Information transmission method, related equipment, medium and product

By receiving and constructing a physical layer secure network topology and using the extended LLDP protocol to carry Physec information, the problem of the controller being unable to obtain Physec information of network devices is solved, and the determination of Physec network topology is realized.

CN121967235APending Publication Date: 2026-05-01CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2024-12-20
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

The controller is unable to obtain physical layer security (Physec) network information from the network devices.

Method used

The first network device receives status information reported by the second and third network devices, constructs a physical layer secure network topology, and extends the Link Layer Discovery Protocol (LLDP) to carry Physec information.

Benefits of technology

This invention enables the controller to determine the Physec network topology of network devices, thus solving the problem that the controller cannot obtain Physec network information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967235A_ABST
    Figure CN121967235A_ABST
Patent Text Reader

Abstract

The invention discloses an information transmission method, related equipment, a medium and a product. The method comprises the following steps: receiving first information reported by second network equipment; the first information comprises local equipment state information of the second network equipment and adjacent equipment state information of the second network equipment; receiving second information reported by a third network device; the second information comprises local equipment state information of the third network equipment and adjacent equipment state information of the third network equipment; and constructing a physical layer security network topology based on the first information and the second information.
Need to check novelty before this filing date? Find Prior Art

Description

An information transmission method, related equipment, medium and product Technical Field

[0001] This invention relates to the field of communication technology, and in particular to an information transmission method, related equipment, medium and product. Background Technology

[0002] In related technologies, network devices can send the acquired status information of other network devices and their own status information to the controller, but the controller cannot obtain the physical layer security (Physec) network information of the network devices. Summary of the Invention

[0003] This application provides an information transmission method, related equipment, medium, and product.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] An information transmission method, applied to a first network device, the method comprising:

[0006] Receive first information reported by the second network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0007] Receive second information reported by a third network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0008] Based on the first information and the second information, a physical layer secure network topology is constructed.

[0009] In the above scheme, the first information is received through a first protocol; the first protocol includes one or more of the following:

[0010] Simple Network Management Protocol;

[0011] Border Gateway Protocol (BGP) Link State Protocol;

[0012] Telemetry protocol.

[0013] In the above scheme, the second information is received through a first protocol; the first protocol includes one or more of the following:

[0014] Simple Network Management Protocol;

[0015] Border Gateway Protocol (BGP) Link State Protocol;

[0016] Telemetry protocol.

[0017] An information transmission method, applied to a second network device, the method comprising:

[0018] Receive a first message sent by a third network device; the first message carries the local device status information of the third network device.

[0019] The first information is reported to the first network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0020] In the above scheme, the first message is received through the second protocol; the first message includes a newly added information field; the local device status information of the third network device is carried through the newly added information field.

[0021] In the above scheme, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0022] In the above scheme, the device status type-length-value includes a physical layer security support type field and a physical layer security enable status field.

[0023] In the above scheme, the physical layer security support type field indicates one of the following:

[0024] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0025] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0026] It does not support L1.5 physical layer security and L1 physical layer security;

[0027] Supports L1.5 physical layer security and L1 physical layer security.

[0028] In the above scheme, the physical layer security enable state field indicates one of the following:

[0029] Enable L1 physical layer security and disable L1.5 physical layer security;

[0030] Enable L1.5 physical layer security and disable L1 physical layer security;

[0031] Disable L1.5 physical layer security and L1 physical layer security;

[0032] Enable L1.5 physical layer security and L1 physical layer security.

[0033] In the above scheme, after receiving the first message sent by the third network device, the process includes:

[0034] The first information is generated based on the device status type-length-value.

[0035] An information transmission method, applied to a third network device, the method comprising:

[0036] Send a first message to the second network device; the first message carries the local device status information of the third network device;

[0037] The second information is reported to the first network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0038] In the above scheme, the first message is received through the second protocol; the first message includes a newly added information field; the local device status information of the third network device is carried through the newly added information field.

[0039] In the above scheme, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0040] In the above scheme, the device status type-length-value includes a physical layer security support type field and a physical layer security enable status field.

[0041] In the above scheme, the physical layer security support type field indicates one of the following:

[0042] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0043] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0044] It does not support L1.5 physical layer security and L1 physical layer security;

[0045] Supports L1.5 physical layer security and L1 physical layer security.

[0046] In the above scheme, the physical layer security enable state field indicates one of the following:

[0047] Enable L1 physical layer security and disable L1.5 physical layer security;

[0048] Enable L1.5 physical layer security and disable L1 physical layer security;

[0049] Disable L1.5 physical layer security and L1 physical layer security;

[0050] Enable L1.5 physical layer security and L1 physical layer security.

[0051] An information transmission device is applied to a first network device, the device comprising:

[0052] The first receiving unit is configured to receive first information reported by the second network device; the first information includes local device status information of the second network device and neighboring device status information of the second network device.

