Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

72 results about "Campus network" patented technology

A campus network, campus area network, corporate area network or CAN is a computer network made up of an interconnection of local area networks (LANs) within a limited geographical area. The networking equipments (switches, routers) and transmission media (optical fiber, copper plant, Cat5 cabling etc.) are almost entirely owned by the campus tenant / owner: an enterprise, university, government etc. A campus area network is larger than a local area network but smaller than a metropolitan area network (MAN) or wide area network (WAN).

Industrial park virtual power plant reactive voltage control method of multi-target multi-agent deep reinforcement learning considering energy storage life

The invention discloses an industrial park virtual power plant reactive voltage control method of multi-target multi-agent deep reinforcement learning considering energy storage life, and belongs to the technical field of virtual power plant reactive voltage control methods based on industrial data acquisition. The problem that in the prior art, a traditional industrial park virtual power plant reactive voltage control method is difficult to consider park network loss optimization and energy storage life protection at the same time is solved. According to the method, a multi-objective optimization model including network loss minimization, node voltage deviation minimization and energy storage battery service life maximization is constructed, a virtual power plant is divided through a distributed multi-agent framework, each agent trains multiple strategies in parallel through a multi-objective multi-agent deep reinforcement learning algorithm based on local observation, the Pareto front is approached, and the energy storage battery service life is maximized. High-efficiency control is realized, and each intelligent agent independently generates an energy storage reactive power regulation and active power charging and discharging instruction. The reliability of the energy storage equipment is improved, and the method can be applied to an industrial park active power distribution network scene with high renewable energy source permeation.
Owner:HARBIN ELECTRIC SCI & TECH CO LTD

Data forwarding processing method and system for campus network

The invention discloses a data forwarding processing method and system for a campus network, and the method comprises the steps: controlling a plurality of independent cameras to generate a multicast video stream carrying a permission identifier according to an access control terminal triggering event; the method comprises the following steps: synchronously creating (S, G) table entries with permission marks and never expired (*, G) table entries on a path multicast router according to a first video stream data packet received by a multicast source side designated router source DR; according to an IGMP join message which is sent by a receiver and carries a permission identifier, through a matching result of an RP comparison (*, G) table entry output interface permission and a multicast data permission identifier, whether a data stream is forwarded along a shared tree (RPT) is decided; and according to a matching result of the permission identifier of the new receiver and the pruned (S, G) flow permission, activating a pruning state on the multicast path and recovering data flow forwarding. According to the embodiment of the invention, occupation of invalid data streams on campus network bandwidth can be reduced, and the overall utilization rate of network resources is improved.
Owner:ZHEJIANG UNIV

Smart campus network security protection system

The invention relates to the technical field of electric digital data processing, and discloses an intelligent campus network security protection system. A network data acquisition module of the system continuously monitors data transmission flow of a smart campus network environment to obtain an original data packet; the chaotic encryption engine encrypts an original data packet by using a key stream based on dynamic chaotic mapping, wherein the key stream is generated by multi-chaotic system switching and a random parameter distribution mechanism; the security protocol processing module converts the encrypted data packet into a format conforming to a network security protocol standard and transmits the encrypted data packet; the data decryption unit decrypts the received encrypted data packet; the security threat analysis module identifies and estimates potential network attack behaviors according to the decrypted plaintext data; and the protection strategy controller generates and executes a network security protection instruction according to the threat analysis result. The system can effectively protect the network security of the smart campus, resist various network attacks, and ensure the security of data transmission and storage.
Owner:NORTHWEST A & F UNIV

Abnormal access defense method and system based on neural network

The invention provides an abnormal access defense method and system based on a neural network, and relates to the technical field of data security, and the method comprises the steps: obtaining equipment access dimension data, traffic log dimension data and user behavior dimension data of a campus network; carrying out preprocessing on the obtained data, and carrying out feature extraction to obtain a real-time high-dimensional feature vector; inputting the historical high-dimensional feature vector into a preset neural network model for training, learning an equipment relationship in combination with a graph structure, optimizing the feature vector, and obtaining a trained neural network model; based on the trained neural network model, the similarity between the real-time feature vector and the historical feature vector is analyzed in real time, and abnormal behavior features are determined; finally, the abnormal behavior characteristics are sent to the optimization model for defense strategy determination, a real-time defense strategy is obtained, and efficient real-time abnormal access detection and dynamic optimization of the defense strategy can be achieved in a large-scale network through the step.
Owner:XIHUA UNIV

