WO2017166936A1 - 一种实现地址管理的方法、装置、aaa服务器及sdn控制器 - Google Patents

一种实现地址管理的方法、装置、aaa服务器及sdn控制器 Download PDF

Info

Publication number
WO2017166936A1
WO2017166936A1 PCT/CN2017/073747 CN2017073747W WO2017166936A1 WO 2017166936 A1 WO2017166936 A1 WO 2017166936A1 CN 2017073747 W CN2017073747 W CN 2017073747W WO 2017166936 A1 WO2017166936 A1 WO 2017166936A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
address
sdn controller
authentication
aaa server
Prior art date
Application number
PCT/CN2017/073747
Other languages
English (en)
French (fr)
Inventor
吴波
王怀滨
张如通
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2017166936A1 publication Critical patent/WO2017166936A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/30Managing network names, e.g. use of aliases or nicknames
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/5014Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]

Definitions

  • Embodiments of the present invention relate to data communication technologies, and in particular, to a method and apparatus for implementing address management, an Authentication and Authorization Accounting (AAA) server, and a Software Defined Network (SDN) controller.
  • AAA Authentication and Authorization Accounting
  • SDN Software Defined Network
  • the virtualization technology adopts a common hardware architecture, and the resource pool management of the general hardware improves the efficiency of service deployment to some extent.
  • the wired data communication network provides Internet (Internet) access and Internet value-added services for home users and enterprise users.
  • the access control in the related art is implemented by a dedicated device such as a Broadband Access Accessor (BRAS), a Service Router (SR), or a Broadband Network Gateway (BNG).
  • BRAS Broadband Access Accessor
  • SR Service Router
  • BNG Broadband Network Gateway
  • the current standards organization proposes to extend the virtualization technology based on the existing dedicated device networking to better resolve the fast forwarding of service data and flexible expansion of services.
  • the Broadband Forum (BBF) standard organization proposes a virtual gateway (VG, Virtual Gateway) to be deployed on the physical gateway of the user's network.
  • the RG Real-Residential Gateway
  • Flexible deployment of services, the WT-317 protocol in the related technology defines the functional requirements of the VG.
  • the embodiment of the invention provides a method for implementing address management, including:
  • the software-defined network SDN controller generates the authentication request information for performing the home gateway RG authentication according to the identification and authentication related information from the first device, and sends the generated RG-authenticated authentication request information to the authentication and authorization charging AAA server;
  • the SDN controller After the SDN controller completes the RG authentication, the SDN controller allocates the virtual gateway VG to the RG according to the user subscription information;
  • the SDN controller configures an address for the VG according to the authentication response information from the AAA server;
  • the authentication response message is: the content of the address management information that is sent to the SDN controller and carried by the AAA server for the VG after the AAA server completes the authentication;
  • the VG is a VG that assigns address management information by an SDN controller or an AAA server.
  • the method further includes: the SDN controller sending the LAN LAN interface access information of the pre-stored VG to the first device.
  • the LAN interface access information of the VG includes:
  • the virtual gateway reachable by the VG LAN interface uniquely encodes the VG-ID information, and/or the connection information of the VG LAN interface.
  • the method further includes:
  • the SDN controller sends the network address translation NAT public network address assigned to the VG and the interface port information of the NAT public network of the VG to the NAT device shared by the VG.
  • the method further includes: the SDN controller separately establishing a corresponding session control management for each RG;
  • the session control management includes: a VLAN associated with the RG, and/or MPLS subnet information associated with the RG, and/or VG-ID information, and/or LAN interface information of the VG, and/or a wide area network WAN of the VG. Interface information, and/or public network address of the NAT public network of the VG, and/or port information of the NAT of the VG, and/or allocation of VG address management information, and/or quality of service QOS, and/or security policy, and/or Or operation management and maintenance OAM management information for recording and maintenance.
  • the authentication request information includes identification and authentication related information
  • the identification and authentication related information includes: a tunnel identifier of the RG encapsulated in the dynamic host configuration protocol DHCP request, and/or a tunnel source address of the RG, and/or a virtual local area network VLAN associated with the RG, and/or associated with the RG
  • the multi-protocol label exchanges MPLS subnet information, and/or line identification information, and/or a broadband network gateway BNG port number that receives the DHCP request, and/or a message containing the content of the DHCP request.
  • the invention further provides a method for implementing address management, comprising:
  • the SDN controller receives the address pool ID information from the AAA server;
  • the SDN controller allocates address management information to the VG according to the pre-configured address pool information and the received address pool ID information;
  • VG is the VG assigned by the SDN controller to the RG.
  • the method further includes:
  • the SDN controller allocates address management information to the VG based on the address pool information and the address pool ID information, determines an IP address assigned to the VG, and sends the determined IP address assigned to the VG to the AAA server.
  • the address management information includes: an IP address related to a wide area network WAN interface of the VG, and/or a public network address of the network address translation NAT of the VG, and interface port information of the NAT of the VG.
  • the present invention also provides a method for implementing address management, including:
  • the AAA server After completing the RG authentication, the AAA server allocates address management information to the VG, and feeds back to the SDN controller an authentication response message carrying the content of the address management information allocated for the VG;
  • the VG is a VG allocated by the SDN controller to the RG.
  • the method further includes:
  • the AAA server sends user subscription information to the SDN controller.
  • the allocating address management information for the VG includes:
  • the AAA server directly allocates address management information to the VG;
  • the address management information includes: an IP address related to a WAN WAN interface of the VG, and / Or the network address of the VG translates the public network address of the NAT and the interface information of the NAT of the VG.
  • the invention further provides a method for implementing address management, comprising:
  • the first device acquires the identification and authentication related information, and sends the information to the software defined network SDN controller, so that the SDN controller generates the authentication request information for performing the RG authentication according to the identification and authentication related information.
  • the obtaining the identification and authentication related information and transmitting the information to the SDN controller comprises:
  • the first device obtains the identification and authentication related information from the information carried in the DHCP request by using the received dynamic host configuration protocol DHCP request.
  • the DHCP request is from a broadband network gateway BNG or a home gateway RG.
  • the first device comprises: a network function virtualization infrastructure gateway NFVI-GATEWAY or BNG.
  • the identifying and authenticating related information includes: a tunnel identifier of the encapsulated RG in the DHCP request, and/or a tunnel source address of the RG, and/or with the RG Associated virtual local area network VLAN, and/or multi-protocol label switched MPLS subnet information associated with the RG, and/or line identification information, and/or a message containing DHCP request content;
  • the identification and authentication related information includes: line identification information, and/or a BNG port number for receiving a DHCP request, and/or a message including a DHCP request content.
  • the method further includes:
  • the first device transmits a communication address of the first device to the SDN controller to cause the SDN controller to communicate with the first device according to the received communication address of the first device.
  • the method further includes:
  • the first device extends the connection of the RG to the first device to the network where the local area network LAN interface of the virtual gateway VG is located.
  • the invention also provides an SDN controller for implementing address management, comprising: generating a sending list Unit, allocation unit, and address configuration unit;
  • the generating and sending unit is configured to generate, according to the identification and authentication related information from the first device, authentication request information for performing RG authentication, and send the generated RG authentication authentication request information to the AAA server;
  • the allocating unit is configured to allocate VG to the RG according to the user subscription information after the AAA server completes the RG authentication;
  • the address configuration unit is configured to: configure, by the SDN controller, an address for the VG according to the authentication response information from the AAA server;
  • the authentication response message is: the content of the address management information that is sent to the SDN controller and carried by the AAA server for the VG after the AAA server completes the authentication;
  • the VG is a VG that assigns address management information by an SDN controller or an AAA server.
  • the SDN controller further includes an access information sending unit, configured to send the LAN interface access information of the pre-stored VG to the first device.
  • the SDN controller further includes a sending unit, configured to: after the VG is allocated to the RG, if the NAT device shared with the allocated VG is included, the NAT public network address and the VG to be allocated to the VG The port information of the NAT public network is sent to the NAT device shared by the VG.
  • the SDN controller further includes a session control unit, configured to separately establish a corresponding session control session management for each RG;
  • the session control management includes: a VLAN associated with the RG, and/or MPLS subnet information associated with the RG, and/or VG-ID information, and/or LAN interface information of the VG, and/or a wide area network WAN of the VG. Interface information, and/or public network address of the NAT public network of the VG, and/or port information of the NAT of the VG, and/or allocation of VG address management information, and/or QOS, and/or security policy, and/or OAM Management information is recorded and maintained.
  • the invention further provides an SDN controller for implementing address management, comprising: receiving an address pool number unit and an allocation address unit; wherein
  • the receiving address pool number unit is configured to receive the address pool unique number ID information from the AAA server;
  • the allocation address unit is used according to the pre-configured address pool information and the received address pool ID information. Assign address management information to the VG;
  • VG is the VG assigned by the SDN controller to the RG.
  • the SDN controller further includes an uplink sending unit,
  • the present invention further provides an AAA server for implementing address management, including an allocation information unit, configured to allocate address management information for the VG after completing the authentication of the RG, and feed back to the SDN controller the address assigned to the VG.
  • An authentication response message that manages the content of the information
  • VG is the VG assigned by the SDN controller to the RG.
  • the allocation information unit is specifically configured to directly allocate address management information to the VG;
  • the address management information includes: an IP address related to the WAN interface of the VG, and/or a public network address of the network address translation NAT of the VG and an interface port information of the NAT of the VG.
  • the AAA server further includes a subscription information sending unit, configured to send the user subscription information to the SDN controller before the VG is allocated to the RG.
  • a subscription information sending unit configured to send the user subscription information to the SDN controller before the VG is allocated to the RG.
  • the present invention also provides an apparatus for implementing address management, comprising: a related information sending unit, configured to acquire identification and authentication related information, and send the information to an SDN controller, so that the SDN controller generates the information according to the identification and authentication related information.
  • a related information sending unit configured to acquire identification and authentication related information, and send the information to an SDN controller, so that the SDN controller generates the information according to the identification and authentication related information.
  • the related information sending unit is further configured to:
  • the related information sending unit is specifically configured to: send the identification and authentication related information included in the DHCP request to the SDN controller according to the received DHCP request, so that the SDN controller generates the information according to the identification and the authentication related information.
  • Authentication request information for RG authentication is specifically configured to: send the identification and authentication related information included in the DHCP request to the SDN controller according to the received DHCP request, so that the SDN controller generates the information according to the identification and the authentication related information.
  • the apparatus further includes an extension unit for extending the connection of the RG to the device to a network where the LAN interface of the VG is located.
  • the present application also provides a computer readable storage medium storing computer executable instructions for performing a method of implementing address management.
  • the technical solution of the present application includes: a software defined network (SDN) controller generates and sends an authentication request for performing home gateway RG authentication according to the received identification and authentication related information of the home gateway (RG) from the first device.
  • the information is sent to the AAA server; the AAA server allocates address management information to the VG after the RG is authenticated; the SDN controller allocates the virtual gateway (VG) to the RG according to the user subscription information after the AAA server completes the RG authentication.
  • the AAA server assigns address management information to the VG, and the SDN controller configures the address for the VG according to the authentication response information from the AAA server carrying the content of the address management information allocated for the VG.
  • the method of the embodiment of the present invention allocates a VG to the RG through the SDN controller, and allocates address management information to the VG through the AAA server, thereby implementing address management after the VG is created.
  • FIG. 1 is a flowchart of a method for implementing address management according to an embodiment of the present invention
  • FIG. 2 is a flowchart of a method for implementing address management according to another embodiment of the present invention.
  • FIG. 3 is a flowchart of a method for implementing address management according to another embodiment of the present invention.
  • FIG. 4 is a flowchart of a method for implementing address management according to still another embodiment of the present invention.
  • FIG. 5 is a structural block diagram of a first apparatus for implementing address management according to an embodiment of the present invention.
  • FIG. 6 is a structural block diagram of an SDN controller for implementing address management according to an embodiment of the present invention.
