Information transmission method, routing device and storage medium
By transmitting routing protocol information in parallel, the problem of poor transmission performance of isolation strategies in user isolation schemes is solved, and user-granular isolation of more routing nodes is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING HUAWEI DIGITAL TECH
- Filing Date
- 2024-11-29
- Publication Date
- 2026-05-29
AI Technical Summary
In existing technologies, user isolation schemes based on user grouping suffer from poor transmission performance of service configuration information, resulting in some routing nodes being unable to obtain relevant information such as isolation policies between user groups, and thus unable to execute the user isolation scheme.
By transmitting routing protocol information in parallel, routing nodes can obtain isolation policies and the correspondence between users and user groups, thus achieving user-level isolation.
Improved the performance of routing nodes in obtaining isolation policies, ensuring that more routing nodes can execute user isolation schemes based on user grouping, and achieving user-level isolation.
Smart Images

Figure CN122120181A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, specifically to an information transmission method, routing device, and storage medium. Background Technology
[0002] The implementation process of the user isolation scheme based on user grouping can be as follows: the routing node obtains relevant information such as the isolation policy between user groups, and when it receives a message sent by the source user, it determines whether the group corresponding to the source user of the message can communicate with the group corresponding to the destination user of the message based on the relevant information such as the isolation policy between user groups, and then determines whether to send the message to the routing node accessed by the destination user, so as to achieve user-granular isolation.
[0003] Currently, isolation policies and other related information between user groups are mainly distributed through service configuration information (such as net count information). However, the transmission performance of service configuration information is poor, which may cause some routing nodes to be unable to obtain information such as isolation policies between user groups, thus preventing some routing nodes from implementing user isolation schemes based on user grouping. Summary of the Invention
[0004] To address the aforementioned technical problems, embodiments of this application provide an information transmission method, a routing device, and a storage medium, which enable as many routing nodes as possible to obtain relevant information such as isolation strategies between user groups, thereby enabling as many routing nodes as possible to execute user isolation schemes based on user grouping.
[0005] Firstly, an information transmission method is provided. This method can be executed by any routing node in a local area network (LAN), or by a component of the routing node, such as its processor, chip, or chip system. It can also be implemented by a logic module or software capable of implementing all or part of the routing nodes. The following explanation uses the execution of this method by a routing node as an example. This information transmission method includes: a routing node forwarding routing protocol information received from a controller to its neighboring routing nodes in the LAN, so that all routing nodes in the LAN can obtain the routing protocol information. The routing protocol information is used to indicate isolation policies and the correspondence between users and user groups in the LAN, while the isolation policy specifies access permissions between different user groups.
[0006] The routing protocol information can be information that is propagated between routing nodes and can be flooded to any routing node in the virtual local area network. After receiving the routing protocol information, the routing node can learn the content carried in the routing protocol information, namely the routing information, isolation policies, and the correspondence between users and user groups in the local area network that are used to instruct the routing nodes in the local area network to synchronize.
[0007] In this embodiment, since the amount of information transmitted in parallel with the routing protocol information is high, that is, the transmission performance of the routing protocol information is good, based on the routing protocol information transmission isolation policy and the correspondence between users and user groups in the local area network, as many routing nodes as possible can obtain the isolation policy and the correspondence between users and user groups in the local area network, that is, as many routing nodes as possible can obtain the isolation policy and other related information between user groups, thereby enabling as many routing nodes as possible to execute the user isolation scheme based on user grouping.
[0008] In conjunction with the first aspect described above, in one possible implementation, the method provided in this application further includes: the routing node can learn the isolation policy and the correspondence between users and user groups in the local area network from the received routing protocol information, providing data preparation for the routing node to execute a user isolation scheme based on user grouping. Furthermore, the routing node receives the packet from the source user and, based on the learned isolation policy and the correspondence between users and user groups in the local area network, determines whether to send the packet to the destination user, thereby implementing a user isolation scheme based on user grouping, that is, implementing user-level isolation.
[0009] In addition, the message sent by the source user includes the data to be transmitted by the source user; or, the message sent by the source user includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user. This provides multiple forms of messages so that routing nodes can determine messages based on multiple forms, thereby improving the reliability of message generation.
[0010] In conjunction with the first aspect mentioned above, in one possible implementation, the identifier of the user group corresponding to the source user is carried in the virtual LAN tag.
[0011] In other words, since the VLAN tag is a field transmitted between routing nodes in a VLAN system, the identifier of the user group corresponding to the source user is carried in the VLAN tag, which enables the transmission of the identifier of the user group corresponding to the user in the VLAN system.
[0012] In conjunction with the first aspect mentioned above, in one possible implementation, the identifier of the user group corresponding to the source user is transmitted transparently through the core routing node. This avoids redundant processing of the identifier of the user group corresponding to the source user by the core routing node, that is, it transmits the identifier of the user group corresponding to the source user in the simplest way, thereby reducing the processing and communication burden in the local area network.
[0013] In conjunction with the first aspect above, in one possible implementation, the identifier of the user group corresponding to the source user is carried in a first opaque tag, which is at least one opaque tag that is identified as carrying the identifier of the user group corresponding to the source user.
[0014] In other words, since the opaque tag is a field transmitted between routing nodes in a VLAN system, the identifier of the user group corresponding to the source user is carried in the VLAN tag that is used to carry the identifier of the user group corresponding to the source user. This enables the transmission of the user group identifier corresponding to the user in the VLAN system. Furthermore, the identifier of the user group corresponding to the source user is carried in an opaque tag.
[0015] In conjunction with the first aspect above, in one possible implementation, when the source user's message includes data to be transmitted by the source user, the decision on whether to send the message to the destination user is based on the isolation policy and the correspondence between users and user groups in the local area network. This includes: the routing node determining the user group corresponding to the source user based on the correspondence between the source user and the users and user groups in the local area network, and determining the user group corresponding to the destination user based on the correspondence between the destination user and the users and user groups in the local area network. If the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are allowed to access each other, the routing node sends the message to the destination user; or, if the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are not allowed to access each other, the routing node does not send the message to the destination user.
[0016] In other words, if the source user's message includes the data to be transmitted by the source user, but does not include the identifier of the user group corresponding to the source user, the routing node can determine the user group corresponding to the source user and the user group corresponding to the destination user on its own. Based on the access permissions of the user group corresponding to the source user and the user group corresponding to the destination user as indicated in the isolation policy, it can determine whether to send a message to the destination user. In this way, a user isolation scheme based on user grouping can be implemented with less information in the source user's message, thereby achieving user-granular isolation while reducing communication overhead.
[0017] In conjunction with the first aspect above, in one possible implementation, when the source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user, the determination of whether to send the message to the destination user is based on the isolation policy and the correspondence between users and user groups in the local area network. This includes: the routing node determining the user group corresponding to the destination user based on the correspondence between the destination user and the user group in the local area network, and sending the message to the destination user if the isolation policy indicates that the user group corresponding to the source user is allowed to access the user group corresponding to the destination user; or, not sending the message to the destination user if the isolation policy indicates that the user group corresponding to the source user is not allowed to access the user group corresponding to the destination user.
