Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

176 results about "Software define network" patented technology

Software defined networking (SDN) allows network engineers to support a switching fabric across multi-vendor hardware and application-specific integrated circuits. A network administrator can shape traffic from a centralised control console without having to touch individual switches.

Security authentication method, device and system of test platform, and storage medium

The embodiment of the invention provides a security authentication method, device and system for a test platform, and a storage medium, and relates to the technical field of network security. The method comprises the following steps: performing fingerprint acquisition on virtual and real equipment to generate a unique identifier, dynamically slicing based on a software defined network to form an isolated test environment, and injecting a zero-trust access strategy associated with the fingerprint; and based on the zero-trust access policy and the device fingerprint, allocating a minimum permission through an attribute-based access control model, continuously evaluating device behaviors to calculate a dynamic trust score, and adaptively updating the permission according to the trust score. By constructing a full-process security certification system and through multi-dimensional mechanism cooperation, dynamic risk perception and timely strategy adjustment, fine-grained control of virtual and real equipment access in an industrial control scene is realized, the dynamic adaptability and risk resistance of a test platform in a complex network environment are improved, and the test efficiency is improved. Equipment access safety, authority distribution minimization and behavior monitoring continuity are ensured, and the safety risk of the industrial control system is reduced.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Intelligent auxiliary and artificial intelligence visual gateway control method and system for station building

The invention relates to the technical field of power distribution station supervision, in particular to an intelligent auxiliary and artificial intelligence visual gateway control method and system for a station building, which monitors network state parameters in real time, calculates a network quality score and dynamically selects an optimal transmission path based on a reinforcement learning algorithm. Comprising a high bandwidth mode, a low delay mode and a disaster recovery backup mode, stage processing and dynamic compression are performed on transmission data according to data types and network quality scores, link switching and a local caching mechanism are automatically triggered when a network is abnormal, and finally, multi-gateway load balancing and visual monitoring are realized through a software defined network architecture. The problem of transmission delay or interruption caused by the fact that a static data transmission framework cannot adapt to network state changes in the prior art is effectively solved, and the reliability and the real-time performance of data transmission are remarkably improved through dynamic path optimization, intelligent hierarchical transmission and a fault self-healing mechanism.
Owner:ZHEJIANG WELLSUN INTELLIGENT TECH CO LTD

SDN (Software Defined Network) inter-domain traffic engineering method based on reinforcement learning

The invention provides an SDN (Software Defined Network) inter-domain traffic engineering method based on reinforcement learning, which comprises the following steps of: deploying a data traffic demand monitoring platform and a control system, and constructing a global network topological graph; calculating a short link identifier for the link in the network and distributing the short link identifier to each network device; flow judgment is carried out, upward notification is carried out according to requirements, and pre-operation of intelligent routing is cooperatively completed; deploying a reinforcement learning model in the total intelligent body, outputting an optimal cross-domain path strategy to the cooperative controller, disassembling the optimal cross-domain path strategy into flow table rules which can be executed by each domain, and issuing the flow table rules to local controllers of related domains; and each local controller pushes the flow table configuration to the domain switching equipment to complete the forwarding decision of the flow. According to the method, a complete closed-loop process of flow measurement, intelligent decision making, cross-domain control and path issuing is realized, feasible reference is provided for actual deployment of an intelligent network, and the method has good engineering popularization value and is suitable for intelligent scheduling scenes such as an operator backbone network, an industrial internet and metro edge cloud.
Owner:NANJING UNIV OF POSTS & TELECOMM

Distributed medical equipment management platform and method based on zero-trust network

