SD-WAN link control method and system based on global situation awareness

By leveraging cloud-edge collaborative global situational awareness technology, a network digital twin is instantiated to simulate future situations and generate a predictive global situational map. This addresses the lack of foresight in SD-WAN link control, enables adaptive optimization of intelligent link control, and improves service reliability and application experience.

CN121940355APending Publication Date: 2026-04-28GUANGDONG YIMA COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG YIMA COMM TECH CO LTD
Filing Date
2026-01-26
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing SD-WAN link control methods lack the ability to predict the future state of the network, making it difficult to achieve foresight and decision-making accuracy in complex and dynamic environments, which affects the service quality and business continuity of critical applications.

Method used

By coordinating with edge devices through a cloud control platform, and utilizing global situational awareness technology, external environmental data, security intelligence data, and local application data are acquired. A network digital twin is instantiated to perform dynamic simulation and deduction of the future network situation, generate a predictive network situation map, and generate local link control policies through a distributed consensus decision-making mechanism to achieve forward-looking optimization and routing of traffic on wide area network links.

Benefits of technology

It significantly enhances the service reliability and application experience quality of SD-WAN in dynamic and complex environments, improves the foresight and adaptability of link control, and enhances the overall operational efficiency of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940355A_ABST
    Figure CN121940355A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of software defined wide area networks, and provides an SD-WAN (Secure Digital Wide Area Network) link control method and system based on global situation awareness, which are used for solving the problems of insufficient perspectiveness and limited accuracy caused by link tuning depending on historical and real-time states in the existing SD-WAN link control. According to the method, a cloud control platform fuses external environment data, security intelligence data and other multi-dimensional data, a network digital twinborn body is constructed, dynamic simulation deduction is carried out, and a predictive whole network situation map is generated and issued to an edge device; the edge device extracts related path information from the predictive whole network situation map, generates a local flow path selection intention, and jointly determines and executes a local link control strategy by performing distributed consensus negotiation with the peer-to-peer device, thereby realizing optimal distribution and routing of flow on a wide area network link. And the path selection foresight and the adaptive tuning capability of the SD-WAN in a dynamic complex network environment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of software-defined networking and distributed intelligent control technology, specifically to an SD-WAN link control method and system based on global situational awareness. Background Technology

[0002] Software-defined wide area networks (SD-WAN) enhance the reliability and user experience of enterprise WAN connections by enabling intelligent routing and load balancing across various network links (such as MPLS, the Internet, and 4G / 5G) through centralized control and policy management. As enterprises undergo deeper digital transformation, their reliance on cloud services, global connectivity, and real-time interactive applications (such as video conferencing and SaaS access) continues to grow, making the continuity and quality of network services crucial. Current mainstream SD-WAN link control methods primarily rely on monitoring and analyzing historical and real-time link status data (such as latency, packet loss rate, and bandwidth utilization) to adjust paths and optimize policies accordingly.

[0003] However, the network environment is highly dynamic and complex, affected not only by internal traffic changes but also by various external factors, such as regional network congestion, sudden security threats, and physical infrastructure risks caused by natural disasters. Existing reactive optimization mechanisms based on current or near-term conditions lack the ability to predict future network conditions and fail to effectively integrate critical information such as external environment and security intelligence. Therefore, when facing complex and dynamic environments, they exhibit insufficient foresight and limited decision-making accuracy, making it difficult to proactively avoid and optimize for potential service quality degradation or security risks before they occur. This leads to potential threats to the quality of service (QoS) and business continuity of critical applications, ultimately impacting the overall efficiency and stability of enterprise operations.

[0004] Therefore, how to integrate multi-source data and perform SD-WAN link control to predict future network conditions, so as to improve the foresight of path selection and the accuracy of decision-making, has become an urgent technical problem to be solved. Summary of the Invention

[0005] To address the aforementioned technical issues, this invention provides an SD-WAN link control method and system based on global situational awareness. This method is executed collaboratively by a cloud control platform and edge devices. Through proactive optimization and routing tuning of traffic on the wide area network link, it achieves proactive and adaptive intelligent link control.

[0006] To address the aforementioned technical problems, this invention provides the following technical solution: an SD-WAN link control method based on full-domain situational awareness, executed collaboratively by a cloud control platform and edge devices. The method includes: the cloud control platform performing the following steps: acquiring external environmental data and security intelligence data affecting network connectivity, and acquiring local application data and link status data reported by the edge devices; loading a full-network situational data model with network status prediction capabilities; based on the full-network situational data model, fusing the external environmental data, security intelligence data, local application data, and link status data to characterize the current network status, and instantiating a network digital twin; acquiring future network variables as prediction input parameters, and performing dynamic simulation and prediction using the network digital twin in conjunction with the future network variables to generate a predictive full-network situational map for future time windows. The predictive network situation map includes predictive quality levels and security risk scores for different paths. The predictive network situation map and corresponding preset application service level targets are distributed to relevant edge devices. The edge devices perform the following steps: receiving the predictive network situation map and the preset application service level targets; extracting the predictive quality levels and security risk scores affecting corresponding paths of local traffic from the predictive network situation map based on the preset application service level targets; generating local traffic path selection intentions based on the extracted predictive quality levels and security risk scores, and exchanging these intentions with associated peer edge devices, jointly negotiating and generating local link control policies through a distributed consensus decision-making mechanism; and executing the local link control policies to adjust the distribution and routing of local traffic on wide area network links.

[0007] This invention also provides an SD-WAN link control system based on full-domain situational awareness, executed collaboratively by a cloud control platform and edge devices. The system includes: the cloud control platform comprising: a first acquisition module, used to acquire external environmental data and security intelligence data affecting network connectivity, and to acquire local application data and link status data reported by the edge devices; an instantiation module, used to load a full-network situational data model with network status prediction capabilities, and based on the full-network situational data model, to fuse the external environmental data, security intelligence data, local application data, and link status data to characterize the current network status, and to instantiate a network digital twin; and a first generation module, used to acquire future network variables as prediction input parameters, and to perform dynamic simulation and prediction using the network digital twin in conjunction with the future network variables to generate a predictive full-network situational map for future time windows, the predictive full-network situational map including predictions for different paths. The system includes: a predictive quality level and a security risk score; a first distribution module for distributing the predictive network situation map and the corresponding preset application service level target to relevant edge devices; the edge devices comprising: a first receiving module for receiving the predictive network situation map and the preset application service level target; a first extraction module for extracting the predictive quality level and security risk score affecting the corresponding path of local traffic from the predictive network situation map according to the preset application service level target; a second generation module for generating a local traffic path selection intention based on the extracted predictive quality level and security risk score, and exchanging the local traffic path selection intention with associated peer edge devices, and jointly negotiating to generate a local link control policy through a distributed consensus decision-making mechanism; and a first execution module for executing the local link control policy to adjust the distribution and routing of local traffic on the wide area network link.

[0008] The beneficial effects of this invention are as follows: By constructing a cloud-edge collaborative control mechanism based on full-domain situational awareness and predictive simulation, the method forms an SD-WAN link collaborative control system that ranges from full-network situational awareness and dynamic simulation to distributed decision-making and execution. This enables the network to adaptively optimize the distribution and routing of traffic on multiple WAN links. Through the forward-looking optimization and routing tuning of traffic on WAN links, forward-looking and adaptive intelligent SD-WAN link control is achieved, significantly enhancing the service reliability, application experience quality, and overall operational efficiency of SD-WAN in dynamic and complex environments. Attached Figure Description

[0009] Figure 1 A flowchart illustrating the SD-WAN link control method based on global situational awareness provided in an embodiment of the present invention; Figure 2This is a schematic diagram of the first sub-process of the SD-WAN link control method based on global situational awareness provided in an embodiment of the present invention; Figure 3 This is a schematic block diagram of an SD-WAN link control system based on global situational awareness, provided in an embodiment of the present invention. Detailed Implementation

[0010] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0011] The SD-WAN link control method and system based on global situational awareness provided in this invention is a network intelligent control engine that operates collaboratively by a cloud control platform and distributed edge devices. It can drive network communication applications including, but not limited to, the following: First, in multinational enterprise cloud-network convergence scenarios, through predictive global network situational mapping and distributed consensus decision-making, it enables intelligent, secure, and high-quality routing of critical application traffic (such as video conferencing, financial transactions, and SaaS access) between data centers in multiple locations and public clouds, ensuring global business continuity. Second, in large branch office interconnection scenarios, through simulation and deduction integrating external environment and security intelligence, it enables proactive risk avoidance and performance optimization of paths, improving overall network resilience and reducing operational complexity.

[0012] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings.

[0013] Example 1, please refer to Figure 1 , Figure 1 This is a flowchart illustrating the SD-WAN link control method based on global situational awareness provided in an embodiment of the present invention. Figure 1 As shown, in this embodiment, the method is executed collaboratively by the cloud control platform and the edge device, and the method includes, but is not limited to, the following steps S11-S18: The cloud control platform performs the following steps: S11: Obtain external environmental data and security intelligence data that affect network connectivity, and obtain local application data and link status data reported by the edge device.

[0014] External environment data: This refers to data that affects network connectivity performance and is not related to the network itself, including but not limited to: weather data (such as rainfall and wind speed), natural disaster warnings, information on major regional events (such as sporting events and large conferences), and statutory holidays and working hours in different regions. Security intelligence data: This refers to external information reflecting the network threat landscape, including but not limited to: lists of malicious IP addresses, known vulnerability (CVE) information, network attack activity indicators for relevant regions, and characteristic descriptions of new attack patterns obtained from cybersecurity companies, Computer Emergency Response Teams (CERTs), or open-source threat intelligence platforms.

[0015] The implementation is as follows: The cloud control platform collects two types of data in parallel: 1) external environment and security intelligence data streams are obtained through API subscription / polling; 2) local application data (such as application identifiers, traffic characteristics, etc.) and link status data (such as link latency, packet loss rate, and bandwidth) reported by each edge device according to policies are received through service interfaces. Subsequently, the cloud control platform performs preprocessing on the multi-source data, including timestamp alignment, validity verification, and anomaly filtering. The aligned data is then preliminarily fused and feature extracted according to predefined association rules to form multi-dimensional fused data features, providing an input basis for the subsequent instantiation of the network digital twin. The specific implementation of data collection, preprocessing, and feature extraction can adopt technologies known in the field.

[0016] For example, in a global enterprise network scenario, suppose an edge device located in branch office A reports an increase in traffic to its "video conferencing" application (local application data), while simultaneously monitoring that the latency of its primary internet link (link status data) increases from 30ms to 80ms. Furthermore, the cloud control platform obtains a DDoS attack warning (security intelligence data) from a security intelligence source targeting a cloud service provider in the region where branch office A is located (which can be referred to as region A), and learns from a public data source that region A is experiencing thunderstorms (external environment data). The purpose of step S11 is to aggregate this multi-dimensional information data from different sources, representing risks and states at different levels, to the cloud control platform, forming the multi-dimensional, comprehensive, and multi-source data necessary for network situation analysis and prediction.

