A multi-vendor network sharing system, method, apparatus, device and storage medium

CN122661111APending Publication Date: 2026-08-28CHINA UNITED NETWORK COMM GRP CO LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610423178.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-01
Publication Date
2026-08-28

AI Technical Summary

Technical Problem

解决了现有技术中适配层将削弱设备厂商独特的网络能力的问题,简化了跨域编排难度与管理复杂度,同时保留各设备厂商功能特色

Benefits of technology

[0015] Fourthly, this application proposes a computer electronic production apparatus, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of any of the methods described in the second aspect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122661111A_ABST
    Figure CN122661111A_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of network sharing, and particularly relates to a multi-service provider network sharing system, method, device and storage medium. The present application provides a multi-service provider network sharing system, which comprises a self virtual private network, service provider virtual private networks and a service application platform; each of the service provider virtual private networks is pre-connected to the self virtual private network in a physical manner, so that the service provider virtual private networks communicate with each other through the self virtual private network; the service application platform is in communication connection with a self private network management system and each service provider private network management system, and is configured to respectively issue a service request to the self private network management system and each service provider private network management system according to a user service. The present application solves the problem that the adaptation layer will weaken the unique network capability of a device manufacturer in the prior art, simplifies the cross-domain arrangement difficulty and management complexity, and meanwhile retains the functional features of each device manufacturer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical field of network sharing, and specifically relates to a network sharing system, method, apparatus, device, and storage medium with multiple service providers. Background Technology

[0002] A Virtual Private Network (VPN) is a logical private network built within a public network. Compared to costly and inflexible physical lines, VPNs establish encrypted tunnels over the public network, achieving secure and low-cost cross-domain interconnection. Software-Defined Wide Area Networks (SD-WAN) utilize software-defined networking technology to separate control and data transfer, further improving network connection efficiency and user experience. It is currently the most commonly used leased line service method for wide area networks.

[0003] SD-WAN equipment vendors, as technology product providers, offer SD-WAN equipment and software licenses. SD-WAN service providers, as network service operators, provide managed SD-WAN services, including SD-WAN equipment delivery, operation, and maintenance services. They typically build SD-WAN network switching points (POPs) around business development areas to establish a backbone transmission network, enabling nearby access for user-side terminal devices and providing more efficient forwarding. POPs can be configured as single-vendor nodes or multi-vendor nodes. Single-vendor nodes only support networking with equipment from a single vendor; multi-vendor nodes require simultaneous deployment of gateway devices from multiple vendors within a single POP resource environment, supporting cross-vendor hybrid networking. Through an application platform, they can collaboratively orchestrate multi-vendor SDN controllers, achieving unified management of cross-vendor hybrid network configurations.

[0004] However, in the existing technology, the control and management system of a single equipment manufacturer cannot manage equipment from other manufacturers. Although an adaptation layer can be established to match the control planes of multiple manufacturers, the management capabilities of the control planes of different manufacturers are different, and the adaptation layer will weaken the unique network capabilities of the equipment manufacturers. Summary of the Invention

[0005] This invention provides a multi-service provider network sharing system, comprising: a proprietary virtual private network (VPN), service provider VPNs, and a business application platform. Each service provider VPN is physically pre-connected to the proprietary VPN, enabling communication between the service provider VPNs via the proprietary VPN. The proprietary VPN is composed of multiple network elements of a designated server, while the service provider VPNs are composed of multiple network elements from the same service provider. The business application platform is communicatively connected to the proprietary VPN management system and the service provider VPN management systems, and is used to send service requests to both the proprietary VPN management system and the service provider VPN management systems based on user services. This allows the proprietary VPN management system to allocate resources to its own VPN based on the service requests, and the service provider VPN management systems to allocate resources to their respective service provider VPNs based on the service requests. This solution addresses the problem in existing technologies where the adaptation layer weakens the unique network capabilities of equipment manufacturers, simplifies cross-domain orchestration and management complexity, and preserves the functional characteristics of each equipment manufacturer.

[0006] To address the aforementioned technical problems, this application proposes five aspects.

