Background technology
Along with continuous advancement in technology, SOHO (Small Office and Home Office, Small Office and Home Office) has become a kind of pattern of modern handle official bussiness.Be accompanied by the development of SOHO, also move towards popular gradually towards the mininet of small office and family.But the means that mininets such as SOHO network and home network are linked into public network are still single, needs that can not satisfy users slowly and the operator demand of commencing business.
The user of a lot of mininets is usually based on cost consideration; can't buy catenet equipment; but buy soho router, HGW (Home Gate Way; home gateway) or even ADSL MODEM; but these equipment; can't well support a plurality of Operation Networks, perhaps the multi-stage service network of an Operation Network.
For example, mininet is to be formed by connecting by the terminal in a plurality of offices, is connected to public network by a HGW or soho router.But a plurality of offices carry out business of networking by different operators;
Again for example, in home network, be connected to public network by a HGW or ADSL MODEM, but operator may carry out multiple business for the domestic consumer, such as Server business in IPTV (Internet video) business, VoIP (voice-over-net) business, data service, Smart Home business, the family, or the like;
In the prior art, when these demands of solution and problem, if traditional ADSL MODEM mode, ADSL MODEM is by a transparent bridge, home network or SOHO network insertion are arrived public network, obtain public network address by home network or the dialing of SOHO network-internal apparatus, ADSL Modem only does two layers of forwarding.The same time period of this mode can only have an equipment to be connected to public network, can't realize that the same time period of a plurality of equipment is connected to public network jointly.
If adopt high-end ADSL MODEM or HGW formula, by ADSL MODEM or HGW dialing, hang a plurality of household internal equipment below again, equipment distributes private net address by HGW in the family, HGW arrives public network by routing forwarding and network address translation with device forwards in a plurality of families of mininet.This mode can have a plurality of equipment to be connected to public network, but can't solve the needs of same operator more business operation, more can't solve the solution needs of a plurality of operators, because these operations need to have on the HGW a plurality of public network outlets usually, need HGW that the powerful traffic identification and the ability of pathfinding (the public network interface of selecting away automatically) are provided.
Summary of the invention
The object of the present invention is to provide a kind of method and apparatus, can make mininet be connected to a plurality of professional subnet of a plurality of public networks or a public network by this equipment.
It is a kind of for mininet provides the method for a plurality of public network services that one aspect of the present invention provides, and comprising: (a) receive business data flow from described mininet or public network; (b) the pairing type of service of the described business data flow of identification produces recognition result; (c) search the network strategy corresponding with this recognition result in the network strategy of the many levels in the hierarchical network policy configurations table according to described recognition result, the networking strategy of described many levels is corresponding with described a plurality of public network services; (d) described business data flow is carried out described network strategy; (e) described business data flow is sent in described public network or the mininet.
Preferably, step (b) comprising: (b1) consult the traffic classification table, mate the service parameter of described business data flow; (b2) according to the value parameter of described service parameter generation as recognition result.
It is a kind of for mininet provides the equipment of a plurality of public network services that the present invention provides on the other hand, and comprising: receiving element is used for receiving business data flow from described mininet or public network; With the recognition unit that described receiving element couples, be used to discern the pairing type of service of described business data flow and produce recognition result; Hierarchical network policy configurations table is used to store the network strategy of many levels, and the networking strategy of described many levels is corresponding with described a plurality of public network services; Search the unit with described recognition unit and hierarchical network policy configurations table couple, be used for searching the hierarchical network policy configurations table network strategy corresponding with this recognition result according to described recognition result; Search the performance element that the unit couples with described, be used for described business data flow is carried out described network strategy; With the transmitting element that described performance element couples, be used for described business data flow is sent to described public network or mininet.
Preferably, also comprise:, be used for storage and described a plurality of public network service corresponding service parameters with the traffic classification table that described recognition unit couples; Described recognition unit comprises consults the unit, is used to consult the traffic classification table, mates the parameter of described business data flow; Described recognition unit also comprises with described consults the generation unit that the unit couples, and is used for according to the value parameter of described parameter generating as recognition result.
This method and apparatus provided by the invention by discerning different business data flows, thereby triggers different network strategy, the business in the corresponding public network of each network strategy.By making up the Policy Table of classification, mininet possessed connect the different different business in the public networks or the abilities of the different business in the same operation public network of runing.
Embodiment
With reference to figure 1, illustrate a kind of enforcement environment that the method for a plurality of public network services is provided for mininet provided by the invention.As shown in the figure, SOHO network 100 is a kind of mininets, can comprise a plurality of users, for example user among the figure 101 and user 105.Each user can comprise a plurality of user terminals again, is used to use a plurality of Networks.For example user 101 comprises PC (personal computer) 102, IAD (integrated access equipment)/PHONE (phone) 103 and STB (set-top box) 104 among the figure; 105 of users comprise PC106, IAD/PHONE107 and STB108.What deserves to be explained is that the user can also comprise other user terminal, also may have only a user terminal.Number of users also is not limited only to two among the figure, and these numbers do not influence enforcement of the present invention.And mininet also may comprise home network.
