Network policy management method and apparatus, and device and storage medium
By acquiring and analyzing network policy examples, optimizing and processing ineffective and redundant strategies, and building a strategy application knowledge graph, the generalization and scalability of policy management in self-intelligent networks are solved, and the systematic management of self-intelligent networks is realized.
Patent Information
- Application Number
- PCT/CN2024/143760
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-02
- Filing Date
- 2024-12-30
- Publication Date
- 2025-07-10
AI Technical Summary
In the prior art, network operation and maintenance strategy management methods lack universality and cannot be applied to the multi-level and multi-field flexible application and scalability requirements of self-intelligent networks, and cannot meet the needs of systematic management of self-intelligent network policies.
By obtaining target policy instances, policy relationship analysis is carried out based on policy application knowledge, including policy effectiveness verification, scope analysis, effectiveness relationship analysis and execution relationship analysis, optimize and process non-effective, redundant or low-priority policy instances, and build a strategy application knowledge graph for management.
It realizes the systematic strategy management of network policies, with the advantages of strong versatility, high flexibility and on-demand expansion, and meets the operation and maintenance management needs of various fields, levels and cross-fields of self-intelligent networks.
Smart Images

Figure CN2024143760_10072025_PF_FP_ABST
Abstract
Description
Network policy management method, device, equipment and storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application is based on the Chinese patent application with application number 202410006798.4 and application date of January 2, 2024, and claims the priority of the Chinese patent application. The entire content of the Chinese patent application is hereby introduced into this application as a reference. Technical Field
[0003] The present application relates to the field of policy management, and in particular to a method, apparatus, device, and storage medium for managing network policies. Background Art
[0004] The "Self-Intelligent Network" is born in response to the development of a digital and intelligent society. Through the digital transformation and upgrade of network operations and maintenance itself, it meets the higher requirements of digital products for network experience and agile support, driving information services to a new level. The "Self-Intelligent Network" aims to build automated and intelligent operations and maintenance capabilities throughout the network lifecycle, providing consumers and vertical industry customers with "zero wait, zero failure, and zero contact" new network and ICT (Information and Communications Technology) services. It also builds digital and intelligent operations and maintenance capabilities for "self-configuration, self-repair, and self-optimization" for intelligent network operations and maintenance.
[0005] In related technologies, solutions that combine knowledge-driven and network operation and maintenance strategy management often simply combine the specific expressions of network information maps and specific field-specific strategies with business logic. This method is not universal and cannot be applied to the multi-level, multi-field flexible application and scalability requirements of systematic management of self-intelligent network strategies. Summary of the Invention
[0006] In view of this, embodiments of the present application provide a network policy management method, apparatus, device, and storage medium, aiming to meet the needs of systematic management of network policies.
[0007] The technical solution of the embodiment of the present application is implemented as follows:
[0008] In a first aspect, an embodiment of the present application provides a method for managing a network policy, including:
[0009] obtaining at least one target policy instance for network management;
[0010] Based on the policy application knowledge, performing a policy relationship analysis on the at least one target policy instance and the existing policy instance to obtain a policy relationship analysis result;
[0011] Based on the policy relationship analysis result, the at least one target policy instance and the existing policy instance are optimized.
[0012] In the above solution, obtaining at least one target policy instance for network management includes at least one of the following:
[0013] Obtain at least one target policy instance imported externally;
[0014] Get at least one target policy instance for internal monitoring.
[0015] In the above solution, the method further includes:
[0016] The policy application knowledge is constructed based on policy instance knowledge and / or network management object instance knowledge.
[0017] In the above solution, the policy application knowledge includes at least one of the following: object instance knowledge, policy instance knowledge, and element instance knowledge. The object instance knowledge is used to characterize object instances, the policy instance knowledge is used to characterize policy instances, and the element instance knowledge is used to characterize element instances. The policy application knowledge-based policy relationship analysis is performed on the at least one target policy instance and the existing policy instance to obtain a policy relationship analysis result, including:
[0018] Verifying the policy validity of the at least one target policy instance based on the policy instance knowledge to obtain a set of policy instances with valid policies; and / or,
[0019] Performing scope analysis on the set of policy instances where the policy is valid and existing policy implementation examples based on the object instance knowledge to obtain a set of policy instances where the policy is valid and the scopes of the policy instances have an intersection; and / or,
[0020] Performing effectiveness relationship analysis on a set of policy instances where the policy is valid and has overlapping scopes of action, to obtain a set of policy instances that meet the set effectiveness relationship; and / or,
[0021] An execution relationship analysis is performed on the set of policy instances that meet the set effectiveness relationship to obtain a set of policy instances whose execution elements meet the set execution relationship.
[0022] In the above solution, the policy instance knowledge includes: effectiveness indicator information that characterizes the expected effect of the policy instance. The effectiveness relationship analysis is performed on the set of policy instances that are effective for the policy and have overlapping scopes of application, and the set of policy instances that meet the set effectiveness relationship is obtained, including:
[0023] Based on the performance indicator information, determining the relationship between the performance indicators in the set of policy instances in which the policy is valid and has an intersection in scope;
[0024] Based on the relationship between the performance indicators, a set of policy instances that meet the set performance relationship is obtained;
[0025] The set performance relationship includes at least one of the following: performance indicators conflict, performance indicators overlap, and performance indicators are included.
[0026] In the above solution, performing execution relationship analysis on the set of policy instances that meet the set effectiveness relationship to obtain policy instances whose execution elements meet the set execution relationship includes:
[0027] Determining, based on the element instance knowledge, the relationship between the execution elements in the set of policy instances that meet the set effectiveness relationship;
[0028] Based on the relationship between the execution elements, a set of policy instances whose execution elements satisfy the set execution relationship is obtained;
[0029] The setting of the execution relationship includes at least one of the following: conflict between execution elements, overlap of execution elements, and association of execution elements.
[0030] In the above solution, the optimizing process of the at least one target policy instance and the existing policy instance based on the policy relationship analysis result includes:
[0031] Based on the policy relationship analysis result, the at least one target policy instance and the existing policy instance are automatically or manually optimized.
[0032] In the above solution, based on the policy relationship analysis result, automatically optimizing the at least one target policy instance and the existing policy instance includes at least one of the following:
[0033] Deleting and / or deactivating inactive policy instances;
[0034] Deleting and / or deactivating redundant policy instances;
[0035] Based on the priority policies, lower priority policy instances are deleted and / or deactivated.
[0036] In the above solution, after optimizing the at least one target policy instance based on the policy relationship analysis result, the method further includes:
[0037] Based on the strategy relationship analysis result, the strategy application knowledge is updated.
[0038] In a second aspect, an embodiment of the present application provides a network policy management device, including:
[0039] an acquisition module configured to acquire at least one target policy instance for network management;
[0040] an analysis module configured to perform a policy relationship analysis on the at least one target policy instance and the existing policy instance based on policy application knowledge to obtain a policy relationship analysis result;
[0041] The optimization module is configured to optimize the at least one target policy instance and the existing policy instance based on the policy relationship analysis result.
[0042] In a third aspect, an embodiment of the present application provides an electronic device comprising: a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the steps of the method described in the first aspect of the embodiment of the present application when running the computer program.
[0043] In a fourth aspect, an embodiment of the present application provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in the first aspect of the embodiment of the present application are implemented.
