Function Composition Method, Apparatus, Device, and Storage Medium

The method constructs a first sequence based on user policies to orchestrate network and security functions in the SASE framework, addressing integration challenges and enhancing management efficiency and compatibility across vendors and deployment locations.

JP2025523029APending Publication Date: 2025-07-17CHINA MOBILE COMM LTD RES INST +1
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2025501400
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-11
Filing Date
2023-06-30
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

The Secure Access Service Edge (SASE) service framework faces challenges in integrating network and security functions from multiple vendors, leading to inefficiencies in orchestration, high costs, and difficulty in meeting user needs due to the complexity of managing diverse technologies across various deployment locations.

Method used

A method and apparatus that obtains a user policy characterizing network and security functions, constructs a first sequence based on this policy, and transmits it to functional modules for execution, ensuring compatibility and efficient management across vendors and deployment locations.

Benefits of technology

This approach enables flexible and efficient orchestration of network and security functions, meeting user needs by ensuring compatibility and orderly traffic transfer, thereby reducing costs and enhancing management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025523029000001_ABST
    Figure 2025523029000001_ABST
Patent Text Reader

Abstract

The present disclosure provides a function composition method, apparatus, device, and storage medium. Here, the method includes the steps of obtaining a user policy that characterizes network functions and / or security functions expected by a user, and obtaining a first sequence and transmitting the first sequence based on the user policy.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-reference to Related Applications

[0001] This application claims the priority of Chinese Patent Application No. 202210813724.2 filed in China on July 11, 2022, the entire content of which is incorporated herein by reference.

Technical Field

[0002] The present disclosure relates to the field of wireless communication technologies, and particularly to a function composition method, apparatus, device, and storage medium.

Background Art

[0003] Currently, the Secure Access Service Edge (SASE) service framework integrates wide area network technology and a new service framework for comprehensive network security protection. It is identity-centric and distributed, and provides cloud-native networks and security services that are compatible with various edges to enterprises. The SASE service contains too many technologies, including both network functions and security functions. Therefore, it is difficult for a single vendor to provide high-quality full-stack network functions and security functions. Multiple vendors can cooperate to realize the SASE framework, but they cannot meet the network and security needs of users.

Summary of the Invention

[0004] In view of this, embodiments of the present disclosure are expected to provide a function composition method, apparatus, device, and storage medium.

[0005] The technical solutions of the embodiments of the present disclosure are realized as follows.

[0006] At least one embodiment of the present disclosure provides a function composition method, the method comprising: Obtaining a user policy characterizing network functions and / or security functions expected by a user; Obtaining a first sequence based on the user policy; Including transmitting the first sequence.

[0007] Also, according to at least one embodiment of the present disclosure, the first sequence is Obtained by analyzing a user policy, selecting a network function module and / or a security function module, and obtaining a first sequence including the network function module and / or the security function module.

[0008] Also, according to at least one embodiment of the present disclosure, the step of obtaining a first sequence based on the user policy is Determining an identifier of each module in the first sequence based on a description of a network function module, a description of a security function module, a module identifier, and at least one of a plurality of function descriptions in the user policy, and obtaining the first sequence. Here, the function description in the user policy characterizes a description of a network function expected by the user and / or a description of a security function expected by the user.

[0009] Also, according to at least one embodiment of the present disclosure, the method further includes Receiving registration information transmitted from the plurality of function modules, where the registration information carries at least one of identifier information of each function module, a description of a network function supporting execution, and a description of a security function supporting execution.

[0010] Also, according to at least one embodiment of the present disclosure, the step of obtaining a first sequence based on the user policy is including the step of obtaining the first sequence based on the user policy and the preset rules.

[0011] Also, according to at least one embodiment of the present disclosure, the step of obtaining the first sequence based on the user policy and the preset rules includes: determining a plurality of function modules based on at least one of a description of a network function module, a description of a security function module, a module identifier, and at least one of a plurality of function descriptions in the user policy; and obtaining the first sequence based on the preset rules.

[0012] Also, according to at least one embodiment of the present disclosure, the step of obtaining the first sequence based on the preset rules includes: selecting and / or rearranging the plurality of function modules based on the preset rules to obtain the first sequence.

[0013] Also, according to at least one embodiment of the present disclosure, the method further includes: receiving operation status information transmitted from the plurality of function modules.

[0014] The step of obtaining the first sequence based on the preset rules includes: selecting a plurality of function modules based on the operation status information to obtain the first sequence.

[0015] Also, according to at least one embodiment of the present disclosure, the step of obtaining the first sequence based on the preset rules includes: obtaining the first sequence based on at least one of a network topology, a network delay, and a network traffic load balancing.

[0016] Also, according to at least one embodiment of the present disclosure, the step of obtaining the first sequence based on at least one of a network topology, a network delay, and a load balancing of network traffic includes: obtaining a source address and a destination address in the user policy; and obtaining the first sequence based on at least one of a network topology, a network delay, and a load balancing of network traffic.

[0017] Also, according to at least one embodiment of the present disclosure, the first sequence matches part or all of a transfer path determined based on a source address and a destination address.

[0018] Also, according to at least one embodiment of the present disclosure, the step of obtaining the first sequence based on at least one of a network topology, a network delay, and a load balancing of network traffic includes: obtaining a target address in the user policy; and obtaining the first sequence based on at least one of a network topology, a network delay, and a load balancing of network traffic.

[0019] Also, according to at least one embodiment of the present disclosure, some or all of the functional modules indicated by the first sequence are functional modules reachable to the target address g via a network.

[0020] Also, according to at least one embodiment of the present disclosure, the step of transmitting the first sequence includes: transmitting the first sequence and a corresponding policy of each functional module in the first sequence, where the corresponding policy of each functional module is obtained based on the user policy.

[0021] At least one embodiment of the present disclosure provides a function composition method, and the method includes: receiving a first sequence, wherein the first sequence is obtained based on a user policy, and the user policy characterizes network functions and / or security functions expected by a user.

[0022] Moreover, according to at least one embodiment of the present disclosure, the method further includes: transmitting registration information carrying at least one of identifier information of each function module, a description of a network function supporting execution, and a description of a security function supporting execution.

[0023] Moreover, according to at least one embodiment of the present disclosure, the method further includes: transmitting operation state information, wherein the operation state information is used to select a plurality of function modules based on the operation state information and obtain the first sequence.

[0024] Moreover, according to at least one embodiment of the present disclosure, the step of receiving a first sequence includes: receiving the first sequence and a corresponding policy of a function module, where the corresponding policy of the function module is obtained based on the user policy.

[0025] At least one embodiment of the present disclosure provides a function composition apparatus, and the apparatus includes: an acquisition unit for acquiring a user policy characterizing network functions and / or security functions expected by a user; and a processing unit for obtaining a first sequence based on the user policy and transmitting the first sequence.

[0026] At least one embodiment of the present disclosure provides a function composition apparatus, and the apparatus includes a receiving unit for receiving a first sequence, wherein the first sequence is obtained based on a user policy, and the user policy characterizes network functions and / or security functions expected by the user.

[0027] At least one embodiment of the present disclosure provides a device including a processor and a memory for storing a computer program operable on the processor, wherein, when executing the computer program, the processor executes the steps of the method described in any one of the above on the device side.

[0028] At least one embodiment of the present disclosure provides a device including a processor and a memory for storing a computer program operable on the processor, wherein, when executing the computer program, the processor executes the steps of the method described in any one of the above on the device side.

[0029] At least one embodiment of the present disclosure provides a storage medium storing a computer program, and when the computer program is executed by a processor, the steps of any one of the above methods are realized.

Advantages of the Invention

[0030] The function composition method, apparatus, device, and storage medium provided by the embodiments of the present disclosure obtain a user policy that characterizes the network function and / or security function expected by the user, obtain a first sequence based on the user policy, and transmit the first sequence. Using the technical solution provided by the embodiments of the present disclosure, in combination with the user policy, a first sequence is obtained. In this way, the device that receives the first sequence can execute the corresponding network function and security function according to the first sequence, thereby providing the network and security services required by the user, and thus meeting the network and security needs of the user.

Brief Description of the Drawings

[0031]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Modes for Carrying Out the Invention

[0032] Before explaining the technical solution of the embodiments of the present disclosure, first, the related technologies will be explained.