[0007] Firstly, a multi-service provider network sharing system includes: a proprietary virtual private network (VPN), service provider VPNs, and a business application platform. Each service provider VPN is physically pre-connected to the proprietary VPN, enabling communication between the service provider VPNs through the proprietary VPN. The proprietary VPN is a VPN composed of multiple network elements of a designated server, and each service provider VPN is a VPN composed of multiple network elements of the same service provider. The business application platform is communicatively connected to the proprietary VPN management system and each service provider VPN management system, and is used to send service requests to the proprietary VPN management system and each service provider VPN management system according to user services. This allows the proprietary VPN management system to allocate resources of the proprietary VPN based on the service requests, and each service provider VPN management system to allocate resources of its corresponding service provider VPN based on the service requests.

[0008] In some embodiments, each of the service provider virtual private networks (VPNs) is physically pre-connected to the proprietary VPN, including: any edge device of the service provider VPN is physically pre-connected to an edge device of the proprietary VPN, enabling interconnection of the underlying networks.

[0009] In some embodiments, the method further includes: when the business application platform receives a first virtual private network access request from a target service provider, the business application platform determines a target interface point in its own virtual private network that connects to the first virtual private network; the business application platform determines a first edge device that connects its own virtual private network to the first virtual private network based on the target interface point; after the first edge device completes a physical pre-connection with the first virtual private network, the business application platform obtains access resource information of the first virtual private network.

[0010] Secondly, this application proposes a network sharing method for multiple service providers, applicable to the system described in the first aspect, comprising: the business application platform acquiring the business needs of a target user; the business application platform establishing a first VPN instance for the target user in edge devices of multiple service provider private networks according to the business needs of the target user; the business application platform establishing a second VPN instance identical to the first VPN instance in its own virtual private network according to each of the first VPN instances, so that the services of the first VPN instance can communicate with other service provider virtual private networks through the second VPN instance.

[0011] In some embodiments, the business application platform establishes a first VPN instance for the target user in edge devices of multiple service provider private networks according to the target user's business needs, including: the business application platform determining the target business resources required by the target user according to the business needs; determining a first resource allocation strategy for each service provider virtual private network according to the current remaining resources of each service provider virtual private network and the target business resources; the business application platform sending the first resource allocation strategy to the service provider private network management system corresponding to each service provider virtual private network in the form of a service request, and the service provider private network management system establishing the first VPN instance in the edge devices according to the first resource allocation strategy.

[0012] In some embodiments, the service provider private network management system establishes the first VPN instance in the edge device according to the first resource allocation policy, including: the service provider private network management system determines a first target edge device according to the first resource allocation policy and the resource occupancy of the corresponding service provider virtual private network, wherein the first target edge device is an edge device that satisfies the first resource allocation policy; and establishes the first VPN instance in the first target edge device according to the first resource allocation policy.

[0013] In some embodiments, the business application platform establishes a second VPN instance identical to the first VPN instance in its own virtual private network based on each of the first VPN instances, including: the business application platform determining a second target edge device based on the service provider virtual private network corresponding to each of the first resource allocation policies, wherein the second target edge device is an edge device in the own virtual private network that is physically connected to the service provider virtual private network corresponding to each of the first resource allocation policies; therefore, the business application platform determines a corresponding second resource allocation policy based on each of the first resource allocation policies; the business application platform sends the second resource allocation policy to the own private network management system in the form of a service request, and the own private network management system establishes the second VPN instance in the corresponding second target edge device based on each of the second resource allocation policies.

[0014] Thirdly, this application proposes a network sharing device for multiple service providers, comprising: a first acquisition module for acquiring the business needs of a target user; a first establishment module for establishing a first VPN instance of the target user in edge devices of multiple service provider private networks according to the business needs of the target user; and a second establishment module for establishing a second VPN instance identical to the first VPN instance in its own virtual private network according to each of the first VPN instances, so that the business of the first VPN instance can communicate with other service provider virtual private networks through the second VPN instance.

[0015] Fourthly, this application proposes a computer electronic production apparatus, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of any of the methods described in the second aspect.

[0016] Fifthly, this application proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any of the second aspects.

