Cross-virtual network domain data flow guiding and optimizing method and device
By adopting a centralized policy control and distributed data forwarding architecture, the system dynamically selects the optimal transmission path and achieves rapid fault switching, thus solving the problems of single point of failure risk and insufficient processing capacity in cross-branch network communication. This improves network reliability and resource utilization, and meets the low latency and high throughput requirements of enterprise-critical businesses.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU SHENGTIAN INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-03-03
- Publication Date
- 2026-04-28
AI Technical Summary
Existing technologies for cross-branch network communication pose a single point of failure risk, and in high-concurrency traffic scenarios, virtual switches have limited processing capabilities, making it difficult to meet the requirements of enterprise-critical businesses for low latency and high throughput.
It adopts a centralized policy control and distributed data forwarding architecture, receives data traffic through edge gateway devices, and dynamically selects the optimal transmission path according to the forwarding policy generated by the centralized policy control center. It supports switching between primary and backup paths, and combines link status information from active detection and passive monitoring to achieve rapid fault switching and closed-loop optimization.
It eliminates the risk of single points of failure, achieves high reliability and continuity of enterprise cross-branch networks, improves network resource utilization and cost-effectiveness, and ensures the service quality requirements of different business types.
Smart Images

Figure CN121940346A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication technology, specifically to a method and apparatus for guiding and optimizing data traffic across virtual network domains. Background Technology
[0002] As businesses expand and expand globally, they often establish communication branches in multiple geographical locations and interconnect these branches via dedicated lines provided by network operators. Traditional enterprise network architectures typically rely on a single dedicated network line for cross-branch communication, which presents a significant single point of failure risk. When the dedicated line or network access equipment fails, communication between branches will be completely interrupted, severely impacting the continuity of business operations.
[0003] As disclosed in CN110311861B, a method and apparatus for guiding data traffic includes a first traffic redirection server on the first communication branch side equipped with a local virtual switch that connects to a dedicated network line between the first and second communication branches; at least one backup network line is established between the first traffic redirection server and a second traffic redirection server on the second communication branch side; the first traffic redirection server receives data traffic from the first communication branch to the second communication branch through the local virtual switch; and the first traffic redirection server sends data traffic to the second communication branch through the dedicated network line or the backup network line based on the traffic filtering rules of the local virtual switch. By adopting the above technical solution, the beneficial effects of this invention are: it can effectively guarantee the interconnection between enterprise communication branches at a lower cost, thereby improving the service quality of enterprise services.
[0004] Although the aforementioned patents can establish backup lines through traffic redirection servers, as all traffic must pass through these servers, their processing capacity and reliability become new single points of failure. Especially in high-concurrency traffic scenarios, the processing capacity of software-based virtual switches is limited, making it difficult to meet the requirements of enterprises' critical businesses for low latency and high throughput. Summary of the Invention
[0005] The purpose of this invention is to provide a method and apparatus for guiding and optimizing data traffic across virtual network domains, so as to solve the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention provides the following technical solution:
[0007] Firstly, a method for guiding and optimizing data traffic across virtual network domains is provided, including:
[0008] The edge gateway device of the first communication branch receives data traffic from the first communication branch to the second communication branch;
[0009] The edge gateway device determines the transmission path corresponding to the data traffic according to the forwarding policy issued by the centralized policy control center. The forwarding policy is dynamically generated by the policy control center based on the link status information between each communication branch.
[0010] The edge gateway device sends the data traffic to the second communication branch through a determined transmission path.
[0011] Optionally, the method further includes:
[0012] The edge gateway devices of each communication branch report the link status information of each physical link they are connected to to the policy control center;
[0013] The policy control center generates the forwarding policy based on the link status information and predefined service policies, and distributes it to each edge gateway device.
[0014] Furthermore, the link status information includes, but is not limited to, at least one of: link latency, available bandwidth, packet loss rate, link load rate, and error rate. The edge gateway device acquires this information through a combination of active probing and passive monitoring, wherein active probing includes periodically sending probe packets, and passive monitoring includes real-time statistics of interface counters.
[0015] Optionally, the transmission path includes a primary transmission path and at least one backup transmission path; the method further includes:
[0016] When the link quality of the primary transmission path is lower than a preset threshold, the edge gateway device switches the data traffic to the backup transmission path.
[0017] The link quality is determined based on at least one of the following indicators: link latency, packet loss rate, and available bandwidth. The preset thresholds can be dynamically adjusted according to different service types. For example, for real-time audio and video services, the latency threshold can be set to a lower value, and the packet loss rate threshold can be set to a lower percentage; for file transfer services, the latency threshold can be set to a higher value.