[0033] In related technologies, due to the digital transformation of enterprises and the impact of the COVID-19 pandemic, the cloudification of enterprises and remote / mobile offices have become major trends. Due to changes in the network, the security boundary has gradually become ambiguous. As a result, there is a lack of unified security inspection for network traffic, the cost of security and operation and maintenance increases due to the distributed deployment of services, the opportunities exposed to risks increase due to the uncertain security boundary, and the security risk increases. To solve the above problems, Gartner proposed the Secure Access Service Edge (SASE) service framework in 2019, integrating wide area network technology and a new service framework for comprehensive network security protection, providing enterprises with cloud-native networks and security services centered on identity, distributed, and compatible with various edges. The SASE framework integrates various security and network functions such as Zero-Trust Network Access (ZTNA), Firewall as a Service (FWaaS), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Data Leakage Prevention (DLP) through Software Defined WAN (SD-WAN), thereby realizing the integrated management and control of network and security functions and flexible deployment. SASE products mainly build full-stack network and security functions for a single supplier through mergers, acquisitions, and technical cooperation, thereby realizing the orchestration management of network and security functions of the same vendor.

[0034] In related technologies, the following problems exist in the orchestration management framework for SASE networks and security functions that are compliant with a single vendor. First, there are too many technologies included in the SASE service. At the same time, it also includes network and security functions. It is difficult for a single vendor to provide high-quality full-stack network functions and security functions. Multiple vendors can cooperate to realize the SASE framework, but they cannot meet the network and security needs of users. They do not perform comprehensive orchestration and unified management of network functions and security functions. As a result, the integration efficiency is low, the cost is high, and a large amount of adaptation work is required. Second, each function in the SASE service is flexibly arranged at various locations such as network service points of presence (PoPs), client terminal devices (Customer Premises Equipment, CPE), user terminals, and the cloud. Unified management and orchestration are difficult. Third, the SASE service includes both network and security functions. In order to simultaneously meet the network and security needs of users, consider both security and network transfer efficiency, and meet the requirements for the priority of network and security function processing, it is necessary to comprehensively and effectively orchestrate and manage network and security functions. In addition, the cross-vendor orchestration management framework mainly targets traffic-based security functions, and realizes the processing sequence of network and security through the traffic attraction function of the network function module, but does not perform integrated orchestration and unified management of network functions and security functions.

[0035] Based on this, in the embodiments of the present disclosure, a user policy characterizing the network function and / or security function expected by the user is obtained, a first sequence is obtained based on the user policy, and the first sequence is transmitted.

[0036] FIG. 1 is a flowchart of the implementation of the function composition method according to an embodiment of the present disclosure, which is applied to a server. As shown in FIG. 1, the method includes steps 101 to 103.

[0037] Step 101: Obtain a user policy that characterizes the network function and / or security function expected by the user.

[0038] In addition, in the embodiment of the present disclosure, the server is applicable to the SASE service architecture, and specifically, it may refer to the composition layer in the SASE service architecture.

[0039] The user policy may also refer to a description of the needs of the network function and security function expected by the user. Usually, it includes descriptions of the needs of security functions and network functions such as the source address and destination address of user traffic, service quality requirements, access control conditions, and target addresses.

[0040] In addition, the basic format of the user policy can use a nested tag language. For example, there are expression forms such as extensible markup language (xml) and JavaScript (registered trademark) Object Notation (json). Taking xml as an example, the basic composition of the user policy is <tag>value< / tag> as follows.

[0041] Here, the types of the user policy can include two types.

[0042] The first type is the user policy for traffic.

[0043] Table 1 is a schematic of the basic format of the user policy for traffic. As shown in Table 1, the user policy for traffic mainly includes the source address, destination address, and the needs of security functions or network functions.

Table 1

[0044] Here, IP refers to the Internet Protocol. IP can be understood as an IP address. The source IP address may be described as the source IP address. The destination IP address may be described as the destination IP address.

[0045] The second type is a user policy for non-traffic.

[0046] Table 2 is a schematic of the basic format of the user policy for non-traffic. As shown in Table 2, the user policy for non-traffic mainly includes the target address and the needs of security functions or network functions.

Table 2

[0047] Note that in Table 1 and Table 2, the values corresponding to the tags of all address classes can represent multiple addresses using methods such as regular expressions, wildcards, or address library names (that is, naming an existing address library as the source address, destination address, or target address by name). In <networkstrategy> ...< / networkstrategy> in Table 1 and Table 2, there are functional policies corresponding to the required network function tags, and in <securitystrategy> ...< / securitystrategy> in Table 1 and Table 2, there are functional policies corresponding to the required security function tags, specifically as shown in Table 3.

Table 3

[0048] As shown in Table 3, the function tag can refer to the name of each network function or security function. In the traffic-type user policy, the function tags indicating security functions include, but are not limited to, traffic encryption, traffic filtering, identity and access management (IAM). The function tags indicating network functions include, but are not limited to, deep packet inspection (DPI), network optimization, traffic isolation, etc. In the non-traffic-type user policy, the function tags indicating security functions include, but are not limited to, resource discovery, vulnerability scan, log review, etc. The function policy is the policy setting of the corresponding security function. For example, the Filter tag value includes filtering conditions and the processing method after filtering.

[0049] Table 4 is a schematic of the function policy corresponding to the function tag. As shown in Table 4, one function tag may include multiple function policies.

Table 4

[0050] Step 102: Obtain a first sequence based on the user policy.

[0051] Here, "obtain" may be understood as constructing / generating and obtaining by oneself, or obtaining from other devices or modules.

[0052] Here, the first sequence is It is obtained by analyzing the user policy to select a network function module and / or a security function module, and obtaining a first sequence including the network function module and / or the security function module.

[0053] The first sequence may include only the network function module and / or the security function module, or may include other modules.

[0054] Here, the arrangement positions of the network function module and the security function module are not limited. For example, they can be arranged at positions such as a network service point (PoP), a client terminal device (Customer Premises Equipment, CPE), a gateway, a user terminal, the cloud, a cloud server, a software-defined wide area network (SD-WAN) / software-defined networking (SDN) controller, a network device, etc.

[0055] The function module obtains the first sequence. Here, the function description in the user policy characterizes the description of the network function expected by the user and / or the description of the security function expected by the user.

[0056] Here, the description has various forms, such as function tags, etc. The description here may explain the content of the function, the type of the function, and other attributes of the function.

[0057] Here, each module in the first sequence is actually a module that can satisfy the network functions / security functions expected by the user. The network function module and the security function module have corresponding module identifiers. First, determine the network / security function module that meets the user's expectations, and then, based on the correspondence between the function module and the module identifier, determine the identifier of the function module compiled in the first sequence. Note that what is actually included in the first sequence is the identifier sequence of the network function module and / or security function module that meets the user's expectations.

[0058] As one embodiment, the step of obtaining the first sequence based on the user policy is reading a plurality of function tags in the user policy, where each function tag characterizes the type of network function expected by the user or the type of security function expected by the user, using the plurality of function tags in combination with the preset correspondence between the type of network function module, the type of security function module, and the module identifier to determine the module identifier corresponding to each function tag and obtain a plurality of module identifiers, and generating the first sequence based on the plurality of function tags and the plurality of module identifiers.

[0059] As another embodiment, the step of obtaining the first sequence based on the user policy is The steps of reading a plurality of function tags in the user policy, each function tag characterizing a type of network function expected by the user or a type of security function expected by the user, and using the plurality of function tags to combine with a preset correspondence relationship of a type of network function, a type of security function, and a function module identifier to determine a function module identifier corresponding to each function tag and obtain a plurality of function module identifiers, and generating the first sequence based on the plurality of function tags and the plurality of function module identifiers.

[0060] Specifically, the following steps may be included.

[0061] Step 1: Read a plurality of function tags in the user policy.

[0062] Specifically, summarize all function tags (tags) in the security policy (SecurityStrategy) and network policy (NetworkStrategy) in the user policy. Here, assume that the aggregation result is {DPI, Filter, Encryption}.

[0063] Step 2: Use the plurality of function tags to combine with a preset correspondence relationship of a type of network function, a type of security function, and a function module identifier to determine a function module identifier corresponding to each function tag and obtain a plurality of function module identifiers.

[0064] Table 5 is a schematic of the preset correspondence relationships among the types of network functions, the types of security functions, and the function module identifiers. As shown in Table 5, based on the names of the network functions or security functions described by the function tags, in combination with the preset correspondence relationships, the function module identifiers corresponding to each of the function tags can be retrieved. For example, assuming there are two function tags, one function tag describes the network function DPI and the other function tag describes the security function Filter, from the preset correspondence relationships, retrieve the function module identifiers corresponding to DPI to obtain function module ID1 and function module ID3, and further retrieve the function module identifiers corresponding to Filter to obtain function module ID2 and function module ID3.

[0065]

Table 5

[0066] In addition, if the function module identifiers corresponding to the corresponding function tags are not retrieved from the preset correspondence relationships, the function tags are deleted.

