An intent-driven network management method and system based on a large language model
By adopting an intent-driven network management method based on a large language model, the problems of complexity and low automation in traditional network management are solved, achieving efficient, secure, and intelligent network management that can adapt to changes in complex network environments.
Patent Information
- Application Number
- CN202511263103.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Traditional network management methods are complex, error-prone, and have low automation. Existing IDNs face efficiency and accuracy challenges in intent translation, while LLMs have accuracy and security issues in network applications and struggle to handle complex contexts and long-range dependencies.
We adopt an intent-driven network management approach based on Large Language Model (LLM). We obtain intent descriptions through a natural language interface and combine them with a network domain knowledge base and a multi-level verification module to achieve deep intent parsing, configuration generation, and automated deployment, including intent parsing, configuration generation, verification, and closed-loop optimization.
It significantly simplifies network management complexity, improves automation and intelligence, ensures the security and effectiveness of configuration, enhances network agility and adaptability, reduces human error, and enables continuous learning and self-evolution.
Smart Images

Figure CN120768781B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the intersection of computer network technology and artificial intelligence, particularly to a network management technology field, and more specifically, to a method and system for efficient management of intent-driven networks (IDN) by utilizing the natural language understanding and reasoning capabilities of large language models (LLM).
[0002] This invention aims to address the complexity and inefficiency of traditional network management methods, simplify network operation processes, significantly improve the automation and intelligence level of network management, and specifically optimize the performance of complex network protocols such as TCP / IP and QUIC to meet the stringent requirements of modern network environments for agility, reliability, and performance. Background Technology
[0003] With the rapid development and widespread application of technologies such as cloud computing, the Internet of Things, 5G communication, and edge computing, the global network scale is expanding at an unprecedented rate, network topology is becoming increasingly complex, and business traffic is exhibiting high dynamism and unpredictability. Against this backdrop, traditional network management models are facing unprecedented and severe challenges.
[0004] For a long time, network administrators have primarily relied on traditional tools such as command-line interfaces (CLI) and Simple Network Management Protocol (SNMP) for configuring, monitoring, and maintaining network devices. While CLI is powerful, its operation is extremely cumbersome. Administrators need to memorize a large number of complex and often subtly different underlying command sets for devices from different vendors. For example, configuring a complex BGP routing policy or deploying an MPLS traffic engineering tunnel may involve inputting dozens or even hundreds of lines of commands, which is not only time-consuming and laborious but also highly susceptible to human error, such as spelling errors, missing parameters, or logical contradictions. This can lead to network outages, performance degradation, or even security vulnerabilities, resulting in significant economic losses and operational risks. Furthermore, CLI operations are difficult to scale and automate, and are inefficient during large-scale network changes or rapid response to business needs, becoming a key bottleneck restricting network agility.
[0005] SNMP primarily focuses on network monitoring and basic status queries. While it offers some management capabilities, its configuration management functions are limited. Furthermore, its polling-based working mode generates significant network overhead and management latency when dealing with large-scale, highly dynamic networks, making it difficult to meet the needs of real-time, granular management.
[0006] To overcome the shortcomings of traditional network management methods, the concept of IDN (Internet Data Networking) emerged and has received widespread attention in the industry. The core idea of IDN is to shift the focus of network management from "how to do it" to "what to do." Administrators only need to describe the business goals or operational status they expect to achieve through high-level, declarative statements, such as "ensuring low-latency communication for video conferencing application A" or "isolating network access between production and testing environments," without needing to concern themselves with the underlying implementation steps and command details. The IDN system then automatically translates these high-level intentions into specific network device configurations and, through continuous monitoring, verification, and adjustment, builds a closed-loop system to ensure that the network status always aligns with the administrator's intentions.
[0007] However, despite the promising future of IDN, its core component, "intent translation," faces significant challenges in practice. How to efficiently and accurately map the high-level, sometimes ambiguous and unclear intentions inherent in human natural language into machine-executable, conflict-free network configurations that satisfy multiple constraints is a critical problem that urgently needs to be solved for the practical application of IDN technology. Existing IDN solutions often rely on predefined templates or complex policy engines, which have limited flexibility and intelligence, making it difficult to cope with complex and ever-changing intents and network scenarios.
[0008] Breakthroughs in LLMs have brought hope for overcoming the intent translation challenge in IDN. LLMs, represented by the GPT and Llama series, have demonstrated remarkable capabilities in natural language understanding, generation, summarization, translation, question answering, and even coding by pre-training on massive amounts of text and code data. They possess powerful context learning and zero-shot or few-shot reasoning abilities, and are expected to serve as "universal translators" and "intelligent reasoning engines" bridging human natural language intent and machine-executable instructions.
[0009] Combining LLM's superior natural language processing capabilities with IDN's automation framework holds immense potential. LLM can understand network requirements expressed by administrators in everyday language, extract key elements, and combine this with network domain expertise to generate corresponding network configuration scripts or API calls. Especially in protocol optimization scenarios like TCP / IP and QUIC, which involve numerous adjustable parameters with complex coupling relationships, the introduction of LLM can help the system understand the complexity of multi-objective optimization and explore better parameter combinations, thereby improving network performance.
[0010] Despite its promising prospects, applying LLM directly to the serious field of network configuration is no easy task, and a series of challenges must be faced and addressed.
[0011] Accuracy and reliability are critical issues for LLM systems, which suffer from an "illusion" problem, potentially generating configurations that appear reasonable but are actually incorrect or invalid. Ensuring that LLM-generated configurations are 100% syntactically and logically correct is the primary challenge.