[0017] S12: Load the network-wide situational data model with network status projection capabilities. Based on the network-wide situational data model, integrate the external environment data, security intelligence data, local application data, and link status data to characterize the current network status and instantiate the network digital twin.

[0018] The network situation data model represents a pre-trained deep learning model used to characterize and predict network states. Its essence is a parameterized function mapping relationship. It is trained with historical data to learn the complex nonlinear correlation and dynamic evolution law between the internal state of the network (link quality, application traffic) and external factors (environmental events, security threats). It has the ability to extrapolate (simulate) the future state of a given input state.

[0019] Network digital twin: Based on the network situational data model, at a corresponding time (t), after injecting multi-source data collected and fused at that time (i.e., the output of S11), a dynamic and virtual network operation instance is generated. It is a real-time mapping and simulation copy of the physical network in the digital space. It not only reflects the current network state, but also has the potential to simulate future evolution possibilities due to the extrapolation capability of the network situational data model on which it is based.

[0020] The network-wide situational awareness model is a universal and reusable "engine" or "rule base." A network digital twin is a spatiotemporally unique running instance generated at a specific point in time after the network-wide situational awareness model is "activated" with data representing the current network state that integrates external environment data, security intelligence data, local application data, and link status data. In other words, the network-wide situational awareness model and the current network state, which integrates external environment data, security intelligence data, local application data, and link status data, jointly determine the specific network digital twin. The network-wide situational awareness model is the foundation for the generation and capability source of the network digital twin.

[0021] The implementation is as follows: The cloud control platform loads a pre-built network-wide situational awareness model. This model can be constructed using a hybrid architecture based on Graph Neural Networks (GNNs) and Temporal Convolutional Networks (TCNs) to encode network topology relationships and temporal dependencies of node / link states, respectively. Subsequently, the multi-source data acquired in S11 is converted into feature vectors recognizable by the network-wide situational awareness model (e.g., external events are encoded as features applied to specific network elements). These features are then weighted and fused using the attention mechanism within the model. Based on the fused features, the model performs forward computation, outputting predicted vectors of the current state of each element in the network and their relationships. This instantiates a network digital twin representing the current comprehensive network state, typically represented as a dynamic graph data structure with predictive attributes. Thus, by fusing topology, temporal, and external event information, a causal basis for understanding disturbance propagation is provided for subsequent simulations, thereby improving prediction accuracy.

[0022] S13: Obtain future network variables as input parameters for simulation, and perform dynamic simulation by combining the network digital twin with the future network variables to generate a predictive network situation map for future time windows. The predictive network situation map includes predictive quality levels and security risk scores for different paths.

[0023] Future network variables: represent a set of input parameters used to drive the network digital twin to simulate future states. These represent events, conditions, or policy changes that may or are planned to occur within the upcoming time window, including but not limited to: preset periodic business plans (such as the next traffic peak), known network change plans (such as link upgrade and maintenance windows), and predictive information subscribed from external services (such as weather forecasts and regional network load forecast reports).

[0024] Predictive Network Situation Map: This represents a structured dataset generated through dynamic simulation and is a digital and graphical predictive description of the overall network situation at a future time. Essentially, it is an enhanced network topology data map with a time dimension. Predictive quality level and security risk score are quantitative evaluation indicators attached to each path (edge) in the predictive network situation map. The predictive quality level is a classification or numerical score calculated based on multiple performance indicators (such as predicted latency, packet loss rate, and available bandwidth) output from the simulation, used to characterize the expected performance level (e.g., "Excellent", "Good", "Average", "Congested") of the corresponding path serving the corresponding type of traffic at a future time. The security risk score is a numerical value calculated based on security threat propagation models, historical attack pattern matching, and path exposure surface analysis during the simulation process, used to quantify the potential likelihood of the corresponding path suffering security breaches or becoming an attack springboard at a future time.

[0025] The implementation is as follows: First, the cloud control platform acquires future network variables through a configurable variable injection interface, supporting reading from static configuration files, management API calls, or external data stream subscriptions. For example, the system can preload the schedules of core business applications (such as "global video conferencing") planned for the next 24 hours as business variables, and obtain the rainfall probability forecasts for major regions for the next 6 hours from the weather service as environmental variables. Second, a dynamic simulation is initiated, starting with the network digital twin instantiated in S12. The dynamic simulation process is executed by a simulation engine that encapsulates multi-step iterative calculation logic. The core of the simulation engine is a recurrent neural network (RNN) unit or a physics-inspired state transition equation, the parameters of which are internalized in the model of the network digital twin. In the actual simulation, the simulation engine injects the acquired future network variables into the network digital twin at the corresponding time steps. In order to solve the problem that "forward-looking simulation needs to handle time-series dependencies and external disturbances", the network digital twin adopts a sequence prediction framework with gated cyclic units (GRU). At each simulation time step (e.g., every 5 minutes in the future is one step), the GRU unit calculates the transition probability and possible value range of the network state (performance indicators of each link, security risk indicators) based on the current state of the network digital twin, the output of the previous step, and the future network variables injected in the current step (e.g., "At the 30th minute, the Asia-Pacific video conference begins"). This process is repeated until the entire preset future time window (e.g., the next hour) is covered. Third, after the dynamic simulation is completed, the simulation engine aggregates and analyzes the simulation outputs of all time steps. To generate an intuitive and usable predictive network situation map, it statistically summarizes the performance fluctuations and security event probabilities of each path within the entire time window. For example, it calculates the average predicted latency, maximum packet loss rate, and security threat exposure duration. Then, through a predefined mapping function, these statistical values ​​are converted into predictive quality levels (e.g., latency <50ms and no packet loss is mapped to "Level A") and security risk scores (e.g., high threat exposure duration >30% is mapped to "High Risk"). Finally, the predictive quality level and security risk score are used as attributes and structured together with network topology and time labels to form a predictive network situation map.

[0026] Step S13, by injecting future network variables into the network digital twin and performing time-series-based dynamic simulation, enables proactive and quantitative prediction of the future state of the network. This solves the problem that "relying solely on responsive tuning based on historical and real-time states makes it difficult to anticipate future quality degradation or security risks." It enables the entire system to shift from post-event remediation to pre-event prevention, fundamentally improving the decision-making accuracy and service reliability of SD-WAN link control.

[0027] S14: Distribute the predictive network situation map and the corresponding preset application service level target to the relevant edge devices.

[0028] Predefined application service level targets: These represent quantifiable network performance requirements predefined for the corresponding application or service traffic type. They serve as the basis for link selection and control strategy decisions and are data structures containing multiple threshold parameters. For example, for a "video conferencing" application, the service level target can be defined as "end-to-end latency ≤ 100 milliseconds, packet loss rate ≤ 0.5%, jitter ≤ 20 milliseconds"; for a "file backup" application, the target can be defined as "available bandwidth ≥ 10Mbps". These targets are configured and managed on the cloud control platform based on application characteristics and service priorities.

[0029] The process is as follows: The cloud control platform determines the edge devices and their corresponding application service level (ASL) targets related to the predictive network situation map based on the network topology. For efficient distribution, the cloud control platform performs data slicing and compression encoding on the predictive network situation map. For example, it extracts sub-maps related to each device based on network partitions and uses differential encoding on time-series data to reduce communication overhead. Simultaneously, the cloud control platform determines the set of ASL targets to be distributed (usually pre-stored or modified preset ASL targets). Finally, the processed map subset and target parameters are pushed to the relevant edge devices through the data channel.

[0030] The edge device performs the following steps: S15: Receive the predictive network situation map and the preset application service level target; S16: Based on the preset application service level target, extract the predictive quality level and security risk score of the corresponding path affecting local traffic from the predictive network situation map.

[0031] The implementation is as follows: Edge devices employ a two-layer filtering mechanism to extract predictive quality levels and security risk scores from the predictive network situation map. The first layer, based on local network configuration and topology knowledge, filters out paths originating from or traversing the edge device. The second layer, based on preset application service level targets, uses a target matching function to evaluate the predictive performance of each path at various future time points. Through sliding window and early pruning strategies, paths that meet the requirements or have acceptable deviations within the target time window are efficiently retained. Finally, the filtered paths are determined to be relevant paths affecting local traffic, and their corresponding predictive quality levels and security risk scores are extracted.

[0032] S17: Based on the extracted predictive quality level and the security risk score, generate a local traffic path selection intention, and exchange the local traffic path selection intention with the associated peer edge device, and jointly negotiate to generate a local link control policy through a distributed consensus decision-making mechanism.

[0033] Local traffic path selection intention: This refers to the edge device's preliminary preferred path selection intention for the corresponding application traffic or traffic category based on the future quality and security assessment of the relevant paths. It usually includes: target application / traffic identifier, a priority ranking list of one or more candidate paths, and quantitative basis for supporting the ranking (such as comprehensive score). For example, "Video conferencing traffic: preferred path B, alternative path C, reject path A".

[0034] Distributed consensus decision-making mechanism: It refers to the computational process and protocol in which a group of decision agents distributed on different edge devices reach a consensus on the allocation of public resources or policy coordination issues involving multiple edge devices by exchanging information, conducting multiple rounds of voting, negotiating or converging based on predetermined rules, without the mandatory command of a single central controller.

[0035] The implementation is as follows: Edge devices, based on extracted predictive quality levels and security risk scores, use a weighted scoring algorithm (e.g., overall score = w1 * quality score + w2 * (1 - risk score)) to calculate the overall intention score for each relevant path, generating a ranked local traffic path selection intention. Subsequently, the edge devices identify sets of peer edge devices and exchange path selection intentions. Then, a distributed consensus decision-making mechanism based on an improved negotiation protocol (e.g., a variant of Paxos) is initiated. Each edge device, through multiple rounds of "proposal-commitment-learning" interaction, integrates conflicting path selection intentions according to predetermined conflict resolution rules (e.g., business priority, load balancing) and introduced predictive quality priorities, ultimately forming a consistent local link control policy.

[0036] Step S17 addresses the issues of high controller computational pressure and high decision latency in traditional centralized SD-WAN, as well as the difficulty in achieving a global optimal solution in traditional distributed systems, by introducing local traffic path selection intention generation based on quantitative evaluation and distributed negotiation based on consensus protocol at the edge side. This transforms the global predictive network situation map into collaborative and adaptive network behavior, greatly enhancing the agility, robustness, and scalability of link control in dynamically changing environments.

[0037] S18: Execute the local link control policy to adjust the distribution and routing of local traffic on the WAN link.

