WO2016078431A1 - 策略文件同步管理的方法及策略同步服务器和管理设备 - Google Patents

策略文件同步管理的方法及策略同步服务器和管理设备 Download PDF

Info

Publication number
WO2016078431A1
WO2016078431A1 PCT/CN2015/083792 CN2015083792W WO2016078431A1 WO 2016078431 A1 WO2016078431 A1 WO 2016078431A1 CN 2015083792 W CN2015083792 W CN 2015083792W WO 2016078431 A1 WO2016078431 A1 WO 2016078431A1
Authority
WO
WIPO (PCT)
Prior art keywords
policy
new version
policy file
dpi device
file
Prior art date
Application number
PCT/CN2015/083792
Other languages
English (en)
French (fr)
Inventor
张纪伟
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016078431A1 publication Critical patent/WO2016078431A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/40Support for services or applications

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a method for policy file synchronization management and a policy synchronization server and a management device.
  • the policy management platform In the current telecom carrier system, the policy management platform is generally only built in the provincial center, and the DPI (Deep Packet Inspection) equipment is deployed in distributed construction in various cities.
  • the policy management platform implements policy management and policy delivery for many DPI devices in the provinces, and implements policy formulation and management for users and applications, policy binding for users and applications, and policy management for DPI devices.
  • the DPI device reports the identification or analysis result based on the user and the application and the related information based on the DPI device management to the statistical analysis system according to the policy delivered by the policy management platform.
  • the existing DPI device When the existing DPI device is started, the user terminal device is online, and the policy synchronization notification is received, a policy request needs to be initiated to the policy management platform.
  • the pressure of the policy management platform When the DPI device concurrently requests the update, the pressure of the policy management platform will reach a peak instantaneously and occupy the bandwidth for a long time. Therefore, the policy management platform carries a large concurrent request pressure, and the same city is in the synchronization time of the policy update. DPI devices cannot guarantee the simultaneous validity of the policy, causing user complaints.
  • the embodiment of the invention provides a method for synchronizing management of policy files and a policy synchronization server and a management device, which are intended to at least effectively improve the performance pressure and long synchronization time caused by policy large file synchronization to the policy management platform.
  • a method for managing policy file synchronization includes the following steps:
  • the DPI device After receiving the success message that the DPI device completes the download according to the download address, the DPI device sends a policy file effective instruction to enable the DPI device to synchronously execute the new version policy file.
  • the method further includes:
  • the delayed notification of the update policy file request message is sent after the predetermined time is sent to the DPI device.
  • the step of sending the return message carrying the download address of the new version policy file to the DPI device further includes:
  • the DPI device that sends the update policy file request message again belongs to the same group number as the DPI device that has successfully downloaded the new version policy file
  • the DPI device that sends the update policy file request message again sends the access address carrying the new version policy file.
  • the DPI device downloading the information for resending the update policy file request message downloads the new version policy file from the DPI device that has successfully downloaded the new version policy file.
  • the new version notification message includes a version number of the new version policy file and an access address, and the access address includes an FTP access address, a username and password, and a file location of the new version policy file in the policy management platform.
  • the embodiment of the present invention further provides a policy synchronization server, where the policy synchronization server includes:
  • a first receiving module configured to receive a new version notification message sent by the policy management platform
  • the downloading module is configured to obtain an access address carried in the new version notification message, and download a new version file from the policy management platform according to the obtained access address;
  • a second receiving module configured to receive an update policy file request message sent by the DPI device
  • the first sending module is configured to send a return message carrying the download address of the new version policy file to the DPI device;
  • the second sending module is configured to send a policy file validation instruction to the DPI device after the DPI device completes the download success message according to the download address, so that the DPI device synchronizes execution of the new version policy file.
  • the policy synchronization server further includes:
  • the third sending module is configured to send a delay notification of the update policy file request message after the predetermined time is sent to the DPI device, if the number of the received update policy file request message is not in the preset range.
  • the policy synchronization server further includes:
  • a third receiving module configured to receive an update policy file request message sent by the DPI device again;
  • the obtaining module is set to obtain a group number of the DPI device that sends the update policy file request message again;
  • the fourth sending module is configured to: if the DPI device that sends the update policy file request message again belongs to the same group number as the DPI device that has successfully downloaded the new version policy file, send the new DPI device that sends the update policy file request message again The download information of the access address of the version policy file, for the DPI device for resending the update policy file request message to download the new version policy file from the DPI device that has successfully downloaded the new version policy file.
  • the new version notification message includes a version number of the new version policy file, and the access address includes an FTP access address, a user name and password, and a file location of the new version policy file in the policy management platform.
  • the embodiment of the present invention further provides a management device, where the management device includes:
  • Policy synchronization server including:
  • a first receiving module configured to receive a new version notification message sent by the policy management platform
  • the downloading module is configured to obtain an access address carried in the new version notification message, and download a new version file from the policy management platform according to the obtained access address;
  • a second receiving module configured to receive an update policy file request message sent by the DPI device
  • the first sending module is configured to send a return message carrying the download address of the new version policy file to the DPI device;
  • the second sending module is configured to send a policy file validating instruction to the DPI device after the DPI device completes the download success message according to the download address, so that the DPI device synchronizes execution of the new version policy file;
  • a policy management platform, the policy management platform includes:
  • the third sending module is configured to send, by using the TCP, the FTP access address, the user name and password of the saved new version policy file to the policy synchronization server, and the version number of the new version policy file and the IP address and port number of the policy synchronization server to the DPI device. ;
  • the DPI device includes:
  • a third receiving module configured to receive a new version notification message sent by the policy management platform
  • a fourth sending module configured to send an update policy file request message to the policy synchronization server
  • a fourth receiving module configured to receive a return message sent by the policy synchronization server and carrying a download address of the new version policy file
  • the update module is configured to obtain a download address of the new version policy file, and download a new version from the policy synchronization server according to the download address to complete the update of the policy file.
  • the method for synchronizing management of policy files and the policy synchronization server and the management device provided by the embodiments of the present invention can automatically upgrade the large files of the policy by setting the policy synchronization server without affecting the running performance of the policy management platform.
  • the upgraded new version of the policy file can be validated at the same time, which can effectively improve the performance pressure caused by the policy large file synchronization to the policy management platform, the long synchronization time and the synchronization uncoordinated problem.
  • FIG. 1 is a schematic flowchart of a method for synchronizing management of policy files according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of another embodiment of a method for managing policy file synchronization according to the present invention
  • FIG. 3 is a schematic diagram of functional modules of an embodiment of a management device according to the present invention.
  • FIG. 4 is a schematic diagram of functional modules of an embodiment of the policy synchronization server of FIG. 3;
  • FIG. 5 is a schematic diagram of functional modules of another embodiment of the policy synchronization server of FIG. 3;
  • FIG. 6 is a schematic diagram of functional modules of an embodiment of the policy management platform of FIG. 3;
  • FIG. 7 is a schematic diagram of functional modules of an embodiment of the DPI device of FIG. 3;
  • FIG. 8 is a schematic diagram of data flow of a management device according to the present invention.
  • An embodiment of the present invention provides a method for policy file synchronization management.
  • the method for managing policy file synchronization includes the following steps:
  • Step S101 receiving a new version notification message sent by the policy management platform 2;
  • the synchronization of the application and management policy files needs to be completed by the policy management platform 2, the DPI device 3, and the policy synchronization server 1.
  • the policy management platform 2 first synchronizes the new version of the policy file to be synchronized to the policy synchronization server 1, and then delivers the policy file.
  • a notification message is sent to each DPI device 3 to inform that a new version of the policy file needs to be synchronized.
  • Step S102 Acquire an access address carried in the new version notification message, and download a new version file from the policy management platform 2 according to the obtained access address.
  • the new version notification message sent by the policy management platform 2 to the policy synchronization server 1 carries the access address of the new version policy file in the policy management platform 2, and the management policy server obtains the access address in the new version notification message. And downloading a new version file from the policy management platform 2 according to the access address.
  • Step S103 receiving an update policy file request message sent by the DPI device 3;
  • the DPI device 3 after receiving the version update notification message of the policy management platform 2, the DPI device 3 checks the version number of the current policy file in the system according to the version number of the new version in the message, and needs to upgrade the policy when the update is required.
  • the server 1 initiates an update policy file request message, where the request message includes the DPI device 3 name and the group number of the DPI device 3 and the current policy file version number of the DPI device 3.
  • Step S104 sending a return message carrying the download address of the new version policy file to the DPI device 3;
  • the policy synchronization server 1 since there may be more DPI devices 3 requesting the update at the same time, the policy synchronization server 1 first accepts the first predetermined number of update policy file requests that arrive first according to the queuing principle, and the DPI is in a predetermined number range.
  • the device 3 sends a return message carrying the download address of the new version of the policy file, and informs the version number of the new version policy file, and the information such as the FTP access address, the user name, and the password, so that the DPI devices 3 synchronize the server from the policy according to the obtained address. 1 download the new version of the policy file; and the subsequent updated update strategy
