Information processing method and apparatus, device, storage medium and computer program product

By using ARN identification in IP networks to mark IP packets, the problem of poor network security in the prior art is solved, and the application of collaborative network capabilities is realized while improving the security and scalability of the system.

WO2025180331A1PCT designated stage Publication Date: 2025-09-04CHINA MOBILE COMM LTD RES INST +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/078846
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-28
Filing Date
2025-02-24
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

When the prior art provides application collaborative network capabilities in IP networks, there are problems with poor network security, especially the privacy and security risks and management difficulties in the way of explicitly carrying type information based on application characteristics.

Method used

The IP packets are marked by application response network (ARN) identification, and the second IP packet is generated. The application's call relationship to network capabilities and the network's ability to be open to applications are characterized by ARN identification, so as to avoid directly exposing user or application information.

Benefits of technology

It improves network security, reduces the problem of frequent configuration changes, enhances the scalability and security of the system, and solves the problems of network attacks and privacy information leakage in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025078846_04092025_PF_FP_ABST
    Figure CN2025078846_04092025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present disclosure are an information processing method and apparatus, a device, a storage medium and a computer program product. The method comprises: a customer edge device acquiring a first application response network (ARN) identifier, the first ARN identifier representing a calling relationship of an application to a network capability and / or a capability of a network to be exposed to the application; marking a first Internet protocol (IP) packet on the basis of the first ARN identifier to generate a second IP packet; and sending the second IP packet.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, device, equipment, storage medium and computer program product

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] The present disclosure is based on and claims the priority of Chinese patent application with application number 2024102243726 and application date of February 28, 2024. The entire contents of the Chinese patent application are hereby introduced into the present disclosure in their entirety. Technical Field

[0003] The present disclosure relates to the field of wireless communication technologies, and in particular to an information processing method, apparatus, device, storage medium, and computer program product. Background Art

[0004] Currently, to ensure quality of service in Internet Protocol (IP) networks, technologies ranging from Multi-Protocol Label Switching (MPLS) to the current Segment Routing over IPv6 (SRv6) focus on providing network path scheduling capabilities. By planning network link resources, point-to-point network paths with different characteristics, such as low latency and high bandwidth, can be constructed. When it comes to the coordination of applications and network capabilities, there are several existing approaches. The first approach classifies traffic based on application characteristics and then directs different traffic to specific network paths. The second approach involves applications explicitly carrying type information. The network edge service access point device identifies the application information explicitly carried in the packet and then maps the packet to a network tunnel / slice. The third approach directly opens the network connection for applications to call. However, all three approaches suffer from poor network security. Summary of the Invention

[0005] In view of this, embodiments of the present disclosure are intended to provide an information processing method, apparatus, device, storage medium, and computer program product.

[0006] The technical solution of the embodiment of the present disclosure is implemented as follows:

[0007] The present disclosure provides an information processing method, which is applied to a user edge device. The method includes:

[0008] Obtaining a first Application Responsive Networking (ARN) identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability of the network to be exposed to the application;

[0009] Marking the first IP packet based on the first ARN identifier to generate a second IP packet;

[0010] Send the second IP message.

[0011] In addition, according to at least one embodiment of the present disclosure, marking the first IP packet based on the first ARN identifier includes:

[0012] Writing the first ARN identifier and the first information into the flow label field and the traffic type field in the header of the first IP packet respectively;

[0013] The first information is used to indicate whether to convert the original content in the flow label field into the first ARN identifier.

[0014] In addition, according to at least one embodiment of the present disclosure, marking the first IP packet based on the first ARN identifier includes:

[0015] Writing the first ARN identifier into the extension header of the first IP packet;

[0016] or,

[0017] The first ARN identifier is written into the source address field in the header of the first IP packet.

[0018] In addition, according to at least one embodiment of the present disclosure, obtaining the first ARN identifier includes:

[0019] Get the first ARN identifier sent by the controller;

[0020] The first ARN identifier is allocated by the controller to the user edge device based on user information, application information and network service information.

[0021] In addition, according to at least one embodiment of the present disclosure, sending the second IP message includes:

[0022] Carrying the first user information in the second IP message;

[0023] Send the second IP message.

[0024] The present disclosure provides an information processing method, which is applied to a network edge device. The method includes:

[0025] Receive a second IP packet;

[0026] in,

[0027] The second IP packet is obtained by the user edge device obtaining the first ARN identifier and marking the first IP packet based on the first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

[0028] In addition, according to at least one embodiment of the present disclosure, the method further includes:

[0029] Parsing the second IP packet to obtain the first ARN identifier;

[0030] Verify the legitimacy of the first ARN identifier according to a preset data table to obtain a verification result; the preset data table stores a preset correspondence between user information and ARN identifiers;

[0031] When the verification result indicates that the first ARN identifier is legal, the second IP packet is mapped to a corresponding path or slice based on the first ARN identifier.

[0032] In addition, according to at least one embodiment of the present disclosure, the method further includes:

[0033] If the verification result indicates that the first ARN identifier is illegal, perform a first operation;

[0034] The first operation includes one of the following:

[0035] Ignore the first ARN identifier carried by the second IP packet or discard the second IP packet;

[0036] Resetting the value of the first ARN identifier;

[0037] Map the second IP packet to the default path or slice corresponding to the packet that does not carry the ARN identifier.

[0038] In addition, according to at least one embodiment of the present disclosure, verifying the legitimacy of the first ARN identifier according to the preset data table includes:

[0039] Parsing the second IP message to obtain the first user information;

[0040] Searching the preset data table for a correspondence between the first user information and the first ARN identifier;

[0041] If a correspondence between the first user information and the first ARN identifier is found in the preset data table, it is determined that the first ARN identifier is legal.

[0042] In addition, according to at least one embodiment of the present disclosure, mapping the second IP packet to a corresponding path or slice based on the first ARN identifier includes:

[0043] If the first ARN identifier is legal, determine the first path or first slice corresponding to the first ARN identifier according to the preset correspondence between the path or slice and the ARN identifier; map the second IP packet to the first path or the first slice;

[0044] The path or slice includes one of the following:

[0045] Policy-based IPv6 segment routing (SRv6 Policy, Segment Routing over IPv6 base Policy);

[0046] Multi protocol label switching (MPLS);

[0047] Internet Layer 3 Protocol (IPinIP);

[0048] Virtual Extended Local Area Network (VxLAN);

[0049] General Routing Encapsulation (GRE);

[0050] Generic Network Virtualization Encapsulation (GENEVE).

[0051] An embodiment of the present disclosure provides an information processing method, applied to a controller, the method comprising:

[0052] Sending a first ARN identifier to a user edge device; the first ARN identifier represents a calling relationship between an application and a network capability and / or a capability open to the application by the network;

[0053] The first ARN identifier is used by the user edge device to mark the first IP packet, generate a second IP packet, and send the second IP packet.

[0054] In addition, according to at least one embodiment of the present disclosure, the method further includes:

[0055] Sending the preset correspondence between user information and ARN identifier to the network edge device; and sending the preset correspondence between path or slice and ARN identifier to the network edge device;

[0056] The path or slice includes one of the following:

[0057] SRv6;

[0058] MPLS;

[0059] IPinIP;

[0060] VxLAN;

[0061] GRE;

[0062] GENEVE.

[0063] In addition, according to at least one embodiment of the present disclosure, the method further includes:

[0064] The first ARN identifier is allocated to the user edge device based on user information, application information, and network service information.

[0065] In addition, according to at least one embodiment of the present disclosure, the method further includes:

[0066] Manage the life cycle of the first ARN identifier.

[0067] In addition, according to at least one embodiment of the present disclosure, managing the lifecycle of the first ARN identifier includes:

[0068] Perform one of the following operations on the first ARN identifier:

[0069] revocation;

[0070] Report loss;

[0071] reissue;

[0072] aging;

[0073] postpone.

[0074] An embodiment of the present disclosure provides an information processing device, including:

[0075] An acquisition module configured to acquire a first ARN identifier; the first ARN identifier represents a calling relationship between an application and a network capability and / or a capability open to the application by the network;

[0076] A processing module configured to mark the first IP packet based on the first ARN identifier to generate a second IP packet;

[0077] The first sending module is configured to send the second IP message.

[0078] An embodiment of the present disclosure provides an information processing device, including:

[0079] A receiving module configured to receive a second IP message;

[0080] in,

[0081] The second IP packet is obtained by the user edge device obtaining the first ARN identifier and marking the first IP packet based on the first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

[0082] An embodiment of the present disclosure provides an information processing device, including:

[0083] A second sending module is configured to send a first ARN identifier to the user edge device; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application;

[0084] The first ARN identifier is used by the user edge device to mark the first IP packet, generate a second IP packet, and send the second IP packet.

[0085] An embodiment of the present disclosure provides a user edge device, including a processor and a memory for storing a computer program that can be run on the processor.

[0086] The processor is configured to execute the steps of any one of the methods described above on the user edge device side when running the computer program.

[0087] An embodiment of the present disclosure provides a network edge device, including a processor and a memory for storing a computer program that can be run on the processor.

[0088] Wherein, when the processor is used to run the computer program, it executes the steps of any one of the methods described above on the network edge device side.

[0089] An embodiment of the present disclosure provides a controller, comprising a processor and a memory for storing a computer program that can be run on the processor.

[0090] Wherein, when the processor is used to run the computer program, it executes the steps of any one of the methods described above on the controller side.

