Data transmission system and method for data networking
By using a data transmission system oriented towards the Internet of Things (IoT), network resources are allocated through virtual private network (VPN) resource pools and bandwidth resource pools. This solves the security and efficiency problems in cross-organizational and cross-regional data flow, and enables automated collaborative scheduling and efficient data transmission across management domains.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-11
- Publication Date
- 2026-04-14
AI Technical Summary
The demand for cross-organizational and cross-regional data flow in current data exchange is growing, and the demand for efficient and secure data exchange among multiple entities is not being met. Traditional leased line technology is unable to meet the needs of emerging data-intensive businesses for agile, elastic, and programmable network capabilities.
This paper provides a data transmission system for the Internet of Things (IoT). Through the collaborative work of data circulation terminals, data circulation support platforms, private network resource scheduling units, and private network forwarding networks, it achieves secure isolation and efficient linkage between the control plane and the data plane. It uses virtual private network resource pools and bandwidth resource pools to allocate network resources, establishes isolated virtual private network channels, and performs bandwidth scheduling.
It enables automated and policy-based collaborative scheduling of network resources in cross-management domain scenarios, significantly shortens the virtual private network (VPN) activation latency, improves the reliability and resource utilization efficiency of cross-domain networking, and ensures the security and controllability of data transmission.
Smart Images

Figure CN121864529A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data communication technology, and in particular to a data transmission system and method for data networks. Background Technology
[0002] Currently, the marketization of data elements is accelerating, and the demand for data circulation across organizations and regions is growing. As the scale of data element circulation continues to expand, efficient and secure data exchange among multiple entities has become a crucial requirement. In various sectors such as finance, energy, and manufacturing, participants are placing high demands on the security, isolation, and controllability of data exchange. Summary of the Invention
[0003] This disclosure provides a data transmission system and method for data networks, which at least partially solves the problem of how to achieve automated and policy-based collaborative scheduling of network resources in data circulation scenarios that support multiple participants and cross management domains, and ensures secure isolation and efficient linkage between the control plane and the data plane.
[0004] Other features and advantages of this disclosure will become apparent from the following detailed description, or may be learned in part from practice of this disclosure.
[0005] According to one aspect of this disclosure, a data transmission system for data networks is provided, comprising: The data circulation terminal is equipped with a first network interface and a second network interface, respectively used for control plane communication and data plane communication. The data circulation support platform is configured to send network demand parameters to the private network resource scheduling unit after identifying the participants that need to transmit data. The private network resource scheduling unit is configured to receive network demand parameters through the application programming interface, allocate network resources based on the virtual private network resource pool and bandwidth resource pool, and communicate with another private network resource scheduling unit in cross-management domain scenarios to collaboratively complete end-to-end resource allocation. It also issues access credentials to data circulation terminals and issues virtual private network configuration and bandwidth templates to the private network transmission network. The private network forwarding network includes interconnected access gateways and service gateways. The access gateways are connected to the second network interface. Based on the virtual private network configuration and bandwidth template, isolated virtual private network channels are established and bandwidth scheduling is performed.
[0006] According to another aspect of this disclosure, a private network resource scheduling device for data networks is provided, comprising: The service enablement interface module is used to receive network requirement parameters from the data circulation support platform. The business addressing module is used to query the access gateway location based on the participating enterprise name and interact with the peer scheduling device in cross-domain scenarios. The network resource management module is used to maintain intra-domain and inter-domain virtual private network resource pools and bandwidth resource pools, and to allocate idle resources; The terminal access control module is used to send dialing configurations to data circulation terminals and monitor connection status. The network access control module is used to generate IPv6 addresses, import user routes to virtual routing forwarding instances, and issue forwarding policies to the service gateway.
[0007] According to another aspect of this disclosure, a data transmission method for data networks is provided, applied to the aforementioned data transmission system for data networks. The method includes: after determining the participants requiring data transmission, the data circulation support platform sends network requirement parameters to a dedicated network resource scheduling unit. The network requirement parameters include participant identifiers, required transmission bandwidth, and transmission duration. The dedicated network resource scheduling unit receives the network requirement parameters through an application programming interface (API), allocates network resources based on a virtual private network (VPC) resource pool and a bandwidth resource pool, and communicates with another dedicated network resource scheduling unit in cross-management domain scenarios to collaboratively complete end-to-end resource allocation. The dedicated network resource scheduling unit issues access credentials to the data circulation terminal and issues VPC configuration and bandwidth templates to the dedicated network forwarding network. The data circulation terminal communicates with the data circulation support platform via a first network interface and establishes an encrypted data connection with the dedicated network forwarding network via a second network interface based on the access credentials. The dedicated network forwarding network establishes an isolated VPC channel between the access gateway and the service gateway and performs bandwidth scheduling based on the VPC configuration and bandwidth template to carry data plane traffic between the data circulation terminals.
[0008] According to another aspect of this disclosure, an electronic device is provided, comprising: a memory for storing instructions; and a processor for calling the instructions stored in the memory to implement the above-described data transmission method for data networking.
[0009] According to another aspect of this disclosure, a computer-readable storage medium is provided that stores computer instructions thereon, which, when executed by a processor, implement the above-described data transmission method for data networking.
[0010] According to another aspect of this disclosure, a computer program product is provided, which stores instructions that, when executed by a computer, cause the computer to implement the above-described data transmission method for data networks.
[0011] According to another aspect of this disclosure, a chip is provided, including at least one processor and an interface; the interface is used to provide program instructions or data to the at least one processor; the at least one processor is used to execute the program instructions to implement the above-described data transmission method for data networking.
[0012] The data transmission system and method for data networks provided in this disclosure configures a first network interface and a second network interface for control plane communication and data plane communication, respectively, so that management instructions (such as identity authentication and policy issuance) and business data flow are separated at the physical or logical level to avoid mutual interference, thereby ensuring control security and data transmission performance. After determining the participants, the data circulation support platform sends network demand parameters to the private network resource scheduling unit, transforming the upper-layer data circulation task into a structured network intent, providing input basis for automated scheduling. The private network resource scheduling unit allocates resources based on the virtual private network resource pool and bandwidth resource pool, and communicates with another scheduling unit in cross-management domain scenarios to collaboratively complete end-to-end allocation, solving the resource silo problem in multi-domain environments and ensuring the consistency and reachability of cross-domain virtual private networks. The private network resource scheduling unit issues access credentials to the terminal and issues virtual private network configuration and bandwidth templates to the private network forwarding network. The access gateway establishes an isolation channel and performs bandwidth scheduling according to the configuration, realizing a closed loop from policy to execution, so that network capabilities take effect on demand and in real time according to tasks. In summary, the aforementioned technical means collectively construct a business-driven, automatically collaborative, surface-separated, and isolable data transmission architecture, which not only significantly shortens the virtual private network (VPN) activation latency but also improves the reliability and resource utilization efficiency of cross-domain networking.