  • FIG. 7 is a structural block diagram of another SDN controller implementing address management according to an embodiment of the present invention.
  • FIG. 8 is a structural block diagram of an AAA server for implementing address management according to an embodiment of the present invention.
  • FIG. 9 is a schematic diagram of a network structure of an application example.
  • FIG. 10 is a flowchart of a method according to a first application example of the present invention.
  • FIG. 11 is a flowchart of a method according to a second application example of the present invention.
  • FIG. 12 is a flowchart of a method according to a third application example of the present invention.
  • VG is usually tens of thousands, and the number is huge.
  • an AAA server is used to allocate a VG-ID to an RG. Since the VG is virtual, it may be faulty, powered down, or changed. When the RG fails, powers down, or changes, the VG server needs to re-allocate the VG-ID to the RG. The implementation is complicated.
  • the VG WAN-related address management information allocation method is not provided in the related art; that is, how to dynamically address the VG. Management, an effective solution has not been proposed in related technologies.
  • FIG. 1 is a flowchart of a method for implementing address management according to an embodiment of the present invention. As shown in FIG. 1 , the method includes:
  • Step 100 The first device acquires identification and authentication related information, and sends the information to a software defined network (SDN) controller.
  • SDN software defined network
  • the first device may obtain the identification and authentication related information from the information carried in the DHCP request by using the received Dynamic Host Configuration Protocol (DHCP) request.
  • DHCP Dynamic Host Configuration Protocol
  • the SDN controller may generate authentication request information for performing RG authentication according to the identification and authentication related information.
  • the DHCP request comes from a Broadband Network Gateway (BNG) or RG.
  • BNG Broadband Network Gateway
  • RG Broadband Network Gateway
  • the DHCP request may be from the BNG, and the DHCP request from the BNG may include the RG sending the BNG DHCP request.
  • the first device includes: a network function virtualization infrastructure gateway (NFVI-GATEWAY) or a BNG.
  • NFVI-GATEWAY network function virtualization infrastructure gateway
  • BNG BNG
  • the identification and authentication related information includes: a tunnel identifier of the encapsulated RG in the DHCP request, and/or a tunnel source address of the RG, and/or a virtual local area network associated with the RG a VLAN, and/or multi-protocol label switching MPLS subnet information associated with the RG, and/or line identification information, and/or a message containing DHCP request content;
  • the identification and authentication related information includes: line identification information, and / Or receive the BNG port number of the DHCP request, and/or the message containing the content of the DHCP request.
  • the method of the embodiment of the present invention further includes a step 101 when the identification and authentication related information is sent to the SDN controller:
  • Step 101 The first device sends a communication address of the first device to the SDN controller, so that the SDN controller communicates with the first device according to the received communication address of the first device.
  • the communication address of the first device may include a tunnel destination address; when the first device is BNG, the communication address of the first device may include the BNG being sent to the SDN controller. Its own number and the BNG port number that receives the DHCP request.
  • the method of the embodiment of the present invention further includes:
  • the first device extends the connection of the RG to the first device to the network where the local area network (LAN) interface of the virtual gateway (VG) is located.
  • LAN local area network
  • VG virtual gateway
  • the network where the VG LAN interface is located includes the network where the SDN controller allocates the VG LAN interface to the RG according to the user subscription information after the AAA server completes the RG authentication.
  • the method of the embodiment of the present invention can be applied to the IPV4, the IPV6, and the NAT network.
  • the implementation method of the present invention is implemented in different networks, part of the information needs to be adaptively adjusted according to different protocols, and the technology provided based on the present invention is specifically implemented.
  • the solution is easy to implement and is not intended to limit the scope of the invention.
  • FIG. 2 is a flowchart of a method for implementing address management according to another embodiment of the present invention. As shown in FIG. 2, the method includes:
  • Step 200 The software defined network (SDN) controller generates authentication request information for performing RG authentication according to the identification and authentication related information from the first device, and sends the generated RG authentication authentication request information to the authentication authorization charging (AAA). server.
  • SDN software defined network
  • Step 201 After the AAA controller completes the RG authentication, the SDN controller allocates a VG to the RG according to the user subscription information.
  • the VG is a VG that assigns address management information by an SDN controller or an AAA server.
  • the user subscription information includes the basic configuration of the user service, including for the network. Connected IP address information, user bandwidth information, quality of service information, security control related information, and user value-added service information (such as home control, firewall, etc.).
  • assigning a VG to the RG according to the user subscription information may include: adopting a template mode, and selecting a basic service template, corresponding to a basic IPv4VG, a basic IPv6VG, or an IPv4 private VG, and an extended service template, corresponding to a home control service, a home security service, etc. .
  • the AAA may send the service template ID to the SDN controller, and the SDN controller creates a VG supporting different services according to the template ID combination.
  • Step 202 The SDN controller configures an address for the VG according to the authentication response information from the AAA server.
  • the authentication response message is: the content that carries the address management information allocated by the AAA server to the VG, which is fed back to the SDN controller after the AAA server completes the authentication.
  • the authentication request information includes identification and authentication related information
  • the identification and authentication related information includes: a tunnel identifier of the RG encapsulated in the DHCP request, and/or a tunnel source address of the RG, and/or a VLAN associated with the RG, and/or MPLS subnet information associated with the RG, and/or Or line identification information, and/or BNG port number to receive the DHCP request, and/or a message containing the content of the DHCP request.
  • the method of the embodiment of the present invention further includes: the SDN controller sends the LAN interface access information of the pre-stored VG to the first device.
  • the VG LAN interface access information includes:
  • the virtual gateway unique code (VG-ID) information that can be reached by the VG's LAN interface, and/or the connection information of the VG's LAN interface.
  • the method of the embodiment of the present invention further includes:
  • the SDN controller sends the network address translation NAT public network address assigned to the VG and the port information of the NAT public network of the VG to the NAT device shared by the VG.
  • the method of the embodiment of the present invention further includes: the SDN controller separately establishing corresponding session control (session) management for each RG;
  • Session control management includes: VLANs associated with RGs, and/or MPLS associated with RGs Subnet information, and/or VG-ID information, and/or WAN LAN interface information, and/or VG WAN interface information, and/or VG's public network address of the NAT public network, and/or NAT of the VG Port information, and/or assigned VG address management information, and/or quality of service (QOS), and/or security policies, and/or operational management maintenance (OAM) management information for recording and maintenance.
  • VLANs associated with RGs and/or MPLS associated with RGs Subnet information, and/or VG-ID information, and/or WAN LAN interface information, and/or VG WAN interface information, and/or VG's public network address of the NAT public network, and/or NAT of the VG Port information, and/or assigned VG address management information, and/or quality of service (QOS), and/or security policies, and/or operational management maintenance (OAM) management information for recording and
  • the method of the embodiment of the present invention allocates a VG to the RG through the SDN controller, and implements address management after the VG is created.
  • the method of the embodiment of the present invention can be applied to IPV4, IPV6, and NAT networks.
  • the implementation method of the present invention is implemented in different networks, part of the information needs to be adaptively adjusted according to different protocols, and the technology provided based on the present invention is specifically implemented.
  • the solution is easy to implement and is not intended to limit the scope of the invention.
  • FIG. 3 is a flowchart of a method for implementing address management according to another embodiment of the present invention. As shown in FIG. 3, the method includes:
  • Step 301 After completing the RG authentication, the AAA server allocates address management information to the VG, and feeds back to the SDN controller an authentication response message carrying the content of the address management information allocated for the VG.
  • the VG is a VG allocated by the SDN controller to the RG.
  • the AAA server in the implementation method of the present invention may be configured in conjunction with the DHCP server, that is, the function of the DHCP server may be implemented in the AAA server, and the information required by the embodiment of the present invention included in the DHCP server may be different.
  • a person skilled in the art can make an adaptive adjustment according to the actual situation.
  • the specific implementation is easy to implement based on the technical solution provided by the present invention, and is not intended to limit the scope of protection of the present invention.
  • assigning address management information to the VG and assigning the VG to the RG can be implemented separately, and there is no timing relationship between the two; when both are completed, the result is that the VG allocated for the RG is assigned address management information.
  • assigning address management information to the VG includes:
  • the AAA server directly assigns address management information to the VG;
  • the address management information includes: an IP address related to a WAN WAN interface of the VG, and/or a public address of a network address translation (NAT) of the VG and a port information of the NAT of the VG.
  • IP address related to a WAN WAN interface of the VG
  • NAT network address translation
  • the AAA server has address management information, or the AAA server queries from the operator operation and maintenance management system.
  • the operator operation and maintenance management system stores the address management information created when the user signs up.
  • the method of the embodiment of the present invention further includes the step 300: the AAA server sends the user subscription information to the SDN controller.
  • the address management information is allocated to the VG through the AAA server, and the address management after the VG is created is implemented.
  • the method of the embodiment of the present invention can be applied to the IPV4, the IPV6, and the NAT network.
  • the implementation method of the present invention is implemented in different networks, some information needs to be adaptively adjusted according to different protocols, and the partial adjustment does not require any person skilled in the art. Carry out creative work.
  • FIG. 4 is a flowchart of a method for implementing address management according to still another embodiment of the present invention. As shown in FIG. 4, the method includes:
  • Step 400 The SDN controller receives the address pool ID information from the AAA server.
  • Step 401 The SDN controller allocates address management information to the VG according to the pre-configured address pool information and the received address pool ID information.
  • the VG is a VG allocated by the SDN controller to the RG.
  • the address pool ID represents an IP address segment and a port end, for example, 130.0.0.1-200, port number 2000-3000, and the SDN controller allocates different VGs from the IP address segment and the port end range respectively.
  • Corresponding management information consisting of IP address and port range; the IP addresses of different VGs can be the same, and the port range is different when the IP addresses are the same.
  • the address management information includes: an IP address related to the WAN interface of the VG, and/or a public address of the network address translation NAT of the VG and an interface port information of the NAT of the VG;
  • the method of the embodiment of the present invention further includes:
  • the SDN controller allocates address management information to the VG based on the address pool information and the address pool ID information, determines an IP address assigned to the VG, and sends the determined IP address assigned to the VG to the AAA server.
  • sending the determined IP address to the AAA server can be used for security control. For example, traceability.
  • the present application also provides a computer readable storage medium storing computer executable instructions for performing any of the methods described above for implementing address management.
  • the present invention also provides an apparatus for implementing a method of address management, comprising at least a memory and a processor for executing executable instructions, wherein
  • the authentication response message is configured according to the authentication response information from the AAA server.
  • the authentication response message is: after the AAA server completes the authentication, the AAA server that feeds back the AAA server is assigned to the VG.
  • the content of the address management information wherein, the VG is a VG that is assigned address management information by the SDN controller or the AAA server;
  • VG is a VG allocated by the SDN controller for the RG;
  • the VG is assigned address management information, and the SDN controller feeds back an authentication response message carrying the content of the address management information allocated for the VG; wherein, the VG is the VG allocated by the SDN controller for the RG. ;
  • the identification and authentication related information is obtained and sent to the software defined network SDN controller, so that the SDN controller generates the authentication request information for performing RG authentication according to the identification and authentication related information.
  • FIG. 5 is a structural block diagram of a first device for implementing address management according to an embodiment of the present invention.
  • the method includes: a related information sending unit, configured to acquire identification and authentication related information, and send the information to an SDN controller.
  • the method may be configured to: send the identification and authentication related information included in the DHCP request to the SDN controller according to the received DHCP request, so that the SDN controller performs the identification and authentication according to the The related information generates authentication request information for performing RG authentication.
  • the related information sending unit is further configured to:
  • the communication address of the transmitting device is sent to the SDN controller to cause the SDN controller to communicate with the device according to the communication address of the received device.
  • the apparatus of the embodiment of the present invention further includes an extension unit for extending the connection of the RG and the device to the network where the LAN interface of the VG is located.
  • FIG. 6 is a structural block diagram of an SDN controller for implementing address management according to an embodiment of the present invention. As shown in FIG. 6, the method includes: generating a sending unit, an allocating unit, and an address configuring unit;