[0053] Receive second information reported by a third network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0054] The first processing unit is used to construct a physical layer secure network topology based on the first information and the second information.

[0055] An information transmission device, applied to a second network device, the device comprising:

[0056] The second receiving unit is configured to receive a first message sent by a third network device; the first message carries the local device status information of the third network device.

[0057] The first sending unit is used to report first information to the first network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0058] An information transmission device, applied to a third network device, the device comprising:

[0059] The second sending unit is used to send a first message to the second network device; the first message carries the local device status information of the third network device.

[0060] The second information is reported to the first network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0061] A first network device includes a first communication interface and a first processor; wherein,

[0062] The first communication interface is used to receive first information reported by the second network device; the first information includes local device status information of the second network device and neighboring device status information of the second network device.

[0063] Receive second information reported by a third network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0064] The first processor is configured to construct a physical layer secure network topology based on the first information and the second information.

[0065] A second network device includes a second communication interface and a second processor; wherein,

[0066] The second communication interface is used to receive a first message sent by a third network device; the first message carries the local device status information of the third network device.

[0067] The first information is reported to the first network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0068] A third network device includes a third communication interface and a third processor; wherein,

[0069] The third communication interface is used to send a first message to the second network device; the first message carries the local device status information of the third network device.

[0070] The second information is reported to the first network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0071] This invention provides an information transmission method, related equipment, medium, and product. It receives first information reported by a second network device; the first information includes the local device status information of the second network device and the status information of neighboring devices of the second network device; it receives second information reported by a third network device; the second information includes the local device status information of the third network device and the status information of neighboring devices of the third network device; and based on the first information and the second information, it constructs a physical layer secure network topology. In other words, this application constructs a physical layer secure network topology by receiving first information reported by a second network device and second information reported by a third network device from a first network device. The first information includes the local device status information of the second network device and the status information of neighboring devices of the second network device, and the second information includes the local device status information of the third network device and the status information of neighboring devices of the third network device. This enables the determination of the Physec information of network devices through network device status information and the construction of a Physec network topology, solving the problem in related technologies where the controller cannot obtain the Physec network information of network devices. Attached Figure Description

[0072] Figure 1 is a schematic diagram of the Ethernet physical layer security technology system in related technologies;

[0073] Figure 2 is a schematic diagram of a Physec network topology provided in an embodiment of this application;

[0074] Figure 3 is a flowchart illustrating an information transmission method provided in an embodiment of this application;

[0075] Figure 4 is a flowchart illustrating another information transmission method provided in an embodiment of this application;

[0076] Figure 5 is a flowchart illustrating the third information transmission method provided in this application embodiment;

[0077] Figure 6 is a schematic diagram of a message format provided in an embodiment of this application;

[0078] Figure 7 is a schematic diagram of a device status type-length-value field provided in an embodiment of this application;

[0079] Figure 8 is a schematic diagram of the fields of Physec information provided in an embodiment of this application;

[0080] Figure 9 is a flowchart illustrating the fourth information transmission method provided in an embodiment of this application;

[0081] Figure 10 is a topology diagram of a Physec device provided in an embodiment of this application;

[0082] Figure 11 is a schematic diagram of the structure of an information transmission device provided in an embodiment of this application;

[0083] Figure 12 is a schematic diagram of another information transmission device provided in an embodiment of this application;

[0084] Figure 13 is a schematic diagram of the structure of the third information transmission device provided in the embodiment of this application;

[0085] Figure 14 is a schematic diagram of the structure of a first network device provided in an embodiment of this application;

[0086] Figure 15 is a schematic diagram of the structure of a second network device provided in an embodiment of this application;

[0087] Figure 16 is a schematic diagram of the structure of a third network device provided in an embodiment of this application. Detailed Implementation

[0088] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application are further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0089] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0090] The terms "first / second / third" used in this application are merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first / second / third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0091] Referring to Figure 1, Ethernet physical layer security technology encrypts and decrypts physical layer bitstreams by masking traffic characteristics, achieving data protection for the link layer and all upper-layer protocols. It offers advantages such as low overhead, low latency, and protocol transparency. Currently, Physec provides two layers of data encryption and decryption. L1.5 Physec encrypts and decrypts 64B / 66B data blocks of the Physical Coding Sublayer (PCS) of the Physical Layer (PHY), achieving channel-level physical layer security that is imperceptible to optical layer devices. L1 Physec encrypts and decrypts the alignment marker (AM) bitstream of the Physical Medium Attachment (PMA) layer of the PHY, achieving link-level physical layer security between physical interfaces. L1.5 Physec and L1 Physec cannot interoperate. Different network devices may have different Physec capabilities. For example, existing devices may only support L1 layer PHYSec, while new devices may support L1.5 layer PHYSec. They may also support both or none of them.