[0013] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0014] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.
[0015] Obviously, the accompanying drawings described below are merely some embodiments of this disclosure. Those skilled in the art can obtain other drawings based on these drawings without any creative effort.
[0016] Figure 1 This illustration shows a schematic diagram of the architecture of a data transmission system for the Internet of Things (IoT) according to an embodiment of the present disclosure; Figure 2 This diagram illustrates the architecture of a private network resource scheduling device according to an embodiment of the present disclosure. Figure 3 This diagram illustrates the steps performed by the network access control module in an embodiment of the present disclosure. Figure 4 This illustration shows a schematic diagram of the architecture of another data transmission system for the Internet of Things (IoT) according to an embodiment of this disclosure; Figure 5 A flowchart illustrating a data transmission method for the Internet of Things (IoT) according to an embodiment of this disclosure is shown. Figure 6 This diagram illustrates a flowchart of the collaborative end-to-end resource allocation process in an embodiment of this disclosure. Figure 7 A structural block diagram of an electronic device according to an embodiment of the present disclosure is shown. Detailed Implementation
[0017] To facilitate understanding of the technical solutions of this disclosure, the disclosure will be further described below with reference to the accompanying drawings.
[0018] The terms "first" and "second," etc., in this disclosure, claim, and drawings are used only to distinguish different objects and not to describe a particular order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.
[0019] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this disclosure. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0020] In this disclosure, "at least one (item)" means one or more, "more than" means two or more, "at least two (items)" means two or three or more, and "and / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist simultaneously, where A and B can be singular or plural. "Or" indicates that there can be two relationships, such as only A exists and only B exists; when A and B are not mutually exclusive, it can also mean that there are three relationships, such as only A exists, only B exists, and A and B exist simultaneously. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c".
[0021] In recent years, relevant guiding documents have proposed accelerating the construction of efficient, resilient, and secure data transmission infrastructure to provide high-speed and stable network support for data flow in key scenarios such as digital finance, smart healthcare, transportation and logistics, and large-scale model training and inference. This aims to significantly improve data exchange performance, reduce transmission costs, and provide high-quality channels for large-scale data sharing and circulation. However, the currently widely used Internet access methods still face challenges such as insufficient bandwidth resources and high security risks. Traditional leased line technologies, such as Multiprotocol Label Switching Virtual Private Network (MPLS VPN) and Optical Transport Network (OTN), generally suffer from long activation cycles, high deployment costs, and difficulty in flexibly adjusting network topology as needed, making it difficult to meet the demands of emerging data-intensive businesses for agile, resilient, and programmable network capabilities.
[0022] To address the aforementioned issues, this disclosure provides a data transmission system and method for data networks. The system comprises four core components: a data circulation terminal, a data circulation support platform, a dedicated data network service system, and a dedicated data network transmission network foundation. Through the interaction of these four core components, it ultimately provides data circulation users with highly secure, highly flexible, high-bandwidth, and task-oriented data transmission services. This constructs a new type of network infrastructure, breaks down "data silos," and achieves efficient data sharing.
[0023] The deficiencies of the above solutions and the proposed solutions are the result of the inventor's practice and careful research. Therefore, the discovery process of the above problems and the solutions proposed in this disclosure below should be considered as the inventor's contribution to this disclosure.
[0024] It is understood that the data involved in this disclosure (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and provisions. Before using the technical solutions disclosed in the embodiments of this disclosure, users shall be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and their authorization shall be obtained.
[0025] The following detailed description of this exemplary implementation method is provided in conjunction with the accompanying drawings and embodiments.
[0026] Figure 1 This disclosure illustrates a data transmission system for the Internet of Things (IoT) according to an embodiment, such as... Figure 1As shown, the data transmission system for the Internet of Things provided in this embodiment includes a data circulation terminal 101, a data circulation support platform 102, a private network resource scheduling unit 103, and a private network forwarding network 104.
[0027] The data circulation terminal 101 is a physical server or virtual machine participating in data circulation. It is configured with a first network interface and a second network interface: the first network interface is used for control plane communication with the data circulation support platform 102, carrying management signaling such as identity authentication, asset registration, and policy issuance; the second network interface is used for data plane communication with other data circulation terminals 101, carrying encrypted business data streams. Through the operating system routing table configuration, control plane traffic is directed to the first network interface, and data plane traffic is directed to the second network interface, achieving logical isolation between control and transmission paths.
[0028] After the data circulation support platform 102 completes the matching of data providers and demanders and generates data circulation tasks, it determines the terminal identifiers of all parties involved in this data transmission, the required transmission bandwidth and transmission duration, and encapsulates the above information into network requirement parameters, which are then sent to the private network resource scheduling unit 103 through the application programming interface (API).
[0029] The private network resource scheduling unit 103 receives network requirement parameters via API and allocates an idle VPN identifier and sufficient link resources to meet the bandwidth requirements for this task based on its locally maintained Virtual Private Network (VPN) resource pool and bandwidth resource pool. When the participants belong to different management domains, the private network resource scheduling unit 103 exchanges resource status information with the peer private network resource scheduling unit 103 through the inter-domain communication interface, and collaboratively selects a VPN identifier that is available to both parties to complete end-to-end resource reservation. Subsequently, the private network resource scheduling unit 103 generates access credentials containing dial-up account, password, and anchor gateway address, and sends them to the corresponding data circulation terminal 101; at the same time, it sends the VPN configuration (including VPN identifier, route distinguisher RD, route target RT, etc.) and bandwidth template to the private network forwarding network 104.
[0030] The private network forwarding network 104 includes interconnected access gateways and service gateways. The access gateway establishes a connection with the second network interface of the data circulation terminal 101. After receiving the virtual private network configuration, it imports the user routes of each participating terminal into the same Virtual Routing and Forwarding (VRF) instance to form a logically isolated virtual private network channel. At the same time, it performs bandwidth scheduling on the channel according to the bandwidth template to ensure the quality of transmission service.
[0031] This disclosure utilizes technologies such as dual-interface terminals separating the control plane and data plane, service-driven network requirement parameter distribution, cross-domain collaborative private network resource scheduling, and automatic establishment of isolated channels based on virtual private network configuration to achieve automated end-to-end virtual private network construction triggered by data flow tasks. This solution significantly improves the efficiency and security of network resource scheduling in cross-management domain scenarios, solves the problems of long activation cycles, poor flexibility, and weak isolation in traditional solutions, and provides efficient, flexible, and secure data transmission capabilities for data networks.
