IPv6 address planning and management methods, equipment, media, and products based on custom identifier templates

CN122578518APending Publication Date: 2026-08-14SHENYANG QIANGXIN COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-20
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0005]针对上述技术问题和缺陷,本发明的目的是提供一种基于自定义标识模板的IPv6地址规划管理方法、设备、介质及产品,可以缓解相关技术中IPv6地址规划管理效率低下且规范性差的问题

Benefits of technology

[0053]第三方面,本发明提供一种计算机可读的存储介质,其存储有计算机指令,当该计算机指令在IP地址管理设备上运行时,使得该IP地址管理设备执行如第一方面,以及第一方面中任一可能的实现方式描述的方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122578518A_ABST
    Figure CN122578518A_ABST
Patent Text Reader

Abstract

This invention discloses an IPv6 address planning and management method, device, medium, and product based on a custom identifier template, relating to the field of data processing. The method includes: parsing the custom identifier template to extract the template configuration parameter set and constructing a multi-level identifier association tree model; generating a target service feature set based on a service network planning request, and obtaining a target identifier node set through hierarchical cascading constraint verification; generating candidate IPv6 addresses based on node bit positions, comparing them with a unified address planning ledger, and generating a target IPv6 address planning scheme when no addresses are occupied. This invention automates IPv6 address planning, improves management efficiency and standardization, reduces the risk of address conflicts, and solves the problems of low efficiency, logical conflicts, and invalid addresses associated with traditional manual IPv6 address management using tables.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing, and in particular to a method, device, medium and product for IPv6 address planning and management based on a custom identifier template. Background Technology

[0002] IPv6 (Internet Protocol Version 6) addresses are up to 128 bits long, consisting of eight hexadecimal characters, and serve as the underlying addressing foundation for the next-generation Internet. In the construction of large enterprises, industrial parks, or IoT networks, IPv6 address planning and management refers to assigning legal, usable IP addresses with specific business affiliations to various physical devices, logical gateways, or service nodes within the network to ensure the stable operation of the underlying network communication infrastructure.

[0003] Currently, in the process of deploying IPv6 and transitioning from IPv4 to IPv6, the industry mainly relies on manual operation combined with offline spreadsheets (such as Excel documents) for the planning, allocation, and management of IPv6 addresses. Typically, network administrators need to rely on their experience to manually assign corresponding routing prefixes based on the network topology, manually calculate hexadecimal address strings and subnet mask lengths by eye and calculator, and then manually record these calculated long address strings one by one in a static ledger to complete the initial address planning task.

[0004] However, due to the excessive length and extremely complex structure of IPv6 addresses, when faced with massive enterprise devices and multi-level business network architectures, relying on manual calculations and conventional tables cannot accurately control and verify the cascading dependencies and business constraints between various address segments. This can easily lead to logical conflicts or the splicing of invalid and illegal address combinations, resulting in low efficiency and poor standardization in IPv6 address planning and management. Summary of the Invention

[0005] To address the aforementioned technical problems and deficiencies, the purpose of this invention is to provide an IPv6 address planning and management method, device, medium, and product based on a custom identifier template, which can alleviate the problems of low efficiency and poor standardization in IPv6 address planning and management in related technologies.

[0006] To achieve the above objectives, in a first aspect, the present invention provides an IPv6 address planning and management method based on a custom identifier template, applied to an IP address management device, the method comprising:

[0007] The received custom identifier template is parsed to extract the template configuration parameter set. The custom identifier template limits the service attributes and hierarchical associations of each segment bit range in the IPv6 address.

[0008] Based on the template configuration parameter set, construct a multi-level identifier association tree model that includes the identifier business meaning, start bit, end bit and parent node association prefix;

[0009] Based on the received business network planning request, generate a set of target business features to be planned;

[0010] The target business feature set is subjected to hierarchical cascading constraint verification by a multi-level identifier association tree model to obtain the set of target identifier nodes that pass the verification.

[0011] Candidate IPv6 addresses are generated based on the start and end bits of each node in the target identifier node set.

[0012] The candidate IPv6 addresses are compared with the pre-set unified address planning ledger to obtain the occupancy status comparison results.

[0013] When the occupancy status comparison result is no occupancy record, assign an available mark to the candidate IPv6 address and generate a target IPv6 address planning scheme.

[0014] This invention employs the aforementioned method to extract configuration parameters by parsing a custom identifier template, constructing a multi-level identifier association tree model, and transforming the 128-bit linear address space into a structured tree topology, thus realizing the digital expression of address planning rules. It filters illegal service requests through hierarchical cascading constraint verification, ensuring the compliance of address service logic. Furthermore, through a closed-loop process of candidate address generation and unified ledger occupancy comparison, it automatically avoids the risk of duplicate allocation. This invention achieves full automation of the IPv6 address process from planning to verification, significantly improving management efficiency and address standardization, reducing the risk of address conflicts in network operation and maintenance, and effectively alleviating the problems of low efficiency and poor standardization in IPv6 address planning and management in related technologies.

[0015] In some implementations, after generating candidate IPv6 addresses based on the start and end bits of each node in the target identifier node set, the method further includes:

[0016] Read the network attribute labels configured for the end nodes from the target identifier node set;

[0017] Determine the corresponding subnet mask length based on the category determination logic of the network attribute label;

[0018] The subnet mask length is increased and added to the candidate IPv6 address to obtain the candidate IPv6 address carrying the subnet mask.

[0019] By adopting the above technical solution, the corresponding subnet mask length is automatically matched by reading the network attribute tags of the end node, realizing intelligent adaptation of the subnet mask. There is no need for manual table lookup configuration, avoiding routing anomalies caused by incorrect mask configuration, and improving the integrity of address configuration and adaptability to different network topologies.

[0020] In some implementations, the occupancy status of candidate IPv6 addresses is compared with a preset unified address planning ledger to obtain the occupancy status comparison results, specifically including:

[0021] Based on the business network planning request, determine the corresponding target bearer network equipment;

[0022] Send a configuration pull command to the target bearer network device to obtain the current actual routing interface configuration information of the target bearer network device;

[0023] The candidate IPv6 addresses are cross-compared in the unified address planning ledger and the actual routing interface configuration information to obtain the tri-state comparison results.

[0024] When the three-state comparison result indicates that there is no record on both the ledger and the actual configuration side, an occupancy status comparison result with no occupancy record is generated.

[0025] By adopting the above technical solution, the data gap between the static ledger and the dynamic live network is eliminated by cross-comparing the candidate IPv6 addresses in the unified address planning ledger and the actual routing interface configuration of the target bearer network device. This avoids discrepancies between the ledger and the actual network caused by unauthorized manual configuration changes and improves the comprehensiveness of address conflict detection.

[0026] In some implementations, after cross-checking the candidate IPv6 addresses in the unified address planning ledger and the actual routing interface configuration information to obtain the tri-state comparison results, the method further includes:

[0027] When the tri-state comparison result indicates that there is no record in the ledger, but there is a record in the actual routing interface configuration information, the candidate IPv6 address will be marked as unregistered and occupied.

[0028] Based on the unregistered occupancy status, trigger an intra-segment offset increment task for the terminal device sequence number node in the target identifier node set;

[0029] Perform the segment offset increment task to obtain the new available sequence number identifier value;

[0030] Replace the original sequence number field data in the candidate IPv6 address with the new available sequence number identifier value to obtain the updated candidate IPv6 address.

[0031] The updated candidate IPv6 addresses are used as the cross-comparison objects and fed back into the cross-comparison step to perform recursive verification.

[0032] By adopting the above technical solution, for abnormal scenarios where there is no record in the ledger but the actual configuration is occupied, the unregistered occupation status is automatically marked and an intra-segment offset increment task is triggered. A legal alternative address is obtained through recursive verification without manual intervention, thereby enhancing the fault tolerance and continuity of the address allocation process.

[0033] In some implementations, an intra-segment offset increment task is performed to obtain a new available sequence number identifier value, specifically including:

[0034] Determine the sequence number segment boundary based on the start and end bits corresponding to the sequence number node of the end device.

[0035] Based on the segment boundaries of the sequence number bits, generate an intra-segment extraction mask to isolate the high-order parent identifier data;

[0036] By extracting the mask within the segment and performing a bitwise AND operation on the candidate IPv6 address, the current sequence number binary value is obtained;

[0037] Within the length interval formed by the boundaries of the sequence number bit segment, perform a single-step addition operation on the current sequence number binary value to obtain an incrementing binary value;

[0038] The overflow check result is obtained by verifying whether the incremental binary value crosses the boundary based on the segment extraction mask;

[0039] If the overflow check result is no overflow, the incrementing binary value is determined as the new available sequence number identifier value.

[0040] By adopting the above technical solution, the sequence number increment operation within the segment is accurately executed through sequence number segment boundary marking, segment extraction mask isolation, and cross-boundary overflow verification, preventing operation overflow from damaging the upper-level parent identification data and ensuring the legality of the address structure and the stability of network routing.

[0041] In some implementations, a multi-level identifier association tree model is used to perform hierarchical cascading constraint verification on the target business feature set to obtain a set of target identifier nodes that pass the verification, specifically including:

[0042] Extract the current level feature items and the previous level feature items from the target service feature set in descending order of network hierarchy.

[0043] Determine whether the first identifier node corresponding to the current level feature item in the multi-level identifier association tree model contains a parent node association prefix pointing to the second identifier node corresponding to the previous level feature item;

[0044] When all hierarchical feature items satisfy the parent node association prefix matching judgment, all extracted identifier nodes are aggregated to generate the target identifier node set.

[0045] By adopting the above technical solution, the matching of the parent node association prefix is ​​verified from high to low according to the network hierarchy, the hierarchical subordinate logic of business characteristics is strictly verified, illegal requests that do not conform to the topology rules are accurately blocked, and invalid addresses that conflict with business logic are avoided from the source.

