A method and apparatus for acquiring an application type

By working together with core network devices and edge network devices, and by utilizing the abundant storage resources of core devices, more granular application type identification was achieved. This solved the problem of difficulty in expanding application identification functions due to limited storage resources of network devices, and improved the application identification and differentiated processing capabilities of edge devices.

CN122120147APending Publication Date: 2026-05-29HUAWEI TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-11-27
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Network devices have limited storage resources, which makes it difficult to effectively identify and meet the different service level commitments (SLAs) requirements of different application types, and it is difficult to expand the existing application identification function.

Method used

By working together with core network devices and edge network devices, and utilizing the abundant storage resources of core devices, more granular application type identification can be achieved, and the identification results can be returned to edge devices to enhance their application identification capabilities.

Benefits of technology

It enables more granular application type identification, better meeting the detailed identification requirements of various application/service differentiation protections, and improving the differentiation processing capabilities of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120147A_ABST
    Figure CN122120147A_ABST
Patent Text Reader

Abstract

The application discloses a method and device for acquiring an application type, and relates to the field of communication, and is used for realizing extensible application identification capability of a network device to meet different SLA appeals of subdivided application types. The method comprises the following steps: a first network device acquires characteristic information of a first packet in a data stream sent by a second network device; an application type corresponding to the characteristic information in a local characteristic library is determined, the application type comprises one or more subdivided types in a multi-level type for dividing the application; and a second packet is sent to the second network device, and the second packet comprises the application type.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more particularly to a method and apparatus for obtaining application types. Background Technology

[0002] In network communication, to meet the varying service level agreements (SLAs) demands of different applications and services in different scenarios—for example, audio and video applications are sensitive to network latency and bandwidth, online office applications are sensitive to latency, and cloud storage upload and download applications are sensitive to bandwidth and packet loss—network devices employ application identification capabilities. After identifying the specific application or service type, network devices implement refined quality of service (QoS) policies (rate limiting / scheduling / shaping / dropping) based on the identification results to better meet the experience requirements of different applications.

[0003] In practical network applications, applications can include various functions, and these functions, as detailed application scenarios, also have different Service Level Agreements (SLAs). For example, collaborative office work, which has become widely adopted in recent years, is a new form of office work. The broad categories of collaborative office applications include the application names of various vendors. A single collaborative office application may contain numerous subcategories and business types, such as: online documents, instant messaging, cloud storage, email, audio and video conferencing, etc. The online document application subcategory can be further subdivided into business types such as text editing and media editing.

[0004] Application identification pre-analyzes application characteristics, mapping these characteristics to application types to generate a feature library. Network devices then identify the specific application type based on this feature library and implement fine-grained QoS policy control (rate limiting / scheduling / shaping / dropping) according to the identification results. Therefore, the granularity of application type identification by the application identification function determines the differentiated processing capabilities that the network device can support. The number of rule entries in the feature library determines the number of application types supported by the application identification function. Network devices typically have limited flash resources, allowing only a limited number of feature library rule entries to be stored, making it difficult to expand application identification capabilities and better meet the different SLA requirements of various application types. Summary of the Invention

[0005] This application provides a method and apparatus for obtaining application types, enabling network devices to have scalable application identification capabilities to meet different SLA requirements for subdivided application types.

[0006] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:

[0007] Firstly, a method for obtaining application types is provided, applied to a first network device. The first network device is used to connect multiple second network devices to a data network, and the second network devices communicate with user equipment. Specifically, the method includes: obtaining feature information of a first packet in a data stream sent by the second network device, the feature information describing the characteristics of the first packet; determining the application type corresponding to the feature information in a local feature library, the application type including one or more refined types from a multi-level classification of applications; and sending a second packet to the second network device, the second packet including one or more refined types from the determined multi-level classification of applications. Wherein, the refined type is a level below the first level in the multi-level classification, and the first level is the highest level type in the multi-level classification.

[0008] The solution provided in this application connects multiple second network devices and a data network to a first network device. Its ample storage resources support a larger number of feature library rule entries, enabling finer-grained application type identification. The first network device performs fine-grained application type identification, and then returns the identification results (the refined type) to the second network devices. Through the cooperation of the network devices and utilizing the ample storage resources of the first network device, the application identification capabilities of the second network devices are enhanced, better meeting the refined identification requirements for various application / service differentiation protections.

[0009] One possible implementation is that the second message is a response message to the first message, where the first message is a data packet forwarded through a tunnel, and the application type is carried in the reserved field of the outer layer of the second message. This approach, in scenarios where data packets are forwarded through a tunnel, utilizes the reserved field of the outer layer to carry the application type and uses the response message to return the application type. This enhances the application identification capability of the second network device while maintaining compatibility with existing communication mechanisms.

[0010] Another possible implementation involves the tunnel employing any of the following protocols: Control and Provisioning of Wireless Access Points Protocol (CAPWAP), Virtual Extensible Local Area Network (VxLAN), Generic Routing Encapsulation (GRE), or Segment Routing Over IPv6 (SRV6).

[0011] Another possible implementation is that the second message is a response message to the first message, where the first message is a data message, and the application type is carried in the reserved field of the protocol header of the second message. This approach, in scenarios where the original data message is forwarded, uses the reserved field of the protocol header to carry the application type and uses the response message to return the application type, enhancing the application identification capability of the second network device while maintaining compatibility with existing communication mechanisms.

[0012] Another possible implementation involves a management channel between the first and second network devices, where the second message is either a management message or a configuration message. By using the management channel and the management message or configuration message to return the application type, there is no need to modify the way data packets are transmitted, thus avoiding interference with data packet transmission.

[0013] Another possible implementation is that the second message is a management message or a configuration message, using any of the following protocols: CAPWAP, Simple Network Management Protocol (SNMP), or Network Configuration Protocol (netconf).

[0014] Another possible implementation is that the aforementioned feature information includes quintuple information.

[0015] Another possible implementation is that the first network device is a core network device, and the second network device is an edge network device.

[0016] Another possible implementation is that the application types included in the second message mentioned above also include the first-level application category in the multi-level type.

[0017] Secondly, another method for obtaining application types is provided, applied to a second network device. The second network device communicates with a user equipment; multiple second network devices communicate with a data network through a first network device. The method includes: sending a data stream to the first network device, the data stream including a first message from service data sent by the user equipment; receiving a second message from the first network device, the second message including an application type corresponding to feature information of the first message; the application type includes one or more refined types from a multi-level classification of the application. The refined type is a level below the first level in the multi-level classification, where the first level is the highest level type in the multi-level classification.

