Data transmission path arrangement method, data cross-domain transmission method, device and system

By obtaining network identification information at the border gateway device and orchestrating the data transmission path of the target network domain, the problem of low visibility and controllability of data transmission between different network domains is solved, thereby improving the controllability and efficiency of cross-domain data transmission and ensuring that network topology privacy is not leaked.

CN121967289APending Publication Date: 2026-05-01CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2026-01-13
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

During data transmission between different network domains, the visibility and controllability of data transmission are reduced because each network domain conceals its own network topology information, making it difficult to meet the network transmission needs of the requesting party.

Method used

By acquiring network identification information, including network demand information, at the border gateway device, orchestrating data transmission paths within the target network domain, and generating network transmission strategies, the system achieves a shift from passive reception to proactive sensing and orchestration. This ensures reduced routing latency and transmission jitter of data packets within the domain, thereby improving the determinism and efficiency of cross-domain data transmission.

Benefits of technology

It achieves controllability and traceability of cross-domain data transmission paths, improves the efficiency and security of cross-domain data transmission, and ensures that network topology privacy is not leaked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967289A_ABST
    Figure CN121967289A_ABST
Patent Text Reader

Abstract

The invention provides a data transmission path arrangement method, a data cross-domain transmission method, a data cross-domain transmission device and a data cross-domain transmission system, and relates to the technical field of network communication, the data transmission path arrangement method comprises the following steps: receiving network identification information sent by border gateway equipment, the boundary gateway device is a gateway device between the source network domain and the target network domain, and the network identification information is extracted by the boundary gateway device from a packaging message sent by a network node of the source network. The network identification information comprises network demand information. And arranging a data transmission path of the target network domain and generating a network transmission strategy based on the network demand information. And sending the network transmission strategy to the network node in the data transmission path. Therefore, the traceability of the data transmission path can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network communication technology, and in particular to data transmission path arrangement methods, cross-domain data transmission methods, apparatus and systems. Background Technology

[0002] With the development of information technology, data has gradually become a core element driving value creation, and data sharing and circulation is a key issue in the current development of the digital economy. Data sharing and circulation refers to the exchange, transmission, and utilization of data between different networks based on specific rules and mechanisms, aiming to break down data barriers and promote the efficient flow of data.

[0003] In this process, cross-network data transmission, as a crucial supporting link for data sharing and circulation, refers to the transmission of data between different network domains. However, for security reasons, each network domain typically conceals its own network topology information. This limitation reduces the visibility and controllability of data transmission between different network domains, thus posing a challenge to ensuring the quality of cross-domain data transmission. Summary of the Invention

[0004] This application provides a data transmission path arrangement method, a data cross-domain transmission method, apparatus, and system, which can realize the controllability of the data cross-domain transmission path and improve the quality of data cross-domain transmission.

[0005] Firstly, this application provides a data transmission path orchestration method applied to a network management device in a target network domain. The method includes: receiving network identification information sent by a border gateway device. The border gateway device is a gateway device between the source network domain and the target network domain. The network identification information is extracted by the border gateway device from encapsulated packets sent by network nodes in the source network. The network identification information includes network requirement information. Based on the network requirement information, the method orchestrates data transmission paths within the network domain where the target network management device is located and generates a network transmission policy. The method then sends the network transmission policy to the network nodes in the data transmission path.

[0006] The data transmission path orchestration method provided in this application obtains network identification information (including network requirement information) from the external (source) network from the border gateway device, enabling the network management device of the target network domain to perceive and understand the cross-domain data transmission requirements. Compared with related technologies, this solution realizes a shift from a "passive reception and blind forwarding" transmission mode to an "active perception and orchestration" mode. This allows the network management device to calculate and pre-set an optimal intra-domain transmission path for data packets before they arrive at the network domain, thereby significantly reducing the routing latency and transmission jitter of data packets within the domain and effectively improving the determinism, predictability, and overall efficiency of cross-domain data transmission.

[0007] One possible implementation method further includes: receiving data flow information sent by each network node in the data transmission path. This data flow information is sent by the network nodes in the data transmission path to the network management device after transmitting encapsulated packets carrying network identification information based on the network transmission policy. Based on the data flow information sent by each network node in the data transmission path, a transmission path record for the encapsulated packets is generated.

[0008] One possible implementation is that the data flow information includes: device information, transmission interface information, and transmission time information of the network nodes through which the data flows.

[0009] One possible implementation, the method further includes: receiving a transmission path query request from a transmission path monitoring device, and sending a transmission path record encapsulated in a message to the transmission path monitoring device. The transmission path monitoring device is communicatively connected to the network management device.

[0010] Secondly, this application provides a method for cross-domain data transmission, applied to a border gateway device between a source network domain and a target network domain, wherein the border gateway device is connected to a first network node in the source network domain and a second network node in the target network domain. The method includes: receiving an encapsulated packet sent by the first network node and obtaining network identification information in the encapsulated packet. The network identification information includes cross-domain information. The cross-domain information is used to indicate whether the encapsulated packet is transmitted across domains. Data flow information is sent to a first network management device. The data flow information is sent by the network node to the network management device after transmitting the encapsulated packet carrying the network identification information based on a network transmission policy. The first network management device is the network management device of the source network domain. When the cross-domain information indicates that the encapsulated packet is transmitted across domains, the first tunnel information on the outer layer of the encapsulated packet is stripped to obtain the user packet. The first tunnel information refers to the tunnel path traversed by the user packet during transmission in the source network domain. Network identification information is sent to a second network management device. The second network management device is the network management device of the target network domain. Based on the network transmission policy sent by the second network management device, the user packet is sent to the second network node.