[0067] Step 3: Generate the first sequence based on the plurality of function tags and the plurality of function module identifiers.

[0068] Here, assuming there are three function tags, one function tag describes the network function DPI, and the other two function tags describe the security functions Filter and Encryption. From the preset correspondence relationships, retrieve the function module identifiers corresponding to DPI to obtain function module ID1 and function module ID3, retrieve the function module identifiers corresponding to Filter to obtain function module ID2 and function module ID3, and assume that retrieving the function module identifier corresponding to Encryption obtains function module ID3. In this way, the obtained first sequence is It may also be [(DPI, Function Module ID1, Function Module ID3), (Filter, Function Module ID2, Function Module ID3), (Encryption, Function Module ID3)].

[0069] Note that the function module identifier can be replaced with the identifier of the network function module and / or security function module set in the function module.

[0070] That is, assuming that the function module identifier is Function Module ID1, the identifier of the network function module set in the function module can be represented by Network Function Module ID1, and the identifier of the security function module set in the function module can be represented by Security Function Module ID1. By analogy, if the function module identifier is Function Module ID2, the identifier of the network function module set in the function module can be represented by Network Function Module ID2, and the identifier of the security function module set in the function module can be represented by Security Function Module ID2. If the function module identifier is Function Module ID3, the identifier of the network function module set in the function module can be represented by Network Function Module ID3, and the identifier of the security function module set in the function module can be represented by Security Function Module ID3. In this way, the obtained first sequence can further be represented as [(DPI, Network Function Module ID1, Network Function Module ID3), (Filter, Security Function Module ID2, Security Function Module ID3), (Encryption, Security Function Module ID3)].

[0071] In one embodiment, the method is A step of receiving registration information transmitted from the plurality of function modules, where the registration information carries at least one of identifier information of each function module, a description of a network function that supports execution, and a description of a security function that supports execution.

[0072] Here, based on the registration information, the composition layer can obtain a preset correspondence relationship between the description of the network function, the description of the security function, and the identifier of the corresponding network function module, and can use it for subsequent composition of function modules. Of course, the description of the function module may further include other contents, such as name, address, call interface, placement type, etc.

[0073] In one embodiment, the method includes A step of receiving registration information transmitted from each of the plurality of function modules, where the registration information includes identifier information of each function module, a type of a network function that supports execution, and a type of a security function that supports execution, and A step of obtaining a preset correspondence relationship between the type of the network function, the type of the security function, and the function module identifier based on the registration information may further be included.

[0074] For example, assuming there are three functional modules, the functional module identifier reported by functional module 1 is ID1, the type of network function that supports execution is DPI, and it does not support the execution of security functions. The functional module identifier reported by functional module 2 is ID2, the type of security function that supports execution is Filter, and it does not support the execution of network functions. The functional module identifier reported by functional module 3 is ID3, the type of network function that supports execution is DPI, and the type of security function that supports execution is Filter. In this way, the server can obtain the preset correspondence relationships of the type of the network function, the type of the security function, and the functional module identifier based on the registration information reported by each functional module.

[0075] In the second case, the first sequence is obtained by using the user policy and the preset rules.

[0076] When actually used, considering that the SASE service is involved in both network functions and security functions at the same time, while satisfying the user's needs for network functions and security functions, and considering security and network transfer efficiency, it is necessary to perform comprehensive and orderly composition management on the functional modules that execute the network functions and security functions expected by the user. In the composition process, in addition to considering information such as user network service requirements, network topology, and network working status, based on the security service requirements of the client, the security functions are composed and route calculated as the necessary network nodes in the transfer process.

[0077] Based on this, in some embodiments, the step of obtaining the first sequence based on the user policy is including the step of obtaining the first sequence based on the user policy and the preset rules.

[0078] Here, the "rule" can be rephrased as a policy, principle, etc.

[0079] In some embodiments, based on the user policy and the preset rule, the step of obtaining the first sequence includes: determining a plurality of functional modules based on a description of a network function module, a description of a security function module, a module identifier, and at least one of the plurality of function descriptions in the user policy; obtaining the first sequence based on the preset rule.

[0080] Here, the preset rule may simultaneously include a rule indicating functional module selection and a rule indicating functional module rearrangement, or may include either one of them.

[0081] Here, the function description in the user policy characterizes a description of a network function expected by the user and / or a description of a security function expected by the user.

[0082] Here, the description has various forms, such as function tags, etc., and the description here may explain the content of the function, the type of the function, and other attributes of the function.

[0083] In some embodiments, based on the preset rule, the step of obtaining the first sequence includes: selecting and / or rearranging the plurality of functional modules based on the preset rule to obtain the first sequence.

[0084] Here, there is no inevitable priority in selecting the plurality of functional modules and rearranging the plurality of functional modules. In the process of obtaining the first sequence, selection and rearrangement do not necessarily occur.

[0085] Here, one embodiment of selecting a function module is as follows. There are various network / security function modules that can meet the user's expectations, and an optimal function module may be used. For example, it can be selected based on attributes such as the operating state of each function module, whether it is located near the user side and / or the resource side, whether it meets the functional requirements of heavy computing, whether it meets the functional requirements of medium computing, and whether it meets the functional requirements of light computing. Note that the optimal function module here is not limited to one function module and may be a plurality of optimal function modules. The selection of the function module may include the selection of the network function module and / or the selection of the security function module. In some cases, only one function module may be selected, and in other cases, it may be necessary to select both function modules.

[0086] Here, one embodiment of rearranging the function module is as follows. Based on the fact that specific multiple functions have special requirements for the execution order, etc., the function module is rearranged. The rearrangement of the function module may include the rearrangement of the network function module and / or the rearrangement of the security function module. In some cases, one function module may be rearranged, and in other cases, both function modules may be rearranged. The rearrangements may be performed separately. For example, multiple network function modules may be rearranged, and multiple security function modules may be rearranged. However, it is difficult to rearrange two types of function modules. Two types of function modules may be mixed and rearranged.

[0087] When the first sequence needs to select and / or rearrange two or more types of function modules, it is the same as the above selection and / or rearrangement method, and detailed description is omitted here.

[0088] Specifically, based on the user policy and the preset rules, the step of obtaining the first sequence is A step of reading a plurality of function tags in the user policy, wherein each function tag characterizes a type of network function expected by the user or a type of security function expected by the user; A step of using the plurality of function tags and combining with a preset correspondence relationship of a type of network function, a type of security function, and a function module identifier to determine a first function module identifier corresponding to each function tag and obtain a plurality of first function module identifiers; A step of selecting at least one second function module identifier that satisfies the preset rule from the plurality of first function module identifiers corresponding to each function tag; A step of obtaining the first sequence based on the plurality of function tags and at least one second function module identifier corresponding to each function tag.

[0089] Here, the preset rule may refer to a rule that a function module needs to satisfy. Specifically, Being arranged near the user side; Being arranged near the resource side; Satisfying the functional requirements of heavy computing; Satisfying the functional requirements of medium computing; Satisfying the functional requirements of light computing, and may include one of them.

[0090] Being placed near the user side means that it needs to be placed near the access entity, and it is necessary to select a function module to be placed in the access POP and the function resource pool near it or the function module placed in the CPE. Being placed near the resource side means that it is placed near the service application or the target resource, and it is necessary to select a function module to be placed in the security resource pool close to the application service or the target resource. The functional requirements of heavy computing mean that it needs to be intensively placed in a large function resource pool, and it is necessary to select a function module to be placed in the large function resource pool placed in the path of user network traffic transfer. By preferentially placing various security functions required by the user in one large resource pool, the transfer delay can be reduced. The functional requirements of light computing can be selectively placed in the function module on the user side. The functional requirements of medium computing are the requirements between the functional requirements of heavy computing and light computing.

[0091] That is, according to the placement location, the function module can be divided into those close to the user (such as SWG), those close to the resource (such as all non-traffic type security functions such as CASB and vulnerability scanning), and those without requirements (such as FireWall). According to the required computing function, the function module can be divided into those that meet the functional requirements of heavy computing, those that meet the functional requirements of medium computing, and those that meet the functional requirements of light computing.

[0092] Specifically, the step of obtaining the first sequence based on the user policy and the preset rules may include the following steps.

[0093] Step 1: Read a plurality of function tags in the user policy.

[0094] Specifically, summarize all the function tags (tag) of SecurityStrategy and NetworkStrategy in the user policy.

[0095] Here, assume that the aggregation result is {DPI, Filter, Encryption}.

[0096] Step 2: Using the plurality of function tags, in combination with the preset correspondence relationships of the type of network function, the type of security function, and the function module identifier, determine the first function module identifier corresponding to each function tag, and obtain a plurality of first function module identifiers.