[0032] In some embodiments, the data circulation terminal 101 includes a first data module and a first network module.
[0033] The first data module is configured to perform standard encapsulation, processing, identifier resolution, and catalog publication of raw data. In other words, the first data module is used to standardize local raw data, including: encapsulating data according to a preset data format, performing processing operations such as desensitization, aggregation, or format conversion, parsing data identifiers (such as data asset IDs), and publishing the processed data metadata to the asset catalog of the data circulation support platform 102 for supply and demand matching.
[0034] The first network module is configured to communicate with the data circulation support platform 102 via the first network interface to perform identity authentication, asset registration, and policy management operations. It also establishes an encrypted data connection with the private network transmission network via the second network interface, based on the access credentials issued by the private network resource scheduling unit 103, to exchange data with other data circulation terminals 101. In other words, the first network module establishes a secure control channel with the data circulation support platform 102 through the first network interface, completes terminal registration using a digital certificate-based identity authentication mechanism, and reports its own asset information to complete asset registration; simultaneously, it receives and caches access policies issued by the platform. Upon receiving the access credentials (including dial-up account, password, and anchor service gateway address) issued by the private network resource scheduling unit 103, the first network module initiates an Ethernet point-to-point dial-up connection via the second network interface and establishes an end-to-end encrypted data tunnel with the private network forwarding network 104 based on the IPSec protocol, thereby securely exchanging business data with other data circulation terminals 101.
[0035] In some embodiments, the first network module provides secure access to a dedicated data network to enable data transactions and data delivery between data circulation terminals 101; it also interfaces with a data infrastructure support platform to enable the data circulation support platform 102 to access, control, and manage the data circulation terminals 101, and to perform functions such as access management, identity authentication, asset registration, catalog publishing, and policy management.
[0036] This embodiment of the disclosure separates data processing and network control functions within the data circulation terminal 101, enabling the first data module to achieve data standardization and directory publishing, and the first network module to complete security authentication and encrypted data transmission based on dual interfaces, thereby ensuring trusted access, policy compliance and transmission security throughout the entire data circulation process, and improving the terminal's autonomy and overall system collaboration efficiency.
[0037] In some embodiments, the data circulation terminal 101 is a physical server or a virtual machine.
[0038] When the data circulation terminal 101 is a physical server, its host is equipped with two independent physical network cards, serving as the first network interface and the second network interface, respectively. The physical server plus two physical network cards ensures that traffic destined for different destinations exits through the correct physical network card by configuring a routing table, thus enabling access to two different logical networks. One network connects to the basic support platform via the internet to complete the transmission of control plane data; the other network uses a virtual private network to achieve high-security, high-elasticity, high-bandwidth, and task-oriented transmission of data transaction data between the data circulation terminals 101.
[0039] When the data circulation terminal 101 is a virtual machine, its virtualization platform allocates two logically isolated virtual network interface cards (NICs) to it, mapped as the first network interface and the second network interface, respectively. Virtual machine + two virtual NICs: By configuring routing tables, it ensures that traffic destined for different destinations exits through the correct virtual NIC, enabling access to two different logical networks. One uses the public network to connect to the basic support platform and complete the transmission of control plane data; the other uses a virtual private network to achieve high-security, high-elasticity, high-bandwidth, and task-oriented transmission of data transaction data between data circulation terminals 101.
[0040] Data circulation terminal 101 separates and forwards control plane and data plane traffic by configuring the routing table in the operating system kernel: control plane traffic destined for the IP address range of data circulation support platform 102 (such as authentication requests, policy synchronization, and asset registration messages) is bound to the first network interface; data plane traffic destined for other data circulation terminals 101 (such as encrypted service data packets) is bound to the second network interface. This routing policy can be implemented through static route configuration or policy-based routing (PBR) to ensure that the two types of traffic are completely isolated at the physical or logical level, avoid mutual interference, and improve security and transmission efficiency.
[0041] This disclosure achieves physical or logical isolation between control plane and data plane traffic by deploying dual network interface cards (NICs) on a physical server or virtual machine and configuring the operating system's routing table. This design effectively prevents interference between management signaling and business data, enhances system security and network predictability, and is compatible with both physical and virtualized environments, improving the architecture's versatility and deployment flexibility.
[0042] In some embodiments, the data flow support platform 102 includes a second data module and a second network module.
[0043] The second data module is configured to manage access, authenticate identities, register assets, and manage directories for the data circulation terminal 101. It also matches data providers and demanders based on directory information to generate data circulation tasks. In other words, the second data module manages the registered data circulation terminal 101 throughout its entire lifecycle, including: authenticating the terminal based on a digital certificate or pre-shared key; reviewing and recording the terminal's enterprise, asset type, and data directory information; and constructing a global data asset directory. Furthermore, based on the query conditions proposed by the data demander, it matches qualified data providers in the directory and generates structured data circulation tasks, clearly defining the identities of the participating parties, the data scope, and the business intent. In some embodiments, the second data module enables access, control, and management of the data circulation terminal 101, provides identity authentication, asset registration, and directory management for data circulation participants, and realizes supply and demand matching services and data delivery.
[0044] The second network module is configured to communicate with the data circulation terminal 101 and the private network resource scheduling unit 103 via the Internet. It is used to send control commands to the data circulation terminal 101 to realize access, control and management, and in response to the determination of the participants that need to transmit data, it sends network requirement parameters including the participant identifier, required bandwidth and transmission duration to the private network resource scheduling unit 103 through the application programming interface to trigger the creation or deletion of the virtual private network.
[0045] In some embodiments, the second network module establishes secure communication channels with the first network interfaces of each data circulation terminal 101 and the private network resource scheduling unit 103 via the Internet. This module sends control commands to the data circulation terminals 101 to trigger terminal registration, policy updates, or connection status queries. Simultaneously, after a data circulation task is determined, the module encapsulates parameters such as participant terminal identifiers, required transmission bandwidth (in Mbps), and transmission duration (in minutes) included in the task into standardized network requirement parameters, and sends them to the private network resource scheduling unit 103 via an Application Programming Interface (API) using the HTTPS protocol, thereby triggering the automatic creation of the virtual private network. After the task is completed, a deletion command can also be sent to release network resources.
[0046] This embodiment integrates data management and network collaboration functions into the data circulation support platform 102, achieving seamless integration from data supply and demand matching to network resource scheduling. The platform generates tasks based on directory matching and automatically distributes structured network parameters, driving the underlying network to open or release virtual private networks on demand, significantly improving the efficiency and automation level of the linkage between data circulation services and network capabilities.