[0018] The solution provided in this application connects multiple second network devices and a data network to a first network device. Its ample storage resources support a larger number of feature library rule entries, enabling finer-grained application type identification. The first network device performs fine-grained application type identification, and then returns the identification results (the refined type) to the second network devices. Through the cooperation of the network devices and utilizing the ample storage resources of the first network device, the application identification capabilities of the second network devices are enhanced, better meeting the refined identification requirements for various application / service differentiation protections.

[0019] One possible implementation, the method provided in this application, further includes: obtaining the first-level application category in the multi-level type corresponding to the feature information of the first message; and performing differentiated processing on the service to which the first message belongs according to the application category and the refined type. Since the application identification capability of the second network device is enhanced by utilizing the storage resources of the first network device, after obtaining the refined type, the second network device performs differentiated processing on the service according to the refined type and the application category, thus achieving more refined differentiated processing.

[0020] Another possible implementation is that the application type included in the second message also includes the application category, and the second network device obtains the application category from the second message. That is, the application category is also identified and returned by the first network device, further saving the storage resources occupied by the second network device.

[0021] Another possible implementation involves obtaining the first-level application category in the multi-level type corresponding to the feature information of the first message. Specifically, this is done by: obtaining the feature information of the first message; and determining the application category corresponding to the feature information based on the local feature library of the second network device. The application category is identified locally by the second network device, while the refined type is identified and returned by the first network device, thus saving on the number of fields used to transmit the application type.

[0022] Thirdly, an apparatus for obtaining application type is provided, the apparatus being deployed on a first network device. The first network device is used to connect multiple second network devices to a data network, and the second network devices communicate with user equipment. The apparatus includes an acquisition unit, a determination unit, and a transmission unit. Wherein:

[0023] The acquisition unit is used to acquire the feature information of the first packet in the data stream sent by the second network device. The feature information is used to describe the features of the first packet.

[0024] The determining unit is used to determine the application type corresponding to the feature information in the local feature library. The application type includes one or more refined types in the multi-level types that divide the application. Among them, the refined type is the level type below the first level in the multi-level type, and the first level is the highest level type in the multi-level type.

[0025] The sending unit is used to send a second message to a second network device, the second message including an application type.

[0026] One possible implementation is that the second message is a response message to the first message, where the first message is a data packet forwarded through a tunnel, and the application type is carried in the reserved field of the outer layer of the second message. This approach, in scenarios where data packets are forwarded through a tunnel, utilizes the reserved field of the outer layer to carry the application type and uses the response message to return the application type. This enhances the application identification capability of the second network device while maintaining compatibility with existing communication mechanisms.

[0027] Another possible implementation is that the second message is a response message to the first message, where the first message is a data message, and the application type is carried in the reserved field of the protocol header of the second message. This approach, in scenarios where the original data message is forwarded, uses the reserved field of the protocol header to carry the application type and uses the response message to return the application type, enhancing the application identification capability of the second network device while maintaining compatibility with existing communication mechanisms.

[0028] Another possible implementation involves a management channel between the first and second network devices, where the second message is either a management message or a configuration message. By using the management channel and the management message or configuration message to return the application type, there is no need to modify the way data packets are transmitted, thus avoiding interference with data packet transmission.

[0029] Another possible implementation is that the tunnel uses any of the following protocols: CAPWAP, Vxlan, GRE, or SRV6.

[0030] Another possible implementation is that the second message is a management message or a configuration message, using any of the following protocols: CAPWAP, SNMP, or netconf.

[0031] Another possible implementation is that the aforementioned feature information includes quintuple information.

[0032] Another possible implementation is that the first network device is a core network device, and the second network device is an edge network device.

[0033] Another possible implementation is that the application types included in the second message mentioned above also include the first-level application category in the multi-level type.

[0034] Fourthly, an apparatus for obtaining application type is provided. This apparatus is deployed in a second network device that communicates with a user equipment. Multiple second network devices communicate with a data network through a first network device. The apparatus includes a transmitting unit and a receiving unit. Wherein:

[0035] The sending unit is used to send a data stream to the first network device, the data stream including the first message in the service data sent by the user equipment.

[0036] The receiving unit is configured to receive a second message from a first network device. The second message includes an application type corresponding to the feature information of the first message. This application type includes one or more refined types from a multi-level classification of the application. The refined type is a level below the first level in the multi-level classification, where the first level is the highest-level type in the multi-level classification.

[0037] In one possible implementation, the apparatus provided in the fourth aspect further includes an acquisition unit and a processing unit. The acquisition unit is used to acquire the first-level application category in the multi-level type corresponding to the feature information of the first message. The processing unit is used to perform differentiated processing on the service to which the first message belongs according to the application category and the refined type. Since the application identification capability of the second network device is enhanced by utilizing the storage resources of the first network device, after acquiring the refined type, the second network device performs differentiated processing on the service according to the refined type and the application category, thereby achieving more refined differentiated processing.

[0038] Another possible implementation is that the application types included in the second message also include application categories, and the acquisition unit specifically retrieves the application categories from the second message. That is, the application categories are also identified and returned by the first network device, further saving the storage resources occupied by the second network device.

[0039] Another possible implementation involves the acquisition unit specifically used to: acquire the feature information of the first message; and determine the application category corresponding to the feature information based on the local feature library of the second network device. The application category is identified locally by the second network device, while the refined type is identified and returned by the first network device, thus saving on the number of fields used to transmit the application type.

[0040] Fifthly, a network device is provided, comprising: a processor and a memory storing instructions that, when executed by the processor, cause the network device to perform a method provided by the first aspect or any possible implementation thereof, or cause the network device to perform a method provided by the second aspect or any possible implementation thereof.

[0041] In a sixth aspect, a chip is provided, the chip including a processor and an interface circuit, the processor and the interface circuit being configured to support the chip in performing methods provided by the first aspect or the second aspect, or any possible implementation thereof.

[0042] In a seventh aspect, a computer-readable storage medium is provided, wherein a computer program or instructions are stored therein, which, when executed, implement the methods provided by the first aspect or the second aspect, or any possible implementation thereof.

