Configuration update method, apparatus, and system, and computer-readable storage medium

By allowing network devices to perform configuration updates based on consistent version information without locking data objects, the method enhances parallel processing efficiency and reduces conflicts in network configuration updates.

JP7700279B2Active Publication Date: 2025-06-30HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023576200
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-07-29
Filing Date
2022-07-25
Publication Date
2025-06-30
Estimated Expiration
2042-07-25

AI Technical Summary

Technical Problem

Existing network configuration protocols, such as NETCONF, require clients to lock dataset objects for configuration updates, leading to low parallel processing control efficiency and increased configuration conflicts among multiple clients.

Method used

A method where a network device performs configuration updates on data objects without locking them, by detecting consistency in version information between the client and the network device, thereby reducing conflicts and improving parallel processing efficiency.

Benefits of technology

This approach allows for improved parallel processing control efficiency and reduced configuration conflicts among multiple clients, enabling more efficient and concurrent network configuration updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007700279000001
    Figure 0007700279000001
  • Figure 0007700279000002
    Figure 0007700279000002
  • Figure 0007700279000003
    Figure 0007700279000003
Patent Text Reader

Abstract

The embodiments of the present application disclose a configuration update method, an apparatus, and a system, and a computer-readable storage medium, and relate to the field of communication technology. In the embodiments of the present application, when a specific client performs a configuration update on a network device, the client may send a NETCONF configuration request message to the network device without locking a data object, and the network device performs a configuration update on the data object when the network device detects that the version information of the data object recorded by the client and the network device, respectively, is consistent. Alternatively, the client sends a NETCONF configuration request message to the network device when the network device detects that the version information of the data object recorded by the client and the network device, respectively, is consistent. In this way, the client does not need to lock the data object on which the configuration update needs to be performed, thereby improving concurrency control efficiency and reducing configuration conflicts between multiple clients, i.e., the impact on another client is relatively small.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims the priority of Chinese Patent Application No. 202110864449.2, titled "Configuration Update Method, Apparatus, and System, and Computer-Readable Storage Medium", filed on July 29, 2021, the entire content of which is incorporated herein by reference.

[0002] Embodiments of this application relate to the field of communication technologies, and in particular, to a configuration update method, apparatus, and system, and a computer-readable storage medium.

Background Art

[0003] The network configuration protocol (NETCONF) is a mechanism for managing network devices. An administrator can use this mechanism to perform configuration management of network devices via a client. Configuration management includes configuration updates, and configuration updates include adding, modifying, and deleting configuration data of network devices.

[0004] In the prior art, multiple clients can perform configuration updates on the same network device in a scenario where network devices are managed in a distributed manner. NETCONF defines lock operations and unlock operations. After a session is established between any client and a specific network device, in the process of performing a configuration update on the network device, the dataset that needs to be updated in the network device needs to be locked first by a lock operation, and the configuration update is performed on the network device with the dataset locked. After the configuration update is performed, the client unlocks the dataset through an unlock operation, or the client closes the session to unlock the dataset, whereupon another client performs a configuration update on the network device.

[0005] However, in the prior art, the client has to perform a configuration update on the network device while locking the dataset. In this way, when the dataset in the network device is locked by one client, another client cannot perform a configuration update on the network device based on the dataset. The parallel processing control efficiency of this solution is relatively low, and it can be known that this has a certain impact on other clients. In addition, when another client needs to urgently perform some important configuration update on the network device based on the dataset, the other client can only forcibly close the session between the client and the network device, and forcibly interrupting the session may affect the client. SUMMARY OF THE INVENTION MEANS FOR SOLVING THE PROBLEM

[0006] Embodiments of the present application provide a configuration update method, apparatus, and system, as well as a computer-readable storage medium. When a network device detects that the version information of data objects recorded by a client and the network device respectively is consistent, the method for the network device to perform a configuration update on the data object can reduce the conflict of configuration updates and improve the parallel processing control efficiency. The technical solution is as follows.

[0007] According to a first aspect, a configuration update method is provided. The method includes the following.

[0008] The network device receives a network configuration protocol NETCONF configuration request message sent by a first client. The NETCONF configuration request message contains operation instruction information, which indicates that the first client requests the network device to perform an operation on a first data object. The operation instruction information includes first version information, which is the version information of the first data object recorded by the first client. The first data object includes the configuration data of the network device. When the network device detects that the first version information is consistent with the first reference version information, the network device performs an operation on the first data object. The first reference version information is the version information of the first data object recorded by the network device.

[0009] That is, when a specific client performs a configuration update on a network device, the client can send a NETCONF configuration request message to the network device without locking the data object. When the network device detects that the version information of the data object recorded by the client and the network device respectively is consistent, the network device performs a configuration update on the data object. In this way, the client does not need to lock the data object on which the configuration update needs to be performed, and as a result, the parallel processing control efficiency is improved and the configuration conflict among multiple clients is reduced, that is, the impact on another client is relatively small.

[0010] Optionally, before sending a NETCONF configuration request message, the first client may or may not detect the consistency of the version information. If the first client detects the consistency of the version information, the NETCONF configuration request message is sent when the first client detects that the first version information is consistent with the first reference version information. That is, both the first client and the network device can detect the consistency of the version information to sufficiently reduce configuration conflicts. If the first client detects that the version information is inconsistent, the first client cannot send a configuration request message. As a result, improper requests from the first client are avoided.

[0011] Optionally, the method further includes the network device receiving a query message sent by a first client, the query message including an identifier of a first data object, the network device sending a query response message to the first client, the query response message including version information of the first data object recorded by the network device. That is, the first client can obtain the version information of the first data object recorded by the network device in an immediate query manner. It should be noted that the first client can send a query message to the network device at any time to query the version information of a specific data object. For example, the first client can send a query message to the network device when it is necessary to detect the consistency of the version information, that is, the network device receives the query message sent by the first client before receiving the NETCONF configuration request message sent by the first client. Alternatively, the first client may send a query message to the network device after sending a NETCONF configuration request message for a period of time. For example, after the network device executes an operation on the first data object, it receives the query message sent by the first client and notifies the first client of the latest version information of the first data object, whereby the first client can confirm whether the network device has successfully executed the operation on the first data object. Alternatively, the first client may send a query message to the network device at any other time to query the version information of a specific data object.

[0012] Optionally, in this method, the network device sends a data change notification message to the first client, the data change notification message includes the version information of the first data object recorded by the network device, and the data change notification message is sent by the network device when the first client subscribes to the change notification of the data in the first data object. That is, the first client can obtain the version information of the first data object recorded by the network device in a subscription manner, that is, obtain the latest version information recorded by the network device. For example, when the network device modifies the data in the first data object based on the request of another client, that is, when the data in the first data object is changed, the network device sends a data change notification message to the first client, and the data change notification message includes the latest version information of the first data object recorded by the network device.

[0013] Note that the two embodiments (including the immediate query method and the subscription method) for the first client to obtain the version information of the first data object recorded by the network device may be used separately or in combination. This is not limited in the present embodiment of this application.

[0014] Optionally, in the present embodiment of this application, the version information includes a version number, a timestamp, or a sequence number. For example, the version information includes a timestamp, and the first reference version information is the system time when the network device completed the operation on the first data object recorded by the network device, or the first reference version information is the system time when the network device started the operation on the first data object recorded by the network device.

[0015] In this embodiment of the present application, some operations are operations related to two data objects, such as a copy operation. Optionally, in order to ensure that the configuration data in the two data objects is consistent with the configuration data maintained by the first client, the network device needs to separately detect the consistency of the version information of the two data objects. A copy operation is used as an example. Optionally, the operation requested by the network device to be executed by the first client on the first data object includes a copy operation, and the operation instruction information further includes fifth version information, and the fifth version information is the version information of the fifth data object recorded by the first client, and the fifth data object includes the configuration data of the network device, and the copy operation is used to overwrite the configuration data in the first data object with the configuration data in the fifth data object. In this case, the network device executing an operation on the first data object when the network device detects that the first version information is consistent with the first reference version information means that when the network device detects that the first version information is consistent with the first reference version information and the fifth version information is consistent with the fifth reference version information, the network device executes an operation on the first data object, and the fifth reference version information is the version information of the fifth data object recorded by the network device.

[0016] Optionally, the method further includes the network device completing the execution of an operation on the first data object and the network device recording the first reference version information.

[0017] Optionally, when the network device records the first reference version information, it includes updating and recording the first reference version information when the data granularity of the first data object corresponding to the first reference version information meets the data granularity at which the network device sets the access control function. That is, when the first data object itself has version information, after the data of the first data object is changed, the network device needs to update the version information of the first data object to record the change status of the first data object using the version information.

[0018] Optionally, the operation instruction information further includes an identifier of a second data object, the first data object is a child data object of the second data object, and the second reference version information is the version information of the second data object recorded by the network device. When the network device records the first reference version information, it includes updating and recording the first reference version information and the second reference version information when the data granularity of the first data object corresponding to the first reference version information meets the data granularity at which the network device sets the access control function and the data granularity of the second data object corresponding to the second reference version information meets the data granularity at which the network device sets the access control function. That is, when the first data object itself has version information and the parent data object of the first data object (i.e., the second data object) also has version information, after the data of the first data object is changed, the second data object is also changed. In this case, the network device not only needs to update the version information of the first data object but also needs to update the version information of the second data object.

[0019] Optionally, the operation instruction information further includes an identifier of a third data object, the first data object is a child data object of the third data object, the third reference version information is the version information of the third data object recorded by the network device, and the access control function set by the network device supports a reverse selection mechanism. The network device recording the first reference version information means that the data granularity of the first data object corresponding to the first reference version information meets the data granularity at which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information meets the data granularity at which the network device sets the access control function, and when the reverse selection mechanism parameter of the access control function set by the network device does not include the identifier of the first data object, the network device updates and records the first reference version information and the third reference version information, or the data granularity of the first data object corresponding to the first reference version information meets the data granularity at which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information meets the data granularity at which the network device sets the access control function, and when the reverse selection mechanism parameter of the access control function set by the network device includes the identifier of the first data object, the network device includes updating and recording the first reference version information. That is, the access control function set by the network device supports a reverse selection mechanism, and the reverse selection mechanism is used to reverse-select child data objects from a parent data object, whereby data changes to the child data object do not affect the version information of the parent data object.

[0020] In this embodiment of the present application, multi-user parallel access control is implemented using an access control mechanism, and as a result, it can be known from the foregoing that reducing configuration conflicts. That is, in this solution, in order to further perform a configuration update on the network device by detecting the consistency of version information, a version information attribute is set for the data object using the access control function. Optionally, the client may request the network device to set the access control function for the data object before the configuration update is performed on the network device by detecting the consistency of the version information. This will be described below.

[0021] Optionally, in this method, the network device receives an access control function setting request message sent by a first client, the access control function setting request message includes an identifier of a first data object, and when the network device determines that the first data object meets the access control function setting condition based on the identifier of the first data object, the network device sets an initial version information value of the first data object based on the identifier of the first data object, and the network device sends a setting success response message to the first client, and the setting success response message further includes indicating to the first client to record the version information of the first data object.

[0022] Optionally, the setting success response message includes the initial version information value, or the setting success response message indicates to the first client to set the initial version information value of the first data object. That is, the network device uses the setting success response message to notify the first client of the specified initial version information value, or the first client automatically sets the initial version information value of the first data object after receiving the setting success response message.

[0023] Optionally, the access control function setting conditions include that the network device supports the setting of the access control function and the first data object does not have version information. That is, if the network device supports the setting of the access control function via the client and the access control function is not set for the first data object, the network device can normally set the access control function for the first data object.

[0024] Optionally, the access control function setting conditions further include that the data granularity of the first data object meets the data granularity for setting the access control function supported by the network device. That is, the data granularity for setting the access control function supported by the network device may or may not include the data granularity of the first data object. If the network device supports the setting of the access control function via the client, the access control function is not set for the first data object, and the data granularity for setting the access control function supported by the network device includes the data granularity of the first data object, the network device can normally set the access control function for the first data object.

[0025] Optionally, the access control function setting request message further includes a reverse selection mechanism parameter, and the reverse selection mechanism parameter includes identifiers of one or more fourth data objects, and the fourth data object is a child data object of the first data object. That is, the first client can also set the reverse selection mechanism parameter when setting the access control function of the first data object to reverse-select some child data objects of the first data object (i.e., the fourth data object) from the first data object, so that the data change of the fourth data object does not affect the version information of the first data object.

[0026] Optionally, the method further includes: a network device receiving an access control function setting deletion request message sent by a first client, the access control function setting deletion request message including an identifier of a first data object, and the network device determining, based on the identifier of the first data object, that the first data object meets an access control function setting deletion condition, and the network device deleting version information of the first data object based on the identifier of the first data object.

[0027] Optionally, the access control function setting deletion condition includes that the network device supports the setting of the access control function and the network device records version information of the first data object. That is, when the network device supports the setting of the access control function via a client and the access control function has already been set for the first data object, the network device can normally delete the version information of the first data object, that is, cancel the access control protection of the first data object.

[0028] Optionally, the method further includes: the network device sending a capability notification message to the first client, the capability notification message including a support capability parameter of the access control function, and the support capability parameter indicating whether the network device supports the setting of the access control function.

[0029] Optionally, the capability notification message further includes a support granularity parameter of the access control function, where the support granularity parameter indicates that the network device supports the data granularity for setting the access control function, and the data granularity includes one or more of dataset granularity, YANG module granularity, and data node granularity. That is, the network device can further notify the client of the support capability and support granularity of the access control function, so that the client can accurately send a request message regarding setting or deleting the access control function to the network device.

[0030] According to a second aspect, a configuration update method is provided. The method includes the following.

[0031] The first client sends a Network Configuration Protocol (NETCONF) configuration request message to the network device. The NETCONF configuration request message includes operation instruction information, where the operation instruction information indicates that the first client requests the network device to perform an operation on a first data object, and the operation instruction information includes first version information, where the first version information is the version information of the first data object recorded by the first client, and the first data object includes the configuration data of the network device. The configuration request message indicates to the network device to perform an operation on the first data object when the network device detects that the first version information is consistent with the first reference version information, and the first reference version information is the version information of the first data object recorded by the network device.

[0032] That is, when a specific client executes a configuration update on a network device, the client can send a NETCONF configuration request message to the network device without locking the data object. When the network device detects that the version information of the data object recorded by the client and the network device respectively is consistent, the network device executes a configuration update on the data object. In this way, the client does not need to lock the data object for which the configuration update needs to be executed, and as a result, the parallel processing control efficiency is improved and the configuration conflict between multiple clients is reduced, that is, the impact on another client is relatively small.

[0033] Optionally, before sending the NETCONF configuration request message, the first client may or may not detect the consistency of the version information. When the first client detects the consistency of the version information, the NETCONF configuration request message is sent when the first client detects that the first version information is consistent with the first reference version information. That is, both the first client and the network device can detect the consistency of the version information to sufficiently reduce the configuration conflict. When the first client detects that the version information is inconsistent, the first client cannot send a configuration request message. As a result, improper requests from the first client are avoided. Optionally, the first client obtains the version information of the first data object recorded by the network device in an immediate query or subscription manner. The embodiment is consistent with the related process in the first aspect and will not be described in detail here again.

[0034] Optionally, after the first client sends a network configuration protocol NETCONF configuration request message to the network device, the method further includes the first client receiving a configuration success response message sent by the network device and the first client updating first version information. That is, after learning that the network device has successfully executed an operation on the first data object, the first client can further update the first version information to record the change status of the first data object.

[0035] Optionally, the configuration success response message includes updated first reference version information. The first client updating the first version information includes the first client updating the first version information to the updated first reference version information. That is, the network device directly notifies the first client of the updated first reference version information using the configuration success response message, and the first client directly updates the first version information to the updated first reference version information.