[0017] This invention provides a multi-service provider network sharing system, comprising: a proprietary virtual private network (VPN), service provider VPNs, and a business application platform. Each service provider VPN is physically pre-connected to the proprietary VPN, enabling communication between the service provider VPNs via the proprietary VPN. The proprietary VPN is composed of multiple network elements of a designated server, while the service provider VPNs are composed of multiple network elements from the same service provider. The business application platform is communicatively connected to the proprietary VPN management system and the service provider VPN management systems, and is used to send service requests to both the proprietary VPN management system and the service provider VPN management systems based on user services. This allows the proprietary VPN management system to allocate resources to its own VPN based on the service requests, and the service provider VPN management systems to allocate resources to their respective service provider VPNs based on the service requests. This solution addresses the problem in existing technologies where the adaptation layer weakens the unique network capabilities of equipment manufacturers, simplifies cross-domain orchestration and management complexity, and preserves the functional characteristics of each equipment manufacturer. Attached Figure Description

[0018] One or more embodiments are illustrated by way of example with reference to the accompanying drawings, and these illustrative descriptions do not constitute a limitation on the embodiments.

[0019] Figure 1 A connection diagram between a self-owned virtual private network and virtual private networks of various service providers is provided for embodiments of this application; Figure 2 A schematic diagram illustrating the connection relationship between a business application platform, a proprietary private network management system, and a service provider's private network management system, provided for embodiments of this application. Figure 3 A main flowchart of a network sharing method for multiple service providers provided in this application embodiment; Figure 4 A main structural block diagram of a multi-service provider network sharing device provided in this application embodiment; Figure 5 This is a structural block diagram of a computer electronic production equipment provided in an embodiment of this application. Detailed Implementation

[0020] A Virtual Private Network (VPN) is a logical private network built within a public network. Compared to costly and inflexible physical lines, VPNs establish encrypted tunnels over the public network, achieving secure and low-cost cross-domain interconnection. Software-Defined Wide Area Networks (SD-WAN) utilize software-defined networking technology to separate control and data transfer, further improving network connection efficiency and user experience. It is currently the most commonly used leased line service method for wide area networks.

[0021] SD-WAN equipment vendors, as technology product providers, offer SD-WAN equipment and software licenses. SD-WAN service providers, as network service operators, provide managed SD-WAN services, including SD-WAN equipment delivery, operation, and maintenance services. They typically build SD-WAN network switching points (POPs) around business development areas to establish a backbone transmission network, enabling nearby access for user-side terminal devices and providing more efficient forwarding. POPs can be configured as single-vendor nodes or multi-vendor nodes. Single-vendor nodes only support networking with equipment from a single vendor; multi-vendor nodes require simultaneous deployment of gateway devices from multiple vendors within a single POP resource environment, supporting cross-vendor hybrid networking. Through an application platform, they can collaboratively orchestrate multi-vendor SDN controllers, achieving unified management of cross-vendor hybrid network configurations.

[0022] However, in the existing technology, the control and management system of a single equipment manufacturer cannot manage equipment from other manufacturers. Although an adaptation layer can be established to match the control planes of multiple manufacturers, the management capabilities of the control planes of different manufacturers are different, and the adaptation layer will weaken the unique network capabilities of the equipment manufacturers.

[0023] Furthermore, different equipment manufacturers employ varying tunnel encryption technologies, preventing user-side terminal devices from directly establishing encrypted tunnels with devices from different manufacturers. To ensure compatibility with multi-vendor environments, enterprises or service providers need to deploy multiple sets of gateway devices and control management systems from different equipment manufacturers, and collaborate with these systems for customized development, resulting in high construction costs and significant maintenance difficulties.

[0024] To address the aforementioned technical problems, this invention proposes a multi-service provider network sharing system. The implementation details of this embodiment of the multi-service provider network sharing system are described below. The following content is only for ease of understanding and is not essential for implementing this solution.

[0025] Example 1: like Figure 1 and Figure 2 As shown, this application provides a network sharing system for multiple service providers, the system comprising: a proprietary virtual private network, service provider virtual private networks, and a business application platform.

[0026] Each of the service provider virtual private networks (VPNs) is pre-connected to the proprietary VPN via physical means, enabling communication between the service provider VPNs through the proprietary VPN. The proprietary VPN is a VPN composed of multiple network element devices of a designated server, while the service provider VPN is a VPN composed of multiple network element devices of the same service provider.

