Device control method, device control apparatus, device, and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2026-08-11
AI Technical Summary
[0003]然而,由于网络设备的数量通常是海量级别的,上述控制方式导致控制器的压力较大,且控制器直接下发指令到设备的方式因网络复杂性,导致网络设备执行效率较低
Smart Images

Figure CN122554449A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and more specifically, to a device control method, a content recommendation device, an electronic device, a computer-readable storage medium, and a computer product. Background Technology
[0002] In the era of cloud computing, as business scale continues to expand, network systems are becoming increasingly complex. To address this challenge, cloud service providers have generally adopted a network management strategy that separates control and control; this strategy involves deploying controllers in the cloud to centrally manage a massive number of network devices and issue commands to these devices, thereby achieving effective control over the entire network system.
[0003] However, since the number of network devices is usually massive, the above control methods put a lot of pressure on the controller, and the method of the controller directly issuing instructions to the devices results in low execution efficiency of the network devices due to the complexity of the network. Summary of the Invention
[0004] Embodiments of this application provide a device control method, device control apparatus, electronic device, computer-readable storage medium, and computer program product, which can effectively reduce the pressure on the global controller and improve device execution efficiency.
[0005] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part from practice of this application.
[0006] According to one aspect of the embodiments of this application, a device control method is provided, applied to a cloud network system, the cloud network system including a global controller, a regional controller, and at least one network device managed within a region to which the regional controller belongs. The method is applied to the regional controller and includes: obtaining a global instruction sent by the global controller, the global instruction carrying a network policy generated based on global network orchestration; determining a target network device from among the currently managed network devices according to the global instruction, and converting the network policy into a device instruction executable by the target network device; and sending the device instruction to the target network device for execution.
[0007] According to one aspect of the embodiments of this application, a device control apparatus is provided, applied to a cloud network system, the cloud network system including a global controller, a regional controller, and at least one network device managed within a region to which the regional controller belongs, the apparatus being deployed on the regional controller, comprising: an acquisition module, configured to acquire a global instruction sent by the global controller, the global instruction carrying a network policy generated based on global network orchestration; a conversion module, configured to determine a target network device from the currently managed network devices according to the global instruction, and convert the network policy into a device instruction executable by the target network device; and an instruction sending module, configured to send the device instruction to the target network device for execution.
[0008] According to one aspect of the embodiments of this application, a device control method is also provided, applied to a cloud network system. The cloud network system includes a global controller, a regional controller, and at least one network device managed within the region to which the regional controller belongs. The method is applied to the global controller and includes: performing global network orchestration based on global network conditions and service requirements to obtain an orchestration scheme, and generating a network policy based on the orchestration scheme; determining a corresponding target regional controller based on the network policy; sending a global instruction carrying the network policy to the target regional controller, so that the target regional controller determines the target network device from the various network devices currently managed, and after converting the network policy into a device instruction executable by the target network device, sends the device instruction to the target network device for execution.
[0009] According to one aspect of the embodiments of this application, a device control apparatus is also provided, applied to a cloud network system. The cloud network system includes a global controller, a regional controller, and at least one network device managed within the region to which the regional controller belongs. The apparatus is deployed on the global controller and includes: a generation module, configured to perform global network orchestration based on global network conditions and service requirements to obtain an orchestration scheme, and generate a network policy based on the orchestration scheme; a determination module, configured to determine a corresponding target regional controller based on the network policy; and a policy sending module, configured to send a global instruction carrying the network policy to the target regional controller, so that the target regional controller determines the target network device from the various network devices currently managed, converts the network policy into a device instruction executable by the target network device, and sends the device instruction to the target network device for execution.
[0010] According to one aspect of the embodiments of this application, an electronic device is provided, including one or more processors; and a storage device for storing one or more computer programs, which, when executed by the one or more processors, cause the electronic device to implement the device control method as described above.
[0011] According to one aspect of the embodiments of this application, an embodiment of this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor of an electronic device, causes the electronic device to perform the device control method as described above.
[0012] According to one aspect of the embodiments of this application, an embodiment of this application provides a computer program product, including a computer program stored in a computer-readable storage medium, wherein a processor of an electronic device reads from the computer-readable storage medium and executes the computer program, causing the electronic device to perform the device control method described above.
[0013] In the technical solution provided by the embodiments of this application, a regional controller is introduced into the cloud network system to manage network devices in its assigned region. This effectively reduces the pressure on the global controller. The regional controller receives global instructions sent by the global controller, which carry network policies generated based on global network orchestration. Based on the global instructions, the regional controller determines the target network device from among the currently managed network devices and converts the network policy into device instructions executable by the target network device. In other words, the global controller ensures that the global policy can dynamically adapt to the real-time status of devices within the region based on global network orchestration, thereby optimizing the overall network performance. The regional controller decomposes the complex network policy of the global controller into specific device instructions, reducing the understanding threshold for devices and ensuring that the policy can be accurately implemented. The device instructions are then sent to the target network device for direct execution without further understanding by the device, enabling the device to execute in the most efficient way, improving device execution efficiency and reducing resource waste.
[0014] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0015] Figure 1 This is a schematic diagram of one implementation environment involved in this application;
[0016] Figure 2 This is a schematic diagram of another implementation environment involved in this application;
[0017] Figure 3 This is a schematic diagram illustrating a device control method in an exemplary embodiment of this application;
[0018] Figure 4 This is a schematic diagram of the architecture of a cloud network system shown in an exemplary embodiment of this application;
[0019] Figure 5 This is a flowchart illustrating another device control method as shown in an exemplary embodiment of this application;
[0020] Figure 6 This is a schematic diagram illustrating another device control method in an exemplary embodiment of this application;
[0021] Figure 7 This is a flowchart illustrating a device control method in another exemplary embodiment of this application;
[0022] Figure 8 This is a schematic diagram illustrating a device control method based on device-level network policies, as shown in an exemplary embodiment of this application.
[0023] Figure 9 This is a schematic diagram illustrating a device control method based on a regional network policy, as shown in an exemplary embodiment of this application.
[0024] Figure 10 This is a schematic diagram illustrating the overall scheme of the equipment reduction strategy in an exemplary embodiment of this application;
[0025] Figure 11 This is a structural block diagram illustrating an exemplary embodiment of the present application of a device control apparatus;
[0026] Figure 12 This is a structural block diagram of another device control apparatus shown in an exemplary embodiment of this application;
[0027] Figure 13 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation
[0028] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0029] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0030] The flowcharts shown in the accompanying diagrams are merely illustrative and do not necessarily include all content and operations, nor do they necessarily have to be executed in the described order. For example, some operations may be broken down, while others may be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.
[0031] It should also be noted that "multiple" as mentioned in this application refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0032] The technical solutions of the embodiments of this application will be described in detail below.