[0091] At least one embodiment of the present disclosure provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the computer program implements the steps of any one of the methods described on the user edge device side, or implements the steps of any one of the methods described on the network edge device side, or implements the steps of any one of the methods described on the controller side.

[0092] An embodiment of the present disclosure further provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements any of the methods described above on the user edge device side, or any of the methods described above on the network edge device side, or any of the methods described above on the controller side.

[0093] The information processing method, apparatus, device, storage medium, and computer program product provided by the embodiments of the present disclosure include: a user edge device obtains a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability open to the application by the network; based on the first ARN identifier, a first IP packet is marked to generate a second IP packet; and the second IP packet is sent.

[0094] By adopting the technical solution provided by the embodiment of the present disclosure, since the first ARN identifier represents the calling relationship of the application to the network capability and / or the capability opened by the network to the application, the user or application does not directly call the network capability, but calls the network capability through the first ARN identifier, so that the network will not see the relevant information of the user or application. Similarly, the network does not directly open the capability to the user, but opens the capability through the first ARN identifier, so that the user will not see the service information of the network, thereby improving network security while providing application collaborative network capabilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0095] FIG1 is a schematic diagram of an Application-Aware Networking (APN) header in the related art;

[0096] FIG2 is a first schematic diagram of an implementation flow of the information processing method according to an embodiment of the present disclosure;

[0097] FIG3 is a second schematic diagram of the implementation flow of the information processing method according to an embodiment of the present disclosure;

[0098] FIG4 is a third schematic diagram of the implementation flow of the information processing method according to an embodiment of the present disclosure;

[0099] FIG5 is a schematic diagram of a system architecture for applying the information processing method according to an embodiment of the present disclosure;

[0100] FIG6 is a schematic diagram of a specific implementation flow of the information processing method according to an embodiment of the present disclosure;

[0101] FIG7 is a schematic diagram of a controller allocating a first ARN ID to a user edge device according to an embodiment of the present disclosure;

[0102] FIG8 is a schematic diagram of the life cycle of an ARN ID according to an embodiment of the present disclosure;

[0103] FIG9 is a first schematic diagram of marking a first IP message according to an embodiment of the present disclosure;

[0104] FIG10 is a second schematic diagram of marking a first IP message according to an embodiment of the present disclosure;

[0105] FIG11 is a third schematic diagram of marking a first IP message according to an embodiment of the present disclosure;

[0106] FIG12 is a fourth schematic diagram of marking a first IP message according to an embodiment of the present disclosure;

[0107] FIG13 is a first schematic diagram of an information processing device according to an embodiment of the present disclosure;

[0108] FIG14 is a second schematic diagram of the information processing device according to an embodiment of the present disclosure;

[0109] FIG15 is a third schematic diagram of an information processing device according to an embodiment of the present disclosure;

[0110] FIG16 is a schematic diagram of the structure of a user edge device according to an embodiment of the present disclosure;

[0111] FIG17 is a schematic diagram of the composition structure of a network edge device according to an embodiment of the present disclosure;

[0112] FIG18 is a schematic diagram of the composition structure of the controller according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0113] Before introducing the technical solutions of the embodiments of the present disclosure, the relevant technologies are first introduced.

[0114] In related technologies, the Internet provides best-effort services, and the digital economy is fully built on Internet Protocol (IP) networks. Diversified application demands place higher demands on network capabilities, driving the continuous evolution of IP technology to meet higher quality assurance requirements. Unlike the fixed resource allocation of Optical Transport Networks (OTNs), IP is essentially statistical time-division multiplexing. The quality of IP networks depends on factors such as path congestion and the bit error rate of the underlying optical links. To ensure quality in IP networks, technologies from Multi-Protocol Label Switching (MPLS) in 2000 to current Segment Routing over IPv6 (SRv6) have all focused on providing network path scheduling capabilities. By planning network link resources, point-to-point network paths with different characteristics, such as low latency and high bandwidth, can be constructed. Furthermore, combining these capabilities with bandwidth resource reservation mechanisms can enable network-wide slicing, virtualizing a physical network into multiple logical slices, each with different resource allocations, thereby achieving differentiated multi-point to multi-point network connectivity.

[0115] Although the IP backbone network already has flexible differentiated service capabilities, there are many different approaches to the coordination of applications and network capabilities.

[0116] The first approach is to classify traffic based on application characteristics and then direct different traffic to specific network paths (MPLS or SRv6). There are usually two solutions based on application identification:

[0117] The first solution uses an access control list (ACL) based on layer 3 and layer 4 header information to classify application types. At the network edge service access point, the traffic is classified by matching the source IP, destination IP, protocol type, source port, and destination port five-tuples of the traffic through the ACL, and then directed to a specific low-latency or high-bandwidth tunnel / slice. Usually, the hardware chips of routers and switches support ACL, so high-performance forwarding can be achieved. However, ACL requires manual maintenance of the application's five-tuple characteristics and configuration on the network device in the form of ACL commands. After the ACL classifies the flow, it specifies the next one for the flow, thereby directing the flow to the specified SRv6 / MPLS tunnel or slice.

[0118] The second solution uses deep packet inspection (DPI) based on seven-layer content information to classify application types. To extract the seven-layer content, DPI needs to identify the packet encapsulation, reassemble a series of packets into application data, and then classify them according to the characteristics of these application data. DPI usually describes application characteristics in the form of regular expressions, which cannot be processed by routing chips and can only be processed by the CPU. Common application characteristics include URLs, HTML tags, text, etc. Similar to ACL, application characteristics need to be manually maintained and configured on network devices, and it also needs to be able to reassemble multiple packets into application data. After DPI classifies the flow, it specifies the next one for the flow, thereby introducing the flow into the specified SRv6 / MPLS tunnel or slice.

[0119] The second school of thought is that applications explicitly carry type information. The network edge service access point PE identifies the application information explicitly carried in the message and then maps this type of message to the network tunnel / slice.

[0120] Application-Aware Networking (APN) defines additional application information within packets. APN utilizes the programmable space within IPv6 datagram extension headers, such as the Hop-by-Hop Options Header (HBH) and the Destination Options Header (DOH). Unlike ACL and DPI, APN requires packets to carry application information, allowing network devices to directly identify the application. After classifying the flow based on the APN information, APN assigns the next path to the flow, thereby routing the flow to a specific SRv6 / MPLS tunnel or slice. APN requires the APN ID to be explicitly carried in packets in an unencrypted format. This requires both applications to be willing to tag the APN ID and a centralized organization to centrally assign APN IDs to applications. Depending on where the APN ID is marked on traffic, there are two methods: end-side tagging and network tagging. Considering that applications may not have the relevant capabilities in the early stages, network edge service access point tagging can be used initially. As the ecosystem matures, more services will be able to autonomously carry the APN ID, further improving service awareness accuracy.

[0121] Refer to FIG. 1 , which is a schematic diagram of an APN header in related art. As shown in FIG. 1 , the APN header includes APN identification information and APN parameter information. The APN header can be used in different data planes.

[0122] As shown in Figure 1, the APN header format may include:

[0123] APN ID;

[0124] APN parameter information (APN-Para).

[0125] Here, the APN ID is used to identify service attributes, indicating that messages carrying the same identifier will be treated the same way. It specifically includes the following information: APP Group ID, which is used to identify the application group to which the message belongs and has a variable length; USER Group ID, which is used to identify the user group to which the message belongs and has a variable length.

[0126] Here, the APN parameter information (APN-Para) is a parameter related to network performance requirements. The specific parameters are defined by the APN-Para-Type, and the length of each APN parameter is 32 bits. By combining different parameter information, application requirements can be expressed in more detail. APN-Para is transmitted together with the APN ID information to describe the required network connection requirements. It specifically includes the following information: Bandwidth, which indicates the bandwidth requirement of the application in Mbit / s; Delay, the first 8 bits are reserved and must be set to 0 when sending and must be ignored when receiving. The last 24 bits indicate the delay requirement in ms, encoded as an integer value; Jitter, the first 8 bits are reserved and must be set to 0 when sending and must be ignored when receiving. The last 24 bits indicate the delay variation requirement in ms, encoded as an integer value; Packet Loss Ratio, the first 8 bits are reserved and must be set to 0 when sending and must be ignored when receiving. The last 24 bits indicate the packet loss rate per second, which is the maximum packet loss rate allowed by the system.

[0127] Here, the APN header (including the APN identifier and required parameters) can be encapsulated in the IPv6 packet extension header. Specifically, the following methods can be used:

[0128] Hop-by-Hop Options Header (HBH): The APN header can be carried as a new option of the Hop-by-Hop Options Header. By using the information carried by the Hop-by-Hop Options Header, each node on the path can read it.

[0129] Destination Options Header (DOH): The APN header can be carried as a new option in the destination options header. The information carried in the destination options header can be read by the corresponding nodes on the path.

[0130] Segment Routing Header (SRH): The APN header can also be placed in the Segment Routing Header, as a type of Segment Routing Header TLV, immediately following the segment list. The information carried in the Segment Routing Header can be read by a specific segment on the SRv6 path.

[0131] The application information carried by data packets in the APN network can indicate the application (class) to which the data packet belongs, the user (group) information using the application (class), the key flows in the application (for example, action instructions in cloud games, etc.), SLA requirements or network performance requirement parameters (for example, bandwidth, latency, jitter, packet loss rate, etc.).