Method for application access in zero trust campus network

Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.
Owner:EXTREME NETWORKS INC

Internet firewall security policy setting method

The invention relates to an Internet firewall security policy setting method, and belongs to the technical field of network information security control methods. According to the technical scheme, statistics and classification are carried out on internet access requirements of enterprise and public intranet users and service objects of DMZ area internet applications, and different security policies are set on an internet firewall according to different types of users and internet applications. The method has the advantages that the possibility that intranet users are infected with viruses and Trojan horses and are phished is reduced to the maximum extent, meanwhile, the possibility that Internet application is attacked by an external network is reduced, on the premise that normal Internet application of enterprises and public institutions is met, the safety of enterprise and public institution information resources is guaranteed, and the safety of enterprises and public institutions is guaranteed. And finally, the management and control target of enterprise and public institution park network overall security is realized.
Owner:TANGSHAN IRON & STEEL GROUP +3

Method for managing substituted dialing account and park BRAS (Broadband Remote Access Server)

The invention provides a method for managing a substituted dialing account and a BRAS (Broadband Remote Access Server). The method comprises the following steps: configuring a port block resource pool of a target substituted dialing user for accessing an operator network, establishing a corresponding relationship between user information of the target substituted dialing user and the port block resource pool, and controlling the user to access the operator network according to the corresponding relationship. Through the method, the problem that one account number and multiple terminals cannot be deployed in a campus network BRAS in a scene of dialing equipment on behalf can be solved.
Owner:NEW H3C TECH CO LTD

Campus integrated energy system multi-energy collaborative regulation method and system

This invention proposes a multi-energy coordinated regulation method and system for a comprehensive energy system in a park, relating to the field of energy management technology. It includes: constructing energy autonomous units and local energy balance equations, energy storage state update equations, and equipment power and energy boundary constraints; solving for the elastic net exchange power range of each autonomous unit under uncertain scenarios based on the equations and constraints, symmetrically shrinking the range and reporting it to the elastic coalition scheduling layer; constructing a clearing model at the elastic coalition scheduling layer based on the reported information, solving for the target net exchange power, reserve capacity allocation, and park network energy flow of each autonomous unit; distributing the solution results to the autonomous units, which then adjust equipment output according to priority and track it in real time; monitoring equipment status and renewable energy output deviations, triggering emergency degradation control when equipment failure or deviation exceeding a threshold is detected, reconstructing the model, and introducing a graded load reduction mechanism, thereby improving the stability, reliability, and regulation accuracy of the system operation.
Owner:TIANJIN JINAN THERMAL POWER

Method for transmitting video identification information through network

The invention discloses a method for transmitting video identification information through a network, which relates to the technical field of video identification, and comprises the following steps: when network transmission video monitoring is carried out, acquiring the area coverage area of a campus network, and delimiting a monitoring management area according to the area coverage area; when video monitoring is transmitted through a network, different set areas of a monitoring management area are coded, abnormal feature points in a network video are identified according to video screening conditions, a video abnormal type report is generated according to the abnormal feature points, and identification is performed through a specific identification watermark of a campus; the method comprises the following steps: carrying out network connection on a student user side for searching through regional coding, obtaining student user side data to generate a student user behavior data analysis report, carrying out selective transmission through a campus privacy protection mechanism based on the campus privacy protection mechanism, achieving the purpose of carrying out health checking on a student user network video, and ensuring privacy and information security. And students are supervised and urged to construct good network video cognition.
Owner:INNER MONGOLIA UNIV OF SCI & TECH

Campus network traffic prediction method and system

The application discloses a campus network flow prediction method and system, relates to the technical field of flow prediction, and comprises the following steps: step one, historical flow analysis, step two, flow distribution and step three, flow scheduling. The flow information of each region in each time period in each historical preset period is analyzed, the total demand of the current period campus flow is predicted, the flow priority and the flow threshold of each region in each time period are obtained, the flow distribution of each region is carried out based on the flow priority of each region in each time period, the speed of each region in each time period is analyzed when the flow threshold is reached, the network management strategy is refined, the flow resource is dynamically adjusted, the network resource utilization is greatly improved, and finally, the flow of each region in each time period is scheduled, so that the on-demand distribution and dynamic optimization of the campus flow are ensured.
Owner:SHANDONG HAIKAN NEW MEDIA RES INST CO LTD

