Communication system, communication method and enhanced gateway
By setting up the home gateway, enhanced gateway and edge cloud devices in the same broadcast domain, the enhanced gateway forwards traffic based on the MAC address, solving the problem of Internet connection interruption caused by edge cloud failure, and enabling the home gateway's Internet traffic to go directly to the Internet, improving the reliability and efficiency of the communication system.
Patent Information
- Application Number
- PCT/CN2025/084761
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-02
- Filing Date
- 2025-03-25
- Publication Date
- 2025-10-09
AI Technical Summary
Home intranet users cannot connect to the Internet normally when the edge cloud fails, resulting in unreliable Internet traffic.
The home gateway, enhanced gateway, and edge cloud device are set in the same broadcast domain. The enhanced gateway determines the forwarding direction based on the destination MAC address of the service message and sends the traffic directly to the Internet without passing through the edge cloud, so that the home gateway's Internet traffic does not need to be connected to the cloud first and then to the Internet.
Even if the edge cloud device fails, the home gateway's Internet traffic can still connect to the Internet normally, improving the reliability and communication efficiency of Internet traffic.
Smart Images

Figure CN2025084761_09102025_PF_FP_ABST
Abstract
Description
A communication system, communication method and enhanced gateway
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on April 2, 2024, with application number 202410397768.0 and application name “A Communication System, Communication Method and Enhanced Gateway”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a communication system, a communication method and an enhanced gateway. Background Art
[0003] The home gateway will form the home intranet into a two-layer or three-layer network, which is isolated from the Internet. When users in the home intranet access the Internet, they connect to the Internet and other external networks through the home gateway's wide area network (WAN) port. The WAN port is configured with an Internet Protocol (IP) address connected to the external network. In order to improve the user experience of users in the home intranet, the home gateway is generally set to bridge mode, so that users in the home intranet can be connected to the edge cloud. The edge cloud is deployed with an access gateway and a service gateway. Since the bridge mode connects the home gateway's WAN port to the edge cloud, all traffic in the home intranet needs to pass through the gateway in the edge cloud before it can be connected to the Internet and other external networks. Furthermore, all Internet traffic of users in the home intranet is connected to the Internet through the edge cloud, that is, users need to access the cloud first and then go online. Therefore, when the edge cloud fails, users cannot connect to the Internet normally. Summary of the Invention
[0004] The present application provides a communication system, a communication method and an enhanced gateway. Users do not need to enter the cloud first and then go online. This solves the problem that users in the home intranet cannot connect to the Internet normally due to edge cloud failure, and improves the reliability of Internet traffic.
[0005] In the first aspect, the present application provides a communication system. The communication system includes: a first home gateway, an enhanced gateway and a first edge cloud device located in the same broadcast domain. The first home gateway includes: a first WAN port and a second WAN port. The first WAN port is used to: send a first business message to the Internet, and the second WAN port is used to: send a second business message to the enhanced gateway. The aforementioned enhanced gateway is used to: if the destination media access control (MAC) address in the second business message is the MAC address of the first edge cloud device, send the second business message to the first edge cloud device. If the destination MAC address in the second business message is the MAC address of the first bridge interface, send the second business message to the Internet.
[0006] In the first aspect of the present application, the first home gateway, the enhanced gateway and the first edge cloud device are set in a broadcast domain, and the broadcast messages in the same broadcast domain can reach each host in the broadcast domain, which is beneficial to improving the communication efficiency in the broadcast domain. Moreover, since the enhanced gateway can determine the forwarding direction of the Internet traffic of the first home gateway based on the destination MAC address in the service message, the service message is sent to the Internet only when the destination MAC address is the MAC address of the first bridge interface. In the process of forwarding the service message by the enhanced gateway, the service message with the destination MAC address being the MAC address of the first bridge interface will not be sent to the first edge cloud device, but will be sent directly to the Internet, that is: the Internet traffic of the first home gateway does not need to be connected to the cloud first and then go online. Therefore, even when the first edge cloud device fails, the Internet traffic of the first home gateway can also be connected to the Internet normally.
[0007] In addition, since the first home gateway and the first edge cloud device are in the same broadcast domain, when the first home gateway wants to use the cloud service provided by the first edge cloud device, the first home gateway can communicate with the first edge cloud device according to the destination MAC address corresponding to the first edge cloud device, thereby reducing the Internet dial-up process that the first home gateway needs to perform to access the cloud.
[0008] In conjunction with the communication system provided in the first aspect, in an optional implementation, a Layer 2 tunnel is established between the enhanced gateway and the first home gateway, and the Layer 2 tunnel is used to transmit the second service message. The enhanced gateway and the first home gateway are in the same broadcast domain, which enables the Layer 2 tunnel to be used to transmit service messages between the enhanced gateway and the first home gateway, thereby improving communication efficiency between devices within the same broadcast domain.
[0009] In combination with the communication system provided in the first aspect, in an optional implementation, the communication system further includes: a second edge cloud device that is not in the broadcast domain. The above-mentioned enhanced gateway is also used to: receive a fifth service message from the first home gateway, and if the destination IP address of the fifth service message is the IP address of the second edge cloud device, send the fifth service message to the second edge cloud device. The communication system can establish a point-to-point communication connection between the enhanced gateway in the broadcast domain and the second edge cloud device located outside the broadcast domain, so that the home gateway or host located in the broadcast domain can realize the communication of service messages based on the point-to-point communication connection.
[0010] In conjunction with the communication system provided in the first aspect, in an optional implementation, the communication system further includes: a second home gateway located in the broadcast domain. The second home gateway includes: a third WAN port and a fourth WAN port. The third WAN port is used to send a third service message to the Internet; the fourth WAN port is used to send a fourth service message to the enhanced gateway. In the present application, the broadcast domain may also include other home gateways (first home gateway), which allows hosts in the broadcast domain to connect to the Internet based on different home gateways, thereby avoiding the problem of hosts being unable to access the Internet due to a single home gateway failure, which is conducive to improving the stability of the communication system.
[0011] In the second aspect, the present application provides a communication method. The communication method is applied to a communication system including a home gateway and an enhanced gateway, wherein the first WAN port of the home gateway is connected to the Internet, the second WAN port of the home gateway is connected to the enhanced gateway, the enhanced gateway is connected to the first edge cloud device, and is connected to the Internet through the first bridge interface, and the home gateway, the enhanced gateway and the first edge cloud device are in the same broadcast domain. The communication method provided by the present application includes: the home gateway sends a first business message to the Internet through the first WAN port, and the home gateway sends a second business message to the enhanced gateway through the second WAN port. And, if the destination MAC address in the second business message is the MAC address of the first edge cloud device, the enhanced gateway sends the second business message to the first edge cloud device; if the destination MAC address in the second business message is the MAC address of the first bridge interface, the enhanced gateway sends the second business message to the Internet.
[0012] In the second aspect of the present application, the first home gateway, the enhanced gateway and the first edge cloud device are set in a broadcast domain, and the broadcast messages in the same broadcast domain can reach each host in the broadcast domain, which is beneficial to improving the communication efficiency in the broadcast domain. Since the enhanced gateway can determine the forwarding direction of the Internet traffic of the first home gateway according to the destination MAC address in the service message, the service message is sent to the Internet only when the destination MAC address is the MAC address of the first bridge interface. That is to say, in the process of forwarding the service message by the enhanced gateway, the service message with the destination MAC address being the MAC address of the first bridge interface will not be sent to the first edge cloud device, but will be sent directly to the Internet, that is: the Internet traffic of the first home gateway does not need to be connected to the cloud first and then go online. Therefore, even when the first edge cloud device fails, the Internet traffic of the first home gateway can also be connected to the Internet normally.
[0013] In conjunction with the communication method provided in the second aspect, in an optional implementation, before the enhanced gateway sends the second service message to the internet, the communication method provided in this application further includes: the enhanced gateway performing network address translation (NAT) on the second service message sent by the home gateway. NAT refers to the process of translating the IP address in the header of a service message into another IP address, and is primarily used to enable an internal network (private IP address) to access an external network (public IP address).
[0014] In conjunction with the communication method provided in the second aspect, in an optional implementation, the communication system further includes: a second edge cloud device that is not in the broadcast domain, the enhanced gateway being connected to the second edge cloud device. The communication method provided in this application further includes: the enhanced gateway receiving a fifth service message from the home gateway. Furthermore, if the destination IP address in the fifth service message is the IP address of the second edge cloud device, the enhanced gateway sending the fifth service message to the second edge cloud device.
[0015] In conjunction with the communication method provided in the second aspect, in an optional implementation, the communication system provided in this application further includes: a second home gateway located in the broadcast domain, the third WAN port of the second home gateway being connected to the Internet, and the fourth WAN port of the second home gateway being connected to the enhanced gateway. The communication method provided in this application further includes: the second home gateway sending a third service message to the Internet via the third WAN port; the second home gateway sending a fourth service message to the enhanced gateway via the fourth WAN port. Furthermore, if the destination MAC address in the fourth service message is the MAC address of the first edge cloud device, the enhanced gateway sends the fourth service message to the first edge cloud device; if the destination MAC address in the fourth service message is the MAC address of the first bridge interface, the enhanced gateway sends the fourth service message to the Internet.
[0016] In conjunction with the communication method provided in the second aspect, in an optional implementation, the first WAN port is connected to the second bridge interface, the IP address of the first bridge interface is the same as the IP address of the second bridge interface, and the MAC address of the first bridge interface is the same as the MAC address of the second bridge interface. The communication method provided in this application further includes: if the first bridge interface fails, the home gateway deletes the MAC address of the first bridge interface configured for the home gateway. If the second bridge interface fails, the enhanced gateway deletes the MAC address of the second bridge interface configured for the enhanced gateway.
[0017] In conjunction with the communication method provided in the second aspect, in an optional implementation, the first WAN port is connected to the second bridge interface, the IP address of the first bridge interface is the same as the IP address of the second bridge interface, and the MAC address of the first bridge interface is different from the MAC address of the second bridge interface. The communication method provided in this application also includes: if the first bridge interface fails, the first home gateway sends a first address resolution protocol (ARP) message to the host in the broadcast domain, the first ARP message carries the MAC address of the second bridge interface. If the second bridge interface fails, the enhanced gateway sends a second ARP message to the host in the broadcast domain, the second ARP message carries the MAC address of the first bridge interface.
[0018] In combination with the communication method provided in the second aspect, in an optional implementation, the first WAN port is connected to the second bridge interface, the IP address of the first bridge interface is the same as the IP address of the second bridge interface, and the MAC address of the first bridge interface is different from the MAC address of the second bridge interface. The communication method provided in this application also includes: if the first bridge interface fails, the enhanced gateway sends a first policy message to the host in the broadcast domain, the first policy message carries: the MAC address of the second bridge interface, and the first policy message indicates: the host's Internet traffic is forwarded through the second bridge interface. If the second bridge interface fails, the first home gateway sends a second policy message to the host in the broadcast domain, the second policy message carries: the MAC address of the first bridge interface, and the second policy message indicates: the host's Internet traffic is forwarded through the first bridge interface.
[0019] In combination with the communication method provided in the second aspect, in an optional implementation, the first WAN port is connected to the second bridge interface, the IP address of the first bridge interface is different from the IP address of the second bridge interface, and the MAC address of the first bridge interface is different from the MAC address of the second bridge interface. The communication method provided in this application also includes: if the connection between the second bridge interface and the Internet is interrupted, the home gateway sends a first access control list (ACL) to the host in the broadcast domain, and the first ACL is used to indicate: modify the MAC address of the second bridge interface in the service message to the MAC address of the first bridge interface; if the second bridge interface restores the connection with the Internet, the home gateway revokes the first ACL.
[0020] Alternatively, if the connection between the first bridge interface and the Internet is interrupted, the enhanced gateway sends a second ACL to the host in the broadcast domain. The second ACL is used to indicate: modify the MAC address of the first bridge interface in the service message to the MAC address of the second bridge interface; if the first bridge interface restores the connection with the Internet, the enhanced gateway revokes the second ACL.
[0021] On the third aspect, the present application provides another communication method. The communication method is applied to an enhanced gateway, which is connected to a first edge cloud device and a first home gateway. The enhanced gateway is connected to the Internet through a first bridge interface, and the home gateway, the enhanced gateway and the edge cloud device are located in the same broadcast domain. The communication method provided by the present application includes: the enhanced gateway receives a second service message from the first home gateway. If the destination media access control MAC address in the second service message is the MAC address of the first edge cloud device, the enhanced gateway sends the second service message to the first edge cloud device; if the destination MAC address in the second service message is: the MAC address of the first bridge interface, the enhanced gateway sends the second service message to the Internet.
[0022] In conjunction with the communication method provided in the third aspect, in an optional implementation, the communication method provided in this application further includes: the enhanced gateway receiving a sixth service message from the first edge cloud device. If the destination MAC address in the sixth service message is the MAC address of the home gateway, the enhanced gateway sends the sixth service message to the home gateway; if the destination MAC address in the sixth service message is the MAC address of the first bridge interface, the enhanced gateway sends the sixth service message to the Internet.
[0023] In conjunction with the communication method provided in the third aspect, in an optional implementation, the communication method provided in this application further includes: the enhanced gateway receiving multiple service messages from the Internet. The enhanced gateway sends a seventh service message from the multiple service messages to the first edge cloud device, where the seventh service message carries the IP address of the first edge cloud device; and / or the enhanced gateway sends an eighth service message from the multiple service messages to the home gateway, where the eighth service message carries the IP address of the home gateway.
[0024] In a fourth aspect, the present application provides an enhanced gateway. The enhanced gateway includes a processor and a transceiver. The transceiver is used to send or receive service messages, and the transceiver and processor collaborate to implement the method steps implemented by the enhanced gateway in any optional implementation of the second or third aspects.