[0012] Domain knowledge integration is crucial, as general-purpose LLMs often lack in-depth network expertise, such as the nuances of specific protocols, vendor equipment configuration specifications, and best practices for network operations and maintenance. Effectively infusing this domain knowledge into LLMs to equip them with the capabilities of network experts is essential.
[0013] Security and compliance are paramount, and network configuration directly impacts network security. Ensuring that LLM-generated configurations conform to established security policies and compliance requirements, and preventing the generation of configurations that may introduce security risks, is a significant challenge.
[0014] Context understanding and long-range dependencies: Network intents often involve complex contexts and cross-device dependencies, but LLMs have limited context windows. How to handle large-scale, long-range network intents is a technical challenge.
[0015] Closed-loop and adaptive management are key to achieving truly intelligent management, as network conditions are constantly changing. The key is to involve LLM in closed-loop management and enable configuration adjustments and self-optimization based on real-time feedback.
[0016] In conclusion, there is an urgent need to develop a new network management method and system that can fully leverage the advantages of LLM while overcoming its application challenges in the network field. This system should construct an intent-driven network management system capable of reliably parsing natural language intents, generating secure and effective configurations by combining network knowledge, and achieving automated deployment and closed-loop self-optimization. This would fundamentally change the current state of network operations and maintenance, and propel network management into a new era of intelligence. Summary of the Invention
[0017] The purpose of this invention is to overcome the challenges of complex operation, error susceptibility, low automation, and efficiency and accuracy issues in intent translation within existing network management technologies. This invention aims to propose an intent-driven network management method and system based on a large-scale language model. By introducing the powerful natural language processing and reasoning capabilities of LLM (Large Language Model), it significantly simplifies the interaction between humans and the network, improves the automation and intelligence of network configuration, management, and optimization, and ensures the security and effectiveness of network configuration.
[0018] To achieve the above objectives, the present invention provides the following technical solution: a method for intent-driven network management based on a large language model, the method comprising:
[0019] The receiving module obtains network intent descriptions input in natural language form by network administrators or upper-layer applications through natural language interfaces such as web interfaces, chatbots, and APIs.
[0020] This intent description can be unstructured and includes the performance goals the network is expected to achieve, business requirements, security policies, and related constraints; for example, inputting "From 9:00 to 18:00 Monday to Friday, prioritize ensuring end-to-end latency of less than 80ms and bandwidth of no less than 20Mbps for a certain video conferencing application A and application B, and ensure that all QUIC traffic is encrypted with TLS 1.3, while avoiding affecting the normal access of the financial system."
[0021] The parsing module utilizes a pre-trained large-scale language model adapted and fine-tuned with network domain knowledge to perform in-depth parsing of the received natural language intent;
[0022] This process aims to transform ambiguous, high-level human language into precise, structured, machine-understandable representations. This module is responsible for extracting key information from the intent, including but not limited to the target service, performance metrics and their thresholds, security requirements, device scope, and constraints, and understanding the logical relationships and priorities between them. Finally, it outputs a structured network intent representation using JSON, YAML, or a custom data structure.
[0023] The configuration generation module is based on the structured network intent representation output by the parsing module and deeply integrates a specially built network protocol knowledge base to intelligently generate specific configuration schemes or complete network configurations for the target network environment.
[0024] This network protocol knowledge base is a key component of the present invention. It is not merely a collection of static documents, but a dynamic knowledge system that includes complex dependencies between protocol parameters, configuration specifications and command syntax of different network equipment manufacturers, best practices for network performance optimization, historical operation and maintenance experience, and formal rules.
[0025] The verification module performs rigorous multi-level and multi-dimensional verification on the configuration schemes or network configurations produced by the configuration generation module to ensure the correctness, effectiveness, security and compliance of the configuration schemes to the greatest extent possible.
[0026] The application module automatically deploys the configuration scheme, verified by the validation module, to physical or virtual devices via the network orchestrator. The deployment process interacts with network devices using standard southbound interface protocols.
[0027] Preferably, the natural language intent parsing specifically includes:
[0028] Leveraging the built-in contextual self-attention mechanism of LLM, it identifies key technologies such as IP address, VLAN ID, application name, and protocol type in intent text, as well as action commands such as "allow", "deny", "optimize", and "protect".
[0029] By dynamically constructing intent decision trees or similar directed graph structures, high-level business objectives are decomposed layer by layer into a series of measurable and executable network configuration subtasks.
[0030] By combining RFC protocol standard texts, network design documents, and historical operation and maintenance work order data stored in the knowledge base, and leveraging the reasoning capabilities of LLM, ambiguity elimination and quantification are performed on polysemous words and vague expressions in the intent. For example, "high bandwidth" is specified as ">100Mbps" based on application type and historical data.
[0031] Preferably, the method for constructing and utilizing the network protocol knowledge base includes:
[0032] Employing retrieval-enhanced generation technology, massive amounts of unstructured text data, including TCP / IP and QUIC protocol RFC documents, official configuration guides from major network equipment manufacturers, technical white papers, and community forum discussions, are vectorized and stored in a vector database in chunks. When LLM requires relevant knowledge, it can quickly retrieve the most relevant text fragments as contextual input, thereby enhancing the accuracy of the generated data.
[0033] By using parameter efficient fine-tuning (PEFT) techniques such as LoRA and Prompt Tuning, the pre-trained LLM is adapted to the domain, enabling it to better understand network domain terminology, abbreviations, configuration syntax and underlying logic, and to establish the ability to reason about the synergistic influence relationships between protocol parameters.
[0034] It integrates a formal verification rule base, using logic language to explicitly define the legal value range of protocol parameters, mutual exclusion constraints between parameters, and the security baselines that must be followed.