  • the request, the policy synchronization server 1 will return to the DPI device 3 that does not belong within the predetermined number range to send the request message again after the predetermined time interval.
  • Step S105 after receiving the success message that the DPI device 3 completes the download according to the download address, send a policy file validation instruction to the DPI device 3, so that the DPI device 3 synchronously executes the new version policy file.
  • the DPI device 3 after successfully downloading the new version policy file, the DPI device 3 reports the success message of completing the download to the policy synchronization server 1 and reports the location of the policy synchronization file that has been downloaded.
  • the policy synchronization server 1 sends a policy to the DPI device 3, and the DPI device 3 executes the new version policy after receiving the policy file effective command.
  • the file in this way, ensures the rapidity of policy information synchronization management and the uniformity of policy execution, and effectively solves the problems caused by the strategy large file synchronization to the policy management platform 2 and the long synchronization time.
  • the method further includes:
  • Step S1031 If the number of received update policy file request messages is not in the preset range, send a delay notice to the update policy file request message after sending the predetermined time to the DPI device 3.
  • the policy synchronization server 1 when the other DPI devices 3 that are not in the preset range initiate a policy request to the policy synchronization server 1, the policy synchronization server 1 performs coordinated optimization scheduling according to the DPI device 3 information, the DPI group number, and the DPI device 3 location. .
  • the method further includes:
  • Step S1041 Receive an update policy file request message sent by the DPI device 3 again.
  • Step S1042 Acquire a group number of the DPI device that sends the update policy file request message again.
  • Step S1043 If the DPI device 3 that sends the update policy file request message again belongs to the same group number as the DPI device 3 that has successfully downloaded the new version policy file, the DPI device 3 that sends the update policy file request message again sends a new version.
  • the policy synchronization server 1 when the policy synchronization server 1 receives the update policy file request message sent by the DPI device 3 again, it first checks whether other DPI devices 3 in the same group as the DPI device 3 to be synchronized have successfully downloaded, and if so, priority Returns the version number of the new version of the DPI device 3 policy file and the FTP access address, user name, and password, etc. that have been successfully synchronized in this DPI group device; if not, returns the FTP access of the new version policy file on the policy synchronization server 1. Information such as address, username, and password.
  • each DPI device 3 can synchronize the new version of the policy file in the vicinity, so that it is not necessary to rely solely on obtaining the new version of the policy file from the policy synchronization server 1.
  • the policy file synchronization success message is also sent to the policy synchronization server 1.
  • the policy synchronization server 1 delivers a management policy file effective command to all the requested DPI devices 3, and the effective command includes information such as the effective time. .
  • the DPI device 3 in the same group uniformly executes the new version policy file according to the effective time.
  • the new version notification message includes a version number of the new version policy file and an access address, the access address including an FTP access address, a username and password, and a file of the new version policy file in the policy management platform 2. position.
  • the embodiment of the present invention further provides a policy synchronization server 1.
  • the policy synchronization server 1 includes:
  • the first receiving module 101 is configured to receive a new version notification message sent by the policy management platform 2;
  • the synchronization of the application and management policy files needs to be completed by the policy management platform 2, the DPI device 3, and the policy synchronization server 1.
  • the policy management platform 2 first synchronizes the new version of the policy file to be synchronized to the policy synchronization server 1, and then delivers the policy file.
  • a notification message is sent to each DPI device 3 to inform that a new version of the policy file needs to be synchronized.
  • the downloading module 102 is configured to obtain an access address carried in the new version notification message, and download a new version file from the policy management platform 2 according to the obtained access address;
  • the new version notification message sent by the policy management platform 2 to the policy synchronization server 1 carries the access address of the new version policy file in the policy management platform 2, the version number of the new version policy file, and
  • the FTP accesses the address, the username, and the password, and the management policy server obtains the access address in the new version notification message and downloads the new version file from the policy management platform 2 according to the access address.
  • the second receiving module 103 is configured to receive an update policy file request message sent by the DPI device 3;
  • the DPI device 3 after receiving the version update notification message of the policy management platform 2, the DPI device 3 checks with the version number of the current policy file according to the version number of the new version in the message, and needs to upgrade the update to the policy synchronization server 1
  • the policy file request message is updated, and the request message includes the DPI device 3 name and the group number of the DPI device 3 and the current policy file version number of the DPI device 3.
  • the first sending module 104 is configured to send a return message carrying the download address of the new version policy file to the DPI device 3;
  • the policy synchronization server 1 since there may be more DPI devices 3 requesting the update at the same time, the policy synchronization server 1 first accepts the first predetermined number of update policy file requests that arrive first according to the queuing principle, and the DPI is in a predetermined number range.
  • the device 3 sends a return message carrying the download address of the new version of the policy file, and informs the version number of the new version policy file, and the information such as the FTP access address, the user name, and the password, so that the DPI devices 3 synchronize the server from the policy according to the obtained address.
  • the policy synchronization server 1 downloading the new version policy file; and the subsequent arrival of the update policy file request, the policy synchronization server 1 returns a request for the DPI device 3 that does not belong within the predetermined number range to transmit the request message again after the predetermined time interval.
  • the second sending module 105 is configured to send a policy file validation instruction to the DPI device 3 after the success message of the DPI device 3 completes the download according to the download address, so that the DPI device 3 synchronously executes the new version policy file.
  • the DPI device 3 after successfully downloading the new version policy file, the DPI device 3 reports the success message of completing the download to the policy synchronization server 1 and reports the location of the policy synchronization file that has been downloaded.
  • the policy synchronization server 1 sends a policy to the DPI device 3, and the DPI device 3 executes the new version policy after receiving the policy file effective command.
  • the file in this way, ensures the rapidity of policy information synchronization management and the uniformity of policy execution, and effectively solves the problems caused by the strategy large file synchronization to the policy management platform 2 and the long synchronization time.
  • the policy synchronization server 1 further includes:
  • the third sending module 1031 is configured to send a delay notification of the update policy file request message after the predetermined time is sent to the DPI device 3, if the number of received update policy file request messages is not in the preset range.
  • the policy synchronization server 1 when the other DPI devices 3 that are not in the preset range initiate a policy request to the policy synchronization server 1, the policy synchronization server 1 performs coordinated optimization scheduling according to the DPI device 3 information, the DPI group number, and the DPI device 3 location. .
  • the policy synchronization server 1 further includes:
  • the third receiving module 1041 is configured to receive an update policy file request message sent by the DPI device 3 again;
  • the obtaining module 1042 is configured to obtain a group number of the DPI device that sends the update policy file request message again;
  • the fourth sending module 1043 is configured to: if the DPI device 3 that sends the update policy file request message again belongs to the same group number as the DPI device 3 that has successfully downloaded the new version policy file, send the DPI device 3 that updates the policy file request message again.
  • the DPI device 3 that transmits the download information carrying the access address of the new version policy file for resending the update policy file request message downloads the new version policy file from the DPI device 3 that has successfully downloaded the new version policy file.
  • the policy synchronization server 1 when the policy synchronization server 1 receives the update policy file request message sent by the DPI device 3 again, it first checks whether other DPI devices 3 in the same group as the DPI device 3 to be synchronized have successfully downloaded, and if so, priority Returns the version number of the new version of the DPI device 3 policy file and the FTP access address, user name, and password, etc. that have been successfully synchronized in this DPI group device; if not, returns the FTP access of the new version policy file on the policy synchronization server 1. Information such as address, username, and password.
  • each DPI device 3 can synchronize the new version of the policy file in the vicinity, so that it is not necessary to rely solely on obtaining the new version of the policy file from the policy synchronization server 1.
  • the policy file synchronization success message is also sent to the policy synchronization server 1.
  • the policy synchronization server 1 delivers a management policy file effective command to all the requested DPI devices 3, and the effective command includes information such as the effective time. .
  • the DPI device 3 in the same group uniformly executes the new version policy file according to the effective time.
  • the new version notification message includes a version number of the new version policy file, the access address including an FTP access address, a username and password, and a file location of the new version policy file within the policy management platform.
  • the new version notification message includes the file location of the new version policy file in the policy management platform 2, the version number of the new version policy file, and the FTP access address, user name, and password.
  • the present invention further provides a management device.
  • the management device includes:
  • the policy synchronization server 1 includes:
  • the first receiving module 101 is configured to receive a new version notification message sent by the policy management platform 2;
  • the synchronization of the application and management policy files needs to be completed by the policy management platform 2, the DPI device 3, and the policy synchronization server 1.
  • the policy management platform 2 first synchronizes the new version of the policy file to be synchronized to the policy synchronization server 1, and then delivers the policy file.
  • a notification message is sent to each DPI device 3 to inform that a new version of the policy file needs to be synchronized.
  • the downloading module 102 is configured to obtain an access address carried in the new version notification message, and download a new version file from the policy management platform 2 according to the obtained access address;
  • the new version notification message sent by the policy management platform 2 to the policy synchronization server 1 carries the access address of the new version policy file in the policy management platform 2, the version number of the new version policy file, and the FTP access address.
  • Information such as a username and password
  • the management policy server obtains an access address in the new version notification message and downloads a new version file from the policy management platform 2 according to the access address.
