Intention-driven network policy adaptive mapping system and method based on knowledge graph
Patent Information
- Application Number
- CN202610921758.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-25
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2046-06-25
AI Technical Summary
[0010]第一,意图理解能力有限;现有意图解析方法主要基于规则匹配和通用自然语言处理技术,缺乏网络领域的专业知识,导致语义鸿沟问题、上下文信息缺失以及对模糊意图的处理能力不足
[0028]本发明中,所提出的基于知识图谱的意图驱动网络策略自适应映射系统及方法,通过构建包含意图层、策略层、网络实体层和状态约束层的多层知识图谱,并采用混合意图解析与图谱推理技术,提升了从高层业务意图到具体网络策略的映射准确性;通过在图谱推理中显式引入实时资源状态与策略冲突关系进行动态剪枝,使策略生成能够自适应网络环境变化,避免了资源过载与策略冲突;同时,基于策略执行反馈闭环动态更新图谱边权与模板优先级,并将失败经验沉淀为约束条件,实现了映射关系的持续优化与自学习;此外,异构适配层支持跨平台统一下发,增强了系统的兼容性与可扩展性。
Smart Images

Figure CN122476034B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network management technology, and in particular to an intent-driven network policy adaptive mapping system and method based on knowledge graphs. Background Technology
[0002] Network policy management is a crucial component of network management, and its development has evolved from manual configuration to automated management. Early network policy management relied entirely on manual configuration by network administrators via command lines, a method that was inefficient and prone to errors. With the increase in the number of network devices and the increasing complexity of network topologies, the concept of policy-based network management was proposed, which automatically generates specific configurations by defining high-level policies. However, traditional policy-based network management systems still require administrators to define specific policy rules and cannot understand the high-level business intent of users.
[0003] In recent years, the rise of new network architectures such as software-defined networking (SDN) and network function virtualization (NFV) has propelled network policy management into a new stage of development. SDN, by separating the control plane and data plane, enables centralized control and programming capabilities, providing a better technological foundation for policy management. NFV, by software-ifying network functions and deploying them on general-purpose hardware, allows for more flexible orchestration and deployment of network policies. However, existing policy management systems based on SDN or NFV still face several technical challenges, including insufficient intent understanding capabilities, reliance on human experience for policy generation, and a lack of intelligent reasoning mechanisms.
[0004] Intent-driven networking is an emerging research direction in network management. Its core idea is to enable the network to understand users' business intentions and automatically implement corresponding network configurations. A typical intent-driven network system usually includes an intent acquisition module, an intent translation module, a policy generation module, a policy execution module, and a verification module. Current research on intent-driven network technology mainly focuses on the following aspects.
[0005] First, intent representation and modeling; researchers are dedicated to studying how to formally represent user intent, with specific methods including natural language-based intent representation, structured template-based intent representation, and domain-specific language-based intent representation. Existing research has proposed various intent models, such as ontology-based intent models, graph-based intent models, and logic-based intent models.
[0006] Second, intent understanding and parsing; this area studies how to extract key information from user-input intent descriptions, employing techniques including natural language processing, semantic analysis, and intent classification. Existing methods mainly include rule-based, machine learning-based, and deep learning-based approaches. However, these methods still have limitations when dealing with complex, ambiguous, and domain-specific intents, such as semantic gaps, lack of context, and difficulties in recognizing domain-specific terms.
[0007] Third, the mapping from intent to policy; this is the core challenge of intent-driven network systems, and the research direction is how to transform high-level intents into specific network policies. Existing methods mainly include rule-based mapping methods, case-based reasoning methods, and machine learning-based methods. However, these methods often lack flexibility and are difficult to adapt to dynamically changing network environments and diverse business needs. At the same time, policy generation relies excessively on human experience, resulting in high rule maintenance costs.
[0008] Knowledge graphs, as a structured semantic knowledge representation method, have been widely applied in network management in recent years. Knowledge graphs represent domain knowledge through triples consisting of entities, attributes, and relationships, supporting complex semantic queries and reasoning. In network management, knowledge graphs can be used to represent multi-dimensional knowledge such as network topology, network device information, network service information, and network policy information, providing a knowledge foundation for intelligent network management. Existing research has explored the applications of knowledge graphs in network fault diagnosis, network configuration management, and network resource optimization. For example, knowledge graph-based network fault diagnosis systems can quickly locate the root cause of faults through graph reasoning techniques; knowledge graph-based network configuration management systems can maintain dependencies between configuration items to avoid configuration conflicts. However, current research on the application of knowledge graphs in intent-to-policy mapping is relatively limited, lacking systematic solutions.
[0009] In summary, although existing technologies have made some progress in network policy management and intent-driven networks, the following major shortcomings still exist.
[0010] First, the ability to understand intent is limited. Existing intent parsing methods are mainly based on rule matching and general natural language processing techniques, lacking expertise in the network domain, which leads to semantic gap problems, missing contextual information, and insufficient ability to handle ambiguous intents.