[0035] Preferably, the verification module further includes:
[0036] The syntax validation submodule uses JSON Schema, YANG model or vendor-specific configuration parsers to perform strict format and syntax validation on the configuration scripts or API payloads generated by LLM.
[0037] The dynamic simulation submodule simulates the deployed configuration scheme in an isolated network sandbox environment.
[0038] By injecting simulated traffic, potential risks such as traffic scheduling conflicts, routing loops, and excessive CPU and memory usage can be detected, and their expected impact on network performance can be assessed.
[0039] The formal verification submodule abstracts the network topology into a directed graph or Kripke structure and describes network policies and security requirements as formal specifications.
[0040] Model checking tools are used to perform an exhaustive or symbolic state space traversal of the deployed and configured network model, and to rigorously prove in a mathematical way whether the configuration scheme complies with all security and compliance policies, such as "a specific subnet A can never access subnet B".
[0041] Preferably, the specific execution flow of the formal verification submodule is as follows:
[0042] The devices, links, interfaces, etc. in the current network are abstracted into a directed graph model G=(V, E);
[0043] Based on the generated configuration scheme and the existing network status, construct the configuration impact propagation matrix M to describe how configuration changes affect the network status.
[0044] A model checking tool is used to take the network model and LTL / CTL reduction as input, and systematically traverses all reachable state spaces to check for state paths that violate the reduction, thereby ensuring that there are no loops, no congestion hotspots, and no policy conflicts.
[0045] Preferably, the closed-loop feedback adjustment includes:
[0046] After deployment and configuration, key network performance indicators and device status data are collected in real time using network telemetry technology;
[0047] The collected actual performance data is continuously compared with the intended goals defined by the administrator in the receiving module to calculate the performance deviation;
[0048] When the performance deviation exceeds the preset threshold or a network anomaly is detected, the system automatically triggers the LLM re-optimization process.
[0049] LLM generates incremental parameter correction schemes based on the current deviation, real-time network status, and historical experience, rather than reconfiguring everything, in order to reduce the impact on the network.
[0050] Record all historical decisions, configuration changes, performance feedback, and final results to form a continuously growing experience base. This base is used to iteratively update the configuration rules, optimization strategies, and formal rules in the network protocol knowledge base, enabling the system to continuously learn and evolve.
[0051] This invention also provides an intent-driven network management system based on a large language model, comprising:
[0052] The Natural Language Interface (NLE) unit, as the user-system interaction front end, provides a Web GUI, chatbot, command-line tool, or API interface to receive unstructured intent commands input by the administrator and preprocess them into text sequences that can be processed by LLM.
[0053] The intent parsing engine, the core intelligent component of the system, integrates a pre-trained LLM adapted for the network domain and the necessary network domain adapter; it performs the intent parsing and reasoning functions in the aforementioned methods, converting natural language into structured intents.
[0054] Multi-protocol configuration generator: Responsible for generating configuration schemes based on structured intents. It has built-in parameter optimization models for core protocols such as TCP / IP and QUIC, and supports configuration template generation and conversion capabilities across multiple mainstream manufacturers' devices.
[0055] The network protocol knowledge base serves as the support for intent parsing and configuration generation, storing massive amounts of network knowledge and providing an efficient retrieval interface;
[0056] The verification sandbox platform provides a secure testing environment that integrates a network simulator, configuration inspector, policy verifier, and formal verification toolchain to perform multi-level verification as described above.
[0057] The orchestration execution unit is responsible for interacting with the real network environment. It securely sends verified configuration commands to physical or virtual network devices through various southbound interface protocols.
[0058] The intent assurance controller, by connecting to the network monitoring system, continuously monitors network operation indicators, compares them with the original intent, drives closed-loop optimization processes, and can generate operation and maintenance reports.
[0059] Preferably, the intent parsing engine adopts a layered architecture:
[0060] The base layer provides the core natural language processing capabilities of general pre-trained LLMs;
[0061] The domain adaptation layer, through LoRA (Low-Rank Adaptation) or other PEFT techniques, fine-tunes and efficiently injects network domain expertise and configuration logic into the base layer LLM;
[0062] The decision enhancement layer may integrate a policy network based on reinforcement learning. Through interactive learning with simulation environments or real networks, it continuously optimizes the efficiency and effectiveness of the mapping from intent to configuration, enabling it to make better decisions when facing complex or unknown scenarios.
[0063] Preferably, the multi-protocol configuration generator includes:
[0064] A protocol parameter inference model based on graph neural networks (GNN) is used to capture and understand the complex, non-linear interdependencies between parameters in network protocols.
[0065] A vendor syntax converter can accurately translate the abstract or generic configuration representation generated by LLM into executable CLI commands or API calls for vendor-specific devices.
[0066] A time-series model-based performance prediction component is used to predict the potential changes in network KPIs after adjustments to specific application parameters, providing forward-looking guidance for configuration selection, before configuration deployment.
[0067] The present invention also provides an electronic device, such as a high-performance server, a network controller, a cloud management platform node, or a dedicated network management workstation. This electronic device includes at least one or more processors, one or more memories, and a computer program stored in the memories. The processor, when configured to execute the computer program, is capable of implementing all or part of the steps in the aforementioned intent-driven network management method based on a large language model, and driving the various modules in the aforementioned system to work collaboratively.
[0068] Compared with the prior art, the beneficial effects of the present invention are:
[0069] By supporting natural language interaction, the complexity of network configuration and management is greatly simplified, enabling network administrators to express their management intentions intuitively and efficiently without having to memorize and enter a large number of complex command lines. This significantly reduces the depth of professional skills required of administrators and shortens the training cycle.
[0070] It achieves end-to-end automated conversion, verification, and deployment from high-level intents to specific network configurations, significantly reducing manual intervention and thus greatly reducing the risk of network failures caused by human error, and greatly accelerating the response speed of network service deployment and changes.