[0027] Each of the service provider virtual private networks is pre-connected to the proprietary virtual private network via physical means, including: any edge device of the service provider virtual private network is pre-connected to an edge device of the proprietary virtual private network via physical means, so that the underlying networks can communicate with each other.

[0028] This application's system physically connects edge devices of multiple server provider virtual private networks (VPNs) to edge devices of its own VPN at the physical layer, enabling network interconnection of underlying devices. The IoT connection is typically a network cable connection. Each server provider's corresponding edge device in its own VPN is connected, establishing a neighbor relationship between them. Ultimately, a shared network is formed with the own VPN at the center and multiple server provider VPNs as boundaries. This allows any two server provider VPNs to communicate only through their own VPN, resolving the problem of chaotic connection methods between server provider VPNs in existing technologies. This is because communication between two server provider VPNs may require traversing multiple VPNs; for example, sometimes two server provider VPNs are directly connected, while other times communication requires communication across multiple server provider VPNs. This also preserves the unique capabilities of each server provider VPN vendor.

[0029] The business application platform is communicatively connected to the proprietary private network management system and the private network management systems of each service provider. It is used to send service requests to the proprietary private network management system and each of the service provider's private network management systems according to the user's business. This enables the proprietary private network management system to allocate resources of its proprietary virtual private network according to the sent service requests, and enables each of the service provider's private network management systems to allocate resources of the corresponding service provider's virtual private network according to the sent service requests.

[0030] This application's system abandons the existing approach of unified resource management by the adaptation layer. Instead, it manages the shared network primarily through a business application platform, supplemented by multiple private network management systems. In this application, the business application platform only allocates resources based on user needs, breaking down user requirements to determine the service provider's virtual private network (VPN). Based on the breakdown, it determines the resource allocation strategy for each VPN and then allocates resources according to the corresponding strategy and resource usage. This allows the business application platform to manage resources only at the macro level, while specific resource management is handled by the individual service provider's private network management systems. This solves the problem in existing technologies where, to ensure compatibility with multi-device vendor environments, enterprises or service providers need to deploy multiple sets of gateway devices and control management systems from different vendors, requiring customized development and collaboration with these systems. This results in high construction costs and maintenance difficulties. The application simplifies cross-domain orchestration and management complexity, supports partner service providers in offering unique services, and is more open and inclusive.

[0031] The system further includes: when the business application platform receives a first virtual private network (VPN) access request from a target service provider, the business application platform determines a target interface point within its own VPN that connects to the first VPN. Based on the target interface point, the business application platform determines a first edge device that connects its own VPN to the first VPN. After the first edge device completes a physical pre-connection with the first VPN, the business application platform obtains access resource information from the first VPN.

[0032] Therefore, in the system of this application, when facing network expansion, there is no need to establish an adaptation layer. It is only necessary to physically connect any edge device of the newly connected service provider's virtual private network to the edge device of the own virtual private network, so as to incorporate the resources of the newly added service provider's virtual private network into the management of the business service platform.

[0033] Example 2: like Figure 3As shown, this application provides a multi-service provider network sharing method applicable to electronic production equipment. The electronic production equipment can be a server, mobile terminal, computer, cloud platform, or multi-service provider network sharing system, and is particularly suitable for business application platforms within such systems. However, the method described in this application only addresses the implementation of user needs using network sharing on a business application platform. Actual business application platforms may have other functions, but these are not the focus of this application and will not be described further. The data processing functionality of the production equipment provided in this application embodiment can be implemented by the processor of the electronic production equipment calling program code, which can be stored in a computer storage medium. The multi-service provider network sharing method includes: Step S1: The business application platform obtains the business needs of the target user.

[0034] Step S2: The business application platform establishes the first VPN instance for the target user in the edge devices of multiple service provider private networks according to the target user's business needs.

[0035] In some embodiments, step S2, "The business application platform establishes a first VPN instance for the target user in the edge devices of multiple service provider private networks according to the target user's business needs," includes: Step S21: The business application platform determines the target business resources required by the target user based on the business requirements.

[0036] Step S22: The business application platform determines the first resource allocation strategy for each service provider's virtual private network based on the current remaining resources of each service provider's virtual private network and the target business resources.

[0037] Step S23: The business application platform sends the first resource allocation policy to the service provider private network management system corresponding to each service provider virtual private network in the form of a service request, and the service provider private network management system establishes the first VPN instance in the edge device according to the first resource allocation policy.