[0018] Secondly, a cross-virtual network domain data traffic guidance and optimization device is provided, deployed on the communication branch side, the device comprising:
[0019] The receiving module is used to receive data traffic sent from the current communication branch to other communication branches;
[0020] The policy execution module is used to determine the transmission path corresponding to the data traffic based on the forwarding policy issued by the centralized policy control center.
[0021] The sending module is used to send the data traffic to the target communication branch through a determined transmission path.
[0022] Optionally, the device further includes:
[0023] The detection module is used to detect the link status information of each physical link connected to the device;
[0024] The reporting module is used to report the link status information to the policy control center.
[0025] Optionally, the policy execution module includes:
[0026] The switching unit is used to switch the data traffic to an alternative transmission path when the link quality of the current transmission path is lower than a preset threshold.
[0027] The switching unit is based on fast fault detection technology, and the detection time is configurable to ensure the real-time nature of service switching.
[0028] Thirdly, a cross-virtual network domain data traffic guidance and optimization system is provided, including:
[0029] Multiple devices as described above are deployed in multiple communication branches;
[0030] A centralized policy control center, which is communicatively connected to each of the aforementioned devices, is used to generate forwarding policies based on the link status information reported by each device and to distribute the forwarding policies to each device.
[0031] Optionally, the policy control center includes:
[0032] The topology management module is used to maintain the network topology relationships between various communication branches, including device connection relationships and link attribute information;
[0033] The policy calculation module is used to calculate the optimal forwarding path based on the link state information and a predefined service policy library using a multi-objective optimization algorithm.
[0034] The policy distribution module is used to distribute the generated forwarding policies to each edge gateway device through a secure encrypted channel.
[0035] The business strategy library defines the service quality requirements, priority policies, and security policies for different business types.
[0036] Fourthly, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method described above.
[0037] Compared with the prior art, the beneficial effects of the present invention are:
[0038] 1. This invention eliminates the single point of failure risk in traditional solutions by combining centralized policy control with distributed data forwarding architecture. Data transmission paths are directly established between edge gateway devices, avoiding performance bottlenecks caused by data traffic passing through a single proxy node. When any transmission path fails, the system can automatically switch to a backup path within milliseconds, significantly improving the reliability and continuity of cross-branch network communication for enterprises.
[0039] 2. This invention utilizes an intelligent path selection mechanism based on real-time link status and service requirements to optimize network resource allocation. The policy control center dynamically calculates the optimal forwarding path based on the overall network conditions, enabling differentiated scheduling for different service types' quality of service requirements. Simultaneously, a closed-loop feedback mechanism continuously optimizes the policy, effectively improving overall network utilization and cost-effectiveness while ensuring the quality of service for critical services. Attached Figure Description
[0040] Figure 1 This is a system architecture diagram of the present invention;
[0041] Figure 2 This is a network connection diagram of the present invention;
[0042] Figure 3 This is the data flow and control diagram of the present invention. Detailed Implementation
[0043] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0044] Example 1
[0045] This invention addresses the single point of failure risk and forwarding performance issues in existing cross-branch network communication technologies. By constructing an architecture that combines centralized policy control with distributed data forwarding, it achieves highly reliable, high-performance, and intelligent cross-domain traffic guidance. The centralized policy control center intelligently generates forwarding policies based on the global network status, and the edge gateway devices deployed in each communication branch execute the policies locally, achieving optimal path selection and rapid failover for data traffic. At the same time, the policy is continuously optimized through a closed-loop feedback mechanism.
[0046] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings. This embodiment uses a typical enterprise multi-branch network interconnection scenario as an example, but the application of the present invention is not limited thereto.
[0047] like Figure 1-3 As shown, the cross-virtual network domain data traffic guidance and optimization method of the present invention includes the following steps:
[0048] Step S101, System initialization and link status monitoring:
[0049] After the edge gateway device starts up, it automatically registers with the centralized policy control center and begins monitoring the real-time status of each physical link it is connected to. Specifically, this includes:
[0050] Step S1011, Device Registration and Topology Discovery: After each edge gateway device powers on, it sends a registration request to the policy control center via the out-of-band management interface or a preset discovery address. Registration information includes the device's unique identifier, software version, and network interface configuration (such as IP address and connection type). Based on the registration information of all devices, the policy control center automatically constructs a full network topology view.
[0051] Step S1012, Active Link Probe: The edge gateway device sends ICMP probe packets to the interfaces of all reachable peer edge gateway devices at a preset first period (e.g., 100 milliseconds) to measure link latency. Simultaneously, a TCP throughput test is initiated at a preset second period (e.g., 5 minutes) to estimate the available bandwidth of the link by transmitting a certain amount of test data.
