belongs, and the meaning expressed by the combination of each bit in the first bitmap and the domain identifier is globally unique within the network device. The bitmap domains to which different bitmaps belong are the same or different.

[0028] The technical solution provided by the present application, since the access scope includes the domain identifier, the domain identifier and the first bitmap are combined to indicate the globally unique meaning in the network device. Therefore, the bit width of the first bitmap can be set shorter, which is convenient for implementation by the network device.

[0029] Optionally, the first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs, and the position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap. That is, the same service group may correspond to the same or different bits in different bitmaps.

[0030] Optionally, the service information is a destination address; or, the service information includes a destination address, a destination port number, and a protocol number. That is, the service information is the destination address of the first message, or, the service information includes the destination address of the first message, the destination port number of the first message, and the protocol number of the first message. The destination address may be a destination IP address or a destination MAC address. In the case where the service information is a destination address, the service information is used to indicate a server that provides a target service. In the case where the service information includes a destination address, a destination port number, and a protocol number, the service information is used to indicate the target service deployed in the server, a virtual machine (VM) deployed in the server and used to provide the target service, a container deployed in the server and used to provide the target service, etc.

[0031] In a second aspect, an access control method is provided, the method comprising: generating a first mapping relationship, the first mapping relationship comprising a mapping relationship between service information and an access scope, the service information being used to indicate a target service, the access scope comprising a first bitmap, the first bitmap being used to indicate at least one service group including the target service, each service group comprising at least one service, the at least one service group comprising a first service group; generating a second mapping relationship, the second mapping relationship comprising a mapping relationship between user information, information of the first service group, and access rights, the user information being used to indicate a user device, the access rights being the user device's access rights to the first service group; and sending the first mapping relationship and the second mapping relationship to a network device. The first mapping relationship and the second mapping relationship are used for the user device indicated by the user information to access the first service group to which the target service indicated by the service information belongs. The method is executed by a controller.

[0032] The technical solution provided by the present application is that the controller sends a first mapping relationship and a second mapping relationship to a network device, which can facilitate the network device to determine the access scope based on the first mapping relationship and the service information for indicating the target service in the message (for example, the first message), and determine the access rights of the user device to the first service group based on the second mapping relationship, the user information for indicating the user device in the message (for example, the first message), and the access scope determined according to the first mapping relationship. Since the access scope includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service. That is, at least one service group including the target service is encoded into the same bitmap. Therefore, the network device can determine the access rights of the user device to the first service group through a single search based on the second mapping relationship, the user information for indicating the user device in the message (for example, the first message), and the access scope determined according to the first mapping relationship. The network device needs to search fewer times in the process of determining the access rights of the user device to the first service group, which can ensure the forwarding performance of the network device.

[0033] Optionally, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group. For example, the bit width of the first bitmap is equal to the bit width of the second bitmap, the first bit in the first bitmap also corresponds to the first service group, and the position of the first bit in the first bitmap is the same as the position of the first bit in the second bitmap.

[0034] The technical solution provided by the present application can facilitate the network device to search for the second mapping relationship according to the access range and the user information in the message, because the access range includes the first bitmap and the information of the first service group includes the second bitmap.

[0035] Optionally, the access range further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

[0036] The meaning of each bit in the first bitmap is unique within the bitmap domain to which the first bitmap belongs, and the meaning expressed by the combination of each bit in the first bitmap and the domain identifier is globally unique within the network device. The bitmap domains to which different bitmaps belong are the same or different.

[0037] The technical solution provided by the present application, since the access scope includes the domain identifier, the domain identifier and the first bitmap are combined to indicate the globally unique meaning in the network device. Therefore, the bit width of the first bitmap can be set shorter, which is convenient for implementation by the network device.

[0038] Optionally, the first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs, and the position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap. That is, the same service group may correspond to the same or different bits in different bitmaps.

[0039] Optionally, generating the first mapping relationship includes: generating the access range according to the service information and the at least one service group; and generating the first mapping relationship according to the service information and the access range.

[0040] Optionally, the access scope further includes a domain identifier, which is used to indicate the bitmap domain to which the first bitmap belongs. Generating the access scope based on the service information and the at least one service group includes: performing a first encoding based on the at least one service group to obtain an initial bitmap, the initial bitmap including a first bit, the first bit corresponding to the first service group; and performing a second encoding based on the service information and the initial bitmap to obtain the access scope. That is, the access scope of the present application is obtained by encoding the at least one service group.

[0041] Optionally, a second encoding is performed based on the service information and the initial bitmap to obtain the access range, including: based on the service information and the initial bitmap, a coding strategy is used to perform a second encoding to obtain the access range; wherein the coding strategy includes at least one of the following: the bit width of the bitmap obtained by the second encoding is smaller than the bit width of the initial bitmap; the service groups to which the same service belongs are encoded into the bitmap of the same bitmap domain; the service groups to which services in the service group to which the same service belongs are encoded into the bitmap of the same bitmap domain.

[0042] Optionally, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, the first bit corresponds to the first service group, and a second mapping relationship is generated, including: determining the information of the first service group based on the access scope; generating the second mapping relationship based on the user information, the information of the first service group and the access permission.

[0043] Optionally, the service information is a destination address; or the service information includes a destination address, a destination port number, and a protocol number. If the service information is a destination address, the service information is used to indicate the server providing the target service. If the service information includes a destination address, a destination port number, and a protocol number, the service information is used to indicate the target service deployed on the server, a VM deployed on the server and used to provide the target service, a container deployed on the server and used to provide the target service, etc.

[0044] Optionally, the second mapping relationship includes a UCL rule table entry. For example, the mapping relationship between the user information, the information of the first service group and the access right is a UCL rule table entry. For example, the second mapping relationship is a UCL rule table, and the second mapping relationship includes at least one UCL rule table entry, each UCL rule table entry in the at least one UCL rule table entry includes a mapping relationship between user information (such as user group information), service group information and access rights. Since a service group includes at least one service, compared to recording the service group information in the UCL rule table, recording the service information in the service group in the UCL rule table will cause a UCL rule to expand into multiple UCL rule table entries. The present application records the service group information in the second mapping relationship instead of recording the service information in the service group, which can avoid the expansion of the number of UCL rule table entries. In addition, in the present application, the encoding strategy adopted by the controller for the second encoding based on the initial bitmap includes encoding the service group to which the services in the service group to which the same service belongs into the bitmap of the same bitmap domain. This encoding strategy can make the number of UCL rule table entries obtained based on the encoding result as small as possible, and can also avoid the expansion of the number of UCL rule table entries to a certain extent.

[0045] In a third aspect, an access control device is provided, comprising at least one functional module configured to execute the access control method provided in the first aspect or any optional embodiment of the first aspect. The at least one functional module may be implemented using software, hardware, or a combination of software and hardware, and the at least one functional module may be arbitrarily combined or divided based on the specific implementation.

[0046] In a fourth aspect, an access control device is provided, comprising at least one functional module configured to execute the access control method provided in the second aspect or any optional embodiment of the second aspect. The at least one functional module may be implemented based on software, hardware, or a combination of software and hardware, and the at least one functional module may be arbitrarily combined or divided based on the specific implementation.

[0047] In a fifth aspect, an access control device is provided, comprising a memory and a processor; the memory is used to store a computer program; the processor is used to execute the computer program stored in the memory so that the access control device performs the method provided in the first aspect or any optional manner of the first aspect, or performs the method provided in the second aspect or any optional manner of the second aspect.

[0048] In the sixth aspect, an access control device is provided, including a main control board and an interface board, wherein the main control board and the interface board are used to implement the method provided by the above-mentioned first aspect or any optional method of the first aspect, or to implement the method provided by the above-mentioned second aspect or any optional method of the second aspect.

[0049] In a seventh aspect, an access control system is provided, comprising a network device and a controller. The network device comprises the access control apparatus provided in the third, fifth, or sixth aspect. The controller comprises the access control apparatus provided in the fourth, fifth, or sixth aspect. The network device is configured to execute the method provided in the first aspect or any optional embodiment of the first aspect. The controller is configured to execute the method provided in the second aspect or any optional embodiment of the second aspect.

[0050] In an eighth aspect, a computer-readable storage medium is provided, in which a computer program is stored. When the computer program is executed (for example, by a processor, an access control device, etc.), it implements the method provided in the first aspect or any optional manner of the first aspect, or implements the method provided in the second aspect or any optional manner of the second aspect.

[0051] In the ninth aspect, a computer program product is provided, which includes a program or code, and when the program or code is executed (for example, by a processor, an access control device, etc.), it implements the method provided in the first aspect or any optional manner of the first aspect, or implements the method provided in the second aspect or any optional manner of the second aspect.

[0052] In the tenth aspect, a chip is provided, which includes a programmable logic circuit and / or program instructions. When the chip is running, it is used to implement the method provided by the first aspect or any optional method of the first aspect, or to implement the method provided by the second aspect or any optional method of the second aspect.

[0053] The technical effects of the third to tenth aspects mentioned above can refer to the technical effects of the first to second aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0055] Figure 2 is a schematic diagram of another application scenario provided by an embodiment of the present application;

[0056] Figure 3 This is a flowchart of an access control method provided by an embodiment of the present application;

[0057] Figure 4 This is a flowchart of another access control method provided by an embodiment of the present application;

[0058] Figure 5 This is a flowchart of another access control method provided by an embodiment of the present application;

[0059] Figure 6 is a schematic diagram of an access control device provided by an embodiment of the present application;

[0060] Figure 7 is a schematic diagram of another access control device provided in an embodiment of the present application;

[0061] Figure 8 is a schematic diagram of another access control device provided in an embodiment of the present application;

[0062] Figure 9 This is a schematic diagram of another access control device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0063] The embodiments of the present application will be described in further detail below with reference to the accompanying drawings.

[0064] User control list (UCL) rules are used by network devices to control user device access to network services. Network devices can process messages from user devices seeking to access network services based on UCL rules to control access to these user devices, ensuring that only authenticated user devices and authorized user devices that comply with security policies can access network services. UCL rules typically include the identifier of a user group, the identifier of a service group, and the access rights granted to the user group to access the service group. For example, access rights may include permitting or denying access.

[0065] A user group includes at least one user device, and a user device belongs to at least one user group. A service group includes at least one service, and a service belongs to at least one service group. For example, user devices in the same department (i.e., devices of employees in the same department) within an enterprise belong to the same user group, while user devices in different departments (i.e., devices of employees in different departments) belong to different user groups. Services accessible to user devices in the same department belong to the same service group, while services accessible to user devices in different departments belong to the same or different service groups. For example, an enterprise includes a trading department and an internet technology (IT) department. The trading department includes the securities trading department, and the IT department includes the network department. All user devices within the enterprise (i.e., all employee devices) can access email services. User devices in the trading department (i.e., devices of employees in the trading department) can access trading services. User devices in the securities trading department (i.e., devices of employees in the securities trading department) can access trading services and securities services. User devices in the IT department (i.e., devices of employees in the IT department) can access operation and maintenance services. User devices in the network department (i.e., devices of employees in the network department) can access operation and maintenance services and network operation and maintenance services. The access control relationship between the enterprise's user groups and service groups is shown in Table 1 below.

[0066] Table 1

[0067] User Group Service Group User Group 1 (all user devices within the enterprise) Service Group 1 (including email services) User Group 2 (User devices of the trading department) Service Group 2 (including email services and transaction services) User Group 3 (User devices in the securities trading department) Service Group 3 (including email services, trading services, and securities services) User Group 4 (User devices of the IT department) Service Group 4 (including email services and operation and maintenance services) User Group 5 (User devices of the network department) Service Group 5 (including email services, operation and maintenance services, and network operation and maintenance services)

[0068] UCL rules are typically stored as table items in network devices. A UCL rule is stored in a network device as at least one rule table item, which can be referred to as a rule table item of the UCL rule or a rule entry of the UCL rule. Currently, there are two related technologies for UCL rules, which are introduced below. For ease of description, in some of the following descriptions, a rule table item of a UCL rule is referred to as a UCL rule table item, and a UCL rule table item has the same meaning as a rule table item of the UCL rule.

[0069] In the first related art, each rule entry of the UCL rule includes: the identifier of the user group in the UCL rule, the Internet Protocol (IP) address of a service in the service group indicated by the identifier of the service group in the UCL rule, and the access rights in the UCL rule. The access rights are the access rights of the user group to the service. After the network device receives a message from the user device, the network device determines the user group to which the message belongs based on the source IP address of the message. The network device searches the UCL rule table based on the identifier of the user group to which the message belongs and the destination IP address of the message (according to the first related art, each UCL rule entry in the UCL rule table includes the identifier of the user group, the IP address of the service, and the access rights) to determine the UCL rule entry that matches both the identifier of the user group and the destination IP address. The network device determines the access rights of the user device to the service indicated by the destination IP address based on the UCL rule entry that matches both the identifier of the user group and the destination IP address. The network device processes the message based on the access rights of the user device to the service indicated by the destination IP address. It should be noted that, in some embodiments, the source IP address is also written as a source internet protocol (SIP) address, and the destination IP address is also written as a destination internet protocol (DIP) address.

[0070] However, the UCL rule table provided by the first related technology easily leads to expansion of the UCL rule table. For one UCL rule, the network device needs to store many UCL rule table entries, resulting in high resource overhead and storage cost for the network device to store the UCL rule.

[0071] For example, UCL rule 1 is: permit source UserGroup3 destination ServiceGroup3 (allow user group 3 to access service group 3). "UserGroup3" in UCL rule 1 is the identifier of user group 3, "ServiceGroup3" in UCL rule 1 is the identifier of service group 3, and "permit" in UCL rule 1 is the access permission of user group 3 to service group 3. "Source" in UCL rule 1 indicates that user group 3 is the source of access, and "destination" in UCL rule 1 indicates that service group 3 is the destination of access. Both user group 3 and service group 3 here can be as shown in Table 1. Referring to Table 1, service group 3 includes email service, transaction service and securities service. According to related technology 1, UCL rule 1 will be stored as three UCL rule table entries in the network device. Each of the three UCL rule table entries includes the identifier "UserGroup3" of user group 3, the IP address of one of the email service, transaction service and securities service, and the access permission "permit" in UCL rule 1. For example, the three UCL rule table entries are shown in Table 2 below.

[0072] Table 2

[0073] User group identifier IP address of the service Access Rights UserGroup3 The IP address of the email service permit UserGroup3 IP address of the transaction service permit UserGroup3 IP address of securities services permit

[0074] The first line in Table 2 is the header of the UCL rule table, and each line from the second to the fourth line is a UCL rule table entry.

[0075] It can be seen that according to the first related technology, UCL rule 1 expands into three UCL rule table entries when stored. The resource overhead of the network device to store the three UCL rule table entries is large, and the storage cost is high. Moreover, the above UCL rule 1 is only used as an example. Under normal circumstances, a service group includes dozens of services. Such a UCL rule will expand into dozens of UCL rule table entries when stored. The resource overhead of the network device to store these UCL rule table entries will be even greater. In addition, network devices usually use ternary content addressable memory (TCAM) to store UCL rule table entries. In TCAM, UCL rule table entries are all rule table entries that use mask matching. TCAM is an expensive storage resource in network devices, which also leads to a high storage cost for network devices to store UCL rules.

[0076] In the second related technology, each rule table entry of the UCL rule includes: the identifier of the user group in the UCL rule, the identifier of a service group in the UCL rule, and the access permission in the UCL rule. The access permission is the access permission of the user group to the service. After the network device receives a message from the user device, the network device determines the user group to which the message belongs based on the source IP address of the message. The network device determines the service group to which the service accessed by the user device belongs based on the destination IP address of the message. The network device searches the UCL rule table based on the identifier of the user group to which the user device belongs and the identifier of the service group to which the service accessed by the user device belongs (according to the second related technology, each UCL rule table entry in the UCL rule table includes the identifier of the user group, the identifier of the service group, and the access permission) to determine a UCL rule table entry that matches both the identifier of the user group to which the user device belongs and the identifier of the service group to which the service accessed by the user device belongs. The network device determines the access permission of the user device to the service group based on the UCL rule table entry that matches both the identifier of the user group to which the user device belongs and the identifier of the service group to which the service accessed by the user device belongs. The network device processes the message based on the access permission.