[0043] Eighthly, a computer program product is provided, comprising: a computer program (or code, or instructions) that, when run, causes a computer to perform the methods provided by the first aspect or the second aspect, or any possible implementation thereof.

[0044] It is understood that the beneficial effects achieved by any of the above-mentioned devices, network equipment, chips, computer-readable storage media, and computer program products for acquiring application types can be referred to in accordance with the beneficial effects of the methods for acquiring application types provided above, and will not be repeated here. Attached Figure Description

[0045] Figure 1 A schematic diagram illustrating the components of a collaborative office application type;

[0046] Figure 2 A schematic diagram illustrating the working principle of an application recognition function;

[0047] Figure 3 This application provides a schematic diagram of the architecture of a communication system.

[0048] Figure 4 A flowchart illustrating a method for obtaining an application type provided in an embodiment of this application;

[0049] Figure 5 A schematic diagram illustrating the format of a CAPWAP tunnel header provided for an embodiment of this application;

[0050] Figure 6 A schematic diagram illustrating the format of a TCP response header provided in an embodiment of this application;

[0051] Figure 7 A flowchart illustrating another method for obtaining application type provided in an embodiment of this application;

[0052] Figure 8 A flowchart illustrating another method for obtaining application type provided in an embodiment of this application;

[0053] Figure 9 A flowchart illustrating another method for obtaining application type provided in an embodiment of this application;

[0054] Figure 10A flowchart illustrating another method for obtaining application type provided in an embodiment of this application;

[0055] Figure 11 This is a schematic diagram of the structure of an apparatus for obtaining application type according to an embodiment of this application;

[0056] Figure 12 A schematic diagram of another device for obtaining an application type provided in an embodiment of this application;

[0057] Figure 13 A schematic diagram of the structure of another device for obtaining an application type provided in this application embodiment;

[0058] Figure 14 This is a schematic diagram of the structure of a network device provided in an embodiment of this application. Detailed Implementation

[0059] The following sections will discuss the fabrication and use of various embodiments in detail. However, it should be understood that many applicable inventive concepts provided in this application can be implemented in a variety of specific environments. The specific embodiments discussed are merely illustrative of specific ways of implementing and using this application and technology, and do not limit the scope of this application.

[0060] Unless otherwise defined, all technical terms used herein have the same meaning as commonly known to one of ordinary skill in the art.

[0061] The technical solutions in the embodiments of this application will be described below with reference to the accompanying drawings. In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that there are three relationships. For example, A and / or B means: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c means: a, b, c, a and b, a and c, b and c, a, b, and c; where a, b, and c can be single or multiple.

[0062] The embodiments of this application use terms such as "first" and "second" to distinguish objects with similar names, functions, or effects. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or order of execution. The term "coupling" is used to indicate an electrical connection, including direct connection via wires or terminals or indirect connection via other devices. Therefore, "coupling" should be considered as a broad type of electronic communication connection.

[0063] It should be noted that, in this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.

[0064] To facilitate understanding, the relevant terms involved in the embodiments of this application will be explained first.

[0065] A Service Level Agreement (SLA) is a mutually agreed-upon agreement between a service provider and a user, or between service providers themselves, to guarantee the performance and reliability of a service, under certain cost constraints.

[0066] The relevant background information for this application is described below.

[0067] In this application, "application" refers to a specific software program used by the user, and "business" refers to a specific user operation. Applications are categorized into multiple levels, including three levels: application category, application subcategory, and business type. Specifically:

[0068] Application category: This is the first-level category in the multi-level classification of applications. It is a type unique to each application and is also the largest category. For example, the application category is usually used to indicate the application's name, provider, or other information. For instance, application categories might be Application 1, Application 2, and Application 3, where Application 1 to Application 3 are collaborative office applications provided by different vendors. It should be understood that the application category is a coarse-grained indication of the application type.

[0069] Application subcategories are the second level and below of a multi-level application classification system. They belong to the main application category and are detailed subcategories within that category. Application subcategories provide a fine-grained indication of the application's type. They are typically used to indicate the application's functionality, and different main application categories can contain the same application subcategories. Within a multi-level classification system, one or more levels of application subcategories are configured based on actual needs. For example, a collaborative office application category might include application subcategories such as: online documents, instant messaging, cloud storage, email, and audio / video conferencing.

[0070] Business type: This is a further subdivision of the application subcategory. The business type is considered the lowest level of the multi-level categories that classify applications, and it also belongs to the first-level refinement type. The business type indicates the specific type of business being performed. It is also a type of application type. For example, the application subcategory of online documents can be further subdivided into: text editing and media editing; the application subcategory of audio and video conferencing can be further subdivided into: voice, video, and sharing.

[0071] Figure 1 This is a component of a collaborative office application type. For example... Figure 1 As shown, the application's main category is its name, Application A, which includes the following subcategories: Online Documents, Instant Messaging, Cloud Storage, Email, and Audio / Video Conferencing. The "Online Documents" subcategory is further subdivided into: Text Editing and Media Editing; the "Instant Messaging" subcategory includes: Message Sending and Receiving, File Transfer, Voice, and Video; the "Cloud Storage" subcategory includes: File Transfer; the "Email" subcategory includes: Text Editing and File Transfer; and the "Audio / Video Conferencing" subcategory includes: Voice, Video, and Sharing.

[0072] As mentioned earlier, different applications and services have different SLA requirements for the network in different scenarios. For example, audio and video applications are sensitive to network latency / bandwidth, online office applications are sensitive to latency, and cloud storage upload and download applications are sensitive to bandwidth and packet loss. Network devices need to use application identification functions (such as smart application control (SAC)) to identify the specific application type based on the characteristics of the data flow (composed of packets), and then perform different differentiated protection and optimization for the data flow of different applications / services in order to better meet the SLA requirements and experience requirements of different applications.

[0073] The application identification function generates a signature database file by pre-analyzing the characteristics of various common applications' flows. This file stores packet characteristics and their corresponding application types. In practice, packet characteristics for different applications are defined and loaded into the signature database file for upgrades. The signature database file is then loaded onto the network device in a predefined manner. The working principle of the application identification function is as follows: Figure 2As shown, when application traffic packets pass through network devices, the application identification function acquires the characteristics of the traffic packets. Next, the acquired packet characteristics are compared with the packet characteristics in the feature database for feature matching. The application type corresponding to the matched traffic packet characteristics is then identified. Finally, based on the identification results, fine-grained QoS policy control is implemented (e.g., statistics / rate limiting / scheduling / shaping / dropping). For voice or video applications, voice and video optimization is performed. Therefore, the granularity of application type identification by the application identification function determines the differentiated processing capabilities that the network device can support.