[0047] Figure 2 This illustration shows a private network resource scheduling device according to an embodiment of the present disclosure. For example... Figure 2 As shown, the device includes a service enablement interface module 201, a service addressing module 202, a network resource management module 203, a terminal access control module 204, and a network access control module 205. It should be noted that this private network resource scheduling device can be deployed as an independent network controller or integrated into the private network resource scheduling unit 103 described in the previous embodiment to achieve automated resource scheduling and virtual private network management for data networks.
[0048] The service enablement interface module 201 receives network requirement parameters from the data circulation support platform 102. The service addressing module 202 queries the access gateway location based on the participating enterprise name and interacts with the peer scheduling device in cross-domain scenarios. The network resource management module 203 maintains intra-domain and inter-domain virtual private network resource pools and bandwidth resource pools, and allocates idle resources. The terminal access control module 204 issues dial-up configurations to the data circulation terminal 101 and monitors the connection status. The network access control module 205 generates IPv6 addresses, imports user routes to virtual routing forwarding instances, and issues forwarding policies to the service gateway.
[0049] In some embodiments, the service enablement interface module 201 has a standardized application programming interface (API) for receiving network requirement parameters from the data circulation support platform 102. These parameters include at least the participant company name, the data circulation terminal 101 identifier, the required transmission bandwidth, and the transmission duration. The service addressing module 202 maintains a mapping table between company names and local access gateway locations, and queries the corresponding access gateway IP address based on the participant company name. When participants belong to different management domains, they send an addressing request to the peer private network resource scheduling device through a pre-configured inter-domain communication interface and receive the access gateway location information returned by the peer. The network resource management module 203 maintains intra-domain virtual private network resource pools and inter-domain virtual private network resource pools, respectively. Each resource pool contains multiple virtual private network identifiers and their corresponding route distinguishers (RD) and route destinations (RT) values, and records each... The module maintains the physical bandwidth, used bandwidth, and remaining available bandwidth information of each service gateway. It selects an idle virtual private network (VPN) identifier from the corresponding resource pool based on network demand parameters and verifies whether the bandwidth meets the requirements. The terminal access control module 204 generates a dial-up configuration template containing the dial-up account, dial-up password, and anchored service gateway address based on the queried access gateway location. This template is then sent to the corresponding data circulation terminal 101 via a secure channel, and periodically receives dial-up status and real-time bandwidth data reported by the terminal. The network access control module 205 allocates service addresses to the terminals according to a preset IPv6 address planning strategy, imports the user routes of each participating terminal into the Virtual Router Forwarding (VRF) instance allocated by the network resource management module, and sends a forwarding strategy containing the VRF identifier and bandwidth template to the service gateway to complete the strategic deployment of the VPN channel.
[0050] In some embodiments, the service enablement model module 201 provides a unified API interface to the data circulation infrastructure support platform, enabling network capability openness and flexible invocation of network service capabilities by applications / services. The main interface parameters include: the names of the participating companies in the data circulation process, the data circulation terminal ID (101ID), the required transmission bandwidth, and the required transmission duration.
[0051] In some embodiments, the business addressing module 202 performs addressing based on the names of the companies that need to communicate with each other, and confirms the geographical location of the company access gateway; when cross-domain scenarios are involved, cross-domain addressing and network resource interaction are performed through the east-west interface.
[0052] In some embodiments, the network resource management module 203 is responsible for maintaining VPN resources and bandwidth resources, reserving VPN and bandwidth resources according to network needs, and releasing VPN and bandwidth resources after the user's subscription ends.
[0053] In some embodiments, the terminal access control module 204 is responsible for completing the access gateway configuration distribution template and dialing status detection based on the service addressing result.
[0054] In some embodiments, the network access control module 205 is responsible for completing the access gateway reliability authentication, formulating service policies such as VPN selection and bandwidth templates, and implementing the QoD, BoD, and ToD service policies required for data networking within seconds through the management and control of the central office service gateway.
[0055] In this embodiment, the service enable interface module receives network requirement parameters, the service addressing module ensures accurate access, and the network resource management module maintains and allocates the resource pool, guaranteeing the effective utilization of bandwidth and virtual private network resources. The terminal access control module and the network access control module work together to provide configuration and monitor the connection status for the data circulation terminal 101, and to generate IPv6 addresses and distribute routing policies, thereby supporting the on-demand creation of secure, cross-domain virtual private network channels. Overall, this private network resource scheduling device significantly improves the automation level and flexibility of network resource scheduling, promoting optimized resource allocation and efficient data transmission in a data network environment.
[0056] In some embodiments, the service enablement model module in the private network resource scheduling unit 103 or the private network resource scheduling device is provided with an application programming interface (API) to receive network requirement parameters from the data circulation support platform 102. These parameters include the participant company name, the data circulation terminal 101 identifier, the required transmission bandwidth, and the required transmission duration. A service addressing module stores the mapping relationship between company names and access gateway locations, and queries the corresponding access gateway location information based on the participant company name. When multiple management domains are involved, it sends cross-domain resource requests to the peer private network resource scheduling unit 103 through an inter-domain communication interface. A network resource management module maintains a virtual private network identifier pool and a bandwidth resource pool, and receives network requirement parameters from the data circulation support platform 102. An idle identifier is allocated in the virtual private network identifier pool, and link resources sufficient for bandwidth requirements are reserved from the bandwidth resource pool. Upon receiving a task completion signal, the allocated identifier and link resources are released. The terminal access control module is configured to generate a dialing configuration template based on the access gateway location information and send it to the corresponding data circulation terminal 101. It also receives the dialing status reported by the data circulation terminal 101. The network access control module is configured to store the authentication credentials of the access gateway, perform reliability authentication on the access gateway that initiates the connection, import the user routes used by the data circulation terminals 101 of each participant into the same virtual routing forwarding instance, and send a forwarding policy containing the virtual private network identifier and bandwidth template to the service gateway.
[0057] This disclosed embodiment achieves automatic transformation from business requirements to network actions through the collaboration of five major modules: precise addressing, on-demand allocation of virtual private networks and bandwidth, dynamic distribution of dialing configurations and forwarding policies, and support for cross-domain collaboration and resource reclamation. This enables the construction of a secure, isolated, elastic, and automatically open / release end-to-end virtual private network channel, significantly improving the automation level of resource scheduling and the efficiency of cross-domain networking in the digital network environment.
