WO2017012089A1 - 一种基于数据链路层的通信方法、设备和系统 - Google Patents

一种基于数据链路层的通信方法、设备和系统 Download PDF

Info

Publication number
WO2017012089A1
WO2017012089A1 PCT/CN2015/084772 CN2015084772W WO2017012089A1 WO 2017012089 A1 WO2017012089 A1 WO 2017012089A1 CN 2015084772 W CN2015084772 W CN 2015084772W WO 2017012089 A1 WO2017012089 A1 WO 2017012089A1
Authority
WO
WIPO (PCT)
Prior art keywords
data link
link layer
acp
network device
message
Prior art date
Application number
PCT/CN2015/084772
Other languages
English (en)
French (fr)
Inventor
杜宗鹏
蒋胜
刘冰
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201580062638.0A priority Critical patent/CN107005430B/zh
Priority to PCT/CN2015/084772 priority patent/WO2017012089A1/zh
Priority to EP19191634.5A priority patent/EP3633921B1/en
Priority to EP15898645.5A priority patent/EP3319272B1/en
Publication of WO2017012089A1 publication Critical patent/WO2017012089A1/zh
Priority to US15/875,028 priority patent/US10560378B2/en
Priority to US16/745,877 priority patent/US11153207B2/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/66Layer 2 routing, e.g. in Ethernet based MAN's
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/12Discovery or management of network topologies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2212/00Encapsulation of packets
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/30Definitions, standards or architectural aspects of layered protocol stacks
    • H04L69/32Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
    • H04L69/322Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
    • H04L69/324Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the data link layer [OSI layer 2], e.g. HDLC