  • the generating and sending unit is configured to generate, according to the identification and authentication related information from the first device, authentication request information for performing RG authentication, and send the generated RG authentication authentication request information to the AAA server;
  • the allocating unit is configured to allocate VG to the RG according to the user subscription information after the AAA server completes the RG authentication;
  • the address configuration unit is configured to: configure, by the SDN controller, an address for the VG according to the authentication response information from the AAA server;
  • the authentication response message includes: content that is fed back to the SDN controller and carries the address management information allocated by the AAA server for the VG after the AAA server completes the authentication;
  • the VG is a VG that assigns address management information by an SDN controller or an AAA server.
  • the SDN controller further includes an address pool sending unit, configured to send the pre-configured address pool information to the AAA server.
  • the SDN controller further includes an access information sending unit, configured to send the LAN interface access information of the pre-stored VG to the first device.
  • the SDN controller further includes a sending unit, configured to allocate a VG to the RG, and if the NAT device that is shared with the allocated VG is included, the NAT public network address and the VG that are allocated to the VG are The NAT information of the public network is sent to the NAT device shared with the VG.
  • the SDN controller further includes a session control unit, configured to separately establish a corresponding session control session management for each RG;
  • Session control management includes: a VLAN associated with the RG, and/or MPLS subnet information associated with the RG, and/or VG-ID information, and/or VG LAN interface information, and/or WAN wide area network WAN interface information, And/or the public network address of the NAT public network of the VG, and/or the port information of the NAT of the VG, and/or the allocation of VG address management information, and/or QOS, and/or security policy, and/or OAM management information. Record and maintain.
  • FIG. 7 is a structural block diagram of an SDN controller for implementing address management according to an embodiment of the present invention, as shown in FIG. 7, including a receiving address pool numbering unit and an allocation address unit;
  • the receiving address pool number unit is configured to receive the address pool unique number ID information from the AAA server;
  • the allocation address unit is configured to allocate address management information to the VG according to the pre-configured address pool information and the received address pool ID information.
  • the VG is a VG allocated by the SDN controller to the RG.
  • the SDN controller further includes: an uplink sending unit, configured to allocate address management information for the VG according to the address pool information and the address pool ID information, determine an IP address allocated for the VG, and determine the determined IP address to be the VG. Send it to the AAA server.
  • an uplink sending unit configured to allocate address management information for the VG according to the address pool information and the address pool ID information, determine an IP address allocated for the VG, and determine the determined IP address to be the VG. Send it to the AAA server.
  • FIG. 8 is a structural block diagram of an AAA server for implementing address management according to an embodiment of the present invention. As shown in FIG. 8, the method includes: an allocation information unit, configured to allocate address management information for a VG, and to an SDN controller after performing authentication on the RG. The feedback response message carrying the content of the address management information assigned to the VG is fed back.
  • the VG is a VG allocated by the SDN controller to the RG.
  • the allocation information unit is specifically configured to directly allocate address management information to the VG;
  • the address management information includes: an IP address related to a wide area network (WAN) interface of the VG, and/or a public network address of a network address translation (NAT) of the VG, and a port information of the NAT of the VG.
  • WAN wide area network
  • NAT network address translation
  • IP address associated with the WAN interface of the VG includes the IPv4, and/or IPv6 address of the WAN interface of the VG.
  • the AAA server of the embodiment of the present invention further includes a subscription information sending unit, configured to send the user subscription information to the SDN controller before the VG is allocated to the RG.
  • FIG. 9 is a schematic diagram of the network structure of the application example.
  • the network structure includes: a home gateway, a virtual gateway, a broadband network gateway, and an NFVI. -GATEWAY, SDN controller and AAA server; etc.; the virtual gateway is located in the network where the network function is virtualized.
  • the Residential Gateway includes a Layer 3 routing access function through Layer 3 tunnel encapsulation and VG interworking on the WAN interface; the Virtual Gateway (VG) is located in the Network Function Virtualization (NFV) network.
  • the first device is NFVI-GATEWAY, which acts as a standalone device and provides RG access for the VG.
  • FIG. 10 is a flowchart of a method according to a first application example of the present invention. As shown in FIG. 8, the method includes:
  • Step 1000 The RG sends a dynamic host configuration protocol (DHCP) request to the BNG providing access;
  • DHCP dynamic host configuration protocol
  • the DHCP request is a protocol (IP) address request for interconnection between networks of the RG's wide area network (WAN) interface.
  • IP protocol
  • the intermediate device adds the line identifier. information.
  • the intermediate device may include: a digital subscriber line access multiplexer (Digital Dilamolt), an optical line terminal or an access switch (OLT), and the like.
  • Step 1001 The BNG receives the DHCP request, and initiates the RG authentication and the VG access AAA request to the authentication and authorization charging (AAA) server.
  • the RG authentication and the VG access AAA request carry the line identification information added when the DHCP request passes through the intermediate device. .
  • Step 1002 The AAA server authenticates the RG according to the received RG authentication and the VG access AAA request.
  • the AAA server can allocate an optional NFV network and VG related access NFVI-GATEWAY through policies.
  • the AAA server sends the RG WAN interface IP address and the access device NFVI-GATEWAY information and connection establishment information of the data center where the VG is located, such as tunnel encapsulation information, such as virtual scalable local area network (VXLAN), general routing encapsulation (GRE), etc.
  • tunnel encapsulation information such as virtual scalable local area network (VXLAN), general routing encapsulation (GRE), etc.
  • VXLAN virtual scalable local area network
  • GRE general routing encapsulation
  • Step 1003 RG and NFVI-GATEWAY establish a connection according to the RG's WAN IP address, NFVI-GATEWAY information, and connection establishment information.
  • Step 1004 RG sends a DHCP request to NFVI-GATEWAY
  • the DHCP request is an IP address request for the local area network (LAN) interface of the RG.
  • Step 1005 NFVI-GATEWAY receives the DHCP request from the RG, and sends the identification and authentication related information included in the DHCP request to the SDN controller.
  • the identification and authentication related information includes a tunnel identifier of the RG encapsulated in the DHCP request, and/or a tunnel source address of the RG;
  • the application example method further includes: NFVI-GATEWAY sending the tunnel destination address to the SDN controller, so that the SDN controller communicates with the NFVI-GATEWAY according to the received tunnel destination address.
  • Step 1006 The SDN controller sends the authentication request information to the AAA server according to the received identification and authentication related information.
  • the authentication request information includes the identification and authentication related information; that is, the authentication request information carries the tunnel identifier of the RG encapsulated in the DHCP request, and/or the tunnel source address of the RG;
  • Step 1007 The AAA server performs RG authentication according to the received authentication request information from the SDN controller.
  • performing RG authentication according to the authentication request information includes: a tunnel identifier of the RG encapsulated in the DHCP request according to the dynamic host configuration protocol, and/or a tunnel source address of the RG, and/or a virtual local area network VLAN associated with the RG, And/or multi-protocol label switching MPLS subnet information associated with the RG, and/or line identification information, and/or a broadband network gateway BNG port number receiving the DHCP request, and/or a message containing the content of the DHCP request for RG authentication;
  • the default SDN controller in the application example method is legal. If the SDN controller needs to be authenticated, the process of authenticating the SDN controller may be added in the application example method.
  • Step 1008 When the AAA server completes the RG authentication, the address management information is allocated to the VG.
  • assigning address management information to the VG may include:
  • the AAA server directly assigns address management information to the VG;
  • this application example may allocate address management information to the VG by the SDN controller, including:
  • the SDN controller receives address pool unique number (ID) information from the AAA server;
  • the address management information is allocated to the VG according to the pre-configured address pool information and the received address pool ID information.
  • the SDN controller allocates address management information to the VG according to the address pool information and the address pool ID information, determines an IP address allocated for the VG, and sends the determined IP address assigned to the VG to the AAA server.
  • sending the determined IP address to the AAA server can be used for security control. For example, traceability.
  • the address management information may include: an IP address related to a WAN interface of the VG, a public address of a network address translation (NAT) of the VG, and a port (port) information of the VG;
  • IP address related to a WAN interface of the VG
  • NAT network address translation
  • port port
  • the address pool is uniformly configured by the operator network management, and the address pool and the ID of different address pools are pre-allocated in the SDN controller.
  • the AAA server can allocate address management information to the VG according to the ID of the address pool, including assigning different IP addresses to different RGs according to the ID of the address pool.
  • the address pool information has been configured on the BNG in the related art.
  • the SDN controller can configure the address pool information according to the same principle.
  • the application example method can also directly obtain the stored address pool information from the BNG. However, before obtaining the address pool information stored on the BNG, you need to establish a connection between the AAA server and the BNG.
  • Step 1009 After completing the RG authentication, the AAA server sends an authentication response message carrying the address management information allocated for the VG to the SDN controller.
  • Step 1010 After receiving the authentication response message from the AAA server, the SDN controller allocates a VG to the RG according to the user subscription information, and configures the address of the address management information allocated for the VG according to the authentication response information as the VG configuration address;
  • the SDN controller may store the content of the address management information allocated for the VG.
  • the application example method further includes: the AAA server The SDN controller sends the user subscription information;
  • the user subscription information is the existing information in the related art, and is the content of the agreement signed by the user when signing the network protocol with the operator, and includes the network policy involving the user, and is stored in the AAA server.
  • the subscription information includes the basic configuration of the user service, including IP address information for network connection, user bandwidth information, quality of service information, security control related information, and user value-added service information (such as home control, firewall, etc.).
  • this application example also includes:
  • the SDN controller sends the pre-stored VG LAN interface access information to NFVI-GATEWAY;
  • the LAN interface access information of the VG may include virtual gateway unique coding (VG-ID) information reachable by the VG LAN interface and/or connection information of the VG LAN interface;
  • VG-ID virtual gateway unique coding
  • the LAN interface access information of the VG may be determined by the user subscription information.
  • the application example method further includes:
  • the SDN controller sends the address management information assigned to the VG to the VG for setting;
  • the SDN controller sends the NAT public network address assigned to the VG and the NAT public network port information of the VG to the NAT device shared by the VG. .
  • the NAT device shared by the VG can be determined by the user subscription information, and the NAT device that is determined by the VG is a common technical means of those skilled in the art, and details are not described herein.
  • Step 1011 NFVI-GATEWAY extends the connection between RG and NFVI-GATEWAY to the network where the LAN interface of the VG is located; that is, the mapping between the RG and NFVI-GATEWAY tunnels and the network where the VG LAN interface is located.
  • the network where the VG LAN interface is located can be determined by the SDN control pre-stored network topology information, and the mapping relationship includes: the NFVI-GATEWAY tunnel connecting the RG to the NFVI-GATEWAY tunnel.
  • Step 1012 The LAN interface of the RG and the home network device connected to the LAN interface send a DHCP request to the VG.
  • Step 1013 The VG allocates an IP address to the home network device connected to the LAN interface of the RG.
  • Step 1014 The RG forwards the data flow of the home network device, and the VG provides service forwarding for the home network device; the service forwarding includes IP forwarding or forwarding of NAT or other service processing.
  • the RG can also send Point-to-Point Protocol (PPPoE) requests over Ethernet for RG access, authentication, and VG-related NFVI-GATEWAY assignments.
  • PPPoE Point-to-Point Protocol
  • the packets sent by the LAN interface of the RG are carried on the Layer 2 tunneling protocol, such as VXLAN, and reach the BNG through PPPoE encapsulation. After the BNG decapsulates the PPPoE packet, the packet sent by the RG LAN interface determines the location of the NFVI-GATEWAY according to the destination address of the Layer 2 tunneling protocol.
  • the RG of this application example may also be an enterprise network gateway access, and the enterprise network gateway may be dynamically accessed or statically accessed.
  • BNG supports Layer 3 forwarding.
  • the NFVI-GATEWAY information about the VG can be accessed by accessing the BNG to the AAA server, and the WAN interface of the enterprise gateway and the WAN interface of the NFVI-GATEWAY are established.
  • the WAN interface of the NFVI-GATEWAY can pass the sub-interface. Or tunnel information distinguishes between different enterprise gateway accesses.
  • This application example home gateway communicates with the VG through the Ethernet access function.
  • the VG is located in the data center.
  • the first device of this application example is NFVI-GATEWAY, NFVI-GATEWAY as a stand-alone device, and provides RG access for the VG.
  • FIG. 11 is a flowchart of a method according to a second application example of the present invention. As shown in FIG. 11, the method includes:
  • Step 1100 The LAN interface of the RG sends a DHCP request to the BNG that provides access.
  • the DHCP request is an IP address request for the LAN interface of the home gateway.
  • Step 1101 The BNG receives the DHCP request, and sends an RG authentication and a VG access AAA request to the AAA server.
  • the RG authentication and the VG access AAA request carry the line identification information.