The embodiment of the invention provides a distributed medical equipment management platform and method based on a zero-trust network. In the distributed medical equipment management platform based on the zero-trust network, an edge trusted access module adopts a hardware root of trust mechanism, so that equipment accessed for the first time is connected to a temporary supply network isolated from a medical core network, and a zero-trust security normal form is followed; the distributed trust anchor point cluster constructs a distributed identity verification network based on federated learning, and the access pre-authorization authority is verified through a device distributed identity identification (DID); the dynamic permission arrangement engine injects an attribute-based access control strategy, generates a permission token in combination with network micro-segmentation, and realizes two-way encryption communication between the equipment and a target service; the intelligent isolation gateway cuts off temporary connection through a software defined network technology and sends a network access state proof through a block chain mechanism, and edge module initialization is executed by a trusted node outside the medical cloud.
Owner:GENERAL HOSPITAL OF PLA

Communication network bandwidth resource visual dynamic allocation method and system based on SDN (Software Defined Network)

The invention discloses a communication network bandwidth resource visualized dynamic allocation method and system based on an SDN, and relates to the technical field of communication networks, and the method comprises the steps: obtaining the channel interference intensity, the spectrum occupancy rate and the service flow priority data of each node in a wireless network based on a southbound interface of an SDN controller, and obtaining the channel interference intensity, the spectrum occupancy rate and the service flow priority data of each node through a channel resource dynamic allocation table; generating a multi-dimensional resource view; according to the multi-dimensional resource view, multi-level coverage domains of the wireless network are divided, the service load level of each coverage domain is identified, and a pre-allocation scheme of cross-domain bandwidth resources is generated; and executing a pre-allocation scheme of cross-domain bandwidth resources by using a northbound interface of the SDN controller, and adjusting bandwidth allocation parameters of each coverage domain. According to the invention, visual monitoring, accurate division and flexible scheduling of the network resource state are realized, and the utilization efficiency of network bandwidth resources is remarkably improved.
Owner:HUAIAN COLLEGE OF INFORMATION TECH +1

Cooperative data migration scheduling method based on topology awareness and deep reinforcement learning

The invention provides a collaborative data migration scheduling method based on topology awareness and deep reinforcement learning, and the method comprises the steps: initializing system configuration, constructing a weighted graph comprising a source server, a working machine, a target storage and network equipment, carrying out the embedded processing of a graph structure through a graph neural network, and generating a node and a path representation vector; in combination with source data, a working machine and a target storage state, constructing a system state vector, inputting the system state vector into a deep reinforcement learning agent for decision making, and outputting a composite action including data block selection, working machine selection, path indexing and migration rate suggestion; the network control module converts path information into flow rules, the flow rules are issued and executed through the software defined network controller, the task management module continuously monitors the migration state and processes failed data blocks, and the integrity and non-repeatability of migration tasks are ensured. According to the method, the defects of an existing data migration system in the aspects of task allocation, path selection, resource control and dynamic adaptability can be overcome.
Owner:JINAN INSPUR DATA TECH CO LTD

Optimization system and method for SDN (Software Defined Network) traffic engineering

The invention discloses an optimization system and method for SDN traffic engineering, and the method specifically comprises the following steps: S1, obtaining a traffic matrix in a network, and representing the network topology as a graph structure; s2, inputting the traffic matrix and the graph structure into a constructed feature extraction model, and outputting a feature vector; s3, inputting the feature vector into a deep reinforcement learning model for iterative optimization, and outputting an initial flow distribution proportion strategy; and S4, performing constraint optimization on the initial flow distribution proportion strategy, and outputting a final flow distribution strategy.
Owner:CHONGQING UNIV

Smart campus Internet of Things multi-service collaborative scheduling control system based on all-optical network