Definitions

  • Embodiments of the present invention relate to the field of communications, and, more particularly, to a data link layer-based communication method, apparatus, and system.
  • Autonomic Network is a network that can support self-management, including network self-configuration, self-protection, self-healing, and self-optimization, which can improve the automation of the network.
  • a key technology in the self-organizing network is the establishment of the Autonomic Control Plane (ACP).
  • the self-organizing control plane ACP refers to the control plane in the ad hoc network, and the upper self-organizing functional entity can be used.
  • the ACP plane transmits control signaling.
  • IPv6 Internet Protocol Version 6
  • the network device is required to support IPv6, so that the ACP can be established, resulting in poor self-organizing network compatibility.
  • the embodiments of the present invention provide a data link layer-based communication method, device, and system.
  • the self-organizing network is established based on the data link layer, which can overcome the problem that the self-organizing network must rely on IPv6 in the prior art, and has better performance. Network compatibility.
  • a data link layer based communication method comprising:
  • the network device generates an adjacency discovery AD message, where the AD message includes a device identifier of the network device;
  • the network device encapsulates the AD message according to a frame of a data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where the source data link layer address is the network device Data link layer address;
  • the network device sends, according to the destination data link layer address, the AD message to the registered Registrar device based on the frame of the data link layer, where the Registrar device is a device supporting the domain certificate in the self-organizing network;
  • the network device receives the domain certificate sent by the Registrar device, and the domain certificate is the Registrar
  • the device allocates the network device according to the device identifier of the network device in the AD message;
  • the network device establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate.
  • the frame of the data link layer is a frame that conforms to an Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates
  • the data payload field of the frame of the data link layer carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field Indicates that the L2 ACP message is the AD message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • a data link layer based communication method comprising:
  • the registration Registrar device receives the frame-encapsulated adjacency discovery AD message from the network device, and the AD message includes the device identifier of the network device, where the data link layer frame includes the source data link layer address and destination. a data link layer address, where the source data link layer address is a data link layer address of the network device, and the destination data link layer address matches a data link layer address of the Registrar device;
  • the Registrar device determines that the network device is allowed to join the ad hoc network, assign a domain certificate to the network device according to the device identifier included in the AD message, and send the domain certificate to the network device;
  • the Registrar device establishes a self-organizing control plane ACP with the network device according to the domain certificate.
  • the frame of the data link layer is a frame that is consistent with an Ethernet protocol, and a Type value of a Type field of the frame of the data link layer indicates the data.
  • the data payload field of the link layer frame carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates the L2
  • the ACP packet is the AD message.
  • the network device is a neighbor device of the Registrar device, and the method further includes:
  • the Registrar device establishes a neighbor list of the Registrar device according to the AD message, and the neighbor list includes a device identifier of the network device and a data link layer address of the network device.
  • the device identifier of the network device is a unique device identifier UDI of the network device
  • the Registrar device determines that the network device is allowed to join the ad hoc network, assigning a domain certificate to the network device according to the device identifier included in the AD message, and sending the domain certificate to the network device, including:
  • the Registrar device determines that the whitelist has a UDI match of the network device, determining that the network device is allowed to join the ad hoc network, and sending the domain certificate according to the UDI to the network device, where the whitelist includes allowing the join UDI of devices that self-organize the network.
  • the device identifier of the network device is a secure unique device identifier S-UDI of the network device
  • the Registrar device determines that the network device is allowed to join the ad hoc network, assigning a domain certificate to the network device according to the device identifier included in the AD message, and sending the domain certificate to the network device, including:
  • the Registrar device determines that the device digital certificate corresponding to the S-UDI is valid by the verification server, it is determined that the network device is allowed to join the self-organizing network, and the domain certificate allocated according to the device digital certificate is sent to the network device.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • a data link layer based communication method is provided, the communication method being applied to an ad hoc network, the method comprising:
  • the first network device generates a data link layer self-organizing control plane L2 ACP message, where the first network device is an ad hoc device in the ad hoc network;
  • the first network device encapsulates the L2 ACP message according to a frame of a data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where the source data link layer address The data link layer address of the first network device;
  • the first network device sends, according to the destination data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device, where the second network device is also in the ad hoc network. Self-organizing the device, and the second network device is a neighbor device of the first network device.
  • the frame of the data link layer is a frame that is consistent with an Ethernet protocol, and a Type value of a Type field of the frame of the data link layer indicates the data.
  • the data payload field of the link layer frame carries the L2 ACP message.
  • the first network device generates a data link layer self-organizing control plane L2 ACP message, including:
  • the L2 The packet header of the ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, and the neighbor list of the first network device includes the neighbor device of the first network device.
  • Device identification and data link layer address when determining that the neighbor list of the first network device includes a matching item of the device identifier of the target device, generating the L2 ACP packet, the L2 The packet header of the ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, and the neighbor list of the first network device includes the neighbor device of the first network device.
  • the first network device encapsulates the L2 ACP message based on a frame of the data link layer, including:
  • the first network device encapsulates the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a data link layer address of the target device;
  • the first network device sends the L2 ACP packet encapsulated by the frame of the data link layer to the target device according to the data link layer address of the target device.
  • the first network device generates a data link layer self-organizing control plane L2 ACP message, including:
  • the L2 ACP packet is generated, and the L2 ACP packet is generated.
  • the packet header includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast message;
  • the first network device encapsulates the L2 ACP message based on a frame of the data link layer, including:
  • the first network device encapsulates the L2 ACP message according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the first network device generates an L2 ACP packet, including:
  • the L2 ACP message is generated, and the packet header of the L2 ACP message includes a flag bit field, and the value of the flag bit field is used to indicate the L2 ACP message.
  • the text is a broadcast message
  • the first network device encapsulates the L2 ACP message based on a frame of the data link layer, including:
  • the first network device encapsulates the L2 ACP message according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the first network device sends the L2 ACP packet based on the frame of the data link layer to the second network device according to the destination data link layer address, including:
  • the packet header of the L2 ACP packet further includes a packet for indicating the L2 ACP packet uniquely ID.
  • the packet header of the L2 ACP packet further includes timing information, the timing information
  • the receiving device for indicating the L2 ACP packet clears the L2 ACP packet when the time for buffering the L2 ACP packet exceeds a preset duration.
  • each device in the ad hoc network has an IP address
  • each of the self-organizing devices has the self-organizing device Mapping between device IDs and the IP address of each self-organizing device
  • the first network device generates a data link layer self-organizing control plane L2 ACP message, including:
  • the L2 ACP message is generated, where the L2 ACP message further includes a destination IP address, where the destination IP address is the IP address of the target device. address.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • a data link layer based communication method is provided, the communication method being applied to an ad hoc network, the method comprising:
  • the second network device receives the frame-encapsulated L2 ACP packet sent by the first network device, where the L2 ACP packet includes the destination device identifier, and the data link layer frame includes the source data link layer address. And a destination data link layer address, where the source data link layer address is a data link layer address of the first network device, and the destination data link layer address is opposite to a data link layer address of the second network device Matching, the second network device and the first network device are both self-organizing devices in the self-organizing network;
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet.
  • the frame of the data link layer is a frame that conforms to an Ethernet protocol, and a Type value of a Type field of the frame of the data link layer indicates the data.
  • the data payload field of the link layer frame carries the L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate the L2 ACP packet.
  • a unicast packet for the neighbor where the destination data link layer address of the frame of the data link layer is a data link layer address of the target device;
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the second network device determines that the destination device identifier is the device identifier of the second network device, and parses the L2 ACP packet.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field is used to indicate
  • the L2 ACP packet is a non-neighbor unicast packet, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the second network device determines that the device identifier of the second network device matches the destination device identifier, parsing the L2 ACP packet and buffering the L2 ACP packet;
  • the second network device determines that the device identifier of the second network device does not match the destination device identifier, buffering the L2 ACP packet, and according to the destination data link layer address of the frame of the data link layer, The neighboring device of the second network device forwards the L2 ACP packet based on the frame encapsulation of the data link layer.
  • the packet header of the L2 ACP packet further includes a flag bit field, where the value of the flag bit field is used for Instructing the L2 ACP message to be a broadcast message, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the layer address is forwarded to the neighboring device of the second network device by the L2 ACP packet encapsulated by the frame of the data link layer.
  • the packet header of the L2 ACP packet further includes a packet for uniquely identifying the L2 ACP packet.
  • Text ID
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the L2 ACP packet is processed by determining whether the device identifier of the second network device matches the destination device identifier.
  • the packet header of the L2 ACP packet further includes timing information, where The timing information is used to indicate that the receiving device of the L2 ACP packet clears the L2 ACP packet when the time for buffering the L2 ACP packet exceeds a preset duration.
  • the method also includes:
  • the second network device determines that the time for buffering the L2 ACP packet exceeds a preset duration indicated by the timing information, the L2 ACP packet is cleared.
  • each of the self-organizing devices in the ad hoc network has an IP address
  • each of the self-organizing devices has the self-organizing device A mapping between the device identifier of the organization device and the IP address of the self-organizing device, wherein the L2 ACP message further includes a destination IP address
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the second network device determines that the device identifier of the second network device does not match the destination device identifier of the L2 ACP packet
  • the destination data link layer address of the L2 ACP packet is sent to the second network device.
  • the neighbor device forwards the L2 ACP packet.
  • the second network device determines that the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, and the IP address of the second network device matches the destination IP address of the L2 ACP packet When matching, the L2 ACP message is parsed.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • a fifth aspect provides a network device, where the network device is applied to an ad hoc network, where the network device includes:
  • a generating module configured to generate, by the network device, a neighbor discovery AD message, where the AD message includes a device identifier of the network device;
  • An encapsulating module configured to encapsulate the AD message generated by the generating module according to a data link layer frame, where the data link layer frame includes a source data link layer address and a destination data link layer address, where the source data link The layer address is the data link layer address of the network device;
  • a sending module configured to send to the registration Registrar device based on the data link layer address of the destination The AD message according to the frame encapsulation of the data link layer determined by the encapsulating module, where the Registrar device is a device supporting a domain certificate in an ad hoc network;
  • a receiving module configured to receive a domain certificate sent by the Registrar device, where the domain certificate is allocated by the Registrar device according to the device identifier of the network device in the AD message;
  • the frame of the data link layer is a frame that is consistent with an Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates
  • the data payload field of the frame of the data link layer carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field Indicates that the L2 ACP message is the AD message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the sixth aspect provides a registration Registrar device, wherein the Registrar device is used in a self-organizing network, and the Registrar device supports a device that allocates a domain certificate in the self-organizing network, and the Registrar device includes:
  • a receiving module configured to receive a data link layer-based frame-decapsulated adjacency discovery AD message from the network device, where the AD message includes a device identifier of the network device, where the data link layer frame includes a source data link layer address And a destination data link layer address, where the source data link layer address is a data link layer address of the network device, and the destination data link layer address matches a data link layer address of the Registrar device;
  • a sending module configured to allocate a domain certificate to the network device according to the device identifier included in the AD message received by the receiving module, and send the domain certificate to the network device, when determining that the network device is allowed to join the ad hoc network;
  • the ACP establishing module is configured to establish an ad hoc control plane ACP with the network device according to the domain certificate sent by the sending module.
  • the frame of the data link layer is a frame that is consistent with an Ethernet protocol, and a Type value of a Type field of the frame of the data link layer indicates the data.
  • the data payload field of the link layer frame carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates the L2
  • the ACP packet is the AD message.
  • the network device is a neighbor device of the Registrar device, and the Registrar device further includes:
  • the neighbor list establishing module is configured to establish a neighbor list of the Registrar device according to the AD message, where the neighbor list includes a device identifier of the network device and a data link layer address of the network device.
  • the device identifier of the network device is a unique device identifier UDI of the network device
  • the sending module is specifically configured to: when it is determined that the whitelist has a matching item of the UDI of the network device, determine that the network device is allowed to join the self-organizing network, and send the domain certificate according to the UDI to the network device, where
  • the whitelist includes UDIs that allow devices that join the ad hoc network.
  • the device identifier of the network device is a secure unique device identifier S-UDI of the network device
  • the sending module is specifically configured to: when it is determined by the verification server that the device digital certificate corresponding to the S-UDI is valid, determine that the network device is allowed to join the ad hoc network, and send the network device according to the device digital certificate. Domain certificate.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • a network device is provided, where the network device is used as a first network device, and the first network device is applied to an ad hoc network, where the first network device includes:
  • the network device is a self-organizing device in the self-organizing network
  • the encapsulating module is configured to encapsulate the L2 ACP packet generated by the generating module according to a data link layer frame, where the data link layer frame includes a source data link layer address and a destination data link layer address, where the source The data link layer address is a data link layer address of the first network device;
  • a sending module configured to send, according to the destination data link layer address, the L2 ACP packet that is encapsulated by the data link layer determined by the encapsulating module to the second network device, where the second network device is also An ad hoc device in a self-organizing network, and the second network device is a neighbor device of the first network device.
  • the frame of the data link layer is a frame that is consistent with an Ethernet protocol, and a Type value of a Type field of the frame of the data link layer indicates the data.
  • the data payload field of the link layer frame carries the L2 ACP message.
  • the generating module is specifically configured to: when it is required to communicate with the target device in the ad hoc network, when determining When the neighbor list of the first network device includes the matching of the device identifier of the target device, the L2 ACP packet is generated, and the header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field is used for Instructing the L2 ACP message to be a neighbor unicast message, where the neighbor list of the first network device includes a device identifier and a data link layer address of the neighbor device of the first network device;
  • the encapsulating module is specifically configured to encapsulate the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a data link layer address of the target device;
  • the sending module is specifically configured to send, according to the data link layer address of the target device, the L2 ACP packet encapsulated by the frame of the data link layer to the target device.
  • the generating module is specifically configured to: when it is required to communicate with the target device in the ad hoc network, when determining When the neighbor list does not include the matching of the device identifier of the target device, the L2 ACP packet is generated, and the header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field is used to indicate the L2 ACP.
  • the packet is a non-neighbor unicast packet.
  • the encapsulating module is specifically configured to encapsulate the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the sending module is configured to send, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the fourth aspect of the seventh aspect is specifically configured to: when the control message is broadcasted in the ACP, generate the L2 ACP packet, where the header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field is used for Instructing the L2 ACP message to be a broadcast message;
  • the encapsulating module is specifically configured to encapsulate the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the sending module is configured to send, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the packet header of the L2 ACP packet further includes a packet for uniquely indicating the L2 ACP packet. ID.
  • the packet header of the L2 ACP packet further includes timing information, the timing information
  • the receiving device for indicating the L2 ACP packet clears the L2 ACP packet when the time for buffering the L2 ACP packet exceeds a preset duration.
  • each device in the ad hoc network has an IP address
  • each of the self-organizing devices has the self-organizing device Mapping between device IDs and the IP address of each self-organizing device
  • the generating module is specifically configured to: when the IP session is required to communicate with the target device in the ad hoc network, generate the L2 ACP packet, where the L2 ACP packet further includes a destination IP address, where the destination IP address is The IP address of the target device.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • a network device is provided, where the network device is used as a second network device, and the second network device is applied to an ad hoc network, where the second network device includes:
  • a receiving module configured to receive a data encapsulation-based L2 ACP packet sent by the first network device, where the L2 ACP packet includes a destination device identifier, where the data link layer frame includes a source data link layer Address and destination data link layer address, wherein the source data link layer address is the first a data link layer address of the network device, where the destination data link layer address matches the data link layer address of the second network device, where the second network device and the first network device are both in the ad hoc network Self-organizing equipment;
  • the processing module is configured to process the L2 ACP packet received by the receiving module by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet.
  • the frame of the data link layer is a frame that is consistent with an Ethernet protocol, and a Type value of a Type field of the frame of the data link layer indicates the data.
  • the data payload field of the link layer frame carries the L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate the L2 ACP packet A unicast packet for the neighbor, where the destination data link layer address of the frame of the data link layer is a data link layer address of the target device;
  • the processing module is specifically configured to determine that the destination device identifier is the device identifier of the second network device, and parse the L2 ACP packet.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field is used to indicate
  • the L2 ACP packet is a non-neighbor unicast packet, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the processing module is configured to: when determining that the device identifier of the second network device matches the destination device identifier, parsing the L2 ACP packet, and buffering the L2 ACP packet;
  • the processing module is configured to: when determining that the device identifier of the second network device does not match the target device identifier, buffering the L2 ACP packet, and according to the destination data link layer address of the frame of the data link layer, The neighboring device of the second network device forwards the L2 ACP packet based on the frame encapsulation of the data link layer.
  • the packet header of the L2 ACP packet further includes a flag bit field, where the value of the flag bit field is used for Instructing the L2 ACP message to be a broadcast message, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the processing module is specifically configured to: determine that the device identifier of the second network device matches the destination device identifier, parse the L2 ACP packet, and cache the L2 ACP packet, and the frame according to the data link layer.
  • the destination data link layer address is forwarded to the neighbor device of the second network device Sending the L2 ACP message based on the frame of the data link layer.
  • the packet header of the L2 ACP packet further includes a packet for uniquely identifying the L2 ACP packet.
  • Text ID
  • the processing module is configured to process the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier when determining that the packet ID is not cached locally.
  • the packet header of the L2 ACP packet further includes timing information, where The timing information is used to indicate that the receiving device of the L2 ACP packet clears the L2 ACP packet when the time for buffering the L2 ACP packet exceeds a preset duration.
  • the second network device further includes:
  • the cache clearing module is configured to clear the L2 ACP message when it is determined that the time for buffering the L2 ACP message exceeds a preset duration indicated by the timing information.
  • each of the self-organizing devices in the ad hoc network has an IP address
  • each of the self-organizing devices has the self-organizing device A mapping between the device identifier of the organization device and the IP address of the self-organizing device, wherein the L2 ACP message further includes a destination IP address
  • the processing module is specifically configured to: when determining that the device identifier of the second network device does not match the destination device identifier of the L2 ACP packet, to the second network according to the destination data link layer address of the L2 ACP packet The neighbor device of the device forwards the L2 ACP packet.
  • the device identifier of the second network device matches the destination device identifier of the L2 ACP packet
  • the IP address of the second network device matches the destination IP address of the L2 ACP packet
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • a ninth aspect provides a data link layer based system, the system comprising the fifth aspect described above The provided network equipment and the registered Registrar device provided by the sixth aspect.
  • a tenth aspect provides a data link layer based system, the system comprising the network device provided in the seventh aspect and the network device provided in the eighth aspect.
  • the data link layer is sent to the Registrar device based on the destination data link layer address of the frame of the data link layer.
  • the AD message is received by the Registrar device, and the self-organizing control plane ACP is established with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • FIG. 1 is a schematic flowchart of a data link layer-based communication method provided by an embodiment of the present invention.
  • FIG. 2 is a schematic diagram of a data link layer based communication method provided by an embodiment of the present invention.
  • FIG. 3 is another schematic flowchart of a data link layer-based communication method according to an embodiment of the present invention.
  • FIG. 4 is still another schematic flowchart of a data link layer-based communication method according to an embodiment of the present invention.
  • FIG. 5 is still another schematic flowchart of a data link layer-based communication method according to an embodiment of the present invention.
  • FIG. 6 is a schematic block diagram of a network device according to an embodiment of the present invention.
  • FIG. 7 is a schematic block diagram of a Registrar device according to an embodiment of the present invention.
  • FIG. 8 is a schematic block diagram of another network device according to an embodiment of the present invention.
  • FIG. 9 is a schematic block diagram of still another network device according to an embodiment of the present invention.
  • FIG. 10 is a schematic block diagram of a data link layer based system according to an embodiment of the present invention.
  • FIG. 11 is a schematic diagram of a data link layer based system according to another embodiment of the present invention. block diagram.
  • FIG. 12 is a schematic block diagram of a network device according to another embodiment of the present invention.
  • FIG. 13 is a schematic block diagram of a Registrar device according to another embodiment of the present invention.
  • FIG. 14 is a schematic block diagram of another network device according to another embodiment of the present invention.
  • FIG. 15 is a schematic block diagram of still another network device according to another embodiment of the present invention.
  • the technical solution of the present invention can be applied to various communication systems, such as fixed network communication systems, specifically, fixed network systems such as access network systems, aggregation network systems, backbone network systems, private network systems, and the like.
  • the technical solution of the present invention can be applied to a mobile communication system, and specifically, for example, a Universal Mobile Telecommunication System (UMTS) or a Global System of Mobile communication (GSM).
  • UMTS Universal Mobile Telecommunication System
  • GSM Global System of Mobile communication
  • the mobile communication system such as a system, a general packet radio service (“GPRS”), and a long term evolution (“LTE”) system, is not limited in this embodiment of the present invention.
  • GPRS general packet radio service
  • LTE long term evolution
  • the device involved in the embodiment of the present invention may be a network device, specifically, for example, a router, a switch, or a user equipment, where the user equipment may also be referred to as a terminal or a mobile station (Mobile Station, simply referred to as " MS"), mobile terminal, etc., the user equipment can access the Internet or the enterprise network via a wired network; the user equipment can also communicate with the radio access network (Radio Access Network, "RAN”) and one or Multiple core networks communicate, for example, the user device can be a mobile phone (or "cellular" phone), a computer with a mobile terminal, or can be portable, pocket, handheld, computer built, or in-vehicle mobile Devices that exchange language and/or data with the radio access network.
  • RAN Radio Access Network
  • the prior art is based on the network layer (also referred to as the L3 layer) to establish an ACP.
  • This hair Ming is based on the data link layer (also known as the L2 layer) to establish ACP.
  • the establishment of ACP can not be aware of the IP protocol, that is, it does not depend on whether the network device supports the IPv4 protocol or supports IPv6. Protocols, and network devices that support IPv4 and network devices that support IPv6 can form a self-organizing network to improve network compatibility and reduce deployment difficulties.
  • the devices involved in the embodiments of the present invention are all self-organizing devices, that is, the device supports the self-organizing feature, and the device has its own unique device identifier (Uniform Device Identification, referred to as "UDI”), or device certificate (IDevID). Certificate).
  • UMI Uniform Device Identification
  • IDevID device certificate
  • the device supports the self-organizing feature, which means that the device has the function of automatically establishing an ACP or automatically joining the ACP.
  • the registered Registrar device in the embodiment of the present invention refers to a device capable of assigning a domain certificate to a device (including the Registrar device) in the self-organizing domain, for example, the Registrar device is connected to a digital certificate authentication authority, and It is possible to communicate, in other words, the Registrar device can assign domain certificates to all devices in the self-organizing domain through the digital certificate authentication management structure. Specifically, for example, the Registrar device determines whether the device is allowed to join the self-organizing domain according to the device identifier of the device, and if it is determined to be allowed, assigns a domain certificate according to the device identifier of the device, and vice versa.
  • the device identifier of the device may be a unique device identifier UDI, or may be a device certificate, which is not limited by the embodiment of the present invention. It should be understood that the Registrar device first assigns a domain certificate to itself.
  • FIG. 1 is a schematic flowchart of a data link layer-based communication method 100 according to an embodiment of the present invention.
  • the method may be performed, for example, by a network device in an ad hoc network.
  • the method 100 includes:
  • the network device generates a neighbor discovery AD message, where the AD message includes a device identifier of the network device.
  • the network device encapsulates the AD message according to a frame of a data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where the source data link layer address is the network The data link layer address of the device;
  • the destination data link layer address of the frame of the data link layer may be a broadcast data link layer address or a data link layer address of a neighbor device of the network device.
  • the network device sends, according to the destination data link layer address, the AD message to the Registrar device according to the frame of the data link layer, where the Registrar device is a device that supports the domain certificate in the ad hoc network.
  • the network device receives a domain certificate sent by the Registrar device, where the domain certificate is The Registrar device allocates the device identifier of the network device according to the AD message to the network device;
  • the network device establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, and establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • the data link layer address is a Media Access Control (MAC) address.
  • MAC Media Access Control
  • the data link layer address is taken as an example of a MAC address.
  • AD a data link layer based frame encapsulation discovery
  • the AD message is directly encapsulated based on the frame of the data link layer, and the AD message is not encapsulated based on the IP packet.
  • the AD message is directly encapsulated in the frame of the data link layer, and is no longer encapsulated based on the IP packet.
  • the AD message in the embodiment of the present invention may not be aware of the IP protocol or the IP address, and thus, the implementation of the ad hoc control plane ACP may not depend on the IP protocol, such as IPv6 or IPv4. Therefore, in the embodiment of the present invention, implementing ACP based on the data link layer has better network compatibility than the prior art, and also reduces the difficulty of self-organizing network deployment.
  • the destination data link layer address of the frame of the data link layer is a data link layer broadcast address or a data link layer address of a neighbor device of the network device, where the neighbor device may be the Registrar device or Proxy device.
  • the Registrar device may be a neighboring device of the network device or a non-neighbor device, which is not limited in this embodiment of the present invention.
  • the neighbor device of the network device includes the Registrar device
  • the destination MAC address of the frame of the data link layer is a MAC address or a MAC broadcast address of the Registrar device.
  • the network device sends, according to the destination data link layer address, the AD message to the Registrar device based on the frame of the data link layer, where the Registrar device is a device that supports the domain certificate in the self-organizing network, including:
  • the network device directly sends the AD message based on the data link layer frame encapsulation to the Registrar device according to the destination MAC address.
  • the AD message goes from the network device to the Registrar device without forwarding from the intermediate device.
  • This situation can also be called, the AD message is transmitted from the network device to the Registrar device in the manner of neighbor unicast.
  • the Registrar device is not a neighbor device of the network device
  • the destination MAC address of the frame of the data link layer is a MAC broadcast address.
  • the network device sends, according to the destination data link layer address, the AD message to the Registrar device based on the frame of the data link layer, where the Registrar device is a device that supports the domain certificate in the self-organizing network, including:
  • the network device sends the frame based on the data link layer to the Registrar device supporting the domain certificate in the self-organizing network by using a Proxy device having a domain certificate assigned by the Registrar device based on the destination data link layer address. AD message.
  • FIG. 2 is used as an example.
  • the network device is the device 5 in FIG. 2, and the Registrar device is the device 1 in FIG. 2.
  • the device 5 sends an AD message to the intermediate device 2, and the intermediate device 2
  • the domain device 2 is requested to apply the domain certificate of the device 5 to the Registrar device, and the domain device 2 receives the domain certificate assigned by the Registrar device for the device 5, and the domain certificate of the device 5 is obtained.
  • the device is sent to the device 5, wherein the intermediate device 2 is a network device that already has a domain certificate assigned by the Registrar device, and the network device that already has the domain certificate may be referred to as a proxy device.
  • the network device establishes an ad hoc control plane ACP with the Registrar device.
  • the network device and the Registrar device are based on the domain certificate of the network device and the domain certificate of the Registrar device (the Registrar device first assigns a domain certificate to itself) ), mutual authentication, establishing a secure connection at the data link layer, such as establishing a MACsec path, this process can be called establishing an ad hoc control plane ACP between the network device and the Registrar device.
  • the frame of the data link layer is a frame defined by the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the L2 ACP message in the embodiment of the present invention is used to indicate a message transmitted on the ACP based on the data link layer.
  • the AD message is encapsulated by a frame of the data link layer, that is, the data payload field of the frame of the data link layer carries the AD message, where the Type field of the frame of the data link layer indicates that the data payload field carries
  • the message is an L2 ACP message, and the L2 ACP message can be considered to include the AD message.
  • the Type value of the Type field of the frame of the data link layer has a Type value of 0x88e7.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates that the L2 ACP packet is the AD message.
  • the packet header of the AD message includes a flag bit field for indicating that the L2 ACP message is the AD message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • Table 1 shows the format of an AD message provided according to an embodiment of the present invention:
  • the AD message according to the embodiment of the present invention includes a packet header and a packet content, wherein the packet content includes information such as a device identifier (such as a UDI) or a domain certificate of the network device, and it should be understood that when After the network device is assigned a domain certificate, its domain message can carry its domain certificate.
  • a device identifier such as a UDI
  • a domain certificate of the network device it should be understood that when After the network device is assigned a domain certificate, its domain message can carry its domain certificate.
  • the packet header of the AD message can be as shown in Table 2:
  • the header of the AD message includes a version field, a flag bit field, a protocol field, and a packet length field, where the value of the version field indicates the version of the protocol corresponding to the AD message, for example, the version field.
  • the protocol field is 8 bits in total, for example, the value of the protocol field corresponding to the IP protocol can be used; the packet length field refers to a total of 16 bits, and the value thereof Used to indicate the length of the entire packet.
  • the format of the AD message after the frame encapsulation of the data link layer includes the frame header, the packet header, and the packet content of the frame of the data link layer, where the packet header and the message content are as above.
  • the frame header of the frame of the data link layer includes a destination MAC address, a source MAC address, and a type Type field, where the destination MAC address may be a MAC broadcast address or a MAC address of a neighbor device of the network device; the source MAC address is the network The MAC address of the device.
  • the Type value of the type Type field indicates that the data payload field of the frame of the data link layer carries the data link layer self-organizing control plane L2 ACP message. Specifically, the Type field can be applied with a value of 0x88e7.
  • Table 1, Table 2, and Table 3 are by way of example only and not limiting.
  • the AD message may also be referred to as an L2 ACP message
  • the device at the data link layer may identify the AD message, that is, the AD message may be effectively transmitted and effectively received at the data link layer.
  • the Registrar device After receiving the AD message based on the data link layer encapsulation of the network device, the Registrar device obtains the AD message by parsing the frame of the data link layer, and acquires the device of the network device carried in the AD message. Identify information such as UDI or MAC address.
  • the network device receives the domain certificate sent by the Registrar device, where the domain certificate is allocated by the Registrar device according to the device identifier of the network device in the AD message, specifically, the Registrar device is configured according to the device.
  • the identifier determines whether the network device is allowed to join the ad hoc network, and if the permission is determined, the domain certificate is allocated according to the device identifier, and is sent to the network device.
  • the device identifier is a Unique Device Identification (UDI) or a Safe Unique Device Identification (SUDI).
  • UMI Unique Device Identification
  • SUVI Safe Unique Device Identification
  • the device identifier of the network device is the only one of the network device.
  • a device identification UDI is the only one of the network device.
  • the network device receives the domain certificate sent by the Registrar device according to the device identifier, including:
  • the white device Receiving, by the network device, the domain certificate sent by the Registrar device according to the UDI of the network device, where the domain certificate is configured by the Registrar device for determining that the whitelist has a UDI match of the network device, the white device
  • the list includes UDIs for devices that are allowed to join the self-organizing domain.
  • the Registrar device determines whether the network device is allowed to join the self-organizing domain by using a white list, and the white list records the UDI of the device allowed to join the self-organizing domain, when the Registrar device
  • a match of the UDI of the network device is found in the whitelist, for example, through a digital certificate authentication management structure, a domain certificate is assigned to the network device based on the UDI of the network device; if the Registrar network device cannot find the whitelist A match of the UDI of the network device determines that the network device is not allowed to join the self-organizing domain.
  • the configuration of the whitelist of the Registrar device may be manually configured, or may be imported by other means, which is not limited by the embodiment of the present invention.
  • the device identifier of the network device is a secure unique device identifier SUDI of the network device
  • the network device receives the domain certificate sent by the Registrar device according to the device identifier, including:
  • the network device receives the domain certificate sent by the Registrar device according to the SUDI, and the domain certificate is that the Registrar device determines that the device digital certificate corresponding to the SUDI is valid, and determines that the network device is allowed to join the self-organizing domain according to the verification result of the verification server. When it is determined, the network device is allowed to join the self-organizing domain, and is allocated according to the device identifier for the network device.
  • the network device sends a device digital certificate corresponding to the SUDI to the Registrar device;
  • the Registrar device allocates a domain certificate to the network device according to the SUDI when verifying that the device digital certificate is valid and determining that the network device is allowed to join the self-organizing domain according to the verification result of the verification server.
  • the device identification is described as UDI as an example.
  • the AD message is continuously sent periodically (for example, every 10 s) to determine its own neighbor device, and the AD message includes the UDI of the self-organizing device.
  • the AD message may also carry its domain certificate.
  • Each device builds its own neighbors based on receiving AD messages. Home list.
  • the device A receives an AD message and determines that the destination MAC address (for example, the MAC broadcast address) carried in the AD message matches the MAC address of the local device, the source sending device of the AD message is its own neighbor. The device updates the UDI and source MAC address carried in the AD message to its neighbor list.
  • the destination MAC address for example, the MAC broadcast address
  • the method 100 further includes:
  • the network device receives a frame-encapsulated AD message based on a data link layer of a neighboring device of the network device, where the AD message includes a device identifier and a MAC address of the neighbor node.
  • the network device establishes a neighbor list of the network device according to the AD message, where the neighbor list includes a device identifier of the neighbor device and a data link layer address of the neighbor device.
  • the neighbor list includes the device identifier of the neighbor device and the data link layer address (MAC address) of the neighbor device, and the neighbor list may further include the security authentication information of the neighbor device, specifically, as shown in Table 4. Shown as follows:
  • the neighbor list of a device includes the UDI and MAC address of the neighbor device, and the security information and the authentication information.
  • the security information may include information such as security authentication type information, authentication time, and the like.
  • the certificate chain if available; the security authentication information (Validity of the trust) is used to indicate whether the neighbor device is authenticated by the Registrar device, that is, whether the domain certificate is assigned.
  • FIG. 2 shows a schematic diagram of an ad hoc network, which schematically shows 11 self-organizing devices, wherein it is assumed that device 1 is a Registrar device, devices 2, 3 and 4 are neighbor devices of device 1, and device 5 6 and 6 are neighbor devices of device 2, devices 7 and 8 are neighbor devices of device 6, device 7 is also a neighbor device of device 5, devices 9 and 10 are neighbor devices of device 3, and device 11 is a neighbor device of device 4.
  • device 2 sends a UDI including device 2 to the Registrar device.
  • the AD message (corresponding to the case where the network device is a neighbor device of the Registrar device in the embodiment of the present invention), and the Registrar device finds the match of the UDI of the device 2 in the whitelist, and allocates the domain certificate to the device 2. Then, the Registrar device and device 2 authenticate each other based on their respective domain certificates, and create a secure connection, that is, an ACP is established between device 1 and device 2.
  • the Registrar device assigns a domain certificate to device 2 and establishes a secure connection with it, that is, device 2 is authenticated. At this time, the device 2 can act as a proxy point or an authentication point to connect its own neighbor device. The AD message is forwarded to the Registrar device so that the Registrar device can authenticate the neighbor device of device 2.
  • the neighboring device 5 of the device 2 has not obtained the domain certificate.
  • the device 2 detects that the device 5 does not have a domain certificate, and the device 2 can Determining that the device 5 has not been authenticated, triggers the process of forwarding the AD message of the device 5, because the device 2 has established a secure connection with the Registrar device, so the device 2 is the UDI of the known Registrar device, so the device 2 can Based on the UDI of the Registrar device, the AD message of the device 5 is forwarded to the Registrar device.
  • the process of authenticating the device 5 and the process of assigning the domain certificate to the device 2 is similar to the process of assigning the domain certificate to the device 2, and is not described here. It should be understood that after the Registrar assigns the domain certificate to the device 5, it is also forwarded to the device 5 through the device 2.
  • the device 5 before the device 5 is assigned to the domain certificate, there is no domain certificate in the AD message of the device 5.
  • the device 2 corresponds to the neighbor list established by the AD message of the device 5, and the device 5 corresponds to the device.
  • the Validity of the trust entry is uncertified.
  • the domain certificate is carried in the AD message sent by the device 5 after the domain 5 is obtained.
  • the AD messages of other self-organizing devices shown in FIG. 2 are transmitted to the Registrar device for authentication, assuming that the Registrar device is as shown in FIG. All the devices shown are assigned domain certificates, that is, the secure connections are established between the devices shown in Figure 2, that is, the self-organizing control plane ACP is established between the 11 devices.
  • FIG. 2 The process of the ACP, Figure 2 is only an example and not a limitation.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, and establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • the data link layer-based communication method provided by the embodiment of the present invention is described in the following with reference to FIG. 1 and FIG. 2, and the following describes the embodiment of the present invention from the perspective of the receiving end device of the AD message.
  • a data link layer based communication method is provided.
  • FIG. 3 is a schematic flowchart of a data link layer-based communication method 200 provided by an embodiment of the present invention.
  • the method may be performed, for example, by a registered Registrar device supporting a domain certificate in an ad hoc network.
  • the method 200 includes :
  • the Registrar device receives a frame-encapsulated adjacency discovery AD message from the network device, and the AD message includes a device identifier of the network device, where the data link layer frame includes a source data link layer address and a destination data link layer address, where the source data link layer address is a data link layer address of the network device, and the destination data link layer address matches a data link layer address of the Registrar device;
  • matching the data link layer address of the destination with the data link layer address of the Registrar device means that the destination data link layer address is the data link layer address of the Registrar device, or the destination data link.
  • the layer address is the broadcast data link layer address. It should be understood that the broadcast data link layer address can be considered to match any fixed data link layer address.
  • the Registrar device establishes an ad hoc control plane ACP with the network device according to the domain certificate.
  • the network device and the Registrar device are based on the domain certificate of the network device and the domain certificate of the Registrar device (the Registrar device first assigns a domain certificate to itself), mutually authenticate, and establish a secure connection at the data link layer, for example, establishing a MACsec path.
  • This process can be called A self-organizing control plane ACP is established between the network device and the Registrar device.
  • the adjacency discovery AD message of the device is encapsulated based on a frame of the data link layer; the AD message is sent to a Registrar device that allocates a domain certificate in the ad hoc network based on the data link layer address; the Registrar device The device is assigned a domain certificate according to the AD message; based on the domain certificate, the device establishes a self-organizing control plane ACP with the Registrar device.
  • the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • AD a data link layer based frame encapsulation discovery
  • the AD message is directly encapsulated based on the frame of the data link layer, and the AD message is not encapsulated based on the IP packet.
  • the AD message is directly encapsulated in the frame of the data link layer, and is no longer encapsulated based on the IP packet.