[0132] The third approach is to directly open network connections and allow applications to call them. This approach, primarily in SRv6 network scenarios, abstracts network connection services through binding segment identifiers (BSIDs, Binding SIDs). This approach is primarily used in SD-WANs. The IP backbone network abstracts the paths between PEs into BSIDs with different service capabilities, such as low latency, large bandwidth, and low packet loss, and directly compiles different BSIDs into path lists on the terminal. This approach requires the BSID to be publicly disclosed, and since the BSID is shared by multiple services, it can easily lead to security issues such as network attacks and BSID bandwidth being misused. Furthermore, since the BSID is a shared resource, deactivating it will affect the service, so deactivating it cannot eliminate security risks.

[0133] The two existing schools of thought have different problems that prevent them from being widely used in the current network.

[0134] For the first type, ACL and DPI are only applicable in specific scenarios.

[0135] The main problem with the ACL approach is that as more and more applications share a single User Datagram Protocol (UDP) port, it becomes impossible to directly identify and differentiate applications based on the UDP port. Overly complex ACLs can also affect device forwarding performance for application packets and generate a large number of "zombie" entries. Especially when application changes invalidate the configuration, the ACL configuration must be updated accordingly, making maintenance extremely complex.

[0136] DPI can address the problem of ACLs failing to accurately identify applications, but its deployment also has significant limitations. First, DPI requires CPU processing, consuming significant processing power. Second, DPI cannot handle encrypted packets, while the vast majority of Internet traffic, such as HTTPS, is encrypted. Therefore, large-scale application is difficult.

[0137] The second approach, APN, has the following core issues that it fails to address, leading to low user adoption and high network security risks. Consequently, deployment has been difficult for many years:

[0138] The first issue is the privacy and security of APN IDs. If traffic can be identified through APN, there is a risk of traffic hijacking and analysis, which can make users less motivated to use APN.

[0139] The second problem is that APN ID management is extremely difficult. APN IDs require unified management across the entire network, and different applications need to be distinguished by different values. However, the internet lacks a centralized application APN ID registration and management mechanism, and with the large number of new applications appearing daily, implementation is difficult.

[0140] The third issue is APN ID leakage. Messages may be intercepted during forwarding, allowing non-accelerated users to obtain this APN ID. This APN ID can then be included in messages sent by non-accelerated users, illegally achieving acceleration effects.

[0141] Question 4: Network attack risk. APN messages have distinct characteristics and are easily attacked. Hackers can launch traffic attacks against messages using APN IDs, which poses a risk to the stable operation of the network.

[0142] Regarding the third approach, using BSID to open network connections carries similar security risks as APNs: leaks of internal network information can lead to attacks and abuse. Therefore, this approach is limited to intranet use.

[0143] In general, both schools of thought one and two adopt an application-centric approach, requiring the network to passively adapt to application changes. School three adopts an open network capability approach, and both schools have network security issues.

[0144] Based on this, in an embodiment of the present disclosure, the user edge device obtains a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability open to the application by the network; the first IP packet is marked based on the first ARN identifier to generate a second IP packet; and the second IP packet is sent.

[0145] Referring to FIG. 2 , FIG. 2 is a schematic diagram of an implementation flow of an information processing method according to an embodiment of the present disclosure, which is applied to a user edge device. The user edge device may be a client router, an SD-WAN CPE, a cloud gateway, or an application. As shown in FIG. 2 , the method includes steps 201 to 203:

[0146] Step 201: Obtain a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

[0147] Here, the network capability may refer to network resources, which may specifically include paths or slices, and the path may be understood as a tunnel.

[0148] Here, the service type of the path or slice includes but is not limited to one of the following:

[0149] Low latency;

[0150] Large bandwidth;

[0151] Low packet loss.

[0152] Here, the calling relationship between the application and the network capability may include but is not limited to one of the following:

[0153] Applications call for low-latency network capabilities;

[0154] Applications call for high-bandwidth network capabilities;

[0155] Applications utilize low-packet-loss network capabilities.

[0156] Here, the application's call to low-latency network capabilities can also be described as the application's call to low-latency path or slice services.

[0157] Here, the application's call to high-bandwidth network capabilities can also be described as the application's call to high-bandwidth path or slice services.

[0158] Here, the application's call for low-packet-loss network capabilities can also be described as the application's call for low-packet-loss path or slice services.

[0159] Here, the ability of the network to be open to applications may refer to network resources, which may specifically include paths or slices, and the paths may be understood as tunnels.

[0160] Step 202: Mark the first IP packet based on the first ARN identifier to generate a second IP packet.

[0161] As an example, the first IP packet may be an IPv6 packet.

[0162] In some embodiments, marking the first IP packet based on the first ARN identifier includes:

[0163] Writing the first ARN identifier and the first information into the flow label field and the traffic type field in the header of the first IP packet respectively;

[0164] The first information is used to indicate whether to convert the original content in the flow label field into the first ARN identifier.

[0165] As an example, the first information may also be described as an escape character.

[0166] As an example, the first information may be located in the most significant bit of the traffic class field.

[0167] That is, the flow label (Flow Label) field is multiplexed, and the highest bit (escape character) of the traffic class (tc) field is used to indicate whether to escape. If this bit is 1, the original content in the flow label field is escaped to the first ARN ID; otherwise, no escape is performed.

[0168] In some embodiments, marking the first IP packet based on the first ARN identifier includes:

[0169] Writing the first ARN identifier into the extension header of the first IP packet;

[0170] or,

[0171] The first ARN identifier is written into the source address field in the header of the first IP packet.

[0172] As an example, the extended header may refer to a DOH, HBH, or SRH header.

[0173] Here, the ARN ID field is introduced into the first IP packet to glue the application and the network together through the first ARN ID. The first ARN ID not only expresses the calling relationship between the application and the network, but also expresses the application's requirements for the network path or slice, such as path constraints such as latency, packet loss, jitter, and bandwidth.

[0174] In some embodiments, obtaining the first ARN identifier includes:

[0175] Get the first ARN identifier sent by the controller;

[0176] The first ARN identifier is allocated by the controller to the user edge device based on user information, application information and network service information.

[0177] Here, the network service information may include Quality of Service (QoS), network interface, etc.

[0178] For example, assuming that low-latency slice or path (tunnel) services are planned in the network, when a user subscribes to a low-latency connection service, how does the network complete the service process and forward it? First, the service system calls the controller interface based on the service type subscribed by the user. After receiving the user's network service subscription request, the controller assigns the first ARN identifier to the user edge device.

[0179] Specifically, the controller may allocate the first ARN identifier to the user edge device based on user information, application information, and network service information.

[0180] Here, the first ARN ID can be any integer that satisfies a one-to-one correspondence between <user, application, network service> and ARN ID. Specifically, it can be generated using a random function, or generated from small to large, or from large to small.

[0181] Here, after the controller allocates the first ARN ID to the user edge device, it can also manage the lifecycle of the first ARN identifier, specifically including:

[0182] Perform one of the following operations on the first ARN identifier:

[0183] revocation;

[0184] Report loss;

[0185] reissue;

[0186] aging;

[0187] postpone.

[0188] Here, the revocation refers to the controller deleting the relevant ARN ID information on the user and the network edge.

[0189] Here, the loss report also corresponds to the cancellation of the related ARN ID.

[0190] Here, reissuance refers to the need to regenerate an ARN ID.

[0191] Here, the aging means that the corresponding APN service has a time limit, and the corresponding ARN ID is automatically revoked after the time expires.

[0192] Here, the extension refers to extending the service time of the ARN ID.

[0193] Step 203: Send the second IP message.

[0194] As an example, the second IP packet may be sent to a network edge device.

[0195] As an example, the network edge device is a BRAS / BNG for home users, a router connected to the core network for wireless users, and a PE for accessing user dedicated lines for government and enterprise users.

[0196] As an example, after receiving the second IP packet, the network edge device parses the second IP packet to obtain the first ARN identifier carried in the first IP packet; and verifies the legitimacy of the first ARN identifier.

[0197] Specifically, the validity of the first ARN identifier is verified in the following two situations:

[0198] In the first case, if the first ARN identifier is verified to be legal, the second IP packet is mapped to the corresponding path or slice based on the first ARN identifier.

[0199] In the second case, if it is verified that the first ARN identifier is illegal, the first operation is performed.

[0200] The first operation includes one of the following:

[0201] Ignore the first ARN identifier carried by the second IP packet or discard the second IP packet;

[0202] Resetting the value of the first ARN identifier;

[0203] Map the second IP packet to the default path or slice corresponding to the packet that does not carry the ARN identifier.

[0204] In actual application, in order for the network edge device to verify the legitimacy of the first ARN identifier, the user edge device may carry the first user information in the second IP message, so that the network edge device can verify the first ARN identifier.

[0205] Based on this, in some embodiments, sending the second IP message includes:

[0206] Carrying the first user information in the second IP message;

[0207] Send the second IP message.

[0208] The embodiments of the present disclosure have the following advantages:

[0209] (1) A user edge device obtains a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application; a first IP packet is marked based on the first ARN identifier to generate a second IP packet; and the second IP packet is sent.

[0210] In the embodiment of the present disclosure, since the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application, the user or application does not directly call the network capability, but calls the network capability through the first ARN identifier, so that the network will not see the relevant information of the user or application. Similarly, the network does not directly open the capability to the user, but opens the capability through the first ARN identifier, so that the user will not see the service information of the network, thereby improving security while providing application collaborative network capabilities.