[0071] The system can more quickly understand and respond to changing network conditions or emerging business needs. When it is necessary to adjust network policies or deploy new services, administrators only need to describe the new intent in natural language, and the system can quickly generate and deploy the corresponding configuration, giving the network unprecedented agility and adaptability.
[0072] Leveraging the powerful information processing and reasoning capabilities of LLM, and combined with a specially constructed network knowledge base, this invention can effectively handle complex scenarios that traditional methods struggle to address, especially in performance optimization of multi-parameter, tightly coupled protocols such as TCP / IP and QUIC, enabling the exploration and generation of superior configuration schemes.
[0073] By introducing multi-level and multi-dimensional verification modules, including syntax validation, semantic logic, network constraints, dynamic simulation, and formal verification, the network configuration scheme generated by LLM is fully tested before deployment, maximizing the effectiveness, security, and compliance of the configuration and preventing the introduction of potential risks.
[0074] By building a closed-loop management system that continuously monitors, analyzes deviations, and adjusts based on feedback, we can not only ensure that the network status always meets the administrator's intended purpose, but also continuously iterate and update the knowledge base and optimization strategies by recording historical data and results and leveraging the learning capabilities of LLM, thus enabling the system to continuously learn and evolve, making network management increasingly intelligent. Attached Figure Description
[0075] Figure 1 The present invention provides a flowchart of an intent-driven network management method based on a large language model.
[0076] Figure 2 This invention provides a structural diagram of an intent-driven network management system based on a large language model.
[0077] Figure 3 This diagram illustrates the process of constructing a network protocol knowledge base in an intent-driven network management approach.
[0078] Figure 4 This is a flowchart illustrating the workflow of the verification module in the intent-driven network management method. Detailed Implementation
[0079] The technical solutions of the embodiments of the present invention will be described more clearly and completely below with reference to the accompanying drawings. It must be understood that the described embodiments are merely some preferred embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort should be considered to fall within the protection scope pursued by the present invention.
[0080] Example 1
[0081] Please see Figure 1 The present invention provides an intent-driven network management method based on a large language model, the core process of which is detailed below:
[0082] S101, Receiving Intent: The system receives input from the network administrator through its natural language interface unit.
[0083] The interface can be a web-based graphical user interface containing a text input box or dialog window; it can also be a chatbot integrated into an enterprise chat platform; or it can be an application programming interface (API) for automation scripts or third-party systems to call.
[0084] The natural language intent input by the administrator (or user) can be diverse, and the main information includes key objectives, performance indicators, constraints, semantic relationships, security policies, etc. This step is responsible for the preliminary processing of these inputs and passing them to the next step. As shown in Table 1, the input natural language is initially classified according to the system's preset intent types.
[0085] Table 1
[0086]
[0087] S102. Parsing Intent: After receiving the natural language intent, the intent parsing engine starts its core LLM for deep parsing.
[0088] In this embodiment, after receiving a natural language intent, the intent parsing engine activates its core LLM (Limited Language Management) for deep parsing to extract key objectives, constraints, and semantic relationships, generating a structured network intent representation, including:
[0089] Entity and Relationship Recognition: LLM first utilizes its powerful contextual self-attention mechanism and pre-trained knowledge to identify key network entities and action target instructions in the text, and then extracts key objectives, constraints, and semantic relationships based on these key network entities and action target instructions. For example, an LLM fine-tuned for the network domain can identify key network entities such as IP addresses, VLAN IDs, application names, and protocol types in intent text, as well as action instructions such as "allow," "deny," "optimize," and "guarantee," thereby enabling a more accurate understanding of technical terms such as "latency," "bandwidth," "QoS," and "ACL."
[0090] Intent Decomposition and Structuring: For complex intents, the system dynamically constructs an intent decision tree to decompose the natural language intent layer by layer into a series (one or more) of measurable and executable network configuration subtasks. For example, the key network entities in the performance assurance intent in S101 include the video conferencing server cluster in City 1 data center, City 2 office, QUIC, etc., and the action target instructions include working hours (Monday to Friday, 9:00-18:00), priority assurance, ensuring the highest level of security for its QUIC traffic, low latency (<50ms), high bandwidth (>500Mbps), etc., which will be decomposed into subtasks including:
[0091] Identify APP-A / APP-B traffic (may require DPI or IP / port-based identification);
[0092] Configure QoS policies and set up high-priority queues;
[0093] Configure bandwidth reservation or traffic shaping;
[0094] Configure encryption policies for QUIC (e.g., enable TLS 1.3 and select a strong encryption suite).
[0095] Apply time-based strategies;
[0096] Apply source / destination address policy.
[0097] Disambiguation and quantification: LLM uses information from a network protocol knowledge base for reasoning. For example, RFC documents and best practices in the knowledge base can help LLM quantify "high bandwidth" into specific values, or, when faced with a vague intent like "ensuring security," retrieve relevant firewall rules, IPSec VPNs, TLS configurations, and other security policies for selection. If the intent is unclear, the system can even use a natural language interface unit to ask the administrator for more information.
[0098] Generate a structured representation: The parsed results are transformed into a precise, machine-readable structured network intent representation that includes at least key objectives, constraints, and semantic relationships. This can be a JSON object.