  • the AD message in the embodiment of the present invention may not be aware of the IP protocol or the IP address, and thus, the implementation of the ad hoc control plane ACP may not depend on the IP protocol, such as IPv6 or IPv4. Therefore, in the embodiment of the present invention, implementing ACP based on the data link layer has better network compatibility than the prior art, and also reduces the difficulty of self-organizing network deployment.
  • the data link layer address is a Media Access Control (MAC) address.
  • MAC Media Access Control
  • the data link layer address is taken as an example of a MAC address.
  • the destination data link layer address of the frame of the data link layer is a data link layer broadcast address or a data link layer address of a neighbor device of the network device
  • the Registrar device may be a neighbor device of the network device. It can also be a non-neighbor device, which is not limited in this embodiment of the present invention.
  • the neighbor device of the network device includes the Registrar device
  • the destination MAC address of the frame of the data link layer is a MAC address or a MAC broadcast address of the Registrar device.
  • the network device directly sends the AD message based on the data link layer frame encapsulation to the Registrar device according to the destination MAC address.
  • the AD message is sent from the network device to the Registrar device. No need for forwarding of intermediate devices. This situation can also be called, the AD message is transmitted from the network device to the Registrar device in the manner of neighbor unicast.
  • the Registrar device is not a neighbor device of the network device
  • the destination MAC address of the frame of the data link layer is a MAC broadcast address.
  • the Registrar device is configured to obtain an AD message from the adjacency of the data link layer based on the data link layer of the network device, including:
  • the Registrar device receives the adjacency discovery AD message of the network device by using a proxy device having a domain certificate assigned by the Registrar device.
  • FIG. 2 a schematic diagram of the ad hoc network shown in FIG. 2, wherein device 1 is a Registrar device, devices 2, 3, and 4 are neighbor devices of device 1, and devices 5 and 6 are neighbor devices of device 2, and device 7 And 8 is a neighbor device of device 6, device 7 is also a neighbor device of device 5, devices 9 and 10 are neighbor devices of device 3, and device 11 is a neighbor device of device 4.
  • the device 2 sends an AD message including the UDI of the device 2 to the Registrar device (corresponding to the case where the network device is a neighbor device of the Registrar device in the embodiment of the present invention), and the Registrar device finds the UDI match of the device 2 in the whitelist.
  • the device 2 is assigned a domain certificate.
  • the Registrar device and device 2 authenticate each other based on their respective domain certificates, and create a secure connection, that is, an ACP is established between device 1 and device 2.
  • the Registrar device assigns a domain certificate to device 2 and establishes a secure connection with it, that is, device 2 is authenticated. At this time, the device 2 can act as a proxy point or an authentication point to connect its own neighbor device. The AD message is forwarded to the Registrar device so that the Registrar device can authenticate the neighbor device of device 2.
  • the neighboring device 5 of the device 2 has not obtained the domain certificate.
  • the device 2 detects that the device 5 does not have a domain certificate, and the device 2 can Determining that the device 5 has not been authenticated, triggers the process of forwarding the AD message of the device 5, because the device 2 has established a secure connection with the Registrar device, so the device 2 is the UDI of the known Registrar device, so the device 2 can Based on the UDI of the Registrar device, the AD message of the device 5 is forwarded to the Registrar device.
  • the process of authenticating the device 5 and the process of assigning the domain certificate to the device 2 is similar to the process of assigning the domain certificate to the device 2, and is not described here. It should be understood that after the Registrar assigns the domain certificate to the device 5, it is also forwarded to the device 5 through the device 2.
  • the device 5 before the device 5 is assigned to the domain certificate, there is no domain certificate in the AD message of the device 5, and at this time, the device 2 establishes a neighbor column according to the AD message of the device 5. In the table, the Validity of the trust entry corresponding to Device 5 is unauthenticated. The domain certificate is carried in the AD message sent by the device 5 after the domain 5 is obtained.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the L2 ACP message in the embodiment of the present invention is used to indicate a message transmitted on the ACP based on the data link layer.
  • the AD message is encapsulated by a frame of the data link layer, that is, the data payload field of the frame of the data link layer carries the AD message, where the Type field of the frame of the data link layer indicates that the data payload field carries
  • the message is an L2 ACP message, and the L2 ACP message can be considered to include the AD message.
  • the Type value of the Type field of the frame of the data link layer has a Type value of 0x88e7.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates that the L2 ACP packet is the AD message.
  • the packet header of the AD message includes a flag bit field for indicating that the L2 ACP message is the AD message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the network device is a neighbor device of the Registrar device, and the method 200 further includes:
  • the Registrar device establishes a neighbor list of the Registrar device according to the AD message, where the neighbor list includes a device identifier of the network device and a data link layer address of the network device.
  • the neighbor list established by the Registrar device according to the AD message is as shown in Table 4, as described in detail above.
  • the domain device is assigned a domain certificate according to the device identifier, and is sent to the network device.
  • the device identifier is a Unique Device Identification (UDI) or a Safe Unique Device Identification (SUDI).
  • UMI Unique Device Identification
  • SUVI Safe Unique Device Identification
  • the device identifier of the network device is a unique device identifier UDI of the network device
  • the S220 when the Registrar device determines that the network device is allowed to join the ad hoc network, assigns a domain certificate to the network device according to the device identifier included in the AD message, and sends the domain certificate to the network device, including:
  • the Registrar device determines whether the network device is allowed to join the self-organizing domain by using a white list, and the white list records the UDI of the device allowed to join the self-organizing domain, when the Registrar device
  • a match of the UDI of the network device is found in the whitelist, for example, through a digital certificate authentication management structure, a domain certificate is assigned to the network device based on the UDI of the network device; if the Registrar network device cannot find the whitelist A match of the UDI of the network device determines that the network device is not allowed to join the self-organizing domain.
  • the device identifier of the network device is a secure unique device identifier S-UDI of the network device
  • the S220 when the Registrar device determines that the network device is allowed to join the ad hoc network, assigns a domain certificate to the network device according to the device identifier included in the AD message, and sends the domain certificate to the network device, including:
  • the Registrar device determines that the device digital certificate corresponding to the S-UDI is valid by using the verification server, determine that the network device is allowed to join the ad hoc network, and send the domain certificate according to the device digital certificate to the network device.
  • the network device sends a device digital certificate corresponding to the SUDI to the Registrar device;
  • the Registrar device allocates a domain certificate to the network device according to the SUDI when verifying that the device digital certificate is valid and determining that the network device is allowed to join the self-organizing domain according to the verification result of the verification server.
  • the adjacency discovery AD message of the device is encapsulated based on a frame of the data link layer; the AD message is sent to a Registrar device that allocates a domain certificate in the ad hoc network based on the data link layer address; the Registrar device The device is assigned a domain certificate according to the AD message; based on the domain certificate, the device establishes a self-organizing control plane ACP with the Registrar device. Therefore, in this In the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce the self-organizing network. Deployment barriers.
  • control message may be control signaling for implementing control and/or management functions.
  • FIG. 4 is a schematic flowchart of a data link layer-based communication method 300 according to an embodiment of the present invention.
  • the communication method is applied to an ad hoc network, and the self-organizing control plane ACP of the ad hoc network is based on a data link layer.
  • the method 300 includes:
  • the first network device generates a data link layer self-organizing control plane L2 ACP packet, where the first network device is an ad hoc device in the ad hoc network;
  • the first network device receives a communication task from an upper-level ad hoc functional entity, for example, the communication task indicates to send a control message from the first network device to the target device in the ACP, or indicates that the first network device broadcasts in the ACP. Controlling the message, etc., the first network device generates the L2 ACP message according to the communication task.
  • the control message may be control signaling for implementing control and/or management functions.
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where the source data link
  • the layer address is a data link layer address of the first network device
  • the destination data link layer address of the frame of the data link layer is the data link layer address of the neighbor device of the first network device, or is the broadcast data link layer address.
  • the first network device sends, according to the destination data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device, where the second network device is also the self-organizing network The self-organizing device in the middle, and the second network device is a neighbor device of the first network device.
  • the L2 ACP packet is encapsulated according to the data link layer frame, and the L2 based on the frame of the data link layer is sent to the second network device according to the destination data link layer address.
  • the packet transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the network device may not need to maintain the routing table as in the prior art.
  • the self-organizing control plane ACP in the embodiment of the present invention is established based on the data link layer, and the specific establishment process is described in detail in the description of the method 100 and the method 200 above, and details are not described herein again.
  • the L2 ACP packet is based on the frame encapsulation of the L2, and is no longer based on the IP packet encapsulation of the network layer.
  • the forwarding table resource (for example, the MAC forwarding table) on the data link layer can be used to implement the transmission of the L2 ACP packet without relying on the network layer IP protocol or the IP routing table. .
  • the MAC forwarding table resource of the L2 may be a neighbor list that each device has, for example, the device identifier and the MAC address of the neighbor device including the device A in the neighbor list of the device A. Therefore, when the device A needs to send the L2 ACP packet, the destination MAC address of the L2 ACP packet is determined based on the MAC address of the neighbor device (one or more) included in the neighbor list, so that the L2 ACP packet is received. Send to the corresponding neighbor device. Alternatively, the destination MAC address of the L2 ACP packet is set to the MAC broadcast address, and then the MAC packet is sent out through the interface between the device A and the neighbor device. It should be understood that the MAC broadcast address and any MAC address are considered to be matched, so the neighbor device of device A can receive the L2 ACP message.
  • signaling is transmitted on the ACP, and does not need to be implemented according to the IP protocol or the IP routing table in the prior art, and may not be aware of the IP protocol or the IP address, compared to the existing one.
  • Technology with good network compatibility is provided.
  • the data link layer address is a Media Access Control (“MAC”) address.
  • MAC Media Access Control
  • the data link layer address is taken as an example of a MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol, and the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the L2 ACP message.
  • the Type value of the Type field of the frame of the data link layer has a Type value of 0x88e7.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • Table 5 schematically shows the format of an L2 ACP message according to an embodiment of the present invention:
  • the L2 ACP message includes the packet header and the packet content.
  • the content of the message of the L2 ACP packet includes the control message indicated in the communication task delivered by the upper-layer self-organizing function entity.
  • the control message may be control signaling for implementing control and/or management functions.
  • the packet header of the L2 ACP packet can be as shown in Table 6:
  • the packet header of the L2 ACP packet includes a version field, a flag bit field, a protocol field, and a packet length field, and a source UDI and a destination UDI, where the source UDI is the UDI of the first network device, and the destination UDI is UDI of the target device or broadcast UDI. It should be understood that when the L2 ACP message is a broadcast message, the destination UDI in the L2 ACP message may be empty.
  • the value of the version field indicates the version of the protocol corresponding to the L2 ACP message, for example, the version field has a total of 4 bits; the flag bit field is 4 bits, and is used to indicate that the L2 ACP message is a neighbor unicast message or a non-neighbor list. Broadcast message or broadcast message, for example, the value of the flag bit field is 0001; the value of the protocol field is used to indicate the protocol of the content carried in the data payload field of the frame of the data link layer, and the protocol field has a total of 8 bits, for example, can be used.
  • the value of the protocol field corresponding to the IP protocol; the packet length field refers to a total of 16 bits, and its value is used to indicate the length of the entire data packet.
  • the frame header of the frame of the data link layer includes a destination MAC address, a source MAC address, and a Type Type field, where the destination MAC address can be a MAC broadcast address or is The MAC address of the target device; the source MAC address is the MAC address of the first network device.
  • the Type value of the type Type field indicates that the data payload field of the frame of the data link layer carries the data link layer self-organizing control plane L2 ACP message. Specifically, the Type field can be applied with a value of 0x88e7.
  • the device on the data link layer receives the encapsulated L2 ACP message based on the data link layer, and the Type value can identify that the L2 ACP message is a message for transmission in the ACP.
  • the device at the data link layer can identify the L2 ACP packet, that is, the L2 ACP packet can be effectively transmitted and effectively received at the data link layer. For example, after receiving the L2 ACP packet of the data link layer based on the frame of the data link layer, the device 2 decodes the frame based on the data link layer to obtain the L2 ACP packet, and further processes the L2 ACP packet, for example, The control message in the L2 ACP message is parsed, or the forwarding is not processed. Specifically, the control message may be control signaling for implementing control and/or management functions.
  • the S310, the first network device generates a data link layer self-organizing control plane L2 ACP message, including:
  • the L2 ACP packet is generated.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, and the neighbor list of the first network device includes the neighbor of the first network device.
  • the communication task received by the first network device from the upper-layer self-organizing function entity, the communication task instructing the first network device to send a control message to the target device in the ACP, specifically, the control message may be implemented to implement control And/or control signaling for management functions.
  • the first network device may obtain the device identifier and the MAC address of the target device from the upper layer self-organizing function entity.
  • the matching of the device identifier of the target device in the neighbor list of the first network device refers to that the neighbor list of the first network device includes the same device identifier as the device identifier of the target device. It should also be understood that when the device identifier of the target device is the broadcast device identifier, the neighbor list of the first network device may also be considered as a matching item of the device identifier of the target device. If the neighbor list of the first network device does not include the same device identifier as the target device If the device identifier of the target device is not the broadcast device identifier, the neighbor list of the first network device is not included as a matching item of the device identifier of the target device.
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, including:
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, where a destination data link layer address of the frame of the data link layer is a data link layer address of the target device;
  • the first network device sends, according to the destination data link layer address, the L2 ACP packet that is encapsulated by the data link layer to the second network device, where:
  • the first network device sends, according to the data link layer address of the target device, the L2 ACP packet encapsulated by the frame of the data link layer to the target device.
  • the first network device determines that the neighboring list includes the matching item of the UDI of the target device, and determines that the destination device of the L2 ACP packet is the neighboring device, and generates the L2 ACP packet, where the L2 ACP packet is generated.
  • the header of the text includes a flag bit field for indicating neighbor unicast.
  • the transmission task delivered by the upper layer self-organizing network function entity transmits the target signaling from the device 5 to the device 2 (the neighbor device of the device 5), and the transmission task carries UDI of device 5.
  • the device 5 determines an L2 ACP packet according to the transmission task 1, the L2 ACP packet includes the target signaling and the destination UDI, the destination UDI is the UDI of the device 2, and the L2 ACP packet is encapsulated based on the frame of the data link layer.
  • the destination MAC address of the frame of the data link layer is the MAC address of the device 2, and the flag bit field in the packet header of the L2 ACP packet is used to indicate neighbor unicast.
  • the format of the L2 ACP packet is as shown in Table 5; the header of the L2 ACP packet is as shown in Table 6, wherein the destination UDI is the UDI of the target device, where the flag bit field
  • the value of the L2 ACP packet is used to indicate that the L2 ACP packet is a neighbor unicast packet, that is, the receiving device that indicates the L2 ACP packet does not forward the L2 ACP packet encapsulated by the data link layer to other devices.
  • the value of the flag bit field is, for example, 0001.
  • the format of the L2 ACP packet after the frame encapsulation based on the data link layer is as shown in Table 7, wherein the destination MAC address is the MAC address of the target device.
  • the L2 ACP message when the target device is determined to be the neighbor device of the first network device, the L2 ACP message is generated, and the L2 ACP message includes a flag bit for indicating that the L2 ACP message is a neighbor unicast message. Then, the L2 ACP message is encapsulated based on the frame of the data link layer, and the L2 ACP message encapsulated by the frame of the data link layer is sent to the second network device according to the destination data link layer address.
  • the message transmitted on the ACP may not depend on the IP association. It has better network compatibility than the prior art.
  • the solution provided by the embodiment of the present invention can also be applied to a network in which some devices are configured as IPv6 and some devices are configured as IPv4.
  • the network device can implement the transmission of the L2 ACP packet without maintaining the routing table.
  • the S310, the first network device generates a data link layer self-organizing control plane L2 ACP message, including:
  • S312 When the first network device needs to communicate with the target device in the ad hoc network, when determining that the neighbor list does not include the matching of the device identifier of the target device, generating the L2 ACP packet, the L2 ACP report The header of the packet includes a flag bit field, and the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast message;
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, including:
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, where a destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the first network device sends, according to the destination data link layer address, the L2 ACP packet that is encapsulated by the data link layer to the second network device, where:
  • the first network device sends, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the format of the L2 ACP packet is as shown in Table 5; the header of the L2 ACP packet is as shown in Table 6, wherein the destination UDI is the UDI of the target device, and the value of the flag bit field is used to indicate the L2.
  • the ACP packet is a non-neighbor unicast packet, which is used to indicate that when the device identifier of the receiving device of the L2 ACP packet does not match the destination device identifier, the device continues to forward the data link layer to the neighboring device of the receiving device.
  • the L2 ACP packet is encapsulated by the frame. When the device identifier of the receiving device of the L2 ACP packet matches the target device identifier, the L2 ACP packet is parsed and is not forwarded.
  • This flag bit field is, for example, 0002.
  • the format of the L2 ACP message after the frame encapsulation based on the data link layer is as shown in Table 7, wherein the destination MAC address of the frame of the data link layer is the MAC broadcast address.
  • the transmission task delivered by the upper layer network function entity is to transmit signaling from the device 7 to the device 2 (not the neighbor device of the device 7). Then device 7 transmits to neighbor devices 5 and 6, respectively.
  • L2 ACP message after frame encapsulation based on data link layer is as shown in Table 7, wherein the packet content includes the signaling content to be actually transmitted, the source UDI is the UDI of the device 7, and the destination UDI is the UDI of the device 2.
  • Flag It is an identifier used to indicate that the message is a non-neighbor unicast message.
  • the device 5 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and forwards the L2 ACP message to itself.
  • the neighboring device 2 similarly, after receiving the L2 ACP message sent by the device 7, the device 6 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and then the L2 ACP is obtained.
  • the packet is forwarded to its neighbor devices 2 and 8.
  • the device 2 determines that the packet is a non-neighbor unicast message and then detects that the destination UDI matches its UDI.
  • the content of the L2 ACP message is forwarded to its neighbor devices 2 and 8.
  • the method for transmitting signaling between the devices may also be referred to as being sent by flooding.
  • the L2 ACP packet when it is determined that the target device is not the neighbor device of the first network device, the L2 ACP packet is generated, and the L2 ACP packet includes a flag indicating that the L2 ACP packet is a non-neighbor unicast packet. And then, according to the frame of the data link layer, the L2 ACP message is encapsulated, and the L2 ACP message encapsulated by the frame of the data link layer is sent to the second network device according to the destination data link layer address.
  • the message transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the solution provided by the embodiment of the present invention can also be applied to a network in which some devices are configured as IPv6 and some devices are configured as IPv4.
  • the network device can implement the transmission of the L2 ACP packet without maintaining the routing table.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely indicating the L2 ACP packet.
  • the packet header of the L2 ACP packet is as shown in Table 8:
  • the message ID is a unique character string on the generating device of the L2 ACP message.
  • the message ID is used by the receiving device to detect whether it has received the same message. Specifically, for example In the example, after receiving the L2 ACP message sent by the device 7, the device 6 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and then forwards the L2 ACP message to the L2 ACP message. If the neighboring devices 2 and 8 are in the same state, the device 2 will repeatedly receive the L2 ACP packet originating from the device 7 from the neighboring devices 5 and 6. The L2 ACP packet includes the packet ID to prevent the device 2 from repeatedly processing the same.
  • the L2 ACP message for example, when the device 2 first receives the L2 ACP message sent by the neighbor device 5, the device 2 caches the L2 ACP message after parsing the L2 ACP message, and naturally saves the L2 ACP message. Message ID.
  • the device 2 receives the L2 ACP packet from the device 7 and sends the L2 ACP packet, the device can discard the L2 ACP packet after detecting that the L2 ACP packet has been received. .
  • the L2 ACP message includes a message ID, which can avoid repeated signaling forwarding.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet caches the L2 ACP packet for a longer period of time than When the duration is set, the L2 ACP message is cleared.
  • the packet header of the L2 ACP packet is as shown in Table 8, and has a field of timing information, where the value is used to indicate a preset time, and is used to indicate that the receiving device of the L2 ACP packet is buffering the L2ACP packet.
  • the time of the text exceeds the preset duration, the L2 ACP message is cleared.
  • the timing information is, for example, a timer.
  • the specific time value may be pre-configured according to service requirements or specific conditions.
  • the device 5 receives the L2 ACP packet from the device 7 and caches the L2 ACP packet. After the threshold is exceeded, the L2 ACP packet can be transmitted to the device corresponding to the destination UDI. That is, the L2 ACP packet is deleted, and the L2 ACP packet can be deleted.
  • the timing information may also be a timestamp.
  • the L2 ACP packet includes the timing information, so that the device can clear the L2 ACP packet that has been transmitted in time, and the device can prevent the L2 ACP packet from being cached for a long time.
  • the S310, the first network device generates an L2 ACP packet, including:
  • the first network device needs to broadcast a control message in the ACP, generate the L2 ACP packet, where the header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field is used by Instructing the L2 ACP message to be a broadcast message;
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, including:
  • the first network device encapsulates the L2 ACP packet according to a frame of a data link layer, where a destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the S330 the first network device, according to the destination data link layer address, sends the L2 ACP packet based on the frame of the data link layer to the second network device, including:
  • the first network device sends, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the format of the L2 ACP packet is as shown in Table 5.
  • the header of the L2 ACP packet is shown in Table 6.
  • the value of the flag bit field is used to indicate that the L2 ACP packet is a broadcast packet.
  • the value is for example 0003.
  • a communication task received by the first network device from an upper self-organizing function entity, the communication task instructing the first network device to broadcast a control message in the ACP, specifically, the control message may be implemented to implement control and/or Control signaling for management functions.
  • the task delivered by the upper layer network function entity is to broadcast the L2 ACP message from the device 6.
  • the L2 ACP message generated by the device 6 is as shown in Table 5 and Table 6.
  • the value of the flag bit field of the packet header of the L2 ACP message is used to indicate the broadcast message; the L2 ACP is encapsulated based on the frame of the data link layer.
  • the message wherein the destination MAC address of the frame of the data link layer is a MAC broadcast address.
  • the neighboring device of the device 6 receives the L2 ACP packet, and determines that the L2 ACP packet is a broadcast packet and continues to forward to its neighbor devices 2, 7, and 8 and 7, similarly, devices 2, 7, and 8 Continue to forward the L2 ACP packet to its neighbor device.
  • the destination UDI in the message header may be a broadcast UDI, or the destination UDI is empty.
  • an L2 ACP message when a broadcast control message is required, an L2 ACP message is generated, and the L2 ACP message includes a flag bit for indicating that the L2 ACP message is a broadcast message, and then is based on a data link layer.
  • the frame encapsulates the L2 ACP packet, and sends the L2 ACP packet based on the frame of the data link layer to the second network device according to the destination data link layer address.
  • the message transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the solution provided by the embodiment of the present invention can also be applied to some devices. Configured as IPv6, some devices are configured as IPv4 networks.
  • the network device can implement the transmission of the L2 ACP packet without maintaining the routing table.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely indicating the L2 ACP packet.
  • the packet header of the L2 ACP packet is as shown in Table 8.
  • the message ID is a unique character string on the generating device of the L2 ACP message.
  • the message ID is used by the receiving device to detect whether it has received the same message. Specifically, for example, in the above example, after receiving the L2 ACP message sent by the device 7, the device 6 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and then reports the L2 ACP. If the packets are forwarded to the neighboring devices 2 and 8, the device 2 will repeatedly receive the L2 ACP packets from the neighboring devices 5 and 6. The L2 ACP packets include the packet ID to avoid the device 2. The same L2 ACP message is processed repeatedly.
  • the device 2 when the device 2 first receives the L2 ACP message sent by the neighbor device 5, the device 2 caches the L2 ACP message after parsing the L2 ACP message, and naturally saves the L2 message. ID of the packet of the ACP packet.
  • the device 2 receives the L2 ACP packet from the device 7 and sends the L2 ACP packet, the device can discard the L2 ACP packet after detecting that the L2 ACP packet has been received. .
  • the L2 ACP message includes a message ID, which can avoid repeated signaling forwarding.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet caches the L2 ACP packet for a longer period of time than When the duration is set, the L2 ACP message is cleared.
  • the packet header of the L2 ACP packet is as shown in Table 8, and has a field of timing information, where the value is used to indicate a preset time, and is used to indicate that the receiving device of the L2 ACP packet is buffering the L2 ACP. When the time of the packet exceeds the preset duration, the L2 ACP packet is cleared.
  • the timing information is, for example, a timer.
  • the specific time value may be pre-configured according to service requirements or specific conditions.
  • the device 5 receives the L2 ACP packet from the device 7 and caches the L2 ACP packet. After the threshold is exceeded, the L2 ACP packet can be transmitted to the device corresponding to the destination UDI. That is, the L2 ACP packet is deleted, and the L2 ACP packet can be deleted.
  • the timing information may also be a timestamp.
  • the L2 ACP message includes timing information, and the device can be implemented in time. Clearing the transmitted L2 ACP packets can prevent the device from buffering unused L2 ACP packets for a long time.
  • the device at the data link layer can identify the L2 ACP packet, that is, the L2 ACP packet can be effectively transmitted and effectively received at the data link layer. For example, after receiving the frame-encapsulated L2 ACP message sent by the device 5, the device 2 decodes the frame based on the data link layer to obtain the L2 ACP message, and matches the L2 ACP message. After the UDI of the destination is successfully matched with the UDI of the device 2, the target signaling in the L2 ACP packet is parsed and obtained.
  • the packet format of the L2 ACP packet and the frame format of the frame of the data link layer encapsulating the L2 ACP packet are all known in the data link layer, that is, data. Devices at the link layer can recognize L2 ACP packets.
  • the L2 ACP packet is encapsulated based on the frame of the data link layer, and the L2 ACP after the frame encapsulation based on the data link layer is sent to the second network device according to the destination data link layer address.
  • the packet transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the L2 ACP message is transmitted between the network devices based on the device identifier of the target device (for example, UDI) and the neighbor list of the network device, instead of relying on the loopback address, thereby avoiding the network device. Need to maintain the routing table.
  • Each network device has its own UDI and neighbor list, which directly utilizes off-the-shelf resources to implement signaling transmission, which can reduce maintenance costs.
  • the ad hoc network in the embodiment of the present invention and the message transmission in the ad hoc network may not be aware of the IP protocol, and therefore the network device is not required to uniformly support IPv6 or IPv4, thereby having better performance than the prior art. Network compatibility, but also reduces the difficulty of self-organizing network deployment.
  • each network device in the ad hoc network has an IP address
  • each of the self-organizing devices has a device identifier of each of the self-organizing devices and each of the self-organizing devices Mapping between IP addresses
  • the S310 generates, by the first network device, a data link layer self-organizing control plane L2 ACP message, including:
  • the first network device needs to communicate with the target device in the ACP by using the IP session, generate the L2 ACP packet, where the L2 ACP packet further includes a destination IP address, where the destination IP address is the IP address of the target device. address.
  • the format of the L2 ACP packet is as shown in Table 5 and Table 6.
  • the value of the protocol field in the packet header of the L2 ACP packet may be the value of the protocol field in the IP packet.
  • RADIUS Remote Authentication Dial In User Service
  • each self-organizing device in the ACP supports a loopback self-configured loopback address; and each self-organizing device in the ACP supports mapping of UDI and IP (including own and pair). End device).
  • the related service device (such as AAA) needs to send its own server IP address and its own UDI to the client device, and this stage is Called service self-discovery, or service advertisement.
  • the client device After receiving the message sent by the service device, the client device binds the IP address, UDI, and related services, and initiates an IP session to the server through a self-configured IPv6 ULA loopback address or an IPv4 loopback address.
  • the UDI layer of the server After receiving the relevant packet, the UDI layer of the server binds the IP and UDI of the client device.
  • the server/client After the server/client encapsulates the IP packet, it searches the IP and UDI mapping table and forwards it based on UDI in the ACP plane.
  • the ACP plane still does not provide IP-based forwarding, and the network device does not need to maintain the related routing table.
  • the ACP provided by the embodiments of the present invention can provide IP-based communication capabilities, thereby providing better compatibility for upper-layer applications, and making them use L2 layer-based ACPs as little as possible.
  • the L2 ACP packet is encapsulated based on the frame of the data link layer, and the L2 ACP after the frame encapsulation based on the data link layer is sent to the second network device according to the destination data link layer address.
  • the packet transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the L2 ACP message is transmitted between the network devices based on the device identifier of the target device (for example, UDI) and the neighbor list of the network device, instead of relying on the loopback address, thereby avoiding the network device. Need to maintain the routing table. Every network device has Own UDI and neighbor lists directly use off-the-shelf resources to implement signaling transmission, which can reduce maintenance costs.
  • the target device for example, UDI
  • the ad hoc network in the embodiment of the present invention and the message transmission in the ad hoc network may not be aware of the IP protocol, and therefore the network device is not required to uniformly support IPv6 or IPv4, thereby having better performance than the prior art. Network compatibility, but also reduces the difficulty of self-organizing network deployment.
  • FIG. 5 is a schematic flowchart of a data link layer-based communication method 400 according to an embodiment of the present invention.
  • the self-organizing control plane ACP of the ad hoc network is established based on a data link layer, and each of the self-organizing networks
  • Each of the self-organizing devices has a neighbor list, the neighbor list including the device identifier and the data link layer address of the neighbor device of each self-organizing device, and the method 400 includes:
  • the second network device receives a frame-encapsulated L2 ACP packet sent by the first network device, where the L2 ACP packet includes a destination device identifier, where the data link layer frame includes a source data link. a layer address and a destination data link layer address, where the source data link layer address is a data link layer address of the first network device, the destination data link layer address and a data link layer of the second network device
  • the addresses are matched, and the second network device and the first network device are both self-organizing devices in the self-organizing network;
  • matching the data link layer address of the destination with the data link layer address of the second network device means that the destination data link layer address is directly the data link layer address of the second network device, or The destination data link layer address is a broadcast data link layer address. It should be understood that the broadcast data link layer address may match any fixed data link layer address.
  • the second network device processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet.
  • the destination device identifier when the destination device identifier is directly the device identifier of the second network device, or the destination device identifier is the broadcast device identifier, the destination device identifier may be considered to match the device identifier of the second network device. Otherwise it does not match.
  • the L2 ACP packet in the embodiment of the present invention is based on the frame of the data link layer, and can transmit the L2 ACP packet in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the implementation of the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • the network device may not need to maintain the routing table as in the prior art.
  • self-organizing control plane ACP in the embodiment of the present invention is based on data link layer construction. For details, see the description of Method 100 and Method 200 above, and details are not described here.
  • the L2 ACP packet is based on the frame encapsulation of the L2, and is no longer based on the IP packet encapsulation of the network layer.
  • the forwarding table resource (for example, the MAC forwarding table) on the data link layer can be used to implement the transmission of the L2 ACP packet without relying on the network layer IP protocol or the IP routing table. .
  • the MAC forwarding table resource of the L2 may be a neighbor list that each device has, for example, the device identifier and the MAC address of the neighbor device including the device A in the neighbor list of the device A. Therefore, when the device A needs to send the L2 ACP packet, the destination MAC address of the L2 ACP packet is determined based on the MAC address of the neighbor device (one or more) included in the neighbor list, so that the L2 ACP packet is received. Send to the corresponding neighbor device. Alternatively, the destination MAC address of the L2 ACP packet is set to the MAC broadcast address, and then the MAC packet is sent out through the interface between the device A and the neighbor device. It should be understood that the MAC broadcast address and any MAC address are considered to be matched, so the neighbor device of device A can receive the L2 ACP message.
  • signaling is transmitted on the ACP, and does not need to be implemented according to the IP protocol or the IP routing table in the prior art, and may not be aware of the IP protocol or the IP address, compared to the existing one.
  • Technology with good network compatibility is provided.
  • the data link layer address is a Media Access Control (“MAC”) address.
  • MAC Media Access Control
  • the data link layer address is taken as an example of a MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol, and the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the L2 ACP message.
  • the Type value of the Type field of the frame of the data link layer has a Type value of 0x88e7.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the L2 ACP packet is as shown in Table 5.
  • the packet header of the L2 ACP packet is as shown in Table 6.
  • the L2 ACP packet encapsulated by the data link layer is shown in Table 7. For details, see the related content above, and I will not repeat them here.
  • the device at the data link layer can identify the L2 ACP packet, that is, the L2 ACP packet can be effectively transmitted and effectively received at the data link layer. For example, after receiving the L2 ACP packet of the data link layer based on the frame of the data link layer, the device 2 decodes the frame based on the data link layer to obtain the L2 ACP packet, and further processes the L2 ACP packet, for example, The control message in the L2 ACP message is parsed. Specifically, the control message may be control signaling for implementing control and/or management functions, or may not be forwarded.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, where the data chain is The destination data link layer address of the path layer frame is the data link layer address of the target device;
  • the S420 processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the second network device determines that the destination device identifier is the device identifier of the second network device, and parses the L2 ACP packet.
  • the L2 ACP packet is parsed to obtain the content of the packet in the L2 ACP packet, for example, a control message, etc.
  • the control message may be control signaling for implementing control and/or management functions. It should be understood that, in the embodiment of the present invention, the receiving device of the L2 ACP packet no longer forwards the L2 ACP packet to its neighbor device.
  • the format of the L2 ACP packet is as shown in Table 5; the header of the L2 ACP packet is as shown in Table 6, wherein the destination UDI is the UDI of the target device, where the flag bit field
  • the value of the L2 ACP packet is used to indicate that the L2 ACP packet is a neighbor unicast packet, that is, the receiving device that indicates the L2 ACP packet does not forward the L2 ACP packet encapsulated by the data link layer to other devices.
  • the value of the flag bit field is, for example, 0001.
  • the format of the L2 ACP packet after the frame encapsulation based on the data link layer is as shown in Table 7, wherein the destination MAC address is the MAC address of the target device.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast packet, where the data is The destination data link layer address of the link layer frame is a broadcast data link layer address;
  • the S420 processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the L2 ACP packet is parsed to obtain the content of the packet in the L2 ACP packet, for example, a control message, etc.
  • the control message may be control signaling for implementing control and/or management functions.
  • the format of the L2 ACP packet is as shown in Table 5; the header of the L2 ACP packet is as shown in Table 6, wherein the destination UDI is the UDI of the target device, and the value of the flag bit field is used to indicate the L2.
  • the ACP packet is a non-neighbor unicast packet, which is used to indicate that when the device identifier of the receiving device of the L2 ACP packet does not match the destination device identifier, the device continues to forward the data link layer to the neighboring device of the receiving device.
  • the L2 ACP packet is encapsulated by the frame. When the device identifier of the receiving device of the L2 ACP packet matches the target device identifier, the L2 ACP packet is parsed and is not forwarded.
  • This flag bit field is, for example, 0002.
  • the format of the L2 ACP message after the frame encapsulation based on the data link layer is as shown in Table 7, wherein the destination MAC address of the frame of the data link layer is the MAC broadcast address.
  • the transmission task delivered by the upper layer network function entity is to transmit signaling from the device 7 to the device 2 (not the neighbor device of the device 7). Then device 7 transmits to neighbor devices 5 and 6, respectively.
  • L2 ACP message after frame encapsulation based on data link layer is as shown in Table 7, wherein the packet content includes the signaling content to be actually transmitted, the source UDI is the UDI of the device 7, and the destination UDI is the UDI of the device 2.
  • the flag bit is an identifier used to indicate that the message is a non-neighbor unicast message.
  • the device 5 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and forwards the L2 ACP message to itself.
  • the neighboring device 2 similarly, after receiving the L2 ACP message sent by the device 7, the device 6 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and then the L2 ACP is obtained.
  • the packet is forwarded to its neighbor devices 2 and 8.
  • the device 2 determines that the packet is a non-neighbor unicast message and then detects that the destination UDI matches its UDI.
  • the content of the L2 ACP message is forwarded to its neighbor devices 2 and 8.
  • the method for transmitting signaling between the devices may also be referred to as using flooding. give away.
  • the message transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the solution provided by the embodiment of the present invention can also be applied to a network in which some devices are configured as IPv6 and some devices are configured as IPv4.
  • the network device can implement the transmission of the L2 ACP packet without maintaining the routing table.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely identifying the L2 ACP packet.
  • the S420 processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the L2 ACP packet is processed by determining whether the device identifier of the second network device matches the destination device identifier.
  • the packet header of the L2 ACP packet is as shown in Table 8.
  • the message ID is a unique string on the source device.
  • the message ID is used by the receiving device to detect whether it has received the same message.
  • a device receives an L2 ACP packet, and determines that the packet ID of the L2 ACP packet is not cached locally, that is, when the L2 ACP packet is received for the first time, the packet content is parsed, and the packet is cached. And the L2 ACP packet is forwarded to the neighboring device. If the device receives the L2 ACP packet and determines that the packet ID of the L2 ACP packet is already buffered, the L2 ACP is not received for the first time. If the packet is received, the packet can be discarded.
  • the L2 ACP packet can be deleted. Specifically, for example, in the above example, after receiving the L2 ACP message sent by the device 7, the device 6 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and then the L2 ACP is obtained. If the packet is forwarded to its neighbors 2 and 8, the device 2 will repeatedly receive the L2 ACP packet from the neighboring device 5 and 6.
  • the L2 ACP packet includes the packet ID to avoid the device. 2, the same L2 ACP message is repeatedly processed.
  • the device 2 when the device 2 first receives the L2 ACP message sent by the neighbor device 5, the device 2 caches the L2 ACP message after parsing the L2 ACP message, and naturally saves the L2 ACP message. ID of the packet of the L2 ACP packet.
  • the device 2 receives the L2 ACP packet from the device 7 and sends the L2 ACP packet, the device can discard the L2 ACP packet after detecting that the L2 ACP packet has been received. .
  • whether the device identifier in the L2 ACP packet is verified is the same as the first Before the device identifier of the network device is matched, first, according to the packet ID, it is verified whether the second network device has received the L2 ACP packet (that is, whether the packet ID has been cached locally), and if it is determined that the packet ID has not been received before, If the L2 ACP packet is received, the subsequent device identification is determined. Otherwise, the L2 ACP packet may be discarded.
  • the L2 ACP message includes the message ID, which can avoid repeated signaling forwarding.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet exceeds the time for buffering the L2 ACP packet. Clear the L2 ACP message when the preset duration is long.
  • the method 400 also includes:
  • the second network device determines that the time for buffering the L2 ACP packet exceeds a preset duration indicated by the timing information, the L2 ACP packet is cleared.
  • the timing information is, for example, a timer, and the specific time value may be pre-configured according to service requirements or specific conditions. For example, after the device 5 receives the L2 ACP message originating from the device 7, the device starts timing and time according to the timestamp. After the threshold is exceeded, the L2 ACP packet can be transmitted to the device corresponding to the destination UDI. That is, the L2 ACP packet is deleted, and the L2 ACP packet can be deleted.
  • the timing information may also be specifically a timestamp.
  • the L2 ACP packet includes the timing information, so that the device can clear the L2 ACP packet that has been transmitted in time, and the device can prevent the L2 ACP packet from being cached for a long time.
  • the packet header of the L2 ACP packet further includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a broadcast packet, where the data chain is The destination data link layer address of the path layer frame is the broadcast data link layer address;
  • the S420 processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the second network device determines that the device identifier of the second network device matches the destination device identifier, parses the L2 ACP packet, and caches the L2 ACP packet, and according to the purpose of the data link layer frame.
  • the data link layer address forwards the L2 ACP message based on the frame encapsulation of the data link layer to the neighbor device of the second network device.
  • the format of the L2 ACP packet is as shown in Table 5.
  • the header of the L2 ACP packet is shown in Table 6.
  • the value of the flag bit field is used to indicate that the L2 ACP packet is a broadcast packet.
  • Receiving, by the receiving device indicating the L2 ACP packet, the L2 ACP packet, and sending the neighbor to the receiving device The device forwards the L2 ACP message based on the frame encapsulation of the data link layer.
  • the value of the flag bit field is, for example, 0003.
  • the L2 ACP message is a broadcast message
  • the destination device identifier in the L2 ACP message may be a broadcast device identifier
  • the L2 ACP is received by any network device in the self-organizing network. The message will determine that its device ID matches the destination device ID.
  • the L2 ACP message when the L2 ACP message is a broadcast message, the L2 ACP message may not include the destination device identifier, and the network device determines that the L2 ACP message is based on the flag of the L2 ACP message. If the broadcast packet is broadcast, the L2 ACP packet is parsed and forwarded. It is not necessary to determine whether the device identifier matches.
  • the task delivered by the upper layer network function entity is to broadcast the L2 ACP message from the device 6.
  • the L2 ACP message generated by the device 6 is as shown in Table 5 and Table 6.
  • the value of the flag bit field of the packet header of the L2 ACP message is used to indicate the broadcast message; the L2 ACP is encapsulated based on the frame of the data link layer.
  • the message, wherein the destination MAC address of the frame of the data link layer is a MAC broadcast address.
  • the neighboring device of the device 6 receives the L2 ACP packet, and determines that the L2 ACP packet is a broadcast packet and continues to forward to its neighbor devices 2, 7, and 8 and 7, similarly, devices 2, 7, and 8 Continue to forward the L2 ACP packet to its neighbor device.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely identifying the L2 ACP packet.
  • the S420 processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the L2 ACP packet is processed by determining whether the device identifier of the second network device matches the destination device identifier.
  • the packet header of the L2 ACP packet is as shown in Table 8.
  • the message ID is a unique string on the source device.
  • the message ID is used by the receiving device to detect whether it has received the same message.