[0074] Edge devices in a network (such as access points (APs) in a Wi-Fi network) have limited flash (a type of memory chip) resources, and the flash space available for each functional module is strictly controlled. When deploying application identification functionality, rule entries from a feature library file need to be loaded into the flash memory. The existing rule entries for the current application identification function have already exhausted the flash space of the AP devices. Figure 1 Taking application A as an example, the application identification function of AP can only identify and distinguish between two major application categories: application A audio and video conferencing and application A other. Other application subcategories and business types are not supported.

[0075] If more application identification rule entries are needed, the flash memory of the edge device needs to be expanded. Alternatively, existing rule entries for other application types need to be replaced before new rule entries can be added. Other options may be limited in capacity and difficult to implement. Therefore, the current application identification function faces difficulties in expanding its application identification capabilities and cannot better meet the different SLA requirements of applications / businesses in scenarios with segmented application types.

[0076] Based on this, this application provides a method for obtaining application types. It utilizes network devices with abundant storage resources (such as core network devices) to support more feature library rule entries, enabling finer-grained application type identification. The identification results are then returned to edge network devices for fine-grained QoS control. Through the cooperation between edge and core network devices, the application identification capabilities of the edge devices are enhanced, better meeting the refined identification requirements for various application / service differentiation protections.

[0077] The solution provided in this application can be applied to various communication systems with network devices. The structure of such a communication system is illustrated below.

[0078] Figure 3 This is a schematic diagram of a communication system provided in an embodiment of the present application. The communication system includes a user equipment 301, an edge network device 302, a core network device 303, and a data server 304.

[0079] The network comprises edge network device 302 and core network device 303 to provide access services. Core network device 303 connects multiple edge network devices 302 and data server 304. User equipment 301 accesses the network and connects to data server 304 through edge network device 302 and core network device 303. User equipment 301 is connected to edge network device 302 via a network connection. Edge network device 302 is also connected to core network device 303 via a network connection. Core network device 303 is also connected to data server 304 via a network connection.

[0080] For example, the user equipment 301 includes, but is not limited to: mobile phone, tablet computer, laptop computer, handheld computer, mobile internet device (MID), camera, wearable device, in-vehicle device, virtual reality (VR) device, augmented reality (AR) device, or intelligent robot, etc.

[0081] For example, the edge network device 302 is located on the network side of the aforementioned communication system to help terminal nodes achieve network access. The edge network device 302 includes, but is not limited to, base stations, evolved NodeBs (eNodeBs), access points (APs), access switches, or access routers.

[0082] For example, the core network device 303 is an access switch, aggregation switch, or core switch in a communication network. The core network device 303 communicates with the edge network device 302, facilitating communication between the edge network device 302 and the data server 304. For instance, the core network device 303 is a WLAN access controller (WAC) device, or it may be a core switch or a core router.

[0083] Specifically, the user equipment 301 sends a service data stream to the core network device 303 through the edge network device 302. Upon receiving the data stream, the core network device 303, while forwarding the data, detects and obtains the characteristics of the packets in the data stream. It then compares these characteristics with a feature database to determine the application type to which the data stream belongs. The core network device 303 then returns the determined application type to the edge network device 302.

[0084] In one possible implementation, each edge network device 302 performs local coarse-grained application category identification and receives fine-grained application type information synchronized from the core network device 303. The core network device 303 centrally performs fine-grained application type identification and synchronizes it to the edge network devices 302.

[0085] For example, the data channel between core network device 303 and edge network device 302 includes tunnel messages or raw messages for synchronizing application type information.

[0086] For example, the management channel between the core network device 303 and the edge network device 302 includes configuration messages or management messages for synchronizing application type information.

[0087] In practical applications, Figure 3 The number of user equipment 301, edge network equipment 302, core network equipment 303, and data server 304 included in the illustrated communication system can be configured according to actual needs. Figure 3 This is merely an example and is not a limitation on the size of a communication system.

[0088] Figure 4 This is a flowchart illustrating a method for obtaining application type according to an embodiment of this application. Figure 4 The illustrated method is applied to a communication system including a first network device, a second network device, and a data network. The second network device communicates with user equipment, and the first network device connects multiple second network devices to the data network. The following description illustrates the solution provided in the application through the interaction process between the first network device and one second network device.

[0089] In one possible implementation, the first network device is a core network device, and the second network device is an edge network device. For example, the first network device can be one of the aforementioned... Figure 3 The core network device 303 in the illustrated communication system can be the second network device described above. Figure 3 The schematic diagram shows edge network device 302 in a communication system.

[0090] For example, the storage resources of the first network device are more abundant than those of the second network device.

[0091] Before implementing the solution provided in this application, a feature library file (hereinafter referred to as the feature library) is generated by pre-analyzing the characteristics of various common application flows. The feature library file records the feature information of different messages and their corresponding application types. The application type corresponding to the feature information of a message is the application type of the application to which that message belongs. The granularity of the application types included in the feature library is configured according to actual needs.

[0092] In one possible implementation, the message's feature information is used to uniquely identify the message. In practical applications, the content of the message's feature information can be configured according to actual needs, and this application embodiment does not limit this.

[0093] For example, the characteristic information of a message is a five-tuple of the message, namely: source network protocol (IP) address information, destination address information, source port information, destination port information, and protocol type.

[0094] In one possible implementation, the feature library includes all levels of application classification. For example, applications can be classified into three levels: application category, application subcategory, and business type. The feature library includes application category, application subcategory, and business type.

[0095] In another possible implementation, the feature library includes partial types categorized by application. For example, applications can be categorized into major application categories, minor application categories, and business types, with the feature library including major application categories and minor application categories. The content and storage format of the feature library are configured according to actual needs, and this application embodiment does not limit this. Any feature library used to record the feature information of different messages and their corresponding application types falls under the category described in this application.

[0096] Next, based on actual needs, configure local feature libraries for each network device that requires application identification. The granularity of application types in the local feature library configured for a network device determines the granularity of the application identification function of that network device. The content of the local feature libraries configured in different network devices can be different. The smaller the minimum granularity of application types configured in the local feature library, the more rule entries the local feature library has, and the more storage resources it consumes. The minimum granularity of application types configured in the local feature library is configured according to actual needs, either as the lowest level of application type classification or as an intermediate level of application type classification.

