A method and apparatus for configuring service characteristics of a terminal device

CN122845404APending Publication Date: 2026-09-29HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510378077.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

目前,部署园区常见的接口级的业务特性,需要在接入层的接入设备上进行配置,配置业务特性的效率较低

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845404A_ABST
    Figure CN122845404A_ABST
Patent Text Reader

Abstract

This application provides a method for configuring service characteristics of terminal devices, applied to a central device. The method includes: obtaining service characteristic configuration information for a user group. The user group includes multiple terminal devices, and all terminal devices in the user group are of the same type, with identical service characteristics deployed on terminal devices of the same type. The service characteristic configuration information of the user group is associated with multiple access interfaces corresponding to the user group, so as to execute the service characteristics corresponding to the service characteristic configuration information on multiple terminal devices in the user group based on the multiple access interfaces. The multiple access interfaces include a first access interface, which is an interface on a first access device. The first terminal device among the multiple terminal devices connects to the first access device through the first access interface to access the network. Using this solution, multiple access interfaces corresponding to the user group can be configured in batches on the central device, thereby effectively improving the efficiency of configuring service characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and in particular to a method and apparatus for configuring service characteristics of a terminal device. Background Technology

[0002] The campus network adopts a three-layer network architecture of "access + aggregation + core". The access layer provides access methods for terminal devices and is the first layer for terminal devices to access the network. The aggregation layer is the network boundary between the access layer and the campus core backbone network. The aggregation layer is mainly used to forward east-west traffic between terminal devices and north-south traffic between the access layer and the core layer. The core layer is the core of data exchange in the campus and is responsible for high-speed interconnection of the entire campus network. The core layer can connect various components of the campus network, such as data centers and the aggregation layer.

[0003] To improve the security of the campus network, it needs to support certain service features, such as the common network access control (NAC) function. Currently, deploying common interface-level service features in a campus network requires configuration on the access layer access devices, which is inefficient. In some scenarios, "service features" can also be referred to as "service functions."

[0004] Therefore, a solution is urgently needed to address the above problems. Summary of the Invention

[0005] This application provides a method and apparatus for configuring service characteristics of a terminal device, which can improve the efficiency of configuring service characteristics.

[0006] Firstly, this application provides a method for configuring service characteristics of terminal devices. This method is applied to a central device, which obtains service characteristic configuration information for a user group. This service characteristic configuration information is the configuration information required to implement the service characteristics. The user group includes multiple terminal devices, and all terminal devices in the user group are of the same type, with identical service characteristics deployed on terminal devices of the same type. After obtaining the service characteristic configuration information of the user group, the user group's service characteristic configuration information is associated with multiple access interfaces corresponding to the user group, so as to execute the service characteristics corresponding to the service characteristic configuration information on the multiple terminal devices in the user group based on the multiple access interfaces. The multiple access interfaces include a first access interface, which is an interface on a first access device. The first terminal device among the multiple terminal devices connects to the first access device through the first access interface to access the network. Using the solution provided in this application, for service characteristics executed on terminal devices based on access interfaces, it is not necessary to configure each access interface individually. Instead, user groups are used as configuration objects, and the service characteristic configuration information of the user group is associated with multiple access interfaces corresponding to the user group. In other words, multiple access interfaces corresponding to the user group are configured in batches on the central device, thereby effectively improving the efficiency of configuring service characteristics.

[0007] In one possible implementation, after associating the aforementioned service characteristic configuration information with multiple access interfaces, the central device also generates service characteristic-related table entries. These service characteristic-related table entries include entries corresponding to each terminal device in the user group. As a specific example, the central device generates table entries corresponding to a first terminal device based on the service characteristic configuration information. These entries are used by the central device to perform validity checks on packets from the first terminal device. The table entries corresponding to the first terminal device include the access location information of the first terminal device on the first access device, which indicates the first access interface. Since the table entries corresponding to the first terminal device include the access location information of the first terminal device on the first access device, the central device can combine this access location information with the validity checks on packets from the first terminal device based on the table entries corresponding to the first terminal device, thereby achieving access location-level security checks.

[0008] In one possible implementation, the central device receives a second message sent by the first access device. This second message is obtained by the first access device based on a first message sent by the first terminal device to the first access device. The second message includes the access location information, and the first access interface is the interface on the first access device used to receive the first message. After receiving the second message, the central device parses it to obtain the access location information and, based on the first access interface indicated by the access location information, queries the service characteristic configuration information associated with the first access interface. Further, the central device generates entry information corresponding to the first terminal device based on the queried service characteristic configuration information and the access location information carried in the aforementioned second message. This allows the central device to subsequently perform legality verification on messages from the first terminal device based on the entry information of the first terminal device, thereby implementing access location-level security verification on the central device.

[0009] In one possible implementation, after associating the aforementioned service characteristic configuration information with multiple access interfaces, the central device also sends indication information to the first access device. This indication information instructs the first access device, upon receiving a message from the first terminal device through the first access interface, to send the access location information of the first terminal device on the first access device to the central device. In this way, after receiving the aforementioned first message, the first access device does not directly send the first message to the central device. Instead, according to the indication information, it obtains a second message including the access location information based on the first message and sends the second message to the central device. Correspondingly, after receiving the second message, the central device further generates the aforementioned entry information for the first terminal device, thereby implementing access location-level security verification on the central device.

[0010] In one possible implementation, considering that in practice, a virtual local area network (VLAN) identifier can be assigned to the first access interface, for example, a first VLAN identifier can be assigned to the first access interface, which can uniquely identify the first access interface on the first access device. Therefore, in one example, the access location information is: the first VLAN identifier assigned to the first access interface.

[0011] In one possible implementation, the service feature configuration information includes at least one security configuration piece of information and a second VLAN identifier for the service corresponding to the user group. Wherein: at least one security configuration piece of information refers to configuration information that implements at least one security feature. This solution enables batch configuration of security configuration information and second VLAN identifiers for multiple access interfaces corresponding to user groups on the central device, improving the efficiency of configuring security configuration information and second VLAN identifiers.

[0012] In one possible implementation, each terminal device in the user group is an office terminal device. Using this solution, for multiple access interfaces corresponding to multiple office terminal devices, service feature configuration information can be configured in batches on the central device, thereby improving the efficiency of configuring service features.

[0013] In one possible implementation, each terminal device in the user group is a security monitoring device. Using this solution, for multiple access interfaces corresponding to multiple security monitoring devices, service characteristic configuration information can be configured in batches on the central device, thereby improving the efficiency of configuring service characteristics.

[0014] In one possible implementation, each terminal device in the user group is an Internet Protocol phone (IP phone). Using this solution, service feature configuration information can be configured in batches on the central device for multiple access interfaces corresponding to multiple IP phones, thereby improving the efficiency of configuring service features.