[0046] In some implementations, candidate IPv6 addresses are generated based on the start and end bits of each node in the target identifier node set, specifically including:

[0047] Initialize a 128-bit binary container with all data bits set to zero;

[0048] Write a fixed unified routing prefix value to the most significant bit of the initialized 128-bit binary container;

[0049] According to the start bit and end bit of each node in the target identifier node set, the binary value of the business identifier corresponding to each node is sequentially embedded into the corresponding bit segment range of the 128-bit binary container;

[0050] Based on the data of the 128-bit binary container after all business identifier binary values ​​have been embedded, candidate IPv6 addresses are generated.

[0051] By adopting the above technical solution, a candidate address is generated by accurately embedding the global routing prefix and service identifier according to the bit range by initializing a 128-bit all-zero binary container, replacing manual conversion and string concatenation, eliminating the risk of human calculation misalignment, and improving the efficiency and accuracy of address generation.

[0052] In a second aspect, the present invention provides an IP address management device, comprising: one or more processors and a memory; the memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, wherein the one or more processors invoke the computer instructions to cause the IP address management device to perform the method as described in the first aspect and any possible implementation thereof.

[0053] Thirdly, the present invention provides a computer-readable storage medium storing computer instructions that, when executed on an IP address management device, cause the IP address management device to perform the method described in the first aspect and any possible implementation thereof.

[0054] Fourthly, the present invention provides a computer program product including computer instructions that, when executed on an IP address management device, cause the IP address management device to perform the method described in the first aspect and any possible implementation thereof.

[0055] Understandably, the IP address management device provided in the second aspect, the storage medium provided in the third aspect, and the computer program product provided in the fourth aspect are all used to execute the method provided by this invention. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here. Attached Figure Description

[0056] Figure 1 This is a flowchart illustrating an IPv6 address planning and management method based on a custom identifier template according to an embodiment of the present invention.

[0057] Figure 2 This is a schematic diagram of the electronic device hardware architecture of an IP address management device according to an embodiment of the present invention. Detailed Implementation

[0058] The terminology used in the following embodiments of the present invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used in the specification and appended claims of the present invention, the singular expressions “a,” “an,” “the,” “the,” “the,” and “this” are intended to include the plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in the present invention refers to any or all possible combinations comprising one or more of the listed items.

[0059] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of the present invention, unless otherwise stated, "a plurality of" means two or more.

[0060] This embodiment provides an IPv6 address planning and management method based on a custom identifier template. The execution entity of this method is an IP address management device. An IP address management device refers to a computer backend service device with data processing, network communication, and data storage capabilities. The IP address management device is responsible for coordinating network address allocation calculations across the entire network environment. The following describes... Figure 1 The method provided in this embodiment will be described in detail, specifically including the following steps:

[0061] S101, parse the received custom identifier template to extract the template configuration parameter set.

[0062] In this embodiment, the IP address management device first receives a custom identifier template input from an external source through a network data interface. The custom identifier template is a pre-defined data file used to define the address structure partitioning logic. It defines the service attributes and hierarchical relationships of each segment bit range in the IPv6 address.

[0063] Since IPv6 addresses are 128 bits long, network administrators would find it difficult to manage them effectively without proper structured partitioning. Therefore, a custom identifier template divides the 128-bit address space into multiple segmented bit ranges. Each segmented bit range corresponds to a specific network service meaning.

[0064] After receiving a custom identifier template, the IP address management device reads and parses the template. Through parsing, the device extracts a template configuration parameter set. This set contains all the basic settings required to partition the address space. The service attributes within the parameter set indicate the service type represented by a specific bit range; for example, a service attribute could represent a network type, an organization, or a device level. The hierarchical relationships within the parameter set represent the hierarchical logic between different segmented bit ranges. For instance, an organization segmented bit range must be subordinate to a network type segmented bit range.

[0065] The IP address management device temporarily stores the extracted template configuration parameter set in an in-memory database for later use in building a tree-like association model. By parsing the custom identifier template, the IP address management device can obtain standardized segmentation rules for complex long addresses, laying the foundation for subsequent automated data processing.

[0066] S102, Based on the template configuration parameter set, construct a multi-level identifier association tree model that includes the identifier business meaning, start bit, end bit, and parent node association prefix.

[0067] This step is the foundational preparation step for address automation planning.

[0068] The IP address management device retrieves the previously extracted template configuration parameter set from the memory database and iterates through each parameter record in the template configuration parameter set. According to the hierarchical logical relationship indicated by the parameter records, the IP address management device dynamically instantiates a tree-like data structure in system memory. The multi-level identifier association tree model refers to a method that transforms a linear 128-bit address space into a non-linear tree-like topology data structure with hierarchical dependencies.

[0069] During the construction of the multi-level identifier association tree model, the IP address management device creates an independent identifier node for each divided bit range. For each created identifier node, the identifier service meaning, start bit, end bit, and parent node association prefix are written into the corresponding identifier node.

[0070] The business meaning of an identifier refers to the specific business domain information represented by a particular identifier node. The start and end bits together define the specific position and length occupied by a particular identifier node within a total 128-bit binary address. For example, if the start bit of an identifier node is the 9th bit and the end bit is the 11th bit, then the start and end bits indicate that the specific identifier node occupies 3 binary bits. The parent node association prefix is ​​the core link reflecting hierarchical dependencies in a multi-level identifier association tree model. The parent node association prefix records the numerical characteristics of which parent identifier node the currently established identifier node must logically depend on.

[0071] If the parent node association prefix recorded by a lower-level identifier node matches the identifier service meaning and corresponding encoding value of a certain upper-level identifier node, the IP address management device establishes a directed connection between the lower-level identifier node and the upper-level identifier node. Through continuous traversal instantiation and connection operations, the IP address management device ultimately transforms the flat and scattered template configuration parameter set into a multi-level identifier association tree model with a rigorous logical structure.

[0072] The top layer of a multi-level identifier association tree model is typically a globally unified routing prefix node. The middle layers consist of organizational structure nodes or service type nodes, while the bottom leaf layer is usually a specific network device serial number node. The multi-level identifier association tree model uses a tree structure to structurally solidify the originally complex business dependency rules.

[0073] After constructing a multi-level identifier association tree model, the IP address management device obtains a set of reference criteria for subsequent legality verification of newly applied addresses.

[0074] S103, Based on the received service network planning request, generate a set of target service features to be planned.

[0075] In actual business scenarios involving network deployment or device deployment, front-end interactive systems or third-party network management systems send business network planning requests to IP address management devices. A business network planning request is a signal data packet that triggers an automatic allocation calculation process. The request carries various background information about the network device requesting an address. For example, it may include natural language descriptions or service numbers such as the organization name, data center location, and gateway attributes of the network device.

[0076] After receiving a service network planning request, the IP address management device invokes its built-in parameter formatting module. This module extracts, cleans, and standardizes non-standardized text data or disorganized parameter fields in the request. The IP address management device then aggregates and combines the cleaned and transformed multi-dimensional service parameters to generate a set of target service characteristics to be planned.

[0077] The set of target service features to be planned is a standardized key-value pair data format. Each key-value pair reflects a service dimension requirement that the network device requesting address allocation must meet. The set of target service features to be planned clarifies the specific constraints of the current allocation task. The IP address management device passes the generated set of target service features to the subsequent verification and calculation module.

[0078] S104. The target business feature set is subjected to hierarchical cascading constraint verification through a multi-level identifier association tree model to obtain the target identifier node set that passes the verification.

[0079] This step is crucial in avoiding the generation of invalid addresses and logically conflicting addresses.

[0080] After obtaining the target service feature set, the IP address management device needs to verify whether the feature items in the target service feature set conform to the pre-set service rules. The IP address management device retrieves the multi-level identifier association tree model constructed in step S102. Hierarchical cascading constraint verification refers to comparing the service requirements in the target service feature set with the fixed hierarchical relationships in the multi-level identifier association tree model in a sequence from macro to micro or from upper level to lower level to see if they are consistent.

[0081] The IP address management device starts from the root node of the multi-level identifier association tree model and searches for the first-level service feature item corresponding to the root node in the target service feature set. If a corresponding first-level service feature item is found, it continues to traverse the next-level node along the edges of the multi-level identifier association tree model. For each addressed lower-level node, the IP address management device checks the parent node association prefix stored in the lower-level node. It compares whether the parent node association prefix stored in the lower-level node matches the previous-level service feature item extracted from the target service feature set.

[0082] If the two match, it indicates that the business logic of the target business feature set at the current level is reasonable. The IP address management device records the verified lower-level node as a valid node. If the parent node association prefix stored in the lower-level node does not match the upper-level business feature item in the target business feature set, it indicates that there is a logical error in the business network planning request. For example, if the business network planning request requires the allocation of a gateway address under an organization that does not have gateway services, the hierarchical cascading constraint verification will fail. The IP address management device will return an error message for the failed verification request and terminate the current process.

[0083] Once the IP address management device has successfully traversed all levels involved in the target service feature set and all parent node association prefixes have been successfully matched, the IP address management device will package and summarize all valid nodes recorded on the traversed path. The IP address management device will then output the packaged and summarized valid nodes as a whole, thus obtaining the target identifier node set that has passed the verification. Each node in the target identifier node set has a valid dependency path in the multi-level identifier association tree model.

[0084] The set of target identifier nodes obtained through hierarchical cascading constraint verification can ensure that the subsequently generated candidate IPv6 addresses are standardized and reasonable in terms of business logic.

[0085] S105, Generate candidate IPv6 addresses based on the start and end bits of each node in the target identifier node set.

[0086] Among them, a candidate IPv6 address refers to a temporary address string that meets the business logic, obtained through preliminary data concatenation operations. The candidate IPv6 addresses have not yet undergone deduplication checks to verify their occupancy status, but they have already met the allocation standards in terms of format and identifier composition.

[0087] When generating candidate IPv6 addresses, the IP address management device first initializes a 128-bit all-zero binary value in memory as a concatenation base. Then, it iterates through the previously output set of target identifier nodes. This set contains multiple node data points carrying specific location information.

[0088] For each identifier node in the target identifier node set, the IP address management device reads the start and end bits recorded inside the identifier node. The IP address management device then converts the specific service code value corresponding to the identifier node into a binary bit stream.