[0011] The cross-domain data transmission method provided in this application, through network identification information, enables border gateway devices to quickly determine whether data needs to be transmitted across domains. Based on this, the border gateway device can selectively strip the first tunnel information of the source network domain, effectively protecting the topology privacy of the source network domain from being leaked, and also transmitting network identification information containing key requirements to the network management device of the target network domain. This allows the network management device of the target network domain to formulate a network transmission strategy that meets the data transmission requirements with the help of the network identification information, achieving collaborative adaptation of cross-domain transmission strategies, thereby improving the efficiency of cross-domain data transmission.

[0012] Thirdly, this application provides a data transmission path orchestration apparatus, which includes various functional modules for the method described in the first aspect above.

[0013] Fourthly, this application provides a data cross-domain transmission apparatus, which includes various functional modules for the method described in the second aspect above.

[0014] Fifthly, this application provides a cross-domain data transmission system, comprising: a network management device and a border gateway device. The network management device is configured to perform the method described in the first aspect above, and the border gateway device is configured to perform the method described in the second aspect above.

[0015] In a sixth aspect, this application provides an electronic device comprising: a memory, a transceiver, and a processor; the memory, transceiver, and processor are configured to collaboratively execute the methods described in any one of the first and second aspects and their possible implementations.

[0016] In a seventh aspect, this application provides a readable storage medium comprising: software instructions. When the software instructions are executed in an electronic device, they cause the electronic device to perform the method described in any one of the first and second aspects described above and their possible implementations.

[0017] Eighthly, this application provides a computer program product comprising computer instructions. When the computer instructions are executed on an electronic device, the electronic device causes the electronic device to perform the method described in any one of the first and second aspects and their possible implementations.

[0018] The beneficial effects of the third to eighth aspects mentioned above can be referred to the first and second aspects, and will not be repeated here. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a schematic diagram illustrating the composition of a cross-domain data transmission system provided in an embodiment of this application; Figure 2 A flowchart illustrating a data transmission path orchestration method provided in an embodiment of this application; Figure 3 A flowchart illustrating another data transmission path orchestration method provided in an embodiment of this application; Figure 4 A schematic diagram illustrating the composition of an encapsulated message provided in an embodiment of this application; Figure 5 A flowchart illustrating another data transmission path orchestration method provided in this application embodiment; Figure 6 A flowchart illustrating a cross-domain data transmission method provided in an embodiment of this application; Figure 7 A schematic diagram illustrating the implementation process of a cross-domain data transmission method provided in this application embodiment; Figure 8 A schematic diagram of the composition of a data transmission path orchestration device provided in an embodiment of this application; Figure 9 This is a schematic diagram illustrating the composition of a cross-domain data transmission device provided in an embodiment of this application; Figure 10 This is a schematic diagram of the composition of an electronic device provided in an embodiment of this application. Detailed Implementation

[0021] Hereinafter, the terms "first," "second," and "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first," "second," or "third," etc., may explicitly or implicitly include one or more of that feature. In the description of this embodiment, unless otherwise stated, "a plurality of" means two or more.

[0022] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0023] In addition, for ease of understanding, the technical terms involved in the embodiments of this application will be introduced below.

[0024] 1. Network management equipment is the core management equipment in network operation. It is mainly responsible for allocating, monitoring, and maintaining various network resources within its network area to ensure the normal operation and stable performance of the network. It can adjust relevant parameters for data transmission based on the real-time status of the network to adapt to different network loads and service requirements.

[0025] 2. Border gateway devices are connection devices located at the boundaries of different networks, acting as bridges connecting different networks. They can process and forward data flows entering and leaving the network, ensuring that data can be transmitted compliantly and securely between different networks, while also undertaking certain network isolation and protection functions.

[0026] During cross-domain data transfer, because the network topology information of each network domain is not publicly accessible, the data transmission path arrangement is uncontrollable. It relies solely on the network management equipment of each network domain to autonomously arrange paths and distribute transmission policies. Therefore, existing cross-domain data transmission methods are insufficient to meet the network transmission needs of the requesting party.

[0027] Therefore, improving the controllability of path orchestration for cross-domain data transmission is an urgent problem to be solved.

[0028] In view of this, the present application provides a data transmission path orchestration method that uses network identification information to carry network demand information, enabling network management and control equipment to perceive the network demand for data transmission and realize the customization of transmission paths.

[0029] First, the application scenarios of the embodiments of this application will be introduced.

[0030] This application provides a cross-domain data transmission system, such as... Figure 1 As shown, the system includes: target node 110, data transmission management device 120, source node 130, first network node 140, first network control device 150, border gateway device 160, second network control device 170, and second network node 180.

[0031] It should be noted that the first network node 140 and the first network management device 150 belong to the source network domain, the second network management device 170 and the second network node 180 belong to the target network domain, and the border gateway device 160 is a device between the source network domain and the target network domain, which can be understood as a communication bridge between the source network domain and the target network domain.

[0032] It should also be noted that the source network domain refers to the network domain connected to the source node, while the target network domain refers to the network domain connected to the target node.