[0036] Note that the configuration update method of the second aspect is consistent with the configuration update method of the first aspect. In the second aspect, only some content corresponding to the first aspect is described. For content not described in the second aspect, refer to the first aspect. Details are not described in the second aspect.

[0037] According to a third aspect, a configuration update method is provided. The method includes the following.

[0038] When the first client detects that the first version information matches the first reference version information, the first client sends a network configuration protocol NETCONF configuration request message to the network device. The first version information is the version information of the first data object recorded by the first client, the first reference version information is the version information of the first data object recorded by the network device, the NETCONF configuration request message carries operation instruction information, and the operation instruction information indicates that the first client requests the network device to perform an operation on the first data object.

[0039] That is, in the present embodiment of the present application, when a specific client performs a configuration update on a network device, if the client does not lock the data object and detects that the version information of the data object recorded by the client and the network device respectively is consistent, the client may send a NETCONF configuration request message to the network device. In this way, the client does not need to lock the data object for which the configuration update needs to be performed, and as a result, the parallel processing control efficiency is improved, and the configuration conflict between multiple clients is reduced, that is, the impact on another client is relatively small.

[0040] Optionally, the method further includes that the first client sends an inquiry message to the network device, the inquiry message carries the identifier of the first data object, the first client receives the inquiry response message sent by the network device, and the inquiry response message carries the version information of the first data object recorded by the network device. That is, the first client can obtain the version information of the first data object recorded by the network device in an immediate inquiry manner.

[0041] Optionally, the method further includes a first client receiving a data change notification message sent by a network device, the data change notification message carrying version information of a first data object recorded by the network device, and the data change notification message being received when the first client has subscribed to receive notifications of changes to data within the first data object. That is, the first client may obtain the version information of the first data object recorded by the network device in a subscription manner.

[0042] Note that in the first and second aspects, to reduce configuration conflicts and improve parallel processing control efficiency, the network device detects the consistency of the version information, or the client and the network device detect the consistency of the version information. In the third aspect, the client detects the consistency of the version information to reduce configuration conflicts and improve parallel processing control efficiency. That is, the difference between the third aspect and the first / second aspects lies in the different entities for detecting the consistency of the version information. However, other contents described in the first and second aspects are also applicable to the third aspect. Details are not described in the third aspect of the embodiments of the present application.

[0043] According to a fourth aspect, a configuration update device is provided. The configuration update device has a function of implementing the behavior of the configuration update method in the first aspect. The configuration update device includes one or more modules, and the one or more modules are configured to implement the configuration update method provided in the first aspect.

[0044] That is, a configuration update device is provided. This device is used for a network device. This device Receive a NETCONF configuration request message sent by a first client, where the NETCONF configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to perform an operation on a first data object. The operation instruction information includes first version information, and the first version information is the version information of the first data object recorded by the first client. The first data object is configured to include the configuration data of the network device, and a first receiving module configured as such. When the network device detects that the first version information matches the first reference version information, execute an operation on the first data object. The first reference version information is the version information of the first data object recorded by the network device, and a configuration update module configured as such. Including.

[0045] Optionally, the NETCONF configuration request message is sent when the first client detects that the first version information matches the first reference version information.

[0046] Optionally, the device Receive an inquiry message sent by the first client, where the inquiry message includes an identifier of the first data object, and a second receiving module configured as such. Send an inquiry response message to the first client, where the inquiry response message includes the version information of the first data object recorded by the network device, and a first sending module configured as such. Further including.

[0047] Optionally, the device Send a data change notification message to the first client, where the data change notification message includes version information of the first data object recorded by the network device, and the data change notification message is configured to be sent by the network device when the first client subscribes to the data change notification within the first data object, a second transmission module Further include.

[0048] Optionally, the version information includes a timestamp, and the first reference version information is the system time when the network device completed performing an operation on the first data object recorded by the network device, or the first reference version information is the system time when the network device started performing an operation on the first data object recorded by the network device.

[0049] Optionally, the device A processing module configured to complete performing an operation on the first data object, and A recording module configured to record the first reference version information Further include.

[0050] Optionally, the recording module A first recording sub-module configured to update and record the first reference version information when the data granularity of the first data object corresponding to the first reference version information meets the data granularity for which the network device sets the access control function Include.

[0051] Optionally, the operation instruction information further includes an identifier of a second data object, the first data object is a child data object of the second data object, and the second reference version information is the version information of the second data object recorded by the network device.

[0052] The recording module A second recording sub-module configured to update and record the first reference version information and the second reference version information when the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity for which the network device sets the access control function, and the data granularity of the second data object corresponding to the second reference version information satisfies the data granularity for which the network device sets the access control function includes.

[0053] Optionally, the operation instruction information further includes an identifier of a third data object, the first data object is a child data object of the third data object, the third reference version information is the version information of the third data object recorded by the network device, and the access control function set by the network device supports a reverse selection mechanism.

[0054] The recording module A third recording sub-module configured to update and record the first reference version information and the third reference version information when the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity for which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity for which the network device sets the access control function, and the reverse selection mechanism parameter of the access control function set by the network device does not include the identifier of the first data object When the data granularity of the first data object corresponding to the first reference version information meets the data granularity for the network device to set the access control function, and the data granularity of the third data object corresponding to the third reference version information meets the data granularity for the network device to set the access control function, and the inverse selection mechanism parameter of the access control function set by the network device includes the identifier of the first data object, a fourth recording sub-module configured to update and record the first reference version information and including.

[0055] Optionally, the apparatus includes a third receiving module configured to receive an access control function setting request message sent by a first client, where the access control function setting request message includes an identifier of the first data object, and a setting module configured to set an initial version information value of the first data object based on the identifier of the first data object when the network device determines that the first data object meets the access control function setting conditions based on the identifier of the first data object, and a third sending module configured to send a setting success response message to the first client, where the setting success response message indicates to the first client to record the version information of the first data object. further includes.

[0056] Optionally, the setting success response message includes the initial version information value, or the setting success response message indicates to the first client to set the initial version information value of the first data object.

[0057] Optionally, the access control function setting conditions include that the network device supports setting the access control function and the first data object does not have version information.

[0058] Optionally, the access control function setting condition further includes that the data granularity of the first data object meets the data granularity of the set access control function supported by the network device.

[0059] Optionally, the access control function setting request message further includes a reverse selection mechanism parameter, and the reverse selection mechanism parameter includes identifiers of one or more fourth data objects, and the fourth data object is a child data object of the first data object.

[0060] Optionally, the apparatus is configured with a fourth receiving module that receives an access control function setting deletion request message sent by the first client, and the access control function setting deletion request message includes an identifier of the first data object, and a deletion module configured to delete the version information of the first data object based on the identifier of the first data object when the network device determines that the first data object meets the access control function setting deletion condition based on the identifier of the first data object further includes.

[0061] Optionally, the access control function setting deletion condition includes that the network device supports the setting of the access control function and the network device records the version information of the first data object.

[0062] Optionally, the apparatus is configured with a fourth sending module that sends a capability notification message to the first client, and the capability notification message includes a support capability parameter of the access control function, and the support capability parameter indicates whether the network device supports the setting of the access control function further includes.

[0063] Optionally, the capability notification message further includes a support granularity parameter of the access control function, where the support granularity parameter indicates that the network device supports the data granularity for setting the access control function, and the data granularity includes one or more of dataset granularity, YANG module granularity, and data node granularity.

[0064] Optionally, the operation includes a copy operation, the operation instruction information further includes fifth version information, where the fifth version information is the version information of the fifth data object recorded by the first client, the fifth data object includes the configuration data of the network device, and the copy operation is used to overwrite the configuration data in the first data object with the configuration data in the fifth data object.

[0065] The configuration update module is configured with a configuration update sub-module that executes an operation on the first data object when the network device detects that the first version information is consistent with the first reference version information and the fifth version information is consistent with the fifth reference version information, where the fifth reference version information is the version information of the fifth data object recorded by the network device. including.

[0066] According to a fifth aspect, a configuration update device is provided. The configuration update device has a function of implementing the behavior of the configuration update method in the second aspect. The configuration update device includes one or more modules, and the one or more modules are configured to implement the configuration update method provided in the second aspect.

[0067] That is, a configuration update device is provided. This device is used by the first client. This device A first transmission module configured to send a NETCONF configuration request message of a network configuration protocol to a network device, the NETCONF configuration request message including operation instruction information, the operation instruction information indicating a request to the network device to perform an operation on a first data object, the operation instruction information including first version information, the first version information being version information of the first data object recorded by a first client, and the first data object including configuration data of the network device including.

[0068] When the network device detects that the first version information matches the first reference version information, the configuration request message indicates to the network device to perform an operation on the first data object, and the first reference version information is version information of the first data object recorded by the network device.

[0069] Optionally, the apparatus further includes a receiving module configured to receive a configuration success response message sent by the network device, and an updating module configured to update the first version information and further includes.

[0070] Optionally, the configuration success response message includes updated first reference version information.

[0071] The updating module includes an updating sub-module configured to update the first version information to the updated first reference version information and includes.

[0072] According to the sixth aspect, a configuration update device is provided. The configuration update device has a function of implementing the behavior of the configuration update method in the third aspect. The configuration update device includes one or more modules, and the one or more modules are configured to implement the configuration update method provided in the third aspect.

[0073] That is, a configuration update device is provided. This device is used for the first client. This device A first transmission module configured to send a network configuration protocol NETCONF configuration request message to a network device when the first client detects that the first version information matches the first reference version information is included.

[0074] The first version information is the version information of the first data object recorded by the first client, the first reference version information is the version information of the first data object recorded by the network device, the NETCONF configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to execute an operation on the first data object.

[0075] Optionally, this device A second transmission module configured to send an inquiry message to the network device, the inquiry message including the identifier of the first data object, and A first reception module configured to receive an inquiry response message sent by the network device, the inquiry response message including the version information of the first data object recorded by the network device are further included.

[0076] Optionally, this device Receives a data change notification message sent by a network device, the data change notification message including version information of a first data object recorded by the network device, the data change notification message being received when a first client subscribes to a notification of a change in data within the first data object, a second receiving module configured as such further includes.

[0077] According to a seventh aspect, a communication device is provided. The communication device includes a processor and a memory. The memory stores a program for executing a configuration update method provided in the first aspect, the second aspect, or the third aspect, and is configured to store data used to implement the configuration update method provided in the first aspect, the second aspect, or the third aspect. The processor is configured to execute the program stored in the memory. The communication device may further include a communication bus, the communication bus being configured to establish a connection between the processor and the memory.

[0078] According to an eighth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions. When the instructions are executed on a computer, the computer is enabled to execute a configuration update method according to the first aspect, the second aspect, or the third aspect.

[0079] According to a ninth aspect, a computer program product including instructions is provided. When the computer program product is executed on a computer, the computer is enabled to execute a configuration update method according to the first aspect, the second aspect, or the third aspect.

[0080] The technical effects obtained in the fourth aspect, the fifth aspect, the sixth aspect, the seventh aspect, the eighth aspect, and the ninth aspect are the same as the technical effects obtained by using the corresponding technical means in the first aspect, the second aspect, or the third aspect. Details are not described again here.

[0081] The technical solutions provided in the embodiments of this application can bring at least the following beneficial effects.

[0082] In the embodiments of this application, when a specific client executes a configuration update on a network device, the client can send a NETCONF configuration request message to the network device without locking the data object. When the network device detects that the version information of the data object recorded by the client and the network device respectively is consistent, the network device executes a configuration update on the data object. Alternatively, when the client detects that the version information of the data object recorded by the client and the network device respectively is consistent, the client sends a NETCONF configuration request message to the network device. In this way, the client does not need to lock the data object for which the configuration update needs to be executed. As a result, the parallel processing control efficiency is improved, and the configuration conflict among multiple clients is reduced, that is, the impact on another client is relatively small.

Brief Description of the Drawings

[0083]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments for Carrying Out the Invention

[0084] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following further describes the embodiments of the present application in detail with reference to the accompanying drawings.

[0085] For ease of understanding, some nouns and terms in the embodiments of the present application are first explained.

[0086] Network Configuration Protocol (NETCONF): A mechanism used to manage network devices. An administrator can use this mechanism to perform configuration management on network devices via a client. Configuration management includes configuration updates, and configuration updates include adding, modifying, and deleting configuration data of network devices. An administrator can further obtain configuration data and status data, etc. of network devices using a client. NETCONF is a network configuration and management protocol based on the Extensible Markup Language (XML), and it implements communication between a client and a network device based on a Remote Procedure Call (RPC) mechanism. The Network Configuration Protocol (NETCONF) is defined in Request for Comments (RFC) 6241 and RFC8526.

[0087] Datastore: Multiple datastores (also called configuration datastores, databases, and configuration databases, etc.) are permitted to be defined in the NETCONF protocol to store the configuration data and status information of network devices. For example, datastores include a running datastore, a candidate datastore, and a startup datastore. The running datastore is used to store the configuration data that becomes effective in the running process of a network device. The candidate datastore is used to store the configuration data that is configured for a network device but not yet effective, that is, the configuration data that is edited by a storage administrator but not committed regarding formal validity. After the candidate datastore is committed and becomes the running datastore, the configuration data becomes formally effective. The startup datastore stores the configuration data to be used for the next startup of a network device.

[0088] YANG (Yet Another Next Generation): First designed as a data modeling language for NETCONF.

[0089] YANG model: A data model established using the YANG data modeling language is called a YANG model. The YANG model can be maintained by a NETCONF client and a network device. The YANG model represents the configuration data and status data of a network device in the form of data nodes. The YANG model defines the data structures that can be used for NETCONF-based operations. The data instantiated using the YANG model can be stored in XML or JSON encoding formats.

[0090] YANG module: A dataset may include one or more YANG modules. That is, one dataset may store configuration data and status information of multiple YANG modules, etc.

[0091] Data node: One YANG module may include one or more data nodes. Multiple data modules are organized into a tree structure. That is, one YANG module may store configuration data and status information of one or more data nodes, etc.

[0092] The system architecture used in the embodiments of this application is described below. It should be noted that the network architecture and service scenarios described in the embodiments of this application are intended to more clearly explain the technical solutions in the embodiments of this application and do not constitute a limitation on the technical solutions provided in the embodiments of this application. Those skilled in the art may know that with the development of network architecture and the emergence of new service scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0093] FIG. 1 is a diagram of the architecture of a system in a configuration update method according to an embodiment of this application. This system may be called a network management system (NMS) or a NETCONF system, etc. Refer to FIG. 1. This system includes a plurality of clients and a network device 101. In FIG. 1, an example in which a plurality of clients include a first client 102 and a second client 103 is used for illustration. Each client among the plurality of clients is connected to the network device 101 in a wired or wireless manner to execute communication. As shown in FIG. 1, each client and the network device 101 can communicate with each other using the Internet protocol (IP) network.

[0094] A plurality of clients are configured to perform configuration updates on the network device 101 using the NETCONF protocol. For example, a first client 102 within the plurality of clients is used as an example. The first client 102 transmits a NETCONF configuration request message to the network device 101 according to the configuration update method provided in the present embodiment of the present application in order to request to perform a configuration update on the network device 101. The NETCONF configuration request message may be simply referred to as a configuration request message and will be described according to a short name in the following embodiments.

[0095] The network device 101 is configured to update the configuration data of the network device 101 using the NETCONF protocol. For example, the network device 101 receives the configuration request message transmitted by the first client 102 and updates the configuration data of the network device 101 according to the configuration update method provided in the present embodiment of the present application.

[0096] Optionally, the system includes a plurality of network devices, and each network device can establish a communication connection to at least one client in order to perform a configuration update using the connected client, and any client can perform a configuration update on at least one network device. In the present embodiment of the present application, the configuration update of one network device is used as an example for explanation, and the principle of performing a configuration update on another network device is the same.