[0025] Regarding the beneficial effects of the fourth aspect, reference may be made to the description of any optional implementation in the first to third aspects, which will not be repeated here. Based on the implementations provided in the above aspects, this application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] FIG1 is a schematic diagram of the structure of a metropolitan area network provided by this application;
[0027] FIG2 is a structural diagram of a communication system provided by the present application;
[0028] FIG3 is a second structural diagram of a communication system provided by the present application;
[0029] FIG4 is a third structural diagram of a communication system provided by the present application;
[0030] FIG5 is a flow chart of a communication method provided by the present application;
[0031] FIG6 is a second flow chart of a communication method provided by the present application;
[0032] FIG7A is a flow chart of a first traffic forwarding method provided in this application;
[0033] FIG7B is a flow chart of a second traffic forwarding method provided in this application;
[0034] FIG7C is a flow chart of a third traffic forwarding method provided by the present application;
[0035] FIG7D is a flow chart of a fourth traffic forwarding method provided in this application;
[0036] FIG7E is a schematic diagram of the structure of a service layer forwarding model provided by the present application;
[0037] FIG8A is a structural diagram 1 of the gateway deployment design provided in this application;
[0038] FIG8B is a second structural diagram of the gateway deployment design provided in this application;
[0039] FIG8C is a third structural diagram of the gateway deployment design provided in this application;
[0040] FIG8D is a fourth structural diagram of the gateway deployment design provided in this application;
[0041] FIG8E is a fifth structural diagram of the gateway deployment design provided in this application;
[0042] FIG9 is a structural diagram of a communication pipeline provided by the present application;
[0043] FIG10 is a schematic diagram of the structure of the ECGW components and ECGW cluster provided in this application;
[0044] FIG11 is a second structural diagram of a communication pipeline provided by the present application;
[0045] FIG12 is a third structural diagram of a communication pipeline provided by the present application;
[0046] FIG13 is a fourth structural diagram of a communication pipeline provided by the present application;
[0047] FIG14 is a fifth structural diagram of a communication pipeline provided by the present application;
[0048] FIG15 is a sixth structural diagram of a communication pipeline provided by the present application;
[0049] FIG16 is a seventh structural diagram of a communication pipeline provided by the present application;
[0050] FIG17 is a structural diagram eight of a communication pipeline provided by the present application;
[0051] FIG18 is a flow chart of an access service provided by this application;
[0052] FIG19 is a schematic diagram of the structure of an SL metropolitan area home bandwidth service model provided by this application;
[0053] FIG20 is a schematic structural diagram of a communication device provided by the present application;
[0054] FIG21 is a schematic structural diagram of a home gateway provided by this application;
[0055] FIG22 is a schematic diagram of the structure of an enhanced gateway provided in this application. DETAILED DESCRIPTION
[0056] In the present application, the first home gateway, the enhanced gateway and the first edge cloud device are set in a broadcast domain, and the broadcast messages in the same broadcast domain can reach each host in the broadcast domain, which is beneficial to improving the communication efficiency in the broadcast domain. Moreover, since the enhanced gateway can determine the forwarding direction of the Internet traffic of the first home gateway according to the destination MAC address in the service message, the service message is sent to the Internet only when the destination MAC address is the MAC address of the second bridge interface. In the process of forwarding the service message by the enhanced gateway, the service message with the destination MAC address being the MAC address of the second bridge interface will not be sent to the first edge cloud device, but will be sent directly to the Internet, that is: the Internet traffic of the first home gateway does not need to access the cloud first and then go online. Therefore, even when the first edge cloud device fails, the Internet traffic of the first home gateway can also be connected to the Internet normally.
[0057] In addition, since the first home gateway and the first edge cloud device are in the same broadcast domain, when the first home gateway wants to use the cloud service provided by the first edge cloud device, the first home gateway can communicate with the first edge cloud device according to the destination MAC address corresponding to the first edge cloud device, thereby reducing the Internet dial-up process that the first home gateway needs to perform to access the cloud.
[0058] This application can be applied not only to existing wireless communication technologies, optical communication technologies, and edge cloud scenarios, but also to future wireless communication technologies, optical communication technologies, and edge cloud scenarios. The terms used in the implementation methods of this application are only used to explain the specific embodiments of this application and are not intended to limit this application. The following is a brief introduction to some concepts that may be involved in this application.
[0059] Cloud: An abstraction of the Internet and the underlying infrastructure.
[0060] Edge cloud: A small-scale cloud data center distributed at the edge of the network that provides real-time data processing, analysis and decision-making.
[0061] Internet: also known as the international network, refers to a huge network connected by networks. These networks are connected by a set of common protocols to form a logically single huge international network.
[0062] Wide Area Network (WAN): Also known as an extranet or public network, a WAN is a long-distance network that connects computers in different local area networks (LANs) or metropolitan area networks (MANs). WANs typically span a large physical area, ranging from tens to thousands of kilometers. A WAN is not the same as the Internet.
[0063] Local Area Network (LAN): A local area network (LAN) typically covers a radius of several thousand meters. Its ease of installation, cost-effectiveness, and ease of expansion make it widely used in offices of all types. LANs enable file management, application software sharing, and printer sharing. Maintaining LAN security effectively protects data and ensures the smooth and stable operation of the LAN.
[0064] Virtual LAN (VLAN): A VLAN is a logical group of devices and users that are not restricted by physical location and can be organized based on factors such as function, department, and application. Communication between them is as if they were on the same network segment, hence the name VLAN. Switch ports have two VLAN attributes: a VLAN identification (ID) and a VLAN tag (TAG). These attributes correspond to setting VLAN tags on data packets (or service messages) and allowing data packets (or service messages) with VLAN tags to pass through. Ports with different VLAN IDs can form VLANs by allowing VLAN tags to pass through.
[0065] Stacked virtual LAN (selective VLAN, SVLAN): also known as outer VLAN, is a VLAN extension technology based on QinQ (802.1Q-in-802.1Q). By stacking two 802.1Q packet headers in the Ethernet frame, it effectively expands the number of VLANs to a maximum of 4096 × 4096.
[0066] Customer VLAN (CVLAN): Defined by 802.1ad, a QinQ tag is added to a VLAN to create a double-tagged VLAN. The outer VLAN is the SVLAN, and the inner VLAN is the CVLAN.
[0067] Gateway: Also known as a network connector or protocol converter, a gateway implements network interconnection above the network layer. It is a complex network interconnection device used only to connect two networks with different high-level protocols. Gateways can be used to interconnect both wide area networks and local area networks. A gateway is a computer system or device that performs a translation task. Used between systems with different communication protocols, data formats, languages, or even completely different architectures, a gateway acts as a translator. Unlike a bridge, which simply transmits information, a gateway repackages the received information to suit the needs of the destination system.
[0068] Dynamic Host Configuration Protocol (DHCP) protocol: DHCP allows a server to dynamically assign IP addresses and configuration information to a client or host.
[0069] Broadband remote access server (BRAS): A BRAS routes traffic to a digital subscriber line access multiplexer (DSLAM) within an internet service provider's network. For example, the BRAS is located within the service provider's core network and aggregates user sessions within the access network.
[0070] The following is an illustrative description of the scenarios in which the embodiments of the present application can be applied, with reference to the accompanying drawings.
[0071] As shown in Figure 1, Figure 1 is a schematic diagram of the structure of a metropolitan area network provided by this application. The metropolitan area network 100 includes: an optical network terminal (ONT) 101, an optical line terminal (OLT) 102, an aggregation network 103, a BRAS 104, a core router (CR) 105 and an edge data center (EDC) 106. For example, ONT 101 refers to the last unit of fiber to the home (FTTH), commonly known as "optical modem", which is used for end users. OLT 102 is located at a location provided by the operator network (such as a building corridor, a computer room, a dedicated communication box on the roadside, etc.). The aggregation network 103 refers to a communication network including one or more routing switches. BRAS 104 is used to connect routing traffic to the Internet service provider's network over a digital subscriber line, such as EDC 106 in Figure 1.
[0072] The metropolitan area network (MAN) shown in Figure 1 is a typical north-south tree-like structure. OLT 102 converges through layers of traffic to the MAN egress (CR 105). In most cases, OLT 102 uses SVLAN+CVLAN (hereinafter referred to as S+C) to tag specific services for specific users. Aggregation network 103 ignores the inner CVLAN and simply forwards OLT 102 traffic to BRAS 104 based on the SVLAN. This means that the S+C packets on a single BRAS 104 port must be unique. After terminating the Point-to-Point Protocol over Ethernet (PPPOE) protocol, BRAS 104 forwards the traffic to EDC 106 via CR 105.
[0073] With the continuous development of technology, based on the traditional metropolitan area network shown in Figure 1, this application provides a new communication system, as shown in Figure 2, which is a structural diagram of a communication system provided by this application. The communication system 200 includes: ONT 201, edge compute gateway (ECGW) 202, edge cloud 203, transmission network 204 and Internet 205.
[0074] In Figure 2, ONT 201 is merely provided for illustration of this embodiment and should not be construed as indicating that communication system 200 includes only one ONT. Communication system 200 may also include a greater number of ONTs. An ONT may refer to an optical modem or other optical network device connected to communication system 200, and this application is not limited thereto. In this document, ONT 201 may also be referred to as a home gateway. In addition to providing ordinary Internet access services to users, the home gateway (ONT 201) also provides a Layer 2 dedicated line to edge cloud 203, extending all the way to ECGW 202 deployed within the edge cloud.
[0075] As shown in Figure 2, ONT 201 is configured with two WAN ports: WAN1 and WAN2. In Figure 2 (1), WAN1 is the existing Internet access channel. Internet traffic from the home network established through ONT 201 can use this channel provided by WAN1 to directly access Internet 205 and access services provided by Internet 205. In Figure 2 (2), WAN2 is the bridge channel between ONT 201 and edge cloud 203 and the Internet. The home network established through ONT 201 accesses edge cloud 203 through this channel provided by WAN2, i.e., the aforementioned Layer 2-based dedicated line to edge cloud 203. This Layer 2 dedicated line is also called a Layer 2 tunnel between ONT 201 and edge cloud 203. This Layer 2 tunnel can be used to transmit service packets between ECGW 202 and edge cloud 203.
[0076] ECGW 202 may also be referred to as an enhanced gateway, a service gateway, a converged edge gateway, an edge gateway or other names. The network enhanced residential gateway (NERG) instance on ECGW 202 is also configured with an Internet WAN port, which is connected to the user plane (UP) of the BRAS. The Internet traffic on the cloud service on the edge cloud goes through the channel provided by the Internet WAN port. In this embodiment, ECGW 202 provides a three-way diversion function, namely, traffic diversion to users, to edge clouds, and to external networks. For example, ECGW 202 provides users with a cloud-based service access experience based on layer 2 or layer 3 to the edge cloud 203, and ECGW 202 provides users with a fast access service to cloud services to external networks (such as the Internet 205).
[0077] In this embodiment, the return traffic diversion of the edge cloud 203 at the ECGW 202 includes: the LAN traffic from the edge cloud 203 to the home intranet returns to the ONT 201, and the Internet traffic from the edge cloud 203 to the Internet 205 goes through the PPPOE export channel (that is, the channel provided by the Internet WAN port of the ECGW 202).
[0078] In this embodiment, the return traffic of the Internet 205 at the ECGW 202 includes traffic to the edge cloud 203 (such as Internet traffic of a cloud computer) and traffic to the home intranet.
[0079] Regarding the Internet access channel provided by WAN 1 in ONT 201, and the Internet access channel provided by WAN 2 in ONT 201 and ECGW WAN (Internet access WAN port of ECGW 202), in order to improve the reliability of the traffic between ONT 201 and Internet 205, the embodiment of the present application provides a feasible example: WAN 1 and ECGW WAN in ONT 201 are configured in active-active mode. The active-active mode means that the Internet exits of ONT 201 and ECGW 202 are both active (for example, using two PPPOE domain names), home Internet traffic goes through ONT WAN 1, and business Internet access in the edge cloud goes through ECGW WAN (ONT 201 can also access the Internet through WAN 2).
[0080] In another feasible example, WAN 1 and the ECGW WAN in ONT 201 are configured in active / standby mode. This active / standby mode means that if WAN 1 of ONT 201 is not working, all Internet traffic will flow through the ECGW WAN by default. Only when the ECGW WAN fails will the Internet traffic of ONT 201 be switched back to WAN 1 of ONT 201.
[0081] The above two feasible examples are merely optional methods provided in this embodiment and should not be understood as limiting the present application.
[0082] As shown in Figure 2, the transmission network 204 includes a leaf-spine network and a core router (CR). The leaf-spine network includes a spine switch (Spine), an access-leaf switch (A-Leaf), and a service-leaf switch (S-Leaf). For example, the A-Leaf is used to connect the traffic transmitted by the ONT 201 via the OLT to the Spine, one S-Leaf is used to connect the Internet traffic of the ECGW WAN to the Spine, and another S-Leaf is used to connect the Internet traffic of the BRAS-UP to the Spine. The Spine is used to transmit the traffic aggregated by multiple channels to the CR, and the CR sends the traffic to the Internet 205.
[0083] Based on Figure 2, the present embodiment introduces another home intranet (secondary home intranet) in addition to the home intranet supported by ONT 201 to further illustrate the communication system provided by the present embodiment, as shown in Figure 3. Figure 3 is a second structural diagram of a communication system provided by the present application. The communication system 200 includes ONT 201a, ONT 201b, ECGW 202, edge cloud 203, and the Internet 205.
[0084] ONT 201a and ONT 201b use the same user identifier. That is, the primary home intranet supported by ONT 201a and the secondary home intranet supported by ONT 201b can be considered as different websites used by the same user. In some cases, ONT 201a is also called a first home gateway or a primary home gateway, and ONT 201b is also called a second home gateway or a secondary home gateway.