[0052] Step S1013, Passive performance statistics: The edge gateway device reads the data from the network interface counter in real time, and counts the number of bytes sent and received, the number of erroneous packets, and the number of dropped packets per unit time, thereby calculating the real-time utilization rate, packet loss rate, and error rate of the link.
[0053] The comprehensive link quality scoring function involved is as follows:
[0054]
[0055] in, Indicates link In time The quality score ranges from 0 to 1, with a higher value indicating better link quality. Indicates time The measured link delay is in milliseconds. Indicates time The measured available bandwidth of the link, in Mbps; Indicates time The packet loss rate obtained from the statistics is a percentage value; and These represent the minimum and maximum acceptable delay thresholds, respectively. This represents the maximum bandwidth reference value, which is usually set as the link's physical bandwidth or management limit. Indicates the maximum acceptable packet loss rate; , , Let be the weighting coefficient, satisfying + + =1.
[0056] Step S102, Strategy Generation and Distribution:
[0057] Based on the link status information periodically reported by all edge gateway devices in step S101, the centralized policy control center dynamically generates forwarding policies for different service traffic and distributes them to the relevant edge gateway devices. Specifically:
[0058] Step S1021, Business Requirement Matching: First, the policy control center maintains a business policy library, which defines the service quality requirements for different business types. When a policy needs to be generated for a certain data traffic from branch A to branch B, the system matches the business type based on the characteristics of the traffic (such as source / destination IP, port, protocol) to obtain its service quality requirements, including the maximum allowable latency. Minimum required bandwidth Maximum allowable packet loss rate .
[0059] Step S1022, Feasible Path Calculation: Then, based on the current global topology and link quality information, calculate all possible paths from the source branch to the destination branch. For each candidate path... Calculate its end-to-end quality and determine whether it meets the hard constraints of the business.
[0060] Step S1023, Optimal Strategy Decision: Among the set of paths that meet the hard constraints, a multi-objective optimization function is used to select the optimal path, forming a forwarding strategy instruction that includes the primary path and at least one backup path.
[0061] The business satisfaction judgment and path optimization functions involved are as follows:
[0062] Business satisfaction judgment logic: For business and path If both conditions are met:
[0063] and and
[0064] Then determine the path Can meet business needs The needs, remember ,otherwise .
[0065] in, The end-to-end delay of the path; The bottleneck bandwidth of the path; This represents the cumulative packet loss rate of the path.
[0066] Multi-objective path optimization function:
[0067]
[0068] in, Indicates all that satisfy The set of feasible paths; Indicates the use of path The cost; Indicates the upper limit of cost; , , , To optimize weights, adjustments can be made based on network management strategies.
[0069] Step S103, Data traffic reception, matching, and forwarding are executed:
[0070] When the edge gateway device receives data traffic destined for other branches from its own communication branch, it executes a local forwarding policy to guide the traffic. The key to this step is that the edge gateway device implements high-performance policy matching and forwarding locally, avoiding the latency and bottlenecks caused by data traffic passing through the central proxy node. The specific implementation process is as follows:
[0071] First, the receiving module of the edge gateway device captures a data packet and extracts its five-tuple information (source IP, destination IP, protocol, source port, destination port). Then, the policy enforcement module performs a fast match in a locally maintained policy table. This local policy table is derived from policy instructions issued by the control center and is typically implemented using a hardware forwarding table (such as TCAM), supporting line-speed matching. If a match is successful, the packet is processed according to the action items in the policy instruction (such as "Use primary path: interface eth0" or "Add DSCP flag EF"). Finally, the sending module sends the processed data packet out through the specified physical network interface. If the policy indicates the need to use a tunnel (such as an IPsec VPN), the corresponding tunnel encapsulation and encryption operations are performed before transmission.
[0072] Step S104, Fault detection, switching, and closed-loop optimization:
[0073] During forwarding, the edge gateway device continuously monitors the quality of the primary transmission path. Simultaneously, the method includes a closed-loop optimization mechanism, which dynamically adjusts parameters or weights in the policy calculation based on the actual feedback after policy execution, thereby achieving adaptive optimization of network performance.
[0074] Step S1041, Fault Detection and Fast Switching: The edge gateway device performs bidirectional forwarding detection on the primary path used by each traffic it forwards. When a path fault or quality below a preset threshold is detected... When this happens, a local handover decision is immediately triggered.
[0075] Switching decision functions:
[0076]
[0077] The judgment condition is:
[0078] condition The current path quality is below the threshold.
[0079]
[0080] condition There is a better alternative path.
[0081]
[0082] in, Indicates the need to switch over; A set of alternative paths; This is a quality difference threshold used to prevent frequent switching.