  • Step 1102 The AAA server authenticates the RG according to the RG authentication and the VG access AAA request, and allocates the VG connection information; the VG connection information includes a virtual local area network (VLAN) or Multi-Protocol Label Switching (MPLS) subnet information; and the AAA server sends the VG of the RG. Connect information to BNG.
  • VLAN virtual local area network
  • MPLS Multi-Protocol Label Switching
  • Step 1103 The BNG establishes a connection with the NFVI-GATEWAY connected to the VG according to the VLAN or MPLS subnet information returned by the AAA server, and establishes a layer 2 of the NFVI-GATEWAY and the RG access connected to the VG on the BNG. Network mapping.
  • mapping between the NFVI-GATEWAY to which the BNG and the VG are connected and the second-layer subnet to which the RG is connected includes: the NFVI-GATEWAY tunnel to which the VG is connected, and the RG corresponding to the NFVI-GATEWAY tunnel.
  • the RG accesses the second-layer subnet of the relationship, and uses the NFVI-GATEWAY tunnel as the middle layer to perform one-to-one correspondence;
  • Step 1104 The BNG sends a DHCP request to the connected NFVI-GATEWAY;
  • Step 1105 The NFVI-GATEWAY receives the DHCP request from the BNG, and sends the identification and authentication related information included in the DHCP request to the SDN controller.
  • the identification and authentication related information includes a VLAN associated with the RG encapsulated in the DHCP request or MPLS subnet information associated with the RG.
  • the package in the related art further includes information such as the LAN interface of the home gateway, and is common knowledge of those skilled in the art.
  • the application example method further includes:
  • NFVI-GATEWAY sends the tunnel destination address of the RG to the SDN controller, so that the SDN controller communicates according to the tunnel destination address of the RG.
  • Step 1106 The SDN controller sends the authentication request information to the AAA server according to the received identification and authentication related information.
  • the authentication request information includes identification and authentication related information, that is, the authentication request information carries a VLAN associated with the RG encapsulated in the DHCP request, and/or MPLS subnet information associated with the RG;
  • Step 1107 The AAA server performs RG authentication according to the received authentication request information from the SDN controller.
  • performing RG authentication according to the authentication request information is a common technical means for those skilled in the art; in addition, the default SDN controller is legal in this application example method, and if the SDN controller needs to be authenticated, The application example method adds a process of authenticating the SDN controller.
  • Step 1108 When the AAA server completes the RG authentication, the address management information is allocated to the VG.
  • assigning address management information to the VG includes:
  • the AAA server directly assigns address management information to the VG;
  • the address management information includes an IP address related to the WAN interface of the VG, a NAT public network address of the VG, and a port information of the NAT of the VG;
  • this application example may allocate address management information to the VG by the SDN controller, including:
  • the SDN controller receives address pool unique number (ID) information from the AAA server;
  • the address management information is allocated to the VG according to the pre-configured address pool information and the received address pool ID information.
  • the SDN controller allocates address management information to the VG according to the address pool information and the address pool ID information, determines an IP address allocated for the VG, and sends the determined IP address assigned to the VG to the AAA server.
  • sending the determined IP address to the AAA server can be used for security control. For example, traceability.
  • the address pool information has been configured on the BNG in the related art.
  • the SDN controller can configure the address pool information according to the same principle.
  • the application example method can also be directly obtained from the BNG.
  • the address pool information is stored. However, before obtaining the address pool information stored on the BNG, you need to establish a connection between the AAA server and the BNG.
  • Step 1109 After completing the RG authentication, the AAA server sends an authentication response message carrying the address management information allocated for the VG to the SDN controller.
  • Step 1110 After receiving the authentication response message from the AAA server, the SDN controller allocates a VG according to the user subscription information, and configures the address of the address management information allocated for the VG according to the authentication response information as the VG configuration address.
  • the example method of the application further includes: the AAA server sending the user subscription information to the SDN controller;
  • the user subscription information is the existing information in the related art, and is the content of the agreement signed by the user when signing the network protocol with the operator, and includes the network policy involving the user, and is stored in the AAA server;
  • the application example further includes: the SDN controller establishes corresponding session management for the address management information allocated by the VG for each RG identification and authentication related information;
  • the content of the session control management includes: the VLAN associated with the RG, the MPLS subnet information associated with the RG, the VG-ID information, the LAN interface information of the VG, the WAN interface information of the VG, the public network address of the VG NAT public network, and the VG.
  • NAT port information which records and maintains VG address management information, QOS, security policies, and OAM management information.
  • the session control management includes recording and maintaining the content of the session control management.
  • the maintenance here includes: when the subscription user logs in, the content of the session control management is recorded, and when the RG exits for some reason, the RG is re-established.
  • the recorded session control management content is sent to the RG that is logged in again.
  • the SDN controller sends the pre-stored VG LAN interface access information to the NFVI-GATEWAY;
  • the LAN interface access information of the VG may include VG-ID information reachable by the VG LAN interface and/or LAN interface connection information of the VG;
  • the LAN interface access information of the VG can be determined by the user subscription information.
  • the example method of the application further includes: the SDN controller sends the address management information allocated to the VG to the VG for setting;
  • the application example method further includes:
  • the SDN controller sends the address management information assigned to the VG to the VG for setting;
  • the example method of the application further includes: sending the NAT public network address assigned to the VG and the port information of the NAT public network of the VG to the NAT device shared by the VG.
  • the NAT device shared by the VG can be determined by the user subscription information, and the NAT device that is determined by the VG is a common technical means of those skilled in the art, and details are not described herein.
  • Step 1111 NFVI-GATEWAY extends the connection of RG to NFVI-GATEWAY to the network where the LAN interface to the VG is located.
  • Step 1112 The LAN interface of the RG and the home network device connected to the LAN interface send a DHCP request to the VG to apply for an IP address.
  • Step 1113 The VG allocates an IP address for the LAN interface of the RG and the home network device connected to the LAN interface.
  • Step 1114 The RG forwards the data flow of the home network device, and the VG provides service forwarding for the home network device; the service forwarding includes IP forwarding or forwarding of NAT or other service processing;
  • the RG can also access the enterprise network gateway.
  • the enterprise network gateway can be dynamically accessed or statically accessed.
  • the BNG supports Layer 2 forwarding.
  • the BNG is requested to access the AAA server.
  • the NFVI-GATEWAY information on the VG side can be accessed to establish a connection between the WAN interface of the enterprise network gateway and the WAN interface of the NFVI-GATEWAY.
  • the WAN interface of the NFVI-GATEWAY can be through the VLAN associated with the RG or the MPLS subnet associated with the RG.
  • the access to the enterprise network gateway is implemented; when the connection has a message, the processing flow of step 1105 to step 1110 of the application example is triggered.
  • the application scenario of the application is that the home gateway communicates with the VG through the Layer 3 routing access function; the VG is located in the data center, and the first device of the application example is the NFVI-GATEWAY in the first application example and the second application example extended in the BNG.
  • the functional device provides RG access for the VG.
  • FIG. 12 is a flowchart of a method according to a third application example of the present invention. As shown in FIG. 12, the method includes:
  • Step 1200 The RG sends a DHCP request to the currently accessed BNG.
  • the DHCP request is an IP address request of the WAN interface of the RG;
  • the intermediate device When the DHCP request passes through the access network of the operator, the intermediate device adds the line identification information.
  • the intermediate device may include: a digital subscriber line access multiplexer (Digital Dilamolt), an optical line terminal or an access switch (OLT), and the like.
  • Digital Dilamolt Digital Dilamolt
  • ONT access switch
  • Step 1201 The BNG receives the DHCP request from the RG, and sends the information related to the identification and authentication in the received DHCP request to the SDN controller.
  • the identification and authentication related information includes: line identification information, or a BNG port number for receiving a DHCP request.
  • the application example method may also be sent to the SDN controller by directly forwarding the DHCP request.
  • Step 1202 The SDN controller determines, according to the pre-stored authentication record information, whether it is a new RG;
  • the SDN controller further includes: the SDN controller stores the identification and authentication related information of the RG that is authenticated by the AAA server, as the authentication record information.
  • step 1003 is performed; if it is not a new RG, it is generally considered that the subsequent processes of the application example are completed;
  • Step 1203 The SDN controller sends the authentication request information to the AAA server according to the received identification and authentication related information.
  • the authentication request message carries the identification and authentication related information, that is, the authentication request information carries the line identification information, the BNG port number that receives the DHCP request, or the message that contains the DHCP request content.
  • the BNG when the BNG sends the identification and authentication related information, in order to implement the SDN control and the BNG communication, the BNG needs to send its own number to the SDN controller, and the SDN controller according to the BNG number and the BNG port number that receives the DHCP request. Communicate with BNG.
  • Step 1204 The AAA server performs RG authentication according to the received authentication request information from the SDN controller.
  • the default SDN controller is legal. If the SDN controller needs to be authenticated, the authentication process of the multiple SDN controller may be added in this step.
  • Step 1205 When the AAA server completes the RG authentication, the address management information is allocated to the VG.
  • the VG address management information is included: the AAA server directly allocates address management information to the VG;
  • the address management information includes a WAN interface-related IP address of the VG, a NAT public network address of the VG, and a port information of the NAT public network of the VG;
  • this application example may allocate address management information to the VG by the SDN controller, including:
  • the SDN controller receives address pool unique number (ID) information from the AAA server;
  • the SDN controller allocates address management information to the VG according to the address pool information and the address pool ID information, determines an IP address allocated for the VG, and sends the determined IP address assigned to the VG to the AAA server.
  • sending the determined IP address to the AAA server can be used for security control. For example, traceability.
  • Step 1206 After the AAA server completes the authentication, the AAA controller returns an authentication response message carrying the address management information allocated for the VG.
  • Step 1207 After receiving the authentication response message from the AAA server, the SDN controller allocates a VG according to the user subscription information, and configures the address of the address management information allocated for the VG according to the authentication response information as the VG configuration address.
  • the example method of the application further includes: the AAA server sending the user subscription information to the SDN controller;
  • the application example further includes: the SDN controller sends the pre-stored WAN IP address of the RG, and the LAN interface access information of the VG to the BNG;
  • the LAN interface access information of the VG includes VG-ID information reachable by the VG LAN interface and/or connection information of the VG LAN interface;
  • the WAN IP address of the RG and the LAN interface access information of the VG can be determined by the user subscription information.
  • the application example method further includes:
  • the SDN controller sends the address management information assigned to the VG to the VG for setting;
  • the application method of the application includes: sending the port information allocated to the VG NAT public network address and the VG NAT public network to the NAT device shared by the VG.
  • VG shared NAT device can be determined by user subscription information, which is a common technical means by those skilled in the art;
  • Step 1208 The BNG returns the WAN IP address of the RG to the RG through a DHCP message, and After the RG network is associated with the subnet where the VG is located, a connection is established.
  • Step 1209 The RG saves the WAN address of the VG and establishes a tunnel connection between the RG and the BNG.
  • Step 1210 The LAN interface of the RG sends a DHCP request.
  • Step 1211 The VG allocates an IP address to the LAN interface of the RG and the connected home network device.
  • the VG After the VG performs service flow processing, it is sent to the RG or NAT or other service device, and the service flow is finally sent from the BNG to the Internet.
  • RG can also access the enterprise network gateway.
  • the enterprise network gateway can be dynamically accessed or statically.
  • BNG supports Layer 2 forwarding.
  • the BNG requests access to the AAA server through the SDN controller.
  • the BNG is dynamically managed by the SDN controller according to the configuration of the SDN controller.
  • Enterprise gateway connection The BNG identifies the enterprise gateway user based on the port connected to the controller; the steps taken are similar to those of 1203 to 1207.
  • the method, device, SDN controller and AAA server for implementing address management according to embodiments of the present invention comprise: a software defined network (SDN) controller according to the received identification and authentication related information of a home gateway (RG) from a first device Generate and send a confirmation for the home gateway RG certification
  • the authentication request information is sent to the authentication and authorization accounting (AAA) server; after the AAA server completes the RG authentication, the AAA server allocates address management information to the VG; after the AAA server completes the RG authentication, the SDN controller allocates a virtual gateway to the RG according to the user subscription information ( VG), the SDN controller configures an address for the VG based on the authentication response information from the AAA server carrying the content of the address management information allocated for the VG.
  • the method of the embodiment of the present invention allocates a VG to the RG through the SDN controller, and allocates address management information to the VG through the AAA server, thereby implementing address management after the VG is created.