[0211] (2) Compared with the related art method of implementing application collaborative network capabilities through APN, BSID, ACL, etc., the disclosed embodiments use ARN identification. The difference is that users / applications cannot directly call the network path, but must call network services through the intermediate layer ARN. The network cannot see user application information, but only sees the intermediate layer ARN. In contrast, APN directly carries application and user information, which the network directly sees. BSID directly opens network capabilities to users, and users directly see network service information.

[0212] In terms of privacy, the ARN ID does not directly use the network connection identifier, such as BSID or SID, but uses an ARN ID independent of the BSID. The ARN ID in the message has a random value range for different users. The controller can map a user network demand contract to different ARN ID values ​​for different devices. It is set to be device-valid rather than globally valid. Different ARN ID values ​​can be different for different devices. Therefore, it carries neither network privacy information nor user privacy information.

[0213] In terms of maintainability, network capabilities are expressed through ARN IDs, which are independent of application changes. Therefore, frequent configuration changes caused by rapid application iterations are eliminated, making it easier to open network capabilities through planning. Furthermore, because ARN IDs correspond one-to-one with user-paid contracts, configuration information can be easily embedded in business processes, eliminating the need to convert contracts into ACL quintuples or APN IDs.

[0214] In terms of scalability, if only a 2-tuple of (ARN ID, user) is configured for differentiated user requirements, and the 2-tuple can be implemented by table lookup, this solution does not have scalability issues.

[0215] In terms of security, the ARN ID sits between applications and the network and has a lifecycle similar to a contract, with operations such as creation, destruction, expiration, renewal, and verification. If ARN ID information is discovered to be leaked, it can be quickly reported and a new ARN ID requested without impacting other user services. Furthermore, packets entering the SR network can be correctly mapped to the corresponding SR Policy path based on the ARN ID, even without carrying a BSID / SID. Even when carrying a BSID / SID, the ARN ID can be used to verify the legitimacy of the BSID / SID call to the network. This resolves security issues.

[0216] Finally, the scope of network ARN IDs can be divided into two categories: global ARN IDs, which have the same lifecycle across all sites, but can be different on different devices at different sites; and localized ARN IDs, which meet the local needs of individual users and have independent lifecycles. Customers with localized ARN IDs must carry them in messages. Because ARN ID values ​​are not required to be the same globally, coordination requirements are minimized.

[0217] (3) Adopting a network-centric approach, we propose Application Responsive Networking technology to address a series of security issues, eliminate the impact of rapidly changing applications on stable network configuration, and enable large-scale deployment through active application invocation of network capabilities. This technology can address the problem in related technologies where application changes lead to frequent changes in network ACL, DPI, APN, and other configurations, making it difficult to converge network stability. It can also address the problem in related technologies where application features are highly discrete and difficult to aggregate, requiring ACL and APN configuration to be configured one by one for each service, resulting in high resource consumption and difficult maintenance. It can also address the problem in related technologies where APN and BSID must carry privacy information, and security issues such as APN ID and BSID being misused or attacked after information leakage.

[0218] 3 , which is a schematic diagram of an implementation flow of an information processing method according to an embodiment of the present disclosure, and is applied to a network edge device. The network edge device is a BRAS / BNG for home users, a router connected to the core network for wireless users, and a PE for accessing user dedicated lines for government and enterprise users. As shown in FIG3 , the method includes step 301:

[0219] Step 301: Receive a second IP message;

[0220] The second IP packet is obtained by the user edge device obtaining the first ARN identifier and marking the first IP packet based on the first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability of the network to be open to the application.

[0221] Here, the network capability may refer to network resources, which may specifically include paths or slices, and the path may be understood as a tunnel.

[0222] Here, the service type of the path or slice includes but is not limited to one of the following:

[0223] Low latency;

[0224] Large bandwidth;

[0225] Low packet loss.

[0226] Here, the calling relationship between the application and the network capability may include but is not limited to one of the following:

[0227] Applications call for low-latency network capabilities;

[0228] Applications call for high-bandwidth network capabilities;

[0229] Applications utilize low-packet-loss network capabilities.

[0230] Here, the application's call to low-latency network capabilities can also be described as the application's call to low-latency path or slice services.

[0231] Here, the application's call to high-bandwidth network capabilities can also be described as the application's call to high-bandwidth path or slice services.

[0232] Here, the application's call for low-packet-loss network capabilities can also be described as the application's call for low-packet-loss path or slice services.

[0233] Here, the ability of the network to be open to applications may refer to network resources, which may specifically include paths or slices, and the paths may be understood as tunnels.

[0234] In some embodiments, the method further comprises:

[0235] Parsing the second IP packet to obtain the first ARN identifier;

[0236] Verify the legitimacy of the first ARN identifier according to a preset data table to obtain a verification result; the preset data table stores a preset correspondence between user information and ARN identifiers;

[0237] When the verification result indicates that the first ARN identifier is legal, the second IP packet is mapped to a corresponding path or slice based on the first ARN identifier.

[0238] As an example, the user information may include a user identifier corresponding to the user, source address information, link information, etc.

[0239] As an example, the network edge device may receive a preset correspondence between user information and ARN identifiers sent by the controller.

[0240] In some embodiments, the method further comprises:

[0241] If the verification result indicates that the first ARN identifier is illegal, perform a first operation;

[0242] The first operation includes one of the following:

[0243] Ignore the first ARN identifier carried by the second IP packet or discard the second IP packet;

[0244] Resetting the value of the first ARN identifier;

[0245] Map the second IP packet to the default path or slice corresponding to the packet that does not carry the ARN identifier.

[0246] As an example, resetting the value of the first ARN identifier may be resetting the first ARN ID to 0 according to configuration.

[0247] Here, if you choose to ignore the first ARN ID and forward it through the default tunnel / slice. If the message does not carry the ARN ID, it should also be forwarded through the default tunnel / slice. This way, during the network upgrade process, it is not necessary for both user-side devices and network edge devices to simultaneously support this feature.

[0248] In some embodiments, verifying the legitimacy of the first ARN identifier according to a preset data table includes:

[0249] Parsing the second IP message to obtain the first user information;

[0250] Searching the preset data table for a correspondence between the first user information and the first ARN identifier;

[0251] If a correspondence between the first user information and the first ARN identifier is found in the preset data table, it is determined that the first ARN identifier is legal.

[0252] As an example, if the correspondence between the first user information and the first ARN identifier is not found in the preset data table, it is determined that the first ARN identifier is illegal.

[0253] As an example, the first user information may be obtained through the source address field of the second IP packet.

[0254] For example, the preset correspondence between user information and ARN identifiers may include: if the user information is Ua, the corresponding ARN identifier is a value of 1; if the user information is Ub, the corresponding ARN identifier is a value of 2; and if the user information is Uc, the corresponding ARN identifier is a value of 3. Thus, assuming that the first user information is Ub and the first ARN identifier is a value of 2, it indicates that the correspondence between the first user information and the first ARN identifier is found in the preset data table, and the first ARN identifier is determined to be legal.

[0255] In some embodiments, mapping the second IP packet to a corresponding path or slice based on the first ARN identifier includes:

[0256] If the first ARN identifier is legal, determine the first path or first slice corresponding to the first ARN identifier according to the preset correspondence between the path or slice and the ARN identifier; map the second IP packet to the first path or the first slice;

[0257] The path or slice includes one of the following:

[0258] Policy-based Segment Routing for IPv6 (SRv6);

[0259] Multiprotocol Label Switching (MPLS);

[0260] Internet Layer 3 Protocol (IPinIP);

[0261] Virtual Extended Local Area Network (VxLAN);

[0262] Generic Routing Encapsulation (GRE);

[0263] Generic Network Virtualization Encapsulation (GENEVE).

[0264] As an example, the network edge device can obtain the preset correspondence between tunnels such as SRv6, Multi-Protocol Label Switching MPLS, Internet Layer 3 Protocol IPinIP, Virtual Extended Local Area Network VxLAN, Generic Routing Encapsulation Protocol GRE, and Generic Network Virtualization Encapsulation GENEVE and ARN identifiers from the controller.

[0265] For example, taking SRv6 as an example, assuming there are SRv6 tunnel 1, SRv6 tunnel 2, and SRv6 tunnel 3, SRv6 tunnel 1 is tunnel color identifier a (high-bandwidth path or slice), and the corresponding ARN identifier is the value 1, SRv6 tunnel 2 is tunnel color identifier b (low-latency path or slice), and the corresponding ARN identifier is the value 2, SRv6 tunnel 3 is tunnel color identifier c (low-packet-loss path or slice), and the corresponding ARN identifier is the value 3. In this way, assuming that the first ARN identifier is the value 2, it can be determined that the corresponding first path or first slice is SRv6 tunnel 2. In this way, the second IP packet is mapped to the low-latency path or slice corresponding to the tunnel color identifier b.

[0266] The embodiments of the present disclosure have the following advantages:

[0267] (1) A user edge device obtains a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application; a first IP packet is marked based on the first ARN identifier to generate a second IP packet; and the second IP packet is sent.

[0268] In the embodiment of the present disclosure, since the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application, the user or application does not directly call the network capability, but calls the network capability through the first ARN identifier, so that the network will not see the relevant information of the user or application. Similarly, the network does not directly open the capability to the user, but opens the capability through the first ARN identifier, so that the user will not see the service information of the network, thereby improving network security while providing application collaborative network capabilities.

[0269] 4 , which is a schematic diagram of an implementation flow of an information processing method according to an embodiment of the present disclosure, and is applied to a controller. As shown in FIG4 , the method includes step 401:

[0270] Step 401: Send a first ARN identifier to a user edge device; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application;

[0271] The first ARN identifier is used by the user edge device to mark the first IP packet, generate a second IP packet, and send the second IP packet.