The invention discloses a smart campus Internet of Things multi-service collaborative scheduling control system based on an all-optical network, and relates to the technical field of Internet of Things, and the system comprises an Internet of Things digital platform which is in communication connection with the following modules: an all-optical network infrastructure module which is used for constructing an optical fiber backbone network in a campus, and each subsystem in the campus is accessed. The reliability and stability of the campus Internet of Things are enhanced by constructing all-optical network infrastructure, the subsystems are directly connected through optical fibers by adopting the passive optical network technology, and the use of active equipment is reduced, so that the equipment failure rate and the maintenance cost are reduced, optical wavelength resources are dynamically allocated by utilizing a software defined network controller, and the reliability and the stability of the campus Internet of Things are improved. The transmission path is adjusted according to the service priority, efficient operation of key services is ensured, network stability is improved, high speed and safety of data transmission are guaranteed, and solid network support is provided for various intelligent applications in the campus.
Owner:CHINA SHANXI SIJIAN GRP

Route synchronization method, device, system and equipment among multiple SDN (Software Defined Network) clusters and medium

The invention relates to the technical field of communication, and discloses a route synchronization method, device, system and equipment among multiple SDN clusters and a medium, and the method comprises the steps: obtaining neighbor configuration information issued by a central controller based on a target BGP service; establishing a neighbor relationship between the target BGP service and other BGP services according to the neighbor configuration information; obtaining first node address information of a target SDN cluster collected by the target SDN controller based on the target BGP service, and generating first routing information; and sending the first routing information to other BGP services which establish the neighbor relationship. According to the invention, the BGP service and the SDN controller are utilized to realize the coordination of the control planes, the BGP service and the SDN controller form a double-layer control plane, and the double-layer control plane is utilized to issue the routing forwarding strategy, so that flooding on the data plane is effectively avoided, and the routing synchronization efficiency is improved.
Owner:NEW H3C CLOUD TECH CO LTD

Method and system for deep packet inspection in software defined networks

A method for deep packet inspection (DPI) in a software defined network (SDN). The method includes configuring a plurality of network nodes operable in the SDN with at least one probe instruction; receiving from a network node a first packet of a flow, the first packet matches the at least one probe instruction and includes a first sequence number; receiving from a network node a second packet of the flow, the second packet matches the at least one probe instruction and includes a second sequence number, the second packet is a response of the first packet; computing a mask value respective of at least the first and second sequence numbers indicating which bytes to be mirrored from subsequent packets belonging to the same flow; generating at least one mirror instruction based on at least the mask value; and configuring the plurality of network nodes with at least one mirror instruction.
Owner:ORCKIT CORP

Software defined network (SDN)- based domain name system (DNS) resolution for a non-SDN service

The present disclosure relates generally to an SDN providing DNS resolution for a non-SDN service. In particular, the SDN hosts a first endpoint communicatively coupled with the non-SDN service. The SDN also hosts a DNS proxy in support of a second private network of a customer. A second endpoint of the customer can be accessible via the second private network The non-SDN service can send a DNS resolution request (that includes, for example, an FQDN of the second endpoint) to the first endpoint. The first endpoint forwards this request to the DNS proxy. In turn, the DNS proxy determines the IP address of the second endpoint and returns a reserved IP address corresponding to the DNS proxy and mapped to the second endpoint's IP address. The first endpoint sends this DNS resolution to the non-SDN service that then learns that the FQDN is resolved to the reserved IP address.
Owner:ORACLE INT CORP

SDN controller load balancing method based on graph neural network and evolutionary algorithm

The invention relates to the technical field of computer network optimization and controller load balancing, and discloses an SDN (Software Defined Network) controller load balancing method based on a graph neural network and an evolutionary algorithm. Constructing a graph model and splicing to obtain a feature matrix; normalizing an adjacent matrix, performing feature aggregation and updating on a feature matrix by using a multilayer graph convolutional network, outputting a high-dimensional embedded vector, setting a final state representation and reward function of a controller, and obtaining a scheduling strategy adapted to a dynamic network environment through meta-reinforcement learning and actor reviewer network training; performing global search on parameters of meta reinforcement learning in a simulation environment to find an optimal solution; the method comprises the following steps: acquiring the newest state of each controller in real time, updating and embedding through a pre-trained GCN, outputting a scheduling strategy by using a trained meta-reinforcement learning model according to a global state, and performing online parameter fine tuning and updating on a network by using Q-learning at the same time.
Owner:QINGCHUANG WANGYU (HEFEI) TECH CO LTD +1