[0089] The IP address management device precisely locates the corresponding segment in the all-zero binary value baseboard based on the read start and end bits. The device then precisely fills or overwrites the corresponding segment in the all-zero binary value baseboard with the converted binary bit stream. For example, if an identifier node representing a railway area has a start bit of 21 and an end bit of 25, and the corresponding business code value occupies 5 bits in binary, the IP address management device will write this 5-bit binary data between bits 21 and 25 in the all-zero binary value baseboard.

[0090] The IP address management device processes all identifier nodes in the target identifier node set one by one according to the extraction, conversion, and filling methods described above. Once all identifier nodes in the target identifier node set have been processed, the splicing baseboard, which was originally in a state of all zeros, is filled with binary data segments representing different service meanings. For bit ranges not covered by service identifier nodes, the IP address management device keeps the zero values ​​of these bit ranges unchanged.

[0091] Finally, the IP address management device will perform format conversion on the completed 128-bit binary data, converting every 4 bits of the 128-bit binary data into a hexadecimal character, and adding a colon separator every 4 hexadecimal characters, thereby generating a candidate IPv6 address that conforms to the standard network communication protocol specification.

[0092] By generating candidate IPv6 addresses through concatenation of start and end bits, IP address management devices use automated algorithms to replace traditional manual identification and string concatenation, improving the computational efficiency of address generation and eliminating the risk of human error in calculation.

[0093] S106, compare the occupancy status of the candidate IPv6 addresses with the preset unified address planning ledger to obtain the occupancy status comparison result.

[0094] In this step, after the IP address management device generates candidate IPv6 addresses, it needs to confirm whether these addresses are already occupied by other network devices. Blindly allocating already occupied addresses can lead to address conflicts. The unified address planning ledger is a global data table deployed in the underlying database of the IP address management device. It records information on all successfully allocated and active addresses from previous periods, along with their corresponding occupancy status.

[0095] The IP address management device extracts the previously generated candidate IPv6 addresses. Using a database query, the candidate IPv6 addresses are input as query keywords into the unified address planning ledger for a full table search. Then, the candidate IPv6 addresses are verified and compared character by character with the existing address fields in the unified address planning ledger.

[0096] The occupancy status comparison result refers to the existence determination feedback information output by the system after querying the database. If a record with the same value as the candidate IPv6 address is found in the unified address planning ledger, the IP address management device determines that the occupancy status comparison result is that the record is occupied. If no record with the same value as the candidate IPv6 address is found after traversing the entire unified address planning ledger, the occupancy status comparison result is determined to be that the record is not occupied.

[0097] By comparing the occupancy status of candidate IPv6 addresses with the unified address planning ledger, a preliminary screening of address conflicts was completed at the system level.

[0098] S107. When the occupancy status comparison result is no occupancy record, assign an available mark to the candidate IPv6 address and generate a target IPv6 address planning scheme.

[0099] Specifically, when the IP address management device receives a status comparison result indicating no occupied record, it confirms that the current candidate IPv6 address is unallocated. The IP address management device then modifies the status attribute field of the current candidate IPv6 address in its memory structure to an available status. Assigning an available flag means, logically, locking the candidate IPv6 address that has passed all verification and deduplication steps as the legitimate result of this allocation task.

[0100] The IP address management device extracts candidate IPv6 addresses with availability tags and associates and packages these candidate IPv6 addresses with the basic device information from the initial service network planning request. Finally, based on the associated packaged data structure, a structured data body containing device attributes and allocated address information is generated, thus obtaining the final target IPv6 address planning scheme.

[0101] The target IPv6 address planning scheme is a structured data file containing device attributes and allocated address information. The target IPv6 address planning scheme can be directly output to network administrators for review and approval, or it can be directly distributed to the automated network configuration module and automatically pushed to the corresponding physical network devices.

[0102] For example, taking a newly added service router in a railway bureau's computer room as an example, when a candidate IPv6 address is calculated by piecing together the various service attributes of this router, and it is verified in the unified address planning ledger that the candidate IPv6 address has no occupied record, the IP address management device will assign an available mark to the candidate IPv6 address. Then, this candidate IPv6 address with the available mark will be associated and bound with the basic equipment information such as the organization name, computer room location, and equipment model contained in the initial service network planning request. Finally, a structured data record that clearly states which service layer node the service router belongs to and which legal IPv6 address it is specifically assigned to will be generated and output. This data entity that integrates the basic information of the network equipment and the network logical address is the final generated target IPv6 address planning scheme.

[0103] By assigning usable tags to candidate IPv6 addresses and generating target IPv6 address planning schemes, the IP address management device achieves an automated closed-loop process from receiving applications to generating compliant and legal allocation results, improving the implementation efficiency of address planning and the data accuracy of address resources.

[0104] This embodiment uses the above method to divide the huge and complex 128-bit IPv6 address space into structured and business-coherent data nodes by parsing the custom identifier template and constructing a multi-level identifier association tree model. This realizes the customizability and digital expression of address planning rules, effectively solving the technical problems of traditional manual calculation based on experience being prone to errors and inefficient.

[0105] Upon receiving a business network planning request, the IP address management device uses a multi-level identifier association tree model to perform hierarchical cascading constraint verification on the target business feature set. This verification mechanism can automatically and accurately filter out illegal request configurations that do not conform to the business hierarchy logic, ensuring that the subsequently generated candidate IPv6 addresses have extremely high standardization and accuracy in terms of business affiliation and network topology.

[0106] In addition, the IP address management device compares the generated candidate IPv6 addresses with the unified address planning ledger to check their occupancy status. Only when there is no occupancy record is the device marked as available and generates the target IPv6 address planning scheme. This closed-loop deduplication mechanism directly eliminates the risk of duplicate address allocation at the system level, effectively reduces the risk of address conflicts during network operation and maintenance, and improves the automation level and management quality of the entire process of IPv6 address planning, generation, verification and distribution in large-scale network environments.

[0107] This embodiment also provides a more specific method for IPv6 address planning and management, including the following steps:

[0108] S201, parse the received custom identifier template to extract the template configuration parameter set.

[0109] S202, based on the template configuration parameter set, construct a multi-level identifier association tree model that includes the identifier business meaning, start bit, end bit, and parent node association prefix.

[0110] S203, Based on the received service network planning request, generate a set of target service features to be planned.

[0111] Steps 201-203 can be explained with reference to the descriptions in the previous embodiments, and will not be repeated here.

[0112] S204. Extract the current level feature items and the previous level feature items from the target service feature set in descending order of network hierarchy.

[0113] In this embodiment, after the IP address management device has completed the generation of the target service feature set, it needs to perform a structured hierarchical traversal of the extracted service features.

[0114] Here, the current-level feature term refers to the business attribute field that is being examined in a logical comparison loop and is located in a lower-level network structure. The previous-level feature term refers to the business attribute field that is logically adjacent to the current level and is located in a higher-level network structure.

[0115] Because network planning often presents a tree-like topology—for example, network types include organizations, and organizations include equipment lines and stations—this inclusion relationship determines a strict sequential dependency between feature items. The IP address management device incorporates a hierarchical depth-first traversal algorithm, starting with feature items representing the most macroscopic network category and gradually progressing to the lower-level microscopic device hierarchy. During each step, the IP address management device simultaneously reads the current-level feature item and its adjacent previous-level feature item from the memory structure of the target service feature set.

[0116] By simultaneously extracting these two logically related feature items, the IP address management device provides a data foundation for subsequent checks on whether there are contradictions between various network dimensions in the business network planning request.

[0117] S205, determine whether the first identifier node corresponding to the current level feature item in the multi-level identifier association tree model contains a parent node association prefix pointing to the second identifier node corresponding to the previous level feature item.

[0118] This step is the core logic for hierarchical cascading constraint verification. The first identifier node refers to the tree node object in the multi-level identifier association tree model that represents the specific network attributes of the feature item at the current level. The second identifier node refers to the parent tree node object in the multi-level identifier association tree model that represents the network attributes of the feature item at the previous level.

[0119] After locating the first identifier node in the memory database, the IP address management device reads the parent node association prefix field recorded within the first identifier node. The device then matches this parent node association prefix field with the unique identifier of the second identifier node. If the parent node association prefix field and the unique identifier of the second identifier node are completely identical, it indicates that the current-level feature item indeed belongs to the previous-level feature item, and the business logic between them is legal and consistent. If the match fails, it indicates that the business network planning request contains an error, such as incorrectly attaching the computer room address of a certain site to another unrelated railway line network type.

[0120] IP address management devices effectively intercept non-compliant network layer configurations by comparing node attributes.

[0121] S206, when all hierarchical feature items satisfy the parent node association prefix matching judgment, all extracted identifier nodes are summarized to generate the target identifier node set.

[0122] In this embodiment, the IP address management device needs to conduct a comprehensive security review of all hierarchical relationships involved in the business network planning request.

[0123] The IP address management device repeatedly performs the feature extraction and matching judgment operation with the parent node's associated prefix until every pair of adjacent feature items from the highest to the lowest level in the target service feature set has undergone strict verification and comparison. Only when the entire hierarchical path from top to bottom is unobstructed in the multi-level identifier association tree model, that is, when all the cascading relationships between all hierarchical feature items are valid, will the IP address management device determine that the address planning request is valid.

[0124] At this point, the IP address management device encapsulates the data of the first and second identifier nodes traversed along the verification path. The IP address management device then stores these verified and compliant tree node objects into a contiguous memory space, thus forming the target identifier node set.

[0125] The target identifier node set became the direct data source for the subsequent automated generation of IPv6 address strings, ensuring that the addresses to be generated strictly comply with the enterprise's network management specifications.

[0126] S207 initializes a 128-bit binary container with all data bits set to zero.

[0127] Among them, a 128-bit binary container refers to a data storage array in memory allocated by an IP address management device with a length of exactly 128 bits.

[0128] Since an IPv6 address is essentially a 128-bit binary number, the IP address management device needs a clean data base before it can begin constructing and generating a specific address. The IP address management device calls the system's underlying memory allocation functions to request a contiguous block of storage space from the operating system.

[0129] IP address management devices use overwrite instructions to force every bit in this contiguous storage space to a value of zero.