[0077] Compared to Related Technology 1, Related Technology 2 can reduce the number of rule table entries for UCL rules, avoid expansion of UCL rule table entries, and reduce the resource overhead and storage cost of network devices storing UCL rules. For example, according to Related Technology 2, UCL rule 1 is stored as a UCL rule table entry in the network device. The UCL rule table entry includes the identifier "UserGroup3" of user group 3, the identifier "ServiceGroup3" of service group 3, and the access permission "permit" in UCL rule 1. For example, the UCL rule table entry is shown in Table 3 below.

[0078] Table 3

[0079] User group identifier ID of the service group Access Rights UserGroup3 ServiceGroup3 permit

[0080] The first line in Table 3 is the header of the UCL rule table, and the second line is a UCL rule table entry.

[0081] As can be seen, according to Related Technology 2, UCL Rule 1 is stored as a single UCL rule entry. Compared to Related Technology 1, this reduces the number of UCL rule entries by two, thereby reducing the resource overhead and storage costs of storing UCL Rule 1 on network devices. Furthermore, when a service group includes dozens or even more services, Related Technology 2 can significantly reduce resource overhead and storage costs.

[0082] However, a user device may belong to multiple user groups, and a service may belong to multiple service groups. According to related technology 2, when a user device belongs to multiple user groups and / or a service belongs to multiple service groups, the network device needs to search the UCL rule table multiple times to determine the user device's access rights to the service group to which the service it is accessing belongs, which can easily lead to a decrease in the forwarding performance of the network device. For example, referring to Table 1, assume that message 1 comes from user device 31, the source IP address of message 1 is the IP address of user device 31, the destination IP address of message 1 is the IP address of the email service, and message 1 is a message from user device 31 accessing the email service. After receiving message 1, the network device determines that user device 31 belongs to user group 3 based on the source IP address of message 1, and the network device determines that the service accessed by user device 1 belongs to service groups 1-5 based on the destination IP address of message 1. Then, the network device needs to search the UCL rule table based on the identifier of user group 3 "UserGroup3" and the identifier of each service group in service groups 1-5 to determine the user device's access rights to service groups 1-5 to which the email service belongs. That is, the network device needs to search the UCL rule table based on the identifier "UserGroup3" of user group 3 and the identifier "ServiceGroup1" of service group 1, search the UCL rule table based on the identifier "UserGroup3" of user group 3 and the identifier "ServiceGroup2" of service group 2, search the UCL rule table based on the identifier "UserGroup3" of user group 3 and the identifier "ServiceGroup3" of service group 3, search the UCL rule table based on the identifier "UserGroup3" of user group 3 and the identifier "ServiceGroup4" of service group 4, and search the UCL rule table based on the identifier "UserGroup3" of user group 3 and the identifier "ServiceGroup5" of service group 5, in order to determine the user device's access rights to service groups 1 to 5 to which the email service belongs. The network device needs to search the UCL rule table five times to determine the user device's access rights to service groups 1 to 5 to which the email service belongs, which can easily lead to a decrease in the forwarding performance of the network device.

[0083] An embodiment of the present application provides an access control method, apparatus, and system, which encodes at least one service group including a target service into the same bitmap, so that a network device can determine the access rights of a user device to the at least one service group through a single search. The network device needs to search fewer times in the process of determining the access rights of the user device to the at least one service group, thereby ensuring the forwarding performance of the network device.

[0084] The following describes the technical solutions of the embodiments of the present application. First, the application scenarios of the embodiments of the present application are introduced.

[0085] The application scenarios of the embodiments of the present application include a communication network, at least one user device connected to the communication network, and at least one service device connected to the communication network. The service device is used to provide services. The communication network is used to forward messages between the user device and the service device, so that the user device can access the services provided by the service device through the communication network. Furthermore, the network devices in the communication network can process messages from the user device for accessing the services provided by the service device according to UCL rules to perform access control on the user device.

[0086] The communication network may be a data center network (DCN), a metropolitan area network (MAN), a wide area network (WAN), a backbone network, or a campus network. The communication network includes multiple network devices. The network devices may be switches, routers, virtual switches, or virtual routers, among other devices used for packet forwarding. A virtual switch may be a node with switching functionality created within a physical switch based on virtualization technology. A virtual router may be a node with routing functionality created within a physical router based on virtualization technology. In some embodiments, the network devices are also referred to as forwarding devices. The network devices in the communication network may be of the same type, for example, all network devices in the communication network may be switches; or the communication network may include different types of network devices, for example, some network devices in the communication network may be routers and others may be switches. In an embodiment of the present application, the network devices in the communication network include access devices, and both user devices and service devices access the communication network through the access devices. In one embodiment, the communication network is a secondary network, comprising an access layer and a convergence layer. The access layer provides access functions, and the convergence layer provides convergence functions. The access devices are located at the access layer, and the network devices in the communication network also include convergence devices located at the convergence layer, which are connected to the access devices. In another embodiment, the communication network is a three-level network, which includes an access layer, an aggregation layer and a core layer. The access layer is used to provide access functions, the aggregation layer is used to provide aggregation functions, and the core layer is used to further aggregate the traffic aggregated by the aggregation layer. The access device is located in the access layer. The network devices in the communication network also include an aggregation device located in the aggregation layer and a core device located in the core layer. The aggregation device is connected to the access device and the core device respectively. For example, the network devices in the communication network are all switches, the access device is an access switch, the aggregation device is an aggregation switch, and the core device is a core switch. The access switch is also called a leaf switch, and the aggregation switch is also called a spine switch.

[0087] Among them, the service devices accessing the communication network may include servers and virtual machines (VMs), containers, etc. created in the servers based on virtualization technology. A service device can provide at least one service, and a service can be provided by at least one service device. User devices accessing the communication network may include user terminals such as mobile phones, tablets, laptops, desktop computers, smart TVs, and Internet of Things (IoT) devices, and may also include enterprise terminals (terminals for enterprise external communication) such as client provider edge (CPE) devices. A service application (application, App) corresponding to the service provided by the service device may be installed in the user device, and the service App in the user device is used to access the service provided by the service device. At least one service App may be installed in a user device, and different service Apps correspond to different services. Optionally, the services described in the embodiments of the present application include but are not limited to: email services, trading services, securities services, operation and maintenance services, artificial intelligence (AI) services, virtual reality (VR) services, video services, game services, and other possible services. Service apps include, but are not limited to, email apps for email services, trading apps for trading services, securities apps for securities services, operations and maintenance apps for operations and maintenance services, AI apps for AI services, VR apps for VR services, video apps for video services, and gaming apps for gaming services. In some embodiments, the service apps installed on a user device are also referred to as service clients.

[0088] In an embodiment of the present application, user devices accessing the communication network can be divided into at least one user group, each user group includes at least one user device, and one user device belongs to at least one user group. The services provided by the service device accessing the communication network can be divided into at least one service group, each service group includes at least one service, and one service belongs to at least one service group. Thus, the network device in the communication network can process the message from the user device for accessing the service provided by the service device according to the UCL rule to perform access control on the user device (the UCL rule is an access control rule based on the user group and the service group, and the UCL rule performs access control at the granularity of the user group and the service group). Among them, the user devices accessing the communication network can be grouped based on various possible grouping strategies, and the services provided by the service device accessing the communication network can be grouped based on various possible grouping strategies. For example, user devices of the same enterprise are divided into the same user group, user devices of different enterprises are divided into different user groups, services allowed to be accessed by the same user group are divided into the same service group, and services allowed to be accessed by different user groups are divided into different service groups. For another example, user devices of the same department within an enterprise may be divided into the same user group, user devices of different departments within the enterprise may be divided into different user groups, services accessible to the same user group may be divided into the same service group, and services accessible to different user groups may be divided into different service groups. This embodiment of the present application does not limit this.

[0089] As an example, see Figure 1, which shows a schematic diagram of an application scenario provided by an embodiment of the present application. The application scenario includes a communication network 10 and user devices 201~205 and service devices 301~305 accessing the communication network 10. The communication network 10 includes network devices 101~103. The network devices 101~103 include access devices, and the user devices 201~205 and service devices 301~305 access the communication network 10 through the access devices. Optionally, the network devices 101~103 also include aggregation devices and core devices. For example, network device 101 is an access device, network device 102 is an aggregation device, and network device 103 is a core device. User devices 201-205 can be divided into at least one user group, each of service devices 301-305 can provide at least one service, and the services provided by service devices 301-305 can be divided into at least one service group. At least one network device among network devices 101-103 (e.g., network device 101) can process packets from user devices 201-205 for accessing services provided by service devices 301-305 according to UCL rules to perform access control on user devices 201-205. For example, user devices 201-205 are divided into user groups 1-2, where user group 1 includes user devices 201-202 and user group 2 includes user devices 203-205. Service devices 301-305 can provide services 1-500. Each of service devices 301-305 provides at least one service from services 1-500. Services 1-500 are divided into service groups 1-1000. Each of service groups 1-1000 includes at least one service from services 1-500, and each service from services 1-500 belongs to at least one of service groups 1-1000. Network device 101 receives message 1 from user device 201 for accessing service 1. Network device 101 searches a UCL rule table based on message 1 to determine a UCL rule entry that matches message 1. Network device 101 determines user device 201's access rights to at least one service group that includes service 1 (e.g., service groups 1-2) based on the UCL rule entry that matches message 1. Network device 101 processes the message based on user device 201's access rights to the at least one service group (i.e., service groups 1-2) to perform access control on user device 201.

[0090] Among them, the UCL rule table includes at least one UCL rule table item, and the UCL rule table item is also called a UCL rule entry. In an embodiment of the present application, the UCL rule table item includes an identifier of a user group, information of a service group, and access rights of the user group to the service group. The information of the service group may include a bitmap. For example, a message 1 from a user device 201 for accessing service 1 includes user information and service information, the user information is used to indicate the user device 201, and the service information is used to indicate the service accessed by the user device 201 (that is, service 1). After the network device 101 receives message 1, the network device 101 determines the user group to which the user device 201 belongs based on the user information in message 1 (in this example, the user device 201 belongs to user group 1), and the network device 101 determines the access range based on the service information in message 1. The access range includes a bitmap, and the bitmap is used to indicate at least one service group (for example, service groups 1 to 2) including service 1. The network device 101 searches the UCL rule table based on the identifier of the user group to which the user device 201 belongs and the access scope to determine a UCL rule table entry that matches both the identifier of the user group and the access scope, that is, a UCL rule table entry that matches message 1. Furthermore, the network device 101 determines the access rights of the user device 201 to the at least one service group including service 1 (that is, service groups 1-2) based on the UCL rule table entry that matches message 1. Since the bitmap in the access scope is used to indicate service groups 1-2 including service 1, the network device 101 can determine the access rights of the user device 201 to service groups 1-2 including service 1 by searching the UCL rule table once. The number of searches required by the network device 101 in determining the access rights of the user device 201 to service groups 1-2 including service 1 is relatively small, which can ensure the forwarding performance of the network device 101.

[0091] In an embodiment of the present application, the UCL rule table item can be generated by the controller and sent to the network device. For example, the controller obtains the UCL rule according to the configuration information, generates the UCL rule table item according to the UCL rule, and sends the UCL rule table item to the network device. The controller can be deployed independently (that is, as an independent device) or integrated into the network device. For example, for Figure 1 In the application scenario shown, the controller can be integrated into any network device among the network devices 101 to 103. Figure 2 shows the case of independent controller deployment, Figure 1 The difference between the application scenarios shown is that Figure 2The illustrated application scenario also includes an independently deployed controller 40, which is connected to the communication network 10 to control the communication network 10. The controller 40 is used to generate UCL rule table entries based on UCL rules and issue UCL rule table entries to network devices in the communication network 10, so that the network devices in the communication network 10 process messages according to the UCL rule table entries. The controller 40 can be a server, a server cluster consisting of several servers, or a cloud computing control center. In some embodiments, the controller 40 is also referred to as a network controller, a control device, a network control device, etc., which is not limited in the embodiments of the present application.

[0092] It should be pointed out that Figure 1 and Figure 2 The application scenarios shown are only for example and are not intended to limit the technical solutions of this application. Figure 1 and Figure 2 More or fewer devices are shown, and the number of network devices, the number of user devices, the number of service devices, and the connection relationship between these devices in the application scenario can be configured as needed. Figure 1 and Figure 2 The three network devices shown can serve as representatives of access devices, aggregation devices, and core devices, but this does not mean that communication network 10 only includes these three network devices. In a communication network, the number of access devices is generally greater than the number of aggregation devices, and the number of aggregation devices is generally greater than the number of core devices. Furthermore, each aggregation device can be connected to all access devices, and each access device can be connected to all aggregation devices (i.e., aggregation devices and access devices are fully interconnected), but this is not limited in the present embodiment.

[0093] The above is an introduction to the application scenarios of the embodiments of the present application. The following introduces the method embodiments of the present application.

[0094] Please refer to Figure 3 , which shows a flowchart of an access control method provided by an embodiment of the present application. Figure 3 The access control method is described as being executed by network device A. Network device A may be an access device, aggregation device, or core device in a communication network. For example, network device A is Figure 1 or Figure 2 Any network device in the application scenario shown. Figure 3 The method includes the following steps S301 to S303.

[0095] S301. Network device A receives a first message from user device B1. The first message includes user information X1 and service information Y1. The user information X1 is used to indicate user device B1. The service information Y1 is used to indicate a target service accessed by user device B1.

[0096] Network device A receives a first message from user equipment B1 from a previous-hop device of network device A. The previous-hop device of network device A may be user equipment B1 or a device connected between network device A and user equipment B1.

[0097] In which, user device B1 accesses the communication network through an access device in the communication network where network device A is located. Network device A can be an access device, an aggregation device, or a core device in the communication network. Depending on the network device A, the previous hop device of network device A is different. In one embodiment, network device A is an access device in the communication network, user device B1 accesses the communication network through the access device (i.e., network device A), the previous hop device of network device A is user device B1, and network device A receives a first message from user device B1 from user device B1. In another embodiment, network device A is an aggregation device in the communication network, the previous hop device of network device A is an access device or a core device in the communication network, and network device A receives a first message from user device B1 from the access device or the core device. In yet another embodiment, network device A is a core device in the communication network, the previous hop device of network device A is an aggregation device in the communication network, and network device A receives a first message from user device B1 from the aggregation device.

[0098] In the embodiment of the present application, the first message includes user information X1 and service information Y1. The user information X1 is used to indicate the user device B1, and the service information Y1 is used to indicate the service accessed by the user device B1. For the sake of convenience, the embodiment of the present application refers to the service accessed by the user device B1 as the target service, and the service information Y1 is used to indicate the target service. The first message is the message for the user device B1 to access the target service. For example, the network device A is Figure 1 or Figure 2 In any network device in the application scenario shown, user device B1 is Figure 1 or Figure 2 For any user device in the application scenario shown, the target service is Figure 1 or Figure 2 Any service provided by the service device in the application scenario shown.

[0099] In an optional embodiment, user information X1 is information about the user group to which user device B1 belongs. User information X1 is used to indicate the user group to which user device B1 belongs, thereby indicating user device B1. Alternatively, user information X1 is information about user device B1, and user information X1 is used to indicate user device B1. For example, user information X1 is a source address, and user information X1 is carried as the source address in the first message. The source address is the address of user device B1, and user information X1 (i.e., the source address) is used to indicate user device B1. The user group information may be a user group identifier, and the source address may be a source IP address or a source media access control (MAC) address.