[0097] For example, assume that there are two function tags, one function tag describes the network function DPI, and the other function tag describes the security function Filter. Then, from the preset correspondence relationship, search for the first function module identifier corresponding to DPI, and obtain function module ID1 and function module ID3. Further, search for the first function module identifier corresponding to Filter, and obtain function module ID2 and function module ID3.

[0098] Note that if the first function module identifier corresponding to the corresponding function tag (tag) cannot be searched from the preset correspondence relationship, delete the function tag (tag).

[0099] Step 3: Select at least one second function module identifier that satisfies the preset rule from the plurality of first function module identifiers corresponding to each function tag.

[0100] For example, assuming that the preset rule is on the side closer to the user and there are two function tags, one function tag describes the network function DPI, and the other function tag describes the security function Filter, from the preset correspondence relationship, search for the first function module identifier corresponding to DPI, and obtain function module ID1 and function module ID3. From function module ID1 and function module ID3, select the function module identifier arranged on the side closer to the user. If function module 1 is arranged on the side closer to the user, the identification function module ID1 of function module 1 can be obtained. Furthermore, check the first function module identifier corresponding to Filter to obtain function module ID2 and function module ID3. From function module ID2 and function module ID3, select the function module identifier arranged on the side closer to the user. If function module 3 is arranged on the side closer to the user, the identification function module ID3 of function module 3 can be obtained.

[0101] Step 4: Obtain the first sequence based on the plurality of function tags and at least one second function module identifier corresponding to each function tag.

[0102] Here, assume that there are three function tags, one function tag describes the network function DPI, and the other two function tags describe the security functions Filter and Encryption, and assume that the second function module identifiers corresponding to each function tag are function module ID1, function module ID3, and function module ID3 respectively. In this way, the obtained first sequence may be [(DPI, function module ID1), (Filter, function module ID3), (Encryption, function module ID3)].

[0103] It should be noted that the function module identifier can be replaced with the identifier of the network function module and / or the security function module set within the function module.

[0104] That is, assuming that the function module identifier is function module ID1, the identifier of the network function module set within the function module can be represented by network function module ID1, and the identifier of the security function module set within the function module can be represented by security function module ID1. By analogy, assuming that the function module identifier is function module ID2, the identifier of the network function module set within the function module can be represented by network function module ID2, and the identifier of the security function module set within the function module can be represented by security function module ID2. Assuming that the function module identifier is function module ID3, the identifier of the network function module set within the function module can be represented by network function module ID3, and the identifier of the security function module set within the function module can be represented by security function module ID3. In this way, the obtained first sequence further can be represented as [(DPI, network function module ID1), (Filter, security function module ID3), (Encryption, security function module ID3)].

[0105] In the third case, the first sequence is obtained by using the user policy and the operation state information of each function module.

[0106] In actual application, considering that the SASE service is related to both network functions and security functions at the same time, it is necessary to simultaneously meet the user's needs for network functions and security functions, and considering security and network transfer efficiency, perform comprehensive and orderly composition management of the function modules that execute the network functions and security functions expected by the user. In the process of composition, the operation state of the function module may be considered.

[0107] Based on this, in some embodiments, the method It further includes the step of receiving the operation status information transmitted from the plurality of function modules.

[0108] Based on the preset rules, the step of obtaining the first sequence includes: selecting a plurality of function modules based on the operation status information and obtaining the first sequence.

[0109] Note that the operation status information may include information such as logs and alarms for characterizing whether the function module is operating normally.

[0110] In some embodiments, based on the user policy and the operation status information, the step of obtaining the first sequence includes: reading a plurality of function tags in the user policy, where each function tag characterizes the type of network function expected by the user or the type of security function expected by the user; using the plurality of function tags and combining with the preset correspondence relationship between the type of network function, the type of security function, and the function module identifier to determine the third function module identifier corresponding to each function tag and obtain a plurality of third function module identifiers; combining with the operation status information, selecting at least one fourth function module identifier that meets the preset conditions from the plurality of third function module identifiers corresponding to each function tag; generating the first sequence based on the plurality of function tags and at least one fourth function module identifier corresponding to each function tag.

[0111] Here, meeting the preset conditions may refer to the normal operation status of the function module.

[0112] Specifically, the step of obtaining the first sequence using the user policy and the operation state information may include the following steps.

[0113] Step 1: Read a plurality of function tags in the user policy.

[0114] Specifically, summarize all function tags (tags) in SecurityStrategy and NetworkStrategy in the user policy.

[0115] Here, assume that the aggregation result is {DPI, Filter, Encryption}.

[0116] Step 2: Using the plurality of function tags, in combination with a preset correspondence relationship between the type of network function, the type of security function, and the function module identifier, determine a third function module identifier corresponding to each function tag, and obtain a plurality of third function module identifiers.

[0117] For example, if there are two function tags, one function tag describes the network function DPI, and the other function tag describes the security function Filter, search for the first function module identifier corresponding to DPI from the preset correspondence relationship, and obtain function module ID1 and function module ID3. Further, search for the first function module identifier corresponding to Filter, and obtain function module ID2 and function module ID3.

[0118] Note that if the first function module identifier corresponding to the corresponding function tag (tag) cannot be found from the preset correspondence relationship, delete the function tag (tag).

[0119] Step 3: In combination with the operation state information, select at least one fourth function module identifier that meets the preset conditions from the plurality of third function module identifiers corresponding to each function tag.

[0120] For example, if there are two function tags, one function tag describes the network function DPI, and the other function tag describes the security function Filter, from the pre-set corresponding relationship, search for the first function module identifier corresponding to DPI, and obtain function module ID1 and function module ID3. Select the function module identifier of the function module with a normal operating state from function module ID1 and function module ID3. If it is assumed that the operating state of function module 1 is normal, obtain the identification function module ID1 of function module 1. Further, search for the first function module identifier corresponding to Filter, and obtain function module ID2 and function module ID3. Select the function module identifier with a normal operating state from function module ID2 and function module ID3. If it is assumed that the deployment operating state of function module 3 is normal, the identification function module ID3 of function module 3 can be obtained.

[0121] Step 4: Obtain the first sequence based on the multiple function tags and at least one fourth function module identifier corresponding to each function tag.

[0122] Here, assume that there are three function tags, one function tag describes the network function DPI, and the other two function tags describe the security functions Filter and Encryption. Assume that the fourth function module identifiers corresponding to each function tag are function module ID1, function module ID3, and function module ID3 respectively. In this way, the obtained first sequence may be [(DPI, function module ID1), (Filter, function module ID3), (Encryption, function module ID3)].

[0123] In addition, the function module identifier can be further replaced with the identifier of the network function module and / or security function module set in the function module.

[0124] That is, assuming that the function module identifier is function module ID1, the identifier of the network function module set within the function module can be represented by network function module ID1, and the identifier of the security function module set within the function module can be represented by security function module ID1. By analogy, assuming that the function module identifier is function module ID2, the identifier of the network function module set within the function module can be represented by network function module ID2, and the identifier of the security function module set within the function module can be represented by security function module ID2. Assuming that the function module identifier is function module ID3, the identifier of the network function module set within the function module can be represented by network function module ID3, and the identifier of the security function module set within the function module can be represented by security function module ID3. Thus, the obtained first sequence is further can be represented as [(DPI, network function module ID1), (Filter, security function module ID3), (Encryption, security function module ID3)].

[0125] In some embodiments, based on the preset rules, the step of obtaining the first sequence is includes the step of obtaining the first sequence based on at least one of network topology, network delay, and network traffic load balancing.

[0126] In some embodiments, based on at least one of the network topology, network delay, and network traffic load balancing, the step of obtaining the first sequence is the step of obtaining the source address and destination address in the user policy, and obtaining the first sequence based on at least one of network topology, network delay, and load balancing of network traffic, and the like.

[0127] Here, the inclusion of the source address and the destination address in the user policy means that the user policy is a traffic-type user policy.

[0128] In some embodiments, the first sequence matches part or all of a transfer path determined based on the source address and the destination address.