Flow control method, device and equipment based on SDN (Software Defined Network) and medium

The invention discloses a flow control method and device based on an SDN, equipment and a medium, and belongs to the technical field of communication. The method comprises the following steps: optimizing a strategy-evaluation network based on real-time network state information of the SDN to obtain an original traffic strategy of a tunnel output by the optimized strategy-evaluation network, the original traffic strategy comprising a demand traffic corresponding to the tunnel of the SDN and an original traffic distribution proportion of each path in the tunnel, the strategy-evaluation network is used for maximizing accumulated rewards and ensuring random exploratory performance of a flow strategy, and reinforcement learning is carried out on the flow strategy with better QoS in a complex network state environment; under the condition that the MLU corresponding to the original flow strategy exceeds a preset safety threshold value, searching a flow distribution proportion meeting an MLU safety condition in a local flow distribution proportion area containing the original flow distribution proportion as a safety flow distribution proportion; and controlling the traffic distribution of each path in the tunnel in the SDN according to the safe traffic distribution proportion. According to the embodiment of the invention, the stability of the SDN can be improved.
Owner:CHINA UNIONPAY

Disaggregation of TIER1 devices in an SDN using SmartSwitches

Techniques are disclosed for processing data packets and implementing policies in a software defined network (SDN) of a virtual computing environment. At least one network device is configured to disaggregate enforcement of policies of the SDN from hosts of the virtual computing environment. Tier-0 devices are communicatively coupled to network interfaces of the network device. The network device comprises a plurality of data processing units that are configured to implement functionality of the network device.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Hybrid SDN link fault protection method based on key network elements

The invention discloses a hybrid SDN (Software Defined Network) link fault protection method based on key network elements, and belongs to the technical field of Internet technologies. According to the method, the LFC rule is used for remarkably reducing the number of target nodes affected when the link fails, conventional candidate SDN node judgment is optimized, the number of the candidate SDN nodes is increased, and finally, the minimum number of SDN switch nodes are flexibly selected according to key network elements. According to the scheme provided by the invention, the problem of most single link faults in the network can be solved, the path stretching degree is relatively small, the deployment cost is relatively low, and the network oscillation and delay are relatively low. Therefore, the invention provides an effective solution for improving the protection efficiency of the hybrid SDN link fault.
Owner:SHANXI UNIV

Advanced network threat intelligent detection and defense system

The invention discloses an advanced network threat intelligent detection and defense system and method in the technical field of network defense. The system comprises a data acquisition module which analyzes encrypted traffic through a deep packet inspection technology and marks space-time metadata; the feature extraction module is used for constructing a node behavior association graph by adopting a multi-scale sliding window and a graph neural network; the detection engine module integrates multi-model parallel analysis of LSTM, random forest and the like, and dynamically fuses detection results through an entropy weight method; and the defense execution module is used for realizing flow cleaning and virtual trapping node deployment based on an SDN (Software Defined Network) technology. The method comprises the steps of protocol extension field reverse analysis, covert channel time sequence correlation analysis and dynamic network topology adjustment. According to the method, the encryption APT attack detection accuracy reaches 98.7%, the false alarm rate is reduced to 0.15%, the defense strategy effective time is shorter than 1 second, and the method is suitable for complex network environments such as cloud computing and industrial Internet of Things.
Owner:GUOANYUN (XIAN) TECH GRP CO LTD

Self-adaptive self-coordination unified communication system and method based on SDN (Software Defined Network)