[0033] In a control-forwarding separation architecture, the control plane and the forwarding plane are separated, making the network control logic more centralized and intelligent. By deploying controllers in the cloud, remote management and control of network devices in IDC data centers across various locations can be achieved. These controllers not only undertake basic network management functions but also possess advanced functions such as traffic engineering, fault recovery, and policy enforcement.
[0034] Please see Figure 1 , Figure 1 This is a schematic diagram of an implementation environment involved in this application. The implementation environment includes a cloud network system, which includes a control system. The control system adopts a two-level architecture design to ensure efficient network operation and flexible management, including a global controller 10 and a local controller 20. The cloud network system also includes at least one network device 30 managed by the local controller within its respective area.
[0035] Among them, the global controller 10 is deployed in the cloud and serves as the centralized management core of the entire network. It has a global perspective and is responsible for unified control across the entire network.
[0036] The area controller 20 is deployed in a distributed manner close to the network devices to control the network devices within its area. The area controller plays a crucial role in the cloud network system, including translating device commands.
[0037] In one example, the global controller 10 performs global network orchestration based on the global network conditions and service requirements to obtain an orchestration scheme, and generates network policies based on the orchestration scheme; determines the corresponding target area controller based on the network policies; and sends global instructions carrying the network policies to the target area controller.
[0038] The local controller 20 receives global instructions from the global controller, which carry network policies generated based on the global network orchestration. Based on these global instructions, it identifies the target network device from among the currently managed network devices and converts the network policy into executable device instructions for the target network device. These device instructions are then sent to the target network device for execution. Because the local controller is physically closer to the device, lower latency and faster response times are achieved.
[0039] In another example, the area controller 20 also has the ability to dynamically adjust and optimize the network.
[0040] As described above, the Local Controller targets regional devices, focusing on the translation and management of device commands. However, it encounters performance limitations when handling large and complex regions. Therefore, this application embodiment introduces a regional-level sub-controller based on a two-level architecture design; please refer to... Figure 2 , Figure 2 This is a schematic diagram of another implementation environment involved in this application.
[0041] The regional sub-controller 40 acts as an intermediate layer between the global controller and the regional controller, focusing on network management and optimization within a specific region. This specific region includes large and complex areas, such as areas where the number of network devices exceeds a device threshold.
[0042] In one example, the global controller distributes policies to regional sub-controllers. The sub-controllers execute refined policy planning and send the policies to the regional controllers corresponding to specific regions. The regional controllers then receive the instructions from the regional sub-controllers and convert them into specific control instructions that can be executed by the devices.
[0043] Understandably, the number of global controllers, regional sub-controllers, regional controllers, and network devices included in a control system can be flexibly adjusted according to actual needs.
[0044] The aforementioned network devices can be electronic devices such as smartphones, tablets, laptops, computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, and aircraft. Network devices can also be servers; global controllers and regional controllers can also be servers. Servers can be independent physical servers, server clusters composed of multiple physical servers, or distributed systems. They can also be cloud servers providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. This section does not impose any restrictions on these aspects.
[0045] It should be noted that in the specific implementation of this application, if the network policy is related to an object, when the embodiments of this application are applied to specific products or technologies, permission or consent from the object is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0046] The following describes in detail the various implementation details of the technical solutions in the embodiments of this application.
[0047] like Figure 3 As shown, Figure 3 This is a flowchart illustrating a device control method according to an embodiment of this application, which can be applied to... Figure 1 In the implementation environment shown, this method can be executed by a regional controller. The device control method may include S310 to S330, which are described in detail below.
[0048] S310. Obtain the global command sent by the global controller. The global command carries the network policy generated based on the global network orchestration.
[0049] In this embodiment, the global control has a global perspective, enabling it to observe the operational status of the entire network and perform global network orchestration according to business needs. This orchestration capability allows network resources to be configured and utilized in the most optimized way, and then generates network policies based on the global network orchestration. These network policies include, but are not limited to, access control lists (ACLs), quality of service (QoS) settings, and security policies.
[0050] The regional controller receives global instructions sent by the global controller, or receives global instructions sent by the global controller forwarded by the regional sub-controller. These global instructions carry network policies. Global instructions are high-level instructions, and network policies are represented by high-level instructions or rules. The global instruction may carry one or more network policies; this is not limited here.
[0051] S320. Based on the global instructions, determine the target network device from the currently managed network devices and convert the network policy into device instructions that can be executed by the target network device.
[0052] It should be noted that there are two types of network policies: one is a policy issued to a specific network device, which is called a device-level network policy; the other is a network policy for a region, which is called a region-level network policy. Therefore, after the region controller obtains the network policy, it needs to first determine whether the network policy is for a specific device or for devices in a region. Therefore, it determines the target network device from the currently managed network devices according to the global instruction, where the global instruction also includes an indication identifier, which is used to determine whether the network policy is for a specific device or for devices in a region.
[0053] After the target network device is identified, since the network policy is represented by high-level instructions or rules, if the network policy is directly forwarded to the network device, the network device will not understand it and the policy execution will fail. Therefore, in this embodiment, the network policy is converted into device instructions that the target network device can execute. These device instructions are low-level specific operation commands.
[0054] For example, if the advanced policy description is "Block traffic from IP range 192.168.1.0 / 24", then the device command would be "ipaccess-list extended BLOCK, deny ip 192.168.1.0 0.0.0.255any".
[0055] It is worth noting that for the same network policy, different target network devices will have different corresponding device commands due to differences in the target network devices. Therefore, converting the network policy into device commands executable by the target network device includes:
[0056] Extract key policy content from network policies; obtain device characteristics of target network devices, and convert key policy content into policy configuration information supported by the target network devices based on device characteristics; generate device instructions based on policy configuration information.
[0057] The key policy content consists of core information within the network policy, guiding the behavior of network devices. Examples include traffic priority rules, ACLs, and QoS parameters. In one example, key parameter fields and operational logic are extracted from the network policy issued by the global controller to generate the key policy content. This requires parsing the high-level description of the policy, such as through predefined policy templates or a DSL (Domain-Specific Language) to achieve accurate extraction of the policy content.
[0058] Device characteristics refer to the hardware, software capabilities, and protocol support of the target network device, such as interface type (e.g., Command Line Interface (CLI) or Application Programming Interface (API)), supported routing protocols, throughput capacity, etc. The area controller locally maintains a configuration information table (device capability database) for each network device it manages, and the area controller can also query device status in real time.
[0059] In one example, the configuration capabilities and command set supported by the device are extracted, and the functions that the device can currently execute are filtered out, such as whether it supports specific QoS rules or traffic mirroring functions.
[0060] During the conversion process, key policy content can be mapped and refined to convert it into a configuration format supported by the target network device. For example, traffic priority rules described in a global policy can be mapped to ACL entries or route redistribution commands; traffic forwarding rules defined in a global policy, but requiring specific interface configuration commands and ACL rules for the device, can be refined to specific interfaces.