Two-stage park network ssh reverse tunnel detection method and system

ActiveCN116506209BSimulationCampus network
The present application relates to a kind of two-stage park network SSH reverse tunnel detection method and system, its method includes: S1: the original traffic collected is divided according to four tuples: {source ip, destination ip, source port number, destination port number}, and the original traffic with same four tuples is regarded as a flow;S2: one-stage SSH reverse tunnel detection based on rule matching, whether the flow contains SSH reverse tunnel is detected;S3: two-stage SSH reverse tunnel detection based on deep learning, after the flow is imaged, classification task is carried out using trained CNN model, whether the flow contains SSH reverse tunnel is judged;S4: the condition of flow containing SSH reverse tunnel obtained in step S2 and S3 is summarized, and detection result is output.The method provided by the present application can quickly and accurately detect the SSH reverse tunnel existing in park network.
Owner:BEIHANG UNIV

Network encryption attack detection method based on dual-source flow diagram fusion

The invention discloses a network encryption attack detection method based on dual-source flow diagram fusion, and the method comprises the steps: collecting IP-level data of campus network flow of a certain college, and carrying out the basic feature extraction of an original pcap flow packet; carrying out feature engineering on the extracted basic features, and carrying out malicious or benign preliminary screening through a random forest model; extracting IP node features and edge features from the benign traffic packets and the malicious traffic packets after preliminary screening; performing data processing on the extracted node features and edge features, and fusing the node features and the edge features into a graph; and executing real-time blocking through a firewall API according to the node malicious probability. According to the method, collaborative analysis is achieved through cross-graph fusion, ID conflicts are eliminated through a node offset mechanism to ensure topological fusion zero loss, the Markov edge features accurately capture an encrypted traffic behavior mode, the novel attack detection rate is improved by 46.5% compared with traditional single-graph modeling, and a brand new solution is provided for encryption threat detection.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Tenant broadband multi-access unified authentication cloud platform, system and method

The invention discloses a tenant broadband multi-access unified authentication cloud platform, system and method, and relates to the technical field of access authentication of a campus network. The tenant broadband multi-access unified authentication cloud platform comprises a tenant management module and at least one tenant module. The tenant management module is configured to receive request information, wherein the request information comprises identification information of tenants. Identifying identification information of the tenant included in the request information; and determining a corresponding tenant module according to the identification information of the tenant. And forwarding the request information to the corresponding tenant module. And the corresponding tenant module is configured to receive the request information and perform identity management, authority management, resource access control and resource access security auditing according to the request information. According to the invention, cloud centralized authentication and centralized dialing services are provided for multiple schools based on a tenant mode, multi-access multi-account unified management of campus broadband users is realized, and at the same time, intra-campus network access authentication platforms and intra-campus network dialing devices of the schools are eliminated.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Network intrusion detection method and system based on firewall

The invention relates to the technical field of data information transmission, in particular to a network intrusion detection method and system based on a firewall, and the method comprises the steps: determining a network instability time period in an association time period of a current moment, and carrying out the detection of the network intrusion according to the condition of a user in an online state at each moment in the network instability time period and the unstable condition of the total flow of a campus network; determining a suspected intrusion time period, obtaining the abnormal behavior intensity of each user according to the active moment of each user in the suspected intrusion time period and the correlation between the user traffic of the active moment and the total traffic of the campus network, and further obtaining the network intrusion risk of the suspected intrusion time period; according to the network intrusion risk of each suspected intrusion time period in the associated time period, the degree of network intrusion threat received at the current moment is obtained, the possibility of misjudgment can be greatly reduced, and therefore the accuracy of a campus network intrusion detection result is improved.
Owner:BEIJING BOHAN TECH CO LTD

Campus network flow anomaly detection method based on rule engine and graph neural network