[0092] Network devices can announce their own status to other devices in the network by sending Link Layer Discovery Protocol (LLDP) messages, and can also obtain status information of neighboring devices through LLDP messages. The status information of network devices may include, but is not limited to, device information, port information, configuration information, or system information. Referring to Figure 2, when R1 and R5 are L1-physec enabled devices, R2 and R4 are L1-physec and L1.5-physec enabled devices, and R3 is a non-physec enabled device, the links between R1 and R2, and between R4 and R5 are L1-physec links, the link between R2 and R4 is an L1.5-physec link, and the links between R2 and R3, and between R3 and R4, are non-physec links. Based on the existing LLDP messages, after collecting the status information of each network device, controller C1 cannot determine the network's physec information or physec topology information based on this status information.

[0093] An embodiment of this application provides an information transmission method applied to a first network device. Referring to FIG3, the method includes the following steps:

[0094] Step S301: Receive the first information reported by the second network device.

[0095] The first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0096] Understandably, network devices can store their own status information, i.e., local device status information, in a local Management Information Base (MIB), while storing the status information of neighboring devices in a remote MIB.

[0097] In practical applications, the Type-Length-Value (TLV) option of the LLDP protocol can be extended, allowing network devices to carry Physec information in LLDP messages to inform other network devices of their own Physec information. A network device can store its own Physec information in its local MIB, and the Physec information of neighboring devices in a remote MIB. The device then encapsulates its own Physec information and that of neighboring devices into an LLDP message and sends it to other network devices.

[0098] After a network device receives an LLDP message carrying Physec information from another device, it can inform the controller of its own and other network devices' Physec information via a notification message. Alternatively, it can directly send its own Physec information stored in its local MIB and the Physec information of neighboring devices stored in a remote MIB to the controller. The first piece of information can be reported via a notification message. The first network device can be understood as the controller. The second network device can be understood as a network device with or without Physec functionality.

[0099] Step S302: Receive the second information reported by the third network device.

[0100] The second information includes the local device status information of the third network device and the status information of the neighboring devices of the third network device.

[0101] Understandably, a third network device can be understood as a network device with or without Physec functionality.

[0102] In practical applications, referring to Figure 4, this embodiment uses network device R4 as the second network device and network device R2 as the third network device as an example for illustration. R2 obtains physec information from the local MIB and the remote MIB, encapsulates it into an LLDP message, and sends it to R4; R4 receives the LLDP message from R2, obtains the physec information of R2, and updates the remote MIB; R4 sends the physec information in the local MIB and the remote MIB to the controller C1 through a notification message; R2 sends its own physec information in the local MIB and R4's physec information in the remote MIB to the controller C1.

[0103] Step S303: Based on the first information and the second information, construct the physical layer security network topology.

[0104] In practical applications, referring to Figure 4, after receiving the second information reported by R2 and the first information reported by R4, the controller C1 verifies the physec information of R2 and R4 based on the first and second information. When the first information is consistent with the physec information of the same network device in the second information, the physical layer security network topology in the network can be determined.

[0105] As can be seen from the above, the embodiments of this application construct a physical layer secure network topology by receiving first information reported by the second network device and second information reported by the third network device from the first network device. The first information includes the local device status information of the second network device and the neighboring device status information of the second network device. The second information includes the local device status information of the third network device and the neighboring device status information of the third network device. This enables the determination of the Physec information of the network device through the network device status information and the construction of the Physec network topology, thus solving the problem in the related technology that the controller cannot obtain the Physec network information of the network device.

[0106] In some embodiments of this application, first information is received via a first protocol; the first protocol includes one or more of the following:

[0107] Simple Network Management Protocol;

[0108] Border Gateway Protocol (BGP) Link State Protocol;

[0109] Telemetry protocol.

[0110] In practical applications, the local device status information and neighboring device status information in the notification message can be sent to the controller via Simple Network Management Protocol (SNMP), Border Gateway Protocol Link State (BGP-LS), or Telemetry.

[0111] In some embodiments of this application, second information is received via a first protocol; the first protocol includes one or more of the following:

[0112] Simple Network Management Protocol;

[0113] Border Gateway Protocol (BGP) Link State Protocol;

[0114] Telemetry protocol.

[0115] In practical applications, the local device status information and neighboring device status information in the notification message can be sent to the controller via SNMP, BGP-LS, or Telemetry.

[0116] An embodiment of this application provides an information transmission method applied to a second network device. Referring to FIG5, the method includes the following steps:

[0117] Step S501: Receive the first message sent by the third network device.

[0118] The first message carries the local device status information of the third network device.

[0119] Understandably, the Type Length Value (TLV) option of the LLDP protocol can be extended to allow network devices to carry Physec information in LLDP messages and inform other network devices of their own Physec information.

[0120] In practical applications, referring to Figure 4, this embodiment uses network device R4 as the second network device and network device R2 as the third network device as an example for illustration. R2 obtains physec information from the local MIB and the remote MIB, encapsulates it into an LLDP message, and sends it to R4; R4 receives the LLDP message from R2, obtains the physec information of R2, and updates the remote MIB; R4 sends the physec information in the local MIB and the remote MIB to the controller C1 through a notification message; R2 sends its own physec information in the local MIB and R4's physec information in the remote MIB to the controller C1.