[0097] From the foregoing, it can be known that the present system adopts a client / server architecture. The client may also be referred to as a network management device, a management device, or a controller, etc. The server is a network device.

[0098] In this embodiment of the present application, the client may be installed and deployed on any type of computer device, such as a server, a desktop computer, a notebook computer, or a mobile phone, or may be installed and deployed on the computing and storage resources of a cloud platform. The network device may be a device such as a router, a switch, a gateway, or a firewall. Optionally, the client may perform a configuration update on the network device by executing an application program or a web page or the like. For example, an administrator (also referred to as a network operation and maintenance staff or a network management system, etc.) may edit, commit, and query configuration data and the like using an application program executed on the client.

[0099] FIG. 2 is a schematic diagram of the structure of a communication device according to an embodiment of the present application. Optionally, the computer device is the client or the network device shown in FIG. 1, and the communication device includes one or more processors 201, a communication bus 202, a memory 203, and one or more communication interfaces 204.

[0100] Processor 201 is a general-purpose central processing unit (CPU), network processor (NP), microprocessor, or one or more integrated circuits configured to implement the solution of this application, for example, an application-specific integrated circuit (ASIC), programmable logic device (PLD), or a combination thereof. Optionally, the PLD is a complex programmable logic device (CPLD), field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.

[0101] Communication bus 202 is configured to transmit information between the aforementioned components. Optionally, communication bus 202 is classified into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure to represent the bus, but this does not mean that there is only one bus or only one type of bus.

[0102] Optionally, memory 203 can be configured to hold or store program code in the form of instructions or data structures in a read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), optical disk (including compact disc read-only memory (CD-ROM), compact disc, laser disc, digital versatile disc, or Blu-ray disc, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be accessed by a computer and is capable of holding or storing program code in the form of instructions or data structures. However, this does not constitute a limitation here. Memory 203 exists independently and is connected to processor 201 via communication bus 202, or memory 203 is integrated with processor 201.

[0103] Communication interface 204 is configured to communicate with another device or communication network using any device such as a transceiver. Communication interface 204 includes a wired communication interface and optionally may include a wireless communication interface. The wired communication interface is, for example, an Ethernet interface. Optionally, the Ethernet interface is an optical interface, an electrical interface, or a combination thereof. The wireless communication interface is a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof, etc.

[0104] Optionally, in some embodiments, the communication device includes a plurality of processors, for example, processors 201 and 205 shown in FIG. 2. Each of the processors is a single-core processor or a multi-core processor. Optionally, the processors here are one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0105] In a specific implementation, in one embodiment, the communication device further includes an output device 206 and an input device 207. The output device 206 communicates with the processor 201 and can display information in a plurality of ways. For example, the output device 206 is a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device 207 communicates with the processor 201 and can receive input from the user in a plurality of ways. For example, the input device 207 is a mouse, a keyboard, a touch screen device, or a sensing device.

[0106] In some embodiments, the memory 203 is configured to store program code 210 for executing the solutions of the present application, and the processor 201 can execute the program code 210 stored in the memory 203. The program code includes one or more software modules, and the communication device can use the processor 201 and the program code 210 in the memory 203 to implement the configuration update method provided in the following embodiments of FIGS. 3 to 6.

[0107] The following describes the configuration update method provided in the embodiments of the present application.

[0108] In an embodiment of the present application, in the process of a first client executing a configuration update on a network device, the first client does not need to lock data objects (such as data sets, YANG modules, or data nodes) that need to be updated in the network device. The first client and the network device respectively record the version information of the data object, and determine whether to execute the configuration update or interrupt the configuration update by detecting the consistency of the version information. In one embodiment, after the first client sends a configuration request message to the network device, the network device determines whether to execute the configuration update by detecting the consistency of the version information. In another embodiment, the first client detects the consistency of the version information, and after detecting that the version information is consistent, sends a configuration request message to the network device, and the network device executes the configuration update after receiving the configuration request message. In yet another embodiment, the first client detects the consistency of the version information, and after detecting that the version information is consistent, sends a configuration request message to the network device, and the network device also detects the consistency of the version information after receiving the configuration request message, and executes the configuration update when detecting that the version information is consistent.

[0109] In the embodiments of the present application, the version information of a data object is essentially optimistic lock information. That is, it should be noted that in this solution, in order to reduce configuration conflicts, an optimistic lock mechanism is used to implement multi-user parallel access control. The optimistic lock mechanism can also be referred to as a parallel access control mechanism. In the embodiments of the present application, an access control function is set for the data object (which can also be referred to as setting lock protection, setting access control protection, or setting an optimistic lock) in order to further perform a configuration update on the network device by detecting the consistency of the version information. To facilitate understanding, before explaining the execution of a configuration update on the network device by detecting the consistency of the version information, the implementation manner of setting the access control protection of the data object will be explained first. Setting the access control protection of a specific data object is essentially setting an optimistic lock for the data object (which can also be considered as setting lock protection), and it is necessary to note that whether access control protection can be set for the data object is determined according to whether the network device supports the setting of the access control function (which can also be referred to as the optimistic lock function). In the embodiments of the present application, the network device supports the setting of the access control function, whereby the configuration update method provided in the embodiments of the present application can be implemented. Setting the access control protection of a data object includes adding access control protection and deleting access control protection. The following will explain the implementation manners of adding access control protection and deleting access control protection with respect to the data object respectively.

[0110] First, an embodiment of adding access control protection to a data object is described, and an example is used in the description where a first client requests a network device to add access control protection to a first data object. Note that all other clients other than the first client may request the network device to add access control protection to one or more data objects. The principle is the same as the principle that the first client requests the network device to add access control protection to the first data object, and the details will not be described one by one in this specification.

[0111] In the present embodiment of the present application, the first client sends an access control function setting request message to the network device, and the network device receives the access control function setting request message sent by the first client. The access control function setting request message may also be called an access control protection addition request message or a protection addition request message, etc. The following uses a protection addition request message as an example for illustration. The protection addition request message sent by the first client includes an identifier of the first data object. When the network device determines that the first data object meets the access control function setting conditions based on the identifier of the first data object, the network device sets an initial version information value of the first data object based on the identifier of the first data object. The network device sends a setting success response message to the first client, and the setting success response message indicates to the first client to record the version information of the first data object. The access control function setting conditions may also be called access control protection addition conditions or protection addition conditions, and the setting success response message may also be called an addition success response message. The following uses protection addition conditions and addition success response messages as examples for illustration.

[0112] Optionally, in the embodiments of the present application, the version information includes a version number, a timestamp, or a sequence number. Optionally, the version number is in an explanatory naming format including one or more of characters, numbers, and symbols. An example of version1.2.0 is used. This version number includes the character version, numbers, and symbols, and the naming format is the major version number of version.minor version number.minor number. In another example, when the version number is 1, the version number includes numbers. Using a timestamp as the version information of a data object means that a network device uses system time information as the version identifier of the data object. The sequence number is a group of numerical sequences, and the numerical sequences may be randomly generated or generated according to a generation rule. For example, a network device obtains a sequence number based on the operation completion time information of a data object using a hash algorithm and uses the sequence number as the version information of the data object. For example, when the version information is a version number, the initial version information value set by the network device for the first data object may be 1 or version1.0.0. When the version information is a timestamp, the initial version information value set by the network device for the first data object may be the system time when the network device sets the access control protection for the first data object.

[0113] Optionally, the additional successful response message includes the initial version information value set by the network device for the first data object. In this way, the first client records the initial version information value included in the additional successful response message as the version information of the first data object. Alternatively, the additional successful response message indicates to the first client to set the initial version information value of the first data object. In this way, after receiving the additional successful response message, the first client sets the initial version information value of the first data object and records the specified initial version information value as the version information of the first data object.

[0114] Optionally, in the present embodiment of the present application, the additional protection condition includes that the network device supports the setting of the access control function and the first data object does not have version information. That is, when the network device supports the setting of the access control function and access control protection has not been added for the first data object, the network device can normally add access control protection for the first data object. It should be noted that the fact that the network device supports the setting of the access control function means that the network device supports the client in setting the access control function for the data object, that is, the network device supports the client in the dynamic setting of the access control function. Optionally, if the network device is configured to support the access control function by default but does not support the client in the dynamic setting of the access control function, it can be considered that the network device does not support the setting of the access control function or does not support the dynamic setting of the access control function. For example, the fact that the access control function has already been set for the data object is configured by default on the network device before distribution, and the addition or deletion of the access control function for the data object is not supported on the client.

[0115] From the foregoing, it can be known that the data objects storing the configuration data of the network device can be data sets, YANG modules, and data nodes. In other words, the data granularity of the data objects in the present embodiment of the present application can be data set granularity, YANG module granularity, or data node granularity. Based on this, optionally, the data granularity supported when the network device sets the access control function can include one or more of data set granularity, YANG module granularity, and data node granularity. That is, in this solution, the access control protection may be set only for the data set, the access control protection may be set only for the YANG module, the access control protection may be set only for the data node device, the access control protection may be set for the data set and the YANG module, the access control protection may be set for the data set and the data node, the access control protection may be set for the YANG module and the data node device, or the access control protection may be set for the data set, the YANG module, and the data node.

[0116] Based on this, optionally, the protection addition condition further includes that the data granularity of the first data object satisfies the data granularity for setting the access control function supported by the network device. That is, when the network device supports setting the access control function, the access control protection has not been added for the first data object, and the data granularity of the first data object satisfies this condition, the network device can normally add the access control protection for the first data object.

[0117] If the network device supports the setting of the access control function by default and does not limit the supported data granularity for setting the access control function, after receiving the protection addition request message from the first client, it should be noted that the network device adds access control protection for the data object requested by the first client.

[0118] In the present embodiment of this application, if the first data object does not meet the protection addition conditions, the network device sends an addition failure response message to the first client, and the addition failure response message may also be called a setting failure response message. Optionally, the addition failure response message conveys the cause of the access control protection addition failure. The cause of the access control protection addition failure may be that the network device does not support the setting of the access control function, or that the network device supports the setting of the access control function, but access control protection has already been added for the first data object.

[0119] For example, by extending NETCONF, access control protection is set for the data object. For example, the set-ol-capability operation is defined to set the access control protection for the data object. <set-ol-capability>The parameters inside are <target>and <support>including <target>The parameter conveys the identifier of the data object for which additional access control protection is required. <support>The value of the parameter is either "True" or "False", and "True" means <target>Indicates that additional access control protection is required for the data object indicated by the parameter, and "False" means <target>Indicates that removal of access control protection is requested for a data object indicated by a parameter.

[0120] For example, assume that a first client requests to add access control protection to a data set. The protection addition request message sent to the network device by the first client carries the following information. <target>The parameter indicates a dataset, which is the first client <target>It indicates a request to add access control protection for a data set indicated by a parameter. The data set is the running data set. That is, <set-ol-capability>The content within the parameter indicates adding access control protection for the running data set. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <set-ol-capability> <target> <running / > < / target> <support> True < / support> < / set-ol-capability> < / rpc>

[0121] When the running data set meets the protection addition conditions, the additional success response message sent by the network device to the first client conveys the following information. <ok / > Indicates that the access control protection has been added successfully. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <ok / > < / rpc-reply>

[0122] Since the network device does not support the setting of the access control function for the data set, when the running data set does not meet the protection addition conditions, the additional failure response message sent by the network device to the first client conveys the following information. <rpc-error>The content within the parameter indicates the failure of additional access control protection and the cause of the failure. <error-message>"This datastore cannot be set revision" within the parameters indicates the cause of the failure to add access control protection, that is, the network device does not support setting the access control protection of the dataset. <rpc-reply xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <rpc-error> <error-type>rpc< / error-type> <error-tag>operation-failed< / error-tag> <error-severity>error< / error-severity> <error-message xml:lang=""en”"> This datastore cannot be set revision < / rpc-error> < / rpc-reply>

[0123] Since the running dataset already has version information (that is, access control protection has already been added), if the running dataset does not meet the conditions for adding protection, the additional failure response message sent by the network device to the first client will carry the following information. <rpc-error>The content within the parameter indicates the failure of additional access control protection and the cause of the failure. <error-message>"Datastore revision already exists" within the parameter indicates the cause of the failure to add access control protection, that is, access control protection has already been added for the dataset. <rpc-reply xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <rpc-error> <error-type>rpc< / error-type> <error-tag>operation-failed< / error-tag> <error-severity>error< / error-severity> <error-message xml:lang=""en”"> Datastore revision already exists < / rpc-error> < / rpc-reply>

[0124] In another example, it is assumed that the first client requests to add access control protection for a data node. The protection addition request message sent by the first client to the network device carries the following information. <target>The parameter indicates a data node, which <target>Indicates that additional access control protection is required for the data node indicated by the parameter. The data node is the data node within the path " / t:top / t:interface / t:name". <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking"> <set-ol-capability> <target> / t:top / t:interface / t:name < / target> <support>true< / support> < / set-ol-capability> < / rpc>

[0125] The additional successful response message sent by the network device to the first client can be the same as the additional successful response message in the above example if the data node meets the additional protection conditions.

[0126] Since the network device does not support setting the access control function for the data node, if the data node does not meet the additional protection conditions, the additional failure response message sent by the network device to the first client carries the following information. <error-message>The "name” element cannot be set revision within the parameter indicates the cause of the access control protection addition failure, that is, the network device does not support setting the access control protection of the data node. <rpc-reply xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <rpc-error> <error-type>rpc< / error-type> <error-tag>operation-failed< / error-tag> <error-severity>error< / error-severity> <error-message xml:lang=""en”"> The "name" element cannot be set to revision < / rpc-error> < / rpc-reply>

[0127] Since the data node already has version information (that is, access control protection has already been added), when the data node does not meet the protection addition conditions, the additional failure response message sent by the network device to the first client carries the following information. <rpc-error>The content within the parameter indicates the addition failure of access control protection and the cause of the failure, <error-message>The "name” revision already exists within the parameter indicates the cause of the failure to add access control protection, that is, access control protection has already been added for the data node. <rpc-error> <error-type>rpc< / error-type> <error-tag>operation-failed< / error-tag> <error-severity>error< / error-severity> <error-message xml:lang=""en”"> "name” revision already exists < / rpc-error>

[0128] In this embodiment of the present application, it can be known from the foregoing that the version information is set to record the change status of the data object. For example, the version information of the data object can be updated after the data of the data object is changed. However, in some cases, the data changes of some child data objects have little impact on the parent data object, or for other reasons, the network administrator may not expect the network device to record the change status of the child data objects within the parent data object. In this case, when access control protection is set for the parent data object, these child data objects are deselected. Thereafter, after the network device performs a configuration update on these child data objects, it does not update the version information of the parent data object. Based on this, in this embodiment of the present application, a deselected mechanism is further provided, that is, the access control function set by the network device supports the deselected mechanism. The network device determines whether the configuration update of a specific data object affects the version information of the data object at the upper level (parent data object) based on the deselected mechanism parameters. Correspondingly, the deselected mechanism parameters can be further set when the first client adds access control protection to the data object. Optionally, the protection addition request message further includes the deselected mechanism parameters. The deselected mechanism parameters include the identifiers of one or more fourth data objects, the fourth data object is a child data object of the first data object, and the data granularity of the fourth data object is smaller than the data granularity of the first data object. That is, one or more fourth data objects are deselected from the first data object when access control protection is added for the first data object, so that subsequent configuration updates of one or more fourth data objects do not affect the version information of the first data object.