The invention provides a campus network flow anomaly detection method based on a rule engine and a graph neural network, which comprises the following steps: acquiring original flow data of a campus network through a flow acquisition module, analyzing and extracting metadata information, and aggregating the metadata information into a flow record; the flow record is input to a rule engine module, flow is screened in real time through a rule set, and the rule set comprises rules predefined based on expert experience and rules generated based on a decision forest model; for the traffic which is not judged to be abnormal by the rule engine module, constructing a dynamic flow graph; inputting the dynamic flow graph into a dynamic graph neural network detection module, performing time sequence modeling and neighbor aggregation based on a memory vector of a node, and generating an abnormal score; and judging whether the flow is abnormal according to the abnormal score, and giving an alarm when the flow is judged to be abnormal. According to the scheme, through collaborative fusion of the rule engine and the dynamic graph neural network, efficient, accurate and adaptive campus network anomaly detection is realized, and the detection efficiency is effectively improved.
Owner:ZHEJIANG UNIV

Hop count triggering-based CSIG telemetering method, network forwarding equipment and system

The invention belongs to the technical field of network communication, provides a hop count triggering-based CSIG telemetering method, network forwarding equipment and a network forwarding system, and aims to solve the technical defects of message expansion and overhigh overhead of an existing IFA in-band measurement scheme and incapability of realizing full-path panoramic acquisition of a native CSIG aggregation scheme. According to the method, specific processing logic is deployed in network forwarding equipment, a CSIG label telemetering message carrying a novel protocol identifier NEW TPID is identified, decreasing operation is carried out on a collection trigger counter TTC, and nodes are triggered according to the TTC value to collect telemetering data and write the telemetering data into a label. The method can be applied to path node state collection and congestion monitoring of a data center network and a park network, and the lightweight characteristic and the refined operation and maintenance requirement are both considered.
Owner:格创通信(浙江)有限公司

Scripted dynamic scheduling system, method, computer device and storage medium

The application discloses a scripted dynamic scheduling system and method, a computer device and a storage medium. The system comprises a resource modeling module, which is responsible for resource modeling conforming to the ISA-95 standard, and maps an object model conforming to the ISA-95 standard into a data structure readable and writable by a script language based on reflection or binding technology; a script engine, which is used for executing scheduling algorithms and rule judgment; a data ferry module, which is used for transmitting scheduling script files as logical loads between a campus network and an industrial control network based on a network lock; a dynamic hot loading and non-inductive switching module, which is used for setting a file listener to monitor a specified directory, and when a new scheduling script file is detected through the file listener, a currently running script engine instance is destroyed and a new instance corresponding to the new scheduling script file and conforming to preset conditions is called when the next scheduling period comes, so that the service does not need to be restarted. The problems of long scheduling logic update period, high deployment cost and difficulty in responding to agile production in the prior art are solved.
Owner:SHANGHAI DINGGE INFORMATION TECH CO LTD

Privacy-enhanced campus network psychological data federated learning analysis method

The application discloses a privacy-enhanced campus network psychological data federated learning analysis method, and belongs to the field of network behavior data collection and privacy protection calculation. The method comprises the following steps: performing field white list projection, sensitive domain hard discarding, pseudo-anonymization and irreversible digest processing, and binning on each original network session collected in the campus network respectively to obtain a plurality of minimized event streams; performing semantic classification and feature extraction on each minimized event stream respectively to obtain a plurality of window statistical features; training a mental health assessment model based on the plurality of window statistical features, and generating a to-be-protected upload object of the i th round; and performing privacy protection processing on the to-be-protected upload object of the i th round to obtain a protected upload object of the i th round. The application can realize risk analysis and controlled uploading without outputting content load, reduce the risk of data leakage, and improve compliance controllability and credibility.
Owner:LANZHOU UNIV

A method and device for roaming authentication-free of a campus network

The present application relates to the technical field of campus network, and provides a method and device for roaming authentication exemption of campus network, which comprises the following steps: setting a roaming group for a terminal in an access cloud gateway in advance, each roaming group corresponding to a virtual ONU device; when receiving a first uplink message from a first terminal, judging whether the first terminal is an authenticated terminal in a roaming area of a first ONU device; if the first terminal is an authenticated terminal in the roaming area, encapsulating the second uplink message into a third uplink message recognizable by a wide area network according to the virtual ONU device related information in the roaming group to which the first ONU device belongs, and transmitting the third uplink message to the network. The present application sets a roaming group and a virtual ONU device, and generates WAN side information using the virtual ONU device related information, so that the whole roaming group appears to be only one ONU device to the outside, and further, repeated authentication is not needed, thus realizing roaming authentication exemption of campus network.
Owner:WUHAN GREENET INFORMATION SERVICE