[0061] Optionally, the area controller can also check whether the generated policy configuration information is fully compatible with the device characteristics when generating policy configuration information; if some policies cannot be directly applied to the target device, it is necessary to downgrade the policy or provide a compatibility reminder.
[0062] The policy configuration information is then converted into specific CLI or API calls, and the syntax and parameters of the commands are formatted according to the target device's operating system (such as Cisco IOS, Huawei VRP, etc.) to ensure compliance with device requirements.
[0063] In one example, multiple generated instructions are packaged according to their execution order and dependencies to generate the final device instructions; for example, the interface is configured first and then traffic rules are applied to ensure the correct logic of instruction execution.
[0064] In this embodiment, the characteristics and differences of network devices are fully considered. Based on the device characteristics of the network devices, the key content of the policy is converted into policy configuration information supported by the target network device, and device instructions are generated. This ensures that the global policy can be accurately mapped to the operation of different devices, realizes the seamless distribution and execution of policies, improves the efficiency of device execution instructions, and enhances the flexibility and adaptability of network management.
[0065] In this embodiment, the area controller can also dynamically adjust the network policy sent by the global controller. In one example, the policy configuration information is information obtained by "translating" the network policy. Device instructions are generated based on the policy configuration information, including:
[0066] Obtain the device status of the target network device, adjust the policy configuration information according to the device status to obtain the target policy configuration information, and convert the target policy configuration information into device commands.
[0067] Among them, device status refers to the current operating status of the device, including the utilization rate of hardware resources (such as the device's CPU, memory, and hard disk), software status, network interface status (such as the traffic, error packets, and connection status of each network interface on the device (such as Ethernet port and fiber optic port), running protocols, and configurations.
[0068] Based on the device status, the original global controller's corresponding policy configuration information is adjusted to obtain the target policy configuration information, ensuring that the policy can be executed efficiently under the current device status. For example, if the traffic on some interfaces of a network device is high, the traffic priority or traffic load balancing policy needs to be adjusted to avoid device overload. Based on the device's current service quality (such as latency, throughput, etc.), the QoS policy is dynamically adjusted, and then the target policy configuration information is converted into device instructions.
[0069] By acquiring device status and adjusting policy configuration information, it is possible to ensure that network policies can change flexibly according to device operation, thus guaranteeing network stability and efficiency. The adjusted policies are then converted into instructions that the devices can understand and execute, ultimately enabling network devices to self-optimize and adjust based on real-time network status and business needs.
[0070] S330: Send the device command to the target network device for execution.
[0071] After the area controller translates network policies into device instructions, it can quickly send the device instructions to the target network device for execution via the local network.
[0072] In one example, if the target network devices are numerous, the area controller can improve efficiency by batch processing or parallel sending. For instance, for a large number of devices within a certain area, multiple instructions can be packaged together and sent over the network all at once, or parallel communication protocols can be used to send instructions to multiple devices simultaneously, further improving the execution efficiency of the instructions.
[0073] In one example, when the network is busy, the area controller needs to optimize the order and strategy of sending instructions to avoid sending instructions to a large number of devices at the same time, which would cause network congestion. A load balancing strategy can be adopted to reasonably schedule the time of instruction sending and the target devices to improve overall efficiency.
[0074] In one example, when dealing with multiple network devices, the area controller can prioritize commands based on their importance and urgency. For instance, for high-priority tasks (such as fault repair), the area controller will send and execute the relevant commands first, ensuring rapid network recovery.
[0075] In one example, if a network policy is a task that needs to be executed across regions, the region controller needs to work with other region controllers to ensure that instructions from each region can be executed consistently and in a coordinated manner. For instance, if a global network policy generated based on global network orchestration needs to be completed across multiple regions, the global controller divides the global network policy into network policies corresponding to each region and assigns them to the relevant region controllers. Each region controller then converts the network policy into device instructions executable by the local target network device. The device instructions are then sent to the target network device for execution, including:
[0076] Obtain the execution progress and resource usage of specific network devices managed by other area controllers when executing specific device commands; based on the execution progress and resource usage, send the device commands to the target network device for execution.
[0077] In this process, other area controllers determine the specific network devices corresponding to the network policies and convert the network policies into specific device instructions. Area controllers exchange information through dedicated communication channels. Therefore, an area controller can locally obtain the execution progress and resource usage of specific network devices of other area controllers executing the corresponding specific device instructions.
[0078] like Figure 4 As shown, the global controller sends network policy 1 and network policy 2 to area controller 1 and area controller 2 respectively. There is a dedicated communication channel between area controller 1 and area controller 2. The execution progress and resource usage of device instructions in other areas are obtained through the dedicated communication channel.
[0079] Assuming a dependency exists between network policy 1 and network policy 2, area controller 1 sends the corresponding device instruction 1 to the target network device 1 it manages, and sends the execution progress of the target network device 1 to area controller 2 according to the dependency. Then, area controller 2 sends the corresponding specific device instruction 2 to the specific network device 2 it manages for execution according to the execution progress of the target network device 1. For example, when device instruction 1 is completed or the execution progress is 90%, specific device instruction 2 is sent to specific network device 2. Assuming a concurrent execution relationship between network policy 1 and network policy 2, specific device instruction is sent to specific network device 2 when device instruction 1 starts execution or the execution progress is less than 5%.
[0080] The regional controller can coordinate resources within and between regions. For example, when device resources in a certain region are insufficient, other regions can provide support. Application scenarios include bandwidth allocation and computing resource sharing. Suppose that local regional controller 1 determines that the bandwidth resources of its region are bottlenecked, regional controller 2 can provide backup bandwidth support. Based on the bandwidth resources provided by regional controller 2, instruction execution resources are allocated to the target network device. Then, based on the characteristics of other regional controllers and the execution progress of device instructions, the device instructions are sent to the target network device for execution, enabling the target network device to execute device instructions based on the instruction execution resources.
[0081] In this embodiment, a regional controller is introduced into the cloud network system to manage network devices within its assigned region. This effectively reduces the load on the global controller. The regional controller receives global instructions from the global controller, which carry network policies generated based on global network orchestration. Based on the global instructions, the regional controller identifies the target network device from among the currently managed network devices and converts the network policy into executable device instructions for the target network device. In other words, the global controller ensures that the global policy can dynamically adapt to the real-time status of devices within the region based on global network orchestration, thereby optimizing overall network performance. The regional controller decomposes the complex network policy of the global controller into specific device instructions, lowering the understanding threshold for devices and ensuring accurate policy implementation. The device instructions are then sent to the target network device for direct execution without further understanding by the device, enabling the device to execute in the most efficient way, improving device execution efficiency and reducing resource waste.