[0011] Second, policy generation relies on human experience. Existing policy generation methods mainly rely on predefined rule templates and human experience, lacking automation and intelligence capabilities. This results in high rule maintenance costs, difficulty in adapting to changes in the network environment and new business needs, and insufficient innovation in policy generation.
[0012] Third, there is a lack of systematic knowledge management; existing systems lack systematic management of network knowledge, strategic knowledge, and intent knowledge, resulting in fragmented knowledge, delayed updates, and weak reasoning ability, making it difficult to discover new insights and relationships from existing knowledge.
[0013] Fourth, insufficient visualization; the existing system lacks a visual representation of the mapping relationship between intent, policy and network status, resulting in poor system interpretability, difficulty in problem diagnosis, and difficulty for network experts to effectively transfer experience and knowledge to novice administrators.
[0014] Fifth, weak dynamic adaptability; existing systems lack dynamic adaptability, the mapping relationship from intent to policy is usually static, making it difficult to adapt to changes in network state, and at the same time, they fail to effectively utilize feedback information from policy execution and lack the ability to learn and improve from historical experience. Summary of the Invention
[0015] To address the technical problems existing in the background art, this invention proposes an intent-driven network policy adaptive mapping system and method based on knowledge graphs.
[0016] The present invention proposes an intent-driven network policy adaptive mapping system based on knowledge graphs, comprising: The intent input interface layer is used to receive configuration intent text and network environment data, and send the configuration intent text to the intent parsing engine and the network environment data to the graph mapping engine. The intent parsing engine is used to parse the configuration intent text, generate a structured intent semantic graph, and output it to the graph mapping engine. The graph mapping engine has a first input end connected to the intent parsing engine to receive a structured intent semantic graph, and a second input end connected to the intent input interface layer to receive network environment data. This data is used to construct or update multi-layer knowledge graphs, and to perform mapping and reasoning in the multi-layer knowledge graphs based on the structured intent semantic graphs, outputting candidate policy paths to the policy generator. The policy generator connects to the graph mapping engine at its input end to receive candidate policy paths, which are used to generate executable network policies and verify them. The verified policies are then output to the policy distribution module. The policy distribution module has its input end connected to the policy generator to receive verified policies, and its output end is used to connect to the network infrastructure to distribute the verified policies to the network infrastructure. The feedback evaluation module connects to the network infrastructure at its input end to collect feedback data, and connects to the graph mapping engine at its output end to update the multi-layer knowledge graph based on the feedback data.
[0017] Preferably, the intent parsing engine includes a hybrid parsing engine, which comprises: a natural language processing module based on a domain-fine-tuned pre-trained model, a rule matching module based on predefined network domain rules, a machine learning inference module based on a conditional random field or deep learning model, and a result fusion and ambiguity resolution module; the natural language processing module, the rule matching module, and the machine learning inference module process the configured intent text in parallel, and their respective outputs are sent to the result fusion and ambiguity resolution module to generate a confidence-weighted intent semantic map as a structured intent semantic map.
[0018] Preferably, the multi-layer knowledge graph includes an intent layer, a policy layer, a network entity layer, and a state constraint layer; the nodes of the intent layer are standardized intent types and entities extracted from the intents, and the edges represent the combination or temporal relationship between intents; the nodes of the policy layer are access control list policy templates, quality of service policy templates, routing policy templates, and service chain policy templates, and the edges represent the dependency or mutual exclusion relationship between policies; the nodes of the network entity layer are physical devices, virtual devices, interfaces, network segments, services, and applications, and the edges represent the topology connection relationship, bearer relationship, and deployment relationship; the nodes of the state constraint layer are device ternary content addressing memory utilization, CPU utilization, interface bandwidth load, link latency, and existing policy conflict relationship, and the edges represent the relationship of constraints acting on the entity layer or the policy layer.
[0019] Preferably, the graph mapping engine includes a graph construction and update module, which is used to extract entities, attributes, and relationships from existing network configuration files, operation and maintenance logs, topology discovery results, policy library, and historical work orders. The extraction includes: matching device names, interface identifiers, and IP network segments in the configuration file using regular expressions; parsing event types and parameters in the operation and maintenance logs using log templates; extracting connection relationships between devices from the topology discovery results using graph traversal algorithms; extracting policy rules and dependencies from the policy library using policy template matching; and extracting intent descriptions and policy mapping cases from historical work orders using natural language processing.
[0020] Preferably, the graph construction and update module is further used to store the extracted entities, attributes and relationships in layers according to the intent layer, strategy layer, network entity layer and state constraint layer, and to establish cross-layer edges; the cross-layer edges include realizeable edges from intent nodes to strategy nodes, deployable edges from strategy nodes to network entity nodes, constraint edges from state constraint nodes to network entity nodes, and conflict edges from state constraint nodes to strategy nodes.