[0033] In some embodiments, the first network node 140 may include an edge gateway device, which refers to a gateway device connected to the source node.

[0034] The data transmission management device 120 is used to determine the address of the source node 130 and generate network identification information based on the data transmission request information sent by the target node 110.

[0035] Specifically, the data transmission request information includes the data request type and the data transmission requirements.

[0036] One possible implementation is that the data transmission management device 120 maintains a data type-source address mapping table, which can determine the address of the source node 110 of the data requested in the data transmission request based on the data requirement type. Furthermore, it determines the data requirement information by parsing the data transmission request. Finally, it creates network identification information based on the data transmission request to identify the data transmission process corresponding to that request.

[0037] It should be noted that the data transmission management device 120 can be implemented using a distributed architecture. It can be a dedicated hardware device deployed independently or a virtualization service deployed on a cloud platform. This application embodiment does not limit the specific form of the data transmission management device.

[0038] Source node 130 is used to configure network identification information into user packets and send user packets to the first network node 140.

[0039] When the first network node 140 is an edge gateway device, it is used to obtain network identification information from user packets and send the network identification information to the first network management device 150.

[0040] It should be noted that when the first network node 140 is an edge gateway device, it needs to transmit the network identification information in the received user packets to the first network management device 150 so that the first network management device 150 can arrange the transmission path (data transmission path) of the user packets according to the network identification information.

[0041] The first network management device 150 is used to arrange the first data transmission path within the source network domain based on the network demand information in the network identification information, and send the first network transmission strategy to the first network node 140.

[0042] It should be noted that network management equipment is responsible for managing and controlling network nodes within its network domain, as well as orchestrating data transmission paths based on network requirements. A network domain refers to a network area covered by the same set of network management rules, security policies, or management boundaries; it is a logical or physical scope defined in network management to achieve refined control.

[0043] In some embodiments, network domains can be divided based on multiple dimensions. For example, when divided based on physical location, each network domain corresponds to an actual geographical area. As another example, when divided based on functional attributes, each network domain represents data transmission tasks for different business scenarios, such as an office network domain, a production network domain, and a physical network device network domain. This application does not limit the specific form of the network domain.

[0044] When the first network node 140 is an edge gateway device, it is also used to obtain first tunnel information from the first network transmission policy, and encapsulate the first tunnel information in the outer layer of the user message to obtain a first encapsulated message. The first encapsulated message is then sent to other first network nodes 140.

[0045] The first network node 140 is used to transmit a first encapsulated message based on a first network transmission strategy. It also sends data flow information of the first encapsulated message to the first network management device 150.

[0046] The first network control device 150 is further configured to receive data flow information sent by each first network node 140 in the first data transmission path. Based on the data flow information sent by each first network node 140, a transmission path record of the first encapsulated message is generated.

[0047] Border gateway device 160 is configured to: receive a first encapsulated packet sent by a first network node 140, and obtain network identification information from the first encapsulated packet. The network identification information includes cross-domain information. This cross-domain information indicates whether the first encapsulated packet is transmitted across domains. It then sends data flow information to a first network management device 150. If the cross-domain information indicates that the first encapsulated packet is transmitted across domains, it strips the first tunnel information from the outer layer of the first encapsulated packet to obtain the user packet. Finally, it sends the network identification information to a second network management device 170.

[0048] The second network management device 170 is used to acquire network identification information, arrange a second data transmission path within the target network domain based on network demand information, and send a second network transmission strategy to the second network node 180.

[0049] The border gateway device 160 is also used to send user messages to the second network segment based on the second network transmission strategy.

[0050] The second network node 180 is used to extract second tunnel information from the second network transmission strategy, encapsulate the second tunnel information in the outer layer of user packets to obtain a second encapsulated packet, and transmit the second encapsulated packet based on the second network transmission strategy. It also sends data flow information of this node to the second network management device 170.

[0051] The second network management device 170 is also used to receive data flow information sent by each second network node 180 in the second data transmission path. Based on the data flow information sent by each second network node 180, a transmission path record for the second encapsulated message is generated.

[0052] Target node 110 receives the second encapsulated message to complete the cross-domain data transmission.

[0053] In some embodiments, the first network management device or the second network management device may be a software defined networking (SDN) controller, or a network functions virtualization (NFV) manager, a network slice manager, a centralized gateway controller, a cloud network controller, etc. The specific form of the network management device is not limited in the embodiments of this application.

[0054] For a detailed description of the above system, please refer to the following text. Figure 2 as well as Figure 6 This will not be elaborated upon here.

[0055] The data transmission path arrangement method provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0056] like Figure 2 As shown, when this method is applied to network management devices, it includes the following: S101. Receive network identification information sent by the border gateway device.

[0057] The border gateway device is a gateway device between the source network domain and the target network domain. It is used to implement protocol conversion, policy mapping, and security isolation between different network domains during data transmission. This application does not limit the specific form of the border gateway device.

[0058] Network identification information is extracted by the border gateway device from the encapsulated packets sent by network nodes in the source network. (As mentioned above...) Figure 1 As can be seen, network identification information is generated by the data transmission management device based on the data transmission request information sent by the target node, and configured by the source node in the encapsulated message for transmission. When the encapsulated message is transmitted to the border gateway device, the border gateway device extracts the network identification information from the encapsulated message and sends it to the border gateway device of the target network domain.