[0099] JSON
[0100] {
[0101] "intent_id": "vidconf_001",
[0102] "description": "App A / App B QoS&Security",
[0103] "targets": [
[0104] {"type": "application", "value": "App A"},
[0105] {"type": "application", "value": "App B"}
[0106] ],
[0107] "scope": {
[0108] "source": "10.10.1.0 / 24",
[0109] "destination": "Shanghai_Office_Range"
[0110] },
[0111] "actions": [
[0112] {"type": "qos", "priority": "high", "latency_max_ms": 50, "bandwidth_min_mbps": 500},
[0113] {"type": "security", "protocol": "QUIC", "level": "highest", "tls_version": "1.3"}
[0114] ],
[0115] "constraints": [
[0116] {"type": "time", "days": ["Mon", "Tue", "Wed", "Thu", "Fri"], "start": "09:00", "end": "18:00"} ]
[0118] }
[0119] Here, "intent_id" represents the intent identifier, "description" represents the intent type and description, "targets" and "scope" represent semantic relationships, "actions" represent key objectives, and "constraints" represent constraints.
[0120] S103. Generate configuration: The multi-protocol configuration generator receives the structured intent and starts the configuration generation process.
[0121] For knowledge base retrieval, the system first uses keywords from the intent representation to retrieve relevant document fragments, configuration templates, and best practices from the network protocol knowledge base. RAG technology ensures that LLM obtains the most relevant and accurate information when generating configurations.
[0122] In parameter reasoning and scheme design, LLM, based on retrieved knowledge and its own reasoning capabilities, begins to design specific configuration schemes. It needs to consider dependencies between parameters, differences in vendor syntax, and the priority of intents. For example, to ensure low latency, LLM might choose a specific congestion control algorithm and adjust the TCP / QUIC buffer size; to ensure security, it will select an appropriate encryption algorithm and key length.
[0123] In configuration code generation, the LLM transforms the designed solution into specific configuration code. Vendor syntax translators play a crucial role here, converting general logic into device-specific commands. For example, generating QoS configuration commands for a router of a certain brand, or security policies for a firewall of a certain brand, would look like this:
[0124] ! QoS Example (Simplified)
[0125] class-map match-any APP-A_APP-B
[0126] match protocol App-A
[0127] match protocol App-B
[0128] policy-map QOS_POLICY
[0129] class APP-A_APP-B
[0130] priority percent 50
[0131] set dscpef
[0132] class class-default
[0133] fair-queue
[0134] interface GigabitEthernet0 / 1
[0135] service-policy output QOS_POLICY
[0136] Performance prediction: When generating multiple possible configuration options, the performance prediction component can assess the potential performance impact of each option, helping LLM select the optimal option.
[0137] S104. Verify Configuration: The sandbox platform rigorously tests the generated configuration.
[0138] Syntax validation: Use the YANG (Yet Another Next Generation) model or vendor-provided tools to check whether configuration commands or API calls conform to syntax specifications.
[0139] Semantic and logical verification checks whether parameter values are within a reasonable range, whether the logic is self-consistent, and whether there are conflicts with existing IP addresses or VLANs.
[0140] Network constraint compliance checks whether the configuration violates higher-level network policies, such as security zone division and routing domain isolation.
[0141] Dynamic simulation loads the configuration into a network simulator, runs simulated traffic, and observes network behavior. For example, it checks whether the QoS policy truly prioritizes APP-A traffic, whether the security policy correctly blocks unauthorized access, and whether it introduces loops or black holes.
[0142] Formal verification is initiated for high-risk or critical business configurations. The network model and security policies are input into a model verification tool. The tool will mathematically prove that the configuration will not violate these critical policies under any possible circumstances.
[0143] S105, Application and Closed Loop: Iteratively update the configuration rules, optimization strategies and formal rules in the network protocol knowledge base to achieve system self-evolution.
[0144] Automated deployment: Once the configuration passes all verifications, the orchestration execution unit will develop a deployment plan and push the configuration to the target network device via modern southbound interfaces such as NETCONF and gNMI, or by executing CLI commands via SSH when necessary.
[0145] Continuous monitoring ensures the controller is operational. It uses a telemetry system to collect key metrics of network devices in real time, such as interface traffic, CPU / memory utilization, latency, jitter, packet loss rate, and security events.
[0146] Deviation detection and re-optimization: The controller compares real-time data with the original intent. If the deviation consistently exceeds a preset threshold, it triggers the LLM re-optimization process. The specific comparison process is as follows:
[0147] Define the intent and objectives: The system first extracts all quantifiable performance metrics and constraints from the administrator's initial input. For example, in the patent, the intent and objective is to "ensure end-to-end latency of less than 80ms and bandwidth of no less than 20Mbps for video conferencing applications A and B." These "80ms latency" and "20Mbps bandwidth" serve as the baseline for comparison.
[0148] Real-time data acquisition: The aim is to ensure that the controller continuously collects real-time key performance indicators and status data from network devices via network telemetry technology. This data is highly granular and may include application-specific traffic latency, throughput of specific ports, CPU utilization, etc.
[0149] Data Matching and Deviation Calculation: The controller matches and calculates the collected real-time data against preset intent targets (such as key targets contained in natural language intents). For example, it continuously measures the traffic flowing through designated interfaces of applications A and B, calculating their real-time end-to-end latency and bandwidth usage. Then, it compares the measured value, such as a latency of 95ms, with the intent target latency of 80ms, thereby calculating a performance deviation of 15ms latency exceeding the standard.
[0150] Setting a trigger threshold: Not every minute fluctuation will immediately trigger optimization. The system presets a "deviation threshold." For example, a significant deviation requiring intervention is only considered when the latency exceeds 80ms for 5 consecutive minutes, or when the bandwidth repeatedly falls below 20Mbps within 10 minutes. This prevents the system from overreacting to momentary network jitter.
[0151] Incremental correction involves the LLM receiving deviation information and analyzing the current network state to determine the cause, then generating an incremental correction plan, such as adjusting QoS queue weights or switching to a backup link. This correction plan also needs to be validated before deployment.