[0018] In other words, when the source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user, the routing node can avoid determining the user group corresponding to the source user, i.e., it avoids maintaining the mapping relationship between source users and user groups. It only needs to determine the user group corresponding to the destination user. Furthermore, the routing node can determine whether to send a message to the destination user based on the access permissions of the user group corresponding to the source user and the user group corresponding to the destination user as indicated in the isolation policy. This saves the routing node from executing user isolation schemes based on user grouping, thus reducing the processing burden on the routing node.
[0019] In conjunction with the first aspect above, in one possible implementation, the routing protocol information is used to indicate Border Gateway Protocol (BGP) routing information and / or Enhanced Border Gateway Protocol (EBGP) routing information. This allows the information transmission method described in the embodiments of this application to be integrated with multiple routing protocols, thereby broadening the application scenarios of the information transmission method described in the embodiments of this application.
[0020] Secondly, an information transmission method is provided. This method can be executed by a controller, or by a component of the controller, such as the controller's processor, chip, or chip system, or by a logic module or software capable of implementing all or part of the controller. The following explanation uses the method executed by the controller as an example. This information transmission method includes: the controller sending routing protocol information to any routing node in the local area network (LAN). The routing protocol information indicates isolation policies and the correspondence between users and user groups in the LAN, while the isolation policies specify access permissions between different user groups.
[0021] Thirdly, a routing device is provided for implementing the various methods described above. This routing device can be a routing node in the first aspect or any implementation thereof, or a device containing the routing node, or a device included in the routing node, such as a chip; or, the routing device can be a controller in the second aspect or any implementation thereof, or a device containing the controller, or a device included in the controller, such as a chip. The routing device includes modules, units, or means corresponding to the methods described above, which can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions described above.
[0022] In some possible designs, the routing device may include a processing module and a transceiver module. The transceiver module, also referred to as a transceiver unit, is used to implement the transmission and / or reception functions in any of the above aspects and their possible implementations. The transceiver module may consist of transceiver circuits, transceivers, transceivers, or communication interfaces. The processing module can be used to implement the processing functions in any of the above aspects and their possible implementations.
[0023] In some possible designs, the transceiver module includes a sending module and a receiving module, which are used to implement the sending and receiving functions in any of the above aspects and any possible implementation methods.
[0024] Fourthly, a routing device is provided, comprising: a processor and a memory; the memory is used to store computer instructions, which, when executed by the processor, cause the routing device to perform the methods of any of the above aspects. The routing device may be a routing node in the first aspect or any implementation thereof, or a device including the routing node, or a device included in the routing node, such as a chip; or, the routing device may be a controller in the second aspect or any implementation thereof, or a device including the controller, or a device included in the controller, such as a chip.
[0025] Fifthly, a routing device is provided, comprising: a processor and a communication interface; the communication interface being used to communicate with a module outside the routing device; the processor being used to execute computer programs or instructions such that the routing device can be a routing node in the first aspect or any implementation thereof, or a device including the routing node, or a device included in the routing node, such as a chip; or, the routing device can be a controller in the second aspect or any implementation thereof, or a device including the controller, or a device included in the controller, such as a chip.
[0026] A sixth aspect provides a routing device, comprising: at least one processor; the processor being configured to execute a computer program or instructions stored in a memory to cause the routing device to perform the methods of any of the above aspects. The memory may be coupled to the processor, or may be independent of the processor. The routing device may be a routing node in the first aspect or any implementation thereof, or a device including the routing node, or a device included in the routing node, such as a chip; or, the routing device may be a controller in the second aspect or any implementation thereof, or a device including the controller, or a device included in the controller, such as a chip.
[0027] In a seventh aspect, a computer-readable storage medium is provided that stores a computer program or instructions that, when executed on a routing device, enable the routing device to perform the methods of any of the above aspects or any implementation thereof.
[0028] Eighthly, a computer program product containing instructions is provided that, when run on a routing device, enables the routing device to perform the method of any of the above aspects or any implementation thereof.
[0029] In a ninth aspect, a routing device (e.g., a chip or chip system) is provided, the routing device including a processor for implementing the functions involved in any of the foregoing aspects or any implementation thereof.
[0030] In some possible designs, the routing device includes a memory for storing necessary program instructions and data.
[0031] In some possible designs, when the device is a chip system, it can be composed of chips or contain chips and other discrete components.
[0032] It is understood that when the routing device provided by any of the third to sixth aspects is a chip, the aforementioned sending action / function can be understood as an output, and the aforementioned receiving action / function can be understood as an input.
[0033] In a tenth aspect, an information transmission method is provided, which includes the method of the first aspect or any implementation thereof, and the method of the second aspect or any implementation thereof.
[0034] Eleventhly, a communication system is provided, which includes the controller and the routing node described above.
[0035] In a twelfth aspect, a computer program product is provided that, when run on a routing device, enables the routing device to perform the methods of any of the above aspects or any implementation thereof.
[0036] The technical effects of any of the implementation methods in aspects two through twelfth can be found in the technical effects of the corresponding implementation method in aspect one, and will not be repeated here.
[0037] Among these, any possible implementation methods of any one of the above aspects can be combined, provided that the solutions do not contradict each other. Attached Figure Description
[0038] Figure 1 A complete flowchart illustrating a user isolation scheme based on user grouping is provided in this application embodiment;
[0039] Figure 2 A structural example diagram of a VXLAN system provided in this application embodiment;
[0040] Figure 3 A schematic diagram of a possible, non-limiting communication system provided for an embodiment of this application;
[0041] Figure 4 A schematic diagram of yet another possible, non-limiting communication system provided for embodiments of this application;
[0042] Figure 5 This is a schematic diagram of the structure of a routing device provided in an embodiment of this application;
[0043] Figure 6 A flowchart illustrating an information transmission method provided in an embodiment of this application;
[0044] Figure 7 A flowchart illustrating another information transmission method provided in an embodiment of this application;
[0045] Figure 8 This is an example diagram illustrating the transmission of VLAN tags between two leaf switches via a spine switch, as provided in an embodiment of this application.
[0046] Figure 9 An example diagram of a source user's message provided in an embodiment of this application;
[0047] Figure 10 This is a schematic diagram of another routing device provided in an embodiment of this application. Detailed Implementation
[0048] To facilitate understanding of the technical solution of this application, the application will be further described below with reference to the accompanying drawings.
[0049] The terms "first" and "second," etc., used in the specification, claims, and drawings of this application are used only to distinguish different objects and not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.
[0050] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0051] In this application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three or more, and "and / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. "Or" indicates that there can be two relationships, such as only A exists or only B exists; when A and B are not mutually exclusive, it can also mean that there are three relationships, such as only A exists, only B exists, or both A and B exist simultaneously. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c".
[0052] In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as XX being the receiving end of the information, which can include direct transmission via the air interface or indirect transmission via the air interface from other units or modules. "Receive information from YY" can be understood as YY being the sending end of the information, which can include direct reception from YY via the air interface or indirect reception from YY via the air interface from other units or modules. "Send" can also be understood as the "output" of a chip interface, and "receive" can also be understood as the "input" of a chip interface. In other words, sending and receiving can occur between devices, such as between two stations, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, trace, or interface.