[0100] In an optional embodiment, the service information Y1 is a destination address, or the service information Y1 includes a destination address, a destination port number, and a protocol number. That is, the service information Y1 is carried in the first message as the destination address, or the service information Y1 is carried in the first message as a combination of the destination address, the destination port number, and the protocol number. The destination address may be the address of a server for providing the target service. The destination port number is the port number corresponding to the target service, and the protocol number is the protocol number of the communication protocol of the target service. In the case where the service information Y1 is a destination address, the service information Y1 is used to indicate the server providing the target service. In the case where the service information Y1 includes a destination address, a destination port number, and a protocol number, the service information Y1 is used to indicate the target service deployed in the server, or the service information Y1 is used to indicate the VM deployed in the server and used to provide the target service, or the service information Y1 is used to indicate the container deployed in the server and used to provide the target service. This embodiment of the present application does not limit this. The destination address may be a destination IP address or a destination MAC address.

[0101] S302. Network device A determines access range Z1 according to service information Y1. Access range Z1 includes a first bitmap, which is used to indicate at least one service group including the target service. Each service group includes at least one service, and the at least one service group includes the first service group.

[0102] For ease of description, the service group including the target service is referred to as the target service group, so the first bitmap is used to indicate at least one target service group. Each service group in the at least one target service group includes the target service, and the at least one target service group includes the first service group. The at least one target service group is obtained by grouping the services provided by the communication network to which the network device A belongs. The services provided by the communication network to which the network device A belongs may be services provided by a service device accessing the communication network. For example, the network device A belongs to Figure 1 and Figure 2In the communication network 10 shown in FIG, the services provided by the communication network 10 may be services provided by the service devices 301 - 305 .

[0103] In an optional embodiment, the first bitmap includes at least one bit, and the at least one bit corresponds one-to-one with the at least one target service group, and the at least one bit is used to indicate the at least one target service group. For example, the value of the at least one bit is the first value to indicate the at least one target service group. For example, the first value is 1. The at least one bit can be all or part of the bits in the first bitmap. In the case where the at least one bit is a plurality of bits, the at least one bit can be continuous or discontinuous. For example, the bit width of the first bitmap is n bits, that is, the first bitmap includes a total of n bits, and the number of the at least one bit is less than or equal to n, where n is a positive integer. In one example, n=128.

[0104] In an optional embodiment, the first bitmap includes a first bit, the first bit corresponding to the first service group, and the first bit is used to indicate the first service group. For example, the value of the first bit is a first value to indicate the first service group. Optionally, the at least one target service group also includes a second service group, and the first bitmap also includes a second bit, the second bit corresponding to the second service group. For example, the value of the second bit is a first value to indicate the second service group. In the first bitmap, the first bit and the second bit may be consecutive or discontinuous.

[0105] In an optional embodiment, the access range Z1 also includes a domain identifier D1, and the domain identifier D1 is used to indicate the bitmap domain to which the first bitmap belongs. For example, the first bitmap belongs to bitmap domain 1, and the domain identifier D1 is used to indicate bitmap domain 1. For the sake of convenience of description, the bitmap belonging to the bitmap domain is called an intra-domain bitmap, and the first bitmap is the intra-domain bitmap of bitmap domain 1. The meaning of each bit in the intra-domain bitmap is unique within the bitmap domain to which the intra-domain bitmap belongs, and the meaning expressed by each bit in the intra-domain bitmap and the domain identifier of the bitmap domain to which the intra-domain bitmap belongs is globally unique in the network device. In an embodiment of the present application, the intra-domain bitmap is obtained by encoding according to multiple service groups, and the multiple service groups are all or part of the service groups provided by the communication network to which the network device A belongs, and the service group provided by the communication network refers to the service group obtained by grouping the services provided by the communication network. A service group can be encoded into an intra-domain bitmap of at least one bitmap domain. The positions of the bits corresponding to the same service group in different intra-domain bitmaps of the same bitmap domain are the same, and the positions of the bits corresponding to the same service group in the intra-domain bitmaps of different bitmap domains are the same or different. The bit widths of different intra-domain bitmaps can be equal or unequal. For example, the bit widths of the intra-domain bitmaps are all n bits, and each intra-domain bitmap includes n bits. For example, the first service group also corresponds to the first bit in the third bitmap, the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs, and the position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap. For example, the third bitmap belongs to bitmap domain 3. The bit width of the third bitmap is n bits.

[0106] In an optional embodiment, network device A includes a first mapping relationship, the first mapping relationship including a mapping relationship between service information Y1 and access range Z1, and network device A determines access range Z1 based on the first mapping relationship and the service information Y1 in the first message. In a specific embodiment, network device A searches the first mapping relationship based on the service information Y1 in the first message to determine access range Z1.

[0107] As an example, the first mapping relationship is shown in Table 4 below.

[0108] Table 4 (first mapping relationship)

[0109] Service information Y1 (e.g. destination address 1) Access range Z1 (e.g. domain identifier D1 + domain bitmap M1)

[0110] Based on Table 4 and the description of the foregoing embodiment, it can be understood that the first bitmap is the intra-domain bitmap M1.

[0111] Table 4 takes the example that the first mapping relationship includes a group of mapping relationships. In some embodiments, the first mapping relationship includes multiple groups of mapping relationships, each group of mapping relationships in the multiple groups of mapping relationships is a mapping relationship between a service information and an access range, and the multiple groups of mapping relationships include a mapping relationship between service information Y1 and access range Z1. In the first mapping relationship, each service information is used to indicate a service, and the access range corresponding to each service information is used to indicate at least one service group including the service indicated by each service information. Each service information is a destination address, or each service information includes a destination address, a destination port number, and a protocol number. The access range corresponding to each service information may include an intra-domain bitmap and a domain identifier of a bitmap domain to which the intra-domain bitmap belongs. As an example, the first mapping relationship is shown in Table 5 below.

[0112] Table 5 (first mapping relationship)

[0113] Service information Y1 (e.g. destination address 1) Access range Z1 (e.g. domain identifier D1 + domain bitmap M1) Service information Y2 (e.g. destination address 2) Access range Z2 (e.g. domain identifier D1 + domain bitmap M2) Service information Y3 (e.g. destination address 3) Access range Z3 (e.g. domain identifier D1 + domain bitmap M3) ...... ......

[0114] Each row in Table 5 is a mapping relationship. For example, as shown in Table 5, service information Y1 and access range Z1 are a mapping relationship, service information Y2 and access range Z2 are a mapping relationship, service information Y3 and access range Z3 are a mapping relationship, and so on.

[0115] For example, service information Y1 is used to indicate service 1, access scope Z1 includes domain identifier D1 and intra-domain bitmap M1, domain identifier D1 included in access scope Z1 is used to indicate the bitmap domain to which intra-domain bitmap M1 belongs, and intra-domain bitmap M1 is used to indicate at least one service group including service 1. Service information Y2 is used to indicate service 2, access scope Z2 includes domain identifier D1 and intra-domain bitmap M2, domain identifier D1 included in access scope Z2 is used to indicate the bitmap domain to which intra-domain bitmap M2 belongs, and intra-domain bitmap M2 is used to indicate at least one service group including service 2. Service information Y3 is used to indicate service 3, access scope Z3 includes domain identifier D1 and intra-domain bitmap M3, domain identifier D1 included in access scope Z3 is used to indicate the bitmap domain to which intra-domain bitmap M3 belongs, and intra-domain bitmap M3 is used to indicate at least one service group including service 3. And so on. Based on the description in this paragraph, it can be understood that the target service described in the embodiment of the present application can be service 1, and the first bitmap can be intra-domain bitmap M1.

[0116] In one example, the communication network to which network device A belongs provides 1,000 service groups (that is, the services provided by the communication network to which network device A belongs are divided into 1,000 service groups; for example, the services provided by the service devices accessing the communication network to which network device A belongs are divided into 1,000 service groups), namely service groups 1 to 1000, where service groups 1 to 1000 are all or part of the service groups provided by the communication network to which network device A belongs. Service 1 belongs to service group 1, service group 2, and service group 400, service 2 belongs to service group 1 and service group 5, and service 3 belongs to service group 1. Intra-domain bitmap M1 is used to indicate that service group 1, service group 2, and service group 400 are included in service 1, intra-domain bitmap M2 is used to indicate that service group 1 and service group 5 are included in service 2, and intra-domain bitmap M3 is used to indicate that service group 1 is included in service 3. For example, domain identifier D1 is used to indicate bitmap domain 1, intra-domain bitmap M1, intra-domain bitmap M2 and intra-domain bitmap M3 are all intra-domain bitmaps of bitmap domain 1, and the bit width of the intra-domain bitmap of bitmap domain 1 is n bits, including n bits arranged from low to high. Among the n bits, the first bit corresponds to service group 1, the second bit corresponds to service group 2, the fourth bit corresponds to service group 400, and the fifth bit corresponds to service group 5. The intra-domain bitmap M1 can be 0000...0001011 (a total of n bits, the values ​​of the 1st bit, the 2nd bit and the 4th bit are 1, and the values ​​of the remaining bits are 0), the intra-domain bitmap M2 can be 0000...0010001 (a total of n bits, the values ​​of the 1st bit and the 5th bit are 1, and the values ​​of the remaining bits are 0), and the intra-domain bitmap M3 can be 0000...0000001 (a total of n bits, the value of the 1st bit is 1, and the values ​​of the remaining bits are 0). The first mapping relationship shown in Table 5 is concretized as shown in Table 6 below. It should be noted that the correspondence between the service group and the bits in the intra-domain bitmap of bitmap domain 1 in this paragraph is only an example. The correspondence between the service group and the bits in the intra-domain bitmap can be set according to actual conditions, and the embodiments of the present application do not limit this. For example, n=128.

[0117] Table 6 (first mapping relationship)

[0118] Service information Y1 (e.g. destination address 1) Access range Z1 (e.g. domain identifier D1+0000…0001011) Service information Y2 (e.g. destination address 2) Access range Z2 (e.g. domain identifier D1+0000…0010001) Service information Y3 (e.g. destination address 3) Access range Z3 (e.g. domain identifier D1+0000…0000001) ...... ......

[0119] It should be noted that the first mapping relationships shown in Tables 5 and 6 only show the intra-domain bitmap of bitmap domain 1. The access scope in the first mapping relationship may also include domain identifiers of other bitmap domains and intra-domain bitmaps of these other bitmap domains, and this embodiment of the present application does not limit this. For example, network device A searches for the first mapping relationship shown in any of Tables 4 to 6 based on the service information Y in the first message to determine the access scope Z.

[0120] In an optional embodiment, before network device A determines access range Z1 based on the first mapping relationship and service information Y1 in the first message, network device A obtains the first mapping relationship. For example, network device A generates the first mapping relationship, or network device A receives the first mapping relationship sent by a controller. The first mapping relationship sent by the controller to network device A is generated by the controller. The implementation process for network device A to generate the first mapping relationship is similar to the implementation process for the controller to generate the first mapping relationship. The specific implementation will be described below and is not detailed here.

[0121] In an optional embodiment, after network device A obtains the first mapping relationship, network device A stores the first mapping relationship for easy use.

[0122] S303. Network device A determines the access rights of user device B1 to the first service group according to user information X1 and access range Z1.

[0123] In an optional embodiment, network device A includes a second mapping relationship, the second mapping relationship including a mapping relationship between user information X1, information about the first service group, and access permission P, where access permission P is user device B1's access permission to the first service group. Network device A determines user device B1's access permission to the first service group based on the second mapping relationship, user information X1 in the first message, and access scope Z1 determined in S302. In a specific embodiment, network device A searches the second mapping relationship based on user information X1 in the first message and access scope Z1 determined in S302 to determine user device B1's access permission to the first service group (because the service groups indicated by access scope Z1 include the first service group and the second mapping relationship includes information about the first service group, network device A can determine user device B's access permission to the first service group by searching the second mapping relationship based on user information X1 and access scope Z1). In an optional embodiment, the information about the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group. The information about the first service group may also include a domain identifier, which is used to indicate the bitmap domain to which the second bitmap belongs. The bitmap domain to which the second bitmap belongs is the same as the bitmap domain to which the first bitmap belongs, and the position of the first bit in the second bitmap is the same as the position of the first bit in the first bitmap.

[0124] In an optional embodiment, user information X1 is information about the user group to which user device B1 belongs. User information X1 is used to indicate the user group to which user device B1 belongs, thereby indicating user device B1. In this case, the second mapping relationship includes a mapping relationship between user information X1, information about the first service group, and access permission P. Access permission P is the access permission of the user group to which user device B1 belongs to the first service group, thereby also being the access permission of user device B1 to the first service group. Network device A searches the second mapping relationship based on user information X1 in the first message and access scope Z1 determined in S302 to determine the access permission of the user group to which user device B1 belongs to the first service group, thereby determining the access permission of user device B1 to the first service group (because the service groups indicated by access scope Z1 include the first service group, and the second mapping relationship includes information about the first service group, network device A can determine the access permission of the user group to which user device B1 belongs to the first service group by searching the second mapping relationship based on user information X1 and access scope Z1). For example, user information X is the information of user group 1 to which user device B belongs, the first service group is service group 1, the information of the first service group includes a domain identifier and a second bitmap, the domain identifier is domain identifier D1, the second bitmap is an intra-domain bitmap Q1, the access permission P is access permission 1, and the second mapping relationship is shown in Table 7 below.

[0125] Table 7 (Second mapping relationship)

[0126]

[0127] Based on Table 7 and the description of the foregoing embodiment, it can be understood that the second bitmap is the intra-domain bitmap Q1.

[0128] As previously mentioned, domain identifier D1 is used to indicate bitmap domain 1, so the intra-domain bitmap Q1 is the intra-domain bitmap of bitmap domain 1. For example, the first service group is service group 1, and the bit width of the intra-domain bitmap of bitmap domain 1 is n bits, including n bits arranged from low to high. Of the n bits, the first bit corresponds to service group 1, so the intra-domain bitmap Q1 can be 0000...0000001 (a total of n bits, the first bit is 1, and the other bits are 0). The second mapping relationship shown in Table 7 can be concretized as shown in the following Table 8. For example, n = 128.

[0129] Table 8 (Second mapping relationship)

[0130]

[0131] For example, network device A searches the second mapping relationship shown in Table 7 or Table 8 based on the user information X1 in the first message and the access scope Z1 determined in S302 to determine that the access permission of user group 1 to which user device B1 belongs for service group 1 (i.e., the first service group) is access permission 1. Thus, network device A determines that the access permission of user device B1 for service group 1 (i.e., the first service group) is access permission 1. For example, access permission 1 is allowed access, so the mapping relationships shown in Table 7 and Table 8 are used to indicate that user group 1 is permitted to access service group 1. It should be noted that since the domain identifier D1 included in the access range Z1 is the same as the domain identifier D1 included in the information of service group 1, and the first bit in the domain bitmap M1 included in the access range Z1 and the first bit in the domain bitmap Q1 included in the information of service group 1 both correspond to service group 1, therefore, network device A searches the second mapping relationship shown in Table 7 or Table 8 based on the user information X1 in the first message and the access range Z1 determined in S302 to determine that the access right of user group 1 to which user device B1 belongs to service group 1 is access right 1.

[0132] In an optional embodiment, user information X1 is information about user device B1. For example, user information X1 is a source address, which is the address of user device B1. Network device A determines the user group to which user device B1 belongs based on user information X1 in the first message. Network device A determines user device B1's access rights to the first service group based on information about the user group to which user device B1 belongs and access scope Z1 determined in S302. In one embodiment, network device A includes a second mapping relationship and a third mapping relationship. The second mapping relationship includes a mapping relationship between information about the user group to which user device B1 belongs, information about the first service group, and access rights P, where access rights P is the access rights of the user group to which user device B1 belongs to the first service group. The third mapping relationship includes a mapping relationship between user information X1 and information about the user group to which user device B1 belongs. Network device A determines the user group to which user device B1 belongs based on the third mapping relationship and user information X1 in the first message. Network device A determines the access rights of the user group to which user device B1 belongs to the first service group based on the second mapping relationship, information about the user group to which user device B1 belongs, and access scope Z1 determined in S302, thereby determining user device B1's access rights to the first service group. In a specific embodiment, network device A searches the third mapping relationship based on user information X1 in the first message to determine the user group to which user device B1 belongs. Network device A searches the second mapping relationship based on information about the user group to which user device B1 belongs and access scope Z1 determined in S302 to determine the access rights of the user group to which user device B1 belongs to the first service group. In an optional embodiment, the information of the first service group includes a second bitmap, the second bitmap including a first bit, the first bit corresponding to the first service group. The information of the first service group may further include a domain identifier, the domain identifier being used to indicate the bitmap domain to which the second bitmap belongs. The bitmap domain to which the second bitmap belongs may be the same as the bitmap domain to which the first bitmap belongs, and the position of the first bit in the second bitmap may be the same as the position of the first bit in the first bitmap. As an example, the user group to which user device B1 belongs is user group 1, the first service group is service group 1, the information of the first service group includes a domain identifier and a second bitmap, the access permission P is access permission 1, the third mapping relationship is shown in Table 9 below, and the second mapping relationship is shown in Table 10 below.