[0085] Compared to Figure 2 , the edge cloud 203 included in the communication system 200 shown in Figure 3 includes L2 cloud services and L3 cloud services. The L3 cloud services and the L2 cloud services belong to different broadcast domains (bridge domains, BD).
[0086] Among them, the device that provides hardware support for L2 cloud services is the first edge cloud device 2031, and the device that provides hardware support for L3 cloud services is the second edge cloud device 2032.
[0087] In FIG3 , ECGW 202 accesses Internet 205 through BR0 gateway, ONT 201a accesses Internet 205 through BR1 gateway, and ONT 201b accesses Internet 205 through BR2 gateway.
[0088] In some feasible scenarios, the BR0 gateway is also called the first bridge interface or first gateway interface used by ECGW 202 to connect to the Internet, the BR1 gateway is also called the second bridge interface or second gateway interface used by ONT 201a to connect to the Internet, and the BR2 gateway is also called the third bridge interface or third gateway interface used by ONT 201b to connect to the Internet.
[0089] From the user service layer perspective, the communication system 200 shown in FIG3 has the following characteristics.
[0090] Feature 1: The primary home intranet, secondary home intranet, and edge cloud L2 cloud services are within the same broadcast domain (BD). Different devices within the BD use different addresses within the same network segment. In this embodiment, the network consisting of the primary home intranet, secondary home intranet, and edge cloud L2 cloud services is also called a large Layer 2 network.
[0091] For example, for services such as family broadband and studio broadband, the communication system 200 shown in Figure 3 can be used to implement multi-site Layer 2 networking, thereby enabling multiple physical houses under one user name and L2 services in the edge cloud to be in the same broadcast domain and use the same network segment.
[0092] Feature 2: A local area network consisting of multiple user sites and L2 cloud services supports multiple L3 cloud services. The BR0 gateway can route to the internet and L3 cloud services in the edge cloud 203. Hosts on the ONTs in each physical building can also be routed to the internet via the BR1 or BR2 gateways. In some optional scenarios, the BR0 gateway can also be referred to as NERG.BR0, the BR1 gateway as ONT.BR1, and the BR2 gateway as ONT.BR2.
[0093] Feature 3: A single user's large LAN uses private addresses. Therefore, all gateways (BR0, BR1, and BR2) must perform NAT or Network Address Port Translation (NAPT) on service packets going out the Internet. To ensure independent address planning for large Layer 2 networking and Layer 3 cloud services, ECGW 202 also needs to perform NAT or NAPT on service packets accessing Layer 3 cloud services.
[0094] For example, NAT is the process of translating the IP address in the header of a service message into another IP address. It is mainly used to enable internal networks (private IP addresses) to access external networks (public IP addresses). NAPT can hide small and medium-sized networks behind a legitimate IP address and map the internal connection to a single IP address on the external network.
[0095] Figures 2 and 3 above are merely examples of the communication systems provided in the embodiments of the present application and should not be construed as limiting the present application. Based on the communication systems shown in Figures 2 and 3, the following illustrative examples illustrate scenarios in which the communication methods provided in the present application may be applied. Figure 4 is a third structural diagram of a communication system provided in the present application. The communication system includes: an ONT 401, a NERG 402, a primary home intranet 403, a secondary home intranet 404, an L2 cloud service, an L3 cloud service, and the Internet.
[0096] Among them, NERG is an instance of a user's edge computing gateway. The instance can be a virtual device used to implement hardware functions, and the virtual device is also implemented by hardware. Exemplarily, an edge computing gateway (ECGW) component may include one or more NERG instances, such as an ECGW component containing 4K~8K NERG instances. The specific implementation of other components in the communication system can be referred to the description of Figure 2 or Figure 3 above, and will not be repeated here.
[0097] Please refer to Figure 4. The connections mentioned below are all service-level connections: such as L2 native ETH, L2 S+C, IP over Ethernet (IPOE), PPPOE sessions, etc. A single user has 7 service-level connections.
[0098] ①. The LAN interface (ETH, WIFI) of ONT 401 is connected to devices on the home network.
[0099] ②. The ONT.WAN1 interface is the Internet exit of the home network. It connects to the BRAS through an L3 session (PPPoE / IPOE) and indirectly connects to the Internet.
[0100] ③. The ONT.WAN2 interface L2 cloud service connects to the NERG instance (NERG 402).
[0101] ④. NERG.WAN1 is the Internet exit of the user LAN on the edge cloud. It is connected to BRAS through an L3 session (PPPOE / IPOE) and indirectly connected to the Internet.
[0102] ⑤. NERG.WAN2 connects to L2 cloud service.
[0103] ⑥. NERG.WAN3 connects to the L3 cloud service via an L3 session. For example, NERG 402 can establish an L3 session with the L3 cloud service via PPPoE, IP0E, or virtual routing and forwarding (VRF).
[0104] ⑦. The NERG.LAN2 interface is connected to another site of the user (secondary home intranet 404).
[0105] Because each user's LAN is isolated E2E (end to end), the same plan can be used for each user's LAN address. When the user eventually modifies the address segment of the user's intranet (for example, changing the default 192.168.16.1 / 24 to 192.168.0.1 / 24), it is also recommended to modify the L2 cloud service and secondary site (secondary home intranet 404) address segments according to the same offset. The address planning suggestions are shown in Table 1 below.
[0106] Table 1 Business layer address planning
[0107] In some feasible examples, L2 cloud service is also called L2 cloud business or L2 edge cloud service, etc., and L3 cloud service is also called L3 cloud business, L3 edge cloud service or other cloud services, etc. This application does not limit this.
[0108] Based on FIG. 2 to FIG. 4 , an embodiment of the present application provides a connection example of a port list of an ONT and a NERG, as shown in Table 2 and Table 3 below.
[0109] Table 2 NERG meaningful port list
[0110] The NERG in Table 2 may be the NERG 402 shown in Figure 4. In the L2 BD, the LAN1 of the NERG 402 is connected to the WAN2 of the ONT 401 (ie, ONT.WAN2).
[0111] Table 3 ONT meaningful port list
[0112] Table 2 and Table 3 above are merely examples provided in this embodiment and should not be construed as limiting the present application.
[0113] The communication method provided by the present application is exemplarily described below in conjunction with the communication systems shown in Figures 2 to 4. As shown in Figure 5, Figure 5 is a flow chart of a communication method provided by the present application. The enhanced gateway can be the aforementioned NERG instance or the ECGW, and the first home gateway can be the aforementioned ONT (such as ONT 201, ONT 201a or ONT 201b). The first home gateway and the enhanced gateway each support a routing WAN port to connect to the external network (Internet). The first home gateway and the enhanced gateway respectively support PPPoE dial-up or DHCP Client to obtain the IP address of the WAN port from the BRAS.
[0114] For example, the enhanced gateway supports PPPoE dial-up, and the home supports DHCP Client to obtain the IP address of the WAN port from the BRAS.
[0115] In this embodiment, the first home gateway and the enhanced gateway are deployed in a distributed manner, and an intranet IP address is allocated to the local host respectively, and the two gateways are kept in the same intranet address segment, that is, the first home gateway and the enhanced gateway are in the same broadcast domain.
[0116] Please refer to Figure 5. The communication method provided in this embodiment of the present application includes the following S501 to S504.
[0117] S501: The enhanced gateway configures a first IP address for the enhanced gateway.
[0118] For example, the enhanced gateway is pre-configured with the entire intranet address range, such as 192.168.0.0 / 20, which can be divided into 16 sub-segments, 192.168.0.0 / 20 to 192.168.15.0 / 20. These 16 sub-segments can be used by one enhanced gateway and 15 first home gateways to form a large Layer 2 intranet.
[0119] S502: The first home gateway sends a first request to the enhanced gateway.
[0120] Corresponding to the process of S502, the enhanced gateway receives the first request from the first home gateway.
[0121] The first request is used to instruct allocation of a network address for the first home gateway. For example, the network address includes information such as a DHCP server address, a host address pool, and a mask.
[0122] For example, when the first home gateway starts, it broadcasts in the local area network and obtains the local DHCP server address and the address pool range that can be allocated to the local users of the first home gateway from the enhanced gateway, such as the DHCP server is 192.168.0.1, the network mask is 20 bits, and the address pool range is 192.168.0.2 to 192.168.0.254.
[0123] For example, the payload of the message (first request) broadcast by the first home gateway may be as described in Table 4 below.
[0124] Table 4
[0125] Wherein, SIP is the source IP address (source IP, SIP), DIP is the destination IP address (destination IP, DIP), SMAC is the source MAC address (source MAC, SMAC), and DMAC is the destination MAC address (destination MAC, DMAC). BR1_MAC may be the MAC address of the first home gateway.
[0126] S503: The enhanced gateway sends a first message to the first home gateway according to the first request.
[0127] The first message includes: a second IP address allocated to the first home gateway, and the second IP address and the aforementioned first IP address are in the same broadcast domain.
[0128] For example, the payload of the first message may be as described in Table 5 below.
[0129] Table 5
[0130] Among them, BR0_IP is the IP address of the enhanced gateway, BR0_MAC is the MAC address of the enhanced gateway, and BR1_MAC is the MAC address of the first home gateway.
[0131] For example, after the enhanced gateway receives the broadcast (first request) from the first home gateway, it judges the received information: if the information reported by the first home gateway is within the subnet range set by the enhanced gateway and is not used by other first home gateways, the information reported by the first home gateway is accepted and recorded; otherwise, within the subnet segment recorded by the enhanced gateway, a more reasonable data (DHCP Server address, mask length, address pool range, etc.) is allocated to the first home gateway for use, and the enhanced gateway is responded to via Layer 2 unicast.
[0132] S504: The first home gateway sends a first response to the enhanced gateway.
[0133] Corresponding to the process of S504 , the enhanced gateway receives the first response from the first home gateway.
[0134] The first response indicates that the first home gateway has been configured with the second IP address.
[0135] For example, after receiving the first message from the enhanced gateway, the first home gateway refreshes local data if necessary and then replies to the enhanced gateway using a layer 3 unicast method, such as sending a first response to the enhanced gateway, so that the enhanced gateway completes data synchronization and update.
[0136] For example, the payload of the first response may be as described in Table 6 below.
[0137] Table 6
[0138] Among them, BR0_IP is the IP address of the enhanced gateway, BR1_IP is the IP address of the first home gateway, BR0_MAC is the MAC address of the enhanced gateway, and BR1_MAC is the MAC address of the first home gateway.
[0139] To enable the transmission of control signaling and other messages between the enhanced gateway and the first home gateway, in this embodiment, the first home gateway can periodically report local data (the IP and MAC addresses in this data can be found in Table 6 above) to synchronize with the enhanced gateway. In response, the enhanced gateway responds to the reported data (the IP and MAC addresses in this response can be found in Table 5 above), maintaining a heartbeat connection. Specifically, a heartbeat connection is established between the first home gateway and the enhanced gateway via the second WAN port (WAN2). This heartbeat connection is used to synchronize the status of the first home gateway and the enhanced gateway.
[0140] The following continues with the accompanying drawings to describe in detail the communication method provided by the embodiment of the present application. As shown in Figure 6, Figure 6 is a flow chart of a communication method provided by the present application. In Figure 6, the first WAN port (WAN1) in the first home gateway is connected to the Internet access device, the second WAN port (WAN2) is connected to the enhanced gateway, and the enhanced gateway is also connected to the first edge cloud device. For the description of each device in Figure 6, please refer to the relevant content of Figures 2 to 4 above, and will not be repeated here.
[0141] The first edge cloud device provided in the embodiment of the present application can be used to support the implementation of the functions corresponding to the L2 cloud service in the aforementioned Figure 3. For example, by utilizing the abundant computer room facilities, the servers and other electronic devices with computing, storage or network transmission functions in these computer room settings are transformed into edge clouds to obtain the "edge computing" advantages for mobile operators. Alternatively, the first edge cloud device can also refer to an electronic device that is idle in the user's home intranet, such as a server that has not been used for a long time, a hardware device with low performance, or other devices.
[0142] In this embodiment, the enhanced gateway, the first home gateway and the first edge cloud device are in the same broadcast domain. For details, please refer to the description in Figure 5 and will not be repeated here.
[0143] Please refer to Figure 6. The communication method provided in this embodiment of the present application includes the following S601 to S605.
[0144] S601. The first home gateway sends a first service message to the Internet through the first WAN port (WAN1).
[0145] S602. The first home gateway sends a second service message to the enhanced gateway through the second WAN port (WAN2).
[0146] Corresponding to the process of S601, the enhanced gateway receives the second service message from the first home gateway.
[0147] Exemplarily, the second service message carries a user identifier that supports the use of the broadcast domain, such as a user ID or a hash value obtained by performing a hash calculation based on the user ID.
[0148] After the enhanced gateway receives the second service message, the enhanced gateway parses the second service message to obtain the destination MAC address.
[0149] If the destination MAC address in the second service message is the MAC address of the first edge cloud device, execute S603; if the destination MAC address in the second service message is the MAC address of the first bridge interface (BR0 gateway), execute S604.
[0150] In some feasible scenarios, a Layer 2 tunnel is established between the enhanced gateway and the first home gateway. This Layer 2 tunnel is used to transmit service messages between the enhanced gateway and the first home gateway. During service message transmission in the Layer 2 tunnel, the message header may include tunnel ID and session ID information to identify different tunnels and sessions. Messages with the same tunnel ID but different session IDs are multiplexed on the same tunnel. For details on labels that can be used in Layer 2 tunnels, please refer to Figure 7E and Table 7 and are not detailed here.
[0151] S603. The enhanced gateway sends a second service message to the first edge cloud device.