[0015] In one possible implementation, each terminal device in the user group is a printer. Using this solution, service feature configuration information can be configured in batches on the central device for multiple access interfaces corresponding to multiple printers, thereby improving the efficiency of configuring service features.

[0016] In one possible implementation, the central device is a core layer network device. Using this solution, for service characteristics executed on terminal devices based on access interfaces, it is unnecessary to configure each access interface individually. Instead, configuration is performed in batches on the core layer network device for multiple access interfaces corresponding to the user group, thereby effectively improving the efficiency of configuring service characteristics.

[0017] In one possible implementation, the central device is a network device at the aggregation layer. Using this solution, for service characteristics executed on terminal devices based on access interfaces, it is not necessary to configure each access interface individually. Instead, configuration is performed in batches on the aggregation layer network device for multiple access interfaces corresponding to the user group, thereby effectively improving the efficiency of configuring service characteristics.

[0018] In one possible implementation, the central device is a firewall. Using this solution, for service characteristics executed on terminal devices based on access interfaces, it is unnecessary to configure each access interface individually. Instead, multiple access interfaces corresponding to the user group are configured in batches on the firewall, thereby effectively improving the efficiency of configuring service characteristics.

[0019] Secondly, this application provides a configuration device for terminal device service characteristics, applied to a central device. The device includes a processing unit, configured to: acquire service characteristic configuration information of a user group, wherein the user group includes multiple terminal devices, and each terminal device in the user group is of the same type, and the service characteristics deployed on terminal devices of the same type are the same, the service characteristic configuration information being configuration information required to implement the service characteristics; associate the service characteristic configuration information of the user group with multiple access interfaces corresponding to the user group, so as to implement the execution of the service characteristics corresponding to the service characteristic configuration information on the multiple terminal devices in the user group based on the multiple access interfaces, wherein the multiple access interfaces include a first access interface, the first access interface being an interface on a first access device, and the first terminal device among the multiple terminal devices connecting to the first access device through the first access interface to access the network.

[0020] In one possible implementation, the apparatus further includes: a sending unit, configured to send indication information to the first access device, the indication information being configured to instruct the first access device to send access location information of the first terminal device on the first access device to the central device when the first access device receives a message from the first terminal device through the first access interface, wherein the access location information is used to indicate the first access interface.

[0021] In one possible implementation, the processing unit is further configured to: generate table entry information corresponding to the first terminal device according to the service characteristic configuration information, wherein the table entry information is used by the central device to perform legality verification on packets from the first terminal device, and wherein the table entry information includes access location information of the first terminal device on the first access device.

[0022] In one possible implementation, the processing unit generates table entry information corresponding to the first terminal device based on the service characteristic configuration information, specifically including: receiving a second message sent by the first access device, the second message being obtained by the first access device based on a first message sent by the first terminal device to the first access device, the second message including the access location information, and the first access interface being an interface on the first access device used to receive the first message; querying the service characteristic configuration information associated with the first access interface according to the first access interface indicated by the access location information; and generating the table entry information based on the service characteristic configuration information and the access location information.

[0023] In one possible implementation, the access location information includes: a first virtual local area network (VLAN) identifier assigned to the first access interface.

[0024] In one possible implementation, the service feature configuration information includes: at least one security configuration information and a second VLAN identifier for the service corresponding to the user group.

[0025] In one possible implementation, each terminal device in the user group is: an office terminal device, a security monitoring device, an Internet Protocol (IP) phone, or a printer.

[0026] In one possible implementation, the central device includes: a core layer network device, or an aggregation layer network device, or a firewall.

[0027] Thirdly, this application provides an apparatus. The apparatus includes a processor and a memory. The memory is used to store instructions or computer programs. The processor is used to execute the instructions or computer programs stored in the memory, performing the methods described in the first aspect and any one of the first aspects above. This apparatus is also referred to as a terminal device service characteristic configuration device or a communication device.

[0028] Fourthly, this application provides a computer-readable storage medium, including instructions or a computer program, which, when run on a computer, cause the computer to perform the methods described in the first aspect above and any one of the first aspects above.

[0029] Fifthly, this application provides a computer program product comprising instructions or a computer program, which, when run on a computer, causes the computer to perform the methods described in the first aspect above and any one of the first aspects above. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0031] Figure 1a A schematic diagram of a campus network structure is shown;

[0032] Figure 1b This diagram illustrates a configuration process tailored to business characteristics.

[0033] Figure 2 A flowchart illustrating a method for configuring service features of a terminal device according to an embodiment of this application;

[0034] Figure 3 This diagram illustrates a configuration process tailored to business characteristics.

[0035] Figure 4 A flowchart illustrating a method for generating table entry information provided in an embodiment of this application;

[0036] Figure 5 A schematic diagram of a message structure provided in an embodiment of this application;

[0037] Figure 6 A flowchart illustrating a communication method provided in an embodiment of this application;

[0038] Figure 7 A flowchart illustrating yet another communication method provided in an embodiment of this application;

[0039] Figure 8 A schematic diagram of a configuration device for service characteristics of a terminal device provided in an embodiment of this application;

[0040] Figure 9 This is a schematic diagram of the structure of a device provided in an embodiment of this application. Detailed Implementation

[0041] This application provides a method and apparatus for configuring service characteristics of a terminal device, which can improve the efficiency of configuring service characteristics.

[0042] To facilitate understanding, a brief introduction to the campus network will be given first. (See also...) Figure 1a , Figure 1a A schematic diagram of a campus network structure is shown.

[0043] like Figure 1aAs shown: The campus network adopts a three-layer network architecture of "access + aggregation + core". Among them:

[0044] The access layer provides access methods for terminal devices and is the first layer for terminal devices to access the network. The access layer typically consists of access (ACC) switches, which are numerous in the network and installed in various locations; they are usually simple Layer 2 switches. In one example, although... Figure 1a Although not shown in the diagram, the access layer may also include wireless access point (AP) devices. AP devices establish connections with wireless terminal devices and access the network through access switches, thereby enabling wireless terminal devices to access the network.

[0045] The aggregation layer serves as the network boundary between the access layer and the core backbone network of the campus. It primarily forwards east-west traffic between terminal devices and north-south traffic traveling from the access layer to the core layer. The aggregation layer can act as a switching core within a department or region, enabling connections to dedicated servers within that region or region. Furthermore, the aggregation layer can expand the number of access terminals. It comprises multiple aggregation (AGG) switches.

[0046] The core layer is the heart of data exchange in the campus network, responsible for high-speed interconnection across the entire campus network. The core layer comprises multiple core switches. It connects various components of the campus network, such as data centers and aggregation layers. To achieve high bandwidth utilization and rapid network fault convergence, high-performance core switches are typically deployed. For wireless networks, the core layer includes a WLAN access controller (WAC), which manages access points (APs) using the CAPWAP (Control and Provisioning of Wireless Access Points) protocol.