[0129] For example, by extending NETCONF, access control protection is set for data objects. For example, a set-ol-capability operation is defined to set access control protection for data objects, and to set the inverse selection mechanism parameters <reverse-match>is defined. <set-ol-capability>The parameters inside are <target> 、 <support>, and <reverse-match>It includes. The protection addition request message sent by the first client to the network device carries the following information. <set-ol-capability>The content within the parameter indicates adding access control protection regarding the candidate dataset and setting the identifiers of the data nodes included in the candidate dataset as the inverse selection mechanism parameters. <target>The parameter carries the identifier of the data object for which the first client requests to add access control protection, that is, candidate. <support>When the value of the parameter is "True", it means that <target>Indicates that access control protection is added for a data object indicated by a parameter. <reverse-match>The " / ietf-interface / address / name" within the parameter is an identifier of a data node included in the candidate data set, indicating that " / ietf-interface / address / name" is set to the identifier of a data object included in the inverse selection mechanism parameter. Optionally, in the present embodiment of the present application, the data node is identified using the path of the data node. That is, <reverse-match>The data nodes within the path specified by the parameter are <target>It belongs to the category of the dataset indicated by the parameter, but the change of the configuration data in the data node does not affect the version information of the dataset. Simply put, the first client requests the network device to add an optimistic lock to the candidate dataset. However, the modification of the data node in the " / ietf-interface / address / name" path is not limited by the optimistic lock, and the change of the data node does not affect the version information of the candidate dataset. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <set-ol-capability> <target> <candidate / > < / target> <support> True < / support> <reverse-match> / ietf-interface / address / name < / set-ol-capability> < / rpc>

[0130] It should be further noted that the above example is described using an example in which one data node is deselected from one dataset. In the present embodiment of the present application, one or more data nodes may be deselected from one YANG module or one dataset, or one or more YANG modules may be deselected from one dataset. In addition, <reverse-match>When the data granularity of the data object within the parameter meets the data granularity for setting the access control function supported by the network device, the access control protection is <reverse-match>It can still be separately set for the data object within the parameter.

[0131] The foregoing has described an embodiment of adding access control protection for a data object. The following will describe an embodiment of deleting access control protection for a data object. Here, an example where a first client requests a network device to delete the access control protection of a first data object will continue to be used for illustration. Note that all other clients other than the first client may request the network device to delete the access control protection of one or more data objects. The principle is the same as the principle that the first client requests the network device to delete the access control protection of the first data object, and the details will not be described one by one in this specification.

[0132] In the present embodiment of the present application, the first client sends an access control function setting deletion request message to the network device, and the access control function setting deletion request message includes an identifier of the first data object. The network device receives the access control function setting deletion request message sent by the first client. When the network device determines that the first data object meets the access control function setting deletion condition based on the identifier of the first data object, the network device deletes the version information of the first data object based on the identifier of the first data object. Optionally, the access control function setting deletion request message may also be referred to as an access control protection deletion request message or a protection deletion request message, etc., and the access control function setting deletion condition may also be referred to as an access control protection deletion condition or a protection deletion condition. In the following embodiments, for the sake of illustration, a protection deletion request message and a protection deletion condition are used.

[0133] Optionally, in the present embodiment of the present application, the protection deletion condition includes that the network device supports the setting of the access control function and the network device records the version information of the first data object. That is, if the network device supports the setting of the access control function and access control protection has already been added for the first data object, the network device can normally delete the optimistic lock of the first data object.

[0134] In the present embodiment of the present application, after the network device deletes the version information of the first data object, it sends a deletion success response message to the first client. Optionally, after receiving the deletion success response message, the first client deletes the version information of the first data object recorded by the first client.

[0135] In the present embodiment of the present application, if the first data object does not meet the protection deletion condition, the network device sends a deletion failure response message to the first client. Optionally, the deletion failure response message includes the cause of the access control protection deletion failure. The cause of the access control protection deletion failure may be that the network device does not support the setting of the access control function, or that the network device supports the setting of the access control function but access control protection has not been added for the first data object.

[0136] For example, by extending NETCONF, access control protection is set for the data object. For example, the set-ol-capability operation is defined to set the access control protection of the data object. <set-ol-capability>The parameters inside are <target>and <support>It includes. The protection deletion request message sent by the first client to the network device carries the following information. <set-ol-capability>The content within the parameter indicates the deletion of access control protection for the running dataset, <target>The value of the parameter is the identifier of the data object that requests the first client to remove access control protection, that is, running. <support>When the value of the parameter is "False", it means that <target>Indicates that access control protection is removed for the data object indicated by <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <set-ol-capability> <target> <running / > < / target> <support> False < / support> < / set-ol-capability> < / rpc>

[0137] When the first data object meets the protection removal condition, the deletion success response message sent by the network device to the first client carries the following information. <ok / > Indicates that the access control protection has been successfully removed. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <ok / > < / rpc-reply>

[0138] Since the network device does not support the setting of the access control function, when the first data object does not meet the protection removal condition, the deletion failure response message sent by the network device to the first client carries the following information. <rpc-error>The content within the parameter indicates access control protection deletion failure and the cause of the failure. <error-message>"This datastore cannot be set revision" within the parameters indicates the cause of the access control protection deletion failure, that is, the network device does not support setting the access control protection of the dataset. <rpc-reply xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <rpc-error> <error-type>rpc< / error-type> <error-tag>operation-failed< / error-tag> <error-severity>error< / error-severity> <error-message xml:lang=""en”"> This datastore cannot be set revision < / rpc-error> < / rpc-reply>

[0139] Since the first data object does not have version information (i.e., access control protection is not added), when the first data object does not meet the protection deletion conditions, the deletion failure response message sent by the network device to the first client carries the following information. <rpc-error>The content within the parameter indicates access control protection deletion failure and the cause of the failure. <error-message>"Datastore revision don’t exist" within the parameters indicates the cause of the failure to delete access control protection, that is, the reason is that access control protection has not been added for the dataset. <rpc-reply xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <rpc-error> <error-type>rpc< / error-type> <error-tag>operation-failed< / error-tag> <error-severity>error< / error-severity> <error-message xml:lang=""en”"> Datastore revision don’t exist < / rpc-error> < / rpc-reply>

[0140] The foregoing describes embodiments of adding access control protection and deleting access control protection for data objects. Optionally, in the embodiments of the present application, the network device and the first client can further exchange their respective capability information. For example, the network device notifies the first client of the capabilities of the network device that supports the access control function, so that the first client can accurately send various requests to the network device. Optionally, after a session connection is established between the network device and the first client, the network device and the first client exchange their respective capability information first. Alternatively, the network device and the first client may exchange their respective capability information at any time during the session process. This is not limited in the embodiments of the present application. The following describes an embodiment in which the network device notifies the first client of the capabilities of the network device that supports the access control function.

[0141] In the present embodiment of the present application, the network device sends a capability notification message to the first client. The capability notification message includes support capability parameters for the access control function. The support capability parameters include a first value or a second value. The first value indicates that the network device supports the setting of the access control function, and the second value indicates that the network device does not support the setting of the access control function.

[0142] Optionally, the first value and the second value may be, for example, values or strings, etc. This is not limited in the embodiments of the present application. For example, the first value and the second value may be "1" and "0" respectively, or the first value and the second value may be "dynamic" and "static" respectively.

[0143] In some embodiments, it can be known from the foregoing that the network device may impose a limit on the supported data granularity for setting the access control function. Based on this, optionally, the capability notification message may further include a support granularity parameter of the access control function, and the support granularity parameter indicates that the network device supports the data granularity for setting the access control function, and the data granularity includes one or more of dataset granularity, YANG module granularity, and data node granularity.

[0144] For example, assume that the capability notification message sent by a network device to a first client carries a basic - mode parameter and a granularity parameter, where the basic - mode parameter and the granularity parameter are the support - capability parameter and the support - granularity parameter of the access control function, respectively. The value of the basic - mode parameter is either "dynamic" or "static". "Dynamic" indicates that dynamic addition and deletion of access control protection are supported. "Static" indicates that dynamic addition and deletion of access control protection are not supported, that is, the network device statically supports the access control function. The capabilities of the network device that supports the access control function are determined before distribution, and access control protection cannot be dynamically added or deleted via the client during the execution process of the network device. The value of the granularity parameter includes one or more of "datastore", "module", and "node". "Datastore" indicates that the network device supports optimistic lock maintenance for data - object at the dataset granularity. When the configuration data within a dataset where access control protection has already been added is modified and the modified data is not the data within the reverse - mechanism parameter, the network device needs to update the version information of the dataset. "Module" indicates that the network device supports optimistic lock maintenance for data - object at the YANG - module granularity. "Node" indicates that the network device supports optimistic lock maintenance for data - object at the data - node granularity.

[0145] Based on the foregoing example, the capability notification message sent by a network device to a first client may carry the following information. Here, an example where the network device sends a hello message to the first client is used. The hello message <capabilities>Carry the parameter set, <capabilities>The parameter set is one or more <capability>including parameters, each <capability>The parameter conveys the capability information of one type of network device. The third one conveyed by the hello message <capability>The parameters carry the support capability parameters of the access control function (i.e., the basic-mode parameters) and the support granularity parameters (i.e., the granularity parameters). <capability>The "basic - mode = dynamic" within the parameters indicates that the first value is "dynamic", showing that the network device supports the dynamic configuration of the access control function. "granularity = datastore,module" indicates that the data granularity for setting the access control function supported by the network device includes the dataset granularity and the YANG module granularity. <hello xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <capabilities> <capability> urn:ietf:params:netconf:base:1.1 < / capability> <capability> urn:ietf:params:netconf:capability:startup:1.0 < / capability> <capability> urn:ietf:params:netconf:capability:optimistic-locking:1.0?basic-mode=dynamic&granularity=datastore,module < / capability> < / capabilities> <session-id> 4< / session-id> < / hello>

[0146] The above describes the implementation process in which when the client executes a configuration update on the network device based on NETCONF, the network device uses the client to set access control protection for data objects, and further explains the case where the network device notifies the client of information such as the support ability and support granularity of the access control function. The following describes the application based on the set access control protection between the network device and the client during configuration update, that is, the implementation process of detecting the consistency of version information during the configuration update process.

[0147] In the present embodiment of this application, in order to reduce configuration conflicts and improve parallel processing control efficiency, it can be known from the above that either the network device detects the consistency of version information, or the client detects the consistency of version information, or both the client and the network device detect the consistency of version information. The following first explains the implementation modes involved in the network device detecting the consistency of version information, including the implementation mode where the network device performs the detection alone and the implementation mode where both the client and the network device perform the detection, using the following embodiments of FIG. 3. Next, the implementation mode of independent detection by the client is explained using the following embodiments of FIG. 5.

[0148] FIG. 3 is a flowchart of a configuration update method according to an embodiment of the present application. In the embodiment of FIG. 3, the network device is involved in detecting the consistency of version information. Refer to FIG. 3. The method includes the following steps.

[0149] Step 301: The first client sends a NETCONF configuration request message to the network device. The configuration request message includes operation instruction information, and the operation instruction information indicates that the network device is requested to execute an operation on the first data object by the first client. The operation instruction information includes first version information, and the first version information is the version information of the first data object recorded by the first client. The first data object includes the configuration data of the network device.

[0150] It can be known from the foregoing that the first client and the network device respectively record the version information of the data object that needs to be updated, and perform configuration update by detecting the consistency of the version information. In addition, the first client sends a configuration request message to the network device to perform configuration update on the network device. Before sending the configuration request message, the first client may or may not detect the consistency of the version information. When the first client detects the consistency of the version information, the configuration request message is sent when the first client detects that the first version information is consistent with the first reference version information. When the first client does not detect the consistency of the version information, the first client directly sends the configuration request message to the network device.

[0151] Optionally, in the embodiments of the present application, the version information is a version number, a timestamp, or a sequence number. The version number is a descriptive naming format including characters, numbers, symbols, etc. An example of version1.2.0 is used. This version number includes the character version, numbers, and symbols, and the naming format is the major version number of version.subversion number.minor number. Using a timestamp as the version information of a data object means that a network device uses system time information as the version identifier of the data object. The sequence number is a group of numerical sequences, and the numerical sequences may be randomly generated or generated according to a generation rule. For example, a network device obtains a sequence number based on the operation completion time information of a data object using a hash algorithm and uses the sequence number as the version information of the data object. That is, the network device and the client may record the version information of the data object using a version number, a timestamp, or a sequence number. In some other embodiments, the version information may also be other mark information that can record changes in the configuration data within the data object. Optionally, in the embodiments of the present application, the data object is divided to include a data set, a YANG module, and / or a data node based on the data granularity.

[0152] In this embodiment of the present application, the configuration request message sent by the first client includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to execute an operation on the first data object. In addition, in the embodiment of FIG. 3, the network device needs to be involved in detecting the consistency of the version information. Therefore, the operation instruction information includes first version information. The first version information is the version information of the first data object recorded by the first client, and the first data object includes configuration data in the network device. For example, the first data object is a running data set, and the first version information is the version number version1.0 of the running data set recorded by the first client. In another example, the first data object is a YANG module whose name is ietf-interface-desc, and the first version information is the timestamp 2021-07-22 10:45 UTC of the YANG module "ietf-interface-desc" recorded by the first client. In another example, the first data object is the data node "mtu" in the YANG module "ietf-interface-desc", and the first version information is the sequence number 0001 of the data node "mtu" recorded by the first client.

[0153] Here, as shown below, a YANG model including data nodes in the YANG module "ietf-interface-desc" is provided as an example. The data nodes in the YANG module "ietf-interface-desc" include "interface", "name", "description", "mtu", and "ip-address". module ietf-interface-desc{ … container interfaces{ list interface{ key name; leaf name{ type string; } leaf description{ type string; } leaf mtu{ type uint16; } leaf-list ip-address{ type inet:ip-address; } } }}

[0154] The type or data granularity of the first data object is set or defined as a YANG module, and the NETCONF configuration request message sent by the first client and received by the network device contains operation instruction information. It should be noted that the operation instruction information is assumed to indicate that the first client requests the network device to perform an operation on the "name" node within the YANG module whose name is ietf-interface-desc. In this case, the first data object here is not the data node "name", but the YANG module whose name is ietf-interface-desc. Therefore, the first version information is the version information of the YANG module "ietf-interface-desc". Similarly, when the type of the first data object is set or defined as a data set, and the NETCONF configuration request message sent by the first client and received by the network device contains operation instruction information, and the operation instruction information is assumed to indicate that the first client requests the network device to perform an operation on the "host-name" node within the running data set. In this case, the first data object here is not the data node "host-name", but the running data set. Therefore, the first version information is the version information of the running data set.

[0155] Optionally, the operations requested by the first client to the network device to perform on the first data object include one or more of operations such as edit-config, copy-config, commit, or delete-config.

[0156] The edit operation and the delete operation in NETCONF are operations related to one data object. It should be noted that the network device only needs to detect the consistency of the version information of this data object. The copy operation in NETCONF is an operation related to two data objects. Optionally, in order to ensure that the configuration data in the two data objects is consistent with the configuration data maintained by the first client, the network device needs to separately detect the consistency of the version information of the two data objects. For example, the commit operation in NETCONF is an operation related to two data objects, that is, one data object is the running data set and the other data object is the candidate data set. The running data set is the first data object. The network device needs to detect the consistency of the version information of the running data set. On the other hand, regarding the candidate data set, the network device may or may not detect the consistency of the version information of the candidate data set. Optionally, if the network device does not detect the version information of the candidate data set, the corresponding version information may not be set for the candidate. The following uses an example where the operation includes a copy operation to explain the case where the consistency of the version information of two data objects needs to be separately detected in the present embodiment of the present application.

[0157] In the present embodiment of the present application, when the operation required by the first client to be performed on the first data object includes a copy operation, the operation instruction information further includes fifth version information, and the fifth version information is the version information of the fifth data object recorded by the first client, and the fifth data object includes the configuration data of the network device. The copy operation is used to overwrite the configuration data in the first data object with the configuration data in the fifth data object. The first data object and the fifth data object are different data objects.

[0158] Optionally, in the present embodiment of the present application, these operations defined by NETCONF are extended to carry version information in order to perform configuration updates on the network device. The following uses an example where the operations include an edit operation, a commit operation, and a copy operation to explain this.