[0038] The implementation is as follows: After the edge device reaches a consensus on the local link control policy through the distributed consensus decision-making mechanism, it executes the local link control policy and translates it into specific configuration actions to control the underlying network forwarding, thereby realizing the distribution and routing adjustment of local traffic on multiple WAN links.

[0039] This invention, through the construction of a cloud-edge collaborative control mechanism based on global situational awareness and predictive simulation, effectively addresses the problems of insufficient foresight and limited decision-making accuracy caused by the reliance on historical and real-time states for reactive optimization in existing SD-WAN link control. Specifically: First, by instantiating a network digital twin and combining it with future network variables for dynamic simulation and extrapolation, a full-network situational map is generated, achieving accurate predictive modeling of the future network state. This provides a forward-looking basis for link decisions and overcomes the shortcomings of traditional methods that cannot predict potential link quality degradation and security risks. Second, by having edge devices generate local traffic path selection intentions based on specific application needs, and then jointly negotiate with peer edge devices to generate local link control strategies, the collaborative integration of global prediction from the cloud and local decision-making is achieved, improving the adaptability and collaborative optimization capabilities of local traffic path selection. In summary, through the collaborative execution of the cloud control platform and edge devices, a collaborative control system for SD-WAN links is formed, encompassing network-wide situational awareness, dynamic simulation and deduction, and distributed decision-making and execution. This enables the network to adaptively optimize the distribution and routing of traffic across multiple WAN links. By proactively optimizing the distribution and routing of traffic across WAN links, forward-looking and adaptive intelligent SD-WAN link control is achieved, significantly enhancing the service reliability, application experience quality, and overall operational efficiency of SD-WAN in dynamic and complex environments.

[0040] In one embodiment, the future network variables include at least one of the following: predicted service traffic plans, natural disaster information from external early warning systems, network maintenance notices issued by operators, and predictive attack activity information issued by threat intelligence platforms; dynamic simulation and deduction are performed by combining the future network variables with the network digital twin, including: inputting the future network variables as disturbance parameters into the network digital twin, performing discrete event simulation in the virtual time domain based on the current network state reflected by the network-wide situational data model, and deducing the time-series change curves of each predicted indicator on different paths within the future time window.

[0041] The implementation is as follows: The cloud control platform preprocesses future network variables into perturbation parameters (e.g., converting network maintenance notices into simulation events that act on specific links at specific times and continuously adjust their bandwidth). Then, a discrete event simulation engine is launched with the network digital twin as the initial state. This engine iteratively executes: 1) retrieving the next perturbation event from the time-sorted event list; 2) advancing the simulation clock to the event's occurrence time; 3) executing the event—calling the state transition predictor of the network digital twin's underlying model based on the event type to update the state attributes of the affected network elements; 4) deriving the chain reaction caused by the state update based on the embedded lightweight traffic model (e.g., traffic redistribution based on the shortest path) and scheduling new "derived events" to be added to the event list. This loop continues until the entire future time window is covered. During the simulation, the temporal changes in the performance indicators of each path are recorded, ultimately generating a time-series curve for constructing a predictive overall network situational map. This method, through the integration of event-driven and lightweight physical models, achieves accurate simulation of the network's internal adaptive behavior while ensuring inference efficiency, thereby obtaining high-quality prediction results.

[0042] In this embodiment of the invention, by clearly defining the specific types of future network variables and adopting a deduction method based on discrete event simulation, the accuracy, reliability, and interpretability of predictive deduction are effectively enhanced, ultimately improving the forward-looking decision-making accuracy and risk avoidance capability of the entire SD-WAN link control system.

[0043] In one embodiment, the cloud control platform is pre-configured with a network vulnerability assessment model. This model is trained based on historical network fault data, historical performance degradation logs, and corresponding historical environmental event data. It is used to output the vulnerability coefficient of network links affected by environmental events, taking network topology features and the event type, geographical scope, and intensity index of the environmental event as input. The model also includes dynamic simulation and deduction using the network digital twin combined with future network variables. During the dynamic simulation and deduction process, the cloud control platform performs the following steps: acquiring external environmental data, which includes the event type, geographical scope, expected impact time window, and a function or sequence of the intensity index changing over time within the expected impact time window; performing spatiotemporal alignment and geocoding on the external environmental data, and mapping it to specific regions in the network topology to obtain the affected network corresponding to the environmental event. Regional topology characteristics; as the simulation progresses, the following loop is executed: determine whether the current virtual time falls within the expected impact time window of any of the external environmental data; if so, determine the real-time intensity index corresponding to the current virtual time based on the function or sequence of the intensity index changing over time; input the event type, geographical range, real-time intensity index, and topology characteristics of the affected network region of the environmental event falling within the time window into the network vulnerability assessment model to calculate the real-time vulnerability coefficient of the corresponding network link under the current virtual time; based on the real-time vulnerability coefficient, dynamically correct the baseline performance parameters of the corresponding network link in the network digital twin according to a preset mapping rule; continue the simulation based on the network digital twin with corrected parameters, and perform the next round of judgment and correction until the simulation ends, so that the generated predictive network situation map integrates the dynamic time-varying impact of the intensity of external environmental events.

[0044] Network vulnerability assessment model: This refers to a trained model used to assess the probability or severity of performance degradation of a given network link under the influence of environmental events of a certain type and intensity. Its training data consists of historically recorded network failures, performance drop events, and corresponding external environmental data (such as typhoon level, rainfall, earthquake intensity). The model learns the correlation between environmental event characteristics (type, range, intensity) and network characteristics (such as link medium, geographical span, redundancy) and the degree of performance degradation. Its output vulnerability coefficient is a scalar value that quantifies the "vulnerability" of the link under the current environmental conditions relative to its normal state.

[0045] Preset mapping rules: These represent a set of predefined mathematical formulas or lookup tables that convert real-time vulnerability coefficients (e.g., a value between 0 and 1, where 0 represents no impact and 1 represents extremely high vulnerability) into adjustments to specific link performance parameters (such as baseline latency and baseline packet loss rate) in the network digital twin. For example, a preset mapping rule could be: Corrected latency = Baseline latency * (1 + α * Vulnerability coefficient), where α is a preset amplification factor.

[0046] The implementation is as follows: The cloud control platform loads a pre-set network vulnerability assessment model (e.g., constructed using Gradient Boosting Decision Tree (GBDT) to handle the complex mapping between environmental events and network characteristics, and output vulnerability coefficients). In the dynamic simulation, the cloud control platform executes the following loop: 1) Geographically encodes external environmental data (such as typhoon paths) and overlays it with the network topology to determine affected links and their overlap, generating topological characteristics of the affected network area (e.g., "Link L1: Located within the typhoon's 7-level wind circle, overlap 80%"); 2) At each time step of the simulation, if within the event impact window, real-time intensity indicators are obtained by interpolation based on the event intensity change curve, and these, along with the event type, geographical scope, and topological characteristics of the affected links, are input into the network vulnerability assessment model to calculate the real-time vulnerability coefficients for each link; 3) Based on preset mapping rules, the baseline performance parameters (such as latency and bandwidth) of the corresponding links in the network digital twin are dynamically corrected using the real-time vulnerability coefficients; 4) The corrected digital twin is used to continue the simulation, and this loop is repeated until the simulation ends. This process achieves dynamic quantitative fusion of environmental impacts, improving the realism of the simulation and the accuracy of predictions.

[0047] This invention, through the integration of a network vulnerability assessment model and a dynamic parameter correction loop, achieves refined time-varying fusion simulation of the impact of the external environment. This significantly improves the accuracy and real-world fit of predictive simulations, thereby enhancing the predictive accuracy and early warning value of the predictive network situation map. It enables link control decisions to more proactively and accurately avoid network risks caused by external environments such as natural disasters, and strengthens the system's forward-looking protection capabilities in complex dynamic environments.

[0048] In one embodiment, generating a predictive network situation map for future time windows includes: calculating the quality index and risk index of each path on each time slice within the future time window based on the time-series change curve; generating a continuous index field in a three-dimensional space composed of network nodes and time dimension based on a spatiotemporal interpolation algorithm; and extracting and visualizing the quality level heatmap and security risk distribution map of the entire network paths at the corresponding future time from the index field to form a predictive network situation map for future time windows.

[0049] Quality Index: A scalar value comprehensively reflecting the overall performance level of a path within a given time slice. It is typically calculated by normalizing the values ​​of metrics such as latency, packet loss, and jitter within that time period and applying preset weights. A higher value indicates better predictive performance. Risk Index: A scalar value comprehensively reflecting the degree of security threat faced by a path within a given time slice. It is typically calculated based on parameters such as security risk score and threat exposure duration. A higher value indicates greater predicted risk. Index Field: Represented as a continuous scalar field distributed within a three-dimensional space consisting of a two-dimensional network topology space (node ​​locations as coordinates) and a one-dimensional time axis, the quality index or risk index is a mathematical model describing the continuous variation of index values ​​across network locations and time points.

[0050] Quality level heatmap and security risk distribution map: These are visual representations of the indicator field. On a two-dimensional network topology diagram (usually a node and link diagram), based on the index values ​​read from the indicator field at corresponding future times, different paths or regions are rendered using color gradients (e.g., from green to red to represent quality from good to bad, or risk from low to high). This creates an image that can intuitively and globally display the spatial distribution of network performance and security status at corresponding future times.

[0051] The implementation is as follows: First, based on the time-series change curves of each path output by the simulation, the cloud control platform iterates through all paths for each preset time slice within the future time window (e.g., every 5 minutes is a time slice) and performs the following calculations: 1) Quality index calculation: Extract the average predicted latency L_avg, maximum packet loss rate P_max, and other indicators of the path in the current time slice. Through a predefined normalization function (e.g., f(x) = 1 / (1 + x / k)), map each indicator to the [0,1] interval. Then, according to the preset weight w of the application type (e.g., for real-time applications, latency has a higher weight), calculate the weighted sum as the quality index Q = w1*f(L_avg) + w2*(1-f(P_max)). 2) Risk index calculation: Extract the average security risk score R_avg and threat exposure duration ratio T_exp of the path in the current time slice. Similarly, perform normalization and weighted calculation to obtain the risk index Risk = v1*f(R_avg) + v2*f(T_exp). Secondly, to address the problem of "generating a continuous, smooth, and comprehensive global situational view that fills in unmonitored areas from discrete path-time data," this invention employs a spatiotemporal interpolation algorithm based on radial basis functions (RBF) to construct an index field. The node positions of all paths on each time slice (taking path endpoints or key intermediate nodes) and their corresponding time points are used as known data points. The calculated quality index or risk index is used as the field value for that data point. The RBF interpolation algorithm defines an influence function centered on each data point and determines the weights of each central function by solving a system of linear equations. This constructs a smooth, continuous index field function F(x, y, t) that reflects the spatial and temporal correlation between data points within the entire three-dimensional (x, y, t) space. This effectively handles the non-uniformity of network topology and allows for reasonable extrapolation of trends in the short term. Third, after the indicator field is constructed, for any future time t_future, the system traverses all key locations (x, y) in the network topology and calculates the field value F(x, y, t_future) at that location at that time, thus obtaining the predicted quality index or risk index. Subsequently, according to the preset mapping rules (e.g., index values ​​in [0.8, 1.0] are mapped to green "excellent"), the index values ​​are converted into corresponding color and level labels. Finally, the paths or regions with color and level information are rendered on the network topology base map, forming a quality level heatmap and a security risk distribution map, respectively. This series of maps together constitutes a structured predictive network situation map, which not only contains raw numerical data but also provides intuitive visual insights.