[0097] It should be understood that the network device performs the same operations for identifying the type of an application. The following embodiments of this application only describe the process by which the network device identifies the type of the application to which the first message belongs; other details will not be repeated.

[0098] like Figure 4 As shown, the method for obtaining the application type provided in this application may include:

[0099] S401: The second network device sends a data stream to the first network device, and the data stream includes the first message in the service data sent by the user equipment.

[0100] Specifically, the second network device, acting as an edge network device communicating with the user equipment, receives uplink service data from the user equipment after it sends the application's data to the network side. Typically, the data sent by the user equipment is transmitted as a data stream, which includes the first packet. Upon receiving the data stream from the user equipment, the second network device, according to the packet forwarding protocol between the first and second network devices, sends its own data stream to the first network device. This sent data stream includes the first packet from the service data sent by the user equipment.

[0101] In one possible implementation, the first network device and the second network device forward data packets through a tunnel. In S401, the second network device encapsulates the first packet in the service data sent by the user equipment using the tunneling technology it employs and then sends the data stream.

[0102] The tunnel described in this application includes any of the following: Control and Provisioning of Wireless Access Points Protocol Specification (CAPWAP), Virtual Extensible Local Area Network (VxLAN) protocol, Generic Routing Encapsulation (GRE) protocol, and Segment Routing over IPv6 (SRV6) protocol based on the Internet Protocol version 6 (IPv6) forwarding plane.

[0103] In another possible implementation, the first network device and the second network device directly forward the original data packets. In S401, the second network device directly forwards the service data stream sent by the user equipment.

[0104] Furthermore, while executing S401, the second network device extracts the feature information of the first packet and records it in the local session table. The local session table also records the application type corresponding to the feature information, facilitating differentiated control based on packet feature information and application type to meet the SLA requirements of different services. This session table supports automatically associating the feature information of uplink and downlink packets within a session.

[0105] For example, the characteristic information is a 5-tuple, and the local session table in the first network device supports automatically associating the uplink and downlink 5-tuples of a session. The source and destination of the uplink and downlink 5-tuples of a session are interchanged, but the protocol types are the same.

[0106] For example, Table 1 illustrates the local session table of the second network device.

[0107] Table 1

[0108]

[0109] In one possible implementation, the second network device is configured with a local feature library. The smallest granularity of application types in this local feature library is the first-level application category in a multi-level classification of applications. The second network device uses the feature information of the first packet and, based on the local feature library, determines the application category corresponding to the feature information of the first packet. For example, the determined application category can be recorded in a local session table, corresponding to the feature information of the first packet.

[0110] In another possible implementation, the application type corresponding to the feature information of the first message in the local session table of the second network device is updated to the local session table after the second network device receives the application type returned by the first network device.

[0111] Correspondingly, after S401, the first network device receives the data stream sent by the second network device, and the data stream includes the first message.

[0112] S402: The first network device obtains the feature information of the first packet in the data stream sent by the second network device. The feature information is used to describe the characteristics of the first packet.

[0113] Specifically, after the uplink data stream of the application arrives, the first network device performs the S402 process while forwarding the data stream normally.

[0114] S403: The first network device determines the application type corresponding to the feature information in the local feature library. The application type includes one or more refined types in the multi-level types that divide the application.

[0115] In this context, the refined type refers to the sub-types below the first level in this multi-level type, where the first level is the highest-level type. For example, in a multi-level type, the first level is the aforementioned application category, and the refined types below the first level are application sub-categories and business types.

[0116] Specifically, the local feature library configured in the first network device includes one or more refined types from the multi-level categories that classify applications, at the application type granularity level. This allows the first network device to identify one or more refined types from the multi-level categories based on the local feature library. After executing S402, the first network device performs fine-grained application type identification by executing S403.

[0117] For example, applications are categorized as: application major category, application minor category, and service type. If the smallest granularity of a rule entry in the local feature library of the first network device is a service type, the smallest granularity of the application type determined by the first network device in S403 is the service type. If the smallest granularity of a rule entry in the local feature library of the first network device is a certain level of application minor category, the smallest granularity of the application type determined by the first network device in S403 is that level of application minor category.

[0118] The specific identification process involves comparing the feature information obtained in S402 with the local feature database to determine the application type corresponding to the feature information in the local feature database, which is then used as the application type of the first message.

[0119] In one possible implementation, after determining the application type corresponding to the feature information in the feature database, the first network device records the feature information and application type in a local session table. The session table supports automatically associating the feature information of uplink and downlink packets of a session. When downlink traffic of an application arrives, the feature information of the downlink packet can be extracted, and the feature information of the uplink packet can be associated with it in the session table to obtain the application type of the application to which the session belongs, so as to execute S404 to feed back the application type to the second network device.

[0120] For example, Table 2 illustrates the local session table of the first network device.

[0121] Table 2

[0122]

[0123] For example, the application type in the local session table is recorded using a type identifier. A type identifier is used to uniquely indicate an application type.

[0124] S404: The first network device sends a second message to the second network device, the second message including one or more refined types from the multi-level types of application classification.

[0125] After the first network device performs detailed application type identification in S403, it returns the identified detailed type to the second network device in S404, so that the second network device can perform differentiated control.

[0126] For example, this application provides the following two implementations for sending a second message:

[0127] Implementation 1: The second message is a response message to the first message.

[0128] In implementation 1, S404 is executed upon receiving downlink traffic. When the application's downlink traffic reaches the first network device, the first network device first extracts the packet characteristic information (called downlink characteristic information) from the downlink traffic and associates it in the local session table. Uplink and downlink characteristic information of the same session are automatically associated in the local session table. The application type corresponding to the session to which the downlink characteristic information belongs in the local session table is determined as the application type to which the currently received traffic belongs.

[0129] For example, suppose the first network device receives downlink traffic and extracts the downlink feature information as "Source IP: Z; Destination IP: A; Source Port: J; Destination Port: Q; Protocol Type: P". According to the local session table shown in Table 2, Session2 is automatically associated, and the type of application to which the currently received traffic belongs is determined to be "Application B, Message Sending and Receiving".

[0130] Then, the first network device encapsulates the application type that needs to be sent to the second network device into a second message and sends it.