[0021] Preferably, the graph mapping engine includes a graph mapping inference module, which is used to: perform similarity calculation based on graph neural networks in a multi-layer knowledge graph according to the intent type, entity and constraint conditions in the structured intent semantic graph; perform random walks starting from the intent layer nodes; prioritize visiting paths with high edge weights during the walk; and record the complete path when the walk reaches the policy layer node. The upper limit of the number of steps of the random walk is a preset maximum mapping hop count.
[0022] Preferably, the graph mapping reasoning module is further configured to: calculate the path score for each recorded complete path, wherein the path score is the product of the weights of all edges on the path multiplied by the intent similarity; sort the paths from high to low according to their path scores, and select the top N paths as candidate strategy paths, where N is a preset positive integer.
[0023] Preferably, during the execution of a random walk, the graph mapping reasoning module explicitly queries the real-time resource status and policy conflict relationships in the state constraint layer. When the state constraint node associated with the policy node or network entity node traversed by the current walk indicates insufficient resources or a conflict, the current random walk path is terminated in advance, and the path is removed from the walk candidate set.
[0024] Preferably, the strategy generator includes: The strategy template retrieval module is used to retrieve the corresponding strategy template from the strategy library based on the strategy template node in the candidate strategy path. The parameter instantiation module is used to populate the constraints and target effect parameters in the structured intent semantic graph into the policy template to generate candidate executable policies; The strategy verification module is used to perform feasibility verification and conflict detection on candidate executable strategies. The feasibility verification includes checking whether the resource reserves of the target device meet the policy deployment requirements. The conflict detection includes checking whether there is rule overlap, action contradiction or resource preemption between the candidate executable strategy and the effective strategy. The strategy output module marks the verified candidate executable strategies as verified strategies and outputs them to the strategy distribution module. It also sends the unverified candidate executable strategies and their failure reasons back to the graph mapping engine to trigger the reselection of candidate strategy paths.
[0025] Preferably, the strategy distribution module specifically includes: The device type identification unit is used to query the device information database to obtain the device type and southbound interface capabilities of the target device based on the target device identifier in the verified policy. The policy format conversion unit is used to convert the verified policy into an intermediate representation format adapted to the target device, based on the device type of the target device. The adapter selection unit is used to select the corresponding protocol adapter according to the southbound interface capability of the target device. The protocol adapter includes at least one of the following: Representational State Transfer Application Programming Interface (API) adapter, Network Configuration Protocol (NIC) adapter, Simple Network Management Protocol (SMAP) adapter, and Secure Shell Command Line Adapter. The execution unit is used to call the selected protocol adapter to send the converted policy to the target device and receive the delivery status response; The distribution status recording unit is used to record the strategy, reason for failure, and timestamp of successful or failed distribution, and to feed back the distribution status to the feedback evaluation module.
[0026] Preferably, the network environment data includes network topology information, device identifiers, device resource status, link status information, and existing policy information; the device resource status includes ternary content-addressable memory utilization, CPU utilization, and memory utilization; the link status information includes interface bandwidth load, link latency, and link packet loss rate; and the existing policy information includes active access control list rules, quality of service policies, routing policies, and conflict relationships between policies.
[0027] The knowledge graph-based intent-driven network policy adaptive mapping method proposed in this invention includes: Obtain the configuration intent text and network environment data; Parse the configuration intent text and generate a structured intent semantic graph; Constructing or updating multi-layered knowledge graphs; Based on the structured intent semantic graph, mapping and reasoning are performed in a multi-layered knowledge graph to discover candidate strategy paths; An executable network policy is generated based on the candidate policy path and then verified to obtain the verified policy. The validated policy is then distributed to the network infrastructure. Collect feedback data and update the multi-layer knowledge graph based on the feedback data.
[0028] This invention proposes a knowledge graph-based intent-driven network policy adaptive mapping system and method. By constructing a multi-layered knowledge graph comprising an intent layer, a policy layer, a network entity layer, and a state constraint layer, and employing hybrid intent parsing and graph reasoning techniques, the accuracy of mapping from high-level business intents to specific network policies is improved. Through explicit introduction of real-time resource states and policy conflict relationships for dynamic pruning in graph reasoning, policy generation can adapt to changes in the network environment, avoiding resource overload and policy conflicts. Simultaneously, based on a policy execution feedback loop, the graph edge weights and template priorities are dynamically updated, and failure experiences are precipitated as constraints, achieving continuous optimization and self-learning of mapping relationships. Furthermore, the heterogeneous adaptation layer supports unified cross-platform deployment, enhancing the system's compatibility and scalability. Attached Figure Description
[0029] Figure 1 This is a schematic diagram of the system architecture of the knowledge graph-based intent-driven network policy adaptive mapping system proposed in this invention. Figure 2 This is a flowchart illustrating the workflow of the knowledge graph-based intent-driven network policy adaptive mapping method proposed in this invention. Detailed Implementation
[0030] Reference Figure 1 The present invention proposes an intent-driven network policy adaptive mapping system based on knowledge graphs, comprising: The intent input interface layer is used to receive configuration intent text and network environment data, and send the configuration intent text to the intent parsing engine and the network environment data to the graph mapping engine.