  • the second receiving module 103 is configured to receive an update policy file request message sent by the DPI device 3;
  • the DPI device 3 after receiving the version update notification message of the policy management platform 2, the DPI device 3 checks the version number of the current policy file in the system according to the version number of the new version in the message, and needs to upgrade the policy when the update is required.
  • the server 1 initiates an update policy file request message, where the request message includes the DPI device 3 name and the group number of the DPI device 3 and the current policy file version number of the DPI device 3.
  • the first sending module 104 is configured to send a return message carrying the download address of the new version policy file to the DPI device 3;
  • the policy synchronization server 1 since there may be more DPI devices 3 requesting the update at the same time, the policy synchronization server 1 first accepts the first predetermined number of update policy file requests that arrive first according to the queuing principle, and the DPI is in a predetermined number range.
  • the device 3 sends a return message carrying the download address of the new version of the policy file, and informs the version number of the new version policy file, and the information such as the FTP access address, the user name, and the password, so that the DPI devices 3 synchronize the server from the policy according to the obtained address.
  • the policy synchronization server 1 downloading the new version policy file; and the subsequent arrival of the update policy file request, the policy synchronization server 1 returns a request for the DPI device 3 that does not belong within the predetermined number range to transmit the request message again after the predetermined time interval.
  • the second sending module 105 is configured to send a policy file validation instruction to the DPI device 3 after the success message of the DPI device 3 completes the download according to the download address, so that the DPI device 3 synchronously executes the new version policy file.
  • the DPI device 3 after successfully downloading the new version policy file, the DPI device 3 reports the success message of completing the download to the policy synchronization server 1 and reports the location of the policy synchronization file that has been downloaded.
  • the policy synchronization server 1 sends a policy to the DPI device 3, and the DPI device 3 executes the new version policy after receiving the policy file effective command.
  • the file in this way, ensures the rapidity of policy information synchronization management and the uniformity of policy execution, and effectively solves the problems caused by the strategy large file synchronization to the policy management platform 2 and the long synchronization time.
  • the saving module 201 is configured to generate a new version of the policy file and save it;
  • the third sending module 202 is configured to send, by using a TCP (Transmission Control Protocol), the FTP access address, the user name and password of the saved new version policy file, and the new version policy file to the DPI device 3, to the policy synchronization server 1
  • TCP Transmission Control Protocol
  • the policy management platform 2 when the administrator constructs a new application policy on the policy management platform 2 to generate a new version policy file, the policy management platform 2 saves the generated new version policy file in the FTP directory of the policy management platform 2, and then A notification message including an FTP access address, a user name, and a password of the saved new version policy file is transmitted to the policy synchronization server 1 via TCP.
  • the DPI device 3 is to be uniformly delivered to each DPI device 3, the version number of the new version policy file and the IP address and port number of the policy synchronization server 1 are sent to the DPI device 3.
  • the third receiving module 301 is configured to receive a new version notification message sent by the policy management platform 2;
  • the synchronization of the application and management policy files needs to be completed by the policy management platform 2, the DPI device 3, and the policy synchronization server 1.
  • the policy management platform 2 first synchronizes the new version of the policy file to be synchronized to the policy synchronization server 1, and then delivers the policy file.
  • a notification message is sent to each DPI device 3 to inform that a new version of the policy file needs to be synchronized.
  • the fourth sending module 302 is configured to send an update policy file request message to the policy synchronization server 1;
  • the DPI device 3 after receiving the version update notification message of the policy management platform 2, the DPI device 3 checks with the version number of the current policy file according to the version number of the new version in the message, and needs to upgrade the update to the policy synchronization server 1
  • the policy file request message is updated, and the request message includes the DPI device number 3 and the group number of the DPI device 3 and the current policy file version number of the DPI device 3.
  • the fourth receiving module 303 is configured to receive a return message that is sent by the policy synchronization server 1 and that carries the download address of the new version policy file.
  • the policy synchronization server 1 since there may be more DPI devices 3 requesting the update at the same time, the policy synchronization server 1 first accepts the first predetermined number of update policy file requests that arrive first according to the queuing principle, and the DPI is in a predetermined number range.
  • the device 3 sends a return message carrying the download address of the new version of the policy file, and informs the version number of the new version policy file, and the information such as the FTP access address, the user name, and the password, so that the DPI devices 3 synchronize the server from the policy according to the obtained address.
  • the policy synchronization server 1 downloading the new version policy file; and the subsequent arrival of the update policy file request, the policy synchronization server 1 returns a request for the DPI device 3 that does not belong within the predetermined number range to transmit the request message again after the predetermined time interval.
  • the update module 304 is configured to obtain a download address of the new version policy file, and download a new version from the policy synchronization server 1 according to the download address to complete the update of the policy file.
  • the policy synchronization server 1 first checks other DPIs in the same group as the DPI device 3 to be synchronized. Whether the device 3 has successfully downloaded the new version of the policy file, and if so, returns the version number of the new version of the DPI device 3 policy file and the FTP access address, user name, and password, etc., which have been successfully synchronized in the DPI group device; If not, the information such as the FTP access address, user name, and password of the new version policy file on the policy synchronization server 1 is returned.
  • each DPI device 3 can synchronize the new version of the policy file in the vicinity, so that it is not necessary to rely solely on obtaining the new version of the policy file from the policy synchronization server 1.
  • the policy file synchronization success message is also sent to the policy synchronization server 1.
  • the policy synchronization server 1 delivers a management policy file effective command to all the requested DPI devices 3, and the effective command includes information such as the effective time. .
  • the DPI device 3 in the same group uniformly executes the new version policy file according to the effective time.
  • the data flow of the management device is as follows:
  • Step 401 When the policy management platform 2 generates a new version of the policy file, first save the new version of the policy file in the local FTP directory, and then send the FTP access address containing the saved new version of the policy file to the policy synchronization server 1 through TCP. Notification message for username and password.
  • Step 402 After receiving the notification message of the policy management platform 2, the policy synchronization server 1 downloads the management policy synchronization file from the policy management platform 2. After the download succeeds, the policy management platform 2 is successfully downloaded.
  • Step 403 The policy management platform 2 sends a new version policy file notification message to all DPI devices 3, informing the DPI device 3 of the version number of the new version policy file, the IP address of the policy synchronization server 1, and the port number.
  • Step 404 After receiving the policy update platform 2 version update notification message, the DPI device 3 checks the current policy file version number according to the version number of the new version in the message, and initiates an update policy to the policy synchronization server 1 when the update is required.
  • a file request message the request message includes a DPI device 3 name and a group number of the DPI device 3 and a current policy file version number of the DPI device 3.
  • Step 405 The policy synchronization server 1 receives the update policy file request message sent by the DPI device 3, and the policy synchronization server 1 first accepts the first predetermined number of update policy file requests that arrive first, and is within a predetermined number range according to the queuing principle.
  • the DPI device 3 sends a return message carrying the download address of the new version of the policy file, notifying the version number of the new version policy file and the FTP access address, user name and password, etc., so that the DPI devices 3 are from the policy according to the obtained address.
  • the synchronization server 1 downloads the new version policy file; and upon subsequent arrival of the update policy file request, the policy synchronization server 1 returns to the DPI device 3 that does not belong within the predetermined number range to transmit the request message again after the predetermined time interval.
  • Step 406 The DPI device 3 initiates a new version of the policy file FTP download to the policy synchronization server 1.
  • Step 407 After the download is successful, the DPI device 3 reports the download success message to the policy synchronization server 1, and simultaneously informs the FTP access address, user name and password, and file location of the downloaded new version policy file.
  • Step 408 After receiving the policy update platform 2 version update notification message, the DPI device 3 checks the version number of the new version in the message with the current policy file version number. When the upgrade is required, the update policy is initiated to the policy synchronization server 1.
  • a file request message, the request message includes the DPI device number 3 and the group number of the DPI device 3 and the current policy file version number of the DPI device 3.
  • Step 409 The policy synchronization server 1 analyzes the device number and the group number of the DPI device 3 and the version number of the policy file to be upgraded. If the DPI device 3 in the same group has obtained the policy file corresponding to the new version, the policy is obtained. The synchronization server 1 returns information such as the FTP access address, user name, and password of the successfully synchronized DPI device 3, and the file location.
  • Step 410 The DPI device 3 initiates an FTP request to the existing DPI device 3 to obtain a new version policy file.
  • Step 411 After obtaining the new version policy file, the DPI device 3 returns a download success message to the policy synchronization server 1, and simultaneously informs the information such as the FTP access address, the user name and the password, and the file location of the downloaded policy file.
  • Steps 412-413 After all the DPI devices 3 requested by the policy synchronization server 1 are successfully downloaded, the policy synchronization server 1 delivers a new version policy file effective command to all the requested DPI devices 3, and the effective command includes the effective time. information. After receiving the message, the DPI device 3 in the same group uniformly executes the policy file according to the effective time.
  • the method for synchronizing management of a policy file and the policy synchronization server and the management device have the following beneficial effects: by setting a policy synchronization server, an automatic upgrade of a policy large file can be realized without affecting the policy. Manage the operational performance of the platform. In addition, the upgraded new version of the policy file can be validated at the same time, which can effectively improve the performance pressure caused by the policy large file synchronization to the policy management platform, the long synchronization time and the synchronization uncoordinated problem.