[0059] Network identification information includes network requirement information. During cross-domain data transmission, network requirement information can be used to identify the network (quality) requirements for cross-domain data transmission and to identify the cross-domain data transmission path.

[0060] In some embodiments, network requirement information may include: transmission path status information, transmission path constraint information, and transmission path resource allocation and scheduling information.

[0061] The transmission path status information may include: transmission rate, latency, jitter, link bandwidth utilization, and network node computing resource utilization. Transmission path constraint information may include: a list of required network nodes, protocol type, and transmission path type. Transmission resource allocation and scheduling information may include: bandwidth reservation for the transmission path, port locking of network nodes in the transmission path, rules for triggering load threshold processing, and resource priority. In some embodiments, the network identification information may be represented as: an instruction label in the IPv6 extended header or SRv6 segment routing, or structured parameters in JSON format. This information can be embedded in the outer header of the encapsulated message or application layer metadata for the identification and processing of cross-domain network nodes.

[0062] Depend on Figure 1 As can be seen from S101, the network management device in the source network domain can obtain network identification information from the edge gateway device to which the source node communicates. Similarly, the network management device in the target network domain can obtain it from the border gateway device.

[0063] S102. Based on network demand information, arrange the data transmission paths of the target network domain and generate data transmission strategies.

[0064] The data transmission path is a sequence of nodes built from multiple network nodes.

[0065] A network transmission path refers to a complete pathway consisting of a series of network nodes (such as routers and switches) and their connection sequence. This path is designed to meet the performance (such as low latency, high bandwidth) or security requirements contained in network demand information.

[0066] Network transmission policies refer to a set of specific configuration instructions generated to enable data forwarding along the aforementioned path. These policies are distributed to each network node in the path to guide their forwarding behavior, and may include, but are not limited to, traffic identification rules, next-hop addresses, quality of service policies, and security rules.

[0067] In some embodiments, the data transmission path includes a tunnel path, which is a logical transmission path whose core is to build a virtual channel in a public or shared network through encapsulation technology, so that user messages can be transmitted securely and independently as if they were in a dedicated link.

[0068] Specifically, when a user message enters a tunnel or is transmitted along a data transmission path, its outer layer is encapsulated with tunnel information. This tunnel information includes tunnel identifier, endpoint information, protocol type, security parameters, and transmission control information, which are used to ensure the directional transmission, secure isolation, and correct parsing of the message within the tunnel.

[0069] One possible implementation is that the network management device can first compile multiple candidate data transmission paths based on the constraints of transmission paths in the network demand information. Then, it selects the candidate data transmission path that best satisfies the status information and resource allocation and scheduling information in the network demand information as the final data transmission path.

[0070] Another possible implementation is that the network management device can pre-configure a path orchestration model. This model is trained using training data including historical network demand information and corresponding historical orchestrated transmission paths, enabling it to learn the mapping relationship between network demand information and optimal transmission paths. The network management device can then use the demand information as input to this path orchestration model and obtain the data transmission path output by the model.

[0071] In one possible implementation, the network transmission policy can be based on the finally determined data transmission path, obtained by transforming the abstract path into specific device instructions. Specifically, the control device resolves the path into the forwarding rules (such as flow table entries and ACL rules) required by each network node on the path, and the set of these rules constitutes the deployable network transmission policy.

[0072] This application does not impose any restrictions on network transmission paths or network transmission strategies.

[0073] S103. Send the network transmission strategy to the network nodes in the data transmission path.

[0074] It should be noted that the data transmission strategy is a standardized operating procedure for each network node in the transmission path. It specifies the forwarding control logic, resource scheduling rules, security protection mechanisms, and anomaly response strategies of each node when processing data on that path.

[0075] In some embodiments, network transmission policies may include: routing flow tables, access control lists, resource reservation configurations, and tunnel information, etc.

[0076] One possible implementation, where the network management device is specifically an SDN controller, is to send network transmission policies to network nodes via the Open Flow protocol.

[0077] The data transmission path orchestration method provided in this application obtains network identification information (including network requirement information) from the external (source) network from the border gateway device, enabling the network management device of the target network domain to perceive and understand the cross-domain data transmission requirements. Compared with related technologies, this solution realizes a shift from "passive reception and blind forwarding" to "active perception and orchestration" of the transmission mode. This allows the network management device to calculate and pre-set an optimal intra-domain transmission path for data packets before they arrive at the network domain, thereby significantly reducing the routing latency and transmission jitter of data packets within the domain and effectively improving the determinism, predictability, and overall efficiency of cross-domain data transmission.

[0078] Additionally, it should be noted that the embodiments in this application describe the data path arrangement method when crossing target network domains from the perspective of the network management device of the target network domain. In other embodiments, the method can also be applied to the network management device of the source network domain. In this case, the network identification information is obtained from the edge gateway device between the source network domain and the source node.

[0079] In some embodiments, the network management device can also identify data transmission information within the network domain based on network identification information, thereby enabling the tracing of data transmission paths across domains. In this case, such as... Figure 3 As shown, after S103, the method may further include the following steps: S104. Receive data flow information sent by each network node in the data transmission path.

[0080] Among them, the data flow information is sent by the network node to the network management and control equipment after transmitting the encapsulated message carrying the network identification information based on the network transmission policy.