[0058] In some embodiments, the service enablement model module also receives at least one of the following operation instructions or parameters through an application programming interface (API), and triggers corresponding resource management or status query operations: Replenishment order, cancellation order, or account closure order; The billing mode selection instruction includes billing methods based on a combination of monthly fee and time, or billing methods based on a combination of monthly fee and data usage. Network port configuration change requests, including modifications to LAN ports, WAN ports, or IP addresses; Service activation test request is used to trigger connectivity or bandwidth availability testing of the virtual private network channel; The query request is used to obtain service activation status, configuration change records, performance reports, or terminal internet access behavior logs.
[0059] In some embodiments, the above-mentioned point-addition instruction is used to: add a data circulation terminal 101 to the existing virtual private network, and the service enablement model module notifies the network resource management module to allocate access credentials to the new terminal, and the terminal access control module issues dialing configuration; the point-removal instruction is used to remove a specified terminal from the current virtual private network, and the service enablement model module notifies the terminal access control module to send a dialing termination instruction to the terminal, and notifies the network resource management module to release the bandwidth resources occupied by it; the account cancellation instruction is used to terminate all data circulation services of an enterprise or user, and the service enablement model module coordinates with various modules to clear all its virtual private network identifiers, routing configurations and authentication credentials.
[0060] All the above instructions are encapsulated in JSON format via HTTPS protocol. After identity authentication, they are parsed by the service enablement model module and distributed to the corresponding functional modules for execution, ensuring the security and traceability of the operation.
[0061] In some embodiments, the network resource management module maintains an intra-domain virtual private network (VPN) resource pool and an inter-domain VPN resource pool. The intra-domain VPN resource pool stores multiple intra-domain VPN identifiers and their corresponding routing distinguishers and routing target values, which are used for the construction of VPNs between different data circulation participants within the same management domain. The inter-domain VPN resource pool stores multiple inter-domain VPN identifiers and their corresponding routing distinguishers and routing target values, which are used for the construction of VPNs between different data circulation participants in cross-management domain scenarios. The network resource management module also records the occupancy status of each virtual private network (VPN) identifier, and upon receiving network demand parameters: If it is an intra-domain scenario, select a currently idle virtual private network identifier from the intra-domain virtual private network resource pool; If it is a cross-management domain scenario, select a virtual private network identifier from the inter-domain virtual private network resource pool that is idle in both the local and remote private network resource scheduling units 103; The network resource management module also maintains information on the physical access bandwidth, used bandwidth, and remaining available bandwidth of each business gateway, and verifies whether the remaining available bandwidth meets the required transmission bandwidth in the network requirement parameters before allocating virtual private network identifiers.
[0062] The network resource management module is responsible for managing VPN resources and bandwidth resources. In detail, VPN resources include VPN name, RD / RT values, etc., and two sets of VPNs are defined for intra-domain and inter-domain scenarios respectively.
[0063] Intra-domain VPN resources: These are used to establish virtual private networks (VPNs) between different data flow participants within a domain and must correspond to the network configuration on the business gateway. The network resource management module manages VPN resources in real time, clearly defining the current VPN occupancy and idle status within the domain, and selecting an idle VPN for VPN establishment based on requirements.
[0064] Inter-domain VPN resources: These are used to establish virtual private networks between different data flow participants in cross-domain scenarios and must correspond to the network configuration on the business gateway. The network resource management module manages VPN resources in real time, clearly defining the current inter-domain VPN usage and idle status, and selects a VPN with idle resources from all parties to establish a virtual private network based on requirements.
[0065] Bandwidth resources include the physical access bandwidth of the service gateway, used bandwidth, and remaining available bandwidth. When new service connection requests arrive, it is determined whether they meet the bandwidth requirements.
[0066] This disclosure achieves resource isolation and reuse by differentiating intra-domain and inter-domain virtual private network resource pools and combining route distinguishers (RD) and route targets (RT) for identification management; it also ensures the uniqueness of identifiers by collaboratively verifying the idle status of both ends in cross-domain scenarios; and it effectively guarantees the accuracy, isolation, and quality of service of virtual private network allocation by performing access control based on real-time bandwidth margin, thereby improving the reliability and efficiency of network resource scheduling in multi-domain environments.
[0067] In some embodiments, after determining the data circulation terminal 101 that needs to be interconnected, the terminal access control module sends dialing configuration information, including dialing account, dialing password and anchor service gateway address, to each terminal to trigger the terminal to initiate a dialing connection through the Ethernet point-to-point dialing protocol; after receiving the data transmission task completion signal, it sends a dialing termination command to the terminal to disconnect the dialing connection; the terminal access control module also periodically receives real-time transmission bandwidth data reported by the terminal and stores or forwards the bandwidth data to the operation and maintenance monitoring interface.
[0068] The terminal access control module is responsible for real-time management and control of the access gateway according to the business policy. This includes: issuing business dialing accounts and passwords and anchoring the business gateway address to the access terminals of both parties that need to communicate, triggering the terminals to make PPPoE dialing; triggering the terminals to stop dialing and delete the virtual private network after the data transmission is completed; and synchronizing the real-time transmission bandwidth of the terminals for users to view.
[0069] This embodiment of the disclosure automatically triggers the terminal to establish an Ethernet point-to-point dial-up connection by issuing dial-up configuration information, and actively terminates the connection when the task ends, realizing the on-demand opening and timely release of the virtual private network channel; at the same time, by periodically collecting real-time bandwidth data, it provides a basis for network monitoring, billing and resource optimization, improving the automation level of connection management and the observability of operation and maintenance.
[0070] In some embodiments, the network access control module executes the following after receiving the networking command: Figure 3 S301-S304 are shown.
[0071] In S301, an IPv6 service address is generated for the data circulation terminal 101 according to the allocation rules based on the IPv6 address planning strategy; In S302, the user service routes of the data circulation terminal 101 are imported into the virtual routing forwarding instance allocated by the network resource management module to establish an isolated virtual private network. In S303, a forwarding policy containing a virtual route forwarding instance identifier and a bandwidth template is issued to the service gateway. The bandwidth template is determined based on the required transmission bandwidth in the network requirement parameters. In S304, during a virtual private network session, the duration of the session, the transmission traffic, and the bandwidth used are recorded, and a billing record containing the duration, traffic, and bandwidth is generated after the session ends.
[0072] This disclosure achieves rapid deployment, logical isolation, and refined management of virtual private networks by automatically generating IPv6 addresses, importing user routes to designated virtual routing forwarding instances, issuing bandwidth policies, and implementing multi-dimensional session metering. At the same time, it generates structured billing records to provide data support for on-demand billing, thereby improving network configuration efficiency, security isolation capabilities, and operational traceability.