Abstract

本发明公开了一种策略文件同步管理的方法,包括以下步骤:接收策略管理平台发送的新版本通知消息;获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;接收DPI设备发送的更新策略文件请求消息;向DPI设备发送携带有新版本策略文件的下载地址的返回消息;待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件。本发明还公开了一种策略同步服务器和管理设备。本发明提供的策略文件同步管理的方法,可以有效改善策略大文件同步给策略管理平台造成的性能压力及同步时间长的问题。

Description

策略文件同步管理的方法及策略同步服务器和管理设备 技术领域
本发明涉及通信技术领域,尤其涉及一种策略文件同步管理的方法及策略同步服务器和管理设备。
背景技术
在目前的电信运营商系统中,策略管理平台一般只建设于省中心,而DPI(Deep Packet Inspection,深度包检测)设备则部署在各地市呈分布式建设。策略管理平台对全省各地市众多的DPI设备进行策略管理和策略下发,实现针对用户与应用的策略制定和管理、用户与应用的策略绑定以及DPI设备的策略管理等功能。DPI设备依照策略管理平台下发的策略,向统计分析系统上报基于用户与应用的识别或分析结果以及基于DPI设备管理的相关信息。现有的DPI设备启动、用户终端设备上线以及接收策略同步通知时,都需要向策略管理平台发起策略请求。在DPI设备同时并发更新请求时,会导致策略管理平台的压力瞬间达到峰值以及长时间占用带宽,因此,使策略管理平台承载着较大的并发请求压力,而且在策略更新同步时间内同一地市DPI设备无法保证策略的同时生效性,从而引发用户投诉。
上述内容仅用于辅助理解本发明的技术方案,并不代表承认上述内容是现有技术。
发明内容
本发明实施例提供了一种策略文件同步管理的方法及策略同步服务器和管理设备,旨在至少有效改善策略大文件同步给策略管理平台造成的性能压力及同步时间长的问题。
为至少实现上述目的,本发明实施例提供的一种策略文件同步管理的方法,所述策略文件同步管理的方法包括以下步骤:
接收策略管理平台发送的新版本通知消息;
获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;
接收DPI设备发送的更新策略文件请求消息;
则向DPI设备发送携带有新版本策略文件的下载地址的返回消息;
待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件。
所述接收DPI设备发送的更新策略文件请求消息的步骤之后还包括:
若接收到的更新策略文件请求消息的数量不在预设范围,则向DPI设备发送预定时间后再发送更新策略文件请求消息的延迟通知。
所述向DPI设备发送携带有新版本策略文件的下载地址的返回消息的步骤之后还包括:
接收DPI设备再次发送的更新策略文件请求消息;
获取再次发送更新策略文件请求消息的DPI设备的组号;
若再次发送更新策略文件请求消息的DPI设备与已成功下载新版本策略文件的DPI设备属于同一组号,则向再次发送更新策略文件请求消息的DPI设备发送携带有新版本策略文件的访问地址的下载信息,以供再次发送更新策略文件请求消息的DPI设备从已成功下载新版本策略文件的DPI设备中下载新版本策略文件。
所述新版本通知消息包括新版本策略文件的版本号以及访问地址,所述访问地址包括新版本策略文件在策略管理平台内的FTP访问地址、用户名和密码以及文件位置。
此外,为至少实现上述目的,本发明实施例还提供一种策略同步服务器,所述策略同步服务器包括:
第一接收模块,设置为接收策略管理平台发送的新版本通知消息;
下载模块,设置为获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;
第二接收模块,设置为接收DPI设备发送的更新策略文件请求消息;
第一发送模块,设置为向DPI设备发送携带有新版本策略文件的下载地址的返回消息;
第二发送模块,设置为待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件。
所述策略同步服务器还包括:
第三发送模块,设置为若接收到的更新策略文件请求消息的数量不在预设范围,则向DPI设备发送预定时间后再发送更新策略文件请求消息的延迟通知。
所述策略同步服务器还包括:
第三接收模块,设置为接收DPI设备再次发送的更新策略文件请求消息;
获取模块,设置为获取再次发送更新策略文件请求消息的DPI设备的组号;
第四发送模块,设置为若再次发送更新策略文件请求消息的DPI设备与已成功下载新版本策略文件的DPI设备属于同一组号,则向再次发送更新策略文件请求消息的DPI设备发送携带有新版本策略文件的访问地址的下载信息,以供再次发送更新策略文件请求消息的DPI设备从已成功下载新版本策略文件的DPI设备中下载新版本策略文件。
所述新版本通知消息包括新版本策略文件的版本号,所述访问地址包括新版本策略文件在策略管理平台内的FTP访问地址、用户名和密码以及文件位置。
此外,为至少实现上述目的,本发明实施例还提供一种管理设备,所述管理设备包括:
策略同步服务器,包括:
第一接收模块,设置为接收策略管理平台发送的新版本通知消息;
下载模块,设置为获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;
第二接收模块,设置为接收DPI设备发送的更新策略文件请求消息;
第一发送模块,设置为向DPI设备发送携带有新版本策略文件的下载地址的返回消息;
第二发送模块,设置为待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件;
策略管理平台,所述策略管理平台包括:
保存模块,设置为生成新版本策略文件并保存;
第三发送模块,设置为通过TCP向策略同步服务器发送保存的新版本策略文件的FTP访问地址、用户名和密码以及向DPI设备发送新版本策略文件的版本号以及策略同步服务器的IP地址和端口号;
DPI设备,所述DPI设备包括:
第三接收模块,设置为接收策略管理平台发送的新版本通知消息;
第四发送模块,设置为向策略同步服务器发送更新策略文件请求消息;
第四接收模块,设置为接收策略同步服务器发送的携带有新版本策略文件的下载地址的返回消息;
更新模块,设置为获取新版本策略文件的下载地址,并根据所述下载地址从所述策略同步服务器下载新版本以完成策略文件的更新。
本发明实施例提供的策略文件同步管理的方法及策略同步服务器和管理设备,通过设置策略同步服务器,可以实现策略大文件的自动升级,而不影响策略管理平台的运行性能。此外,还可以使得升级完成的新版本策略文件同时生效,从而可以有效改善策略大文件同步给策略管理平台造成的性能压力、同步时间长及同步不协调的问题。
附图说明
图1为本发明策略文件同步管理的方法一实施例的流程示意图;
图2为本发明策略文件同步管理的方法另一实施例的流程示意图;
图3为本发明管理设备一实施例的功能模块示意图;
图4为图3中策略同步服务器一实施例的功能模块示意图;
图5为图3中策略同步服务器另一实施例的功能模块示意图;
图6为图3中策略管理平台一实施例的功能模块示意图;
图7为图3中DPI设备一实施例的功能模块示意图;
图8为本发明管理设备的数据流程示意图。
本发明目的的实现、功能特点及优点将结合实施例,参照附图做进一步说明。
具体实施方式
应当理解,此处所描述的具体实施例仅仅用以解释本发明,并不用于限定本发明。
本发明实施例提供一种策略文件同步管理的方法,参照图1,在一实施例中,所述策略文件同步管理的方法包括以下步骤:
步骤S101,接收策略管理平台2发送的新版本通知消息;
本实施例中,应用和管理策略文件的同步需要策略管理平台2、DPI设备3以及策略同步服务器1协作完成。当管理者在策略管理平台2上构造了新的应用策略,需要统一下发到各DPI设备3时,策略管理平台2先将需同步的新版本策略文件同步到策略同步服务器1,之后下发通知消息给各DPI设备3,告知有新版本策略文件需要同步。
步骤S102,获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台2下载新版本文件;
本实施例中,策略管理平台2发送给策略同步服务器1的新版本通知消息中携带有该新版本策略文件在策略管理平台2内的访问地址,管理策略服务器获取新版本通知消息中的访问地址并根据所述访问地址从策略管理平台2下载新版本文件。
步骤S103,接收DPI设备3发送的更新策略文件请求消息;
本实施例中,DPI设备3收到策略管理平台2版本更新通知消息后,根据消息中新版本的版本号,与自己系统中当前的策略文件版本号核对,需要升级更新时,则向策略同步服务器1发起更新策略文件请求消息,请求消息中含有DPI设备3名称和该DPI设备3所在的组号以及DPI设备3当前的策略文件版本号。
步骤S104,向DPI设备3发送携带有新版本策略文件的下载地址的返回消息;
本实施例中,由于同时请求更新的DPI设备3可能较多,策略同步服务器1会根据排队原理,先受理最先到达的预定数目的更新策略文件请求,并向处于在预定数目范围内的DPI设备3发送携带有新版本策略文件的下载地址的返回消息,告知新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息,使这些DPI设备3根据获取的地址从所述策略同步服务器1下载新版本策略文件;而后续到达的更新策略文 件请求,策略同步服务器1则会返回要求不属于预定数目范围内的DPI设备3在间隔预定时间后再次发送请求消息。