[0121] Referring to Figure 6, an LLDP message includes a destination address, source address, type, Link Layer Discovery Protocol Data Unit (LLDPDU), and Frame Check Sequence (FCS). The destination address is the multicast address 01-80-C2-00-00-0E, the source address is the Medium Access Control (MAC) address of the sending node or the originating port, the type is the LLDP message type, the LLDPDU is the LLDP message information, and the FCS is the frame check sequence number.

[0122] An LLDPDU includes multiple TLV fields. Referring to Figure 7, the Device Identifier TLV identifies the sending device; the Port Identifier TLV identifies the sending port; and the Time to Live (TTL) TLV indicates the device's lifespan in neighboring nodes. These three TLVs are the basic TLVs and must be carried in the LLDP message. An LLDPDU can also carry multiple optional TLVs, which are used to transmit physec information.

[0123] Step S502: Report the first information to the first network device.

[0124] The first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0125] In practical applications, the R4 device sends the physec information from the local MIB and the remote MIB to the controller C1 via a notification message.

[0126] As can be seen from the above, in this embodiment of the application, the network device obtains the Physec information of other network devices through LLDP messages, and sends the local device status information and the status information of neighboring devices to the controller, so that the controller can determine the Physec information of the network device through the network device status information and construct the Physec network topology, thus solving the problem in the related technology that the controller cannot obtain the Physec network information of the network device.

[0127] In some embodiments of this application, a first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of a third network device.

[0128] In practical applications, the second protocol can be understood as LLDP. The first message can be understood as an LLDP message. The newly added information field can be understood as an optional TLV, which carries the network device's Physec information by setting the device status type-length-value.

[0129] In some embodiments of this application, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0130] In practical applications, referring to Figure 8, the newly added information fields include a type field (TLY type), a length field (TLV length), and a physec information field. The TLV type indicates that the TLV carries physec information; field values ​​0 to 8 are defined by the 802.1AB standard, and in this embodiment, values ​​9 to 127 can be used. The TLV length field is 9 bits, and the maximum length of an LLDPDU is 512 bytes. The physec information field may include a physec support type (PST) and a physec enable status (PES), and may also include multi-frame length (MFL), O code mode (OCM), encryption algorithm type (EAT), forward error correction (FEC) type, and reserved fields.

[0131] In some embodiments of this application, the device state type-length-value includes a physical layer security support type field and a physical layer security enable state field.

[0132] In practical applications, the Physec information fields are shown in Table 1:

[0133] Table 1

[0134]

[0135]

[0136] In some embodiments of this application, the physical layer security support type field indicates one of the following:

[0137] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0138] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0139] It does not support L1.5 physical layer security and L1 physical layer security;

[0140] Supports L1.5 physical layer security and L1 physical layer security.

[0141] In practical applications, the physical layer security support type field can be referenced from Table 1 of the aforementioned steps.

[0142] In some embodiments of this application, the physical layer security enable state field indicates one of the following:

[0143] Enable L1 physical layer security and disable L1.5 physical layer security;

[0144] Enable L1.5 physical layer security and disable L1 physical layer security;

[0145] Disable L1.5 physical layer security and L1 physical layer security;

[0146] Enable L1.5 physical layer security and L1 physical layer security.

[0147] In practical applications, the physical layer security enable state field can be referenced from Table 1 of the aforementioned steps.

[0148] In some embodiments of this application, after receiving the first message sent by the third network device, the process includes:

[0149] First information is generated based on device status type-length-value.

[0150] In practical applications, after receiving an LLDP message, a network device can determine the Physec information of neighboring network devices based on the device status type-length-value, and then send it to the controller via a notification message in conjunction with its own Physec information.

[0151] An embodiment of this application provides an information transmission method applied to a third network device. Referring to FIG9, the method includes the following steps:

[0152] Step S901: Send the first message to the second network device.

[0153] The first message carries the local device status information of the third network device.

[0154] Referring to Figure 4, this embodiment of the application uses network device R4 as the second network device and network device R2 as the third network device as an example for illustration. R2 obtains physec information from the local MIB and the remote MIB, encapsulates it into an LLDP message, and sends it to R4; R4 receives the LLDP message from R2, obtains the physec information of R2, and updates the remote MIB; R4 sends the physec information in the local MIB and the remote MIB to the controller C1 through a notification message; R2 sends its own physec information in the local MIB and R4's physec information in the remote MIB to the controller C1.

[0155] Referring to Figure 6, an LLDP message includes a destination address, source address, type, LLDPDU, and FCS. The destination address is the multicast address 01-80-C2-00-00-0E, the source address is the MAC address of the sending node or the originating port; the type is the LLDP message type; the LLDPDU is the LLDP message information; and the FCS is the frame checksum.