[0131] In one possible implementation, the application type to be sent to the second network device includes the type of application to which the currently received traffic belongs, excluding the application category. The application category is identified by the second network device itself.

[0132] In another possible implementation, the application types to be sent to the second network device include all types within the application types to which the currently received traffic belongs. For example, the first network device sends both the identified application category and its sub-category to the second network device.

[0133] For example, the second message includes the application type, a reserved field carried in the response message.

[0134] For example, the first message is a data packet forwarded through the tunnel, and the second message is a response message to the first message. The reserved field of the tunnel outer layer of the second message carries the application type. The tunnel adopts any of the following protocols: CAPWAP, Vxlan, GRE, or SRV6.

[0135] Figure 5 This illustrates the format of the CAPWAP tunnel header. For example... Figure 5As shown, the CAPWAP tunnel header includes the following fields: CAPWAP Preamble, Header Length (HLEN), Radio ID (RID), WLAN Basic Service Set Identifier (WBID), Fragment ID, Frag Offset, and Reserved Field (Rsvd). Figure 5 The reserved field (Rsvd, 3 bits) shown in the diagram is used to carry the refined type. Figure 5 Only a portion of the CAPWAP tunnel header is shown.

[0136] For example, the first network device and the second network device directly forward the original data packets. The first packet is the original data packet, and the second packet is a response packet to the first packet. The application type is carried in the reserved field of the protocol header of the second packet.

[0137] For example, the raw data packets use the Transmission Control Protocol (TCP). Figure 6 This illustrates the format of the TCP response header. For example... Figure 6 As shown, the TCP response header includes fields such as source connection port, destination connection port, sequence number, acknowledgment number, data offset, and reserved fields (000). Figure 6 The reserved field (3 bits) shown in the diagram is used to carry the refined type. Figure 6 Only a portion of the TCP response header is shown.

[0138] Implementation 2: The second message is a management message or a configuration message.

[0139] In implementation 2, a management channel exists between the first network device and the second network device. This can be understood as the first network device having management authority over the second network device. The first network device sends management commands to the second network device using management messages and configuration commands using configuration messages. This application embodiment does not limit the type or form of the management or configuration messages.

[0140] For example, management or configuration messages are privately defined and implemented by the device / vendor and carried by generic TCP / UDP messages.

[0141] For example, in implementation 2, the second message may use any of the following protocols: CAPWAP, SNMP, netconf.

[0142] In one possible implementation, in implementation 2, the first network device executes S404 immediately after executing S403. The application type to be sent is encapsulated into a management message or configuration message and then sent to the second network device.

[0143] Furthermore, the management message or configuration message also includes the characteristic information of the first message, which facilitates the second network device to identify the service or application to which the application type carried in the management message or configuration message belongs.

[0144] In one possible implementation, the application category is identified by the second network device itself, and the second message sent in S404 only includes one or more refined types from the multi-level types of application classification corresponding to the feature information.

[0145] In another possible implementation, the application category is also sent from the first network device to the second network device. The second message sent in S404 includes the application category corresponding to the feature information, as well as one or more refined types in the multi-level types of application classification corresponding to the feature information.

[0146] S405: The second network device receives a second message from the first network device.

[0147] The second message received by the second network device in S405 is the same as the second message sent by the first network device in S404. The content of the second message will not be described again here.

[0148] By executing the S405 second network device, the application type included in the second message can be obtained, the type of application to which the message with a certain characteristic information belongs can be determined, and it can be recorded in the local session table, corresponding to the characteristic information.

[0149] The solution provided in this application connects multiple second network devices and a data network to a first network device. Its ample storage resources support a larger number of feature library rule entries, enabling finer-grained application type identification. The first network device performs fine-grained application type identification and then returns the identification results to the second network devices. Through the cooperation of these network devices, the application identification capabilities of the second network devices are enhanced, better meeting the refined identification requirements for various application / service differentiation protections.

[0150] Furthermore, such as Figure 7 As shown, after receiving the second message, the second network device performs operations S406 and S407 to determine the specific type of the application and perform differentiated processing.

[0151] S406. The second network device obtains the application category corresponding to the feature information of the first message.

[0152] In a possible implementation, the second message further includes the application category corresponding to the feature information of the first message, and in S406, the second network device extracts the application category from the second message.

[0153] In another possible implementation, the second message does not include the application category. S406 is specifically implemented as follows: The second network device obtains the feature information of the first message and determines the application category corresponding to the feature information according to the local feature library of the second network device. Among them, the minimum granularity of the application type in the local feature library of the second network device is the application category. For example, in this implementation, S406 is executed before S401.

[0154] S407. The second network device performs differential processing on the service to which the first message belongs according to the application category and the refined type.

[0155] Specifically, the second network device performs differential processing on the data flow with the same feature information as the first message or the data flow with the feature information belonging to the same session as the first message according to the application category and the refined type to which the first message belongs.

[0156] Exemplarily, the differential processing includes speed limiting, scheduling, shaping, and discarding.

[0157] It should be noted that the steps included in the method for obtaining the application type provided in the embodiments of the present application are configured according to actual requirements for the execution order. Figure 4 Or Figure 7 It only shows a possible execution order of the steps and does not limit the execution order of the steps.

[0158] Next, the solution provided by the present application will be described exemplarily through specific examples.

[0159] Example 1: The core network device and the edge network device forward data messages through a CAPWAP tunnel, and the refined type is carried in the tunnel message header. The application recognition capabilities between devices are linked, thereby enhancing the granularity of application type recognition on the edge network device. A local feature library with the minimum granularity of the application type being the service type is configured in the core network device. A local feature library with the minimum granularity of the application type being the application category is configured in the edge network device. The upstream traffic of Application A is represented by a five-tuple: (Source IP (Sip): X; Destination IP (Dip): Y; Source Port (Sport): M; Destination Port (Dport): N; Protocol Type (proto): P). The downstream traffic of Application A is represented by a five-tuple (Sip: Y; Dip: X; Sport: N; Dport: M; proto: P).

[0160] Such as Figure 8The flow of the method for obtaining the application type shown is the method flow of Example 1. When the uplink traffic of application A passes through the edge network device, the edge network device first initially identifies the application category (application A) and records the application category and the corresponding uplink 5-tuple in the local session table (as shown in Table 3 below).

[0161] Table 3

[0162]

[0163] In Table 3, the type identifier "123" is used to indicate the application category A.