[0133] Table 9 (third mapping relationship)

[0134] User information X1 (e.g. source address 1) Information about user group 1 (e.g., the ID of user group 1)

[0135] Table 10 (Second mapping relationship)

[0136]

[0137] Based on Table 10 and the description of the foregoing embodiment, it can be understood that the second bitmap is the intra-domain bitmap Q1.

[0138] Table 9 illustrates the third mapping relationship as including a set of mapping relationships. In some embodiments, the third mapping relationship includes multiple mapping relationships, each of which is a mapping relationship between user information and user group information. The multiple mapping relationships include a mapping relationship between user information X1 and information about the user group to which user device B1 belongs. In the third mapping relationship, each piece of user information indicates a user device, and the user group information corresponding to each piece of user information indicates a user group to which the user device indicated by the user information belongs. Each piece of user information can be a source address. As an example, the third mapping relationship is shown in Table 11 below.

[0139] Table 11 (third mapping relationship)

[0140] User information X1 (e.g. source address 1) Information about user group 1 (e.g., the ID of user group 1) User information X2 (e.g. source address 2) Information about user group 1 (e.g., the ID of user group 1) User information X3 (e.g. source address 3) Information about user group 2 (e.g., the identifier of user group 2) ...... ......

[0141] Each row in Table 11 represents a set of mapping relationships. For example, as shown in Table 11, user information X1 and user group 1 information form a mapping relationship, user information X2 and user group 2 information form a mapping relationship, user information X3 and user group 3 information form a mapping relationship, and so on. For example, user information X1 is used to indicate user device B1, and user group 1 information is used to indicate user group 1. The mapping relationship between user information X1 and user group 1 information indicates that user device B1 belongs to user group 1. User information X2 is used to indicate user device B2, and user group 2 information is used to indicate user group 2. The mapping relationship between user information X2 and user group 2 information indicates that user device B2 belongs to user group 2. User information X3 is used to indicate user device B3, and user group 3 information is used to indicate user group 3. The mapping relationship between user information X3 and user group 3 information indicates that user device 3 belongs to user group B3. And so on. Table 11 uses the example of one user device belonging to one user group. In actual applications, one user device belongs to at least one user group, and one user group includes at least one user device.

[0142] Tables 7, 8, and 10 illustrate the second mapping relationship as including a set of mapping relationships. In some embodiments, the second mapping relationship includes multiple sets of mapping relationships, each of which is a mapping relationship of user group information, service group information, and access rights. The multiple sets of mapping relationships include mapping relationships of user group information to which user device B1 belongs, information of the first service group, and access rights. In the second mapping relationship, each user group information is used to indicate a user group, each service group information is used to indicate a service group, and the access rights in each set of mapping relationships are the access rights of the user group indicated by the user group information in each set of mapping relationships to the service group indicated by the service group information in each set of mapping relationships. The user group information can be a user group identifier. The service group information can include an intra-domain bitmap and a domain identifier of the bitmap domain to which the intra-domain bitmap belongs. As an example, the second mapping relationship is shown in Table 12 below.

[0143] Table 12 (Second Mapping Relationship)

[0144]

[0145] Each row in Table 12 is a set of mapping relationships. For example, as shown in Table 12, the information of user group 1, the information of service group 1, and the access right 1 form a set of mapping relationships (for example, called mapping relationship 1), the information of user group 1, the information of service group 2, and the access right 1 form a set of mapping relationships (for example, called mapping relationship 2), the information of user group 1, the information of service group 5, and the access right 1 form a set of mapping relationships (for example, called mapping relationship 3), the information of user group 1, the information of service group 400, and the access right 1 form a set of mapping relationships (for example, called mapping relationship 4), and so on. Table 12 shows four sets of mapping relationships between the information of user group 1 and the information of four service groups. For example, access right 1 is to allow access, and the four sets of mapping relationships are used to indicate that user group 1 is allowed to access service group 1, service group 2, service group 5, and service group 400. In an optional embodiment, the four sets of mapping relationships have priorities, for example, the priorities of mapping relationships 1 to 4 decrease in sequence.

[0146] As shown in Table 12, information about service group 1 includes domain identifier D1 and intra-domain bitmap Q1. Domain identifier D1 is used to indicate that intra-domain bitmap Q1 belongs to bitmap domain 1. Information about service group 2 includes domain identifier D1 and intra-domain bitmap Q2. Domain identifier D1 is used to indicate that intra-domain bitmap Q2 belongs to bitmap domain 1. Information about service group 5 includes domain identifier D1 and intra-domain bitmap Q3. Domain identifier D1 is used to indicate that intra-domain bitmap Q3 belongs to bitmap domain 1. Information about service group 400 includes domain identifier D1 and intra-domain bitmap Q4. Domain identifier D1 is used to indicate that intra-domain bitmap Q4 belongs to bitmap domain 1. For example, the intra-domain bitmap of bitmap domain 1 has a bit width of n bits, including n bits arranged from low to high. Of these n bits, the first bit corresponds to service group 1, the second bit corresponds to service group 2, the fourth bit corresponds to service group 400, and the fifth bit corresponds to service group 5. Then the intra-domain bitmap Q1 can be 0000…0000001 (a total of n bits, the value of the first bit and the values ​​of the remaining bits are 0), the intra-domain bitmap Q2 can be 0000…0000010 (a total of n bits, the value of the second bit is 1, and the values ​​of the remaining bits are 0), and the intra-domain bitmap Q3 can be 0000…0010000 (a total of n bits, the value of the fifth bit is 1, and the values ​​of the remaining bits are 0). The intra-domain bitmap Q4 can be 0000…0001000 (a total of n bits, the value of the fourth bit is 1, and the values ​​of the remaining bits are 0). The first mapping relationship shown in Table 12 can be concretized as shown in the following Table 13. It should be noted that the correspondence between the service group and the bits in the intra-domain bitmap of bitmap domain 1 in this paragraph is only an example. The correspondence between the service group and the bits in the intra-domain bitmap can be set according to actual conditions, and the embodiments of the present application do not limit this. For example, n=128.

[0147] Table 13 (Second mapping relationship)

[0148]

[0149] It should be noted that the second mapping relationships shown in Table 12 and Table 13 only show mapping relationships related to user group 1. The second mapping relationships may also include mapping relationships related to other user groups, which is not limited in this embodiment of the present application.

[0150] For example, the first service group is service group 1. Network device A searches the third mapping relationship shown in Table 9 or Table 11 based on the user information X1 in the first message to determine that user device B1 belongs to user group 1. Network device A searches the second mapping relationship shown in Table 10, Table 12, or Table 13 based on the information of user group 1 and the access scope Z1 determined in S302 to determine access permission 1 of user group 1 for service group 1. Thus, network device A determines that the access permission of user device B1 in user group 1 for service group 1 is access permission 1. For example, access permission 1 is allowed.

[0151] In an optional embodiment, the second mapping relationship is a UCL rule table, and each group of mapping relationships in the second mapping relationship is a UCL rule table item (or called a UCL rule entry). For example, the mapping relationships 1 to 4 shown in Table 12 and Table 13 can be four UCL rule table items generated based on the first UCL rule "permit source UserGroup1 destination ServiceGroup1, 2, 5, 400", and the mapping relationships 1 to 4 are four UCL rule table items of the first UCL rule "permit source UserGroup1 destination ServiceGroup1, 2, 5, 400". Since the second mapping relationship includes information about the service group rather than information about the services in the service group, the embodiment of the present application can avoid the expansion of UCL rule items, the resource overhead of the network device for storing UCL rules is small, and the storage cost is low.

[0152] In an optional embodiment, the at least one target service group indicated by the first bitmap (that is, at least one service group including the target service) also includes a second service group. For example, the first bitmap also includes a second bit, and the second bit corresponds to the second service group. Network device A determines the access rights of user device B1 to the first service group and the second service group based on user information X1 and access range Z1. For example, network device A determines the access rights of user device B1 to the at least one target service group based on user information X1 and access range Z1. The implementation process of network device A determining the access rights of user device B1 to the at least one target service group based on user information X1 and access range Z1 can refer to the implementation process of network device A determining the access rights of user device B1 to the first service group based on user information X1 and access range Z1, which will not be repeated here. It should be noted that network device A can search the second mapping relationship when determining user device B1's access rights to the at least one target service group based on user information X1 and access scope Z1. Since the first bitmap included in access scope Z1 is used to indicate the at least one target service group, network device A can determine user device B1's access rights to the at least one target service group by searching the second mapping relationship once, thereby ensuring the forwarding performance of network device A. For example, the second mapping relationship is a UCL rule table. That is, network device A can determine user device B1's access rights to the at least one target service group by searching the UCL rule table once, without requiring multiple searches. Therefore, the forwarding performance of network device A can be guaranteed.

[0153] In an optional embodiment, before S303, network device A obtains the second mapping relationship. For example, network device A generates the second mapping relationship, or network device A receives the second mapping relationship sent by the controller. The second mapping relationship sent by the controller to network device A is generated by the controller. The implementation process for network device A to generate the second mapping relationship is similar to the implementation process for the controller to generate the second mapping relationship. The specific implementation will be described below and is not repeated here. After network device A obtains the second mapping relationship, network device A stores the second mapping relationship for easy use. For example, network device A includes a TCAM, and network device A stores the second mapping relationship in the TCAM.

[0154] In an optional embodiment, before S303, network device A obtains a third mapping relationship. For example, network device A generates the third mapping relationship, or network device A receives the third mapping relationship sent by a controller. The third mapping relationship sent by the controller to network device A is generated by the controller. The implementation process for network device A to generate the third mapping relationship is similar to the implementation process for the controller to generate the third mapping relationship. The specific implementation will be described below and is not detailed here. After obtaining the third mapping relationship, network device A may store the third mapping relationship for easy use.

[0155] After network device A determines user device B1's access rights to the first service group, it processes the first message based on user device B1's access rights to the first service group. In one embodiment, if user device B1's access rights to the first service group are "allowed access," meaning user device B1 is permitted to access the first service group, network device A forwards the first message. In another embodiment, if user device B1's access rights to the first service group are "not allowed access," meaning user device B1 is not permitted to access the first service group, network device A discards the first message.

[0156] In summary, the technical solution provided by the embodiments of the present application, because the access scope includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service. Therefore, after the network device determines the access scope based on the service information indicating the target service in the first message, the network device can determine the user device's access rights to the first service group in the at least one service group through a single lookup based on the access scope and the user information indicating the user device in the first message. The network device requires fewer searches to determine the user device's access rights to the first service group, thereby ensuring the network device's forwarding performance.

[0157] Please refer to Figure 4 , which shows a flow chart of another access control method provided by an embodiment of the present application. The access control method is executed by a controller. For example, the controller is Figure 2 The controller 40 in the application scenario shown. Figure 4 The method includes the following steps S401 to S403.

[0158] S401. The controller generates a first mapping relationship, which includes a mapping relationship between service information Y1 and access range Z1. The service information Y1 is used to indicate the target service. The access range Z1 includes a first bitmap. The first bitmap is used to indicate at least one service group including the target service. Each service group includes at least one service, and the at least one service group includes the first service group.

[0159] For information about service information Y1 and access range Z1, please refer to Figure 3 The illustrated embodiment will not be described in detail here. This step S401 mainly introduces the implementation process of the controller generating the first mapping relationship. As mentioned above, the service group including the target service can be called the target service group, so the first bitmap is used to indicate at least one target service group, each service group in the at least one target service group includes the target service.

[0160] In an optional embodiment, the controller generates an access range Z1 based on the service information Y1 and the at least one target service group (including at least one service group of the target service), and the controller generates a first mapping relationship based on the service information Y1 and the access range Z1. For example, the controller generates a mapping relationship between the service information Y1 and the access range Z1, and the controller obtains the first mapping relationship based on the mapping relationship between the service information Y1 and the access range Z1. For example, the controller uses the mapping relationship between the service information Y1 and the access range Z1 as the first mapping relationship; or, the controller uses the mapping relationship between the service information Y1 and the access range Z1 as a group of mapping relationships in the first mapping relationship, which is not limited in the embodiments of the present application.

[0161] In an optional embodiment, the access range Z1 also includes a domain identifier D1, that is, the access range Z1 includes the domain identifier D1 and the first bitmap. The domain identifier D1 is used to indicate the bitmap domain to which the first bitmap belongs. The controller performs a first encoding based on the at least one target service group to obtain an initial bitmap C1, and the controller obtains the access range Z1 based on the service information Y1 and the initial bitmap C1. The initial bitmap C1 is used to indicate the at least one target service group, and the bit width of the initial bitmap C1 is greater than the bit width of the first bitmap. For example, the bit width of the initial bitmap C1 is k bits, and the bit width of the first bitmap is n bits, k is greater than n, and both k and n are positive integers. The initial bitmap C1 includes k bits corresponding one-to-one to k service groups, the k service groups include the at least one target service group, and the k bits include at least one bit corresponding one-to-one to the at least one target service group. In the initial bitmap C1, the value of the at least one bit corresponding one-to-one to the at least one target service group is a first value (for example, 1), and the values ​​of the other bits are a second value (for example, 0). In one embodiment, the bit width of the initial bitmap C1 is equal to the number of multiple service groups provided by the communication network to which the network device A belongs, and the k service groups to which the k bits in the initial bitmap C1 correspond one-to-one are all or part of the service groups provided by the communication network. For example, k=1000 and n=128. That is, the initial bitmap C1 includes 1000 bits, and the first bitmap includes 128 bits. Among them, the 1000 bits correspond one-to-one to 1000 service groups, and the 1000 service groups are all or part of the service groups provided by the communication network to which the network device A belongs. The service groups provided by the communication network to which the network device A belongs refer to service groups obtained by grouping the services provided by the communication network, and the services provided by the communication network may be services provided by service devices connected to the communication network.

[0162] In an optional embodiment, the controller performs a first encoding based on the service group to which each service in the at least one service belongs, to obtain at least one initial bitmap corresponding to the at least one service. Each initial bitmap in the at least one initial bitmap is used to indicate the at least one service group to which the corresponding service belongs. The at least one initial bitmap includes initial bitmap C1. As an example, the at least one service includes service 1, service 2, and service 3. The communication network to which network device A belongs provides 1000 service groups, namely service groups 1 to 1000. Service 1 belongs to service group 1, service group 2, and service group 400, service 2 belongs to service group 1 and service group 5, and service 3 belongs to service group 1. The controller performs a first encoding based on the service groups to which service 1 belongs (i.e., service group 1, service group 2, and service group 400) to obtain an initial bitmap corresponding to service 1. This initial bitmap is 0000…1…0000011 (a total of 1000 bits, with the values ​​of the first, second, and 400th bits being 1, and the values ​​of the remaining bits being 0). This initial bitmap is used to indicate service groups 1, 2, and 400. The controller performs a first encoding based on the service groups to which service 2 belongs (i.e., service group 1 and service group 5) to obtain an initial bitmap corresponding to service 2. This initial bitmap is 0000…0010001 (a total of 1000 bits, with the values ​​of the first and fifth bits being 1, and the values ​​of the remaining bits being 0). This initial bitmap is used to indicate service groups 1 and 5. The controller performs a first encoding based on the service group to which service 3 belongs (i.e., service group 1) to obtain an initial bitmap corresponding to service 3. The initial bitmap is 0000…0000001 (a total of 1000 bits, the value of the first bit is 1, and the values ​​of the remaining bits are 0). The initial bitmap is used to indicate service group 1. Among them, the initial bitmap C1 can be the initial bitmap corresponding to any service among service 1, service 2, and service 3. For example, the target service is service 1, and the initial bitmap C1 is the initial bitmap corresponding to service 1. The initial bitmap corresponding to service 2 can be called initial bitmap C2, and the initial bitmap corresponding to service 3 can be called initial bitmap C3. The initial bitmap C1, initial bitmap C2, and initial bitmap C3 can be shown in Table 14 below.