[0129] Here, the first sequence actually instructs a plurality of functional modules, and not only the existing functional modules but also the order of the plurality of functional modules. The first sequence may actually be understood as something like a transfer path. When the first sequence is sent to each functional module, each functional module can perform traffic transfer based on the functional modules and the order indicated in the sequence. If the user policy includes a source address and a destination address, it means that the user policy is a traffic type user policy, that is, it is necessary to perform the processing of the corresponding network / security function for this traffic. The first sequence actually specifically stipulates the network / security functional modules that participate in and process this traffic. The traffic is transferred by the network / security functional modules stipulated in the first sequence and at the same time, network / security processing operations are performed by the corresponding network / security functional modules. Therefore, the functional modules indicated by the first sequence coincide with the transfer path determined based on the source address and the destination address. For example, it may completely coincide with one of the transfer paths, that is, the address of the device arranged by the first functional module in the first sequence is the same as the source address, and the address of the device arranged by the last functional module in the first sequence is the same as the destination address. Or, the address of the device arranged by the first functional module in the first sequence is the same as the source address, but the address of the device arranged by the last functional module in the first sequence is different from the destination address, and the address of the device arranged by the last functional module is the same as the address of the intermediate node in the path. Or, the address of the device arranged by the first functional module in the first sequence is different from the source address, but the address of the device arranged by the first functional module is the same as the address of the intermediate node in the path, and the address of the device arranged by the last functional module in the first sequence is the same as the destination address.Alternatively, the address of the device arranged by the first functional module in the first sequence is different from the source address, but the address of the device arranged by the last functional module in the first sequence is also different from the destination address.

[0130] In some embodiments, based on at least one of the network topology, network delay, and load balancing of network traffic, the step of obtaining the first sequence includes: the step of obtaining the target address in the user policy; and the step of obtaining the first sequence based on at least one of network topology, network delay, and load balancing of network traffic.

[0131] Here, the fact that the user policy only has a target address means that the user policy is a non-traffic type user policy.

[0132] In some embodiments, some or all of the functional modules indicated by the first sequence are functional modules reachable to the target address network.

[0133] Here, some or all of the functional modules indicated by the first sequence can establish a path to the target address, whereby the functional module can perform corresponding network / security processing on the target (such as a resource) indicated by the target address.

[0134] In actual application, considering that the user hopes to perform an orderly transfer through a functional module with network functions and security functions during the transfer process of user traffic, a first sequence characterized by the priority order of function execution can be generated.

[0135] Based on this, in some embodiments, the method includes: determining the type of the user policy; when it is determined that the type of the user policy is a first preset type, obtaining a first sequence based on the user policy, where the first sequence carries order information for the plurality of functional modules to execute network functions and security functions expected by the user;

[0136] In actual application, considering that the user hopes to perform an orderly transfer without a functional module with network functions and security functions in the process of transferring user traffic, a first sequence without characterizing the execution priority of functions can be generated.

[0137] Based on this, in some embodiments, the method further includes: when it is determined that the type of the user policy is a second preset type, obtaining a first sequence based on the user policy, where the first sequence further includes a step in which the plurality of functional modules do not carry order information for executing network functions and security functions expected by the user.

[0138] In some embodiments, the step of determining the type of the user policy includes: determining whether the user policy contains preset content; when it is determined that the user policy contains the preset content, determining that the type of the user policy is a first preset type; when it is determined that the user policy does not contain the preset content, determining that the type of the user policy is a second preset type.

[0139] Note that determining whether the user policy contains pre-set content may refer to determining whether the user policy simultaneously contains tags for the source address (SourceAddress) and the destination address (DestinationAddress). If the user policy simultaneously contains tags for SourceAddress and DestinationAddress, it is determined that the type of the user policy is the first preset type. If the user policy contains only the tag for the target address (AssetsAddress), it is determined that the type of the user policy is the second preset type.

[0140] Here, the first preset type may indicate that the user policy is a traffic type user policy. The second preset type may indicate that the user policy is a non-traffic type user policy.

[0141] Here, when it is determined that the type of the user policy is the first preset type, a first sequence is generated based on the user policy. The first sequence carries order information for the plurality of functional modules to execute the network functions and security functions expected by the user.

[0142] Here, the first sequence carrying the order information may be [{(DPI, functional module identifier), (Filter, functional module identifier)}, (Encryption, functional module identifier)]

[0143] Here, the elements within [] must be executed in strict order. That is, functions related to the message content, such as DPI corresponding to security functions and Filter corresponding to network functions, must be executed before Encryption corresponding to security functions. The part within braces {} has nothing to do with the priority. That is, the execution of functions related to the message content, such as DPI corresponding to security functions and Filter corresponding to network functions, has no priority. What is within () is first the type of network function or security function, and then the specific function module identifier.

[0144] Note that the function module identifier may be replaced with the identifier of the network function module and / or security function module set within the function module.

[0145] That is, the first sequence carrying the order information may be [(DPI, function module ID), (Filter, function module ID), (Encryption, function module ID)].

[0146] Here, when it is determined that the type of the user policy is the second preset type, based on the user policy, a first sequence is generated, and the first sequence does not carry the order information for the plurality of function modules to execute the network functions and security functions expected by the user.

[0147] Here, the first sequence that does not carry the order information may be {(DPI, function module identifier), (Filter, function module identifier), (Encryption, function module identifier)}.

[0148] Step 103: Transmit the first sequence.

[0149] Here, there are various embodiments for "transmitting the first sequence". All the first sequences may be transmitted to all the functional modules, or the first sequence may be transmitted to some of the functional modules, or a part of the first sequence may be transmitted to all the functional modules, or a part of the first sequence may be transmitted to some of the modules. For different functional modules, the same first sequence may be transmitted, or different first sequences may be transmitted. That is, for each functional module, the sequence it should know may be transmitted, and there is no need to inform other parts of the sequence.

[0150] In some embodiments, the step of transmitting the first sequence is a step of transmitting the first sequence and the corresponding policy of each functional module in the first sequence, where the corresponding policy of each functional module is obtained based on the user policy.

[0151] Note that according to the first sequence, the plurality of functional modules realize unified scheduling and management of the plurality of functional modules according to the user's needs by executing the security function and network function expected by the user, and further meet the user's network and security needs.

[0152] In actual application, for the user policy carried by the source node and the target node, that is, the user policy of the first preset type, based on the source node and the target node, a plurality of first transfer paths can be determined. From the plurality of first transfer paths, at least one second transfer path passing through the plurality of functional modules is selected, and the relevant information of the at least one second transfer path is transmitted to the plurality of functional modules respectively. In this way, the plurality of functional modules can realize orderly transfer of user traffic in combination with the at least one second transfer path and the first sequence.

[0153] Based on this foundation, in some embodiments, the method includes: reading the source node and the target node in the user policy; determining a plurality of first transfer paths based on the source node and the target node; selecting at least one second transfer path passing through the plurality of functional modules from the plurality of first transfer paths; further including causing the plurality of functional modules to transfer user traffic by sending the relevant information of the at least one second transfer path to each of the plurality of functional modules.

[0154] Note that for a user policy without a source node and a target node, that is, a user policy of the second preset type, there is no need to determine a transfer path. That is, each functional module independently accesses resources based on the first sequence and executes corresponding functions for the accessed resources, but there is no need to transfer.

[0155] The embodiments of the present disclosure have the following advantages. (1) Obtaining a first sequence based on a user policy, so that a device receiving the first sequence can execute corresponding network functions and security functions according to the first sequence, thereby providing network and security services required by the user. Therefore, not only can the network and security needs of the user be met, but also the compatibility of network and security functions among multiple vendors and at each deployment location can be satisfied, and the network and security needs can be met more flexibly. (2) Uniformly orchestrating and managing network and security functions across the entire vendor and network domain to form an ordered first sequence, and thus performing orderly transfer of user traffic by means of the ordered first sequence. (3) Uniformly orchestrate and manage network and security functions across the vendor and the entire network domain to form an unordered first sequence, and perform resource processing with the unordered first sequence in this way.

[0156] Figure 2 is a flowchart of the implementation of the function orchestration method according to an embodiment of the present disclosure, which is applied to a function module. As shown in Figure 2, the method includes step 201.

[0157] Step 201: Receive a first sequence. Here, the first sequence is obtained based on a user policy, and the user policy characterizes the network function and / or security function expected by the user.

[0158] In some embodiments, the method further includes the step of transmitting registration information carrying at least one of the identifier information of each function module, the description of the network function supporting the execution, and the description of the security function supporting the execution.

[0159] In some embodiments, the method further includes the step of transmitting operation status information, where the operation status information is used to select a plurality of function modules based on the operation status information to obtain the first sequence.

[0160] In some embodiments, the step of receiving a first sequence is the step of receiving the first sequence and the corresponding policy of the function module, where the corresponding policy of the function module is obtained based on the user policy.

[0161] The corresponding policy of the functional module here may include only the corresponding policy of the functional module, or may include the corresponding policies of other functional modules in addition to the functional module, or may include the corresponding policies of other functional modules.

[0162] It should be noted that according to the first sequence, the functional module realizes the unified programming management of a plurality of functional modules according to user needs by executing the security function and network function expected by the user, thus meeting the user's network and security needs.