步骤S105,待接收到DPI设备3根据下载地址完成下载的成功消息后,向DPI设备3发送策略文件生效指令,以使DPI设备3同步执行新版本策略文件。
本实施例中,DPI设备3下载新版本策略文件成功后,将会向策略同步服务器1报告完成下载的成功消息,并报告自己已下载的策略同步文件的位置。待所有DPI设备3的新版本策略文件都同步成功后,策略同步服务器1向所有DPI设备3统一下发策文件略生效指令,各DPI设备3收到策略文件生效指令后,统一执行新版本策略文件,如此,则保证了策略信息同步管理的快速性和策略执行的统一性,有效解决了策略大文件同步给策略管理平台2造成的压力以及同步时间长等问题。
在一实施例中,如图2所示,在上述图1的实施例的基础上,本实施例中,所述步骤S103之后还包括:
步骤S1031,若接收到的更新策略文件请求消息的数量不在预设范围,则向DPI设备3发送预定时间后再发送更新策略文件请求消息的延迟通知。
本实施例中,不在预设范围内的其他待同步DPI设备3向策略同步服务器1发起策略请求时,策略同步服务器1根据DPI设备3信息、DPI组号以及DPI设备3位置,进行协调优化调度。
在一实施例中,如图2所示,在上述图1的实施例的基础上,本实施例中,所述步骤S104之后还包括:
步骤S1041,接收DPI设备3再次发送的更新策略文件请求消息;
步骤S1042,获取再次发送更新策略文件请求消息的DPI设备的组号;
步骤S1043,若再次发送更新策略文件请求消息的DPI设备3与已成功下载新版本策略文件的DPI设备3属于同一组号,则向再次发送更新策略文件请求消息的DPI设备3发送携带有新版本策略文件的访问地址的下载信息,以供再次发送更新策略文件请求消息的DPI设备3从已成功下载新版本策略文件的DPI设备3中下载新版本策略文件。
本实施例中,策略同步服务器1接收DPI设备3再次发送的更新策略文件请求消息时,先检查与待同步DPI设备3同组的其他DPI设备3是否有已经下载成功的,如果有,则优先返回此DPI组设备中已经同步成功的DPI设备3新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息等;如果没有,则返回策略同步服务器1上的新版本策略文件的FTP访问地址、用户名和密码等信息等。采用这种机制后,各DPI设备3可以就近同步新版本策略文件,从而不必仅依赖从策略同步服务器1上获得新版本策略文件。再次发送的更新策略文件请求的DPI设备3下载新版本策略文件成功后,同样需要向策略同步服务器1发送策略文件同步成功消息。
本实施例中,所有向策略同步服务器1请求的DPI设备3都下载成功后,策略同步服务器1向所有请求的DPI设备3按组下发管理策略文件生效指令,生效指令中含有生效时间等信息。同组中的DPI设备3收到消息后,按生效时间统一执行新版本策略文件。
在一优选实施例中,所述新版本通知消息包括新版本策略文件的版本号以及访问地址,所述访问地址包括新版本策略文件在策略管理平台2内的FTP访问地址、用户名和密码以及文件位置。
本发明实施例还提供一种策略同步服务器1,参照图4,在一实施例中,在一优选实施例中,所述策略同步服务器1包括:
第一接收模块101,设置为接收策略管理平台2发送的新版本通知消息;
本实施例中,应用和管理策略文件的同步需要策略管理平台2、DPI设备3以及策略同步服务器1协作完成。当管理者在策略管理平台2上构造了新的应用策略,需要统一下发到各DPI设备3时,策略管理平台2先将需同步的新版本策略文件同步到策略同步服务器1,之后下发通知消息给各DPI设备3,告知有新版本策略文件需要同步。
下载模块102,设置为获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台2下载新版本文件;
本实施例中,策略管理平台2发送给策略同步服务器1的新版本通知消息中携带有该新版本策略文件在策略管理平台2内的访问地址、新版本策略文件的版本号以及 FTP访问地址、用户名和密码等信息,管理策略服务器获取新版本通知消息中的访问地址并根据所述访问地址从策略管理平台2下载新版本文件。
第二接收模块103,设置为接收DPI设备3发送的更新策略文件请求消息;
本实施例中,DPI设备3收到策略管理平台2版本更新通知消息后,根据消息中新版本的版本号,与当前的策略文件版本号核对,需要升级更新时,则向策略同步服务器1发起更新策略文件请求消息,请求消息中含有DPI设备3名称和该DPI设备3所在的组号以及DPI设备3当前的策略文件版本号。
第一发送模块104,设置为向DPI设备3发送携带有新版本策略文件的下载地址的返回消息;
本实施例中,由于同时请求更新的DPI设备3可能较多,策略同步服务器1会根据排队原理,先受理最先到达的预定数目的更新策略文件请求,并向处于在预定数目范围内的DPI设备3发送携带有新版本策略文件的下载地址的返回消息,告知新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息,使这些DPI设备3根据获取的地址从所述策略同步服务器1下载新版本策略文件;而后续到达的更新策略文件请求,策略同步服务器1则会返回要求不属于预定数目范围内的DPI设备3在间隔预定时间后再次发送请求消息。
第二发送模块105,设置为待接收到DPI设备3根据下载地址完成下载的成功消息后,向DPI设备3发送策略文件生效指令,以使DPI设备3同步执行新版本策略文件。
本实施例中,DPI设备3下载新版本策略文件成功后,将会向策略同步服务器1报告完成下载的成功消息,并报告自己已下载的策略同步文件的位置。待所有DPI设备3的新版本策略文件都同步成功后,策略同步服务器1向所有DPI设备3统一下发策文件略生效指令,各DPI设备3收到策略文件生效指令后,统一执行新版本策略文件,如此,则保证了策略信息同步管理的快速性和策略执行的统一性,有效解决了策略大文件同步给策略管理平台2造成的压力以及同步时间长等问题。
在一实施例中,如图5所示,在上述图4的实施例的基础上,所述策略同步服务器1还包括:
第三发送模块1031,设置为若接收到的更新策略文件请求消息的数量不在预设范围,则向DPI设备3发送预定时间后再发送更新策略文件请求消息的延迟通知。
本实施例中,不在预设范围内的其他待同步DPI设备3向策略同步服务器1发起策略请求时,策略同步服务器1根据DPI设备3信息、DPI组号以及DPI设备3位置,进行协调优化调度。
在一实施例中,如图5所示,在上述图4的实施例的基础上,本实施例中,所述策略同步服务器1还包括:
第三接收模块1041,设置为接收DPI设备3再次发送的更新策略文件请求消息;
获取模块1042,设置为获取再次发送更新策略文件请求消息的DPI设备的组号;
第四发送模块1043,设置为若再次发送更新策略文件请求消息的DPI设备3与已成功下载新版本策略文件的DPI设备3属于同一组号,则向再次发送更新策略文件请求消息的DPI设备3发送携带有新版本策略文件的访问地址的下载信息,以供再次发送更新策略文件请求消息的DPI设备3从已成功下载新版本策略文件的DPI设备3中下载新版本策略文件。
本实施例中,策略同步服务器1接收DPI设备3再次发送的更新策略文件请求消息时,先检查与待同步DPI设备3同组的其他DPI设备3是否有已经下载成功的,如果有,则优先返回此DPI组设备中已经同步成功的DPI设备3新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息等;如果没有,则返回策略同步服务器1上的新版本策略文件的FTP访问地址、用户名和密码等信息等。采用这种机制后,各DPI设备3可以就近同步新版本策略文件,从而不必仅依赖从策略同步服务器1上获得新版本策略文件。再次发送的更新策略文件请求的DPI设备3下载新版本策略文件成功后,同样需要向策略同步服务器1发送策略文件同步成功消息。
本实施例中,所有向策略同步服务器1请求的DPI设备3都下载成功后,策略同步服务器1向所有请求的DPI设备3按组下发管理策略文件生效指令,生效指令中含有生效时间等信息。同组中的DPI设备3收到消息后,按生效时间统一执行新版本策略文件。
在一优选实施例中,所述新版本通知消息包括新版本策略文件的版本号,所述访问地址包括新版本策略文件在策略管理平台内的FTP访问地址、用户名和密码以及文件位置。
本实施例中,新版本通知消息包括新版本策略文件在策略管理平台2内的文件位置、新版本策略文件的版本号以及FTP访问地址、用户名和密码等。
本发明还提供一种管理设备,参照图3,在一实施例中,在一优选实施例中,所述管理设备包括:
策略同步服务器1,参照图5,在一实施例中,所述策略同步服务器1包括:
第一接收模块101,设置为接收策略管理平台2发送的新版本通知消息;
本实施例中,应用和管理策略文件的同步需要策略管理平台2、DPI设备3以及策略同步服务器1协作完成。当管理者在策略管理平台2上构造了新的应用策略,需要统一下发到各DPI设备3时,策略管理平台2先将需同步的新版本策略文件同步到策略同步服务器1,之后下发通知消息给各DPI设备3,告知有新版本策略文件需要同步。
下载模块102,设置为获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台2下载新版本文件;