[0047] exist Figure 1a For ease of understanding, the diagram illustrates one core switch (CORE), two aggregation switches, and three access switches. The two aggregation switches are AGG1 and AGG2, and the three access switches are ACC1, ACC2, and ACC3. ACC1, ACC2, and ACC3 can each connect to multiple terminal devices, enabling these devices to access the campus network. Figure 1aFor ease of understanding, only the two terminal devices connected to ACC1 are shown. ACC1's interface 1 connects to terminal device 1, and ACC1's interface 2 connects to terminal device 2. ACC1's interface 1 is the access point for terminal device 1 on ACC1, and ACC1's interface 2 is the access point for terminal device 2 on ACC1. ACC1's interface 1 is also the access interface for terminal device 1 to access the campus network; terminal device 1 connects to ACC1 through this interface to access the campus network. ACC1's interface 2 is also the access interface for terminal device 2 to access the campus network; terminal device 2 connects to ACC2 through this interface to access the campus network.

[0048] exist Figure 1a In this context, the interface information is represented by a number (i.e., a digit). However, the interface information is not limited to the interface number; it can also include other identifying information that can uniquely identify an interface, such as the interface index or the interface name.

[0049] In addition, although Figure 1a Although not shown in the diagram, the campus network also includes security devices, such as firewalls.

[0050] Currently, deploying common interface-level service features in a campus network requires configuration on the access layer devices, which is inefficient. Specifically, for each terminal device that needs to deploy service features, each access interface of that terminal device accessing the campus network needs to be configured separately to enable the aforementioned service features to be implemented on each terminal device based on those access interfaces.

[0051] There are several ways to configure the access interface. Two possible implementation methods are described below.

[0052] First implementation method:

[0053] An embedded network management system runs on the core device, and access devices connect to it via Simple Network Management Protocol (SNMP) or Network Configuration Protocol (Netconf). This allows administrators to configure all access devices simply by logging into the core device and using the embedded network management system. Specifically, the administrator logs into the core device to configure each of the aforementioned access interfaces. Here, the core device refers to the network device at the core layer.

[0054] The second implementation method:

[0055] Through stacking technology, a chip cascading protocol runs between the core device and the access devices, virtualizing each access device as a single board of the core device. In this scenario, the core device can run the chip cascading protocol with each of the multiple access devices, thus treating each access device as its own single board. Correspondingly, the core device configures these multiple access interfaces.

[0056] However, whether running embedded network management on the core device or using stacking technology to virtualize access devices as a single board of the core device, each of the aforementioned access interfaces requires separate configuration. With a large number of access devices and interfaces to be configured, this leads to low configuration efficiency. (This can be combined with...) Figure 1b To understand, Figure 1b This diagram illustrates a process for configuring business characteristics.

[0057] Suppose we need to configure a certain service feature on N access interfaces, then the configuration process for a single access interface is as follows: Figure 1b As shown, it includes the following steps A1 to A2.

[0058] Step A1: Log in to the access device corresponding to the access interface on the core device, and select an access interface that needs to be configured from the interfaces corresponding to the access device.

[0059] Step A2: Bind the access interface selected in Step A1 to the service characteristics that need to be configured.

[0060] By repeating steps A1 to A2 N times, the configuration of the aforementioned N access interfaces can be achieved.

[0061] The larger the value of N, the more times steps A1 to A2 need to be repeated, and consequently, the lower the efficiency of configuring business features.

[0062] In view of this, this application provides a method and apparatus for configuring service characteristics of a terminal device, which can improve the efficiency of configuring service characteristics.

[0063] See Figure 2 The figure is a flowchart illustrating a method for configuring service features of a terminal device according to an embodiment of this application.

[0064] Figure 2 The method shown, for example, is applied to Figure 1a The application scenarios shown are executed by the central device.

[0065] Figure 2The first access device in the method shown is one of the access devices in the access layer. The first access device includes a first access interface, which is an interface on the first access device. The first access interface is the interface through which the first access device and the first terminal device are connected. In other words, the first terminal device can connect to the first access device through the first access interface to access the network. The first access interface is also referred to as the access location of the first terminal device on the first access device.

[0066] In one example, the central device and the access devices belong to the same network. For instance, both the central device and the first access device are devices in a campus network. In this scenario, the central device could be a core layer network device, an aggregation layer network device, or a firewall. The core layer network device could be a core layer switch (i.e., a core switch) or a core layer router. The aggregation layer network device could be an aggregation layer switch (i.e., an aggregation switch) or an aggregation layer router.

[0067] Figure 2 The method shown includes steps S1-S2.

[0068] S1: The central device obtains the service characteristic configuration information of the user group. The user group includes multiple terminal devices, and each terminal device in the user group is of the same type. The service characteristics deployed on the terminal devices of the same type are the same. The service characteristic configuration information is the configuration information required to implement the service characteristics.

[0069] In one example, the administrator inputs a command to the central device via the command line, indicating the service feature configuration information. The central device then obtains the input command to acquire the service feature configuration information.

[0070] In another example, the administrator inputs a configuration file indicating the service feature configuration information into the central device, and the central device obtains the input configuration file to obtain the service feature configuration information.

[0071] This application does not specifically limit the service characteristic configuration information; the service characteristic configuration information is related to specific service characteristics. In a specific example, the service characteristic configuration information includes at least one security configuration information and a second VLAN identifier for the service corresponding to the user group. Wherein:

[0072] At least one security configuration information refers to configuration information that implements at least one security feature. The security features mentioned here include, but are not limited to, one or more of the following: Dynamic Host Configuration Protocol Snooping (DHCP SNP), Address Resolution Protocol (ARP), Media Access Control Limit (MAC limit), and Storm Control.

[0073] The DHCP SNP feature refers to the support for traffic filtering based on DHCP SNP entry information.

[0074] ARP features refer to the ability to support ARP entry learning and ARP entry updating.

[0075] The MAC limit feature refers to limiting the number of MAC addresses that can be learned for a specific access port.

[0076] The storm control feature is used to prevent packets from being transmitted continuously in the ring network in loop scenarios, thus maliciously consuming network bandwidth.

[0077] In this application, the user group includes multiple terminal devices, which access the network through at least one access device. Any one of these access devices can connect to at least one of the multiple terminal devices. For example, the first access device can connect to at least one first terminal device, allowing the first terminal device to access the network via a first access interface.

[0078] All terminal devices in the user group are of the same type. Examples of terminal device types include: office terminal equipment, security monitoring equipment, IP phones, or printers.

[0079] Office terminal equipment includes, for example, desktop computers or laptops.

[0080] Security monitoring equipment includes, for example, surveillance cameras.

[0081] An IP-phone is an independent telephone device that uses the IP network protocol as its primary communication protocol and network ports or wireless communication technologies (Wi-Fi) as its primary interface, and has dialing and calling functions.