[0152] Exemplarily, the second service message may carry the MAC address of the first edge cloud device, or the second service message may carry the IP address of the cloud service provided by the first edge cloud device.
[0153] S604: The enhanced gateway sends a second service message to the Internet.
[0154] In a feasible example, if the IP address carried in the second service message is a private domain IPv4 address allocated on the Internet (there is no address on the Internet that duplicates the IPv4 address), the enhanced gateway can send the second service message directly to the Internet.
[0155] In another feasible example, if the IP address carried in the second service message is an IP address (IPv4 address or IPv6 address) allocated in the broadcast domain, the enhanced gateway can also perform NAT or network address port translation (NAPT) on the second service message before sending the second service message.
[0156] Wherein, NAT refers to the process of converting the IP address in the header of a service message into another IP address, which is mainly used to realize the function of an internal network (private IP address) accessing an external network (public IP address). NAPT can hide a small or medium-sized network behind a legal IP address and map the internal connection to a separate IP address in the external network. On the basis of NAT, NAPT can also perform address translation on the port, thereby further improving the accuracy of the converted address. The above two feasible examples are illustrated by the conversion of IP addresses, but in some other feasible examples, address translation can also be applied to MAC addresses or ports, etc., which are not limited in this application.
[0157] In the process of the first home gateway accessing the edge cloud, the first home gateway, the enhanced gateway and the first edge cloud device are set in the same broadcast domain, so that the first home gateway, the enhanced gateway and the first edge cloud device are in a second-layer network, thereby providing users of the first home gateway with an in-cloud service access experience to the edge cloud.
[0158] Combining the contents of S602 to S604, it can be seen that in this embodiment, the enhanced gateway can identify the destination MAC address of the service message sent by the first home gateway, and send the service messages with different MAC addresses to different destination devices, such as the first edge cloud device or the Internet, so that the enhanced gateway can select different service messages in the data stream to enter the cloud on demand, that is: there is no need to connect all the Internet traffic of the first home gateway to the cloud, avoiding the problem of insufficient performance of the first edge cloud device caused by all service messages sent by the first home gateway to the enhanced gateway needing to enter the cloud, and realizing the diversion function of the Internet traffic of the first home gateway in the enhanced gateway.
[0159] In an optional implementation, the first home gateway may also receive a response service message sent from the Internet through the first WAN port (WAN1), where the destination IP address carried in the response service message is the IP address of the first home gateway.
[0160] Combining the contents of S601, S602 and S604, it can be seen that in the process of the first home gateway accessing the Internet, the first home gateway can not only transmit Internet traffic through the first WAN port (WAN1), but also transmit Internet traffic through the second WAN port (WAN2) via the enhanced gateway, thereby avoiding the communication interruption problem between the first home gateway and the Internet caused by failure or abnormality of the enhanced gateway, which is conducive to improving the communication reliability of the first home gateway.
[0161] It is worth noting that although the service messages sent in S603 and S604 in Figure 6 are different, in some feasible scenarios, the valid data carried in the second service message sent by the enhanced gateway to the Internet and the service message sent by the first home gateway to the Internet can be the same. This application uses the second service message to exemplify the data accessed to the Internet and should not be construed as limiting this application. For example, if the valid data carried in the first service message sent by the first home gateway through the first WAN port (WAN1) is Data 1, the valid data carried in the second service message sent by the enhanced gateway to the Internet is also Data 1.
[0162] The following will exemplarily illustrate the traffic forwarding process in the enhanced gateway provided by the present application based on the embodiments shown in Figures 4 and 6 in combination with Figures 7A to 7D.
[0163] FIG7A is a flow chart of the first traffic forwarding method provided by the present application. S601 to S603 in FIG7A can refer to the description of FIG6 above and are not described here in detail. Referring to FIG7A , the traffic forwarding method provided by the embodiment of the present application further includes the following S6061 to S6063.
[0164] S6061. The first edge cloud device sends a first set of response service messages to the enhanced gateway.
[0165] Corresponding to the process of S6061, the enhanced gateway receives the first set of response service messages sent by the first edge cloud device.
[0166] The first group of response service messages is determined by the first edge cloud device according to the second service message in the aforementioned S603. The first group of response service messages may include one or more service messages.
[0167] Exemplarily, the first set of response service messages is a service message outputted after the L2 cloud service provided by the first edge cloud device is executed. For example, the cloud service provided by the first edge cloud device may be cloud computing, cloud desktop, cloud storage, hybrid cloud server, or other cloud services, etc., which is not limited in this application.
[0168] S6062. The enhanced gateway sends the sixth service message in the first group of response service messages to the first home gateway.
[0169] Corresponding to the process of S6062, the first home gateway receives the sixth service message.
[0170] For example, the sixth service message refers to a message set including one or more service messages, such as a data stream. The destination IP address of the sixth service message is the IP address of the first home gateway.
[0171] S6063. The enhanced gateway sends the Internet access service message in the first group of response service messages to the Internet.
[0172] Corresponding to the process of S6063, the Internet receives the Internet access service message.
[0173] The Internet service message refers to a message set including one or more service messages, such as a data stream. The difference between the Internet service message and the sixth service message is that the destination IP address of the data in the Internet service message is the IP address of the target device on the Internet.
[0174] Regarding the specific process from S6061 to S6063 above, ③ in FIG. 2 provides a feasible specific example: ECGW 202 receives traffic from Internet 205 , a portion of which is forwarded by ECGW 202 to edge cloud 203 , and the other portion is forwarded by ECGW 202 to ONT 201 .
[0175] It is worth noting that in the embodiment shown in FIG. 7A , S6062 and S6063 exist simultaneously, but in some optional embodiments, S6062 and S6063 may exist alternatively, which is not limited in this application.
[0176] In an embodiment of the present application, the enhanced gateway can forward traffic from the edge cloud, thereby achieving the function of diversion at the enhanced gateway, avoiding the problem that all edge cloud traffic can only be transmitted in one direction, and is beneficial to improving the communication stability of users in the first home gateway.
[0177] FIG7B is a flow chart of the second traffic forwarding method provided by the present application. S601 to S603 in FIG7B can refer to the description of FIG6 above and are not described here in detail. Referring to FIG7B , the traffic forwarding method provided by the embodiment of the present application further includes the following S6071 to S6073.
[0178] S6071. The Internet sends a second set of response service messages to the enhanced gateway.
[0179] Corresponding to the process of S6071, the enhanced gateway receives the second set of response service messages from the Internet.
[0180] The second set of response service messages is determined by a device on the Internet based on the second service message in S604. The second set of response service messages may include one or more service messages. The device on the Internet may include, but is not limited to, an application server, a cloud server, a user device, a game server, or other types of devices, which are not limited in this application.
[0181] For example, the second group of response service messages are service messages generated or obtained by one or more service providers in the Internet in response to the second service message.
[0182] S6072. The enhanced gateway sends the seventh service message in the second group of response service messages to the first edge cloud device.
[0183] For example, the seventh service message refers to a message set including one or more service messages, such as a data stream. The destination IP address of the data in the seventh service message is the IP address of the first edge cloud device.
[0184] S6073. The enhanced gateway sends the eighth service message in the second group of response service messages to the first home gateway.
[0185] The eighth service message refers to a data stream containing one or more service messages. The destination IP address of the data in the eighth service message is: the IP address of the host accessing the Internet through the first home gateway. The difference between the eighth service message and the seventh service message is that: the destination IP address is different.
[0186] Regarding the specific process from S6071 to S6073 above, ④ in FIG. 2 provides a feasible specific example: a portion of the traffic received by ECGW 202 from Internet 205 is forwarded by ECGW 202 to edge cloud 203 , and another portion is forwarded by ECGW 202 to ONT 201 .
[0187] It is worth noting that in the embodiment shown in FIG. 7B , S6072 and S6073 exist simultaneously, but in some optional embodiments, S6072 and S6073 may exist alternatively, which is not limited in this application.
[0188] In an embodiment of the present application, the enhanced gateway can forward traffic from the Internet, achieving the function of diversion in the enhanced gateway, avoiding the problem that all Internet traffic must be transmitted through the edge cloud, and is beneficial to improving the communication stability of users (hosts) in the first home gateway.
[0189] In an optional implementation, the aforementioned enhanced gateway is also connected to a second home gateway, which is also in the broadcast domain where the aforementioned first home gateway, enhanced gateway and first edge cloud device are located. For example, the first home gateway refers to ONT 201a in Figure 3, the second home gateway refers to ONT 201b in Figure 3, the enhanced gateway refers to ECGW 202, and the first edge cloud device refers to the first edge cloud device 2031 corresponding to the L2 cloud service. For the content of each device in the same broadcast domain, please refer to the description of Figure 3 above and will not be repeated here.
[0190] In conjunction with the communication system provided in FIG3 and the example of this implementation, the traffic forwarding process provided in this application is exemplarily described. FIG7C is a flow chart of the third traffic forwarding method provided in this application. Referring to FIG7C, the traffic forwarding method provided in this embodiment of the application further includes the following S6081 to S6084.
[0191] S6081. The second home gateway sends a third service message to the Internet through WAN3.
[0192] S6082. The second home gateway sends a fourth service message to the enhanced gateway through WAN4.
[0193] Corresponding to the process of S6082, the enhanced gateway receives the fourth service message from the second home gateway.
[0194] The fourth service message and the second service message sent by the first home gateway to the enhanced gateway are similar in that the destination MAC address in the fourth service message and the second service message is the MAC address of the first bridge interface (BR0.MAC). The fourth service message and the second service message differ in that the second service message is sent by the first home gateway and the fourth service message is sent by the second home gateway, that is, the two service messages are sent to the enhanced gateway by different home gateways.
[0195] The enhanced gateway parses the fourth business message to obtain the destination MAC address. If the destination MAC address in the fourth business message is the MAC address of the first edge cloud device, execute S6083; if the destination MAC address in the fourth business message is the MAC address of the first bridge interface, execute S6084.
[0196] S6083. The enhanced gateway sends a fourth service message to the first edge cloud device.
[0197] Corresponding to the process of S6083, the first edge cloud device receives the fourth service message sent by the enhanced gateway.
[0198] S6084. The enhanced gateway sends a fourth service message to the Internet.
[0199] Corresponding to the process of S6084, the Internet receives the fourth service message sent by the enhanced gateway.
[0200] Optionally, before the enhanced gateway sends the fourth service message, it may further perform NAT or Network Address Port Translation (NAPT) on the fourth service message.
[0201] 3 provides a feasible specific example of the specific process of S6081 to S6084 above: ECGW 202 receives traffic from ONT 201b (secondary home intranet), part of which is forwarded by ECGW 202 to the L2 cloud service, and the other part is forwarded by ECGW 202 to the Internet.
[0202] In an embodiment of the present application, the enhanced gateway can forward traffic from the secondary home intranet, achieving the function of diversion at the enhanced gateway, avoiding the problem that all traffic must be transmitted through the edge cloud service, and is beneficial to improving the communication stability of users in the first home gateway.
[0203] In an optional implementation, the aforementioned enhanced gateway is further connected to a second edge cloud device, which is not in the broadcast domain where the aforementioned first home gateway, enhanced gateway, and first edge cloud device are located. For example, the first home gateway refers to ONT 201a in Figure 3, the second edge cloud device refers to the L3 cloud service in Figure 3, the enhanced gateway refers to ECGW 202, and the first edge cloud device refers to the L2 cloud service. Regarding the session establishment process between the second edge cloud device and the enhanced gateway, please refer to the relevant content of Figure 3 above and will not be repeated here.
[0204] In conjunction with the communication system provided in FIG3 and the example of this implementation, the traffic forwarding process provided in this application is exemplarily described. FIG7D is a flow chart of the fourth traffic forwarding method provided in this application. S601 to S603 in FIG7D can refer to the description of FIG6 above and are not repeated here. Referring to FIG7D , the traffic forwarding method provided in this embodiment of the application also includes the following S6091 to S6093.
[0205] S6091. The first home gateway sends a fifth service message to the enhanced gateway.
[0206] Corresponding to the process of S6091, the enhanced gateway receives the fifth service message from the first home gateway.
[0207] If the destination MAC address in the fifth service message is the second edge cloud device, execute S6092; if the destination MAC address in the fifth service message is the MAC address of the first bridge interface, execute S6093.
[0208] S6092. The enhanced gateway sends a fifth service message to the second edge cloud device.
[0209] Corresponding to the process of S6092, the aforementioned second edge cloud device receives the fifth service message sent by the enhanced gateway.
[0210] The destination IP address in the fifth service message is the IP address of the second edge cloud device. For example, before the enhanced gateway sends the fifth service message to the Internet, it can also perform NAT or NAPT on the service message. For details, please refer to the relevant content of S604 above, and this application is not limited to this. When the destination IP address in the fifth service message is the IP address of the second edge cloud device, the fifth service message is also called a cloud service message.
[0211] S6093. The enhanced gateway sends the fifth service message to the Internet.
[0212] Corresponding to the process of S6092, the Internet receives the fifth service message sent by the enhanced gateway.
[0213] For example, before the enhanced gateway sends the fifth service message to the Internet, it may also perform NAT or NAPT on the service message. For details, please refer to the relevant content of the aforementioned S604, and this application is not limited to this.
[0214] In an embodiment of the present application, the enhanced gateway can send business messages with different IP addresses to different devices, such as the above-mentioned second edge cloud device (such as L3 cloud service) or the Internet, thereby achieving the function of diversion in the enhanced gateway, avoiding the problem that all traffic must be transmitted through the edge cloud service, and is conducive to improving the communication stability of users in the first home gateway.