[0031] In this embodiment, network environment data includes network topology information, device identifier, device resource status, link status information, and existing policy information; device resource status includes ternary content-addressable memory utilization, CPU utilization, and memory utilization; link status information includes interface bandwidth load, link latency, and link packet loss rate; existing policy information includes active access control list rules, quality of service policies, routing policies, and conflict relationships between policies.
[0032] The intent input interface layer supports multiple input methods, including web interfaces, REST APIs, command-line interfaces, and mobile applications, to accommodate different user habits and integration needs. The system should perform completeness and semantic rationality checks on intent representations and perform unified internal representation conversion for intents in different formats.
[0033] The intent parsing engine is used to parse the configuration intent text, generate a structured intent semantic graph, and output it to the graph mapping engine.
[0034] In this embodiment, the intent parsing engine includes a hybrid parsing engine, which comprises: a natural language processing module based on a domain-fine-tuned pre-trained model, a rule matching module based on predefined network domain rules, a machine learning inference module based on a conditional random field or deep learning model, and a result fusion and ambiguity resolution module. The natural language processing module, rule matching module, and machine learning inference module process the configuration intent text in parallel, and their respective outputs are sent to the result fusion and ambiguity resolution module to generate a confidence-weighted intent semantic map as a structured intent semantic map.
[0035] It should be noted that after obtaining the three output results through parallel parsing, the system performs terminology normalization processing. For example, it maps the financial terminals identified by the natural language processing module to their corresponding IP network segments, the ERP server to its IP address, and the visitor wireless network to the virtual LAN identifier VLAN 200, ensuring that the entity names are consistent with the standard nodes in the network entity layer. Subsequently, the rule base in the rule matching module corrects and verifies the legality of the three outputs: for example, when the time window is detected to be from 8:00 to 18:00 on weekdays, it automatically excludes statutory holidays and verifies whether the low latency target matches the service quality capabilities of the current network equipment, marking or adjusting outputs that do not conform to physical constraints. Finally, the result fusion and ambiguity resolution module uses a voting mechanism based on network context to handle conflicting results with the same confidence level: when the natural language processing and machine learning modules give different intent classifications, the output of the rule matching module is used as a reference benchmark, and weighted voting is performed in combination with the current network time and load context; if it is still impossible to determine, an interactive confirmation is initiated with the administrator through the intent input interface layer to ensure the uniqueness and accuracy of the structured intent semantic graph.
[0036] The graph mapping engine has a first input end connected to the intent parsing engine to receive a structured intent semantic graph, and a second input end connected to the intent input interface layer to receive network environment data. This data is used to construct or update multi-layer knowledge graphs, and to perform mapping and reasoning in the multi-layer knowledge graphs based on the structured intent semantic graphs, outputting candidate policy paths to the policy generator.
[0037] In this embodiment, the multi-layer knowledge graph includes an intent layer, a policy layer, a network entity layer, and a state constraint layer. The nodes of the intent layer are standardized intent types and entities extracted from the intents, with edges representing combinations or temporal relationships between intents. The nodes of the policy layer are access control list policy templates, quality of service policy templates, routing policy templates, and service chain policy templates, with edges representing dependencies or mutual exclusions between policies. The nodes of the network entity layer are physical devices, virtual devices, interfaces, network segments, services, and applications, with edges representing topology connections, bearer relationships, and deployment relationships. The nodes of the state constraint layer are device ternary content addressing memory utilization, CPU utilization, interface bandwidth load, link latency, and existing policy conflict relationships, with edges representing the relationship of constraints acting on the entity layer or the policy layer.
[0038] In this embodiment, the graph mapping engine includes a graph construction and update module. The graph construction and update module is used to extract entities, attributes, and relationships from the existing network configuration files, operation and maintenance logs, topology discovery results, policy library, and historical work orders. The extraction includes: matching device names, interface identifiers, and IP network segments in the configuration files using regular expressions; parsing event types and parameters in the operation and maintenance logs using log templates; extracting connection relationships between devices from the topology discovery results using graph traversal algorithms; extracting policy rules and dependencies from the policy library using policy template matching; and extracting intent descriptions and policy mapping cases from historical work orders using natural language processing.
[0039] In this embodiment, the graph construction and update module is also used to store the extracted entities, attributes and relationships in layers according to the intent layer, strategy layer, network entity layer and state constraint layer, and to establish cross-layer edges; the cross-layer edges include the implementable edge from the intent node to the strategy node, the deployable edge from the strategy node to the network entity node, the constraint edge from the state constraint node to the network entity node, and the conflict edge from the state constraint node to the strategy node.