[0082] In one embodiment of this application, another device control method is provided, which can be applied to... Figure 1 In the implementation environment shown, this method can be executed by a region controller, where the network policy includes device-level network policies for devices and region-level network policies for regions, such as... Figure 5 As shown, S510 to S540 are detailed below:
[0083] S510: Obtain global commands sent by the global controller.
[0084] S520a: Extract the device identifier corresponding to the device-level network policy from the global command, and determine the target network device from each network device based on the device identifier.
[0085] S520b: Extract the region identifier applicable to the regional network policy from the global command. If the extracted region identifier includes the local region identifier, then the online network device among the various network devices is used as the target network device.
[0086] S530: Convert the network policy into device instructions executable by the target network device, and send the device instructions to the target network device for execution.
[0087] S540: Receive the execution confirmation message from the target network device and send the execution result of the target network device carried in the execution confirmation message to the global controller so that the global controller stores the device-level network policy of the target network device.
[0088] For the processes of S510 and S530, please refer to the aforementioned S310 to S330. S520a and S520b are two different cases.
[0089] In S520a, the global controller specifies the specific devices to which the network policy applies. The network policy includes device-level network policies for the devices. The area controller can extract the device identifier corresponding to the device-level network policy from the global instructions. This device identifier is used to indicate the specific device to which the network policy applies. Then, the area controller compares the device identifier with the device identifiers of each local network device to determine the target network device corresponding to the device identifier.
[0090] To facilitate subsequent auditing and management by the global controller, after the area controller sends the device instruction to the target network device, the target network device will send an execution confirmation message to the area controller after successfully executing the policy. This execution confirmation message carries the execution result of the target network device, and then the area controller sends the execution result to the global controller. The global controller then stores the device-level network policy of the target network device in the database.
[0091] In S520b, the global controller specifies the regions to which network policies apply. These network policies include region-level network policies. The region controller can extract the region identifier corresponding to the region-level network policy from global commands. The region identifier indicates the specific region to which the network policy applies. If the extracted region identifier includes a local region identifier, it means that the network policy can be applied to all network devices within that specific region. When the region controller confirms that a device within the region is offline, since the offline device cannot receive and execute commands, the online network device among the network devices is used as the target network device.
[0092] Optionally, the area controller can also include temporarily offline network devices as target network devices. The area controller needs to detect the offline duration of each offline network device, select devices with an offline duration of less than a preset duration as candidate network devices, and then determine whether the offline status is temporary based on the number of times the candidate network devices have gone offline.
[0093] In the embodiments of this application, device-level network policies can be applied to target network devices efficiently and accurately, ensuring the flexibility and reliability of network operation. The storage of policy execution results facilitates future detection and auditing, while the distribution of regional-level network policies is more efficient and accurate, meeting the rapidly changing management needs in modern large-scale network environments.
[0094] This application provides another device control method, which can be applied to... Figure 1 The implementation environment shown is illustrated using the example of this method being executed by a regional controller. Figure 6 As shown, S610 to S640 are detailed below:
[0095] S610: Obtain global commands sent by the global controller.
[0096] S620. Based on the global instructions, determine the target network device from the currently managed network devices and convert the network policy into device instructions that can be executed by the target network device.
[0097] S630: Send the device command to the target network device for execution.
[0098] S640: Receive the cancellation information sent by the global controller. The cancellation information is used to indicate that the device status of the cancelled network device is marked as cancelled.
[0099] S650, in response to the policy deletion command sent by the global controller, deletes the network policies and device configuration information associated with the network device being removed.
[0100] Please refer to the above S310 to S330 for the processes of S610 to S630.
[0101] Network devices may need to be decommissioned due to failure, expiration of service life, or other reasons. The decommissioned devices are offline (e.g., due to failure or power failure), but the related network policies and configurations are still retained in the global controller and regional controller. The residual data and configurations not only occupy valuable system resources, but may also increase the complexity of network management and maintenance. The traditional direct power-off method is no longer applicable. Therefore, it is necessary to delete the configurations related to these devices and the controllers, while ensuring the normal operation of other devices.
[0102] In this embodiment, before deleting the policy, the global controller can mark the status of the network device to be removed and update its status to "removed", thereby generating removal information. The regional controller receives the removal information to know the removal status of the removed network device. Since the device is identified as removed according to the status mark, the regional controller will skip the control command issuance to the device itself. After receiving the policy deletion command sent by the global controller, it will delete the network policy and device configuration information related to the removed network device from the local machine.
[0103] By marking the status of the devices to be removed, the deletion process no longer depends on the online status of the devices, ensuring that the deletion operation can be completed smoothly.
[0104] The network devices being removed may involve both device-level and region-level network policies. The S650 removal process varies depending on the type of network policy:
[0105] S650a: Delete the device configuration information related to the cut-off network device from the local area controller, and delete the device-level network policy for the cut-off network device from the database through the global controller.
[0106] S650b: If the regional network policy of the area to which the area controller belongs includes the network device to be removed, then query each other network device to which the regional network policy applies, delete the associated configuration information related to the removed network device from each other network device, and delete the removed network device from the regional network policy through the global controller.
[0107] In S650a, since the removed network device is already removed, its device configuration information can be directly deleted from the local storage area. The global controller stores the device-level network policies of the removed network device, so these policies also need to be deleted. In one example, if the area controller also stores the device-level network policies of the removed network device, these policies also need to be deleted. After deleting the relevant policies and configurations of the removed device, the area controller can perform cleanup to ensure that no redundant data remains.
[0108] In S650b, unlike device-level policies, region-level policies affect the collaboration between multiple devices, such as network tunneling, load balancing, and quality of service. When a device is removed, it's not only necessary to delete the configuration of the individual device, but also to ensure that the related policies within the region are correctly adjusted. Therefore, the region controller needs to query whether the region-level network policy includes the removed network device. If it does, it queries all other network devices to which the region-level network policy applies, such as... Figure 2 If network devices 2-3 are involved, the area controller needs to analyze the relationship between the removed network device 1 and network devices 2-3, and delete the associated configuration information related to the removed network device 1 from network devices 2-3 based on the relationship. For example, if network devices 2-3 share a Quality of Service (QoS) assurance policy with the removed network device 1, then the configuration information corresponding to the QoS assurance policy needs to be deleted from network devices 2-3; another example is deleting the routing configuration information related to the removed network device 1 from network devices 2-3. Simultaneously, the global controller will remove the removed network devices from the area-level network policy.
[0109] Understandably, if the network device being removed only involves regional network policies, the regional controller will delete the device configuration information related to the removed network device from its local storage and delete the associated configuration information related to the removed network device from all other network devices.
[0110] In one example, after a device is removed, the area controller will reconfigure the devices within the area so that the remaining devices in the area can continue to work together; reconfiguration may include reallocating network bandwidth and adjusting routing priorities.