[0044] The technical solution provided by the embodiment of the present application obtains at least one target policy instance for network management; based on the policy application knowledge, performs a policy relationship analysis on the at least one target policy instance and an existing policy instance to obtain a policy relationship analysis result; based on the policy relationship analysis result, optimizes the at least one target policy instance and the existing policy instance. In this way, a policy relationship analysis can be performed on at least one target policy instance and an existing policy instance for network management based on the policy application knowledge, and based on the policy relationship analysis result, optimizes the at least one target policy instance and the existing policy instance, thereby realizing the policy systematization management of network policies, which can meet the systematic and universal management of operation and maintenance management policies in various fields, hierarchies and cross-fields of the network, and has the advantages of strong versatility, high flexibility and on-demand expansion. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] FIG1 is a flow chart of a method for managing network policies according to an embodiment of the present application;
[0046] FIG2 is a schematic diagram of the architecture of the network policy management system of this application embodiment;
[0047] FIG3 is a schematic diagram of the structure of a network policy management device according to an embodiment of the present application;
[0048] FIG4 is a schematic structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0049] The present application will be described in further detail below with reference to the accompanying drawings and embodiments.
[0050] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application pertains. The terms used herein in the specification of this application are for the purpose of describing specific embodiments only and are not intended to limit this application.
[0051] Before further explaining the embodiments of the present application in detail, the nouns and terms involved in the embodiments of the present application are explained. The nouns and terms involved in the embodiments of the present application are subject to the following interpretations:
[0052] Autonomous Networks: Aims to build automated and intelligent O&M capabilities throughout the entire network lifecycle, providing consumers and vertical industry customers with new network and ICT services with "zero wait, zero failure, and zero contact," and creating digital O&M capabilities with "self-configuration, self-repair, and self-optimization" for intelligent network O&M.
[0053] Management: A set of processes responsible for describing, organizing, controlling access to, and managing the lifecycle requirements of information and organizational entities.
[0054] Managed entity: A manageable object associated with a product, service and / or resource.
[0055] Administrative domain: A domain that uses a common set of management mechanisms to manage its contents. An administrative domain is a managed entity with three key characteristics: 1) a defined set of administrators who perform management operations on the managed entities it contains; 2) a defined set of applications responsible for different management operations (e.g., monitoring, configuration, etc.); and 3) a defined set of common management mechanisms, such as policy rules, that govern the behavior of the managed entities contained within the administrative domain.
[0056] Policy (also known as a policy instance): A policy is a set of rules used to manage and control changes and / or maintenance of the state of one or more managed objects. Organizations are policy-driven entities. Policy is a natural way to express rules and restrictions on behavior and then automatically enforce them. The purpose of policy is to ensure consistent decisions governing the behavior of a system.
[0057] Imperative policy: A policy type that uses statements to explicitly change the state of a set of target objects. The order of statements that make up the policy is clearly defined. In the embodiments of this application, unless explicitly stated, a policy will refer to a type of imperative policy, that is, a policy consisting of events, conditions, and actions. Among them, events, conditions, and actions are defined as follows:
[0058] Event: Anything that occurs in time that is important to the management system (e.g., a change to the managed system and / or its environment).
[0059] Condition: A set of attributes, characteristics, and / or values that is compared to a known set of attributes, characteristics, and / or values to determine the decision to be made.
[0060] Action: A set of operations that can be performed on a set of managed entities, representing a transformation or processing in the system being modeled.
[0061] Strategy is a key feature in enhancing the capabilities of intelligent networks. Related technologies define intelligent network levels to guide the automation and intelligence of networks and services, assess the value and advantages of intelligent network services, and guide operators and manufacturers in intelligent upgrades. The details are as follows:
[0062] Manual operation and maintenance: Corresponding to level L0, the system provides auxiliary monitoring capabilities, and all dynamic tasks require manual execution.
[0063] Assisted operation and maintenance: Corresponding to the L1 level, the system can perform specific repetitive subtasks according to pre-configuration to improve execution efficiency.
[0064] Partially autonomous networks correspond to the L2 level. Within a specific external environment, the system can enable automated closed-loop operations and maintenance for specific units based on predefined rules and policies. At the L2 level, rules can be statically injected, and policies implement an automated closed-loop system that includes event monitoring, condition analysis, and action execution.
[0065] Conditional Self-Intelligent Network: Corresponding to the L3 level, building on the L2 level, the system can perceive environmental changes in real time and self-optimize and adjust within specific network disciplines to adapt to the external environment. The L3 level allows for dynamic decoupling of rules, allowing operations personnel to dynamically edit and import policy rules based on formalized policy specifications during system execution. This requires the system to be able to systematically manage a much larger number of policy rules, sourced from a wider range of sources, and with more complex relationships.
[0066] Highly Intelligent Networks: Corresponding to the L4 level, building on L3, the system enables predictive or proactive closed-loop management of business and customer experience-driven networks in more complex, cross-network environments, enabling analysis and decision-making. L4 is typically characterized by AI-assisted rule generation, meaning that policy rules themselves undergo automatic iteration through application monitoring and effectiveness evaluation.
[0067] Fully Intelligent Network: This corresponds to Level 5 and is the ultimate goal of telecom network evolution. The system possesses closed-loop autonomy across multiple services, domains, and the entire lifecycle, encompassing all scenarios. Level 5 is characterized by adaptive evolution, meaning that policy rules must dynamically adapt to changes in the system's internal and external environments and proactively evolve based on evolving system objectives.
[0068] It is understandable that with the technological evolution and development of self-intelligent networks, it is necessary to expand the policy management technology system of self-intelligent networks to achieve standardized formal expression of policy rules, systematic management, and enhanced dynamic evolution capabilities. Based on this, in various embodiments of this application, a knowledge-driven network policy management method is proposed to meet the general needs of systematic management of operation and maintenance management policies in various fields, hierarchical and cross-domains of self-intelligent networks, with the advantages of strong versatility, high flexibility, and on-demand expansion.
[0069] The present application provides a method for managing network policies, which can be applied to electronic devices with data processing capabilities, such as a network policy management platform or a network policy management system. As shown in Figure 1, the management method includes:
[0070] Step 101: Obtain at least one target policy instance for network management.
[0071] Step 102: Based on the policy application knowledge, perform policy relationship analysis on the at least one target policy instance and the existing policy instance to obtain a policy relationship analysis result.
[0072] Step 103: Optimize the at least one target policy instance and the existing policy instance based on the policy relationship analysis result.
[0073] It can be understood that the embodiments of the present application can perform policy relationship analysis on at least one target policy instance and existing policy instances used for network management based on policy application knowledge, and optimize at least one target policy instance and existing policy instances based on the policy relationship analysis results, thereby realizing systematic policy management of network policies, which can meet the systematic and general management of operation and maintenance management policies in various fields, hierarchical and cross-fields of the network, and has the advantages of strong versatility, high flexibility and on-demand expansion.
[0074] Exemplarily, obtaining at least one target policy instance for network management includes at least one of the following:
[0075] Obtain at least one target policy instance imported externally;
[0076] Get at least one target policy instance for internal monitoring.
[0077] It is understood that the network policy management system can obtain at least one target policy instance imported externally and / or at least one target policy instance monitored internally, thereby implementing systematic management of policy instances based on the at least one target policy instance. External import can include policy instances imported by experts or from an external system policy knowledge base, and internal monitoring can include at least one target policy instance monitored by the network policy management system based on a preset monitoring policy.
[0078] Exemplarily, the method further includes:
[0079] The policy application knowledge is constructed based on policy instance knowledge and / or network management object instance knowledge.
[0080] Here, the network policy management system can construct policy application knowledge based on policy instance knowledge and / or network management object instance knowledge. Exemplarily, the policy application knowledge can be a policy application knowledge graph.