Abstract

本文公布了一种实现地址管理的方法、装置、SDN控制器及AAA服务器,包括:SDN控制器根据接收的来自第一装置的RG的识别和认证相关信息生成并发送进行家庭网关RG认证的认证请求信息到AAA服务器;AAA服务器在完成RG的认证后,为VG分配地址管理信息;SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配VG,SDN控制器根据来自AAA服务器的携带有为VG分配的地址管理信息的内容的认证响应信息为VG配置地址。本发明实施例方法通过SDN控制器为RG分配VG,通过AAA服务器为VG分配地址管理信息,实现了VG创建后的地址管理。

Description

一种实现地址管理的方法、装置、AAA服务器及SDN控制器 技术领域
本发明实施例涉及数据通信技术,尤指一种实现地址管理的方法、装置、认证授权计费(AAA)服务器及软件定义网络(SDN)控制器。
背景技术
随着互联网应用和宽带业务的普及,运营商为宽带用户提供了更多的网络业务,例如安全、虚拟网络、过滤、负载均衡、多媒体及多媒体增强等业务。为了提供这些业务,运营商主要是采用专用设备或路由器专用业务板来部署业务。部署专用设备或在现有的路由架构使用专用业务板成本高、且存在部署复杂和耗时的问题,网络运营商无法快速完成。此外,专用设备或路由器的部署还存在维护费用高,存在进行特定定制和手工配置的影响部署业务的问题。
虚拟化技术采用通用的硬件架构,通过将通用硬件进行资源池化管理,一定程度上提高了业务部署的效率。
有线数据通信网为家庭用户以及企业用户提供因特网(Internet)接入及互联网增值服务。相关技术中的接入控制通过宽带接入服务器(BRAS,Broadband Remote Access Server)、业务路由器(SR,Service Router)、宽带网络网关(BNG,Broadband Network Gateway)等专用设备实现。然而,有线数据通信网的用户多、流量大、业务复杂。单一的专用设备或是单一虚拟技术都无法全面解决这些问题。当前标准组织提出了通过在现有专用设备组网的基础上扩展虚拟化技术,以更好的解决业务数据的快速转发以及对业务进行灵活的扩展。宽带论坛(BBF,Broadband Forum)标准组织提出虚拟网关(VG,Virtual Gateway)配合部署在用户所在网络的物理网关,用户家庭网关(RG,Residential Gateway)用于实现基本网络功能接入,由VG实现业务的灵活部署,相关技术中的WT-317协议定义了VG的功能需求。
发明内容
以下是对本文详细描述的主题的概述。本概述并非是为了限制权利要求 的保护范围。
本发明实施例提供了一种实现地址管理的方法,包括:
软件定义网络SDN控制器根据来自第一装置的识别和认证相关信息生成进行家庭网关RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到认证授权计费AAA服务器;
SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配虚拟网关VG;
SDN控制器根据来自AAA服务器的认证响应信息为VG配置地址;
所述认证响应消息为:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容;
其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG。
可选地,该方法还包括:所述SDN控制器将预先存储的VG的局域网LAN接口接入信息发往所述第一装置。
可选地,所述VG的LAN接口接入信息包括:
VG的LAN接口可达的虚拟网关唯一编码VG-ID信息、和/或VG的LAN接口的连接信息。
可选地,所述为RG分配VG之后,如果包含有与分配的所述VG共享的NAT设备,所述方法还包括:
所述SDN控制器将分配给VG的网络地址转换NAT公网地址及VG的NAT公网的接口port信息下发给与所述VG共享的NAT设备。
可选地,所述方法还包括:所述SDN控制器对每一RG分别建立相应的会话控制管理;
所述会话控制管理包括:对与RG关联的VLAN、和/或与RG关联的MPLS子网信息、和/或VG-ID信息、和/或VG的LAN接口信息、和/或VG的广域网WAN接口信息、和/或VG的NAT公网的公网地址、和/或VG的NAT的port信息、和/或分配VG地址管理信息、和/或服务质量QOS、和/或安全策略、和/或操作管理维护OAM管理信息进行记录和维护。
可选地,所述认证请求信息包含识别和认证相关信息;
所述识别和认证相关信息包括:动态主机配置协议DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的虚拟局域网VLAN、和/或与RG关联的多协议标签交换MPLS子网信息、和/或线路标识信息、和/或接收DHCP请求的宽带网络网关BNG端口号、和/或包含DHCP请求内容的消息。
本发明又提供了一种实现地址管理的方法,包括:
SDN控制器接收来自AAA服务器的地址池ID信息;
SDN控制器根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息;
其中,VG为SDN控制器为RG分配的VG。
可选地,所述方法还包括:
SDN控制器根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
可选地,所述地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息。
本发明还提供了一种实现地址管理的方法,包括:
AAA服务器在完成RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有所述为VG分配的地址管理信息的内容的认证响应消息;
其中,所述VG为SDN控制器为RG分配的VG。
可选地,为RG分配VG之前,所述方法还包括:
所述AAA服务器向SDN控制器发送用户签约信息。
可选地,所述为VG分配地址管理信息包括:
所述AAA服务器直接为VG分配地址管理信息;
所述地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/ 或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息。
本发明又提供了一种实现地址管理的方法,包括:
第一装置获取识别和认证相关信息,并发送给软件定义网络SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
14、根据权利要求13所述的方法,其特征在于,所述获取识别和认证相关信息,并发送给SDN控制器包括:
所述第一装置通过接收的动态主机配置协议DHCP请求,从DHCP请求中携带的信息中获取识别和认证相关信息。
可选地,所述DHCP请求来自宽带网络网关BNG或家庭网关RG。
可选地,所述第一装置包括:网络功能虚拟化基础架构网关NFVI-GATEWAY或BNG。
可选地,当所述第一装置为NFVI-GATEWAY时,所述识别和认证相关信息包括:DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的虚拟局域网VLAN、和/或与RG关联的多协议标签交换MPLS子网信息、和/或线路标识信息、和/或包含DHCP请求内容的消息;
当所述第一装置为BNG时,所述识别和认证相关信息包括:线路标识信息、和/或接收DHCP请求的BNG端口号、和/或包含DHCP请求内容的消息。
可选地,发送所述识别和认证相关信息到SDN控制器时,所述方法还包括:
所述第一装置发送第一装置的通信地址到SDN控制器,以使SDN控制器根据接收的第一装置的通信地址与第一装置通信。
可选地,该方法还包括:
所述第一装置将RG与第一装置的连接延伸至虚拟网关VG的局域网LAN接口所在网络。
本发明还提供了一种实现地址管理的SDN控制器,包括:生成发送单 元、分配单元和地址配置单元;其中,
生成发送单元用于,根据来自第一装置的识别和认证相关信息生成进行RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到AAA服务器;
分配单元用于,在AAA服务器完成RG认证后,根据用户签约信息为RG分配VG;
地址配置单元用于,SDN控制器根据来自AAA服务器的认证响应信息为VG配置地址;
所述认证响应消息为:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容;
其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG。
可选地,所述SDN控制器还包括接入信息发送单元,用于将预先存储的VG的LAN接口接入信息发往所述第一装置。
可选地,所述SDN控制器还包括下发单元,用于所述为RG分配VG之后,如果包含有与分配的所述VG共享的NAT设备,将分配给VG的NAT公网地址及VG的NAT公网的port信息下发给与所述VG共享的NAT设备。
可选地,所述SDN控制器还包括会话控制单元,用于对每一RG分别建立相应的会话控制session管理;
所述会话控制管理包括:对与RG关联的VLAN、和/或与RG关联的MPLS子网信息、和/或VG-ID信息、和/或VG的LAN接口信息、和/或VG的广域网WAN接口信息、和/或VG的NAT公网的公网地址、和/或VG的NAT的port信息、和/或分配VG地址管理信息、和/或QOS、和/或安全策略、和/或OAM管理信息进行记录和维护。
本发明又提供了一种实现地址管理的SDN控制器,包括:接收地址池编号单元和分配地址单元;其中,
接收地址池编号单元用于,接收来自AAA服务器的地址池唯一编号ID信息;
分配地址单元用于,根据预先配置地址池信息及接收的地址池ID信息 为VG分配地址管理信息;
其中,VG为SDN控制器为RG分配的VG。
可选地,所述SDN控制器还包括上送单元,
用于根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
本发明再提供了一种实现地址管理的AAA服务器,包括分配信息单元,用于完成对RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有所述为VG分配的地址管理信息的内容的认证响应消息;
其中,VG为SDN控制器为RG分配的VG。
可选地,所述分配信息单元具体用于,直接为VG分配地址管理信息;
所述地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息。
可选地,所述AAA服务器还包括签约信息发送单元,用于为RG分配VG之前,向SDN控制器发送用户签约信息。
本发明还提供了一种实现地址管理的装置,包括:相关信息发送单元,用于获取识别和认证相关信息,并发送给SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
可选地,所述相关信息发送单元还用于,
发送所述识别和认证相关信息到SDN控制器时,发送所述装置的通信地址到SDN控制器,以使SDN控制器根据接收的所述装置的通信地址与所述装置通信。
可选地,所述相关信息发送单元具体用于:根据接收的DHCP请求,发送DHCP请求中包含的识别和认证相关信息到SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
可选地,该装置还包括延伸单元,用于,将RG与所述装置的连接延伸至VG的LAN接口所在网络。
之外,本申请还提供了计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令用于执行实现地址管理的方法。
与相关技术相比,本申请技术方案包括:软件定义网络(SDN)控制器根据接收的来自第一装置的家庭网关(RG)的识别和认证相关信息生成并发送进行家庭网关RG认证的认证请求信息到认证授权计费(AAA)服务器;AAA服务器在完成RG的认证后,为VG分配地址管理信息;SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配虚拟网关(VG);AAA服务器在完成RG的认证后,为VG分配地址管理信息,SDN控制器根据来自AAA服务器的携带有为VG分配的地址管理信息的内容的认证响应信息为VG配置地址。本发明实施例方法通过SDN控制器为RG分配VG,通过AAA服务器为VG分配地址管理信息,实现了VG创建后的地址管理。
在阅读并理解了附图和详细描述后,可以明白其他方面。
附图概述
此处所说明的附图用来提供对本发明的进一步理解,构成本申请的一部分,本发明的示意性实施例及其说明用于解释本发明,并不构成对本发明的不当限定。在附图中:
图1为本发明实施例实现地址管理的方法的流程图;
图2为本发明另一实施例实现地址管理的方法的流程图;
图3为本发明另一实施例实现地址管理的方法的流程图;
图4为本发明再一实施例实现地址管理的方法的流程图;
图5为本发明实施例实现地址管理的第一装置的结构框图;
图6为本发明实施例实现地址管理的SDN控制器的结构框图;
图7为本发明实施例另一实现地址管理的SDN控制器的结构框图;
图8为本发明实施例实现地址管理的AAA服务器的结构框图;
图9为应用示例的网络结构示意图;
图10为本发发明第一应用示例的方法流程图;
图11为本发明第二应用示例的方法流程图;
图12为本发明第三应用示例的方法流程图。
本发明的较佳实施方式
下文中将参考附图并结合实施例来详细说明本发明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。
本申请发明人发现,VG通常成千上万,数目巨大;相关技术中采用认证授权计费(AAA)服务器为RG分配VG-ID,由于VG是虚拟的,可能会故障、掉电或变更,RG发生故障、掉电或变更时,需要在AAA服务器重新为RG分配VG-ID,实现复杂,另外,相关技术中没有提供VG WAN相关的地址管理信息的分配方法;即如何对VG进行动态地址管理,相关技术中尚未提出有效的方案。
图1为本发明实施例实现地址管理的方法的流程图,如图1所示,包括:
步骤100、第一装置获取识别和认证相关信息,并发送给软件定义网络(SDN)控制器。
第一装置可以通过接收的动态主机配置协议(DHCP)请求,从DHCP请求中携带的信息中获取识别和认证相关信息。
本发明实施例方法,根据识别和认证相关信息,SDN控制器可以生成进行RG认证的认证请求信息。
可选的,DHCP请求来自宽带网络网关(BNG)或RG。
需要说明的是,本发明实施例方法,DHCP请求可以来自BNG,来自BNG的DHCP请求可以包括RG发送BNG的DHCP请求。
可选的,本发明实施例方法中,第一装置包括:网络功能虚拟化基础架构网关(NFVI-GATEWAY)或BNG。
可选的,当第一装置为NFVI-GATEWAY时,识别和认证相关信息包括:DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的虚拟局域网VLAN、和/或与RG关联的多协议标签交换MPLS子网信息、和/或线路标识信息、和/或包含DHCP请求内容的消息;
当第一装置为BNG时,识别和认证相关信息包括:线路标识信息、和/ 或接收DHCP请求的BNG端口号、和/或包含DHCP请求内容的消息。
在发送识别和认证相关信息到SDN控制器时,本发明实施例方法还包括步骤101:
步骤101、第一装置发送第一装置的通信地址到SDN控制器,以使SDN控制器根据接收的第一装置的通信地址与第一装置通信。
需要说明的是,当第一装置为NFVI-GATEWAY时,第一装置的通信地址可以包括隧道目的地址;当第一装置为BNG时,第一装置的通信地址可以包括BNG发送到SDN控制器的自身编号和接收DHCP请求的BNG端口号。
可选的,本发明实施例方法还包括:
第一装置将RG与第一装置的连接延伸至虚拟网关(VG)的局域网(LAN)接口所在网络。
需要说明的是,这里的VG的LAN接口所在网络包括:SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配VG的LAN接口所在网络。
本发明实施例方法可以应用于IPV4、IPV6及NAT网络中,在不同网络中实施本发明实施方法时,根据协议的不同,部分信息需要进行适应性的调整,具体实现在基于本发明提供的技术方案基础上是容易实现的,并不用于限定本发明的保护范围。
图2为本发明另一实施例实现地址管理的方法的流程图,如图2所示,包括:
步骤200、软件定义网络(SDN)控制器根据来自第一装置的识别和认证相关信息生成进行RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到认证授权计费(AAA)服务器。
步骤201、SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配VG。