[0159] For example, an example where the operation includes an edit operation and the version information is a version number (revision) is used to extend the edit-config operation defined by NETCONF to carry the first version information. For example, a version information attribute is added after the identifier of the first data object for which a configuration update needs to be performed. For example, in the following example, the operation instruction information is <edit-config>It includes the content within the parameter. <target>Within the parameters <running ol:revision=""1” / ">indicates that the first data object is the running data set and the version number of the running data set recorded by the first client is 1. In addition, <edit-config>The parameter indicates an editing operation in which a first client requests execution from a network device. <target>The parameter may further be known to be used to carry an identifier of a first data object. In the edit-config operation defined by NETCONF, it should be noted that the edit-config operation may use the operation parameter to indicate that a particular operation is a merge, delete, or replace, etc. For example, in the following example, <interface xc:operation=""merge”">Indicates that a merge operation is performed on the configuration data of the corresponding interface. Note further that the operation parameter is an optional parameter. <edit-config>If the parameter does not carry the operation parameter, it indicates that the edit-config operation represents the default operation, and the default operation is the merge operation. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking”"> <edit-config> <target> <running ol:revision=""1” / "> < / running> < / target> <config> <top xmlns=""http: / / example.com / schema / 1.2 / config”"> <interface xc:operation=""merge”"> <name>Ethernet0 / 0< / name> <mtu> 1500< / mtu> < / interface> < / top> < / config> < / edit-config> < / rpc>

[0160] An example where the operation includes a commit operation and the version information is a version number (revision) is used. The commit operation defined by NETCONF is extended to carry the first version information. For example, in the following example, the operation instruction information is <commit ol:revision=""2” / ">including <commit ol:revision=""2” / ">represents a commit operation in which a first client requests execution from a network device, indicates that a first data object is a running data set, indicates that a second data object is a candidate data set, and further conveys version information 2 of the running data set recorded by the first client. The commit operation is used to overwrite the configuration data in the running data set with the configuration data in the candidate data set in order to commit the configuration data in the candidate data set with respect to formal validity. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking”"> <commit ol:revision=""2” / "> < / commit> < / rpc>

[0161] An example where the operation includes a copy operation and the version information is a version number (revision) is used. The copy-config operation defined by NETCONF is extended to convey the first version information and the fifth version information. For example, corresponding version information attributes are respectively added after the identifiers of the first data object (destination data object) and the second data object (source data object). For example, in the following example, the operation instruction information is <copy-config>It includes the content within the parameters. <target>Within the parameters <startup ol:revision=""1” / ">indicates that the first data object is the startup data set, and the version number of the startup data set recorded by the first client is 1. <source> within the parameter <running ol:revision=""2” / ">indicates that the second data object is the running data set and the version number of the running data set recorded by the first client is 2. In addition, <copy-config>The parameter indicates a copy operation in which a first client requests execution from a network device, <target>The parameter is used to carry the identifier of the first data object, <source> It may further be known that the parameter is used to carry the identifier of the second data object. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking”"> <copy-config> <target> <startup ol:revision=""1” / "> < / startup> < / target> <source> <running ol:revision=""2” / "> < / running> < / copy-config> < / rpc>

[0162] It can be known from the foregoing that the first client may alternatively first detect the consistency of the version information before sending a configuration request message to the network device. When detecting the consistency of the version information, the first client needs to first obtain the version information of the first data object recorded by the network device. The following describes two embodiments in which the first client obtains the version information of the first data object recorded by the network device. If it is necessary to further detect the consistency of the version information of the fifth data object, it should be noted that the first client may separately obtain the version information of the first data object and the version information of the fifth data object recorded by the network device. The following uses an example in which the first client obtains the version information of the first data object recorded by the network device to explain this. The same applies to the embodiment in which the first client obtains the version information of the fifth data object recorded by the network device.

[0163] In an embodiment where a first client obtains version information of a first data object recorded by a network device, the first client sends an inquiry message to the network device, and the inquiry message includes an identifier of the first data object. The network device receives the inquiry message sent by the first client, and the network device sends an inquiry response message to the first client, and the inquiry response message includes the version information of the first data object recorded by the network device. That is, the first client obtains the version information of the first data object recorded by the network device in an immediate inquiry manner.

[0164] Note that when the network device records the version information of the first data object, the network device feeds back a success response message to the first client, the success response message is the inquiry response message, and the inquiry response message includes the version information of the first data object recorded by the network device. Optionally, the inquiry response message includes a version field, and the version field includes the version information of the first data object recorded by the network device.

[0165] If the network device does not record the version information of the first data object, the network device feeds back a failure response message to the first client, and the failure response message indicates that the network device does not record the version information of the first data object. Optionally, the failure response message also includes a version field, but the version field is null. The network device feeds back a failure response message to the first client if the first data object does not support the setting of the access control function, or if the first data object supports the setting of the access control function but the access control function is not set. Optionally, in various cases, the failure response messages fed back by the network device are the same or different. For example, if the first data object does not support the setting of the access control function, the failure response message fed back by the network device indicates that the first data object does not support the setting of the access control function. If the first data object supports the setting of the access control function but the access control function is not set, the failure response message fed back by the network device indicates that the first data object supports the setting of the access control function but the access control function is not set.

[0166] For example, NETCONF is extended. For example, the get-revision operation is defined to be used by the client to query version information, and the parameters within the get-revision operation are <source> parameters and <filter>It includes parameters. <source> The parameters are used to carry an identifier of a data set, <filter>The parameter is <source> used to carry the name of the YANG module, the path of the data node, or the name of the data node within the data set indicated by the parameter. <filter>The parameter is an optional parameter. For example, when the first data object is a data set, in the version query request message <get-revision>The parameter is <source> used to indicate the identifier of the first data object by <source> including only the parameter. If the first data object is a YANG module or a data node, in the version query request message <get-revision>The parameter is, <source> the parameter and <filter>To jointly indicate the identifier of the first data object using the parameter, <source> the parameter and <filter>It includes parameters. For example, in the following example, the query message sent by the first client to the network device carries the following information. <get-revision>The content within the parameter indicates that the first client requests to inquire about the version information of the first data object. <get-revision>The parameter is <source> including the parameter and indicating that the first data object is a data set. <source> Within the parameter <running / > indicates that the first data object is a running data set. Optionally, <get-revision>The query message sent by the first client to the network device using can be called a version query message. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <get-revision> <source> <running / > < / get-revision> < / rpc>

[0167] In another example, in the following example, the query message sent by the first client to the network device carries the following information. The content within the <get-revision parameter indicates that the first client requests to query the version information of the first data object. <get-revision>The parameter is, <source> the parameter and <filter>It includes parameters and indicates that the first data object is a YANG module or data node within a data set. <source> Within the parameters <running / > indicates that the data set to which the first data object belongs is the running data set. <filter>Within the parameters <top>The parameter indicates that the first data object is the / top / users data node within the running data set. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <get-revision> <source> <running / > <filter type=""subtree”"> <top xmlns=""http: / / example.com / schema / 1.2 / config”"> <users / > < / top> < / filter> < / get-revision> < / rpc>

[0168] When the network device records the version information of the first data object, the inquiry response message fed back by the network device conveys the following information. <revision> 2 <revision>is the version field, and the version field indicates that the version information of the first data object recorded by the network device is 2. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <revision> 2 <revision> < / revision> < / revision> < / rpc-reply>

[0169] When the network device does not record the version information of the first data object, the failure response message fed back by the network device carries the following information. <revision> <revision>is null, indicating that the network device has not recorded the version information of the first data object. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <revision> <revision> < / revision> < / revision> < / rpc-reply>

[0170] The foregoing uses the extended get-revision operation as an example to illustrate how the first client obtains the version information of the first data object recorded by the network device by sending an inquiry message. Optionally, the first client may alternatively be defined in NETCOF <get-config>Using this, version information of the first data object recorded by the network device may be obtained. <get-config>is used by a client or a controller to query a network device for configuration data on the network device. In the present embodiment of the present application, the query message transmitted to the network device by the first client is <get-config>including parameters, <get-config>The parameter conveys an identifier of a first data object. The query response message fed back to a first client by a network device is, <data>including parameters, <data>The parameter conveys specific data of the first data object and further conveys version information of the first data object recorded by the network device. Optionally, the first client, or, defined by NETCOF <get-data>Or <get>Using, the version information of the first data object recorded by the network device may be obtained, and the principle is <get-config>This is similar to the principle. That is, in the present embodiment of the present application, or the standard requirement message defined by NETCOF may be extended. When the first client sends an inquiry message to the network device to request to inquire about specific data in the first data object, the network device feeds back the specific data in the first data object to the first client, and further feeds back the version information of the first data object recorded by the network device. Optionally, <get-config>The inquiry message sent to the network device by the first client using, or which may be called a configuration inquiry message.

[0171] In the present embodiment of the present application, when expecting to perform a configuration update on the first data object, the first client may obtain the version information of the first data object recorded by the network device in an immediate inquiry manner, or note that the first client may obtain the version information of the first data object recorded by the network device in an immediate inquiry manner at any time. In addition to inquiring about the version information of the first data object, the first client may further inquire about the version information of another data object.

[0172] Optionally, the first client requests to inquire about the version information of one or more data objects by sending an inquiry message. In some of the foregoing examples, one inquiry message is used to request to inquire about the version information of one data object. The following describes an embodiment in which the first client requests to inquire about the version information of a plurality of data objects by sending an inquiry message.

[0173] As described above <get-config>is used as an example. For example, the inquiry message sent by the first client carries the following information. <get-revision>The parameters are <source> parameters and <filter>Carry the parameter. <source> The parameter indicates that the data set where the data object to be queried is located is the running data set. <filter>The parameter indicates that the data object for which version information is requested includes multiple data nodes corresponding to the interface name eth0, which are included in the interface YANG module within the running data set. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <get-config> <source> <running / > <filter type=""subtree”"> <top xmlns=""http: / / example.com / schema / 1.2 / config”"> <t:interfaces> <t:interface t:ifname=""eth0” / "> < / t:interface> < / t:interfaces> < / top> < / filter> < / get-config> < / rpc>

[0174] When the network device corresponds to ifName eth0 and records the version information of multiple data nodes included in the interface YANG module, the query response message fed back by the network device conveys the following information. The query response message <data>Carry parameters, <data>The parameter corresponds to the ifName interface name eth0 and carries the version information of each of the four data nodes included in the interface YANG module. <ifname ol:revision=""1”">eth0< / ifname> indicates that the version information of the data node with the interface name eth0 is 1. <mtu ol:revision=""3”"> 1450< / mtu> indicates that the version information of the data node with its mtu (maximum transmission unit) being 1450 is 3. <ip-address ol:revision=""2”"> 172.168.0.1< / ip-address> indicates that the version information of the data node with its ipv4 - address being 172.168.0.1 is 2. <ip-address ol:revision=""1”"> ::1< / ip-address> indicates that the version information of the data node with its ipv6 - address being ::1 is 1. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking”"> <data> <top xmlns=""http: / / example.com / schema / 1.2 / stats”"> <interfaces> <interface> <ifname ol:revision=""1”">eth0< / ifname> <mtu ol:revision=""3”"> 1450< / mtu> <ip-address ol:revision=""2”"> 172.168.0.1< / ip-address> <ip-address ol:revision=""1”"> ::1< / ip-address> < / interface> < / interfaces> < / top> < / data> < / rpc-reply>

[0175] When some of the four data nodes have version information, the inquiry response message fed back by the network device to the first client carries the version information of the data node. For example, the inquiry response message fed back by the network device carries the following information. The data node with the interface name eth0 has version information 1, the data node with its maximum transmission unit mtu being 1450 has version information 3, and the data nodes with their ipv4 - address being 172.168.0.1 and ipv6 - address being ::1 do not have version information. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking”"> <data> <top xmlns=""http: / / example.com / schema / 1.2 / stats”"> <interfaces> <interface> <ifname ol:revision=""1”">eth0< / ifname> <mtu ol:revision=""3”"> 1450< / mtu> <ip-address> 172.168.0.1< / ip-address> <ip-address> ::1< / ip-address> < / interface> < / interfaces> < / top> < / data> < / rpc-reply>

[0176] In some of the above examples, the first client requests to inquire about the version information by specifying the name of the data node. In the present embodiment of this application, the first client may alternatively request to inquire about the version information by specifying the path of the data node. For example, the xpath expression indicates the path of the data node.

[0177] For example, the inquiry message transmitted by the first client carries the following information. <filter>The parameter conveys an xpath expression, which indicates that the first client requests version information of a plurality of data nodes corresponding to the user whose name is fred in the running data set. <rpc message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <get-revision> <source> <running / > <!--get the user named fred--> <filter xmlns:t=""http: / / example.com / schema / 1.2 / config”" type=""xpath”" select="" / t:top / t:users / t:user[t:name=’fred’]” / "> < / filter> < / rpc>

[0178] Optionally, when the version information of a plurality of data nodes belonging to one data set or one YANG module is consistent, the query response message fed back to the first client by the network device may have version information appended after the identifier of the parent node of the plurality of data nodes to indicate that all the plurality of data nodes inherit the version information of the parent node. In some cases, the plurality of data nodes have version information and the version information is the same. In other cases, the plurality of data nodes do not have version information, and the version information of the plurality of data nodes is essentially the version information of the parent node of the plurality of data nodes.

[0179] For example, the query message sent by the first client to the network device conveys the following information. <user ol:revision=""1”">It indicates that the version information of the data node whose name is fred and the company - info data node with id = 2 is inherited from the version information 1 of the parent node user. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”" xmlns:ol=""urn:changjia:params:xml:ns:yang:optimistic-locking”"> <data> <top xmlns=""http: / / example.com / schema / 1.2 / config”"> <users> <user ol:revision=""1”"> <name>fred< / name> <company-info> <id> 2< / id> < / company-info> < / user> < / users> < / top> < / data> < / rpc-reply>

[0180] The foregoing has described an embodiment in which the first client obtains the version information of the first data object by sending an inquiry message to the network device. In this embodiment of the present application, another embodiment in which the first client obtains the version information of the first data object recorded by the network device is that the network device sends a data change notification message to the first client, and the data change notification message includes the version information of the first data object recorded by the network device, and the data change notification message is sent by the network device when the first client subscribes to the data change notification in the first data object. That is, the first client obtains the version information of the first data object recorded by the network device in a subscription manner, that is, obtains the latest version information recorded by the network device. For example, when the network device modifies the data in the first data object based on the request of another client, that is, when the data in the first data object is changed, the network device sends a data change notification message to the first client, and the data change notification message includes the latest version information of the first data object recorded by the network device.

[0181] Optionally, the first client sends a subscription request to the network device to subscribe to change notifications for the configuration data in the first data object, and the first client is set by default to subscribe to change notifications for the configuration data in the first data object from the network device, or the network device pushes data change notification messages to the first client by default.

[0182] The version information can be considered as a mark recording that the configuration data in the first data object has been changed. Note that when the configuration data included in the first data object is changed (i.e., a configuration update is executed), the version information of the first data object can be changed. In this case, the network device sends a data change notification message to the first client, and the data change notification message carries the version information of the first data object recorded by the network device. Optionally, the data change notification message further includes specific change information of the configuration data in the first data object.

[0183] In the present embodiment of the present application, the above two embodiments in which the first client obtains the version information of the first data object recorded by the network device may be used separately or in combination. This is not limited in the present embodiment of the present application. For example, in the case of combined use, the first client can obtain the version information by sending a version query request message to the network device at any time, or the first client can obtain the version information by receiving a configuration change push message sent by the network device.

[0184] Step 302: The network device receives a configuration request message.

[0185] In the present embodiment of the present application, after the first client sends a configuration request message to the network device, the network device receives the configuration request message.

[0186] Step 303: When the network device detects that the first version information matches the first reference version information, the network device executes an operation on the first data object, and the first reference version information is the version information of the first data object recorded by the network device.