[0053] In this application, "instruction" can be understood as direct instruction or indirect instruction, and the embodiments of this application do not impose any restrictions on this.
[0054] With increasing awareness of network security, most large and medium-sized networks (such as data centers and campus office networks) require isolation of users (terminals or servers) accessing the network. Traditional isolation solutions mainly include Virtual Local Area Networks (VLANs), Virtual Extended Local Area Networks (VXLANs), Access Control List (ACL)-based isolation solutions, and physical scope-based isolation solutions. However, these traditional isolation solutions also have drawbacks. The following provides a detailed explanation of the traditional isolation solutions described above and their shortcomings.
[0055] VLANs (Virtual Private Networks) are a technology that logically divides a physical local area network (LAN) into multiple broadcast domains. Each broadcast domain is a VLAN. Devices within the same VLAN can communicate directly, while devices in different VLANs cannot communicate directly, thus restricting packet transmission to a single VLAN for isolation. VLANs are typically implemented at the service level; that is, VLANs can achieve service-level isolation, but not user-level isolation.
[0056] VXLAN is an isolation technology that extends VLAN. VXLAN is identified by a 24-bit VXLAN network identifier (VNI), which greatly expands its scalability, enabling its application in large networks for greater isolation. However, VXLAN is also based on service-level granularity; that is, it can achieve service-level isolation but not user-level isolation.
[0057] ACL-based isolation schemes aim to isolate users by controlling their access permissions to specific resources. While ACL-based isolation schemes can achieve fine-grained isolation, they require the deployment of a large number of ACLs, placing high demands on the capabilities and management of devices within the virtual LAN. This makes ACL-based isolation schemes difficult to implement in practice, and thus challenging to achieve.
[0058] Physical scope-based isolation schemes define a physical scope that can be directly accessed, while devices outside that physical scope are not allowed to access it.
[0059] However, user isolation schemes based on user groups can overcome the shortcomings of the traditional isolation schemes described above. In simple terms, the implementation process of a user isolation scheme based on user groups can be as follows: Routing nodes obtain relevant information such as isolation policies between user groups (i.e., the correspondence between users and user groups, and the access permissions between user groups). Upon receiving a packet sent by a source user, the routing node determines, based on the isolation policies between user groups, whether the packet corresponding to the source user of the packet can communicate with the packet corresponding to the destination user. It then determines whether to send the packet to the routing node accessed by the destination user, thus achieving user-level isolation.
[0060] The following provides a complete and detailed explanation of user isolation schemes based on user grouping. Figure 1 This is a complete flowchart of a user isolation scheme based on user grouping, as shown below. Figure 1 As shown, the complete process of a user isolation scheme based on user grouping can be achieved through the following steps.
[0061] S101. Relevant management personnel input the standardized correspondence between users and user groups, as well as the access permissions between user groups, into the network management system, and then distribute the correspondence between users and user groups, as well as the access permissions between user groups, to the execution point devices in the network.
[0062] Optionally, the access permissions between user groups can also be referred to as an isolation strategy or an isolation matrix, and this application embodiment does not impose any restrictions on this.
[0063] S102. During the first user's online authentication process, the network management system can determine the first user's identifier (e.g., Internet Protocol (IP) address or Media Access Control (MAC) address) based on the first user's login conditions (e.g., username, location, terminal type, etc.) and associate the first user's identifier with the user group to determine the identifier of the user group corresponding to the first user.
[0064] S103. After the first user's online authentication is successful, the network management system will send the identifier of the user group corresponding to the first user as the authorization result to the authentication point device accessed by the first user.
[0065] S104. The authentication point device accessed by the first user writes the identifier of the user group corresponding to the first user into the original message, obtains the message to be transmitted, and sends the message to be transmitted to the execution point device corresponding to the second user.
[0066] The second user is the destination user of the message to be transmitted.
[0067] S105. The execution point device corresponding to the second user determines the identifier of the user group corresponding to the second user based on the identifier of the second user and the correspondence between users and user groups, and queries the access permissions between user groups to determine whether the user group corresponding to the first user and the user group corresponding to the second user are allowed to access each other.
[0068] S106. If the user group corresponding to the first user is allowed to access the user group corresponding to the second user, the execution point device corresponding to the second user sends the message to be transmitted to the authentication point device accessed by the second user; or, if the user group corresponding to the first user is not allowed to access the user group corresponding to the second user, the execution point device corresponding to the second user does not send the message to be transmitted to the authentication point device accessed by the second user.
[0069] Furthermore, user isolation schemes based on user grouping can be applied to VXLAN systems. Figure 2 Here is an example diagram of the architecture of a VXLAN system, such as... Figure 2As shown, the VXLAN system may include at least one edge device and at least one user device. The at least one edge device acts as an execution point device, while the user device may act as an authentication point device. The at least one edge device may include VXLAN tunnel endpoints (VTEP) 1, VTEP2, and VTEP3, which can communicate with each other via a VXLAN tunnel. The at least one user device may include user 1, user 2, user 3, and user 4. User 1 and user 2 can access VTEP1, and user 3 and user 4 can access VTEP2.
[0070] The following section describes a user isolation scheme based on user groups, applied to a VXLAN system.
[0071] One example, taking the message transmission between user device 1 and user device 3 as an example, illustrates a user isolation scheme based on user packet method. In this example, the implementation process of the user isolation scheme based on user packet method may include the following steps.
[0072] Step 1: VTEP1 and VTEP2 obtain the correspondence between users and user groups, as well as the access permissions between user groups.
[0073] The correspondence between users and user groups can be shown in Table 1 below. The correspondence between users and user groups can include the correspondence between user1 and group1, user2 and group2, and user3 and group3.
[0074] Table 1
[0075]
[0076]
[0077] Access permissions between user groups are shown in Table 2 below. N indicates that two user groups are not allowed to access each other, and Y indicates that two user groups are not allowed to access each other.
[0078] Table 2
[0079] User group identifier group1 group2 group3 group1 Y Y N group2 Y Y N group3 N N Y
[0080] Step 2: VTEP1 receives the first message sent by user1 device and determines the user group corresponding to user1 based on the identifier of user1 in the message, so as to determine the identifier of the user group corresponding to user1 (i.e., group1).
[0081] Step 3: VTEP1 performs corresponding VXLAN encapsulation on the first message and writes the identifier of the user group corresponding to user1 (i.e., group1) into the VXLAN header of the first message after VXLAN encapsulation to obtain the second message.
[0082] Step 4: VTEP1 sends a second message to VTEP2, and VTEP2 receives the second message from VTEP1.
[0083] Step 5: VTEP2 performs VXLAN decapsulation on the second message to determine the identifier of the user group corresponding to user1, the first message, and the identifier of the destination user (i.e., the identifier of user3).
[0084] Step 6: VTEP2 determines the identifier of the user group corresponding to user3 (i.e., group2) based on the correspondence between users and user groups and the identifier of the target user (i.e., the identifier of user3), and determines from the access permissions between user groups that group1 and group2 are allowed to access each other.
[0085] Step 7: VTEP2 sends the first message to user3 device, and user3 device receives the first message from VTEP2.