[0082] A printer is a device that has printing capabilities. It can connect to office terminal equipment, receive printing instructions from the office terminal equipment, and then perform printing operations.

[0083] In this application, the services deployed on terminal devices of the same type are identical; therefore, the service characteristics deployed on terminal devices of the same type are also identical. Specifically, the service characteristics deployed on the terminal device refer to the service characteristics deployed on the access interface of the terminal device accessing the network, thereby enabling the execution of corresponding service characteristics on the terminal device based on the access interface.

[0084] Examples of services deployed on various types of terminal devices are provided below:

[0085] The services deployed on office terminal devices primarily access the internet. The services deployed on security monitoring devices primarily upload footage captured by the monitoring equipment to the corresponding server. The services deployed on IP phones primarily establish connections with the server corresponding to the session, thereby establishing sessions with other terminal devices (such as other IP phones) through that server. The services deployed on printing devices primarily receive print commands from office terminal devices and then execute the print operation.

[0086] S2: The central device associates the service characteristic configuration information of the user group with multiple access interfaces corresponding to the user group, so as to execute the service characteristics corresponding to the service characteristic configuration information on multiple terminal devices in the user group based on the multiple access interfaces. The multiple access interfaces include a first access interface, which is an interface on a first access device. The first terminal device among the multiple terminal devices connects to the first access device through the first access interface to access the network.

[0087] In this application, since the service characteristics deployed on terminal devices of the same type are identical, the aforementioned service characteristic configuration information for a user group can be applied to each terminal device in that user group. Furthermore, the service characteristics deployed on the terminal devices are implemented through the access interfaces of the terminal devices accessing the network. Therefore, after the central device obtains the service characteristic configuration information for the user group, it associates the service characteristic configuration information of the user group with multiple access interfaces corresponding to the user group, so as to execute the service characteristics corresponding to the service characteristic configuration information on multiple terminal devices in the user group based on the multiple access interfaces. Wherein:

[0088] The multiple access interfaces corresponding to the user group include: the access interface for each of the multiple terminal devices to access the network. The first terminal device is any one of the terminal devices in the user group. The first terminal device accesses the network through the first access interface. Therefore, the multiple access interfaces include at least the first access interface.

[0089] Associating the service characteristic configuration information with the multiple access interfaces involves establishing an association between the service characteristic configuration information and the multiple access interfaces, essentially binding the service characteristic configuration information to the multiple access interfaces. Associating the service characteristic configuration information with the multiple access interfaces means batch configuring service characteristics for multiple access interfaces corresponding to user groups. Specifically, establishing the association between the service characteristic configuration information and the multiple access interfaces involves establishing an association between the service characteristic configuration information and the interface information of the multiple access interfaces. Regarding interface information, please refer to the relevant description above; it will not be repeated here.

[0090] As described above, the solution provided in this application eliminates the need for individual configuration of each access interface for service characteristics executed on terminal devices based on access interfaces. Instead, it uses user groups as configuration objects, batch configuring multiple access interfaces corresponding to a user group on the central device. This effectively improves the efficiency of configuring service characteristics. (See reference...) Figure 3 To understand, Figure 3 This diagram illustrates a process for configuring business characteristics.

[0091] like Figure 3 As shown, the process of configuring business characteristics includes the following steps B1 to B2.

[0092] Step B1: The central device obtains the service characteristic configuration information corresponding to the user group. The service characteristic configuration information includes at least one security configuration information and the second VLAN corresponding to the service.

[0093] Step B2: The central device binds the service characteristic configuration information to multiple access interfaces corresponding to the user group.

[0094] By comparison Figure 3 The configuration process shown and Figure 1b As can be seen from the configuration process shown, using Figure 3 The proposed solution, even with a large number of access interfaces requiring configuration of business characteristics, utilizes... Figure 3 The solution shown can also configure a large number of access interfaces in batches, without needing to... Figure 1b As shown, it is necessary to repeat almost the same configuration operation multiple times, therefore, utilizing Figure 3 The configuration method shown can effectively improve the efficiency of configuring business characteristics.

[0095] Currently, to implement the aforementioned service characteristics, the access device (e.g., the first access device) needs to generate table entries corresponding to these service characteristics so that the terminal devices can subsequently execute the service characteristics based on these table entries. However, the process of creating these table entries consumes certain memory resources, and access devices are generally ordinary Layer 2 switches with limited resources. Therefore, the limited resources of the access switch cannot support the deployment of many service characteristics, while not deploying service characteristics may lead to network security compromises.

[0096] The above problems could be solved by replacing all access devices with high-specification devices that have abundant resources. However, with a large number of access devices, this approach would result in high costs.

[0097] Therefore, in this application, considering that the central device has more resources than the access devices, the central device generates table entries related to service characteristics. Furthermore, the table entries generated by the central device include the access location of the terminal devices, thereby enabling access location-level service characteristic deployment on the central device.

[0098] The central device generates service-specific entries, including entries corresponding to each terminal device in the user group. As a specific example, the central device generates entries corresponding to a first terminal device based on service-specific configuration information. These entries are used by the central device to perform validity checks on packets from the first terminal device. The entries for the first terminal device include the access location information of the first terminal device on the first access device, which indicates the first access interface. Because the entries for the first terminal device include this access location information, the central device can combine this access location information with the validity checks on packets from the first terminal device based on these entries, thus achieving access location-level security verification.

[0099] For details on the specific implementation of the central device generating the table entry information corresponding to the first terminal device, please refer to the following text. Figure 4 The description of the method shown will not be repeated here.

[0100] In this embodiment, entry information is stored in a table, and a table may include multiple entries. For example, one row in the table corresponds to one entry. The entry information mentioned in this embodiment refers to one entry in the table. For example, DHCP SNP entry information refers to one entry in the DHCP SNP table.

[0101] Regarding the access location information of the first terminal device on the first access device, this application embodiment does not specifically limit it, as long as the access location information can uniquely identify the first access interface on the first access device.

[0102] Considering that in practice, a VLAN identifier can be assigned to the first access interface, for example, a first VLAN identifier can be assigned to the first access interface. This first VLAN identifier can uniquely identify the first access interface on the first access device. Therefore, in one example, the access location information is: the first VLAN identifier assigned to the first access interface. In this scenario, both the first access device and the central device store the correspondence between the first VLAN identifier and the first access interface, for example, referring to Table 1. The value of the first VLAN identifier is 5, corresponding to interface 1 on the first access device.

[0103] Table 1

[0104] First VLAN ID First access interface 5 Access device interface 1

[0105] Furthermore, considering that in practical applications, the combination of the name of the first access device and the interface identifier of the first access interface can uniquely identify the first access interface on the first access device, in another example, the access location information is: the name of the first access device and the interface identifier of the first access interface. The interface identifier of the first access interface includes, but is not limited to, the interface name and interface number of the first access interface.