  • a device receives an L2 ACP packet, and determines that the packet ID of the L2 ACP packet is not cached locally, that is, when the L2 ACP packet is received for the first time, the packet content is parsed, and the packet is cached. And the L2 ACP packet is forwarded to the neighboring device. If the device receives the L2 ACP packet and determines that the packet ID of the L2 ACP packet is already buffered, the L2 ACP is not received for the first time. If the packet is received, the packet can be discarded.
  • the L2 ACP message can be deleted. Specifically, for example, in the above example, after receiving the L2 ACP message sent by the device 7, the device 6 parses the L2 ACP message as a non-neighbor unicast message, and detects that the destination UDI does not match its own UDI, and then the L2 ACP is obtained. If the packet is forwarded to its neighbors 2 and 8, the device 2 will repeatedly receive the L2 ACP packet from the neighboring device 5 and 6.
  • the L2 ACP packet includes the packet ID to avoid the device. 2, the same L2 ACP message is repeatedly processed.
  • the device 2 when the device 2 first receives the L2 ACP message sent by the neighbor device 5, the device 2 caches the L2 ACP message after parsing the L2 ACP message, and naturally saves the L2 ACP message. ID of the packet of the L2 ACP packet.
  • the device 2 receives the L2 ACP packet from the device 7 and sends the L2 ACP packet, the device can discard the L2 ACP packet after detecting that the L2 ACP packet has been received. .
  • the second network device verifies whether the device identifier in the L2 ACP packet matches the device identifier of the second network device, first verifying, according to the packet ID, whether the second network device is The L2 ACP packet has been received (that is, whether the packet ID has been cached in the local area). If it is determined that the L2 ACP packet has not been received before, the device identification is performed. Otherwise, the L2 ACP can be discarded. Message.
  • the L2 ACP message includes the message ID, which can avoid repeated signaling forwarding.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet exceeds the time for buffering the L2 ACP packet. Clear the L2 ACP message when the preset duration is long.
  • the method 400 also includes:
  • the second network device determines that the time for buffering the L2 ACP packet exceeds a preset duration indicated by the timing information, the L2 ACP packet is cleared.
  • the packet header of the L2 ACP packet is as shown in Table 8:
  • the timing information is, for example, a timer, and the specific time value may be pre-configured according to service requirements or specific conditions. For example, after the device 5 receives the L2 ACP message originating from the device 7, the device starts timing and time according to the timestamp. After the threshold is exceeded, the L2 ACP packet can be transmitted to the device corresponding to the destination UDI. That is, the L2 ACP packet is deleted, and the L2 ACP packet can be deleted.
  • the timing information may also be specifically a timestamp.
  • the L2 ACP packet includes the timing information, so that the device can clear the L2 ACP packet that has been transmitted in time, and the device can prevent the L2 ACP packet from being cached for a long time.
  • the L2 ACP packet is encapsulated based on the frame of the data link layer, and the L2 ACP after the frame encapsulation based on the data link layer is sent to the second network device according to the destination data link layer address.
  • the packet transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the L2 ACP message is transmitted between the network devices based on the device identifier of the target device (for example, UDI) and the neighbor list of the network device, instead of relying on the loopback address, thereby avoiding the network device. Need to maintain the routing table.
  • Each network device has its own UDI and neighbor list, which directly utilizes off-the-shelf resources to implement signaling transmission, which can reduce maintenance costs.
  • the ad hoc network in the embodiment of the present invention and the message transmission in the ad hoc network may not be aware of the IP protocol, and therefore the network device is not required to uniformly support IPv6 or IPv4, thereby having better performance than the prior art. Network compatibility, but also reduces the difficulty of self-organizing network deployment.
  • each network device in the ad hoc network has an IP address
  • each of the self-organizing devices has a device identifier of each of the self-organizing devices and each of the self-organizing devices Mapping between IP addresses
  • the L2 ACP message further includes a destination IP address
  • the S420 processes the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, including:
  • the second network device determines that the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, and the IP address of the second network device and the destination IP address of the L2 ACP packet
  • the L2 ACP packet is parsed when the addresses match.
  • the format of the L2 ACP packet is as shown in Table 5 and Table 6.
  • the value of the protocol field in the packet header of the L2 ACP packet may be the value of the protocol field in the IP packet.
  • RADIUS Remote Authentication Dial In User Service
  • each self-organizing device in the ACP supports a loopback self-configured loopback address; and each self-organizing device in the ACP supports mapping of UDI and IP (package) Including your own and the peer device).
  • the related service device (such as AAA) needs to send its own server IP address and its own UDI to the client device, and this stage is Called service self-discovery, or service advertisement.
  • the client device After receiving the message sent by the service device, the client device binds the IP address, UDI, and related services, and initiates an IP session to the server through a self-configured IPv6 ULA loopback address or an IPv4 loopback address.
  • the UDI layer of the server After receiving the relevant packet, the UDI layer of the server binds the IP and UDI of the client device.
  • the server/client After the server/client encapsulates the IP packet, it searches the IP and UDI mapping table and forwards it based on UDI in the ACP plane.
  • the ACP plane still does not provide IP-based forwarding, and the network device does not need to maintain the related routing table.
  • the ACP provided by the embodiments of the present invention can provide IP-based communication capabilities, thereby providing better compatibility for upper-layer applications, and making them use L2 layer-based ACPs as little as possible.
  • the packet format of the L2 ACP packet in the embodiment of the present invention is well known in the data link layer, that is, the device at the data link layer can recognize the L2 ACP packet.
  • the UDI and the neighbor list of the device are used to transmit signaling in the ACP instead of relying on the loopback address, thereby avoiding that each device needs to maintain a routing table, and each device has its own UDI and neighbors.
  • the list directly utilizes off-the-shelf resources to implement signaling transmission, which can reduce maintenance costs.
  • the ACP in the embodiment of the present invention may not be aware of the IP protocol, and does not require the network device to uniformly support the IPv6 or the IPv4, so that the unified ACP can be established, thereby having better network compatibility than the prior art. It also reduces the difficulty of deploying self-organizing networks.
  • the signaling is transmitted based on the UDI of the device, which avoids the problem that the device needs to additionally maintain the routing table in the prior art, and the deployment cost can be saved.
  • signaling is transmitted on the ACP, and the IP protocol may not be perceived. For example, even if the entire network does not support IPv6, signaling can be transmitted on the ACP, which is better than the prior art. Network compatibility can also reduce the difficulty of network deployment.
  • the present invention The solution provided by the example can also be applied to a network where some devices are configured as IPv6 and some devices are configured as IPv4.
  • the AD message (referred to as message 1) involved in the method 100 and the method 200 and the L2 ACP message (referred to as the message 2) involved in the method 300 and the method 400 may be based on
  • the frame format encapsulation of the same data link layer for example, the value of the data link layer of the encapsulated message 1 and the type of the data type of the data link layer of the encapsulated message 2 may take the same value. It should be understood that the value of the type of the data link layer of the encapsulated message 1 and the type of the data type of the data link layer of the encapsulated message 2 may also adopt different values.
  • the different assignments of the flag bits in the message header are used to distinguish between the message 1 and the message 2.
  • the frame type of the packet 1 and the packet 2 are both 88e7, but the flag in the header of the packet 1 is 0000, which is used to indicate that the frame bearer of the data link layer is adjacency-discovered AD message, and message 2
  • the flag in the header of the packet is 0001, which is used to indicate that the frame of the data link layer carries an ACP packet (that is, a packet that transmits signaling on the ACP).
  • the packet is divided into a neighbor unicast packet, a non-neighbor unicast packet, and a broadcast packet, and different transmission values can be determined by assigning different values to the flag bits of the three different transmission types.
  • Type 2 of the packet for example, when the flag bit in the packet header of the packet 2 is 0001, indicating that the frame of the data link layer carries the neighbor unicast packet, and the flag bit in the packet header of the packet 2 0002, indicating that the frame of the data link layer is a non-neighbor unicast packet, and the flag bit in the packet header of the packet 2 is 0003, indicating that the frame of the data link layer carries the broadcast packet.
  • the frame type Type can be used to distinguish between the message type 1 and the message type 2, for example, the frame type Type of the data link layer of the encapsulated message 1 is assigned.
  • the frame type of the data link layer of the encapsulated message 2 is assigned a value of 88e8.
  • the frame type Type assignment of the two types of the packet type 2 may be different, thereby distinguishing different transmission types.
  • the frame type of the data link layer of the encapsulated neighbor unicast packet is set to 88e8, and the frame type of the data link layer of the non-neighbor unicast packet is set to 88e9, and the data of the broadcast packet is encapsulated.
  • the frame type of the link layer is assigned a value of 88e6. It should be understood that the frame type of the message type 2 of the three transmission types adopts the same assignment, and the flag bit is used to distinguish the message type 2 of the three transmission types, which is not limited by the embodiment of the present invention.
  • FIG. 6 shows a network device 500 according to an embodiment of the present invention.
  • the network device is applied to an ad hoc network, and the network device 500 includes:
  • a generating module 510 configured to generate, by the network device, a neighbor discovery AD message, where the AD message includes a device identifier of the network device;
  • the encapsulating module 520 is configured to encapsulate the AD message generated by the generating module according to a frame of the data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where the source data link
  • the layer address is the data link layer address of the network device
  • the destination data link layer address of the frame of the data link layer may be a broadcast data link layer address or a data link layer address of a neighbor device of the network device.
  • the sending module 530 is configured to send, according to the destination data link layer address, the AD message that is encapsulated by the data link layer determined by the encapsulating module to the registration Registrar device, where the Registrar device supports allocation in the ad hoc network.
  • the receiving module 540 is configured to receive a domain certificate sent by the Registrar device, where the domain certificate is allocated by the Registrar device according to the device identifier of the network device in the AD message;
  • the establishing module 550 is configured to establish an ad hoc control plane ACP with the Registrar device according to the domain certificate received by the receiving module.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, and establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates that the L2 ACP packet is the AD message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the network device 500 may correspond to the network device in the data link layer-based communication method of the embodiment of the present invention, and the above and other operations and/or functions of the respective modules in the network device 500 In order to implement the corresponding processes of the respective methods in FIG. 1 to FIG. 5, for brevity, details are not described herein again.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, and establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • FIG. 7 shows a registration Registrar device 600, which is applied to a self-organizing network, and the Registrar device 600 supports a device that allocates a domain certificate in the self-organizing network, and the Registrar device 600 includes :
  • the receiving module 610 is configured to receive a data link layer-based frame-decapsulated adjacency discovery AD message from the network device, where the AD message includes a device identifier of the network device, where the data link layer frame includes a source data link layer An address and destination data link layer address, where the source data link layer address is a data link layer address of the network device, and the destination data link layer address matches a data link layer address of the Registrar device;
  • matching the data link layer address of the destination with the data link layer address of the Registrar device means that the destination data link layer address is the data link layer address of the Registrar device, or the destination data link.
  • the layer address is the broadcast data link layer address. It should be understood that the broadcast data link layer address can be considered to match any fixed data link layer address.
  • the sending module 620 is configured to: when determining that the network device is allowed to join the ad hoc network, assign a domain certificate to the network device according to the device identifier included in the AD message received by the receiving module, and send the domain certificate to the network device. ;
  • the ACP establishing module 630 is configured to establish an ad hoc control plane ACP with the network device according to the domain certificate sent by the sending module.
  • the adjacency discovery AD message of the device is a frame seal based on the data link layer.
  • the AD message is sent to a Registrar device that allocates a domain certificate in the ad hoc network based on the data link layer address; the Registrar device allocates a domain certificate to the device according to the AD message; based on the domain certificate, the device and the Registrar device Establish a self-organizing control plane ACP. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates that the L2 ACP packet is the AD message.
  • the network device is a neighbor device of the Registrar device, and the Registrar device further includes:
  • the neighbor list establishing module 640 is configured to establish, according to the AD message, a neighbor list of the Registrar device, where the neighbor list includes a device identifier of the network device and a data link layer address of the network device.
  • the device identifier of the network device is a unique device identifier UDI of the network device
  • the sending module 620 is specifically configured to: when determining that the whitelist has a matching item of the UDI of the network device, determine that the network device is allowed to join the ad hoc network, and send the domain certificate according to the UDI to the network device,
  • the whitelist includes UDIs that allow devices that join the ad hoc network.
  • the device identifier of the network device is a secure unique device identifier S-UDI of the network device
  • the sending module 620 is specifically configured to: when it is determined by the verification server that the device digital certificate corresponding to the S-UDI is valid, determine that the network device is allowed to join the ad hoc network, and send the network device according to the device digital certificate.
  • the domain certificate is specifically configured to: when it is determined by the verification server that the device digital certificate corresponding to the S-UDI is valid, determine that the network device is allowed to join the ad hoc network, and send the network device according to the device digital certificate.
  • the domain certificate is specifically configured to: when it is determined by the verification server that the device digital certificate corresponding to the S-UDI is valid, determine that the network device is allowed to join the ad hoc network.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the Registrar device 600 may correspond to the Registrar device in the data link layer based communication method of the embodiment of the present invention, and the above and other operations and/or functions of the respective modules in the Registrar device 600.
  • the Registrar device 600 may correspond to the Registrar device in the data link layer based communication method of the embodiment of the present invention, and the above and other operations and/or functions of the respective modules in the Registrar device 600.
  • FIG. 1 to FIG. 5 details are not described herein again.
  • the adjacency discovery AD message of the device is encapsulated based on a frame of the data link layer; the AD message is sent to a Registrar device that allocates a domain certificate in the ad hoc network based on the data link layer address; the Registrar device The device is assigned a domain certificate according to the AD message; based on the domain certificate, the device establishes a self-organizing control plane ACP with the Registrar device.
  • the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • FIG. 8 shows a network device 700 according to an embodiment of the present invention.
  • the network device is used as a first network device, and the first network device is applied to an ad hoc network.
  • the network device 700 includes:
  • the generating module 710 is configured to generate a data link layer self-organizing control plane L2 ACP packet, where the first network device is a self-organizing device in the ad hoc network;
  • the encapsulating module 720 is configured to encapsulate the L2 ACP packet generated by the generating module according to a frame of the data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where The source data link layer address is a data link layer address of the first network device;
  • the destination data link layer address of the frame of the data link layer is the data link layer address of the neighbor device of the first network device, or is the broadcast data link layer address.
  • the sending module 730 is configured to send, according to the destination data link layer address, the L2 ACP packet that is encapsulated by the data link layer determined by the encapsulating module to the second network device, where the second network device is also The self-organizing device in the self-organizing network, and the second network device is a neighbor device of the first network device.
  • the L2 ACP packet is encapsulated according to the data link layer frame, and the L2 based on the frame of the data link layer is sent to the second network device according to the destination data link layer address.
  • the packet transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the network device may not need to maintain the routing table as in the prior art.
  • the frame of the data link layer is in accordance with an Ethernet protocol definition.
  • the value of the Type field of the frame of the data link layer indicates that the data payload field of the frame of the data link layer carries the L2 ACP message.
  • the generating module 710 is specifically configured to: when it is required to communicate with the target device in the ad hoc network, determine that the device identifier of the target device is included in the neighbor list of the first network device.
  • the L2 ACP message is generated, and the L2 ACP message header includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP message is a neighbor unicast message, the first network
  • the neighbor list of the device includes the device identifier and the data link layer address of the neighbor device of the first network device;
  • the matching of the device identifier of the target device in the neighbor list of the first network device refers to that the neighbor list of the first network device includes the same device identifier as the device identifier of the target device. It should also be understood that when the device identifier of the target device is the broadcast device identifier, the neighbor list of the first network device may also be considered as a matching item of the device identifier of the target device. If the neighbor list of the first network device does not include the same device identifier as the target device, and the device identifier of the target device is not the broadcast device identifier, the neighbor list of the first network device is considered not to include the A match for the device ID of the target device.
  • the encapsulating module 720 is specifically configured to encapsulate the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a data link layer address of the target device;
  • the sending module 730 is specifically configured to send, according to the data link layer address of the target device, the L2 ACP packet encapsulated by the frame of the data link layer to the target device.
  • the generating module 710 is specifically configured to: when it is required to communicate with the target device in the ad hoc network, when determining that the neighbor list does not include the matching of the device identifier of the target device, And generating the L2 ACP packet, where the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast packet;
  • the encapsulating module 720 is specifically configured to encapsulate the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the sending module 730 is specifically configured to send, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the generating module 710 is specifically configured to: when the control message is broadcasted in the ACP, generate the L2 ACP packet, where the header of the L2 ACP packet includes a flag bit field. The value of the flag bit field is used to indicate that the L2 ACP message is a broadcast message;
  • control message may be control signaling that implements control and/or management functions.
  • the encapsulating module 720 is specifically configured to encapsulate the L2 ACP packet according to a frame of the data link layer, where the destination data link layer address of the frame of the data link layer is a broadcast data link layer address;
  • the sending module 730 is specifically configured to send, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely indicating the L2 ACP packet.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet caches the L2 ACP packet for a longer period of time than When the duration is set, the L2 ACP message is cleared.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • each self-organizing device in the ad hoc network has an IP address
  • each self-organizing device has a device identifier of each self-organizing device and each self-organizing The mapping between the IP addresses of the devices
  • the generating module 710 is specifically configured to: when the IP session is required to communicate with the target device in the ACP, generate the L2 ACP packet, where the L2 ACP packet further includes a destination IP address, where the destination IP address is the target device IP address.
  • the network device 700 may correspond to the first network device in the data link layer-based communication method of the embodiment of the present invention, and the above and other operations of the respective modules in the network device 700 and/or For the sake of brevity, the functions of the respective methods in FIG. 1 to FIG. 5 are not described here.
  • the L2 ACP packet sent by the embodiment of the present invention is based on the frame of the data link layer, and the L2 ACP packet can be transmitted in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • ACP-based communication can be implemented without the device maintaining the routing table as in the prior art.
  • FIG. 9 shows a network device 800 according to an embodiment of the present invention.
  • the network device 800 is used as a second network device.
  • the network device 800 is applied to an ad hoc network.
  • the network device 800 includes:
  • the receiving module 810 is configured to receive a frame-encapsulated L2 ACP packet sent by the first network device, where the L2 ACP packet includes a destination device identifier, where the data link layer frame includes a source data link. a layer address and a destination data link layer address, where the source data link layer address is a data link layer address of the first network device, the destination data link layer address and a data link layer of the second network device The addresses are matched, and the second network device and the first network device are both self-organizing devices in the self-organizing network;
  • matching the data link layer address of the destination with the data link layer address of the second network device means that the destination data link layer address is directly the data link layer address of the second network device, or The destination data link layer address is a broadcast data link layer address. It should be understood that the broadcast data link layer address may match any fixed data link layer address.
  • the processing module 820 is configured to process the L2 ACP packet received by the receiving module by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet.
  • the destination device identifier when the destination device identifier directly interprets the device identifier of the second network device, or the destination device identifier is a broadcast device identifier, the destination device identifier may be considered to match the device identifier of the second network device. Otherwise it does not match.
  • the self-organizing control plane ACP of the self-organizing network is established based on the data link layer, and the specific method is described in the foregoing methods 100 and 200, and details are not described herein again.
  • the L2 ACP packet in the embodiment of the present invention is based on the frame of the data link layer, and can transmit the L2 ACP packet in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the implementation of the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • the device does not need to maintain the routing table as in the prior art, and can also implement ACP-based communication.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol, and the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, where the data chain is The destination data link layer address of the path layer frame is the data link layer address of the target device;
  • the processing module 820 is specifically configured to determine that the destination device identifier is the device identifier of the second network device, and parse the L2 ACP packet.
  • the processing module 820 is specifically configured to obtain the content of the packet in the L2 ACP packet, for example, a control message, etc. by analyzing the L2 ACP packet.
  • the control message may be implemented to implement control and/or Control signaling for management functions.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast packet, where the data is The destination data link layer address of the link layer frame is a broadcast data link layer address;
  • the processing module 820 is specifically configured to: when determining that the device identifier of the second network device matches the destination device identifier, parsing the L2 ACP packet, and buffering the L2 ACP packet;
  • the content of the message in the L2 ACP message is obtained by parsing the L2 ACP message.
  • the processing module 820 is specifically configured to: when determining that the device identifier of the second network device does not match the destination device identifier, buffering the L2 ACP packet, and according to the destination data link layer address of the frame of the data link layer The neighboring device of the second network device forwards the L2 ACP packet based on the frame encapsulation of the data link layer.
  • the packet header of the L2 ACP packet further includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a broadcast packet, where the data chain is The destination data link layer address of the path layer frame is the broadcast data link layer address;
  • the processing module 820 is specifically configured to: determine that the device identifier of the second network device matches the destination device identifier, parse the L2 ACP packet, and cache the L2 ACP packet, and according to the data link layer.
  • the destination data link layer address of the frame forwards the L2 ACP message based on the frame encapsulation of the data link layer to the neighbor device of the second network device.
  • the L2 ACP message is a broadcast message
  • the destination device identifier in the L2 ACP message may be a broadcast device identifier
  • the L2 ACP is received by any network device in the self-organizing network. The message will determine that its device ID matches the destination device ID.
  • the L2 ACP message when the L2 ACP message is a broadcast message, the L2 ACP message may not include the destination device identifier, and the network device determines that the L2 ACP message is based on the flag of the L2 ACP message. If the broadcast packet is broadcast, the L2 ACP packet is parsed and forwarded. It is not necessary to determine whether the device identifier matches.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely identifying the L2 ACP packet.
  • the processing module 820 is specifically configured to process the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier when determining that the packet ID is not cached locally.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet exceeds the time for buffering the L2 ACP packet. Clear the L2 ACP message when the preset duration is long.
  • the network device 800 also includes:
  • the cache clearing module 830 is configured to: when it is determined that the time for buffering the L2 ACP message exceeds a preset duration indicated by the timing information, clear the L2 ACP message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • each self-organizing device in the ad hoc network has an IP address
  • each self-organizing device has a device identifier of each self-organizing device and each self-organizing Mapping between IP addresses of the device, where the L2 ACP message further includes a destination IP address.
  • the processing module 820 is specifically configured to: when the second network device determines that the device identifier of the second network device does not match the destination device identifier of the L2 ACP packet, according to the destination data link layer of the L2 ACP packet Transmitting the L2 ACP message to the neighboring device of the second network device;
  • the processing module 820 is specifically configured to: when the second network device determines that the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, and the IP address of the second network device and the L2 ACP The L2 ACP packet is parsed when the destination IP address of the packet matches.
  • the network device 800 may correspond to the second network device in the data link layer-based communication method of the embodiment of the present invention, and the above and other operations of the respective modules in the network device 800 and/or For the sake of brevity, the functions of the respective methods in FIG. 1 to FIG. 5 are not described here.
  • the L2 ACP packet sent in the embodiment of the present invention is based on a frame of a data link layer, and may be The L2 ACP packet is transmitted in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the embodiment of the present invention, the ACP-based communication may not depend on the IP protocol, compared to the prior art. , with good network compatibility.
  • the device does not need to maintain the routing table as in the prior art, and can also implement ACP-based communication.
  • FIG. 10 is a schematic block diagram of an ad hoc network-based system 900 according to an embodiment of the present invention.
  • the system 900 includes a network device 500 and a Registrar device 600 according to an embodiment of the present invention.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, and establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • FIG. 11 is a schematic block diagram of a system 1000 based on an ad hoc network provided by an embodiment of the present invention.
  • the system 1000 includes a network device 700 and a network device 800 provided by an embodiment of the present invention.
  • the L2 ACP packet sent by the embodiment of the present invention is based on the frame of the data link layer, and the L2 ACP packet can be transmitted in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • the device does not need to maintain the routing table as in the prior art, and can also implement ACP-based communication.
  • FIG. 12 is a schematic block diagram of a network device 1100 according to an embodiment of the present invention.
  • the network device 1100 includes a processor 1110, a memory 1120, a bus system 1130, a receiver 1140, and a transmitter 1150.
  • the processor 1110, the memory 1120, the receiver 1140, and the transmitter 1150 are connected by a bus system 1130.
  • the memory 1120 is configured to store an instruction, where the processor 1110 is configured to generate a neighbor discovery AD message, where the AD message includes the network.
  • the AD message is encapsulated according to a frame of the data link layer, where the frame of the data link layer includes a source data link layer address and a destination data link layer address, where the source data link layer address is the network
  • the data link layer address of the device is configured to register the Registrar based on the data link layer address of the destination.
  • the device sends the AD message according to the frame encapsulation of the data link layer, where the Registrar device is a device that supports the domain certificate in the self-organizing network, and the receiver 1140 is configured to receive the domain certificate sent by the Registrar device, the domain certificate.
  • the Registrar device is configured to allocate the device identifier of the network device according to the device identifier of the network device.
  • the processor 1110 is further configured to establish an ad hoc control plane ACP with the Registrar device according to the domain certificate.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, and establishes a self-organizing control plane ACP with the Registrar device according to the domain certificate. Therefore, in the embodiment of the present invention, the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates that the L2 ACP packet is the AD message.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the network device 1100 may correspond to a network device in a data link layer-based communication method according to an embodiment of the present invention, and may correspond to the network device 500 according to an embodiment of the present invention, and the network device
  • the above and other operations and/or functions of the respective modules in the 1100 are respectively implemented in order to implement the respective processes of the respective methods in FIG. 1 to FIG. 5, and are not described herein again for brevity.
  • the frame-packet AD message based on the data link layer is sent to the Registrar device according to the destination data link layer address of the frame of the data link layer.
  • the AD message receives the domain certificate sent by the Registrar device, according to the domain certificate.
  • FIG. 13 is a schematic block diagram of a registration Registrar device 1200 provided by an embodiment of the present invention.
  • the Registrar device 1200 is applied to an ad hoc network.
  • the Registrar device 1200 includes a processor 1210, a memory 1220, a bus system 1230, and a receiver 1240. And transmitter 1250.
  • the processor 1210, the memory 1220, the receiver 1240, and the transmitter 1250 are connected by a bus system 1230, where the memory 1220 is configured to store an instruction, where
  • the receiver 1240 is configured to receive a data link layer-based frame-decapsulated adjacency discovery AD message from the network device, where the AD message includes a device identifier of the network device, where the data link layer frame includes a source data link layer An address and destination data link layer address, where the source data link layer address is a data link layer address of the network device, and the destination data link layer address matches a data link layer address of the Registrar device; 1210 is configured to: when the network device is allowed to join the ad hoc network, assign a domain certificate to the network device according to the device identifier included in the AD message; the sender 1250 is configured to send the domain certificate to the network device; The 1210 is further configured to establish an ad hoc control plane ACP with the network device according to the domain certificate.
  • the adjacency discovery AD message of the device is encapsulated based on a frame of the data link layer; the AD message is sent to a Registrar device that allocates a domain certificate in the ad hoc network based on the data link layer address; the Registrar device The device is assigned a domain certificate according to the AD message; based on the domain certificate, the device establishes a self-organizing control plane ACP with the Registrar device.
  • the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, and the value of the flag bit field indicates that the L2 ACP packet is the AD message.
  • the network device is a neighboring device of the second network device
  • the processor 1210 is further configured to: establish, according to the AD message, a neighbor list of the second network device,
  • the neighbor list includes the device identifier of the network device and a data link layer address of the network device.
  • the device identifier of the network device is a unique device identifier UDI of the network device
  • the processor 1210 is further configured to: when determining that the whitelist has a match of the UDI of the network device, determine that the network device is allowed to join the ad hoc network, and allocate the domain certificate according to the UDI, the whitelist includes allowing the self-organization to be joined.
  • the UDI of the network device is further configured to: when determining that the whitelist has a match of the UDI of the network device, determine that the network device is allowed to join the ad hoc network, and allocate the domain certificate according to the UDI, the whitelist includes allowing the self-organization to be joined.
  • the UDI of the network device is further configured to: when determining that the whitelist has a match of the UDI of the network device, determine that the network device is allowed to join the ad hoc network, and allocate the domain certificate according to the UDI, the whitelist includes allowing the self-organization to be joined.
  • the UDI of the network device is further configured to: when determining that the
  • the device identifier of the network device is a secure unique device identifier S-UDI of the network device
  • the processor 1210 is further configured to: when it is determined by the verification server that the device digital certificate corresponding to the S-UDI is valid, determine that the network device is allowed to join the ad hoc network, and allocate the domain certificate according to the device digital certificate.
  • the header of the AD message further includes a version field, a protocol field, and a data packet length field.
  • the data link layer address is a medium access control MAC address.
  • the Registrar device 1200 may correspond to a Registrar device in a data link layer-based communication method according to an embodiment of the present invention, and may correspond to a Registrar device 600 according to an embodiment of the present invention, and a Registrar device.
  • the above and other operations and/or functions of the respective modules in the 1200 are respectively implemented in order to implement the respective processes of the respective methods in FIG. 1 to FIG. 5, and are not described herein again for brevity.
  • the adjacency discovery AD message of the device is encapsulated based on a frame of the data link layer; the AD message is sent to a Registrar device that allocates a domain certificate in the ad hoc network based on the data link layer address; the Registrar device The device is assigned a domain certificate according to the AD message; based on the domain certificate, the device establishes a self-organizing control plane ACP with the Registrar device.
  • the establishment of the ACP may not depend on the IP protocol, that is, the communication based on the self-organizing network may not be perceived by the IP protocol, and has better network compatibility than the prior art, and can effectively reduce Barriers to the deployment of small self-organizing networks.
  • FIG. 14 is a schematic block diagram of a network device 1300 according to an embodiment of the present invention.
  • the network device 1300 is applied to an ad hoc network.
  • the network device 1300 is used as a first network device, and the network device 1300 includes: a processor 1310.
  • Memory 1330, bus system 1330, receiver 1340, and transmitter 1350 are used as a first network device, and the network device 1300 includes: a processor 1310.
  • Memory 1330, bus system 1330, receiver 1340, and transmitter 1350 included in FIG. 14
  • Memory 1330 Memory 1330, bus system 1330, receiver 1340, and transmitter 1350.
  • the processor 1310, the memory 1330, the receiver 1340, and the transmitter 1350 is connected by a bus system 1330, where the memory 1330 is configured to store an instruction, wherein the processor 1310 is configured to generate a data link layer self-organizing control plane L2 ACP message, where the first network device is a self in the self-organizing network Organizing the device; encapsulating the L2 ACP message according to the data link layer frame, where the data link layer frame includes a source data link layer address and a destination data link layer address, where the source data link layer address is a data link layer address of the first network device; the transmitter 1350 is configured to send, according to the destination data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device, where The second network device is also an ad hoc device in the ad hoc network, and the second network device is a neighbor device of the first network device.
  • the second network device is also an ad hoc device in the ad
  • the L2 ACP packet is encapsulated according to the data link layer frame, and the L2 based on the frame of the data link layer is sent to the second network device according to the destination data link layer address.
  • the packet transmitted on the ACP may not depend on the IP protocol, and has better network compatibility than the prior art.
  • the network device may not need to maintain the routing table as in the prior art.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the processor 1310 is specifically configured to: when it is required to communicate with the target device in the ad hoc network, determine that the device identifier of the target device is included in the neighbor list of the first network device.
  • the L2 ACP packet is generated, and the L2 ACP packet header includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, and the first network device
  • the neighbor list includes the device identifier and the data link layer address of the neighbor device of the first network device; the L2 ACP packet is encapsulated according to the data link layer frame, and the destination data link layer address of the frame of the data link layer a data link layer address of the target device.
  • the transmitter 1350 is configured to send, according to the data link layer address of the target device, the L2 ACP packet encapsulated by the data link layer according to the data link layer. .
  • the processor 1310 is specifically configured to: when it is required to communicate with the target device in the ad hoc network, when determining that the neighbor list does not include the matching of the device identifier of the target device, Generating the L2 ACP packet, the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast packet; and the data link layer is based on a frame encapsulation
  • the address is a broadcast data link layer address.
  • the transmitter 1350 is configured to send, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • the processor 1310 is specifically configured to: when the control message is to be broadcast in the ACP, generate the L2 ACP packet, where the header of the L2 ACP packet includes a flag bit field, where The value of the flag bit field is used to indicate that the L2 ACP message is a broadcast message; the L2 ACP message is encapsulated according to a frame of the data link layer, and the destination data link layer address of the frame of the data link layer is a broadcast data link.
  • the layer 1 address is specifically configured to send, according to the broadcast data link layer address, the L2 ACP packet encapsulated by the frame of the data link layer to the second network device.
  • control message may be control signaling that implements control and/or management functions.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely indicating the L2 ACP packet.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet caches the L2 ACP packet for a longer period of time than When the duration is set, the L2 ACP message is cleared.
  • each self-organizing device in the ad hoc network has an IP address
  • each self-organizing device has a device identifier of each self-organizing device and each self-organizing The mapping between the IP addresses of the devices
  • the processor 1310 is specifically configured to: when the IP session is required to communicate with the target device in the ACP, generate the L2 ACP message, where the L2 ACP message further includes a destination IP address, where the destination IP address is the IP address of the target device. address.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the network device 1300 may correspond to the first network device in the data link layer-based communication method of the embodiment of the present invention, and may correspond to the network device 700 according to the embodiment of the present invention, and
  • the above and other operations and/or functions of the various modules in the network device 1300 are respectively implemented in order to implement the respective processes of the respective methods in FIGS. 1 to 5, for the sake of brevity, This will not be repeated here.
  • the L2 ACP packet sent by the embodiment of the present invention is based on the frame of the data link layer, and the L2 ACP packet can be transmitted in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • ACP-based communication can be implemented without the device maintaining the routing table as in the prior art.
  • FIG. 15 is a schematic block diagram of a network device 1400, which is used in a self-organizing network, and the network device 1400 is used as a second network device, and the network device 1400 includes: a processor 1410, Memory 1420, bus system 1440, receiver 1440, and transmitter 1450.
  • the processor 1410, the memory 1420, the receiver 1440, and the transmitter 1450 are connected by a bus system 1440, where the memory 1420 is configured to store an instruction, where the receiver 1440 is configured to receive a data link layer sent by the first network device.
  • the frame encapsulated L2 ACP message, the L2 ACP message includes a destination device identifier, and the data link layer frame includes a source data link layer address and a destination data link layer address, where the source data link layer The address is a data link layer address of the first network device, and the destination data link layer address matches the data link layer address of the second network device, where the second network device and the first network device are both
  • the self-organizing device in the self-organizing network; the processor 1410 is configured to process the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier of the L2 ACP packet.
  • the L2 ACP packet sent by the embodiment of the present invention is based on the frame of the data link layer, and the L2 ACP packet can be transmitted in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • the network device may not need to maintain the routing table as in the prior art.
  • the frame of the data link layer is a frame that conforms to the definition of the Ethernet protocol
  • the Type value of the Type field of the frame of the data link layer indicates the frame of the data link layer.
  • the data payload field carries the data link layer self-organizing control plane L2 ACP message.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a neighbor unicast packet, where the data chain is The destination data link layer address of the path layer frame is the data link layer address of the target device;
  • the processor 1410 is specifically configured to determine that the destination device identifier is the device identifier of the second network device, and parse the L2 ACP packet.
  • the packet header of the L2 ACP packet includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a non-neighbor unicast packet, where the data is The destination data link layer address of the link layer frame is a broadcast data link layer address;
  • the processor 1410 is specifically configured to: when determining that the device identifier of the second network device matches the destination device identifier, parse the L2 ACP packet, and cache the L2 ACP packet; and determine the device of the second network device When the identifier does not match the destination device identifier, the L2 ACP packet is buffered, and the data link layer address of the data link layer is forwarded to the neighbor device of the second network device based on the data link layer.
  • the L2 ACP packet after the frame is encapsulated.
  • the packet header of the L2 ACP packet further includes a flag bit field, where the value of the flag bit field is used to indicate that the L2 ACP packet is a broadcast packet, where the data chain is The destination data link layer address of the path layer frame is the broadcast data link layer address;
  • the processor 1410 is specifically configured to: determine that the device identifier of the second network device matches the destination device identifier, parse the L2 ACP packet, and cache the L2 ACP packet, and according to the purpose of the data link layer frame The data link layer address forwards the L2 ACP message based on the frame encapsulation of the data link layer to the neighbor device of the second network device.
  • the packet header of the L2 ACP packet further includes a packet ID for uniquely identifying the L2 ACP packet.
  • the processor 1410 is specifically configured to process the L2 ACP packet by determining whether the device identifier of the second network device matches the destination device identifier when the packet ID is not cached locally.
  • the packet header of the L2 ACP packet further includes timing information, where the timing information is used to indicate that the receiving device of the L2 ACP packet exceeds the time for buffering the L2 ACP packet. Clear the L2 ACP message when the preset duration is long.
  • the processor 1410 is further configured to: when it is determined that the time for buffering the L2 ACP message exceeds a preset duration indicated by the timing information, clearing the L2 ACP message.
  • each self-organizing device in the ad hoc network has an IP address
  • each self-organizing device has a device identifier of each self-organizing device and each self-organizing Mapping between IP addresses of the device, where the L2 ACP message further includes a destination IP address.
  • the processor 1410 is specifically configured to: when determining that the device identifier of the second network device does not match the destination device identifier of the L2 ACP packet, according to the destination data link layer of the L2 ACP packet Forwarding the L2 ACP message to the neighboring device of the second network device; determining that the device identifier of the second network device matches the destination device identifier of the L2 ACP packet, and the IP address of the second network device
  • the L2 ACP packet is parsed when it matches the destination IP address of the L2 ACP packet.
  • the packet header of the L2 ACP packet further includes a version field, a protocol field, and a packet length field.
  • the data link layer address is a medium access control MAC address.
  • the device identifier is a unique device identifier UDI or a secure unique device identifier SUDI.
  • the network device 1400 may correspond to the second network device in the data link layer-based communication method of the embodiment of the present invention, and may correspond to the network device 800 according to an embodiment of the present invention, and
  • the foregoing and other operations and/or functions of the respective modules in the network device 1400 are respectively omitted in order to implement the corresponding processes of the respective methods in FIG. 1 to FIG. 5 for brevity.
  • the L2 ACP packet sent by the embodiment of the present invention is based on the frame of the data link layer, and the L2 ACP packet can be transmitted in the ACP based on the destination data link layer address of the L2 ACP packet, that is, in the present invention.
  • the ACP-based communication can be independent of the IP protocol and has better network compatibility than the prior art.
  • the device does not need to maintain the routing table as in the prior art, and can also implement ACP-based communication.
  • the size of the sequence numbers of the above processes does not mean the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not be taken to the embodiments of the present invention.
  • the implementation process constitutes any limitation.
  • the disclosed systems, devices, and methods may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the functions may be stored in a computer readable storage medium if implemented in the form of a software functional unit and sold or used as a standalone product.
  • the technical solution of the present invention which is essential or contributes to the prior art, or a part of the technical solution, may be embodied in the form of a software product, which is stored in a storage medium, including
  • the instructions are used to cause a computer device (which may be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .

Abstract

本发明实施例提供一种基于数据链路层的通信方法、设备和系统,该方法包括:网络设备生成邻接发现AD消息,AD消息包括该网络设备的设备标识;网络设备基于数据链路层的帧封装该AD消息,数据链路层的帧包括源数据链路层地址与目的数据链路层地址;该网络设备基于目的数据链路层地址,向Registrar设备发送基于该数据链路层的帧封装后的该AD消息;该网络设备接收该Registrar设备发送的域证书,该域证书为该Registrar设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的;网络设备根据该域证书,与该Registrar设备建立自组织控制平面ACP。在本发明实施例中,基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,有效减小自组织网络的部署障碍。

Description

一种基于数据链路层的通信方法、设备和系统 技术领域
本发明实施例涉及通信领域,并且更具体地,涉及一种基于数据链路层的通信方法、设备和系统。
背景技术
自组织网络(Autonomic Network,简称为“AN”)是一种能够支持自管理的网络,例如包括网络自配置、自保护、自愈和自优化,能够提升网络的自动化程度。自组织网络中的一个关键技术是自动控制平面(Autonomic Control Plane,简称为“ACP”)的建立,自组织控制平面ACP指的是自组织网络中的控制平面,上层的自组织功能实体可以使用该ACP平面传输控制信令。
当前技术中提出一种基于IPv6(Internet Protocol Version 6)建立ACP的实现方式,但是当前技术中,需要网络设备支持IPv6,才能实现ACP的建立,导致自组织网络兼容性不好。
发明内容
本发明实施例提供一种基于数据链路层的通信方法、设备和系统,基于数据链路层建立自组织网络,能够克服现有技术中实现自组织网络必须依赖于IPv6的问题,具有较好的网络兼容性。
第一方面,提供了一种基于数据链路层的通信方法,该方法包括:
网络设备生成邻接发现AD消息,该AD消息包括该网络设备的设备标识;
该网络设备基于数据链路层的帧封装该AD消息,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址;
该网络设备基于该目的数据链路层地址,向登记Registrar设备发送基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备;
该网络设备接收该Registrar设备发送的域证书,该域证书为该Registrar 设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的;
该网络设备根据该域证书,与该Registrar设备建立自组织控制平面ACP。
结合第一方面,在第一方面的第一种可能的实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
结合第一方面或一方面的第一种可能的实现方式,在第一方面的第二种可能的实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
结合第一方面及其上述实现方式,在第一方面的第三种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第一方面及其上述实现方式,在第一方面的第四种实现方式中,该数据链路层地址为介质访问控制MAC地址。
结合第一方面及其上述实现方式,在第一方面的第五种实现方式中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
第二方面,提供了一种基于数据链路层的通信方法,该方法包括:
登记Registrar设备接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,该AD消息包括该网络设备的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配;
当该Registrar设备确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书;
该Registrar设备根据该域证书,与该网络设备建立自组织控制平面ACP。
结合第二方面,在第二方面的第一种实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
结合第二方面或第二方面的第一种实现方式,在第二方面的第二种实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
结合第二方面及其上述实现方式,在第二方面的第三种实现方式中,该网络设备为该Registrar设备的邻居设备,该方法还包括:
该Registrar设备根据该AD消息,建立该Registrar设备的邻居列表,该邻居列表包括该网络设备的设备标识以及该网络设备的数据链路层地址。
结合第二方面及其上述实现方式,在第二方面的第四种实现方式中,该网络设备的设备标识为该网络设备的唯一设备标识UDI,
其中,当该Registrar设备确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书,包括:
当该Registrar设备确定白名单具有该网络设备的UDI的匹配项时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该UDI分配的该域证书,该白名单包括允许加入该自组织网络的设备的UDI。
结合第二方面及其上述实现方式,在第二方面的第五种实现方式中,该网络设备的设备标识为该网络设备的安全的唯一设备标识S-UDI,
其中,当该Registrar设备确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书,包括:
当该Registrar设备通过验证服务器确定该S-UDI对应的设备数字证书有效时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该设备数字证书分配的该域证书。
结合第二方面及其上述实现方式,在第二方面的第六种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第二方面及其上述实现方式,在第二方面的第七种实现方式中,该数据链路层地址为介质访问控制MAC地址。
第三方面,提供了一种基于数据链路层的通信方法,该通信方法应用于自组织网络,该方法包括:
第一网络设备生成数据链路层自组织控制平面L2 ACP报文,该第一网络设备为该自组织网络中的自组织设备;
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址;
该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,该第二网络设备也为该自组织网络中的自组织设备,且该第二网络设备为该第一网络设备的邻居设备。
结合第三方面,在第三方面的第一种实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
结合第三方面或在第三方面的第一种实现方式,在第三方面的第二种实现方式中,
该第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
该第一网络设备需要与该自组织网络中的目标设备通信时,当确定该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,该第一网络设备的邻居列表包括该第一网络设备的邻居设备的设备标识与数据链路层地址;
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,包括:
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,包括:
该第一网络设备根据该目标设备的数据链路层地址,向该目标设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
结合第三方面或在第三方面的第一种实现方式,在第三方面的第三种实现方式中,该第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
该第一网络设备需要与该自组织网络中的目标设备通信时,当确定该邻居列表中不包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文;
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,包括:
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,包括:
该第一网络设备根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
结合第三方面或在第三方面的第一种实现方式,在第三方面的第四种实现方式中,该第一网络设备生成L2 ACP报文,包括:
当该第一网络设备需要在该ACP内广播控制消息时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文;
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,包括:
该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,包括:
该第一网络设备根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
结合第三方面的第三种或第四种实现方式,在第三方面的第五种实现方式中,该L2 ACP报文的报文头还包括用于唯一指示该L2 ACP报文的报文ID。
结合第三方面第三种至第五种实现方式中的任一种实现方式,在第三方面的第六种实现方式中,该L2 ACP报文的报文头还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
结合第三方面及其上述实现方式,在第三方面的第七种实现方式中,该自组织网络中的每个设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,
其中,该第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
当该第一网络设备需要通过IP会话与该自组织网络内的目标设备通信时,生成该L2 ACP报文,该L2 ACP报文还包括目的IP地址,该目的IP地址为该目标设备的IP地址。
结合第三方面及其上述实现方式,在第三方面的第八种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第三方面及其上述实现方式,在第三方面的第九种实现方式中,该数据链路层地址为介质访问控制MAC地址。
结合第三方面及其上述实现方式,在第三方面的第十种实现方式中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
第四方面,提供了一种基于数据链路层的通信方法,该通信方法应用于自组织网络,该方法包括:
第二网络设备接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,该L2 ACP报文包括目的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配,该第二网络设备与该第一网络设备均为该自组织网络中的自组织设备;
该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文。
结合第四方面,在第四方面的第一种实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
结合第四方面及其上述实现方式,在第四方面的第二种实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
其中,该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
该第二网络设备确定该目的设备标识为该第二网络设备的设备标识,并解析该L2 ACP报文。
结合第四方面或第四方面的第一种实现方式,在第四方面的第三种实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
当该第二网络设备确定该第二网络设备的设备标识与该目的设备标识相匹配时,解析该L2 ACP报文,并缓存该L2 ACP报文;
当该第二网络设备确定该第二网络设备的设备标识与该目的设备标识不匹配时,缓存该L2 ACP报文,并根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
结合第四方面或第四方面的第一种实现方式,在第四方面的第四种实现方式中,该L2 ACP报文的报文头还包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
该第二网络设备确定该第二网络设备的设备标识与该目的设备标识相匹配,解析该L2 ACP报文,并缓存该L2 ACP报文,以及根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
结合第四方面的第三种或第四种实现方式,在第四方面的第五种实现方式中,该L2 ACP报文的报文头中还包括用于唯一标识该L2 ACP报文的报文ID,
其中,该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
当该第二网络设备确定本地未缓存该报文ID时,通过判断该第二网络设备的设备标识是否与该目的设备标识相匹配,处理该L2 ACP报文。
结合第四方面的第三种至第五种实现方式中的任一种实现方式,在第四方面的第六种实现方式中,该L2 ACP报文的报文头中还包括定时信息,该 定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文,
该方法还包括:
当该第二网络设备确定缓存该L2 ACP报文的时间超过该定时信息所指示的预设时长时,清除该L2 ACP报文。
结合第四方面及其上述实现方式,在第四方面的第七种实现方式中,该自组织网络内的每个自组织设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,其中,该L2 ACP报文还包括目的IP地址,
该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
当该第二网络设备确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识不匹配时,根据该L2 ACP报文的目的数据链路层地址向该第二网络设备的邻居设备转发该L2 ACP报文;
当该第二网络设备确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识相匹配、且该第二网络设备的IP地址与该L2 ACP报文的该目的IP地址相匹配时,解析该L2 ACP报文。
结合第四方面及其上述实现方式,在第四方面的第八种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第四方面及其上述实现方式,在第四方面的第九种实现方式中,该数据链路层地址为介质访问控制MAC地址。
结合第四方面及其上述实现方式,在第四方面的第十种实现方式中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
第五方面,提供了一种网络设备,该网络设备应用于自组织网络,该网络设备包括:
生成模块,用于网络设备生成邻接发现AD消息,该AD消息包括该网络设备的设备标识;
封装模块,用于基于数据链路层的帧封装该生成模块生成的该AD消息,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址;
发送模块,用于基于该目的数据链路层地址,向登记Registrar设备发送 该封装模块确定的基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备;
接收模块,用于接收该Registrar设备发送的域证书,该域证书为该Registrar设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的;
建立模块,用于根据该接收模块接收的该域证书,与该Registrar设备建立自组织控制平面ACP。
结合第五方面,在第五方面的第一种可能的实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
结合第五方面或一方面的第一种可能的实现方式,在第五方面的第二种可能的实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
结合第五方面及其上述实现方式,在第五方面的第三种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第五方面及其上述实现方式,在第五方面的第四种实现方式中,该数据链路层地址为介质访问控制MAC地址。
结合第五方面及其上述实现方式,在第五方面的第五种实现方式中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
第六方面,提供了一种登记Registrar设备,该Registrar设备应用于自组织网络,该Registrar设备为该自组织网络中支持分配域证书的设备,Registrar设备包括:
接收模块,用于接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,该AD消息包括该网络设备的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配;
发送模块,用于当确定该网络设备允许加入该自组织网络时,根据该接收模块接收的该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书;
ACP建立模块,用于根据该发送模块发送的该域证书,与该网络设备建立自组织控制平面ACP。
结合第六方面,在第六方面的第一种实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
结合第六方面或第六方面的第一种实现方式,在第六方面的第二种实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
结合第六方面及其上述实现方式,在第六方面的第三种实现方式中,该网络设备为该Registrar设备的邻居设备,该Registrar设备还包括:
邻居列表建立模块,用于根据该AD消息,建立该Registrar设备的邻居列表,该邻居列表包括该网络设备的设备标识以及该网络设备的数据链路层地址。
结合第六方面及其上述实现方式,在第六方面的第四种实现方式中,该网络设备的设备标识为该网络设备的唯一设备标识UDI,
其中,该发送模块具体用于,当确定白名单具有该网络设备的UDI的匹配项时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该UDI分配的该域证书,该白名单包括允许加入该自组织网络的设备的UDI。
结合第六方面及其上述实现方式,在第六方面的第五种实现方式中,该网络设备的设备标识为该网络设备的安全的唯一设备标识S-UDI,
其中,该发送模块具体用于,当通过验证服务器确定该S-UDI对应的设备数字证书有效时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该设备数字证书分配的该域证书。
结合第六方面及其上述实现方式,在第六方面的第六种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第六方面及其上述实现方式,在第六方面的第七种实现方式中,该数据链路层地址为介质访问控制MAC地址。
第七方面,提供了一种网络设备,该网络设备用作第一网络设备,该第一网络设备应用于自组织网络,该第一网络设备包括:
生成模块,用于生成数据链路层自组织控制平面L2 ACP报文,该第一 网络设备为该自组织网络中的自组织设备;
封装模块,用于基于数据链路层的帧封装该生成模块生成的该L2 ACP报文,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址;
发送模块,用于根据该目的数据链路层地址,向第二网络设备发送该封装模块确定的基于该数据链路层的帧封装后的该L2 ACP报文,该第二网络设备也为该自组织网络中的自组织设备,且该第二网络设备为该第一网络设备的邻居设备。
结合第七方面,在第七方面的第一种实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
结合第七方面或在第七方面的第一种实现方式,在第七方面的第二种实现方式中,该生成模块具体用于,需要与该自组织网络中的目标设备通信时,当确定该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,该第一网络设备的邻居列表包括该第一网络设备的邻居设备的设备标识与数据链路层地址;
该封装模块具体用于,基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
该发送模块具体用于,根据该目标设备的数据链路层地址,向该目标设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
结合第七方面或在第七方面的第一种实现方式,在第七方面的第三种实现方式中,该生成模块具体用于,需要与该自组织网络中的目标设备通信时,当确定该邻居列表中不包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文;
该封装模块具体用于,基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
该发送模块具体用于,根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
结合第七方面或在第七方面的第一种实现方式,在第七方面的第四种实 现方式中,该生成模块具体用于,需要在该ACP内广播控制消息时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文;
该封装模块具体用于,基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该发送模块具体用于,根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
结合第七方面的第三种或第四种实现方式,在第七方面的第五种实现方式中,该L2 ACP报文的报文头还包括用于唯一指示该L2 ACP报文的报文ID。
结合第七方面第三种至第五种实现方式中的任一种实现方式,在第七方面的第六种实现方式中,该L2 ACP报文的报文头还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
结合第七方面及其上述实现方式,在第七方面的第七种实现方式中,该自组织网络中的每个设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,
其中,该生成模块具体用于,当需要通过IP会话与该自组织网络内的目标设备通信时,生成该L2 ACP报文,该L2 ACP报文还包括目的IP地址,该目的IP地址为该目标设备的IP地址。
结合第七方面及其上述实现方式,在第七方面的第八种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第七方面及其上述实现方式,在第七方面的第九种实现方式中,该数据链路层地址为介质访问控制MAC地址。
结合第七方面及其上述实现方式,在第七方面的第十种实现方式中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
第八方面,提供了一种网络设备,该网络设备用作第二网络设备,该第二网络设备应用于自组织网络,该第二网络设备包括:
接收模块,用于接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,该L2 ACP报文包括目的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第 一网络设备的数据链路层地址,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配,该第二网络设备与该第一网络设备均为该自组织网络中的自组织设备;
处理模块,用于通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该接收模块接收的该L2 ACP报文。
结合第八方面,在第八方面的第一种实现方式中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
结合第八方面及其上述实现方式,在第八方面的第二种实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
其中,该处理模块具体用于,确定该目的设备标识为该第二网络设备的设备标识,并解析该L2 ACP报文。
结合第八方面或第八方面的第一种实现方式,在第八方面的第三种实现方式中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该处理模块具体用于,当确定该第二网络设备的设备标识与该目的设备标识相匹配时,解析该L2 ACP报文,并缓存该L2 ACP报文;
处理模块具体用于,当确定该第二网络设备的设备标识与该目的设备标识不匹配时,缓存该L2 ACP报文,并根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
结合第八方面或第八方面的第一种实现方式,在第八方面的第四种实现方式中,该L2 ACP报文的报文头还包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该处理模块具体用于,确定该第二网络设备的设备标识与该目的设备标识相匹配,解析该L2 ACP报文,并缓存该L2 ACP报文,以及根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转 发基于该数据链路层的帧封装后的该L2 ACP报文。
结合第八方面的第三种或第四种实现方式,在第八方面的第五种实现方式中,该L2 ACP报文的报文头中还包括用于唯一标识该L2 ACP报文的报文ID,
其中,该处理模块具体用于,当确定本地未缓存该报文ID时,通过判断该第二网络设备的设备标识是否与该目的设备标识相匹配,处理该L2 ACP报文。
结合第八方面的第三种至第五种实现方式中的任一种实现方式,在第八方面的第六种实现方式中,该L2 ACP报文的报文头中还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文,
该第二网络设备还包括:
缓存清除模块,用于当确定缓存该L2 ACP报文的时间超过该定时信息所指示的预设时长时,清除该L2 ACP报文。
结合第八方面及其上述实现方式,在第八方面的第七种实现方式中,该自组织网络内的每个自组织设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,其中,该L2 ACP报文还包括目的IP地址,
该处理模块具体用于,当确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识不匹配时,根据该L2 ACP报文的目的数据链路层地址向该第二网络设备的邻居设备转发该L2 ACP报文;
当确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识相匹配、且该第二网络设备的IP地址与该L2 ACP报文的该目的IP地址相匹配时,解析该L2 ACP报文。
结合第八方面及其上述实现方式,在第八方面的第八种实现方式中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
结合第八方面及其上述实现方式,在第八方面的第九种实现方式中,该数据链路层地址为介质访问控制MAC地址。
结合第八方面及其上述实现方式,在第八方面的第十种实现方式中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
第九方面提供了一种基于数据链路层的系统,该系统包括上述第五方面 提供的网络设备和第六方面提供的登记Registrar设备。
第十方面提供了一种基于数据链路层的系统,该系统包括上述第七方面提供的网络设备和第八方面提供的网络设备。
基于上述技术方案,在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
附图说明
为了更清楚地说明本发明实施例的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1示出了本发明实施例提供的基于数据链路层的通信方法的示意性流程图。
图2示出了本发明实施例提供的基于数据链路层的通信方法的示意图。
图3示出了本发明实施例提供的基于数据链路层的通信方法的另一示意性流程图。
图4示出了本发明实施例提供的基于数据链路层的通信方法的再一示意性流程图。
图5示出了本发明实施例提供的基于数据链路层的通信方法的再一示意性流程图。
图6示出了本发明实施例提供的网络设备的示意性框图。
图7示出了本发明实施例提供的Registrar设备的示意性框图。
图8示出了本发明实施例提供的另一网络设备的示意性框图。
图9示出了本发明实施例提供的再一网络设备的示意性框图。
图10示出了本发明实施例提供的基于数据链路层的系统的示意性框图。
图11示出了本发明另一实施例提供的基于数据链路层的系统的示意性 框图。
图12示出了本发明另一实施例提供的网络设备的示意性框图。
图13示出了本发明另一实施例提供的Registrar设备的示意性框图。
图14示出了本发明另一实施例提供的另一网络设备的示意性框图。
图15示出了本发明另一实施例提供的再一网络设备的示意性框图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
应理解,本发明的技术方案可以应用于各种通信系统,例如固定网络通信系统,具体地例如接入网络系统、汇聚网络系统、骨干网络系统、专用网络系统等固定网络系统。本发明的技术方案可以应用于移动通信系统,具体地,例如为通用移动通信系统(Universal Mobile Telecommunication System,简称为“UMTS”)、全球移动通讯(Global System of Mobile communication,简称为“GSM”)系统、通用分组无线业务(General Packet Radio Service,简称为“GPRS”)、长期演进(Long Term Evolution,简称为“LTE”)系统等移动通信系统,本发明实施例对此不作限定。
还应理解,本发明实施例涉及到的设备可以为网络设备,具体地,例如路由器、交换机、或者用户设备,其中,该用户设备也可称之为终端、移动台(Mobile Station,简称为“MS”)、移动终端(Mobile Terminal)等,该用户设备可以经有线网络接入Internet或者企业网络;该用户设备也可以经无线接入网(Radio Access Network,简称为“RAN”)与一个或多个核心网进行通信,例如,该用户设备可以是移动电话(或称为“蜂窝”电话)、具有移动终端的计算机,还可以是便携式、袖珍式、手持式、计算机内置的或者车载的移动装置,它们与无线接入网交换语言和/或数据。
应理解,现有的ACP技术方案中,要支持自组织特性,需要先支持IPv6,就ACP的构建依赖于IPv6的实现,网络兼容性差,网络部署有困难,给管理工作带来麻烦。
应理解,现有技术是基于网络层(也可称之为L3层)建立ACP。本发 明是基于数据链路层(也可称之为L2层)建立ACP,相对于现有技术,实现了建立ACP可以不感知IP协议,也就是不依赖于网络设备是支持IPv4协议,还是支持IPv6协议,而且支持IPv4的网络设备和支持IPv6协议的网络设备可以共同组成自组织网络,提高了网络兼容性,降低了部署困难。
应理解,本发明实施例中涉及的设备均为自组织设备,即该设备支持自组织特性,该设备有自己的唯一设备标识(Unique Device Identification,简称为“UDI”),或者设备证书(IDevID Certificate)。其中,设备支持自组织特性,指的是设备具有自动建立ACP或者自动加入ACP的功能。
还应理解,本发明实施例中涉及的登记Registrar设备指的是能够为自组织域内的设备(包括该Registrar设备)分配域证书的设备,例如该Registrar设备与数字证书认证管理机构有连接,且可以通信,换句话说,该Registrar设备能够通过数字证书认证管理结构为自组织域内的所有设备分配域证书。具体地,例如Registrar设备根据设备的设备标识,判断该设备是否允许加入自组织域,如果确定允许,则根据该设备的设备标识为其分配域证书,反之亦然。具体地,设备的设备标识可以是唯一设备标识UDI,也可以是设备证书,本发明实施例对此不作限定。应理解,Registrar设备首先会给自己分配域证书。
图1示出了本发明实施例提供的基于数据链路层的通信方法100的示意性流程图,该方法例如可以由自组织网络中的网络设备来执行,该方法100包括:
S110,网络设备生成邻接发现AD消息,该AD消息包括该网络设备的设备标识;
S120,该网络设备基于数据链路层的帧封装该AD消息,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址;
应理解,该数据链路层的帧的目的数据链路层地址可以为广播数据链路层地址,或者为该网络设备的邻居设备的数据链路层地址。
S130,该网络设备基于该目的数据链路层地址,向Registrar设备发送基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备;
S140,该网络设备接收该Registrar设备发送的域证书,该域证书为该 Registrar设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的;
S150,该网络设备根据该域证书,与该Registrar设备建立自组织控制平面ACP。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
在本发明实施例中,可选地,该数据链路层地址为介质访问控制(Media Access Control,简称为“MAC”)地址。
下文的示例中均以数据链路层地址为MAC地址为例进行描述。
应理解,在本发明实施例中,基于数据链路层的帧封装邻接发现(Adjacency Discovery,简称为“AD”)消息。应理解,在本发明实施例中,生成AD消息后,直接基于数据链路层的帧封装该AD消息,并不基于IP的报文封装该AD消息。换句话说,在本发明实施例中,AD消息直接封装在数据链路层的帧中,不再基于IP报文封装。因此,本发明实施例中的AD消息对IP协议或者IP地址可以不感知,从而,自组织控制平面ACP的实现可以不依赖于IP协议,例如IPv6或IPv4。因此,在本发明实施例中,基于数据链路层实现ACP,相比于现有技术具有较好的网络兼容性,也降低了自组织网络部署的难度。
还应理解,该数据链路层的帧的目的数据链路层地址为数据链路层广播地址或该网络设备的邻居设备的数据链路层地址,其中,该邻居设备可以为该Registrar设备或Proxy设备。该Registrar设备可以是该网络设备的邻居设备,也可以是非邻居设备,本发明实施例对此不作限定。
可选地,在本发明实施例中,该网络设备的邻居设备包括该Registrar设备;
其中,该数据链路层的帧的目的MAC地址为该Registrar设备的MAC地址或MAC广播地址;
S130该网络设备基于该目的数据链路层地址,向Registrar设备发送基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备,包括:
该网络设备根据该目的MAC地址,直接向该Registrar设备发送基于数据链路层的帧封装后的该AD消息。
换句话说,该AD消息从网络设备到该Registrar设备,无需中间设备的转发。这种情形也可称之为,该AD消息以邻居单播的方式,从网络设备传输至Registrar设备。
可选地,在本发明实施例中,该Registrar设备不是该网络设备的邻居设备;
其中,该数据链路层的帧的目的MAC地址为MAC广播地址;
S130该网络设备基于该目的数据链路层地址,向Registrar设备发送基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备,包括:
该网络设备基于该目的数据链路层地址,通过具备由Registrar设备分配的域证书的Proxy设备,向该自组织网络中支持分配域证书的Registrar设备发送基于数据链路层的帧封装后的该AD消息。
具体地,以图2为例进行说明,例如网络设备为图2中的设备5,Registrar设备为图2中的设备1,这种情形下,设备5向中间设备2发送AD消息,中间设备2确定所述网络设备还不具备域证书时,向该Registrar设备申请该设备5的域证书,该中间设备2还接收该Registrar设备为该设备5分配的域证书,并将该设备5的域证书发送给该设备5,其中,该中间设备2为已经具备由Registrar设备分配的域证书的网络设备,已经具备域证书的网络设备可以称之为Proxy设备。
在S150中,该网络设备与该Registrar设备建立自组织控制平面ACP,具体地,该网络设备与该Registrar设备基于网络设备的域证书以及Registrar设备的域证书(Registrar设备会首先给自己分配域证书),相互认证,在数据链路层建立安全连接,例如建立MACsec通路,这个过程可称之为在网络设备与Registrar设备之间建立自组织控制平面ACP。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧 的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
具体地,本发明实施例中的L2 ACP报文用于指示基于数据链路层的在ACP上传输的报文。应理解,基于数据链路层的帧封装该AD消息,即该数据链路层的帧的数据载荷字段承载该AD消息,其中,该数据链路层的帧的Type字段指示该数据载荷字段承载的消息为L2 ACP报文,可以认为L2 ACP报文包括该AD消息。
具体地,例如该数据链路层的帧的类型Type字段的Type值为0x88e7。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
具体地,该AD消息的报文头包括用于指示该L2 ACP报文为该AD消息的标志位字段。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
具体地,表1示出了根据本发明实施例提供的AD消息的格式:
表1
Figure PCTCN2015084772-appb-000001
从表1可知,根据本发明实施例提供的AD消息包括报文头和报文内容,其中,报文内容中包括了网络设备的设备标识(例如UDI)或域证书等信息,应理解,当网络设备分配了域证书后,其AD消息里可以携带其域证书。
AD消息的报文头具体可以如表2所示:
表2
版本 标志位 协议 数据包长度
如表2所示,该AD消息的报文头包括版本字段、标志位字段、协议字段和数据包长度字段,其中,版本字段的值指示的该AD消息对应的协议的版本,例如该版本字段共4位;该标志位字段为4位,例如该标志位字段的值为0000,用于指示该AD消息为该AD消息;协议字段的值用于指示该数据链路层的帧的数据载荷字段携带的内容的协议,协议字段共8位,例如可以使用与IP协议对应的协议字段的取值;数据包长度字段指共16位,其值 用于指示整个数据包的长度。
基于数据链路层的帧封装之后的AD消息的格式如表3所示:
表3
Figure PCTCN2015084772-appb-000002
由表3可知,基于数据链路层的帧封装之后的AD消息的格式包括该数据链路层的帧的帧头、报文头和报文内容,其中,报文头与报文内容如上文结合表1和表2所示。该数据链路层的帧的帧头包括目的MAC地址、源MAC地址和类型Type字段,其中目的MAC地址可以为MAC广播地址或者是该网络设备的邻居设备的MAC地址;源MAC地址为该网络设备的MAC地址。类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文,具体地,该Type字段可申请赋值为0x88e7。
应理解,表1、表2和表3仅作为示例而非限定。
应理解,在本发明实施例中,AD消息也可以称之为L2 ACP报文,数据链路层的设备均可识别该AD消息,即该AD消息可以在数据链路层有效传输、有效接收。例如,Registrar设备接收到来自于网络设备的基于数据链路层封装的AD消息后,通过该数据链路层的帧进行解析获取到该AD消息,从而获取AD消息中携带的该网络设备的设备标识(例如UDI)或MAC地址等信息。
在S140中,该网络设备接收该Registrar设备发送的域证书,该域证书为该Registrar设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的,具体地,该Registrar设备根据设备标识判断该网络设备是否允许加入自组织网络,确定允许的情况下,根据该设备标识分配域证书,并发送给该网络设备。
可选地,在本发明实施例中,该设备标识为唯一设备标识(Unique Device Identification,简称为“UDI”)或者安全的唯一设备标识(Safe Unique Device Identification,简称为“SUDI”)。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的唯 一设备标识UDI;
该网络设备接收该Registrar设备根据该设备标识发送的域证书,包括:
该网络设备接收该Registrar设备根据该网络设备的UDI发送的域证书,该域证书是该Registrar设备在确定白名单具有该网络设备的UDI的匹配项的情况下为该网络设备配置的,该白名单包括允许加入自组织域的设备的UDI。
具体地,例如,当该设备标识为UDI时,该Registrar设备通过白名单来判断该网络设备是否允许加入自组织域,该白名单记载了允许加入该自组织域的设备的UDI,当Registrar设备在白名单内找到该网络设备的UDI的匹配项时,例如通过数字证书认证管理结构,基于该网络设备的UDI,为该网络设备分配域证书;如果Registrar网络设备在白名单内找不到该网络设备的UDI的匹配项,则确定该网络设备不允许加入自组织域。
应理解,给Registrar设备配置白名单,可以是人为配置的,也可以是通过其他的方式导入的,本发明实施例对此不作限定。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的安全的唯一设备标识SUDI;
该网络设备接收该Registrar设备根据该设备标识发送的域证书,包括:
该网络设备接收该Registrar设备根据该SUDI发送的域证书,该域证书是该Registrar设备确定该SUDI对应的设备数字证书有效时,以及根据验证服务器的验证结果确定该网络设备被允许加入自组织域时,确定该网络设备允许加入自组织域,根据该设备标识为该网络设备分配的。
具体地,例如,当该设备标识为安全的唯一设备标识SUDI时,该网络设备向该Registrar设备发送与该SUDI相对应的设备数字证书;
该Registrar设备在验证该设备数字证书有效,以及根据验证服务器的验证结果确定该网络设备被允许加入自组织域时,根据SUDI,为该网络设备分配域证书。
为了便于描述和理解,在下文示例中,以设备标识为UDI为例进行描述。
应理解,自组织网络中的设备的自组织特性使能之后,会持续周期性(例如每隔10s)地发送AD消息,以确定自己的邻居设备,该AD消息包括该自组织设备的UDI,可选地,在该自组织设备具备域证书的情况下,该AD消息中也可以携带其域证书。每个设备根据接收到AD消息,构建自己的邻 居列表。
应理解,当设备A接收到一个AD消息,当确定该AD消息中携带的目的MAC地址(例如MAC广播地址)与本设备的MAC地址匹配,则可知该AD消息的源发送设备为自己的邻居设备,将该AD消息中携带的UDI和源MAC地址更新到自己的邻居列表中。
可选地,在本发明实施例中,该方法100还包括:
S160,该网络设备接收来自于该网络设备的邻居设备的基于数据链路层的帧封装后的AD消息,该AD消息包括邻居节点的设备标识与MAC地址;
应理解,来自于该网络设备的邻居设备的该基于数据链路层的帧封装后的AD消息的格式也如上述表3所示。
S170,该网络设备根据该AD消息,建立该网络设备的邻居列表,该邻居列表包括该邻居设备的设备标识以及该邻居设备的数据链路层地址。
具体地,该邻居列表除了包括该邻居设备的设备标识以及该邻居设备的数据链路层地址(MAC地址)之外,该邻居列表还可以包括邻居设备的安全认证信息,具体地,如表4所示:
表4
Figure PCTCN2015084772-appb-000003
如表4所示,一个设备的邻居列表包括邻居设备的UDI、MAC地址,以及安全信息和认证信息,其中,安全认证信息(Trust information)可以包括安全认证类型信息,认证时间等信息,例如,the certificate chain,if available;安全认证验证信息(Validity of the trust)用于指示邻居设备是否通过Registrar设备的认证,即是否分配了域证书。
具体地,图2示出了自组织网络的示意图,示意性地给出了11个自组织设备,其中,假设设备1为Registrar设备,设备2、3和4为设备1的邻居设备,设备5和6为设备2的邻居设备,设备7和8为设备6的邻居设备,设备7也是设备5的邻居设备,设备9和10为设备3的邻居设备,设备11为设备4的邻居设备。例如,设备2向Registrar设备发送包括设备2的UDI 的AD消息(对应于本发明实施例中网络设备为Registrar设备的邻居设备的情形),Registrar设备在白名单里找到设备2的UDI的匹配项,则为设备2分配域证书。然后Registrar设备与设备2基于各自的域证书,相互认证,创建安全的连接,即在设备1和设备2之间建立了ACP。