[0130] The 128-bit binary container, after being cleared, effectively avoids interference from residual random garbage data in memory on address generation calculations. This 128-bit binary container, in its all-zero state, is like a blank canvas, waiting for the IP address management device to fill in the identification data of each business dimension according to precise location coordinates.

[0131] S208 writes a fixed unified routing prefix value to the most significant bit of the initialized 128-bit binary container.

[0132] The unified routing prefix value refers to the basic network prefix data uniformly allocated by the Internet Corporation for Assigned Numbers (ICANN) or the backbone network planning department of large enterprises, used to identify the enterprise's public network exit or internal regional network boundary. The unified routing prefix value is the foundation of the entire network address.

[0133] The IP address management device reads the unified routing prefix value from the global configuration database and converts it into binary format. The device locates the leftmost, or most significant, bit of the 128-bit binary container. It then performs a bitwise copy operation, overwriting each bit of the binary data of the unified routing prefix value into the most significant bit range of the 128-bit binary container. For example, if an enterprise is assigned the hexadecimal value FD00, the device will write the corresponding binary sequence into the first 16 bits of the 128-bit binary container. This ensures that the generated address can be correctly identified and addressed in the macro-routing protocol, guaranteeing the correct routing of network traffic.

[0134] S209, according to the start bit and end bit of each node in the target identifier node set, the binary value of the business identifier corresponding to each node is sequentially embedded into the corresponding bit segment range of the 128-bit binary container.

[0135] This step is a key processing step for automating the assembly of long addresses based on a custom identifier template.

[0136] Among them, the binary value of the service identifier refers to the pure binary value obtained by encoding specific network characteristics such as network type, service type or device level through a number system conversion.

[0137] A bit segment interval refers to a continuous position of a specific length defined by the start bit and the end bit within a total length of 128 bits.

[0138] The IP address management device extracts node data from the target identifier node set and initiates a traversal loop. For each identifier node, it first reads the node's value and converts it into a service identifier binary value. Then, it reads the predefined start and end bits from the node. The IP address management device calls the processor's shift register and uses a left shift operation to shift the service identifier binary value to a precise spatial position aligned with the start bit.

[0139] Next, the IP address management device uses a bitwise OR operation to overlay the shifted and aligned binary value of the service identifier into the bit range of the 128-bit binary container. Since each identifier node has non-overlapping start and end bits defined in the custom identifier template, this bitwise OR operation will not destroy other bit range data that has already been written.

[0140] Through this precise bit-level data embedding operation, IP address management devices accurately concatenate previously isolated network layer features into a unified data structure. This automatic embedding method based on bit ranges replaces the tedious work of traditional maintenance personnel manually converting hexadecimal strings with calculators, improving the computational efficiency and absolute accuracy of address generation.

[0141] S210 generates candidate IPv6 addresses based on the data of the 128-bit binary container after all service identifier binary values ​​have been embedded.

[0142] In this embodiment, after all node data in the target identifier node set is embedded into a 128-bit binary container, the container, which was originally all zeros, now contains the unified routing prefix value and binary information of various service segments. Bit ranges that have not been assigned service meanings continue to remain at zero values.

[0143] The IP address management device performs a formatting conversion operation on the assembled 128-bit binary container. Following standard Internet protocol requirements, the device divides the 128-bit binary data into eight 16-bit blocks. Each 16-bit block is then converted into a four-digit hexadecimal character sequence.

[0144] The IP address management device then inserts standard colon separators between adjacent hexadecimal character sequences. If consecutive blocks of all zeros appear during the conversion, the IP address management device also performs a double-colon zero compression algorithm to reduce the address length.

[0145] After complete character conversion and format compression, the IP address management device converts the underlying binary container content into a human-readable hexadecimal string that conforms to standard network communication syntax. This string is the candidate IPv6 address, serving as the basis for subsequent deduplication verification.

[0146] S211, Read the network attribute labels configured for the end nodes from the target identifier node set.

[0147] This step provides a basis for subsequent intelligent adaptation of the network mask.

[0148] Among them, the end node refers to the lowest level of the target identifier node set, which usually represents a specific physical equipment room or a virtualized business gateway.

[0149] Network attribute tags are identifiers that administrators attach to specific nodes when configuring custom identifier templates to describe the network topology characteristics of the node.

[0150] Because different network topologies require different network boundary delineation methods, IP address management devices cannot use a one-size-fits-all mask configuration for all addresses. The IP address management device performs a deep search of the target identifier node set to locate the end node without any child nodes. The device then extracts the network attribute tag field from the memory attribute structure of this end node. By reading the network attribute tag, the IP address management device can determine whether the address being planned is for ordinary local area network communication or for point-to-point direct communication between two core routers.

[0151] S212, determine the corresponding subnet mask length based on the category determination logic of the network attribute label.

[0152] The network attribute label category determination logic refers to a set of mask rule matching engines pre-installed within the IP address management device. The subnet mask length is a numerical identifier used to indicate the boundary between network and host bits in an IPv6 address.

[0153] The IP address management device inputs the network attribute label read in the previous step into the category determination logic of the network attribute label for processing. The IP address management device performs matching calculations according to the preset determination branches. For example, when the network attribute label indicates that the current node belongs to the management address of the network device, the category determination logic of the network attribute label will determine that the address belongs to the loopback test interface of the device, thereby determining that the corresponding subnet mask length is 128 bits.

[0154] When the network attribute label indicates that the current node belongs to the interconnection interface service, the network attribute label category determination logic will determine that the address belongs to the point-to-point link topology, thereby determining that the corresponding subnet mask length is 127 bits.

[0155] When the network attribute label indicates that the current node belongs to the ordinary terminal gateway access service, the network attribute label category determination logic determines that the corresponding subnet mask length is 64 bits.

[0156] IP address management devices achieve automated deduction of mask parameters through category determination logic, eliminating the cumbersome process of manual table lookup.

[0157] S213, add the subnet mask length to the candidate IPv6 address to obtain the candidate IPv6 address carrying the subnet mask.

[0158] In this embodiment, after determining the main string of the candidate IPv6 address and the corresponding subnet mask length, the IP address management device needs to combine the two into a standard classless inter-domain routing format.

[0159] The IP address management device reads the text string of candidate IPv6 addresses from memory. It then adds a forward slash character as a separator to the end of the candidate IPv6 address string. The calculated subnet mask length is then converted to decimal text numbers and appended to the forward slash ( / ). Through this string concatenation operation, the IP address management device generates a complete address data structure, such as one with a / 64 or / 128 suffix.

[0160] The candidate IPv6 address carrying the subnet mask not only contains the unicast addressing information of the network device, but also strictly defines the broadcast domain range in which the address belongs, providing complete network prefix parameters for the routing table subsequently sent to the routing device.

[0161] S214, Based on the service network planning request, determine the corresponding target bearer network device.

[0162] In this embodiment, in order to ensure that the generated address does not actually conflict with the devices running on the network, the IP address management device needs to lock the specific physical or virtual verification object.

[0163] The target network device refers to the physical router or switch that will be configured with this new planned address in a real physical computer room or cloud computing resource pool.

[0164] The IP address management device extracts natural language description fields such as device name, device number, or data center location from the business network planning request. These fields are then used as query keywords to perform a relational mapping query in the asset management database. The asset management database stores management access information for all network devices across the entire network.

[0165] Through comparison and matching, the IP address management device accurately locates the target bearer network device that perfectly corresponds to the business network planning request from among numerous network devices. The IP address management device extracts the out-of-band management address protocol port number and security authentication credentials of the target bearer network device, preparing for the next step of proactively establishing a network communication connection.

[0166] S215, send a configuration pull command to the target bearer network device to obtain the current actual routing interface configuration information of the target bearer network device.

[0167] This step is the core operation for eliminating the data gap between static ledgers and dynamic live networks.

[0168] The configuration retrieval command refers to a data packet sent to the managed device via the network control protocol, requesting the device to return its current operating status parameters. The actual routing interface configuration information refers to the running configuration file currently in effect in the network device's memory, containing information on the occupancy of all interface addresses.

[0169] IP address management devices use pre-determined security authentication credentials to establish encrypted communication tunnels with the target network device via Secure Shell Protocol or Network Configuration Protocol.

[0170] After the connection is established, the IP address management device sends a configuration retrieval command through an encrypted communication tunnel. Upon receiving the configuration retrieval command, the control plane of the target bearer network device packages the IPv6 address information currently in use on its various service interfaces, loopback interfaces, and interconnect interfaces, and sends it back to the IP address management device.

[0171] After receiving the raw text packet returned by the device, the IP address management device starts the regular expression parsing engine. The regular expression parsing engine extracts all running IPv6 address strings from the lengthy and complex underlying code of the network device. These extracted running IPv6 address strings constitute the actual routing interface configuration information.

[0172] By proactively retrieving actual routing interface configuration information from network devices, the IP address management device gains a true and real-time understanding of the device's address consumption status, effectively compensating for the lag and distortion of ledger data caused by unauthorized modifications to device configurations.

[0173] S216. The candidate IPv6 addresses are cross-compared in the unified address planning ledger and the actual routing interface configuration information to obtain the tri-state comparison results.

[0174] Cross-checking refers to the process of placing the temporary address to be allocated into two data sources of different dimensions for double deduplication verification. The tri-state comparison result refers to the feedback of three different security levels of occupancy status derived from the existence of the ledger database source and the actual device configuration source.

[0175] The IP address management device starts a parallel search engine, submitting candidate IPv6 addresses as keywords to the backend unified address planning ledger database query interface and the memory list of actual routing interface configuration information obtained from frontend parsing.

[0176] The IP address management device waits for both ends to return query matching results simultaneously. If both ends report that the address was not found, it means that the address is secure and available.

[0177] If the unified address planning ledger database indicates that the address already exists, regardless of whether it has been configured on the device, it means that the address has already been planned out by the previous process, which is a conflict situation.

[0178] If the unified address planning ledger database does not report that the address is missing, but the same address is found in the actual routing interface configuration information list, it indicates that there is a blind spot in the data due to manual violations.

[0179] The IP address management device logically summarizes the independent feedback from both ends and outputs a three-state comparison result that accurately reflects the actual address occupancy status based on the preset state machine, providing an authoritative basis for subsequent processing.