[0272] In some embodiments, the method further comprises:

[0273] Sending the preset correspondence between user information and ARN identifier to the network edge device; and sending the preset correspondence between path or slice and ARN identifier to the network edge device;

[0274] The path or slice includes one of the following:

[0275] SRv6;

[0276] MPLS;

[0277] IPinIP;

[0278] VxLAN;

[0279] GRE;

[0280] GENEVE.

[0281] As an example, the controller sends the preset correspondence between the user information and the ARN identifier to the network edge device. In this way, the network edge device can verify the legitimacy of the first ARN identifier based on the preset correspondence between the user information and the ARN identifier.

[0282] As an example, the controller sends the preset correspondence between the path or slice and the ARN identifier to the network edge device. In this way, the network edge device can map the second IP packet to the path or slice corresponding to the first ARN identifier according to the preset correspondence between the path or slice and the ARN identifier if the first ARN identifier is legal.

[0283] In some embodiments, the method further comprises:

[0284] The first ARN identifier is allocated to the user edge device based on user information, application information, and network service information.

[0285] Here, the first ARN ID can be any integer as long as there is a one-to-one correspondence between <user, application, network service> and ARN ID. Specifically, the first ARN identifier can be generated using a random function, or generated from small to large, or from large to small.

[0286] In some embodiments, the method further comprises:

[0287] Manage the life cycle of the first ARN identifier.

[0288] In some embodiments, managing the lifecycle of the first ARN identifier includes:

[0289] Perform one of the following operations on the first ARN identifier:

[0290] revocation;

[0291] Report loss;

[0292] reissue;

[0293] aging;

[0294] postpone.

[0295] Here, the revocation refers to the controller deleting the relevant ARN ID information on the user and the network edge.

[0296] Here, the loss report also corresponds to the cancellation of the related ARN ID.

[0297] Here, reissuance refers to the need to regenerate an ARN ID.

[0298] Here, the aging means that the corresponding APN service has a time limit, and the corresponding ARN ID is automatically revoked after the time expires.

[0299] Here, the extension refers to extending the service time of the ARN ID.

[0300] The embodiments of the present disclosure have the following advantages:

[0301] (1) A user edge device obtains a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application; a first IP packet is marked based on the first ARN identifier to generate a second IP packet; and the second IP packet is sent.

[0302] In the embodiment of the present disclosure, since the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application, the user or application does not directly call the network capability, but calls the network capability through the first ARN identifier, so that the network will not see the relevant information of the user or application. Similarly, the network does not directly open the capability to the user, but opens the capability through the first ARN identifier, so that the user will not see the service information of the network, thereby improving security while providing application collaborative network capabilities.

[0303] 5 , which is a schematic diagram of a system architecture for an information processing method according to an embodiment of the present disclosure. As shown in FIG5 , the system includes:

[0304] The controller is configured to allocate a first ARN identifier to a user edge device; the first ARN identifier represents a calling relationship between an application and a network capability and / or a capability exposed by the network to the application.

[0305] The customer edge device (CPE1) is configured to mark the first IP packet based on the first ARN identifier to generate a second IP packet; and send the second IP packet to the network edge device.

[0306] A network edge device (PE) is used to parse the second IP packet to obtain the first ARN identifier and first user information (such as user ID); use the first user information to verify the legitimacy of the first ARN identifier, and if the first ARN identifier is legal, map the second IP packet to the corresponding path or slice based on the first ARN identifier.

[0307] Here, the customer edge device can be a customer-side router, SD-WAN CPE, cloud gateway, or an application.

[0308] Here, the network edge device is BRAS / BNG for home users, a router connected to the core network for wireless users, and a PE for accessing user dedicated lines for government and enterprise users.

[0309] 6 , which is a schematic diagram of a specific implementation flow of the information processing method according to an embodiment of the present disclosure. As shown in FIG6 , the method includes steps 601 to 606:

[0310] Step 601: The controller allocates a first ARN identifier to the user edge device; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

[0311] Here, the network capability may refer to network resources, which may specifically include paths or slices, and the path may be understood as a tunnel.

[0312] Here, the service type of the path or slice includes but is not limited to one of the following:

[0313] Low latency;

[0314] Large bandwidth;

[0315] Low packet loss.

[0316] Here, the calling relationship between the application and the network capability may include but is not limited to one of the following:

[0317] Applications call for low-latency network capabilities;

[0318] Applications call for high-bandwidth network capabilities;

[0319] Applications utilize low-packet-loss network capabilities.

[0320] Here, the application's call to low-latency network capabilities can also be described as the application's call to low-latency path or slice services.

[0321] Here, the application's call to high-bandwidth network capabilities can also be described as the application's call to high-bandwidth path or slice services.

[0322] Here, the application's call for low-packet-loss network capabilities can also be described as the application's call for low-packet-loss path or slice services.

[0323] Here, the ability of the network to be open to applications may refer to network resources, which may specifically include paths or slices, and the paths may be understood as tunnels.

[0324] For example, assuming that low-latency slice or path (tunnel) services are planned in the network, when a user subscribes to a low-latency connection service, how does the network complete the service process and forward it? First, the service system calls the controller interface based on the service type subscribed by the user. After receiving the user's network service subscription request, the controller assigns the first ARN identifier to the user edge device.

[0325] Specifically, the controller may allocate the first ARN identifier to the user edge device based on user information, application information, and network service information.

[0326] Here, the first ARN ID can be any integer as long as there is a one-to-one correspondence between <user, application, network service> and ARN ID. Specifically, the first ARN identifier can be generated using a random function, or generated from small to large, or from large to small.

[0327] FIG7 is a schematic diagram of the controller of the embodiment of the present disclosure allocating a first ARN ID to a user edge device. As shown in FIG7 , assuming that the user information is Ua, the application information is a video application, and the network service information is a low-latency path or slice, an ARN ID is randomly selected from the unassigned ARN ID database and assigned to the corresponding user edge device as the first ARN ID. Similarly, assuming that the user information is Ua, the application information is a video application, and the network service information is a low-latency and high-bandwidth path or slice, two ARN IDs are randomly selected from the unassigned ARN ID database and assigned to the corresponding user edge device as the first ARN ID.

[0328] Here, the user edge device is used to call network capabilities.

[0329] The user edge device may be a client router, SD-WAN CPE, cloud gateway or an application.

[0330] Figure 8 is a schematic diagram of the life cycle of the ARN ID in an embodiment of the present disclosure. As shown in Figure 8, the ARN ID has three states: unallocated, active period, and silent period. In the initial stage, the ARN ID is in the unallocated state; once allocated, it enters the active period. During the active period, the ARN ID service contract expires, the user terminates the ARN ID early, or the ARN ID is reported lost, which will cause the ARN ID to enter the silent period. The ARN ID in the silent period is in a suspended state. The purpose is to avoid conflicts or security risks. Therefore, it will not be allocated to the outside for a period of time. After a period of time (generally half a year or more than a year), it will be recycled into the unallocated ARN ID database.

[0331] Here, after the controller allocates the first ARN ID to the user edge device, it can also manage the lifecycle of the first ARN identifier, specifically including:

[0332] Perform one of the following operations on the first ARN identifier:

[0333] revocation;

[0334] Report loss;

[0335] reissue;

[0336] aging;

[0337] postpone.

[0338] Here, the revocation refers to the controller deleting the relevant ARN ID information on the user and the network edge.

[0339] Here, the loss report also corresponds to the cancellation of the related ARN ID.

[0340] Here, reissuance refers to the need to regenerate an ARN ID.

[0341] Here, the aging means that the corresponding APN service has a time limit, and the corresponding ARN ID is automatically revoked after the time expires.

[0342] Here, the extension refers to extending the service time of the ARN ID.

[0343] Step 602: The user edge device marks the first IP packet based on the first ARN identifier to generate a second IP packet.

[0344] Here, the first IP packet may refer to an IPv6 packet.

[0345] Here, the length of the first ARN ID is at least 10 bits.

[0346] The following methods describe several frame formats carried in messages, using the first ARN ID as 20 bits. In IPv6 messages, ARN identification (ID) information can be placed in the following ways:

[0347] The first carrying method is IPv6 header escape method.

[0348] Refer to Figure 9, which is a schematic diagram of marking the first IP message according to an embodiment of the present disclosure. As shown in Figure 9, assuming that the first IP message is an IPv6 message and the ARN ID is 20 bits, the ARN ID and the first information (escape character) are written into the flow label field (Flow Label) and the traffic type field (traffic class) in the header of the IPv6 message, respectively; wherein the first information is used to indicate whether the original content in the flow label field is escaped into the ARN ID.

[0349] That is, the 20 bits of the flow label are reused, and the highest bit (escape character) of the traffic class field (tc) indicates whether to escape. If this bit is 1, the original content in the flow label field is escaped to the ARN ID; otherwise, no escape is performed.

[0350] The second way is to carry it through the IPv6 extension header.

[0351] See Figure 10, which is a schematic diagram of marking the first IP message according to an embodiment of the present disclosure. As shown in Figure 10, it is assumed that the first IP message is an IPv6 message, the ARN ID is 20 bits, and the ARN ID is written into the extended header of the IPv6 message, namely DOH and HBH, type indicates that the 4 bytes (0 to 31 bits) are ARN ID, and flag is reserved and undefined.