[0052] In this embodiment of the invention, by processing and visualizing simulation data, discrete predictions are transformed into a continuous and intuitive global situation map, which improves the information density and operability of the map, provides a more efficient basis for edge device decision-making and centralized monitoring, and enhances the system's overall perception and decision-making capabilities in the face of future uncertainties.

[0053] In one embodiment, please refer to Figure 2 , Figure 2 This is a schematic diagram of the first sub-process of the SD-WAN link control method based on global situational awareness provided in an embodiment of the present invention. Figure 2 As shown, in this embodiment, based on the extracted predictive quality level and security risk score, a local traffic path selection intention is generated, including: S21: For each application data stream to be transmitted locally with a preset application service level target, according to the preset application service level target, all paths that meet its connectivity requirements are selected from the paths covered by the predictive network situation map as the candidate path set for the application data stream; S22: Obtain the predictive quality level and security risk score corresponding to each candidate path in the candidate path set; S23: According to the preset weight corresponding to the application type of the application data stream, the predictive quality level and the security risk score are weighted and fused to calculate the comprehensive priority value of each candidate path; S24: The candidate path with the highest comprehensive priority value is determined as the initial intention selection path for the application data stream; S25: The initial intention selection path and its comprehensive priority value are encapsulated as the local traffic path selection intention for the application data stream.

[0054] The implementation is as follows: First (S21), the edge device performs path pre-screening for each application data stream to be transmitted locally (e.g., a VoIP call stream, a file transfer stream). Based on the preset application service level target of the application data stream (e.g., the preset application service level target implicitly includes the destination IP address range), it performs connectivity verification from all path sets described in the predictive network situation map. The verification process is completed by querying the local routing table, checking the tunnel endpoint configuration, and comparing the protocol support list. All paths that pass the verification and meet the connectivity requirements are included in the candidate path set of the application data stream, thereby excluding unreachable or incompatible paths at the network layer, narrowing the scope of subsequent fine-grained evaluation, and improving processing efficiency. Second (S22), the edge device queries the locally cached predictive network situation map data to query the predictive quality level (e.g., "A" or "B" level) and security risk score (e.g., numerical score) of each path in the candidate path set at the current and future relevant time points from the locally cached predictive network situation map data. Next (S23), a weighted fusion method based on an application type feature library and a multi-objective utility function is used to calculate the comprehensive priority value of each candidate path. The edge device reads the preset weight corresponding to the application type (such as "real-time video", "batch backup", "critical transaction") from the pre-configured feature library according to the application type of the current application data stream. For example, the weight configuration for the "real-time video" application is: quality weight W_q = 0.8, security weight W_s = 0.2; while the configuration for "confidential file transfer" may be W_q = 0.3, W_s = 0.7. Then, the predictive quality level and security risk score are mapped to a unified numerical range (e.g., levels "A / B / C / D" are mapped to scores of 100 / 80 / 60 / 40; risk scores of 0-100 are mapped to negative risk scores of 100 / 60 / 20 / 0). The formula for calculating the comprehensive priority value is: P = W_q * Q_score + W_s * S_score, where Q_score is the quality mapping score, S_score is the security mapping score, and W_q and W_s are the corresponding weights. This utility-based weighted fusion enables path decisions to accurately match different application needs and achieve personalized path optimization. Subsequently (S24), the edge device sorts the comprehensive priority values ​​calculated for all candidate paths and determines the paths with the highest comprehensive priority values ​​as the initial intended selection paths for the application data flow. Finally (S25), the edge device encapsulates the identifier of the initial intended path selection (such as path ID), its corresponding comprehensive priority value, and the identifier of the application data stream into a data object, which serves as the local traffic path selection intention for the application data stream.

[0055] In this embodiment of the invention, by designing a decision-making process that integrates connectivity filtering and quantitative trade-offs for each application data flow, edge devices can make automated and precise personalized decisions when generating local traffic path selection intentions, taking into account future network conditions and specific application requirements. This improves the path optimization accuracy of the SD-WAN system under complex multi-service mixed loads.

[0056] In one embodiment, the local traffic path selection intention is exchanged with associated peer edge devices, and a local link control policy is jointly negotiated and generated through a distributed consensus decision-making mechanism. This includes: each edge device sending its local traffic path selection intention to its connected peer edge devices in the network topology and receiving path selection intentions from the peer edge devices; each edge device identifying disputed paths where the initial intention paths overlap, based on its own and all received path selection intentions; each edge device using the disputed paths as resources to be allocated, and using the initial intention paths, comprehensive priority values, and corresponding preset application service level targets contained in each path selection intention as input parameters, constructing a distributed path allocation optimization model; and solving the distributed path allocation optimization model by iteratively executing the following negotiation steps: each edge device, based on the current round's temporary path allocation scheme and the predictive network-wide situation map, calculates the expected experience quality index of all its affected application data flows; if If the expected experience quality index does not meet its preset application service level target, the edge device, acting as the proposing edge device, generates an adjustment proposal for the corresponding disputed path and sends the adjustment proposal to the receiving edge device currently assigned to use the disputed path. The receiving edge device receives the adjustment proposal, assesses the impact of accepting the adjustment proposal on its own application data flow, and accordingly provides feedback of agreement or rejection to the proposing edge device. The proposing edge device updates the temporary path allocation scheme based on the adjustment proposal and the corresponding feedback. The above negotiation steps are repeated until no new adjustment proposals are generated within a preset number of consecutive rounds, or the total number of iterations reaches a preset upper limit. The temporary path allocation scheme determined at this time is used as the path allocation consensus scheme. Based on the path allocation consensus scheme, the proposing edge device binds the disputed path assigned to it with the corresponding application data flow, and, combined with the undisputed initial intention path selection, generates a local link control policy containing specific routing rules.

[0057] Distributed path allocation optimization model: In this embodiment of the invention, a technical framework is established to resolve the allocation conflict of multiple edge devices for disputed paths in a central node-less environment. It includes a formal description of the optimization objective (such as maximizing total utility) and constraints (such as path capacity and service quality), as well as a collaborative mechanism for distributed solution through "proposal-feedback-update" iteration among edge devices.

[0058] Temporary path allocation scheme: This refers to the provisional allocation record of disputed path usage rights maintained locally by the edge device during each round of negotiation iterations.

[0059] Expected experience quality indicators: These represent the performance indicators (such as latency and packet loss rate) that edge devices can achieve on the corresponding paths based on the predictive network situation map. They are used to determine whether the temporary path allocation scheme meets the preset application service level target.

[0060] The implementation is as follows: After exchanging local traffic path selection intentions and identifying disputed paths, edge devices construct a distributed path allocation optimization model. This model does not perform centralized solutions but rather approximates the optimal solution through the following iterative negotiation steps: First, each edge device, based on its current temporary path allocation scheme (the initial scheme can be random allocation or a simple ranking based on comprehensive priority values), uses a predictive network situational map to calculate the expected quality of experience (QI) index for each application data stream on the allocated path (e.g., if a video conferencing stream is allocated to a disputed path P in the current scheme, combined with the predicted quality level "B" of P in the predictive network situational map, the expected latency is calculated to be 85ms). Then, it checks whether the expected QI index meets its preset application service level target (e.g., video conferencing requires latency ≤100ms). For applications that do not meet their preset application service level target, the edge device acts as the proposing edge device and generates an adjustment proposal for that application. The adjustment proposal typically requests that a better disputed path (e.g., a path with quality level "A") currently allocated to another edge device be reassigned to the reference of this edge device. When generating an adjustment proposal, the edge device prioritizes the path that maximizes its expected experience while minimizing global disruption, and sends the proposal to the receiving edge device currently using that path. Secondly, upon receiving the proposal, the receiving edge device simulates and evaluates the impact on its own application if it accepts the proposal (i.e., abandons the controversial path). It recalculates its expected experience quality index on the new alternative path (assigning a temporary solution based on its current path) to determine if it still meets the corresponding preset application service level goals. To encourage a globally better solution, the receiving edge device can adopt a decision rule based on "social welfare increment": it not only considers whether it suffers losses but also calculates the net value between the improvement gained by the proposing edge device's application and its potential losses after accepting the proposal. If the net value (total social utility increment) is positive, or its own goals are still met and the net value is non-negative, it tends to agree; otherwise, it rejects. Feedback on agreement or rejection is sent back to the proposing edge device. Thirdly, upon receiving feedback from the receiving edge device, the proposing edge device executes specific update operations based on the feedback. If the feedback is "agree", the proposing edge device performs an atomic state transition in its locally maintained temporary path allocation scheme data structure. Specifically, the "current user" field of the disputed path requested in the proposal is changed from the identifier of the receiving edge device to the identifier of this edge device. At the same time, a path that this edge device originally planned to use (usually a poor one) is released or marked as available. This update operation is implemented by manipulating local data structures (such as hash tables or priority queues) to ensure consistent changes in the scheme state.If the feedback is "rejection," the proposing edge device records the rejection locally and may adjust its subsequent adjustment proposal strategy based on the reason for rejection (e.g., the receiving edge device also relies on the disputed path to meet its key objectives). For example, it may reduce the priority of the disputed path or try other paths in the next round of negotiation. Fourth, all edge devices execute the above steps in parallel. Each round of exchanging and updating all possible adjustment proposals is called an iteration. To prevent circular negotiations, a "concession counter" and a "tacit list" mechanism are introduced to record and avoid repeatedly proposing the same adjustment proposal that has been rejected multiple times. When no new adjustment proposals are generated for several consecutive rounds (preset rounds), or when the total number of iterations reaches the upper limit, the negotiation stops. At this point, the temporary path allocation schemes held by each edge device have reached a consensus, which becomes the path allocation consensus scheme. This mechanism, guided by the exchange of local interests and global utility, can eventually converge to a stable and generally better allocation state. Finally, it is proposed that edge devices (i.e., all edge devices that participated in the negotiation) bind the disputed paths to the corresponding application data streams according to the final path allocation consensus scheme, and directly adopt the non-disputed paths without competition (whose initial intended paths do not overlap) and convert them into specific routing rules (such as policy routing and SD-WAN tunnel selection rules) to generate the final local link control policy.