上面例子中,Registrar设备为设备2分配了域证书,并与之建立了安全连接,即设备2得到认证,这时,该设备2可以作为代理(Proxy)点或认证点,将自己邻居设备的AD消息转发给Registrar设备,以便于Registrar设备认证设备2的邻居设备。
具体地,例如设备2的邻居设备5还未得到域证书,当设备2接收到设备5发的AD消息后,设备2通过解析该AD消息,检测到设备5没有域证书,设备2基于此可以确定设备5还没有得到认证,就会触发将设备5的AD消息转发出去的流程,因为设备2已经与Registrar设备建立了安全连接,所以设备2是已知Registrar设备的UDI的,所以设备2可以基于Registrar设备的UDI,将设备5的AD消息转发给Registrar设备,后续Registrar设备对设备5的认证以及分配域证书的过程与为设备2分配域证书的流程类似,这里不再赘述。应理解,Registrar为设备5分配了域证书后,也是通过设备2转发给设备5的。
需要说明的是,在本实施例中,在设备5分配到域证书之前,设备5的AD消息中没有域证书,这时,设备2根据设备5的AD消息建立的邻居列表中,设备5对应的Validity of the trust条目是未通过认证的。后续当设备5获取域证书后发送的AD消息中会携带域证书。
应理解,对于任一个经过Registrar设备认证之后的代理(Proxy)点或认证点,当其确定自己的某个邻居设备的Validity of the trust条目是未通过认证的,就会将该邻居设备的AD消息转发至Registrar设备,以便于Registrar设备对该邻居设备进行认证。
还应理解,在图2所示的例子中,与设备2和设备5认证过程类似,图2所示的其他自组织设备的AD消息都会传输至Registrar设备进行认证,假设Registrar设备为图2所示的所有设备都分配了域证书,即图2所示的各个设备之间均建立起安全连接,即这11个设备之间建立了自组织控制平面ACP。
应理解,上文为了便于理解和描述,以图2为例描述了设备之间建立 ACP的过程,图2仅为示例而非限定。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
上文结合图1和图2,从AD消息的发送端设备的角度描述了本发明实施例提供的基于数据链路层的通信方法,下文从AD消息的接收端设备的角度描述本发明实施例提供的基于数据链路层的通信方法。
图3示出了本发明实施例提供的基于数据链路层的通信方法200的示意性流程图,该方法例如可以由自组织网络中支持分配域证书的登记Registrar设备来执行,该方法200包括:
S210,Registrar设备接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,该AD消息包括该网络设备的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配;
应理解,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配指的是,该目的数据链路层地址就是为该Registrar设备的数据链路层地址,或者该目的数据链路层地址为广播数据链路层地址,应理解,可以认为广播数据链路层地址与任意固定的数据链路层地址相匹配。
S220,当该Registrar设备确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书;
S230,该Registrar设备根据该域证书,与该网络设备建立自组织控制平面ACP。
具体地,该网络设备与该Registrar设备基于网络设备的域证书以及Registrar设备的域证书(Registrar设备会首先给自己分配域证书),相互认证,在数据链路层建立安全连接,例如建立MACsec通路,这个过程可称之 为在网络设备与Registrar设备之间建立自组织控制平面ACP。
在本发明实施例中,设备的邻接发现AD消息是基于数据链路层的帧封装的;该AD消息基于数据链路层地址,发送至自组织网络中分配域证书的Registrar设备;该Registrar设备根据该AD消息为该设备分配域证书;基于该域证书,该设备与Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
应理解,在本发明实施例中,基于数据链路层的帧封装邻接发现(Adjacency Discovery,简称为“AD”)消息。应理解,在本发明实施例中,生成AD消息后,直接基于数据链路层的帧封装该AD消息,并不基于IP的报文封装该AD消息。换句话说,在本发明实施例中,AD消息直接封装在数据链路层的帧中,不再基于IP报文封装。因此,本发明实施例中的AD消息对IP协议或者IP地址可以不感知,从而,自组织控制平面ACP的实现可以不依赖于IP协议,例如IPv6或IPv4。因此,在本发明实施例中,基于数据链路层实现ACP,相比于现有技术具有较好的网络兼容性,也降低了自组织网络部署的难度。
在本发明实施例中,可选地,该数据链路层地址为介质访问控制(Media Access Control,简称为“MAC”)地址。
下文的示例中均以数据链路层地址为MAC地址为例进行描述。
还应理解,该数据链路层的帧的目的数据链路层地址为数据链路层广播地址或该网络设备的邻居设备的数据链路层地址,该Registrar设备可以是该网络设备的邻居设备,也可以是非邻居设备,本发明实施例对此不作限定。
可选地,在本发明实施例中,该网络设备的邻居设备包括该Registrar设备;
其中,该数据链路层的帧的目的MAC地址为该Registrar设备的MAC地址或MAC广播地址。
具体地,该网络设备根据该目的MAC地址,直接向该Registrar设备发送基于数据链路层的帧封装后的该AD消息,换句话说,该AD消息是从网络设备一跳发送到该Registrar设备的,无需中间设备的转发。这种情形也可称之为,该AD消息以邻居单播的方式,从网络设备传输至Registrar设备。
可选地,在本发明实施例中,该Registrar设备不是该网络设备的邻居设备;
其中,该数据链路层的帧的目的MAC地址为MAC广播地址;
S210,Registrar设备来自于网络设备的基于数据链路层的帧封装后的邻接发现AD消息,包括:
Registrar设备通过具备由该Registrar设备分配的域证书的Proxy设备,接收该网络设备的邻接发现AD消息。
具体地,如图2所示的自组织网络的示意图,其中,假设设备1为Registrar设备,设备2、3和4为设备1的邻居设备,设备5和6为设备2的邻居设备,设备7和8为设备6的邻居设备,设备7也是设备5的邻居设备,设备9和10为设备3的邻居设备,设备11为设备4的邻居设备。例如,设备2向Registrar设备发送包括设备2的UDI的AD消息(对应于本发明实施例中网络设备为Registrar设备的邻居设备的情形),Registrar设备在白名单里找到设备2的UDI的匹配项,则为设备2分配域证书。然后Registrar设备与设备2基于各自的域证书,相互认证,创建安全的连接,即在设备1和设备2之间建立了ACP。
上面例子中,Registrar设备为设备2分配了域证书,并与之建立了安全连接,即设备2得到认证,这时,该设备2可以作为代理(Proxy)点或认证点,将自己邻居设备的AD消息转发给Registrar设备,以便于Registrar设备认证设备2的邻居设备。
具体地,例如设备2的邻居设备5还未得到域证书,当设备2接收到设备5发的AD消息后,设备2通过解析该AD消息,检测到设备5没有域证书,设备2基于此可以确定设备5还没有得到认证,就会触发将设备5的AD消息转发出去的流程,因为设备2已经与Registrar设备建立了安全连接,所以设备2是已知Registrar设备的UDI的,所以设备2可以基于Registrar设备的UDI,将设备5的AD消息转发给Registrar设备,后续Registrar设备对设备5的认证以及分配域证书的过程与为设备2分配域证书的流程类似,这里不再赘述。应理解,Registrar为设备5分配了域证书后,也是通过设备2转发给设备5的。
需要说明的是,在本实施例中,在设备5分配到域证书之前,设备5的AD消息中没有域证书,这时,设备2根据设备5的AD消息建立的邻居列 表中,设备5对应的Validity of the trust条目是未通过认证的。后续当设备5获取域证书后发送的AD消息中会携带域证书。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
具体地,本发明实施例中的L2 ACP报文用于指示基于数据链路层的在ACP上传输的报文。应理解,基于数据链路层的帧封装该AD消息,即该数据链路层的帧的数据载荷字段承载该AD消息,其中,该数据链路层的帧的Type字段指示该数据载荷字段承载的消息为L2 ACP报文,可以认为L2 ACP报文包括该AD消息。
具体地,例如该数据链路层的帧的类型Type字段的Type值为0x88e7。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
具体地,该AD消息的报文头包括用于指示该L2 ACP报文为该AD消息的标志位字段。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
基于数据链路层的帧封装之后的AD消息的格式如表3所示,具体描述见上文描述,为了简洁这里不再赘述。
可选地,在本发明实施例中,该网络设备为该Registrar设备的邻居设备,该方法200还包括:
S240,该Registrar设备根据该AD消息,建立该Registrar设备的邻居列表,该邻居列表包括该网络设备的设备标识以及该网络设备的数据链路层地址。
具体地,该Registrar设备根据该AD消息建立的邻居列表如表4所示,详述见上文。
在S220中,该Registrar设备当确定该邻居设备允许加入自组织域时,根据该设备标识为该邻居设备分配域证书,并发送给该网络设备。
可选地,在本发明实施例中,该设备标识为唯一设备标识(Unique Device Identification,简称为“UDI”)或者安全的唯一设备标识(Safe Unique Device Identification,简称为“SUDI”)。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的唯一设备标识UDI,
其中,S220当该Registrar设备确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书,包括:
S221,当该Registrar设备确定白名单具有该网络设备的UDI的匹配项时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该UDI分配的该域证书,该白名单包括允许加入该自组织网络的设备的UDI。
具体地,例如,当该设备标识为UDI时,该Registrar设备通过白名单来判断该网络设备是否允许加入自组织域,该白名单记载了允许加入该自组织域的设备的UDI,当Registrar设备在白名单内找到该网络设备的UDI的匹配项时,例如通过数字证书认证管理结构,基于该网络设备的UDI,为该网络设备分配域证书;如果Registrar网络设备在白名单内找不到该网络设备的UDI的匹配项,则确定该网络设备不允许加入自组织域。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的安全的唯一设备标识S-UDI,
其中,S220当该Registrar设备确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书,包括:
S222,当该Registrar设备通过验证服务器确定该S-UDI对应的设备数字证书有效时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该设备数字证书分配的该域证书。
具体地,例如,当该设备标识为安全的唯一设备标识SUDI时,该网络设备向该Registrar设备发送与该SUDI相对应的设备数字证书;
该Registrar设备在验证该设备数字证书有效,以及根据验证服务器的验证结果确定该网络设备被允许加入自组织域时,根据SUDI,为该网络设备分配域证书。
在本发明实施例中,设备的邻接发现AD消息是基于数据链路层的帧封装的;该AD消息基于数据链路层地址,发送至自组织网络中分配域证书的Registrar设备;该Registrar设备根据该AD消息为该设备分配域证书;基于该域证书,该设备与Registrar设备建立自组织控制平面ACP。因此,在本 发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
应理解,自组织设备之间建立了ACP之后,上层的自组织功能实体可以使用该ACP平面传输控制消息,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
图4示出了本发明实施例提供的基于数据链路层的通信方法300的示意性流程图,该通信方法应用于自组织网络,该自组织网络的自组织控制平面ACP基于数据链路层建立,该方法300包括:
S310,第一网络设备生成数据链路层自组织控制平面L2 ACP报文,该第一网络设备为该自组织网络中的自组织设备;
具体地,第一网络设备从上层的自组织功能实体接收通信任务,例如该通信任务指示从第一网络设备向ACP内的目标设备发送控制消息,或者,指示该第一网络设备在ACP内广播控制消息等,第一网络设备根据该通信任务,生成该L2 ACP报文,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
S320,该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址;
应理解,该数据链路层的帧的目的数据链路层地址为该第一网络设备的邻居设备的数据链路层地址,或者为广播数据链路层地址。
S330,该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,该第二网络设备也为该自组织网络中的自组织设备,且该第二网络设备为该第一网络设备的邻居设备。
在本发明实施例中,基于数据链路层的帧封装该L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,网络设备可以无需像现有技术中一样维护路由表。
应理解,本发明实施例中的自组织控制平面ACP是基于数据链路层建立的,具体建立过程,详见上文方法100和方法200的描述,这里不再赘述。
还应理解,在本发明实施例中,L2 ACP报文基于L2的帧封装,不再基于网络层的IP报文封装。换句话说,在本发明实施例中,可以利用数据链路层上的转发表资源(例如MAC转发表)来实现L2 ACP报文的传输,而无需依赖于网络层的IP协议或者IP路由表。
还应理解,在本发明实施例中,该L2的MAC转发表资源可以为每个设备所具有的邻居列表,例如,设备A的邻居列表中包括该设备A的邻居设备的设备标识与MAC地址,所以,当设备A需要发送L2 ACP报文时,基于邻居列表中包括的邻居设备(一个或多个)的MAC地址,确定该L2 ACP报文的目的MAC地址,从而将该L2 ACP报文发送到对应的邻居设备。或者是,将该L2 ACP报文的目的MAC地址设置为MAC广播地址,然后通过设备A与邻居设备的接口将该MAC报文发送出去。应理解,MAC广播地址与任意的MAC地址都认为是相匹配的,所以设备A的邻居设备都能接收到该L2 ACP报文。
综上所述,在本发明实施例中,在ACP上传输信令,无需像现有技术中依赖于IP协议或者IP路由表来实现,可以不感知IP协议或IP地址,相比于现有技术,具有较好的网络兼容性。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制(Media Access Control,简称为“MAC”)地址。
下文的示例中均以数据链路层地址为MAC地址为例进行描述。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
具体地,例如该数据链路层的帧的类型Type字段的Type值为0x88e7。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
具体地,表5示意性地给出了根据本发明实施例提供的L2 ACP报文的格式:
表5
Figure PCTCN2015084772-appb-000004
从表5可知,该L2 ACP报文包括报文头和报文内容。其中,L2 ACP报文的报文内容,例如,包括上层自组织功能实体下发的通信任务中指示的控制消息,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。L2 ACP报文的报文头具体可以如表6所示:
表6
Figure PCTCN2015084772-appb-000005
具体地,该L2 ACP报文的报文头包括版本字段、标志位字段、协议字段和数据包长度字段,以及源UDI和目的UDI,其中源UDI为该第一网络设备的UDI,目的UDI为目标设备的UDI或者广播UDI。应理解,当L2 ACP报文为广播报文时,该L2 ACP报文中的目的UDI可以为空。版本字段的值指示的该L2 ACP报文对应的协议的版本,例如该版本字段共4位;该标志位字段为4位,用于指示该L2 ACP报文为邻居单播报文或非邻居单播报文或者广播报文,例如该标志位字段的值为0001;协议字段的值用于指示该数据链路层的帧的数据载荷字段携带的内容的协议,协议字段共8位,例如可以使用与IP协议对应的协议字段的取值;数据包长度字段指共16位,其值用于指示整个数据包的长度。
基于数据链路层的帧封装之后的L2 ACP报文的格式如表7所示:
表7
Figure PCTCN2015084772-appb-000006
由表7可知,该数据链路层的帧的帧头包括目的MAC地址、源MAC地址和类型Type字段,其中目的MAC地址可以为MAC广播地址或者是为 目标设备的MAC地址;源MAC地址为第一网络设备的MAC地址。类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文,具体地,该Type字段可申请赋值为0x88e7。
应理解,数据链路层上的设备接收到基于该数据链路层的封装的L2 ACP报文,通过其Type值能够识别出该L2 ACP报文为用于在ACP传输的报文。
应理解,表5、表6和表7仅作为L2 ACP报文的示例而非限定。
应理解,在本发明实施例中,数据链路层的设备均可识别该L2 ACP报文,即L2 ACP报文可以在数据链路层有效传输、有效接收。例如,设备2接收到设备5发送的基于数据链路层的帧封装的L2 ACP报文后,基于数据链路层的帧进行解码获得该L2 ACP报文,进一步处理该L2 ACP报文,例如解析L2 ACP报文中的控制消息,或者不处理转发出去等,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
可选地,在本发明实施例中,S310该第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
S311,该第一网络设备需要与该自组织网络中的目标设备通信时,当确定该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,该第一网络设备的邻居列表包括该第一网络设备的邻居设备的设备标识与数据链路层地址;
具体地,例如第一网络设备从上层的自组织功能实体接收到的通信任务,该通信任务指示该第一网络设备向ACP内的目标设备发送控制消息,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。应理解,第一网络设备可以从上层自组织功能实体获取到该目标设备的设备标识与MAC地址。
应理解,该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项指的是,该第一网络设备的邻居列表包括与该目标设备的设备标识相同的设备标识。还应理解,当该目标设备的设备标识为广播设备标识时,也可认为该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项。如果该第一网络设备的邻居列表不包括与该目标设备的设备标识相同的设备 标识、且该目标设备的设备标识也不是广播设备标识时,则认为该第一网络设备的邻居列表不包括该目标设备的设备标识的匹配项。
S320该第一网络设备基于数据链路层的帧封装该L2 ACP报文,包括:
S321,该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
S330该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,包括:
S331,该第一网络设备根据该目标设备的数据链路层地址,向该目标设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
具体地,该第一网络设备确定邻居列表中包括该目标设备的UDI的匹配项,则确定该L2 ACP报文的目的设备为自己的邻居设备,则生成该L2 ACP报文,该L2 ACP报文的报文头中包括用于指示邻居单播的标志位字段。
具体地,还以图2所示为例,例如上层自组织网络功能实体下发的传输任务一为从设备5向设备2(设备5的邻居设备)传输目标信令,该传输任务一中携带设备5的UDI。设备5根据传输任务一,确定L2 ACP报文,该L2 ACP报文包括该目标信令和目的UDI,该目的UDI为该设备2的UDI,并基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的MAC地址为该设备2的MAC地址,且该L2 ACP报文的报文头中的标志位字段用于指示邻居单播。
具体地,在本发明实施例中,L2 ACP报文的格式如表5所示;L2 ACP报文的报文头如表6所示,其中目的UDI为该目标设备的UDI,其中标志位字段的值用于指示该L2 ACP报文为邻居单播报文,即用于指示该L2 ACP报文的接收设备不再向其他设备转发基于该数据链路层的帧封装后的该L2 ACP报文,该标志位字段的值例如为0001。基于数据链路层的帧封装后的该L2 ACP报文的格式如表7所示,其中目的MAC地址为该目标设备的MAC地址。
在本发明实施例中,当确定目标设备为第一网络设备的邻居设备时,生成L2 ACP报文,且该L2 ACP报文包括用于指示该L2 ACP报文为邻居单播报文的标志位,然后基于数据链路层的帧封装该L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。在本发明实施例中,在ACP上传输报文可以不依赖于IP协 议,相比于现有技术,具有较好的网络兼容性。此外,本发明实施例提供的方案也可以应用于部分设备配置为IPv6,部分设备配置为IPv4的网络中。
此外,在本发明实施例中,网络设备无需维护路由表,就能实现L2 ACP报文的传输。
可选地,在本发明实施例中,S310该第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
S312,该第一网络设备需要与该自组织网络中的目标设备通信时,当确定该邻居列表中不包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文;
S320,该第一网络设备基于数据链路层的帧封装该L2 ACP报文,包括:
S322,该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
S330,该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,包括:
S332,该第一网络设备根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
具体地,L2 ACP报文的格式如表5所示;L2 ACP报文的报文头如表6所示,其中目的UDI为该目标设备的UDI,其中标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,即用于指示当该L2 ACP报文的接收设备的设备标识与该目的设备标识不匹配时,继续向该接收设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文;当该L2 ACP报文的接收设备的设备标识与该目的设备标相匹配时,解析该L2 ACP报文,不再转发。该标志位字段的值例如为0002。基于数据链路层的帧封装之后的L2 ACP报文的格式如表7所示,其中,数据链路层的帧的目的MAC地址为MAC广播地址。
具体地,以图2为例,例如上层网络功能实体下发的传输任务为从设备7向设备2(不是设备7的邻居设备)传输信令。则设备7向邻居设备5和6分别发送。基于数据链路层的帧封装之后L2 ACP报文。基于数据链路层的帧封装之后L2 ACP报文如表7所示,其中,报文内容中包括实际要传输的信令内容,源UDI即为设备7的UDI,目的UDI为设备2的UDI,标志位 是用于指示该报文为非邻居单播消息的标识。
对应地,设备5接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2;类似的,设备6接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2和8;当设备2接收到该L2 ACP报文后,通过解析,确定该报文为非邻居单播消息,然后检测目的UDI与自己的UDI匹配,则解析该L2 ACP报文的内容。
本发明实施例中描述的当上层的传输需求中指明的目的UDI不在设备的邻居列表中时,在设备之间传输信令的方法也可称之为采用泛洪的方式发送。
在本发明实施例中,当确定目标设备不是第一网络设备的邻居设备时,生成L2 ACP报文,且该L2 ACP报文包括用于指示该L2 ACP报文为非邻居单播报文的标志位,然后基于数据链路层的帧封装该L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。此外,本发明实施例提供的方案也可以应用于部分设备配置为IPv6,部分设备配置为IPv4的网络中。
此外,在本发明实施例中,网络设备无需维护路由表,就能实现L2 ACP报文的传输。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括用于唯一指示该L2 ACP报文的报文ID。
具体地,该L2 ACP报文的报文头如表8所示:
表8
Figure PCTCN2015084772-appb-000007
具体地,报文ID是该L2 ACP报文的生成设备上的唯一的字符串。报文ID是用于接收设备检测自己是否已经接收过相同的报文。具体,例如上 述例子中,设备6接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2和8,则设备2会从自己的邻居设备5和6重复收到源自设备7的L2 ACP报文,L2 ACP报文中包括报文ID就可以避免设备2重复处理相同的L2 ACP报文,例如当设备2首先接收到邻居设备5发送的L2 ACP报文,设备2在解析该L2 ACP报文后,缓存该L2 ACP报文,自然也保存了该L2 ACP报文的报文ID。当设备2接收到设备6发送的源自设备7的L2 ACP报文时,解析该L2 ACP报文,检测到自己已经接收过该L2 ACP报文,就可以对该L2 ACP报文作丢弃操作。
在本发明实施例中,在L2 ACP报文包括报文ID,能够避免重复的信令转发。
应理解,表8中的版本字段、标志位字段、协议字段、数据包长度字段、源UDI与目的UDI的描述与上文结合表6的描述一致,这里不再赘述。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
具体地,该L2 ACP报文的报文头如表8所示,有一个定时信息的字段,其值用于指示预设时间,用于指示该L2 ACP报文的接收设备在缓存该L2ACP报文的时间超过预设时长时,清除该L2 ACP报文。
具体地,该定时信息例如为一个定时器,具体的时间值可以根据业务需求或者具体情况预配置,例如设备5接收到来自设备7的L2 ACP报文,并缓存该L2 ACP报文,缓存的时常超过阈值之后,可以认为该L2 ACP报文已经传输到目的UDI对应的设备了,即该L2 ACP报文的传输结束了,就可以删除该L2 ACP报文了。可选的,该定时信息也可以是一个时间戳。
在本发明实施例中,在L2 ACP报文包括定时信息,能够实现设备及时地清除已经传输完毕的L2 ACP报文,能够避免设备长时间缓存无用L2 ACP报文。
可选地,在本发明实施例中,S310该第一网络设备生成L2 ACP报文,包括:
S313,当该第一网络设备需要在该ACP内广播控制消息时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用 于指示该L2 ACP报文为广播报文;
S320,该第一网络设备基于数据链路层的帧封装该L2 ACP报文,包括:
S323,该第一网络设备基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,S330该第一网络设备根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,包括:
S333,该第一网络设备根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
具体地,L2 ACP报文的格式如表5所示,L2 ACP报文的报文头如表6所示,其中标志位字段的值用于指示该L2 ACP报文为广播报文,即用于指示该L2 ACP报文的接收设备解析该L2 ACP报文,并向该接收设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文,例如,该标志位字段的值例如为0003。
具体地,例如第一网络设备从上层的自组织功能实体接收到的通信任务,该通信任务指示该第一网络设备在ACP内广播控制消息,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。还以图2为例,例如上层网络功能实体下发的任务是从设备6广播L2 ACP报文。设备6生成的L2 ACP报文如表5和表6所示,该L2 ACP报文的报文头的标志位字段的值用于指示广播报文;基于数据链路层的帧封装该L2 ACP报文,其中,数据链路层的帧的目的MAC地址为MAC广播地址。设备6的邻居设备接收到该L2 ACP报文,通过解析确定该L2 ACP报文为广播报文,继续转发给自己的邻居设备2、7和8和7,类似的,设备2、7和8继续向自己的邻居设备转发该L2 ACP报文。
应理解,当L2 ACP报文为广播报文时,其报文头中的目的UDI可以为广播UDI,或者该目的UDI为空。
在本发明实施例中,当需要广播控制消息时,生成L2 ACP报文,且该L2 ACP报文包括用于指示该L2 ACP报文为广播报文的标志位,然后基于数据链路层的帧封装该L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。此外,本发明实施例提供的方案也可以应用于部分设备 配置为IPv6,部分设备配置为IPv4的网络中。
此外,在本发明实施例中,网络设备无需维护路由表,就能实现L2 ACP报文的传输。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括用于唯一指示该L2 ACP报文的报文ID。
具体地,该L2 ACP报文的报文头如表8所示。
具体地,报文ID是该L2 ACP报文的生成设备上的唯一的字符串。报文ID是用于接收设备检测自己是否已经接收过相同的报文。具体,例如上述例子中,设备6接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2和8,则设备2会从自己的邻居设备5和6重复收到源自设备7的L2 ACP报文,L2 ACP报文中包括报文ID就可以避免设备2重复处理相同的L2 ACP报文,例如当设备2首先接收到邻居设备5发送的L2 ACP报文,设备2在解析该L2 ACP报文后,缓存该L2 ACP报文,自然也保存了该L2 ACP报文的报文ID。当设备2接收到设备6发送的源自设备7的L2 ACP报文时,解析该L2 ACP报文,检测到自己已经接收过该L2 ACP报文,就可以对该L2 ACP报文作丢弃操作。
在本发明实施例中,在L2 ACP报文包括报文ID,能够避免重复的信令转发。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
具体地,该L2 ACP报文的报文头如表8所示,有一个定时信息的字段,其值用于指示预设时间,用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
具体地,该定时信息例如为一个定时器,具体的时间值可以根据业务需求或者具体情况预配置,例如设备5接收到来自设备7的L2 ACP报文,并缓存该L2 ACP报文,缓存的时常超过阈值之后,可以认为该L2 ACP报文已经传输到目的UDI对应的设备了,即该L2 ACP报文的传输结束了,就可以删除该L2 ACP报文了。可选的,该定时信息也可以是一个时间戳。
在本发明实施例中,在L2 ACP报文包括定时信息,能够实现设备及时 地清除已经传输完毕的L2 ACP报文,能够避免设备长时间缓存无用L2 ACP报文。
应理解,在本发明实施例中,数据链路层的设备均可识别该L2 ACP报文,即L2 ACP报文可以在数据链路层有效传输、有效接收。例如,设备2接收到设备5发送的基于数据链路层的帧封装后的L2 ACP报文后,基于数据链路层的帧进行解码获取到该L2 ACP报文,匹配该L2 ACP报文中的目的UDI与设备2的UDI,匹配成功后,解析获取该L2 ACP报文中目标信令。
应理解,本发明实施例中L2 ACP报文的报文格式、以及封装该L2 ACP报文的数据链路层的帧的帧格式均是数据链路层的收发端设备都公知的,即数据链路层的设备都能够识别L2 ACP报文。
在本发明实施例中,基于数据链路层的帧封装L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
进一步地,在本发明实施例中,基于目标设备的设备标识(例如UDI)和网络设备的邻居列表,在网络设备之间传输L2 ACP报文,而非依赖于loopback地址,从而避免了网络设备需要维护路由表。每个网络设备都具有自己的UDI和邻居列表,直接利用现成的资源去实现信令传输,能够降低维护成本。
此外,本发明实施例中的自组织网络以及自组织网络中的报文传输均可以不感知IP协议,因此并不苛求网络设备统一支持IPv6或者IPv4,从而相对于现有技术,具有更好的网络兼容性,而且也降低了自组织网络部署的难度。
可选地,在本发明实施例中,自组织网络中的每个网络设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,
其中,S310该第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
S314,当该第一网络设备需要通过IP会话与该ACP内的目标设备通信时,生成该L2 ACP报文,该L2 ACP报文还包括目的IP地址,该目的IP地址为该目标设备的IP地址。
具体地,该L2 ACP报文的格式如表5和表6所示,其中L2 ACP报文的报文头中的协议字段的值可以采用IP报文中的协议字段的值。
具体地,例如,某些上层业务,例如远端用户拨入验证服务(Remote Authentication Dial In User Service,简称为“RADIUS”),严格要求基于IP,或者TCP/UDP来传输信令。
在本发明实施例中,ACP内的每个自组织设备支持无重复的自配置的环回(Loopback)地址;且ACP内的每个自组织设备支持UDI和IP的映射(包括自己的和对端设备的)。
具体地,例如,上层的自组织代理(Agent)的传输需求中指明需要建立IP会话,则相关的服务设备(如AAA)需要向客户设备发送自己的服务器IP地址和自己的UDI,此阶段被称为服务自发现,或者service advertisement。
客户设备接收到服务设备发送的消息后,绑定该IP地址,UDI,以及相关服务,并且通过一个自配置的IPv6 ULA loopback地址,或者IPv4 loopback地址,向服务器发起IP会话。
服务器的UDI层收到相关报文后,绑定该客户设备的IP和UDI。
后续,在服务器和客户端的ACP通信中,服务端/客户端封装了IP包后,查找IP和UDI映射表,在ACP平面内基于UDI进行转发。
在本发明实施例涉及的场景下,虽然在上层设备应用看来它们之间在ACP平面内发起了一次IP会话,但是ACP平面仍然不提供基于IP的转发,网络设备无需维护相关的路由表。
因此,本发明实施例提供的ACP能够提供基于IP的通信能力,从而能够为上层应用提供更好的兼容性,让它们尽量无感知的使用基于L2层的ACP。
在本发明实施例中,基于数据链路层的帧封装L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
进一步地,在本发明实施例中,基于目标设备的设备标识(例如UDI)和网络设备的邻居列表,在网络设备之间传输L2 ACP报文,而非依赖于loopback地址,从而避免了网络设备需要维护路由表。每个网络设备都具有 自己的UDI和邻居列表,直接利用现成的资源去实现信令传输,能够降低维护成本。
此外,本发明实施例中的自组织网络以及自组织网络中的报文传输均可以不感知IP协议,因此并不苛求网络设备统一支持IPv6或者IPv4,从而相对于现有技术,具有更好的网络兼容性,而且也降低了自组织网络部署的难度。
图5示出了本发明实施例提供的基于数据链路层的通信方法400的示意性流程图,该自组织网络的自组织控制平面ACP基于数据链路层建立,该自组织网络内的每个自组织设备均具有邻居列表,该邻居列表包括该每个自组织设备的邻居设备的设备标识与数据链路层地址,该方法400包括:
S410,第二网络设备接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,该L2 ACP报文包括目的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配,该第二网络设备与该第一网络设备均为该自组织网络中的自组织设备;
应理解,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配指的是,该目的数据链路层地址直接为该第二网络设备的数据链路层地址,或者,该目的数据链路层地址为广播数据链路层地址,应理解,广播数据链路层地址可以为认为任意固定的数据链路层地址相匹配。
S420,该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文。
应理解,当该目的设备标识直接就是该第二网络设备的设备标识时,或者该目的设备标识为广播设备标识时,则可认为该目的设备标识与该第二网络设备的设备标识相匹配,否则不匹配。
本发明实施例中的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。此外,在本发明实施例中,网络设备可以无需像现有技术中一样维护路由表。
应理解,本发明实施例中的自组织控制平面ACP是基于数据链路层建 立的,具体建立过程,详见上文方法100和方法200的描述,这里不再赘述。
还应理解,在本发明实施例中,L2 ACP报文基于L2的帧封装,不再基于网络层的IP报文封装。换句话说,在本发明实施例中,可以利用数据链路层上的转发表资源(例如MAC转发表)来实现L2 ACP报文的传输,而无需依赖于网络层的IP协议或者IP路由表。
还应理解,在本发明实施例中,该L2的MAC转发表资源可以为每个设备所具有的邻居列表,例如,设备A的邻居列表中包括该设备A的邻居设备的设备标识与MAC地址,所以,当设备A需要发送L2 ACP报文时,基于邻居列表中包括的邻居设备(一个或多个)的MAC地址,确定该L2 ACP报文的目的MAC地址,从而将该L2 ACP报文发送到对应的邻居设备。或者是,将该L2 ACP报文的目的MAC地址设置为MAC广播地址,然后通过设备A与邻居设备的接口将该MAC报文发送出去。应理解,MAC广播地址与任意的MAC地址都认为是相匹配的,所以设备A的邻居设备都能接收到该L2 ACP报文。
综上所述,在本发明实施例中,在ACP上传输信令,无需像现有技术中依赖于IP协议或者IP路由表来实现,可以不感知IP协议或IP地址,相比于现有技术,具有较好的网络兼容性。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制(Media Access Control,简称为“MAC”)地址。
下文的示例中均以数据链路层地址为MAC地址为例进行描述。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
具体地,例如该数据链路层的帧的类型Type字段的Type值为0x88e7。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
具体地,该L2 ACP报文如表5所示,该L2 ACP报文的报文头如表6所示,基于数据链路层的帧封装后的该L2 ACP报文如表7所示。具体描述见上文相关内容,这里不再赘述。
应理解,在本发明实施例中,数据链路层的设备均可识别该L2 ACP报文,即L2 ACP报文可以在数据链路层有效传输、有效接收。例如,设备2接收到设备5发送的基于数据链路层的帧封装的L2 ACP报文后,基于数据链路层的帧进行解码获得该L2 ACP报文,进一步处理该L2 ACP报文,例如解析L2 ACP报文中的控制消息,具体地,该控制消息可以为实现控制和/或管理功能的控制信令,或者不处理转发出去等。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
其中,S420该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
S421,该第二网络设备确定该目的设备标识为该第二网络设备的设备标识,并解析该L2 ACP报文。
具体地,通过解析该L2 ACP报文,获取该L2 ACP报文中的报文内容,例如控制消息等,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。应理解,在本发明实施例中,该L2 ACP报文的接收设备不再向其邻居设备转发该L2 ACP报文。
具体地,在本发明实施例中,L2 ACP报文的格式如表5所示;L2 ACP报文的报文头如表6所示,其中目的UDI为该目标设备的UDI,其中标志位字段的值用于指示该L2 ACP报文为邻居单播报文,即用于指示该L2 ACP报文的接收设备不再向其他设备转发基于该数据链路层的帧封装后的该L2 ACP报文,该标志位字段的值例如为0001。基于数据链路层的帧封装后的该L2 ACP报文的格式如表7所示,其中目的MAC地址为该目标设备的MAC地址。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,S420该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
S422,当该第二网络设备确定该第二网络设备的设备标识与该目的设备标识相匹配时,解析该L2 ACP报文,并缓存该L2 ACP报文;
具体地,通过解析该L2 ACP报文,获取该L2 ACP报文中的报文内容,例如控制消息等,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
S423,当该第二网络设备确定该第二网络设备的设备标识与该目的设备标识不匹配时,缓存该L2 ACP报文,并根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
具体地,L2 ACP报文的格式如表5所示;L2 ACP报文的报文头如表6所示,其中目的UDI为该目标设备的UDI,其中标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,即用于指示当该L2 ACP报文的接收设备的设备标识与该目的设备标识不匹配时,继续向该接收设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文;当该L2 ACP报文的接收设备的设备标识与该目的设备标相匹配时,解析该L2 ACP报文,不再转发。该标志位字段的值例如为0002。基于数据链路层的帧封装之后的L2 ACP报文的格式如表7所示,其中,数据链路层的帧的目的MAC地址为MAC广播地址。
具体地,以图2为例,例如上层网络功能实体下发的传输任务为从设备7向设备2(不是设备7的邻居设备)传输信令。则设备7向邻居设备5和6分别发送。基于数据链路层的帧封装之后L2 ACP报文。基于数据链路层的帧封装之后L2 ACP报文如表7所示,其中,报文内容中包括实际要传输的信令内容,源UDI即为设备7的UDI,目的UDI为设备2的UDI,标志位是用于指示该报文为非邻居单播消息的标识。
对应地,设备5接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2;类似的,设备6接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2和8;当设备2接收到该L2 ACP报文后,通过解析,确定该报文为非邻居单播消息,然后检测目的UDI与自己的UDI匹配,则解析该L2 ACP报文的内容。
本发明实施例中描述的当上层的传输需求中指明的目的UDI不在设备的邻居列表中时,在设备之间传输信令的方法也可称之为采用泛洪的方式发 送。
在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。此外,本发明实施例提供的方案也可以应用于部分设备配置为IPv6,部分设备配置为IPv4的网络中。
此外,在本发明实施例中,网络设备无需维护路由表,就能实现L2 ACP报文的传输。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括用于唯一标识该L2 ACP报文的报文ID,
其中,S420该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
S425,当该第二网络设备确定本地未缓存该报文ID时,通过判断该第二网络设备的设备标识是否与该目的设备标识相匹配,处理该L2 ACP报文。
具体地,该L2 ACP报文的报文头如表8所示。