[0106] Next, we will introduce the process by which the central device generates the table entry information corresponding to the first terminal device.

[0107] See Figure 4 The figure is a flowchart illustrating a method for generating table entry information provided in an embodiment of this application. Figure 4 The method shown includes the following steps S101-S106.

[0108] S101: The first access device receives the first message sent by the first terminal device through the first access interface, where the first access interface is an interface on the first access device.

[0109] A first terminal device sends a first message to a first access device, and the first message sent by the first terminal device is received by the first access interface of the first access device. The type of the first message is not specifically limited in this embodiment. In one example, the first message is a control message; in another example, the first message is a service message.

[0110] This application does not specifically limit the content included in the first message.

[0111] In one example, the first message includes the MAC address of the first terminal device, which serves as the source MAC address of the first message.

[0112] If the first terminal device has already been assigned an IP address, then in one example, the first message also includes the IP address of the first terminal device, which serves as the source IP address of the first message. In this scenario, the first message is, for example, a service message.

[0113] If the first terminal device has not yet been assigned an IP address, the first message will not include the IP address of the first terminal device. In this scenario, the first message may be, for example, a DHCP request message, used to request the DHCP server to assign an IP address to itself.

[0114] S102: The first access device obtains a second message based on the first message. The second message includes access location information, which is used to indicate the first access interface on the first access device.

[0115] After receiving the first message through the first access interface, the first access device processes the first message to obtain a second message. Specifically, the first access device processes the first message according to access location information to obtain a second message including the access location information. The access location information indicates the access location of the first terminal device on the first access device. Since the first access device uses the first access interface to receive the first message sent by the first terminal device, the access location of the first terminal device on the first access device is the first access interface; therefore, the aforementioned access location information indicates the first access interface on the first access device.

[0116] Regarding the access location information, please refer to the relevant description above; it will not be repeated here.

[0117] The embodiments of this application do not specifically limit the specific implementation method of the first access device processing the first message to obtain the second message.

[0118] In one example, the first access device adds the access location information to the available fields in the first message to obtain the second message.

[0119] In another example, the first access device re-encapsulates the first packet using access location information to obtain the second packet. As a specific example, the first packet includes one layer of VLAN encapsulation. The first access device adds an outer layer of VLAN encapsulation to the first packet to obtain the second packet, and the access location information is located within this outer VLAN encapsulation. In this scenario, the second packet includes two layers of VLAN encapsulation; the outer VLAN encapsulation carries the aforementioned access location information, and the inner VLAN encapsulation is the same as the VLAN encapsulation included in the first packet.

[0120] The outer and inner VLAN encapsulation have the same structure, both including: Tag Protocol Identifier (TPID), Priority (PRI), Canonical Format Indicator (CFI) field, and VLAN Identifier (VID) field. The specific functions of the TPID, PRI, CFI, and VID fields are not detailed here.

[0121] When the access location information is the first VLAN identifier, the first VLAN identifier is, for example, located in the VID field of the outer VLAN encapsulation of the second packet.

[0122] In one example, if the first packet includes a VLAN encapsulation layer, then in that example, the VLAN encapsulation of the first packet includes the aforementioned second VLAN identifier. This second VLAN identifier is the VLAN identifier corresponding to the service associated with the first terminal device, that is, the second VLAN identifier of the service associated with the user group. By carrying the second VLAN identifier in the VLAN encapsulation of the first packet, the network device can perform operations related to the second VLAN identifier. Since the VLAN encapsulation of the first packet is the inner VLAN encapsulation of the second packet, the inner VLAN encapsulation of the second packet includes the second VLAN identifier.

[0123] Regarding the first and second messages, now combined with Figure 5 Please provide an explanation. Figure 5 This is a schematic diagram of a message structure provided in an embodiment of this application. Figure 5 As shown:

[0124] The first packet includes: Destination MAC Address (DMAC), Source MAC Address (SMAC), 802.1Q Tag field 501, Ethernet Type (ETH-Type), Data field, and Frame Check Sequence (FCS) field. The 802.1Q Tag field 401 is the VLAN encapsulation for the first packet. The ETH-Type field in the first packet can be replaced with the length field.

[0125] The second message adds an outer VLAN encapsulation to the first message; this outer VLAN encapsulation is... Figure 5 The 802.1Q tag field 502 shown, and the 802.1Q tag field 501 in the second packet, are also referred to as the inner VLAN encapsulation of the second packet. Figure 5 The encapsulation method of the second packet shown is also known as QinQ (802.1Q-in-802.1Q) encapsulation. QinQ is also called VLAN Stacking or Double VLAN.

[0126] Although Figure 5 The first and second messages shown do not include three-layer encapsulation, however, Figure 5 The images shown are for ease of understanding of outer and inner VLAN encapsulation and do not imply that the first and second packets do not include Layer 3 encapsulation. In some scenarios, both the first and second packets include Layer 3 encapsulation. This Layer 3 encapsulation includes at least the source IP address and the destination IP address.

[0127] S103: The first access device sends the second message to the central device, the second message being used by the central device to generate table entry information including the access location information.

[0128] S104: The central device receives the second message sent by the first access device.

[0129] S105: The central device queries the service characteristic configuration information associated with the first access interface based on the first access interface indicated by the access location information.

[0130] S106: The central device generates table entry information including the access location information based on the access location information and the service characteristic configuration information.

[0131] In one example, after executing the aforementioned S1-S2, the central device also sends indication information to the first access device. This indication information instructs the first access device, upon receiving a message from the first terminal device via the first access interface, to send the access location information of the first terminal device on the first access device to the central device. As a specific example, the indication information instructs the first access device, upon receiving a message from the first terminal device via the first access interface, to add the access location information of the first terminal device to the message and then send the message with the added access location information to the central device. In this way, after receiving the first message, the first access device does not directly send the first message to the central device. Instead, according to the indication information, it obtains a second message including the access location information based on the first message and sends the second message to the central device. The access location information in the second message enables the central device to generate table entries including the access location information. Specifically, the access location information in the second message enables the central device to generate table entries corresponding to the first terminal device, and these table entries must include the access location information.

[0132] After receiving the second message sent by the first access device, the central device extracts the access location information from the second message. As described above, the central device stores a correspondence similar to that shown in Table 1. Therefore, after extracting the access location information, the central device determines the first access interface indicated by the access location information based on the correspondence shown in Table 1. Further, a query is performed using the first access interface as an index to obtain the service characteristic configuration information associated with the first access interface. After obtaining the service characteristic configuration information, the central device further generates table entries that include the access location information and correspond to the service characteristics indicated by the service characteristic configuration information, based on the access location information and the service characteristic configuration information.