[0081] It should be noted that encapsulated messages refer to user messages with tunnel information encapsulated in the outer layer. These encapsulated messages can be tunneled in the network domain using the tunnel information encapsulated in the outer layer.

[0082] For example, the structure of an encapsulated message is as follows: Figure 4 As shown, the encapsulated message includes: tunnel information 310, other fields 320, network identification information 330, and payload information 340. Specifically, the network identification information includes network requirement information 331, network cross-domain information 332, and network cross-domain encoding information 333. Furthermore, after removing the tunnel information 310 from the encapsulated message, the other fields 320, network identification information 330, and payload information 340 can form the user message 350.

[0083] Among them, other fields 320 are used to carry auxiliary control information in user messages, such as user message checksums, message timing markers, priority identifiers, etc. Although this information does not directly participate in the core business logic, it provides support for the reliable transmission of user messages. Payload information 340 represents the core business data that the user actually needs to transmit, such as application layer text messages, file content, command codes, etc. It is the most practically valuable part of the entire message transmission and the core content of the interaction between the source node and the target node.

[0084] In some embodiments, the data flow information includes: device information, transmission interface information, and transmission time information of the network nodes through which the data flows.

[0085] Among these, device information refers to the device information of network nodes that transmit data based on data transmission strategies, including device identifiers and network status indicators during transmission. Transmission interface information refers to the port information used by network nodes for data transmission, as well as port status indicators. Transmission time information refers to the start and end times of data transmission by network nodes.

[0086] It should be noted that network nodes in a network domain may transmit different data transmission tasks. Therefore, when reporting data flow information, the network identification information in the encapsulated message can be reported together with the data flow information to the network management device, so that the network management device can identify the data flow information of different data transmission tasks through the network identification information.

[0087] In some embodiments, when acquiring network identification information, the network management device can convert it into a unique hash code and store it locally. Then, when the network management device receives data flow information, it can convert the received network node's network identification information into a hash code following the same rules and compare it with the locally stored set of unique hash codes to identify the data transmission task (path) corresponding to the data flow information.

[0088] S105. Based on the data flow information sent by each network node in the data transmission path, generate a transmission path record for the encapsulated message.

[0089] One possible implementation, as described in the foregoing embodiments (S104), is that the network management device can identify the data flow information of network nodes in the same data transmission path based on a unique hash code. Then, the data flow information of network nodes in the same data transmission path is sorted by time (from earliest to latest) according to the transmission start time in each data flow information to generate a complete transmission path record of the encapsulated message in this network domain.

[0090] It should be understood that this scheme instructs network management equipment to generate data transmission paths by using network demand information within the network identification information. This enables on-demand customization and flexible adjustment of data transmission paths, improving the utilization rate of network resources. Furthermore, the network identification information can also identify data transmission paths, allowing network management equipment to receive and identify the data flow information reported by each network node in the network transmission path. Based on this flow information, a complete transmission path record can be generated, enabling the tracking and tracing of data transmission paths. This solves the problem of fragmented path information and difficulty in unified management in traditional cross-network domain transmission, providing a reliable basis for data transmission security supervision and anomaly investigation.

[0091] In some embodiments, after the encapsulated message completes cross-domain transmission, the transmission path records generated by each network management device can be concatenated to form a complete cross-domain data transmission path. In this case, such as... Figure 5 As shown, the method further includes: S106. Receive the transmission path query request information sent by the transmission path monitoring device, and send the transmission path record of the encapsulated message to the transmission path monitoring device.

[0092] The transmission path monitoring device is communicatively connected to the network control device.

[0093] In some embodiments, the transmission path monitoring device is typically a service platform deployed in the network operation and maintenance center. As a centralized traceability system, it is used to collect, associate, and store path records reported by various domains, so that a complete end-to-end cross-domain transmission path can be quickly pieced together during querying, realizing global visual monitoring, auditing, and traceability.

[0094] One possible implementation is that the transmission path query request information can carry network identification information. The network management device can convert the network identification information into a unique hash code and match it with the unique hash code of the network identification information stored locally. Then, it sends the transmission path record corresponding to the successfully matched network identification information to the transmission path monitoring device.

[0095] In some embodiments, when returning path records, network management devices can simultaneously report key performance indicators of the path during data transmission, such as processing latency, link jitter, or packet loss rate at key nodes along the path. This performance data, combined with path records, provides valuable data support for monitoring devices to perform global transmission quality analysis and fault localization.

[0096] It should be noted that this embodiment implements a cross-domain path record traceability function. Each network domain can flexibly choose whether to enable this function based on actual operation and maintenance or regulatory needs. This mechanism provides a way to achieve observability of cross-domain transmissions. While ensuring the concealment of internal topology, network domains can provide summarized or confirmed path information to regulators as needed.

[0097] In one possible implementation, to balance global oversight with intra-domain topology privacy, network management devices can perform data anonymization processing on path records before sending them. For example, specific device identifiers can be replaced with rule-based anonymized identifiers, or differential privacy techniques can be used to add controllable noise to the path. In this way, the management device can verify the accessibility of the path without needing to know the precise intra-domain topology.

[0098] It should be understood that S106 enables the transmission path monitoring device to aggregate transmission path records from different network domains, thereby constructing a complete transmission path for data throughout the entire cross-domain transmission process. This improves the traceability of data transmission paths across domains.