具体地,报文ID是源设备上的唯一的字符串。报文ID是用于接收设备检测自己是否已经接收过相同的报文。具体地,例如一个设备接收到L2 ACP报文,确定本地没有缓存该L2 ACP报文的报文ID,即是第一次接收到该L2 ACP报文,则解析报文内容,并且缓存该报文ID,然后向邻居设备转发该L2 ACP报文;如果一个设备接收到L2 ACP报文,确定本地已经缓存了该L2 ACP报文的报文ID,则认为不是第一次收到该L2 ACP报文,则可以丢弃该报文。与第二种情况类似,当一个设备接收到L2 ACP报文之后,超过时间戳指示的时间后,可以删除这个L2 ACP报文。具体地,例如上述例子中,设备6接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2和8,则设备2会从自己的邻居设备5和6重复收到源自设备7的L2 ACP报文,L2 ACP报文中包括报文ID就可以避免设备2重复处理相同的L2 ACP报文,例如当设备2首先接收到邻居设备5发送的L2 ACP报文,设备2在解析该L2 ACP报文后,缓存该L2 ACP报文,自然也保存了该L2 ACP报文的报文ID。当设备2接收到设备6发送的源自设备7的L2 ACP报文时,解析该L2 ACP报文,检测到自己已经接收过该L2 ACP报文,就可以对该L2 ACP报文作丢弃操作。
因此,在本发明实施例中,在验证L2 ACP报文中的设备标识是否与第 二网络设备的设备标识匹配之前,首先根据该报文ID,验证第二网络设备是否已经收到过该L2 ACP报文(即检测本地是否已经缓存了该报文ID),如果确定之前没有接收过该L2 ACP报文,则进行后续设备标识的判断,否则,可以丢弃该L2 ACP报文。
在L2 ACP报文包括报文ID,能够避免重复的信令转发。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文,
该方法400还包括:
S430,当该第二网络设备确定缓存该L2 ACP报文的时间超过该定时信息所指示的预设时长时,清除该L2 ACP报文。
具体地,该定时信息例如为一个定时器,具体的时间值可以根据业务需求或者具体情况预配置,例如设备5接收到源自设备7的L2 ACP报文之后,根据该时间戳开始计时,计时超过阈值之后,可以认为该L2 ACP报文已经传输到目的UDI对应的设备了,即该L2 ACP报文的传输结束了,就可以删除该L2 ACP报文了。该定时信息也可以具体地为时间戳。
在本发明实施例中,在L2 ACP报文包括定时信息,能够实现设备及时地清除已经传输完毕的L2 ACP报文,能够避免设备长时间缓存无用L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,S420该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
S424,该第二网络设备确定该第二网络设备的设备标识与该目的设备标识相匹配,解析该L2 ACP报文,并缓存该L2 ACP报文,以及根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
具体地,L2 ACP报文的格式如表5所示,L2 ACP报文的报文头如表6所示,其中标志位字段的值用于指示该L2 ACP报文为广播报文,即用于指示该L2 ACP报文的接收设备解析该L2 ACP报文,并向该接收设备的邻居 设备转发基于该数据链路层的帧封装后的该L2 ACP报文,例如,该标志位字段的值例如为0003。
应理解,在本发明实施例中,该L2 ACP报文为广播报文,该L2 ACP报文中的目的设备标识可以为广播设备标识,则自组织网络中的任意网络设备接收到该L2 ACP报文,都会确定自己的设备标识与该目的设备标识相匹配。
还应理解,当该L2 ACP报文为广播报文的情况下,该L2 ACP报文中也可以不包括目的设备标识,网络设备根据该L2 ACP报文的标志位确定该L2 ACP报文为广播报文,则解析该L2 ACP报文,并转发,无需判断设备标识是否匹配。
具体地,还以图2为例,例如上层网络功能实体下发的任务是从设备6广播L2 ACP报文。设备6生成的L2 ACP报文如表5和表6所示,该L2 ACP报文的报文头的标志位字段的值用于指示广播报文;基于数据链路层的帧封装该L2 ACP报文,其中,数据链路层的帧的目的MAC地址为MAC广播地址。设备6的邻居设备接收到该L2 ACP报文,通过解析确定该L2 ACP报文为广播报文,继续转发给自己的邻居设备2、7和8和7,类似的,设备2、7和8继续向自己的邻居设备转发该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括用于唯一标识该L2 ACP报文的报文ID,
其中,S420该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
S425,当该第二网络设备确定本地未缓存该报文ID时,通过判断该第二网络设备的设备标识是否与该目的设备标识相匹配,处理该L2 ACP报文。
具体地,该L2 ACP报文的报文头如表8所示。
具体地,报文ID是源设备上的唯一的字符串。报文ID是用于接收设备检测自己是否已经接收过相同的报文。具体地,例如一个设备接收到L2 ACP报文,确定本地没有缓存该L2 ACP报文的报文ID,即是第一次接收到该L2 ACP报文,则解析报文内容,并且缓存该报文ID,然后向邻居设备转发该L2 ACP报文;如果一个设备接收到L2 ACP报文,确定本地已经缓存了该L2 ACP报文的报文ID,则认为不是第一次收到该L2 ACP报文,则可以丢弃该报文。与第二种情况类似,当一个设备接收到L2 ACP报文之后,超 过时间戳指示的时间后,可以删除这个L2 ACP报文。具体地,例如上述例子中,设备6接收到设备7发送的L2 ACP报文后,解析该L2 ACP报文为非邻居单播消息,检测目的UDI与自己的UDI不匹配,则将该L2 ACP报文转发给自己的邻居设备2和8,则设备2会从自己的邻居设备5和6重复收到源自设备7的L2 ACP报文,L2 ACP报文中包括报文ID就可以避免设备2重复处理相同的L2 ACP报文,例如当设备2首先接收到邻居设备5发送的L2 ACP报文,设备2在解析该L2 ACP报文后,缓存该L2 ACP报文,自然也保存了该L2 ACP报文的报文ID。当设备2接收到设备6发送的源自设备7的L2 ACP报文时,解析该L2 ACP报文,检测到自己已经接收过该L2 ACP报文,就可以对该L2 ACP报文作丢弃操作。
因此,在本发明实施例中,在第二网络设备验证L2 ACP报文中的设备标识是否与该第二网络设备的设备标识匹配之前,首先根据该报文ID,验证该第二网络设备是否已经收到过该L2 ACP报文(即检测本地是否已经缓存了该报文ID),如果确定之前没有接收过该L2 ACP报文,则进行后续设备标识的判断,否则,可以丢弃该L2 ACP报文。
在L2 ACP报文包括报文ID,能够避免重复的信令转发。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文,
该方法400还包括:
S430,当该第二网络设备确定缓存该L2 ACP报文的时间超过该定时信息所指示的预设时长时,清除该L2 ACP报文。
具体地,该L2 ACP报文的报文头如表8所示:
具体地,该定时信息例如为一个定时器,具体的时间值可以根据业务需求或者具体情况预配置,例如设备5接收到源自设备7的L2 ACP报文之后,根据该时间戳开始计时,计时超过阈值之后,可以认为该L2 ACP报文已经传输到目的UDI对应的设备了,即该L2 ACP报文的传输结束了,就可以删除该L2 ACP报文了。该定时信息也可以具体地为时间戳。
在本发明实施例中,在L2 ACP报文包括定时信息,能够实现设备及时地清除已经传输完毕的L2 ACP报文,能够避免设备长时间缓存无用L2 ACP报文。
在本发明实施例中,基于数据链路层的帧封装L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
进一步地,在本发明实施例中,基于目标设备的设备标识(例如UDI)和网络设备的邻居列表,在网络设备之间传输L2 ACP报文,而非依赖于loopback地址,从而避免了网络设备需要维护路由表。每个网络设备都具有自己的UDI和邻居列表,直接利用现成的资源去实现信令传输,能够降低维护成本。
此外,本发明实施例中的自组织网络以及自组织网络中的报文传输均可以不感知IP协议,因此并不苛求网络设备统一支持IPv6或者IPv4,从而相对于现有技术,具有更好的网络兼容性,而且也降低了自组织网络部署的难度。
可选地,在本发明实施例中,自组织网络中的每个网络设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,其中,该L2 ACP报文还包括目的IP地址,
其中,S420该第二网络设备通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文,包括:
S426,当该第二网络设备确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识不匹配时,根据该L2 ACP报文的目的数据链路层地址向该第二网络设备的邻居设备转发该L2 ACP报文;
S427,当该第二网络设备确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识相匹配、且该第二网络设备的IP地址与该L2 ACP报文的该目的IP地址相匹配时,解析该L2 ACP报文。
具体地,该L2 ACP报文的格式如表5和表6所示,其中L2 ACP报文的报文头中的协议字段的值可以采用IP报文中的协议字段的值。
具体地,例如,某些上层业务,例如远端用户拨入验证服务(Remote Authentication Dial In User Service,简称为“RADIUS”),严格要求基于IP,或者TCP/UDP来传输信令。
在本发明实施例中,ACP内的每个自组织设备支持无重复的自配置的环回(Loopback)地址;且ACP内的每个自组织设备支持UDI和IP的映射(包 括自己的和对端设备的)。
具体地,例如,上层的自组织代理(Agent)的传输需求中指明需要建立IP会话,则相关的服务设备(如AAA)需要向客户设备发送自己的服务器IP地址和自己的UDI,此阶段被称为服务自发现,或者service advertisement。
客户设备接收到服务设备发送的消息后,绑定该IP地址,UDI,以及相关服务,并且通过一个自配置的IPv6 ULA loopback地址,或者IPv4 loopback地址,向服务器发起IP会话。
服务器的UDI层收到相关报文后,绑定该客户设备的IP和UDI。
后续,在服务器和客户端的ACP通信中,服务端/客户端封装了IP包后,查找IP和UDI映射表,在ACP平面内基于UDI进行转发。
在本发明实施例涉及的场景下,虽然在上层设备应用看来它们之间在ACP平面内发起了一次IP会话,但是ACP平面仍然不提供基于IP的转发,网络设备无需维护相关的路由表。
因此,本发明实施例提供的ACP能够提供基于IP的通信能力,从而能够为上层应用提供更好的兼容性,让它们尽量无感知的使用基于L2层的ACP。
应理解,本发明实施例中L2 ACP报文的报文格式是数据链路层的收发端设备都公知的,即数据链路层的设备都能够识别L2 ACP报文。
在本发明实施例中,利用UDI和设备的邻居列表,在ACP内传输信令,而非依赖于loopback地址,从而避免了每个设备需要维护路由表,每个设备都具有自己的UDI和邻居列表,直接利用现成的资源去实现信令传输,能够降低维护成本。
此外,本发明实施例中的ACP可以不感知IP协议,并不要求网络设备统一支持IPv6或者IPv4的情况才可以实现建立统一的ACP,从而相对于现有技术,具有更好的网络兼容性,而且也降低了自组织网络部署的难度。
因此,在本发明实施例中,在ACP内,是基于设备的UDI来传输信令的,避免了现有技术中设备需要额外维护路由表的问题,能够节省部署成本。此外,在本发明实施例中,在ACP上传输信令,可以不感知IP协议,例如整个网络即使不支持IPv6,也可以实现在ACP上传输信令,相比于现有技术,具有较好的网络兼容性,也能够减少网络部署的困难。此外,本发明实 施例提供的方案也可以应用于部分设备配置为IPv6,部分设备配置为IPv4的网络中。
可选地,在本发明实施例中,方法100与方法200中涉及的AD消息(记为报文一)与方法300和方法400中涉及的L2 ACP报文(记为报文二)可以基于相同的数据链路层的帧格式封装,例如封装报文一的数据链路层的帧与封装报文二的数据链路层的帧的类型Type字段的取值可以采用同一个值。应理解,封装报文一的数据链路层的帧与封装报文二的数据链路层的帧的类型Type字段的取值也可以采用不同的值。
例如,当封装报文一与报文二的帧的类型Type采用同一个赋值时,利用报文头中的标志位的不同赋值来区分报文一和报文二。例如报文一与报文二的帧类型Type均为88e7,但是报文一的报文头中的标志位为0000,用于指示数据链路层的帧承载是邻接发现AD消息,报文二的报文头中的标志位为0001,用于指示该数据链路层的帧承载的是ACP报文(即在ACP上传输信令的报文)。再具体地,例如该报文二分为邻居单播报文、非邻居单播报文和广播报文,可以通过对这三种不同传输类型的报文二的标志位赋不同的值,来区分不同传输类型的报文二,例如,当报文二的报文头中的标志位为0001,指示数据链路层的帧承载的为邻居单播报文,当报文二的报文头中的标志位为0002,指示数据链路层的帧承载的为非邻居单播报文,当报文二的报文头中的标志位为0003,指示数据链路层的帧承载的为广播报文
例如,当报文一与报文二的帧类型Type采用不同赋值时,该帧类型Type可以用于区分报文一和报文二,例如封装报文一的数据链路层的帧类型Type赋值为88e7,封装报文二的数据链路层的帧类型Type赋值为88e8。再具体地,例如报文二分为邻居单播报文、非邻居单播报文和广播报文,则这三种传输类型的报文二的帧类型Type赋值也可以不同,以此来区分不同传输类型的报文二,例如,封装邻居单播报文的数据链路层的帧类型Type赋值为88e8,封装非邻居单播报文的数据链路层的帧类型Type赋值为88e9,封装广播报文的数据链路层的帧类型Type赋值为88e6。应理解,还可以是,这三种传输类型的报文二的帧类型Type采用同一赋值,利用标志位来区分这三种传输类型的报文二,本发明实施例对此不作限定。
图6示出了本发明实施例提供的一种网络设备500,该网络设备应用于自组织网络,该网络设备500包括:
生成模块510,用于网络设备生成邻接发现AD消息,该AD消息包括该网络设备的设备标识;
封装模块520,用于基于数据链路层的帧封装该生成模块生成的该AD消息,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址;
应理解,该数据链路层的帧的目的数据链路层地址可以为广播数据链路层地址,或者为该网络设备的邻居设备的数据链路层地址。
发送模块530,用于基于该目的数据链路层地址,向登记Registrar设备发送该封装模块确定的基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备;
接收模块540,用于接收该Registrar设备发送的域证书,该域证书为该Registrar设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的;
建立模块550,用于根据该接收模块接收的该域证书,与该Registrar设备建立自组织控制平面ACP。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
应理解,根据本发明实施例的网络设备500可对应于本发明实施例的基于数据链路层的通信方法中的网络设备,并且网络设备500中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
图7示出了本发明实施例提供的一种登记Registrar设备600,该Registrar设备600应用于自组织网络,该Registrar设备600为该自组织网络中支持分配域证书的设备,该Registrar设备600包括:
接收模块610,用于接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,该AD消息包括该网络设备的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配;
应理解,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配指的是,该目的数据链路层地址就是为该Registrar设备的数据链路层地址,或者该目的数据链路层地址为广播数据链路层地址,应理解,可以认为广播数据链路层地址与任意固定的数据链路层地址相匹配。
发送模块620,用于当确定该网络设备允许加入该自组织网络时,根据该接收模块接收的该AD消息包括的该设备标识为该网络设备分配域证书,并向该网络设备发送该域证书;
ACP建立模块630,用于根据该发送模块发送的该域证书,与该网络设备建立自组织控制平面ACP。
在本发明实施例中,设备的邻接发现AD消息是基于数据链路层的帧封 装的;该AD消息基于数据链路层地址,发送至自组织网络中分配域证书的Registrar设备;该Registrar设备根据该AD消息为该设备分配域证书;基于该域证书,该设备与Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
可选地,在本发明实施例中,该网络设备为该Registrar设备的邻居设备,该Registrar设备还包括:
邻居列表建立模块640,用于根据该AD消息,建立该Registrar设备的邻居列表,该邻居列表包括该网络设备的设备标识以及该网络设备的数据链路层地址。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的唯一设备标识UDI,
其中,该发送模块620具体用于,当确定白名单具有该网络设备的UDI的匹配项时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该UDI分配的该域证书,该白名单包括允许加入该自组织网络的设备的UDI。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的安全的唯一设备标识S-UDI,
其中,该发送模块620具体用于,当通过验证服务器确定该S-UDI对应的设备数字证书有效时,确定该网络设备允许加入该自组织网络,向该网络设备发送根据该设备数字证书分配的该域证书。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
应理解,根据本发明实施例的Registrar设备600可对应于本发明实施例的基于数据链路层的通信方法中的Registrar设备,并且Registrar设备600中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
在本发明实施例中,设备的邻接发现AD消息是基于数据链路层的帧封装的;该AD消息基于数据链路层地址,发送至自组织网络中分配域证书的Registrar设备;该Registrar设备根据该AD消息为该设备分配域证书;基于该域证书,该设备与Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
图8示出了本发明实施例提供的网络设备700,该网络设备用作第一网络设备,该第一网络设备应用于自组织网络,该网络设备700包括:
生成模块710,用于生成数据链路层自组织控制平面L2 ACP报文,该第一网络设备为该自组织网络中的自组织设备;
封装模块720,用于基于数据链路层的帧封装该生成模块生成的该L2 ACP报文,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址;
应理解,该数据链路层的帧的目的数据链路层地址为该第一网络设备的邻居设备的数据链路层地址,或者为广播数据链路层地址。
发送模块730,用于根据该目的数据链路层地址,向第二网络设备发送该封装模块确定的基于该数据链路层的帧封装后的该L2 ACP报文,该第二网络设备也为该自组织网络中的自组织设备,且该第二网络设备为该第一网络设备的邻居设备。
在本发明实施例中,基于数据链路层的帧封装该L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,网络设备可以无需像现有技术中一样维护路由表。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义 的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
可选地,在本发明实施例中,该生成模块710具体用于,需要与该自组织网络中的目标设备通信时,当确定该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,该第一网络设备的邻居列表包括该第一网络设备的邻居设备的设备标识与数据链路层地址;
应理解,该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项指的是,该第一网络设备的邻居列表包括与该目标设备的设备标识相同的设备标识。还应理解,当该目标设备的设备标识为广播设备标识时,也可认为该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项。如果该第一网络设备的邻居列表不包括与该目标设备的设备标识相同的设备标识、且该目标设备的设备标识也不是广播设备标识时,则认为该第一网络设备的邻居列表不包括该目标设备的设备标识的匹配项。
该封装模块720具体用于,基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
该发送模块730具体用于,根据该目标设备的数据链路层地址,向该目标设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,该生成模块710具体用于,需要与该自组织网络中的目标设备通信时,当确定该邻居列表中不包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文;
该封装模块720具体用于,基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
该发送模块730具体用于,根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,该生成模块710具体用于,需要在该ACP内广播控制消息时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文;
具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
该封装模块720具体用于,基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该发送模块730具体用于,根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括用于唯一指示该L2 ACP报文的报文ID。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
可选地,在本发明实施例中,该自组织网络内的每个自组织设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,
该生成模块710具体用于,当需要通过IP会话与该ACP内的目标设备通信时,生成该L2 ACP报文,该L2 ACP报文还包括目的IP地址,该目的IP地址为该目标设备的IP地址。
应理解,根据本发明实施例的网络设备700可对应于本发明实施例的基于数据链路层的通信方法中的第一网络设备,并且网络设备700中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
本发明实施例中发送的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,无需设备像现有技术中一样维护路由表,也能够实现基于ACP的通信。
图9示出了本发明实施例提供的一种网络设备800,该网络设备800用作第二网络设备,该网络设备800应用于自组织网络,该网络设备800包括:
接收模块810,用于接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,该L2 ACP报文包括目的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配,该第二网络设备与该第一网络设备均为该自组织网络中的自组织设备;
应理解,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配指的是,该目的数据链路层地址直接为该第二网络设备的数据链路层地址,或者,该目的数据链路层地址为广播数据链路层地址,应理解,广播数据链路层地址可以为认为任意固定的数据链路层地址相匹配。
处理模块820,用于通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该接收模块接收的该L2 ACP报文。
应理解,当该目的设备标识直接解释该第二网络设备的设备标识时,或者该目的设备标识为广播设备标识时,则可认为该目的设备标识与该第二网络设备的设备标识相匹配,否则不匹配。
应理解,在本发明实施例中,该自组织网络的自组织控制平面ACP是基于数据链路层建立的,具体方法见上文方法100和200该,这里不再赘述。
本发明实施例中的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,设备也无需像现有技术中一样维护路由表,也能够实现基于ACP的通信。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
其中,该处理模块820具体用于,确定该目的设备标识为该第二网络设备的设备标识,并解析该L2 ACP报文。
具体地,处理模块820具体用于具体地,通过解析该L2 ACP报文,获取该L2 ACP报文中的报文内容,例如控制消息等,具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该处理模块820具体用于,当确定该第二网络设备的设备标识与该目的设备标识相匹配时,解析该L2 ACP报文,并缓存该L2 ACP报文;
具体地,通过解析该L2 ACP报文,获取该L2 ACP报文中的报文内容,例如控制消息等。
处理模块820具体用于,当确定该第二网络设备的设备标识与该目的设备标识不匹配时,缓存该L2 ACP报文,并根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
其中,该处理模块820具体用于,确定该第二网络设备的设备标识与该目的设备标识相匹配,解析该L2 ACP报文,并缓存该L2 ACP报文,以及根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
应理解,在本发明实施例中,该L2 ACP报文为广播报文,该L2 ACP报文中的目的设备标识可以为广播设备标识,则自组织网络中的任意网络设备接收到该L2 ACP报文,都会确定自己的设备标识与该目的设备标识相匹配。
还应理解,当该L2 ACP报文为广播报文的情况下,该L2 ACP报文中也可以不包括目的设备标识,网络设备根据该L2 ACP报文的标志位确定该L2 ACP报文为广播报文,则解析该L2 ACP报文,并转发,无需判断设备标识是否匹配。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括用于唯一标识该L2 ACP报文的报文ID,
其中,该处理模块820具体用于,当确定本地未缓存该报文ID时,通过判断该第二网络设备的设备标识是否与该目的设备标识相匹配,处理该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文,
该网络设备800还包括:
缓存清除模块830,用于当确定缓存该L2 ACP报文的时间超过该定时信息所指示的预设时长时,清除该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
可选地,在本发明实施例中,该自组织网络内的每个自组织设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,其中,该L2 ACP报文还包括目的IP地址,
该处理模块820具体用于,当该第二网络设备确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识不匹配时,根据该L2 ACP报文的目的数据链路层地址向该第二网络设备的邻居设备转发该L2 ACP报文;
该处理模块820具体用于,当该第二网络设备确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识相匹配、且该第二网络设备的IP地址与该L2 ACP报文的该目的IP地址相匹配时,解析该L2 ACP报文。
应理解,根据本发明实施例的网络设备800可对应于本发明实施例的基于数据链路层的通信方法中的第二网络设备,并且网络设备800中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
本发明实施例中发送的L2 ACP报文是基于数据链路层的帧封装的,可 以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,设备也无需像现有技术中一样维护路由表,也能够实现基于ACP的通信。
图10示出了本发明实施例提供的基于自组织网络的系统900的示意性框图,该系统900包括本发明实施例提供的网络设备500与Registrar设备600。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
图11示出了本发明实施例提供的基于自组织网络的系统1000的示意性框图,该系统1000包括本发明实施例提供的网络设备700与网络设备800。
本发明实施例中发送的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,设备也无需像现有技术中一样维护路由表,也能够实现基于ACP的通信。
图12示出了本发明实施例提供的网络设备1100的示意性框图,该网络设备1100包括:处理器1110、存储器1120、总线系统1130、接收器1140和发送器1150。其中,处理器1110、存储器1120、接收器1140和发送器1150通过总线系统1130相连,该存储器1120用于存储指令,其中,处理器1110用于,生成邻接发现AD消息,该AD消息包括该网络设备的设备标识;基于数据链路层的帧封装该AD消息,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址;发送器1150用于,基于该目的数据链路层地址,向登记Registrar 设备发送基于该数据链路层的帧封装后的该AD消息,该Registrar设备为自组织网络中支持分配域证书的设备;接收器1140用于,接收该Registrar设备发送的域证书,该域证书为该Registrar设备根据该AD消息中的该网络设备的设备标识为该网络设备分配的;处理器1110还用于,根据该域证书,与该Registrar设备建立自组织控制平面ACP。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书,与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
应理解,根据本发明实施例的网络设备1100可对应于本发明实施例的基于数据链路层的通信方法中的网络设备,以及可以对应于根据本发明实施例的网络设备500,并且网络设备1100中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
在本发明实施例中,基于数据链路层的帧封装AD消息,基于该数据链路层的帧的目的数据链路层地址,向Registrar设备发送该基于数据链路层的帧封装后的该AD消息,接收该Registrar设备发送的域证书,根据该域证书, 与该Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
图13示出了本发明实施例提供的登记Registrar设备1200的示意性框图该Registrar设备1200应用于自组织网络中,该Registrar设备1200包括:处理器1210、存储器1220、总线系统1230、接收器1240和发送器1250。其中,处理器1210、存储器1220、接收器1240和发送器1250通过总线系统1230相连,该存储器1220用于存储指令,其中,
接收器1240用于,接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,该AD消息包括该网络设备的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中该源数据链路层地址为该网络设备的数据链路层地址,该目的数据链路层地址与该Registrar设备的数据链路层地址相匹配;处理器1210用于,确定该网络设备允许加入该自组织网络时,根据该AD消息包括的该设备标识为该网络设备分配域证书;发送器1250用于,向该网络设备发送该域证书;处理器1210还用于,根据该域证书,与该网络设备建立自组织控制平面ACP。
在本发明实施例中,设备的邻接发现AD消息是基于数据链路层的帧封装的;该AD消息基于数据链路层地址,发送至自组织网络中分配域证书的Registrar设备;该Registrar设备根据该AD消息为该设备分配域证书;基于该域证书,该设备与Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值指示该L2 ACP报文为该AD消息。
可选地,在本发明实施例中,该网络设备为该第二网络设备的邻居设备,处理器1210还用于,根据该AD消息,建立该第二网络设备的邻居列表, 该邻居列表包括该网络设备的设备标识以及该网络设备的数据链路层地址。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的唯一设备标识UDI,
处理器1210还用于,当确定白名单具有该网络设备的UDI的匹配项时,确定该网络设备允许加入该自组织网络,根据该UDI分配该域证书,该白名单包括允许加入该自组织网络的设备的UDI。
可选地,在本发明实施例中,该网络设备的设备标识为该网络设备的安全的唯一设备标识S-UDI,
处理器1210还用于,当通过验证服务器确定该S-UDI对应的设备数字证书有效时,确定该网络设备允许加入该自组织网络,根据该设备数字证书分配该域证书。
可选地,在本发明实施例中,该AD消息的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
应理解,根据本发明实施例的Registrar设备1200可对应于本发明实施例的基于数据链路层的通信方法中的Registrar设备,以及可以对应于根据本发明实施例的Registrar设备600,并且Registrar设备1200中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
在本发明实施例中,设备的邻接发现AD消息是基于数据链路层的帧封装的;该AD消息基于数据链路层地址,发送至自组织网络中分配域证书的Registrar设备;该Registrar设备根据该AD消息为该设备分配域证书;基于该域证书,该设备与Registrar设备建立自组织控制平面ACP。因此,在本发明实施例中,建立ACP可以不依赖于IP协议,即实现基于自组织网络的通信可以对IP协议不感知,相对于现有技术,具有较好的网络兼容性,能够有效减小自组织网络的部署障碍。
图14示出了本发明实施例提供的网络设备1300的示意性框图,该网络设备1300应用于自组织网络,该网络设备1300用作第一网络设备,该网络设备1300包括:处理器1310、存储器1330、总线系统1330、接收器1340和发送器1350。其中,处理器1310、存储器1330、接收器1340和发送器 1350通过总线系统1330相连,该存储器1330用于存储指令,其中,处理器1310用于,生成数据链路层自组织控制平面L2 ACP报文,该第一网络设备为该自组织网络中的自组织设备;基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址;发送器1350用于,根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,该第二网络设备也为该自组织网络中的自组织设备,且该第二网络设备为该第一网络设备的邻居设备。
在本发明实施例中,基于数据链路层的帧封装该L2 ACP报文,并根据该目的数据链路层地址,向第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文,在本发明实施例中,在ACP上传输报文可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,网络设备可以无需像现有技术中一样维护路由表。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
可选地,在本发明实施例中,处理器1310具体用于,需要与该自组织网络中的目标设备通信时,当确定该第一网络设备的邻居列表中包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,该第一网络设备的邻居列表包括该第一网络设备的邻居设备的设备标识与数据链路层地址;基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;发送器1350具体用于,根据该目标设备的数据链路层地址,向该目标设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,处理器1310具体用于,需要与该自组织网络中的目标设备通信时,当确定该邻居列表中不包括该目标设备的设备标识的匹配项时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文;基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层 地址为广播数据链路层地址;发送器1350具体用于,根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,处理器1310具体用于,需要在该ACP内广播控制消息时,生成该L2 ACP报文,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文;基于数据链路层的帧封装该L2 ACP报文,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;发送器1350具体用于,根据该广播数据链路层地址,向该第二网络设备发送基于该数据链路层的帧封装后的该L2 ACP报文。
具体地,该控制消息可以为实现控制和/或管理功能的控制信令。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括用于唯一指示该L2 ACP报文的报文ID。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文。
可选地,在本发明实施例中,该自组织网络内的每个自组织设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,
处理器1310具体用于,当需要通过IP会话与该ACP内的目标设备通信时,生成该L2 ACP报文,该L2 ACP报文还包括目的IP地址,该目的IP地址为该目标设备的IP地址。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
应理解,根据本发明实施例的网络设备1300可对应于本发明实施例的基于数据链路层的通信方法中的第一网络设备,以及可以对应于根据本发明实施例的网络设备700,并且网络设备1300中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在 此不再赘述。
本发明实施例中发送的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,无需设备像现有技术中一样维护路由表,也能够实现基于ACP的通信。
图15示出了本发明实施例提供的网络设备1400的示意性框图,该网络设备1400应用于自组织网络,该网络设备1400用作为第二网络设备,该网络设备1400包括:处理器1410、存储器1420、总线系统1440、接收器1440和发送器1450。其中,处理器1410、存储器1420、接收器1440和发送器1450通过总线系统1440相连,该存储器1420用于存储指令,其中,接收器1440用于,接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,该L2 ACP报文包括目的设备标识,该数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,该源数据链路层地址为该第一网络设备的数据链路层地址,该目的数据链路层地址与该第二网络设备的数据链路层地址相匹配,该第二网络设备与该第一网络设备均为该自组织网络中的自组织设备;处理器1410用于,通过判断该第二网络设备的设备标识是否与该L2 ACP报文的该目的设备标识相匹配,处理该L2 ACP报文。
本发明实施例中发送的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,网络设备可以无需像现有技术中一样维护路由表。
可选地,在本发明实施例中,该数据链路层的帧为符合以太网协议定义的帧,该数据链路层的帧的类型Type字段的Type值指示该数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为该目标设备的数据链路层地址;
处理器1410具体用于,确定该目的设备标识为该第二网络设备的设备标识,并解析该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为非邻居单播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
处理器1410具体用于,当确定该第二网络设备的设备标识与该目的设备标识相匹配时,解析该L2 ACP报文,并缓存该L2 ACP报文;当确定该第二网络设备的设备标识与该目的设备标识不匹配时,缓存该L2 ACP报文,并根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括标志位字段,该标志位字段的值用于指示该L2 ACP报文为广播报文,其中,该数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
处理器1410具体用于,确定该第二网络设备的设备标识与该目的设备标识相匹配,解析该L2 ACP报文,并缓存该L2 ACP报文,以及根据该数据链路层的帧的目的数据链路层地址向该第二网络设备的邻居设备转发基于该数据链路层的帧封装后的该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括用于唯一标识该L2 ACP报文的报文ID,
处理器1410具体用于,当确定本地未缓存该报文ID时,通过判断该第二网络设备的设备标识是否与该目的设备标识相匹配,处理该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头中还包括定时信息,该定时信息用于指示该L2 ACP报文的接收设备在缓存该L2 ACP报文的时间超过预设时长时,清除该L2 ACP报文,
处理器1410还用于,当确定缓存该L2 ACP报文的时间超过该定时信息所指示的预设时长时,清除该L2 ACP报文。
可选地,在本发明实施例中,该自组织网络内的每个自组织设备均具有IP地址,且该每个自组织设备具有该每个自组织设备的设备标识与该每个自组织设备的IP地址之间的映射,其中,该L2 ACP报文还包括目的IP地址,
处理器1410具体用于,当确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识不匹配时,根据该L2 ACP报文的目的数据链路层地 址向该第二网络设备的邻居设备转发该L2 ACP报文;当确定该第二网络设备的设备标识与该L2 ACP报文的该目的设备标识相匹配、且该第二网络设备的IP地址与该L2 ACP报文的该目的IP地址相匹配时,解析该L2 ACP报文。
可选地,在本发明实施例中,该L2 ACP报文的报文头还包括版本字段、协议字段和数据包长度字段。
可选地,在本发明实施例中,该数据链路层地址为介质访问控制MAC地址。
可选地,在本发明实施例中,该设备标识为唯一设备标识UDI或者安全的唯一设备标识SUDI。
应理解,根据本发明实施例的网络设备1400可对应于本发明实施例的基于数据链路层的通信方法中的第二网络设备,以及可以对应于根据本发明实施例的网络设备800,并且网络设备1400中的各个模块的上述和其它操作和/或功能分别为了实现图1至图5中的各个方法的相应流程,为了简洁,在此不再赘述。
本发明实施例中发送的L2 ACP报文是基于数据链路层的帧封装的,可以基于该L2 ACP报文的目的数据链路层地址在ACP内传输该L2 ACP报文,即在本发明实施例中,基于ACP的通信,可以不依赖于IP协议,相比于现有技术,具有较好的网络兼容性。
此外,在本发明实施例中,设备也无需像现有技术中一样维护路由表,也能够实现基于ACP的通信。
还应理解,本文中涉及的第一、第二、第三、第四、第五、第六、第七、第八以及各种数字编号仅为描述方便进行的区分,并不用来限制本发明实施例的范围。
应理解,本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本文中字符“/”,一般表示前后关联对象是一种“或”的关系。
应理解,在本发明的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本发明实施例的实施过程构成任何限定。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、或者计算机软件和电子硬件的结合来实现。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本发明的范围。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。
所述功能如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,仅为本发明的具体实施方式,但本发明的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本发明的保护范围之内。因此,本发明的保护范围应以所述权利要求的保护范围为准。