[0133] Furthermore, although in the above examples, after receiving the first message, the first access device sends the access location information to the central device in a second message obtained based on the first message, in other examples, the first access device, after receiving the first message, may not modify the first message but instead send another message independent of the first message, carrying the aforementioned access location information in that message to the central device. This allows the central device to generate the corresponding table entry information for the first terminal device based on the access location information.

[0134] In this application, the table entry information includes, in addition to the access location information, information about the first terminal device. This information includes, but is not limited to, the name of the first terminal device, the type of the first terminal device, the address of the first terminal device, or the VLAN identifier (i.e., the aforementioned second VLAN identifier) ​​corresponding to the service provided by the first terminal device. The address of the first terminal device includes, but is not limited to, the IP address and / or the MAC address of the first terminal device.

[0135] In a specific example, the service characteristic indicated by the aforementioned service characteristic configuration information is the DHCP SNP characteristic. In this scenario, the aforementioned entry information is DHCP SNP entry information. In this case, the entry information also includes the MAC address and IP address of the first terminal device. In this scenario, using this solution, DHCP SNP entry information related to the first terminal device can be generated on the central device, and this DHCP SNP entry information includes the access location information of the first terminal device. Optionally, in the scenario where the inner VLAN encapsulation of the second packet includes a second VLAN identifier, the DHCP SNP entry information also includes the second VLAN identifier.

[0136] As described above, in one example, the first message includes the MAC address and IP address of the first terminal device. In this case, since the second message is obtained by adding access location information to the available fields of the first message, or by encapsulating access location information on top of the first message, the second message also includes the MAC address and IP address of the first terminal device. In this case, after receiving the second message, the central device extracts the source IP address (i.e., the IP address of the first terminal device), the source MAC address (i.e., the MAC address of the first terminal device), and the access location information included in the second message, thereby generating DHCP SNP entry information including the IP address of the first terminal device, the MAC address of the first terminal device, and the access location information.

[0137] As described above, in another example, the first message includes the MAC address of the first terminal device but not its IP address. In this case, the second message also includes the MAC address of the first terminal device but not its IP address. In this scenario, after receiving the second message, the central device extracts the source MAC address and the access location information included in the second message. Furthermore, when the DHCP server sends a DHCP response message to the first terminal device through the central device, the central device obtains the IP address of the first terminal device from the DHCP message. Further, the central device generates DHCP SNP entry information including the IP address, MAC address, and access location information of the first terminal device based on the MAC address, IP address, and access location information of the first terminal device.

[0138] In one example, after generating the aforementioned DHCP SNP entry information, the central device can also intercept illegal packets based on this DHCP SNP entry information. For details, please refer to... Figure 6 , Figure 6 This is a flowchart illustrating a communication method provided in an embodiment of this application.

[0139] Figure 6 The method shown includes the following steps S201-S205.

[0140] S201: The first access device receives a third message sent by the first terminal device through the first access interface, wherein the source IP address of the third message is the IP address of the first terminal device, and the source MAC address of the third message is the MAC address of the first terminal device.

[0141] In one example, the third message is a service message.

[0142] In another example, the third message is a control message. For instance, the third message is a first ARP request message used to request the MAC address of another first terminal device. Alternatively, the third message could be a first ARP response message used to announce its own MAC address to other first terminal devices.

[0143] The third message sent by the first terminal device is received by the first access interface of the first access device.

[0144] S202: The first access device obtains a fourth message based on the third message, the fourth message including the access location information, the source IP address of the fourth message being the IP address of the first terminal device, and the source MAC address of the fourth message being the MAC address of the first terminal device.

[0145] After receiving the third message, the first access device processes it to obtain a fourth message including the access location information. The principle behind the first access device obtaining the fourth message from the third message is the same as the principle behind obtaining the second message from the first message. Therefore, for the specific implementation of "obtaining the fourth message from the third message," please refer to the previous description of "obtaining the second message from the first message" in S102; it will not be repeated here.

[0146] S203: The first access device sends a fourth message to the central device. The source MAC address, the source IP address, and the access location information in the fourth message are used by the central device to verify the legality of the fourth message.

[0147] S204: The central device receives the fourth message sent by the first access device.

[0148] S205: The central device performs a validity check on the fourth message based on the source MAC address, the source IP address, the access location information, and the DHCP SNP entry information in the fourth message.

[0149] After receiving the fourth packet, the first access device sends it to the central device, which then receives it. Upon receiving the fourth packet, the central device extracts the source IP address, source MAC address, and access location information from the packet. It then matches these extracted information with the aforementioned DHCP SNP entry. If a match is found, the fourth packet is deemed valid; otherwise, it is deemed invalid. A successful match means the DHCP SNP entry includes the extracted source IP address, source MAC address, and access location information. Conversely, if the DHCP SNP entry does not include any of these elements, the match fails. In one example, if the match fails, the central device discards the fourth packet to prevent illegal packets from continuing to transmit in the network, thus ensuring network security while preventing illegal packets from unreasonably consuming network resources.

[0150] In this application, the central device and the first access device are not only able to receive and forward messages from the first terminal device, but also to forward messages sent to the first terminal device by other devices. The following describes the methods by which the central device and the first access device forward messages sent to the first terminal device by other devices.

[0151] See Figure 7 , Figure 7 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 7 The method shown includes the following steps S301-S306.

[0152] S301: The central device receives the fifth message, and the destination device of the fifth message is the first terminal device.

[0153] In one example, the fifth message is a service message. In another example, the fifth message is a control message.

[0154] The destination device of the fifth message is the first terminal device. In one example, the destination MAC address of the fifth message is the MAC address of the first terminal device, and the destination IP address of the fifth message is the IP address of the first terminal device.

[0155] S302: The central device obtains a sixth message based on the fifth message, wherein the sixth message includes the access location information.

[0156] After receiving the fifth message, the central device queries the aforementioned table entries based on the destination IP address and destination MAC address in the fifth message, for example, by querying the aforementioned DHCP SNP table entries, to obtain the aforementioned access location information. Further, the central device obtains a sixth message including the access location information based on the fifth message and the access location information.

[0157] In one example, the central device adds the access location information to the available fields of the fifth message to obtain the sixth message.

[0158] In another example, the central device re-encapsulates the fifth packet using access location information to obtain the sixth packet. As a specific example, the fifth packet includes one layer of VLAN encapsulation. In a concrete implementation, the central device re-encapsulates the fifth packet to obtain the sixth packet by adding an outer VLAN encapsulation to the fifth packet, thus obtaining the sixth packet. Furthermore, the access location information is located within the outer VLAN encapsulation of the sixth packet. In this scenario, the sixth packet includes two layers of VLAN encapsulation: the outer VLAN encapsulation carries the aforementioned access location information, and the inner VLAN encapsulation is the same as the VLAN encapsulation included in the fifth packet.

[0159] S303: The central device sends the sixth message to the first access device.