[0163] Table 14

[0164]

[0165] In an optional embodiment, after the controller obtains at least one initial bitmap corresponding to at least one service, the controller stores the mapping relationship between the service information of the at least one service and the at least one initial bitmap for use in the subsequent second encoding. The service information may be a destination address, or the service information includes a destination address, a destination port number, and a protocol number. For example, the service information of service 1 is service information Y1 (for example, destination address 1), the service information of service 2 is service information Y2 (for example, destination address 2), and the service information of service 3 is service information Y3 (for example, destination address 3). The controller may also store multiple sets of mapping relationships as shown in Table 15 below.

[0166] Table 15

[0167] Service information Y1 (e.g. destination address 1) Initial bitmap C1 (e.g. 0000…1…0000011) Service information Y2 (e.g. destination address 2) Initial bitmap C2 (e.g. 0000…0010001) Service information Y3 (e.g. destination address 3) Initial bitmap C3 (e.g. 0000…0000001) ...... ......

[0168] Since the initial bitmap C1 is used to indicate service group 1, service group 2 and service group 400 shown in service 1, the initial bitmap C2 is used to indicate service group 1 and service group 5 shown in service 2, and the initial bitmap C3 is used to indicate service group 1 shown in service 3, each of the initial bitmaps C1, C2 and C3 also expresses an access range, which is not limited in the embodiments of the present application.

[0169] After the controller obtains the initial bitmap C1, the controller obtains the access range Z1 according to the service information Y1 and the initial bitmap C1. In the embodiment of the present application, the controller obtains the access range Z1 according to the service information Y1 and the initial bitmap C1 in the following two implementations.

[0170] A first implementation manner: the controller performs a second encoding based on the service information Y1 and the initial bitmap C1 to obtain the access range Z1.

[0171] In an optional embodiment, the controller adopts a coding strategy to perform a second coding based on the service information Y1 and the initial bitmap C1 to obtain an access range Z1. In a specific embodiment, the controller adopts a coding strategy to perform a second coding based on the service information Y1 and the initial bitmap C1 to obtain a first bitmap and a bitmap domain to which the first bitmap belongs, and the controller generates an access range Z1 based on the first bitmap and the bitmap domain to which the first bitmap belongs. In an embodiment of the present application, a service group includes at least one service, and a service belongs to at least one service group. The coding strategy may include at least one of the following: the bit width of the bitmap obtained by the second coding (i.e., the bitmap within the domain) is smaller than the bit width of the initial bitmap; the service group to which the same service belongs is encoded into the bitmap of the same bitmap domain (i.e., the bitmap within the domain); the service group to which the services in the service group to which the same service belongs is encoded into the bitmap of the same bitmap domain (i.e., the bitmap within the domain). In a specific example, the encoding strategy includes at least one of the following: the bit width of the intra-domain bitmap obtained by the second encoding is smaller than the bit width of the initial bitmap; all service groups belonging to the same service are encoded into the same intra-domain bitmap; service groups belonging to different services in all service groups belonging to the same service are encoded into different intra-domain bitmaps in the same bitmap domain. Among them, the bit widths of different intra-domain bitmaps obtained by the second encoding are equal, for example, both are n bits. For example, the bit width of the intra-domain bitmap obtained by the second encoding is smaller than the bit width of the initial bitmap, including: the bit width of the initial bitmap is 1000 bits, and the bit width of the intra-domain bitmap obtained by the second encoding is 128 bits. For example, service 1 belongs to service group 1, service group 2, and service group 400, service 2 belongs to service group 1 and service group 5, and service 3 belongs to service group 1. All service groups belonging to the same service are encoded into the same intra-domain bitmap, for example: service group 1, service group 2 and service group 400 belonging to service 1 are encoded into the same intra-domain bitmap (for example, intra-domain bitmap M1), service group 1 and service group 5 belonging to service 2 are encoded into the same intra-domain bitmap (for example, intra-domain bitmap M2), and service group 1 belonging to service 3 is encoded into the same intra-domain bitmap (for example, intra-domain bitmap M3). The service groups to which different services in all service groups to which the same service belongs are encoded into different intra-domain bitmaps of the same bitmap domain, for example, including: the service groups to which different services (that is, service 1, service 2, and service 3) in the service group to which service 1 belongs (that is, service group 1, service group 2, and service group 400) are encoded into different intra-domain bitmaps of the same bitmap domain, for example, service group 1, service group 2, and service group 400 to which service 1 belongs are encoded into intra-domain bitmap M1, service group 1 and service group 5 to which service 2 belongs are encoded into intra-domain bitmap M2, and service group 1 to which service 3 belongs is encoded into intra-domain bitmap M3, and the intra-domain bitmap M1, intra-domain bitmap M2, and intra-domain bitmap M3 belong to the same bitmap domain, for example, all belong to bitmap domain 1.

[0172] In an optional embodiment, the controller uses a coding strategy to perform a second encoding based on the service information Y1 and the initial bitmap C1 to obtain the first bitmap and the bitmap domain to which the first bitmap belongs, including: the controller obtains (e.g., generates) a base bitmap of bitmap domain 1, the bit width of the base bitmap being smaller than the bit width of the initial bitmap C1; the controller determines the target service based on the service information Y1; the controller determines the at least one target service group to which the target service belongs based on the initial bitmap C1; the controller encodes the at least one target service group into the base bitmap to obtain the first bitmap; the controller determines that the first bitmap belongs to bitmap domain 1. In a specific embodiment, the value of each bit in the base bitmap is a second value (e.g., 0), the controller determines at least one bit in the base bitmap that corresponds one-to-one to the at least one target service group, and the controller modifies the value of the at least one bit to the first value (e.g., 1) to encode the at least one target service group into the base bitmap. The meaning of each bit in the basic bitmap of bitmap domain 1 is determined according to the encoding rule of bitmap domain 1, and the encoding rule of bitmap domain 1 is used to indicate the meaning of each bit in the intra-domain bitmap of bitmap domain 1. For example, the encoding rule of bitmap domain 1 is the correspondence between each bit in the intra-domain bitmap of bitmap domain 1 and the service group, or the encoding rule of bitmap domain 1 is the correspondence between each bit in the intra-domain bitmap of bitmap domain 1 and the bit in the initial bitmap. The encoding rule of the bitmap domain can be configured by the user, and the encoding rules of different bitmap domains may be different, which is not limited in the embodiment of the present application. In a specific embodiment, the controller determines at least one bit in the basic bitmap corresponding to the at least one target service group according to the encoding rule of bitmap domain 1, and the controller modifies the value of the at least one bit to a first value (for example, 1).

[0173] For example, the initial bitmap C1 is shown in Table 14, and the target service is service 1 indicated by the service information Y1. The encoding rules of bitmap domain 1 include: the first bit in the domain bitmap corresponds to the first bit in the initial bitmap (that is, corresponding to service group 1), the second bit in the domain bitmap corresponds to the second bit in the initial bitmap (that is, corresponding to service group 2), and the fourth bit in the domain bitmap corresponds to the 400th bit in the initial bitmap (that is, corresponding to service group 400). The bit width of the initial bitmap C1 is 1000 bits, and the bit width of the first bitmap is 128 bits. The process of the controller performing the second encoding using the encoding strategy based on the service information Y1 and the initial bitmap C1 is as follows. The controller generates a basic bitmap of bitmap domain 1, the bit width of the basic bitmap is 128 bits, and the value of each bit in the basic bitmap is 0. The controller determines service 1 based on service information Y1, and determines that service 1 belongs to service group 1, service group 2, and service group 400 based on the initial bitmap C1 shown in Table 14 (the values ​​of the first bit, the second bit, and the 400th bit in the initial bitmap C1 are 1, and the values ​​of the remaining bits are 0). The controller determines that the first bit in the base bitmap corresponds to the first bit in the initial bitmap (i.e., corresponding to service group 1), the second bit in the base bitmap corresponds to the second bit in the initial bitmap (i.e., corresponding to service group 2), and the fourth bit in the base bitmap corresponds to the 400th bit in the initial bitmap (i.e., corresponding to service group 400) based on the above-mentioned encoding rule of bitmap domain 1. The controller modifies the values ​​of the first bit, the second bit, and the fourth bit in the base bitmap to 1 to encode service group 1, service group 2, and service group 400 into the base bitmap. The controller encodes service group 1, service group 2, and service group 400 into the basic bitmap to obtain a first bitmap, which belongs to bitmap domain 1. For example, the first bitmap is 0000...0001011 (a total of 128 bits, with the values ​​of the first, second, and fourth bits being 1, and the values ​​of the remaining bits being 0).

[0174] In an optional embodiment, the controller performs a second encoding using a coding strategy based on at least one piece of service information and at least one initial bitmap corresponding to the at least one piece of service information to obtain at least one intra-domain bitmap and the bitmap domain to which each intra-domain bitmap in the at least one intra-domain bitmap belongs. The at least one piece of service information includes service information Y1, the at least one initial bitmap includes initial bitmap C1, and the at least one intra-domain bitmap includes a first bitmap. In a specific embodiment, for each piece of service information in the at least one piece of service information, the controller determines at least one service group to which the service indicated by the service information belongs based on the initial bitmap corresponding to the service information, and encodes the at least one service group into the same intra-domain bitmap, such that service groups belonging to different services within all service groups belonging to the same service are encoded into different intra-domain bitmaps in the same bitmap domain. The following example illustrates the controller performing the second encoding using the coding strategy based on the service information Y1-Y3 and the initial bitmaps C1-C3 corresponding to the service information Y1-Y3 shown in Table 15. The following description assumes that the bit width of the initial bitmaps C1-C3 is 1000 bits and the bit width of the intra-domain bitmap is 128 bits. For example, the encoding rules of bitmap domain 1 include: the first bit in the domain bitmap corresponds to the first bit in the initial bitmap (that is, corresponding to service group 1), the second bit in the domain bitmap corresponds to the second bit in the initial bitmap (that is, corresponding to service group 2), the fourth bit in the domain bitmap corresponds to the 400th bit in the initial bitmap (that is, corresponding to service group 400), and the fifth bit in the domain bitmap corresponds to the fifth bit in the initial bitmap (that is, corresponding to service group 5).

[0175] The controller first performs a second encoding based on the service information Y1 and the initial bitmap C1 corresponding to the service information Y1. Specifically, the controller generates a basic bitmap of bitmap domain 1, the bit width of the basic bitmap is 128 bits, and the value of each bit in the basic bitmap is 0. The controller determines service 1 based on the service information Y1, and the controller determines that service 1 belongs to service group 1, service group 2, and service group 400 based on the initial bitmap C1 shown in Table 14 (the values ​​of the 1st bit, the 2nd bit, and the 400th bit in the initial bitmap C1 are 1, and the values ​​of the remaining bits are 0). According to the above-mentioned encoding rules of bitmap domain 1, the controller determines that the 1st bit in the basic bitmap corresponds to the 1st bit in the initial bitmap (that is, corresponding to service group 1), the 2nd bit in the basic bitmap corresponds to the 2nd bit in the initial bitmap (that is, corresponding to service group 2), and the 4th bit in the basic bitmap corresponds to the 400th bit in the initial bitmap (that is, corresponding to service group 400). The controller modifies the values ​​of the first, second, and fourth bits in the base bitmap to 1, thereby encoding service group 1, service group 2, and service group 400 into the base bitmap. After encoding service group 1, service group 2, and service group 400 into the base bitmap, the controller obtains an intra-domain bitmap M1, which is 0000...0001011 (a total of 128 bits, with the values ​​of the first, second, and fourth bits being 1 and the values ​​of the remaining bits being 0).

[0176] After determining that service 1 belongs to service group 1, service group 2, and service group 400, the controller determines, for each of service groups 1, 2, and 400 to which service 1 belongs, at least one service other than service 1 in each service group based on initial bitmaps C1 to C3 shown in Table 15. The controller determines, based on the initial bitmap corresponding to each of the at least one service, at least one service group to which each service belongs, and also encodes the at least one service group into the intra-domain bitmap of bitmap domain 1. Specifically, the controller determines that service group 1 also includes service 2 and service 3 based on the initial bitmaps C1 to C3 (since the value of the first bit in each of the initial bitmaps C1 to C3 is 1, the controller determines that the service group indicated by each initial bitmap in the initial bitmaps C1 to C3 includes service group 1, and then the controller determines that service group 1 also includes service 2 indicated by service information Y2 based on the mapping relationship between service information Y2 and initial bitmap C2 shown in Table 15, and the controller determines that service group 1 also includes service 3 indicated by service information Y3 based on the mapping relationship between service information Y3 and initial bitmap C3 shown in Table 15), and determines that service group 2 and service group 400 do not include at least one service other than service 1, and the controller also encodes the service group to which service 2 belongs and the service group to which service 3 belongs into the intra-domain bitmap of bitmap domain 1. Specifically, the controller performs a second encoding based on the service information Y2 and the initial bitmap C2 corresponding to the service information Y2 to encode the service group to which the service 2 indicated by the service information Y2 belongs into the intra-domain bitmap of the bitmap domain 1. The controller performs a second encoding based on the service information Y3 and the initial bitmap C3 corresponding to the service information Y3 to encode the service group to which the service 3 indicated by the service information Y3 belongs into the intra-domain bitmap of the bitmap domain 1.

[0177] The controller performs a second encoding based on the service information Y2 and the initial bitmap C2 corresponding to the service information Y2. Specifically, the controller generates a basic bitmap of bitmap domain 1, the bit width of the basic bitmap is 128 bits, and the value of each bit in the basic bitmap is 0. The controller determines service 2 based on the service information Y2, and the controller determines that service 2 belongs to service group 1 and service group 5 based on the initial bitmap C2 shown in Table 14 (the values ​​of the first bit and the fifth bit in the initial bitmap C2 are 1, and the values ​​of the remaining bits are 0). The controller determines that the first bit in the basic bitmap corresponds to the first bit in the initial bitmap (that is, corresponding to service group 1), and the fifth bit in the basic bitmap corresponds to the fifth bit in the initial bitmap (that is, corresponding to service group 5) based on the above-mentioned encoding rules of bitmap domain 1. The controller modifies the values ​​of the first bit and the fifth bit in the basic bitmap to 1 to encode service group 1 and service group 5 into the basic bitmap. The controller encodes service group 1 and service group 5 into the basic bitmap to obtain the intra-domain bitmap M2, which is 0000...0010001 (a total of 128 bits, the values ​​of the first and fifth bits are 1, and the values ​​of the remaining bits are 0).

[0178] The controller performs a second encoding based on the service information Y3 and the initial bitmap C3 corresponding to the service information Y3. Specifically, the controller generates a basic bitmap of bitmap domain 1, the bit width of the basic bitmap is 128 bits, and the value of each bit in the basic bitmap is 0. The controller determines service 3 based on the service information Y3, and the controller determines that service 3 belongs to service group 1 based on the initial bitmap C3 shown in Table 14 (the first bit in the initial bitmap C3, the values ​​of the remaining bits are 0). The controller determines that the first bit in the basic bitmap corresponds to the first bit in the initial bitmap (that is, corresponding to service group 1) based on the above-mentioned encoding rule of bitmap domain 1. The controller modifies the value of the first bit in the basic bitmap to 1 to encode service group 1 into the basic bitmap. After encoding service group 1 into the basic bitmap, the controller obtains the intra-domain bitmap M3, which is 0000...0000001 (a total of 128 bits, the value of the first bit is 1, and the values ​​of the remaining bits are 0).