[0081] The knowledge graph (KG) is a key branch of knowledge engineering. It describes concepts and their relationships in a structured, symbolic manner in the physical world. The basic component of a knowledge graph is a triple of <entity, relationship, entity>. Entities are connected through relationships, forming a complex network of knowledge structures. A knowledge graph is a multi-relationship graph composed of entities and relationships, where entities and relationships are considered nodes and different types of edges, respectively. It can be understood that by mining relationships between instances of policy modeling and / or policy management modeling, relationships between entities can be constructed, resulting in a policy application knowledge graph.
[0082] For example, the aforementioned policy instance knowledge and / or network management object instance knowledge can be described using the RDF (Resource Description Framework) language, and a policy application knowledge graph can be constructed. RDF is a resource description language, influenced by metadata standards, framework systems, object-oriented languages, and other factors. It is used to describe various network resources. Its emergence provides a standard data description framework for publishing structured data on the Web, converting various network resources into triples and storing them in a knowledge base.
[0083] Exemplarily, the policy application knowledge includes at least one of the following: object instance knowledge, policy instance knowledge, and element instance knowledge. The object instance knowledge is used to characterize object instances, the policy instance knowledge is used to characterize policy instances, and the element instance knowledge is used to characterize element instances. The policy application knowledge-based policy relationship analysis is performed on the at least one target policy instance and the existing policy instance to obtain a policy relationship analysis result, including:
[0084] Verifying the policy validity of the at least one target policy instance based on the policy instance knowledge to obtain a set of policy instances with valid policies; and / or,
[0085] Performing scope analysis on the set of policy instances where the policy is valid and existing policy implementation examples based on the object instance knowledge to obtain a set of policy instances where the policy is valid and the scopes of the policy instances have an intersection; and / or,
[0086] Performing effectiveness relationship analysis on a set of policy instances where the policy is valid and has overlapping scopes of action, to obtain a set of policy instances that meet the set effectiveness relationship; and / or,
[0087] An execution relationship analysis is performed on the set of policy instances that meet the set effectiveness relationship to obtain a set of policy instances whose execution elements meet the set execution relationship.
[0088] It is understandable that, based on policy application knowledge, by performing policy relationship analysis on at least one target policy instance and an existing policy instance, the relationship classification and sorting of active policies for the same object or set can be performed, and the policy relationship analysis results can be identified. For example, invalid policies, redundant policies, conflicting policies, and related policies can be identified. Among them, invalid policies refer to policies that cannot actually play a role in any management object instance due to reasons such as applicability; redundant policies refer to policies that are included in other policies and can achieve the same effect without being triggered and executed separately; conflicting policies refer to policies that are triggered simultaneously with other policies and have inconsistent execution effects; and related policies refer to policies that are triggered by the execution effects of other policies to form a chain effect.
[0089] In an application example, policy application knowledge includes but is not limited to: object instance knowledge, policy instance knowledge, and element instance knowledge. The following describes each instance knowledge:
[0090] 1) Object instance knowledge
[0091] The policy application knowledge graph can maintain instance information for the current management domain and its managed objects for subsequent comprehensive analysis, including but not limited to:
[0092] Management domain instance status: instance status and subordinate relationships of management domains at all levels;
[0093] Management object instance status: the instance status and subordinate relationships of individual managed objects under the management domains at all levels.
[0094] 2) Strategy instance knowledge
[0095] The strategy application knowledge graph can maintain information for each strategy instance for subsequent comprehensive analysis, including but not limited to:
[0096] Policy instance status: active / activated, suspended / deactivated, etc.
[0097] Target scope of the policy: the management domain and management objects to which the policy applies;
[0098] Strategy effectiveness indicators: indicators used to evaluate the effectiveness of strategy application include but are not limited to functionality, performance, security, scalability, fairness, etc.
[0099] The execution elements of a policy include, but are not limited to, the subscribed trigger events, the dependent conditional variables, and the invoked execution operations.
[0100] Policy relationship records: including but not limited to: information about other policy instances with conflicting / redundant / associated relationships, specific relationship types (e.g., performance indicator conflicts and / or execution element conflicts) and related information descriptions (e.g., specific conflicting performance indicators or execution elements, etc.)
[0101] 3) Element instance knowledge
[0102] The strategy application knowledge graph can maintain information about each execution element instance referenced by the strategy for subsequent comprehensive analysis, including but not limited to:
[0103] Event instance information: event instances and relationships between event instances (derivative, mutually exclusive, etc.) can be reported;
[0104] Condition instance information: can evaluate condition instances and the relationships between condition instances (inclusion, overlap, mutual exclusion, etc.);
[0105] Action instance information: executable action instances and relationships between action instances (inclusion, influence, mutual exclusion, etc.);
[0106] Performance indicator information (optional): The relationship between the target performance expected to be achieved by the policy application and the performance indicator (inclusion, impact, mutual exclusion, etc.).
[0107] Exemplarily, the policy instance knowledge includes: effectiveness indicator information characterizing the effect expected to be achieved by the policy instance; performing effectiveness relationship analysis on a set of policy instances that are effective for the policy and have overlapping scopes of action, and obtaining a set of policy instances that meet the set effectiveness relationship, including:
[0108] Based on the performance indicator information, determining the relationship between the performance indicators in the set of policy instances in which the policy is valid and has an intersection in scope;
[0109] Based on the relationship between the performance indicators, a set of policy instances that meet the set performance relationship is obtained;
[0110] The set performance relationship includes at least one of the following: performance indicators conflict, performance indicators overlap, and performance indicators are included.
[0111] It is understandable that based on the above effectiveness relationship analysis, a set of policy instances that meet the set effectiveness relationship can be obtained, providing basic data for subsequent policy optimization.
[0112] Exemplarily, performing execution relationship analysis on the set of policy instances that meet the set effectiveness relationship to obtain policy instances whose execution elements meet the set execution relationship includes:
[0113] Determining, based on the element instance knowledge, the relationship between the execution elements in the set of policy instances that meet the set effectiveness relationship;
[0114] Based on the relationship between the execution elements, a set of policy instances whose execution elements satisfy the set execution relationship is obtained;
[0115] The setting of the execution relationship includes at least one of the following: conflict between execution elements, overlap of execution elements, and association of execution elements.
[0116] It is understandable that based on the above execution relationship analysis, a set of policy instances that meet the set execution relationship can be obtained, providing basic data for subsequent policy optimization.
[0117] In the above solution, the optimizing process of the at least one target policy instance and the existing policy instance based on the policy relationship analysis result includes:
[0118] Based on the policy relationship analysis result, the at least one target policy instance and the existing policy instance are automatically or manually optimized.
[0119] For example, based on the policy relationship analysis results and relying on the policy management framework, active policies can be automatically or manually optimized based on the relationship classification results.
[0120] Exemplarily, based on the policy relationship analysis result, automatically optimizing the at least one target policy instance and the existing policy instance includes at least one of the following:
[0121] Deleting and / or deactivating inactive policy instances;
[0122] Deleting and / or deactivating redundant policy instances;
[0123] Based on the priority policies, lower priority policy instances are deleted and / or deactivated.
[0124] It can be understood that automatic or manual optimization of active policies based on the results of policy relationship analysis can achieve systematic policy management of network policies, which can meet the systematic and general management of operation and maintenance management policies in various fields, hierarchical and cross-fields of the network, and has the advantages of strong versatility, high flexibility and on-demand expansion.
[0125] Exemplarily, after optimizing the at least one target policy instance based on the policy relationship analysis result, the method further includes:
[0126] Based on the strategy relationship analysis result, the strategy application knowledge is updated.