[0160] After receiving the sixth packet, the central device sends the sixth packet to the first access device. Specifically, the central device, for example, queries its local forwarding table based on the access location information (e.g., the first VLAN identifier) ​​to determine the outgoing interface for forwarding the sixth packet, and then sends the sixth packet to the first access device through that outgoing interface. Alternatively, the central device, for example, queries its local forwarding table based on the access location information (e.g., the first VLAN identifier) ​​and the destination MAC address of the sixth packet to determine the outgoing interface for forwarding the sixth packet, and then sends the sixth packet to the first access device through that outgoing interface. The destination MAC address of the sixth packet is the same as the destination MAC address of the fifth packet.

[0161] S304: The first access device receives the sixth message sent by the central device.

[0162] S305: The first access device obtains the fifth message based on the sixth message, and the fifth message does not include the access location information.

[0163] S306: The first access device forwards the fifth message through the first access interface.

[0164] After receiving the sixth message from the central device, the access device extracts the access location information from the sixth message. Based on this access location information, the first access device determines to forward the sixth message through the first access interface. Specifically, if the access location information is the first VLAN identifier, the first access device looks up the correspondence shown in Table 1 according to the first VLAN identifier to determine that the interface used to forward the sixth message is the first access interface.

[0165] In addition, before forwarding the sixth packet, the first access device obtains the fifth packet based on the sixth packet. Obtaining the fifth packet based on the sixth packet is the reverse operation of the aforementioned S302. For example, if the sixth packet is obtained by adding an outer VLAN encapsulation to the fifth packet, the first access device strips the outer encapsulation of the sixth packet to obtain the fifth packet.

[0166] After receiving the fifth message, the first access device forwards the fifth message through the first access interface. Since the first access interface is the interface through which the first terminal device connects to the first access device, the fifth message forwarded by the first access device through the first access interface can be forwarded to the first terminal device, and correspondingly, the first terminal device can receive the fifth message.

[0167] Based on the methods provided in the above embodiments, this application also provides a corresponding apparatus, which will be described below with reference to the accompanying drawings.

[0168] See Figure 8 The figure is a schematic diagram of the structure of a terminal device service feature configuration device provided in an embodiment of this application. Figure 8 The device 800 shown is applied to a central device to perform the steps provided in the above embodiments that are executed by the central device.

[0169] like Figure 8 As shown, the device 800 includes a processing unit 801 and a sending unit 802, wherein the sending unit 802 is optional.

[0170] The processing unit 801 is used for:

[0171] Obtain the service characteristic configuration information of the user group, wherein the user group includes multiple terminal devices, and each terminal device in the user group is of the same type. The service characteristics deployed on terminal devices of the same type are the same. The service characteristic configuration information is the configuration information required to implement the service characteristics.

[0172] The service characteristic configuration information of the user group is associated with multiple access interfaces corresponding to the user group, so as to enable the execution of the service characteristics corresponding to the service characteristic configuration information on multiple terminal devices in the user group based on the multiple access interfaces. The multiple access interfaces include a first access interface, which is an interface on a first access device. The first terminal device among the multiple terminal devices connects to the first access device through the first access interface to access the network.

[0173] In one possible implementation, the sending unit 802 is configured to send indication information to the first access device. The indication information is configured to instruct the first access device to send the access location information of the first terminal device on the first access device to the central device when it receives a message from the first terminal device through the first access interface. The access location information is used to indicate the first access interface.

[0174] In one possible implementation, the processing unit 801 is further configured to: generate table entry information corresponding to the first terminal device according to the service characteristic configuration information, wherein the table entry information is used by the central device to perform legality verification on the messages from the first terminal device, wherein the table entry information includes the access location information of the first terminal device on the first access device.

[0175] In one possible implementation, the processing unit 801 generates table entry information corresponding to the first terminal device based on the service characteristic configuration information, specifically including: receiving a second message sent by the first access device, the second message being obtained by the first access device based on a first message sent by the first terminal device to the first access device, the second message including the access location information, and the first access interface being an interface on the first access device used to receive the first message; querying the service characteristic configuration information associated with the first access interface according to the first access interface indicated by the access location information; and generating the table entry information based on the service characteristic configuration information and the access location information.

[0176] In one possible implementation, the access location information includes: a first virtual local area network (VLAN) identifier assigned to the first access interface.

[0177] In one possible implementation, the service feature configuration information includes: at least one security configuration information and a second VLAN identifier for the service corresponding to the user group.

[0178] In one possible implementation, each terminal device in the user group is: an office terminal device, a security monitoring device, an Internet Protocol (IP) phone, or a printer.

[0179] In one possible implementation, the central device includes: a core layer network device, or an aggregation layer network device, or a firewall.

[0180] For details regarding the specific implementation of each unit of the device 800, and other operations that the device 800 can perform, please refer to the description of the configuration method for the service characteristics of the terminal device provided in the embodiments of this application above; these details will not be repeated here.

[0181] In this application, the aforementioned device 800 may have the following hardware structure: Figure 9 The structure shown, Figure 9 This is a schematic diagram of the structure of a device provided in an embodiment of this application.

[0182] Please see Figure 9 As shown, device 900 includes: processor 910, communication interface 920, and memory 930. The number of processors 910 in device 900 can be one or more. Figure 9 Taking a processor as an example. In this embodiment, the processor 910, communication interface 920, and memory 930 can be connected via a bus system or other means. Figure 9 Taking the connection between China and Israel via the 940 bus system as an example.

[0183] Processor 910 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. Processor 910 may further include hardware chips. These hardware chips may be application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or combinations thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.

[0184] The memory 930 may include volatile memory, such as random-access memory (RAM); the memory 930 may also include non-volatile memory, such as flash memory, hard disk drive (HDD), or solid-state drive (SSD); the memory 930 may also include combinations of the above types of memory. The memory 930 stores, for example, the aforementioned service characteristic configuration information.

[0185] Optionally, the memory 930 stores an operating system and programs, executable modules, or data structures, or subsets thereof, or extended sets thereof. The programs may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and handling hardware-based tasks. The processor 910 can read the programs from the memory 930 to implement the methods provided in the embodiments of this application.

[0186] The bus system 940 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus system 940 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 9 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0187] This application also provides a computer-readable storage medium, including instructions or a computer program, which, when run on a computer, causes the computer to execute the configuration method and communication method for terminal device service characteristics provided in the above embodiments. For example, it causes the computer to execute the configuration method for terminal device service characteristics executed by the central device provided in the above embodiments (corresponding to...). Figure 2 (The method shown). For example, causing the computer to execute the communication method provided in the above embodiments (corresponding to...) Figure 4 or Figure 6 or Figure 7 (The steps performed by the central device). For example, causing the computer to execute the communication method provided in the above embodiments (corresponding to...) Figure 4 or Figure 6 or Figure 7 (The steps performed by the first access device).