[0086] Another example, taking the message transmission between user device 2 and user device 4 as an example, illustrates a user isolation scheme based on user packet method. In this example, the implementation process of the user isolation scheme based on user packet method may include the following steps.
[0087] Step 8: VTEP1 and VTEP2 obtain the correspondence between users and user groups, as well as the access permissions between user groups.
[0088] The correspondence between users and user groups can be shown in Table 1 above. The access permissions between user groups can be shown in Table 2 above.
[0089] Step 9: VTEP1 receives the third message sent by user2 device and determines the user group corresponding to user2 based on the identifier of user2 in the message, so as to determine the identifier of the user group corresponding to user2 (i.e., group1).
[0090] Step 10: VTEP1 performs corresponding VXLAN encapsulation on the third message and writes the identifier of the user group corresponding to user2 (i.e., group1) into the VXLAN header of the encapsulated third message to obtain the fourth message.
[0091] Step 11: VTEP1 sends the fourth message to VTEP2, and VTEP2 receives the fourth message from VTEP1 accordingly.
[0092] Step 12: VTEP2 performs VXLAN decapsulation on the fourth message to determine the identifier of the user group corresponding to user2, the third message, and the identifier of the destination user (i.e., the identifier of user4).
[0093] Step 13: VTEP2 determines the identifier of the user group corresponding to user4 (i.e., group3) based on the correspondence between users and user groups and the identifier of the target user (i.e., the identifier of user4), and determines from the access permissions between user groups that group1 and group3 are not allowed to access each other.
[0094] Step 14: VTEP2 discards the third message and does not send the third message to user4 device. Correspondingly, user4 device receives the third message from VTEP2.
[0095] Understandably, user isolation schemes based on user grouping can achieve isolation at the user level, rather than just at the business level, and by grouping and aggregating users, they reduce the regulations governing access control between users. Furthermore, since user grouping is based on the correspondence between user identifiers and user groups, user isolation schemes based on user grouping are not related to the user's access location, thus allowing them to be applied in scenarios involving user roaming or migration.
[0096] Currently, user isolation schemes based on user grouping primarily use service configuration information (e.g., netcounf information) to distribute isolation policies and other related information between user groups (i.e., the correspondence between users and user groups, and the access permissions between user groups). However, the transmission performance of service configuration information is poor, which may cause some routing nodes to be unable to obtain the isolation policies and other related information between user groups, thus preventing some routing nodes from executing the user isolation scheme.
[0097] This application provides an information transmission method. Since the amount of information transmitted in parallel with routing protocol information is high, that is, the transmission performance of routing protocol information is good, based on the routing protocol information transmission isolation strategy and the correspondence between users and user groups in the local area network, as many routing nodes as possible can obtain the isolation strategy and the correspondence between users and user groups in the local area network. That is, as many routing nodes as possible can obtain the isolation strategy and other related information between user groups, thereby enabling as many routing nodes as possible to execute the user isolation scheme based on user grouping.
[0098] The technical solution provided in this application can be applied to various communication systems, such as VLAN systems, VXLAN systems, or future local area network systems. The application scenarios of the technical solution provided in this application can include a variety of scenarios, such as machine-to-machine (M2M), enhanced mobile broadband (eMBB), ultra-reliable and low-latency communication (uRLLC), and massive machine-type communication (mMTC). These scenarios may include, but are not limited to: communication scenarios between controllers and routing nodes, communication scenarios between routing nodes, and communication scenarios between routing nodes and user equipment.
[0099] Figure 3 A schematic diagram of a possible, non-limiting communication system is shown. (e.g.) Figure 3 As shown, the communication system 3000 includes at least one controller 301 and at least one routing node 302. It should be understood that... Figure 3 This explanation uses one controller 301 and two routing nodes 302 as an example. Figure 3 The number of controllers 301 and routing nodes 302 is just an example; there can be more or fewer.
[0100] In one possible implementation, routing node 302 receives routing protocol information from controller 301 and sends the routing protocol information to its neighboring routing nodes 302 in the local area network. This forwards the routing protocol information obtained from controller 301 to the neighboring routing nodes 302, ensuring that all routing nodes in the communication system 3000 can obtain the routing protocol information. The routing protocol information indicates isolation policies and the correspondence between users and user groups in the local area network, while the isolation policies specify access permissions between different user groups. The specific implementation and related technical effects of this scheme can be found in subsequent method embodiments and will not be elaborated upon here.
[0101] In another possible implementation, controller 301 sends routing protocol information to any routing node 302 in the local area network (LAN). This routing protocol information indicates the isolation policy and the correspondence between users and user groups in the LAN, while the isolation policy specifies access permissions between different user groups. The specific implementation and related technical effects of this scheme can be found in subsequent method embodiments and will not be elaborated upon here.
[0102] Optionally, routing node 302 can be divided into spine switches and leaf switches according to their functions. Figure 4 A schematic diagram of another possible, non-limiting communication system is shown. For example... Figure 4 As shown, the communication system 4000 may include at least one controller 301, at least one spine switch 401, and at least one leaf switch 402. The leaf switch 402 can be connected to the controller 301, and two leaf switches 402 can communicate with each other through the spine switch 401. Furthermore, at least one user device can be connected to the leaf switch 402, thus the communication system 4000 may also include at least one user device 403. It should be understood that... Figure 4 The following example illustrates the system using one controller 301, four Spine switches 401, four Leaf switches 402, and seven user devices 403. Figure 4 The number of controllers 301, spine switches 401, leaf switches 402, and user equipment 403 is just an example; there can be more or fewer.
[0103] In one possible implementation, the routing node and controller in the embodiments of this application may also be referred to as a routing device, which may be a general-purpose device or a special-purpose device. The embodiments of this application do not specifically limit this.
[0104] In one possible implementation, the functions of the routing node or controller in this application embodiment can be implemented by one device, multiple devices working together, or one or more functional modules within a single device. This application embodiment does not specifically limit this. It is understood that the above functions can be network elements in hardware devices, software functions running on dedicated hardware, a combination of hardware and software, or virtualization functions instantiated on a platform (e.g., a cloud platform).
[0105] For example, the related functions of the routing node and controller in the embodiments of this application can be achieved through... Figure 5 The routing device 510 in the middle is used to implement this. Figure 5 A schematic diagram of a possible routing device is shown. It will be understood that the routing device 510 includes means of the necessary form, such as modules, units, elements, circuits, or interfaces, to be appropriately configured together to perform this solution. The routing device 510 can be... Figure 3 or Figure 4 The routing device 510 includes one or more processors 511. The processor 511 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control the routing device (e.g., a routing node, a controller, etc.), execute software programs, and process data from the software programs.
[0106] Optionally, in one design, the processor 511 may include a program 513 (sometimes also referred to as code or instructions), which can be executed on the processor 511 to cause the routing device 510 to perform the methods described in the embodiments below. In yet another possible design, the routing device 510 includes circuitry (…). Figure 5 (Not shown), the circuit is used to implement the communication function in the following embodiments.
[0107] Optionally, the routing device 510 may include one or more memories 512 storing a program 514 (sometimes referred to as code or instructions), which can be run on the processor 511 to cause the routing device 510 to perform the methods described in the following method embodiments.