[0061] In this embodiment of the invention, through the aforementioned distributed negotiation mechanism, each edge device can efficiently and fairly resolve path contention and achieve a near-globally optimal traffic scheduling scheme by relying only on local and limited neighborhood information, thereby significantly improving network resource utilization efficiency and service experience.

[0062] In one embodiment, the distributed consensus decision-making mechanism is based on the principle of global optimization of application utility. Specifically, each edge device obtains a corresponding preset multi-dimensional utility function for each application data stream with a preset application service level target. In the step of generating an adjustment proposal for a corresponding disputed path, the proposing edge device calculates the change in the overall utility value of its corresponding application data stream, ΔU_self, if the adjustment proposal is accepted, and includes the change ΔU_self in the adjustment proposal and sends it to the receiving edge device. When the receiving edge device receives the adjustment proposal and evaluates the impact of accepting the adjustment proposal on its own application data stream, if the receiving edge device simultaneously receives multiple adjustment proposals for the same disputed path, it performs the following steps: For each adjustment proposal, it calculates the change in the overall utility value of its corresponding application data stream, ΔU_peer, caused by accepting the adjustment proposal; it broadcasts a list containing each adjustment proposal and its corresponding change ΔU_peer to all proposing edge devices; each proposing edge device calculates the total utility improvement value ΔU_total = ΔU_self + ... ΔU_peer; Each proposing edge device reaches a consensus on the adjustment proposal with the highest total utility improvement value ΔU_total through a round of fast voting or weight declaration, and uses it as the path allocation consensus proposal; The proposing edge device and the receiving edge device of the path allocation consensus proposal perform path allocation updates according to the proposal, and other proposing edge devices terminate their adjustment proposals.

[0063] Predefined multi-dimensional utility function: This function is predefined for each type of application data stream and maps multiple dimensions of indicators such as network transmission quality and security to a single comprehensive utility value. This function is usually formally represented as U = f(indicator 1, indicator 2, ...), where indicators include, but are not limited to, predicted end-to-end latency, packet loss rate, security risk score, etc. The parameters and form of the function are preset according to the application type. For example, the utility function of real-time video may be sensitive to latency and exhibit the characteristic of a sharp drop in utility after the latency exceeds a threshold. This function is used to quantify the effect of a specific path allocation scheme on a certain application.

[0064] The implementation is as follows: First, during the negotiation preparation phase, each edge device loads a pre-defined multi-dimensional utility function corresponding to its application type from its local configuration library for each application data stream it manages. This pre-defined multi-dimensional utility function exists in the form of executable code (such as Python functions) or parameterized templates (such as logarithmic / exponential functions with coefficients). When the proposing edge device (denoted as Device A) generates an adjustment proposal for the disputed path P, it calculates the utility increment. Device A simulates two scenarios: Scenario 1 (Current State): Its application data stream App1 uses the path allocated by the current temporary scheme (which may not be P). Scenario 2 (Proposal State): App1 obtains the right to use path P. For each scenario, Device A calculates the key performance indicators (KPIs) that App1 can achieve in that scenario based on the predictive quality level and security risk score of the path in the predictive network situation map. Then, these KPIs are substituted into App1's preset multi-dimensional utility function to calculate the utility values ​​U_current and U_proposed, respectively. The utility change ΔU_self = U_proposed - U_current, where ΔU_self is a quantitative representation of the expected benefit Device A gains from the adjustment proposal. Device A sends ΔU_self, along with other information from the adjustment proposal (such as the requested path and application identifier), to the receiving edge device (denoted as Device B) currently holding path P. Secondly, when device B simultaneously receives adjustment proposals for path P from multiple proposing edge devices (such as device A, device C, and device D), it no longer performs bilateral evaluations one by one, but instead initiates a parallel decision-making process: 1) For each adjustment proposal, device B simulates the impact on its application if it accepts the proposal (i.e., abandons path P), and calculates the utility change of its application before and after the adjustment proposal using the predicted information of these alternative paths, obtaining its own utility change ΔU_peer (this value is usually negative or zero, representing a loss). Thirdly, device B encapsulates all collected adjustment proposals and their corresponding ΔU_peer values ​​into a list and sends it to all relevant proposing edge devices (A, C, and D) via multicast or broadcast. Fourthly, after receiving the list, each proposing edge device (such as device A) can obtain its own utility change ΔU_self (known to itself) and the utility change ΔU_peer of the receiving edge device (obtained from the list) for each proposal in the list (including its own proposal). Then, it calculates the total utility improvement value ΔU_total = ΔU_self + ΔU_peer of the proposed adjustment, which represents the overall utility increase of the proposed adjustment for both parties involved (the proposing edge device and the receiving edge device). In order to reach a consensus quickly, the proposing edge devices then conduct a round of "fast voting or weight declaration".For example, each proposing edge device broadcasts the adjustment proposal ID it considers to have the highest ΔU_total. Since all edge devices perform calculations based on the same list and calculation rules, they will calculate the same ΔU_total ranking result in the absence of transmission errors. Therefore, they can quickly reach a consensus on the adjustment proposal with the highest ΔU_total and determine it as the path allocation consensus proposal. Thus, rapid comparison and optimization of global utility are achieved using local information. Fifth, the proposing edge device from which the path allocation consensus proposal originated, along with the receiving edge device, updates the temporary path selection scheme according to the path allocation consensus proposal. Other proposing edge devices terminate their current adjustment proposals for path P, avoiding subsequent invalid negotiation rounds.

[0065] This invention improves the decision quality and convergence speed of distributed negotiation by introducing a utility function-based quantitative calculation and a parallel decision-making mechanism for multiple adjustment proposals. This ensures that high-quality network resources are preferentially allocated to the application with the highest overall utility, thereby achieving near-globally optimal traffic scheduling and further enhancing the overall performance and resource utilization efficiency of the SD-WAN system.

[0066] In one embodiment, the network-wide situational awareness data model is constructed through the following process: acquiring historical external environment data, security intelligence data, local application data, and link status data, and aligning and associating them according to a unified timestamp and network node identifier; extracting multi-dimensional temporal feature vectors for each network node at each historical moment; based on the network topology, constructing a basic graph structure with the network nodes as vertices and links as edges, and using the multi-dimensional temporal feature vectors as dynamic attributes of the corresponding vertices and edges to form a historical spatiotemporal heterogeneous graph data sequence; defining a graph neural network model, which includes a situational graph encoder and a state transition predictor; the situational graph encoder is used to encode a snapshot of the historical spatiotemporal heterogeneous graph data sequence at any historical moment into a situational graph embedding vector representing the overall network situation at the corresponding historical moment; the state transition predictor uses the situational graph embedding vector from the previous historical moment... The input vector and its corresponding historical and future network variables are used as inputs to predict the situational graph embedding vector at the next historical moment. The historical spatiotemporal heterogeneous graph data sequence and its corresponding historical and future network variables are used as training samples to supervise the training of the graph neural network model, thereby optimizing the parameters of the situational graph encoder and the state transition predictor. This enables the graph neural network model to learn the dynamic evolution of the network situation under the combined influence of multidimensional data and future network variables. The trained graph neural network model serves as a full-network situational data model with network state deduction capabilities. The situational graph embedding vector constitutes the internal representation of the network state within the full-network situational data model. The state transition predictor endows the full-network situational data model with the ability to deduce the situational graph embedding vector at the next moment based on the current situational graph embedding vector and future network variables, thus supporting the simulation and deduction of the network digital twin.

[0067] Historical spatiotemporal heterogeneous graph data sequence: It is a data structure that describes the historical evolution of network state. It consists of a static topology graph composed of nodes and links, and attaches heterogeneous attributes (such as load and latency) that change over time to the vertices and edges. It is composed of graph snapshots arranged according to historical timestamps, and fully represents the historical temporal changes of network topology and multidimensional state.

[0068] Graph Neural Network Model: This refers to a deep learning model used to process graph-structured data. It can effectively aggregate information of adjacent nodes and edges in the graph through message passing, aggregation, and update mechanisms defined on the vertices and edges of the graph, learn the representation of elements in the graph, and capture the dependencies between elements. In this embodiment of the invention, it refers to a model set up for predicting the evolution of network situation, which includes a corresponding situation graph encoder and state transition predictor.

[0069] The implementation is as follows: First, external environment data, security intelligence data, local application data, and link status data from historical time periods (e.g., the past six months) are collected and cleaned. These heterogeneous data streams are then aligned, correlated, and aggregated according to timestamps (e.g., per minute) and network node identifiers (e.g., device ID, link ID). For each time point, a unified multi-dimensional temporal feature vector is calculated for each network node (node, link). (For example, for a link, its vector may contain normalized values ​​such as average latency, packet loss rate, traffic volume, and external temperature and security threat level at that time) to prepare training data. Second, based on the known network topology (which can be automatically discovered by the network or manually defined), a graph data structure G is constructed. For each historical time point t, the multi-dimensional temporal feature vectors of all entities at that time are used as attribute values ​​for the corresponding vertices and edges in graph G, resulting in a network state snapshot graph G_t at that time. The snapshot graphs G_1, G_2, ..., G_T from consecutive historical time points are arranged in chronological order, thus forming a historical spatiotemporal heterogeneous graph data sequence for model training. Third, to address the problem of "how to automatically learn the complex laws of network state evolution from historical spatiotemporal data and predict future states under external intervention," this invention proposes a two-stage graph neural network architecture comprising a situation graph encoder and a state transition predictor. Specifically: 1) The situation graph encoder: its core is a multi-layer graph convolutional network (GCN) or graph attention network (GAT), which takes a graph snapshot G_t (containing vertex and edge features) at time t as input. The GCN / GAT layers in the situation graph encoder aggregate information from each network node and its neighboring nodes through multiple rounds of iterative message passing, ultimately generating an encoded high-level feature representation for each element (node, edge) in the graph. Then, through global pooling operations (such as attention pooling), these scattered node / edge features are aggregated into a fixed-length, low-dimensional situation graph embedding vector H_t. Vector H_t is a compact, abstract representation of the global state of the entire network at time t.2) State Transition Predictor: Its core can be a recurrent neural network (such as LSTM or GRU) or a multilayer perceptron (MLP). It uses the situational graph embedding vector H_{t-1} from the previous time step and historical future network variables occurring between time step t-1 and t (i.e., events historically known to have occurred between [t-1, t], such as planned maintenance or a sudden attack) as input. The goal of the state transition predictor is to learn a mapping function f such that f(H_{t-1}, future network variables) = \hat{H}_t is as close as possible to the true H_t calculated from G_t by the encoder. Through this design, the graph neural network model is forced to learn how the global state of the network transitions to the next state under the combined influence of the current state and external events. This allows for the definition and training of the graph neural network model. The graph neural network model training employs supervised learning, and the loss function is typically the mean squared error (MSE) between the predicted embedding vector H^t and the true embedding vector H_t. The backpropagation algorithm simultaneously optimizes all parameters of both the situational graph encoder and the state transition predictor. Finally, the trained graph neural network model is saved and deployed as the overall network situational data model. When needed, the overall network situational data model can accept the current real network data (obtained through the encoder H_now) and future network variables. Through its state transition predictor, it iteratively predicts the situational graph embedding vector sequence H_{now+1}, H_{now+2}, ... for multiple future time points. These predicted embedding vectors can be further converted into specific network performance indicator prediction values ​​(such as the latency of each link) through a lightweight decoder (which can be pre-trained or regularized) when needed, thereby supporting the simulation and deduction of the network digital twin.