本实施例中,策略管理平台2发送给策略同步服务器1的新版本通知消息中携带有该新版本策略文件在策略管理平台2内的访问地址、新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息,管理策略服务器获取新版本通知消息中的访问地址并根据所述访问地址从策略管理平台2下载新版本文件。
第二接收模块103,设置为接收DPI设备3发送的更新策略文件请求消息;
本实施例中,DPI设备3收到策略管理平台2版本更新通知消息后,根据消息中新版本的版本号,与自己系统中当前的策略文件版本号核对,需要升级更新时,则向策略同步服务器1发起更新策略文件请求消息,请求消息中含有DPI设备3名称和该DPI设备3所在的组号以及DPI设备3当前的策略文件版本号。
第一发送模块104,设置为向DPI设备3发送携带有新版本策略文件的下载地址的返回消息;
本实施例中,由于同时请求更新的DPI设备3可能较多,策略同步服务器1会根据排队原理,先受理最先到达的预定数目的更新策略文件请求,并向处于在预定数目范围内的DPI设备3发送携带有新版本策略文件的下载地址的返回消息,告知新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息,使这些DPI设备3根据获取的地址从所述策略同步服务器1下载新版本策略文件;而后续到达的更新策略文件请求,策略同步服务器1则会返回要求不属于预定数目范围内的DPI设备3在间隔预定时间后再次发送请求消息。
第二发送模块105,设置为待接收到DPI设备3根据下载地址完成下载的成功消息后,向DPI设备3发送策略文件生效指令,以使DPI设备3同步执行新版本策略文件。
本实施例中,DPI设备3下载新版本策略文件成功后,将会向策略同步服务器1报告完成下载的成功消息,并报告自己已下载的策略同步文件的位置。待所有DPI设备3的新版本策略文件都同步成功后,策略同步服务器1向所有DPI设备3统一下发策文件略生效指令,各DPI设备3收到策略文件生效指令后,统一执行新版本策略文件,如此,则保证了策略信息同步管理的快速性和策略执行的统一性,有效解决了策略大文件同步给策略管理平台2造成的压力以及同步时间长等问题。
图3中的策略管理平台2,在一实施例中,参照图6,所述策略管理平台2包括:
保存模块201,设置为生成新版本策略文件并保存;
第三发送模块202,设置为通过TCP(Transmission Control Protocol,传输控制协议)向策略同步服务器1发送保存的新版本策略文件的FTP访问地址、用户名和密码以及向DPI设备3发送新版本策略文件的版本号以及策略同步服务器1的IP地址和端口号;
本实施例中,当管理者在策略管理平台2上构造了新的应用策略生成新版本策略文件时,策略管理平台2将生成的新版本策略文件保存在策略管理平台2的FTP目录下,然后通过TCP向策略同步服务器1发送含有保存的新版本策略文件的FTP访问地址、用户名和密码的通知消息。需要统一下发到各DPI设备3时,向DPI设备3发送新版本策略文件的版本号以及策略同步服务器1的IP地址和端口号。
图3中的DPI设备3,在一实施例中,参照图7,所述DPI设备3包括:
第三接收模块301,设置为接收策略管理平台2发送的新版本通知消息;
本实施例中,应用和管理策略文件的同步需要策略管理平台2、DPI设备3以及策略同步服务器1协作完成。当管理者在策略管理平台2上构造了新的应用策略,需要统一下发到各DPI设备3时,策略管理平台2先将需同步的新版本策略文件同步到策略同步服务器1,之后下发通知消息给各DPI设备3,告知有新版本策略文件需要同步。
第四发送模块302,设置为向策略同步服务器1发送更新策略文件请求消息;
本实施例中,DPI设备3收到策略管理平台2版本更新通知消息后,根据消息中新版本的版本号,与当前的策略文件版本号核对,需要升级更新时,则向策略同步服务器1发起更新策略文件请求消息,请求消息中含有DPI设备3号和该DPI设备3所在的组号以及DPI设备3当前的策略文件版本号。
第四接收模块303,设置为接收策略同步服务器1发送的携带有新版本策略文件的下载地址的返回消息;
本实施例中,由于同时请求更新的DPI设备3可能较多,策略同步服务器1会根据排队原理,先受理最先到达的预定数目的更新策略文件请求,并向处于在预定数目范围内的DPI设备3发送携带有新版本策略文件的下载地址的返回消息,告知新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息,使这些DPI设备3根据获取的地址从所述策略同步服务器1下载新版本策略文件;而后续到达的更新策略文件请求,策略同步服务器1则会返回要求不属于预定数目范围内的DPI设备3在间隔预定时间后再次发送请求消息。
更新模块304,设置为获取新版本策略文件的下载地址,并根据所述下载地址从所述策略同步服务器1下载新版本以完成策略文件的更新。
本实施例中,不在预设范围内的DPI设备3,经过预定时间后再次向策略同步服务器1发送更新策略文件请求消息时,策略同步服务器1先检查与待同步DPI设备3同组的其他DPI设备3是否有已经成功下载新版本策略文件的,如果有,则优先返回此DPI组设备中已经同步成功的DPI设备3新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息等;如果没有,则返回策略同步服务器1上的新版本策略文件的FTP访问地址、用户名和密码等信息等。采用这种机制后,各DPI设备3可以就近同步新版本策略文件,从而不必仅依赖从策略同步服务器1上获得新版本策略文件。再次发送的更新策略文件请求的DPI设备3下载新版本策略文件成功后,同样需要向策略同步服务器1发送策略文件同步成功消息。
本实施例中,所有向策略同步服务器1请求的DPI设备3都下载成功后,策略同步服务器1向所有请求的DPI设备3按组下发管理策略文件生效指令,生效指令中含有生效时间等信息。同组中的DPI设备3收到消息后,按生效时间统一执行新版本策略文件。
参照图8,在一实施例中,所述管理设备的数据流程如下:
步骤401:当策略管理平台2生成新版本策略文件时,首先将新版本策略文件保存在本机FTP目录下,然后通过TCP向策略同步服务器1发送含有保存的新版本策略文件的FTP访问地址、用户名和密码的通知消息。
步骤402:策略同步服务器1收到策略管理平台2的通知消息后,从策略管理平台2下载管理策略同步文件,下载成功后通知策略管理平台2已成功下载。
步骤403:策略管理平台2向所有DPI设备3发送新版本策略文件通知消息,告知DPI设备3新版本策略文件的版本号、策略同步服务器1的IP地址以及端口号。
步骤404:DPI设备3收到策略管理平台2版本更新通知消息后,根据消息中新版本的版本号,与当前的策略文件版本号核对,需要升级更新时,则向策略同步服务器1发起更新策略文件请求消息,请求消息中含有DPI设备3名称和该DPI设备3所在的组号以及DPI设备3当前的策略文件版本号。
步骤405:策略同步服务器1接收DPI设备3发送的更新策略文件请求消息,策略同步服务器1会根据排队原理,先受理最先到达的预定数目的更新策略文件请求,并向处于在预定数目范围内的DPI设备3发送携带有新版本策略文件的下载地址的返回消息,告知新版本策略文件的版本号以及FTP访问地址、用户名和密码等信息,使这些DPI设备3根据获取的地址从所述策略同步服务器1下载新版本策略文件;而后续到达的更新策略文件请求,策略同步服务器1则会返回要求不属于预定数目范围内的DPI设备3在间隔预定时间后再次发送请求消息。
步骤406:DPI设备3向策略同步服务器1发起新版本策略文件FTP下载。
步骤407:下载成功后,DPI设备3向策略同步服务器1报告下载成功消息,并同时告知已下载的新版本策略文件的FTP访问地址、用户名和密码和文件位置。
步骤408:DPI设备3收到策略管理平台2版本更新通知消息后,将消息中新版本的版本号,与当前的策略文件版本号核对,需要升级更新时,则向策略同步服务器1发起更新策略文件请求消息,请求消息中含有DPI设备3号和该DPI设备3所在的组号以及DPI设备3当前的策略文件版本号。
步骤409:策略同步服务器1分析此DPI设备3的设备号和组号以及待升级的策略文件的版本号,如果DPI设备3同组中已有DPI设备3获取了对应新版本的策略文件,策略同步服务器1则返回已同步成功的DPI设备3的FTP访问地址、用户名和密码等信息和文件位置。
步骤410:此DPI设备3向已有DPI设备3发起FTP请求,获取新版本策略文件。
步骤411:此DPI设备3获取新版本策略文件成功后,向策略同步服务器1返回下载成功消息,并同时告知已下载策略文件的FTP访问地址、用户名和密码等信息和文件位置。
步骤412-413:所有向策略同步服务器1请求的DPI设备3都下载成功后,策略同步服务器1向所有请求的DPI设备3按组下发新版本策略文件生效命令,生效命令中含有生效时间等信息。同组中的DPI设备3收到消息后,按生效时间统一执行策略文件。
以上仅为本发明的优选实施例,并非因此限制本发明的专利范围,凡是利用本发明说明书及附图内容所作的等效结构或等效流程变换,或直接或间接运用在其他相关的技术领域,均同理包括在本发明的专利保护范围内。
工业实用性
如上所述,本发明实施例提供的一种策略文件同步管理的方法及策略同步服务器和管理设备,具有以下有益效果:通过设置策略同步服务器,可以实现策略大文件的自动升级,而不影响策略管理平台的运行性能。此外,还可以使得升级完成的新版本策略文件同时生效,从而可以有效改善策略大文件同步给策略管理平台造成的性能压力、同步时间长及同步不协调的问题。