[0108] Optionally, the processor 511 and / or memory 512 may include artificial intelligence (AI) modules 517 and 518, which are used to implement AI-related functions. AI modules 517 or 518 can be implemented through software, hardware, or a combination of both. For example, AI modules 517 or 518 may include a radio intelligent controller (RIC) module. For example, AI modules 517 or 518 can be near real-time RICs or non-real-time RICs.
[0109] Optionally, data may also be stored in the processor 511 and / or the memory 512. The processor and memory may be configured separately or integrated together.
[0110] Optionally, the routing device 510 may also include a transceiver 515 and / or an antenna 516. The processor 511, sometimes referred to as a processing unit, controls the routing device (e.g., a routing node, a controller). The transceiver 515, sometimes referred to as a transceiver unit, transceiver, transceiver circuit, or transceiver, is used to implement the transmission and reception functions of the routing device via the antenna 516.
[0111] The following will combine Figure 6 The information transmission method provided in the embodiments of this application will be described in detail below.
[0112] In the following embodiments of this application, the message names, parameter names, or information names between network elements are merely examples, and other names may be used in other embodiments. The methods provided in the embodiments of this application are not specifically limited in this regard. It is understood that in the embodiments of this application, each network element may execute some or all of the steps in the embodiments of this application. These steps or operations are examples, and the embodiments of this application may also execute other operations or variations of various operations. Furthermore, the steps may be executed in different orders as presented in the embodiments of this application, and it is not necessary to execute all the operations in the embodiments of this application.
[0113] Figure 6 This is an example of the information transmission method provided in this application. The method is described using the interaction between a routing node and a controller as an example. Of course, the entity executing the routing node's actions in this method can also be a device / module within the routing node, such as a chip, processor, or processing unit within the routing node; similarly, the entity executing the controller's actions in this method can also be a device / module within the controller, such as a chip, processor, or processing unit within the controller. This application does not specifically limit this. For example, as shown... Figure 6 As shown, the information transmission method includes the following steps:
[0114] S601: The controller sends routing protocol information to any routing node in the local area network, and the routing node receives the routing protocol information from the controller accordingly.
[0115] The routing protocol information is used to indicate the routing information synchronized by the routing nodes in the local area network. The routing protocol information is also used to indicate the isolation policy (also known as the isolation matrix) and the correspondence between users and user groups in the local area network. The isolation policy is used to specify the access permissions between different user groups.
[0116] For example, taking a local area network (LAN) with users including user 1, user 2, and user 3, and user groups including user group 1 and user group 2 as an example: the correspondence between users and user groups recorded in this application embodiment may include the correspondence between user 1 and user group 1, the correspondence between user 2 and user group 1, and the correspondence between user 3 and user group 2.
[0117] Furthermore, exemplary, the isolation strategy described in the embodiments of this application may include allowing user group 1 to access each other with user group 2, allowing user group 1 to access each other with user group 3, and allowing user group 2 to access each other with user group 3.
[0118] Optionally, routing protocol information is used to indicate Border Gateway Protocol (BGP) routing information and / or Enhanced Border Gateway Protocol (EBGP) routing information. Furthermore, isolation policies and the mapping between users and user groups within the local area network (LAN) can be carried in at least one of the BGP, EBGP, and RIP routing information. In other words, the controller can extend at least one of the BGP, EBGP, and RIP routing information to add isolation policies and mappings between users and user groups within the LAN.
[0119] It is understood that the routing protocol information is used to indicate at least one of BGP routing information, EBGP routing information, and RIP routing information, so that the information transmission method described in the embodiments of this application can be integrated with multiple routing protocols, thereby broadening the application scenarios of the information transmission method described in the embodiments of this application.
[0120] Of course, the above is an exemplary description of routing protocol information. Routing protocol information may also include other routing information, such as interior gateway routing protocol (IGRP) routing information. This application embodiment does not impose any limitations on this.
[0121] Furthermore, optionally, taking the example of the controller being able to extend BGP routing information to add the mapping relationship between users and user groups in the local area network: During the generation of BGP routing information, the controller can specify the end point group ID (epgid), which can be used to indicate the identifier of the user group and establish the mapping relationship between users and user groups in the local area network, so as to add the mapping relationship between users and user groups in the local area network to the BGP routing information.
[0122] For example, as shown in Table 3 below, the BGP routing information described in this application embodiment may include: next hop, isolation strategy, and the correspondence between users and user groups in the local area network (LAN). The correspondence between users and user groups in the LAN includes user identifiers (e.g., network layer reachability information (NLRI)) and the user group identifiers corresponding to the user (e.g., epqid). For example, as shown in Table 3 below, the NLRI included in the correspondence between users and user groups in the LAN is 192.168.10.1, and the epqid included in the correspondence between users and user groups in the LAN is 10. Of course, the above is an exemplary description of BGP routing information; BGP routing information may also include other information, and this application embodiment does not impose any limitations on this.
[0123] Table 3
[0124] BGP routing information Field value NLRI 192.168.10.1 Netxthop 1.1.1.1 epqid 10 isolation strategy /
[0125] In addition, optionally, the users in the local area network described in the embodiments of this application may include all or some users in the local area network who have passed online authentication. The embodiments of this application do not impose any restrictions on this.
[0126] In this embodiment, the local area network (LAN) may include at least one VLAN and at least one VXLAN; this embodiment does not impose any limitations on this. Routing nodes may include switches or routers; this embodiment also does not impose any limitations on this.
[0127] S602. Any routing node in the local area network (LAN) sends routing protocol information to its neighboring routing nodes in the LAN. Correspondingly, the neighboring routing nodes in the LAN receive routing protocol information from any routing node in the LAN.
[0128] This application provides an information transmission method. Since the amount of information transmitted in parallel with routing protocol information is high, that is, the transmission performance of routing protocol information is good, based on the routing protocol information transmission isolation strategy and the correspondence between users and user groups in the local area network, as many routing nodes as possible can obtain the isolation strategy and the correspondence between users and user groups in the local area network. That is, as many routing nodes as possible can obtain the isolation strategy and other related information between user groups, thereby enabling as many routing nodes as possible to execute the user isolation scheme based on user grouping.
[0129] As described above regarding the "user isolation scheme based on user grouping," the routing node can obtain the isolation policy and the correspondence between users and user groups in the local area network (LAN), enabling it to perform user isolation based on the isolation policy and the correspondence between users and user groups in the LAN. Therefore, the information transmission method described in this application embodiment may further include the process of the routing node performing user isolation. In view of this, as... Figure 7 As shown, the process of routing nodes performing user isolation as described in the embodiments of this application can also be implemented through the following S701 to S703.
[0130] S701, the routing node receives messages from the source user.
[0131] In one possible implementation, the S701 process can be as follows: The source user inputs the data to be transmitted into its user equipment. The source user's user equipment generates a source user message based on the data to be transmitted and sends the source user message to the routing node. Correspondingly, the routing node receives the source user message from the source user's user equipment.
[0132] The source user's message includes the data to be transmitted by the source user; or, the source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user. The source user is a user in the local area network.
[0133] Optionally, the identification of user groups can be understood by referring to the descriptions in the corresponding positions above, and will not be repeated here.