[0188] This application also provides a computer program product containing instructions or a computer program, which, when run on a computer, causes the computer to execute the methods provided in the above embodiments. For example, it causes the computer to execute the configuration method for terminal device service characteristics executed by the central device provided in the above embodiments (corresponding to...). Figure 2 (The method shown). For example, causing the computer to execute the communication method provided in the above embodiments (corresponding to...) Figure 4 or Figure 6 or Figure 7 (The steps performed by the central device). For example, causing the computer to execute the communication method provided in the above embodiments (corresponding to...) Figure 4 or Figure 6 or Figure 7 (The steps performed by the first access device).

[0189] This application also provides a communication system, which includes a first access device and a central device mentioned in the above embodiments. The central device is used to execute the steps performed by the central device provided in the above embodiments, and the first access device is used to execute the steps performed by the access device provided in the above embodiments. For example, the central device executes steps for performing... Figure 2 or Figure 4 or Figure 6 or Figure 7 The operation is performed by the central device; the first access device is used to perform the operation. Figure 4 or Figure 6 or Figure 7 The steps performed by the first access device.

[0190] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0191] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0192] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical business division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0193] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0194] Furthermore, the various business units in the embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software business unit.

[0195] If the integrated unit is implemented as a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0196] Those skilled in the art will recognize that, in one or more of the examples above, the services described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one place to another. Storage media can be any available medium accessible to general-purpose or special-purpose computers.

[0197] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention.

[0198] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. A method for configuring service characteristics of a terminal device, characterized in that, Applied to central equipment, the method includes: Obtain the service characteristic configuration information of the user group, wherein the user group includes multiple terminal devices, and each terminal device in the user group is of the same type. The service characteristics deployed on terminal devices of the same type are the same. The service characteristic configuration information is the configuration information required to implement the service characteristics. The service characteristic configuration information of the user group is associated with multiple access interfaces corresponding to the user group, so as to enable the execution of the service characteristics corresponding to the service characteristic configuration information on multiple terminal devices in the user group based on the multiple access interfaces. The multiple access interfaces include a first access interface, which is an interface on a first access device. The first terminal device among the multiple terminal devices connects to the first access device through the first access interface to access the network.

2. The method according to claim 1, characterized in that, The method further includes: Send indication information to the first access device, the indication information being used to instruct the first access device to send the access location information of the first terminal device on the first access device to the central device when it receives a message from the first terminal device through the first access interface, wherein the access location information is used to indicate the first access interface.

3. The method according to claim 1 or 2, characterized in that, The method further includes: Based on the service characteristic configuration information, table entry information corresponding to the first terminal device is generated. The table entry information is used by the central device to perform legality verification on the packets from the first terminal device. The table entry information includes the access location information of the first terminal device on the first access device.

4. The method according to claim 3, characterized in that, The step of generating table entry information corresponding to the first terminal device based on the service characteristic configuration information includes: The system receives a second message sent by the first access device. The second message is obtained by the first access device based on the first message sent by the first terminal device to the first access device. The second message includes the access location information. The first access interface is the interface on the first access device used to receive the first message. Based on the first access interface indicated by the access location information, query the service feature configuration information associated with the first access interface; The table entry information is generated based on the service characteristic configuration information and the access location information.

5. The method according to any one of claims 2-4, characterized in that, The access location information includes: The first virtual local area network (VLAN) identifier is assigned to the first access interface.

6. The method according to any one of claims 1-5, characterized in that, The service feature configuration information includes: At least one security configuration information and a second VLAN identifier for the service corresponding to the user group.

7. The method according to any one of claims 1-6, characterized in that, Each terminal device in the user group is: Office terminal equipment, security monitoring equipment, Internet Protocol (IP) phones, or printers.

8. The method according to any one of claims 1-7, characterized in that, The central equipment includes: Core layer network devices, or aggregation layer network devices, or firewalls.

9. A configuration device for service characteristics of a terminal device, characterized in that, Applied to central equipment, the device includes: a processing unit, the processing unit being used for: Obtain the service characteristic configuration information of the user group, wherein the user group includes multiple terminal devices, and each terminal device in the user group is of the same type. The service characteristics deployed on terminal devices of the same type are the same. The service characteristic configuration information is the configuration information required to implement the service characteristics. The service characteristic configuration information of the user group is associated with multiple access interfaces corresponding to the user group, so as to enable the execution of the service characteristics corresponding to the service characteristic configuration information on multiple terminal devices in the user group based on the multiple access interfaces. The multiple access interfaces include a first access interface, which is an interface on a first access device. The first terminal device among the multiple terminal devices connects to the first access device through the first access interface to access the network.

10. The apparatus according to claim 9, characterized in that, The device further includes: A sending unit is configured to send indication information to the first access device. The indication information is configured to instruct the first access device to send the access location information of the first terminal device on the first access device to the central device when it receives a message from the first terminal device through the first access interface. The access location information is used to indicate the first access interface.

11. The apparatus according to claim 9 or 10, characterized in that, The processing unit is further configured to: Based on the service characteristic configuration information, table entry information corresponding to the first terminal device is generated. The table entry information is used by the central device to perform legality verification on the packets from the first terminal device. The table entry information includes the access location information of the first terminal device on the first access device.

12. The apparatus according to claim 11, characterized in that, The processing unit generates table entry information corresponding to the first terminal device based on the service characteristic configuration information, specifically including: The system receives a second message sent by the first access device. The second message is obtained by the first access device based on the first message sent by the first terminal device to the first access device. The second message includes the access location information. The first access interface is the interface on the first access device used to receive the first message. Based on the first access interface indicated by the access location information, query the service feature configuration information associated with the first access interface; The table entry information is generated based on the service characteristic configuration information and the access location information.

13. The apparatus according to any one of claims 10-12, characterized in that, The access location information includes: The first virtual local area network (VLAN) identifier is assigned to the first access interface.

14. The apparatus according to any one of claims 9-13, characterized in that, The service feature configuration information includes: At least one security configuration information and a second VLAN identifier for the service corresponding to the user group.

15. The apparatus according to any one of claims 9-14, characterized in that, Each terminal device in the user group is: Office terminal equipment, security monitoring equipment, Internet Protocol (IP) phones, or printers.

16. The apparatus according to any one of claims 9-15, characterized in that, The central equipment includes: Core layer network devices, or aggregation layer network devices, or firewalls.

17. A terminal device service characteristic configuration device, comprising a processor and a memory, wherein the memory is used to store program code, and the processor is used to call the program code in the memory to cause the terminal device service characteristic configuration device to perform the method as described in any one of claims 1-8.

18. A computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1-8.

19. A computer program product, characterized in that, Includes program code that, when a computer runs the computer program product, causes the computer to perform the method as described in any one of claims 1-8.