其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG。
需要说明的是,用户签约信息包含用户业务的基础配置,包括用于网络 连接的IP地址信息、用户带宽信息、服务质量信息、安全控制相关信息以及用户增值业务信息(如家庭控制、防火墙等)。
另外,根据用户签约信息为RG分配VG可以包括:采用模板方式,可以选择基础业务模板,对应基础IPv4VG、基础IPv6VG或是IPv4私有VG,以及扩展业务模板,对应有家庭控制业务,家庭安全业务等。AAA可以将业务模板ID发送给SDN控制器,SDN控制器根据模板ID组合创建支持不同业务的VG。
步骤202、SDN控制器根据来自AAA服务器的认证响应信息为VG配置地址。
认证响应消息为:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容。
可选的,本发明实施例方法中,认证请求信息包含识别和认证相关信息;
识别和认证相关信息包括:DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的VLAN、和/或与RG关联的MPLS子网信息、和/或线路标识信息、和/或接收DHCP请求的BNG端口号、和/或包含DHCP请求内容的消息。
可选的,本发明实施例方法还包括:SDN控制器将预先存储的VG的LAN接口接入信息发往第一装置。
可选的,VG的LAN接口接入信息包括:
VG的LAN接口可达的虚拟网关唯一编码(VG-ID)信息、和/或VG的LAN接口的连接信息。
可选的,为RG分配VG之后,如果包含有与分配的VG共享的NAT设备,本发明实施例方法还包括:
SDN控制器将分配给VG的网络地址转换NAT公网地址及VG的NAT公网的接口(port)信息下发给与VG共享的NAT设备。
可选的,本发明实施例方法还包括:SDN控制器对每一RG分别建立相应的会话控制(session)管理;
会话控制管理包括:对与RG关联的VLAN、和/或与RG关联的MPLS 子网信息、和/或VG-ID信息、和/或VG的LAN接口信息、和/或VG的广域网WAN接口信息、和/或VG的NAT公网的公网地址、和/或VG的NAT的port信息、和/或分配VG地址管理信息、和/或服务质量(QOS)、和/或安全策略、和/或操作管理维护(OAM)管理信息进行记录和维护。
本发明实施例方法通过SDN控制器为RG分配VG,实现了VG创建后的地址管理。
本发明实施例方法可以应用与IPV4、IPV6及NAT网络中,在不同网络中实施本发明实施方法时,根据协议的不同,部分信息需要进行适应性的调整,具体实现在基于本发明提供的技术方案基础上是容易实现的,并不用于限定本发明的保护范围。
图3为本发明另一实施例实现地址管理的方法的流程图,如图3所示,包括:
步骤301、AAA服务器在完成RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有为VG分配的地址管理信息的内容的认证响应消息。
其中,所述VG为SDN控制器为RG分配的VG。
需要说明的是,本发明实施方法的AAA服务器可以与DHCP服务器合设,即可以在AAA服务器中实现DHCP服务器的功能,由于DHCP服务器中包含的本发明实施例所需的信息存在差异,需要本领域技术人员结合实际情况进行适应性的调整,具体实现在基于本发明提供的技术方案基础上是容易实现的,并不用于限定本发明的保护范围。
另外,为VG分配地址管理信息,和为RG分配VG可以分开实施,两者不存在时序关系;当两者均完成时,则达到的结果是为RG分配的VG为分配了地址管理信息的。
可选的,为VG分配地址管理信息包括:
AAA服务器直接为VG分配地址管理信息;
地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换(NAT)的公网地址及VG的NAT的接口(port)信息。
需要说明的是,AAA服务器内存有地址管理信息,或AAA服务器从运营商运维管理系统中查询。运营商运维管理系统存储了用户签约时创建的地址管理信息。
可选的,为RG分配VG之前,本发明实施例方法还包括步骤300:AAA服务器向SDN控制器发送用户签约信息。
本发明实施例方法,通过AAA服务器为VG分配地址管理信息,实现了VG创建后的地址管理。
本发明实施例方法可以应用于IPV4、IPV6及NAT网络中,在不同网络中实施本发明实施方法时,根据协议的不同,部分信息需要进行适应性的调整,该部分调整不需要本领域技术人员进行创造性劳动。
图4为本发明再一实施例实现地址管理的方法的流程图,如图4所示,包括:
步骤400、SDN控制器接收来自AAA服务器的地址池ID信息。
步骤401、SDN控制器根据预先配置的地址池信息及接收的地址池ID信息为VG分配地址管理信息。
其中,所述VG为SDN控制器为RG分配的VG。
需要说明的是,地址池ID代表一个IP地址段和端口端,例如、130.0.0.1~200,端口号2000~3000,SDN控制器从这个IP地址段和端口端范围内为不同的VG分别分配相应的由IP地址和端口范围构成的管理信息;不同VG的IP地址可以相同,IP地址相同时,端口范围不同。
可选的,地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息;
可选的,本发明实施例方法还包括:
SDN控制器根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
需要说明的是,将确定的IP地址上送至AAA服务器可以用于进行安全控制。例如、溯源。
本申请还提供了一种计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令用于执行上述任一项实现地址管理的方法。
本发明还提供一种用于实现地址管理的方法的设备,至少包括存储器和用于执行可执行指令的处理器,其中,
存储器中存储有以下可执行指令:
根据来自第一装置的识别和认证相关信息生成进行家庭网关RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到认证授权计费AAA服务器;在AAA服务器完成RG认证后,根据用户签约信息为RG分配虚拟网关VG;根据来自AAA服务器的认证响应信息为VG配置地址;其中,认证响应消息为:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容;其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG;
或者,
接收来自AAA服务器的地址池ID信息;根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息;其中,VG为SDN控制器为RG分配的VG;
或者,
在完成RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有所述为VG分配的地址管理信息的内容的认证响应消息;其中,VG为SDN控制器为RG分配的VG;
或者,
获取识别和认证相关信息,并发送给软件定义网络SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
图5为本发明实施例实现地址管理的第一装置的结构框图,如图5所示,包括:相关信息发送单元,用于获取识别和认证相关信息,并发送给SDN控制器。具体可以用于:根据接收的DHCP请求,发送DHCP请求中包含的识别和认证相关信息到SDN控制器,以使SDN控制器根据所述识别和认证 相关信息生成进行RG认证的认证请求信息。
可选的,相关信息发送单元还用于,
当发送识别和认证相关信息到SDN控制器时,发送装置的通信地址到SDN控制器,以使SDN控制器根据接收的装置的通信地址与装置通信。
本发明实施例装置还包括延伸单元用于,将RG与装置的连接延伸至VG的LAN接口所在网络。
图6为本发明实施例实现地址管理的SDN控制器的结构框图,如图6所示,包括:生成发送单元、分配单元和地址配置单元;其中,
生成发送单元用于,根据来自第一装置的识别和认证相关信息生成进行RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到AAA服务器;
分配单元用于,在AAA服务器完成RG认证后,根据用户签约信息为RG分配VG;
地址配置单元用于,SDN控制器根据来自AAA服务器的认证响应信息为VG配置地址;
认证响应消息包括:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容;
其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG。
可选的,本发明实施例,SDN控制器还包括地址池发送单元,用于发送预先配置的地址池信息到AAA服务器。
可选的,本发明实施例,SDN控制器还包括接入信息发送单元,用于将预先存储的VG的LAN接口接入信息发往第一装置。
可选的,本发明实施例,SDN控制器还包括下发单元,用于为RG分配VG之后,如果包含有与分配的VG共享的NAT设备,将分配给VG的NAT公网地址及VG的NAT公网的port信息下发给与VG共享的NAT设备。
可选的,本发明实施例,SDN控制器还包括会话控制单元,用于对每一RG分别建立相应的会话控制session管理;
会话控制管理包括:对与RG关联的VLAN、和/或与RG关联的MPLS子网信息、和/或VG-ID信息、和/或VG LAN接口信息、和/或VG的广域网WAN接口信息、和/或VG的NAT公网的公网地址、和/或VG的NAT的port信息、和/或分配VG地址管理信息、和/或QOS、和/或安全策略、和/或OAM管理信息进行记录和维护。
图7为本发明实施例实现地址管理的SDN控制器的结构框图,如图7所示,包括接收地址池编号单元和分配地址单元;其中,
接收地址池编号单元用于,接收来自AAA服务器的地址池唯一编号ID信息;
分配地址单元用于,根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息。
其中,所述VG为SDN控制器为RG分配的VG。
可选的,SDN控制器还包括上送单元:用于根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
图8为本发明实施例实现地址管理的AAA服务器的结构框图,如图8所示,包括:分配信息单元,用于完成对RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有所述为VG分配的地址管理信息的内容的认证响应消息。
其中,所述VG为SDN控制器为RG分配的VG。
可选的,分配信息单元具体用于,直接为VG分配地址管理信息;
地址管理信息包括:VG的广域网(WAN)接口相关的IP地址、和/或VG的网络地址转换(NAT)的公网地址及VG的NAT的接口(port)信息。
需要说明的是,VG的WAN接口相关的IP地址包括VG的WAN接口的IPv4、和/或IPv6地址。
可选的,本发明实施例AAA服务器还包括签约信息发送单元,用于为RG分配VG之前,向SDN控制器发送用户签约信息。
以下通过应用示例对本发明方法进行清楚详细的说明,应用示例仅用于 陈述本发明实施例,并不用于限定本发明的保护范围。
为使应用示例陈述更为清楚,对应用示例的网络结构进行说明,图9为应用示例的网络结构示意图,如图9所示,网络结构中包括:家庭网关、虚拟网关、宽带网络网关、NFVI-GATEWAY、SDN控制器和AAA服务器等;其中虚拟网关位于网络功能虚拟化的网络内。
应用示例1
本应用示例中,家庭网关(RG,Residential Gateway)包含三层路由接入功能,通过在WAN接口上通过三层隧道封装和VG互通;虚拟网关(VG)位于网络功能虚拟化(NFV)的网络内,第一装置为NFVI-GATEWAY,作为独立设备,为VG提供RG接入。
图10为本发发明第一应用示例的方法流程图,如图8所示,包括:
步骤1000:RG向提供接入的BNG发送动态主机配置协议(DHCP)请求;
本应用示例中,DHCP请求为RG的广域网(WAN)接口的网络之间互连的协议(IP)地址请求,DHCP请求在经过运营商接入网络(Access network)时,中间设备会增加线路标识信息。中间设备可以包括:数字用户线路接入复用器(Digital Dilamolt),光线路终端或接入交换机(OLT)等。
步骤1001:BNG收到DHCP请求,向认证授权计费(AAA)服务器发起RG认证及VG接入AAA请求;其中,RG认证及VG接入AAA请求携带DHCP请求经过中间设备时增加的线路标识信息。
步骤1002:AAA服务器根据接收到的RG认证及VG接入AAA请求认证RG。
需要说明的是,相关技术中,当运营商网络有多个NFV网络提供VG接入时,AAA服务器可以通过策略分配可选的NFV网络以及VG相关接入NFVI-GATEWAY。AAA服务器将RG的WAN接口的IP地址及VG所在数据中心的接入设备NFVI-GATEWAY信息及连接建立信息,例如隧道封装信息,如虚拟可扩展局域网(VXLAN)、通用路由封装(GRE)等发送给BNG。BNG将RG的WAN接口的IP地址、NFVI-GATEWAY信息及连接建立信息 发送给RG。
步骤1003:RG和NFVI-GATEWAY根据RG的WAN的IP地址、NFVI-GATEWAY信息及连接建立信息建立连接。
步骤1004:RG向NFVI-GATEWAY发送DHCP请求;
本应用示例,DHCP请求为RG的局域网(LAN)接口的IP地址请求。
步骤1005:NFVI-GATEWAY接收来自RG的DHCP请求,将DHCP请求中包含的识别和认证相关信息上送到SDN控制器;
识别和认证相关信息包括DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址;
可选的,上送识别和认证相关信息时,本应用示例方法还包括:NFVI-GATEWAY发送隧道目的地址到SDN控制器,以使SDN控制器根据接收的隧道目的地址与NFVI-GATEWAY通信。
需要说明的是,DHCP请求中按照相关技术中的封装还可以包括RG的LAN接口在内的其他信息,属于本领域技术人员的公知常识。
步骤1006:SDN控制器根据接收的识别和认证相关信息发送认证请求信息到AAA服务器;
认证请求信息包含识别和认证相关信息;即认证请求信息携带有DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址;
步骤1007、AAA服务器根据接收的来自SDN控制器的认证请求信息进行RG认证;
需要说明的是,根据认证请求信息进行RG认证包括:根据动态主机配置协议DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的虚拟局域网VLAN、和/或与RG关联的多协议标签交换MPLS子网信息、和/或线路标识信息、和/或接收DHCP请求的宽带网络网关BNG端口号、和/或包含DHCP请求内容的消息进行RG认证;另外,本应用示例方法中默认SDN控制器为合法的,如果需要对SDN控制器进行认证,则可以在本应用示例方法中添加对SDN控制器进行认证的处理过程。
步骤1008、AAA服务器完成RG认证时,为VG分配地址管理信息;
可选的,为VG分配地址管理信息可以包括:
AAA服务器直接为VG分配地址管理信息;
可选的,本应用示例可以由SDN控制器为VG分配地址管理信息,包括:
SDN控制器接收来自AAA服务器的地址池唯一编号(ID)信息;
根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息。
可选的,SDN控制器根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
需要说明的是,将确定的IP地址上送至AAA服务器可以用于进行安全控制。例如、溯源。
地址管理信息可以包括:VG的WAN接口相关的IP地址、VG的网络地址转换(NAT)的公网地址及VG的NAT的接口(port)信息;
需要说明的是,地址池由运营商网管统一配置,在SDN控制器预先分配地址池、及不同的地址池的ID。AAA服务器可以根据地址池的ID为VG分配地址管理信息,包括根据地址池的ID为不同的RG分配不同的IP地址。在BNG上已经采用相关技术中的方法配置了地址池信息,本应用示例方法中SDN控制器可以按照相同的原理配置地址池信息;本应用示例方法还可以从BNG中直接获取存储的地址池信息,但是,在获取BNG上存储的地址池信息之前,需要建立AAA服务器与BNG的连接。
步骤1009、AAA服务器在完成对RG认证后向SDN控制器发送携带有为VG分配的地址管理信息的认证响应消息;
步骤1010:SDN控制器接收来自AAA服务器的认证响应消息后,根据用户签约信息为RG分配VG,根据认证响应信息中的为VG分配的地址管理信息的内容为VG配置地址;
需要说明的是,SDN控制器接收到认证响应信息时,可以对为VG分配的地址管理信息的内容进行存储。