[0083] Step S1042, Closed-Loop Optimization: The edge gateway device periodically (e.g., every 5 seconds) reports policy execution statistics to the policy control center, including actual latency, packet loss rate, throughput, and handover events for each path. The optimization module of the policy control center analyzes this feedback data. If it is found that the actual performance of a certain path continuously deviates from the predicted value, or the requirements of a certain service type change, the policy calculation in step S102 is re-executed, and an updated policy is generated and issued, thus forming a closed loop of "monitoring-decision-execution-feedback-optimization".
[0084] Example 2
[0085] This embodiment provides a cross-virtual network domain data traffic guidance and optimization device and system corresponding to the method described in Embodiment 1.
[0086] The system includes multiple edge gateway devices and a centralized policy control center.
[0087] Edge gateway devices, deployed at each communication branch, perform local reception, policy matching, and forwarding of data traffic. Each edge gateway device includes:
[0088] Receiving module: Used to perform the operation of receiving data traffic sent from this branch to external branches in step S103 of embodiment one.
[0089] Detection and reporting module: used to perform the link status active detection, passive statistics and reporting to the control center in step S101 of embodiment one.
[0090] Policy execution module: Used to perform local policy matching and traffic processing (such as tagging and encryption) in step S103 of Embodiment 1, and fast switching decision in step S104. This module can be further divided into a matching unit, a processing unit, and a switching unit.
[0091] Sending module: Used to perform the operation of sending the processed data packet out through the specified interface in step S103 of embodiment one.
[0092] A centralized policy control center, communicating with all edge gateway devices, is used for centralized policy management. It includes:
[0093] Topology Management Module: Used to maintain the network topology composed of the registration information of each edge gateway device.
[0094] Strategy calculation module: used to perform business requirement matching, feasible path calculation and optimal strategy decision in step S102 of embodiment one.
[0095] Policy delivery module: Used to securely deliver generated policy instructions to designated edge gateway devices.
[0096] Optimization Analysis Module: Used to perform closed-loop optimization in step S104 of Example 1, analyze feedback data and trigger strategy recalculation.
[0097] The working process of this device / system is the same as that described in Embodiment 1, and will not be repeated here.
[0098] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for guiding and optimizing data traffic across virtual network domains, characterized in that, include: The edge gateway device of the first communication branch receives data traffic from the first communication branch to the second communication branch; The edge gateway device determines the transmission path corresponding to the data traffic according to the forwarding policy issued by the centralized policy control center. The forwarding policy is dynamically generated by the policy control center based on the link status information between each communication branch. The edge gateway device sends the data traffic to the second communication branch through a determined transmission path.
2. The method for guiding and optimizing data traffic across virtual network domains according to claim 1, characterized in that: Also includes: The edge gateway devices of each communication branch report the link status information of each physical link they are connected to to the policy control center; The policy control center generates the forwarding policy based on the link status information and predefined service policies, and distributes it to each edge gateway device.
3. The method for guiding and optimizing data traffic across virtual network domains according to claim 2, characterized in that: The link status information includes at least one of link latency, available bandwidth, and packet loss rate.
4. The method for guiding and optimizing data traffic across virtual network domains according to claim 1, characterized in that: The transmission path includes a primary transmission path and at least one backup transmission path. When the link quality of the primary transmission path is lower than a preset threshold, the edge gateway device switches the data traffic to the backup transmission path.
5. The method for guiding and optimizing data traffic across virtual network domains according to claim 4, characterized in that: The link quality is determined based on at least one of the following metrics: link latency, packet loss rate, and available bandwidth.
6. A data traffic guidance and optimization device across virtual network domains, characterized in that: Deployed on the communication branch side, the device includes: The receiving module is used to receive data traffic sent from the current communication branch to other communication branches; The policy execution module is used to determine the transmission path corresponding to the data traffic based on the forwarding policy issued by the centralized policy control center. The sending module is used to send the data traffic to the target communication branch through a determined transmission path.
7. The data traffic guidance and optimization device across virtual network domains according to claim 6, characterized in that: The device further includes: The detection module is used to detect the link status information of each physical link connected to the device; The reporting module is used to report the link status information to the policy control center.
8. The data traffic guidance and optimization device across virtual network domains according to claim 6, characterized in that: The strategy execution module includes: The switching unit is used to switch the data traffic to an alternative transmission path when the link quality of the current transmission path is lower than a preset threshold.
9. A data traffic guidance and optimization system across virtual network domains, characterized in that, include: Multiple devices as described in any one of claims 6-8 are respectively deployed in multiple communication branches; A centralized policy control center, which is communicatively connected to each of the aforementioned devices, is used to generate forwarding policies based on the link status information reported by each device and to distribute the forwarding policies to each device.
10. An electronic device, characterized in that, It includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method as described in any one of claims 1-5.
Citation Information
Patent Citations
A method and apparatus for guiding data traffic
CN110311861B