[0180] S217 When the three-state comparison result indicates that there is no record on both the ledger and the actual configuration side, generate an occupancy status comparison result with no occupancy record.

[0181] This step represents a relatively ideal and smooth branch path in the address planning process.

[0182] When the IP address management device analyzes the tri-state comparison results, if it finds that the ledger database query interface returns an empty set, and no matching string element is found in the actual routing interface configuration information memory list, this indicates that the candidate IPv6 address is not only an unallocated blank asset at the company's rules and approval process management level, but also has not been privately occupied by any engineer at the actual operational level of the physical network environment. The data at both ends maintains a high degree of purity and consistency.

[0183] Upon receiving a double-sided, double-no verification signal, the IP address management device activates the system's security clearance logic. The device then generates a comparison result indicating no occupancy record. This comparison result is equivalent to issuing a pass, directly declaring that the candidate IPv6 address has passed all security checks and conflict verifications and can directly proceed to the final usability label assignment stage.

[0184] S218. When the tri-state comparison result indicates that there is no record in the ledger, but there is a record in the actual routing interface configuration information, the candidate IPv6 address is marked as unregistered and occupied.

[0185] This step is a fault-tolerance and adaptive mechanism designed to cope with complex live network operation and maintenance environments. The "unregistered occupied state" refers to an abnormal state where the network address appears available at the management system level, but is actually occupied at the physical device level.

[0186] In actual network operation and maintenance, it often happens that network engineers, in order to quickly repair faults, manually configure an IPv6 address by logging into the device command line, but then forget to register it in the unified address planning ledger afterwards. If the IP address management device relies solely on the ledger for allocation, it will assign this already-in-use address to a new service, leading to a serious dual-address allocation fault in the network.

[0187] When the IP address management device detects a conflict signal—where the ledger query shows no record but the device's configuration return contains the candidate IPv6 address—through cross-comparison, the IP address management device triggers exception handling logic. The IP address management device updates the internal identifier of the candidate IPv6 address to an unregistered and occupied state.

[0188] Marking the address as unregistered allows the system to avoid immediate network conflict risks while also recording such discrepancies between the registered address and the actual address, triggering subsequent adaptive address offset calculations.

[0189] S219, based on the unregistered occupancy status, triggers an intra-segment offset increment task for the end device sequence number node in the target identifier node set.

[0190] In this embodiment, when a candidate IPv6 address is flagged as unregistered and occupied, the IP address management device needs to find a replacement address that also belongs to the current service network.

[0191] Among them, the terminal device sequence number node refers to the last numerical identifier in the target identification node set, specifically used to distinguish different physical hosts at the same level. The intra-segment offset increment task refers to a sequence of instructions that performs single-step addition operations on the host portion of the data to find the next free address without changing the higher-level network routing prefix.

[0192] The IP address management device extracts the target identifier node set. The IP address management device then locks the data block representing the sequence number of the end device within the set. This is because, in cases of unauthorized access, similar services typically need to be planned within the same subnet segment. Arbitrarily changing network types or higher-level nodes such as organizational structures can lead to routing failures.

[0193] Therefore, the IP address management device issues an instruction requiring the system to start an offset incrementing task within the segment, and the command calculation engine only performs numerical recursion evolution for the interval where the end device sequence number node is located.

[0194] S220, execute the segment offset increment task to obtain a new available sequence number identifier value.

[0195] The new available sequence number identifier value refers to the untried end host number data that has undergone mathematical calculations and passed the boundary validity check.

[0196] After receiving the intra-segment offset increment task, the arithmetic logic unit inside the IP address management device begins executing low-level operations. First, it reads the current binary value of the end device sequence number node from the target identifier node set. The IP address management device then performs an increment calculation on this binary value. To prevent data overflow caused by the addition operation from corrupting adjacent high-order service identifier intervals, the IP address management device establishes a virtual calculation boundary based on the preset start and end bits of the end device sequence number node.

[0197] For example, if the sequence number node of the end device is limited to a length of only ten bits, then the result of the increment operation must never exceed the maximum value that ten bits can represent.

[0198] The IP address management device verifies whether the result of adding one to the binary number exceeds the calculation boundary. If it does not exceed the boundary, the valid addition result is recognized as the new available sequence number identifier. If it exceeds the boundary, it indicates that the address resources within the current subnet are exhausted, and the IP address management device will send a resource exhaustion alarm message to the upper layer and terminate the process.

[0199] By executing an intra-segment offset increment task, the system can autonomously correct errors when it encounters addresses that are secretly occupied, and intelligently explore available resources by extending the offset forward.

[0200] S221, replace the original sequence number field data in the candidate IPv6 address with the new available sequence number identifier value to obtain the updated candidate IPv6 address.

[0201] The sequence number segment data refers to the old values ​​written into the corresponding end node positions of the 128-bit binary container during the previous concatenation process. The updated candidate IPv6 address refers to a completely new long string of addresses to be verified, formed by replacing some of the last digits.

[0202] The IP address management device retrieves the 128-bit binary container corresponding to the previously constructed candidate IPv6 addresses. Based on the start and end bits of the end device sequence number node, it precisely locates the memory space containing the old sequence number segment data that caused the conflict. The IP address management device then uses a bit-zero mask operation to erase and reset the data in this memory space.

[0203] Subsequently, the IP address management device precisely writes the new available sequence number identifier value calculated in the previous step into the empty space that was just erased through a bitwise OR operation. After this minor data replacement, the high-level service routing prefix in the entire 128-bit binary container remains unchanged; only the last few bits of the host number have changed.

[0204] The IP address management device reformatts the modified 128-bit binary container to output updated candidate IPv6 addresses.

[0205] S222, the updated candidate IPv6 address is used as the cross-comparison object and fed back to the cross-comparison step to perform recursive verification.

[0206] The cross-comparison targets refer to the data samples that will be sent to the ledger database and the actual equipment configuration information for existence checks. Recursive verification refers to the process of re-importing the new results generated by the algorithm back into the starting point of the verification process for iterative checks until the exit conditions are met.

[0207] After the IP address management device generates an updated candidate IPv6 address, it cannot guarantee that the newly calculated address is absolutely secure. This is because multiple unregistered and illegally occupied addresses may exist simultaneously on the network. Therefore, the IP address management device defines this updated candidate IPv6 address as a new cross-checking target.

[0208] The IP address management device redirects the execution pointer back to the code module containing step S216 via program control flow. The new cross-comparison object will again face dual scrutiny from both the ledger database interface and the device's actual routing interface configuration information list.

[0209] This recursive verification mechanism forms a tight, loop-based defense, ensuring that any addresses that are occupied, whether registered in the ledger or secretly occupied by devices, are recalculated. The recursive verification process only exits the loop when it encounters a clean address with no records on both sides, thus guaranteeing that the final output address scheme has sufficient availability and security.

[0210] S223, when the occupancy status comparison result is no occupancy record, assign an available mark to the candidate IPv6 address and generate a target IPv6 address planning scheme.

[0211] This step can be explained with reference to the description in the previous embodiments, and will not be repeated here.

[0212] In some embodiments, S220 may specifically include the following steps:

[0213] S2201, determine the sequence number segment boundary based on the start bit and end bit corresponding to the sequence number node of the end device.

[0214] In this embodiment, when performing the intra-segment offset increment task, the IP address management device first needs to determine the allowed physical memory range for the increment operation. The sequence number segment boundary refers to the continuous position range reserved specifically for the lowest-level physical host or virtual interface in the candidate IPv6 address with a total length of 128 bits.

[0215] The IP address management device retrieves the data structure of the end device sequence number node, which has already been verified in the multi-level identifier association tree model, from memory. Then, it reads the start bit value and end bit value configured in the end device sequence number node.

[0216] The start bit value represents the leftmost starting point of the sequence number interval within the total 128-bit length. The end bit value represents the rightmost ending point of the sequence number interval within the total 128-bit length.

[0217] IP address management devices define a closed data space by mathematically marking the start and end bit values. By determining the sequence number segment boundaries, the IP address management device establishes a secure operating sandbox. Incremental operations performed within this secure sandbox will not damage other service network prefixes outside the sandbox.

[0218] Determining the boundaries of the sequence number segment provides a strict coordinate reference for subsequent accurate host address extension calculations.

[0219] S2202, Generate an intra-segment extraction mask to isolate high-order parent identifier data based on the segment boundary of the sequence number bit.

[0220] The high-order parent identifier data refers to the macro-level routing prefix information, located to the left of the sequence number segment boundary in candidate IPv6 addresses, representing the network type, organization, or business category. The intra-segment extraction mask is a 128-bit binary auxiliary filter string specifically used for data filtering.

[0221] The IP address management device initializes a 128-bit binary sequence of all zeros in memory. Then, based on the sequence number segment boundaries determined in the previous step, it locates the corresponding interval of the 128-bit binary sequence. The IP address management device sets all bits within the corresponding interval to one, while keeping all other bits outside the interval as zero. This interval-setting operation generates an intra-segment extraction mask. The purpose of generating the intra-segment extraction mask is to utilize the low-level logical operation characteristics of the computer to retain only data segments with corresponding positions set to one during subsequent data extraction. The intra-segment extraction mask is like a filter funnel with precisely calibrated openings. The openings of the filter funnel are precisely aligned with the sequence number segment boundaries of the device.

[0222] By generating an intra-segment extraction mask, IP address management devices can accurately locate and isolate target data units from a large and complex pool of candidate IPv6 addresses, thereby protecting high-level parent identifier data from interference from the underlying computation process.

[0223] S2203: Perform a bitwise AND operation on the candidate IPv6 address by extracting the mask within the segment to obtain the binary value of the current sequence number.

[0224] The current sequence number binary value refers to the underlying digital information of the candidate IPv6 address after stripping away all high-level network prefix information, which purely represents the end host number.

[0225] The IP address management device converts conflicting candidate IPv6 addresses into a 128-bit binary data stream and retrieves the newly generated intra-segment extraction mask. The IP address management device then inputs the binary data stream of the candidate IPv6 addresses and the intra-segment extraction mask into the arithmetic logic unit of the central processing unit.