[0111] In one example, to mitigate the impact of device removal, the regional controller incorporates redundancy and fault tolerance mechanisms. For instance, backup devices can automatically take over tasks after device removal, ensuring uninterrupted service.
[0112] In this embodiment, by marking the status of the device to be removed, the deletion process no longer depends on the online status of the device, ensuring that the deletion operation can be completed smoothly. Device removal involves deleting the configuration of the device, and it is ensured that it does not affect the operation of other devices. Device removal will affect regional policies and requires adjustment of policy configurations related to other devices, thus ensuring the integrity and consistency of network configuration after device removal.
[0113] It is worth noting that in this embodiment, the area controller plays a crucial role in the cloud network system, and its functions extend far beyond simply translating device commands. In addition to this fundamental responsibility, the area controller also undertakes a series of dynamic tasks, which are essential for the efficient operation and flexible management of the network. Because the area controller is physically close to the equipment room, this advantage can be fully utilized to establish a closer and more efficient communication mechanism. Therefore, in this embodiment, before receiving global commands from the global controller, the area controller establishes neighbor relationships with each network device within its area, such as based on the Border Gateway Protocol (BGP). BGP, as an efficient and reliable routing protocol, is widely used between Internet service providers and in large enterprise intranets.
[0114] Based on neighbor relationships, the area controller exchanges routing information with various network devices. If the network policy includes a routing adjustment policy, the routing information of the target network device is adjusted according to the routing adjustment policy and the current network state. In other words, by establishing BGP neighbor relationships, the area controller can directly exchange routing information with devices and dynamically adjust the device's routing table using BGP based on the routing adjustment policy defined on the global controller and the current network conditions. The routing adjustment policy can be based on various factors, such as network traffic load, link state, and quality of service requirements; the routing information includes the route destination, next-hop address, and route weight.
[0115] In one example, the area controller updates its or the network topology view within the area based on the routing information exchanged with the devices, forming a complete network topology. After obtaining the routing adjustment policy, the area controller checks the current routing adjustment policy to identify whether adjustments are needed based on the real-time status of the current network. For example, if a link between devices is overloaded, the route is adjusted to divert some traffic to other links. Then, based on the adjusted routing adjustment policy and the current network topology, the optimal route for each device is calculated to obtain the updated routing table.
[0116] After adjusting the routing table of a device, the area controller immediately transmits the updated routing table to the network device via the BGP protocol. Upon receiving the routing update from the area controller, the network device adjusts its routing table accordingly, thereby changing the forwarding path of traffic in the network. This dynamic routing adjustment mechanism enables the network to self-optimize based on real-time conditions, improving network resource utilization and overall network performance.
[0117] In one example, the network device can also report the update status of the routing table to the area controller, which then compares the updated status of the routing table reported by the device with the routing adjustment policy to determine whether it meets expectations and whether further optimization is needed.
[0118] In cloud network systems, the introduction of area controllers not only enables the translation of device commands but also endows the network with the ability to dynamically adjust and optimize. Through the BGP neighbor relationships established between the area controller and devices, network administrators can utilize policies on the controller and dynamically control device routing via the BGP protocol, thereby achieving fine-grained management of network traffic. This mechanism not only improves network flexibility and responsiveness but also enhances network controllability and manageability.
[0119] Figures 3 to 6 The illustrated embodiment is presented from the perspective of a zone controller. The following description, in conjunction with... Figure 7 The implementation details of the technical solutions in the embodiments of this application are described in detail from the perspective of a global controller:
[0120] like Figure 7 As shown, Figure 7 This is a flowchart illustrating a device control method according to an embodiment of this application, which can be applied to... Figure 1 or Figure 2 In the implementation environment shown, this method can be executed by a global controller. This device control method can include S710 to S730, which are described in detail below:
[0121] S710. Based on the overall network conditions and business requirements, perform global network orchestration to obtain an orchestration scheme, and generate network policies based on the orchestration scheme.
[0122] Global network orchestration refers to the process by which a global controller plans and manages the entire network in a unified manner after comprehensively considering factors such as the operating status of network devices, service requirements, traffic distribution, and network topology. Its purpose is to ensure that the network can meet performance requirements while improving resource utilization and service quality through measures such as efficient allocation of network resources, optimization of routing, and dynamic adjustment of strategies.
[0123] The global controller collects network device operating status, traffic distribution, and network topology information to form a global view of the entire network. Device operating status includes link load, bandwidth utilization, device fault status, packet loss rate, and latency. Traffic distribution includes identifying areas with high traffic load and areas with available bandwidth. Network topology information includes the connection relationships between devices and link characteristics. The global controller can obtain service requirements from user input, such as improving network performance in specific areas, and then perform global network orchestration based on the global view and service requirements.
[0124] In one example, during global network orchestration, the allocation of bandwidth, routing, and computing resources can be dynamically adjusted according to business needs, or the routing or backup path can be adjusted based on the fault status of devices or links, to obtain an orchestration scheme.
[0125] Optionally, after obtaining the orchestration scheme, the specific adjustment requirements for each region are extracted from the orchestration scheme, these requirements are converted into policy instructions to obtain network policies, and the network policies are layered into region-level policies and device-level policies.
[0126] S720: Determine the corresponding target area controller based on the network policy.
[0127] Each area controller is responsible for the device management of its assigned area. The global controller queries the area allocation table and determines the target area controller based on the area information involved in the network policy.
[0128] S730: Send a global instruction carrying the network policy to the target area controller, so that the target area controller can determine the target network device from the various network devices currently managed, convert the network policy into a device instruction that the target network device can execute, and then send the device instruction to the target network device for execution.
[0129] The global controller generates global instructions based on network policies, and then sends the global instructions to the target area controller. For details of the target area controller process, please refer to the aforementioned embodiments.
[0130] In this embodiment of the application, after sending the global instruction carrying the network policy to the target area controller, the method further includes: if the network policy includes a device-level network policy for the target network device, then in response to the execution result of the target network device sent by the area controller, the device-level network policy is stored in the database; if the network policy includes a region-level network policy for the region, then after the global instruction is successfully sent to the area controller, the region-level network policy is stored in the database.
[0131] For device-level network policies, after a target network device successfully executes the policy, the area controller will report the execution result of the target network device. The global controller will detect that the execution result of the target network device is the same as the expected result and associate the device-level network policy with the device identifier of the target network device and store it in the database. For region-level network policies, the region-level policy can be saved in the database after the global controller successfully forwards it to the region controller. It does not need to wait for the region controller to confirm that the policy has been successfully distributed to each device, thereby speeding up the overall policy deployment speed.
[0132] In this embodiment of the application, after sending the global instruction carrying the network policy to the target area controller, the method further includes: determining the network device to be removed, querying the area controller to which the network device to be removed belongs, and sending removal information indicating that the device status of the network device to be removed is marked as removed to the area controller; sending a policy deletion instruction to the area controller; deleting the device-level network policy associated with the network device to the database according to the policy deletion instruction, and deleting the network device to be removed from the area-level network policy associated with the network device to be removed.