[0215] With respect to the specific implementation process of Figures 7A to 7D above, Figure 7E provides a possible example based on the ports shown in ONT 401 and NERG 402 shown in Figure 4. Figure 7E is a schematic structural diagram of a service layer forwarding model provided by this application. In ONT 401 shown in Figure 7E, both ONT 401 and NERG 402 forward service packets using a traffic forwarding method.
[0216] For example, in ONT 401, ONT 401 determines the destination MAC address (DA) of an incoming service packet, e.g., "Does DA = ONT.BR1 MAC?" If DA = ONT.BR1 MAC, ONT 401 queries the flow forwarding table and performs packet editing (e.g., port redirection, header editing, etc.) on the service packet. The edited service packet is then forwarded via ONT 401's WAN1 (ONT.WAN1). If DA ≠ ONT.BR1 MAC, ONT 401 queries the Layer 2 (L2) table and forwards the service packet through the bridge egress. For example, the Layer 2 table may support SVLAN + destination MAC (DMAC) forwarding.
[0217] As another example, NERG 402 determines the DA of an incoming service packet, e.g., if DA = ONT.BR0MAC? If DA = ONT.BR0MAC, NERG 402 queries the flow forwarding table and performs packet editing on the service packet (e.g., port redirection, header editing, etc.), then forwards the edited service packet via NERG 402's WAN1 (NERG.WAN1) or WAN3 (NERG.WAN3). If DA ≠ ONT.BR0MAC, NERG 402 queries the L2 table and forwards the service packet through the bridge egress. For example, the L2 table may support SVLAN+DMAC forwarding.
[0218] In some feasible scenarios, the aforementioned L2 table can also support port + SVLAN + DMAC forwarding. To improve the adaptability of traffic forwarding, ONT 401 and NERG 402 can also support some extended functions or protocol processing, such as bridge protocol data unit (BPDU) processing. This application does not limit the extended functions that ONT 401 and NERG 402 can support. The aforementioned flow forwarding table (L3 table) adopts 5-tuple-based flow forwarding and also supports packet header-based policy messages. The actions after the table lookup also support functions such as port redirection and packet header editing.
[0219] The above Figures 7A to 7E are only examples of traffic forwarding provided in this embodiment and should not be understood as limiting the present application. In order to achieve traffic forwarding and communication between users and edge clouds or the Internet, the gateway design of the Internet access device in the communication system is exemplified below based on the aforementioned Figures 3 and 4: There are two or more L3 gateways in the local area network corresponding to the large two-layer network, such as BR0 gateway, BR1 gateway and BR2 gateway. Among them, the function of accessing the Internet through the BR0 gateway is realized by the gateway outlet NERG.WAN1 (the WAN port in NERG for connecting to the Internet), and the function of accessing the Internet through the BR1 gateway is realized by the gateway outlet ONT.WAN1 (the WAN port in ONT for connecting to the Internet).
[0220] In a large Layer 2 network, user devices or hosts within the LAN must use appropriate gateways to connect to other networks. To prevent a single gateway failure from preventing some hosts in the LAN from accessing the Internet, large Layer 2 networks can employ the following constraints.
[0221] Constraint 1: If both Internet gateways (NERG.WAN1 and ONT.WAN1) are available, local hosts use the nearest Internet interface. For example, hosts in the cloud service use NERG.WAN1 for Internet access, and hosts in the home network use ONT.WAN1 for Internet access.
[0222] Constraint 2: If the local internet gateway is unavailable, the local host's internet access is achieved through a remote internet gateway. Optionally, the host is unaware of the switchover process.
[0223] Constraint 3: The interfaces of NERG.BR0 and the ONT.BRx (such as ONT.BR1) of the primary and secondary home intranets must be able to log in to independent websites (websites) locally for easy maintenance.
[0224] Constraint 4: If the active / standby mode of the Internet gateway egress is considered, active / standby is only implemented between the NERG (or ECGW) and the ONT, and not between the primary and secondary ONTs (such as ONT 201a and ONT 201b).
[0225] The configuration states of the BR interface include: active and deactive, wherein the active state indicates that the forwarding and interface protocol functions are unavailable; and the deactive state indicates that the interface forwarding and protocol functions are unavailable.
[0226] The BR interface operates in three states: Up, Passive, and Down. Up indicates that the local WAN interface in the VRF where the interface resides is up. Passive indicates that the local WAN interface in the VRF where the interface resides is down and can only forward packets and function as an IP host. Down indicates that the BR interface enters this state after being disabled (pure bridging mode).
[0227] For example, if the NERG and ONT Internet egress are in active-active mode, the NERG.BR0 and ONT.BR1 interfaces are in the Up state by default. When ONT.WAN1 goes Down, ONT.BR1 enters the Passive state. When ONT.WAN1 comes back Up, ONT.BR1 returns to the Up state.
[0228] Based on the above constraints and feasible examples of BR interfaces, the following table provides a suggestion for service layer routing design, as shown in Table 7.
[0229] Table 7 Business layer routing design recommendations
[0230] The master ONT may refer to the aforementioned home gateway, ONT 201a, etc., the slave ONT may refer to the aforementioned other home gateway, ONT 201b, and the NERG may refer to the aforementioned enhanced gateway, ECGW 202, etc.
[0231] For example, if multiple ONTs and NERGs are considered as multiple independent routers connected to a local area network, the above routing table design recommendations do not include ARP entries. The core routing design principles include the following.
[0232] Design Principle 1: Both ONT.BRx and NERG.BR0 can route to the Internet, but the local gateway takes precedence (the default route of the local outbound interface takes precedence over another gateway as the next hop).
[0233] Design Principle 2: L3 cloud services ultimately exit through NERG.WAN3. If L3 cloud service traffic is sent to the ONT.BRx interface, it must be routed and forwarded to the NERG.BR0 interface. Downstream traffic from the L3 cloud service to hosts within the LAN is directly forwarded by the NERG direct router.
[0234] Design Principle 3: Messages or service messages destined for the directly connected network segment 192.168.16.1 / 20 are also prioritized to go directly through the local interface, with the route indirectly to this network segment (NERG.BR0) as a backup.
[0235] Design Principle 4: ONTs and NERGs also need to process protocol messages. Messages destined for Layer 3 interfaces and the 127.0.0.0 / 8 network segment must be received on the loopback interface for CPU processing.
[0236] Design Principle 5: For security reasons, network segment broadcasts, multicast packets, and IP broadcasts are terminated locally and processed by the protocol without L3 forwarding.
[0237] It is worth noting that the above constraints, BR interface, and service layer routing design recommendations are merely examples provided for this embodiment and should not be construed as limiting the implementation of this application. In some optional implementations, the above constraints, BR interface, and routing design recommendations may vary based on actual circumstances, depending on user needs or network segment changes, and are not detailed here.
[0238] The above Figures 2 to 7E introduce the communication method provided in the embodiment of the present application based on the second-layer network. The communication method provided in the embodiment of the present application will be further described in detail in combination with the different deployment methods of the home gateway and the enhanced gateway. For details, see the first optional implementation method to the third optional implementation method below.
[0239] In a first optional implementation manner, the home gateway and the enhanced gateway are distributed full anycast gateways.
[0240] Exemplarily, the IP address of the first bridge interface (BR0) is the same as the IP address of the second bridge interface (BR1), and the MAC address of (BR0) is the same as the MAC address of the second bridge interface (BR1).
[0241] In one possible scenario, if the first network bridge interface fails, the first home gateway deletes the MAC address of the first network bridge interface configured by the first home gateway, such as BR0.MAC (MAC address of NERG.BR0).
[0242] In another possible situation, if the second network bridge interface fails, the enhanced gateway deletes the MAC address of the second network bridge interface configured by the enhanced gateway, such as BR1.MAC (the MAC address of ONT.BR1).
[0243] Figure 8A is a schematic diagram of the gateway deployment design provided in this application. The two BR interfaces, ONT.BR1 and NERG.BR0, appear as a single logical interface to the LAN, using the same IP and MAC addresses. By default, both BR interfaces are active and enabled. If one BR interface fails, all hosts in the LAN (such as the aforementioned large Layer 2 network) are unaware of the failure. Outgoing traffic from a host identifies only one logical gateway, namely the IP and MAC addresses used by the two BR interfaces. Therefore, the host does not require segment routing, only a default route.
[0244] In other words, the ONT and NERG use a distributed Full Anycast gateway deployment design, and ONT.BR1 and NERG.BR0 are in active-active mode. Both BR interfaces are active, appearing as a single logical anycast interface to the LAN. For example, the IP address uses 192.168.16.1 / 20, and the MAC address uses the same MAC=A (for example, a locally valid virtual MAC calculated based on the same IP address). ARP packets from hosts within the LAN requesting the BR interface MAC address are processed locally and respond to the same MAC address. This MAC address is also configured in the local forwarding table as the BR interface MAC address.
[0245] For example, when a BR interface in Figure 8A fails, such as when ONT.WAN1's external connection to the Internet is interrupted, it can be considered that the ONT.BR1 interface has also failed (because the only external network connected to ONT.BR1 is ONT.WAN1). At this time, it is necessary to delete BR1.MAC on the forwarding plane so that all messages or service messages are forwarded only by bridges.
[0246] As a feasible example, when the DHCP servers of the ONT and NERG assign addresses to hosts, they only need to use DHCP option 3 to convey the default gateway; DHCP option 33 / 121 is not required to convey the route to a specific network segment.
[0247] It is worth noting that heartbeats and a lot of information need to be transmitted between NERG and ONT, and LAN information synchronization protocol is supported for communication.
[0248] For example, the enhanced gateway deletes the MAC address of the forwarding plane in the home gateway, so that the traffic directly connected to the Internet via the home gateway is switched to the enhanced gateway, and all messages or business messages are forwarded only through the bridge channel of the enhanced gateway. That is, the Internet traffic is switched to the enhanced gateway, avoiding the problem of being unable to access the Internet due to failure of the communication pipeline directly connecting the home gateway to the Internet, which is conducive to improving the communication robustness of users' Internet access.
[0249] In a second optional implementation, the home gateway and the enhanced gateway are distributed Half Anycast gateways.
[0250] Exemplarily, the IP address of the first bridge interface (BR0) is the same as the IP address of the second bridge interface (BR1), and the MAC address of (BR0) is different from the MAC address of the second bridge interface (BR1).
[0251] In one possible scenario, if the first network bridge interface fails, the first home gateway sends a first ARP message to a host in the broadcast domain, where the first ARP message carries the MAC address of the second network bridge interface;
[0252] In another possible scenario, if the second bridge interface fails, the enhanced gateway sends a second ARP message to the host in the broadcast domain, where the second ARP message carries the MAC address of the first bridge interface.
[0253] For example, the first ARP message and the second ARP message may be sent in a gratuitous ARP broadcast manner, where the gratuitous ARP broadcast includes: "IP=192.168.16.1 / 20MAC=A".
[0254] Figure 8B is a second structural diagram of the gateway deployment design provided in this application. The ONT and NERG use a distributed Half Anycast gateway deployment design, which means that the two BR interfaces use the same IP address but different MAC addresses. In this way, the host only sees one logical gateway, so only the default route is still required on the host.
[0255] In the example provided in Figure 8B , when both BR interfaces are active, the ARP table entries for the logical gateway obtained by the edge cloud L2 host and the home network host are different. For example, the ARP table entry for the logical gateway obtained by the edge cloud L2 host includes "IP=192.168.16.1 / 20MAC=A", while the ARP table entry for the logical gateway obtained by the home network L2 host includes "IP=192.168.16.1 / 20MAC=B".
[0256] In the event that a BR interface fails, two possible solutions are provided below.
[0257] In the first possible processing method, if a BR interface fails, the BR interface will no longer intercept ARP messages, and the other BR interface will immediately send a free ARP to all hosts in the network to declare the gateway MAC.
[0258] For example, if the heartbeat connection between the home gateway (ONT) and the enhanced gateway (NERG) is in an abnormal state, the enhanced gateway (NERG) sends an address resolution protocol (ARP message) to all hosts in the broadcast domain. The ARP message carries the MAC address of the enhanced gateway (MAC=A).
[0259] In the second possible approach, if a BR interface fails, the ONT does not immediately refresh the host ARP entry. Instead, it uses a policy message to forcefully modify the destination MAC address and then redirects traffic to another BR interface, waiting for the host's ARP entry to age before responding to the update. For example, a NERG sends an ARP request (ARP request What is MAC of 192.168.16.1) and waits for the ARP entry in the L2 host on the home network to age before redirecting the traffic to "IP=192.168.16.1 / 20MAC=B."
[0260] Exemplarily, if the first bridge interface fails, the enhanced gateway sends a first policy message to the host in the broadcast domain. The first policy message carries: the MAC address of the second bridge interface. The first policy message indicates: the Internet traffic of the host in the large Layer 2 network is forwarded through the second bridge interface.
[0261] As another example, if the second bridge interface fails, the first home gateway sends a second policy message to hosts in the broadcast domain. The second policy message carries the MAC address of the first bridge interface and instructs hosts in the large Layer 2 network to forward their internet traffic through the first bridge interface. For example, if ONT.WAN1 is in an abnormal state, the ONT sends a policy message instructing all service packets connecting the ONT to the internet to be transferred to the enhanced gateway (NERG). The policy message includes the MAC address of the first bridge interface (BR0.MAC), such as MAC=A.
[0262] As shown in Figure 8C, Figure 8C is the third structural diagram of the gateway deployment design provided by this application. In the event of a BR interface failure, the processing flow includes the following: After ONT.WAN1 loses connection, ONT.BR1 is no longer valid. At this time, in order to reduce NERG linkage, NERG.BR0 can be prevented from sending a gratuitous ARP to declare a new gateway MAC. Instead, the ONT locally sends a policy message. For any message received with a destination MAC equal to the ONT.BR1 interface MAC, the destination MAC is modified to the NERG.BR0 interface MAC. The message is then bridged and forwarded to the NERG.BR0 interface via the ONT.WAN2 interface. When the ARP table entry on the home network host ages, the NERG.BR0 interface responds to the ARP request and generates a new ARP table entry on the home network host.