[0040] Specifically, the graph construction and update module extracts entities, attributes, and relationships from existing network configuration files, operation and maintenance logs, topology discovery results, policy libraries, and historical work orders. This is achieved through various methods, including matching device names, interface identifiers, and IP network segments in configuration files using regular expressions; parsing event types and parameters in operation and maintenance logs using log templates; extracting device connections from topology discovery results using graph traversal algorithms; extracting policy rules and dependencies from the policy library using policy template matching; and extracting intent descriptions and policy mapping cases from historical work orders using natural language processing. The extracted content is stored hierarchically according to intent layer, policy layer, network entity layer, and state constraint layer. Furthermore, it establishes implementable edges from intent nodes to policy nodes, deployable edges from policy nodes to network entity nodes, constraint edges from state constraint nodes to network entity nodes, and conflict edges from state constraint nodes to policy nodes.
[0041] In this embodiment, the graph mapping engine includes a graph mapping inference module, which is used to: perform similarity calculation based on graph neural network in a multi-layer knowledge graph according to the intent type, entity and constraint conditions in the structured intent semantic graph; perform random walk starting from the intent layer node; prioritize visiting the path with higher edge weight during the walk; record the complete path when the walk reaches the policy layer node; and set the upper limit of the number of steps of the random walk to the preset maximum mapping hops.
[0042] In this embodiment, the graph mapping reasoning module is also used to: calculate the path score for each recorded complete path, the path score being the product of the weights of all edges on the path multiplied by the intent similarity; sort the paths from high to low according to their path scores, and select the top N paths as candidate strategy paths, where N is a preset positive integer.
[0043] In this embodiment, during the execution of a random walk, the graph mapping reasoning module explicitly queries the real-time resource status and policy conflict relationships in the state constraint layer. When the state constraint node associated with the policy node or network entity node traversed by the current walk indicates insufficient resources or a conflict, the current random walk path is terminated in advance, and the path is removed from the walk candidate set.
[0044] Specifically, the graph mapping reasoning module performs intent similarity search in a multi-layered knowledge graph based on intent types, entities, and constraints in the structured intent semantic graph to find similar intents and their processing methods in the past. At the same time, it performs context-aware queries in combination with the current network state and environmental context, and explores possible mapping paths from intent nodes to policy nodes through multi-hop relationships. During the reasoning process, the real-time resource state and policy conflict relationship in the state constraint layer are explicitly introduced to prune and sort the original mapping paths, and select feasible candidate policy paths that meet the current network resource constraints and are conflict-free.
[0045] The policy generator connects to the graph mapping engine at its input end to receive candidate policy paths, which are used to generate executable network policies and verify them. The verified policies are then output to the policy distribution module.
[0046] In this embodiment, the policy generator includes: The strategy template retrieval module is used to retrieve the corresponding strategy template from the strategy library based on the strategy template node in the candidate strategy path. The parameter instantiation module is used to populate the constraints and target effect parameters in the structured intent semantic graph into the policy template to generate candidate executable policies; The strategy verification module is used to perform feasibility verification and conflict detection on candidate executable strategies. Feasibility verification includes checking whether the resource reserves of the target device meet the policy deployment requirements. Conflict detection includes checking whether there are rule overlaps, action contradictions or resource preemption between candidate executable strategies and effective strategies. The strategy output module marks the verified candidate executable strategies as verified strategies and outputs them to the strategy distribution module. It also sends the unverified candidate executable strategies and their failure reasons back to the graph mapping engine to trigger the reselection of candidate strategy paths.
[0047] The policy distribution module has its input end connected to the policy generator to receive verified policies, and its output end connected to the network infrastructure to distribute the verified policies to the network infrastructure.
[0048] Specifically, the policy generator generates specific executable network policies based on candidate policy paths, including access control policies, quality of service policies, routing or path policies, service chain policies, isolation policies, and address translation policies. After policy generation, policy verification is performed to detect rule coverage conflicts, action conflicts, resource preemption conflicts, and timing conflicts. Conflicts are resolved by combining priority relationships, dependency relationships, and historical feedback. At the same time, the feasibility, consistency, and security of the policy are verified. If the verification passes, it is output to the distribution module; if it fails, an alternative path is selected or the scope of policy application is narrowed.
[0049] In this embodiment, the policy distribution module specifically includes: The device type identification unit is used to query the device information database to obtain the device type and southbound interface capabilities of the target device based on the target device identifier in the verified policy. The policy format conversion unit is used to convert the verified policy into an intermediate representation format adapted to the target device, based on the device type of the target device. The adapter selection unit is used to select the corresponding protocol adapter based on the southbound interface capability of the target device. The protocol adapter includes at least one of the following: Representational State Transfer Application Programming Interface (API) adapter, Network Configuration Protocol (NIC) adapter, Simple Network Management Protocol (SMAP) adapter, and Secure Shell Command Line (SLL) adapter. The execution unit is used to call the selected protocol adapter to send the converted policy to the target device and receive the delivery status response; The distribution status recording unit is used to record the strategy, reason for failure, and timestamp of successful or failed distribution, and to feed back the distribution status to the feedback evaluation module.