[0099] The data cross-domain transmission method provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0100] In some embodiments, the data transmission path orchestration method orchestrates data transmission paths within a network domain using network identification information, which can solve the problems of controllability and traceability of cross-domain data transmission paths. Simultaneously, by transmitting network identification information between different network domains, network requirement information can also be passed to the next network domain, ensuring consistency in customized network transmission strategies across different network domains, thereby improving the efficiency of cross-domain data transmission.

[0101] like Figure 6 As shown, when this cross-domain data transmission method is applied to a border gateway device, it includes the following: S201. Receive the encapsulated message sent by the first network node and obtain the network identification information in the encapsulated message.

[0102] The network identification information includes cross-domain information, which indicates whether the encapsulated message is transmitted across domains. The transmission path monitoring equipment communicates with the network control equipment.

[0103] It should be noted that the first network node refers to a network node in the source network domain. The first network node may include an edge gateway device, which is a gateway device connected to the source node. The edge gateway device differs from other first network nodes in that it needs to send network identification information to the first network management device to determine the data transmission strategy and encapsulate the tunnel information in the data transmission strategy within the user packet to form an encapsulated packet.

[0104] In some embodiments, the network cross-domain information includes network cross-domain information and network cross-domain encoding information. The network cross-domain information indicates whether the encapsulated message is transmitted across domains. The network cross-domain encoding information includes the encoding of the target network domain, which helps the border gateway device identify the topological location of the target network domain.

[0105] One possible implementation is that the network cross-domain information can specifically take the value of 0 or 1, where a data cross-domain information of 1 indicates that the encapsulated message is for cross-domain transmission.

[0106] S202, Send data flow information to the first network control device.

[0107] It should be noted that after the border gateway device receives the encapsulated message, it means that the source network domain has completed the transmission of the encapsulated message. At this time, the border gateway device needs to encapsulate the received encapsulated message, the receiving time, the receiving port, and its own device information into data flow information and send it to the first network management device.

[0108] Specifically, this step can be referred to. Figure 3 S104 in the middle.

[0109] S203. When the network cross-domain information indicates that the encapsulated message is for cross-domain transmission, the first tunnel information of the outer layer of the encapsulated message is stripped to obtain the user message.

[0110] The first tunnel information is used to indicate the tunnel path that the user message passes through during transmission in the source network domain.

[0111] It should be noted that, in order to ensure that the network topology information of the source network domain is not perceived by the target network domain, the border gateway device needs to strip the first tunnel information from the encapsulated message when transmitting encapsulated messages across domains.

[0112] S204. Send network identification information to the second network control device.

[0113] It should be noted that before user packets are transmitted to the target network domain, a second network management device needs to orchestrate the data transmission path for the target network domain. This is based on the preceding text. Figure 1 As can be seen from S102, the second network management device can determine the network transmission strategy based on the network identification information, so the border gateway device needs to send the network identification to the second network management device.

[0114] S205. Based on the network transmission policy sent by the second network management device, send user messages to the second network section.

[0115] It should be noted that, based on the preceding text... Figure 1As shown in S103, the second network management device needs to distribute the network transmission policy to the network nodes in the network transmission path. At this time, since the border gateway device has user packets to be transmitted, it is necessary to make the border gateway device the first node in the data transmission path of the target network domain and distribute the network transmission policy to the border gateway device.

[0116] The cross-domain data transmission method provided in this application uses network identifiers to carry cross-domain information, enabling border gateway devices to quickly and accurately identify whether data needs to be transmitted across domains, providing a clear basis for subsequent path processing and policy execution. Based on this, border gateway devices can selectively extract the first tunnel information of the source network domain, effectively protecting the topology privacy of the source network domain from leakage, while also transmitting network identifier information containing key requirements to the network management device of the target network domain. This allows the network management device of the target network domain to accurately formulate network transmission policies that meet its requirements using the network identifier information, achieving collaborative adaptation of cross-domain transmission policies, and thus significantly improving the security, accuracy, and overall efficiency of cross-domain data transmission.

[0117] In an exemplary embodiment, for Figure 1 The system described above, in conjunction with the data transmission path orchestration method provided in the embodiments of this application, also provides a schematic diagram of the implementation process of a cross-domain data transmission method, the process as follows: Figure 7 As shown, it specifically includes the following: S1. Send data transmission request information.

[0118] It should be noted that the target node can also be referred to as the data access device of the data requester, and the source node can also be referred to as the data access device of the data provider.

[0119] S2. Generate and send network identification information.

[0120] Based on the received data transmission request, the data transmission management device generates network identification information and sends it to the source node.

[0121] S3. Configure network identification information for user messages.

[0122] S4. Transmit the user message to the source network domain.

[0123] S5. Send network identification information.

[0124] Send network identification information to the first network control device in the source network domain.

[0125] S6. Send network transmission path.

[0126] The first network management device in the source network domain arranges the data transmission path of the source network domain based on the network identification information, and sends the network transmission path to the first network node in the data transmission path of the source network domain.

[0127] In this data transmission path, the first network node is the edge gateway device. (That is, the user message is transmitted starting from the edge gateway device).

[0128] Additionally, if the network identification information indicates that the user message is a cross-domain transmission, the edge gateway device of the source network domain needs to identify the boundary gateway device between the source network domain and the destination network domain as the tail node of the network transmission path.

[0129] S7. Generate and transmit the encapsulated message.