A Method for Isolating Security Zones in a Campus Network Based on Streaming Authorization Label Verification

The present invention relates to a method for isolating security areas in a campus network based on flow authorization label verification, belonging to the technical field of network security research. Develop a security area isolation application for the campus network based on flow authorization label verification in the SDN controller. Establish a user database by collecting campus network user information, generate a unique authorization code for each user, and at the same time demarcate the range of security areas that the user is allowed to access in the campus network. After the SDN controller senses the user access, it issues an access control flow table based on flow authorization label verification to the access switch. The access switch performs access control on the user's communication in the specified security area according to the flow table, providing a guarantee for preventing users from illegally accessing campus network resources across security areas in the campus network.
Owner:QUAN CHENG LABORATORY

Network fault real-time predicting and positioning method based on multi-modal data fusion

The invention relates to the technical field of network operation and maintenance, in particular to a network fault real-time predicting and positioning method based on multi-modal data fusion, which comprises the following steps of: acquiring multi-source network data such as performance, flow and logs, and forming a multi-modal data set through space-time alignment and feature fusion; dividing multiple operation scenes of the campus network by using density peak clustering, and training a scene-based normal behavior baseline of each network entity through VAE; then calculating the mahalanobis distance recognition anomaly of the real-time fusion feature and the baseline, and outputting the fault probability and type in combination with the LSTM; then constructing a causal graph by using a PC algorithm, and determining candidate root causes by Bayesian reasoning; and finally, learning a node attention weight by using the GAT, generating an interpretable report in combination with the LLaMA-2, and outputting a positioning result. According to the method, accurate campus network fault prediction and interpretable positioning are effectively realized.
Owner:JIANGSU VOCATION & TECHNICAL COLLEGE OF FINANCE & ECONOMICS

PON system supporting multi-level slicing, OLT device and ONU device

The application provides a PON system supporting multi-level slices, an OLT device and an ONU device, and belongs to the technical field of communication. The system comprises an OLT device, an optical distribution network and an ONU device. The OLT device is decomposed into a vOLT management plane and a vOLT user plane through a virtual OLT technology. The OLT device is provided with a first-level network slice management module, and the ONU device is provided with a second-level network slice management module. The second-level network slice management module is used for dividing and managing the second-level network slice of the connected user terminal device. The network slice hierarchical capability is used for dividing the priority and network performance of each service in a large park network, solving the problems of single network slice division, insufficient granularity, inability to completely solve the problems of the concentration of various service types and different requirements, and realizing the intelligentization of the park network and reducing the deployment cost.
Owner:SHANDONG INSPUR SCI RES INST CO LTD

A firewall-based network intrusion detection method and system

The present application relates to the technical field of data information transmission, and particularly relates to a network intrusion detection method and system based on a firewall, which comprises the following steps: determining a network unstable period in a relevant period at a current time, determining a suspected intrusion period according to the situation of users in an online state and the unstable situation of total traffic of a campus network in the network unstable period, obtaining the abnormal behavior intensity of each user according to the active time of each user in the suspected intrusion period and the correlation between the user traffic of the active time and the total traffic of the campus network, and then obtaining the network intrusion risk of the suspected intrusion period; and obtaining the network intrusion threat degree at the current time according to the network intrusion risk of each suspected intrusion period in the relevant period. The present application can greatly reduce the possibility of misjudgment, thereby improving the accuracy of the network intrusion detection result of the campus network.
Owner:BEIJING BOHAN TECH CO LTD

Mental health assessment method based on dynamic time sequence hypergraph representation learning

The invention discloses a psychological health assessment method based on dynamic time sequence hypergraph representation learning, and belongs to the technical field of artificial intelligence and psychological health assessment. The method comprises the steps that according to campus network behavior data of a target student in an evaluation time period, a dynamic time sequence hypergraph of the target student is constructed, and the campus network behavior data comprises N pieces of access behavior data sorted according to timestamps; determining weight values of N hyperedges connecting a single time slice node, a single website category node and a single access strength node in the dynamic time sequence hypergraph, and updating initial features of each node in the dynamic time sequence hypergraph based on the weight values of the N hyperedges to obtain target features corresponding to each node; and determining rhythm characterization features and preference characterization features based on the updated dynamic time sequence hypergraph, and evaluating the mental health state of the target student according to the rhythm characterization features and the preference characterization features. The psychological health state of the student is objectively and effectively evaluated by analyzing the campus network behavior data of the student.
Owner:LANZHOU UNIV