[0134] S702, the routing node learns routing protocol information, obtains isolation policies, and the correspondence between users and user groups in the local area network.
[0135] S703: Based on the isolation policy and the correspondence between users and user groups in the local area network, the routing node determines whether to send the source user's packet to the destination user of the source user's packet.
[0136] The target user is a user within the local area network.
[0137] In addition, optionally, the users (e.g., source user, destination user) described in the embodiments of this application can be understood as user equipment, and the embodiments of this application do not impose any restrictions on this.
[0138] The implementation process of S703 will be explained in detail below.
[0139] As mentioned earlier regarding the "source user's message," it can be divided into two cases: Case 1, the source user's message includes the data to be transmitted by the source user; Case 2, the source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user. However, the implementation of S703 differs in these different cases. The following provides a detailed explanation of the implementation process of S703 in different cases.
[0140] Scenario 1: The source user's message includes the data to be transmitted by the source user.
[0141] Optionally, in Case 1, the implementation process of S703 can be as follows: The routing node can determine the user group corresponding to the source user based on the correspondence between the source user and the users and user groups in the local area network, and determine the user group corresponding to the destination user based on the correspondence between the destination user and the users and user groups in the local area network. If the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are allowed to access each other, the routing node sends the source user's packet to the destination user; or, if the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are not allowed to access each other, the routing node does not send the source user's packet to the destination user.
[0142] Alternatively, if the source user's packet does not include the identifier of the user group corresponding to the source user, the routing node may also directly discard the source user's packet and not perform the S603 related operations.
[0143] Understandably, when the source user's message includes the data to be transmitted by the source user, that is, when the source user's message does not include the identifier of the user group corresponding to the source user, the routing node can determine the user group corresponding to the source user and the user group corresponding to the destination user on its own. Based on the access permissions of the user group corresponding to the source user and the user group corresponding to the destination user as indicated in the isolation policy, it can determine whether to send a message to the destination user. In this way, a user isolation scheme based on user grouping can be implemented with less information in the source user's message, thereby achieving user-granular isolation while reducing communication overhead.
[0144] Case 2: The source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user.
[0145] Optionally, in case 2, the implementation process of S703 can be as follows: the routing node determines the user group corresponding to the destination user based on the correspondence between the destination user and the user and user group in the local area network, and sends the source user's message to the destination user if the isolation policy indicates that the user group corresponding to the source user is allowed to access the user group corresponding to the destination user; or, if the isolation policy indicates that the user group corresponding to the source user is not allowed to access the user group corresponding to the destination user, the source user's message is not sent to the destination user.
[0146] Understandably, in scenario 1, the routing node matches the source user and destination user of the packet to determine the user group corresponding to the source user and the user group corresponding to the destination user. This requires the routing node to maintain not only the mapping between source users and user groups but also the mapping between destination users and user groups. For medium to large-sized networks, maintaining this mapping between users and user groups is costly and lacks scalability.
[0147] Therefore, an identifier for the user group corresponding to the source user can be added to the source user's packet. This ensures that the source user's packet includes both the data to be transmitted and the identifier of the user group. This eliminates the need for routing nodes to determine the user group corresponding to the source user, and thus avoids maintaining the mapping between source users and user groups. Instead, the routing node only needs to determine the user group corresponding to the destination user. Furthermore, the routing node can determine whether to send a packet to the destination user based on the access permissions of the user groups corresponding to the source user and the destination user as indicated in the isolation policy. This saves the routing node from executing user isolation schemes based on user grouping, thus reducing its processing burden.
[0148] As can be seen from the description of the "user isolation scheme based on user grouping", the authentication point device that the first user accesses writes the identifier of the user group corresponding to the first user into the original message, that is, the identifier of the user group corresponding to the user can be carried in the original message.
[0149] Furthermore, in a possible implementation of the general technology, the identifier of the user group corresponding to the user can be carried in the Group Policy ID field in the VXLAN header of the original message. The Group Policy ID field is a VXLAN-GPE extension header determined based on the VXLAN-generic protocol extension (GPE) technology.
[0150] This implementation requires adding a VXLAN-GPE extension header to the VXLAN-encapsulated packet so that the VXLAN-GPE extension header can include the identifier of the user's corresponding user group. However, the commercial chips used in current routing nodes do not support programming the packet forwarding process, thus preventing current routing nodes from adding the VXLAN-GPE extension header to VXLAN-encapsulated packets, and also preventing the addition of the VXLAN-GPE extension header to VXLAN-encapsulated packets through software upgrades.
[0151] In another possible implementation of general technology, the identifier of the user group corresponding to the user can be carried in the reserved field of the VXLAN header in the original message. That is, in this implementation, the identifier of the user group corresponding to the user can be carried in the reserved field of the VXLAN header.
[0152] However, the relevant protocol stipulates that reserved fields (24 bits and 8 bits) must be set to zero. If the reserved fields in the VXLAN header are used to carry the identifier of the user's corresponding user group, that is, if the reserved fields are not set to zero, the routing node is likely to drop the packet, which will prevent the scheme of using the reserved fields in the VXLAN header to carry the identifier of the user's corresponding user group for transmission from being implemented.
[0153] The two implementation methods described above are mainly applicable to VXLAN systems. Since the packets transmitted in a VLAN system do not contain a VXLAN header field, these two implementation methods cannot be applied to VLAN systems; that is, it is impossible to transmit the user group identifier corresponding to a user in a VLAN system.
[0154] In view of this, the information transmission method described in the embodiments of this application can provide the following two methods for carrying the identifier of the user group corresponding to the source user, so as to realize the transmission of the identifier of the user group corresponding to the user in the VLAN system: Method 1: The identifier of the user group corresponding to the source user is carried in a virtual local area network tag (VLAN tag); Method 2: The identifier of the user group corresponding to the source user is carried in a first opaque tag, wherein the first opaque tag is at least one opaque tag that is identified as carrying the identifier of the user group corresponding to the source user. The two methods are described in detail below.
[0155] In the first method of carrying out the process, the identifier of the user group corresponding to the source user is carried in the virtual LAN tag.
[0156] It is understandable that, since the VLAN tag is a field transmitted between routing nodes in a VLAN system, the identifier of the user group corresponding to the source user is carried in the VLAN tag, which enables the transmission of the identifier of the user group corresponding to the user in the VLAN system.
[0157] Optionally, in bearer mode one, the routing node can determine the identifier of the user group corresponding to the source user based on the source user's identifier and the correspondence between users and user groups included in its neural processing unit (NPU). Then, based on the identifier of the user group corresponding to the source user, a VLAN tag is added to the data to be transmitted by the source user to identify the source user's packet. In this case, the source user's packet includes a VLAN tag, and the VLAN tag includes the identifier of the user group corresponding to the source user.
[0158] Furthermore, a VLAN tag can also be understood as an identifier indicating the user group to which the source user belongs. For example, VLAN tag 10 can be used to indicate user group 1, VLAN tag 20 can be used to indicate user group 2, and VLAN tag 30 can be used to indicate user group 3. Therefore, if user group 1 and user group 2 are allowed to access each other, then users corresponding to VLAN tag 10 and users corresponding to VLAN tag 20 are allowed to access each other; similarly, if user group 2 and user group 3 are allowed to access each other, then users corresponding to VLAN tag 20 and users corresponding to VLAN tag 30 are allowed to access each other.