[0156] An LLDPDU includes multiple TLV fields. Referring to Figure 7, the Device Identifier TLV identifies the sending device; the Port Identifier TLV identifies the sending port; and the Time to Live (TTL) TLV indicates the device's lifespan in neighboring nodes. These three TLVs are the basic TLVs and must be carried in the LLDP message. An LLDPDU can also carry multiple optional TLVs, which are used to transmit physec information.

[0157] Step S902: Report the second information to the first network device.

[0158] The second information includes the local device status information of the third network device and the status information of the neighboring devices of the third network device.

[0159] In practical applications, the R2 device sends the physec information from the local MIB and the remote MIB to the controller C1 via a notification message.

[0160] As can be seen from the above, in this embodiment of the application, the network device obtains the Physec information of other network devices through LLDP messages, and sends the local device status information and the status information of neighboring devices to the controller, so that the controller can determine the Physec information of the network device through the network device status information and construct the Physec network topology, thus solving the problem in the related technology that the controller cannot obtain the Physec network information of the network device.

[0161] In some embodiments of this application, a first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of a third network device.

[0162] In practical applications, the second protocol can be understood as LLDP. The first message can be understood as an LLDP message. The newly added information field can be understood as an optional TLV, which carries the network device's Physec information by setting the device status type-length-value.

[0163] In some embodiments of this application, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0164] In some embodiments of this application, the device state type-length-value includes a physical layer security support type field and a physical layer security enable state field.

[0165] In practical applications, referring to Figure 8, the newly added information fields include a type field (TLY type), a length field (TLV length), and a physec information field. The TLV type indicates that the TLV carries physec information; field values ​​0 to 8 are defined by the 802.1AB standard, and in this embodiment, values ​​9 to 127 can be used. The TLV length field is 9 bits, and the maximum length of an LLDPDU is 512 bytes. The physec information field may include PST and PES, and may also include MFL, OCM, EAT, FEC types, and reserved fields.

[0166] In some embodiments of this application, the physical layer security support type field indicates one of the following:

[0167] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0168] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0169] It does not support L1.5 physical layer security and L1 physical layer security;

[0170] Supports L1.5 physical layer security and L1 physical layer security.

[0171] In some embodiments of this application, the physical layer security enable state field indicates one of the following:

[0172] Enable L1 physical layer security and disable L1.5 physical layer security;

[0173] Enable L1.5 physical layer security and disable L1 physical layer security;

[0174] Disable L1.5 physical layer security and L1 physical layer security;

[0175] Enable L1.5 physical layer security and L1 physical layer security.

[0176] In a feasible scenario, referring to Figure 10, the physec network topology in this embodiment can be implemented using the following devices:

[0177] R2 and R4 are Physec-enabled network devices, including a local MIB, a remote MIB, a processing unit, a sending unit, and a receiving unit. The local MIB and remote MIB store Physec information for the local device and neighboring devices, respectively. The processing unit retrieves Physec information from the local and remote MIBs, encapsulates it into LLDP packets, and extracts Physec information from received LLDP packets. The sending unit sends LLDP packets or notification messages, and the receiving unit receives LLDP packets or request messages.

[0178] C1 is the controller, comprising a sending unit, a receiving unit, a processing unit, a storage unit, and a topology presentation. The sending unit sends request messages to network devices, requesting their Physec information. The receiving unit receives notification messages from network devices that include Physec information. The processing unit extracts the Physec information from the notification messages. The storage unit stores the Physec information. The topology presentation determines the Physec network topology from the Physec information.

[0179] Based on the same inventive concept as described above, Figure 11 is a schematic diagram of an information transmission device provided in an embodiment of the present invention, applied to a first network device, the information transmission device comprising:

[0180] The first receiving unit 1101 is used to receive first information reported by the second network device; the first information includes local device status information of the second network device and neighboring device status information of the second network device.

[0181] Receive second information reported by the third network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0182] The first processing unit 1102 is used to construct a physical layer secure network topology based on the first information and the second information.

[0183] In some embodiments of this application, first information is received via a first protocol; the first protocol includes one or more of the following:

[0184] Simple Network Management Protocol;

[0185] Border Gateway Protocol (BGP) Link State Protocol;

[0186] Telemetry protocol.

[0187] In some embodiments of this application, second information is received via a first protocol; the first protocol includes one or more of the following:

[0188] Simple Network Management Protocol;

[0189] Border Gateway Protocol (BGP) Link State Protocol;

[0190] Telemetry protocol.

[0191] Based on the same inventive concept as described above, Figure 12 is a schematic diagram of an information transmission device provided in an embodiment of the present invention, applied to a second network device, the information transmission device comprising:

[0192] The second receiving unit 1201 is used to receive a first message sent by the third network device; the first message carries the local device status information of the third network device.

[0193] The first sending unit 1202 is used to report first information to the first network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0194] In some embodiments of this application, a first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of a third network device.