[0263] Because the MAC addresses are different, the communication link between NERG and ONT can use native ETH for communication.
[0264] It is important to note that when both BR interfaces are active, each BR interface has its own "sphere of influence." The edge cloud L2 host uses the NERG.BR0 interface as the gateway, and the home network host uses the ONT.BR1 interface as the egress gateway. To prevent the ARP table entries on the host from being incorrectly overwritten, the ARP messages sent by NERG.BR0 and ONT.BR1 on the intranet must be isolated from each other. ARP replies or gratuitous ARPs sent by NERG.BR0 must be intercepted by the ONT CPU on the ONT and not allowed to be sent to the home network host. The reverse is also true.
[0265] When a BR interface fails, you need to disable the ARP function on the interface to stop intercepting ARP messages sent to the local host by the other BR interface. Instead, the other BR interface can assume the ARP server function for the local host.
[0266] In this implementation, if one BR interface fails, another BR interface takes over the Internet traffic of the host in the LAN. This avoids the problem of Internet traffic disconnection caused by BR interface failure in large Layer 2 networks and helps improve user Internet stability.
[0267] In a third optional implementation, the home gateway and the enhanced gateway are distributed independent gateways.
[0268] Illustratively, the IP address of the first bridge interface (BR0) is different from the IP address of the second bridge interface (BR1), and the MAC address of (BR0) is different from the MAC address of the second bridge interface (BR1).
[0269] In one possible scenario, if the connection between the second bridge interface and the Internet is lost, the first home gateway sends a first ACL to hosts in the broadcast domain. The first ACL instructs the hosts in service packets to change the MAC address of the second bridge interface to the MAC address of the first bridge interface. Furthermore, if the second bridge interface regains connectivity with the Internet, the first home gateway revokes the first ACL.
[0270] In another possible scenario, if the connection between the first bridge interface and the Internet is interrupted, the enhanced gateway sends a second ACL to hosts in the broadcast domain. This second ACL instructs the hosts in service packets to replace the MAC address of the first bridge interface with the MAC address of the second bridge interface. Furthermore, if the first bridge interface regains connectivity to the Internet, the enhanced gateway revokes the second ACL.
[0271] The following is an exemplary explanation with reference to FIG8D . FIG8D is a structural diagram four of the gateway deployment design provided in this application. For different hosts, the two BR interfaces are reflected as two independent gateways. The routing table matches which gateway to use. Therefore, when assigning an address to the host, it is also necessary to carry a detailed network segment route through DHCP option 121. For example, the L3 cloud service network segment needs to go out from NERG.BR0.
[0272] In Figure 8D, the default route to the Internet is only delivered to the local BR interface as the egress route. The alternative route to the remote BR interface is not delivered. This is mainly because the router does not want the route switching to affect the final host. If both default routes are delivered, the local BR interface enters the passive state. DHCP force-renew is required to update the routing table on the local host and adjust the remote BR egress route to the preferred route. When the BR interface comes back up, a similar mechanism is also required to update the routing table on the local host.
[0273] When the ONT is unreachable to the Internet, it is necessary to forcibly redirect the local host's uplink Internet packets to NERG.BR0.
[0274] As shown in Figure 8E, Figure 8E is the fifth structural diagram of the gateway deployment design provided by this application. When ONT.WAN1 is disconnected and ONT.BR1 enters the passive state, the ONT issues an ACL to forcibly change the destination MAC of packets with BR1 to the NERG.BR0 MAC, thereby redirecting them. The source MAC remains unchanged. To the NERG, this packet is originally sent directly from the home host to the NERG.BR0 interface, and the NERG performs L3+NAPT forwarding on this flow.
[0275] When ONT.BR1 returns to the UP state, the redirection ACL is revoked.
[0276] L3 forwarding is not used on the ONT to process this upstream packet. This is because the upstream and downstream paths would be inconsistent: the upstream packet undergoes L3 forwarding on the ONT and L3+NAPT on the NERG. The downstream packet undergoes L3+NAPT on the NERG and is then forwarded on the ONT using L2. This would lead to inconsistencies between the L2 and L3 tables. Furthermore, adjusting host routing using ICMP redirect is not recommended, primarily because different operating systems cannot control how ICMP redirect messages are handled.
[0277] In this implementation, when a BR interface fails, the gateway sends a policy message so that the traffic originally accessing the Internet through the failed BR interface is switched to the remaining BR interface.
[0278] Figures 2 through 8E above describe the communication method provided by the embodiments of the present application based on a Layer 2 network. The communication method provided by the embodiments of the present application will be further described in detail below in conjunction with communication pipelines. Figure 9 is a schematic diagram of the structure of a communication pipeline provided by the present application. The pipeline of this communication system adopts an underlay / overlay separation design and can operate in traditional metropolitan areas and SL metropolitan areas, thereby reducing the workload required for planning and configuring metropolitan area networks.
[0279] It is worth noting that, in some optional ways, the pipeline provided in this application may also be called a tunnel or other names, which is not limited in this application.
[0280] In Figure 9, the ECGW components include: ECGW C-plane and U-plane, NCE-FAN network management (managing the ECGW U-plane), FC management platform (responsible for ECGW C-plane virtualized chassis management), and ONT. Other components include OLT, metropolitan area network, BRAS, DCN network, edge cloud service, converged edge management platform, and other management and control systems.
[0281] As shown in Figure 9, for the ONT, the ONT's internet access includes dialing up to the BRAS via PPPoE1@S+C and then accessing the internet. One possible example involves tagging service packets transmitted from the ONT to the BRAS using an SVLAN+CVLAN (S+C) scheme. The SVLAN identifies the OLT node and service type used by the ONT to access the metropolitan area network, while the CVLAN represents the subscriber ID of a particular OLT. For example, "SVLAN1001" represents standard internet services for OLT1, while "CVLAN32" represents the 32nd subscriber under this OLT.
[0282] The user-level service flow transmitted through the pipeline from the ONT to the ECGW includes: the service message transmitted from the ONT to the OLT is tagged using the CVLAN method, and the service message transmitted from the OLT to the user plane (U plane) of the ECGW 202 is tagged using the SVLAN+CVLAN (S+C) method.
[0283] Service packets transmitted through the pipeline from ECGW to cloud services are marked using the S+C method. VXLAN is used for marking on the underlay tunnel, and user-based EVPN is used for marking on the overlay VPN. Furthermore, virtual routing and forwarding (VRF) technology based on the L3 cloud service can be used on the overlay VPN to implement traffic forwarding between ECGW and L3 cloud services.
[0284] In the ECGW's Internet pipeline, user-level service flows access the Internet through PPPoE2@S+C dial-up connections to the BRAS, with user traffic then connected to the Internet via the ECGW's U-plane. As shown in Figure 9, the ECGW establishes an EVPN pipeline with the Internet through its WAN port. This EVPN pipeline carries Internet traffic from all users accessing the Internet through the home gateway.
[0285] As shown in FIG10 , FIG10 is a schematic diagram of the structure of the ECGW component and ECGW cluster provided in this application.
[0286] In mode 1 of Figure 10, the ECGW component includes 1 C-plane server (ECGW C-plane or C-plane for short) and 1 U-plane board (ECGW U-plane or U-plane for short). The ECGW component mainly implements the functions of user access gateway and edge cloud service gateway.
[0287] Optionally, the C-plane server can be implemented as a control-plane network element, and the U-plane board can be implemented as a user-plane network element. The control-plane network element is used to perform protocol processing on service messages, and the user-plane network element is used to transmit service messages.
[0288] For example, the C-plane can be used to implement functions such as DHCP-S, DNS (domain name server, DNS), PPPOE, NAPT, application-level gateway (ALG), and universal plug and play (UPnP) in the user access gateway. The C-plane can also be used to implement functions such as NAPT and VHOST (virtual host) in the edge cloud service gateway, where VHOST includes functions such as server message block (SMB) proxy, multicast DNS (mDNS), and basic input and output (NETBIOS). For another example, the U-plane is used to implement functions such as SRv6 / VXLAN tunnels, EVPN L2 virtual private LAN service / virtual private wire service (VPLS / VPWS), protocol packet capture and insertion, 5-tuple flow forwarding, ACL, policy messages, and Quality of Service (QoS) management.
[0289] In some feasible approaches, the ECGW component may also be extended to support unified data management (UDM) functions, such as AAA client, user authority, and bandwidth control.
[0290] In some other feasible embodiments, the ECGW component may also support the three-way traffic distribution function of the aforementioned ECGW 202, which will not be described in detail here.
[0291] In an optional implementation, the ECGW component can provide 4K to 8K user capacity, that is, 4K to 8K NERG instances, and provide each user with a bidirectional bandwidth of 10M to 20Mbps.
[0292] In mode 2 of Figure 10, the ECGW component also supports a cluster organization consisting of multiple C-planes and multiple U-planes. As shown in the ECGW cluster in mode 2 of Figure 10, the functions that can be achieved by the U-plane and the C-plane can be referred to the above description and will not be repeated here.
[0293] The following, combined with the contents of Figures 9 and 10, details the communication pipeline used in Figures 2 through 8E. Figure 11 is a second structural schematic diagram of a communication pipeline provided by this application. The pipeline model shown in Figure 11 is the edge cloud network pipeline model within the SL metropolitan area network. First, looking at the access side, the ONT.WAN2 interface egress encapsulates a single layer of CVLAN, which is converted to the corresponding S+C at the OLT. Each OLT is assigned a specific SVLAN, which is shared by 3000 users on the OLT, and CVLAN is used for user-level differentiation.
[0294] On an AL pair, the SVLAN must be unique. The AL is mapped to a specific EVPN based on the SVLAN (using the VPLS method to query the BD L2 table to obtain the EVPN.SID), using a TAG approach without stripping the S+C tag. This extends to a specific ECGW. This means that an SVLAN (OLT) can only correspond to one ECGW component or cluster and cannot span across ECGWs. Multiple SVLANs can terminate on a single ECGW component. After the ECGW terminates the coarse-grained EVPN, it routes the S+C traffic to the corresponding NERG.LAN1 port and enters the user-level L2 BD domain (i.e., the large Layer 2 network, LAN, or broadcast domain in the aforementioned embodiments).
[0295] Similarly, the ECGW to SL pair also uses a coarse-grained EVPN pipeline to carry the WAN3 interface of all users in an SVLAN. At the ingress, the packet is forwarded to the NERG.WAN1 interface, encapsulated with a PPPOE / IPOE header, and an S+C double tag is added (which can be the same as the NERG.LAN1 encapsulation). It is connected to the SVLAN-level BD domain, and the EVPN.SID is obtained after querying the BD L2 table. The EVPN SRv6 is encapsulated and sent to the SL pair. After the SL pair terminates the EVPN, the S+C L2 table is restored (EDN.DX2V behavior) and sent to the corresponding BRAS interface. One SVLAN 1:1 corresponds to one ECGW and SL pair, and does not cross ECGW or SL pairs.
[0296] Figure 12 is a third structural diagram of a communication pipeline provided by this application, showing the access-side (ONT.WAN2 to NERG.LAN1) pipeline model. As shown in Figure 12, the access-side pipeline model is divided into two levels: one is the user-level pipeline, and the other is the OLT-level pipeline (or user group). The home network, ONT, ECGW NERG instance, and L2 cloud service all belong to the user-level pipeline; AL and ECGW coarse-grained EVPN both belong to the OLT level.
[0297] Take a specific forwarding process as an example. For example, a TV on the home network accesses the cloud NAS (L2 cloud service) in the edge cloud. The TV's IP address is 192.168.16.2, and its MAC address is A. The user's cloud NAS address is 192.168.17.2, and its MAC address is B. The previous broadcast ARP process is omitted, and the process starts directly with unicast data packet forwarding.
[0298] 1. The original message is untagged, and a CVLAN layer is added to the ONT.WAN2 interface.
[0299] 2.OLT up-converts to S+C.
[0300] 3. In the AL, the SVLAN is introduced as the local AC interface of the corresponding BD. The BD L2 table is queried and the outgoing interface is found to be an EVPN.END.DT2U SID.
[0301] 4. The AL encapsulates the EVPN SRv6 packet and sends it to the ECGW.
[0302] 5. The ECGW terminates the OLT-level EVPN and searches the BD L2 table corresponding to the EVPN. It finds that the egress is a local AC interface (SVLAN). This local AC interface is connected to a logical port of the ECGW (facing the ONT).
[0303] 6. ECGW introduces the S+C on this logical port to the corresponding user-level BD (VNI), and checks the L2 table to find that the outgoing interface is the remote VXLAN tunnel endpoint (VTEP).
[0304] 7. ECGW encapsulates the user-level VXLAN EVPN and sends it to the multilayer virtual switch (Open vSwitch, OVS) where the L2 cloud service is located.
[0305] 8. OVS terminates VXLAN, restores the original data encapsulation, and sends it to the corresponding cloud NAS virtual machine based on DMAC.
[0306] In the above description, OLT-level EVPN uses VPLS. VPWS does not require MAC table lookup and can directly forward packets based on the cross-connect table.
[0307] The above description describes accessing an L2 cloud service from a home network. The process for accessing an L3 cloud service or the Internet is similar, with the following differences: the destination MAC address in the service packet is replaced with the NERG.BR0 interface MAC address, and the destination IP address in the service packet needs to be replaced with the L3 cloud service network segment.