[0127] It can be understood that based on the results of the strategy relationship analysis, the strategy application knowledge can be updated by utilizing the original strategy rule knowledge of the strategy knowledge base and combining it with the newly input strategy rule knowledge. Through knowledge reasoning, mining and other technologies, new strategy knowledge can be combined, inferred and created to improve the completeness of the strategy knowledge.
[0128] The present application will be described in further detail below in conjunction with application examples.
[0129] Figure 2 shows the architecture of the network policy management system in this application embodiment. Based on the knowledge management foundational functional architecture, it implements knowledge-driven policy management. Specifically, the network policy management system supports static policy import, application, and updates. Specifically, it includes a policy fusion submodule and a policy knowledge base. It supports the import, application, and passive update of policy knowledge by operations and maintenance experts and external systems.
[0130] In this application embodiment, the policy knowledge base can be reused to implement the storage and reading functions of the above-mentioned policy application knowledge graph. The reading scenarios of the policy application knowledge graph include:
[0131] Respond to requests for strategic application knowledge from various sub-modules within the strategic systematization management and provide corresponding strategic application knowledge;
[0132] Respond to the policy application knowledge sharing needs of external systems and provide corresponding policy application knowledge.
[0133] Here, the strategy application knowledge includes but is not limited to: object instance knowledge, strategy instance knowledge and element instance knowledge. For details, please refer to the above description and will not be repeated here.
[0134] The following is an exemplary description of the process of policy relationship analysis and policy optimization processing in this application embodiment:
[0135] 1. Strategic Relationship Analysis
[0136] In this application embodiment, the policy relationship analysis includes the following four stages:
[0137] In the first stage, the validity of the input strategies is verified to exclude invalid strategies (strategies that cannot be executed, will not be triggered, and will not cause potential conflicts).
[0138] In the second phase, the scopes of all input valid policies are analyzed to eliminate cases where the scopes of valid policies do not overlap. The scope of an effective policy refers to the managed objects (e.g., physical or virtual network resources, or network services, businesses, etc.) that can be affected or impacted by the management operations automatically executed after the policy is triggered. If the scopes of two effective policies do not overlap, meaning that they do not affect the same managed object at any given time, then there is no potential conflict between them.
[0139] In the third stage, the effectiveness relationship of the effective policies with a common scope of action is analyzed to exclude situations where the value ranges of the application effectiveness indicators for specific management objects within the common scope of action are incompatible or irrelevant. The application effectiveness indicators of an effective policy for a specific management object within its scope of action refer to the range of effectiveness indicator values that the policy maker hopes to ensure that the specific management object will maintain during the policy's validity period by applying the policy (for example, ensuring that the average CPU usage of a data center server remains between 40% and 80% by applying an automatic scaling policy). If the value ranges of the application effectiveness indicators of two effective policies with a common scope of action for specific management objects are incompatible, they cannot achieve their respective application effectiveness indicators at the same time, and there is a potential policy conflict. The effectiveness relationship analysis is terminated and the execution relationship analysis is further performed. Otherwise, further exclude whether there is an inclusion relationship between the effectiveness targets between the policies before further performing the execution relationship analysis.
[0140] In the fourth stage, the policy execution relationships are analyzed to identify policy relationships that will not be triggered at the same time, or will not be executed at the same time, or that may have conflicts, redundancies, inclusions, and derivatives when executed at the same time.
[0141] For example, the above-mentioned stage 1 is specifically performed as follows:
[0142] Use the strategy application knowledge graph to identify the effectiveness of input strategies and exclude ineffective strategies. Ineffective strategies include but are not limited to the following:
[0143] (1) Applicability
[0144] 1) The policy instance status is inactive / deactivated;
[0145] 2) The set of managed objects under the specified management domain of the policy target scope is empty;
[0146] 3) The trigger event, evaluation condition or execution action specified by the policy execution element is not applicable or supported in the specified management domain / management object;
[0147] (2) Effectiveness
[0148] 1) The specified evaluation method of the policy effectiveness indicator is not applicable or supported in the specified management domain / management object;
[0149] 2) The current evaluation status of the strategy effectiveness indicator is invalid.
[0150] For example, the above-mentioned stage 2 is specifically performed as follows:
[0151] Using the strategy application knowledge graph, we analyze the relationship between the input and the target scope of existing strategies to confirm whether there is any intersection and to exclude potential conflicts, overlaps, and derivative relationships between strategies with non-intersecting target scopes. This scope relationship analysis includes but is not limited to:
[0152] By utilizing the subordinate relationships between management domains and objects in the object instance knowledge in the policy application knowledge graph, we derive the direct and indirect relationships of the policy's target scope and infer the set of all management objects actually applied by each policy.
[0153] The intersection S1 of the actual management object sets of each policy involved in the analysis is calculated. If the intersection is empty, any scope overlap relationship is excluded and the policy relationship analysis ends; otherwise, proceed to the next step.
[0154] For example, the above-mentioned stage three is specifically performed as follows:
[0155] Using the strategy application knowledge graph, we can analyze the relationship between the performance indicators of the input strategies, confirm whether there are any intersections, and identify strategies with conflicting, overlapping, or inclusive performance indicators. The steps for performance relationship analysis include but are not limited to:
[0156] (1) Using the inclusion, derivation, and association relationships between the effectiveness indicators in the strategy instance knowledge in the strategy application knowledge graph, the direct and indirect relationships of the strategy effectiveness indicators are derived, and the set of all effectiveness indicators and their value ranges of the actual application of each strategy is inferred;
[0157] (2) Calculate the intersection S of the actual performance indicator value range of each object i in the management object set S1 of the common scope of each strategy involved in the analysis i2 , and record:
[0158] Object set S3, where each object j, S j2 Empty; that is, any possible value of the performance indicator of the management object i contained in the object set S3 cannot simultaneously satisfy all participating analysis strategies;
[0159] Object set S4, where each object k, S k2 Not empty; that is, some performance indicators of management object k contained in object set S4 have a value range S that can simultaneously satisfy all participating analysis strategies k2 .
[0160] (3) Check set S3. If set S3 is not empty, it is determined that the expected effectiveness of the relevant strategies for object set S3 cannot coexist. If they are triggered at the same time, there is a potential conflict. In this case, the effectiveness relationship analysis is terminated and the execution relationship analysis is continued. Otherwise, the target indicators of all analysis strategies have an intersection. Even if they are triggered at the same time, there is still room for further collaboration and there is no absolute conflict.
[0161] (4) Check the set S4, and for each management object m, check S m2 Is the original value range of the input policy effectiveness indicator the same as that of the input policy? If the above relationship holds for all management objects included in S4, the input policy has been included in other policies, the policy relationship analysis is completed, there is no policy conflict, and there is no need to explicitly add the policy; otherwise, it is preliminarily determined that there is a target overlap relationship between the policies, and subsequent execution relationship analysis is continued. The relevant policies can be optimized in combination with S4 records as needed.
[0162] For example, the fourth stage is specifically performed as follows:
[0163] Using the strategy application knowledge graph information, we can analyze the relationship between the execution elements of the input strategy and identify the strategies with conflicts, overlaps and correlations between the execution elements. The execution relationship analysis steps include but are not limited to:
[0164] (1) Utilizing the conflicts, overlaps, and associations among the execution elements in the element instance knowledge in the strategy application knowledge graph, we derive the direct and indirect relationships between the events, conditions, and operations associated with the execution elements of the strategy, and infer the system context parameters (input conditions and output conditions) of all the execution elements and their value ranges for the actual application of each strategy;
[0165] (2) Use the strategy application knowledge graph to determine whether the input strategies are likely to be triggered simultaneously:
[0166] Take the intersection S5 of the triggering event of the policy and all its derived events. If S5 is not empty, the policy can be triggered simultaneously by any event contained in S5. Otherwise, take the union S6 of the triggering event of the policy and all its derived events. Further use the mutually exclusive relationship between events in the policy application knowledge graph to exclude the mutually exclusive events one by one to obtain S7. If S7 is empty, the input policies cannot be triggered simultaneously. Otherwise, check whether the remaining events in S7 can still trigger multiple input policies simultaneously.