[0159] As Figure 4The communication system described in this application embodiment can be understood as follows: the communication system may include at least one spine switch and at least one leaf switch, and the two leaf switches can communicate with each other through the spine switch. If the routing node described in this application embodiment is a leaf switch, a Layer 3 routing interface can be configured between the leaf switch and the spine switch, so that the leaf switch can communicate with the spine switch through the Layer 3 routing interface, thereby enabling the two leaf switches to communicate with each other through the spine switch, that is, the two leaf switches can transmit information through the spine switch. In other words, the core routing node is the spine switch.
[0160] Optionally, taking the information transmitted between two leaf switches via a spine switch as an example, where the information is the identifier of the user group corresponding to the source user: the spine switch can transmit the identifier of the user group corresponding to the source user in a transparent manner, that is, the spine switch can transmit the VLAN tag in a transparent manner. In other words, after receiving the VLAN tag sent by the leaf switch corresponding to the source user, the spine switch does not modify or discard the VLAN tag, but sends the VLAN tag to the leaf switch corresponding to the destination user.
[0161] For example, Figure 8 This diagram illustrates an example of VLAN tag transmission between two leaf switches via a spine switch. Figure 8 As shown, Figure 8 The communication system shown may include a controller, at least one switch, such as leaf switch 1, leaf switch 2, leaf switch 3, and leaf switch 4, and at least one user (or user equipment), such as user equipment 1, user equipment 2, user equipment 3, user equipment 4, user equipment 5, user equipment 6, user equipment 7, and user equipment 8. Taking the transmission of VLAN tags between leaf switch 1 and leaf switch 3 via a spine switch as an example: leaf switch 1 can add a VLAN tag to the data to be transmitted by the source user (i.e., user equipment 1) to identify the source user's packet, and send the source user's packet to the spine switch. Correspondingly, the spine switch receives the source user's packet from leaf switch 1. The spine switch does not modify or delete the VLAN tag in the source user's packet, and sends the source user's packet to leaf switch 3. Correspondingly, leaf switch 3 receives the source user's packet from the spine switch. Leaf switch 3 is the switch accessed by the destination user (i.e., user equipment 3).
[0162] Method 2: The identifier of the user group corresponding to the source user is carried in the first opaque tag.
[0163] It is understandable that, since the opaque tag is a field transmitted between routing nodes in a VLAN system, the identifier of the user group corresponding to the source user is carried in the vlantag that is used to carry the identifier of the user group corresponding to the source user, thus enabling the transmission of the identifier of the user group corresponding to the user in the VLAN system.
[0164] Optionally, in bearer mode two, if the routing node described in this application embodiment is a leaf switch and the core routing node is a spine switch, then the spine switch can transmit the identifier of the user group corresponding to the source user through transparent transmission, that is, the spine switch can transmit the first opaque tag through transparent transmission. In other words, after receiving the first opaque tag sent by the leaf switch corresponding to the source user, the spine switch does not modify or discard the first opaque tag, but sends the first opaque tag to the leaf switch corresponding to the destination user.
[0165] For example, Figure 9 This is an example diagram of a source user's message provided in an embodiment of this application. Figure 9 As shown, the source user's message may include the destination MAC address (DMAC), source MAC address (SMAC), VLAN, first opaque tag, ethtype field, IP & User Datagram Protocol / Transmission Control Protocol (UDP / TCP), and payload.
[0166] Furthermore, exemplarily, such as Figure 9 As shown, the first opaque tag may include a tag protocol identifier (TPID) and information (info), where the info can be used to indicate the identifier of the user group corresponding to the source user; or, the first opaque tag may include TPID, info, control (ctrl), and miscellaneous information (misc-info), where the info can be used to indicate the identifier of the user group corresponding to the source user.
[0167] The above mainly describes the solutions provided by the embodiments of this application from the perspective of interaction between various network elements. Correspondingly, the embodiments of this application also provide a routing device for implementing the various methods described above. This routing device can be a controller in the above method embodiments, or a device including the controller, or a component usable in a controller; or, this routing device can be a routing node in the above method embodiments, or a device including the routing node, or a component usable in a routing node. It is understood that, in order to achieve the above functions, the routing device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0168] This application embodiment can divide the routing device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be understood that the module division in this application embodiment is illustrative and represents a logical functional division; in actual implementation, there may be other division methods.
[0169] Figure 10 A schematic diagram of a routing device 100 is shown. The routing device 100 includes a processing module 1001 and a transceiver module 1002. The transceiver module 1002, also known as a transceiver unit, is used to implement transceiver functions, and may be, for example, a transceiver circuit, a transceiver, a transceiver device, or a communication interface.
[0170] when Figure 10 When the routing device 100 shown is the routing node in the above embodiment:
[0171] In one possible implementation: the processing module 1001 is used to instruct the transceiver module 1002 to receive routing protocol information from the controller and send routing protocol information to the neighboring routing nodes of any routing node in the local area network. The routing protocol information is used to indicate the routing information synchronized by the routing nodes in the local area network. The routing protocol information is also used to indicate the isolation policy and the correspondence between users and user groups in the local area network. The isolation policy is used to specify the access permissions between different user groups.
[0172] In one possible implementation, the processing module 1001 is further configured to instruct the transceiver module 1002 to receive the message from the source user; wherein the message includes data to be transmitted by the source user; or, the message includes data to be transmitted by the source user and the identifier of the user group corresponding to the source user; the processing module 1001 is further configured to learn routing protocol information to obtain the isolation policy and the correspondence between users and user groups in the local area network; the processing module 1001 is further configured to determine whether to send the message to the destination user of the message based on the isolation policy and the correspondence between users and user groups in the local area network, wherein both the source user and the destination user are users in the local area network.
[0173] In one possible implementation, the identifier of the user group corresponding to the source user is carried in the virtual LAN tag.
[0174] In one possible implementation, the identifier of the user group corresponding to the source user is transparently transmitted through the core routing node.
[0175] In one possible implementation, the identifier of the user group corresponding to the source user is carried in a first opaque tag, which is at least one opaque tag that is identified as carrying the identifier of the user group corresponding to the source user.
[0176] In one possible implementation, if the source user's message includes data to be transmitted by the source user, the processing module 1001 is further configured to determine the user group corresponding to the source user based on the correspondence between the source user and users and user groups in the local area network, and to determine the user group corresponding to the destination user based on the correspondence between the destination user and users and user groups in the local area network; the processing module 1001 is further configured to send a message to the destination user if the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are allowed to access each other; or, if the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are not allowed to access each other, not to send a message to the destination user.
[0177] In one possible implementation, if the source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user, the processing module 1001 is further configured to determine the user group corresponding to the destination user based on the correspondence between the destination user and the users and user groups in the local area network, and send a message to the destination user if the isolation policy indicates that the user group corresponding to the source user is allowed to access the user group corresponding to the destination user; or, if the isolation policy indicates that the user group corresponding to the source user is not allowed to access the user group corresponding to the destination user, no message is sent to the destination user.