[0195] In some embodiments of this application, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0196] In some embodiments of this application, the device state type-length-value includes a physical layer security support type field and a physical layer security enable state field.

[0197] In some embodiments of this application, the physical layer security support type field indicates one of the following:

[0198] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0199] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0200] It does not support L1.5 physical layer security and L1 physical layer security;

[0201] Supports L1.5 physical layer security and L1 physical layer security.

[0202] In some embodiments of this application, the physical layer security enable state field indicates one of the following:

[0203] Enable L1 physical layer security and disable L1.5 physical layer security;

[0204] Enable L1.5 physical layer security and disable L1 physical layer security;

[0205] Disable L1.5 physical layer security and L1 physical layer security;

[0206] Enable L1.5 physical layer security and L1 physical layer security.

[0207] In some embodiments of this application, the information transmission device further includes: a second processing unit, configured to generate first information based on device state type-length-value.

[0208] Based on the same inventive concept as described above, Figure 13 is a schematic diagram of the structure of an information transmission device provided in an embodiment of the present invention, applied to a third network device. The information transmission device includes:

[0209] The second sending unit 1301 is used to send a first message to the second network device; the first message carries the local device status information of the third network device.

[0210] The second information is reported to the first network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0211] In some embodiments of this application, a first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of a third network device.

[0212] In some embodiments of this application, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0213] In some embodiments of this application, the device state type-length-value includes a physical layer security support type field and a physical layer security enable state field.

[0214] In some embodiments of this application, the physical layer security support type field indicates one of the following:

[0215] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0216] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0217] It does not support L1.5 physical layer security and L1 physical layer security;

[0218] Supports L1.5 physical layer security and L1 physical layer security.

[0219] In some embodiments of this application, the physical layer security enable state field indicates one of the following:

[0220] Enable L1 physical layer security and disable L1.5 physical layer security;

[0221] Enable L1.5 physical layer security and disable L1 physical layer security;

[0222] Disable L1.5 physical layer security and L1 physical layer security;

[0223] Enable L1.5 physical layer security and L1 physical layer security.

[0224] Based on the hardware implementation of the above program modules, and in order to implement the method on the first network device side of this application embodiment, this application embodiment also provides a first network device, as shown in FIG14, the first network device 1400 including:

[0225] The first communication interface 1401 is capable of exchanging information with the second network device and the third network device;

[0226] The first processor 1402 is connected to the first communication interface 1401 to enable information interaction with the second network device and the third network device, and to execute the methods provided by one or more technical solutions on the first network device side when running computer programs.

[0227] The first memory 1403 is where the computer program is stored.

[0228] Specifically, the first communication interface 1401 receives first information reported by the second network device; the first information includes local device status information of the second network device and neighboring device status information of the second network device.

[0229] Receive second information reported by the third network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0230] The first processor 1402 is used to construct a physical layer secure network topology based on the first information and the second information.

[0231] In some embodiments of this application, first information is received via a first protocol; the first protocol includes one or more of the following:

[0232] Simple Network Management Protocol;

[0233] Border Gateway Protocol (BGP) Link State Protocol;

[0234] Telemetry protocol.

[0235] In some embodiments of this application, second information is received via a first protocol; the first protocol includes one or more of the following:

[0236] Simple Network Management Protocol;

[0237] Border Gateway Protocol (BGP) Link State Protocol;

[0238] Telemetry protocol.

[0239] Of course, in practical applications, the various components in the first network device 1400 are coupled together through the bus system 1404. It can be understood that the bus system 1404 is used to implement communication between these components. In addition to the data bus, the bus system 1404 also includes a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled as bus system 1404 in Figure 14.

[0240] The first memory 1403 in this embodiment is used to store various types of data to support the operation of the first network device 1400. Examples of such data include any computer program used to operate on the first network device 1400.

[0241] The methods disclosed in the above embodiments of this application can be applied to or implemented by the first processor 1402. The first processor 1402 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 1402. The first processor 1402 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1402 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 1403. The first processor 1402 reads the information in the first memory 1403 and completes the steps of the aforementioned method in combination with its hardware.

[0242] In an exemplary embodiment, the first network device 1400 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0243] Based on the hardware implementation of the above program modules, and in order to implement the method on the second network device side of the embodiments of this application, the embodiments of this application also provide a second network device, as shown in FIG15, the second network device 1500 including:

[0244] The second communication interface 1501 is capable of exchanging information with the third network device and the first network device;

[0245] The second processor 1502 is connected to the second communication interface 1501 to enable information interaction with the third network device and the first network device, and to execute the methods provided by one or more technical solutions on the second network device side when running computer programs.

[0246] The computer program is stored in the second memory 1503.

[0247] Specifically, the second communication interface 1501 is used to receive a first message sent by the third network device; the first message carries the local device status information of the third network device.

[0248] Report first information to the first network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

[0249] In some embodiments of this application, a first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of a third network device.