[0163] When actually applied, for the user policies carried by the source node and the target node, that is, the user policies of the first preset type, based on the source node and the target node, a plurality of first transfer paths can be determined, and at least one second transfer path passing through the plurality of functional modules is selected from the plurality of first transfer paths, and the related information of the at least one second transfer path is respectively sent to the plurality of functional modules. In this way, the plurality of functional modules can combine the at least one second transfer path and the first sequence to realize the orderly transfer of user traffic.

[0164] Based on this, in some embodiments, the method further includes: receiving the related information of at least one second transfer path; Here, the at least one second transfer path is obtained by the server reading the source node and the target node in the user policy, determining a plurality of first transfer paths based on the source node and the target node, and selecting at least one transfer path passing through the plurality of functional modules from the plurality of first transfer paths.

[0165] Note that for a user policy in which the source node and the target node are not carried, that is, a user policy of the second preset type, it is not necessary to determine a transfer path. That is, each functional module independently accesses a resource based on the first sequence and executes a corresponding function on the accessed resource, but there is no need to transfer it.

[0166] The embodiments of the present disclosure have the following advantages. (1) Based on a user policy, a first sequence is constructed. In this way, the plurality of functional modules can execute corresponding network functions and security functions according to the first sequence, thereby providing network and security services required by the user. Therefore, not only can the network and security needs of the user be satisfied, but also the compatibility of the network and security functions of multiple vendors and each deployment location can be satisfied, and the network and security needs can be satisfied more flexibly. (2) The network and security functions across the vendor and the entire network domain are uniformly orchestrated and managed to form an ordered first sequence. In this way, the ordered first sequence is used to perform orderly transfer of user traffic. (3) The network and security functions across the vendor and the entire network domain are uniformly orchestrated and managed to form an unordered first sequence. In this way, the unordered first sequence is used to perform resource processing.

[0167] FIG. 3 is a system architecture diagram of the adaptation of the function orchestration method of the embodiment of the present disclosure. As shown in FIG. 3, the system includes a first device that obtains a user policy characterizing network functions and / or security functions expected by a user, obtains a first sequence based on the user policy, and transmits the first sequence, and a second device that receives the first sequence.

[0168] In the application scenario of Secure Access Service Edge (SASE), the system may further include a SASE management presentation layer. Specifically, the first device may refer to a SASE orchestration support layer, and the second device may specifically refer to functional modules, virtual machines, containers, etc.

[0169] Here, the SASE management presentation layer collects user policies through methods such as a user interface (UI) or a configuration file, and sends them to the SASE orchestration support layer. Here, the user policy is an explanation of the needs of network functions and security functions expected by the user, and usually includes explanations of the needs of security functions and network functions such as user traffic source addresses and destination addresses, service quality requirements, access control conditions, and target addresses.

[0170] Here, the SASE composition support layer analyzes user policies and is used to construct one sequence of the composition sequence. Specifically, it may include a service composition module, a security function management module, and a network function management module. Here, the service composition module analyzes user policies, constructs a first sequence, and is used to send the first sequence to the security function management module and the network function management module. The security function management module and the network function management module send the first sequence to the security function module or the network function module in the corresponding function module, and further obtain the registration information, operation status information, and the result of executing the first sequence sent from each function module, and are used to report to the service composition module. Here, the registration information includes at least the type of security function and / or network function managed by the function module, the operation status, the function module ID, the name, the description of its own function, the ID, the name, the address, the call interface, the deployment type, etc. The operation status information includes at least information such as the log and alarm of the function module. The function module may specifically be a PoP point, a CPE, an SD-WAN / SDN controller, a virtual machine, a container, etc. The deployment type includes, but is not limited to, physical deployment, cloudification, or virtual deployment.

[0171] Here, the function module receives the first sequence and is used to execute the network function and security function expected by the user. Specifically, it may include a security function module and a network function module. Here, the security function module receives the first sequence, executes the security function expected by the user, and is further used to send feedback such as registration information, operation status information, and the result of executing the first sequence. The network function module receives the first sequence, executes the network function expected by the user, and is further used to send feedback such as registration information, operation status information, and the result of executing the first sequence.

[0172] Here, the security function module may specifically include a traffic type security function module and a non-traffic type security function module.

[0173] The traffic type security function module means that the security function module has a traffic transfer function, can realize the transfer of user traffic according to the first sequence, and the processing target of the security function module is user traffic, and the network function module needs to attract user traffic to complete the security processing.

[0174] The non-traffic type security function module means that the security function module does not have a traffic transfer function, can access resources according to the first sequence, and execute the corresponding security function on the resources, and the processing target of the security function module is non-traffic, that is, it refers to completing security processing such as discovery scanning, monitoring or auditing of the target.

[0175] The process of realizing the reporting of registration information by the function module and the reporting of operation status information by the function module may include the following steps.

[0176] Step 1: The network function module and the security function module in the function module submit registration information and register with the function management module and the security function management module in the network SASE orchestration support layer.

[0177] Step 2: The network function management module in the SASE composition support layer processes the registration information sent from the network function module and generates the registration information of the network function module that can be searched by the service composition module in the SASE composition support layer. The security function management module processes the registration information sent from the security function module and generates the registration information of the security function module that can be searched by the service composition module in the SASE composition support layer.

[0178] Step 3: The network function management module in the SASE composition support layer monitors the operation status information of the network function module in the function module and sends it to the service composition module in the SASE composition support layer. The security function management module monitors the operation status information of the security function module in the function module and sends it to the service composition module in the SASE composition support layer. The service composition module in the SASE composition support layer can send the registration information and the operation status information to the SASE management presentation layer.

[0179] The process by which the SASE composition support layer realizes constructing a first sequence based on a user policy may include the following steps.

[0180] Step 1: The SASE management presentation layer sends the user policy to the SASE composition support layer.

[0181] Step 2: The service composition module in the SASE composition support layer analyzes the user policy, searches for the preset correspondence relationships between the types of network functions, the types of security functions, and the function module identifiers, selects the function module identifiers corresponding to each function tag to obtain a plurality of function module identifiers, generates a first sequence based on the plurality of function tags and the plurality of function module identifiers, and transmits the first sequence to the network function management module and the security function management module in the SASE composition support layer.

[0182] Here, when the user policy contains both SourceAddress and DestinationAddress tags at the same time, it is determined that the type of the user policy is the first preset type. When the user policy contains only the AssetsAddress tag, it is determined that the type of the user policy is the second preset type. If the user policy does not match the above two formats, it is regarded as a format error and the process is terminated. The first preset type may indicate that the user policy is a traffic type user policy. The second preset type may indicate that the user policy is a non-traffic type user policy.

[0183] Here, when it is determined that the type of the user policy is the first preset type, a first sequence is generated based on the user policy, and the first sequence carries the order information for the plurality of function modules to execute the network functions and security functions expected by the user.

[0184] Here, the first sequence carrying the order information is [{(DPI, function module identifier), (Filter, function module identifier)}, (Encryption, function module identifier)] may be used.

[0185] Here, the elements within [] must be executed in strict order. That is, functions related to the message content, such as DPI corresponding to the security function and Filter corresponding to the network function, need to be executed before Encryption corresponding to the security function. The part within braces {} has no relation to the order before and after. That is, the execution of functions related to the message content, such as DPI corresponding to the security function and Filter corresponding to the network function, has no priority. Inside (), it is first the type of the network function or security function, and then the specific function module identifier.

[0186] Note that the function module identifier can be further replaced by the identifier of the network function module and / or security function module set within the function module.

[0187] That is, the first sequence carrying the order information may be [(DPI, function module ID1), (Filter, function module ID2), (Encryption, function module ID3)].

[0188] Here, the service composition module in the SASE composition support layer can send the security function policy in the first sequence and the user policy to the network function management module, as shown in Table 6.

Table 6

[0189] Here, the service composition module in the SASE composition support layer can send the network function policy in the first sequence and the user policy to the security function management module, as shown in Table 7.

Table 7

[0190] Table 8 outlines the traffic type user policy. As shown in Table 8, since the example of the user policy includes SourceAddress and DestinationAddress, it is a traffic type user policy. SourceAddress refers to the source address. DestinationAddress refers to the destination address. The meaning of this traffic type user policy is as follows. For all protocol types from source IP and port to destination IP and port, perform network function processing and execute a deep packet analysis policy for all traffic. Perform security function processing, filter traffic and discard the policy for messages with a source address of 192.168.0.23 regardless of the port. Perform an encryption policy for all traffic.

Table 8

[0191] Here, when it is determined that the type of the user policy is the second preset type, based on the user policy, a first sequence is generated, and the first sequence carries order information for the plurality of functional modules to execute the network functions and security functions expected by the user.