[0133] If a network device experiences multiple failures or its service life expires, it will be identified as a device to be phased out. First, the device needs to be marked as "phased out" in the database. Then, phase-out information indicating the phased-out device's status is sent to the regional controller, enabling the regional controller to also recognize it as a phased-out device. Since the database also stores policies related to the phased-out device, and the regional controller contains configuration information related to it, a policy deletion command is sent to the regional controller to delete the relevant configuration information. Simultaneously, the global controller queries the database for the device-level and regional-level network policies associated with the phased-out device based on the policy deletion command, deletes the device-level network policy, and removes the phased-out device from the regional-level policies.
[0134] For ease of understanding, the embodiments of this application use... Figure 1 The implementation environment provides a detailed description of policy conversion and distribution, as well as device removal policies for the global controller and regional controller.
[0135] like Figure 8 As shown, the conversion and distribution of device-level network policies and the device decommissioning policies include:
[0136] S810, Object creation of device-level network policies.
[0137] The object specifies the device-level network policies to be deployed on the global controller. This involves detailed configuration of policy parameters, including but not limited to ACLs, QoS settings, and security policies.
[0138] In other embodiments of this application, the global controller may formulate a global network orchestration scheme based on network conditions and service requirements to create device-level network policies.
[0139] S820: The global controller queries the database for the area controller to which the device belongs, corresponding to the device-level network policy.
[0140] Once a policy is specified, the global controller uses its built-in database to query and determine the area controller to which the target device belongs, ensuring that the policy is correctly routed to the area controller responsible for managing the device.
[0141] S830, the global controller sends device-level network policies to the corresponding area controllers.
[0142] The S840 and area controller convert device-level network policies into device commands and send them to the corresponding devices.
[0143] The global controller forwards policy information to the corresponding area controllers via global commands. Upon receiving the policy, the area controller converts the high-level device-level network policy into low-level control commands, i.e., device commands, that the device can understand and execute, based on the characteristics and capabilities of the device.
[0144] The S850 global controller saves device-level network policies to the database based on the execution results of the devices.
[0145] The translated device instructions are sent to the target device for execution. After successfully executing the policy, the device sends an acknowledgment message to the area controller. Upon receiving the execution acknowledgment, the area controller sends the execution result back to the global controller. After confirming that the policy has been successfully deployed, the global controller saves the device-level policy information to its database for future auditing and management.
[0146] S860: The object cancels the device and sends the cancellation information, which marks the device as canceled, to the global controller.
[0147] If a device-level policy is issued, when a network device needs to be decommissioned due to various reasons such as failure or expiration of service life, the device may be offline, but the global controller and regional controller still retain network policies and device configurations, which need to be deleted. If the object is deleted through the northbound interface of the global controller using a regular policy, the deletion will ultimately fail because the regional controller fails to send control commands to the device (because the device has failed or is powered off). If the deletion policy process fails, the global controller will not delete its data in the database to ensure data consistency, and the data of the decommissioned device will remain.
[0148] Therefore, before applying a deletion policy to a device that has already been removed, the object can remove the device and mark it as removed in the global controller before applying the deletion policy. During deletion, both the global controller and the regional controller will recognize that the device has been removed, skipping the step of issuing control commands to the device itself, and the process can be completed normally.
[0149] In other embodiments of this application, the global controller may also remove the device based on the device's status.
[0150] S870: The global controller queries the area controller to which the device belongs and sends the removal information of the device marked as removed to the area controller.
[0151] S880, the object indicates the global controller's policy for deleting devices.
[0152] S890, the global controller sends a policy deletion command to the corresponding regional controller.
[0153] S8100, delete relevant device configuration information for the area controller.
[0154] S8110, the global controller deletes device-level policies from the database.
[0155] The global controller and regional controller each delete the network policies and configuration information associated with the device. After deletion, the global controller synchronously updates the database to ensure no device data remains. In network management, the distribution of regional network policies is a more macro-level process, allowing network policies to be managed on a regional basis, rather than individually for each device. Figure 9 As shown, the regional network policy conversion and distribution, and equipment removal policies include:
[0156] S910, Object creation of regional network policies.
[0157] The object defines the required region-level network policy on the global controller and specifies the region to which the policy applies. Compared with device-level network policies, this avoids the tedious configuration of each device and improves the efficiency of policy deployment.
[0158] S920: The global controller queries the database to find the area controller to which the device corresponding to the area-level network policy belongs.
[0159] S930: The global controller sends regional network policies to the corresponding regional controllers.
[0160] After receiving the policy and region information, the global controller queries its database to determine the region controller corresponding to the region, ensuring that the policy can be correctly distributed to the region controller responsible for the network management of that region.
[0161] Once the zone controller is identified, the global controller forwards the policy to it. The zone controller then queries a list of all devices it currently manages to translate and adapt the policy to those devices.
[0162] S940, Global Controller saves region-level policies to the database.
[0163] Unlike device-level policies, region-level policies are saved to the database immediately after being successfully forwarded from the global controller to the region controller. This step does not require waiting for the region controller to confirm that the policy has been successfully distributed to every device, thus speeding up the overall policy deployment process.
[0164] Through this mechanism, regional network policies can be quickly extended to all devices within a specified area, while reducing the latency that may occur due to waiting for a single device to respond. This method is particularly suitable for large-scale network environments where there are a large number of devices and policies are updated frequently.
[0165] S950, the area controller determines the devices involved in the area-level network policy and sends the corresponding device instructions for converting the area-level network policy to the corresponding devices.
[0166] S960, the object cancels the device and sends the cancellation information, which marks the device as canceled, to the global controller.
[0167] S970, the global controller queries the area controller to which the device belongs and sends the removal information of the device marked as removed to the area controller.
[0168] S980, the object indicates the global controller's policy for deleting devices.
[0169] S990, the global controller sends a policy deletion command to the corresponding regional controller.
[0170] Remove relevant configurations from S9100 and the area controller.
[0171] S9110, the area controller removes the associated configurations related to the eliminated device from other devices.
[0172] S9120, the global controller deletes the region-level policy from the database.
[0173] When decommissioning devices, region-level policies cannot be applied directly because they involve the configuration of other devices. When decommissioning a device, the global controller first queries the region to which the decommissioned network device belongs to, identifies which region-level policies are configured, and then sends these region-level policies and device configurations to the corresponding region controller. The region controller then queries the devices to which the policy applies and removes the decommissioned network device from the region-level policy list.
[0174] Regional policies not only distribute configurations individually to each device, but also involve configurations associated with multiple devices, such as network tunnels established between two devices, policy routing, and so on. Therefore, after only deleting the removed device, configuration data may still remain on other devices; the regional controller also needs to query the device configurations associated with the removed network device and delete the associated device configurations from the associated devices.