[0179] The second implementation manner: the controller obtains the access range Z1 by segmenting the initial bitmap C1.

[0180] The controller segments the initial bitmap C1 to obtain a first segment, which is the first bitmap. The first segment includes a plurality of consecutive bits in the initial bitmap C1, and the first segment includes bits corresponding to the target service indicated by the service information Y1. The first segment belongs to a bitmap domain, the first segment is an intra-domain bitmap, and the identifier of the first segment is the domain identifier of the bitmap domain. The controller generates an access range Z1 based on the first bitmap and the domain identifier of the bitmap domain to which the first bitmap belongs (e.g., the identifier of the first segment).

[0181] In an optional embodiment, the controller segments the initial bitmap C1 to obtain a plurality of segments, each of the plurality of segments being an intra-domain bitmap, the plurality of segments corresponding one-to-one to a plurality of bitmap domains, and the identifier of each segment being the domain identifier of the bitmap domain to which the segment belongs. For example, each segment of the plurality of segments includes a plurality of consecutive bits in the initial bitmap C1. For example, the bit width of the initial bitmap C1 is 1000 bits, and the bit width of each of the multiple segments is 128 bits. The controller divides the 1st to 128th bits in the initial bitmap C1 into a segment (e.g., segment 1), the controller divides the 129th to 256th bits in the initial bitmap C1 into a segment (e.g., segment 2), the controller divides the 257th to 384th bits in the initial bitmap C1 into a segment (e.g., segment 3), and so on. The controller divides the 769th to 896th bits in the initial bitmap C1 into a segment (e.g., segment 7), and the controller divides the 897th to 1000th bits in the initial bitmap C1 into a segment (e.g., segment 8), and the controller pads segment 8 so that the bit width of segment 8 is 128 bits. For example, the controller adds 24 zeros to the high bits of segment 8 to pad segment 8.

[0182] Based on the foregoing description, it can be seen that in the embodiments of the present application, both the first encoding and the second encoding are bitmap encoding. The first encoding process generates an initial bitmap based on at least one service group. The second encoding process generates an access range including an intra-domain bitmap and a domain identifier based on the service information and the initial bitmap. Because the bit width of the intra-domain bitmap is smaller than the bit width of the initial bitmap, the second encoding is a bitmap compression encoding.

[0183] S402. The controller generates a second mapping relationship, which includes a mapping relationship between user information X1, information of the first service group, and access rights P. The user information X1 is used to indicate the user device B1, and the access rights P is the access rights of the user device B1 to the first service group.

[0184] In an optional embodiment, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit in the second bitmap corresponds to the first service group. The information of the first service group may also include a domain identifier, the domain identifier is used to indicate the bitmap domain to which the second bitmap belongs, and the second bitmap is an intra-domain bitmap. The first bit in the first bitmap corresponds to the first service group, the bitmap domain to which the second bitmap belongs is the same as the bitmap domain to which the first bitmap belongs, and the position of the first bit in the first bitmap is the same as the position of the first bit in the second bitmap.

[0185] In an optional embodiment, the controller determines the information of the first service group based on the access range Z1, the controller obtains the user information X1 and the access permission P, and the controller generates a second mapping relationship based on the user information X1, the information of the first service group, and the access permission P. In a specific embodiment, the controller generates a mapping relationship among the user information X1, the information of the first service group, and the access permission P, and the controller obtains the second mapping relationship based on the mapping relationship among the user information X1, the information of the first service group, and the access permission P. For example, the controller uses the mapping relationship among the user information X1, the information of the first service group, and the access permission P as the second mapping relationship. Alternatively, the controller uses the mapping relationship among the user information X1, the information of the first service group, and the access permission P as a set of mapping relationships in the second mapping relationship, which is not limited in the embodiments of the present application.

[0186] In an optional embodiment, the access range Z1 includes a domain identifier D1 and a first bitmap (e.g., an intra-domain bitmap M1), and the controller determines the domain identifier D1 and the first bitmap included in the access range Z1. The controller generates a second bitmap (e.g., an intra-domain bitmap Q1) based on the first bitmap, wherein the value of the first bit in the second bitmap is a first value (e.g., 1), and the values ​​of the other bits are second values ​​(e.g., 0), and the position of the first bit in the second bitmap is the same as the position of the first bit in the first bitmap. The controller generates information of the first service group based on the second bitmap and the domain identifier D1 included in the access range Z1, and the information of the first service group includes the domain identifier D1 and the second bitmap (e.g., the intra-domain bitmap Q1).

[0187] In an optional embodiment, the user information X1 is information about the user group to which the user device B1 belongs, for example, an identifier of the user group. The user information X1 is used to indicate the user group to which the user device B1 belongs, thereby indicating the user device B1. In this case, the second mapping relationship includes a mapping relationship among the user information X1, information about the first service group, and access rights P. The access rights P is the access rights of the user group to which the user device B1 belongs to the first service group, thereby also being the access rights of the user device B1 to the first service group. The controller obtains a first UCL rule, for example, the controller obtains a first UCL rule configured by the user. The first UCL rule includes user information X1 (that is, information about the user group to which the user device B1 belongs), an identifier of the first service group, and access rights P. The controller obtains user information X1 and access rights P according to the first UCL rule, and the controller generates a second mapping relationship based on the user information X1, information about the first service group, and access rights P. For example, user information X is information about user group 1 to which user device B belongs, the first service group is service group 1, and the information about the first service group includes a domain identifier and a second bitmap. The domain identifier is domain identifier D1, the second bitmap is intra-domain bitmap Q1, and the access permission P is access permission 1. The second mapping relationship is shown in Table 7 above. As an example, the intra-domain bitmap Q1 is 0000...0000001, and the second mapping relationship shown in Table 7 can be specifically shown in Table 8.

[0188] In an optional embodiment, the user information X1 is the information of the user device B1. For example, the user information X1 is a source address, which is the address of the user device B1. In this case, the second mapping relationship includes the mapping relationship between the information of the user group to which the user device B1 belongs, the information of the first service group, and the access permission P, and the access permission P is the access permission of the user group to which the user device B1 belongs to the first service group. The controller obtains the first UCL rule, for example, the controller obtains the first UCL rule configured by the user. The first UCL rule includes the information of the user group to which the user device B1 belongs, the identifier of the first service group, and the access permission P. The controller obtains the information of the user group to which the user device B1 belongs and the access permission P according to the first UCL rule, and the controller generates a second mapping relationship based on the information of the user group to which the user device B1 belongs, the information of the first service group, and the access permission P. For example, the first UCL rule includes information about the user group 1 to which the user device B1 belongs, an identifier of the first service group, and access rights P. The first service group is service group 1. The information about the first service group includes a domain identifier and a second bitmap. The domain identifier is the domain identifier D1. The second bitmap is the intra-domain bitmap Q1. The access rights P is access rights 1. The controller generates a second mapping relationship as shown in Table 10 above based on the information about the user group 1 to which the user device B1 belongs, the information of the first service group (domain identifier D1 + intra-domain bitmap Q1), and the access rights P.

[0189] It should be noted that S402 is described using the example of the controller generating a mapping relationship between user information X1, information of the first service group, and access rights P. The controller can use the same method to generate multiple sets of mapping relationships. For example, the controller can generate multiple sets of mapping relationships as shown in Tables 12 and 13. The implementation process of the controller generating each of the multiple sets of mapping relationships refers to the implementation process of the controller generating a mapping relationship between user information X1, information of the first service group, and access rights P, and is not further described in detail in this embodiment of the present application.

[0190] S403: The controller sends the first mapping relationship and the second mapping relationship to network device A.

[0191] The controller can send the first mapping relationship and the second mapping relationship to network device A through the border gateway protocol (BGP), the network configuration protocol (NETCONF), the path computation element communication protocol (PCEP), the telemetry protocol or other private protocols.

[0192] The controller may carry the first mapping relationship and the second mapping relationship in the same message and send it to network device A, or may carry the first mapping relationship and the second mapping relationship in two independent messages and send them to network device A. This embodiment of the present application does not limit this. In one embodiment, the controller sends a control message to network device A, and the control message includes the first mapping relationship and the second mapping relationship. In another embodiment, the controller sends a first control message and a second control message to network device A, and the first control message includes the first mapping relationship, and the second control message includes the second mapping relationship. The control message may be a BGP message, a NETCONF message, a PCEP message, a telemetry message, or other private protocol message, and the protocols used by the first control message and the second control message may be the same or different.

[0193] In summary, the technical solution provided by the embodiment of the present application, in which the controller generates a first mapping relationship and a second mapping relationship, and sends the first mapping relationship and the second mapping relationship to the network device, can facilitate the network device to determine the access scope based on the first mapping relationship and the service information indicating the target service in the message, and determine the user device's access rights to the first service group based on the second mapping relationship, the user information indicating the user device in the message, and the access scope determined based on the first mapping relationship. Because the access scope includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service. That is, at least one service group including the target service is encoded into the same bitmap. Therefore, the network device can determine the user device's access rights to the first service group through a single search based on the second mapping relationship, the user information indicating the user device in the message, and the access scope determined based on the first mapping relationship. The network device requires fewer searches in the process of determining the user device's access rights to the first service group, which can ensure the forwarding performance of the network device.

[0194] In an embodiment of the present application, at least one service group including the target service is encoded into the same bitmap, and the device (such as a network device or a controller) can also avoid the device (such as a network device or a controller) from modifying the user configuration. For example, in the related art, the device usually stores the mapping relationship between the service information and the identifier of the service group to which the service indicated by the service information belongs (a set of mapping relationships includes a service information and an identifier of a service group); when the user configures a service to belong to multiple service groups, the device may generate a comprehensive service group based on the multiple service groups, and generate a mapping relationship between the service information of the service and the identifier of the comprehensive service group to indicate the comprehensive service group through the mapping relationship, thereby indicating the multiple service groups. That is, the device modifies the user configuration. In an embodiment of the present application, at least one service group to which a service belongs is encoded into the same bitmap, and the access scope corresponding to the service information of the service includes the bitmap. The device stores the mapping relationship between the service information of the service and the access scope. The mapping relationship can reflect the at least one service group to which the service belongs. Therefore, the device does not need to generate a comprehensive service group, nor does it need to generate a mapping relationship between the service information and the identifier of the comprehensive service group, which can avoid the device from modifying the user configuration.

[0195] Figure 4 The illustrated embodiment uses the example of a controller generating a first mapping relationship and a second mapping relationship and sending the first mapping relationship and the second mapping relationship to network device A. In an optional embodiment, the controller further generates a third mapping relationship and sends the third mapping relationship to network device A. The third mapping relationship includes a mapping relationship between user information X1 and information about the user group to which user device B1 belongs. For example, if user information X1 is information about user device B1, the controller generates the third mapping relationship and sends the third mapping relationship to network device A.

[0196] In a specific embodiment, the controller determines the user group to which user device B1 belongs. The controller obtains user information X1 indicating user device B1 and information about the user group to which user device B1 belongs. The controller generates a third mapping relationship based on the user information X1 indicating user device B1 and the information about the user group to which user device B1 belongs. For example, if user device B1 belongs to user group 1, the controller generates the third mapping relationship shown in Table 9 based on the user information X1 and the information about user group 1 to which user device B1 belongs.

[0197] In an optional embodiment, a controller determines the user groups to which multiple user devices belong. The controller obtains user information indicating each of the multiple user devices and information indicating the user groups to which each of the multiple user devices belongs. The controller generates a third mapping relationship based on the user information of the multiple user devices and the information of the user groups to which the multiple user devices belong. The third mapping relationship includes multiple groups of mapping relationships, each of which is a mapping relationship between user information and user group information. For example, the multiple user devices include user device B1, user device B2, and user device B3. The controller determines that user device B1 and user device B2 both belong to user group 1, and user device B3 belongs to user group 2. The controller obtains user information X1 indicating user device B1, user information X2 indicating user device B2, user information X3 indicating user device B3, information about user group 1, and information about user group 2. The controller generates the third mapping relationship shown in Table 11 based on user information X1, user information X2, user information X3, information about user group 1, and information about user group 2. The third mapping relationship includes a set of mapping relationships between user information X1 and information of user group 1, a set of mapping relationships between user information X2 and information of user group 2, and a set of mapping relationships between user information X3 and information of user group 3.

[0198] Please refer to Figure 5 , which shows a flowchart of another access control method provided by an embodiment of the present application. Figure 5 The access control method is applied to a system including a network device A and a controller as an example. The network device A can be an access device, a convergence device or a core device in a communication network. For example, the network device A is Figure 2 For any network device in the application scenario shown, the controller is Figure 2 The controller 40 in the application scenario shown. Figure 5 The method includes the following steps S501 to S509.

[0199] S501. The controller generates a first mapping relationship, which includes a mapping relationship between service information Y1 and access range Z1. The service information Y1 is used to indicate the target service. The access range Z1 includes a first bitmap. The first bitmap is used to indicate at least one service group including the target service. Each service group includes at least one service, and the at least one service group includes the first service group.

[0200] S502. The controller generates a second mapping relationship, which includes a mapping relationship between user information X1, information of the first service group, and access rights P. The user information X1 is used to indicate the user equipment B1, and the access rights P is the access rights of the user equipment B1 to the first service group.

[0201] S503: The controller sends the first mapping relationship and the second mapping relationship to network device A.

[0202] S504. Network device A receives the first mapping relationship and the second mapping relationship.

[0203] S505. Network device A stores the first mapping relationship and the second mapping relationship.

[0204] S506. Network device A receives a first message from user device B1. The first message includes user information X1 and service information Y1.

[0205] S507. Network device A determines access range Z1 according to service information Y1 and the first mapping relationship.

[0206] S508. Network device A determines the access rights of user device B1 to the first service group according to user information X1, access scope Z1 and the second mapping relationship.

[0207] S509 . Network device A processes the first message according to the access permission of user device B1 to the first service group.

[0208] The implementation process from S501 to S503 can be Figure 4 The relevant description in the embodiment shown in FIG. 5 can refer to the implementation process of S504 to S509. Figure 3 The relevant descriptions in the illustrated embodiments are not repeated here.

[0209] In summary, the technical solution provided by the embodiment of the present application is that the controller generates a first mapping relationship and a second mapping relationship, and sends the first mapping relationship and the second mapping relationship to the network device. After the network device receives the first message, the network device determines the access range based on the first mapping relationship and the service information for indicating the target service in the first message, and the network device determines the access right of the user device to the first service group based on the second mapping relationship, the user information for indicating the user device in the first message, and the access range determined according to the first mapping relationship. Since the access range includes the first bitmap, the first bitmap is used to indicate at least one service group including the target service. Therefore, the network device can determine the access right of the user device to the first service group through a single search based on the second mapping relationship, the user information for indicating the user device in the first message, and the access range determined according to the first mapping relationship. The number of searches required in the process of the network device determining the access right of the user device to the first service group is relatively small, which can ensure the forwarding performance of the network device.