The invention discloses a self-adaptive and self-coordinated unified communication system and method based on an SDN, and relates to the field of coordinated communication, and the method comprises the steps: collecting network state data of a switch, extracting traffic chaos features through a lightweight chaos analysis algorithm, generating a traffic feature vector, generating a network management threshold based on the traffic feature vector, and carrying out the dynamic adjustment, updating a flow table, generating a resource state log, evaluating cross-domain network congestion according to the resource state log, calculating a congestion index, generating a key through a quantum key distribution unit, dynamically adjusting a key update frequency and distributing the key update frequency to a cross-domain switch, recording a key distribution log, and using the key distribution log and a real-time network state to determine the congestion of the cross-domain network. Detecting network abnormity, defining as an antigen, running an antibody generation algorithm to generate a repair strategy, and storing as an antibody record; according to the method, the traffic feature vector is generated through the chaos analysis algorithm, potential congestion or abnormity can be detected earlier, and the dynamic adaptability of a cross-domain network is improved.
Owner:HONGXI (TAIZHOU) TECH CO LTD

SDN routing method and architecture based on graph attention mechanism and dynamic priority playback

ActiveCN120321167ABiological modelsTransmissionTactical communicationsPathPing
The invention discloses an SDN (Software Defined Network) routing method and architecture based on a graph attention mechanism and dynamic priority playback. The method comprises the following steps: acquiring network equipment and link states in real time; generating an alternative path set based on a shortest path algorithm; constructing a GAT-DPR model structure, taking the state information of the alternative paths as input, training the model structure, fusing a graph attention mechanism and a dynamic priority playback technology, optimizing the training efficiency of a strategy network, and obtaining an optimal routing strategy; the optimal routing strategy is converted into a flow table to be issued to a data layer, and flow forwarding is completed; and a network topology sensing module, a network state detection module, an initial path calculation module, a path optimization module and a path installation module in the control layer complete corresponding operation steps. Compared with an existing algorithm, the GAT-DPR algorithm provided by the invention has obvious advantages in the aspects of improving throughput and reducing time delay and packet loss rate, and an innovative solution is provided for efficient routing decision-making of a tactical communication network.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

SDN industrial network routing method based on deep traffic classification and dynamic pheromone optimization

The invention relates to the technical field of industrial network communication, in particular to an SDN (Software Defined Network) industrial network routing method based on deep traffic classification and dynamic pheromone optimization. According to the method, an SMOTE algorithm is improved, a target sub-region is selected through an adaptive boundary to perform oversampling to balance sample data, the problem of flow imbalance of the SDN multi-access interconnection architecture is solved, meanwhile, a CNN-LSTM model fused with an attention mechanism is established, and depth feature extraction is performed on samples after the samples are balanced so as to meet dynamic features of the flow in a short sequence.
Owner:JIANGSU KEREAD INTELLIGENT CONTROL AUTOMATION TECH CO LTD

Networks Comprising Multi-Quantum Blockchain Systems, Methods, And Products

Systems, methods and products for blockchain distributed networks, including software defined networks, are provided, that include a management plane blockchain for distributing public keys and other management functions, a control plane blockchain for configuring how to communicate data, and a data plane blockchain to communicate data, including private keys, that each interact with artificial intelligence and use quantum generated random numbers for encrypted keys and other processes, and which can be controlled by human users, artificial intelligence users, or a combination of both users.
Owner:EDGIN TIMOTHY

Satellite network mobility management system and method based on SDN

The invention provides a satellite network mobility management system and method based on an SDN, and relates to the technical field of satellite network communication management, the system comprises a space unit, a ground unit and a user unit, the space unit comprises a plurality of satellites with a data forwarding function, the satellites are deployed in a plurality of position management areas, and the space unit comprises a plurality of user units; a network switch is deployed on each satellite, and a satellite in each position management area is used as a local SDN controller; the network switch processes the data packet from the user unit according to the flow table item in the local flow table; the ground unit comprises a global SDN (Software Defined Network) controller, and the global SDN controller communicates with the local SDN controller and carries out global management on the information of the user equipment; and the user unit comprises a plurality of pieces of user equipment, and the user equipment communicates with the network switch. According to the invention, the signaling overhead is effectively reduced, the data transmission path optimization is realized, and the data transmission path switching delay is shortened.
Owner:CHINA ELECTRONICS TECH GRP NO 7 RES INST