[0152] The entire learning and evolution process—including intent, configuration, verification results, performance feedback, and corrective actions—is recorded and used to update the network protocol knowledge base. This allows the system to learn from both successes and failures, enabling it to make more informed decisions in similar situations in the future.
[0153] Example 2
[0154] Please see Figure 2 The various modules of the system 200 of this invention work together to realize the complete process from natural language to closed-loop network management.
[0155] The Natural Language Interface Unit 210 provides a user-friendly interface and supports text, voice, and even possible multimodal input in the future. It is responsible for initial input processing and user session management.
[0156] The Intent Resolution Engine 220, as the core intelligent agent, boasts a layered architecture that ensures its powerful capabilities. The base layer, LLM, provides general language capabilities; the domain adaptation layer, through technologies such as LoRA, enables LLM to understand network terminology at a relatively low cost; and the decision enhancement layer, through reinforcement learning, allows it to find the optimal strategy in a simulation environment without explicit instructions or insufficient knowledge base coverage, thus possessing a certain degree of creative problem-solving ability.
[0157] The Network Protocol Knowledge Base 230 serves as the system's reference book. Its RAG mechanism enables dynamic information acquisition; fine-tuning allows it to understand information; and the formal rule base sets the baseline for its behavior. It is a dynamically optimized knowledge system, continuously updated through closed-loop feedback.
[0158] The multi-protocol configuration generator 240 can not only generate configurations, but also use GNNs to understand the complex relationships within protocols, predict the future through time series models, and adapt to various network devices through converters.
[0159] The Verification Sandbox Platform 250 provides a zero-risk testing environment, ensuring that every factory configuration is safe, reliable, and effective through layers of checks from syntax and logic to simulation and formal verification.
[0160] The orchestration execution unit 260, as the executor of the system, is proficient in various languages for communicating with network devices. It is used to automatically deploy verified configuration schemes to target network devices, ensuring that the configuration is delivered and applied accurately.
[0161] The Intent Assurance Controller 270, acting as the system's guardian, continuously monitors the network to ensure that the intentions of administrators or users are consistently met, and promptly triggers alarms and initiates corrective procedures when deviations occur.
[0162] Example 3
[0163] This embodiment aims to elaborate on the construction process of the network protocol knowledge base in this invention, and how the intent parsing engine deeply utilizes this knowledge base. Through key technologies such as enhanced retrieval generation and efficient parameter fine-tuning (PEFT), it achieves accurate understanding and deep parsing of complex network intents. Please refer to [link to relevant documentation]. Figure 3 .
[0164] The construction of a network protocol knowledge base is an ongoing and systematic project, beginning with the aggregation of massive amounts of heterogeneous network domain expertise. The system regularly retrieves the latest data from multiple globally recognized authoritative sources through the configuration of efficient web crawlers and API interfaces. These sources primarily include:
[0165] The system includes official RFC standard documents on core protocols such as TCP / IP, QUIC, BGP, and MPLS published by the IETF (Internet Engineering Task Force) and others; official configuration guides, command reference manuals, technical white papers, and the latest product errata published by network equipment manufacturers; best practice documents on network architecture design and operation and maintenance publicly released by large network operators and leading enterprises; and high-quality discussions and solutions on network troubleshooting and configuration optimization extracted from industry technical forums and professional communities. In addition, the system will integrate historical operation and maintenance work orders, network change records, and root cause analysis reports accumulated within the enterprise after anonymization, incorporating these valuable practical experiences into the knowledge base.
[0166] The collected raw data comes in various formats, such as PDF, HTML, and plain text. The system first performs a data cleaning process to convert it into a standardized plain text format. Next, to facilitate subsequent processing, the system employs an advanced semantic segmentation strategy, replacing traditional fixed-length segmentation. This strategy understands the context of the text and intelligently segments long documents into appropriately sized knowledge fragments that contain complete logical semantics.
[0167] After segmentation, the system uses a powerful text embedding model to accurately convert each knowledge fragment into a high-dimensional vector that represents its semantic information. These vectors are then stored in a vector database specifically designed for efficient similarity retrieval and indexed quickly.
[0168] To enable a general-purpose LLM to understand network domain terminology and complex logic, the system employs LoRA (Local Area Redirection) technology for efficient parameter fine-tuning. This process first requires building a high-quality fine-tuning dataset, typically containing thousands to tens of thousands of instruction-response formatted sample pairs. These samples are carefully designed to cover various key tasks, such as network terminology interpretation, conversion of natural language intents to structured data, and translation of general configuration strategies into vendor-specific configuration commands.
[0169] During LoRA fine-tuning, the system does not update the large number of original parameters of the LLM. Instead, it injects trainable, very low-rank adaptation matrices into its core Transformer structure. The training process only updates these newly added matrices with a very small number of parameters, thereby efficiently injecting network domain expertise and configuration logic into the LLM with extremely low computational and time costs, transforming it into a model with network expert capabilities.
[0170] When a network intent, such as "ensure all QUIC traffic is encrypted with TLS 1.3", is input into the intent parsing engine, its internal RAG-based workflow is initiated. First, the LoRA-tuned LLM can quickly identify the core requirement in the intent, "secure configuration of QUIC traffic", and the key entity, "TLS 1.3".
[0171] Subsequently, the system converts keywords such as "QUIC and TLS 1.3 security configuration" into query vectors and performs a high-speed similarity search in the vector database of the network protocol knowledge base. The database immediately returns several knowledge fragments most relevant to the query. These fragments may include: the mandatory requirement in RFC 9001 that the QUIC protocol must use TLS 1.3 for encryption; specific commands and parameters in a particular vendor's firewall configuration guide on how to create a QUIC security policy and specify the TLS version; and a detailed discussion in an industry best practice document on recommended high-strength TLS 1.3 encryption suites. The system then uses these retrieved, highly relevant knowledge fragments as contextual information, concatenating them with the original intent text entered by the administrator to form a more informative and contextually clear enhanced prompt.