[0226] The arithmetic logic unit performs bitwise AND operations on each bit of the input 128-bit data string. The rule for bitwise AND operations is that the result is 1 only if both corresponding bits are 1; otherwise, the result is 0.

[0227] Because all bits outside the sequence number segment boundary of the segment extraction mask are 0, after the bitwise AND operation, all high-order parent identifier data in the candidate IPv6 address is forcibly cleared to zero. The original data of the candidate IPv6 address within the sequence number segment boundary is retained. The IP address management device uses this retained original data as the current sequence number binary value and temporarily stores it in a register.

[0228] By performing bitwise AND operations, the core basic data that needs to be added and iterated can be extracted from a very long string of complex addresses in a very efficient and safe manner.

[0229] S2204: Within the length interval formed by the boundaries of the sequence number segment, perform a single-step addition operation on the current sequence number binary value to obtain an incrementing binary value.

[0230] Single-step addition refers to the process of adding a minimum counting unit (one) to an existing numerical sequence without changing the number system rules. An incrementing binary value refers to a tentative new number to be assigned after cumulative addition.

[0231] The IP address management device reads the extracted current sequence number binary value from the register. It calculates the total bit width of the current sequence number binary value based on the sequence number segment boundaries. For example, if the start bit is bit 100 and the end bit is bit 103, the total bit width is four bits. The IP address management device then initiates an arithmetic accumulation instruction on the four-bit current sequence number binary value. A binary '1' is added to the least significant bit (the rightmost bit) of the current sequence number binary value.

[0232] When encountering a situation where two ones are added together, the IP address management device generates a carry-over to the higher bit according to the binary rule of carrying over when reaching two. After one round of single-step addition, the IP address management device calculates the number of the next adjacent address following the conflicting address. The direct result of the addition operation is then output and stored as an incrementing binary value.

[0233] Performing single-step addition ensures that available resources are continuously searched within the current service network segment, without arbitrarily jumping to other unknown network segments.

[0234] S2205, based on the segment extraction mask, verifies whether the incrementing binary value has overflowed across the boundary, and obtains the overflow verification result.

[0235] This step is a crucial defensive step to ensure that the network address allocation logic is not compromised.

[0236] Cross-boundary overflow refers to a dangerous phenomenon that occurs during single-step addition operations. Because the current binary value has reached the maximum allowed by the specified length, the carry generated by the highest bit not only alters the data within the current interval but also intrudes into memory locations outside the current interval. For example, in a three-bit interval, if the original value is a 7 (all ones), adding one will result in an 8, requiring four bits. The carry exceeding the three-bit length constitutes a cross-boundary overflow.

[0237] Overflow check result refers to the Boolean feedback conclusion on the security status of the operation after rigorous mathematical comparison.

[0238] The IP address management device extracts the incrementing binary value obtained through calculation, retrieves the segment extraction mask used for filtering again, and performs a bitwise AND operation on the bitwise inverse sequence of the incrementing binary value and the segment extraction mask. If the incrementing binary value contains a 1 at any bit to the left of the segment boundary, it indicates that the carry from the addition operation has exceeded the constraint. In this case, the IP address management device generates an overflow check result. An overflow means that there are no more free addresses available for allocation within the current subnet, and address resources are exhausted.

[0239] If the operation detects that all bits of the incrementing binary value outside the sequence number segment boundary remain 0, it means that the carry from the addition was absorbed within the reasonable sequence number segment boundary. At this point, the IP address management device generates a non-overflow check result.

[0240] By implementing a robust cross-boundary overflow verification mechanism, IP address management devices can effectively block illegal operations that could corrupt high-level parent identifier data, thereby avoiding catastrophic failures that could cause the entire upper-layer backbone network routing protocol to collapse due to the exhaustion of underlying host numbers.

[0241] S2206: When the overflow check result is no overflow, the incrementing binary value is determined as the new available sequence number identifier value.

[0242] In this embodiment, once the security detection logic of the IP address management device confirms that the incrementing operation process has not caused damage to the surrounding data environment, the trial operation result needs to be confirmed as the formal output parameter.

[0243] The IP address management device reads the overflow check result. When the overflow check result is determined to be non-overflowing, it indicates that the host number just calculated is valid in terms of mathematical length, and that the host number just calculated is the first one generated by the system within the current level of the service network segment.

[0244] The IP address management device removes the temporary isolation status of the incrementing binary value. It then officially tags the valid incrementing binary value as usable and designates it as the new usable sequence number identifier.

[0245] The new available serial number identifier value is then passed to the calling function at the next higher level as direct material to replace the old conflict number.

[0246] If the overflow check result indicates an overflow, the IP address management device will discard the incrementing binary value and send an emergency alarm message indicating that the address pool is exhausted to the network administrator.

[0247] By confirming new available sequence number identifier values ​​in a non-overflow state, the IP address management device achieves intelligent and smooth replacement of faulty addresses while ensuring the security of network routing topology, greatly enhancing its fault tolerance and error correction capabilities in the face of complex live network environments.

[0248] In some embodiments, for service scenarios where the end device sequence number node in the target identifier node set is configured with a high-security defense label, in order to prevent the traditional single-step continuous incremental allocation mechanism from causing the allocated addresses in the IPv6 subnet to be highly continuously distributed, thus making them extremely vulnerable to IP address range lateral scanning (PingSweep) probing attacks by hackers using automated scripts.

[0249] To solve the above problems, step S220 of this embodiment may further include the following:

[0250] S301, based on the sequence number segment boundary, calculate the effective bit width occupied by the sequence number node of the end device.

[0251] The effective bit width refers to the number of binary bits that can actually be varied within the 128-bit address space for the end device sequence number node. The IP address management device calculates the length of host numbers that can be allocated within the current subnet by measuring the difference between the end bit and the start bit of the sequence number segment boundary.

[0252] S302, based on the effective bit width, extracts the corresponding target primitive polynomial configuration parameters from the preset characteristic equation library.

[0253] The pre-defined characteristic equation library stores sets of primitive polynomials for different orders. The target primitive polynomial configuration parameter defines the tap position in the linear feedback operation. The IP address management device utilizes the number theory properties of primitive polynomials to ensure that the subsequently generated pseudo-random sequence reaches the maximum period within the effective bit width, thereby guaranteeing that the algorithm can traverse every available address within the current subnet without omission and without generating premature dead loops.

[0254] S303 instantiates a linear feedback shift register in memory and injects the extracted current sequence number binary value as the initial calculation seed into the linear feedback shift register.

[0255] In this step, the IP address management device constructs a Linear Feedback Shift Register (LFSR) with a dynamic length equal to the width of the effective bits in the underlying logic operation unit. The current sequence number binary value of the old address that was found to have a conflict during the previous cross-matching is directly used as the initial calculation seed of the random number generator and loaded into the data bits of the instantiated LFSR.

[0256] S304 performs shift and bitwise XOR operations on the linear feedback shift register based on the tap position set by the target primitive polynomial configuration parameters to generate a pseudo-random incrementing binary value with non-continuous jump characteristics.

[0257] The clock pulse inside the IP address management device triggers a rightward shift of the register data. During this shift, the IP address management device performs a bitwise XOR operation on the bit data at a specific tap position specified by the target primitive polynomial, and feeds the result back into the highest input bit of the register. After one or more set shift-XOR iterations, the new value output in the register no longer exhibits a continuous linear relationship of incrementing by one with the initial calculation seed, but instead displays a pseudo-random jump with unpredictable ranges. This new value is the pseudo-randomly incrementing binary value.

[0258] S305, based on the segment extraction mask, verifies whether the pseudo-randomly incrementing binary value exceeds the sequence number segment boundary, and obtains the safe jump verification result.

[0259] Although the operations of linear feedback shift registers are limited to the effective bit width, strict verification is still required near the boundaries of certain reserved addresses (such as network addresses with all 0s or broadcast routing addresses with all 1s). IP address management devices use intra-segment extraction masks to perform boundary validity inversion on the pseudo-random incrementing binary value, ensuring that it falls within the valid communication host bit range.

[0260] S306, when the security jump check result is that the address has not exceeded the boundary and is not a reserved address, the pseudo-random incrementing binary value is determined as the new available sequence number identifier value.

[0261] If the generated pseudo-random incrementing binary value is valid, the IP address management device will recognize it as the final end host number replacement data. If the generated value is within the reserved address range, or if it is found to be occupied again in subsequent recursive cross-checks, the IP address management device will not reset the system. Instead, it will directly use the current pseudo-random incrementing binary value as a new seed to trigger the linear feedback shift register to continue executing the next round of shift XOR operation until an unoccupied discrete secure address is found.

[0262] This embodiment employs the aforementioned dynamic hop addressing scheme, cleverly integrating the mobile target defense concept from the network security field into the IP address management device. Without increasing external database retrieval overhead, it breaks the continuity and predictability of IPv6 address allocation. Because the newly generated available sequence number identifiers exhibit a discrete pseudo-random hop distribution in the numerical space, attackers cannot use a known successfully probed IP address to probe its adjacent live hosts using simple addition, thus improving the stealth of the network address space. Simultaneously, thanks to the mathematical guarantee of primitive polynomials, the system still ensures full utilization of the entire free address pool, achieving a triple enhancement in addressing efficiency, address utilization, and underlying network anti-scanning security defense capabilities.

[0263] In some related technologies, address conflicts are typically verified by retrieving the actual routing interface configuration information of the router. However, in practical applications, many terminal servers or IoT devices connected to the router dynamically and randomly generate IPv6 addresses using stateless address autoconfiguration protocols or privacy extension protocols. These randomly generated dynamic IPv6 addresses are only active in the Layer 2 network and are not hard-coded into the static interface configuration files of network administrators or routers. This creates a hidden conflict blind spot. When querying the router's static interface configuration, IP address management devices may mistakenly assume that the address is unused, thus incorrectly assigning the candidate IPv6 address to a new core service gateway. Once the new address is assigned, it will cause a serious Layer 2 network conflict with the dynamically configured address that is hidden in the existing network, resulting in the interception or dropping of service data packets and causing a hidden network paralysis.