可选的,为RG分配VG之前,本应用示例方法还包括:AAA服务器向 SDN控制器发送用户签约信息;
需要说明的是,用户签约信息是相关技术中的现有的信息,是用户在与运营商签订用网协议时签订的协议内容,包含涉及用户的用网策略,存储在AAA服务器中。签约信息包含用户业务的基础配置,包括用于网络连接的IP地址信息、用户带宽信息、服务质量信息、安全控制相关信息以及用户增值业务信息(如家庭控制、防火墙等)。
可选的,本应用示例还包括:
SDN控制器将预先存储的VG的LAN接口接入信息发往NFVI-GATEWAY;
VG的LAN接口接入信息可以包括VG的LAN接口可达的虚拟网关唯一编码(VG-ID)信息和/或VG的LAN接口的连接信息;
需要说明的是,本应用示例,VG的LAN接口接入信息可以通过用户签约信息确定。
可选的,本应用示例方法还包括:
SDN控制器将分配给VG的地址管理信息下发给VG进行设置;
可选的,如果包含与VG共享的NAT设备,本应用示例方法还包括:SDN控制器将分配给VG的NAT公网地址及VG的NAT公网的port信息下发给与VG共享的NAT设备。
需要说明的是,VG共享的NAT设备可以通过用户签约信息确定,确定VG共享的NAT设备属于本领域技术人员的惯用技术手段,在此不再赘述;
步骤1011:NFVI-GATEWAY将RG与NFVI-GATEWAY的连接延伸至VG的LAN接口所在网络;即将RG和NFVI-GATEWAY的隧道和VG的LAN接口所在的网络建立映射关系。
需要说明的是,VG的LAN接口所在网络可以通过SDN控制预先存储的网络拓扑信息进行确定,建立映射关系的内容包括:将RG连接到的NFVI-GATEWAY的隧道,与NFVI-GATEWAY的隧道连接的与RG成对应关系的VG的LAN接口所在的网络,以NFVI-GATEWAY的隧道作为中间层,进行一一对应的连接;
步骤1012:RG的LAN接口及LAN接口所连的家庭网络设备发送DHCP请求到VG。
步骤1013:VG为RG的LAN接口所连的家庭网络设备分配IP地址。
步骤1014:RG转发家庭网络设备的数据流,VG为家庭网络设备提供业务转发;业务转发包括IP转发或NAT或其他业务处理的转发。
RG也可以发送以太网上的点对点协议(PPPoE)请求用于实现RG的接入、认证以及VG相关的NFVI-GATEWAY分配。RG的LAN接口发送的报文会承载在VXLAN等二层隧道协议之上,并通过PPPoE封装到达BNG。BNG解封装PPPoE报文后,RG的LAN接口发送的报文会根据二层隧道协议的目的地址确定NFVI-GATEWAY的位置。
本应用示例的RG也可以是企业网网关接入,企业网网关可以动态接入,也可以静态接入。企业网网关接入时,BNG支持三层转发。动态接入时,通过接入BNG,向AAA服务器请求可接入VG的NFVI-GATEWAY相关信息,建立企业网关WAN接口和NFVI-GATEWAY的WAN接口的连接,NFVI-GATEWAY的WAN接口可通过子接口或隧道信息区分不同的企业网关接入。当该连接有报文,会触发步骤1005到步骤1010的处理流程。
应用示例2
本应用示例家庭网关通过以太网接入功能和VG通信。VG位于数据中心内,本应用示例第一装置为NFVI-GATEWAY,NFVI-GATEWAY作为独立设备,并为VG提供RG接入。
图11为本发明第二应用示例的方法流程图,如图11所示,包括:
步骤1100:RG的LAN接口向提供接入的BNG发送DHCP请求;
本应用示例,DHCP请求为家庭网关的LAN接口的IP地址请求。
步骤1101:BNG收到DHCP请求,向AAA服务器发送RG认证及VG接入AAA请求;其中,RG认证及VG接入AAA请求携带有线路标识信息。
步骤1102:AAA服务器根据RG认证及VG接入AAA请求认证RG,并分配VG连接信息;VG连接信息包括虚拟局域网(VLAN)或多协议标签交换(MPLS)子网信息;AAA服务器发送RG的VG连接信息至BNG。
步骤1103:BNG根据AAA服务器返回的VLAN或MPLS子网信息,建立与VG所连接的NFVI-GATEWAY的连接,并在BNG上建立BNG与VG所连接的NFVI-GATEWAY与RG接入的二层子网的映射。
需要说明的是,BNG与VG所连接的NFVI-GATEWAY与RG接入的二层子网的映射包括:将VG连接到的NFVI-GATEWAY的隧道,与NFVI-GATEWAY的隧道连接的与RG成对应关系的RG接入的二层子网,以NFVI-GATEWAY的隧道作为中间层,进行一一对应的连接;
步骤1104:BNG将接收到DHCP请求发送给连接的NFVI-GATEWAY;
步骤1105:NFVI-GATEWAY接收来自BNG的DHCP请求,将DHCP请求中包含的识别和认证相关信息上送到SDN控制器;
识别和认证相关信息包括DHCP请求中封装的与RG关联的VLAN或与RG关联的MPLS子网信息。
需要说明的是,DHCP请求中按照相关技术中的封装还包括家庭网关的LAN接口等信息,属于本领域技术人员的公知常识。
可选的,上送识别和认证相关信息时,本应用示例方法还包括:
NFVI-GATEWAY发送RG的隧道目的地址到SDN控制器,以使SDN控制器根据RG的隧道目的地址进行通信。
步骤1106:SDN控制器根据接收的识别和认证相关信息发送认证请求信息到AAA服务器;
认证请求信息包含识别和认证相关信息,即认证请求信息携带有DHCP请求中封装的与RG关联的VLAN、和/或与RG关联的MPLS子网信息;
步骤1107、AAA服务器根据接收的来自SDN控制器的认证请求信息进行RG认证;
需要说明的是,根据认证请求信息进行RG认证为本领域技术人员的惯用技术手段;另外,本应用示例方法,默认SDN控制器为合法的,如果需要对SDN控制器进行认证,则可以在本应用示例方法中添加对SDN控制器进行认证的处理过程。
步骤1108、AAA服务器完成RG认证时,为VG分配地址管理信息;
可选的,为VG分配地址管理信息包括:
AAA服务器直接为VG分配地址管理信息;
地址管理信息包括VG的WAN接口相关的IP地址、VG的NAT公网地址及VG的NAT的port信息;
可选的,本应用示例可以由SDN控制器为VG分配地址管理信息,包括:
SDN控制器接收来自AAA服务器的地址池唯一编号(ID)信息;
根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息。
可选的,SDN控制器根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
需要说明的是,将确定的IP地址上送至AAA服务器可以用于进行安全控制。例如、溯源。
需要说明的是,在BNG上已经采用相关技术中的方法配置了地址池信息,本应用示例方法中SDN控制器可以按照相同的原理配置地址池信息;本应用示例方法还可以从BNG中直接获取存储的地址池信息,但是,在获取BNG上存储的地址池信息之前,需要建立AAA服务器与BNG的连接。
步骤1109、AAA服务器完成对RG认证后,向SDN控制器发送携带有为VG分配的地址管理信息的认证响应消息;
步骤1110:SDN控制器接收来自AAA服务器的认证响应消息后,根据用户签约信息为RG分配VG,根据认证响应信息中的为VG分配的地址管理信息的内容为VG配置地址;
可选的,为RG分配VG之前,本应用示例方法还包括:AAA服务器向SDN控制器发送用户签约信息;
需要说明的是,用户签约信息是相关技术中的现有的信息,是用户在与运营商签订用网协议时签订的协议内容,包含涉及用户的用网策略,存储在AAA服务器中;
可选的,本应用示例还包括:SDN控制器对每一RG的识别和认证相关信息为VG分配的地址管理信息建立相应的会话控制(session)管理;
会话控制管理的内容包括:与RG关联的VLAN、与RG关联的MPLS子网信息、VG-ID信息、VG的LAN接口信息、VG的WAN接口信息、VG NAT公网的公网地址、VG的NAT的port信息,分配VG地址管理信息、QOS、安全策略以及OAM管理信息的记录和维护。
需要说明的是,进行会话控制管理包括对会话控制管理的内容进行记录和维护,这里的维护包括:签约用户登录时,对会话控制管理的内容进行记录,当RG由于一些原因退出时,在重新登录过程中,发送记录的会话控制管理的内容到再次登录的RG。
可选的,SDN控制器将预先存储的VG的LAN接口接入信息发往NFVI-GATEWAY;
VG的LAN接口接入信息可以包括VG的LAN接口可达的VG-ID信息和/或VG的LAN接口连接信息;
需要说明的是,VG的LAN接口接入信息可以通过用户签约信息确定。
可选的,本应用示例方法还包括:SDN控制器将分配给VG的地址管理信息下发给VG进行设置;
可选的,本应用示例方法还包括:
SDN控制器将分配给VG的地址管理信息下发给VG进行设置;
可选的,如果有与VG共享的NAT设备,本应用示例方法还包括:将分配给VG的NAT公网地址及VG的NAT公网的port信息下发给与VG共享的NAT设备。
需要说明的是,VG共享的NAT设备可以通过用户签约信息确定,确定VG共享的NAT设备属于本领域技术人员的惯用技术手段,在此不再赘述;
步骤1111:NFVI-GATEWAY将RG与NFVI-GATEWAY的连接延伸至与VG的LAN接口所在的网络。
步骤1112:RG的LAN接口及LAN接口所连的家庭网络设备向VG发送DHCP请求,申请IP地址。
步骤1113:VG为RG的LAN接口及LAN接口所连的家庭网络设备分配IP地址。
步骤1114:RG转发家庭网络设备的数据流,VG为家庭网络设备提供业务转发;业务转发包括IP转发或NAT或其他业务处理的转发;
如果多个VG共享NAT或其他业务,则对其他业务进行转发处理。
RG也可以企业网网关接入,企业网网关可以动态接入,也可以静态接入;企业网网关接入时,BNG支持二层转发;动态接入时,通过接入BNG,向AAA服务器请求可接入VG侧的NFVI-GATEWAY相关信息,建立企业网网关的WAN接口和NFVI-GATEWAY的WAN接口的连接,NFVI-GATEWAY的WAN接口可通过与RG关联的VLAN或与RG关联的MPLS子网实现与企业网网关的接入;当该连接有报文,会触发和本应用示例步骤1105到步骤1110的处理流程。
应用示例3
本应用示例应用场景为家庭网关通过三层路由接入功能和VG互通;VG位于数据中心内,本应用示例第一装置为通过BNG中扩展第一应用示例和第二应用示例中的NFVI-GATEWAY的功能的装置,为VG提供RG接入。
图12为本发明第三应用示例的方法流程图,如图12所示,包括:
步骤1200:RG向当前接入的BNG发送DHCP请求;
DHCP请求为RG的WAN接口的IP地址请求;
DHCP请求在经过运营商接入网络(Access network)时,中间设备会增加线路标识信息。
需要说明的是,中间设备可以包括:数字用户线路接入复用器(Digital Dilamolt),光线路终端或接入交换机(OLT)等。
步骤1201:BNG接收来自RG的DHCP请求,将收到DHCP请求中包含识别和认证相关信息发往SDN控制器;
识别和认证相关信息包括:线路标识信息、或接收DHCP请求的BNG端口号。
需要说明的是,本应用示例方法,包含识别和认证相关信息也可以通过直接转发DHCP请求的方式发往SDN控制器。
步骤1202、SDN控制器根据预先存储的认证记录信息判断是否是新的RG;
可选的,本应用示例方法步骤1002之前还包括:SDN控制器存储在AAA服务器完成认证的RG的识别和认证相关信息,作为认证记录信息。
如果RG是新的RG,则执行步骤1003;如果不是新的RG,则一般认为本应用示例后续流程均已完成;
步骤1203、SDN控制器根据接收的识别和认证相关信息发送认证请求信息到AAA服务器;
认证请求消息携带识别和认证相关信息,即认证请求信息中携带有线路标识信息、接收DHCP请求的BNG端口号、或包含DHCP请求内容的消息;
可选的,BNG上送识别和认证相关信息的时候,为了实现SDN控制与BNG的通信,BNG需要发送自身的编号到SDN控制器,SDN控制器根据BNG的编号和接收DHCP请求的BNG端口号与BNG通信。
步骤1204:AAA服务器根据接收的来自SDN控制器的认证请求信息进行RG认证;
需要说明的是,本应用示例方法,默认SDN控制器为合法的,如果需要对SDN控制器进行认证,则可以在本步骤中添加多SDN控制器的认证处理。
步骤1205、AAA服务器完成RG认证时,为VG分配地址管理信息;
可选的,分配VG地址管理信息包括:AAA服务器直接为VG分配地址管理信息;
地址管理信息包括VG的WAN接口相关IP地址、VG的NAT公网地址及VG的NAT公网的port信息;
可选的,本应用示例可以由SDN控制器为VG分配地址管理信息,包括:
SDN控制器接收来自AAA服务器的地址池唯一编号(ID)信息;
根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信 息。
可选的,SDN控制器根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
需要说明的是,将确定的IP地址上送至AAA服务器可以用于进行安全控制。例如、溯源。
步骤1206、AAA服务器完成认证后,向SDN控制器返回携带有为VG分配的地址管理信息的认证响应消息。
步骤1207:SDN控制器接收到来自AAA服务器的认证响应消息后,根据用户签约信息为RG分配VG,根据认证响应信息中的为VG分配的地址管理信息的内容为VG配置地址;
可选的,为RG分配VG之前,本应用示例方法还包括:AAA服务器向SDN控制器发送用户签约信息;
可选的,本应用示例还包括,SDN控制器将预先存储的RG的WAN IP地址、VG的LAN接口接入信息发往BNG;
VG的LAN接口接入信息包括VG的LAN接口可达的VG-ID信息和/或VG的LAN接口的连接信息;
需要说明的是,RG的WAN IP地址、VG的LAN接口接入信息可以通过用户签约信息确定。
可选的,本应用示例方法还包括:
SDN控制器将分配给VG的地址管理信息下发给VG进行设置;
可选的,如果包含与VG共享的NAT设备,本应用示例方法还包括:将分配给VG NAT公网地址及VG NAT公网的port信息下发给与VG共享的NAT设备。
需要说明的是,VG共享NAT设备可以通过用户签约信息确定,属于本领域技术人员的惯用技术手段;
步骤1208:BNG将RG的WAN IP地址通过DHCP消息回复给RG,并 将RG所在网络与VG所在的子网进行关联后,建立连接。
步骤1209:RG保存VG的WAN地址,建立RG和BNG的隧道连接。
步骤1210:RG的LAN接口发送DHCP请求。
步骤1211:VG为RG的LAN接口及所连家庭网络设备分配IP地址。
VG进行业务流处理后,发送给RG或NAT或其他业务设备,业务流最终由BNG上送到因特网(Internet)。
RG也可以企业网网关接入。企业网网关可以动态接入,也可以静态接入。企业网网关接入时,BNG支持二层转发;动态接入时,通过接入BNG,BNG通过SDN控制器向AAA服务器请求接入;BNG根据SDN控制器的配置建立由SDN控制器动态管理虚拟企业网关连接。BNG根据与控制器连接的端口来识别企业网关用户;采用的步骤和1203到1207的处理流程相似。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序来指令相关硬件(例如处理器)完成,所述程序可以存储于计算机可读存储介质中,如只读存储器、磁盘或光盘等。可选地,上述实施例的全部或部分步骤也可以使用一个或多个集成电路来实现。相应地,上述实施例中的每个模块/单元可以采用硬件的形式实现,例如通过集成电路来实现其相应功能,也可以采用软件功能模块的形式实现,例如通过处理器执行存储于存储器中的程序/指令来实现其相应功能。本发明不限制于任何特定形式的硬件和软件的结合。”。
虽然本发明所揭露的实施方式如上,但所述的内容仅为便于理解本发明而采用的实施方式,并非用以限定本发明。任何本发明所属领域内的技术人员,在不脱离本发明所揭露的精神和范围的前提下,可以在实施的形式及细节上进行任何的修改与变化,但本发明的专利保护范围,仍须以所附的权利要求书所界定的范围为准。
工业实用性
本发明实施例提出的实现地址管理的方法、装置、SDN控制器及AAA服务器,包括:软件定义网络(SDN)控制器根据接收的来自第一装置的家庭网关(RG)的识别和认证相关信息生成并发送进行家庭网关RG认证的认 证请求信息到认证授权计费(AAA)服务器;AAA服务器在完成RG的认证后,为VG分配地址管理信息;SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配虚拟网关(VG),SDN控制器根据来自AAA服务器的携带有为VG分配的地址管理信息的内容的认证响应信息为VG配置地址。本发明实施例方法通过SDN控制器为RG分配VG,通过AAA服务器为VG分配地址管理信息,实现了VG创建后的地址管理。