[0352] The third method is to carry it through the IPv6 extension header.

[0353] See Figure 11, which is a schematic diagram of marking the first IP message according to an embodiment of the present disclosure. As shown in Figure 11, it is assumed that the first IP message is an IPv6 message, the ARN ID is 20 bits, and the ARN ID is written into the extended header SRH header of the IPv6 message. Type indicates that the 4 bytes (0 to 31 bits) are ARN ID, and flag is reserved and undefined.

[0354] The fourth method is to carry the IPv6 source address.

[0355] See Figure 12, which is a schematic diagram of marking the first IP message according to an embodiment of the present disclosure. As shown in Figure 12, assuming that the first IP message is an IPv6 message and the ARN ID is 20 bits, the ARN ID is written into the source address field of the IPv6 message.

[0356] In summary, the first ARN ID is actively carried in the first IP message, and the specific location can be DOH, HBH, SRH, FlowLabel, and source address. Specifically, if the Flow Label is reused to carry the ARN ID, the 7th bit of the traffic type field (TC) needs to be set to 1 to indicate that the current Flow Label carries the ARN ID. When DOH, HBH, and SRH are used to carry the ARN ID, the type field needs to be additionally defined to indicate that the 32-bit carries the ARN ID. When the ARN ID is carried through the source address, it is necessary to specify through configuration that all messages received through a certain link or IP carry the ARN ID through the source address.

[0357] Step 603: The user edge device sends the second IP packet to the network edge device.

[0358] Here, the network edge device is BRAS / BNG for home users, a router connected to the core network for wireless users, and a PE for accessing user dedicated lines for government and enterprise users.

[0359] Step 604: The network edge device parses the second IP packet to obtain the first ARN identifier; and verifies the legitimacy of the first ARN identifier.

[0360] Specifically, the validity of the first ARN identifier is verified according to a preset data table, wherein the preset data table stores a preset correspondence between user information and ARN identifiers, wherein the user information may include a user identifier corresponding to the user, source address information, or link information.

[0361] That is, the interface of the network edge device stores the ARN ID verification table, ie, the preset data table. Each item in the data table contains the correspondence between user information and ARN identifier, wherein the user information can be represented by a source IP address, etc.

[0362] Here, the network edge device may obtain the preset data table from the controller.

[0363] Here, when the network edge device receives the second IP message containing the first ARN ID, it can obtain the first user information based on the source IP address in the second IP message, and obtain the first ARN ID based on the second IP message, and then search the preset data table to see whether it contains a correspondence between the first user information and the first ARN identifier to perform a legitimacy verification on the first ARN identifier.

[0364] Table 1 is a schematic diagram of the correspondence between user information and ARN identifiers. As shown in Table 1, if the user information is Ua, the corresponding ARN identifier is the value 1; if the user information is Ub, the corresponding ARN identifier is the value 2; and if the user information is Uc, the corresponding ARN identifier is the value 3.

[0365] Table 1

[0366] Here, verifying the legitimacy of the first ARN identifier according to the preset data table includes:

[0367] Parsing the second IP message to obtain the first user information;

[0368] Searching the preset data table for a correspondence between the first user information and the first ARN identifier;

[0369] If a correspondence between the first user information and the first ARN identifier is found in the preset data table, it is determined that the first ARN identifier is legal;

[0370] If the correspondence between the first user information and the first ARN identifier is not found in the preset data table, it is determined that the first ARN identifier is illegal.

[0371] Here, the first user information may be obtained through the inbound interface link or the source IP address in the second IP packet.

[0372] Step 605: When the ARN identifier is verified to be legal, the second IP packet is mapped to a corresponding path or slice based on the first ARN identifier.

[0373] Specifically, mapping the second IP packet to a corresponding path or slice based on the first ARN identifier includes:

[0374] Determine, according to a preset correspondence between a path or slice and an ARN identifier, a first path or a first slice corresponding to the first ARN identifier; and map the second IP packet to the first path or the first slice;

[0375] The path or slice includes one of the following:

[0376] Policy-based Segment Routing for IPv6 (SRv6);

[0377] Multiprotocol Label Switching (MPLS);

[0378] Internet Layer 3 Protocol (IPinIP);

[0379] Virtual Extended Local Area Network (VxLAN);

[0380] Generic Routing Encapsulation (GRE);

[0381] Generic Network Virtualization Encapsulation (GENEVE).

[0382] Here, the network edge device can obtain the preset correspondence between the path or slice and the ARN identifier from the controller.

[0383] Table 2 shows the correspondence between SRv6 tunnels and ARN identifiers. As shown in Table 2, taking SRv6 as an example, it includes SRv6 tunnel 1, SRv6 tunnel 2, and SRv6 tunnel 3. SRv6 tunnel 1 has tunnel color identifier a (high-bandwidth path or slice), and its corresponding ARN identifier is 1. SRv6 tunnel 2 has tunnel color identifier b (low-latency path or slice), and its corresponding ARN identifier is 2. SRv6 tunnel 3 has tunnel color identifier c (low-packet-loss path or slice), and its corresponding ARN identifier is 3.

[0384] Table 2

[0385] Here, assuming that the first ARN identifier is the value 2, according to Table 2, it can be determined that the corresponding first path or first slice is SRv6 tunnel 2, that is, tunnel color identifier b (low-latency path or slice). In this way, the second IP packet is mapped to SRv6 tunnel 2.

[0386] Step 606: When it is verified that the ARN identifier is illegal, perform the first operation.

[0387] Here, the first operation includes one of the following:

[0388] Ignore the first ARN identifier carried by the second IP packet or discard the second IP packet;

[0389] Resetting the value of the first ARN identifier;

[0390] Map the second IP packet to other paths or slices.

[0391] That is, if the first ARN ID carried by the second IP packet is not an invalid value of 0 and the legitimacy check fails, the second IP packet can be processed as follows according to the configuration:

[0392] Ignore the first ARN ID in the second IP packet or discard the second IP packet according to configuration; or

[0393] The first ARN ID is reset to 0 according to the configuration; or,

[0394] If you choose to ignore the first ARN ID, the second IP packet will be forwarded according to the slice and tunnel that does not contain the ARN ID.

[0395] That is, if you choose to ignore the first ARN ID, forward it through the default tunnel / slice. If the message does not carry the ARN ID, it should also be forwarded through the default tunnel / slice. In this way, during the network upgrade process, it is not necessary for user-side devices and network edge devices to simultaneously support this feature.

[0396] Here, in terms of coordinated application requirements and network capabilities, the network ARN ID is mainly used on network edge service access points (such as PE, BRAS / BNG).

[0397] For example, assume that low-latency slices or tunnel services are planned in the network. When a user subscribes to a low-latency connection service, the service system first calls the controller interface based on the service type subscribed by the user. After receiving the user's network service subscription request, the controller locates the corresponding network edge device (PE / BRAS / BNG) based on the locations of both ends of the connection. Based on the user's low-latency requirements, the controller creates or reuses SRv6, Multiprotocol Label Switching (MPLS), Internet Layer 3 Protocol (IPinIP), Virtual Extended Local Area Network (VxLAN), Generic Routing Encapsulation (GRE), Generic Network Virtualization Encapsulation (GENEVE) and other low-latency color tunnel identifiers (color) between the PE / BRAS / BNG to obtain the corresponding tunnel / slice. At the same time, the controller generates an ARN ID for the user, application, and network service (corresponding color) and searches for the user's corresponding source address or link information to identify the user. The controller then sends the user (source address or link information) and ARN ID to the network edge service access point PE / BRAS / BNG and associates it with the network resource slice / tunnel, thus completing the configuration of the network-side PE / BRAS / BNG.

[0398] On the user-side network, the controller locates the corresponding user edge device (CPE / gateway) based on the user and then issues the ARN ID information. This allows users to tag the ARN ID based on the application type in subsequent applications. When sending messages to the network edge device (PE / BRAS / BNG), legitimacy verification is performed to enable the invocation of corresponding network capabilities. Users can also tag applications with the ARN ID through methods such as ACLs and designated links, thus adding the ARN ID to user-side messages.

[0399] It can be seen that when providing differentiated network services to users, network services can provide users with differentiated connections (low latency, large bandwidth tunnels / slices) through ARN ID instead of BSID / SID. On the user-side edge device, multiple ARN IDs can be mapped to one SR Policy. ARN ID provides the ability to assign different values ​​to each user, which is different from the security issues caused by multiple users sharing one BSID. Unlike APN6, the value of ARN ID is a number that does not explicitly carry application or user information. It can be a random number or a sequentially assigned value, so there is no problem of APN6 exposing user privacy. On the network-side edge device, unlike APN6 and BSID, multiple ARN IDs that can be mapped to the same network capability can be aggregated into one ARN ID.

[0400] Here, the first ARN ID can be used together with user information for traffic billing. In the BRAS / BNG scenario, user information can be identified based on the link, i.e., the PPPoE connection, and in the PE scenario, it can be identified based on the source IP address or dedicated line link.

[0401] Here, the scope of the first ARN ID can be global or local. Local validity means that different ARN IDs on the device can remain unique; global validity means that one or more ARN IDs of a specific user within a certain range of devices can be mapped to a tunnel / slice in the network.

[0402] In this example, the following advantages are achieved:

[0403] (1) Since the ARN ID does not explicitly carry the user's application information and each user's ARN ID is different, this solves the user privacy problem and also solves the network security problem caused by different users sharing the BSID.