[0178] In one possible implementation, routing protocol information is used to indicate Border Gateway Protocol (BGP) routing information and / or Enhanced Border Gateway Protocol (EBGP) routing information.
[0179] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0180] In this embodiment, the routing node is presented as an integrated functional module. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the routing node can employ... Figure 5 The routing device 510 shown is in this form.
[0181] for example, Figure 5 The processor 511 in the routing device 510 shown can execute the information transmission method in the above method embodiment by calling the computer execution instructions stored in the memory 512.
[0182] Specifically, Figure 10 The functions / implementation process of the transceiver module 1002 and the processing module 1001 can be obtained through... Figure 5 The processor 511 in the routing device 510 shown calls computer execution instructions stored in memory 512 to implement the function. Alternatively, Figure 10 The function / implementation process of the processing module 1001 can be achieved through... Figure 5 The processor 511 in the routing device 510 shown calls computer execution instructions stored in the memory 512 to implement the function. Figure 10 The function / implementation process of the transceiver module 1002 can be obtained through Figure 5 This is achieved by the transceiver 515 in the routing device 510 shown.
[0183] Since the routing device 100 provided in this application embodiment can execute the above information transmission method, the technical effects it can obtain can be referred to the above method embodiment, and will not be repeated here.
[0184] when Figure 10 When the routing device 100 shown is the controller in the above embodiment:
[0185] In one possible implementation: the processing module 1001 is used to instruct the transceiver module 1002 to send routing protocol information to any routing node in the local area network. The routing protocol information is used to indicate the routing information synchronized by the routing node in the local area network. The routing protocol information is also used to indicate the isolation policy and the correspondence between users and user groups in the local area network. The isolation policy is used to specify the access permissions between different user groups.
[0186] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0187] In this embodiment, the routing node is presented as an integrated functional module. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the routing node can employ... Figure 5 The routing device 510 shown is in this form.
[0188] for example, Figure 5 The processor 511 in the routing device 510 shown can execute the information transmission method in the above method embodiment by calling the computer execution instructions stored in the memory 512.
[0189] Specifically, Figure 10 The functions / implementation process of the transceiver module 1002 and the processing module 1001 can be obtained through... Figure 5 The processor 511 in the routing device 510 shown calls computer execution instructions stored in memory 512 to implement the function. Alternatively, Figure 10 The function / implementation process of the processing module 1001 can be achieved through... Figure 5 The processor 511 in the routing device 510 shown calls computer execution instructions stored in the memory 512 to implement the function. Figure 10 The function / implementation process of the transceiver module 1002 can be obtained through Figure 5 This is achieved by the transceiver 515 in the routing device 510 shown.
[0190] Since the routing device 100 provided in this application embodiment can execute the above information transmission method, the technical effects it can obtain can be referred to the above method embodiment, and will not be repeated here.
[0191] In one possible implementation, this application embodiment also provides a routing device (e.g., the routing device may be a chip or a chip system), which includes a processor for implementing the methods in any of the above method embodiments. In one possible design, the routing device further includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the routing device to execute the methods in any of the above method embodiments. Of course, the memory may not be included in the routing device. When the routing device is a chip system, it may be composed of chips or may include chips and other discrete devices; this application embodiment does not specifically limit this.
[0192] In one possible implementation, this application also provides a computer-readable storage medium storing a computer program or instructions that, when run on a routing device, enable the routing device to execute the methods of any of the above-described method embodiments or any implementation thereof.
[0193] In one possible implementation, this application also provides an information transmission method, which includes the method of any of the above-described method embodiments or any implementation thereof.
[0194] In one possible implementation, this application embodiment also provides a communication system, which includes a routing node and a controller from the above method embodiments.
[0195] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).
[0196] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0197] Although this application has been described in conjunction with specific features and embodiments, it is apparent that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are exemplary illustrations of this application as defined by the appended claims and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
Claims
1. An information transmission method, characterized in that, The method, applicable to any routing node in a local area network, includes: Receive routing protocol information from the controller; The routing protocol information is sent to the neighboring routing nodes of any routing node in the local area network. The routing protocol information is used to indicate the routing information synchronized by the routing nodes in the local area network. The routing protocol information is also used to indicate the isolation policy and the correspondence between users and user groups in the local area network. The isolation policy is used to specify the access permissions between different user groups.
2. The method according to claim 1, characterized in that, The method further includes: Receive a message from a source user; wherein the message includes data to be transmitted by the source user; or, the message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user; Learn the routing protocol information to obtain the isolation policy and the correspondence between users and user groups in the local area network; Based on the isolation policy and the correspondence between users and user groups in the local area network, it is determined whether to send the message to the destination user of the message, wherein both the source user and the destination user are users in the local area network.
3. The method according to claim 2, characterized in that, The identifier of the user group corresponding to the source user is carried in the virtual LAN tag.
4. The method according to claim 3, characterized in that, The identifier of the user group corresponding to the source user is transmitted transparently through the core routing node.
5. The method according to claim 2, characterized in that, The identifier of the user group corresponding to the source user is carried in a first opaque tag, which is at least one opaque tag that is identified as carrying the identifier of the user group corresponding to the source user.
6. The method according to claim 2, characterized in that, When the source user's message includes data to be transmitted by the source user, determining whether to send the message to the destination user based on the isolation policy and the correspondence between users and user groups in the local area network includes: Based on the correspondence between the source user and the users and user groups in the local area network, the user group corresponding to the source user is determined, and based on the correspondence between the destination user and the users and user groups in the local area network, the user group corresponding to the destination user is determined. If the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are allowed to access each other, the message is sent to the destination user; or, if the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are not allowed to access each other, the message is not sent to the destination user.
7. The method according to any one of claims 2-5, characterized in that, When the source user's message includes the data to be transmitted by the source user and the identifier of the user group corresponding to the source user, determining whether to send the message to the destination user based on the isolation policy and the correspondence between users and user groups in the local area network includes: Based on the correspondence between the target user and the users and user groups in the local area network, the user group corresponding to the target user is determined; If the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are allowed to access each other, the message is sent to the destination user; or, if the isolation policy indicates that the user group corresponding to the source user and the user group corresponding to the destination user are not allowed to access each other, the message is not sent to the destination user.
8. The method according to any one of claims 1-7, characterized in that, The routing protocol information is used to indicate Border Gateway Protocol (BGP) routing information and / or Enhanced Border Gateway Protocol (EBGP) routing information.
9. An information transmission method, characterized in that, Applied to a controller, the method includes: Send routing protocol information to any routing node in the local area network. The routing protocol information is used to indicate the routing information synchronized by the routing nodes in the local area network. The routing protocol information is also used to indicate the isolation policy and the correspondence between users and user groups in the local area network. The isolation policy is used to specify the access permissions between different user groups.
10. A routing device, characterized in that, The routing device includes a processor; the processor is configured to run computer programs or instructions, or to cause the routing device to perform the method as described in any one of claims 1-9 via logic circuitry.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions or programs that, when executed on a computer, cause the routing device to perform the method as described in any one of claims 1-9.
12. A computer program product comprising instructions, characterized in that, When it is running on a routing device, it causes the routing device to implement the method as described in any one of claims 1-9.