[0038] In some embodiments, step S23, "the service provider private network management system establishes the first VPN instance in the edge device according to the first resource allocation policy," includes: Step S231: The service provider private network management system determines the first target edge device based on the first resource allocation strategy and the resource occupancy of the corresponding service provider virtual private network. The first target edge device is an edge device that satisfies the first resource allocation strategy.

[0039] Step S232: Establish the first VPN instance in the first target edge device according to the first resource allocation policy.

[0040] When the system in this application addresses a user's network sharing needs, it first obtains the user's business requirements. Then, it breaks down these requirements according to the characteristics of each service provider's virtual private network (VPN), creating a first resource allocation strategy. This first resource allocation strategy includes the resources that each service provider's VPN needs to allocate to the user, such as the edge device IP address, VPN ID, VLAN ID, bandwidth, local BGP information, northbound BGP information, and other special functional requirements when establishing a VPN instance for the user. The first resource allocation strategy is then sent to the corresponding service provider's VPN management system. This system determines the edge device (first target edge device) for establishing the user's VPN instance within the service provider's VPN based on the first resource allocation strategy. The user's VPN instance (first VPN instance) is then established on the first edge device according to the first resource allocation strategy. Furthermore, when establishing the user's VPN instance, the service provider's VPN management system determines the necessary network elements for the first VPN instance based on the first resource allocation strategy, and then synchronizes the parameters in the first resource allocation strategy to the network elements at each level. This step does not restrict the configuration and activation method of the service provider's virtual private network (VPN) equipment. The service provider can use synchronous or asynchronous configuration deployment based on its system development capabilities. In synchronous mode, the service provider's VPN management system orchestrates its own VPN resources and automatically sends configuration requests to the network element control system. In asynchronous mode, the service provider's VPN management system operators can synchronize configuration requests to multi-vendor control systems in the form of work orders, based on the resources required for configuration and activation.

[0041] Step S3: The business application platform establishes a second VPN instance in its own virtual private network that is identical to the first VPN instance, based on each of the first VPN instances, so that the services of the first VPN instance can communicate with other service providers' virtual private networks through the second VPN instance.

[0042] In some embodiments, step S3, "the business application platform establishes a second VPN instance identical to the first VPN instance in its own virtual private network according to each of the first VPN instances," includes: Step S31: The business application platform determines the second target edge device based on the service provider virtual private network corresponding to each of the first resource allocation strategies. The second target edge device is the edge device in the proprietary virtual private network that is physically connected to the service provider virtual private network corresponding to each of the first resource allocation strategies.

[0043] Step S32: Therefore, the business application platform determines the corresponding second resource allocation strategy based on each of the first resource allocation strategies.

[0044] Step S33: The business application platform sends the second resource allocation strategy to the proprietary private network management system in the form of a service request. The proprietary private network management system then establishes the second VPN instance in the corresponding second target edge device according to each of the second resource allocation strategies.

[0045] To achieve interconnection across service provider virtual private networks (VPNs) without applying the applicable layer, this application establishes multiple second VPN instances within the proprietary VPN. Each second VPN instance is identical to its corresponding first VPN instance. Specifically, since a first VPN instance is established in each service provider VPN assigned the first resource allocation policy, and each service provider VPN is physically connected to an edge device within the proprietary VPN, the edge device connected to the service provider VPN assigned the first resource allocation policy within the proprietary VPN is designated as the second target edge device. A second VPN instance identical to the first VPN instance in the corresponding service provider VPN is then established on this second edge device. The first and second VPN instances share the same VPN ID, VLAN ID, and edge device interconnection address. Although the first and second VPN instances are identical, since the second VPN instance is established within the proprietary VPN, a corresponding resource allocation policy (i.e., the second resource allocation policy) needs to be sent to the proprietary VPN management system. Then, the proprietary private network management system establishes a second VPN instance in the corresponding edge device according to the second resource allocation policy. During network sharing, multiple second VPN instances communicate with each other in the proprietary virtual private network to transmit information, while each first VPN instance communicates with its corresponding second NPV instance, that is, cross-domain route transmission is performed through the EBGP dynamic routing protocol to enable user services to be interconnected across multiple service provider virtual private networks.