[0187] In the present embodiment of the present application, after receiving the configuration request message, the network device detects whether the first version information matches the first reference version information, that is, detects whether the version information recorded by the first client matches the version information recorded by the network device. When the network device detects that the first version information matches the first reference version information, the network device executes an operation on the first data object. The first reference version information is the version information of the first data object recorded by the network device.

[0188] When the operation includes a copy operation, the operation instruction information carried in the configuration request message further includes fifth version information, and the fifth version information is the version information of a fifth data object recorded by a first client. The fifth data object includes the configuration data of the network device, and it can be known from the foregoing that the fifth data object and the first data object are different data objects. In this case, the network device needs to further detect whether the fifth version information matches the fifth reference version information. When the network device detects that the first version information matches the first reference version information and the fifth version information matches the fifth reference version information, the network device executes an operation on the first data object. The fifth reference version information is the version information of the fifth data object recorded by the network device.

[0189] It can be known from the foregoing that the operation instruction information carried in the composition requirement message includes the identifier of the first data object. For example, the operation instruction information of operations such as editing, deleting, and copying includes the identifier of the first data object (also called the target data object), or the operation instruction information carried in the composition requirement message indicates the identifier of the first data object. For example, the operation instruction information of the commit operation indicates the identifier of the first data object (i.e., the running data set). Optionally, after receiving the composition requirement message, the network device queries the version information of the first data object based on the identifier of the first data object on the basis of the optimistic lock information. The version information found through the query is the version information of the first data object recorded by the network device. Optionally, when the operation includes a copy operation, the operation instruction information further includes the identifier of the fifth data object. The network device queries the version information of the fifth data object based on the identifier of the fifth data object on the basis of the optimistic lock information. The version information found through the query is the version information of the fifth data object recorded by the network device. The optimistic lock information base is used to record the version information and store the data object by the network device. The optimistic lock information base is stored by the network device or stored by another device. This is not limited in the present embodiment of the present application. Optionally, the optimistic lock information base is an information base constructed based on the YANG model.

[0190] For the embodiment in which the network device performs an operation on the first data object in this application, please refer to the relevant description of NETCONF. Details will not be described again here. After the network device has completed performing an operation on the first data object, the network device records the first reference version information. It should be noted that the network device needs to determine whether to update the version information of the first data object, that is, whether to update the first reference version information, based on the situation.

[0191] In the present embodiment of this application, the data granularity for setting the access control function supported by the network device includes one or more of dataset granularity, YANG module granularity, and data node granularity, and the reverse selection mechanism parameter can be further set when access control protection is set for the data object. That is, in the present embodiment of this application, there may be a parent-child relationship between data objects, and there may further exist a case where a child data object is reverse-selected or not reverse-selected from a parent data object between data objects having a parent-child relationship. It should be noted that it can be known from the foregoing that based on this, after performing an operation on the first data object in the present embodiment of this application, the network device determines whether to update the version information and how to update the version information based on the supported data granularity for setting the access control function, the parent-child relationship between data objects, and the reverse selection mechanism parameter.

[0192] In some cases, when the data granularity of the first data object corresponding to the first reference version information meets the data granularity for which the network device sets the access control function, the network device updates and records the first reference version information. That is, the network device maintains the version information of the first data object itself, and after performing a configuration update operation on the first data object, the network device needs to update and record the first reference version information.

[0193] Optionally, when the operation instruction information further includes the identifier of the second data object, the first data object is a child data object of the second data object, and the second reference version information is the version information of the second data object recorded by the network device, the implementation manner in which the network device records the first reference version information is that when the data granularity of the first data object corresponding to the first reference version information meets the data granularity for which the network device sets the access control function, and the data granularity of the second data object corresponding to the second reference version information meets the data granularity for which the network device sets the access control function, the network device updates and records the first reference version information and the second reference version information. Note that in this case, the access control function set by the network device may not support the reverse selection mechanism. In this way, when the data of the first data object is changed, the network device needs to update the version information of the first data object, and the network device also needs to update the version information of the second data object (i.e., the parent data object of the first data object) when the data of the second data object is changed due to the data change of the first data object.

[0194] Optionally, the operation instruction information further includes an identifier of a third data object, the first data object is a child data object of the third data object, the third reference version information is version information of the third data object recorded by the network device, and when the access control function set by the network device supports a reverse selection mechanism, in an embodiment where the network device records the first reference version information, the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity at which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity at which the network device sets the access control function, and when the reverse selection mechanism parameter of the access control function set by the network device does not include the identifier of the first data object, the network device updates and records the first reference version information and the third reference version information. When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity at which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity at which the network device sets the access control function, and when the reverse selection mechanism parameter of the access control function set by the network device includes the identifier of the first data object, the network device updates and records the first reference version information.

[0195] That is, when the access control function set by the network device supports the adverse selection mechanism, a third data object is the parent data object of the first data object, and both the data granularity of the first data object and the data granularity of the third data object satisfy the data granularity at which the network device sets the access control function. That is, when the data granularity at which the network device sets the access control function includes at least two data granularities, the network device not only updates the version information of the first data object, but also, depending on whether the adverse selection mechanism parameter includes the identifier of the first data object, further determines whether to update the version information of the third data object after completing the operation on the first data object. When the adverse selection mechanism parameter does not include the identifier of the first data object, the network device updates the version information of the third data object after completing the operation on the first data object. When the adverse selection mechanism parameter includes the identifier of the first data object, the network device retains the version information of the third data object without change after completing the operation on the first data object.

[0196] Optionally, in this case, the operation instruction information further includes an identifier of a third data object, the third data object is a parent data object of the first data object, and both the data granularity of the third data object and the data granularity of the first data object satisfy the data granularity at which the network device sets the access control function. That is, the third data object includes the first data object, and the data granularity of the first data object is smaller than the data granularity of the third data object. In this case, the network device records the version information of the third data object and the version information of the first data object. That is, the third data object is a higher-level data object or a parent data object of the first data object, and both the third data object and the first data object have version information. Therefore, in addition to updating the version information of the first data object, the network device needs to further determine whether to update the version information of the third data object after completing the execution of the operation on the first data object according to whether the reverse selection mechanism parameter includes the identifier of the first data object. When the reverse selection mechanism parameter does not include the identifier of the first data object, if the operation performed on the first data object by the network device causes a change to the first data object and further causes a change to the parent data object of the first data object (i.e., the third data object), since the first data object is not set to be reverse-selected from the third data object, the network device needs to update the version information of the third data object in this case.When the reverse selection mechanism parameter includes the identifier of the first data object, and the operation performed by the network device on the first data object causes a change to the first data object, the first data object is set to be reverse selected from the third data object. To indicate that the network device does not need to record the change to the third data object caused by the first data object, when the data objects other than the first data object in the third data object are not changed even if the first data object is changed, the network device retains the version information of the third data object without changing it in this case. That is, in the present embodiment of this application, when the third data object is the parent data object of the first data object and the reverse selection mechanism parameter corresponding to the third data object includes the identifier of the first data object, the network device does not update the version information of the third data object even if a configuration update is performed on the first data object. Briefly speaking, the first data object is reverse selected from the third data object, and the configuration update for the first data object does not affect the version information of the third data object.

[0197] For example, when a NETCONF configuration request message sent by a first client and received by a network device contains operation instruction information, the operation instruction information requests the network device for the first client to perform an operation on the "name" node in the YANG module whose name is ietf-interface-desc. The YANG module of ietf-interface-desc is the third data object, the type or data granularity of the third data object is a YANG module, the "name" node is the first data object, and the type or data granularity of the first data object is a data node. The data granularity for setting the access control function supported by the network device includes a YANG module and a data node. It is assumed that the network device records the version information of the YANG module of ietf-interface-desc and the version information of the "name" node. In this case, after performing an operation on the "name" node, the network device updates the version information of the "name" node. In addition, when the reverse selection mechanism parameter contains the identifier of the "name" node, the network device retains the version information of the YANG module of ietf-interface-desc without changing it. When the reverse selection mechanism parameter does not contain the identifier of the "name" node, the network device updates the version information of the YANG module of ietf-interface-desc.

[0198] In this case, that is, when there is a parent-child relationship between the third data object and the first data object, and both the data granularity of the first data object and the data granularity of the third data object satisfy the data granularity at which the network device sets the access control function, if the network device in the present embodiment of the present application does not support setting the reverse selection mechanism parameter, after performing an operation on the first data object to execute the configuration update, it should be noted that the network device separately updates the version information of the first data object and the version information of the third data object.

[0199] For example, assume that the first data object is a data node, the third data object is a data set, the data set contains the data node, both the data granularity of the data node and the data granularity of the data set satisfy the data granularity at which the network device sets the access control function, and the network device separately records the version information of the data node and the version information of the data set. In this case, if the reverse selection mechanism parameter corresponding to the data set contains the identifier of the data node, after the network device performs an operation on the data node to execute the configuration update, the network device updates the version information of the data node and retains the version information of the data set without change. If the reverse selection mechanism parameter corresponding to the data set does not contain the identifier of the data node, or if the network device does not support setting the reverse selection mechanism parameter, after the network device performs an operation on the data node to execute the configuration update, the network device separately updates the version information of the data node and the version information of the data set.

[0200] In another case, the data granularity of the first data object does not meet the data granularity for which the network device sets the access control function, the third data object is the parent data object of the first data object, and the data granularity of the third data object meets the data granularity for which the network device sets the access control function, that is, the parent data object of the first data object has version information. In this case, after the network device finishes executing the operation on the first data object, it needs to determine whether to update the version information of the third data object according to whether the identifier of the first data object is set in the reverse selection mechanism parameter. If the reverse selection mechanism parameter includes the identifier of the first data object, the network device retains the version information of the third data object without change. If the reverse selection mechanism parameter does not include the identifier of the first data object, the network device updates the version information of the third data object.

[0201] For example, a network device supports setting an access control function for a data object with one data granularity. The network device does not support setting an access control function for a data node, but supports setting an access control function for a data set. Assume that the first data object is a data node, the third data object is a data set, and the third data object is the parent data object of the first data object. In this case, the network device records the version information of the third data object, and the first data object itself does not have version information. That is, the first data object is a data node, the third data object is a data set, the data set is the parent data object of the data node, the data granularity of the data node does not meet the data granularity for which the network device sets the access control function, and the data granularity of the data set is assumed to meet the data granularity for which the network device sets the access control function. In addition, the network device records the version information of the data set, but the data node itself does not have version information. When the reverse selection mechanism parameter corresponding to the data set includes the identifier of the data node, after the network device performs an operation on the data node to execute a configuration update, the network device retains the version information of the data set without changing it. When the reverse selection mechanism parameter corresponding to the data set does not include the identifier of the data node, after the network device performs an operation on the data node to execute a configuration update, the network device updates the version information of the data set.

[0202] For example, when a NETCONF configuration request message sent by a first client and received by a network device contains operation instruction information, the operation instruction information indicates that the first client requests the network device to perform an operation on the "name" node in a YANG module whose name is ietf-interface-desc. Assume that the data granularity for setting the access control function supported by the network device includes a YANG module, and the network device records the version information of the YANG module of ietf-interface-desc. In this case, after the network device executes an operation on the "name" node, if the reverse selection mechanism parameter includes the identifier of the "name" node, the network device retains the version information of the YANG module of ietf-interface-desc without modification. If the reverse selection mechanism parameter does not include the identifier of the "name" node, the network device updates the version information of the YANG module of ietf-interface-desc.

[0203] Optionally, when the network device stores the version information of a data object using an optimistic lock information base, the network device updates the version information of the first data object by updating the optimistic lock information base, or updates the version information of the first data object and the version information of the third data object. Optionally, the reverse selection mechanism parameter is stored in the optimistic lock information base, and the network device queries the optimistic lock information base for the reverse selection mechanism parameter to determine whether the reverse selection mechanism parameter includes the identifier of the first data object.

[0204] For example, when the version information is a version number and the version number is in a numeric format, an embodiment in which the network device updates the first reference version information is to obtain the updated first reference version information by adding 1 to the first reference version information. When the version number is a version number, the version number is in the naming format of major version number.minor version number.patch version number, and an embodiment in which the network device updates the first reference version information is to obtain the updated first reference version information by adding 1 to the major version number, minor version number, or patch version number of the first reference version information. When the version information is a timestamp, an embodiment in which the network device updates the first reference version information is that the network device updates the first reference version information with the system time when the operation on the first data object is completed, the network device updates the first reference version information with the system time when the operation to be performed on the first data object is started, or the network device updates the first reference version information with the system time when the configuration request message is received. That is, the first reference version information is the system time when the network device has completed performing the operation on the first data object recorded by the network device, or the first reference version information is the system time when the network device has started performing the operation on the first data object recorded by the network device, or the first reference version information is the time when the network device has received the configuration request message recorded by the network device. When the version information is in another format, the method by which the network device updates the first reference version information can be adaptively changed.

[0205] Optionally, if the operation by which the first client requests execution on the network device is a commit operation, after the network device commits the configuration data in the candidate dataset to the running dataset, since the configuration data in the running dataset is modified, the network device needs to update the version information of the running dataset. It is assumed that the network device updates the version information in a cumulative manner. After the network device executes the commit operation, in one embodiment, the network device adds 1 to the version information of the running dataset to obtain the updated version information, and in another embodiment, the network device resets the version information of the running dataset to the initial version information value.

[0206] In the present embodiment of this application, after executing an operation on the first data object, the network device can further send a configuration success response message to the first client to notify the first client that the operation has been successfully executed. Correspondingly, after the first client sends a configuration request message to the network device, the first client further receives the configuration success response message sent by the network device.

[0207] Optionally, after the first client receives the configuration success response message sent by the network device, the first client records the first version information, that is, updates and records the version information of the first data object recorded by the first client. It should be noted that the first client may immediately update the first version information automatically, or may update the first version information later by querying the network device for the version information of the first data object recorded by the network device. That is, in the present embodiment of this application, the embodiments in which the first client updates the first version information are not limited.

[0208] For example, in one embodiment, after a first client sends a configuration request message to a network device during a certain period, the first client sends an inquiry message to the network device to inquire about the latest version information of a first data object. The network device receives the inquiry message sent by the first client, and the inquiry message includes an identifier of the first data object. The network device sends an inquiry response message to the first client, and the inquiry response message includes the version information of the first data object recorded by the network device, that is, the network device notifies the first client of the updated version information of the first data object. In this way, after the first client obtains the updated version information of the first data object, if it finds that the version information of the first data object has been changed, the first client determines that the network device has successfully executed an operation on the first data object. Briefly speaking, in the present embodiment of the present application, the first client can obtain version information by inquiry to confirm whether the network device has successfully executed an operation on the first data object or has completed an operation on the first data object.

[0209] In another embodiment, the configuration success response message sent by the network device to the first client includes updated first reference version information. In this case, the first client updates and records the first version information as the updated first reference version information.

[0210] For example, the configuration success response message sent by the network device to the first client conveys the following information. <ok / > indicates that the network device has successfully executed an operation on the first data object, that is, the network device has successfully executed a configuration update. Optionally, <ok / > is used to indicate that the updated first reference version information is 4, <ok ol:revision=""4” / ">It may be replaced with. <rpc-reply message-id=""101”" xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <ok ol:revision=""4” / "> < / ok> < / rpc-reply>

[0211] In the present embodiment of the present application, when the network device detects that the first version information does not match the first reference version information, the network device sends a configuration failure response message to the first client. When the operation is a copy operation and the network device detects that the first version information does not match the first reference version information, or when the network device detects that the fifth version information does not match the fifth reference version information, the network device sends a configuration failure response message to the first client. That is, when the version information maintained by the first client does not match the version information maintained by the network device, the network device does not execute the operation on the first data object and feedbacks a configuration failure response message to the first client.