[0050] Specifically, the policy distribution module selects the adaptation method according to the type of the target device: for devices that support the southbound interface of the software-defined network controller, structured configuration is distributed through the expressive state transfer application interface or network configuration protocol; for traditional network devices, the policy is converted into a command-line interface command sequence through the command template engine, and can be written to the simple network management protocol or executed by the secure shell batch script; during the distribution process, the execution status is monitored in real time and the result of successful or failed distribution is recorded.
[0051] The feedback evaluation module connects to the network infrastructure at its input end to collect feedback data, and connects to the graph mapping engine at its output end to update the multi-layer knowledge graph based on the feedback data.
[0052] Specifically, the feedback evaluation module collects data from multiple sources, including network monitoring systems, log systems, and user feedback, after the strategy is executed. This data includes strategy delivery success rate, end-to-end latency, packet loss rate, access blocking effect, queue occupancy rate, number of rollbacks, and number of manual interventions. It evaluates whether the intent has been achieved by calculating key performance indicators and conducts root cause analysis on strategies that fail or have poor results. The feedback information is classified into types such as success, partial success, and failure. Based on the evaluation results, the mapping weights from intent to strategy are adjusted, successful mapping experiences are added to the graph as new knowledge, erroneous or outdated mapping relationships are corrected, and the reasons for failure are precipitated as constraints for subsequent reasoning.
[0053] This application solves the problems of inaccurate intent understanding, policy generation relying on static experience, inability to adapt to dynamic networks, and opaque mapping process in the prior art, and achieves accurate, interpretable, adaptive, efficient and stable network policy mapping effect.
[0054] Example 1:
[0055] This embodiment uses an enterprise campus network as an application scenario; the network includes a core switch, aggregation switch, firewall, wireless controller, ERP server, financial database server, financial terminal, and guest wireless network.
[0056] The operations and maintenance personnel entered the following configuration intent: "To ensure low latency for financial terminals accessing ERP services from 8:00 AM to 6:00 PM on weekdays, while prohibiting guest wireless network access to the financial database server." After receiving this intent, the system can execute it according to the following process: The system's intent input interface layer provides a web graphical interface through which administrators input the aforementioned configuration intent text. Simultaneously, the intent input interface layer obtains current network environment data from the network monitoring system, including network topology information, device identifiers, device resource status, link status information, and existing policy information. Device resource status includes ternary content-addressable memory utilization and CPU utilization; link status information includes interface bandwidth load and link latency; and existing policy information includes active access control list rules, quality of service policies, routing policies, and conflict relationships between these policies.
[0057] The intent input interface layer sends the received configuration intent text to the intent parsing engine, and the intent input interface layer sends the network environment data to the graph mapping engine.
[0058] In the intent parsing engine, the natural language processing module performs semantic understanding on the configuration intent text, identifying action words such as "guarantee," "low latency," and "deny access," as well as time window information; the rule matching module applies a predefined network domain rule base to match time constraint templates from 8:00 to 18:00 on weekdays and service quality target templates with latency below 50 milliseconds; the machine learning inference module extracts entities based on a conditional random field model, obtaining the first set of entities as the source object financial terminal, the destination object ERP server, and the business type HTTP; the second set of entities as the source object visitor wireless network, the destination object financial database server, and the action denial.
[0059] The three modules described above process the configuration intent text in parallel, and their respective outputs are simultaneously fed into the result fusion and ambiguity resolution module. This module integrates the three results according to a confidence-weighted strategy, generating two structured intent semantic graphs. The first structured intent semantic graph represents the service quality assurance intent, with the intent type being service quality assurance. It includes the source entity (financial terminal), the destination entity (ERP server), and the constraints of latency less than 50 milliseconds and a time window of 8:00 AM to 6:00 PM on weekdays. The second structured intent semantic graph represents the access control intent, with the intent type being access control. It includes the source entity (Virtual LAN identifier of the visitor's wireless network), the destination entity (financial database server), and the action being denial.
[0060] The system then constructs or updates a multi-layered knowledge graph. The graph construction and update module extracts entity relationships from configuration files, logs, topology, policy library, and historical work orders, and stores them in layers according to intent layer, policy layer, network entity layer, and state constraint layer. The intent layer stores intent types and entities; the policy layer stores ACL and QoS policy templates; the network entity layer stores devices, interfaces, network segments, etc.; and the state constraint layer stores real-time TCAM utilization, link load, and existing policy conflicts. At the same time, it establishes cross-layer edges: implementable edges, deployable edges, constraint edges, and conflict edges.
[0061] For QoS intents, the graph mapping inference module performs a random walk, starting from the intent node and prioritizing paths with higher edge weights, traversing to the "guaranteed low latency" template node in the policy layer. During the walk, the state constraint layer is queried, and constraint nodes with excessively high bandwidth loads on intermediate links are found. Therefore, this branch is terminated early and the path is eliminated. The final feasible candidate path is: traffic marking on the access switch and queue scheduling on the core switch.