[0073] In some embodiments, the service addressing module stores the correspondence between enterprise names and access gateway location information, and queries the corresponding access gateway location based on the participating enterprise name in the network requirement parameters; when the participating enterprise belongs to different management domains, the service addressing module sends an addressing request to the peer private network resource scheduling unit 103 through the inter-domain communication interface, and receives the peer access gateway location information returned by the peer private network resource scheduling unit 103.
[0074] The business addressing module is responsible for addressing based on the enterprise name and confirming the terminal location; when cross-domain scenarios are involved, it uses the east-west interface to determine the business system of the other party; the business system of the other party performs business policy configuration to complete the end-to-end virtual private network construction.
[0075] This disclosure embodiment achieves rapid location of participating terminal terminals through a mapping mechanism between enterprise names and access gateway locations; in cross-management domain scenarios, it automatically obtains peer gateway information through inter-domain communication interfaces, avoiding manual configuration, effectively supporting the automated collaborative construction of end-to-end virtual private networks, and improving the efficiency and scalability of multi-domain networking.
[0076] In some embodiments, the private network forwarding network 104 includes the following modules: Access Gateway: Interacts with data flow access terminals, providing multiple ubiquitous access methods such as STN, OTN, PON, and fiber optic direct drive; the control plane supports the management of data private network service systems and remote service automated configuration, triggering dialing to achieve rapid network setup in seconds; Service gateway: Overlay access is achieved with the access gateway through solutions such as PPPoEoIPv6, VXLAN, and L2TP, enabling one-hop overlay access for the access gateway; the control plane supports signaling-level QoD / BoD / ToD service policy control, which takes effect within seconds.
[0077] Figure 4 This disclosure illustrates a data transmission system for the Internet of Things (IoT) according to an embodiment, such as... Figure 4As shown, the data transmission system for the Internet of Things (IoT) provided in this embodiment includes a data circulation terminal 101, a data circulation support platform 102, a private network resource scheduling unit 103, and a private network forwarding network 104. This embodiment constructs a low-cost, service-oriented overlay network on an existing network, providing elasticity, agility, isolation protection, and task-oriented service capabilities. It deploys the private network resource scheduling unit 103 (also known as the data private network business system), and provides open API interfaces for the data circulation support platform 102 to call network capabilities. Through the private network resource scheduling unit 103, the system provides real-time control of the data private network transmission network base (i.e., the private network forwarding network 104, including access gateways and service gateways). The access gateway interfaces with the data circulation terminal 101, formulating business policies such as service addressing, VPN management, and bandwidth templates. It provides capabilities such as service admission authentication, virtual private network construction / modification, dynamic bandwidth adjustment, and service lifecycle management, enabling QoD, BoD, and ToD business policies to take effect within seconds. Ultimately, it achieves high-bandwidth, high-elasticity, high-security, and task-oriented data circulation.
[0078] This embodiment of the disclosure provides multiple interfaces such as service ordering, service cancellation, information synchronization, and session query through the API interface between the private network resource scheduling unit 103 (also known as the data private network service system) and the data circulation support platform 102, meeting users' self-service needs; relying on the dynamic virtual private network resource scheduling unit 103 to manage service gateways and access terminals, it enables the creation / deletion of virtual private networks between data circulation participants in seconds, providing elastic bandwidth; through the east-west interface, it enables rapid connection of cross-regional network resources; it performs reliability authentication based on the account and password of data circulation participants, and only after successful authentication can secure networking be achieved; it matches different VRF instances in real time based on different networking requirements, isolating them from Internet services to ensure the reliability of data transmission.
[0079] The concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to define the order of functions performed by these devices, modules or units or their interdependencies.
[0080] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0081] Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0082] Figure 5 This diagram illustrates a data transmission method for data networks according to an embodiment of the present disclosure, applicable to the data transmission system for data networks in any of the above embodiments, such as... Figure 5 As shown, the data transmission method for data networks provided in this embodiment includes S501-S506.
[0083] In S501, after the data circulation support platform determines the participants that need to transmit data, it sends network requirement parameters to the private network resource scheduling unit. The network requirement parameters include the participant identifier, the required transmission bandwidth, and the transmission duration. In S502, the private network resource scheduling unit receives network demand parameters through the application programming interface, allocates network resources based on the virtual private network resource pool and bandwidth resource pool, and communicates with another private network resource scheduling unit in cross-management domain scenarios to collaboratively complete end-to-end resource allocation. In S503, the private network resource scheduling unit issues access credentials to the data circulation terminal and issues virtual private network configuration and bandwidth templates to the private network forwarding network; In S504, the data circulation terminal communicates with the data circulation support platform through the first network interface in the control plane, and establishes an encrypted data connection with the private network forwarding network through the second network interface based on the access credentials. In S505, the private network forwarding network establishes an isolated virtual private network channel between the access gateway and the service gateway and performs bandwidth scheduling based on the virtual private network configuration and bandwidth template to carry data plane traffic between data circulation terminals.
[0084] This disclosure achieves fully automated end-to-end virtual private network (VPN) activation through business-driven parameter distribution, cross-domain collaborative resource allocation, dual-channel terminal access, and automatic channel construction; separation of control plane and data plane ensures security isolation, and on-demand bandwidth scheduling improves resource efficiency, significantly enhancing the agility, reliability, and security of multi-entity, cross-domain data transmission in the data network environment.
[0085] In some embodiments, in cross-management domain scenarios, communication with another private network resource scheduling unit is used to collaboratively complete end-to-end resource allocation, including... Figure 6 S601-S603 are shown.
[0086] In S601, an addressing request containing the names of the participating companies is sent to the private network resource scheduling unit at the other end. In S602, the location information of the peer access gateway returned by the peer private network resource scheduling unit is received; In S603, a virtual private network identifier for an inter-domain network is jointly negotiated and selected when both the local and remote ends are idle.
[0087] This embodiment of the disclosure achieves bidirectional addressing and resource coordination through a cross-domain communication interface, ensuring rapid location of the peer access gateway and jointly selecting an inter-domain virtual private network identifier where both ends are idle. This enables effective allocation and isolation of resources in a cross-management domain environment. This method avoids manual intervention, improves the automation level and resource utilization of cross-domain networking, and enhances network flexibility and reliability in multi-domain environments.
[0088] In some embodiments, the data circulation terminal establishes an encrypted data connection based on access credentials, including: receiving dialing configuration information containing a dialing account, dialing password, and anchor service gateway address; initiating a dialing connection via Ethernet point-to-point dialing protocol; and disconnecting the dialing connection after receiving a task completion signal. This disclosure embodiment, by issuing dialing configuration and automatically establishing and releasing connections based on Ethernet point-to-point dialing protocol, achieves secure and on-demand access to the virtual private network by the data circulation terminal, improving the automation and security of connection management.