[0264] To address the above problems, the present invention provides a solution comprising the following method flow:

[0265] S401, retrieve the dynamically generated neighbor discovery protocol cache table in the target bearer network device.

[0266] In order to eliminate the blind spots of hidden device conflicts caused by the traditional static configuration retrieval method, the IP address management device needs to delve into the dynamic operating status of the device at the underlying level while performing static configuration information verification.

[0267] Among them, the target bearer network equipment refers to the underlying communication nodes such as physical routers, switches or virtual gateways that will be officially issued and configured with the planned new IPv6 addresses in the actual physical computer room or cloud resource pool.

[0268] The Neighbor Discovery Protocol (NIP) cache table is a data netlist that is dynamically built and maintained in the system memory of an IPv6 network device during operation. It records the dynamic mapping relationship between IPv6 addresses and underlying physical media access control addresses by listening to neighbor request and neighbor advertisement messages on the underlying link.

[0269] The IP address management device sends a specific forwarding table entry read command to the underlying operating system kernel of the target network device via an encrypted network configuration protocol or simple network management protocol. After receiving the read command, the target network device packages and encapsulates all neighbor node information currently cached in its memory chip.

[0270] The IP address management device receives and parses these packetized information to extract the most up-to-date neighbor discovery protocol cache table.

[0271] By proactively acquiring the Neighbor Discovery Protocol (NNP) cache table, IP address management devices extend the reach of conflict detection from static text configuration files to the dynamic cache of active Layer 2 physical links. This makes it impossible for unauthorized devices attempting to stealthily access the network by randomly generating addresses to hide, thus expanding the physical depth and coverage of address conflict detection.

[0272] S402 performs a shadow cross-comparison of candidate IPv6 addresses with the neighbor discovery protocol cache table based on time status.

[0273] In this embodiment, after obtaining the dynamic table entry, it is not possible to directly and simply determine the conflict, because the data in the cache table has extremely high time sensitivity and variability.

[0274] Shadow cross-matching based on time-sensitive status refers to a complex verification mechanism that not only checks whether a candidate IPv6 address appears in the cache record, but also delves into the lifecycle stage of the address in the underlying protocol stack.

[0275] The IP address management device uses the generated candidate IPv6 addresses as target search keywords and performs a full table scan of the neighbor discovery protocol cache table. If the scan misses, it means that no device on the underlying physical link is indeed using the address. If the scan hits, the IP address management device further extracts the network status identifier field corresponding to the hit record. The network status identifier field typically includes reachability status, delay status, or aging status.

[0276] If a candidate IPv6 address is found in the cache table and its status is reachable or delayed, it means that there is indeed a physical host on the network actively sending data using that address. The IP address management device immediately determines that the candidate IPv6 address is unavailable.

[0277] This comparison method, which incorporates a time-sensitive status dimension, can accurately distinguish whether an address is continuously occupied by a real physical device or is merely a phantom record generated because the network cache has not been cleared, thus improving the scientific rigor and accuracy of address conflict determination.

[0278] S403, when a candidate IPv6 address is in an aging cache state, triggers a directed neighbor request micro-probe task.

[0279] In this embodiment, a complex and potentially misleading situation during shadow cross-matching is when a hit record is displayed as cached aging. Cache aging means that the IPv6 address was once active on the network and recorded by the router, but the router has not received any data packets from that address for a long time.

[0280] If candidate IPv6 addresses that are in an aging cache state are directly classified as conflicting, it will result in a serious waste of address resources. On the other hand, if they are classified as idle, it is highly likely to lead to catastrophic conflicts when older devices are suddenly woken up.

[0281] Targeted Neighbor Request Microprobe Task refers to a sophisticated operation in which the IP address management device controls the target network device to send a lightweight unicast probe message to a specific address in order to force potential stealthy devices to reveal themselves.

[0282] The IP address management device issues a dedicated probe command to the target bearer network device. Based on the command, the target bearer network device constructs a unicast neighbor request protocol control message whose target IP is only the candidate IPv6 address, and sends it to the network through its physical interface.

[0283] Unlike traditional broadcast flooding probes, targeted neighbor request microprobes do not unnecessarily consume network bandwidth. The IP address management device starts a micro-timer at the millisecond level to wait for a response.

[0284] By performing targeted neighbor request micro-probing tasks, we can penetrate the cached appearance with minimal system overhead and accurately verify the true availability of addresses in the gray area.

[0285] S404: Construct a dynamic address evasion black hole mask based on the response results of the directed neighbor request micro-probe task.

[0286] The purpose of this step is to permanently isolate the detected dynamic address blind spots in subsequent automated allocation algorithms.

[0287] Dynamic address avoidance black hole mask refers to a protective data filtering structure in memory space specifically used to block algorithms from selecting specific illegal address ranges.

[0288] If the targeted neighbor request micro-probe task receives a neighbor advertisement response message from an unknown device within the timeout period, the IP address management device confirms that the candidate IPv6 address in the aging state is actually occupied (including malicious occupation or occupation by device hibernation keep-alive), and cannot be allocated an address.

[0289] At this point, the IP address management device extracts the underlying binary value of the sequence number node of the end device corresponding to the conflicting address; initializes a binary space in memory with the same length as the boundary of the sequence number bit segment; and sets the specific offset position where the binary value with the hidden conflict exists to 1 through logical bit setting operations, while keeping the other safe bit segments at 0. The generated data sequence is the dynamic address avoidance black hole mask.

[0290] The IP address management device integrates the generated dynamic address avoidance black hole mask into the node constraint attributes of the aforementioned multi-level identifier association tree model. In the subsequent generation of new candidate IPv6 addresses, any calculation result attempting to generate the conflicting address will be directly blocked and filtered by the dynamic address avoidance black hole mask.

[0291] This masking mechanism enables IP address management devices to have advanced immune memory capabilities against unknown network environments, effectively eliminating the interference of dynamic hidden addresses on the automatic planning of the core network.

[0292] In high-concurrency scenarios involving cloud-native microservice architectures or the rapid scaling of large-scale container clusters, hundreds or even thousands of business network planning requests flood the IP address management device within a very short time during the large-scale deployment of microservices. These requests often point to the same set of target identifier nodes. If the conventional single-step increment logic is used, multiple concurrent threads will simultaneously read the same candidate IPv6 address that appears to be idle. When multiple concurrent threads detect address conflicts simultaneously, they will synchronously initiate single-step addition operations to offset the address backward, causing the massive concurrent processing process to fall into an infinite recursive cross-comparison loop. At the same time, multiple concurrent threads launching intensive deduplication read and write operations on the same underlying database will trigger severe database row-level lock contention and deadlock phenomena, ultimately leading to the instantaneous exhaustion of the central processing unit resources of the IP address management device and the collapse of the entire network address allocation service.

[0293] To solve the above problems, the method of this embodiment further includes the following steps:

[0294] S501: When multiple concurrent service network planning requests are detected for the same target identifier node set, the total number of concurrent transactions is extracted.

[0295] This step is a preliminary awareness process to address concurrent failures caused by the rapid scaling of large-scale cloud-native network microservices.

[0296] When a large number of containers or microservice gateways simultaneously send address request requests to the IP address management device, the request receiving module inside the IP address management device starts a concurrent traffic monitor. The concurrent traffic monitor scans all business network planning requests entering the system queue in real time. When the analysis finds that the target business feature set carried by a large number of requests all points to the same specific network segment or the same target identifier node set, it is determined that the system is suffering from a surge of instantaneous high-concurrency address requests.

[0297] At this point, the IP address management device immediately performs a memory snapshot capture operation on the queue. By reading the queue length counter from the memory snapshot, it extracts the total number of concurrent transactions currently competing for resources on the same network segment. The total number of concurrent transactions refers to the precise number of independent threads attempting to perform address allocation operations within the same sequence number segment boundary within a preset, very short monitoring time window.

[0298] By accurately sensing and extracting the total number of concurrent transactions, sudden and disordered network planning requests can be transformed into quantitative indicators that can be mathematically coordinated and scheduled, providing a key global basis for the subsequent implementation of spatial isolation algorithms.

[0299] S502 performs prime number step size isolation partitioning on the boundary of the sequence number bit segment corresponding to the sequence number node of the end device based on the total number of concurrent transactions.

[0300] This step is the core mathematical coordination algorithm for resolving resource conflicts arising from multiple processing threads during the free address lookup process. The prime number step-size isolation partitioning refers to breaking away from the traditional continuous single-step increment logic and utilizing the coprime property of prime numbers to divide the complete, continuous address lookup space into multiple mathematically non-overlapping addressing tracks.

[0301] In concurrent congestion scenarios, multiple processing threads search for free addresses within the same sequence number segment boundary, following a single-step incrementing logic. This homogeneous search method can lead to severe resource conflicts.

[0302] Therefore, the IP address management device performs prime number step size isolation segmentation processing, calls the internal advanced mathematical algorithm module, and according to the total number of concurrent transactions extracted, sequentially matches multiple distinct prime values ​​(such as prime number 3, prime number 7, prime number 11, etc.) that are equal to the total number of concurrent transactions in the preset prime number sequence table, and determines these prime values ​​as the independent addressing span of different threads.

[0303] Subsequently, the IP address management device uses the total length of the sequence number segment boundary corresponding to the sequence number node of the terminal device as the divisor boundary, and performs a modulo operation on each prime value to forcibly scatter the initial offset of each concurrent request.

[0304] By performing the prime step size isolation partitioning described above, the originally single continuous address space can be divided into multiple independent addressing channels with no intersection, eliminating the possibility of multiple concurrent transactions hitting the same conflicting address from a mathematical perspective.

[0305] In some specific implementations, when performing prime number step-size isolation segmentation, the IP address management device first calculates the precise capacity boundary value of the current closed addressing subspace based on the start and end bits of the end device sequence number node. Since this capacity boundary value is an integer power of 2, the prime number pool allocation engine inside the IP address management device executes coprime verification logic, forcibly removing the even prime number 2 from the available prime number pool, ensuring that the step-size parameter distributed to all concurrent processing threads is an odd prime number. Utilizing the number theory principle that odd prime numbers and integer powers of 2 are always coprime, the system guarantees from the underlying algorithm that when any concurrent processing thread performs modulo superposition jumps, its addressing trajectory can traverse every legal address coordinate in the entire subspace without repetition or omission, eliminating the risk of the addressing trajectory getting stuck in a local infinite loop.