With reference to figure 1, described SOHO network 100 is connected with a plurality of (for example two) Operation Network by intelligent HGW200, for example Operation Network among the figure 301 and Operation Network 305.Operation Network 301 may further include data network 302, voip network 303 and video network 304 again.And Operation Network 305 also may further include data network 306, voip network 307 and video network 308.Each Operation Network provides a kind of business.What deserves to be explained is that Operation Network can be a plurality of among the figure, also can be one, and these numbers can not be regarded the restriction to claim of the present invention as.
With reference to figure 1, the situation of service application may be: 1, user 101 PC102 uses the business that the data network 302 of Operation Network 301 provides; The business that the voip network 303 of user 101 IAD/PHONE103 application Operation Network 301 provides; The business that the video network 304 of user 101 STB104 application Operation Network 301 provides.Correspondingly, each terminal of user 105 is then used the various corresponding business that Operation Network 305 provides.2, user 101 PC102 uses the business that the data network 302 of Operation Network 301 provides; The business that the voip network 307 of user 101 IAD/PHONE103 application Operation Network 305 provides; The business that the video network 304 of user 101 STB104 application Operation Network 301 provides.Or the like.That is to say that the user in the SOHO network 100 both can use the different business that identical Operation Network provides, also can use the different business that different Operation Networks provide.
With reference to figure 1, no matter which kind of the situation of applied business is, the business datum of contact all will be transmitted by intelligent HGW200 between SOHO network 100 and Operation Network 301 and 305.This intelligence HGW200 is exactly an equipment provided by the invention.
With reference to figure 2, described intelligent HGW200 comprises I/O interface 201, and this I/O interface 201 is used for carrying out data contacts with the external world, for example and carry out the data contact between SOHU.com's network 100 or the Operation Network 301.Described intelligent HGW200 also comprises receiving element 202 and the transmitting element 206 that connects with described I/O interface 201 lotus roots, is used for respectively handling receiving and send data.Also has recognition unit 203 with receiving element 202 lotus roots connect.Search unit 204 with recognition unit 203 lotus roots connect.With search that unit 204 lotus roots connect performance element 205 arranged.Performance element 205 connects with described transmitting element 206 lotus roots.Described intelligent HGW200 also comprise the traffic classification table 208 that connects with recognition unit 203 lotus roots, with search the tree network policy configurations table 207 that unit 204 lotus roots connect.Described tree network policy configurations table 207 is a kind of hierarchical network policy configurations tables.Described intelligent HGW200 can also comprise the collision detection unit 209 that connects with receiving element 202 lotus roots, also has configuration memory cell 210 with these collision detection unit 209 lotus roots connect.Configuration memory cell 210 couples with configuration data table memory 211.Also comprise Command Line Parsing unit 212, itself and traffic classification table 208 and tree network policy configurations table 207 lotus root connect.
With reference to figure 4, illustrate a kind of business data processing flow process that the method for a plurality of public network services is provided for mininet provided by the invention.Simultaneously with reference to figure 1 and Fig. 2, describe this handling process in detail below in conjunction with each unit of above-mentioned intelligent HGW200: after the beginning step, program enters
Step 401: from described SOHO network 100 or Operation Network 301 or Operation Network 305, receive business data flow.This step is received by I/O interface 201 by described receiving element 202.The business data flow that receives may be to come from Operation Network 301, also may come from user 101.No matter promptly up or downlink service data can.Program enters then
Step 402: the unit (figure does not show) of consulting in the recognition unit 203 according to described business data flow, goes to consult in the described traffic classification table 208 and the corresponding service parameter of described business data flow.Certainly, consulting unit and traffic classification table 208 is that lotus root connects.Described service parameter generally comprises but is not limited to: five-tuple (source/purpose IP, source/destination interface, agreement), two layers of definition (source/purpose MAC, classification, VLAN ID, 802.1p), DHCP OPTION (dynamic host machine configuring protocol option), type of service (video, voice, P2P etc.), go into physical interface.Can also comprise other service parameter, as message length etc.During concrete enforcement, these parameters can be selected one by demand, also can select its independent assortment.Program enters then
Step 403: with consult the generation unit that the unit lotus root connects (figure does not show) and will mate the parameter of consulting in result and the described business data flow one by one, generate value parameter, as the program use of recognition result for the back.Program enters then
Step 404: the described unit 204 of searching is searched in described tree network policy configurations table 207 and the corresponding networking of described value parameter strategy by described value parameter.With reference to figure 3, the data structure in the described tree network policy configurations table 207 as shown in Figure 3.In this tree data structure, oval node is a leaf node, has only and is just storing network strategy in the leaf node.The rectangle node is the branch node, is storing in the branch node to guide the described routing information that unit 204 will be searched of searching.Root node is all starting points of searching the path.Illustrate, if the PC102 among the user 101 in the SOHO network 100 has opened the business of the data network 302 of Operation Network 301, search value parameter that unit 204 sends according to self-identifying unit 203 step by step with described tree data structure in the branch node in Data Matching.Begin coupling from root node, match Operation Network 301, just arrive branch node Operation Network 301, discovery is to continue coupling downwards behind the branch node, match data network 302, promptly arrive leaf node data network 302 strategies, discovery is a leaf node, shows and has found the network strategy corresponding with value parameter.That is to say that the networking strategy is multi-level, corresponding with a plurality of business (for example data network 302 and data network 306 etc.) of a plurality of public networks (for example Operation Network 301 and Operation Network 305) respectively.After finding corresponding network strategy, program enters