[0250] In some embodiments of this application, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0251] In some embodiments of this application, the device state type-length-value includes a physical layer security support type field and a physical layer security enable state field.

[0252] In some embodiments of this application, the physical layer security support type field indicates one of the following:

[0253] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0254] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0255] It does not support L1.5 physical layer security and L1 physical layer security;

[0256] Supports L1.5 physical layer security and L1 physical layer security.

[0257] In some embodiments of this application, the physical layer security enable state field indicates one of the following:

[0258] Enable L1 physical layer security and disable L1.5 physical layer security;

[0259] Enable L1.5 physical layer security and disable L1 physical layer security;

[0260] Disable L1.5 physical layer security and L1 physical layer security;

[0261] Enable L1.5 physical layer security and L1 physical layer security.

[0262] In some embodiments of this application, the second processor 1502 is used to generate first information based on device state type-length-value.

[0263] Of course, in practical applications, the various components in the second network device 1500 are coupled together through the bus system 1504. It can be understood that the bus system 1504 is used to achieve communication between these components. In addition to the data bus, the bus system 1504 also includes a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled as bus system 1504 in Figure 15.

[0264] The second memory 1503 in this embodiment is used to store various types of data to support the operation of the network device 1500. Examples of such data include any computer program used to operate on the second network device 1500.

[0265] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the second processor 1502. The second processor 1502 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the form of software within the second processor 1502. The second processor 1502 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1502 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium, specifically a second memory 1503. The second processor 1502 reads information from the second memory 1503 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0266] In an exemplary embodiment, the second network device 1500 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0267] Based on the hardware implementation of the above program modules, and in order to implement the method on the third network device side of this application embodiment, this application embodiment also provides a third network device, as shown in FIG16, the third network device 1600 includes:

[0268] The third communication interface 1601 is capable of exchanging information with the first network device and the second network device;

[0269] The third processor 1602 is connected to the third communication interface 1601 to enable information interaction with the first network device and the second network device, and to execute the methods provided by one or more technical solutions on the third network device side when running a computer program.

[0270] The third memory 1603 is where computer programs are stored.

[0271] Specifically, the third communication interface 1601 is used to send a first message to the second network device; the first message carries the local device status information of the third network device.

[0272] The second information is reported to the first network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

[0273] In some embodiments of this application, a first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of a third network device.

[0274] In some embodiments of this application, the second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

[0275] In some embodiments of this application, the device state type-length-value includes a physical layer security support type field and a physical layer security enable state field.

[0276] In some embodiments of this application, the physical layer security support type field indicates one of the following:

[0277] It supports L1 physical layer security but does not support L1.5 physical layer security.

[0278] It supports L1.5 physical layer security but does not support L1 physical layer security.

[0279] It does not support L1.5 physical layer security and L1 physical layer security;

[0280] Supports L1.5 physical layer security and L1 physical layer security.

[0281] In some embodiments of this application, the physical layer security enable state field indicates one of the following:

[0282] Enable L1 physical layer security and disable L1.5 physical layer security;

[0283] Enable L1.5 physical layer security and disable L1 physical layer security;

[0284] Disable L1.5 physical layer security and L1 physical layer security;

[0285] Enable L1.5 physical layer security and L1 physical layer security.

[0286] Of course, in practical applications, the various components in the third network device 1600 are coupled together through the bus system 1604. It can be understood that the bus system 1604 is used to achieve communication between these components. In addition to the data bus, the bus system 1604 also includes a power bus, a control bus, and a status signal bus. However, for clarity, all buses are labeled as bus system 1604 in Figure 16.

[0287] The third memory 1603 in this embodiment is used to store various types of data to support the operation of the network device 1600. Examples of such data include any computer program used to operate on the third network device 1600.

[0288] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the third processor 1602. The third processor 1602 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the form of software within the third processor 1602. The third processor 1602 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1602 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a third memory 1603. The third processor 1602 reads information from the third memory 1603 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0289] In an exemplary embodiment, the third network device 1600 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0290] It is understood that the memories (first memory 1403, second memory 1503, and third memory 1603) in the embodiments of this application can be volatile memories or non-volatile memories, or both. Non-volatile memories can be read-only memories (ROM), programmable read-only memories (PROM), erasable programmable read-only memories (EPROM), electrically erasable programmable read-only memories (EEPROM), magnetic random access memories (FRAM), flash memories, magnetic surface memories, optical discs, or compact disc read-only memories (CD-ROM); magnetic surface memories can be disk storage or magnetic tape storage. Volatile memories can be random access memories (RAM), which are used as external caches.By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM). The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memory.

[0291] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium. For example, it may include a first memory 1403 storing a computer program, which can be executed by a first processor 1402 of a first network device 1400 to complete the aforementioned first network device-side method steps. Another example is a second memory 1303 storing a computer program, which can be executed by a second processor 1102 of a second network device 1100 to complete the aforementioned second network device-side method steps. Yet another example is a third memory 1203 storing a computer program, which can be executed by a third processor 1202 of a third network device 1200 to complete the aforementioned third network device-side method steps. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM.