Claims (33)

  1. 一种实现地址管理的方法,其特征在于,包括:
    软件定义网络SDN控制器根据来自第一装置的识别和认证相关信息生成进行家庭网关RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到认证授权计费AAA服务器;
    SDN控制器在AAA服务器完成RG认证后,根据用户签约信息为RG分配虚拟网关VG;
    SDN控制器根据来自AAA服务器的认证响应信息为VG配置地址;
    所述认证响应消息为:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容;
    其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG。
  2. 根据权利要求1所述的方法,其特征在于,该方法还包括:所述SDN控制器将预先存储的VG的局域网LAN接口接入信息发往所述第一装置。
  3. 根据权利要求2所述的方法,其特征在于,所述VG的LAN接口接入信息包括:
    VG的LAN接口可达的虚拟网关唯一编码VG-ID信息、和/或VG的LAN接口的连接信息。
  4. 根据权利要求1项所述的方法,其特征在于,所述为RG分配VG之后,如果包含有与分配的所述VG共享的NAT设备,所述方法还包括:
    所述SDN控制器将分配给VG的网络地址转换NAT公网地址及VG的NAT公网的接口port信息下发给与所述VG共享的NAT设备。
  5. 根据权利要求1所述的方法,其特征在于,所述方法还包括:所述SDN控制器对每一RG分别建立相应的会话控制管理;
    所述会话控制管理包括:对与RG关联的VLAN、和/或与RG关联的MPLS子网信息、和/或VG-ID信息、和/或VG的LAN接口信息、和/或VG的广域网WAN接口信息、和/或VG的NAT公网的公网地址、和/或VG的NAT的port信息、和/或分配VG地址管理信息、和/或服务质量QOS、和/ 或安全策略、和/或操作管理维护OAM管理信息进行记录和维护。
  6. 根据权利要求1、2、4或5所述的方法,其特征在于,所述认证请求信息包含识别和认证相关信息;
    所述识别和认证相关信息包括:动态主机配置协议DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的虚拟局域网VLAN、和/或与RG关联的多协议标签交换MPLS子网信息、和/或线路标识信息、和/或接收DHCP请求的宽带网络网关BNG端口号、和/或包含DHCP请求内容的消息。
  7. 一种实现地址管理的方法,其特征在于,包括:
    SDN控制器接收来自AAA服务器的地址池ID信息;
    SDN控制器根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息;
    其中,VG为SDN控制器为RG分配的VG。
  8. 根据权利要求7所述的方法,其特征在于,所述方法还包括:
    SDN控制器根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
  9. 根据权利要求7或8所述的方法,其特征在于,
    所述地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息。
  10. 一种实现地址管理的方法,其特征在于,包括:
    AAA服务器在完成RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有所述为VG分配的地址管理信息的内容的认证响应消息;
    其中,所述VG为SDN控制器为RG分配的VG。
  11. 根据权利要求10所述的方法,其特征在于,为RG分配VG之前,所述方法还包括:
    所述AAA服务器向SDN控制器发送用户签约信息。
  12. 根据权利要求10或11所述的方法,其特征在于,所述为VG分配地址管理信息包括:
    所述AAA服务器直接为VG分配地址管理信息;
    所述地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息。
  13. 一种实现地址管理的方法,其特征在于,包括:
    第一装置获取识别和认证相关信息,并发送给软件定义网络SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
  14. 根据权利要求13所述的方法,其特征在于,所述获取识别和认证相关信息,并发送给SDN控制器包括:
    所述第一装置通过接收的动态主机配置协议DHCP请求,从DHCP请求中携带的信息中获取识别和认证相关信息。
  15. 根据权利要求14所述的方法,其特征在于,所述DHCP请求来自宽带网络网关BNG或家庭网关RG。
  16. 根据权利要求13所述的方法,其特征在于,所述第一装置包括:网络功能虚拟化基础架构网关NFVI-GATEWAY或BNG。
  17. 根据权利要求13~16任一项所述的方法,其特征在于,
    当所述第一装置为NFVI-GATEWAY时,所述识别和认证相关信息包括:DHCP请求中封装的RG的隧道标识符、和/或RG的隧道源地址、和/或与RG关联的虚拟局域网VLAN、和/或与RG关联的多协议标签交换MPLS子网信息、和/或线路标识信息、和/或包含DHCP请求内容的消息;
    当所述第一装置为BNG时,所述识别和认证相关信息包括:线路标识信息、和/或接收DHCP请求的BNG端口号、和/或包含DHCP请求内容的消息。
  18. 根据权利要求13~16任一项所述的方法,其特征在于,发送所述识别和认证相关信息到SDN控制器时,所述方法还包括:
    所述第一装置发送第一装置的通信地址到SDN控制器,以使SDN控制器根据接收的第一装置的通信地址与第一装置通信。
  19. 根据权利要求13~16任一项所述的方法,其特征在于,该方法还包括:
    所述第一装置将RG与第一装置的连接延伸至虚拟网关VG的局域网LAN接口所在网络。
  20. 一种实现地址管理的SDN控制器,其特征在于,包括:生成发送单元、分配单元和地址配置单元;其中,
    生成发送单元用于,根据来自第一装置的识别和认证相关信息生成进行RG认证的认证请求信息,并将生成的RG认证的认证请求信息发送到AAA服务器;
    分配单元用于,在AAA服务器完成RG认证后,根据用户签约信息为RG分配VG;
    地址配置单元用于,SDN控制器根据来自AAA服务器的认证响应信息为VG配置地址;
    所述认证响应消息为:AAA服务器完成认证后,向SDN控制器反馈的携带有AAA服务器为VG分配的地址管理信息的内容;
    其中,VG为由SDN控制器或AAA服务器分配地址管理信息的VG。
  21. 根据权利要求20所述的SDN控制器,其特征在于,所述SDN控制器还包括接入信息发送单元,用于将预先存储的VG的LAN接口接入信息发往所述第一装置。
  22. 根据权利要求20或21所述的SDN控制器,其特征在于,所述SDN控制器还包括下发单元,用于所述为RG分配VG之后,如果包含有与分配的所述VG共享的NAT设备,将分配给VG的NAT公网地址及VG的NAT公网的port信息下发给与所述VG共享的NAT设备。
  23. 根据权利要求20或21所述的SDN控制器,其特征在于,所述SDN控制器还包括会话控制单元,用于对每一RG分别建立相应的会话控制session管理;
    所述会话控制管理包括:对与RG关联的VLAN、和/或与RG关联的MPLS子网信息、和/或VG-ID信息、和/或VG的LAN接口信息、和/或VG的广域网WAN接口信息、和/或VG的NAT公网的公网地址、和/或VG的NAT的port信息、和/或分配VG地址管理信息、和/或QOS、和/或安全策略、和/或OAM管理信息进行记录和维护。
  24. 一种实现地址管理的SDN控制器,其特征在于,包括:接收地址池编号单元和分配地址单元;其中,
    接收地址池编号单元用于,接收来自AAA服务器的地址池唯一编号ID信息;
    分配地址单元用于,根据预先配置地址池信息及接收的地址池ID信息为VG分配地址管理信息;
    其中,VG为SDN控制器为RG分配的VG。
  25. 根据权利要求24所述的SDN控制器,其特征在于,所述SDN控制器还包括上送单元,
    用于根据基于地址池信息及地址池ID信息为VG分配地址管理信息,确定为VG分配的IP地址,并将确定的为VG分配的IP地址上送至AAA服务器。
  26. 一种实现地址管理的AAA服务器,其特征在于,包括分配信息单元,用于完成对RG的认证后,为VG分配地址管理信息,并向SDN控制器反馈携带有所述为VG分配的地址管理信息的内容的认证响应消息;
    其中,VG为SDN控制器为RG分配的VG。
  27. 根据权利要求26所述的AAA服务器,其特征在于,所述分配信息单元具体用于,直接为VG分配地址管理信息;
    所述地址管理信息包括:VG的广域网WAN接口相关的IP地址、和/或VG的网络地址转换NAT的公网地址及VG的NAT的接口port信息。
  28. 根据权利要求26或27所述的AAA服务器,其特征在于,所述AAA服务器还包括签约信息发送单元,用于为RG分配VG之前,向SDN控制器发送用户签约信息。
  29. 一种实现地址管理的装置,其特征在于,包括:相关信息发送单元,用于获取识别和认证相关信息,并发送给SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
  30. 根据权利要求29所述的装置,其特征在于,所述相关信息发送单元还用于,
    发送所述识别和认证相关信息到SDN控制器时,发送所述装置的通信地址到SDN控制器,以使SDN控制器根据接收的所述装置的通信地址与所述装置通信。
  31. 根据权利要求29所述的装置,其特征在于,所述相关信息发送单元具体用于:根据接收的DHCP请求,发送DHCP请求中包含的识别和认证相关信息到SDN控制器,以使SDN控制器根据所述识别和认证相关信息生成进行RG认证的认证请求信息。
  32. 根据权利要求29、30或31所述的装置,其特征在于,该装置还包括延伸单元,用于,将RG与所述装置的连接延伸至VG的LAN接口所在网络。
  33. 一种计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令用于执行权利要求1~权利要求6,和/或权利要求7~权利要求9,和/或权利要求10~权利要求12,和/或权利要求13~权利要求19任一项实现地址管理的方法。
PCT/CN2017/073747 2016-03-29 2017-02-16 一种实现地址管理的方法、装置、aaa服务器及sdn控制器 WO2017166936A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610188372.0A CN107241454B (zh) 2016-03-29 2016-03-29 一种实现地址管理的方法、装置、aaa服务器及sdn控制器
CN201610188372.0 2016-03-29

Publications (1)

Publication Number Publication Date
WO2017166936A1 true WO2017166936A1 (zh) 2017-10-05

Family

ID=59963367

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/073747 WO2017166936A1 (zh) 2016-03-29 2017-02-16 一种实现地址管理的方法、装置、aaa服务器及sdn控制器

Country Status (2)

Country Link
CN (1) CN107241454B (zh)
WO (1) WO2017166936A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3493483A4 (en) * 2016-07-28 2020-02-12 ZTE Corporation VIRTUAL BROADBAND ACCESS METHOD, CONTROL UNIT AND SYSTEM
CN115361605A (zh) * 2022-10-20 2022-11-18 武汉长光科技有限公司 虚拟域域内漫游方法、装置、设备和计算机可读存储介质

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111200665B (zh) * 2018-11-19 2022-07-01 中国移动通信集团吉林有限公司 一种用户溯源方法、装置及计算机可读存储介质
CN112637154B (zh) * 2020-12-09 2022-06-21 迈普通信技术股份有限公司 设备认证方法、装置、电子设备及存储介质
CN113765904B (zh) * 2021-08-26 2023-03-31 新华三大数据技术有限公司 一种认证方法及装置
CN114125596B (zh) * 2021-10-21 2023-12-05 中盈优创资讯科技有限公司 一种pon-sdwan智能终端归一化控制方法及装置
CN116980247B (zh) * 2023-09-22 2024-01-16 广州市成格信息技术有限公司 一种基于软件定义局域网实现ip随行的方法及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103685250A (zh) * 2013-12-04 2014-03-26 蓝盾信息安全技术股份有限公司 一种基于sdn的虚拟机安全策略迁移的系统及方法
CN104767696A (zh) * 2014-01-07 2015-07-08 上海贝尔股份有限公司 Sdn化的接入网中控制用户接入的方法及装置
US20150207699A1 (en) * 2014-01-21 2015-07-23 Centurylink Intellectual Property Llc Consumer Choice for Broadband Application and Content Services
CN104969590A (zh) * 2013-02-11 2015-10-07 瑞典爱立信有限公司 用于允许在虚拟家庭网关中的数据路径选择的方法和设备

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103067268B (zh) * 2012-12-31 2017-02-08 华为技术有限公司 一种虚拟家庭网关服务提供方法及服务器
CN103428771B (zh) * 2013-09-05 2017-02-15 迈普通信技术股份有限公司 通信方法、软件定义网络sdn交换机及通信系统
CN104243265B (zh) * 2014-09-05 2018-01-05 华为技术有限公司 一种基于虚拟机迁移的网关控制方法、装置及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104969590A (zh) * 2013-02-11 2015-10-07 瑞典爱立信有限公司 用于允许在虚拟家庭网关中的数据路径选择的方法和设备
CN103685250A (zh) * 2013-12-04 2014-03-26 蓝盾信息安全技术股份有限公司 一种基于sdn的虚拟机安全策略迁移的系统及方法
CN104767696A (zh) * 2014-01-07 2015-07-08 上海贝尔股份有限公司 Sdn化的接入网中控制用户接入的方法及装置
US20150207699A1 (en) * 2014-01-21 2015-07-23 Centurylink Intellectual Property Llc Consumer Choice for Broadband Application and Content Services

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3493483A4 (en) * 2016-07-28 2020-02-12 ZTE Corporation VIRTUAL BROADBAND ACCESS METHOD, CONTROL UNIT AND SYSTEM
CN115361605A (zh) * 2022-10-20 2022-11-18 武汉长光科技有限公司 虚拟域域内漫游方法、装置、设备和计算机可读存储介质

Also Published As

Publication number Publication date
CN107241454B (zh) 2019-08-16
CN107241454A (zh) 2017-10-10

Similar Documents

Publication Publication Date Title
WO2017166936A1 (zh) 一种实现地址管理的方法、装置、aaa服务器及sdn控制器
JP6722820B2 (ja) ブロードバンドリモートアクセスサーバの制御プレーン機能と転送プレーン機能の分離
US9485147B2 (en) Method and device thereof for automatically finding and configuring virtual network
US8681695B1 (en) Single address prefix allocation within computer networks
EP3282667B1 (en) Generating a vnf for authorizing service
US20040004968A1 (en) System and method for dynamic simultaneous connection to multiple service providers
WO2018019299A1 (zh) 一种虚拟宽带接入方法、控制器和系统
EP3108643B1 (en) Ipoe dual-stack subscriber for routed residential gateway configuration
JP5424007B2 (ja) 情報を提供するための方法、ホームゲートウェイおよびホームネットワークシステム
JP2008547295A (ja) 2種類の装置を管理する装置及び方法
CN107547351B (zh) 地址分配方法和装置
US10749797B2 (en) Service label routing in a network
WO2018113591A1 (zh) 一种调度方法、系统、控制器和计算机存储介质
WO2013071765A1 (zh) 为用户终端分配ip地址的方法、装置和系统
WO2009143729A1 (zh) 实现dhcp用户业务批发的方法、系统和设备
US20200274948A1 (en) Service flow configuration method and apparatus
CN107547403B (zh) 报文转发方法、协助方法、装置、控制器及主机
US9521033B2 (en) IPoE dual-stack subscriber for bridged residential gateway configuration
WO2024000975A1 (zh) 一种会话建立系统、方法、电子设备及存储介质
CN113938353A (zh) 室内机与室外机之间的多pdn实现方法及存储介质
WO2020029793A1 (zh) 一种上网行为管理系统、设备及方法
Jeong et al. Experience on the development of LISP-enabled services: An ISP perspective
CN108418700B (zh) 通信方法和设备
RU2635216C1 (ru) Способ маршрутизации IP-пакетов при использовании VPLS совместно с DHCP в сети с коммутацией пакетов
EP3301860A1 (en) Method for interconnecting virtual gateways and corresponding virtual gateway

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17772967

Country of ref document: EP

Kind code of ref document: A1

122 Ep: pct application non-entry in european phase

Ref document number: 17772967

Country of ref document: EP

Kind code of ref document: A1