[0167] If the input strategies do not have the possibility of being triggered simultaneously, the strategies are judged to be irrelevant and the strategy execution relationship analysis is exited. Otherwise, the evaluation condition relationship analysis is continued.
[0168] (3) Use the strategy application knowledge graph to determine whether there is a possibility of simultaneous execution of input strategies after they are triggered simultaneously:
[0169] Take the intersection of the evaluation conditions of the policy and the value range of its derived conditions, use S8 to record the evaluation condition set referenced by multiple policies; use S9 to record each evaluation condition m belonging to S8 and its value range S that enables multiple policies at the same time 9m ;
[0170] If both S8 and S9 are empty, the strategies are judged to be irrelevant and the strategy execution relationship analysis ends;
[0171] If S9 is not empty, the input strategy may be executed simultaneously when the S9 condition is met, and the strategy execution action relationship is further analyzed;
[0172] (4) Use the strategy application knowledge graph to determine whether there is a possibility of conflict in execution when the input strategies are triggered and executed simultaneously:
[0173] Take the union of the input policy's execution actions and their derivative actions;
[0174] Utilize the mutually exclusive relationship between actions in the strategy application knowledge graph to identify whether there are mutually exclusive actions one by one. If so, it is determined that there is a conflict between the input strategies.
[0175] Using the inclusion relationship between actions in the strategy application knowledge graph, we identify one by one whether there are actions with inclusion relationships. If so, we determine that there is an inclusion relationship between the input strategies, and the included strategies are redundant strategies.
[0176] By utilizing the inclusion relationship between actions in the strategy application knowledge graph, we identify one by one whether there are actions with derivative relationships. If so, we determine whether there is a derivative relationship between the input strategies.
[0177] 2. Strategy Optimization Processing
[0178] In this application embodiment, the policy optimization process includes two parts:
[0179] First, based on the analysis results of the policy relationship analysis, automatic / manual dynamic optimization is performed on the input policy set.
[0180] Second, according to the analysis results of the strategic relationship analysis, the relevant information in the strategic knowledge base is dynamically improved.
[0181] To this end, we can define a meta-strategy for strategy optimization to achieve an automatic closed loop of iterative optimization of the strategy itself and its management knowledge; we can also use a reporting mechanism to remind experts or external systems of the results of strategy analysis and implement the strategy / knowledge optimization suggestions they provide.
[0182] Specific mechanisms for automated strategy optimization include but are not limited to:
[0183] Deactivate ineffective policies and record / update the corresponding policy instance status in the knowledge base;
[0184] Deactivate redundant (included) policies and record / update the relationships between corresponding policy instances in the knowledge base;
[0185] Eliminate mutually exclusive relationships among policies based on priority or other predefined meta-policies. Based on statically configured / dynamically specified priorities, differentiate mutually exclusive policies of different priorities based on the policy source (VIP customer service assurance takes precedence over routine management and maintenance), the target (primary equipment takes precedence over backup equipment), and the effectiveness indicator (service assurance takes precedence over energy conservation). Deactivate low-priority policy instances, and record / update the status and mutually exclusive relationships of policy instances in the policy knowledge base.
[0186] The following is an example of constructing strategy application knowledge in this application embodiment, which includes constructing object instance knowledge, strategy instance knowledge, and factor instance knowledge, as follows:
[0187] Object instance knowledge
[0188] The policy application knowledge graph maintains instance information for the current management domain and its managed objects for subsequent comprehensive analysis, including but not limited to:
[0189] Management domain instance status: The instance status and subordinate relationships of management domains at all levels. For example, Beijing, Fengtai District, Data Center 1, and computer rooms on floors 1-3 are different management domains, each with a sequential inclusion relationship.
[0190] Management object instance status: The instance status and subordinate relationships of individual managed objects within each level of management domain. For example, Huawei's 5G core network (5G Core) primary equipment in the North China region is deployed in the first-floor computer room of Data Center No. 1 in Fengtai District, Beijing, with backup equipment in Computer Room 2. Meanwhile, ZTE's 5G Core network primary equipment in the North China region is deployed in Computer Room 3, with backup equipment in Computer Room 2. From a network perspective, each 5GC managed object consists of different types of NF (Network Function) elements, such as SMF (Session Management Function), AMF (Access and Mobility Management Function), and UPF (User Plane Function), along with their specific network topology connections. Each NF instance corresponds to a VNF (Virtual Network Function) instance. A VNF instance can contain multiple VNFC (Virtualized Network Function Component) components, each of which can consist of a group of VMs (Virtual Machines) interconnected by specific network topology connections. On the one hand, from a resource perspective, each active VM corresponds to a process on a physical server and shares all the physical resources of the physical server (CPU, memory, network, etc.); each server corresponds to an access slot position on a rack and shares the ToR (Top of Rack) switch bandwidth resources and power efficiency of the rack.
[0191] Strategy instance knowledge
[0192] The strategy application knowledge graph maintains information for each strategy instance for subsequent comprehensive analysis, including but not limited to:
[0193] Policy instance states: Active or Suspended. For example, the VNFs and physical servers, ToR switches, routers, and other supporting equipment in computer rooms 1 and 3, which host active services, such as air conditioners, are all operating normally, and their corresponding policy instances are all active. Conversely, because computer room 2's management objects do not actually carry services, its related policy instances are all in Suspended state.
[0194] Target scope of the policy: the management domain and management objects to which the policy applies, i.e., the object instance knowledge mentioned above.
[0195] Strategy effectiveness indicators: Functional, performance, and availability indicators used to evaluate the effectiveness of strategy application. Examples include energy consumption indicators, business performance indicators, resource efficiency indicators, and redundancy assurance indicators.
[0196] Policy execution elements include: subscribed trigger events (for example, time-driven events such as major holidays, specific times, seasons, and events), dependent conditional variables (for example, threshold-driven conditions such as low energy efficiency, high load, and insufficient redundancy), and invoked execution operations (for example, VNF migration / shutdown / startup / restart, link switching, physical machine shutdown / startup, increasing / decreasing redundancy, increasing / decreasing room temperature, increasing CPU frequency / reducing rack power consumption, etc.).
[0197] Feature instance knowledge
[0198] The strategy application knowledge graph maintains information about each execution element instance referenced by the strategy for subsequent comprehensive analysis, including but not limited to:
[0199] Event instance information: Event instances and relationships between event instances (derivative, mutually exclusive, etc.) can be reported. For example, there is a derivative relationship between the college entrance examination and summer, and a mutually exclusive relationship between the college entrance examination and winter.
[0200] Condition instance information: This can evaluate condition instances and the relationships between them (inclusion, overlap, mutual exclusion, etc.). For example, simple conditions can be affected by the inclusion, overlap, and mutual exclusion relationships between indicator value ranges, and complex conditions can be affected by the "and," "or," and "not" logical combination operations between simple conditions.
[0201] Action instance information: executable action instances and relationships between action instances (inclusion, impact, mutual exclusion, etc.). For example, scaling down and scaling up are mutually exclusive operations, shutting down a physical machine includes migrating / shutting down the VNFs on it, and increasing the CPU frequency of a server can potentially impact the power management of the rack in which it resides.