[0210] It should be noted that the embodiment of the present application is explained by taking the example that the access range includes a bitmap and a domain identifier, and the information of the service group includes and domain identifier. In some embodiments, the access range includes a bitmap but does not include a domain identifier, and the information of the service group includes a bitmap but does not include a domain identifier. In this case, the technical solution provided by the embodiment of the present application is still applicable. For example, the initial bitmap in the above embodiment is directly used as the access range, and the information of the service group is determined based on the initial bitmap, so that the access range includes a bitmap but does not include a domain identifier, and the information of the service group includes a bitmap but does not include a domain identifier. As an example, referring to Table 14 and Table 15, the initial bitmap C1 is used as the access range corresponding to the service information Y1, the initial bitmap C2 is used as the access range corresponding to the service information Y2, the initial bitmap C3 is used as the access range corresponding to the service information Y3, and so on. Furthermore, according to the initial bitmaps C1 to C3, the information of service group 1 is determined to be 0000…0000001 (a total of 1000 bits, the value of the first bit is 1, and the values ​​of the remaining bits are 0), the information of service group 2 is 0000…0000010 (a total of 1000 bits, the value of the second bit is 1, and the values ​​of the remaining bits are 0), the information of service group 5 is 0000…0010000 (a total of 1000 bits, the value of the fifth bit is 1, and the values ​​of the remaining bits are 0), and the information of service group 400 is 0000…1…0000001 (a total of 1000 bits, the value of the 400th bit is 1, and the values ​​of the remaining bits are 0). That is, the access range Z1 in the above embodiment is replaced with the initial bitmap C1, the access range Z2 is replaced with the initial bitmap C2, the access range Z3 is replaced with the initial bitmap C3, and the information of service group 1 is replaced with 0000…0000001, the information of service group 2 is replaced with 0000…0000010, the information of service group 5 is replaced with 0000…0010000, and the information of service group 400 is replaced with 0000…1…0000001, and the technical solution provided in the embodiment of the present application is still available.

[0211] The embodiment of the present application achieves a compression effect on the bitmap by processing the initial bitmap (for example, performing a second encoding based on the initial bitmap or segmenting the initial bitmap), reducing the bit width of the bitmap, thereby reducing the bit width of the access range and the bit width of the service group information, which helps to improve the search efficiency of the network device in determining the access range based on the service information, and improve the search efficiency of the network device in determining the access permission based on the user information and the access range. For example, the bit width of the initial bitmap is 1000 bits. If the initial bitmap is used as the access range, the bit width of the access range is 1000 bits, and the bit width of the service group information is also 1000 bits. In the process of determining the access range based on the service information, the network device needs to search for data with a bit width of 1000 bits (for example, it needs to traverse 1000 bits). In the process of determining the access permission based on the user information and the access range, the network device also needs to search for data with a bit width of 1000 bits (for example, it needs to traverse 1000 bits). In an embodiment of the present application, a second encoding is performed based on the initial bitmap or the initial bitmap is segmented to convert the initial bitmap with a bit width of 1000 bits into a combination of a domain identifier and a bitmap with a bit width of 128 bits of the domain identifier. After this conversion, the information of the access range and the service group can be represented by a combination of a domain identifier and a bitmap with a bit width of 128 bits of the domain identifier. Since the length of the domain identifier is relatively small (for example, usually 2 to 3 bits), the bit width of the access range represented by the combination of the domain identifier and the bitmap is relatively small, and the bit width of the information of the service group represented by the combination of the domain identifier and the bitmap is also relatively small. In the process of determining the access range based on the service information, the network device only needs to look up the domain identifier and data with a bit width of 128 bits (for example, only needs to traverse the domain identifier + 128 bits). In the process of determining the access rights based on the user information and the access range, the network device also only needs to look up the domain identifier and data with a bit width of 128 bits (for example, only needs to traverse the domain identifier + 128 bits). It can be seen that the embodiment of the present application performs a second encoding based on the initial bitmap or segments the initial bitmap, which reduces the bit width of the access range and the bit width of the service group information. In addition, fewer bits need to be traversed during the network device search process, which can improve the search efficiency of the network device. The technical solution of the embodiment of the present application is more effective in improving the search efficiency in scenarios with multiple searches. For example, the network device receives multiple messages from the user device. For each of the multiple messages, the network device searches based on the service information in the message to determine the access range, and searches based on the access range and the user information in the message to determine the access rights.If the access range has a bit width of 1000 bits, the network device needs to search for data with a bit width of 1000 bits each time it determines the access range based on the service information. The network device also needs to search for data with a bit width of 1000 bits each time it determines the access permission based on the user information and the access range. The amount of data that the network device needs to traverse in a single search is large. The more times the network device searches, the larger the total amount of data that the network device traverses (for example, if a search traverses 1000 bits, 10 searches will require traversing 10,000 bits). In the embodiment of the present application, the network device only needs to search for a domain identifier and data with a bit width of 128 bits each time it determines the access range based on the service information. The network device also only needs to search for a domain identifier and data with a bit width of 128 bits each time it determines the access permission based on the user information and the access range. The amount of data that the network device needs to traverse in a single search is small. The more times the network device searches, the smaller the total amount of data that the network device traverses (for example, if a search traverses 128 bits, 10 searches will require traversing 1280 bits). It can be seen that the technical solution of the embodiment of the present application is more effective in improving search efficiency in scenarios with multiple searches.

[0212] It should be noted that the i-th bit (e.g., the first bit, the second bit, etc.) in the bitmap described in the embodiments of the present application refers to the i-th bit in the bitmap arranged in order from low to high. In other embodiments, the i-th bit in the bitmap may be the i-th bit arranged in order from high to low, and this arrangement is also applicable to the technical solutions of the embodiments of the present application.

[0213] The above is an introduction to the method embodiments of the present application. The following describes the device embodiments of the present application, which are used to perform the method of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments.

[0214] Please refer to Figure 6 , which shows a schematic diagram of an access control device 600 provided by an embodiment of the present application. The access control device 600 is applied to a network device. For example, the access control device 600 is a network device or a functional component in a network device. The network device can be Figures 3 to 5 The network device A in the embodiment of the method shown. The network device A may be Figure 1 or Figure 2 Any network device in the application scenario shown. Figure 6 As shown, the access control device 600 includes a receiving module 610 and a processing module 620 .

[0215] A receiving module 610 is configured to receive a first message from a user equipment, where the first message includes user information and service information, where the user information indicates the user equipment and the service information indicates a target service accessed by the user equipment;

[0216] a processing module 620 configured to determine an access scope based on the service information, the access scope including a first bitmap, the first bitmap being used to indicate at least one service group including the target service, each service group including at least one service, the at least one service group including the first service group;

[0217] The processing module 620 is further configured to determine the access permission of the user equipment to the first service group according to the user information and the access scope.

[0218] Optionally, the processing module 620 is configured to determine the access range according to the service information and a first mapping relationship, where the first mapping relationship includes a mapping relationship between the service information and the access range.

[0219] Optionally, the receiving module 610 is further configured to receive a first mapping relationship sent by the controller.

[0220] Optionally, the processing module 620 is used to determine the access rights of the user device to the first service group based on the user information, the access scope and a second mapping relationship, where the second mapping relationship includes a mapping relationship between the user information, the information of the first service group and the access rights.

[0221] Optionally, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group.

[0222] Optionally, the receiving module 610 is further configured to receive a second mapping relationship sent by the controller.

[0223] Optionally, the user information is a source address, and the processing module 620 is used to: determine the user group to which the user equipment belongs according to the user information; and determine the access rights of the user equipment to the first service group according to the information of the user group to which the user equipment belongs and the access scope.

[0224] Optionally, the at least one service group further includes a second service group, and the processing module 620 is configured to determine the access rights of the user equipment to the first service group and the second service group according to the user information and the access scope.

[0225] Optionally, the access range further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

[0226] Optionally, the first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs, and the position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap.

[0227] Optionally, the service information is a destination address; or, the service information includes a destination address, a destination port number, and a protocol number.

[0228] Optionally, the processing module 620 is further configured to process the first message according to the access permission of the user equipment to the first service group.

[0229] Optionally, the processing module 620 is further configured to store the first mapping relationship and the second mapping relationship.

[0230] The function of the receiving module 610 is implemented as follows: Figure 3 Step S301 in the method embodiment shown and Figure 5 For the description of steps S504 and S506 in the embodiment of the method shown, please refer to the following for the functional implementation of the processing module 620. Figure 3 Steps S302 to S303 in the method embodiment shown and Figure 5 The relevant descriptions of step S505 and steps S507 to S509 in the method embodiment are shown.

[0231] In summary, the technical solution provided by the embodiment of the present application, since the access range includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service. That is, at least one service group including the target service is encoded into the same bitmap. Therefore, after the network device determines the access range based on the service information indicating the target service in the first message, the network device can determine the user device's access rights to the first service group in the at least one service group through a single search based on the user information in the first message and the access range. The network device requires fewer searches in the process of determining the user device's access rights to the first service group, thereby ensuring the forwarding performance of the network device.

[0232] Please refer to Figure 7 , which shows a schematic diagram of another access control device 700 provided by an embodiment of the present application. The access control device 700 is applied to a controller. For example, the access control device 700 is a controller or a functional component in a controller. The controller can Figure 2 The controller 40 in the application scenario shown. Figure 7 As shown, the access control device 700 includes a processing module 710 and a sending module 720 .

[0233] Processing module 710 is configured to generate a first mapping relationship, the first mapping relationship including a mapping relationship between service information and an access scope, the service information being used to indicate a target service, the access scope including a first bitmap, the first bitmap being used to indicate at least one service group including the target service, each service group including at least one service, and the at least one service group including the first service group;

[0234] The processing module 710 is further configured to generate a second mapping relationship, the second mapping relationship including a mapping relationship between user information, information of the first service group, and access rights, wherein the user information is used to indicate a user device, and the access rights are access rights of the user device to the first service group;

[0235] The sending module 720 is configured to send the first mapping relationship and the second mapping relationship to the network device.

[0236] Optionally, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group.

[0237] Optionally, the access range further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

[0238] Optionally, the first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs, and the position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap.

[0239] Optionally, the processing module 710 is configured to: generate the access range according to the service information and the at least one service group; and generate a first mapping relationship according to the service information and the access range.

[0240] Optionally, the access range also includes a domain identifier, which is used to indicate the bitmap domain to which the first bitmap belongs. The processing module 710 is used to: perform a first encoding based on the at least one service group to obtain an initial bitmap, the initial bitmap including a first bit, and the first bit corresponding to the first service group; perform a second encoding based on the service information and the initial bitmap to obtain the access range.

[0241] Optionally, the processing module 710 is configured to perform a second encoding using an encoding strategy based on the service information and the initial bitmap to obtain the access range; wherein the encoding strategy includes at least one of the following:

[0242] The bit width of the bitmap obtained by performing the second encoding is smaller than the bit width of the initial bitmap;

[0243] The service groups to which the same service belongs are encoded into the bitmap of the same bitmap field;

[0244] The service groups to which services in the same service group belong are encoded into the bitmap of the same bitmap field.

[0245] Optionally, the information of the first service group includes a second bitmap, the second bitmap includes a first bit, the first bit corresponds to the first service group, and the processing module 710 is used to: determine the information of the first service group based on the access scope; generate a second mapping relationship based on the user information, the information of the first service group and the access permission.

[0246] Optionally, the service information is a destination address; or, the service information includes a destination address, a destination port number, and a protocol number.

[0247] The processing module 710 is used to execute the following steps: Figure 3 Steps S401 to S402 in the method embodiment shown and Figure 5 The sending module 720 is used to execute the following steps: Figure 4 Step S403 in the method embodiment shown and Figure 5 The relevant description of step S503 in the method embodiment is shown.

[0248] In summary, the technical solution provided by the embodiment of the present application, in which the controller sends the first mapping relationship and the second mapping relationship to the network device, can facilitate the network device to determine the access scope based on the first mapping relationship and the service information indicating the target service in the message (such as the first message), and determine the access rights of the user device to the first service group based on the second mapping relationship, the user information indicating the user device in the message (such as the first message), and the access scope determined according to the first mapping relationship. Since the access scope includes a first bitmap, the first bitmap is used to indicate at least one service group including the target service. That is, at least one service group including the target service is encoded into the same bitmap. Therefore, the network device can determine the access rights of the user device to the first service group through a single search based on the second mapping relationship, the user information indicating the user device in the message, and the access scope determined according to the first mapping relationship. The network device needs to search fewer times in the process of determining the access rights of the user device to the first service group, which can ensure the forwarding performance of the network device.

[0249] The access control device provided in the embodiments of the present application can also be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The access control method provided in the above method embodiment can also be implemented using software. When the access control method provided in the above method embodiment is implemented using software, each module in the access control device can also be a software module.

[0250] The embodiment of the present application provides an access control device, including a memory and a processor. The memory is used to store a computer program. The processor is used to execute the computer program stored in the memory so that the access control device performs the following operations: Figures 3 to 5 The illustrated method embodiment provides all or part of the steps of the access control method.

[0251] Please refer to Figure 8 , which shows a schematic diagram of another access control device 800 provided by an embodiment of the present application. The access control device 800 is a network device or a functional component in a network device. The network device can be Figures 3 to 5 The network device A in the embodiment of the method shown. The network device A may be Figure 1 or Figure 2 Any network device in the application scenario shown. The access control device 800 can be used to perform Figure 3 The method embodiment shown and Figure 5 The steps in the method embodiment shown are performed by network device A. Figure 8 As shown, the access control device 800 includes: a main control board 810, an interface board 830 and an interface board 840. In the case of multiple interface boards, a switching network board ( Figure 8 The switching network board is used to complete data exchange between interface boards (interface boards are also called line cards or service boards).

[0252] The main control board 810 performs functions such as system management, device maintenance, and protocol processing. The interface boards 830 and 840 provide various service interfaces and implement message forwarding. These service interfaces include POS interfaces, Gigabit Ethernet (GE) interfaces, and Asynchronous Transfer Mode (ATM) interfaces. The main control board 810 primarily includes three functional units: a system management and control unit, a system clock unit, and a system maintenance unit. The main control board 810, interface boards 830, and interface boards 840 are interconnected via a system bus and the system backplane. The interface board 830 includes one or more processors 831. Processors 831 control and manage the interface boards 830 and communicate with the central processing unit 812 on the main control board 810. The memory 832 on the interface board 830 stores various information required to implement the aforementioned access control method, such as the UCL rule table. The interface board 830 also includes one or more network interfaces 833 for receiving and sending messages. The specific implementation is not detailed here. The main control board 810 also includes a memory 814, which is used to store system management information, protocols, etc., which is not limited in this embodiment of the present application.

[0253] like Figure 8 As shown, this embodiment includes multiple interface boards and employs a distributed forwarding mechanism. Under this mechanism, the operations on interface board 840 are substantially similar to those on interface board 830. For example, interface board 840 includes one or more network interfaces 843 for receiving and sending messages, a memory 842 for storing various possible information required to execute the aforementioned access control method, and a processor 841 for controlling and managing interface board 840 and communicating with central processing unit 812 on main control board 810. For the sake of brevity, detailed description of interface board 840 is omitted here.

[0254] Figure 8 The processor 831 in interface board 830 and / or the processor 841 in interface board 840 can be dedicated hardware or chips, such as a network processor or an application-specific integrated circuit, to implement the aforementioned functions. This implementation is commonly referred to as using dedicated hardware or chips for forwarding plane processing. In other embodiments, the processor 831 in interface board 830 and / or the processor 841 in interface board 840 can also be a general-purpose processor, such as a central processing unit (CPU).

[0255] It should be noted that there may be one or more main control boards, including active and standby boards. There may also be one or more interface boards. The higher the data processing capabilities of a network device, the more interface boards it provides. With multiple interface boards, they can communicate with each other through one or more switching fabric boards (SFMs), enabling load balancing and redundant backup. In a centralized forwarding architecture, network devices may not require SFMs; the interface boards handle service data processing for the entire system. In a distributed forwarding architecture, network devices include multiple interface boards, which can exchange data between them through SFMs, providing high-capacity data exchange and processing capabilities. Therefore, network devices with distributed architectures have greater data access and processing capabilities than those with centralized architectures. The specific architecture to adopt depends on the network deployment scenario and is not defined here.

[0256] In an optional embodiment, the memory 832 and / or the memory 842 is a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these. The memory 832 can be independent and connected to the processor 831 via a communication bus, or it can be integrated with the processor 831. The memory 842 can be independent and connected to the processor 841 via a communication bus, or it can be integrated with the processor 841.

[0257] The memory 832 is used to store program codes and is controlled by the processor 831 to execute part or all of the steps of the method provided in the above embodiment. The processor 831 is used to execute the program codes stored in the memory 832. The program codes may include one or more software modules. The one or more software modules may be the above Figure 6The functional modules provided in the illustrated embodiments. The memory 842 can also be used to store program code, and the processor 841 controls execution thereof to perform some or all steps of the methods provided in the above embodiments. Similarly, the memory 814 can also be used to store program code, and the central processing unit 812 controls execution thereof to perform some or all steps of the methods provided in the above embodiments.