[0292] It should be noted that the aforementioned computer storage media can be ROM, PROM, EPROM, EEPROM, FRAM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.; or it can be various electronic devices that include one or any combination of the above-mentioned storage media, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0293] Based on the foregoing embodiments, embodiments of this application also provide a computer product, including a computer program, which, when executed by a processor, implements the steps in the information transmission method provided in the embodiments corresponding to FIG3, FIG5, or FIG9.

[0294] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0295] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0296] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0297] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.

[0298] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0299] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0300] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. An information transmission method, characterized in that, Applied to a first network device, the method includes: receiving first information reported by a second network device; the first information includes local device status information of the second network device and neighboring device status information of the second network device; receiving second information reported by a third network device; the second information includes local device status information of the third network device and neighboring device status information of the third network device; and constructing a physical layer secure network topology based on the first information and the second information.

2. The method according to claim 1, characterized in that, The first information is received through a first protocol; the first protocol includes one or more of the following: Simple Network Management Protocol; Border Gateway Protocol Link State Protocol; Telemetry Protocol.

3. The method according to claim 1, characterized in that, The second information is received via a first protocol; the first protocol includes one or more of the following: Simple Network Management Protocol; Border Gateway Protocol Link State Protocol; Telemetry Protocol.

4. An information transmission method, characterized in that, Applied to a second network device, the method includes: receiving a first message sent by a third network device; the first message carrying local device status information of the third network device; and reporting first information to a first network device; the first information including local device status information of the second network device and neighboring device status information of the second network device.

5. The method according to claim 4, characterized in that, The first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of the third network device.

6. The method according to claim 5, characterized in that, The second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

7. The method according to claim 6, characterized in that, The device status type-length-value includes a physical layer security support type field and a physical layer security enable status field.

8. The method according to claim 7, characterized in that, The physical layer security support type field indicates one of the following: supports L1 physical layer security but does not support L1.5 physical layer security; supports L1.5 physical layer security but does not support L1 physical layer security; does not support both L1.5 and L1 physical layer security. Supports L1.5 physical layer security and L1 physical layer security.

9. The method according to claim 7, characterized in that, The physical layer security enable state field indicates one of the following: enabling L1 physical layer security and disabling L1.5 physical layer security; enabling L1.5 physical layer security and disabling L1 physical layer security; disabling both L1.5 and L1 physical layer security; enabling both L1.5 and L1 physical layer security.

10. The method according to claim 6, characterized in that, After receiving the first message sent by the third network device, the process includes: generating the first information based on the device status type-length-value.

11. An information transmission method, characterized in that, Applied to a third network device, the method includes: sending a first message to a second network device; the first message carrying local device status information of the third network device; and reporting second information to a first network device; the second information including local device status information of the third network device and neighboring device status information of the third network device.

12. The method according to claim 11, characterized in that, The first message is received via a second protocol; the first message includes a newly added information field; the newly added information field carries the local device status information of the third network device.

13. The method according to claim 12, characterized in that, The second protocol includes a link layer discovery protocol; the information field includes device status type-length-value.

14. The method according to claim 13, characterized in that, The device status type-length-value includes a physical layer security support type field and a physical layer security enable status field.

15. The method according to claim 14, characterized in that, The physical layer security support type field indicates one of the following: supports L1 physical layer security but does not support L1.5 physical layer security; supports L1.5 physical layer security but does not support L1 physical layer security; does not support both L1.5 and L1 physical layer security. Supports L1.5 physical layer security and L1 physical layer security.

16. The method according to claim 14, characterized in that, The physical layer security enable state field indicates one of the following: enabling L1 physical layer security and disabling L1.5 physical layer security; enabling L1.5 physical layer security and disabling L1 physical layer security; disabling both L1.5 and L1 physical layer security; enabling both L1.5 and L1 physical layer security.

17. A first network device, comprising a first communication interface and a first processor; wherein, The first communication interface is used to receive first information reported by the second network device; the first information includes local device status information of the second network device and neighboring device status information of the second network device; and to receive second information reported by the third network device; the second information includes local device status information of the third network device and neighboring device status information of the third network device. The first processor is configured to construct a physical layer secure network topology based on the first information and the second information.

18. A second network device, comprising a second communication interface and a second processor; wherein, The second communication interface is used to receive a first message sent by a third network device; the first message carries the local device status information of the third network device; and reports first information to the first network device; the first information includes the local device status information of the second network device and the neighboring device status information of the second network device.

19. A third network device, comprising a third communication interface and a third processor; wherein, The third communication interface is used to send a first message to the second network device; the first message carries the local device status information of the third network device; and to report second information to the first network device; the second information includes the local device status information of the third network device and the neighboring device status information of the third network device.

20. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 3, 5 to 10, or 11 to 16.

21. A computer product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 3, 5 to 10, or 11 to 16.