Radio communication device for providing locally defined park network for industrial environment

PendingCN120419282ANetwork topologiesMobile entityCampus network
The proposed embodiments relate to a radio communication device for providing a locally defined park network for an industrial environment. The radio communication device may include one or more mobile entities including at least one radio unit for operating a radio front end that maintains the park network.
Owner:SIEMENS AG

Efficient security management and control method, system and equipment for park network and medium

The invention discloses an efficient security management and control method, system and device for a park network, and a medium. The method comprises the following steps: building a DHCP server, configuring an action range, an address pool and a security policy, and realizing dynamic binding of an IP and an MAC address; a DHCP relay and an SNOOPING function are configured in a switch, and equipment information is collected and synchronized to a firewall in combination with an SNMP service; an IP-MAC binding strategy, dumb terminal isolation and a dynamic verification mechanism are set in a firewall, terminal legality is compared through cross-three-layer detection, and abnormal traffic is intercepted. Through a triple binding mechanism, a dynamic filter and reserved address configuration, multi-factor authentication of a terminal identity is realized, and the network security defense capability is enhanced; iP address management efficiency and network stability are improved through dynamic allocation of DHCP service and address pool management in combination with SNMP real-time monitoring and a cross-three-layer detection mechanism; through a firewall IP-MAC binding strategy, dumb terminal isolation and a dynamic verification mechanism, terminal full life cycle management and control and refined flow control are realized.
Owner:GUIZHOU WUJIANG HYDROPOWER DEV

Smart campus network security operation integrated protection method and system

The invention provides a smart campus network security operation integrated protection method and system, and the method comprises the steps: collecting behavior data of terminal equipment, inputting the behavior data into a pre-constructed local risk scoring model, and generating a local risk score of each terminal equipment; performing privacy disturbance processing on the local risk score, and generating a risk situation map matrix according to region and role dimension aggregation; obtaining teaching rhythm vectors from an educational administration system, and converting the teaching rhythm vectors into strategy enhancement factors; calculating a strategy intervention score and matching a strategy template in combination with the risk situation map matrix and a strategy enhancement factor, and generating a strategy rule set; gathering the strategy rules into a structured instruction set, and adding an effective time constraint; and distributing the structured instruction set to terminal equipment for execution according to network equipment types and capability differences in the campus network. According to the invention, the safety operation efficiency and the strategy response precision in a smart campus network environment are obviously improved.
Owner:GUANGDONG POLYTECHNIC OF IND & COMMERCE +1

Method for application class of service in zero trust campus network

Disclosed herein are system, method, and computer program product aspects for providing packets from an agent-based zero trust network access (ZTNA) user device class of service in a campus network. Some aspects of this disclosure relate to a user equipment (UE) including a memory and a processor. The processor is configured to generate a packet that include a payload and an inner header and generate an encrypted packet by encrypting the packet. The processor is further configured to generate a combined packet based on the encrypted packet and an outer header. The outer header indicates a class of service corresponding to the packet. The processor is further configured to transmit the combined packet to a campus network via a secured tunnel.
Owner:EXTREME NETWORKS INC

Flow control method, routing forwarding device, storage medium and program product

The embodiment of the invention discloses a flow control method, a routing forwarding device, a storage medium and a program product, and belongs to the technical field of communication. In the embodiments of the present application, after a first routing forwarding device in a park network classifies and caches messages in traffic from a second routing forwarding device in an operator network to a plurality of queues, first packet loss information and second packet loss information are obtained, the first packet loss information is used for indicating packet loss conditions of the plurality of queues, and the second packet loss information is used for indicating packet loss conditions of the plurality of queues. The second packet loss information is used for indicating the packet loss condition at the second routing forwarding equipment. The queue speed limit of each queue is dynamically adjusted according to the first packet loss information and the second packet loss information, so that the queue speed limit corresponding to each queue can better conform to the real situation of the flow in the current network, and the flow control effect is improved. Compared with the method for configuring the queue speed limits of different queues only according to the signed bandwidth, the flow control method provided by the embodiment of the invention is higher in flexibility, so that the flow control effect is better.
Owner:HUAWEI TECH CO LTD