[0202] Performance indicator information (optional): The target performance target for the policy application and the relationships between performance indicators (inclusion, impact, mutual exclusion, etc.). Similar to condition instance information, performance indicators can be viewed as a condition or a logical combination of multiple conditions. Therefore, they can also have relationships caused by the indicator values and condition combinations. For example, simple conditions can have inclusion, overlap, and mutual exclusion relationships due to the inclusion, overlap, and mutual exclusion relationships between indicator values, and complex conditions can have inclusion, overlap, and mutual exclusion relationships due to the "AND," "OR," and "NOT" logical combination operations of simple conditions.
[0203] The following is an example of an application example to illustrate the policy relationship analysis in this application embodiment. Taking a wireless network link resource pool management policy knowledge base at a certain location as an example, some input policies are as follows:
[0204] For strategy a, the bandwidth allocated to link A is adjusted to 300 Mbps from midnight to 6:00 AM every day; at other times, the bandwidth allocated to link A is restored to 500 Mbps. Its effectiveness indicator includes link utilization (ranging from 50% to 95%).
[0205] Strategy b: If the PRB utilization rate of the local cell is greater than 50% during busy hours, load balancing between adjacent cells is enabled. Its effectiveness indicator includes the PRB utilization rate (40%-60%).
[0206] Strategy c: When the link utilization of link A is greater than 85% and lasts for more than 60% of the running time, the allocated bandwidth is adjusted to 800 Mbps. Its performance indicator includes link utilization (range: 50%-95%).
[0207] Policy d: During holidays, the bandwidth allocated to link A is adjusted to 800 Mbps; during non-holidays, the bandwidth allocated to link A is restored to 500 Mbps. Its effectiveness indicator includes link utilization (range: 50%-95%).
[0208] Strategy e: From midnight to 6 a.m. every day, the bandwidth allocated to link B is adjusted to 300Mbps-500Mbps; at other times, the bandwidth allocated to link B is restored to 100Mbps-400Mbps. Its performance indicator includes link utilization (range: 50%-80%).
[0209] In strategy f, devices X and Y can communicate via either link A or link B. When the traffic between X and Y is low (less than 200 Mbps), only link B is used. When the traffic between X and Y is between 200 Mbps and 500 Mbps, only link A is used. When the traffic between X and Y is high (greater than 500 Mbps), link aggregation is implemented. The effectiveness metric includes link utilization (ranging from 60% to 80%).
[0210] “Strategy Effectiveness Identification”:
[0211] Among them, strategy b "if the PRB utilization rate of the local cell is greater than 50% when the local cell is busy, enable load balancing between adjacent cells" is not applicable to the wireless network link resource pool management strategy knowledge base and is an invalid strategy in the knowledge base.
[0212] “Strategy Scope Relationship Analysis”:
[0213] After validity screening, the invalid policy b is excluded and the relationship between the input policy ranges is analyzed. The actual management objects are as follows:
[0214] Policy a, link A
[0215] Policy c, link A
[0216] Policy d, link A
[0217] Policy e, link B
[0218] Strategy f, Link A and Link B
[0219] After analysis, it is found that the management objects of the above strategies have intersections.
[0220] “Strategy-Effectiveness Relationship Analysis”:
[0221] Furthermore, the strategy effectiveness relationship analysis is conducted on strategies a, c, d, e, and f.
[0222] For the management objects of the intersection, the analysis of the performance indicator link utilization is as follows:
[0223] Link utilization: The value ranges of policies a, c, and d are consistent, while the value range of policy e overlaps. Therefore, the execution relationship needs to be analyzed further.
[0224] Strategy Execution Relationship Analysis
[0225] Further analysis of the execution relationship of strategies a, c, d, e, and f:
[0226] Policy a: From midnight to 6 a.m. every day, the allocated bandwidth of link A is adjusted to 300 Mbps; at other times, the allocated bandwidth of link A returns to 500 Mbps.
[0227] The trigger event is from midnight to 6 a.m. every day; the evaluation condition is none; and the execution action is to adjust the allocated bandwidth of link A to 500 Mbps.
[0228] For policy c, when the link utilization of link A is greater than 85% and the duration exceeds 60% of the running time, the allocated bandwidth is adjusted to 800 Mbps.
[0229] The trigger event is when the link utilization of link A is greater than 85%; the evaluation condition is when the duration exceeds 60% of the running time; and the execution action is when the bandwidth is adjusted to 800 Mbps.
[0230] Policy d: During holidays, the allocated bandwidth of link A is adjusted to 800 Mbps; during non-holidays, the allocated bandwidth of link A is restored to 500 Mbps.
[0231] Among them, the trigger event is: operating link A during holidays; evaluation condition is: none; execution action is: adjusting the bandwidth of link A to 800 Mbps.
[0232] Policy e: From midnight to 6 a.m. every day, the allocated bandwidth of link B is adjusted to 300 Mbps to 500 Mbps. During the rest of the time, the allocated bandwidth of link B is restored to 100 Mbps to 400 Mbps.
[0233] Trigger event: 12:00 AM to 6:00 AM every day; Evaluation condition: None; Action: Adjust the allocated bandwidth of link B to 300 Mbps-500 Mbps.
[0234] In strategy f, devices X and Y can communicate through link A or link B. When the traffic between X and Y is low (less than 200 Mbps), only link B is used for communication. When the traffic between X and Y is between 200 Mbps and 500 Mbps, only link A is used for communication. When the traffic between X and Y is too high (greater than 500 Mbps), link aggregation is adopted.
[0235] Among them, the trigger event is when the traffic between X and Y is too large; the evaluation condition is none; the execution action is link aggregation.
[0236] For the management objects of the intersection, the intersection of the triggering events of policies a, c, d, e, and f is taken, where:
[0237] The intersection trigger event of strategies a and c is: when the link utilization of link A is greater than 85% between midnight and 6 a.m. every day;
[0238] The intersection trigger event of strategies a and d is: midnight to 6:00 am during holidays;
[0239] The intersection trigger event of policies c and d is: when link A is running during holidays and the link utilization is greater than 85%.
[0240] Furthermore, we take the intersection of the evaluation conditions of strategies a, c, and d, where:
[0241] Strategies a and d have no evaluation conditions.
[0242] Finally, we take the union of the execution actions of strategies a, c, and d and perform mutual exclusion and inclusion judgments one by one, and the analysis results are:
[0243] When the triggering event is between midnight and 6 a.m. every day and the link utilization of link A is greater than 85%, policies a and c execute mutually exclusive actions, which are conflicting policies.
[0244] Strategies a and d execute mutually exclusive actions when the triggering event is a holiday between midnight and 6:00 a.m., and are therefore conflicting strategies.
[0245] When the trigger event is running link A during holidays and the link utilization is greater than 85%, policies c and d perform the same action, which is to allocate bandwidth to maintain 30 MHz. This is a derivative relationship.
[0246] For the management objects of the intersection, the implicit relationship between link A and link B is obtained through knowledge reasoning for policy f, that is, when the traffic between X and Y is too large (greater than 500Mbps), the link utilization of link A and link B after aggregation is between 60% and 80%.
[0247] Superposition analysis of strategies a, c, d, e, and f:
[0248] The intersection trigger event for policies a, e, and f is: every day between midnight and 6:00 a.m., when the traffic between X and Y is too high (greater than 500 Mbps);
[0249] The intersection trigger event for policies d, e, and f is: between midnight and 6:00 a.m. during holidays, when the traffic between X and Y is excessive (greater than 500 Mbps);
[0250] The intersection trigger event of policies c, e, and f is: from midnight to 6 a.m. every day, when the traffic between X and Y is too large (greater than 500 Mbps) and the link utilization of link A is greater than 85%.