[0212] Optionally, the configuration failure response message sent by the network device to the first client includes the first reference version information, that is, the network device may notify the first client of the version information of the first data object recorded by the network device.

[0213] For example, the configuration failure response message sent by the network device to the first client carries the following information. <rpc-error>The content within the parameter indicates a configuration failure, <error-info>The parameter conveys the cause of the configuration failure, <message>The parameter carries the first reference version information 2 recorded by the network device. <rpc-reply xmlns=""urn:ietf:params:xml:ns:netconf:base:1.0”"> <rpc-error> <error-type>rpc< / error-type> <error-tag>bad-attribute< / error-tag> <error-severity>error< / error-severity> <error-info> <bad-attribute>target-revision< / bad-attribute> <message>the current target-revision is 2< / message> < / error-info> < / rpc-error> < / rpc-reply>

[0214] The foregoing provides an explanation of the process in which, when the first client executes a configuration update on the network device, the network device determines whether to execute the configuration update by detecting the consistency of the version information. Next, the configuration update method described in the embodiment of FIG. 3 will be described again using an example with reference to FIG. 4.

[0215] In FIG. 4, it is assumed that the network device detects the consistency of the version information. The version information is a version number updated by accumulation. Both client A and client B can execute a configuration update on the network device.

[0216] At time t1, client A sends a configuration request message to the network device. The configuration request message indicates that an edit operation is to be performed on the first data object and carries the first version information 1 recorded by client A, i.e., V = 1. After receiving the configuration request message, the network device finds by query that the first reference version information recorded by the network device is 1, i.e., V = 1, and determines by comparison that the first version information is consistent with the first reference version information. In this case, the network device accepts the request of client A, normally executes the edit operation to perform the configuration update, and after normally executing the configuration update, the network device updates the recorded first reference version information to 2, i.e., V = 2. At time t2, the network device sends a configuration success response message to client A. The configuration success response message indicates a successful configuration and carries the updated first reference version information, i.e., V = 2. Client A updates the first version information recorded by client A to 2.

[0217] At time t3, client B sends a configuration request message to the network device. The configuration request message indicates to perform an edit operation on the data object and carries the first version information 2, i.e., V = 2, recorded by client B. After receiving the configuration request message, the network device finds by query that the first reference version information recorded by the network device is 2, i.e., V = 2, and determines by comparison that the first version information is consistent with the first reference version information. In this case, the network device accepts the request of client B, normally executes the edit operation to perform a configuration update, and after successfully performing the configuration update, the network device updates the recorded first reference version information to 3, i.e., V = 3. At time t4, the network device sends a configuration success response message to client B. The configuration success response message indicates a successful configuration and carries the updated first reference version information, i.e., V = 3.

[0218] After time t2, expecting to update the configuration data in the first data object again, client A edits the configuration data at the local end. At time t5, client A further sends a configuration request message to the network device. The configuration request message indicates to perform an edit operation on the data object and carries the first version information 2, i.e., V = 2, recorded by client A. After receiving the configuration request message, the network device finds by query that the first reference version information recorded by the network device is 3, i.e., V = 3, and determines by comparison that the first version information is not consistent with the first reference version information. In this case, the network device rejects the request of client A. At time t6, the network device sends a configuration failure response message to client A. The configuration failure response message indicates a configuration failure and carries the currently recorded first reference version information, i.e., V = 3.

[0219] The foregoing has described how a client executes a configuration update on a network device based on NETCONF. The network device is involved in detecting the consistency of version information. This can greatly avoid conflicts in configuration updates. In addition, it can be known that the present embodiment of this application provides a complete access control mechanism for reducing configuration conflicts. The access control mechanism provided in the present embodiment of this application includes optimistic lock capability notification, addition and deletion of lock protection, maintenance and query of optimistic lock information (i.e., version information), and application of optimistic lock during configuration update (i.e., detection of consistency of version information). In specific implementation, this solution is to extend NETCONF, for example, define new RPC operations such as get-revision operation and set-ol-capability operation, and modify the original RPC operations, for example, to notify the optimistic lock support capability <capability>It can be implemented by adding parameters to the hello message. Note that some of the specific embodiments described above are not intended to limit this application, and this solution may alternatively be implemented between the client and the network device in some other possible embodiments.

[0220] In conclusion, in the present embodiment of this application, when the client executes a configuration update on the network device, the client can send a NETCONF configuration request message to the network device without locking the data object, and the network device executes a configuration update on the data object when the network device detects that the version information of the data object recorded by the client and the network device respectively is consistent. Alternatively, the client sends a NETCONF configuration request message to the network device when it detects that the version information of the data object recorded by the client and the network device respectively is consistent. In this way, the client does not need to lock the data object for which the configuration update needs to be executed, and as a result, the parallel processing control efficiency is improved and the configuration conflict between multiple clients is reduced, that is, the impact on another client is relatively small.

[0221] Figure 5 is a flowchart of another configuration update method according to an embodiment of this application. In the embodiment of Figure 5, the client detects the consistency of the version information alone. Please refer to Figure 5. This method includes the following steps.

[0222] Step 501: When the first client detects that the first version information matches the first reference version information, the first client sends a NETCONF configuration request message to the network device. The first version information is the version information of the first data object recorded by the first client, the first reference version information is the version information of the first data object recorded by the network device, the configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to perform an operation on the first data object.

[0223] In the present embodiment of the present application, when it is expected that the first client performs a configuration update on the network device, the first client first detects whether the first version information matches the first reference version information. The first version information is the version information of the first data object recorded by the first client, and the first reference version information is the version information of the first data object recorded by the network device. When the first client detects that the first version information matches the first reference version information, the first client sends a configuration request message to the network device. The configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to perform an operation on the first data object.

[0224] When detecting the consistency of the version information, it can be known from the foregoing that the first client needs to first obtain the version information of the first data object recorded by the network device. The following describes two embodiments in which the first client obtains the version information of the first data object recorded by the network device.

[0225] In an embodiment where the first client obtains version information of a first data object recorded by a network device, the first client sends an inquiry message to the network device, and the inquiry message includes an identifier of the first data object. The first client receives an inquiry response message sent by the network device, and the inquiry response message includes the version information of the first data object recorded by the network device. That is, the first client obtains the version information of the first data object recorded by the network device in an immediate inquiry manner.

[0226] In another embodiment where the first client obtains version information of a first data object recorded by a network device, the first client receives a data change notification message sent by the network device, the data change notification message includes the version information of the first data object recorded by the network device, and the data change notification message is received when the first client subscribes to a change notification of configuration data in the first data object. That is, the first client obtains the version information of the first data object recorded by the network device in a subscription manner.

[0227] The above two embodiments are consistent with the relevant content of step 301 in the embodiment of FIG. 3. For the two embodiments where the first client obtains the version information of the first data object recorded by the network device in step 501, please refer to the relevant description of step 301. Details will not be described again here.

[0228] If the first client detects that the first version information does not match the first reference version information, the first client may interrupt the configuration update. In this case, even if the first client still sends a configuration request message to the network device, the network device will not accept the request of the first client.

[0229] Step 502: The network device receives the configuration request message and executes an operation on the first data object.

[0230] In the present embodiment of the present application, when the network device receives a configuration request message sent by the first client, it indicates that the first client has detected that the first version information matches the first reference version information. In this case, the network device may not need to detect the consistency of the version information, and the network device executes a corresponding operation on the first data object based on the operation instruction information included in the configuration request message.

[0231] It should be noted that in this case, the probability that the network device executes the operation normally is relatively high. However, in some cases, the network device may fail to execute the configuration update. For example, due to reasons such as processing efficiency or network delay, there is a relatively long time interval between the time when the first client detects the consistency of the version information and the time when the network device receives the configuration request message. During this time interval, the network device may accept the requests of other clients and modify the configuration data in the first data object. In this case, the first reference version information obtained by the first client is not the latest version information recorded by the network device. Alternatively, the network device may fail to execute the configuration update due to reasons such as a network device failure or an incorrect operation requested by the first client.

[0232] It should be further noted that the embodiment in which the first client detects the consistency of version information alone, as described in the embodiment of FIG. 5, is different from the embodiment of FIG. 3 only in that the execution entity for detecting the consistency of version information is different. Other contents described in the embodiment of FIG. 3 are also applicable to the embodiment of FIG. 5 and will not be described again in FIG. 5.

[0233] Next, the configuration update method described in the embodiment of FIG. 5 will be described again using an example with reference to FIG. 6.

[0234] In FIG. 6, it is assumed that the first client detects the consistency of version information. The version information is a version number updated by accumulation. Both client A and client B can execute a configuration update on the network device.

[0235] Client A expects to modify the configuration data within the first data object of the network device and edits the configuration data locally at the local end. The first version information recorded by Client A is 1, i.e., V = 1. At time t1, Client A requests to obtain the first reference version information from the network device (e.g., by a get-revision operation). At time t2, the first reference version information fed back to Client A by the network device is 1, i.e., V = 1. Client A determines by comparison that the first version information is consistent with the first reference version information. In this case, at time t3, Client A sends a configuration request message to the network device, and the configuration request message indicates to perform an edit operation on the first data object. After receiving the configuration request message, the network device performs a configuration operation on the first data object to execute the configuration update. After successfully executing the configuration update, the network device updates the recorded first reference version information to 2, i.e., V = 2. At time t4, the network device sends a configuration success response message to Client A, and the configuration success response message indicates a successful configuration. After receiving the configuration success response message, Client A may update the first version information recorded by Client A to 2.

[0236] Client B anticipates modifying the configuration data within the first data object of the network device and edits the configuration data locally at the local end. The first version information recorded by Client B is 2, i.e., V = 2. At time t5, Client B requests to obtain the first reference version information from the network device (e.g., by means of a get-revision operation). At time t6, the first reference version information fed back to Client B by the network device is 2, i.e., V = 2. If Client B determines by comparison that the first version information is consistent with the first reference version information, then at time t7, Client B sends a configuration request message to the network device, and the configuration request message indicates to execute an edit operation on the first data object. After receiving the configuration request message, the network device executes a configuration operation on the first data object to perform a configuration update. After successfully executing the configuration update, the network device updates the recorded first reference version information to 3, i.e., V = 3. At time t8, the network device sends a configuration success response message to Client B, and the configuration success response message indicates a successful configuration.

[0237] Client A anticipates modifying the configuration data within the first data object of the network device and edits the configuration data again locally at the local end. At this time, the first version information recorded by Client A is 2, i.e., V = 2. At time t9, Client A requests to obtain the first reference version information from the network device (e.g., by means of a get-revision operation). At time t10, the first reference version information fed back to Client A by the network device is 3, i.e., V = 3. If Client A determines by comparison that the first version information is not consistent with the first reference version information, then Client A interrupts the current configuration request.

[0238] As a conclusion, in the present embodiment of the present application, when a client executes a configuration update on a network device, the client can send a NETCONF configuration request message to the network device without locking a data object, and when the network device detects that the version information of the data object recorded by the client and the network device respectively is consistent, the network device executes a configuration update on the data object. Alternatively, the client sends a NETCONF configuration request message to the network device when detecting that the version information of the data object recorded by the client and the network device respectively is consistent. In this way, the client does not need to lock the data object for which the configuration update needs to be executed, and as a result, the parallel processing control efficiency is improved, and the configuration conflict between multiple clients is reduced, that is, the influence on another client is relatively small.

[0239] FIG. 7 is a schematic diagram of the structure of a configuration update device 700 according to an embodiment of the present application. The configuration update device 700 can be implemented as part or all of a communication device using software, hardware, or a combination thereof. The communication device can be the network device in the embodiments of FIGS. 1-6. In the present embodiment of the present application, the device 700 is used for a network device. Please refer to FIG. 7. The device 700 includes a first receiving module 701 and a configuration update module 702.

[0240] The first receiving module 701 receives a network configuration protocol NETCONF configuration request message sent by a first client. The NETCONF configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to perform an operation on a first data object. The operation instruction information includes first version information, and the first version information is the version information of the first data object recorded by the first client. The first data object includes the configuration data of the network device, and is configured as such.

[0241] When the network device detects that the first version information matches the first reference version information, the configuration update module 702 performs an operation on the first data object. The first reference version information is the version information of the first data object recorded by the network device, and is configured as such.

[0242] Optionally, the NETCONF configuration request message is sent when the first client detects that the first version information matches the first reference version information.

[0243] Optionally, the device 700 further includes a second receiving module configured to receive an inquiry message sent by the first client, the inquiry message including an identifier of the first data object, and a first sending module configured to send an inquiry response message to the first client, the inquiry response message including the version information of the first data object recorded by the network device. is further included.

[0244] Optionally, the device 700 Send a data change notification message to a first client, the data change notification message including version information of a first data object recorded by a network device, the data change notification message being configured to be sent by the network device when the first client has subscribed to a notification of a change in data within the first data object, a second transmission module further comprising.

[0245] Optionally, the version information includes a timestamp, and the first reference version information is the system time at which the network device completed performing an operation on the first data object recorded by the network device, or the first reference version information is the system time at which the network device started performing an operation on the first data object recorded by the network device.

[0246] Optionally, apparatus 700 a processing module configured to complete performing an operation on a first data object, and a recording module configured to record first reference version information further comprising.

[0247] Optionally, the recording module a first recording sub-module configured to update and record the first reference version information when the data granularity of the first data object corresponding to the first reference version information meets the data granularity at which the network device sets an access control function comprising.

[0248] Optionally, the operation instruction information further includes an identifier of a second data object, the first data object being a child data object of the second data object, and the second reference version information being version information of the second data object recorded by the network device.

[0249] The recording module When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity for which the network device sets the access control function, and the data granularity of the second data object corresponding to the second reference version information satisfies the data granularity for which the network device sets the access control function, a second recording sub-module configured to update and record the first reference version information and the second reference version information is included.

[0250] Optionally, the operation instruction information further includes an identifier of a third data object, the first data object is a child data object of the third data object, the third reference version information is the version information of the third data object recorded by the network device, and the access control function set by the network device supports a reverse selection mechanism.

[0251] The recording module When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity for which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity for which the network device sets the access control function, and the reverse selection mechanism parameter of the access control function set by the network device does not include the identifier of the first data object, a third recording sub-module configured to update and record the first reference version information and the third reference version information, and When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity for which the network device sets the access control function, and the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity for which the network device sets the access control function, and the inverse selection mechanism parameter of the access control function set by the network device includes the identifier of the first data object, a fourth recording sub-module configured to update and record the first reference version information and including.

[0252] Optionally, device 700 a third receiving module configured to receive an access control function setting request message sent by a first client, the access control function setting request message including an identifier of the first data object, and a setting module configured to set an initial version information value of the first data object based on the identifier of the first data object when the network device determines that the first data object satisfies the access control function setting condition based on the identifier of the first data object, and a third sending module configured to send a setting success response message to the first client, the setting success response message indicating to the first client to record the version information of the first data object. further including.

[0253] Optionally, the setting success response message includes the initial version information value, or the setting success response message indicates to the first client to set the initial version information value of the first data object.

[0254] Optionally, the access control function setting condition includes that the network device supports setting the access control function and the first data object has no version information.

[0255] Optionally, the access control function setting condition further includes that the data granularity of the first data object meets the data granularity for setting the access control function supported by the network device.

[0256] Optionally, the access control function setting request message further includes a reverse selection mechanism parameter, the reverse selection mechanism parameter includes identifiers of one or more fourth data objects, and the fourth data object is a child data object of the first data object.

[0257] Optionally, the apparatus 700 is configured with a fourth receiving module that receives an access control function setting deletion request message sent by the first client, and the access control function setting deletion request message includes an identifier of the first data object, and a deletion module configured to delete the version information of the first data object based on the identifier of the first data object when the network device determines that the first data object meets the access control function setting deletion condition based on the identifier of the first data object and further includes.

[0258] Optionally, the access control function setting deletion condition includes that the network device supports the setting of the access control function and the network device records the version information of the first data object.