[0308] Figure 13 is a fourth structural diagram of a communication pipeline provided by this application, which shows the network-side (NERG.WAN1 to BRAS-UP) pipeline model. Figure 13 is exemplarily illustrated in conjunction with Figure 12. Similar to the access-side pipeline model, the network-side pipeline model is also divided into two levels: user-level pipelines and ECGW-level pipelines (or user groups). ECGW NERG instances and L2 cloud services belong to user-level pipelines; SL and ECGW coarse-grained EVPNs belong to the ECGW level.
[0309] Assume that the cloud NAS in the edge cloud needs to access the external network. The cloud NAS address is 192.168.17.2 and the MAC address is B.
[0310] 1. The cloud NAS sends an original message, with the destination MAC address set to the NERG.BR0 interface address.
[0311] 2. The OVS of the server where the cloud NAS is located searches the L2 table based on the VNI + destination MAC address, finds the VTEP of the remote ECGW, and encapsulates the VXLAN EVPN.
[0312] 3. The NERG instance searches the BD L2 table and knows that the packet needs to be forwarded to the gateway based on the destination MAC address. By searching the flow table (assuming the flow table has been created), it finds that the outgoing interface is NERG.WAN1. The packet is edited using NAPT, PPPoE header encapsulation, S+C encapsulation, and sent to the internal logical port.
[0313] 4. The ECGW connects the SVLAN subport of the internal logical port to a BD as the local AC, obtains the remote EVPN.SID from the table, and encapsulates the SRv6 EVPN header.
[0314] 5. SRv6 EVPN is terminated on the SL. The L2 table is checked and the outbound direction is found to be the local AC (SVLAN).
[0315] The above is merely a specific example of the network-side pipeline model provided in this embodiment and should not be understood as limiting the present application.
[0316] FIG14 is a structural diagram of a communication pipeline provided by the present application. FIG14 shows a secondary home access pipeline model (secondary ONT to NERG.LAN2). The secondary ONT may refer to the ONT 201b in FIG3 . FIG14 is exemplarily illustrated in conjunction with FIG12 . The access side pipeline model adopts coarse-grained EVPN mainly to simplify the user-level service provisioning on the metropolitan area network. The OLT-level EVPN is pre-configured. When the user activates the service, only the user-level equipment, such as ONT, OLT and ECGW, needs to be configured. The access to the secondary home intranet is similar to a dedicated line for networking, and coarse-grained pipelines cannot be pre-configured. Therefore, the logic of dedicated line configuration is adopted. When the user activates multi-point access to the secondary home, the ONT, OLT, AL and ECGW are configured on demand.
[0317] The secondary ONT reuses the WAN2 channel and configuration, and uses a different SVLAN on the OLT. The edge cloud network's SVLAN cannot be used; similar encoding rules can be used for the CVLAN. The OLT re-adds the S+C and sends it to the AL. The AL identifies this as a secondary ONT access based on this specific SVLAN and maps the S+C to the secondary ONT-level EVPN (using VPWS or VPLS to find the corresponding EVPN.SID through the BD table). The S+C tag is stripped and the EVPN is encapsulated. On the ECGW, this EVPN.SID acts as a remote port for the user-level BD. After traffic is diverted out of the tunnel, the BD L2 table or GW routing table is searched to locate the final egress of the NERG.
[0318] With respect to the contents of Figures 11 to 14 above, the embodiment of the present application also provides an optional VLAN / VNI planning suggestion, as shown in Table 8 below.
[0319] Table 8 VLAN / VNI planning recommendations
[0320] Figures 11 to 14 above use SRv6-BE EVPN as the coarse-grained metropolitan area pipe by default. VXLAN EVPN can also be used, and the principles are similar. The main difference is that VTEP+VNI planning must be considered. This can follow the existing VXLAN VTEP+VNI planning principles. The following examples illustrate different pipe models using VXLAN EVPN.
[0321] Figure 15 is a sixth structural diagram of a communication pipeline provided by this application. The pipeline model shown in Figure 15 is a traditional metropolitan area pipeline model. In a traditional metropolitan area, the OLT serves as the VTEP starting point and maps the SVLAN to a coarse-grained EVPN, which can adopt VPWS or VPLS.
[0322] The processing on the ECGW is similar to that on the SL metropolitan area. After terminating the coarse-grained EVPN, it leads to the S+C as the local AC to access the corresponding user-level BD, and finds the final NERG egress after searching the BD L2 table or the GW flow forwarding table.
[0323] The secondary home broadband is also treated as a dedicated line on demand. The OLT is mapped to the secondary home-level EVPN based on a specific S+C, and accesses the user-level BD as a remote VTEP port on the ECGW.
[0324] After Internet traffic from NERG.WAN1 is aggregated to a specific SVLAN, it serves as a coarse-grained EVPN local AC interface. It searches the EVPN BD table or VPWS cross-connect table to find the VTEP port corresponding to the DC-GW and encapsulates it into an ECGW-level VXLAN EVPN. After the DC-GW terminates the EVPN, it exports the S+C traffic to the BRAS.
[0325] To make the communication method provided by the embodiments of this application clearer, the following is a brief introduction to the edge cloud: The edge cloud is constructed as a three-level hierarchical architecture, consisting of a provincial center, a shallow edge, and a deep edge. The edge cloud management VPN (EC-mgnt) and the edge cloud storage VPN (EC-obs) are deployed through the cloud network convergence center to form a unified scheduling network for cloud resources. The edge cloud designs and plans a business network centered around NAS-type services, and the product applications of many ecological business partners are added to form an edge cloud ecological application business network, providing a rich variety of scenarios such as home entertainment, collaborative office, and game competitions.
[0326] Edge cloud applications mainly include L2 cloud services (cloud NAS, cloud desktop, cloud STB) and L3 cloud services (cloud rendering, cloud server). In the future, service function chaining (SFC) can be used to expand support for security-related value-added server (VAS) services.
[0327] The L2 cloud service is a dedicated L2 host, primarily providing Layer 2 network access. A top-of-rack (TOR) switch or Open Virtual Server (OVS) provides Layer 2 VXLAN static / dynamic tunneling capabilities. This serves as the L2 VXLAN tunnel entry point and connects to the ECGW. The ECGW.NERG instance provides DHCP capabilities. During startup, the L2 cloud service automatically obtains an IP address from the ECGW.NERG using DHCP, using the same subnet mask as the user's home intranet. This allows the L2 cloud service and the user's home intranet to form a large Layer 2 intranet.
[0328] L3 cloud service docking is a three-layer network access method. The L3 cloud service business platform has multi-tenant access capabilities. Because the platform provides shared service capabilities, when users access shared services, traffic passes through the ECGW, which provides source NAT address capabilities and implements three-layer network access through IP routing.
[0329] Based on the edge cloud service, a pipeline model for docking edge cloud services is proposed below, as shown in Figure 16. Figure 16 is a structural schematic diagram of a communication pipeline provided by this application. The pipeline model shown in Figure 16 is an L2 cloud service docking pipeline model. L2 cloud service means that a service is exclusive to a certain user and is isolated between different users. There is no access path between each other. Figure 16 provides two pipeline termination methods: one is that VXLAN terminates at the opposite TOR switch; the other is that VXLAN terminates on OVS. In this way, ECGW does not need to plan VLANs for user-level L2 cloud services, which is simpler.
[0330] In the first termination method in Figure 16, the ECGW is connected to the TOR switch associated with the L2 cloud service. One ECGW needs to connect to multiple TOR devices. The ECGW can use the outer VLAN to identify the TOR device (VTEP) and the inner VLAN to identify the VM / container (user level) connected to the TOR device.
[0331] The NERG checks the BD table or flow table to find the traffic egress as the remote VTEP (remote TOR). It then encapsulates the traffic with a double VLAN tag: the outer tag represents the remote TOR, and the inner tag represents the user-level L2 cloud service below the TOR. When the traffic is diverted to the user-level VXLAN EVPN, the double VLAN tag is not stripped.
[0332] After the peer TOR switch terminates EVPN, it strips the outer VLAN and sends it to the corresponding VM / container based on the inner VLAN.
[0333] You can also use the RAW method. ECGW does not encapsulate double-layer VLANs, but uses the untag method. The TOR switch adds a user-level VLAN based on the VNI (representing a user under the ECGW), and then forwards it to the corresponding virtual machine / container based on the VLAN.
[0334] The ECGW and the TOR are connected via VTEPs in the underlay domain. Overlay domains are connected on a per-home or 2B basis, with each home using a BD domain. Underlay routing uses OSPF, with the loopback address passed to the gateway (DC-GW) via OSPF. Overlay routing can be statically configured or via EVPN. The ECGW establishes BGP EVPN neighbors with each TOR.
[0335] When the host accesses the L2 cloud service VM / container via IP, it first requests the MAC address of the VM / container through a Layer 2 ARP broadcast. The VM / container returns the MAC address to the host, and then the host directly accesses the VM based on the unicast MAC address of the VM.
[0336] In the second termination method shown in Figure 16, the server OVS performs VTEP. The main difference between this and TOR is that OVS can directly associate with user-level VMs / containers based on the VNI without the need for VLAN identification. Therefore, EVPN uses the untag RAW mode.
[0337] Based on edge cloud services, another pipeline model for connecting to edge cloud services is proposed below, as shown in Figure 17. Figure 17 is a structural schematic diagram of a communication pipeline provided by this application. The pipeline model shown in Figure 17 is an L3 cloud service connection pipeline model. In Figure 17, all L3 cloud services in the edge cloud share an underlay VRF. Each NERG.WAN2 and all L3 cloud services are placed in a VRF, which can use a centralized gateway or a distributed gateway. The centralized gateway of the VRF can be deployed on SPINE or DC-GW. The VRF plane needs to deploy a DHCP server to provide dynamic address management services for the L3 cloud service virtual machines and NERG.WAN3.
[0338] 17 , for the shared service access process within the edge cloud, assuming that the two BR interfaces of the ONT and NERG are two independent gateways, the process steps for the home network host to access the virtual machine 29.2.3.10 include the following ① to ④.
[0339] ①. According to the default route, the home network host routes packets accessing 29.2.3.10 to BR1 on the ONT.
[0340] BR1 is configured with a static route (to the L3 cloud service network segment 29.0,0.0 / 8) that routes to NERG.BR0.
[0341] ③. NERG.BR0 routes from the WAN3 interface to the DC-GW gateway 29.2.2.1 according to the configured network segment routing.
[0342] ④. Gateway 29.2.2.1 then routes to the specific virtual machine / container.
[0343] In this embodiment, it is recommended to build a local DNS in the edge cloud, publish domain names for L3 cloud services, and users resolve to virtual machine addresses through domain names. The process of accessing services through DNS is shown in Figure 18 below, which is a flow chart of an access service provided by this application. The preparations required before executing the access service include: 1. Building a DNS Server; 2. Publishing the service to the DNS Server; 3. In the DHCP Server of the BRAS, providing a private network DNS Server as a parameter and sending it to the optical modem (ONT); 4. Configuring the optical modem (ONT) to use the DNS Server obtained on the WAN side.
[0344] Please refer to Figure 18. The access service provided by this embodiment of the present application includes the following S801 to S804.
[0345] S801. The host sends a DNS request to the local DNS.
[0346] Corresponding to the process of S801, the DNS receives the DNS request of the host.
[0347] For example, the DNS request includes: www.aabbccddeeff.com.
[0348] S802. DNS sends the private IP address to the host.
[0349] Corresponding to the process of S802, the host receives the private IP address sent by the DNS, such as the private IP address 29.3.2.16.
[0350] As for DNS, DNS can determine whether the address used by the user in the host is an intranet address, such as the address 29.xxx. If so, it returns the private network address of the edge cloud to the host (depending on the type of service provided, load balancing, etc.). If the address used by the user is an external network address, DNS returns the public network address provided by the service. In addition, if the DNS local query cannot be found, the public network DNS server address is returned to the host, and the host obtains the content it wants to access from the public network.
[0351] S803: The host accesses the application server corresponding to the private IP address.
[0352] For application servers, the application can publish a list of addresses providing services to the DNS.
[0353] S804: The application server sends the access data result to the host.
[0354] Corresponding to the process of S804, the host receives the data result sent by the application server.
[0355] For hosts, the DNS server address is obtained in two ways: When the BRAS assigns the WAN address to the optical modem / NERG, it carries the DNS server address. Zhu Yong's address is filled in with the private DNS server address based on the POD location, and the public DNS server address is used as a backup.
[0356] It is worth noting that the evolution of traditional metropolitan area networks to SL metropolitan area networks will not change the user-level service model on OLT and BRAS. It only transports the traffic of the OLT upstream port to BRAS-UP intact. Therefore, even if some operators do not use S+C to mark each user and each service at the user level, but instead use a single-layer VLAN with N:1 aggregation to mark the service, the pure transmission service nature of the SL metropolitan area network will not change.
[0357] Figure 19 shows the structure of a SL metropolitan area home bandwidth service model provided by this application. To avoid user-level service provisioning, the metropolitan area network uses SVLAN-based EVPN to transport traffic. Instead of considering the inner VLAN, the SVLAN is mapped 1:1 to the EVPN. Using the TAG mode, traffic is transparently transmitted without any processing of the VLAN tags on both sides when entering and leaving the tunnel. For details on S+C, please refer to the previous embodiment and will not be elaborated here.
[0358] It is understood that, to implement the functions described in the above embodiments, the home gateway and enhanced gateway include hardware structures and / or software modules corresponding to the respective functions. Those skilled in the art will readily appreciate that, in conjunction with the various exemplary units and method steps described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or in a hardware-driven manner by computer software depends on the specific application scenario and design constraints of the technical solution.
[0359] The communication method provided according to the embodiment of the present application is described in detail above in conjunction with Figures 1 to 19. The communication device provided according to the embodiment of the present application will be described below in conjunction with Figure 20.