[0070] This invention, through the specific construction of a network-wide situational data model, not only illustrates the source of the model but also discloses its specific construction process (data preparation, model structure, and training methods). The successful construction of the network-wide situational data model is the fundamental premise and core technical guarantee for the entire method to achieve forward-looking and intelligent link control. Its ability to automatically learn evolutionary patterns from historical data is the core manifestation of the significant technical progress and contribution of this invention compared to traditional prediction methods based on fixed rules or simple statistics.

[0071] In one embodiment, after executing the local link control policy, the method further includes: The edge device monitors the end-to-end actual performance indicators of the corresponding application data stream, and reports the actual performance indicators and the corresponding path and time information as performance feedback data to the cloud control platform. The cloud control platform performs the following steps based on the performance feedback data: Based on the path and time information in the performance feedback data, it extracts the corresponding predicted performance indicators from the predictive network situation map and calculates the prediction deviation between the actual performance indicators and the predicted performance indicators; it obtains the network state context vector corresponding to the time information, where the network state context vector is a network state representation corresponding to the time information generated by calling the situation map encoder in the network situation data model; it inputs the prediction deviation value and the corresponding network state context vector into a preset sensitivity analysis model, which is configured to analyze the contribution of each simulation parameter in the network digital twin to the generation of the prediction deviation value and outputs a contribution ranking list; based on the contribution ranking list, it selects the simulation parameter with the highest contribution as the parameter to be adjusted. The parameters are calculated according to the direction and magnitude of the prediction deviation value, and the adjustment amount of the parameter to be adjusted is calculated according to the preset gradient descent or weighted allocation rule. The parameter to be adjusted is then fine-tuned. Using the network digital twin with the fine-tuned parameters, combined with the network state context vector, a new simulation is performed, and a new prediction deviation value between the predicted performance index obtained from the re-simulation and the actual performance index is calculated. If the new prediction deviation value is less than or equal to a preset threshold, the fine-tuned parameters are updated as new parameters of the network digital twin for subsequent simulation. Otherwise, based on the relationship between the new prediction deviation value and the prediction deviation value, the step size parameter in the gradient descent or weighted allocation rule is dynamically adjusted, the adjustment amount of the parameter to be adjusted is recalculated, and fine-tuning iteration is performed until the iteration condition is met or the upper limit of the number of iterations is reached, wherein the preset threshold is less than the prediction deviation value.

[0072] Network State Context Vector: This is a dense vector generated by encoding a snapshot of the network state at a specific moment using the situation map encoder that calls the overall network situation data model. It mathematically represents the overall situation of the entire network at that moment (topology, load, environment, etc.), providing the background context for the occurrence of deviations in subsequent analysis.

[0073] Sensitivity analysis model: This refers to a model or algorithm used to quantify the impact of changes in various simulation parameters (such as link baseline delay, bandwidth model coefficients, routing policy weights, etc.) in a network digital twin on the simulation output results (specifically, the prediction performance indicators). It is used to analyze the sensitivity (i.e., contribution) of the output results when a parameter undergoes a small perturbation.

[0074] The implementation is as follows: After the edge device executes the corresponding local link control strategy, it monitors the actual end-to-end performance indicators of the application data stream and reports them, along with transmission path and time information, as performance feedback data to the cloud control platform. Upon receiving the performance feedback data, the cloud control platform initiates an online fine-tuning process: 1) Based on the feedback time and path, it extracts predicted performance indicators (such as predicted latency) from the predictive network situation map at the corresponding time, and calculates the prediction deviation value δ = actual value - predicted value; 2) It obtains the network state context vector C_t at that time; 3) It inputs δ and C_t into a sensitivity analysis model (e.g., based on Monte Carlo sampling and linear regression), calculates the contribution of each simulation parameter to δ, and sorts them; 4) It selects the parameter with the highest contribution as the parameter to be adjusted θ, calculates the adjustment amount Δθ according to the direction and magnitude of δ using gradient descent and other rules, and performs fine-tuning; 5) It re-simulates using the fine-tuned network digital twin and calculates the new prediction deviation value δ_new. If δ_new is less than or equal to a preset threshold, the parameter update is accepted; otherwise, the step size parameter η is dynamically adjusted and iterated again until the threshold condition is met or the preset maximum number of iterations is reached. This invention, through a closed-loop parameter online adaptive fine-tuning mechanism based on actual performance feedback, achieves continuous self-optimization and accuracy improvement of the network digital twin. It effectively alleviates the problem of prediction error accumulation caused by dynamic changes in the network environment and inaccurate initial model, and solves the problem that static models are difficult to adapt to dynamic network environments. It is the core of ensuring long-term effective operation and maintaining high prediction accuracy.

[0075] The SD-WAN link control method based on global situational awareness described in the above embodiments can be recombined with the technical features included in different embodiments as needed to obtain a combined implementation scheme, but all are within the protection scope claimed by this invention.

[0076] In one embodiment, a global situational awareness-based SD-WAN link control system is provided, which corresponds one-to-one with the global situational awareness-based SD-WAN link control method described in the above embodiments. Please refer to [link to relevant documentation]. Figure 3 , Figure 3 This is a schematic block diagram of an SD-WAN link control system based on global situational awareness, provided as an embodiment of the present invention. Figure 3As shown, the SD-WAN link control system 30 based on global situational awareness is executed collaboratively by a cloud control platform and edge devices. The cloud control platform includes: a first acquisition module 31, an instantiation module 32, a first generation module 33, and a first distribution module 34; the edge devices include: a first receiving module 35, a first extraction module 36, a second generation module 37, and a first execution module 38. The detailed descriptions of each functional module are as follows: The cloud control platform includes: a first acquisition module 31, used to acquire external environmental data and security intelligence data affecting network connectivity, and to acquire local application data and link status data reported by the edge devices; an instantiation module 32, used to load a global situational awareness data model with network status prediction capabilities, and based on the global situational awareness data model, integrate the external environmental data, security intelligence data, local application data, and link status data to characterize the current network status, and instantiate a network digital twin; a first generation module 33, used to acquire future network variables as prediction input parameters, and combine the network digital twin with the future network variables for prediction. The system performs dynamic simulation and simulation to generate a predictive network-wide situation map for future time windows. The predictive network-wide situation map includes predictive quality levels and security risk scores for different paths. A first distribution module 34 is used to distribute the predictive network-wide situation map and the corresponding preset application service level targets to relevant edge devices. The edge devices include: a first receiving module 35, used to receive the predictive network-wide situation map and the preset application service level targets; a first extraction module 36, used to extract the predictive quality levels and security risk scores affecting the corresponding paths of local traffic from the predictive network-wide situation map according to the preset application service level targets; a second generation module 37, used to generate local traffic path selection intentions based on the extracted predictive quality levels and security risk scores, and exchange the local traffic path selection intentions with associated peer edge devices, and jointly negotiate to generate local link control policies through a distributed consensus decision-making mechanism; and a first execution module 38, used to execute the local link control policies to adjust the distribution and routing of local traffic on the wide area network links.

[0077] In one embodiment, the future network variables include at least one of the following: predicted service traffic plans, natural disaster information from external early warning systems, network maintenance notices issued by operators, and predictive attack activity information issued by threat intelligence platforms; the first generation module 33 is specifically used to input the future network variables as disturbance parameters into the network digital twin, and perform discrete event simulation in the virtual time domain based on the current network state reflected by the network situation data model, and deduce the time series change curves of each predicted indicator on different paths within the future time window.

[0078] In one embodiment, the cloud control platform is pre-configured with a network vulnerability assessment model. This model takes network topology features and the event type, geographical scope, and intensity index of an environmental event as input, and outputs the vulnerability coefficient of the network link affected by the environmental event. The first generation module 33 further includes: a first acquisition submodule, used to acquire external environmental data, which includes the event type, geographical scope, expected impact time window, and a function or sequence of the intensity index changing over time within the expected impact time window; a first mapping submodule, used to perform spatiotemporal alignment and geocoding of the external environmental data, and map it to a specific region in the network topology to obtain the topological features of the affected network region corresponding to the environmental event; and a first loop submodule, used to execute a corresponding loop as the simulation virtual time progresses, and includes: a first judgment submodule, used to determine whether the current virtual time falls within any... The system comprises: a predicted impact time window for the external environmental data; a first determining submodule, configured to determine, if applicable, a real-time intensity index corresponding to the current virtual time based on a function or sequence of the intensity index changing over time; a first calculating submodule, configured to input the event type, geographical range, real-time intensity index, and topological characteristics of the affected network area of ​​the environmental event falling within the time window into the network vulnerability assessment model, and calculate the real-time vulnerability coefficient of the corresponding network link at the current virtual time; a first correcting submodule, configured to dynamically correct the baseline performance parameters of the corresponding network link in the network digital twin according to the real-time vulnerability coefficient and a preset mapping rule; and a second looping submodule, configured to continue simulation and deduction based on the network digital twin with corrected parameters, and perform the next round of judgment and correction until the simulation ends, so that the generated predictive network situation map integrates the dynamic time-varying impact of the intensity of external environmental events.

[0079] In one embodiment, the first generation module 33 includes: a second calculation submodule, used to calculate the quality index and risk index of each path on each time slice within a future time window based on the time-series change curve; a first generation submodule, used to generate a continuous index field in a three-dimensional space composed of network nodes and time dimension based on a spatiotemporal interpolation algorithm; and a first composition submodule, used to extract and visualize the quality level heatmap and security risk distribution map of the entire network path at the corresponding future time from the index field, thereby constructing a predictive network situation map for the future time window.

[0080] In one embodiment, the second generation module 37 includes: a first filtering submodule, configured to, for each application data stream to be transmitted locally with a preset application service level target, filter out all paths that meet its connectivity requirements from the paths covered by the predictive network situation map according to the preset application service level target, as a candidate path set for the application data stream; a second acquisition submodule, configured to acquire the predictive quality level and security risk score corresponding to each candidate path in the candidate path set; a third calculation submodule, configured to, according to the preset weight corresponding to the application type of the application data stream, perform weighted fusion of the predictive quality level and the security risk score to calculate the comprehensive priority value of each candidate path; a second determination submodule, configured to, determine the candidate path with the highest comprehensive priority value as the initial intention selection path of the application data stream; and a first encapsulation submodule, configured to, encapsulate the initial intention selection path and its comprehensive priority value into the local traffic path selection intention of the application data stream.