[0046] This application utilizes a Virtual Private Network (VPN) where edge devices interface with multiple service provider VPN edge devices. The business application platform centrally plans VPN instance information and performs consistent VPN configurations across their respective VPNs. Cross-domain routing is achieved through the EBGP dynamic routing protocol, enabling interoperability between the applicant's own VPN and other service provider VPNs. Furthermore, the network architecture of this application is flexible and scalable, allowing for flexible expansion of service provider VPNs according to business needs. By sharing network resources with multiple service providers, it maximizes the return on investment. The business application platform collaboratively orchestrates its own VPN system and the multi-service provider VPN management system. The service provider VPN management system can prioritize the deployment of vendor control systems according to business development strategies, managing these systems independently. This reduces the complexity of the business application platform's orchestration logic and management, supports partner service providers in offering unique service capabilities, and is more open and inclusive.

[0047] Example 3: Based on the foregoing embodiments, this application provides a network sharing device for multiple service providers. The various modules and units included in the device can be implemented by a processor in a computer device; of course, they can also be implemented by specific logic circuits. In the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.

[0048] like Figure 4 As shown, a network sharing device with multiple service providers includes: a first acquisition module 1, a first establishment module 2, and a second establishment module 3.

[0049] The first acquisition module 1 is used to acquire the business needs of the target user. The first establishment module 2 is used to establish a first VPN instance for the target user in the edge devices of multiple service provider private networks according to the business needs of the target user. The second establishment module 3 is used to establish a second VPN instance identical to the first VPN instance in its own virtual private network according to each first VPN instance, so that the business of the first VPN instance can communicate with other service provider virtual private networks through the second VPN instance.

[0050] The modules in the aforementioned multi-service provider network sharing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of the device in hardware form or independently of it, or stored in the memory of the processing device in software form, so that the processor can call and execute the operations corresponding to each module. It should be noted that the module division in this embodiment is illustrative and only represents a logical functional division; in actual implementation, there may be other division methods.

[0051] Example 4: Fourthly, this application provides a computer electronic production device, such as... Figure 5 As shown, it includes: at least one processor 901; and a memory 902 communicatively connected to the at least one processor 901; wherein the memory 902 stores instructions executable by the at least one processor 901, the instructions being executed by the at least one processor 901 to enable the at least one processor 901 to execute a multi-service provider network sharing method in the above embodiments.

[0052] The memory and processor are connected via a bus, which can include any number of interconnecting buses and bridges, connecting various circuits of one or more processors and memories. The bus can also connect various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and will not be described further herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by the processor is transmitted over the wireless medium via an antenna, which further receives data and transmits it to the processor.

[0053] The processor manages the bus and general processing, and also provides various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory is used to store data used by the processor during operation.

[0054] In addition, the computer device may include (but is not limited to) a data bus, an input / output (I / O) bus, a display, and input / output devices (e.g., keyboard, mouse, speakers, etc.).

[0055] The processor can communicate with external devices via the I / O bus through wired or wireless networks.

[0056] In one embodiment, the at least one computer-executable instruction may also be compiled into or comprise a software product / computer program product, wherein one or more computer-executable instructions are executed by a processor to perform the steps of the various functions and / or methods in the embodiments described herein.

[0057] Example 5: Fifthly, this application proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any of the first aspects.

[0058] Computer-readable storage media can be implemented by any type of volatile or non-volatile storage device or a combination thereof. Computer-readable storage media may include, but are not limited to, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, and computer storage media (e.g., hard disks, floppy disks, solid-state drives, removable disks, CD-ROMs, DVD-ROMs, Blu-ray discs, etc.).

[0059] Computer-readable storage media may also store at least one computer-executable program / instruction, such as computer-readable instructions. Computer-readable storage media include, but are not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Computer-readable storage media may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, a non-transitory computer-readable storage medium may be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions stored on the computer-readable storage medium, the various methods described above can be performed.

[0060] Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0061] It should be understood that the phrase "an embodiment" or "one embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "one embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0062] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0063] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0064] In the embodiments provided in this disclosure, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0065] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a controller to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0066] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein.

[0067] Those skilled in the art will understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made to them in form and detail without departing from the spirit and scope of this application.