[0404] (2) The user actively adds the ARN ID in the message. The ARN ID is actually equivalent to the routing policy Color (directly corresponding to the SR Policy Color). After the user message carrying the ARN ID information enters the network edge service access point device (hereinafter referred to as PE), the PE can obtain the user information based on the source IP, verify the legitimacy of the ARN ID, and then map the ARN ID to a specific network tunnel / slice.

[0405] To implement the information processing method of the embodiment of the present disclosure, the embodiment of the present disclosure also provides an information processing device, which is installed in the user edge device. Figure 13 is a schematic diagram of the composition structure of the information processing device of the embodiment of the present disclosure. As shown in Figure 13, the device includes:

[0406] The acquisition module 131 is configured to acquire a first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application;

[0407] The processing module 132 is configured to mark the first IP packet based on the first ARN identifier to generate a second IP packet;

[0408] The first sending module 133 is configured to send the second IP message.

[0409] In some embodiments, the processing module 132 is configured to:

[0410] Writing the first ARN identifier and the first information into the flow label field and the traffic type field in the header of the first IP packet respectively;

[0411] The first information is used to indicate whether to convert the original content in the flow label field into the first ARN identifier.

[0412] In some embodiments, the processing module 132 is configured to:

[0413] Writing the first ARN identifier into the extension header of the first IP packet;

[0414] or,

[0415] The first ARN identifier is written into the source address field in the header of the first IP packet.

[0416] In some embodiments, the acquisition module 131 is configured to:

[0417] Get the first ARN identifier sent by the controller;

[0418] The first ARN identifier is allocated by the controller to the user edge device based on user information, application information and network service information.

[0419] In some embodiments, the first sending module 133 is configured to:

[0420] Carrying the first user information in the second IP message;

[0421] Send the second IP message.

[0422] In actual application, the acquisition module 131 and the first sending module 133 can be implemented by a communication interface in an information processing device; and the processing module 132 can be implemented by a processor in the information processing device.

[0423] It should be noted that the information processing device provided in the above embodiments is illustrated only by the division of the above-mentioned program modules when performing information processing. In actual applications, the above-mentioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the above-described processing. In addition, the information processing device provided in the above embodiments and the information processing method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and is not repeated here.

[0424] To implement the information processing method of the embodiment of the present disclosure, the embodiment of the present disclosure also provides an information processing device, which is installed on the network edge device. Figure 14 is a schematic diagram of the composition structure of the information processing device of the embodiment of the present disclosure. As shown in Figure 14, the device includes:

[0425] Receiving module 141, configured to receive a second IP message;

[0426] in,

[0427] The second IP packet is obtained by the user edge device obtaining the first ARN identifier and marking the first IP packet based on the first ARN identifier; the ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

[0428] In some embodiments, the apparatus is configured to:

[0429] Parsing the second IP packet to obtain the first ARN identifier;

[0430] Verify the legitimacy of the first ARN identifier according to a preset data table to obtain a verification result; the preset data table stores a preset correspondence between user information and ARN identifiers;

[0431] When the verification result indicates that the first ARN identifier is legal, the second IP packet is mapped to a corresponding path or slice based on the first ARN identifier.

[0432] In some embodiments, the apparatus is configured to:

[0433] If the verification result indicates that the ARN identifier is illegal, perform the first operation;

[0434] The first operation includes one of the following:

[0435] Ignore the first ARN identifier carried by the second IP packet or discard the second IP packet;

[0436] Resetting the value of the first ARN identifier;

[0437] Map the second IP packet to the default path or slice corresponding to the packet that does not carry the ARN identifier.

[0438] In some embodiments, the apparatus is configured to:

[0439] Parsing the second IP message to obtain the first user information;

[0440] Searching the preset data table for a correspondence between the first user information and the first ARN identifier;

[0441] If a correspondence between the first user information and the first ARN identifier is found in the preset data table, it is determined that the first ARN identifier is legal.

[0442] In some embodiments, the apparatus is configured to:

[0443] If the first ARN identifier is legal, determine the first path or first slice corresponding to the first ARN identifier according to the preset correspondence between the path or slice and the ARN identifier; map the second IP packet to the first path or the first slice;

[0444] The path or slice includes one of the following:

[0445] SRv6;

[0446] MPLS;

[0447] IPinIP;

[0448] VxLAN;

[0449] GRE;

[0450] GENEVE.

[0451] In actual application, the receiving module 141 can be implemented by a communication interface in an information processing device.

[0452] It should be noted that the information processing device provided in the above embodiments is illustrated only by the division of the above-mentioned program modules when performing information processing. In actual applications, the above-mentioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the above-described processing. In addition, the information processing device provided in the above embodiments and the information processing method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and is not repeated here.

[0453] To implement the information processing method of the embodiment of the present disclosure, the embodiment of the present disclosure further provides an information processing device, which is provided in the controller. FIG15 is a schematic diagram of the composition structure of the information processing device of the embodiment of the present disclosure. As shown in FIG15 , the device includes:

[0454] The second sending module 151 is configured to send a first ARN identifier to the user edge device; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application;

[0455] The first ARN identifier is used by the user edge device to mark the first IP packet, generate a second IP packet, and send the second IP packet.

[0456] In some embodiments, the second sending module 151 is configured to:

[0457] Sending the preset correspondence between user information and ARN identifier to the network edge device; and sending the preset correspondence between path or slice and ARN identifier to the network edge device;

[0458] The path or slice includes one of the following:

[0459] SRv6;

[0460] MPLS;

[0461] IPinIP;

[0462] VxLAN;

[0463] GRE;

[0464] GENEVE.

[0465] In some embodiments, the apparatus is configured to:

[0466] The first ARN identifier is allocated to the user edge device based on user information, application information, and network service information.

[0467] In addition, according to at least one embodiment of the present disclosure, the method further includes: managing the life cycle of the first ARN identifier.

[0468] In some embodiments, the apparatus is configured to:

[0469] Perform one of the following operations on the first ARN identifier:

[0470] revocation;

[0471] Report loss;

[0472] reissue;

[0473] aging;

[0474] postpone.

[0475] In actual application, the second sending module 151 can be implemented by a communication interface in an information processing device.

[0476] It should be noted that the information processing device provided in the above embodiments is illustrated only by the division of the above-mentioned program modules when performing information processing. In actual applications, the above-mentioned processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the above-described processing. In addition, the information processing device provided in the above embodiments and the information processing method embodiment are based on the same concept. The specific implementation process is detailed in the method embodiment and is not repeated here.

[0477] The present disclosure also provides a user edge device, as shown in FIG16 , including:

[0478] The first communication interface 161 is capable of exchanging information with other user edge devices;

[0479] The first processor 162 is connected to the first communication interface 161 and is configured to execute the method provided by one or more technical solutions on the user edge device side when running a computer program. The computer program is stored in the first memory 163 .

[0480] It should be noted that the specific processing procedures of the first processor 162 and the first communication interface 161 are detailed in the method embodiment and will not be repeated here.

[0481] In practice, the various components within the customer edge device 160 are coupled together via a bus system 164. It will be appreciated that bus system 164 is used to enable communication between these components. In addition to a data bus, bus system 164 also includes a power bus, a control bus, and a status signal bus. However, for clarity, all of these buses are labeled as bus system 164 in FIG. 16 .

[0482] The first memory 163 in the embodiment of the present disclosure is used to store various types of data to support the operation of the user edge device 160 . Examples of such data include any computer program used to operate on the user edge device 160 .

[0483] The methods disclosed in the above embodiments of the present disclosure can be applied to or implemented by the first processor 162. The first processor 162 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits or software instructions in the first processor 162. The above first processor 162 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The first processor 162 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present disclosure can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium located in the first memory 163. The first processor 162 reads the information in the first memory 163 and, in conjunction with its hardware, completes the steps of the above method.

[0484] The present disclosure also provides a network edge device, as shown in FIG17 , including:

[0485] The second communication interface 171 is capable of exchanging information with other user edge devices;

[0486] The second processor 172 is connected to the second communication interface 171 and is configured to execute the method provided by one or more technical solutions on the network edge device side when running a computer program. The computer program is stored in the second memory 173 .

[0487] It should be noted that the specific processing procedures of the second processor 172 and the second communication interface 171 are detailed in the method embodiment and will not be repeated here.

[0488] In practice, the various components within network edge device 170 are coupled together via bus system 174. It will be appreciated that bus system 174 is used to enable communication between these components. In addition to a data bus, bus system 174 also includes a power bus, a control bus, and a status signal bus. However, for clarity, all of these buses are labeled as bus system 174 in FIG. 17 .

[0489] The second memory 173 in the embodiment of the present disclosure is used to store various types of data to support the operation of the network boundary device 170. Examples of such data include any computer program used to operate on the network boundary device 170.

[0490] The methods disclosed in the above embodiments of the present disclosure can be applied to or implemented by the second processor 172. The second processor 172 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits or software instructions in the second processor 172. The above second processor 172 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The second processor 172 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present disclosure can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium located in the second memory 173. The second processor 172 reads the information in the second memory 173 and, in conjunction with its hardware, completes the steps of the above method.

[0491] The present disclosure also provides a controller, as shown in FIG18 , including:

[0492] The third communication interface 181 is capable of exchanging information with other devices;

[0493] The third processor 182 is connected to the third communication interface 181 and is used to execute the method provided by one or more technical solutions of the controller side when running a computer program. The computer program is stored in the third memory 183.

[0494] It should be noted that the specific processing process of the third processor 182 and the third communication interface 181 is detailed in the method embodiment and will not be repeated here.