Claims (9)

  1. 一种策略文件同步管理的方法,所述策略文件同步管理的方法包括以下步骤:
    接收策略管理平台发送的新版本通知消息;
    获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;
    接收DPI设备发送的更新策略文件请求消息;
    向DPI设备发送携带有新版本策略文件的下载地址的返回消息;
    待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件。
  2. 如权利要求1所述的策略文件同步管理的方法,其中,所述接收DPI设备发送的更新策略文件请求消息的步骤之后还包括:
    若接收到的更新策略文件请求消息的数量不在预设范围,则向DPI设备发送预定时间后再发送更新策略文件请求消息的延迟通知。
  3. 如权利要求2所述的策略文件同步管理的方法,其中,向DPI设备发送携带有新版本策略文件的下载地址的返回消息的步骤之后还包括:
    接收DPI设备再次发送的更新策略文件请求消息;
    获取再次发送更新策略文件请求消息的DPI设备的组号;
    若再次发送更新策略文件请求消息的DPI设备与已成功下载新版本策略文件的DPI设备属于同一组号,则向再次发送更新策略文件请求消息的DPI设备发送携带有新版本策略文件的访问地址的下载信息,以供再次发送更新策略文件请求消息的DPI设备从已成功下载新版本策略文件的DPI设备中下载新版本策略文件。
  4. 如权利要求3所述的策略文件同步管理的方法,其中,所述新版本通知消息包括新版本策略文件的版本号以及访问地址,所述访问地址包括新版本策略文件在策略管理平台内的FTP访问地址、用户名和密码以及文件位置。
  5. 一种策略同步服务器,所述策略同步服务器包括:
    第一接收模块,设置为接收策略管理平台发送的新版本通知消息;
    下载模块,设置为获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;
    第二接收模块,设置为接收DPI设备发送的更新策略文件请求消息;
    第一发送模块,设置为向DPI设备发送携带有新版本策略文件的下载地址的返回消息;
    第二发送模块,设置为待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件。
  6. 如权利要求5所述的策略同步服务器,其中,所述策略同步服务器还包括:
    第三发送模块,设置为若接收到的更新策略文件请求消息的数量不在预设范围,则向DPI设备发送预定时间后再发送更新策略文件请求消息的延迟通知。
  7. 如权利要求6所述的策略同步服务器,其中,所述策略同步服务器还包括:
    第三接收模块,设置为接收DPI设备再次发送的更新策略文件请求消息;
    获取模块,设置为获取再次发送更新策略文件请求消息的DPI设备的组号;
    第四发送模块,设置为若再次发送更新策略文件请求消息的DPI设备与已成功下载新版本策略文件的DPI设备属于同一组号,则向再次发送更新策略文件请求消息的DPI设备发送携带有新版本策略文件的访问地址的下载信息,以供再次发送更新策略文件请求消息的DPI设备从已成功下载新版本策略文件的DPI设备中下载新版本策略文件。
  8. 如权利要求7所述的策略同步服务器,其中,所述新版本通知消息包括新版本策略文件的版本号,所述访问地址包括新版本策略文件在策略管理平台内的FTP访问地址、用户名和密码以及文件位置。
  9. 一种管理设备,所述管理设备包括:
    策略同步服务器,包括:
    第一接收模块,设置为接收策略管理平台发送的新版本通知消息;
    下载模块,设置为获取新版本通知消息中携带的访问地址,根据获取的访问地址从所述策略管理平台下载新版本文件;
    第二接收模块,设置为接收DPI设备发送的更新策略文件请求消息;
    第一发送模块,设置为向DPI设备发送携带有新版本策略文件的下载地址的返回消息;
    第二发送模块,设置为待接收到DPI设备根据下载地址完成下载的成功消息后,向DPI设备发送策略文件生效指令,以使DPI设备同步执行新版本策略文件;
    策略管理平台,所述策略管理平台包括:
    保存模块,设置为生成新版本策略文件并保存;
    第三发送模块,设置为通过传输控制协议TCP向策略同步服务器发送保存的新版本策略文件的FTP访问地址、用户名和密码以及向DPI设备发送新版本策略文件的版本号以及策略同步服务器的IP地址和端口号;
    DPI设备,所述DPI设备包括:
    第三接收模块,设置为接收策略管理平台发送的新版本通知消息;
    第四发送模块,设置为向策略同步服务器发送更新策略文件请求消息;
    第四接收模块,设置为接收策略同步服务器发送的携带有新版本策略文件的下载地址的返回消息;
    更新模块,设置为获取新版本策略文件的下载地址,并根据所述下载地址从所述策略同步服务器下载新版本以完成策略文件的更新。
PCT/CN2015/083792 2014-11-21 2015-07-10 策略文件同步管理的方法及策略同步服务器和管理设备 WO2016078431A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410677456.1A CN105610883A (zh) 2014-11-21 2014-11-21 策略文件同步管理的方法及策略同步服务器和管理设备
CN201410677456.1 2014-11-21