Claims

1. A network sharing system with multiple service providers, characterized in that, include: Owned virtual private network, service provider virtual private network and business application platform; Each of the service provider virtual private networks (VPNs) is pre-connected to the proprietary VPN via physical means, enabling the service provider VPNs to communicate with each other through the proprietary VPN. The proprietary VPN is a VPN composed of multiple network element devices of a designated server, and the service provider VPN is a VPN composed of multiple network element devices of the same service provider. The business application platform is communicatively connected to the proprietary private network management system and the private network management systems of each service provider. It is used to send service requests to the proprietary private network management system and each of the service provider's private network management systems according to the user's business. This enables the proprietary private network management system to allocate resources of its proprietary virtual private network according to the sent service requests, and enables each of the service provider's private network management systems to allocate resources of the corresponding service provider's virtual private network according to the sent service requests.

2. The system according to claim 1, characterized in that, Each of the aforementioned service provider virtual private networks is pre-connected to the proprietary virtual private network via physical means, including: Any edge device of the service provider's virtual private network is pre-connected to an edge device of the proprietary virtual private network through physical means, enabling interconnection of the underlying networks.

3. The system according to claim 1, characterized in that, Also includes: When the business application platform receives a first virtual private network access request from the target service provider, the business application platform determines the target interface point with the first virtual private network in its own virtual private network; The business application platform determines the first edge device that connects its own virtual private network to the first virtual private network based on the target connection point; After the first edge device completes a physical pre-connection with the first virtual private network, the business application platform obtains the access resource information of the first virtual private network.

4. A network sharing method for multiple service providers, applicable to the system described in any one of claims 1-3, characterized in that, include: The business application platform acquires the business needs of target users; The business application platform establishes the first VPN instance of the target user in the edge devices of multiple service provider private networks according to the target user's business needs; The business application platform establishes a second VPN instance identical to the first VPN instance in its own virtual private network based on each first VPN instance, so that the services of the first VPN instance can communicate with other service providers' virtual private networks through the second VPN instance.

5. The method according to claim 4, characterized in that, The business application platform establishes a first VPN instance for the target user in multiple service provider private network edge devices according to the target user's business needs, including: The business application platform determines the target business resources required by the target user based on the business requirements. The business application platform determines the first resource allocation strategy for each service provider's virtual private network based on the current remaining resources of each service provider's virtual private network and the target business resources. The business application platform sends the first resource allocation policy to the service provider private network management system corresponding to each service provider virtual private network in the form of a service request. The service provider private network management system then establishes the first VPN instance in the edge device according to the first resource allocation policy.

6. The method according to claim 5, characterized in that, The service provider's private network management system establishes the first VPN instance in the edge device according to the first resource allocation policy, including: The service provider private network management system determines the first target edge device based on the first resource allocation strategy and the resource usage of the corresponding service provider virtual private network. The first target edge device is the edge device that meets the first resource allocation strategy. The first VPN instance is established in the first target edge device according to the first resource allocation policy.

7. The method according to claim 6, characterized in that, The business application platform establishes a second VPN instance identical to the first VPN instance in its own virtual private network based on each of the first VPN instances, including: The business application platform determines the second target edge device based on the service provider virtual private network corresponding to each of the first resource allocation strategies. The second target edge device is the edge device in the proprietary virtual private network that is physically connected to the service provider virtual private network corresponding to each of the first resource allocation strategies. Therefore, the business application platform determines the corresponding second resource allocation strategy based on each of the first resource allocation strategies; The business application platform sends the second resource allocation strategy to its own private network management system in the form of a service request. The private network management system then establishes the second VPN instance in the corresponding second target edge device according to each of the second resource allocation strategies.

8. A network sharing device with multiple service providers, characterized in that, include: The first acquisition module is used to acquire the business needs of the target user; The first establishment module is used to establish a first VPN instance for the target user in the edge devices of multiple service provider private networks according to the target user's business needs; The second establishment module is used to establish a second VPN instance in its own virtual private network based on each of the first VPN instances, so that the services of the first VPN instances can communicate with other service providers' virtual private networks through the second VPN instance.

9. A computer electronic production equipment, characterized in that, It includes a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method according to any one of claims 4 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 4 to 7.