[0172] Finally, this enhanced cue word is input into the LoRA-tuned LLM for final inference generation. At this point, the LLM not only possesses domain knowledge internalized through fine-tuning but also obtains precise reference materials for the specific problem, akin to an "open-book exam." Therefore, it can generate an extremely accurate and detailed structured intent representation (JSON), which not only includes basic {"protocol": "QUIC", "tls_version": "1.3"} but can even further refine it to a recommended list of cryptographic suites based on best practices, for example:
[0173] {"cipher_suites":["TLS_AES_128_GCM_SHA256","TLS_CHACHA20_POLY1305_SHA256"]}
[0174] By combining Retrieval Enhanced Generation (RAG) with Parameter Efficient Fine-Tuning (PEFT), this invention effectively overcomes the two core defects of general large-scale language models: knowledge obsolescence and domain insufficiency. This enables them to accurately, reliably, and deeply understand complex network management intentions, laying a solid and intelligent foundation for the subsequent realization of highly automated configuration generation and closed-loop management.
[0175] Example 4
[0176] This embodiment aims to elaborate on the specific workflow of the verification module after receiving the configuration scheme, especially the collaborative working process between the dynamic simulation submodule and the formal verification submodule, to ensure the correctness, effectiveness, and security of the configuration scheme before deployment. Please refer to [link / reference]. Figure 4 .
[0177] In this embodiment, the QoS configuration generated under the following scenario is used as the object to be verified.
[0178] To ensure the smooth operation of video conferencing applications: Enter the following: "From Monday to Friday, 9:00 AM to 6:00 PM, prioritize ensuring end-to-end latency of less than 80ms and bandwidth of no less than 20Mbps for video conferencing applications A and B, and ensure all QUIC traffic is encrypted using TLS 1.3, while avoiding impacting normal access to the financial system."
[0179] Once the "Configuration Generation Module" outputs the QoS configuration script for the video conferencing application based on the intent, the verification task begins. First, the verification sandbox platform receives the configuration scheme and its associated structured intent representation (JSON object). By parsing this intent, the platform clarifies the core objectives of this verification, including the performance metrics to be achieved, such as end-to-end latency of less than 80ms and bandwidth greater than 20Mbps for applications A and B; and the constraints that must be met, such as ensuring that access to the financial system is completely unaffected and that all QUIC traffic is encrypted using the TLS 1.3 protocol.
[0180] The first step in the verification process is syntax and semantic verification, performed by the syntax verification submodule. This submodule loads the YANG model corresponding to the target network device. YANG, as a data modeling language, can precisely define the structure, type, and constraints of configuration data. In the syntax check, the submodule rigorously verifies whether the generated CLI commands, such as class-map, policy-map, and service-policy, fully conform to the command specifications of the target device's operating system, checking for spelling errors, missing parameters, or improper formatting. The subsequent semantic check further verifies the rationality of parameter values. For example, for the configuration "priority percent 50", the system combines information from the knowledge base about the maximum reservable bandwidth for this interface to determine whether reserving 50% is an invalid value exceeding physical limits or violating policies. Simultaneously, it verifies whether the DSCP value "ef" used in the configuration is a valid flag supported by the device, ensuring that the configuration is logically correct and executable.
[0181] After passing basic syntax and semantic validation, the configuration scheme will enter the dynamic simulation verification phase. This phase is conducted by the dynamic simulation submodule in a completely isolated network sandbox environment. This sandbox is a digital twin environment built using professional network simulation software, consistent with the topology of a real production network. The system will first automatically deploy the QoS configuration to be verified to the virtual router within the sandbox.
[0182] Subsequently, a traffic generator is activated, which simulates and injects three types of key traffic based on the application profiles stored in the knowledge base: the first type is target traffic, which simulates real video streams from application A and application B; the second type is background traffic, which simulates mixed traffic from other ordinary services in the network to test the effectiveness of QoS policies in complex environments; and the third type is constraint traffic, which specifically simulates the financial system's access to the database to verify whether the new configuration has any unexpected negative impact on it.
[0183] Throughout the traffic injection process, the intent is to ensure that the controller connects to the sandbox environment to collect key performance indicators (KPIs) of the virtual network interface in real time and accurately measure the end-to-end latency, jitter, actual bandwidth, and packet loss rate of the target traffic.
[0184] After the simulation, the system rigorously compares the collected actual performance data with the performance targets initially intended. For example, for the target traffic, the configuration scheme can only be considered to have passed the dynamic simulation verification if the traffic latency of application A and application B is stable below 80ms, the bandwidth meets the 20Mbps requirement, and the packet loss rate of the financial system traffic is always zero.
[0185] For high-risk intents involving core security strategies or critical business isolation, the system will also initiate the highest-level "formal verification submodule" for final verification. Taking intents such as "avoiding interference with normal access to the financial system" or "isolating the production environment from the test environment" as examples, formal verification provides mathematical-level security guarantees.
[0186] First, the system abstracts network topology, routing tables, firewall rules, etc., into a precise mathematical model, such as a directed graph G=(V, E). Then, security policies described in natural language, such as "financial system traffic cannot be dropped" or "the production environment can never access the test environment," are converted into a rigorous formal logical language, such as linear temporal logic (LTL). For example, the former can be represented as G (pkt.src_ip ∈ Finance_Subnet→F pkt.dest_ip ∈ Finance_DB_Server), whose logical meaning is "in any global state, as long as a data packet originates from the finance subnet, it will eventually reach the finance database server."