[0130] The edge gateway device of the source network domain encapsulates the tunnel information into the user message according to the network transmission path to obtain the encapsulated message, and begins to transmit the encapsulated message to the first network node.

[0131] It should be understood that, for the convenience of describing the process by which the edge gateway device obtains network identification information, this embodiment describes the edge gateway device as a separate device. In actual embodiments, the edge gateway device can be categorized as the first network node.

[0132] S8. Send the encapsulated message.

[0133] If the data transmission process is a cross-domain transmission, the encapsulated message will be sent to the border gateway device.

[0134] S9. Generate a data transmission path record for the source network domain.

[0135] Simultaneously, the first network control device acquires the data flow information reported by the source network domain edge gateway device, the first network node, and the border gateway device, and generates a data transmission path record.

[0136] S10. Receive the encapsulated message and parse the message to obtain the user message and network identification information.

[0137] From the encapsulated message, the network transmission path of the source network domain encapsulated in the source network domain is extracted to obtain the user message (i.e., the user message is the user message initially sent by the source node), and the network identifier in the user message is obtained.

[0138] The following steps describe the transmission process of user messages in the target network domain. S11-S13 below can refer to S5-S7 above.

[0139] S11. Send network identification information.

[0140] Send network identification information to the second network management device in the source network domain.

[0141] S12, Send network transmission path.

[0142] S13. Generate and transmit the encapsulated message.

[0143] S14. Receive the encapsulated message and parse the encapsulated message to obtain the user message.

[0144] The target node receives the encapsulated message transmitted from the target network domain, parses it to obtain the user message, and completes the data transmission process.

[0145] S15. Obtain the data transmission path record of the target network domain.

[0146] After the data transmission process is completed, the second network management device obtains the data flow information reported by the border gateway device and the first network node (including the edge gateway device of the target network domain) and generates a data transmission path record for the target network domain. The second network node is the network node in the data transmission strategy of the target network domain.

[0147] In an exemplary embodiment, such as Figure 8 As shown in the figure, this application embodiment also provides a data transmission path recording device. The data transmission path recording device includes an acquisition module 810 and a processing module 820.

[0148] The acquisition module 810 receives network identification information sent by the border gateway device. The border gateway device is the gateway device between the source network domain and the destination network domain. The network identification information is extracted by the border gateway device from the encapsulated packets sent by the network nodes of the source network. The network identification information includes network requirement information.

[0149] The processing module 820, based on network demand information, orchestrates data transmission paths for the target network domain and generates network transmission strategies. It then sends these strategies to network nodes along the data transmission paths.

[0150] In one possible implementation, the processing module 820 is further configured to: receive data flow information sent by each network node in the data transmission path. This data flow information is sent by the network nodes in the data transmission path to the network management device after transmitting encapsulated packets carrying network identification information based on the network transmission policy. Based on the data flow information sent by each network node in the data transmission path, a transmission path record for the encapsulated packets is generated.

[0151] One possible implementation is that the data flow information includes: device information, transmission interface information, and transmission time information of the network nodes through which the data flows.

[0152] In one possible implementation, the processing module 820 is further configured to: receive a transmission path query request from the transmission path monitoring device, and send a transmission path record containing an encapsulated message to the transmission path monitoring device. The transmission path monitoring device is communicatively connected to the network management device.

[0153] In an exemplary embodiment, such as Figure 9 As shown in the figure, this application embodiment also provides a cross-domain data transmission device. The cross-domain data transmission device includes a receiving module 910 and a sending module 920.

[0154] The receiving module 910 receives the encapsulated message sent by the first network node and obtains the network identification information in the encapsulated message. The network identification information includes cross-domain information. The cross-domain information is used to indicate whether the encapsulated message is transmitted across domains.

[0155] The sending module 920 sends data flow information to the first network management device. This data flow information is sent by the network node to the network management device after transmitting an encapsulated message carrying network identification information based on the network transmission policy. The first network management device is the network management device of the source network domain. When the network cross-domain information indicates that the encapsulated message is being transmitted across domains, the first tunnel information on the outer layer of the encapsulated message is stripped to obtain the user message. The first tunnel information refers to the tunnel path traversed by the user message during transmission in the source network domain. The module then sends network identification information to the second network management device. The second network management device is the network management device of the target network domain. Based on the network transmission policy sent by the second network management device, the module sends the user message to the second network node.

[0156] In an exemplary embodiment, Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 10 As shown, the electronic device includes: a memory 1001, a transceiver 1002, and at least one processor 1003.

[0157] The memory 1001 stores computer program code, which includes computer instructions. These computer instructions run in the aforementioned electronic device to implement the data transmission path orchestration method or the cross-domain data transmission method shown in the above method embodiments.

[0158] For example, memory 1001 may include high-speed random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device, and may also be a USB flash drive, portable hard drive, read-only memory, disk or optical disc, etc.

[0159] The transceiver 1002 is used to interact with other devices to send and receive data. For example, in this embodiment, the transceiver 1002 can specifically be used to obtain network identification information.

[0160] Processor 1003 can be a general-purpose processor, including a Central Processing Unit (CPU), a network processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. Processor 1003 can also be other general-purpose processors. The general-purpose processor can be a microprocessor or any conventional processor.