Step 405: 205 pairs of business data flows of described performance element are carried out the network strategy that finds.Described network strategy comprises one of following strategy or its combination in any: the outgoing interface strategy, the default gateway strategy, routing policy (comprises Routing Protocol, static routing etc.), name server (DNS) strategy (comprises DNS Relay, DNS Server and DDNS definition etc.), DHCP (DHCP) strategy (comprises DHCPServer, Relay, Snooping etc.), service quality (QoS) strategy (comprises traffic classification and mark, queue scheduling, CAR etc.), security strategy (comprises fire compartment wall, filtrations at different levels etc.).After carrying out described network strategy, program enters
Step 406: send in Operation Network 301 or Operation Network 305 by I/O interface 201 described business data flow or in the described SOHO network 100 by described transmitting element 206.Program enters end step then.
By above-mentioned steps as can be known, SOHO network 100 can be signed a plurality of business of a plurality of Operation Networks or a plurality of business of an Operation Network by intelligent HGW200 as mininet.Because each business can dispose corresponding network strategy in intelligent HGW200, these nets are slightly tactful also can carry out it and intelligent HGW200 can just can discern by business data flow, therefore, mininet just can be implemented in this mininet and to realize and being connected of a plurality of business of a plurality of business of a plurality of Operation Networks or an Operation Network by disposing intelligent HGW200.
What deserves to be explained is that hierarchical network policy configurations table can also have other hierarchical pattern, might not be defined in tree type hierarchical pattern.For example can be the index hierarchical pattern, set a concordance list, the length of index condition can be regulated, the corresponding network strategy of each index condition.What the index condition was long like this is exactly that classification is many, and what the index condition was short is exactly that classification is few, can realize the hierarchical network policy configurations equally.
Make when the data in described traffic classification table 208 and the tree network policy configurations table 207 are activated the service according to the user by operator and change configuration in initial configuration or the operation process.The mode of configuration data can be webmaster or local management.Each Operation Network all has a NM server, is used for configuration data.
With reference to figure 5, the flow chart of store configuration data when illustrating the administration configuration data.With reference to figure 2, program enters through after beginning step simultaneously
Step 501: receiving element 202 receives the configuration data that the NM server that comes from Operation Network or local device send by I/O interface 201, each Operation Network all have one with the corresponding NM server of intelligent HGW200.Program enters after receiving configuration data
Step 502: whether collision detection unit 209 detects described configuration data conflict.Because exist a plurality of operators, there is the configuration data of oneself each operation commercial city.Should be invisible mutually between each operator, therefore, need carry out collision detection, prevent that different operators from causing conflict when sending configuration data.Program enters
Step 503: determination step, judge whether conflict is arranged, if conflict is arranged, then enter
Step 505: send alarm signal, EP (end of program) then to configuration side (operator).If conflict does not then enter
Step 506: described configuration data is stored in the described configuration data table memory 211 by configuration memory cell 210.There are a plurality of configuration data table described configuration data table memory 211 the insides.A kind of business of the corresponding Operation Network of each configuration data table.Therefore, configuration memory cell 210 needs to identify according to described configuration data earlier the configuration data of which kind of business that is which Operation Network, then this configuration data is stored in the corresponding configuration data table.Configuration data has been stored the back EP (end of program).
Storing the configuration data of all signatory operators in the described configuration data table memory 211, each business of each signatory operator all has corresponding configuration data, by the configuration data table storage and uniform.
Described configuration data finally will be configured in traffic classification table 207 and/or the tree network policy configurations table 207.Therefore, need Command Line Parsing unit 212 in described configuration data table memory 211, to parse described configuration data, and it is configured in traffic classification table 207 and/or the tree network policy configurations table 207.
As can be seen, the webmaster of intelligence HGW can be a plurality of NM servers, satisfy the needs that a plurality of operators manage same intelligent HGW equipment, intelligence HGW can accept the cover configuration data that each NM server provides, but is unified management to all configuration datas on the intelligent HGW equipment and carries out collision detection and alarm.
Above disclosed only is the preferred embodiments of the present invention, can not limit the present invention's interest field certainly with this, and therefore the equivalent variations of being done according to the present patent application claim still belongs to the scope that the present invention is contained.