[0187] Subsequently, the system invokes a professional model checking tool (such as Batfish), taking the constructed network model and LTL protocol as input. This tool uses algorithms to exhaustively or symbolically traverse and explore all possible state spaces reachable by the model, and rigorously proves mathematically that after applying the new QoS configuration, the network will not violate any defined security protocol under any possible packet forwarding path.
[0188] Ultimately, only after a configuration scheme successfully passes all levels of verification, from syntax and semantic validation to dynamic simulation verification and formal verification, will the orchestration execution unit be officially authorized and deployed to the real physical network environment. This series of rigorous, multi-dimensional verification processes maximizes the security and reliability of network changes, nipping potential risks in the bud before deployment.
Claims
1. An intent-driven network management method based on a large-scale language model, characterized in that, The method includes: Obtain the natural language intent of the input and perform a preliminary classification of the input natural language intent according to the preset intent type; The natural language intent is parsed using a pre-trained large-scale language model, and the key objectives, constraints, and semantic relationships contained in the natural language intent are extracted. Combined with the results of preliminary classification, a structured network intent representation is generated. Based on the structured network intent representation, massive amounts of raw data containing network domain expertise are collected and combined with a network protocol knowledge base to generate configuration schemes for TCP / IP or QUIC protocols; wherein, the network protocol knowledge base includes protocol parameter dependencies, vendor configuration specifications, and performance optimization strategies. The generated configuration scheme is subjected to syntax validation, semantic logic verification, and network constraint compliance checks to ensure its security and effectiveness, including: Receive the configuration scheme and its associated structured intent representation, and perform the natural language intent parsing operation to determine the performance metrics that need to be achieved; Load the YANG model corresponding to the target network device, verify whether the generated CLI commands conform to the command specifications of the target network device's operating system, and verify the rationality of the parameter values corresponding to the performance indicators; The configuration scheme was dynamically simulated and verified in a network sandbox environment; and The verified configuration scheme is automatically deployed to the target network device, and the network status is continuously monitored for closed-loop feedback adjustments.
2. The intent-driven network management method based on a large language model according to claim 1, characterized in that, The process involves parsing the natural language intent using a pre-trained large-scale language model, extracting the key objectives, constraints, and semantic relationships contained within the natural language intent, and combining this with the preliminary classification results to generate a structured network intent representation, including: The key network entities and action target instructions in the natural language intent are identified through the context self-attention mechanism of the large language model. The natural language intent is decomposed into one or more executable network configuration subtasks; By combining the RFC protocol texts in the network protocol knowledge base with historical operation and maintenance data, the ambiguity and vague expression of the natural language intent are eliminated; By combining the key network entities and action target instructions in the natural language intent with the results of the preliminary classification, a structured network intent representation containing key targets, constraints, and semantic relationships is generated.
3. The intent-driven network management method based on a large language model according to claim 1, characterized in that, The method combines a network protocol knowledge base, collects massive amounts of raw data containing professional network knowledge, and generates configuration schemes for TCP / IP or QUIC protocols, including: By configuring web crawlers and API interfaces, data can be collected from official standard documents containing TCP / IP or QUIC protocols, official configuration guides from network equipment manufacturers, best practice documents for operation and maintenance from carrier enterprises, industry technical forums, and historical operation and maintenance work orders and reports within the enterprise. The collected raw data is cleaned and uniformly converted into a standardized plain text format. Long documents are then cut into knowledge fragments of appropriate size that contain complete logical semantics. By using a text embedding model, each knowledge fragment is converted into a high-dimensional vector and stored in a vector database to build a fast index; The LoRA technique is used to adapt the pre-trained large language model to a specific domain, enabling the large language model to understand technical terms, abbreviations, configuration syntax, and to establish the ability to reason about the collaborative influence relationships between protocol parameters. The large language model identifies the core needs and key entities in the natural language intent, and identifies the keywords in the core needs and key entities. The identified keywords are then converted into query vectors, and a similarity search is performed in the vector database to return the most relevant knowledge fragments. The retrieved knowledge fragments are concatenated with the original natural language intent text as contextual information to form enhanced prompt words; The enhanced prompt input is used for inference generation by the large language model fine-tuned by LoRA, outputting the configuration scheme, and converting the configuration scheme into the corresponding configuration code based on the type of the target network device.
4. The intent-driven network management method based on a large language model according to claim 1, characterized in that, The step of performing syntax validation, semantic logic validation, and network constraint compliance checks on the generated configuration scheme also includes: Activate the traffic generator and, based on the application profile stored in the network protocol knowledge base, simulate and inject target traffic, background traffic, and constraint traffic (critical traffic) to verify whether the configuration scheme produces unexpected negative effects. Collect actual performance data of the corresponding key traffic in the dynamic simulation, and compare the actual performance data with the performance indicators that need to be achieved by the natural language intent parsing operation to determine whether the configuration scheme has passed the dynamic simulation verification.
5. The intent-driven network management method based on a large language model according to claim 1, characterized in that, The closed-loop feedback adjustment includes: After deployment, network telemetry data is collected in real time, and the deviation between the actual performance and the key objectives contained in the natural language intent is compared. When the deviation exceeds the threshold, the large language model is triggered to perform a re-optimization operation and generate an incremental correction scheme. Record historical decisions and results, and iteratively update the configuration rules and optimization strategies in the knowledge base.
6. An intent-driven network management system based on a large-scale language model, characterized in that, The intent-driven network management system is applied to the method described in any one of claims 1-5.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Large model and knowledge graph enabled intention-driven network design method
CN118228815A
Network management agent based on natural language intention interaction
CN118780267A