[0089] In some embodiments, the above-described data transmission method for data networks further includes: after the data transmission task is completed, the private network resource scheduling unit releases the allocated virtual private network identifier and bandwidth resources, and deletes the corresponding virtual routing forwarding instance. This embodiment of the present disclosure automatically releases the virtual private network identifier, bandwidth resources, and routing instance after the task is completed, avoiding resource idleness, improving network resource utilization efficiency, and ensuring the long-term stability and scalability of the system.
[0090] The following reference Figure 7 This describes the electronic device provided in the embodiments of this disclosure. Figure 7 The electronic device 700 shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments disclosed herein.
[0091] Figure 7 This diagram illustrates the architecture of an electronic device 700 provided in an embodiment of the present invention. Figure 7 As shown, the electronic device 700 includes, but is not limited to, at least one processor 710 and at least one memory 720. The memory 720 is used to store instructions.
[0092] In some embodiments, memory 720 may include a readable medium in the form of volatile memory cells, such as random access memory (RAM) 7201 and / or cache 7202, and may further include read-only memory (ROM) 7203.
[0093] In some embodiments, the memory 720 may also include a program / utility 7204 having a set (at least one) program module 7205, such program module 7205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0094] In some embodiments, the memory 720 may also store data.
[0095] As an example, processor 710 can read data stored in memory 720, which may be stored at the same memory address as the instruction, or the data may be stored at a different memory address than the instruction.
[0096] Processor 710 is configured to invoke instructions stored in memory 720 to implement the steps described in the "Exemplary Methods" section above, according to various exemplary embodiments of this disclosure. For example, processor 710 can execute the steps of the above-described embodiments of the data transmission method for data networks.
[0097] It should be noted that the processor 710 described above can be a general-purpose processor or a special-purpose processor. The processor 710 may include one or more processing cores, and the processor 710 executes various functional applications and data processing by running instructions.
[0098] In some embodiments, processor 710 may include a central processing unit (CPU) and / or a baseband processor.
[0099] In some embodiments, the processor 710 may determine an instruction based on the priority identifier and / or function category information carried in each control instruction.
[0100] In this disclosure, the processor 710 and memory 720 can be configured separately or integrated together. As an example, the processor 710 and memory 720 can be integrated on a single board or a system-on-chip (SOC).
[0101] like Figure 7 As shown, the electronic device 700 is embodied in the form of a general-purpose computing device. The electronic device 700 may also include a bus 730.
[0102] Bus 730 can represent one or more of several types of bus structures, including a memory bus or memory controller, peripheral bus, graphics acceleration port, processor, or a local bus using any of the various bus structures.
[0103] Electronic device 700 can also communicate with one or more external devices 740 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 700, and / or with any device that enables electronic device 700 to communicate with one or more other computing devices (e.g., router, modem, etc.). Such communication can be performed through input / output (I / O) interface 750.
[0104] Furthermore, the electronic device 700 can also communicate with one or more networks (such as local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via the network adapter 760.
[0105] like Figure 7 As shown, the network adapter 760 communicates with other modules of the electronic device 700 via the bus 730.
[0106] It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 700, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0107] It is understood that the structure illustrated in the embodiments of this disclosure does not constitute a specific limitation on the electronic device 700. In other embodiments of this disclosure, the electronic device 700 may include more than Figure 7 This may involve more or fewer components, or combining certain components, or splitting certain components, or different component arrangements. Figure 7 The components shown can be implemented in hardware, software, or a combination of both.
[0108] This disclosure also provides a computer-readable storage medium storing computer instructions thereon, which, when executed by a processor, implement the data transmission method for data networks described in the above method embodiments.
[0109] In this disclosure, the computer-readable storage medium is one capable of sending, propagating, or transmitting computer instructions for use by or in connection with an instruction execution system, apparatus, or device. As an example, the computer-readable storage medium is a non-volatile storage medium.
[0110] In some embodiments, more specific examples of computer-readable storage media in this disclosure may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, USB flash drives, portable hard drives, or any suitable combination of the foregoing.
[0111] In this embodiment of the disclosure, the computer-readable storage medium may include data signals propagated in baseband or as part of a carrier wave, wherein computer instructions (readable program code) are carried.
[0112] In some examples, computational instructions contained on a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0113] This disclosure also provides a computer program product storing instructions that, when executed by a computer, cause the computer to implement the data transmission method for data networks described in the above-described method embodiments. The instructions may be program code. In specific implementations, the program code may be written using any combination of one or more programming languages. The program code may execute entirely on a user's computing device, partially on a user's device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0114] This disclosure also provides a chip, including at least one processor and an interface; the interface is used to provide program instructions or data to at least one processor; the at least one processor is used to execute the program instructions to implement the data transmission method for data networking described in the above method embodiments.
[0115] In some embodiments, the chip may further include a memory for storing program instructions and data, the memory being located within or outside the processor.
[0116] Those skilled in the art will understand that all or part of the steps of the above embodiments can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, which can be collectively referred to as "circuit", "module" or "system".
[0117] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein.
[0118] This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.
Claims
1. A data transmission system for the Internet of Things, characterized in that, include: The data circulation terminal is equipped with a first network interface and a second network interface, respectively used for control plane communication and data plane communication. The data circulation support platform is configured to send network demand parameters to the private network resource scheduling unit after determining the participants that need to transmit data. The private network resource scheduling unit is configured to receive the network demand parameters through the application programming interface, allocate network resources based on the virtual private network resource pool and bandwidth resource pool, and communicate with another private network resource scheduling unit in cross-management domain scenarios to collaboratively complete end-to-end resource allocation. It also issues access credentials to the data circulation terminal and issues virtual private network configuration and bandwidth templates to the private network transmission network. The private network forwarding network includes interconnected access gateways and service gateways. The access gateway is connected to the second network interface and establishes isolated virtual private network channels and performs bandwidth scheduling according to the virtual private network configuration and bandwidth template.
2. The system according to claim 1, characterized in that, The data circulation terminal includes: The first data module is configured to perform standard encapsulation, processing, identifier resolution, and directory publication of raw data; The first network module is configured to communicate with the data circulation support platform through the first network interface, perform identity authentication, asset registration and policy management operations, and establish an encrypted data connection with the private network transmission network through the second network interface according to the access credential issued by the private network resource scheduling unit, and exchange data with other data circulation terminals.
3. The system according to claim 2, characterized in that, The data circulation terminal is a physical server or a virtual machine; When the data circulation terminal is a physical server, the first network interface and the second network interface are two physical network cards, respectively. When the data circulation terminal is a virtual machine, the first network interface and the second network interface are two virtual network cards, respectively. The data circulation terminal, by configuring the operating system routing table, directs control plane traffic destined for the data circulation support platform to the first network interface, and directs data plane traffic destined for other data circulation terminals to the second network interface.