[0258] In an optional implementation, the network interface 833 and the network interface 843 can be devices such as any transceiver for communicating with other devices or communication networks. For example, the communication network can be Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc., which is not limited to this embodiment of the present application.

[0259] Please refer to Figure 9 , which shows a schematic diagram of another access control device 900 provided by an embodiment of the present application. The access control device 900 is a network device or a functional component in a network device, or the access control device 900 is a controller or a functional component in a controller. The network device can be Figures 3 to 5 In the embodiment of the method shown, the network device A may be Figure 1 or Figure 2 Any network device in the application scenario shown. The controller can be Figure 2 The controller 40 in the application scenario shown. The access control device 900 can be used to perform Figures 3 to 5 The method embodiment shown provides all or part of the steps of the access control method. Figure 9 The access control device 900 includes a processor 902 , a memory 904 , a communication interface 906 , and a bus 908 . The processor 902 , the memory 904 , and the communication interface 906 are communicatively connected via the bus 908 . Figure 9 The connection manner among the processor 902 , the memory 904 , and the communication interface 906 shown is only an example. The processor 902 , the memory 904 , and the communication interface 906 may also be connected using a connection manner other than the bus 908 .

[0260] Memory 904 is used to store computer programs 9042, which may include instructions and data. Memory 904 may be various types of storage media, such as RAM, ROM, non-volatile RAM (NVRAM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), flash memory, optical storage, and registers.

[0261] Among them, the processor 902 can be a general-purpose processor. The general-purpose processor can be a processor that performs specific steps and / or operations by reading and executing a computer program (e.g., computer program 9042) stored in a memory (e.g., memory 904). The general-purpose processor may use data stored in the memory (e.g., memory 904) in the process of performing the above steps and / or operations. The stored computer program can be executed, for example, to implement the related functions of the aforementioned processing module 620 and processing module 710. The general-purpose processor can be a CPU. The processor 902 can also be a dedicated processor. A dedicated processor is a processor specially designed to perform specific steps and / or operations. The dedicated processor can be a digital signal processor (DSP), ASIC, or FPGA, etc. The processor 902 can also be a combination of multiple processors, such as a multi-core processor. The processor 902 includes at least one circuit to perform all or part of the steps of the above-mentioned embodiment method.

[0262] The communication interface 906 may include an input / output (I / O) interface, a physical interface, and a logical interface, etc., for interconnecting devices within the access control device 900, as well as an interface for interconnecting the access control device 900 with other devices (e.g., network devices). The physical interface may be a gigabit Ethernet (GE) interface, which may be used to interconnect the access control device 900 with other devices. The logical interface is an interface within the access control device 900, which may be used to interconnect devices within the access control device 900. It is easy to understand that the communication interface 906 may be used for the access control device 900 to communicate with other devices. For example, the communication interface 906 is used to send and receive messages between the access control device 900 and other devices. The communication interface 906 may implement the related functions of the aforementioned receiving module 610 and the related functions of the sending module 720.

[0263] The bus 908 may be any type of communication bus for interconnecting the processor 902, the memory 904, and the communication interface 906. For example, the bus 908 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus 908 may be divided into an address bus, a data bus, a control bus, and the like. For ease of illustration, Figure 9 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0264] The aforementioned components in access control device 900 may be provided on separate chips, or at least partially or entirely on the same chip. Whether to independently provide each component on different chips or to integrate them on one or more chips often depends on product design requirements. The embodiments of this application do not limit the specific implementation of the aforementioned components.

[0265] Figure 9 The access control device 900 shown is merely exemplary. During implementation, the access control device 900 may further include other components, which are not listed here one by one. Figure 9 The access control apparatus 900 shown performs access control on user equipment by executing all or part of the steps of the access control method provided in the above embodiment.

[0266] Based on the same inventive concept, an embodiment of the present application provides an access control system, which includes a network device and a controller. The network device includes Figure 6 、 Figure 8 or Figure 9 Any access control device shown. The controller includes Figures 7 to 9 Any of the access control devices shown. For example, the access control system is as follows Figure 1 or Figure 2 As shown. The network device is any network device in the communication network 10. Figure 1 In the application scenario shown, the controller can be integrated into any network device in the communication network 10.

[0267] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed (for example, by a network device, an access control device, one or more processors, etc.), it implements all or part of the steps of the method provided in the above method embodiment.

[0268] Based on the same inventive concept, an embodiment of the present application provides a computer program product, which includes a program or code. When the program or code is executed (for example, by a network device, an access control device, one or more processors, etc.), it implements all or part of the steps of the method provided in the above method embodiment.

[0269] Based on the same inventive concept, an embodiment of the present application provides a chip comprising a programmable logic circuit and / or program instructions, which, when running, is used to implement all or part of the steps of the method provided in the above method embodiment. The chip can be a control chip or a forwarding chip.

[0270] It should be noted that the description of services and service groups in the embodiments of the present application is only for example and is not intended to limit the technical solutions of the embodiments of the present application. In some embodiments, services are also described as applications, and service groups are also described as application groups, security groups, etc.

[0271] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product, which includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium, or a semiconductor medium (e.g., a solid-state hard disk).

[0272] It should be understood that the term "at least one" in this application refers to one or more, and "a plurality of" refers to two or more. In this application, unless otherwise specified, the symbol " / " generally means or, for example, A / B can mean A or B. The term "and / or" in this application is merely a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, for the sake of clarity of description, this application uses words such as "first", "second", and "third" to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first", "second", and "third" do not limit the quantity and execution order.

[0273] Different types of embodiments, such as method embodiments and device embodiments, provided in the embodiments of the present application can refer to each other. The order of operations of the method embodiments can be appropriately adjusted, and the operations can be increased or decreased in response to the situation. Any technician familiar with this technical field can easily think of different methods within the technical scope disclosed in this application, and they should all be covered within the scope of protection of this application, so they will not be repeated here.

[0274] In the corresponding embodiments provided in the present application, it should be understood that the disclosed devices and the like can be implemented through other structural methods. For example, the device embodiments described above are merely illustrative. For example, the division of modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. On the other hand, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical or other forms. The modules described as separate components may or may not be physically separated, and the components described as modules may or may not be physical modules, and may be located in one place or distributed on multiple network nodes. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment.

[0275] The above description is merely an exemplary embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. An access control method, characterized in that: The method comprises: receiving a first message from a user equipment, the first message including user information and service information, the user information being used to indicate the user equipment, and the service information being used to indicate a target service accessed by the user equipment; determining an access scope according to the service information, the access scope comprising a first bitmap, the first bitmap being used to indicate at least one service group including the target service, each of the service groups comprising at least one service, and the at least one service group comprising a first service group; The access permission of the user equipment to the first service group is determined according to the user information and the access scope.

2. The method according to claim 1, characterized in that The determining of the access scope according to the service information includes: The access range is determined according to the service information and a first mapping relationship, where the first mapping relationship includes a mapping relationship between the service information and the access range.

3. The method according to claim 2, characterized in that The method further comprises: The first mapping relationship sent by the receiving controller is received.

4. The method according to any one of claims 1 to 3, characterized in that The determining, according to the user information and the access scope, the access permission of the user equipment to the first service group includes: The access permission of the user equipment to the first service group is determined according to the user information, the access scope, and a second mapping relationship, where the second mapping relationship includes a mapping relationship between the user information, information of the first service group, and the access permission.

5. The method according to claim 4, characterized in that The information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group.

6. The method according to claim 4 or 5, characterized in that The method further comprises: The second mapping relationship sent by the receiving controller is received.

7. The method according to any one of claims 1 to 6, characterized in that The user information is a source address, and determining the access permission of the user equipment to the first service group according to the user information and the access scope includes: determining the user group to which the user equipment belongs according to the user information; The access permission of the user equipment to the first service group is determined according to the information of the user group to which the user equipment belongs and the access scope.

8. The method according to any one of claims 1 to 7, characterized in that The at least one service group further includes a second service group, and determining, based on the user information and the access scope, access rights of the user equipment to the first service group includes: The access rights of the user equipment to the first service group and the second service group are determined according to the user information and the access scope.

9. The method according to any one of claims 1 to 8, characterized in that The access scope further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

10. The method according to claim 9, characterized in that The first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, and the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs. The position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap.

11. The method according to any one of claims 1 to 10, characterized in that The service information is the destination address; or, The service information includes a destination address, a destination port number and a protocol number.

12. An access control method, characterized in that: The method comprises: generating a first mapping relationship, the first mapping relationship including a mapping relationship between service information and an access scope, the service information being used to indicate a target service, the access scope including a first bitmap, the first bitmap being used to indicate at least one service group including the target service, each of the service groups including at least one service, and the at least one service group including a first service group; generating a second mapping relationship, the second mapping relationship including a mapping relationship between user information, information of the first service group, and access rights, wherein the user information is used to indicate a user equipment, and the access rights are access rights of the user equipment to the first service group; The first mapping relationship and the second mapping relationship are sent to a network device.

13. The method according to claim 12, characterized in that The information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group.

14. The method according to claim 12 or 13, characterized in that The access scope further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

15. The method according to claim 14, characterized in that The first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, and the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs. The position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap.

16. The method according to any one of claims 12 to 15, characterized in that Generating the first mapping relationship includes: generating the access scope according to the service information and the at least one service group; The first mapping relationship is generated according to the service information and the access range.

17. The method according to claim 16, characterized in that The access scope further includes a domain identifier, where the domain identifier is used to indicate a bitmap domain to which the first bitmap belongs. Generating the access scope according to the service information and the at least one service group includes: Performing a first encoding according to the at least one service group to obtain an initial bitmap, the initial bitmap comprising a first bit, the first bit corresponding to the first service group; A second encoding is performed according to the service information and the initial bitmap to obtain the access range.

18. The method according to claim 17, characterized in that The performing second encoding according to the service information and the initial bitmap to obtain the access range includes: performing a second encoding using an encoding strategy according to the service information and the initial bitmap to obtain the access range; The encoding strategy includes at least one of the following: The bit width of the bitmap obtained by performing the second encoding is smaller than the bit width of the initial bitmap; The service groups to which the same service belongs are encoded into the bitmap of the same bitmap field; The service groups to which services in the same service group belong are encoded into the bitmap of the same bitmap field.

19. The method according to any one of claims 12 to 18, characterized in that The information of the first service group includes a second bitmap, the second bitmap includes a first bit, the first bit corresponds to the first service group, and generating the second mapping relationship includes: determining information of the first service group according to the access scope; The second mapping relationship is generated according to the user information, the information of the first service group and the access permission.

20. The method according to any one of claims 12 to 19, characterized in that The service information is the destination address; or, The service information includes a destination address, a destination port number and a protocol number.

21. An access control device, characterized in that: The device includes: a receiving module and a processing module; The receiving module is configured to receive a first message from a user equipment, the first message including user information and service information, the user information being used to indicate the user equipment, and the service information being used to indicate a target service accessed by the user equipment; The processing module is configured to determine an access range according to the service information, the access range comprising a first bitmap, the first bitmap being configured to indicate at least one service group including the target service, each of the service groups comprising at least one service, and the at least one service group comprising the first service group; The processing module is further configured to determine the access rights of the user equipment to the first service group according to the user information and the access scope.

22. The device according to claim 21, characterized in that The processing module is configured to determine the access range according to the service information and a first mapping relationship, where the first mapping relationship includes a mapping relationship between the service information and the access range.

23. The device according to claim 22, characterized in that The receiving module is further configured to receive the first mapping relationship sent by the controller.

24. The device according to any one of claims 21 to 23, characterized in that The processing module is used to determine the access rights of the user equipment to the first service group according to the user information, the access scope and a second mapping relationship, wherein the second mapping relationship includes a mapping relationship between the user information, information of the first service group and the access rights.

25. The device according to claim 24, characterized in that The information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group.

26. The device according to claim 24 or 25, characterized in that The receiving module is further configured to receive the second mapping relationship sent by the controller.

27. The device according to any one of claims 21 to 26, characterized in that The user information is a source address, and the processing module is used to: determine the user group to which the user equipment belongs according to the user information; and determine the access permission of the user equipment to the first service group according to the information of the user group to which the user equipment belongs and the access scope.

28. The device according to any one of claims 21 to 27, characterized in that The at least one service group further includes a second service group, The processing module is configured to determine the access rights of the user equipment to the first service group and the second service group according to the user information and the access scope.

29. The device according to any one of claims 21 to 28, characterized in that The access scope further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

30. The device according to claim 29, characterized in that The first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, and the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs. The position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap.

31. The device according to any one of claims 21 to 30, characterized in that The service information is the destination address; or, The service information includes a destination address, a destination port number and a protocol number.

32. An access control device, characterized in that: The device includes: a processing module and a sending module; The processing module is configured to generate a first mapping relationship, the first mapping relationship including a mapping relationship between service information and an access scope, the service information being used to indicate a target service, the access scope including a first bitmap, the first bitmap being used to indicate at least one service group including the target service, each of the service groups including at least one service, and the at least one service group including the first service group; The processing module is further configured to generate a second mapping relationship, the second mapping relationship including a mapping relationship between user information, information of the first service group, and access rights, wherein the user information is used to indicate a user equipment, and the access rights are access rights of the user equipment to the first service group; The sending module is used to send the first mapping relationship and the second mapping relationship to the network device.

33. The device according to claim 32, characterized in that The information of the first service group includes a second bitmap, the second bitmap includes a first bit, and the first bit corresponds to the first service group.

34. The device according to claim 32 or 33, characterized in that The access scope further includes a domain identifier, and the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs.

35. The device according to claim 34, characterized in that The first service group corresponds to the first bit in the first bitmap and the first bit in the third bitmap, and the bitmap domain to which the third bitmap belongs is different from the bitmap domain to which the first bitmap belongs. The position of the first bit in the first bitmap is the same as or different from the position of the first bit in the third bitmap.

36. The device according to any one of claims 32 to 35, characterized in that The processing module is used to: generating the access scope according to the service information and the at least one service group; The first mapping relationship is generated according to the service information and the access range.

37. The device according to claim 36, characterized in that The access scope further includes a domain identifier, where the domain identifier is used to indicate the bitmap domain to which the first bitmap belongs. The processing module is configured to: Performing a first encoding according to the at least one service group to obtain an initial bitmap, the initial bitmap comprising a first bit, the first bit corresponding to the first service group; A second encoding is performed according to the service information and the initial bitmap to obtain the access range.

38. The device according to claim 37, characterized in that The processing module is configured to perform a second encoding using an encoding strategy according to the service information and the initial bitmap to obtain the access range; The encoding strategy includes at least one of the following: The bit width of the bitmap obtained by performing the second encoding is smaller than the bit width of the initial bitmap; The service groups to which the same service belongs are encoded into the bitmap of the same bitmap field; The service groups to which services in the same service group belong are encoded into the bitmap of the same bitmap field.

39. The device according to any one of claims 32 to 38, characterized in that The information of the first service group includes a second bitmap, the second bitmap includes a first bit, the first bit corresponds to the first service group, and the processing module is configured to: determining information of the first service group according to the access scope; The second mapping relationship is generated according to the user information, the information of the first service group and the access permission.

40. The device according to any one of claims 32 to 39, characterized in that The service information is the destination address; or, The service information includes a destination address, a destination port number and a protocol number.

41. An access control device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is configured to execute the computer program stored in the memory so that the access control device executes the access control method according to any one of claims 1 to 20.

42. An access control system, characterized in that: including network equipment and controllers; The network device comprises the access control device according to any one of claims 21 to 31 and 41; The controller comprises the access control device according to any one of claims 32 to 41.

43. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed, the access control method according to any one of claims 1 to 20 is implemented.

44. A computer program product, characterized in that The computer program product includes a program or code, and when the program or code is executed, the access control method according to any one of claims 1 to 20 is implemented.