A software defined network system

The application discloses a software defined network system, which comprises a BGP proxy component, an SDN controller, a plurality of gateway devices not supporting a BGP protocol and computer nodes; the BGP proxy component is used for establishing a BGP session with the SDN controller and announcing routing information of the plurality of gateway devices to the SDN controller through the BGP session; the SDN controller is used for generating node-side data plane configuration information based on the received routing information and delivering the node-side data plane configuration information to the computer nodes; and the computer nodes are used for configuring a forwarding table and / or tunnel encapsulation parameters of a virtual switch on the nodes according to the received node-side data plane configuration information. The application reduces the complexity of networking.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Delay information query method and device, equipment, readable storage medium and product

The present disclosure provides a latency information query method, device, equipment, readable storage medium and product, the method comprises: obtaining the latency query request sent by a lightweight network management platform; determining the query times and the query latency interval according to the query constraint information; according to the latency query request, sending the query request matched with the query times to the preset software defined network controller according to the query latency interval; obtaining the query result fed back by the software defined network controller, determining the target latency data between the starting end information and the terminal end information according to the query result, and the query result includes at least one path information matched with the query constraint information. Through limited query times, the query result including all circuit path information data meeting the query constraint information provided by the user can be queried, different circuit path options are provided for the user, and the efficiency and accuracy of the latency information query are improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

A hospital multi-active data center network management system based on software defined network

The application discloses a hospital multi-active data center network management system based on a software defined network, relates to the technical field of data management, and discloses a network management system controlled based on an SDN controller, which comprises a traffic collection module, a prediction module, a scheduling module, a multi-active data module and a security module; the traffic collection module is used for collecting historical traffic data of a hospital, analyzing and managing the acquired traffic data, obtaining historical data of traffic loads of various devices of the hospital, and storing the data; the prediction module predicts future traffic loads of devices of the hospital based on historical data acquired in the traffic collection module and uploads the prediction result to the scheduling module; the application can predict future traffic loads of devices of the hospital, reasonably distribute network traffic to various data centers and corresponding servers according to the prediction result, flexibly configure the network, quickly adjust the distribution of network resources, and improve the medical experience of patients.
Owner:THE SECOND AFFILIATED HOSPITAL OF NANJING MEDICAL UNIV

Dynamic white list management method and system based on immune-kalman collaborative evolution

The present application relates to the technical field of information security, and more particularly to a dynamic white list management method and system based on immune-Kalman collaborative evolution, which comprises the following steps: receiving the observation data of the service access request collected and sent by the edge access gateway; predicting and updating the state vector of the current service baseline through the Kalman filter state estimator to obtain the prior state prediction value and the prediction residual; dynamically adjusting the "self-non-self" judgment threshold of the immune system, if it is judged as self, the characteristics of the service access request are fed back to the Kalman filter state estimator as observation samples and updated; if it is judged as non-self, an isolation instruction is generated and sent to the software defined network controller, and a denial of access instruction is sent to the edge access gateway; based on the prediction residual and the comprehensive health degree index, the running state of the system is judged, and the corresponding matching strategy is selected from the preset white list matching strategy set and sent to the edge access gateway for execution.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Network traffic load balancing method based on reinforcement learning

The application discloses a network traffic load balancing method based on reinforcement learning, comprising the following steps: 1) a software defined network (SDN) controller acquires switch flow table information, constructs an end-to-end traffic matrix and a network topology; 2) based on the network topology and the traffic matrix, a linear programming model is used to solve an optimization problem with the minimum maximum link bandwidth utilization as the target, and the result is stored in a database in the form of data pairs; 3) a reinforcement learning model with the optimal bandwidth utilization and the minimum service disturbance as the target is established, and data in the database is extracted for training; 4) actual traffic forwarding requirements are collected and sent into the reinforcement learning model to obtain a key data flow set, and a linear programming model is used to solve a key data flow rerouting scheme; 5) the rerouting scheme is parsed into a transmission path; and 6) the network configuration is updated according to the transmission path, and the link load is optimized. The application has good application prospects while realizing load balancing and taking the influence on services into account.
Owner:SOUTH CHINA UNIV OF TECH