[0360] Figure 20 is a schematic diagram of the structure of a communication device provided by the present application. This communication device can be used to implement the functions of a home gateway or enhanced gateway in the above-mentioned method embodiments, thereby also achieving the beneficial effects of the above-mentioned method embodiments. In the embodiments of the present application, the communication device can also be the aforementioned ONT, NERG, ECGW, or a chip used in the above-mentioned devices.
[0361] As shown in FIG. 20 , the communication device 2000 includes a transceiver module 2010 and a processing module 2020 .
[0362] When the communication device 2000 is used to implement the functions of a home gateway, the transceiver module 2010 can be used to send a first service message to the Internet via the first WAN port and send a second service message to the enhanced gateway via the second WAN port. The processing module 220 can be used to collaborate with the transceiver module 2010 to implement the functions of the home gateway or any OLT described above, and will not be described in detail here.
[0363] When the communication device 2000 is used to implement the enhanced gateway function, the transceiver module 2010 can be used to receive a second service message from the home gateway; the processing module 2020 can be used to parse the second service message to obtain a destination MAC address. The transceiver module 2010 is further configured to: if the destination MAC address is the MAC address of the first edge cloud device, send the second service message to the first edge cloud device; if the destination MAC address is the MAC address of the first bridge interface, send the second service message to the Internet access device.
[0364] The communication device 2000 of the embodiment of the present application can be implemented by a software module. The communication device 2000 according to the embodiment of the present application can be corresponding to executing the method described in the embodiment of the present application, and the above-mentioned and other operations and / or functions of each module in the communication device 2000 are respectively for implementing the method flow in the aforementioned figures, and for the sake of brevity, they are not further described here.
[0365] It is worth noting that if the communication device 2000 is implemented through a software module, for example, the communication device 2000 can be a logical gateway, etc.
[0366] The communication device 2000 of the embodiment of the present application can also be implemented by hardware. For example, the hardware refers to a home gateway or an enhanced gateway. Regarding the specific implementation methods of the home gateway and the enhanced gateway, the following Figures 21 and 22 provide possible examples respectively.
[0367] Figure 21 is a schematic diagram of the structure of a home gateway provided by this application. The home gateway 2100 includes: a memory 2110 and at least one processor 2120. The processor 2120 can implement the communication method provided in the above embodiment. The memory 2110 is used to store software instructions corresponding to the above communication method.
[0368] As an optional implementation, in hardware implementation, the home gateway 2100 may refer to a chip or chip system encapsulating one or more processors 2120. For example, when the home gateway 2100 is used to implement the method steps in the above embodiment, the processor 2120 included in the home gateway 2100 executes the steps of the above method and its possible sub-steps.
[0369] In an optional scenario, the home gateway 2100 may further include a communication interface 2130, which may be used to send and receive data. For example, the communication interface 2130 may be used to send or receive service messages, etc. The communication interface 2130 may be implemented by an interface circuit included in the home gateway 2100.
[0370] In some optional examples, the communication interface 2130 can be used to provide multiple WAN ports, such as WAN1 directly connected to the Internet, WAN2 connected to the enhanced gateway, etc. It should be understood that in some cases, the communication interface 2130 can also be called a transceiver of the home gateway 2100, which is not limited in this application.
[0371] In an embodiment of the present application, the communication interface 2130, the processor 2120, and the memory 2110 may be connected via a bus 2140, which may be divided into an address bus, a data bus, a control bus, etc. The bus 2140 may be a Peripheral Component Interconnect Express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc.
[0372] It is worth noting that the home gateway 2100 can also perform the functions of the communication device 2000 shown in Figure 20, which will not be described in detail here. The home gateway 2100 provided in this embodiment can be any of the above ONTs, or other home gateways with data processing functions, and this application is not limited to this. For example, the home gateway 2100 can be any of the aforementioned home gateways.
[0373] Figure 22 is a schematic diagram of the structure of an enhanced gateway provided by this application. The enhanced gateway can be a terminal device or a network device, or a chip (system) or other component or assembly that can be set in a terminal device or a network device. As shown in Figure 22, the enhanced gateway 2200 may include a processor 2201. Optionally, the enhanced gateway 2200 may also include a memory 2202 and / or a transceiver 2203. The processor 2201 is coupled to the memory 2202 and the transceiver 2203, for example, via a communication bus.
[0374] The following is a detailed introduction to the various components of the enhanced gateway 2200 with reference to FIG22 :
[0375] The processor 2201 is the control center of the enhanced gateway 2200 and can be a single processor or a collective term for multiple processing elements. For example, the processor 2201 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0376] Optionally, the processor 2201 may perform various functions of the enhanced gateway 2200 by running or executing software programs stored in the memory 2202 and calling data stored in the memory 2202. In a specific implementation, as an embodiment, the processor 2201 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG.
[0377] Optionally, the enhanced gateway 2200 may also include multiple processors, such as processor 2201 and processor 2204 shown in FIG22 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0378] The memory 2202 is used to store the software program for executing the solution of the present application, and is controlled by the processor 2201 to execute the software program. The specific implementation method can refer to the above method embodiment and will not be repeated here. Exemplarily, the memory 2202 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these. The memory 2202 can be integrated with the processor 2201 or exist independently and be coupled to the processor 2201 through the interface circuit of the enhanced gateway 2200 (not shown in Figure 22). This embodiment of the present application does not specifically limit this.
[0379] The transceiver 2203 is used for communication with other network devices.
[0380] Optionally, the transceiver 2203 may include a receiver and a transmitter (not shown separately in FIG22 ), wherein the receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0381] Optionally, the transceiver 2203 can be integrated with the processor 2201, or it can exist independently and be coupled to the processor 2201 through the interface circuit of the edge computing gateway 2200 (not shown in Figure 22). This embodiment of the present application does not specifically limit this.
[0382] The method steps in this embodiment can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in RAM, flash memory, ROM, PROM, EPROM, EEPROM, registers, hard disk, mobile hard disk, CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and storage medium can be located in an ASIC. In addition, the ASIC can be located in a computing device or an electronic device. Of course, the processor and storage medium can also exist as discrete components in a network device or a terminal device.
[0383] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the process or function described in the embodiments of the present application is performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid state drive (SSD).
[0384] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A communication system, characterized in that: include: The first home gateway, enhanced gateway, and first edge cloud device located in the same broadcast domain, The first home gateway includes: a first wide area network (WAN) port and a second WAN port; The first WAN port is used to send a first service message to the Internet; The second WAN port is used to: send a second service message to the enhanced gateway; The enhanced gateway is used to: if the destination media access control MAC address in the second business message is the MAC address of the first edge cloud device, send the second business message to the first edge cloud device; if the destination MAC address in the second business message is the MAC address of the first bridge interface, send the second business message to the Internet.
2. The communication system according to claim 1, wherein: A layer 2 tunnel is established between the enhanced gateway and the first home gateway, and the layer 2 tunnel is used to transmit the second service message.
3. The communication system according to claim 1 or 2, characterized in that The communication system further includes: a second edge cloud device that is not in the broadcast domain; The enhanced gateway is also used to: receive a fifth service message from the first home gateway, and if the destination Internet Protocol IP address of the fifth service message is the IP address of the second edge cloud device, send the fifth service message to the second edge cloud device.
4. The communication system according to any one of claims 1 to 3, characterized in that: The communication system further includes: a second home gateway located in the broadcast domain; The second home gateway includes: a third WAN port and a fourth WAN port; The third WAN port is used to send a third service message to the Internet; The fourth WAN port is used to send a fourth service message to the enhanced gateway.
5. A communication method, characterized in that: Applied to a communication system including a first home gateway and an enhanced gateway, wherein a first wide area network (WAN) port of the first home gateway is connected to the Internet, a second WAN port of the first home gateway is connected to the enhanced gateway, the enhanced gateway is connected to a first edge cloud device and to the Internet via a first bridge interface, and the first home gateway, the enhanced gateway, and the first edge cloud device are in the same broadcast domain, the method comprising: The first home gateway sends a first service message to the Internet through the first WAN port; The first home gateway sends a second service message to the enhanced gateway through the second WAN port; If the destination media access control MAC address in the second service message is the MAC address of the first edge cloud device, the enhanced gateway sends the second service message to the first edge cloud device; If the destination MAC address in the second service message is the MAC address of the first bridge interface, the enhanced gateway sends the second service message to the Internet.
6. The method according to claim 5, characterized in that Before the enhanced gateway sends the second service message to the Internet, the method further includes: The enhanced gateway performs network address translation NAT on the second service message sent by the first home gateway.
7. The method according to claim 5 or 6, characterized in that The communication system further includes: a second edge cloud device that is not in the broadcast domain, the enhanced gateway is connected to the second edge cloud device, and the method further includes: The enhanced gateway receives the fifth service message from the first home gateway; If the destination IP address in the fifth service message is the IP address of the second edge cloud device, the enhanced gateway sends the fifth service message to the second edge cloud device.
8. The method according to any one of claims 5 to 7, characterized in that The communication system further includes: a second home gateway located in the broadcast domain, a third WAN port of the second home gateway connected to the Internet, and a fourth WAN port of the second home gateway connected to the enhanced gateway, and the method further includes: The second home gateway sends a third service message to the Internet through the third WAN port; The second home gateway sends a fourth service message to the enhanced gateway through the fourth WAN port; If the destination MAC address in the fourth service message is the MAC address of the first edge cloud device, the enhanced gateway sends the fourth service message to the first edge cloud device; If the destination MAC address in the fourth service message is the MAC address of the first bridge interface, the enhanced gateway sends the fourth service message to the Internet.
9. The method according to any one of claims 5 to 8, characterized in that The first WAN port is connected to a second bridge interface, the IP address of the first bridge interface is the same as the IP address of the second bridge interface, and the MAC address of the first bridge interface is the same as the MAC address of the second bridge interface, and the method further includes: If the first network bridge interface fails, the first home gateway deletes the MAC address of the first network bridge interface configured by the first home gateway; If the second network bridge interface fails, the enhanced gateway deletes the MAC address of the second network bridge interface configured by the enhanced gateway.
10. The method according to any one of claims 5 to 8, characterized in that The first WAN port is connected to a second bridge interface, the IP address of the first bridge interface is the same as the IP address of the second bridge interface, and the MAC address of the first bridge interface is different from the MAC address of the second bridge interface, and the method further includes: If the first bridge interface fails, the first home gateway sends a first Address Resolution Protocol ARP message to the host in the broadcast domain, where the first ARP message carries the MAC address of the second bridge interface; If the second bridge interface fails, the enhanced gateway sends a second ARP message to the host in the broadcast domain, where the second ARP message carries the MAC address of the first bridge interface.
11. The method according to any one of claims 5 to 8, characterized in that The first WAN port is connected to a second bridge interface, the IP address of the first bridge interface is the same as the IP address of the second bridge interface, and the MAC address of the first bridge interface is different from the MAC address of the second bridge interface, and the method further includes: If the first bridge interface fails, the enhanced gateway sends a first policy message to the host in the broadcast domain, the first policy message carrying: the MAC address of the second bridge interface, the first policy message indicating: the Internet traffic of the host is forwarded through the second bridge interface; If the second bridge interface fails, the first home gateway sends a second policy message to the host in the broadcast domain. The second policy message carries: the MAC address of the first bridge interface. The second policy message indicates: the Internet traffic of the host is forwarded through the first bridge interface.
12. The method according to any one of claims 5 to 8, characterized in that The first WAN port is connected to a second bridge interface, the IP address of the first bridge interface is different from the IP address of the second bridge interface, and the MAC address of the first bridge interface is different from the MAC address of the second bridge interface, and the method further includes: If the connection between the second bridge interface and the Internet is interrupted, the first home gateway sends a first access control list (ACL) to the host in the broadcast domain, where the first ACL is used to instruct: to modify the MAC address of the second bridge interface in the service message to the MAC address of the first bridge interface; If the second bridge interface recovers the connection with the Internet, the first home gateway cancels the first ACL; or If the connection between the first bridge interface and the Internet is interrupted, the enhanced gateway sends a second ACL to the host in the broadcast domain, where the second ACL is used to instruct: to modify the MAC address of the first bridge interface in the service message to the MAC address of the second bridge interface; If the first bridge interface recovers the connection with the Internet, the enhanced gateway revokes the second ACL.
13. A communication method, characterized in that: The method is applied to an enhanced gateway, the enhanced gateway is connected to a first edge cloud device and a first home gateway, the first home gateway, the enhanced gateway, and the first edge cloud device are located in the same broadcast domain, and the method includes: The enhanced gateway receives the second service message from the first home gateway; If the destination media access control MAC address in the second service message is the MAC address of the first edge cloud device, the enhanced gateway sends the second service message to the first edge cloud device; If the destination MAC address in the second service message is the MAC address of the first bridge interface, the enhanced gateway sends the second service message to the Internet.
14. The method according to claim 13, wherein: The method further comprises: The enhanced gateway receives a sixth service message from the first edge cloud device; If the destination MAC address in the sixth service message is the MAC address of the first home gateway, the enhanced gateway sends the sixth service message to the first home gateway; If the destination MAC address in the sixth service message is the MAC address of the first bridge interface, the enhanced gateway sends the sixth service message to the Internet.
15. An enhanced gateway, characterized in that: include: Processor and transceiver; the transceiver is used to send business messages or receive messages, and the transceiver and the processor cooperate to implement the method steps of enhancing the gateway implementation in the method as described in any one of claims 5-14.
Citation Information
Patent Citations
Information processing method, apparatus, and system
CN113228567A
Edge cloud gateway system
CN115987719A
Gateway processing method, virtual access gateway, virtual service gateway and related equipment
CN116488958A
Using symmetric and asymmetric flow response paths from an autonomous system
US20170019428A1
Packet forwarding
WO2018219326A1