[0062] For access control intent, the module discovers state constraints with high utilization of the firewall TCAM, and therefore prioritizes the denial policy path that can be deployed on the aggregation switch rather than the firewall path. After calculating the score of each path, the module outputs candidate policy paths.
[0063] The policy generator retrieves the corresponding policy template, fills in the parameters from the intent into the template, and generates candidate executable policies. Feasibility verification and conflict detection are then performed: checking the queue resources of access switches and core switches, and the sufficiency of TCAM entries on aggregation switches; checking for overlaps or contradictions between the new ACL rules and existing rules; after all checks pass, the policy is marked as verified.
[0064] The policy delivery module identifies the target device type as a traditional switch and supports SSH command line. It converts the policy into an intermediate representation format, selects the SSH adapter, generates a specific CLI command sequence and delivers it to the device. The delivery status is recorded as success or failure and timestamp, and then fed back to the feedback evaluation module.
[0065] After the policy is executed, the feedback evaluation module collects operational metrics: the average end-to-end latency of the QoS policy is 48ms, lower than the 50ms target; the ACL log shows that multiple visitor accesses were successfully blocked, and the intent achievement calculation unit determines that both intents have been achieved. The update instruction generation unit positively increases the edge weight of the used mapping path and increases the priority of the corresponding policy template.
[0066] If a strategy fails to be deployed due to insufficient TCAM resources, the system will negatively reduce the edge weight of that path and write "this strategy should not be deployed when TCAM utilization is too high" as a new constraint into the state constraint layer. Subsequent similar intentions will automatically avoid this path.
[0067] Through the closed-loop process described above, this embodiment demonstrates the complete mapping process from high-level intent to specific device commands, verifying the effectiveness of the system in intent parsing, resource-aware reasoning, policy verification, heterogeneous delivery, and feedback self-optimization.
[0068] Reference Figure 2 The present invention proposes an intention-driven network policy adaptive mapping method based on knowledge graphs, comprising: Obtain the configuration intent text and network environment data; Parse the configuration intent text and generate a structured intent semantic graph; Constructing or updating multi-layered knowledge graphs; Based on the structured intent semantic graph, mapping and reasoning are performed in a multi-layered knowledge graph to discover candidate strategy paths; An executable network policy is generated based on the candidate policy path and then verified to obtain the verified policy. The validated policy is then distributed to the network infrastructure. Collect feedback data and update the multi-layered knowledge graph based on the feedback data.
[0069] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A knowledge graph-based intent-driven network policy adaptive mapping system, characterized in that, include: The intent input interface layer is used to receive configuration intent text and network environment data, and send the configuration intent text to the intent parsing engine and the network environment data to the graph mapping engine. The intent parsing engine is used to parse the configuration intent text, generate a structured intent semantic graph, and output it to the graph mapping engine. The graph mapping engine has a first input end connected to the intent parsing engine to receive a structured intent semantic graph, and a second input end connected to the intent input interface layer to receive network environment data. This data is used to construct or update multi-layer knowledge graphs, and to perform mapping and reasoning in the multi-layer knowledge graphs based on the structured intent semantic graphs, outputting candidate policy paths to the policy generator. The policy generator connects to the graph mapping engine at its input end to receive candidate policy paths, which are used to generate executable network policies and verify them. The verified policies are then output to the policy distribution module. The policy distribution module has its input end connected to the policy generator to receive verified policies, and its output end is used to connect to the network infrastructure to distribute the verified policies to the network infrastructure. The feedback evaluation module connects to the network infrastructure at its input end to collect feedback data, and connects to the graph mapping engine at its output end to update the multi-layer knowledge graph based on the feedback data.
2. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 1, characterized in that, The intent parsing engine includes a hybrid parsing engine, which comprises: a natural language processing module based on a domain-fine-tuned pre-trained model, a rule matching module based on predefined network domain rules, a machine learning inference module based on a conditional random field or deep learning model, and a result fusion and ambiguity resolution module. The natural language processing module, rule matching module, and machine learning inference module process the configured intent text in parallel, and their respective outputs are sent to the result fusion and ambiguity resolution module to generate a confidence-weighted intent semantic map as a structured intent semantic map.
3. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 1, characterized in that, The multi-layered knowledge graph comprises an intent layer, a policy layer, a network entity layer, and a state constraint layer. Nodes in the intent layer are standardized intent types and entities extracted from those intents, with edges representing combinations or temporal relationships between intents. Nodes in the policy layer are access control list policy templates, quality of service policy templates, routing policy templates, and service chain policy templates, with edges representing dependencies or mutual exclusions between policies. Nodes in the network entity layer are physical devices, virtual devices, interfaces, network segments, services, and applications, with edges representing topology connections, bearer relationships, and deployment relationships. Nodes in the state constraint layer are device ternary content addressing memory utilization, CPU utilization, interface bandwidth load, link latency, and existing policy conflict relationships, with edges representing the relationship of constraints acting on the entity layer or the policy layer.
4. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 1, characterized in that, The graph mapping engine includes a graph construction and update module, which is used to extract entities, attributes, and relationships from live network configuration files, operation and maintenance logs, topology discovery results, policy library, and historical work orders. The extraction includes: matching device names, interface identifiers, and IP network segments in the configuration file using regular expressions; parsing event types and parameters in the operation and maintenance logs using log templates; extracting connection relationships between devices from the topology discovery results using graph traversal algorithms; extracting policy rules and dependencies from the policy library using policy template matching; and extracting intent descriptions and policy mapping cases from historical work orders using natural language processing.
5. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 4, characterized in that, The graph construction and update module is also used to store the extracted entities, attributes and relationships in layers according to the intent layer, strategy layer, network entity layer and state constraint layer, and to establish cross-layer edges; the cross-layer edges include the implementable edge from the intent node to the strategy node, the deployable edge from the strategy node to the network entity node, the constraint edge from the state constraint node to the network entity node, and the conflict edge from the state constraint node to the strategy node.
6. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 3, characterized in that, The graph mapping engine includes a graph mapping inference module, which is used to: perform similarity calculation based on graph neural networks in a multi-layer knowledge graph according to the intent type, entity and constraint conditions in the structured intent semantic graph; perform random walks starting from the intent layer nodes; prioritize visiting paths with high edge weights during the walk; and record the complete path when the walk reaches the policy layer node. The upper limit of the number of steps of the random walk is the preset maximum number of mapping hops.
7. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 6, characterized in that, The graph mapping reasoning module is also used to: calculate the path score for each recorded complete path, wherein the path score is the product of the weights of all edges on the path multiplied by the intent similarity; sort the paths from high to low according to their path scores, and select the top N paths as candidate strategy paths, where N is a preset positive integer.
8. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 6, characterized in that, During the execution of a random walk, the graph mapping reasoning module explicitly queries the real-time resource status and policy conflict relationships in the state constraint layer. When the state constraint node associated with the policy node or network entity node traversed by the current walk indicates insufficient resources or a conflict, the current random walk path is terminated in advance, and the path is removed from the walk candidate set.
9. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 1, characterized in that, The strategy generator includes: The strategy template retrieval module is used to retrieve the corresponding strategy template from the strategy library based on the strategy template node in the candidate strategy path. The parameter instantiation module is used to populate the constraints and target effect parameters in the structured intent semantic graph into the policy template to generate candidate executable policies; The strategy verification module is used to perform feasibility verification and conflict detection on candidate executable strategies. The feasibility verification includes checking whether the resource reserves of the target device meet the policy deployment requirements. The conflict detection includes checking whether there is rule overlap, action contradiction or resource preemption between the candidate executable strategy and the effective strategy. The strategy output module marks the verified candidate executable strategies as verified strategies and outputs them to the strategy distribution module. It also sends the unverified candidate executable strategies and their failure reasons back to the graph mapping engine to trigger the reselection of candidate strategy paths.
10. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 1, characterized in that, The strategy distribution module specifically includes: The device type identification unit is used to query the device information database to obtain the device type and southbound interface capabilities of the target device based on the target device identifier in the verified policy. The policy format conversion unit is used to convert the verified policy into an intermediate representation format adapted to the target device, based on the device type of the target device. The adapter selection unit is used to select the corresponding protocol adapter according to the southbound interface capability of the target device. The protocol adapter includes at least one of the following: Representational State Transfer Application Programming Interface (API) adapter, Network Configuration Protocol (NIC) adapter, Simple Network Management Protocol (SMAP) adapter, and Secure Shell Command Line Adapter. The execution unit is used to call the selected protocol adapter to send the converted policy to the target device and receive the delivery status response; The distribution status recording unit is used to record the strategy, reason for failure, and timestamp of successful or failed distribution, and to feed back the distribution status to the feedback evaluation module.
11. The knowledge graph-based intent-driven network policy adaptive mapping system according to claim 1, characterized in that, The network environment data includes network topology information, device identifiers, device resource status, link status information, and existing policy information; the device resource status includes ternary content-addressable memory utilization, CPU utilization, and memory utilization; the link status information includes interface bandwidth load, link latency, and link packet loss rate; the existing policy information includes active access control list rules, quality of service policies, routing policies, and conflict relationships between policies.
12. A knowledge graph-based intent-driven network policy adaptive mapping method, characterized in that, include: Obtain the configuration intent text and network environment data; Parse the configuration intent text and generate a structured intent semantic graph; Constructing or updating multi-layered knowledge graphs; Based on the structured intent semantic graph, mapping and reasoning are performed in a multi-layered knowledge graph to discover candidate strategy paths; An executable network policy is generated based on the candidate policy path and then verified to obtain the verified policy. The validated policy is then distributed to the network infrastructure. Collect feedback data and update the multi-layer knowledge graph based on the feedback data.
Citation Information
Patent Citations
Large model and knowledge graph enabled intention-driven network design method
CN118228815A
Information technology auxiliary consultation system based on artificial intelligence
CN121350586A