[0175] The controller's removal of devices is a complete process, including the deletion of device-level and region-level policies, such as... Figure 10 As shown.
[0176] After a device is successfully removed from the network, if it sends its device-level policy to the global controller again, the global controller interface will reject it directly. If it sends a region-level policy containing the region to which the device belongs, the region controller will ignore it and only process other devices.
[0177] In this embodiment, a globally centralized global controller and a regional controller are used to achieve efficient network operation and flexible management. The regional controller converts high-level policy instructions into low-level control instructions that devices can understand and execute, and distributes them to the corresponding devices to achieve fine-grained management of network traffic, thereby enhancing the controllability and manageability of the network. In addition, a complete device removal process is proposed, including the deletion of device-level and regional-level policies, timely deletion of configuration data of removed devices, avoiding resource waste and potential network conflicts, and ensuring data consistency and network stability.
[0178] This application describes an apparatus embodiment that can be used to execute the device control method described above in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the device control method described above in this application.
[0179] This application provides a device control apparatus applied to a cloud network system. The cloud network system includes a global controller, a regional controller, and at least one network device managed within the region to which the regional controller belongs. The apparatus is deployed on the regional controller. Figure 11 As shown, it includes:
[0180] The acquisition module 1110 is used to acquire the global instructions sent by the global controller, the global instructions carrying a network strategy generated based on the global network orchestration;
[0181] The conversion module 1120 is used to determine the target network device from the currently managed network devices according to the global instructions, and convert the network policy into device instructions executable by the target network device.
[0182] The instruction sending module 1130 is used to send the device instruction to the target network device for execution.
[0183] In one embodiment of this application, based on the foregoing scheme, the network policy includes a device-level network policy for the device; the conversion module is further configured to extract the device identifier corresponding to the device-level network policy from the global instruction, and determine the target network device from the various network devices according to the device identifier; the device also includes a feedback module, configured to receive an execution confirmation message from the target network device, and send the execution result of the target network device carried in the execution confirmation message to the global controller, so that the global controller stores the device-level network policy of the target network device.
[0184] In one embodiment of this application, based on the foregoing scheme, the network policy includes a region-level network policy for a region, and the conversion module is further configured to extract the region identifier to which the region-level network policy applies from the global instruction. If the extracted region identifier includes a local region identifier, then the online network device among the various network devices is used as the target network device.
[0185] In one embodiment of this application, based on the foregoing scheme, the conversion module is further configured to extract key policy content from the network policy; obtain the device characteristics of the target network device, and convert the key policy content into policy configuration information supported by the target network device according to the device characteristics; and generate the device instruction according to the policy configuration information.
[0186] In one embodiment of this application, based on the foregoing scheme, the conversion module is further configured to obtain the device status of the target network device, and adjust the policy configuration information according to the device status to obtain target policy configuration information; and convert the target policy configuration information into the device instruction.
[0187] In one embodiment of this application, based on the foregoing scheme, the device further includes a culling module, configured to receive culling information sent by the global controller, the culling information being used to indicate that the device status of the culled network device is marked as culled; and in response to a policy deletion instruction sent by the global controller, to delete network policies and device configuration information related to the culled network device.
[0188] In one embodiment of this application, based on the foregoing scheme, the removal module is further configured to delete the device configuration information related to the removed network device from the local area controller, and delete the device-level network policy for the removed network device from the database through the global controller; if the regional-level network policy of the area to which the area controller belongs includes the removed network device, then query each other network device to which the regional-level network policy is applied, delete the associated configuration information related to the removed network device from each other network device, and delete the removed network device from the regional-level network policy through the global controller.
[0189] In one embodiment of this application, based on the foregoing scheme, the device further includes a routing module, configured to establish neighbor relationships with each network device in the region, and exchange routing information with each network device according to the neighbor relationships, and further configured to adjust the routing information of the target network device according to the routing adjustment policy and the current network state if the network policy includes a routing adjustment policy.
[0190] In one embodiment of this application, based on the foregoing scheme, the sending module is further configured to obtain the execution progress and resource usage of a specific network device managed by another area controller executing a specific device instruction; and send the device instruction to the target network device for execution according to the execution progress and resource usage.
[0191] This application also provides a device control apparatus applied to a cloud network system. The cloud network system includes a global controller, a regional controller, and at least one network device managed within the region to which the regional controller belongs. The apparatus is deployed on the global controller, such as... Figure 12 As shown, it includes:
[0192] The generation module 1210 is used to perform global network orchestration based on the global network conditions and business requirements to obtain an orchestration scheme, and to generate network policies based on the orchestration scheme.
[0193] The determination module 1220 is used to determine the corresponding target area controller according to the network policy;
[0194] The policy sending module 1230 is used to send a global instruction carrying the network policy to the target area controller, so that the target area controller can determine the target network device from the various network devices currently managed, convert the network policy into a device instruction that can be executed by the target network device, and send the device instruction to the target network device for execution.
[0195] In one embodiment of this application, based on the foregoing scheme, the device module further includes a storage module, configured to: if the network policy includes a device-level network policy for a target network device, then in response to the execution result of the target network device sent by the area controller, store the device-level network policy in a database; if the network policy includes a region-level network policy for a region, then after the global instruction is successfully sent to the area controller, store the region-level network policy in a database.
[0196] In one embodiment of this application, based on the foregoing scheme, the device module further includes a deletion module, configured to determine the network device to be removed, query the area controller to which the removed network device belongs, and send removal information indicating that the device status of the removed device is marked as removed to the area controller; send a policy deletion instruction to the area controller; delete the device-level network policy associated with the removed network device from the database according to the policy deletion instruction, and delete the removed device from the area-level network policy associated with the removed device.
[0197] It should be noted that the apparatus provided in the above embodiments and the method provided in the above embodiments belong to the same concept, and the specific way in which each module and unit performs operations has been described in detail in the method embodiments, and will not be repeated here.
[0198] Embodiments of this application also provide an electronic device, including one or more processors and a storage device, wherein the storage device is used to store one or more computer programs, which, when executed by one or more processors, cause the electronic device to implement the device control method described above.
[0199] Figure 13 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown.
[0200] It should be noted that, Figure 13 The computer system 1300 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0201] like Figure 13As shown, the computer system 1300 includes a central processing unit (CPU) 1301, which can perform various appropriate actions and processes, such as executing the methods described in the above embodiments, based on a program stored in read-only memory (ROM) 1302 or a program loaded from storage portion 1308 into random access memory (RAM) 1303. The RAM 1303 also stores various programs and data required for system operation. The CPU 1301, ROM 1302, and RAM 1303 are interconnected via a bus 1304. An input / output (I / O) interface 1305 is also connected to the bus 1304.