[0259] Optionally, the apparatus 700 is configured with a fourth sending module that sends a capability notification message to the first client, the capability notification message includes a support capability parameter of the access control function, and the support capability parameter indicates whether the network device supports the setting of the access control function and further includes.

[0260] Optionally, the capability notification message further includes a support granularity parameter of the access control function, where the support granularity parameter indicates that the network device supports the data granularity for setting the access control function, and the data granularity includes one or more of dataset granularity, YANG module granularity, and data node granularity.

[0261] Optionally, the operation includes a copy operation, the operation instruction information further includes fifth version information, the fifth version information is the version information of the fifth data object recorded by the first client, the fifth data object includes the configuration data of the network device, and the copy operation is used to overwrite the configuration data in the first data object with the configuration data in the fifth data object.

[0262] The configuration update module 702 is configured with a configuration update sub-module that, when the network device detects that the first version information is consistent with the first reference version information and the fifth version information is consistent with the fifth reference version information, executes an operation on the first data object, and the fifth reference version information is the version information of the fifth data object recorded by the network device. including.

[0263] In the present embodiment of this application, when a specific client executes a configuration update on a network device, the client may send a NETCONF configuration request message to the network device without locking the data object, and the network device executes a configuration update on the data object when the network device detects that the version information of the data object recorded by the client and the network device respectively is consistent. Alternatively, the client sends a NETCONF configuration request message to the network device when the client detects that the version information of the data object recorded by the client and the network device respectively is consistent. In this way, the client does not need to lock the data object for which the configuration update needs to be executed, and as a result, the parallel processing control efficiency is improved and the configuration conflict between multiple clients is reduced, that is, the impact on another client is relatively small.

[0264] It should be noted that when performing the configuration update executed by the configuration update device provided in the foregoing embodiment, the division of the foregoing functional modules is only used as an example for illustration. In actual application, the foregoing functions may be assigned to different functional modules for implementation according to requirements, that is, the internal structure of the device is divided into different functional modules to implement all or part of the functions described above. In addition, the configuration update device provided in the foregoing embodiment and the embodiment of the configuration update method belong to the same concept. For the specific implementation process, please refer to the method embodiment. Details are not described again here.

[0265] FIG. 8 is a schematic diagram of the structure of a configuration update device 800 according to an embodiment of the present application. The configuration update device 700 can be implemented as part or all of a communication device using software, hardware, or a combination thereof. The communication device can be the first client in the embodiments of FIGS. 1-6. In the present embodiment of the present application, the device 800 is used for the first client. Refer to FIG. 8. The device 800 includes a first transmission module 801.

[0266] The first transmission module 801 transmits a network configuration protocol NETCONF configuration request message to a network device. The NETCONF configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to perform an operation on a first data object. The operation instruction information includes first version information, and the first version information is the version information of the first data object recorded by the first client. The first data object includes the configuration data of the network device.

[0267] When the network device detects that the first version information matches the first reference version information, the configuration request message indicates to the network device to perform an operation on the first data object. The first reference version information is the version information of the first data object recorded by the network device.

[0268] Optionally, the device 800 further includes a reception module configured to receive a configuration success response message transmitted by the network device, and a recording module configured to record the first version information.

[0269] Optionally, the configuration success response message includes updated first reference version information.

[0270] The recording module includes a recording sub-module configured to update and record the first version information as updated first reference version information. In the present embodiment of the present application, when a specific client executes a configuration update on a network device, the client may send a NETCONF configuration request message to the network device without locking the data object, and the network device may detect that the version information of the data object recorded by the client and the network device respectively is consistent, and execute a configuration update on the data object. Alternatively, the client may send a NETCONF configuration request message to the network device when it detects that the version information of the data object recorded by the client and the network device respectively is consistent. In this way, the client does not need to lock the data object for which the configuration update needs to be executed, and as a result, the parallel processing control efficiency is improved, and the configuration conflict between multiple clients is reduced, that is, the influence on another client is relatively small.

[0271] It should be noted that the division of the foregoing functional modules is only used as an example for explanation when performing the configuration update executed by the configuration update device provided in the foregoing embodiment. In actual application, the foregoing functions may be assigned to different functional modules for implementation according to requirements, that is, the internal structure of the device is divided into different functional modules to implement all or part of the functions described above. In addition, the configuration update device provided in the foregoing embodiment and the embodiment of the configuration update method belong to the same concept. For the specific implementation process, please refer to the method embodiment. Details are not described again here.

[0272]

[0273] ​FIG. 9 is a schematic diagram of the structure of a configuration update device 900 according to an embodiment of the present application. The configuration update device 900 can be implemented as part or all of a communication device using software, hardware, or a combination thereof. The communication device can be the first client in the embodiments of FIGS. 1-6. In the present embodiment of the present application, the present device is used for the first client. Refer to FIG. 9. The device 900 includes a first transmission module 901.

[0274] The first transmission module 901 is configured to transmit a network configuration protocol NETCONF configuration request message to a network device when the first client detects that the first version information matches the first reference version information.

[0275] The first version information is the version information of the first data object recorded by the first client, and the first reference version information is the version information of the first data object recorded by the network device. The NETCONF configuration request message includes operation instruction information, and the operation instruction information indicates that the first client requests the network device to execute an operation on the first data object.

[0276] Optionally, the device 900 is further configured with a second transmission module that transmits an inquiry message to the network device, where the inquiry message includes an identifier of the first data object, and a first reception module that receives an inquiry response message transmitted by the network device, where the inquiry response message includes the version information of the first data object recorded by the network device. and further includes.

[0277] Optionally, the device 900 A second receiving module configured to receive a data change notification message sent by a network device, the data change notification message including version information of a first data object recorded by the network device, the data change notification message being received when a first client subscribes to a data change notification within the first data object further includes.

[0278] In the present embodiment of the present application, when a specific client executes a configuration update on a network device, if the client does not lock the data object and detects that the version information of the data object recorded by the client and the network device respectively is consistent, the client may send a NETCONF configuration request message to the network device. In this way, the client does not need to lock the data object for which the configuration update needs to be executed, and as a result, the parallel processing control efficiency is improved and the configuration conflict between multiple clients is reduced, that is, the impact on another client is relatively small.

[0279] It should be noted that the division of the foregoing functional modules during the configuration update executed by the configuration update device provided in the foregoing embodiment is only used as an example for explanation. In actual application, the foregoing functions may be assigned to different functional modules for implementation according to requirements, that is, the internal structure of the device is divided into different functional modules to implement all or part of the functions described above. In addition, the configuration update device provided in the foregoing embodiment and the embodiment of the configuration update method belong to the same concept. For the specific implementation process, please refer to the method embodiment. Details are not described again here.

[0280] All or part of the foregoing embodiments may be implemented by software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the procedures or functions according to the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, or microwave) manner. The computer-readable storage medium may be any available medium accessible by a computer or a data storage device such as a server or a data center incorporating one or more available media. The available media may be a magnetic medium (e.g., floppy disk, hard disk, or magnetic tape), an optical medium (e.g., digital versatile disc (DVD)), or a semiconductor medium (e.g., solid state drive (SSD)), etc. It should be noted that the computer-readable storage medium referred to in the present embodiment of the present application may be a non-volatile storage medium, in other words, a non-transitory storage medium.

[0281] It should be understood that "at least one" referred to in this specification means one or more, and "a plurality of" means two or more. In the description of the embodiments of this application, unless otherwise specified, " / " means "or". For example, A / B may represent A or B. In this specification, "and / or" only describes the association relationship between related objects and indicates that three relationships may exist. For example, A and / or B may represent the following three cases, namely, only A exists, both A and B exist, and only B exists. In addition, in order to clearly explain the technical solutions of the embodiments of this application, terms such as the first and the second are used in the embodiments of this application to distinguish the same or similar things that basically provide the same function or purpose. Those skilled in the art can understand that terms such as "the first" and "the second" do not limit the number or execution order, and terms such as "the first" and "the second" do not indicate a clear difference.

[0282] The foregoing description is only an embodiment of this application and is not intended to limit this application. Any modification, equivalent replacement, or improvement made without departing from the spirit and principle of this application shall be within the protection scope of this application.

Description of Reference Numerals

[0283] 101 Network device 102 First client 103 Second client 201 Processor 202 Communication bus 203 Memory 204 Communication interface 205 Processor 206 Output device 207 Input device 210 Program code 700 Configuration update device 701 First receiving module 702 Configuration update module 800 Configuration update device 801 First transmission module 900 Configuration update device 901 First transmission module< / capability> < / message> < / ok> < / user> < / filter> < / data> < / data> < / filter> < / filter> < / get> < / data> < / data> < / revision> < / revision> < / revision> < / revision> < / top> < / filter> < / filter> < / filter> < / filter> < / filter> < / filter> < / filter> < / target> < / running> < / startup> < / target> < / commit> < / commit> < / interface> < / target> < / running> < / target> < / capability> < / capability> < / capability> < / capability> < / capabilities> < / capabilities> < / target> < / support> < / target> < / support> < / target> < / target> < / target> < / support> < / target> < / support> < / target> < / target> < / target> < / target> < / target> < / target> < / target> < / support> < / target> < / support> < / target>

Claims

1. A configuration update method, the method comprising: receiving, by a network device, an inquiry message sent by a first client, the inquiry message including an identifier of a first data object; sending, by the network device, an inquiry response message to the first client, the inquiry response message including first reference version information of the first data object recorded by the network device; detecting, by the first client, the consistency between the first reference version information and first version information, the first version information being version information of the first data object recorded by the first client; when the first client detects that the first version information matches the first reference version information, receiving, by the network device, a network configuration protocol NETCONF configuration request message sent by the first client, the NETCONF configuration request message including operation instruction information, the operation instruction information indicating that the first client requests the network device to perform an operation on the first data object, the operation instruction information including the first version information, and the first data object including configuration data of the network device; when the network device detects that the first version information matches the first reference version information, performing, by the network device, the operation on the first data object, the first reference version information being version information of the first data object recorded by the network device; A configuration update method comprising the above steps.

2. The method further comprises: A step of transmitting, by the network device, a data change notification message to the first client, where the data change notification message includes the first reference version information of the first data object recorded by the network device, and the data change notification message is transmitted by the network device when the first client subscribes to a data change notification within the first data object, step The method according to claim 1, further comprising **Claim 3** The first version information includes a timestamp, and the first reference version information is the system time when the network device completed executing the operation on the first data object recorded by the network device, or the first reference version information is the system time when the network device started executing the operation on the first data object recorded by the network device. The method according to claim 1 **Claim 4** The method comprises A step of completing, by the network device, executing the operation on the first data object; and A step of recording, by the network device, the first reference version information The method according to claim 1, further comprising **Claim 5** The step of recording, by the network device, the first reference version information is When the data granularity of the first data object corresponding to the first reference version information meets the data granularity for which the network device sets an access control function, a step of updating and recording, by the network device, the first reference version information The method according to claim 4, comprising **Claim 6** The operation instruction information further includes an identifier of a second data object, the first data object is a child data object of the second data object, the second reference version information is the version information of the second data object recorded by the network device, and the step of recording, by the network device, the first reference version information is When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity at which the network device sets the access control function, and the data granularity of the second data object corresponding to the second reference version information satisfies the data granularity at which the network device sets the access control function, the step of updating and recording the first reference version information and the second reference version information by the network device The method according to claim 4, comprising:

7. The operation instruction information further includes an identifier of a third data object, the first data object is a child data object of the third data object, the third reference version information is the version information of the third data object recorded by the network device, the access control function set by the network device supports an inverse selection mechanism, and the step of the network device recording the first reference version information is When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity at which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity at which the network device sets the access control function, and the inverse selection mechanism parameter of the access control function set by the network device does not include the identifier of the first data object, the step of the network device updating and recording the first reference version information and the third reference version information, and When the data granularity of the first data object corresponding to the first reference version information satisfies the data granularity for which the network device sets the access control function, the data granularity of the third data object corresponding to the third reference version information satisfies the data granularity for which the network device sets the access control function, and the inverse selection mechanism parameter of the access control function set by the network device includes the identifier of the first data object, the step of updating and recording the first reference version information by the network device The method according to claim 4, comprising: **Claim 8** The method includes: The step of receiving, by the network device, an access control function setting request message sent by the first client, where the access control function setting request message includes the identifier of the first data object When the network device determines that the first data object satisfies the access control function setting condition based on the identifier of the first data object, the step of setting, by the network device, an initial version information value of the first data object based on the identifier of the first data object The step of sending, by the network device, a setting success response message to the first client, where the setting success response message indicates to the first client to record the version information of the first data object further comprising: The setting success response message includes the initial version information value, or the setting success response message indicates to the first client to set the initial version information value of the first data object The method according to claim 1 **Claim 9** The access control function setting condition includes that the network device supports setting the access control function and the first data object does not have version information The access control function setting condition further includes that the data granularity of the first data object satisfies the data granularity for setting the access control function supported by the network device. The method according to claim 8.

10. The access control function setting request message further includes an inverse selection mechanism parameter, the inverse selection mechanism parameter includes identifiers of one or more fourth data objects, and the fourth data object is a child data object of the first data object. The method according to claim 8.

11. The method includes: Receiving, by the network device, an access control function setting deletion request message sent by the first client, where the access control function setting deletion request message includes an identifier of the first data object; When the network device determines that the first data object satisfies the access control function setting deletion condition based on the identifier of the first data object, deleting, by the network device, the version information of the first data object based on the identifier of the first data object The method according to claim 1 further includes.

12. The method includes: Sending, by the network device, a capability notification message to the first client, where the capability notification message includes a support capability parameter for the access control function, and the support capability parameter indicates whether the network device supports setting the access control function; The method further includes: The capability notification message further includes a support granularity parameter for the access control function, the support granularity parameter indicates that the network device supports the data granularity for setting the access control function, and the data granularity includes one or more of a data set granularity, a YANG module granularity, and a data node granularity. The method according to claim 1.

13. A configuration update method, the method includes: A step in which a first client sends an inquiry message to a network device, the inquiry message including an identifier of a first data object A step in which the first client receives an inquiry response message from the network device, the inquiry response message including first reference version information of the first data object recorded by the network device A step in which the first client detects the consistency between the first reference version information and first version information, the first version information being version information of the first data object recorded by the first client When the first client detects that the first version information matches the first reference version information, a step in which the first client sends a network configuration protocol NETCONF configuration request message to the network device, the NETCONF configuration request message including operation instruction information, the operation instruction information indicating that the first client requests the network device to execute an operation on the first data object, the operation instruction information including the first version information, and the first data object including configuration data of the network device including When the network device detects that the first version information matches the first reference version information, the NETCONF configuration request message indicates to the network device to execute the operation on the first data object, and the first reference version information is version information of the first data object recorded by the network device Configuration update method

14. After the step of the first client sending a network configuration protocol NETCONF configuration request message to the network device, the method includes A step in which the first client receives a configuration success response message sent by the network device A step in which the first client records the first version information The method according to claim 13, further comprising

15. wherein the configured success response message includes updated first reference version information, wherein, by the first client, the step of recording the first version information is the step of updating and recording, by the first client, the first version information as the updated first reference version information The method according to claim 14, comprising

16. An apparatus configured to implement the method according to any one of claims 1 to 12.

17. An apparatus configured to implement the method according to any one of claims 13 to 15.

18. A configuration update system, the system comprising a plurality of clients and network devices, the plurality of clients being configured to configure the network devices using the network configuration protocol NETCONF, a first client being one of the plurality of clients, the network devices being configured to perform the steps of the method according to any one of claims 1 to 12, the first client being configured to perform the steps of the method according to any one of claims 13 to 15, a configuration update system.

Citation Information

Patent Citations

  • Optimistic concurrency control for managed network devices

    US10567223B1

  • Method and system for sending a netconf-based notification

    US20100057849A1