[0164] Application uplink traffic is sent to the core network device via the CAPWAP tunnel. In addition to normal forwarding, the core network device extracts the uplink quintuple (Sip: X; Dip: Y; Sport: M; Dport: N; proto: P) and, based on a local feature library, identifies fine-grained application subclasses (e.g., online documents, instant messaging, cloud storage, email) and service types (e.g., text editing, media editing, message sending / receiving, file transfer, etc.). The identification results are recorded in the local session table, corresponding to the uplink traffic quintuple. Assuming the identified fine-grained type is document / media editing, the local session table is shown in Table 4 below.

[0165] Table 4

[0166]

[0167] In Table 4, the type identifier "123" indicates the application category A, and the type identifier "2" indicates the business type "document media editing".

[0168] After the downlink traffic of application A (Sip: Y; Dip: X; Sport: N; Dport: M; proto: P) reaches the core network device, the core network device uses its local session table to correlate the uplink traffic (such as the uplink traffic of Session 1 in Table 4) to obtain the fine-grained application type (such as the type identifier "2" in Table 4). The core network device then modifies the reserved Rsvd fields on the outer layer of the CAPWAP tunnel (such as...). Figure 5 ), and send downlink traffic to application A.

[0169] Downlink traffic from application A is encapsulated in a CAPWAP tunnel and sent to the edge network device. While stripping the tunnel header, the edge network device retrieves the application type from the Rsvd field within the tunnel header. The edge network device then uses its local session table (as shown in Table 3) to correlate with the uplink traffic, refreshing the application type of Session 1 in its local session table to a fine-grained type, as shown in Table 4.

[0170] In this way, edge network devices can differentiate Session1 according to fine-grained types.

[0171] Example 2: Raw data packets are directly forwarded between edge network devices and core network devices. Detailed types are carried in the protocol header.

[0172] Figure 9 The flow of the method for obtaining the application type provided in Example 2. Figure 9 The first example illustrates the use of TCP protocol to forward raw data packets between edge network devices and core network devices. In Example 2, the interaction process between the edge network device and the core network device is similar to that in Example 1, except that the refined identification result from the core network device is carried in the protocol header of the raw data packet (TCP's ACK response). Figure 6 (The reserved fields are shown in the diagram). The interaction process between edge network devices and core network devices will not be described in detail.

[0173] Example 3: A dedicated configuration management channel exists between core network devices and edge network devices. Core network devices use management or configuration messages to carry detailed identification of application types.

[0174] like Figure 10 The flowchart illustrates the method for obtaining application types. The uplink traffic data packets for application A are first identified as application categories on the edge network device to obtain the application category (application A) corresponding to the 5-tuple. The application category and the corresponding uplink 5-tuple are then recorded in the local session table. This process is the same as in Example 1 and will not be repeated here.

[0175] After data packets are forwarded to the core device through the data channel, the core network device, in addition to normal forwarding, extracts the uplink 5-tuple and performs refined identification of application subcategories based on a local feature library. The corresponding application major and minor categories are recorded in the local session table in the form of 5-tuples. This process is the same as in Example 1 and will not be described again.

[0176] The core network device notifies the corresponding edge network device of the five-tuple information and the corresponding application subclass information through management messages or configuration messages in the management channel.

[0177] When an edge network device receives a management message or configuration message through the management channel, it parses out the corresponding service flow 5-tuple and application subclass information, and then refreshes the application subclass information corresponding to the 5-tuple in its local session table. This process is the same as in Example 1 and will not be described again.

[0178] This application uses a multi-level type with three levels as an example for illustration. It is understood that a multi-level type may include at least two levels, and may also include four or more levels. When a multi-level type includes two, four, or more levels, the principle of the edge network device obtaining the application type is similar to that when a multi-level type includes three levels; therefore, these will not be listed individually in this application embodiment.

[0179] The above primarily describes the solutions provided by the embodiments of this application from the perspective of the network devices (first network device, second network device) as a whole. It is understood that, in order to achieve the above functions, the network devices include corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0180] This application embodiment can divide the network device into functional modules according to the above method example. For example, each function can be divided into its own functional modules, or two or more functions can be integrated into one module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the division of functional modules according to each function as an example.

[0181] When using integrated units, Figure 11 A schematic diagram of the structure of a device 110 for obtaining application type according to the above embodiments is shown. Optionally, the device 110 is a first network device or a chip applied to a first network device. The device 110 includes: an acquisition unit 1101, a determination unit 1102, and a transmission unit 1103. The acquisition unit 1101 can be used to support the device 110 in executing S402 of the above method embodiments; the determination unit 1102 is used to support the device 110 in executing S403 of the above method embodiments; and the transmission unit 1103 is used to support the device 110 in executing S404 of the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional module, and will not be repeated here.

[0182] When using integrated units, Figure 12 A schematic diagram of another device 120 for acquiring application type involved in the above embodiments is shown. Optionally, the device 120 is a second network device or a chip applied to a second network device. The device 120 includes a transmitting unit 1201 and a receiving unit 1202. The transmitting unit 1201 can be used to support the device 120 in executing S401 in the above method embodiments; the receiving unit 1202 is used to support the device 120 in executing S405 in the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional module, and will not be repeated here.

[0183] Furthermore, such as Figure 13 As shown, the device 120 for obtaining application types further includes an acquisition unit 1203 and a processing unit 1204. The acquisition unit 1203 can be used to support the device 120 in executing S406 of the above method embodiment. For example, the acquisition unit 1203 is used to acquire feature information of the first message and determine the application category corresponding to the feature information based on the local feature library of the second network device. The processing unit 1204 can be used to support the device 120 in executing S407 of the above method embodiment.

[0184] like Figure 14 The diagram shown is a structural schematic of a network device 140 according to the above embodiments provided in this application. The network device 140 includes a processor 311, a memory 312, a communication interface 313, and a bus 314. The processor 311, the memory 312, and the communication interface 313 are connected through the bus 314.

[0185] The processor 311 is used to control and manage the operation of the network device 140. In one possible embodiment, the processor 311 can be used to support the network device 140 in receiving one or more steps S401 to S407 in the above method embodiments, and / or other technical processes described herein. The communication interface 313 is used to support the network device 140 in communication, such as supporting the network device 140 in communicating with user equipment or other network devices.