[0306] Meanwhile, before each concurrent processing thread is awakened and ready to begin lock-free concurrent incremental computation, to prevent a large number of threads from starting from the zero base address at the same time, thus causing instantaneous congestion on the underlying memory bus, the IP address management device extracts the unique thread identifier or microservice process number carried by each concurrent request. The extracted thread identifier is then input into a hash function, and the output hash value is moduloed by the capacity boundary value of the addressing subspace to generate a pseudo-random initial space offset for each independent thread.

[0307] Each thread, upon obtaining its own prime number step size, uses this initial spatial offset as the starting line for its concurrent jump addressing, thus scattering the calculation of the initial landing point from a spatial physical perspective.

[0308] S503 allocates the step size of the divided independent prime numbers to the corresponding concurrent processing threads to perform lock-free concurrent incremental calculations.

[0309] This step is the execution phase of the simulation for achieving efficient address allocation under high concurrency pressure.

[0310] Concurrent processing threads refer to logical operation units that run independently at the operating system kernel level of IP address management devices and are dedicated to handling single-service network planning requests. Lock-free concurrent incremental computation refers to a mechanism that performs safe address optimization iterations using thread-specific jump steps without invoking the exclusive global pessimistic lock of the underlying database.

[0311] The IP address management device uses inter-process communication to inject the multiple non-overlapping prime number step size parameters calculated in the previous step into the local variable registers of each concurrent processing thread in a waiting state, thereby waking up each concurrent processing thread and enabling it to work independently. When each concurrent processing thread detects that an address is occupied and needs to offset backward to find a new available sequence number identifier value, it no longer performs the traditional single-step addition operation. Instead, it reads its own exclusive prime number step size parameter from its local variable register and directly adds the prime number step size parameter to the current sequence number binary value.

[0312] Since the step size of all concurrent processing threads is a coprime number and the initial starting point has been shuffled, it can be strictly guaranteed from a mathematical perspective that the computational trajectories of any two concurrent processing threads will not overlap during tens of thousands of incremental address lookups. Therefore, during the entire address extrapolation calculation process, the IP address management device does not need to request any performance-impacting global blocking locks from the underlying unified address planning ledger database.

[0313] By allocating independent prime step sizes to perform lock-free concurrent incremental calculations, this embodiment breaks through the performance bottleneck of traditional relational databases in high-concurrency addressing and deduplication, and achieves low-overhead, instantaneous, and efficient processing of massive IPv6 address planning tasks.

[0314] In some specific implementations, during the execution of lock-free concurrent incremental computation, in order to give concurrent processing threads the ability to autonomously determine the exhaustion of network segment resources, the IP address management device initializes an independent security anchor register for each thread.

[0315] Before the thread initiates its first prime number jump, the generated initial space offset is copied and locked into the safety anchor register. During subsequent intensive lock-free concurrent incrementing calculations, each time the thread adds the current index binary value to the prime number step size and completes the out-of-bounds modulo fallback operation, an anchor point overlap comparison instruction is triggered. This instruction compares the newly calculated address offset with the initial position fixed in the safety anchor register.

[0316] Once the comparison results show that the two values ​​are completely consistent, it is mathematically proven that the thread has completed a complete closed-loop inspection of all address points in the current subspace by relying on its own prime number step size, and all points are in an occupied state.

[0317] At this point, the concurrent processing thread will immediately terminate the prime number jump addressing loop, actively release the CPU core computing resources it occupies, and throw an abnormal alarm status of subnet address pool exhaustion to the upper-level concurrent scheduler, thereby avoiding the catastrophic system failure of a massive number of concurrent threads collectively getting stuck in an infinite optimization deadlock under a fully loaded network environment.

[0318] The following describes an exemplary IP address management device provided in an embodiment of the present invention. Figure 2 This is a schematic diagram of an exemplary hardware architecture of the IP address management device provided in an embodiment of the present invention.

[0319] In some embodiments, the IP address management device is an electronic device, or the IP address management device includes an electronic device. The electronic device includes a processor, memory, and a network interface connected via a system bus. The processor of the electronic device provides computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the electronic device stores data. The network interface of the electronic device is used to communicate with other external terminals or servers via a network connection. In some embodiments, the network interface can be a wired network interface; in some embodiments, the network interface can also be a wireless network interface. When the computer program is executed by the processor, it implements the methods in the embodiments of the present invention.

[0320] Those skilled in the art will understand that Figure 2 The architecture shown is merely a block diagram of a portion of the architecture related to the present invention and does not constitute a limitation on the electronic device to which the present invention is applied. Specific electronic devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0321] The above-described embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

[0322] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".

[0323] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on an electronic device, all or part of the processes or functions described in the embodiments of the present invention are generated. The electronic device may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0324] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for IPv6 address planning and management based on a custom identifier template, characterized in that, Applied to IP address management devices, the method includes: The received custom identifier template is parsed to extract the template configuration parameter set. The custom identifier template defines the service attributes and hierarchical associations of each segment bit range in the IPv6 address. Based on the template configuration parameter set, a multi-level identifier association tree model is constructed, which includes the identifier business meaning, start bit, end bit and parent node association prefix; Based on the received business network planning request, generate a set of target business features to be planned; The target business feature set is subjected to hierarchical cascading constraint verification using the multi-level identifier association tree model to obtain a set of target identifier nodes that pass the verification. Based on the start and end bits of each node in the target identifier node set, candidate IPv6 addresses are generated; The candidate IPv6 addresses are compared with the preset unified address planning ledger to obtain the occupancy status comparison results. When the occupancy status comparison result is no occupancy record, the candidate IPv6 address is assigned an available tag, and a target IPv6 address planning scheme is generated.

2. The method according to claim 1, characterized in that, After generating candidate IPv6 addresses based on the start and end bits of each node in the target identifier node set, the method further includes: Read the network attribute tags configured for the end nodes from the target identifier node set; The corresponding subnet mask length is determined based on the category determination logic of the network attribute tags; The subnet mask length is increased and added to the candidate IPv6 address to obtain the candidate IPv6 address carrying the subnet mask.

3. The method according to claim 1 or 2, characterized in that, The step of comparing the candidate IPv6 addresses with the preset unified address planning ledger to obtain the occupancy status comparison result specifically includes: Based on the aforementioned service network planning request, the corresponding target bearer network device is determined; Send a configuration pull command to the target bearer network device to obtain the current actual routing interface configuration information of the target bearer network device; The candidate IPv6 addresses are cross-compared in the unified address planning ledger and the actual routing interface configuration information to obtain the tri-state comparison results. When the three-state comparison result indicates that there is no record on both the ledger and the actual configuration side, an occupancy status comparison result with no occupancy record is generated.

4. The method according to claim 3, characterized in that, After cross-comparing the candidate IPv6 addresses with the unified address planning ledger and the actual routing interface configuration information to obtain the tri-state comparison result, the method further includes: When the tri-state comparison result indicates that there is no record in the ledger, but there is a record in the actual routing interface configuration information, the candidate IPv6 address is marked as unregistered and occupied. Based on the unregistered occupancy status, trigger an intra-segment offset increment task for the end device sequence number node in the target identifier node set; Execute the segment offset increment task to obtain a new available sequence number identifier value; Replace the original sequence number field data in the candidate IPv6 address with the new available sequence number identifier value to obtain the updated candidate IPv6 address. The updated candidate IPv6 addresses are used as the cross-comparison objects and fed back to the cross-comparison step to perform recursive verification.

5. The method according to claim 4, characterized in that, The process of executing the segment offset increment task to obtain a new available sequence number identifier value specifically includes: Based on the start bit and the end bit corresponding to the sequence number node of the terminal device, the sequence number segment boundary is determined; Based on the sequence number segment boundary, generate an intra-segment extraction mask for isolating high-level parent identifier data; The candidate IPv6 address is subjected to a bitwise AND operation by extracting the mask within the segment to obtain the current sequence number binary value; Within the length interval formed by the boundaries of the sequence number segment, a single-step addition operation is performed on the current sequence number binary value to obtain an incrementing binary value; Based on the segment-extracted mask, check whether the incrementing binary value overflows across the boundary to obtain the overflow check result; When the overflow check result is no overflow, the incrementing binary value is determined as the new available sequence number identifier value.

6. The method according to claim 1, characterized in that, The step of performing hierarchical cascading constraint verification on the target business feature set through the multi-level identifier association tree model to obtain a set of target identifier nodes that pass the verification specifically includes: Extract the current level feature items and the previous level feature items from the target service feature set in descending order of network hierarchy; Determine whether the first identifier node corresponding to the current level feature item in the multi-level identifier association tree model contains the parent node association prefix pointing to the second identifier node corresponding to the previous level feature item; When all hierarchical feature items satisfy the parent node association prefix matching judgment, all extracted identifier nodes are aggregated to generate the target identifier node set.

7. The method according to claim 1, characterized in that, The step of generating candidate IPv6 addresses based on the start and end bits of each node in the target identifier node set specifically includes: Initialize a 128-bit binary container with all data bits set to zero; A fixed unified routing prefix value is written to the most significant bit of the initialized 128-bit binary container; According to the start bit and the end bit of each node in the target identifier node set, the binary value of the service identifier corresponding to each node is sequentially embedded into the corresponding bit segment range of the 128-bit binary container; The candidate IPv6 address is generated based on the data of the 128-bit binary container after all service identifier binary values ​​have been embedded.

8. An IP address management device, characterized in that, Includes one or more processors and memory; The memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, the one or more processors invoking the computer instructions to cause the IP address management device to perform the method as described in any one of claims 1-7.

9. A computer-readable storage medium storing computer instructions, characterized in that, When the computer instructions are executed on the IP address management device, the IP address management device performs the method as described in any one of claims 1-7.

10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed on the IP address management device, the IP address management device performs the method as described in any one of claims 1-7.