[0202] In some embodiments, the following components are connected to the I / O interface 1305: an input section 1306 including a keyboard, mouse, etc.; an output section 1307 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1308 including a hard disk, etc.; and a communication section 1309 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 1309 performs communication processing via a network such as the Internet. A drive 1310 is also connected to the I / O interface 1305 as needed. A removable medium 1313, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1310 as needed so that computer programs read from it can be installed into the storage section 1308 as needed.
[0203] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as a computer program. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1309, and / or installed from removable medium 1313. When the computer program is executed by processor (CPU) 1301, it performs various functions defined in the system of this application.
[0204] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory, flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0205] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and a computer program.
[0206] The units or modules described in the embodiments of this application can be implemented in software or hardware, and can also be located in a processor. The names of these units or modules do not necessarily limit the specific unit or module itself.
[0207] Another aspect of this application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the device control method as described above. This computer-readable storage medium may be included in the electronic device described in the above embodiments, or it may exist independently and not assembled into the electronic device.
[0208] Another aspect of this application provides a computer program product comprising a computer program stored in a computer-readable storage medium. A processor of an electronic device reads the computer program from the computer-readable storage medium and executes the computer program, causing the electronic device to perform the device control method as described above in the various embodiments.
[0209] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0210] Other embodiments of this application will readily conceive of by considering the specification and practicing the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.
[0211] The above content is merely a preferred exemplary embodiment of this application and is not intended to limit the implementation of this application. Those skilled in the art can easily make corresponding modifications or alterations based on the main concept and spirit of this application. Therefore, the scope of protection of this application should be determined by the scope of protection claimed in the claims.
Claims
1. A device control method characterized by, The method is applied to a cloud network system, which includes a global controller, a regional controller, and at least one network device managed within a region to which the regional controller belongs. The method is applied to the regional controller and includes: Obtain the global instruction sent by the global controller, the global instruction carrying a network policy generated based on the global network orchestration; Based on the global instructions, the target network device is determined from the currently managed network devices, and the network policy is converted into device instructions executable by the target network device. The device command is sent to the target network device for execution.
2. The method of claim 1, wherein, The network policy includes device-level network policies for devices; determining the target device from the currently managed network devices according to the global instruction includes: Extract the device identifier corresponding to the device-level network policy from the global instructions, and determine the target network device from the various network devices based on the device identifier; After sending the device instruction to the target network device for execution, the method further includes: The system receives the execution confirmation message from the target network device and sends the execution result of the target network device carried in the execution confirmation message to the global controller, so that the global controller stores the device-level network policy of the target network device.
3. The method of claim 1, wherein, The network policy includes a region-level network policy for a specific area. The step of determining the target network device from the currently managed network devices based on the global instruction includes: Extract the region identifier to which the regional network policy applies from the global instructions. If the extracted region identifier includes a local region identifier, then the online network device among the various network devices is taken as the target network device.
4. The method of claim 1, wherein, The step of converting the network policy into device instructions executable by the target network device includes: Extract the key policy content from the network policy; Obtain the device characteristics of the target network device, and convert the key policy content into policy configuration information supported by the target network device based on the device characteristics; The device instructions are generated based on the policy configuration information.
5. The method of claim 4, wherein, The step of generating the device instruction based on the policy configuration information includes: Obtain the device status of the target network device, and adjust the policy configuration information according to the device status to obtain the target policy configuration information; The target policy configuration information is converted into device instructions.
6. The method according to any one of claims 1 to 5, characterized in that, After sending the device instruction to the target network device for execution, the method further includes: Receive the culling information sent by the global controller, the culling information being used to indicate that the device status of the culled network device is marked as culled; In response to the policy deletion command sent by the global controller, the network policies and device configuration information associated with the removed network device are deleted.
7. The method of claim 6, wherein, The deletion of network policies and device configuration information related to the eliminated network devices includes: The device configuration information related to the cut-off network device is deleted locally from the regional controller, and the device-level network policy for the cut-off network device is deleted from the database through the global controller; If the regional network policy of the region to which the regional controller belongs includes the cut-off network device, then query each other network device to which the regional network policy applies, delete the associated configuration information related to the cut-off network device from each other network device, and delete the cut-off network device from the regional network policy through the global controller.
8. The method according to any one of claims 1 to 5, characterized in that, Before obtaining the global instructions sent by the global controller, the method further includes: Establish neighbor relationships with each network device in the region, and exchange routing information with each network device based on the neighbor relationships; After obtaining the global instructions sent by the global controller, the method further includes: If the network policy includes a routing adjustment policy, then the routing information of the target network device is adjusted according to the routing adjustment policy and the current network state.
9. The method according to any one of claims 1 to 5, characterized in that, Sending the device instructions to the target network device for execution includes: Obtain the execution progress and resource usage of specific network devices managed by other area controllers when executing specific device commands; Based on the execution progress and resource usage, the device instructions are sent to the target network device for execution.
10. A device control method characterized by, The method is applied to a cloud network system, which includes a global controller, a regional controller, and at least one network device managed within a region to which the regional controller belongs. The method is applied to the global controller and includes: Based on the overall network conditions and business requirements, a global network orchestration scheme is obtained, and a network policy is generated based on the orchestration scheme. The corresponding target area controller is determined based on the network strategy; A global instruction carrying the network policy is sent to the target area controller, so that the target area controller can determine the target network device from the various network devices currently managed, convert the network policy into a device instruction executable by the target network device, and then send the device instruction to the target network device for execution.
11. An apparatus control device characterized by comprising: An application in a cloud network system, the cloud network system including a global controller, a regional controller, and at least one network device managed within the region to which the regional controller belongs, the device being deployed in the regional controller, comprising: The acquisition module is used to acquire global instructions sent by the global controller, wherein the global instructions carry a network strategy generated based on global network orchestration; The conversion module is used to determine the target network device from the currently managed network devices according to the global instructions, and convert the network policy into device instructions executable by the target network device. The instruction sending module is used to send the device instruction to the target network device for execution.
12. A device control apparatus, characterized in that, An application in a cloud network system, the cloud network system including a global controller, a regional controller, and at least one network device managed within the region to which the regional controller belongs, the device being deployed on the global controller, including: The generation module is used to perform global network orchestration based on the global network conditions and business requirements to obtain an orchestration scheme, and to generate network policies based on the orchestration scheme. The determination module is used to determine the corresponding target area controller based on the network policy; The policy sending module is used to send a global instruction carrying the network policy to the target area controller, so that the target area controller can determine the target network device from the various network devices currently managed, convert the network policy into a device instruction executable by the target network device, and send the device instruction to the target network device for execution.
13. An electronic device, comprising: include: One or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, cause the electronic device to perform the method of any one of claims 1 to 9, or to perform the method of claim 10.
14. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by the processor of the electronic device, causes the electronic device to perform the method of any one of claims 1 to 9, or to perform the method of claim 10.