[0495] Of course, in actual applications, the various components in controller 180 are coupled together via bus system 184. It will be appreciated that bus system 184 is used to enable communication between these components. In addition to a data bus, bus system 184 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in FIG. 18 , all of these buses are labeled as bus system 184.

[0496] The third memory 183 in the embodiment of the present disclosure is used to store various types of data to support the operation of the controller 180. Examples of such data include any computer programs used to operate on the controller 180.

[0497] The methods disclosed in the above-mentioned embodiments of the present disclosure can be applied to or implemented by the third processor 182. The third processor 182 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above-mentioned method can be completed by hardware integrated logic circuits or software instructions in the third processor 182. The above-mentioned third processor 182 may be a general-purpose third processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The third processor 182 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure. The general-purpose third processor can be a microprocessor or any conventional third processor. The steps of the methods disclosed in the embodiments of the present disclosure can be directly implemented and executed by the hardware decoding third processor, or by a combination of hardware and software modules in the decoding third processor. The software module can be located in a storage medium located in the third memory 183. The third processor 182 reads the information in the third memory 183 and, in conjunction with its hardware, completes the steps of the above-mentioned method.

[0498] In an exemplary embodiment, the user edge device 160, the network edge device 170, and the controller 180 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0499] It can be understood that the memory (first memory 163, second memory 173, third memory 183) of the embodiment of the present disclosure can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache.By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM). The memory described in the embodiments of the present disclosure is intended to include, but is not limited to, these and any other suitable types of memory.

[0500] In an exemplary embodiment, the present disclosure further provides a storage medium, namely, a computer storage medium, specifically, a computer-readable storage medium, such as a memory storing a computer program. The computer program can be executed by the first processor 162 of the user edge device 160 to complete the steps of the user edge device-side method described above. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface mount storage, optical disk, or CD-ROM.

[0501] Illustratively, an embodiment of the present disclosure also provides a computer program product, including a computer program, which can be executed by the first processor 162 of the user edge device 160 to complete the steps of any of the aforementioned methods, or executed by the second processor 172 of the network edge device 170 to complete the steps of any of the aforementioned methods, or executed by the third processor 182 of the controller 180 to complete the steps of any of the aforementioned methods.

[0502] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0503] In addition, the technical solutions described in the embodiments of the present disclosure can be arbitrarily combined without conflict.

[0504] The above description is merely a preferred embodiment of the present disclosure and is not intended to limit the scope of protection of the present disclosure.

Claims

1. An information processing method, applied to a user edge device, comprising: Get the first application response network ARN identifier; The first ARN identifier represents the calling relationship between the application and the network capability and / or the capability exposed by the network to the application; Marking the first Internet Protocol (IP) packet based on the first ARN identifier to generate a second IP packet; Send the second IP message.

2. The method according to claim 1, wherein The marking the first IP packet based on the first ARN identifier includes: Writing the first ARN identifier and the first information into the flow label field and the traffic type field in the header of the first IP packet respectively; The first information is used to indicate whether to convert the original content in the flow label field into the first ARN identifier.

3. The method according to claim 1, wherein The marking the first IP packet based on the first ARN identifier includes: Writing the first ARN identifier into the extension header of the first IP packet; or, The first ARN identifier is written into the source address field in the header of the first IP packet.

4. The method according to claim 1, wherein The obtaining of the first ARN identifier includes: Get the first ARN identifier sent by the controller; The first ARN identifier is allocated by the controller to the user edge device based on user information, application information and network service information.

5. The method according to any one of claims 1 to 4, wherein: The sending of the second IP message includes: Carrying the first user information in the second IP message; Send the second IP message.

6. The method according to claim 1, wherein The obtaining of the first ARN identifier includes: Get the first ARN identifier sent by the Dynamic Host Configuration Protocol DHCP server.

7. The method according to any one of claims 1 to 4, wherein: The sending of the second IP message includes: Adding an outer IPv6 header to the second IP packet, and carrying the first user information in the outer IPv6 header; The second IP packet with the outer IPv6 header added is sent.

8. The method according to claim 1, wherein The marking the first IP packet based on the first ARN identifier includes: Adding an outer IPv6 header to the first message; The first ARN identifier is carried in the destination options header DOH of the outer IPv6 header.

9. The method according to claim 1, wherein The method also applies to application programs.

10. The method according to claim 9, wherein: The method further comprises: Carrying the first ARN identifier in the hop-by-hop options header HBH of the third message to generate a fourth message; The fourth message is sent.

11. An information processing method, applied to a network edge device, comprising: Receive a second IP packet; in, The second IP packet is obtained by the user edge device obtaining the first ARN identifier and marking the first IP packet based on the first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

12. The method according to claim 11, wherein The method further comprises: Parsing the second IP packet to obtain the first ARN identifier; Verify the legitimacy of the first ARN identifier according to a preset data table to obtain a verification result; the preset data table stores a preset correspondence between user information and ARN identifiers; When the verification result indicates that the first ARN identifier is legal, the second IP packet is mapped to a corresponding path or slice based on the first ARN identifier.

13. The method according to claim 12, wherein: The method further comprises: If the verification result indicates that the first ARN identifier is illegal, perform a first operation; The first operation includes one of the following: Ignore the first ARN identifier carried by the second IP packet or discard the second IP packet; Resetting the value of the first ARN identifier; Map the second IP packet to the default path or slice corresponding to the packet that does not carry the ARN identifier.

14. The method according to claim 12, wherein: The verifying the legitimacy of the first ARN identifier according to the preset data table includes: Parsing the second IP message to obtain the first user information; Searching the preset data table for a correspondence between the first user information and the first ARN identifier; If a correspondence between the first user information and the first ARN identifier is found in the preset data table, it is determined that the first ARN identifier is legal.

15. The method according to claim 12, wherein: The mapping of the second IP packet to a corresponding path or slice based on the first ARN identifier includes: If the first ARN identifier is legal, determine the first path or first slice corresponding to the first ARN identifier according to the preset correspondence between the path or slice and the ARN identifier; map the second IP packet to the first path or the first slice; The path or slice includes one of the following: Policy-based IPv6 Segment Routing (SRv6); Multi-protocol Label Switching (MPLS); Internet Layer 3 protocol IPinIP; Virtual extended local area network VxLAN; Generic Routing Encapsulation Protocol GRE; Geneve, a general network virtualization package.

16. An information processing method, applied to a controller, comprising: Sending a first ARN identifier to a user edge device; The first ARN identifier represents the calling relationship between the application and the network capability and / or the capability exposed by the network to the application; The first ARN identifier is used by the user edge device to mark the first IP packet, generate a second IP packet, and send the second IP packet.

17. The method according to claim 16, wherein The method further comprises: Sending the preset correspondence between user information and ARN identifier to the network edge device; and sending the preset correspondence between path or slice and ARN identifier to the network edge device; The path or slice includes one of the following: SRv6; MPLS; IPinIP; VxLAN; GRE; GENEVE.

18. The method according to claim 16, wherein The method further comprises: The first ARN identifier is allocated to the user edge device based on user information, application information, and network service information.

19. The method according to claim 16, wherein The method further comprises: Manage the life cycle of the first ARN identifier.

20. The method according to claim 19, wherein The managing the lifecycle of the first ARN identifier includes: Perform one of the following operations on the first ARN identifier: revocation; Report loss; reissue; aging; postpone.

21. An information processing device comprising: An acquisition module configured to acquire a first ARN identifier; The first ARN identifier represents the calling relationship between the application and the network capability and / or the capability exposed by the network to the application; A processing module configured to mark the first IP packet based on the first ARN identifier to generate a second IP packet; The first sending module is configured to send the second IP message.

22. An information processing device comprising: A receiving module configured to receive a second IP message; in, The second IP packet is obtained by the user edge device obtaining the first ARN identifier and marking the first IP packet based on the first ARN identifier; the first ARN identifier represents the calling relationship between the application and the network capability and / or the capability opened by the network to the application.

23. An information processing device comprising: A second sending module is configured to send the first ARN identifier to the user edge device; The first ARN identifier represents the calling relationship between the application and the network capability and / or the capability exposed by the network to the application; The first ARN identifier is used by the user edge device to mark the first IP packet, generate a second IP packet, and send the second IP packet.

24. A user edge device comprising a processor and a memory for storing a computer program capable of running on the processor, in, When the processor is used to run the computer program, the processor performs the steps of the method according to any one of claims 1 to 10.

25. A network edge device comprising a processor and a memory for storing a computer program capable of being executed on the processor, in, When the processor is used to run the computer program, the processor performs the steps of the method according to any one of claims 11 to 15.

26. A controller comprising a processor and a memory for storing a computer program capable of being executed on the processor, in, When the processor is used to run the computer program, the processor performs the steps of the method according to any one of claims 16 to 20.

27. A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 10, or the steps of the method described in any one of claims 11 to 15, or the steps of the method described in any one of claims 16 to 20.

28. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the method according to any one of claims 1 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 20.

Citation Information

Patent Citations

  • Message transmission method and device, related equipment and storage medium

    CN115334589A

  • SRv6 message processing method and device, communication equipment and storage medium

    CN116846862A

  • Information processing method and device, equipment, storage medium and computer program product

    CN118802068A

  • Transporting A Multi-Transport Network Context-Identifier (MTNC-ID) Across Multiple Domains

    US20210037410A1

  • Packet sending method, device, and system

    WO2022110535A1