[0251] Furthermore, taking the intersection of the evaluation conditions, the evaluation condition exists only for strategy c if the duration exceeds 60% of the running time.
[0252] Finally, we take the union of the execution actions of strategies a, c, d, e, and f and perform mutual exclusion and inclusion judgments one by one, and the analysis results are:
[0253] Policies a, e, and f have an intersection in their execution actions when the trigger event is between midnight and 6 a.m. every day and the traffic between X and Y is too large (greater than 500 Mbps). This is a derivative relationship.
[0254] When the triggering event is between midnight and 6:00 a.m. on holidays, the execution actions of strategies d, e, and f overlap, forming a derivative relationship.
[0255] When the trigger event is to run link A during holidays and the link utilization is greater than 85%, the execution actions of policies c, e, and f have an intersection, which is a derivative relationship.
[0256] In order to implement the method of the embodiment of the present application, the embodiment of the present application also provides a network policy management device, which corresponds to the above-mentioned network policy management method, and each step in the above-mentioned network policy management method embodiment is also fully applicable to the embodiment of the network policy management device.
[0257] As shown in Figure 3, the network policy management device includes an acquisition module 301, an analysis module 302, and an optimization module 303. Acquisition module 301 is configured to acquire at least one target policy instance for network management; analysis module 302 is configured to perform policy relationship analysis on the at least one target policy instance and existing policy instances based on policy application knowledge to obtain a policy relationship analysis result; and optimization module 303 is configured to optimize the at least one target policy instance and existing policy instances based on the policy relationship analysis result.
[0258] Exemplarily, the acquisition module 301 acquires at least one target policy instance for network management, including at least one of the following:
[0259] Obtain at least one target policy instance imported externally;
[0260] Get at least one target policy instance for internal monitoring.
[0261] Exemplarily, the network policy management device further includes: a construction module 304 configured to construct the policy application knowledge based on the policy instance knowledge and / or the network management object instance knowledge.
[0262] Exemplarily, the policy application knowledge includes at least one of the following: object instance knowledge, policy instance knowledge, and element instance knowledge. The object instance knowledge is used to characterize object instances, the policy instance knowledge is used to characterize policy instances, and the element instance knowledge is used to characterize element instances. The analysis module 302 is specifically configured as follows:
[0263] Verifying the policy validity of the at least one target policy instance based on the policy instance knowledge to obtain a set of policy instances with valid policies; and / or,
[0264] Performing scope analysis on the set of policy instances where the policy is valid and existing policy implementation examples based on the object instance knowledge to obtain a set of policy instances where the policy is valid and the scopes of the policy instances have an intersection; and / or,
[0265] Performing effectiveness relationship analysis on a set of policy instances where the policy is valid and has overlapping scopes of action, to obtain a set of policy instances that meet the set effectiveness relationship; and / or,
[0266] An execution relationship analysis is performed on the set of policy instances that meet the set effectiveness relationship to obtain a set of policy instances whose execution elements meet the set execution relationship.
[0267] Exemplarily, the policy instance knowledge includes: effectiveness indicator information characterizing the expected effect of the policy instance. The analysis module 302 performs effectiveness relationship analysis on a set of policy instances in which the policy is effective and has overlapping scopes of application, and obtains a set of policy instances that meet the set effectiveness relationship, including:
[0268] Based on the performance indicator information, determining the relationship between the performance indicators in the set of policy instances in which the policy is valid and has an intersection in scope;
[0269] Based on the relationship between the performance indicators, a set of policy instances that meet the set performance relationship is obtained;
[0270] The set performance relationship includes at least one of the following: performance indicators conflict, performance indicators overlap, and performance indicators are included.
[0271] Exemplarily, the analysis module 302 performs execution relationship analysis on the set of policy instances that meet the set effectiveness relationship, and obtains a set of policy instances whose execution elements meet the set execution relationship, including:
[0272] Determining, based on the element instance knowledge, the relationship between the execution elements in the set of policy instances that meet the set effectiveness relationship;
[0273] Based on the relationship between the execution elements, a set of policy instances whose execution elements satisfy the set execution relationship is obtained;
[0274] The setting of the execution relationship includes at least one of the following: conflict between execution elements, overlap of execution elements, and association of execution elements.
[0275] Exemplarily, the optimization module 303 is specifically configured as follows:
[0276] Based on the policy relationship analysis result, the at least one target policy instance and the existing policy instance are automatically or manually optimized.
[0277] Exemplarily, the optimization module 303 automatically optimizes the at least one target policy instance and the existing policy instance based on the policy relationship analysis result, including at least one of the following:
[0278] Deleting and / or deactivating inactive policy instances;
[0279] Deleting and / or deactivating redundant policy instances;
[0280] Based on the priority policies, lower priority policy instances are deleted and / or deactivated.
[0281] Exemplarily, the optimization module 303 is further configured to:
[0282] Based on the strategy relationship analysis result, the strategy application knowledge is updated.
[0283] In actual application, the acquisition module 301, the analysis module 302, the optimization module 303 and the construction module 304 can be implemented by a processor in the network policy management device. Of course, the processor needs to run the computer program in the memory to implement its functions.
[0284] It should be noted that the network policy management device provided in the above embodiment only uses the aforementioned division of program modules as an example to illustrate network policy management. In actual applications, the aforementioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the aforementioned processing. In addition, the network policy management device provided in the above embodiment and the network policy management method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0285] Based on the hardware implementation of the above program modules and in order to implement the method of the embodiment of the present application, the embodiment of the present application further provides an electronic device. Figure 4 only shows an exemplary structure of the electronic device rather than the entire structure. Part or all of the structure shown in Figure 4 can be implemented as needed.
[0286] As shown in Figure 4, an electronic device 400 provided in an embodiment of the present application includes: at least one processor 401, a memory 402, a user interface 403, and at least one network interface 404. The various components in the electronic device 400 are coupled together via a bus system 405. It will be understood that the bus system 405 is used to implement connection and communication between these components. In addition to including a data bus, the bus system 405 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in Figure 4, various buses are labeled as bus system 405.
[0287] The user interface 403 may include a display, a keyboard, a mouse, a trackball, a click wheel, keys, buttons, a touch pad or a touch screen.
[0288] The memory 402 in the embodiment of the present application is used to store various types of data to support the operation of the electronic device. Examples of such data include: any computer program used to operate on the electronic device.
[0289] The network policy management method disclosed in the embodiments of the present application can be applied to or implemented by processor 401. Processor 401 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the network policy management method can be completed by hardware integrated logic circuits in processor 401 or by software instructions. The aforementioned processor 401 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. Processor 401 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium located in memory 402. Processor 401 reads the information in memory 402 and, in conjunction with its hardware, completes the steps of the network policy management method provided in the embodiments of the present application.
[0290] In an exemplary embodiment, the electronic device may be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.
[0291] It is understood that memory 402 can be volatile memory or non-volatile memory, or can include both volatile and non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disk, or compact disc read-only memory (CD-ROM); magnetic surface memory can be magnetic disk memory or tape memory. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.
[0292] In an exemplary embodiment, the present application also provides a computer storage medium, which may be a computer-readable storage medium, for example, including a memory 402 storing a computer program. The computer program may be executed by a processor 401 of an electronic device to complete the steps of the method described in the embodiment of the present application. The computer-readable storage medium may be a memory such as a ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.
[0293] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0294] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.
[0295] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for managing network policies, comprising: Obtaining at least one target policy instance for network management; Based on policy application knowledge, performing policy relationship analysis on the at least one target policy instance and existing policy instances to obtain a policy relationship analysis result; Based on the policy relationship analysis result, performing optimization processing on the at least one target policy instance and existing policy instances.