[0081] In one embodiment, the second generation module 37 includes: a first sending submodule, used by each edge device to send the local traffic path selection intention to the peer edge devices connected to it in the network topology, and to receive path selection intentions from the peer edge devices; a first identification submodule, used by each edge device to identify disputed paths in which the initial intention selection paths overlap, based on its own and all received path selection intentions; a first construction submodule, used by each edge device to construct a distributed path allocation optimization model with the disputed paths as resources to be allocated, and with the initial intention selection paths, comprehensive priority values, and corresponding preset application service level targets contained in each path selection intention as input parameters; a first iteration submodule, used to solve the distributed path allocation optimization model by iteratively executing the following negotiation steps, and including: a fourth calculation submodule, used by each edge device to calculate the expected experience quality index of all its affected application data streams based on the current round's temporary path allocation scheme and the predictive network situation map; and a second sending submodule, used to... If the proposed edge device does not meet its preset application service level target, it generates an adjustment proposal for the corresponding disputed path and sends the adjustment proposal to the receiving edge device currently assigned to use the disputed path. A first evaluation submodule is used by the receiving edge device to receive the adjustment proposal, evaluate the impact of accepting the proposal on its own application data flow, and provide feedback of agreement or rejection to the proposing edge device accordingly. A first update submodule is used by the proposing edge device to update the temporary path allocation scheme based on the adjustment proposal and the corresponding feedback. A third determination submodule is used to repeat the above negotiation steps until no new adjustment proposal is generated within a preset number of consecutive rounds, or the total number of iterations reaches a preset upper limit, and the temporary path allocation scheme determined at this time is used as the path allocation consensus scheme. A second generation submodule is used by the proposing edge device to bind the disputed path assigned to it with the corresponding application data flow according to the path allocation consensus scheme, and generate a local link control policy containing specific routing rules, based on the undisputed initial intention path selection.

[0082] In one embodiment, the second generation module 37 includes: a third acquisition submodule, used by each edge device to acquire a corresponding preset multi-dimensional utility function for each application data stream with a preset application service level target; a third sending submodule, used in generating an adjustment proposal for a corresponding disputed path, whereby the proposing edge device calculates the change ΔU_self in the overall utility value of its corresponding application data stream if the adjustment proposal is accepted, and includes the change ΔU_self in the adjustment proposal and sends it to the receiving edge device; and a first execution submodule, used by the receiving edge device to receive and evaluate the adjustment proposal. When accepting the impact of the adjustment proposal on its own application data flow, if the receiving edge device simultaneously receives multiple adjustment proposals for the same disputed path, it executes corresponding processing steps, including: a fifth calculation submodule, used to calculate, for each adjustment proposal, the change in the overall utility value of its corresponding application data flow caused by accepting the adjustment proposal, ΔU_peer; a first broadcast submodule, used to broadcast to all proposing edge devices a list containing each adjustment proposal and its corresponding change ΔU_peer; a sixth calculation submodule, used by each proposing edge device to calculate the total utility improvement value ΔU_total = ΔU_self + ΔU_peer for each adjustment proposal based on the list; a first consensus submodule, used by each proposing edge device to reach a consensus on the adjustment proposal with the highest total utility improvement value ΔU_total through a round of fast voting or weight declaration, and use it as the path allocation consensus proposal; and a second execution submodule, used by the proposing edge device and the receiving edge device of the path allocation consensus proposal to execute the path allocation update according to the proposal, and other proposing edge devices to terminate their adjustment proposals.

[0083] In one embodiment, the SD-WAN link control system 30 based on global situational awareness further includes: a second extraction module, used to acquire historical external environment data, security intelligence data, local application data, and link status data, and align and associate them according to a unified timestamp and network node identifier, extracting multi-dimensional temporal feature vectors for each network node at each historical moment; a first forming module, used to construct a basic graph structure based on the network topology, with the network nodes as vertices and the links as edges, and using the multi-dimensional temporal feature vectors as dynamic attributes of the corresponding vertices and edges of the graph, forming a historical spatiotemporal heterogeneous graph data sequence; and a first definition module, used to define a graph neural network model, the graph neural network model including a situational graph encoder and a state transition predictor, the situational graph encoder being used to encode a snapshot of the historical spatiotemporal heterogeneous graph data sequence at any historical moment into a situational graph embedding vector representing the overall situation of the entire network at the corresponding historical moment, the state transition predictor being based on the previous historical... The system uses the situational graph embedding vector at a given historical moment and the corresponding historical future network variables as input to predict the situational graph embedding vector at the next historical moment. A first training module is used to supervise the training of the graph neural network model using the historical spatiotemporal heterogeneous graph data sequence and the corresponding historical future network variables as training samples. This optimizes the parameters of the situational graph encoder and the state transition predictor, enabling the graph neural network model to learn the dynamic evolution of network situation under the combined influence of multidimensional data and future network variables. A second definition module uses the trained graph neural network model as a full-network situational data model with network state deduction capabilities. The situational graph embedding vector constitutes the internal representation of the network state in the full-network situational data model, and the state transition predictor endows the full-network situational data model with the ability to deduce the situational graph embedding vector at the next moment based on the current situational graph embedding vector and future network variables, thus supporting the simulation and deduction of the network digital twin.

[0084] In one embodiment, the SD-WAN link control system 30 based on global situational awareness further includes: the edge device, which further includes: a first monitoring module, used to monitor the end-to-end actual performance indicators of the corresponding application data stream, and report the actual performance indicators and the corresponding path and time information as performance feedback data to the cloud control platform; the cloud control platform further includes: a first calculation module, used to extract the corresponding predicted performance indicators from the predictive global situational map based on the path and time information in the performance feedback data, and calculate the prediction deviation value between the actual performance indicators and the predicted performance indicators; a second acquisition module, used to acquire the network state context vector corresponding to the time information, the network state context vector being a network state representation corresponding to the time information generated by calling the situational map encoder in the global situational data model; a first input module, used to input the prediction deviation value and the corresponding network state context vector into a preset sensitivity analysis model, the sensitivity analysis model being configured to analyze the impact of each simulation parameter in the network digital twin on the production The system comprises the following modules: a first module, a second module, and a third module. The first module generates the contribution of the predicted deviation value and outputs a contribution ranking list. The second module selects the simulation parameter with the highest contribution from the contribution ranking list as the parameter to be adjusted, and calculates the adjustment amount of the parameter to be adjusted according to the direction and magnitude of the predicted deviation value, following a preset gradient descent or weighted allocation rule. The third module uses the network digital twin with the finely adjusted parameters, combined with the network state context vector, to perform a re-simulation and calculate a new predicted deviation value between the re-simulated predicted performance index and the actual performance index. The fourth module iterates to update the finely adjusted parameters to the new parameters of the network digital twin if the new predicted deviation value is less than or equal to a preset threshold, for subsequent simulations. Otherwise, based on the relationship between the new predicted deviation value and the predicted deviation value, it dynamically adjusts the step size parameter in the gradient descent or weighted allocation rule, recalculates the adjustment amount of the parameter to be adjusted, and performs fine-tuning iterations until the iteration condition is met or the upper limit of the number of iterations is reached, wherein the preset threshold is less than the predicted deviation value.

[0085] Specific limitations regarding the SD-WAN link control system based on global situational awareness can be found in the limitations of the SD-WAN link control method based on global situational awareness mentioned above, and will not be repeated here. Each module in the aforementioned SD-WAN link control system based on global situational awareness can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0086] Those skilled in the art will understand that the methods and systems provided in the embodiments of the present invention can be implemented, in whole or in part, by software, hardware, firmware, or any combination thereof. The methods can also be implemented as a computer program product stored in one or more computer-readable storage media, including but not limited to: disks, optical disks, read-only memory (ROM), random access memory (RAM), flash memory, etc. When the computer program product is executed by one or more data processing devices (such as computers), the devices perform the steps as described in any of the preceding method embodiments.

[0087] Software tools, components, or models not belonging to this company that appear in the embodiments of this invention are merely illustrative examples and do not represent actual use. The data collection methods used in the embodiments of this invention comply with relevant laws and regulations, such as the "Data Security Law of the People's Republic of China," the "Personal Information Protection Law of the People's Republic of China," GDPR (General Data Protection Regulation of the European Union), or information security standards of other countries and regions.

[0088] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. An SD-WAN link control method based on global situational awareness, characterized in that, The method, executed collaboratively by a cloud control platform and edge devices, includes: The cloud control platform performs the following steps: Acquire external environmental data and security intelligence data that affect network connectivity, and acquire local application data and link status data reported by the edge device; Load a network-wide situational data model with network status projection capabilities. Based on the network-wide situational data model, integrate external environment data, security intelligence data, local application data, and link status data to characterize the current network status and instantiate a network digital twin. The future network variables are obtained as input parameters for the simulation. Dynamic simulation is performed by combining the future network variables with the network digital twin to generate a predictive network situation map for future time windows. The predictive network situation map includes the predictive quality level and security risk score of different paths. The predictive network situation map and the corresponding preset application service level targets are distributed to the relevant edge devices; The edge device performs the following steps: Receive the predictive network-wide situation map and the preset application service level target; Based on the preset application service level target, the predictive quality level and security risk score of the corresponding path affecting local traffic are extracted from the predictive network situation map; Based on the extracted predictive quality level and the security risk score, a local traffic path selection intention is generated, and the local traffic path selection intention is exchanged with the associated peer edge device. A local link control policy is then jointly negotiated and generated through a distributed consensus decision-making mechanism. The local link control policy is executed to adjust the distribution and routing of local traffic on the WAN link.

2. The SD-WAN link control method based on global situational awareness as described in claim 1, characterized in that, The future network variables include at least one of the following: predicted service traffic plans, natural disaster information from external early warning systems, network maintenance notices issued by operators, and predictive attack activity information issued by threat intelligence platforms; Dynamic simulation and deduction are performed by combining the network digital twin with the future network variables, including: The future network variables are input as perturbation parameters into the network digital twin. Based on the current network state reflected by the network situation data model, discrete event simulation is performed in the virtual time domain to deduce the time series change curves of each prediction index on different paths within the future time window.