[0192] Here, the first sequence without the carried order information is {(DPI, functional module identifier), (Filter, functional module identifier), (Encryption, functional module identifier)} may also be.

[0193] Note that the functional module identifier is further replaced with the identifier of the network function module and / or security function module set within the functional module.

[0194] That is, the first sequence with the carried order information is {(DPI, Function Module ID1), (Filter, Function Module ID2), (Encryption, Function Module ID3)} may also be used.

[0195] Here, the network function management module in the SASE orchestration support layer receives the first sequence, sends it to the network function module of the corresponding function module, realizes the transfer and scheduling of user traffic and the optimization process of the network, realizes the first sequence through traffic transfer, and obtains the network policy processing result.

[0196] Here, the security function management module receives the first sequence and sends it to the security function module of the corresponding function module, realizes the security processing of user traffic, and summarizes the security policy processing result.

[0197] Step 3: The network function management module aggregation function module in the SASE orchestration support layer executes the result of the first sequence and feeds it back to the SASE management presentation layer. The security function management module in the SASE orchestration support layer summarizes the result of the function module executing the first sequence and feeds it back to the SASE management presentation layer.

[0198] The implementation process for the function module to execute the first sequence may include the following steps.

[0199] Step 1: The traffic-type security function module in the function module needs to attract user traffic by the network function module transferring according to the first sequence execution path. Therefore, its execution process further includes the network function module executing the first sequence to attract traffic. The network function module in the function module attracts user traffic to the next function module according to the first sequence, and finally attracts it to the target resource, and feeds back the processing result to the network function management module in the SASE orchestration support layer.

[0200] Step 2: The traffic-type security function module in the function module executes the first sequence, processes the user traffic to be transferred, and feeds back the processing result to the security function management module in the SASE orchestration support layer. The network function management module in the SASE orchestration support layer summarizes the processing results of executing the first sequence and sends them to the SASE management presentation layer.

[0201] The security function management module summarizes the processing results and feeds them back to the SASE management presentation layer.

[0202] The process for the function module to implement the first sequence may include the following steps.

[0203] Step 1: The non-traffic security function module in the function module receives the first sequence and executes the first sequence for non-traffic.

[0204] Step 2: The security function module in the function module feeds back the processing result to the security function management module in the SASE orchestration support layer. The security function management module summarizes the execution results and feeds them back to the SASE management presentation layer.

[0205] In addition, the process in which the network function module in the function module executes the first sequence is the same as the process in which the traffic type security function module in the function module executes the first sequence.

[0206] To implement the function composition method of the embodiments of the present disclosure, the embodiments of the present disclosure further provide a function composition device. FIG. 4 is a schematic configuration diagram of the function composition device of the embodiments of the present disclosure. As shown in FIG. 4, the device includes an acquisition unit 41 for acquiring a user policy characterizing the network function and / or security function expected by the user, and a processing unit 42 for acquiring a first sequence based on the user policy and transmitting the first sequence.

[0207] In some embodiments, the first sequence is obtained by analyzing the user policy, selecting a network function module and / or a security function module, and acquiring a first sequence including the network function module and / or the security function module.

[0208] In some embodiments, the processing unit 42 specifically determines the identifier of each module in the first sequence based on the description of the network function module, the description of the security function module, the module identifier, and at least one of the plurality of function descriptions in the user policy, and acquires the first sequence. Here, the function description in the user policy characterizes the description of the network function expected by the user and / or the description of the security function expected by the user.

[0209] In some embodiments, the device Receives the registration information sent from the plurality of function modules, and at least one of the identifier information of each function module, the description of the network function supporting execution, and the description of the security function supporting execution is carried in the registration information.

[0210] In some embodiments, specifically, the processing unit 42 Obtains the first sequence based on the user policy and the preset rules.

[0211] In some embodiments, specifically, the processing unit 42 determines a plurality of function modules based on at least one of the description of the network function module, the description of the security function module, the module identifier, and the plurality of function descriptions in the user policy, And obtains the first sequence based on the preset rules.

[0212] In some embodiments, specifically, the processing unit 42 Selects and / or rearranges the plurality of function modules based on preset rules to obtain the first sequence.

[0213] In one embodiment, the apparatus further Receives the operation status information sent from the plurality of function modules, The step of obtaining the first sequence based on the preset rules Includes the step of selecting a plurality of function modules based on the operation status information to obtain the first sequence.

[0214] In some embodiments, specifically, the processing unit 42 Obtains the first sequence based on at least one of the network topology, network delay, and network traffic load balancing.

[0215] In some embodiments, the processing unit 42 specifically obtains the source address and destination address in the user policy, and obtains the first sequence based on at least one of network topology, network delay, and network traffic load balancing.

[0216] In some embodiments, the first sequence matches part or all of the transfer path determined based on the source address and destination address.

[0217] In some embodiments, the processing unit 42 specifically obtains the target address in the user policy, and obtains the first sequence based on at least one of network topology, network delay, and network traffic load balancing.

[0218] In some embodiments, some or all of the functional modules indicated by the first sequence are functional modules reachable to the target address network.

[0219] In some embodiments, the processing unit 42 specifically sends the first sequence and the corresponding policy of each functional module in the first sequence, where the corresponding policy of each functional module is obtained based on the user policy.

[0220] In actual application, the acquisition unit 41 can be realized by a communication interface in the function orchestration device, and the processing unit 42 can be realized by a processor in the function orchestration device.

[0221] Note that when the function composition apparatus provided by the above embodiment performs function composition, the classification of each of the above program modules is described as an example, and in actual application, the above processing can be assigned to different program modules as needed to be completed. That is, the internal structure of the apparatus can be divided into different program modules to complete all or part of the processing described above. In addition, the embodiments of the function composition apparatus and the function composition method provided by the above embodiment belong to the same concept. For details of the specific implementation process, reference may be made to the embodiments of the method, and detailed description is omitted here.

[0222] To implement the function composition method of the embodiment of the present disclosure, the embodiment of the present disclosure further provides a function composition apparatus. FIG. 5 is a schematic configuration diagram of the function composition apparatus of the embodiment of the present disclosure. As shown in FIG. 5, the apparatus includes a receiving unit 51 for receiving a first sequence, wherein the first sequence is obtained based on a user policy, and the user policy characterizes network functions and / or security functions expected by the user.

[0223] In some embodiments, the apparatus further transmits registration information carrying at least one of identifier information of each function module, a description of a network function supported for execution, and a description of a security function supported for execution.

[0224] In some embodiments, the apparatus further transmits operation state information, wherein the operation state information is used to select a plurality of function modules based on the operation state information to obtain the first sequence.

[0225] In some embodiments, specifically, the receiving unit 51 receives the first sequence and the corresponding policy of the function module, where the corresponding policy of the function module is obtained based on the user policy.

[0226] When actually applied, the receiving unit 51 can be realized by a communication interface in the function composition device.

[0227] In addition, when the function composition device provided by the above embodiment performs function composition, only the classification of each of the above program modules is taken as an example for explanation. When actually applied, the above processing can be completed in different program modules as required. That is, by dividing the internal structure of the device into different program modules, all or part of the processing described above can be completed. In addition, the embodiments of the function composition device and the function composition method provided by the above embodiment belong to the same concept. For details of the specific implementation process, reference may be made to the method embodiment, and detailed description is omitted here.

[0228] The embodiments of the present disclosure further provide a device. As shown in FIG. 6, a first communication interface 61 for performing information interaction with other devices, a first processor 62 connected to the first communication interface 61 and configured to execute a method provided by one or more technical solutions on the device side when executing a computer program, are included. The computer program is stored in a first memory 63.

[0229] For details of the specific processing processes of the first processor 62 and the first communication interface 61, reference may be made to the method embodiment, and detailed description is omitted here.

[0230] Of course, when actually applied, each component in the device 60 is coupled via a bus system 64. The bus system 64 is used to realize connection communication between these components. The bus system 64 further includes a power bus, a control bus, and a status signal bus in addition to a data bus. However, for the sake of clear description, in FIG. 6, each bus is described as the bus system 64.

[0231] The first memory 63 in the embodiments of the present disclosure supports the operation of the device 60 by storing various types of data. Examples of such data include any computer program operated on the device 60.