4. The system according to claim 1, characterized in that, The data circulation support platform includes: The second data module is configured to perform access management, identity authentication, asset registration and catalog management on the data circulation terminal, and to match data providers and demanders based on catalog information to generate data circulation tasks. The second network module is configured to communicate with the data circulation terminal and the private network resource scheduling unit via the Internet. It is used to send control commands to the data circulation terminal to realize access, control and management, and in response to determining the participants that need to transmit data, it sends network requirement parameters containing the participant identifier, required bandwidth and transmission duration to the private network resource scheduling unit through the application programming interface to trigger the creation or deletion of the virtual private network.
5. The system according to claim 1, characterized in that, The private network resource scheduling unit includes: The service enablement model module is equipped with an application programming interface (API) to receive network requirement parameters from the data circulation support platform. The network requirement parameters include the names of participating companies, data circulation terminal identifiers, required transmission bandwidth, and required transmission duration. The business addressing module stores the mapping relationship between enterprise names and access gateway locations, and queries the corresponding access gateway location information based on the enterprise names of the participating parties. When multiple management domains are involved, it sends cross-domain resource requests to the peer private network resource scheduling unit through the inter-domain communication interface. The network resource management module maintains a virtual private network (VPN) identifier pool and a bandwidth resource pool. Based on the network requirement parameters, it allocates an idle identifier from the VPN identifier pool and reserves link resources from the bandwidth resource pool to meet the bandwidth requirements. Upon receiving a task completion signal, it releases the allocated identifier and link resources. The terminal access control module is configured to generate a dialing configuration template based on the access gateway location information and send it to the corresponding data circulation terminal, and also receive the dialing status reported by the data circulation terminal. The network access control module is configured to store the authentication credentials of the access gateway, perform reliability authentication on the access gateway that initiates the connection, import the user routes used by the data circulation terminals of each participant into the same virtual routing forwarding instance, and issue a forwarding policy containing the virtual private network identifier and bandwidth template to the service gateway.
6. The system according to claim 5, characterized in that, The service enabling model module also receives at least one of the following operation instructions or parameters through the application programming interface: Replenishment order, cancellation order, or account closure order; A billing mode selection instruction, wherein the billing mode includes a billing method based on a combination of monthly fee and time, or a billing method based on a combination of monthly fee and data usage; Network port configuration change requests, including modifications to LAN ports, WAN ports, or IP addresses; Service activation test request is used to trigger connectivity or bandwidth availability testing of the virtual private network channel; The query request is used to obtain service activation status, configuration change records, performance reports, or terminal internet access behavior logs.
7. The system according to claim 5, characterized in that, The network resource management module maintains intra-domain virtual private network (VPN) resource pools and inter-domain VPN resource pools. The intra-domain VPN resource pool stores multiple intra-domain VPN identifiers and their corresponding routing distinguishers and routing target values, which are used for the construction of VPNs between different data circulation participants within the same management domain. The inter-domain VPN resource pool stores multiple inter-domain VPN identifiers and their corresponding routing distinguishers and routing target values, which are used for the construction of VPNs between different data circulation participants in cross-management domain scenarios. The network resource management module also records the occupancy status of each virtual private network identifier, and upon receiving network demand parameters: If it is an intra-domain scenario, then select a currently idle virtual private network identifier from the intra-domain virtual private network resource pool; If it is a cross-management domain scenario, then select a virtual private network identifier from the inter-domain virtual private network resource pool that is idle in both the local and remote private network resource scheduling units; The network resource management module also maintains information on the physical access bandwidth, used bandwidth, and remaining available bandwidth of each service gateway, and verifies whether the remaining available bandwidth meets the required transmission bandwidth in the network requirement parameters before allocating the virtual private network identifier.
8. The system according to claim 5, characterized in that, After determining the data circulation terminals that need to communicate, the terminal access control module sends dialing configuration information, including dialing account, dialing password and anchor service gateway address, to each terminal to trigger the terminal to initiate a dialing connection through the Ethernet point-to-point dialing protocol. After receiving the data transmission task completion signal, a dialing termination command is sent to the terminal to disconnect the dialing connection; The terminal access control module also periodically receives real-time transmission bandwidth data reported by the terminal and stores or forwards the bandwidth data to the operation and maintenance monitoring interface.
9. The system according to claim 5, characterized in that, After receiving the networking command, the network access control module performs the following operations: IPv6 service addresses are generated for data circulation terminals according to the allocation rules based on the IPv6 address planning strategy; The user service routes of the data circulation terminal are imported into the virtual routing forwarding instance allocated by the network resource management module to establish an isolated virtual private network; A forwarding policy containing the virtual route forwarding instance identifier and bandwidth template is issued to the service gateway, wherein the bandwidth template is determined according to the required transmission bandwidth in the network requirement parameters; During a virtual private network session, the session duration, transmission traffic, and bandwidth used are recorded, and a billing record containing the duration, traffic, and bandwidth is generated after the session ends.
10. The system according to claim 5, characterized in that, The service addressing module stores the correspondence between enterprise names and access gateway location information, and queries the corresponding access gateway location based on the participating enterprise name in the network requirement parameters. When the participating enterprise belongs to a different management domain, the service addressing module sends an addressing request to the peer private network resource scheduling unit through the inter-domain communication interface, and receives the peer access gateway location information returned by the peer private network resource scheduling unit.
11. A data transmission method for data networks, characterized in that, The method, applied to the data transmission system oriented towards data networking according to any one of claims 1-10, comprises: After identifying the participants that need to transmit data, the data circulation support platform sends network requirement parameters to the private network resource scheduling unit. The network requirement parameters include the participant identifier, the required transmission bandwidth, and the transmission duration. The private network resource scheduling unit receives the network demand parameters through the application programming interface, allocates network resources based on the virtual private network resource pool and bandwidth resource pool, and communicates with another private network resource scheduling unit in cross-management domain scenarios to collaboratively complete end-to-end resource allocation. The private network resource scheduling unit issues access credentials to the data circulation terminal and issues virtual private network configuration and bandwidth template to the private network forwarding network. The data circulation terminal communicates with the data circulation support platform via the first network interface, and establishes an encrypted data connection with the private network forwarding network via the second network interface based on the access credentials. The private network forwarding network establishes an isolated virtual private network channel between the access gateway and the service gateway and performs bandwidth scheduling based on the virtual private network configuration and bandwidth template to carry the data plane traffic between the data circulation terminals.