[0161] The memory 1001, transceiver 1002, and processor 1003 are communicatively connected. For example, the memory 1001 and transceiver 1002 can be connected to the processor 1003 via a system bus to complete mutual communication. The system bus can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, an industry standard architecture (ISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in the figure, but this does not mean that there is only one bus or one type of bus.

[0162] Optionally, the memory 1001 can be either standalone or integrated with the processor 1003. When the memory 1001 is set up independently, it is connected to the processor 1003 via a system bus.

[0163] In an exemplary embodiment, this application also provides a readable storage medium including software instructions that, when run on an electronic device, cause the electronic device to perform any of the methods provided in the above embodiments.

[0164] In an exemplary embodiment, this application also provides a computer program product containing computer execution instructions, which, when run on an electronic device, causes the electronic device to perform any of the methods provided in the above embodiments.

[0165] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer-executable instructions. When these computer-executable instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer-executable instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer-executable instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).

[0166] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, disclosure, and appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.

[0167] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.

[0168] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A data transmission path orchestration method, characterized in that, A network management device applied to a target network domain; the method includes: The system receives network identification information sent by a border gateway device; the border gateway device is a gateway device between the source network domain and the target network domain; the network identification information is extracted by the border gateway device from the encapsulated message sent by the network node of the source network; the network identification information includes network requirement information. Based on the network demand information, the data transmission paths of the target network domain are arranged and a network transmission strategy is generated; The network transmission strategy is sent to the network nodes in the data transmission path.

2. The method according to claim 1, characterized in that, The method further includes: The system receives data flow information sent by each network node in the data transmission path; the data flow information is sent by the network node in the data transmission path to the network management device after transmitting an encapsulated message carrying the network identification information based on the network transmission strategy. Based on the data flow information sent by each network node in the data transmission path, a transmission path record for the encapsulated message is generated.

3. The method according to claim 2, characterized in that, The data flow information includes: device information, transmission interface information, and transmission time information of the network nodes through which the data flows.

4. The method according to claim 2, characterized in that, The method also includes: The system receives a transmission path query request from a transmission path monitoring device and sends the transmission path record of the encapsulated message to the transmission path monitoring device; the transmission path monitoring device is communicatively connected to the network management device.

5. A method for cross-domain data transmission, characterized in that, A border gateway device applied between a source network domain and a target network domain, the border gateway device being connected to a first network node in the source network domain and a second network node in the target network domain; comprising: The system receives an encapsulated message sent by the first network node and obtains network identification information from the encapsulated message. The network identification information includes cross-domain information and is used to indicate whether the encapsulated message is transmitted across domains. The data flow information is sent to the first network management device; the data flow information is sent by the network node to the network management device after transmitting an encapsulated message carrying the network identification information based on the network transmission policy; the first network management device is the network management device of the source network domain. When the network cross-domain information indicates that the encapsulated packet is a cross-domain transmission, the first tunnel information of the outer layer of the encapsulated packet is stripped to obtain the user packet; the first tunnel information refers to the tunnel path that the user packet passes through during transmission in the source network domain. The network identification information is sent to the second network management device; the second network management device is the network management device of the target network domain. Based on the network transmission policy sent by the second network management device, the user message is sent to the second network node.

6. A data transmission path arrangement device, characterized in that, A network management and control device applied to a target network domain, including an acquisition module and a processing module; The acquisition module receives network identification information sent by a border gateway device; the border gateway device is a gateway device between the source network domain and the target network domain; the network identification information is extracted by the border gateway device from the encapsulated packets sent by the network nodes of the source network; the network identification information includes network requirement information. The processing module, based on the network demand information, arranges the data transmission paths of the target network domain and generates a network transmission strategy; The network transmission strategy is sent to the network nodes in the data transmission path.

7. A data cross-domain transmission device, characterized in that, A border gateway device applied between a source network domain and a target network domain, the border gateway device being connected to a first network node in the source network domain and a second network node in the target network domain, including a receiving module and a sending module; The receiving module receives the encapsulated message sent by the first network node and obtains the network identification information in the encapsulated message; the network identification information includes cross-domain information; the cross-domain information is used to indicate whether the encapsulated message is transmitted across domains. The sending module sends the data flow information to the first network control device; The data flow information is sent by the network node to the network management device after transmitting an encapsulated message carrying the network identification information based on the network transmission policy; the first network management device is the network management device of the source network domain; when the network cross-domain information indicates that the encapsulated message is a cross-domain transmission, the first tunnel information of the outer layer of the encapsulated message is stripped to obtain the user message; The first tunnel information refers to the tunnel path that the user message passes through during transmission in the source network domain; The network identification information is sent to the second network management device; the second network management device is the network management device of the target network domain. Based on the network transmission policy sent by the second network management device, the user message is sent to the second network node.

8. A cross-domain data transmission system, characterized in that, The system includes: a network management and control device and a border gateway device; the network management and control device and the border gateway device are communicatively connected. The network management device is used to perform the method according to any one of claims 1-4; The border gateway device is used to perform the method described in claim 5.

9. An electronic device, characterized in that, include: Transceiver, processor, and memory; The transceiver, the memory, and the processor are used to collaboratively execute the method according to any one of claims 1 to 5.

10. A readable storage medium, characterized in that, include: Software instructions; When the software instructions are executed in an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-5.

11. A computer program product, characterized in that, include: Computer instructions; When the computer instructions are executed in an electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-5.