[0186] In this embodiment, processor 311 includes a central processor unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. Optionally, the processor may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application; or, the processor may be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processor and a microprocessor, etc. The bus 314 includes an address bus, a data bus, a control bus, etc.

[0187] In this embodiment, memory 312 includes volatile memory or non-volatile memory, or both. Non-volatile memory includes read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory, etc. Volatile memory includes random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0188] In another embodiment of this application, a communication system is provided, comprising a user equipment, a first network device, and a second network device. The first network device is the application type acquisition apparatus deployed in the first network device as described above, used to execute multiple steps performed by the first network device in the method embodiment provided above. The second network device is the application type acquisition apparatus deployed in the second network device as described above, used to execute multiple steps performed by the second network device in the method embodiment provided above.

[0189] In another aspect of this application, a chip is provided, the chip including a processor and an interface circuit, the processor and the interface circuit being used to support the chip in performing one or more steps in the method embodiments provided above.

[0190] It is understood that all relevant content of each step involved in the above method embodiments is referenced in the embodiments of the device for obtaining application type, the embodiments of the network device, and the embodiments of the communication system, and will not be repeated here in the embodiments of this application.

[0191] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods may be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of modules or units is merely a logical functional division, and in actual implementation, there may be other division methods, such as multiple units or components being combined or integrated into another apparatus, or some features being ignored or not executed.

[0192] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units, meaning it can be located in one place or distributed across multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0193] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium, including various media capable of storing program code such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks. Based on this understanding, the technical solutions of the embodiments of this application, in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, are embodied in the form of software products.

[0194] In another embodiment of this application, a readable storage medium is also provided, which stores computer-executable instructions when a device (e.g., a microcontroller, chip, etc.) or processor executes the steps in the above method embodiments.

[0195] In another embodiment of this application, a computer program product is also provided, the computer program product including computer instructions stored in a readable storage medium; at least one processor of the device reads the computer instructions from the readable storage medium, and the at least one processor executes the computer instructions to cause the device to perform the steps in the above method embodiments.

[0196] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for obtaining application type, characterized in that, The method is applied to a first network device, which connects multiple second network devices to a data network, and the second network devices communicate with user equipment; the method includes: Obtain feature information of the first packet in the data stream sent by the second network device, wherein the feature information is used to describe the characteristics of the first packet; Determine the application type corresponding to the feature information in the local feature library. The application type includes one or more refined types in the multi-level types that divide the application. The refined type is the level type below the first level in the multi-level types. The first level is the largest type. Send a second message to the second network device, the second message including the application type.

2. The method according to claim 1, characterized in that, The second message is a response message to the first message, the first message is a data message forwarded through a tunnel, and the application type is carried in the reserved field of the outer layer of the tunnel of the second message.

3. The method according to claim 2, characterized in that, The tunnel uses any of the following protocols: CAPWAP (Control and Configuration Protocol for Wireless Access Points), VxLAN (Virtual Extended LAN Protocol), GRE (Generic Routing Encapsulation) protocol, or SRV6 (Segment Routing Protocol Based on the Internet Protocol Version 6 (IPv6) Forwarding Plane).

4. The method according to claim 1, characterized in that, The second message is a response message to the first message, the first message is a data message, and the application type is carried in the reserved field of the protocol header of the second message.

5. The method according to claim 1, characterized in that, There is a management channel between the first network device and the second network device, and the second message is a management message or a configuration message.

6. The method according to claim 5, characterized in that, The second message uses any of the following protocols: CAPWAP, Simple Network Management Protocol (SNMP), or Network Configuration Protocol (netconf).

7. The method according to any one of claims 1-6, characterized in that, The feature information includes quintuple information.

8. The method according to any one of claims 1-7, characterized in that, The first network device is a core network device, and the second network device is an edge network device.

9. The method according to any one of claims 1-8, characterized in that, The application type also includes the first-level application category in the multi-level type.

10. A method for obtaining application type, characterized in that, It is applied to a second network device, which communicates with the user equipment. The second network device communicates with the data network through the first network device; the method includes: Send a data stream to the first network device, the data stream including a first message from the service data sent by the user equipment; The system receives a second message from the first network device. The second message includes an application type corresponding to the feature information of the first message. The application type includes one or more refined types in a multi-level type that divides the application. The refined type is a level type below the first level in the multi-level type, and the first level is the largest type.

11. The method according to claim 10, characterized in that, The method further includes: Obtain the application category of the first level in the multi-level type corresponding to the feature information of the first message; Differentiated processing is performed on the service to which the first message belongs, according to the application category and the detailed type.

12. The method according to claim 11, characterized in that, The application type also includes the application category; the first-level application category in the multi-level type corresponding to the feature information of the first message includes: Obtain the application category included in the second message.

13. The method according to claim 11, characterized in that, The step of obtaining the feature information of the first message corresponding to the first-level application category in the multi-level type includes: Obtain the feature information of the first message; Based on the local feature library of the second network device, the application category corresponding to the feature information is determined.

14. An apparatus for acquiring application type, characterized in that, Deployed in a first network device, the first network device being used to connect multiple second network devices to a data network, the second network devices communicating with user equipment; the apparatus includes: The acquisition unit is configured to acquire feature information of a first packet in a data stream sent by the second network device, wherein the feature information is used to describe the features of the first packet; The determining unit is used to determine the application type corresponding to the feature information in the local feature library. The application type includes one or more refined types in the multi-level types that divide the application. The refined type is the level type below the first level in the multi-level types, and the first level is the largest type. The sending unit is configured to send a second message to the second network device, the second message including the application type.

15. An apparatus for acquiring application type, characterized in that, Deployed on a second network device, which communicates with the user equipment; The second network device communicates with the data network through the first network device; the apparatus includes: A sending unit is configured to send a data stream to the first network device, wherein the data stream includes a first message from the service data sent by the user equipment. The receiving unit is configured to receive a second message from the first network device, the second message including an application type corresponding to the feature information of the first message; the application type includes one or more refined types in a multi-level type that divides the application, the refined type being a level type below the first level in the multi-level type, the first level being the largest type.

16. A network device, characterized in that, The network device includes a processor and a memory, the memory storing instructions that, when executed by the processor, cause the network device to perform the method as described in any one of claims 1-13.

17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on the device, cause the device to perform the method as described in any one of claims 1-13.

18. A computer program product, characterized in that, The computer program product includes a computer program that, when run on a device, causes the device to perform the method as described in any one of claims 1-13.