Claims (42)

  1. 一种基于数据链路层的通信方法,所述通信方法应用于自组织网络,其特征在于,包括:
    网络设备生成邻接发现AD消息,所述AD消息包括所述网络设备的设备标识;
    所述网络设备基于数据链路层的帧封装所述AD消息,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中所述源数据链路层地址为所述网络设备的数据链路层地址;
    所述网络设备基于所述目的数据链路层地址,向登记Registrar设备发送基于所述数据链路层的帧封装后的所述AD消息,所述Registrar设备为自组织网络中支持分配域证书的设备;
    所述网络设备接收所述Registrar设备发送的域证书,所述域证书为所述Registrar设备根据所述AD消息中的所述网络设备的设备标识为所述网络设备分配的;
    所述网络设备根据所述域证书,与所述Registrar设备建立自组织控制平面ACP。
  2. 根据权利要求1所述的方法,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
  3. 根据权利要求2所述的方法,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值指示所述L2 ACP报文为所述AD消息。
  4. 一种基于数据链路层的通信方法,所述通信方法应用于自组织网络,其特征在于,包括:
    登记Registrar设备接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,所述AD消息包括所述网络设备的设备标识,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中所述源数据链路层地址为所述网络设备的数据链路层地址,所述目的数据链路层地址与所述Registrar设备的数据链路层地址相匹配;
    当所述Registrar设备确定所述网络设备允许加入所述自组织网络时,根 据所述AD消息包括的所述设备标识为所述网络设备分配域证书,并向所述网络设备发送所述域证书;
    所述Registrar设备根据所述域证书,与所述网络设备建立自组织控制平面ACP。
  5. 根据权利要求4所述的方法,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
  6. 根据权利要求4或5所述的方法,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值指示所述L2 ACP报文为所述AD消息。
  7. 一种基于数据链路层的通信方法,所述通信方法应用于自组织网络,其特征在于,所述方法包括:
    第一网络设备生成数据链路层自组织控制平面L2 ACP报文,所述第一网络设备为所述自组织网络中的自组织设备;
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,所述源数据链路层地址为所述第一网络设备的数据链路层地址;
    所述第一网络设备根据所述目的数据链路层地址,向第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文,所述第二网络设备也为所述自组织网络中的自组织设备,且所述第二网络设备为所述第一网络设备的邻居设备。
  8. 根据权利要求7所述的方法,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是所述L2 ACP报文。
  9. 根据权利要求7或8所述的方法,其特征在于,所述第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
    所述第一网络设备需要与所述自组织网络中的目标设备通信时,当确定所述第一网络设备的邻居列表中包括所述目标设备的设备标识的匹配项时,生成所述L2 ACP报文,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为邻居单播报文,所述第一网络 设备的邻居列表包括所述第一网络设备的邻居设备的设备标识与数据链路层地址;
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,包括:
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧的目的数据链路层地址为所述目标设备的数据链路层地址;
    所述第一网络设备根据所述目的数据链路层地址,向第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文,包括:
    所述第一网络设备根据所述目标设备的数据链路层地址,向所述目标设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文。
  10. 根据权利要求7或8所述的方法,其特征在于,所述第一网络设备生成数据链路层自组织控制平面L2 ACP报文,包括:
    所述第一网络设备需要与所述自组织网络中的目标设备通信时,当确定所述邻居列表中不包括所述目标设备的设备标识的匹配项时,生成所述L2 ACP报文,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为非邻居单播报文;
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,包括:
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    所述第一网络设备根据所述目的数据链路层地址,向第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文,包括:
    所述第一网络设备根据所述广播数据链路层地址,向所述第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文。
  11. 根据权利要求7或8所述的方法,其特征在于,所述第一网络设备生成L2 ACP报文,包括:
    当所述第一网络设备需要在所述ACP内广播控制消息时,生成所述L2 ACP报文,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为广播报文;
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,包括:
    所述第一网络设备基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    其中,所述第一网络设备根据所述目的数据链路层地址,向第二网络设 备发送基于所述数据链路层的帧封装后的所述L2 ACP报文,包括:
    所述第一网络设备根据所述广播数据链路层地址,向所述第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文。
  12. 根据权利要求10或11所述的方法,其特征在于,所述L2 ACP报文的报文头还包括用于唯一指示所述L2 ACP报文的报文ID。
  13. 根据权利要求10至12中任一项所述的方法,其特征在于,所述L2 ACP报文的报文头还包括定时信息,所述定时信息用于指示所述L2 ACP报文的接收设备在缓存所述L2 ACP报文的时间超过预设时长时,清除所述L2 ACP报文。
  14. 一种基于数据链路层的通信方法,所述通信方法应用于自组织网络,其特征在于,所述方法包括:
    第二网络设备接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,所述L2 ACP报文包括目的设备标识,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,所述源数据链路层地址为所述第一网络设备的数据链路层地址,所述目的数据链路层地址与所述第二网络设备的数据链路层地址相匹配,所述第二网络设备与所述第一网络设备均为所述自组织网络中的自组织设备;
    所述第二网络设备通过判断所述第二网络设备的设备标识是否与所述L2 ACP报文的所述目的设备标识相匹配,处理所述L2 ACP报文。
  15. 根据权利要求14所述的方法,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是所述L2 ACP报文。
  16. 根据权利要求14或15所述的方法,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为邻居单播报文,其中,所述数据链路层的帧的目的数据链路层地址为所述目标设备的数据链路层地址;
    其中,所述第二网络设备通过判断所述第二网络设备的设备标识是否与所述L2 ACP报文的所述目的设备标识相匹配,处理所述L2 ACP报文,包括:
    所述第二网络设备确定所述目的设备标识为所述第二网络设备的设备标识,并解析所述L2 ACP报文。
  17. 根据权利要求14或15所述的方法,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为非邻居单播报文,其中,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    其中,所述第二网络设备通过判断所述第二网络设备的设备标识是否与所述L2 ACP报文的所述目的设备标识相匹配,处理所述L2 ACP报文,包括:
    当所述第二网络设备确定所述第二网络设备的设备标识与所述目的设备标识相匹配时,解析所述L2 ACP报文,并缓存所述L2 ACP报文;
    当所述第二网络设备确定所述第二网络设备的设备标识与所述目的设备标识不匹配时,缓存所述L2 ACP报文,并根据所述数据链路层的帧的目的数据链路层地址向所述第二网络设备的邻居设备转发基于所述数据链路层的帧封装后的所述L2 ACP报文。
  18. 根据权利要求14或15所述的方法,其特征在于,所述L2 ACP报文的报文头还包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为广播报文,其中,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    其中,所述第二网络设备通过判断所述第二网络设备的设备标识是否与所述L2 ACP报文的所述目的设备标识相匹配,处理所述L2 ACP报文,包括:
    所述第二网络设备确定所述第二网络设备的设备标识与所述目的设备标识相匹配,解析所述L2 ACP报文,并缓存所述L2 ACP报文,以及根据所述数据链路层的帧的目的数据链路层地址向所述第二网络设备的邻居设备转发基于所述数据链路层的帧封装后的所述L2 ACP报文。
  19. 根据权利要求17或18所述的方法,其特征在于,所述L2 ACP报文的报文头中还包括用于唯一标识所述L2 ACP报文的报文ID,
    其中,所述第二网络设备通过判断所述第二网络设备的设备标识是否与所述L2 ACP报文的所述目的设备标识相匹配,处理所述L2 ACP报文,包括:
    当所述第二网络设备确定本地未缓存所述报文ID时,通过判断所述第二网络设备的设备标识是否与所述目的设备标识相匹配,处理所述L2 ACP 报文。
  20. 根据权利要求17至19中任一项所述的方法,其特征在于,所述L2 ACP报文的报文头中还包括定时信息,所述定时信息用于指示所述L2 ACP报文的接收设备在缓存所述L2 ACP报文的时间超过预设时长时,清除所述L2 ACP报文,
    所述方法还包括:
    当所述第二网络设备确定缓存所述L2 ACP报文的时间超过所述定时信息所指示的预设时长时,清除所述L2 ACP报文。
  21. 一种网络设备,所述网络设备应用于自组织网络,其特征在于,包括:
    生成模块,用于网络设备生成邻接发现AD消息,所述AD消息包括所述网络设备的设备标识;
    封装模块,用于基于数据链路层的帧封装所述生成模块生成的所述AD消息,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中所述源数据链路层地址为所述网络设备的数据链路层地址;
    发送模块,用于基于所述目的数据链路层地址,向Registrar设备发送所述封装模块确定的基于所述数据链路层的帧封装后的所述AD消息,所述Registrar设备为自组织网络中支持分配域证书的设备;
    接收模块,用于接收所述Registrar设备发送的域证书,所述域证书为所述Registrar设备根据所述AD消息中的所述网络设备的设备标识为所述网络设备分配的;
    建立模块,用于根据所述接收模块接收的所述域证书,与所述Registrar设备建立自组织控制平面ACP。
  22. 根据权利要求21所述的网络设备,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
  23. 根据权利要求22所述的网络设备,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值指示所述L2 ACP报文为所述AD消息。
  24. 一种登记Registrar设备,所述Registrar设备应用于自组织网络, 所述Registrar设备为所述自组织网络中支持分配域证书的设备,其特征在于,包括:
    接收模块,用于接收来自网络设备的基于数据链路层的帧封装后的邻接发现AD消息,所述AD消息包括所述网络设备的设备标识,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中所述源数据链路层地址为所述网络设备的数据链路层地址,所述目的数据链路层地址与所述Registrar设备的数据链路层地址相匹配;
    发送模块,用于当确定所述网络设备允许加入所述自组织网络时,根据所述接收模块接收的所述AD消息包括的所述设备标识为所述网络设备分配域证书,并向所述网络设备发送所述域证书;
    ACP建立模块,用于根据所述发送模块发送的所述域证书,与所述网络设备建立自组织控制平面ACP。
  25. 根据权利要求24所述的Registrar设备,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是数据链路层自组织控制平面L2 ACP报文。
  26. 根据权利要求24或25所述的Registrar设备,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值指示所述L2 ACP报文为所述AD消息。
  27. 一种网络设备,所述网络设备用作第一网络设备,所述第一网络设备应用于自组织网络,其特征在于,包括:
    生成模块,用于生成数据链路层自组织控制平面L2 ACP报文,所述第一网络设备为所述自组织网络中的自组织设备;
    封装模块,用于基于数据链路层的帧封装所述生成模块生成的所述L2 ACP报文,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,所述源数据链路层地址为所述第一网络设备的数据链路层地址;
    发送模块,用于根据所述目的数据链路层地址,向第二网络设备发送所述封装模块确定的基于所述数据链路层的帧封装后的所述L2 ACP报文,所述第二网络设备也为所述自组织网络中的自组织设备,且所述第二网络设备为所述第一网络设备的邻居设备。
  28. 根据权利要求27所述的第一网络设备,其特征在于,所述数据链 路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是所述L2 ACP报文。
  29. 根据权利要求27或28所述的第一网络设备,其特征在于,所述生成模块具体用于,需要与所述自组织网络中的目标设备通信时,当确定所述第一网络设备的邻居列表中包括所述目标设备的设备标识的匹配项时,生成所述L2 ACP报文,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为邻居单播报文,所述第一网络设备的邻居列表包括所述第一网络设备的邻居设备的设备标识与数据链路层地址;
    所述封装模块具体用于,基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧的目的数据链路层地址为所述目标设备的数据链路层地址;
    所述发送模块具体用于,根据所述目标设备的数据链路层地址,向所述目标设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文。
  30. 根据权利要求27或28所述的第一网络设备,其特征在于,所述生成模块具体用于,需要与所述自组织网络中的目标设备通信时,当确定所述邻居列表中不包括所述目标设备的设备标识的匹配项时,生成所述L2 ACP报文,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为非邻居单播报文;
    所述封装模块具体用于,基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    所述发送模块具体用于,根据所述广播数据链路层地址,向所述第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文。
  31. 根据权利要求27或28所述的第一网络设备,其特征在于,所述生成模块具体用于,需要在所述ACP内广播控制消息时,生成所述L2 ACP报文,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为广播报文;
    所述封装模块具体用于,基于数据链路层的帧封装所述L2 ACP报文,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    其中,所述发送模块具体用于,根据所述广播数据链路层地址,向所述 第二网络设备发送基于所述数据链路层的帧封装后的所述L2 ACP报文。
  32. 根据权利要求30或31所述的第一网络设备,其特征在于,所述L2 ACP报文的报文头还包括用于唯一指示所述L2 ACP报文的报文ID。
  33. 根据权利要求30至32中任一项所述的第一网络设备,其特征在于,所述L2 ACP报文的报文头还包括定时信息,所述定时信息用于指示所述L2 ACP报文的接收设备在缓存所述L2 ACP报文的时间超过预设时长时,清除所述L2 ACP报文。
  34. 一种网络设备,所述网络设备用作第二网络设备,所述第二网络设备应用于自组织网络,其特征在于,所述第二网络设备包括:
    接收模块,用于接收第一网络设备发送的基于数据链路层的帧封装后的L2 ACP报文,所述L2 ACP报文包括目的设备标识,所述数据链路层的帧包括源数据链路层地址与目的数据链路层地址,其中,所述源数据链路层地址为所述第一网络设备的数据链路层地址,所述目的数据链路层地址与所述第二网络设备的数据链路层地址相匹配,所述第二网络设备与所述第一网络设备均为所述自组织网络中的自组织设备;
    处理模块,用于通过判断所述第二网络设备的设备标识是否与所述L2 ACP报文的所述目的设备标识相匹配,处理所述接收模块接收的所述L2 ACP报文。
  35. 根据权利要求34所述的第二网络设备,其特征在于,所述数据链路层的帧为符合以太网协议定义的帧,所述数据链路层的帧的类型Type字段的Type值指示所述数据链路层的帧的数据载荷字段承载的是所述L2 ACP报文。
  36. 根据权利要求34或35所述的第二网络设备,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为邻居单播报文,其中,所述数据链路层的帧的目的数据链路层地址为所述目标设备的数据链路层地址;
    其中,所述处理模块具体用于,确定所述目的设备标识为所述第二网络设备的设备标识,并解析所述L2 ACP报文。
  37. 根据权利要求34或35所述的第二网络设备,其特征在于,所述L2 ACP报文的报文头包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为非邻居单播报文,其中,所述数据链路层的帧的目的数据链 路层地址为广播数据链路层地址;
    其中,所述处理模块具体用于,当确定所述第二网络设备的设备标识与所述目的设备标识相匹配时,解析所述L2 ACP报文,并缓存所述L2 ACP报文;
    处理模块具体用于,当确定所述第二网络设备的设备标识与所述目的设备标识不匹配时,缓存所述L2 ACP报文,并根据所述数据链路层的帧的目的数据链路层地址向所述第二网络设备的邻居设备转发基于所述数据链路层的帧封装后的所述L2 ACP报文。
  38. 根据权利要求34或35所述的第二网络设备,其特征在于,所述L2 ACP报文的报文头还包括标志位字段,所述标志位字段的值用于指示所述L2 ACP报文为广播报文,其中,所述数据链路层的帧的目的数据链路层地址为广播数据链路层地址;
    其中,所述处理模块具体用于,确定所述第二网络设备的设备标识与所述目的设备标识相匹配,解析所述L2 ACP报文,并缓存所述L2 ACP报文,以及根据所述数据链路层的帧的目的数据链路层地址向所述第二网络设备的邻居设备转发基于所述数据链路层的帧封装后的所述L2 ACP报文。
  39. 根据权利要求37或38所述的第二网络设备,其特征在于,所述L2 ACP报文的报文头中还包括用于唯一标识所述L2 ACP报文的报文ID,
    其中,所述处理模块具体用于,当确定本地未缓存所述报文ID时,通过判断所述第二网络设备的设备标识是否与所述目的设备标识相匹配,处理所述L2 ACP报文。
  40. 根据权利要求37至39中任一项所述的第二网络设备,其特征在于,所述L2 ACP报文的报文头中还包括定时信息,所述定时信息用于指示所述L2 ACP报文的接收设备在缓存所述L2 ACP报文的时间超过预设时长时,清除所述L2 ACP报文,
    所述第二网络设备还包括:
    缓存清除模块,用于当确定缓存所述L2 ACP报文的时间超过所述定时信息所指示的预设时长时,清除所述L2 ACP报文。
  41. 一种基于自组织网络的系统,其特征在于,包括如上述权利要求21至23中任一项所述的网络设备与上述权利要求24至26中任一项所述的Registrar设备。
  42. 一种基于自组织网络的系统,其特征在于,包括如上述权利要求27至33中任一项所述的网络设备与上述权利要求34至40中任一项所述的网络设备。
PCT/CN2015/084772 2015-07-22 2015-07-22 一种基于数据链路层的通信方法、设备和系统 WO2017012089A1 (zh)

Priority Applications (6)

Application Number Priority Date Filing Date Title
CN201580062638.0A CN107005430B (zh) 2015-07-22 2015-07-22 一种基于数据链路层的通信方法、设备和系统
PCT/CN2015/084772 WO2017012089A1 (zh) 2015-07-22 2015-07-22 一种基于数据链路层的通信方法、设备和系统
EP19191634.5A EP3633921B1 (en) 2015-07-22 2015-07-22 Data link layer-based communication method, device, and system
EP15898645.5A EP3319272B1 (en) 2015-07-22 2015-07-22 Communication method, device and system based on data link layer
US15/875,028 US10560378B2 (en) 2015-07-22 2018-01-19 Data link layer-based communication method, device, and system
US16/745,877 US11153207B2 (en) 2015-07-22 2020-01-17 Data link layer-based communication method, device, and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/084772 WO2017012089A1 (zh) 2015-07-22 2015-07-22 一种基于数据链路层的通信方法、设备和系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/875,028 Continuation US10560378B2 (en) 2015-07-22 2018-01-19 Data link layer-based communication method, device, and system

Publications (1)

Publication Number Publication Date
WO2017012089A1 true WO2017012089A1 (zh) 2017-01-26

Family

ID=57833673

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/084772 WO2017012089A1 (zh) 2015-07-22 2015-07-22 一种基于数据链路层的通信方法、设备和系统

Country Status (4)

Country Link
US (2) US10560378B2 (zh)
EP (2) EP3633921B1 (zh)
CN (1) CN107005430B (zh)
WO (1) WO2017012089A1 (zh)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3633921B1 (en) 2015-07-22 2021-07-21 Huawei Technologies Co., Ltd. Data link layer-based communication method, device, and system
US10819685B2 (en) 2018-03-02 2020-10-27 Futurewei Technologies, Inc. Lightweight secure autonomic control plane
US11265714B2 (en) * 2018-12-28 2022-03-01 Cable Television Laboratories, Inc. Systems and methods for subscriber certificate provisioning
CN110035016B (zh) * 2019-02-26 2023-03-10 北京钰安信息科技有限公司 一种数据传输方法及装置
US11558363B2 (en) * 2019-08-19 2023-01-17 Verizon Patent And Licensing Inc. Method and device for provisioning a node in a wireless network

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1897518A (zh) * 2005-07-14 2007-01-17 华为技术有限公司 一种分布式的身份证书签发方法
CN101192928A (zh) * 2006-12-01 2008-06-04 华为技术有限公司 移动自组织网络的认证方法、网络和系统
CN102148756A (zh) * 2011-01-26 2011-08-10 武汉邮电科学研究院 一种基于6LoWPAN邻居发现的树状路由方法
WO2013177069A1 (en) * 2012-05-22 2013-11-28 Cisco Technology, Inc. System and method for enabling unconfigured devices to join an autonomic network in a secure manner

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101399814B (zh) * 2007-09-30 2012-08-08 华为技术有限公司 验证数据链路层地址与其发送方关系的方法、系统及装置
JP5434975B2 (ja) * 2011-07-07 2014-03-05 横河電機株式会社 通信装置、通信システム、及び通信方法
US9515868B2 (en) * 2012-03-23 2016-12-06 Nec Corporation System and method for communication
US10257161B2 (en) * 2012-05-22 2019-04-09 Cisco Technology, Inc. Using neighbor discovery to create trust information for other applications
CN102811143A (zh) * 2012-07-25 2012-12-05 北京星网锐捷网络技术有限公司 数据链路层故障监测方法及装置、网络设备
US10091102B2 (en) * 2013-01-09 2018-10-02 Cisco Technology, Inc. Tunnel sub-interface using IP header field
EP3633921B1 (en) 2015-07-22 2021-07-21 Huawei Technologies Co., Ltd. Data link layer-based communication method, device, and system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1897518A (zh) * 2005-07-14 2007-01-17 华为技术有限公司 一种分布式的身份证书签发方法
CN101192928A (zh) * 2006-12-01 2008-06-04 华为技术有限公司 移动自组织网络的认证方法、网络和系统
CN102148756A (zh) * 2011-01-26 2011-08-10 武汉邮电科学研究院 一种基于6LoWPAN邻居发现的树状路由方法
WO2013177069A1 (en) * 2012-05-22 2013-11-28 Cisco Technology, Inc. System and method for enabling unconfigured devices to join an autonomic network in a secure manner

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3319272A4 *

Also Published As

Publication number Publication date
EP3633921B1 (en) 2021-07-21
CN107005430A (zh) 2017-08-01
EP3319272B1 (en) 2019-09-04
CN107005430B (zh) 2020-03-31
EP3319272A1 (en) 2018-05-09
US10560378B2 (en) 2020-02-11
EP3633921A1 (en) 2020-04-08
US20180145905A1 (en) 2018-05-24
US11153207B2 (en) 2021-10-19
US20200153735A1 (en) 2020-05-14
EP3319272A4 (en) 2018-05-09

Similar Documents

Publication Publication Date Title
US11838203B2 (en) Multipath data transmission method and device
US11463527B2 (en) User plane model for non-3GPP access to fifth generation core network
CN110087236B (zh) 用于通过无线网络与匿名主机建立安全通信会话的协议
US11153207B2 (en) Data link layer-based communication method, device, and system
US10863422B2 (en) Mechanisms for ad hoc service discovery
CN107580768B (zh) 报文传输的方法、装置和系统
CN106376003B (zh) 检测无线局域网连接及无线局域网数据发送方法及其装置
EP3706500A1 (en) Device-to-device communication among wireless communication devices using group id and application id
US20130182651A1 (en) Virtual Private Network Client Internet Protocol Conflict Detection
US20130250934A1 (en) Rapid local address assignment for wireless communication networks
KR102059282B1 (ko) 통신 네트워크들에서의 향상된 이웃 발견
US20150200938A1 (en) Method and device for transmitting wireless information
CN113541989A (zh) 一种网络切片检测方法、装置和存储介质
US7969933B2 (en) System and method for facilitating a persistent application session with anonymity between a mobile host and a network host
US9503418B2 (en) Method and apparatus for obtaining remote IP address
WO2018054272A1 (zh) 数据的发送方法和装置、计算机存储介质
JP5034534B2 (ja) 通信システム
WO2014169590A1 (zh) 一种数据业务通信方法、设备及系统
WO2016205673A1 (en) Enhanced address registration in constrained networks
CN107113295B (zh) 一种通信方法、装置和系统
CN116192986A (zh) 一种数据传输方法
KR20070021903A (ko) 무선 휴대 인터넷 시스템에서의 방송형 메시지 전송 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15898645

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2015898645

Country of ref document: EP