Publications (1)

Publication Number Publication Date
WO2016078431A1 true WO2016078431A1 (zh) 2016-05-26

Family

ID=55990418

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/083792 WO2016078431A1 (zh) 2014-11-21 2015-07-10 策略文件同步管理的方法及策略同步服务器和管理设备

Country Status (2)

Country Link
CN (1) CN105610883A (zh)
WO (1) WO2016078431A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109375946A (zh) * 2018-09-03 2019-02-22 平安普惠企业管理有限公司 一种管理节点包管理器的组件包的方法及系统
CN114143377A (zh) * 2021-11-29 2022-03-04 杭州逗酷软件科技有限公司 资源请求的配置方法、服务端、客户端、设备和存储介质

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106358224B (zh) * 2016-08-31 2019-06-28 北京青石绿网科技有限公司 一种移动设备dpi数据及应用与基站安全同步的方法和系统
CN106254278A (zh) * 2016-08-31 2016-12-21 武汉绿色网络信息服务有限责任公司 一种在负载均衡环境下控制单用户带宽的方法
CN106657251A (zh) * 2016-10-25 2017-05-10 广东欧珀移动通信有限公司 一种数据同步方法和装置
CN106878445B (zh) * 2017-03-09 2020-09-11 腾讯科技(深圳)有限公司 资源文件更新方法及装置
CN111131243B (zh) * 2019-12-24 2022-05-27 北京拓明科技有限公司 Dpi系统策略处理方法及装置
CN111988750B (zh) * 2020-08-20 2023-06-13 多点(深圳)数字科技有限公司 一种通过超市中局域网下载应用包的方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101132573A (zh) * 2006-08-23 2008-02-27 中兴通讯股份有限公司 一种终端批量升级的实现方法
CN101720111A (zh) * 2009-02-03 2010-06-02 中兴通讯股份有限公司 一种下发深度包检测技术策略的方法和装置
CN101945021A (zh) * 2010-09-20 2011-01-12 中兴通讯股份有限公司 一种实现策略同步的方法及系统
US20140317269A1 (en) * 2010-11-12 2014-10-23 Telefonaktiebolaget L M Ericsson (Publ) Installation and Enforcement of Dynamic and Static PCC Rules in Tunneling Scenarios

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1658574A (zh) * 2005-03-23 2005-08-24 港湾网络有限公司 网络设备自动更新方法及系统
CN101854745B (zh) * 2009-04-02 2014-09-10 中兴通讯股份有限公司 软件版本的传输方法及装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101132573A (zh) * 2006-08-23 2008-02-27 中兴通讯股份有限公司 一种终端批量升级的实现方法
CN101720111A (zh) * 2009-02-03 2010-06-02 中兴通讯股份有限公司 一种下发深度包检测技术策略的方法和装置
CN101945021A (zh) * 2010-09-20 2011-01-12 中兴通讯股份有限公司 一种实现策略同步的方法及系统
US20140317269A1 (en) * 2010-11-12 2014-10-23 Telefonaktiebolaget L M Ericsson (Publ) Installation and Enforcement of Dynamic and Static PCC Rules in Tunneling Scenarios

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109375946A (zh) * 2018-09-03 2019-02-22 平安普惠企业管理有限公司 一种管理节点包管理器的组件包的方法及系统
CN109375946B (zh) * 2018-09-03 2023-11-03 顺维(重庆)科技有限公司 一种管理节点包管理器的组件包的方法及系统
CN114143377A (zh) * 2021-11-29 2022-03-04 杭州逗酷软件科技有限公司 资源请求的配置方法、服务端、客户端、设备和存储介质
CN114143377B (zh) * 2021-11-29 2024-04-02 杭州逗酷软件科技有限公司 资源请求的配置方法、服务端、客户端、设备和存储介质

Also Published As

Publication number Publication date
CN105610883A (zh) 2016-05-25

Similar Documents

Publication Publication Date Title
WO2016078431A1 (zh) 策略文件同步管理的方法及策略同步服务器和管理设备
WO2020135355A1 (zh) 一种无线网络配置方法及装置
KR101481443B1 (ko) 통신 네트워크의 디바이스 관리 방법 및 시스템
CN102118263B (zh) 配置信息的发布方法及系统
WO2016149908A1 (zh) 一种终端系统的升级方法、终端及系统
CN110191007A (zh) 节点管理方法、系统及计算机可读存储介质
US20160020947A1 (en) Synchronization of Configuration File of Virtual Application Distribution Chassis
WO2017097023A1 (zh) 无感知认证方法系统,基于该方法系统的控制方法、系统
WO2010034257A1 (zh) 一种终端配置和管理方法及终端装置
JP2015500520A (ja) エンドユーザデバイス、およびそれぞれのエンドユーザデバイスの遠隔管理のためのパブリッシュ/サブスクライブブローカを備えるシステム
CN104679528B (zh) 应用程序远程更新的方法和装置
CN103580921A (zh) 一种网络设备自动升级的方法及自动升级系统
EP2512064A1 (en) Data configuration method and apparatus
WO2014180235A1 (zh) 数据包过滤规则配置方法、装置及系统
CN107835257B (zh) 一种会话管理方法和装置
EP2661016A1 (en) Software downloading method and device
CN107450954A (zh) 一种基于云桌面的用户云终端升级方法
WO2021238554A1 (zh) 接入网络切片的方法、电子设备及存储介质
US9438603B2 (en) Method for managing access right of terminal to resource by server in wireless communication system, and device for same
CN111901162A (zh) 物联网设备及其配网方法、物联网系统
WO2015180251A1 (zh) 远程唤醒的方法、服务器及客户终端
CN105635222A (zh) 云终端升级方法、系统、网管服务器及代理服务器
EP2981043B1 (en) Method for managing portal device, and portal device and system
CN112637221B (zh) 一种设备控制方法及装置
US9736027B2 (en) Centralized enterprise image upgrades for distributed campus networks

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15860859

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15860859

Country of ref document: EP

Kind code of ref document: A1