Facilitation of deep service path discovery for 5g or other next generation network

PendingUS20250301394A1Network traffic/resource managementTransmissionPathPingAlert correlation
A software defined network (SDN) can add network repository functions (NRF) into a configurations database to enable NF discovery. The SDN can subscribe to NRF notifications to receive new cloud native functions (CNF), registrations, or any other update to the CNF status in 5G system. In addition to listening to NRF notifications, the SDN can implement CNF pooling processes to periodically retrieve CNF from an NRF repository and stay in sync with 5G systems. Thus, a deep service path discovery can be developed from network service configurations and container call flows to enable an accurate alarm correlation and troubleshooting for the operations. This service path deep discovery can be designed and implemented as a standalone system or in an SDN framework with integration of a container management framework such as K8 kubernetes.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Efficient state replication in SDN networks

Transmission Control Protocol (TCP) states of an active device are replicated at a backup device configured to track connections in a software defined network (SDN). The backup device receives, from the active device, a TCP packet with a TCP flag including one or more of SYN, SYN-ACK, ACK, FIN, FIN-ACK, ACK, or RESET. When the TCP packet has a SYN flag, the backup device adds a connection record to a connection table. Otherwise, the backup device derives an updated connection state for the connection record using a TCP state machine. The connection state is updated as future packets are received by the backup device.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Network flow table automatic analysis method and system based on OpenFlow technology

The invention provides a network flow table automatic analysis method and system based on an OpenFlow technology, relates to the technical field of operation and maintenance of a cloud computing data center network and a software defined network, and aims to carry out automatic routing inspection and positioning aiming at the problems of missing, repetition and inconsistency of a CVK host flow table at a bottom layer of a cloud platform. The method comprises the following steps: inputting target CVK host access information and carrying out connectivity and authentication verification; traversing virtual machine network information on the CVK host, connecting the Redis to query security group information associated with a virtual network card, and detecting missing of a security group flow table; the offline state of the network-cvk-agent service is checked, whether the network-cvk-agent service is caused by missing of a basic flow table of a network port or not is positioned in the offline mode, and missing information is output; detecting repetition and inconsistency of the basic flow table when the basic flow table is not offline or not missing; and finally, all task results are summarized and output to a console, and repair guidance is provided in a knowledge base link form, so that operation and maintenance personnel are helped to quickly position root causes and recover businesses.
Owner:UNICLOUD TECH CO LTD

SDN controller network domain division method based on MPLS network

The invention discloses an SDN (Software Defined Network) controller network domain division method based on an MPLS (Multi-Protocol Label Switching) network, which comprises the following steps: (1) MPLS configuration item resource static planning: carrying out static range division according to a hardware resource condition, the number of actually required domain division and an actual condition of an actual multi-department network management monitoring permission; (2) deploying controllers according to domains: the SDN controller obtains whole network topology data through equipment directly connected with the SDN controller, the equipment directly connected with each domain controller is different, and the controllers between the domains do not influence each other and work independently; (3) deploying network management software: each piece of network management software is only allowed to issue an instruction to the controller in the respective domain, and the network management software running in the network does not influence each other and independently works; and (4) realizing network domain division. According to the invention, in the SDN architecture, a domain-divided networking mode is provided for centralized networking, so that the requirements of multi-department network management monitoring or different services and authority are met, and the network stability and the operation and maintenance efficiency are improved.
Owner:THE 34TH RES INST OF CHINA ELECTRONICS TECH CORP