3. The SD-WAN link control method based on global situational awareness as described in claim 2, characterized in that, The cloud control platform is pre-installed with a network vulnerability assessment model. The network vulnerability assessment model is used to take network topology characteristics and the event type, geographical range, and intensity index of environmental events as inputs, and output the vulnerability coefficient of network links affected by environmental events. The dynamic simulation and deduction based on the network digital twin and the future network variables also includes: Acquire external environmental data, which includes the event type, geographical scope, expected impact time window, and a function or sequence of intensity indicators changing over time within the expected impact time window; The external environment data is spatiotemporally aligned and geocoded, and mapped to specific regions in the network topology to obtain the topological features of the affected network regions corresponding to the environmental event. As the simulation progresses through virtual time, the following loop is executed: Determine whether the current virtual time falls within the expected impact time window of any of the aforementioned external environment data; If so, determine the real-time intensity index corresponding to the current virtual time based on the function or sequence of the intensity index changing over time; The event type, geographical range, real-time intensity index, and topological characteristics of the affected network area of ​​the environmental event falling within the time window are input into the network vulnerability assessment model to calculate the real-time vulnerability coefficient of the corresponding network link in the current virtual time. Based on the real-time vulnerability coefficient, the baseline performance parameters of the corresponding network links in the network digital twin are dynamically corrected according to a preset mapping rule; The network digital twin, after parameter correction, continues to be simulated and deduced, and the next round of judgment and correction is carried out until the simulation ends, so that the generated predictive network situation map can integrate the dynamic time-varying impact of the intensity of external environmental events.

4. The SD-WAN link control method based on global situational awareness as described in claim 2 or 3, characterized in that, Generate predictive network-wide situational maps for future time windows, including: Based on the time-series change curve, calculate the quality index and risk index of each path in each time slice within the future time window; Based on the spatiotemporal interpolation algorithm, the quality index and the risk index are generated into a continuous index field in a three-dimensional space composed of network nodes and time dimension. From the aforementioned indicator field, a heatmap of the quality level of the entire network path and a security risk distribution map are extracted and visualized to present the corresponding future time, thus forming a predictive network situation map for future time windows.

5. The SD-WAN link control method based on global situational awareness as described in claim 1, characterized in that, Based on the extracted predictive quality level and the security risk score, a local traffic path selection intention is generated, including: For each application data stream with a preset application service level target to be transmitted locally, according to the preset application service level target, all paths that meet its connectivity requirements are selected from the paths covered by the predictive network situation map and used as the candidate path set for the application data stream. Obtain the predictive quality level and security risk score corresponding to each candidate path in the candidate path set; Based on the preset weights corresponding to the application types of the application data streams, the predictive quality level and the security risk score are weighted and fused together to calculate the comprehensive priority value of each candidate path. The candidate path with the highest overall priority value is determined as the initial intended selection path for the application data flow; The initial intended path selection and its overall priority value are encapsulated into the local traffic path selection intention of the application data stream.

6. The SD-WAN link control method based on global situational awareness as described in claim 5, characterized in that, The local traffic path selection intention is exchanged with the associated peer edge device, and a local link control policy is jointly negotiated and generated through a distributed consensus decision-making mechanism, including: Each edge device sends its local traffic path selection intention to its peer edge devices connected in the network topology, and receives path selection intentions from its peer edge devices. Each edge device identifies disputed paths where the initial intention selection paths overlap, based on its own and all received path selection intentions. Each edge device uses the disputed path as the resource to be allocated, and uses the initial intended path selection, comprehensive priority value and corresponding preset application service level target contained in each path selection intention as input parameters to construct a distributed path allocation optimization model; The distributed path allocation optimization model is solved by iteratively executing the following negotiation steps: Each edge device uses a temporary path allocation scheme based on the current round and calculates the expected experience quality index of all its affected application data streams based on the predictive network situation map. If the expected experience quality index does not meet its preset application service level target, the edge device, as the proposing edge device, generates an adjustment proposal for the corresponding disputed path and sends the adjustment proposal to the receiving edge device currently assigned to use the disputed path. The receiving edge device receives the adjustment proposal and assesses the impact of accepting the adjustment proposal on its own application data stream, and accordingly sends a response of agreement or rejection to the proposing edge device. The proposing edge device updates the temporary path allocation scheme based on the adjustment proposal and corresponding feedback; Repeat the above negotiation steps until no new adjustment proposals are generated within a consecutive preset number of rounds, or the total number of iterations reaches the preset limit. The temporary path allocation scheme determined at this time shall be used as the path allocation consensus scheme. The proposing edge device binds the disputed path allocated to it with the corresponding application data stream according to the path allocation consensus scheme, and generates a local link control policy containing specific routing rules by combining the undisputed initial intention selection path.

7. The SD-WAN link control method based on global situational awareness as described in claim 6, characterized in that, The distributed consensus decision-making mechanism is based on the principle of global optimization of application utility, and its specific implementation includes: Each edge device obtains a corresponding preset multi-dimensional utility function for each application data stream with a preset application service level target. In generating an adjustment proposal for the corresponding disputed path, the proposing edge device calculates the change ΔU_self in the overall utility value of its corresponding application data stream if the adjustment proposal is accepted, and includes the change ΔU_self in the adjustment proposal and sends it to the receiving edge device. When the receiving edge device receives the adjustment proposal and assesses the impact of accepting the adjustment proposal on its own application data flow, if the receiving edge device simultaneously receives multiple adjustment proposals for the same disputed path, the following steps are performed: For each adjustment proposal, calculate the change ΔU_peer in the overall utility value of the corresponding application data stream that will result from accepting the adjustment proposal; Broadcast a list containing each adjustment proposal and its corresponding change ΔU_peer to all proposing edge devices; Each proposing edge device calculates the total utility improvement value ΔU_total = ΔU_self + ΔU_peer for each adjustment proposal based on the list; Each proposing edge device reaches a consensus on the adjustment proposal with the highest total utility improvement value ΔU_total through a round of fast voting or weight declaration, and uses it as the path allocation consensus proposal. The proposing edge device and the receiving edge device of the path allocation consensus proposal perform path allocation updates according to the proposal, while other proposing edge devices terminate their adjustment proposals.

8. The SD-WAN link control method based on global situational awareness as described in claim 1, characterized in that, The overall network situation data model is obtained through the following construction process: It acquires historical external environment data, security intelligence data, local application data, and link status data, and aligns and associates them with network node identifiers according to a unified timestamp, extracting multi-dimensional temporal feature vectors for each network node at each historical moment; Based on the network topology, a basic graph structure is constructed with the network nodes as vertices and the links as edges. The multi-dimensional temporal feature vectors are used as dynamic attributes of the corresponding vertices and edges of the graph to form a historical spatiotemporal heterogeneous graph data sequence. A graph neural network model is defined, which includes a situation map encoder and a state transition predictor. The situation map encoder is used to encode a snapshot of the historical spatiotemporal heterogeneous graph data sequence at any historical moment into a situation map embedding vector that represents the overall situation of the entire network at the corresponding historical moment. The state transition predictor uses the situation map embedding vector of the previous historical moment and the corresponding historical future network variables as input to predict the situation map embedding vector of the next historical moment. Using the historical spatiotemporal heterogeneous graph data sequence and the corresponding historical future network variables as training samples, the graph neural network model is trained under supervision to optimize the parameters of the situation graph encoder and the state transition predictor, so that the graph neural network model can learn the dynamic evolution law of the network situation under the joint drive of multidimensional data and future network variables. The trained graph neural network model is used as a full-network situational data model with network state inference capabilities. The situational graph embedding vector constitutes the internal representation of the network state of the full-network situational data model. The state transition predictor enables the full-network situational data model to infer the situational graph embedding vector at the next moment based on the situational graph embedding vector at the current moment and future network variables, so as to support the simulation and inference of the network digital twin.

9. The SD-WAN link control method based on global situational awareness as described in claim 8, characterized in that, After executing the local link control policy, the method further includes: The edge device monitors the end-to-end actual performance indicators of the corresponding application data stream, and reports the actual performance indicators and the corresponding path and time information as performance feedback data to the cloud control platform. Based on the performance feedback data, the cloud control platform performs the following steps: Based on the path and time information in the performance feedback data, the corresponding predicted performance indicators are extracted from the predictive network situation map, and the prediction deviation between the actual performance indicators and the predicted performance indicators is calculated. Obtain the network state context vector corresponding to the time information. The network state context vector is a network state representation corresponding to the time information generated by calling the situation map encoder in the network situation data model. The predicted deviation value and the corresponding network state context vector are input into a preset sensitivity analysis model. The sensitivity analysis model is configured to analyze the contribution of each simulation parameter in the network digital twin to the generation of the predicted deviation value and output a contribution ranking list. According to the contribution ranking list, the simulation parameter with the highest contribution is selected as the parameter to be adjusted. Based on the direction and magnitude of the prediction deviation value, the adjustment amount of the parameter to be adjusted is calculated according to the preset gradient descent or weighted allocation rules, and the parameter to be adjusted is fine-tuned. Using the network digital twin with fine-tuned parameters, combined with the network state context vector, a re-simulation is performed, and a new prediction deviation value between the predicted performance index obtained from the re-simulation and the actual performance index is calculated. If the new prediction deviation value is less than or equal to a preset threshold, the fine-tuned parameters are updated to the new parameters of the network digital twin for subsequent simulation and deduction. Otherwise, based on the relationship between the new prediction deviation value and the prediction deviation value, the step size parameter in the gradient descent or weighted allocation rule is dynamically adjusted, the adjustment amount of the parameter to be adjusted is recalculated, and fine-tuning iteration is performed until the iteration condition is met or the upper limit of the number of iterations is reached, wherein the preset threshold is less than the prediction deviation value.

10. An SD-WAN link control system based on global situational awareness, characterized in that, The system, executed collaboratively by a cloud control platform and edge devices, includes: The cloud control platform includes: The first acquisition module is used to acquire external environmental data and security intelligence data that affect network connectivity, and to acquire local application data and link status data reported by the edge device. The instantiation module is used to load a network-wide situational data model with network status inference capabilities. Based on the network-wide situational data model, the module integrates external environment data, security intelligence data, local application data, and link status data to characterize the current network status and instantiate a network digital twin. The first generation module is used to acquire future network variables as input parameters for the simulation, and to perform dynamic simulation and simulation by combining the network digital twin with the future network variables to generate a predictive network situation map for future time windows. The predictive network situation map includes the predictive quality level and security risk score of different paths. The predictive network situation map and the corresponding preset application service level targets are distributed to the relevant edge devices; The edge device includes: The first receiving module is used to receive the predictive network situation map and the preset application service level target; The first extraction module is used to extract the predictive quality level and security risk score of the corresponding path affecting local traffic from the predictive network situation map according to the preset application service level target. The second generation module is used to generate a local traffic path selection intention based on the extracted predictive quality level and the security risk score, and exchange the local traffic path selection intention with the associated peer edge device, and jointly negotiate to generate a local link control policy through a distributed consensus decision-making mechanism. The first execution module is used to execute the local link control policy to adjust the distribution and routing of local traffic on the wide area network link.