[0232] The method disclosed in the embodiments of the present disclosure may be applied to the first processor 62 or may be implemented by the first processor 62. The first processor 62 may be a chip of an integrated circuit with signal processing capabilities. In the process of implementation, each step of the above method can be completed by the integrated logic circuit of the hardware in the first processor 62 or instructions in the form of software. The first processor 62 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 62 can implement or execute each method, step, and logical block diagram disclosed in the embodiments of the present disclosure. The general-purpose processor may be a microprocessor or any ordinary processor, etc. In combination with the steps of the method disclosed in the embodiments of the present disclosure, it can be directly embodied as being executed by a hardware decoding processor or by a combination of hardware and software modules in the decoding processor. The software module may be stored in a storage medium, the storage medium is located in the first memory 63, and the first processor 62 reads the information in the first memory 63 and combines it with the hardware to complete the steps of the above-mentioned method.

[0233] The embodiments of the present disclosure further provide a device. As shown in FIG. 7, a second communication interface 71 capable of information exchange with other devices, Connected to the second communication interface 71, when executing a computer program, it executes the method provided by one or more technical solutions on the device side. It includes a second processor 72. The computer program is stored in a second memory 73.

[0234] Note that for the details of the specific processing process by the second processor 72 and the second communication interface 71, please refer to the method embodiments, and detailed descriptions are omitted here.

[0235] Of course, when actually applied, each component in the device 70 is integrally coupled via a bus system 74. Note that the bus system 74 is used to realize connection communication between these components. In addition to the data bus, the bus system 74 further includes a power bus, a control bus, and a status signal bus. For the sake of clear explanation, in FIG. 7, each bus is described as the bus system 74.

[0236] The second memory 73 in the embodiments of the present disclosure supports the operation of the device 70 by storing various types of data. Examples of these data include any computer program operated on the device 70.

[0237] The method disclosed in the embodiments of the present disclosure may be applied to the second processor 72 or may be implemented by the second processor 72. The second processor 72 may be a chip of an integrated circuit having signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the second processor 72 or instructions in the form of software. The second processor 72 may be a general-purpose processor, a digital data processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 72 can implement or execute each method, step, and logic block diagram disclosed in the embodiments of the present disclosure. The general-purpose processor may be a microprocessor or any ordinary processor, etc. In combination with the steps of the method disclosed in the embodiments of the present disclosure, it can be directly embodied as being executed by a hardware decoding processor or by a combination of hardware and software modules in the decoding processor. The software module may be stored in a storage medium, and the storage medium is located in the first memory 73. The first processor 72 reads the information in the first memory 73 and combines it with the hardware to complete the steps of the above-described method.

[0238] In an exemplary embodiment, the devices 60 and 70 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontroller units (MCUs), microprocessors, or other electronic elements to execute the methods described above

[0239] Note that the memories (the first memory 63 and the second memory 73) in the embodiments of the present disclosure may include a volatile memory or a non-volatile memory, or may include both a volatile memory and a non-volatile memory. Here, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM (registered trademark)), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM). The magnetic surface memory may be a magnetic disk memory or a magnetic tape memory. The volatile memory may be a random access memory (RAM) used for an external high-speed cache.As a non-limiting example, various RAMs are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), Direct Rambus Random Access Memory (DRRAM). The memory described in the embodiments of the present disclosure includes, but is not limited to, these memories and other suitable types of memories.

[0240] In an exemplary embodiment, the embodiments of the present disclosure further provide a storage medium, that is, a computer storage medium, specifically, a computer-readable storage medium, including, for example, a memory for storing a computer program, and the computer program is executable by a first processor 62 of the device 60 to complete the steps of the above-described method on the device side. The computer-readable storage medium may be a memory such as FRAM (registered trademark), ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM.

[0241] Note that "first", "second", etc. are for distinguishing similar objects and do not necessarily explain a specific order or priority.

[0242] In addition, in the technical solutions described in the embodiments of the present disclosure, they can be arbitrarily combined when they do not conflict.

[0243] What has been described above is only a preferred embodiment of the present disclosure and is not intended to limit the protection scope of the present disclosure.

Claims

1. A method for function composition, comprising: obtaining a user policy that characterizes network functions and / or security functions expected by a user; obtaining a first sequence based on the user policy; transmitting the first sequence. A method for function composition.

2. The first sequence is obtained by analyzing the user policy, selecting network function modules and / or security function modules, and obtaining a first sequence including the network function modules and / or security function modules. The method according to claim 1.

3. The step of obtaining a first sequence based on the user policy includes: determining identifiers of each module in the first sequence based on a description of a network function module, a description of a security function module, a module identifier, and at least one of a plurality of function descriptions in the user policy, and obtaining a first sequence. The function description in the user policy characterizes a description of a network function expected by the user and / or a description of a security function expected by the user. The method according to claim 1 or 2.

4. The method for function composition further includes: receiving registration information transmitted from a plurality of function modules, where the registration information carries at least one of identifier information of each function module, a description of a network function supporting execution, and a description of a security function supporting execution. The method according to any one of claims 1 to 3.

5. The step of obtaining a first sequence based on the user policy includes: obtaining the first sequence based on the user policy and a preset rule. The method according to claim 1.

6. The step of obtaining a first sequence based on the user policy and a preset rule includes: determining a plurality of function modules based on a description of a network function module, a description of a security function module, a module identifier, and at least one of a plurality of function descriptions in the user policy; obtaining the first sequence based on the preset rule. The method according to claim 5. ​

7. The step of obtaining the first sequence based on the preset rule is The method according to claim 6, comprising the step of selecting and / or rearranging the plurality of function modules based on the preset rule to obtain the first sequence.

8. The function composition method Further includes the step of receiving the operation state information sent from the plurality of function modules, The step of obtaining the first sequence based on the preset rule is The method according to claim 6 or 7, comprising the step of selecting a plurality of function modules based on the operation state information to obtain the first sequence.

9. The step of obtaining the first sequence based on the preset rule is The method according to claim 6 or 7, comprising the step of obtaining the first sequence based on at least one of network topology, network delay, and network traffic load balancing.

10. The step of obtaining the first sequence based on at least one of network topology, network delay, and network traffic load balancing is The step of obtaining the source address and destination address in the user policy; and The step of obtaining the first sequence based on at least one of network topology, network delay, and network traffic load balancing. The method according to claim 9.

11. The method according to claim 10, wherein the first sequence coincides with part or all of the transfer path determined based on the source address and destination address.

12. The step of obtaining the first sequence based on at least one of network topology, network delay, and network traffic load balancing is The step of obtaining the target address in the user policy; and The step of obtaining the first sequence based on at least one of network topology, network delay, and network traffic load balancing. The method according to claim 9.

13. The method according to claim 12, wherein some or all of the functional modules indicated in the first sequence are functional modules reachable at the target address via a network.

14. The step of transmitting the first sequence is a step of transmitting the first sequence and the corresponding policy of each functional module in the first sequence, wherein the corresponding policy of each functional module is obtained based on the user policy, the method according to claim 1.

15. A function composition method, comprising: receiving a first sequence, wherein the first sequence is obtained based on a user policy, and the user policy characterizes network functions and / or security functions expected by the user.

16. The function composition method further includes: transmitting registration information carrying at least one of identifier information of each functional module, a description of network functions supporting execution, and a description of security functions supporting execution, the method according to claim 15.

17. The function composition method further includes: transmitting operation state information, wherein the operation state information is used to select a plurality of functional modules based on the operation state information to obtain the first sequence, the method according to claim 15.

18. The step of receiving the first sequence is a step of receiving the first sequence and the corresponding policy of the functional module, wherein the corresponding policy of the functional module is obtained based on the user policy, the method according to claim 15.

19. A function composition apparatus, comprising: an acquisition unit for acquiring a user policy characterizing network functions and / or security functions expected by the user; a processing unit for acquiring a first sequence based on the user policy and transmitting the first sequence. A function composition apparatus.

20. A function composition apparatus, comprising: a receiving unit for receiving a first sequence, wherein the first sequence is obtained based on a user policy, and the user policy characterizes network functions and / or security functions expected by the user.

21. A device comprising a processor and a memory for storing a computer program operable on the processor, wherein the processor is used to execute the steps of the method according to any one of claims 1 to 14 when executing the computer program, Device.

22. A device comprising a processor and a memory for storing a computer program operable on the processor, wherein the processor is used to execute the steps of the method according to any one of claims 15 to 18 when executing the computer program, Device.

23. A computer-readable storage medium storing a computer program, wherein the computer program realizes the steps of the method according to any one of claims 1 to 14 or the steps of the method according to any one of claims 15 to 18 when executed by a processor, a computer-readable storage medium.

Citation Information

Patent Citations

  • Security service system and method

    CN108092934A

  • Service function chain construction system and method thereof

    CN111988395A

  • Service process control method and network device

    JP2015525549A

  • Network function load distribution system and method

    JP2016046603A

  • Service chaining system, service chaining policy controller, and service chaining method

    JP2016046737A