2. The method according to claim 1, wherein Obtaining at least one target policy instance for network management includes at least one of the following: Obtaining at least one target policy instance imported externally; Obtaining at least one target policy instance monitored internally.
3. The method according to claim 1, wherein, The method further includes: Constructing the policy application knowledge based on policy instance knowledge and / or network management object instance knowledge.
4. The method according to claim 1, wherein The policy application knowledge includes at least one of the following: object instance knowledge, policy instance knowledge, and element instance knowledge. The object instance knowledge is used to represent object instances, the policy instance knowledge is used to represent policy instances, and the element instance knowledge is used to represent element instances. Based on the policy application knowledge, performing policy relationship analysis on the at least one target policy instance and existing policy instances to obtain a policy relationship analysis result includes: Verifying the policy effectiveness of the at least one target policy instance based on the policy instance knowledge to obtain a set of policy instances with effective policies; and / or, Performing scope of action analysis on the set of policy instances with effective policies and existing policy instances based on the object instance knowledge to obtain a set of policy instances with effective policies and an overlapping scope of action; and / or, Performing effectiveness relationship analysis on the set of policy instances with effective policies and an overlapping scope of action to obtain a set of policy instances that meet the set effectiveness relationship; and / or, Performing execution relationship analysis on the set of policy instances that meet the set effectiveness relationship to obtain a set of policy instances whose execution elements meet the set execution relationship.
5. The method according to claim 4, wherein The policy instance knowledge includes: effectiveness index information representing the expected effects of policy instances. Performing effectiveness relationship analysis on the set of policy instances with effective policies and an overlapping scope of action to obtain a set of policy instances that meet the set effectiveness relationship includes: Based on the effectiveness index information, determining the relationship between the effectiveness indexes in the set of policy instances with effective policies and an overlapping scope of action; Based on the relationship between the effectiveness indexes, obtaining a set of policy instances that meet the set effectiveness relationship; Wherein, the set effectiveness relationship includes at least one of the following: effectiveness indexes conflict, effectiveness indexes overlap, effectiveness indexes are included.
6. The method according to claim 4, wherein, Performing execution relationship analysis on the set of policy instances that meet the set execution relationship to obtain policy instances whose execution elements meet the set execution relationship includes: Based on the element instance knowledge, determining the relationship between the execution elements in the set of policy instances that meet the set execution relationship; Based on the relationship between the execution elements, obtaining a set of policy instances whose execution elements meet the set execution relationship; Wherein, the set execution relationship includes at least one of the following: execution elements conflict, execution elements overlap, execution elements are associated.
7. The method according to claim 1, wherein Performing optimization processing on the at least one target policy instance and the existing policy instances based on the result of the policy relationship analysis, including: Performing automatic or manual optimization processing on the at least one target policy instance and the existing policy instances based on the result of the policy relationship analysis.
8. The method according to claim 7, wherein Performing automatic optimization processing on the at least one target policy instance and the existing policy instances based on the result of the policy relationship analysis, including at least one of the following: Deleting and / or deactivating invalid policy instances; Deleting and / or deactivating redundant policy instances; Based on the priority policy, deleting and / or deactivating low-priority policy instances.
9. The method according to claim 1, wherein After performing the optimization processing on the at least one target policy instance based on the result of the policy relationship analysis, the method further includes: Updating the policy application knowledge based on the result of the policy relationship analysis.
10. A management device for network policies, including: An acquisition module configured to acquire at least one target policy instance for network management; An analysis module configured to perform policy relationship analysis on the at least one target policy instance and the existing policy instances based on policy application knowledge to obtain a policy relationship analysis result; An optimization module configured to perform optimization processing on the at least one target policy instance and the existing policy instances based on the policy relationship analysis result.
11. The management device according to claim 10, wherein, The acquisition module acquiring at least one target policy instance for network management includes at least one of the following: Acquiring at least one target policy instance imported externally; Acquiring at least one target policy instance monitored internally.
12. The management device according to claim 10, wherein, The management device further includes: A construction module for constructing the policy application knowledge based on policy instance knowledge and / or network management object instance knowledge.
13. The management device according to claim 10, wherein, The policy application knowledge includes at least one of the following: object instance knowledge, policy instance knowledge, and element instance knowledge. The object instance knowledge is used to represent object instances, the policy instance knowledge is used to represent policy instances, and the element instance knowledge is used to represent element instances. The analysis module is specifically configured to: Verifying the policy effectiveness of the at least one target policy instance based on the policy instance knowledge to obtain a set of policy-effective policy instances; and / or, Performing scope-of-action analysis on the set of policy-effective policy instances and the existing policy instances based on the object instance knowledge to obtain a set of policy-effective policy instances whose scopes of action intersect; and / or, Performing effectiveness relationship analysis on the set of policy-effective policy instances whose scopes of action intersect to obtain a set of policy instances that meet the set effectiveness relationship; and / or, Performing execution relationship analysis on the set of policy instances that meet the set effectiveness relationship to obtain a set of policy instances whose execution elements meet the set execution relationship.
14. The management device according to claim 13, wherein, The policy instance knowledge includes: effectiveness index information representing the expected effects of policy instances. The analysis module performing effectiveness relationship analysis on the set of policy-effective policy instances whose scopes of action intersect to obtain a set of policy instances that meet the set effectiveness relationship includes: Based on the effectiveness index information, determine the relationship between the effectiveness indexes in the set of policy instances where the policies are effective and the scopes of action intersect; Based on the relationship between the effectiveness indexes, obtain the set of policy instances that meet the set effectiveness relationship; Wherein, the set effectiveness relationship includes at least one of the following: there is a conflict between effectiveness indexes, effectiveness indexes overlap, an effectiveness index is included.
15. The management device according to claim 13, wherein, The analysis module performs an execution relationship analysis on the set of policy instances that meet the set execution relationship, and obtains the set of policy instances where the execution elements meet the set execution relationship, including: Based on the element instance knowledge, determine the relationship between the execution elements in the set of policy instances that meet the set execution relationship; Based on the relationship between the execution elements, obtain the set of policy instances where the execution elements meet the set execution relationship; Wherein, the set execution relationship includes at least one of the following: there is a conflict between execution elements, execution elements overlap, execution elements are associated.
16. The management device according to claim 10, wherein, The optimization module is specifically configured as: Based on the policy relationship analysis result, perform automatic or manual optimization processing on the at least one target policy instance and the existing policy instances.
17. The management device according to claim 16, wherein, The optimization module performs automatic optimization processing on the at least one target policy instance and the existing policy instances based on the policy relationship analysis result, including at least one of the following: Delete and / or deactivate ineffective policy instances; Delete and / or deactivate redundant policy instances; Based on the priority policy, delete and / or deactivate low-priority policy instances.
18. The management device according to claim 10, wherein, The optimization module is further configured as: Based on the policy relationship analysis result, update the policy application knowledge.
19. An electronic device, comprising: A processor and a memory for storing a computer program that can run on the processor, wherein, The processor, when configured to run the computer program, executes the steps of the method according to any one of claims 1 to 9.
20. A computer storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Method, device, equipment and system based on intention-driven network, and storage medium
CN114095368A
Power grid fault processing method and device and computer readable storage medium
CN114266364A
Strategy automatic deduction method and system based on description logic
CN115865405A
Network policy management method and device, equipment and storage medium
CN118827384A
Method Of Lowering The Computational Overhead Involved In Money Management For Systematic Multi-Strategy Hedge Funds
US20080097884A1
Cited By
Abnormality monitoring method and system for shared device based on big data
CN120804998A